How Ventoy Detects and Validates the Integrity of an Existing Ventoy Installation
Ventoy uses a layered detection strategy that combines magic-byte verification at offset 0x190, fallback signature matching at offset 0x1B8, and partition offset validation to confirm an existing installation is intact.
When the Ventoy Boot Manager (the "hook") initializes, it must quickly and reliably identify which physical drive contains the Ventoy installation without relying on a single point of failure. According to the ventoy/Ventoy source code, this detection happens in vtoyjump/vtoyjump/vtoyjump.c through a rigorous multi-step validation process that safeguards against corrupted or tampered drives.
Primary Detection via Magic Bytes at Offset 0x190
The first line of defense is a rapid sector scan that looks for a fixed 8-byte magic pattern embedded in the MBR or GPT header.
In vtoyjump/vtoyjump/vtoyjump.c, the CheckVentoyDisk() function enumerates logical drives using GetLogicalDrives(), opens each physical drive (\\.\PhysicalDriveX), and reads the first 512-byte sector into a buffer. It then performs a memcmp at offset 0x190 against the magic sequence {0x56, 0x54, 0x00, 0x47, 0x65, 0x00, 0x48, 0x44} (representing "VT\0G e\0HD"):
static BOOL CheckVentoyDisk(DWORD DiskNum)
{
// ... open \\.\PhysicalDrive<DiskNum> ...
ReadFile(Handle, SectorBuf, sizeof(SectorBuf), &dwSize, NULL);
// Magic = {0x56,0x54,0x00,0x47,0x65,0x00,0x48,0x44} // "VT\0G e\0HD"
if (memcmp(SectorBuf + 0x190, check, 8) == 0) // ← detect Ventoy partition
return TRUE;
return FALSE;
}
This check confirms the drive contains the "VTOYEFI" partition layout and serves as the primary integrity validation. If this signature is present and uncorrupted, Ventoy proceeds with the boot process immediately.
Fallback Detection via Disk Signature at Offset 0x1B8
If the magic-byte check fails—perhaps due to sector layout alterations or unusual partitioning—the system falls back to a secondary 32-bit signature stored in the boot parameters.
During initialization, Ventoy extracts a signature value from g_os_param_reserved[7] through g_os_param_reserved[10] when g_os_param_reserved[6] == 1 (indicating "Ventoy is present"):
if (g_os_param_reserved[6] == 1) // "Ventoy is present"
memcpy(&VtoySig, g_os_param_reserved + 7, 4);
The FindVentoyDiskBySig() function then scans up to 32 physical drives, reading each drive's first sector and comparing the 32-bit value at offset 0x1B8 against the retrieved signature:
static BOOL FindVentoyDiskBySig(UINT32 VtoySig, DWORD* pDiskNum)
{
for (int DiskNum = 0; DiskNum < 32; DiskNum++) {
// … read first sector into SectorBuf …
if (*(UINT32*)(SectorBuf + 0x1B8) == VtoySig) {
*pDiskNum = DiskNum;
return TRUE; // ← signature match
}
}
return FALSE;
}
This signature-based approach provides redundancy when the primary magic bytes are inaccessible or have been overwritten by third-party tools.
Cross-Validation and Partition Offset Verification
The final stage occurs inside the main VentoyHook() function, which orchestrates the validation flow. After identifying a candidate drive through either method, Ventoy performs an additional integrity check: it verifies that the partition starts at the expected 1 MiB offset (VtoyDiskExtent.StartingOffset.QuadPart == SIZE_1MB).
The validation logic follows this precedence:
- Attempt primary detection using
CheckVentoyDisk() - If that fails, attempt signature-based recovery using
FindVentoyDiskBySig() - Validate geometry by confirming the 1MB partition alignment
Only after passing all applicable checks does Ventoy proceed to mount the ISO via VentoyMountISOByAPI() or VentoyMountISOByImdisk(). This multi-layer approach ensures that even if one validation layer is compromised, subsequent checks prevent booting from an invalid or corrupted installation.
Practical Code Examples
The detection functions are implemented as reusable helpers that can be compiled into standalone diagnostic utilities.
Direct Magic-Byte Check
This snippet demonstrates how to scan all physical drives for the Ventoy magic signature:
#include "vtoyjump.h" // declares CheckVentoyDisk
int main(void)
{
for (DWORD i = 0; i < 32; ++i) {
if (CheckVentoyDisk(i)) {
printf("Ventoy detected on PhysicalDrive%u\n", i);
}
}
return 0;
}
Signature-Based Search
This example shows how to locate a Ventoy installation using the boot-parameter signature extracted from g_os_param_reserved:
#include "vtoyjump.h"
int main(void)
{
UINT32 mySig = 0x12345678; // obtain from boot parameters
DWORD disk;
if (FindVentoyDiskBySig(mySig, &disk)) {
printf("Ventoy found via signature on PhysicalDrive%u\n", disk);
} else {
puts("Ventoy not found");
}
return 0;
}
Both examples compile against the existing Ventoy source tree and reuse the internal validation logic found in vtoyjump/vtoyjump/vtoyjump.c.
Summary
- Magic-byte detection at offset 0x190 serves as the primary validation method, checking for the "VT\0G e\0HD" pattern in the first sector.
- Signature-based fallback at offset 0x1B8 provides redundancy when the primary check fails, using a 32-bit value extracted from boot parameters.
- Partition offset verification confirms the installation geometry matches the expected 1MB alignment before proceeding.
- Implementation location: All detection logic resides in
vtoyjump/vtoyjump/vtoyjump.c, specifically withinCheckVentoyDisk(),FindVentoyDiskBySig(), andVentoyHook().
Frequently Asked Questions
What happens if the magic bytes at offset 0x190 are corrupted?
Ventoy automatically falls back to the signature-based detection method. The VentoyHook() function calls FindVentoyDiskBySig() to scan for the 32-bit signature stored at offset 0x1B8, allowing the boot process to continue even if the primary magic-byte header is damaged.
How does Ventoy prevent booting from a drive that merely contains the signature but isn't a valid installation?
The system performs cross-validation by checking the partition offset. Even if a drive contains the correct signature at 0x1B8, Ventoy verifies that VtoyDiskExtent.StartingOffset.QuadPart == SIZE_1MB (1MB alignment). This ensures the drive has the proper Ventoy partition geometry, not just a coincidental signature match.
Where is the Ventoy signature stored during the installation process?
The 32-bit fallback signature is written into the boot parameter block and accessed via the g_os_param_reserved array. Specifically, g_os_param_reserved[6] acts as a presence flag (value 1), while bytes 7 through 10 contain the actual signature value used for disk identification.
Can these detection routines be used in external utilities?
Yes. The functions CheckVentoyDisk() and FindVentoyDiskBySig() are declared in vtoyjump/vtoyjump/vtoyjump.h and can be linked into standalone diagnostic tools to verify Ventoy installations without booting from them.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →