| Server IP : 209.209.40.120 / Your IP : 216.73.217.112 Web Server : Microsoft-IIS/10.0 System : Windows NT NEWWWW 10.0 build 17763 (Windows Server 2019) i586 User : NEWWWW$ ( 0) PHP Version : 8.3.30 Disable Function : NONE MySQL : OFF | cURL : ON | WGET : OFF | Perl : OFF | Python : OFF | Sudo : OFF | Pkexec : OFF Directory : C:/Program Files (x86)/Windows Kits/10/bin/10.0.19041.0/x86/ |
Upload File : |
MZ� �� � @ � � � �!�L�!This program cannot be run in DOS mode.
$ 9���}���}���}���t�m�{���i�x���i�q���i�l���}���ƞ��i�O���i�c���i�����i��|���i�|���Rich}��� PE L �D]e � � �Y � @
@
�o @� � �R � p H� � �!
�4 �� T � � @ P � .text � � `.data �S � � @ �.idata B P � @ @.rsrc H� p � � @ @.reloc �4
6 ~ @ B �@ @ZG ��G �G ��C ��C ��C ��C ��C ��C ��C �C @�D |@ ��D p�D �@ ��D p�D �@ ��D p�D @ ��D p�D @�E P�E ��E ��C ��E �E ��C ��E `�E p�D ��F �F �F P�F ��F ,\A p$@ �%@ 7
(0@ � �0@ 2 1@ (4@ H7@ � �;@ 1 >@ ! 8X@ G �Z@ . �f@ �u@ . �z@ & �@ � ��@ W �@ � ��@ C ح@ o H�@ 1 ��@ ~ �@ � ��@ �@ � ��@ � 8�@ P�@ s �@ � �A 8
�A 1 0A @A L �+A � 0-A 4.A 8 p.A � @0A ? �GA | MA F
� �G P�C � �RI �@ s u h�G p�G $�G �@ 0 ,�G �@ �@ �@ ,�G ���� @ �@ @�G ���� @ �@ D�G �@ @ �@ 8@ T@ 8@ D�G ���� @ �@ ��G ���� @ �@ �@ 8@ �G �@ 8@ @ p@ �@ @�G �@ ��G �@ ,@ �G ���� @ �@ XG ��C ��C �C 0�C @�C P�C `�C p�C ��C ��C ��C ��C ��C ��C ��C ��C �C �C �C 0�C @�C P�C p�C ��C ��C ��C ��C �C @�C `�C p�C pWG XG WG WG PWG �fG �� �� � 0� @� P� `� p� �� �� �� �� �� �� �� �� � � � 0� @� P� p� �� �� �� �� � @� `� p� p� �� �� �� �� �� �� �� � 0� P� @� @� p� �� � P� p� �� �� � P� �� �� @� P� �� � `� � �� � �� � � P� �� W W PW pW X X �Y �Y Z @Z �_ �a b �f h �� Т � � � � � 0� @� `� p� �� �� �� �� У � � � � 0� @� �� �� �� Ф � � � � 0� P� a p i - m s - w i n - c o r e - s y n c h - l 1 - 2 - 0 . d l l k e r n e l 3 2 . d l l InitializeConditionVariable SleepConditionVariableCS WakeAllConditionVariable a n s i u t f 8 u t f - 8 u t f 1 6 u t f 1 6 l e u t f - 1 6 u t f - 1 6 l e u c s 2 u c s 2 l e u c s - 2 u c s - 2 l e w t w t , c c s = U T F - 8 w t , c c s = U T F - 1 6 L E I N C L U D E %ls : error : %ls
Message text larger than size specified by -m %lu _ _ m c I d _ _ $ ( m c . ) %ls : error : For template '%ls', invalid Custom Xml specified. Custom Xml must have a top-level element and it should be in its own namespace: %ls. Manifest File Name: %ls.
Schema File Name: %ls.
Winmeta File Name: %ls.
MC: error : Failed creating parse context : reason :: %hs
MetadataResourceFileName: %ls MC: error : Failed creating provider resources for manifest %ls
%ls : error : The generated header file for the .mc file and the manifest will not have unique names.
. r c unable to open output file - %ls r , c c s = U N I C O D E i n s t r u m e n t a t i o n ManParseXml: Failed HR = %d %ls
MC: error : Failed creating single provider resources for manifest %ls
m a n * Target dir is %ls
No files Found in %ls
File %ls
Failed to parse manifest : %ls
Couldn't find next file, GetLastError() = 0x%08X.
Failed to create global resource file
W i n R T T e m p l a t e P r o v i d e r S t u b s A p p l i c a t i o n S u c c e s s I n f o r m a t i o n a l W a r n i n g E r r o r M S G 0 0 0 0 1 E n g l i s h . \ h c s s c s mc : error : Missing name space argument for -cs or -css switch.
c o c p mc : error : Invalid encoding argument for -cp "%ls".
mc : error : Missing argument for -%ls switch.
mc : error : Invalid argument for -e switch.
mc : error : Missing argument for -%c switch.
g e n e r a t e T e m p l a t e P r o j e c t i o n s g e n e r a t e T e m p l a t e S t u b s mc : error : generateTemplateStubs argument too large
mc : error : Missing argument for -generateTemplateStubs switch.
g e n e r a t e P r o j e c t i o n s mc : error : Invalid switch: %c.
k m m o f mc : error : Invalid argument (%ls) for -%c switch.
N o V e r s i o n mc : error : Prefix too large, max size allowed 16 chars
mc : error : Invalid baseline path name %ls
mc : error : Missing Baseline argument for -%c switch.
u m u 8 mc : error : Choose -um, -km or -cs option
mc : error : -km is not allowed with -um, -winrt or -cs option
mc : error : choose either -generateProjections or -cs option, not both
mc : error : choose either -um or -cs option, not both
mc : error : Both ANSI and Unicode input were specified.
mc : error : Both ANSI and Unicode output were specified.
mc : error : Both UTF8 and Unicode output were specified.
mc : error : Both ANSI and UTF8 output were specified.
mc : error : -u switch was specified but .mc file "%ls" has no BOM and does not appear to be UTF-16.
mc : error : -u switch was not specified but .mc file "%ls" has no BOM and appears to be UTF-16.
mc : error : -x switch cannot be used without a legacy .mc file!
mc : error : CoInitialize failed, error = 0x%x
. mc : error : Internal error - ErrorCode=%u, SubErrorCode=%u, Message=%ls
mc : error : Internal error - ErrorCode=%u, SubErrorCode=%u
vector<T> too long string too long //**********************************************************************`
//* This is an include file generated by Message Compiler. *`
//* *`
//* Copyright (c) Microsoft Corporation. All Rights Reserved. *`
//**********************************************************************`
#pragma once
//*****************************************************************************
//
// Notes on the ETW event code generated by MC:
//
// - Structures and arrays of structures are treated as an opaque binary blob.
// The caller is responsible for packing the data for the structure into a
// single region of memory, with no padding between values. The macro will
// have an extra parameter for the length of the blob.
// - Arrays of nul-terminated strings must be packed by the caller into a
// single binary blob containing the correct number of strings, with a nul
// after each string. The size of the blob is specified in characters, and
// includes the final nul.
// - Arrays of SID are treated as a single binary blob. The caller is
// responsible for packing the SID values into a single region of memory with
// no padding.
// - The length attribute on the data element in the manifest is significant
// for values with intype win:UnicodeString, win:AnsiString, or win:Binary.
// The length attribute must be specified for win:Binary, and is optional for
// win:UnicodeString and win:AnsiString (if no length is given, the strings
// are assumed to be nul-terminated). For win:UnicodeString, the length is
// measured in characters, not bytes.
// - For an array of win:UnicodeString, win:AnsiString, or win:Binary, the
// length attribute applies to every value in the array, so every value in
// the array must have the same length. The values in the array are provided
// to the macro via a single pointer -- the caller is responsible for packing
// all of the values into a single region of memory with no padding between
// values.
// - Values of type win:CountedUnicodeString, win:CountedAnsiString, and
// win:CountedBinary can be generated and collected on Vista or later.
// However, they may not decode properly without the Windows 10 2018 Fall
// Update.
// - Arrays of type win:CountedUnicodeString, win:CountedAnsiString, and
// win:CountedBinary must be packed by the caller into a single region of
// memory. The format for each item is a UINT16 byte-count followed by that
// many bytes of data. When providing the array to the generated macro, you
// must provide the total size of the packed array data, including the UINT16
// sizes for each item. In the case of win:CountedUnicodeString, the data
// size is specified in WCHAR (16-bit) units. In the case of
// win:CountedAnsiString and win:CountedBinary, the data size is specified in
// bytes.
//
//*****************************************************************************
//
// MCGEN_DISABLE_PROVIDER_CODE_GENERATION macro:
// Define this macro to have the compiler skip the generated functions in this
// header.
//
#ifndef MCGEN_DISABLE_PROVIDER_CODE_GENERATION
#endif // MCGEN_DISABLE_PROVIDER_CODE_GENERATION
//
// MCGEN_EVENT_ENABLED macro:
// Override to control how the EventWrite[EventName] macros determine whether
// an event is enabled. The default behavior is for EventWrite[EventName] to
// use the EventEnabled[EventName] macros.
//
#ifndef MCGEN_EVENT_ENABLED
#define MCGEN_EVENT_ENABLED(EventName) EventEnabled##EventName()
#endif
//
// MCGEN_EVENT_ENABLED_FORCONTEXT macro:
// Override to control how the EventWrite[EventName]_ForContext macros
// determine whether an event is enabled. The default behavior is for
// EventWrite[EventName]_ForContext to use the
// EventEnabled[EventName]_ForContext macros.
//
#ifndef MCGEN_EVENT_ENABLED_FORCONTEXT
#define MCGEN_EVENT_ENABLED_FORCONTEXT(pContext, EventName) EventEnabled##EventName##_ForContext(pContext)
#endif
#if !defined(MCGEN_TRACE_CONTEXT_DEF)
#define MCGEN_TRACE_CONTEXT_DEF
// This structure is for use by MC-generated code and should not be used directly.
typedef struct _MCGEN_TRACE_CONTEXT
{
TRACEHANDLE RegistrationHandle;
TRACEHANDLE Logger; // Used as pointer to provider traits.
ULONGLONG MatchAnyKeyword;
ULONGLONG MatchAllKeyword;
ULONG Flags;
ULONG IsEnabled;
UCHAR Level;
UCHAR Reserve;
USHORT EnableBitsCount;
PULONG EnableBitMask;
const ULONGLONG* EnableKeyWords;
const UCHAR* EnableLevel;
} MCGEN_TRACE_CONTEXT, *PMCGEN_TRACE_CONTEXT;
#endif // MCGEN_TRACE_CONTEXT_DEF
#if !defined(MCGEN_LEVEL_KEYWORD_ENABLED_DEF)
#define MCGEN_LEVEL_KEYWORD_ENABLED_DEF
//
// Determines whether an event with a given Level and Keyword would be
// considered as enabled based on the state of the specified context.
// Note that you may want to use MCGEN_ENABLE_CHECK instead of calling this
// function directly.
//
FORCEINLINE
BOOLEAN
McGenLevelKeywordEnabled(
_In_ PMCGEN_TRACE_CONTEXT EnableInfo,
_In_ UCHAR Level,
_In_ ULONGLONG Keyword
)
{
//
// Check if the event Level is lower than the level at which
// the channel is enabled.
