Built a self-healing WinRE manager for Windows 11 — sharing the failure modes and what I learned about the recovery partition lifecycle


ArthurDurand

Member
Local time
12:51 PM
Posts
9
OS
Windows 11
Hi all,

I've been reading the recovery partition threads here for a while and wanted to share something I built. It's a PowerShell script that manages the Windows Recovery Environment — it repairs broken WinRE registrations, rebuilds winre.wim with the correct drivers, and resizes recovery partitions that have been outgrown by Windows Updates. MIT-licensed, single file.

I built it because three Windows 11-specific failure modes kept breaking machines:

1. 0x80070643 after KB updates. Windows pushes a WinRE update that requires more space than the OEM's recovery partition has. The update fails, and the partition is technically present but undersized by 50–200 MiB. This is the one that generates the most "Windows Update broke my recovery" threads here.

2. Device Encryption on 24H2+. The encryption service claims a newly created partition before the recovery type GUID can be applied. reagentc /enable then refuses with "Windows RE cannot be enabled on a volume with BitLocker Drive Encryption enabled." The machine has a recovery partition, but WinRE cannot use it.

3. VMD storage drivers missing from WinRE. On 12th-gen Intel and later, the recovery image needs the Intel VMD driver to see the OS disk. Without it, Startup Repair and Reset this PC fail with INACCESSIBLE_BOOT_DEVICE.

The script runs idempotently. On a healthy machine it takes a fast path — no WIM mount, no partition touch, no reagentc call. On a broken machine it does a full rebuild: strips the image to zero third-party drivers, injects the correct OEM/VMD recipe, resizes the recovery partition, and re-registers WinRE.

What took the longest to get right:

  • The reagentc /disable → /enable window. Everything that doesn't require a disabled WinRE runs before the disable. A race detector re-reads the registered image immediately before /disable and aborts if Windows Update serviced it during preparation.
  • Target-volume BitLocker policy. reagentc checks the target volume, not C:. The dedicated-partition and enable-only paths don't care about C:'s encryption state. Only the OS-fallback route does.
  • Driver strip normalization. Every rebuild strips the mounted image to zero third-party drivers, proven by re-enumeration, before injecting the current recipe. Otherwise drivers accumulate across rebuild cycles.
Field-verified on:

  • Dell Pro Max 16 (Core Ultra 7) — full rebuild, 64 drivers injected, 1,000 MiB partition rejected as undersized, new 1,100 MiB partition created, reagentc /enable exit 0
  • Two ASUS Vivobooks (both mid-encryption at 91%) — dedicated-partition path completed, new partition not re-claimed by Device Encryption
  • ASUS PRIME H510M-D — fast path, DEDICATED, exit 0
What it doesn't do yet:

  • The strip stage hasn't been exercised against a source image with third-party drivers in production
  • The destructive partition paths are VM-tested but not physical-hardware-tested under the current code
  • A known residual corner: a post-deletion failure on an encrypted C: can leave the machine without a dedicated recovery partition or OS-fallback
Repo is github.com/ArthurJDurand/WinRE-Manager if anyone wants to look at the code. More interested in the failure modes than the tool — if you've hit the KB5034441 class of failures, how are you handling it?
 

My Computer My Computer

At a glance

Windows 11Intel® Core™ i5-11400Samsung 16GB DDR4 3200MHzNvidia GeForce GTX 1660 SUPER
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Custom Built
CPU
Intel® Core™ i5-11400
Motherboard
ASUS PRIME H510M-D
Memory
Samsung 16GB DDR4 3200MHz
Graphics Card(s)
Nvidia GeForce GTX 1660 SUPER
Sound Card
Onboard
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920 * 1080
How about a brief biography in your profile? What is your age and relevant coding experience?
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 26H2 26300.9550AMD Ryzen 7 5825U with Radeon Graphics16GB
    OS
    Windows 11 Pro 26H2 26300.9550
    Computer type
    Laptop
    Manufacturer/Model
    Acemagic LX15PRO
    CPU
    AMD Ryzen 7 5825U with Radeon Graphics
    Motherboard
    BIOS CT_BI_AMI_LX15PRO_AB8139_A-004
    Memory
    16GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 2TB
    Internet Speed
    30 Mbps
    Browser
    Brave
    Antivirus
    Webroot SecureAnywhere Complete beta
  • At a glance

