5 #include <pseh/pseh2.h>
7 #define CACHEPAGESIZE(pDeviceExt) \
8 ((pDeviceExt)->NtfsInfo.UCHARsPerCluster > PAGE_SIZE ? \
9 (pDeviceExt)->NtfsInfo.UCHARsPerCluster : PAGE_SIZE)
11 #define TAG_NTFS 'SFTN'
13 #define ROUND_UP(N, S) ((((N) + (S) - 1) / (S)) * (S))
14 #define ROUND_DOWN(N, S) ((N) - ((N) % (S)))
16 #define DEVICE_NAME L"\\Ntfs"
19 typedef struct _BIOS_PARAMETERS_BLOCK
21 USHORT BytesPerSector
; // 0x0B
22 UCHAR SectorsPerCluster
; // 0x0D
23 UCHAR Unused0
[7]; // 0x0E, checked when volume is mounted
24 UCHAR MediaId
; // 0x15
25 UCHAR Unused1
[2]; // 0x16
26 USHORT SectorsPerTrack
; // 0x18
28 UCHAR Unused2
[4]; // 0x1C
29 UCHAR Unused3
[4]; // 0x20, checked when volume is mounted
30 } BIOS_PARAMETERS_BLOCK
, *PBIOS_PARAMETERS_BLOCK
;
32 typedef struct _EXTENDED_BIOS_PARAMETERS_BLOCK
34 USHORT Unknown
[2]; // 0x24, always 80 00 80 00
35 ULONGLONG SectorCount
; // 0x28
36 ULONGLONG MftLocation
; // 0x30
37 ULONGLONG MftMirrLocation
; // 0x38
38 CHAR ClustersPerMftRecord
; // 0x40
39 UCHAR Unused4
[3]; // 0x41
40 CHAR ClustersPerIndexRecord
; // 0x44
41 UCHAR Unused5
[3]; // 0x45
42 ULONGLONG SerialNumber
; // 0x48
43 UCHAR Checksum
[4]; // 0x50
44 } EXTENDED_BIOS_PARAMETERS_BLOCK
, *PEXTENDED_BIOS_PARAMETERS_BLOCK
;
46 typedef struct _BOOT_SECTOR
48 UCHAR Jump
[3]; // 0x00
49 UCHAR OEMID
[8]; // 0x03
50 BIOS_PARAMETERS_BLOCK BPB
;
51 EXTENDED_BIOS_PARAMETERS_BLOCK EBPB
;
52 UCHAR BootStrap
[426]; // 0x54
53 USHORT EndSector
; // 0x1FE
54 } BOOT_SECTOR
, *PBOOT_SECTOR
;
57 //typedef struct _BootSector BootSector;
59 typedef struct _NTFS_INFO
62 ULONG SectorsPerCluster
;
63 ULONG BytesPerCluster
;
64 ULONGLONG SectorCount
;
65 ULONGLONG ClusterCount
;
66 ULARGE_INTEGER MftStart
;
67 ULARGE_INTEGER MftMirrStart
;
68 ULONG BytesPerFileRecord
;
69 ULONG BytesPerIndexRecord
;
71 ULONGLONG SerialNumber
;
72 USHORT VolumeLabelLength
;
73 WCHAR VolumeLabel
[MAXIMUM_VOLUME_LABEL_LENGTH
];
78 ULONG MftZoneReservation
;
79 } NTFS_INFO
, *PNTFS_INFO
;
81 #define NTFS_TYPE_CCB '20SF'
82 #define NTFS_TYPE_FCB '30SF'
83 #define NTFS_TYPE_VCB '50SF'
84 #define NTFS_TYPE_IRP_CONTEST '60SF'
85 #define NTFS_TYPE_GLOBAL_DATA '70SF'
91 } NTFSIDENTIFIER
, *PNTFSIDENTIFIER
;
95 NTFSIDENTIFIER Identifier
;
97 ERESOURCE DirResource
;
98 // ERESOURCE FatResource;
100 KSPIN_LOCK FcbListLock
;
101 LIST_ENTRY FcbListHead
;
