4 ms·
Is the behavior that a running .js script is fully loaded into memory and the file doesn't need to exist documented, supported behavior? What if, hypotheticall
by dmazzoni 3y ago
Is the behavior that a running .js script is fully loaded into memory and the file doesn't need to exist documented, supported behavior?
What if, hypothetically, the system was suspended in the middle of script execution, and the resume function was designed to reload the script from disk?
It just feels like a different hack to me.
Also - trying 20 times and pausing 500 ms seems wasteful. What are the chances that it's going to succeed a subsequent try if it fails the first try? Why not catch the error message and only retry for errors that have a plausible chance of succeeding if you retry?
- omnicognate 3y ago> Is the behavior that a running .js script is fully loaded into memory and the file doesn't need to exist documented, supported behavior? If Raymond Chen says to rely on it then yes.
- sim7c00 3y agoeven though i admot this guy is genious level, its not really good to rely on one persons judgement for anything. thats a bad practice in general. zerotrust and all :)
- chrchang523 3y agoAgree, I'm shocked at how ugly the recommended alternative is. This does not make MS look good.
- Arainach 3y agoThere are plenty of other solutions; that was merely one straightforward option that could be shown in a few lines of code and which doesn't require *injecting code into a binary you don't own*.
- chrchang523 3y agoSure, but there isn't even an offhand remark about how hacky this kind of polling is. It's presented as if it's a completely normal way to do things in reliable software.
- kazinator 3y agoNo worse than the 10 minute delay rule in DllCanUnloadNow. DllCanUnloadNow returns an indication that a DLL can be unloaded. A DLL cannot be unloaded if any threads are executing the code. But a DLL can only change to the unloadable state by executing some code, and that code has to return after it has set the indication. Only after it returns is the DLL is actually unloadable! So a delay is needed for that thread to vacate the DLL. https://groups.google.com/g/microsoft.public.vc.atl/c/AQvHCWohaqw https://groups.google.com/g/microsoft.public.vc.atl/c/AQvHCW... [2001]
- kazinator 3y agoSo in the present example from Raymond Chen you need the loop for a similar reason. The binary .exe program which the script is trying to delete is the one which created the script and launched it. So that means the .exe is still running at that point and cannot yet be deleted. Lauching the script indicates "I'm about to die", not "I'm already dead". The script cannot delete the .exe until the .exe terminates. Without some event to indicate that, you poll. The script knows it can delete itself, so it tries that only once. If a handle could be attached to the process, then the script could do a WaitForSingleObject on it; that would be the prim and proper way. It doesn't seem worth doing; the chances are low that the process cannot terminate within 20 seconds of launching the reaper script.
- sim7c00 3y agoi am not shocked, but its hacky like comments suggested. ultimately done because the lack of a better alternative. id still follow chens advice even though its hacky.
- Arainach 3y agoThere is never a good reason to inject code into another process - particularly a system process. At the point at which you believe this is necessary you are several layers of hackiness deep and should go find a beverage and think over what your actual goal is. As a metaphor: you find the instructions to sweep your floor cumbersome so you reprogram your neighbor's Roomba to come clean your floor. Sure, it may well go back to their house and no harm done, but it's hacky, socially unacceptable, and no matter how hard your broom is to use it's not OK.
- sim7c00 3y agosecurity products have valid reasons, though maybe not _good_. forcing plt and got entries to be bound rather than lazy loaded, forcing certain segments to be read only and hooking a bunch of stuff is neccesary for them, and that can only be done by suspending processes at startup and then injecting and modifying them. its a bandaid to a bad system hence its a valid but maybe not good reason (better to prevent than this cure of theirs..)
- slaymaker1907 3y agoEven if it doesn't, I think you could do something similar by just spawning a shell (command prompt) that executes a small script trying to delete the file. You just have to take care to make sure the process is detached from the original one and then let the spawning process terminate to release the lock on the executable. PowerShell could also work, but I know it is pretty restricted in a lot of environments. These completely avoid any intermediate file. I think the retry is necessary because if you launch "wscript cleanup.js" from the process that wants to be cleaned up, you then need to wait for the spawning process to finish executing. I agree if it fails after 20 times, you should probably spawn an alert or something letting the user know that uninstall failed. There are also so many random processes that might take a reference on the file like antivirus in Windows so just spamming retry will help wait that stuff out (this problem does not exist on Linux since Linux generally just does garbage collection which has the downside of not keeping specific paths around, just file inodes).