registry_manager class provides Windows registry emulation by parsing real registry hive files and supporting runtime modifications through an overlay system.
Overview
This class implements registry functionality by:- Parsing Windows registry hive files (NTUSER.DAT, SOFTWARE, SYSTEM, etc.)
- Providing read access to registry keys and values
- Supporting runtime modifications via an in-memory overlay
- Path normalization and redirection
- Serialization for state persistence
- Type-safe value accessors
Constructors
Default Constructor
Hive Path Constructor
const std::filesystem::path&
Directory containing Windows registry hive files
Destructor
Move Semantics
The class supports move construction and assignment but prohibits copying:Key Operations
get_key
Retrieves a registry key by path.const utils::path_key&
Full registry path (e.g.,
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft)registry_key object if found, or std::nullopt otherwise.
Example:
Value Operations
get_value (by name)
Retrieves a registry value by name.const registry_key&
The registry key containing the value
std::string_view
Name of the value to retrieve (empty string for default value)
registry_value structure if found, or std::nullopt otherwise.
get_value (by index)
Retrieves a registry value by enumeration index.const registry_key&
The registry key containing the value
size_t
Zero-based index of the value to retrieve
std::nullopt if index is out of range.
set_value
Writes a value to the registry overlay (runtime modifications only).const registry_key&
The registry key to write to
std::string
Name of the value to set
uint32_t
Registry value type (REG_SZ, REG_DWORD, etc.)
std::span<const std::byte>
Raw value data
Subkey Operations
get_sub_key_name
Retrieves the name of a subkey by index.const registry_key&
The parent registry key
size_t
Zero-based index of the subkey
std::nullopt otherwise.
Advanced Access
get_hive_key
Retrieves direct access to the underlying hive key structure.const registry_key&
The registry key to expose
exposed_hive_key structure containing:
key: Reference to the internalhive_keystructurefile: Reference to the hive file stream
read_u16string
Reads a UTF-16 string value by index.const registry_key&
The registry key containing the value
size_t
Index of the string value
Serialization
serialize_runtime_state
utils::buffer_serializer&
Output buffer for serialized state
deserialize_runtime_state
utils::buffer_deserializer&
Input buffer containing serialized state
Data Structures
registry_key
Represents a registry key handle.registry_value
Represents a registry value with type-safe accessors.is_dword(): Returnstrueif type isREG_DWORDis_string(): Returnstrueif type isREG_SZ
as_dword(): Converts toDWORDif type matchesas_string(): Converts to UTF-16 string if type matches
Registry Type Constants
Usage Example
Path Normalization
The registry manager automatically handles:- Case-insensitive key and value names
- Path redirection (e.g.,
HKLM→HKEY_LOCAL_MACHINE) - Forward slash to backslash conversion
- Leading/trailing slash removal
Standard Hive Mapping
When initialized with a hive directory, the following files are loaded:SYSTEM→HKEY_LOCAL_MACHINE\SYSTEMSOFTWARE→HKEY_LOCAL_MACHINE\SOFTWARENTUSER.DAT→HKEY_CURRENT_USERSAM→HKEY_LOCAL_MACHINE\SAMSECURITY→HKEY_LOCAL_MACHINE\SECURITY
See Also
- process_context - Uses registry for system configuration
- windows_emulator - Main emulator with registry support
- file_system - Related virtual file system