ReactOS  r75619
obref.c File Reference
#include <ntoskrnl.h>
#include <debug.h>
Include dependency graph for obref.c:

Go to the source code of this file.

Macros

#define NDEBUG
 

Functions

BOOLEAN FASTCALL ObReferenceObjectSafe (IN PVOID Object)
 
VOID NTAPI ObpDeferObjectDeletion (IN POBJECT_HEADER Header)
 
LONG FASTCALL ObReferenceObjectEx (IN PVOID Object, IN LONG Count)
 
LONG FASTCALL ObDereferenceObjectEx (IN PVOID Object, IN LONG Count)
 
VOID FASTCALL ObInitializeFastReference (IN PEX_FAST_REF FastRef, IN PVOID Object OPTIONAL)
 
PVOID FASTCALL ObFastReferenceObjectLocked (IN PEX_FAST_REF FastRef)
 
PVOID FASTCALL ObFastReferenceObject (IN PEX_FAST_REF FastRef)
 
VOID FASTCALL ObFastDereferenceObject (IN PEX_FAST_REF FastRef, IN PVOID Object)
 
PVOID FASTCALL ObFastReplaceObject (IN PEX_FAST_REF FastRef, PVOID Object)
 
LONG_PTR FASTCALL ObfReferenceObject (IN PVOID Object)
 
LONG_PTR FASTCALL ObfDereferenceObject (IN PVOID Object)
 
VOID NTAPI ObDereferenceObjectDeferDelete (IN PVOID Object)
 
VOID NTAPI ObDereferenceObject (IN PVOID Object)
 
NTSTATUS NTAPI ObReferenceObjectByPointer (IN PVOID Object, IN ACCESS_MASK DesiredAccess, IN POBJECT_TYPE ObjectType, IN KPROCESSOR_MODE AccessMode)
 
NTSTATUS NTAPI ObReferenceObjectByName (IN PUNICODE_STRING ObjectPath, IN ULONG Attributes, IN PACCESS_STATE PassedAccessState, IN ACCESS_MASK DesiredAccess, IN POBJECT_TYPE ObjectType, IN KPROCESSOR_MODE AccessMode, IN OUT PVOID ParseContext, OUT PVOID *ObjectPtr)
 
NTSTATUS NTAPI ObReferenceObjectByHandle (IN HANDLE Handle, IN ACCESS_MASK DesiredAccess, IN POBJECT_TYPE ObjectType, IN KPROCESSOR_MODE AccessMode, OUT PVOID *Object, OUT POBJECT_HANDLE_INFORMATION HandleInformation OPTIONAL)
 

Macro Definition Documentation

#define NDEBUG

Definition at line 15 of file obref.c.

Function Documentation

VOID NTAPI ObDereferenceObject ( IN PVOID  Object)

Definition at line 267 of file obref.c.