// If the event Level is 0 or the channel is enabled at level 0,
// all levels are enabled.
//
if ((Level <= EnableInfo->Level) || // This also covers the case of Level == 0.
(EnableInfo->Level == 0)) {
//
// Check if Keyword is enabled
//
if ((Keyword == (ULONGLONG)0) ||
((Keyword & EnableInfo->MatchAnyKeyword) &&
((Keyword & EnableInfo->MatchAllKeyword) == EnableInfo->MatchAllKeyword))) {
return TRUE;
}
}
return FALSE;
}
#endif // MCGEN_LEVEL_KEYWORD_ENABLED_DEF
#if !defined(MCGEN_EVENT_ENABLED_DEF)
#define MCGEN_EVENT_ENABLED_DEF
//
// Determines whether the specified event would be considered as enabled based
// on the state of the specified context. Note that you may want to use
// MCGEN_ENABLE_CHECK instead of calling this function directly.
//
FORCEINLINE
BOOLEAN
McGenEventEnabled(
_In_ PMCGEN_TRACE_CONTEXT EnableInfo,
_In_ PCEVENT_DESCRIPTOR EventDescriptor
)
{
return McGenLevelKeywordEnabled(EnableInfo, EventDescriptor->Level, EventDescriptor->Keyword);
}
#endif // MCGEN_EVENT_ENABLED_DEF
//
// MCGEN_USE_KERNEL_MODE_APIS macro:
// Controls whether the generated code uses kernel-mode or user-mode APIs.
// - Set to 0 to use Windows user-mode APIs such as EventRegister.
// - Set to 1 to use Windows kernel-mode APIs such as EtwRegister.
// Default is based on whether the _ETW_KM_ macro is defined (i.e. by wdm.h).
// Note that the APIs can also be overridden directly, e.g. by setting the
// MCGEN_EVENTWRITETRANSFER or MCGEN_EVENTREGISTER macros.
//
#ifndef MCGEN_USE_KERNEL_MODE_APIS
#ifdef _ETW_KM_
#define MCGEN_USE_KERNEL_MODE_APIS 1
#else
#define MCGEN_USE_KERNEL_MODE_APIS 0
#endif
#endif // MCGEN_USE_KERNEL_MODE_APIS
//
// MCGEN_HAVE_EVENTSETINFORMATION macro:
// Controls how McGenEventSetInformation uses the EventSetInformation API.
// - Set to 0 to disable the use of EventSetInformation
// (McGenEventSetInformation will always return an error).
// - Set to 1 to directly invoke MCGEN_EVENTSETINFORMATION.
// - Set to 2 to to locate EventSetInformation at runtime via GetProcAddress
// (user-mode) or MmGetSystemRoutineAddress (kernel-mode).
// Default is determined as follows:
// - If MCGEN_EVENTSETINFORMATION has been customized, set to 1
// (i.e. use MCGEN_EVENTSETINFORMATION).
// - Else if the target OS version has EventSetInformation, set to 1
// (i.e. use MCGEN_EVENTSETINFORMATION).
// - Else set to 2 (i.e. try to dynamically locate EventSetInformation).
// Note that an McGenEventSetInformation function will only be generated if one
// or more provider in a manifest has provider traits.
//
#ifndef MCGEN_HAVE_EVENTSETINFORMATION
#ifdef MCGEN_EVENTSETINFORMATION // if MCGEN_EVENTSETINFORMATION has been customized,
#define MCGEN_HAVE_EVENTSETINFORMATION 1 // directly invoke MCGEN_EVENTSETINFORMATION(...).
#elif MCGEN_USE_KERNEL_MODE_APIS // else if using kernel-mode APIs,
#if NTDDI_VERSION >= 0x06040000 // if target OS is Windows 10 or later,
#define MCGEN_HAVE_EVENTSETINFORMATION 1 // directly invoke MCGEN_EVENTSETINFORMATION(...).
#else // else
#define MCGEN_HAVE_EVENTSETINFORMATION 2 // find "EtwSetInformation" via MmGetSystemRoutineAddress.
#endif // else (using user-mode APIs)
#else // if target OS and SDK is Windows 8 or later,
#if WINVER >= 0x0602 && defined(EVENT_FILTER_TYPE_SCHEMATIZED)
#define MCGEN_HAVE_EVENTSETINFORMATION 1 // directly invoke MCGEN_EVENTSETINFORMATION(...).
#else // else
#define MCGEN_HAVE_EVENTSETINFORMATION 2 // find "EventSetInformation" via GetModuleHandleExW/GetProcAddress.
#endif
#endif
#endif // MCGEN_HAVE_EVENTSETINFORMATION
//
// MCGEN Override Macros
//
// The following override macros may be defined before including this header
// to control the APIs used by this header:
//
// - MCGEN_EVENTREGISTER
// - MCGEN_EVENTUNREGISTER
// - MCGEN_EVENTSETINFORMATION
// - MCGEN_EVENTWRITETRANSFER
//
// If the the macro is undefined, the MC implementation will default to the
// corresponding ETW APIs. For example, if the MCGEN_EVENTREGISTER macro is
// undefined, the EventRegister[MyProviderName] macro will use EventRegister
// in user mode and will use EtwRegister in kernel mode.
//
// To prevent issues from conflicting definitions of these macros, the value
// of the override macro will be used as a suffix in certain internal function
// names. Because of this, the override macros must follow certain rules:
//
// - The macro must be defined before any MC-generated header is included and
// must not be undefined or redefined after any MC-generated header is
// included. Different translation units (i.e. different .c or .cpp files)
// may set the macros to different values, but within a translation unit
// (within a single .c or .cpp file), the macro must be set once and not
// changed.
// - The override must be an object-like macro, not a function-like macro
// (i.e. the override macro must not have a parameter list).
// - The override macro's value must be a simple identifier, i.e. must be
// something that starts with a letter or '_' and contains only letters,
// numbers, and '_' characters.
// - If the override macro's value is the name of a second object-like macro,
// the second object-like macro must follow the same rules. (The override
// macro's value can also be the name of a function-like macro, in which
// case the function-like macro does not need to follow the same rules.)
//
// For example, the following will cause compile errors:
//
// #define MCGEN_EVENTWRITETRANSFER MyNamespace::MyClass::MyFunction // Value has non-identifier characters (colon).
// #define MCGEN_EVENTWRITETRANSFER GetEventWriteFunctionPointer(7) // Value has non-identifier characters (parentheses).
// #define MCGEN_EVENTWRITETRANSFER(h,e,a,r,c,d) EventWrite(h,e,c,d) // Override is defined as a function-like macro.
// #define MY_OBJECT_LIKE_MACRO MyNamespace::MyClass::MyEventWriteFunction
// #define MCGEN_EVENTWRITETRANSFER MY_OBJECT_LIKE_MACRO // Evaluates to something with non-identifier characters (colon).
//
// The following would be ok:
//
// #define MCGEN_EVENTWRITETRANSFER MyEventWriteFunction1 // OK, suffix will be "MyEventWriteFunction1".
// #define MY_OBJECT_LIKE_MACRO MyEventWriteFunction2
// #define MCGEN_EVENTWRITETRANSFER MY_OBJECT_LIKE_MACRO // OK, suffix will be "MyEventWriteFunction2".
// #define MY_FUNCTION_LIKE_MACRO(h,e,a,r,c,d) MyNamespace::MyClass::MyEventWriteFunction3(h,e,c,d)
// #define MCGEN_EVENTWRITETRANSFER MY_FUNCTION_LIKE_MACRO // OK, suffix will be "MY_FUNCTION_LIKE_MACRO".
//
#ifndef MCGEN_EVENTREGISTER
#if MCGEN_USE_KERNEL_MODE_APIS
#define MCGEN_EVENTREGISTER EtwRegister
#else
#define MCGEN_EVENTREGISTER EventRegister
#endif
#endif // MCGEN_EVENTREGISTER
#ifndef MCGEN_EVENTUNREGISTER
#if MCGEN_USE_KERNEL_MODE_APIS
#define MCGEN_EVENTUNREGISTER EtwUnregister
#else
#define MCGEN_EVENTUNREGISTER EventUnregister
#endif
#endif // MCGEN_EVENTUNREGISTER
#ifndef MCGEN_EVENTSETINFORMATION
#if MCGEN_USE_KERNEL_MODE_APIS
#define MCGEN_EVENTSETINFORMATION EtwSetInformation
#else
#define MCGEN_EVENTSETINFORMATION EventSetInformation
#endif
#endif // MCGEN_EVENTSETINFORMATION
#ifndef MCGEN_EVENTWRITETRANSFER
#if MCGEN_USE_KERNEL_MODE_APIS
#define MCGEN_EVENTWRITETRANSFER EtwWriteTransfer
#else
#define MCGEN_EVENTWRITETRANSFER EventWriteTransfer
#endif
#endif // MCGEN_EVENTWRITETRANSFER
#ifndef _mcgen_EVENT_BIT_SET
#if defined(_M_IX86) || defined(_M_X64)
// This macro is for use by MC-generated code and should not be used directly.
#define _mcgen_EVENT_BIT_SET(EnableBits, BitPosition) ((((const unsigned char*)EnableBits)[BitPosition >> 3] & (1u << (BitPosition & 7))) != 0)
#else // CPU type
// This macro is for use by MC-generated code and should not be used directly.
#define _mcgen_EVENT_BIT_SET(EnableBits, BitPosition) ((EnableBits[BitPosition >> 5] & (1u << (BitPosition & 31))) != 0)
#endif // CPU type
#endif // _mcgen_EVENT_BIT_SET
// This function is for use by MC-generated code and should not be used directly.
DECLSPEC_NOINLINE __inline
VOID
__stdcall
McGenControlCallbackV2(
_In_ LPCGUID SourceId,
_In_ ULONG ControlCode,
_In_ UCHAR Level,
_In_ ULONGLONG MatchAnyKeyword,
_In_ ULONGLONG MatchAllKeyword,
_In_opt_ PEVENT_FILTER_DESCRIPTOR FilterData,
_Inout_opt_ PVOID CallbackContext
)
/*++
Routine Description:
This is the notification callback for Windows Vista and later.
Arguments:
SourceId - The GUID that identifies the session that enabled the provider.
ControlCode - The parameter indicates whether the provider
is being enabled or disabled.
Level - The level at which the event is enabled.
MatchAnyKeyword - The bitmask of keywords that the provider uses to
determine the category of events that it writes.
MatchAllKeyword - This bitmask additionally restricts the category
of events that the provider writes.
FilterData - The provider-defined data.
CallbackContext - The context of the callback that is defined when the provider
called EtwRegister to register itself.
