2 * PROJECT: ReactOS Kernel
3 * LICENSE: GPL - See COPYING in the top level directory
4 * FILE: ntoskrnl/io/iomgr/driver.c
5 * PURPOSE: Driver Object Management
6 * PROGRAMMERS: Alex Ionescu (alex.ionescu@reactos.org)
7 * Filip Navara (navaraf@reactos.org)
8 * Hervé Poussineau (hpoussin@reactos.org)
11 /* INCLUDES *******************************************************************/
15 #include <internal/debug.h>
17 /* GLOBALS ********************************************************************/
19 LIST_ENTRY DriverReinitListHead
;
20 KSPIN_LOCK DriverReinitListLock
;
21 PLIST_ENTRY DriverReinitTailEntry
;
23 PLIST_ENTRY DriverBootReinitTailEntry
;
24 LIST_ENTRY DriverBootReinitListHead
;
25 KSPIN_LOCK DriverBootReinitListLock
;
27 UNICODE_STRING IopHardwareDatabaseKey
=
28 RTL_CONSTANT_STRING(L
"\\REGISTRY\\MACHINE\\HARDWARE\\DESCRIPTION\\SYSTEM");
30 POBJECT_TYPE IoDriverObjectType
= NULL
;
32 extern BOOLEAN ExpInTextModeSetup
;
34 /* PRIVATE FUNCTIONS **********************************************************/
37 IopInvalidDeviceRequest(
38 PDEVICE_OBJECT DeviceObject
,
41 Irp
->IoStatus
.Status
= STATUS_INVALID_DEVICE_REQUEST
;
42 Irp
->IoStatus
.Information
= 0;
43 IoCompleteRequest(Irp
, IO_NO_INCREMENT
);
44 return STATUS_INVALID_DEVICE_REQUEST
;
49 IopDeleteDriver(IN PVOID ObjectBody
)
51 PDRIVER_OBJECT DriverObject
= ObjectBody
;
52 PIO_CLIENT_EXTENSION DriverExtension
, NextDriverExtension
;
55 /* Get the extension and loop them */
56 DriverExtension
= IoGetDrvObjExtension(DriverObject
)->
57 ClientDriverExtension
;
58 while (DriverExtension
)
60 /* Get the next one */
61 NextDriverExtension
= DriverExtension
->NextExtension
;
62 ExFreePoolWithTag(DriverExtension
, TAG_DRIVER_EXTENSION
);
65 DriverExtension
= NextDriverExtension
;
68 /* Check if the driver image is still loaded */
69 if (DriverObject
->DriverSection
)
72 //LdrpUnloadImage(DriverObject->DriverSection);
75 /* Check if it has a name */
76 if (DriverObject
->DriverName
.Buffer
)
79 ExFreePool(DriverObject
->DriverName
.Buffer
);
82 #if 0 /* See a bit of hack in IopCreateDriver */
83 /* Check if it has a service key name */
84 if (DriverObject
->DriverExtension
->ServiceKeyName
.Buffer
)
87 ExFreePool(DriverObject
->DriverExtension
->ServiceKeyName
.Buffer
);
94 PDRIVER_OBJECT
*DriverObject
,
95 PUNICODE_STRING ServiceName
,
98 PDRIVER_OBJECT Object
;
99 WCHAR NameBuffer
[MAX_PATH
];
100 UNICODE_STRING DriverName
;
103 DPRINT("IopGetDriverObject(%p '%wZ' %x)\n",
104 DriverObject
, ServiceName
, FileSystem
);
106 *DriverObject
= NULL
;
108 /* Create ModuleName string */
109 if (ServiceName
== NULL
|| ServiceName
->Buffer
== NULL
)
110 /* We don't know which DriverObject we have to open */
111 return STATUS_INVALID_PARAMETER_2
;
113 DriverName
.Buffer
= NameBuffer
;
114 DriverName
.Length
= 0;
115 DriverName
.MaximumLength
= sizeof(NameBuffer
);
117 if (FileSystem
== TRUE
)
118 RtlAppendUnicodeToString(&DriverName
, FILESYSTEM_ROOT_NAME
);
120 RtlAppendUnicodeToString(&DriverName
, DRIVER_ROOT_NAME
);
121 RtlAppendUnicodeStringToString(&DriverName
, ServiceName
);
123 DPRINT("Driver name: '%wZ'\n", &DriverName
);
125 /* Open driver object */
126 Status
= ObReferenceObjectByName(
128 OBJ_OPENIF
| OBJ_KERNEL_HANDLE
| OBJ_CASE_INSENSITIVE
, /* Attributes */
129 NULL
, /* PassedAccessState */
130 0, /* DesiredAccess */
133 NULL
, /* ParseContext */
136 if (!NT_SUCCESS(Status
))
138 DPRINT("Failed to reference driver object, status=0x%08x\n", Status
);
142 *DriverObject
= Object
;
144 DPRINT("Driver Object: %p\n", Object
);
146 return STATUS_SUCCESS
;
150 * IopDisplayLoadingMessage
152 * Display 'Loading XXX...' message.
158 IopDisplayLoadingMessage(PVOID ServiceName
,
161 CHAR TextBuffer
[256];
162 PCHAR Extra
= ".sys";
164 if (ExpInTextModeSetup
) return;
167 if (wcsstr(_wcsupr(ServiceName
), L
".SYS")) Extra
= "";
170 KeLoaderBlock
->ArcBootDeviceName
,
171 KeLoaderBlock
->NtBootPathName
,
178 if (strstr(_strupr(ServiceName
), ".SYS")) Extra
= "";
181 KeLoaderBlock
->ArcBootDeviceName
,
182 KeLoaderBlock
->NtBootPathName
,
187 HalDisplayString(TextBuffer
);
191 * IopNormalizeImagePath
193 * Normalize an image path to contain complete path.
197 * The input path and on exit the result path. ImagePath.Buffer
198 * must be allocated by ExAllocatePool on input. Caller is responsible
199 * for freeing the buffer when it's no longer needed.
202 * Name of the service that ImagePath belongs to.
208 * The input image path isn't freed on error.