Referenced by _Function_class_(), _Success_(), add_device(), AdvancedErrorChecks(), AfdAccept(), AfdCloseSocket(), AfdEnumEvents(), AfdEventSelect(), BasicBehaviorChecks(), BehaviorChecks(), BuildDesktopNameList(), Bus_GetDeviceCapabilities(), calc_thread(), CcpDereferenceCache(), CcpMapData(), CcpReadAhead(), CcpUnmapCache(), CcRosDeleteFileCache(), CcUninitializeCacheMap(), CdCreateInternalStream(), CdDeleteInternalStream(), CdDeleteVcb(), CdfsFCBInitializeCache(), CdfsMountVolume(), CdInvalidateVolumes(), CdMountVolume(), CdReMountOldVcb(), CdRomCreateDeviceObject(), CdUnload(), CdVerifyVolume(), ClassCreateDeviceObject(), ClasspFailurePredict(), CmBattUnload(), CmGetSystemDriverList(), CmpCreateRegistryRoot(), CmpDoCreateChild(), CmpDoOpen(), CmpIsHiveAlreadyLoaded(), CmpOpenHiveFiles(), co_HOOK_CallHooks(), co_IntRegisterLogonProcess(), co_UserCreateWindowEx(), CompBattAddNewBattery(), CompBattRemoveBattery(), Control(), create_snapshot(), CreateGreenFdo(), CreateMixerPinAndSetFormat(), DbgkClearProcessDebugObject(), DbgkOpenProcessDebugPort(), DbgkpCloseObject(), DbgkpFreeDebugEvent(), DbgkpPostFakeProcessCreateMessages(), DbgkpPostFakeThreadMessages(), DbgkpQueueMessage(), DbgkpSetProcessDebugObject(), DecrementGdiHandleCount(), DestroyPortDriver(), disk_arrival(), DiskCreateFdo(), DiskDeviceControl(), DiskSendFailurePredictIoctl(), DispTdiAssociateAddress(), DriverEntry(), DriverUnload(), EngFreeModule(), EngFreeSectionMem(), EngUnmapEvent(), ExFreePoolWithTag(), ExitThreadCallback(), ExpCreateWorkerThread(), ExpDebuggerWorker(), ExpDeleteProfile(), ExpWorkerThreadBalanceManager(), ExRegisterCallback(), ExReturnPoolQuota(), Ext2DestroyVcb(), Ext2FloppyFlush(), Ext2InitializeVcb(), Ext2InvalidateVolumes(), Ext2MountVolume(), Ext2TearDownStream(), ExUnregisterCallback(), FatiCommonClose(), FatUninitializeVcb(), FFSFloppyFlush(), FFSFreeVcb(), FFSInvalidateVolumes(), find_device_from_uuid(), finish_removing_device(), FinishThread(), FltpEnumerateFileSystemVolumes(), FltpGetBaseDeviceObjectName(), FltpIsAttachedToDevice(), flush_thread(), FsRtlNotifyVolumeEvent(), FsRtlTest_StartTest(), GetDeviceId(), GetProcessLuid(), GreenQueryBusRelations(), GspQuery(), GspQueryThreadStatus(), GspSetThread(), HalGetAdapter(), HalPutDmaAdapter(), i8042SendHookWorkItem(), IKsPin_PinMasterClock(), IncrementGdiHandleCount(), InitGdiHandleTable(), InitializeCmdEventInfo(), IntAllowSetForegroundWindow(), IntDesktopObjectDelete(), IntDesktopObjectParse(), IntFreeDesktopHeap(), IntGdiAddFontResource(), IntSetThreadDesktop(), IntTID2PTI(), IntUnmapDesktopView(), invalidate_volumes(), IoAttachDevice(), IoCompletion(), IoCreateDevice(), IoCreateStreamFileObjectEx(), IoDeleteController(), IoDeleteDriver(), IoFreeErrorLogEntry(), IoGetBootDiskInformation(), IopActionInitChildServices(), IopAttachFilterDriversCallback(), IopCancelRemoveDeviceRelations(), IopCleanupAfterException(), IopCleanupFailedIrp(), IopCleanupIrp(), IopCompleteRequest(), IopCreateArcNamesCd(), IopCreateArcNamesDisk(), IopCreateDriver(), IopCreateEvent(), IopCreateFile(), IopDeleteDevice(), IopDeleteFile(), IopDeviceFsIoControl(), IopDeviceRelationsWorker(), IopDeviceStatus(), IopEnumerateDevice(), IopGetDeviceDepth(), IopGetDeviceProperty(), IopGetDeviceRelations(), IopGetFileInformation(), IopGetInterfaceDeviceList(), IopGetRelatedDevice(), IopGetSetSecurityObject(), IopInitializeBootDrivers(), IopInitializeBuiltinDriver(), IopInitializeDevice(), IopInitiatePnpIrp(), IopLoadUnloadDriver(), IopLogWorker(), IopMarkBootPartition(), IopMountVolume(), IopOpenLinkOrRenameTarget(), IopParseDevice(), IopQueryRemoveDeviceRelations(), IopReportTargetDeviceChangeAsyncWorker(), IopResetDevice(), IopSendRemoveDevice(), IopSetDeviceSecurityDescriptors(), IopShutdownBaseFileSystems(), IopSynchronousCall(), IopUnloadDevice(), IopUnloadDriver(), IopUnloadSafeCompletion(), IopWorkItemCallback(), IoRegisterPlugPlayNotification(), IoSetDeviceInterfaceState(), IoShutdownSystem(), IoUnregisterFsRegistrationChange(), IoUnregisterPlugPlayNotification(), IoUnregisterShutdownNotification(), IoVolumeDeviceToDosName(), IoWMIQueryAllData(), IsFtVolume(), IssueUniqueIdChangeNotify(), IssueUniqueIdChangeNotifyWorker(), IsThreadSuspended(), KdbpAttachToProcess(), KdbpAttachToThread(), KdbpCmdProc(), KdbpCmdThread(), KdbpReleaseFileForSymbols(), KdbpSymLoadModuleSymbols(), KdpGdbEnterDebuggerException(), KernelModeTest(), KmtFinishThread(), KsDiscardEvent(), load_chunk_root(), LpcpCopyRequestData(), LpcpCreatePort(), LpcpDeletePort(), LpcpDestroyPortQueue(), LpcpFreeToPortZone(), LpcRequestPort(), LpcRequestWaitReplyPort(), MiQueryMemoryBasicInformation(), MiQueryMemorySectionName(), MmCreateArm3Section(), MmCreateCacheSection(), MmCreateDataFileSection(), MmCreateImageSection(), MmCreatePageFileSection(), MmCreatePhysicalMemorySection(), MmCreateSection(), MmFinalizeSegment(), MmGetFileNameForAddress(), MmLoadSystemImage(), MmPageOutPhysicalAddress(), MmpDeleteSection(), MmpPageOutPhysicalAddress(), MmQuitNextSession(), MmUnloadSystemImage(), MmUnmapViewOfSegment(), mount_vol(), MountMgrNotifyNameChange(), MountMgrVolumeMountPointChanged(), MupCloseUncProvider(), MupDereferenceCcb(), nfs41_DeleteConnection(), NpCancelWaiter(), NpCancelWaitQueueIrp(), NpDeleteEventTableEntry(), NpFreeClientSecurityContext(), NpTimerDispatch(), NtAcceptConnectPort(), NtAccessCheck(), NtAdjustPrivilegesToken(), NtAlertResumeThread(), NtAlertThread(), NtAllocateVirtualMemory(), NtAssignProcessToJobObject(), NtCancelIoFile(), NtClearEvent(), NtCompareTokens(), NtCompleteConnectPort(), NtCreateJobObject(), NtCreatePagingFile(), NtCreateProfile(), NtCreateSymbolicLinkObject(), NtDebugActiveProcess(), NtDebugContinue(), NtDeleteKey(), NtDeleteValueKey(), NtDuplicateObject(), NtDuplicateToken(), NtEnumerateKey(), NtEnumerateValueKey(), NtExtendSection(), NtFlushBuffersFile(), NtFlushInstructionCache(), NtFlushKey(), NtFlushVirtualMemory(), NtFreeVirtualMemory(), NtfsFCBInitializeCache(), NtGetContextThread(), NtGetWriteWatch(), NtImpersonateClientOfPort(), NtImpersonateThread(), NtIsProcessInJob(), NtLoadKeyEx(), NtLockFile(), NtLockVirtualMemory(), NtMakePermanentObject(), NtMakeTemporaryObject(), NtMapViewOfSection(), NtNotifyChangeDirectoryFile(), NtOpenObjectAuditAlarm(), NtOpenProcess(), NtOpenProcessTokenEx(), NtOpenThread(), NtOpenThreadTokenEx(), NtPrivilegeCheck(), NtPrivilegedServiceAuditAlarm(), NtProtectVirtualMemory(), NtPulseEvent(), NtQueryDirectoryFile(), NtQueryDirectoryObject(), NtQueryEvent(), NtQueryInformationFile(), NtQueryInformationProcess(), NtQueryInformationThread(), NtQueryInformationToken(), NtQueryIoCompletion(), NtQueryKey(), NtQueryMutant(), NtQueryObject(), NtQueryOpenSubKeys(), NtQuerySection(), NtQuerySecurityObject(), NtQuerySemaphore(), NtQuerySymbolicLinkObject(), NtQueryTimer(), NtQueryValueKey(), NtQueryVolumeInformationFile(), NtQueueApcThread(), NtReadFile(), NtReadVirtualMemory(), NtRegisterThreadTerminatePort(), NtReleaseMutant(), NtReleaseSemaphore(), NtRemoveIoCompletion(), NtRemoveProcessDebug(), NtReplyPort(), NtReplyWaitReceivePortEx(), NtRequestPort(), NtRequestWaitReplyPort(), NtResetEvent(), NtResetWriteWatch(), NtResumeProcess(), NtResumeThread(), NtSaveKeyEx(), NtSaveMergedKeys(), NtSecureConnectPort(), NtSetContextThread(), NtSetEvent(), NtSetEventBoostPriority(), NtSetHighEventPair(), NtSetHighWaitLowEventPair(), NtSetInformationDebugObject(), NtSetInformationFile(), NtSetInformationObject(), NtSetInformationProcess(), NtSetInformationThread(), NtSetInformationToken(), NtSetIoCompletion(), NtSetLowEventPair(), NtSetLowWaitHighEventPair(), NtSetSecurityObject(), NtSetValueKey(), NtSetVolumeInformationFile(), NtSignalAndWaitForSingleObject(), NtStartProfile(), NtStopProfile(), NtSuspendProcess(), NtSuspendThread(), NtTerminateJobObject(), NtTerminateProcess(), NtTerminateThread(), NtUnloadKey2(), NtUnlockFile(), NtUnlockVirtualMemory(), NtUnmapViewOfSection(), NtUserBuildHwndList(), NtUserChangeClipboardChain(), NtUserCloseDesktop(), NtUserCloseWindowStation(), NtUserConsoleControl(), NtUserCountClipboardFormats(), NtUserCreateDesktop(), NtUserCreateWindowStation(), NtUserGetClipboardData(), NtUserGetClipboardOwner(), NtUserGetClipboardSequenceNumber(), NtUserGetClipboardViewer(), NtUserGetGuiResources(), NtUserGetGUIThreadInfo(), NtUserGetObjectInformation(), NtUserGetOpenClipboardWindow(), NtUserGetPriorityClipboardFormat(), NtUserGetThreadDesktop(), NtUserIsClipboardFormatAvailable(), NtUserLockWindowStation(), NtUserPostThreadMessage(), NtUserProcessConnect(), NtUserQueryInformationThread(), NtUserResolveDesktop(), NtUserSetClipboardViewer(), NtUserSetInformationThread(), NtUserSetShellWindowEx(), NtUserSetWindowsHookEx(), NtUserSetWindowStationUser(), NtUserSetWinEventHook(), NtUserSwitchDesktop(), NtUserUnlockWindowStation(), NtUserWaitForInputIdle(), NtWaitForDebugEvent(), NtWaitForMultipleObjects(), NtWaitForSingleObject(), NtWaitHighEventPair(), NtWaitLowEventPair(), NtWriteFile(), NtWriteVirtualMemory(), ObDereferenceDeviceMap(), ObDuplicateObject(), ObFastDereferenceObject(), ObfDereferenceDeviceMap(), ObInsertObject(), ObOpenObjectByName(), ObOpenObjectByPointer(), ObpCloseHandleTableEntry(), ObpCreateDeviceMap(), ObpCreateHandle(), ObpDeleteNameCheck(), ObpDuplicateHandleCallback(), ObpLookupEntryDirectory(), ObpLookupObjectName(), ObpReleaseLookupContextObject(), ObtClose(), PageFileBehaviorChecks(), PatchKeyboardDriver(), PciGetDeviceCapabilities(), PciQueryForPciBusInterface(), PciSendIoctl(), Pin_fnDeviceIoControl(), Pin_fnWrite(), PopAddRemoveSysCapsCallback(), PopQuerySystemPowerStateTraverse(), PopRequestPowerIrpCompletion(), PopSetSystemPowerState(), PopSetSystemPowerStateTraverse(), PoRequestPowerIrp(), PoRequestShutdownWait(), PsAssignImpersonationToken(), PsDereferenceImpersonationToken(), PsDereferencePrimaryToken(), PsGetNextProcess(), PsGetNextProcessThread(), PsOpenTokenOfProcess(), PspAssignPrimaryToken(), PspCreateProcess(), PspCreateThread(), PspDeleteJob(), PspDeleteProcess(), PspDeleteThread(), PspDeleteThreadSecurity(), PspExitProcess(), PspExitThread(), PspReapRoutine(), PspSetPrimaryToken(), PspSetQuotaLimits(), PsRestoreImpersonation(), PsRevertThreadToSelf(), QSI_DEF(), QueryDeviceInformation(), QuerySuggestedLinkName(), RawInputThreadMain(), RawMountVolume(), RawUnload(), ReconcileThisDatabaseWithMasterWorker(), RegisterForTargetDeviceNotification(), ResetCsrApiPort(), ResetCsrProcess(), RfsdFloppyFlush(), RfsdFreeVcb(), RfsdInvalidateVolumes(), RxpWorkerThreadDispatcher(), RxUnregisterMinirdr(), ScsiClassClaimDevice(), SearchForLegacyDrivers(), SeCreateClientSecurity(), SeCreateClientSecurityFromSubjectContext(), SeDeassignPrimaryToken(), SeLocateProcessImageName(), SendLinkCreated(), SendLinkDeleted(), SendOnlineNotification(), SepAccessCheckAndAuditAlarm(), SepCreateToken(), SepDuplicateToken(), START_TEST(), SysAudio_Shutdown(), SystemProcessTest(), TdiCloseDevice(), test_vol(), TestCreateSection(), TestEventConcurrent(), TestIoCreateFile(), TestLowerDeviceKernelAPI(), TestObjectTypes(), TestObRootSecurity(), TestPhysicalMemorySection(), TestProviderInfo(), TestReference(), TestSharedCacheMap(), TestSymlinks(), TestTcpConnect(), UDFCheckOtherFSByName(), UDFCommonDeviceControl(), UDFInvalidateVolumes(), uninit(), Unload(), UnlockHandles(), USBH_FdoQueryBusRelations(), USBPORT_IsCompanionController(), USBPORT_QueryPciBusInterface(), UserClipboardFreeWindow(), UserClipboardRelease(), UserCloseClipboard(), UserCreateHeap(), UserCreateMenu(), UserDeleteW32Process(), UserEmptyClipboard(), UserEnumClipboardFormats(), UserGetShellWindow(), UserOpenClipboard(), UserSetClipboardData(), UserSetProcessWindowStation(), VerifyEventWaitable(), VfatCleanupFile(), VfatDismountVolume(), vfatFCBInitializeCacheFromVolume(), VfatMount(), VfatSetRenameInformation(), WdmAudControlCloseMixer(), WdmAudControlDeviceState(), WdmAudControlOpenMixer(), WdmAudFrameSize(), WdmAudResetStream(), WmipOpenGuidForEvents(), WmipRegisterGuids(), and xHalQueryDriveLayout().

