4 * Copyright 1996 Alexandre Julliard
5 * Copyright 1998 Ulrich Weigand
10 #include <ntdll/rtl.h>
11 #include <ntos/heap.h>
12 #include <ntos/minmax.h>
15 #include <ntdll/ntdll.h>
17 CRITICAL_SECTION ProcessHeapsLock
;
19 /* Note: the heap data structures are based on what Pietrek describes in his
20 * book 'Windows 95 System Programming Secrets'. The layout is not exactly
21 * the same, but could be easily adapted if it turns out some programs
25 typedef struct tagARENA_INUSE
27 DWORD size
; /* Block size; must be the first field */
28 WORD threadId
; /* Allocating thread id */
29 WORD magic
; /* Magic number */
30 DWORD callerEIP
; /* EIP of caller upon allocation */
33 typedef struct tagARENA_FREE
35 DWORD size
; /* Block size; must be the first field */
36 WORD threadId
; /* Freeing thread id */
37 WORD magic
; /* Magic number */
38 struct tagARENA_FREE
*next
; /* Next free arena */
39 struct tagARENA_FREE
*prev
; /* Prev free arena */
42 #define ARENA_FLAG_FREE 0x00000001 /* flags OR'ed with arena size */
43 #define ARENA_FLAG_PREV_FREE 0x00000002
44 #define ARENA_SIZE_MASK 0xfffffffc
45 #define ARENA_INUSE_MAGIC 0x4842 /* Value for arena 'magic' field */
46 #define ARENA_FREE_MAGIC 0x4846 /* Value for arena 'magic' field */
48 #define ARENA_INUSE_FILLER 0x55
49 #define ARENA_FREE_FILLER 0xaa
51 #define HEAP_NB_FREE_LISTS 4 /* Number of free lists */
53 /* Max size of the blocks on the free lists */
54 static const DWORD HEAP_freeListSizes
[HEAP_NB_FREE_LISTS
] =
56 0x20, 0x80, 0x200, 0xffffffff
67 typedef struct tagSUBHEAP
69 DWORD size
; /* Size of the whole sub-heap */
70 DWORD commitSize
; /* Committed size of the sub-heap */
71 DWORD headerSize
; /* Size of the heap header */
72 struct tagSUBHEAP
*next
; /* Next sub-heap */
73 struct tagHEAP
*heap
; /* Main heap structure */
74 DWORD magic
; /* Magic number */
75 WORD selector
; /* Selector for HEAP_WINE_SEGPTR heaps */
78 #define SUBHEAP_MAGIC ((DWORD)('S' | ('U'<<8) | ('B'<<16) | ('H'<<24)))
80 typedef struct tagHEAP
82 SUBHEAP subheap
; /* First sub-heap */
83 struct tagHEAP
*next
; /* Next heap for this process */
84 FREE_LIST_ENTRY freeList
[HEAP_NB_FREE_LISTS
]; /* Free lists */
85 CRITICAL_SECTION critSection
; /* Critical section for serialization */
86 DWORD flags
; /* Heap flags */
87 DWORD magic
; /* Magic number */
90 #define HEAP_MAGIC ((DWORD)('H' | ('E'<<8) | ('A'<<16) | ('P'<<24)))
92 #define HEAP_DEF_SIZE 0x110000 /* Default heap size = 1Mb + 64Kb */
93 #define HEAP_MIN_BLOCK_SIZE (8+sizeof(ARENA_FREE)) /* Min. heap block size */
96 /***********************************************************************
99 void HEAP_Dump( HEAP
*heap
)
105 DPRINT( "Heap: %08lx\n", (DWORD
)heap
);
106 DPRINT( "Next: %08lx Sub-heaps: %08lx",
107 (DWORD
)heap
->next
, (DWORD
)&heap
->subheap
);
108 subheap
= &heap
->subheap
;
109 while (subheap
->next
)
111 DPRINT( " -> %08lx", (DWORD
)subheap
->next
);
112 subheap
= subheap
->next
;
115 DPRINT( "\nFree lists:\n Block Stat Size Id\n" );
116 for (i
= 0; i
< HEAP_NB_FREE_LISTS
; i
++)
117 DPRINT( "%08lx free %08lx %04x prev=%08lx next=%08lx\n",
118 (DWORD
)&heap
->freeList
[i
].arena
, heap
->freeList
[i
].arena
.size
,
119 heap
->freeList
[i
].arena
.threadId
,
120 (DWORD
)heap
->freeList
[i
].arena
.prev
,
121 (DWORD
)heap
->freeList
[i
].arena
.next
);
123 subheap
= &heap
->subheap
;
126 DWORD freeSize
= 0, usedSize
= 0, arenaSize
= subheap
->headerSize
;
127 DPRINT( "\n\nSub-heap %08lx: size=%08lx committed=%08lx\n",
128 (DWORD
)subheap
, subheap
->size
, subheap
->commitSize
);
130 DPRINT( "\n Block Stat Size Id\n" );
131 ptr
= (char*)subheap
+ subheap
->headerSize
;
132 while (ptr
< (char *)subheap
+ subheap
->size
)
134 if (*(DWORD
*)ptr
& ARENA_FLAG_FREE
)
136 ARENA_FREE
*pArena
= (ARENA_FREE
*)ptr
;
137 DPRINT( "%08lx free %08lx %04x prev=%08lx next=%08lx\n",
138 (DWORD
)pArena
, pArena
->size
& ARENA_SIZE_MASK
,
139 pArena
->threadId
, (DWORD
)pArena
->prev
,
140 (DWORD
)pArena
->next
);
141 ptr
+= sizeof(*pArena
) + (pArena
->size
& ARENA_SIZE_MASK
);
142 arenaSize
+= sizeof(ARENA_FREE
);
143 freeSize
+= pArena
->size
& ARENA_SIZE_MASK
;
145 else if (*(DWORD
*)ptr
& ARENA_FLAG_PREV_FREE
