3 Copyright (c) Alex Ionescu. All rights reserved.
11 Type definitions for the Executive.
15 Alex Ionescu (alexi@tinykrnl.org) - Updated - 27-Feb-2006
27 #if defined(_MSC_VER) && !defined(NTOS_MODE_USER)
39 #define __ALIGNED(n) __attribute__((aligned (n)))
40 #elif defined(_MSC_VER)
41 #define __ALIGNED(n) __declspec(align(n))
43 #error __ALIGNED not defined for your compiler!
47 // Atom and Language IDs
49 typedef USHORT LANGID
, *PLANGID
;
50 typedef USHORT RTL_ATOM
, *PRTL_ATOM
;
52 #ifndef NTOS_MODE_USER
55 // Kernel Exported Object Types
57 extern POBJECT_TYPE NTSYSAPI ExDesktopObjectType
;
58 extern POBJECT_TYPE NTSYSAPI ExWindowStationObjectType
;
59 extern POBJECT_TYPE NTSYSAPI ExIoCompletionType
;
60 extern POBJECT_TYPE NTSYSAPI ExMutantObjectType
;
61 extern POBJECT_TYPE NTSYSAPI ExTimerType
;
64 // Exported NT Build Number
66 extern ULONG NtBuildNumber
;
69 // Invalid Handle Value Constant
71 #define INVALID_HANDLE_VALUE (HANDLE)-1
78 #define MUTANT_INCREMENT 1
81 // Callback Object Access Mask
83 #define CALLBACK_ALL_ACCESS (STANDARD_RIGHTS_REQUIRED|SYNCHRONIZE|0x0001)
84 #define CALLBACK_EXECUTE (STANDARD_RIGHTS_EXECUTE|SYNCHRONIZE|0x0001)
85 #define CALLBACK_WRITE (STANDARD_RIGHTS_WRITE|SYNCHRONIZE|0x0001)
86 #define CALLBACK_READ (STANDARD_RIGHTS_READ|SYNCHRONIZE|0x0001)
89 // Event Object Access Masks
92 #define EVENT_QUERY_STATE 0x0001
95 // Semaphore Object Access Masks
97 #define SEMAPHORE_QUERY_STATE 0x0001
101 // Mutant Object Access Masks
103 #define MUTANT_QUERY_STATE 0x0001
104 #define MUTANT_ALL_ACCESS (STANDARD_RIGHTS_REQUIRED | \
108 #define TIMER_QUERY_STATE 0x0001
109 #define TIMER_MODIFY_STATE 0x0002
110 #define TIMER_ALL_ACCESS (STANDARD_RIGHTS_REQUIRED | \
112 TIMER_QUERY_STATE | \
117 // Event Pair Access Masks
119 #define EVENT_PAIR_ALL_ACCESS 0x1F0000L
122 // Profile Object Access Masks
124 #define PROFILE_CONTROL 0x0001
125 #define PROFILE_ALL_ACCESS (STANDARD_RIGHTS_REQUIRED | PROFILE_CONTROL)
128 // Maximum Parameters for NtRaiseHardError
130 #define MAXIMUM_HARDERROR_PARAMETERS 4
135 #define EX_PUSH_LOCK_LOCK_V ((ULONG_PTR)0x0)
136 #define EX_PUSH_LOCK_LOCK ((ULONG_PTR)0x1)
137 #define EX_PUSH_LOCK_WAITING ((ULONG_PTR)0x2)
138 #define EX_PUSH_LOCK_WAKING ((ULONG_PTR)0x4)
139 #define EX_PUSH_LOCK_MULTIPLE_SHARED ((ULONG_PTR)0x8)
140 #define EX_PUSH_LOCK_SHARE_INC ((ULONG_PTR)0x10)
141 #define EX_PUSH_LOCK_PTR_BITS ((ULONG_PTR)0xf)
144 // Pushlock Wait Block Flags
146 #define EX_PUSH_LOCK_FLAGS_EXCLUSIVE 1
147 #define EX_PUSH_LOCK_FLAGS_WAIT 2
150 // Resource (ERESOURCE) Flags
152 #define ResourceHasDisabledPriorityBoost 0x08
155 // Shutdown types for NtShutdownSystem
157 typedef enum _SHUTDOWN_ACTION
165 // Responses for NtRaiseHardError
167 typedef enum _HARDERROR_RESPONSE_OPTION
169 OptionAbortRetryIgnore
,
176 } HARDERROR_RESPONSE_OPTION
, *PHARDERROR_RESPONSE_OPTION
;
178 typedef enum _HARDERROR_RESPONSE
180 ResponseReturnToCaller
,
191 } HARDERROR_RESPONSE
, *PHARDERROR_RESPONSE
;
194 // System Information Classes for NtQuerySystemInformation
196 typedef enum _SYSTEM_INFORMATION_CLASS
198 SystemBasicInformation
,
199 SystemProcessorInformation
,
200 SystemPerformanceInformation
,
201 SystemTimeOfDayInformation
,
202 SystemPathInformation
, /// Obsolete: Use KUSER_SHARED_DATA
203 SystemProcessInformation
,
204 SystemCallCountInformation
,
205 SystemDeviceInformation
,
206 SystemProcessorPerformanceInformation
,
207 SystemFlagsInformation
,
208 SystemCallTimeInformation
,
209 SystemModuleInformation
,
210 SystemLocksInformation
,
211 SystemStackTraceInformation
,
212 SystemPagedPoolInformation
,
213 SystemNonPagedPoolInformation
