commit 772c784d9f9a1c047cb8f2d17cc02e45eb113254 Author: g3rzi Date: Sun Jul 31 14:15:49 2022 +0300 Init diff --git a/CODE_OF_CONDUCT.md b/CODE_OF_CONDUCT.md new file mode 100644 index 0000000..087b3eb --- /dev/null +++ b/CODE_OF_CONDUCT.md @@ -0,0 +1,66 @@ +# CyberArk Community Code of Conduct + +CyberArk is a leader in Privileged Access Management, thanks to its customers and community. We listen to our community and wish to provide additional relevant tools. We believe that our mission is best served in an environment that is friendly, safe, and accepting; free from intimidation or harassment. +Towards this end, CyberArk’s developers have created this Community Code of Conduct for the CyberArk open source community. Our Code of Conduct sets the standard for how developers, and community members can work together in a respectful and collaborative manner. Those who do not abide by this Code of Conduct will not be permitted to remain part of our community. + + +## Summary of Key Principles + +- Be respectful to others in the community at all times. +- Report harassing or abusive behavior that you experience or witness at ReportAbuse@cyberark.com +- The CyberArk community will not tolerate abusive or disrespectful behavior towards its members; anyone engaging in such behavior will be suspended from the CyberArk community. + + +## Scope + +This Code of Conduct applies to all members of the CyberArk community, including paid and unpaid agents, administrators, users, and customers of CyberArk. It applies in all CyberArk community venues, online and in person, including CyberArk Open Source project communities (such as public GitHub repositories, chat channels, social media, mailing lists, and public events) and in one-on-one communications pertaining to CyberArk affairs. +This policy covers the usage of CyberArk hosted services, as well as the CyberArk website, CyberArk related events, and any other services offered by or on behalf of CyberArk (collectively, the "Service"). +This Code of Conduct is in addition to, and does not in any way nullify or invalidate, any other terms or conditions related to use of the Service. + + +## Maintaining a Friendly, Harassment-Free Space + +We are committed to providing a friendly, safe and welcoming environment for all, regardless of gender identity, sexual orientation, ability, ethnicity, religion, age, physical appearance, body size, race, or similar personal characteristics. +We ask that you please respect that people have differences of opinion regarding technical choices, and that every design or implementation choice carries a trade-off and numerous costs. There is seldom a single right answer. A difference of technology preferences is not a license to be rude. +Harassing other users of the Service for any reason is never tolerated, whether via public or private media. Any spamming, trolling, flaming, baiting, or other attention-stealing behavior is not welcome, and will not be tolerated. +Even if your intent is not to harass or offend others, be mindful of how your comments might be perceived by others in the community. + + +## Unacceptable Behavior + +The following behaviors are considered harassment under this Code of Conduct and are unacceptable within our community: +- Violence, threats of violence, or violent language directed against another person or group of people. +- Sexist, racist, homophobic, transphobic, ableist, or otherwise discriminatory jokes and language. +- Posting or displaying sexually explicit or violent material. +- Posting or threatening to post other people’s personally identifying information ("doxing"). +- Personal insults, particularly those related to related to gender identity, sexual orientation, ability, ethnicity, religion, age, physical appearance, body size, race, or similar personal characteristics. +- Using offensive or harassing nicknames or other identifiers. +- Inappropriate photography or recording. +- Inappropriate physical contact. You should have someone’s consent before touching them. +- Unwelcome sexual attention. This includes: sexualized comments or jokes; inappropriate touching, groping, and unwelcome sexual advances. +- Deliberate intimidation, stalking, or following (online or in person). +- Sustained disruption of community events, including talks and presentations. +- Advocating for, or encouraging, any of the above behavior. + +## Reporting Violations + +If you witness or experience unacceptable behavior in the CyberArk community, please promptly report it to our team at ReportAbuse@cyberark.com. If this is the initial report of a problem, please include as much detail as possible. It is easiest for us to address issues when we have more context. +The CyberArk Community Team will look into any reported issues in a confidential manner and take any necessary actions to address and resolve the problem. +We will not tolerate any form of retaliation towards users who report these issues to us. +If you feel that you have been falsely or unfairly accused of violating this Code of Conduct by others in the community, you should notify the ReportAbuse@cyberark.com team so that we can address and resolve the accusation. +As always, if you have an urgent security issue, contact product_security@cyberark.com and if you have concerns about a potential copyright violation, contact legal@cyberark.com. + +## Consequences + +All content published to the Service, including user account credentials, is hosted at the sole discretion of the CyberArk administrators. If a community member engages in unacceptable behavior, the CyberArk administrators may take any action they deem appropriate, up to and including a temporary ban or permanent expulsion from the community without warning. In general, we will choose the course of action that we judge as being most in the interest of fostering a safe and friendly community. + +## Contact Info +Please contact ReportAbuse@cyberark.com if you need to report a problem or address a grievance related to an abuse report. +You are also encouraged to contact us if you have questions about what constitutes appropriate and inappropriate content. We are happy to provide guidance to help you be a successful part of our community. Our technical community is available [here](https://cyberark-customers.force.com/s/). + +## Credit and License + +This Code of Conduct borrows from the [npm Code of Conduct](https://www.npmjs.com/policies/conduct), Stumptown Syndicate [Citizen's Code of Conduct](http://citizencodeofconduct.org/), and the [Rust Project Code of Conduct](https://www.rust-lang.org/conduct.html). +This document may be reused under a [Creative Commons Attribution-ShareAlike License](https://creativecommons.org/licenses/by-sa/4.0/). + + diff --git a/DB/RPC_UUID_Map_Windows10_1909_18363.1977.rpcdb.json b/DB/RPC_UUID_Map_Windows10_1909_18363.1977.rpcdb.json new file mode 100644 index 0000000..1274cca --- /dev/null +++ b/DB/RPC_UUID_Map_Windows10_1909_18363.1977.rpcdb.json @@ -0,0 +1,12555 @@ +{ + "54f96d15-d9a7-4422-bd32-8b0cebd00400": { + "Module": "NcaSvc.dll", + "ModulePath": "C:\\Windows\\System32\\NcaSvc.dll", + "InterfaceId": "54f96d15-d9a7-4422-bd32-8b0cebd00400", + "InterfaceStructOffset": 125648, + "ProceduresCount": 11, + "Procedures": [ + "Rpc_NcaEngineOpen", + "Rpc_NcaEngineClose", + "Rpc_NcaNetworkOpen", + "Rpc_NcaNetworkClose", + "Rpc_NcaStatusEventSubscribe", + "Rpc_NcaStatusEventSubscriptionGetLastEvent", + "Rpc_NcaStatusEventUnsubscribe", + "Rpc_NcaGetConfig", + "Rpc_NcaToggleNamePreferenceState", + "Rpc_NcaExecuteAndCaptureLogs", + "Rpc_NcaGetEvidenceCollectorResult" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707581182256, + "Service": "NcaSvc", + "IsServiceRunning": false + }, + "cb407bbf-c14f-4cd9-8f55-cbb08146598c": { + "Module": "IMJPDCT.EXE", + "ModulePath": "C:\\Windows\\System32\\IME\\IMEJP\\IMJPDCT.EXE", + "InterfaceId": "cb407bbf-c14f-4cd9-8f55-cbb08146598c", + "InterfaceStructOffset": 269360, + "ProceduresCount": 2, + "Procedures": [ + "Rpc_Open", + "Rpc_GetServerProcessId" + ], + "ProcStackSize": 16, + "DispatchFunction": 140702047819808, + "Service": null, + "IsServiceRunning": false + }, + "847c6e33-7372-4a11-9b86-f5a4af446dd8": { + "Module": "VoipRT.dll", + "ModulePath": "C:\\Windows\\System32\\VoipRT.dll", + "InterfaceId": "847c6e33-7372-4a11-9b86-f5a4af446dd8", + "InterfaceStructOffset": 112720, + "ProceduresCount": 7, + "Procedures": [ + "EndCall", + "HoldCall", + "UnholdCall", + "MuteAllCalls", + "UnmuteAllCalls", + "AcceptIncomingCall", + "RejectIncomingCall" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707581089376, + "Service": null, + "IsServiceRunning": false + }, + "18f70770-8e64-11cf-9af1-0020af6e72f4": { + "Module": "combase.dll", + "ModulePath": "C:\\Windows\\System32\\combase.dll", + "InterfaceId": "18f70770-8e64-11cf-9af1-0020af6e72f4", + "InterfaceStructOffset": 2274736, + "ProceduresCount": 5, + "Procedures": [ + "_UseProtseq", + "_GetCustomProtseqInfo", + "_UpdateResolverBindings", + "_NotifyFDT", + "_ControlTracing" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708189286624, + "Service": null, + "IsServiceRunning": false + }, + "8c7fbdb0-8513-44f9-a8b1-1a3b49322bf4": { + "Module": "AppVEntSubsystemController.dll", + "ModulePath": "C:\\Windows\\System32\\AppVEntSubsystemController.dll", + "InterfaceId": "8c7fbdb0-8513-44f9-a8b1-1a3b49322bf4", + "InterfaceStructOffset": 864448, + "ProceduresCount": 1, + "Procedures": [ + "vfs_server_GetConfiguration" + ], + "ProcStackSize": 56, + "DispatchFunction": 140706797870656, + "Service": null, + "IsServiceRunning": false + }, + "00000131-0000-0000-c000-000000000046": { + "Module": "combase.dll", + "ModulePath": "C:\\Windows\\System32\\combase.dll", + "InterfaceId": "00000131-0000-0000-c000-000000000046", + "InterfaceStructOffset": 2274640, + "ProceduresCount": 0, + "Procedures": [], + "ProcStackSize": 56, + "DispatchFunction": 140707382121168, + "Service": null, + "IsServiceRunning": false + }, + "7c69ac10-fa12-4dbf-90d9-c7f1e40f5dc5": { + "Module": "audiosrv.dll", + "ModulePath": "C:\\Windows\\System32\\audiosrv.dll", + "InterfaceId": "7c69ac10-fa12-4dbf-90d9-c7f1e40f5dc5", + "InterfaceStructOffset": 1381312, + "ProceduresCount": 52, + "Procedures": [ + "s_winmmGetPnpInfo", + "s_mmeNotifyDeviceStateChanged", + "s_mmeNotifyDeviceAdded", + "s_mmeNotifyDeviceRemoved", + "s_mmeNotifyDefaultDeviceChanged", + "s_tsSessionGetAudioProtocol", + "s_tsRegisterAudioProtocolNotification", + "s_tsUnregisterAudioProtocolNotification", + "s_sndevtResolveSoundAlias", + "s_pbmRegisterPlaybackManagerNotifications", + "s_pbmUnregisterPlaybackManagerNotifications", + "s_pbmSetSmtcSubscriptionState", + "s_pbmGetSoundLevel", + "s_ccCreateHandsfreeHidFileFromAudioId", + "s_pbmRegisterAppClosureNotification", + "s_pbmUnregisterAppClosureNotification", + "s_pbmPlayToStreamStateChanged", + "s_pbmIsPlaying", + "s_pbmCastingAppStateChanged", + "s_pbmVoipCallStateChanged", + "s_pbmLaunchBackgroundTask", + "s_pbmRegisterAsBackgroundTask", + "s_afxOpenAudioEffectsWatcher", + "s_afxCloseAudioEffectsWatcher", + "s_midiOpenPort", + "s_rtgGetDefaultAudioEndpoint", + "s_apmRegisterProxyAudioProcess", + "s_apmSetDuckingGainForId", + "s_apmSetLayoutGainForId", + "s_apmSetVolumeGroupGainForId", + "s_apmSetVolumeGroupGainScalarForId", + "s_apmSetVolumeGroupMuteForId", + "s_setRingerVibrateState", + "s_getRingerVibrateState", + "s_getEmergencyCallbackMode", + "s_setEmergencyCallbackMode", + "s_apmSetPersistedDefaultAudioEndpoint", + "s_apmGetPersistedDefaultAudioEndpoint", + "s_apmClearAllPersistedApplicationDefaultEndpoints", + "s_apmRegisterAudioStateMonitor", + "s_apmUnregisterAudioStateMonitor", + "s_apmHandleEuVolumeNotificationResponse", + "AudioServerTelephonyControlGetCallStateSync", + "AudioServerTelephonyControlGetMuteSync", + "s_StartPersonalAssistantDialogSession", + "s_StopPersonalAssistantDialogSession", + "s_apmSetBalanceGroupBalanceForId", + "s_apmSetPreferredChatApplication", + "s_apmResetPreferredChatApplication", + "s_CreateHolographicDisplay", + "s_DestroyHolographicDisplay", + "s_GetHeadRotation" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708026792256, + "Service": "Audiosrv", + "IsServiceRunning": true + }, + "76f226c3-ec14-4325-8a99-6a46348418ae": { + "Module": "wininit.exe", + "ModulePath": "C:\\Windows\\System32\\wininit.exe", + "InterfaceId": "76f226c3-ec14-4325-8a99-6a46348418ae", + "InterfaceStructOffset": 296208, + "ProceduresCount": 2, + "Procedures": [ + "I_WMsgkSendMessage", + "I_WMsgkSendPSPMessage" + ], + "ProcStackSize": 40, + "DispatchFunction": 140699626518608, + "Service": null, + "IsServiceRunning": false + }, + "7f89f606-468e-4ee4-b1f3-73b68767b0e1": { + "Module": "AppVShNotify.exe", + "ModulePath": "C:\\Windows\\System32\\AppVShNotify.exe", + "InterfaceId": "7f89f606-468e-4ee4-b1f3-73b68767b0e1", + "InterfaceStructOffset": 103200, + "ProceduresCount": 1, + "Procedures": [ + "s_IShellExtensionNotify_ShellNotify" + ], + "ProcStackSize": 16, + "DispatchFunction": 140702910021472, + "Service": null, + "IsServiceRunning": false + }, + "ff00653f-064a-49ca-9783-0e33730d7d71": { + "Module": "ipxlatcfg.dll", + "ModulePath": "C:\\Windows\\System32\\ipxlatcfg.dll", + "InterfaceId": "ff00653f-064a-49ca-9783-0e33730d7d71", + "InterfaceStructOffset": 41456, + "ProceduresCount": 2, + "Procedures": [ + "Enable464xlat", + "Disable464xlat" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707880071568, + "Service": "IpxlatCfgSvc", + "IsServiceRunning": false + }, + "b50f395f-b08b-495a-b2d3-b8201e1f2388": { + "Module": "uireng.dll", + "ModulePath": "C:\\Windows\\System32\\uireng.dll", + "InterfaceId": "b50f395f-b08b-495a-b2d3-b8201e1f2388", + "InterfaceStructOffset": 156416, + "ProceduresCount": 1, + "Procedures": [ + "GetData" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707581061632, + "Service": null, + "IsServiceRunning": false + }, + "afa8bd80-7d8a-11c9-bef4-08002b102989": { + "Module": "rpcrt4.dll", + "ModulePath": "C:\\Windows\\System32\\rpcrt4.dll", + "InterfaceId": "afa8bd80-7d8a-11c9-bef4-08002b102989", + "InterfaceStructOffset": 916704, + "ProceduresCount": 5, + "Procedures": [ + "rpc_mgmt_inq_if_ids", + "rpc_mgmt_inq_stats", + "rpc_mgmt_is_server_listening", + "rpc_mgmt_stop_server_listening", + "rpc_mgmt_inq_princ_name" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708203084256, + "Service": null, + "IsServiceRunning": false + }, + "11899a43-2b68-4a76-92e3-a3d6ad8c26ce": { + "Module": "lsm.dll", + "ModulePath": "C:\\Windows\\System32\\lsm.dll", + "InterfaceId": "11899a43-2b68-4a76-92e3-a3d6ad8c26ce", + "InterfaceStructOffset": 479888, + "ProceduresCount": 4, + "Procedures": [ + "RpcWaitForSessionState", + "RpcRegisterAsyncNotification", + "RpcWaitAsyncNotification", + "RpcUnRegisterAsyncNotification" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708131490608, + "Service": "LSM", + "IsServiceRunning": true + }, + "3a7e8d55-62d7-4626-8af6-c19598881347": { + "Module": "CCG.exe", + "ModulePath": "C:\\Windows\\System32\\CCG.exe", + "InterfaceId": "3a7e8d55-62d7-4626-8af6-c19598881347", + "InterfaceStructOffset": 92896, + "ProceduresCount": 4, + "Procedures": [ + "CredFetchGetContext", + "CredFetchGetDomainJoinConfig", + "CredFetchAddAccount", + "CredFetchGetPasswordInfo" + ], + "ProcStackSize": 56, + "DispatchFunction": 140699048540048, + "Service": null, + "IsServiceRunning": false + }, + "c2d15ccf-a416-46dc-ba58-4624ac7a9123": { + "Module": "lsm.dll", + "ModulePath": "C:\\Windows\\System32\\lsm.dll", + "InterfaceId": "c2d15ccf-a416-46dc-ba58-4624ac7a9123", + "InterfaceStructOffset": 479792, + "ProceduresCount": 3, + "Procedures": [ + "RpcRegisterCurrentSessionAsyncNotification", + "RpcWaitAsyncNotificationEx", + "RpcUnRegisterAsyncNotificationEx" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708131561136, + "Service": "LSM", + "IsServiceRunning": true + }, + "f02facbc-a48b-4de1-98ec-70025bd9b48e": { + "Module": "BioIso.exe", + "ModulePath": "C:\\Windows\\System32\\BioIso.exe", + "InterfaceId": "f02facbc-a48b-4de1-98ec-70025bd9b48e", + "InterfaceStructOffset": 632624, + "ProceduresCount": 96, + "Procedures": [ + "BioIsoSrvCreateSecureBiometricUnit", + "BioIsoSrvSetBiometricUnitPolicy", + "BioIsoSrvCloseSecureBiometricUnit", + "BioIsoSrvSensorAttach", + "BioIsoSrvSensorDetach", + "BioIsoSrvSensorClearContext", + "BioIsoSrvSensorAsyncRawBufferClear", + "BioIsoSrvSensorAsyncRawBufferImportBegin", + "BioIsoSrvSensorAsyncRawBufferImportNext", + "BioIsoSrvSensorAsyncRawBufferImportEnd", + "BioIsoSrvSensorAsyncImportSecureBuffer", + "BioIsoSrvSensorPushDataToEngine", + "BioIsoSrvSensorNotifyPowerChange", + "BioIsoSrvSensorPipelineInit", + "BioIsoSrvSensorPipelineCleanup", + "BioIsoSrvSensorActivate", + "BioIsoSrvSensorDeactivate", + "BioIsoSrvEngineAttach", + "BioIsoSrvEngineDetach", + "BioIsoSrvEngineClearContext", + "BioIsoSrvEngineQueryPreferredFormat", + "BioIsoSrvEngineQueryIndexVectorSize", + "BioIsoSrvEngineQuerySampleHint", + "BioIsoSrvEngineSampleClear", + "BioIsoSrvEngineSampleImportBegin", + "BioIsoSrvEngineSampleImportNext", + "BioIsoSrvEngineSampleImportEnd", + "BioIsoSrvEngineAcceptSampleData", + "BioIsoSrvEngineCreateEnrollment", + "BioIsoSrvEngineUpdateEnrollment", + "BioIsoSrvEngineGetEnrollmentStatus", + "BioIsoSrvEngineGetEnrollmentHash", + "BioIsoSrvEngineCheckForDuplicate", + "BioIsoSrvEngineCommitEnrollment", + "BioIsoSrvEngineDiscardEnrollment", + "BioIsoSrvEngineNotifyPowerChange", + "BioIsoSrvEnginePipelineInit", + "BioIsoSrvEnginePipelineCleanup", + "BioIsoSrvEngineActivate", + "BioIsoSrvEngineDeactivate", + "BioIsoSrvEngineQueryExtendedInfo", + "BioIsoSrvEngineSetEnrollmentSelector", + "BioIsoSrvEngineSetEnrollmentParameters", + "BioIsoSrvEngineQueryExtendedEnrollmentStatus", + "BioIsoSrvEngineRefreshCache", + "BioIsoSrvEngineSelectCalibrationFormat", + "BioIsoSrvEngineQueryCalibrationData", + "BioIsoSrvEngineSetAccountPolicy", + "BioIsoSrvEngineIdentifyFeatureSetSecure", + "BioIsoSrvEngineAcceptPrivateSensorTypeInfo", + "BioIsoSrvStorageAttach", + "BioIsoSrvStorageDetach", + "BioIsoSrvStorageClearContext", + "BioIsoSrvStorageCreateDatabase", + "BioIsoSrvStorageOpenDatabase", + "BioIsoSrvStorageCloseDatabase", + "BioIsoSrvStorageDeleteRecord", + "BioIsoSrvStorageNotifyPowerChange", + "BioIsoSrvStoragePipelineInit", + "BioIsoSrvStoragePipelineCleanup", + "BioIsoSrvStorageActivate", + "BioIsoSrvStorageDeactivate", + "BioIsoSrvStorageQueryExtendedInfo", + "BioIsoSrvStorageCacheClear", + "BioIsoSrvStorageCacheImportBegin", + "BioIsoSrvStorageCacheImportNext", + "BioIsoSrvStorageCacheImportEnd", + "BioIsoSrvStorageCacheExportBegin", + "BioIsoSrvStorageCacheExportNext", + "BioIsoSrvStorageCacheExportEnd", + "BioIsoSrvStorageManagerImportBegin", + "BioIsoSrvStorageManagerImportNext", + "BioIsoSrvStorageManagerImportEnd", + "BioIsoSrvStorageManagerExportBegin", + "BioIsoSrvStorageManagerExportNext", + "BioIsoSrvStorageManagerExportEnd", + "BioIsoSrvPresenceMonitorUpdate", + "BioIsoSrvPresenceMonitorGetChanges", + "BioIsoSrvPresenceMonitorClearCache", + "BioIsoSrvPresenceMonitorEnumAll", + "BioIsoSrvPresenceMonitorSetLifetimeInSeconds", + "BioIsoSrvOpenEnrollAuthorizationSession", + "BioIsoSrvAuthorizeEnrollment", + "BioIsoSrvCloseEnrollAuthorizationSession", + "BioIsoSrvQueryAuthorizedEnrollments", + "BioIsoSrvDeleteAuthorizedEnrollments", + "BioIsoSrvAuthorizeKeyRelease", + "BioIsoSrvCloseKeyAuthorizationSession", + "BioIsoSrvGetSecureConnectionParams", + "BioIsoSrvConnectSecure", + "BioIsoSrvAuthenticateEnrollmentIdentity", + "BioIsoSrvGetIdentificationNonce", + "BioIsoSrvAuthenticateIdentification", + "BioIsoSrvIsIdle", + "BioIsoSrvPingTrustlet", + "BioIsoSrvStopServer" + ], + "ProcStackSize": 8, + "DispatchFunction": 140701342552624, + "Service": null, + "IsServiceRunning": false + }, + "cad784cb-4c1b-4d96-b8f7-4716b568b13c": { + "Module": "wininet.dll", + "ModulePath": "C:\\Windows\\System32\\wininet.dll", + "InterfaceId": "cad784cb-4c1b-4d96-b8f7-4716b568b13c", + "InterfaceStructOffset": 2033776, + "ProceduresCount": 83, + "Procedures": [ + "s_UrlCacheGetManagerInterface", + "CancelAll", + "s_UrlCacheOpenContainer", + "s_UrlCacheCloseContainer", + "s_UrlCacheSetContainerEntryMaximumAge", + "s_UrlCacheAddUrl", + "s_UrlCacheLookupUrl", + "s_UrlCacheCheckUrlsExist", + "s_UrlCacheGetUrlBinaryBlob", + "s_UrlCacheAddUrlBinaryBlob", + "s_UrlCacheDeleteUrl", + "s_UrlCacheUnlockUrl", + "s_UrlCacheUpdateUrl", + "s_UrlCacheEntryEnum", + "s_UrlCacheEntryEnumClose", + "s_UrlCacheEntryEnumNext", + "s_UrlCacheCleanupUrls", + "s_UrlCacheCleanupHttpsUrls", + "s_UrlCacheGetSize", + "s_UrlCacheGetLimit", + "s_UrlCacheSetLimit", + "s_UrlCacheGetCrossContainerContentTotalSizeAndLimit", + "s_UrlCacheCleanupCrossContainers", + "s_UrlCacheGetBloomFilter", + "s_UrlCacheReleaseBloomFilter", + "s_UrlCacheGetNextDirectory", + "s_UrlCacheAddLeakFile", + "s_UrlCacheCreateGroup", + "s_UrlCacheDeleteGroup", + "s_UrlCacheGetGroupIds", + "s_UrlCacheGetGroup", + "s_UrlCacheUpdateGroup", + "s_UrlCacheSetUrlGroup", + "s_UrlCacheGetContentContainerDirectories", + "s_UrlCacheCreateExtensibleContainer", + "s_UrlCacheDeleteExtensibleContainer", + "s_UrlCacheGetExtensibleContainersList", + "s_UrlCacheRpcSetGlobalLimit", + "s_UrlCacheRpcGetGlobalLimit", + "s_UrlCacheRpcReloadSettings", + "s_UrlCacheGetGlobalCounters", + "s_AppCacheOpenContainer", + "s_AppCacheCloseContainer", + "s_AppCacheRpcCheckManifest", + "s_AppCacheRpcLookup", + "s_AppCacheRpcDeleteGroup", + "s_AppCacheRpcDeleteIeGroup", + "s_AppCacheRpcGetFallbackUrl", + "s_AppCacheRpcGetDownloadList", + "s_AppCacheRpcCloseHandle", + "s_AppCacheRpcInvalidate", + "s_AppCacheRpcGetInfo", + "s_AppCacheRpcGetGroupsList", + "s_AppCacheRpcFreeSpace", + "s_AppCacheRpcGetIeGroupList", + "s_AppCacheRpcFreeIeSpace", + "s_AppCacheRpcRetrieveUrl", + "s_AppCacheRpcCommitUrl", + "s_AppCacheRpcUpdateExtraData", + "s_AppCacheRpcFinalize", + "s_DependencyStoreOpenContainer", + "s_DependencyStoreCloseContainer", + "s_DependencyStoreUpdateUrl", + "s_DependencyStoreRetrieveUrl", + "s_DependencyStoreDeleteContainer", + "s_HstsOpenContainer", + "s_HstsCloseContainer", + "s_HstsGetHstsEntries", + "s_HstsSetHstsEntries", + "s_HstsPurgeContainer", + "s_CookieOpenContainer", + "s_CookieCloseContainer", + "s_CookieGetCookies", + "s_CookieGetAllCookies", + "s_CookieUpdateCookies", + "s_CookiePurgeContainer", + "s_BlobOpenContainer", + "s_BlobCloseContainer", + "s_BlobGetEntries", + "s_BlobGetEntry", + "s_BlobSetEntry", + "s_BlobDeleteEntry", + "s_BlobPurgeContainer" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707608812464, + "Service": null, + "IsServiceRunning": false + }, + "8bef2320-f308-4720-b913-0129cecfa6b9": { + "Module": "NgcCtnrSvc.dll", + "ModulePath": "C:\\Windows\\System32\\NgcCtnrSvc.dll", + "InterfaceId": "8bef2320-f308-4720-b913-0129cecfa6b9", + "InterfaceStructOffset": 551296, + "ProceduresCount": 3, + "Procedures": [ + "s_RpcCreateVsc", + "s_RpcCreateVsc", + "s_RpcVscCreated" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707094013104, + "Service": "NgcCtnrSvc", + "IsServiceRunning": false + }, + "857fb1be-084f-4fb5-b59c-4b2c4be5f0cf": { + "Module": "bisrv.dll", + "ModulePath": "C:\\Windows\\System32\\bisrv.dll", + "InterfaceId": "857fb1be-084f-4fb5-b59c-4b2c4be5f0cf", + "InterfaceStructOffset": 551968, + "ProceduresCount": 1, + "Procedures": [ + "SrvOdbPrivGetLaunchInfo" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708130747456, + "Service": null, + "IsServiceRunning": false + }, + "7e048d38-ac08-4ff1-8e6b-f35dbab88d4a": { + "Module": "mqqm.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-msmq-queuemanager-core_31bf3856ad364e35_10.0.18362.1977_none_8d1646dec2a87b94\\mqqm.dll", + "InterfaceId": "7e048d38-ac08-4ff1-8e6b-f35dbab88d4a", + "InterfaceStructOffset": 1028672, + "ProceduresCount": 1, + "Procedures": [ + "R_NotifyQM" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707093296656, + "Service": null, + "IsServiceRunning": false + }, + "9cbc9d3a-7586-4814-8d70-18737dcbe523": { + "Module": "ngcsvc.dll", + "ModulePath": "C:\\Windows\\System32\\ngcsvc.dll", + "InterfaceId": "9cbc9d3a-7586-4814-8d70-18737dcbe523", + "InterfaceStructOffset": 629936, + "ProceduresCount": 6, + "Procedures": [ + "s_NgcLocalAccountVaultAddCredential", + "s_NgcLocalAccountVaultRemoveCredential", + "s_NgcLocalAccountVaultGetCredential", + "s_NgcLocalAccountVaultGetDefaultUserCredential", + "s_NgcLocalAccountVaultFindCredential", + "s_NgcLocalAccountVaultProtectCredential" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707093973408, + "Service": "NgcSvc", + "IsServiceRunning": false + }, + "1832bcf6-cab8-41d4-85d2-c9410764f75a": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "1832bcf6-cab8-41d4-85d2-c9410764f75a", + "InterfaceStructOffset": 560000, + "ProceduresCount": 9, + "Procedures": [ + "RmCoreRpcSrvConnectToRmServer", + "RmCoreRpcSrvDisconnectFromRmServer", + "RmCoreRpcSrvRegisterActivityHostCallbacks", + "RmCoreRpcSrvUnregisterActivityHostCallbacks", + "RmCoreRpcSrvAcquireResourceSet", + "RmCoreRpcSrvApplyResourceSet", + "RmCoreRpcSrvReleaseResourceSet", + "CrmRpcSrvActivityRenew", + "RmCoreRpcSrvQueryHostMemoryLimitValues" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708133698384, + "Service": null, + "IsServiceRunning": false + }, + "3f31c91e-2545-4b7b-9311-9529e8bffef6": { + "Module": "p2psvc.dll", + "ModulePath": "C:\\Windows\\System32\\p2psvc.dll", + "InterfaceId": "3f31c91e-2545-4b7b-9311-9529e8bffef6", + "InterfaceStructOffset": 364016, + "ProceduresCount": 39, + "Procedures": [ + "PeerGroupCreateRpc", + "PeerGroupOpenRpc", + "PeerGroupJoinRpc", + "PeerGroupPasswordJoinRpc", + "PeerGroupConnectRpc", + "PeerGroupCloseRpc", + "PeerGroupDeleteRpc", + "PeerGroupCreateInvitationRpc", + "PeerGroupCreatePasswordInvitationRpc", + "PeerGroupGetStatusRpc", + "PeerGroupGetPropertiesRpc", + "PeerGroupSetPropertiesRpc", + "PeerGroupEnumConnectionsRpc", + "PeerGroupEnumMembersRpc", + "PeerGroupOpenDirectConnectionRpc", + "PeerGroupCloseDirectConnectionRpc", + "PeerGroupSendDataRpc", + "PeerGroupRegisterEventRpc", + "PeerGroupUnregisterEventRpc", + "PeerGroupGetEventDataRpc", + "PeerGroupGetRecordRpc", + "PeerGroupAddRecordRpc", + "PeerGroupUpdateRecordRpc", + "PeerGroupDeleteRecordRpc", + "PeerGroupEnumRecordsRpc", + "PeerGroupSearchRecordsRpc", + "PeerGroupExportDatabaseRpc", + "PeerGroupImportDatabaseRpc", + "PeerGroupUniversalTimeToPeerTimeRpc", + "PeerGroupPeerTimeToUniversalTimeRpc", + "PeerGetItemCountRpc", + "PeerGetNextMemberInfoItemRpc", + "PeerGetNextConnectionInfoItemRpc", + "PeerGetNextRecordItemRpc", + "PeerEndEnumerationRpc", + "PeerGroupIssueCredentialsRpc", + "PeerGroupConnectByAddressRpc", + "PeerGroupResumePasswordAuthenticationRpc", + "PeerGroupHandlePowerEventRpc" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707580884080, + "Service": "p2psvc", + "IsServiceRunning": false + }, + "7642249b-84c2-4404-b6eb-1e0a2458839a": { + "Module": "NgcCtnrSvc.dll", + "ModulePath": "C:\\Windows\\System32\\NgcCtnrSvc.dll", + "InterfaceId": "7642249b-84c2-4404-b6eb-1e0a2458839a", + "InterfaceStructOffset": 544224, + "ProceduresCount": 1, + "Procedures": [ + "s_NgcSecureBioHandlerRpcGetAuthorizationNonce" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707093991616, + "Service": "NgcCtnrSvc", + "IsServiceRunning": false + }, + "a2484e1a-a313-4ea2-8fe9-8a873ea275ba": { + "Module": "witnesswmiv2provider.dll", + "ModulePath": "C:\\Windows\\System32\\witnesswmiv2provider.dll", + "InterfaceId": "a2484e1a-a313-4ea2-8fe9-8a873ea275ba", + "InterfaceStructOffset": 26592, + "ProceduresCount": 4, + "Procedures": [ + "SERVER_WitnessrMoveClientRequest", + "SERVER_WitnessrGetWmiObjects", + "SERVER_WitnessrGetSvcVersion", + "SERVER_WitnessrMoveClientRequestEx" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708037793552, + "Service": null, + "IsServiceRunning": false + }, + "b4cb7611-ad0b-4c2d-b35f-ffe45785c709": { + "Module": "wwansvc.dll", + "ModulePath": "C:\\Windows\\System32\\wwansvc.dll", + "InterfaceId": "b4cb7611-ad0b-4c2d-b35f-ffe45785c709", + "InterfaceStructOffset": 1117296, + "ProceduresCount": 46, + "Procedures": [ + "WwanRpcOpenHandle", + "WwanRpcCloseHandle", + "WwanRpcRegisterNotification", + "WwanRpcAsyncGetNotification", + "WwanRpcEnumerateInterfaces", + "WwanRpcSetInterface", + "WwanRpcQueryInterface", + "WwanRpcScan", + "WwanRpcRegister", + "WwanRpcConnect", + "WwanRpcConnectAdditionalPdpContext", + "WwanRpcDisconnect", + "WwanRpcSetSmsConfiguration", + "WwanRpcSmsRead", + "WwanRpcSmsSend", + "WwanRpcSmsDelete", + "WwanRpcSetProfile", + "WwanRpcDeleteProfile", + "WwanRpcGetProfile", + "WwanRpcGetProfileList", + "WwanRpcGetProfileListByPurpose", + "WwanRpcGetProfileIstream", + "WwanRpcGetProfileMetaData", + "WwanRpcSetProfileMetaData", + "WwanRpcAuthChallenge", + "WwanRpcGetProfileIndex", + "WwanRpcUssdRequest", + "WwanRpcGetProfileHomeProviderName", + "WwanRpcSearchProfile", + "WwanRpcGetProfileState", + "WwanRpcGetDMConfigProfileList", + "WwanRpcGetDMConfigProfile", + "WwanRpcSetDMConfigProfile", + "WwanRpcDeleteDMConfigProfile", + "WwanRpcGetDMConfigBinary", + "WwanRpcSetDMConfigBinary", + "WwanRpcSetNetworkQuietMode", + "WwanRpcQueryInterfaceEx", + "WwanRpcIPv6eHRPDControlSet", + "WwanRpcIPv6eHRPDControlQuery", + "WwanRpcUiccOpenChannel", + "WwanRpcUiccCloseChannel", + "WwanRpcUiccSendApdu", + "WwanRpcUiccSetTerminalCapability", + "WwanRpcActivateNotification", + "WwanRpcModemLogging" + ], + "ProcStackSize": 64, + "DispatchFunction": 140707093454224, + "Service": "WwanSvc", + "IsServiceRunning": false + }, + "ea0a3165-4834-11d2-a6f8-00c04fa346cc": { + "Module": "FXSSVC.exe", + "ModulePath": "C:\\Windows\\System32\\FXSSVC.exe", + "InterfaceId": "ea0a3165-4834-11d2-a6f8-00c04fa346cc", + "InterfaceStructOffset": 518000, + "ProceduresCount": 105, + "Procedures": [ + "FAX_GetServicePrinters", + "FAX_ConnectionRefCount", + "FAX_OpenPort", + "FAX_ClosePort", + "FAX_EnumJobs", + "FAX_GetJob", + "FAX_SetJob", + "FAX_GetPageData", + "FAX_GetDeviceStatus", + "FAX_Abort", + "FAX_EnumPorts", + "FAX_GetPort", + "FAX_SetPort", + "FAX_EnumRoutingMethods", + "FAX_EnableRoutingMethod", + "FAX_GetRoutingInfo", + "FAX_SetRoutingInfo", + "FAX_EnumGlobalRoutingInfo", + "FAX_SetGlobalRoutingInfo", + "FAX_GetConfiguration", + "FAX_SetConfiguration", + "FAX_GetLoggingCategories", + "FAX_SetLoggingCategories", + "FAX_GetSecurity", + "FAX_SetSecurity", + "FAX_AccessCheck", + "FAX_CheckServerProtSeq", + "FAX_SendDocumentEx", + "FAX_EnumJobsEx", + "FAX_GetJobEx", + "FAX_GetCountryList", + "FAX_GetPersonalProfileInfo", + "FAX_GetQueueStates", + "FAX_SetQueue", + "FAX_GetReceiptsConfiguration", + "FAX_SetReceiptsConfiguration", + "FAX_GetReceiptsOptions", + "FAX_GetVersion", + "FAX_GetOutboxConfiguration", + "FAX_SetOutboxConfiguration", + "FAX_GetPersonalCoverPagesOption", + "FAX_GetArchiveConfiguration", + "FAX_SetArchiveConfiguration", + "FAX_GetActivityLoggingConfiguration", + "FAX_SetActivityLoggingConfiguration", + "FAX_EnumerateProviders", + "FAX_GetPortEx", + "FAX_SetPortEx", + "FAX_EnumPortsEx", + "FAX_GetExtensionData", + "FAX_SetExtensionData", + "FAX_AddOutboundGroup", + "FAX_SetOutboundGroup", + "FAX_RemoveOutboundGroup", + "FAX_EnumOutboundGroups", + "FAX_SetDeviceOrderInGroup", + "FAX_AddOutboundRule", + "FAX_RemoveOutboundRule", + "FAX_SetOutboundRule", + "FAX_EnumOutboundRules", + "FAX_RegisterServiceProviderEx", + "FAX_UnregisterServiceProviderEx", + "FAX_UnregisterRoutingExtension", + "FAX_StartMessagesEnum", + "FAX_EndMessagesEnum", + "FAX_EnumMessages", + "FAX_GetMessage", + "FAX_RemoveMessage", + "FAX_StartCopyToServer", + "FAX_StartCopyMessageFromServer", + "FAX_WriteFile", + "FAX_ReadFile", + "FAX_EndCopy", + "FAX_StartServerNotification", + "FAX_StartServerNotificationEx", + "FAX_EndServerNotification", + "FAX_GetServerActivity", + "FAX_SetConfigWizardUsed", + "FAX_EnumRoutingExtensions", + "FAX_AnswerCall", + "FAX_ConnectFaxServer", + "FAX_GetSecurityEx", + "FAX_RefreshArchive", + "FAX_SetRecipientsLimit", + "FAX_GetRecipientsLimit", + "FAX_GetServerSKU", + "FAX_CheckValidFaxFolder", + "FAX_GetJobEx2", + "FAX_EnumJobsEx2", + "FAX_GetMessageEx", + "FAX_StartMessagesEnumEx", + "FAX_EnumMessagesEx", + "FAX_StartServerNotificationEx2", + "FAX_CreateAccount", + "FAX_DeleteAccount", + "FAX_EnumAccounts", + "FAX_GetAccountInfo", + "FAX_GetGeneralConfiguration", + "FAX_SetGeneralConfiguration", + "FAX_GetSecurityEx2", + "FAX_SetSecurityEx2", + "FAX_AccessCheckEx2", + "FAX_ReAssignMessage", + "FAX_SetMessage", + "FAX_GetConfigOption" + ], + "ProcStackSize": 32, + "DispatchFunction": 140702770662416, + "Service": "Fax", + "IsServiceRunning": false + }, + "fd7a0523-dc70-43dd-9b2e-9c5ed48225b1": { + "Module": "appinfo.dll", + "ModulePath": "C:\\Windows\\System32\\appinfo.dll", + "InterfaceId": "fd7a0523-dc70-43dd-9b2e-9c5ed48225b1", + "InterfaceStructOffset": 106688, + "ProceduresCount": 1, + "Procedures": [ + "RAiGetTokenForMSI" + ], + "ProcStackSize": 152, + "DispatchFunction": 140707486598720, + "Service": "Appinfo", + "IsServiceRunning": true + }, + "bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760": { + "Module": "psmsrv.dll", + "ModulePath": "C:\\Windows\\System32\\psmsrv.dll", + "InterfaceId": "bdaa0970-413b-4a3e-9e5d-f6dc9d7e0760", + "InterfaceStructOffset": 168672, + "ProceduresCount": 5, + "Procedures": [ + "PsmSrvOpenTcChannel", + "PsmSrvApplyTaskCompletion", + "PsmSrvRegisterDynamicProcess", + "PsmSrvCloseActivationChannel", + "PsmSrvGetSessionInfo" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708134210256, + "Service": "BrokerInfrastructure", + "IsServiceRunning": true + }, + "4943e10d-2d9c-4f31-a31b-212c9f1dca8b": { + "Module": "rpcss.dll", + "ModulePath": "C:\\Windows\\System32\\rpcss.dll", + "InterfaceId": "4943e10d-2d9c-4f31-a31b-212c9f1dca8b", + "InterfaceStructOffset": 978608, + "ProceduresCount": 1, + "Procedures": [ + "ExpireRemoteResources" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708135228400, + "Service": "RpcSs", + "IsServiceRunning": true + }, + "53825514-1183-4934-a0f4-cfdc51c3389b": { + "Module": "lsm.dll", + "ModulePath": "C:\\Windows\\System32\\lsm.dll", + "InterfaceId": "53825514-1183-4934-a0f4-cfdc51c3389b", + "InterfaceStructOffset": 479984, + "ProceduresCount": 5, + "Procedures": [ + "RpcIsCurrentSessionTerminalRemote", + "RpcGetCurrentSessionTerminalName", + "RpcGetCurrentSessionInformation", + "RpcGetCurrentSessionCapabilities", + "RpcGetCurrentSessionType" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708131516656, + "Service": "LSM", + "IsServiceRunning": true + }, + "ecbdb051-f208-46b9-8c8b-648d9d3f3944": { + "Module": "iphlpsvc.dll", + "ModulePath": "C:\\Windows\\System32\\iphlpsvc.dll", + "InterfaceId": "ecbdb051-f208-46b9-8c8b-648d9d3f3944", + "InterfaceStructOffset": 483776, + "ProceduresCount": 2, + "Procedures": [ + "RefreshTeredoState", + "ResetDisabledComponentsForTeredo" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707888009952, + "Service": "iphlpsvc", + "IsServiceRunning": true + }, + "367abb81-9844-35f1-ad32-98f038001003": { + "Module": "services.exe", + "ModulePath": "C:\\Windows\\System32\\services.exe", + "InterfaceId": "367abb81-9844-35f1-ad32-98f038001003", + "InterfaceStructOffset": 501200, + "ProceduresCount": 65, + "Procedures": [ + "RCloseServiceHandle", + "RControlService", + "RDeleteService", + "RLockServiceDatabase", + "RQueryServiceObjectSecurity", + "RSetServiceObjectSecurity", + "RQueryServiceStatus", + "RSetServiceStatus", + "RUnlockServiceDatabase", + "RNotifyBootConfigStatus", + "RI_ScSetServiceBitsW", + "RChangeServiceConfigW", + "RCreateServiceW", + "REnumDependentServicesW", + "REnumServicesStatusW", + "ROpenSCManagerW", + "ROpenServiceW", + "RQueryServiceConfigW", + "RQueryServiceLockStatusW", + "RStartServiceW", + "RGetServiceDisplayNameW", + "RGetServiceKeyNameW", + "GetStatusInternal", + "RChangeServiceConfigA", + "RCreateServiceA", + "REnumDependentServicesA", + "REnumServicesStatusA", + "ROpenSCManagerA", + "ROpenServiceA", + "RQueryServiceConfigA", + "RQueryServiceLockStatusA", + "RStartServiceA", + "RGetServiceDisplayNameA", + "RGetServiceKeyNameA", + "GetStatusInternal", + "REnumServiceGroupW", + "RChangeServiceConfig2A", + "RChangeServiceConfig2W", + "RQueryServiceConfig2A", + "RQueryServiceConfig2W", + "RQueryServiceStatusEx", + "REnumServicesStatusExA", + "REnumServicesStatusExW", + "RI_ScBroadcastServiceControlMessage", + "RCreateServiceWOW64A", + "RCreateServiceWOW64W", + "RI_ScQueryServiceTagInfo", + "RNotifyServiceStatusChange", + "RGetNotifyResults", + "RCloseNotifyHandle", + "RControlServiceExA", + "RControlServiceExW", + "RI_ScSendPnPMessage", + "RI_ScValidatePnPService", + "RI_ScOpenServiceStatusHandle", + "RI_ScQueryServiceConfig", + "RQueryServiceConfigEx", + "RI_ScRegisterPreshutdownRestart", + "RI_ScReparseServiceDatabase", + "RQueryUserServiceName", + "RCreateWowService", + "RGetServiceRegistryStateKey", + "RGetServiceDirectory", + "RGetServiceProcessToken", + "ROpenSCManager2" + ], + "ProcStackSize": 40, + "DispatchFunction": 140702191738272, + "Service": null, + "IsServiceRunning": false + }, + "78e5d322-59a2-4324-ae3f-8bc8de32bdfc": { + "Module": "sstpsvc.dll", + "ModulePath": "C:\\Windows\\System32\\sstpsvc.dll", + "InterfaceId": "78e5d322-59a2-4324-ae3f-8bc8de32bdfc", + "InterfaceStructOffset": 127152, + "ProceduresCount": 5, + "Procedures": [ + "SstpSvcSetConfig", + "SstpSvcGetConfig", + "SstpSvcCreateUpdateTenantGatewayMapping", + "SstpSvcRemoveTenantGatewayMapping", + "SstpSvcGetTenantGatewayMapping" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707932021904, + "Service": "SstpSvc", + "IsServiceRunning": true + }, + "c8ba73d2-3d55-429c-8e9a-c44f006f69fc": { + "Module": "UserDataService.dll", + "ModulePath": "C:\\Windows\\System32\\UserDataService.dll", + "InterfaceId": "c8ba73d2-3d55-429c-8e9a-c44f006f69fc", + "InterfaceStructOffset": 1286160, + "ProceduresCount": 133, + "Procedures": [ + "UdmSvcImpl_CloseEnumHandle", + "UdmSvcImpl_CloseSessionHandle", + "UdmSvcImpl_OpenSession", + "UdmSvcImpl_CreateSessionWithSameSecurityContext", + "UdmSvcImpl_OpenCallHistorySession", + "UdmSvcImpl_EnableProcessForTesting", + "UdmSvcImpl_EnableUserDataServiceBackgroundNotification", + "UdmSvcImpl_CheckObjectExistence", + "UdmSvcImpl_GetObjectProperties", + "UdmSvcImpl_GetObjectPropertiesWithScope", + "UdmSvcImpl_GetAppointmentProperties", + "UdmSvcImpl_GetCallHistoryEnum", + "UdmSvcImpl_DeleteCallHistory", + "UdmSvcImpl_MarkCallHistorySeen", + "UdmSvcImpl_CreateCallHistoryItem", + "UdmSvcImpl_GetUnseenCallCount", + "UdmSvcImpl_UpdateCallDetails", + "UdmSvcImpl_ResolveCalls", + "UdmSvcImpl_GetCallHistoryEntryEnum", + "UdmSvcImpl_UpdateEnumPropertySet", + "UdmSvcImpl_EnumFetchObjects", + "UdmSvcImpl_EnumFetchMatchingObjects", + "UdmSvcImpl_EnumGetCount", + "UdmSvcImpl_EnumGetState", + "UdmSvcImpl_EnumMoveFirst", + "UdmSvcImpl_EnumMoveLast", + "UdmSvcImpl_CreateCallFavoriteItem", + "UdmSvcImpl_DeleteCallFavorite", + "UdmSvcImpl_MoveCallFavoriteItem", + "UdmSvcImpl_ReorderGroups", + "UdmSvcImpl_ResolveFavorites", + "UdmSvcImpl_GetCallFavoriteEnum", + "UdmSvcImpl_ControlSessionNotifies", + "UdmSvcImpl_Advise", + "UdmSvcImpl_Unadvise", + "UdmSvcImpl_HasNotifications", + "UdmSvcImpl_GetNotifyMessage", + "UdmSvcImpl_GetFilePropertyStream", + "UdmSvcImpl_UpdateCallHistoryObjects", + "UdmSvcImpl_UpdateCalendarObjects", + "UdmSvcImpl_GetUnexpandedAppointmentEnum", + "UdmSvcImpl_GetCalendarEnum", + "UdmSvcImpl_GetAppointmentEnum", + "UdmSvcImpl_GetSingleAppointmentEnum", + "UdmSvcImpl_GetAppointmentSearchEnum", + "UdmSvcImpl_GetAppointmentExceptionEnum", + "UdmSvcImpl_GetAppointmentRevisionEnum", + "UdmSvcImpl_GetConflictInfoById", + "UdmSvcImpl_GetConflictInfoByProperties", + "UdmSvcImpl_GetAppointmentAppInfo", + "UdmSvcImpl_GetLocalIdArrayFromAppointmentRemoteObjectId", + "UdmSvcImpl_SetAutoReplySettings", + "UdmSvcImpl_GetAutoReplySettings", + "UdmSvcImpl_StartOrResetChangeTracking", + "UdmSvcImpl_ValidateCallerAccess", + "UdmSvcImpl_GenerateValidationToken", + "UdmSvcImpl_RedeemValidationToken", + "UdmSvcImpl_DeleteAllPackageData", + "UdmSvcImpl_CleanupStaleAppData", + "UdmSvcImpl_UpdateChatObjects", + "UdmSvcImpl_UpdateChangeTracking", + "UdmSvcImpl_ValidateChatMessage", + "UdmSvcImpl_GetChatObjectProperties", + "UdmSvcImpl_GetChatMessageEnum", + "UdmSvcImpl_GetChatRevisionMessageEnum", + "UdmSvcImpl_EnumFetchChatMessages", + "UdmSvcImpl_GetChatConversationEnum", + "UdmSvcImpl_GetChatSearchEnum", + "UdmSvcImpl_GetChatConversationIdFromThreadingInfo", + "UdmSvcImpl_GetChatTransports", + "UdmSvcImpl_RegisterChatTransport", + "UdmSvcImpl_GetChatApps", + "UdmSvcImpl_GetDefaultChatApp", + "UdmSvcImpl_SetDefaultChatApp", + "UdmSvcImpl_NotifyChatApp", + "UdmSvcImpl_UpdateAnnotationObjects", + "UdmSvcImpl_GetContactMatchSuggestions", + "UdmSvcImpl_UpdateContactObjects", + "UdmSvcImpl_ContactLinking", + "UdmSvcImpl_SetContactPreference", + "UdmSvcImpl_SetRemoteIdentificationInformation", + "UdmSvcImpl_GetMeContactId", + "UdmSvcImpl_VCardToContact", + "UdmSvcImpl_ContactToVCard", + "UdmSvcImpl_SetContactNameOrder", + "UdmSvcImpl_SetContactNameIncludeMiddle", + "UdmSvcImpl_ToggleContactMaintenance", + "UdmSvcImpl_GetObjectByRemoteId", + "UdmSvcImpl_GetAnnotationListEnum", + "UdmSvcImpl_GetContactListEnum", + "UdmSvcImpl_GetContactEnum", + "UdmSvcImpl_GetAnnotationEnum", + "UdmSvcImpl_GetContactRevisionEnum", + "UdmSvcImpl_UpdateEmailObjects", + "UdmSvcImpl_GetEmailFolderMessageCounts", + "UdmSvcImpl_GetEmailMailboxEnum", + "UdmSvcImpl_GetEmailFolderEnum", + "UdmSvcImpl_GetEmailRevisionEnum", + "UdmSvcImpl_GetEmailMessageEnum", + "UdmSvcImpl_GetEmailConversationEnum", + "UdmSvcImpl_IsChangeTrackingEnabled", + "UdmSvcImpl_EmptyEmailFolder", + "UdmSvcImpl_CreateResponseMessage", + "UdmSvcImpl_MoveFolder", + "UdmSvcImpl_CreateFolder", + "UdmSvcImpl_RespondToMeeting", + "UdmSvcImpl_ForwardMeeting", + "UdmSvcImpl_ProposeNewTimeForMeeting", + "UdmSvcImpl_ResolveRecipients", + "UdmSvcImpl_ValidateCertificates", + "UdmSvcImpl_GetMessageIdFromAttachmentId", + "UdmSvcImpl_RegisterSyncManager", + "UdmSvcImpl_SyncObject", + "UdmSvcImpl_GetUserDataAccountEnum", + "UdmSvcImpl_UpdateUserDataAccountObjects", + "UdmSvcImpl_MakeDefaultAccount", + "UdmSvcImpl_GetCachedChatCapabilities", + "UdmSvcImpl_GetChatCapabilitiesFromNetwork", + "UdmSvcImpl_GetRcsServiceStatus", + "UdmSvcImpl_SendLocalParticipantComposing", + "UdmSvcImpl_RaiseRemoteParticipantComposing", + "UdmSvcImpl_AdviseForConversationComposingStatusChanges", + "UdmSvcImpl_UnadviseFromConversationComposingStatusChanges", + "UdmSvcImpl_GetChatCloudServiceSettings", + "UdmSvcImpl_SetChatCloudServiceSettings", + "UdmSvcImpl_UpdateRcsEndUserMessage", + "UdmSvcImpl_StartCloudServiceSync", + "UdmSvcImpl_UpdateTaskObjects", + "UdmSvcImpl_GetTaskListEnum", + "UdmSvcImpl_GetTaskEnum", + "UdmSvcImpl_UpdateContactGroupObjects", + "UdmSvcImpl_GetContactGroupEnum", + "UdmSvcImpl_GetContactGroupMemberEnum" + ], + "ProcStackSize": 48, + "DispatchFunction": 140706535273312, + "Service": "UserDataSvc", + "IsServiceRunning": false + }, + "cc105610-da03-467e-bc73-5b9e2937458d": { + "Module": "wlidsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wlidsvc.dll", + "InterfaceId": "cc105610-da03-467e-bc73-5b9e2937458d", + "InterfaceStructOffset": 1315024, + "ProceduresCount": 87, + "Procedures": [ + "WLIDPublishService", + "WLIDUnpublishService", + "WLIDResolveDevice", + "WLIDResolveUser", + "WLIDConnectIdentity", + "WLIDUpdateConnectedIdentity", + "WLIDCompleteConnect", + "WLIDDisconnectIdentity", + "WLIDCreateIdentity", + "WLIDDeleteIdentity", + "WLIDImportIdentity", + "WLIDGetLocalDeviceName", + "WLIDCreateContext", + "WLIDCreateContextWithLogonId", + "WLIDSetAuthData", + "WLIDDeleteContext", + "WLIDGetServiceConfig", + "WLIDAcquireTokens", + "WLIDUpdateToken", + "WLIDAddOrDeleteColorSetCookie", + "WLIDWatsonReport", + "WLIDGetCachedTokens", + "WLIDGetExtendedError", + "WLIDGetUserExtendedProperty", + "WLIDSetUserExtendedProperty", + "WLIDGetIdentityProperty", + "WLIDSetOptions", + "WLIDEnumIdentities", + "WLIDHasPersistedCredential", + "WLIDPersistCredential", + "WLIDPersistCredentialForConnectedUser", + "WLIDRemovePersistedCredential", + "WLIDVerifyAssertion", + "WLIDGetDeviceId", + "WLIDProvisionDeviceId", + "WLIDGetDeviceIdEx", + "WLIDRenewDeviceId", + "WLIDDeProvisionDeviceId", + "WLIDEnumDevices", + "WLIDAssociateDeviceToUser", + "WLIDDisassociateDeviceFromUser", + "WLIDEnumerateUserAssociatedDevices", + "WLIDUpdateUserAssociatedDeviceProperties", + "WLIDCreateContextForLinkedIdentity", + "WLIDAddUserToSsoGroup", + "WLIDGetUsersFromSsoGroup", + "WLIDRemoveUserFromSsoGroup", + "WLIDGetAuthError", + "WLIDGetDeviceShortLivedToken", + "WLIDGetHIPChallenge", + "WLIDSetHIPSolution", + "WLIDSetDefaultUserForTarget", + "WLIDGetDefaultUserForTarget", + "WLIDIsKioskMode", + "WLIDGetConfigString", + "WLIDGetSvcEnvironment", + "WLIDGetIdName", + "WLIDGetConfigDWORDValue", + "WLIDGetUserPropertiesFromSystemStore", + "WLIDSetUserPropertiesToSystemStore", + "WLIDInitializeEx", + "WLIDEnableTrace", + "WLIDDisableTrace", + "WLIDGetOneTimeCredential", + "WLIDGetIssuerCertificate", + "WLIDCreateContextWithChallenge", + "WLIDGetDefaultUserForTargetEx", + "WLIDSendOneTimeCode", + "WLIDGetUserPropertiesFromHandle", + "WLIDGetKeyLatest", + "WLIDGetKeyWithVersion", + "WLIDGetOpenHandlesData", + "WLIDGetSignedTokens", + "WLIDGetDeviceDAToken", + "WLIDGetProofOfPossessionTokens", + "WLIDRegisterUserIdkey", + "WLIDUpdateDeviceLicenseInfo", + "WLIDManageApprover", + "WLIDListSessions", + "WLIDApproveSession", + "WLIDGetScenarioInlineUrlWithContextData", + "WLIDGetInlineUrlContextData", + "WLIDAcquireTokensWithNGC", + "WLIDGetTotpCode", + "WLIDCleanupIdentity", + "WLIDGetAppData", + "WLIDProvisionIdentityWithTransferToken" + ], + "ProcStackSize": 72, + "DispatchFunction": 140707092939056, + "Service": "wlidsvc", + "IsServiceRunning": false + }, + "00efb8be-002d-45cd-81b0-f65b260f8a13": { + "Module": "ActionMgr.dll", + "ModulePath": "C:\\Windows\\System32\\ActionMgr.dll", + "InterfaceId": "00efb8be-002d-45cd-81b0-f65b260f8a13", + "InterfaceStructOffset": 49152, + "ProceduresCount": 3, + "Procedures": [ + "SrvRpcActionObjectServiceConnect", + "SrvRpcActionObjectServiceDisconnect", + "SrvRpcActionObjectRunJson" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707392628128, + "Service": null, + "IsServiceRunning": false + }, + "0b1c2170-5732-4e0e-8cd3-d9b16f3b84d7": { + "Module": "authz.dll", + "ModulePath": "C:\\Windows\\System32\\authz.dll", + "InterfaceId": "0b1c2170-5732-4e0e-8cd3-d9b16f3b84d7", + "InterfaceStructOffset": 172224, + "ProceduresCount": 7, + "Procedures": [ + "s_AuthzrFreeContext", + "s_AuthzrInitializeContextFromSid", + "s_AuthzrInitializeCompoundContext", + "s_AuthzrAccessCheck", + "s_AuthzGetInformationFromContext", + "s_AuthzrModifyClaims", + "s_AuthzrModifySids" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708142033392, + "Service": null, + "IsServiceRunning": false + }, + "26268c86-e770-433e-86ef-5f3ba6731fba": { + "Module": "HostNetSvc.dll", + "ModulePath": "C:\\Windows\\System32\\HostNetSvc.dll", + "InterfaceId": "26268c86-e770-433e-86ef-5f3ba6731fba", + "InterfaceStructOffset": 2499872, + "ProceduresCount": 53, + "Procedures": [ + "HnsRpc_EnumerateNetworks", + "HnsRpc_CreateNetwork", + "HnsRpc_OpenNetwork", + "HnsRpc_ModifyNetwork", + "HnsRpc_QueryNetworkProperties", + "HnsRpc_DeleteNetwork", + "HnsRpc_RegisterNetworkNotifications", + "HnsRpc_UnregisterGuestNetworkServiceNotifications", + "HnsRpc_QueryGuestNetworkServiceNotification", + "HnsRpc_CloseGuestNetworkService", + "HnsRpc_EnumerateNamespaces", + "HnsRpc_CreateNamespace", + "HnsRpc_OpenNamespace", + "HnsRpc_ModifyNamespace", + "HnsRpc_QueryNamespaceProperties", + "HnsRpc_DeleteNamespace", + "HnsRpc_CloseGuestNetworkService", + "HnsRpc_EnumerateEndpoints", + "HnsRpc_CreateEndpoint", + "HnsRpc_OpenEndpoint", + "HnsRpc_ModifyEndpoint", + "HnsRpc_QueryEndpointProperties", + "HnsRpc_DeleteEndpoint", + "HnsRpc_CloseEndpoint", + "HnsRpc_EnumerateLoadBalancers", + "HnsRpc_CreateLoadBalancer", + "HnsRpc_OpenLoadBalancer", + "HnsRpc_ModifyLoadBalancer", + "HnsRpc_QueryLoadBalancerProperties", + "HnsRpc_DeleteLoadBalancer", + "HnsRpc_CloseGuestNetworkService", + "HnsRpc_EnumerateSdnRoutes", + "HnsRpc_CreateSdnRoute", + "HnsRpc_OpenLoadBalancer", + "HnsRpc_ModifySdnRoute", + "HnsRpc_QuerySdnRouteProperties", + "HnsRpc_DeleteLoadBalancer", + "HnsRpc_CloseGuestNetworkService", + "HnsRpc_OpenService", + "HnsRpc_RegisterServiceNotifications", + "HnsRpc_UnregisterGuestNetworkServiceNotifications", + "HnsRpc_QueryGuestNetworkServiceNotification", + "HnsRpc_CloseGuestNetworkService", + "HnsRpc_EnumerateGuestNetworkServices", + "HnsRpc_CreateGuestNetworkService", + "HnsRpc_OpenGuestNetworkService", + "HnsRpc_ModifyGuestNetworkService", + "HnsRpc_QueryGuestNetworkServiceProperties", + "HnsRpc_DeleteGuestNetworkService", + "HnsRpc_RegisterGuestNetworkServiceNotifications", + "HnsRpc_UnregisterGuestNetworkServiceNotifications", + "HnsRpc_QueryGuestNetworkServiceNotification", + "HnsRpc_CloseGuestNetworkService" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707750170608, + "Service": "hns", + "IsServiceRunning": true + }, + "7f9d11bf-7fb9-436b-a812-b2d50c5d4c03": { + "Module": "MPSSVC.dll", + "ModulePath": "C:\\Windows\\System32\\MPSSVC.dll", + "InterfaceId": "7f9d11bf-7fb9-436b-a812-b2d50c5d4c03", + "InterfaceStructOffset": 710800, + "ProceduresCount": 18, + "Procedures": [ + "RPC_FWIndicatePortInUse", + "RPC_FWGetIndicatedPortInUse", + "RPC_FWIndicateTupleInUse", + "RPC_FWResetIndicatedTupleInUse", + "RPC_FWIndicateProxyForUrl", + "OnNetworkAdded", + "RPC_FWIsTargetAProxy", + "RPC_NetworkIsolationSetupAppContainerBinaries", + "RPC_NetworkIsolationRegisterForAppContainerChanges", + "Rpc_NetworkIsolationRegistrationGetLastEvent", + "RPC_NetworkIsolationUnregisterForAppContainerChanges", + "RPC_NetworkIsolationGetAppContainer", + "RPC_NetworkIsolationEnumAppContainers", + "RPC_NetworkIsolationAddAllowEnterpriseIdRule", + "RPC_NetworkIsolationCreateAllInterfacesContainer", + "RPC_NetworkIsolationCreateInterfaceContainer", + "RPC_NetworkIsolationDeleteAllInterfacesContainer", + "RPC_NetworkIsolationDeleteInterfaceContainer" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708003537936, + "Service": "mpssvc", + "IsServiceRunning": true + }, + "fd6bb951-c830-4734-bf2c-18ba6ec7ab49": { + "Module": "iscsiexe.dll", + "ModulePath": "C:\\Windows\\System32\\iscsiexe.dll", + "InterfaceId": "fd6bb951-c830-4734-bf2c-18ba6ec7ab49", + "InterfaceStructOffset": 121488, + "ProceduresCount": 24, + "Procedures": [ + "DiscGetInitiatorList", + "DiscGetTargets", + "DiscGetTargetInfo", + "DiscLoginTarget", + "DiscLogoutTarget", + "DiscRefreshAll", + "DiscRefreshInitiator", + "DiscSessionIdToHBA", + "DiscStaticTarget", + "DiscSNS", + "DiscTargetPortal", + "DiscReportTargetPortals", + "DiscPresharedKey", + "DiscGetIKEInformation", + "DiscAddConnection", + "DiscRemoveConnection", + "DiscSetTunnelOuterModeAddress", + "DiscInitiatorSharedSecret", + "DiscRadiusSharedSecret", + "DiscInitiatorNodeName", + "DiscGetInitiatorNodeName", + "DiscSetupPersistentDevices", + "DiscGetTargetPortals", + "DiscRADIUSServer" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707581084992, + "Service": "MSiSCSI", + "IsServiceRunning": false + }, + "cc4b408c-4c4e-422f-9849-47bb47bd4d2e": { + "Module": "NaturalAuth.dll", + "ModulePath": "C:\\Windows\\System32\\NaturalAuth.dll", + "InterfaceId": "cc4b408c-4c4e-422f-9849-47bb47bd4d2e", + "InterfaceStructOffset": 385824, + "ProceduresCount": 12, + "Procedures": [ + "NARPCRuleRegister", + "NARPCRuleQuery", + "NARPCRuleUnregister", + "NARPCRuleValidate", + "NARPCDynamicLockStart", + "NARPCDynamicLockStop", + "NARPCDynamicLockForceEvaluate", + "NARPCDynamicLockShouldSkipGracePeriod", + "NARPCDynamicLockShouldIgnoreUserActivity", + "NARPCDynamicLockShouldIgnoreDisplayRequestActivity", + "NARPCDeviceUnlockStart", + "NARPCDeviceUnlockStop" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707093834192, + "Service": "NaturalAuthentication", + "IsServiceRunning": false + }, + "12345778-1234-abcd-ef00-0123456789ab": { + "Module": "lsasrv.dll", + "ModulePath": "C:\\Windows\\System32\\lsasrv.dll", + "InterfaceId": "12345778-1234-abcd-ef00-0123456789ab", + "InterfaceStructOffset": 1270144, + "ProceduresCount": 129, + "Procedures": [ + "LsarClose", + "CredrRename", + "LsarEnumeratePrivileges", + "LsarQuerySecurityObject", + "LsarSetSecurityObject", + "LsaITestCall", + "LsarOpenPolicyRPC", + "LsarQueryInformationPolicy", + "LsarSetInformationPolicy", + "LsaITestCall", + "LsarCreateAccount", + "LsarEnumerateAccounts", + "LsarCreateTrustedDomain", + "LsarEnumerateTrustedDomains", + "LsarLookupNames", + "LsarLookupSids", + "LsarCreateSecret", + "LsarOpenAccount", + "LsarEnumeratePrivilegesAccount", + "LsarAddPrivilegesToAccount", + "LsarRemovePrivilegesFromAccount", + "LsarGetQuotasForAccount", + "LsarSetQuotasForAccount", + "LsarGetSystemAccessAccount", + "LsarSetSystemAccessAccount", + "LsarOpenTrustedDomain", + "LsarQueryInfoTrustedDomain", + "LsarSetInformationTrustedDomain", + "LsarOpenSecret", + "LsarSetSecret", + "LsarQuerySecret", + "LsarLookupPrivilegeValue", + "LsarLookupPrivilegeName", + "LsarLookupPrivilegeDisplayName", + "LsarDeleteObject", + "LsarEnumerateAccountsWithUserRight", + "LsarEnumerateAccountRights", + "LsarAddAccountRights", + "LsarRemoveAccountRights", + "LsarQueryTrustedDomainInfo", + "LsarSetTrustedDomainInfo", + "LsarDeleteTrustedDomain", + "LsarStorePrivateData", + "LsarRetrievePrivateData", + "LsarOpenPolicy2", + "LsarGetUserName", + "LsarQueryInformationPolicy2", + "LsarSetInformationPolicy2", + "LsarQueryTrustedDomainInfoByName", + "LsarSetTrustedDomainInfoByName", + "LsarEnumerateTrustedDomainsEx", + "LsarCreateTrustedDomainEx", + "LsaITestCall", + "LsarQueryDomainInformationPolicy", + "LsarSetDomainInformationPolicy", + "LsarOpenTrustedDomainByName", + "LsaITestCall", + "LsarLookupSids2", + "LsarLookupNames2", + "LsarCreateTrustedDomainEx2", + "CredrWrite", + "CredrRead", + "CredrEnumerate", + "CredrWriteDomainCredentials", + "CredrReadDomainCredentials", + "CredrDelete", + "CredrGetTargetInfo", + "CredrProfileLoaded", + "LsarLookupNames3", + "CredrGetSessionTypes", + "LsarRegisterAuditEvent", + "LsarGenAuditEvent", + "LsarUnregisterAuditEvent", + "LsarQueryForestTrustInformation", + "LsarSetForestTrustInformation", + "CredrRename", + "LsarLookupSids3", + "LsarLookupNames4", + "LsarOpenPolicySce", + "LsarAdtRegisterSecurityEventSource", + "LsarAdtUnregisterSecurityEventSource", + "LsarAdtReportSecurityEvent", + "CredrFindBestCredential", + "LsarSetAuditPolicy", + "LsarQueryAuditPolicy", + "LsarEnumerateAuditPolicy", + "LsarEnumerateAuditCategories", + "LsarEnumerateAuditSubCategories", + "LsarLookupAuditCategoryName", + "LsarLookupAuditSubCategoryName", + "LsarSetAuditSecurity", + "LsarQueryAuditSecurity", + "CredrReadByTokenHandle", + "CredrRestoreCredentials", + "CredrBackupCredentials", + "LsarManageSidNameMapping", + "CredrProfileUnloaded", + "CredrRename", + "CredrRename", + "CredrRename", + "CredrRename", + "CredrRename", + "LsarEfsGetSmartcardCredentials", + "LsarAuditSetGlobalSacl", + "LsarAuditQueryGlobalSacl", + "CredrProfileLoadedEx", + "LsarInteractiveSessionIsLoggedOff", + "LsarConfigureAutoLogonCredentials", + "LsarGetDeviceRegistrationInfo", + "LsaITestCall", + "LsarProfileDeleted", + "LsaITestCall", + "CredrRename", + "LsarValidateProcUniqueLuid", + "LsarIsArsoAllowedByPolicy", + "LsarIsArsoAllowedByConsent", + "LsarEnableArsoConsent", + "LsarDisableArsoConsent", + "LsarIsUserArsoAllowed", + "LsarIsUserArsoEnabled", + "LsarEnableUserArso", + "LsarDisableUserArso", + "LsarConfigureUserArso", + "LsarGetInprocDispatchTable", + "LsarSetSharedUserSession", + "LsarClearSharedUserSession", + "LsarEnablePasswordLessCurrentUser", + "LsarDisablePasswordLessCurrentUser", + "LsarUpdateUserTokenSessionId" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708153895600, + "Service": null, + "IsServiceRunning": false + }, + "9d420415-b8fb-4f4a-8c53-4502ead30ca9": { + "Module": "PlaySndSrv.dll", + "ModulePath": "C:\\Windows\\System32\\PlaySndSrv.dll", + "InterfaceId": "9d420415-b8fb-4f4a-8c53-4502ead30ca9", + "InterfaceStructOffset": 20688, + "ProceduresCount": 1, + "Procedures": [ + "I_PlaySoundkPostMessage" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707681603712, + "Service": null, + "IsServiceRunning": false + }, + "a58d24fe-8b46-4a22-811b-15f95a43956e": { + "Module": "mpengine.dll", + "ModulePath": "C:\\ProgramData\\Microsoft\\Windows Defender\\Definition Updates\\Backup\\mpengine.dll", + "InterfaceId": "a58d24fe-8b46-4a22-811b-15f95a43956e", + "InterfaceStructOffset": 11413344, + "ProceduresCount": 9, + "Procedures": [ + "MpBootStrap", + "MpBootStrap", + "Proc2", + "MpBootStrap", + "MpBootStrap", + "MpBootStrap", + "MpBootStrap", + "MpBootStrap", + "MpBootStrap" + ], + "ProcStackSize": 24, + "DispatchFunction": 140706774273824, + "Service": null, + "IsServiceRunning": false + }, + "b450acb1-fe83-4b48-956e-89be5c42b5c4": { + "Module": "hvsirpcd.exe", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-hvsi-manager_31bf3856ad364e35_10.0.18362.1832_none_158049e1d563edb9\\hvsirpcd.exe", + "InterfaceId": "b450acb1-fe83-4b48-956e-89be5c42b5c4", + "InterfaceStructOffset": 67904, + "ProceduresCount": 5, + "Procedures": [ + "s_HvsiLsaProxyInitializeSecurityContext", + "s_HvsiLsaProxyQueryContextAttributesEx", + "s_HvsiLsaProxyDeleteSecurityContext", + "s_HvsiLsaProxyAcquireCredentialsHandle", + "s_HvsiLsaProxyFreeCredentialsHandle" + ], + "ProcStackSize": 24, + "DispatchFunction": 140698086703920, + "Service": null, + "IsServiceRunning": false + }, + "2fb92682-6599-42dc-ae13-bd2ca89bd11c": { + "Module": "MPSSVC.dll", + "ModulePath": "C:\\Windows\\System32\\MPSSVC.dll", + "InterfaceId": "2fb92682-6599-42dc-ae13-bd2ca89bd11c", + "InterfaceStructOffset": 710592, + "ProceduresCount": 92, + "Procedures": [ + "RPC_FWOpenPolicyStore", + "RPC_FWClosePolicyStore", + "RPC_FWRestoreDefaults", + "RPC_FWGetGlobalConfig", + "RPC_FWSetGlobalConfig", + "RPC_FWAddFirewallRule", + "RPC_FWSetFirewallRule", + "RPC_FWDeleteFirewallRule", + "RPC_FWDeleteAllFirewallRules", + "RPC_FWEnumFirewallRules", + "RPC_FWGetConfig", + "RPC_FWSetConfig", + "RPC_FWNotifyUnsupportedAttempt", + "RPC_FWAddConnectionSecurityRule", + "RPC_FWSetConnectionSecurityRule", + "RPC_FWDeleteConnectionSecurityRule", + "RPC_FWDeleteAllConnectionSecurityRules", + "RPC_FWEnumConnectionSecurityRules", + "RPC_FWAddAuthenticationSet", + "RPC_FWSetAuthenticationSet", + "RPC_FWDeleteAuthenticationSet", + "RPC_FWDeleteAllAuthenticationSets", + "RPC_FWEnumAuthenticationSets", + "RPC_FWAddCryptoSet", + "RPC_FWSetCryptoSet", + "RPC_FWDeleteCryptoSet", + "RPC_FWDeleteAllCryptoSets", + "RPC_FWEnumCryptoSets", + "RPC_FWEnumPhase1SAs", + "RPC_FWEnumPhase2SAs", + "RPC_FWDeletePhase1SAs", + "RPC_FWDeletePhase2SAs", + "RPC_FWRegisterProduct", + "RPC_FWUnregisterProduct", + "RPC_FWEnumProducts", + "RPC_FWAddMainModeRule", + "RPC_FWSetMainModeRule", + "RPC_FWDeleteMainModeRule", + "RPC_FWDeleteAllMainModeRules", + "RPC_FWEnumMainModeRules", + "RPC_FWQueryFirewallRules", + "RPC_FWQueryConnectionSecurityRules2_10", + "RPC_FWQueryMainModeRules", + "RPC_FWQueryAuthenticationSets", + "RPC_FWQueryCryptoSets", + "RPC_FWEnumNetworks", + "RPC_FWEnumAdapters", + "RPC_FWGetGlobalConfig2_10", + "RPC_FWGetConfig2_10", + "RPC_FWAddFirewallRule2_10", + "RPC_FWSetFirewallRule2_10", + "RPC_FWEnumFirewallRules2_10", + "RPC_FWAddConnectionSecurityRule2_10", + "RPC_FWSetConnectionSecurityRule2_10", + "RPC_FWEnumConnectionSecurityRules2_10", + "RPC_FWAddAuthenticationSet2_10", + "RPC_FWSetAuthenticationSet2_10", + "RPC_FWEnumAuthenticationSets2_10", + "RPC_FWAddCryptoSet2_10", + "RPC_FWSetCryptoSet2_10", + "RPC_FWEnumCryptoSets2_10", + "RPC_FWDiagGetAppList", + "RPC_FWAddConnectionSecurityRule2_20", + "RPC_FWSetConnectionSecurityRule2_20", + "RPC_FWEnumConnectionSecurityRules2_20", + "RPC_FWQueryConnectionSecurityRules2_20", + "RPC_FWAddAuthenticationSet2_20", + "RPC_FWSetAuthenticationSet2_20", + "RPC_FWEnumAuthenticationSets2_20", + "RPC_FWQueryAuthenticationSets2_20", + "RPC_FWAddFirewallRule2_20", + "RPC_FWSetFirewallRule2_20", + "RPC_FWEnumFirewallRules2_20", + "RPC_FWQueryFirewallRules2_20", + "RPC_FWQueryIsolationType", + "RPC_FWSelectConSecRule", + "RPC_FWAddFirewallRule2_24", + "RPC_FWSetFirewallRule2_24", + "RPC_FWEnumFirewallRules2_24", + "RPC_FWQueryFirewallRules2_24", + "RPC_FWAddFirewallRule2_25", + "RPC_FWSetFirewallRule2_25", + "RPC_FWEnumFirewallRules2_25", + "RPC_FWQueryFirewallRules2_25", + "RPC_FWAddFirewallRule2_26", + "RPC_FWSetFirewallRule2_26", + "RPC_FWEnumFirewallRules2_26", + "RPC_FWQueryFirewallRules2_26", + "RPC_FWAddFirewallRule2_27", + "RPC_FWSetFirewallRule2_27", + "RPC_FWEnumFirewallRules2_27", + "RPC_FWQueryFirewallRules2_27" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708002896304, + "Service": "mpssvc", + "IsServiceRunning": true + }, + "8337aebc-5564-46fd-bc41-7798f18d2e4b": { + "Module": "ngcsvc.dll", + "ModulePath": "C:\\Windows\\System32\\ngcsvc.dll", + "InterfaceId": "8337aebc-5564-46fd-bc41-7798f18d2e4b", + "InterfaceStructOffset": 630512, + "ProceduresCount": 9, + "Procedures": [ + "s_DeviceCredentialMgrRpcBeginAuthentication", + "s_DeviceCredentialMgrRpcUpdateAuthenticationStage", + "s_DeviceCredentialMgrRpcGetAuthenticationData", + "s_DeviceCredentialMgrRpcProtectData", + "s_DeviceCredentialMgrRpcUnprotectData", + "s_DeviceCredentialMgrRpcCheckProvisionedDevice", + "s_DeviceCredentialMgrRpcHasLogonSession", + "s_DeviceCredentialMgrRpcCheckIfUserSessionIsRequired", + "s_DeviceCredentialMgrRpcStartDevicePresenceCheck" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707094133664, + "Service": "NgcSvc", + "IsServiceRunning": false + }, + "55e6b932-1979-45d6-90c5-7f6270724112": { + "Module": "ResourcePolicyServer.dll", + "ModulePath": "C:\\Windows\\System32\\ResourcePolicyServer.dll", + "InterfaceId": "55e6b932-1979-45d6-90c5-7f6270724112", + "InterfaceStructOffset": 105984, + "ProceduresCount": 10, + "Procedures": [ + "Srv_GetResourcePolicyKey", + "Srv_GetResourcePolicyInformation", + "Srv_CreateResourcePolicy", + "Srv_GetResourcePolicyName", + "Srv_CreatePolicyEngineClientContext", + "Srv_ClosePolicyEngineClientContext", + "Srv_RegisterForPackageEnergyStateChangeNotifications", + "Srv_IsPackageInGoodEnergyState", + "Srv_InterruptiveUIStateChanged_Subscribe", + "Srv_InterruptiveUIStateChanged_Unsubscribe" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708127422960, + "Service": null, + "IsServiceRunning": false + }, + "07b91411-14fe-4856-8982-c3fa7581d784": { + "Module": "PackageStateRoaming.dll", + "ModulePath": "C:\\Windows\\System32\\PackageStateRoaming.dll", + "InterfaceId": "07b91411-14fe-4856-8982-c3fa7581d784", + "InterfaceStructOffset": 98720, + "ProceduresCount": 7, + "Procedures": [ + "SignalRoamingDataChange", + "SignalPackageRegistrationChange", + "SignalHighPrioritySettingChange", + "SignalBackgroundUploadsStarted", + "SignalEnableBackupForPackage", + "SignalForcedQuiesceForPackage", + "SignalStateChangeForPackage" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707581156528, + "Service": null, + "IsServiceRunning": false + }, + "4dace966-a243-4450-ae3f-9b7bcb5315b8": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "4dace966-a243-4450-ae3f-9b7bcb5315b8", + "InterfaceStructOffset": 562224, + "ProceduresCount": 6, + "Procedures": [ + "RmGameModeSrvRegisterProcess", + "RmGameModeSrvUnregisterProcess", + "RmGameModeSrvDisableForRegisteredProcess", + "RmGameModeSrvReenableForRegisteredProcess", + "RmGameModeSrvGetLargestValidResourceRequest", + "RmGameModeSrvRegisterPairedAuxiliaryProcess" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708133699104, + "Service": null, + "IsServiceRunning": false + }, + "b9e79e60-3d52-11ce-aaa1-00006901293f": { + "Module": "rpcss.dll", + "ModulePath": "C:\\Windows\\System32\\rpcss.dll", + "InterfaceId": "b9e79e60-3d52-11ce-aaa1-00006901293f", + "InterfaceStructOffset": 959984, + "ProceduresCount": 11, + "Procedures": [ + "IrotRegister", + "IrotRevoke", + "IrotIsRunning", + "IrotGetObject", + "IrotNoteChangeTime", + "IrotGetTimeOfLastChange", + "IrotEnumRunning", + "IMgotRegister", + "IMgotRevoke", + "IMgotGetObject", + "IMgotEnumRunning" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708135455360, + "Service": "RpcSs", + "IsServiceRunning": true + }, + "e7f76134-9ef5-4949-a2d6-3368cc0988f3": { + "Module": "wcmsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wcmsvc.dll", + "InterfaceId": "e7f76134-9ef5-4949-a2d6-3368cc0988f3", + "InterfaceStructOffset": 768272, + "ProceduresCount": 4, + "Procedures": [ + "RpcEnterConnectedStandby", + "RpcExitConnectedStandby", + "RpcEnterNetQuiet", + "RpcExitNetQuiet" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708018993856, + "Service": "Wcmsvc", + "IsServiceRunning": true + }, + "ffe01159-cfe1-4002-91de-0e0ef32731f5": { + "Module": "NaturalAuth.dll", + "ModulePath": "C:\\Windows\\System32\\NaturalAuth.dll", + "InterfaceId": "ffe01159-cfe1-4002-91de-0e0ef32731f5", + "InterfaceStructOffset": 387104, + "ProceduresCount": 3, + "Procedures": [ + "CDFRPCUpdatePresenceState", + "CDFRPCRegisterDevice", + "CDFRPCUnregisterDevice" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707094069344, + "Service": "NaturalAuthentication", + "IsServiceRunning": false + }, + "015163bb-e769-45e1-afaf-dff7e782b560": { + "Module": "CmService.