)
147 ARENA_INUSE
*pArena
= (ARENA_INUSE
*)ptr
;
148 DPRINT( "%08lx Used %08lx %04x back=%08lx EIP=%08lx\n",
149 (DWORD
)pArena
, pArena
->size
& ARENA_SIZE_MASK
,
150 pArena
->threadId
, *((DWORD
*)pArena
- 1),
152 ptr
+= sizeof(*pArena
) + (pArena
->size
& ARENA_SIZE_MASK
);
153 arenaSize
+= sizeof(ARENA_INUSE
);
154 usedSize
+= pArena
->size
& ARENA_SIZE_MASK
;
158 ARENA_INUSE
*pArena
= (ARENA_INUSE
*)ptr
;
159 DPRINT( "%08lx used %08lx %04x EIP=%08lx\n",
160 (DWORD
)pArena
, pArena
->size
& ARENA_SIZE_MASK
,
161 pArena
->threadId
, pArena
->callerEIP
);
162 ptr
+= sizeof(*pArena
) + (pArena
->size
& ARENA_SIZE_MASK
);
163 arenaSize
+= sizeof(ARENA_INUSE
);
164 usedSize
+= pArena
->size
& ARENA_SIZE_MASK
;
167 DPRINT( "\nTotal: Size=%08lx Committed=%08lx Free=%08lx Used=%08lx Arenas=%08lx (%ld%%)\n\n",
168 subheap
->size
, subheap
->commitSize
, freeSize
, usedSize
,
169 arenaSize
, (arenaSize
* 100) / subheap
->size
);
170 subheap
= subheap
->next
;
175 /***********************************************************************
178 * Pointer to the heap
181 static HEAP
*HEAP_GetPtr(
182 HANDLE heap
/* [in] Handle to the heap */
184 HEAP
*heapPtr
= (HEAP
*)heap
;
185 if (!heapPtr
|| (heapPtr
->magic
!= HEAP_MAGIC
))
187 DPRINT(heap
, "Invalid heap %08x!\n", heap
);
188 // SetLastError( ERROR_INVALID_HANDLE );
191 if (!RtlValidateHeap( heap
, 0, NULL
))
193 HEAP_Dump( heapPtr
);
194 DPRINT("NTDLL:%s:%d: assertion failed\n",__FILE__
,__LINE__
);
195 // SetLastError( ERROR_INVALID_HANDLE );
202 /***********************************************************************
203 * HEAP_InsertFreeBlock
205 * Insert a free block into the free list.
207 static void HEAP_InsertFreeBlock( HEAP
*heap
, ARENA_FREE
*pArena
)
209 FREE_LIST_ENTRY
*pEntry
= heap
->freeList
;
210 while (pEntry
->size
< pArena
->size
) pEntry
++;
211 pArena
->size
|= ARENA_FLAG_FREE
;
212 pArena
->next
= pEntry
->arena
.next
;
213 pArena
->next
->prev
= pArena
;
214 pArena
->prev
= &pEntry
->arena
;
215 pEntry
->arena
.next
= pArena
;
219 /***********************************************************************
221 * Find the sub-heap containing a given address.
227 static SUBHEAP
*HEAP_FindSubHeap(
228 HEAP
*heap
, /* [in] Heap pointer */
229 LPCVOID ptr
/* [in] Address */
231 SUBHEAP
*sub
= &heap
->subheap
;
234 if (((char *)ptr
>= (char *)sub
) &&
235 ((char *)ptr
< (char *)sub
+ sub
->size
)) return sub
;
242 /***********************************************************************
245 * Make sure the heap storage is committed up to (not including) ptr.
247 static BOOL
HEAP_Commit( SUBHEAP
*subheap
, void *ptr
)
249 DWORD size
= (DWORD
)((char *)ptr
- (char *)subheap
);
254 size
= (size
+ 0xfff) & 0xfffff000; /* Align size on a page boundary */
255 if (size
> subheap
->size
) size
= subheap
->size
;
256 if (size
<= subheap
->commitSize
) return TRUE
;
257 commitsize
= size
- subheap
->commitSize
;
258 address
= (PVOID
)((char *)subheap
+ subheap
->commitSize
);
259 Status
= ZwAllocateVirtualMemory(NtCurrentProcess(),
264 PAGE_EXECUTE_READWRITE
);
265 if (!NT_SUCCESS(Status
))
267 DPRINT("ZwAllocateVirtualMemory failed\n");
270 subheap
->commitSize
= size
;
275 /***********************************************************************
278 * If possible, decommit the heap storage from (including) 'ptr'.
280 static BOOL
HEAP_Decommit( SUBHEAP
*subheap
, void *ptr
)
282 DWORD size
= (DWORD
)((char *)ptr
- (char *)subheap
);
287 size
= (size
+ 0xfff) & 0xfffff000; /* Align size on a page boundary */
288 if (size
>= subheap
->commitSize
) return TRUE
;
289 freebase
= (PVOID
)((char *)subheap
+ size
);
290 freesize
= subheap
->commitSize
- size
;
291 Status
= ZwFreeVirtualMemory(NtCurrentProcess(),
295 if (!NT_SUCCESS(Status
))
297 DPRINT("Could not decommit %08lx bytes at %08lx for heap %08lx\n",
298 subheap
->commitSize
- size
,
299 (DWORD
)((char *)subheap
+ size
),
300 (DWORD
)subheap
->heap
);
303 subheap
->commitSize
= size
;
308 /***********************************************************************
309 * HEAP_CreateFreeBlock
311 * Create a free block at a specified address. 'size' is the size of the
312 * whole block, including the new arena.