212 IopNormalizeImagePath(
213 IN OUT PUNICODE_STRING ImagePath
,
214 IN PUNICODE_STRING ServiceName
)
216 UNICODE_STRING InputImagePath
;
221 sizeof(UNICODE_STRING
));
223 if (InputImagePath
.Length
== 0)
225 ImagePath
->Length
= 0;
226 ImagePath
->MaximumLength
=
227 (33 * sizeof(WCHAR
)) + ServiceName
->Length
+ sizeof(UNICODE_NULL
);
228 ImagePath
->Buffer
= ExAllocatePool(NonPagedPool
, ImagePath
->MaximumLength
);
229 if (ImagePath
->Buffer
== NULL
)
230 return STATUS_NO_MEMORY
;
232 RtlAppendUnicodeToString(ImagePath
, L
"\\SystemRoot\\system32\\drivers\\");
233 RtlAppendUnicodeStringToString(ImagePath
, ServiceName
);
234 RtlAppendUnicodeToString(ImagePath
, L
".sys");
236 if (InputImagePath
.Buffer
[0] != L
'\\')
238 ImagePath
->Length
= 0;
239 ImagePath
->MaximumLength
=
240 12 * sizeof(WCHAR
) + InputImagePath
.Length
+ sizeof(UNICODE_NULL
);
241 ImagePath
->Buffer
= ExAllocatePool(NonPagedPool
, ImagePath
->MaximumLength
);
242 if (ImagePath
->Buffer
== NULL
)
243 return STATUS_NO_MEMORY
;
245 RtlAppendUnicodeToString(ImagePath
, L
"\\SystemRoot\\");
246 RtlAppendUnicodeStringToString(ImagePath
, &InputImagePath
);
248 /* Free caller's string */
249 RtlFreeUnicodeString(&InputImagePath
);
252 return STATUS_SUCCESS
;
256 * IopLoadServiceModule
258 * Load a module specified by registry settings for service.
262 * Name of the service to load.
269 IopLoadServiceModule(
270 IN PUNICODE_STRING ServiceName
,
271 OUT PLDR_DATA_TABLE_ENTRY
*ModuleObject
)
273 RTL_QUERY_REGISTRY_TABLE QueryTable
[3];
275 UNICODE_STRING ServiceImagePath
, CCSName
;
277 HANDLE CCSKey
, ServiceKey
;
279 DPRINT("IopLoadServiceModule(%wZ, 0x%p)\n", ServiceName
, ModuleObject
);
281 /* FIXME: This check may be removed once the bug is fixed */
282 if (ServiceName
->Buffer
== NULL
)
284 DPRINT1("If you see this, please report to Fireball or hpoussin!\n");
285 return STATUS_UNSUCCESSFUL
;
288 /* Open CurrentControlSet */
289 RtlInitUnicodeString(&CCSName
,
290 L
"\\Registry\\Machine\\SYSTEM\\CurrentControlSet\\Services");
291 Status
= IopOpenRegistryKeyEx(&CCSKey
, NULL
, &CCSName
, KEY_READ
);
292 if (!NT_SUCCESS(Status
))
294 DPRINT1("ZwOpenKey() failed with Status %08X\n", Status
);
298 /* Open service key */
299 Status
= IopOpenRegistryKeyEx(&ServiceKey
, CCSKey
, ServiceName
, KEY_READ
);
300 if (!NT_SUCCESS(Status
))
302 DPRINT1("ZwOpenKey() failed with Status %08X\n", Status
);
308 * Get information about the service.
311 RtlZeroMemory(QueryTable
, sizeof(QueryTable
));
313 RtlInitUnicodeString(&ServiceImagePath
, NULL
);
315 QueryTable
[0].Name
= L
"Start";
316 QueryTable
[0].Flags
= RTL_QUERY_REGISTRY_DIRECT
;
317 QueryTable
[0].EntryContext
= &ServiceStart
;
319 QueryTable
[1].Name
= L
"ImagePath";
320 QueryTable
[1].Flags
= RTL_QUERY_REGISTRY_DIRECT
;
321 QueryTable
[1].EntryContext
= &ServiceImagePath
;
323 Status
= RtlQueryRegistryValues(RTL_REGISTRY_HANDLE
,
324 (PWSTR
)ServiceKey
, QueryTable
, NULL
, NULL
);
329 if (!NT_SUCCESS(Status
))
331 DPRINT1("RtlQueryRegistryValues() failed (Status %x)\n", Status
);
336 * Normalize the image path for all later processing.
339 Status
= IopNormalizeImagePath(&ServiceImagePath
, ServiceName
);
341 if (!NT_SUCCESS(Status
))
343 DPRINT("IopNormalizeImagePath() failed (Status %x)\n", Status
);
348 * Case for disabled drivers
351 if (ServiceStart
>= 4)
353 /* FIXME: Check if it is the right status code */
354 Status
= STATUS_PLUGPLAY_NO_DEVICE
;
358 DPRINT("Loading module\n");
359 Status
= MmLoadSystemImage(&ServiceImagePath
, NULL
, NULL
, 0, (PVOID
)ModuleObject
, NULL
);
362 ExFreePool(ServiceImagePath
.Buffer
);
365 * Now check if the module was loaded successfully.
368 if (!NT_SUCCESS(Status
))
370 DPRINT("Module loading failed (Status %x)\n", Status
);
373 DPRINT("Module loading (Status %x)\n", Status
);
379 * IopInitializeDriverModule
381 * Initalize a loaded driver.
385 * Pointer to device node.
388 * Module object representing the driver. It can be retrieve by
389 * IopLoadServiceModule.
392 * Name of the service (as in registry).
395 * Set to TRUE for file system drivers.
398 * On successful return this contains the driver object representing
403 IopInitializeDriverModule(
404 IN PDEVICE_NODE DeviceNode
,
405 IN PLDR_DATA_TABLE_ENTRY ModuleObject
,
406 IN PUNICODE_STRING ServiceName
,
407 IN BOOLEAN FileSystemDriver
,
408 OUT PDRIVER_OBJECT
*DriverObject
)
410 const WCHAR ServicesKeyName
[] = L
"\\Registry\\Machine\\System\\CurrentControlSet\\Services\\";
411 WCHAR NameBuffer
[MAX_PATH
];
412 UNICODE_STRING DriverName
;
413 UNICODE_STRING RegistryKey
;
414 PDRIVER_INITIALIZE DriverEntry
;
415 PDRIVER_OBJECT Driver
;
416 PDEVICE_OBJECT DeviceObject
;
419 DriverEntry
= ModuleObject
->EntryPoint
;
421 if (ServiceName
!= NULL
&& ServiceName
->Length
!= 0)
423 RegistryKey
.Length
= 0;
424 RegistryKey
.MaximumLength
= sizeof(ServicesKeyName
) + ServiceName
->Length
;
425 RegistryKey
.Buffer
= ExAllocatePool(PagedPool
, RegistryKey
.MaximumLength
);
426 if (RegistryKey
.Buffer
== NULL
)
428 return STATUS_INSUFFICIENT_RESOURCES
;
430 RtlAppendUnicodeToString(&RegistryKey
, ServicesKeyName
);
431 RtlAppendUnicodeStringToString(&RegistryKey
, ServiceName
);
435 RtlInitUnicodeString(&RegistryKey
, NULL
);
438 /* Create ModuleName string */
439 if (ServiceName
&& ServiceName
->Length
> 0)
441 if (FileSystemDriver
== TRUE
)
442 wcscpy(NameBuffer
, FILESYSTEM_ROOT_NAME
);
444 wcscpy(NameBuffer
, DRIVER_ROOT_NAME
);
446 RtlInitUnicodeString(&DriverName
, NameBuffer
);
447 DriverName
.MaximumLength
= sizeof(NameBuffer
);
449 RtlAppendUnicodeStringToString(&DriverName
, ServiceName
);
451 DPRINT("Driver name: '%wZ'\n", &DriverName
);
454 DriverName
.Length
= 0;
456 Status
= IopCreateDriver(
457 DriverName
.Length
> 0 ? &DriverName
: NULL
,
460 ModuleObject
->DllBase
,
461 ModuleObject
->SizeOfImage
,
463 RtlFreeUnicodeString(&RegistryKey
);
465 *DriverObject
= Driver
;
466 if (!NT_SUCCESS(Status
))
468 DPRINT("IopCreateDriver() failed (Status 0x%08lx)\n", Status
);
472 /* Set the driver as initialized */
473 Driver
->Flags
|= DRVO_INITIALIZED
;
474 DeviceObject
= Driver
->DeviceObject
;
477 /* Set every device as initialized too */
478 DeviceObject
->Flags
&= ~DO_DEVICE_INITIALIZING
;
479 DeviceObject
= DeviceObject
->NextDevice
;
482 IopReinitializeDrivers();
484 return STATUS_SUCCESS
;
488 * IopAttachFilterDriversCallback
490 * Internal routine used by IopAttachFilterDrivers.
