hn.today

If somebody tries to hot-patch an already-hot-patched function

devblogs.microsoft.com42 points14 comments
Screenshot of If somebody tries to hot-patch an already-hot-patched function

Hot-patching on Windows uses reserved code space so Windows Update can replace function bodies on the fly; it’s supported primarily for server SKUs and newer enterprise desktops. The mechanism is intentionally single-owner: only Windows Update is authorized to write into the hot-patch area, and only functions marked as “safe for hot-patching” (no incompatible layout or invariant changes) are eligible. This simplifies design because the updater need not coordinate with arbitrary third-party patchers.

When the hot-patch logic finds evidence of an unexpected or “rogue” patch, it marks the file as not hot-patchable and falls back to requiring a reboot. A race between the prescan and the actual patching can lead to a half-applied update if another agent tampers with a function after the prescan, leaving an in-memory binary in an inconsistent state that can’t be reliably rolled back. The upshot is that applications that opportunistically use the hot-patch space risk breaking official updates and forcing reboots or crashes; hot-patching is a controlled facility meant only for the authorized update path.

Read on devblogs.microsoft.com14 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Security

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.