2 * PROJECT: ReactOS Kernel
3 * LICENSE: GPL - See COPYING in the top level directory
4 * FILE: ntoskrnl/io/iomgr/driver.c
5 * PURPOSE: Driver Object Management
6 * PROGRAMMERS: Alex Ionescu (alex.ionescu@reactos.org)
7 * Filip Navara (navaraf@reactos.org)
8 * Hervé Poussineau (hpoussin@reactos.org)
11 /* INCLUDES *******************************************************************/
15 #include <internal/debug.h>
17 /* GLOBALS ********************************************************************/
19 LIST_ENTRY DriverReinitListHead
;
20 KSPIN_LOCK DriverReinitListLock
;
21 PLIST_ENTRY DriverReinitTailEntry
;
23 PLIST_ENTRY DriverBootReinitTailEntry
;
24 LIST_ENTRY DriverBootReinitListHead
;
25 KSPIN_LOCK DriverBootReinitListLock
;
27 UNICODE_STRING IopHardwareDatabaseKey
=
28 RTL_CONSTANT_STRING(L
"\\REGISTRY\\MACHINE\\HARDWARE\\DESCRIPTION\\SYSTEM");
30 POBJECT_TYPE IoDriverObjectType
= NULL
;
32 extern BOOLEAN ExpInTextModeSetup
;
34 /* PRIVATE FUNCTIONS **********************************************************/
37 IopInvalidDeviceRequest(
38 PDEVICE_OBJECT DeviceObject
,
41 Irp
->IoStatus
.Status
= STATUS_INVALID_DEVICE_REQUEST
;
42 Irp
->IoStatus
.Information
= 0;
43 IoCompleteRequest(Irp
, IO_NO_INCREMENT
);
44 return STATUS_INVALID_DEVICE_REQUEST
;
49 IopDeleteDriver(IN PVOID ObjectBody
)
51 PDRIVER_OBJECT DriverObject
= ObjectBody
;
52 PIO_CLIENT_EXTENSION DriverExtension
, NextDriverExtension
;
55 /* Get the extension and loop them */
56 DriverExtension
= IoGetDrvObjExtension(DriverObject
)->
57 ClientDriverExtension
;
58 while (DriverExtension
)
60 /* Get the next one */
61 NextDriverExtension
= DriverExtension
->NextExtension
;
62 ExFreePoolWithTag(DriverExtension
, TAG_DRIVER_EXTENSION
);
65 DriverExtension
= NextDriverExtension
;
68 /* Check if the driver image is still loaded */
69 if (DriverObject
->DriverSection
)
72 //LdrpUnloadImage(DriverObject->DriverSection);
75 /* Check if it has a name */
76 if (DriverObject
->DriverName
.Buffer
)
79 ExFreePool(DriverObject
->DriverName
.Buffer
);
82 #if 0 /* See a bit of hack in IopCreateDriver */
83 /* Check if it has a service key name */
84 if (DriverObject
->DriverExtension
->ServiceKeyName
.Buffer
)
87 ExFreePool(DriverObject
->DriverExtension
->ServiceKeyName
.Buffer
);
94 PDRIVER_OBJECT
*DriverObject
,
95 PUNICODE_STRING ServiceName
,
98 PDRIVER_OBJECT Object
;
99 WCHAR NameBuffer
[MAX_PATH
];
100 UNICODE_STRING DriverName
;
103 DPRINT("IopGetDriverObject(%p '%wZ' %x)\n",
104 DriverObject
, ServiceName
, FileSystem
);
106 *DriverObject
= NULL
;
108 /* Create ModuleName string */
109 if (ServiceName
== NULL
|| ServiceName
->Buffer
== NULL
)
110 /* We don't know which DriverObject we have to open */
111 return STATUS_INVALID_PARAMETER_2
;
113 DriverName
.Buffer
= NameBuffer
;
114 DriverName
.Length
= 0;
115 DriverName
.MaximumLength
= sizeof(NameBuffer
);
117 if (FileSystem
== TRUE
)
118 RtlAppendUnicodeToString(&DriverName
, FILESYSTEM_ROOT_NAME
);
120 RtlAppendUnicodeToString(&DriverName
, DRIVER_ROOT_NAME
);
121 RtlAppendUnicodeStringToString(&DriverName
, ServiceName
);
123 DPRINT("Driver name: '%wZ'\n", &DriverName
);
125 /* Open driver object */
126 Status
= ObReferenceObjectByName(
128 OBJ_OPENIF
| OBJ_KERNEL_HANDLE
| OBJ_CASE_INSENSITIVE
, /* Attributes */
129 NULL
, /* PassedAccessState */
130 0, /* DesiredAccess */
133 NULL
, /* ParseContext */
136 if (!NT_SUCCESS(Status
))
138 DPRINT("Failed to reference driver object, status=0x%08x\n", Status
);
142 *DriverObject
= Object
;
144 DPRINT("Driver Object: %p\n", Object
);
146 return STATUS_SUCCESS
;
150 * IopDisplayLoadingMessage
152 * Display 'Loading XXX...' message.
158 IopDisplayLoadingMessage(PVOID ServiceName
,
161 CHAR TextBuffer
[256];
162 PCHAR Extra
= ".sys";
164 if (ExpInTextModeSetup
) return;
167 if (wcsstr(_wcsupr(ServiceName
), L
".SYS")) Extra
= "";
170 KeLoaderBlock
->ArcBootDeviceName
,
171 KeLoaderBlock
->NtBootPathName
,
178 if (strstr(_strupr(ServiceName
), ".SYS")) Extra
= "";
181 KeLoaderBlock
->ArcBootDeviceName
,
182 KeLoaderBlock
->NtBootPathName
,
187 HalDisplayString(TextBuffer
);
191 * IopNormalizeImagePath
193 * Normalize an image path to contain complete path.
197 * The input path and on exit the result path. ImagePath.Buffer
198 * must be allocated by ExAllocatePool on input. Caller is responsible
199 * for freeing the buffer when it's no longer needed.
202 * Name of the service that ImagePath belongs to.
208 * The input image path isn't freed on error.
