DecodedHypercall

final class ntoseye.DecodedHypercall

Subclass of BaseRecord.

The hypercall of a VMCALL exit, with its input decoded as the Hyper-V TLFS lays it out (!hvcall).

property code: int
property decoded: bool

Whether ntoseye knows the layout of the call’s input. When it does not, fields holds the input as raw qwords: RDX and R8 for a fast call, else the first 8 qwords of the input.

property elements: list[HypercallElement]

A rep call’s input list, each element up to the rep count.

property fast: bool

Whether the input is in registers (RDX, R8, and XMM0 to XMM5) rather than in memory.

property fields: list[HypercallField]
property input_gpa: int | None

The guest physical address of the input (RDX), for a call whose input is in memory.

property input_value: int

The hypercall input value (RCX).

property name: str | None

The TLFS name, or None for a code that the TLFS does not list.

property nested: bool

Whether the call is for the L0 hypervisor of a nested environment.

property output_gpa: int | None

The guest physical address of the output (R8), for a call whose input is in memory.

property rep_count: int
property rep_start: int

The first rep element still to process; those before it are done.

property summary: str

The call on one line, as the stop header shows it.

property unavailable: str | None

Why some of the input is missing: an unreadable input page, input in XMM registers, or input past the end of its page.

property variable_header_size: int

The size of the variable input header, in qwords.