Saturday, 11 March 2006

Development Tools for Windows CE and Windows Mobile

This is kind of a brain-dump. I get asked this a fair bit – which tools do you need to develop for Windows CE and/or Windows Mobile? (See here for the difference.)

Native code:

For Windows CE 3.0 custom platforms, Pocket PC 2000 and Pocket PC 2002: eMbedded Visual C++ 3.0. You cannot debug on these older devices using eVC 4.0; you can’t debug CE 4.x or later devices using eVC 3.0.

For Windows CE 4.x custom platforms: eMbedded Visual C++ 4.0. At least SP1 is required for CE 4.1, SP2 for CE 4.2, latest is SP4. SP1 and SP2 were mutually exclusive – if you installed SP2 you couldn’t develop for CE 4.1; this was rectified in SP3.

For Pocket PC 2003 (alternatively Windows Mobile 2003 for Pocket PC), Smartphone 2003 (Windows Mobile 2003 for Smartphone) and respective Second Editions: eVC 4.0 SP2 or later, or VS 2005.

For Windows CE 5.x custom platforms: eVC 4.0 SP4, or VS 2005. You will get link errors complaining about corrupt debug information if you use eVC 4.0 because the platforms are actually built using version 13.1 (VS2003–compatible) compilers while eVC 4.0 SP4 can only handle debug information from version 12.0 (VC 6.0–compatible) compilers, hence SP4 only includes 12.0 compilers.

For Windows Mobile 5.0: VS 2005 only. The SDKs do not install into eVC 4.0.

For whatever device you’re building for, you need the correct SDK. However, you will find that programs are binary-compatible across different CE platforms, if the APIs required by the program are present on the platform. Using the correct SDK ensures that you build for the correct processor type and don’t accidentally reference APIs that won’t be available at runtime.

Managed code:

.NET Compact Framework 1.0 is supported for Pocket PC 2002, Windows Mobile 2003 for Pocket PC, Windows Mobile 2003 for Smartphone and Windows Mobile 5.0, and custom CE 4.x platforms. For Pocket PC 2002 you must use VS.NET 2003; for Windows Mobile 5.0 you need VS 2005 (I think). For Windows Mobile 2003 you can use either, and I would strongly recommend using VS 2005 as soon as you can stand to convert your project. This will completely rewrite your resx files. Converting the project does not mean immediately upgrading to .NET Compact Framework 2.0, that’s a separate step.

.NET Compact Framework 2.0 requires VS 2005 and only runs on Windows Mobile 2003 for Pocket PC (not WM2003 Smartphone), and CE 5.0 and Windows Mobile 5.0 devices.

VS2005 requires ActiveSync 4.1, minimum, for deployment and debugging. I was originally annoyed at the loss of network synchronisation capability, but found that, if a wireless connection is present, you can begin a debugging session over USB and continue over wireless if you disconnect from the cradle or cable.

To complete the compatibility matrix, as far as I can see CF1.0’s SqlCeClient only works with SQL Server CE 2.0 while CF2.0’s only works with SQL Mobile 2005 (SQL Server 2005 Mobile Edition). If anyone knows different let me know.

Monday, 27 February 2006

I tried so hard

I tried so hard, but I was defeated.

I was looking to buy Joe Satriani’s new album, “Super Colossal”, from a genuine UK retailer – ideally actually a UK copy. First of all, it doesn’t look like this is getting a UK release, or at least if it is, there’s no official information on it.

OK, so it has to be an import. I look on Amazon UK, it’s there, I pre-order it. About a day later I get an email – they’re cancelling the order. So now I’m buying from CD-WOW instead. Since this is Sony USA, I hope it’s not too badly DRM infested (although I am of course running as a limited user).

If you’re interested, Joe’s podcasting a little about each track, plus a one minute (or so) preview of the track. Schedule: Monday/Wednesday/Friday. If you want the videos, you’ll need QuickTime 7. I’m using Media Player Classic plus ffdshow codecs.

Tuesday, 14 February 2006

Back in time

I’ve been meaning to switch around the samples of the band I was in, back in sixth form. This is an appropriate day to do it, because the song I’ve put up was written the day after Valentine’s in 1995, and it was written because of what happened.

Song: Torn In Two (MP3, 128kbps, 7.2MB, 7:53).