212 IopNormalizeImagePath(
213 IN OUT PUNICODE_STRING ImagePath
,
214 IN PUNICODE_STRING ServiceName
)
216 UNICODE_STRING InputImagePath
;
221 sizeof(UNICODE_STRING
));
223 if (InputImagePath
.Length
== 0)
225 ImagePath
->Length
= 0;
226 ImagePath
->MaximumLength
=
227 (33 * sizeof(WCHAR
)) + ServiceName
->Length
+ sizeof(UNICODE_NULL
);
228 ImagePath
->Buffer
= ExAllocatePool(NonPagedPool
, ImagePath
->MaximumLength
);
229 if (ImagePath
->Buffer
== NULL
)
230 return STATUS_NO_MEMORY
;
232 RtlAppendUnicodeToString(ImagePath
, L
"\\SystemRoot\\system32\\drivers\\");
233 RtlAppendUnicodeStringToString(ImagePath
, ServiceName
);
234 RtlAppendUnicodeToString(ImagePath
, L
".sys");
236 if (InputImagePath
.Buffer
[0] != L
'\\')
238 ImagePath
->Length
= 0;
239 ImagePath
->MaximumLength
=
240 12 * sizeof(WCHAR
) + InputImagePath
.Length
+ sizeof(UNICODE_NULL
);
241 ImagePath
->Buffer
= ExAllocatePool(NonPagedPool
, ImagePath
->MaximumLength
);
242 if (ImagePath
->Buffer
== NULL
)
243 return STATUS_NO_MEMORY
;
245 RtlAppendUnicodeToString(ImagePath
, L
"\\SystemRoot\\");
246 RtlAppendUnicodeStringToString(ImagePath
, &InputImagePath
);
248 /* Free caller's string */
249 RtlFreeUnicodeString(&InputImagePath
);
252 return STATUS_SUCCESS
;
256 * IopLoadServiceModule
258 * Load a module specified by registry settings for service.
262 * Name of the service to load.
269 IopLoadServiceModule(
270 IN PUNICODE_STRING ServiceName
,
271 OUT PLDR_DATA_TABLE_ENTRY
*ModuleObject
)
273 RTL_QUERY_REGISTRY_TABLE QueryTable
[3];
275 UNICODE_STRING ServiceImagePath
, CCSName
;
277 HANDLE CCSKey
, ServiceKey
;
279 DPRINT("IopLoadServiceModule(%wZ, 0x%p)\n", ServiceName
, ModuleObject
);
281 /* FIXME: This check may be removed once the bug is fixed */
282 if (ServiceName
->Buffer
== NULL
)
283 return STATUS_UNSUCCESSFUL
;
285 /* Open CurrentControlSet */
286 RtlInitUnicodeString(&CCSName
,
287 L
"\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Services");
288 Status
= IopOpenRegistryKeyEx(&CCSKey
, NULL
, &CCSName
, KEY_READ
);
289 if (!NT_SUCCESS(Status
))
291 DPRINT1("ZwOpenKey() failed with Status %08X\n", Status
);
295 /* Open service key */
296 Status
= IopOpenRegistryKeyEx(&ServiceKey
, CCSKey
, ServiceName
, KEY_READ
);
297 if (!NT_SUCCESS(Status
))
299 DPRINT1("ZwOpenKey() failed with Status %08X\n", Status
);
305 * Get information about the service.
308 RtlZeroMemory(QueryTable
, sizeof(QueryTable
));
310 RtlInitUnicodeString(&ServiceImagePath
, NULL
);
312 QueryTable
[0].Name
= L
"Start";
313 QueryTable
[0].Flags
= RTL_QUERY_REGISTRY_DIRECT
;
314 QueryTable
[0].EntryContext
= &ServiceStart
;
316 QueryTable
[1].Name
= L
"ImagePath";
317 QueryTable
[1].Flags
= RTL_QUERY_REGISTRY_DIRECT
;
318 QueryTable
[1].EntryContext
= &ServiceImagePath
;
320 Status
= RtlQueryRegistryValues(RTL_REGISTRY_HANDLE
,
321 (PWSTR
)ServiceKey
, QueryTable
, NULL
, NULL
);
326 if (!NT_SUCCESS(Status
))
328 DPRINT1("RtlQueryRegistryValues() failed (Status %x)\n", Status
);
333 * Normalize the image path for all later processing.
336 Status
= IopNormalizeImagePath(&ServiceImagePath
, ServiceName
);
338 if (!NT_SUCCESS(Status
))
340 DPRINT("IopNormalizeImagePath() failed (Status %x)\n", Status
);
345 * Case for disabled drivers
348 if (ServiceStart
>= 4)
350 /* FIXME: Check if it is the right status code */
351 Status
= STATUS_PLUGPLAY_NO_DEVICE
;
355 DPRINT("Loading module\n");
356 Status
= MmLoadSystemImage(&ServiceImagePath
, NULL
, NULL
, 0, (PVOID
)ModuleObject
, NULL
);
359 ExFreePool(ServiceImagePath
.Buffer
);
362 * Now check if the module was loaded successfully.
365 if (!NT_SUCCESS(Status
))
367 DPRINT("Module loading failed (Status %x)\n", Status
);
370 DPRINT("Module loading (Status %x)\n", Status
);
376 * IopInitializeDriverModule
378 * Initalize a loaded driver.
382 * Pointer to device node.
385 * Module object representing the driver. It can be retrieve by
386 * IopLoadServiceModule.
389 * Name of the service (as in registry).
392 * Set to TRUE for file system drivers.
395 * On successful return this contains the driver object representing
400 IopInitializeDriverModule(
401 IN PDEVICE_NODE DeviceNode
,
402 IN PLDR_DATA_TABLE_ENTRY ModuleObject
,
403 IN PUNICODE_STRING ServiceName
,
404 IN BOOLEAN FileSystemDriver
,
405 OUT PDRIVER_OBJECT
*DriverObject
)
407 const WCHAR ServicesKeyName
[] = L
"\\Registry\\Machine\\System\\CurrentControlSet\\Services\\";
408 WCHAR NameBuffer
[MAX_PATH
];
409 UNICODE_STRING DriverName
;
410 UNICODE_STRING RegistryKey
;
411 PDRIVER_INITIALIZE DriverEntry
;
412 PDRIVER_OBJECT Driver
;
413 PDEVICE_OBJECT DeviceObject
;
416 DriverEntry
= ModuleObject
->EntryPoint
;
418 if (ServiceName
!= NULL
&& ServiceName
->Length
!= 0)
420 RegistryKey
.Length
= 0;
421 RegistryKey
.MaximumLength
= sizeof(ServicesKeyName
) + ServiceName
->Length
;
422 RegistryKey
.Buffer
= ExAllocatePool(PagedPool
, RegistryKey
.MaximumLength
);
423 if (RegistryKey
.Buffer
== NULL
)
425 return STATUS_INSUFFICIENT_RESOURCES
;
427 RtlAppendUnicodeToString(&RegistryKey
, ServicesKeyName
);
428 RtlAppendUnicodeStringToString(&RegistryKey
, ServiceName
);
432 RtlInitUnicodeString(&RegistryKey
, NULL
);
435 /* Create ModuleName string */
436 if (ServiceName
&& ServiceName
->Length
> 0)
438 if (FileSystemDriver
== TRUE
)
439 wcscpy(NameBuffer
, FILESYSTEM_ROOT_NAME
);
441 wcscpy(NameBuffer
, DRIVER_ROOT_NAME
);
443 RtlInitUnicodeString(&DriverName
, NameBuffer
);
444 DriverName
.MaximumLength
= sizeof(NameBuffer
);
446 RtlAppendUnicodeStringToString(&DriverName
, ServiceName
);
448 DPRINT("Driver name: '%wZ'\n", &DriverName
);
451 DriverName
.Length
= 0;
453 Status
= IopCreateDriver(
454 DriverName
.Length
> 0 ? &DriverName
: NULL
,
457 ModuleObject
->DllBase
,
458 ModuleObject
->SizeOfImage
,
460 RtlFreeUnicodeString(&RegistryKey
);
462 *DriverObject
= Driver
;
463 if (!NT_SUCCESS(Status
))
465 DPRINT("IopCreateDriver() failed (Status 0x%08lx)\n", Status
);
469 /* Set the driver as initialized */
470 Driver
->Flags
|= DRVO_INITIALIZED
;
471 DeviceObject
= Driver
->DeviceObject
;
474 /* Set every device as initialized too */
475 DeviceObject
->Flags
&= ~DO_DEVICE_INITIALIZING
;
476 DeviceObject
= DeviceObject
->NextDevice
;
479 IopReinitializeDrivers();
481 return STATUS_SUCCESS
;
485 * IopAttachFilterDriversCallback
487 * Internal routine used by IopAttachFilterDrivers.
