Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
99 changes: 88 additions & 11 deletions Source/Shared/ntos/ntos.h
Original file line number Diff line number Diff line change
Expand Up @@ -5,9 +5,9 @@
*
* TITLE: NTOS.H
*
* VERSION: 1.243
* VERSION: 1.244
*
* DATE: 04 Jun 2026
* DATE: 16 Jun 2026
*
* Common header file for the ntos API functions and definitions.
*
Expand Down Expand Up @@ -7213,7 +7213,7 @@ typedef enum _ALTERNATIVE_ARCHITECTURE_TYPE {
#define MM_SHARED_USER_DATA_VA 0x000000007FFE0000

//
// WARNING: this definition is OS version dependent.
// WARNING: this definition is OS version/CPU architecture type dependent.
// Structure maybe incomplete.
//
#include <pshpack4.h>
Expand Down Expand Up @@ -7363,8 +7363,19 @@ typedef struct _KUSER_SHARED_DATA {
union {
USHORT QpcData;
struct {
UCHAR QpcBypassEnabled : 1;
UCHAR QpcShift : 1;
union {
volatile UCHAR QpcBypassEnabled;
struct {
volatile UCHAR BypassAllowed : 1;
volatile UCHAR HypervisorAssist : 1;
volatile UCHAR Reserved_2_3 : 2;
volatile UCHAR UseMfence : 1;
volatile UCHAR UseLfence : 1;
volatile UCHAR Reserved_6 : 1;
volatile UCHAR UseRdtscp : 1;
};
};
UCHAR QpcReserved;
};
};

Expand Down Expand Up @@ -11538,6 +11549,71 @@ NtSetSystemInformation(
_In_reads_bytes_opt_(SystemInformationLength) PVOID SystemInformation,
_In_ ULONG SystemInformationLength);

/************************************************************************************
*
* Power API.
*
************************************************************************************/

typedef enum _SHUTDOWN_ACTION {
ShutdownNoReboot,
ShutdownReboot,
ShutdownPowerOff,
ShutdownRebootForRecovery
} SHUTDOWN_ACTION;

NTSYSAPI
NTSTATUS
NTAPI
NtShutdownSystem(
_In_ SHUTDOWN_ACTION Action);

NTSYSAPI
NTSTATUS
NTAPI
NtPowerInformation(
_In_ POWER_INFORMATION_LEVEL InformationLevel,
_In_reads_bytes_opt_(InputBufferLength) PVOID InputBuffer,
_In_ ULONG InputBufferLength,
_Out_writes_bytes_opt_(OutputBufferLength) PVOID OutputBuffer,
_In_ ULONG OutputBufferLength);

NTSYSAPI
NTSTATUS
NTAPI
NtInitiatePowerAction(
_In_ POWER_ACTION SystemAction,
_In_ SYSTEM_POWER_STATE LightestSystemState,
_In_ ULONG Flags,
_In_ BOOLEAN Asynchronous);

NTSYSAPI
NTSTATUS
NTAPI
NtSetSystemPowerState(
_In_ POWER_ACTION SystemAction,
_In_ SYSTEM_POWER_STATE LightestSystemState,
_In_ ULONG Flags);

NTSYSAPI
NTSTATUS
NTAPI
NtGetDevicePowerState(
_In_ HANDLE Device,
_Out_ PDEVICE_POWER_STATE State);

NTSYSAPI
NTSTATUS
NTAPI
NtRequestWakeupLatency(
_In_ LATENCY_TIME latency);

NTSYSAPI
BOOLEAN
NTAPI
NtIsSystemResumeAutomatic(
VOID);

/************************************************************************************
*
* Event (EventPair) API.
Expand Down Expand Up @@ -13519,9 +13595,11 @@ NtLoadKey2(
//https://gist.github.com/tyranid/1db47869da253a912242c694e921009d#file-ntloadkeyex3-h

typedef enum _KEY_LOAD_HANDLE_TYPE {
KeyLoadTrustKey = 1,
KeyLoadEvent,
KeyLoadToken
InvalidType,
TrustClassKey,
Event,
FileAccessToken,
TypeMax,
} KEY_LOAD_HANDLE_TYPE;

typedef struct _KEY_LOAD_HANDLE {
Expand All @@ -13540,7 +13618,7 @@ NtLoadKey3(
_In_ ULONG LoadEntryCount,
_In_opt_ ACCESS_MASK DesiredAccess,
_Out_opt_ PHANDLE RootHandle,
_In_ PVOID Unused);
_Reserved_ PVOID Reserved);

