syscall_dispatcher class routes Windows NT system calls to their handler implementations and manages asynchronous completion callbacks.
Overview
This class provides:- System call routing based on syscall number
- Handler registration from ntdll.dll and win32u.dll exports
- Asynchronous callback completion handling
- Serialization support for syscall state
- Completion state management for multi-step operations
Enums
dispatch_result
Result of a syscall or callback dispatch operation.Types
syscall_handler
Function pointer type for syscall handlers.syscall_handler_entry
Entry in the syscall handler table.syscall_handler
Function pointer to the syscall implementation
std::string
Name of the syscall (e.g., “NtCreateFile”)
Completion State Classes
Completion states track multi-step asynchronous operations.completion_state
Base class for all completion states.window_create_state
Tracks window creation callbacks.hwnd
Window handle being created
emulator_stack_allocation
Stack allocation for MINMAXINFO structure
emulator_stack_allocation
Stack allocation for window rectangle
emulator_stack_allocation
Stack allocation for CREATESTRUCT
emulator_stack_allocation
Stack allocation for WINDOWPOS structure
std::vector<qmsg>
Pending window messages
window_destroy_state
Tracks window destruction callbacks.window_show_state
Tracks window show/hide callbacks.bool
Whether the window was visible before the operation
Constructor
const exported_symbols&
Exported symbols from ntdll.dll
std::span<const std::byte>
Raw data from ntdll.dll (for extracting syscall numbers)
const exported_symbols&
Exported symbols from win32u.dll
std::span<const std::byte>
Raw data from win32u.dll
Methods
setup
Initializes or reinitializes the dispatcher with module exports.const exported_symbols&
ntdll.dll exports
std::span<const std::byte>
ntdll.dll binary data
const exported_symbols&
win32u.dll exports
std::span<const std::byte>
win32u.dll binary data
dispatch
Dispatches a system call from the emulated code.windows_emulator&
Windows emulator instance with CPU state
- Extracts the syscall number from the CPU registers
- Looks up the corresponding handler
- Invokes the handler with the syscall context
- Updates the CPU state with the return value
dispatch_callback
Dispatches a callback invocation (static method).windows_emulator&
Windows emulator instance
std::string&
Name of the syscall that triggered the callback
dispatch_completion
Dispatches completion of an asynchronous operation.windows_emulator&
Windows emulator instance
callback_id
ID identifying the type of callback
completion_state*
State object tracking the operation
uint64_t
Result value from the callback
dispatch_result indicating the outcome.
get_syscall_name
Retrieves the name of a syscall by its number.uint64_t
Syscall number
create_completion_state
Factory method for creating completion state objects.callback_id
Callback ID
nullptr if none is registered for this callback.
Serialization
Usage Example
Syscall Context
When a syscall handler is invoked, it receives asyscall_context structure containing:
- Read syscall arguments from registers or stack
- Access process resources via
proc - Modify thread state via
thread - Set return value via
emu->reg(x64_register::rax, value)
Callback Flow
- Syscall initiation: User code executes
syscallinstruction - Handler invocation: Dispatcher calls the registered handler
- Callback registration: Handler may register a callback (e.g., window procedure)
- Callback execution: Emulator calls into user code
- Completion dispatch: Handler processes callback result
- Return: Final result returned to user code
See Also
- process_context - Process state and resources
- module_manager - Module management for extracting syscall tables