104 PDEVICE_OBJECT StorageDevice
;
105 PFILE_OBJECT StreamFileObject
;
107 struct _NTFS_ATTR_CONTEXT
* MFTContext
;
108 struct _FILE_RECORD_HEADER
* MasterFileTable
;
109 struct _FCB
*VolumeFcb
;
113 } DEVICE_EXTENSION
, *PDEVICE_EXTENSION
, NTFS_VCB
, *PNTFS_VCB
;
117 NTFSIDENTIFIER Identifier
;
119 PFILE_OBJECT PtrFileObject
;
120 LARGE_INTEGER CurrentByteOffset
;
121 /* for DirectoryControl */
123 /* for DirectoryControl */
124 PWCHAR DirectorySearchPattern
;
127 } NTFS_CCB
, *PNTFS_CCB
;
129 #define TAG_CCB 'BCCI'
130 #define TAG_FCB 'BCFI'
134 NTFSIDENTIFIER Identifier
;
136 PDRIVER_OBJECT DriverObject
;
137 PDEVICE_OBJECT DeviceObject
;
138 CACHE_MANAGER_CALLBACKS CacheMgrCallbacks
;
140 FAST_IO_DISPATCH FastIoDispatch
;
141 NPAGED_LOOKASIDE_LIST IrpContextLookasideList
;
142 NPAGED_LOOKASIDE_LIST FcbLookasideList
;
143 } NTFS_GLOBAL_DATA
, *PNTFS_GLOBAL_DATA
;
148 AttributeStandardInformation
= 0x10,
149 AttributeAttributeList
= 0x20,
150 AttributeFileName
= 0x30,
151 AttributeObjectId
= 0x40,
152 AttributeSecurityDescriptor
= 0x50,
153 AttributeVolumeName
= 0x60,
154 AttributeVolumeInformation
= 0x70,
155 AttributeData
= 0x80,
156 AttributeIndexRoot
= 0x90,
157 AttributeIndexAllocation
= 0xA0,
158 AttributeBitmap
= 0xB0,
159 AttributeReparsePoint
= 0xC0,
160 AttributeEAInformation
= 0xD0,
162 AttributePropertySet
= 0xF0,
163 AttributeLoggedUtilityStream
= 0x100,
164 AttributeEnd
= 0xFFFFFFFF
165 } ATTRIBUTE_TYPE
, *PATTRIBUTE_TYPE
;
167 #define NTFS_FILE_MFT 0
168 #define NTFS_FILE_MFTMIRR 1
169 #define NTFS_FILE_LOGFILE 2
170 #define NTFS_FILE_VOLUME 3
171 #define NTFS_FILE_ATTRDEF 4
172 #define NTFS_FILE_ROOT 5
173 #define NTFS_FILE_BITMAP 6
174 #define NTFS_FILE_BOOT 7
175 #define NTFS_FILE_BADCLUS 8
176 #define NTFS_FILE_QUOTA 9
177 #define NTFS_FILE_UPCASE 10
178 #define NTFS_FILE_EXTEND 11
180 #define NTFS_MFT_MASK 0x0000FFFFFFFFFFFFULL
182 #define COLLATION_BINARY 0x00
183 #define COLLATION_FILE_NAME 0x01
184 #define COLLATION_UNICODE_STRING 0x02
185 #define COLLATION_NTOFS_ULONG 0x10
186 #define COLLATION_NTOFS_SID 0x11
187 #define COLLATION_NTOFS_SECURITY_HASH 0x12
188 #define COLLATION_NTOFS_ULONGS 0x13
190 #define INDEX_ROOT_SMALL 0x0
191 #define INDEX_ROOT_LARGE 0x1
193 #define NTFS_INDEX_ENTRY_NODE 1
194 #define NTFS_INDEX_ENTRY_END 2
196 #define NTFS_FILE_NAME_POSIX 0
197 #define NTFS_FILE_NAME_WIN32 1