268 {
269  /* Call the fastcall function */
271 }
LONG_PTR FASTCALL ObfDereferenceObject(IN PVOID Object)
Definition: obref.c:212
static IUnknown Object
Definition: main.c:512
VOID NTAPI ObDereferenceObjectDeferDelete ( IN PVOID  Object)

Definition at line 252 of file obref.c.

Referenced by CmpDoCreateChild(), CmpFlushNotifiesOnKeyBodyList(), IopCompleteRequest(), and ObpDereferenceNameInfo().

253 {
255 
256  /* Check whether the object can now be deleted. */
257  if (!InterlockedDecrement(&Header->PointerCount))
258  {
259  /* Add us to the deferred deletion list */
260  ObpDeferObjectDeletion(Header);
261  }
262 }
LONG PointerCount
Definition: obtypes.h:481
#define OBJECT_TO_OBJECT_HEADER(o)
Definition: obtypes.h:111
VOID NTAPI ObpDeferObjectDeletion(IN POBJECT_HEADER Header)
Definition: obref.c:53
Definition: Header.h:8
static IUnknown Object
Definition: main.c:512
#define InterlockedDecrement
Definition: armddk.h:52
LONG FASTCALL ObDereferenceObjectEx ( IN PVOID  Object,
IN LONG  Count 
)

Definition at line 88 of file obref.c.

Referenced by ExpTimerApcKernelRoutine(), ExTimerRundown(), NtCancelTimer(), NtSetTimer(), ObFastReferenceObject(), ObFastReplaceObject(), and PspCreateThread().

90 {
92  LONG NewCount;
93 
94  /* Extract the object header */
96 
97  /* Check whether the object can now be deleted. */
98  NewCount = InterlockedExchangeAdd(&Header->PointerCount, -Count) - Count;
99  if (!NewCount) ObpDeferObjectDeletion(Header);
100 
101  /* Return the current count */
102  return NewCount;
103 }
_Inout_ __drv_aliasesMem PSLIST_ENTRY _Inout_ PSLIST_ENTRY _In_ ULONG Count
Definition: exfuncs.h:1015
LONG PointerCount
Definition: obtypes.h:481
#define OBJECT_TO_OBJECT_HEADER(o)
Definition: obtypes.h:111
VOID NTAPI ObpDeferObjectDeletion(IN POBJECT_HEADER Header)
Definition: obref.c:53
Definition: Header.h:8
long LONG
Definition: pedump.c:60
#define InterlockedExchangeAdd
Definition: interlocked.h:181
static IUnknown Object
Definition: main.c:512
VOID FASTCALL ObFastDereferenceObject ( IN PEX_FAST_REF  FastRef,
IN PVOID  Object 
)

Definition at line 167 of file obref.c.

Referenced by NtOpenThreadTokenEx(), PspCreateProcess(), PspCreateThread(), PspExitThread(), PspInitializeProcessSecurity(), PspSetPrimaryToken(), SeIsTokenChild(), and SeReleaseSubjectContext().

169 {
170  /* Release a fast reference. If this failed, use the slow path */
172 }
VOID NTAPI ObDereferenceObject(IN PVOID Object)
Definition: obref.c:267
static IUnknown Object
Definition: main.c:512
FORCEINLINE BOOLEAN ExReleaseFastReference(IN PEX_FAST_REF FastRef, IN PVOID Object)
Definition: ex.h:625
PVOID FASTCALL ObFastReferenceObject ( IN PEX_FAST_REF  FastRef)

Definition at line 132 of file obref.c.

Referenced by PsReferenceEffectiveToken(), and PsReferencePrimaryToken().