494 IopAttachFilterDriversCallback(
502 PDEVICE_NODE DeviceNode
= Context
;
503 UNICODE_STRING ServiceName
;
505 PLDR_DATA_TABLE_ENTRY ModuleObject
;
506 PDRIVER_OBJECT DriverObject
;
509 for (Filters
= ValueData
;
510 ((ULONG_PTR
)Filters
- (ULONG_PTR
)ValueData
) < ValueLength
&&
512 Filters
+= (ServiceName
.Length
/ sizeof(WCHAR
)) + 1)
514 DPRINT("Filter Driver: %S (%wZ)\n", Filters
, &DeviceNode
->InstancePath
);
515 ServiceName
.Buffer
= Filters
;
516 ServiceName
.MaximumLength
=
517 ServiceName
.Length
= wcslen(Filters
) * sizeof(WCHAR
);
519 /* Load and initialize the filter driver */
520 Status
= IopLoadServiceModule(&ServiceName
, &ModuleObject
);
521 if (Status
!= STATUS_IMAGE_ALREADY_LOADED
)
523 if (!NT_SUCCESS(Status
))
526 Status
= IopInitializeDriverModule(DeviceNode
, ModuleObject
, &ServiceName
,
527 FALSE
, &DriverObject
);
528 if (!NT_SUCCESS(Status
))
533 /* get existing DriverObject pointer */
534 Status
= IopGetDriverObject(
538 if (!NT_SUCCESS(Status
))
540 DPRINT1("IopGetDriverObject() returned status 0x%08x!\n", Status
);
545 Status
= IopInitializeDevice(DeviceNode
, DriverObject
);
546 if (!NT_SUCCESS(Status
))
550 return STATUS_SUCCESS
;
554 * IopAttachFilterDrivers
556 * Load filter drivers for specified device node.
560 * Set to TRUE for loading lower level filters or FALSE for upper
565 IopAttachFilterDrivers(
566 PDEVICE_NODE DeviceNode
,
569 RTL_QUERY_REGISTRY_TABLE QueryTable
[2] = {{0}};
570 UNICODE_STRING Class
;
571 WCHAR ClassBuffer
[40];
572 UNICODE_STRING EnumRoot
= RTL_CONSTANT_STRING(ENUM_ROOT
);
573 HANDLE EnumRootKey
, SubKey
;
576 /* Open enumeration root key */
577 Status
= IopOpenRegistryKeyEx(&EnumRootKey
, NULL
,
578 &EnumRoot
, KEY_READ
);
579 if (!NT_SUCCESS(Status
))
581 DPRINT1("ZwOpenKey() failed with Status %08X\n", Status
);
586 Status
= IopOpenRegistryKeyEx(&SubKey
, EnumRootKey
,
587 &DeviceNode
->InstancePath
, KEY_READ
);
588 if (!NT_SUCCESS(Status
))
590 DPRINT1("ZwOpenKey() failed with Status %08X\n", Status
);
591 ZwClose(EnumRootKey
);
596 * First load the device filters
598 QueryTable
[0].QueryRoutine
= IopAttachFilterDriversCallback
;
600 QueryTable
[0].Name
= L
"LowerFilters";
602 QueryTable
[0].Name
= L
"UpperFilters";
603 QueryTable
[0].Flags
= RTL_QUERY_REGISTRY_REQUIRED
;
605 RtlQueryRegistryValues(
613 * Now get the class GUID
616 Class
.MaximumLength
= 40 * sizeof(WCHAR
);
617 Class
.Buffer
= ClassBuffer
;
618 QueryTable
[0].QueryRoutine
= NULL
;
619 QueryTable
[0].Name
= L
"ClassGUID";
620 QueryTable
[0].EntryContext
= &Class
;
621 QueryTable
[0].Flags
= RTL_QUERY_REGISTRY_REQUIRED
| RTL_QUERY_REGISTRY_DIRECT
;
623 Status
= RtlQueryRegistryValues(
632 ZwClose(EnumRootKey
);
635 * Load the class filter driver
637 if (NT_SUCCESS(Status
))
639 UNICODE_STRING ControlClass
= RTL_CONSTANT_STRING(L
"\\Registry\\Machine\\System\\CurrentControlSet\\Control\\Class");
641 Status
= IopOpenRegistryKeyEx(&EnumRootKey
, NULL
,
642 &ControlClass
, KEY_READ
);
643 if (!NT_SUCCESS(Status
))
645 DPRINT1("ZwOpenKey() failed with Status %08X\n", Status
);
650 Status
= IopOpenRegistryKeyEx(&SubKey
, EnumRootKey
,
652 if (!NT_SUCCESS(Status
))
654 DPRINT1("ZwOpenKey() failed with Status %08X\n", Status
);
655 ZwClose(EnumRootKey
);
659 QueryTable
[0].QueryRoutine
= IopAttachFilterDriversCallback
;
661 QueryTable
[0].Name
= L
"LowerFilters";
663 QueryTable
[0].Name
= L
"UpperFilters";
664 QueryTable
[0].EntryContext
= NULL
;
665 QueryTable
[0].Flags
= RTL_QUERY_REGISTRY_REQUIRED
;
667 RtlQueryRegistryValues(
676 ZwClose(EnumRootKey
);
679 return STATUS_SUCCESS
;
684 MiResolveImageReferences(IN PVOID ImageBase
,
685 IN PUNICODE_STRING ImageFileDirectory
,
686 IN PUNICODE_STRING NamePrefix OPTIONAL
,
687 OUT PCHAR
*MissingApi
,
688 OUT PWCHAR
*MissingDriver
,
689 OUT PLOAD_IMPORTS
*LoadImports
);
691 extern KSPIN_LOCK PsLoadedModuleSpinLock
;
694 // Used for images already loaded (boot drivers)
698 LdrProcessDriverModule(PLDR_DATA_TABLE_ENTRY LdrEntry
,
699 PUNICODE_STRING FileName
,
700 PLDR_DATA_TABLE_ENTRY
*ModuleObject
)
703 PLDR_DATA_TABLE_ENTRY NewEntry
;
704 UNICODE_STRING BaseName
, BaseDirectory
;
705 PLOAD_IMPORTS LoadedImports
= (PVOID
)-2;
706 PCHAR MissingApiName
, Buffer
;
707 PWCHAR MissingDriverName
;
708 PVOID DriverBase
= LdrEntry
->DllBase
;
710 /* Allocate a buffer we'll use for names */
711 Buffer
