12 ms·
Windows 10 works incorrectly with Large memory pages
- Afforess 8y agoFor all the improvements to Windows that have come from Microsoft thanks Nadella & co., it is still rather shocking to realize Windows has no public bug tracker, and no real way to report these issues besides screaming loudly and hoping someone in Redmond hears you. It's even worse customer service than Google, which is quite an achievement.
- EliRivers 8y agoInteresting to hear you say that; a couple of days ago someone reposted the link to ITBWTCL ( http://cristal.inria.fr/~weis/info/commandline.html http://cristal.inria.fr/~weis/info/commandline.html ) in which Stephenson, twenty years ago, discusses at length the differences in attitude and culture that mean Windows has no public bug tracker and no way to submit bugs.
- binarycrusader 8y agoThe Feedback Hub app in Windows 10 is how someone can publicly submit and comment on public issues and suggestions relating to Windows (and various other Microsoft-related/provided components).
- ColinWielga 8y agoThis issue is on feedback hub for anyone who wants to upvote it: https://aka.ms/Yxum93 https://aka.ms/Yxum93
- deleted 8y ago[deleted]
- onion2k 8y agoSome teams at Microsoft have public bug tracking. Edge lets users submit issues from Twitter... https://blogs.windows.com/msedgedev/2016/08/11/edgebug-twitter/#KSYpvDDzyFMwXVvB.97 https://blogs.windows.com/msedgedev/2016/08/11/edgebug-twitt...
- nasredin 8y agoIf you bug is longer than 140 (or 280 characters) it is a feature!
- antoncohen 8y agoI don't think that is true. I haven't used Windows in years, but in the past I have talked to Microsoft support on the phone, as an individual without a support contract. To check that it is still possible, I went through the IT professional and developer support flow [1] and ended up with a button that said "Contact Microsoft. Have a technical support representative contact you. Start request". So it is at least possible to contact them, though maybe it isn't on the phone anymore. If you are a paying enterprise customer of Microsoft you can get very good support. I briefly worked for a company that ran their compute infrastructure on Windows (~2000 physical servers), in the month I worked there they had multiple tickets open with Microsoft. If I remember correctly, one was for excess memory usage and Microsoft dug through a memory dump to find the problem. I hear Google has improved for paying enterprise customers, under Diane Greene's leadership, but they certainly burned some bridges in the past with poor support. Public bug trackers are super helpful for professionals, but the lack of one isn't necessarily an indication of poor customer service. [1] https://support.microsoft.com/en-us/assistedsupportproducts https://support.microsoft.com/en-us/assistedsupportproducts
- larkeith 8y agoThe last time I tried to use Microsoft's support, the only way I was able to contact them was via a webchat, which at first dumped me into a long and infuriating "dialogue" with their support AI - it was the chatroom equivalent of an IVR, and just as useless. At least, after I managed to get past the faux-IVR, the support staff was competent enough.
- ThoAppelsin 8y agoRather unconventional, but Windows 10 on desktop and mobile do have a Feedback Hub [1] where Windows 10 users are able to provide all sorts of feedback, either as a suggestion or a problem. All the feedbacks are public and users can freely vote them up to draw more attention on them. The more vote they have, the more likely they receive a response from the developers and also get the priority in the queue of issues to be resolved. I use it every so often when I notice something peculiar. None of my feedbacks actually became so popular. Even then I know one of them has been fixed. The fix probably didn't come because I have pointed it out, but I was happy about it regardless. I couldn't find a web-link to the Hub, so I think it is not entirely public, but surely available to the Windows 10 users. [1] https://support.microsoft.com/en-us/help/4021566/windows-10-send-feedback-to-microsoft-with-feedback-hub-app https://support.microsoft.com/en-us/help/4021566/windows-10-...
- oldmanhorton 8y agoAs a Microsoft employee, I can say that that feedback is taken pretty seriously in most teams, especially if the description is good or if the problem recorder/screenshot tool is used. It's not all based on up votes.
- metalliqaz 8y agoWell then I'll report something about how my PC refuses to stay asleep after I tell it to sleep.
- MLR 8y agoThis happens to mine if I have an update pending, worth checking if it's an intermittent issue.
- metalliqaz 8y agoI've dug into it several times. First it was network adapter, which for some reason had a default setting to wake on any received packet (lol, wut?). Then it was waking because there was some setting deep in the system about waking up for scheduled operations. (not scheduled tasks, but timers within individual processes... why???) Now it started again but this time the power management tools report no reason for the wake.
