2 * COPYRIGHT: See COPYING in the top level directory
3 * PROJECT: ReactOS kernel
4 * FILE: ntoskrnl/ke/process.c
5 * PURPOSE: Attaching/Detaching and System Call Tables
7 * PROGRAMMERS: Alex Ionescu (Implemented Attach/Detach and KeRemoveSystemServiceTable)
8 * Gregor Anich (Bugfixes to Attach Functions)
11 /* INCLUDES *****************************************************************/
14 #include <ntdll/napi.h>
16 #include <internal/debug.h>
18 /* GLOBALS *****************************************************************/
22 KeServiceDescriptorTable
[SSDT_MAX_ENTRIES
] = {
23 { MainSSDT
, NULL
, NUMBER_OF_SYSCALLS
, MainSSPT
},
24 { NULL
, NULL
, 0, NULL
},
25 { NULL
, NULL
, 0, NULL
},
26 { NULL
, NULL
, 0, NULL
}
30 KeServiceDescriptorTableShadow
[SSDT_MAX_ENTRIES
] = {
31 { MainSSDT
, NULL
, NUMBER_OF_SYSCALLS
, MainSSPT
},
32 { NULL
, NULL
, 0, NULL
},
33 { NULL
, NULL
, 0, NULL
},
34 { NULL
, NULL
, 0, NULL
}
37 /* FUNCTIONS *****************************************************************/
40 UpdatePageDirs(PKTHREAD Thread
, PKPROCESS Process
)
43 * The stack and the thread structure of the current process may be
44 * located in a page which is not present in the page directory of
45 * the process we're attaching to. That would lead to a page fault
46 * when this function returns. However, since the processor can't
47 * call the page fault handler 'cause it can't push EIP on the stack,
48 * this will show up as a stack fault which will crash the entire system.
49 * To prevent this, make sure the page directory of the process we're
50 * attaching to is up-to-date.
52 MmUpdatePageDir((PEPROCESS
)Process
, (PVOID
)Thread
->StackLimit
, MM_STACK_SIZE
);
53 MmUpdatePageDir((PEPROCESS
)Process
, (PVOID
)Thread
, sizeof(ETHREAD
));
57 * FUNCTION: Returns a pointer to the current process
61 KeGetCurrentProcess(VOID
)
63 return(&(PsGetCurrentProcess()->Pcb
));
68 KeInitializeProcess(PKPROCESS Process
,
71 LARGE_INTEGER DirectoryTableBase
)
73 DPRINT("KeInitializeProcess. Process: %x, DirectoryTableBase: %x\n", Process
, DirectoryTableBase
);
75 /* Initialize the Dispatcher Header */
76 KeInitializeDispatcherHeader(&Process
->DispatcherHeader
,
81 /* Initialize Scheduler Data, Disable Alignment Faults and Set the PDE */
82 Process
->Affinity
= Affinity
;
83 Process
->BasePriority
= Priority
;
84 Process
->ThreadQuantum
= 6;
85 Process
->DirectoryTableBase
= DirectoryTableBase
;
86 Process
->AutoAlignment
= TRUE
;
87 Process
->IopmOffset
= 0xFFFF;
88 Process
->State
= PROCESS_STATE_ACTIVE
;
90 /* Initialize the Thread List */
91 InitializeListHead(&Process
->ThreadListHead
);
92 DPRINT("The Process has now been initalized with the Kernel\n");
97 KeSetProcess(PKPROCESS Process
,
103 /* Lock Dispatcher */
104 OldIrql
= KeAcquireDispatcherDatabaseLock();
107 OldState
= Process
->DispatcherHeader
.SignalState
;
109 /* Signal the Process */
110 Process
->DispatcherHeader
.SignalState
= TRUE
;
111 if ((OldState
== 0) && IsListEmpty(&Process
->DispatcherHeader
.WaitListHead
) != TRUE
) {
114 KiWaitTest((PVOID
)Process
, Increment
);
117 /* Release Dispatcher Database */
118 KeReleaseDispatcherDatabaseLock(OldIrql
);
120 /* Return the previous State */
129 KeAttachProcess(PKPROCESS Process
)
132 PKTHREAD Thread
= KeGetCurrentThread();
134 DPRINT("KeAttachProcess: %x\n", Process
);
136 /* Make sure that we are in the right page directory */
137 UpdatePageDirs(Thread
, Process
);
139 /* Lock Dispatcher */
140 OldIrql
= KeAcquireDispatcherDatabaseLock();
142 /* Crash system if DPC is being executed! */
143 if (KeIsExecutingDpc()) {
145 DPRINT1("Invalid attach (Thread is executing a DPC!)\n");
