Skip to main content
The syscall_dispatcher class routes Windows NT system calls to their handler implementations and manages asynchronous completion callbacks.

Overview

This class provides:
  • System call routing based on syscall number
  • Handler registration from ntdll.dll and win32u.dll exports
  • Asynchronous callback completion handling
  • Serialization support for syscall state
  • Completion state management for multi-step operations

Enums

dispatch_result

Result of a syscall or callback dispatch operation.

Types

syscall_handler

Function pointer type for syscall handlers.

syscall_handler_entry

Entry in the syscall handler table.
syscall_handler
Function pointer to the syscall implementation
std::string
Name of the syscall (e.g., “NtCreateFile”)

Completion State Classes

Completion states track multi-step asynchronous operations.

completion_state

Base class for all completion states.

window_create_state

Tracks window creation callbacks.
hwnd
Window handle being created
emulator_stack_allocation
Stack allocation for MINMAXINFO structure
emulator_stack_allocation
Stack allocation for window rectangle
emulator_stack_allocation
Stack allocation for CREATESTRUCT
emulator_stack_allocation
Stack allocation for WINDOWPOS structure
std::vector<qmsg>
Pending window messages

window_destroy_state

Tracks window destruction callbacks.

window_show_state

Tracks window show/hide callbacks.
bool
Whether the window was visible before the operation

Constructor

const exported_symbols&
Exported symbols from ntdll.dll
std::span<const std::byte>
Raw data from ntdll.dll (for extracting syscall numbers)
const exported_symbols&
Exported symbols from win32u.dll
std::span<const std::byte>
Raw data from win32u.dll
The constructor extracts syscall numbers from the native DLL code and builds the handler table.

Methods

setup

Initializes or reinitializes the dispatcher with module exports.
const exported_symbols&
ntdll.dll exports
std::span<const std::byte>
ntdll.dll binary data
const exported_symbols&
win32u.dll exports
std::span<const std::byte>
win32u.dll binary data

dispatch

Dispatches a system call from the emulated code.
windows_emulator&
Windows emulator instance with CPU state
This method:
  1. Extracts the syscall number from the CPU registers
  2. Looks up the corresponding handler
  3. Invokes the handler with the syscall context
  4. Updates the CPU state with the return value

dispatch_callback

Dispatches a callback invocation (static method).
windows_emulator&
Windows emulator instance
std::string&
Name of the syscall that triggered the callback
Used when the emulated code calls back into the emulator (e.g., window procedures).

dispatch_completion

Dispatches completion of an asynchronous operation.
windows_emulator&
Windows emulator instance
callback_id
ID identifying the type of callback
completion_state*
State object tracking the operation
uint64_t
Result value from the callback
Returns: dispatch_result indicating the outcome.

get_syscall_name

Retrieves the name of a syscall by its number.
uint64_t
Syscall number
Returns: Name of the syscall (e.g., “NtCreateFile”).

create_completion_state

Factory method for creating completion state objects.
callback_id
Callback ID
Returns: New completion state object, or nullptr if none is registered for this callback.

Serialization

Serialization support for saving/loading dispatcher state.

Usage Example

Syscall Context

When a syscall handler is invoked, it receives a syscall_context structure containing:
Handlers can:
  • Read syscall arguments from registers or stack
  • Access process resources via proc
  • Modify thread state via thread
  • Set return value via emu->reg(x64_register::rax, value)

Callback Flow

  1. Syscall initiation: User code executes syscall instruction
  2. Handler invocation: Dispatcher calls the registered handler
  3. Callback registration: Handler may register a callback (e.g., window procedure)
  4. Callback execution: Emulator calls into user code
  5. Completion dispatch: Handler processes callback result
  6. Return: Final result returned to user code

See Also