If somebody tries to hot-patch an already-hot-patched function
2 days ago
- The hot-patch design only supports one hot-patcher, which is Windows Update; if another patcher attempts to patch an already hot-patched function, it indicates an error.
- Hot-patching is intended for Windows Update on systems that have opted in, and only functions marked as safe for hot-patching are patched on the fly.
- If rogue patching is detected, the file is marked as not hot-patchable, requiring a reboot, which negatively impacts customer satisfaction.
- A race condition exists: a prescan may show functions as safe, but a rogue patch applied after the prescan can leave the system in a half-patched, unrecoverable state.
- Not all changes are safe for hot-patching; for example, modifications to data structure layout or invariants are not hot-patchable because existing instances would be left in an invalid state.
- Windows Update manages hot-patching by either checking patch history to update jump targets or verifying that the jump target points into the patch-reserved region.