Windows NT: Peeking into the Cradle
blogsystem5.substack.com
blogsystem5.substack.com
Back in September, I got the recommendation to read the "Showstopper!: The Breakneck Race to Create Windows NT and the Next Generation at Microsoft" book from some other comment thread here in HN. I don't exactly remember which thread that was though... but learning about the history of Windows NT sounded interesting, so I bought the book right away and have been slowly reading through it over the last three months.
The story in the book seemed so exciting (and messed up) that I ended up writing a "book review" with commentary on various topics that caught my attention. The details might not be super-precise, but they are hopefully enough to paint the right picture in its context. I thought you might enjoy it due to where I got the suggestion from!
We have a temporary emulated VAX running VMS 7 and Rdb [a SQL database now owned by Oracle]. After several tries to move the Rdb backup files through our QA firewall with FTP, we finally had to use Multinet SFTP2 to push the backup instead (upping the transfer time from 3 to 40 minutes), which autodetected "VMS mode."
There are some secret record blocking/delimiter capabilities in the ODS-2 filesystem used by VMS that an FTP binary transfer will not preserve, and which the Rdb backup/restore process absolutely needs.
Thank heavens that UNIX thinks a file is a single stream of bytes.
Windows continues the feature experimentation with NTFS "alternate data streams." My, how clever that is [not].
EDIT: from the article, the claim "The open-source BSDs and Linux had just seen the light of day." is not quite correct. Bill Joy was involved in the earliest BSD repacking of v6 Research UNIX, shipped in 1978.
"In 1975, Ken Thompson took a sabbatical from Bell Labs and came to Berkeley as a visiting professor. He helped to install Version 6 Unix and started working on a Pascal implementation for the system. Graduate students Chuck Haley and Bill Joy improved Thompson's Pascal and implemented an improved text editor, ex. Other universities became interested in the software at Berkeley, and so in 1977 Joy started compiling the first Berkeley Software Distribution (1BSD), which was released on March 9, 1978."
https://en.wikipedia.org/wiki/Berkeley_Software_Distribution
...I have also read elsewhere that a conscious decision was made in Windows to never, ever support big-endian architectures (but I am not certain that this is correct). NetBSD and Linux can run big-endian.
"Now, I know you will complain that NTFS is slow… but you know what? It almost-certainly is not... NTFS on its own is fine..."
XFS appears to trounce NTFS, and it consistently leads the performance scores on tpc.org; until very recently, SQL Server on XFS/Linux was well ahead of Windows.
VMS's ODS2 filesystem evidently has concept of files that are grouped in records. The ftp program that you use on VMS wasn't designed to support sending that info to a destination filesystem. Probably because the original Unix filesystem only supported the idea of one stream of bytes for a file. You'd need an FTP server on the destination side to support records seamlessly if you wanted full fidelity.
That's why NTFS supports alternate data streams - the MacOS HFS filesystem supported data and resource forks for a file. An NTFS alternate datastream was where the resource fork was placed so the NTFS user would only see one file from the CLI and the GUI and the builtin copy tools would copy all streams. deleting such a file would remove both streams on NTFS.
Can I ask why a 'single binary stream' view of a file would cause problems when dealing with something from a 'file is actually a bunch of records' system?
Like, if the FTP program sends an identical sequence of bits to the destination machine, how could the destination have problems deciphering the (identical) file?
I don't have any experience with VMS, but I'm assuming that there's information in the file (somehow, somewhere) that tells you where the records start and stop (whether it's a terminating character or a set size of each record, etc) because otherwise how would VMS know where to find each record. Is this not true? Is there information about the file that's stored outside the file?
That is a "wild assumptive guess."
POSIX was wise in having absolutely none of this. Would you rather Apple had won over this standard and we had resource forks everywhere? I understand that the largest use of alternate data streams at times in the past was malware, to evade virus scanners, which seems to be an anti-feature to me.
A file should be a stream of bytes that can at least survive transfer over a socket (that is 8-bit clean), unlike this ODS-2 detritus.
