Added stub for the PLatform event file
Some checks are pending
vs2026-ci / win-amd64-build (debug, x64) (push) Waiting to run
vs2026-ci / win-amd64-build (release, x64) (push) Waiting to run
vs2026-ci / Deploy release (push) Blocked by required conditions

Added a  empty stub for the event functions on linux, since they don't
have a one to one mapping. also removed some redundant guards.
This commit is contained in:
Max Raulea 2026-08-11 11:17:35 +02:00
parent 6bb174b006
commit d64ce241f7
6 changed files with 80 additions and 16 deletions

View file

@ -76,9 +76,9 @@ HyperDbg-objs += include/platform/kernel/code/PlatformBroadcast.o
HyperDbg-objs += include/platform/kernel/code/PlatformCpu.o
HyperDbg-objs += include/platform/kernel/code/PlatformDbg.o
HyperDbg-objs += include/platform/kernel/code/PlatformDpc.o
# Still on the WDK (IRQL/event/io/process/spinlock/time). Commented out so
# the module links today; uncomment each as `make one FILE=...` on it goes green.
# HyperDbg-objs += include/platform/kernel/code/PlatformEvent.o
HyperDbg-objs += include/platform/kernel/code/PlatformEvent.o
# Still on the WDK (IRQL/io/process/spinlock/time). Commented out so the module
# links today; uncomment each as `make one FILE=...` on it goes green.
# HyperDbg-objs += include/platform/kernel/code/PlatformIo.o
# HyperDbg-objs += include/platform/kernel/code/PlatformIrql.o
# HyperDbg-objs += include/platform/kernel/code/PlatformProcess.o

View file

@ -125,6 +125,24 @@ typedef struct _PROCESS_INFORMATION
DWORD dwThreadId;
} PROCESS_INFORMATION, *PPROCESS_INFORMATION, *LPPROCESS_INFORMATION;
// NT status + kernel event/object types (the kernel notify path — see
// PlatformEvent). Scalar/opaque definitions so the shared Windows signatures
// compile on Linux; the event/object backing itself is stubbed for now (a real
// version would map KEVENT onto eventfd). NTSTATUS is fundamental and reused
// across many kernel TUs.
typedef LONG NTSTATUS;
typedef LONG KPRIORITY;
typedef ULONG ACCESS_MASK;
typedef CHAR KPROCESSOR_MODE;
typedef struct _KEVENT KEVENT, *PKEVENT; // opaque (eventfd-backed later)
typedef PVOID POBJECT_TYPE; // opaque NT object type
typedef PVOID POBJECT_HANDLE_INFORMATION; // opaque access-state out-param
# define STATUS_SUCCESS ((NTSTATUS)0x00000000L)
# define STATUS_NOT_IMPLEMENTED ((NTSTATUS)0xC0000002L)
# define NT_SUCCESS(Status) (((NTSTATUS)(Status)) >= 0)
#endif
#define NULL_ZERO 0

View file

@ -30,7 +30,11 @@ PlatformObjectDereference(PVOID Object)
#elif defined(__linux__)
# error "Not yet implemented"
//
// STUB: EVENT_BASED notify is unsupported on Linux until an eventfd backing
// lands. TODO(Linux): eventfd_ctx_put((struct eventfd_ctx *)Object).
//
UNREFERENCED_PARAMETER(Object);
#else
@ -56,7 +60,15 @@ PlatformEventSet(PKEVENT Event, KPRIORITY Increment, BOOLEAN Wait)
#elif defined(__linux__)
# error "Not yet implemented"
//
// STUB. TODO(Linux): eventfd_signal((struct eventfd_ctx *)Event). Returns the
// previous signal state; 0 is a safe default (no caller inspects it).
//
UNREFERENCED_PARAMETER(Event);
UNREFERENCED_PARAMETER(Increment);
UNREFERENCED_PARAMETER(Wait);
return 0;
#else
@ -95,7 +107,22 @@ PlatformObjectReferenceByHandle(HANDLE Handle,
#elif defined(__linux__)
# error "Not yet implemented"
//
// STUB. TODO(Linux): eventfd_ctx_fdget((int)(uintptr_t)Handle) into *Object.
// Fail closed so the EVENT_BASED registration path bails cleanly.
//
UNREFERENCED_PARAMETER(Handle);
UNREFERENCED_PARAMETER(DesiredAccess);
UNREFERENCED_PARAMETER(ObjectType);
UNREFERENCED_PARAMETER(AccessMode);
UNREFERENCED_PARAMETER(HandleInformation);
if (Object != NULL)
{
*Object = NULL;
}
return STATUS_NOT_IMPLEMENTED;
#else