314 static void HEAP_CreateFreeBlock( SUBHEAP
*subheap
, void *ptr
, DWORD size
)
318 /* Create a free arena */
320 pFree
= (ARENA_FREE
*)ptr
;
321 pFree
->magic
= ARENA_FREE_MAGIC
;
323 /* If debugging, erase the freed block content */
327 char *pEnd
= (char *)ptr
+ size
;
328 if (pEnd
> (char *)subheap
+ subheap
->commitSize
)
329 pEnd
= (char *)subheap
+ subheap
->commitSize
;
330 if (pEnd
> (char *)(pFree
+ 1))
331 memset( pFree
+ 1, ARENA_FREE_FILLER
, pEnd
- (char *)(pFree
+ 1) );
334 /* Check if next block is free also */
336 if (((char *)ptr
+ size
< (char *)subheap
+ subheap
->size
) &&
337 (*(DWORD
*)((char *)ptr
+ size
) & ARENA_FLAG_FREE
))
339 /* Remove the next arena from the free list */
340 ARENA_FREE
*pNext
= (ARENA_FREE
*)((char *)ptr
+ size
);
341 pNext
->next
->prev
= pNext
->prev
;
342 pNext
->prev
->next
= pNext
->next
;
343 size
+= (pNext
->size
& ARENA_SIZE_MASK
) + sizeof(*pNext
);
345 memset( pNext
, ARENA_FREE_FILLER
, sizeof(ARENA_FREE
) );
348 /* Set the next block PREV_FREE flag and pointer */
350 if ((char *)ptr
+ size
< (char *)subheap
+ subheap
->size
)
352 DWORD
*pNext
= (DWORD
*)((char *)ptr
+ size
);
353 *pNext
|= ARENA_FLAG_PREV_FREE
;
354 *(ARENA_FREE
**)(pNext
- 1) = pFree
;
357 /* Last, insert the new block into the free list */
359 pFree
->size
= size
- sizeof(*pFree
);
360 HEAP_InsertFreeBlock( subheap
->heap
, pFree
);
364 /***********************************************************************
365 * HEAP_MakeInUseBlockFree
367 * Turn an in-use block into a free block. Can also decommit the end of
368 * the heap, and possibly even free the sub-heap altogether.
370 static void HEAP_MakeInUseBlockFree( SUBHEAP
*subheap
, ARENA_INUSE
*pArena
)
373 DWORD size
= (pArena
->size
& ARENA_SIZE_MASK
) + sizeof(*pArena
);
375 /* Check if we can merge with previous block */
377 if (pArena
->size
& ARENA_FLAG_PREV_FREE
)
379 pFree
= *((ARENA_FREE
**)pArena
- 1);
380 size
+= (pFree
->size
& ARENA_SIZE_MASK
) + sizeof(ARENA_FREE
);
381 /* Remove it from the free list */
382 pFree
->next
->prev
= pFree
->prev
;
383 pFree
->prev
->next
= pFree
->next
;
385 else pFree
= (ARENA_FREE
*)pArena
;
387 /* Create a free block */
389 HEAP_CreateFreeBlock( subheap
, pFree
, size
);
390 size
= (pFree
->size
& ARENA_SIZE_MASK
) + sizeof(ARENA_FREE
);
391 if ((char *)pFree
+ size
< (char *)subheap
+ subheap
->size
)
392 return; /* Not the last block, so nothing more to do */
394 /* Free the whole sub-heap if it's empty and not the original one */
396 if (((char *)pFree
== (char *)subheap
+ subheap
->headerSize
) &&
397 (subheap
!= &subheap
->heap
->subheap
))
399 SUBHEAP
*pPrev
= &subheap
->heap
->subheap
;
400 /* Remove the free block from the list */
401 pFree
->next
->prev
= pFree
->prev
;
402 pFree
->prev
->next
= pFree
->next
;
403 /* Remove the subheap from the list */
404 while (pPrev
&& (pPrev
->next
!= subheap
)) pPrev
= pPrev
->next
;
405 if (pPrev
) pPrev
->next
= subheap
->next
;
406 /* Free the memory */
408 ZwFreeVirtualMemory(NtCurrentProcess(), (PVOID
*)&subheap
, 0, MEM_RELEASE
);
412 /* Decommit the end of the heap */
414 HEAP_Decommit( subheap
, pFree
+ 1 );
418 /***********************************************************************
421 * Shrink an in-use block.
423 static void HEAP_ShrinkBlock(SUBHEAP
*subheap
, ARENA_INUSE
*pArena
, DWORD size
)
425 if ((pArena
->size
& ARENA_SIZE_MASK
) >= size
+ HEAP_MIN_BLOCK_SIZE
)
427 HEAP_CreateFreeBlock( subheap
, (char *)(pArena
+ 1) + size
,
428 (pArena
->size
& ARENA_SIZE_MASK
) - size
);
429 pArena
->size
= (pArena
->size
& ~ARENA_SIZE_MASK
) | size
;
433 /* Turn off PREV_FREE flag in next block */
434 char *pNext
= (char *)(pArena
+ 1) + (pArena
->size
& ARENA_SIZE_MASK
);
435 if (pNext
< (char *)subheap
+ subheap
->size
)
436 *(DWORD
*)pNext
&= ~ARENA_FLAG_PREV_FREE
;
440 /***********************************************************************
443 static BOOL
HEAP_InitSubHeap( HEAP
*heap
, LPVOID address
, DWORD flags
,
444 DWORD commitSize
, DWORD totalSize
)
446 SUBHEAP
*subheap
= (SUBHEAP
*)address
;
447 FREE_LIST_ENTRY
*pEntry
;
453 Status
= ZwAllocateVirtualMemory(NtCurrentProcess(),
458 PAGE_EXECUTE_READWRITE
);
459 if (!NT_SUCCESS(Status
))
461 DPRINT("Could not commit %08lx bytes for sub-heap %08lx\n",
462 commitSize
, (DWORD
)address
);
467 /* Fill the sub-heap structure */
469 subheap
->heap
= heap
;
470 subheap
->size
= totalSize
;
471 subheap
->commitSize
= commitSize
;
472 subheap
->magic
= SUBHEAP_MAGIC
;
474 if ( subheap
!= (SUBHEAP
*)heap
)
476 /* If this is a secondary subheap, insert it into list */
478 subheap
->headerSize
= sizeof(SUBHEAP
);
479 subheap
->next
= heap
->subheap
.next
;
480 heap
->subheap
.next
= subheap
;
484 /* If this is a primary subheap, initialize main heap */
486 subheap
->headerSize
= sizeof(HEAP
);
487 subheap
->next
= NULL
;
490 heap
->magic
= HEAP_MAGIC
;
492 /* Build the free lists */
494 for (i
= 0, pEntry
= heap
->freeList
; i
< HEAP_NB_FREE_LISTS
; i
++, pEntry
++)
496 pEntry
->size
= HEAP_freeListSizes
[i
];
497 pEntry
->arena
.size
= 0 | ARENA_FLAG_FREE
;
498 pEntry
->arena
.next
= i
< HEAP_NB_FREE_LISTS
-1 ?