The song, basically, is about Dave having a crush on a girl in his music class, and her not being interested. He sent her a card, she sent him a note, and he was pretty cut up. He wrote some lyrics that night (first verse and chorus, if I remember right), the following morning he and Roger put together a chord sequence and basic vocal melody, then that afternoon I joined them to practice. After Roger had to leave, I added the second verse, and David and I put together the third. I took some of my inspiration from my own feelings at the time (yup, more unrequited crushing) and some from the note Dave received. There are harder things to take when you’re 17 than ‘I just want to be friends,’ but not all that many.

We practiced the song for about a week, then Dave called his guitar teacher and asked if, instead of a lesson, we could record it. Our then-drummer, James, couldn’t make it, so we had Nigel, the teacher, program a sequencer with a simple drum beat. Roger and Dave played together, with me singing a guide track, to get the keyboard track into the sequencer as well. Then Dave let it all out (and boy, did he let it out) on his lead guitar track – that’s all one take I think, or it might be two. I added the vocals, then we asked Nige to add a bass track for us. There’s a little ‘fill’ bit in the bassline where the fridge motor cut in and knocked the sequencer out for half a bar! A quick mix later and we had something. I can’t recall if Dave sent the girl in question a tape or not – he may well have!

I’m not sure if we were asked, or Dave asked, to perform Torn In Two at a school concert. The girl asked us not to, but by that point Dave had got over it a bit, so we did it anyway.

Six months later we had a new drummer, Chris, and returned to Nige’s studio to record four more tracks (among them, Survivor). We asked if we could add a new, live, drum track to Torn In Two. We found the tape, which had miraculously not been recorded over, but the sequencer program was gone: Roger had to re-record the keyboards. Nige programmed in a ‘click’ track for Chris to follow, since the sequencer timing data was still on the tape. I’m still amazed at just how well Chris was able to add drum fills building to some key parts in Dave’s solos.

I love this song. It’s my favourite of the ones we recorded. Now that I have my own guitar, it’s one of the songs I practice, although I’m only playing the chords in a semi-acoustic setup.

I’ve left Survivor up for the moment; I’ve re-encoded to 128kbps to save some space and download time.

Thursday, 2 February 2006

WeWare?

Eric Sink has a great article “Yours, Mine and Ours” in which he discusses different types of software:

“I claim here that there are three categories of software:

  • MeWare:  The developer creates software.  The developer uses it.  Nobody else does.
  • ThemWare:  The developer creates software.  Other people use it.  The developer does not.
  • UsWare:  The developer creates software.  Other people use it.  The developer uses it too.”

Can I add WeWare to that list? I define it as MeWare but for your own development team. This gives it a slightly larger audience – requiring a touch more thought than MeWare in user interface and usability, but not really requiring the robustness or even completeness of true UsWare.

I spend a fair chunk of my time on WeWare – libraries for helping to complete a project rather than actually writing the code that solves the customer’s problem. Of course I do a lot of that too.

We’re still having trouble pushing Meteor Server over the chasm from WeWare to UsWare (from an application-development point of view, at least – there are plenty of installations where we wrote the application). We might have a couple of customers now, but it remains to be seen whether they’re able to run with it themselves.

Why you should install and enable a firewall on your PC

…even if you have a hardware firewall/NAT/whatever.

Larry Osterman has a great post “Firewalls, a history lesson,” in which he makes an analogy to the first world war. An interesting read.

I should take up this fight with my colleagues again. They all think I’m crazy for running as a low-privileged user and having the XP SP2 software firewall on, but when one of the salesmen brings their horribly-infected notebooks into the office for me to disentangle, I’m glad of it.

I remain unconvinced of the merits of a two-way firewall: the trick is not to get the malware onto your PC in the first place. Two-way firewalls are pretty annoying whenever there’s a change to the client software you use; you only have to configure an incoming-only firewall when there’s a change to the services you provide. There’s a common problem in computer security – ensuring that you don’t train the user to just click ‘Yes’ all the time. That’s why the ‘enter root password for elevation’ prompts in Mac OS X worry me, especially since there doesn’t seem to be a way for the user to validate that the prompt came from a secure subsystem rather than J. Random Malware. I’m actually happier that the initial plan for Windows Vista is that “Consent Admins” will default to being presented simply with a dialog explaining the elevation, to which you click Permit to elevate or Deny to refuse.

Tuesday, 31 January 2006

Thursday, 12 January 2006

What's the difference between Windows Mobile 5.0 and Windows CE 5.0?

