project log/005

SmartUpdate

A deterministic, vendor-agnostic engine for discovering and managing Windows driver and application updates — built around fail-closed safety rules instead of "find a newer driver and install it."

status: actively in development — not finished software view_source_on_github →

Why I built this

Most "update tools" treat a Windows update as one step: find something newer, install it. I wanted to pull that apart. Knowing what hardware is actually on a machine, where a driver candidate came from, whether it's really compatible, whether its version evidence is trustworthy, whether the package itself is valid, whether installing it was authorized, and whether the install actually worked afterward — those are different questions with different ways of failing. SmartUpdate keeps them separate, and when the evidence for one of those questions is missing, it fails closed rather than guessing.

How it's structured

The intended flow runs through nine distinct stages:

Inventory → Discovery → Candidate normalization → Compatibility matching → Update decision → Risk / intelligence → Acquisition & validation → Installation → Recovery

The first seven stages exist in the current code, though not every source or package type is complete yet. Recovery is kept as its own boundary and currently refuses any unsupported generic rollback rather than pretending it can undo something it can't.

The rules it won't break

A few constraints sit at the center of the design, and they're non-negotiable in the codebase:

Honest status

I'd rather this page undersell the project than oversell it. Here's what's actually working and what's still open:

Implemented

  • • Raw & normalized Windows hardware inventory (versioned JSON)
  • • Deterministic driver matching (hardware/compatible IDs, OS, architecture)
  • • Separate decision and metadata-only intelligence stages
  • • Windows Update Agent discovery via an isolated worker process
  • • HTTPS download policy, hashing, INF & catalog signature validation
  • • Explicit pnputil-based install for validated packages
  • • Application inventory, WinGet discovery, MSI-only install
  • • WPF dashboard with audit trail and JSON export

Research / incomplete

  • • General rollback: no implementation claimed — fails closed as RollbackUnavailable
  • • Microsoft Catalog & Lenovo sources: intentionally unavailable, no endpoint configured
  • • WUA metadata is limited — missing data is never guessed
  • • WinGet install path is report-only; install engine stays MSI-only for now
  • • Real-machine WUA install/signature checks need a disposable elevated Windows box

Repository layout

src/SmartUpdate.Engine Inventory, discovery, matching, decisions, acquisition, installation, recovery, applications, orchestration
src/SmartUpdate.Cli Read-only scan/plan commands plus explicit transaction commands
src/SmartUpdate.Gui WPF presentation layer
src/SmartUpdate.WuaWorker Isolated Windows Update Agent process
tests/SmartUpdate.Engine.Tests Unit & presentation tests using fakes and in-memory providers

Build & run

Requires Windows and the .NET 10 SDK pinned in global.json.

$ dotnet restore SmartUpdate.Engine.sln

$ dotnet build SmartUpdate.Engine.sln --configuration Release

$ dotnet test SmartUpdate.Engine.sln --configuration Release

# read-only commands — never download or install anything

$ dotnet run --project src\SmartUpdate.Cli -- scan

$ dotnet run --project src\SmartUpdate.Cli -- app-scan

$ dotnet run --project src\SmartUpdate.Cli -- plan --output plan.json

Stack

C# .NET 10 WPF Windows Update Agent pnputil WinGet xUnit GitHub Actions CI

The full source, docs, and roadmap are on GitHub.