499 &heap
->freeList
[i
+1].arena
: &heap
->freeList
[0].arena
;
500 pEntry
->arena
.prev
= i
? &heap
->freeList
[i
-1].arena
:
501 &heap
->freeList
[HEAP_NB_FREE_LISTS
-1].arena
;
502 pEntry
->arena
.threadId
= 0;
503 pEntry
->arena
.magic
= ARENA_FREE_MAGIC
;
506 /* Initialize critical section */
508 RtlInitializeCriticalSection( &heap
->critSection
);
511 /* Create the first free block */
513 HEAP_CreateFreeBlock( subheap
, (LPBYTE
)subheap
+ subheap
->headerSize
,
514 subheap
->size
- subheap
->headerSize
);
519 /***********************************************************************
522 * Create a sub-heap of the given size.
523 * If heap == NULL, creates a main heap.
525 static SUBHEAP
*HEAP_CreateSubHeap(PVOID BaseAddress
,
533 /* Round-up sizes on a 64K boundary */
535 totalSize
= (totalSize
+ 0xffff) & 0xffff0000;
536 commitSize
= (commitSize
+ 0xffff) & 0xffff0000;
537 if (!commitSize
) commitSize
= 0x10000;
538 if (totalSize
< commitSize
) totalSize
= commitSize
;
540 /* Allocate the memory block */
542 address
= BaseAddress
;
543 ZwAllocateVirtualMemory(NtCurrentProcess(),
548 PAGE_EXECUTE_READWRITE
);
550 /* Initialize subheap */
552 if (!HEAP_InitSubHeap( heap
? heap
: (HEAP
*)address
,
553 address
, flags
, commitSize
, totalSize
))
555 ZwFreeVirtualMemory(NtCurrentProcess(), address
, 0, MEM_RELEASE
);
559 return (SUBHEAP
*)address
;
563 /***********************************************************************
566 * Find a free block at least as large as the requested size, and make sure
567 * the requested size is committed.
569 static ARENA_FREE
*HEAP_FindFreeBlock( HEAP
*heap
, DWORD size
,
570 SUBHEAP
**ppSubHeap
)
574 FREE_LIST_ENTRY
*pEntry
= heap
->freeList
;
576 /* Find a suitable free list, and in it find a block large enough */
578 while (pEntry
->size
< size
) pEntry
++;
579 pArena
= pEntry
->arena
.next
;
580 while (pArena
!= &heap
->freeList
[0].arena
)
582 if (pArena
->size
> size
)
584 subheap
= HEAP_FindSubHeap( heap
, pArena
);
585 if (!HEAP_Commit( subheap
, (char *)pArena
+ sizeof(ARENA_INUSE
)
586 + size
+ HEAP_MIN_BLOCK_SIZE
))
588 *ppSubHeap
= subheap
;
592 pArena
= pArena
->next
;
595 /* If no block was found, attempt to grow the heap */
597 if (!(heap
->flags
& HEAP_GROWABLE
))
599 DPRINT("Not enough space in heap %08lx for %08lx bytes\n",
603 size
+= sizeof(SUBHEAP
) + sizeof(ARENA_FREE
);
604 if (!(subheap
= HEAP_CreateSubHeap( NULL
, heap
, heap
->flags
, size
,
605 max( HEAP_DEF_SIZE
, size
) )))
608 DPRINT("created new sub-heap %08lx of %08lx bytes for heap %08lx\n",
609 (DWORD
)subheap
, size
, (DWORD
)heap
);
611 *ppSubHeap
= subheap
;
612 return (ARENA_FREE
*)(subheap
+ 1);
616 /***********************************************************************
617 * HEAP_IsValidArenaPtr
619 * Check that the pointer is inside the range possible for arenas.
621 static BOOL
HEAP_IsValidArenaPtr( HEAP
*heap
, void *ptr
)
624 SUBHEAP
*subheap
= HEAP_FindSubHeap( heap
, ptr
);
625 if (!subheap
) return FALSE
;
626 if ((char *)ptr
>= (char *)subheap
+ subheap
->headerSize
) return TRUE
;
627 if (subheap
!= &heap
->subheap
) return FALSE
;
628 for (i
= 0; i
< HEAP_NB_FREE_LISTS
; i
++)
629 if (ptr
== (void *)&heap
->freeList
[i
].arena
) return TRUE
;
634 /***********************************************************************
635 * HEAP_ValidateFreeArena
637 static BOOL
HEAP_ValidateFreeArena( SUBHEAP
*subheap
, ARENA_FREE
*pArena
)
639 char *heapEnd
= (char *)subheap
+ subheap
->size
;
641 /* Check magic number */
642 if (pArena
->magic
!= ARENA_FREE_MAGIC
)
644 DPRINT("Heap %08lx: invalid free arena magic for %08lx\n",
645 (DWORD
)subheap
->heap
, (DWORD
)pArena
);
648 /* Check size flags */
649 if (!(pArena
->size
& ARENA_FLAG_FREE
) ||
650 (pArena
->size
& ARENA_FLAG_PREV_FREE
))
652 DPRINT("Heap %08lx: bad flags %lx for free arena %08lx\n",
653 (DWORD
)subheap
->heap
, pArena
->size
& ~ARENA_SIZE_MASK
, (DWORD
)pArena
);
655 /* Check arena size */
656 if ((char *)(pArena
+ 1) + (pArena
->size
& ARENA_SIZE_MASK
) > heapEnd
)
658 DPRINT("Heap %08lx: bad size %08lx for free arena %08lx\n",
659 (DWORD
)subheap
->heap
