2 * Service process to load a kernel driver
4 * Copyright 2007 Alexandre Julliard
6 * This library is free software; you can redistribute it and/or
7 * modify it under the terms of the GNU Lesser General Public
8 * License as published by the Free Software Foundation; either
9 * version 2.1 of the License, or (at your option) any later version.
11 * This library is distributed in the hope that it will be useful,
12 * but WITHOUT ANY WARRANTY; without even the implied warranty of
13 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU
14 * Lesser General Public License for more details.
16 * You should have received a copy of the GNU Lesser General Public
17 * License along with this library; if not, write to the Free Software
18 * Foundation, Inc., 51 Franklin St, Fifth Floor, Boston, MA 02110-1301, USA
22 #include "wine/port.h"
27 #define WIN32_NO_STATUS
35 #include "wine/unicode.h"
36 #include "wine/debug.h"
38 WINE_DEFAULT_DEBUG_CHANNEL(winedevice
);
39 WINE_DECLARE_DEBUG_CHANNEL(relay
);
41 extern NTSTATUS CDECL
wine_ntoskrnl_main_loop( HANDLE stop_event
);
43 static WCHAR
*driver_name
;
44 static SERVICE_STATUS_HANDLE service_handle
;
45 static HKEY driver_hkey
;
46 static HANDLE stop_event
;
47 static DRIVER_OBJECT driver_obj
;
48 static DRIVER_EXTENSION driver_extension
;
50 /* find the LDR_MODULE corresponding to the driver module */
51 static LDR_MODULE
*find_ldr_module( HMODULE module
)
53 LIST_ENTRY
*entry
, *list
= &NtCurrentTeb()->Peb
->LdrData
->InMemoryOrderModuleList
;
55 for (entry
= list
->Flink
; entry
!= list
; entry
= entry
->Flink
)
57 LDR_MODULE
*ldr
= CONTAINING_RECORD(entry
, LDR_MODULE
, InMemoryOrderModuleList
);
58 if (ldr
->BaseAddress
== module
) return ldr
;
59 if (ldr
->BaseAddress
> (void *)module
) break;
64 /* load the driver module file */
65 static HMODULE
load_driver_module( const WCHAR
*name
)
68 const IMAGE_IMPORT_DESCRIPTOR
*imports
;
69 size_t page_size
= getpagesize();
73 HMODULE module
= LoadLibraryW( name
);
75 if (!module
) return NULL
;
76 nt
= RtlImageNtHeader( module
);
78 if (!(delta
= (char *)module
- (char *)nt
->OptionalHeader
.ImageBase
)) return module
;
80 /* the loader does not apply relocations to non page-aligned binaries or executables,
81 * we have to do it ourselves */
83 if (nt
->OptionalHeader
.SectionAlignment
< page_size
||
84 !(nt
->FileHeader
.Characteristics
& IMAGE_FILE_DLL
))
87 IMAGE_BASE_RELOCATION
*rel
, *end
;
89 if ((rel
= RtlImageDirectoryEntryToData( module
, TRUE
, IMAGE_DIRECTORY_ENTRY_BASERELOC
, &size
)))
91 WINE_TRACE( "%s: relocating from %p to %p\n",
92 wine_dbgstr_w(name
), (char *)module
- delta
, module
);
93 end
= (IMAGE_BASE_RELOCATION
*)((char *)rel
+ size
);
94 while (rel
< end
&& rel
->SizeOfBlock
)
96 void *page
= (char *)module
+ rel
->VirtualAddress
;
97 VirtualProtect( page
, page_size
, PAGE_EXECUTE_READWRITE
, &old
);
98 rel
= LdrProcessRelocationBlock( page
, (rel
->SizeOfBlock
- sizeof(*rel
)) / sizeof(USHORT
),
99 (USHORT
*)(rel
+ 1), delta
);
100 if (old
!= PAGE_EXECUTE_READWRITE
) VirtualProtect( page
, page_size
, old
, NULL
);
101 if (!rel
) goto error
;
103 /* make sure we don't try again */
104 size
= FIELD_OFFSET( IMAGE_NT_HEADERS
, OptionalHeader
) + nt
->FileHeader
.SizeOfOptionalHeader
;
105 VirtualProtect( nt
, size
, PAGE_READWRITE
, &old
);
106 nt
->OptionalHeader
.DataDirectory
[IMAGE_DIRECTORY_ENTRY_BASERELOC
].VirtualAddress
= 0;
