Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
15 changes: 8 additions & 7 deletions docs/architecture/current.md
Original file line number Diff line number Diff line change
Expand Up @@ -173,13 +173,14 @@ Start-GodBrain. Never logout, `--reset`, or uninstall Tailscale. Start/Heal
skip the mouth while CS2 is running or has been gone under 10 minutes.

`godbrain_core/reclaim11/` is a WPF kit (Reclaim11), not Heal and not
Galaxy. Pack A = Defender / PPL / Sense / AppID. Prep media is a WinPE ISO
(`scripts\New-Reclaim11WinPeIso.ps1`, ADK 10.1.26100.2454) that **deletes**
named catalog `.sys` (never a usermode EXE over a driver, never `Wd*.sys`).
`WdBoot` is refused when Secure Boot is on or n/a. GUI Safe cleanse is
move-only (`restore.json`). Killing blows (IFEO + `sc delete` pack A) require
that receipt and **refuse IoTEnterpriseS**. Never BFE / `mpssvc` / `FltMgr`.
VMware ISO before a physical USB. Check: `scripts\Test-Reclaim11.ps1`.
Galaxy. Pack A = Defender / PPL / Sense / AppID. `WdBoot` stub is refused
when Secure Boot is on. Prep media is a WinPE ISO (`scripts\New-Reclaim11WinPeIso.ps1`,
ADK 10.1.26100.2454) that **parks** catalog `.sys` (does not copy a
usermode EXE over a driver), stubs usermode images, and writes
`Windows\reclaim11-winpe.log` plus `C:\reclaim11\`. Killing blows (IFEO +
`sc delete` pack A) require that receipt.
Never BFE / `mpssvc` / `FltMgr`. VMware ISO before a
physical USB. Check: `scripts\Test-Reclaim11.ps1` on a VM.

## Also in the tree, not the Jarvis path

Expand Down
16 changes: 10 additions & 6 deletions godbrain_core/reclaim11/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -117,14 +117,16 @@ Rx/Tx **256–512**. Skips VMware host VMnet / Tailscale / Wi-Fi.
`hypervisorlaunchtype Auto`, `vsmlaunchtype Off`, `sos No`,
`useplatformclock No`, `useplatformtick No`, `disabledynamictick Yes`;
`{bootmgr}` `bootmenupolicy Legacy`. HKLM
`GlobalTimerResolutionRequests=1`, `SystemResponsiveness=0`,
`GlobalTimerResolutionRequests=1`, `SystemResponsiveness=10`,
`Win32PrioritySeparation=38`. On the **active** plan (and High
Performance if it exists): USB selective suspend Off, USB 3 link
power Off, PCIe ASPM Off. Does **not** switch the plan, does **not**
set min processor 100%, does **not** disable C-states. AGGRO
(`61329e62`) and Ultimate (`e9a42b02`) refused — those were the
+idle-heat cooks. High Performance as a 24/7 plan stays out
(Start-CS2). `restore.json` first. Desk (IoTEnterpriseS) refused.
power Off, PCIe ASPM Off. The GUI **asks** before switching the
active plan to High Performance (Yes = `/setactive` that GUID;
No = bake HP settings but keep the current plan). CLI needs
`-SwitchHighPerformance`. Does **not** set min processor 100%,
does **not** disable C-states. AGGRO (`61329e62`) and Ultimate
(`e9a42b02`) refused — those were the +idle-heat cooks.
`restore.json` first.
WinPE MiniNT refused (that would be the PE BCD).
`pwsh -File latency_bake.ps1 -T`. Restore:
`pwsh -File latency_bake.ps1 -Restore restore.json`.
Expand All @@ -135,6 +137,8 @@ SYSTEM and skips that hop.

### From this repo

Run `Test-Reclaim11.ps1` on a VM. Not physical hardware.

```text
godbrain_core\reclaim11\Reclaim11.cmd
pwsh -NoProfile -File godbrain_core\reclaim11\ps1\Reclaim11.ps1 -T
Expand Down
2 changes: 1 addition & 1 deletion godbrain_core/reclaim11/brave-policy/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -17,7 +17,7 @@ Rewards, Wallet, VPN, Talk, News, Leo, P3A, metrics, Tor, stats ping:
**off**. Home button off (`ShowHomeButton=0`). Safe Browsing stays on.
Download warnings stay on.