,
214 SystemHandleInformation
,
215 SystemObjectInformation
,
216 SystemPageFileInformation
,
217 SystemVdmInstemulInformation
,
218 SystemVdmBopInformation
,
219 SystemFileCacheInformation
,
220 SystemPoolTagInformation
,
221 SystemInterruptInformation
,
222 SystemDpcBehaviorInformation
,
223 SystemFullMemoryInformation
,
224 SystemLoadGdiDriverInformation
,
225 SystemUnloadGdiDriverInformation
,
226 SystemTimeAdjustmentInformation
,
227 SystemSummaryMemoryInformation
,
228 SystemMirrorMemoryInformation
,
229 SystemPerformanceTraceInformation
,
231 SystemExceptionInformation
,
232 SystemCrashDumpStateInformation
,
233 SystemKernelDebuggerInformation
,
234 SystemContextSwitchInformation
,
235 SystemRegistryQuotaInformation
,
236 SystemExtendServiceTableInformation
,
237 SystemPrioritySeperation
,
238 SystemPlugPlayBusInformation
,
239 SystemDockInformation
,
240 SystemPowerInformationNative
,
241 SystemProcessorSpeedInformation
,
242 SystemCurrentTimeZoneInformation
,
243 SystemLookasideInformation
,
244 SystemTimeSlipNotification
,
247 SystemSessionInformation
,
248 SystemRangeStartInformation
,
249 SystemVerifierInformation
,
251 SystemSessionProcessesInformation
,
252 SystemLoadGdiDriverInSystemSpaceInformation
,
253 SystemNumaProcessorMap
,
254 SystemPrefetcherInformation
,
255 SystemExtendedProcessInformation
,
256 SystemRecommendedSharedDataAlignment
,
257 SystemComPlusPackage
,
258 SystemNumaAvailableMemory
,
259 SystemProcessorPowerInformation
,
260 SystemEmulationBasicInformation
,
261 SystemEmulationProcessorInformation
,
262 SystemExtendedHanfleInformation
,
263 SystemLostDelayedWriteInformation
,
264 SystemBigPoolInformation
,
265 SystemSessionPoolTagInformation
,
266 SystemSessionMappedViewInformation
,
267 SystemHotpatchInformation
,
268 SystemObjectSecurityMode
,
269 SystemWatchDogTimerHandler
,
270 SystemWatchDogTimerInformation
,
271 SystemLogicalProcessorInformation
,
272 SystemWo64SharedInformationObosolete
,
273 SystemRegisterFirmwareTableInformationHandler
,
274 SystemFirmwareTableInformation
,
275 SystemModuleInformationEx
,
276 SystemVerifierTriageInformation
,
277 SystemSuperfetchInformation
,
278 SystemMemoryListInformation
,
279 SystemFileCacheInformationEx
,
280 SystemThreadPriorityClientIdInformation
,
281 SystemProcessorIdleCycleTimeInformation
,
282 SystemVerifierCancellationInformation
,
283 SystemProcessorPowerInformationEx
,
284 SystemRefTraceInformation
,
285 SystemSpecialPoolInformation
,
286 SystemProcessIdInformation
,
287 SystemErrorPortInformation
,
288 SystemBootEnvironmentInformation
,
289 SystemHypervisorInformation
,
290 SystemVerifierInformationEx
,
291 SystemTimeZoneInformation
,
292 SystemImageFileExecutionOptionsInformation
,
293 SystemCoverageInformation
,
294 SystemPrefetchPathInformation
,
295 SystemVerifierFaultsInformation
,
297 } SYSTEM_INFORMATION_CLASS
;
300 // System Information Classes for NtQueryMutant
302 typedef enum _MUTANT_INFORMATION_CLASS
304 MutantBasicInformation
,
305 MutantOwnerInformation
306 } MUTANT_INFORMATION_CLASS
;
309 // System Information Classes for NtQueryAtom
311 typedef enum _ATOM_INFORMATION_CLASS
313 AtomBasicInformation
,
314 AtomTableInformation
,
315 } ATOM_INFORMATION_CLASS
;
318 // System Information Classes for NtQueryTimer
320 typedef enum _TIMER_INFORMATION_CLASS
322 TimerBasicInformation
323 } TIMER_INFORMATION_CLASS
;
326 // System Information Classes for NtQuerySemaphore
328 typedef enum _SEMAPHORE_INFORMATION_CLASS
330 SemaphoreBasicInformation
331 } SEMAPHORE_INFORMATION_CLASS
;
334 // System Information Classes for NtQueryEvent
336 typedef enum _EVENT_INFORMATION_CLASS
338 EventBasicInformation
339 } EVENT_INFORMATION_CLASS
;
341 #ifdef NTOS_MODE_USER
344 // Firmware Table Actions for SystemFirmwareTableInformation
346 typedef enum _SYSTEM_FIRMWARE_TABLE_ACTION
348 SystemFirmwareTable_Enumerate
= 0,
349 SystemFirmwareTable_Get
= 1,
350 } SYSTEM_FIRMWARE_TABLE_ACTION
, *PSYSTEM_FIRMWARE_TABLE_ACTION
;
353 // Firmware Handler Callback
355 struct _SYSTEM_FIRMWARE_TABLE_INFORMATION
;
359 IN
struct _SYSTEM_FIRMWARE_TABLE_INFORMATION
*FirmwareTableInformation
365 // Compatibility with Windows XP Drivers using ERESOURCE
367 typedef struct _ERESOURCE_XP
369 LIST_ENTRY SystemResourcesList
;
370 POWNER_ENTRY OwnerTable
;
373 PKSEMAPHORE SharedWaiters
;
374 PKEVENT ExclusiveWaiters
;
375 OWNER_ENTRY OwnerThreads
[2];
376 ULONG ContentionCount
;
377 USHORT NumberOfSharedWaiters
;
378 USHORT NumberOfExclusiveWaiters
;
382 ULONG_PTR CreatorBackTraceIndex
;
385 } ERESOURCE_XP
, *PERESOURCE_XP
;
388 // Executive Work Queue Structures
390 typedef struct _EX_QUEUE_WORKER_INFO
392 ULONG QueueDisabled
:1;
393 ULONG MakeThreadsAsNecessary
:1;
395 ULONG WorkerCount
:29;
396 } EX_QUEUE_WORKER_INFO
, *PEX_QUEUE_WORKER_INFO
;
398 typedef struct _EX_WORK_QUEUE
401 LONG DynamicThreadCount
;
402 ULONG WorkItemsProcessed
;
403 ULONG WorkItemsProcessedLastPass
;
404 ULONG QueueDepthLastPass
;
405 EX_QUEUE_WORKER_INFO Info
;
406 } EX_WORK_QUEUE
, *PEX_WORK_QUEUE
;
409 // Executive Fast Reference Structure
411 typedef struct _EX_FAST_REF
419 } EX_FAST_REF
, *PEX_FAST_REF
;
422 // Executive Cache-Aware Rundown Reference Descriptor
424 typedef struct _EX_RUNDOWN_REF_CACHE_AWARE
426 PEX_RUNDOWN_REF RunRefs
;
430 } EX_RUNDOWN_REF_CACHE_AWARE
, *PEX_RUNDOWN_REF_CACHE_AWARE
;
433 // Executive Rundown Wait Block
435 typedef struct _EX_RUNDOWN_WAIT_BLOCK
439 } EX_RUNDOWN_WAIT_BLOCK
, *PEX_RUNDOWN_WAIT_BLOCK
;
442 // Executive Pushlock
446 typedef struct _EX_PUSH_LOCK
455 ULONG_PTR MultipleShared
:1;
456 ULONG_PTR Shared
:sizeof (ULONG_PTR
) * 8 - 4;
461 } EX_PUSH_LOCK
, *PEX_PUSH_LOCK
;
464 // Executive Pushlock Wait Block
466 typedef __ALIGNED(16) struct _EX_PUSH_LOCK_WAIT_BLOCK
473 struct _EX_PUSH_LOCK_WAIT_BLOCK
*Next
;
474 struct _EX_PUSH_LOCK_WAIT_BLOCK
*Last
;
475 struct _EX_PUSH_LOCK_WAIT_BLOCK
*Previous
;
480 EX_PUSH_LOCK NewValue
;
481 EX_PUSH_LOCK OldValue
;
482 PEX_PUSH_LOCK PushLock
;
484 } EX_PUSH_LOCK_WAIT_BLOCK
, *PEX_PUSH_LOCK_WAIT_BLOCK
;
489 typedef struct _CALLBACK_OBJECT
493 LIST_ENTRY RegisteredCallbacks
;
494 BOOLEAN AllowMultipleCallbacks
;
496 } CALLBACK_OBJECT
, *PCALLBACK_OBJECT
;
501 typedef struct _CALLBACK_REGISTRATION
504 PCALLBACK_OBJECT CallbackObject
;
505 PCALLBACK_FUNCTION CallbackFunction
;
506 PVOID CallbackContext
;
508 BOOLEAN UnregisterWaiting
;
509 } CALLBACK_REGISTRATION
, *PCALLBACK_REGISTRATION
;
512 // Internal Callback Object
514 typedef struct _EX_CALLBACK_ROUTINE_BLOCK
516 EX_RUNDOWN_REF RundownProtect
;
517 PEX_CALLBACK_FUNCTION Function
;
519 } EX_CALLBACK_ROUTINE_BLOCK
, *PEX_CALLBACK_ROUTINE_BLOCK
;
522 // Internal Callback Handle
524 typedef struct _EX_CALLBACK
526 EX_FAST_REF RoutineBlock
;
527 } EX_CALLBACK
, *PEX_CALLBACK
;
532 typedef struct _EPROFILE
540 PKPROFILE ProfileObject
;
541 PVOID LockedBufferAddress
;
544 KPROFILE_SOURCE ProfileSource
;
546 } EPROFILE
, *PEPROFILE
;
549 // Handle Table Structures
551 typedef struct _HANDLE_TRACE_DB_ENTRY
556 PVOID StackTrace
[16];
557 } HANDLE_TRACE_DB_ENTRY
, *PHANDLE_TRACE_DB_ENTRY
;
559 typedef struct _HANDLE_TRACE_DEBUG_INFO
564 FAST_MUTEX CloseCompatcionLock
;
565 ULONG CurrentStackIndex
;
566 HANDLE_TRACE_DB_ENTRY TraceDb
[1];
567 } HANDLE_TRACE_DEBUG_INFO
