Hasty Briefsbeta

Bilingual

If somebody tries to hot-patch an already-hot-patched function

2 days ago
  • The hot-patch design only supports one hot-patcher, which is Windows Update; if another patcher attempts to patch an already hot-patched function, it indicates an error.
  • Hot-patching is intended for Windows Update on systems that have opted in, and only functions marked as safe for hot-patching are patched on the fly.
  • If rogue patching is detected, the file is marked as not hot-patchable, requiring a reboot, which negatively impacts customer satisfaction.
  • A race condition exists: a prescan may show functions as safe, but a rogue patch applied after the prescan can leave the system in a half-patched, unrecoverable state.
  • Not all changes are safe for hot-patching; for example, modifications to data structure layout or invariants are not hot-patchable because existing instances would be left in an invalid state.
  • Windows Update manages hot-patching by either checking patch history to update jump targets or verifying that the jump target points into the patch-reserved region.