View file

@ -19,12 +19,8 @@
// Functions //
//////////////////////////////////////////////////
#if defined(_WIN32) || defined(_WIN64) || defined(__linux__)
VOID
PlatformDpcInitialize(PRKDPC Dpc, PKDEFERRED_ROUTINE DeferredRoutine, PVOID DeferredContext);
BOOLEAN
PlatformDpcInsertQueueDpc(PRKDPC Dpc, PVOID SystemArgument1, PVOID SystemArgument2);
#endif // defined(_WIN32) || defined(_WIN64) || defined(__linux__)

View file

@ -22,8 +22,6 @@
VOID
PlatformObjectDereference(PVOID Object);
#if defined(_WIN32) || defined(_WIN64)
LONG
PlatformEventSet(PKEVENT Event, KPRIORITY Increment, BOOLEAN Wait);
@ -34,5 +32,3 @@ PlatformObjectReferenceByHandle(HANDLE Handle,
KPROCESSOR_MODE AccessMode,
PVOID * Object,
POBJECT_HANDLE_INFORMATION HandleInformation);
#endif // defined(_WIN32) || defined(_WIN64)

View file

@ -848,9 +848,9 @@ stops at the first `#error "Not yet implemented"`.
| `PlatformCpu.c` | ✅ ported 2026-08-01 — see below |
| `PlatformDbg.c` | ✅ ported 2026-08-01 — see below |
| `PlatformDpc.c` | ✅ ported 2026-08-11 — tasklet skeleton, see below |
| `PlatformEvent.c` | ✅ ported 2026-08-11 — stub skeleton, see below |
| `PlatformIrql.c` | ❌ 2 stubs |
| `PlatformEvent.c` | ❌ 3 stubs — **next to fail** |
| `PlatformIo.c` | ❌ 3 stubs |
| `PlatformIo.c` | ❌ 3 stubs — **next to fail** |
| `PlatformSpinlock.c` | ❌ 3 stubs |
| `PlatformTime.c` | ❌ 3 stubs |
| `PlatformProcess.c` | ❌ 5 stubs |
@ -916,6 +916,33 @@ which matches `KeInsertQueueDpc`'s "FALSE if already queued" — returned direct
in a freed `NOTIFY_RECORD` = UAF; needs `cancel_work_sync` before free once
hyperlog is ported). No live caller yet (hyperlog not compiled).
### `PlatformEvent.c` — DONE (2026-08-11) — stub skeleton
The EVENT_BASED half of the same hyperlog notify path: user-mode passes an event
*handle*, the kernel references it to a `KEVENT` and later signals it. No direct
Linux analog (no NT handles/object-manager); the real backing would be **eventfd**
(deferred — it also needs a coordinated user-mode-side change). Stubbed for now.
Type plumbing added to `BasicTypes.h` Linux block (shared, reused by later kernel
TUs): `NTSTATUS`/`KPRIORITY`/`ACCESS_MASK`/`KPROCESSOR_MODE` scalars, opaque
`KEVENT`/`POBJECT_TYPE`/`POBJECT_HANDLE_INFORMATION`, and
`STATUS_SUCCESS`/`STATUS_NOT_IMPLEMENTED`/`NT_SUCCESS`. Sole definitions (no
collision — the two other `NTSTATUS` hits are *uses* in kernel headers).
| Windows | Linux stub | eventfd TODO |
|---------|-----------|--------------|
| `ObDereferenceObject` | no-op | `eventfd_ctx_put` |
| `KeSetEvent` | return 0 | `eventfd_signal` |
| `ObReferenceObjectByHandle` | `*Object=NULL`, return `STATUS_NOT_IMPLEMENTED` | `eventfd_ctx_fdget` |
Consequence: EVENT_BASED notify is a no-op/fail-closed on Linux until eventfd
lands. No live caller yet (hyperlog not compiled).
**Header cleanup (both Dpc + Event):** the `#if _WIN32 || _WIN64 || __linux__`
wrappers around the prototypes were removed — that condition is every supported
platform (the `.c` files `#error` on anything else), so the prototypes are now
declared unconditionally.
---
## Building