Shields (GPO, from the desk profile — not a 40-click Settings tour):
Shields (GPO, curated Shields, not a 40-click Settings tour):

| Setting | Value |
|---|---|
Expand Down
2 changes: 1 addition & 1 deletion godbrain_core/reclaim11/brave-policy/SOURCE.txt
Original file line number Diff line number Diff line change
Expand Up @@ -9,5 +9,5 @@ Fetched 2026-09-02:
windows/examples/brave.reg (ALL policies with SAMPLE values — do not import whole)

Home: Brave documents registry because gpedit is not on Home.
Reclaim11 lockdown.reg is a curated subset (bloat + desk Shields), HKLM+HKCU.
Reclaim11 lockdown.reg is a curated subset (bloat + Shields), HKLM+HKCU.
Local cache (outside git): C:\nvme\godbrain-hf-raw\brave-policy-templates\
2 changes: 1 addition & 1 deletion godbrain_core/reclaim11/brave-policy/lockdown.reg
Original file line number Diff line number Diff line change
Expand Up @@ -22,7 +22,7 @@ Windows Registry Editor Version 5.00
"BravePlaylistEnabled"=dword:00000000
"ShowHomeButton"=dword:00000000

; Shields defaults from the operator's current Brave (desk). Aggressive
; Shields defaults from a curated Brave profile. Aggressive
; vs Standard adblock is not in ADMX; BlockAds is the GPO equivalent.
"DefaultBraveAdblockSetting"=dword:00000002
"DefaultBraveHttpsUpgradeSetting"=dword:00000003
Expand Down
20 changes: 16 additions & 4 deletions godbrain_core/reclaim11/ps1/Reclaim11.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -314,9 +314,9 @@ $btnRun.Add_Click({
"Reclaim11") | Out-Null
return
}
$warn = "Run the ticked actions on THIS Windows. restore.json is written first where it applies. Desk/IoT is refused. Continue?"
$warn = "Run the ticked actions on THIS Windows. restore.json is written first where it applies. Continue?"
if ($doReaper) {
$warn = "Send Grim Reaper on THIS Windows. WU/Medic/USO die. Defender trees stub+DACL. After PE. Desk refused. Continue?"
$warn = "Send Grim Reaper on THIS Windows. WU/Medic/USO die. Defender trees stub+DACL. After PE. Continue?"
}
$q = [System.Windows.MessageBox]::Show(
$warn,
Expand Down Expand Up @@ -367,7 +367,19 @@ $btnRun.Add_Click({
}
if ($doLatency) {
try {
$plan = Invoke-Reclaim11LatencyBake -Root $here
$switchHp = $false
$hpOffer = Get-Reclaim11LatencyHighPerformanceOffer
if ($hpOffer.listed -and -not $hpOffer.already_active) {
$hpQ = [System.Windows.MessageBox]::Show(
"Recommended: switch the active power plan to High Performance.`n`nUSB selective suspend, USB 3 link power, and PCIe ASPM are written onto High Performance and onto the current plan either way. Switch now?",
"Reclaim11 High Performance",
"YesNo",
"Question")
$switchHp = ($hpQ -eq "Yes")
} elseif (-not $hpOffer.listed) {
Add-Log "High Performance plan not listed; baking the active plan only."