I'm sure the FTP devs were just trying to get something working - they weren't worried about supporting all the possibilities for the definition of "file".
I'd guess the only people who really care are those affected (mainly VMS/Apple people who have to send/receive files via FTP).
Well, I guess if I was trying to FTP a file that had data in an alternate data stream (ADS) from an NTFS drive, I'd care. But then I know that the ADS wouldn't be sent by FTP and package the file accordingly.
I don't think POSIX designed anything - they just codified/standardized what was running in the wild.
Wouldn't something like the VMS-equivalent of a tar archive of your files work better for round-tripping to a non-VMS computer?
The largest use of alternate data streams is actually when a user downloads a file from the Internet via Internet Explorer/Chrome/Firefox on WinXP+. The browser creates an alternate data stream, Zone.Identifier, for the downloaded file so Windows will know that the file may be tainted.
see https://guyrleech.wordpress.com/2018/08/06/where-did-that-do...
However, my ODS-2 problem was not metadata, it was data that lacked esoteric formatting. I certainly don't need that for Oracle RMAN - an FTP binary transfer will always works.
It's a fuzzy line and everyone is probably a bit discontent to where it's drawn.
New large scale multi billion dollar healthcare systems are still being written in it.
Macs use Resource Forks, a type of alternate data stream, yet I am frequently reminded (here) that macOS is Certified (r) UNIX (r)(c)(tm).
https://blogs.oracle.com/linux/post/xfs-2019-development-ret...
Though I must confess the reason I initially chose it was because of the name.
"The MFT structure supports algorithms which minimize disk fragmentation... While this strongly resembles the W_FID of Files-11, other NTFS structures radically differ."
https://en.wikipedia.org/wiki/NTFS
"ODS-2 is the standard VMS file system, and remains the most common file system for system disks (the disk on which the operating system is installed)... NTFS - Has many structural and metadata similarities with Files-11 and is almost certainly conceptually derived from it."
The NTFS of today is rather different to the NTFS of 1993.
And the on-disk format was completely changed for windows 2000, hence me saying what you call "NTFS" today is different to what it was originally.
If you differentiate between ext2/3/4, which are all forwards-compatible like NTFS, you need to do the same here. Though that "forward compatibility" may be an update pass when first mounting an older version of the filesystem, which may break backward-compatibility. Though that may be desirable, especially if you want to use the new features.
I remember there being a bit of a stink at the time when Windows2000 would automatically update the NTFS version and make it incompatible with NT4.0 if you didn't have the latest service pack, and even with that update some of the system tools didn't work on that filesystem anymore.
I understand that early versions of NT emitted error messages identifying itself as OS/2. Did the book explain when NT became "brand new OS from scratch".
I think there's been a bit of revisionist history WRT the roots of NT. MS wants to make it something "we did without their help."
I didn't read your entire blog so apologies if you addressed this.
The VMS kernel itself would also emulate programs written for the earlier RSX-11 operating system that ran on the PDP-11, so there is a history of emulation between these operating systems.
"Broad software compatibility was initially achieved with support for several API 'personalities', including Windows API, POSIX, and OS/2 APIs – the latter two were phased out starting with Windows XP...
"Mark Russinovich wrote in 1998 that while creating Windows NT, Microsoft developers rewrote VMS in C. Although they added the Win32 API, NTFS file system, GUI, and backwards compatibility with DOS, OS/2, and Win16, DEC engineers almost immediately noticed the two operating systems' internal similarities; parts of VAX/VMS Internals and Data Structures, published by Digital Press, accurately describe Windows NT internals using VMS terms. Instead of a lawsuit, Microsoft agreed to pay DEC $65–100 million, help market VMS, train Digital personnel on Windows NT, and continue Windows NT support for the DEC Alpha."
https://en.wikipedia.org/wiki/Windows_NT
Information on the Windows POSIX subsystem:
Not quite. I'd rephrase this as "NT presented three userland personalities—the CSR (Win32), OS/2, and POSIX—through a composition of kernel primitives implemented as userspace subsystems."