, *PHANDLE_TRACE_DEBUG_INFO
;
569 typedef struct _HANDLE_TABLE_ENTRY_INFO
572 } HANDLE_TABLE_ENTRY_INFO
, *PHANDLE_TABLE_ENTRY_INFO
;
574 typedef struct _HANDLE_TABLE_ENTRY
579 ULONG_PTR ObAttributes
;
580 PHANDLE_TABLE_ENTRY_INFO InfoTable
;
588 USHORT GrantedAccessIndex
;
589 USHORT CreatorBackTraceIndex
;
591 LONG NextFreeTableEntry
;
593 } HANDLE_TABLE_ENTRY
, *PHANDLE_TABLE_ENTRY
;
595 typedef struct _HANDLE_TABLE
597 #if (NTDDI_VERSION >= NTDDI_WINXP)
600 PHANDLE_TABLE_ENTRY
**Table
;
602 PEPROCESS QuotaProcess
;
603 PVOID UniqueProcessId
;
604 #if (NTDDI_VERSION >= NTDDI_WINXP)
605 EX_PUSH_LOCK HandleTableLock
[4];
606 LIST_ENTRY HandleTableList
;
607 EX_PUSH_LOCK HandleContentionEvent
;
609 ERESOURCE HandleLock
;
610 LIST_ENTRY HandleTableList
;
611 KEVENT HandleContentionEvent
;
613 PHANDLE_TRACE_DEBUG_INFO DebugInfo
;
615 #if (NTDDI_VERSION >= NTDDI_LONGHORN)
621 LONG FirstFreeHandle
;
622 PHANDLE_TABLE_ENTRY LastFreeHandleEntry
;
624 ULONG NextHandleNeedingPool
;
628 ULONG NextHandleNeedingPool
;
636 } HANDLE_TABLE
, *PHANDLE_TABLE
;
641 // Hard Error LPC Message
643 typedef struct _HARDERROR_MSG
647 LARGE_INTEGER ErrorTime
;
648 ULONG ValidResponseOptions
;
650 ULONG NumberOfParameters
;
651 ULONG UnicodeStringParameterMask
;
652 ULONG Parameters
[MAXIMUM_HARDERROR_PARAMETERS
];
653 } HARDERROR_MSG
, *PHARDERROR_MSG
;
656 // Information Structures for NtQueryMutant
658 typedef struct _MUTANT_BASIC_INFORMATION
661 BOOLEAN OwnedByCaller
;
662 BOOLEAN AbandonedState
;
663 } MUTANT_BASIC_INFORMATION
, *PMUTANT_BASIC_INFORMATION
;
665 typedef struct _MUTANT_OWNER_INFORMATION
668 } MUTANT_OWNER_INFORMATION
, *PMUTANT_OWNER_INFORMATION
;
671 // Information Structures for NtQueryAtom
673 typedef struct _ATOM_BASIC_INFORMATION
679 } ATOM_BASIC_INFORMATION
, *PATOM_BASIC_INFORMATION
;
681 typedef struct _ATOM_TABLE_INFORMATION
685 } ATOM_TABLE_INFORMATION
, *PATOM_TABLE_INFORMATION
;
688 // Information Structures for NtQueryTimer
690 typedef struct _TIMER_BASIC_INFORMATION
692 LARGE_INTEGER TimeRemaining
;
694 } TIMER_BASIC_INFORMATION
, *PTIMER_BASIC_INFORMATION
;
697 // Information Structures for NtQuerySemaphore
699 typedef struct _SEMAPHORE_BASIC_INFORMATION
703 } SEMAPHORE_BASIC_INFORMATION
, *PSEMAPHORE_BASIC_INFORMATION
;
706 // Information Structures for NtQueryEvent
708 typedef struct _EVENT_BASIC_INFORMATION
710 EVENT_TYPE EventType
;
712 } EVENT_BASIC_INFORMATION
, *PEVENT_BASIC_INFORMATION
;
715 // Information Structures for NtQuerySystemInformation
717 typedef struct _SYSTEM_BASIC_INFORMATION
720 ULONG TimerResolution
;
722 ULONG NumberOfPhysicalPages
;
723 ULONG LowestPhysicalPageNumber
;
724 ULONG HighestPhysicalPageNumber
;
725 ULONG AllocationGranularity
;
726 ULONG MinimumUserModeAddress
;
727 ULONG MaximumUserModeAddress
;
728 KAFFINITY ActiveProcessorsAffinityMask
;
729 CCHAR NumberOfProcessors
;
730 } SYSTEM_BASIC_INFORMATION
, *PSYSTEM_BASIC_INFORMATION
;
733 typedef struct _SYSTEM_PROCESSOR_INFORMATION
735 USHORT ProcessorArchitecture
;
736 USHORT ProcessorLevel
;
737 USHORT ProcessorRevision
;
739 ULONG ProcessorFeatureBits
;
740 } SYSTEM_PROCESSOR_INFORMATION
, *PSYSTEM_PROCESSOR_INFORMATION
;
743 typedef struct _SYSTEM_PERFORMANCE_INFORMATION
745 LARGE_INTEGER IdleProcessTime
;
746 LARGE_INTEGER IoReadTransferCount
;
747 LARGE_INTEGER IoWriteTransferCount
;
748 LARGE_INTEGER IoOtherTransferCount
;
749 ULONG IoReadOperationCount
;
750 ULONG IoWriteOperationCount
;
751 ULONG IoOtherOperationCount
;
752 ULONG AvailablePages
;
753 ULONG CommittedPages
;
755 ULONG PeakCommitment
;
756 ULONG PageFaultCount
;
757 ULONG CopyOnWriteCount
