[15551] | 1 | ; $Id: SUPDrvA-win.asm 98103 2023-01-17 14:15:46Z vboxsync $
|
---|
| 2 | ;; @file
|
---|
| 3 | ; VirtualBox Support Driver - Windows NT specific assembly parts.
|
---|
| 4 | ;
|
---|
| 5 |
|
---|
| 6 | ;
|
---|
[98103] | 7 | ; Copyright (C) 2006-2023 Oracle and/or its affiliates.
|
---|
[15551] | 8 | ;
|
---|
[96407] | 9 | ; This file is part of VirtualBox base platform packages, as
|
---|
| 10 | ; available from https://www.virtualbox.org.
|
---|
[15551] | 11 | ;
|
---|
[96407] | 12 | ; This program is free software; you can redistribute it and/or
|
---|
| 13 | ; modify it under the terms of the GNU General Public License
|
---|
| 14 | ; as published by the Free Software Foundation, in version 3 of the
|
---|
| 15 | ; License.
|
---|
| 16 | ;
|
---|
| 17 | ; This program is distributed in the hope that it will be useful, but
|
---|
| 18 | ; WITHOUT ANY WARRANTY; without even the implied warranty of
|
---|
| 19 | ; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
|
---|
| 20 | ; General Public License for more details.
|
---|
| 21 | ;
|
---|
| 22 | ; You should have received a copy of the GNU General Public License
|
---|
| 23 | ; along with this program; if not, see <https://www.gnu.org/licenses>.
|
---|
| 24 | ;
|
---|
[15551] | 25 | ; The contents of this file may alternatively be used under the terms
|
---|
| 26 | ; of the Common Development and Distribution License Version 1.0
|
---|
[96407] | 27 | ; (CDDL), a copy of it is provided in the "COPYING.CDDL" file included
|
---|
| 28 | ; in the VirtualBox distribution, in which case the provisions of the
|
---|
[15551] | 29 | ; CDDL are applicable instead of those of the GPL.
|
---|
| 30 | ;
|
---|
| 31 | ; You may elect to license modified versions of this file under the
|
---|
| 32 | ; terms and conditions of either the GPL or the CDDL or both.
|
---|
| 33 | ;
|
---|
[96407] | 34 | ; SPDX-License-Identifier: GPL-3.0-only OR CDDL-1.0
|
---|
| 35 | ;
|
---|
[15551] | 36 |
|
---|
| 37 | ;*******************************************************************************
|
---|
| 38 | ;* Header Files *
|
---|
| 39 | ;*******************************************************************************
|
---|
[25336] | 40 | %include "iprt/asmdefs.mac"
|
---|
[15551] | 41 |
|
---|
| 42 | BEGINCODE
|
---|
| 43 |
|
---|
[51789] | 44 | %ifdef VBOX_WITH_HARDENING
|
---|
| 45 |
|
---|
| 46 | %ifdef RT_ARCH_X86
|
---|
[51770] | 47 | ;
|
---|
| 48 | ; Faking up ZwQueryVirtualMemory on XP and W2K3 where it's not exported.
|
---|
[51958] | 49 | ; Using ZwOpenFile as a helper as it has the name number of parameters.
