5 #include <pseh/pseh2.h>
8 #define INIT_SECTION __attribute__((section ("INIT")))
10 #define INIT_SECTION /* Done via alloc_text for MSC */
13 #define CACHEPAGESIZE(pDeviceExt) \
14 ((pDeviceExt)->NtfsInfo.UCHARsPerCluster > PAGE_SIZE ? \
15 (pDeviceExt)->NtfsInfo.UCHARsPerCluster : PAGE_SIZE)
17 #define TAG_NTFS 'SFTN'
19 #define ROUND_UP(N, S) ((((N) + (S) - 1) / (S)) * (S))
20 #define ROUND_DOWN(N, S) ((N) - ((N) % (S)))
22 #define DEVICE_NAME L"\\Ntfs"
25 typedef struct _BIOS_PARAMETERS_BLOCK
27 USHORT BytesPerSector
; // 0x0B
28 UCHAR SectorsPerCluster
; // 0x0D
29 UCHAR Unused0
[7]; // 0x0E, checked when volume is mounted
30 UCHAR MediaId
; // 0x15
31 UCHAR Unused1
[2]; // 0x16
32 USHORT SectorsPerTrack
; // 0x18
34 UCHAR Unused2
[4]; // 0x1C
35 UCHAR Unused3
[4]; // 0x20, checked when volume is mounted
36 } BIOS_PARAMETERS_BLOCK
, *PBIOS_PARAMETERS_BLOCK
;
38 typedef struct _EXTENDED_BIOS_PARAMETERS_BLOCK
40 USHORT Unknown
[2]; // 0x24, always 80 00 80 00
41 ULONGLONG SectorCount
; // 0x28
42 ULONGLONG MftLocation
; // 0x30
43 ULONGLONG MftMirrLocation
; // 0x38
44 CHAR ClustersPerMftRecord
; // 0x40
45 UCHAR Unused4
[3]; // 0x41
46 CHAR ClustersPerIndexRecord
; // 0x44
47 UCHAR Unused5
[3]; // 0x45
48 ULONGLONG SerialNumber
; // 0x48
49 UCHAR Checksum
[4]; // 0x50
50 } EXTENDED_BIOS_PARAMETERS_BLOCK
, *PEXTENDED_BIOS_PARAMETERS_BLOCK
;
52 typedef struct _BOOT_SECTOR
54 UCHAR Jump
[3]; // 0x00
55 UCHAR OEMID
[8]; // 0x03
56 BIOS_PARAMETERS_BLOCK BPB
;
57 EXTENDED_BIOS_PARAMETERS_BLOCK EBPB
;
58 UCHAR BootStrap
[426]; // 0x54
59 USHORT EndSector
; // 0x1FE
60 } BOOT_SECTOR
, *PBOOT_SECTOR
;
63 //typedef struct _BootSector BootSector;
65 typedef struct _NTFS_INFO
68 ULONG SectorsPerCluster
;
69 ULONG BytesPerCluster
;
70 ULONGLONG SectorCount
;
71 ULONGLONG ClusterCount
;
72 ULARGE_INTEGER MftStart
;
73 ULARGE_INTEGER MftMirrStart
;
74 ULONG BytesPerFileRecord
;
75 ULONG BytesPerIndexRecord
;
77 ULONGLONG SerialNumber
;
78 USHORT VolumeLabelLength
;
79 WCHAR VolumeLabel
[MAXIMUM_VOLUME_LABEL_LENGTH
];
84 ULONG MftZoneReservation
;
85 } NTFS_INFO
, *PNTFS_INFO
;
87 #define NTFS_TYPE_CCB '20SF'
88 #define NTFS_TYPE_FCB '30SF'
89 #define NTFS_TYPE_VCB '50SF'
90 #define NTFS_TYPE_IRP_CONTEXT '60SF'
91 #define NTFS_TYPE_GLOBAL_DATA '70SF'
97 } NTFSIDENTIFIER
, *PNTFSIDENTIFIER
;
101 NTFSIDENTIFIER Identifier
;
103 ERESOURCE DirResource
;
104 // ERESOURCE FatResource;
106 KSPIN_LOCK FcbListLock
;
107 LIST_ENTRY FcbListHead
;
110 PDEVICE_OBJECT StorageDevice
;