491 IopAttachFilterDriversCallback(
499 PDEVICE_NODE DeviceNode
= Context
;
500 UNICODE_STRING ServiceName
;
502 PLDR_DATA_TABLE_ENTRY ModuleObject
;
503 PDRIVER_OBJECT DriverObject
;
506 for (Filters
= ValueData
;
507 ((ULONG_PTR
)Filters
- (ULONG_PTR
)ValueData
) < ValueLength
&&
509 Filters
+= (ServiceName
.Length
/ sizeof(WCHAR
)) + 1)
511 DPRINT("Filter Driver: %S (%wZ)\n", Filters
, &DeviceNode
->InstancePath
);
512 ServiceName
.Buffer
= Filters
;
513 ServiceName
.MaximumLength
=
514 ServiceName
.Length
= wcslen(Filters
) * sizeof(WCHAR
);
516 /* Load and initialize the filter driver */
517 Status
= IopLoadServiceModule(&ServiceName
, &ModuleObject
);
518 if (Status
!= STATUS_IMAGE_ALREADY_LOADED
)
520 if (!NT_SUCCESS(Status
))
523 Status
= IopInitializeDriverModule(DeviceNode
, ModuleObject
, &ServiceName
,
524 FALSE
, &DriverObject
);
525 if (!NT_SUCCESS(Status
))
530 /* get existing DriverObject pointer */
531 Status
= IopGetDriverObject(
535 if (!NT_SUCCESS(Status
))
537 DPRINT1("IopGetDriverObject() returned status 0x%08x!\n", Status
);
542 Status
= IopInitializeDevice(DeviceNode
, DriverObject
);
543 if (!NT_SUCCESS(Status
))
547 return STATUS_SUCCESS
;
551 * IopAttachFilterDrivers
553 * Load filter drivers for specified device node.
557 * Set to TRUE for loading lower level filters or FALSE for upper
562 IopAttachFilterDrivers(
563 PDEVICE_NODE DeviceNode
,
566 RTL_QUERY_REGISTRY_TABLE QueryTable
[2] = {{0}};
567 UNICODE_STRING Class
;
568 WCHAR ClassBuffer
[40];
569 UNICODE_STRING EnumRoot
= RTL_CONSTANT_STRING(ENUM_ROOT
);
570 HANDLE EnumRootKey
, SubKey
;
573 /* Open enumeration root key */
574 Status
= IopOpenRegistryKeyEx(&EnumRootKey
, NULL
,
575 &EnumRoot
, KEY_READ
);
576 if (!NT_SUCCESS(Status
))
578 DPRINT1("ZwOpenKey() failed with Status %08X\n", Status
);
583 Status
= IopOpenRegistryKeyEx(&SubKey
, EnumRootKey
,
584 &DeviceNode
->InstancePath
, KEY_READ
);
585 if (!NT_SUCCESS(Status
))
587 DPRINT1("ZwOpenKey() failed with Status %08X\n", Status
);
588 ZwClose(EnumRootKey
);
593 * First load the device filters
595 QueryTable
[0].QueryRoutine
= IopAttachFilterDriversCallback
;
597 QueryTable
[0].Name
= L
"LowerFilters";
599 QueryTable
[0].Name
= L
"UpperFilters";
600 QueryTable
[0].Flags
= RTL_QUERY_REGISTRY_REQUIRED
;
602 RtlQueryRegistryValues(
610 * Now get the class GUID
613 Class
.MaximumLength
= 40 * sizeof(WCHAR
);
614 Class
.Buffer
= ClassBuffer
;
615 QueryTable
[0].QueryRoutine
= NULL
;
616 QueryTable
[0].Name
= L
"ClassGUID";
617 QueryTable
[0].EntryContext
= &Class
;
618 QueryTable
[0].Flags
= RTL_QUERY_REGISTRY_REQUIRED
| RTL_QUERY_REGISTRY_DIRECT
;
620 Status
= RtlQueryRegistryValues(
629 ZwClose(EnumRootKey
);
632 * Load the class filter driver
634 if (NT_SUCCESS(Status
))
636 UNICODE_STRING ControlClass
= RTL_CONSTANT_STRING(L
"\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Class");
638 Status
= IopOpenRegistryKeyEx(&EnumRootKey
, NULL
,
639 &ControlClass
, KEY_READ
);
640 if (!NT_SUCCESS(Status
))
642 DPRINT1("ZwOpenKey() failed with Status %08X\n", Status
);
647 Status
= IopOpenRegistryKeyEx(&SubKey
, EnumRootKey
,
649 if (!NT_SUCCESS(Status
))
651 DPRINT1("ZwOpenKey() failed with Status %08X\n", Status
);
652 ZwClose(EnumRootKey
);
656 QueryTable
[0].QueryRoutine
= IopAttachFilterDriversCallback
;
658 QueryTable
[0].Name
= L
"LowerFilters";
660 QueryTable
[0].Name
= L
"UpperFilters";
661 QueryTable
[0].EntryContext
= NULL
;
662 QueryTable
[0].Flags
= RTL_QUERY_REGISTRY_REQUIRED
;
664 RtlQueryRegistryValues(
673 ZwClose(EnumRootKey
);
676 return STATUS_SUCCESS
;
681 MiResolveImageReferences(IN PVOID ImageBase
,
682 IN PUNICODE_STRING ImageFileDirectory
,
683 IN PUNICODE_STRING NamePrefix OPTIONAL
,
684 OUT PCHAR
*MissingApi
,
685 OUT PWCHAR
*MissingDriver
,
686 OUT PLOAD_IMPORTS
*LoadImports
);
688 extern KSPIN_LOCK PsLoadedModuleSpinLock
;
691 // Used for images already loaded (boot drivers)
695 LdrProcessDriverModule(PLDR_DATA_TABLE_ENTRY LdrEntry
,
696 PUNICODE_STRING FileName
,
697 PLDR_DATA_TABLE_ENTRY
*ModuleObject
)
700 PLDR_DATA_TABLE_ENTRY NewEntry
;
701 UNICODE_STRING BaseName
, BaseDirectory
;
702 PLOAD_IMPORTS LoadedImports
= (PVOID
)-2;
703 PCHAR MissingApiName
, Buffer
;
704 PWCHAR MissingDriverName
;
705 PVOID DriverBase
= LdrEntry
->DllBase
;
707 /* Allocate a buffer we'll use for names */
708 Buffer
= ExAllocatePoolWithTag(NonPagedPool
, MAX_PATH
, TAG_LDR_WSTR
);
712 return STATUS_INSUFFICIENT_RESOURCES
;
715 /* Check for a separator */
716 if (FileName
->Buffer
[0] == OBJ_NAME_PATH_SEPARATOR
)
721 /* Loop the path until we get to the base name */