, (DWORD
)pArena
->size
& ARENA_SIZE_MASK
, (DWORD
)pArena
);
662 /* Check that next pointer is valid */
663 if (!HEAP_IsValidArenaPtr( subheap
->heap
, pArena
->next
))
665 DPRINT("Heap %08lx: bad next ptr %08lx for arena %08lx\n",
666 (DWORD
)subheap
->heap
, (DWORD
)pArena
->next
, (DWORD
)pArena
);
669 /* Check that next arena is free */
670 if (!(pArena
->next
->size
& ARENA_FLAG_FREE
) ||
671 (pArena
->next
->magic
!= ARENA_FREE_MAGIC
))
673 DPRINT("Heap %08lx: next arena %08lx invalid for %08lx\n",
674 (DWORD
)subheap
->heap
, (DWORD
)pArena
->next
, (DWORD
)pArena
);
677 /* Check that prev pointer is valid */
678 if (!HEAP_IsValidArenaPtr( subheap
->heap
, pArena
->prev
))
680 DPRINT("Heap %08lx: bad prev ptr %08lx for arena %08lx\n",
681 (DWORD
)subheap
->heap
, (DWORD
)pArena
->prev
, (DWORD
)pArena
);
684 /* Check that prev arena is free */
685 if (!(pArena
->prev
->size
& ARENA_FLAG_FREE
) ||
686 (pArena
->prev
->magic
!= ARENA_FREE_MAGIC
))
688 DPRINT("Heap %08lx: prev arena %08lx invalid for %08lx\n",
689 (DWORD
)subheap
->heap
, (DWORD
)pArena
->prev
, (DWORD
)pArena
);
692 /* Check that next block has PREV_FREE flag */
693 if ((char *)(pArena
+ 1) + (pArena
->size
& ARENA_SIZE_MASK
) < heapEnd
)
695 if (!(*(DWORD
*)((char *)(pArena
+ 1) +
696 (pArena
->size
& ARENA_SIZE_MASK
)) & ARENA_FLAG_PREV_FREE
))
698 DPRINT("Heap %08lx: free arena %08lx next block has no PREV_FREE flag\n",
699 (DWORD
)subheap
->heap
, (DWORD
)pArena
);
702 /* Check next block back pointer */
703 if (*((ARENA_FREE
**)((char *)(pArena
+ 1) +
704 (pArena
->size
& ARENA_SIZE_MASK
)) - 1) != pArena
)
706 DPRINT("Heap %08lx: arena %08lx has wrong back ptr %08lx\n",
707 (DWORD
)subheap
->heap
, (DWORD
)pArena
,
708 *((DWORD
*)((char *)(pArena
+1)+ (pArena
->size
& ARENA_SIZE_MASK
)) - 1));
716 /***********************************************************************
717 * HEAP_ValidateInUseArena
719 static BOOL
HEAP_ValidateInUseArena( SUBHEAP
*subheap
, ARENA_INUSE
*pArena
)
721 char *heapEnd
= (char *)subheap
+ subheap
->size
;
723 /* Check magic number */
724 if (pArena
->magic
!= ARENA_INUSE_MAGIC
)
726 DPRINT("Heap %08lx: invalid in-use arena magic for %08lx\n",
727 (DWORD
)subheap
->heap
, (DWORD
)pArena
);
730 /* Check size flags */
731 if (pArena
->size
& ARENA_FLAG_FREE
)
733 DPRINT("Heap %08lx: bad flags %lx for in-use arena %08lx\n",
734 (DWORD
)subheap
->heap
, pArena
->size
& ~ARENA_SIZE_MASK
, (DWORD
)pArena
);
736 /* Check arena size */
737 if ((char *)(pArena
+ 1) + (pArena
->size
& ARENA_SIZE_MASK
) > heapEnd
)
739 DPRINT("Heap %08lx: bad size %08lx for in-use arena %08lx\n",
740 (DWORD
)subheap
->heap
, (DWORD
)pArena
->size
& ARENA_SIZE_MASK
, (DWORD
)pArena
);
743 /* Check next arena PREV_FREE flag */
744 if (((char *)(pArena
+ 1) + (pArena
->size
& ARENA_SIZE_MASK
) < heapEnd
) &&
745 (*(DWORD
*)((char *)(pArena
+ 1) + (pArena
->size
& ARENA_SIZE_MASK
)) & ARENA_FLAG_PREV_FREE
))
747 DPRINT("Heap %08lx: in-use arena %08lx next block has PREV_FREE flag\n",
748 (DWORD
)subheap
->heap
, (DWORD
)pArena
);
751 /* Check prev free arena */
752 if (pArena
->size
& ARENA_FLAG_PREV_FREE
)
754 ARENA_FREE
*pPrev
= *((ARENA_FREE
**)pArena
- 1);
755 /* Check prev pointer */
756 if (!HEAP_IsValidArenaPtr( subheap
->heap
, pPrev
))
758 DPRINT("Heap %08lx: bad back ptr %08lx for arena %08lx\n",
759 (DWORD
)subheap
->heap
, (DWORD
)pPrev
, (DWORD
)pArena
);
762 /* Check that prev arena is free */
763 if (!(pPrev
->size
& ARENA_FLAG_FREE
) ||
764 (pPrev
->magic
!= ARENA_FREE_MAGIC
))
766 DPRINT("Heap %08lx: prev arena %08lx invalid for in-use %08lx\n",
767 (DWORD
)subheap
->heap
, (DWORD
)pPrev
, (DWORD
)pArena
);
770 /* Check that prev arena is really the previous block */
771 if ((char *)(pPrev
+ 1) + (pPrev
->size
& ARENA_SIZE_MASK
) != (char *)pArena
)
773 DPRINT("Heap %08lx: prev arena %08lx is not prev for in-use %08lx\n",
774 (DWORD
)subheap
->heap
, (DWORD
)pPrev
, (DWORD
)pArena
);
782 /***********************************************************************
784 * Checks whether the pointer points to a block inside a given heap.
787 * Should this return BOOL32?