133 {
134  EX_FAST_REF OldValue;
136  PVOID Object;
137 
138  /* Reference the object and get it pointer */
139  OldValue = ExAcquireFastReference(FastRef);
140  Object = ExGetObjectFastReference(OldValue);
141 
142  /* Check how many references are left */
143  Count = ExGetCountFastReference(OldValue);
144 
145  /* Check if the reference count is over 1 */
146  if (Count > 1) return Object;
147 
148  /* Check if the reference count has reached 0 */
149  if (!Count) return NULL;
150 
151  /* Otherwise, reference the object 7 times */
153 
154  /* Now update the reference count */
155  if (!ExInsertFastReference(FastRef, Object))
156  {
157  /* We failed: completely dereference the object */
159  }
160 
161  /* Return the Object */
162  return Object;
163 }
DWORD *typedef PVOID
Definition: winlogon.h:52
LONG FASTCALL ObReferenceObjectEx(IN PVOID Object, IN LONG Count)
Definition: obref.c:77
FORCEINLINE PVOID ExGetObjectFastReference(IN EX_FAST_REF FastRef)
Definition: ex.h:520
FORCEINLINE BOOLEAN ExInsertFastReference(IN OUT PEX_FAST_REF FastRef, IN PVOID Object)
Definition: ex.h:586
_Inout_ __drv_aliasesMem PSLIST_ENTRY _Inout_ PSLIST_ENTRY _In_ ULONG Count
Definition: exfuncs.h:1015
uint32_t ULONG_PTR
Definition: typedefs.h:64
FORCEINLINE EX_FAST_REF ExAcquireFastReference(IN OUT PEX_FAST_REF FastRef)
Definition: ex.h:557
smooth NULL
Definition: ftsmooth.c:513
LONG FASTCALL ObDereferenceObjectEx(IN PVOID Object, IN LONG Count)
Definition: obref.c:88
FORCEINLINE ULONG ExGetCountFastReference(IN EX_FAST_REF FastRef)
Definition: ex.h:528
static IUnknown Object
Definition: main.c:512
#define MAX_FAST_REFS
Definition: ex.h:118
PVOID FASTCALL ObFastReferenceObjectLocked ( IN PEX_FAST_REF  FastRef)

Definition at line 119 of file obref.c.

Referenced by PsReferenceEffectiveToken(), and PsReferencePrimaryToken().

120 {
121  PVOID Object;
122  EX_FAST_REF OldValue = *FastRef;
123 
124  /* Get the object and reference it slowly */
125  Object = ExGetObjectFastReference(OldValue);
126  if (Object) ObReferenceObject(Object);
127  return Object;
128 }
DWORD *typedef PVOID
Definition: winlogon.h:52
FORCEINLINE PVOID ExGetObjectFastReference(IN EX_FAST_REF FastRef)
Definition: ex.h:520
static IUnknown Object
Definition: main.c:512
#define ObReferenceObject
Definition: obfuncs.h:204
PVOID FASTCALL ObFastReplaceObject ( IN PEX_FAST_REF  FastRef,
PVOID  Object 
)

Definition at line 176 of file obref.c.

178 {
179  EX_FAST_REF OldValue;
180  PVOID OldObject;
181  ULONG Count;
182 
183  /* Check if we were given an object and reference it 7 times */
185 
186  /* Do the swap */
187  OldValue = ExSwapFastReference(FastRef, Object);
188  OldObject = ExGetObjectFastReference(OldValue);
189 
190  /* Check if we had an active object and dereference it */
191  Count = ExGetCountFastReference(OldValue);
192  if ((OldObject) && (Count)) ObDereferenceObjectEx(OldObject, Count);
193 
194  /* Return the old object */
195  return OldObject;
196 }
DWORD *typedef PVOID
Definition: winlogon.h:52
LONG FASTCALL ObReferenceObjectEx(IN PVOID Object, IN LONG Count)
Definition: obref.c:77
FORCEINLINE PVOID ExGetObjectFastReference(IN EX_FAST_REF FastRef)
Definition: ex.h:520
_Inout_ __drv_aliasesMem PSLIST_ENTRY _Inout_ PSLIST_ENTRY _In_ ULONG Count
Definition: exfuncs.h:1015
FORCEINLINE EX_FAST_REF ExSwapFastReference(IN PEX_FAST_REF FastRef, IN PVOID Object)
Definition: ex.h:660
LONG FASTCALL ObDereferenceObjectEx(IN PVOID Object, IN LONG Count)
Definition: obref.c:88
FORCEINLINE ULONG ExGetCountFastReference(IN EX_FAST_REF FastRef)
Definition: ex.h:528
static IUnknown Object
Definition: main.c:512
unsigned int ULONG
Definition: retypes.h:1
#define MAX_FAST_REFS
Definition: ex.h:118
LONG_PTR FASTCALL ObfDereferenceObject ( IN PVOID  Object)

Definition at line 212 of file obref.c.

Referenced by DriverEntry(), FltpClientPortDelete(), FltpDetachFromFileSystemDevice(), FltpSetupCommunicationObjects(), ObDereferenceObject(), PopProcessShutDownLists(), RawCheckForDismount(), VfatCheckForDismount(), and WmipOpenGuidObject().

213 {
215  LONG_PTR OldCount;
216 
217  /* Extract the object header */
219 
220  if (Header->PointerCount < Header->HandleCount)
221  {
222  DPRINT1("Misbehaving object: %wZ\n", &Header->Type->Name);
223  return Header->PointerCount;
224  }
225 
226  /* Check whether the object can now be deleted. */
227  OldCount = InterlockedDecrement(&Header->PointerCount);
228  if (!OldCount)
229  {
230  /* Sanity check */
231  ASSERT(Header->HandleCount == 0);
232 
233  /* Check if APCs are still active */
234  if (!KeAreAllApcsDisabled())
235  {
236  /* Remove the object */
238  }
239  else
240  {
241  /* Add us to the deferred deletion list */
242  ObpDeferObjectDeletion(Header);
243  }
244  }
245 
246  /* Return the old count */
247  return OldCount;
248 }
BOOLEAN NTAPI KeAreAllApcsDisabled(VOID)
Definition: apc.c:985
ASSERT((InvokeOnSuccess||InvokeOnError||InvokeOnCancel)?(CompletionRoutine!=NULL):TRUE)
LONG PointerCount
Definition: obtypes.h:481
#define OBJECT_TO_OBJECT_HEADER(o)
Definition: obtypes.h:111
VOID NTAPI ObpDeferObjectDeletion(IN POBJECT_HEADER Header)
Definition: obref.c:53
#define FALSE
Definition: types.h:117
Definition: Header.h:8
VOID NTAPI ObpDeleteObject(IN PVOID Object, IN BOOLEAN CalledFromWorkerThread)
Definition: oblife.c:148
LONG HandleCount
Definition: obtypes.h:484
static IUnknown Object
Definition: main.c:512
#define InterlockedDecrement
Definition: armddk.h:52
__int3264 LONG_PTR
Definition: mstsclib_h.h:276
#define DPRINT1
Definition: precomp.h:8
UNICODE_STRING Name
Definition: obtypes.h:383
POBJECT_TYPE Type
Definition: obtypes.h:487
LONG_PTR FASTCALL ObfReferenceObject ( IN PVOID  Object)

Definition at line 202 of file obref.c.

203 {
204  ASSERT(Object);
205 
206  /* Get the header and increment the reference count */
207  return InterlockedIncrement(&OBJECT_TO_OBJECT_HEADER(Object)->PointerCount);
208 }
ASSERT((InvokeOnSuccess||InvokeOnError||InvokeOnCancel)?(CompletionRoutine!=NULL):TRUE)
#define OBJECT_TO_OBJECT_HEADER(o)
Definition: obtypes.h:111
static IUnknown Object
Definition: main.c:512
#define InterlockedIncrement
Definition: armddk.h:53
VOID FASTCALL ObInitializeFastReference ( IN PEX_FAST_REF  FastRef,
IN PVOID Object  OPTIONAL 
)

Definition at line 107 of file obref.c.

