use tags for pool allocations, and reformat code

svn path=/trunk/; revision=14545
This commit is contained in:
Royce Mitchell III 2005-04-08 12:54:37 +00:00
parent d57bccaddf
commit dac8f53fe5

View file

@ -41,7 +41,10 @@ STATIC MODULE_TEXT_SECTION NtoskrnlTextSection;
STATIC MODULE_TEXT_SECTION LdrHalTextSection;
ULONG_PTR LdrHalBase;
#define TAG_DRIVER_MEM TAG('D', 'R', 'V', 'M')
#define TAG_DRIVER_MEM TAG('D', 'R', 'V', 'M') /* drvm */
#define TAG_MODULE_OBJECT TAG('k', 'l', 'm', 'o') /* klmo - kernel ldr module object */
#define TAG_LDR_WSTR TAG('k', 'l', 'w', 's') /* klws - kernel ldr wide string */
#define TAG_MODULE_TEXT_SECTION TAG('k', 'l', 'm', 't') /* klmt - kernel ldr module text */
#ifndef HIWORD
#define HIWORD(X) ((WORD) (((DWORD) (X) >> 16) & 0xFFFF))
@ -53,42 +56,50 @@ ULONG_PTR LdrHalBase;
/* FORWARD DECLARATIONS ******************************************************/
NTSTATUS
LdrProcessModule(PVOID ModuleLoadBase,
LdrProcessModule (
PVOID ModuleLoadBase,
PUNICODE_STRING ModuleName,
PMODULE_OBJECT *ModuleObject);
PMODULE_OBJECT *ModuleObject );
static VOID
LdrpBuildModuleBaseName(PUNICODE_STRING BaseName,
PUNICODE_STRING FullName);
LdrpBuildModuleBaseName (
PUNICODE_STRING BaseName,
PUNICODE_STRING FullName );
static LONG
LdrpCompareModuleNames(IN PUNICODE_STRING String1,
IN PUNICODE_STRING String2);
LdrpCompareModuleNames (
IN PUNICODE_STRING String1,
IN PUNICODE_STRING String2 );
/* PE Driver load support */
static NTSTATUS LdrPEProcessModule(PVOID ModuleLoadBase,
static NTSTATUS
LdrPEProcessModule (
PVOID ModuleLoadBase,
PUNICODE_STRING FileName,
PMODULE_OBJECT *ModuleObject);
PMODULE_OBJECT *ModuleObject );
static PVOID
LdrPEGetExportByName(PVOID BaseAddress,
LdrPEGetExportByName (
PVOID BaseAddress,
PUCHAR SymbolName,
WORD Hint);
WORD Hint );
static PVOID
LdrPEFixupForward(PCHAR ForwardName);
LdrPEFixupForward ( PCHAR ForwardName );
static NTSTATUS
LdrPEPerformRelocations(PVOID DriverBase,
ULONG DriverSize);
LdrPEPerformRelocations (
PVOID DriverBase,
ULONG DriverSize );
static NTSTATUS
LdrPEFixupImports(PMODULE_OBJECT Module);
LdrPEFixupImports ( PMODULE_OBJECT Module );
/* FUNCTIONS *****************************************************************/
VOID
LdrInitDebug(PLOADER_MODULE Module, PWCH Name)
LdrInitDebug ( PLOADER_MODULE Module, PWCH Name )
{
PLIST_ENTRY current_entry;
MODULE_TEXT_SECTION* current;
@ -112,7 +123,7 @@ LdrInitDebug(PLOADER_MODULE Module, PWCH Name)
}
VOID INIT_FUNCTION
LdrInit1(VOID)
LdrInit1 ( VOID )
{
PIMAGE_NT_HEADERS NtHeader;
PIMAGE_SECTION_HEADER SectionList;
