Interesting framing that hooking functions is considered “rogue” by Microsoft, or something you’re “not authorized” to do, when Microsoft themselves makes the detours library and never framed it like this before.
Also, missing from this explanation: hooks are usually applied per process, from user space. The code pages in a dynamic library are CoW’d from the shared page when you write to them to apply a patch.
Does the Windows Update work similarly, or does it somehow modify the original, shared page, affecting all processes? Does a hook in a single process disable hot patching on the entire system?
jonhohle 3 hours ago [-]
At a previous job I wrote a docker build for patching individual Java class files on top of a monolithic docker image. This was not runtime patching, but allowed a single layer that was only a few kilobytes to be deployed quickly in emergency situations.
Interestingly, it had similar constraints and checked them at build time: it could not be a public ABI change and only one patch at a time.
itintheory 1 hours ago [-]
Was it for the log4shell vulnerability? I did something similar there.
Dwedit 1 hours ago [-]
Detouring can be done for already detoured functions. Just look at Steam Overlay vs other systems that hook into Direct3D, they can coexist.
The world could use more hot patching. Now that AI upends computer security, getting software patched in a timely fashion is more important than ever, and having to reboot/restart the process or computer to get those updates is more of a problem than it was before.
Firerouge 2 hours ago [-]
Agreed, it would be nice if it was more straightforward to set up self hosted hot patching on arbitrary Linux distros
traverseda 37 minutes ago [-]
Super easy to override software on nixos.
CoastalCoder 3 hours ago [-]
I genuinely cannot tell if you're joking.
fragmede 3 hours ago [-]
I don't understand the joke. My background is worked at Ksplice a long time ago, patching the Linux kernel for security fixes without having to reboot.
mauvehaus 2 hours ago [-]
It's been at least 20 years, and Microsoft's blogging platform still doesn't support previous/next post links. Makes it goddamn hard to read the prior series about hot patching if it's not at the top of the blog.
icepush 56 minutes ago [-]
There actually used to be links, but they broke every time the blog platform was moved and eventually were taken out.
arcanemachiner 48 minutes ago [-]
Missed opportunity for Microsoft to rewrite the whole blog in React Native.
j45 3 hours ago [-]
It’s like mixing two different hot sauces, ymmv.
Rendered at 02:09:00 GMT+0000 (Coordinated Universal Time) with Vercel.
Also, missing from this explanation: hooks are usually applied per process, from user space. The code pages in a dynamic library are CoW’d from the shared page when you write to them to apply a patch.
Does the Windows Update work similarly, or does it somehow modify the original, shared page, affecting all processes? Does a hook in a single process disable hot patching on the entire system?
Interestingly, it had similar constraints and checked them at build time: it could not be a public ABI change and only one patch at a time.