111 PFILE_OBJECT StreamFileObject
;
113 struct _NTFS_ATTR_CONTEXT
* MFTContext
;
114 struct _FILE_RECORD_HEADER
* MasterFileTable
;
115 struct _FCB
*VolumeFcb
;
120 ULONG OpenHandleCount
;
122 } DEVICE_EXTENSION
, *PDEVICE_EXTENSION
, NTFS_VCB
, *PNTFS_VCB
;
124 #define VCB_VOLUME_LOCKED 0x0001
128 NTFSIDENTIFIER Identifier
;
130 PFILE_OBJECT PtrFileObject
;
131 LARGE_INTEGER CurrentByteOffset
;
132 /* for DirectoryControl */
134 /* for DirectoryControl */
135 PWCHAR DirectorySearchPattern
;
138 } NTFS_CCB
, *PNTFS_CCB
;
140 #define TAG_CCB 'BCCI'
141 #define TAG_FCB 'BCFI'
145 NTFSIDENTIFIER Identifier
;
147 PDRIVER_OBJECT DriverObject
;
148 PDEVICE_OBJECT DeviceObject
;
149 CACHE_MANAGER_CALLBACKS CacheMgrCallbacks
;
151 FAST_IO_DISPATCH FastIoDispatch
;
152 NPAGED_LOOKASIDE_LIST IrpContextLookasideList
;
153 NPAGED_LOOKASIDE_LIST FcbLookasideList
;
154 } NTFS_GLOBAL_DATA
, *PNTFS_GLOBAL_DATA
;
159 AttributeStandardInformation
= 0x10,
160 AttributeAttributeList
= 0x20,
161 AttributeFileName
= 0x30,
162 AttributeObjectId
= 0x40,
163 AttributeSecurityDescriptor
= 0x50,
164 AttributeVolumeName
= 0x60,
165 AttributeVolumeInformation
= 0x70,
166 AttributeData
= 0x80,
167 AttributeIndexRoot
= 0x90,
168 AttributeIndexAllocation
= 0xA0,
169 AttributeBitmap
= 0xB0,
170 AttributeReparsePoint
= 0xC0,
171 AttributeEAInformation
= 0xD0,
173 AttributePropertySet
= 0xF0,
174 AttributeLoggedUtilityStream
= 0x100,
175 AttributeEnd
= 0xFFFFFFFF
176 } ATTRIBUTE_TYPE
, *PATTRIBUTE_TYPE
;
178 #define NTFS_FILE_MFT 0
179 #define NTFS_FILE_MFTMIRR 1
180 #define NTFS_FILE_LOGFILE 2
181 #define NTFS_FILE_VOLUME 3
182 #define NTFS_FILE_ATTRDEF 4
183 #define NTFS_FILE_ROOT 5
184 #define NTFS_FILE_BITMAP 6
185 #define NTFS_FILE_BOOT 7
186 #define NTFS_FILE_BADCLUS 8
187 #define NTFS_FILE_QUOTA 9
188 #define NTFS_FILE_UPCASE 10
189 #define NTFS_FILE_EXTEND 11
191 #define NTFS_MFT_MASK 0x0000FFFFFFFFFFFFULL
193 #define COLLATION_BINARY 0x00
194 #define COLLATION_FILE_NAME 0x01
195 #define COLLATION_UNICODE_STRING 0x02
196 #define COLLATION_NTOFS_ULONG 0x10
197 #define COLLATION_NTOFS_SID 0x11
198 #define COLLATION_NTOFS_SECURITY_HASH 0x12
199 #define COLLATION_NTOFS_ULONGS 0x13
201 #define INDEX_ROOT_SMALL 0x0
202 #define INDEX_ROOT_LARGE 0x1
204 #define NTFS_INDEX_ENTRY_NODE 1
205 #define NTFS_INDEX_ENTRY_END 2
207 #define NTFS_FILE_NAME_POSIX 0
208 #define NTFS_FILE_NAME_WIN32 1
209 #define NTFS_FILE_NAME_DOS 2
210 #define NTFS_FILE_NAME_WIN32_AND_DOS 3
212 #define NTFS_FILE_TYPE_READ_ONLY 0x1
