15 ms·
Git for Windows accidentally creates NTFS alternate data streams
- smhenderson 10y agoThe root cause of all this is a relatively obscure NTFS feature called alternate data streams. Obscure indeed, I've never seen them used for anything other than hiding malicious content. Curious, I read about them on Wikipedia[1] and it turns out they were originally created to support resource forks in Services for Macintosh. Browsers also use them to flag files downloaded from the internet. [1] https://en.wikipedia.org/wiki/NTFS#Alternate_data_streams_.28ADS.29 https://en.wikipedia.org/wiki/NTFS#Alternate_data_streams_.2...
- J_Darnley 10y ago> Browsers also use them to flag files downloaded from the internet. Is that where that annoying shit comes from? Good to know. When firefox kills off DownThemAll I will then use a FAT partition to store downloaded files (and see if I can force the temporary files to go there too).
- icebraining 10y agoUnless it has changed in newer Windows versions, you can simply disable that warning in the Internet Settings, no need to keep files in an outdated filesystem.
- anonymfus 10y ago>use a FAT partition to store downloaded files Do you never download anything bigger than or equal to 4 GiB?
- J_Darnley 10y agoNot from a browser and, AFAIK, only a browser idiotically marks files as coming from the internet.
- mfenniak 10y agoI laugh these days when OSX warns me, "This application was downloaded from the internet." when I first access an app. Every application on my machine was downloaded from the internet. Even the OS, after the first upgrade. That's not what is dangerous.
- ChoGGi 10y agostick this in a reg file REGEDIT4 ;https://support.microsoft.com/en-us/kb/889815 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Environment] "SEE_MASK_NOZONECHECKS"="1" ;https://technet.microsoft.com/en-us/library/cc783259 [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download] "CheckExeSignatures"="no" "RunInvalidSignatures"=dword:00000001 ;https://support.microsoft.com/kb/883260 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Associations] "LowRiskFileTypes"=".zip;.rar;.nfo;.txt;.exe;.bat;.com;.cmd;.reg;.msi;.htm;.html;.gif;.bmp;.jpg;.avi;.mpg;.mpeg;.mov;.mp3;.m3u;.wav;" "DefaultFileTypeRisk"=dword:00001808 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Attachments] "SaveZoneInformation"=dword:00000001
- 2close4comfort 10y agothey should market this as a feature! alternate streams for people who think it is "an obscure feature" I mean that many people using alternate streams would be interesting for anyone forensicating systems for malware or as protection from...
- CoolGuySteve 10y agoiTunes for Windows uses them to store how much of a streaming file it has already downloaded. I wrote it (but I won't take credit for most things in iTunes for Windows) It's a nifty feature but I'll admit NTFS is really obscure at times.
- enjoy-your-stay 10y agoGreat place to store meta data about a file, never thought about that before. I guess if the download stream is interrupted it reads that to know where to pick up again if resumed? Another obscure feature of NTFS is Transactional NTFS which I'd never heard of until recently. https://msdn.microsoft.com/en-us/library/windows/desktop/aa363859(v=vs.85).aspx https://msdn.microsoft.com/en-us/library/windows/desktop/aa3...
- ygra 10y agoWindows even includes mechanisms to perform transactions over different things like file system, registry, and even multiple machines. Back when SVN was horribly slow and implemented transactions by actually touching thousands of small files in the .svn directories, I actually wanted to implement its file system layer on Windows with NTFS transactions, figuring that a native solution would probably be better. But by now they completely changed their working copy format so I don't think it's necessary anymore.
- int_19h 10y agoUnfortunately, transactional NTFS is being deprecated. MSDN says: "Microsoft strongly recommends developers utilize alternative means to achieve your application’s needs. Many scenarios that TxF was developed for can be achieved through simpler and more readily available techniques. Furthermore, TxF may not be available in future versions of Microsoft Windows." Which is a shame, because, conceptually speaking, a true transactional filesystem with snapshot semantics makes some things so much easier.
- flukus 10y agoDo you mean DTC or something else?
- deleted 10y ago[deleted]
- wslh 10y agoThis is used in specific sectors like data loss prevention. For example, you can tag files based on the security sensitiveness and if the file is copied it retains the tags.
- __jal 10y ago> if the file is copied it retains the tags. ...if your miscreant is technically illiterate and only uses NTFS.