= ExAllocatePoolWithTag(NonPagedPool
, MAX_PATH
, TAG_LDR_WSTR
);
715 return STATUS_INSUFFICIENT_RESOURCES
;
718 /* Check for a separator */
719 if (FileName
->Buffer
[0] == OBJ_NAME_PATH_SEPARATOR
)
724 /* Loop the path until we get to the base name */
725 p
= &FileName
->Buffer
[FileName
->Length
/ sizeof(WCHAR
)];
726 while (*(p
- 1) != OBJ_NAME_PATH_SEPARATOR
) p
--;
729 BaseLength
= (ULONG
)(&FileName
->Buffer
[FileName
->Length
/ sizeof(WCHAR
)] - p
);
730 BaseLength
*= sizeof(WCHAR
);
732 /* Setup the string */
733 BaseName
.Length
= (USHORT
)BaseLength
;
738 /* Otherwise, we already have a base name */
739 BaseName
.Length
= FileName
->Length
;
740 BaseName
.Buffer
= FileName
->Buffer
;
743 /* Setup the maximum length */
744 BaseName
.MaximumLength
= BaseName
.Length
;
746 /* Now compute the base directory */
747 BaseDirectory
= *FileName
;
748 BaseDirectory
.Length
-= BaseName
.Length
;
749 BaseDirectory
.MaximumLength
= BaseDirectory
.Length
;
753 /* Resolve imports */
754 MissingApiName
= Buffer
;
755 Status
= MiResolveImageReferences(DriverBase
,
761 if (!NT_SUCCESS(Status
)) return Status
;
764 *ModuleObject
= LdrEntry
;
765 return STATUS_SUCCESS
;
769 * IopInitializeBuiltinDriver
771 * Initialize a driver that is already loaded in memory.
776 IopInitializeBuiltinDriver(IN PLDR_DATA_TABLE_ENTRY LdrEntry
)
778 PDEVICE_NODE DeviceNode
;
779 PDRIVER_OBJECT DriverObject
;
781 PWCHAR FileNameWithoutPath
;
782 LPWSTR FileExtension
;
783 PUNICODE_STRING ModuleName
= &LdrEntry
->BaseDllName
;
784 UNICODE_STRING ServiceName
;
787 * Display 'Loading XXX...' message
789 IopDisplayLoadingMessage(ModuleName
->Buffer
, TRUE
);
792 * Generate filename without path (not needed by freeldr)
794 FileNameWithoutPath
= wcsrchr(ModuleName
->Buffer
, L
'\\');
795 if (FileNameWithoutPath
== NULL
)
797 FileNameWithoutPath
= ModuleName
->Buffer
;
801 FileNameWithoutPath
++;
805 * Strip the file extension from ServiceName
807 RtlCreateUnicodeString(&ServiceName
, FileNameWithoutPath
);
808 FileExtension
= wcsrchr(ServiceName
.Buffer
, '.');
809 if (FileExtension
!= NULL
)
811 ServiceName
.Length
-= wcslen(FileExtension
) * sizeof(WCHAR
);
812 FileExtension
[0] = 0;
816 * Determine the right device object
818 /* Use IopRootDeviceNode for now */
819 Status
= IopCreateDeviceNode(IopRootDeviceNode
, NULL
, &ServiceName
, &DeviceNode
);
820 if (!NT_SUCCESS(Status
))
822 CPRINT("Driver '%wZ' load failed, status (%x)\n", ModuleName
, Status
);
825 DeviceNode
->ServiceName
= ServiceName
;
828 * Initialize the driver
830 Status
= IopInitializeDriverModule(DeviceNode
, LdrEntry
,
831 &DeviceNode
->ServiceName
, FALSE
, &DriverObject
);
833 if (!NT_SUCCESS(Status
))
835 IopFreeDeviceNode(DeviceNode
);
839 Status
= IopInitializeDevice(DeviceNode
, DriverObject
);
840 if (NT_SUCCESS(Status
))
842 Status
= IopStartDevice(DeviceNode
);
849 * IopInitializeBootDrivers
851 * Initialize boot drivers and free memory for boot files.
861 IopInitializeBootDrivers(VOID
)
863 PLIST_ENTRY ListHead
, NextEntry
;
864 PLDR_DATA_TABLE_ENTRY LdrEntry
;
865 PDEVICE_NODE DeviceNode
;
866 PDRIVER_OBJECT DriverObject
;
867 LDR_DATA_TABLE_ENTRY ModuleObject
;
869 UNICODE_STRING DriverName
;
871 DPRINT("IopInitializeBootDrivers()\n");
873 /* Use IopRootDeviceNode for now */
874 Status
= IopCreateDeviceNode(IopRootDeviceNode
, NULL
, NULL
, &DeviceNode
);
875 if (!NT_SUCCESS(Status
)) return;
877 /* Setup the module object for the RAW FS Driver */
878 ModuleObject
.DllBase
= NULL
;
879 ModuleObject
.SizeOfImage
= 0;
880 ModuleObject
.EntryPoint
= RawFsDriverEntry
;
881 RtlInitUnicodeString(&DriverName
, L
"RAW");
884 Status
= IopInitializeDriverModule(DeviceNode
,
889 if (!NT_SUCCESS(Status
))
892 IopFreeDeviceNode(DeviceNode
);
896 /* Now initialize the associated device */
897 Status
= IopInitializeDevice(DeviceNode
, DriverObject
);
898 if (!NT_SUCCESS(Status
))
901 IopFreeDeviceNode(DeviceNode
);
906 Status
= IopStartDevice(DeviceNode
);
907 if (!NT_SUCCESS(Status
))
910 IopFreeDeviceNode(DeviceNode
);
914 /* Loop the boot modules */
915 ListHead
= &KeLoaderBlock
->LoadOrderListHead
;
916 NextEntry
= ListHead
->Flink
;
917 while (ListHead
!= NextEntry
)
920 LdrEntry
= CONTAINING_RECORD(NextEntry
,
921 LDR_DATA_TABLE_ENTRY
,
925 * HACK: Make sure we're loading a driver
926 * (we should be using BootDriverListHead!)
