Skip to content

Alchemy September 2026

The following topic describes each component available to upgrade within this release of Cloudhouse Alchemy. For the most recent component versions of Alchemy, see Alchemy Current Component Versions.

AppAcceleratorV (AAV)

The following table outlines each version of AppAcceleratorV (AAV) that has been released this month, alongside the release date.

Note: The table is ordered in reverse chronological order, with the most recent release at the top.

Release Date Version Number
28th September 2026 V4.7.2609.26966
25th September 2026 V4.7.2609.26962
25th September 2026 V4.7.2609.26960

Note: AAV V4.7.2609.26962 changes the format of the AuthenticodeFingerprints.xml file used by the DynamicHooking Compatibility Feature. This is a breaking change. If you maintain your own DynamicHooking callback DLLs and fingerprint file, you must regenerate AuthenticodeFingerprints.xml with the new ExtractFingerprints.ps1 script before using this version of AAV (or any later version). AAV rejects fingerprint files in the previous (version 1) format and logs "Unsupported fingerprint schema version", so callback DLLs fail verification until the file is regenerated. The new AAV binaries and the regenerated fingerprint file must be deployed together. If you cannot regenerate the file immediately, the DisableSignatureVerification Compatibility Feature can be used as a temporary workaround. Packages that do not use custom DynamicHooking callback DLLs are not affected.

New Features

The following new feature is included within this month's release of AAV.

New ProtectPackagedServiceImagePath Compatibility Feature (V4.7.2609.26966)

AAV now includes the ProtectPackagedServiceImagePath Compatibility Feature. The feature is opt-in and is off by default.

Some applications and licensing components that run inside a package attempt to reconfigure a Windows service that runs from the package, repointing the service's ImagePath at a native binary installed on the machine. When this happens, the service no longer runs from the package, and the applications that depend on it can lose access to it. For example, a licensing helper that re-registers a packaged licensing service against its native executable (as FlexNet licensing components can) can break licensing for the other packaged applications that rely on that service.

When ProtectPackagedServiceImagePath is enabled:

  • AAV suppresses attempts made by code running in the package to repoint a packaged service's ImagePath at a native binary. The ImagePath remains unchanged.
  • Any other changes requested in the same call, such as the service's display name or start type, still apply, and the calling application receives the result of the call as normal.
  • Calls that set the ImagePath to the package's own Cloudhouse.Container.Run.exe stub, calls that change services that are not packaged, and calls that do not set an ImagePath are not affected.
  • The feature works with the IncludeFeaturesByProcess and ExcludeFeaturesByProcess settings, so you can limit it to, or exclude it from, specific processes.
  • The feature has no effect when the legacy Service Compatibility Feature is enabled.

Each suppressed change is logged at the INFO level in the Service log category, showing the current and requested ImagePath values. If AAV cannot read the service's current configuration, it allows the change to proceed and logs an error.

Note: For information on enabling a Compatibility Feature, and on limiting it to specific processes, see Enable a Compatibility Feature, Include a Specific Process and Exclude a Specific Process from a Compatibility Package.

Other Enhancements

There are no additional enhancements included within this release of AAV.

Fixed Issues

The following issues have been fixed within this release of AAV.

Release Date Version Number
25th September 2026 V4.7.2609.26962
PPD-5600 – DynamicHooking Callback DLL Signature Verification Fails on Machines in a Different Time Zone
Affects Versions: V4.7.2601.26901 Fix Version: V4.7.2609.26962
Problem: DynamicHooking callback DLL signature verification failed with the error "Failed to verify main signer" on machines whose time zone differed from the time zone of the machine on which the callback DLLs were built and signed.
Cause: AAV identified the signing certificate by comparing the certificate's validity dates as text, and these were formatted using the local time zone. The values recorded when the fingerprints were generated therefore did not match the values calculated on a machine in a different time zone.
Solution: AAV now identifies the signing certificate using a SHA-256 hash of the certificate only. The certificate name, issuer, serial number, validity dates and timestamping certificate are no longer part of the check, so the result no longer depends on the machine's time zone. The AuthenticodeFingerprints.xml file format is now versioned, and AAV expects SchemaVersion="2". A fingerprint entry with an empty value is now rejected instead of being treated as a match. The timestamping certificate is no longer checked, so a callback DLL that is signed but not timestamped no longer fails verification. Note: This is a breaking change. AAV rejects version 1 fingerprint files with the error "Unsupported fingerprint schema version". Regenerate AuthenticodeFingerprints.xml for your callback DLLs using the new ExtractFingerprints.ps1 script, and deploy it together with the new version of AAV. The DisableSignatureVerification Compatibility Feature can be used as a temporary workaround.
Release Date Version Number
25th September 2026 V4.7.2609.26960
PPD-5602 – Application Hangs at Startup Under PackageIsolation When a Directory Listing Coincides with a DLL Load
Affects Versions: V4.7.2608.26947 Fix Version: V4.7.2609.26960
Problem: With the PackageIsolation Compatibility Feature enabled, applications could intermittently hang at startup. This was seen as SOLIDWORKS 2026 hanging, with the splash screen never advancing, on a cold first launch.
Cause: A deadlock occurred between two threads. While AAV was enumerating a directory, it held an internal lock and looked up a system function. At the same moment, another thread in the application was loading a DLL, which holds a Windows loader lock and then needs the same AAV lock to clean up. Each thread waited for the lock held by the other, so neither could continue.
Solution: AAV no longer looks up system functions while holding its directory-merge lock. The functions are now resolved once, when AAV initialises, and before the lock is taken. Directory listings and DLL loads on different threads can no longer block each other, and applications start normally.

Auto Packager

The following table outlines each version of Auto Packager that has been released this month, alongside the release date.

Release Dates Current Version Number AAV Version Number
29th September 2026 V4.7.2609.2 V4.7.2609.26966

New Features

There are no new features included within this month's release of Auto Packager.

Other Enhancements

The following additional enhancement is included within this month's release of Auto Packager.

Updated Component Version

The following component version has been updated:

  • Updated AAV component version to 4.7.2609.26966.

Fixed Issues

No issues have been fixed within this month's release of Auto Packager.