793 int HEAP_IsInsideHeap(
794 HANDLE heap
, /* [in] Heap */
795 DWORD flags
, /* [in] Flags */
796 LPCVOID ptr
/* [in] Pointer */
798 HEAP
*heapPtr
= HEAP_GetPtr( heap
);
802 /* Validate the parameters */
804 if (!heapPtr
) return 0;
805 flags
|= heapPtr
->flags
;
806 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlLockHeap( heap
);
807 ret
= (((subheap
= HEAP_FindSubHeap( heapPtr
, ptr
)) != NULL
) &&
808 (((char *)ptr
>= (char *)subheap
+ subheap
->headerSize
809 + sizeof(ARENA_INUSE
))));
810 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlUnlockHeap( heap
);
815 /***********************************************************************
816 * HeapCreate (KERNEL32.336)
818 * Handle of heap: Success
821 HANDLE STDCALL
RtlCreateHeap(ULONG flags
,
826 PRTL_HEAP_DEFINITION Definition
)
830 /* Allocate the heap block */
832 DPRINT("RtlCreateHeap(flags %x, BaseAddress %x, initialSize %x, "
833 "maxSize %x\n)",flags
,BaseAddress
,initialSize
, maxSize
);
837 maxSize
= HEAP_DEF_SIZE
;
838 flags
|= HEAP_GROWABLE
;
840 if (!(subheap
= HEAP_CreateSubHeap(BaseAddress
,
846 // SetLastError( ERROR_OUTOFMEMORY );
847 DPRINT("RtlCreateHeap() = %x\n",0);
851 DPRINT("RtlCreateHeap() = %x\n",subheap
);
853 return (HANDLE
)subheap
;
856 /***********************************************************************
857 * HeapDestroy (KERNEL32.337)
862 BOOL STDCALL
RtlDestroyHeap(
863 HANDLE heap
/* [in] Handle of heap */
865 HEAP
*heapPtr
= HEAP_GetPtr( heap
);
868 DPRINT("%08x\n", heap
);
869 if (!heapPtr
) return FALSE
;
871 RtlDeleteCriticalSection( &heapPtr
->critSection
);
872 subheap
= &heapPtr
->subheap
;
875 SUBHEAP
*next
= subheap
->next
;
876 ZwFreeVirtualMemory(NtCurrentProcess(), (PVOID
*)&subheap
, 0, MEM_RELEASE
);
883 /***********************************************************************
884 * HeapAlloc (KERNEL32.334)
886 * Pointer to allocated memory block
889 PVOID STDCALL
RtlAllocateHeap(
890 HANDLE heap
, /* [in] Handle of private heap block */
891 ULONG flags
, /* [in] Heap allocation control flags */
892 ULONG size
/* [in] Number of bytes to allocate */
897 HEAP
*heapPtr
= HEAP_GetPtr( heap
);
899 /* Validate the parameters */
901 if (!heapPtr
) return NULL
;
902 flags
&= HEAP_GENERATE_EXCEPTIONS
| HEAP_NO_SERIALIZE
| HEAP_ZERO_MEMORY
;
903 flags
|= heapPtr
->flags
;
904 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlLockHeap( heap
);
905 size
= (size
+ 3) & ~3;
906 if (size
< HEAP_MIN_BLOCK_SIZE
) size
= HEAP_MIN_BLOCK_SIZE
;
908 /* Locate a suitable free block */
910 if (!(pArena
= HEAP_FindFreeBlock( heapPtr
, size
, &subheap
)))
912 DPRINT("(%08x,%08lx,%08lx): returning NULL\n",
914 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlUnlockHeap( heap
);
915 // SetLastError( ERROR_COMMITMENT_LIMIT );
919 /* Remove the arena from the free list */
921 pArena
->next
->prev
= pArena
->prev
;
922 pArena
->prev
->next
= pArena
->next
;
924 /* Build the in-use arena */
926 pInUse
= (ARENA_INUSE
*)pArena
;
927 pInUse
->size
= (pInUse
->size
& ~ARENA_FLAG_FREE
)
928 + sizeof(ARENA_FREE
) - sizeof(ARENA_INUSE
);
929 pInUse
->callerEIP
= *((DWORD
*)&heap
- 1); /* hack hack */
930 // pInUse->threadId = GetCurrentTask();
931 pInUse
->magic
= ARENA_INUSE_MAGIC
;
933 /* Shrink the block */
935 HEAP_ShrinkBlock( subheap
, pInUse
, size
);
937 if (flags
& HEAP_ZERO_MEMORY
) memset( pInUse
+ 1, 0, size
);
938 else if (1) memset( pInUse
+ 1, ARENA_INUSE_FILLER
, size
); //DEBUGGING
940 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlUnlockHeap( heap
);
942 DPRINT("(%08x,%08lx,%08lx): returning %08lx\n",
943 heap
, flags
, size
, (DWORD
)(pInUse
+ 1) );
944 return (LPVOID
)(pInUse
+ 1);
948 /***********************************************************************
949 * HeapFree (KERNEL32.338)
954 BOOLEAN STDCALL
RtlFreeHeap(
955 HANDLE heap
, /* [in] Handle of heap */
956 ULONG flags
, /* [in] Heap freeing flags */
957 PVOID ptr
/* [in] Address of memory to free */
961 HEAP
*heapPtr
= HEAP_GetPtr( heap
);
963 /* Validate the parameters */
965 if (!heapPtr
) return FALSE
;
966 flags
&= HEAP_NO_SERIALIZE
;
967 flags
|= heapPtr
->flags
;
968 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlLockHeap( heap
);
971 DPRINT("(%08x,%08lx,%08lx): asked to free NULL\n",
972 heap
, flags
, (DWORD
)ptr
);
974 if (!ptr
|| !RtlValidateHeap( heap
, HEAP_NO_SERIALIZE
, ptr
))
976 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlUnlockHeap( heap
);
977 // SetLastError( ERROR_INVALID_PARAMETER );
978 DPRINT("(%08x,%08lx,%08lx): returning FALSE\n",
979 heap
, flags
, (DWORD
)ptr
);
