HypercallField

final class ntoseye.HypercallField

Subclass of BaseRecord.

One field of a hypercall’s input, as the Hyper-V TLFS lays it out.

property meaning: str | None

What the value means, where it has a name or stands for a set (HV_PARTITION_ID_SELF, VPs 0-3, a register’s TLFS name).

property name: str

The TLFS parameter name, with its member for a structure (ProcessorSet.ValidBanksMask) and its index for an array (Message[2]); Input[n] for the raw qwords of a call whose layout ntoseye does not know.

property offset: int

The offset in the input, from its first byte.

property size: int

The size in bytes, at most 8.

property value: int