00001
00002
00003
00004
00005
00006
00007
00008
00009
00010
00011
00012
00013
00014
00015
00016
00017
00018
00019
00020
00021
00022
00023
00024
00025
00026
#include "exp.h"
00027
00028
00029
00030
00031
00032 typedef struct _EPROFILE {
00033 PKPROCESS Process;
00034 PVOID
RangeBase;
00035 SIZE_T
RangeSize;
00036 PVOID
Buffer;
00037 ULONG
BufferSize;
00038 ULONG
BucketSize;
00039 PKPROFILE ProfileObject;
00040 PVOID
LockedBufferAddress;
00041 PMDL Mdl;
00042 ULONG
Segment;
00043 KPROFILE_SOURCE
ProfileSource;
00044 KAFFINITY
Affinity;
00045 }
EPROFILE, *
PEPROFILE;
00046
00047
00048
00049
00050
00051 POBJECT_TYPE ExProfileObjectType;
00052
00053 KMUTEX ExpProfileStateMutex;
00054
00055 ULONG
ExpCurrentProfileUsage = 0;
00056
00057 GENERIC_MAPPING
ExpProfileMapping = {
00058 STANDARD_RIGHTS_READ | PROFILE_CONTROL,
00059 STANDARD_RIGHTS_WRITE | PROFILE_CONTROL,
00060 STANDARD_RIGHTS_EXECUTE | PROFILE_CONTROL,
00061 PROFILE_ALL_ACCESS
00062 };
00063
00064 #define ACTIVE_PROFILE_LIMIT 8
00065
00066
#ifdef ALLOC_PRAGMA
00067
#pragma alloc_text(INIT, ExpProfileInitialization)
00068
#pragma alloc_text(PAGE, ExpProfileDelete)
00069
#pragma alloc_text(PAGE, NtCreateProfile)
00070
#pragma alloc_text(PAGE, NtStartProfile)
00071
#pragma alloc_text(PAGE, NtStopProfile)
00072
#pragma alloc_text(PAGE, NtSetIntervalProfile)
00073
#pragma alloc_text(PAGE, NtQueryIntervalProfile)
00074
#pragma alloc_text(PAGE, NtQueryPerformanceCounter)
00075
#endif
00076
00077
00078 BOOLEAN
00079 ExpProfileInitialization (
00080 )
00081
00082
00083
00084
00085
00086
00087
00088
00089
00090
00091
00092
00093
00094
00095
00096
00097
00098
00099
00100
00101 {
00102
00103
OBJECT_TYPE_INITIALIZER ObjectTypeInitializer;
00104
NTSTATUS Status;
00105 UNICODE_STRING TypeName;
00106
00107
00108
00109
00110
00111
KeInitializeMutex (&
ExpProfileStateMutex,
MUTEX_LEVEL_EX_PROFILE);
00112
00113
00114
00115
00116
00117
RtlInitUnicodeString(&TypeName,
L"Profile");
00118
00119
00120
00121
00122
00123 RtlZeroMemory(&ObjectTypeInitializer,
sizeof(ObjectTypeInitializer));
00124 ObjectTypeInitializer.Length =
sizeof(ObjectTypeInitializer);
00125 ObjectTypeInitializer.InvalidAttributes = OBJ_OPENLINK;
00126 ObjectTypeInitializer.PoolType =
NonPagedPool;
00127 ObjectTypeInitializer.DefaultNonPagedPoolCharge =
sizeof(
EPROFILE);
00128 ObjectTypeInitializer.ValidAccessMask = PROFILE_ALL_ACCESS;
00129 ObjectTypeInitializer.DeleteProcedure =
ExpProfileDelete;
00130 ObjectTypeInitializer.GenericMapping =
ExpProfileMapping;
00131
00132
Status =
ObCreateObjectType(&TypeName,
00133 &ObjectTypeInitializer,
00134 (PSECURITY_DESCRIPTOR)
NULL,
00135 &
ExProfileObjectType);
00136
00137
00138
00139
00140
00141
00142
return (BOOLEAN)(
NT_SUCCESS(
Status));
00143 }
00144
VOID
00145 ExpProfileDelete (
00146 IN PVOID Object
