Windows 7 - EWF and FBWF active at the same time

Asked By Armin on 14-Jul-11 04:19 AM
We already use FBWF and EWF with Windows XPE.
Recently we use WES7.
Now I found out, that it is possible to activate both, FBWF and EWF.
As a consequence of this there's no way to get one of both disabled.
I've tried all possible combination and restarted the machine x-times.
The system is cought in this configuration. Does anybody know how to get out of that?

The write filter will be used on many of our customers devices and it's usual business to switch the EWF/FBWF.
It could happen that the described case could happen.

Is this known bug in the write-filter?

Thank you in advance

Armin
Jitendra Faye replied to Armin on 14-Jul-11 04:22 AM
With the FBWF it should be a bit easier than with EWF to service updates on embedded devices. FBWF allows you to commit on file basis.

Since you know what your update contains (what files, directories, etc.) it is doable to implement that logic in your DUA script.

Here is the list of Fbwfmgr commands supported:
http://msdn2.microsoft.com/en-us/library/aa940817.aspx (the command you might be looking for are addexclusion/removeexclusion).

Or, better, use FbwfCommitFile API to commit particular files (from your own app, for instance):
http://msdn2.microsoft.com/en-us/library/aa940894.aspx

The "fbwfmgr /disable" should actually work.
Btw, here is relevant article in the docs that talks about servicing Fbwf protected devices:
http://msdn2.microsoft.com/en-us/library/aa940864.aspx.

Hope this will help you.
Radhika roy replied to Armin on 14-Jul-11 10:52 AM
EWF anf FBWF can be manipulated programmatically through teh EWf or FBWF
APIs (these ship with the embedded product), or through calling the cmd line
management tool EWFMGR.exe or FBWFMGR.exe.


These can be used to enable or disable the filter. However, every enable or
disable action will require a reboot, as the filter actions are implemented
on shutdown of the system.

Having the filter enables will certinaly reduce the likelihood of corruption
occurring when the system is unexpectedly shut down, but will not eliminate
the possiblity entirely.

Hope this will help you.
Armin replied to Radhika roy on 14-Jul-11 11:24 AM
Of course we use the these filters to prevent file corruption by shutting down uncorrectly.
But if customer want to make changes they have to switch sometimes protect or unprotect.

Never mind if we use a self-written tool that uses the API or the command line, it's possible to get the system in
a condition with no turning back. 
E.g. with two commands:
ewfmgr c: -enable
fbwfmgr /enable

...after a reboot both ewf and fbwf are active(it is of course contradictory to have both active)

...try it.

I don't understand why these two features are not locked against each other.
At least it should be possible to get out of this state.