3 ms·
> The one I notice the most is the filesystem. This is due to the extensible file system filter model in place; I'm not aware of another OS that implements thi
by nullindividual 2y ago
> The one I notice the most is the filesystem.
This is due to the extensible file system filter model in place; I'm not aware of another OS that implements this feature and is primarily used for antivirus, but can be used by any developer for any purpose.
It applies to all file systems on Windows.
DevDrive[0] is Microsoft's current solution to this.
> Meanwhile Win10 Explorer opens after a noticeable delay
This could be, again, largely due to 3rd party hooks (or 1st party software that doesn't ship with Windows) into Explorer.
[0] https://devblogs.microsoft.com/visualstudio/devdrive/ https://devblogs.microsoft.com/visualstudio/devdrive/
- andai 2y agoI'm glad you mentioned that. I noticed when running "Hello world" C program on Windows 10 that Windows performs over 100 reads of the Registry before running the program. Same thing when I right click a file... A few of those are 3rd party, but most are not.
- nullindividual 2y agoRemember that Win32 process creation is expensive[0]. And on NT, processes don't run, threads do. The strategy of applications, like olde-tymey Apache using multiple processes to handle incoming connections is fine on UN*X, but terrible on Windows. [0] https://fourcore.io/blogs/how-a-windows-process-is-created-part-2 https://fourcore.io/blogs/how-a-windows-process-is-created-p...
- redleader55 2y ago> I'm not aware of another OS that implements this feature I'm not sure this is exactly what you mean, but Linux has inotify and all sorts of BPF hooks for filtering various syscalls, for example file operations.
- rincebrain 2y agoFSFilters are basically a custom kernel module that can and will do anything they want on any filesystem access. (There's also network filters, which is how things like WinPcap get implemented.) So yes, you could implement something similar in Linux, but there's not, last I looked, a prebuilt toolkit and infrastructure for them, just the generic interfaces you can use to hook anything. (Compare the difference between writing a BPF module to hook all FS operations, and the limitations of eBPF, to having an InterceptFSCalls struct that you define in your custom kernel module to run your own arbitrary code on every access.)