NTSYSAPI
NTSTATUS
Expand Down Expand Up @@ -15009,8 +15087,7 @@ NtWaitForDebugEvent(
_In_ HANDLE DebugObjectHandle,
_In_ BOOLEAN Alertable,
_In_opt_ PLARGE_INTEGER Timeout,
_Out_ PDBGUI_WAIT_STATE_CHANGE WaitStateChange
);
_Out_ PDBGUI_WAIT_STATE_CHANGE WaitStateChange);

NTSYSAPI
NTSTATUS
Expand Down
94 changes: 81 additions & 13 deletions Source/WinObjEx64/extras/extrasCallbacks.c
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
/*******************************************************************************
*
* (C) COPYRIGHT AUTHORS, 2018 - 2025
* (C) COPYRIGHT AUTHORS, 2018 - 2026
*
* TITLE: EXTRASCALLBACKS.C
*
* VERSION: 2.09
* VERSION: 2.11
*
* DATE: 22 Aug 2025
* DATE: 15 Jun 2026
*
* THIS CODE AND INFORMATION IS PROVIDED "AS IS" WITHOUT WARRANTY OF
* ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING BUT NOT LIMITED
Expand Down Expand Up @@ -48,6 +48,7 @@ static FAST_EVENT SysCbInitializedEvent = FAST_EVENT_INIT;
#define CBT_SIZE_CO_V1 0x100
#define CBT_SIZE_NI_V1 0xF8
#define CBT_SIZE_GE_V1 0x100 //same as CU/GA
#define CBT_SIZE_GE_V2 0x110

typedef struct _CBT_MAPPING {
ULONG Build;
Expand Down Expand Up @@ -79,7 +80,7 @@ CBT_MAPPING g_CbtMapping[] = {
{ NT_WIN11_22H2, NTDDI_WIN10_NI, CBT_SIZE_NI_V1 },
{ NT_WIN11_23H2, NTDDI_WIN10_NI, CBT_SIZE_NI_V1 },
{ NT_WIN11_24H2, NTDDI_WIN11_GE, CBT_SIZE_GE_V1 },
{ NT_WIN11_25H2, NTDDI_WIN11_SE, CBT_SIZE_GE_V1 } //update on release
{ NT_WIN11_25H2, NTDDI_WIN11_GE, CBT_SIZE_GE_V2 } //update on release
};

//
Expand Down Expand Up @@ -386,7 +387,9 @@ static const WCHAR* CiCallbackNames[] = {
L"CiHvciReportMmIncompatibility",//30
L"CiCompareExistingSePool",//31
L"CiSetCachedOriginClaim",//32,
L"CipIsDeveloperModeEnabled"//33
L"CipIsDeveloperModeEnabled",//33
L"CiIsTrustedLaunchPolicyEnabled",//34
L"Id_CiUnknownCallback"//35
};

typedef enum _CiNameIds {
Expand Down Expand Up @@ -423,7 +426,9 @@ typedef enum _CiNameIds {
Id_CiHvciReportMmIncompatibility,
Id_CiCompareExistingSePool,
Id_CiSetCachedOriginClaim,
Id_CipIsDeveloperModeEnabled
Id_CipIsDeveloperModeEnabled,
Id_CiIsTrustedLaunchPolicyEnabled,
Id_CiUnknownCallback
} CiNameIds;

//
Expand Down Expand Up @@ -711,9 +716,9 @@ static const BYTE CiCallbackIndexes_Win11_21H1[] = {
};