928 if (wcsstr(_wcsupr(LdrEntry
->BaseDllName
.Buffer
), L
".SYS"))
930 /* Make sure we didn't load this driver already */
931 if (!(LdrEntry
->Flags
& LDRP_ENTRY_INSERTED
))
933 DPRINT("Initializing bootdriver %wZ\n", &LdrEntry
->BaseDllName
);
935 IopInitializeBuiltinDriver(LdrEntry
);
939 /* Go to the next driver */
940 NextEntry
= NextEntry
->Flink
;
943 /* In old ROS, the loader list became empty after this point. Simulate. */
944 InitializeListHead(&KeLoaderBlock
->LoadOrderListHead
);
950 * Unloads a device driver.
954 * Name of the service to unload (registry key).
957 * Whether to unload Plug & Plug or only legacy drivers. If this
958 * parameter is set to FALSE, the routine will unload only legacy
965 * Guard the whole function by SEH.
969 IopUnloadDriver(PUNICODE_STRING DriverServiceName
, BOOLEAN UnloadPnpDrivers
)
971 RTL_QUERY_REGISTRY_TABLE QueryTable
[2];
972 UNICODE_STRING ImagePath
;
973 UNICODE_STRING ServiceName
;
974 UNICODE_STRING ObjectName
;
975 PDRIVER_OBJECT DriverObject
;
976 LOAD_UNLOAD_PARAMS LoadParams
;
980 DPRINT("IopUnloadDriver('%wZ', %d)\n", DriverServiceName
, UnloadPnpDrivers
);
985 * Get the service name from the registry key name
988 Start
= wcsrchr(DriverServiceName
->Buffer
, L
'\\');
990 Start
= DriverServiceName
->Buffer
;
994 RtlInitUnicodeString(&ServiceName
, Start
);
997 * Construct the driver object name
1000 ObjectName
.Length
= (wcslen(Start
) + 8) * sizeof(WCHAR
);
1001 ObjectName
.MaximumLength
= ObjectName
.Length
+ sizeof(WCHAR
);
1002 ObjectName
.Buffer
= ExAllocatePool(PagedPool
, ObjectName
.MaximumLength
);
1003 wcscpy(ObjectName
.Buffer
, L
"\\Driver\\");
1004 memcpy(ObjectName
.Buffer
+ 8, Start
, ObjectName
.Length
- 8 * sizeof(WCHAR
));
1005 ObjectName
.Buffer
[ObjectName
.Length
/sizeof(WCHAR
)] = 0;
1008 * Find the driver object
1011 Status
= ObReferenceObjectByName(&ObjectName
, 0, 0, 0, IoDriverObjectType
,
1012 KernelMode
, 0, (PVOID
*)&DriverObject
);
1014 if (!NT_SUCCESS(Status
))
1016 DPRINT1("Can't locate driver object for %wZ\n", &ObjectName
);
1021 * Free the buffer for driver object name
1024 ExFreePool(ObjectName
.Buffer
);
1027 * Get path of service...
1030 RtlZeroMemory(QueryTable
, sizeof(QueryTable
));
1032 RtlInitUnicodeString(&ImagePath
, NULL
);
1034 QueryTable
[0].Name
= L
"ImagePath";
1035 QueryTable
[0].Flags
= RTL_QUERY_REGISTRY_DIRECT
;
1036 QueryTable
[0].EntryContext
= &ImagePath
;
1038 Status
= RtlQueryRegistryValues(RTL_REGISTRY_ABSOLUTE
,
1039 DriverServiceName
->Buffer
, QueryTable
, NULL
, NULL
);
1041 if (!NT_SUCCESS(Status
))
1043 DPRINT1("RtlQueryRegistryValues() failed (Status %x)\n", Status
);
1048 * Normalize the image path for all later processing.
1051 Status
= IopNormalizeImagePath(&ImagePath
, &ServiceName
);
1053 if (!NT_SUCCESS(Status
))
1055 DPRINT1("IopNormalizeImagePath() failed (Status %x)\n", Status
);
1060 * Free the service path
1063 ExFreePool(ImagePath
.Buffer
);
1066 * Unload the module and release the references to the device object
1069 /* Call the load/unload routine, depending on current process */
1070 if (DriverObject
->DriverUnload
&& DriverObject
->DriverSection
)
1072 if (PsGetCurrentProcess() == PsInitialSystemProcess
)
1074 /* Just call right away */
1075 (*DriverObject
->DriverUnload
)(DriverObject
);
1079 /* Load/Unload must be called from system process */
1081 /* Prepare parameters block */
1082 LoadParams
.DriverObject
= DriverObject
;
1083 KeInitializeEvent(&LoadParams
.Event
, NotificationEvent
, FALSE
);
1085 ExInitializeWorkItem(&LoadParams
.WorkItem
,
1086 (PWORKER_THREAD_ROUTINE
)IopLoadUnloadDriver
,
1087 (PVOID
)&LoadParams
);
1090 ExQueueWorkItem(&LoadParams
.WorkItem
, DelayedWorkQueue
);
1092 /* And wait when it completes */
1093 KeWaitForSingleObject(&LoadParams
.Event
, UserRequest
, KernelMode
,
1097 /* Unload the driver */
1098 ObDereferenceObject(DriverObject
);
1099 ObDereferenceObject(DriverObject
);
1100 MmUnloadSystemImage(DriverObject
->DriverSection
);
1102 return STATUS_SUCCESS
;
1106 /* Dereference one time (refd inside this function) */
1107 ObDereferenceObject(DriverObject
);
1109 /* Return unloading failure */
1110 return STATUS_INVALID_DEVICE_REQUEST
;
1116 IopReinitializeDrivers(VOID
)
1118 PDRIVER_REINIT_ITEM ReinitItem
;
1121 /* Get the first entry and start looping */
1122 Entry
= ExInterlockedRemoveHeadList(&DriverReinitListHead
,
1123 &DriverReinitListLock
);
1127 ReinitItem
= CONTAINING_RECORD(Entry
, DRIVER_REINIT_ITEM
, ItemEntry
);
1129 /* Increment reinitialization counter */
1130 ReinitItem
->DriverObject
->DriverExtension
->Count
++;
1132 /* Remove the device object flag */
1133 ReinitItem
->DriverObject
->Flags
&= ~DRVO_REINIT_REGISTERED
;
1135 /* Call the routine */
1136 ReinitItem
->ReinitRoutine(ReinitItem
->DriverObject
,
1137 ReinitItem
->Context
,
1138 ReinitItem
->DriverObject
->
1139 DriverExtension
->Count
);
1141 /* Free the entry */
1144 /* Move to the next one */
1145 Entry
= ExInterlockedRemoveHeadList(&DriverReinitListHead
,
1146 &DriverReinitListLock
);
1152 IopReinitializeBootDrivers(VOID
)
1154 PDRIVER_REINIT_ITEM ReinitItem
;
