{"id":1053,"date":"2014-05-07T07:00:00","date_gmt":"2014-05-07T07:00:00","guid":{"rendered":"https:\/\/blogs.msdn.microsoft.com\/oldnewthing\/2014\/05\/07\/why-does-saving-a-file-in-notepad-fire-multiple-findfirstchangenotification-events\/"},"modified":"2014-05-07T07:00:00","modified_gmt":"2014-05-07T07:00:00","slug":"why-does-saving-a-file-in-notepad-fire-multiple-findfirstchangenotification-events","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/oldnewthing\/20140507-00\/?p=1053\/","title":{"rendered":"Why does saving a file in Notepad fire multiple FindFirstChangeNotification events?"},"content":{"rendered":"<p>Many people have noticed that the <code>Read&shy;Directory&shy;ChangesW<\/code> and <code>Find&shy;First&shy;Change&shy;Notification<\/code> functions (and therefore their BCL equivalent <code>File&shy;System&shy;Watcher<\/code> and WinRT equivalent <code>Storage&shy;Folder&shy;Query&shy;Result<\/code>) fire multiple <code>FILE_ACTION_MODIFIED<\/code> events when you save a file in Notepad. Why is that?\n Because multiple things were modified.\n Notepad opens the file for writing, writes the new data, calls <code>Set&shy;End&shy;Of&shy;File<\/code> to truncate any excess data (in case the new file is shorter than the old file), then closes the handle. Two things definitely changed, and a third thing might have changed.<\/p>\n<ul>\n<li>The file last-modified time definitely changed. <\/li>\n<li>The file size definitely changed. <\/li>\n<li>The file last-access time might have changed. <\/li>\n<\/ul>\n<p> It&#8217;s therefore not surprising that you got two events, possibly three.\n Remember <a href=\"http:\/\/blogs.msdn.com\/b\/oldnewthing\/archive\/2011\/08\/12\/10195186.aspx\"> the original design goals of the <code>Read&shy;Directory&shy;ChangesW<\/code> function<\/a>: It&#8217;s for letting an application cache a directory listing and update it incrementally. Given these design goals, filtering out redundant notifications in the kernel is not required aside from the performance benefits of reduced chatter. In theory, <code>Read&shy;Directory&shy;ChangesW<\/code> could report a spurious change every 5 seconds, and the target audience for the function would still function correctly (albeit suboptimally).\n Given this intended usage pattern, any consumer of <code>Read&shy;Directory&shy;ChangesW<\/code> needs to accept that any notifications you receive encompass the minimum information you require in order to keep your cached directory information up to date, but it can contain <i>extra<\/i> information, too. If you want to respond only to actual changes, you need to compare the new file attributes against the old ones.<\/p>\n<p> <b>Bonus chatter<\/b>: Actually, the two things that changed when Notepad set the file size are <a href=\"http:\/\/msdn.microsoft.com\/en-us\/library\/windows\/hardware\/ff545855(v=vs.85).aspx\"> the allocation size and the file size<\/a> (which you can think of as the physical and logical file sizes, respectively). Internally, this is done by two separate calls into the I\/O manager, so it generates two change notifications. <\/p>\n","protected":false},"excerpt":{"rendered":"<p>Many people have noticed that the Read&shy;Directory&shy;ChangesW and Find&shy;First&shy;Change&shy;Notification functions (and therefore their BCL equivalent File&shy;System&shy;Watcher and WinRT equivalent Storage&shy;Folder&shy;Query&shy;Result) fire multiple FILE_ACTION_MODIFIED events when you save a file in Notepad. Why is that? Because multiple things were modified. Notepad opens the file for writing, writes the new data, calls Set&shy;End&shy;Of&shy;File to truncate any excess [&hellip;]<\/p>\n","protected":false},"author":1069,"featured_media":111744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[25],"class_list":["post-1053","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-oldnewthing","tag-code"],"acf":[],"blog_post_summary":"<p>Many people have noticed that the Read&shy;Directory&shy;ChangesW and Find&shy;First&shy;Change&shy;Notification functions (and therefore their BCL equivalent File&shy;System&shy;Watcher and WinRT equivalent Storage&shy;Folder&shy;Query&shy;Result) fire multiple FILE_ACTION_MODIFIED events when you save a file in Notepad. Why is that? Because multiple things were modified. Notepad opens the file for writing, writes the new data, calls Set&shy;End&shy;Of&shy;File to truncate any excess [&hellip;]<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/1053","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/users\/1069"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/comments?post=1053"}],"version-history":[{"count":0,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/1053\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media\/111744"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media?parent=1053"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/categories?post=1053"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/tags?post=1053"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}