feature: randomize constants xorshift triple (#69) - #107
Merged
Merged
Conversation
The Constants protection expands its key with a 32-bit xorshift (n ^= n >> a; n ^= n << b; n ^= n >> c) on both the obfuscator (EncodePhase) and the injected runtime (Constant.Initialize), using the fixed 12/25/27 that de4dot/AV pattern-match to fingerprint the stub. The triple is now chosen per module from a curated set and injected into the runtime Initialize via mutation keys (KeyI2/KeyI3/KeyI4). Both sides share it, so the round-trip holds for any shifts; the curated triples are additionally full-period (period 2^32-1, verified by GF(2) matrix order) with non-extreme shifts, so the key stream is well mixed. The historic 12/25/27 is not even full period. ~7 bits of added per-module identity. Injection goes through a new MutationHelper.InjectKeysEnsured that verifies each placeholder is present, so a runtime-source change that drops one fails the build instead of silently desyncing. scripts/curate_xorshift.py regenerates the set deterministically. Validated by 270_EnumArrayConstantProtection.Test and 193_ConstantsInlining.Test.
This was referenced Sep 21, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Level 2 constant randomization — Constants xorshift (#69)
Removes the fixed
12/25/27xorshift shifts from the Constants protection key generator. The generatorn ^= n >> a; n ^= n << b; n ^= n >> cruns identically on the obfuscator (EncodePhase) and the injected runtime (Constant.Initialize) to expand a seed into the 16-word key stream; the fixed shifts let de4dot/AV pattern-match the stub.Change
ConstantXorshift.Triples) and injected into the runtimeInitializeviaMutation.KeyI2/KeyI3/KeyI4.Curated set (
scripts/curate_xorshift.py)Each triple is a full-period xorshift (period 2³²−1), verified exactly by computing the GF(2) transition matrix's multiplicative order (primitivity test against the factors of 2³²−1 = 3·5·17·257·65537), restricted to non-extreme shifts (2–30) for good avalanche over the 16-word expansion. 128 triples → ~7 bits of per-module identity.
Notably, the historic
12/25/27is not even full-period — the curated set is a strict quality upgrade.Fail-loud injection
Injection now goes through a new
MutationHelper.InjectKeysEnsured, which verifies every requested placeholder is present in the method before injecting and throws otherwise. A future runtime-source change that drops a placeholder fails the build instead of silently desyncing encode/decode. (The compressor's local verifier from #106 can later migrate to this shared helper.)Validation
270_EnumArrayConstantProtection.Testand193_ConstantsInlining.Testpass — both obfuscate and run, exercising the full encode →InjectKeys→ runtimeInitializekey path; a broken sync fails immediately.Remaining on #69 (follow-ups)
5/3/7/11(curated rotation-quad set).0x3dbb2819(Normal/Anti done in feature: randomize anti-tamper feedback + CFG multiplier constants (#69 level 2) #98)..sh).Part of #69. Related: #106 (compressor moduli).