Inject Win11 Creator drivers per package instead of one batch (#5048)

* fix(iso): inject drivers per package

Add each root package folder separately so one bad driver cannot fail the rest. The batch form is roughly four times faster. That cost is accepted for one deterministic code path

* Preserve retained nested driver packages

* Discard partial driver injection attempts

* Remove excluded nested driver INFs

---------

Co-authored-by: Chris Titus <contact@christitus.com>
This commit is contained in:
Omar
2026-09-02 12:09:18 -05:00
committed by GitHub
co-authored by Chris Titus
parent cc5e31460b
commit df858c4cd7
5 changed files with 390 additions and 77 deletions
+4 -2
View File
@@ -280,12 +280,14 @@ function Invoke-WinUtilISOModify {
$driversInjected = [ref]$false
Invoke-WinUtilISOScript -ISOContentsDir $isoContents -AutoUnattendXml $autounattendContent -InjectCurrentSystemDrivers $injectDrivers -InstallImagePath $localWim -InstallImageIndex $selectedWimIndex -InstallEditionId $selectedEditionId -Log { param($m) Log $m } -DriversInjected $driversInjected
SetProgress "Preserving install image..." 70
if ($driversInjected.Value) {
SetProgress "Finalizing install image..." 70
Log "Added current-system drivers to $sourceImageFileName index $selectedWimIndex with one mount and commit."
} elseif ($injectDrivers) {
Log "No current-system drivers needed injection into $sourceImageFileName index $selectedWimIndex; install.wim was left unchanged."
SetProgress "Preserving install image..." 70
Log "No current-system drivers were injected into $sourceImageFileName index $selectedWimIndex; install.wim was left unchanged. Review the warning log entries for details."
} else {
SetProgress "Preserving install image..." 70
Log "Preserved the original $sourceImageFileName without mounting, exporting, or modifying it."
}
+88 -23
View File
@@ -28,7 +28,7 @@ function Invoke-WinUtilISOScript {
.PARAMETER DriversInjected
Optional [ref] set to $true only if driver injection actually mounted and committed
install.wim; stays $false if injection was skipped (disabled, or nothing survived filtering).
install.wim; stays $false if injection was skipped or no package was added successfully.
#>
param (
[Parameter(Mandatory)][string]$ISOContentsDir,
@@ -300,17 +300,18 @@ function Invoke-WinUtilISOScript {
$driverExportRoot = Join-Path $env:TEMP "WinUtil_DriverExport_$(Get-Date -Format 'yyyyMMdd_HHmmss')_$(([guid]::NewGuid()).ToString('N').Substring(0, 8))"
$mountDir = Join-Path (Split-Path -Path $ContentRoot -Parent) 'wim_mount'
New-Item -Path $driverExportRoot -ItemType Directory -Force | Out-Null
# %TEMP% can be an 8.3 alias, but Get-ChildItem below reports long paths, so the
# exported folders would not share this prefix unless it is expanded first.
$driverExportRoot = (Get-Item -LiteralPath $driverExportRoot).FullName
$imageMounted = $false
try {
& $Logger "Exporting current system drivers before modifying install.wim..."
$dismLog = Join-Path $env:TEMP "WinUtil_DismDriverExport_$(Get-Date -Format 'yyyyMMdd_HHmmss').log"
$dismProcess = Start-Process -FilePath "dism.exe" -ArgumentList "/online /export-driver /destination:`"$driverExportRoot`" /LogPath:`"$dismLog`"" -Wait -NoNewWindow -PassThru
if ($dismProcess.ExitCode -ne 0) {
throw "dism.exe driver export failed with exit code $($dismProcess.ExitCode)."
}
Invoke-WinUtilISODism -Arguments @('/English', '/Online', '/Export-Driver', "/Destination:$driverExportRoot", "/LogPath:$dismLog") -Operation 'export-driver' | Out-Null
$driverInfs = @(Get-ChildItem -Path $driverExportRoot -Filter '*.inf' -Recurse -File)
$driverInfs = @(Get-ChildItem -LiteralPath $driverExportRoot -Filter '*.inf' -Recurse -File)
if ($driverInfs.Count -eq 0) {
throw 'DISM exported no driver INF files.'
}
@@ -350,8 +351,25 @@ function Invoke-WinUtilISOScript {
# isn't a failure: leave install.wim untouched and continue building the ISO.
& $Logger 'No drivers found to inject: every exported package was excluded (Extension class or stale duplicate). Skipping driver injection; install.wim is unchanged.'
} else {
$excludedFolders = @($driverFolders.Name | Where-Object { $_ -notin $stagedDriverFolders })
foreach ($excludedFolder in $excludedFolders) {
$excludedDriverFolderGroups = @($driverFolders | Where-Object { $_.Name -notin $stagedDriverFolders })
foreach ($excludedDriverFolderGroup in $excludedDriverFolderGroups) {
$excludedFolder = [string]$excludedDriverFolderGroup.Name
$hasRetainedDescendant = [bool]@($stagedDriverFolders | Where-Object {
$_.StartsWith("$excludedFolder\", [System.StringComparison]::OrdinalIgnoreCase)
}).Count
if ($hasRetainedDescendant) {
try {
foreach ($excludedInf in $excludedDriverFolderGroup.Group) {
Remove-Item -LiteralPath $excludedInf.FullName -Force -ErrorAction Stop
}
} catch {
throw "Failed to remove excluded driver INF files from package '$excludedFolder' before injection: $_"
}
& $Logger "Keeping excluded driver package directory '$excludedFolder' because it contains a retained nested package, after removing its excluded INF files."
continue
}
try {