213 #define NTFS_FILE_TYPE_HIDDEN 0x2
214 #define NTFS_FILE_TYPE_SYSTEM 0x4
215 #define NTFS_FILE_TYPE_ARCHIVE 0x20
216 #define NTFS_FILE_TYPE_REPARSE 0x400
217 #define NTFS_FILE_TYPE_COMPRESSED 0x800
218 #define NTFS_FILE_TYPE_DIRECTORY 0x10000000
222 ULONG Type
; /* Magic number 'FILE' */
223 USHORT UsaOffset
; /* Offset to the update sequence */
224 USHORT UsaCount
; /* Size in words of Update Sequence Number & Array (S) */
225 ULONGLONG Lsn
; /* $LogFile Sequence Number (LSN) */
226 } NTFS_RECORD_HEADER
, *PNTFS_RECORD_HEADER
;
228 /* NTFS_RECORD_HEADER.Type */
229 #define NRH_FILE_TYPE 0x454C4946 /* 'FILE' */
230 #define NRH_INDX_TYPE 0x58444E49 /* 'INDX' */
233 typedef struct _FILE_RECORD_HEADER
235 NTFS_RECORD_HEADER Ntfs
;
236 USHORT SequenceNumber
; /* Sequence number */
237 USHORT LinkCount
; /* Hard link count */
238 USHORT AttributeOffset
; /* Offset to the first Attribute */
239 USHORT Flags
; /* Flags */
240 ULONG BytesInUse
; /* Real size of the FILE record */
241 ULONG BytesAllocated
; /* Allocated size of the FILE record */
242 ULONGLONG BaseFileRecord
; /* File reference to the base FILE record */
243 USHORT NextAttributeNumber
; /* Next Attribute Id */
244 USHORT Padding
; /* Align to 4 UCHAR boundary (XP) */
245 ULONG MFTRecordNumber
; /* Number of this MFT Record (XP) */
246 } FILE_RECORD_HEADER
, *PFILE_RECORD_HEADER
;
248 /* Flags in FILE_RECORD_HEADER */
250 #define FRH_IN_USE 0x0001 /* Record is in use */
251 #define FRH_DIRECTORY 0x0002 /* Record is a directory */
252 #define FRH_UNKNOWN1 0x0004 /* Don't know */
253 #define FRH_UNKNOWN2 0x0008 /* Don't know */
266 // Resident attributes
274 // Non-resident attributes
278 ULONGLONG HighestVCN
;
279 USHORT MappingPairsOffset
;
280 USHORT CompressionUnit
;
282 LONGLONG AllocatedSize
;
284 LONGLONG InitializedSize
;
285 LONGLONG CompressedSize
;
288 } NTFS_ATTR_RECORD
, *PNTFS_ATTR_RECORD
;
292 ULONGLONG CreationTime
;
293 ULONGLONG ChangeTime
;
294 ULONGLONG LastWriteTime
;
295 ULONGLONG LastAccessTime
;
297 ULONG AlignmentOrReserved
[3];
301 ULONGLONG QuotaCharge
;
304 } STANDARD_INFORMATION
, *PSTANDARD_INFORMATION
;
309 ATTRIBUTE_TYPE AttributeType
;
313 ULONGLONG StartVcn
; // LowVcn
314 ULONGLONG FileReferenceNumber
;
315 USHORT AttributeNumber
;
316 USHORT AlignmentOrReserved
[3];
317 } ATTRIBUTE_LIST
, *PATTRIBUTE_LIST
;
322 ULONGLONG DirectoryFileReferenceNumber
;
323 ULONGLONG CreationTime
;
324 ULONGLONG ChangeTime
;
325 ULONGLONG LastWriteTime
;
326 ULONGLONG LastAccessTime
