{"thread":{"id":"29235","subject":"Warning from AV software about kill.exe","startedAt":"2011-12-22T07:47:24Z","lastAt":"2012-01-06T13:51:55Z","messageCount":6,"participants":["Erik Blake","Thomas Rast","Pat Thoyts","Erik Faye-Lund"],"isPatch":false,"patchVersion":null,"patchTotal":null},"messages":[{"id":"181613","messageId":"4EF2E08C.3050502@icefield.yk.ca","threadId":"29235","inReplyTo":null,"subject":"Warning from AV software about kill.exe","fromName":"Erik Blake","fromEmail":"erik@icefield.yk.ca","sentAt":"2011-12-22T07:47:24Z","receivedAt":"2011-12-22T07:47:24Z","isPatch":false,"sender":{"key":"erik@icefield.yk.ca","avatar":null},"body":"I'm running git under Win7 64. As I selected \"Repository|Visualize all \nbranch history\" in the git gui, my AV software (Trustport) trapped the \nbin\\kill.exe program for \"trying to modify system global settings (time, \ntimezone, registry quota, etc.)\"\n\nDoes anyone know the details of this process and what it's function is? \nFirst time I've seen it, though I'm a relatively new user.\n\nCheers,\ne.\n"},{"id":"181615","messageId":"87mxalkn9q.fsf@thomas.inf.ethz.ch","threadId":"29235","inReplyTo":"4EF2E08C.3050502@icefield.yk.ca","subject":"Re: Warning from AV software about kill.exe","fromName":"Thomas Rast","fromEmail":"trast@student.ethz.ch","sentAt":"2011-12-22T08:45:37Z","receivedAt":"2011-12-22T08:45:37Z","isPatch":false,"sender":{"key":"tr@thomasrast.ch","avatar":"https://avatars.githubusercontent.com/u/153510?v=4"},"body":"Erik Blake <erik@icefield.yk.ca> writes:\n\n> I'm running git under Win7 64. As I selected \"Repository|Visualize all\n> branch history\" in the git gui, my AV software (Trustport) trapped the\n> bin\\kill.exe program for \"trying to modify system global settings\n> (time, timezone, registry quota, etc.)\"\n>\n> Does anyone know the details of this process and what it's function\n> is? First time I've seen it, though I'm a relatively new user.\n\n'kill' is a standard unix utility that sends signals to processes, in\nparticular signals that cause the processes to exit or be killed\nforcibly by the kernel, hence the name.  (I don't know how the windows\nequivalent works under the hood, but presumably it's something similar.)\n\ngit-gui and gitk use kill to terminate background worker processes that\nare no longer needed because you closed the window their output would\nhave been displayed in, etc.\n\n-- \nThomas Rast\ntrast@{inf,student}.ethz.ch\n"},{"id":"181624","messageId":"878vm4lb9q.fsf@fox.patthoyts.tk","threadId":"29235","inReplyTo":"87mxalkn9q.fsf@thomas.inf.ethz.ch","subject":"Re: Warning from AV software about kill.exe","fromName":"Pat Thoyts","fromEmail":"patthoyts@users.sourceforge.net","sentAt":"2011-12-22T18:19:29Z","receivedAt":"2011-12-22T18:19:29Z","isPatch":false,"sender":{"key":"patthoyts@users.sourceforge.net","avatar":"https://avatars.githubusercontent.com/u/30739?v=4"},"body":"Thomas Rast <trast@student.ethz.ch> writes:\n\n>Erik Blake <erik@icefield.yk.ca> writes:\n>\n>> I'm running git under Win7 64. As I selected \"Repository|Visualize all\n>> branch history\" in the git gui, my AV software (Trustport) trapped the\n>> bin\\kill.exe program for \"trying to modify system global settings\n>> (time, timezone, registry quota, etc.)\"\n>>\n>> Does anyone know the details of this process and what it's function\n>> is? First time I've seen it, though I'm a relatively new user.\n>\n>'kill' is a standard unix utility that sends signals to processes, in\n>particular signals that cause the processes to exit or be killed\n>forcibly by the kernel, hence the name.  (I don't know how the windows\n>equivalent works under the hood, but presumably it's something similar.)\n>\n>git-gui and gitk use kill to terminate background worker processes that\n>are no longer needed because you closed the window their output would\n>have been displayed in, etc.\n\nYou might try replacing the command in the tcl scripts with 'exec\ntaskkill /f /pid $pid' and see if that avoids the error. taskkill is\npresent on XP and above as part of the OS distribution so shouldn't\nsuffer any AV complaints.