107 VirtualProtect( nt
, size
, old
, NULL
);
111 /* make sure imports are relocated too */
113 if ((imports
= RtlImageDirectoryEntryToData( module
, TRUE
, IMAGE_DIRECTORY_ENTRY_IMPORT
, &size
)))
115 for (i
= 0; imports
[i
].Name
&& imports
[i
].FirstThunk
; i
++)
117 char *name
= (char *)module
+ imports
[i
].Name
;
118 WCHAR buffer
[32], *p
= buffer
;
120 while (p
< buffer
+ 32) if (!(*p
++ = *name
++)) break;
121 if (p
<= buffer
+ 32) FreeLibrary( load_driver_module( buffer
) );
128 FreeLibrary( module
);
132 /* call the driver init entry point */
133 static NTSTATUS
init_driver( HMODULE module
, UNICODE_STRING
*keyname
)
137 const IMAGE_NT_HEADERS
*nt
= RtlImageNtHeader( module
);
139 if (!nt
->OptionalHeader
.AddressOfEntryPoint
) return STATUS_SUCCESS
;
141 driver_obj
.Size
= sizeof(driver_obj
);
142 driver_obj
.DriverSection
= find_ldr_module( module
);
143 driver_obj
.DriverInit
= (PDRIVER_INITIALIZE
)((char *)module
+ nt
->OptionalHeader
.AddressOfEntryPoint
);
144 driver_obj
.DriverExtension
= &driver_extension
;
146 driver_extension
.DriverObject
= &driver_obj
;
147 driver_extension
.ServiceKeyName
= *keyname
;
149 if (WINE_TRACE_ON(relay
))
150 WINE_DPRINTF( "%04x:Call driver init %p (obj=%p,str=%s)\n", GetCurrentThreadId(),
151 driver_obj
.DriverInit
, &driver_obj
, wine_dbgstr_w(keyname
->Buffer
) );
153 status
= driver_obj
.DriverInit( &driver_obj
, keyname
);
155 if (WINE_TRACE_ON(relay
))
156 WINE_DPRINTF( "%04x:Ret driver init %p (obj=%p,str=%s) retval=%08x\n", GetCurrentThreadId(),
157 driver_obj
.DriverInit
, &driver_obj
, wine_dbgstr_w(keyname
->Buffer
), status
);
159 WINE_TRACE( "init done for %s obj %p\n", wine_dbgstr_w(driver_name
), &driver_obj
);
160 WINE_TRACE( "- DriverInit = %p\n", driver_obj
.DriverInit
);
161 WINE_TRACE( "- DriverStartIo = %p\n", driver_obj
.DriverStartIo
);
162 WINE_TRACE( "- DriverUnload = %p\n", driver_obj
.DriverUnload
);
163 for (i
= 0; i
<= IRP_MJ_MAXIMUM_FUNCTION
; i
++)
164 WINE_TRACE( "- MajorFunction[%d] = %p\n", i
, driver_obj
.MajorFunction
[i
] );
169 /* load the .sys module for a device driver */
170 static BOOL
load_driver(void)
172 static const WCHAR driversW
[] = {'\\','d','r','i','v','e','r','s','\\',0};
173 static const WCHAR postfixW
[] = {'.','s','y','s',0};
174 static const WCHAR ntprefixW
[] = {'\\','?','?','\\',0};
175 static const WCHAR ImagePathW
[] = {'I','m','a','g','e','P','a','t','h',0};
176 static const WCHAR servicesW
[] = {'\\','R','e','g','i','s','t','r','y',
177 '\\','M','a','c','h','i','n','e',
178 '\\','S','y','s','t','e','m',
179 '\\','C','u','r','r','e','n','t','C','o','n','t','r','o','l','S','e','t',
180 '\\','S','e','r','v','i','c','e','s','\\',0};
182 UNICODE_STRING keypath
;
184 LPWSTR path
= NULL
, str
;
187 str
= HeapAlloc( GetProcessHeap(), 0, sizeof(servicesW
) + strlenW(driver_name
)*sizeof(WCHAR
) );
188 lstrcpyW( str
, servicesW
);
189 lstrcatW( str
, driver_name
);
191 if (RegOpenKeyW( HKEY_LOCAL_MACHINE
, str
+ 18 /* skip \registry\machine */, &driver_hkey
))
193 WINE_ERR( "cannot open key %s, err=%u\n", wine_dbgstr_w(str
), GetLastError() );
194 HeapFree( GetProcessHeap(), 0, str
);
197 RtlInitUnicodeString( &keypath
, str
);
199 /* read the executable path from memory */
201 if (!RegQueryValueExW( driver_hkey
, ImagePathW
, NULL
, &type
, NULL
, &size
))
203 str
= HeapAlloc( GetProcessHeap(), 0, size
);
204 if (!RegQueryValueExW( driver_hkey
, ImagePathW
, NULL
, &type