- tamana 10y agoIt's metadata. It's as obscure as file permissions bits.
- OJFord 10y agoExcept that millions of developers routinely make use of file permissions; as evidenced by this discussion, many - perhaps even a majority - haven't heard of alternate data streams.
- OJFord 10y agoActually, I'm not going to shy away from it. I'd be willing to bet that a clear majority haven't heard of alternate data streams. There are too many developers who care not for NTFS at all, never mind some little-used feature, for that not to be true.
- tracker1 10y agoI really like NTFS as a file system... seems to offer a lot more than many other file systems, and pretty interestingly so for as old as it is now. That said, hopefully broader adoption can happen when the patents expire (ugh, in 7 years). Maybe the "new" MS could be convinced to create a royalty-free spec release/promise. Would love for NTFS to become default for external storage, I already use it, but getting it on macOS and Linux isn't always as straight forward as it could be. NTFS-3G ftw.
- viraptor 10y agoBut millions of developers also go "I don't get how it works, just make it world-writable". Not sure they understand either.
- _wmd 10y agoHardly obscure, every modern OS has an equivalent feature, but only OSX and Windows unify it with the regular filesystem API. Streams and resource forks are a play on a now-standard UNIX feature that almost nobody uses because it has a shitty non-file based API that also breaks most tools unless they are specifically aware of them: extended attributes. Resource forks and extended attributes are almost equivalent in every single way, except that extended attributes can only be read/written atomically (limiting their size to strings that will fit in RAM), whereas a fork or stream can be opened like a regular file. Stick that in your pipe and smoke it, UNIX sycophants, another case where Windows is more UNIX than UNIX ;) The file-or-directory vagueness created by the hierarchy of resources buried within a file also more closely maps how the most popular path naming scheme on the planet (URLs) work: an URL can always represent both a file and a collection simultaneously, so I see this as closer to an ideal than the alternative where files can have no children at all. Sadly nobody actually uses these APIs like that, because all our tooling sucks so bad at coping with it. I sometimes wonder what the world would look like if directories on popular operating systems had simply been made 0 byte files
- ksherlock 10y agoSolaris unfies it too. You can even use the runat command to open a shell where extended attributes are exposed as and can be manipulated as regular files. http://docs.oracle.com/cd/E23824_01/html/821-1474/fsattr-5.html http://docs.oracle.com/cd/E23824_01/html/821-1474/fsattr-5.h...
- amyjess 10y ago> feature that almost nobody uses because it has a shitty non-file based API that also breaks most tools unless they are specifically aware of them: extended attributes Mind you, OS X makes extensive use of extended attributes in addition to resource forks (and it's largely deprecated resource forks in favor of app folders). Spend some time poking around Siracusa's reviews (since Tiger); he loves to go into detail about every new way Apple makes use of extended attributes. Also, it's not fair to say that almost nobody uses them. Chrome makes use of extended attributes, as does KDE's metadata system and a few other things. > (limiting their size to strings that will fit in RAM) That's an understatement. The Linux kernel API limits the size of all extended attributes to 64KB, and the most popular filesystems limit them further to 4KB. That's not really comparable to a true fork. ZFS is the exception: its extended attributes are implemented as forks, and the maximum size of an extended attribute is the same as that of a file. Unfortunately, those aren't accessible on ZOL because the kernel won't support it, so you can really only take advantage of it on Solaris/Illumos (and maybe FreeBSD?).
- banana_giraffe 10y agoIt's used by all the browsers on Windows these days. They all create a 'Zone.Identifier' stream when a file is downloaded to mark is downloaded. It's content's is what triggers the "You downloaded this file! It's Evil!' warning in Windows. To be fair, it's not used by a ton of things, since it requires NTFS, disappears when files are moved to different filesystems, and various things that read and write files destroy them if they're not careful, not to mention actually enumerating the streams is tricky, last I checked.
- ryanburk 10y agosome history: this was introduced with XP SP2 as part of the windows security push. was a clever way to track the information without touching the binary data directly and supporting it in IE meant the majority of customers saw the benefit right away. and since most people (in windows) don't move files across file systems.
