Blob Blame History Raw
/********************************************************/
/*  ntapi: Native API core library                      */
/*  Copyright (C) 2013--2016  Z. Gilboa                 */
/*  Released under GPLv2 and GPLv3; see COPYING.NTAPI.  */
/********************************************************/

#include <ntapi/ntapi.h>
#include <ntapi/nt_file.h>
#include <ntapi/nt_fsctl.h>
#include <ntapi/nt_mount.h>
#include <ntapi/nt_istat.h>
#include "ntapi_impl.h"

int32_t __stdcall __ntapi_tt_istat(
	__in	void *			hfile,
	__in	void *			hroot	__optional,
	__in	nt_unicode_string *	path,
	__out	nt_istat *		istat,
	__out	uintptr_t *		buffer,
	__in	uint32_t		buffer_size,
	__in	uint32_t		open_options,
	__in	uint32_t		flags)
{
	int32_t			status;

	nt_oa			oa;
	nt_iosb			iosb;
	nt_unicode_string *	sdev;
	wchar16_t *		wch;
	wchar16_t *		wch_mark;
	uint32_t		hash;

	(void)flags;

	/* validaton */
	if (!hfile && !path)
		return NT_STATUS_INVALID_PARAMETER;

	/* hfile */
	if (hfile) {
		istat->flags = 0;
	} else {
		/* oa */
		oa.len = sizeof(nt_oa);
		oa.root_dir = hroot;
		oa.obj_name = path;
		oa.obj_attr = 0;
		oa.sec_desc = 0;
		oa.sec_qos = 0;

		/* open file/folder */
		if ((status = __ntapi->zw_open_file(
				&hfile,
				NT_SEC_SYNCHRONIZE
					| NT_FILE_READ_ATTRIBUTES
					| NT_FILE_READ_ACCESS,
				&oa,
				&iosb,
				NT_FILE_SHARE_READ | NT_FILE_SHARE_WRITE,
				open_options | NT_FILE_SYNCHRONOUS_IO_ALERT)))
			return status;

		istat->flags = NT_STAT_NEW_HANDLE;
	}

	istat->hfile = hfile;

	/* file index number */
	if (!(flags & NT_ISTAT_DEV_NAME_ONLY))
		if ((status = __ntapi->zw_query_information_file(
				hfile,
				&iosb,
				&istat->fii,
				sizeof(istat->fii),
				NT_FILE_INTERNAL_INFORMATION)))
			return status;

	/* attributes & reparse tag information */
	if (!(flags & NT_ISTAT_DEV_NAME_ONLY))
		if ((status = __ntapi->zw_query_information_file(
				hfile,
				&iosb,
				&istat->ftagi,
				sizeof(istat->ftagi),
				NT_FILE_ATTRIBUTE_TAG_INFORMATION)))
			return status;

	/* system-unique device name */
	if ((status = __ntapi->zw_query_object(
			hfile,
			NT_OBJECT_NAME_INFORMATION,
			buffer,
			buffer_size,
			(uint32_t *)&iosb.info)))
		return status;

	sdev = (nt_unicode_string *)buffer;
	wch  = sdev->buffer;

	if (sdev->strlen < __DEVICE_PATH_PREFIX_LEN)
		return NT_STATUS_INVALID_HANDLE;

	if ((wch[0] != '\\')
			|| (wch[1] != 'D')
			|| (wch[2] != 'e')
			|| (wch[3] != 'v')
			|| (wch[4] != 'i')
			|| (wch[5] != 'c')
			|| (wch[6] != 'e')
			|| (wch[7] != '\\'))
		return NT_STATUS_INVALID_HANDLE;

	if ((sdev->strlen >= __DEVICE_MUP_PREFIX_LEN)
			&& (wch[8]=='M')
			&& (wch[9]=='u')
			&& (wch[10]=='p')
			&& (wch[11]=='\\')) {
		wch_mark = &wch[12];
		hash     = __DEVICE_MUP_PREFIX_HASH;
		istat->flags |= NT_STATFS_MUP_DEVICE;

		for (wch=wch_mark; *wch!='\\'; wch++)
			(void)0;
		wch++;
	} else {
		wch_mark = &wch[8];
		wch      = wch_mark;
		hash     = __DEVICE_PATH_PREFIX_HASH;
	}

	for (; *wch!='\\'; )
		wch++;

	istat->obj_name_strlen = sdev->strlen;
	istat->obj_name_maxlen = istat->dev_name_maxlen;
	istat->dev_name_strlen = (uint16_t)((wch - sdev->buffer) * sizeof(uint16_t));
	istat->dev_name_hash   = __ntapi->tt_buffer_crc32(
					hash,wch_mark,
					sizeof(wchar16_t)*(wch-wch_mark));

	if (!(flags & NT_ISTAT_DEV_NAME_COPY))
		return NT_STATUS_SUCCESS;
	else if (istat->dev_name_maxlen < istat->dev_name_strlen)
		return NT_STATUS_BUFFER_TOO_SMALL;

	__ntapi->tt_memcpy_utf16(
		istat->dev_name,
		sdev->buffer,
		istat->dev_name_strlen);

	return status;
}


int32_t __stdcall __ntapi_tt_validate_fs_handle(
	__in	void *		hfile,
	__in	uint32_t	dev_name_hash,
	__in	nt_fii		fii,
	__out	uintptr_t *	buffer,
	__in	uint32_t	buffer_size)
{
	int32_t		status;
	nt_istat	istat;

	status = __ntapi->tt_istat(
		hfile,
		(void *)0,
		(nt_unicode_string *)0,
		&istat,
		buffer,
		buffer_size,
		0,
		NT_ISTAT_DEFAULT);

	if (status) return status;

	if (istat.fii.index_number.quad != fii.index_number.quad)
		return NT_STATUS_CONTEXT_MISMATCH;
	else if (istat.dev_name_hash != dev_name_hash)
		return NT_STATUS_CONTEXT_MISMATCH;

	return NT_STATUS_SUCCESS;
}