feat(build): randomized build-time class-name obfuscation + pin Qt 6.10.2
Rename every shit.zen.* / asm.patchify.* class to a fresh random 16-char name in one random 16-char package on each build, via an ASM ClassRemapper pass (build.gradle ext.obfuscateJar, run after ForgeGradle reobfJar). Class names only; methods/fields preserved. Manifest Premain/Agent-Class, the DllBootstrap Class.forName string, and the native bridge name (generated_names.h OZ_BRIDGE_FQCN) are wired to the generated names. Residual original-name strings (loggers, log text, the asm.patchify.* property keys) scrubbed. Emits build/rename-mapping.txt. Pin Qt to 6.10.2 (vcpkg builtin-baseline + CI tag 2026.04.27): MSVC 14.44 crashes building Qt 6.11.0. Build Qt single-threaded locally (VCPKG_MAX_CONCURRENCY=1, loader --parallel 1, gated off GitHub Actions) to dodge parallel-compilation compiler crashes on that toolset. CI uploads rename-mapping.txt as an artifact and attaches it to the Release; the Release body warns that prebuilt artifacts share one fixed (blacklist-able) mapping and users should self-compile. README documents the obfuscation + the self-compile warning. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -92,10 +92,13 @@ jobs:
|
||||
# "builtin-baseline". A floating HEAD clone made the qtbase port
|
||||
# (and thus its package ABI) drift every time upstream vcpkg moved,
|
||||
# so the restored Qt cache never matched and qtbase was rebuilt
|
||||
# from source (~31 min) on every run. Tag 2026.05.25 ==
|
||||
# d015e31e90838a4c9dfa3eed45979bc70d9357fc and ships qtbase 6.11.0.
|
||||
# from source (~31 min) on every run. Tag 2026.04.27 ==
|
||||
# 56bb2411609227288b70117ead2c47585ba07713 and ships qtbase 6.10.2.
|
||||
# We pin 6.10.2 (not the newer 6.11.0 from 2026.05.25) because MSVC
|
||||
# 14.44.x crashes with an internal compiler error (C1001) building
|
||||
# Qt 6.11.0 from source; 6.10.2 builds cleanly on every toolset we use.
|
||||
# Keep this tag and the builtin-baseline in vcpkg.json in lockstep.
|
||||
$vcpkgTag = '2026.05.25'
|
||||
$vcpkgTag = '2026.04.27'
|
||||
$vcpkg = Join-Path $env:GITHUB_WORKSPACE 'vcpkg'
|
||||
if (Test-Path $vcpkg) {
|
||||
Write-Host "Reusing existing $vcpkg"
|
||||
@@ -156,20 +159,28 @@ jobs:
|
||||
$sha = "${{ steps.rev.outputs.sha }}"
|
||||
$exeSrc = "build\dist\OpenZenLoader.exe"
|
||||
$jarSrc = "build\libs\hey-1.0.jar"