I got the following question in email today:

Can you please explain me the difference in windows CE 5.0 and windows mobile 5.0? Isn't windows 5.0 is based on windows CE 5.0? If yes then why is the development tools for these are different, i mean windows CE based applications can be developed using evc++ 4.0 but for WM 5.0 based application we need Visual Studio 5.0?

Well, I’ve kind of answered this question already. The only new thing to add is that Windows Mobile 5.0 for Pocket PCs is based on Windows CE 5.1 bits according to the About screen (Microsoft using pre-release versions of Windows CE in Windows Mobile again? That caused a boatload of trouble for Pocket PC 2000 and 2002 and I thought they’d finally got over it.)

As for the development tools question, don’t ask me – ask Microsoft. The simple answer is that they didn’t generate an eVC-compatible SDK therefore it doesn’t register with eVC 4.0 therefore you can’t select Windows Mobile 5.0 as a target. As to why they didn’t do this, who knows? Perhaps something to do with the old Platform Manager, which was not the most reliable of software (understating the case severely). Also, it appears that MFC 6.0/CE and ATL 3.0/CE are not supported for new development; they don’t ship with the SDK any more, although the DLLs do ship on the device I think.

Tuesday, 10 January 2006

Two more alleged WMF 'vulnerabilities' - but there's a problem with the 'exploit'...

A number of news sites are pointing to a post on the Bugtraq mailing list alleging more problems with Windows’ handling of the Windows Metafile format.

Just a quick recap on the original issue: I originally thought that this was simply a buffer overflow issue, but in fact it appears that it’s something different – that an intended feature can be used in an unintended way. As I said last time, a WMF file contains a sequence of GDI commands. One of the supported commands is the GDI Escape function, which allows the application programmer to pass additional commands to the graphics driver, which – because GDI is a unified screen and printing API – can be a printer driver. The exploit apparently uses the SETABORTPROC escape. This escape was intended to permit GDI to call the application back, periodically during printing, to determine whether the user had tried to abort the print job. The attacker can use the SETABORTPROC escape to point to another part of the WMF file which contains code, which will be executed by GDI. It’s a case of an overlooked feature with insufficient security protection, not a failure to correctly validate the input parameters – the parameters are valid.

To the new ‘vulnerability’. Here we are dealing with a malformed file. The attacker supplies sizes for some of the parameters which are larger than the amount of data supplied. There is no vulnerability here – all that happens is that Windows tries to copy more data than is supplied. When the source pointer goes off the end of the input buffer, it may encounter an unallocated page. When this occurs, an access violation exception occurs, which, unless the application has been written to guard against it, causes the application to crash.

Note that this cannot crash Windows itself. It can only crash the process performing the file parsing. Now, in many cases this will be Windows Explorer (explorer.exe) – but Explorer should restart after a crash (it always used to – I haven’t actually had a problem in a while so I don’t recall if it still does). If an attacker put a WMF malformed in this way on a website, and the user browsed to it, the browser would simply crash. So yes, it is a denial of service, of a sort, but it’s not a serious issue.

With this information in hand, Microsoft’s response seems pretty reasonable.

Don’t believe everything you read on Bugtraq.

Thursday, 5 January 2006

WMF vulnerability patch to be released early

2pm Pacific Time today. That’s 10pm GMT according to my handy World Clock app (recently updated to not crash if you’ve disabled automatic daylight saving adjustment).

Tuesday, 3 January 2006

Thoughts on the WMF vulnerability

OK, so we know there’s a zero-day vulnerability (i.e. one which was not reported to any security organisation or vendor before being exploited) out there which utilises a malformed WMF file to execute code on a victim’s computer. This is being termed a ‘remote code execution’ vulnerability – this term is now being used to cover any situation where an attacker could cause code to be executed, but doesn’t differentiate between a situation where this can be done by the attacker actively sending data over a network to the victim, and one (such as this) where the victim must request data from the attacker. However, the attacker can cause software executing on the victim computer to automatically request the bad data – in this case, for example, by sending an email message to the victim containing a suitably malformed image file, which will cause some email packages to automatically render (draw) the image when the message is displayed.