@ -130,8 +141,8 @@ LdrInit1(VOID)
NtHeader = RtlImageNtHeader((PVOID)KERNEL_BASE);
SectionList = IMAGE_FIRST_SECTION(NtHeader);
NtoskrnlTextSection.Base = KERNEL_BASE;
NtoskrnlTextSection.Length = SectionList[0].Misc.VirtualSize +
SectionList[0].VirtualAddress;
NtoskrnlTextSection.Length = SectionList[0].Misc.VirtualSize
+ SectionList[0].VirtualAddress;
NtoskrnlTextSection.Name = KERNEL_MODULE_NAME;
NtoskrnlTextSection.OptionalHeader = OPTHDROFFSET(KERNEL_BASE);
InsertTailList(&ModuleTextListHead, &NtoskrnlTextSection.ListEntry);
@ -141,8 +152,8 @@ LdrInit1(VOID)
NtHeader = RtlImageNtHeader((PVOID)LdrHalBase);
SectionList = IMAGE_FIRST_SECTION(NtHeader);
LdrHalTextSection.Base = LdrHalBase;
LdrHalTextSection.Length = SectionList[0].Misc.VirtualSize +
SectionList[0].VirtualAddress;
LdrHalTextSection.Length = SectionList[0].Misc.VirtualSize
+ SectionList[0].VirtualAddress;
LdrHalTextSection.Name = HAL_MODULE_NAME;
LdrHalTextSection.OptionalHeader = OPTHDROFFSET(LdrHalBase);
InsertTailList(&ModuleTextListHead, &LdrHalTextSection.ListEntry);
@ -152,7 +163,7 @@ LdrInit1(VOID)
}
VOID INIT_FUNCTION
LdrInitModuleManagement(VOID)
LdrInitModuleManagement ( VOID )
{
PIMAGE_NT_HEADERS NtHeader;
@ -201,11 +212,12 @@ LdrInitModuleManagement(VOID)
}
NTSTATUS
LdrpLoadImage(PUNICODE_STRING DriverName,
LdrpLoadImage (
PUNICODE_STRING DriverName,
PVOID *ModuleBase,
PVOID *SectionPointer,
PVOID *EntryPoint,
PVOID *ExportSectionPointer)
PVOID *ExportSectionPointer )
{
PMODULE_OBJECT ModuleObject;
NTSTATUS Status;
@ -223,28 +235,28 @@ LdrpLoadImage(PUNICODE_STRING DriverName,
if (ModuleBase)
*ModuleBase = ModuleObject->Base;
// if (SectionPointer)
// *SectionPointer = ModuleObject->
//if (SectionPointer)
// *SectionPointer = ModuleObject->
if (EntryPoint)
*EntryPoint = ModuleObject->EntryPoint;
// if (ExportSectionPointer)
// *ExportSectionPointer = ModuleObject->
//if (ExportSectionPointer)
// *ExportSectionPointer = ModuleObject->
return(STATUS_SUCCESS);
}
NTSTATUS
LdrpUnloadImage(PVOID ModuleBase)
LdrpUnloadImage ( PVOID ModuleBase )
{
return(STATUS_NOT_IMPLEMENTED);
}
NTSTATUS
LdrpLoadAndCallImage(PUNICODE_STRING ModuleName)
LdrpLoadAndCallImage ( PUNICODE_STRING ModuleName )
{
PDRIVER_INITIALIZE DriverEntry;
PMODULE_OBJECT ModuleObject;
@ -275,8 +287,9 @@ LdrpLoadAndCallImage(PUNICODE_STRING ModuleName)
NTSTATUS
LdrLoadModule(PUNICODE_STRING Filename,
PMODULE_OBJECT *ModuleObject)
LdrLoadModule(
PUNICODE_STRING Filename,
PMODULE_OBJECT *ModuleObject )
{
PVOID ModuleLoadBase;
NTSTATUS Status;