- vbezhenar 8y agoIt's the same for many companies. I'm experiencing (what I believe) Nvidia bug. There's some strange page, I submitted that bug and I know nothing of it, absolutely zero further communication, I'm not even sure that this page works.
- mgkimsal 8y agoOn the other end of that spectrum, it seems MS have had large teams of QA people doing proactive outreach for security problems. My family members have been contacted 6 times in the past 2 years, each time to let them know that MS had detected a security problem and they needed to help us install a patch immediately.
- digi_owl 8y agoNot sure if joking, as that sounds like a scam call...
- dboreham 8y agoProbably forgot the <sarcasm> tag.
- michaelmrose 8y agoHow would you distinguish between MS personnel and scammers calling your house to have you install malware?
- egeozcan 8y agoThat was sarcasm, if I'm not mistaken. Nobody from Microsoft would call you for patching security problems.
- digi_owl 8y agoReminds me that for some time now the SD reader on a certain model of Intel Atom package has a bad driver. A driver supplied by Microsoft via automatic updates, that can't be rolled back. This seems to affect a number of models from a number of OEMs that use the same "template".
- setquk 8y agoMicrosoft's customer service is non-existent even for paying customers and quality is declining. The development tools are getting less reliable each release. On large projects we're seeing tens of Visual Studio crashes a day. On top of that the ecosystem is a wasteland of abandoned projects and rapid semi-schizophrenic direction changes. It's difficult building a product on a moving target. In once case we got Scott Hanselman's attention via HN on an issue but the outcome was clearly that a major part of SCVMM's support for Linux was a hack job and mostly abandoned and their own assigned team member didn't understand the problem domain properly. Chuck it on github for open source lip service then ignore it. Add telemetry on by default. Make it a paid service. Anything to hurt the customer's trust. And I'm going to keep complaining loudly about this until it changes.
- ken 8y agoWhy is this shocking? I can't think of any proprietary software, offhand, that has a public bug tracker.
- nasredin 8y agoWait, Google has customer service? The googleproductforum.com (whatever it's called) which is usually the #1 result in Google is absolutely worthless. I am not joking. It is infuriatingly worthless.
- bubblethink 8y agoYes, that forum is utterly useless. The trick with google is to use only open source google products. If you find a bug in chromium, AOSP, or any of their other open projects, you can report them on their respective trackers.
- bubblethink 8y agoIs it a brand/PR thing that having a bug tracker means admitting that there are bugs ? Microsoft tends to use github issues as a tracker for some projects even though they don't put code on github (WSL for example). So why not do it for windows ?
- ThoAppelsin 8y agoIt is funnily interesting to me how they prefer to capitalize the word BUG, perhaps as a means of drawing attention to its (apparent) importance.
- gascan 8y agoThe pattern I've seen before is all-caps tags inserted in the code, making for easy grep, e.g. FIXME, BUG, TODO. Perhaps it becomes habit.
- UncleEntity 8y agoMy super hitech code editor (erm...gedit) highlights FIXME and TODO in comments so you can easily find them while scrolling. Doesn't know about BUG though so I guess it just assumes you write bug-free code.
- metalliqaz 8y agoThe author is Igor Pavlov, the creator of 7-zip. He's eccentric and very Russian.
- zentiggr 8y agoLeery about going to read this - has sourceforge cleaned up its act at all since the download poisoning issues?
- codezero 8y agoIt got a new owner. I think they reduced but didn’t eliminate the surface area of the questionable ads. This url is a forum and appears clean on mobile.
- metalliqaz 8y agoInsightful response in the linked thread: https://sourceforge.net/p/sevenzip/discussion/45797/thread/e730c709/?limit=25&page=1#b240 https://sourceforge.net/p/sevenzip/discussion/45797/thread/e...
- leeter 8y agoI'm not surprised at Igor's response, it's in keeping with his refusal to use modern compilers, security features, sign his code, or support ALSR properly.
- deleted 8y ago[deleted]
- leeter 8y agoIn reading the article it's clear this is not a bug, it's API abuse. The documentation for VirtualAlloc is very clear that Large Pages should be a one time allocation thing are not intended for general malloc replacement.
- iforgotpassword 8y agoApi abuse should not lead to system crashes or global memory corruption.
- leeter 8y agoMaybe, large pages are such a specialty feature on windows that generally speaking this use case was never supported. I'm not saying the crashes shouldn't be fixed. But VirtualAlloc should fail much faster because there are no large pages to alloc.
- freeone3000 8y agoYes, that would be one possible fix.