198 #define NTFS_FILE_NAME_DOS 2
199 #define NTFS_FILE_NAME_WIN32_AND_DOS 3
201 #define NTFS_FILE_TYPE_READ_ONLY 0x1
202 #define NTFS_FILE_TYPE_HIDDEN 0x2
203 #define NTFS_FILE_TYPE_SYSTEM 0x4
204 #define NTFS_FILE_TYPE_ARCHIVE 0x20
205 #define NTFS_FILE_TYPE_REPARSE 0x400
206 #define NTFS_FILE_TYPE_COMPRESSED 0x800
207 #define NTFS_FILE_TYPE_DIRECTORY 0x10000000
211 ULONG Type
; /* Magic number 'FILE' */
212 USHORT UsaOffset
; /* Offset to the update sequence */
213 USHORT UsaCount
; /* Size in words of Update Sequence Number & Array (S) */
214 ULONGLONG Lsn
; /* $LogFile Sequence Number (LSN) */
215 } NTFS_RECORD_HEADER
, *PNTFS_RECORD_HEADER
;
217 /* NTFS_RECORD_HEADER.Type */
218 #define NRH_FILE_TYPE 0x454C4946 /* 'FILE' */
219 #define NRH_INDX_TYPE 0x58444E49 /* 'INDX' */
222 typedef struct _FILE_RECORD_HEADER
224 NTFS_RECORD_HEADER Ntfs
;
225 USHORT SequenceNumber
; /* Sequence number */
226 USHORT LinkCount
; /* Hard link count */
227 USHORT AttributeOffset
; /* Offset to the first Attribute */
228 USHORT Flags
; /* Flags */
229 ULONG BytesInUse
; /* Real size of the FILE record */
230 ULONG BytesAllocated
; /* Allocated size of the FILE record */
231 ULONGLONG BaseFileRecord
; /* File reference to the base FILE record */
232 USHORT NextAttributeNumber
; /* Next Attribute Id */
233 USHORT Pading
; /* Align to 4 UCHAR boundary (XP) */
234 ULONG MFTRecordNumber
; /* Number of this MFT Record (XP) */
235 } FILE_RECORD_HEADER
, *PFILE_RECORD_HEADER
;
237 /* Flags in FILE_RECORD_HEADER */
239 #define FRH_IN_USE 0x0001 /* Record is in use */
240 #define FRH_DIRECTORY 0x0002 /* Record is a directory */
241 #define FRH_UNKNOWN1 0x0004 /* Don't know */
242 #define FRH_UNKNOWN2 0x0008 /* Don't know */
255 // Resident attributes
263 // Non-resident attributes
267 ULONGLONG HighestVCN
;
268 USHORT MappingPairsOffset
;
269 USHORT CompressionUnit
;
271 LONGLONG AllocatedSize
;
273 LONGLONG InitializedSize
;
274 LONGLONG CompressedSize
;
277 } NTFS_ATTR_RECORD
, *PNTFS_ATTR_RECORD
;
281 ULONGLONG CreationTime
;
282 ULONGLONG ChangeTime
;
283 ULONGLONG LastWriteTime
;
284 ULONGLONG LastAccessTime
;
286 ULONG AlignmentOrReserved
[3];
290 ULONGLONG QuotaCharge
;
293 } STANDARD_INFORMATION
, *PSTANDARD_INFORMATION
;
298 ATTRIBUTE_TYPE AttributeType
;
302 ULONGLONG StartVcn
; // LowVcn
303 ULONGLONG FileReferenceNumber