00147 )
00148
00149
00150
00151
00152
00153
00154
00155
00156
00157
00158
00159
00160
00161
00162
00163
00164
00165
00166
00167
00168
00169 {
00170
PEPROFILE Profile;
00171 BOOLEAN State;
00172
PEPROCESS ProcessAddress;
00173
00174 Profile = (
PEPROFILE)Object;
00175
00176
if (Profile->
LockedBufferAddress !=
NULL) {
00177
00178
00179
00180
00181
00182 State =
KeStopProfile (Profile->
ProfileObject);
00183
ASSERT (State !=
FALSE);
00184
00185
MmUnmapLockedPages (Profile->
LockedBufferAddress, Profile->
Mdl);
00186
MmUnlockPages (Profile->
Mdl);
00187
ExFreePool (Profile->
ProfileObject);
00188 }
00189
00190
if (Profile->
Process !=
NULL) {
00191 ProcessAddress = CONTAINING_RECORD(Profile->
Process,
EPROCESS, Pcb);
00192
ObDereferenceObject ((PVOID)ProcessAddress);
00193 }
00194
00195
return;
00196 }
00197
00198
NTSTATUS
00199 NtCreateProfile (
00200 OUT PHANDLE ProfileHandle,
00201 IN HANDLE Process OPTIONAL,
00202 IN PVOID RangeBase,
00203 IN SIZE_T RangeSize,
00204 IN ULONG BucketSize,
00205 IN PULONG Buffer,
00206 IN ULONG BufferSize,
00207 IN KPROFILE_SOURCE ProfileSource,
00208 IN KAFFINITY Affinity
00209 )
00210
00211
00212
00213
00214
00215
00216
00217
00218
00219
00220
00221
00222
00223
00224
00225
00226
00227
00228
00229
00230
00231
00232
00233
00234
00235
00236
00237
00238
00239
00240
00241
00242
00243
00244
00245
00246
00247
00248
00249
00250
00251
00252
00253
00254
00255
00256
00257
00258
00259 {
00260
00261
PEPROFILE Profile;
00262 HANDLE
Handle;
00263
KPROCESSOR_MODE PreviousMode;
00264
NTSTATUS Status;
00265
PEPROCESS ProcessAddress;
00266 OBJECT_ATTRIBUTES
ObjectAttributes;
00267 BOOLEAN HasPrivilege =
FALSE;
00268 ULONG Segment =
FALSE;
00269
USHORT PowerOf2;
00270
00271
00272
00273
00274
00275
if (
BufferSize == 0) {
00276
return STATUS_INVALID_PARAMETER_7;
00277 }
00278
00279
#ifdef i386
00280
00281
00282
00283
00284
00285
00286
00287
if ((BucketSize == 0) && (RangeBase < (PVOID)(64 * 1024))) {
00288
00289
if (
BufferSize <
sizeof(ULONG)) {
00290
return STATUS_INVALID_PARAMETER_7;
00291 }
00292
00293 Segment = (ULONG)RangeBase;
00294 RangeBase = 0;
00295 BucketSize = RangeSize / (
BufferSize /
sizeof(ULONG));
00296
00297
00298
00299
00300 PowerOf2 = 0;
00301 BucketSize = BucketSize - 1;
00302
while (BucketSize >>= 1) {
00303 PowerOf2++;
00304 }
00305
00306 BucketSize = PowerOf2 + 1;
00307
00308
if (BucketSize < 2) {
00309 BucketSize = 2;
00310 }
00311 }
00312
#endif
00313
00314
if ((BucketSize > 31) || (BucketSize < 2)) {
00315
return STATUS_INVALID_PARAMETER;
00316 }
00317
00318
if ((RangeSize >> (BucketSize - 2)) >
BufferSize) {
00319
return STATUS_BUFFER_TOO_SMALL;
00320 }
00321
00322
if (((ULONG_PTR)RangeBase + RangeSize) < RangeSize) {
00323
return STATUS_BUFFER_OVERFLOW;
00324 }
00325
00326
00327
00328
00329
