• drdexebtjl 3 hours ago

Interesting framing that hooking functions is considered “rogue” by Microsoft, or something you’re “not authorized” to do, when Microsoft themselves makes the detours library and never framed it like this before.

Also, missing from this explanation: hooks are usually applied per process, from user space. The code pages in a dynamic library are CoW’d from the shared page when you write to them to apply a patch.

Does the Windows Update work similarly, or does it somehow modify the original, shared page, affecting all processes? Does a hook in a single process disable hot patching on the entire system?

• saagarjha 35 minutes ago

Hooking code you don’t own is typically playing with fire. Because Microsoft wrote the code, they’re generally in a better position to understand when it is safe to do so.

• vlovich123 40 minutes ago

What happens if two consecutive updates try to hot patch the same function? Wouldn’t this be completely within the realm of possibility and be a pure Microsoft issue with no one else involved?

• jonhohle 4 hours ago

At a previous job I wrote a docker build for patching individual Java class files on top of a monolithic docker image. This was not runtime patching, but allowed a single layer that was only a few kilobytes to be deployed quickly in emergency situations.

Interestingly, it had similar constraints and checked them at build time: it could not be a public ABI change and only one patch at a time.

• itintheory 2 hours ago

Was it for the log4shell vulnerability? I did something similar there.

• fsfod 4 hours ago

Windows parallel DLL loading also defensively disables itself for a process if it finds some NT DLL functions have been hooked https://stackoverflow.com/questions/42789199/why-there-are-t...

• Dwedit 2 hours ago

Detouring can be done for already detoured functions. Just look at Steam Overlay vs other systems that hook into Direct3D, they can coexist.

• fragmede 4 hours ago

The world could use more hot patching. Now that AI upends computer security, getting software patched in a timely fashion is more important than ever, and having to reboot/restart the process or computer to get those updates is more of a problem than it was before.

• Firerouge 2 hours ago

Agreed, it would be nice if it was more straightforward to set up self hosted hot patching on arbitrary Linux distros

• traverseda an hour ago

Super easy to override software on nixos.

• CoastalCoder 4 hours ago

I genuinely cannot tell if you're joking.

• fragmede 4 hours ago

I don't understand the joke. My background is worked at Ksplice a long time ago, patching the Linux kernel for security fixes without having to reboot.

• mauvehaus 3 hours ago

It's been at least 20 years, and Microsoft's blogging platform still doesn't support previous/next post links. Makes it goddamn hard to read the prior series about hot patching if it's not at the top of the blog.

• icepush 2 hours ago

There actually used to be links, but they broke every time the blog platform was moved and eventually were taken out.

• arcanemachiner an hour ago

Missed opportunity for Microsoft to rewrite the whole blog in React Native.

• j45 3 hours ago

It’s like mixing two different hot sauces, ymmv.