PoolIrp

final class ntoseye.PoolIrp

Subclass of BaseRecord.

An IRP that !irpfind found in pool.

property completed: bool

Whether all stack locations are used, which means that completion of the IRP is in progress or done.

property driver: str | None

The driver that owns the device of the current stack location. None if ntoseye cannot resolve it.

property irp: Irp
property mdl_process: int | None

MdlAddress->Process. None if the IRP has no MDL.

property original_file_object: int

Tail.Overlay.OriginalFileObject.

property pool_header: int | None

The _POOL_HEADER before the IRP. None for a big-pool allocation.

property tag: str

The pool tag of the allocation.