Firstly, what is a WMF file? It stands for Windows Metafile. That’s a pretty meaningless name. What it actually contains is just a sequence of commands – that map one-to-one to GDI API calls – for producing a drawing. The easiest way to construct a WMF is to use the CreateMetaFile API which produces a GDI drawing surface, a device context, and returns a handle to it, an HDC. Once you’ve finished drawing – using the regular GDI API calls – you then call CloseMetaFile which gives you a HMETAFILE. You can then draw the metafile again using PlayMetaFile. It appears that this API is the one which contains the vulnerability – that some part of the format is insufficiently checked and the attacker can therefore cause the processor’s instruction pointer to end up pointing at a part of the supplied file.

This does suggest that any application that renders WMF data using the PlayMetaFile API could be an attack vector. Because it is such a venerable format, many applications will support it. You can include WMF drawings in your Word documents. You can process WMF files in Paint Shop Pro.

The current advisory from Microsoft suggests unregistering the shimgvw.dll component. This component is responsible for much more than WMF rendering. It performs all thumbnail rendering in Windows Explorer for all the best-known filetypes. It provides the size and other information for the Task pane and status bar. It also implements the ‘Windows Picture and Fax Viewer’ frame that appears if you click Preview on the context menu for an image. Unregistering this DLL kills all this functionality – but it does not protect against the vulnerability in other applications which call PlayMetaFile (except those which use shimgvw.dll as a proxy, such as Internet Explorer). This is my supposition, anyway – I would be astonished if shimgvw.dll did not render WMF simply by calling PlayMetaFile, and likewise Enhanced Metafiles by calling PlayEnhMetaFile.

While WMF files are most often used in the filesystem for storing vector-based clip-art (one among many other formats), you can also find them used within other formats, because of the native OS support. For example, when copying a diagram from Visio to Word, you will find that the prerendered version of the diagram (used for a linked or embedded diagram when the diagram is not active) is a metafile – although in this case it is most likely an Enhanced Metafile. Whether the Enhanced Metafile format can also be exploited is an unknown.

How to stop TlbImp requiring admin privileges

It seems that the Type Library Importer tool, TlbImp.exe, sometimes needs administrative privileges to do its job, if you’re trying to create a Primary Interop Assembly (or otherwise a strong-named reference). At work today, even admin privileges weren’t enough – I’m not sure if something’s been broken after installing Visual Studio 2005 since it used to work fine. The error given is ‘Invalid strong name parameters specified.’

What seems to be required is that the strong-name-key needs to be added to a key container in order to be used, which TlbImp is doing for you behind the scenes. The container used by strong-name functions can be either a user or a machine container. The default seems to be a machine container (at least that’s been the case both here at home and at work).

You can switch to a user container using the following command from a Visual Studio command prompt (either from the Start Menu’s Visual Studio group, or by running vsvars32.bat from the Common7\Tools directory, or sdkvars.bat from the .NET Framework SDK Bin directory):

sn -m n

Having done this, you should no longer need administrative privileges to strongly-name an assembly.

Friday, 23 December 2005

This much laughing hurts

I don’t often end up laughing hysterically at musical instruments!

In today’s feeds, an article from the Annals of Improbable Research blog linked to a Mr. Jay C. Easton, who plays the saxophone. Well, not just the saxophone, since there are many different types. Many more than the traditional four.

Including this monster.

There are some very smart saxophone makers out there, and the sound is actually pretty good. Well, except for the very lowest notes. I’m sure you can guess what they sound like, but there are plenty of clips on Easton’s site and Mr Eppelsheim’s. Another player, Fred Bayer, has had his Tubax modified to play much higher notes too (click on Tubax under Music in the navigation frame – a direct link takes you to the German language site).

Thursday, 22 December 2005

Revisiting .NET CF Whinges

18 months ago, I wrote an article called “.NET CF whinging”. Now that Compact Framework 2.0 has been released, what’s been fixed?

  • I complained that only DrawLine was available, not DrawLines (which maps better to the underlying Polyline call). In .NET CF 2.0, you can now use DrawLines.
  • Previously, you could only create a one-pixel-wide pen. Now you can create pens of any width.
  • The System.Diagnostics.Process class has been added.
  • WaitHandle.WaitOne now offers a timeout overload. WaitAny is still missing.
  • Thread.Abort and Thread.Join are now present.
  • Control.InvokeRequired makes an appearance, and the Control.Invoke overload that takes an array of object parameters to pass to the delegate is now present. However, the documentation still contains a note that for .NET Compact Framework, you must use the EventHandler delegate, which only offers an empty EventArgs. This appears to be a documentation error – passing other delegate types and parameters does now work! The new BackgroundWorker class of the desktop Framework is not offered.

