Full Unlock sources are public
How it worked
WP7 verifies every module before it loads. When an app wants something protected, the OS asks a policy engine. Full Unlock replaced both of them and hid the replacement.
- clkflt is a file-system filter. When the OS opens a stock system module, clkflt serves a patched copy instead. The modified files stay hidden from the kernel, so Windows Update kept working. It also caches file contents in memory, which made the phone a bit faster.
- ulv stands in for
\Windows\mslvmod.dll, the loader verifier. It calls the original and then overrides the verdict. Every module gets permission to execute. - upl stands in for the policy engine. If the caller’s account is privileged, the request passes. If not, upl denies it and posts a record to a message queue.
- uplhlp reads that queue and shows a toast that offers to unlock the app.
- accman moves accounts into the privileged group. It takes the list from
HKLM\Software\OEM\Accman. AFULL_TRUSTvalue there opens the whole system to every app. - StringLoader is a small library that loads localized strings for uplhlp.
I described the whole chain in detail back in 2014: How it works: Full Unlock (in English) and Как это работает: Full Unlock (in Russian). In 2019 I gave a talk on the same topic at SPISOK-2019: Windows Phone 7 full unlock architecture.
Building it
You need Visual Studio 2008, the Windows Mobile 6 Professional SDK and the WP7 SDK. Every project targets ARMv4I. constellation-wp7 is a workspace: basis install clones all six components side by side.
Microsoft ended WP7 support in 2014, so the code is here for reading. The project pages on this site now link to the sources: Cloaking Filter, LoaderVerifier, uPolicyEngine, Account Manager.