Remarks:
ETW calls this function to notify provider of enable/disable
--*/
{
PMCGEN_TRACE_CONTEXT Ctx = (PMCGEN_TRACE_CONTEXT)CallbackContext;
ULONG Ix;
#ifndef MCGEN_PRIVATE_ENABLE_CALLBACK_V2
UNREFERENCED_PARAMETER(SourceId);
UNREFERENCED_PARAMETER(FilterData);
#endif
if (Ctx == NULL) {
return;
}
switch (ControlCode) {
case EVENT_CONTROL_CODE_ENABLE_PROVIDER:
Ctx->Level = Level;
Ctx->MatchAnyKeyword = MatchAnyKeyword;
Ctx->MatchAllKeyword = MatchAllKeyword;
Ctx->IsEnabled = EVENT_CONTROL_CODE_ENABLE_PROVIDER;
for (Ix = 0; Ix < Ctx->EnableBitsCount; Ix += 1) {
if (McGenLevelKeywordEnabled(Ctx, Ctx->EnableLevel[Ix], Ctx->EnableKeyWords[Ix]) != FALSE) {
Ctx->EnableBitMask[Ix >> 5] |= (1 << (Ix % 32));
} else {
Ctx->EnableBitMask[Ix >> 5] &= ~(1 << (Ix % 32));
}
}
break;
case EVENT_CONTROL_CODE_DISABLE_PROVIDER:
Ctx->IsEnabled = EVENT_CONTROL_CODE_DISABLE_PROVIDER;
Ctx->Level = 0;
Ctx->MatchAnyKeyword = 0;
Ctx->MatchAllKeyword = 0;
if (Ctx->EnableBitsCount > 0) {
#pragma warning(suppress: 26451) // Arithmetic overflow cannot occur, no matter the value of EnableBitCount
RtlZeroMemory(Ctx->EnableBitMask, (((Ctx->EnableBitsCount - 1) / 32) + 1) * sizeof(ULONG));
}
break;
default:
break;
}
#ifdef MCGEN_PRIVATE_ENABLE_CALLBACK_V2
//
// Call user defined callback
//
MCGEN_PRIVATE_ENABLE_CALLBACK_V2(
SourceId,
ControlCode,
Level,
MatchAnyKeyword,
MatchAllKeyword,
FilterData,
CallbackContext
);
#endif // MCGEN_PRIVATE_ENABLE_CALLBACK_V2
return;
}
#ifndef _mcgen_PENABLECALLBACK
#if MCGEN_USE_KERNEL_MODE_APIS
#define _mcgen_PENABLECALLBACK PETWENABLECALLBACK
#else
#define _mcgen_PENABLECALLBACK PENABLECALLBACK
#endif
#endif // _mcgen_PENABLECALLBACK
#if !defined(_mcgen_PASTE2)
// This macro is for use by MC-generated code and should not be used directly.
#define _mcgen_PASTE2(a, b) _mcgen_PASTE2_imp(a, b)
#define _mcgen_PASTE2_imp(a, b) a##b
#endif // _mcgen_PASTE2
#if !defined(_mcgen_PASTE3)
// This macro is for use by MC-generated code and should not be used directly.
#define _mcgen_PASTE3(a, b, c) _mcgen_PASTE3_imp(a, b, c)
#define _mcgen_PASTE3_imp(a, b, c) a##b##_##c
#endif // _mcgen_PASTE3
//
// Macro validation
//
// Validate MCGEN_EVENTREGISTER:
// Trigger an error if MCGEN_EVENTREGISTER is not an unqualified (simple) identifier:
struct _mcgen_PASTE2(MCGEN_EVENTREGISTER_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTREGISTER);
// Trigger an error if MCGEN_EVENTREGISTER is redefined:
typedef struct _mcgen_PASTE2(MCGEN_EVENTREGISTER_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTREGISTER)
MCGEN_EVENTREGISTER_must_not_be_redefined_between_headers;
// Trigger an error if MCGEN_EVENTREGISTER is defined as a function-like macro:
typedef void MCGEN_EVENTREGISTER_must_not_be_a_functionLike_macro_MCGEN_EVENTREGISTER;
typedef int _mcgen_PASTE2(MCGEN_EVENTREGISTER_must_not_be_a_functionLike_macro_, MCGEN_EVENTREGISTER);
// Validate MCGEN_EVENTUNREGISTER:
// Trigger an error if MCGEN_EVENTUNREGISTER is not an unqualified (simple) identifier:
struct _mcgen_PASTE2(MCGEN_EVENTUNREGISTER_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTUNREGISTER);
// Trigger an error if MCGEN_EVENTUNREGISTER is redefined:
typedef struct _mcgen_PASTE2(MCGEN_EVENTUNREGISTER_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTUNREGISTER)
MCGEN_EVENTUNREGISTER_must_not_be_redefined_between_headers;
// Trigger an error if MCGEN_EVENTUNREGISTER is defined as a function-like macro:
typedef void MCGEN_EVENTUNREGISTER_must_not_be_a_functionLike_macro_MCGEN_EVENTUNREGISTER;
typedef int _mcgen_PASTE2(MCGEN_EVENTUNREGISTER_must_not_be_a_functionLike_macro_, MCGEN_EVENTUNREGISTER);
// Validate MCGEN_EVENTSETINFORMATION:
// Trigger an error if MCGEN_EVENTSETINFORMATION is not an unqualified (simple) identifier:
struct _mcgen_PASTE2(MCGEN_EVENTSETINFORMATION_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTSETINFORMATION);
// Trigger an error if MCGEN_EVENTSETINFORMATION is redefined:
typedef struct _mcgen_PASTE2(MCGEN_EVENTSETINFORMATION_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTSETINFORMATION)
MCGEN_EVENTSETINFORMATION_must_not_be_redefined_between_headers;
// Trigger an error if MCGEN_EVENTSETINFORMATION is defined as a function-like macro:
typedef void MCGEN_EVENTSETINFORMATION_must_not_be_a_functionLike_macro_MCGEN_EVENTSETINFORMATION;
typedef int _mcgen_PASTE2(MCGEN_EVENTSETINFORMATION_must_not_be_a_functionLike_macro_, MCGEN_EVENTSETINFORMATION);
// Validate MCGEN_EVENTWRITETRANSFER:
// Trigger an error if MCGEN_EVENTWRITETRANSFER is not an unqualified (simple) identifier:
struct _mcgen_PASTE2(MCGEN_EVENTWRITETRANSFER_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTWRITETRANSFER);
// Trigger an error if MCGEN_EVENTWRITETRANSFER is redefined:
typedef struct _mcgen_PASTE2(MCGEN_EVENTWRITETRANSFER_definition_must_be_an_unqualified_identifier_, MCGEN_EVENTWRITETRANSFER)
MCGEN_EVENTWRITETRANSFER_must_not_be_redefined_between_headers;;
// Trigger an error if MCGEN_EVENTWRITETRANSFER is defined as a function-like macro:
typedef void MCGEN_EVENTWRITETRANSFER_must_not_be_a_functionLike_macro_MCGEN_EVENTWRITETRANSFER;
typedef int _mcgen_PASTE2(MCGEN_EVENTWRITETRANSFER_must_not_be_a_functionLike_macro_, MCGEN_EVENTWRITETRANSFER);
#ifndef McGenEventWrite_def
#define McGenEventWrite_def
// This macro is for use by MC-generated code and should not be used directly.
#define McGenEventWrite _mcgen_PASTE2(McGenEventWrite_, MCGEN_EVENTWRITETRANSFER)
// This function is for use by MC-generated code and should not be used directly.
DECLSPEC_NOINLINE __inline
ULONG __stdcall
McGenEventWrite(
_In_ PMCGEN_TRACE_CONTEXT Context,
_In_ PCEVENT_DESCRIPTOR Descriptor,
_In_opt_ LPCGUID ActivityId,
_In_range_(1, 128) ULONG EventDataCount,
_Pre_cap_(EventDataCount) EVENT_DATA_DESCRIPTOR* EventData
)
{
const USHORT UNALIGNED* Traits;
// Some customized MCGEN_EVENTWRITETRANSFER macros might ignore ActivityId.
UNREFERENCED_PARAMETER(ActivityId);
Traits = (const USHORT UNALIGNED*)(UINT_PTR)Context->Logger;
if (Traits == NULL) {
EventData[0].Ptr = 0;
EventData[0].Size = 0;
EventData[0].Reserved = 0;
} else {
EventData[0].Ptr = (ULONG_PTR)Traits;
EventData[0].Size = *Traits;
EventData[0].Reserved = 2; // EVENT_DATA_DESCRIPTOR_TYPE_PROVIDER_METADATA
}
return MCGEN_EVENTWRITETRANSFER(
Context->RegistrationHandle,
Descriptor,
ActivityId,
NULL,
EventDataCount,
EventData);
}
#endif // McGenEventWrite_def
#ifndef McGenEventSetInformation_def
#define McGenEventSetInformation_def
#if MCGEN_HAVE_EVENTSETINFORMATION == 1
// This macro is for use by MC-generated code and should not be used directly.
#define _mcgen_EVENTSETINFORMATION_SUFFIX MCGEN_EVENTSETINFORMATION
#elif MCGEN_HAVE_EVENTSETINFORMATION == 2
#if MCGEN_USE_KERNEL_MODE_APIS
// This macro is for use by MC-generated code and should not be used directly.
#define _mcgen_EVENTSETINFORMATION_SUFFIX 2K
#else // MCGEN_USE_KERNEL_MODE_APIS
// This macro is for use by MC-generated code and should not be used directly.
#define _mcgen_EVENTSETINFORMATION_SUFFIX 2U
#endif // MCGEN_USE_KERNEL_MODE_APIS
#else // MCGEN_HAVE_EVENTSETINFORMATION == 0
// This macro is for use by MC-generated code and should not be used directly.
#define _mcgen_EVENTSETINFORMATION_SUFFIX 0
#endif // MCGEN_HAVE_EVENTSETINFORMATION
// This macro is for use by MC-generated code and should not be used directly.
#define McGenEventSetInformation _mcgen_PASTE2(McGenEventSetInformation_, _mcgen_EVENTSETINFORMATION_SUFFIX)
// This function is for use by MC-generated code and should not be used directly.
_IRQL_requires_max_(PASSIVE_LEVEL)
DECLSPEC_NOINLINE __inline
ULONG __stdcall
McGenEventSetInformation(
_In_ REGHANDLE RegHandle,
_In_ EVENT_INFO_CLASS InformationClass,
_In_opt_bytecount_(InformationLength) PVOID EventInformation,
_In_ ULONG InformationLength
)
/*++
Routine Description:
This function invokes EventSetInformation to provide additional information
to the ETW runtime.
Note that the implementation of this function depends on the values of
the MCGEN_HAVE_EVENTSETINFORMATION and MCGEN_EVENTSETINFORMATION macros.
Depending on the values of these macros, this function may call
EventSetInformation directly, may dynamically-load EventSetInformation
via GetProcAddress, or may call a replacement function.
Arguments:
RegHandle - Registration handle returned by EventRegister.
InformationClass - Type of operation to be performed on the registration
object.
EventInformation - The input buffer.
InformationLength - Size of the input buffer.
--*/
{
ULONG Error;
#if MCGEN_HAVE_EVENTSETINFORMATION == 1
#pragma warning(suppress: 6387) // It's ok for EventInformation to be null if InformationLength is 0.