//
// Windows 11 22H2 - 25H2
// Windows 11 22H2 - 24H2
//
static const BYTE CiCallbackIndexes_Win11_22H2_25H2[] = {
static const BYTE CiCallbackIndexes_Win11_22H2_24H2[] = {
Id_CiSetFileCache,
Id_CiGetFileCache,
Id_CiQueryInformation,
Expand Down Expand Up @@ -746,6 +751,41 @@ static const BYTE CiCallbackIndexes_Win11_22H2_25H2[] = {
Id_CipIsDeveloperModeEnabled
};

static const BYTE CiCallbackIndexes_Win11_25H2[] = {
Id_CiSetFileCache,
Id_CiGetFileCache,
Id_CiQueryInformation,
Id_CiValidateImageHeader,
Id_CiValidateImageData,
Id_CiHashMemory,
Id_KappxIsPackageFile,
Id_CiCompareSigningLevels,
Id_CiValidateFileAsImageType,
Id_CiRegisterSigningInformation,
Id_CiUnregisterSigningInformation,
Id_CiInitializePolicy,
Id_CiReleaseContext,
Id_XciUnknownCallback,
Id_CiGetStrongImageReference,
Id_CiHvciSetImageBaseAddress,
Id_CipQueryPolicyInformation,
Id_CiQuerySecurityPolicy,
Id_CiRevalidateImage,
Id_CiSetInformation,
Id_CiSetInformationProcess,
Id_CiGetBuildExpiryTime,
Id_CiCheckProcessDebugAccessPolicy,
Id_CiGetCodeIntegrityOriginClaimForFileObject,
Id_CiDeleteCodeIntegrityOriginClaimMembers,
Id_CiDeleteCodeIntegrityOriginClaimForFileObject,
Id_CiHvciReportMmIncompatibility,
Id_CiCompareExistingSePool,
Id_CiSetCachedOriginClaim,
Id_CipIsDeveloperModeEnabled,
Id_CiUnknownCallback,
Id_CiIsTrustedLaunchPolicyEnabled
};

typedef struct _CI_INDEX_MAP {
ULONG MinBuild;
ULONG MaxBuild;
Expand Down Expand Up @@ -787,8 +827,11 @@ static CI_INDEX_MAP g_CiIndexMap[] = {
// Windows 11 21H2
{ NT_WIN11_21H2, NT_WIN11_21H2, 0, CiCallbackIndexes_Win11_21H1, RTL_NUMBER_OF(CiCallbackIndexes_Win11_21H1) },

// Windows 11 22H2 .. 25H2
{ NT_WIN11_22H2, NT_WIN11_25H2, 0, CiCallbackIndexes_Win11_22H2_25H2, RTL_NUMBER_OF(CiCallbackIndexes_Win11_22H2_25H2) }
// Windows 11 22H2 .. 24H2
{ NT_WIN11_22H2, NT_WIN11_25H2, 0, CiCallbackIndexes_Win11_22H2_24H2, RTL_NUMBER_OF(CiCallbackIndexes_Win11_22H2_24H2) },

// Windows 11 25H2
{ NT_WIN11_25H2, NT_WIN11_25H2, 0, CiCallbackIndexes_Win11_25H2, RTL_NUMBER_OF(CiCallbackIndexes_Win11_25H2) }
};

/*
Expand Down Expand Up @@ -2037,7 +2080,7 @@ OBEX_FINDCALLBACK_ROUTINE(FindCmCallbackHead)
if (hs.flags & F_ERROR)
break;

if (g_NtBuildNumber < NT_WIN11_25H2)
if (g_NtBuildNumber <= NT_WIN11_25H2)
{
if (hs.len == 5) {
/*
Expand Down Expand Up @@ -4095,15 +4138,21 @@ OBEX_DISPLAYCALLBACK_ROUTINE(DumpObCallbacks)
(PVOID)&RegEntry,
sizeof(OB_REGISTRATION)))
{
AltitudeSize = 100 + (SIZE_T)RegEntry.Altitude.Length;
AltitudeSize = (SIZE_T)RegEntry.Altitude.Length + sizeof(UNICODE_NULL);
lpAltitudeBuffer = (LPWSTR)supHeapAlloc(AltitudeSize);
if (lpAltitudeBuffer) {