00330
00331
00332
00333
try {
00334
00335
00336
00337
00338
00339 PreviousMode = KeGetPreviousMode ();
00340
00341
if (PreviousMode !=
KernelMode) {
00342
ProbeForWriteHandle(ProfileHandle);
00343
00344
ProbeForWrite(
Buffer,
00345
BufferSize,
00346
sizeof(ULONG));
00347 }
00348
00349
00350
00351
00352
00353
00354
00355 } except (
EXCEPTION_EXECUTE_HANDLER) {
00356
return GetExceptionCode();
00357 }
00358
00359
00360
00361
00362
00363
00364
00365
00366
00367
00368
00369
00370
00371
00372
00373
00374
00375
00376
00377
00378
00379
00380
00381
if (!ARGUMENT_PRESENT(Process)) {
00382
00383
00384
00385
00386
00387
if (Segment) {
00388
return STATUS_INVALID_PARAMETER;
00389 }
00390
00391
00392
00393
00394
00395
00396
if (RangeBase <= MM_HIGHEST_USER_ADDRESS) {
00397
00398
00399
00400
00401
00402
00403
if (PreviousMode !=
KernelMode) {
00404 HasPrivilege =
SeSinglePrivilegeCheck(
00405
SeSystemProfilePrivilege,
00406 PreviousMode
00407 );
00408
00409
if (!HasPrivilege) {
00410
#if DBG
00411
DbgPrint(
"SeSystemProfilePrivilege needed to profile all USER addresses.\n");
00412
#endif //DBG
00413
return( STATUS_PRIVILEGE_NOT_HELD );
00414 }
00415
00416 }
00417 }
00418
00419 ProcessAddress =
NULL;
00420
00421
00422 }
else {
00423
00424
00425
00426
00427
00428
Status =
ObReferenceObjectByHandle ( Process,
00429 PROCESS_QUERY_INFORMATION,
00430
PsProcessType,
00431 PreviousMode,
00432 (PVOID *)&ProcessAddress,
00433
NULL );
00434
00435
if (!
NT_SUCCESS(
Status)) {
00436
return Status;
00437 }
00438 }
00439
00440 InitializeObjectAttributes( &
ObjectAttributes,
00441
NULL,
00442 OBJ_EXCLUSIVE,
00443
NULL,
00444
NULL );
00445
00446
Status =
ObCreateObject(
KernelMode,
00447
ExProfileObjectType,
00448 &
ObjectAttributes,
00449 PreviousMode,
00450
NULL,
00451
sizeof(
EPROFILE),
00452 0,
00453
sizeof(
EPROFILE) +
sizeof(
KPROFILE),
00454 (PVOID *)&Profile);
00455
00456
00457
00458
00459
00460
if (
NT_SUCCESS(
Status)) {
00461
00462
00463
if (ProcessAddress !=
NULL) {
00464 Profile->Process = &ProcessAddress->
Pcb;
00465 }
else {
00466 Profile->Process =
NULL;
00467 }
00468
00469 Profile->RangeBase = RangeBase;
00470 Profile->RangeSize = RangeSize;
00471 Profile->Buffer =
Buffer;
00472 Profile->BufferSize =
BufferSize;
00473 Profile->BucketSize = BucketSize;
00474 Profile->LockedBufferAddress =
NULL;
00475 Profile->Segment = Segment;
00476 Profile->ProfileSource = ProfileSource;
00477 Profile->Affinity = Affinity;
00478
00479
Status =
ObInsertObject(Profile,
00480
NULL,
00481 PROFILE_CONTROL,
00482 0,
00483 (PVOID *)
NULL,
00484 &
Handle);
00485
00486
00487
00488
00489
00490
00491
00492
if (
NT_SUCCESS(
Status)) {
00493
try {
00494 *ProfileHandle =
Handle;
00495 } except(
EXCEPTION_EXECUTE_HANDLER) {
00496 }
00497 }
00498 }
00499
00500
00501
00502
00503
if (!