- dragontamer 8y agoLarge pages cannot be paged to disk (lol: amount of time to write 2MB to disk while the scheduler is locked), and are prone to fragmentation. When you use Large Pages and you run out of contiguous 2MB chunks, what do you do then? Unlike Linux, Windows actually guarantees its memory to anything that requested it. Windows does NOT ever "take back" memory and crash processes randomly (see Linux's OOM killer). But this guarantee has its own issue on Windows: important services who make requests for new bits of code will crash instead. So Large Pages naturally will run out the longer a system runs. They are a limited resource: how often do you find a contiguous 2MB block when most programs request memory in 4kB blocks?? And the longer a system runs, the fewer 2MB blocks will exist. I guess Linux handles the issue by making normal pool, large pool, and "huge" pool all separate. So you can run out of normal-pool but have lots of large-pool space remaining. But this has the disadvantage of being wasteful (Ex: 1GB Huge Pool permanently eats up 1GB that the smaller pools can't ever use). ------------ Ultimately, applications aren't supposed to use the OS-level memory allocator as if it were malloc / free. Because when fragmentation hits you in malloc/free, you mess up your own memory. But if fragmentation hits you at the OS-level, you're basically screwing the entire system.
- dragontamer 8y agoSo, as much as I hate to hate on somebody here, Igor is... somewhat unreliable with regards to these issues. Igor is infamous for disabling virtually every setting. 7-Zip has no ASLR, compiler-stack checks, or anything what-so-ever. Igor refuses to use a modern VC++ (Visual Studio 2015 and later have FREE versions available for open-source code) that would solve a lot of security issues and bugs. I'm not entirely sure if this is a Win10 problem, or if its a 7-Zip problem. Any complaints from the 7-Zip dev IMO will require a very careful eye: 7-Zip code is not necessarily in the cleanest state or using the best practices.
- AnIdiotOnTheNet 8y agoAnd yet it is about 100x as useful as most free software that does. One wonders whether that is coincidence or correlation. I don't know Igor, but if 7z is anything to go by then he probably uses VC--I'm guessing here--6 for the same reason Sean Barrett does: It's way faster and less bloated than modern VS. I'm also guessing he doesn't use those security features because they're largely ineffective and just complicate things and slow them down. I'm sure many will argue the last point, but it's hard to imagine that that mindset doesn't play a role in 7-zip being as great a utility as it is.
- dragontamer 8y agoThere's a big difference between quality code and being a cowboy. > I don't know Igor, but if 7z is anything to go by then he probably uses VC--I'm guessing here--6 for the same reason Sean Barrett does: It's way faster and less bloated than modern VS. Then they should learn how to download the SDK and learn to use the command line to properly compile code with proper ASLR and other such security features. Keep working in VC 6.0 if you want, but for the love of all things good please enable basic ASLR. Its 2018. Its time to get with the program. Various solutions (or at least... mitigations) to buffer overflows and code execution bugs have been discovered in the last 20 years. Yes, VS 6 was released in 1998. My use of the phrase "20 years" is literal. Its shameful that a dev of one of the most popular open source tools out there doesn't care about security. -------------- In any case, Igor runs his dev environment from 20 years ago. If someone was compiling code with GCC 2.95 (released 2001, three years after his version of VS), the first response from Linus Torvalds would be "Dear lord, please upgrade your compiler. I'm not going to ensure compatibility with 18-year old tech". > I'm also guessing he doesn't use those security features because they're largely ineffective and just complicate things and slow them down. ASLR is ineffective? Really? https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-7-zip-could-allow-for-arbitrary-code-execution_2018-009/ https://www.cisecurity.org/advisory/multiple-vulnerabilities... https://landave.io/2018/01/7-zip-multiple-memory-corruptions-via-rar-and-zip/ https://landave.io/2018/01/7-zip-multiple-memory-corruptions... The freaking executable doesn't have the freaking "NX Bit". We're talking about the most barebone basics of security here. No ASLR. A lack of NX Bit. Pretty much any security feature discovered in the last 20 years is missing from 7zip. Its actually one of the worst offenders of security I've ever seen in 2018.
- yuhong 8y ago// A Windows bug exists where a VirtualAlloc call immediately after VirtualFree // yields a page that has not been zeroed. The returned page is asynchronously // zeroed a few milliseconds later, resulting in memory corruption. The same bug // allows VirtualFree to return before the page has been unmapped. I wonder what MSRC would think of that bug
- binarycrusader 8y agoFor those interested, this issue was apparently already resolved in RS4 insider builds and only affects some older releases. After updating a system to RS4 (the upcoming release), this issue should no longer be encountered: https://aka.ms/Yxum93 https://aka.ms/Yxum93 (requires Feedback Hub App on Win 10 to view)