722 p
= &FileName
->Buffer
[FileName
->Length
/ sizeof(WCHAR
)];
723 while (*(p
- 1) != OBJ_NAME_PATH_SEPARATOR
) p
--;
726 BaseLength
= (ULONG
)(&FileName
->Buffer
[FileName
->Length
/ sizeof(WCHAR
)] - p
);
727 BaseLength
*= sizeof(WCHAR
);
729 /* Setup the string */
730 BaseName
.Length
= (USHORT
)BaseLength
;
735 /* Otherwise, we already have a base name */
736 BaseName
.Length
= FileName
->Length
;
737 BaseName
.Buffer
= FileName
->Buffer
;
740 /* Setup the maximum length */
741 BaseName
.MaximumLength
= BaseName
.Length
;
743 /* Now compute the base directory */
744 BaseDirectory
= *FileName
;
745 BaseDirectory
.Length
-= BaseName
.Length
;
746 BaseDirectory
.MaximumLength
= BaseDirectory
.Length
;
750 /* Resolve imports */
751 MissingApiName
= Buffer
;
752 Status
= MiResolveImageReferences(DriverBase
,
758 if (!NT_SUCCESS(Status
)) return Status
;
761 *ModuleObject
= LdrEntry
;
762 return STATUS_SUCCESS
;
766 * IopInitializeBuiltinDriver
768 * Initialize a driver that is already loaded in memory.
773 IopInitializeBuiltinDriver(IN PLDR_DATA_TABLE_ENTRY LdrEntry
)
775 PDEVICE_NODE DeviceNode
;
776 PDRIVER_OBJECT DriverObject
;
778 PWCHAR FileNameWithoutPath
;
779 LPWSTR FileExtension
;
780 PUNICODE_STRING ModuleName
= &LdrEntry
->BaseDllName
;
781 UNICODE_STRING ServiceName
;
782 #if 1 // Disable for FreeLDR 2.5
783 UNICODE_STRING ServiceNameWithExtension
;
784 PLDR_DATA_TABLE_ENTRY ModuleObject
;
788 * Display 'Loading XXX...' message
790 IopDisplayLoadingMessage(ModuleName
->Buffer
, TRUE
);
793 * Generate filename without path (not needed by freeldr)
795 FileNameWithoutPath
= wcsrchr(ModuleName
->Buffer
, L
'\\');
796 if (FileNameWithoutPath
== NULL
)
798 FileNameWithoutPath
= ModuleName
->Buffer
;
802 FileNameWithoutPath
++;
808 #if 1 // Remove for FreeLDR 2.5.
809 RtlCreateUnicodeString(&ServiceNameWithExtension
, FileNameWithoutPath
);
810 Status
= LdrProcessDriverModule(LdrEntry
, &ServiceNameWithExtension
, &ModuleObject
);
811 if (!NT_SUCCESS(Status
))
813 CPRINT("Driver '%wZ' load failed, status (%x)\n", ModuleName
, Status
);
819 * Strip the file extension from ServiceName
821 RtlCreateUnicodeString(&ServiceName
, FileNameWithoutPath
);
822 FileExtension
= wcsrchr(ServiceName
.Buffer
, '.');
823 if (FileExtension
!= NULL
)
825 ServiceName
.Length
-= wcslen(FileExtension
) * sizeof(WCHAR
);
826 FileExtension
[0] = 0;
830 * Determine the right device object
832 /* Use IopRootDeviceNode for now */
833 Status
= IopCreateDeviceNode(IopRootDeviceNode
, NULL
, &ServiceName
, &DeviceNode
);
834 if (!NT_SUCCESS(Status
))
836 CPRINT("Driver '%wZ' load failed, status (%x)\n", ModuleName
, Status
);
839 DeviceNode
->ServiceName
= ServiceName
;
842 * Initialize the driver
844 DeviceNode
->Flags
|= DN_DRIVER_LOADED
;
845 Status
= IopInitializeDriverModule(DeviceNode
, LdrEntry
,
846 &DeviceNode
->ServiceName
, FALSE
, &DriverObject
);
848 if (!NT_SUCCESS(Status
))
850 IopFreeDeviceNode(DeviceNode
);
854 Status
= IopInitializeDevice(DeviceNode
, DriverObject
);
855 if (NT_SUCCESS(Status
))
857 Status
= IopStartDevice(DeviceNode
);
864 * IopInitializeBootDrivers
866 * Initialize boot drivers and free memory for boot files.
876 IopInitializeBootDrivers(VOID
)
878 PLIST_ENTRY ListHead
, NextEntry
;
879 PLDR_DATA_TABLE_ENTRY LdrEntry
;
880 PDEVICE_NODE DeviceNode
;
881 PDRIVER_OBJECT DriverObject
;
882 LDR_DATA_TABLE_ENTRY ModuleObject
;
884 UNICODE_STRING DriverName
;
886 DPRINT("IopInitializeBootDrivers()");
888 /* Use IopRootDeviceNode for now */
889 Status
= IopCreateDeviceNode(IopRootDeviceNode
, NULL
, NULL
, &DeviceNode
);
890 if (!NT_SUCCESS(Status
)) return;
892 /* Setup the module object for the RAW FS Driver */
893 ModuleObject
.DllBase
= NULL
;
894 ModuleObject
.SizeOfImage
= 0;
895 ModuleObject
.EntryPoint
= RawFsDriverEntry
;
896 RtlInitUnicodeString(&DriverName
, L
"RAW");
899 Status
= IopInitializeDriverModule(DeviceNode
,
904 if (!NT_SUCCESS(Status
))
907 IopFreeDeviceNode(DeviceNode
);
911 /* Now initialize the associated device */
912 Status
= IopInitializeDevice(DeviceNode
, DriverObject
);
913 if (!NT_SUCCESS(Status
))
916 IopFreeDeviceNode(DeviceNode
);
921 Status
= IopStartDevice(DeviceNode
);
922 if (!NT_SUCCESS(Status
))
925 IopFreeDeviceNode(DeviceNode
);
929 /* Loop the boot modules */
930 ListHead
= &KeLoaderBlock
->LoadOrderListHead
;
931 NextEntry
= ListHead
->Flink
;
932 while (ListHead
!= NextEntry
)
935 LdrEntry
= CONTAINING_RECORD(NextEntry
,
936 LDR_DATA_TABLE_ENTRY
,
940 * HACK: Make sure we're loading a driver
941 * (we should be using BootDriverListHead!)