;
304 USHORT AttributeNumber
;
305 USHORT AlignmentOrReserved
[3];
306 } ATTRIBUTE_LIST
, *PATTRIBUTE_LIST
;
311 ULONGLONG DirectoryFileReferenceNumber
;
312 ULONGLONG CreationTime
;
313 ULONGLONG ChangeTime
;
314 ULONGLONG LastWriteTime
;
315 ULONGLONG LastAccessTime
;
316 ULONGLONG AllocatedSize
;
318 ULONG FileAttributes
;
324 USHORT AlignmentOrReserved
;
331 } FILENAME_ATTRIBUTE
, *PFILENAME_ATTRIBUTE
;
335 ULONG FirstEntryOffset
;
336 ULONG TotalSizeOfEntries
;
340 } INDEX_HEADER_ATTRIBUTE
, *PINDEX_HEADER_ATTRIBUTE
;
347 UCHAR ClustersPerIndexRecord
;
349 INDEX_HEADER_ATTRIBUTE Header
;
350 } INDEX_ROOT_ATTRIBUTE
, *PINDEX_ROOT_ATTRIBUTE
;
354 NTFS_RECORD_HEADER Ntfs
;
356 INDEX_HEADER_ATTRIBUTE Header
;
357 } INDEX_BUFFER
, *PINDEX_BUFFER
;
365 ULONGLONG IndexedFile
;
378 FILENAME_ATTRIBUTE FileName
;
379 } INDEX_ENTRY_ATTRIBUTE
, *PINDEX_ENTRY_ATTRIBUTE
;
388 } VOLINFO_ATTRIBUTE
, *PVOLINFO_ATTRIBUTE
;
395 } REPARSE_POINT_ATTRIBUTE
, *PREPARSE_POINT_ATTRIBUTE
;
397 #define IRPCONTEXT_CANWAIT 0x1
398 #define IRPCONTEXT_COMPLETE 0x2
399 #define IRPCONTEXT_QUEUE 0x4
403 NTFSIDENTIFIER Identifier
;
405 PIO_STACK_LOCATION Stack
;
408 WORK_QUEUE_ITEM WorkQueueItem
;
411 PDEVICE_OBJECT DeviceObject
;
412 PFILE_OBJECT FileObject
;
413 NTSTATUS SavedExceptionCode
;
415 } NTFS_IRP_CONTEXT
, *PNTFS_IRP_CONTEXT
;
417 typedef struct _NTFS_ATTR_CONTEXT
420 ULONGLONG CacheRunOffset
;
421 LONGLONG CacheRunStartLCN
;
422 ULONGLONG CacheRunLength
;
423 LONGLONG CacheRunLastLCN
;
424 ULONGLONG CacheRunCurrentOffset
;
425 NTFS_ATTR_RECORD Record
;
426 } NTFS_ATTR_CONTEXT
, *PNTFS_ATTR_CONTEXT
;
428 #define FCB_CACHE_INITIALIZED 0x0001
429 #define FCB_IS_VOLUME_STREAM 0x0002
430 #define FCB_IS_VOLUME 0x0004
435 NTFSIDENTIFIER Identifier
;
437 FSRTL_COMMON_FCB_HEADER RFCB
;
438 SECTION_OBJECT_POINTERS SectionObjectPointers
;
440 PFILE_OBJECT FileObject
;
443 WCHAR Stream
[MAX_PATH
];
444 WCHAR
*ObjectName
; /* point on filename (250 chars max) in PathName */
445 WCHAR PathName
[MAX_PATH
]; /* path+filename 260 max */
447 ERESOURCE PagingIoResource
;
448 ERESOURCE MainResource
;
450 LIST_ENTRY FcbListEntry
;
451 struct _FCB
* ParentFcb
;
461 FILENAME_ATTRIBUTE Entry
;
463 } NTFS_FCB
, *PNTFS_FCB
;
465 extern PNTFS_GLOBAL_DATA NtfsGlobalData
;
469 NtfsMarkIrpContextForQueue(PNTFS_IRP_CONTEXT IrpContext
)
