c03a977a96
The residual Windows-on-ARM integrity-gate fix added GetNativeSystemInfo as a second "OS-native" probe behind IsWow64Process2. Microsoft documents the opposite behavior: "the API GetNativeSystemInfo also returns emulated processor details when run from an app under emulation." On the exact hosts the probe was added to rescue -- an x64 hermes-setup.exe emulated on an ARM64 Surface -- it therefore reports AMD64, making it a duplicate of the PROCESSOR_ARCHITECTURE rung already below it rather than a fallback for it. Its test only passed because the kernel32 fake was hand-fed ARM64, asserting behavior real Windows does not exhibit. Replace it with GetMachineTypeAttributes, which answers the question the gate actually asks -- "can this host load a PE of machine X?" -- instead of inferring it from an architecture name. It is also the only documented API that reports AMD64-on-ARM64 emulation support. The gate prefers it and falls back to the existing name-based mapping on pre-Windows-11 hosts. The load-bearing half of the previous fix (typing GetCurrentProcess as HANDLE so IsWow64Process2 stops failing ERROR_INVALID_HANDLE) is unchanged. Co-authored-by: xxxigm <xxxigm@users.noreply.github.com> Co-authored-by: Teknium <teknium1@users.noreply.github.com>