From June to now, most of my time on this project was spent writing "The Rise of Microsoft". Researching and writing that thing took an inordinate amount of time. Also, I took a break to work primarily on another unreleased project I have before switching back to this one. I am proud of what I got here though and I feel like it is all coming together. My plans for the whitepapers are already well drafted and I know they will make an impact. I have learned a ton from working on this project and it has definitely given me something to idly think about and work on in my spare time. Finishing "The Problem with How Windows Uses Threads" was something I thought I wanted done before this release, but oh well. The main README is at about 50K words now, plus all the other smaller documents and you are looking at about a small novel's worth of technical writing. And technical writing takes multiple times longer than typical story writing. Anyway, this project is exciting for me - people who I show it to also really like it - and I am even more excited about what is to come!
Timeline Verification
Understanding history requires knowing the timeline (i.e. the order in which things happened) to get an accurate depiction of events. Let's collect some details on the files included throughout Windows versions to help establish timeline information on its development.
Methods
DLL Imports/Exports
Contained are the imports and/or exports of the core DLLs from these Windows version:
- Windows 3.1
KRNL286.EXEandKRNL386.EXE(16-bit and 32-bit base DLLs) - Windows NT 3.1 early pre-release
BASE.DLL - Windows NT 3.1
NTDLL.dllandKERNEL32.dll
To obtain these file artifacts, see the Legacy Software Analysis document.
Windows 3.1 Files
> file KRNL286.EXE
KRNL286.EXE: MS-DOS executable, NE for MS Windows 3.x (3.0) (DLL or font)
> file KRNL386.EXE
KRNL386.EXE: MS-DOS executable, NE for MS Windows 3.x (3.0) (DLL or font)
16-Bit Windows executables are in the New Executable file format. Early 16-bit library executables did not support imports because Windows 3.1 did not have a dynamic linking mechanism. An EXE had to manually load another EXE, for instance by calling LoadLibrary, to use its functionality.
We use the exehdr tool to get infromation about a 16-bit executable, which can be obtained by downloading an early version of the VC++ development tools.
Windows NT 3.1 Early Pre-Release Files
> file BASE.DLL
BASE.DLL: PE Unknown PE signature 0xffff8300 (Microsoft compiled help format 2.0), for MS Windows, 2 sections
This Windows NT pre-release used a botched Portable Executable file format because the new format did not have a stable ABI yet (hence why the Microsoft compiled help format 2.0 detail is inaccurate). By the time of Windows NT's formal release, Microsoft split BASE.DLL into the KERNEL32.dll and NTDLL.dll files to separate the public and private Windows APIs.
There is no tool available that can parse this half-baked executable format, DLL information is obtained using the strings command.
Windows NT 3.1 Files
> file KERNEL32.DLL
KERNEL32.DLL: PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows, 8 sections
> file NTDLL.DLL
NTDLL.DLL: PE32 executable (DLL) (console) Intel 80386 (stripped to external PDB), for MS Windows, 10 sections
Execetubles in the final Windows NT release are in the Portable Executable file format.
We use the dumpbin tool to get DLL information, which can be obtained by installing Visual Studio with the C++ development pack.