}
$plan = Invoke-Reclaim11LatencyBake -Root $here -SwitchHighPerformance:$switchHp
Add-Log ("latency bake applied {0}" -f (@($plan.applied).Count))
Add-Log ("manifest {0}" -f $plan.manifest_path)
} catch {
Expand Down Expand Up @@ -504,7 +516,7 @@ $btnNoobTest.Add_Click({
$btnNoobFix.Add_Click({
if ($script:ProcessRunning) { return }
$q = [System.Windows.MessageBox]::Show(
"TEST already listed Xbox + telemetry. This RUNS them on THIS Windows. restore.json first. Not Grim Reaper. Desk/IoT refused. Continue?",
"TEST already listed Xbox + telemetry. This RUNS them on THIS Windows. restore.json first. Not Grim Reaper. Continue?",
"Reclaim11 JUST FIX MY SH*T",
"YesNo",
"Warning")
Expand Down
21 changes: 1 addition & 20 deletions godbrain_core/reclaim11/ps1/grim_reaper.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -665,15 +665,6 @@ if ($SelfTest) {
return
}

function Test-Reclaim11ReaperDeskHost {
# Inline EditionID. Do not dotsource inventory.ps1 (StrictMode/Stop).
$n = Get-ItemProperty -LiteralPath "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion" -ErrorAction SilentlyContinue
if (-not $n) { return $null }
$prop = $n.PSObject.Properties["EditionID"]
if (-not $prop) { return $null }
[string]$prop.Value -eq "IoTEnterpriseS"
}

function Test-Reclaim11ReaperWinPeReceipt {
# Inline JSON id. Do not dotsource inventory.ps1 (StrictMode/Stop).
$root = $env:SystemRoot
Expand All @@ -695,17 +686,10 @@ function Test-Reclaim11ReaperWinPeReceipt {
$false
}

$desk = Test-Reclaim11ReaperDeskHost
$hasReceipt = Test-Reclaim11ReaperWinPeReceipt
$wd = Join-Path $env:SystemRoot "System32\drivers\WdFilter.sys"
$wdPresent = Test-Path -LiteralPath $wd
if (-not $WhatIf) {
if ($null -eq $desk) {
throw "Refuse: cannot read EditionID (needed to refuse desk)"
}
if ($desk) {
throw "Refuse: desk (IoTEnterpriseS). Grim Reaper is VM-only. Not M1ABRAMS."
}
if (-not $hasReceipt) {
throw "Refuse: no WinPE receipt. Boot the Reclaim11 WinPE ISO first."
}
Expand All @@ -716,7 +700,6 @@ if (-not $WhatIf) {

if ($WhatIf) {
Write-Host "TEST ONLY (DeviceCleanupCmd -t). mutate=false." -ForegroundColor Yellow
Write-Host (" desk={0} (IoTEnterpriseS would refuse)" -f $desk)
Write-Host (" winpe_receipt={0}" -f $hasReceipt)
Write-Host (" WdFilter.sys present={0}" -f $wdPresent)
Write-Host (" stub={0} exists={1}" -f $StubPath, (Test-PeMz $StubPath))
Expand All @@ -739,9 +722,7 @@ if ($WhatIf) {
Write-Host " would deltask WindowsUpdate / WaaSMedic / UpdateOrchestrator (named folders)"
Write-Host (" would hide WU in Settings ({0}; Game Mode stays)" -f (Merge-WipeHidePages -Current "" -Hide $script:WuHidePages))
Write-Host " would SetDisableUXWUAccess=1 (Check for updates on System)"
if ($null -eq $desk) { Write-Host "WOULD REFUSE cannot read EditionID" -ForegroundColor Red }
elseif ($desk) { Write-Host "WOULD REFUSE desk (IoTEnterpriseS)" -ForegroundColor Red }
elseif (-not $hasReceipt) { Write-Host "WOULD REFUSE no WinPE receipt" -ForegroundColor Red }
if (-not $hasReceipt) { Write-Host "WOULD REFUSE no WinPE receipt" -ForegroundColor Red }
elseif ($wdPresent) { Write-Host "WOULD REFUSE WdFilter.sys still present" -ForegroundColor Red }
else { Write-Host "WOULD RUN (after WinPE; named .sys delete, never stub kernel)" -ForegroundColor Green }
return
Expand Down
5 changes: 0 additions & 5 deletions godbrain_core/reclaim11/ps1/inventory.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -5,11 +5,6 @@ param()
Set-StrictMode -Version Latest
$ErrorActionPreference = "Stop"

function Test-Reclaim11DeskHost {
$n = Get-ItemProperty -LiteralPath "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion"
[string]$n.EditionID -eq "IoTEnterpriseS"
}

function Get-Reclaim11Root {
$start = $PSScriptRoot
if ([string]::IsNullOrWhiteSpace($start) -and $MyInvocation.MyCommand.Path) {
Expand Down
12 changes: 1 addition & 11 deletions godbrain_core/reclaim11/ps1/killing_blows.ps1