943 if (wcsstr(_wcsupr(LdrEntry
->BaseDllName
.Buffer
), L
".SYS"))
945 /* Make sure we didn't load this driver already */
946 if (!(LdrEntry
->Flags
& LDRP_ENTRY_INSERTED
))
948 DPRINT("Initializing bootdriver %wZ\n", &LdrEntry
->BaseDllName
);
950 IopInitializeBuiltinDriver(LdrEntry
);
954 /* Go to the next driver */
955 NextEntry
= NextEntry
->Flink
;
958 /* In old ROS, the loader list became empty after this point. Simulate. */
959 InitializeListHead(&KeLoaderBlock
->LoadOrderListHead
);
965 * Unloads a device driver.
969 * Name of the service to unload (registry key).
972 * Whether to unload Plug & Plug or only legacy drivers. If this
973 * parameter is set to FALSE, the routine will unload only legacy
980 * Guard the whole function by SEH.
984 IopUnloadDriver(PUNICODE_STRING DriverServiceName
, BOOLEAN UnloadPnpDrivers
)
986 RTL_QUERY_REGISTRY_TABLE QueryTable
[2];
987 UNICODE_STRING ImagePath
;
988 UNICODE_STRING ServiceName
;
989 UNICODE_STRING ObjectName
;
990 PDRIVER_OBJECT DriverObject
;
991 LOAD_UNLOAD_PARAMS LoadParams
;
995 DPRINT("IopUnloadDriver('%wZ', %d)\n", DriverServiceName
, UnloadPnpDrivers
);
1000 * Get the service name from the registry key name
1003 Start
= wcsrchr(DriverServiceName
->Buffer
, L
'\\');
1005 Start
= DriverServiceName
->Buffer
;
1009 RtlInitUnicodeString(&ServiceName
, Start
);
1012 * Construct the driver object name
1015 ObjectName
.Length
= (wcslen(Start
) + 8) * sizeof(WCHAR
);
1016 ObjectName
.MaximumLength
= ObjectName
.Length
+ sizeof(WCHAR
);
1017 ObjectName
.Buffer
= ExAllocatePool(PagedPool
, ObjectName
.MaximumLength
);
1018 wcscpy(ObjectName
.Buffer
, L
"\\Driver\\");
1019 memcpy(ObjectName
.Buffer
+ 8, Start
, ObjectName
.Length
- 8 * sizeof(WCHAR
));
1020 ObjectName
.Buffer
[ObjectName
.Length
/sizeof(WCHAR
)] = 0;
1023 * Find the driver object
1026 Status
= ObReferenceObjectByName(&ObjectName
, 0, 0, 0, IoDriverObjectType
,
1027 KernelMode
, 0, (PVOID
*)&DriverObject
);
1029 if (!NT_SUCCESS(Status
))
1031 DPRINT1("Can't locate driver object for %wZ\n", &ObjectName
);
1036 * Free the buffer for driver object name
1039 ExFreePool(ObjectName
.Buffer
);
1042 * Get path of service...
1045 RtlZeroMemory(QueryTable
, sizeof(QueryTable
));
1047 RtlInitUnicodeString(&ImagePath
, NULL
);
1049 QueryTable
[0].Name
= L
"ImagePath";
1050 QueryTable
[0].Flags
= RTL_QUERY_REGISTRY_DIRECT
;
1051 QueryTable
[0].EntryContext
= &ImagePath
;
1053 Status
= RtlQueryRegistryValues(RTL_REGISTRY_ABSOLUTE
,
1054 DriverServiceName
->Buffer
, QueryTable
, NULL
, NULL
);
1056 if (!NT_SUCCESS(Status
))
1058 DPRINT1("RtlQueryRegistryValues() failed (Status %x)\n", Status
);
1063 * Normalize the image path for all later processing.
1066 Status
= IopNormalizeImagePath(&ImagePath
, &ServiceName
);
1068 if (!NT_SUCCESS(Status
))
1070 DPRINT1("IopNormalizeImagePath() failed (Status %x)\n", Status
);
1075 * Free the service path
1078 ExFreePool(ImagePath
.Buffer
);
1081 * Unload the module and release the references to the device object
1084 /* Call the load/unload routine, depending on current process */
1085 if (DriverObject
->DriverUnload
)
1087 if (PsGetCurrentProcess() == PsInitialSystemProcess
)
1089 /* Just call right away */
1090 (*DriverObject
->DriverUnload
)(DriverObject
);
1094 /* Load/Unload must be called from system process */
1096 /* Prepare parameters block */
1097 LoadParams
.DriverObject
= DriverObject
;
1098 KeInitializeEvent(&LoadParams
.Event
, NotificationEvent
, FALSE
);
1100 ExInitializeWorkItem(&LoadParams
.WorkItem
,
1101 (PWORKER_THREAD_ROUTINE
)IopLoadUnloadDriver
,
1102 (PVOID
)&LoadParams
);
1105 ExQueueWorkItem(&LoadParams
.WorkItem
, DelayedWorkQueue
);
1107 /* And wait when it completes */
1108 KeWaitForSingleObject(&LoadParams
.Event
, UserRequest
, KernelMode
,
1113 ObDereferenceObject(DriverObject
);
1114 ObDereferenceObject(DriverObject
);
1115 MmUnloadSystemImage(DriverObject
->DriverSection
);
1117 return STATUS_SUCCESS
;
1122 IopReinitializeDrivers(VOID
)
1124 PDRIVER_REINIT_ITEM ReinitItem
;
1127 /* Get the first entry and start looping */
1128 Entry
= ExInterlockedRemoveHeadList(&DriverReinitListHead
,
1129 &DriverReinitListLock
);
1133 ReinitItem
= CONTAINING_RECORD(Entry
, DRIVER_REINIT_ITEM
, ItemEntry
);
1135 /* Increment reinitialization counter */
1136 ReinitItem
->DriverObject
->DriverExtension
->Count
++;
1138 /* Remove the device object flag */
1139 ReinitItem
->DriverObject
->Flags
&= ~DRVO_REINIT_REGISTERED
;
1141 /* Call the routine */
1142 ReinitItem
->ReinitRoutine(ReinitItem
->DriverObject
,
1143 ReinitItem
->Context
,
1144 ReinitItem
->DriverObject
->
1145 DriverExtension
->Count
);
1147 /* Free the entry */
1150 /* Move to the next one */
1151 Entry
= ExInterlockedRemoveHeadList(&DriverReinitListHead
,
1152 &DriverReinitListLock
);
1158 IopReinitializeBootDrivers(VOID
)
1160 PDRIVER_REINIT_ITEM ReinitItem
;
1163 /* Get the first entry and start looping */
1164 Entry
= ExInterlockedRemoveHeadList(&DriverBootReinitListHead
,
1165 &DriverBootReinitListLock
);
1169 ReinitItem