The core binary image ntoskrnl.exe only exposes the primitives needed to get the CSR, OS2, and PSX subsystems started, and those (mostly, save for some code that lives in win32k.sys) run in userspace. They more or less act as translators between the native NT ABI/API and the respective subsystems' ABIs/APIs.
PSX in particular did a lot of its own PE image mapping and parsing (something that you'd perhaps think would be done in kernel space) so that it could defer to the other subsystems to run foreign code among other things.
You can edit the wiki if you strongly feel this not to be the case, but I have seen this claim in many other places.
So Gates sided with Maritz. NT would assume the Windows “personality,” by assuming those of its attributes that were visible to the customer. NT also would be redesigned to run applications written specifically for Windows. But Gates added a wrinkle to his position. Given the depth of IBM’s attachment to OS/2, Gates reasoned, abandoning the program altogether would only trigger a nasty split with IBM. Why not maintain a pretense of cooperation by convincing IBM of the merits of an operating system that hosted both Windows and OS/2? NT could be designed to do this, Gates reasoned.
If IBM accepted this, Microsoft could continue to describe Cutler’s program as “NT OS/2.” Even though it contradicted his rhetoric about the need for a single software standard, Gates was prepared to tell IBM: “There’s no reason to think two [program personalities] can’t be of equal importance” to customers.
This was a bold stroke. By denying reality, Gates’s tactic would freeze IBM long enough for Microsoft to install Windows as the standard for computing. Gates would peddle this apparent compromise to IBM and rival software makers, while Maritz and Cutler’s team pursued the real objective internally.
...
Cutler asked about Ballmer’s promise that NT would still sport an OS/2 personality. Not to worry, Ballmer assured him, someone else could take care of that. Indeed, OS/2 was now so unimportant to Microsoft that Ballmer had assigned a tiny team in Israel to create an OS/2 variant of NT. The Microsofties hated OS/2 so much they couldn’t even bear to have someone working on it in the same continent.
Part of it is Cutler really really hated working with IBM... it starts around 3:00 minute mark.
It sounds like there was acrimony all around:
Another problem that came up here was that IBM didn't want us to use the windows API for the graphical environment under OS/2. Many key folks inside IBM had always hated Windows. IBM had this crazy thing called TopView, it was a character oriented windowing scheme and not very good. Bill Gates, myself, and some other folks made several trips to Boca Raton to try to explain to those guys why a character oriented windowing scheme was obsolete before it was even written, but to no avail. One of IBM's most major problems is that although their top guys may be smart, they aren't techically savvy.
"...although their top guys may be smart, they aren't techically savvy. And their low level guys are often neither. IBM doesn't promote on the basis of your skills and ability; they promote on the basis of seniority and other secondary factors. So the guy who makes these decisions often doesn't know what he's doing. And he doesn't know that he doesn't know, because his peers are equally butt-ignorant too. So these guys can never figure out how other folks, including but not limited to Microsoft, keep doing better! Must be dumb luck, they think. I always agreed that it was dumb luck. If you catch my drift... :-) "
> I understand that early versions of NT emitted error messages identifying itself as OS/2. Did the book explain when NT became "brand new OS from scratch".
Windows NT started out as Microsoft's effort to do OS/2 NT. There was a 32-bit Microsoft OS/2 2.0 (distinct from IBM OS/2 2.0), and OS/2 NT was to be OS/2 3.0.
OS/2 NT wasn't rebranded Windows NT until Windows 3.0 eliminated OS/2 from relevance, and with it, the Microsoft/IBM partnership. That's when IBM introduced their own (very nice) OS/2 2.0 and started a years long effort to eliminate Microsoft code from the OS/2 codebase (and the Microsoft copyright message from all over the UI)
https://en.wikipedia.org/wiki/OS/2 provides a recap of the history but I cannot find details on exactly who did what in that page. And my memory from what I read in the book is fuzzy at this point...
Back then I was more impressed by NT and OS/2. Windows 2000 is the one I remember most fondly.
