2 * COPYRIGHT: See COPYING in the top level directory
3 * PROJECT: ReactOS kernel
4 * FILE: ntoskrnl/ke/process.c
5 * PURPOSE: Attaching/Detaching and System Call Tables
7 * PROGRAMMERS: Alex Ionescu (Implemented Attach/Detach and KeRemoveSystemServiceTable)
8 * Gregor Anich (Bugfixes to Attach Functions)
11 /* INCLUDES *****************************************************************/
14 #include <internal/napi.h>
16 #include <internal/debug.h>
18 /* GLOBALS *****************************************************************/
20 KSERVICE_TABLE_DESCRIPTOR
22 KeServiceDescriptorTable
[SSDT_MAX_ENTRIES
] = {
23 { MainSSDT
, NULL
, NUMBER_OF_SYSCALLS
, MainSSPT
},
24 { NULL
, NULL
, 0, NULL
},
25 { NULL
, NULL
, 0, NULL
},
26 { NULL
, NULL
, 0, NULL
}
29 KSERVICE_TABLE_DESCRIPTOR
30 KeServiceDescriptorTableShadow
[SSDT_MAX_ENTRIES
] = {
31 { MainSSDT
, NULL
, NUMBER_OF_SYSCALLS
, MainSSPT
},
32 { NULL
, NULL
, 0, NULL
},
33 { NULL
, NULL
, 0, NULL
},
34 { NULL
, NULL
, 0, NULL
}
37 /* FUNCTIONS *****************************************************************/
40 UpdatePageDirs(PKTHREAD Thread
, PKPROCESS Process
)
43 * The stack and the thread structure of the current process may be
44 * located in a page which is not present in the page directory of
45 * the process we're attaching to. That would lead to a page fault
46 * when this function returns. However, since the processor can't
47 * call the page fault handler 'cause it can't push EIP on the stack,
48 * this will show up as a stack fault which will crash the entire system.
49 * To prevent this, make sure the page directory of the process we're
50 * attaching to is up-to-date.
52 MmUpdatePageDir((PEPROCESS
)Process
, (PVOID
)Thread
->StackLimit
, MM_STACK_SIZE
);
53 MmUpdatePageDir((PEPROCESS
)Process
, (PVOID
)Thread
, sizeof(ETHREAD
));
57 * FUNCTION: Returns a pointer to the current process
61 KeGetCurrentProcess(VOID
)
63 return(&(PsGetCurrentProcess()->Pcb
));
68 KeInitializeProcess(PKPROCESS Process
,
71 LARGE_INTEGER DirectoryTableBase
)
73 DPRINT("KeInitializeProcess. Process: %x, DirectoryTableBase: %x\n", Process
, DirectoryTableBase
);
75 /* Initialize the Dispatcher Header */
76 KeInitializeDispatcherHeader(&Process
->Header
,
81 /* Initialize Scheduler Data, Disable Alignment Faults and Set the PDE */
82 Process
->Affinity
= Affinity
;
83 Process
->BasePriority
= Priority
;
84 Process
->QuantumReset
= 6;
85 Process
->DirectoryTableBase
= DirectoryTableBase
;
86 Process
->AutoAlignment
= TRUE
;
87 Process
->IopmOffset
= 0xFFFF;
88 Process
->State
= ProcessInMemory
;
90 /* Initialize the Thread List */
91 InitializeListHead(&Process
->ThreadListHead
);
92 KeInitializeSpinLock(&Process
->ProcessLock
);
93 DPRINT("The Process has now been initalized with the Kernel\n");
98 KeSetProcess(PKPROCESS Process
,
104 /* Lock Dispatcher */
105 OldIrql
= KeAcquireDispatcherDatabaseLock();
108 OldState
= Process
->Header
.SignalState
;
110 /* Signal the Process */
111 Process
->Header
.SignalState
= TRUE
;
112 if ((OldState
== 0) && IsListEmpty(&Process
->Header
.WaitListHead
) != TRUE
) {
115 KiWaitTest((PVOID
)Process
, Increment
);
118 /* Release Dispatcher Database */
119 KeReleaseDispatcherDatabaseLock(OldIrql
);
121 /* Return the previous State */
130 KeAttachProcess(PKPROCESS Process
)
133 PKTHREAD Thread
= KeGetCurrentThread();
135 DPRINT("KeAttachProcess: %x\n", Process
);
137 /* Make sure that we are in the right page directory */
138 UpdatePageDirs(Thread
, Process
);
140 /* Lock Dispatcher */
141 OldIrql
= KeAcquireDispatcherDatabaseLock();
142 KeAcquireSpinLockAtDpcLevel(&Thread
->ApcQueueLock
);
144 /* Crash system if DPC is being executed! */