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
# Pack-A killing blows after a valid WinPE receipt. Never BFE / mpssvc / FltMgr.
# Desk (IoTEnterpriseS) is refused. Not Heal. Not a live wipe of the host.
# Not Heal. Not a live wipe of the running OS without a WinPE receipt.

Set-StrictMode -Version Latest
$ErrorActionPreference = "Stop"
Expand All @@ -14,11 +14,6 @@ function Test-Reclaim11Admin {
$p.IsInRole([Security.Principal.WindowsBuiltInRole]::Administrator)
}

function Test-Reclaim11DeskHost {
$n = Get-ItemProperty -LiteralPath "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion"
[string]$n.EditionID -eq "IoTEnterpriseS"
}

function Test-Reclaim11PackATaskPath {
param($Catalog, [string]$Path)
$p = ([string]$Path).Replace("/", "\").TrimEnd("\")
Expand Down Expand Up @@ -87,16 +82,12 @@ function Invoke-Reclaim11KillingBlows {
throw "Invoke-Reclaim11KillingBlows: pack A lists never-touch $s"
}
}
$desk = Test-Reclaim11DeskHost
$admin = Test-Reclaim11Admin
$receipt = Get-Reclaim11WinPeReceipt
$wd = Join-Path $env:SystemRoot "System32\drivers\WdFilter.sys"
$wdPresent = Test-Path -LiteralPath $wd
$inv = Get-Reclaim11Inventory -Root $Root
$stub = Get-Reclaim11KillingStub -Catalog $cat
if ((-not $WhatIf) -and $desk) {
throw "Refuse: desk (IoTEnterpriseS). Killing blows are VM-only. Not M1ABRAMS."
}
if (-not $WhatIf) {
$el = Resolve-Reclaim11Worker -Name "elevate.ps1" -Root $Root
. $el
Expand Down Expand Up @@ -151,7 +142,6 @@ function Invoke-Reclaim11KillingBlows {
if ($WhatIf) {
$checks = @(
(New-Reclaim11Check -Name "admin" -Ok $admin -Detail "killing blows need TI via admin"),
(New-Reclaim11Check -Name "desk" -Ok (-not $desk) -Detail $(if ($desk) { "IoTEnterpriseS would refuse" } else { "not desk SKU" })),
(New-Reclaim11Check -Name "winpe" -Ok ([bool]$receipt) -Detail $(if ($receipt) { [string]$receipt } else { "no reclaim11-winpe.log" })),
(New-Reclaim11Check -Name "WdFilter" -Ok (-not $wdPresent) -Detail $(if ($wdPresent) { $wd } else { "parked" })),
(New-Reclaim11Check -Name "never_touch" -Ok ([bool]$inv.never_touch_ok) -Detail "BFE/mpssvc RUNNING"),
Expand Down
73 changes: 48 additions & 25 deletions godbrain_core/reclaim11/ps1/latency_bake.ps1
Original file line number Diff line number Diff line change
@@ -1,13 +1,15 @@
# Expert BCD + timer/MMCSS + USB/ASPM bake. restore.json first. Desk refused.
# Expert BCD + timer/MMCSS + USB/ASPM bake. restore.json first.
# Not pack A. Not startnet. Not AGGRO/Ultimate (those kill C-states, +idle heat).
# Not min-processor 100. High Performance switch stays Start-CS2.
# Not min-processor 100. USB/ASPM on active + High Performance if listed.
# GUI asks before /setactive High Performance. CLI needs -SwitchHighPerformance.
# nx AlwaysOff is DEP off — Expert only. MiniNT refused (that is the PE BCD).

[CmdletBinding()]
param(
[string]$Restore = "",
[Alias("T", "Test")]
[switch]$WhatIf
[switch]$WhatIf,
[switch]$SwitchHighPerformance
)

Set-StrictMode -Version Latest
Expand Down Expand Up @@ -39,7 +41,7 @@ $script:RegBake = @(
@{
Path = "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Multimedia\SystemProfile"
Name = "SystemResponsiveness"
Wanted = 0
Wanted = 10 # 0-9 clamp to 20 (stock). 10 is the lowest MMCSS keeps.