146 KEBUGCHECK(INVALID_PROCESS_ATTACH_ATTEMPT
);
149 /* Check if the Target Process is already attached */
150 if (Thread
->ApcState
.Process
== Process
|| Thread
->ApcStateIndex
!= OriginalApcEnvironment
) {
152 DPRINT("Process already Attached. Exitting\n");
153 KeReleaseDispatcherDatabaseLock(OldIrql
);
156 KiAttachProcess(Thread
, Process
, OldIrql
, &Thread
->SavedApcState
);
162 KiAttachProcess(PKTHREAD Thread
, PKPROCESS Process
, KIRQL ApcLock
, PRKAPC_STATE SavedApcState
)
165 DPRINT("KiAttachProcess(Thread: %x, Process: %x, SavedApcState: %x\n", Thread
, Process
, SavedApcState
);
167 /* Increase Stack Count */
168 Process
->StackCount
++;
170 /* Swap the APC Environment */
171 KiMoveApcState(&Thread
->ApcState
, SavedApcState
);
173 /* Reinitialize Apc State */
174 InitializeListHead(&Thread
->ApcState
.ApcListHead
[KernelMode
]);
175 InitializeListHead(&Thread
->ApcState
.ApcListHead
[UserMode
]);
176 Thread
->ApcState
.Process
= Process
;
177 Thread
->ApcState
.KernelApcInProgress
= FALSE
;
178 Thread
->ApcState
.KernelApcPending
= FALSE
;
179 Thread
->ApcState
.UserApcPending
= FALSE
;
181 /* Update Environment Pointers if needed*/
182 if (SavedApcState
== &Thread
->SavedApcState
) {
184 Thread
->ApcStatePointer
[OriginalApcEnvironment
] = &Thread
->SavedApcState
;
185 Thread
->ApcStatePointer
[AttachedApcEnvironment
] = &Thread
->ApcState
;
186 Thread
->ApcStateIndex
= AttachedApcEnvironment
;
189 /* Swap the Processes */
190 DPRINT("Swapping\n");
191 KiSwapProcess(Process
, SavedApcState
->Process
);
193 /* Return to old IRQL*/
194 KeReleaseDispatcherDatabaseLock(ApcLock
);
196 DPRINT("KiAttachProcess Completed Sucesfully\n");
201 KiSwapProcess(PKPROCESS NewProcess
, PKPROCESS OldProcess
)
203 //PKPCR Pcr = KeGetCurrentKpcr();
205 /* Do they have an LDT? */
206 if ((NewProcess
->LdtDescriptor
) || (OldProcess
->LdtDescriptor
)) {
208 /* FIXME : SWitch GDT/IDT */
210 DPRINT("Switching CR3 to: %x\n", NewProcess
->DirectoryTableBase
.u
.LowPart
);
211 Ke386SetPageTableDirectory(NewProcess
->DirectoryTableBase
.u
.LowPart
);
213 /* FIXME: Set IopmOffset in TSS */
221 KeIsAttachedProcess(VOID
)
223 /* Return the APC State */
224 return KeGetCurrentThread()->ApcStateIndex
;
232 KeStackAttachProcess(IN PKPROCESS Process
,
233 OUT PRKAPC_STATE ApcState
)
236 PKTHREAD Thread
= KeGetCurrentThread();
238 /* Make sure that we are in the right page directory */
239 UpdatePageDirs(Thread
, Process
);
241 OldIrql
= KeAcquireDispatcherDatabaseLock();
243 /* Crash system if DPC is being executed! */
244 if (KeIsExecutingDpc()) {
246 DPRINT1("Invalid attach (Thread is executing a DPC!)\n");
247 KEBUGCHECK(INVALID_PROCESS_ATTACH_ATTEMPT
);
250 /* Check if the Target Process is already attached */
251 if (Thread
->ApcState
.Process
== Process
) {
253 ApcState
->Process
= (PKPROCESS
)1; /* Meaning already attached to the same Process */
257 /* Check if the Current Thread is already attached and call the Internal Function*/
258 if (Thread
->ApcStateIndex
!= OriginalApcEnvironment
) {
260 KiAttachProcess(Thread
, Process
, OldIrql
, ApcState
);
263 KiAttachProcess(Thread
, Process
, OldIrql
, &Thread
->SavedApcState
);
264 ApcState
->Process
= NULL
;
273 KeDetachProcess (VOID
)
278 DPRINT("KeDetachProcess()\n");
280 /* Get Current Thread and Lock */
281 Thread
= KeGetCurrentThread();
282 OldIrql
= KeAcquireDispatcherDatabaseLock();
284 /* Check if it's attached */
285 DPRINT("Current ApcStateIndex: %x\n", Thread
->ApcStateIndex
);
287 if (Thread
->ApcStateIndex
== OriginalApcEnvironment
) {
289 DPRINT1("Invalid detach (thread was not attached)\n");
290 KEBUGCHECK(INVALID_PROCESS_DETACH_ATTEMPT
);