;
758 ULONG TransitionCount
;
759 ULONG CacheTransitionCount
;
760 ULONG DemandZeroCount
;
762 ULONG PageReadIoCount
;
763 ULONG CacheReadCount
;
765 ULONG DirtyPagesWriteCount
;
766 ULONG DirtyWriteIoCount
;
767 ULONG MappedPagesWriteCount
;
768 ULONG MappedWriteIoCount
;
769 ULONG PagedPoolPages
;
770 ULONG NonPagedPoolPages
;
771 ULONG PagedPoolAllocs
;
772 ULONG PagedPoolFrees
;
773 ULONG NonPagedPoolAllocs
;
774 ULONG NonPagedPoolFrees
;
775 ULONG FreeSystemPtes
;
776 ULONG ResidentSystemCodePage
;
777 ULONG TotalSystemDriverPages
;
778 ULONG TotalSystemCodePages
;
779 ULONG NonPagedPoolLookasideHits
;
780 ULONG PagedPoolLookasideHits
;
782 ULONG ResidentSystemCachePage
;
783 ULONG ResidentPagedPoolPage
;
784 ULONG ResidentSystemDriverPage
;
785 ULONG CcFastReadNoWait
;
786 ULONG CcFastReadWait
;
787 ULONG CcFastReadResourceMiss
;
788 ULONG CcFastReadNotPossible
;
789 ULONG CcFastMdlReadNoWait
;
790 ULONG CcFastMdlReadWait
;
791 ULONG CcFastMdlReadResourceMiss
;
792 ULONG CcFastMdlReadNotPossible
;
793 ULONG CcMapDataNoWait
;
795 ULONG CcMapDataNoWaitMiss
;
796 ULONG CcMapDataWaitMiss
;
797 ULONG CcPinMappedDataCount
;
798 ULONG CcPinReadNoWait
;
800 ULONG CcPinReadNoWaitMiss
;
801 ULONG CcPinReadWaitMiss
;
802 ULONG CcCopyReadNoWait
;
803 ULONG CcCopyReadWait
;
804 ULONG CcCopyReadNoWaitMiss
;
805 ULONG CcCopyReadWaitMiss
;
806 ULONG CcMdlReadNoWait
;
808 ULONG CcMdlReadNoWaitMiss
;
809 ULONG CcMdlReadWaitMiss
;
810 ULONG CcReadAheadIos
;
811 ULONG CcLazyWriteIos
;
812 ULONG CcLazyWritePages
;
815 ULONG ContextSwitches
;
816 ULONG FirstLevelTbFills
;
817 ULONG SecondLevelTbFills
;
819 } SYSTEM_PERFORMANCE_INFORMATION
, *PSYSTEM_PERFORMANCE_INFORMATION
;
822 typedef struct _SYSTEM_TIMEOFDAY_INFORMATION
824 LARGE_INTEGER BootTime
;
825 LARGE_INTEGER CurrentTime
;
826 LARGE_INTEGER TimeZoneBias
;
829 } SYSTEM_TIMEOFDAY_INFORMATION
, *PSYSTEM_TIMEOFDAY_INFORMATION
;
832 // This class is obsolete, please use KUSER_SHARED_DATA instead
835 typedef struct _SYSTEM_THREAD_INFORMATION
837 LARGE_INTEGER KernelTime
;
838 LARGE_INTEGER UserTime
;
839 LARGE_INTEGER CreateTime
;
845 ULONG ContextSwitches
;
848 } SYSTEM_THREAD_INFORMATION
, *PSYSTEM_THREAD_INFORMATION
;
850 typedef struct _SYSTEM_PROCESS_INFORMATION
852 ULONG NextEntryOffset
;
853 ULONG NumberOfThreads
;
854 LARGE_INTEGER SpareLi1
;
855 LARGE_INTEGER SpareLi2
;
856 LARGE_INTEGER SpareLi3
;
857 LARGE_INTEGER CreateTime
;
858 LARGE_INTEGER UserTime
;
859 LARGE_INTEGER KernelTime
;
860 UNICODE_STRING ImageName
;
861 KPRIORITY BasePriority
;
862 HANDLE UniqueProcessId
;
863 HANDLE InheritedFromUniqueProcessId
;
866 ULONG UniqueProcessKey
;
869 // This part corresponds to VM_COUNTERS_EX.
870 // NOTE: *NOT* THE SAME AS VM_COUNTERS!
872 ULONG PeakVirtualSize
;
874 ULONG PageFaultCount
;
875 ULONG PeakWorkingSetSize
;
876 ULONG WorkingSetSize
;
877 ULONG QuotaPeakPagedPoolUsage
;
878 ULONG QuotaPagedPoolUsage
;
879 ULONG QuotaPeakNonPagedPoolUsage
;
880 ULONG QuotaNonPagedPoolUsage
;
882 ULONG PeakPagefileUsage
;
883 ULONG PrivatePageCount
;
886 // This part corresponds to IO_COUNTERS
888 LARGE_INTEGER ReadOperationCount
;
889 LARGE_INTEGER WriteOperationCount
;
890 LARGE_INTEGER OtherOperationCount
;
891 LARGE_INTEGER ReadTransferCount
;
892 LARGE_INTEGER WriteTransferCount
;
893 LARGE_INTEGER OtherTransferCount
;
895 //SYSTEM_THREAD_INFORMATION TH[1];
896 } SYSTEM_PROCESS_INFORMATION
, *PSYSTEM_PROCESS_INFORMATION
;
899 typedef struct _SYSTEM_CALL_COUNT_INFORMATION
902 ULONG NumberOfTables
;
903 } SYSTEM_CALL_COUNT_INFORMATION
, *PSYSTEM_CALL_COUNT_INFORMATION
;
906 typedef struct _SYSTEM_DEVICE_INFORMATION