= CONTAINING_RECORD(Entry
, DRIVER_REINIT_ITEM
, ItemEntry
);
1171 /* Increment reinitialization counter */
1172 ReinitItem
->DriverObject
->DriverExtension
->Count
++;
1174 /* Remove the device object flag */
1175 ReinitItem
->DriverObject
->Flags
&= ~DRVO_BOOTREINIT_REGISTERED
;
1177 /* Call the routine */
1178 ReinitItem
->ReinitRoutine(ReinitItem
->DriverObject
,
1179 ReinitItem
->Context
,
1180 ReinitItem
->DriverObject
->
1181 DriverExtension
->Count
);
1183 /* Free the entry */
1186 /* Move to the next one */
1187 Entry
= ExInterlockedRemoveHeadList(&DriverBootReinitListHead
,
1188 &DriverBootReinitListLock
);
1194 IopCreateDriver(IN PUNICODE_STRING DriverName OPTIONAL
,
1195 IN PDRIVER_INITIALIZE InitializationFunction
,
1196 IN PUNICODE_STRING RegistryPath
,
1198 IN ULONG SizeOfImage
,
1199 OUT PDRIVER_OBJECT
*pDriverObject
)
1201 WCHAR NameBuffer
[100];
1203 UNICODE_STRING LocalDriverName
;
1205 OBJECT_ATTRIBUTES ObjectAttributes
;
1207 PDRIVER_OBJECT DriverObject
;
1208 UNICODE_STRING ServiceKeyName
;
1210 ULONG i
, RetryCount
= 0;
1213 /* First, create a unique name for the driver if we don't have one */
1216 /* Create a random name and set up the string*/
1217 NameLength
= (USHORT
)swprintf(NameBuffer
,
1220 LocalDriverName
.Length
= NameLength
* sizeof(WCHAR
);
1221 LocalDriverName
.MaximumLength
= LocalDriverName
.Length
+ sizeof(UNICODE_NULL
);
1222 LocalDriverName
.Buffer
= NameBuffer
;
1226 /* So we can avoid another code path, use a local var */
1227 LocalDriverName
= *DriverName
;
1230 /* Initialize the Attributes */
1231 ObjectSize
= sizeof(DRIVER_OBJECT
) + sizeof(EXTENDED_DRIVER_EXTENSION
);
1232 InitializeObjectAttributes(&ObjectAttributes
,
1234 OBJ_PERMANENT
| OBJ_CASE_INSENSITIVE
,
1238 /* Create the Object */
1239 Status
= ObCreateObject(KernelMode
,
1247 (PVOID
*)&DriverObject
);
1248 if (!NT_SUCCESS(Status
)) return Status
;
1250 DPRINT("IopCreateDriver(): created DO %p\n", DriverObject
);
1252 /* Set up the Object */
1253 RtlZeroMemory(DriverObject
, ObjectSize
);
1254 DriverObject
->Type
= IO_TYPE_DRIVER
;
1255 DriverObject
->Size
= sizeof(DRIVER_OBJECT
);
1256 DriverObject
->Flags
= DRVO_BUILTIN_DRIVER
;
1257 DriverObject
->DriverExtension
= (PDRIVER_EXTENSION
)(DriverObject
+ 1);
1258 DriverObject
->DriverExtension
->DriverObject
= DriverObject
;
1259 DriverObject
->DriverInit
= InitializationFunction
;
1261 /* Loop all Major Functions */
1262 for (i
= 0; i
<= IRP_MJ_MAXIMUM_FUNCTION
; i
++)
1264 /* Invalidate each function */
1265 DriverObject
->MajorFunction
[i
] = IopInvalidDeviceRequest
;
1268 /* Set up the service key name buffer */
1269 ServiceKeyName
.Buffer
= ExAllocatePoolWithTag(PagedPool
,
1270 LocalDriverName
.Length
+
1273 if (!ServiceKeyName
.Buffer
)
1276 ObMakeTemporaryObject(DriverObject
);
1277 ObDereferenceObject(DriverObject
);
1278 return STATUS_INSUFFICIENT_RESOURCES
;
1281 /* Fill out the key data and copy the buffer */
1282 ServiceKeyName
.Length
= LocalDriverName
.Length
;
1283 ServiceKeyName
.MaximumLength
= LocalDriverName
.MaximumLength
;
1284 RtlCopyMemory(ServiceKeyName
.Buffer
,
1285 LocalDriverName
.Buffer
,
1286 LocalDriverName
.Length
);
1288 /* Null-terminate it and set it */
1289 ServiceKeyName
.Buffer
[ServiceKeyName
.Length
/ sizeof(WCHAR
)] = UNICODE_NULL
;
1290 DriverObject
->DriverExtension
->ServiceKeyName
= ServiceKeyName
;
1292 /* Also store it in the Driver Object. This is a bit of a hack. */
1293 RtlCopyMemory(&DriverObject
->DriverName
,
1295 sizeof(UNICODE_STRING
));
1297 /* Add the Object and get its handle */
1298 Status
= ObInsertObject(DriverObject
,
1305 /* Eliminate small possibility when this function is called more than
1306 once in a row, and KeTickCount doesn't get enough time to change */
1307 if (!DriverName
&& (Status
== STATUS_OBJECT_NAME_COLLISION
) && (RetryCount
< 100))
1313 if (!NT_SUCCESS(Status
)) return Status
;
1315 /* Now reference it */
1316 Status
= ObReferenceObjectByHandle(hDriver
,
1320 (PVOID
*)&DriverObject
,
1322 if (!NT_SUCCESS(Status
))
1325 ObMakeTemporaryObject(DriverObject
);
1326 ObDereferenceObject(DriverObject
);
1330 /* Close the extra handle */
1333 DriverObject
->HardwareDatabase
= &IopHardwareDatabaseKey
;
1334 DriverObject
->DriverStart
= DllBase
;
1335 DriverObject
->DriverSize
= SizeOfImage
;
1337 /* Finally, call its init function */
1338 DPRINT("RegistryKey: %wZ\n", RegistryPath
);
1339 DPRINT("Calling driver entrypoint at %p\n", InitializationFunction
);
1340 Status
= (*InitializationFunction
)(DriverObject
, RegistryPath
);
1341 if (!NT_SUCCESS(Status
))
1343 /* If it didn't work, then kill the object */
1344 DPRINT1("'%wZ' initialization failed, status (0x%08lx)\n", DriverName
, Status
);
1345 ObMakeTemporaryObject(DriverObject
);
1346 ObDereferenceObject(DriverObject
);
1350 /* Returns to caller the object */
1351 *pDriverObject
= DriverObject
;
1354 /* Return the Status */
1358 /* PUBLIC FUNCTIONS ***********************************************************/
1365 IoCreateDriver(IN PUNICODE_STRING DriverName OPTIONAL
,