293 /* Decrease Stack Count */
294 Thread
->ApcState
.Process
->StackCount
--;
296 /* Restore the APC State */
297 KiMoveApcState(&Thread
->SavedApcState
, &Thread
->ApcState
);
298 Thread
->SavedApcState
.Process
= NULL
;
299 Thread
->ApcStatePointer
[OriginalApcEnvironment
] = &Thread
->ApcState
;
300 Thread
->ApcStatePointer
[AttachedApcEnvironment
] = &Thread
->SavedApcState
;
301 Thread
->ApcStateIndex
= OriginalApcEnvironment
;
304 KiSwapProcess(Thread
->ApcState
.Process
, Thread
->ApcState
.Process
);
306 /* Unlock Dispatcher */
307 KeReleaseDispatcherDatabaseLock(OldIrql
);
315 KeUnstackDetachProcess (
316 IN PRKAPC_STATE ApcState
323 * If the special "We tried to attach to the process already being
324 * attached to" flag is there, don't do anything
326 if (ApcState
->Process
== (PKPROCESS
)1) return;
328 Thread
= KeGetCurrentThread();
329 OldIrql
= KeAcquireDispatcherDatabaseLock();
331 /* Sorry Buddy, can't help you if you've got APCs or just aren't attached */
332 if ((Thread
->ApcStateIndex
== OriginalApcEnvironment
) || (Thread
->ApcState
.KernelApcInProgress
)) {
334 DPRINT1("Invalid detach (Thread not Attached, or Kernel APC in Progress!)\n");
335 KEBUGCHECK(INVALID_PROCESS_DETACH_ATTEMPT
);
338 /* Restore the Old APC State if a Process was present */
339 if (ApcState
->Process
) {
341 KiMoveApcState(ApcState
, &Thread
->ApcState
);
345 /* The ApcState parameter is useless, so use the saved data and reset it */
346 KiMoveApcState(&Thread
->SavedApcState
, &Thread
->ApcState
);
347 Thread
->SavedApcState
.Process
= NULL
;
348 Thread
->ApcStateIndex
= OriginalApcEnvironment
;
349 Thread
->ApcStatePointer
[OriginalApcEnvironment
] = &Thread
->ApcState
;
350 Thread
->ApcStatePointer
[AttachedApcEnvironment
] = &Thread
->SavedApcState
;
354 KiSwapProcess(Thread
->ApcState
.Process
, Thread
->ApcState
.Process
);
356 /* Return to old IRQL*/
357 KeReleaseDispatcherDatabaseLock(OldIrql
);
364 KeAddSystemServiceTable(PSSDT SSDT
,
365 PULONG ServiceCounterTable
,
366 ULONG NumberOfServices
,
370 /* check if descriptor table entry is free */
371 if ((TableIndex
> SSDT_MAX_ENTRIES
- 1) ||
372 (KeServiceDescriptorTable
[TableIndex
].SSDT
!= NULL
) ||
373 (KeServiceDescriptorTableShadow
[TableIndex
].SSDT
!= NULL
))
376 /* initialize the shadow service descriptor table */
377 KeServiceDescriptorTableShadow
[TableIndex
].SSDT
= SSDT
;
378 KeServiceDescriptorTableShadow
[TableIndex
].SSPT
= SSPT
;
379 KeServiceDescriptorTableShadow
[TableIndex
].NumberOfServices
= NumberOfServices
;
380 KeServiceDescriptorTableShadow
[TableIndex
].ServiceCounterTable
= ServiceCounterTable
;
390 KeRemoveSystemServiceTable(IN ULONG TableIndex
)
392 /* Make sure the Index is valid */
393 if (TableIndex
> SSDT_MAX_ENTRIES
- 1) return FALSE
;
395 /* Is there a Normal Descriptor Table? */
396 if (!KeServiceDescriptorTable
[TableIndex
].SSDT
) {
398 /* Not with the index, is there a shadow at least? */
399 if (!KeServiceDescriptorTableShadow
[TableIndex
].SSDT
) return FALSE
;
402 /* Now clear from the Shadow Table. */
403 KeServiceDescriptorTableShadow
[TableIndex
].SSDT
= NULL
;
404 KeServiceDescriptorTableShadow
[TableIndex
].SSPT
= NULL
;
405 KeServiceDescriptorTableShadow
[TableIndex
].NumberOfServices
= 0;
406 KeServiceDescriptorTableShadow
[TableIndex
].ServiceCounterTable
= NULL
;
408 /* Check if we should clean from the Master one too */
409 if (TableIndex
== 1) {
411 KeServiceDescriptorTable
[TableIndex
].SSDT
= NULL
;
412 KeServiceDescriptorTable
[TableIndex
].SSPT
= NULL
;
413 KeServiceDescriptorTable
[TableIndex
].NumberOfServices
= 0;
414 KeServiceDescriptorTable
[TableIndex
].ServiceCounterTable
= NULL
;