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-container-manager_31bf3856ad364e35_10.0.18362.1500_none_a0633e62409b621c\\CmService.dll", + "InterfaceId": "015163bb-e769-45e1-afaf-dff7e782b560", + "InterfaceStructOffset": 626560, + "ProceduresCount": 2, + "Procedures": [ + "CmsRpcSrv_EnumerateContainers", + "CmsRpcSrv_GetDebugLayerPath" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707487015760, + "Service": null, + "IsServiceRunning": false + }, + "faf2447b-b348-4feb-8dbe-beee5b7f7778": { + "Module": "wlidsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wlidsvc.dll", + "InterfaceId": "faf2447b-b348-4feb-8dbe-beee5b7f7778", + "InterfaceStructOffset": 1314928, + "ProceduresCount": 1, + "Procedures": [ + "RenewCertificate" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707092905904, + "Service": "wlidsvc", + "IsServiceRunning": false + }, + "f6beaff7-1e19-4fbb-9f8f-b89e2018337c": { + "Module": "wevtsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wevtsvc.dll", + "InterfaceId": "f6beaff7-1e19-4fbb-9f8f-b89e2018337c", + "InterfaceStructOffset": 970752, + "ProceduresCount": 29, + "Procedures": [ + "_EvtRpcRegisterRemoteSubscription", + "_EvtRpcRemoteSubscriptionNextAsync", + "_EvtRpcRemoteSubscriptionNext", + "_EvtRpcRemoteSubscriptionWaitAsync", + "EvtRpcRegisterControllableOperation", + "_EvtRpcRegisterLogQuery", + "EvtRpcClearLog", + "EvtRpcExportLog", + "EvtRpcLocalizeExportLog", + "_EvtRpcMessageRender", + "_EvtRpcMessageRenderDefault", + "_EvtRpcQueryNext", + "_EvtRpcQuerySeek", + "_EvtRpcClose", + "_EvtRpcCancel", + "_EvtRpcAssertConfig", + "_EvtRpcRetractConfig", + "_EvtRpcOpenLogHandle", + "_EvtRpcGetLogFileInfo", + "_EvtRpcGetChannelList", + "_EvtRpcGetChannelConfig", + "EvtRpcPutChannelConfig", + "_EvtRpcGetPublisherList", + "EvtRpcGetPublisherListForChannel", + "_EvtRpcGetPublisherMetadata", + "_EvtRpcGetPublisherResourceMetadata", + "EvtRpcGetEventMetadataEnum", + "EvtRpcGetNextEventMetadata", + "_EvtRpcGetClassicLogDisplayName" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708089353104, + "Service": "EventLog", + "IsServiceRunning": true + }, + "b8cadbaf-e84b-46b9-84f2-6f71c03f9e55": { + "Module": "bisrv.dll", + "ModulePath": "C:\\Windows\\System32\\bisrv.dll", + "InterfaceId": "b8cadbaf-e84b-46b9-84f2-6f71c03f9e55", + "InterfaceStructOffset": 552064, + "ProceduresCount": 1, + "Procedures": [ + "SrvOdbLbPublishLegacyExitCode" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708131134848, + "Service": null, + "IsServiceRunning": false + }, + "df1941c5-fe89-4e79-bf10-463657acf44d": { + "Module": "efssvc.dll", + "ModulePath": "C:\\Windows\\System32\\efssvc.dll", + "InterfaceId": "df1941c5-fe89-4e79-bf10-463657acf44d", + "InterfaceStructOffset": 57104, + "ProceduresCount": 53, + "Procedures": [ + "EfsRpcOpenFileRaw", + "EfsRpcReadFileRaw", + "EfsRpcWriteFileRaw", + "EfsRpcCloseRaw", + "EfsRpcEncryptFileSrv", + "EfsRpcDecryptFileSrv", + "EfsRpcQueryUsersOnFile", + "EfsRpcQueryRecoveryAgents", + "EfsRpcRemoveUsersFromFile", + "EfsRpcAddUsersToFile", + "EfsRpcSetFileEncryptionKey", + "EfsRpcFileKeyInfoEx", + "EfsRpcFileKeyInfo", + "EfsRpcDuplicateEncryptionInfoFile", + "EfsUsePinForEncryptedFiles", + "EfsRpcAddUsersToFileEx", + "EfsRpcFileKeyInfoEx", + "EfsRpcFileKeyInfoEx", + "EfsRpcFileKeyInfoEx", + "EfsRpcFileKeyInfoEx", + "EfsRpcFlushEfsCache", + "EfsRpcEncryptFileExSrv", + "EfsRpcQueryProtectors", + "EfsRpcWriteFileWithHeaderRaw", + "EdpRpcCredentialCreate", + "EdpRpcCredentialQuery", + "EdpRpcCredentialExists", + "EdpRpcCredentialDelete", + "EdpRpcQueryRevokedPolicyOwnerIds", + "EdpRpcQueryDplEnforcedPolicyOwnerIds", + "EdpRpcGetLockSessionWrappedKey", + "EdpRpcGetLockSessionUnwrappedKey", + "EdpRpcGetCredServiceState", + "EdpRpcDplUpgradePinInfo", + "EdpRpcDplUpgradeVerifyUser", + "EdpRpcDplUserCredentialsSet", + "EdpRpcDplUserUnlockStart", + "EdpRpcDplUserUnlockComplete", + "EdpRpcQueueFileForEncryption", + "EdpRpcServiceFileEncryptionQueue", + "EdpRpcCredSvcControl", + "EdpRpcRmsClearKeys", + "EdpRpcRmsContainerizeFile", + "EdpRpcRmsGetContainerIdentity", + "EdpRpcRmsDecontainerizeFile", + "EdpRpcAllowFileAccessForProcess", + "EdpRpcGetTfaCache", + "EdpRpcUnprotectFile", + "EdpRpcPurgeAppLearningEvents", + "OefsRpcCheckSupport", + "EdpRpcWriteLogSiteLearningEvents", + "EfsRpcReprotectFile", + "EdpRpcIsConsumerProtectionEnforced" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707880067024, + "Service": "EFS", + "IsServiceRunning": false + }, + "d3c1b64b-cd05-4fb2-bb2c-bb61d80c123e": { + "Module": "Spectrum.exe", + "ModulePath": "C:\\Windows\\System32\\Spectrum.exe", + "InterfaceId": "d3c1b64b-cd05-4fb2-bb2c-bb61d80c123e", + "InterfaceStructOffset": 726992, + "ProceduresCount": 50, + "Procedures": [ + "S_System_Connect", + "S_System_Disconnect", + "S_System_DrainSensorData", + "S_System_SetSensorRefs", + "S_Capability_GetRequestedAccessState", + "S_Capability_RequestAccess", + "S_PVCamCalibrator_GetPVCamCalibration", + "S_SecondaryHead_GetUpdates", + "S_SecondaryHead_GetCalibration", + "S_Stage_GetCurrent", + "S_GestureRecognizer_GetParams", + "S_HeadTracker_RegisterActiveLocation", + "S_HeadTracker_RegisterLocation", + "S_HeadTracker_UnregisterLocation", + "S_HeadTracker_PersistedLocations", + "S_HeadTracker_PersistLocation", + "S_HeadTracker_UnpersistLocation", + "S_HeadTracker_GetAugmentedPoseForTime", + "S_HeadTracker_GenerateRenderingMetadataForPose", + "S_HeadTracker_GetAugmentedPoseForSerializedRigPose", + "S_HeadTracker_GetHeTLayoutBuffer", + "S_HeadTracker_SetRequestedMrcStatus", + "S_HeadTracker_GetRequestedMrcStatus", + "S_HeadTracker_SetupExportAnchors", + "S_HeadTracker_SetupImportAnchors", + "S_HeadTracker_SetupGetNeighborhoodData", + "S_HeadTracker_SetupGetNeighborhoodDataStatus", + "S_HeadTracker_GetDeviceID", + "S_Display_GetDisplays", + "S_Display_GetDisplayCalibration", + "S_Display_RenderingMetadataSharedBuffer", + "S_Display_GetDisplayAreaMesh", + "S_Display_GetIsUserPresent", + "S_Display_ContainsDevice", + "S_Display_SetIPD", + "S_Display_GetIPD", + "S_Display_GetIPDAdjustmentCapability", + "S_Display_GetPrimaryAdapterId", + "S_Surfaces_IsSupported", + "S_Surfaces_GetSRBuffer", + "S_Surfaces_FetchMesh", + "S_SpatialDevice_FindById", + "S_SpatialDevice_GetAllDevices", + "S_SpatialDevice_GetOrCreateGlobal", + "S_SpatialDevice_CreateAppLocal", + "S_SpatialDevice_ComputeSpatialGraphBinding", + "S_SpatialDevice_SetDesiredTrackingLevel", + "S_SpatialDevice_GetLastKnownTrackerMode", + "S_SpatialGraph_GetSpatialDeviceForFloor", + "S_SpatialDevice_GetDynamicNodePoseQueueLayoutBuffer" + ], + "ProcStackSize": 32, + "DispatchFunction": 140701106670448, + "Service": "spectrum", + "IsServiceRunning": false + }, + "4ed8abcc-f1e2-438b-981f-bb0e8abc010c": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "4ed8abcc-f1e2-438b-981f-bb0e8abc010c", + "InterfaceStructOffset": 565648, + "ProceduresCount": 4, + "Procedures": [ + "HamRpcSrvConnectStateChangeNotifications", + "HamRpcSrvDisconnect", + "HamRpcSrvGetApplicationStateForPsmKey", + "HamRpcSrvTerminateIfSuspendedByProcess" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708133772976, + "Service": null, + "IsServiceRunning": false + }, + "56244243-3ed3-4013-b3e7-0fc809e35fba": { + "Module": "wephostsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wephostsvc.dll", + "InterfaceId": "56244243-3ed3-4013-b3e7-0fc809e35fba", + "InterfaceStructOffset": 17424, + "ProceduresCount": 8, + "Procedures": [ + "s_QueryProtectionStatus", + "s_IsDeviceLockable", + "s_LockDevice", + "s_GetDeviceLockoutData", + "s_ValidateDeviceLockoutState", + "s_UpdateDeviceLockoutState", + "s_DisableDeviceLockoutState", + "s_GetDeviceLockoutSize" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708037796368, + "Service": "WEPHOSTSVC", + "IsServiceRunning": false + }, + "6d809348-7e6c-41b9-91bc-630fe5503d66": { + "Module": "AppVEntSubsystemController.dll", + "ModulePath": "C:\\Windows\\System32\\AppVEntSubsystemController.dll", + "InterfaceId": "6d809348-7e6c-41b9-91bc-630fe5503d66", + "InterfaceStructOffset": 900944, + "ProceduresCount": 1, + "Procedures": [ + "vobjects_server_GetObjectExclusions" + ], + "ProcStackSize": 72, + "DispatchFunction": 140706797802416, + "Service": null, + "IsServiceRunning": false + }, + "e1ac57d7-2eeb-4553-b980-f80c69a9e0f7": { + "Module": "combase.dll", + "ModulePath": "C:\\Windows\\System32\\combase.dll", + "InterfaceId": "e1ac57d7-2eeb-4553-b980-f80c69a9e0f7", + "InterfaceStructOffset": 2274448, + "ProceduresCount": 0, + "Procedures": [], + "ProcStackSize": 56, + "DispatchFunction": 140707382121168, + "Service": null, + "IsServiceRunning": false + }, + "81ee95a8-882e-4615-888a-53344ca149e4": { + "Module": "vpnike.dll", + "ModulePath": "C:\\Windows\\System32\\vpnike.dll", + "InterfaceId": "81ee95a8-882e-4615-888a-53344ca149e4", + "InterfaceStructOffset": 480064, + "ProceduresCount": 18, + "Procedures": [ + "VpnikeCreateTunnel", + "VpnikeUpdateTunnel", + "VpnikeCloseTunnel", + "VpnikeGetCfgPayloadRequest", + "VpnikeProcessCfgPayloadReply", + "VpnikeProcessCfgPayloadRequest", + "VpnikeNewRasIncomingCall", + "VpnikeGetTsRequest", + "VpnikeProcessTsReply", + "VpnikeProcessTsRequest", + "VpnikeRemoveTs", + "VpnikeGetServerEapAuthRequestPacket", + "VpnikeProcessEapAuthPacket", + "VpnikeQueryEapAuthAttributes", + "VpnIkeProcessAdditionalAddressNotification", + "VpnikeCreateIDPayload", + "VpnikeTunnelAuthDone", + "VpnikeCreateOptionalIDrPayload" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707795823200, + "Service": null, + "IsServiceRunning": false + }, + "4c8d0bef-d7f1-49f0-9102-caa05f58d114": { + "Module": "nlasvc.dll", + "ModulePath": "C:\\Windows\\System32\\nlasvc.dll", + "InterfaceId": "4c8d0bef-d7f1-49f0-9102-caa05f58d114", + "InterfaceStructOffset": 294912, + "ProceduresCount": 1, + "Procedures": [ + "RPCQueryLANIds" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708037538960, + "Service": "NlaSvc", + "IsServiceRunning": true + }, + "b35534c5-a66e-473f-afa3-a4b21c02ea27": { + "Module": "WaaSMedicAgent.exe", + "ModulePath": "C:\\Windows\\System32\\WaaSMedicAgent.exe", + "InterfaceId": "b35534c5-a66e-473f-afa3-a4b21c02ea27", + "InterfaceStructOffset": 50080, + "ProceduresCount": 4, + "Procedures": [ + "PluginAction", + "LoadPluginLibrary", + "FreePluginLibrary", + "Shutdown" + ], + "ProcStackSize": 8, + "DispatchFunction": 140696469456784, + "Service": null, + "IsServiceRunning": false + }, + "178d84be-9291-4994-82c6-3f909aca5a03": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "178d84be-9291-4994-82c6-3f909aca5a03", + "InterfaceStructOffset": 562448, + "ProceduresCount": 5, + "Procedures": [ + "RmGameModeRSrvRegisterProcess", + "RmGameModeRSrvUnregisterProcess", + "RmGameModeRSrvDisableForRegisteredProcess", + "RmGameModeRSrvReenableForRegisteredProcess", + "RmGameModeRSrvRegisterPairedAuxiliaryProcess" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708133698688, + "Service": null, + "IsServiceRunning": false + }, + "5f54ce7d-5b79-4175-8584-cb65313a0e98": { + "Module": "appinfo.dll", + "ModulePath": "C:\\Windows\\System32\\appinfo.dll", + "InterfaceId": "5f54ce7d-5b79-4175-8584-cb65313a0e98", + "InterfaceStructOffset": 106784, + "ProceduresCount": 1, + "Procedures": [ + "RAiGetTokenForCOM" + ], + "ProcStackSize": 120, + "DispatchFunction": 140707486598080, + "Service": "Appinfo", + "IsServiceRunning": true + }, + "de2daf3b-5c16-4613-b204-d810ee629d9e": { + "Module": "wwansvc.dll", + "ModulePath": "C:\\Windows\\System32\\wwansvc.dll", + "InterfaceId": "de2daf3b-5c16-4613-b204-d810ee629d9e", + "InterfaceStructOffset": 1118336, + "ProceduresCount": 15, + "Procedures": [ + "RpcSetPowerState", + "RpcScanForAvailableOperators", + "RpcSaveRegistrationPreferences", + "RpcGet2GSupportSettings", + "RpcInform2GSettingsChanges", + "RpcSetCanPowerState", + "RpcSetLocationUpdateFilterOverride", + "RpcSetDataAffinityForSlot", + "RpcSetFriendlyName", + "RpcArdActivated", + "RpcSavePin", + "RpcGetMccFromSidNid", + "RpcSwitchToNextCDMANetwork", + "RpcUpdateIWLANPreferences", + "RpcSavePSMediaPreferences" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707093623584, + "Service": "WwanSvc", + "IsServiceRunning": false + }, + "aa411582-9bdf-48fb-b42b-faa1eee33949": { + "Module": "nlasvc.dll", + "ModulePath": "C:\\Windows\\System32\\nlasvc.dll", + "InterfaceId": "aa411582-9bdf-48fb-b42b-faa1eee33949", + "InterfaceStructOffset": 295104, + "ProceduresCount": 3, + "Procedures": [ + "PMuxRpcPluginRegister", + "PMuxRpcPluginUnregister", + "PMuxRpcPluginDataIndicate" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708037368176, + "Service": "NlaSvc", + "IsServiceRunning": true + }, + "2d24ff0b-1bab-404c-a0fd-42c85577bf68": { + "Module": "NgcCtnrSvc.dll", + "ModulePath": "C:\\Windows\\System32\\NgcCtnrSvc.dll", + "InterfaceId": "2d24ff0b-1bab-404c-a0fd-42c85577bf68", + "InterfaceStructOffset": 545296, + "ProceduresCount": 25, + "Procedures": [ + "s_NgcHandlerRpcAuthenticateGesture", + "s_NgcHandlerRpcDeauthenticate", + "s_NgcHandlerRpcChangePin", + "s_NgcHandlerRpcRecoverPin", + "s_NgcHandlerRpcAddBioProtector", + "s_NgcHandlerRpcRemoveBioProtector", + "s_NgcHandlerRpcAddPrebootProtector", + "s_NgcHandlerRpcRemovePrebootProtector", + "s_NgcHandlerRpcAddCompanionDeviceProtector", + "s_NgcHandlerRpcRemoveCompanionDeviceProtector", + "s_NgcHandlerRpcRsaSignWithPkcs1", + "s_NgcHandlerRpcRsaDecryptWithPkcs1", + "s_NgcHandlerRpcRsaCreateKey", + "s_NgcHandlerRpcRsaImportKey", + "s_NgcHandlerRpcExportKey", + "s_NgcHandlerRpcRsaExportPublicKey", + "s_NgcHandlerRpcRsaDeleteKey", + "s_NgcHandlerRpcEnumContainers", + "s_NgcHandlerRpcEnumKeys", + "s_NgcHandlerRpcSetKeyMetadata", + "s_NgcHandlerRpcGetKeyMetadata", + "s_NgcHandlerRpcSetContainerMetadata", + "s_NgcHandlerRpcGetContainerMetadata", + "s_NgcHandlerRpcGetKeyAikCertificate", + "s_NgcHandlerRpcCreateClaim" + ], + "ProcStackSize": 88, + "DispatchFunction": 140707093988480, + "Service": "NgcCtnrSvc", + "IsServiceRunning": false + }, + "c6b5235a-e413-481d-9ac8-31681b1faaf5": { + "Module": "SCardSvr.dll", + "ModulePath": "C:\\Windows\\System32\\SCardSvr.dll", + "InterfaceId": "c6b5235a-e413-481d-9ac8-31681b1faaf5", + "InterfaceStructOffset": 173456, + "ProceduresCount": 20, + "Procedures": [ + "s_RPC_SCardBeginTransaction", + "s_RPC_SCardCancel", + "s_RPC_SCardConnect", + "s_RPC_SCardControl", + "s_RPC_SCardDisconnect", + "s_RPC_SCardEndTransaction", + "s_RPC_SCardEstablishContext", + "s_RPC_SCardGetAttrib", + "s_RPC_SCardGetStatusChange", + "s_RPC_SCardGetTransmitCount", + "s_RPC_SCardIsValidContext", + "s_RPC_SCardListReaders", + "s_RPC_SCardLocateCards", + "s_RPC_SCardReconnect", + "s_RPC_SCardReleaseContext", + "s_RPC_SCardSetAttrib", + "s_RPC_SCardStatus", + "s_RPC_SCardTransmit", + "s_RPC_SCardGetReaderDeviceInstanceId", + "s_RPC_SCardGetDeviceTypeId" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707581067088, + "Service": "SCardSvr", + "IsServiceRunning": false + }, + "f26e2372-d601-44f0-84b8-2591d2af2f82": { + "Module": "PhoneService.dll", + "ModulePath": "C:\\Windows\\System32\\PhoneService.dll", + "InterfaceId": "f26e2372-d601-44f0-84b8-2591d2af2f82", + "InterfaceStructOffset": 787024, + "ProceduresCount": 36, + "Procedures": [ + "PhoneSvcImpl_PhoneRpcCallVoicemail", + "PhoneSvcImpl_PhoneRpcPublicDial", + "PhoneSvcImpl_PhoneRpcCallCapabilityAccessCheck", + "PhoneSvcImpl_PhoneRpcGetLinePublicInfo", + "PhoneSvcImpl_PhoneRpcGetLinePublicInfoExtended", + "PhoneSvcImpl_PhoneRpcGetLinePublicSettings", + "PhoneSvcImpl_PhoneRpcGetDefaultOutgoingLine", + "PhoneSvcImpl_PhoneRpcGetCallFilteringEnabled", + "PhoneSvcImpl_PhoneRpcIsEmergencyNumber", + "PhoneSvcImpl_PhoneRpcIsImmediateDialString", + "PhoneSvcImpl_PhoneRpcGetLines", + "PhoneSvcImpl_PhoneRpcAdvise", + "PhoneSvcImpl_PhoneRpcUnadvise", + "PhoneSvcImpl_PhoneRpcGetNotifyData", + "PhoneSvcImpl_PhoneRpcIsPhoneNumberInBlockList", + "PhoneSvcImpl_PhoneRpcGetActiveSpamFilterApp", + "PhoneSvcImpl_PhoneRpcSetBlockPrivateNumbersSetting", + "PhoneSvcImpl_PhoneRpcGetBlockPrivateNumbersSetting", + "PhoneSvcImpl_PhoneRpcSetBlockUnknownNumbersSetting", + "PhoneSvcImpl_PhoneRpcGetBlockUnknownNumbersSetting", + "PhoneSvcImpl_PhoneRpcSetFilterAppBlockList", + "PhoneSvcImpl_PhoneRpcSetCallOriginInfo", + "PhoneSvcImpl_PhoneRpcSetCallerAsActiveAppByType", + "PhoneSvcImpl_PhoneRpcGetActiveAppByType", + "PhoneSvcImpl_PhoneRpcGetDeviceSupportsVideoCalling", + "PhoneSvcImpl_PhoneRpcGetDeviceRealTimeTextEnabled", + "PhoneSvcImpl_PhoneRpcGetDeviceRealTimeTextAutomaticEnabled", + "PhoneSvcImpl_PhoneRpcGetRecordingApplications", + "PhoneSvcImpl_PhoneRpcSetRecordingApplication", + "PhoneSvcImpl_PhoneRpcGetVideoCapabilities", + "PhoneSvcImpl_PhoneRpcGetShouldMuteKeypad", + "PhoneSvcImpl_PhoneRpcIsVideoCallingEnabled", + "PhoneSvcImpl_PhoneRpcGetBluetoothHandsFreeLineInfo", + "PhoneSvcImpl_PhoneRpcAddLineCapabilities", + "PhoneSvcImpl_PhoneRpcRemoveLineCapabilities", + "PhoneSvcImpl_PhoneRpcIsCallOriginManagerSupported" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707094340384, + "Service": "PhoneSvc", + "IsServiceRunning": false + }, + "cb40a179-20e1-43f0-97fb-3c5c6ff37ec3": { + "Module": "rpcss.dll", + "ModulePath": "C:\\Windows\\System32\\rpcss.dll", + "InterfaceId": "cb40a179-20e1-43f0-97fb-3c5c6ff37ec3", + "InterfaceStructOffset": 978784, + "ProceduresCount": 6, + "Procedures": [ + "GetCrossContainerServerInfo", + "CreateCrossContainerOidSet", + "DeleteCrossContainerOidSet", + "CrossContainerActivation", + "CrossContainerResolveOxid", + "CrossContainerBulkUpdateOids" + ], + "ProcStackSize": 96, + "DispatchFunction": 140708135528576, + "Service": "RpcSs", + "IsServiceRunning": true + }, + "420bca2f-a0e8-45f4-a8ff-906745e8876c": { + "Module": "DeviceSetupManager.dll", + "ModulePath": "C:\\Windows\\System32\\DeviceSetupManager.dll", + "InterfaceId": "420bca2f-a0e8-45f4-a8ff-906745e8876c", + "InterfaceStructOffset": 167936, + "ProceduresCount": 3, + "Procedures": [ + "DsmRpcOpenDevice", + "DsmRpcCloseDevice", + "DsmRpcGetDeviceNotification" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707581087440, + "Service": "DsmSvc", + "IsServiceRunning": false + }, + "76f226c3-ec14-4325-8a99-6a46348418af": { + "Module": "wininit.exe", + "ModulePath": "C:\\Windows\\System32\\wininit.exe", + "InterfaceId": "76f226c3-ec14-4325-8a99-6a46348418af", + "InterfaceStructOffset": 296304, + "ProceduresCount": 5, + "Procedures": [ + "I_WMsgSendMessage", + "I_WMsgSendPSPMessage", + "I_WMsgSendNotifyMessage", + "I_WMsgSendReconnectionUpdateMessage", + "I_WMsgGetSwitchUserLogonInfo" + ], + "ProcStackSize": 48, + "DispatchFunction": 140699626706192, + "Service": null, + "IsServiceRunning": false + }, + "06bba54a-be05-49f9-b0a0-30f790261023": { + "Module": "wscsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wscsvc.dll", + "InterfaceId": "06bba54a-be05-49f9-b0a0-30f790261023", + "InterfaceStructOffset": 233904, + "ProceduresCount": 28, + "Procedures": [ + "DrawTextExW", + "s_wscRegisterChangeNotification", + "s_wscUnRegisterChangeNotification", + "s_wscGetAlertStatus", + "s_wscAntiVirusExpiredBeyondThreshold", + "s_wscAntiVirusExpiredBeyondThreshold", + "s_wscAntiVirusExpiredBeyondThreshold", + "s_wscFirewallGetStatus", + "s_wscIcfEnable", + "s_wscAntiVirusGetStatus", + "s_wscAntiSpywareGetStatus", + "s_wscGeneralSecurityGetStatus", + "s_wscLuaSettingsFix", + "s_wscRegisterSecurityProduct", + "s_wscUnregisterSecurityProduct", + "s_wscUpdateProductStatus", + "s_wscAntiVirusExpiredBeyondThreshold", + "s_wscIsDefenderAntivirusSupported", + "s_wscUserNotificationRequired", + "s_wscInitiateOfflineCleaning", + "s_wscAbortOfflineCleaning", + "s_wscNotifyUserForNearExpiration", + "s_wscAntiVirusGetUpgradableProducts", + "s_wscAntiVirusRemoveUpgradableProduct", + "s_wscAntiVirusGetRemovedButNotUpgradableProducts", + "s_wscMakeDefaultProductRequest", + "s_wscSetDefaultProduct", + "s_wscUpdateProductSubStatus" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707589576992, + "Service": "wscsvc", + "IsServiceRunning": true + }, + "c521facf-09a9-42c5-b155-72388595cbf0": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "c521facf-09a9-42c5-b155-72388595cbf0", + "InterfaceStructOffset": 558144, + "ProceduresCount": 8, + "Procedures": [ + "RmtSrv_RM_ConnectToServer", + "RmtSrv_RM_DisconnectFromServer", + "RmtSrv_RM_AcquireResourceSet", + "RmtSrv_RS_Apply", + "RmtSrv_RS_ReleaseResources", + "OnAccessLost", + "RmtSrv_RS_SetExternalResourcePriorities", + "OnAccessLost" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708133530576, + "Service": null, + "IsServiceRunning": false + }, + "ae2dc901-312d-41df-8b79-e835e63db874": { + "Module": "AppXDeploymentServer.dll", + "ModulePath": "C:\\Windows\\System32\\AppXDeploymentServer.dll", + "InterfaceId": "ae2dc901-312d-41df-8b79-e835e63db874", + "InterfaceStructOffset": 2609472, + "ProceduresCount": 63, + "Procedures": [ + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "MergeSystemResourceFilesImplementation", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "MergeSystemResourceFilesImplementation", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder" + ], + "ProcStackSize": 16, + "DispatchFunction": 140706734141664, + "Service": "AppXSvc", + "IsServiceRunning": false + }, + "c0d930f0-b787-4124-99bc-21f0ecb642ce": { + "Module": "lsasrv.dll", + "ModulePath": "C:\\Windows\\System32\\lsasrv.dll", + "InterfaceId": "c0d930f0-b787-4124-99bc-21f0ecb642ce", + "InterfaceStructOffset": 1269856, + "ProceduresCount": 7, + "Procedures": [ + "LsarConnectLocalUser", + "LsarDisconnectLocalUser", + "LsarCreateConnectedUser", + "LsarIsCurrentUserConnected", + "LsarRenewCertificate", + "LsarGetSSOAccountType", + "LsarIsUserMSA" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708154214960, + "Service": null, + "IsServiceRunning": false + }, + "e00c29a5-0f62-4d84-b7f0-d2387e41ed18": { + "Module": "tetheringservice.dll", + "ModulePath": "C:\\Windows\\System32\\tetheringservice.dll", + "InterfaceId": "e00c29a5-0f62-4d84-b7f0-d2387e41ed18", + "InterfaceStructOffset": 179792, + "ProceduresCount": 16, + "Procedures": [ + "TetheringSvcGetSharingState", + "TetheringSvcGetDefaultInterface", + "TetheringSvcStartSharing", + "TetheringSvcStopSharing", + "TetheringSvcGetLastApiError", + "TetheringSvcGetConfiguration", + "TetheringSvcSetConfiguration", + "TetheringSvcGetPeerList", + "TetheringSvcGetSharedInterfaceIndices", + "TetheringSvcGetMaxClientCount", + "TetheringSvcAuthorize", + "TetheringSvcGetErrorString", + "TetheringSvcRpcSetPreferredInterface", + "TetheringSvcRpcGetPreferredInterface", + "TetheringSvcGetIsPeerlessTimeoutEnabled", + "TetheringSvcSetIsPeerlessTimeoutEnabled" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707581026592, + "Service": "icssvc", + "IsServiceRunning": false + }, + "6c323e3f-585f-4432-8a2e-0719fb35e48b": { + "Module": "SenseCE.exe", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_windows-senseclient-service_31bf3856ad364e35_10.0.18362.1916_none_b57d3553f248f034\\SenseCE.exe", + "InterfaceId": "6c323e3f-585f-4432-8a2e-0719fb35e48b", + "InterfaceStructOffset": 269328, + "ProceduresCount": 7, + "Procedures": [ + "Init", + "ParseFile", + "ClassifyFile", + "OpenArchiveFile", + "GetNextDlpFileName", + "DumpNextDlpFile", + "GetArchiveFileData" + ], + "ProcStackSize": 32, + "DispatchFunction": 140701284818768, + "Service": null, + "IsServiceRunning": false + }, + "fdb3a030-065f-11d1-bb9b-00a024ea5525": { + "Module": "mqqm.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-msmq-queuemanager-core_31bf3856ad364e35_10.0.18362.1977_none_8d1646dec2a87b94\\mqqm.dll", + "InterfaceId": "fdb3a030-065f-11d1-bb9b-00a024ea5525", + "InterfaceStructOffset": 1012048, + "ProceduresCount": 35, + "Procedures": [ + "qmcomm_v1_0_S_QMOpenQueue", + "qmcomm_v1_0_S_QMGetRemoteQueueName", + "qmcomm_v1_0_S_QMOpenRemoteQueue", + "qmcomm_v1_0_S_QMCloseRemoteQueueContext", + "qmcomm_v1_0_S_QMCreateRemoteCursor", + "qmcomm_v1_0_S_QMSendMessageInternal", + "qmcomm_v1_0_S_QMCreateObjectInternal", + "qmcomm_v1_0_S_QMSetObjectSecurityInternal", + "qmcomm_v1_0_S_QMGetObjectSecurityInternal", + "qmcomm_v1_0_S_QMDeleteObject", + "qmcomm_v1_0_S_QMGetObjectProperties", + "qmcomm_v1_0_S_QMSetObjectProperties", + "qmcomm_v1_0_S_QMObjectPathToObjectFormat", + "qmcomm_v1_0_S_QMAttachProcess", + "qmcomm_v1_0_S_QMGetTmWhereabouts", + "qmcomm_v1_0_S_QMEnlistTransaction", + "qmcomm_v1_0_S_QMEnlistInternalTransaction", + "qmcomm_v1_0_S_QMCommitTransaction", + "qmcomm_v1_0_S_QMAbortTransaction", + "qmcomm_v1_0_S_rpc_QMOpenQueueInternal", + "qmcomm_v1_0_S_rpc_ACCloseHandle", + "qmcomm_v1_0_S_rpc_ACCreateCursor", + "qmcomm_v1_0_S_rpc_ACCloseCursor", + "qmcomm_v1_0_S_rpc_ACSetCursorProperties", + "qmcomm_v1_0_S_rpc_ACSendMessage", + "qmcomm_v1_0_S_rpc_ACReceiveMessage", + "qmcomm_v1_0_S_rpc_ACHandleToFormatName", + "qmcomm_v1_0_S_rpc_ACPurgeQueue", + "qmcomm_v1_0_S_QMQueryQMRegistryInternal", + "qmcomm_v1_0_S_QMListInternalQueues", + "qmcomm_v1_0_S_QMCorrectOutSequence", + "qm2qm_v1_0_R_QMGetRemoteQMServerPort", + "qmcomm_v1_0_S_QMGetMsmqServiceName", + "qmcomm_v1_0_S_QMCreateDSObjectInternal", + "qmcomm_v1_0_S_QMEnlistTransactionEx" + ], + "ProcStackSize": 64, + "DispatchFunction": 140707093285248, + "Service": null, + "IsServiceRunning": false + }, + "3919286a-b10c-11d0-9ba8-00c04fd92ef5": { + "Module": "lsasrv.dll", + "ModulePath": "C:\\Windows\\System32\\lsasrv.dll", + "InterfaceId": "3919286a-b10c-11d0-9ba8-00c04fd92ef5", + "InterfaceStructOffset": 1269760, + "ProceduresCount": 1, + "Procedures": [ + "DsRolerGetPrimaryDomainInformation" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708153128080, + "Service": null, + "IsServiceRunning": false + }, + "1088a980-eae5-11d0-8d9b-00a02453c337": { + "Module": "mqqm.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-msmq-queuemanager-core_31bf3856ad364e35_10.0.18362.1977_none_8d1646dec2a87b94\\mqqm.dll", + "InterfaceId": "1088a980-eae5-11d0-8d9b-00a02453c337", + "InterfaceStructOffset": 979840, + "ProceduresCount": 11, + "Procedures": [ + "qm2qm_v1_0_R_QMRemoteStartReceive", + "qm2qm_v1_0_R_QMRemoteEndReceive", + "qm2qm_v1_0_R_QMRemoteOpenQueue", + "qm2qm_v1_0_R_QMRemoteCloseQueue", + "qm2qm_v1_0_R_QMRemoteCloseCursor", + "qm2qm_v1_0_R_QMRemoteCancelReceive", + "qm2qm_v1_0_R_QMRemotePurgeQueue", + "qm2qm_v1_0_R_QMGetRemoteQMServerPort", + "qm2qm_v1_0_R_QMRemoteGetVersion", + "qm2qm_v1_0_R_QMRemoteStartReceive2", + "qm2qm_v1_0_R_QMRemoteStartReceiveByLookupId" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707093325904, + "Service": null, + "IsServiceRunning": false + }, + "7df1ceae-de4e-4e6f-ab14-49636e7c2052": { + "Module": "diagtrack.dll", + "ModulePath": "C:\\Windows\\System32\\diagtrack.dll", + "InterfaceId": "7df1ceae-de4e-4e6f-ab14-49636e7c2052", + "InterfaceStructOffset": 2764704, + "ProceduresCount": 1, + "Procedures": [ + "UtcInternalApi_SendAggregatorEvents" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707991506176, + "Service": "DiagTrack", + "IsServiceRunning": true + }, + "326731e3-c1c0-4a69-ae20-7d9044a4ea5c": { + "Module": "profsvc.dll", + "ModulePath": "C:\\Windows\\System32\\profsvc.dll", + "InterfaceId": "326731e3-c1c0-4a69-ae20-7d9044a4ea5c", + "InterfaceStructOffset": 307808, + "ProceduresCount": 8, + "Procedures": [ + "DropClientContext", + "ReleaseClientContext", + "LoadUserProfileServer", + "UnloadUserProfileServer", + "DeleteProfileServer", + "RemapProfileServer", + "CreateProfileServer", + "ProcessWmiSettingsServer" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708064859888, + "Service": "ProfSvc", + "IsServiceRunning": true + }, + "e8748f69-a2a4-40df-9366-62dbeb696e26": { + "Module": "Unistore.dll", + "ModulePath": "C:\\Windows\\System32\\Unistore.dll", + "InterfaceId": "e8748f69-a2a4-40df-9366-62dbeb696e26", + "InterfaceStructOffset": 812192, + "ProceduresCount": 212, + "Procedures": [ + "USSvcImpl_Object_Close", + "USSvcImpl_RegisterRundownProtection", + "USSvcImpl_ConvertToOtherObject", + "USSvcImpl_Manager_Create", + "USSvcImpl_Manager_CreateStoreGrouping", + "USSvcImpl_Manager_CreateStore", + "USSvcImpl_Manager_GetDeviceStore", + "USSvcImpl_Manager_GetDeviceStoreOid", + "USSvcImpl_Manager_GetHighestStoreBitPosition", + "USSvcImpl_Manager_GetStore", + "USSvcImpl_Manager_GetStoreCollection", + "USSvcImpl_Manager_Notify", + "USSvcImpl_Manager_CustomNotify", + "USSvcImpl_Manager_GetObjectByOid", + "USSvcImpl_Manager_GetAllEmbeddedObjects", + "USSvcImpl_Manager_GetAllItems", + "USSvcImpl_Manager_GetTypeManager", + "USSvcImpl_Manager_StartTransaction", + "USSvcImpl_Manager_EndTransaction", + "USSvcImpl_Manager_CleanupTombstones", + "USSvcImpl_Manager_GetStreamFilePath", + "USSvcImpl_Manager_CleanupTemporaryFolders", + "USSvcImpl_Manager_GetAllAggregateObjects", + "USSvcImpl_Manager_GetAllObjects", + "USSvcImpl_Manager_GetBatchedPropValsFromIdsBlob", + "USSvcImpl_Manager_GetPropValsFromIdBlob", + "USSvcImpl_Manager_MapNamedProps", + "USSvcImpl_Manager_GetDefaultPIMStoreId", + "USSvcImpl_Manager_SetDefaultPIMStoreId", + "USSvcImpl_Manager_GetUnistoreDatabaseRefreshTime", + "USSvcImpl_ManagerPriv_put_DeviceStoreId", + "USSvcImpl_ManagerPriv_GetNotificationsManager", + "USSvcImpl_ManagerPriv_UnmapNamedProps", + "USSvcImpl_ManagerPriv_GetPerfStats", + "USSvcImpl_ManagerPriv_ResetPerfStats", + "USSvcImpl_ManagerPriv_ToggleRecordingPerfStats", + "USSvcImpl_ManagerPriv_BackupStoreVolume", + "USSvcImpl_ManagerPriv_SetToSuspending", + "USSvcImpl_ManagerPriv_SetToResumed", + "USSvcImpl_NotificationManager_Advise", + "USSvcImpl_NotificationManager_Unadvise", + "USSvcImpl_NotificationManager_Notify", + "USSvcImpl_NotificationManager_SuspendNotifications", + "USSvcImpl_NotificationManager_ResumeNotifications", + "USSvcImpl_NotificationManager_FilterProcessEventsForTests", + "USSvcImpl_NotificationManager_GetAdviseContent", + "USSvcImpl_Object_GetOid", + "USSvcImpl_Object_Delete", + "USSvcImpl_Object_GetPropValsBlob", + "USSvcImpl_Object_GetAllPropValsBlob", + "USSvcImpl_Object_SetPropVals", + "USSvcImpl_Object_SetPropValsEx", + "USSvcImpl_Object_SetStreamProperty", + "USSvcImpl_Object_GetStreamProp", + "USSvcImpl_Object_GetStore", + "USSvcImpl_Object_GetStreamFilePath", + "USSvcImpl_Object_GetAssociatedItems", + "USSvcImpl_Object_CreateEmbeddedObject", + "USSvcImpl_Object_DeleteEmbeddedObjects", + "USSvcImpl_Object_GetEmbeddedObjects", + "USSvcImpl_Object_IncrementRevision", + "USSvcImpl_Store_GetRootFolder", + "USSvcImpl_Store_GetObjectByOid", + "USSvcImpl_Store_CreateAssociateObject", + "USSvcImpl_Store_GetAssociateObjects", + "USSvcImpl_Store_GetEmbeddedObjects", + "USSvcImpl_Store_GetTypeManager", + "USSvcImpl_Store_Flush", + "USSvcImpl_Store_AddSyncPartner", + "USSvcImpl_Store_GetSyncPartner", + "USSvcImpl_Store_GetSyncPartners", + "USSvcImpl_Store_StartFetchSession", + "USSvcImpl_Store_EndFetchSession", + "USSvcImpl_Store_ThreadInFetchSession", + "USSvcImpl_Store_CreateAggregateObject", + "USSvcImpl_Store_GetAggregateObjects", + "USSvcImpl_Store_GetDeletedRevisionItems", + "USSvcImpl_Store_GetLongDeletedRevisionItems", + "USSvcImpl_Store_ResetLongRevisionChangeTracking", + "USSvcImpl_Store_UpdateLongRevisionChangeTracking", + "USSvcImpl_Store_GetLongRevision", + "USSvcImpl_Store_IsObjectRevisionTracked", + "USSvcImpl_Store_GetFolders", + "USSvcImpl_Store_GetStoreGrouping", + "USSvcImpl_Folder_CreateFolder", + "USSvcImpl_Folder_CreateItem", + "USSvcImpl_Folder_DeleteItems", + "USSvcImpl_Folder_GetChildFolders", + "USSvcImpl_Folder_GetItems", + "USSvcImpl_Folder_GetAllItems", + "USSvcImpl_Folder_GetParent", + "USSvcImpl_Folder_IsEmpty", + "USSvcImpl_Folder_CopyToFolder", + "USSvcImpl_Folder_MoveToFolder", + "USSvcImpl_Item_DeleteWithFlags", + "USSvcImpl_Item_GetParent", + "USSvcImpl_Item_CopyToFolder", + "USSvcImpl_Item_MoveToFolder", + "USSvcImpl_Item_AssociateObject", + "USSvcImpl_Item_DeleteAssociations", + "USSvcImpl_Item_DeleteAllAssociations", + "USSvcImpl_Item_GetAssociateObjects", + "USSvcImpl_Item_GetAggregateObject", + "USSvcImpl_Item_AggregateObject", + "USSvcImpl_Item_DeleteAggregation", + "USSvcImpl_EmbeddeObject_GetItem", + "USSvcImpl_EmbeddedObject_GetObject", + "USSvcImpl_AssociatedObject_HasItems", + "USSvcImpl_AggregateObject_GetAggregatedObjects", + "USSvcImpl_ObjectCollection_GetCount", + "USSvcImpl_ObjectCollection_GetCurrentIndex", + "USSvcImpl_ObjectCollection_GetObject", + "USSvcImpl_ObjectCollection_GetPropValsBlob", + "USSvcImpl_ObjectCollection_GetBatchedPropValsBlob", + "USSvcImpl_ObjectCollection_SetPropValsOnAll", + "USSvcImpl_ObjectCollection_GetAllPropValsBlob", + "USSvcImpl_ObjectCollection_Oid", + "USSvcImpl_ObjectCollection_GetBookmark", + "USSvcImpl_ObjectCollection_Move", + "USSvcImpl_ObjectCollection_DeleteAllObjects", + "USSvcImpl_SyncPartnerEnum_Next", + "USSvcImpl_SyncPartnerEnum_Skip", + "USSvcImpl_SyncPartnerEnum_Reset", + "USSvcImpl_SyncPartnerEnum_Clone", + "USSvcImpl_TypeManager_MapNamedProps", + "USSvcImpl_TypeManager_GetSchemaPropertiesFromObjectType", + "USSvcImpl_Stream_Seek", + "USSvcImpl_Stream_SetSize", + "USSvcImpl_Stream_Commit", + "USSvcImpl_Stream_Revert", + "USSvcImpl_Stream_LockRegion", + "USSvcImpl_Stream_UnlockRegion", + "USSvcImpl_Stream_Stat", + "USSvcImpl_Stream_Clone", + "USSvcImpl_Stream_Read", + "USSvcImpl_Stream_Write", + "USSvcImpl_SyncPartner_GetPropsBlob", + "USSvcImpl_SyncPartner_SetProps", + "USSvcImpl_SyncPartner_GetName", + "USSvcImpl_SyncPartner_GetGuid", + "USSvcImpl_SyncPartner_GetStoreId", + "USSvcImpl_SyncPartner_GetPartnerId", + "USSvcImpl_SyncPartner_EnableFolderForSync", + "USSvcImpl_SyncPartner_IsFolderEnabledForSync", + "USSvcImpl_SyncPartner_HasChanges", + "USSvcImpl_SyncPartner_GetChangeCount", + "USSvcImpl_SyncPartner_StartSyncSession", + "USSvcImpl_SyncPartner_StartSyncSessionNoContext", + "USSvcImpl_SyncPartner_GetNextChange", + "USSvcImpl_SyncPartner_GetChangeForObject", + "USSvcImpl_SyncPartner_SetExceptionOnChange", + "USSvcImpl_SyncPartner_SetExceptionOnChangeUnits", + "USSvcImpl_SyncPartner_ResetChangeEnumeration", + "USSvcImpl_SyncPartner_EndSyncSession", + "USSvcImpl_SyncPartner_GetRootFolder", + "USSvcImpl_SyncPartner_LookupFolderObjectId", + "USSvcImpl_SyncPartner_LookupFolderRemoteId", + "USSvcImpl_SyncPartner_GetFolders", + "USSvcImpl_SyncPartner_LookupItemObjectId", + "USSvcImpl_SyncPartner_UpdateSyncPartnerSchema", + "USSvcImpl_SyncPartner_Delete", + "USSvcImpl_SyncPartner_SetMeetingResponse", + "USSvcImpl_SyncPartner_GetAllMeetingResponses", + "USSvcImpl_SyncPartner_DefragmentKnowledge", + "USSvcImpl_ObjectMetadata_GetPropsBlob", + "USSvcImpl_ObjectMetadata_SetProps", + "USSvcImpl_ObjectMetadata_GetObjectId", + "USSvcImpl_ObjectMetadata_GetPartner", + "USSvcImpl_ObjectMetadata_GetRemoteId", + "USSvcImpl_ObjectMetadata_SetRemoteId", + "USSvcImpl_ObjectMetadata_GetParent", + "USSvcImpl_ObjectMetadata_SetParent", + "USSvcImpl_ItemMetadata_Move", + "USSvcImpl_ItemMetadata_SetMeetingResponse", + "USSvcImpl_ItemMetadata_GetMeetingResponses", + "USSvcImpl_ItemMetadata_Delete", + "USSvcImpl_FolderMetadata_GetFolderName", + "USSvcImpl_FolderMetadata_GetFolderType", + "USSvcImpl_FolderMetadata_GetRemoteKnowledge", + "USSvcImpl_FolderMetadata_SetRemoteKnowledge", + "USSvcImpl_FolderMetadata_AddItem", + "USSvcImpl_FolderMetadata_LookupItemObjectId", + "USSvcImpl_FolderMetadata_LookupItemRemoteId", + "USSvcImpl_FolderMetadata_GetItems", + "USSvcImpl_FolderMetadata_AddFolder", + "USSvcImpl_FolderMetadata_LookupFolderObjectId", + "USSvcImpl_FolderMetadata_LookupFolderRemoteId", + "USSvcImpl_FolderMetadata_GetChildFolders", + "USSvcImpl_FolderMetadata_Delete", + "USSvcImpl_FolderMetadata_DeleteInBatches", + "USSvcImpl_MeetingResponse_GetResponseId", + "USSvcImpl_MeetingResponse_GetMeetingMetadata", + "USSvcImpl_MeetingResponse_GetMeetingPermanentId", + "USSvcImpl_MeetingResponse_GetMeetingInstanceId", + "USSvcImpl_MeetingResponse_GetResponseType", + "USSvcImpl_MeetingResponse_GetMeetingUserComments", + "USSvcImpl_MeetingResponse_GetPlaceholderMeetingObjectId", + "USSvcImpl_MeetingResponse_GetPropsBlob", + "USSvcImpl_MeetingResponse_SetProps", + "USSvcImpl_MeetingResponse_Delete", + "USSvcImpl_ItemMetadataEnum_Next", + "USSvcImpl_ItemMetadataEnum_Skip", + "USSvcImpl_ItemMetadataEnum_Reset", + "USSvcImpl_ItemMetadataEnum_Clone", + "USSvcImpl_FolderMetadataEnum_Next", + "USSvcImpl_FolderMetadataEnum_Skip", + "USSvcImpl_FolderMetadataEnum_Reset", + "USSvcImpl_FolderMetadataEnum_Clone", + "USSvcImpl_EnumMeetingResponses_Next", + "USSvcImpl_EnumMeetingResponses_Skip", + "USSvcImpl_EnumMeetingResponses_Reset", + "USSvcImpl_EnumMeetingResponses_Clone" + ], + "ProcStackSize": 32, + "DispatchFunction": 140706535998720, + "Service": "UnistoreSvc", + "IsServiceRunning": false + }, + "05ebb278-e114-4ec1-a5a3-096153f300e4": { + "Module": "tsgqec.dll", + "ModulePath": "C:\\Windows\\System32\\tsgqec.dll", + "InterfaceId": "05ebb278-e114-4ec1-a5a3-096153f300e4", + "InterfaceStructOffset": 46096, + "ProceduresCount": 5, + "Procedures": [ + "TsgQecCreateNapConnection", + "TsgQecNapConnectionGetNapChangeNotify", + "TsgQecNapConnectionGetSoHRequest", + "TsgQecNapConnectionProcessSoHResponse", + "TsgQecNapConnectionTerminate" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707880905584, + "Service": null, + "IsServiceRunning": false + }, + "894de0c0-0d55-11d3-a322-00c04fa321a1": { + "Module": "wininit.exe", + "ModulePath": "C:\\Windows\\System32\\wininit.exe", + "InterfaceId": "894de0c0-0d55-11d3-a322-00c04fa321a1", + "InterfaceStructOffset": 294368, + "ProceduresCount": 3, + "Procedures": [ + "s_BaseInitiateShutdown", + "s_BaseAbortShutdown", + "s_BaseInitiateShutdownEx" + ], + "ProcStackSize": 56, + "DispatchFunction": 140699626688608, + "Service": null, + "IsServiceRunning": false + }, + "9fa6aff6-e0ad-48df-a6b4-e64be66a17a1": { + "Module": "WFDSConMgrSvc.dll", + "ModulePath": "C:\\Windows\\System32\\WFDSConMgrSvc.dll", + "InterfaceId": "9fa6aff6-e0ad-48df-a6b4-e64be66a17a1", + "InterfaceStructOffset": 524320, + "ProceduresCount": 17, + "Procedures": [ + "WFDSConMgrOpenSessionContextRPC", + "WFDSConMgrOpenSessionContextForMacAddressRPC", + "WFDSConMgrOpenSessionContextForNotificationRPC", + "WFDSConMgrCloseSessionContextRPC", + "WFDSConMgrGetOpenSessionListRPC", + "WFDSConMgrConnectRPC", + "WFDSConMgrWriteCeremonyDataRPC", + "WFDSConMgrReadCeremonyDataRPC", + "WFDSConMgrConnectTransportRPC", + "WFDSConMgrSetAllowRemoteInputRPC", + "WFDSConMgrQueryStatusRPC", + "WFDSConMgrQueryCorrelationIdRPC", + "WFDSConMgrDisconnectRPC", + "WFDSConMgrDisconnectTransportRPC", + "WFDSConMgrAsyncGetNotificationRPC", + "WFDSConMgrIntCompleteInfracastConnectionRPC", + "WFDSConMgrIntGetInfracastBackchannelParamsRPC" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707487041664, + "Service": "WFDSConMgrSvc", + "IsServiceRunning": false + }, + "5b665b9a-a086-4e26-ae24-96ab050b0ec3": { + "Module": "das.dll", + "ModulePath": "C:\\Windows\\System32\\das.dll", + "InterfaceId": "5b665b9a-a086-4e26-ae24-96ab050b0ec3", + "InterfaceStructOffset": 368640, + "ProceduresCount": 3, + "Procedures": [ + "DasCreateAepStoreAep", + "DasDeleteAepStoreAep", + "DasSetAepStoreAepProperties" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707580862288, + "Service": "DeviceAssociationService", + "IsServiceRunning": false + }, + "f44e62af-dab1-44c2-8013-049a9de417d6": { + "Module": "wcmsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wcmsvc.dll", + "InterfaceId": "f44e62af-dab1-44c2-8013-049a9de417d6", + "InterfaceStructOffset": 768368, + "ProceduresCount": 2, + "Procedures": [ + "RpcUpdateCapabilityAccess", + "RpcDeprovisionCapability" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708018992432, + "Service": "Wcmsvc", + "IsServiceRunning": true + }, + "76d12b80-3467-11d3-91ff-0090272f9ea3": { + "Module": "mqqm.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-msmq-queuemanager-core_31bf3856ad364e35_10.0.18362.1977_none_8d1646dec2a87b94\\mqqm.dll", + "InterfaceId": "76d12b80-3467-11d3-91ff-0090272f9ea3", + "InterfaceStructOffset": 1017936, + "ProceduresCount": 4, + "Procedures": [ + "qmcomm2_v1_0_S_QMSendMessageInternalEx", + "qmcomm2_v1_0_S_rpc_ACSendMessageEx", + "qmcomm2_v1_0_S_rpc_ACReceiveMessageEx", + "qmcomm2_v1_0_S_rpc_ACCreateCursorEx" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707093191616, + "Service": null, + "IsServiceRunning": false + }, + "d95afe70-a6d5-4259-822e-2c84da1ddb0d": { + "Module": "wininit.exe", + "ModulePath": "C:\\Windows\\System32\\wininit.exe", + "InterfaceId": "d95afe70-a6d5-4259-822e-2c84da1ddb0d", + "InterfaceStructOffset": 295072, + "ProceduresCount": 3, + "Procedures": [ + "s_WsdrInitiateShutdown", + "s_WsdrAbortShutdown", + "s_WsdrCheckForHiberboot" + ], + "ProcStackSize": 40, + "DispatchFunction": 140699626515200, + "Service": null, + "IsServiceRunning": false + }, + "12345678-1234-abcd-ef00-01234567cffb": { + "Module": "netlogon.dll", + "ModulePath": "C:\\Windows\\System32\\netlogon.dll", + "InterfaceId": "12345678-1234-abcd-ef00-01234567cffb", + "InterfaceStructOffset": 479232, + "ProceduresCount": 59, + "Procedures": [ + "NetrLogonUasLogon", + "NetrLogonUasLogoff", + "NetrLogonSamLogon", + "NetrLogonSamLogoff", + "NetrServerReqChallenge", + "NetrServerAuthenticate", + "NetrServerPasswordSet", + "NetrDatabaseDeltas", + "NetrDatabaseSync", + "NetrAccountDeltas", + "NetrAccountSync", + "NetrGetDCName", + "NetrLogonControl", + "NetrGetAnyDCName", + "NetrLogonControl2", + "NetrServerAuthenticate2", + "NetrDatabaseSync2", + "NetrDatabaseRedo", + "NetrLogonControl2Ex", + "NetrEnumerateTrustedDomains", + "DsrGetDcName", + "NetrLogonGetCapabilities", + "NetrLogonSetServiceBits", + "NetrLogonGetTrustRid", + "NetrLogonComputeServerDigest", + "NetrLogonComputeClientDigest", + "NetrServerAuthenticate3", + "DsrGetDcNameEx", + "DsrGetSiteName", + "NetrLogonGetDomainInfo", + "NetrServerPasswordSet2", + "NetrServerPasswordGet", + "NetrLogonSendToSam", + "DsrAddressToSiteNamesW", + "DsrGetDcNameEx2", + "NetrLogonGetTimeServiceParentDomain", + "NetrEnumerateTrustedDomainsEx", + "DsrAddressToSiteNamesExW", + "DsrGetDcSiteCoverageW", + "NetrLogonSamLogonEx", + "DsrEnumerateDomainTrusts", + "DsrDeregisterDnsHostRecords", + "NetrServerTrustPasswordsGet", + "DsrGetForestTrustInformation", + "NetrGetForestTrustInformation", + "NetrLogonSamLogonWithFlags", + "NetrServerGetTrustInfo", + "NetrCollectPerfData", + "DsrUpdateReadOnlyServerDnsRecords", + "NetrChainSetClientAttributes", + "NetrAddServiceAccount", + "NetrRemoveServiceAccount", + "NetrEnumerateServiceAccounts", + "NetrQueryServiceAccount", + "NetrChainSetClientAttributes2", + "NetrLogonComputeClientSignature", + "NetrLogonComputeServerSignature", + "NetrExtendMachinePasswordExpirationTimeout", + "NetrQuerySecureChannelDCInfo" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708147754544, + "Service": "Netlogon", + "IsServiceRunning": false + }, + "048cf666-ab42-42b4-8975-1357018decb3": { + "Module": "ws2_32.dll", + "ModulePath": "C:\\Windows\\System32\\ws2_32.dll", + "InterfaceId": "048cf666-ab42-42b4-8975-1357018decb3", + "InterfaceStructOffset": 295024, + "ProceduresCount": 6, + "Procedures": [ + "RPCNSPv2Startup", + "RPCNSPv2Cleanup", + "RPCNSPv2LookupServiceBegin", + "RPCNSPv2LookupServiceNextEx", + "RPCNSPv2LookupServiceEnd", + "RPCNSPv2SetServiceEx" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708205991280, + "Service": null, + "IsServiceRunning": false + }, + "c6f3ee72-ce7e-11d1-b71e-00c04fc3111a": { + "Module": "rpcss.dll", + "ModulePath": "C:\\Windows\\System32\\rpcss.dll", + "InterfaceId": "c6f3ee72-ce7e-11d1-b71e-00c04fc3111a", + "InterfaceStructOffset": 959600, + "ProceduresCount": 7, + "Procedures": [ + "ProcessActivatorStarted", + "ProcessActivatorInitializing", + "ProcessActivatorReady", + "ProcessActivatorStopped", + "ProcessActivatorPaused", + "ProcessActivatorResumed", + "ProcessActivatorUserInitializing" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708135488704, + "Service": "RpcSs", + "IsServiceRunning": true + }, + "647d4452-9f33-4a18-b2be-c5c0e920e94e": { + "Module": "pla.dll", + "ModulePath": "C:\\Windows\\System32\\pla.dll", + "InterfaceId": "647d4452-9f33-4a18-b2be-c5c0e920e94e", + "InterfaceStructOffset": 1261888, + "ProceduresCount": 7, + "Procedures": [ + "PlaiSrvControl", + "PlaiSrvQuerySession", + "PlaiSrvGetStatus", + "PlaiSrvRegisterCollectorSet", + "PlaiSrvUpdateMetadata", + "PlaiSrvSwitchToCompiling", + "PlaiSrvCloseCollectorSet" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707093898272, + "Service": "pla", + "IsServiceRunning": false + }, + "c6fce9d4-0b0e-49aa-a7ba-a6b217b52d16": { + "Module": "gns.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-guest-network-service_31bf3856ad364e35_10.0.18362.1714_none_7b03a8936de4e29d\\gns.dll", + "InterfaceId": "c6fce9d4-0b0e-49aa-a7ba-a6b217b52d16", + "InterfaceStructOffset": 338752, + "ProceduresCount": 13, + "Procedures": [ + "Request", + "GnsRpc_EnumerateEndpoints", + "GnsRpc_CreateEndpoint", + "GnsRpc_OpenEndpoint", + "GnsRpc_ModifyEndpoint", + "GnsRpc_DeleteEndpoint", + "GnsRpc_CloseEndpoint", + "GnsRpc_EnumerateNamespaces", + "GnsRpc_CreateNamespace", + "GnsRpc_OpenNamespace", + "GnsRpc_ModifyNamespace", + "GnsRpc_DeleteNamespace", + "GnsRpc_CloseNamespace" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707880336864, + "Service": null, + "IsServiceRunning": false + }, + "e6f89680-fc98-11e3-80d4-10604b681cfa": { + "Module": "NgcCtnrGidsHandler.dll", + "ModulePath": "C:\\Windows\\System32\\NgcCtnrGidsHandler.dll", + "InterfaceId": "e6f89680-fc98-11e3-80d4-10604b681cfa", + "InterfaceStructOffset": 369680, + "ProceduresCount": 7, + "Procedures": [ + "ProcessAfterContainerCreation", + "s_GidsHandlerRpcAcquireChannel", + "s_GidsHandlerRpcReleaseChannel", + "s_GidsHandlerRpcGetAttribute", + "s_GidsHandlerRpcGetAttribute", + "s_GidsHandlerRpcGetAttribute", + "s_GidsHandlerRpcSendReceiveData" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707580798048, + "Service": null, + "IsServiceRunning": false + }, + "68227ae7-9a32-45b0-8472-bf9619965838": { + "Module": "PhoneService.dll", + "ModulePath": "C:\\Windows\\System32\\PhoneService.dll", + "InterfaceId": "68227ae7-9a32-45b0-8472-bf9619965838", + "InterfaceStructOffset": 783312, + "ProceduresCount": 2, + "Procedures": [ + "PhoneSvcImpl_PhoneRpcDialExternal", + "PhoneSvcImpl_PhoneRpcClearMissedCallCount" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707094325280, + "Service": "PhoneSvc", + "IsServiceRunning": false + }, + "2f5f6520-ca46-1067-b319-00dd010662da": { + "Module": "tapisrv.dll", + "ModulePath": "C:\\Windows\\System32\\tapisrv.dll", + "InterfaceId": "2f5f6520-ca46-1067-b319-00dd010662da", + "InterfaceStructOffset": 245408, + "ProceduresCount": 3, + "Procedures": [ + "ClientAttach", + "ClientRequest", + "ClientDetach" + ], + "ProcStackSize": 8, + "DispatchFunction": 140707581105040, + "Service": "TapiSrv", + "IsServiceRunning": false + }, + "3ca78105-a3a3-4a68-b458-1a606bab8fd6": { + "Module": "mpnotify.exe", + "ModulePath": "C:\\Windows\\System32\\mpnotify.exe", + "InterfaceId": "3ca78105-a3a3-4a68-b458-1a606bab8fd6", + "InterfaceStructOffset": 13072, + "ProceduresCount": 2, + "Procedures": [ + "LogonNotify", + "ChangePasswordNotify" + ], + "ProcStackSize": 48, + "DispatchFunction": 140700413990832, + "Service": null, + "IsServiceRunning": false + }, + "d2716e94-25cb-4820-bc15-537866578562": { + "Module": "APHostService.dll", + "ModulePath": "C:\\Windows\\System32\\APHostService.dll", + "InterfaceId": "d2716e94-25cb-4820-bc15-537866578562", + "InterfaceStructOffset": 229168, + "ProceduresCount": 8, + "Procedures": [ + "ServerRPC_SubmitJob", + "ServerRPC_GetPendingJobs", + "ServerRPC_RetryJobById", + "ServerRPC_CancelJobById", + "ServerRPC_AdviseNotifications", + "ServerRPC_SubscribeNextNotification", + "ServerRPC_RegisterAppId", + "ServerRPC_UnadviseNotifications" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707488996416, + "Service": "OneSyncSvc", + "IsServiceRunning": false + }, + "c33b9f46-2088-4dbc-97e3-6125f127661c": { + "Module": "nlasvc.dll", + "ModulePath": "C:\\Windows\\System32\\nlasvc.dll", + "InterfaceId": "c33b9f46-2088-4dbc-97e3-6125f127661c", + "InterfaceStructOffset": 295008, + "ProceduresCount": 6, + "Procedures": [ + "AppSrv_NlaOpenQuery", + "AppSrv_NlaAsyncIndicate", + "AppSrv_NlaRefreshQuery", + "AppSrv_NlaCloseQuery", + "RpcNlaIndicateReprobe", + "RpcNlaGetCaptivePortalHosts" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708037495088, + "Service": "NlaSvc", + "IsServiceRunning": true + }, + "f1c37891-201f-4aa3-94b1-a5d131b04920": { + "Module": "CmService.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-container-manager_31bf3856ad364e35_10.0.18362.1500_none_a0633e62409b621c\\CmService.dll", + "InterfaceId": "f1c37891-201f-4aa3-94b1-a5d131b04920", + "InterfaceStructOffset": 623616, + "ProceduresCount": 14, + "Procedures": [ + "CmsRpcSrv_CreateContainer", + "CmsRpcSrv_OpenContainer", + "CmsRpcSrv_CloseContainer", + "CmsRpcSrv_TerminateContainer", + "CmsRpcSrv_QueryInformationContainer", + "CmsRpcSrv_EnumerateNetworkEndpoints", + "CmsRpcSrv_StartActivityAsync", + "CmsRpcSrv_StopActivity", + "CmsRpcSrv_AddHostNetworkToContainer", + "CmsRpcSrv_RemoveHostNetworkFromContainer", + "CmsRpcSrv_MapNamedPipeToContainer", + "CmsRpcSrv_UnmapNamedPipeFromContainer", + "CmsRpcSrv_MapVirtualDiskToContainer", + "CmsRpcSrv_UnmapVirtualDiskFromContainer" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707487005728, + "Service": null, + "IsServiceRunning": false + }, + "82273fdc-e32a-18c3-3f78-827929dc23ea": { + "Module": "wevtsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wevtsvc.dll", + "InterfaceId": "82273fdc-e32a-18c3-3f78-827929dc23ea", + "InterfaceStructOffset": 970848, + "ProceduresCount": 27, + "Procedures": [ + "ElfrClearELFW", + "ElfrBackupELFW", + "ElfrCloseEL", + "ElfrDeregisterEventSource", + "ElfrNumberOfRecords", + "ElfrOldestRecord", + "ElfrChangeNotify", + "ElfrOpenELW", + "ElfrRegisterEventSourceW", + "ElfrOpenBELW", + "ElfrReadELW", + "ElfrReportEventW", + "ElfrClearELFA", + "ElfrBackupELFA", + "ElfrOpenELA", + "ElfrRegisterEventSourceA", + "ElfrOpenBELA", + "ElfrReadELA", + "ElfrReportEventA", + "ElfrRegisterClusterSvc", + "ElfrDeregisterClusterSvc", + "ElfrWriteClusterEvents", + "ElfrGetLogInformation", + "ElfrFlushEL", + "ElfrReportEventAndSourceW", + "ElfrReportEventExW", + "ElfrReportEventExA" + ], + "ProcStackSize": 112, + "DispatchFunction": 140708090064864, + "Service": "EventLog", + "IsServiceRunning": true + }, + "51c82175-844e-4750-b0d8-ec255555bc06": { + "Module": "SppExtComObj.Exe", + "ModulePath": "C:\\Windows\\System32\\SppExtComObj.Exe", + "InterfaceId": "51c82175-844e-4750-b0d8-ec255555bc06", + "InterfaceStructOffset": 480064, + "ProceduresCount": 1, + "Procedures": [ + "Proc0" + ], + "ProcStackSize": 56, + "DispatchFunction": 140694666941856, + "Service": null, + "IsServiceRunning": false + }, + "30034843-029d-46ec-8fff-5d12987f85c4": { + "Module": "NgcCtnrSvc.dll", + "ModulePath": "C:\\Windows\\System32\\NgcCtnrSvc.dll", + "InterfaceId": "30034843-029d-46ec-8fff-5d12987f85c4", + "InterfaceStructOffset": 549680, + "ProceduresCount": 2, + "Procedures": [ + "s_NgcRpcCreateContainer", + "s_NgcRpcDeleteContainer" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707094013008, + "Service": "NgcCtnrSvc", + "IsServiceRunning": false + }, + "6ddfc7d1-7fca-44eb-a279-e9988f4db32b": { + "Module": "FrameServer.dll", + "ModulePath": "C:\\Windows\\System32\\FrameServer.dll", + "InterfaceId": "6ddfc7d1-7fca-44eb-a279-e9988f4db32b", + "InterfaceStructOffset": 630112, + "ProceduresCount": 24, + "Procedures": [ + "Server_CreateClientContext", + "Server_EnableNotifications", + "Server_AddDeviceToClientContext", + "Server_CreateMSKSHandle", + "Server_GetFSStreamInformationSizes", + "Server_GetFSStreamInformation", + "Server_GetCurrentMediaType", + "Server_SetCurrentMediaType", + "Server_SetStreamState", + "Server_GetStreamState", + "Server_GetNotifications", + "Server_SendContextCommand", + "Server_RegisterKSEvent", + "Server_RegisterKSSemaphore", + "Server_CloseClientContext", + "Server_GetCurrentMuxMediaType", + "Server_SetCurrentMuxMediaType", + "Server_GetMuxedMediaTypes", + "Server_GetMuxedStreamAttributes", + "Server_SetBufferAccessMode", + "Server_AddMultipleSensorDevicesToClientContext", + "Server_ShutdownContextSource", + "Server_SetDXGIAdapter", + "Server_ContextKeepAlive" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707093865712, + "Service": "FrameServer", + "IsServiceRunning": false + }, + "6a59ed09-c0dd-404a-8428-da82ad5153cb": { + "Module": "UtcDecoderHost.exe", + "ModulePath": "C:\\Windows\\System32\\UtcDecoderHost.exe", + "InterfaceId": "6a59ed09-c0dd-404a-8428-da82ad5153cb", + "InterfaceStructOffset": 76640, + "ProceduresCount": 1, + "Procedures": [ + "UtcDecoderHostApi_Decode" + ], + "ProcStackSize": 48, + "DispatchFunction": 140702477510320, + "Service": null, + "IsServiceRunning": false + }, + "e3907f22-c899-44e7-9d11-9d8b3d924832": { + "Module": "lsm.dll", + "ModulePath": "C:\\Windows\\System32\\lsm.dll", + "InterfaceId": "e3907f22-c899-44e7-9d11-9d8b3d924832", + "InterfaceStructOffset": 480080, + "ProceduresCount": 5, + "Procedures": [ + "RpcEnableChildSessions", + "RpcIsChildSessionsEnabled", + "RpcGetChildSessionId", + "RpcGetParentSessionId", + "RpcGetAllUserSessions" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708131495280, + "Service": "LSM", + "IsServiceRunning": true + }, + "cb735210-b16a-4fdd-8bf3-e3e63424f4cd": { + "Module": "hvsicontainerservice.