1157 /* Get the first entry and start looping */
1158 Entry
= ExInterlockedRemoveHeadList(&DriverBootReinitListHead
,
1159 &DriverBootReinitListLock
);
1163 ReinitItem
= CONTAINING_RECORD(Entry
, DRIVER_REINIT_ITEM
, ItemEntry
);
1165 /* Increment reinitialization counter */
1166 ReinitItem
->DriverObject
->DriverExtension
->Count
++;
1168 /* Remove the device object flag */
1169 ReinitItem
->DriverObject
->Flags
&= ~DRVO_BOOTREINIT_REGISTERED
;
1171 /* Call the routine */
1172 ReinitItem
->ReinitRoutine(ReinitItem
->DriverObject
,
1173 ReinitItem
->Context
,
1174 ReinitItem
->DriverObject
->
1175 DriverExtension
->Count
);
1177 /* Free the entry */
1180 /* Move to the next one */
1181 Entry
= ExInterlockedRemoveHeadList(&DriverBootReinitListHead
,
1182 &DriverBootReinitListLock
);
1188 IopCreateDriver(IN PUNICODE_STRING DriverName OPTIONAL
,
1189 IN PDRIVER_INITIALIZE InitializationFunction
,
1190 IN PUNICODE_STRING RegistryPath
,
1192 IN ULONG SizeOfImage
,
1193 OUT PDRIVER_OBJECT
*pDriverObject
)
1195 WCHAR NameBuffer
[100];
1197 UNICODE_STRING LocalDriverName
;
1199 OBJECT_ATTRIBUTES ObjectAttributes
;
1201 PDRIVER_OBJECT DriverObject
;
1202 UNICODE_STRING ServiceKeyName
;
1204 ULONG i
, RetryCount
= 0;
1207 /* First, create a unique name for the driver if we don't have one */
1210 /* Create a random name and set up the string*/
1211 NameLength
= (USHORT
)swprintf(NameBuffer
,
1214 LocalDriverName
.Length
= NameLength
* sizeof(WCHAR
);
1215 LocalDriverName
.MaximumLength
= LocalDriverName
.Length
+ sizeof(UNICODE_NULL
);
1216 LocalDriverName
.Buffer
= NameBuffer
;
1220 /* So we can avoid another code path, use a local var */
1221 LocalDriverName
= *DriverName
;
1224 /* Initialize the Attributes */
1225 ObjectSize
= sizeof(DRIVER_OBJECT
) + sizeof(EXTENDED_DRIVER_EXTENSION
);
1226 InitializeObjectAttributes(&ObjectAttributes
,
1228 OBJ_PERMANENT
| OBJ_CASE_INSENSITIVE
,
1232 /* Create the Object */
1233 Status
= ObCreateObject(KernelMode
,
1241 (PVOID
*)&DriverObject
);
1242 if (!NT_SUCCESS(Status
)) return Status
;
1244 DPRINT("IopCreateDriver(): created DO %p\n", DriverObject
);
1246 /* Set up the Object */
1247 RtlZeroMemory(DriverObject
, ObjectSize
);
1248 DriverObject
->Type
= IO_TYPE_DRIVER
;
1249 DriverObject
->Size
= sizeof(DRIVER_OBJECT
);
1250 DriverObject
->Flags
= DRVO_BUILTIN_DRIVER
;
1251 DriverObject
->DriverExtension
= (PDRIVER_EXTENSION
)(DriverObject
+ 1);
1252 DriverObject
->DriverExtension
->DriverObject
= DriverObject
;
1253 DriverObject
->DriverInit
= InitializationFunction
;
1255 /* Loop all Major Functions */
1256 for (i
= 0; i
<= IRP_MJ_MAXIMUM_FUNCTION
; i
++)
1258 /* Invalidate each function */
1259 DriverObject
->MajorFunction
[i
] = IopInvalidDeviceRequest
;
1262 /* Set up the service key name buffer */
1263 ServiceKeyName
.Buffer
= ExAllocatePoolWithTag(PagedPool
,
1264 LocalDriverName
.Length
+
1267 if (!ServiceKeyName
.Buffer
)
1270 ObMakeTemporaryObject(DriverObject
);
1271 ObDereferenceObject(DriverObject
);
1272 return STATUS_INSUFFICIENT_RESOURCES
;
1275 /* Fill out the key data and copy the buffer */
1276 ServiceKeyName
.Length
= LocalDriverName
.Length
;
1277 ServiceKeyName
.MaximumLength
= LocalDriverName
.MaximumLength
;
1278 RtlCopyMemory(ServiceKeyName
.Buffer
,
1279 LocalDriverName
.Buffer
,
1280 LocalDriverName
.Length
);
1282 /* Null-terminate it and set it */
1283 ServiceKeyName
.Buffer
[ServiceKeyName
.Length
/ sizeof(WCHAR
)] = UNICODE_NULL
;
1284 DriverObject
->DriverExtension
->ServiceKeyName
= ServiceKeyName
;
1286 /* Also store it in the Driver Object. This is a bit of a hack. */
1287 RtlCopyMemory(&DriverObject
->DriverName
,
1289 sizeof(UNICODE_STRING
));
1291 /* Add the Object and get its handle */
1292 Status
= ObInsertObject(DriverObject
,
1299 /* Eliminate small possibility when this function is called more than
1300 once in a row, and KeTickCount doesn't get enough time to change */
1301 if (!DriverName
&& (Status
== STATUS_OBJECT_NAME_COLLISION
) && (RetryCount
< 100))
1307 if (!NT_SUCCESS(Status
)) return Status
;
1309 /* Now reference it */
1310 Status
= ObReferenceObjectByHandle(hDriver
,
1314 (PVOID
*)&DriverObject
,
1316 if (!NT_SUCCESS(Status
))
1319 ObMakeTemporaryObject(DriverObject
);
1320 ObDereferenceObject(DriverObject
);
1324 /* Close the extra handle */
1327 DriverObject
->HardwareDatabase
= &IopHardwareDatabaseKey
;
1328 DriverObject
->DriverStart
= DllBase
;
1329 DriverObject
->DriverSize
= SizeOfImage
;
1331 /* Finally, call its init function */
1332 DPRINT("RegistryKey: %wZ\n", RegistryPath
);
1333 DPRINT("Calling driver entrypoint at %p\n", InitializationFunction
);
1334 Status
= (*InitializationFunction
)(DriverObject
, RegistryPath
);
1335 if (!NT_SUCCESS(Status
))
1337 /* If it didn't work, then kill the object */
1338 DPRINT1("'%wZ' initialization failed, status (0x%08lx)\n", DriverName
, Status
);
1339 ObMakeTemporaryObject(DriverObject
);
1340 ObDereferenceObject(DriverObject
);
1344 /* Returns to caller the object */
1345 *pDriverObject
= DriverObject
;
1348 /* Return the Status */
1352 /* PUBLIC FUNCTIONS ***********************************************************/