;
327 ULONGLONG AllocatedSize
;
329 ULONG FileAttributes
;
335 USHORT AlignmentOrReserved
;
342 } FILENAME_ATTRIBUTE
, *PFILENAME_ATTRIBUTE
;
346 ULONG FirstEntryOffset
;
347 ULONG TotalSizeOfEntries
;
351 } INDEX_HEADER_ATTRIBUTE
, *PINDEX_HEADER_ATTRIBUTE
;
358 UCHAR ClustersPerIndexRecord
;
360 INDEX_HEADER_ATTRIBUTE Header
;
361 } INDEX_ROOT_ATTRIBUTE
, *PINDEX_ROOT_ATTRIBUTE
;
365 NTFS_RECORD_HEADER Ntfs
;
367 INDEX_HEADER_ATTRIBUTE Header
;
368 } INDEX_BUFFER
, *PINDEX_BUFFER
;
376 ULONGLONG IndexedFile
;
389 FILENAME_ATTRIBUTE FileName
;
390 } INDEX_ENTRY_ATTRIBUTE
, *PINDEX_ENTRY_ATTRIBUTE
;
399 } VOLINFO_ATTRIBUTE
, *PVOLINFO_ATTRIBUTE
;
406 } REPARSE_POINT_ATTRIBUTE
, *PREPARSE_POINT_ATTRIBUTE
;
408 #define IRPCONTEXT_CANWAIT 0x1
409 #define IRPCONTEXT_COMPLETE 0x2
410 #define IRPCONTEXT_QUEUE 0x4
414 NTFSIDENTIFIER Identifier
;
416 PIO_STACK_LOCATION Stack
;
419 WORK_QUEUE_ITEM WorkQueueItem
;
422 PDEVICE_OBJECT DeviceObject
;
423 PFILE_OBJECT FileObject
;
424 NTSTATUS SavedExceptionCode
;
426 } NTFS_IRP_CONTEXT
, *PNTFS_IRP_CONTEXT
;
428 typedef struct _NTFS_ATTR_CONTEXT
431 ULONGLONG CacheRunOffset
;
432 LONGLONG CacheRunStartLCN
;
433 ULONGLONG CacheRunLength
;
434 LONGLONG CacheRunLastLCN
;
435 ULONGLONG CacheRunCurrentOffset
;
436 NTFS_ATTR_RECORD Record
;
437 } NTFS_ATTR_CONTEXT
, *PNTFS_ATTR_CONTEXT
;
439 #define FCB_CACHE_INITIALIZED 0x0001
440 #define FCB_IS_VOLUME_STREAM 0x0002
441 #define FCB_IS_VOLUME 0x0004
446 NTFSIDENTIFIER Identifier
;
448 FSRTL_COMMON_FCB_HEADER RFCB
;
449 SECTION_OBJECT_POINTERS SectionObjectPointers
;
451 PFILE_OBJECT FileObject
;
454 WCHAR Stream
[MAX_PATH
];
455 WCHAR
*ObjectName
; /* point on filename (250 chars max) in PathName */
456 WCHAR PathName
[MAX_PATH
]; /* path+filename 260 max */
458 ERESOURCE PagingIoResource
;
459 ERESOURCE MainResource
;
461 LIST_ENTRY FcbListEntry
;
462 struct _FCB
* ParentFcb
;
468 ULONG OpenHandleCount
;
473 FILENAME_ATTRIBUTE Entry
;
475 } NTFS_FCB
, *PNTFS_FCB
;
477 typedef struct _FIND_ATTR_CONTXT
479 PDEVICE_EXTENSION Vcb
;
480 BOOLEAN OnlyResident
;
481 PNTFS_ATTR_RECORD FirstAttr
;
482 PNTFS_ATTR_RECORD CurrAttr
;
483 PNTFS_ATTR_RECORD LastAttr
;
484 PNTFS_ATTR_RECORD NonResidentStart
;
485 PNTFS_ATTR_RECORD NonResidentEnd
;
486 } FIND_ATTR_CONTXT
, *PFIND_ATTR_CONTXT
;
488 extern PNTFS_GLOBAL_DATA NtfsGlobalData
;
492 NtfsMarkIrpContextForQueue(PNTFS_IRP_CONTEXT IrpContext
)
494 PULONG Flags
= &IrpContext
->Flags
;
496 *Flags
&= ~IRPCONTEXT_COMPLETE
;
497 *Flags