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-hvsi-service_31bf3856ad364e35_10.0.18362.1916_none_ce843808b173de74\\hvsicontainerservice.dll", + "InterfaceId": "cb735210-b16a-4fdd-8bf3-e3e63424f4cd", + "InterfaceStructOffset": 966832, + "ProceduresCount": 1, + "Procedures": [ + "s_HvsiK_ValidateConnection" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707093997920, + "Service": null, + "IsServiceRunning": false + }, + "e60c73e6-88f9-11cf-9af1-0020af6e72f4": { + "Module": "rpcss.dll", + "ModulePath": "C:\\Windows\\System32\\rpcss.dll", + "InterfaceId": "e60c73e6-88f9-11cf-9af1-0020af6e72f4", + "InterfaceStructOffset": 960176, + "ProceduresCount": 12, + "Procedures": [ + "_Connect", + "_SetAppID", + "GetDefaultSecurityPermissions", + "_AllocateReservedIds", + "BulkUpdateOIDs", + "_ClientResolveOXID", + "_ServerAllocateOXIDAndOIDs", + "ServerAllocateOIDs", + "_ServerFreeOXIDAndOIDs", + "_SetServerOIDFlags", + "_Disconnect", + "GetUpdatedResolverBindings" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708135236880, + "Service": "RpcSs", + "IsServiceRunning": true + }, + "04557228-209a-46b4-aaa4-4eb4c84db7a2": { + "Module": "rdpshell.exe", + "ModulePath": "C:\\Windows\\System32\\rdpshell.exe", + "InterfaceId": "04557228-209a-46b4-aaa4-4eb4c84db7a2", + "InterfaceStructOffset": 427536, + "ProceduresCount": 1, + "Procedures": [ + "RpcEncodeRailOrder" + ], + "ProcStackSize": 40, + "DispatchFunction": 140698607236592, + "Service": null, + "IsServiceRunning": false + }, + "4d9f4ab8-7d1c-11cf-861e-0020af6e7c57": { + "Module": "rpcss.dll", + "ModulePath": "C:\\Windows\\System32\\rpcss.dll", + "InterfaceId": "4d9f4ab8-7d1c-11cf-861e-0020af6e7c57", + "InterfaceStructOffset": 959504, + "ProceduresCount": 1, + "Procedures": [ + "RemoteActivation" + ], + "ProcStackSize": 168, + "DispatchFunction": 140708135482080, + "Service": "RpcSs", + "IsServiceRunning": true + }, + "af7fead8-c34a-461f-8894-6d6f0e5eddcd": { + "Module": "wifinetworkmanager.dll", + "ModulePath": "C:\\Windows\\System32\\wifinetworkmanager.dll", + "InterfaceId": "af7fead8-c34a-461f-8894-6d6f0e5eddcd", + "InterfaceStructOffset": 488512, + "ProceduresCount": 12, + "Procedures": [ + "WiFiUserGetPowerBackOnOption", + "WiFiUserSetPowerBackOnOption", + "WiFiUserDeleteNetwork", + "WiFiUserGetHotspotStatus", + "WiFiUserSetHotspotStatus", + "WiFiUserProvisionHotspotApp", + "WifiUserStartHotspot2Registration", + "WifiUserEnableHotspot2OsuRegistration", + "WifiUserGetHotspot2OsuRegistrationStatus", + "WiFiUserActivateNotification", + "WiFiUserGetNotificationTargetProfile", + "WiFiTestSetActionRequired" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707601932064, + "Service": null, + "IsServiceRunning": false + }, + "1f260487-ba29-4f13-928a-bbd29761b083": { + "Module": "termsrv.dll", + "ModulePath": "C:\\Windows\\System32\\termsrv.dll", + "InterfaceId": "1f260487-ba29-4f13-928a-bbd29761b083", + "InterfaceStructOffset": 748560, + "ProceduresCount": 10, + "Procedures": [ + "RpcIsSessionPermitted", + "RpcGetUserCredentials", + "RpcGetUserProfile", + "RpcWinStationRedirectErrorMessage", + "RpcRedirectLogonBeginPainting", + "RpcRedirectLogonStatus", + "RpcRedirectLogonMessage", + "RpcRedirectLogonError", + "RpcGetRedirectAuthInfo", + "RpcGetRestrictedLogonInfo" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708119075584, + "Service": "TermService", + "IsServiceRunning": true + }, + "12345778-1234-abcd-ef00-0123456789ac": { + "Module": "samsrv.dll", + "ModulePath": "C:\\Windows\\System32\\samsrv.dll", + "InterfaceId": "12345778-1234-abcd-ef00-0123456789ac", + "InterfaceStructOffset": 667648, + "ProceduresCount": 74, + "Procedures": [ + "SamrConnect", + "SamrCloseHandle", + "SamrSetSecurityObject", + "SamrQuerySecurityObject", + "SamrShutdownSamServer", + "SamrLookupDomainInSamServer", + "SamrEnumerateDomainsInSamServer", + "SamrOpenDomain", + "SamrQueryInformationDomain", + "SamrSetInformationDomain", + "SamrCreateGroupInDomain", + "SamrEnumerateGroupsInDomain", + "SamrCreateUserInDomain", + "SamrEnumerateUsersInDomain", + "SamrCreateAliasInDomain", + "SamrEnumerateAliasesInDomain", + "SamrGetAliasMembership", + "SamrLookupNamesInDomain", + "SamrLookupIdsInDomain", + "SamrOpenGroup", + "SamrQueryInformationGroup", + "SamrSetInformationGroup", + "SamrAddMemberToGroup", + "SamrDeleteGroup", + "SamrRemoveMemberFromGroup", + "SamrGetMembersInGroup", + "SamrSetMemberAttributesOfGroup", + "SamrOpenAlias", + "SamrQueryInformationAlias", + "SamrSetInformationAlias", + "SamrDeleteAlias", + "SamrAddMemberToAlias", + "SamrRemoveMemberFromAlias", + "SamrGetMembersInAlias", + "SamrOpenUser", + "SamrDeleteUser", + "SamrQueryInformationUser", + "SamrSetInformationUser", + "SamrChangePasswordUser", + "SamrGetGroupsForUser", + "SamrQueryDisplayInformation", + "SamrGetDisplayEnumerationIndex", + "SamrTestPrivateFunctionsDomain", + "SamrTestPrivateFunctionsUser", + "SamrGetUserDomainPasswordInformation", + "SamrRemoveMemberFromForeignDomain", + "SamrQueryInformationDomain2", + "SamrQueryInformationUser2", + "SamrQueryDisplayInformation2", + "SamrGetDisplayEnumerationIndex2", + "SamrCreateUser2InDomain", + "SamrQueryDisplayInformation3", + "SamrAddMultipleMembersToAlias", + "SamrRemoveMultipleMembersFromAlias", + "SamrOemChangePasswordUser2", + "SamrUnicodeChangePasswordUser2", + "SamrGetDomainPasswordInformation", + "SamrConnect2", + "SamrSetInformationUser2", + "SamrSetBootKeyInformation", + "SamrGetBootKeyInformation", + "SamrConnect3", + "SamrConnect4", + "SamrUnicodeChangePasswordUser3", + "SamrConnect5", + "SamrRidToSid", + "SamrSetDSRMPassword", + "SamrValidatePassword", + "SamrQueryLocalizableAccountsInDomain", + "SamrPerformGenericOperation", + "SamrSyncDSRMPasswordFromAccount", + "SamrLookupNamesInDomain2", + "SamrEnumerateUsersInDomain2", + "SamrUnicodeChangePasswordUser4" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708152242448, + "Service": null, + "IsServiceRunning": false + }, + "850cee52-3038-4277-b9b4-e05db8b2c35c": { + "Module": "das.dll", + "ModulePath": "C:\\Windows\\System32\\das.dll", + "InterfaceId": "850cee52-3038-4277-b9b4-e05db8b2c35c", + "InterfaceStructOffset": 369024, + "ProceduresCount": 14, + "Procedures": [ + "DasCreateAssociationContextForApp", + "DasCreateAssociationContextFromOobBlob", + "DasStartEnumCeremonies", + "DasSelectCeremony", + "DasStartReadCeremonyData", + "DasStartWriteCeremonyData", + "DasStartFinalize", + "DasStartDeviceStatusNotification", + "DasCloseAssociationContext", + "DasStartRemoveAssociation", + "DasCreateImportExportContext", + "DasStartAepImport", + "DasStartAepExport", + "DasCloseImportExportContext" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707580866480, + "Service": "DeviceAssociationService", + "IsServiceRunning": false + }, + "c605f9fb-f0a3-4e2a-a073-73560f8d9e3e": { + "Module": "bisrv.dll", + "ModulePath": "C:\\Windows\\System32\\bisrv.dll", + "InterfaceId": "c605f9fb-f0a3-4e2a-a073-73560f8d9e3e", + "InterfaceStructOffset": 551584, + "ProceduresCount": 1, + "Procedures": [ + "RBiSrvSignalEvent" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708131125024, + "Service": null, + "IsServiceRunning": false + }, + "b05885e9-fd8c-4839-9d73-f1baff8f4e44": { + "Module": "datamarketsvc.dll", + "ModulePath": "C:\\Windows\\System32\\datamarketsvc.dll", + "InterfaceId": "b05885e9-fd8c-4839-9d73-f1baff8f4e44", + "InterfaceStructOffset": 83712, + "ProceduresCount": 6, + "Procedures": [ + "s_SetMobileBroadbandFirewall", + "s_RemoveMobileBroadbandFirewall", + "s_IsDynaMoDisabled", + "s_GetInterfaceGuid", + "s_GetWmiProperty", + "s_IsUserAdmin" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707594718608, + "Service": null, + "IsServiceRunning": false + }, + "9b008953-f195-4bf9-bde0-4471971e58ed": { + "Module": "SystemEventsBrokerServer.dll", + "ModulePath": "C:\\Windows\\System32\\SystemEventsBrokerServer.dll", + "InterfaceId": "9b008953-f195-4bf9-bde0-4471971e58ed", + "InterfaceStructOffset": 154320, + "ProceduresCount": 6, + "Procedures": [ + "SebiEnumerateEvents", + "_SebiEnumerateEventsByType", + "_SebiQueryEventData", + "SebiQueryEventPackage", + "_SebiSignalSyncEventEx", + "SebiCancelEvent" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708127150736, + "Service": "SystemEventsBroker", + "IsServiceRunning": true + }, + "c2d1b5dd-fa81-4460-9dd6-e7658b85454b": { + "Module": "wcmsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wcmsvc.dll", + "InterfaceId": "c2d1b5dd-fa81-4460-9dd6-e7658b85454b", + "InterfaceStructOffset": 768560, + "ProceduresCount": 2, + "Procedures": [ + "RpcSetProxyInformation", + "RpcDeleteProxyInformation" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708018992160, + "Service": "Wcmsvc", + "IsServiceRunning": true + }, + "6b5bdd1e-528c-422c-af8c-a4079be4fe48": { + "Module": "FwRemoteSvr.dll", + "ModulePath": "C:\\Windows\\System32\\FwRemoteSvr.dll", + "InterfaceId": "6b5bdd1e-528c-422c-af8c-a4079be4fe48", + "InterfaceStructOffset": 72192, + "ProceduresCount": 86, + "Procedures": [ + "RRPC_FWOpenPolicyStore", + "RRPC_FWClosePolicyStore", + "RRPC_FWRestoreDefaults", + "RRPC_FWGetGlobalConfig", + "RRPC_FWSetGlobalConfig", + "RRPC_FWAddFirewallRule", + "RRPC_FWSetFirewallRule", + "RRPC_FWDeleteFirewallRule", + "RRPC_FWDeleteAllFirewallRules", + "RRPC_FWEnumFirewallRules", + "RRPC_FWGetConfig", + "RRPC_FWSetConfig", + "RRPC_FWAddConnectionSecurityRule", + "RRPC_FWSetConnectionSecurityRule", + "RRPC_FWDeleteConnectionSecurityRule", + "RRPC_FWDeleteAllConnectionSecurityRules", + "RRPC_FWEnumConnectionSecurityRules", + "RRPC_FWAddAuthenticationSet", + "RRPC_FWSetAuthenticationSet", + "RRPC_FWDeleteAuthenticationSet", + "RRPC_FWDeleteAllAuthenticationSets", + "RRPC_FWEnumAuthenticationSets", + "RRPC_FWAddCryptoSet", + "RRPC_FWSetCryptoSet", + "RRPC_FWDeleteCryptoSet", + "RRPC_FWDeleteAllCryptoSets", + "RRPC_FWEnumCryptoSets", + "RRPC_FWEnumPhase1SAs", + "RRPC_FWEnumPhase2SAs", + "RRPC_FWDeletePhase1SAs", + "RRPC_FWDeletePhase2SAs", + "RRPC_FWEnumProducts", + "RRPC_FWAddMainModeRule", + "RRPC_FWSetMainModeRule", + "RRPC_FWDeleteMainModeRule", + "RRPC_FWDeleteAllMainModeRules", + "RRPC_FWEnumMainModeRules", + "RRPC_FWQueryFirewallRules", + "RRPC_FWQueryConnectionSecurityRules2_10", + "RRPC_FWQueryMainModeRules", + "RRPC_FWQueryAuthenticationSets", + "RRPC_FWQueryCryptoSets", + "RRPC_FWEnumNetworks", + "RRPC_FWEnumAdapters", + "RRPC_FWGetGlobalConfig2_10", + "RRPC_FWGetConfig2_10", + "RRPC_FWAddFirewallRule2_10", + "RRPC_FWSetFirewallRule2_10", + "RRPC_FWEnumFirewallRules2_10", + "RRPC_FWAddConnectionSecurityRule2_10", + "RRPC_FWSetConnectionSecurityRule2_10", + "RRPC_FWEnumConnectionSecurityRules2_10", + "RRPC_FWAddAuthenticationSet2_10", + "RRPC_FWSetAuthenticationSet2_10", + "RRPC_FWEnumAuthenticationSets2_10", + "RRPC_FWAddCryptoSet2_10", + "RRPC_FWSetCryptoSet2_10", + "RRPC_FWEnumCryptoSets2_10", + "RRPC_FWAddConnectionSecurityRule2_20", + "RRPC_FWSetConnectionSecurityRule2_20", + "RRPC_FWEnumConnectionSecurityRules2_20", + "RRPC_FWQueryConnectionSecurityRules2_20", + "RRPC_FWAddAuthenticationSet2_20", + "RRPC_FWSetAuthenticationSet2_20", + "RRPC_FWEnumAuthenticationSets2_20", + "RRPC_FWQueryAuthenticationSets2_20", + "RRPC_FWAddFirewallRule2_20", + "RRPC_FWSetFirewallRule2_20", + "RRPC_FWEnumFirewallRules2_20", + "RRPC_FWQueryFirewallRules2_20", + "RRPC_FWAddFirewallRule2_24", + "RRPC_FWSetFirewallRule2_24", + "RRPC_FWEnumFirewallRules2_24", + "RRPC_FWQueryFirewallRules2_24", + "RRPC_FWAddFirewallRule2_25", + "RRPC_FWSetFirewallRule2_25", + "RRPC_FWEnumFirewallRules2_25", + "RRPC_FWQueryFirewallRules2_25", + "RRPC_FWAddFirewallRule2_26", + "RRPC_FWSetFirewallRule2_26", + "RRPC_FWEnumFirewallRules2_26", + "RRPC_FWQueryFirewallRules2_26", + "RRPC_FWAddFirewallRule2_27", + "RRPC_FWSetFirewallRule2_27", + "RRPC_FWEnumFirewallRules2_27", + "RRPC_FWQueryFirewallRules2_27" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707880924336, + "Service": null, + "IsServiceRunning": false + }, + "00000143-0000-0000-c000-000000000046": { + "Module": "combase.dll", + "ModulePath": "C:\\Windows\\System32\\combase.dll", + "InterfaceId": "00000143-0000-0000-c000-000000000046", + "InterfaceStructOffset": 2274544, + "ProceduresCount": 0, + "Procedures": [], + "ProcStackSize": 56, + "DispatchFunction": 140707382121168, + "Service": null, + "IsServiceRunning": false + }, + "412f241e-c12a-11ce-abff-0020af6e7a17": { + "Module": "rpcss.dll", + "ModulePath": "C:\\Windows\\System32\\rpcss.dll", + "InterfaceId": "412f241e-c12a-11ce-abff-0020af6e7a17", + "InterfaceStructOffset": 959792, + "ProceduresCount": 29, + "Procedures": [ + "ServerRegisterClsid", + "ServerRevokeClsid", + "ServerRegisterActivatableClasses", + "ServerRevokeActivatableClasses", + "GetThreadID", + "UpdateActivationSettings", + "RegisterWindowPropInterface", + "GetWindowPropInterface", + "EnableDisableDynamicIPTracking", + "GetCurrentAddrExclusionList", + "SetAddrExclusionList", + "FlushSCMBindings", + "RetireServer", + "NotifyDDStartOrStop", + "QueryDragDropActive", + "SetOrRevokeForcedDropTarget", + "IsObjectCreationAllowed", + "ControlTracingForProcess", + "QueryPIDForActivation", + "NotifyWinRTActivationStoreChanged", + "DecodeProxy", + "NotifyPsmResume", + "QueryServerProcessHandleHeld", + "RegisterRacActivationToken", + "RevokeRacActivationToken", + "RegisterConsoleHandles", + "RevokeConsoleHandles", + "NotifyComClassChangesFromDeployment", + "LogMachineClassesRootPermissions" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708135400464, + "Service": "RpcSs", + "IsServiceRunning": true + }, + "824d8d77-a27f-4915-a536-36e9283dce29": { + "Module": "winhttp.dll", + "ModulePath": "C:\\Windows\\System32\\winhttp.dll", + "InterfaceId": "824d8d77-a27f-4915-a536-36e9283dce29", + "InterfaceStructOffset": 805088, + "ProceduresCount": 11, + "Procedures": [ + "s_PacWorkerCallbackInitSessionRpc", + "s_PacWorkerCallbackCloseSessionRpc", + "s_PacWorkerCallbackIsResolvableRpc", + "s_PacWorkerCallbackIsResolvableExRpc", + "s_PacWorkerCallbackIsInNetRpc", + "s_PacWorkerCallbackIsInNetExRpc", + "s_PacWorkerCallbackDnsResolveRpc", + "s_PacWorkerCallbackDnsResolveExRpc", + "s_PacWorkerCallbackMyIpAddressRpc", + "s_PacWorkerCallbackMyIpAddressExRpc", + "s_PacWorkerCallbackSortIpAddressListRpc" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708017921968, + "Service": "WinHttpAutoProxySvc", + "IsServiceRunning": true + }, + "b54e9aa3-cf29-4f21-a8ea-98c5850ce296": { + "Module": "Microsoft.Graphics.Display.DisplayEnhancementService.dll", + "ModulePath": "C:\\Windows\\System32\\Microsoft.Graphics.Display.DisplayEnhancementService.dll", + "InterfaceId": "b54e9aa3-cf29-4f21-a8ea-98c5850ce296", + "InterfaceStructOffset": 900832, + "ProceduresCount": 26, + "Procedures": [ + "DeoRpcServerOpenContextHandle", + "DeoRpcServerCloseContextHandle", + "DeoRpcServerStartViewPropertyChangedCallbacks", + "DeoRpcServerStartCanOverrideChangedCallbacks", + "DeoRpcServerStartIsOverrideActiveChangedCallbacks", + "DeoRpcServerStopViewPropertyChangedCallbacks", + "DeoRpcServerStopCanOverrideChangedCallbacks", + "DeoRpcServerStopIsOverrideActiveChangedCallbacks", + "DeoRpcServerStartOverride", + "DeoRpcServerStopOverride", + "DeoRpcServerGetCanOverride", + "DeoRpcServerGetIsOverrideActive", + "DeoRpcServerGetIsBrightnessOverrideSupported", + "DeoRpcServerGetIsBrightnessNitsOverrideSupported", + "DeoRpcServerGetSupportedMillinitRanges", + "DeoRpcServerGetBrightnessLevel", + "DeoRpcServerGetBrightnessMillinits", + "DeoRpcServerGetBrightnessLevelForBrightnessScenario", + "DeoRpcServerGetBrightnessMillinitsForBrightnessScenario", + "DeoRpcServerSetBrightnessLevel", + "DeoRpcServerSetBrightnessMillinits", + "DeoRpcServerSetBrightnessScenario", + "DeoRpcServerGetIsColorOverrideSupported", + "DeoRpcServerGetColorScenario", + "DeoRpcServerSetColorScenario", + "DeoRpcServerSaveForSystem" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707093776944, + "Service": "DisplayEnhancementService", + "IsServiceRunning": false + }, + "29770a8f-829b-4158-90a2-78cd488501f7": { + "Module": "SessEnv.dll", + "ModulePath": "C:\\Windows\\System32\\SessEnv.dll", + "InterfaceId": "29770a8f-829b-4158-90a2-78cd488501f7", + "InterfaceStructOffset": 332832, + "ProceduresCount": 1, + "Procedures": [ + "TSSDFarmRpcGrantUserTSAccessRight" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708025016560, + "Service": "SessionEnv", + "IsServiceRunning": true + }, + "650a7e26-eab8-5533-ce43-9c1dfce11511": { + "Module": "rascustom.dll", + "ModulePath": "C:\\Windows\\System32\\rascustom.dll", + "InterfaceId": "650a7e26-eab8-5533-ce43-9c1dfce11511", + "InterfaceStructOffset": 310544, + "ProceduresCount": 37, + "Procedures": [ + "Rpc_VpnProtEngOpen", + "Rpc_VpnProtEngClose", + "Rpc_VpnProtEngEventSubscribe", + "Rpc_VpnProtEngEventSubscriptionGetLastEvent", + "Rpc_VpnProtEngEventUnsubscribe", + "Rpc_VpnProtEngSendGetCredentialsRequest", + "Rpc_VpnProtEngSendNegotiatingNetworkRequest", + "Rpc_VpnProtEngSendInterfaceCreateRequest", + "Rpc_VpnProtEngSendInterfaceDestroyRequest", + "Rpc_VpnProtEngDisconnectInternal", + "Rpc_VpnProtEngSendConnectError", + "Rpc_VpnProtEngGetConfiguration", + "Rpc_VpnProtEngGetBestCostInterface", + "Rpc_VpnProtEngGetStatementOfHealth", + "Rpc_VpnProtEngSetKeepAliveFrequencyOverrideRequest", + "Rpc_VpnProtEngSendGetCustomPromptRequest", + "Rpc_VpnProtEngSendGetCertificateConsentBlankUiRequest", + "Rpc_VpnProtEngSendCloseCertificateConsentBlankUiRequest", + "Rpc_VpnProtEngPluginInstall", + "Rpc_VpnProtEngPluginUninstall", + "Rpc_VpnProtEngSetCostNetworkSettings", + "Rpc_VpnProtEngGetCostNetworkSettings", + "Rpc_VpnProtEngExecuteAndCaptureLogs", + "Rpc_VpnProtEngGetInterface", + "Rpc_VpnProtEngPluginEnumerate", + "Rpc_VpnProtEngAddProfileFromXml", + "Rpc_VpnProtEngWinRtConnect", + "Rpc_VpnProtEngWinRtDisconnect", + "Rpc_VpnProtEngWinRtEnumerate", + "Rpc_VpnProtEngWinRtGetEntryProperties", + "Rpc_VpnProtEngWinRtGetRasCustomData", + "Rpc_VpnProtEngWinRtGetEapBlob", + "Rpc_VpnProtEngWinRtGetEapXml", + "Rpc_VpnProtEngWinRtGetMoniker", + "Rpc_VpnProtEngWinRtGetConnectionStatus", + "Rpc_VpnProtEngWinRtUpdateRegistryProfileList", + "Rpc_VpnProtEngGetProxyForUrlAndSingleSessionDeviceUser" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707795102544, + "Service": null, + "IsServiceRunning": false + }, + "8c7a6de0-788d-11d0-9edf-444553540000": { + "Module": "wiaservc.dll", + "ModulePath": "C:\\Windows\\System32\\wiaservc.dll", + "InterfaceId": "8c7a6de0-788d-11d0-9edf-444553540000", + "InterfaceStructOffset": 421984, + "ProceduresCount": 16, + "Procedures": [ + "R_StiApiGetVersion", + "R_StiApiEnableHwNotifications", + "R_StiApiGetHwNotificationState", + "R_StiApiLaunchApplication", + "R_StiApiOpenDevice", + "R_StiApiSubscribe", + "R_StiApiGetLastNotificationData", + "R_StiApiUnSubscribe", + "R_StiApiCloseDevice", + "R_StiApiLockDevice", + "R_StiApiUnlockDevice", + "R_WiaGetEventDataAsync", + "OpenClientConnection", + "CloseClientConnection", + "RegisterUnregisterForEventNotification", + "WiaGetRuntimetEventDataAsync" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707487128656, + "Service": "stisvc", + "IsServiceRunning": false + }, + "97be9507-17da-4999-87d7-66c0b2d83cc7": { + "Module": "SensorService.dll", + "ModulePath": "C:\\Windows\\System32\\SensorService.dll", + "InterfaceId": "97be9507-17da-4999-87d7-66c0b2d83cc7", + "InterfaceStructOffset": 373472, + "ProceduresCount": 8, + "Procedures": [ + "RSensorBrokerServerOpen", + "RSensorBrokerServerClose", + "RSensorBrokerServerDoesSdoExist", + "RSensorBrokerServerStart", + "RSensorBrokerServerStop", + "RSensorBrokerServerGetDeviceID", + "RSensorBrokerServerGetCurrentOrientation", + "RSensorBrokerServerGetProperties" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707580872032, + "Service": "SensorService", + "IsServiceRunning": false + }, + "0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53": { + "Module": "schedsvc.dll", + "ModulePath": "C:\\Windows\\System32\\schedsvc.dll", + "InterfaceId": "0a74ef1c-41a4-4e06-83ae-dc74fb1cdd53", + "InterfaceStructOffset": 478080, + "ProceduresCount": 5, + "Procedures": [ + "ItSrvRegisterIdleTask", + "ItSrvUnregisterIdleTask", + "ItSrvProcessIdleTasks", + "ItSrvSetDetectionParameters", + "ItSrvSetRuntimeOverrides" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708047002624, + "Service": "Schedule", + "IsServiceRunning": true + }, + "5dea026d-f999-40b1-a234-2164fd086783": { + "Module": "Windows.Internal.Bluetooth.dll", + "ModulePath": "C:\\Windows\\System32\\Windows.Internal.Bluetooth.dll", + "InterfaceId": "5dea026d-f999-40b1-a234-2164fd086783", + "InterfaceStructOffset": 494032, + "ProceduresCount": 9, + "Procedures": [ + "s_BthEvtBrRetrieveEventSocket", + "s_BthEvtBrCloseEventSocket", + "s_BthEvtBrRetrieveEventAdvertisements", + "s_BthEvtBrRetrieveEventCharacteristicNotifications", + "s_BthEvtBrGattEnumerateBrokeredServices", + "s_BthEvtBrGattEnumerateBrokeredAttributeRequests", + "s_BthEvtBrGattRetrieveBrokeredAttributeRequestDetails", + "s_BthEvtBrGattSendResponseForBrokeredAttributeRequest", + "s_BthEvtBrGattDisposeBrokeredAttributeRequest" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707487503888, + "Service": null, + "IsServiceRunning": false + }, + "10bd2718-13bd-4b84-8e7d-8b5c83770a86": { + "Module": "rdpclip.exe", + "ModulePath": "C:\\Windows\\System32\\rdpclip.exe", + "InterfaceId": "10bd2718-13bd-4b84-8e7d-8b5c83770a86", + "InterfaceStructOffset": 358080, + "ProceduresCount": 2, + "Procedures": [ + "RpcSetRenderHint", + "RpcGetStartMenuRect" + ], + "ProcStackSize": 24, + "DispatchFunction": 140698142342480, + "Service": null, + "IsServiceRunning": false + }, + "572e35b4-1344-4565-96a1-f5df3bfa89bb": { + "Module": "wlidsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wlidsvc.dll", + "InterfaceId": "572e35b4-1344-4565-96a1-f5df3bfa89bb", + "InterfaceStructOffset": 1314832, + "ProceduresCount": 3, + "Procedures": [ + "WLIDNCreateContext", + "WLIDNDeleteContext", + "WLIDNGetNextNotification" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707092937264, + "Service": "wlidsvc", + "IsServiceRunning": false + }, + "5c9a4cd7-ba75-45d2-9898-1773b3d1e5f1": { + "Module": "umpnpmgr.dll", + "ModulePath": "C:\\Windows\\System32\\umpnpmgr.dll", + "InterfaceId": "5c9a4cd7-ba75-45d2-9898-1773b3d1e5f1", + "InterfaceStructOffset": 79936, + "ProceduresCount": 7, + "Procedures": [ + "PNP_Local_Connect", + "PNP_Local_Connect", + "PNP_Local_InstallDevInst", + "PNP_Local_InstallDriver", + "PNP_Local_UninstallDriver", + "PNP_Local_AddDriverPackage", + "PNP_Local_DeleteDriverPackage" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708140331504, + "Service": "PlugPlay", + "IsServiceRunning": true + }, + "c3f42c6e-d4cc-4e5a-938b-9c5e8a5d8c2e": { + "Module": "wlanmsm.dll", + "ModulePath": "C:\\Windows\\System32\\wlanmsm.dll", + "InterfaceId": "c3f42c6e-d4cc-4e5a-938b-9c5e8a5d8c2e", + "InterfaceStructOffset": 368240, + "ProceduresCount": 15, + "Procedures": [ + "RpcDot11ExtRegisterIhvProcess", + "RpcDot11ExtPreAssociateCompletion", + "RpcDot11ExtPostAssociateCompletion", + "RpcDot11ExtSendUIRequest", + "RpcDot11ExtSendNotification", + "RpcDot11ExtGetProfileCustomUserData", + "RpcDot11ExtSetProfileCustomUserData", + "RpcDot11ExtNotifyChangeState", + "RpcDot11ExtSetCurrentProfile", + "RpcDot11ExtStartOneX", + "RpcDot11ExtStopOneX", + "RpcDot11ExtProcessSecurityPacket", + "RpcDot11ExtRequestVirtualStation", + "RpcDot11ExtReleaseVirtualStation", + "RpcDot11ExtSetVirtualStationAPProperties" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707753709952, + "Service": null, + "IsServiceRunning": false + }, + "9435cc56-1d9c-4924-ac7d-b60a2c3520e1": { + "Module": "sppsvc.exe", + "ModulePath": "C:\\Windows\\System32\\sppsvc.exe", + "InterfaceId": "9435cc56-1d9c-4924-ac7d-b60a2c3520e1", + "InterfaceStructOffset": 3858208, + "ProceduresCount": 5, + "Procedures": [ + "Proc0", + "Proc1", + "Proc2", + "Proc3", + "Proc4" + ], + "ProcStackSize": 56, + "DispatchFunction": 140699231198240, + "Service": "sppsvc", + "IsServiceRunning": false + }, + "e1af8308-5d1f-11c9-91a4-08002b14a0fa": { + "Module": "RpcEpMap.dll", + "ModulePath": "C:\\Windows\\System32\\RpcEpMap.dll", + "InterfaceId": "e1af8308-5d1f-11c9-91a4-08002b14a0fa", + "InterfaceStructOffset": 45248, + "ProceduresCount": 9, + "Procedures": [ + "ept_delete", + "ept_delete", + "ept_lookup", + "ept_map", + "ept_lookup_handle_free", + "ept_delete", + "ept_delete", + "ept_map_auth", + "ept_map_auth_async" + ], + "ProcStackSize": 80, + "DispatchFunction": 140708134459744, + "Service": "RpcEptMapper", + "IsServiceRunning": true + }, + "4f4fa786-2f8f-49e8-8aae-6669febd5d1d": { + "Module": "lpasvc.dll", + "ModulePath": "C:\\Windows\\System32\\lpasvc.dll", + "InterfaceId": "4f4fa786-2f8f-49e8-8aae-6669febd5d1d", + "InterfaceStructOffset": 992336, + "ProceduresCount": 23, + "Procedures": [ + "LuiApiOpenHandle", + "LuiApiCloseHandle", + "LuiApiRegisterForAllEnterpriseProfileNotifications", + "LuiApiRegisterForAllProfileNotifications", + "LuiApiRegisterForEnterpriseEsimNotifications", + "LuiApiRegisterForEsimNotifications", + "LuiApiRegisterForLpaNotifications", + "LuiApiAddProfile", + "LuiApiCancelOperation", + "LuiApiDeleteProfile", + "LuiApiDisableProfile", + "LuiApiDiscoverProfiles", + "LuiApiEnableProfile", + "LuiApiInstallProfile", + "LuiApiProcessActivationCode", + "LuiApiReleaseProvisioningProfile", + "LuiApiRequestProvisioningProfile", + "LuiApiSetDefaultSmdpAddress", + "LuiApiSetEsimPolicy", + "LuiApiSetProfileNickname", + "LuiApiSetUserAuthenticationMode", + "LuiApiVerifyClientToken", + "LuiApiWipeEsim" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707094052928, + "Service": "wlpasvc", + "IsServiceRunning": false + }, + "4b112204-0e19-11d3-b42b-0000f81feb9f": { + "Module": "ssdpsrv.dll", + "ModulePath": "C:\\Windows\\System32\\ssdpsrv.dll", + "InterfaceId": "4b112204-0e19-11d3-b42b-0000f81feb9f", + "InterfaceStructOffset": 217120, + "ProceduresCount": 21, + "Procedures": [ + "_SSDPOpenRpc", + "_SSDPCloseRpc", + "RegisterServiceExRpc", + "_DeregisterServiceRpc", + "CleanupCacheRpc", + "BeginSearchRpc", + "GetSearchNotificationRpc", + "CancelSearchRpc", + "CloseSearchRpc", + "EnableNotificationRpc", + "_InitializeSyncHandle", + "_RemoveSyncHandle", + "RegisterNotificationRpc", + "RegisterNotificationAsyncRpc", + "_GetNotificationRpc", + "_WakeupGetNotificationRpc", + "DeregisterNotificationRpc", + "SetICSInterfaces", + "SetICSOff", + "EnableFirewallRuleRpc", + "DisableFirewallRuleRpc" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708048804496, + "Service": "SSDPSRV", + "IsServiceRunning": true + }, + "8a92a787-eba6-4d09-ba84-0a8cb293bc30": { + "Module": "AppVEntSubsystems64.dll", + "ModulePath": "C:\\Windows\\System32\\AppVEntSubsystems64.dll", + "InterfaceId": "8a92a787-eba6-4d09-ba84-0a8cb293bc30", + "InterfaceStructOffset": 1410848, + "ProceduresCount": 1, + "Procedures": [ + "IActivationMarshaller_CoGetClassObject" + ], + "ProcStackSize": 48, + "DispatchFunction": 140706797638080, + "Service": null, + "IsServiceRunning": false + }, + "3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5": { + "Module": "dhcpcore.dll", + "ModulePath": "C:\\Windows\\System32\\dhcpcore.dll", + "InterfaceId": "3c4728c5-f0ab-448b-bda1-6ce01eb0a6d5", + "InterfaceStructOffset": 270336, + "ProceduresCount": 43, + "Procedures": [ + "RpcSrvEnableDhcp", + "RpcSrvEnableDhcpAdvanced", + "RpcSrvRenewLease", + "RpcSrvDeleteStaticAddressAndDefaultGateways", + "RpcSrvCheckServerAvailability", + "RpcSrvRenewLeaseByBroadcast", + "RpcSrvReleaseLease", + "RpcSrvSetFallbackParams", + "RpcSrvGetFallbackParams", + "RpcSrvFallbackRefreshParams", + "RpcSrvStaticRefreshParams", + "RpcSrvRemoveDnsRegistrations", + "RpcSrvRequestParams", + "RpcSrvPersistentRequestParams", + "RpcSrvRegisterParams", + "RpcSrvDeRegisterParams", + "RpcSrvEnumInterfaces", + "RpcSrvQueryLeaseInfo", + "RpcSrvQueryLeaseInfoArray", + "RpcSrvSetClassId", + "RpcSrvGetClassId", + "RpcSrvSetClientId", + "RpcSrvGetClientId", + "RpcSrvNotifyMediaReconnected", + "RpcSrvGetOriginalSubnetMask", + "RpcSrvSetMSFTVendorSpecificOptions", + "RpcSrvRequestCachedParams", + "RpcSrvRegisterConnectionStateNotification", + "RpcSrvDeRegisterConnectionStateNotification", + "RpcSrvGetNotificationStatus", + "RpcSrvGetDhcpServicedConnections", + "RpcSrvGetTraceArray", + "RpcSrvEnableTracing", + "RpcSrvLeaseIpAddressEx", + "RpcSrvRenewIpAddressLeaseEx", + "RpcSrvReleaseIpAddressLeaseEx", + "RpcSrvMadcapApiStartup", + "RpcSrvMadcapApiCleanup", + "RpcSrvMadcapEnumerateScopes", + "RpcSrvMadcapGenUID", + "RpcSrvMadcapRequestAddress", + "RpcSrvMadcapRenewAddress", + "RpcSrvMadcapReleaseAddress" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708059983744, + "Service": "Dhcp", + "IsServiceRunning": true + }, + "5824833b-3c1a-4ad2-bdfd-c31d19e23ed2": { + "Module": "psmsrv.dll", + "ModulePath": "C:\\Windows\\System32\\psmsrv.dll", + "InterfaceId": "5824833b-3c1a-4ad2-bdfd-c31d19e23ed2", + "InterfaceStructOffset": 168768, + "ProceduresCount": 6, + "Procedures": [ + "PsmSrvRegisterAppPriorityNotification", + "PsmSrvQueryApplicationResourceUsageForTimer", + "PsmSrvTimerStart", + "PsmSrvTimerCleanup", + "PsmSrvTimerRemainingResourceTimeGet", + "PsmSrvTimerElapsedResourceTimeGet" + ], + "ProcStackSize": 104, + "DispatchFunction": 140708134219824, + "Service": "BrokerInfrastructure", + "IsServiceRunning": true + }, + "ecd85155-cc3a-4f10-aad5-9a9a2bf2ef0c": { + "Module": "termsrv.dll", + "ModulePath": "C:\\Windows\\System32\\termsrv.dll", + "InterfaceId": "ecd85155-cc3a-4f10-aad5-9a9a2bf2ef0c", + "InterfaceStructOffset": 747680, + "ProceduresCount": 1, + "Procedures": [ + "RpcSetAutologonPassword" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708119080560, + "Service": "TermService", + "IsServiceRunning": true + }, + "c8cb7687-e6d3-11d2-a958-00c04f682e16": { + "Module": "WebClnt.dll", + "ModulePath": "C:\\Windows\\System32\\WebClnt.dll", + "InterfaceId": "c8cb7687-e6d3-11d2-a958-00c04f682e16", + "InterfaceStructOffset": 189584, + "ProceduresCount": 19, + "Procedures": [ + "DavrCreateConnection", + "DavrGetCookie", + "DavrSetCookie", + "DavrDoesServerDoDav", + "DavrIsValidShare", + "DavrEnumNetUses", + "DavrEnumShares", + "DavrEnumServers", + "DavrGetConnection", + "DavrDeleteConnection", + "DavrCancelConnectionsToServer", + "DavrGetUser", + "DavrConnectionExist", + "BeginChildren", + "DavrFreeUsedDiskSpace", + "DavrGetTheLockOwnerOfTheFile", + "DavrInvalidateCache", + "DavrIsWebClientRunning", + "DavrGetServerAuthType" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707580976304, + "Service": "WebClient", + "IsServiceRunning": false + }, + "3473dd4d-2e88-4006-9cba-22570909dd10": { + "Module": "winhttp.dll", + "ModulePath": "C:\\Windows\\System32\\winhttp.dll", + "InterfaceId": "3473dd4d-2e88-4006-9cba-22570909dd10", + "InterfaceStructOffset": 789984, + "ProceduresCount": 11, + "Procedures": [ + "GetProxyForUrl", + "ResetAutoProxy", + "SaveProxyCredentials", + "StoreSavedProxyCredentialsForCurrentUser", + "DeleteSavedProxyCredentials", + "ReindicateAllProxies", + "ReadProxySettings", + "WriteProxySettings", + "ConnectionUpdateIfIndexTable", + "ConnectionSetPolicyEntries", + "ConnectionDeletePolicyEntries" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708017721872, + "Service": "WinHttpAutoProxySvc", + "IsServiceRunning": true + }, + "58e604e8-9adb-4d2e-a464-3b0683fb1480": { + "Module": "appinfo.dll", + "ModulePath": "C:\\Windows\\System32\\appinfo.dll", + "InterfaceId": "58e604e8-9adb-4d2e-a464-3b0683fb1480", + "InterfaceStructOffset": 106592, + "ProceduresCount": 1, + "Procedures": [ + "RAiGetTokenForAxIS" + ], + "ProcStackSize": 88, + "DispatchFunction": 140707486597664, + "Service": "Appinfo", + "IsServiceRunning": true + }, + "a3e5af3e-8a33-4737-af6e-bc1f8ecee4bf": { + "Module": "LsaIso.exe", + "ModulePath": "C:\\Windows\\System32\\LsaIso.exe", + "InterfaceId": "a3e5af3e-8a33-4737-af6e-bc1f8ecee4bf", + "InterfaceStructOffset": 179344, + "ProceduresCount": 5, + "Procedures": [ + "ProvIumCreateMachineKey", + "ProvIumCreateMachineSelfSignedCertificate", + "ProvIumCreateMachineCertificateRequest", + "ProvIumCheckMachineKey", + "ProvIumCheckRootSecretValidity" + ], + "ProcStackSize": 56, + "DispatchFunction": 140697528904208, + "Service": null, + "IsServiceRunning": false + }, + "0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd": { + "Module": "SyncController.dll", + "ModulePath": "C:\\Windows\\System32\\SyncController.dll", + "InterfaceId": "0c53aa2e-fb1c-49c5-bfb6-c54f8e5857cd", + "InterfaceStructOffset": 498464, + "ProceduresCount": 14, + "Procedures": [ + "ActiveSyncServer_QuerySyncStatusProps", + "ActiveSyncServer_QueryLastSyncResult", + "ActiveSyncServer_SetPassword", + "ActiveSyncServer_CopyCredentials", + "ActiveSyncServer_DeletePassword", + "ActiveSyncServer_IsPasswordSet", + "ActiveSyncServer_CreateDataStoreLock", + "ActiveSyncServer_CloseDataStoreLock", + "ActiveSyncServer_SetConversationSyncEnabled", + "ActiveSyncServer_GetConversationSyncEnabled", + "ActiveSyncServer_SetUnifiedInboxEnabled", + "ActiveSyncServer_GetUnifiedInboxEnabled", + "ActiveSyncServer_GetUnifiedInboxServerValue", + "ActiveSyncServer_GetUserInfoForUnconfiguredAccount" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707460332240, + "Service": null, + "IsServiceRunning": false + }, + "22e5386d-8b12-4bf0-b0ec-6a1ea419e366": { + "Module": "NetEvtFwdr.exe", + "ModulePath": "C:\\Windows\\System32\\NetEvtFwdr.exe", + "InterfaceId": "22e5386d-8b12-4bf0-b0ec-6a1ea419e366", + "InterfaceStructOffset": 25488, + "ProceduresCount": 3, + "Procedures": [ + "RpcNetEventOpenSession", + "RpcNetEventReceiveData", + "RpcNetEventCloseSession" + ], + "ProcStackSize": 8, + "DispatchFunction": 140702640380160, + "Service": null, + "IsServiceRunning": false + }, + "64d1d045-f675-460b-8a94-570246b36dab": { + "Module": "ClipSVC.dll", + "ModulePath": "C:\\Windows\\System32\\ClipSVC.dll", + "InterfaceId": "64d1d045-f675-460b-8a94-570246b36dab", + "InterfaceStructOffset": 820464, + "ProceduresCount": 4, + "Procedures": [ + "rpcsClipOpen", + "rpcsClipClose", + "rpcsClipExecute", + "rpcsClipExecute2" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707382121168, + "Service": "ClipSVC", + "IsServiceRunning": false + }, + "f3f09ffd-fbcf-4291-944d-70ad6e0e73bb": { + "Module": "LogonController.dll", + "ModulePath": "C:\\Windows\\System32\\LogonController.dll", + "InterfaceId": "f3f09ffd-fbcf-4291-944d-70ad6e0e73bb", + "InterfaceStructOffset": 594528, + "ProceduresCount": 29, + "Procedures": [ + "WluirAbort", + "WluirSecureDisplayLocked", + "WluirDisplayLocked", + "WluirWaitForLockScreenDismiss", + "WluirDisplayMessage", + "WluirDisplayRequestCredentialsError", + "WluirDisplaySequentialLogonPrompt", + "WluirDisplaySecurityOptions", + "WluirDisplayStatus", + "WluirDisplayStatusOnCredentialPage", + "WluirDisplayTSDisconnectOptions", + "WluirDisplayWelcome", + "WluirNotifyIsReadyForDesktopSwitch", + "WluirPromptForCredentials", + "WluirReleaseContext", + "WluirClearUIState", + "WluirReportResult", + "WluirRequestCredentials", + "WluirDisplayTSDisconnectUI", + "WluirDisplayTSReconnectUI", + "WluirNotifyUserIsLoggedOn", + "WluirFinishOperation", + "WluirInformLogonUI", + "WluirDelayLocked", + "WluirSecureDelayLocked", + "WluirGetShutdownResolverInfo", + "WluirSignalShutdown", + "WluirPrepareWebDialog", + "WluirWaitForWebDialogComplete" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707094315136, + "Service": null, + "IsServiceRunning": false + }, + "51a227ae-825b-41f2-b4a9-1ac9557a1018": { + "Module": "keyiso.dll", + "ModulePath": "C:\\Windows\\System32\\keyiso.dll", + "InterfaceId": "51a227ae-825b-41f2-b4a9-1ac9557a1018", + "InterfaceStructOffset": 57344, + "ProceduresCount": 1, + "Procedures": [ + "s_TokenBindingGenerateTpmKeyFromSoftware" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707761406896, + "Service": "KeyIso", + "IsServiceRunning": true + }, + "1f53838b-693a-4bbb-99c9-b154f749b8a3": { + "Module": "audiodg.exe", + "ModulePath": "C:\\Windows\\System32\\audiodg.exe", + "InterfaceId": "1f53838b-693a-4bbb-99c9-b154f749b8a3", + "InterfaceStructOffset": 426720, + "ProceduresCount": 7, + "Procedures": [ + "AudioDGGetStartupStatus", + "AudioDGChallenge", + "AudioDGGetStreamVpoDescription", + "AudioDGSetStreamVpoPolicySchemas", + "AudioDGCloseStreamVpo", + "AudioDGGetDeviceGraphWnfStateName", + "AudioDGGetVpoFromVpoContext" + ], + "ProcStackSize": 48, + "DispatchFunction": 140702252390464, + "Service": null, + "IsServiceRunning": false + }, + "09c76598-1491-4810-bbb0-7f403a2ab7ea": { + "Module": "winhttp.dll", + "ModulePath": "C:\\Windows\\System32\\winhttp.dll", + "InterfaceId": "09c76598-1491-4810-bbb0-7f403a2ab7ea", + "InterfaceStructOffset": 806512, + "ProceduresCount": 3, + "Procedures": [ + "s_PacScriptWorkerOpenSiteRpc", + "s_PacScriptWorkerCloseSiteRpc", + "s_PacScriptWorkerGetProxyRpc" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708017922496, + "Service": "WinHttpAutoProxySvc", + "IsServiceRunning": true + }, + "f19c345c-5e00-4cb4-b1d1-eff9ea31b166": { + "Module": "DeviceSetupManager.dll", + "ModulePath": "C:\\Windows\\System32\\DeviceSetupManager.dll", + "InterfaceId": "f19c345c-5e00-4cb4-b1d1-eff9ea31b166", + "InterfaceStructOffset": 168032, + "ProceduresCount": 4, + "Procedures": [ + "DsmRpcInstallDevice", + "DsmRpcRemoveDevice", + "DsmRpcSetServicePaused", + "DsmRpcGetServiceInfo" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707581087696, + "Service": "DsmSvc", + "IsServiceRunning": false + }, + "6b06753b-9073-4cfd-ba89-12af04bec9eb": { + "Module": "TimeBrokerServer.dll", + "ModulePath": "C:\\Windows\\System32\\TimeBrokerServer.dll", + "InterfaceId": "6b06753b-9073-4cfd-ba89-12af04bec9eb", + "InterfaceStructOffset": 118976, + "ProceduresCount": 5, + "Procedures": [ + "TbThQueryEventState", + "TbThSimulatePowerState", + "TbThSimulatePsmQuantumStart", + "TbThSimulateExpireEvent", + "TbThSimulateChangeLockScreen" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708098226400, + "Service": "TimeBrokerSvc", + "IsServiceRunning": true + }, + "8be456ec-9244-4d10-88e8-1ddf1baa9ade": { + "Module": "PhoneService.dll", + "ModulePath": "C:\\Windows\\System32\\PhoneService.dll", + "InterfaceId": "8be456ec-9244-4d10-88e8-1ddf1baa9ade", + "InterfaceStructOffset": 780672, + "ProceduresCount": 85, + "Procedures": [ + "PhoneSvcImpl_PhoneRpcDial", + "PhoneSvcImpl_PhoneRpcEnd", + "PhoneSvcImpl_PhoneRpcSwap", + "PhoneSvcImpl_PhoneRpcHold", + "PhoneSvcImpl_PhoneRpcFlash", + "PhoneSvcImpl_PhoneRpcConference", + "PhoneSvcImpl_PhoneRpcPrivate", + "PhoneSvcImpl_PhoneRpcSendDtmf", + "PhoneSvcImpl_PhoneRpcSendDtmfStart", + "PhoneSvcImpl_PhoneRpcSendDtmfStop", + "PhoneSvcImpl_PhoneRpcAcceptIncoming", + "PhoneSvcImpl_PhoneRpcRejectIncomingEx", + "PhoneSvcImpl_PhoneRpcDropAccept", + "PhoneSvcImpl_PhoneRpcGetContactPictureHandle", + "PhoneSvcImpl_PhoneRpcGetCallInfo", + "PhoneSvcImpl_PhoneRpcGetState", + "PhoneSvcImpl_PhoneRpcGetCallCounts", + "PhoneSvcImpl_PhoneRpcGetProviderLineInfo", + "PhoneSvcImpl_PhoneRpcGetProviderLineServiceInfo", + "PhoneSvcImpl_PhoneRpcGetProviderLineLockInfo", + "PhoneSvcImpl_PhoneRpcModifyLineSetting", + "PhoneSvcImpl_PhoneRpcSendRealTimeTextData", + "PhoneSvcImpl_PhoneRpcAcceptUpgradingRealTimeTextCall", + "PhoneSvcImpl_PhoneRpcUpgradeToRealTimeTextCall", + "PhoneSvcImpl_PhoneRpcDowngradeFromRealTimeTextCall", + "PhoneSvcImpl_PhoneRpcGetAudioRouting", + "PhoneSvcImpl_PhoneRpcSetAudioRouting", + "PhoneSvcImpl_PhoneRpcSetMute", + "PhoneSvcImpl_PhoneRpcSetBluetoothHfpCallAudioTransfer", + "PhoneSvcImpl_PhoneRpcClearIdleCallsFromController", + "PhoneSvcImpl_PhoneRpcIsDtmfWaitPending", + "PhoneSvcImpl_PhoneRpcExitEmergencyMode", + "PhoneSvcImpl_PhoneRpcGetCellularApiComponentInfo", + "PhoneSvcImpl_PhoneRpcGetVoicemailNumberAndOverrideInfo", + "PhoneSvcImpl_PhoneRpcInitiateRetrievalOfCIDRestrictionSupport", + "PhoneSvcImpl_PhoneRpcRefreshCallForwardingState", + "PhoneSvcImpl_PhoneRpcGetServiceProcessId", + "PhoneSvcImpl_PhoneRpcStartVoicemailSync", + "PhoneSvcImpl_PhoneRpcSaveVvmPassword", + "PhoneSvcImpl_PhoneRpcGetSupportsLocalVvmConfig", + "PhoneSvcImpl_PhoneRpcActivateVisualVoicemail", + "PhoneSvcImpl_PhoneRpcDeactivateVisualVoicemail", + "PhoneSvcImpl_PhoneRpcGetVisualVoicemailAccessorInfo", + "PhoneSvcImpl_PhoneRpcGetVisualVoicemailBranding", + "PhoneSvcImpl_PhoneRpcMapIddPrefixToPlus", + "PhoneSvcImpl_PhoneRpcGetAssistedDialNumber", + "PhoneSvcImpl_PhoneRpcGetAssistedDialSetting", + "PhoneSvcImpl_PhoneRpcGetGlobalAvailableVerbs", + "PhoneSvcImpl_PhoneRpcGetNetworkAlertText", + "PhoneSvcImpl_PhoneRpcIsVvmSetupComplete", + "PhoneSvcImpl_PhoneRpcMarkVvmSetupComplete", + "PhoneSvcImpl_PhoneRpcReinitiateCallerIdLookup", + "PhoneSvcImpl_PhoneRpcGetPreferredCallUpgradeLine", + "PhoneSvcImpl_PhoneRpcSetPreferredCallUpgradeLine", + "PhoneSvcImpl_PhoneRpcInitiateCallUpgrade", + "PhoneSvcImpl_PhoneRpcIsVoiceRoamingRestrictionActive", + "PhoneSvcImpl_PhoneRpcSetForegroundLine", + "PhoneSvcImpl_PhoneRpcGetAggregateBranding", + "PhoneSvcImpl_PhoneRpcGetBrandingText", + "PhoneSvcImpl_PhoneRpcSetReminderInfo", + "PhoneSvcImpl_PhoneRpcConfirmNonSeamlessUpgrade", + "PhoneSvcImpl_PhoneRpcCancelNonSeamlessUpgrade", + "PhoneSvcImpl_PhoneRpcSetLocalVideo", + "PhoneSvcImpl_PhoneRpcAddVideo", + "PhoneSvcImpl_PhoneRpcDropVideo", + "PhoneSvcImpl_PhoneRpcAcceptVideo", + "PhoneSvcImpl_PhoneRpcRejectVideo", + "PhoneSvcImpl_PhoneRpcSetVideoPaused", + "PhoneSvcImpl_PhoneRpcRefreshVideoCallingSetting", + "PhoneSvcImpl_PhoneRpcIsVideoCallingSwitchActionable", + "PhoneSvcImpl_PhoneRpcSetActiveAppByType", + "PhoneSvcImpl_PhoneRpcGetAppListByType", + "PhoneSvcImpl_PhoneRpcSetActiveSpamFilterApp", + "PhoneSvcImpl_PhoneRpcHandleAppUninstallByType", + "PhoneSvcImpl_PhoneRpcGetRecordingState", + "PhoneSvcImpl_PhoneRpcStartRecording", + "PhoneSvcImpl_PhoneRpcPauseRecording", + "PhoneSvcImpl_PhoneRpcFinishRecording", + "PhoneSvcImpl_PhoneRpcRefreshEcbmState", + "PhoneSvcImpl_PhoneRpcGetVideoCapabilitySharingSettings", + "PhoneSvcImpl_PhoneRpcSetVideoCapabilitySharingSettings", + "PhoneSvcImpl_PhoneRpcExplicitCallTransfer", + "PhoneSvcImpl_PhoneRpcMarkDataAffinityNotificationSeen", + "PhoneSvcImpl_ReceivedSystemNotificationCallbackPayload", + "PhoneSvcImpl_RpcRetrieveSystemNotificationCallbackPayload" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707094323776, + "Service": "PhoneSvc", + "IsServiceRunning": false + }, + "e0606e56-2380-422f-a66f-ae6b71b85832": { + "Module": "FsIso.exe", + "ModulePath": "C:\\Windows\\System32\\FsIso.exe", + "InterfaceId": "e0606e56-2380-422f-a66f-ae6b71b85832", + "InterfaceStructOffset": 62960, + "ProceduresCount": 8, + "Procedures": [ + "RpcCloseSecureSection", + "RpcCopySecureSection", + "RpcCreateSecureSection", + "RpcDestroyFsIsoConnection", + "RpcEstablishFsIsoConnection", + "RpcCreateMJPEGSession", + "RpcDecodeOneMJPGFrameSecure", + "RpcDeleteMJPEGSession" + ], + "ProcStackSize": 24, + "DispatchFunction": 140695587203136, + "Service": null, + "IsServiceRunning": false + }, + "0361ae94-0316-4c6c-8ad8-c594375800e2": { + "Module": "psmsrv.dll", + "ModulePath": "C:\\Windows\\System32\\psmsrv.dll", + "InterfaceId": "0361ae94-0316-4c6c-8ad8-c594375800e2", + "InterfaceStructOffset": 168864, + "ProceduresCount": 8, + "Procedures": [ + "PsmSrvQueryCurrentApplications", + "PsmSrvQueryApplicationHosts", + "PsmSrvQueryApplicationHostExecutionState", + "PsmSrvQueryApplicationHostJob", + "PsmSrvConnect", + "PsmSrvDisconnect", + "PsmSrvSubscribeToNotifications", + "PsmSrvUnsubscribeFromNotifications" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708134220512, + "Service": "BrokerInfrastructure", + "IsServiceRunning": true + }, + "2d98a740-581d-41b9-aa0d-a88b9d5ce938": { + "Module": "bisrv.dll", + "ModulePath": "C:\\Windows\\System32\\bisrv.dll", + "InterfaceId": "2d98a740-581d-41b9-aa0d-a88b9d5ce938", + "InterfaceStructOffset": 551872, + "ProceduresCount": 28, + "Procedures": [ + "RBiSrvActivateDeferredWorkItem", + "RBiSrvActivateInBackground", + "RBiSrvActivateWorkItem", + "RBiSrvAssociateActivationProxy", + "RBiSrvAssociateApplicationExtensionClass", + "RBiSrvCancelWorkItem", + "RBiSrvCreateEvent", + "RBiSrvCreateEventForPackageName", + "RBiSrvDeleteEvent", + "RBiSrvDisassociateWorkItem", + "RBiSrvDiscardPendingActivations", + "RBiSrvEnumerateBrokeredEvents", + "RBiSrvEnumerateUserContexts", + "RBiSrvEnumerateUserSessions", + "RBiSrvEnumerateWorkItemsForPackageName", + "RBiPtSrvGetStatusStateNameFromBrokerEventId", + "RBiSrvQueryBrokeredEvent", + "RBiSrvQuerySystemStateBroadcastChannels", + "RBiSrvQueryUserContext", + "RBiSrvQueryUserSession", + "RBiSrvQueryWorkItem", + "RBiPtSrvQueryWorkItemStatusStateName", + "RBiSrvSignalEvent", + "RBiSrvSignalMultipleEvents", + "RBiSrvSignalTriggerEvent", + "RBiSrvUpdateEventParameters", + "RBiSrvUpdateEventFlags", + "RBiSrvUpdateEventInformation" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708131127056, + "Service": null, + "IsServiceRunning": false + }, + "a0bc4698-b8d7-4330-a28f-7709e18b6108": { + "Module": "Sens.dll", + "ModulePath": "C:\\Windows\\System32\\Sens.dll", + "InterfaceId": "a0bc4698-b8d7-4330-a28f-7709e18b6108", + "InterfaceStructOffset": 49344, + "ProceduresCount": 3, + "Procedures": [ + "RPC_SensNotifyWinlogonEvent", + "RPC_SensNotifyRasEvent", + "RPC_SensNotifyNetconEvent" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708049295712, + "Service": "SENS", + "IsServiceRunning": true + }, + "a4b04892-b1e0-5ca3-a5e4-098751b2b4c2": { + "Module": "vmsp.exe", + "ModulePath": "C:\\Windows\\System32\\vmsp.exe", + "InterfaceId": "a4b04892-b1e0-5ca3-a5e4-098751b2b4c2", + "InterfaceStructOffset": 113280, + "ProceduresCount": 10, + "Procedures": [ + "RpcVmspOpenSecureHandle", + "RpcVmspCloseSecureHandle", + "RpcVTpmInitialize", + "RpcVTpmShutdown", + "RpcVTpmExecuteCommand", + "RpcVTpmGetRuntimeSize", + "RpcVTpmGetRuntimeState", + "RpcVTpmSetCancelFlag", + "Deserialize", + "RpcVTpmCreateReport" + ], + "ProcStackSize": 72, + "DispatchFunction": 140701201367168, + "Service": null, + "IsServiceRunning": false + }, + "fc13257d-5567-4dea-898d-c6f9c48415a0": { + "Module": "mqqm.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-msmq-queuemanager-core_31bf3856ad364e35_10.0.18362.1977_none_8d1646dec2a87b94\\mqqm.dll", + "InterfaceId": "fc13257d-5567-4dea-898d-c6f9c48415a0", + "InterfaceStructOffset": 1028128, + "ProceduresCount": 1, + "Procedures": [ + "R_ProcessHTTPRequest" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707093564560, + "Service": null, + "IsServiceRunning": false + }, + "acd792e4-5239-48b6-8baf-7d0a79a64ac0": { + "Module": "SmsRouterSvc.dll", + "ModulePath": "C:\\Windows\\System32\\SmsRouterSvc.dll", + "InterfaceId": "acd792e4-5239-48b6-8baf-7d0a79a64ac0", + "InterfaceStructOffset": 427728, + "ProceduresCount": 16, + "Procedures": [ + "RpcSmsRouter_GetRegistrationList", + "RpcSmsRouter_RegisterForMessagesPersistent", + "RpcSmsRouter_UnregisterForMessagesPersistent", + "RpcSmsRouter_RegisterForMessagesTransient", + "RpcSmsRouter_UnregisterForMessagesTransient", + "RpcSmsRouter_GetMessageAvailableEvent", + "RpcSmsRouter_GetMessage", + "RpcSmsRouter_AcknowledgeMessage", + "RpcSmsRouter_SendMessage", + "RpcSmsRouter_SendMessageClose", + "SetBroadcastConfiguration", + "SetBroadcastConfiguration", + "SetBroadcastConfiguration", + "RpcSmsRouter_SetSmscAddress", + "RpcSmsRouter_GetSmscAddress", + "RpcSmsRouter_GetSmsDeviceStatusEvent" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707580621328, + "Service": "SmsRouter", + "IsServiceRunning": false + }, + "906b0ce0-c70b-1067-b317-00dd010662da": { + "Module": "msdtcprx.dll", + "ModulePath": "C:\\Windows\\System32\\msdtcprx.dll", + "InterfaceId": "906b0ce0-c70b-1067-b317-00dd010662da", + "InterfaceStructOffset": 533696, + "ProceduresCount": 8, + "Procedures": [ + "Poke", + "BuildContext", + "NegotiateResources", + "SendReceive", + "TearDownContext", + "BeginTearDown", + "PokeW", + "BuildContextW" + ], + "ProcStackSize": 104, + "DispatchFunction": 140707789486384, + "Service": null, + "IsServiceRunning": false + }, + "98716d03-89ac-44c7-bb8c-285824e51c4a": { + "Module": "srvsvc.dll", + "ModulePath": "C:\\Windows\\System32\\srvsvc.dll", + "InterfaceId": "98716d03-89ac-44c7-bb8c-285824e51c4a", + "InterfaceStructOffset": 192704, + "ProceduresCount": 6, + "Procedures": [ + "XsOpenPrinter", + "XsClosePrinter", + "XsAddJob", + "XsScheduleJob", + "XsProcessPnp", + "XsProcDownLevelAPI" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707955985056, + "Service": "LanmanServer", + "IsServiceRunning": true + }, + "6982a06e-5fe2-46b1-b39c-a2c545bfa069": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "6982a06e-5fe2-46b1-b39c-a2c545bfa069", + "InterfaceStructOffset": 563616, + "ProceduresCount": 5, + "Procedures": [ + "HamRpcSrvConnectFullTrust", + "HamRpcSrvDisconnect", + "HamRpcSrvFullTrustOpenPackageHandle", + "HamRpcSrvDebugClosePackageHandle", + "HamRpcSrvDebugTerminatePackage" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708133772720, + "Service": null, + "IsServiceRunning": false + }, + "8bfc3be1-6def-4e2d-af74-7c47cd0ade4a": { + "Module": "bisrv.dll", + "ModulePath": "C:\\Windows\\System32\\bisrv.dll", + "InterfaceId": "8bfc3be1-6def-4e2d-af74-7c47cd0ade4a", + "InterfaceStructOffset": 551776, + "ProceduresCount": 17, + "Procedures": [ + "RBiSrvActivateWorkItemForUser", + "RBiSrvChangeApplicationStateForPackageNameForUser", + "RBiSrvChangeApplicationStateForPsmKeyForUser", + "RBiSrvChangeUserState", + "RBiSrvEnumerateWorkItemsForPackageNameAndUser", + "RBiSrvGetActiveBackgroundTasksEventForUser", + "RBiSrvGetCancellationTimeoutInMs", + "RBiSrvIsApplicationTerminateSensitiveForUser", + "RBiSrvNotifyEndSession", + "RBiSrvNotifyNewSession", + "RBiSrvNotifyNewSessionComplete", + "RBiSrvNotifyNewUser", + "RBiSrvQueryWorkItemForUser", + "RBiSrvResetActiveUserForPackage", + "RBiSrvSetActiveUserForPackage", + "RBiSrvTerminateApplicationHostForUser", + "RBiSrvUpdateBackgroundAccessApplicationsForUser" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708131126304, + "Service": null, + "IsServiceRunning": false + }, + "dd59071b-3215-4c59-8481-972edadc0f6a": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "dd59071b-3215-4c59-8481-972edadc0f6a", + "InterfaceStructOffset": 546672, + "ProceduresCount": 10, + "Procedures": [ + "CrmRpcSrvRegister", + "CrmRpcSrvUnregister", + "CrmRpcSrvActivityAllocate", + "CrmRpcSrvActivityQueryWindowClosedReasons", + "CrmRpcSrvActivityFree", + "CrmRpcSrvActivityStart", + "CrmRpcSrvActivityRenew", + "CrmRpcSrvActivityStop", + "CrmRpcSrvActivityWindowClosedReasonSubscribe", + "CrmRpcSrvActivityWindowClosedReasonUnsubscribe" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708133530944, + "Service": null, + "IsServiceRunning": false + }, + "a398e520-d59a-4bdd-aa7a-3c1e0303a511": { + "Module": "IKEEXT.DLL", + "ModulePath": "C:\\Windows\\System32\\IKEEXT.DLL", + "InterfaceId": "a398e520-d59a-4bdd-aa7a-3c1e0303a511", + "InterfaceStructOffset": 835664, + "ProceduresCount": 10, + "Procedures": [ + "IkeRpcIkeGetStatistics", + "IkeRpcIkeSACreateEnumHandle", + "IkeRpcIkeSAEnum", + "IkeRpcIkeSADestroyEnumHandle", + "IkeRpcIkeSADeleteById", + "IkeRpcIkeSAGetById", + "IkeRpcIkeSaDbGetSecurityInfo", + "IkeRpcIkeSaDbSetSecurityInfo", + "IkeRpcIkeSaUpdatePreferredAddressesAsync", + "IkeRpcIkeSaUpdateAdditionalAddressesAsync" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707093787648, + "Service": "IKEEXT", + "IsServiceRunning": false + }, + "1495a2be-b7a8-4299-9d3b-8825e5bcbfb9": { + "Module": "webauthn.dll", + "ModulePath": "C:\\Windows\\System32\\webauthn.dll", + "InterfaceId": "1495a2be-b7a8-4299-9d3b-8825e5bcbfb9", + "InterfaceStructOffset": 343568, + "ProceduresCount": 1, + "Procedures": [ + "s_SSCtapCommand" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707993672896, + "Service": null, + "IsServiceRunning": false + }, + "fdd45924-784a-499c-aee9-0813850ce182": { + "Module": "DiagnosticInvoker.dll", + "ModulePath": "C:\\Windows\\System32\\DiagnosticInvoker.dll", + "InterfaceId": "fdd45924-784a-499c-aee9-0813850ce182", + "InterfaceStructOffset": 75824, + "ProceduresCount": 1, + "Procedures": [ + "Server_NotifyProgress" + ], + "ProcStackSize": 8, + "DispatchFunction": 140707880915648, + "Service": null, + "IsServiceRunning": false + }, + "2579ff35-0ab0-4e5a-88fa-1d88c4e0cb92": { + "Module": "crypttpmeksvc.dll", + "ModulePath": "C:\\Windows\\System32\\crypttpmeksvc.dll", + "InterfaceId": "2579ff35-0ab0-4e5a-88fa-1d88c4e0cb92", + "InterfaceStructOffset": 40960, + "ProceduresCount": 5, + "Procedures": [ + "s_SSTpmEndorsementKeyGetInfo", + "s_SSTpmEndorsementKeyDecryptChallenge", + "s_SSTpmAttestationCapable", + "s_SSTpmGetAttestationForAik", + "s_SSTpmGetManufacturerInfo" + ], + "ProcStackSize": 80, + "DispatchFunction": 140707994238576, + "Service": null, + "IsServiceRunning": false + }, + "63fbe424-2029-11d1-8db8-00aa004abd5e": { + "Module": "Sens.dll", + "ModulePath": "C:\\Windows\\System32\\Sens.dll", + "InterfaceId": "63fbe424-2029-11d1-8db8-00aa004abd5e", + "InterfaceStructOffset": 49440, + "ProceduresCount": 3, + "Procedures": [ + "RPC_IsNetworkAlive", + "RPC_IsDestinationReachableA", + "RPC_IsDestinationReachableA" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708049267824, + "Service": "SENS", + "IsServiceRunning": true + }, + "7f1317a8-4dea-4fa2-a551-df5516ff8879": { + "Module": "dpapisrv.dll", + "ModulePath": "C:\\Windows\\System32\\dpapisrv.dll", + "InterfaceId": "7f1317a8-4dea-4fa2-a551-df5516ff8879", + "InterfaceStructOffset": 184512, + "ProceduresCount": 2, + "Procedures": [ + "s_LRpcSIDKeyProtect", + "s_LRpcSIDKeyUnprotect" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708143086592, + "Service": null, + "IsServiceRunning": false + }, + "2eb08e3e-639f-4fba-97b1-14f878961076": { + "Module": "gpsvc.dll", + "ModulePath": "C:\\Windows\\System32\\gpsvc.dll", + "InterfaceId": "2eb08e3e-639f-4fba-97b1-14f878961076", + "InterfaceStructOffset": 770144, + "ProceduresCount": 8, + "Procedures": [ + "Server_ProcessRefresh", + "Server_RegisterForNotification", + "Server_CheckRegisterForNotification", + "Server_LockPolicySection", + "Server_UnLockPolicySection", + "Server_GetGroupPolicyObjectList", + "Server_GetAppliedGroupPolicyObjectList", + "Server_GenerateGroupPolicyNotification" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707093628208, + "Service": "gpsvc", + "IsServiceRunning": false + }, + "1bddb2a6-c0c3-41be-8703-ddbdf4f0e80a": { + "Module": "dot3svc.dll", + "ModulePath": "C:\\Windows\\System32\\dot3svc.dll", + "InterfaceId": "1bddb2a6-c0c3-41be-8703-ddbdf4f0e80a", + "InterfaceStructOffset": 196960, + "ProceduresCount": 21, + "Procedures": [ + "RpcOpenHandle", + "RpcCloseHandle", + "RpcEnumInterfaces", + "RpcSetInterface", + "RpcGetInterfaceState", + "RpcReConnect", + "RpcRegisterNotification", + "RpcAsyncGetNotification", + "RpcSetProfile", + "RpcGetProfile", + "RpcGetCurrentProfile", + "RpcDeleteProfile", + "RpcUIResponse", + "RpcQueryUIRequest", + "RpcSetProfileEapUserData", + "RpcAsyncDoPlap", + "RpcQueryPlapCredentials", + "RpcCancelPlap", + "RpcGetProfileEapUserDataInfo", + "RpcSetAutoConfigParameter", + "RpcQueryAutoConfigParameter" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707580982704, + "Service": "dot3svc", + "IsServiceRunning": false + }, + "75ef42c7-22f4-44a0-8200-9351cd316e01": { + "Module": "CExecSvc.exe", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_hyperv-compute-cont..utionservice-shared_31bf3856ad364e35_10.0.18362.1500_none_635326ad9114445f\\CExecSvc.exe", + "InterfaceId": "75ef42c7-22f4-44a0-8200-9351cd316e01", + "InterfaceStructOffset": 138752, + "ProceduresCount": 4, + "Procedures": [ + "CExecCreateProcess", + "CExecResizeConsole", + "CExecSignalProcess", + "CExecShutdownSystem" + ], + "ProcStackSize": 16, + "DispatchFunction": 140703104628976, + "Service": null, + "IsServiceRunning": false + }, + "7aeb6705-3ae6-471a-882d-f39c109edc12": { + "Module": "wcmsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wcmsvc.dll", + "InterfaceId": "7aeb6705-3ae6-471a-882d-f39c109edc12", + "InterfaceStructOffset": 768080, + "ProceduresCount": 3, + "Procedures": [ + "RpcSetOperatorDataplanStatus", + "RpcSetOperatorConnectionCost", + "RpcSetOperatorCycleData" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708019001776, + "Service": "Wcmsvc", + "IsServiceRunning": true + }, + "169c453b-5955-4672-be44-21f61e9ef18f": { + "Module": "ScDeviceEnum.dll", + "ModulePath": "C:\\Windows\\System32\\ScDeviceEnum.dll", + "InterfaceId": "169c453b-5955-4672-be44-21f61e9ef18f", + "InterfaceStructOffset": 142976, + "ProceduresCount": 2, + "Procedures": [ + "s_NgcCtnrEnumCreateNode", + "s_NgcCtnrEnumDeleteNode" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707581063232, + "Service": "ScDeviceEnum", + "IsServiceRunning": false + }, + "98e96949-bc59-47f1-92d1-8c25b46f85c7": { + "Module": "wlanext.exe", + "ModulePath": "C:\\Windows\\System32\\wlanext.exe", + "InterfaceId": "98e96949-bc59-47f1-92d1-8c25b46f85c7", + "InterfaceStructOffset": 81648, + "ProceduresCount": 15, + "Procedures": [ + "RpcDot11ExtIhvInitService", + "RpcDot11ExtIhvDeinitService", + "RpcDot11ExtIhvInitAdapter", + "RpcDot11ExtIhvDeinitAdapter", + "RpcDot11ExtIhvProcessSessionChange", + "RpcDot11ExtIhvIsUIRequestPending", + "RpcDot11ExtIhvPerformCapabilityMatch", + "RpcDot11ExtIhvValidateProfile", + "RpcDot11ExtIhvPerformPreAssociate", + "RpcDot11ExtIhvAdapterReset", + "RpcDot11ExtIhvCreateDiscoveryProfiles", + "RpcDot11ExtIhvProcessUIResponse", + "RpcDot11ExtIhvQueryUIRequest", + "RpcDot11ExtIhvOnexIndicateResult", + "RpcDot11ExtIhvControl" + ], + "ProcStackSize": 72, + "DispatchFunction": 140702830459824, + "Service": null, + "IsServiceRunning": false + }, + "ae987d31-12d4-450d-90ce-0d6e7cb483be": { + "Module": "tttracer.exe", + "ModulePath": "C:\\Windows\\System32\\tttracer.exe", + "InterfaceId": "ae987d31-12d4-450d-90ce-0d6e7cb483be", + "InterfaceStructOffset": 239808, + "ProceduresCount": 2, + "Procedures": [ + "RpcServerPassCommandLine", + "RpcServerRetrieveStatus" + ], + "ProcStackSize": 16, + "DispatchFunction": 140702201977872, + "Service": null, + "IsServiceRunning": false + }, + "714dc5c4-c5f6-466a-b037-a573c958031e": { + "Module": "eeprov.dll", + "ModulePath": "C:\\Windows\\System32\\eeprov.dll", + "InterfaceId": "714dc5c4-c5f6-466a-b037-a573c958031e", + "InterfaceStructOffset": 129088, + "ProceduresCount": 2, + "Procedures": [ + "PtRpcSetProcessTag", + "PtRpcWriteTelemetry" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707800202528, + "Service": null, + "IsServiceRunning": false + }, + "1a9134dd-7b39-45ba-ad88-44d01ca47f28": { + "Module": "mqqm.