@ -378,7 +391,7 @@ LdrLoadModule(PUNICODE_STRING Filename,
NTSTATUS
LdrUnloadModule(PMODULE_OBJECT ModuleObject)
LdrUnloadModule ( PMODULE_OBJECT ModuleObject )
{
KIRQL Irql;
@ -400,7 +413,7 @@ LdrUnloadModule(PMODULE_OBJECT ModuleObject)
}
/* Free module section */
// MmFreeSection(ModuleObject->Base);
// MmFreeSection(ModuleObject->Base);
ExFreePool(ModuleObject->FullName.Buffer);
ExFreePool(ModuleObject);
@ -410,9 +423,10 @@ LdrUnloadModule(PMODULE_OBJECT ModuleObject)
NTSTATUS
LdrProcessModule(PVOID ModuleLoadBase,
LdrProcessModule(
PVOID ModuleLoadBase,
PUNICODE_STRING ModuleName,
PMODULE_OBJECT *ModuleObject)
PMODULE_OBJECT *ModuleObject )
{
PIMAGE_DOS_HEADER PEDosHeader;
@ -430,9 +444,10 @@ LdrProcessModule(PVOID ModuleLoadBase,
}
NTSTATUS
LdrpQueryModuleInformation(PVOID Buffer,
LdrpQueryModuleInformation (
PVOID Buffer,
ULONG Size,
PULONG ReqSize)
PULONG ReqSize )
{
PLIST_ENTRY current_entry;
PMODULE_OBJECT current;
@ -511,8 +526,9 @@ LdrpQueryModuleInformation(PVOID Buffer,
static VOID
LdrpBuildModuleBaseName(PUNICODE_STRING BaseName,
PUNICODE_STRING FullName)
LdrpBuildModuleBaseName (
PUNICODE_STRING BaseName,
PUNICODE_STRING FullName )
{
PWCHAR p;
@ -536,8 +552,9 @@ LdrpBuildModuleBaseName(PUNICODE_STRING BaseName,
static LONG
LdrpCompareModuleNames(IN PUNICODE_STRING String1,
IN PUNICODE_STRING String2)
LdrpCompareModuleNames (
IN PUNICODE_STRING String1,
IN PUNICODE_STRING String2 )
{
ULONG len1, len2, i;
PWCHAR s1, s2, p;
@ -604,7 +621,7 @@ LdrpCompareModuleNames(IN PUNICODE_STRING String1,
}
PMODULE_OBJECT
LdrGetModuleObject(PUNICODE_STRING ModuleName)
LdrGetModuleObject ( PUNICODE_STRING ModuleName )
{
PMODULE_OBJECT Module;
PLIST_ENTRY Entry;
@ -644,10 +661,11 @@ LdrGetModuleObject(PUNICODE_STRING ModuleName)
/* ---------------------------------------------- PE Module support */
static ULONG
LdrLookupPageProtection(PVOID PageStart,
LdrLookupPageProtection (
PVOID PageStart,
PVOID DriverBase,
PIMAGE_FILE_HEADER PEFileHeader,
PIMAGE_SECTION_HEADER PESectionHeaders)
PIMAGE_SECTION_HEADER PESectionHeaders )
{
BOOLEAN Write = FALSE;
BOOLEAN Execute = FALSE;
@ -696,9 +714,10 @@ LdrLookupPageProtection(PVOID PageStart,
}
static NTSTATUS
LdrPEProcessModule(PVOID ModuleLoadBase,
LdrPEProcessModule(
PVOID ModuleLoadBase,
PUNICODE_STRING FileName,
PMODULE_OBJECT *ModuleObject)
PMODULE_OBJECT *ModuleObject )
{
unsigned int DriverSize, Idx;
DWORD CurrentSize;
@ -799,15 +818,16 @@ LdrPEProcessModule(PVOID ModuleLoadBase,
Status = LdrPEPerformRelocations(DriverBase, DriverSize);
if (!NT_SUCCESS(Status))
{
// MmFreeSection(DriverBase);
