Alchemy September 2026
The following topic describes each component available to upgrade within this release of Cloudhouse Alchemy. For the most recent component versions of Alchemy, see Alchemy Current Component Versions.
AppAcceleratorV (AAV)
The following table outlines each version of AppAcceleratorV (AAV) that has been released this month, alongside the release date.
Note: The table is ordered in reverse chronological order, with the most recent release at the top.
| Release Date | Version Number |
|---|---|
| 28th September 2026 | V4.7.2609.26966 |
| 25th September 2026 | V4.7.2609.26962 |
| 25th September 2026 | V4.7.2609.26960 |
Note: AAV V4.7.2609.26962 changes the format of the AuthenticodeFingerprints.xml file used by the DynamicHooking Compatibility Feature. This is a breaking change. If you maintain your own DynamicHooking callback DLLs and fingerprint file, you must regenerate AuthenticodeFingerprints.xml with the new ExtractFingerprints.ps1 script before using this version of AAV (or any later version). AAV rejects fingerprint files in the previous (version 1) format and logs "Unsupported fingerprint schema version", so callback DLLs fail verification until the file is regenerated. The new AAV binaries and the regenerated fingerprint file must be deployed together. If you cannot regenerate the file immediately, the DisableSignatureVerification Compatibility Feature can be used as a temporary workaround. Packages that do not use custom DynamicHooking callback DLLs are not affected.
New Features
The following new feature is included within this month's release of AAV.
New ProtectPackagedServiceImagePath Compatibility Feature (V4.7.2609.26966)
AAV now includes the ProtectPackagedServiceImagePath Compatibility Feature. The feature is opt-in and is off by default.
Some applications and licensing components that run inside a package attempt to reconfigure a Windows service that runs from the package, repointing the service's ImagePath at a native binary installed on the machine. When this happens, the service no longer runs from the package, and the applications that depend on it can lose access to it. For example, a licensing helper that re-registers a packaged licensing service against its native executable (as FlexNet licensing components can) can break licensing for the other packaged applications that rely on that service.
When ProtectPackagedServiceImagePath is enabled:
- AAV suppresses attempts made by code running in the package to repoint a packaged service's
ImagePathat a native binary. TheImagePathremains unchanged. - Any other changes requested in the same call, such as the service's display name or start type, still apply, and the calling application receives the result of the call as normal.
- Calls that set the
ImagePathto the package's ownCloudhouse.Container.Run.exestub, calls that change services that are not packaged, and calls that do not set anImagePathare not affected. - The feature works with the
IncludeFeaturesByProcessandExcludeFeaturesByProcesssettings, so you can limit it to, or exclude it from, specific processes. - The feature has no effect when the legacy
ServiceCompatibility Feature is enabled.
Each suppressed change is logged at the INFO level in the Service log category, showing the current and requested ImagePath values. If AAV cannot read the service's current configuration, it allows the change to proceed and logs an error.
Note: For information on enabling a Compatibility Feature, and on limiting it to specific processes, see Enable a Compatibility Feature, Include a Specific Process and Exclude a Specific Process from a Compatibility Package.
Other Enhancements
There are no additional enhancements included within this release of AAV.
Fixed Issues
The following issues have been fixed within this release of AAV.
| Release Date | Version Number |
|---|---|
| 25th September 2026 | V4.7.2609.26962 |
PPD-5600 – DynamicHooking Callback DLL Signature Verification Fails on Machines in a Different Time Zone |
|
|---|---|
| Affects Versions: V4.7.2601.26901 | Fix Version: V4.7.2609.26962 |
| Problem: | DynamicHooking callback DLL signature verification failed with the error "Failed to verify main signer" on machines whose time zone differed from the time zone of the machine on which the callback DLLs were built and signed. |
| Cause: | AAV identified the signing certificate by comparing the certificate's validity dates as text, and these were formatted using the local time zone. The values recorded when the fingerprints were generated therefore did not match the values calculated on a machine in a different time zone. |
| Solution: | AAV now identifies the signing certificate using a SHA-256 hash of the certificate only. The certificate name, issuer, serial number, validity dates and timestamping certificate are no longer part of the check, so the result no longer depends on the machine's time zone. The AuthenticodeFingerprints.xml file format is now versioned, and AAV expects SchemaVersion="2". A fingerprint entry with an empty value is now rejected instead of being treated as a match. The timestamping certificate is no longer checked, so a callback DLL that is signed but not timestamped no longer fails verification. Note: This is a breaking change. AAV rejects version 1 fingerprint files with the error "Unsupported fingerprint schema version". Regenerate AuthenticodeFingerprints.xml for your callback DLLs using the new ExtractFingerprints.ps1 script, and deploy it together with the new version of AAV. The DisableSignatureVerification Compatibility Feature can be used as a temporary workaround. |
| Release Date | Version Number |
|---|---|
| 25th September 2026 | V4.7.2609.26960 |
PPD-5602 – Application Hangs at Startup Under PackageIsolation When a Directory Listing Coincides with a DLL Load |
|
|---|---|
| Affects Versions: V4.7.2608.26947 | Fix Version: V4.7.2609.26960 |
| Problem: | With the PackageIsolation Compatibility Feature enabled, applications could intermittently hang at startup. This was seen as SOLIDWORKS 2026 hanging, with the splash screen never advancing, on a cold first launch. |
| Cause: | A deadlock occurred between two threads. While AAV was enumerating a directory, it held an internal lock and looked up a system function. At the same moment, another thread in the application was loading a DLL, which holds a Windows loader lock and then needs the same AAV lock to clean up. Each thread waited for the lock held by the other, so neither could continue. |
| Solution: | AAV no longer looks up system functions while holding its directory-merge lock. The functions are now resolved once, when AAV initialises, and before the lock is taken. Directory listings and DLL loads on different threads can no longer block each other, and applications start normally. |
Auto Packager
The following table outlines each version of Auto Packager that has been released this month, alongside the release date.
| Release Dates | Current Version Number | AAV Version Number |
|---|---|---|
| 29th September 2026 | V4.7.2609.2 | V4.7.2609.26966 |
New Features
There are no new features included within this month's release of Auto Packager.
Other Enhancements
The following additional enhancement is included within this month's release of Auto Packager.
Updated Component Version
The following component version has been updated:
- Updated AAV component version to 4.7.2609.26966.
Fixed Issues
No issues have been fixed within this month's release of Auto Packager.