983 /* Turn the block into a free block */
985 pInUse
= (ARENA_INUSE
*)ptr
- 1;
986 subheap
= HEAP_FindSubHeap( heapPtr
, pInUse
);
987 HEAP_MakeInUseBlockFree( subheap
, pInUse
);
989 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlUnlockHeap( heap
);
990 /* SetLastError( 0 ); */
992 DPRINT("(%08x,%08lx,%08lx): returning TRUE\n",
993 heap
, flags
, (DWORD
)ptr
);
998 /***********************************************************************
999 * HeapReAlloc (KERNEL32.340)
1001 * Pointer to reallocated memory block
1005 * Renamed RtlReAllocateHeap as in NT
1010 HANDLE heap
, /* [in] Handle of heap block */
1011 DWORD flags
, /* [in] Heap reallocation flags */
1012 LPVOID ptr
, /* [in] Address of memory to reallocate */
1013 DWORD size
/* [in] Number of bytes to reallocate */
1016 ARENA_INUSE
*pArena
;
1021 if (!ptr
) return RtlAllocateHeap( heap
, flags
, size
); /* FIXME: correct? */
1022 if (!(heapPtr
= HEAP_GetPtr( heap
))) return FALSE
;
1024 /* Validate the parameters */
1026 flags
&= HEAP_GENERATE_EXCEPTIONS
| HEAP_NO_SERIALIZE
| HEAP_ZERO_MEMORY
|
1027 HEAP_REALLOC_IN_PLACE_ONLY
;
1028 flags
|= heapPtr
->flags
;
1029 size
= (size
+ 3) & ~3;
1030 if (size
< HEAP_MIN_BLOCK_SIZE
) size
= HEAP_MIN_BLOCK_SIZE
;
1032 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlLockHeap( heap
);
1033 if (!RtlValidateHeap( heap
, HEAP_NO_SERIALIZE
, ptr
))
1035 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlUnlockHeap( heap
);
1036 // SetLastError( ERROR_INVALID_PARAMETER );
1037 DPRINT("(%08x,%08lx,%08lx,%08lx): returning NULL\n",
1038 heap
, flags
, (DWORD
)ptr
, size
);
1042 /* Check if we need to grow the block */
1044 pArena
= (ARENA_INUSE
*)ptr
- 1;
1045 // pArena->threadId = GetCurrentTask();
1046 subheap
= HEAP_FindSubHeap( heapPtr
, pArena
);
1047 oldSize
= (pArena
->size
& ARENA_SIZE_MASK
);
1050 char *pNext
= (char *)(pArena
+ 1) + oldSize
;
1051 if ((pNext
< (char *)subheap
+ subheap
->size
) &&
1052 (*(DWORD
*)pNext
& ARENA_FLAG_FREE
) &&
1053 (oldSize
+ (*(DWORD
*)pNext
& ARENA_SIZE_MASK
) + sizeof(ARENA_FREE
) >= size
))
1055 /* The next block is free and large enough */
1056 ARENA_FREE
*pFree
= (ARENA_FREE
*)pNext
;
1057 pFree
->next
->prev
= pFree
->prev
;
1058 pFree
->prev
->next
= pFree
->next
;
1059 pArena
->size
+= (pFree
->size
& ARENA_SIZE_MASK
) + sizeof(*pFree
);
1060 if (!HEAP_Commit( subheap
, (char *)pArena
+ sizeof(ARENA_INUSE
)
1061 + size
+ HEAP_MIN_BLOCK_SIZE
))
1063 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlUnlockHeap( heap
);
1064 // SetLastError( ERROR_OUTOFMEMORY );
1067 HEAP_ShrinkBlock( subheap
, pArena
, size
);
1069 else /* Do it the hard way */
1072 ARENA_INUSE
*pInUse
;
1073 SUBHEAP
*newsubheap
;
1075 if ((flags
& HEAP_REALLOC_IN_PLACE_ONLY
) ||
1076 !(pNew
= HEAP_FindFreeBlock( heapPtr
, size
, &newsubheap
)))
1078 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlUnlockHeap( heap
);
1079 // SetLastError( ERROR_OUTOFMEMORY );
1083 /* Build the in-use arena */
1085 pNew
->next
->prev
= pNew
->prev
;
1086 pNew
->prev
->next
= pNew
->next
;
1087 pInUse
= (ARENA_INUSE
*)pNew
;
1088 pInUse
->size
= (pInUse
->size
& ~ARENA_FLAG_FREE
)
1089 + sizeof(ARENA_FREE
) - sizeof(ARENA_INUSE
);
1090 // pInUse->threadId = GetCurrentTask();
1091 pInUse
->magic
= ARENA_INUSE_MAGIC
;
1092 HEAP_ShrinkBlock( newsubheap
, pInUse
, size
);
1093 memcpy( pInUse
+ 1, pArena
+ 1, oldSize
);
1095 /* Free the previous block */
1097 HEAP_MakeInUseBlockFree( subheap
, pArena
);
1098 subheap
= newsubheap
;
1102 else HEAP_ShrinkBlock( subheap
, pArena
, size
); /* Shrink the block */
1104 /* Clear the extra bytes if needed */
1108 if (flags
& HEAP_ZERO_MEMORY
)
1109 memset( (char *)(pArena
+ 1) + oldSize
, 0,
1110 (pArena
->size
& ARENA_SIZE_MASK
) - oldSize
);
1111 else if (1) // DEBUGGING
1112 memset( (char *)(pArena
+ 1) + oldSize
, ARENA_INUSE_FILLER
,
1113 (pArena
->size
& ARENA_SIZE_MASK
) - oldSize
);
1116 /* Return the new arena */
1118 pArena
->callerEIP
= *((DWORD
*)&heap
- 1); /* hack hack */
1119 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlUnlockHeap( heap
);
1121 DPRINT("(%08x,%08lx,%08lx,%08lx): returning %08lx\n",
1122 heap
, flags
, (DWORD
)ptr
, size
, (DWORD
)(pArena
+ 1) );
1123 return (LPVOID
)(pArena
+ 1);
1127 /***********************************************************************
1128 * HeapCompact (KERNEL32.335)
1130 DWORD STDCALL
RtlCompactHeap( HANDLE heap
, DWORD flags
)
1136 /***********************************************************************
1137 * HeapLock (KERNEL32.339)
1138 * Attempts to acquire the critical section object for a specified heap.