909 ULONG NumberOfFloppies
;
910 ULONG NumberOfCdRoms
;
912 ULONG NumberOfSerialPorts
;
913 ULONG NumberOfParallelPorts
;
914 } SYSTEM_DEVICE_INFORMATION
, *PSYSTEM_DEVICE_INFORMATION
;
917 typedef struct _SYSTEM_PROCESSOR_PERFORMANCE_INFORMATION
919 LARGE_INTEGER IdleTime
;
920 LARGE_INTEGER KernelTime
;
921 LARGE_INTEGER UserTime
;
922 LARGE_INTEGER DpcTime
;
923 LARGE_INTEGER InterruptTime
;
924 ULONG InterruptCount
;
925 } SYSTEM_PROCESSOR_PERFORMANCE_INFORMATION
, *PSYSTEM_PROCESSOR_PERFORMANCE_INFORMATION
;
928 typedef struct _SYSTEM_FLAGS_INFORMATION
931 } SYSTEM_FLAGS_INFORMATION
, *PSYSTEM_FLAGS_INFORMATION
;
934 typedef struct _SYSTEM_CALL_TIME_INFORMATION
938 LARGE_INTEGER TimeOfCalls
[1];
939 } SYSTEM_CALL_TIME_INFORMATION
, *PSYSTEM_CALL_TIME_INFORMATION
;
941 // Class 11 - See RTL_PROCESS_MODULES
943 // Class 12 - See RTL_PROCESS_LOCKS
945 // Class 13 - See RTL_PROCESS_BACKTRACES
948 typedef struct _SYSTEM_POOL_ENTRY
952 USHORT AllocatorBackTraceIndex
;
958 PVOID ProcessChargedQuota
;
960 } SYSTEM_POOL_ENTRY
, *PSYSTEM_POOL_ENTRY
;
962 typedef struct _SYSTEM_POOL_INFORMATION
966 USHORT EntryOverhead
;
967 BOOLEAN PoolTagPresent
;
969 ULONG NumberOfEntries
;
970 SYSTEM_POOL_ENTRY Entries
[1];
971 } SYSTEM_POOL_INFORMATION
, *PSYSTEM_POOL_INFORMATION
;
974 typedef struct _SYSTEM_HANDLE_TABLE_ENTRY_INFO
976 USHORT UniqueProcessId
;
977 USHORT CreatorBackTraceIndex
;
978 UCHAR ObjectTypeIndex
;
979 UCHAR HandleAttributes
;
983 } SYSTEM_HANDLE_TABLE_ENTRY_INFO
, *PSYSTEM_HANDLE_TABLE_ENTRY_INFO
;
985 typedef struct _SYSTEM_HANDLE_INFORMATION
987 ULONG NumberOfHandles
;
988 SYSTEM_HANDLE_TABLE_ENTRY_INFO Handles
[1];
989 } SYSTEM_HANDLE_INFORMATION
, *PSYSTEM_HANDLE_INFORMATION
;
992 typedef struct _SYSTEM_OBJECTTYPE_INFORMATION
994 ULONG NextEntryOffset
;
995 ULONG NumberOfObjects
;
996 ULONG NumberOfHandles
;
998 ULONG InvalidAttributes
;
999 GENERIC_MAPPING GenericMapping
;
1000 ULONG ValidAccessMask
;
1002 BOOLEAN SecurityRequired
;
1003 BOOLEAN WaitableObject
;
1004 UNICODE_STRING TypeName
;
1005 } SYSTEM_OBJECTTYPE_INFORMATION
, *PSYSTEM_OBJECTTYPE_INFORMATION
;
1007 typedef struct _SYSTEM_OBJECT_INFORMATION
1009 ULONG NextEntryOffset
;
1011 HANDLE CreatorUniqueProcess
;
1012 USHORT CreatorBackTraceIndex
;
1016 ULONG PagedPoolCharge
;
1017 ULONG NonPagedPoolCharge
;
1018 HANDLE ExclusiveProcessId
;
1019 PVOID SecurityDescriptor
;
1020 OBJECT_NAME_INFORMATION NameInfo
;
1021 } SYSTEM_OBJECT_INFORMATION
, *PSYSTEM_OBJECT_INFORMATION
;
1024 typedef struct _SYSTEM_PAGEFILE_INFORMATION
1026 ULONG NextEntryOffset
;
1030 UNICODE_STRING PageFileName
;
1031 } SYSTEM_PAGEFILE_INFORMATION
, *PSYSTEM_PAGEFILE_INFORMATION
;
1034 typedef struct _SYSTEM_VDM_INSTEMUL_INFO
1036 ULONG SegmentNotPresent
;
1038 ULONG OpcodeESPrefix
;
1039 ULONG OpcodeCSPrefix
;
1040 ULONG OpcodeSSPrefix
;
1041 ULONG OpcodeDSPrefix
;
1042 ULONG OpcodeFSPrefix
;
1043 ULONG OpcodeGSPrefix
;
1044 ULONG OpcodeOPER32Prefix
;
1045 ULONG OpcodeADDR32Prefix
;
1057 ULONG OpcodeOUTBimm
;
1058 ULONG OpcodeOUTWimm
;
1063 ULONG OpcodeLOCKPrefix
;
1064 ULONG OpcodeREPNEPrefix
;
1065 ULONG OpcodeREPPrefix
;
1070 } SYSTEM_VDM_INSTEMUL_INFO
, *PSYSTEM_VDM_INSTEMUL_INFO
;
1072 // Class 20 - ULONG VDMBOPINFO
1075 typedef struct _SYSTEM_FILECACHE_INFORMATION
1079 ULONG PageFaultCount
;
1080 ULONG MinimumWorkingSet
;
1081 ULONG MaximumWorkingSet
;
1082 ULONG CurrentSizeIncludingTransitionInPages
;
1083 ULONG PeakSizeIncludingTransitionInPages
;
1084 ULONG TransitionRePurposeCount
;
1086 } SYSTEM_FILECACHE_INFORMATION
, *PSYSTEM_FILECACHE_INFORMATION
;
1089 typedef struct _SYSTEM_POOLTAG
1099 ULONG NonPagedAllocs