Referenced by PspInitializeProcessSecurity(), SeAssignPrimaryToken(), and SepInitializationPhase0().

109 {
110  /* Check if we were given an object and reference it 7 times */
112 
113  /* Setup the fast reference */
115 }
LONG FASTCALL ObReferenceObjectEx(IN PVOID Object, IN LONG Count)
Definition: obref.c:77
FORCEINLINE VOID ExInitializeFastReference(OUT PEX_FAST_REF FastRef, IN OPTIONAL PVOID Object)
Definition: ex.h:536
static IUnknown Object
Definition: main.c:512
#define MAX_FAST_REFS
Definition: ex.h:118
VOID NTAPI ObpDeferObjectDeletion ( IN POBJECT_HEADER  Header)

Definition at line 53 of file obref.c.

Referenced by ObDereferenceObjectDeferDelete(), ObDereferenceObjectEx(), and ObfDereferenceObject().

54 {
55  PVOID Entry;
56 
57  /* Loop while trying to update the list */
58  do
59  {
60  /* Get the current entry */
61  Entry = ObpReaperList;
62 
63  /* Link our object to the list */
64  Header->NextToFree = Entry;
65 
66  /* Update the list */
68  Header,
69  Entry) != Entry);
70 
71  /* Queue the work item if needed */
73 }
DWORD *typedef PVOID
Definition: winlogon.h:52
VOID NTAPI ExQueueWorkItem(IN PWORK_QUEUE_ITEM WorkItem, IN WORK_QUEUE_TYPE QueueType)
Definition: work.c:716
struct _Entry Entry
Definition: kefuncs.h:640
WORK_QUEUE_ITEM ObpReaperWorkItem
Definition: oblife.c:28
Definition: Header.h:8
#define InterlockedCompareExchangePointer
Definition: interlocked.h:129
volatile PVOID ObpReaperList
Definition: oblife.c:29
NTSTATUS NTAPI ObReferenceObjectByHandle ( IN HANDLE  Handle,
IN ACCESS_MASK  DesiredAccess,
IN POBJECT_TYPE  ObjectType,
IN KPROCESSOR_MODE  AccessMode,
OUT PVOID Object,
OUT POBJECT_HANDLE_INFORMATION HandleInformation  OPTIONAL 
)

Definition at line 388 of file obref.c.

Referenced by _IRQL_requires_max_(), _Success_(), add_device(), AdvancedErrorChecks(), AfdAccept(), AfdEnumEvents(), AfdEventSelect(), BasicBehaviorChecks(), BehaviorChecks(), BroadcastOpen(), CdInvalidateVolumes(), CmGetSystemDriverList(), CmpCreateEvent(), CmpCreateRegistryRoot(), CmpIsHiveAlreadyLoaded(), CmpLinkHiveToMaster(), CompBattGetDeviceObjectPointer(), Control(), create_snapshot(), CreateGreenFdo(), CreateMixerPinAndSetFormat(), DispTdiAssociateAddress(), DriverEntry(), EngMapEvent(), ExCreateCallback(), ExpCreateWorkerThread(), ExpInitializeWorkerThreads(), ExpInitNls(), Ext2InvalidateVolumes(), FFSInvalidateVolumes(), FsRtlTest_OpenTestDirectory(), FsRtlTest_OpenTestFile(), GetObjectType(), IKsPin_PinMasterClock(), InitCsrApiPort(), InitThreadCallback(), IntValidateDesktopHandle(), IntValidateWindowStationHandle(), invalidate_volumes(), IopCreateDriver(), IopCreateEvent(), IopDeviceFsIoControl(), IopGetDeviceObjectPointer(), IopMarkBootPartition(), IopOpenLinkOrRenameTarget(), KdbpSymLoadModuleSymbols(), KernelModeTest(), KmtStartThread(), KspEnableEvent(), LockHandles(), LpcpCopyRequestData(), MiCreateMemoryEvent(), MiQueryMemoryBasicInformation(), MiQueryMemorySectionName(), MmCreateArm3Section(), MmCreateSection(), MmLoadSystemImage(), MountMgrVolumeMountPointChanged(), nfs41_DeleteConnection(), NtAccessCheck(), NtAdjustPrivilegesToken(), NtAlertResumeThread(), NtAlertThread(), NtAllocateVirtualMemory(), NtAssignProcessToJobObject(), NtCancelIoFile(), NtCancelTimer(), NtClearEvent(), NtCompareTokens(), NtCompleteConnectPort(), NtCreatePagingFile(), NtCreateProfile(), NtDebugActiveProcess(), NtDebugContinue(), NtDeleteKey(), NtDeleteValueKey(), NtDuplicateObject(), NtDuplicateToken(), NtEnumerateKey(), NtEnumerateValueKey(), NtExtendSection(), NtFlushBuffersFile(), NtFlushInstructionCache(), NtFlushKey(), NtFlushVirtualMemory(), NtFreeVirtualMemory(), NtGetContextThread(), NtGetWriteWatch(), NtImpersonateClientOfPort(), NtImpersonateThread(), NtIsProcessInJob(), NtLoadKeyEx(), NtLockFile(), NtLockVirtualMemory(), NtMakePermanentObject(), NtMakeTemporaryObject(), NtMapViewOfSection(), NtNotifyChangeDirectoryFile(), NtOpenObjectAuditAlarm(), NtOpenThreadTokenEx(), NtPrivilegeCheck(), NtPrivilegedServiceAuditAlarm(), NtProtectVirtualMemory(), NtPulseEvent(), NtQueryDirectoryFile(), NtQueryDirectoryObject(), NtQueryEvent(), NtQueryInformationFile(), NtQueryInformationProcess(), NtQueryInformationThread(), NtQueryInformationToken(), NtQueryIoCompletion(), NtQueryKey(), NtQueryMutant(), NtQueryObject(), NtQueryOpenSubKeys(), NtQuerySection(), NtQuerySecurityObject(), NtQuerySemaphore(), NtQuerySymbolicLinkObject(), NtQueryTimer(), NtQueryValueKey(), NtQueryVolumeInformationFile(), NtQueueApcThread(), NtReadFile(), NtReadVirtualMemory(), NtRegisterThreadTerminatePort(), NtReleaseMutant(), NtReleaseSemaphore(), NtRemoveIoCompletion(), NtRemoveProcessDebug(), NtReplyPort(), NtReplyWaitReceivePortEx(), NtRequestPort(), NtRequestWaitReplyPort(), NtResetEvent(), NtResetWriteWatch(), NtResumeProcess(), NtResumeThread(), NtSaveKeyEx(), NtSaveMergedKeys(), NtSecureConnectPort(), NtSetContextThread(), NtSetDefaultHardErrorPort(), NtSetEvent(), NtSetEventBoostPriority(), NtSetHighEventPair(), NtSetHighWaitLowEventPair(), NtSetInformationDebugObject(), NtSetInformationFile(), NtSetInformationObject(), NtSetInformationProcess(), NtSetInformationThread(), NtSetInformationToken(), NtSetIoCompletion(), NtSetLowEventPair(), NtSetLowWaitHighEventPair(), NtSetSecurityObject(), NtSetTimer(), NtSetValueKey(), NtSetVolumeInformationFile(), NtSignalAndWaitForSingleObject(), NtStartProfile(), NtStopProfile(), NtSuspendProcess(), NtSuspendThread(), NtTerminateJobObject(), NtTerminateProcess(), NtTerminateThread(), NtUnloadKey2(), NtUnlockFile(), NtUnlockVirtualMemory(), NtUnmapViewOfSection(), NtUserConsoleControl(), NtUserCreateDesktop(), NtUserGetGuiResources(), NtUserGetObjectInformation(), NtUserGetThreadDesktop(), NtUserProcessConnect(), NtUserQueryInformationThread(), NtUserResolveDesktop(), NtUserSetInformationThread(), NtUserWaitForInputIdle(), NtWaitForDebugEvent(), NtWaitForSingleObject(), NtWaitHighEventPair(), NtWaitLowEventPair(), NtWriteFile(), NtWriteVirtualMemory(), ObInitSystem(), ObpCreateDeviceMap(), ObpLookupObjectName(), ObtCreateObjectTypes(), OpenDevice(), OpenInputDevice(), PageFileBehaviorChecks(), Pin_fnDeviceIoControl(), Pin_fnWrite(), PopAddRemoveSysCapsCallback(), PsAssignImpersonationToken(), PsLocateSystemDll(), PsOpenTokenOfProcess(), PspAssignPrimaryToken(), PspCreateProcess(), PspCreateThread(), PspInitPhase0(), PspSetPrimaryToken(), RegisterUncProvider(), RfsdInvalidateVolumes(), SepAccessCheckAndAuditAlarm(), START_TEST(), StartThread(), SystemProcessTest(), TdiOpenDevice(), TdiUnload(), TestEventConcurrent(), TestIoCreateFile(), TestObRootSecurity(), TestProviderInfo(), TestReference(), TestSharedCacheMap(), TestSymlinks(), TestTcpConnect(), UDFCommonDeviceControl(), UDFInvalidateVolumes(), VerifyEventWaitable(), VfatSetRenameInformation(), WdmAudControlDeviceState(), WdmAudControlOpenMixer(), WdmAudFrameSize(), WdmAudOpenSysAudioDevices(), WdmAudReadWrite(), and WdmAudResetStream().