1359 IoCreateDriver(IN PUNICODE_STRING DriverName OPTIONAL
,
1360 IN PDRIVER_INITIALIZE InitializationFunction
)
1362 PDRIVER_OBJECT DriverObject
;
1363 return IopCreateDriver(DriverName
, InitializationFunction
, NULL
, 0, 0, &DriverObject
);
1371 IoDeleteDriver(IN PDRIVER_OBJECT DriverObject
)
1373 /* Simply dereference the Object */
1374 ObDereferenceObject(DriverObject
);
1382 IoRegisterBootDriverReinitialization(IN PDRIVER_OBJECT DriverObject
,
1383 IN PDRIVER_REINITIALIZE ReinitRoutine
,
1386 PDRIVER_REINIT_ITEM ReinitItem
;
1388 /* Allocate the entry */
1389 ReinitItem
= ExAllocatePoolWithTag(NonPagedPool
,
1390 sizeof(DRIVER_REINIT_ITEM
),
1392 if (!ReinitItem
) return;
1395 ReinitItem
->DriverObject
= DriverObject
;
1396 ReinitItem
->ReinitRoutine
= ReinitRoutine
;
1397 ReinitItem
->Context
= Context
;
1399 /* Set the Driver Object flag and insert the entry into the list */
1400 DriverObject
->Flags
|= DRVO_BOOTREINIT_REGISTERED
;
1401 ExInterlockedInsertTailList(&DriverBootReinitListHead
,
1402 &ReinitItem
->ItemEntry
,
1403 &DriverBootReinitListLock
);
1411 IoRegisterDriverReinitialization(IN PDRIVER_OBJECT DriverObject
,
1412 IN PDRIVER_REINITIALIZE ReinitRoutine
,
1415 PDRIVER_REINIT_ITEM ReinitItem
;
1417 /* Allocate the entry */
1418 ReinitItem
= ExAllocatePoolWithTag(NonPagedPool
,
1419 sizeof(DRIVER_REINIT_ITEM
),
1421 if (!ReinitItem
) return;
1424 ReinitItem
->DriverObject
= DriverObject
;
1425 ReinitItem
->ReinitRoutine
= ReinitRoutine
;
1426 ReinitItem
->Context
= Context
;
1428 /* Set the Driver Object flag and insert the entry into the list */
1429 DriverObject
->Flags
|= DRVO_REINIT_REGISTERED
;
1430 ExInterlockedInsertTailList(&DriverReinitListHead
,
1431 &ReinitItem
->ItemEntry
,
1432 &DriverReinitListLock
);
1440 IoAllocateDriverObjectExtension(IN PDRIVER_OBJECT DriverObject
,
1441 IN PVOID ClientIdentificationAddress
,
1442 IN ULONG DriverObjectExtensionSize
,
1443 OUT PVOID
*DriverObjectExtension
)
1446 PIO_CLIENT_EXTENSION DriverExtensions
, NewDriverExtension
;
1447 BOOLEAN Inserted
= FALSE
;
1449 /* Assume failure */
1450 *DriverObjectExtension
= NULL
;
1452 /* Allocate the extension */
1453 NewDriverExtension
= ExAllocatePoolWithTag(NonPagedPool
,
1454 sizeof(IO_CLIENT_EXTENSION
) +
1455 DriverObjectExtensionSize
,
1456 TAG_DRIVER_EXTENSION
);
1457 if (!NewDriverExtension
) return STATUS_INSUFFICIENT_RESOURCES
;
1459 /* Clear the extension for teh caller */
1460 RtlZeroMemory(NewDriverExtension
,
1461 sizeof(IO_CLIENT_EXTENSION
) + DriverObjectExtensionSize
);
1464 OldIrql
= KeRaiseIrqlToDpcLevel();
1466 /* Fill out the extension */
1467 NewDriverExtension
->ClientIdentificationAddress
= ClientIdentificationAddress
;
1469 /* Loop the current extensions */
1470 DriverExtensions
= IoGetDrvObjExtension(DriverObject
)->
1471 ClientDriverExtension
;
1472 while (DriverExtensions
)
1474 /* Check if the identifier matches */
1475 if (DriverExtensions
->ClientIdentificationAddress
==
1476 ClientIdentificationAddress
)
1478 /* We have a collision, break out */
1482 /* Go to the next one */
1483 DriverExtensions
= DriverExtensions
->NextExtension
;
1486 /* Check if we didn't collide */
1487 if (!DriverExtensions
)
1489 /* Link this one in */
1490 NewDriverExtension
->NextExtension
=
1491 IoGetDrvObjExtension(DriverObject
)->ClientDriverExtension
;
1492 IoGetDrvObjExtension(DriverObject
)->ClientDriverExtension
=
1497 /* Release the lock */
1498 KeLowerIrql(OldIrql
);
1500 /* Check if insertion failed */
1503 /* Free the entry and fail */
1504 ExFreePool(NewDriverExtension
);
1505 return STATUS_OBJECT_NAME_COLLISION
;
1508 /* Otherwise, return the pointer */
1509 *DriverObjectExtension
= NewDriverExtension
+ 1;
1510 return STATUS_SUCCESS
;
1518 IoGetDriverObjectExtension(IN PDRIVER_OBJECT DriverObject
,
1519 IN PVOID ClientIdentificationAddress
)
1522 PIO_CLIENT_EXTENSION DriverExtensions
;
1525 OldIrql
= KeRaiseIrqlToDpcLevel();
1527 /* Loop the list until we find the right one */
1528 DriverExtensions
= IoGetDrvObjExtension(DriverObject
)->ClientDriverExtension
;
1529 while (DriverExtensions
)
1531 /* Check for a match */
1532 if (DriverExtensions
->ClientIdentificationAddress
==
1533 ClientIdentificationAddress
)
1540 DriverExtensions
= DriverExtensions
->NextExtension
;
1544 KeLowerIrql(OldIrql
);
1546 /* Return nothing or the extension */
1547 if (!DriverExtensions
) return NULL
;
1548 return DriverExtensions
+ 1;
1552 IopLoadUnloadDriver(PLOAD_UNLOAD_PARAMS LoadParams
)
1554 RTL_QUERY_REGISTRY_TABLE QueryTable
[3];
1555 UNICODE_STRING ImagePath
;
1556 UNICODE_STRING ServiceName
;
1559 PDEVICE_NODE DeviceNode
;
1560 PDRIVER_OBJECT DriverObject
;
1561 PLDR_DATA_TABLE_ENTRY ModuleObject
;
1564 /* Check if it's an unload request */
1565 if (LoadParams
->DriverObject
)
1567 (*LoadParams
->DriverObject
->DriverUnload
)(LoadParams
->DriverObject
);
1569 /* Return success and signal the event */
1570 LoadParams
->Status
= STATUS_SUCCESS
;
1571 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1575 RtlInitUnicodeString(&ImagePath
, NULL
);
1578 * Get the service name from the registry key name.