Rumour has it that the marshalling’s better in this version too.

HOWTO: Program Symbol MC3000 function keys

With my powers of intuition, I divine that someone out there needs to handle or program the function keys on the Symbol MC3000 device.

(Well, OK, it turned up in my referrer log – click the tracker icon at the bottom of the right-hand bar!)

The 28–key variant has F1 through F10 available through pressing the blue Func button and then the corresponding number key. The 38–key variant has F1 through F10 keys, then F11 through F14 on Func+F1 to Func+F4. The 48–key variant has F1 to F13 on Func+A to Func+M. (Nothing like consistency). When pressed, these will appear as VK_F1 through VK_F14 in your application’s WM_KEYDOWN and WM_KEYUP handlers or their equivalent in your environment (Control.KeyDown and Control.KeyUp events in the .NET Compact Framework, the value of KeyEventArgs.KeyCode will be Key.F1 through Key.F14).

That’s the default keyboard map. If you want to change the keyboard map, on any Symbol device, you need the Device Configuration Package for that device, which you can download from Symbol DevZone. In the package, you’ll find under Tools\kbtool a bunch of C++ files and a VC6 project. This is a program for your desktop computer which generates the keyboard map files. Open this with VC6 or later.

Each keyboard layout has (up to) three files associated with it – for the MC3000, MC3000KeynnM, R and S.cpp, where nn is the number of keys. The M file controls the multiple-press key operations, such as the mobile-phone-style input on the 28–key variant. The R file controls remapping key functions in different shift states. Finally the S file controls the scan code that’s output by each key – this is normally the one you want to edit. The available scan codes can be found in the accompanying ScanCode.h file.

Running the program generates the files that the keyboard driver is looking for. For the MC3000 these are named MC3000–{28,38,48}.{sct,rmt,mmt}. You can either overwrite these files in their normal location (\Platform\Keyboard) or modify the registry under HKLM\Hardware\DeviceMap\KEYBD to point to your version of the files.

We did this for New Look to make the two keys below the screen – with the red and green surrounds – perform ‘soft key’ functions in their applications.

Tuesday, 20 December 2005

Do I look old to you?

I met up with some of the people from Channel 9 last Saturday – Dave Oliver, Barry Dorrans, Sarah Blow and Richard Peat (and his lovely wife Beth, who I don’t think has her own blog). Richard’s already written it up here.

Separately, Dave and Barry both told me that I looked older than my tender years (ahem) of 27, and suggested that I get rid of my beard. Barry also reckoned the ponytail should go (can’t remember what Dave thought but he did admit he’d had one when younger!)

For comparison:

Passport Photo

What I looked like in 1998, the last photo I have to hand of me with short hair and no beard (digital snapshot of my passport photo!)

2004

What I looked like last year (taken at my friend’s wedding in Toppenish, WA, USA).

The length of hair and beard varies. I was short-haired and clean-shaven at my graduation ceremony in 2001 and frankly I thought I still looked a bit too young in the photo (and very pale!) I’ve been letting the hair grow pretty much since then and it now just reaches the small of my back. I trim my beard every few weeks, normally when it starts itching too much – it’s quite short right now as you can see in Richard’s picture from Saturday where we’re attempting to play Barry’s card game Fluxx while waiting for food and/or Ian to arrive.

So, should I follow their advice?

Can the Windows Vista Network Map Control Panel detect a non-functioning switch?

Adam Nathan blogged today about some new features in the Windows Vista December CTP. One of them is a new Control Panel applet: Network Map.

Network Map applet

At work we commonly have problems with our switched network fabric. Sometimes after a power failure (a regrettably common occurrence at our location) the cheap 5-port switches at each desk will give all the signs of working, but not actually forward network frames – quite literally, “the lights are on, but no-one’s home.” Only power-cycling them gets them working again. Unfortunately there are chains of these in some places before reaching one of the wall sockets which connects to the main switch.

We also have a problem where, if one particular machine is switched on and connected, the entire LAN seems to go nuts, intermittently or permanently causing some routes to fail, unpredictably. We think this is due to the switches’ internal mapping of MAC addresses to ports somehow becoming incorrect, and forwarding packets to the wrong ports, or not at all. This is a mystery to all of us, especially since we’ve replaced the network card with a different model, tried it with different operating systems, tried it on a different wall socket, and repatched the wall socket/main switch connection. Nothing helps! If you have any ideas, leave a comment!