\n\n-- \nPat Thoyts                            http://www.patthoyts.tk/\nPGP fingerprint 2C 6E 98 07 2C 59 C8 97  10 CE 11 E6 04 E0 B9 DD\n"},{"id":"181913","messageId":"4F0418B1.5050403@icefield.yk.ca","threadId":"29235","inReplyTo":"878vm4lb9q.fsf@fox.patthoyts.tk","subject":"Re: Warning from AV software about kill.exe","fromName":"Erik Blake","fromEmail":"erik@icefield.yk.ca","sentAt":"2012-01-04T09:15:29Z","receivedAt":"2012-01-04T09:15:29Z","isPatch":false,"sender":{"key":"erik@icefield.yk.ca","avatar":null},"body":"Another way to implement this (on Windows) would be for the git programs \nto tag themselves with a mutex. Then the \"kill\" program can determine \nwhich git programs are running and send them user-defined windows \nmessages to shut themselves down. Alternatively, you could send the \nprograms the standard windows WM_CLOSE message, but the OS or an AV \nprogram might still be troubled by that behaviour.\n\nThis is how we implement this type of behaviour in our windows programs. \nIt does not raise the ire of the OS or AV since you do not have one \nprocess trying to shut down another. It also bypasses all issues with \nprocess privileges etc.\n\nErik\n\nOn 2011-12-22 19:19, Pat Thoyts wrote:\n> Thomas Rast<trast@student.ethz.ch>  writes:\n>\n>> Erik Blake<erik@icefield.yk.ca>  writes:\n>>\n>>> I'm running git under Win7 64. As I selected \"Repository|Visualize all\n>>> branch history\" in the git gui, my AV software (Trustport) trapped the\n>>> bin\\kill.exe program for \"trying to modify system global settings\n>>> (time, timezone, registry quota, etc.)\"\n>>>\n>>> Does anyone know the details of this process and what it's function\n>>> is? First time I've seen it, though I'm a relatively new user.\n>> 'kill' is a standard unix utility that sends signals to processes, in\n>> particular signals that cause the processes to exit or be killed\n>> forcibly by the kernel, hence the name.  (I don't know how the windows\n>> equivalent works under the hood, but presumably it's something similar.)\n>>\n>> git-gui and gitk use kill to terminate background worker processes that\n>> are no longer needed because you closed the window their output would\n>> have been displayed in, etc.\n> You might try replacing the command in the tcl scripts with 'exec\n> taskkill /f /pid $pid' and see if that avoids the error. taskkill is\n> present on XP and above as part of the OS distribution so shouldn't\n> suffer any AV complaints.\n>\n"},{"id":"181986","messageId":"CABPQNSbd++dAOGu+5+WNMXzF6xtsdTpZq=xeXPbHwmxputXVRA@mail.gmail.com","threadId":"29235","inReplyTo":"4F0418B1.5050403@icefield.yk.ca","subject":"Re: Warning from AV software about kill.exe","fromName":"Erik Faye-Lund","fromEmail":"kusmabite@gmail.com","sentAt":"2012-01-05T16:33:25Z","receivedAt":"2012-01-05T16:33:25Z","isPatch":false,"sender":{"key":"kusmabite@gmail.com","avatar":"https://avatars.githubusercontent.com/u/47073?v=4"},"body":"On Wed, Jan 4, 2012 at 10:15 AM, Erik Blake <erik@icefield.yk.ca> wrote:\n> On 2011-12-22 19:19, Pat Thoyts wrote:\n>> Thomas Rast<trast@student.ethz.ch>  writes:\n>>> Erik Blake<erik@icefield.yk.ca>  writes:\n>>>\n>>>> I'm running git under Win7 64. As I selected \"Repository|Visualize all\n>>>> branch history\" in the git gui, my AV software (Trustport) trapped the\n>>>> bin\\kill.exe program for \"trying to modify system global settings\n>>>> (time, timezone, registry quota, etc.)\"\n>>>>\n>>>> Does anyone know the details of this process and what it's function\n>>>> is? First time I've seen it, though I'm a relatively new user.\n>>>\n>>> 'kill' is a standard unix utility that sends signals to processes, in\n>>> particular signals that cause the processes to exit or be killed\n>>> forcibly by the kernel, hence the name.  (I don't know how the windows\n>>> equivalent works under the hood, but presumably it's something similar.)\n>>>\n>>> git-gui and gitk use kill to terminate background worker processes that\n>>> are no longer needed because you closed the window their output would\n>>> have been displayed in, etc.\n>>\n>> You might try replacing the command in the tcl scripts with 'exec\n>> taskkill /f /pid $pid' and see if that avoids the error. taskkill is\n>> present on XP and above as part of the OS distribution so shouldn't\n>> suffer any AV complaints.\n>>\n>\n> Another way to implement this (on Windows) would be for the git programs to\n> tag themselves with a mutex. Then the \"kill\" program can determine which git\n> programs are running and send them user-defined windows messages to shut\n> themselves down. Alternatively, you could send the programs the standard\n> windows WM_CLOSE message, but the OS or an AV program might still be\n> troubled by that behaviour.