},
@{
Path = "HKLM:\SYSTEM\CurrentControlSet\Control\PriorityControl"
Expand Down Expand Up @@ -74,11 +76,6 @@ $script:PowerAcBake = @(
}
)

function Test-Reclaim11LatencyDeskHost {
$n = Get-ItemProperty -LiteralPath "HKLM:\SOFTWARE\Microsoft\Windows NT\CurrentVersion"
[string]$n.EditionID -eq "IoTEnterpriseS"
}

function Test-Reclaim11LatencyPeHost {
Test-Path -LiteralPath "HKLM:\SYSTEM\CurrentControlSet\Control\MiniNT"
}
Expand Down Expand Up @@ -184,6 +181,21 @@ function Test-Reclaim11PowerForbiddenGuid {
@($script:PowerForbiddenGuid | ForEach-Object { $_.ToLowerInvariant() }) -contains $g
}

function Get-Reclaim11LatencyHighPerformanceOffer {
$hp = $script:PowerHighPerfGuid.ToLowerInvariant()
$active = Get-Reclaim11ActivePowerGuid
$listed = @(Get-Reclaim11ListedPowerGuids)
$have = $listed -contains $hp
$activeNorm = if ($active) { $active.ToLowerInvariant() } else { "" }
[pscustomobject]@{
guid = $hp
listed = [bool]$have
already_active = ($have -and ($activeNorm -eq $hp))
active = $active
forbidden = Test-Reclaim11PowerForbiddenGuid $active
}
}

function Get-Reclaim11PowerBakeSchemes {
param([string]$Active)
$listed = @(Get-Reclaim11ListedPowerGuids)
Expand Down Expand Up @@ -224,17 +236,14 @@ function Write-Reclaim11LatencyManifest {
function Invoke-Reclaim11LatencyBake {
param(
[string]$Root,
[switch]$WhatIf
[switch]$WhatIf,
[switch]$SwitchHighPerformance
)
if ([string]::IsNullOrWhiteSpace($Root)) { $Root = $script:Reclaim11Here }
$pe = Test-Reclaim11LatencyPeHost
$desk = Test-Reclaim11LatencyDeskHost
if ($pe -and -not $WhatIf) {
throw "Refuse: WinPE (MiniNT). Latency bake is in-Windows on a VM, not the PE BCD."
}
if ($desk -and -not $WhatIf) {
throw "Refuse: desk (IoTEnterpriseS). Latency bake is VM-only. Not M1ABRAMS."
