Irp

final class ntoseye.Irp

Subclass of BaseRecord.

An _IRP and its current I/O stack location (!irp).

property address: int
property current_location: int

CurrentLocation, which is more than stack_count after the IRP completes.

property current_stack: IoStackLocation | None

None if the current location is out of range or ntoseye cannot read it.

property io_status: int | None

IoStatus.Status as an NTSTATUS. None if ntoseye cannot read it.

property mdl_address: int
property pending_returned: bool
property requestor_mode: int

0 for KernelMode, 1 for UserMode.

property size: int

Size in bytes, including the stack locations.

property stack_count: int
property thread: int

Tail.Overlay.Thread, the thread that issued the IRP.

property type: int

Type, which is IO_TYPE_IRP (6) for a valid IRP.

property user_buffer: int
property user_event: int