NT_SUCCESS(
Status)) {
00504
if (ProcessAddress !=
NULL) {
00505
ObDereferenceObject ((PVOID)ProcessAddress);
00506 }
00507 }
00508
00509
00510
00511
00512
00513
return Status;
00514 }
00515
00516
NTSTATUS
00517 NtStartProfile (
00518 IN HANDLE ProfileHandle
00519 )
00520
00521
00522
00523
00524
00525
00526
00527
00528
00529
00530
00531
00532
00533
00534
00535
00536
00537
00538
00539
00540 {
00541
00542
KPROCESSOR_MODE PreviousMode;
00543
NTSTATUS Status;
00544
PEPROFILE Profile;
00545
PKPROFILE ProfileObject;
00546 PVOID LockedVa;
00547 BOOLEAN State;
00548
00549 PreviousMode = KeGetPreviousMode();
00550
00551
Status =
ObReferenceObjectByHandle( ProfileHandle,
00552 PROFILE_CONTROL,
00553
ExProfileObjectType,
00554 PreviousMode,
00555 (PVOID *)&Profile,
00556
NULL);
00557
if (!
NT_SUCCESS(
Status)) {
00558
return Status;
00559 }
00560
00561
00562
00563
00564
00565
00566
KeWaitForSingleObject( &
ExpProfileStateMutex,
00567
Executive,
00568
KernelMode,
00569
FALSE,
00570 (PLARGE_INTEGER)
NULL);
00571
00572
00573
00574
00575
00576
if (Profile->LockedBufferAddress !=
NULL) {
00577
KeReleaseMutex (&
ExpProfileStateMutex,
FALSE);
00578
ObDereferenceObject ((PVOID)Profile);
00579
return STATUS_PROFILING_NOT_STOPPED;
00580 }
00581
00582
if (
ExpCurrentProfileUsage ==
ACTIVE_PROFILE_LIMIT) {
00583
KeReleaseMutex (&
ExpProfileStateMutex,
FALSE);
00584
ObDereferenceObject ((PVOID)Profile);
00585
return STATUS_PROFILING_AT_LIMIT;
00586 }
00587
00588
ProfileObject =
ExAllocatePoolWithTag (
NonPagedPool,
00589
MmSizeOfMdl(Profile->Buffer,
00590 Profile->BufferSize) +
00591
sizeof(
KPROFILE),
00592 'forP');
00593
00594
if (
ProfileObject ==
NULL) {
00595
KeReleaseMutex (&
ExpProfileStateMutex,
FALSE);
00596
ObDereferenceObject ((PVOID)Profile);
00597
return STATUS_INSUFFICIENT_RESOURCES;
00598 }
00599
00600 Profile->Mdl = (
PMDL)(
ProfileObject + 1);
00601 Profile->ProfileObject =
ProfileObject;
00602
00603
00604
00605
00606
00607
MmInitializeMdl(Profile->Mdl, Profile->Buffer, Profile->BufferSize);
00608
00609
try {
00610
00611 LockedVa =
NULL;
00612
00613
MmProbeAndLockPages (Profile->Mdl,
00614 PreviousMode,
00615
IoWriteAccess );
00616