|= IRPCONTEXT_QUEUE
;
499 return STATUS_PENDING
;
505 //NtfsDumpAttribute(PATTRIBUTE Attribute);
508 DecodeRun(PUCHAR DataRun
,
509 LONGLONG
*DataRunOffset
,
510 ULONGLONG
*DataRunLength
);
513 NtfsDumpFileAttributes(PDEVICE_EXTENSION Vcb
,
514 PFILE_RECORD_HEADER FileRecord
);
516 PSTANDARD_INFORMATION
517 GetStandardInformationFromRecord(PDEVICE_EXTENSION Vcb
,
518 PFILE_RECORD_HEADER FileRecord
);
521 GetFileNameFromRecord(PDEVICE_EXTENSION Vcb
,
522 PFILE_RECORD_HEADER FileRecord
,
526 GetBestFileNameFromRecord(PDEVICE_EXTENSION Vcb
,
527 PFILE_RECORD_HEADER FileRecord
);
530 FindFirstAttribute(PFIND_ATTR_CONTXT Context
,
531 PDEVICE_EXTENSION Vcb
,
532 PFILE_RECORD_HEADER FileRecord
,
533 BOOLEAN OnlyResident
,
534 PNTFS_ATTR_RECORD
* Attribute
);
537 FindNextAttribute(PFIND_ATTR_CONTXT Context
,
538 PNTFS_ATTR_RECORD
* Attribute
);
541 FindCloseAttribute(PFIND_ATTR_CONTXT Context
);
546 NtfsReadDisk(IN PDEVICE_OBJECT DeviceObject
,
547 IN LONGLONG StartingOffset
,
550 IN OUT PUCHAR Buffer
,
551 IN BOOLEAN Override
);
554 NtfsReadSectors(IN PDEVICE_OBJECT DeviceObject
,
556 IN ULONG SectorCount
,
558 IN OUT PUCHAR Buffer
,
559 IN BOOLEAN Override
);
562 NtfsDeviceIoControl(IN PDEVICE_OBJECT DeviceObject
,
563 IN ULONG ControlCode
,
564 IN PVOID InputBuffer
,
565 IN ULONG InputBufferSize
,
566 IN OUT PVOID OutputBuffer
,
567 IN OUT PULONG OutputBufferSize
,
568 IN BOOLEAN Override
);
574 NtfsCleanup(PNTFS_IRP_CONTEXT IrpContext
);
580 NtfsCloseFile(PDEVICE_EXTENSION DeviceExt
,
581 PFILE_OBJECT FileObject
);
584 NtfsClose(PNTFS_IRP_CONTEXT IrpContext
);
590 NtfsCreate(PNTFS_IRP_CONTEXT IrpContext
);
596 NtfsDeviceControl(PNTFS_IRP_CONTEXT IrpContext
);
602 NtfsGetFileSize(PDEVICE_EXTENSION DeviceExt
,
603 PFILE_RECORD_HEADER FileRecord
,
606 PULONGLONG AllocatedSize
);
609 NtfsDirectoryControl(PNTFS_IRP_CONTEXT IrpContext
);
614 DRIVER_DISPATCH NtfsFsdDispatch
;
616 NtfsFsdDispatch(PDEVICE_OBJECT DeviceObject
,
623 NtfsAcqLazyWrite(PVOID Context
,
627 NtfsRelLazyWrite(PVOID Context
);
630 NtfsAcqReadAhead(PVOID Context
,
634 NtfsRelReadAhead(PVOID Context
);
636 FAST_IO_CHECK_IF_POSSIBLE NtfsFastIoCheckIfPossible
;
637 FAST_IO_READ NtfsFastIoRead
;
638 FAST_IO_WRITE NtfsFastIoWrite
;
644 NtfsCreateFCB(PCWSTR FileName
,
649 NtfsDestroyFCB(PNTFS_FCB Fcb
);
652 NtfsFCBIsDirectory(PNTFS_FCB Fcb
);
655 NtfsFCBIsReparsePoint(PNTFS_FCB Fcb
);
658 NtfsFCBIsCompressed(PNTFS_FCB Fcb
);
661 NtfsFCBIsRoot(PNTFS_FCB Fcb
);
664 NtfsGrabFCB(PNTFS_VCB Vcb
,
668 NtfsReleaseFCB(PNTFS_VCB Vcb
