1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
|
/********************************************************/
/* ntapi: Native API core library */
/* Copyright (C) 2013--2016 Z. Gilboa */
/* Released under GPLv2 and GPLv3; see COPYING.NTAPI. */
/********************************************************/
#include <ntapi/ntapi.h>
#include <ntapi/nt_file.h>
#include <ntapi/nt_fsctl.h>
#include <ntapi/nt_mount.h>
#include <ntapi/nt_istat.h>
#include "ntapi_impl.h"
int32_t __stdcall __ntapi_tt_istat(
__in void * hfile,
__in void * hroot __optional,
__in nt_unicode_string * path,
__out nt_istat * istat,
__out uintptr_t * buffer,
__in uint32_t buffer_size,
__in uint32_t open_options,
__in uint32_t flags)
{
int32_t status;
nt_oa oa;
nt_iosb iosb;
nt_unicode_string * sdev;
wchar16_t * wch;
wchar16_t * wch_mark;
uint32_t hash;
/* validaton */
if (!hfile && !path)
return NT_STATUS_INVALID_HANDLE;
/* hfile */
if (hfile) {
istat->flags_out = 0;
} else {
/* oa */
oa.len = sizeof(nt_oa);
oa.root_dir = hroot;
oa.obj_name = path;
oa.obj_attr = 0;
oa.sec_desc = 0;
oa.sec_qos = 0;
/* open file/folder */
if ((status = __ntapi->zw_open_file(
&hfile,
NT_SEC_SYNCHRONIZE
| NT_FILE_READ_ATTRIBUTES
| NT_FILE_READ_ACCESS,
&oa,
&iosb,
NT_FILE_SHARE_READ | NT_FILE_SHARE_WRITE,
open_options | NT_FILE_SYNCHRONOUS_IO_ALERT)))
return status;
istat->flags_out = NT_STAT_NEW_HANDLE;
}
istat->hfile = hfile;
istat->flags_in = flags;
/* file index number */
if ((status = __ntapi->zw_query_information_file(
hfile,
&iosb,
&istat->fii,
sizeof(istat->fii),
NT_FILE_INTERNAL_INFORMATION)))
return status;
/* attributes & reparse tag information */
if ((status = __ntapi->zw_query_information_file(
hfile,
&iosb,
&istat->ftagi,
sizeof(istat->ftagi),
NT_FILE_ATTRIBUTE_TAG_INFORMATION)))
return status;
/* system-unique device name */
if ((status = __ntapi->zw_query_object(
hfile,
NT_OBJECT_NAME_INFORMATION,
buffer,
buffer_size,
(uint32_t *)&iosb.info)))
return status;
sdev = (nt_unicode_string *)buffer;
wch = sdev->buffer;
if (sdev->strlen < __DEVICE_PATH_PREFIX_LEN)
return NT_STATUS_INVALID_HANDLE;
if ((wch[0] != '\\')
|| (wch[1] != 'D')
|| (wch[2] != 'e')
|| (wch[3] != 'v')
|| (wch[4] != 'i')
|| (wch[5] != 'c')
|| (wch[6] != 'e')
|| (wch[7] != '\\'))
return NT_STATUS_INVALID_HANDLE;
if ((sdev->strlen >= __DEVICE_MUP_PREFIX_LEN)
&& (wch[8]=='M')
&& (wch[9]=='u')
&& (wch[10]=='p')
&& (wch[11]=='\\')) {
istat->flags_out |= NT_STATFS_MUP_DEVICE;
wch_mark = &wch[12];
hash = __DEVICE_MUP_PREFIX_HASH;
} else {
wch_mark = &wch[8];
hash = __DEVICE_PATH_PREFIX_HASH;
}
for (wch=wch_mark; *wch!='\\'; wch++)
(void)0;
istat->dev_name_strlen = (uint16_t)((wch - sdev->buffer) * sizeof(uint16_t));
istat->dev_name_hash = __ntapi->tt_buffer_crc32(
hash,
wch_mark,
(uintptr_t)wch - (uintptr_t)wch_mark);
return status;
}
int32_t __stdcall __ntapi_tt_validate_fs_handle(
__in void * hfile,
__in uint32_t dev_name_hash,
__in nt_fii fii,
__out uintptr_t * buffer,
__in uint32_t buffer_size)
{
int32_t status;
nt_istat istat;
status = __ntapi->tt_istat(
hfile,
(void *)0,
(nt_unicode_string *)0,
&istat,
buffer,
buffer_size,
0,
NT_ISTAT_DEFAULT);
if (status) return status;
if (istat.fii.index_number.quad != fii.index_number.quad)
return NT_STATUS_CONTEXT_MISMATCH;
else if (istat.dev_name_hash != dev_name_hash)
return NT_STATUS_CONTEXT_MISMATCH;
return NT_STATUS_SUCCESS;
}
|