Error = MCGEN_EVENTSETINFORMATION(
RegHandle,
InformationClass,
EventInformation,
InformationLength);
#elif MCGEN_HAVE_EVENTSETINFORMATION == 2
#if MCGEN_USE_KERNEL_MODE_APIS
typedef NTSTATUS(NTAPI* PFEtwSetInformation)(
_In_ REGHANDLE regHandle,
_In_ EVENT_INFO_CLASS informationClass,
_In_opt_bytecount_(informationLength) PVOID eventInformation,
_In_ ULONG informationLength);
static UNICODE_STRING strEtwSetInformation = {
sizeof(L"EtwSetInformation") - 2,
sizeof(L"EtwSetInformation") - 2,
L"EtwSetInformation"
};
PFEtwSetInformation pfEtwSetInformation;
#pragma warning(push)
#pragma warning(disable: 4055) // Allow the cast from a PVOID to a PFN
pfEtwSetInformation = (PFEtwSetInformation)MmGetSystemRoutineAddress(&strEtwSetInformation);
#pragma warning(pop)
if (pfEtwSetInformation)
{
Error = pfEtwSetInformation(
RegHandle,
InformationClass,
EventInformation,
InformationLength);
}
else
{
Error = STATUS_NOT_SUPPORTED;
}
#else // !MCGEN_USE_KERNEL_MODE_APIS
HMODULE hEventing;
Error = ERROR_NOT_SUPPORTED;
if (GetModuleHandleExW(0, L"api-ms-win-eventing-provider-l1-1-0", &hEventing) ||
GetModuleHandleExW(0, L"advapi32", &hEventing))
{
typedef ULONG(WINAPI* PFEventSetInformation)(
_In_ REGHANDLE regHandle,
_In_ EVENT_INFO_CLASS informationClass,
_In_opt_bytecount_(informationLength) PVOID eventInformation,
_In_ ULONG informationLength);
PFEventSetInformation pfEventSetInformation =
(PFEventSetInformation)GetProcAddress(hEventing, "EventSetInformation");
if (pfEventSetInformation)
{
Error = pfEventSetInformation(
RegHandle,
InformationClass,
EventInformation,
InformationLength);
}
FreeLibrary(hEventing);
}
#endif // MCGEN_USE_KERNEL_MODE_APIS
#else // MCGEN_HAVE_EVENTSETINFORMATION == 0
(void)RegHandle;
(void)InformationClass;
(void)EventInformation;
(void)InformationLength;
#if MCGEN_USE_KERNEL_MODE_APIS
Error = STATUS_NOT_SUPPORTED;
#else // !MCGEN_USE_KERNEL_MODE_APIS
Error = ERROR_NOT_SUPPORTED;
#endif // MCGEN_USE_KERNEL_MODE_APIS
#endif // MCGEN_HAVE_EVENTSETINFORMATION
return Error;
}
#endif // McGenEventSetInformation_def
#ifndef McGenEventRegisterContext_def
#define McGenEventRegisterContext_def
// This macro is for use by MC-generated code and should not be used directly.
#define McGenEventRegisterContext _mcgen_PASTE3(McGenEventRegisterContext_, MCGEN_EVENTREGISTER, _mcgen_EVENTSETINFORMATION_SUFFIX)
#pragma warning(push)
#pragma warning(disable:6103)
// This function is for use by MC-generated code and should not be used directly.
_IRQL_requires_max_(PASSIVE_LEVEL)
DECLSPEC_NOINLINE __inline
ULONG __stdcall
McGenEventRegisterContext(
_In_ LPCGUID ProviderId,
_In_opt_ _mcgen_PENABLECALLBACK EnableCallback,
_In_opt_ PVOID CallbackContext,
_Inout_ MCGEN_TRACE_CONTEXT* Context
)
/*++
Routine Description:
This function registers the provider with ETW and registers provider
traits. The EventRegister[ProviderName] macro will use this function
instead of McGenEventRegister if the provider has traits to be registered.
Arguments:
ProviderId - Provider ID to register with ETW.
EnableCallback - Callback to be used.
CallbackContext - Context for the callback.
Context - Provider context.
Remarks:
Should not be called if the provider is already registered (i.e. should not
be called if Context->RegistrationHandle != 0). Repeatedly registering a
provider is a bug and may indicate a race condition.
--*/
{
ULONG Error;
if (Context->RegistrationHandle != 0)
{
#if MCGEN_USE_KERNEL_MODE_APIS
Error = (ULONG)STATUS_INVALID_PARAMETER;
#else
Error = ERROR_INVALID_PARAMETER;
#endif
}
else
{
Error = MCGEN_EVENTREGISTER(
ProviderId,
EnableCallback,
CallbackContext,
&Context->RegistrationHandle);
if (Error == 0 && Context->Logger != 0)
{
(void)McGenEventSetInformation(
Context->RegistrationHandle,
(EVENT_INFO_CLASS)2, // EventProviderSetTraits
(void*)(UINT_PTR)Context->Logger,
*(USHORT const UNALIGNED*)(UINT_PTR)Context->Logger);
}
}
return Error;
}
#pragma warning(pop)
#endif // McGenEventRegisterContext_def
// This macro is for use by MC-generated code and should not be used directly.
#define McGenEventRegister _mcgen_PASTE2(McGenEventRegister_, MCGEN_EVENTREGISTER)
#pragma warning(push)
#pragma warning(disable:6103)
// This function is for use by MC-generated code and should not be used directly.
DECLSPEC_NOINLINE __inline
ULONG __stdcall
McGenEventRegister(
_In_ LPCGUID ProviderId,
_In_opt_ _mcgen_PENABLECALLBACK EnableCallback,
_In_opt_ PVOID CallbackContext,
_Inout_ PREGHANDLE RegHandle
)
/*++
Routine Description:
This function registers the provider with ETW.
Arguments:
ProviderId - Provider ID to register with ETW.
EnableCallback - Callback to be used.
CallbackContext - Context for the callback.
RegHandle - Pointer to registration handle.
Remarks:
Should not be called if the provider is already registered (i.e. should not
be called if *RegHandle != 0). Repeatedly registering a provider is a bug
and may indicate a race condition. However, for compatibility with previous
behavior, this function will return SUCCESS in this case.
--*/
{
ULONG Error;
if (*RegHandle != 0)
{
Error = 0; // ERROR_SUCCESS
}
else
{
Error = MCGEN_EVENTREGISTER(ProviderId, EnableCallback, CallbackContext, RegHandle);
}
return Error;
}
#pragma warning(pop)
// This macro is for use by MC-generated code and should not be used directly.
#define McGenEventUnregister _mcgen_PASTE2(McGenEventUnregister_, MCGEN_EVENTUNREGISTER)
// This function is for use by MC-generated code and should not be used directly.
DECLSPEC_NOINLINE __inline
ULONG __stdcall
McGenEventUnregister(_Inout_ PREGHANDLE RegHandle)
/*++
Routine Description:
Unregister from ETW and set *RegHandle = 0.
Arguments:
RegHandle - the pointer to the provider registration handle
Remarks:
If provider has not been registered (i.e. if *RegHandle == 0),
return SUCCESS. It is safe to call McGenEventUnregister even if the
call to McGenEventRegister returned an error.
--*/
{
ULONG Error;
if(*RegHandle == 0)
{
Error = 0; // ERROR_SUCCESS
}
else
{
Error = MCGEN_EVENTUNREGISTER(*RegHandle);
*RegHandle = (REGHANDLE)0;
}
return Error;
}
typedef LONG (__stdcall *PFN_WMIENTRY_CALLBACK)(
_In_ UCHAR MinorFunction,
_In_opt_ PVOID DataPath,
_In_ ULONG BufferLength,
_Inout_updates_bytes_(BufferLength) PVOID Buffer,
_In_ PVOID Context,
_Out_ PULONG Size
);
// This function is for use by MC-generated code and should not be used directly.
NTSTATUS __stdcall
McGenEventTracingRegister(
_In_ LPCGUID ProviderId,
_In_opt_ PETWENABLECALLBACK EnableCallback,
_In_opt_ PVOID CallbackContext,
_Inout_ PREGHANDLE RegHandle
);
// This function is for use by MC-generated code and should not be used directly.
NTSTATUS __stdcall
McGenControlCallback(
_In_ UCHAR MinorFunction,
_In_opt_ PVOID DataPath,
_In_ ULONG BufferLength,
_Inout_updates_bytes_(BufferLength) PVOID Buffer,
_In_ PVOID Context,
_Out_ PULONG Size
);
// This function is for use by MC-generated code and should not be used directly.
VOID __stdcall
McGenControlCallbackV2(
_In_ LPCGUID SourceId,
_In_ ULONG ControlCode,
_In_ UCHAR Level,
_In_ ULONGLONG MatchAnyKeyword,
_In_ ULONGLONG MatchAllKeyword,
_In_opt_ PEVENT_FILTER_DESCRIPTOR FilterData,
_Inout_opt_ PVOID CallbackContext
);
typedef
ULONG
(__stdcall *PFN_ETW_WRITE)(
_In_ REGHANDLE RegHandle,
_In_ PCEVENT_DESCRIPTOR EventDescriptor,
_In_opt_ LPCGUID ActivityId,
_In_ ULONG UserDataCount,
_In_reads_opt_(UserDataCount) PEVENT_DATA_DESCRIPTOR UserData
);
typedef
NTSTATUS
(__stdcall *PFN_ETW_REGISTER)(
_In_ LPCGUID ProviderId,
_In_opt_ PETWENABLECALLBACK EnableCallback,
_In_opt_ PVOID CallbackContext,
_Out_ PREGHANDLE RegHandle
);
typedef
NTSTATUS
(__stdcall *PFN_ETW_UNREGISTER)(
_In_ REGHANDLE RegHandle
);
typedef
BOOLEAN
NTKERNELAPI
(__stdcall FN_PS_GETVERSION)(
_Out_opt_ PULONG MajorVersion,
_Out_opt_ PULONG MinorVersion,
_Out_opt_ PULONG BuildNumber,
_Out_opt_ PUNICODE_STRING CSDVersion
);
typedef FN_PS_GETVERSION *PFN_PS_GETVERSION;
#define WMIREG_FLAG_CALLBACK 0x80000000 // not exposed in DDK
#ifndef WMIREG_FLAG_TRACE_PROVIDER
#define WMIREG_FLAG_TRACE_PROVIDER 0x00010000
#endif
// This structure is for use by MC-generated code and should not be used directly.
typedef struct _MCGEN_TRACE_CONTEXT
{
#pragma prefast(suppress:__WARNING_ENCODE_GLOBAL_FUNCTION_POINTER, "this pointer can not be encoded");
PFN_WMIENTRY_CALLBACK Callback;
TRACEHANDLE Logger;
TRACEHANDLE RegistrationHandle;
ULONGLONG MatchAnyKeyword;
ULONGLONG MatchAllKeyword;
LPCGUID ControlGuid;
#pragma prefast(suppress:__WARNING_ENCODE_GLOBAL_FUNCTION_POINTER, "this pointer can not be encoded");
PFN_ETW_WRITE PfnEtwWrite;
#pragma prefast(suppress:__WARNING_ENCODE_GLOBAL_FUNCTION_POINTER, "this pointer can not be encoded");
PFN_ETW_REGISTER PfnEtwRegister;
#pragma prefast(suppress:__WARNING_ENCODE_GLOBAL_FUNCTION_POINTER, "this pointer can not be encoded");
PFN_ETW_UNREGISTER PfnEtwUnregister;
#pragma prefast(suppress:__WARNING_ENCODE_GLOBAL_FUNCTION_POINTER, "this pointer can not be encoded");
PFN_PS_GETVERSION pfnPsGetVersion;
ULONG Flags;
ULONG IsEnabled;
UCHAR Level;
BOOLEAN McGenPreVista;
BOOLEAN McGenTracingSupportInit;
USHORT EnableBitsCount;
PULONG EnableBitMask;
const ULONGLONG* EnableKeyWords;
const UCHAR* EnableLevel;
} MCGEN_TRACE_CONTEXT, *PMCGEN_TRACE_CONTEXT;
BOOLEAN __stdcall
McGenEventTracingEnabled(
_In_ PMCGEN_TRACE_CONTEXT EnableInfo,
_In_ PCEVENT_DESCRIPTOR EventDescriptor
);
BOOLEAN __stdcall
McGenLevelKeywordEnabled(
_In_ PMCGEN_TRACE_CONTEXT EnableInfo,
_In_ UCHAR Level,
_In_ ULONGLONG Keyword
);
// This function is for use by MC-generated code and should not be used directly.