471 PULONG Flags
= &IrpContext
->Flags
;
473 *Flags
&= ~IRPCONTEXT_COMPLETE
;
474 *Flags
|= IRPCONTEXT_QUEUE
;
476 return STATUS_PENDING
;
482 //NtfsDumpAttribute(PATTRIBUTE Attribute);
485 DecodeRun(PUCHAR DataRun
,
486 LONGLONG
*DataRunOffset
,
487 ULONGLONG
*DataRunLength
);
490 NtfsDumpFileAttributes(PDEVICE_EXTENSION Vcb
, PFILE_RECORD_HEADER FileRecord
);
492 PSTANDARD_INFORMATION
493 GetStandardInformationFromRecord(PFILE_RECORD_HEADER FileRecord
);
496 GetFileNameFromRecord(PFILE_RECORD_HEADER FileRecord
, UCHAR NameType
);
499 GetBestFileNameFromRecord(PFILE_RECORD_HEADER FileRecord
);
504 NtfsReadDisk(IN PDEVICE_OBJECT DeviceObject
,
505 IN LONGLONG StartingOffset
,
508 IN OUT PUCHAR Buffer
,
509 IN BOOLEAN Override
);
512 NtfsReadSectors(IN PDEVICE_OBJECT DeviceObject
,
514 IN ULONG SectorCount
,
516 IN OUT PUCHAR Buffer
,
517 IN BOOLEAN Override
);
520 NtfsDeviceIoControl(IN PDEVICE_OBJECT DeviceObject
,
521 IN ULONG ControlCode
,
522 IN PVOID InputBuffer
,
523 IN ULONG InputBufferSize
,
524 IN OUT PVOID OutputBuffer
,
525 IN OUT PULONG OutputBufferSize
,
526 IN BOOLEAN Override
);
532 NtfsCloseFile(PDEVICE_EXTENSION DeviceExt
,
533 PFILE_OBJECT FileObject
);
536 NtfsClose(PNTFS_IRP_CONTEXT IrpContext
);
542 NtfsCreate(PNTFS_IRP_CONTEXT IrpContext
);
548 NtfsDeviceControl(PNTFS_IRP_CONTEXT IrpContext
);
554 NtfsGetFileSize(PDEVICE_EXTENSION DeviceExt
,
555 PFILE_RECORD_HEADER FileRecord
,
558 PULONGLONG AllocatedSize
);
561 NtfsDirectoryControl(PNTFS_IRP_CONTEXT IrpContext
);
566 DRIVER_DISPATCH NtfsFsdDispatch
;
568 NtfsFsdDispatch(PDEVICE_OBJECT DeviceObject
,
575 NtfsAcqLazyWrite(PVOID Context
,
579 NtfsRelLazyWrite(PVOID Context
);
582 NtfsAcqReadAhead(PVOID Context
,
586 NtfsRelReadAhead(PVOID Context
);
588 FAST_IO_CHECK_IF_POSSIBLE NtfsFastIoCheckIfPossible
;
589 FAST_IO_READ NtfsFastIoRead
;
590 FAST_IO_WRITE NtfsFastIoWrite
;
596 NtfsCreateFCB(PCWSTR FileName
,
601 NtfsDestroyFCB(PNTFS_FCB Fcb
);
604 NtfsFCBIsDirectory(PNTFS_FCB Fcb
);
607 NtfsFCBIsReparsePoint(PNTFS_FCB Fcb
);
610 NtfsFCBIsRoot(PNTFS_FCB Fcb
);
613 NtfsGrabFCB(PNTFS_VCB Vcb
,
617 NtfsReleaseFCB(PNTFS_VCB Vcb
,
621 NtfsAddFCBToTable(PNTFS_VCB Vcb
,
625 NtfsGrabFCBFromTable(PNTFS_VCB Vcb
,
629 NtfsFCBInitializeCache(PNTFS_VCB Vcb
,
633 NtfsMakeRootFCB(PNTFS_VCB Vcb
);
636 NtfsOpenRootFCB(PNTFS_VCB Vcb
);
