Interesting framing that hooking functions is considered “rogue” by Microsoft, or something you’re “not authorized” to do, when Microsoft themselves makes the detours library and never framed it like this before.
Also, missing from this explanation: hooks are usually applied per process, from user space. The code pages in a dynamic library are CoW’d from the shared page when you write to them to apply a patch.
Does the Windows Update work similarly, or does it somehow modify the original, shared page, affecting all processes? Does a hook in a single process disable hot patching on the entire system?
Hooking code you don’t own is typically playing with fire. Because Microsoft wrote the code, they’re generally in a better position to understand when it is safe to do so.
They've also used Detours within Windows itself. The auto super resolution (AutoSR) feature works by dxgi.dll detouring specific calls in user32.dll, in-process, to virtualize certain monitor metrics. I found this out because it was broken for a while on Windows 11 ARM64 when it couldn't handle PAC-enabled function prologs and enabling it would just crash programs by corrupting user32 functions.
At a previous job I wrote a docker build for patching individual Java class files on top of a monolithic docker image. This was not runtime patching, but allowed a single layer that was only a few kilobytes to be deployed quickly in emergency situations.
Interestingly, it had similar constraints and checked them at build time: it could not be a public ABI change and only one patch at a time.
If your hotpatching library is competent, then it does everything atomically. Either by suspending all threads first and temporarily resuming them while they're executing any affected instructions, or by just using atomics when possible.
What happens if two consecutive updates try to hot patch the same function? Wouldn’t this be completely within the realm of possibility and be a pure Microsoft issue with no one else involved?
Any idea of how that's done? In particular, how do multiple systems synchronize the installation of their hooks?
I've made my own hooking library that lets multiple plug-ins hook the same function, but it only works decently because it has this central library synchronizing access.
If you use OBS, a game capture works the same way, it hooks the DirectX (or whatever API) functions to grab the rendered scene directly. It often has issues picking up overlays because there isn't really any synchronisation, just whatever made the last detour fires first. Like the sibling commit says, you can stack detours, it's only an issue for OBS if something that runs after it renders more things to the screen.
There is a setting to make it pick up overlays, which works reasonably well, I'm not entirely sure how it's implemented.
Detours rewrites instructions at the start of the detoured function. Why should it know or care whether the instructions it's overwriting happen to be ones written by a previous detour? Why would you need to synchronize?
Doesn't the Microsoft implementation work by having nop instruction as the first instruction of the function, which can then be patched to a jump to the patched code, that finally jumps back to the original function past the NOP?
Naive implementation of this scheme doesn't allow stacking.
The world could use more hot patching. Now that AI upends computer security, getting software patched in a timely fashion is more important than ever, and having to reboot/restart the process or computer to get those updates is more of a problem than it was before.
I don't understand the joke. My background is worked at Ksplice a long time ago, patching the Linux kernel for security fixes without having to reboot.
It's been at least 20 years, and Microsoft's blogging platform still doesn't support previous/next post links. Makes it goddamn hard to read the prior series about hot patching if it's not at the top of the blog.
Also, missing from this explanation: hooks are usually applied per process, from user space. The code pages in a dynamic library are CoW’d from the shared page when you write to them to apply a patch.
Does the Windows Update work similarly, or does it somehow modify the original, shared page, affecting all processes? Does a hook in a single process disable hot patching on the entire system?
https://en.wikipedia.org/wiki/MinWin
https://techcommunity.microsoft.com/blog/windowsosplatform/o...
Detours like technology is used in API Sets, to redirect legacy DLLS into the new refactored ones.
https://learn.microsoft.com/en-us/windows/win32/apiindex/win...
Interestingly, it had similar constraints and checked them at build time: it could not be a public ABI change and only one patch at a time.
In which case there is no race condition.
I've made my own hooking library that lets multiple plug-ins hook the same function, but it only works decently because it has this central library synchronizing access.
There is a setting to make it pick up overlays, which works reasonably well, I'm not entirely sure how it's implemented.
Naive implementation of this scheme doesn't allow stacking.