NTSTATUS __stdcall
McGenEventTracingUnregister(_Inout_ PMCGEN_TRACE_CONTEXT Context);
// This function is for use by MC-generated code and should not be used directly.
NTSTATUS McGenInitTracingSupport(
_In_ PMCGEN_TRACE_CONTEXT Context
);
#ifdef ALLOC_PRAGMA
#pragma alloc_text( PAGE, McGenEventTracingRegister)
#pragma alloc_text( PAGE, McGenEventTracingUnregister)
#pragma alloc_text( PAGE, McGenControlCallback)
#pragma alloc_text( PAGE, McGenInitTracingSupport)
#endif // ALLOC_PRAGMA
FORCEINLINE
BOOLEAN
__stdcall
McGenEventTracingEnabled(
_In_ PMCGEN_TRACE_CONTEXT EnableInfo,
_In_ PCEVENT_DESCRIPTOR EventDescriptor
)
{
return McGenLevelKeywordEnabled(EnableInfo, EventDescriptor->Level, EventDescriptor->Keyword);
}
FORCEINLINE
BOOLEAN __stdcall
McGenLevelKeywordEnabled(
_In_ PMCGEN_TRACE_CONTEXT EnableInfo,
_In_ UCHAR Level,
_In_ ULONGLONG Keyword
)
{
if(!EnableInfo){
return FALSE;
}
if (EnableInfo->McGenPreVista) {
return ( ((Level <= EnableInfo->Level) || (Level == 0)) &&
(((ULONG)(Keyword & 0xFFFFFFFF) == 0) || ((ULONG)(Keyword & 0xFFFFFFFF) & EnableInfo->Flags)));
}
//
// Check if the event Level is lower than the level at which
// the channel is enabled.
// If the event Level is 0 or the channel is enabled at level 0,
// all levels are enabled.
//
if ((Level <= EnableInfo->Level) || // This also covers the case of Level == 0.
(EnableInfo->Level == 0)) {
//
// Check if Keyword is enabled
//
if ((Keyword == (ULONGLONG)0) ||
((Keyword & EnableInfo->MatchAnyKeyword) &&
((Keyword & EnableInfo->MatchAllKeyword) == EnableInfo->MatchAllKeyword))) {
return TRUE;
}
}
return FALSE;
}
// This function is for use by MC-generated code and should not be used directly.
DECLSPEC_NOINLINE __inline
NTSTATUS __stdcall
McGenControlCallback(
_In_ UCHAR MinorFunction,
_In_opt_ PVOID DataPath,
_In_ ULONG BufferLength,
_Inout_updates_bytes_(BufferLength) PVOID Buffer,
_In_ PVOID Context,
_Out_ PULONG Size
)
/*++
Routine Description:
Called by WMI for registration/unregistration
or enabled/disabled.
Arguments:
MinorFunction - specifies the type of callback (register, event enable/disable)
DataPath - varies depending on the ActionCode
BufferLength - size of the Buffer parameter
Buffer - in/out buffer where we read from or write to depending on the type
of callback
Context - the pointer private struct MCGEN_TRACE_CONTEXT
Size - output parameter to receive the amount of data written into Buffer
Return Value:
NTSTATUS code indicating success/failure
Comments:
If return value is STATUS_BUFFER_TOO_SMALL and BufferLength >= 4,
then first ulong of buffer contains required size.
Supports XP and W2K3, no W2K support.
--*/
{
PMCGEN_TRACE_CONTEXT Ctx;
NTSTATUS Status = STATUS_SUCCESS;
UNREFERENCED_PARAMETER(DataPath);
PAGED_CODE();
McGenDebug(0,("McGenControlCallback 0x%08X %p\n", MinorFunction, Context));
*Size = 0;
//
// Get the context
//
Ctx = (PMCGEN_TRACE_CONTEXT)Context;
switch (MinorFunction) {
case IRP_MN_REGINFO:
{
PWMIREGINFOW WmiRegInfo;
ULONG BufferNeeded;
WmiRegInfo = (PWMIREGINFO)Buffer;
//
// Calculate buffer size need to hold all info.
//
BufferNeeded = FIELD_OFFSET(WMIREGINFOW, WmiRegGuid) +
sizeof(WMIREGGUIDW);
//
// If the provided buffer is large enough, then fill with info.
//
if (BufferNeeded <= BufferLength) {
RtlZeroMemory(Buffer, BufferLength);
//
// Fill in the WMIREGINFO
//
WmiRegInfo->BufferSize = BufferNeeded;
WmiRegInfo->RegistryPath = 0;
WmiRegInfo->GuidCount = 1;
//
// Fill in the WMIREGGUID
//
WmiRegInfo->WmiRegGuid[0].Guid = *Ctx->ControlGuid;
WmiRegInfo->WmiRegGuid[0].Flags = WMIREG_FLAG_TRACE_CONTROL_GUID |
WMIREG_FLAG_TRACED_GUID;
McGenDebug(0,("Control GUID::%08x-%04x-%04x-%02x%02x-%02x%02x%02x%02x%02x%02x\n",
Ctx->ControlGuid->Data1,
Ctx->ControlGuid->Data2,
Ctx->ControlGuid->Data3,
Ctx->ControlGuid->Data4[0],
Ctx->ControlGuid->Data4[1],
Ctx->ControlGuid->Data4[2],
Ctx->ControlGuid->Data4[3],
Ctx->ControlGuid->Data4[4],
Ctx->ControlGuid->Data4[5],
Ctx->ControlGuid->Data4[6],
Ctx->ControlGuid->Data4[7]
));
Status = STATUS_SUCCESS;
*Size = BufferNeeded;
} else {
Status = STATUS_BUFFER_TOO_SMALL;
if (BufferLength >= sizeof(ULONG)) {
*((PULONG)Buffer) = BufferNeeded;
*Size = sizeof(ULONG);
}
}
break;
}
case IRP_MN_ENABLE_EVENTS:
case IRP_MN_DISABLE_EVENTS:
{
PWNODE_HEADER Wnode;
ULONG Level;
ULONG ReturnLength;
ULONG Ix;
if (Context == NULL) {
Status = STATUS_WMI_GUID_NOT_FOUND;
break;
}
if (BufferLength < sizeof(WNODE_HEADER)) {
Status = STATUS_INVALID_PARAMETER;
break;
}
//
// Initialize locals
//
Wnode = (PWNODE_HEADER)Buffer;
//
// Do the requested event action
//
if (MinorFunction == IRP_MN_DISABLE_EVENTS) {
McGenDebug(0,("McGenControlCallback: DISABLE_EVENTS\n"));
Ctx->IsEnabled = 0;
Ctx->Level = 0;
Ctx->Flags = 0;
Ctx->Logger = 0;
if (Ctx->EnableBitsCount > 0) {
RtlZeroMemory(Ctx->EnableBitMask, (((Ctx->EnableBitsCount - 1) / 32) + 1) * sizeof(ULONG));
}
} else {
Ctx->Logger = (TRACEHANDLE)( Wnode->HistoricalContext);
Status = WmiQueryTraceInformation(TraceEnableLevelClass,
&Level,
sizeof(Level),
&ReturnLength,
(PVOID) Wnode );
if (Status == STATUS_SUCCESS) {
Ctx->Level = (UCHAR)Level;
}
Status = WmiQueryTraceInformation(TraceEnableFlagsClass,
&Ctx->Flags,
sizeof(Ctx->Flags),
&ReturnLength,
(PVOID) Wnode );
Ctx->IsEnabled = 1;
for (Ix = 0; Ix < Ctx->EnableBitsCount; Ix += 1) {
if (McGenLevelKeywordEnabled(Ctx, Ctx->EnableLevel[Ix], Ctx->EnableKeyWords[Ix]) != FALSE) {
Ctx->EnableBitMask[Ix >> 5] |= (1 << (Ix % 32));
} else {
Ctx->EnableBitMask[Ix >> 5] &= ~(1 << (Ix % 32));
}
}
McGenDebug(0,("McGenControlCallback: ENABLE_EVENTS "
"LoggerId %d, Flags 0x%08X, Level 0x%02X\n",
(USHORT) Ctx->Logger,
Ctx->Flags,
Ctx->Level));
}
#ifdef MCGEN_PRIVATE_ENABLE_CALLBACK
//
// Notify changes to flags, level for GUID
//
MCGEN_PRIVATE_ENABLE_CALLBACK(Ctx->ControlGuid,
Ctx->Logger,
(MinorFunction != IRP_MN_DISABLE_EVENTS) ? TRUE:FALSE,
Ctx->Flags,
Ctx->Level );
#endif
break;
}
case IRP_MN_ENABLE_COLLECTION:
case IRP_MN_DISABLE_COLLECTION:
{
Status = STATUS_SUCCESS;
break;
}
case IRP_MN_QUERY_ALL_DATA:
case IRP_MN_QUERY_SINGLE_INSTANCE:
case IRP_MN_CHANGE_SINGLE_INSTANCE:
case IRP_MN_CHANGE_SINGLE_ITEM:
case IRP_MN_EXECUTE_METHOD:
{
Status = STATUS_INVALID_DEVICE_REQUEST;
break;
}
default:
{
Status = STATUS_INVALID_DEVICE_REQUEST;
break;
}
}
return(Status);
}
// This function is for use by MC-generated code and should not be used directly.
DECLSPEC_NOINLINE __inline
NTSTATUS __stdcall
McGenEventTracingRegister(
_In_ LPCGUID ProviderId,
_In_opt_ PETWENABLECALLBACK EnableCallback,
_In_opt_ PVOID CallbackContext,
_Inout_ PREGHANDLE RegHandle
)
/*++
Routine Description:
This function registers the provider with ETW KERNEL mode.
Arguments:
ProviderId - Provider ID to be registered with ETW.
EnableCallback - Callback to be used.
CallbackContext - Context for this provider.
RegHandle - Pointer to registration handle.
Remarks:
If the handle != NULL will return STATUS_SUCCESS
If Windows 2000, provider will not register.