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-msmq-queuemanager-core_31bf3856ad364e35_10.0.18362.1977_none_8d1646dec2a87b94\\mqqm.dll", + "InterfaceId": "1a9134dd-7b39-45ba-ad88-44d01ca47f28", + "InterfaceStructOffset": 1025248, + "ProceduresCount": 16, + "Procedures": [ + "RemoteRead_v1_0_S_GetServerPort", + "RemoteRead_v1_0_S_GetVersion", + "RemoteRead_v1_0_S_OpenQueue", + "RemoteRead_v1_0_S_CloseQueue", + "RemoteRead_v1_0_S_CreateCursor", + "RemoteRead_v1_0_S_CloseCursor", + "RemoteRead_v1_0_S_PurgeQueue", + "RemoteRead_v1_0_S_StartReceive", + "RemoteRead_v1_0_S_CancelReceive", + "RemoteRead_v1_0_S_EndReceive", + "RemoteRead_v1_0_S_MoveMessage", + "RemoteRead_v1_0_S_OpenQueueForMove", + "RemoteRead_v1_0_S_QMEnlistRemoteTransaction", + "RemoteRead_v1_0_S_StartTransactionalReceive", + "RemoteRead_v1_0_S_SetUserAcknowledgementClass", + "RemoteRead_v1_0_S_EndReceiveSynch" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707093646000, + "Service": null, + "IsServiceRunning": false + }, + "f5cc5a18-4264-101a-8c59-08002b2f8426": { + "Module": "ntdsai.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-d..toryservices-ntdsai_31bf3856ad364e35_10.0.18362.1916_none_fe1eba331c36e95d\\ntdsai.dll", + "InterfaceId": "f5cc5a18-4264-101a-8c59-08002b2f8426", + "InterfaceStructOffset": 4346288, + "ProceduresCount": 21, + "Procedures": [ + "NspiBind", + "NspiUnbind", + "NspiUpdateStat", + "NspiQueryRows", + "NspiSeekEntries", + "NspiGetMatches", + "NspiResortRestriction", + "NspiDNToEph", + "NspiGetPropList", + "NspiGetProps", + "NspiCompareDNTs", + "NspiModProps", + "NspiGetHierarchyInfo", + "NspiGetTemplateInfo", + "NspiModLinkAtt", + "NspiDeleteEntries", + "NspiQueryColumns", + "NspiGetNamesFromIDs", + "NspiGetIDsFromNames", + "NspiResolveNames", + "NspiResolveNamesW" + ], + "ProcStackSize": 64, + "DispatchFunction": 140706771718336, + "Service": null, + "IsServiceRunning": false + }, + "ade78933-5718-4476-9ce3-6be8cc4d1cc8": { + "Module": "webplatstorageserver.dll", + "ModulePath": "C:\\Windows\\System32\\webplatstorageserver.dll", + "InterfaceId": "ade78933-5718-4476-9ce3-6be8cc4d1cc8", + "InterfaceStructOffset": 934336, + "ProceduresCount": 14, + "Procedures": [ + "s_CreateCacheStorage", + "s_CacheStorage_open", + "s_CacheStorage_has", + "s_CacheStorage_delete", + "s_CacheStorage_match", + "s_CacheStorage_keys", + "s_CacheStorage_close", + "s_Cache_put", + "s_Cache_put_complete", + "s_Cache_match", + "s_Cache_matchAll", + "s_Cache_delete", + "s_Cache_keys", + "s_Cache_close" + ], + "ProcStackSize": 16, + "DispatchFunction": 140706992637504, + "Service": null, + "IsServiceRunning": false + }, + "4a51dcf2-5c3a-4dd2-84db-c3802ee7f9b7": { + "Module": "ntdsai.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-d..toryservices-ntdsai_31bf3856ad364e35_10.0.18362.1916_none_fe1eba331c36e95d\\ntdsai.dll", + "InterfaceId": "4a51dcf2-5c3a-4dd2-84db-c3802ee7f9b7", + "InterfaceStructOffset": 4346192, + "ProceduresCount": 11, + "Procedures": [ + "IDL_SsiInitialize", + "IDL_SsiReleaseHandle", + "IDL_SsiRegisterNotification", + "IDL_SsiUnRegisterNotification", + "IDL_SsiQueryRealmList", + "IDL_SsiSearchByIdentityKey", + "IDL_SsiQueryRealmInformation", + "IDL_SsiQueryRealmInformation", + "IDL_SsiQueryPrincipalInformation", + "IDL_SsiSetPrincipalInformation", + "IDL_SsiIsPrincipalKnown" + ], + "ProcStackSize": 40, + "DispatchFunction": 140706770304064, + "Service": null, + "IsServiceRunning": false + }, + "910562c3-ebd9-46b9-baba-1d45842a0ceb": { + "Module": "audiosrv.dll", + "ModulePath": "C:\\Windows\\System32\\audiosrv.dll", + "InterfaceId": "910562c3-ebd9-46b9-baba-1d45842a0ceb", + "InterfaceStructOffset": 1381216, + "ProceduresCount": 12, + "Procedures": [ + "s_pbmReportAppInteractivityChange", + "Commit", + "s_pbmAllowMediaPlaybackForApp", + "s_CapabilityAccessManagerNotification", + "s_pbmRegisterAppManagerNotification", + "s_pbmUnregisterAppManagerNotification", + "s_pbmReportAppClosing", + "s_pbmReportHostedAppStateChange", + "s_SetScreenReaderState", + "s_pbmSwitchSoftNonInteractiveAppsToHardNonInteractive", + "s_pbmReportApplicationState", + "s_pbmSetApplicationViewPosition" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708026803328, + "Service": "Audiosrv", + "IsServiceRunning": true + }, + "4719c6c2-b769-48c6-9caf-392f8e6ea642": { + "Module": "BthAvrcpAppSvc.dll", + "ModulePath": "C:\\Windows\\System32\\BthAvrcpAppSvc.dll", + "InterfaceId": "4719c6c2-b769-48c6-9caf-392f8e6ea642", + "InterfaceStructOffset": 46624, + "ProceduresCount": 5, + "Procedures": [ + "BthAvrcpApp_GetAppDescription", + "BthAvrcpApp_OpenConnection", + "BthAvrcpApp_StartPlayback", + "BthAvrcpApp_SendMessage", + "BthAvrcpApp_CloseConnection" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707880907904, + "Service": null, + "IsServiceRunning": false + }, + "f6c98708-c7b8-4919-887c-2ce66e78b9a0": { + "Module": "XblGameSave.dll", + "ModulePath": "C:\\Windows\\System32\\XblGameSave.dll", + "InterfaceId": "f6c98708-c7b8-4919-887c-2ce66e78b9a0", + "InterfaceStructOffset": 871104, + "ProceduresCount": 1, + "Procedures": [ + "svcScheduleTaskOperation" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707093326144, + "Service": "XblGameSave", + "IsServiceRunning": false + }, + "ae58b386-c914-4a73-ba5c-2c3e2749e478": { + "Module": "PhoneService.dll", + "ModulePath": "C:\\Windows\\System32\\PhoneService.dll", + "InterfaceId": "ae58b386-c914-4a73-ba5c-2c3e2749e478", + "InterfaceStructOffset": 783920, + "ProceduresCount": 1, + "Procedures": [ + "PhoneSvcImpl_RpcClearNewVoicemailCount" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707094325664, + "Service": "PhoneSvc", + "IsServiceRunning": false + }, + "484809d6-4239-471b-b5bc-61df8c23ac48": { + "Module": "lsm.dll", + "ModulePath": "C:\\Windows\\System32\\lsm.dll", + "InterfaceId": "484809d6-4239-471b-b5bc-61df8c23ac48", + "InterfaceStructOffset": 480176, + "ProceduresCount": 21, + "Procedures": [ + "RpcOpenSession", + "RpcCloseSession", + "RpcConnect", + "RpcDisconnect", + "RpcLogoff", + "RpcGetUserName", + "RpcGetTerminalName", + "RpcGetState", + "RpcIsSessionDesktopLocked", + "RpcShowMessageBox", + "RpcGetTimes", + "RpcGetSessionCounters", + "RpcGetSessionInformation", + "RpcSwitchToServicesSession", + "RpcRevertFromServicesSession", + "RpcGetLoggedOnCount", + "RpcGetSessionType", + "RpcGetSessionInformationEx", + "RpcIsTerminalRemote", + "RpcIsBoundToCacheTerminal", + "RpcConnectAndLockTargetDesktop" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708131754464, + "Service": "LSM", + "IsServiceRunning": true + }, + "db2ce634-191d-42af-a28c-16be97924ca7": { + "Module": "SensorService.dll", + "ModulePath": "C:\\Windows\\System32\\SensorService.dll", + "InterfaceId": "db2ce634-191d-42af-a28c-16be97924ca7", + "InterfaceStructOffset": 375152, + "ProceduresCount": 10, + "Procedures": [ + "RSensorBrokerServerClearMotionHistory", + "RSensorBrokerServerGetActivityHistory", + "RSensorBrokerServerGetActivityTriggerReports", + "RSensorBrokerServerGetPedometerHistory", + "RSensorBrokerServerGetPedometerTriggerReports", + "RSensorBrokerServerEnableDisableProximityMonitoringForDisplay", + "RSensorBrokerServerCreateProximityContextHandle", + "RSensorBrokerServerReleaseProximityContextHandle", + "RSensorBrokerServerGetProximityTriggerReports", + "RSensorBrokerServerGetFloorElevationTriggerReports" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707580902032, + "Service": "SensorService", + "IsServiceRunning": false + }, + "91fd044b-902f-42c7-a945-6861bcf9309c": { + "Module": "moshost.dll", + "ModulePath": "C:\\Windows\\System32\\moshost.dll", + "InterfaceId": "91fd044b-902f-42c7-a945-6861bcf9309c", + "InterfaceStructOffset": 55584, + "ProceduresCount": 9, + "Procedures": [ + "MapsStorageSvcOpen", + "MapsStorageSvcClose", + "MapsStorageSvcGetCurrentLocation", + "MapsStorageSvcGetLocations", + "MapsStorageSvcGetMigrationState", + "MapsStorageSvcValidateLocationAsync", + "MapsStorageSvcGetDataDirectory", + "MapsStorageSvcUseDefaultExternalStorage", + "MapsStorageSvcQueueSwitchToDefaultExternalStorage" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707880922096, + "Service": "MapsBroker", + "IsServiceRunning": false + }, + "c80066a8-7579-44fc-b9b2-8466930791b0": { + "Module": "umrdp.dll", + "ModulePath": "C:\\Windows\\System32\\umrdp.dll", + "InterfaceId": "c80066a8-7579-44fc-b9b2-8466930791b0", + "InterfaceStructOffset": 272000, + "ProceduresCount": 1, + "Procedures": [ + "RpcPrintDrvGetInfo" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708067585184, + "Service": "UmRdpService", + "IsServiceRunning": true + }, + "5267aaba-4f49-4653-8e26-d1e11f3f2ad9": { + "Module": "termsrv.dll", + "ModulePath": "C:\\Windows\\System32\\termsrv.dll", + "InterfaceId": "5267aaba-4f49-4653-8e26-d1e11f3f2ad9", + "InterfaceStructOffset": 755296, + "ProceduresCount": 11, + "Procedures": [ + "RpcCreateVirtualChannel", + "Connect", + "RpcPopSecurityDialog", + "RpcGetInitialApplication", + "RpcGetConnectionProperty", + "Connect", + "RpcVerify", + "RpcCreateChildSessionTransport", + "RpcRcmShadow2", + "RpcShadowAccessCheck", + "RpcShadowStop2" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708119094384, + "Service": "TermService", + "IsServiceRunning": true + }, + "99fcfec4-5260-101b-bbcb-00aa0021347a": { + "Module": "rpcss.dll", + "ModulePath": "C:\\Windows\\System32\\rpcss.dll", + "InterfaceId": "99fcfec4-5260-101b-bbcb-00aa0021347a", + "InterfaceStructOffset": 960080, + "ProceduresCount": 6, + "Procedures": [ + "ResolveOxid", + "SimplePing", + "ComplexPing", + "ServerAlive", + "ResolveOxid2", + "ServerAlive2" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708135229568, + "Service": "RpcSs", + "IsServiceRunning": true + }, + "b1ef227e-dfa5-421e-82bb-67a6a129c496": { + "Module": "modernexecserver.dll", + "ModulePath": "C:\\Windows\\System32\\modernexecserver.dll", + "InterfaceId": "b1ef227e-dfa5-421e-82bb-67a6a129c496", + "InterfaceStructOffset": 324112, + "ProceduresCount": 11, + "Procedures": [ + "FmMuxSrvIsActivationBeingDebugged", + "FmMuxSrvIsForegroundActivation", + "FmMuxSrvGetForegroundActivationInstanceId", + "FmMuxSrvGetApplicationId", + "FmMuxSrvGetPackageFamilyName", + "FmMuxSrvGetPackageFullName", + "FmMuxSrvGetPSMKey", + "FmMuxSrvDehydrateApplication", + "FmMuxSrvSetAutoDehydrateFlag", + "FmMuxSrvGetAutoDehydrateFlag", + "FmMuxSrvReloadSettings" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707571598096, + "Service": null, + "IsServiceRunning": false + }, + "f0c68743-5631-4289-8aad-37e5e64d843f": { + "Module": "embeddedmodesvc.dll", + "ModulePath": "C:\\Windows\\System32\\embeddedmodesvc.dll", + "InterfaceId": "f0c68743-5631-4289-8aad-37e5e64d843f", + "InterfaceStructOffset": 124960, + "ProceduresCount": 3, + "Procedures": [ + "s_CreateContext", + "s_CloseContext", + "s_ActivatePackage" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707581090288, + "Service": "embeddedmode", + "IsServiceRunning": false + }, + "3a9ef155-691d-4449-8d05-09ad57031823": { + "Module": "schedsvc.dll", + "ModulePath": "C:\\Windows\\System32\\schedsvc.dll", + "InterfaceId": "3a9ef155-691d-4449-8d05-09ad57031823", + "InterfaceStructOffset": 477984, + "ProceduresCount": 7, + "Procedures": [ + "I_pSchRpcRegisterTask", + "I_pSchRpcEnumTasks", + "I_pSchRpcGetTaskInfo", + "I_pSchRpcAquireTaskStateNotificationsName", + "I_pAcquireBackgroundExecutionMode", + "I_pReleaseBackgroundExecutionMode", + "I_pSetTaskDisabledForCurrentUser" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708046653104, + "Service": "Schedule", + "IsServiceRunning": true + }, + "e7a216af-1ec1-447f-8d3f-a87278db564d": { + "Module": "vmcompute.exe", + "ModulePath": "C:\\Windows\\System32\\vmcompute.exe", + "InterfaceId": "e7a216af-1ec1-447f-8d3f-a87278db564d", + "InterfaceStructOffset": 2458432, + "ProceduresCount": 27, + "Procedures": [ + "HcsRpc_EnumerateSystems", + "HcsRpc_CreateSystem", + "HcsRpc_OpenSystem", + "HcsRpc_StartSystem", + "HcsRpc_ShutdownSystem", + "HcsRpc_TerminateSystem", + "HcsRpc_PauseSystem", + "HcsRpc_ResumeSystem", + "HcsRpc_SaveSystem", + "HcsRpc_GetSystemProperties", + "HcsRpc_ModifySystem", + "HcsRpc_RegisterSystemNotifications", + "HcsRpc_UnregisterSystemNotifications", + "HcsRpc_QuerySystemNotification", + "HcsRpc_CloseSystem", + "HcsRpc_CreateProcess", + "HcsRpc_OpenProcess", + "HcsRpc_SignalProcess", + "HcsRpc_GetProcessInfo", + "HcsRpc_GetProcessProperties", + "HcsRpc_ModifyProcess", + "HcsRpc_RegisterProcessNotifications", + "HcsRpc_UnregisterProcessNotifications", + "HcsRpc_QueryProcessNotification", + "HcsRpc_CloseProcess", + "HcsRpc_GetServiceProperties", + "HcsRpc_ModifyServiceSettings" + ], + "ProcStackSize": 32, + "DispatchFunction": 140697749985376, + "Service": "vmcompute", + "IsServiceRunning": true + }, + "8c7daf44-b6dc-11d1-9a4c-0020af6e7c57": { + "Module": "appmgmts.dll", + "ModulePath": "C:\\Windows\\System32\\appmgmts.dll", + "InterfaceId": "8c7daf44-b6dc-11d1-9a4c-0020af6e7c57", + "InterfaceStructOffset": 160400, + "ProceduresCount": 9, + "Procedures": [ + "PINSTALLCONTEXT_rundown", + "InstallBegin", + "InstallManageApp", + "InstallUnmanageApp", + "InstallEnd", + "ARPRemoveApp", + "GetManagedApps", + "RsopReportInstallFailure", + "GetManagedAppCategories" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707880776320, + "Service": "AppMgmt", + "IsServiceRunning": false + }, + "bf4dc912-e52f-4904-8ebe-9317c1bdd497": { + "Module": "dssvc.dll", + "ModulePath": "C:\\Windows\\System32\\dssvc.dll", + "InterfaceId": "bf4dc912-e52f-4904-8ebe-9317c1bdd497", + "InterfaceStructOffset": 104592, + "ProceduresCount": 8, + "Procedures": [ + "RpcDSSCreateSharedFileToken", + "RpcDSSGetSharedFileName", + "RpcDSSGetSharingTokenInformation", + "RpcDSSDelegateSharingToken", + "RpcDSSRemoveSharingToken", + "RpcDSSOpenSharedFile", + "RpcDSSCopyFromSharedFile", + "RpcDSSRemoveExpiredTokens" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708033741296, + "Service": "DsSvc", + "IsServiceRunning": true + }, + "3f7b77f5-7f38-4033-afd9-343d42d8dabb": { + "Module": "moshost.dll", + "ModulePath": "C:\\Windows\\System32\\moshost.dll", + "InterfaceId": "3f7b77f5-7f38-4033-afd9-343d42d8dabb", + "InterfaceStructOffset": 58624, + "ProceduresCount": 5, + "Procedures": [ + "MapsPackageSvcOpen", + "MapsPackageSvcClose", + "MapsPackageSvcFindNearbyPackagesAsync", + "MapsPackageSvcGetPackages", + "MapsPackageSvcAddMapPackageAsync" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707880923216, + "Service": "MapsBroker", + "IsServiceRunning": false + }, + "8f1acdc1-754d-43eb-9629-aa1620928e65": { + "Module": "IMEPADSM.DLL", + "ModulePath": "C:\\Windows\\System32\\IME\\SHARED\\IMEPADSM.DLL", + "InterfaceId": "8f1acdc1-754d-43eb-9629-aa1620928e65", + "InterfaceStructOffset": 80624, + "ProceduresCount": 2, + "Procedures": [ + "AddRef", + "s_ToClientFromServer" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707880930576, + "Service": null, + "IsServiceRunning": false + }, + "15cd3850-28ca-11ce-a4e8-00aa006116cb": { + "Module": "PeerDistSvc.dll", + "ModulePath": "C:\\Windows\\System32\\PeerDistSvc.dll", + "InterfaceId": "15cd3850-28ca-11ce-a4e8-00aa006116cb", + "InterfaceStructOffset": 1559872, + "ProceduresCount": 24, + "Procedures": [ + "PeerDistStartupRPC", + "PeerDistShutdownRPC", + "PeerDistGetServiceStatusRPC", + "PeerDistServerPublishStreamRPC", + "PeerDistServerPublishAddToStreamRPC", + "PeerDistServerPublishCompleteStreamRPC", + "PeerDistServerCloseStreamHandleRPC", + "PeerDistServerUnpublishRPC", + "PeerDistServerOpenContentInformationRPC", + "PeerDistServerRetrieveContentInformationRPC", + "PeerDistServerCloseContentInfoRPC", + "PeerDistClientOpenContentRPC", + "PeerDistClientCloseContentRPC", + "PeerDistClientAddContentInformationRPC", + "PeerDistClientCompleteContentInformationRPC", + "PeerDistClientAddDataRPC", + "PeerDistClientBlockReadRPC", + "PeerDistClientStreamReadRPC", + "PeerDistClientIsFlashCrowdRPC", + "PeerDistClientFlushContentRPC", + "PeerDistFlushContentRPC", + "PeerDistQueryCacheInformationRPC", + "PeerDistConfigureCacheDatabaseRPC", + "PeerDistForceConfigurationRefreshRPC" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707093992784, + "Service": "PeerDistSvc", + "IsServiceRunning": false + }, + "86d35949-83c9-4044-b424-db363231fd0c": { + "Module": "schedsvc.dll", + "ModulePath": "C:\\Windows\\System32\\schedsvc.dll", + "InterfaceId": "86d35949-83c9-4044-b424-db363231fd0c", + "InterfaceStructOffset": 477888, + "ProceduresCount": 20, + "Procedures": [ + "SchRpcHighestVersion", + "SchRpcRegisterTask", + "SchRpcRetrieveTask", + "SchRpcCreateFolder", + "SchRpcSetSecurity", + "SchRpcGetSecurity", + "SchRpcEnumFolders", + "SchRpcEnumTasks", + "SchRpcEnumInstances", + "SchRpcGetInstanceInfo", + "SchRpcStopInstance", + "SchRpcStop", + "SchRpcRun", + "SchRpcDelete", + "SchRpcRename", + "SchRpcScheduledRuntimes", + "SchRpcGetLastRunInfo", + "_SchRpcGetTaskInfo", + "SchRpcGetNumberOfMissedRuns", + "SchRpcEnableTask" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708046648816, + "Service": "Schedule", + "IsServiceRunning": true + }, + "d4051bde-9cdd-4910-b393-4aa85ec3c482": { + "Module": "diagtrack.dll", + "ModulePath": "C:\\Windows\\System32\\diagtrack.dll", + "InterfaceId": "d4051bde-9cdd-4910-b393-4aa85ec3c482", + "InterfaceStructOffset": 2709376, + "ProceduresCount": 1, + "Procedures": [ + "UtcAdminApi_SnapMiniTrace" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707991489344, + "Service": "DiagTrack", + "IsServiceRunning": true + }, + "c36be077-e14b-4fe9-8abc-e856ef4f048b": { + "Module": "httpprxm.dll", + "ModulePath": "C:\\Windows\\System32\\httpprxm.dll", + "InterfaceId": "c36be077-e14b-4fe9-8abc-e856ef4f048b", + "InterfaceStructOffset": 69808, + "ProceduresCount": 6, + "Procedures": [ + "RpcSrvProxyMgrClientRegisterForEventNotification", + "RpcSrvProxyMgrClientGetNotification", + "RpcSrvProxyMgrClientUnregisterEventNotification", + "RpcSrvProxyMgrClientGetProxyForUrl", + "RpcSrvProxyMgrClientGetProxyCredentials", + "RpcSrvProxyMgrClientGetAllProxiesForUrl" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707879068848, + "Service": null, + "IsServiceRunning": false + }, + "9b8699ae-0e44-47b1-8e7f-86a461d7ecdc": { + "Module": "rpcss.dll", + "ModulePath": "C:\\Windows\\System32\\rpcss.dll", + "InterfaceId": "9b8699ae-0e44-47b1-8e7f-86a461d7ecdc", + "InterfaceStructOffset": 959888, + "ProceduresCount": 29, + "Procedures": [ + "_LaunchActivatorServer", + "_LaunchRunAsServer", + "_LaunchService", + "_LaunchWinRTActivatorServer", + "_LaunchWinRTRunAsServer", + "_LaunchWinRTService", + "_CertifyServerIdentity", + "_QueryNTService", + "QueryNTServiceType", + "ControlNTService", + "PrivTranslateShareName", + "Commit", + "IsPortOpen", + "TickleActivationSettings", + "QueryProcessArchitecture", + "PrivilegedNotifyWinRTActivationStoreChanged", + "_QueryUserSidForSession", + "PrivActivatePsmServer", + "_PrivGetUserTokenForSession", + "PrivGetBrokerToken", + "PrivGetDesktopWinRTBrokerToken", + "PrivGetPsmToken", + "GetSessionUserTokenCacheDetails", + "PrivilegedNotifyComClassChangesFromDeployment", + "PrivGetPsmTokenWithDynamicId", + "PrivGetInteractiveUserToken", + "PrivReportUnhealthyProcess", + "PrivNormalizePsmTokenHostId", + "PrivLogMachineClassesRootPermissions" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708135411984, + "Service": "RpcSs", + "IsServiceRunning": true + }, + "fd8be72b-a9cd-4b2c-a9ca-4ded242fbe4d": { + "Module": "diagtrack.dll", + "ModulePath": "C:\\Windows\\System32\\diagtrack.dll", + "InterfaceId": "fd8be72b-a9cd-4b2c-a9ca-4ded242fbe4d", + "InterfaceStructOffset": 2709568, + "ProceduresCount": 2, + "Procedures": [ + "UtcApi_SendSyntheticTrigger", + "UtcApi_ChangeEtmPauseState" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707991489568, + "Service": "DiagTrack", + "IsServiceRunning": true + }, + "ba26f803-f095-40e9-b5e1-0afc44e18479": { + "Module": "dnsrslvr.dll", + "ModulePath": "C:\\Windows\\System32\\dnsrslvr.dll", + "InterfaceId": "ba26f803-f095-40e9-b5e1-0afc44e18479", + "InterfaceStructOffset": 250464, + "ProceduresCount": 3, + "Procedures": [ + "s_HvsiK_CloseHandle", + "s_HvsiK_JoinHandles", + "s_HvsiK_CloneHandle" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708025556688, + "Service": "Dnscache", + "IsServiceRunning": true + }, + "1a0d010f-1c33-432c-b0f5-8cf4e8053099": { + "Module": "srvsvc.dll", + "ModulePath": "C:\\Windows\\System32\\srvsvc.dll", + "InterfaceId": "1a0d010f-1c33-432c-b0f5-8cf4e8053099", + "InterfaceStructOffset": 192608, + "ProceduresCount": 2, + "Procedures": [ + "IdSegRequestNextSequence", + "IdSegRequestNodeInvalidation" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707955945888, + "Service": "LanmanServer", + "IsServiceRunning": true + }, + "bf999caa-2e5d-4bdd-ae89-e7ee0ea5fcbe": { + "Module": "mspdb140.dll", + "ModulePath": "C:\\Program Files (x86)\\Microsoft Visual Studio\\2017\\Community\\VC\\Tools\\MSVC\\14.12.25827\\bin\\Hostx64\\x64\\mspdb140.dll", + "InterfaceId": "bf999caa-2e5d-4bdd-ae89-e7ee0ea5fcbe", + "InterfaceStructOffset": 212576, + "ProceduresCount": 26, + "Procedures": [ + "RPC_CALLBACK_PfnPDBQueryCallback", + "RPC_CALLBACK_PfnPDBNotifyDebugDir", + "RPC_CALLBACK_PfnPDBNotifyDebugDir", + "RPC_CALLBACK_PfnPDBNotifyDebugDir", + "RPC_CALLBACK_PfnPDBQueryCallback", + "RPC_CALLBACK_PfnPDBQueryCallback", + "RPC_CALLBACK_PfnPDBNotifyDebugDir", + "RPC_CALLBACK_PfnPDBQueryCallback", + "RPC_CALLBACK_PfnPDBReadMiscDebugData", + "RPC_CALLBACK_PfnPDBQueryCallback", + "RPC_CALLBACK_PfnPDBQueryCallback", + "RPC_CALLBACK_PfnPDBQueryCallback", + "RPC_CALLBACK_PfnPDBQueryCallback", + "RPC_CALLBACK_PfnPDBQueryCallback", + "RPC_CALLBACK_PfnPDBQueryCallback", + "RPC_CALLBACK_PfnFEFDepCallBack", + "RPC_CALLBACK_PfnFEFDepCallBack", + "RPC_CALLBACK_PfnFEFAllCallBack", + "RPC_CALLBACK_PfnPdbCopyQueryCallback", + "RPC_CALLBACK_PfnPdbCopyFilterPublics", + "RPC_CALLBACK_PfnNoteTypeMismatch", + "RPC_CALLBACK_PfnPdbCopyFilterStreamNames", + "RPC_CALLBACK_PfnDBIQueryCallback", + "RPC_CALLBACK_PfnNotePdbUsed", + "RPC_CALLBACK_PfnNoteTypeMismatch", + "RPC_CALLBACK_PfnPdbCopyFilterStreamNames" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707880323872, + "Service": null, + "IsServiceRunning": false + }, + "c100beab-d33a-4a4b-bf23-bbef4663d017": { + "Module": "wcncsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wcncsvc.dll", + "InterfaceId": "c100beab-d33a-4a4b-bf23-bbef4663d017", + "InterfaceStructOffset": 354176, + "ProceduresCount": 31, + "Procedures": [ + "WcnpRpcSubscribe", + "WcnpRpcUnSubscribe", + "WcnpRpcSetNotificationFilter", + "WcnpRpcGetCachedPeers", + "WcnpRpcAsyncGetNotification", + "WcnpRpcCancelPendingNotification", + "WcnpRpcPerformDiscovery", + "WcnpRpcTargetedWlanDiscovery", + "WcnpRpcGetPeerUuidFromTransportAddress", + "WcnpRpcGetPeer", + "WcnpRpcReleasePeer", + "WcnpRpcPeerOpenSession", + "WcnpRpcPeerGetAttribute", + "WcnpRpcPeerGetAttributeAsInteger", + "WcnpRpcPeerGetAttributeAsString", + "WcnpRpcPeerGetVendorExtensions", + "WcnpRpcSessionSetPassword", + "WcnpRpcSessionSetNFCPassword", + "WcnpRpcSessionSetProfileData", + "WcnpRpcSessionSetProfilePassphrase", + "WcnpRpcSessionConnect", + "WcnpRpcSessionGetNotifications", + "WcnpRpcSessionGetWirelessProfile", + "WcnpRpcSessionGetTelemetry", + "WcnpRpcSessionGetAttributeAsInteger", + "WcnpRpcReleaseSession", + "WcnpRpcSessionSetVendorExtensions", + "WcnpRpcSessionGetVendorExtensions", + "WcnpRpcCreateManagementHandle", + "WcnpRpcSetAdvertisementsEnabled", + "WcnpRpcCloseManagementHandle" + ], + "ProcStackSize": 8, + "DispatchFunction": 140707580936848, + "Service": "wcncsvc", + "IsServiceRunning": false + }, + "e38f5360-8572-473e-b696-1b46873beeab": { + "Module": "diagtrack.dll", + "ModulePath": "C:\\Windows\\System32\\diagtrack.dll", + "InterfaceId": "e38f5360-8572-473e-b696-1b46873beeab", + "InterfaceStructOffset": 2709760, + "ProceduresCount": 4, + "Procedures": [ + "UtcTenantApi_RegisterTelemetryTenant", + "UtcTenantApi_UnregisterTelemetryTenant", + "UtcTenantApi_UpdateDailyUploadQuota", + "UtcTenantApi_ForceUpload" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707991503584, + "Service": "DiagTrack", + "IsServiceRunning": true + }, + "a13a9961-953f-4157-8a29-e65e29be510d": { + "Module": "SgrmLpac.exe", + "ModulePath": "C:\\Windows\\System32\\SgrmLpac.exe", + "InterfaceId": "a13a9961-953f-4157-8a29-e65e29be510d", + "InterfaceStructOffset": 33696, + "ProceduresCount": 1, + "Procedures": [ + "s_HttpPost" + ], + "ProcStackSize": 80, + "DispatchFunction": 140700842341040, + "Service": null, + "IsServiceRunning": false + }, + "1e665584-40fe-4450-8f6e-802362399694": { + "Module": "lsm.dll", + "ModulePath": "C:\\Windows\\System32\\lsm.dll", + "InterfaceId": "1e665584-40fe-4450-8f6e-802362399694", + "InterfaceStructOffset": 479504, + "ProceduresCount": 4, + "Procedures": [ + "RpcBroadcastSystemMessage", + "RpcSendWindowMessage", + "RpcCreateSession", + "RpcTerminateSession" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708131751312, + "Service": "LSM", + "IsServiceRunning": true + }, + "eda3c9e4-0d4c-4bb7-b612-0e89d4f0607d": { + "Module": "LsaIso.exe", + "ModulePath": "C:\\Windows\\System32\\LsaIso.exe", + "InterfaceId": "eda3c9e4-0d4c-4bb7-b612-0e89d4f0607d", + "InterfaceStructOffset": 184832, + "ProceduresCount": 1, + "Procedures": [ + "GetRunningServices" + ], + "ProcStackSize": 16, + "DispatchFunction": 140697528904848, + "Service": null, + "IsServiceRunning": false + }, + "0e3ae095-8a23-48f4-9782-03c1594a890e": { + "Module": "ngcsvc.dll", + "ModulePath": "C:\\Windows\\System32\\ngcsvc.dll", + "InterfaceId": "0e3ae095-8a23-48f4-9782-03c1594a890e", + "InterfaceStructOffset": 629840, + "ProceduresCount": 19, + "Procedures": [ + "s_NgcKspOpenStorageProvider", + "s_NgcKspEnumKeys", + "s_NgcKspFreeBuffer", + "s_NgcKspFreeProvider", + "s_NgcKspFreeKey", + "s_NgcKspOpenKey", + "s_NgcKspCreatePersistedKey", + "s_NgcKspGetProviderProperty", + "s_NgcKspSetProviderProperty", + "s_NgcKspGetKeyProperty", + "s_NgcKspSetKeyProperty", + "s_NgcKspFinalizeKey", + "s_NgcKspDecrypt", + "s_NgcKspSignHash", + "s_NgcKspDeleteKey", + "s_NgcKspImportKey", + "s_NgcKspExportKey", + "s_NgcKspCreateClaim", + "s_NgcKspVerifyClaim" + ], + "ProcStackSize": 72, + "DispatchFunction": 140707093969040, + "Service": "NgcSvc", + "IsServiceRunning": false + }, + "28098650-fe3c-4af4-8a41-8bcd284941c5": { + "Module": "termsrv.dll", + "ModulePath": "C:\\Windows\\System32\\termsrv.dll", + "InterfaceId": "28098650-fe3c-4af4-8a41-8bcd284941c5", + "InterfaceStructOffset": 749568, + "ProceduresCount": 4, + "Procedures": [ + "RpcGetCurrentSessionConnectionProperty", + "RpcGetCurrentSessionClientData", + "RpcGetCurrentSessionConfigData", + "RpcGetCurrentSessionProtocolLastInputTime" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708118764736, + "Service": "TermService", + "IsServiceRunning": true + }, + "4f361416-bd16-44a5-ab86-e8bf3a86410d": { + "Module": "hvsirpcd.exe", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-hvsi-manager_31bf3856ad364e35_10.0.18362.1832_none_158049e1d563edb9\\hvsirpcd.exe", + "InterfaceId": "4f361416-bd16-44a5-ab86-e8bf3a86410d", + "InterfaceStructOffset": 68096, + "ProceduresCount": 4, + "Procedures": [ + "s_HvsiR_ResolverQuery", + "s_HvsiR_CloseHandle", + "s_HvsiR_JoinHandles", + "s_HvsiR_CloneHandle" + ], + "ProcStackSize": 32, + "DispatchFunction": 140698086697280, + "Service": null, + "IsServiceRunning": false + }, + "76f03f96-cdfd-44fc-a22c-64950a001209": { + "Module": "spoolsv.exe", + "ModulePath": "C:\\Windows\\System32\\spoolsv.exe", + "InterfaceId": "76f03f96-cdfd-44fc-a22c-64950a001209", + "InterfaceStructOffset": 476528, + "ProceduresCount": 75, + "Procedures": [ + "RpcAsyncOpenPrinter", + "RpcAsyncAddPrinter", + "RpcAsyncSetJob", + "RpcAsyncGetJob", + "RpcAsyncEnumJobs", + "RpcAsyncAddJob", + "RpcAsyncScheduleJob", + "RpcAsyncDeletePrinter", + "RpcAsyncSetPrinter", + "RpcAsyncGetPrinter", + "RpcAsyncStartDocPrinter", + "RpcAsyncStartPagePrinter", + "RpcAsyncWritePrinter", + "RpcAsyncEndPagePrinter", + "RpcAsyncEndDocPrinter", + "RpcAsyncAbortPrinter", + "RpcAsyncGetPrinterData", + "RpcAsyncGetPrinterDataEx", + "RpcAsyncSetPrinterData", + "RpcAsyncSetPrinterDataEx", + "RpcAsyncClosePrinter", + "RpcAsyncAddForm", + "RpcAsyncDeleteForm", + "RpcAsyncGetForm", + "RpcAsyncSetForm", + "RpcAsyncEnumForms", + "RpcAsyncGetPrinterDriver", + "RpcAsyncEnumPrinterData", + "RpcAsyncEnumPrinterDataEx", + "RpcAsyncEnumPrinterKey", + "RpcAsyncDeletePrinterData", + "RpcAsyncDeletePrinterDataEx", + "RpcAsyncDeletePrinterKey", + "RpcAsyncXcvData", + "RpcAsyncSendRecvBidiData", + "RpcAsyncCreatePrinterIC", + "RpcAsyncPlayGdiScriptOnPrinterIC", + "RpcAsyncDeletePrinterIC", + "RpcAsyncEnumPrinters", + "RpcAsyncAddPrinterDriver", + "RpcAsyncEnumPrinterDrivers", + "RpcAsyncGetPrinterDriverDirectory", + "RpcAsyncDeletePrinterDriver", + "RpcAsyncDeletePrinterDriverEx", + "RpcAsyncAddPrintProcessor", + "RpcAsyncEnumPrintProcessors", + "RpcAsyncGetPrintProcessorDirectory", + "RpcAsyncEnumPorts", + "RpcAsyncEnumMonitors", + "RpcAsyncAddPort", + "RpcAsyncSetPort", + "RpcAsyncAddMonitor", + "RpcAsyncDeleteMonitor", + "RpcAsyncDeletePrintProcessor", + "RpcAsyncEnumPrintProcessorDatatypes", + "RpcAsyncAddPerMachineConnection", + "RpcAsyncDeletePerMachineConnection", + "RpcAsyncEnumPerMachineConnections", + "RpcSyncRegisterForRemoteNotifications", + "RpcSyncUnRegisterForRemoteNotifications", + "RpcSyncRefreshRemoteNotifications", + "RpcAsyncGetRemoteNotifications", + "RpcAsyncInstallPrinterDriverFromPackage", + "RpcAsyncUploadPrinterDriverPackage", + "RpcAsyncGetCorePrinterDrivers", + "RpcAsyncCorePrinterDriverInstalled", + "RpcAsyncGetPrinterDriverPackagePath", + "RpcAsyncDeletePrinterDriverPackage", + "RpcAsyncReadPrinter", + "RpcAsyncResetPrinter", + "RpcAsyncGetJobNamedPropertyValue", + "RpcAsyncSetJobNamedProperty", + "RpcAsyncDeleteJobNamedProperty", + "RpcAsyncEnumJobNamedProperties", + "RpcAsyncLogJobInfoForBranchOffice" + ], + "ProcStackSize": 32, + "DispatchFunction": 140698296502800, + "Service": "Spooler", + "IsServiceRunning": true + }, + "ed19cc3c-31d4-4b12-b63e-78b2c65a61d5": { + "Module": "vmicrdv.dll", + "ModulePath": "C:\\Windows\\System32\\vmicrdv.dll", + "InterfaceId": "ed19cc3c-31d4-4b12-b63e-78b2c65a61d5", + "InterfaceStructOffset": 96416, + "ProceduresCount": 1, + "Procedures": [ + "RpcCreateVmEndPoint" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707581023248, + "Service": null, + "IsServiceRunning": false + }, + "5ca4a760-ebb1-11cf-8611-00a0245420ed": { + "Module": "termsrv.dll", + "ModulePath": "C:\\Windows\\System32\\termsrv.dll", + "InterfaceId": "5ca4a760-ebb1-11cf-8611-00a0245420ed", + "InterfaceStructOffset": 756576, + "ProceduresCount": 76, + "Procedures": [ + "RpcWinStationOpenServer", + "RpcWinStationCloseServer", + "RpcIcaServerPing", + "RpcWinStationEnumerate", + "RpcWinStationRename", + "RpcWinStationQueryInformation", + "RpcWinStationSetInformation", + "RpcWinStationSendMessage", + "RpcLogonIdFromWinStationName", + "RpcWinStationNameFromLogonId", + "RpcWinStationConnect", + "RpcWinStationVirtualOpen", + "RpcWinStationBeepOpen", + "RpcWinStationDisconnect", + "RpcWinStationReset", + "RpcWinStationShutdownSystem", + "RpcWinStationWaitSystemEvent", + "RpcWinStationShadow", + "RpcWinStationShadowTargetSetup", + "RpcWinStationShadowTarget", + "RpcWinStationGenerateLicense", + "RpcWinStationInstallLicense", + "RpcWinStationEnumerateLicenses", + "RpcWinStationActivateLicense", + "RpcWinStationRemoveLicense", + "RpcWinStationQueryLicense", + "RpcWinStationSetPoolCount", + "RpcWinStationQueryUpdateRequired", + "RpcWinStationCallback", + "RpcWinStationBreakPoint", + "RpcWinStationReadRegistry", + "RpcWinStationWaitForConnect", + "RpcWinStationNotifyLogon", + "RpcWinStationNotifyLogoff", + "OldRpcWinStationEnumerateProcesses", + "RpcWinStationAnnoyancePopup", + "RpcWinStationEnumerateProcesses", + "RpcWinStationTerminateProcess", + "RpcServerNWLogonSetAdmin", + "RpcServerNWLogonQueryAdmin", + "RpcWinStationCheckForApplicationName", + "RpcWinStationGetApplicationInfo", + "RpcWinStationNtsdDebug", + "RpcWinStationGetAllProcesses", + "RpcWinStationGetProcessSid", + "RpcWinStationGetTermSrvCountersValue", + "RpcWinStationReInitializeSecurity", + "RpcWinStationBroadcastSystemMessage", + "RpcWinStationSendWindowMessage", + "RpcWinStationNotifyNewSession", + "RpcServerGetInternetConnectorStatus", + "RpcServerSetInternetConnectorStatus", + "RpcServerQueryInetConnectorInformation", + "RpcWinStationGetLanAdapterName", + "RpcWinStationUpdateUserConfig", + "RpcWinStationQueryLogonCredentials", + "RpcWinStationRegisterConsoleNotification", + "RpcWinStationUnRegisterConsoleNotification", + "RpcWinStationUpdateSettings", + "RpcWinStationShadowStop", + "RpcWinStationCloseServerEx", + "RpcWinStationIsHelpAssistantSession", + "RpcWinStationGetMachinePolicy", + "RpcWinStationUpdateClientCachedCredentials", + "RpcWinStationFUSCanRemoteUserDisconnect", + "RpcWinStationCheckLoopBack", + "RpcConnectCallback", + "RpcWinStationNotifyDisconnectPipe", + "RpcWinStationSessionInitialized", + "RpcRemoteAssistancePrepareSystemRestore", + "RpcWinStationGetAllProcesses_NT6", + "RpcWinStationRegisterNotificationEvent", + "RpcWinStationUnRegisterNotificationEvent", + "RpcWinStationAutoReconnect", + "RpcWinStationCheckAccess", + "RpcWinStationOpenSessionDirectory" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708119110608, + "Service": "TermService", + "IsServiceRunning": true + }, + "53b46b02-c73b-4a3e-8dee-b16b80672fc0": { + "Module": "TSVIPSrv.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-t..-tsappsrv-component_31bf3856ad364e35_10.0.18362.1316_none_7c6dc83f556303be\\TSVIPSrv.dll", + "InterfaceId": "53b46b02-c73b-4a3e-8dee-b16b80672fc0", + "InterfaceStructOffset": 99808, + "ProceduresCount": 2, + "Procedures": [ + "RpcGetSessionIP", + "RpcGetBindingAdapter" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707880844688, + "Service": null, + "IsServiceRunning": false + }, + "bd84cd86-9825-4376-813d-334c543f89b1": { + "Module": "das.dll", + "ModulePath": "C:\\Windows\\System32\\das.dll", + "InterfaceId": "bd84cd86-9825-4376-813d-334c543f89b1", + "InterfaceStructOffset": 368736, + "ProceduresCount": 4, + "Procedures": [ + "RpcDevQueryCreate", + "RpcDevQueryClose", + "RpcDevQueryGetResult", + "RpcDevPropertySet" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707580792416, + "Service": "DeviceAssociationService", + "IsServiceRunning": false + }, + "e3514235-4b06-11d1-ab04-00c04fc2dcd2": { + "Module": "ntdsai.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-d..toryservices-ntdsai_31bf3856ad364e35_10.0.18362.1916_none_fe1eba331c36e95d\\ntdsai.dll", + "InterfaceId": "e3514235-4b06-11d1-ab04-00c04fc2dcd2", + "InterfaceStructOffset": 4346000, + "ProceduresCount": 31, + "Procedures": [ + "IDL_DRSBind", + "IDL_DRSUnbind", + "IDL_DRSReplicaSync", + "IDL_DRSGetNCChanges", + "IDL_DRSUpdateRefs", + "IDL_DRSReplicaAdd", + "IDL_DRSReplicaDel", + "IDL_DRSReplicaModify", + "IDL_DRSVerifyNames", + "IDL_DRSGetMemberships", + "IDL_DRSInterDomainMove", + "IDL_DRSGetNT4ChangeLog", + "IDL_DRSCrackNames", + "IDL_DRSWriteSPN", + "IDL_DRSRemoveDsServer", + "IDL_DRSRemoveDsDomain", + "IDL_DRSDomainControllerInfo", + "IDL_DRSAddEntry", + "IDL_DRSExecuteKCC", + "IDL_DRSGetReplInfo", + "IDL_DRSAddSidHistory", + "IDL_DRSGetMemberships2", + "IDL_DRSReplicaVerifyObjects", + "IDL_DRSGetObjectExistence", + "IDL_DRSQuerySitesByCost", + "IDL_DRSInitDemotion", + "IDL_DRSReplicaDemotion", + "IDL_DRSFinishDemotion", + "IDL_DRSAddCloneDC", + "IDL_DRSWriteNgcKey", + "IDL_DRSReadNgcKey" + ], + "ProcStackSize": 48, + "DispatchFunction": 140706768764672, + "Service": null, + "IsServiceRunning": false + }, + "c503f532-443a-4c69-8300-ccd1fbdb3839": { + "Module": "MpSvc.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_windows-defender-service_31bf3856ad364e35_10.0.18362.1533_none_d32c1fb0b9be2eb7\\MpSvc.dll", + "InterfaceId": "c503f532-443a-4c69-8300-ccd1fbdb3839", + "InterfaceStructOffset": 1872048, + "ProceduresCount": 152, + "Procedures": [ + "ServerMpEnableFeature", + "ServerMpDisableFeature", + "ServerMpQueryStatus", + "ServerMpEventOpen", + "ServerMpEventClose", + "ServerMpEventQueryNotification", + "ServerMpOnDemandStartScan", + "ServerMpOnDemandQueryNotification", + "ServerMpOnDemandQueryScanResult", + "ServerMpOnDemandControlScan", + "ServerMpOnDemandControlSystemScan", + "ServerMpOnDemandPersistScan", + "ServerMpOnDemandCloseScan", + "ServerMpOnDemandThreatOpen", + "ServerMpOnDemandThreatEnum", + "ServerMpOnDemandThreatClose", + "ServerMpScanOpenThreatHistory", + "ServerMpScanEnumerateThreatHistory", + "ServerMpScanEnumerateDetectionHistory", + "ServerMpScanCloseThreatHistory", + "ServerMpScanDeleteThreatHistory", + "ServerMpRpcCleanOpen", + "ServerMpRpcScanCleanOpen", + "ServerMpRpcCleanStart", + "ServerMpRpcCleanControl", + "ServerMpRpcCleanThreatsNotification", + "ServerMpRpcPrecheckStart", + "ServerMpRpcPrecheckNotification", + "ServerMpRpcCleanQuery", + "ServerMpRpcCleanClose", + "Clone", + "Clone", + "Clone", + "Clone", + "ServerMpQuarantineEnumOpen", + "ServerMpQuarantineEnumerate", + "ServerMpQuarantineEnumClose", + "ServerMpQuarantineQueryInfo", + "ServerMpQuarantineRestoreThreat", + "ServerMpQuarantineDeleteThreat", + "ServerMpStateEnumOpen", + "ServerMpQueryEngineVersion", + "ServerMpUpdateEngineSignature", + "ServerMpRollbackEngineSignature", + "ServerMpThreatStaticInfo", + "ServerMpQuerySystemInfo", + "ServerMpRpcConfigSetValue", + "ServerMpRpcConfigDelValue", + "ServerMpRpcElevationHandleOpen", + "ServerMpRpcElevationHandleAttach", + "ServerMpRpcElevationHandleClose", + "ServerMpRpcElevateCleanHandle", + "ServerMpRpcSignatureThreatOpen", + "ServerMpRpcSignatureThreatEnum", + "ServerMpRpcSignatureThreatClose", + "ServerMpRpcGetSampleInfo", + "ServerMpRpcQueryScansWithSamples", + "ServerMpRpcDropScansWithSamples", + "ServerMpRpcSpynetQueueCreate", + "ServerMpRpcSpynetQueueQueryNotification", + "ServerMpRpcSpynetQueueClose", + "ServerMpRpcSpynetGenerateReport", + "ServerMpRpcSenseGenerateReport", + "ServerMpRpcSpynetOnResponse", + "ServerMpRpcSpynetGetStartTime", + "ServerMpRpcSpynetUpdateSpynetMetrics", + "ServerMpRpcSpynetClose", + "ServerMpRpcSigUpdServiceOpen", + "ServerMpRpcSigUpdServiceQueryNotification", + "ServerMpRpcSigUpdServiceSendProgressNotification", + "ServerMpRpcSigUpdServiceClose", + "ServerMpRpcSigUpdClientOpen", + "ServerMpRpcSigUpdClientQueryNotification", + "ServerMpRpcSigUpdClientClose", + "ServerMpRpcSigUpdControl", + "ServerMpRpcIdleNotificationOpen", + "ServerMpRpcIdleNotificationClose", + "ServerMpRpcNotifyIdle", + "ServerMpRpcIdleCheckTaskCompletion", + "ServerMpRpcThreatOpen", + "ServerMpRpcThreatEnumerate", + "ServerMpRpcThreatClose", + "ServerMpRpcDbgThreatViewAction", + "ServerMpRpcForcedReboot", + "Clone", + "ServerMpRpcAddFastPathSignatureFile", + "ServerMpRpcRemoveFastPathSignatureFile", + "ServerMpRpcDynamicSignatureOpen", + "ServerMpRpcDynamicSignatureEnumerate", + "ServerMpRpcDynamicSignatureClose", + "Clone", + "Clone", + "Clone", + "Clone", + "ServerMpRpcMemoryScanStart", + "ServerMpRpcMemoryScanQueryNotification", + "ServerMpRpcMemoryScanClose", + "ServerMpRpcFastMemoryScanOpen", + "ServerMpRpcFastMemoryScan", + "ServerMpRpcFastMemoryScanClose", + "ServerMpRpcFastMemoryScanCacheInfo", + "ServerMpRpcAmsiCloseSession", + "ServerMpRpcTcgLogScan", + "ServerMpRpcTcgLogApplyExtResult", + "ServerMpRpcDbgSendCallbackNotification", + "ServerMpRpcThreatRollup", + "ServerMpDetectionQuery", + "ServerMpRpcRequestSnooze", + "ServerMpRpcOfflineScanInstall", + "ServerMpRpcOfflineScanStatusQuery", + "ServerMpRpcTriggerHeartbeatOnDefenderDisable", + "ServerMpRpcTriggerHeartbeatOnUninstall", + "ServerMpRpcTriggerErrorHeartbeatReport", + "ServerMpRpcTriggerHeartbeatReport", + "ServerMpRpcRemapCallistoDetections", + "ServerMpRpcGetCallistoDetections", + "ServerMpRpcIsAdlFallbackDue", + "ServerMpRpcIsRtpAutoEnable", + "ServerMpRpcEngineQueryConfigDword", + "ServerMpRpcSampleHeaderQueueCreate", + "ServerMpRpcSampleHeaderQueueQueryNotification", + "ServerMpRpcSampleHeaderQueueClose", + "ServerMpRpcSampleHeaderClose", + "ServerMpRpcSampleHeaderGetSampleDetails", + "ServerMpRpcGetSampleChunk", + "ServerMpRpcConveySampleSubmissionResult", + "ServerMpRpcGetSampleListRequiringConsent", + "ServerMpRpcConveyUserChoiceForSampleList", + "ServerMpRpcGetRunningMode", + "ServerMpRpcIsGivenRunningModeSupported", + "ServerMpDisableXBGM", + "ServerMpDisableXBGM", + "ServerMpXBGMUpdateIV", + "ServerMpXBGMGetData", + "ServerMpXBGMGetData", + "ServerMpOnDemandStartScan2", + "ServerMpQueryDefaultFolderGuardList", + "ServerMpRpcTriggerStatusRefreshNotification", + "ServerMpRpcGetHIPSRuleInfo", + "ServerMpEnableSmartLocker", + "ServerMpDisableSmartLocker", + "ServerMpXBGMUpdateIV", + "ServerMpFlushLowfiCache", + "ServerMpRpcGetAsrBlockedProcesses", + "ServerMpRpcGetAsrBlockedActions", + "ServerMpRpcDeleteAsrHistory", + "ServerMpGetTaskSchedulerStrings", + "ServerMpRpcGetAsrBlockedActionInfos", + "ServerMpRpcGetTPStateInfo", + "ServerMpRpcSetTPState", + "ServerMpRpcUpdateDevMode", + "ServerMpRpcGetDevMode" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707092421504, + "Service": null, + "IsServiceRunning": false + }, + "0767a036-0d22-48aa-ba69-b619480f38cb": { + "Module": "pcasvc.dll", + "ModulePath": "C:\\Windows\\System32\\pcasvc.dll", + "InterfaceId": "0767a036-0d22-48aa-ba69-b619480f38cb", + "InterfaceStructOffset": 404384, + "ProceduresCount": 5, + "Procedures": [ + "RAiMonitorProcess", + "RAiSendToService", + "RAiNotifyMsiInstall", + "RAiLinkChildToParent", + "RAiGetFileInfoFromPath" + ], + "ProcStackSize": 72, + "DispatchFunction": 140707617368272, + "Service": "PcaSvc", + "IsServiceRunning": true + }, + "54b4c689-969a-476f-8dc2-990885e9f562": { + "Module": "StorSvc.dll", + "ModulePath": "C:\\Windows\\System32\\StorSvc.dll", + "InterfaceId": "54b4c689-969a-476f-8dc2-990885e9f562", + "InterfaceStructOffset": 661280, + "ProceduresCount": 10, + "Procedures": [ + "SvcOpenStorageType", + "SvcSelectStorageVolumeEx", + "SvcSelectStorageVolume", + "SvcFindNextStorageType", + "SvcFindNextStorageTypeEx", + "SvcCloseFindStorage", + "SvcGetStorageDebugInfo", + "SvcGetStorageExecutionInfo", + "SvcGetTopFolders", + "SvcFindNextStorageTypeExAsync" + ], + "ProcStackSize": 64, + "DispatchFunction": 140707759710864, + "Service": "StorSvc", + "IsServiceRunning": true + }, + "b754ffa1-7b7b-4fb1-9d0c-f12bbda17593": { + "Module": "webplatstorageserver.dll", + "ModulePath": "C:\\Windows\\System32\\webplatstorageserver.dll", + "InterfaceId": "b754ffa1-7b7b-4fb1-9d0c-f12bbda17593", + "InterfaceStructOffset": 933072, + "ProceduresCount": 46, + "Procedures": [ + "s_Legacy_IDBFactory_openDatabase", + "s_Legacy_IDBFactory_Handle_openDatabase_Blocked", + "s_Legacy_IDBFactory_deleteDatabase", + "s_Legacy_IDBFactory_setClientOriginAttributes", + "s_Legacy_IDBDatabase_createObjectStore", + "s_Legacy_IDBDatabase_deleteObjectStore", + "s_Legacy_IDBDatabase_transaction", + "s_Legacy_IDBDatabase_close", + "s_Legacy_IDBDatabaseBlocked_close", + "s_Legacy_IDBTransaction_openObjectStore", + "s_Legacy_IDBTransaction_abortAndClose", + "s_Legacy_IDBTransaction_commitAndClose", + "s_Legacy_IDBObjectStore_put", + "s_Legacy_IDBObjectStore_add", + "s_Legacy_IDBObjectStore_get", + "s_Legacy_IDBObjectStore_getFromKeyRange", + "s_Legacy_IDBObjectStore_delete", + "s_Legacy_IDBObjectStore_deleteFromKeyRange", + "s_Legacy_IDBObjectStore_clear", + "s_Legacy_IDBObjectStore_openCursor", + "s_Legacy_IDBObjectStore_count", + "s_Legacy_IDBObjectStore_createIndex", + "s_Legacy_IDBObjectStore_openIndex", + "s_Legacy_IDBObjectStore_deleteIndex", + "s_Legacy_IDBObjectStore_close", + "s_Legacy_IDBIndex_openCursor", + "s_Legacy_IDBIndex_count", + "s_Legacy_IDBIndex_get", + "s_Legacy_IDBIndex_getFromKeyRange", + "s_Legacy_IDBIndex_getKey", + "s_Legacy_IDBIndex_getKeyFromKeyRange", + "s_Legacy_IDBIndex_close", + "s_Legacy_IDBCursor_update", + "s_Legacy_IDBCursor_continue", + "s_Legacy_IDBCursor_advance", + "s_Legacy_IDBCursor_delete", + "s_Legacy_IDBCursor_close", + "s_Legacy_IDB_BrowserQuota_DeleteWebSiteDatabases", + "s_Legacy_IDB_SpartanQuota_DeleteWebSiteDatabases", + "s_Legacy_IDB_BrowserQuota_DeleteAllDatabases", + "s_Legacy_IDB_Spartan_DeleteAllDatabases", + "s_Legacy_IDB_BrowserQuota_GetSpaceConsumption", + "s_Legacy_IDB_SpartanQuota_GetSpaceConsumption", + "s_Legacy_IDB_AppQuota_Uninstall", + "s_Legacy_IDB_App_CheckIfIDBDataPresent", + "s_Legacy_IDB_App_ForceShutdownIndexedDBDatabase" + ], + "ProcStackSize": 24, + "DispatchFunction": 140706993135264, + "Service": null, + "IsServiceRunning": false + }, + "2b70bed6-1757-4d22-9f39-448589fbebf5": { + "Module": "ngcsvc.dll", + "ModulePath": "C:\\Windows\\System32\\ngcsvc.dll", + "InterfaceId": "2b70bed6-1757-4d22-9f39-448589fbebf5", + "InterfaceStructOffset": 630224, + "ProceduresCount": 4, + "Procedures": [ + "s_NgcTicketCreateForKeyOperations", + "s_NgcTicketCreateForNewKey", + "s_NgcTicketCreateForSmartCard", + "s_NgcTicketGetTicketFromPinCache" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707094056144, + "Service": "NgcSvc", + "IsServiceRunning": false + }, + "abfb6ca3-0c5e-4734-9285-0aee72fe8d1c": { + "Module": "wcmsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wcmsvc.dll", + "InterfaceId": "abfb6ca3-0c5e-4734-9285-0aee72fe8d1c", + "InterfaceStructOffset": 768176, + "ProceduresCount": 21, + "Procedures": [ + "RpcOpenHandle", + "RpcCloseHandle", + "RpcEnumInterfaces", + "RpcQueryParameter", + "RpcSetParameter", + "RpcQueryPublicParameter", + "RpcSetPublicParameter", + "RpcSetProfileList", + "RpcGetProfileList", + "RpcGetProfileListByPurpose", + "RpcGetTokens", + "RpcOrderConnection", + "RpcBeginIgnoreProfileList", + "RpcResetIgnoreProfileList", + "RpcEndIgnoreProfileList", + "RpcOpenOnDemandRequestHandle", + "RpcOpenOnDemandRequestHandleByWwanProfileName", + "RpcStartOnDemandRequest", + "RpcCancelOnDemandRequest", + "RpcCloseOnDemandRequestHandle", + "RpcQueryOnDemandRequestStateInfo" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708018998304, + "Service": "Wcmsvc", + "IsServiceRunning": true + }, + "eeee008d-5c99-4e4b-861b-547a26e8abd0": { + "Module": "dasHost.exe", + "ModulePath": "C:\\Windows\\System32\\dasHost.exe", + "InterfaceId": "eeee008d-5c99-4e4b-861b-547a26e8abd0", + "InterfaceStructOffset": 68016, + "ProceduresCount": 33, + "Procedures": [ + "DasHostLoadProvider", + "DasHostSetDasProcessHandle", + "DasHostUnloadProvider", + "DasHostShutdown", + "DasHostCreateProviderQuery", + "DasHostCloseQuery", + "DasHostProviderQueryGetResult", + "DasHostCreateAssociationContext", + "DasHostCreateAssociationContextFromOobBlob", + "DasHostStartEnumCeremonies", + "DasHostSelectCeremony", + "DasHostStartReadCeremonyData", + "DasHostStartWriteCeremonyData", + "DasHostStartFinalize", + "DasHostDeviceStatusNotification", + "DasHostStartRemoveAssociation", + "DasHostCloseAssociationContext", + "DasHostCreateDevnodeManagementContext", + "DasHostStartDevnodeManagement", + "DasHostEndDevnodeManagement", + "DasHostPickupDevnodeManagementOperation", + "DasHostGetDevnodeFactoryOperationInfo", + "DasHostCompleteDevnodeFactoryOperation", + "DasHostGetDevnodeOperationInfo", + "DasHostCompleteDevnodeOperation", + "DasHostCloseDevnodeManagementContext", + "DasHostCreateChallengeContext", + "DasHostStartChallengeDevicePresence", + "DasHostCloseChallengeContext", + "DasHostCreateImportExportContext", + "DasHostStartImport", + "DasHostStartExport", + "DasHostCloseImportExportContext" + ], + "ProcStackSize": 16, + "DispatchFunction": 140700528890528, + "Service": null, + "IsServiceRunning": false + }, + "69510fa1-2f99-4eeb-a4ff-af259f0f9749": { + "Module": "wecsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wecsvc.dll", + "InterfaceId": "69510fa1-2f99-4eeb-a4ff-af259f0f9749", + "InterfaceStructOffset": 143664, + "ProceduresCount": 7, + "Procedures": [ + "EcRpcGetSubscriptionNames", + "EcRpcGetSubscription", + "EcRpcPutSubscription", + "EcRpcDeleteSubscription", + "EcRpcGetSubscriptionRunTimeStatus", + "EcRpcGetSubscriptionRunTimeEventSources", + "EcRpcRetrySubscription" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707581011872, + "Service": "Wecsvc", + "IsServiceRunning": false + }, + "d3e9e61c-7c85-4a62-8e06-9bd2892311bd": { + "Module": "mpengine.dll", + "ModulePath": "C:\\ProgramData\\Microsoft\\Windows Defender\\Definition Updates\\Backup\\mpengine.dll", + "InterfaceId": "d3e9e61c-7c85-4a62-8e06-9bd2892311bd", + "InterfaceStructOffset": 11416768, + "ProceduresCount": 22, + "Procedures": [ + "MpBootStrap", + "_rsignal", + "MpBootStrap", + "Proc3", + "Proc4", + "MpBootStrap", + "MpBootStrap", + "Proc7", + "MpBootStrap", + "MpBootStrap", + "MpBootStrap", + "_rsignal", + "Proc12", + "Proc13", + "MpBootStrap", + "MpBootStrap", + "Proc16", + "MpBootStrap", + "MpBootStrap", + "MpBootStrap", + "MpBootStrap", + "MpBootStrap" + ], + "ProcStackSize": 56, + "DispatchFunction": 140706774274704, + "Service": null, + "IsServiceRunning": false + }, + "88143fd0-c28d-4b2b-8fef-8d882f6a9390": { + "Module": "lsm.dll", + "ModulePath": "C:\\Windows\\System32\\lsm.dll", + "InterfaceId": "88143fd0-c28d-4b2b-8fef-8d882f6a9390", + "InterfaceStructOffset": 479696, + "ProceduresCount": 12, + "Procedures": [ + "RpcOpenEnum", + "RpcCloseEnum", + "RpcFilterByState", + "RpcFilterByCallersName", + "RpcEnumAddFilter", + "RpcGetEnumResult", + "RpcFilterBySessionType", + "RpcFilterByLicenseType", + "RpcGetSessionIds", + "RpcGetEnumResultEx", + "RpcGetAllSessions", + "RpcGetAllSessionsEx" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708131514208, + "Service": "LSM", + "IsServiceRunning": true + }, + "300f3532-38cc-11d0-a3f0-0020af6b0add": { + "Module": "trkwks.dll", + "ModulePath": "C:\\Windows\\System32\\trkwks.dll", + "InterfaceId": "300f3532-38cc-11d0-a3f0-0020af6b0add", + "InterfaceStructOffset": 80672, + "ProceduresCount": 13, + "Procedures": [ + "Stubold_LnkMendLink", + "StubGetFileTrackingInformation", + "StubGetFileTrackingInformation", + "StubLnkSetVolumeId", + "StubGetFileTrackingInformation", + "StubGetFileTrackingInformation", + "StubGetFileTrackingInformation", + "StubGetFileTrackingInformation", + "StubLnkOnRestore", + "StubLnkMendLink", + "StubGetFileTrackingInformation", + "StubGetFileTrackingInformation", + "StubLnkSearchMachine" + ], + "ProcStackSize": 72, + "DispatchFunction": 140707904071616, + "Service": "TrkWks", + "IsServiceRunning": true + }, + "1d55b526-c137-46c5-ab79-638f2a68e869": { + "Module": "RpcEpMap.dll", + "ModulePath": "C:\\Windows\\System32\\RpcEpMap.dll", + "InterfaceId": "1d55b526-c137-46c5-ab79-638f2a68e869", + "InterfaceStructOffset": 45056, + "ProceduresCount": 13, + "Procedures": [ + "RemoteGetCellByDebugCellID", + "RemoteOpenRPCDebugCallInfoEnumeration", + "RemoteGetNextRPCDebugCallInfo", + "RemoteFinishRPCDebugCallInfoEnumeration", + "RemoteOpenRPCDebugEndpointInfoEnumeration", + "RemoteGetNextRPCDebugEndpointInfo", + "RemoteFinishRPCDebugEndpointInfoEnumeration", + "RemoteOpenRPCDebugThreadInfoEnumeration", + "RemoteGetNextRPCDebugThreadInfo", + "RemoteFinishRPCDebugThreadInfoEnumeration", + "RemoteOpenRPCDebugClientCallInfoEnumeration", + "RemoteGetNextRPCDebugClientCallInfo", + "RemoteFinishRPCDebugClientCallInfoEnumeration" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708134488656, + "Service": "RpcEptMapper", + "IsServiceRunning": true + }, + "c225e799-29de-42af-bc05-1e2127cc056e": { + "Module": "ngcsvc.dll", + "ModulePath": "C:\\Windows\\System32\\ngcsvc.dll", + "InterfaceId": "c225e799-29de-42af-bc05-1e2127cc056e", + "InterfaceStructOffset": 630128, + "ProceduresCount": 13, + "Procedures": [ + "s_NgcMgmtGetPolicy", + "s_NgcMgmtGetProtectedRecoveryBlob", + "s_NgcMgmtChangePin", + "s_NgcMgmtChangePinSilent", + "s_NgcMgmtRecoverPin", + "s_NgcMgmtRecoverPinSilent", + "s_NgcMgmtAddBioProtector", + "s_NgcMgmtRemoveBioProtector", + "s_NgcMgmtSetLastCredProv", + "s_NgcMgmtAddPrebootProtector", + "s_NgcMgmtRemovePrebootProtector", + "s_NgcMgmtAddCompanionDeviceProtector", + "s_NgcMgmtRemoveCompanionDeviceProtector" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707093979344, + "Service": "NgcSvc", + "IsServiceRunning": false + }, + "9c56d792-0591-4431-8d1f-681bfd80e4c0": { + "Module": "wwansvc.dll", + "ModulePath": "C:\\Windows\\System32\\wwansvc.dll", + "InterfaceId": "9c56d792-0591-4431-8d1f-681bfd80e4c0", + "InterfaceStructOffset": 1110496, + "ProceduresCount": 14, + "Procedures": [ + "Wwan2RpcOpenHandle", + "Wwan2RpcCloseHandle", + "Wwan2RpcQueryInterfaces", + "Wwan2RpcEnumerateDeviceServices", + "Wwan2RpcRegisterNotification", + "Wwan2RpcAsyncGetNotification", + "Wwan2RpcOpenDeviceServiceCommandSession", + "Wwan2RpcCloseDeviceServiceCommandSession", + "Wwan2RpcSendDeviceServiceCommand", + "Wwan2RpcQueryDeviceServiceSupportedCommands", + "Wwan2RpcOpenDeviceServiceDataSession", + "Wwan2RpcCloseDeviceServiceDataSession", + "Wwan2RpcWriteDeviceServiceData", + "Wwan2RpcSubscribePowerStateEvents" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707093452496, + "Service": "WwanSvc", + "IsServiceRunning": false + }, + "6099fc12-3eff-11d0-abd0-00c04fd91a4e": { + "Module": "FXSAPI.DLL", + "ModulePath": "C:\\Windows\\System32\\DriverStore\\FileRepository\\prnms002.inf_amd64_327b6e6da271683d\\Amd64\\FXSAPI.DLL", + "InterfaceId": "6099fc12-3eff-11d0-abd0-00c04fd91a4e", + "InterfaceStructOffset": 223984, + "ProceduresCount": 4, + "Procedures": [ + "FAX_OpenConnection", + "FAX_ClientEventQueue", + "FAX_CloseConnection", + "FAX_ClientEventQueueEx" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707880707760, + "Service": null, + "IsServiceRunning": false + }, + "11220835-5b26-4d94-ae86-c3e475a809de": { + "Module": "dpapisrv.dll", + "ModulePath": "C:\\Windows\\System32\\dpapisrv.dll", + "InterfaceId": "11220835-5b26-4d94-ae86-c3e475a809de", + "InterfaceStructOffset": 184416, + "ProceduresCount": 3, + "Procedures": [ + "s_SSCryptProtectData", + "s_SSCryptUnprotectData", + "s_SSCryptUpdateProtectedState" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708143007488, + "Service": null, + "IsServiceRunning": false + }, + "ace1c026-8b3f-4711-8918-f345d17f5bff": { + "Module": "lsasrv.dll", + "ModulePath": "C:\\Windows\\System32\\lsasrv.dll", + "InterfaceId": "ace1c026-8b3f-4711-8918-f345d17f5bff", + "InterfaceStructOffset": 1270048, + "ProceduresCount": 2, + "Procedures": [ + "S_RPC_LspUpdatePrivateData", + "S_RPC_LspReadPrivateData" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708153423376, + "Service": null, + "IsServiceRunning": false + }, + "93149ca2-973b-11d1-8c39-00c04fb984f9": { + "Module": "scecli.dll", + "ModulePath": "C:\\Windows\\System32\\scecli.dll", + "InterfaceId": "93149ca2-973b-11d1-8c39-00c04fb984f9", + "InterfaceStructOffset": 191248, + "ProceduresCount": 3, + "Procedures": [ + "SceClientCallback", + "SceClientBrowseCallback", + "SceClientCallbackRsopLog" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708141469440, + "Service": null, + "IsServiceRunning": false + }, + "71d6addc-3548-4d49-8580-589694df3c9d": { + "Module": "AppVEntSubsystemController.dll", + "ModulePath": "C:\\Windows\\System32\\AppVEntSubsystemController.dll", + "InterfaceId": "71d6addc-3548-4d49-8580-589694df3c9d", + "InterfaceStructOffset": 900560, + "ProceduresCount": 2, + "Procedures": [ + "registry_staging_server_GetConfiguration", + "registry_staging_server_RequestStaging" + ], + "ProcStackSize": 64, + "DispatchFunction": 140706797733328, + "Service": null, + "IsServiceRunning": false + }, + "f2c9b409-c1c9-4100-8639-d8ab1486694a": { + "Module": "wkssvc.dll", + "ModulePath": "C:\\Windows\\System32\\wkssvc.dll", + "InterfaceId": "f2c9b409-c1c9-4100-8639-d8ab1486694a", + "InterfaceStructOffset": 195888, + "ProceduresCount": 2, + "Procedures": [ + "ClusterConnectUpcall", + "ClusterDisConnectUpcall" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708036954688, + "Service": "LanmanWorkstation", + "IsServiceRunning": true + }, + "880fd55e-43b9-11e0-b1a8-cf4edfd72085": { + "Module": "ncbservice.dll", + "ModulePath": "C:\\Windows\\System32\\ncbservice.dll", + "InterfaceId": "880fd55e-43b9-11e0-b1a8-cf4edfd72085", + "InterfaceStructOffset": 233568, + "ProceduresCount": 4, + "Procedures": [ + "KapiRegisterProvider", + "KapiDeregisterProvider", + "KapiUpdateKaSample", + "KapiReceiveKaUpdateRequest" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708099397504, + "Service": "NcbService", + "IsServiceRunning": true + }, + "0820a0d0-1aae-49f9-acf9-3e3d3fe303cb": { + "Module": "webplatstorageserver.dll", + "ModulePath": "C:\\Windows\\System32\\webplatstorageserver.dll", + "InterfaceId": "0820a0d0-1aae-49f9-acf9-3e3d3fe303cb", + "InterfaceStructOffset": 922240, + "ProceduresCount": 40, + "Procedures": [ + "s_CreateIDBFactory", + "s_IDBFactory_openDatabase", + "s_IDBFactory_deleteDatabase", + "s_IDBFactory_getDatabaseNames", + "s_IDBFactory_setClientOriginAttributes", + "s_IDBFactory_close", + "s_IDBDatabase_createObjectStore", + "s_IDBDatabase_deleteObjectStore", + "s_IDBDatabase_transaction", + "s_IDBDatabase_close", + "s_IDBTransaction_objectStore", + "s_IDBTransaction_abortAndClose", + "s_IDBTransaction_commitAndClose", + "s_IDBObjectStore_put", + "s_IDBObjectStore_add", + "s_IDBObjectStore_get", + "s_IDBObjectStore_getFromKeyRange", + "s_IDBObjectStore_delete", + "s_IDBObjectStore_deleteFromKeyRange", + "s_IDBObjectStore_clear", + "s_IDBObjectStore_openCursor", + "s_IDBObjectStore_count", + "s_IDBObjectStore_createIndex", + "s_IDBObjectStore_openIndex", + "s_IDBObjectStore_deleteIndex", + "s_IDBObjectStore_close", + "s_IDBIndex_openCursor", + "s_IDBIndex_count", + "s_IDBIndex_get", + "s_IDBIndex_getFromKeyRange", + "s_IDBIndex_getKey", + "s_IDBIndex_getKeyFromKeyRange", + "s_IDBIndex_close", + "s_IDBCursor_update", + "s_IDBCursor_continue", + "s_IDBCursor_advance", + "s_IDBCursor_delete", + "s_IDBCursor_close", + "s_IDB_AppQuota_Uninstall", + "s_HaveDataInSharedDatabase" + ], + "ProcStackSize": 24, + "DispatchFunction": 140706993055072, + "Service": null, + "IsServiceRunning": false + }, + "d22895ef-aff4-42c5-a5b2-b14466d34ab4": { + "Module": "diagtrack.dll", + "ModulePath": "C:\\Windows\\System32\\diagtrack.dll", + "InterfaceId": "d22895ef-aff4-42c5-a5b2-b14466d34ab4", + "InterfaceStructOffset": 2709856, + "ProceduresCount": 13, + "Procedures": [ + "UtcEventTranscriptApi_FetchTranscriptStats", + "UtcEventTranscriptApi_FetchTranscriptRecordsPage", + "UtcEventTranscriptApi_FetchTranscriptRecordPayload", + "UtcEventTranscriptApi_FetchKnownTags", + "UtcEventTranscriptApi_FetchEventTags", + "UtcEventTranscriptApi_IsSampledIn", + "UtcEventTranscriptApi_FetchTranscriptRecordsPage2", + "UtcEventTranscriptApi_CancelFetchOperations", + "UtcEventTranscriptApi_FetchEventPerCategoryDistribution", + "UtcEventTranscriptApi_FetchEventPerBinaryDistribution", + "UtcEventTranscriptApi_FetchDiagnosticsStats", + "UtcEventTranscriptApi_SetTranscriptConfiguration", + "UtcEventTranscriptApi_GetTranscriptConfiguration" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707991502544, + "Service": "DiagTrack", + "IsServiceRunning": true + }, + "aed52de0-6162-4172-b4a5-258ff409ecc4": { + "Module": "MpCopyAccelerator.exe", + "ModulePath": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.2109.6-0\\MpCopyAccelerator.exe", + "InterfaceId": "aed52de0-6162-4172-b4a5-258ff409ecc4", + "InterfaceStructOffset": 70736, + "ProceduresCount": 3, + "Procedures": [ + "Proc0", + "Proc1", + "Proc2" + ], + "ProcStackSize": 40, + "DispatchFunction": 140701464608272, + "Service": null, + "IsServiceRunning": false + }, + "38d99c23-51e0-4487-8c43-5b83c7b5ec30": { + "Module": "vmplatformca.exe", + "ModulePath": "C:\\Windows\\System32\\vmplatformca.exe", + "InterfaceId": "38d99c23-51e0-4487-8c43-5b83c7b5ec30", + "InterfaceStructOffset": 21152, + "ProceduresCount": 5, + "Procedures": [ + "RpcVmCaCertProvOpenHandle", + "RpcVmCaCertProvCloseHandle", + "RpcVmCaCreateReport", + "RpcVmCaSetIntermediateCertificate", + "RpcVmCaGetIdkSigningKey" + ], + "ProcStackSize": 40, + "DispatchFunction": 140696258621488, + "Service": null, + "IsServiceRunning": false + }, + "6bbd4016-73b6-4fac-81c4-f2256dcee12d": { + "Module": "AppVShNotify.exe", + "ModulePath": "C:\\Windows\\System32\\AppVShNotify.exe", + "InterfaceId": "6bbd4016-73b6-4fac-81c4-f2256dcee12d", + "InterfaceStructOffset": 103328, + "ProceduresCount": 1, + "Procedures": [ + "s_IShortcutNotify_ShellNotifyPath" + ], + "ProcStackSize": 32, + "DispatchFunction": 140702910023424, + "Service": null, + "IsServiceRunning": false + }, + "a3bae3f7-bf97-49fb-b48d-2a5e8657b436": { + "Module": "PhoneProviders.dll", + "ModulePath": "C:\\Windows\\System32\\PhoneProviders.dll", + "InterfaceId": "a3bae3f7-bf97-49fb-b48d-2a5e8657b436", + "InterfaceStructOffset": 737312, + "ProceduresCount": 25, + "Procedures": [ + "InitializeConnectionToAppHost", + "NewIncomingCall", + "NewIncomingUpgradeCall", + "NewOutgoingCall", + "NewAcceptedCall", + "NewAppInitiatedCall", + "ShowAppUI", + "NewOutgoingUpgradeCall", + "CallAccepted", + "CallActive", + "CallReady", + "CallHeld", + "CallEnded", + "SetMuteState", + "UpdateCallContactName", + "UpdateCallStartTime", + "GetCallStartTime", + "UpdateCallAttributes", + "GetNextVoipAppOperation", + "VoipAppOperationComplete", + "ConfirmVoipNonSeamlessUpgrade", + "CancelVoipUpgrade", + "ReserveVoipCallResources", + "ReserveVoipCallResourcesForOneProcessVoIP", + "CancelVoipCallResourceReservation" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707093695296, + "Service": null, + "IsServiceRunning": false + }, + "8174bb16-571b-4c38-8386-1102b449044a": { + "Module": "pnrpsvc.dll", + "ModulePath": "C:\\Windows\\System32\\pnrpsvc.dll", + "InterfaceId": "8174bb16-571b-4c38-8386-1102b449044a", + "InterfaceStructOffset": 301584, + "ProceduresCount": 13, + "Procedures": [ + "RPCPeerIdentityCreate", + "RPCPeerIdentityRelease", + "RPCPeerIdentityDelete", + "RPCPeerIdentityByPeerName", + "RPCPeerIdentitySetFriendlyName", + "RPCPeerIdentityCreateCert", + "RPCPeerIdentityGetCert", + "RPCPeerIdentitySetCert", + "RPCPeerIdentityList", + "RPCPeerIdentityGroupCreate", + "RPCPeerIdentityGroupList", + "RPCPeerIdentityGroupDelete", + "RPCPeerIdentityImport" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707580889584, + "Service": "PNRPsvc", + "IsServiceRunning": false + }, + "2bacbe6a-051a-4524-b495-c26a9878fb2b": { + "Module": "HostNetSvc.dll", + "ModulePath": "C:\\Windows\\System32\\HostNetSvc.dll", + "InterfaceId": "2bacbe6a-051a-4524-b495-c26a9878fb2b", + "InterfaceStructOffset": 2501600, + "ProceduresCount": 1, + "Procedures": [ + "HnsRpcHv_NotifyGuestStatus" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707750176736, + "Service": "hns", + "IsServiceRunning": true + }, + "eb17bee4-2a08-46ba-89d3-0be4a2239df3": { + "Module": "TSVIPSrv.