95 dealt with every weakness of NT in those markets and provided developers, consumers and SMBs with a smooth migration path towards it. It had very good backwards (DOS and 3.11) and forwards (XP) compatibility, reasonable hardware requirements and the ability to boot into DOS (important for gaming and some other applications at the time). It also offered massive advances over 3.11 (proper multi-tasking, the best looking GUI of the time and greatly improved stability) that when combined with the above, pushed user adoption.
Given its design requirements, 95 could never have been as stable as NT, but it was a spectacularly successful interim solution for customers not yet ready for the trade-offs that would have involved.
—-EDIT:
I misremembered. It was NT 3.51 that still had the video driver in userspace, NT 4 moved it into the kernel: https://en.m.wikipedia.org/wiki/Windows_NT_4.0
For me, the key Windows 95 moment happened while I was sitting in an IBM lab working as a tester for OS/2 Lan Server. We had a copy of Windows 95 we were testing for compatibility.
Playing around one afternoon, we decided to try to break it. We started Drivespace compression, let it run for a while, and pulled the plug on the machine. Plugged it back in and it picked up right where it had left off...
I'm pretty sure it's possible for a DOS process running in a window to issue a file system request (a DOS API call) that gets trapped and processed by 32-bit VMM code and then immediately forwarded back to (a different instance of) DOS for handling by a legacy device driver.
There are reasons for this.
It's amazing it worked.
I'm thankful it's gone.
While Windows 95's kernel didn't have the full feature set of NT, it still was more sophisticated than DOS.
The reason for this is that the RISC architectures at the time (MIPS, Alpha AXP, PPC) had weird ISAs. There are things like branch delay slots and MIPS in particular required aligning to a 32-bit boundary (x86 does not). Dave Plummer has a YT channel and I highly recommend his interview with both Dave Cutler and Raymond Chen. It was a lot of work to port to these other architectures, and they didn't have source control at the time, so they were hand merging these changes.
And if you're interested in that, you'll likely be interested in his Raymond Chen interview as well:
https://www.youtube.com/watch?v=UTPTPJEVYlY&list=PLF2KJ6Gy3c...
One typo that could be fixed:
> a couple paragraphs are completely unreadable due to broken grammar, punctuation, and capitaliazation [sic]
Microsoft was really trying hard to win a huge contact with DOD (If memory serves). They worked along with DEC for the contract and planned to sell computers based on DEC Alpha + WindowsNT. The POSIX compatibility subsystem was added specifically because the DOD contact demanded such a feature.
Sadly (for them) they did not win the contract.
The DOD was not the reason Microsoft developed Windows but some of the features and archtetures were in respons to features demanded.
The author must not like Macs :)
It's their product. They didn't have to make it trash but they've not just let it, they made it by design this way.
Why eat trash?
Work - I work on Windows clients and Windows Server, so I need to know my way around the OS. The tooling with Powershell is nice now, too. The workflow with window snapping is actually also excellent.
Entertainment - All "official" streaming Netflix stuff runs at 4k and I can also run VPN and torrent just fine on Windows.
Stability - I run an old rig on Windows 10 privately and a work Win11 laptop. Nowadays, you only need to reboot Windows once a month for updates.
And all the good apps runs like Firefox, Ocular, sumatraPDF etc...
Nobody will force you but I felt MS certainly pushed me away hard.
At home I don't get reboots when I don't want to. At work Windows did that to the workstation at work here last weekend - really infuriating that one.
There's too much to list re: 20 years of windows decline.
There's some good no doubt, I'm expect the kernel has been getting gradual if not huge improvements. It's just the rest of the company is not run like the core engineers would be required to.
All the other shit hanging of it is overwhelmingly bad. It's too much, too user hostile, too dark patterned.
How they messed up the near perfect Win2k gui to this... yuck.
It's all just too much, for me at least. So I left it on a dedicated disk but is practically never booted anymore. Maybe once a year. If that.
I've been many years gaming, developing, doing my tax, spreadsheets, watching media, web surfing - it's all much the same. I use firefox at work or home. It feels the same at work on windows as it does on home. I have no need.