--*/
{
NTSTATUS Status;
PMCGEN_TRACE_CONTEXT Context = (PMCGEN_TRACE_CONTEXT)CallbackContext;
PAGED_CODE();
if (!Context) {
return STATUS_INVALID_PARAMETER;
}
if (!RegHandle) {
return STATUS_INVALID_PARAMETER;
}
if (*RegHandle) {
//
// already registered
//
return STATUS_SUCCESS;
}
//
// Initialize Tracing funtion pointers according to OS version
//
Status = McGenInitTracingSupport(Context);
if (Status == STATUS_INVALID_PARAMETER) {
//
// This means that its W2K, we will not register the provider
//
McGenDebug(0,("Generated code does not support Windows 2000\n"));
return STATUS_SUCCESS;
}
//
// Vista
//
if (!Context->McGenPreVista) {
Status = Context->PfnEtwRegister(ProviderId,
(EnableCallback == NULL) ? McGenControlCallbackV2 : EnableCallback,
CallbackContext,
RegHandle);
} else {
Context->Callback = (EnableCallback == NULL) ? McGenControlCallback : (PFN_WMIENTRY_CALLBACK)EnableCallback;
Context->ControlGuid = ProviderId;
#pragma prefast(suppress:__WARNING_BANNED_API_ARGUMENT_USAGE, "MC Generated Code Down-Level Support");
Status = IoWMIRegistrationControl((PDEVICE_OBJECT)Context,
WMIREG_ACTION_REGISTER |
WMIREG_FLAG_CALLBACK |
WMIREG_FLAG_TRACE_PROVIDER);
McGenDebug(0,("IoWMIRegistrationControl Status = %08X\n", Status));
Context->RegistrationHandle = (REGHANDLE)Context;
}
return Status;
}
// This function is for use by MC-generated code and should not be used directly.
DECLSPEC_NOINLINE __inline
NTSTATUS
__stdcall
McGenEventTracingUnregister(
_Inout_ PMCGEN_TRACE_CONTEXT Context
)
/*++
Routine Description:
Unregister from ETW KERNEL mode.
N.B. If provider has not registered, RegistrationHandle == NULL,
return STATUS_SUCCESS
Arguments:
Context - Context for this provider
Return Value:
Status code.
--*/
{
NTSTATUS Status = STATUS_SUCCESS;
PAGED_CODE();
if (!Context) {
return STATUS_INVALID_PARAMETER;
}
if (!Context->McGenTracingSupportInit) {
//
// EventRegister<ProviderName> macro has not been called
//
return STATUS_SUCCESS;
}
if (!(Context->RegistrationHandle)) {
//
// Provider has not been registerd
//
return STATUS_SUCCESS;
}
Context->IsEnabled = 0;
if (!Context->McGenPreVista) {
Status = Context->PfnEtwUnregister(Context->RegistrationHandle);
} else {
IoWMIRegistrationControl((PDEVICE_OBJECT)Context,
WMIREG_ACTION_DEREGISTER |
WMIREG_FLAG_CALLBACK );
Context->Flags = 0;
Context->Level = 0;
Context->Logger = 0;
if (Context->EnableBitsCount > 0) {
RtlZeroMemory(Context->EnableBitMask, (((Context->EnableBitsCount - 1) / 32) + 1) * sizeof(ULONG));
}
}
Context->RegistrationHandle = (REGHANDLE)0;
return Status;
}
#endif
// This function is for use by MC-generated code and should not be used directly.
FORCEINLINE
NTSTATUS McGenInitTracingSupport(
_In_ PMCGEN_TRACE_CONTEXT Context
)
/*++
Routine Description:
This function assigns at runtime the ETW API set to be use for tracing.
Arguments:
Context - Provider Context
Remarks:
At runtime assign the functions pointers for the trace APIs to be use.
Vista and later use EtwWrite, EtwRegister, otherwise use IoWMIWriteEvent, IoWMIRegistrationControl
--*/
{
ULONG MajorVersion = 0;
ULONG MinorVersion = 0;
UNICODE_STRING Name;
PAGED_CODE();
if (Context->McGenTracingSupportInit) {
return STATUS_SUCCESS;
}
RtlInitUnicodeString(&Name, L"PsGetVersion");
Context->pfnPsGetVersion = (PFN_PS_GETVERSION) (INT_PTR)
MmGetSystemRoutineAddress(&Name);
if (Context->pfnPsGetVersion != NULL) {
Context->pfnPsGetVersion(&MajorVersion,
&MinorVersion,
NULL,
NULL);
}
if (MajorVersion < 6) {
//
// If it's W2K return
//
if ((MajorVersion == 5) && (MinorVersion == 0)) {
return STATUS_INVALID_PARAMETER;
}
//
// XP or W2K3
//
Context->McGenPreVista = TRUE;
goto done;
}
RtlInitUnicodeString(&Name, L"EtwRegister");
Context->PfnEtwRegister = (PFN_ETW_REGISTER) (INT_PTR)
MmGetSystemRoutineAddress(&Name);
RtlInitUnicodeString(&Name, L"EtwUnregister");
Context->PfnEtwUnregister = (PFN_ETW_UNREGISTER) (INT_PTR)
MmGetSystemRoutineAddress(&Name);
RtlInitUnicodeString(&Name, L"EtwWrite");
Context->PfnEtwWrite = (PFN_ETW_WRITE) (INT_PTR)
MmGetSystemRoutineAddress(&Name);
if ((Context->PfnEtwRegister == NULL) ||
(Context->PfnEtwUnregister == NULL) ||
(Context->PfnEtwWrite == NULL)) {
//
// Subsitute with the generated funtions
//
Context->PfnEtwRegister = McGenEventTracingRegister;
Context->PfnEtwUnregister = NULL;
Context->McGenPreVista = TRUE;
McGenDebug(0,("[McGenInitTracingSupport] : Could not load V2 ETW APIs\n"));
}
done:
McGenDebug(1, ("[McGenInitTracingSupport] Prevista %s \n", McGenPreVista ? "TRUE" : "FALSE" ));
Context->McGenTracingSupportInit = TRUE;
return STATUS_SUCCESS;
}
//*****************************************************************************
// Notes on the ETW event code generated by MC with the -mof option enabled:
//
// General: The -mof option is deprecated and will be removed in a future
// version of MC.exe.
//
// Arrays : Only constant size arrays supported. The length must be specified
// in the manifest.
//
// Strings: No support for arrays of strings.
//
// SID : No support for array of SIDs. The macro will take a pointer to the
// SID and use appropriate GetLengthSid function to get the length.
//*****************************************************************************
//**********************************************************************
//
// Vista down-level support
//
//**********************************************************************
#define __WARNING_BANNED_LEGACY_INSTRUMENTATION_API_USAGE 28735
typedef
ULONG
(__stdcall *PFN_EVENT_WRITE)(
_In_ REGHANDLE RegHandle,
_In_ PCEVENT_DESCRIPTOR EventDescriptor,
_In_ ULONG UserDataCount,
_In_reads_opt_(UserDataCount) PEVENT_DATA_DESCRIPTOR UserData
);
typedef
ULONG
(__stdcall *PFN_EVENT_REGISTER)(
_In_ LPCGUID ProviderId,
_In_opt_ PENABLECALLBACK EnableCallback,
_In_opt_ PVOID CallbackContext,
_Out_ PREGHANDLE RegHandle
);
typedef
ULONG
(__stdcall *PFN_EVENT_UNREGISTER)(
_In_ REGHANDLE RegHandle
);
// This function is for use by MC-generated code and should not be used directly.
ULONG __stdcall
McGenEventTracingRegister(
_In_ LPCGUID ProviderId,
_In_opt_ PENABLECALLBACK EnableCallback,
_In_opt_ PVOID CallbackContext,
_Inout_ PREGHANDLE RegHandle
);
// This function is for use by MC-generated code and should not be used directly.
ULONG __stdcall
McGenEventTracingUnregister2(
_Inout_ PMCGEN_TRACE_CONTEXT Context
);
BOOLEAN __stdcall
McGenEventTracingEnabled(
_In_ PMCGEN_TRACE_CONTEXT EnableInfo,
_In_ PCEVENT_DESCRIPTOR EventDescriptor
);
BOOLEAN __stdcall
McGenLevelKeywordEnabled(
_In_ PMCGEN_TRACE_CONTEXT EnableInfo,
_In_ UCHAR Level,
_In_ ULONGLONG Keyword
);
#if !defined(MCGEN_TRACE_GLOBALS_DEF)
#define MCGEN_TRACE_GLOBALS_DEF
// These variables are for use by MC-generated code and should not be used directly.
__declspec(selectany) BOOLEAN McGenTracingSupportInit = FALSE;
__declspec(selectany) BOOLEAN McGenPreVista = FALSE;
#pragma prefast(suppress:__WARNING_ENCODE_GLOBAL_FUNCTION_POINTER, "this pointer can not be encoded");
__declspec(selectany) PFN_EVENT_WRITE PfnEventWrite = NULL;
#pragma prefast(suppress:__WARNING_ENCODE_GLOBAL_FUNCTION_POINTER, "this pointer can not be encoded");
__declspec(selectany) PFN_EVENT_REGISTER PfnEventRegister = McGenEventTracingRegister;
#pragma prefast(suppress:__WARNING_ENCODE_GLOBAL_FUNCTION_POINTER, "this pointer can not be encoded");
__declspec(selectany) PFN_EVENT_UNREGISTER PfnEventUnregister = NULL;
#endif // MCGEN_TRACE_GLOBALS_DEF
#if !defined(McGenEventEnabledCheck)
#define McGenEventEnabledCheck
FORCEINLINE
BOOLEAN __stdcall
McGenLevelKeywordEnabled(
_In_ PMCGEN_TRACE_CONTEXT EnableInfo,
_In_ UCHAR Level,
_In_ ULONGLONG Keyword
)
{
if(!EnableInfo){
return FALSE;
}
if(McGenPreVista){
return ( ((Level <= EnableInfo->Level) || (EnableInfo->Level == 0)) &&
(((ULONG)(Keyword & 0xFFFFFFFF) == 0) || ((ULONG)(Keyword & 0xFFFFFFFF) & EnableInfo->Flags)));
}
//
// Check if the event level is lower than the level at which
// the channel is enabled.
// If the event level is 0 or the channel is enabled at level 0,
// all levels are enabled.
//
if ((Level <= EnableInfo->Level) || // This also covers the case of Level == 0.
(EnableInfo->Level == 0)) {
//
// Check if Keyword is enabled
//
if ((Keyword == (ULONGLONG)0) ||
((Keyword & EnableInfo->MatchAnyKeyword) &&
((Keyword & EnableInfo->MatchAllKeyword) == EnableInfo->MatchAllKeyword))) {
return TRUE;
}
}
return FALSE;
}
FORCEINLINE
BOOLEAN __stdcall
McGenEventTracingEnabled(
_In_ PMCGEN_TRACE_CONTEXT EnableInfo,
_In_ PCEVENT_DESCRIPTOR EventDescriptor
)
{
return McGenLevelKeywordEnabled(EnableInfo, EventDescriptor->Level, EventDescriptor->Keyword);
}
#endif
// This function is for use by MC-generated code and should not be used directly.
DECLSPEC_NOINLINE __inline
ULONG __stdcall
McGenControlCallback(
_In_ WMIDPREQUESTCODE RequestCode,
_In_ PVOID Context,
_Inout_ ULONG *InOutBufferSize,
_Inout_ PVOID Buffer
)
/*++
Routine Description:
This is the notification callback for pre-Vista support.