}
$admin = $false
if (Get-Command Test-Reclaim11Admin -ErrorAction SilentlyContinue) {
$admin = Test-Reclaim11Admin
Expand Down Expand Up @@ -300,16 +309,31 @@ function Invoke-Reclaim11LatencyBake {
$would += ("power {0} {1} {2}->{3}" -f $x.scheme, $x.name, $x.before, $x.wanted)
}
}
$hpOffer = Get-Reclaim11LatencyHighPerformanceOffer
$willSwitchHp = $false
if ($SwitchHighPerformance -and $hpOffer.listed -and -not $hpOffer.already_active -and -not (Test-Reclaim11PowerForbiddenGuid $hpOffer.guid)) {
$willSwitchHp = $true
}
if ($hpOffer.already_active) {
$would += "active already High Performance"
} elseif (-not $hpOffer.listed) {
$would += "High Performance not listed; bake active only"
} else {
$would += "ask High Performance (USB/ASPM baked onto it either way)"
if ($willSwitchHp) {
$would += ("power-active {0}" -f $hpOffer.guid)
} else {
$would += ("keep active {0}" -f $activePower)
}
}

$checks = @(
(New-Reclaim11Check -Name "admin" -Ok $admin -Detail "bcdedit / HKLM needs admin"),
(New-Reclaim11Check -Name "winpe" -Ok (-not $pe) -Detail $(if ($pe) { "MiniNT would refuse (PE BCD)" } else { "not WinPE" })),
(New-Reclaim11Check -Name "desk" -Ok (-not $desk) -Detail $(if ($desk) { "IoTEnterpriseS would refuse" } else { "not desk SKU" })),
(New-Reclaim11Check -Name "power" -Ok (-not $powerForbidden) -Detail $(if ($powerForbidden) { "AGGRO/Ultimate idle-disable" } else { "not AGGRO/Ultimate" }))
)
$refuse = ""
if ($pe) { $refuse = "WinPE (MiniNT)" }
elseif ($desk) { $refuse = "desk (IoTEnterpriseS)" }
elseif (-not $admin) { $refuse = "needs elevation" }
elseif ($powerForbidden) { $refuse = "AGGRO/Ultimate (processor idle disable)" }

Expand All @@ -320,8 +344,10 @@ function Invoke-Reclaim11LatencyBake {
registry = @($regs)
power = @($power)
power_active = $activePower
power_high_performance_listed = [bool]$hpOffer.listed
power_switch_high_performance = [bool]$willSwitchHp
backup_root = $backupRoot
note = "Restore with pwsh -File latency_bake.ps1 -Restore restore.json. Expert. nx AlwaysOff is DEP off. USB/ASPM on AC, not min-processor 100, not C-state kill."
note = "Restore with pwsh -File latency_bake.ps1 -Restore restore.json. Expert. nx AlwaysOff is DEP off. USB/ASPM on AC, not min-processor 100, not C-state kill. High Performance switch is opt-in."
}

if ($WhatIf) {
Expand Down Expand Up @@ -366,12 +392,12 @@ function Invoke-Reclaim11LatencyBake {
$failed += ("power:{0}:{1}:{2}" -f $x.scheme, $x.name, $_.Exception.Message)
}
}
if ($activePower -and -not (Test-Reclaim11PowerForbiddenGuid $activePower)) {
if ($willSwitchHp) {
try {
$null = Invoke-Reclaim11PowerCfg -PowerArgs @("/setactive", $activePower)
$applied += ("power-active:{0}" -f $activePower)
$null = Invoke-Reclaim11PowerCfg -PowerArgs @("/setactive", $hpOffer.guid)
$applied += ("power-active:{0}" -f $hpOffer.guid)
} catch {
$failed += ("power-active:{0}:{1}" -f $activePower, $_.Exception.Message)
$failed += ("power-active:{0}:{1}" -f $hpOffer.guid, $_.Exception.Message)
}
}
$manifest | Add-Member -NotePropertyName applied -NotePropertyValue $applied
Expand All @@ -392,9 +418,6 @@ function Restore-Reclaim11LatencyBackup {
if (Test-Reclaim11LatencyPeHost) {
throw "Refuse: WinPE (MiniNT). Latency restore is in-Windows on a VM, not the PE BCD."
}
if (Test-Reclaim11LatencyDeskHost) {
throw "Refuse: desk (IoTEnterpriseS). Latency restore is VM-only. Not M1ABRAMS."
}
$restored = @()
foreach ($x in @($m.bcd)) {
$before = [string]$x.before
Expand Down Expand Up @@ -445,7 +468,7 @@ if ($MyInvocation.InvocationName -ne ".") {
if (-not [string]::IsNullOrWhiteSpace($Restore)) {
Restore-Reclaim11LatencyBackup -Manifest $Restore | ConvertTo-Json -Depth 6
} else {
$plan = Invoke-Reclaim11LatencyBake -WhatIf:$WhatIf
$plan = Invoke-Reclaim11LatencyBake -WhatIf:$WhatIf -SwitchHighPerformance:$SwitchHighPerformance
if ($WhatIf) {
Write-Host (Format-Reclaim11TestReport -Plan $plan -Title "latency_bake")
}
Expand Down
Loading