394 {
395  PHANDLE_TABLE_ENTRY HandleEntry;
396  POBJECT_HEADER ObjectHeader;
401  PETHREAD CurrentThread;
403  PAGED_CODE();
404 
405  /* Assume failure */
406  *Object = NULL;
407 
408  /* Check if this is a special handle */
409  if (HandleToLong(Handle) < 0)
410  {
411  /* Check if this is the current process */
412  if (Handle == NtCurrentProcess())
413  {
414  /* Check if this is the right object type */
415  if ((ObjectType == PsProcessType) || !(ObjectType))
416  {
417  /* Get the current process and granted access */
418  CurrentProcess = PsGetCurrentProcess();
419  GrantedAccess = CurrentProcess->GrantedAccess;
420 
421  /* Validate access */
422  /* ~GrantedAccess = RefusedAccess.*/
423  /* ~GrantedAccess & DesiredAccess = list of refused bits. */
424  /* !(~GrantedAccess & DesiredAccess) == TRUE means ALL requested rights are granted */
425  if ((AccessMode == KernelMode) ||
426  !(~GrantedAccess & DesiredAccess))
427  {
428  /* Check if the caller wanted handle information */
429  if (HandleInformation)
430  {
431  /* Return it */
432  HandleInformation->HandleAttributes = 0;
433  HandleInformation->GrantedAccess = GrantedAccess;
434  }
435 
436  /* Reference ourselves */
437  ObjectHeader = OBJECT_TO_OBJECT_HEADER(CurrentProcess);
438  InterlockedExchangeAdd(&ObjectHeader->PointerCount, 1);
439 
440  /* Return the pointer */
442  ASSERT(*Object != NULL);
443  Status = STATUS_SUCCESS;
444  }
445  else
446  {
447  /* Access denied */
448  Status = STATUS_ACCESS_DENIED;
449  }
450  }
451  else
452  {
453  /* The caller used this special handle value with a non-process type */
455  }
456 
457  /* Return the status */
458  return Status;
459  }
460  else if (Handle == NtCurrentThread())
461  {
462  /* Check if this is the right object type */
463  if ((ObjectType == PsThreadType) || !(ObjectType))
464  {
465  /* Get the current process and granted access */
466  CurrentThread = PsGetCurrentThread();
467  GrantedAccess = CurrentThread->GrantedAccess;
468 
469  /* Validate access */
470  /* ~GrantedAccess = RefusedAccess.*/
471  /* ~GrantedAccess & DesiredAccess = list of refused bits. */
472  /* !(~GrantedAccess & DesiredAccess) == TRUE means ALL requested rights are granted */
473  if ((AccessMode == KernelMode) ||
474  !(~GrantedAccess & DesiredAccess))
475  {
476  /* Check if the caller wanted handle information */
477  if (HandleInformation)
478  {
479  /* Return it */
480  HandleInformation->HandleAttributes = 0;
481  HandleInformation->GrantedAccess = GrantedAccess;
482  }
483 
484  /* Reference ourselves */
485  ObjectHeader = OBJECT_TO_OBJECT_HEADER(CurrentThread);
486  InterlockedExchangeAdd(&ObjectHeader->PointerCount, 1);
487 
488  /* Return the pointer */
489  *Object = CurrentThread;
490  ASSERT(*Object != NULL);
491  Status = STATUS_SUCCESS;
492  }
493  else
494  {
495  /* Access denied */
496  Status = STATUS_ACCESS_DENIED;
497  }
498  }
499  else
500  {
501  /* The caller used this special handle value with a non-process type */
503  }
504 
505  /* Return the status */
506  return Status;
507  }
508  else if (AccessMode == KernelMode)
509  {
510  /* Use the kernel handle table and get the actual handle value */
512  HandleTable = ObpKernelHandleTable;
513  }
514  else
515  {
516  /* Invalid access, fail */
517  return STATUS_INVALID_HANDLE;
518  }
519  }
520  else
521  {
522  /* Otherwise use this process's handle table */
523  HandleTable = PsGetCurrentProcess()->ObjectTable;
524  }
525 
526  /* Enter a critical region while we touch the handle table */
527  ASSERT(HandleTable != NULL);
529 
530  /* Get the handle entry */
531  HandleEntry = ExMapHandleToPointer(HandleTable, Handle);
532  if (HandleEntry)
533  {
534  /* Get the object header and validate the type*/
535  ObjectHeader = ObpGetHandleObject(HandleEntry);
536  if (!(ObjectType) || (ObjectType == ObjectHeader->Type))
537  {
538  /* Get the granted access and validate it */
539  GrantedAccess = HandleEntry->GrantedAccess;
540 
541  /* Validate access */
542  /* ~GrantedAccess = RefusedAccess.*/
543  /* ~GrantedAccess & DesiredAccess = list of refused bits. */
544  /* !(~GrantedAccess & DesiredAccess) == TRUE means ALL requested rights are granted */
545  if ((AccessMode == KernelMode) ||
546  !(~GrantedAccess & DesiredAccess))
547  {
548  /* Reference the object directly since we have its header */
549  InterlockedIncrement(&ObjectHeader->PointerCount);
550 
551  /* Mask out the internal attributes */
552  Attributes = HandleEntry->ObAttributes & OBJ_HANDLE_ATTRIBUTES;
553 
554  /* Check if the caller wants handle information */
555  if (HandleInformation)
556  {
557  /* Fill out the information */
558  HandleInformation->HandleAttributes = Attributes;
559  HandleInformation->GrantedAccess = GrantedAccess;
560  }
561 
562  /* Return the pointer */
563  *Object = &ObjectHeader->Body;
564 
565  /* Unlock the handle */
566  ExUnlockHandleTableEntry(HandleTable, HandleEntry);
568 
569  /* Return success */
570  ASSERT(*Object != NULL);
571  return STATUS_SUCCESS;
572  }
573  else
574  {
575  /* Requested access failed */
576  DPRINT("Rights not granted: %x\n", ~GrantedAccess & DesiredAccess);
577  Status = STATUS_ACCESS_DENIED;
578  }
579  }
580  else
581  {
582  /* Invalid object type */
584  }
585 
586  /* Unlock the entry */
587  ExUnlockHandleTableEntry(HandleTable, HandleEntry);
588  }
589  else
590  {
591  /* Invalid handle */
592  Status = STATUS_INVALID_HANDLE;
593  }
594 
595  /* Return failure status */
597  *Object = NULL;
598  return Status;
599 }
DWORD *typedef PVOID
Definition: winlogon.h:52
#define STATUS_SUCCESS
Definition: contextmenu.cpp:55
static POBJECTS_AND_NAME_A SE_OBJECT_TYPE ObjectType
Definition: security.c:80
#define PsGetCurrentThread()
Definition: env_spec_w32.h:81
ULONG_PTR ObAttributes
Definition: extypes.h:600
ASSERT((InvokeOnSuccess||InvokeOnError||InvokeOnCancel)?(CompletionRoutine!=NULL):TRUE)
PHANDLE_TABLE_ENTRY NTAPI ExMapHandleToPointer(IN PHANDLE_TABLE HandleTable, IN HANDLE Handle)
Definition: handle.c:1006
#define NtCurrentThread()
static EMS_HANDLE HandleTable[EMS_MAX_HANDLES]
Definition: emsdrv.c:40
LONG PointerCount
Definition: obtypes.h:481
IN POBJECT_ATTRIBUTES PortAttributes IN ACCESS_MASK DesiredAccess
Definition: creport.c:28
VOID NTAPI ExUnlockHandleTableEntry(IN PHANDLE_TABLE HandleTable, IN PHANDLE_TABLE_ENTRY HandleTableEntry)
Definition: handle.c:883
#define STATUS_INVALID_HANDLE
Definition: ntstatus.h:231
#define OBJECT_TO_OBJECT_HEADER(o)
Definition: obtypes.h:111
_In_ PEPROCESS _In_ KPROCESSOR_MODE AccessMode
Definition: mmfuncs.h:396
#define PsGetCurrentProcess
Definition: psfuncs.h:17
Definition: extypes.h:595
smooth NULL
Definition: ftsmooth.c:513
#define ObpGetHandleObject(x)
Definition: ob.h:81
void DPRINT(...)
Definition: polytest.cpp:61
PHANDLE_TABLE ObpKernelHandleTable
Definition: obhandle.c:20
#define InterlockedExchangeAdd
Definition: interlocked.h:181
#define NtCurrentProcess()
Definition: nt_native.h:1657
_In_ HANDLE Handle
Definition: extypes.h:390
#define STATUS_OBJECT_TYPE_MISMATCH
Definition: ntstatus.h:259
ULONG CurrentProcess
Definition: shell.c:125
ULONG GrantedAccess
Definition: extypes.h:606
_In_ ACCESS_MASK _In_opt_ POBJECT_TYPE _In_ KPROCESSOR_MODE _Out_ PVOID _Out_opt_ POBJECT_HANDLE_INFORMATION HandleInformation
Definition: obfuncs.h:40
#define STATUS_ACCESS_DENIED
Definition: udferr_usr.h:145
#define PAGED_CODE()
Definition: video.h:57
static IUnknown Object
Definition: main.c:512
POBJECT_TYPE PsThreadType
Definition: thread.c:20
#define KeEnterCriticalRegion()
Definition: ke_x.h:83
Status
Definition: gdiplustypes.h:24
LONG NTSTATUS
Definition: DriverTester.h:11
#define KeLeaveCriticalRegion()
Definition: ke_x.h:114
#define InterlockedIncrement
Definition: armddk.h:53
unsigned int ULONG
Definition: retypes.h:1
#define ObKernelHandleToHandle(Handle)
Definition: ob.h:73
POBJECT_TYPE Type
Definition: obtypes.h:487
#define OBJ_HANDLE_ATTRIBUTES
Definition: ob.h:52
_In_ PSECURITY_SUBJECT_CONTEXT _In_ BOOLEAN _In_ ACCESS_MASK _In_ ACCESS_MASK _Outptr_opt_ PPRIVILEGE_SET _In_ PGENERIC_MAPPING _In_ KPROCESSOR_MODE _Out_ PACCESS_MASK GrantedAccess
Definition: sefuncs.h:13
POBJECT_TYPE PsProcessType
Definition: process.c:20
ULONG ACCESS_MASK
Definition: nt_native.h:40
struct _ACPI_EFI_FILE_HANDLE CHAR16 UINT64 UINT64 Attributes
Definition: acefiex.h:335
#define HandleToLong(h)
Definition: basetsd.h:79
NTSTATUS NTAPI ObReferenceObjectByName ( IN PUNICODE_STRING  ObjectPath,
IN ULONG  Attributes,
IN PACCESS_STATE  PassedAccessState,
IN ACCESS_MASK  DesiredAccess,
IN POBJECT_TYPE  ObjectType,
IN KPROCESSOR_MODE  AccessMode,
IN OUT PVOID  ParseContext,
OUT PVOID ObjectPtr 
)

