HypercallCaller

final class ntoseye.HypercallCaller

The virtual processor whose hypercall a processor halted in the Windows hypervisor handles (cpu.hypercall_caller()), found as !hvcall and a hypercall breakpoint’s filter find it: the call as the caller made it, and the caller’s memory, which a hypercall breakpoint’s condition reads.

property hypercall: DecodedHypercall | None

The call with its input decoded, as !hvcall shows it, or None when the caller’s registers are not known.

property partition_id: int

The caller’s partition ID (the root partition’s is 1).

read(address: int, size: int, physical: bool = False) → bytes

Read size bytes of the caller’s memory, as a hypercall breakpoint’s condition reads it: guest virtual memory through the calling VTL’s page tables (its CR3), or with physical=True guest physical memory (a slow call’s input, at the GPA in rdx), both through its EPT. The memory is read now, so read it while the target is halted at the call. Raises NtoseyeError when the caller’s state at the call is not known, when a page is not mapped, and for a virtual address unless the caller is in 4-level long-mode paging. The memory is read-only.

property registers: dict[str, int]

The caller’s registers at its VMCALL by name (rcx, rdx, r8, rip, cr3, …), as a hypercall breakpoint’s condition sees them: RIP, RSP, flags, control and segment registers from the calling VTL’s eVMCS, and the general-purpose registers when ntoseye recovered them. Empty when the state ntoseye found is an older exit’s.

property root: bool

Whether the caller is a VP of the root partition (Windows itself) rather than of a guest partition.

to_dict() → dict[str, Any]

Return the caller as a plain dict (partition_id, root, vp_index, vtl, registers, and hypercall, the call’s dict or None).

property vp_index: int

The caller’s VP index in its partition.

property vtl: int

The VTL that made the call.