// MmFreeSection(DriverBase);
return Status;
}
/* Create the module */
CreatedModuleObject = ExAllocatePool(NonPagedPool, sizeof(MODULE_OBJECT));
CreatedModuleObject = ExAllocatePoolWithTag (
NonPagedPool, sizeof(MODULE_OBJECT), TAG_MODULE_OBJECT );
if (CreatedModuleObject == NULL)
{
// MmFreeSection(DriverBase);
// MmFreeSection(DriverBase);
return STATUS_INSUFFICIENT_RESOURCES;
}
@ -819,11 +839,12 @@ LdrPEProcessModule(PVOID ModuleLoadBase,
CreatedModuleObject->FullName.Length = 0;
CreatedModuleObject->FullName.MaximumLength = FileName->Length + sizeof(UNICODE_NULL);
CreatedModuleObject->FullName.Buffer = ExAllocatePool(PagedPool, CreatedModuleObject->FullName.MaximumLength);
CreatedModuleObject->FullName.Buffer =
ExAllocatePoolWithTag(PagedPool, CreatedModuleObject->FullName.MaximumLength, TAG_LDR_WSTR);
if (CreatedModuleObject->FullName.Buffer == NULL)
{
ExFreePool(CreatedModuleObject);
// MmFreeSection(DriverBase);
// MmFreeSection(DriverBase);
return STATUS_INSUFFICIENT_RESOURCES;
}
@ -854,7 +875,7 @@ LdrPEProcessModule(PVOID ModuleLoadBase,
Status = LdrPEFixupImports(CreatedModuleObject);
if (!NT_SUCCESS(Status))
{
// MmFreeSection(DriverBase);
// MmFreeSection(DriverBase);
ExFreePool(CreatedModuleObject->FullName.Buffer);
ExFreePool(CreatedModuleObject);
return Status;
@ -932,14 +953,18 @@ LdrPEProcessModule(PVOID ModuleLoadBase,
KeReleaseSpinLock(&ModuleListLock, Irql);
ModuleTextSection = ExAllocatePool(NonPagedPool,
sizeof(MODULE_TEXT_SECTION));
ModuleTextSection = ExAllocatePoolWithTag (
NonPagedPool,
sizeof(MODULE_TEXT_SECTION),
TAG_MODULE_TEXT_SECTION );
ASSERT(ModuleTextSection);
RtlZeroMemory(ModuleTextSection, sizeof(MODULE_TEXT_SECTION));
ModuleTextSection->Base = (ULONG)DriverBase;
ModuleTextSection->Length = DriverSize;
ModuleTextSection->Name = ExAllocatePool(NonPagedPool,
(CreatedModuleObject->BaseName.Length + 1) * sizeof(WCHAR));
ModuleTextSection->Name = ExAllocatePoolWithTag (
NonPagedPool,
(CreatedModuleObject->BaseName.Length + 1) * sizeof(WCHAR),
TAG_LDR_WSTR );
RtlCopyMemory(ModuleTextSection->Name,
CreatedModuleObject->BaseName.Buffer,
CreatedModuleObject->BaseName.Length);
@ -965,7 +990,8 @@ LdrPEProcessModule(PVOID ModuleLoadBase,
PVOID INIT_FUNCTION
LdrSafePEProcessModule(PVOID ModuleLoadBase,
LdrSafePEProcessModule (
PVOID ModuleLoadBase,
PVOID DriverBase,
PVOID ImportModuleBase,
PULONG DriverSize)
@ -1036,8 +1062,8 @@ LdrSafePEProcessModule(PVOID ModuleLoadBase,
// Copy current section into current offset of virtual section
if (Section->SizeOfRawData)
{