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-t..-tsappsrv-component_31bf3856ad364e35_10.0.18362.1316_none_7c6dc83f556303be\\TSVIPSrv.dll", + "InterfaceId": "eb17bee4-2a08-46ba-89d3-0be4a2239df3", + "InterfaceStructOffset": 98384, + "ProceduresCount": 3, + "Procedures": [ + "RpcRequestVirtualIP", + "FailedToBind", + "RpcGetMachineIPs" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707880843744, + "Service": null, + "IsServiceRunning": false + }, + "1ff70682-0a51-30e8-076d-740be8cee98b": { + "Module": "taskcomp.dll", + "ModulePath": "C:\\Windows\\System32\\taskcomp.dll", + "InterfaceId": "1ff70682-0a51-30e8-076d-740be8cee98b", + "InterfaceStructOffset": 293472, + "ProceduresCount": 4, + "Procedures": [ + "NetrJobAdd", + "NetrJobDel", + "NetrJobEnum", + "NetrJobGetInfo" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708043127840, + "Service": null, + "IsServiceRunning": false + }, + "51919b05-128e-4db4-9686-27e6c89a7db9": { + "Module": "psp.exe", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-p..ioningsecureprocess_31bf3856ad364e35_10.0.18362.1_none_69337af49cf9e1d5\\psp.exe", + "InterfaceId": "51919b05-128e-4db4-9686-27e6c89a7db9", + "InterfaceStructOffset": 124416, + "ProceduresCount": 5, + "Procedures": [ + "RpcPspTerminate", + "RpcPspOpenHandle", + "RpcPspCloseHandle", + "RpcPspSetMessageBuffer", + "RpcPspCallbackWorker" + ], + "ProcStackSize": 24, + "DispatchFunction": 140697258585424, + "Service": null, + "IsServiceRunning": false + }, + "7a20fcec-dec4-4c59-be57-212e8f65d3de": { + "Module": "SgrmBroker.exe", + "ModulePath": "C:\\Windows\\System32\\SgrmBroker.exe", + "InterfaceId": "7a20fcec-dec4-4c59-be57-212e8f65d3de", + "InterfaceStructOffset": 182720, + "ProceduresCount": 5, + "Procedures": [ + "s_SgrmCreateSession", + "s_SgrmEndSession", + "s_GetSessionReport", + "s_GetRuntimeReport", + "s_GetSessionCertificate" + ], + "ProcStackSize": 40, + "DispatchFunction": 140696621664176, + "Service": "SgrmBroker", + "IsServiceRunning": true + }, + "4a452661-8290-4b36-8fbe-7f4093a94978": { + "Module": "spoolsv.exe", + "ModulePath": "C:\\Windows\\System32\\spoolsv.exe", + "InterfaceId": "4a452661-8290-4b36-8fbe-7f4093a94978", + "InterfaceStructOffset": 557936, + "ProceduresCount": 4, + "Procedures": [ + "IRPCAsyncNotifyChannel_CreateChannel", + "IRPCAsyncNotifyChannel_SendNotification", + "IRPCAsyncNotifyChannel_SendNotificationGetResponse", + "IRPCAsyncNotifyChannel_CloseChannel" + ], + "ProcStackSize": 48, + "DispatchFunction": 140698296497600, + "Service": "Spooler", + "IsServiceRunning": true + }, + "6c9b7b96-45a8-4cca-9eb3-e21ccf8b5a89": { + "Module": "umpo.dll", + "ModulePath": "C:\\Windows\\System32\\umpo.dll", + "InterfaceId": "6c9b7b96-45a8-4cca-9eb3-e21ccf8b5a89", + "InterfaceStructOffset": 81984, + "ProceduresCount": 33, + "Procedures": [ + "UmpoRpcGetPowerConfiguration", + "UmpoRpcReadFromSystemPowerKey", + "UmpoRpcReadFromUserPowerKey", + "UmpoRpcReadACValue", + "UmpoRpcReadDCValue", + "UmpoRpcWriteToSystemPowerKey", + "UmpoRpcWriteToUserPowerKey", + "UmpoRpcApplyPowerRequestOverride", + "UmpoRpcApplyPowerSetting", + "UmpoRpcSetActiveScheme", + "UmpoRpcGetActiveScheme", + "UmpoRpcSetActiveOverlayScheme", + "UmpoRpcGetActualOverlayScheme", + "UmpoRpcGetEffectiveOverlayScheme", + "UmpoRpcGetOverlaySchemes", + "UmpoRpcRestoreDefaultScheme", + "UmpoRpcRestoreDefaultSchemesAll", + "UmpoRpcDuplicateScheme", + "UmpoRpcDeleteScheme", + "UmpoRpcImportScheme", + "UmpoRpcReplaceDefaultPowerSchemes", + "UmpoRpcLegacyEventRegisterNotification", + "UmpoRpcEnumerate", + "UmpoRpcReadSecurityDescriptor", + "UmpoRpcWriteSecurityDescriptor", + "UmpoRpcSettingAccessCheck", + "UmpoRpcCreateSetting", + "UmpoRpcCreatePossibleSetting", + "UmpoRpcRemoveSetting", + "UmpoSetExpectedUserAwayIntervals", + "UmpoClearExpectedUserAwayIntervals", + "UmpoGetMinUserAwayPredictionInterval", + "UmpoRpcGetAdaptiveStandbyDiagnostics" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708139495552, + "Service": "Power", + "IsServiceRunning": true + }, + "0d47017b-b33b-46ad-9e18-fe96456c5078": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "0d47017b-b33b-46ad-9e18-fe96456c5078", + "InterfaceStructOffset": 564272, + "ProceduresCount": 4, + "Procedures": [ + "HamRpcSrvConnectSessionState", + "HamRpcSrvDisconnect", + "HamRpcSrvSessionStateLogoffUser", + "HamRpcSrvSessionStateLogoffSession" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708133531776, + "Service": null, + "IsServiceRunning": false + }, + "ddee8f08-c317-41b1-9f40-d0f57b8f6f20": { + "Module": "ResetEngine.dll", + "ModulePath": "C:\\Windows\\System32\\ResetEngine.dll", + "InterfaceId": "ddee8f08-c317-41b1-9f40-d0f57b8f6f20", + "InterfaceStructOffset": 1223744, + "ProceduresCount": 1, + "Procedures": [ + "PbrCloudPluginDownloadProgressCallback" + ], + "ProcStackSize": 8, + "DispatchFunction": 140707093109632, + "Service": null, + "IsServiceRunning": false + }, + "6bffd098-a112-3610-9833-012892020162": { + "Module": "browser.dll", + "ModulePath": "C:\\Windows\\System32\\browser.dll", + "InterfaceId": "6bffd098-a112-3610-9833-012892020162", + "InterfaceStructOffset": 97664, + "ProceduresCount": 12, + "Procedures": [ + "I_BrowserrServerEnum", + "I_BrowserrDebugCall", + "I_BrowserrQueryOtherDomains", + "I_BrowserrDebugCall", + "I_BrowserrDebugCall", + "I_BrowserrQueryStatistics", + "I_BrowserrResetStatistics", + "NetrBrowserStatisticsClear", + "NetrBrowserStatisticsClear", + "I_BrowserrDebugCall", + "I_BrowserrQueryEmulatedDomains", + "I_BrowserrServerEnumEx" + ], + "ProcStackSize": 80, + "DispatchFunction": 140707594741024, + "Service": "Browser", + "IsServiceRunning": false + }, + "4e25f4a2-21e8-40ce-b401-32050413143a": { + "Module": "ngcsvc.dll", + "ModulePath": "C:\\Windows\\System32\\ngcsvc.dll", + "InterfaceId": "4e25f4a2-21e8-40ce-b401-32050413143a", + "InterfaceStructOffset": 630320, + "ProceduresCount": 16, + "Procedures": [ + "s_DeviceCredentialRpcInitializeProvisioning", + "s_DeviceCredentialRpcCompleteProvisioning", + "s_DeviceCredentialRpcAbortProvisioning", + "s_DeviceCredentialRpcInitializeAuthentication", + "s_DeviceCredentialRpcCompleteAuthentication", + "s_DeviceCredentialRpcShowNotificationMessage", + "s_DeviceCredentialRpcAbortAuthentication", + "s_DeviceCredentialRpcFindFirst", + "s_DeviceCredentialRpcFindNext", + "s_DeviceCredentialRpcGetDeviceInfo", + "s_DeviceCredentialRpcFindClose", + "s_DeviceCredentialRpcDeprovision", + "s_DeviceCredentialRpcSetOpaqueBlob", + "s_DeviceCredentialRpcSetFriendlyName", + "s_DeviceCredentialRpcScanDeploymentData", + "s_DeviceCredentialRpcUpdateDeploymentData" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707094139024, + "Service": "NgcSvc", + "IsServiceRunning": false + }, + "1fff8faa-ec23-4e3f-a8ce-4b2f8707e636": { + "Module": "iphlpsvc.dll", + "ModulePath": "C:\\Windows\\System32\\iphlpsvc.dll", + "InterfaceId": "1fff8faa-ec23-4e3f-a8ce-4b2f8707e636", + "InterfaceStructOffset": 483680, + "ProceduresCount": 2, + "Procedures": [ + "TeredoCreateConsumerHandle", + "TeredoCloseConsumerHandle" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707888011808, + "Service": "iphlpsvc", + "IsServiceRunning": true + }, + "fb8a0729-2d04-4658-be93-27b4ad553fac": { + "Module": "lsass.exe", + "ModulePath": "C:\\Windows\\System32\\lsass.exe", + "InterfaceId": "fb8a0729-2d04-4658-be93-27b4ad553fac", + "InterfaceStructOffset": 24576, + "ProceduresCount": 7, + "Procedures": [ + "LsaLookuprOpenPolicy2", + "LsaLookuprClose", + "LsaLookuprTranslateSids2", + "LsaLookuprTranslateNames3", + "LsaLookuprManageCache", + "LsaLookuprGetDomainInfo", + "LsaLookuprUserAccountType" + ], + "ProcStackSize": 32, + "DispatchFunction": 140698808751088, + "Service": "VaultSvc", + "IsServiceRunning": true + }, + "b50bf410-9fc9-4a20-ab6d-9c7453fe8f94": { + "Module": "DmApiSetExtImplDesktop.dll", + "ModulePath": "C:\\Windows\\System32\\DmApiSetExtImplDesktop.dll", + "InterfaceId": "b50bf410-9fc9-4a20-ab6d-9c7453fe8f94", + "InterfaceStructOffset": 53808, + "ProceduresCount": 1, + "Procedures": [ + "RpcDmUI_SubmitUserInput" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707880919632, + "Service": null, + "IsServiceRunning": false + }, + "4b183cf6-affd-4872-9da2-7564b683d027": { + "Module": "AppVEntSubsystemController.dll", + "ModulePath": "C:\\Windows\\System32\\AppVEntSubsystemController.dll", + "InterfaceId": "4b183cf6-affd-4872-9da2-7564b683d027", + "InterfaceStructOffset": 900368, + "ProceduresCount": 6, + "Procedures": [ + "jitv_server_get_package_for_process", + "jitv_find_ve_for_path", + "jitv_virtual_module_loaded", + "jitv_virtual_module_unloaded", + "jitv_activate_for_thread", + "jitv_deactivate_for_thread" + ], + "ProcStackSize": 32, + "DispatchFunction": 140706797674144, + "Service": null, + "IsServiceRunning": false + }, + "bde95fdf-eee0-45de-9e12-e5a61cd0d4fe": { + "Module": "termsrv.dll", + "ModulePath": "C:\\Windows\\System32\\termsrv.dll", + "InterfaceId": "bde95fdf-eee0-45de-9e12-e5a61cd0d4fe", + "InterfaceStructOffset": 750928, + "ProceduresCount": 12, + "Procedures": [ + "RpcGetClientData", + "RpcGetConfigData", + "RpcGetProtocolStatus", + "RpcGetLastInputTime", + "RpcGetRemoteAddress", + "RpcShadow", + "RpcShadowTarget", + "RpcShadowStop", + "RpcGetAllListeners", + "RpcGetSessionProtocolLastInputTime", + "RpcGetUserCertificates", + "RpcQuerySessionData" + ], + "ProcStackSize": 80, + "DispatchFunction": 140708118828576, + "Service": "TermService", + "IsServiceRunning": true + }, + "c100beac-d33a-4a4b-bf23-bbef4663d017": { + "Module": "wcncsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wcncsvc.dll", + "InterfaceId": "c100beac-d33a-4a4b-bf23-bbef4663d017", + "InterfaceStructOffset": 352384, + "ProceduresCount": 4, + "Procedures": [ + "WcnSinkOpenHandle", + "WcnSinkCloseHandle", + "WcnSinkDeliverMessage", + "WcnSinkAsyncGetNextAction" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707580952704, + "Service": "wcncsvc", + "IsServiceRunning": false + }, + "509bc7ae-77be-4ee8-b07c-0d096bb44345": { + "Module": "DispBroker.Desktop.dll", + "ModulePath": "C:\\Windows\\System32\\DispBroker.Desktop.dll", + "InterfaceId": "509bc7ae-77be-4ee8-b07c-0d096bb44345", + "InterfaceStructOffset": 289696, + "ProceduresCount": 9, + "Procedures": [ + "ColorManagementRpcServerOpenFromMonitorId", + "ColorManagementRpcServerClose", + "ColorManagementRpcServerGetDisplayActiveColorProfile", + "ColorManagementRpcServerSetDisplayColorGdiLut", + "ColorManagementRpcServerGetDisplayColorGdiLut", + "ColorManagementRpcServerSetDisplayColorLut", + "ColorManagementRpcServerGetDisplayColorLut", + "ColorManagementRpcServerSetDisplayColorMatrix", + "ColorManagementRpcServerGetDisplayColorMatrix" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708076860416, + "Service": "DispBrokerDesktopSvc", + "IsServiceRunning": true + }, + "ae33069b-a2a8-46ee-a235-ddfd339be281": { + "Module": "spoolsv.exe", + "ModulePath": "C:\\Windows\\System32\\spoolsv.exe", + "InterfaceId": "ae33069b-a2a8-46ee-a235-ddfd339be281", + "InterfaceStructOffset": 580000, + "ProceduresCount": 2, + "Procedures": [ + "IRPCRemoteObject_Create", + "IRPCRemoteObject_Delete" + ], + "ProcStackSize": 8, + "DispatchFunction": 140698296505296, + "Service": "Spooler", + "IsServiceRunning": true + }, + "085b0334-e454-4d91-9b8c-4134f9e793f3": { + "Module": "psmsrv.dll", + "ModulePath": "C:\\Windows\\System32\\psmsrv.dll", + "InterfaceId": "085b0334-e454-4d91-9b8c-4134f9e793f3", + "InterfaceStructOffset": 168384, + "ProceduresCount": 13, + "Procedures": [ + "PsmSrvOpenManagementChannel", + "PsmSrvSetApplicationState", + "PsmSrvSetApplicationPriority", + "PsmSrvReleaseCacheEntry", + "PsmSrvAcquireCachedEntries", + "PsmSrvQueryApplicationSwapState", + "PsmSrvCloseActivationChannel", + "PsmSrvSetApplicationProperties", + "PsmSrvQueryApplicationProperties", + "PsmSrvQueryApplicationResourceUsage", + "PsmSrvQueryMemoryUsage", + "PsmSrvResetMaxMemoryUsage", + "PsmSrvQuerySharedCommit" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708134215616, + "Service": "BrokerInfrastructure", + "IsServiceRunning": true + }, + "45776b01-5956-4485-9f80-f428f7d60129": { + "Module": "dnsrslvr.dll", + "ModulePath": "C:\\Windows\\System32\\dnsrslvr.dll", + "InterfaceId": "45776b01-5956-4485-9f80-f428f7d60129", + "InterfaceStructOffset": 249856, + "ProceduresCount": 25, + "Procedures": [ + "R_ReadCache", + "R_ResolverGetConfig", + "R_ResolverFlushCache", + "R_ResolverFlushCacheEntry", + "R_ResolverQuery", + "R_DnsRegisterLocal", + "R_DnsDeRegisterLocal", + "R_DnsStartMulticastQuery", + "R_DnsGetMulticastData", + "R_DnsStopMulticastQuery", + "R_ResolverSimpleOp", + "R_DnsGetProxyInformation", + "R_DnsGetPolicyTableInfo", + "R_DnsSetConnectionPolicyInfo", + "R_DnsDeleteConnectionPolicyInfo", + "R_DnsGetSettings", + "R_DnsGetSettings", + "R_DnsSetSettings", + "R_DnsSetSettings", + "R_DnsGetInterfaceSettings", + "R_DnsGetInterfaceSettings", + "R_DnsSetInterfaceSettings", + "R_DnsSetInterfaceSettings", + "R_DnsGetAdaptersInfo", + "R_DnsSetNrptRules" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708025509552, + "Service": "Dnscache", + "IsServiceRunning": true + }, + "32507ba5-a647-4201-83a9-d3a02c0fb0f8": { + "Module": "Wex.Communication.dll", + "ModulePath": "C:\\Program Files (x86)\\Windows Kits\\10\\Testing\\Runtimes\\TAEF\\MinTe\\Wex.Communication.dll", + "InterfaceId": "32507ba5-a647-4201-83a9-d3a02c0fb0f8", + "InterfaceStructOffset": 214640, + "ProceduresCount": 4, + "Procedures": [ + "RpcEntry_Initialize", + "RpcEntry_ReceiveData", + "RpcEntry_MoreData", + "RpcEntry_Close" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707880289824, + "Service": null, + "IsServiceRunning": false + }, + "ba4aa15a-be94-47fb-9bfb-fef110e7efad": { + "Module": "DevQueryBroker.dll", + "ModulePath": "C:\\Windows\\System32\\DevQueryBroker.dll", + "InterfaceId": "ba4aa15a-be94-47fb-9bfb-fef110e7efad", + "InterfaceStructOffset": 24464, + "ProceduresCount": 1, + "Procedures": [ + "DqbGetEvents" + ], + "ProcStackSize": 80, + "DispatchFunction": 140707960198384, + "Service": "DevQueryBroker", + "IsServiceRunning": false + }, + "082a3471-31b6-422a-b931-a54401960c62": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "082a3471-31b6-422a-b931-a54401960c62", + "InterfaceStructOffset": 570592, + "ProceduresCount": 13, + "Procedures": [ + "HamRpcSrvConnectExtendedExecution", + "HamRpcSrvDisconnect", + "HamRpcSrvQueryTaskCompletionsForTerminateGraph", + "HamRpcSrvCreateExtendedExecution", + "HamRpcSrvStartExtendedExecutionAsync", + "HamRpcSrvCloseActivity", + "HamRpcSrvAddDependency", + "HamRpcSrvRemoveDependency", + "HamRpcSrvAddHostDependency", + "HamRpcSrvRemoveHostDependency", + "HamRpcSrvTerminateSelf", + "HamRpcSrvTerminateSelfOnRequiredProcessExit", + "HamRpcSrvTryEstimateRemainingQuiesceTime" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708133527920, + "Service": null, + "IsServiceRunning": false + }, + "9cfeead6-6135-4fcf-831a-fd3b236023f8": { + "Module": "LsaIso.exe", + "ModulePath": "C:\\Windows\\System32\\LsaIso.exe", + "InterfaceId": "9cfeead6-6135-4fcf-831a-fd3b236023f8", + "InterfaceStructOffset": 194400, + "ProceduresCount": 31, + "Procedures": [ + "KerbIumGetClientContext", + "KerbIumEncryptPassword", + "KerbIumBuildPasswordList", + "KerbIumBuildAsReqAuthenticator", + "KerbIumVerifyServiceTicket", + "KerbIumCreateApReqAuthenticator", + "KerbIumDecryptApReply", + "KerbIumUnpackKdcReplyBody", + "KerbIumComputeTgsChecksum", + "KerbIumBuildEncryptedAuthData", + "KerbIumPackApReply", + "KerbIumHashS4UPreauth", + "KerbIumSignS4UPreauthData", + "KerbIumVerifyChecksum", + "KerbIumBuildTicketArmorKey", + "KerbIumBuildExplicitArmorKey", + "KerbIumVerifyFastArmoredTgsReply", + "KerbIumVerifyEncryptedChallengePaData", + "KerbIumBuildFastArmoredKdcRequest", + "KerbIumDecryptFastArmoredKerbError", + "KerbIumDecryptFastArmoredAsReply", + "KerbIumUpdateSharedConfiguration", + "KerbIumDecryptPacCredentials", + "KerbIumCreateECDHKeyAgreement", + "KerbIumCreateDHKeyAgreement", + "KerbIumDestroyKeyAgreement", + "KerbIumKeyAgreementGenerateNonce", + "KerbIumFinalizeKeyAgreement", + "KerbIumSignPkcsMessage", + "KerbIumConvertCredManPasswordToKerbPassword", + "KerbIumAreEncryptionKeysEqual" + ], + "ProcStackSize": 40, + "DispatchFunction": 140697528960176, + "Service": null, + "IsServiceRunning": false + }, + "f50aac00-c7f3-428e-a022-a6b71bfb9d43": { + "Module": "cryptcatsvc.dll", + "ModulePath": "C:\\Windows\\System32\\cryptcatsvc.dll", + "InterfaceId": "f50aac00-c7f3-428e-a022-a6b71bfb9d43", + "InterfaceStructOffset": 81920, + "ProceduresCount": 8, + "Procedures": [ + "s_SSCatDBAddCatalog", + "s_SSCatDBDeleteCatalog", + "s_SSCatDBEnumCatalogs", + "s_SSCatDBPauseResumeService", + "s_SSCatDBRebuildDatabase", + "s_SSCatDBPrepareForCall", + "s_SSCatDBAddCatalog2", + "s_SSCatDBSmartlockerDefenderCheck" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707994046912, + "Service": null, + "IsServiceRunning": false + }, + "25952c5d-7976-4aa1-a3cb-c35f7ae79d1b": { + "Module": "wlansvc.dll", + "ModulePath": "C:\\Windows\\System32\\wlansvc.dll", + "InterfaceId": "25952c5d-7976-4aa1-a3cb-c35f7ae79d1b", + "InterfaceStructOffset": 2057984, + "ProceduresCount": 6, + "Procedures": [ + "Srv_WDiagRpcInitSession", + "Srv_WDiagRpcEndSession", + "Srv_WDiagRpcQueryStatistics", + "Srv_WDiagRpcQueryConnectionContextInfo", + "Srv_WDiagRpcAutoConfigGetInterfaceInfo", + "Srv_WDiagRpcGetExtensibilityInfo" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707603856032, + "Service": "WlanSvc", + "IsServiceRunning": true + }, + "6bffd098-a112-3610-9833-46c3f87e345a": { + "Module": "wkssvc.dll", + "ModulePath": "C:\\Windows\\System32\\wkssvc.dll", + "InterfaceId": "6bffd098-a112-3610-9833-46c3f87e345a", + "InterfaceStructOffset": 184688, + "ProceduresCount": 31, + "Procedures": [ + "NetrWkstaGetInfo", + "NetrWkstaSetInfo", + "NetrWkstaUserEnum", + "NetrWkstaUserGetInfo", + "NetrWkstaUserSetInfo", + "NetrWkstaTransportEnum", + "NetrWkstaTransportAdd", + "NetrWkstaTransportDel", + "NetrUseAdd", + "NetrUseGetInfo", + "NetrUseDel", + "NetrUseEnum", + "I_NetrLogonDomainNameAdd", + "NetrWorkstationStatisticsGet", + "I_NetrLogonDomainNameAdd", + "I_NetrLogonDomainNameAdd", + "I_NetrLogonDomainNameAdd", + "I_NetrLogonDomainNameAdd", + "I_NetrLogonDomainNameAdd", + "I_NetrLogonDomainNameAdd", + "NetrGetJoinInformation", + "I_NetrLogonDomainNameAdd", + "NetrJoinDomain2", + "NetrUnjoinDomain2", + "NetrRenameMachineInDomain2", + "NetrValidateName2", + "NetrGetJoinableOUs2", + "NetrAddAlternateComputerName", + "NetrRemoveAlternateComputerName", + "NetrSetPrimaryComputerName", + "NetrEnumerateComputerNames" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708036838992, + "Service": "LanmanWorkstation", + "IsServiceRunning": true + }, + "5222821f-d5e2-4885-84f1-5f6185a0ec41": { + "Module": "ncbservice.dll", + "ModulePath": "C:\\Windows\\System32\\ncbservice.dll", + "InterfaceId": "5222821f-d5e2-4885-84f1-5f6185a0ec41", + "InterfaceStructOffset": 233984, + "ProceduresCount": 2, + "Procedures": [ + "RpcSrvRegisterControlChannelReset", + "RpcSrvUnregisterControlChannelReset" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708099551856, + "Service": "NcbService", + "IsServiceRunning": true + }, + "33d99c14-71e0-1487-8c43-9a8328b5ea30": { + "Module": "vmplatformca.exe", + "ModulePath": "C:\\Windows\\System32\\vmplatformca.exe", + "InterfaceId": "33d99c14-71e0-1487-8c43-9a8328b5ea30", + "InterfaceStructOffset": 22512, + "ProceduresCount": 1, + "Procedures": [ + "RpcVmCaIssueCertificate" + ], + "ProcStackSize": 104, + "DispatchFunction": 140696258621792, + "Service": null, + "IsServiceRunning": false + }, + "6770612b-b256-4b6e-891b-2ff9936755a1": { + "Module": "SmsRouterSvc.dll", + "ModulePath": "C:\\Windows\\System32\\SmsRouterSvc.dll", + "InterfaceId": "6770612b-b256-4b6e-891b-2ff9936755a1", + "InterfaceStructOffset": 428336, + "ProceduresCount": 2, + "Procedures": [ + "BriCreateEvent2", + "BriDeleteEvent2" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707580796784, + "Service": "SmsRouter", + "IsServiceRunning": false + }, + "e64b9aee-f372-4312-9a14-8f1502b5c8e3": { + "Module": "ipnathlp.dll", + "ModulePath": "C:\\Windows\\System32\\ipnathlp.dll", + "InterfaceId": "e64b9aee-f372-4312-9a14-8f1502b5c8e3", + "InterfaceStructOffset": 530432, + "ProceduresCount": 16, + "Procedures": [ + "IpNatHlpRpcServerGetConnectedDevices", + "IpNatHlpRpcServerStartSharing", + "IpNatHlpRpcServerStopSharing", + "IpNatHlpRpcServerStartDhcpServer", + "IpNatHlpRpcServerStopDhcpServer", + "IpNatHlpRpcServerUpdateSharingSettingsFromStorage", + "V2IpNatHlpRpcServerStartSharingByInternalPrefix", + "V2IpNatHlpRpcServerStopSharingByInternalPrefix", + "V2IpNatHlpRpcServerStartDhcpServer", + "V2IpNatHlpRpcServerStopDhcpServer", + "V2IpNatHlpRpcServerStartDnsServer", + "V2IpNatHlpRpcServerStopDnsServer", + "V2IpNatHlpRpcServerEnumDhcpState", + "V2IpNatHlpRpcServerEnumDnsState", + "V2IpNatHlpRpcServerCreateStaticMapping", + "V2IpNatHlpRpcServerDeleteStaticMapping" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707971615808, + "Service": "SharedAccess", + "IsServiceRunning": true + }, + "9ccb59aa-1358-4169-aebb-ed83357d6304": { + "Module": "edgehtml.dll", + "ModulePath": "C:\\Windows\\System32\\edgehtml.dll", + "InterfaceId": "9ccb59aa-1358-4169-aebb-ed83357d6304", + "InterfaceStructOffset": 21370720, + "ProceduresCount": 173, + "Procedures": [ + "ControlToEdgeServerIOleHostConnect", + "ControlToEdgeServerIOleHostDisconnect", + "ControlToEdgeServerIOleHostConnectUiThread", + "ControlToEdgeServerIOleHostDisconnectUiThread", + "ControlToEdgeServerIOleHostHandleGetWindowContext", + "ControlToEdgeServerIOleHostHandleGetMoniker", + "ControlToEdgeServerIOleHostHandleQueryServiceForWebBrowserObject", + "ControlToEdgeServerIOleHostClientAddRef", + "ControlToEdgeServerIOleHostClientRelease", + "ControlToEdgeServerIOleHostQueryServiceForWindowObject", + "ControlToEdgeServerDisconnectIDataObject", + "ControlToEdgeServerIDispatchGetDispatchHandleForParam", + "ControlToEdgeServerIDispatchInvokeWithHandle", + "ControlToEdgeServerIDispatchInvokeRequestHandle", + "ControlToEdgeServerIDispatchExGetDispID", + "ControlToEdgeServerIDispatchExDeleteMemberByName", + "ControlToEdgeServerIRemoteSurfacePresenterFrontBufferDisconnect", + "ControlToEdgeServerIFlashShimHandlerCreateIconFromBuffer", + "ControlToEdgeServerIFlashShimHandlerDestroyIcon", + "ControlToEdgeServerIFlashShimHandlerSetCursorById", + "ControlToEdgeServerIFlashShimHandlerSetCursorPos", + "ControlToEdgeServerIFlashShimHandlerGetPointerFrameInfoHistorySize", + "ControlToEdgeServerIFlashShimHandlerGetPointerFrameInfoHistory", + "ControlToEdgeServerIFlashShimHandlerGetPointerInfo", + "ControlToEdgeServerIFlashShimHandlerGetPointerFrameTouchInfo", + "ControlToEdgeServerIFlashShimHandlerGetCurrentInputMessageSource", + "ControlToEdgeServerIFlashShimHandlerImmGetContext", + "ControlToEdgeServerIFlashShimHandlerGetKeyboardLayout", + "ControlToEdgeServerIFlashShimHandlerActivateKeyboardLayout", + "ControlToEdgeServerIFlashShimHandlerOleGetClipboard", + "ControlToEdgeServerIFlashShimHandlerOleSetClipboard", + "ControlToEdgeServerIWebBrowser2HandleQueryServiceForTargetFrameObject", + "ControlToEdgeServerIWebBrowser2GetDocument", + "ControlToEdgeServerDisconnectIDataObject", + "ControlToEdgeServerITargetFrame2FindFrame", + "ControlToEdgeServerDisconnectIDataObject", + "ControlToEdgeServerDisconnectIDataObject", + "ControlToEdgeServerIHTMLDocument2get_Script", + "ControlToEdgeServerIHTMLDocument2get_parentWindow", + "ControlToEdgeServerDisconnectIDataObject", + "ControlToEdgeServerIHTMLWindow2get_parent", + "ControlToEdgeServerIHTMLWindow2get_document", + "ControlToEdgeServerIHTMLWindow2get_top", + "ControlToEdgeServerIHTMLWindow2get_location", + "ControlToEdgeServerIHTMLWindow2ExecuteEvalScriptWithResultWrapper", + "ControlToEdgeServerIHTMLWindow2get_userAgent", + "ControlToEdgeServerDisconnectIDataObject", + "ControlToEdgeServerIActiveXUIHandlerSiteHandleSaveFilePickerAndGetResult", + "ControlToEdgeServerIOleHostHandleChainPlayToSources", + "ControlToEdgeServerDisconnectIDataObject", + "ControlToEdgeServerIEnumFORMATETCNext", + "ControlToEdgeServerDisconnectIDataObject", + "ControlToEdgeServerIDataObjectGetData", + "ControlToEdgeServerIDataObjectEnumFormatEtc", + "ControlToEdgeServerIHGlobalHolderGetGlobalData", + "ControlToEdgeServerDisconnectIHGlobalHolder", + "ControlToEdgeServerCallBlockTabForDialogUntilActive", + "ControlToEdgeServerIOleHostHandleDeactivateAndUndo", + "ControlToEdgeServerIOleHostHandleDiscardUndoState", + "ControlToEdgeServerIOleHostHandleOnInPlaceActivateEx", + "ControlToEdgeServerIOleHostHandleOnInPlaceDeactivateEx", + "ControlToEdgeServerIOleHostHandleOnInPlaceDeactivate", + "ControlToEdgeServerIOleHostHandleOnUIActivate", + "ControlToEdgeServerIOleHostHandleOnUIDeactivate", + "ControlToEdgeServerIOleHostHandleRequestUIActivate", + "ControlToEdgeServerIOleHostHandleCanWindowlessActivate", + "ControlToEdgeServerIOleHostHandleGetCapture", + "ControlToEdgeServerIOleHostHandleSetCapture", + "ControlToEdgeServerIOleHostHandleGetFocus", + "ControlToEdgeServerIOleHostHandleSetFocus", + "ControlToEdgeServerIOleHostHandleInvalidateRect", + "ControlToEdgeServerIOleHostHandleIsHardwareComposition", + "ControlToEdgeServerIOleHostHandleRequestFrame", + "ControlToEdgeServerIOleHostGetSurfacePresenterFlipMode", + "ControlToEdgeServerIOleHostHandleCreateIndependentSurfacePresenterFlip", + "ControlToEdgeServerIOleHostHandleCreateDependentSurfacePresenterFlip", + "ControlToEdgeServerIOleHostHandleGetDeviceLuid", + "ControlToEdgeServerIOleHostHandleEnterFullScreen", + "ControlToEdgeServerIOleHostHandleExitFullScreen", + "ControlToEdgeServerIOleHostHandleIsFullScreen", + "ControlToEdgeServerIOleHostHandleGetMetrics", + "ControlToEdgeServerIOleHostHandleGetFullScreenSize", + "ControlToEdgeServerIOleHostHandleGetRotationForCurrentOutput", + "ControlToEdgeServerIOleHostHandleLockInPlaceActive", + "ControlToEdgeServerIOleHostHandleGetExtendedControl", + "ControlToEdgeServerIOleHostHandleTranslateAccelerator", + "ControlToEdgeServerIOleHostHandleShowPropertyFrame", + "ControlToEdgeServerIOleHostPopulatePersistPropertyBag", + "ControlToEdgeServerIOleHostHandleAcquireObjectIdRange", + "ControlToEdgeServerIOleHostHandleReleaseObjectIdRange", + "ControlToEdgeServerIOleHostHandleGetWindow", + "ControlToEdgeServerIOleHostHandleOnDataChange", + "ControlToEdgeServerIOleHostHandleOnViewChange", + "ControlToEdgeServerIOleHostHandleViewStatusChange", + "ControlToEdgeServerIOleHostHandleShowObject", + "ControlToEdgeServerIOleHostHandleOnShowWindow", + "ControlToEdgeServerIOleHostHandleRequestNewObjectLayout", + "ControlToEdgeServerIOleHostHandleValidateSecureUrl", + "ControlToEdgeServerIOleHostHandleEventNotify", + "ControlToEdgeServerIOleHostGetPlayToObjectStateIsMuted", + "ControlToEdgeServerIOleHostHandleAddSuspensionExemption", + "ControlToEdgeServerIOleHostHandleRemoveSuspensionExemption", + "ControlToEdgeServerIOleHostHandleMessageBoxW", + "ControlToEdgeServerIOleHostHandleSetManipulationMode", + "ControlToEdgeServerIOleHostHandleZoomToPoint", + "ControlToEdgeServerIOleHostHandleOnMediaActivityStarted", + "ControlToEdgeServerIOleHostHandleOnMediaActivityStopped", + "ControlToEdgeServerIOleHostHandleGetAudioSessionGuid", + "ControlToEdgeServerIOleHostHandleOnAudioStreamCreated", + "ControlToEdgeServerIOleHostHandleOnAudioStreamDestroyed", + "ControlToEdgeServerIOleHostHandleGetOpticalZoomPercent", + "ControlToEdgeServerIOleHostHandleITridentHostWindowInfoSiteGetWindowRect", + "ControlToEdgeServerIOleHostHandleITridentHostWindowInfoSiteGetClientRect", + "ControlToEdgeServerIOleHostHandleITridentHostWindowInfoSiteScreenToClient", + "ControlToEdgeServerIOleHostHandleITridentHostWindowInfoSiteClientToScreen", + "ControlToEdgeServerIOleHostHandleITridentHostWindowInfoSiteMapWindowPoints", + "ControlToEdgeServerIOleHostHandleITridentHostWindowInfoSiteWindowFromPoint", + "ControlToEdgeServerIOleHostHandleITridentHostWindowInfoSiteGetFocus", + "ControlToEdgeServerIOleHostHandleITridentHostWindowInfoSiteSetFocus", + "ControlToEdgeServerIOleHostHandleImmGetContext", + "ControlToEdgeServerIOleHostHandleImmReleaseContext", + "ControlToEdgeServerIOleHostHandleImmAssociateContextEx", + "ControlToEdgeServerIOleHostGetUrlForCreateMoniker", + "ControlToEdgeServerIOleHostHandleIsClientRectTopMost", + "ControlToEdgeServerIOleHostHandleOnChanged", + "ControlToEdgeServerIOleHostHandleFireRequestEdit", + "ControlToEdgeServerIOleHostHandleReportOutOfMemoryShutdown", + "ControlToEdgeServerIOleHostGetAmbientProp", + "ControlToEdgeServerIOleHostCallFocus", + "ControlToEdgeServerIOleHostGetObjectIDHelper", + "ControlToEdgeServerIOleHostHandleSetBorderSpace", + "ControlToEdgeServerIOleHostHandleSetActiveObject", + "ControlToEdgeServerIOleHostGetObjectIdRangesCount", + "ControlToEdgeServerIOleHostGetObjectIdRanges", + "ControlToEdgeServerIOleHostConnectCrossProcessWindows", + "ControlToEdgeServerIOleHostHandleAllowSetForegroundWindow", + "ControlToEdgeServerIDispatchGetTypeInfoCount", + "ControlToEdgeServerIDispatchGetTypeInfo", + "ControlToEdgeServerIDispatchGetIDsOfNames", + "ControlToEdgeServerIDispatchInvoke", + "ControlToEdgeServerIRemoteSurfacePresenterFrontBufferPresentBackBuffer", + "ControlToEdgeServerIFlashShimHandlerGetKeyState", + "ControlToEdgeServerIFlashShimHandlerShowJSONContextMenu", + "ControlToEdgeServerIFlashShimHandlerGetQueueStatus", + "ControlToEdgeServerIFlashShimHandlerImmReleaseContext", + "ControlToEdgeServerIFlashShimHandlerImmSetCompositionWindow", + "ControlToEdgeServerIFlashShimHandlerImmSetCompositionFontW", + "ControlToEdgeServerIFlashShimHandlerImmGetCompositionFontW", + "ControlToEdgeServerIFlashShimHandlerImmGetCompositionStringW", + "ControlToEdgeServerIFlashShimHandlerImmSetCompositionStringW", + "ControlToEdgeServerIFlashShimHandlerImmSetCandidateWindow", + "ControlToEdgeServerIFlashShimHandlerImmGetOpenStatus", + "ControlToEdgeServerIFlashShimHandlerImmSetOpenStatus", + "ControlToEdgeServerIFlashShimHandlerImmNotifyIME", + "ControlToEdgeServerIFlashShimHandlerImmAssociateContextEx", + "ControlToEdgeServerIFlashShimHandlerImmGetConversionStatus", + "ControlToEdgeServerIFlashShimHandlerImmSetConversionStatus", + "ControlToEdgeServerIFlashShimHandlerImmIsIME", + "ControlToEdgeServerIFlashShimHandlerImmGetProperty", + "ControlToEdgeServerIFlashShimHandlerDefWindowProcW", + "ControlToEdgeServerIFlashShimHandlerSendMessageW", + "ControlToEdgeServerIFlashShimHandlerSendMessageTimeoutW", + "ControlToEdgeServerIWebBrowser2Navigate", + "ControlToEdgeServerIOleHostHandleGetFullScreenSize", + "ControlToEdgeServerIHTMLLocationput_href", + "ControlToEdgeServerIHTMLLocationget_href", + "ControlToEdgeServerIHTMLLocationget_hash", + "ControlToEdgeServerIHTMLDocument2put_title", + "ControlToEdgeServerIHTMLDocument2get_title", + "ControlToEdgeServerIHTMLDocument2get_referrer", + "ControlToEdgeServerIHTMLDocument2get_URL", + "ControlToEdgeServerIEnumFORMATETCReset", + "ControlToEdgeServerIEnumFORMATETCSkip" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707340390160, + "Service": null, + "IsServiceRunning": false + }, + "b58aa02e-2884-4e97-8176-4ee06d794184": { + "Module": "sysmain.dll", + "ModulePath": "C:\\Windows\\System32\\sysmain.dll", + "InterfaceId": "b58aa02e-2884-4e97-8176-4ee06d794184", + "InterfaceStructOffset": 816288, + "ProceduresCount": 1, + "Procedures": [ + "PfRpcServerExecuteCommand" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708066601600, + "Service": "SysMain", + "IsServiceRunning": true + }, + "eef58ec9-6367-47f8-b7f2-b272e4032af9": { + "Module": "hvsimgr.exe", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-hvsi-manager_31bf3856ad364e35_10.0.18362.1832_none_158049e1d563edb9\\hvsimgr.exe", + "InterfaceId": "eef58ec9-6367-47f8-b7f2-b272e4032af9", + "InterfaceStructOffset": 403680, + "ProceduresCount": 11, + "Procedures": [ + "s_ProxyTaskBarMessage", + "s_ProxyTaskBarMessage", + "s_ProxyTaskBarMessage", + "s_ProxyTaskBarMessage", + "s_ProxyTaskBarMessage", + "s_ProxyTaskBarMessage", + "s_ProxyTaskBarMessage", + "s_ProxyTaskBarMessage", + "s_ProxyTaskBarMessage", + "s_ProxyTaskBarMessage", + "s_ProxyTaskBarMessage" + ], + "ProcStackSize": 48, + "DispatchFunction": 140697792740080, + "Service": null, + "IsServiceRunning": false + }, + "497d95a6-2d27-4bf5-9bbd-a6046957133c": { + "Module": "termsrv.dll", + "ModulePath": "C:\\Windows\\System32\\termsrv.dll", + "InterfaceId": "497d95a6-2d27-4bf5-9bbd-a6046957133c", + "InterfaceStructOffset": 749904, + "ProceduresCount": 5, + "Procedures": [ + "RpcOpenListener", + "RpcCloseListener", + "RpcStopListener", + "RpcStartListener", + "RpcIsListening" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708118767520, + "Service": "TermService", + "IsServiceRunning": true + }, + "7419cf08-91a7-4afd-8f5e-1dd76de094fd": { + "Module": "dab.dll", + "ModulePath": "C:\\Windows\\System32\\dab.dll", + "InterfaceId": "7419cf08-91a7-4afd-8f5e-1dd76de094fd", + "InterfaceStructOffset": 81920, + "ProceduresCount": 3, + "Procedures": [ + "s_DabRpcRegisterTriggerConsumer", + "s_DabRpcUnregisterTriggerConsumer", + "s_DabRpcGetLastScheduledRunTime" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708125807648, + "Service": null, + "IsServiceRunning": false + }, + "b37f900a-eae4-4304-a2ab-12bb668c0188": { + "Module": "wcmsvc.dll", + "ModulePath": "C:\\Windows\\System32\\wcmsvc.dll", + "InterfaceId": "b37f900a-eae4-4304-a2ab-12bb668c0188", + "InterfaceStructOffset": 768464, + "ProceduresCount": 12, + "Procedures": [ + "RpcRegisterForNotifications", + "RpcGetPendingNotification", + "RpcCloseNotificationsHandle", + "RpcAcquireSelectableConnectionAsync", + "RpcReleaseSelectableConnection", + "RpcGetSelectableConnectionList", + "RpcGetInterfaceContextTable", + "RpcAddRoutePolicy", + "RpcRemoveRoutePolicy", + "RpcRemoveMatchingRoutePolicy", + "RpcGetRoutingHint", + "RpcCheckCapabilityStatus" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708018990976, + "Service": "Wcmsvc", + "IsServiceRunning": true + }, + "d9844ed9-f72a-4745-a4a1-ee71f950781d": { + "Module": "ngcsvc.dll", + "ModulePath": "C:\\Windows\\System32\\ngcsvc.dll", + "InterfaceId": "d9844ed9-f72a-4745-a4a1-ee71f950781d", + "InterfaceStructOffset": 630032, + "ProceduresCount": 2, + "Procedures": [ + "s_NgcMgmtEnumContainers", + "s_NgcMgmtIsAnyContainerInVsm" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707093723280, + "Service": "NgcSvc", + "IsServiceRunning": false + }, + "1257b580-ce2f-4109-82d6-a9459d0bf6bc": { + "Module": "SessEnv.dll", + "ModulePath": "C:\\Windows\\System32\\SessEnv.dll", + "InterfaceId": "1257b580-ce2f-4109-82d6-a9459d0bf6bc", + "InterfaceStructOffset": 333952, + "ProceduresCount": 1, + "Procedures": [ + "RpcShadow2" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708025010752, + "Service": "SessionEnv", + "IsServiceRunning": true + }, + "1377d115-98fd-4034-b574-111156ca239c": { + "Module": "SystemEventsBrokerServer.dll", + "ModulePath": "C:\\Windows\\System32\\SystemEventsBrokerServer.dll", + "InterfaceId": "1377d115-98fd-4034-b574-111156ca239c", + "InterfaceStructOffset": 154064, + "ProceduresCount": 3, + "Procedures": [ + "_CSebiRegisterPublisher", + "CSebiPublisherUpdateLevelEvent", + "CSebiUnregisterPublisher" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708127099312, + "Service": "SystemEventsBroker", + "IsServiceRunning": true + }, + "2f59a331-bf7d-48cb-9e5c-7c090d76e8b8": { + "Module": "termsrv.dll", + "ModulePath": "C:\\Windows\\System32\\termsrv.dll", + "InterfaceId": "2f59a331-bf7d-48cb-9e5c-7c090d76e8b8", + "InterfaceStructOffset": 767792, + "ProceduresCount": 13, + "Procedures": [ + "RpcLicensingOpenServer", + "RpcLicensingCloseServer", + "RpcLicensingLoadPolicy", + "RpcLicensingLoadPolicy", + "RpcLicensingSetPolicy", + "RpcLicensingGetAvailablePolicyIds", + "RpcLicensingGetPolicy", + "RpcLicensingGetPolicyInformation", + "RpcLicensingDeactivateCurrentPolicy", + "RpcLicensingServerPing", + "RpcGetSessionUnderArbitration", + "RpcLicensingSetAadInfo", + "RpcLicensingGetAadInfo" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708119277488, + "Service": "TermService", + "IsServiceRunning": true + }, + "52d9f704-d3c6-4748-ad11-2550209e80af": { + "Module": "IMEPADSM.DLL", + "ModulePath": "C:\\Windows\\System32\\IME\\SHARED\\IMEPADSM.DLL", + "InterfaceId": "52d9f704-d3c6-4748-ad11-2550209e80af", + "InterfaceStructOffset": 79888, + "ProceduresCount": 4, + "Procedures": [ + "s_OpenContext", + "s_CloseContext", + "s_PingServerFromClient", + "s_ToServerFromClient" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707880930496, + "Service": null, + "IsServiceRunning": false + }, + "ff9fd3c4-742e-45e0-91dd-2f5bc632a1df": { + "Module": "AppXDeploymentServer.dll", + "ModulePath": "C:\\Windows\\System32\\AppXDeploymentServer.dll", + "InterfaceId": "ff9fd3c4-742e-45e0-91dd-2f5bc632a1df", + "InterfaceStructOffset": 2613024, + "ProceduresCount": 3, + "Procedures": [ + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder", + "AppXApplyTrustLabelToFolder" + ], + "ProcStackSize": 48, + "DispatchFunction": 140706734131232, + "Service": "AppXSvc", + "IsServiceRunning": false + }, + "39730ec4-82ea-4fdf-8a45-c408e393e212": { + "Module": "LsaIso.exe", + "ModulePath": "C:\\Windows\\System32\\LsaIso.exe", + "InterfaceId": "39730ec4-82ea-4fdf-8a45-c408e393e212", + "InterfaceStructOffset": 184224, + "ProceduresCount": 2, + "Procedures": [ + "CredManIumProtectCredential", + "CredManIumCheckProtectedCredential" + ], + "ProcStackSize": 48, + "DispatchFunction": 140697528904608, + "Service": null, + "IsServiceRunning": false + }, + "64fe0b7f-9ef5-4553-a7db-9a1975777554": { + "Module": "RpcRtRemote.dll", + "ModulePath": "C:\\Windows\\System32\\RpcRtRemote.dll", + "InterfaceId": "64fe0b7f-9ef5-4553-a7db-9a1975777554", + "InterfaceStructOffset": 36912, + "ProceduresCount": 3, + "Procedures": [ + "FwConnectToManager", + "FwSubscribeForNewRulesNotification", + "FwInterfaceRegistered" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708134351008, + "Service": null, + "IsServiceRunning": false + }, + "c7ce3826-891f-4376-b161-c63d2403142c": { + "Module": "audiosrv.dll", + "ModulePath": "C:\\Windows\\System32\\audiosrv.dll", + "InterfaceId": "c7ce3826-891f-4376-b161-c63d2403142c", + "InterfaceStructOffset": 1381024, + "ProceduresCount": 1, + "Procedures": [ + "s_RequestHrtfData" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708026150320, + "Service": "Audiosrv", + "IsServiceRunning": true + }, + "8f09f000-b7ed-11ce-bbd2-00001a181cad": { + "Module": "mprdim.dll", + "ModulePath": "C:\\Windows\\System32\\mprdim.dll", + "InterfaceId": "8f09f000-b7ed-11ce-bbd2-00001a181cad", + "InterfaceStructOffset": 360624, + "ProceduresCount": 72, + "Procedures": [ + "RMprAdminServerGetInfo", + "RRasAdminConnectionEnum", + "RRasAdminConnectionGetInfo", + "RRasAdminConnectionClearStats", + "RRasAdminPortEnum", + "RRasAdminPortGetInfo", + "RRasAdminPortClearStats", + "RRasAdminPortReset", + "RRasAdminPortDisconnect", + "RRouterInterfaceTransportSetGlobalInfo", + "RRouterInterfaceTransportGetGlobalInfo", + "RRouterInterfaceGetHandle", + "RRouterInterfaceCreate", + "RRouterInterfaceGetInfo", + "RRouterInterfaceSetInfo", + "RRouterInterfaceDelete", + "RRouterInterfaceTransportRemove", + "RRouterInterfaceTransportAdd", + "RRouterInterfaceTransportGetInfo", + "RRouterInterfaceTransportSetInfo", + "RRouterInterfaceEnum", + "RRouterInterfaceConnect", + "RRouterInterfaceDisconnect", + "RRouterInterfaceUpdateRoutes", + "RRouterInterfaceQueryUpdateResult", + "RRouterInterfaceUpdatePhonebookInfo", + "RMIBEntryCreate", + "RMIBEntryDelete", + "RMIBEntrySet", + "RMIBEntryGet", + "RMIBEntryGetFirst", + "RMIBEntryGetNext", + "RMIBGetTrapInfo", + "RMIBSetTrapInfo", + "RRasAdminConnectionNotification", + "RRasAdminSendUserMessage", + "RRouterDeviceEnum", + "RRouterInterfaceTransportCreate", + "RRouterInterfaceDeviceGetInfo", + "RRouterInterfaceDeviceSetInfo", + "RRouterInterfaceSetCredentialsEx", + "RRouterInterfaceGetCredentialsEx", + "RRasAdminConnectionRemoveQuarantine", + "RMprAdminServerSetInfo", + "RMprAdminServerGetInfoEx", + "RRasAdminConnectionEnumEx", + "RRasAdminConnectionGetInfoEx", + "RMprAdminServerSetInfoEx", + "RRasAdminUpdateConnection", + "RRouterInterfaceSetCredentialsLocal", + "RRouterInterfaceGetCredentialsLocal", + "RRouterInterfaceGetCustomInfoEx", + "RRouterInterfaceSetCustomInfoEx", + "RRouterAdminIsMultiTenancyEnabled", + "RRouterAdminGetRoutingDomainId", + "RRouterAdminInterfaceEnumEx", + "RRouterAdminInterfaceCreateEx", + "RRouterAdminInterfaceGetInfoEx", + "RRouterAdminInterfaceSetInfoEx", + "RRouterAdminInterfaceGetStatisticsEx", + "RRouterAdminInterfaceClearStatisticsEx", + "RRouterMarkServerOffline", + "RRouterAdminRoutingDomainsEnumEx", + "RRouterAdminRoutingDomainGetConfigEx", + "RRouterAdminRoutingDomainSetConfigEx", + "RRouterAdminAddRoutingDomainEx", + "RRouterAdminDeleteRoutingDomainEx", + "RRasAdminRoutingDomainConnectionEnumEx", + "RRouterProtocolAction", + "RRouterGetProtocolStatistics", + "RRouterAdminIsModernStackEnabled", + "RRouterInterfaceAddIkev2Policy" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707580693408, + "Service": "RemoteAccess", + "IsServiceRunning": false + }, + "795b6bf9-97b6-4f89-bd8d-2f42bbbe996e": { + "Module": "DMPushRouterCore.dll", + "ModulePath": "C:\\Windows\\System32\\DMPushRouterCore.dll", + "InterfaceId": "795b6bf9-97b6-4f89-bd8d-2f42bbbe996e", + "InterfaceStructOffset": 152784, + "ProceduresCount": 4, + "Procedures": [ + "RpcPushRouter_Open", + "RpcPushRouter_Close", + "RpcPushRouter_GetPushMessage", + "RpcPushRouter_SubmitPush" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707581018112, + "Service": null, + "IsServiceRunning": false + }, + "fae436b0-b864-4a87-9eda-298547cd82f2": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "fae436b0-b864-4a87-9eda-298547cd82f2", + "InterfaceStructOffset": 572064, + "ProceduresCount": 8, + "Procedures": [ + "HamRpcSrvConnectDebugging", + "HamRpcSrvDisconnect", + "HamRpcSrvDebugOpenPackageHandle", + "HamRpcSrvDebugClosePackageHandle", + "HamRpcSrvDebugModeEnable", + "HamRpcSrvDebugTerminatePackage", + "HamRpcSrvDebugQueryPackageState", + "HamRpcSrvDebugSuspendPackage" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708133773216, + "Service": null, + "IsServiceRunning": false + }, + "378e52b0-c0a9-11cf-822d-00aa0051e40f": { + "Module": "taskcomp.dll", + "ModulePath": "C:\\Windows\\System32\\taskcomp.dll", + "InterfaceId": "378e52b0-c0a9-11cf-822d-00aa0051e40f", + "InterfaceStructOffset": 294256, + "ProceduresCount": 4, + "Procedures": [ + "SASetAccountInformation", + "SASetNSAccountInformation", + "SAGetNSAccountInformation", + "SAGetAccountInformation" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708043119952, + "Service": null, + "IsServiceRunning": false + }, + "eb081a0d-10ee-478a-a1dd-50995283e7a8": { + "Module": "wkssvc.dll", + "ModulePath": "C:\\Windows\\System32\\wkssvc.dll", + "InterfaceId": "eb081a0d-10ee-478a-a1dd-50995283e7a8", + "InterfaceStructOffset": 195120, + "ProceduresCount": 1, + "Procedures": [ + "GetWitnessNodes" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708036939680, + "Service": "LanmanWorkstation", + "IsServiceRunning": true + }, + "2e7d4935-59d2-4312-a2c8-41900aa5495f": { + "Module": "das.dll", + "ModulePath": "C:\\Windows\\System32\\das.dll", + "InterfaceId": "2e7d4935-59d2-4312-a2c8-41900aa5495f", + "InterfaceStructOffset": 368832, + "ProceduresCount": 3, + "Procedures": [ + "DasCreateChallengeContext", + "DasStartChallengeDevicePresence", + "DasCloseChallengeContext" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707580857088, + "Service": "DeviceAssociationService", + "IsServiceRunning": false + }, + "697dcda9-3ba9-4eb2-9247-e11f1901b0d2": { + "Module": "SystemEventsBrokerServer.dll", + "ModulePath": "C:\\Windows\\System32\\SystemEventsBrokerServer.dll", + "InterfaceId": "697dcda9-3ba9-4eb2-9247-e11f1901b0d2", + "InterfaceStructOffset": 156032, + "ProceduresCount": 6, + "Procedures": [ + "CSebiCreateWellKnownEvent", + "_CSebiCreatePrivateEvent", + "_CSebiDeleteEvent", + "CSebiEnumerateEvents", + "CSebiQueryEventData", + "CSebiCreateCustomEvent" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708127169888, + "Service": "SystemEventsBroker", + "IsServiceRunning": true + }, + "0d72a7d4-6148-11d1-b4aa-00c04fb66ea0": { + "Module": "cryptsvc.dll", + "ModulePath": "C:\\Windows\\System32\\cryptsvc.dll", + "InterfaceId": "0d72a7d4-6148-11d1-b4aa-00c04fb66ea0", + "InterfaceStructOffset": 69632, + "ProceduresCount": 1, + "Procedures": [ + "s_SSCertProtectFunction" + ], + "ProcStackSize": 72, + "DispatchFunction": 140707994358480, + "Service": "CryptSvc", + "IsServiceRunning": true + }, + "2513bcbe-6cd4-4348-855e-7efb3c336dd3": { + "Module": "bisrv.dll", + "ModulePath": "C:\\Windows\\System32\\bisrv.dll", + "InterfaceId": "2513bcbe-6cd4-4348-855e-7efb3c336dd3", + "InterfaceStructOffset": 552256, + "ProceduresCount": 5, + "Procedures": [ + "SrvOdbCreateSession", + "SrvOdbCompleteSession", + "SrvOdbLaunchBackgroundTask", + "SrvOdbCancelBackgroundTask", + "SrvOdbCancelBackgroundTasksForPackage" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708131134752, + "Service": null, + "IsServiceRunning": false + }, + "c604b99f-725f-43d8-a6b8-185086c09c9c": { + "Module": "WpAXHolder.dll", + "ModulePath": "C:\\Windows\\System32\\WpAXHolder.dll", + "InterfaceId": "c604b99f-725f-43d8-a6b8-185086c09c9c", + "InterfaceStructOffset": 297248, + "ProceduresCount": 123, + "Procedures": [ + "EdgeToControlServerIOleControlWrapperConnect", + "EdgeToControlServerIOleControlWrapperDisconnect", + "EdgeToControlServerIOleControlWrapperConnectUiThread", + "EdgeToControlServerIOleControlWrapperDisconnectUiThread", + "EdgeToControlServerIOleControlWrapperHandleNextThreadMessage", + "EdgeToControlServerIOleControlWrapperShutdown", + "EdgeToControlServerIOleControlWrapperCallPersistPropertyBagLoad", + "EdgeToControlServerIOleControlWrapperGetControlReference", + "EdgeToControlServerIOleControlWrapperCallPersistPropertyBagSave", + "EdgeToControlServerIOleControlWrapperCallIMERequestReconvertString", + "EdgeToControlServerIOleControlWrapperCallIMERequestQueryCharPosition", + "EdgeToControlServerDisconnectIPlayToSource", + "EdgeToControlServerIOleControlWrapperGetPlayToSource", + "EdgeToControlServerIPlayToSourceput_Next", + "EdgeToControlServerIPlayToSourcePlayNext", + "EdgeToControlServerGetChainPlayToSources", + "EdgeToControlServerDisconnectIDataObject", + "EdgeToControlServerGetSupportedMediaTypes", + "EdgeToControlServerEnsureIEdgeOutOfProcessCastingHelper", + "EdgeToControlServerDisconnectIDataObject", + "EdgeToControlServerDisconnectIDataObject", + "EdgeToControlServerIDispatchGetDispatchHandleForParam", + "EdgeToControlServerIDispatchInvokeWithHandle", + "EdgeToControlServerIDispatchInvokeRequestHandle", + "EdgeToControlServerIDispatchExGetDispID", + "EdgeToControlServerIDispatchExDeleteMemberByName", + "EdgeToControlServerDisconnectIDataObject", + "EdgeToControlServerIDataObjectGetData", + "EdgeToControlServerIDataObjectQueryGetData", + "EdgeToControlServerIDataObjectEnumFormatEtc", + "EdgeToControlServerDisconnectIDataObject", + "EdgeToControlServerIEnumFORMATETCNext", + "EdgeToControlServerGetDataObject", + "EdgeToControlServerIHGlobalHolderGetGlobalData", + "EdgeToControlServerDisconnectIHGlobalHolder", + "EdgeToControlServerDisconnectIDataObject", + "EdgeToControlServerIOleControlWrapperTestOleObjectPtr", + "EdgeToControlServerIOleControlWrapperCallDoVerb", + "EdgeToControlServerIOleControlWrapperCallClose", + "EdgeToControlServerIOleControlWrapperCallOleRun", + "EdgeToControlServerIOleControlWrapperCallDoEmbedVerbs", + "EdgeToControlServerIOleControlWrapperCallGetExtent", + "EdgeToControlServerIOleControlWrapperCallSetExtent", + "EdgeToControlServerIOleControlWrapperSupportsViewObjectPresenterFlip", + "EdgeToControlServerIOleControlWrapperCallNotifyRender", + "EdgeToControlServerIOleControlWrapperHasViewObjectPresentNotify", + "EdgeToControlServerIOleControlWrapperCallOnPreRender", + "EdgeToControlServerIOleControlWrapperCreateControl", + "EdgeToControlServerIOleControlWrapperRemoveControl", + "EdgeToControlServerIOleControlWrapperSetControlVisibility", + "EdgeToControlServerIOleControlWrapperSetMediaPlaybackState", + "EdgeToControlServerIOleControlWrapperEnsureInPlaceObject", + "EdgeToControlServerIOleControlWrapperClearInPlaceObjectObject", + "EdgeToControlServerIOleControlWrapperSetInPlaceObjectWindowless", + "EdgeToControlServerIOleControlWrapperCallGetWindow", + "EdgeToControlServerIOleControlWrapperCallInPlaceDeactivate", + "EdgeToControlServerIOleControlWrapperCallUIDeactivate", + "EdgeToControlServerIOleControlWrapperCallSetObjectRects", + "EdgeToControlServerIOleControlWrapperCallOnWindowMessage", + "EdgeToControlServerIOleControlWrapperWindowlessControlWindowProc", + "EdgeToControlServerIOleControlWrapperHasViewObject", + "EdgeToControlServerIOleControlWrapperHasViewObjectEx", + "EdgeToControlServerIOleControlWrapperEnsureViewObject", + "EdgeToControlServerIOleControlWrapperClearViewObject", + "EdgeToControlServerIOleControlWrapperCallQueryHitPoint", + "EdgeToControlServerIOleControlWrapperHasPlayToSource", + "EdgeToControlServerIOleControlWrapperGetPlayToCapabilities", + "EdgeToControlServerIOleControlWrapperGetPlayToIsPlaying", + "EdgeToControlServerIOleControlWrapperGetPlayToIsMuted", + "EdgeToControlServerIOleControlWrapperGetCastingSource", + "EdgeToControlServerIOleControlWrapperGetId", + "EdgeToControlServerIOleControlWrapperCallGetDispID", + "EdgeToControlServerIOleControlWrapperGetLongProperty", + "EdgeToControlServerIOleControlWrapperGetBoolProperty", + "EdgeToControlServerIOleControlWrapperGetBstrProperty", + "EdgeToControlServerIOleControlWrapperCallGetNextDispID", + "EdgeToControlServerIOleControlWrapperCallGetMemberName", + "EdgeToControlServerIOleControlWrapperGetControlDispatch", + "EdgeToControlServerIOleControlWrapperCacheDispatch", + "EdgeToControlServerIOleControlWrapperClearDispatchCache", + "EdgeToControlServerIOleControlWrapperIsControlNotRepurposed", + "EdgeToControlServerIOleControlWrapperCallGetActivationPolicy", + "EdgeToControlServerIOleControlWrapperHasSurfacePresenterFlip", + "EdgeToControlServerIOleControlWrapperRenderObjectToSharedBuffer", + "EdgeToControlServerIOleControlWrapperReleasePresenter", + "EdgeToControlServerIOleControlWrapperSavePrintBitmapFromSurfacePresenterFlipControl", + "EdgeToControlServerIOleControlWrapperSupportsOleControl", + "EdgeToControlServerIOleControlWrapperCallFreezeEvents", + "EdgeToControlServerIOleControlWrapperCallGetMiscStatus", + "EdgeToControlServerIOleControlWrapperCallSetHostNames", + "EdgeToControlServerIOleControlWrapperCallUpdate", + "EdgeToControlServerIOleControlWrapperCallIsUpToDate", + "EdgeToControlServerIOleControlWrapperIsQuickActivateSupported", + "EdgeToControlServerIOleControlWrapperQuickActivate", + "EdgeToControlServerIOleControlWrapperSetClientSite", + "EdgeToControlServerIOleControlWrapperUnsetClientSite", + "EdgeToControlServerIOleControlWrapperIsActiveDesignerSupported", + "EdgeToControlServerIOleControlWrapperHasSaveFormatInterface", + "EdgeToControlServerIOleControlWrapperCallInitNew", + "EdgeToControlServerIOleControlWrapperCallGetClassID", + "EdgeToControlServerIOleControlWrapperCallNotifyLeavingView", + "EdgeToControlServerIOleControlWrapperCallOnPointerMessage", + "EdgeToControlServerIOleControlWrapperImplementsITridentTouchInput", + "EdgeToControlServerIOleControlWrapperHasObjectSafety", + "EdgeToControlServerIOleControlWrapperCallMakeObjectSafe", + "EdgeToControlServerIOleControlWrapperCallSetAccessibilityWindow", + "EdgeToControlServerIOleControlWrapperHasInterface", + "EdgeToControlServerIOleControlWrapperCallOnFrameWindowActivate", + "EdgeToControlServerIOleControlWrapperCallTranslateAccelerator", + "EdgeToControlServerIOleControlWrapperCallEnterBFCache", + "EdgeToControlServerIOleControlWrapperCallExitBFCache", + "EdgeToControlServerIOleControlWrapperCallLResultForObjectId", + "EdgeToControlServerIOleControlWrapperUpdateClickToPlayState", + "EdgeToControlServerIOleControlWrapperCallGetCaretPosition", + "EdgeToControlServerIOleControlWrapperCallSetExpandedUrls", + "EdgeToControlServerIDispatchGetTypeInfoCount", + "EdgeToControlServerIDispatchGetTypeInfo", + "EdgeToControlServerIDispatchGetIDsOfNames", + "EdgeToControlServerIDispatchInvoke", + "EdgeToControlServerIEdgeOutOfProcessCastingHelperCreateConnection", + "EdgeToControlServerIEdgeOutOfProcessCastingHelperStartDisconnectConnection", + "EdgeToControlServerIEnumFORMATETCReset", + "EdgeToControlServerIEnumFORMATETCSkip" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707880192480, + "Service": null, + "IsServiceRunning": false + }, + "1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0": { + "Module": "bisrv.dll", + "ModulePath": "C:\\Windows\\System32\\bisrv.dll", + "InterfaceId": "1b37ca91-76b1-4f5e-a3c7-2abfc61f2bb0", + "InterfaceStructOffset": 551680, + "ProceduresCount": 16, + "Procedures": [ + "RBiRtSrvAddWaitableEvent", + "RBiRtSrvAssociateWorkItem", + "RBiRtSrvCreateEvent", + "RBiRtSrvCreateEventForApp", + "RBiRtSrvCreateStatusStateName", + "RBiRtSrvDeleteEvent", + "RBiRtSrvDisassociateWorkItem", + "RBiRtSrvEnumerateBrokeredEvents", + "RBiRtSrvEnumerateWorkItems", + "RBiRtSrvGetWorkItemProperties", + "RBiRtSrvInitiatePause", + "RBiRtSrvQueryBrokerEventId", + "RBiRtSrvQueryBrokerEventIdFromWorkItem", + "RBiRtSrvRegisterWorkItem", + "RBiRtSrvSignalEvent", + "RBiRtSrvUpdateEventParameters" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708131133328, + "Service": null, + "IsServiceRunning": false + }, + "58b19028-b9a0-4c25-887f-aca58b584d1b": { + "Module": "mispace.dll", + "ModulePath": "C:\\Windows\\System32\\mispace.dll", + "InterfaceId": "58b19028-b9a0-4c25-887f-aca58b584d1b", + "InterfaceStructOffset": 2853200, + "ProceduresCount": 