RtlSecureZeroMemory(lpAltitudeBuffer, AltitudeSize);

if (!kdReadSystemMemory((ULONG_PTR)RegEntry.Altitude.Buffer,
(PVOID)lpAltitudeBuffer,
RegEntry.Altitude.Length))
{
_strcpy(lpAltitudeBuffer, TEXT("Cannot read altitude"));
}
else {
lpAltitudeBuffer[RegEntry.Altitude.Length / sizeof(WCHAR)] = UNICODE_NULL;
}
}
}

Expand Down Expand Up @@ -4152,6 +4201,7 @@ OBEX_DISPLAYCALLBACK_ROUTINE(DumpObCallbacks)
OBEX_DISPLAYCALLBACK_ROUTINE(DumpSeFileSystemCallbacks)
{
ULONG_PTR Next;
SIZE_T GuardIter = 0;

SEP_LOGON_SESSION_TERMINATED_NOTIFICATION SeEntry; // This structure is different for Ex variant but
// key callback function field is on the same offset.
Expand Down Expand Up @@ -4182,6 +4232,12 @@ OBEX_DISPLAYCALLBACK_ROUTINE(DumpSeFileSystemCallbacks)
//
Next = (ULONG_PTR)SeEntry.Next;
while (Next) {
LIST_ITERATION_GUARD(GuardIter);

if (Next < g_kdctx.SystemRangeStart) {
logAdd(EntryTypeWarning, TEXT("SeFileSystemCallbacks invalid Next pointer"));
break;
}
RtlSecureZeroMemory(&SeEntry, sizeof(SeEntry));
if (!kdReadSystemMemory(Next,
(PVOID)&SeEntry,
Expand Down Expand Up @@ -5122,7 +5178,7 @@ OBEX_DISPLAYCALLBACK_ROUTINE(DumpPspPicoProviderRoutines)

dataSize -= sizeof(SIZE_T); //exclude size element

picoRoutines = (PULONG_PTR)supHeapAlloc(ALIGN_UP(dataSize, PULONG_PTR));
picoRoutines = (PULONG_PTR)supHeapAlloc(ALIGN_UP(dataSize, ULONG_PTR));
if (picoRoutines) {
if (kdReadSystemMemory(KernelVariableAddress + sizeof(SIZE_T),
picoRoutines,
Expand Down Expand Up @@ -5184,6 +5240,12 @@ OBEX_DISPLAYCALLBACK_ROUTINE(DumpKiNmiCallbackListHead)
Next = (ULONG_PTR)NmiEntry.Next;
while (Next) {
LIST_ITERATION_GUARD(GuardIter);

if (Next < g_kdctx.SystemRangeStart) {
logAdd(EntryTypeWarning, TEXT("NmiCallbacks invalid Next pointer"));
break;
}

RtlSecureZeroMemory(&NmiEntry, sizeof(NmiEntry));

if (!kdReadSystemMemory(Next,
Expand Down Expand Up @@ -5315,6 +5377,12 @@ OBEX_DISPLAYCALLBACK_ROUTINE(DumpEmpCallbackListHead)
Next = (ULONG_PTR)Head.Next;
while (Next) {
LIST_ITERATION_GUARD(GuardIter);

if (Next < g_kdctx.SystemRangeStart) {
logAdd(EntryTypeWarning, TEXT("EmpCallbackList invalid Next pointer"));
break;
}

RtlSecureZeroMemory(&CallbackRecord, sizeof(CallbackRecord));
RecordAddress = (ULONG_PTR)Next - FIELD_OFFSET(EMP_CALLBACK_DB_RECORD, List);

Expand Down
2 changes: 1 addition & 1 deletion Source/WinObjEx64/tests/testunit.c
Original file line number Diff line number Diff line change
Expand Up @@ -1558,7 +1558,7 @@ VOID TestStart(
//TestSectionControlArea();
//TestSymbols();
//TestSectionImage();
//TestShadowDirectory();
TestShadowDirectory();
//TestPsObjectSecurity();
//TestLicenseCache();
//TestApiSetResolve();
Expand Down