fix(windows): report the running build as the kernel version - #295
Open
Shubham-Padkonde wants to merge 2 commits into
Open
Shubham-Padkonde wants to merge 2 commits into
Shubham-Padkonde wants to merge 2 commits into
Conversation
Feature updates delivered as enablement packages change the OS build without replacing ntoskrnl.exe, so the file version of the kernel image reported the previous feature release (e.g. 10.0.22621.x on a 22631 host). Read the version from the CurrentVersion registry key instead and keep the file version as a fallback when the values are unavailable. Fixes elastic#294 Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #294.
KernelVersion()read theFileVersionofntoskrnl.exe. Feature updates shipped as enablement packages change the OS build without replacing that file, so it reported the previous feature release.It now composes
<CurrentMajorVersionNumber>.<CurrentMinorVersionNumber>.<CurrentBuildNumber>.<UBR>fromHKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion, the keyOperatingSystem()already reads. If any of these values is missing (they exist since Windows 10), it falls back to the previous file-version lookup, sokernelExePathis kept for that path. The result no longer has the(WinBuild.160101.0800)suffix.The machine I tested on reproduces the issue: before this change
KernelVersion()returned10.0.26100.9278 (WinBuild.160101.0800)while the running build is26200.9278; with it,10.0.26200.9278. The newTestKernelVersionMatchesRunningBuildcompares the result withOperatingSystem()and fails before the change. The Windows provider tests pass (built withGOOS=windows, run on Windows 11), along withgofmtandgo vet.🤖 Generated with Claude Code