145 if (KeIsExecutingDpc()) {
147 DPRINT1("Invalid attach (Thread is executing a DPC!)\n");
148 KEBUGCHECK(INVALID_PROCESS_ATTACH_ATTEMPT
);
151 /* Check if the Target Process is already attached */
152 if (Thread
->ApcState
.Process
== Process
|| Thread
->ApcStateIndex
!= OriginalApcEnvironment
) {
154 DPRINT("Process already Attached. Exitting\n");
155 KeReleaseSpinLockFromDpcLevel(&Thread
->ApcQueueLock
);
156 KeReleaseDispatcherDatabaseLock(OldIrql
);
159 KiAttachProcess(Thread
, Process
, OldIrql
, &Thread
->SavedApcState
);
165 KiAttachProcess(PKTHREAD Thread
, PKPROCESS Process
, KIRQL ApcLock
, PRKAPC_STATE SavedApcState
)
168 DPRINT("KiAttachProcess(Thread: %x, Process: %x, SavedApcState: %x\n", Thread
, Process
, SavedApcState
);
170 /* Increase Stack Count */
171 Process
->StackCount
++;
173 /* Swap the APC Environment */
174 KiMoveApcState(&Thread
->ApcState
, SavedApcState
);
176 /* Reinitialize Apc State */
177 InitializeListHead(&Thread
->ApcState
.ApcListHead
[KernelMode
]);
178 InitializeListHead(&Thread
->ApcState
.ApcListHead
[UserMode
]);
179 Thread
->ApcState
.Process
= Process
;
180 Thread
->ApcState
.KernelApcInProgress
= FALSE
;
181 Thread
->ApcState
.KernelApcPending
= FALSE
;
182 Thread
->ApcState
.UserApcPending
= FALSE
;
184 /* Update Environment Pointers if needed*/
185 if (SavedApcState
== &Thread
->SavedApcState
) {
187 Thread
->ApcStatePointer
[OriginalApcEnvironment
] = &Thread
->SavedApcState
;
188 Thread
->ApcStatePointer
[AttachedApcEnvironment
] = &Thread
->ApcState
;
189 Thread
->ApcStateIndex
= AttachedApcEnvironment
;
192 /* Swap the Processes */
193 DPRINT("Swapping\n");
194 KiSwapProcess(Process
, SavedApcState
->Process
);
196 /* Return to old IRQL*/
197 KeReleaseSpinLockFromDpcLevel(&Thread
->ApcQueueLock
);
198 KeReleaseDispatcherDatabaseLock(ApcLock
);
200 DPRINT("KiAttachProcess Completed Sucesfully\n");
205 KiSwapProcess(PKPROCESS NewProcess
,
206 PKPROCESS OldProcess
)
208 DPRINT("Switching CR3 to: %x\n", NewProcess
->DirectoryTableBase
.u
.LowPart
);
209 Ke386SetPageTableDirectory(NewProcess
->DirectoryTableBase
.u
.LowPart
);
217 KeIsAttachedProcess(VOID
)
219 /* Return the APC State */
220 return KeGetCurrentThread()->ApcStateIndex
;
228 KeStackAttachProcess(IN PKPROCESS Process
,
229 OUT PRKAPC_STATE ApcState
)
232 PKTHREAD Thread
= KeGetCurrentThread();
234 /* Make sure that we are in the right page directory */
235 UpdatePageDirs(Thread
, Process
);
237 OldIrql
= KeAcquireDispatcherDatabaseLock();
238 KeAcquireSpinLockAtDpcLevel(&Thread
->ApcQueueLock
);
240 /* Crash system if DPC is being executed! */
241 if (KeIsExecutingDpc()) {
243 DPRINT1("Invalid attach (Thread is executing a DPC!)\n");
244 KEBUGCHECK(INVALID_PROCESS_ATTACH_ATTEMPT
);
247 /* Check if the Target Process is already attached */
248 if (Thread
->ApcState
.Process
== Process
) {
250 ApcState
->Process
= (PKPROCESS
)1; /* Meaning already attached to the same Process */
254 /* Check if the Current Thread is already attached and call the Internal Function*/
255 if (Thread
->ApcStateIndex
!= OriginalApcEnvironment
) {
257 KiAttachProcess(Thread
, Process
, OldIrql
, ApcState
);
260 KiAttachProcess(Thread
, Process
, OldIrql
, &Thread
->SavedApcState
);
261 ApcState
->Process
= NULL
;
270 KeDetachProcess (VOID
)
275 DPRINT("KeDetachProcess()\n");
277 /* Get Current Thread and Lock */
278 Thread
= KeGetCurrentThread();
279 OldIrql
= KeAcquireDispatcherDatabaseLock();
280 KeAcquireSpinLockAtDpcLevel(&Thread
->ApcQueueLock
);
282 /* Check if it's attached */
283 DPRINT("Current ApcStateIndex: %x\n", Thread
->ApcStateIndex
);
285 if (Thread
->ApcStateIndex
== OriginalApcEnvironment
) {