\n>\n> This is how we implement this type of behaviour in our windows programs. It\n> does not raise the ire of the OS or AV since you do not have one process\n> trying to shut down another. It also bypasses all issues with process\n> privileges etc.\n>\n> Erik\n>\n\nNo thanks. A process is allowed to terminate another process on\nWindows (as long as they are running as the same user, and the access\ntoken has not been messed with). If your AV detects this and prevents\nit, then your AV is broken. Re-building a kind of cooperative process\ntermination for that reason is not the way forward.\n\nBut the problem might be that MSYS' kill does more than it's supposed\nto (or misbehaves in some other way). This is, however, something you\nshould take up with the MSYS developers, not the git development\ncommunity.\n\nI would take this up with Trustport support. Overly eager AV\nheuristics is a fairly common problem, and usually gets fixed quickly.\n"},{"id":"182023","messageId":"4F06FC7B.5010206@icefield.yk.ca","threadId":"29235","inReplyTo":"CABPQNSbd++dAOGu+5+WNMXzF6xtsdTpZq=xeXPbHwmxputXVRA@mail.gmail.com","subject":"Re: Warning from AV software about kill.exe","fromName":"Erik Blake","fromEmail":"erik@icefield.yk.ca","sentAt":"2012-01-06T13:51:55Z","receivedAt":"2012-01-06T13:51:55Z","isPatch":false,"sender":{"key":"erik@icefield.yk.ca","avatar":null},"body":"\n\nOn 2012-01-05 17:33, Erik Faye-Lund wrote:\n> On Wed, Jan 4, 2012 at 10:15 AM, Erik Blake<erik@icefield.yk.ca>  wrote:\n>> On 2011-12-22 19:19, Pat Thoyts wrote:\n>>> Thomas Rast<trast@student.ethz.ch>    writes:\n>>>> Erik Blake<erik@icefield.yk.ca>    writes:\n>>>>\n>>>>> I'm running git under Win7 64. As I selected \"Repository|Visualize all\n>>>>> branch history\" in the git gui, my AV software (Trustport) trapped the\n>>>>> bin\\kill.exe program for \"trying to modify system global settings\n>>>>> (time, timezone, registry quota, etc.)\"\n>>>>>\n>>>>> Does anyone know the details of this process and what it's function\n>>>>> is? First time I've seen it, though I'm a relatively new user.\n>>>> 'kill' is a standard unix utility that sends signals to processes, in\n>>>> particular signals that cause the processes to exit or be killed\n>>>> forcibly by the kernel, hence the name.  (I don't know how the windows\n>>>> equivalent works under the hood, but presumably it's something similar.)\n>>>>\n>>>> git-gui and gitk use kill to terminate background worker processes that\n>>>> are no longer needed because you closed the window their output would\n>>>> have been displayed in, etc.\n>>> You might try replacing the command in the tcl scripts with 'exec\n>>> taskkill /f /pid $pid' and see if that avoids the error. taskkill is\n>>> present on XP and above as part of the OS distribution so shouldn't\n>>> suffer any AV complaints.\n>>>\n>> Another way to implement this (on Windows) would be for the git programs to\n>> tag themselves with a mutex. Then the \"kill\" program can determine which git\n>> programs are running and send them user-defined windows messages to shut\n>> themselves down. Alternatively, you could send the programs the standard\n>> windows WM_CLOSE message, but the OS or an AV program might still be\n>> troubled by that behaviour.\n>>\n>> This is how we implement this type of behaviour in our windows programs. It\n>> does not raise the ire of the OS or AV since you do not have one process\n>> trying to shut down another. It also bypasses all issues with process\n>> privileges etc.\n>>\n>> Erik\n>>\n> No thanks. A process is allowed to terminate another process on\n> Windows (as long as they are running as the same user, and the access\n> token has not been messed with). If your AV detects this and prevents\n> it, then your AV is broken. Re-building a kind of cooperative process\n> termination for that reason is not the way forward.\n>\n> But the problem might be that MSYS' kill does more than it's supposed\n> to (or misbehaves in some other way). This is, however, something you\n> should take up with the MSYS developers, not the git development\n> community.\n>\n> I would take this up with Trustport support. Overly eager AV\n> heuristics is a fairly common problem, and usually gets fixed quickly.\n>\nEither solution should work, but \"trying to modify system global \nsettings (time, timezone, registry quota, etc.)\" suggests kill.exe is \noverstepping the requirements for terminating another process. As you \nsuggest, I'll send a note to the MSYS developers. Maybe also ask \nTrustport for details on that triggers this message.\n\ne.\n"}]}