00617 LockedVa = (PVOID)43;
00618
00619 LockedVa =
MmMapLockedPagesSpecifyCache (Profile->Mdl,
00620
KernelMode,
00621
MmCached,
00622
NULL,
00623
FALSE,
00624
NormalPagePriority);
00625
00626 } except (
EXCEPTION_EXECUTE_HANDLER) {
00627
00628
if (LockedVa == (PVOID)43 ) {
00629
MmUnlockPages (Profile->Mdl);
00630 }
00631
ExFreePool (
ProfileObject);
00632
KeReleaseMutex (&
ExpProfileStateMutex,
FALSE);
00633
ObDereferenceObject ((PVOID)Profile);
00634
return GetExceptionCode();
00635 }
00636
00637
if (LockedVa ==
NULL) {
00638
MmUnlockPages (Profile->Mdl);
00639
ExFreePool (
ProfileObject);
00640
KeReleaseMutex (&
ExpProfileStateMutex,
FALSE);
00641
ObDereferenceObject ((PVOID)Profile);
00642
return STATUS_INSUFFICIENT_RESOURCES;
00643 }
00644
00645
00646
00647
00648
00649
KeInitializeProfile (
ProfileObject,
00650 Profile->Process,
00651 Profile->RangeBase,
00652 Profile->RangeSize,
00653 Profile->BucketSize,
00654 Profile->Segment,
00655 Profile->ProfileSource,
00656 Profile->Affinity);
00657
try {
00658 State =
KeStartProfile (
ProfileObject, LockedVa);
00659
ASSERT (State !=
FALSE);
00660
00661 } except (
EXCEPTION_EXECUTE_HANDLER) {
00662
00663
MmUnlockPages (Profile->Mdl);
00664
MmUnmapLockedPages (LockedVa, Profile->Mdl);
00665
ExFreePool (
ProfileObject);
00666
KeReleaseMutex (&
ExpProfileStateMutex,
FALSE);
00667
ObDereferenceObject ((PVOID)Profile);
00668
return GetExceptionCode();
00669 }
00670
00671 Profile->LockedBufferAddress = LockedVa;
00672
00673
KeReleaseMutex (&
ExpProfileStateMutex,
FALSE);
00674
ObDereferenceObject ((PVOID)Profile);
00675
00676
return STATUS_SUCCESS;
00677 }
00678
00679
NTSTATUS
00680 NtStopProfile (
00681 IN HANDLE ProfileHandle
00682 )
00683
00684
00685
00686
00687
00688
00689
00690
00691
00692
00693
00694
00695
00696
00697
00698
00699
00700
00701
00702
00703 {
00704
00705
PEPROFILE Profile;
00706
KPROCESSOR_MODE PreviousMode;
00707
NTSTATUS Status;
00708 BOOLEAN State;
00709
00710 PreviousMode = KeGetPreviousMode();
00711
00712
Status =
ObReferenceObjectByHandle( ProfileHandle,
00713 PROFILE_CONTROL,
00714
ExProfileObjectType,
00715 PreviousMode,
00716 (PVOID *)&Profile,
00717
NULL);
00718
00719
if (!