|
||||
# The class-name obfuscator emits a fresh, random old->new mapping on every
|
||||
# build; rename-mapping.txt is the ONLY way to de-obfuscate a stack trace, so
|
||||
# ship it with the artifacts/release.
|
||||
$mapSrc = "build\rename-mapping.txt"
|
||||
if (-not (Test-Path $exeSrc)) { throw "missing $exeSrc" }
|
||||
if (-not (Test-Path $jarSrc)) { throw "missing $jarSrc" }
|
||||
if (-not (Test-Path $mapSrc)) { throw "missing $mapSrc" }
|
||||
|
||||
$release = "build\release"
|
||||
New-Item -ItemType Directory -Force -Path $release | Out-Null
|
||||
$exeDst = Join-Path $release "OpenZenLoader-$sha.exe"
|
||||
$jarDst = Join-Path $release "OpenZen-$sha.jar"
|
||||
$mapDst = Join-Path $release "OpenZen-$sha-mapping.txt"
|
||||
Copy-Item -Force $exeSrc $exeDst
|
||||
Copy-Item -Force $jarSrc $jarDst
|
||||
Copy-Item -Force $mapSrc $mapDst
|
||||
|
||||
$exeSz = (Get-Item $exeDst).Length
|
||||
$jarSz = (Get-Item $jarDst).Length
|
||||
Write-Host ("OpenZenLoader-{0}.exe : {1:N0} bytes ({2:N2} MB)" -f $sha, $exeSz, ($exeSz/1MB))
|
||||
Write-Host ("OpenZen-{0}.jar : {1:N0} bytes ({2:N2} MB)" -f $sha, $jarSz, ($jarSz/1MB))
|
||||
Write-Host ("OpenZen-{0}-mapping.txt : {1:N0} bytes" -f $sha, (Get-Item $mapDst).Length)
|
||||
|
||||
# NOTE: actions/upload-artifact always wraps its content in a zip; that
|
||||
# is a platform limitation we cannot disable. By giving each artifact a
|
||||
@@ -193,6 +204,14 @@ jobs:
|
||||
if-no-files-found: error
|
||||
retention-days: 30
|
||||
|
||||
- name: Upload de-obfuscation mapping
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: OpenZen-${{ steps.rev.outputs.sha }}-mapping.txt
|
||||
path: build/release/OpenZen-${{ steps.rev.outputs.sha }}-mapping.txt
|
||||
if-no-files-found: error
|
||||
retention-days: 30
|
||||
|
||||
# ===== Optional GitHub Release publish =====
|
||||
# If the HEAD commit message contains the literal marker "[Release]",
|
||||
# cut a GitHub Release tagged build-<sha> and attach the exe + jar.
|
||||
@@ -224,9 +243,30 @@ jobs:
|
||||
# Write notes via a file so quoting / [brackets] / newlines in the
|
||||
# commit message can't corrupt the gh command line.
|
||||
$notes = "release-notes.md"
|
||||
git log -1 --pretty=%B HEAD | Out-File -FilePath $notes -Encoding utf8
|
||||
# Prepend a PRE-BUILT warning to the release body: these artifacts all share
|
||||
# one fixed obfuscation mapping, so an anti-cheat class-name blacklist can
|
||||
# target them. Tell users to self-compile for unique, per-build random names.
|
||||
# Build the banner as a string array (one line each) to avoid PowerShell
|
||||
# here-string column-0 terminator issues inside a YAML block scalar.
|
||||
$warn = @(
|
||||
'> ⚠️ **这是预构建版本(PRE-BUILT)**'
|
||||
'>'
|
||||
'> 本 Release 里的 `OpenZenLoader.exe` / `OpenZen-*.jar` 是 GitHub Actions 编译的成品,**所有人下载到的是同一套混淆类名**。这套固定的名字随时可能被反作弊(如布吉岛)收录进**类名黑名单**而失效。'
|
||||
'>'
|
||||
'> 想要一套**独一无二、别人都不知道**的类名,请**自己编译**(每次构建都会生成全新随机类名):'
|
||||
'> - **Fork 本仓库**,在你自己的 GitHub Actions 里跑 `Build Loader` 工作流,下载你自己的 artifact;**或**'
|
||||
'> - **clone 到本地**自己 `gradlew jar` / `gradlew dll`。'
|
||||
'>'
|
||||
'> 详见仓库 README 的「编译时类名混淆」。`OpenZen-*-mapping.txt` 是本次构建的反混淆映射(每次构建都不同)。'
|
||||
''
|
||||
'---'
|
||||
''
|
||||
)
|
||||
$warn | Out-File -FilePath $notes -Encoding utf8
|
||||
git log -1 --pretty=%B HEAD | Out-File -FilePath $notes -Encoding utf8 -Append
|
||||
gh release create $tag `
|
||||
--title $title `
|
||||
--notes-file $notes `
|
||||
"build/release/OpenZenLoader-$env:SHA.exe" `
|
||||
"build/release/OpenZen-$env:SHA.jar"
|
||||
"build/release/OpenZen-$env:SHA.jar" `
|
||||
"build/release/OpenZen-$env:SHA-mapping.txt"
|
||||
|
||||
Reference in New Issue
Block a user