;
1100 ULONG NonPagedFrees
;
1102 } SYSTEM_POOLTAG
, *PSYSTEM_POOLTAG
;
1103 typedef struct _SYSTEM_POOLTAG_INFORMATION
1106 SYSTEM_POOLTAG TagInfo
[1];
1107 } SYSTEM_POOLTAG_INFORMATION
, *PSYSTEM_POOLTAG_INFORMATION
;
1110 typedef struct _SYSTEM_INTERRUPT_INFORMATION
1112 ULONG ContextSwitches
;
1115 ULONG TimeIncrement
;
1116 ULONG DpcBypassCount
;
1117 ULONG ApcBypassCount
;
1118 } SYSTEM_INTERRUPT_INFORMATION
, *PSYSTEM_INTERRUPT_INFORMATION
;
1121 typedef struct _SYSTEM_DPC_BEHAVIOR_INFORMATION
1124 ULONG DpcQueueDepth
;
1125 ULONG MinimumDpcRate
;
1126 ULONG AdjustDpcThreshold
;
1128 } SYSTEM_DPC_BEHAVIOR_INFORMATION
, *PSYSTEM_DPC_BEHAVIOR_INFORMATION
;
1131 typedef struct _SYSTEM_MEMORY_INFO
1133 PUCHAR StringOffset
;
1135 USHORT TransitionCount
;
1136 USHORT ModifiedCount
;
1137 USHORT PageTableCount
;
1138 } SYSTEM_MEMORY_INFO
, *PSYSTEM_MEMORY_INFO
;
1140 typedef struct _SYSTEM_MEMORY_INFORMATION
1144 SYSTEM_MEMORY_INFO Memory
[1];
1145 } SYSTEM_MEMORY_INFORMATION
, *PSYSTEM_MEMORY_INFORMATION
;
1148 typedef struct _SYSTEM_GDI_DRIVER_INFORMATION
1150 UNICODE_STRING DriverName
;
1152 PVOID SectionPointer
;
1154 PIMAGE_EXPORT_DIRECTORY ExportSectionPointer
;
1156 } SYSTEM_GDI_DRIVER_INFORMATION
, *PSYSTEM_GDI_DRIVER_INFORMATION
;
1159 // Not an actually class, simply a PVOID to the ImageAddress
1162 typedef struct _SYSTEM_QUERY_TIME_ADJUST_INFORMATION
1164 ULONG TimeAdjustment
;
1165 ULONG TimeIncrement
;
1167 } SYSTEM_QUERY_TIME_ADJUST_INFORMATION
, *PSYSTEM_QUERY_TIME_ADJUST_INFORMATION
;
1169 typedef struct _SYSTEM_SET_TIME_ADJUST_INFORMATION
1171 ULONG TimeAdjustment
;
1173 } SYSTEM_SET_TIME_ADJUST_INFORMATION
, *PSYSTEM_SET_TIME_ADJUST_INFORMATION
;
1175 // Class 29 - Same as 25
1180 typedef struct _SYSTEM_REF_TRACE_INFORMATION
1183 UCHAR TracePermanent
;
1184 UNICODE_STRING TraceProcessName
;
1185 UNICODE_STRING TracePoolTags
;
1186 } SYSTEM_REF_TRACE_INFORMATION
, *PSYSTEM_REF_TRACE_INFORMATION
;
1188 // Class 32 - OBSOLETE
1191 typedef struct _SYSTEM_EXCEPTION_INFORMATION
1193 ULONG AlignmentFixupCount
;
1194 ULONG ExceptionDispatchCount
;
1195 ULONG FloatingEmulationCount
;
1196 ULONG ByteWordEmulationCount
;
1197 } SYSTEM_EXCEPTION_INFORMATION
, *PSYSTEM_EXCEPTION_INFORMATION
;
1200 typedef struct _SYSTEM_CRASH_STATE_INFORMATION
1202 ULONG ValidCrashDump
;
1203 } SYSTEM_CRASH_STATE_INFORMATION
, *PSYSTEM_CRASH_STATE_INFORMATION
;
1206 typedef struct _SYSTEM_KERNEL_DEBUGGER_INFORMATION
1208 BOOLEAN KernelDebuggerEnabled
;
1209 BOOLEAN KernelDebuggerNotPresent
;
1210 } SYSTEM_KERNEL_DEBUGGER_INFORMATION
, *PSYSTEM_KERNEL_DEBUGGER_INFORMATION
;
1213 typedef struct _SYSTEM_CONTEXT_SWITCH_INFORMATION
1215 ULONG ContextSwitches
;
1224 ULONG PreemptCurrent
;
1227 } SYSTEM_CONTEXT_SWITCH_INFORMATION
, *PSYSTEM_CONTEXT_SWITCH_INFORMATION
;
1230 typedef struct _SYSTEM_REGISTRY_QUOTA_INFORMATION
1232 ULONG RegistryQuotaAllowed
;
1233 ULONG RegistryQuotaUsed
;
1234 ULONG PagedPoolSize
;
1235 } SYSTEM_REGISTRY_QUOTA_INFORMATION
, *PSYSTEM_REGISTRY_QUOTA_INFORMATION
;
1238 // Not a structure, simply send the UNICODE_STRING
1241 // Not a structure, simply send a ULONG containing the new separation
1244 typedef struct _SYSTEM_PLUGPLAY_BUS_INFORMATION
1247 PLUGPLAY_BUS_INSTANCE BusInstance
[1];
1248 } SYSTEM_PLUGPLAY_BUS_INFORMATION
, *PSYSTEM_PLUGPLAY_BUS_INFORMATION
;
1251 typedef struct _SYSTEM_DOCK_INFORMATION
1253 SYSTEM_DOCK_STATE DockState
;
1254 INTERFACE_TYPE DeviceBusType
;
1255 ULONG DeviceBusNumber
;
1257 } SYSTEM_DOCK_INFORMATION
, *PSYSTEM_DOCK_INFORMATION
;
1260 typedef struct _SYSTEM_POWER_INFORMATION_NATIVE
1262 BOOLEAN SystemSuspendSupported