, (LPBYTE
)str
, &size
))
206 size
= ExpandEnvironmentStringsW(str
,NULL
,0);
207 path
= HeapAlloc(GetProcessHeap(),0,size
*sizeof(WCHAR
));
208 ExpandEnvironmentStringsW(str
,path
,size
);
210 HeapFree( GetProcessHeap(), 0, str
);
211 if (!path
) return FALSE
;
215 /* default is to use the driver name + ".sys" */
216 WCHAR buffer
[MAX_PATH
];
217 GetSystemDirectoryW(buffer
, MAX_PATH
);
218 path
= HeapAlloc(GetProcessHeap(),0,
219 (strlenW(buffer
) + strlenW(driversW
) + strlenW(driver_name
) + strlenW(postfixW
) + 1)
221 lstrcpyW(path
, buffer
);
222 lstrcatW(path
, driversW
);
223 lstrcatW(path
, driver_name
);
224 lstrcatW(path
, postfixW
);
227 /* GameGuard uses an NT-style path name */
229 if (!strncmpW( path
, ntprefixW
, 4 )) str
+= 4;
231 WINE_TRACE( "loading driver %s\n", wine_dbgstr_w(str
) );
233 module
= load_driver_module( str
);
234 HeapFree( GetProcessHeap(), 0, path
);
235 if (!module
) return FALSE
;
237 init_driver( module
, &keypath
);
241 static DWORD WINAPI
service_handler( DWORD ctrl
, DWORD event_type
, LPVOID event_data
, LPVOID context
)
243 SERVICE_STATUS status
;
245 status
.dwServiceType
= SERVICE_WIN32
;
246 status
.dwControlsAccepted
= SERVICE_ACCEPT_STOP
;
247 status
.dwWin32ExitCode
= 0;
248 status
.dwServiceSpecificExitCode
= 0;
249 status
.dwCheckPoint
= 0;
250 status
.dwWaitHint
= 0;
254 case SERVICE_CONTROL_STOP
:
255 case SERVICE_CONTROL_SHUTDOWN
:
256 WINE_TRACE( "shutting down %s\n", wine_dbgstr_w(driver_name
) );
257 status
.dwCurrentState
= SERVICE_STOP_PENDING
;
258 status
.dwControlsAccepted
= 0;
259 SetServiceStatus( service_handle
, &status
);
260 SetEvent( stop_event
);
263 WINE_FIXME( "got service ctrl %x for %s\n", ctrl
, wine_dbgstr_w(driver_name
) );
264 status
.dwCurrentState
= SERVICE_RUNNING
;
265 SetServiceStatus( service_handle
, &status
);
270 static void WINAPI
ServiceMain( DWORD argc
, LPWSTR
*argv
)
272 SERVICE_STATUS status
;
274 WINE_TRACE( "starting service %s\n", wine_dbgstr_w(driver_name
) );
276 stop_event
= CreateEventW( NULL
, TRUE
, FALSE
, NULL
);
278 service_handle
= RegisterServiceCtrlHandlerExW( driver_name
, service_handler
, NULL
);
282 status
.dwServiceType
= SERVICE_WIN32
;
283 status
.dwCurrentState
= SERVICE_START_PENDING
;
284 status
.dwControlsAccepted
= 0;
285 status
.dwWin32ExitCode
= 0;
286 status
.dwServiceSpecificExitCode
= 0;
287 status
.dwCheckPoint
= 0;
288 status
.dwWaitHint
= 10000;
289 SetServiceStatus( service_handle
, &status
);
293 status
.dwCurrentState
= SERVICE_RUNNING
;
294 status
.dwControlsAccepted
= SERVICE_ACCEPT_STOP
| SERVICE_ACCEPT_SHUTDOWN
;
295 SetServiceStatus( service_handle
, &status
);
297 wine_ntoskrnl_main_loop( stop_event
);
299 else WINE_ERR( "driver %s failed to load\n", wine_dbgstr_w(driver_name
) );
301 status
.dwCurrentState
= SERVICE_STOPPED
;
302 status
.dwControlsAccepted
= 0;
303 SetServiceStatus( service_handle
, &status
);
304 WINE_TRACE( "service %s stopped\n", wine_dbgstr_w(driver_name
) );
307 int wmain( int argc
, WCHAR
*argv
[] )
309 SERVICE_TABLE_ENTRYW service_table
[2];
311 if (!(driver_name
= argv
[1]))
313 WINE_ERR( "missing device name, winedevice isn't supposed to be run manually\n" );
317 service_table
[0].lpServiceName
= argv
[1];
318 service_table
[0].lpServiceProc
= ServiceMain
;
319 service_table
[1].lpServiceName
= NULL
;
320 service_table
[1].lpServiceProc
= NULL
;
322 StartServiceCtrlDispatcherW( service_table
);