,
672 NtfsAddFCBToTable(PNTFS_VCB Vcb
,
676 NtfsGrabFCBFromTable(PNTFS_VCB Vcb
,
680 NtfsFCBInitializeCache(PNTFS_VCB Vcb
,
684 NtfsMakeRootFCB(PNTFS_VCB Vcb
);
687 NtfsOpenRootFCB(PNTFS_VCB Vcb
);
690 NtfsAttachFCBToFileObject(PNTFS_VCB Vcb
,
692 PFILE_OBJECT FileObject
);
695 NtfsGetFCBForFile(PNTFS_VCB Vcb
,
696 PNTFS_FCB
*pParentFCB
,
698 const PWSTR pFileName
);
701 NtfsReadFCBAttribute(PNTFS_VCB Vcb
,
709 NtfsMakeFCBFromDirEntry(PNTFS_VCB Vcb
,
710 PNTFS_FCB DirectoryFCB
,
711 PUNICODE_STRING Name
,
713 PFILE_RECORD_HEADER Record
,
715 PNTFS_FCB
* fileFCB
);
721 NtfsQueryInformation(PNTFS_IRP_CONTEXT IrpContext
);
727 NtfsFileSystemControl(PNTFS_IRP_CONTEXT IrpContext
);
732 PrepareAttributeContext(PNTFS_ATTR_RECORD AttrRecord
);
735 ReleaseAttributeContext(PNTFS_ATTR_CONTEXT Context
);
738 ReadAttribute(PDEVICE_EXTENSION Vcb
,
739 PNTFS_ATTR_CONTEXT Context
,
745 AttributeDataLength(PNTFS_ATTR_RECORD AttrRecord
);
748 AttributeAllocatedLength(PNTFS_ATTR_RECORD AttrRecord
);
751 ReadFileRecord(PDEVICE_EXTENSION Vcb
,
753 PFILE_RECORD_HEADER file
);
756 FindAttribute(PDEVICE_EXTENSION Vcb
,
757 PFILE_RECORD_HEADER MftRecord
,
761 PNTFS_ATTR_CONTEXT
* AttrCtx
);
764 ReadVCN(PDEVICE_EXTENSION Vcb
,
765 PFILE_RECORD_HEADER file
,
772 FixupUpdateSequenceArray(PDEVICE_EXTENSION Vcb
,
773 PNTFS_RECORD_HEADER Record
);
776 ReadLCN(PDEVICE_EXTENSION Vcb
,
782 EnumerAttribute(PFILE_RECORD_HEADER file
,
783 PDEVICE_EXTENSION Vcb
,
784 PDEVICE_OBJECT DeviceObject
);
787 NtfsLookupFile(PDEVICE_EXTENSION Vcb
,
788 PUNICODE_STRING PathName
,
789 PFILE_RECORD_HEADER
*FileRecord
,
790 PULONGLONG MFTIndex
);
793 NtfsLookupFileAt(PDEVICE_EXTENSION Vcb
,
794 PUNICODE_STRING PathName
,
795 PFILE_RECORD_HEADER
*FileRecord
,
797 ULONGLONG CurrentMFTIndex
);
800 NtfsFindFileAt(PDEVICE_EXTENSION Vcb
,
801 PUNICODE_STRING SearchPattern
,
803 PFILE_RECORD_HEADER
*FileRecord
,
805 ULONGLONG CurrentMFTIndex
);
810 NtfsIsIrpTopLevel(PIRP Irp
);
813 NtfsAllocateIrpContext(PDEVICE_OBJECT DeviceObject
,
817 NtfsGetUserBuffer(PIRP Irp
,
821 NtfsFileFlagsToAttributes(ULONG NtfsAttributes
,
822 PULONG FileAttributes
);
828 NtfsRead(PNTFS_IRP_CONTEXT IrpContext
);
831 NtfsWrite(PNTFS_IRP_CONTEXT IrpContext
);
837 NtfsGetFreeClusters(PDEVICE_EXTENSION DeviceExt
);
840 NtfsQueryVolumeInformation(PNTFS_IRP_CONTEXT IrpContext
);
843 NtfsSetVolumeInformation(PNTFS_IRP_CONTEXT IrpContext
);
848 DRIVER_INITIALIZE DriverEntry
;
852 NtfsInitializeFunctionPointers(PDRIVER_OBJECT DriverObject
);