Remove-Item -LiteralPath $excludedFolder -Recurse -Force -ErrorAction Stop
} catch {
@@ -359,25 +377,72 @@ function Invoke-WinUtilISOScript {
}
}
& $Logger "Exported $($stagedDriverFolders.Count) of $($driverFolders.Count) driver packages ($storageCount staged for WinPE, $($excludedFolders.Count) excluded)."
& $Logger "Exported $($stagedDriverFolders.Count) of $($driverFolders.Count) driver packages ($storageCount staged for WinPE, $($excludedDriverFolderGroups.Count) excluded)."
Set-ItemProperty -LiteralPath $InstallImagePath -Name IsReadOnly -Value $false
New-Item -Path $mountDir -ItemType Directory -Force | Out-Null
& $Logger "Mounting install.wim index $InstallImageIndex once for driver injection..."
Invoke-WinUtilISODism -Arguments @('/English', '/Mount-Image', "/ImageFile:$InstallImagePath", "/Index:$InstallImageIndex", "/MountDir:$mountDir") -Operation 'mount' | Out-Null
$imageMounted = $true
& $Logger "Adding all exported drivers to the selected Windows image in one DISM operation..."
Invoke-WinUtilISODism -Arguments @('/English', "/Image:$mountDir", '/Add-Driver', "/Driver:$driverExportRoot", '/Recurse') -Operation 'add-driver' | Out-Null
# Add each package separately so one bad driver cannot fail the rest. Because
# /Recurse covers descendants, only the highest surviving folder in each tree
# needs its own DISM call.
$rootPackageFolders = @($stagedDriverFolders | Where-Object {
$candidate = $_
-not ($stagedDriverFolders | Where-Object { $candidate.StartsWith("$_\", [System.StringComparison]::OrdinalIgnoreCase) })
})
& $Logger 'Committing the driver-only install.wim change...'
Invoke-WinUtilISODism -Arguments @('/English', '/Unmount-Image', "/MountDir:$mountDir", '/Commit') -Operation 'commit' | Out-Null
$imageMounted = $false
& $Logger "Adding $($rootPackageFolders.Count) root driver packages to install.wim."
$remainingDriverFolders = @($rootPackageFolders)
while ($remainingDriverFolders.Count -gt 0) {
& $Logger "Mounting install.wim index $InstallImageIndex for driver injection..."
Invoke-WinUtilISODism -Arguments @('/English', '/Mount-Image', "/ImageFile:$InstallImagePath", "/Index:$InstallImageIndex", "/MountDir:$mountDir") -Operation 'mount' | Out-Null
$imageMounted = $true
$metadataAfter = Get-WinUtilISOWimMetadata -ImagePath $InstallImagePath -Index $InstallImageIndex
Assert-WinUtilISOWimMetadata -Before $metadataBefore -After $metadataAfter
& $Logger 'Driver injection complete; install.wim metadata validation passed.'
$DriversInjected.Value = $true
$failedDriverFolder = $null
foreach ($driverFolder in $remainingDriverFolders) {
$driverName = $driverFolder
if ($driverFolder.StartsWith($driverExportRoot, [System.StringComparison]::OrdinalIgnoreCase)) {
$driverName = $driverFolder.Substring($driverExportRoot.Length).TrimStart('\')
}
try {
Invoke-WinUtilISODism -Arguments @('/English', "/Image:$mountDir", '/Add-Driver', "/Driver:$driverFolder", '/Recurse') -Operation "add-driver:$driverName" | Out-Null
} catch {
& $Logger "Warning: failed to add driver package '$driverName': $_"
$failedDriverFolder = $driverFolder
break
}
}
if (-not $failedDriverFolder) {
break
}
& $Logger "Discarding the potentially partial install.wim mount before continuing without '$driverName'."
try {
Invoke-WinUtilISODism -Arguments @('/English', '/Unmount-Image', "/MountDir:$mountDir", '/Discard') -Operation 'discard' | Out-Null
$imageMounted = $false
} catch {
throw "Failed to discard the potentially partial install.wim mount after driver package '$driverName' failed: $_"
}
$remainingDriverFolders = @($remainingDriverFolders | Where-Object { $_ -ne $failedDriverFolder })
}
$addedCount = $remainingDriverFolders.Count
if ($addedCount -eq 0) {
# Boot-storage drivers staged for WinPE remain available to Windows Setup.
& $Logger "Warning: none of the $($rootPackageFolders.Count) exported driver packages could be added; continuing with an unmodified install.wim."
} else {
& $Logger "Added $addedCount of $($rootPackageFolders.Count) driver packages to install.wim."
& $Logger 'Committing the driver-only install.wim change...'
Invoke-WinUtilISODism -Arguments @('/English', '/Unmount-Image', "/MountDir:$mountDir", '/Commit') -Operation 'commit' | Out-Null
$imageMounted = $false
$metadataAfter = Get-WinUtilISOWimMetadata -ImagePath $InstallImagePath -Index $InstallImageIndex
Assert-WinUtilISOWimMetadata -Before $metadataBefore -After $metadataAfter
& $Logger 'Driver injection complete; install.wim metadata validation passed.'
$DriversInjected.Value = $true
}
}
} finally {
if ($imageMounted -or (Test-WinUtilISOMountedImage -Path $mountDir)) {
@@ -387,8 +452,8 @@ function Invoke-WinUtilISOScript {
& $Logger "Warning: could not discard the failed install.wim mount: $_"
}
}
Remove-Item -Path $mountDir -Recurse -Force -ErrorAction SilentlyContinue
Remove-Item -Path $driverExportRoot -Recurse -Force -ErrorAction SilentlyContinue
Remove-Item -LiteralPath $mountDir -Recurse -Force -ErrorAction SilentlyContinue
Remove-Item -LiteralPath $driverExportRoot -Recurse -Force -ErrorAction SilentlyContinue
}
}