{"id":112755,"date":"2026-10-05T07:00:00","date_gmt":"2026-10-05T14:00:00","guid":{"rendered":"https:\/\/devblogs.microsoft.com\/oldnewthing\/?p=112755"},"modified":"2026-10-05T21:56:49","modified_gmt":"2026-10-06T04:56:49","slug":"20261005-00","status":"publish","type":"post","link":"https:\/\/devblogs.microsoft.com\/oldnewthing\/20261005-00\/?p=112755\/","title":{"rendered":"If somebody tries to hot-patch an already-hot-patched function, how do they avoid conflicts?"},"content":{"rendered":"<p>For the past few days, I did a quick survey of hot-patching mechanisms. But the hot-patch design accommodates only one hot-patcher. If somebody goes to hot-patch a function and finds that it&#8217;s already been hot-patched, what happens?<\/p>\n<p>If somebody goes to hot-patch a function and finds that it&#8217;s already been hot-patched, then something has gone wrong.<\/p>\n<p>The intended audience of hot-patching is Windows Update on systems that support hot-patching (as of this writing, <a href=\"https:\/\/learn.microsoft.com\/en-us\/windows-server\/get-started\/hotpatch\"> Windows Server<\/a> and more recently <a href=\"https:\/\/techcommunity.microsoft.com\/blog\/windows-itpro-blog\/hotpatch-for-windows-client-now-available\/4399808\"> Windows 11 Enterprise<\/a>, as far as I can tell). The idea is that when a Windows Update arrives, and the administrator has opted into hot-patching, and a file in the update is marked as &#8220;safe for hot-patching&#8221;,\u00b9 then Windows Update will use the space reserved for hot-patching to replace the affected functions on the fly.<\/p>\n<p>Since the only code authorized to use the hot-patch space is Windows Update, the system doesn&#8217;t have to deal with the case that the function has already been hot-patched by somebody else. There is no other code authorized to be somebody else!<\/p>\n<p>But what if the function has been detoured or otherwise patched by somebody not authorized to do so?<\/p>\n<p>My reading of the hot-patching code suggests that if the hot-patch code detects rogue patching, it declares the file to be not hot-patchable, and the system will have to reboot. (This tends to make customers unhappy.)<\/p>\n<p>There is a race condition: The prescan may show that all the functions are safe to patch, but then somebody might patch a function <i>after<\/i> the prescan completes. In that case, the patcher will get halfway through and then discover the rogue-patched function, and now it&#8217;s kind of stuck. It can&#8217;t continue forward, and it can&#8217;t reliably roll back (because the rollback is probably also going to fail because the patch got overpatched). You&#8217;re stuck with a binary in memory that is half-patched, and who knows what&#8217;ll happen now.<\/p>\n<p>An application that uses the hot-patching space is parking in a fire zone. Everything seems to be fine until the fire truck shows up, and then somebody&#8217;s house burns to the ground because the fire truck can&#8217;t get there.<\/p>\n<p><b>Related reading<\/b>: <a title=\"Application compatibility layers are there for the customer, not for the program\" href=\"https:\/\/devblogs.microsoft.com\/oldnewthing\/20100311-00\/?p=14643\"> Application compatibility layers are there for the customer, not for the program<\/a>.<\/p>\n<p>\u00b9 Not all changes are safe for hot-patching, For example, if it changes a data structure&#8217;s layout or invariants, it isn&#8217;t hot-patchable because any instances of the data structure that were created before the hot-patch will not be in a legal state after the hot-patch.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Hot-patching is for Windows, not for you.<\/p>\n","protected":false},"author":1069,"featured_media":111744,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[25],"class_list":["post-112755","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-oldnewthing","tag-code"],"acf":[],"blog_post_summary":"<p>Hot-patching is for Windows, not for you.<\/p>\n","_links":{"self":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/112755","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/users\/1069"}],"replies":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/comments?post=112755"}],"version-history":[{"count":1,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/112755\/revisions"}],"predecessor-version":[{"id":112756,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/posts\/112755\/revisions\/112756"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media\/111744"}],"wp:attachment":[{"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/media?parent=112755"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/categories?post=112755"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/devblogs.microsoft.com\/oldnewthing\/wp-json\/wp\/v2\/tags?post=112755"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}