1580 ASSERT(LoadParams
->ServiceName
->Length
>= sizeof(WCHAR
));
1582 ServiceName
= *LoadParams
->ServiceName
;
1583 cur
= LoadParams
->ServiceName
->Buffer
+
1584 (LoadParams
->ServiceName
->Length
/ sizeof(WCHAR
)) - 1;
1585 while (LoadParams
->ServiceName
->Buffer
!= cur
)
1589 ServiceName
.Buffer
= cur
+ 1;
1590 ServiceName
.Length
= LoadParams
->ServiceName
->Length
-
1591 (USHORT
)((ULONG_PTR
)ServiceName
.Buffer
-
1592 (ULONG_PTR
)LoadParams
->ServiceName
->Buffer
);
1602 RtlZeroMemory(&QueryTable
, sizeof(QueryTable
));
1604 RtlInitUnicodeString(&ImagePath
, NULL
);
1606 QueryTable
[0].Name
= L
"Type";
1607 QueryTable
[0].Flags
= RTL_QUERY_REGISTRY_DIRECT
| RTL_QUERY_REGISTRY_REQUIRED
;
1608 QueryTable
[0].EntryContext
= &Type
;
1610 QueryTable
[1].Name
= L
"ImagePath";
1611 QueryTable
[1].Flags
= RTL_QUERY_REGISTRY_DIRECT
;
1612 QueryTable
[1].EntryContext
= &ImagePath
;
1614 Status
= RtlQueryRegistryValues(RTL_REGISTRY_ABSOLUTE
,
1615 LoadParams
->ServiceName
->Buffer
, QueryTable
, NULL
, NULL
);
1617 if (!NT_SUCCESS(Status
))
1619 DPRINT("RtlQueryRegistryValues() failed (Status %lx)\n", Status
);
1620 ExFreePool(ImagePath
.Buffer
);
1621 LoadParams
->Status
= Status
;
1622 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1627 * Normalize the image path for all later processing.
1630 Status
= IopNormalizeImagePath(&ImagePath
, &ServiceName
);
1632 if (!NT_SUCCESS(Status
))
1634 DPRINT("IopNormalizeImagePath() failed (Status %x)\n", Status
);
1635 LoadParams
->Status
= Status
;
1636 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1640 DPRINT("FullImagePath: '%wZ'\n", &ImagePath
);
1641 DPRINT("Type: %lx\n", Type
);
1644 * Create device node
1647 /* Use IopRootDeviceNode for now */
1648 Status
= IopCreateDeviceNode(IopRootDeviceNode
, NULL
, &ServiceName
, &DeviceNode
);
1650 if (!NT_SUCCESS(Status
))
1652 DPRINT("IopCreateDeviceNode() failed (Status %lx)\n", Status
);
1653 LoadParams
->Status
= Status
;
1654 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1658 /* Get existing DriverObject pointer (in case the driver has
1659 already been loaded and initialized) */
1660 Status
= IopGetDriverObject(
1663 (Type
== 2 /* SERVICE_FILE_SYSTEM_DRIVER */ ||
1664 Type
== 8 /* SERVICE_RECOGNIZER_DRIVER */));
1666 if (!NT_SUCCESS(Status
))
1669 * Load the driver module
1672 Status
= MmLoadSystemImage(&ImagePath
, NULL
, NULL
, 0, (PVOID
)&ModuleObject
, NULL
);
1673 if (!NT_SUCCESS(Status
) && Status
!= STATUS_IMAGE_ALREADY_LOADED
)
1675 DPRINT("MmLoadSystemImage() failed (Status %lx)\n", Status
);
1676 IopFreeDeviceNode(DeviceNode
);
1677 LoadParams
->Status
= Status
;
1678 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1683 * Set a service name for the device node
1686 RtlCreateUnicodeString(&DeviceNode
->ServiceName
, ServiceName
.Buffer
);
1689 * Initialize the driver module if it's loaded for the first time
1691 if (Status
!= STATUS_IMAGE_ALREADY_LOADED
)
1693 Status
= IopInitializeDriverModule(
1696 &DeviceNode
->ServiceName
,
1697 (Type
== 2 /* SERVICE_FILE_SYSTEM_DRIVER */ ||
1698 Type
== 8 /* SERVICE_RECOGNIZER_DRIVER */),
1701 if (!NT_SUCCESS(Status
))
1703 DPRINT("IopInitializeDriver() failed (Status %lx)\n", Status
);
1704 MmUnloadSystemImage(ModuleObject
);
1705 IopFreeDeviceNode(DeviceNode
);
1706 LoadParams
->Status
= Status
;
1707 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1712 /* Store its DriverSection, so that it could be unloaded */
1713 DriverObject
->DriverSection
= ModuleObject
;
1716 IopInitializeDevice(DeviceNode
, DriverObject
);
1717 LoadParams
->Status
= IopStartDevice(DeviceNode
);
1718 (VOID
)KeSetEvent(&LoadParams
->Event
, 0, FALSE
);
1724 * Loads a device driver.
1728 * Name of the service to load (registry key).
1737 NtLoadDriver(IN PUNICODE_STRING DriverServiceName
)
1739 UNICODE_STRING CapturedDriverServiceName
= {0};
1740 KPROCESSOR_MODE PreviousMode
;
1741 LOAD_UNLOAD_PARAMS LoadParams
;
1746 PreviousMode
= KeGetPreviousMode();
1749 * Check security privileges
1752 /* FIXME: Uncomment when privileges will be correctly implemented. */
1754 if (!SeSinglePrivilegeCheck(SeLoadDriverPrivilege
, PreviousMode
))
1756 DPRINT("Privilege not held\n");
1757 return STATUS_PRIVILEGE_NOT_HELD
;
1761 Status
= ProbeAndCaptureUnicodeString(&CapturedDriverServiceName
,
1764 if (!NT_SUCCESS(Status
))
1769 DPRINT("NtLoadDriver('%wZ')\n", &CapturedDriverServiceName
);
1771 LoadParams
.ServiceName
= &CapturedDriverServiceName
;
1772 LoadParams
.DriverObject
= NULL
;
1773 KeInitializeEvent(&LoadParams
.Event
, NotificationEvent
, FALSE
);
1775 /* Call the load/unload routine, depending on current process */
1776 if (PsGetCurrentProcess() == PsInitialSystemProcess
)
1778 /* Just call right away */
1779 IopLoadUnloadDriver(&LoadParams
);
1783 /* Load/Unload must be called from system process */
1784 ExInitializeWorkItem(&LoadParams
.WorkItem
,
1785 (PWORKER_THREAD_ROUTINE
)IopLoadUnloadDriver
,
1786 (PVOID
)&LoadParams
);
1789 ExQueueWorkItem(&LoadParams
.WorkItem
, DelayedWorkQueue
);
1791 /* And wait when it completes */
1792 KeWaitForSingleObject(&LoadParams
.Event
, UserRequest
, KernelMode
,
1796 ReleaseCapturedUnicodeString(&CapturedDriverServiceName
,
1799 return LoadParams
.Status
;
1805 * Unloads a legacy device driver.
1809 * Name of the service to unload (registry key).
1819 NtUnloadDriver(IN PUNICODE_STRING DriverServiceName
)
1821 return IopUnloadDriver(DriverServiceName
, FALSE
);