If this Network Map can tell you which device seems to be malfunctioning, that would be a serious boost to network administrators everywhere.

Monday, 19 December 2005

Idiotic things to do

Look on Flickr for your own photos, from the machine you uploaded them from.

Doh!

Sunday, 18 December 2005

The two-minute Xbox 360 and PGR3 review

I’m underwhelmed.

OK, that evaluation is based on playing a guy for one race on multiplayer on a demo pod yesterday. The shop was pretty loud and the console quiet, which made it not very involving. The rumble didn’t feel that great. The graphics are better than the current generation but actually not that much better than PGR2 – but I had a one foot view, not a ten foot view since the controllers are hard-attached to the pod. I think the screen was set up correctly but I don’t actually know.

We were lost in the game’s UI. Very lost. We ended up having a race with one computer car which zoomed off into the distance – and that was only on Medium skill. I lost – I kept crashing into the corners due to the lack of feedback from the game (audio and rumble), and lost when I crashed into the last corner on the last lap. I lost so badly that I didn’t even reach the finish line before the 30 second timer ran out after the computer car crossed the line (hence ending the game).

Maybe I should go back when it’s quieter and have a go at Career Mode.

Wednesday, 14 December 2005

Coining a word

horricious (adj): Mind-numbingly awful. Descriptive of the speed of Microsoft’s first attempt at a ‘real’ Windows CE emulator.

A colleague asked if there was an emulator for one of Symbol’s hand-helds – a customer wanted to evaluate it with some software. While eVC 4.0 and VS.NET 2003 do ship an emulation platform, and Symbol supplies an emulator image for this platform, it is pretty slow. In describing this emulator to my colleague, I inadvertently coined this word. I’d just used ‘horrible’ and ‘horrendous’ and was searching for a third – lists of three, you know – and somehow got ‘horrific’ and ‘atrocious’ mangled together.

Oops.

The Pocket PC 2000 emulator, and earlier Windows CE emulators, ran weirdly compiled x86 code inside an app running on top of Windows. Stable it was not, and it didn’t emulate a CE device at all accurately. This made it completely unusable for actually developing apps.

The Pocket PC 2002 and later emulators were a little better. Now they were based on Connectix’ Virtual PC technology, which virtualises your PC’s processor and other resources (Microsoft bought out Connectix soon after). Unfortunately that’s still a virtualised x86, which is different from the actual Pocket PC 2002 devices, which use ARM processors. The result is that you had to do a special build for the emulator, meaning again that you’re not testing the same code you’re going to ship – and it was very hard to get libraries built for the emulator.

Windows CE on the x86 has always been a slug – Microsoft have never really taken it seriously as a platform, most hand-helds using MIPS or SH3 to begin with, then later ARM. Virtual PC wasn’t really designed to run Windows CE. Putting some form of Additions on the image would have been a) hard and b) defeated the object a little.

Visual Studio 2005 (at least, some editions) includes the Microsoft Device Emulator 1.0. This, finally, emulates an ARM processor. And you know what? It’s quicker than the virtualised x86! At last, it’s possible to use virtually a real OS image and real binaries in an emulated environment.

It’s still quite a bit slower than a real device though, even a 400MHz PXA255.

A rant on programming books

Matt Pietrek – he of the erstwhile MSDN Magazine column ‘Under The Hood’ – has an interesting post:

In a nut shell, there are a lot of books out there, and people are relying on them less and less as search engines become the dominant way to find information. It's pretty hard to pour massive amounts of work into something when you know most people just want the code snippet that gets them past their current problem. No actual learning required.

 ...and then they have no idea how the code works, so cannot adapt it to new requirements, or debug it when it doesn't work.

To me, a good tutorial is worth a thousand times a code snippet - although I do find that often MS Press books (at least, of a certain vintage) will print the entire source of a sample program which leads to the new stuff being lost among the boilerplate.

How new Windows programmers are supposed to learn what's going on when truly excellent books like Jeff Richter's "Programming Applications for Windows" go out of print I don't know. All abstractions leak, and I think you're better off understanding what leaks through the abstraction.

I only really ‘got’ MFC once I’d read “MFC Internals”, and understood the boilerplate that Visual Studio generates for a new MFC project.