Move loader to tools/, bundle in ESXi release archive

- vmkatz_loader.py moved to tools/vmkatz_loader.py
- Release workflow includes the loader in the esxi-x86_64 tar.gz
- Updated README and docs/esxi.md paths
This commit is contained in:
NK
2026-03-25 00:52:57 +01:00
parent f8c72d0ef8
commit 3ed50ef292
4 changed files with 9 additions and 5 deletions
+5 -1
View File
@@ -53,7 +53,11 @@ jobs:
run: |
mkdir -p dist
cp target/${{ matrix.target }}/release/vmkatz dist/vmkatz
tar -C dist -czf vmkatz-${{ github.ref_name }}-${{ matrix.name }}.tar.gz vmkatz
# Include the Python loader in the ESXi musl build
if [ "${{ matrix.name }}" = "esxi-x86_64" ]; then
cp tools/vmkatz_loader.py dist/vmkatz_loader.py
fi
tar -C dist -czf vmkatz-${{ github.ref_name }}-${{ matrix.name }}.tar.gz .
- name: Archive (Windows)
if: runner.os == 'Windows'
+2 -2
View File
@@ -129,8 +129,8 @@ scp target/x86_64-unknown-linux-musl/release/vmkatz root@esxi:/tmp/
When VIB protection (`execInstalledOnly`) is enabled, use the Python loader — no need to disable the setting:
```bash
scp vmkatz_loader.py target/x86_64-unknown-linux-musl/release/vmkatz root@esxi:/tmp/
python3 /tmp/vmkatz_loader.py /tmp/vmkatz /vmfs/volumes/datastore1/MyVM/snapshot.vmsn
scp tools/vmkatz_loader.py target/x86_64-unknown-linux-musl/release/vmkatz root@esxi:/tmp/
python /tmp/vmkatz_loader.py /tmp/vmkatz /vmfs/volumes/datastore1/MyVM/snapshot.vmsn
```
See [docs/esxi.md](docs/esxi.md) for VIB bypass details, VMFS raw device access, and auto-discovery.
+2 -2
View File
@@ -21,13 +21,13 @@ esxcli system settings advanced set -o /User/execInstalledOnly -i 0
## Running with VIB protection enabled
When `execInstalledOnly` is set to 1 (default on ESXi 7.0+), unsigned binaries cannot be executed directly. The included Python loader (`vmkatz_loader.py`) bypasses this by loading vmkatz into anonymous memory pages — ESXi allows `PROT_EXEC` on anonymous mappings while blocking `execve` on unsigned files.
When `execInstalledOnly` is set to 1 (default on ESXi 7.0+), unsigned binaries cannot be executed directly. The included Python loader (`tools/vmkatz_loader.py`, bundled in the ESXi release archive) bypasses this by loading vmkatz into anonymous memory pages — ESXi allows `PROT_EXEC` on anonymous mappings while blocking `execve` on unsigned files.
Python is VIB-signed on all ESXi versions and can execute normally.
```bash
# Upload both files
scp vmkatz_loader.py target/x86_64-unknown-linux-musl/release/vmkatz root@esxi:/tmp/
scp tools/vmkatz_loader.py target/x86_64-unknown-linux-musl/release/vmkatz root@esxi:/tmp/
# Run through the loader (no need to disable execInstalledOnly)
python3 /tmp/vmkatz_loader.py /tmp/vmkatz /vmfs/volumes/datastore1/MyVM/snapshot.vmsn