1366 IN PDRIVER_INITIALIZE InitializationFunction
)
1368 PDRIVER_OBJECT DriverObject
;
1369 return IopCreateDriver(DriverName
, InitializationFunction
, NULL
, 0, 0, &DriverObject
);
1377 IoDeleteDriver(IN PDRIVER_OBJECT DriverObject
)
1379 /* Simply derefence the Object */
1380 ObDereferenceObject(DriverObject
);
1388 IoRegisterBootDriverReinitialization(IN PDRIVER_OBJECT DriverObject
,
1389 IN PDRIVER_REINITIALIZE ReinitRoutine
,
1392 PDRIVER_REINIT_ITEM ReinitItem
;
1394 /* Allocate the entry */
1395 ReinitItem
= ExAllocatePoolWithTag(NonPagedPool
,
1396 sizeof(DRIVER_REINIT_ITEM
),
1398 if (!ReinitItem
) return;
1401 ReinitItem
->DriverObject
= DriverObject
;
1402 ReinitItem
->ReinitRoutine
= ReinitRoutine
;
1403 ReinitItem
->Context
= Context
;
1405 /* Set the Driver Object flag and insert the entry into the list */
1406 DriverObject
->Flags
|= DRVO_BOOTREINIT_REGISTERED
;
1407 ExInterlockedInsertTailList(&DriverBootReinitListHead
,
1408 &ReinitItem
->ItemEntry
,
1409 &DriverBootReinitListLock
);
1417 IoRegisterDriverReinitialization(IN PDRIVER_OBJECT DriverObject
,
1418 IN PDRIVER_REINITIALIZE ReinitRoutine
,
1421 PDRIVER_REINIT_ITEM ReinitItem
;
1423 /* Allocate the entry */
1424 ReinitItem
= ExAllocatePoolWithTag(NonPagedPool
,
1425 sizeof(DRIVER_REINIT_ITEM
),
1427 if (!ReinitItem
) return;
1430 ReinitItem
->DriverObject
= DriverObject
;
1431 ReinitItem
->ReinitRoutine
= ReinitRoutine
;
1432 ReinitItem
->Context
= Context
;
1434 /* Set the Driver Object flag and insert the entry into the list */
1435 DriverObject
->Flags
|= DRVO_REINIT_REGISTERED
;
1436 ExInterlockedInsertTailList(&DriverReinitListHead
,
1437 &ReinitItem
->ItemEntry
,
1438 &DriverReinitListLock
);
1446 IoAllocateDriverObjectExtension(IN PDRIVER_OBJECT DriverObject
,
1447 IN PVOID ClientIdentificationAddress
,
1448 IN ULONG DriverObjectExtensionSize
,
1449 OUT PVOID
*DriverObjectExtension
)
1452 PIO_CLIENT_EXTENSION DriverExtensions
, NewDriverExtension
;
1453 BOOLEAN Inserted
= FALSE
;
1455 /* Assume failure */
1456 *DriverObjectExtension
= NULL
;
1458 /* Allocate the extension */
1459 NewDriverExtension
= ExAllocatePoolWithTag(NonPagedPool
,
1460 sizeof(IO_CLIENT_EXTENSION
) +
1461 DriverObjectExtensionSize
,
1462 TAG_DRIVER_EXTENSION
);
1463 if (!NewDriverExtension
) return STATUS_INSUFFICIENT_RESOURCES
;
1465 /* Clear the extension for teh caller */
1466 RtlZeroMemory(NewDriverExtension
,
1467 sizeof(IO_CLIENT_EXTENSION
) + DriverObjectExtensionSize
);
1470 OldIrql
= KeRaiseIrqlToDpcLevel();
1472 /* Fill out the extension */
1473 NewDriverExtension
->ClientIdentificationAddress
= ClientIdentificationAddress
;
1475 /* Loop the current extensions */
1476 DriverExtensions
= IoGetDrvObjExtension(DriverObject
)->
1477 ClientDriverExtension
;
1478 while (DriverExtensions
)
1480 /* Check if the identifier matches */
1481 if (DriverExtensions
->ClientIdentificationAddress
==
1482 ClientIdentificationAddress
)
1484 /* We have a collision, break out */
1488 /* Go to the next one */
1489 DriverExtensions
= DriverExtensions
->NextExtension
;
1492 /* Check if we didn't collide */
1493 if (!DriverExtensions
)
1495 /* Link this one in */
1496 NewDriverExtension
->NextExtension
=
1497 IoGetDrvObjExtension(DriverObject
)->ClientDriverExtension
;
1498 IoGetDrvObjExtension(DriverObject
)->ClientDriverExtension
=
1503 /* Release the lock */
1504 KeLowerIrql(OldIrql
);
1506 /* Check if insertion failed */
1509 /* Free the entry and fail */
1510 ExFreePool(NewDriverExtension
);
1511 return STATUS_OBJECT_NAME_COLLISION
;
1514 /* Otherwise, return the pointer */
1515 *DriverObjectExtension
= NewDriverExtension
+ 1;
1516 return STATUS_SUCCESS
;
1524 IoGetDriverObjectExtension(IN PDRIVER_OBJECT DriverObject
,
1525 IN PVOID ClientIdentificationAddress
)
1528 PIO_CLIENT_EXTENSION DriverExtensions
;
1531 OldIrql
= KeRaiseIrqlToDpcLevel();
1533 /* Loop the list until we find the right one */
1534 DriverExtensions
= IoGetDrvObjExtension(DriverObject
)->ClientDriverExtension
;
1535 while (DriverExtensions
)
1537 /* Check for a match */
1538 if (DriverExtensions
->ClientIdentificationAddress
==
1539 ClientIdentificationAddress
)
1546 DriverExtensions
= DriverExtensions
->NextExtension
;
1550 KeLowerIrql(OldIrql
);
1552 /* Return nothing or the extension */
1553 if (!DriverExtensions
) return NULL
;
1554 return DriverExtensions
+ 1;
1558 IopLoadUnloadDriver(PLOAD_UNLOAD_PARAMS LoadParams
)
1560 RTL_QUERY_REGISTRY_TABLE QueryTable
[3];
1561 UNICODE_STRING ImagePath
;
1562 UNICODE_STRING ServiceName
;
1565 PDEVICE_NODE DeviceNode
;
1566 PDRIVER_OBJECT DriverObject
;
1567 PLDR_DATA_TABLE_ENTRY ModuleObject
;
1570 /* Check if it's an unload request */
1571 if (LoadParams
->DriverObject
)
1573 (*LoadParams
->DriverObject
->DriverUnload
)(LoadParams
->DriverObject
);
1575 /* Return success and signal the event */
1576 LoadParams
->Status
= STATUS_SUCCESS
;
1577 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1581 RtlInitUnicodeString(&ImagePath
, NULL
);
1584 * Get the service name from the registry key name.