- ams6110 10y agoPeople in windows often move files across file systems: between the internal hard drive (generally NTFS) to external USB drives (often FAT32, or exFAT)
- GirlsCanCode 10y agoExactly! It's amazing how unaware Mac zealots are of other operating systems. They may learn something if they'd shut up and listen.
- Mikhail_Edoshin 10y agoWhen this happens and the file has alternate streams you get a warning that some of the file's attributes cannot be copied.
- banana_giraffe 10y agoI've not seen that warning before. I just tested on a file I downloaded, which had the 'Zone.Identifier' stream. Using Explorer, I copied it to a FAT32 volume, then back to my NTFS drive. Sure enough, it lost the 'Zone.Identifier' stream, and there was no warning when I opened it. This is on a fairly normal Windows 10 installation. YMMV on different versions, of course.
- donatj 10y agoI used them for a VCS thought experiment I was playing with a while ago.
- sixothree 10y agoJust pretend they're "resource forks".
- jahewson 10y agoThere were once plans to store the individual streams which make up Microsoft Office files (OLE2) as alternate data streams, which would have been... interesting.
- Animats 10y agoThe original idea on the Macintosh was to have some place to put non-code assets - icons, images, etc - that came with an application. So MacOS files had a "data fork" and a "resource fork". The "resource fork" was a tree structure managed by the Resource Manager. The problem was that the original Macintosh had limited memory and only a floppy disk, and the implementation of writing to the resource fork wasn't very good. Many programs wrote to their own resource fork for preferences and such. The tree structure wasn't updated fully until the program was closed, because writing to the floppy was so slow. If the program exited abnormally, the resource fork's links were broken. This gave the resource fork approach a bad reputation. Since Windows programs had to run on DOS, which didn't have resource forks, Windows never used this much. Windows put non-code assets in the executable as read-only objects. NT, which was supposed to do everything (originally it had POSIX and OS/2 compatibility, and ran on MIPS, Alpha, and x86) added generalized support for resource forks, just in case. But since most applications were written for Windows 3.1/95/ME, they didn't use those facilities. So that's how we got here.
- zwieback 10y agoIn the early 90's I worked at a company that made server software that allowed Mac AppleTalk (AFP) clients to connect to a PC network. Eventually IBM had us write a custom version for OS/2 called LAN Server for Macintosh. We were really excited about using the streams/resource forks feature but had to give up eventually. We used a separate database to store what's in the resource forks instead.
- kalleboo 10y ago> The tree structure wasn't updated fully until the program was closed, because writing to the floppy was so slow Not to mention in many cases on the original Macs, you probably didn't even have the program floppy in the drive when you were working, because with only 400K on a disk you had to swap to the disk with your document on it. I recall Inside Macintosh had a big disclaimer at the top that warned "The Resource Manager IS NOT A DATABASE". It was originally just meant to handle localizable resources, but since it was already there it was handy for developers (including Apple themselves) to use to load any kind of structured data. And who didn't love going messing around in system and application files with ResEdit?
- jobigoud 10y agoI have used them. We had a system that generated millions of images and needed to be sure that from one version to the next the images produced by a given request were the same, and also have some diagnostic data in case of problematic images. The images could be either JPG or PNG and we needed a unified way to associate arbitrary metadata with them. We had a special mode that would store an equivalent of the request in an alternate data stream of the image. When a problem was detected we would open the alternate data stream and test the request manually.
- vocatus_gate 10y agoVery cool niche case. Thanks for sharing.
- andrewaylett 10y agoI've worked on Windows-only software that used resource forks. It stored mail messages, one per file, with the message metadata in a resource fork so we didn't have to modify the file containing the actual mail when the metadata changed.
- Ecio78 10y agoSQLServer uses it from version 2005 til 2012 to create databases snapshots in order to run DBCC CHECKDB (consistency check). So for actually a critical feature of MSSQL. I suppose this was the reason why ReFS was not supported for SQL data disks. It seems they are not used anymore since sql 2014. See for example http://www.sqlskills.com/blogs/paul/issues-around-dbcc-checkdb-and-the-use-of-hidden-database-snapshots/ http://www.sqlskills.com/blogs/paul/issues-around-dbcc-check...
- artifaxx 10y agoThat is quite the obscure and interesting issue to run into! Who puts colons in their filenames though? I haven't ever seen that used...