1, + "Procedures": [ + "ClusterSpaceControl" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707090917392, + "Service": null, + "IsServiceRunning": false + }, + "de79fc6c-dc6f-43c7-a48e-63bbc8d4009d": { + "Module": "rdpclip.exe", + "ModulePath": "C:\\Windows\\System32\\rdpclip.exe", + "InterfaceId": "de79fc6c-dc6f-43c7-a48e-63bbc8d4009d", + "InterfaceStructOffset": 357584, + "ProceduresCount": 7, + "Procedures": [ + "UMRDP_SHChangeNotify", + "UMRDP_WNetAddConnection2", + "UMRDP_WNetCancelConnection2", + "UMRDP_StorePrinterConfig", + "UMRDP_StoreDefaultPrinter", + "UMRDP_RestoreDefaultPrinter", + "UMRDP_SetDefaultPrinter" + ], + "ProcStackSize": 24, + "DispatchFunction": 140698142225440, + "Service": null, + "IsServiceRunning": false + }, + "11f25515-c879-400a-989e-b074d5f092fe": { + "Module": "lsm.dll", + "ModulePath": "C:\\Windows\\System32\\lsm.dll", + "InterfaceId": "11f25515-c879-400a-989e-b074d5f092fe", + "InterfaceStructOffset": 479600, + "ProceduresCount": 9, + "Procedures": [ + "RpcGetUserToken", + "RpcConnectTerminal", + "RpcSystemShutdownStarted", + "RpcConsumeCacheSession", + "RpcGetRequestForWinlogon", + "RpcReportWinlogonReply", + "RpcGetReconnectId", + "RpcCreateWorkerSession", + "RpcGetWorkerSessionGpuLuid" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708131750400, + "Service": "LSM", + "IsServiceRunning": true + }, + "a111f1c6-5923-47c0-9a68-d0bafb577901": { + "Module": "NetCfgNotifyObjectHost.exe", + "ModulePath": "C:\\Windows\\System32\\NetCfgNotifyObjectHost.exe", + "InterfaceId": "a111f1c6-5923-47c0-9a68-d0bafb577901", + "InterfaceStructOffset": 55600, + "ProceduresCount": 18, + "Procedures": [ + "RpcNetSetup_NotifyHost_Connect", + "RpcNetSetup_NotifyHost_Disconnect", + "RpcNetSetup_Isolation_ExecuteInfSection", + "RpcNetSetup_NotifyObject_Load", + "RpcNetSetup_NotifyObject_Unload", + "RpcNetSetup_ComponentControl_Initialize", + "RpcNetSetup_ComponentControl_ApplyChanges", + "RpcNetSetup_ComponentControl_ApplyPnpChanges", + "RpcNetSetup_ComponentControl_CancelChanges", + "RpcNetSetup_ComponentSetup_Install", + "RpcNetSetup_ComponentSetup_Upgrade", + "RpcNetSetup_ComponentSetup_Removing", + "RpcNetSetup_NotifyBinding_QueryBindingPath", + "RpcNetSetup_NotifyBinding_NotifyBindingPath", + "RpcNetSetup_NotifyGlobal_GetSupportedNotifications", + "RpcNetSetup_NotifyGlobal_SysQueryBindingPath", + "RpcNetSetup_NotifyGlobal_SysNotifyBindingPath", + "RpcNetSetup_NotifyGlobal_SysNotifyComponent" + ], + "ProcStackSize": 40, + "DispatchFunction": 140698387567008, + "Service": null, + "IsServiceRunning": false + }, + "88abcbc3-34ea-76ae-8215-767520655a23": { + "Module": "ResourcePolicyServer.dll", + "ModulePath": "C:\\Windows\\System32\\ResourcePolicyServer.dll", + "InterfaceId": "88abcbc3-34ea-76ae-8215-767520655a23", + "InterfaceStructOffset": 104336, + "ProceduresCount": 21, + "Procedures": [ + "GcsSrv_GetGameConfigSize", + "GcsSrv_GetGameConfig", + "GcsSrv_GetGameConfigSizeForClientProcess", + "GcsSrv_GetGameConfigForClientProcess", + "GcsSrv_ModifyGameConfig", + "GcsSrv_AddGameConfig", + "GcsSrv_RemoveGameConfig", + "GcsSrv_GetGameIdByAUMID", + "GcsSrv_GetGameIdByPID", + "GcsSrv_GetGameIdCount", + "GcsSrv_GetAllGameIds", + "GcsSrv_GetGameIdsByExeNameCount", + "GcsSrv_GetGameIdsByExeName", + "GcsSrv_GetGameProperty", + "GcsSrv_GetGamePropertySize", + "GcsSrv_SetGameProperty", + "GcsSrv_GetGlobalProperty", + "GcsSrv_GetGlobalPropertySize", + "GcsSrv_SetGlobalProperty", + "GcsSrv_SetGamePropertyUserOverride", + "GcsSrv_GetGamePropertyIsUserOverride" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708127396576, + "Service": null, + "IsServiceRunning": false + }, + "5a0ce74d-f9cf-4dea-a4c1-2d5fe4c89d51": { + "Module": "d3d10warp.dll", + "ModulePath": "C:\\Windows\\System32\\d3d10warp.dll", + "InterfaceId": "5a0ce74d-f9cf-4dea-a4c1-2d5fe4c89d51", + "InterfaceStructOffset": 6118256, + "ProceduresCount": 4, + "Procedures": [ + "WARPJITOOPServerConnect", + "WARPJITOOPServerPassMessage", + "WARPJITOOPServerGetConnectionUUID", + "WARPJITOOPServerGetConnectionUUID2" + ], + "ProcStackSize": 48, + "DispatchFunction": 140708050490560, + "Service": null, + "IsServiceRunning": false + }, + "c681d488-d850-11d0-8c52-00c04fd90f7e": { + "Module": "efslsaext.dll", + "ModulePath": "C:\\Windows\\System32\\efslsaext.dll", + "InterfaceId": "c681d488-d850-11d0-8c52-00c04fd90f7e", + "InterfaceStructOffset": 59440, + "ProceduresCount": 21, + "Procedures": [ + "EfsRpcOpenFileRaw_Downlevel", + "EfsRpcReadFileRaw_Downlevel", + "EfsRpcWriteFileRaw_Downlevel", + "EfsRpcCloseRaw_Downlevel", + "EfsRpcEncryptFileSrv_Downlevel", + "EfsRpcDecryptFileSrv_Downlevel", + "EfsRpcQueryUsersOnFile_Downlevel", + "EfsRpcQueryRecoveryAgents_Downlevel", + "EfsRpcRemoveUsersFromFile_Downlevel", + "EfsRpcAddUsersToFile_Downlevel", + "EfsRpcFileKeyInfoEx_Downlevel", + "EfsRpcFileKeyInfoEx_Downlevel", + "EfsRpcFileKeyInfo_Downlevel", + "EfsRpcDuplicateEncryptionInfoFile_Downlevel", + "EfsRpcFileKeyInfoEx_Downlevel", + "EfsRpcAddUsersToFileEx_Downlevel", + "EfsRpcFileKeyInfoEx_Downlevel", + "EfsRpcFileKeyInfoEx_Downlevel", + "EfsRpcFileKeyInfoEx_Downlevel", + "EfsRpcFileKeyInfoEx_Downlevel", + "EfsRpcFlushEfsCache_Downlevel" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708143182256, + "Service": null, + "IsServiceRunning": false + }, + "3573e5f2-cfe7-4a79-845f-fe7c68823738": { + "Module": "PhoneService.dll", + "ModulePath": "C:\\Windows\\System32\\PhoneService.dll", + "InterfaceId": "3573e5f2-cfe7-4a79-845f-fe7c68823738", + "InterfaceStructOffset": 784304, + "ProceduresCount": 3, + "Procedures": [ + "PhoneSvcImpl_PhoneRpcInitializeConnectionToOBA", + "PhoneSvcImpl_PhoneRpcEnableFiltering", + "PhoneSvcImpl_PhoneRpcSetCallBlockingPreferences" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707094326704, + "Service": "PhoneSvc", + "IsServiceRunning": false + }, + "35464382-ad29-4881-9392-b43e55b8f7ac": { + "Module": "audiosrv.dll", + "ModulePath": "C:\\Windows\\System32\\audiosrv.dll", + "InterfaceId": "35464382-ad29-4881-9392-b43e55b8f7ac", + "InterfaceStructOffset": 1379568, + "ProceduresCount": 167, + "Procedures": [ + "AudioServerGetMixFormat", + "AudioServerIsFormatSupported", + "AudioServerGetDevicePeriod", + "AudioServerIsOffloadCapable", + "AudioServerInitialize", + "AudioServerDisconnect", + "AudioServerGetAudioSession", + "AudioServerCreateStream", + "AudioServerStartStream", + "AudioServerStopStream", + "AudioServerPreStartStream", + "AudioServerStartStreamAborted", + "AudioServerResetEndpoint", + "AudioServerDestroyStream", + "AudioServerGetEndpointBufferSize", + "AudioServerGetStreamLatency", + "AudioServerSetStreamSampleRate", + "AudioServerGetChannelCount", + "AudioServerSetChannelVolume", + "AudioServerGetChannelVolume", + "AudioServerSetAllVolumes", + "AudioServerGetAllVolumes", + "AudioServerSetAllInitialVolumesWithRamp", + "AudioSessionGetId", + "AudioSessionGetInstanceId", + "AudioSessionGetStreamSwitchId", + "AudioSessionGetProcessId", + "AudioSessionGetState", + "AudioSessionGetLastActivation", + "AudioSessionGetLastInactivation", + "AudioSessionIsSystemSoundsSession", + "AudioSessionGetDisplayOptions", + "AudioSessionGetDisplayName", + "AudioSessionSetDisplayName", + "AudioSessionGetIconPath", + "AudioSessionSetIconPath", + "AudioSessionGetGroupingParam", + "AudioSessionSetGroupingParam", + "AudioSessionGetVolume", + "AudioSessionSetVolume", + "AudioSessionGetMute", + "AudioSessionSetMute", + "AudioSessionGetChannelCount", + "AudioSessionSetChannelVolume", + "AudioSessionGetChannelVolume", + "AudioSessionSetAllVolumes", + "AudioSessionGetAllVolumes", + "AudioSessionPropertyStoreCommit", + "AudioSessionPropertyStoreGetAt", + "AudioSessionPropertyStoreGetCount", + "AudioSessionPropertyStoreGetValue", + "AudioSessionPropertyStoreSetValue", + "AudioSessionSetDuckingPreference", + "AudioSessionGetDuckingState", + "AudioSessionGetIsComms", + "AudioSessionDestroy", + "AudioSessionMeterGetPeakValue", + "AudioSessionMeterGetMeteringChannelCount", + "AudioSessionMeterGetChannelsPeakValues", + "AudioSessionSetWindowId", + "PolicyConfigGetMixFormat", + "PolicyConfigGetDeviceFormat", + "PolicyConfigGetDeviceFormatForConnector", + "PolicyConfigSetDeviceFormat", + "PolicyConfigResetDeviceFormat", + "PolicyConfigGetProcessingPeriod", + "PolicyConfigSetProcessingPeriod", + "PolicyConfigGetShareMode", + "PolicyConfigSetShareMode", + "PolicyConfigGetPropertyValue", + "PolicyConfigSetPropertyValue", + "PolicyConfigSetDefaultEndpoint", + "PolicyConfigSetEndpointVisibility", + "PolicyConfigSetEndpointAbilityToBeDefault", + "PolicyConfigSetAccessibilityAudioMonoMixState", + "PolicyConfigGetAccessibilityAudioMonoMixState", + "PolicyConfigValidateSpatialAudioSettings", + "PolicyConfigReportSpatialLicenseChanged", + "PolicyConfigSetMixedRealitySpatialAudioFormatPolicy", + "PolicyConfigGetDeviceFormatAndSpatialSettings", + "PolicyConfigSetDeviceSpatialSettings", + "PolicyConfigAddDynamicRoutingRule", + "PolicyConfigRemoveDynamicRoutingRule", + "PolicyConfigUpdateDynamicRoutingRule", + "PolicyConfigGetDynamicRoutingRule", + "GetAudioSessionManager", + "AudioSessionManagerDestroy", + "AudioSessionManagerGetAudioSessions", + "AudioSessionManagerGetCurrentSession", + "AudioSessionManagerGetExistingSession", + "AudioSessionManagerGetSessionForStreamSwitch", + "AudioSessionManagerAddAudioSessionClientNotification", + "AudioSessionManagerDeleteAudioSessionClientNotification", + "AudioSessionManagerAddVolumeDuckNotification", + "AudioSessionManagerDeleteVolumeDuckNotification", + "AudioVolumeConnect", + "AudioVolumeDisconnect", + "AudioVolumeQueryHardwareSupport", + "AudioVolumeGetVolumeRange", + "AudioVolumeGetChannelCount", + "AudioVolumeSetMasterVolumeLevel", + "AudioVolumeSetMasterVolumeLevelScalar", + "AudioVolumeGetMasterVolumeLevel", + "AudioVolumeGetMasterVolumeLevelScalar", + "AudioVolumeSetChannelVolumeLevel", + "AudioVolumeSetChannelVolumeLevelScalar", + "AudioVolumeGetChannelVolumeLevel", + "AudioVolumeGetChannelVolumeLevelScalar", + "AudioVolumeSetMute", + "AudioVolumeGetMute", + "AudioVolumeAddMasterVolumeNotification", + "AudioVolumeDeleteMasterVolumeNotification", + "AudioMeterGetPeakValue", + "AudioMeterGetMeteringChannelCount", + "AudioMeterGetChannelsPeakValues", + "AudioVolumeGetStepInfo", + "AudioVolumeStepUp", + "AudioVolumeStepDown", + "AudioServerGetBufferSizeLimits", + "AudioServerSetLastBufferInProgress", + "AudioServerIsRawStreamSupported", + "AudioServerDeriveStreamCategory", + "AudioServerGetStreamVpoContext", + "AudioServerGetEndpointVpoContext", + "AudioServerCloseVpoContext", + "AudioServerGetCurrentSharedModeEnginePeriod", + "AudioServerGetSharedModeEnginePeriod", + "AudioServerRequestSpatialDynamicObjects", + "AudioServerSetAmbMetadata", + "AudioServerSetAmbHeadTracking", + "AudioServerGetAmbHeadTracking", + "AudioServerSetAmbRotation", + "asm_GetApplicationSubmixContext", + "asm_GetApplicationSubmixContextFromPID", + "asm_GetApplicationSubmixContextForProcessTree", + "asm_ApplicationSubmixContextDestroy", + "asm_GetApplicationSubmixes", + "asm_ApplicationSubmixDestroy", + "asm_AudioServerGetApplicationSubmixFormat", + "asm_AudioServerGetApplicationSubmixPeriod", + "asm_AudioServerGetApplicationSubmixId", + "asm_GetApplicationSubmixFromId", + "asm_AudioServerInitializeStream", + "AudioServerTelephonyControlStartSession", + "AudioServerTelephonyControlIsSessionStarted", + "AudioServerTelephonyControlEndSession", + "AudioServerTelephonyControlSetRoutingPolicy", + "AudioServerTelephonyControlGetRoutingPolicy", + "AudioServerTelephonyControlSetCallState", + "AudioServerTelephonyControlGetCallState", + "AudioServerTelephonyControlProviderChange", + "AudioServerTelephonyControlSetMute", + "AudioServerTelephonyControlGetMute", + "AudioServerTelephonyControlSetVOIPMute", + "AudioServerTelephonyControlGetVOIPMute", + "AudioServerTelephonyControlSetVolume", + "AudioServerTelephonyControlGetMaxCallInstanceCount", + "AudioServerTelephonyControlGetValidTelephonyInstance", + "AudioServerGetAudioHistoryProducerHandle", + "AudioServerReleaseAudioHistoryProducerHandle", + "AudioServerGetAudioHistoryProducerInfo", + "AudioServerPopulateAudioHistoryForStream", + "PolicyConfigGetEndpointExtendedSpatialLicenseInfo", + "PolicyConfigGetSpatialSpeakerProtectionOverrideValue", + "AudioServerCreateStreamConnection", + "AudioServerReleaseStreamConnection", + "AudioServerStartStopStreamConnection" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708026687696, + "Service": "Audiosrv", + "IsServiceRunning": true + }, + "3b338d89-6cfa-44b8-847e-531531bc9992": { + "Module": "psmsrv.dll", + "ModulePath": "C:\\Windows\\System32\\psmsrv.dll", + "InterfaceId": "3b338d89-6cfa-44b8-847e-531531bc9992", + "InterfaceStructOffset": 168576, + "ProceduresCount": 2, + "Procedures": [ + "PsmSrvQueryApplicationPerformanceInformation", + "PsmSrvQueryQuotaInformation" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708134215520, + "Service": "BrokerInfrastructure", + "IsServiceRunning": true + }, + "a111f1c5-5923-47c0-9a68-d0bafb577901": { + "Module": "NetSetupSvc.dll", + "ModulePath": "C:\\Windows\\System32\\NetSetupSvc.dll", + "InterfaceId": "a111f1c5-5923-47c0-9a68-d0bafb577901", + "InterfaceStructOffset": 214768, + "ProceduresCount": 12, + "Procedures": [ + "RpcNetSetupInitialize", + "RpcNetSetupValidateTransaction", + "RpcNetSetupRollback", + "RpcNetSetupCommit", + "RpcNetSetupClose", + "RpcNetSetupCreateObject", + "RpcNetSetupDeleteObject", + "RpcNetSetupGetObjectPropertyKeys", + "RpcNetSetupGetObjectProperties", + "RpcNetSetupSetObjectProperties", + "RpcNetSetupGetObjects", + "RpcNetSetupSynchronizeDevices" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707580939392, + "Service": "NetSetupSvc", + "IsServiceRunning": false + }, + "c27f3c08-92ba-478c-b446-b419c4cef0e2": { + "Module": "dusmsvc.dll", + "ModulePath": "C:\\Windows\\System32\\dusmsvc.dll", + "InterfaceId": "c27f3c08-92ba-478c-b446-b419c4cef0e2", + "InterfaceStructOffset": 246560, + "ProceduresCount": 25, + "Procedures": [ + "DusmRpcEnumConnectionList", + "DusmRpcEnumProfileList", + "DusmRpcQueryConnectionProperties", + "DusmRpcQueryCost", + "DusmRpcQueryUserCost", + "DusmRpcQueryOperatorCost", + "DusmRpcSetUserCost", + "DusmRpcSetOperatorCost", + "DusmRpcQueryDataPlan", + "DusmRpcQueryUserDataPlan", + "DusmRpcQueryOperatorDataPlan", + "DusmRpcSetUserDataPlan", + "DusmRpcSetOperatorDataPlan", + "DusmRpcQuerySource", + "DusmRpcSetSource", + "DusmRpcQueryBackgroundRestriction", + "DusmRpcSetBackgroundRestriction", + "DusmRpcQueryGlobalDpuState", + "DusmRpcGetAttributedNetworkUsage", + "DusmRpcGetConnectionListNetworkUsage", + "DusmRpcGetNetworkUsage", + "DusmRpcGetProviderNetworkUsage", + "DusmRpcSetAttributionMapping", + "DusmRpcResetNetworkUsage", + "DusmRpcFlushCostCache" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708018354432, + "Service": "DusmSvc", + "IsServiceRunning": true + }, + "552d076a-cb29-4e44-8b6a-d15e59e2c0af": { + "Module": "iphlpsvc.dll", + "ModulePath": "C:\\Windows\\System32\\iphlpsvc.dll", + "InterfaceId": "552d076a-cb29-4e44-8b6a-d15e59e2c0af", + "InterfaceStructOffset": 483584, + "ProceduresCount": 4, + "Procedures": [ + "IpTransitionProtocolApplyConfigChanges", + "IpTransitionProtocolApplyConfigChangesEx", + "IpTransitionCreatev6Inv4Tunnel", + "IpTransitionDeletev6Inv4Tunnel" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707888009120, + "Service": "iphlpsvc", + "IsServiceRunning": true + }, + "4be96a0f-9f52-4729-a51d-c70610f118b0": { + "Module": "wbiosrvc.dll", + "ModulePath": "C:\\Windows\\System32\\wbiosrvc.dll", + "InterfaceId": "4be96a0f-9f52-4729-a51d-c70610f118b0", + "InterfaceStructOffset": 697248, + "ProceduresCount": 7, + "Procedures": [ + "WinBioCredMgrSrvSetCredential", + "WinBioCredMgrSrvRemoveCredential", + "WinBioCredMgrSrvRemoveAllCredentials", + "WinBioCredMgrSrvRemoveAllDomainCredentials", + "WinBioCredMgrSrvGetCredentialState", + "WinBioCredMgrSrvGetCredentialWithTicket", + "WinBioSrvGetServiceMonitorEvent" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707487436608, + "Service": "WbioSrvc", + "IsServiceRunning": false + }, + "e53d94ca-7464-4839-b044-09a2fb8b3ae5": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "e53d94ca-7464-4839-b044-09a2fb8b3ae5", + "InterfaceStructOffset": 566112, + "ProceduresCount": 17, + "Procedures": [ + "HamRpcSrvConnect", + "HamRpcSrvDisconnect", + "HamRpcSrvCreateActivity", + "HamRpcSrvCreateActivityForProcess", + "HamRpcSrvCreateAutoRestartActivity", + "HamRpcSrvStartActivityAsync", + "HamRpcSrvStopActivity", + "HamRpcSrvUpdateActivityProperties", + "HamRpcSrvTerminateActivityHost", + "HamRpcSrvSetExternalResourcePriority", + "HamRpcSrvResetExternalResourcePriority", + "HamRpcSrvCloseActivity", + "HamRpcSrvIsHostBeingDebugged", + "HamRpcSrvTerminateHostOnProcessExit", + "HamRpcSrvGetApplicationInterruptiveUIState", + "HamRpcSrvGetPackageInterruptiveUIState", + "HamRpcSrvGetInterruptiveUIStateForAumid" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708133772736, + "Service": null, + "IsServiceRunning": false + }, + "7f1343fe-50a9-4927-a778-0c5859517bac": { + "Module": "wkssvc.dll", + "ModulePath": "C:\\Windows\\System32\\wkssvc.dll", + "InterfaceId": "7f1343fe-50a9-4927-a778-0c5859517bac", + "InterfaceStructOffset": 194912, + "ProceduresCount": 4, + "Procedures": [ + "DfsDsGetDcName", + "DfsDsIsDomainController", + "DfsCredWrite", + "DfsCredDelete" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708036827040, + "Service": "LanmanWorkstation", + "IsServiceRunning": true + }, + "c9ac6db5-82b7-4e55-ae8a-e464ed7b4277": { + "Module": "sysntfy.dll", + "ModulePath": "C:\\Windows\\System32\\sysntfy.dll", + "InterfaceId": "c9ac6db5-82b7-4e55-ae8a-e464ed7b4277", + "InterfaceStructOffset": 17248, + "ProceduresCount": 15, + "Procedures": [ + "s_OnInitialConnection", + "s_OnCreateSession", + "s_OnStartScreenSaverAsDefaultUser", + "s_OnStopScreenSaverAsDefaultUser", + "s_OnLogon", + "s_OnLock", + "s_OnUnlock", + "s_OnStartScreenSaverAsUser", + "s_OnStopScreenSaverAsUser", + "s_OnDisconnect", + "s_OnReconnect", + "s_OnLogoff", + "s_OnTerminateSession", + "s_OnStartShell", + "s_OnEndShell" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708127709872, + "Service": null, + "IsServiceRunning": false + }, + "46f91c6b-1f95-4bff-8490-eb648ca0a9b9": { + "Module": "webplatstorageserver.dll", + "ModulePath": "C:\\Windows\\System32\\webplatstorageserver.dll", + "InterfaceId": "46f91c6b-1f95-4bff-8490-eb648ca0a9b9", + "InterfaceStructOffset": 940384, + "ProceduresCount": 28, + "Procedures": [ + "s_ServiceWorkerSession_Open", + "s_ServiceWorkerSession_Close", + "s_ServiceWorkerSession_EnumerateAllSessions", + "s_ServiceWorkerSession_CreateNewRegistration", + "s_ServiceWorkerSession_GetRegistrationWithScopeUrl", + "s_ServiceWorkerSession_GetRegistrationWithUniqueId", + "s_ServiceWorkerSession_FindActiveMatchingRegistration", + "s_ServiceWorkerSession_FindAllRegistrationsForOrigin", + "s_ServiceWorkerSession_FindAllRegistrationsWithPendingTaskTypes", + "s_ServiceWorkerRegistration_Close", + "s_ServiceWorkerRegistration_SetInstallingWorker", + "s_ServiceWorkerRegistration_UpdateState", + "s_ServiceWorkerRegistration_Unregister", + "s_ServiceWorkerRegistration_ClearWorkerUninstallingFlag", + "s_ServiceWorkerRegistration_Delete", + "s_ServiceWorkerRegistration_SetLastUpdateCheckTime", + "s_ServiceWorkerRegistration_SetHasRequestedUpdate", + "s_ServiceWorkerRegistration_SetUpdateViaCache", + "s_ServiceWorkerRegistration_HasPushSubscriptionPolicyViolation", + "s_ServiceWorkerRegistration_GetPolicyViolations", + "s_ServiceWorkerRegistration_IncrementPolicyViolations", + "s_ServiceWorkerRegistration_ResetPolicyViolations", + "s_ServiceWorkerRegistration_SetIsNavigationPreloadEnabled", + "s_ServiceWorkerRegistration_SetNavigationPreloadHeader", + "s_ServiceWorkerRegistration_GetNavigationPreloadState", + "s_ServiceWorkerRegistration_GetPushSubscription", + "s_ServiceWorkerRegistration_SetPushSubscription", + "s_ServiceWorkerRegistration_DeletePushSubscription" + ], + "ProcStackSize": 32, + "DispatchFunction": 140706992781888, + "Service": null, + "IsServiceRunning": false + }, + "44e10347-37a0-494c-871c-fb90f7145742": { + "Module": "AppVEntSubsystemController.dll", + "ModulePath": "C:\\Windows\\System32\\AppVEntSubsystemController.dll", + "InterfaceId": "44e10347-37a0-494c-871c-fb90f7145742", + "InterfaceStructOffset": 901104, + "ProceduresCount": 10, + "Procedures": [ + "s_vcom_server_GetVComPolicies", + "s_vcom_server_RegisterServer", + "s_vcom_server_ReleaseServer", + "s_vcom_server_RequestServerResource", + "s_vcom_server_AcceptServerResource", + "s_vcom_server_ReleaseServerResource", + "s_vcom_server_WaitForClsidRegistration", + "s_vcom_server_StartComVirtualService", + "s_vcom_server_ComVirtualService", + "s_vcom_server_MakeLowIntegrityCOMMap" + ], + "ProcStackSize": 40, + "DispatchFunction": 140706797823920, + "Service": null, + "IsServiceRunning": false + }, + "be7f785e-0e3a-4ab7-91de-7e46e443be29": { + "Module": "StorSvc.dll", + "ModulePath": "C:\\Windows\\System32\\StorSvc.dll", + "InterfaceId": "be7f785e-0e3a-4ab7-91de-7e46e443be29", + "InterfaceStructOffset": 654768, + "ProceduresCount": 23, + "Procedures": [ + "SvcMountVolume", + "SvcDismountVolume", + "SvcFormatVolume", + "SvcGetStorageInstanceCount", + "SvcGetStorageDeviceInfo", + "CleanupItem", + "SvcRebootToFlashingMode", + "SvcRebootToUosFlashing", + "SvcFinalizeVolume", + "SvcGetStorageSettings", + "SvcResetStoragePolicySettings", + "SvcSetStorageSettings", + "SvcTriggerStorageCleanup", + "SvcTriggerLowStorageNotification", + "SvcMoveFileInheritSecurity", + "SvcScanVolume", + "SvcProcessStorageCardChange", + "SvcProvisionForAppInstall", + "SvcGetStorageInstanceCountForMaps", + "SvcGetStoragePolicySettings", + "SvcSetStoragePolicySettings", + "SvcTriggerStoragePolicies", + "SvcPredictStorageHealth" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707759709328, + "Service": "StorSvc", + "IsServiceRunning": true + }, + "45527ae0-2a7d-4cec-b214-739f4159c392": { + "Module": "LsaIso.exe", + "ModulePath": "C:\\Windows\\System32\\LsaIso.exe", + "InterfaceId": "45527ae0-2a7d-4cec-b214-739f4159c392", + "InterfaceStructOffset": 201376, + "ProceduresCount": 19, + "Procedures": [ + "NtlmIumGetContext", + "NtlmIumProtectCredential", + "NtlmIumLm20GetNtlm3ChallengeResponse", + "NtlmIumCalculateNtResponse", + "NtlmIumCalculateUserSessionKeyNt", + "NtlmIumPasswordValidateInteractive", + "NtlmIumPasswordValidateNetwork", + "NtlmIumIsGMSACred", + "NtlmIumMakeSecretPasswordNT5", + "NtlmIumCompareCredentials", + "NtlmIumDecryptDpapiMasterKey", + "NtlmIumGenerateRootSecret", + "NtlmIumGetCredentialKey", + "NtlmIumUpdateSharedConfiguration", + "NtlmIumMakeOwfsFromIumSupplementalCredential", + "NtlmIumMakeOwfsFromIumEncryptedPassword", + "NtlmIumConvertCredManPasswordToSupplementalCredential", + "NtlmIumProtectSspCredentialPassword", + "NtlmIumComparePasswordToProtectedPassword" + ], + "ProcStackSize": 40, + "DispatchFunction": 140697529061744, + "Service": null, + "IsServiceRunning": false + }, + "c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1": { + "Module": "adhsvc.dll", + "ModulePath": "C:\\Windows\\System32\\adhsvc.dll", + "InterfaceId": "c49a5a70-8a7f-4e70-ba16-1e8f1f193ef1", + "InterfaceStructOffset": 65776, + "ProceduresCount": 7, + "Procedures": [ + "Rpc_AdhEngineOpen", + "Rpc_AdhEngineClose", + "Rpc_AdhStatusEventSubscribe", + "Rpc_AdhStatusEventSubscriptionGetLastEvent", + "Rpc_AdhStatusEventUnsubscribe", + "Rpc_AdhGetConfig", + "Rpc_AdhGetEvidenceCollectorResult" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707878979392, + "Service": null, + "IsServiceRunning": false + }, + "3dde7c30-165d-11d1-ab8f-00805f14db40": { + "Module": "dpapisrv.dll", + "ModulePath": "C:\\Windows\\System32\\dpapisrv.dll", + "InterfaceId": "3dde7c30-165d-11d1-ab8f-00805f14db40", + "InterfaceStructOffset": 189440, + "ProceduresCount": 1, + "Procedures": [ + "s_BackuprKey" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708143064640, + "Service": null, + "IsServiceRunning": false + }, + "76c217bc-c8b4-4201-a745-373ad9032b1a": { + "Module": "ResourcePolicyServer.dll", + "ModulePath": "C:\\Windows\\System32\\ResourcePolicyServer.dll", + "InterfaceId": "76c217bc-c8b4-4201-a745-373ad9032b1a", + "InterfaceStructOffset": 106320, + "ProceduresCount": 3, + "Procedures": [ + "Srv_QueryApplicationEnergyUsage", + "Srv_GetDeviceSpecificConversionFactor", + "Srv_ResetTotalEnergyUsage" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708127422560, + "Service": null, + "IsServiceRunning": false + }, + "4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9": { + "Module": "psmsrv.dll", + "ModulePath": "C:\\Windows\\System32\\psmsrv.dll", + "InterfaceId": "4bec6bb8-b5c2-4b6f-b2c1-5da5cf92d0d9", + "InterfaceStructOffset": 168288, + "ProceduresCount": 4, + "Procedures": [ + "PsmSrvActivateApplication", + "PsmSrvCloseActivationChannel", + "PsmSrvOpenActivationChannel", + "PsmSrvRegisterProcess" + ], + "ProcStackSize": 80, + "DispatchFunction": 140708134117536, + "Service": "BrokerInfrastructure", + "IsServiceRunning": true + }, + "95095ec8-32ea-4eb0-a3e2-041f97b36168": { + "Module": "diagtrack.dll", + "ModulePath": "C:\\Windows\\System32\\diagtrack.dll", + "InterfaceId": "95095ec8-32ea-4eb0-a3e2-041f97b36168", + "InterfaceStructOffset": 2709664, + "ProceduresCount": 1, + "Procedures": [ + "UtcTelemetryOptInApi_SetTelemetryOptIn" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707991503344, + "Service": "DiagTrack", + "IsServiceRunning": true + }, + "f47433c3-3e9d-4157-aad4-83aa1f5c2d4c": { + "Module": "MPSSVC.dll", + "ModulePath": "C:\\Windows\\System32\\MPSSVC.dll", + "InterfaceId": "f47433c3-3e9d-4157-aad4-83aa1f5c2d4c", + "InterfaceStructOffset": 710704, + "ProceduresCount": 10, + "Procedures": [ + "RPC_NetworkIsolationDiagnoseConnectFailure", + "RPC_NetworkIsolationGetEnterpriseIdAsync", + "RPC_NetworkIsolationCreateContainer", + "RPC_NetworkIsolationDeleteContainer", + "RPC_NetworkIsolationGetAppContainerConfig", + "RPC_NetworkIsolationSetAppContainerConfig", + "RPC_NetworkIsolationCreateAppContainer", + "RPC_NetworkIsolationDeleteAppContainer", + "RPC_NetworkIsolationCreateAppContainerLoopbackRules", + "RPC_NetworkIsolationDeleteAppContainerLoopbackRules" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708003537664, + "Service": "mpssvc", + "IsServiceRunning": true + }, + "12345678-1234-abcd-ef00-0123456789ab": { + "Module": "IPSECSVC.DLL", + "ModulePath": "C:\\Windows\\System32\\IPSECSVC.DLL", + "InterfaceId": "12345678-1234-abcd-ef00-0123456789ab", + "InterfaceStructOffset": 372960, + "ProceduresCount": 71, + "Procedures": [ + "RpcAddTransportFilter", + "RpcDeleteTransportFilter", + "RpcEnumTransportFilters", + "RpcSetTransportFilter", + "RpcGetTransportFilter", + "RpcAddQMPolicy", + "RpcDeleteQMPolicy", + "RpcEnumQMPolicies", + "RpcSetQMPolicy", + "RpcGetQMPolicy", + "RpcAddMMPolicy", + "RpcDeleteMMPolicy", + "RpcEnumMMPolicies", + "RpcSetMMPolicy", + "RpcGetMMPolicy", + "RpcAddMMFilter", + "RpcDeleteMMFilter", + "RpcEnumMMFilters", + "RpcSetMMFilter", + "RpcGetMMFilter", + "RpcMatchMMFilter", + "RpcMatchTransportFilter", + "RpcGetQMPolicyByID", + "RpcGetMMPolicyByID", + "RpcAddMMAuthMethods", + "RpcDeleteMMAuthMethods", + "RpcEnumMMAuthMethods", + "RpcSetMMAuthMethods", + "RpcGetMMAuthMethods", + "RpcAddSAs", + "RpcAddSAs", + "RpcAddSAs", + "RpcEnumMMSAs", + "RpcDeleteMMSAs", + "RpcDeleteQMSAs", + "RpcQueryIKEStatistics", + "RpcAddSAs", + "RpcAddSAs", + "RpcAddSAs", + "RpcQueryIPSecStatistics", + "RpcEnumQMSAs", + "RpcAddTunnelFilter", + "RpcDeleteTunnelFilter", + "RpcEnumTunnelFilters", + "RpcSetTunnelFilter", + "RpcGetTunnelFilter", + "RpcMatchTunnelFilter", + "RpcOpenMMFilterHandle", + "RpcCloseMMFilterHandle", + "RpcOpenTransportFilterHandle", + "RpcCloseTransportFilterHandle", + "RpcOpenTunnelFilterHandle", + "RpcCloseTunnelFilterHandle", + "RpcEnumIpsecInterfaces", + "RpcAddSAs", + "RpcSetConfigurationVariables", + "RpcGetConfigurationVariables", + "RpcQuerySpdPolicyState", + "RpcAddMMFilterEx", + "RpcEnumMMFiltersEx", + "RpcSetMMFilterEx", + "RpcGetMMFilterEx", + "RpcMatchMMFilterEx", + "RpcOpenMMFilterHandleEx", + "RpcAddTransportFilterEx", + "RpcEnumTransportFiltersEx", + "RpcSetTransportFilterEx", + "RpcGetTransportFilterEx", + "RpcMatchTransportFilterEx", + "RpcOpenTransportFilterHandleEx", + "RpcQueryRemoteFWRunning" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707580797552, + "Service": "PolicyAgent", + "IsServiceRunning": false + }, + "cba4c918-e55a-46ee-aa62-cade158e9165": { + "Module": "audiosrv.dll", + "ModulePath": "C:\\Windows\\System32\\audiosrv.dll", + "InterfaceId": "cba4c918-e55a-46ee-aa62-cade158e9165", + "InterfaceStructOffset": 1381120, + "ProceduresCount": 1, + "Procedures": [ + "s_adGetDeviceGraphWnfStateName" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708027005360, + "Service": "Audiosrv", + "IsServiceRunning": true + }, + "0b0a6584-9e0f-11cf-a3cf-00805f68cb1b": { + "Module": "RpcEpMap.dll", + "ModulePath": "C:\\Windows\\System32\\RpcEpMap.dll", + "InterfaceId": "0b0a6584-9e0f-11cf-a3cf-00805f68cb1b", + "InterfaceStructOffset": 45152, + "ProceduresCount": 6, + "Procedures": [ + "OpenEndpointMapper", + "AllocateReservedIPPort", + "ept_insert_ex", + "ept_delete_ex", + "SetRestrictRemoteClients", + "ResetWithNoAuthException" + ], + "ProcStackSize": 8, + "DispatchFunction": 140708134471696, + "Service": "RpcEptMapper", + "IsServiceRunning": true + }, + "da5a86c5-12c2-4943-ab30-7f74a813d853": { + "Module": "regsvc.dll", + "ModulePath": "C:\\Windows\\System32\\regsvc.dll", + "InterfaceId": "da5a86c5-12c2-4943-ab30-7f74a813d853", + "InterfaceStructOffset": 126368, + "ProceduresCount": 8, + "Procedures": [ + "PerflibV2EnumerateCounterSet", + "PerflibV2QueryCounterSetRegistrationInfo", + "PerflibV2EnumerateCounterSetInstances", + "PerflibV2OpenQueryHandle", + "PerflibV2CloseQueryHandle", + "PerflibV2QueryCounterInfo", + "PerflibV2QueryCounterData", + "PerflibV2ValidateCounters" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707581089648, + "Service": "RemoteRegistry", + "IsServiceRunning": false + }, + "66055171-882c-4625-8fd7-cc7c30e2b226": { + "Module": "AppVEntSubsystemController.dll", + "ModulePath": "C:\\Windows\\System32\\AppVEntSubsystemController.dll", + "InterfaceId": "66055171-882c-4625-8fd7-cc7c30e2b226", + "InterfaceStructOffset": 901872, + "ProceduresCount": 1, + "Procedures": [ + "vshell_server_get_vshell_process_data" + ], + "ProcStackSize": 64, + "DispatchFunction": 140706798058224, + "Service": null, + "IsServiceRunning": false + }, + "dd490425-5325-4565-b774-7e27d6c09c24": { + "Module": "BFE.DLL", + "ModulePath": "C:\\Windows\\System32\\BFE.DLL", + "InterfaceId": "dd490425-5325-4565-b774-7e27d6c09c24", + "InterfaceStructOffset": 473856, + "ProceduresCount": 195, + "Procedures": [ + "BfeRpcGetNextNotificationBatch", + "BfeRpcNotifyComplete", + "BfeRpcEngineOpen", + "BfeRpcEngineClose", + "BfeRpcEngineGetOption", + "BfeRpcEngineSetOption", + "BfeRpcEngineGetSecurityInfo", + "BfeRpcEngineSetSecurityInfo", + "BfeRpcSessionCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcAleEndpointDestroyEnumHandle", + "BfeRpcTransactionBegin", + "BfeRpcTransactionCommit", + "BfeRpcTransactionAbort", + "BfeRpcProviderAdd", + "BfeRpcProviderDeleteByKey", + "BfeRpcProviderGetByKey", + "BfeRpcProviderCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcAleEndpointDestroyEnumHandle", + "BfeRpcProviderGetSecurityInfoByKey", + "BfeRpcProviderSetSecurityInfoByKey", + "BfeRpcProviderSubscribeChanges", + "BfeRpcProviderUnsubscribeChanges", + "BfeRpcProviderSubscriptionsGet", + "BfeRpcProviderContextAdd", + "BfeRpcProviderContextDeleteById", + "BfeRpcProviderContextDeleteByKey", + "BfeRpcProviderContextGetById", + "BfeRpcProviderContextGetByKey", + "BfeRpcProviderContextCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcAleEndpointDestroyEnumHandle", + "BfeRpcProviderContextGetSecurityInfoByKey", + "BfeRpcProviderContextSetSecurityInfoByKey", + "BfeRpcProviderContextSubscribeChanges", + "BfeRpcProviderContextUnsubscribeChanges", + "BfeRpcProviderContextSubscriptionsGet", + "BfeRpcSubLayerAdd", + "BfeRpcSubLayerDeleteByKey", + "BfeRpcSubLayerGetByKey", + "BfeRpcSubLayerCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcAleEndpointDestroyEnumHandle", + "BfeRpcSubLayerGetSecurityInfoByKey", + "BfeRpcSubLayerSetSecurityInfoByKey", + "BfeRpcSubLayerSubscribeChanges", + "BfeRpcSubLayerUnsubscribeChanges", + "BfeRpcSubLayerSubscriptionsGet", + "BfeRpcLayerGetById", + "BfeRpcLayerGetByKey", + "BfeRpcLayerCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcAleEndpointDestroyEnumHandle", + "BfeRpcLayerGetSecurityInfoByKey", + "BfeRpcLayerSetSecurityInfoByKey", + "BfeRpcCalloutAdd", + "BfeRpcCalloutDeleteById", + "BfeRpcCalloutDeleteByKey", + "BfeRpcCalloutGetById", + "BfeRpcCalloutGetByKey", + "BfeRpcCalloutCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcAleEndpointDestroyEnumHandle", + "BfeRpcCalloutGetSecurityInfoByKey", + "BfeRpcCalloutSetSecurityInfoByKey", + "BfeRpcCalloutSubscribeChanges", + "BfeRpcCalloutUnsubscribeChanges", + "BfeRpcCalloutSubscriptionsGet", + "BfeRpcFilterAdd", + "BfeRpcFilterDeleteById", + "BfeRpcFilterDeleteByKey", + "BfeRpcFilterGetById", + "BfeRpcFilterGetByKey", + "BfeRpcFilterCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcAleEndpointDestroyEnumHandle", + "BfeRpcFilterGetSecurityInfoByKey", + "BfeRpcFilterSetSecurityInfoByKey", + "BfeRpcFilterSubscribeChanges", + "BfeRpcFilterUnsubscribeChanges", + "BfeRpcFilterSubscriptionsGet", + "BfeRpcBfeIPsecOffloadDone", + "BfeRpcBfeIPsecDosFWUsed", + "BfeRpcBfeIPsecGetStatistics", + "BfeRpcBfeIPsecSaContextCreate", + "BfeRpcBfeIPsecSaContextDeleteById", + "BfeRpcBfeIPsecSaContextGetById", + "BfeRpcBfeIPsecSaContextGetOrSetSpi", + "BfeRpcBfeIPsecSaContextAddInbound", + "BfeRpcBfeIPsecSaContextAddOutbound", + "BfeRpcBfeIPsecSaContextUpdate", + "BfeRpcBfeIPsecSaContextExpire", + "BfeRpcBfeIPsecSaContextCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcAleEndpointDestroyEnumHandle", + "BfeRpcBfeIPsecSaContextSubscribe", + "BfeRpcBfeIPsecSaContextUnsubscribe", + "BfeRpcBfeIPsecSaContextSubscriptionsGet", + "BfeRpcBfeIPsecSaCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcAleEndpointDestroyEnumHandle", + "BfeRpcBfeIPsecSaDbGetSecurityInfo", + "BfeRpcBfeIPsecSaDbSetSecurityInfo", + "BfeRpcBfeIPsecDospGetStatistics", + "BfeRpcBfeIPsecDospStateCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcBfeIPsecDospStateDestroyEnumHandle", + "BfeRpcBfeIPsecDospGetSecurityInfo", + "BfeRpcBfeIPsecDospSetSecurityInfo", + "BfeRpcNetEventCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcAleEndpointDestroyEnumHandle", + "BfeRpcNetEventsGetSecurityInfo", + "BfeRpcNetEventsSetSecurityInfo", + "BfeRpcNetEventSubscribe", + "BfeRpcNetEventUnsubscribe", + "BfeRpcNetEventSubscriptionsGet", + "BfeRpcNetEventsLost", + "BfeRpcConnectionGetById", + "BfeRpcConnectionGetByIPsecInfo", + "BfeRpcConnectionGetByS2STunnelId", + "BfeRpcConnectionCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcAleEndpointDestroyEnumHandle", + "BfeRpcConnectionGetSecurityInfo", + "BfeRpcConnectionSetSecurityInfo", + "BfeRpcConnectionGetS2STunnelId", + "BfeRpcConnectionSubscribe", + "BfeRpcConnectionUnsubscribe", + "BfeRpcConnectionSubscriptionsGet", + "BfeRpcConnectionsLost", + "BfeRpcClassify", + "BfeRpcAddLayerReplica", + "BfeRpcDeleteLayerReplica", + "BfeRpcSecureSocketAdd", + "BfeRpcBfeIPsecTunnelDeleteByKey", + "BfeRpcBfeIPsecTunnelAdd", + "BfeRpcBfeIPsecTunnelAddConditions", + "BfeRpcBfeIPsecS2STunnelAddConditions", + "BfeRpcBfeIPsecS2STunnelRemoveConditions", + "BfeRpcBfeIPsecTunnelDeleteByKey", + "BfeRpcBfeIPsecS2STunnelAddInterfaceToCompartment", + "BfeRpcBfeIPsecS2STunnelGetInterfaceForCompartment", + "BfeRpcBfeIPsecS2STunnelRemoveInterfaceFromCompartment", + "BfeRpcBfeIPsecSaInitiateAsync", + "BfeRpcOpenToken", + "BfeRpcCloseToken", + "BfeRpcAleExplicitCredentialsQuery", + "BfeRpcAleEndpointGetById", + "BfeRpcAleEndpointCreateEnumHandle", + "BfeRpcAleEndpointEnum", + "BfeRpcAleEndpointDestroyEnumHandle", + "BfeRpcAleEndpointGetSecurityInfo", + "BfeRpcAleEndpointSetSecurityInfo", + "BfeRpcAleGetPortStatus", + "BfeRpcIsUserAuthConfigured", + "BfeRpcKeyModuleAdd", + "BfeRpcKeyModuleDeleteByKey", + "BfeRpcKeyModuleUpdateAcquire", + "BfeRpcKeyDictatorCheck", + "BfeRpcGetKeyFromDictator", + "BfeRpcNotifyKey", + "BfeRpcKeyManagerAdd", + "BfeRpcKeyManagerDeleteByKey", + "BfeRpcKeyManagersGet", + "BfeRpcKeyManagerGetSecurityInfoByKey", + "BfeRpcKeyManagerSetSecurityInfoByKey", + "BfeRpcvSwitchEventFire", + "BfeRpcvSwitchEventsGetSecurityInfo", + "BfeRpcvSwitchEventsSetSecurityInfo", + "BfeRpcvSwitchEventSubscribe", + "BfeRpcvSwitchEventUnsubscribe", + "BfeRpcvSwitchEventSubscriptionsGet", + "BfeRpcBfeIPsecDriverInitiateAcquire", + "BfeRpcBfeIPsecDriverExpire", + "BfeRpcBfeIPsecDriverSaOffloaded", + "BfeRpcBfeIPsecDriverProcessClearTextResponse", + "BfeRpcBfeProcessNameResolutionEvent", + "BfeRpcVpnTriggerEventFire", + "BfeRpcVpnTriggerEventSubscribe", + "BfeRpcVpnTriggerEventUnsubscribe", + "BfeRpcVpnTriggerAddAppSids", + "BfeRpcVpnTriggerRemoveAppSids", + "BfeRpcVpnTriggerAddFilePaths", + "BfeRpcVpnTriggerRemoveFilePaths", + "BfeRpcVpnTriggerAddSecurityDescriptor", + "BfeRpcVpnTriggerRemoveSecurityDescriptor", + "BfeRpcVpnTriggerSetStateDisconnected", + "BfeRpcVpnTriggerInitializeNrptTriggering", + "BfeRpcVpnTriggerUninitializeNrptTriggering", + "BfeRpcVpnTriggerResetNrptTriggering", + "BfeRpcVpnTriggerConfigureParameters", + "BfeRpcBitmapIndexGet", + "BfeRpcBitmapIndexFree" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708010958864, + "Service": "BFE", + "IsServiceRunning": true + }, + "43890c94-bfd7-4655-ad6a-b4a68397cdcb": { + "Module": "PimIndexMaintenance.dll", + "ModulePath": "C:\\Windows\\System32\\PimIndexMaintenance.dll", + "InterfaceId": "43890c94-bfd7-4655-ad6a-b4a68397cdcb", + "InterfaceStructOffset": 146912, + "ProceduresCount": 14, + "Procedures": [ + "PimIMService_UpdateStores", + "PimIMService_UpdateItems", + "PimIMService_RebuildAggregateCache", + "PimIMService_Suspend", + "PimIMService_Resume", + "PimIMService_CacheAggregateCacheFileMapping", + "PimIMService_LoadAggregateCache", + "PimIMService_CreateIndexedFilter", + "PimIMService_SetStaticFilter", + "PimIMService_GetIndexedProperties", + "PimIMService_FindNextServerMatch", + "PimIMService_SetFilter", + "PimIMService_Reset", + "PimIMService_CloseIndexedFilter" + ], + "ProcStackSize": 8, + "DispatchFunction": 140706806864608, + "Service": "PimIndexMaintenanceSvc", + "IsServiceRunning": false + }, + "4f32adc8-6052-4a04-8701-293ccf2096f0": { + "Module": "sspicli.dll", + "ModulePath": "C:\\Windows\\System32\\sspicli.dll", + "InterfaceId": "4f32adc8-6052-4a04-8701-293ccf2096f0", + "InterfaceStructOffset": 123584, + "ProceduresCount": 1, + "Procedures": [ + "SspiClientCallback" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708155972640, + "Service": null, + "IsServiceRunning": false + }, + "0b6edbfa-4a24-4fc6-8a23-942b1eca65d1": { + "Module": "spoolsv.exe", + "ModulePath": "C:\\Windows\\System32\\spoolsv.exe", + "InterfaceId": "0b6edbfa-4a24-4fc6-8a23-942b1eca65d1", + "InterfaceStructOffset": 476336, + "ProceduresCount": 7, + "Procedures": [ + "IRPCAsyncNotify_RegisterClient", + "IRPCAsyncNotify_UnregisterClient", + "IRPCAsyncNotify_GetServerRefferal", + "IRPCAsyncNotify_GetNewChannel", + "IRPCAsyncNotify_GetNotificationSendResponse", + "IRPCAsyncNotify_GetNotification", + "IRPCAsyncNotify_CloseChannel" + ], + "ProcStackSize": 48, + "DispatchFunction": 140698296497952, + "Service": "Spooler", + "IsServiceRunning": true + }, + "c59c3bf4-7812-43e9-bc34-d369f1cf8416": { + "Module": "webplatstorageserver.dll", + "ModulePath": "C:\\Windows\\System32\\webplatstorageserver.dll", + "InterfaceId": "c59c3bf4-7812-43e9-bc34-d369f1cf8416", + "InterfaceStructOffset": 943808, + "ProceduresCount": 4, + "Procedures": [ + "s_WebPlatStorageEvents_CreateChannel", + "s_WebPlatStorageEvents_WaitForEvents", + "s_WebPlatStorageEvents_CloseChannel", + "s_WebPlatStorageEvents_Shutdown" + ], + "ProcStackSize": 16, + "DispatchFunction": 140706992862736, + "Service": null, + "IsServiceRunning": false + }, + "58b2a725-c4e2-43f0-956f-d9c3b6fa0c8b": { + "Module": "moshost.dll", + "ModulePath": "C:\\Windows\\System32\\moshost.dll", + "InterfaceId": "58b2a725-c4e2-43f0-956f-d9c3b6fa0c8b", + "InterfaceStructOffset": 56432, + "ProceduresCount": 18, + "Procedures": [ + "MosHostCreateContext", + "MosHostCloseContext", + "MosHostGetDataDirectory", + "MosHostGetResourceDirectory", + "MosHostGetBrowseCacheSizeInMBytes", + "MosHostCacheStateGetSizes", + "MosHostCacheStateGetSizes", + "MosHostCacheStateGetSizes", + "MosHostCacheStateGetSizes", + "MosHostCacheStateGetSizes", + "MosHostCacheStateGetSizes", + "MosHostCacheStateGetSizes", + "MosHostCacheStateGetSizes", + "MosHostCacheStateGetSizes", + "MosHostCacheStateGetSizes", + "MosHostGetDataAsync", + "MosHostDeleteDataAsync", + "MosHostGetCopyrightString" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707880916016, + "Service": "MapsBroker", + "IsServiceRunning": false + }, + "0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e": { + "Module": "bisrv.dll", + "ModulePath": "C:\\Windows\\System32\\bisrv.dll", + "InterfaceId": "0d3e2735-cea0-4ecc-a9e2-41a2d81aed4e", + "InterfaceStructOffset": 551488, + "ProceduresCount": 24, + "Procedures": [ + "RBiPtSrvActivateDeferredWorkItem", + "RBiPtSrvActivateInBackground", + "RBiPtSrvActivateWorkItem", + "RBiPtSrvAssociateActivationProxy", + "RBiPtSrvAssociateApplicationEntryPoint", + "RBiPtSrvCancelWorkItem", + "RBiPtSrvCreateEvent", + "RBiPtSrvCreateEventForApp", + "RBiPtSrvCreateEventForPackageName", + "RBiPtSrvDeleteEvent", + "RBiPtSrvDisableWorkItem", + "RBiPtSrvDisassociateWorkItem", + "RBiPtSrvEnableWorkItem", + "RBiPtSrvEnumerateBrokeredEvents", + "RBiPtSrvEnumerateWorkItemsForPackageName", + "RBiPtSrvGetStatusStateNameFromBrokerEventId", + "RBiPtSrvQueryBrokeredEvent", + "RBiPtSrvQueryBrokerEventId", + "RBiPtSrvQuerySystemStateBroadcastChannels", + "RBiPtSrvQueryWorkItem", + "RBiPtSrvQueryWorkItemStatusStateName", + "RBiPtSrvSignalEvent", + "RBiPtSrvSignalMultipleEvents", + "RBiPtSrvSignalTriggerEvent" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708131130896, + "Service": null, + "IsServiceRunning": false + }, + "3d27921d-9a28-483f-a749-a48fde7d0c5f": { + "Module": "DeviceSetupManager.dll", + "ModulePath": "C:\\Windows\\System32\\DeviceSetupManager.dll", + "InterfaceId": "3d27921d-9a28-483f-a749-a48fde7d0c5f", + "InterfaceStructOffset": 168128, + "ProceduresCount": 9, + "Procedures": [ + "DsmRpcRefreshAllDevices", + "DsmRpcRefreshDevice", + "DsmRpcSetInstallBehavior", + "DsmRpcGetInstallBehavior", + "DsmRpcUnelevatedRemoveDevice", + "DsmRpcWaitServiceReady", + "DsmRpcSetCostedNetworkPolicy", + "DsmRpcRegisterDcaStateName", + "DsmRpcSetPairingUXInfo" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707581089360, + "Service": "DsmSvc", + "IsServiceRunning": false + }, + "8a7b5006-cc13-11db-9705-005056c00008": { + "Module": "appidsvc.dll", + "ModulePath": "C:\\Windows\\System32\\appidsvc.dll", + "InterfaceId": "8a7b5006-cc13-11db-9705-005056c00008", + "InterfaceStructOffset": 53904, + "ProceduresCount": 4, + "Procedures": [ + "AppIDRpcVerifyFile", + "AppIDRpcVerifyPackageMoniker", + "AppIDRpcOnCreateProcess", + "AppIDRpcOnCreateFile" + ], + "ProcStackSize": 72, + "DispatchFunction": 140707880933984, + "Service": "AppIDSvc", + "IsServiceRunning": false + }, + "8ec21e98-b5ce-4916-a3d6-449fa428a007": { + "Module": "modernexecserver.dll", + "ModulePath": "C:\\Windows\\System32\\modernexecserver.dll", + "InterfaceId": "8ec21e98-b5ce-4916-a3d6-449fa428a007", + "InterfaceStructOffset": 324304, + "ProceduresCount": 24, + "Procedures": [ + "FmMuxSrvRegisterCoreUIEndpoints", + "FmMuxSrvGenerateTaskInstanceId", + "FmMuxSrvLaunchTask", + "FmMuxSrvResumeTask", + "FmMuxSrvPauseTask", + "FmMuxSrvCancelTask", + "FmMuxSrvAbortTask", + "FmMuxSrvGetTaskPid", + "FmMuxSrvSetTaskDehydrationEligibility", + "FmMuxSrvSetTaskProperty", + "FmMuxSrvResolveApplicationUri", + "FmMuxSrvGetActivationPolicy", + "FmMuxSrvLogoffUser", + "FmMuxSrvShutdown", + "FmMuxSrvSetForegroundTaskInstanceId", + "FmMuxSrvGenerateActivationInstanceId", + "FmMuxSrvActivationPrerequisitePhase", + "FmMuxSrvIsCBETask", + "FmMuxSrvIsValidTaskPid", + "FmMuxSrvResumePrerequisitePhase", + "FmMuxSrvGetForegroundTaskInstanceId", + "FmMuxSrvActivationBypass", + "FmMuxSrvIsActivationDehydrated", + "FmMuxSrvRequestResourceSet" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707571598128, + "Service": null, + "IsServiceRunning": false + }, + "69c09ea0-4a09-101b-ae4b-08002b349a02": { + "Module": "combase.dll", + "ModulePath": "C:\\Windows\\System32\\combase.dll", + "InterfaceId": "69c09ea0-4a09-101b-ae4b-08002b349a02", + "InterfaceStructOffset": 2338480, + "ProceduresCount": 0, + "Procedures": [], + "ProcStackSize": 24, + "DispatchFunction": 140708189286624, + "Service": null, + "IsServiceRunning": false + }, + "338cd001-2244-31f1-aaaa-900038001003": { + "Module": "regsvc.dll", + "ModulePath": "C:\\Windows\\System32\\regsvc.dll", + "InterfaceId": "338cd001-2244-31f1-aaaa-900038001003", + "InterfaceStructOffset": 124320, + "ProceduresCount": 36, + "Procedures": [ + "OpenClassesRoot", + "OpenCurrentUser", + "OpenLocalMachine", + "OpenPerformanceData", + "OpenUsers", + "BaseRegCloseKey", + "BaseRegCreateKey", + "BaseRegDeleteKey", + "BaseRegDeleteValue", + "SafeBaseRegEnumKey", + "SafeBaseRegEnumValue", + "BaseRegFlushKey", + "SafeBaseRegGetKeySecurity", + "BaseRegLoadKey", + "BaseRegNotifyChangeKeyValue", + "BaseRegOpenKey", + "SafeBaseRegQueryInfoKey", + "BaseRegQueryValue", + "BaseRegReplaceKey", + "BaseRegRestoreKey", + "BaseRegSaveKey", + "BaseRegSetKeySecurity", + "BaseRegSetValue", + "BaseRegUnLoadKey", + "BaseAbortSystemShutdown", + "BaseAbortSystemShutdown", + "BaseRegGetVersion", + "OpenCurrentConfig", + "BaseAbortSystemShutdown", + "SafeBaseRegQueryMultipleValues", + "BaseAbortSystemShutdown", + "BaseRegSaveKeyEx", + "OpenPerformanceText", + "OpenPerformanceNlsText", + "SafeBaseRegQueryMultipleValues2", + "BaseRegDeleteKeyEx" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707581092976, + "Service": "RemoteRegistry", + "IsServiceRunning": false + }, + "a4b8d482-80ce-40d6-934d-b22a01a44fe7": { + "Module": "LicenseManagerSvc.dll", + "ModulePath": "C:\\Windows\\System32\\LicenseManagerSvc.dll", + "InterfaceId": "a4b8d482-80ce-40d6-934d-b22a01a44fe7", + "InterfaceStructOffset": 28672, + "ProceduresCount": 8, + "Procedures": [ + "BeginAcquireLicense", + "PrecacheLicenseForPackageResume", + "EnsureLicenseForPackageActivation", + "EnsureLicenseForOptionalPackageUsage", + "PackageSuspendedNotification", + "PackageRundownNotification", + "OptionalPackageRundownNotification", + "Reset" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707877972720, + "Service": "LicenseManager", + "IsServiceRunning": true + }, + "0ff1f646-13bb-400a-ab50-9a78f2b7a85a": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "0ff1f646-13bb-400a-ab50-9a78f2b7a85a", + "InterfaceStructOffset": 568704, + "ProceduresCount": 3, + "Procedures": [ + "HamRpcSrvFindOrCreateHostId", + "HamRpcSrvCreateSingleUseHostId", + "HamRpcSrvRetrieveDynamicIdForHostId" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708133284816, + "Service": null, + "IsServiceRunning": false + }, + "b12fd546-c875-4b41-97d8-950487662202": { + "Module": "SessEnv.dll", + "ModulePath": "C:\\Windows\\System32\\SessEnv.dll", + "InterfaceId": "b12fd546-c875-4b41-97d8-950487662202", + "InterfaceStructOffset": 334048, + "ProceduresCount": 9, + "Procedures": [ + "RpcCreateUserVhdTemplate", + "RpcGetCreateUserProfileVhd", + "RpcDestroyUserProfileVhd", + "RpcRepairUserProfileVhd", + "RpcReEncryptUserCredential", + "RpcDeleteFileFromVHD", + "RpcSetupVhdForRdv", + "RpcCopyRdvFolderFromVhdToHost", + "RpcQueryVhdOfflineInformation" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708025006864, + "Service": "SessionEnv", + "IsServiceRunning": true + }, + "0a533b58-0ed9-4085-b6e8-95795e147972": { + "Module": "Microsoft.Bluetooth.Service.dll", + "ModulePath": "C:\\Windows\\System32\\Microsoft.Bluetooth.Service.dll", + "InterfaceId": "0a533b58-0ed9-4085-b6e8-95795e147972", + "InterfaceStructOffset": 3123168, + "ProceduresCount": 20, + "Procedures": [ + "s_RpcBluetoothGattGetServicesCount", + "s_RpcBluetoothGattGetServices", + "s_RpcBluetoothGattGetIncludedServicesCount", + "s_RpcBluetoothGattGetIncludedServices", + "s_RpcBluetoothGattGetCharacteristicsCount", + "s_RpcBluetoothGattGetCharacteristics", + "s_RpcBluetoothGattGetDescriptorsCount", + "s_RpcBluetoothGattGetDescriptors", + "s_RpcBluetoothGattGetCharacteristicValueSize", + "s_RpcBluetoothGattGetCharacteristicValue", + "s_RpcBluetoothGattGetDescriptorValueSize", + "s_RpcBluetoothGattGetDescriptorValue", + "s_RpcBluetoothGattSetCharacteristicValue", + "s_RpcBluetoothGattSetDescriptorValue", + "s_RpcBluetoothGattBeginReliableWrite", + "s_RpcBluetoothGattEndReliableWrite", + "s_RpcBluetoothGattAbortReliableWrite", + "s_RpcBluetoothGattRegisterEvent", + "s_RpcBluetoothGattUnregisterEvent", + "s_RpcBluetoothGattGetEvents" + ], + "ProcStackSize": 72, + "DispatchFunction": 140707091139984, + "Service": null, + "IsServiceRunning": false + }, + "12b81e99-f207-4a4c-85d3-77b42f76fd14": { + "Module": "seclogon.dll", + "ModulePath": "C:\\Windows\\System32\\seclogon.dll", + "InterfaceId": "12b81e99-f207-4a4c-85d3-77b42f76fd14", + "InterfaceStructOffset": 20480, + "ProceduresCount": 1, + "Procedures": [ + "SeclCreateProcessWithLogonW" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708037791760, + "Service": "seclogon", + "IsServiceRunning": false + }, + "ae55c4c0-64ce-11dd-ad8b-0800200c9a66": { + "Module": "bdesvc.dll", + "ModulePath": "C:\\Windows\\System32\\bdesvc.dll", + "InterfaceId": "ae55c4c0-64ce-11dd-ad8b-0800200c9a66", + "InterfaceStructOffset": 405616, + "ProceduresCount": 13, + "Procedures": [ + "BdeSvcApipAddRecoveryPassword", + "BdeSvcApipConversionEncrypt", + "BdeSvcApipEventTrigger", + "BdeSvcApipChangeProtector", + "BdeSvcApipConversionEncryptEx", + "BdeSvcApipCheckADSchema", + "BdeSvcApipQueryCachedEASProtectionStatus", + "BdeSvcApipDoTurnOnDeviceEncryption", + "BdeSvcApipEnableSilentDeviceEncryption", + "BdeSvcApipEnableSilentBitLocker", + "BdeSvcApipIsEncryptableFDVPresent", + "BdeSvcApipRotateRecoveryPasswords", + "BdeSvcApipGetRotateRecoveryPasswordsStatus" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707580956464, + "Service": "BDESVC", + "IsServiceRunning": false + }, + "201ef99a-7fa0-444c-9399-19ba84f12a1a": { + "Module": "appinfo.dll", + "ModulePath": "C:\\Windows\\System32\\appinfo.dll", + "InterfaceId": "201ef99a-7fa0-444c-9399-19ba84f12a1a", + "InterfaceStructOffset": 106880, + "ProceduresCount": 7, + "Procedures": [ + "RAiLaunchAdminProcess", + "RAiProcessRunOnce", + "RAiLogonWithSmartCardCreds", + "RAiOverrideDesktopPromptPolicy", + "RAiDisableElevationForSession", + "RAiEnableElevationForSession", + "RAiForceElevationPromptForCOM" + ], + "ProcStackSize": 112, + "DispatchFunction": 140707486597008, + "Service": "Appinfo", + "IsServiceRunning": true + }, + "43d210c2-4dfb-44d0-ab40-31aab2e980f3": { + "Module": "ByteCodeGenerator.exe", + "ModulePath": "C:\\Windows\\System32\\ByteCodeGenerator.exe", + "InterfaceId": "43d210c2-4dfb-44d0-ab40-31aab2e980f3", + "InterfaceStructOffset": 46560, + "ProceduresCount": 2, + "Procedures": [ + "ShutdownRpcServer", + "GenerateByteCodeForPackage" + ], + "ProcStackSize": 88, + "DispatchFunction": 140696553727600, + "Service": null, + "IsServiceRunning": false + }, + "c0e9671e-33c6-4438-9464-56b2e1b1c7b4": { + "Module": "wbiosrvc.dll", + "ModulePath": "C:\\Windows\\System32\\wbiosrvc.dll", + "InterfaceId": "c0e9671e-33c6-4438-9464-56b2e1b1c7b4", + "InterfaceStructOffset": 686832, + "ProceduresCount": 43, + "Procedures": [ + "WinBioSrvOpenFrameworkSession", + "WinBioSrvCloseFrameworkSession", + "WinBioSrvEnumBiometricUnits", + "WinBioSrvEnumServiceProviders", + "WinBioSrvMonitorFrameworkChanges", + "WinBioSrvOpenBiometricSession", + "WinBioSrvCloseBiometricSession", + "WinBioSrvCancel", + "WinBioSrvVerify", + "WinBioSrvIdentify", + "WinBioSrvVerifyAndReleaseTicket", + "WinBioSrvIdentifyAndReleaseTicket", + "WinBioSrvLocateSensor", + "WinBioSrvEnrollAuthorize", + "WinBioSrvEnrollRevoke", + "WinBioSrvEnrollBegin", + "WinBioSrvEnrollSelect", + "WinBioSrvEnrollCapture", + "WinBioSrvEnrollCommit", + "WinBioSrvEnrollDiscard", + "WinBioSrvEnumEnrollments", + "WinBioSrvGetEvent", + "WinBioSrvGetPresenceData", + "WinBioSrvCaptureSample", + "WinBioSrvDeleteTemplate", + "WinBioSrvLockUnit", + "WinBioSrvUnlockUnit", + "WinBioSrvControlUnit", + "WinBioSrvControlUnitPrivileged", + "WinBioSrvGetProperty", + "WinBioSrvSetProperty", + "WinBioSrvAcquireFocus", + "WinBioSrvReleaseFocus", + "WinBioSrvLogonIdentifiedUser", + "BioSrvGetLogonUserIdentity", + "WinBioSrvProtectData", + "WinBioSrvUnprotectData", + "WinBioSrvDiscardTicket", + "WinBioSrvGetGestureMetadata", + "WinBioSrvNgcOpenAuthorizationSession", + "WinBioSrvNgcAuthorizeEnrollment", + "WinBioSrvNgcCloseAuthorizationSession", + "WinBioSrvNgcGetAuthorizationWithTicket" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707487243712, + "Service": "WbioSrvc", + "IsServiceRunning": false + }, + "7ea70bcf-48af-4f6a-8968-6a440754d5fa": { + "Module": "nsisvc.dll", + "ModulePath": "C:\\Windows\\System32\\nsisvc.dll", + "InterfaceId": "7ea70bcf-48af-4f6a-8968-6a440754d5fa", + "InterfaceStructOffset": 20480, + "ProceduresCount": 9, + "Procedures": [ + "RpcNsiGetParameter", + "RpcNsiGetAllParameters", + "RpcNsiEnumerateObjectsAllParameters", + "RpcNsiSetParameter", + "RpcNsiSetAllParameters", + "RpcNsiRegisterChangeNotification", + "RpcNsiDeregisterChangeNotification", + "RpcNsiRequestChangeNotification", + "RpcNsiParameterChange" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708082684992, + "Service": "nsi", + "IsServiceRunning": true + }, + "afc07e2e-311c-4435-808c-c483ffeec7c9": { + "Module": "lsasrv.dll", + "ModulePath": "C:\\Windows\\System32\\lsasrv.dll", + "InterfaceId": "afc07e2e-311c-4435-808c-c483ffeec7c9", + "InterfaceStructOffset": 1269952, + "ProceduresCount": 3, + "Procedures": [ + "LsarGetAvailableCAPIDs", + "LsarSetCAPs", + "LsarQueryCAPs" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708154023936, + "Service": null, + "IsServiceRunning": false + }, + "95406f0b-b239-4318-91bb-cea3a46ff0dc": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "95406f0b-b239-4318-91bb-cea3a46ff0dc", + "InterfaceStructOffset": 568896, + "ProceduresCount": 7, + "Procedures": [ + "HamRpcSrvConnectServicing", + "HamRpcSrvDisconnect", + "HamRpcSrvFullTrustOpenPackageHandle", + "HamRpcSrvDebugClosePackageHandle", + "HamRpcSrvServicingQueryActiveAppsInPackage", + "HamRpcSrvServicingEnableServicing", + "HamRpcSrvDebugTerminatePackage" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708133772720, + "Service": null, + "IsServiceRunning": false + }, + "e5b92378-0c65-442c-a66b-f9714d2d7b00": { + "Module": "Spectrum.exe", + "ModulePath": "C:\\Windows\\System32\\Spectrum.exe", + "InterfaceId": "e5b92378-0c65-442c-a66b-f9714d2d7b00", + "InterfaceStructOffset": 729008, + "ProceduresCount": 44, + "Procedures": [ + "S_System_Internal_Connect", + "S_System_Internal_Disconnect", + "S_System_Internal_DrainSensorData", + "S_System_Internal_SetSensorRefs", + "S_Internal_HeadTracker_GetAugmentedPoseForTime", + "S_Internal_HeadTracker_GenerateRenderingMetadataForPose", + "S_Internal_HeadTracker_GetHeTLayoutBuffer", + "S_Debug_GetAnchorStatistics", + "S_Debug_GetHeTMapAndLocationData", + "S_Debug_GetHeTDepthData", + "S_Debug_GetAppSpatialAnchors", + "S_Light_GetSensorData", + "S_Environment_GetCurrent", + "S_Environment_SetCurrent", + "S_Environment_GetAvailable", + "S_Environment_Delete", + "S_Environment_SetMetadata", + "S_Environment_IsMapLocked", + "S_Environment_LockCurrentMap", + "S_Environment_UnlockCurrentMap", + "S_Environment_SaveCurrentMap", + "S_Environment_LoadMap", + "S_Environment_DeleteMap", + "S_Environment_DeleteSpatialNeighborhoodForSpatialAnchors", + "S_Environment_DeleteSpatialNeighborhoodForAllSpatialAnchors", + "S_Stage_SetCurrent", + "S_Stage_SetCurrentNull", + "S_HaT_MiniMonitor_Flush", + "S_Speech_GetActivationState", + "S_InternalGestures_SendHome", + "S_ViewCalibration_CalibrateHeadSize", + "S_DisplayMetadata_GetClientsAndSharedBuffers", + "S_Internal_SpatialDevice_FindById", + "S_Internal_SpatialDevice_GetAllDevices", + "S_Internal_SpatialDevice_GetOrCreateGlobal", + "S_Internal_SpatialDevice_CreateAppLocal", + "S_Internal_SpatialDevice_ComputeSpatialGraphBinding", + "S_Internal_SpatialDevice_SetDesiredTrackingLevel", + "S_Internal_SpatialDevice_GetLastKnownTrackerMode", + "S_Internal_SpatialDevice_GetDynamicNodePoseQueueLayoutBuffer", + "S_Display_SetMonitors", + "S_HolographicDevicesError_ToggleSendingUpdates", + "S_HolographicDevicesError_GetStatus", + "S_Semantics_CastRay" + ], + "ProcStackSize": 56, + "DispatchFunction": 140701106677168, + "Service": "spectrum", + "IsServiceRunning": false + }, + "0fc77b1a-95d8-4a2e-a0c0-cff54237462b": { + "Module": "modernexecserver.dll", + "ModulePath": "C:\\Windows\\System32\\modernexecserver.dll", + "InterfaceId": "0fc77b1a-95d8-4a2e-a0c0-cff54237462b", + "InterfaceStructOffset": 324208, + "ProceduresCount": 9, + "Procedures": [ + "FmMuxSrvRegisterFGNotificationCoreUIEndpoint", + "FmMuxSrvUnRegisterFGNotificationCoreUIEndpoint", + "FmMuxSrvGetForegroundProductId", + "FmMuxSrvIsForegroundProductId", + "FmMuxSrvGetProductIdFromProcessId", + "FmMuxSrvGenerateWatsonReport", + "FmMuxSrvGetProcessProductId", + "FmMuxSrvDehydrateHost", + "FmMuxSrvIsCallingProcessForeground" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707571597600, + "Service": null, + "IsServiceRunning": false + }, + "266f33b4-c7c1-4bd1-8f52-ddb8f2214eb0": { + "Module": "wlansvc.dll", + "ModulePath": "C:\\Windows\\System32\\wlansvc.dll", + "InterfaceId": "266f33b4-c7c1-4bd1-8f52-ddb8f2214eb0", + "InterfaceStructOffset": 2051696, + "ProceduresCount": 39, + "Procedures": [ + "RpcLowPrivOpenHandle", + "RpcLowPrivCloseHandle", + "RpcLowPrivRegisterNotification", + "RpcLowPrivAsyncGetNotification", + "RpcLowPrivSetInterface", + "RpcLowPrivQueryInterface", + "RpcLowPrivEnumInterfaces", + "RpcWfdLowPrivIsWfdSupported", + "RpcWfdLowPrivOpenHandle", + "RpcWfdLowPrivCancelOpenSession", + "RpcWfdLowPrivCloseSession", + "RpcWfdLowPrivGetSessionEndpointPairs", + "RpcWfdLowPrivConfigureFirewallForSession", + "RpcWfdLowPrivOpenLegacySessionWithProfile", + "RpcWfdLowPrivCloseLegacySession", + "RpcWfdLowPrivQueryProperty", + "RpcWfdLowPrivSetProperty", + "RpcWfdLowPrivStartUsingGroup", + "RpcWfdLowPrivStopUsingGroup", + "RpcWlanLowPrivNotifyVsIeProvider", + "RpcWfdLowPrivOpenSessionByDafObjectId", + "RpcWfdLowPrivDeclineDeviceApiConnectionRequest", + "RpcWfdLowPrivStartDeviceApiConnectionRequestListener", + "RpcWfdLowPrivStopDeviceApiConnectionRequestListener", + "RpcWFDSvcLowPrivPublishService", + "RpcWFDSvcLowPrivUnpublishService", + "RpcWfdSvcLowPrivOpenSeekerSession", + "RpcWfdSvcLowPrivOpenAdvertiserSession", + "RpcWfdSvcLowPrivGetProvisioningInfo", + "RpcWfdSvcLowPrivConnectSession", + "RpcWfdSvcLowPrivCancelSession", + "RpcWfdSvcLowPrivAcceptSession", + "RpcWfdSvcLowPrivConfigureSession", + "RpcWfdSvcLowPrivCloseSession", + "RpcWfdSvcLowPrivGetSessionEndpointPairs", + "RpcWfdLowPrivRegisterVMgrCaller", + "RpcWfdLowPrivUnregisterVMgrCaller", + "RpcWlanVMgrQueryCurrentScenarios", + "RpcWfdLowPrivGetPendingGroupRequestDetails" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707602716720, + "Service": "WlanSvc", + "IsServiceRunning": true + }, + "8782d3b9-ebbd-4644-a3d8-e8725381919b": { + "Module": "psmsrv.dll", + "ModulePath": "C:\\Windows\\System32\\psmsrv.dll", + "InterfaceId": "8782d3b9-ebbd-4644-a3d8-e8725381919b", + "InterfaceStructOffset": 168480, + "ProceduresCount": 3, + "Procedures": [ + "PsmSrvRegisterQuiesceResumeApp", + "PsmSrvQuiesceCallbacksComplete", + "PsmSrvCloseActivationChannel" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708134134848, + "Service": "BrokerInfrastructure", + "IsServiceRunning": true + }, + "2e6035b2-e8f1-41a7-a044-656b439c4c34": { + "Module": "httpprxm.dll", + "ModulePath": "C:\\Windows\\System32\\httpprxm.dll", + "InterfaceId": "2e6035b2-e8f1-41a7-a044-656b439c4c34", + "InterfaceStructOffset": 69904, + "ProceduresCount": 6, + "Procedures": [ + "ProxyMgrProviderRegisterForEventNotification", + "ProxyMgrProviderUnregisterEventNotification", + "ProxyMgrProviderGetNotification", + "ProxyMgrGetProxyEventInformation", + "ProxyMgrSetProxyConfiguration", + "ProxyMgrSetProxyCredentials" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707879109728, + "Service": null, + "IsServiceRunning": false + }, + "83da4c30-ea3a-11cf-9cc1-08003601e506": { + "Module": "nfsclnt.exe", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-nfs-clientcore_31bf3856ad364e35_10.0.18362.1714_none_ba50c263a597cfbe\\nfsclnt.exe", + "InterfaceId": "83da4c30-ea3a-11cf-9cc1-08003601e506", + "InterfaceStructOffset": 80080, + "ProceduresCount": 10, + "Procedures": [ + "Ping", + "DaRpcAddConnectedDevice", + "DaRpcRemoveConnectedDevice", + "DaRpcFetchConnectedDevice", + "DaRpcFetchConnectionNameForConnectedDevice", + "DaRpcListConnectedDevice", + "DaRpcListHostsInLan", + "DaRpcIsLanName", + "DaRpcListConfiguredLans", + "DaRpcGetExportList" + ], + "ProcStackSize": 56, + "DispatchFunction": 140695726692960, + "Service": null, + "IsServiceRunning": false + }, + "4c9dbf19-d39e-4bb9-90ee-8f7179b20283": { + "Module": "diagtrack.dll", + "ModulePath": "C:\\Windows\\System32\\diagtrack.dll", + "InterfaceId": "4c9dbf19-d39e-4bb9-90ee-8f7179b20283", + "InterfaceStructOffset": 2709472, + "ProceduresCount": 37, + "Procedures": [ + "UtcApi_IsScenarioActive", + "UtcApi_EscalateScenario", + "UtcApi_EscalateScenarioAsync", + "UtcApi_IsEscalationRunning", + "UtcApi_DownloadLatestSettingsForNamespace", + "UtcApi_DownloadLatestSettingsForNamespaceAsync", + "UtcApi_GetActiveScenarioList", + "UtcApi_ForceUpload", + "UtcApi_ResetUsageMetrics", + "UtcApi_IsTraceRunning", + "UtcApi_GetActiveTraceRuntime", + "UtcApi_GetKnownTraceList", + "UtcApi_DownloadLatestSettings", + "UtcApi_ReloadSettings", + "UtcApi_UpdateTimerConfiguration", + "UtcApi_ClearTimerConfiguration", + "UtcApi_GetNextScheduledFireTime", + "UtcApi_GetTimerConfiguration", + "UtcApi_GetCustomTraceList", + "UtcApi_StartCustomTrace", + "UtcApi_SnapCustomTrace", + "UtcApi_StopCustomTrace", + "UtcApi_EscalateScenario2", + "UtcApi_EscalateScenarioAsync2", + "UtcApi_GetActiveTraceInfo", + "UtcApi_EnableWERLocalReports", + "UtcApi_RestoreWERLocalReportsSettings", + "UtcApi_QueryWERLocalReportsEnabled", + "UtcApi_IsEscalationRunningEx", + "UtcApi_QueryDiagnosticCollectionState", + "UtcApi_EscalateScenario3", + "UtcApi_GetIdsFromCategory", + "UtcApi_GetRunningTraces", + "UtcApi_GetContextProperty", + "UtcApi_GetRunningEscalationsForContext", + "UtcApi_EscalateScenarioAsync3", + "UtcApi_GetApiVersion" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707991494352, + "Service": "DiagTrack", + "IsServiceRunning": true + }, + "af1e812f-2d47-4c99-9b36-15984de66d89": { + "Module": "AppVEntSubsystemController.dll", + "ModulePath": "C:\\Windows\\System32\\AppVEntSubsystemController.dll", + "InterfaceId": "af1e812f-2d47-4c99-9b36-15984de66d89", + "InterfaceStructOffset": 901424, + "ProceduresCount": 2, + "Procedures": [ + "vfonts_server_GetListOfVirtualFonts", + "vfonts_server_StageFontFile" + ], + "ProcStackSize": 48, + "DispatchFunction": 140706797869280, + "Service": null, + "IsServiceRunning": false + }, + "b18fbab6-56f8-4702-84e0-41053293a869": { + "Module": "usermgr.dll", + "ModulePath": "C:\\Windows\\System32\\usermgr.dll", + "InterfaceId": "b18fbab6-56f8-4702-84e0-41053293a869", + "InterfaceStructOffset": 695952, + "ProceduresCount": 40, + "Procedures": [ + "svcQueryUserToken", + "svcGetConstrainedUserToken", + "svcIsAllowedToActivateAsUser", + "svcQueryDefaultAccountToken", + "svcQuerySessionVirtualAccountToken", + "svcLaunchShell", + "svcLaunchShellInfrastructureHost", + "svcSetShellInformation", + "svcInformUserLogon", + "svcInformUserLogoff", + "svcQueryUserContext", + "svcUMLogonUser", + "svcQuerySessionUserToken", + "svcGetConstrainedUserTokenFromAppcontainer", + "svcEnumerateSessionUsers", + "svcQueryUserTokenFromName", + "svcQueryUserContextFromName", + "svcQueryUserTokenFromSid", + "svcQueryUserContextFromSid", + "svcOpenProcessHandleForAccess", + "svcOpenProcessTokenForQuery", + "svcUMSetCachedCredentials", + "svcUMGetCachedCredentials", + "svcInformFlags", + "svcChangeSessionUserToken", + "svcConnectLocalUser", + "svcDisconnectLocalUser", + "svcGetImpersonationTokenForContext", + "svcGetDefaultSignInAccount", + "svcClearDefaultSignInAccount", + "svcGetSessionActiveShellUserToken", + "svcChangeSessionActiveShellUser", + "svcIsCandidateUser", + "svcIsEphemeralCandidateUser", + "svcGetCandidateAccountCredz", + "svcConnectCandidateUser", + "svcGetNonCandidateUserSessionIds", + "svcGetCandidateUserSessionIds", + "svcRefreshCandidateUser", + "svcCleanupDisardedCandidateAccounts" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708013770016, + "Service": "UserManager", + "IsServiceRunning": true + }, + "41baa680-50ce-4967-a8fa-0596343a7ccf": { + "Module": "lsasrv.dll", + "ModulePath": "C:\\Windows\\System32\\lsasrv.dll", + "InterfaceId": "41baa680-50ce-4967-a8fa-0596343a7ccf", + "InterfaceStructOffset": 1327728, + "ProceduresCount": 2, + "Procedures": [ + "LsarSetMachineCertificate", + "LsarDeleteMachineCertificate" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708153899648, + "Service": null, + "IsServiceRunning": false + }, + "04eeb297-cbf4-466b-8a2a-bfd6a2f10bba": { + "Module": "efssvc.dll", + "ModulePath": "C:\\Windows\\System32\\efssvc.dll", + "InterfaceId": "04eeb297-cbf4-466b-8a2a-bfd6a2f10bba", + "InterfaceStructOffset": 59200, + "ProceduresCount": 7, + "Procedures": [ + "EfsKRpcEstablishRpcConnection", + "EfsKRpcDecryptFek", + "EfsKRpcGenerateKey", + "EfsKRpcGenerateDirEfs", + "EfsKRpcNotifyEnterpriseFileWrite", + "EfsKRpcNotifyEnterpriseFileCleanup", + "EdpKRpcWriteNetworkAppLearningEvt" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707880079504, + "Service": "EFS", + "IsServiceRunning": false + }, + "945693c4-3648-4966-b2aa-37d66e24495f": { + "Module": "DMPushRouterCore.dll", + "ModulePath": "C:\\Windows\\System32\\DMPushRouterCore.dll", + "InterfaceId": "945693c4-3648-4966-b2aa-37d66e24495f", + "InterfaceStructOffset": 154144, + "ProceduresCount": 4, + "Procedures": [ + "CreateContext", + "CloseContext", + "CreateNamedProvisioningLock", + "ReleaseNamedProvisioningLock" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707581064480, + "Service": null, + "IsServiceRunning": false + }, + "1be3206b-2e03-4ea1-9321-12f4dfcd41d0": { + "Module": "webplatstorageserver.dll", + "ModulePath": "C:\\Windows\\System32\\webplatstorageserver.dll", + "InterfaceId": "1be3206b-2e03-4ea1-9321-12f4dfcd41d0", + "InterfaceStructOffset": 942672, + "ProceduresCount": 3, + "Procedures": [ + "s_DeleteAllStorages", + "s_DeleteAllStoragesForOrigin", + "s_DetachAllDatabasesForAppPackage" + ], + "ProcStackSize": 32, + "DispatchFunction": 140706992850944, + "Service": null, + "IsServiceRunning": false + }, + "4a72bfe1-9294-11da-a72b-0800200c9a66": { + "Module": "rdpinit.exe", + "ModulePath": "C:\\Windows\\System32\\rdpinit.exe", + "InterfaceId": "4a72bfe1-9294-11da-a72b-0800200c9a66", + "InterfaceStructOffset": 289120, + "ProceduresCount": 20, + "Procedures": [ + "RpcAcquireContextHandle", + "RpcReleaseContextHandle", + "RpcRailShellExecute", + "RpcOnTaskbarPosition", + "RpcOnDisplayChange", + "RpcStartRailTray", + "RpcStopRailTray", + "RpcOnTrayNotifyEvent", + "RpcNotifyLogoffParameterChange", + "RpcUpdateMaxIconSize", + "RpcRailActivateApplication", + "RpcUpdateAppBarRemotingSupport", + "RpcWindowCloakingTrackerAddWindow", + "RpcWindowCloakingTrackerRemoveWindow", + "RpcWindowCloakingTrackerReset", + "RpcOnWindowCloakStateChanged", + "RpcGetMarkerWindow", + "RpcDestroyMarkerWindow", + "RpcSetWindowSnapArrangement", + "RpcAcquireRdpInitPID" + ], + "ProcStackSize": 24, + "DispatchFunction": 140695030147136, + "Service": null, + "IsServiceRunning": false + }, + "461e6f82-89d8-4b7b-95ca-2e5c965953fc": { + "Module": "AppVEntSubsystemController.dll", + "ModulePath": "C:\\Windows\\System32\\AppVEntSubsystemController.dll", + "InterfaceId": "461e6f82-89d8-4b7b-95ca-2e5c965953fc", + "InterfaceStructOffset": 901712, + "ProceduresCount": 22, + "Procedures": [ + "s_vservices_server_GetVeProcessRuntimeSettings", + "s_vservices_server_OpenSCManager", + "s_vservices_server_OpenService", + "s_vservices_server_StartService", + "s_vservices_server_StartServiceControlDispatcher", + "s_vservices_server_SetServiceStatus", + "s_vservices_server_ControlService", + "s_vservices_server_QueryServiceStatusEx", + "s_vservices_server_EnumServicesStatusW", + "s_vservices_server_EnumServicesStatusA", + "s_vservices_server_EnumServicesStatusExW", + "s_vservices_server_EnumServicesStatusExA", + "s_vservices_server_EnumDependentServicesW", + "s_vservices_server_EnumDependentServicesA", + "s_vservices_server_CloseServiceHandle", + "s_vservices_server_GetServiceKeyName", + "s_vservices_server_GetServiceDisplayName", + "s_vservices_server_QueryServiceConfigW", + "s_vservices_server_QueryServiceConfigA", + "s_vservices_server_QueryServiceConfig2W", + "s_vservices_server_QueryServiceConfig2A", + "s_vservices_server_QueryServiceObjectSecurity" + ], + "ProcStackSize": 72, + "DispatchFunction": 140706797979552, + "Service": null, + "IsServiceRunning": false + }, + "f3cc53ae-499d-47d9-929b-a51b1176affb": { + "Module": "hvsirpcd.exe", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-hvsi-manager_31bf3856ad364e35_10.0.18362.1832_none_158049e1d563edb9\\hvsirpcd.exe", + "InterfaceId": "f3cc53ae-499d-47d9-929b-a51b1176affb", + "InterfaceStructOffset": 67712, + "ProceduresCount": 2, + "Procedures": [ + "s_HvsiWinHttpGetProxyForUrl", + "s_HvsiWinHttpReadProxySettings" + ], + "ProcStackSize": 64, + "DispatchFunction": 140698086710848, + "Service": null, + "IsServiceRunning": false + }, + "bb8b98e8-84dd-45e7-9f34-c3fb6155eeed": { + "Module": "vaultsvc.dll", + "ModulePath": "C:\\Windows\\System32\\vaultsvc.dll", + "InterfaceId": "bb8b98e8-84dd-45e7-9f34-c3fb6155eeed", + "InterfaceStructOffset": 266240, + "ProceduresCount": 19, + "Procedures": [ + "VltCreateItemType", + "VltDeleteItemType", + "VltEnumerateItemTypes", + "VltAddItem", + "VltFindItems", + "VltEnumerateItems", + "VltGetItem", + "VltRemoveItem", + "VltGetItemType", + "VltOpenVault", + "VltCloseVault", + "VltGetInformation", + "VltEnumerateVaults", + "VltEnumerateSettingUnits", + "VltGetSettingUnit", + "VltApplySettingUnit", + "VltRemoveSettingUnit", + "VltTriggerSync", + "VltGetSettingUnitInfo" + ], + "ProcStackSize": 64, + "DispatchFunction": 140707205764480, + "Service": "VaultSvc", + "IsServiceRunning": true + }, + "bbdc1d6b-35d9-480e-b5d2-c07545d32641": { + "Module": "moshost.dll", + "ModulePath": "C:\\Windows\\System32\\moshost.dll", + "InterfaceId": "bbdc1d6b-35d9-480e-b5d2-c07545d32641", + "InterfaceStructOffset": 58416, + "ProceduresCount": 20, + "Procedures": [ + "OdmlSvcOpen", + "OdmlSvcClose", + "OdmlSvcStartCheckForUpdates", + "OdmlSvcStartInstallUpdate", + "OdmlSvcGetUserPackages", + "OdmlSvcGetAvailablePackages", + "OdmlSvcFindNearbyPackagesAsync", + "OdmlSvcAddMapPackages", + "OdmlSvcRemoveMapPackages", + "OdmlSvcCancelMapPackage", + "OdmlSvcDeleteAllMaps", + "OdmlSvcGetCopyrightString", + "OdmlSvcSetAutoUpdateEnabled", + "OdmlSvcGetAutoUpdateEnabled", + "OdmlSvcSetUpdateOnlyOnWifi", + "OdmlSvcGetUpdateOnlyOnWifi", + "OdmlSvcGetShouldUseWlanString", + "OdmlSvcGetIsStorageStateValid", + "OdmlSvcStartMapDataMigration", + "OdmlSvcCancelMapDataMigration" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707880920224, + "Service": "MapsBroker", + "IsServiceRunning": false + }, + "5a7ccda5-1cd7-4693-a8d6-4bdded80c32f": { + "Module": "splwow64.exe", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-printing-spooler-core_31bf3856ad364e35_10.0.18362.1854_none_e3b31a0c2490fffd\\splwow64.exe", + "InterfaceId": "5a7ccda5-1cd7-4693-a8d6-4bdded80c32f", + "InterfaceStructOffset": 57104, + "ProceduresCount": 18, + "Procedures": [ + "RPCSplWOW64RefreshLifeSpan", + "RPCSplWOW64GetProcessID", + "RPCSplWOW64GetProcessHndl", + "RPCSplWOW64AddPort", + "RPCSplWOW64DeletePort", + "RPCSplWOW64ConfigurePort", + "RPCSplWOW64DeviceCapabilities", + "RPCSplWOW64DocumentProperties", + "RPCSplWOW64PrintUIDocumentProperties", + "RPCSplWOW64PrinterProperties", + "RPCSplWOW64SpoolerPrinterEvent", + "RPCSplWOW64DocumentEvent", + "RPCSplWOW64PrintUIQueueCreate", + "RPCSplWOW64PrintUIPrinterPropPages", + "RPCSplWOW64PrintUIDocumentDefaults", + "RPCSplWOW64PrintUIPrinterSetup", + "RPCSplWOW64PrintUIServerPropPages", + "RPCSplGetSaveFileInfo" + ], + "ProcStackSize": 56, + "DispatchFunction": 140699011929056, + "Service": null, + "IsServiceRunning": false + }, + "0d3c7f20-1c8d-4654-a1b3-51563b298bda": { + "Module": "usermgr.dll", + "ModulePath": "C:\\Windows\\System32\\usermgr.dll", + "InterfaceId": "0d3c7f20-1c8d-4654-a1b3-51563b298bda", + "InterfaceStructOffset": 779872, + "ProceduresCount": 1, + "Procedures": [ + "svcGetUserMarshalData" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708013377056, + "Service": "UserManager", + "IsServiceRunning": true + }, + "2c7fd9ce-e706-4b40-b412-953107ef9bb0": { + "Module": "PsmServiceExtHost.dll", + "ModulePath": "C:\\Windows\\System32\\PsmServiceExtHost.dll", + "InterfaceId": "2c7fd9ce-e706-4b40-b412-953107ef9bb0", + "InterfaceStructOffset": 559712, + "ProceduresCount": 9, + "Procedures": [ + "RmgrSrv_RegisterWithServer", + "RmgrSrv_RmSetMemoryUsageLimit", + "RmgrSrv_RmRegisterResource", + "RmgrSrv_RmAccessCheck", + "RmgrSrv_RmAccessCheckOnCaller", + "RmgrSrv_RmAvailabilityCheck", + "RmgrSrv_RmAcquireResources", + "RmgrSrv_RmGetNotification", + "RmgrSrv_RmReleaseResources" + ], + "ProcStackSize": 16, + "DispatchFunction": 140708133524944, + "Service": null, + "IsServiceRunning": false + }, + "8fb74744-b2ff-4c00-be0d-9ef9a191fe1b": { + "Module": "keyiso.dll", + "ModulePath": "C:\\Windows\\System32\\keyiso.dll", + "InterfaceId": "8fb74744-b2ff-4c00-be0d-9ef9a191fe1b", + "InterfaceStructOffset": 57440, + "ProceduresCount": 12, + "Procedures": [ + "s_GetSymmetricPopKeyTransportKey", + "s_GetSymmetricPopKeyTransportKeyName", + "s_DeleteSymmetricPopKeyTransportKey", + "s_ImportSymmetricPopKey", + "s_SignWithSymmetricPopKey", + "s_VerifyWithSymmetricPopKey", + "s_DecryptWithSymmetricPopKey", + "s_EncryptWithSymmetricPopKey", + "s_GetKeyAttestationForContainerService", + "s_RenewKeyAttestation", + "s_GetPregenUserKey", + "s_GetPregenKeyState" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707761381104, + "Service": "KeyIso", + "IsServiceRunning": true + }, + "1cbcad78-df0b-4934-b558-87839ea501c9": { + "Module": "dsrolesrv.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-d..vices-dsrole-server_31bf3856ad364e35_10.0.18362.1_none_faf38a04e7aff2af\\dsrolesrv.dll", + "InterfaceId": "1cbcad78-df0b-4934-b558-87839ea501c9", + "InterfaceStructOffset": 166656, + "ProceduresCount": 12, + "Procedures": [ + "DsRolerDnsNameToFlatName", + "DsRolerDcAsDc", + "DsRolerDcAsReplica", + "DsRolerDemoteDc", + "DsRolerGetDcOperationProgress", + "DsRolerGetDcOperationResults", + "DsRolerCancel", + "DsRolerIfmHandleFree", + "DsRolerServerSaveStateForUpgrade", + "DsRolerUpgradeDownlevelServer", + "DsRolerAbortDownlevelServerUpgrade", + "DsRolerGetDatabaseFacts" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707880721328, + "Service": null, + "IsServiceRunning": false + }, + "33d84484-3626-47ee-8c6f-e7e98b113be1": { + "Module": "WPTaskScheduler.dll", + "ModulePath": "C:\\Windows\\System32\\WPTaskScheduler.dll", + "InterfaceId": "33d84484-3626-47ee-8c6f-e7e98b113be1", + "InterfaceStructOffset": 111584, + "ProceduresCount": 13, + "Procedures": [ + "s_TaskSchedulerCreateSchedule", + "s_TaskSchedulerDeleteSchedule", + "s_TaskSchedulerFindFirstSchedule", + "s_TaskSchedulerFindNextSchedule", + "s_TaskSchedulerFindScheduleClose", + "s_TaskSchedulerGetSchedule", + "s_TaskSchedulerEnableSchedule", + "s_TaskSchedulerExecuteSchedule", + "s_TaskSchedulerAdvanceSchedule", + "s_TaskSchedulerAdvanceScheduleIntervals", + "s_TaskSchedulerSnoozeSchedule", + "s_TaskSchedulerGetPublishStateName", + "s_TaskSchedulerServiceControl" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708036372944, + "Service": null, + "IsServiceRunning": false + }, + "a2d47257-12f7-4beb-8981-0ebfa935c407": { + "Module": "pnrpsvc.dll", + "ModulePath": "C:\\Windows\\System32\\pnrpsvc.dll", + "InterfaceId": "a2d47257-12f7-4beb-8981-0ebfa935c407", + "InterfaceStructOffset": 309792, + "ProceduresCount": 13, + "Procedures": [ + "PnrpRpcInitializeCloudList", + "PnrpRpcGetCloudList", + "PnrpRpcShutdownCloudList", + "PnrpRpcClientInitialize", + "PnrpRpcClientUninitialize", + "PnrpRpcRegister", + "PnrpRpcUnregister", + "PnrpRpcResolve", + "PnrpRpcGetResolveResult", + "PnrpRpcEndResolve", + "PnrpRpcPing", + "PnrpRpcDiagControl", + "PnrpRpcHandlePowerEvent" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707581099104, + "Service": "PNRPsvc", + "IsServiceRunning": false + }, + "4b324fc8-1670-01d3-1278-5a47bf6ee188": { + "Module": "srvsvc.dll", + "ModulePath": "C:\\Windows\\System32\\srvsvc.dll", + "InterfaceId": "4b324fc8-1670-01d3-1278-5a47bf6ee188", + "InterfaceStructOffset": 192512, + "ProceduresCount": 72, + "Procedures": [ + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrConnectionEnum", + "NetrFileEnum", + "NetrFileGetInfo", + "NetrFileClose", + "NetrSessionEnum", + "NetrSessionDel", + "NetrShareAdd", + "NetrShareEnum", + "NetrShareGetInfo", + "NetrShareSetInfo", + "NetrShareDel", + "NetrShareDelSticky", + "NetrShareCheck", + "NetrServerGetInfo", + "NetrServerSetInfo", + "NetrServerDiskEnum", + "NetrServerStatisticsGet", + "NetrServerTransportAdd", + "NetrServerTransportEnum", + "NetrServerTransportDel", + "NetrRemoteTOD", + "I_NetrServerSetServiceBits", + "NetprPathType", + "NetprPathCanonicalize", + "NetprPathCompare", + "NetprNameValidate", + "NetprNameCanonicalize", + "NetprNameCompare", + "NetrShareEnumSticky", + "NetrShareDelStart", + "NetrShareDelCommit", + "NetrpGetFileSecurity", + "NetrpSetFileSecurity", + "NetrServerTransportAddEx", + "I_NetrServerSetServiceBitsEx", + "NetrDfsGetVersion", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrCharDevControl", + "NetrServerTransportDelEx", + "NetrServerAliasAdd", + "NetrServerAliasEnum", + "NetrServerAliasDel", + "NetrShareDelEx", + "LocalrSessionEnum", + "LocalrSessionGetInfo", + "LocalrSessionDel", + "LocalrFileEnum", + "LocalrFileGetInfo", + "LocalrFileClose", + "LocalrShareEnum", + "LocalrShareGetInfo", + "LocalrShareSetInfo", + "LocalrShareAdd", + "LocalrShareDelEx", + "LocalrAliasGet", + "NetrServerTransportAddForInstance", + "NetrServerTransportDelForInstance" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707955978944, + "Service": "LanmanServer", + "IsServiceRunning": true + }, + "12e65dd8-887f-41ef-91bf-8d816c42c2e7": { + "Module": "winlogon.exe", + "ModulePath": "C:\\Windows\\System32\\winlogon.exe", + "InterfaceId": "12e65dd8-887f-41ef-91bf-8d816c42c2e7", + "InterfaceStructOffset": 610992, + "ProceduresCount": 5, + "Procedures": [ + "WlSecureDesktoprPromptingRequest", + "WlSecureDesktoprConfirmationRequest", + "WlSecureDesktoprCredmanBackupRequest", + "WlSecureDesktoprCredmanRestoreRequest", + "WlSecureDesktoprSimulateSAS" + ], + "ProcStackSize": 16, + "DispatchFunction": 140701228583248, + "Service": null, + "IsServiceRunning": false + }, + "7c44d7d4-31d5-424c-bd5e-2b3e1f323d22": { + "Module": "ntdsai.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-d..toryservices-ntdsai_31bf3856ad364e35_10.0.18362.1916_none_fe1eba331c36e95d\\ntdsai.dll", + "InterfaceId": "7c44d7d4-31d5-424c-bd5e-2b3e1f323d22", + "InterfaceStructOffset": 4346096, + "ProceduresCount": 2, + "Procedures": [ + "IDL_DSAPrepareScript", + "IDL_DSAExecuteScript" + ], + "ProcStackSize": 48, + "DispatchFunction": 140706770989344, + "Service": null, + "IsServiceRunning": false + }, + "98cd761e-e77d-41c8-a3c0-0fb756d90ec2": { + "Module": "diagtrack.dll", + "ModulePath": "C:\\Windows\\System32\\diagtrack.dll", + "InterfaceId": "98cd761e-e77d-41c8-a3c0-0fb756d90ec2", + "InterfaceStructOffset": 2709952, + "ProceduresCount": 7, + "Procedures": [ + "UtcWerHelperApi_FetchReportCount", + "UtcEventTranscriptApi_FetchTranscriptRecordsPage", + "UtcWerHelperApi_EnableWerLocalReports", + "UtcWerHelperApi_RestoreWerLocalReportsSettings", + "UtcWerHelperApi_QueryWerLocalReportsEnabled", + "UtcWerHelperApi_FetchReportData2", + "UtcWerHelperApi_ExtractReport" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707991505040, + "Service": "DiagTrack", + "IsServiceRunning": true + }, + "f87e728f-2bf3-4358-9539-9b130ad71b54": { + "Module": "KeyboardFilterCore.dll", + "ModulePath": "C:\\Windows\\System32\\KeyboardFilterCore.dll", + "InterfaceId": "f87e728f-2bf3-4358-9539-9b130ad71b54", + "InterfaceStructOffset": 22256, + "ProceduresCount": 1, + "Procedures": [ + "KBFKEYToScancode" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707890538768, + "Service": null, + "IsServiceRunning": false + }, + "a80a054e-95a5-46b2-9b3b-afdb29f247fb": { + "Module": "AppVShNotify.exe", + "ModulePath": "C:\\Windows\\System32\\AppVShNotify.exe", + "InterfaceId": "a80a054e-95a5-46b2-9b3b-afdb29f247fb", + "InterfaceStructOffset": 102976, + "ProceduresCount": 1, + "Procedures": [ + "s_IFTANotify_ShellNotify" + ], + "ProcStackSize": 16, + "DispatchFunction": 140702910017168, + "Service": null, + "IsServiceRunning": false + }, + "e40f7b57-7a25-4cd3-a135-7f7d3df9d16b": { + "Module": "ncbservice.dll", + "ModulePath": "C:\\Windows\\System32\\ncbservice.dll", + "InterfaceId": "e40f7b57-7a25-4cd3-a135-7f7d3df9d16b", + "InterfaceStructOffset": 233472, + "ProceduresCount": 21, + "Procedures": [ + "RpcSrvCreateSession", + "RpcSrvDestroySession", + "RpcSrvStartBrokeredActivation", + "RpcSrvSetServerKeepAliveInterval", + "RpcSrvGetCurrentKeepAliveInterval", + "RpcSrvDecreaseKeepAliveInterval", + "RpcSrvUsingTransport", + "RpcSrvIndicateSlotAllocation", + "RpcSrvSBCreatePushEnabledContext", + "RpcSrvSBTransferOwnership", + "RpcSrvSBRetrieveSocket", + "RpcSrvSBCompleteRetrieveSocket", + "RpcSrvSBRetrieveContext", + "RpcSrvSBEnumSockets", + "RpcSrvHotspotRegisterHotspotApp", + "RpcSrvHotspotFindEventForPackage", + "RpcSrvHotspotTriggerBackgroundEvent", + "RpcSrvHotspotIsAppInstalled", + "RpcSrvFirewallWcmSetFirewallRule", + "RpcSrvFirewallWcmSetFirewallRuleFlags", + "RpcSrvFirewallWcmDeleteFirewallRule" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708099605296, + "Service": "NcbService", + "IsServiceRunning": true + }, + "266f33b4-c7c1-4bd1-8f52-ddb8f2214ea9": { + "Module": "wlansvc.dll", + "ModulePath": "C:\\Windows\\System32\\wlansvc.dll", + "InterfaceId": "266f33b4-c7c1-4bd1-8f52-ddb8f2214ea9", + "InterfaceStructOffset": 2051888, + "ProceduresCount": 151, + "Procedures": [ + "RpcOpenHandle", + "RpcCloseHandle", + "RpcEnumInterfaces", + "RpcSetAutoConfigParameter", + "RpcQueryAutoConfigParameter", + "RpcGetInterfaceCapability", + "RpcSetInterface", + "RpcQueryInterface", + "RpcIhvControl", + "RpcScan", + "RpcGetLastScanTimeInTicks", + "RpcGetAvailableNetworkList", + "RpcPrivateGetAvailableNetworkList", + "RpcPrivateClearAnqpCache", + "RpcPrivateRefreshAnqpCache", + "RpcPrivateGetAnqpCacheResponse", + "RpcPrivateParseAnqpRawData", + "RpcPrivateGetAnqpOSUProviderList", + "RpcPrivateEnableAnqpOsuRegistration", + "RpcPrivateGetAnqpOsuRegistrationStatus", + "RpcGetNetworkBssList", + "RpcConnect", + "RpcConnectEx", + "RpcDisconnect", + "RpcRegisterNotification", + "RpcAsyncGetNotification", + "RpcSetProfileEapUserData", + "RpcSetProfile", + "RpcGetProfile", + "RpcDeleteProfile", + "RpcRenameProfile", + "RpcSetProfileList", + "RpcSetProfileListForOffload", + "RpcGetProfileList", + "RpcSetProfilePosition", + "RpcSetProfileCustomUserData", + "RpcGetProfileCustomUserData", + "RpcSetFilterList", + "RpcGetFilterList", + "RpcSetPsdIEDataList", + "RpcSaveTemporaryProfile", + "RpcIsUIRequestPending", + "RpcSetUIForwardingNetworkList", + "RpcIsNetworkSuppressed", + "RpcRemoveUIForwardingNetworkList", + "RpcQueryExtUIRequest", + "RpcUIResponse", + "RpcGetProfileKeyInfo", + "RpcCanDeleteProfile", + "RpcAsyncDoPlap", + "RpcQueryPlapCredentials", + "RpcCancelPlap", + "RpcSetSecuritySettings", + "RpcGetSecuritySettings", + "RpcHostedNetworkPerformOperation", + "RpcHostedNetworkHlpQueryEverUsed", + "RpcHostedNetworkSetProperty", + "RpcHostedNetworkQueryProperty", + "RpcHostedNetworkQueryStatus", + "RpcHostedNetworkQueryWCNSettings", + "RpcHostedNetworkSetWCNSettings", + "RpcGetProfileEapUserDataInfo", + "RpcQueryPreConnectInput", + "RpcConnectWithInput", + "RpcRefreshConnections", + "RpcInternalRequestFtm", + "RpcInternalScan", + "RpcHostedNetworkSetSecondaryKey", + "RpcHostedNetworkQuerySecondaryKey", + "RpcRegisterVirtualStationNotification", + "RpcEnumAllInterfaces", + "RpcQueryInterfacePortType", + "RpcStartMovementDetector", + "RpcStopMovementDetector", + "RpcSetProtectedScenario", + "RpcWFDDiscoverDevices", + "RpcWFDGetVisibleDevices", + "RpcWFDStopDiscoverDevices", + "RpcWFDStartBackgroundDiscovery", + "RpcWFDStopBackgroundDiscovery", + "RpcWFDDiscoverDeviceServiceInformation", + "RpcWFDOpenHandle", + "RpcWFDRegisterVMgrCaller", + "RpcWFDUnregisterVMgrCaller", + "RpcWFDQueryProperty", + "RpcWFDSetProperty", + "RpcWFDSetSecondaryDeviceTypeList", + "RpcWFDPairEnumerateCeremonies", + "RpcWFDPairSelectCeremony", + "RpcWFDPairWithDevice", + "RpcWFDPairCancel", + "RpcWFDPairCancelByDeviceAddress", + "RpcWFDOpenSession", + "RpcWFDGetSessionEndpointPairs", + "RpcWFDConfigureFirewallForSession", + "RpcWFDCancelOpenSession", + "RpcWFDCloseSession", + "RpcWFDAbortSession", + "RpcWFDForceDisconnect", + "RpcWFDForceDisconnectLegacyPeer", + "RpcWFDAcceptGroupRequestAndOpenSession", + "RpcWFDDeclineGroupRequest", + "RpcWFDSetWCNSettings", + "RpcWFDAcceptConnectRequestAndOpenSession", + "RpcWFDDeclineConnectRequest", + "RpcWFDGetPeerInfo", + "RpcWFDGetDefaultGroupProfile", + "RpcWFDGetProfileKeyInfo", + "RpcWFDStartUsingGroup", + "RpcWFDStopUsingGroup", + "RpcWFDOpenLegacySessionWithProfile", + "RpcWFDCloseLegacySession", + "RpcWFDIsInterfaceWiFiDirect", + "RpcIsWiFiDirectRunningOnWiFiAdapter", + "RpcWFDUpdateDeviceVisibility", + "RpcWFDOpenLegacySession", + "RpcWFDFlushVisibleDeviceList", + "RpcWlanNotifyVsIeProvider", + "RpcWlanNotifyVsIeProviderEx", + "RpcWFDGetDeviceDescriptorForPendingRequest", + "RpcWFDStartOffloadedDiscovery", + "RpcWFDStopOffloadedDiscovery", + "RpcWFDGetPrimaryAdapterState", + "RpcWFDDiscoverDevicesEx", + "RpcWFDGetVisibleDevicesEx", + "RpcWFDStopDiscoverDevicesEx", + "RpcWFDSetSelectedWfdMgr", + "RpcWFDSetSelectedWfdMgrWithoutClientContext", + "RpcWFDResetSelectedWfdMgr", + "RpcWiFiDisplaySetSinkClientHandle", + "RpcWiFiDisplaySetSinkState", + "RpcWiFiDisplayResetSinkState", + "RpcSetProfileMetadata", + "RpcGetProfileMetadata", + "RpcWCMGetProfileList", + "RpcWcmSetProfile", + "RpcWcmSetInterface", + "RpcWcmGetInterface", + "RpcWcmDisconnect", + "RpcStoreRadioState", + "RpcGetStoredRadioState", + "RpcGetRadioInformation", + "RpcGetProfileIndex", + "RpcGetMFPNegotiated", + "RpcPrivateQueryInterface", + "RpcPrivateSetInterface", + "RpcUpdateBasicProfileSecurity", + "RpcPrivateQuery11adPairedConfig", + "RpcGetSupportedDeviceServices", + "RpcDeviceServiceCommand", + "RpcRegisterDeviceServiceNotification" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707602732992, + "Service": "WlanSvc", + "IsServiceRunning": true + }, + "5cbe92cb-f4be-45c9-9fc9-33e73e557b20": { + "Module": "dpapisrv.dll", + "ModulePath": "C:\\Windows\\System32\\dpapisrv.dll", + "InterfaceId": "5cbe92cb-f4be-45c9-9fc9-33e73e557b20", + "InterfaceStructOffset": 184320, + "ProceduresCount": 3, + "Procedures": [ + "s_SSRecoverQueryStatus", + "s_SSRecoverImportRecoveryKey", + "s_SSRecoverPassword" + ], + "ProcStackSize": 64, + "DispatchFunction": 140708143075392, + "Service": null, + "IsServiceRunning": false + }, + "fc48cd89-98d6-4628-9839-86f7a3e4161a": { + "Module": "ACPBackgroundManagerPolicy.dll", + "ModulePath": "C:\\Windows\\System32\\ACPBackgroundManagerPolicy.dll", + "InterfaceId": "fc48cd89-98d6-4628-9839-86f7a3e4161a", + "InterfaceStructOffset": 121712, + "ProceduresCount": 9, + "Procedures": [ + "MVoipSrvNotifyVoipActiveCall", + "MVoipSrvNotifyVoipActivityCompleted", + "MVoipSrvHoldActiveCall", + "MVoipSrvUnholdActiveCall", + "MVoipSrvNotifyIncomingCallDialogDisplayed", + "MVoipSrvNotifyIncomingCallDialogDismissed", + "MVoipSrvLaunchVoipRtcTask", + "MVoipSrvLaunchVoipActivity", + "MVoipSrvCancelVoipCall" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707565913168, + "Service": null, + "IsServiceRunning": false + }, + "923c9623-db7f-4b34-9e6d-e86580f8ca2a": { + "Module": "SyncController.dll", + "ModulePath": "C:\\Windows\\System32\\SyncController.dll", + "InterfaceId": "923c9623-db7f-4b34-9e6d-e86580f8ca2a", + "InterfaceStructOffset": 494608, + "ProceduresCount": 18, + "Procedures": [ + "AccountsMgmtRpcCreateAccount", + "AccountsMgmtRpcDeleteAccount", + "AccountsMgmtRpcConvertWebAccountIdFromAppSpecificId", + "AccountsMgmtRpcConvertWebAccountIdToAppSpecificId", + "AccountsMgmtRpcSyncAccount", + "AccountsMgmtRpcSyncAccountAndWaitForCompletion", + "AccountsMgmtRpcQueryAccountProperties", + "AccountsMgmtRpcSaveAccountProperties", + "AccountsMgmtRpcEnumAccounts", + "AccountsMgmtRpcAdviseAccount", + "AccountsMgmtRpcUnadviseAccount", + "AccountsMgmtRpcGetNotifications", + "AccountsMgmtRpcDiscoverExchangeServerConfig", + "AccountsMgmtRpcDiscoverExchangeServerAuthType", + "AccountsMgmtRpcVerifyExchangeMailBoxTokenAuth", + "AccountsMgmtRpcDiscoverInternetMailServerConfig", + "AccountsMgmtRpcCancelDiscoverInternetMailServerConfig", + "AccountsMgmtRpcMayIgnoreInvalidServerCertificate" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707460221856, + "Service": null, + "IsServiceRunning": false + }, + "00000136-0000-0000-c000-000000000046": { + "Module": "rpcss.dll", + "ModulePath": "C:\\Windows\\System32\\rpcss.dll", + "InterfaceId": "00000136-0000-0000-c000-000000000046", + "InterfaceStructOffset": 959696, + "ProceduresCount": 5, + "Procedures": [ + "DummyAddRefISCMActivator", + "DummyAddRefISCMActivator", + "DummyAddRefISCMActivator", + "SCMActivatorGetClassObject", + "SCMActivatorCreateInstance" + ], + "ProcStackSize": 72, + "DispatchFunction": 140708134680352, + "Service": "RpcSs", + "IsServiceRunning": true + }, + "a2c45f7c-7d32-46ad-96f5-adafb486be74": { + "Module": "services.exe", + "ModulePath": "C:\\Windows\\System32\\services.exe", + "InterfaceId": "a2c45f7c-7d32-46ad-96f5-adafb486be74", + "InterfaceStructOffset": 501296, + "ProceduresCount": 3, + "Procedures": [ + "RI_ScOpenServiceChannelHandle", + "RI_ScSendResponseReceiveControls", + "RI_ScCloseServiceChannelHandle" + ], + "ProcStackSize": 16, + "DispatchFunction": 140702191674768, + "Service": null, + "IsServiceRunning": false + }, + "8833d1d0-965f-4216-b3e9-fbe58cad3100": { + "Module": "SCardSvr.dll", + "ModulePath": "C:\\Windows\\System32\\SCardSvr.dll", + "InterfaceId": "8833d1d0-965f-4216-b3e9-fbe58cad3100", + "InterfaceStructOffset": 171936, + "ProceduresCount": 2, + "Procedures": [ + "s_RPC_SCardReadCache", + "s_RPC_SCardWriteCache" + ], + "ProcStackSize": 56, + "DispatchFunction": 140707581070336, + "Service": "SCardSvr", + "IsServiceRunning": false + }, + "7d814569-35b3-4850-bb32-83035fcebf6e": { + "Module": "ias.dll", + "ModulePath": "C:\\Windows\\System32\\ias.dll", + "InterfaceId": "7d814569-35b3-4850-bb32-83035fcebf6e", + "InterfaceStructOffset": 20720, + "ProceduresCount": 3, + "Procedures": [ + "ServerDoRequest", + "ServerDoRequestAsync", + "ServerConfigureIas" + ], + "ProcStackSize": 8, + "DispatchFunction": 140708037797984, + "Service": null, + "IsServiceRunning": false + }, + "f763c91c-2ab1-47fa-868f-7de7efd42194": { + "Module": "vmrdvcore.dll", + "ModulePath": "C:\\Windows\\System32\\vmrdvcore.dll", + "InterfaceId": "f763c91c-2ab1-47fa-868f-7de7efd42194", + "InterfaceStructOffset": 307520, + "ProceduresCount": 2, + "Procedures": [ + "VmGetAppAllowListEntryByAlias", + "VmVerifyAppAllowed" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707581097632, + "Service": null, + "IsServiceRunning": false + }, + "d25576e4-00d2-43f7-98f9-b4c0724158f9": { + "Module": "lsasrv.dll", + "ModulePath": "C:\\Windows\\System32\\lsasrv.dll", + "InterfaceId": "d25576e4-00d2-43f7-98f9-b4c0724158f9", + "InterfaceStructOffset": 1270240, + "ProceduresCount": 3, + "Procedures": [ + "LsarEasMarkUserControlled", + "LsarEasGetCallerPasswordComplexity", + "LsarEasGetControlledUsersInfo" + ], + "ProcStackSize": 40, + "DispatchFunction": 140708154094704, + "Service": null, + "IsServiceRunning": false + }, + "57cce375-4430-47a6-bb96-2cad0d2fd140": { + "Module": "LsaIso.exe", + "ModulePath": "C:\\Windows\\System32\\LsaIso.exe", + "InterfaceId": "57cce375-4430-47a6-bb96-2cad0d2fd140", + "InterfaceStructOffset": 188688, + "ProceduresCount": 26, + "Procedures": [ + "BCryptIumGetClientContext", + "BCryptIumReleaseContext", + "BCryptIumOpenAlgorithmProvider", + "BCryptIumGetProperty", + "BCryptIumSetProperty", + "BCryptIumCloseAlgorithmProvider", + "BCryptIumGenerateSymmetricKey", + "BCryptIumGenerateKeyPair", + "BCryptIumEncrypt", + "BCryptIumDecrypt", + "BCryptIumExportKey", + "BCryptIumImportKey", + "BCryptIumImportKeyPair", + "BCryptIumDuplicateKey", + "BCryptIumFinalizeKeyPair", + "BCryptIumDestroyKey", + "BCryptIumDestroySecret", + "BCryptIumSignHash", + "BCryptIumVerifySignature", + "BCryptIumSecretAgreement", + "BCryptIumDeriveKey", + "BCryptIumKeyDerivation", + "BCryptIumCreateClaim", + "BCryptIumGetIdkSPub", + "BCryptIumCheckKey", + "BCryptIumPingTrustlet" + ], + "ProcStackSize": 32, + "DispatchFunction": 140697528931680, + "Service": null, + "IsServiceRunning": false + }, + "8fb6d884-2388-11d0-8c35-00c04fda2795": { + "Module": "w32time.dll", + "ModulePath": "C:\\Windows\\System32\\w32time.dll", + "InterfaceId": "8fb6d884-2388-11d0-8c35-00c04fda2795", + "InterfaceStructOffset": 270496, + "ProceduresCount": 8, + "Procedures": [ + "s_W32TimeSync", + "s_W32TimeGetNetlogonServiceBits", + "s_W32TimeQueryProviderStatus", + "s_W32TimeQuerySource", + "s_W32TimeQueryProviderConfiguration", + "s_W32TimeQueryConfiguration", + "s_W32TimeQueryStatus", + "s_W32TimeLog" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707580926128, + "Service": "W32Time", + "IsServiceRunning": false + }, + "a500d4c6-0dd1-4543-bc0c-d5f93486eaf8": { + "Module": "TimeBrokerServer.dll", + "ModulePath": "C:\\Windows\\System32\\TimeBrokerServer.dll", + "InterfaceId": "a500d4c6-0dd1-4543-bc0c-d5f93486eaf8", + "InterfaceStructOffset": 117872, + "ProceduresCount": 6, + "Procedures": [ + "TbiEnumerateEvents", + "TbiQueryEventData", + "TbiUpdateEvent", + "TbiQueryCEventData", + "_TbiQueryCEventTriggerTime", + "_TbiUpdateCEvent" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708098182112, + "Service": "TimeBrokerSvc", + "IsServiceRunning": true + }, + "03a04892-b1e0-4ca3-a5e4-097751b2b4c1": { + "Module": "vmsp.exe", + "ModulePath": "C:\\Windows\\System32\\vmsp.exe", + "InterfaceId": "03a04892-b1e0-4ca3-a5e4-097751b2b4c1", + "InterfaceStructOffset": 114960, + "ProceduresCount": 8, + "Procedures": [ + "RpcVmspOpenHandle", + "RpcVmspCloseHandle", + "RpcKmSetEncryptionKeys", + "RpcKmEgressKeyForDecryption", + "RpcVbsVmReleaseKeys", + "RpcVbsVmSetKeyProtector", + "RpcVbsVmUpdateKeyProtector", + "RpcVbsVmCreateVsmReport" + ], + "ProcStackSize": 88, + "DispatchFunction": 140701201368400, + "Service": null, + "IsServiceRunning": false + }, + "7212a04b-b463-402e-9649-2ba477394676": { + "Module": "umrdp.dll", + "ModulePath": "C:\\Windows\\System32\\umrdp.dll", + "InterfaceId": "7212a04b-b463-402e-9649-2ba477394676", + "InterfaceStructOffset": 272544, + "ProceduresCount": 7, + "Procedures": [ + "AllowTSEvent", + "RpcOpenDevice", + "RpcCloseDevice", + "RpcGetSessionId", + "RpcGetInterfaceGuids", + "RpcGetClientDeviceId", + "RpcGetDeviceCaps" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708067700656, + "Service": "UmRdpService", + "IsServiceRunning": true + }, + "6d9fe472-30f1-4708-8fa8-678362b96155": { + "Module": "wimserv.exe", + "ModulePath": "C:\\Windows\\System32\\wimserv.exe", + "InterfaceId": "6d9fe472-30f1-4708-8fa8-678362b96155", + "InterfaceStructOffset": 424128, + "ProceduresCount": 3, + "Procedures": [ + "AddImage", + "IsImageMounted", + "RemoveImage" + ], + "ProcStackSize": 24, + "DispatchFunction": 140700630591440, + "Service": null, + "IsServiceRunning": false + }, + "d09bdeb5-6171-4a34-bfe2-06fa82652568": { + "Module": "BrokerLib.dll", + "ModulePath": "C:\\Windows\\System32\\BrokerLib.dll", + "InterfaceId": "d09bdeb5-6171-4a34-bfe2-06fa82652568", + "InterfaceStructOffset": 164064, + "ProceduresCount": 3, + "Procedures": [ + "BriCreateEventForKernel", + "BriCreateEvent", + "BriDeleteEvent" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708126600576, + "Service": null, + "IsServiceRunning": false + }, + "a1d4eae7-39f8-4bca-8e72-832767f5082a": { + "Module": "das.dll", + "ModulePath": "C:\\Windows\\System32\\das.dll", + "InterfaceId": "a1d4eae7-39f8-4bca-8e72-832767f5082a", + "InterfaceStructOffset": 368928, + "ProceduresCount": 6, + "Procedures": [ + "DasCreateInboundContext", + "DasStartListenForInboundAssociations", + "DasGetInboundAssociationResult", + "DasCloseInboundContext", + "DasRegisterForInboundAssociationsAppActivation", + "DasGetInboundAssociationResultForAppActivation" + ], + "ProcStackSize": 48, + "DispatchFunction": 140707580865152, + "Service": "DeviceAssociationService", + "IsServiceRunning": false + }, + "20c40295-8dba-48e6-aebf-3e78ef3bb144": { + "Module": "bisrv.dll", + "ModulePath": "C:\\Windows\\System32\\bisrv.dll", + "InterfaceId": "20c40295-8dba-48e6-aebf-3e78ef3bb144", + "InterfaceStructOffset": 552160, + "ProceduresCount": 5, + "Procedures": [ + "SrvOdbPtCreateSession", + "SrvOdbPtCompleteSession", + "SrvOdbPtLaunchBackgroundTask", + "SrvOdbPtCancelBackgroundTask", + "SrvOdbPtCancelBackgroundTasksForPackage" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708131135040, + "Service": null, + "IsServiceRunning": false + }, + "3706415d-4987-4fcf-9e08-00742572bd5a": { + "Module": "fhsvc.dll", + "ModulePath": "C:\\Windows\\System32\\fhsvc.dll", + "InterfaceId": "3706415d-4987-4fcf-9e08-00742572bd5a", + "InterfaceStructOffset": 73728, + "ProceduresCount": 10, + "Procedures": [ + "FhSvcApiOpenPipe", + "FhSvcApiClosePipe", + "FhSvcApiStartBackup", + "FhSvcApiStopBackup", + "FhSvcApiBlockUnblockBackup", + "FhSvcApiClearProtectionState", + "FhSvcApiEnterMaintenanceMode", + "FhSvcApiExitMaintenanceMode", + "FhSvcApiMigrationStarting", + "FhSvcApiMigrationFinished" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707581103760, + "Service": "fhsvc", + "IsServiceRunning": false + }, + "b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86": { + "Module": "keyiso.dll", + "ModulePath": "C:\\Windows\\System32\\keyiso.dll", + "InterfaceId": "b25a52bf-e5dd-4f4a-aea6-8ca7272a0e86", + "InterfaceStructOffset": 57536, + "ProceduresCount": 32, + "Procedures": [ + "s_SrvRpcCreateContext", + "s_SrvRpcReleaseContext", + "s_SrvRpcCryptOpenStorageProvider", + "s_SrvRpcCryptIsAlgSupported", + "s_SrvRpcCryptEnumAlgorithms", + "s_SrvRpcCryptEnumKeys", + "s_SrvRpcCryptFreeBuffer", + "s_SrvRpcCryptFreeProvider", + "s_SrvRpcCryptFreeKey", + "s_SrvRpcCryptOpenKey", + "s_SrvRpcCryptCreatePersistedKey", + "s_SrvRpcCryptGetProviderProperty", + "s_SrvRpcCryptSetProviderProperty", + "s_SrvRpcCryptGetKeyProperty", + "s_SrvRpcCryptSetKeyProperty", + "s_SrvRpcCryptFinalizeKey", + "s_SrvRpcCryptEncrypt", + "s_SrvRpcCryptDecrypt", + "s_SrvRpcCryptImportKey", + "s_SrvRpcCryptExportKey", + "s_SrvRpcCryptSignHash", + "s_SrvRpcCryptVerifySignature", + "s_SrvRpcCryptDeleteKey", + "s_SrvRpcCryptNotifyChangeKey", + "s_SrvRpcCryptSecretAgreement", + "s_SrvRpcCryptDeriveKey", + "s_SrvRpcCryptFreeSecret", + "s_SrvRpcCryptCipherEncrypt", + "s_SrvRpcCryptCipherDecrypt", + "s_SrvRpcCryptKeyDerivation", + "s_SrvRpcCryptCreateClaim", + "s_SrvRpcCryptVerifyClaim" + ], + "ProcStackSize": 96, + "DispatchFunction": 140707761401984, + "Service": "KeyIso", + "IsServiceRunning": true + }, + "2a82bb21-e44f-4791-9aa1-dfae788e2f43": { + "Module": "ubpm.dll", + "ModulePath": "C:\\Windows\\System32\\ubpm.dll", + "InterfaceId": "2a82bb21-e44f-4791-9aa1-dfae788e2f43", + "InterfaceStructOffset": 213792, + "ProceduresCount": 4, + "Procedures": [ + "s_UbpmRpcOpenTaskHostChannel", + "s_UbpmRpcCloseTaskHostChannel", + "s_UbpmRpcTaskHostSendResponseReceiveCommand", + "s_UbpmRpcTaskHostReportTaskStatus" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708046276672, + "Service": null, + "IsServiceRunning": false + }, + "edce686d-acae-4a2a-8945-24489443c35e": { + "Module": "AppVEntSubsystemController.dll", + "ModulePath": "C:\\Windows\\System32\\AppVEntSubsystemController.dll", + "InterfaceId": "edce686d-acae-4a2a-8945-24489443c35e", + "InterfaceStructOffset": 901232, + "ProceduresCount": 1, + "Procedures": [ + "vEnv_server_GetListOfVirtualEnvVars" + ], + "ProcStackSize": 80, + "DispatchFunction": 140706797844832, + "Service": null, + "IsServiceRunning": false + }, + "3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6": { + "Module": "dhcpcore6.dll", + "ModulePath": "C:\\Windows\\System32\\dhcpcore6.dll", + "InterfaceId": "3c4728c5-f0ab-448b-bda1-6ce01eb0a6d6", + "InterfaceStructOffset": 204800, + "ProceduresCount": 13, + "Procedures": [ + "RpcSrvRequestPrefixEx", + "RpcSrvRenewPrefixEx", + "RpcSrvReleasePrefixEx", + "RpcSrvCancelOperation", + "RpcSrvEnablev6Tracing", + "RpcSrvRequestParams", + "RpcSrvAcquireParametersv6", + "RpcSrvReleaseParametersv6", + "RpcSrvQueryLeaseInfov6", + "RpcSrvGetTraceArray", + "RpcSrvSetUserClass", + "RpcSrvQueryLeaseInfov6Array", + "RpcSrvEnableDhcpv6" + ], + "ProcStackSize": 32, + "DispatchFunction": 140708049621600, + "Service": null, + "IsServiceRunning": false + }, + "fd6b7e61-2bed-4d48-a267-d746fe449fed": { + "Module": "ngcsvc.dll", + "ModulePath": "C:\\Windows\\System32\\ngcsvc.dll", + "InterfaceId": "fd6b7e61-2bed-4d48-a267-d746fe449fed", + "InterfaceStructOffset": 630416, + "ProceduresCount": 4, + "Procedures": [ + "s_DeviceCredentialRpcRegisterPresenceMonitoring", + "s_DeviceCredentialRpcRegisterPresenceMonitoringOnExistingDevice", + "s_DeviceCredentialRpcUnregisterPresenceMonitoring", + "s_DeviceCredentialRpcUpdatePresenceState" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707094139280, + "Service": "NgcSvc", + "IsServiceRunning": false + }, + "0497b57d-2e66-424f-a0c6-157cd5d41700": { + "Module": "appinfo.dll", + "ModulePath": "C:\\Windows\\System32\\appinfo.dll", + "InterfaceId": "0497b57d-2e66-424f-a0c6-157cd5d41700", + "InterfaceStructOffset": 106496, + "ProceduresCount": 4, + "Procedures": [ + "RAiLaunchProcessWithIdentity", + "RAiGetPackageActivationToken", + "RAiFinishPackageActivation", + "RAiEnsurePackageShutdown" + ], + "ProcStackSize": 40, + "DispatchFunction": 140707486581232, + "Service": "Appinfo", + "IsServiceRunning": true + }, + "20610036-fa22-11cf-9823-00a0c911e5df": { + "Module": "rasmans.dll", + "ModulePath": "C:\\Windows\\System32\\rasmans.dll", + "InterfaceId": "20610036-fa22-11cf-9823-00a0c911e5df", + "InterfaceStructOffset": 794960, + "ProceduresCount": 16, + "Procedures": [ + "RasRpcPortEnum", + "RasRpcDeviceEnum", + "RasRpcGetDevConfig", + "RasRpcPortGetInfo", + "RasRpcEnumConnections", + "RasRpcDeleteEntry", + "RasRpcGetErrorString", + "RasRpcGetCountryInfo", + "RasRpcGetInstalledProtocols", + "RasRpcGetUserPreferences", + "RasRpcSetUserPreferences", + "RasRpcGetSystemDirectory", + "RasRpcSubmitRequest", + "RasRpcSubmitRequestLocal", + "RasRpcGetInstalledProtocolsEx", + "RasRpcGetVersion" + ], + "ProcStackSize": 24, + "DispatchFunction": 140707835672752, + "Service": "RasMan", + "IsServiceRunning": true + }, + "41208ee0-e970-11d1-9b9e-00e02c064c39": { + "Module": "mqqm.dll", + "ModulePath": "C:\\Windows\\WinSxS\\amd64_microsoft-windows-msmq-queuemanager-core_31bf3856ad364e35_10.0.18362.1977_none_8d1646dec2a87b94\\mqqm.dll", + "InterfaceId": "41208ee0-e970-11d1-9b9e-00e02c064c39", + "InterfaceStructOffset": 984448, + "ProceduresCount": 2, + "Procedures": [ + "R_QMMgmtGetInfo", + "R_QMMgmtAction" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707093258608, + "Service": null, + "IsServiceRunning": false + }, + "30adc50c-5cbc-46ce-9a0e-91914789e23c": { + "Module": "nrpsrv.dll", + "ModulePath": "C:\\Windows\\System32\\nrpsrv.dll", + "InterfaceId": "30adc50c-5cbc-46ce-9a0e-91914789e23c", + "InterfaceStructOffset": 13632, + "ProceduresCount": 2, + "Procedures": [ + "RpcNrpGetAddrInfo", + "RpcNrpGetNameInfo" + ], + "ProcStackSize": 80, + "DispatchFunction": 140708027832832, + "Service": null, + "IsServiceRunning": false + }, + "000001a0-0000-0000-c000-000000000046": { + "Module": "rpcss.dll", + "ModulePath": "C:\\Windows\\System32\\rpcss.dll", + "InterfaceId": "000001a0-0000-0000-c000-000000000046", + "InterfaceStructOffset": 959408, + "ProceduresCount": 5, + "Procedures": [ + "CopyTo", + "CopyTo", + "CopyTo", + "RemoteGetClassObject", + "RemoteCreateInstance" + ], + "ProcStackSize": 56, + "DispatchFunction": 140708135533424, + "Service": "RpcSs", + "IsServiceRunning": true + }, + "9cd76d01-051c-44e7-a449-942a3ff90f7c": { + "Module": "KeyboardFilterSvc.dll", + "ModulePath": "C:\\Windows\\System32\\KeyboardFilterSvc.dll", + "InterfaceId": "9cd76d01-051c-44e7-a449-942a3ff90f7c", + "InterfaceStructOffset": 100880, + "ProceduresCount": 3, + "Procedures": [ + "RemoveFilteredKeys", + "KeyboardLayoutChange", + "DesktopChange" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707581092000, + "Service": "MsKeyboardFilter", + "IsServiceRunning": false + }, + "0f9719b5-6a85-4bad-abdf-d8a678600f9b": { + "Module": "NgcCtnrSvc.dll", + "ModulePath": "C:\\Windows\\System32\\NgcCtnrSvc.dll", + "InterfaceId": "0f9719b5-6a85-4bad-abdf-d8a678600f9b", + "InterfaceStructOffset": 539632, + "ProceduresCount": 3, + "Procedures": [ + "s_NgcIsoTpmSubmitCommandCallback", + "s_NgcIsoTpmGetResponseCallback", + "s_NgcIsoTpmCloseCallback" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707093934512, + "Service": "NgcCtnrSvc", + "IsServiceRunning": false + }, + "2acb9d68-b434-4b3e-b966-e06b4b3a84cb": { + "Module": "bthserv.dll", + "ModulePath": "C:\\Windows\\System32\\bthserv.dll", + "InterfaceId": "2acb9d68-b434-4b3e-b966-e06b4b3a84cb", + "InterfaceStructOffset": 170672, + "ProceduresCount": 21, + "Procedures": [ + "BthServOpen", + "BthServClose", + "BthServRegisterAuthenticationEvent", + "BthServDeregisterAuthenticationEvent", + "BthServGetAuthRequest", + "BthServGetDeviceInfo", + "BthServSetDeviceName", + "BthServGetDeviceList", + "BthServActivateService", + "BthServUpdateService", + "BthServGetSdpRecord", + "BthServSetSdpRecord", + "BthServSetSdpRecordWithInfo", + "BthServRemoveSdpRecord", + "BthServEnableDiscovery", + "BthServEnableIncomingConnections", + "BthServUninstallDevice", + "BthServEirGetRecords", + "BthServEirSetRecord", + "BthServEirUpdateRecord", + "BthServEirRemoveRecord" + ], + "ProcStackSize": 32, + "DispatchFunction": 140707581041024, + "Service": "bthserv", + "IsServiceRunning": false + }, + "8d17061c-534a-4f1b-bd77-f615421cf379": { + "Module": "AppVEntSubsystemController.dll", + "ModulePath": "C:\\Windows\\System32\\AppVEntSubsystemController.dll", + "InterfaceId": "8d17061c-534a-4f1b-bd77-f615421cf379", + "InterfaceStructOffset": 900752, + "ProceduresCount": 4, + "Procedures": [ + "vreg_server_GetConfiguration", + "vreg_server_IsPidInVE", + "vreg_server_AddDuplicatedKeyToProcess", + "vreg_server_IsDuplicatedKey" + ], + "ProcStackSize": 72, + "DispatchFunction": 140706797782080, + "Service": null, + "IsServiceRunning": false + }, + "30b044a5-a225-43f0-b3a4-e060df91f9c1": { + "Module": "certprop.dll", + "ModulePath": "C:\\Windows\\System32\\certprop.dll", + "InterfaceId": "30b044a5-a225-43f0-b3a4-e060df91f9c1", + "InterfaceStructOffset": 143360, + "ProceduresCount": 2, + "Procedures": [ + "s_RPC_SmartCardRootCertsNotifyService", + "s_RPC_SmartCardCertsNotifyService" + ], + "ProcStackSize": 24, + "DispatchFunction": 140708042710576, + "Service": "SCPolicySvc", + "IsServiceRunning": false + }, + "a69816f5-83b6-4d48-8633-067f99f5f2d3": { + "Module": "Microsoft.Graphics.Display.DisplayEnhancementService.dll", + "ModulePath": "C:\\Windows\\System32\\Microsoft.Graphics.Display.DisplayEnhancementService.dll", + "InterfaceId": "a69816f5-83b6-4d48-8633-067f99f5f2d3", + "InterfaceStructOffset": 895856, + "ProceduresCount": 77, + "Procedures": [ + "DeManagementRpcServerOpenFromMonitorId", + "DeManagementRpcServerClose", + "DeManagementRpcServerGetIsNightLightCapable", + "DeManagementRpcServerGetIsNightLightOverridden", + "DeManagementRpcServerStartNightLightTransition", + "DeManagementRpcServerRegisterCallbackForIsNightLightCapableChanged", + "DeManagementRpcServerUnregisterCallbackForIsNightLightCapableChanged", + "DeManagementRpcServerRegisterCallbackForIsNightLightOverriddenChanged", + "DeManagementRpcServerUnregisterCallbackForIsNightLightOverriddenChanged", + "DeManagementRpcServerGetIsRealColorCapable", + "DeManagementRpcServerGetIsRealColorOverridden", + "DeManagementRpcServerGetIsRealColorOn", + "DeManagementRpcServerSetIsRealColorOn", + "DeManagementRpcServerGetColorLightSensorDeviceId", + "DeManagementRpcServerSetColorLightSensorDeviceId", + "DeManagementRpcServerGetRealColorAdaptationStrength", + "DeManagementRpcServerSetRealColorAdaptationStrength", + "DeManagementRpcServerGetAdaptiveColorPolicy", + "DeManagementRpcServerGetCurrentWhitePoint", + "DeManagementRpcServerSetCurrentWhitePoint", + "DeManagementRpcServerRegisterCallbackForIsRealColorCapableChanged", + "DeManagementRpcServerUnregisterCallbackForIsRealColorCapableChanged", + "DeManagementRpcServerRegisterCallbackForIsRealColorOnChanged", + "DeManagementRpcServerUnregisterCallbackForIsRealColorOnChanged", + "DeManagementRpcServerRegisterCallbackForIsRealColorAdaptationStrengthChanged", + "DeManagementRpcServerUnregisterCallbackForIsRealColorAdaptationStrengthChanged", + "DeManagementRpcServerRegisterCallbackForIsRealColorOverriddenChanged", + "DeManagementRpcServerUnregisterCallbackForIsRealColorOverriddenChanged", + "DeManagementRpcServerRegisterCallbackForColorLightSensorDeviceIdChanged", + "DeManagementRpcServerUnregisterCallbackForColorLightSensorDeviceIdChanged", + "DeManagementRpcServerRegisterCallbackForAdaptiveColorPolicyChanged", + "DeManagementRpcServerUnregisterCallbackForAdaptiveColorPolicyChanged", + "DeManagementRpcServerRegisterCallbackForCurrentWhitePointChanged", + "DeManagementRpcServerUnregisterCallbackForCurrentWhitePointChanged", + "DeManagementRpcServerGetIsBrightnessCapable", + "DeManagementRpcServerGetIsAutobrightnessCapable", + "DeManagementRpcServerGetIsAutobrightnessOn", + "DeManagementRpcServerSetIsAutobrightnessOn", + "DeManagementRpcServerGetIsBoostModeOn", + "DeManagementRpcServerGetBatterySaverBrightnessMultiplier", + "DeManagementRpcServerSetBatterySaverBrightnessMultiplier", + "DeManagementRpcServerGetDimBrightnessMultiplier", + "DeManagementRpcServerSetDimBrightnessMultiplier", + "DeManagementRpcServerGetUserBrightnessSettingPercent", + "DeManagementRpcServerSetUserBrightnessSettingPercent", + "DeManagementRpcServerGetScreenBrightnessPercent", + "DeManagementRpcServerGetIsBrightnessOverridden", + "DeManagementRpcServerGetThermalThrottlingMaxMilliNits", + "DeManagementRpcServerSetThermalThrottlingMaxMilliNits", + "DeManagementRpcServerGetIsThermalThrottlingOn", + "DeManagementRpcServerSetIsThermalThrottlingOn", + "DeManagementRpcServerGetAmbientLightSensorDeviceId", + "DeManagementRpcServerSetAmbientLightSensorDeviceId", + "DeManagementRpcServerRegisterCallbackForIsBrightnessCapableChanged", + "DeManagementRpcServerUnregisterCallbackForIsBrightnessCapableChanged", + "DeManagementRpcServerRegisterCallbackForIsAutobrightnessCapableChanged", + "DeManagementRpcServerUnregisterCallbackForIsAutobrightnessCapableChanged", + "DeManagementRpcServerRegisterCallbackForIsAutobrightnessOnChanged", + "DeManagementRpcServerUnregisterCallbackForIsAutobrightnessOnChanged", + "DeManagementRpcServerRegisterCallbackForIsBoostModeOnChanged", + "DeManagementRpcServerUnregisterCallbackForIsBoostModeOnChanged", + "DeManagementRpcServerRegisterCallbackForBatterySaverBrightnessMultiplierChanged", + "DeManagementRpcServerUnregisterCallbackForBatterySaverBrightnessMultiplierChanged", + "DeManagementRpcServerRegisterCallbackForDimBrightnessMultiplierChanged", + "DeManagementRpcServerUnregisterCallbackForDimBrightnessMultiplierChanged", + "DeManagementRpcServerRegisterCallbackForUserBrightnessSettingPercentChanged", + "DeManagementRpcServerUnregisterCallbackForUserBrightnessSettingPercentChanged", + "DeManagementRpcServerRegisterCallbackForScreenBrightnessPercentChanged", + "DeManagementRpcServerUnregisterCallbackForScreenBrightnessPercentChanged", + "DeManagementRpcServerRegisterCallbackForIsBrightnessOverriddenChanged", + "DeManagementRpcServerUnregisterCallbackForIsBrightnessOverriddenChanged", + "DeManagementRpcServerRegisterCallbackForThermalThrottlingMaxMilliNitsChanged", + "DeManagementRpcServerUnregisterCallbackForThermalThrottlingMaxMilliNitsChanged", + "DeManagementRpcServerRegisterCallbackForIsThermalThrottlingOnChanged", + "DeManagementRpcServerUnregisterCallbackForIsThermalThrottlingOnChanged", + "DeManagementRpcServerRegisterCallbackForAmbientLightSensorDeviceIdChanged", + "DeManagementRpcServerUnregisterCallbackForAmbientLightSensorDeviceIdChanged" + ], + "ProcStackSize": 16, + "DispatchFunction": 140707093519792, + "Service": "DisplayEnhancementService", + "IsServiceRunning": false + } +} \ No newline at end of file diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..e514216 --- /dev/null +++ b/LICENSE @@ -0,0 +1,201 @@ + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright (c) 2022 CyberArk Software Ltd. All rights reserved. + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. diff --git a/NOTICES.txt b/NOTICES.txt new file mode 100644 index 0000000..26b573b --- /dev/null +++ b/NOTICES.txt @@ -0,0 +1,211 @@ +RPCMon is using the following open source components: + +NtApiDotNet (https://github.com/googleprojectzero/sandbox-attacksurface-analysis-tools) : Apache License 2.0 +(c) Google LLC. 2015 - 2021 +Developed by James Forshaw + +Apache License 2.0 +====================== + + + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/.signature.p7s b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/.signature.p7s new file mode 100644 index 0000000..9be3b6d Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/.signature.p7s differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42.nupkg b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42.nupkg new file mode 100644 index 0000000..e20eb51 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42.nupkg differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/build/Microsoft.Diagnostics.Tracing.TraceEvent.props b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/build/Microsoft.Diagnostics.Tracing.TraceEvent.props new file mode 100644 index 0000000..f1c5358 --- /dev/null +++ b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/build/Microsoft.Diagnostics.Tracing.TraceEvent.props @@ -0,0 +1,58 @@ + + + + + x86\KernelTraceControl.dll + PreserveNewest + False + + + x86\KernelTraceControl.Win61.dll + PreserveNewest + False + + + x86\msdia140.dll + PreserveNewest + False + + + amd64\KernelTraceControl.dll + PreserveNewest + False + + + amd64\msdia140.dll + PreserveNewest + False + + + + + TraceReloggerLib.dll + PreserveNewest + False + + + Dia2Lib.dll + PreserveNewest + False + + + + + OSExtensions.dll + PreserveNewest + False + + + OSExtensions.dll + PreserveNewest + False + + + diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/amd64/KernelTraceControl.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/amd64/KernelTraceControl.dll new file mode 100644 index 0000000..12fa249 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/amd64/KernelTraceControl.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/amd64/msdia140.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/amd64/msdia140.dll new file mode 100644 index 0000000..f8104f1 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/amd64/msdia140.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/x86/KernelTraceControl.Win61.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/x86/KernelTraceControl.Win61.dll new file mode 100644 index 0000000..63bd780 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/x86/KernelTraceControl.Win61.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/x86/KernelTraceControl.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/x86/KernelTraceControl.dll new file mode 100644 index 0000000..3529ca3 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/x86/KernelTraceControl.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/x86/msdia140.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/x86/msdia140.dll new file mode 100644 index 0000000..894b4e3 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/native/x86/msdia140.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Dia2Lib.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Dia2Lib.dll new file mode 100644 index 0000000..68b11b6 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Dia2Lib.