Arguments:
Remarks:
ETW calls this function to notify provider of enable/disable
--*/
{
PMCGEN_TRACE_CONTEXT Ctx = (PMCGEN_TRACE_CONTEXT)Context;
TRACEHANDLE Logger;
ULONG Flags;
ULONG IsEnabled = 0;
UCHAR Level;
ULONG Ix;
*InOutBufferSize = 0;
switch (RequestCode) {
case WMI_ENABLE_EVENTS:
{
Logger = GetTraceLoggerHandle( Buffer );
Level = GetTraceEnableLevel(Logger);
Flags = GetTraceEnableFlags(Logger);
IsEnabled = 1;
McGenDebug(1, ("[Callback] WMI_ENABLE_EVENTS Ctx %p Flags %x"
" Lev %d Logger %I64x\n",
Ctx, Flags, Level, Logger) );
//
// 0 for flags is considered "ALL"
//
if (Flags == 0) {
Flags = 0xFFFFFFFF;
}
break;
}
case WMI_DISABLE_EVENTS:
{
Logger = 0;
Flags = 0;
Level = 0;
if (Ctx->EnableBitsCount > 0) {
RtlZeroMemory(Ctx->EnableBitMask, (((Ctx->EnableBitsCount - 1) / 32) + 1) * sizeof(ULONG));
}
McGenDebug(1, ("[Callback] WMI_DISABLE_EVENTS Ctx 0x%08p\n", Ctx));
break;
}
default:
{
return(ERROR_INVALID_PARAMETER);
}
}
Ctx->Logger = Logger;
Ctx->Level = Level;
Ctx->Flags = Flags;
Ctx->IsEnabled = IsEnabled;
for (Ix = 0; Ix < Ctx->EnableBitsCount; Ix += 1) {
if (McGenLevelKeywordEnabled(Ctx, Ctx->EnableLevel[Ix], Ctx->EnableKeyWords[Ix]) != FALSE) {
Ctx->EnableBitMask[Ix >> 5] |= (1 << (Ix % 32));
} else {
Ctx->EnableBitMask[Ix >> 5] &= ~(1 << (Ix % 32));
}
}
#ifdef MCGEN_PRIVATE_ENABLE_CALLBACK
//
// Call user defined callback down-level
//
MCGEN_PRIVATE_ENABLE_CALLBACK(
RequestCode,
Context,
InOutBufferSize,
Buffer
);
#endif
return(ERROR_SUCCESS);
}
// This function is for use by MC-generated code and should not be used directly.
FORCEINLINE
ULONG __stdcall
McGenEventTracingRegister(
_In_ LPCGUID ProviderId,
_In_opt_ PENABLECALLBACK EnableCallback,
_In_opt_ PVOID CallbackContext,
_Inout_ PREGHANDLE RegHandle
)
/*++
Routine Description:
This function registers the provider with ETW and handles OS version.
Arguments:
ProviderId - Provider Id to be register with ETW
EnableCallback - Callback to be used:
Vista : McGenControlCallbackV2
down-level : McGenControlCallback
CallbackContext - Context for this provider is PMCGEN_TRACE_CONTEXT
RegHandle - down-level is a pointer to PMCGEN_TRACE_CONTEXT
Remarks:
Register with ETW Vista down-level, and set the RegHandle as a pointer to
PMCGEN_TRACE_CONTEXT for this provider. For Vista registers the provider.
--*/
{
ULONG Error = ERROR_SUCCESS;
if(!RegHandle) {
return ERROR_INVALID_PARAMETER;
}
if(*RegHandle) {
//
// already registered, ignore this one
//
goto Cleanup;
}
//
// Initialize Tracing funtion pointers according to OS version
//
McGenInitTracingSupport();
//
// Vista
//
if(!McGenPreVista ){
Error = PfnEventRegister(ProviderId,
(EnableCallback == NULL) ? McGenControlCallbackV2 : EnableCallback,
CallbackContext,
RegHandle);
} else {
//
// down-level : XP/W2K3
//
PMCGEN_TRACE_CONTEXT Context = (PMCGEN_TRACE_CONTEXT)CallbackContext;
TRACE_GUID_REGISTRATION TraceRegistration;
if(CallbackContext == NULL) {
Error = ERROR_INVALID_PARAMETER;
goto Cleanup;
}
*RegHandle = (REGHANDLE)CallbackContext;
TraceRegistration.Guid = ProviderId;
TraceRegistration.RegHandle = 0;
#pragma prefast(suppress:__WARNING_BANNED_LEGACY_INSTRUMENTATION_API_USAGE, "Generated Code Down-Level Support");
Error = RegisterTraceGuids((EnableCallback == NULL) ? McGenControlCallback : (WMIDPREQUEST)EnableCallback,
CallbackContext,
ProviderId,
1,
&TraceRegistration,
0,
0,
&Context->RegistrationHandle);
}
Cleanup:
return Error;
}
#if !defined(McGenEventTracingUnregister2_df)
#define McGenEventTracingUnregister2_df
#pragma warning(push)
#pragma warning(disable:4068)
// This function is for use by MC-generated code and should not be used directly.
__inline
ULONG __stdcall
McGenEventTracingUnregister2(
_Inout_ PMCGEN_TRACE_CONTEXT Context
)
/*++
Routine Description:
Unregister from ETW.
Arguments:
Context is the pointer to the provider context.
--*/
{
ULONG Error;
if (Context == NULL) {
return ERROR_INVALID_PARAMETER;
}
if (!McGenTracingSupportInit) {
//
// EventRegister<ProviderName> macro has not been called
//
return ERROR_SUCCESS;
}
if (!Context->RegistrationHandle) {
//
// Provider has not registered
//
return ERROR_SUCCESS;
}
//
// Vista
//
if (!McGenPreVista) {
Error = PfnEventUnregister(Context->RegistrationHandle);
} else {
//
// down-level : XP/W2K3
//
#pragma prefast(suppress:__WARNING_BANNED_LEGACY_INSTRUMENTATION_API_USAGE, "Generated Code Down-Level Support");
Error = UnregisterTraceGuids(Context->RegistrationHandle);
Context->Flags = 0;
Context->Level = 0;
Context->Logger = 0;
if (Context->EnableBitsCount > 0) {
RtlZeroMemory(Context->EnableBitMask, (((Context->EnableBitsCount - 1) / 32) + 1) * sizeof(ULONG));
}
}
Context->RegistrationHandle = 0;
return Error;
}
#pragma warning(pop)
#endif // McGenEventTracingUnregister2_df
// This function is for use by MC-generated code and should not be used directly.
FORCEINLINE
ULONG __stdcall
McGenEventTracingUnregister(_In_ PREGHANDLE RegHandle)
/*++
Routine Description:
Unregister from ETW.
Arguments:
RegHandle is the pointer to the provider context down-level
Remarks:
Unregister provider and disables provider context
--*/
{
ULONG Error = ERROR_SUCCESS;
if(!RegHandle) {
return ERROR_INVALID_PARAMETER;
}
if (!McGenTracingSupportInit){
//
// EventRegister<ProviderName> macro has not been called
//
return ERROR_SUCCESS;
}
if(!(*RegHandle)) {
//
// Provider has not registerd
//
return ERROR_SUCCESS;
}
//
// Vista
//
if(!McGenPreVista ){
Error = PfnEventUnregister(*RegHandle);
} else {
//
// down-level : XP/W2K3
//
PMCGEN_TRACE_CONTEXT Context = (PMCGEN_TRACE_CONTEXT)(ULONG_PTR)(*RegHandle);
#pragma prefast(suppress:__WARNING_BANNED_LEGACY_INSTRUMENTATION_API_USAGE, "Generated Code Down-Level Support");
Error = UnregisterTraceGuids(Context->RegistrationHandle);
Context->Flags = 0;
Context->Level = 0;
Context->Logger = 0;
if (Context->EnableBitsCount > 0) {
RtlZeroMemory(Context->EnableBitMask, (((Context->EnableBitsCount - 1) / 32) + 1) * sizeof(ULONG));
}
Context->RegistrationHandle = 0;
}
*RegHandle = (REGHANDLE)0;
return Error;
}
#if !defined(MCGEN_TRACING_DLL)
#define MCGEN_TRACING_DLL L"advapi32.dll"
#endif
#if !defined(MCGEN_TRACING_DLL_V2)
#define MCGEN_TRACING_DLL_V2 L"api-ms-win-eventing-provider-l1-1-0.dll"
#endif
#if !defined(MCGEN_EVENTWRITE_API)
#define MCGEN_EVENTWRITE_API "EventWrite"
#endif
#if !defined(MCGEN_EVENTREGISTER_API)
#define MCGEN_EVENTREGISTER_API "EventRegister"
#endif
#if !defined(MCGEN_EVENTUNREGISTER_API)
#define MCGEN_EVENTUNREGISTER_API "EventUnregister"
#endif
#if !defined(McGenInitTracingSupportFunc)
#define McGenInitTracingSupportFunc
// This function is for use by MC-generated code and should not be used directly.
FORCEINLINE
VOID McGenInitTracingSupport(
VOID
)
/*++
Routine Description:
This function assigns at runtime the ETW API set to be use for tracing.
Arguments:
Remarks:
At runtime assign the function pointers for the trace APIs to be used.
Vista and later uses WriteEvent, otherwise use TraceEvent.
--*/
{
OSVERSIONINFO OSVersion;
HINSTANCE TraceApiDll = NULL;
BOOL OkVersion;
BOOL IsWin8OrLater = FALSE;
if (McGenTracingSupportInit){
return;
}
OSVersion.dwOSVersionInfoSize = sizeof(OSVERSIONINFO);
OkVersion = GetVersionEx(&OSVersion);
if (OkVersion) {
McGenPreVista = (OSVersion.dwMajorVersion < 6);
IsWin8OrLater = (OSVersion.dwMajorVersion > 6) || ((OSVersion.dwMajorVersion == 6) && (OSVersion.dwMinorVersion > 1));
if (McGenPreVista) {
goto done;
}
}
TraceApiDll = GetModuleHandleW(MCGEN_TRACING_DLL);
if ((TraceApiDll == NULL) && (IsWin8OrLater != FALSE)) {
TraceApiDll = GetModuleHandleW(MCGEN_TRACING_DLL_V2);
}
if (TraceApiDll != NULL)
{
PfnEventWrite = (PFN_EVENT_WRITE)GetProcAddress(TraceApiDll, MCGEN_EVENTWRITE_API);
if (NULL == PfnEventWrite) {
if (OkVersion) {
McGenDebug(1, ("[McGenInitTracing] Failed to load EventWrite, using PreVista ETW \n"));
}
McGenPreVista = TRUE;
goto done;
}
PfnEventRegister = (PFN_EVENT_REGISTER) GetProcAddress(TraceApiDll, MCGEN_EVENTREGISTER_API);
if (NULL == PfnEventRegister) {
McGenDebug(1, ("[McGenInitTracing] Failed to load EventRegister, using PreVista ETW \n"));
PfnEventRegister = McGenEventTracingRegister;
McGenPreVista = TRUE;
goto done;
}
PfnEventUnregister = (PFN_EVENT_UNREGISTER) GetProcAddress(TraceApiDll, MCGEN_EVENTUNREGISTER_API);
if (NULL == PfnEventUnregister) {
McGenDebug(1, ("[McGenInitTracing] Failed to load EventUnregister, using PreVista ETW \n"));
PfnEventRegister = McGenEventTracingRegister;
McGenPreVista = TRUE;
goto done;
}
} else {
McGenDebug(1, ("[McGenInitTracing] Failed to load %ls, using PreVista ETW \n", MCGEN_TRACING_DLL));
McGenPreVista = TRUE;
}
done:
McGenDebug(1, ("[McGenInitTracing] Prevista %s \n", McGenPreVista ? "TRUE" : "FALSE" ));
McGenTracingSupportInit = TRUE;
}
#endif
//---------------------------------------------------------------------
// <autogenerated>
//
// Generated by Message Compiler (mc.exe)
//
// Copyright (c) Microsoft Corporation. All Rights Reserved.