639 NtfsAttachFCBToFileObject(PNTFS_VCB Vcb
,
641 PFILE_OBJECT FileObject
);
644 NtfsGetFCBForFile(PNTFS_VCB Vcb
,
645 PNTFS_FCB
*pParentFCB
,
647 const PWSTR pFileName
);
650 NtfsReadFCBAttribute(PNTFS_VCB Vcb
,
658 NtfsMakeFCBFromDirEntry(PNTFS_VCB Vcb
,
659 PNTFS_FCB DirectoryFCB
,
660 PUNICODE_STRING Name
,
662 PFILE_RECORD_HEADER Record
,
664 PNTFS_FCB
* fileFCB
);
670 NtfsQueryInformation(PNTFS_IRP_CONTEXT IrpContext
);
676 NtfsFileSystemControl(PNTFS_IRP_CONTEXT IrpContext
);
681 PrepareAttributeContext(PNTFS_ATTR_RECORD AttrRecord
);
684 ReleaseAttributeContext(PNTFS_ATTR_CONTEXT Context
);
687 ReadAttribute(PDEVICE_EXTENSION Vcb
,
688 PNTFS_ATTR_CONTEXT Context
,
694 AttributeDataLength(PNTFS_ATTR_RECORD AttrRecord
);
697 AttributeAllocatedLength(PNTFS_ATTR_RECORD AttrRecord
);
700 ReadFileRecord(PDEVICE_EXTENSION Vcb
,
702 PFILE_RECORD_HEADER file
);
705 FindAttribute(PDEVICE_EXTENSION Vcb
,
706 PFILE_RECORD_HEADER MftRecord
,
710 PNTFS_ATTR_CONTEXT
* AttrCtx
);
713 ReadVCN(PDEVICE_EXTENSION Vcb
,
714 PFILE_RECORD_HEADER file
,
721 FixupUpdateSequenceArray(PDEVICE_EXTENSION Vcb
,
722 PNTFS_RECORD_HEADER Record
);
725 ReadLCN(PDEVICE_EXTENSION Vcb
,
731 EnumerAttribute(PFILE_RECORD_HEADER file
,
732 PDEVICE_EXTENSION Vcb
,
733 PDEVICE_OBJECT DeviceObject
);
736 NtfsLookupFile(PDEVICE_EXTENSION Vcb
,
737 PUNICODE_STRING PathName
,
738 PFILE_RECORD_HEADER
*FileRecord
,
739 PULONGLONG MFTIndex
);
742 NtfsLookupFileAt(PDEVICE_EXTENSION Vcb
,
743 PUNICODE_STRING PathName
,
744 PFILE_RECORD_HEADER
*FileRecord
,
746 ULONGLONG CurrentMFTIndex
);
749 NtfsFindFileAt(PDEVICE_EXTENSION Vcb
,
750 PUNICODE_STRING SearchPattern
,
752 PFILE_RECORD_HEADER
*FileRecord
,
754 ULONGLONG CurrentMFTIndex
);
759 NtfsIsIrpTopLevel(PIRP Irp
);
762 NtfsAllocateIrpContext(PDEVICE_OBJECT DeviceObject
,
766 NtfsGetUserBuffer(PIRP Irp
,
771 wstrcmpjoki(PWSTR s1
, PWSTR s2
);
774 CdfsSwapString(PWCHAR Out
,
780 NtfsFileFlagsToAttributes(ULONG NtfsAttributes
,
781 PULONG FileAttributes
);
787 NtfsRead(PNTFS_IRP_CONTEXT IrpContext
);
790 NtfsWrite(PNTFS_IRP_CONTEXT IrpContext
);
796 NtfsGetFreeClusters(PDEVICE_EXTENSION DeviceExt
);
799 NtfsQueryVolumeInformation(PNTFS_IRP_CONTEXT IrpContext
);
802 NtfsSetVolumeInformation(PNTFS_IRP_CONTEXT IrpContext
);
807 DRIVER_INITIALIZE DriverEntry
;
811 NtfsInitializeFunctionPointers(PDRIVER_OBJECT DriverObject
);