Definition at line 303 of file obref.c.

Referenced by IopGetDriverObject(), IopUnloadDriver(), NtSecureConnectPort(), ObtClose(), and TestReference().

311 {
312  PVOID Object = NULL;
316  AUX_ACCESS_DATA AuxData;
318  PAGED_CODE();
319 
320  /* Fail quickly */
321  if (!ObjectPath) return STATUS_OBJECT_NAME_INVALID;
322 
323  /* Capture the name */
324  Status = ObpCaptureObjectName(&ObjectName, ObjectPath, AccessMode, TRUE);
325  if (!NT_SUCCESS(Status)) return Status;
326 
327  /* We also need a valid name after capture */
328  if (!ObjectName.Length) return STATUS_OBJECT_NAME_INVALID;
329 
330  /* Check if we didn't get an access state */
331  if (!PassedAccessState)
332  {
333  /* Use our built-in access state */
335  Status = SeCreateAccessState(&AccessState,
336  &AuxData,
338  &ObjectType->TypeInfo.GenericMapping);
339  if (!NT_SUCCESS(Status)) goto Quickie;
340  }
341 
342  /* Find the object */
343  *ObjectPtr = NULL;
344  Status = ObpLookupObjectName(NULL,
345  &ObjectName,
346  Attributes,
347  ObjectType,
348  AccessMode,
349  ParseContext,
350  NULL,
351  NULL,
353  &Context,
354  &Object);
355 
356  /* Cleanup after lookup */
357  ObpReleaseLookupContext(&Context);
358 
359  /* Check if the lookup succeeded */
360  if (NT_SUCCESS(Status))
361  {
362  /* Check if access is allowed */
363  if (ObpCheckObjectReference(Object,
365  FALSE,
366  AccessMode,
367  &Status))
368  {
369  /* Return the object */
370  *ObjectPtr = Object;
371  }
372  }
373 
374  /* Free the access state */
375  if (PassedAccessState == &AccessState)
376  {
378  }
379 
380 Quickie:
381  /* Free the captured name if we had one, and return status */
382  ObpFreeObjectNameBuffer(&ObjectName);
383  return Status;
384 }
DWORD *typedef PVOID
Definition: winlogon.h:52
BOOLEAN NTAPI ObpCheckObjectReference(IN PVOID Object, IN OUT PACCESS_STATE AccessState, IN BOOLEAN LockHeld, IN KPROCESSOR_MODE AccessMode, OUT PNTSTATUS AccessStatus)
Definition: obsecure.c:340
#define TRUE
Definition: types.h:120
NTSTATUS NTAPI SeCreateAccessState(IN OUT PACCESS_STATE AccessState, IN PAUX_ACCESS_DATA AuxData, IN ACCESS_MASK Access, IN PGENERIC_MAPPING GenericMapping)
Definition: access.c:435
static POBJECTS_AND_NAME_A SE_OBJECT_TYPE ObjectType
Definition: security.c:80
VOID NTAPI ObpFreeObjectNameBuffer(IN PUNICODE_STRING Name)
Definition: oblife.c:347
_Inout_opt_ PACCESS_STATE PassedAccessState
Definition: obfuncs.h:71
IN POBJECT_ATTRIBUTES PortAttributes IN ACCESS_MASK DesiredAccess
Definition: creport.c:28
_In_ PVOID _Out_opt_ PULONG_PTR _Outptr_opt_ PCUNICODE_STRING * ObjectName
Definition: cmfuncs.h:62
#define FALSE
Definition: types.h:117
_In_ PEPROCESS _In_ KPROCESSOR_MODE AccessMode
Definition: mmfuncs.h:396
smooth NULL
Definition: ftsmooth.c:513
#define PAGED_CODE()
Definition: video.h:57
static IUnknown Object
Definition: main.c:512
_In_opt_ PVOID _In_opt_ PUNICODE_STRING _In_ PSECURITY_DESCRIPTOR _In_ PACCESS_STATE AccessState
Definition: sefuncs.h:414
Status
Definition: gdiplustypes.h:24
FORCEINLINE VOID ObpReleaseLookupContext(IN POBP_LOOKUP_CONTEXT Context)
Definition: ob_x.h:255
#define NT_SUCCESS(StatCode)
Definition: cmd.c:149
LONG NTSTATUS
Definition: DriverTester.h:11
#define STATUS_OBJECT_NAME_INVALID
Definition: udferr_usr.h:148
VOID NTAPI SeDeleteAccessState(IN PACCESS_STATE AccessState)
Definition: access.c:456
struct tagContext Context
Definition: acpixf.h:1014
NTSTATUS NTAPI ObpCaptureObjectName(IN PUNICODE_STRING CapturedName, IN PUNICODE_STRING ObjectName, IN KPROCESSOR_MODE AccessMode, IN BOOLEAN AllocateFromLookaside)
struct _ACPI_EFI_FILE_HANDLE CHAR16 UINT64 UINT64 Attributes
Definition: acefiex.h:335
NTSTATUS NTAPI ObpLookupObjectName(IN HANDLE RootHandle OPTIONAL, IN OUT PUNICODE_STRING ObjectName, IN ULONG Attributes, IN POBJECT_TYPE ObjectType, IN KPROCESSOR_MODE AccessMode, IN OUT PVOID ParseContext, IN PSECURITY_QUALITY_OF_SERVICE SecurityQos OPTIONAL, IN PVOID InsertObject OPTIONAL, IN OUT PACCESS_STATE AccessState, OUT POBP_LOOKUP_CONTEXT LookupContext, OUT PVOID *FoundObject)
Definition: obname.c:358
NTSTATUS NTAPI ObReferenceObjectByPointer ( IN PVOID  Object,
IN ACCESS_MASK  DesiredAccess,
IN POBJECT_TYPE  ObjectType,
IN KPROCESSOR_MODE  AccessMode 
)

Definition at line 275 of file obref.c.

Referenced by CcRosInitializeFileCache(), ClassRetrieveDeviceRelations(), co_UserCreateWindowEx(), DriverEntry(), HalpDmaAllocateChildAdapter(), IoWMIQueryAllData(), MmPageOutPhysicalAddress(), ObOpenObjectByPointer(), ObpLookupObjectName(), ObpParseSymbolicLink(), RxpWorkerThreadDispatcher(), RxSpinUpRequestsDispatcher(), ScsiClassClaimDevice(), and TestReference().

279 {
281 
282  /* Get the header */
284 
285  /*
286  * Validate object type if the call is for UserMode.
287  * NOTE: Unless it's a symbolic link (Caz Yokoyama [MSFT])
288  */
289  if ((Header->Type != ObjectType) && ((AccessMode != KernelMode) ||
291  {
292  /* Invalid type */
294  }
295 
296  /* Increment the reference count and return success */
298  return STATUS_SUCCESS;
299 }
#define STATUS_SUCCESS
Definition: contextmenu.cpp:55
static POBJECTS_AND_NAME_A SE_OBJECT_TYPE ObjectType
Definition: security.c:80
LONG PointerCount
Definition: obtypes.h:481
#define OBJECT_TO_OBJECT_HEADER(o)
Definition: obtypes.h:111
Definition: Header.h:8
_In_ PEPROCESS _In_ KPROCESSOR_MODE AccessMode
Definition: mmfuncs.h:396
#define STATUS_OBJECT_TYPE_MISMATCH
Definition: ntstatus.h:259
static IUnknown Object
Definition: main.c:512
#define InterlockedIncrement
Definition: armddk.h:53
POBJECT_TYPE ObSymbolicLinkType
Definition: oblink.c:18
POBJECT_TYPE Type
Definition: obtypes.h:487
LONG FASTCALL ObReferenceObjectEx ( IN PVOID  Object,
IN LONG  Count 
)

Definition at line 77 of file obref.c.

Referenced by ObFastReferenceObject(), ObFastReplaceObject(), ObInitializeFastReference(), and PspCreateThread().

79 {
80  /* Increment the reference count and return the count now */
82  PointerCount,
83  Count) + Count;
84 }
_Inout_ __drv_aliasesMem PSLIST_ENTRY _Inout_ PSLIST_ENTRY _In_ ULONG Count
Definition: exfuncs.h:1015
#define OBJECT_TO_OBJECT_HEADER(o)
Definition: obtypes.h:111
#define InterlockedExchangeAdd
Definition: interlocked.h:181
static IUnknown Object
Definition: main.c:512
BOOLEAN FASTCALL ObReferenceObjectSafe ( IN PVOID  Object)

Definition at line 22 of file obref.c.

Referenced by _Function_class_(), CmpFlushNotifiesOnKeyBodyList(), NtImpersonateClientOfPort(), NtRequestPort(), PsGetNextProcess(), PsGetNextProcessThread(), PsLookupProcessByProcessId(), PsLookupProcessThreadByCid(), PsLookupThreadByThreadId(), and PspExitThread().

23 {
24  POBJECT_HEADER ObjectHeader;
25  LONG OldValue, NewValue;
26 
27  /* Get the object header */
28  ObjectHeader = OBJECT_TO_OBJECT_HEADER(Object);
29 
30  /* Get the current reference count and fail if it's zero */
31  OldValue = ObjectHeader->PointerCount;
32  if (!OldValue) return FALSE;
33 
34  /* Start reference loop */
35  do
36  {
37  /* Increase the reference count */
38  NewValue = InterlockedCompareExchange(&ObjectHeader->PointerCount,
39  OldValue + 1,
40  OldValue);
41  if (OldValue == NewValue) return TRUE;
42 
43  /* Keep looping */
44  OldValue = NewValue;
45  } while (OldValue);
46 
47  /* If we got here, then the reference count is now 0 */
48  return FALSE;
49 }
#define TRUE
Definition: types.h:120
#define InterlockedCompareExchange
Definition: interlocked.h:104
LONG PointerCount
Definition: obtypes.h:481
#define OBJECT_TO_OBJECT_HEADER(o)
Definition: obtypes.h:111
#define FALSE
Definition: types.h:117
long LONG
Definition: pedump.c:60
static IUnknown Object
Definition: main.c:512