;
1263 BOOLEAN SystemHibernateSupported
;
1264 BOOLEAN ResumeTimerSupportsSuspend
;
1265 BOOLEAN ResumeTimerSupportsHibernate
;
1266 BOOLEAN LidSupported
;
1267 BOOLEAN TurboSettingSupported
;
1269 BOOLEAN SystemAcOrDc
;
1270 BOOLEAN PowerDownDisabled
;
1271 LARGE_INTEGER SpindownDrives
;
1272 } SYSTEM_POWER_INFORMATION_NATIVE
, *PSYSTEM_POWER_INFORMATION_NATIVE
;
1275 typedef struct _SYSTEM_LEGACY_DRIVER_INFORMATION
1277 PNP_VETO_TYPE VetoType
;
1278 UNICODE_STRING VetoDriver
;
1280 } SYSTEM_LEGACY_DRIVER_INFORMATION
, *PSYSTEM_LEGACY_DRIVER_INFORMATION
;
1283 //typedef struct _TIME_ZONE_INFORMATION RTL_TIME_ZONE_INFORMATION;
1286 typedef struct _SYSTEM_LOOKASIDE_INFORMATION
1288 USHORT CurrentDepth
;
1289 USHORT MaximumDepth
;
1290 ULONG TotalAllocates
;
1291 ULONG AllocateMisses
;
1297 } SYSTEM_LOOKASIDE_INFORMATION
, *PSYSTEM_LOOKASIDE_INFORMATION
;
1300 // Not a structure. Only a HANDLE for the SlipEvent;
1303 // Not a structure. Only a ULONG for the SessionId;
1306 // Not a structure. Only a ULONG for the SessionId;
1311 // Not a structure. Only a ULONG_PTR for the SystemRangeStart
1314 typedef struct _SYSTEM_VERIFIER_INFORMATION
1316 ULONG NextEntryOffset
;
1318 UNICODE_STRING DriverName
;
1320 ULONG AcquireSpinLocks
;
1321 ULONG SynchronizeExecutions
;
1322 ULONG AllocationsAttempted
;
1323 ULONG AllocationsSucceeded
;
1324 ULONG AllocationsSucceededSpecialPool
;
1325 ULONG AllocationsWithNoTag
;
1328 ULONG AllocationsFailed
;
1329 ULONG AllocationsFailedDeliberately
;
1332 ULONG UnTrackedPool
;
1333 ULONG CurrentPagedPoolAllocations
;
1334 ULONG CurrentNonPagedPoolAllocations
;
1335 ULONG PeakPagedPoolAllocations
;
1336 ULONG PeakNonPagedPoolAllocations
;
1337 ULONG PagedPoolUsageInBytes
;
1338 ULONG NonPagedPoolUsageInBytes
;
1339 ULONG PeakPagedPoolUsageInBytes
;
1340 ULONG PeakNonPagedPoolUsageInBytes
;
1341 } SYSTEM_VERIFIER_INFORMATION
, *PSYSTEM_VERIFIER_INFORMATION
;
1346 typedef struct _SYSTEM_SESSION_PROCESS_INFORMATION
1350 PVOID Buffer
; // Same format as in SystemProcessInformation
1351 } SYSTEM_SESSION_PROCESS_INFORMATION
, *PSYSTEM_SESSION_PROCESS_INFORMATION
;
1353 // FIXME: Class 54-97
1358 #define RTL_HOTPATCH_SUPPORTED_FLAG 0x01
1359 #define RTL_HOTPATCH_SWAP_OBJECT_NAMES 0x08 << 24
1360 #define RTL_HOTPATCH_SYNC_RENAME_FILES 0x10 << 24
1361 #define RTL_HOTPATCH_PATCH_USER_MODE 0x20 << 24
1362 #define RTL_HOTPATCH_REMAP_SYSTEM_DLL 0x40 << 24
1363 #define RTL_HOTPATCH_PATCH_KERNEL_MODE 0x80 << 24
1367 typedef struct _SYSTEM_HOTPATCH_CODE_INFORMATION
1386 USHORT TargetNameOffset
;
1387 USHORT TargetNameLength
;
1388 UCHAR PatchingFinished
;
1394 USHORT TargetNameOffset
;
1395 USHORT TargetNameLength
;
1396 UCHAR PatchingFinished
;
1397 NTSTATUS ReturnCode
;
1398 HANDLE TargetProcess
;
1403 PIO_STATUS_BLOCK IoStatusBlock1
;
1404 PVOID RenameInformation1
;
1405 PVOID RenameInformationLength1
;
1407 PIO_STATUS_BLOCK IoStatusBlock2
;
1408 PVOID RenameInformation2
;
1409 PVOID RenameInformationLength2
;
1413 HANDLE ParentDirectory
;
1414 HANDLE ObjectHandle1
;
1415 HANDLE ObjectHandle2
;
1418 } SYSTEM_HOTPATCH_CODE_INFORMATION
, *PSYSTEM_HOTPATCH_CODE_INFORMATION
;
1423 #ifdef NTOS_MODE_USER
1424 typedef struct _SYSTEM_FIRMWARE_TABLE_HANDLER
1426 ULONG ProviderSignature
;
1428 PFNFTH FirmwareTableHandler
;
1430 } SYSTEM_FIRMWARE_TABLE_HANDLER
, *PSYSTEM_FIRMWARE_TABLE_HANDLER
;
1435 typedef struct _SYSTEM_FIRMWARE_TABLE_INFORMATION
1437 ULONG ProviderSignature
;
1438 SYSTEM_FIRMWARE_TABLE_ACTION Action
;
1440 ULONG TableBufferLength
;
1441 UCHAR TableBuffer
[1];
1442 } SYSTEM_FIRMWARE_TABLE_INFORMATION
, *PSYSTEM_FIRMWARE_TABLE_INFORMATION
;