// ps("PESectionHeaders[Idx].VirtualAddress (%X) + DriverBase %x\n",
// PESectionHeaders[Idx].VirtualAddress, PESectionHeaders[Idx].VirtualAddress + DriverBase);
// ps("PESectionHeaders[Idx].VirtualAddress (%X) + DriverBase %x\n",
// PESectionHeaders[Idx].VirtualAddress, PESectionHeaders[Idx].VirtualAddress + DriverBase);
memcpy(Section->VirtualAddress + (char*)DriverBase,
Section->PointerToRawData + (char*)ModuleLoadBase,
Section->Misc.VirtualSize > Section->SizeOfRawData ? Section->SizeOfRawData : Section->Misc.VirtualSize);
@ -1117,7 +1143,7 @@ LdrSafePEProcessModule(PVOID ModuleLoadBase,
}
static PVOID
LdrPEFixupForward(PCHAR ForwardName)
LdrPEFixupForward ( PCHAR ForwardName )
{
CHAR NameBuffer[128];
UNICODE_STRING ModuleName;
@ -1153,7 +1179,8 @@ LdrPEFixupForward(PCHAR ForwardName)
}
static NTSTATUS
LdrPEPerformRelocations(PVOID DriverBase,
LdrPEPerformRelocations (
PVOID DriverBase,
ULONG DriverSize)
{
PIMAGE_NT_HEADERS NtHeaders;
@ -1249,7 +1276,8 @@ LdrPEPerformRelocations(PVOID DriverBase,
}
static NTSTATUS
LdrPEGetOrLoadModule(PMODULE_OBJECT Module,
LdrPEGetOrLoadModule (
PMODULE_OBJECT Module,
PCHAR ImportedName,
PMODULE_OBJECT* ImportedModule)
{
@ -1321,9 +1349,10 @@ LdrPEGetOrLoadModule(PMODULE_OBJECT Module,
}
static PVOID
LdrPEGetExportByName(PVOID BaseAddress,
LdrPEGetExportByName (
PVOID BaseAddress,
PUCHAR SymbolName,
WORD Hint)
WORD Hint )
{
PIMAGE_EXPORT_DIRECTORY ExportDir;
PDWORD * ExFunctions;
@ -1470,15 +1499,17 @@ LdrPEGetExportByName(PVOID BaseAddress,
}
static PVOID
LdrPEGetExportByOrdinal (PVOID BaseAddress,
ULONG Ordinal)
LdrPEGetExportByOrdinal (
PVOID BaseAddress,
ULONG Ordinal )
{
PIMAGE_EXPORT_DIRECTORY ExportDir;
ULONG ExportDirSize;
PDWORD * ExFunctions;
PVOID Function;
ExportDir = (PIMAGE_EXPORT_DIRECTORY)RtlImageDirectoryEntryToData (BaseAddress,
ExportDir = (PIMAGE_EXPORT_DIRECTORY)RtlImageDirectoryEntryToData (
BaseAddress,
TRUE,
IMAGE_DIRECTORY_ENTRY_EXPORT,
&ExportDirSize);
@ -1504,9 +1535,10 @@ LdrPEGetExportByOrdinal (PVOID BaseAddress,
}
static NTSTATUS
LdrPEProcessImportDirectoryEntry(PVOID DriverBase,
LdrPEProcessImportDirectoryEntry(
PVOID DriverBase,
PMODULE_OBJECT ImportedModule,
PIMAGE_IMPORT_DESCRIPTOR ImportModuleDirectory)
PIMAGE_IMPORT_DESCRIPTOR ImportModuleDirectory )
{
PVOID* ImportAddressList;
PULONG FunctionNameList;
@ -1561,7 +1593,7 @@ LdrPEProcessImportDirectoryEntry(PVOID DriverBase,
}
static NTSTATUS
LdrPEFixupImports(PMODULE_OBJECT Module)
LdrPEFixupImports ( PMODULE_OBJECT Module )
{
PIMAGE_IMPORT_DESCRIPTOR ImportModuleDirectory;
PCHAR ImportedName;