|
---|
[51770] | 50 | ;
|
---|
[51958] | 51 | extern IMPNAME(ZwOpenFile@24)
|
---|
[51770] | 52 |
|
---|
| 53 | BEGINPROC supdrvNtQueryVirtualMemory_Xxx
|
---|
[51789] | 54 | %macro NtQueryVirtualMemorySyscall 1
|
---|
| 55 | GLOBALNAME supdrvNtQueryVirtualMemory_ %+ %1
|
---|
[51770] | 56 | mov eax, %1
|
---|
| 57 | jmp supdrvNtQueryVirtualMemory_Jump
|
---|
[51789] | 58 | %endm
|
---|
[51770] | 59 | NtQueryVirtualMemorySyscall 0xAF
|
---|
| 60 | NtQueryVirtualMemorySyscall 0xB0
|
---|
| 61 | NtQueryVirtualMemorySyscall 0xB1
|
---|
| 62 | NtQueryVirtualMemorySyscall 0xB2
|
---|
| 63 | NtQueryVirtualMemorySyscall 0xB3
|
---|
| 64 | NtQueryVirtualMemorySyscall 0xB4
|
---|
| 65 | NtQueryVirtualMemorySyscall 0xB5
|
---|
| 66 | NtQueryVirtualMemorySyscall 0xB6
|
---|
| 67 | NtQueryVirtualMemorySyscall 0xB7
|
---|
| 68 | NtQueryVirtualMemorySyscall 0xB8
|
---|
| 69 | NtQueryVirtualMemorySyscall 0xB9
|
---|
| 70 | NtQueryVirtualMemorySyscall 0xBA
|
---|
| 71 | NtQueryVirtualMemorySyscall 0xBB
|
---|
| 72 | NtQueryVirtualMemorySyscall 0xBC
|
---|
| 73 | NtQueryVirtualMemorySyscall 0xBD
|
---|
| 74 | NtQueryVirtualMemorySyscall 0xBE
|
---|
| 75 |
|
---|
| 76 | supdrvNtQueryVirtualMemory_Jump:
|
---|
[51958] | 77 | mov edx, IMP2(ZwOpenFile@24)
|
---|
[51770] | 78 | lea edx, [edx + 5]
|
---|
| 79 | jmp edx
|
---|
| 80 | ENDPROC supdrvNtQueryVirtualMemory_Xxx
|
---|
| 81 |
|
---|
[51789] | 82 | %endif
|
---|
[51770] | 83 |
|
---|
[51789] | 84 | %ifdef RT_ARCH_AMD64
|
---|
[51770] | 85 | ;
|
---|
| 86 | ; Faking up ZwQueryVirtualMemory on XP64 and W2K3-64 where it's not exported.
|
---|
| 87 | ; The C code locates and verifies the essentials in ZwRequestWaitReplyPort.
|
---|
| 88 | ;
|
---|
| 89 | extern NAME(g_pfnKiServiceLinkage)
|
---|
| 90 | extern NAME(g_pfnKiServiceInternal)
|
---|
| 91 | BEGINPROC supdrvNtQueryVirtualMemory_Xxx
|
---|
[51789] | 92 | %macro NtQueryVirtualMemorySyscall 1
|
---|
| 93 | GLOBALNAME supdrvNtQueryVirtualMemory_ %+ %1
|
---|
[51770] | 94 | mov eax, %1
|
---|
| 95 | jmp supdrvNtQueryVirtualMemory_Jump
|
---|
[51789] | 96 | %endm
|
---|
[51770] | 97 |
|
---|
| 98 | NtQueryVirtualMemorySyscall 0x1F
|
---|
| 99 | NtQueryVirtualMemorySyscall 0x20
|
---|
| 100 | NtQueryVirtualMemorySyscall 0x21
|
---|
| 101 | NtQueryVirtualMemorySyscall 0x22
|
---|
| 102 | NtQueryVirtualMemorySyscall 0x23
|
---|
| 103 |
|
---|
| 104 | supdrvNtQueryVirtualMemory_Jump:
|
---|
| 105 | cli
|
---|
| 106 | mov r10, rsp ; save call frame pointer.
|
---|
| 107 | mov r11, [NAME(g_pfnKiServiceLinkage) wrt rip]
|
---|
| 108 | push 0
|
---|
| 109 | push 0
|
---|
| 110 | push r10 ; call frame pointer (incoming rsp).
|
---|
| 111 | pushfq
|
---|
| 112 | push 10h
|
---|
| 113 | push r11 ; r11 = KiServiceLinkage (ret w/ unwind info)
|
---|
| 114 | jmp qword [NAME(g_pfnKiServiceInternal) wrt rip]
|
---|
| 115 | ENDPROC supdrvNtQueryVirtualMemory_Xxx
|
---|
[51789] | 116 | %endif
|
---|
[51770] | 117 |
|
---|
[51789] | 118 | %endif ; VBOX_WITH_HARDENING
|
---|
| 119 |
|
---|