- Tharkun 10y agoWhy wouldn't you put colons in filenames? Unless of course you use Windows. Colons, spaces, backslashes, whatever.
- belovedeagle 10y agoThe colon should be reserved in Unix to separate path names a la PATH.
- TazeTSchnitzel 10y agoIt isn't, though.
- ambrop7 10y agoThe PATH should be a list of strings not a string where : means something special.
- the_mitsuhiko 10y agoAnd then how do you escape it?
- zeveb 10y agoIn a sane system, PATH=/home/me/bin:/usr/local/bin:/usr/bin would be (setf bin-dirs '(#P"/home/me/bin/" #P"/usr/local/bin/" #P"/usr/bin/")) and if I wanted to have a quote in a file I could just write #P"/really-weird-name\"-isn't-it台北/bin/".
- geofft 10y agoTransmit it as a JSON list or whatever. We're already assuming we're breaking UNIX userspace compatibility, so any option for reliably transmitting lists of strings is fine, and we have lots of those.
- sickbeard 10y agoputting colons in your filenames are almost as weird as alternate data streams.
- cordite 10y agoIt's not a forward slash or a NUL byte. And it is a printable character. Doesn't seem so wrong to me.
- tamana 10y agoA colon is a forward slash on MacOS
- stevekemp 10y agoSome tools assume particular characters mean things. For example GNU tar will assume if you find ":" in the filename of the archive it's marks a hostname..
- brobinson 10y agoUse --force-local to bypass this issue. I got hit by this recently. :)
- cygx 10y agoIt's used as separator in various places on *nix (eg PATH).
- ygra 10y agoSo are semicolons on Windows, yet still legal in file names. For PATH you can just quote the ones containing the separator (at least on Windows).
- cygx 10y agoTraditionally, there's no way to quote in PATH on *nix. I do not believe that's changed, so if you cannot just change the name, you'd need to use a workaround like creating a colon-free symlink.
- Grue3 10y agoI had a related problem with Dropbox. Some files uploaded from my Linux machine were not synced to my Windows machine. Later I narrowed down this problem to images being saved from Twitter, which have URLs ending with ":orig". On Linux, Firefox happily saves such images as "blahblah:orig.jpg", whereas on Windows it uses space instead of a colon. And of course Dropbox on Windows would completely ignore filenames that contain colons and tell that the directories are synced, when they obviously aren't.
- Ieyeefae 10y agoThere's https://www.dropbox.com/bad_files_check https://www.dropbox.com/bad_files_check
- reycharles 10y agoI get hit with a login page. Can anyone describe what is linked to?
- deleted 10y ago[deleted]
- mcculley 10y agoThis is interesting. I was just recently working on an app where I wanted to ensure the UI wouldn't accept problematic characters in filenames. Obviously, Unix has problems with '/'. I'll add ':' to the list. That's unfortunate. What else should portable apps avoid?
- mikeash 10y agoMicrosoft seems to have a fairly comprehensive list: https://msdn.microsoft.com/en-us/library/aa365247(VS.85).aspx https://msdn.microsoft.com/en-us/library/aa365247(VS.85).asp... They suggest avoiding <>:"/\|?* as well as all ASCII characters 0-31. ASCII 0 can be really fun. Lots of filesystem APIs deal with NUL-terminated strings (like, all of POSIX) so a zero byte in the middle of your string just truncates it at that point. If you use something that tolerates zero bytes for your UI strings (like NSString on the Mac, maybe C++ UI frameworks dealing with std::string) then the full string may show in the UI and you just mysteriously get a filename that's shorter on disk than what you see on screen.
- outworlder 10y agoASCII 255 used to be fun in the Windows 3.1 days. DOS would handle just fine (displaying whitespace). The Windows Explorer (or whatever it was called back then) would not let you select a directory named like that. Basically this made a directory inaccessible, unless dealing with very tech savvy people.
- finnh 10y agoIIRC, windows has a dialog that shows their full list of disallowed characters if you try to use one of them ... so try to make a file with (eg) "\" in the name and see what the dialog says. disclaimer: i'm remembering something from the Windows 2003 era, so YMMV.
- thoth 10y agoIt's still there, as a balloon popup that says a file name can't contain the following characters: \/:*?"<>|
- xg15 10y agoThe problem should be addressed, but the proposed workaround seems strange. So git should refuse to write the file to disk? How am I supposed to use a git repo that contains such problematic files on Windows then?
