Rendered at 06:45:24 GMT+0000 (Coordinated Universal Time) with Cloudflare Workers.
drdexebtjl 7 hours ago [-]
Interesting framing that hooking functions is considered “rogue” by Microsoft, or something you’re “not authorized” to do, when Microsoft themselves makes the detours library and never framed it like this before.
Also, missing from this explanation: hooks are usually applied per process, from user space. The code pages in a dynamic library are CoW’d from the shared page when you write to them to apply a patch.
Does the Windows Update work similarly, or does it somehow modify the original, shared page, affecting all processes? Does a hook in a single process disable hot patching on the entire system?
saagarjha 5 hours ago [-]
Hooking code you don’t own is typically playing with fire. Because Microsoft wrote the code, they’re generally in a better position to understand when it is safe to do so.
drdexebtjl 3 hours ago [-]
It is perfectly safe to hook any code as long as you can guarantee no thread is currently executing the instructions you're replacing.
saagarjha 3 hours ago [-]
Safety means more than torn writes
ack_complete 3 hours ago [-]
They've also used Detours within Windows itself. The auto super resolution (AutoSR) feature works by dxgi.dll detouring specific calls in user32.dll, in-process, to virtualize certain monitor metrics. I found this out because it was broken for a while on Windows 11 ARM64 when it couldn't handle PAC-enabled function prologs and enabling it would just crash programs by corrupting user32 functions.
jonhohle 8 hours ago [-]
At a previous job I wrote a docker build for patching individual Java class files on top of a monolithic docker image. This was not runtime patching, but allowed a single layer that was only a few kilobytes to be deployed quickly in emergency situations.
Interestingly, it had similar constraints and checked them at build time: it could not be a public ABI change and only one patch at a time.
itintheory 6 hours ago [-]
Was it for the log4shell vulnerability? I did something similar there.
dataflow 2 hours ago [-]
If your hotpatching library is competent, then it does everything atomically. Either by suspending all threads first and temporarily resuming them while they're executing any affected instructions, or by just using atomics when possible.
What happens if two consecutive updates try to hot patch the same function? Wouldn’t this be completely within the realm of possibility and be a pure Microsoft issue with no one else involved?
Dwedit 6 hours ago [-]
Detouring can be done for already detoured functions. Just look at Steam Overlay vs other systems that hook into Direct3D, they can coexist.
drdexebtjl 3 hours ago [-]
Any idea of how that's done? In particular, how do multiple systems synchronize the installation of their hooks?
I've made my own hooking library that lets multiple plug-ins hook the same function, but it only works decently because it has this central library synchronizing access.
apple1417 2 hours ago [-]
If you use OBS, a game capture works the same way, it hooks the DirectX (or whatever API) functions to grab the rendered scene directly. It often has issues picking up overlays because there isn't really any synchronisation, just whatever made the last detour fires first. Like the sibling commit says, you can stack detours, it's only an issue for OBS if something that runs after it renders more things to the screen.
There is a setting to make it pick up overlays, which works reasonably well, I'm not entirely sure how it's implemented.
quotemstr 3 hours ago [-]
Detours rewrites instructions at the start of the detoured function. Why should it know or care whether the instructions it's overwriting happen to be ones written by a previous detour? Why would you need to synchronize?
mauvehaus 7 hours ago [-]
It's been at least 20 years, and Microsoft's blogging platform still doesn't support previous/next post links. Makes it goddamn hard to read the prior series about hot patching if it's not at the top of the blog.
icepush 6 hours ago [-]
There actually used to be links, but they broke every time the blog platform was moved and eventually were taken out.
arcanemachiner 5 hours ago [-]
Missed opportunity for Microsoft to rewrite the whole blog in React Native.
fragmede 8 hours ago [-]
The world could use more hot patching. Now that AI upends computer security, getting software patched in a timely fashion is more important than ever, and having to reboot/restart the process or computer to get those updates is more of a problem than it was before.
Firerouge 6 hours ago [-]
Agreed, it would be nice if it was more straightforward to set up self hosted hot patching on arbitrary Linux distros
traverseda 5 hours ago [-]
Super easy to override software on nixos.
CoastalCoder 8 hours ago [-]
I genuinely cannot tell if you're joking.
fragmede 8 hours ago [-]
I don't understand the joke. My background is worked at Ksplice a long time ago, patching the Linux kernel for security fixes without having to reboot.
Also, missing from this explanation: hooks are usually applied per process, from user space. The code pages in a dynamic library are CoW’d from the shared page when you write to them to apply a patch.
Does the Windows Update work similarly, or does it somehow modify the original, shared page, affecting all processes? Does a hook in a single process disable hot patching on the entire system?
Interestingly, it had similar constraints and checked them at build time: it could not be a public ABI change and only one patch at a time.
In which case there is no race condition.
I've made my own hooking library that lets multiple plug-ins hook the same function, but it only works decently because it has this central library synchronizing access.
There is a setting to make it pick up overlays, which works reasonably well, I'm not entirely sure how it's implemented.