NT_SUCCESS(
Status)) {
00720
return Status;
00721 }
00722
00723
KeWaitForSingleObject( &
ExpProfileStateMutex,
00724
Executive,
00725
KernelMode,
00726
FALSE,
00727 (PLARGE_INTEGER)
NULL);
00728
00729
00730
00731
00732
00733
if (Profile->LockedBufferAddress ==
NULL) {
00734
KeReleaseMutex (&
ExpProfileStateMutex,
FALSE);
00735
ObDereferenceObject ((PVOID)Profile);
00736
return STATUS_PROFILING_NOT_STARTED;
00737 }
00738
00739
00740
00741
00742
00743 State =
KeStopProfile (Profile->ProfileObject);
00744
ASSERT (State !=
FALSE);
00745
00746
MmUnmapLockedPages (Profile->LockedBufferAddress, Profile->Mdl);
00747
MmUnlockPages (Profile->Mdl);
00748
ExFreePool (Profile->ProfileObject);
00749 Profile->LockedBufferAddress =
NULL;
00750
KeReleaseMutex (&
ExpProfileStateMutex,
FALSE);
00751
00752
ObDereferenceObject ((PVOID)Profile);
00753
return STATUS_SUCCESS;
00754 }
00755
00756
NTSTATUS
00757 NtSetIntervalProfile (
00758 IN ULONG Interval,
00759 IN KPROFILE_SOURCE Source
00760 )
00761
00762
00763
00764
00765
00766
00767
00768
00769
00770
00771
00772
00773
00774
00775
00776
00777
00778
00779
00780
00781 {
00782
00783
KeSetIntervalProfile (Interval, Source);
00784
return STATUS_SUCCESS;
00785 }
00786
00787
NTSTATUS
00788 NtQueryIntervalProfile (
00789 IN KPROFILE_SOURCE ProfileSource,
00790 OUT PULONG Interval
00791 )
00792
00793
00794
00795
00796
00797
00798
00799
00800
00801
00802
00803
00804
00805
00806
00807
00808
00809
00810
00811
00812 {
00813 ULONG CapturedInterval;
00814
KPROCESSOR_MODE PreviousMode;
00815
00816 PreviousMode = KeGetPreviousMode ();
00817
if (PreviousMode !=
KernelMode) {
00818
00819
00820
00821
00822
00823
try {
00824
ProbeForWriteUlong (Interval);
00825
00826 } except (
EXCEPTION_EXECUTE_HANDLER) {
00827
00828
00829
00830
00831
00832
00833
00834
return GetExceptionCode();
00835 }
00836 }
00837
00838 CapturedInterval =
KeQueryIntervalProfile (ProfileSource);
00839
00840
try {
00841 *Interval = CapturedInterval;
00842
00843 } except (
EXCEPTION_EXECUTE_HANDLER) {
00844 NOTHING;
00845 }
00846
00847
return STATUS_SUCCESS;
00848 }
00849
00850
NTSTATUS
00851 NtQueryPerformanceCounter (
00852 OUT PLARGE_INTEGER PerformanceCounter,
00853 OUT PLARGE_INTEGER PerformanceFrequency OPTIONAL
00854 )
00855
00856
00857
00858
00859
00860
00861
00862
00863
00864
00865
00866
00867
00868
00869
00870
00871
00872
00873
00874
00875
00876
00877
00878
00879
00880
00881
00882 {
00883
KPROCESSOR_MODE PreviousMode;
00884 LARGE_INTEGER KernelPerformanceFrequency;
00885
00886 PreviousMode = KeGetPreviousMode();
00887
if (PreviousMode !=
KernelMode) {
00888
00889
00890
00891
00892
00893
try {
00894
ProbeForWrite ( PerformanceCounter,
00895
sizeof (LARGE_INTEGER),
00896
sizeof (ULONG)
00897 );
00898
00899
if (ARGUMENT_PRESENT(PerformanceFrequency)) {
00900
ProbeForWrite ( PerformanceFrequency,
00901
sizeof (LARGE_INTEGER),
00902
sizeof (ULONG)
00903 );
00904 }
00905
00906 } except (
EXCEPTION_EXECUTE_HANDLER) {
00907
00908
00909
00910
00911
00912
00913
00914
return GetExceptionCode();
00915 }
00916 }
00917
00918
try {
00919 *PerformanceCounter =
KeQueryPerformanceCounter (
00920 (PLARGE_INTEGER)&KernelPerformanceFrequency );
00921
if (ARGUMENT_PRESENT(PerformanceFrequency)) {
00922 *PerformanceFrequency = KernelPerformanceFrequency;
00923 }
00924 } except (
EXCEPTION_EXECUTE_HANDLER) {
00925
return GetExceptionCode();
00926 }
00927
00928
return STATUS_SUCCESS;
00929 }