- Ruud-v-A 10y agoWhat is the alternative? Renaming the file? This was actually an issue with early versions of Servo on Windows: cloning the repository would fail because it contained a file with a # in the name. https://github.com/servo/servo/commit/43c999905c01627133240cbb3efe4aef0149abd9 https://github.com/servo/servo/commit/43c999905c01627133240c...
- moogly 10y ago'#' is allowed. It appears the issue was the wildcard '?' character, which could be argued isn't the best idea to use on *nix either.
- SpaceManiac 10y agoMSYS2 (a Cygwin-based platform) does renaming, mapping colons to U+F03A from the Private Use Area (which renders in Explorer like a bullet point). Its git package cloned the repository from the article with no problem, "ls" shows "foo:bar", and "cat foo:bar" works. Opening the file in non-MSYS tools also has no problems with the exotic character.
- ajross 10y agoHow would you propose to "use" a git repo that contains files with unrepresentable file names in the first place? It's the repo that's not portable, not git. You'd have the same problem if someone handed you a zip file or tarball.
- smellf 10y agoThis is how Tortoise SVN handles SVN paths that are invalid on Windows - it doesn't write the offending file. You should probably not check out such code on Windows in the first place, but if you accidentally do, then you really need to get loud warnings splashed everywhere.
- Someone 10y agoIt's not alone. In MS SQL Server, you can name a database "foo:bar". If you give a database such a name when you restore it from disk, you'll find that the database takes zero bytes on disk (at least, that's what Explorer claims) Your disk space is gone, though.
- _nedR 10y agoWhat? You are saying windows explorer doesn't handle this feature properly? Thats insane.
- sitharus 10y agoThere are a lot of NTFS features that Explorer doesn't handle properly, like file paths greater than 255 characters.
- exceptione 10y agoI think that is the correct behaviour though. The default is left empty in this case, so it should indeed be zero bytes. Keep in mind that for each file you can have multiple data-streams. Suppose the system reports the total of al the streams for foo combined... You would be surprised if you would read the reported number of bytes from foo and see it crash because there are in reality no bytes in the default stream. However, there are other tools to report the presence of alternative streams. This is not a feature intended for casual end-users.
- mietek 10y agoThe user should not have to use a third-party tool to interact with a feature which is always present in the core OS. The principle of least surprise applies here: it’s surprising for a user to find a seemingly-empty file, especially if they expect the file to contain valuable data. Clearly, Explorer should make the presence of multiple streams obvious to the user.
- Too 10y agoIf I dump a SQL database to a file and see that the file size is 0kb in explorer I will assume there was something wrong during the export. Not that the data is hiding in another place which requires me to use special tools to inspect, how am I supposed to know these tools exist in the first place anyway? Explorer is clearly doing the wrong thing here. This sounds like a bug in SQL server also, what if you try to transfer the data to another computer using a fat32 USB stick, then none of the actual data will be copied.
- kazinator 10y agoThe colon has been special since the dawn of DOS. For instance, you cannot use "con:" as a file name. (In fact, in a fit of extreme stupidity, DOS also claimed some devices with no Colon suffix, like "con" and "prn", effectively making these into globally reserved names in any directory.) Stock Cygwin does something special with the colon character, so the Cygwin git shouldn't have this problem. A path like "C:foo.txt" is not understood by stock Cygwin as a relative reference in the current directory of drive C; the colon is mapped to some other character and then this is just a regular one-component pathname. In the Cygnal project (Cygwin Native Appplication Library), paths passed to library are considered native. So that certain useful virtual filesystem areas remain available, I remapped Cygwin's "/dev" and "/proc" to "dev:/" and "proc:/", taking advantage of the special status of the colon to take this liberty. You can list these directories (opendir, readdir, ...) and of course open the entries inside them; but chdir is not allowed into these locations. (Unlike under stock Cygwin, where you can chdir to /dev). chdir is not allowed because then that would render the library's current working directory out of sync with the Win32 process current working directory, which would not be "native" behavior.