1586 ASSERT(LoadParams
->ServiceName
->Length
>= sizeof(WCHAR
));
1588 ServiceName
= *LoadParams
->ServiceName
;
1589 cur
= LoadParams
->ServiceName
->Buffer
+
1590 (LoadParams
->ServiceName
->Length
/ sizeof(WCHAR
)) - 1;
1591 while (LoadParams
->ServiceName
->Buffer
!= cur
)
1595 ServiceName
.Buffer
= cur
+ 1;
1596 ServiceName
.Length
= LoadParams
->ServiceName
->Length
-
1597 (USHORT
)((ULONG_PTR
)ServiceName
.Buffer
-
1598 (ULONG_PTR
)LoadParams
->ServiceName
->Buffer
);
1608 RtlZeroMemory(&QueryTable
, sizeof(QueryTable
));
1610 RtlInitUnicodeString(&ImagePath
, NULL
);
1612 QueryTable
[0].Name
= L
"Type";
1613 QueryTable
[0].Flags
= RTL_QUERY_REGISTRY_DIRECT
| RTL_QUERY_REGISTRY_REQUIRED
;
1614 QueryTable
[0].EntryContext
= &Type
;
1616 QueryTable
[1].Name
= L
"ImagePath";
1617 QueryTable
[1].Flags
= RTL_QUERY_REGISTRY_DIRECT
;
1618 QueryTable
[1].EntryContext
= &ImagePath
;
1620 Status
= RtlQueryRegistryValues(RTL_REGISTRY_ABSOLUTE
,
1621 LoadParams
->ServiceName
->Buffer
, QueryTable
, NULL
, NULL
);
1623 if (!NT_SUCCESS(Status
))
1625 DPRINT("RtlQueryRegistryValues() failed (Status %lx)\n", Status
);
1626 ExFreePool(ImagePath
.Buffer
);
1627 LoadParams
->Status
= Status
;
1628 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1633 * Normalize the image path for all later processing.
1636 Status
= IopNormalizeImagePath(&ImagePath
, &ServiceName
);
1638 if (!NT_SUCCESS(Status
))
1640 DPRINT("IopNormalizeImagePath() failed (Status %x)\n", Status
);
1641 LoadParams
->Status
= Status
;
1642 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1646 DPRINT("FullImagePath: '%wZ'\n", &ImagePath
);
1647 DPRINT("Type: %lx\n", Type
);
1650 * Create device node
1653 /* Use IopRootDeviceNode for now */
1654 Status
= IopCreateDeviceNode(IopRootDeviceNode
, NULL
, &ServiceName
, &DeviceNode
);
1656 if (!NT_SUCCESS(Status
))
1658 DPRINT("IopCreateDeviceNode() failed (Status %lx)\n", Status
);
1659 LoadParams
->Status
= Status
;
1660 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1664 /* Get existing DriverObject pointer (in case the driver has
1665 already been loaded and initialized) */
1666 Status
= IopGetDriverObject(
1669 (Type
== 2 /* SERVICE_FILE_SYSTEM_DRIVER */ ||
1670 Type
== 8 /* SERVICE_RECOGNIZER_DRIVER */));
1672 if (!NT_SUCCESS(Status
))
1675 * Load the driver module
1678 Status
= MmLoadSystemImage(&ImagePath
, NULL
, NULL
, 0, (PVOID
)&ModuleObject
, NULL
);
1679 if (!NT_SUCCESS(Status
) && Status
!= STATUS_IMAGE_ALREADY_LOADED
)
1681 DPRINT("MmLoadSystemImage() failed (Status %lx)\n", Status
);
1682 IopFreeDeviceNode(DeviceNode
);
1683 LoadParams
->Status
= Status
;
1684 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1689 * Set a service name for the device node
1692 RtlCreateUnicodeString(&DeviceNode
->ServiceName
, ServiceName
.Buffer
);
1695 * Initialize the driver module if it's loaded for the first time
1697 if (Status
!= STATUS_IMAGE_ALREADY_LOADED
)
1699 Status
= IopInitializeDriverModule(
1702 &DeviceNode
->ServiceName
,
1703 (Type
== 2 /* SERVICE_FILE_SYSTEM_DRIVER */ ||
1704 Type
== 8 /* SERVICE_RECOGNIZER_DRIVER */),
1707 if (!NT_SUCCESS(Status
))
1709 DPRINT("IopInitializeDriver() failed (Status %lx)\n", Status
);
1710 MmUnloadSystemImage(ModuleObject
);
1711 IopFreeDeviceNode(DeviceNode
);
1712 LoadParams
->Status
= Status
;
1713 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1718 /* We have a driver for this DeviceNode */
1719 DeviceNode
->Flags
|= DN_DRIVER_LOADED
;
1722 IopInitializeDevice(DeviceNode
, DriverObject
);
1723 LoadParams
->Status
= IopStartDevice(DeviceNode
);
1724 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1730 * Loads a device driver.
1734 * Name of the service to load (registry key).
1743 NtLoadDriver(IN PUNICODE_STRING DriverServiceName
)
1745 UNICODE_STRING CapturedDriverServiceName
= {0};
1746 KPROCESSOR_MODE PreviousMode
;
1747 LOAD_UNLOAD_PARAMS LoadParams
;
1752 PreviousMode
= KeGetPreviousMode();
1755 * Check security privileges
1758 /* FIXME: Uncomment when privileges will be correctly implemented. */
1760 if (!SeSinglePrivilegeCheck(SeLoadDriverPrivilege
, PreviousMode
))
1762 DPRINT("Privilege not held\n");
1763 return STATUS_PRIVILEGE_NOT_HELD
;
1767 Status
= ProbeAndCaptureUnicodeString(&CapturedDriverServiceName
,
1770 if (!NT_SUCCESS(Status
))
1775 DPRINT("NtLoadDriver('%wZ')\n", &CapturedDriverServiceName
);
1777 LoadParams
.ServiceName
= &CapturedDriverServiceName
;
1778 LoadParams
.DriverObject
= NULL
;
1779 KeInitializeEvent(&LoadParams
.Event
, NotificationEvent
, FALSE
);
1781 /* Call the load/unload routine, depending on current process */
1782 if (PsGetCurrentProcess() == PsInitialSystemProcess
)
1784 /* Just call right away */
1785 IopLoadUnloadDriver(&LoadParams
);
1789 /* Load/Unload must be called from system process */
1790 ExInitializeWorkItem(&LoadParams
.WorkItem
,
1791 (PWORKER_THREAD_ROUTINE
)IopLoadUnloadDriver
,
1792 (PVOID
)&LoadParams
);
1795 ExQueueWorkItem(&LoadParams
.WorkItem
, DelayedWorkQueue
);
1797 /* And wait when it completes */
1798 KeWaitForSingleObject(&LoadParams
.Event
, UserRequest
, KernelMode
,
1802 ReleaseCapturedUnicodeString(&CapturedDriverServiceName
,
1805 return LoadParams
.Status
;
1811 * Unloads a legacy device driver.
1815 * Name of the service to unload (registry key).
1825 NtUnloadDriver(IN PUNICODE_STRING DriverServiceName
)
1827 return IopUnloadDriver(DriverServiceName
, FALSE
);