1144 BOOL STDCALL
RtlLockHeap(
1145 HANDLE heap
/* [in] Handle of heap to lock for exclusive access */
1147 HEAP
*heapPtr
= HEAP_GetPtr( heap
);
1148 if (!heapPtr
) return FALSE
;
1149 RtlEnterCriticalSection( &heapPtr
->critSection
);
1154 /***********************************************************************
1155 * HeapUnlock (KERNEL32.342)
1156 * Releases ownership of the critical section object.
1162 BOOL STDCALL
RtlUnlockHeap(
1163 HANDLE heap
/* [in] Handle to the heap to unlock */
1165 HEAP
*heapPtr
= HEAP_GetPtr( heap
);
1166 if (!heapPtr
) return FALSE
;
1167 RtlLeaveCriticalSection( &heapPtr
->critSection
);
1172 /***********************************************************************
1173 * HeapSize (KERNEL32.341)
1175 * Size in bytes of allocated memory
1178 DWORD STDCALL
RtlSizeHeap(
1179 HANDLE heap
, /* [in] Handle of heap */
1180 DWORD flags
, /* [in] Heap size control flags */
1181 LPVOID ptr
/* [in] Address of memory to return size for */
1184 HEAP
*heapPtr
= HEAP_GetPtr( heap
);
1186 if (!heapPtr
) return FALSE
;
1187 flags
&= HEAP_NO_SERIALIZE
;
1188 flags
|= heapPtr
->flags
;
1189 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlLockHeap( heap
);
1190 if (!RtlValidateHeap( heap
, HEAP_NO_SERIALIZE
, ptr
))
1192 // SetLastError( ERROR_INVALID_PARAMETER );
1197 ARENA_INUSE
*pArena
= (ARENA_INUSE
*)ptr
- 1;
1198 ret
= pArena
->size
& ARENA_SIZE_MASK
;
1200 if (!(flags
& HEAP_NO_SERIALIZE
)) RtlUnlockHeap( heap
);
1202 DPRINT("(%08x,%08lx,%08lx): returning %08lx\n",
1203 heap
, flags
, (DWORD
)ptr
, ret
);
1208 /***********************************************************************
1209 * HeapValidate (KERNEL32.343)
1210 * Validates a specified heap.
1219 BOOL STDCALL
RtlValidateHeap(
1220 HANDLE heap
, /* [in] Handle to the heap */
1221 DWORD flags
, /* [in] Bit flags that control access during operation */
1222 PVOID block
/* [in] Optional pointer to memory block to validate */
1225 HEAP
*heapPtr
= (HEAP
*)(heap
);
1227 if (!heapPtr
|| (heapPtr
->magic
!= HEAP_MAGIC
))
1229 DPRINT("Invalid heap %08x!\n", heap
);
1235 /* Only check this single memory block */
1236 if (!(subheap
= HEAP_FindSubHeap( heapPtr
, block
)) ||
1237 ((char *)block
< (char *)subheap
+ subheap
->headerSize
1238 + sizeof(ARENA_INUSE
)))
1240 DPRINT("Heap %08lx: block %08lx is not inside heap\n",
1241 (DWORD
)heap
, (DWORD
)block
);
1244 return HEAP_ValidateInUseArena( subheap
, (ARENA_INUSE
*)block
- 1 );
1247 subheap
= &heapPtr
->subheap
;
1250 char *ptr
= (char *)subheap
+ subheap
->headerSize
;
1251 while (ptr
< (char *)subheap
+ subheap
->size
)
1253 if (*(DWORD
*)ptr
& ARENA_FLAG_FREE
)
1255 if (!HEAP_ValidateFreeArena( subheap
, (ARENA_FREE
*)ptr
))
1257 ptr
+= sizeof(ARENA_FREE
) + (*(DWORD
*)ptr
& ARENA_SIZE_MASK
);
1261 if (!HEAP_ValidateInUseArena( subheap
, (ARENA_INUSE
*)ptr
))
1263 ptr
+= sizeof(ARENA_INUSE
) + (*(DWORD
*)ptr
& ARENA_SIZE_MASK
);
1266 subheap
= subheap
->next
;
1271 HANDLE STDCALL
RtlGetProcessHeap(VOID
)
1273 DPRINT("RtlGetProcessHeap()\n");
1274 return (HANDLE
)NtCurrentPeb()->ProcessHeap
;
1278 RtlpInitProcessHeaps (PPEB Peb
)
1280 Peb
->NumberOfHeaps
= 0;
1281 Peb
->MaximumNumberOfHeaps
= (PAGESIZE
- sizeof(PPEB
)) / sizeof(HANDLE
);
1282 Peb
->ProcessHeaps
= (PVOID
)Peb
+ sizeof(PEB
);
1284 RtlInitializeCriticalSection (&ProcessHeapsLock
);
1290 RtlEnumProcessHeaps (
1291 DWORD
STDCALL(*func
)(void*,LONG
),
1295 NTSTATUS Status
= STATUS_SUCCESS
;
1298 RtlEnterCriticalSection (&ProcessHeapsLock
);
1300 for (i
= 0; i
< NtCurrentPeb ()->NumberOfHeaps
; i
++)
1302 Status
= func (NtCurrentPeb ()->ProcessHeaps
[i
],lParam
);
1303 if(!NT_SUCCESS(Status
))
1307 RtlLeaveCriticalSection (&ProcessHeapsLock
);
1315 RtlGetProcessHeaps (
1322 RtlEnterCriticalSection (&ProcessHeapsLock
);
1324 if (NtCurrentPeb ()->NumberOfHeaps
<= HeapCount
)
1326 Result
= NtCurrentPeb ()->NumberOfHeaps
;
1328 NtCurrentPeb ()->ProcessHeaps
,
1329 Result
* sizeof(HANDLE
));
1332 RtlLeaveCriticalSection (&ProcessHeapsLock
);
1340 RtlValidateProcessHeaps (
1345 BOOLEAN Result
= TRUE
;
1349 HeapCount
= RtlGetProcessHeaps (128, Heaps
);
1350 for (i
= 0; i
< HeapCount
; i
++)
1352 if (!RtlValidateHeap (Heaps
[i
], 0, NULL
))