- dboreham 10y agoThe colon pre-dates DOS by a long time. I seem to recall it in RSX-11 pip. Definitely it was present in CP/M : https://en.wikipedia.org/wiki/Peripheral_Interchange_Program https://en.wikipedia.org/wiki/Peripheral_Interchange_Program
- kazinator 10y agoI used CP/M with a Z80 coprocessor card on an Apple II. I didn't know RSX-11 also had pip, though.
- blastrat 10y agoPeripheral Interchange Program. Gary Kildall recreated PIP for CP/M because he had come from using Digital/DEC systems. It wasn't just RSX-11, it was in a bunch of PDP stuff going back. It was a pretty "revolutionary" feature of Unix that device I/O was just in the filesystem along with everything else so all software could access devices. (Not claiming revolutionary as in invented, revolutionary as in one of the things that helped unix achieve ubiquity and would be the first place most people saw it. Maybe it came from Multics, I don't recall.) Without filesystem mapped I/O, you need to create peripheral interchange programs to do ordinary things like copy files and print. Once you get used to PIP style file specification on command lines, it's a next step to push it into the OS API, so CON: will always mean the console, rather than only to software like PIP. This is the origin of MS-DOS having those special names too. And colon as a special character in a file specification (I didn't say filename) is not just Windows, it's also in Unix (that's where it came from in http:), that's why I'm astonished to hear that people are naming files with colons in them. It used to be, there were more experienced people you worked with who would teach you very quickly that you don't put colons in filenames. Those days are gone, it's emojis all the way down, including some very sad emojis.
- duncans 10y agoRelated to this bug: used to be a vulnerability in IIS back in the late 90s where you could append ::$DATA to a file name (e.g Foo.asp::$DATA) and download a server-side script's source code.
- jameshart 10y agoRelated - meaning the ::$DATA was interpreted as a request for an alternate data stream from the file, and then read the default stream?
- duncans 10y agoMore info https://technet.microsoft.com/en-us/library/security/ms98-003.aspx https://technet.microsoft.com/en-us/library/security/ms98-00... - seems to imply that $DATA is the default stream.
- SirEricson 10y agoThis is all rather silly and should never have been allowed to happen in the first place.
- AWildDHHAppears 10y agoMacOs (i.e., Os9 and before) had special meaning for colons, too. I wonder what would happen for git on those platforms. Edit: Apparently colon is _still_ a special character on Mac! http://stackoverflow.com/questions/13298434/colon-appears-as-forward-slash-when-creating-file-name http://stackoverflow.com/questions/13298434/colon-appears-as...
- lostlogin 10y agoAnd this is how we enter the new era. It goes MacOs, OS X then macOS. Unfortunately the 10.xx has been kept to mess with what is (capitalisation aside?) a nice tidy up. Maybe dropping the names part, Sierra, would have made it better. Relying on readers to spot your capitalisation isn't ideal at all, and what if you start a sentence with macOS, how do you capitalise it?
- AWildDHHAppears 10y agoI fixed my MacOs in my post. (For me it went MacOs, OS X, then Windows 10).
- kalleboo 10y agoTo be super pedantic, it went 1. "Macintosh System Software" 2. "Mac OS" (starting with 7.5/7.6) 3. "Mac OS X" 4. "OS X" (starting with Mountain Lion) 5. "macOS" (starting with Sierra)
- DashRattlesnake 10y agoIsn't the colon the directory separator character in HFS, akin to the unix '/' and windows '\'?
- fowl2 10y ago"McAfee Web Gateway" thinks this is porn, great.
- voltagex_ 10y agoSo does BlueCoat. I've submitted it for review, but I think McAffee is maintaining its own list.
- kristianp 10y agoWhy would that be I wonder? I don't see any keywords that might trigger it. That reminds me of web filtering software that blocked my search for "java proxy", but allowed "java procy", which google understood!
- ragsagar 10y agoWonder why this site is blocked in UAE! :|
- jorangreef 10y agoThe flip-side of this: I was running a fuzz test on a backup tool, which verified that file data and metadata (including timestamps) as reflected by Windows were exactly as produced by the fuzz test. I noticed that for some ".eml" files this was not the case. The mtime of these files was being modified by something else after the initial create by the application. At last, it came down to a Windows process which was automatically indexing ".eml" files and creating an ADS for each of them, thereby touching the mtime. This was intentional on the part of Windows, but I never saw it coming.