    Windows 11 Pro 23H2 22631.2506Atom N450 1.66GHz2GB
    Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
  • Acer Swift SF114-34 laptop
    OS Windows 11 Pro 26200.8894
    CPU Pentium Silver N6000
    RAM 4GB
    BIOS v1.17
    SSD Samsung 970 EVO Plus SSD 2TB (an upgrade)
I see this

PS C:\Users\Martin> $p = "$env:TEMP\WinRE.ps1"
PS C:\Users\Martin> Invoke-RestMethod -Uri 'https://raw.githubusercontent.com/ArthurJDurand/WinRE-Manager/main/scripts/WinRE.ps1' -UseBasicParsing -OutFile $p
PS C:\Users\Martin> powershell -ExecutionPolicy Bypass -File $p -DryRun
C:\Users\Martin\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 : Atuin requires the PSReadLine module to
be installed.
At line:1 char:1
+ . 'C:\Users\Martin\Documents\WindowsPowerShell\Microsoft.PowerShell_p ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [Write-Error], WriteErrorException
+ FullyQualifiedErrorId : Microsoft.PowerShell.Commands.WriteErrorException,Microsoft.PowerShell_profile.ps1
 

My Computers My Computers

  • At a glance

    Windows 11 Pro 26H2 26300.9550AMD Ryzen 7 5825U with Radeon Graphics16GB
    OS
    Windows 11 Pro 26H2 26300.9550
    Computer type
    Laptop
    Manufacturer/Model
    Acemagic LX15PRO
    CPU
    AMD Ryzen 7 5825U with Radeon Graphics
    Motherboard
    BIOS CT_BI_AMI_LX15PRO_AB8139_A-004
    Memory
    16GB
    Screen Resolution
    1920 x 1080
    Hard Drives
    SSD 2TB
    Internet Speed
    30 Mbps
    Browser
    Brave
    Antivirus
    Webroot SecureAnywhere Complete beta
  • At a glance

    Windows 11 Pro 23H2 22631.2506Atom N450 1.66GHz2GB
    Operating System
    Windows 11 Pro 23H2 22631.2506
    Computer type
    Laptop
    Manufacturer/Model
    HP Mini 210-1090NR PC (bought in late 2009!)
    CPU
    Atom N450 1.66GHz
    Memory
    2GB
    Browser
    Brave
    Antivirus
    Webroot
  • Acer Swift SF114-34 laptop
    OS Windows 11 Pro 26200.8894
    CPU Pentium Silver N6000
    RAM 4GB
    BIOS v1.17
    SSD Samsung 970 EVO Plus SSD 2TB (an upgrade)
I see this

PS C:\Users\Martin> $p = "$env:TEMP\WinRE.ps1"
PS C:\Users\Martin> Invoke-RestMethod -Uri 'https://raw.githubusercontent.com/ArthurJDurand/WinRE-Manager/main/scripts/WinRE.ps1' -UseBasicParsing -OutFile $p
PS C:\Users\Martin> powershell -ExecutionPolicy Bypass -File $p -DryRun
C:\Users\Martin\Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 : Atuin requires the PSReadLine module to
be installed.
At line:1 char:1
+ . 'C:\Users\Martin\Documents\WindowsPowerShell\Microsoft.PowerShell_p ...
+ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+ CategoryInfo : NotSpecified: (:) [Write-Error], WriteErrorException
+ FullyQualifiedErrorId : Microsoft.PowerShell.Commands.WriteErrorException,Microsoft.PowerShell_profile.ps1
Thanks for your valuable feedback!

Please try:
Invoke-RestMethod -Uri 'https://raw.githubusercontent.com/ArthurJDurand/WinRE-Manager/main/scripts/Test-WinRE.ps1' -UseBasicParsing | Invoke-Expression

instead?


I'm fixing the README.md and index.md!
 

My Computer My Computer

At a glance

Windows 11Intel® Core™ i5-11400Samsung 16GB DDR4 3200MHzNvidia GeForce GTX 1660 SUPER
OS
Windows 11
Computer type
PC/Desktop
Manufacturer/Model
Custom Built
CPU
Intel® Core™ i5-11400
Motherboard
ASUS PRIME H510M-D
Memory
Samsung 16GB DDR4 3200MHz
Graphics Card(s)
Nvidia GeForce GTX 1660 SUPER
Sound Card
Onboard
Monitor(s) Displays
Samsung 24"
Screen Resolution
1920 * 1080

Latest Support Threads

Latest Tutorials

Back
Top Bottom