Example pulled at random:
D:\analysis\Windows\WinSxS\amd64_microsoft-windows
-imageres_31bf3856ad364e35_10.0.15063.0_none_edd17c6c30b4bf9f\imageres.dll
...
- Total: 4435
D:\analysis\Windows\System32\imageres.dll
...
- Total: 4435
I am willing to bet those are the same file hardlinked and only wastes the 4435 bytes once, verifiable thusly: cmd> fsutil hardlink list \Windows\System32\imageres.dll
Windows\WinSxS\amd64_microsoft-windows-imageres_31bf3856ad364e35_6.3.9600.16384_
none_cd7c033dcbdd0cab\imageres.dll
Windows\System32\imageres.dllSeems to check though https://github.com/riverar/eoraptor/blob/master/FileEnumerat...
A way to correct for this would be to open the files and de-dupe by (((ULONGLONG)nFileIndexHigh) << 32) | nFileIndexLow in this structure: https://msdn.microsoft.com/en-us/library/windows/desktop/aa3...
Edit:
> Seems to check though https://github.com/riverar/eoraptor/blob/master/FileEnumerat...
No it does not, reparse points are used for symbolic links and junctions - not hardlinks.
There's still a lot of size growth over time, of course.
I found it is common to find XMP inside media files embedded inside Windows EXE, as well as Linux binaries, JAR, Microsoft Word and other composite formats.
Complex media objects frequently use an encapsulation system such as ZIP. When a PNG file is incorporated into a JAR or a Word Document, the XMP content in the file may not be compressed because the archiver may not attempt to compress the png file since it assumes the data is already compressed.
XMP is very good from the viewpoint of content creators in terms of having comprehensive metadata incorporated into files so that it does not get out of sync. XMP data is RDF data using an improved version of Dublin Core, IPCC and other industry RDF vocabulary. You can write SPARQL queries right away, plus XMP specifies a way to make an XMP packet based on pre-existing metadata in common industry schemes.
The XMP packets can get big, and you sometimes see people make a tiny GIF image (say a transparent pixel GIF) that is bulked up 100x because of bulky metadata. Once you package data for delivery to consumers you want to strip all that stuff out.
The XMP spec is here:
http://www.adobe.com/devnet/xmp.html
There is some brilliant thinking in there, but also things that will make your head explode such as the method for embedding an XMP packet into a GIF
PNG can apply DEFLATE to blocks though, right? Does XMP not use it?
The two former are limited in scope and language encoding support, so iTXt is typically used for extended textual data such as XML/XMP etc. But if is saved compressed or not depends on the PNG encoder/host used (there can also be multiple instances of these chunks in the same file).
Photoshop for instance saves uncompressed, I guess to give fast access for performance reasons (ie. file viewers using galleries for numerous images while displaying their meta-data).
Bear in mind, that was the Vista days, and Windows 10 now supports even more devices. 800MB of drivers at the time. I would not be surprised if Windows supported by default upwards of 10000 drivers. It works pretty much flawlessly on even somewhat obscure and old hardware. And when your OS is installed on that many consumer devices, and not informally standardized servers, you are going to meet those weird devices one way or the other.
Windows drivers may also take up a bit more space individually because of the overhead caused by either the Windows Driver Model or Windows Driver Framework, but that's the price to pay to not have a driver crashing and bringing down your entire system. Yes, Linux, I'm looking at you.