//
// Changes to this file may cause incorrect behavior and will be lost if
// the code is regenerated.
// </autogenerated>
//---------------------------------------------------------------------
{
using System;
using System.Collections.Generic;
using System.Text;
using System.Diagnostics;
using System.Diagnostics.Eventing;
using Microsoft.Win32;
using System.Runtime.InteropServices;
using System.Security.Principal;
using System.Threading;
using System.Security;
internal class EventProviderVersionTwo : EventProvider
{
internal EventProviderVersionTwo(Guid id)
: base(id)
{}
[StructLayout(LayoutKind.Explicit, Size = 16)]
private struct EventData
{
[FieldOffset(0)]
internal UInt64 DataPointer;
[FieldOffset(8)]
internal uint Size;
[FieldOffset(12)]
internal int Reserved;
}
//
// ETW Pre Vista support class
//
internal class EventProviderVersionOne : IDisposable {
EtwNativeMethods.EtwEnableCallback m_etwCallback; // Trace Callback function
private ulong m_regHandle; // Trace Registration Handle
private byte m_level; // Tracing Level
private long m_flags; // Trace Enable Flags
private int m_enabled; // Enabled flag from Trace callback
private Guid m_providerId; // Control Guid
private ulong m_logger; // logger
private int m_disposed; // when 1, provider has unregister
internal const uint s_eventFlags = 0x00140000; // WNODE_FLAG_TRACED_GUID |WNODE_FLAG_USE_MOF_PTR
//
// Mof Structure is the same as EventData
//
[StructLayout(LayoutKind.Explicit, Size = 16)]
private struct EventData
{
[FieldOffset(0)]
internal UInt64 DataPointer;
[FieldOffset(8)]
internal uint Size;
[FieldOffset(12)]
internal int Reserved;
}
internal EventProviderVersionOne(Guid providerId)
{
m_providerId = providerId;
//
// Register the ProviderId with ETW
//
Register();
}
//
// Registration Vista Down-Level
//
private unsafe uint Register () {
m_etwCallback = new EtwNativeMethods.EtwEnableCallback(EtwEnableCallBack);
EtwNativeMethods.TRACE_GUID_REGISTRATION guidReg;
//
// This dummyGuid is there for ETW backward compatibility issues
//
Guid dummyGuid = new Guid ("{b4955bf0-3af1-4740-b475-99055d3fe9aa}");
guidReg.Id = (IntPtr)(&dummyGuid);
guidReg.RegHandle = IntPtr.Zero;
return EtwNativeMethods.RegisterTraceGuids(m_etwCallback, null, ref m_providerId, 1, ref guidReg, null, null, out m_regHandle);
}
//
// called by ETW to enable or disable tracing
//
internal unsafe uint EtwEnableCallBack (EtwNativeMethods.WMIDPREQUESTCODE requestCode, IntPtr context, uint* bufferSize, byte* byteBuffer) {
switch (requestCode) {
case EtwNativeMethods.WMIDPREQUESTCODE.WMI_ENABLE_EVENTS:
m_logger = EtwNativeMethods.GetTraceLoggerHandle(byteBuffer);
m_flags = EtwNativeMethods.GetTraceEnableFlags (m_logger);
m_level = EtwNativeMethods.GetTraceEnableLevel (m_logger);
m_enabled = 1;
break;
case EtwNativeMethods.WMIDPREQUESTCODE.WMI_DISABLE_EVENTS:
m_enabled = 0;
m_logger = 0L;
m_level = 0;
m_flags = 0;
break;
default:
m_enabled = 0;
m_logger = 0L;
break;
}
return 0;
}
//
// implement Dispose Pattern to early deregister from ETW insted of waiting for
// the finalizer to call deregistration.
// Once the user is done with the provider it needs to call Close() or Dispose()
// If neither are called the finalizer will unregister the provider anyway.
//
public void Dispose()
{
Dispose(true);
GC.SuppressFinalize(this);
}
protected virtual void Dispose(bool disposing)
{
//
// explicit cleanup is done by calling Dispose with true from
// Dispose() or Close(). The disposing arguement is ignored because there
// are no unmanaged resources.
// The finalizer calls Dispose with false.
//
//
// check if the object has been already been disposed
//
if (m_disposed == 1) return;
if (Interlocked.Exchange(ref m_disposed, 1) != 0)
{
// somebody is already disposing the provider
return;
}
//
// Disables Tracing in the provider, then unregisters
//
m_enabled = 0;
Deregister();
}
//
// This method deregisters the controlGuid of this class with ETW.
//
public virtual void Close()
{
Dispose();
}
~EventProviderVersionOne()
{
Dispose(false);
}
//
// This method unregisters from ETW.
//
private unsafe void Deregister()
{
//
// Unregister from ETW using the RegHandle saved from
// the register call.
//
if (m_regHandle != 0)
{
EtwNativeMethods.UnregisterTraceGuids(m_regHandle);
m_regHandle = 0;
}
}
public bool IsEnabled(byte level, uint flags)
{
//
// If not enabled, return false.
//
if (m_enabled == 0)
{
return false;
}
// This also covers the case of Level == 0.
if ((level <= m_level) ||
(m_level == 0))
{
//
// Check if flags is enabled
//
if ((flags == 0) ||
(((flags & m_flags) != 0)))
{
return true;
}
}
return false;
}
public bool IsEnabled()
{
if (m_enabled == 0)
{
return false;
}
return true;
}
internal unsafe bool WriteEvent(ref EventDescriptor eventDescriptor, ref Guid eventGuid, string data) {
if (IsEnabled(eventDescriptor.Level, (uint)eventDescriptor.Keywords))
{
int eventSize = sizeof(EtwNativeMethods.EVENT_TRACE_HEADER)+ sizeof(EventData);
byte* userData = stackalloc byte[eventSize];
EventData* userDataPtr = (EventData*)(userData+ sizeof(EtwNativeMethods.EVENT_TRACE_HEADER));
EtwNativeMethods.EVENT_TRACE_HEADER* header = (EtwNativeMethods.EVENT_TRACE_HEADER*)userData;
//
// header here
//
header->Guid = eventGuid;
header->Flags = s_eventFlags; // WNODE_FLAG_TRACED_GUID |WNODE_FLAG_USE_MOF_PTR;
header->Version = (short)eventDescriptor.Version;
header->Level = eventDescriptor.Level;
header->Type = eventDescriptor.Opcode;
header->Size = (short)eventSize;
//
// Event data here
userDataPtr->Size = (uint)(data.Length + 1)*sizeof(char);
fixed (char* a0 = data)
{
userDataPtr->DataPointer = (ulong)a0;
EtwNativeMethods.TraceEvent(m_logger, userData);
}
}
return true;
}
[SuppressUnmanagedCodeSecurityAttribute()]
internal static class EtwNativeMethods {
[StructLayout (LayoutKind.Explicit, Size=48)]
internal struct EVENT_TRACE_HEADER {
[FieldOffset (0)] internal short Size;
[FieldOffset (2)] internal ushort FieldTypeFlags;
[FieldOffset (4)] internal byte Type;
[FieldOffset (5)] internal byte Level;
[FieldOffset (6)] internal short Version;
[FieldOffset (8)] internal uint ThreadId;
[FieldOffset (12)] internal uint ProcessId;
[FieldOffset (16)] internal Int64 TimeStamp;
[FieldOffset (24)] internal Guid GuidPtr;
[FieldOffset (24)] internal Guid Guid;
[FieldOffset (40)] internal uint ClientContext;
[FieldOffset (44)] internal uint Flags;
}
[StructLayout (LayoutKind.Sequential, CharSet = CharSet.Unicode, Pack = 1)]
internal struct TRACE_GUID_REGISTRATION {
internal IntPtr Id;
internal IntPtr RegHandle;
}
internal enum WMIDPREQUESTCODE : uint {
WMI_ENABLE_EVENTS = 4,
WMI_DISABLE_EVENTS = 5
}
internal const String ADVAPI32 = "advapi32.dll";
//
// Callback WMIDPREQUEST
//
internal unsafe delegate uint EtwEnableCallback (
WMIDPREQUESTCODE requestCode,
IntPtr requestContext,
uint* bufferSize,
byte* buffer
);
//
// Registration APIs
//
[DllImport (ADVAPI32, ExactSpelling = true, EntryPoint="RegisterTraceGuidsW", CharSet=System.Runtime.InteropServices.CharSet.Unicode)]
internal static extern unsafe uint RegisterTraceGuids(
EtwEnableCallback requestAddress,
void* requestContext,
ref Guid controlGuid,
uint guidCount,
ref TRACE_GUID_REGISTRATION traceGuidReg,
string mofImagePath,
string mofResourceName,
out ulong registrationHandle
);
[DllImport (ADVAPI32, ExactSpelling = true, EntryPoint="UnregisterTraceGuids", CharSet=System.Runtime.InteropServices.CharSet.Unicode)]
internal static extern int UnregisterTraceGuids (ulong registrationHandle);
//
// Enable
//
[DllImport (ADVAPI32, ExactSpelling = true, EntryPoint="GetTraceLoggerHandle", CharSet=System.Runtime.InteropServices.CharSet.Unicode)]
internal static extern unsafe ulong GetTraceLoggerHandle (byte* Buffer);
[DllImport (ADVAPI32, ExactSpelling = true, EntryPoint="GetTraceEnableFlags", CharSet=System.Runtime.InteropServices.CharSet.Unicode)]
internal static extern uint GetTraceEnableFlags (ulong TraceHandle);
[DllImport(ADVAPI32, ExactSpelling = true, EntryPoint="GetTraceEnableLevel", CharSet=System.Runtime.InteropServices.CharSet.Unicode)]
internal static extern byte GetTraceEnableLevel (ulong TraceHandle);
//
// Writing (Publishing/Logging) APIs
//
[DllImport (ADVAPI32, ExactSpelling = true, EntryPoint="TraceEvent", CharSet=System.Runtime.InteropServices.CharSet.Unicode)]
internal static extern unsafe uint TraceEvent (
ulong traceHandle,
byte* eventTrace
);
}
( d e f a u l t ) E v e n t W r i t e w i n _ N o n e ! ! ! N O T S U P P O R T E D ! ! ! c o n s t s i g n e d c h a r c o n s t u n s i g n e d c h a r c o n s t s i g n e d s h o r t c o n s t u n s i g n e d s h o r t c o n s t s i g n e d i n t c o n s t u n s i g n e d i n t c o n s t s i g n e d _ _ i n t 6 4 c o n s t u n s i g n e d _ _ i n t 6 4 c o n s t f l o a t c o n s t d o u b l e W i n R t P r o v i d e r % l s : e r r o r : F a i l e d t r y i n g t o o p e n a h e a d e r f i l e ( "