287 DPRINT1("Invalid detach (thread was not attached)\n");
288 KEBUGCHECK(INVALID_PROCESS_DETACH_ATTEMPT
);
291 /* Decrease Stack Count */
292 Thread
->ApcState
.Process
->StackCount
--;
294 /* Restore the APC State */
295 KiMoveApcState(&Thread
->SavedApcState
, &Thread
->ApcState
);
296 Thread
->SavedApcState
.Process
= NULL
;
297 Thread
->ApcStatePointer
[OriginalApcEnvironment
] = &Thread
->ApcState
;
298 Thread
->ApcStatePointer
[AttachedApcEnvironment
] = &Thread
->SavedApcState
;
299 Thread
->ApcStateIndex
= OriginalApcEnvironment
;
302 KiSwapProcess(Thread
->ApcState
.Process
, Thread
->ApcState
.Process
);
304 /* Unlock Dispatcher */
305 KeReleaseSpinLockFromDpcLevel(&Thread
->ApcQueueLock
);
306 KeReleaseDispatcherDatabaseLock(OldIrql
);
314 KeUnstackDetachProcess (
315 IN PRKAPC_STATE ApcState
322 * If the special "We tried to attach to the process already being
323 * attached to" flag is there, don't do anything
325 if (ApcState
->Process
== (PKPROCESS
)1) return;
327 Thread
= KeGetCurrentThread();
328 OldIrql
= KeAcquireDispatcherDatabaseLock();
329 KeAcquireSpinLockAtDpcLevel(&Thread
->ApcQueueLock
);
331 /* Sorry Buddy, can't help you if you've got APCs or just aren't attached */
332 if ((Thread
->ApcStateIndex
== OriginalApcEnvironment
) || (Thread
->ApcState
.KernelApcInProgress
)) {
334 DPRINT1("Invalid detach (Thread not Attached, or Kernel APC in Progress!)\n");
335 KEBUGCHECK(INVALID_PROCESS_DETACH_ATTEMPT
);
338 /* Restore the Old APC State if a Process was present */
339 if (ApcState
->Process
) {
341 KiMoveApcState(ApcState
, &Thread
->ApcState
);
345 /* The ApcState parameter is useless, so use the saved data and reset it */
346 KiMoveApcState(&Thread
->SavedApcState
, &Thread
->ApcState
);
347 Thread
->SavedApcState
.Process
= NULL
;
348 Thread
->ApcStateIndex
= OriginalApcEnvironment
;
349 Thread
->ApcStatePointer
[OriginalApcEnvironment
] = &Thread
->ApcState
;
350 Thread
->ApcStatePointer
[AttachedApcEnvironment
] = &Thread
->SavedApcState
;
354 KiSwapProcess(Thread
->ApcState
.Process
, Thread
->ApcState
.Process
);
356 /* Return to old IRQL*/
357 KeReleaseSpinLockFromDpcLevel(&Thread
->ApcQueueLock
);
358 KeReleaseDispatcherDatabaseLock(OldIrql
);
366 KeAddSystemServiceTable(PULONG_PTR Base
,
367 PULONG Count OPTIONAL
,
372 /* Check if descriptor table entry is free */
373 if ((Index
> SSDT_MAX_ENTRIES
- 1) ||
374 (KeServiceDescriptorTable
[Index
].Base
) ||
375 (KeServiceDescriptorTableShadow
[Index
].Base
))
380 /* Initialize the shadow service descriptor table */
381 KeServiceDescriptorTableShadow
[Index
].Base
= Base
;
382 KeServiceDescriptorTableShadow
[Index
].Limit
= Limit
;
383 KeServiceDescriptorTableShadow
[Index
].Number
= Number
;
384 KeServiceDescriptorTableShadow
[Index
].Count
= Count
;
394 KeRemoveSystemServiceTable(IN ULONG Index
)
396 /* Make sure the Index is valid */
397 if (Index
> SSDT_MAX_ENTRIES
- 1) return FALSE
;
399 /* Is there a Normal Descriptor Table? */
400 if (!KeServiceDescriptorTable
[Index
].Base
)
402 /* Not with the index, is there a shadow at least? */
403 if (!KeServiceDescriptorTableShadow
[Index
].Base
) return FALSE
;
406 /* Now clear from the Shadow Table. */
407 KeServiceDescriptorTableShadow
[Index
].Base
= NULL
;
408 KeServiceDescriptorTableShadow
[Index
].Number
= NULL
;
409 KeServiceDescriptorTableShadow
[Index
].Limit
= 0;
410 KeServiceDescriptorTableShadow
[Index
].Count
= NULL
;
412 /* Check if we should clean from the Master one too */
415 KeServiceDescriptorTable
[Index
].Base
= NULL
;
416 KeServiceDescriptorTable
[Index
].Number
= NULL
;
417 KeServiceDescriptorTable
[Index
].Limit
= 0;
418 KeServiceDescriptorTable
[Index
].Count
= NULL
;