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Microsoft.Diagnostics.FastSerialization.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Microsoft.Diagnostics.FastSerialization.dll new file mode 100644 index 0000000..b7aaf6c Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Microsoft.Diagnostics.FastSerialization.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Microsoft.Diagnostics.FastSerialization.xml b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Microsoft.Diagnostics.FastSerialization.xml new file mode 100644 index 0000000..683b613 --- /dev/null +++ b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Microsoft.Diagnostics.FastSerialization.xml @@ -0,0 +1,1866 @@ + + + + Microsoft.Diagnostics.FastSerialization + + + + + A StreamLabel is a 32 bit integer that represents a position in a IStreamReader or + IStreamWriter. During writing it is generated by the IStreamWriter.GetLabel method an + consumed by the IStreamWriter.WriteLabel method. On reading you can use + IStreamReader.Current and and IStreamReader. + + + + + Represents a stream label that is not a valid value + + + + + IStreamWriter is meant to be a very simple streaming protocol. You can write integral types, + strings, and labels to the stream itself. + + IStreamWrite can be thought of a simplified System.IO.BinaryWriter, or maybe the writer + part of a System.IO.Stream with a few helpers for primitive types. + + See also IStreamReader + + + + + Write a byte to a stream + + + + + Write a short to a stream + + + + + Write an int to a stream + + + + + Write a long to a stream + + + + + Write a StreamLabel (a pointer to another part of the stream) to a stream + + + + + Write a string to a stream (supports null values). + + + + + Get the stream label for the current position (points at whatever is written next + + + + + + Write a SuffixLabel it must be the last thing written to the stream. The stream + guarantees that this value can be efficiently read at any time (probably by seeking + back from the end of the stream)). The idea is that when you generate a 'tableOfContents' + you can only do this after processing the data (and probably writing it out), If you + remember where you write this table of contents and then write a suffix label to it + as the last thing in the stream using this API, you guarantee that the reader can + efficiently seek to the end, read the value, and then goto that position. (See + IStreamReader.GotoSuffixLabel for more) + + + + IStreamReader is meant to be a very simple streaming protocol. You can read integral types, + strings, and labels to the stream itself. You can also goto labels you have read from the stream. + + IStreamReader can be thought of a simplified System.IO.BinaryReder, or maybe the reader + part of a System.IO.Stream with a few helpers for primitive types. + + See also IStreamWriter + + + + Read a byte from the stream + + + + + Read a short from the stream + + + + + Read an int from the stream + + + + + Read a long from the stream + + + + + Read a string from the stream. Can represent null strings + + + + + Read a span of bytes from the stream. + + + + + Read a StreamLabel (pointer to some other part of the stream) from the stream + + + + + Goto a location in the stream + + + + + Returns the current position in the stream. + + + + + Sometimes information is only known after writing the entire stream. This information can be put + on the end of the stream, but there needs to be a way of finding it relative to the end, rather + than from the beginning. A IStreamReader, however, does not actually let you go 'backwards' easily + because it does not guarantee the size what it writes out (it might compress). + + The solution is the concept of a 'suffixLabel' which is location in the stream where you can always + efficiently get to. + + It is written with a special API (WriteSuffixLabel that must be the last thing written. It is + expected that it simply write an uncompressed StreamLabel. It can then be used by using the + GotoSTreamLabel() method below. This goes to this well know position in the stream. We expect + this is implemented by seeking to the end of the stream, reading the uncompressed streamLabel, + and then seeking to that position. + + + + + Support for higher level operations on IStreamWriter and IStreamReader + + + + + Writes a Guid to stream 'writer' as sequence of 8 bytes + + + + + Reads a Guid to stream 'reader' as sequence of 8 bytes and returns it + + + + + Returns a StreamLabel that is the sum of label + offset. + + + + + Returns the difference between two stream labels (currently guarenteed to fit in an int) + + + + + Convenience method for skipping a a certain number of bytes in the stream. + + + + + Like a StreamLabel, a ForwardReference represents a pointer to a location in the stream. + However unlike a StreamLabel, the exact value in the stream does not need to be known at the + time the forward references is written. Instead the ID is written, and later that ID is + associated with the target location (using DefineForwardReference). + + + + + Returned when no appropriate ForwardReference exists. + + + + + #SerializerIntroduction see also #StreamLayout + + The Serializer class is a general purpose object graph serializer helper. While it does not have + any knowledge of the serialization format of individual object, it does impose conventions on how to + serialize support information like the header (which holds versioning information), a trailer (which + holds deferred pointer information), and how types are versioned. However these conventions are + intended to be very generic and thus this class can be used for essentially any serialization need. + + Goals: + * Allows full range of serialization, including subclassing and cyclic object graphs. + * Can be serialized and deserialized efficiently sequentially (no seeks MANDATED on read or + write). This allows the serializer to be used over pipes and other non-seekable devices). + * Pay for play (thus very efficient in simple cases (no subclassing or cyclic graphs). + * Ideally self-describing, and debuggable (output as XML if desired?) + + Versioning: + * We want the ability for new formats to accept old versions if objects wish to support old + formats + * Also wish to allow new formats to be read by OLD version if the new format is just an + 'extension' (data added to end of objects). This makes making new versions almost pain-free. + + Concepts: + * No-seek requirement + + The serialized form should be such that it can be deserialized efficiently in a serial fashion + (no seeks). This means all information needed to deserialize has to be 'just in time' (can't + be some table at the end). Pragmatically this means that type information (needed to create + instances), has to be output on first use, so it is available for the deserializer. + + * Laziness requirement + + While is should be possible to read the serialized for sequentially, we should also not force + it. It should be possible to have a large file that represents a persisted structure that can + be lazily brought into memory on demand. This means that all information needed to + deserialize must also be 'randomly available' and not depend on reading from the beginning. + Pragmatically this means that type information, and forward forwardReference information needs to + have a table in a well known Location at the end so that it can be found without having to + search the file sequentially. + + * Versioning requirement + + To allow OLD code to access NEW formats, it must be the case that the serialized form of + every instance knows how to 'skip' past any new data (even if it does not know its exact + size). To support this, objects have 'begin' and 'end' tags, which allows the deserializer to + skip the next object. + + * Polymorphism requirement + + Because the user of a filed may not know the exact instance stored there, in general objects + need to store the exact type of the instance. Thus they need to store a type identifier, this + can be folded into the 'begin' tag. + + * Arbitrary object graph (circularity) requirement (Forward references) + + The serializer needs to be able to serialize arbitrary object graphs, including those with + cycles in them. While you can do this without forward references, the system is more flexible + if it has the concept of a forward reference. Thus whenever a object reference is required, a + 'forward forwardReference' can be given instead. What gets serialized is simply an unique forward + reference index (index into an array), and at some later time that index is given its true + value. This can either happen with the target object is serialized (see + Serializer.Tags.ForwardDefintion) or at the end of the serialization in a forward + reference table (which allows forward references to be resolved without scanning then entire + file. + + * Contract between objects IFastSerializable.ToStream: + + The heart of the serialization and deserialization process the IFastSerializable + interface, which implements just two methods: ToStream (for serializing an object), and + FromStream (for deserializing and object). This interfaces is the mechanism by which objects + tell the serializer what data to store for an individual instance. However this core is not + enough. An object that implements IFastSerializable must also implement a default + constructor (constructor with no args), so that that deserializer can create the object (and + then call FromStream to populated it). + + The ToStream method is only responsible for serializing the data in the object, and by itself + is not sufficient to serialize an interconnected, polymorphic graph of objects. It needs + help from the Serializer and Deserialize to do this. Serializer takes on the + responsibility to deal with persisting type information (so that Deserialize can create + the correct type before IFastSerializable.FromStream is called). It is also the + serializer's responsibility to provide the mechanism for dealing with circular object graphs + and forward references. + + * Layout of a serialized object: A serialized object has the following basic format + + * If the object is the definition of a previous forward references, then the definition must + begin with a Serializer.Tags.ForwardDefintion tag followed by a forward forwardReference + index which is being defined. + * Serializer.Tags.BeginObject tag + * A reference to the SerializationType for the object. This reference CANNOT be a + forward forwardReference because its value is needed during the deserialization process before + forward references are resolved. + * All the data that that objects 'IFastSerializable.ToStream method wrote. This is the + heart of the deserialized data, and the object itself has a lot of control over this + format. + * Serializer.Tags.EndObject tag. This marks the end of the object. It quickly finds bugs + in ToStream FromStream mismatches, and also allows for V1 deserializers to skip past + additional fields added since V1. + + * Serializing Object references: + When an object forwardReference is serialized, any of the following may follow in the stream + + * Serializer.Tags.NullReference used to encode a null object forwardReference. + * Serializer.Tags.BeginObject or Serializer.Tags.ForwardDefintion, which indicates + that this the first time the target object has been referenced, and the target is being + serialized on the spot. + * Serializer.Tags.ObjectReference which indicates that the target object has already + been serialized and what follows is the StreamLabel of where the definition is. + * Serializer.Tags.ForwardReference followed by a new forward forwardReference index. This + indicates that the object is not yet serialized, but the serializer has chosen not to + immediately serialize the object. Ultimately this object will be defined, but has not + happened yet. + + * Serializing Types: + Types are simply objects of type SerializationType which contain enough information about + the type for the Deserializer to do its work (it full name and version number). They are + serialized just like all other types. The only thing special about it is that references to + types after the BeginObject tag must not be forward references. + + #StreamLayout: + The structure of the file as a whole is simply a list of objects. The first and last objects in + the file are part of the serialization infrastructure. + + Layout Synopsis + * Signature representing Serializer format + * EntryObject (most of the rest of the file) + * BeginObject tag + * Type for This object (which is a object of type SerializationType) + * BeginObject tag + * Type for SerializationType POSITION1 + * BeginObject tag + * Type for SerializationType + * ObjectReference tag // This is how our recursion ends. + * StreamLabel for POSITION1 + * Version Field for SerializationType + * Minimum Version Field for SerializationType + * FullName string for SerializationType + * EndObject tag + * Version field for EntryObject's type + * Minimum Version field for EntryObject's type + * FullName string for EntryObject's type + * EndObject tag + * Field1 + * Field2 + * V2_Field (this should be tagged so that it can be skipped by V1 deserializers. + * EndObject tag + * ForwardReferenceTable pseudo-object + * Count of forward references + * StreamLabel for forward ref 0 + * StreamLabel for forward ref 1. + * ... + * SerializationTrailer pseudo-object + * StreamLabel ForwardReferenceTable + * StreamLabel to SerializationTrailer + * End of stream + + + + + Create a serializer writes 'entryObject' to a file. + + + + + Create a serializer that writes to a . The serializer + will close the stream when it closes. + + + + + Create a serializer that writes to a . The + parameter determines whether the serializer will close the stream when it + closes. + + + + + Create a serializer that writes 'entryObject' another IStreamWriter + + + + + Write a bool to a stream + + + + + Write a byte to a stream + + + + + Write a short to a stream + + + + + Write an int to a stream + + + + + Write a long to a stream + + + + + Write a Guid to a stream + + + + + Write a string to a stream + + + + + Write a float to a stream + + + + + Write a double to a stream + + + + + Write a StreamLabel (pointer to some other part of the stream whose location is current known) to the stream + + + + + Write a ForwardReference (pointer to some other part of the stream that whose location is not currently known) to the stream + + + + + If the object is potentially aliased (multiple references to it), you should write it with this method. + + + + + To tune working set (or disk seeks), or to make the dump of the format more readable, it is + valuable to have control over which of several references to an object will actually cause it to + be serialized (by default the first encountered does it). + + WriteDefered allows you to write just a forwardReference to an object with the expectation that + somewhere later in the serialization process the object will be serialized. If no call to + WriteObject() occurs, then the object is serialized automatically before the stream is closed + (thus dangling references are impossible). + + + + + This is an optimized version of WriteObjectReference that can be used in some cases. + + If the object is not aliased (it has an 'owner' and only that owner has references to it (which + implies its lifetime is strictly less than its owners), then the serialization system does not + need to put the object in the 'interning' table. This saves a space (entries in the intern table + as well as 'SyncEntry' overhead of creating hash codes for object) as well as time (to create + that bookkeeping) for each object that is treated as private (which can add up if because it is + common that many objects are private). The private instances are also marked in the serialized + format so on reading there is a similar bookkeeping savings. + + The ultimate bits written by WritePrivateObject are the same as WriteObject. + + TODO Need a DEBUG mode where we detect if others besides the owner reference the object. + + + + + Create a ForwardReference. At some point before the end of the serialization, DefineForwardReference must be called on this value + + + + + + Define the ForwardReference forwardReference to point at the current write location. + + + + + + Write a byte preceded by a tag that indicates its a byte. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a byte. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a short. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a int. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a long. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a string. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a object. These should be read with the corresponding TryReadTagged operation + + + + + Writes the header for a skipping an arbitrary blob. THus it writes a Blob + tag and the size, and the caller must then write 'sizes' bytes of data in + some way. This allows you to create regions of arbitrary size that can + be skipped by old as well as new parsers. + + + + + + Writes an end tag (which is different from all others). This is useful + when you have a deferred region of tagged items. + + + + + Retrieve the underlying stream we are writing to. Generally the Write* methods are enough. + + + + + Completes the writing of the stream. + + + + + To help debug any serialization issues, you can write data to a side file called 'log.serialize.xml' + which can track exactly what serialization operations occurred. + + + + + Dispose pattern + + + + + Deserializer is a helper class that holds all the information needed to deserialize an object + graph as a whole (things like the table of objects already deserialized, and the list of types in + the object graph. + + see #SerializerIntroduction for more + + + + + Create a Deserializer that reads its data from a given file + + + + + Create a Deserializer that reads its data from a given System.IO.Stream. The stream will be closed when the Deserializer is done with it. + + + + + Create a Deserializer that reads its data from a given System.IO.Stream. The + parameter determines whether the deserializer will close the stream when it + closes. + + + + + Create a Deserializer that reads its data from a given IStreamReader. The stream will be closed when the Deserializer is done with it. + + + + + Returns the full name of the type of the entry object without actually creating it. + Will return null on failure. + + + + + GetEntryObject is the main deserialization entry point. The serialization stream always has an object that represents the stream as + a whole, called the entry object and this returns it and places it in 'ret' + + + + + GetEntryObject is the main deserialization entry point. The serialization stream always has an object that represents the stream as + a whole, called the entry object and this returns it and returns it + + + + + Read a bool from the stream + + + + + Read a byte from the stream + + + + + Read a short from the stream + + + + + Read an int from the stream + + + + + Read a long from the stream + + + + + Read a Guid from the stream + + + + + Read a float from the stream + + + + + Read a double from the stream + + + + + Read a string from the stream. Can represent null + + + + + d) from the stream + + + + + Read a IFastSerializable object from the stream and place it in ret + + + + + Read a IFastSerializable object from the stream and return it + + + + + Read a bool from the stream and return it + + + + + Read a byte from the stream and return it + + + + + Read a short from the stream and return it + + + + + Read an int from the stream and return it + + + + + Read a long from the stream and return it + + + + + Read a float from the stream and return it + + + + + Read a double from the stream and return it + + + + + Read in a string value and return it + + + + + Read in a StreamLabel (a pointer to some other part of the stream) and return it + + + + + Read in a ForwardReference (a pointer to some other part of the stream which was not known at the tie it was written) and return it + Use ResolveForwardReference to convert the ForwardReference to a StreamLabel + + + + + Given a forward reference find the StreamLabel (location in the stream) that it points at). + Normally this call preserves the current read location, but if you do don't care you can + set preserveCurrent as an optimization to make it more efficient. + + + + + Meant to be called from FromStream. It returns the version number of the + type being deserialized. It can be used so that new code can recognizes that it + is reading an old file format and adjust what it reads. + + + + + Meant to be called from FromStream. It returns the version number of the MinimumReaderVersion + of the type that was serialized. + + + + + The filename if read from a file or the stream name if read from a stream + + + + + If set this function is set, then it is called whenever a type name from the serialization + data is encountered. It is your you then need to look that up. If it is not present + it uses Type.GetType(string) which only checks the current assembly and mscorlib. + + + + + For every IFastSerializable object being deserialized, the Deserializer needs to create 'empty' objects + that 'FromStream' is invoked on. The Deserializer gets these 'empty' objects by calling a 'factory' + delegate for that type. Thus all types being deserialized must have a factory. + + RegisterFactory registers such a factory for particular 'type'. + + + + + For every IFastSerializable object being deserialized, the Deserializer needs to create 'empty' objects + that 'FromStream' is invoked on. The Deserializer gets these 'empty' objects by calling a 'factory' + delegate for that type. Thus all types being deserialized must have a factory. + + RegisterDefaultFactory registers a factory that is passed a type parameter and returns a new IFastSerialable object. + + + + + Try to read tagged value from the stream. If it is a tagged bool, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged byte, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged short, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged int, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged long, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged string, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read the header for a tagged blob of bytes. If Current points at a tagged + blob it succeeds and returns the size of the blob (the caller must read or skip + past it manually) If it is not a tagged blob it returns a size of 0 and resets + the read pointer to what it was before this method was called. + + + + + Try to read tagged value from the stream. If it is a tagged FastSerializable, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged FastSerializable, return it, otherwise leave the cursor unchanged and return null + + + + + Set the read position to the given StreamLabel + + + + + Set the read position to the given ForwardReference + + + + + Returns the current read position in the stream. + + + + + Fetch the underlying IStreamReader that the deserializer reads data from + + + + + Close the IStreamReader and free resources associated with the Deserializer + + + + + When we encounter a forward reference, we can either go to the forward reference table immediately and resolve it + (deferForwardReferences == false), or simply remember that that position needs to be fixed up and continue with + the deserialization. This later approach allows 'no seek' deserialization. This variable which scheme we do. + + + + + #DeferedRegionOverview. + + A DeferedRegion help make 'lazy' objects. You will have a DeferedRegion for each block of object you + wish to independently decide whether to deserialize lazily (typically you have one per object however + in the limit you can have one per field, it is up to you). + + When you call DeferedRegion.Write you give it a delegate that will write all the deferred fields. + The Write operation will place a forward reference in the stream that skips all the fields written, + then the fields themselves, then define the forward reference. This allows readers to skip the + deferred fields. + + When you call DeferedRegion.Read you also give it a delegate that reads all the deferred fields. + However when 'Read' instead of reading the fields it + + * remembers the deserializer, stream position, and reading delegate. + * it uses the forward reference to skip the region. + + When DeferedRegion.FinishRead is called, it first checks if the region was already restored. + If not it used the information to read in the deferred region and returns. Thus this FinishRead + should be called before any deferred field is used. + + + + + see #DeferedRegionOverview. + TODO more + + + + + See overview in DeferedRegion class comment. + This call indicates that the 'fromStream' delegate can deserialize a region of the object, which + was serialized with the DeferedRegion.Write method. The read skips the data for the region (thus + no objects associated with the region are created in memory) but the deferred object remembers + 'fromStream' and will call it when 'FinishRead()' is called. + + + + + FinishRead indicates that you need to deserialize the lazy region you defined with the 'Read' method. + If the region has already been deserialized, nothing is done. Otherwise when you call this + method the current position in the stream is put back to where it was when Read was called and the + 'fromStream' delegate registered in 'Read' is called to perform the deserialization. + + + + + Returns true if the FinsihRead() has already been called. + + + + + Get the deserializer assoicated with this DeferredRegion + + + + + Get the stream position when Read was called + + + + + This helper is just here to insure that FinishRead gets inlined + + + + + A type can opt into being serializable by implementing IFastSerializable and a default constructor + (constructor that takes not arguments). + + Conceptually all clients of IFastSerializable also implement IFastSerializableVersion + however the serializer will assume a default implementation of IFastSerializableVersion (that + Returns version 1 and assumes all versions are allowed to deserialize it. + + + + + Given a Serializer, write yourself to the output stream. Conceptually this routine is NOT + responsible for serializing its type information but only its field values. However it is + conceptually responsible for the full transitive closure of its fields. + + * For primitive fields, the choice is easy, simply call Serializer.Write + * For object fields there is a choice + * If is is only references by the enclosing object (eg and therefore field's lifetime is + identical to referencing object), then the Serialize.WritePrivateObject can be + used. This skips placing the object in the interning table (that insures it is written + exactly once). + * Otherwise call Serialize.WriteObject + * For value type fields (or collections of structs), you serialize the component fields. + * For collections, typically you serialize an integer inclusiveCountRet followed by each object. + + + + + + Given a reader, and a 'this' instance, made by calling the default constructor, create a fully + initialized instance of the object from the reader stream. The deserializer provides the extra + state needed to do this for cyclic object graphs. + + Note that it is legal for the instance to cache the deserializer and thus be 'lazy' about when + the actual deserialization happens (thus large persisted strucuture on the disk might stay on the + disk). + + Typically the FromStream implementation is an exact mirror of the ToStream implementation, where + there is a Read() for every Write(). + + + + + Objects implement IFastSerializableVersion to indicate what the current version is for writing + and which readers can read the current version. If this interface is not implemented a default is + provided (assuming version 1 for writing and MinimumVersion = 0). + + By default Serializer.WriteObject will place marks when the object ends and always skip to the + end even if the FromStream did not read all the object data. This allows considerable versioning + flexibility. Simply by placing the new data at the end of the existing serialization, new versions + of the type can be read by OLD deserializers (new fields will have the value determined by the + default constructor (typically 0 or null). This makes is relatively easy to keep MinimumVersion = 0 + (the ideal case). + + + + + This is the version number for the serialization CODE (that is the app decoding the format) + It should be incremented whenever a change is made to IFastSerializable.ToStream and the format + is publicly disseminated. It must not vary from instance to instance. This is pretty straightforward. + It defaults to 0 + + + + + At some point typically you give up allowing new versions of the read to read old wire formats + This is the Minimum version of the serialized data that this reader can deserialize. Trying + to read wire formats strictly smaller (older) than this will fail. Setting this to the current + version indicates that you don't care about ever reading data generated with an older version + of the code. + + If you set this to something other than your current version, you are obligated to insure that + your FromStream() method can handle all formats >= than this number. + + You can achieve this if you simply use the 'WriteTagged' and 'ReadTagged' APIs in your 'ToStream' + and 'FromStream' after your V1 AND you always add new fields to the end of your class. + This is the best practice. Thus + + void IFastSerializable.ToStream(Serializer serializer) + { + serializer.Write(Ver_1_Field1); + serializer.Write(Ver_1_Field2); + // ... + serializer.WriteTagged(Ver_2_Field1); + serializer.WriteTagged(Ver_2_Field2); + // ... + serializer.WriteTagged(Ver_3_Field1); + } + + void IFastSerializable.FromStream(Deserializer deserializer) + { + deserializer.Read(out Ver_1_Field1); + deserializer.Read(out Ver_1_Field2); + // ... + deserializer.TryReadTagged(ref Ver_2_Field1); // If data no present (old format) then Ver_2_Field1 not set. + deserializer.TryReadTagged(ref Ver_2_Field2); // ditto... + // ... + deserializer.TryReadTagged(ref Ver_3_Field1); + } + + Tagging outputs a byte tag in addition to the field itself. If that is a problem you can also use the + VersionBeingRead to find out what format is being read and write code that explicitly handles it. + Note however that this only gets you Backward compatibility (new readers can read the old format, but old readers + will still not be able to read the new format), which is why this is not the preferred method. + + void IFastSerializable.FromStream(Deserializer deserializer) + { + // We assume that MinVersionCanRead == 4 + // Deserialize things that are common to all versions (4 and earlier) + + if (deserializer.VersionBeingRead >= 5) + { + deserializer.Read(AVersion5Field); + if (deserializer.VersionBeingRead >= 5) + deserializer.ReadTagged(AVersion6Field); + } + } + + + + + This is the minimum version of a READER that can read this format. If you don't support forward + compatibility (old readers reading data generated by new readers) then this should be set to + the current version. + + If you set this to something besides the current version you are obligated to insure that your + ToStream() method ONLY adds fields at the end, AND that all of those added fields use the WriteTagged() + operations (which tags the data in a way that old readers can skip even if they don't know what it is) + In addition your FromStream() method must read these with the ReadTagged() deserializer APIs. + + See the comment in front of MinimumVersionCanRead for an example of using the WriteTagged() and ReadTagged() + methods. + + + + + Thrown when the deserializer detects an error. + + + + + Thown when a error occurs in serialization. + + + + + This is the version represents the version of both the reading + code and the version for the format for this type in serialized form. + See IFastSerializableVersion for more. + + + + + The version the the smallest (oldest) reader code that can read + this file format. Readers strictly less than this are rejected. + This allows support for forward compatbility. + See IFastSerializableVersion for more. + + + + + Create a IStreamReader (reads binary data) from a given byte buffer + + + + + Create a IStreamReader (reads binary data) from a given subregion of a byte buffer + + + + + The total length of bytes that this reader can read. + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Dispose pattern + + + + + Dispose pattern + + + + + A MemoryStreamReader is an implementation of the IStreamReader interface that works over a given byte[] array. + + + + + Create a IStreamReader (reads binary data) from a given byte buffer + + + + + Create a IStreamReader (reads binary data) from a given subregion of a byte buffer + + + + + The total length of bytes that this reader can read. + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Dispose pattern + + + + + Dispose pattern + + + + + A StreamWriter is an implementation of the IStreamWriter interface that generates a byte[] array. + + + + + Create IStreamWriter that writes its data to an internal byte[] buffer. It will grow as needed. + Call 'GetReader' to get a IStreamReader for the written bytes. + + Call 'GetBytes' call to get the raw array. Only the first 'Length' bytes are valid + + + + + Returns a IStreamReader that will read the written bytes. You cannot write additional bytes to the stream after making this call. + + + + + + The number of bytes written so far. + + + + + The array that holds the serialized data. + + + + + + Clears any data that was previously written. + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Dispose pattern + + + + + Dispose pattern + + + + + Makespace makes at least sizeof(long) bytes available (or throws OutOfMemory) + + + + + A IOStreamStreamReader hooks a MemoryStreamReader up to an input System.IO.Stream. + + + + + Create a new IOStreamStreamReader from the given file. + + + + + + Create a new IOStreamStreamReader from the given System.IO.Stream. Optionally you can specify the size of the read buffer + The stream will be closed by the IOStreamStreamReader when it is closed. + + + + + close the file or underlying stream and clean up + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of MemoryStreamReader + + + + + Dispose pattern + + + + + Fill the buffer, making sure at least 'minimum' byte are available to read. Throw an exception + if there are not that many bytes. + + + + + + A PinnedStreamReader is an IOStream reader that will pin its read buffer. + This allows it it support a 'GetPointer' API efficiently. The + GetPointer API lets you access data from the stream as raw byte + blobs without having to copy the data. + + + + + Create a new PinnedStreamReader that gets its data from a given file. You can optionally set the size of the read buffer. + + + + + Create a new PinnedStreamReader that gets its data from a given System.IO.Stream. You can optionally set the size of the read buffer. + The stream will be closed by the PinnedStreamReader when it is closed. + + + + + Clone the PinnnedStreamReader so that it reads from the same stream as this one. They will share the same + System.IO.Stream, but each will lock and seek when accessing that stream so they can both safely share it. + + + + + + Get a byte* pointer to the input buffer at 'Position' in the IReadStream that is at least 'length' bytes long. + (thus ptr to ptr+len is valid). Note that length cannot be larger than the buffer size passed to the reader + when it was constructed. + + + + + Get a byte* pointer to the input buffer at the current read position is at least 'length' bytes long. + (thus ptr to ptr+len is valid). Note that length cannot be larger than the buffer size passed to the reader + when it was constructed. + + + + + A IOStreamStreamWriter hooks a MemoryStreamWriter up to an output System.IO.Stream + + + + + Create a IOStreamStreamWriter that writes its data to a given file that it creates + + + + + + Create a IOStreamStreamWriter that writes its data to a System.IO.Stream + + + + + Flush any written data to the underlying System.IO.Stream + + + + + Insures the bytes in the stream are written to the stream and cleans up resources. + + + + + Access the underlying System.IO.Stream. You should avoid using this if at all possible. + + + + + Implementation of the MemoryStreamWriter interface + + + + + Implementation of the IStreamWriter interface + + + + + Implementation of the MemoryStreamWriter interface + + + + + Implementation of the MemoryStreamWriter interface + + + + + Implementation of the MemoryStreamWriter interface + + + + + Dispose pattern + + + + + A cheap version of List(T). The idea is to make it as cheap as if you did it 'by hand' using an array and + an int which represents the logical charCount. It is a struct to avoid an extra pointer dereference, so this + is really meant to be embedded in other structures. + + + + + Create a growable array with the given initial size it will grow as needed. There is also the + default constructor that assumes initialSize of 0 (and does not actually allocate the array. + + + + + + Fetch the element at the given index. Will throw an IndexOutOfRange exception otherwise + + + + + The number of elements in the array + + + + + Remove all elements in the array. + + + + + Add an item at the end of the array, growing as necessary. + + + + + + Add all items 'items' to the end of the array, growing as necessary. + + + + + + Insert 'item' directly at 'index', shifting all items >= index up. 'index' can be code:Count in + which case the item is appended to the end. Larger indexes are not allowed. + + + + + Remove 'count' elements starting at 'index' + + + + + Sets the 'index' element to 'value' growing the array if necessary (filling in default values if necessary). + + + + + Gets the value at 'index'. Never fails, will return 'default' if out of range. + + + + + Returns true if there are no elements in the array. + + + + + Remove the last element added and return it. Will throw if there are no elements. + + + + + + Returns the last element added Will throw if there are no elements. + + + + + Trims the size of the array so that no more than 'maxWaste' slots are wasted. Useful when + you know that the array has stopped growing. + + + + + Returns true if the Growable array was initialized by the default constructor + which has no capacity (and thus will cause growth on the first addition). + This method allows you to lazily set the compacity of your GrowableArray by + testing if it is of EmtpyCapacity, and if so set it to some useful capacity. + This avoids unecessary reallocs to get to a reasonable capacity. + + + + + A string representing the array. Only intended for debugging. + + + + + + Sets 'index' to the the smallest index such that all elements with index > 'idx' are > key. If + index does not match any elements a new element should always be placed AFTER index. Note that this + means that index may be -1 if the new element belongs in the first position. + + Returns true if the return index matched exactly (success) + + TODO FIX NOW harmonize with List.BinarySearch + + + + + Sort the range starting at 'index' of length 'count' using 'comparision' in assending order + + + + + Sort the whole array using 'comparison' in ascending order + + + + + Executes 'func' for each element in the GrowableArray and returns a GrowableArray + for the result. + + + + + Perform a linear search starting at 'startIndex'. If found return true and the index in 'index'. + It is legal that 'startIndex' is greater than the charCount, in which case, the search returns false + immediately. This allows a nice loop to find all items matching a pattern. + + + + + Returns the underlying array. Should not be used most of the time! + + + + + Implementation of foreach protocol + + + + + + Enumerator for foreach interface + + + + + implementation of IEnumerable interface + + + + + implementation of IEnumerable interface + + + + + Segmented list implementation, copied from Microsoft.Exchange.Collections. + + The type of the list element. + + This class implement a list which is allocated in segments, to avoid large lists to go into LOH. + + + + + Constructs SegmentedList. + + Segment size + + + + Constructs SegmentedList. + + Segment size + Initial capacity + + + + Returns the count of elements in the list. + + + + + Copy to Array + + Array copy + + + + Returns the last element on the list and removes it from it. + + The last element that was on the list. + + + + Returns true if this ICollection is read-only. + + + + + Gets or sets the given element in the list. + + Element index. + + + + Necessary if the list is being used as an array since it creates the segments lazily. + + + true if the segment is allocated and false otherwise + + + + Get slot of an element + + + + + + + + Adds new element at the end of the list. + + New element. + + + + Inserts new element at the given position in the list. + + Insert position. + New element to insert. + + + + Removes element at the given position in the list. + + Position of the element to remove. + + + + Performs a binary search in a sorted list. + + Element to search for. + Comparer to use. + Non-negative position of the element if found, negative binary complement of the position of the next element if not found. + The implementation was copied from CLR BinarySearch implementation. + + + + Performs a binary search in a sorted list. + + Element to search for. + The lowest index in which to search. + The highest index in which to search. + Comparer to use. + The index + + + + Sorts the list using default comparer for elements. + + + + + Sorts the list using specified comparer for elements. + + Comparer to use. + + + + Appends a range of elements from anothe list. + + Source list. + Start index in the source list. + Count of elements from the source list to append. + + + + Returns the enumerator. + + + + + Copy to Array + + Array copy + + + + CopyTo copies a collection into an Array, starting at a particular + index into the array. + + Destination array. + Destination array starting index. + + + + Copies the contents of the collection that are within a range into an Array, starting at a particular + index into the array. + + Destination array. + Destination array starting index. + The collection index from where the copying should start. + The collection index where the copying should end. + + + + Returns the enumerator. + + + + + Returns the enumerator. + + + + + Clears the list (removes all elements). + + + + + Check if ICollection contains the given element. + + Element to check. + + + + CopyTo copies a collection into an Array, starting at a particular + index into the array. + + Destination array. + Destination array starting index. + + + + Removes the given element from this ICollection. + + Element to remove. + + + + Shifts the tail of the list to make room for a new inserted element. + + Index of a new inserted element. + + + + Shifts the tail of the list to remove the element. + + Index of the removed element. + + + + Ensures that we have enough capacity for the given number of elements. + + Number of elements. + + + + Helper method for QuickSort. + + Comparer to use. + Position of the first element. + Position of the second element. + + + + QuickSort implementation. + + left boundary. + right boundary. + Comparer to use. + The implementation was copied from CLR QuickSort implementation. + + + + Enumerator over the segmented list. + + + + + Constructws the Enumerator. + + List to enumerate. + + + + Disposes the Enumerator. + + + + + Moves to the nest element in the list. + + True if move successful, false if there are no more elements. + + + + Returns the current element. + + + + + Returns the current element. + + + + + Resets the enumerator to initial state. + + + + diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Microsoft.Diagnostics.Tracing.TraceEvent.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Microsoft.Diagnostics.Tracing.TraceEvent.dll new file mode 100644 index 0000000..5be2124 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Microsoft.Diagnostics.Tracing.TraceEvent.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Microsoft.Diagnostics.Tracing.TraceEvent.xml b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Microsoft.Diagnostics.Tracing.TraceEvent.xml new file mode 100644 index 0000000..f1522a3 --- /dev/null +++ b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/Microsoft.Diagnostics.Tracing.TraceEvent.xml @@ -0,0 +1,13649 @@ + + + + Microsoft.Diagnostics.Tracing.TraceEvent + + + + + BPerf Trace Log (BTL) are files generated by the CPU Samples Collector tool in https://github.com/Microsoft/BPerf + The layout of the file is as follows --> + + Format: + 4 byte integer describing compressed size + 4 byte integer describing uncompressed size + byte[compressed size] + + The byte array is a list of EVENT_RECORDs. Each Event_RECORD is aligned to 16-bytes. + + The EVENT_RECORD is laid out as a memory dump of the structure in memory. All pointers from + the structure are laid out successively in front of the EVENT_RECORD. + + The compression mechanism is using the NTDLL.RtlDecompressBufferEx Express Huffman procedure. + + + + + This constructor is used when the consumer has an offset within the BTL file that it would like to seek to. + + + + + This constructor is used when the consumer is supplying the buffers for reasons like buffer pooling. + + + + + An ActivityComputer is a state machine that track information about Activities. In particular, it can + compute a activity aware call stack. (GetCallStack). + + + + + Construct a new ActivityComputer that will process events from 'eventLog' and output activity - aware stacks to 'outputStackSource'. + + + + + Returns the TraceLog that is associated with the computer (at construction time) + + + + + Fires when an activity is first created (scheduled). The activity exists, and has an ID, but has not run yet. + + + + + First when an activity starts to run (using a thread). It fires after the start has logically happened. + so you are logically in the started activity. + + + + + Fires when the activity ends (no longer using a thread). It fires just BEFORE the task actually dies + (that is you ask the activity of the event being passed to 'Stop' it will still give the passed + activity as the answer). The first TraceActivity is the activity that was stopped, the second + is the activity that exists afer the stop completes. + + + + + Like OnStop but gets called AFTER the stop has completed (thus the current thread's activity has been updated) + The activity may be null, which indicates a failure to look up the activity being stopped (and thus the + thread's activity will be set to null). + + + + + AwaitUnblocks is a specialized form of the 'Start' event that fires when a task starts because + an AWAIT has ended. The start event also fires on awaits end and comes AFTER the AwaitUnblocks + event has been delivered. + + Not every AWAIT end causes a callback. Because an AWAIT begin happens for every FRAME you only + want a callback for the FIRST task (activity) created by parent of this activity. This is what + this callback does. + + AwaitUnblocks are often treated differently because you want to consider the time between the begin + (Activity Created) and awaitUnbock to be accounted for as on the critical path, whereas for 'normal' + tasks you normally don't think that time is interesting. + + + + + Fetches the current activity for 'thread' at the present time (the current event being dispatched). + Never returns null because there is always and activity (it may be the thread task). + This is arguably the main thing that this computer keeps track of. + + + + + Gets the default activity for a thread (the activity a thread is doing when the thread starts). + + + + + Maps an activity index back to its activity. + + + + + Returns a activity-aware call stackIndex associated with'ouputStackSource' for the call stack associated with 'data'. + Such activity-aware call stacks have pseudo-frame every time on thread causes another task to run code (because the + creator 'caused' the target code). + + If 'topFrames' is non-null, then this function is called with a Thread and is expected to return a CallStack index that + represents the thread-and-process nodes of the stack. This allows the returned stack to be have pseudo-frames + at the root of the stack. Typically this is used to represent the 'request' or other 'global' context. If it is not + present the thread and process are used to form these nodes. + + This needs to be a function mapping threads to the stack base rather than just the stack base because in the presence + of activities the thread at the 'base' whose 'top' you want may not be the one that 'data' started with, so the caller + needs to be prepared to answer the question about any thread. + + + + + Returns a StackSource call stack associated with outputStackSource for the activity 'activity' (that is the call stack at the + the time this activity was first created. This stack will have it 'top' defined by topFrames (by default just the thread and process frames) + + + + + This is not a call stack but rather the chain of ACTIVITIES (tasks), and can be formed even when call stacks + + Returns a Stack Source stack associated with outputStackSource where each frame is a task starting with 'activity' and + going back until the activity has no parent (e.g. the Thread's default activity). + + + + + If set, we don't assume that the top top frames are an attribute of the TOP THREAD (if they vary based on + the current activity, then you can't cache. Setting this disables caching. + + + + + Returns true if the call stack is in the thread pool parked (not running user code) + This means that the thread CAN'T be running an active activity and we can kill it. + + + + + This cache remembers Activity * CallStackIndex pairs and the result. + + + + + Remembers the current Activity for 'Get' and 'Put' operations. Needs to be set before Get or Put is called. + + + + + Gets the cache entry for the CurrnetActivityIndex with the call stack 'fromStackIndex' returns Invalid if + there is no entry. + + This is not passed the CurrentActivityIndex, so it can implement the CallStackMap interface + + + + + updates the cache entry for the CurrnetActivityIndex with the call stack 'fromStackIndex' with the value + 'toStackIndex' + + This is not passed the CurrentActivityIndex, so it can implement the CallStackMap interface + + + + + Creation handles ANY creation of a task. + + + + + Activity can be null, which means we could not figure out the activity we are stopping. + + + + + Get a trace wide ID for a TPL event. TPL tasks might be 'Scheduled' in the sense + that it might run independently on another thread. Tasks that do 'BeginWait and 'EndWait' + are not scheduled. The same ID might have both operating simultaneously (if you wait + on a scheduled task). Thus you need an independent ID for both. + + + + + if 'activity' has not creator (it is top-level), then return baseStack (near execution) followed by 'top' representing the thread-process frames. + + otherwise, find the fragment of 'baseStack' up to the point to enters the threadpool (the user code) and splice it to the stack of the creator + of the activity and return that. (thus returning your full user-stack). + + + + + Trims off frames that call ETW logic and return. If the pattern is not matched, we return callStackIndex + + + + + If the stack from 'startStack' (closest to execution) through 'stopStack' is the same as 'baseStack' return a non-invalid frame + indicating that it is recursive and should be dropped. The frame index returned is the name of the task on 'baseStack' that + begins the recursion (so you can update it if necessary) + + + + + Create a stack which is executing at 'startStack' and finds the region until 'stopStack', appending that (in order) to 'baseStack'. + + + + + Returns the point in 'callStackIndex' where the CLR thread pool transitions from + a thread pool worker to the work being done by the threadpool. + + Basically we find the closest to execution (furthest from thread-start) call to a 'Run' method + that shows we are running an independent task. + + + + + Used by TrimETWFrames and FindThreadPoolTransition to find particular frame names and place the information in 'm_methodFlags' + + + + + We look for various well known methods inside the Task library. This array maps method indexes + and returns a bitvector of 'kinds' of methods (Run, Schedule, ScheduleHelper). + + + + + A small number that you can get from the GetReferenceForGCAddress that is + invariant as the GC address moves around during GCs. Because this index + is small it can be used to store information about the GC reference in a + side growable array. + + + + + Indicates that the address is no longer alive. + + + + + This computer will keep track of GC references as they change over time + + + + + Create a new GCRefernece computer from the stream of events 'source'. When 'source' is processed + you can call 'GetReferenceForGCAddress' to get stable ids for GC references. + + + + + + Get a stable ID for a GcAddress. This ID can be compared for object identity. + This only works at the current point in time when scanning the source. + + + + + If you no longer need to track the GC reference, call this function to remove the tracking. + + + + + A EventPipeThreadTimeComputer does a simple simulation of what each thread is doing to create stack events that represent + CPU, blocked time + + + + + Create a new ThreadTimeComputer + + + + + If set we compute thread time using Tasks + + + + + Track additional info on like EventName or so. + Default to true to keep backward compatibility. + + + + + Use start-stop activities as the grouping construct. + + + + + Generate the thread time stacks, outputting to 'stackSource'. + + + Optional filtered trace events. + + + + Updates it so that 'thread' is now working on newStartStop, which can be null which means that it is not working on any + start-stop task. + + + + + This can actually be called with any event that has a stack. Basically it will log a CPU sample whose + size is the time between the last such call and the current one. + + + + + Get the call stack for 'data' Note that you thread must be data.Thread(). We pass it just to save the lookup. + + + + + Returns a function that figures out the top (closest to stack root) frames for an event. Often + this returns null which means 'use the normal thread-process frames'. + Normally this stack is for the current time, but if 'getAtCreationTime' is true, it will compute the + stack at the time that the current activity was CREATED rather than the current time. This works + better for await time. + + + + + Represents all the information that we need to track for each thread. + + + + + Used to create UNKNOWN frames for start-stop activities. This is indexed by StartStopActivityIndex. + and for each start-stop activity indicates when unknown time starts. However if that activity still + has known activities associated with it then the number will be negative, and its value is the + ref-count of known activities (thus when it falls to 0, it we set it to the start of unknown time. + This is indexed by the TOP-MOST start-stop activity. + + + + + maps thread ID to the current TOP-MOST start-stop activity running on that thread. Used to updated m_unknownTimeStartMsec + to figure out when to put in UNKNOWN_ASYNC nodes. + + + + + Sadly, with AWAIT nodes might come into existance AFTER we would have normally identified + a region as having no thread/await working on it. Thus you have to be able to 'undo' ASYNC_UNKONWN + nodes. We solve this by remembering all of our ASYNC_UNKNOWN nodes on a list (basically provisional) + and only add them when the start-stop activity dies (when we know there can't be another AWAIT. + Note that we only care about TOP-MOST activities. + + + + + Calculates stacks grouping them by the server request (e.g. ASP.NET) request they are for) + + + + + Create a new ServerRequest Computer. + + + + + The server request that we currently processing + + + + + A ServerRequest contains all the information we know about a server request (e.g. ASP.NET request) + + + + + Any URL associated with the request + + + + + If the request has a GUID associated with it to uniquely identify it, this is it + + + + + The time that the request started (or the earliest that we know about it) + + + + + Calculates start-stop activities (computes duration), It uses the 'standard' mechanism of using + ActivityIDs to corelate the start and stop (and any other events between the start and stop, + and use the RelatedActivityID on START events to indicate the creator of the activity, so you can + form nested start-stop activities. + + + + + Create a new ServerRequest Computer. + + + + + The current start-stop activity on the given thread. + If present 'context' is used to look up the current activityID and try to use that to repair missing Starts. + Basically if we can't figure out what StartStop activity the thread from just the threadID we can use the activityID + from the 'context' event to find it as a backup. + + + + + Gets the current Start-Stop activity for a given TraceActivity. + + + + + + + Returns a stack index representing the nesting of Start-Stop activities for the thread 'curThread' at the current time + (At this point of the current event for the computer). The stack starts with a frame for the process of the thread, then + has all the start-stop activity frames, then a frame representing 'topThread' which may not be the same as 'thread' since + 'topThread' is the thread that spawned the first task, not the currently executing thread. + + Normally this stack is for the current time, but if 'getAtCreationTime' is true, it will compute the + stack at the time that the current activity was CREATED rather than the current time. This works + better for await time + + + + + Gets a stack that represents the nesting of the Start-Stop tasks. curActivity can be null, in which case just he process node is returned. + + + + + If set, called AFTER a Start-Stop activity starts, called with the activity and the event that caused the start. + + + + + If set, called BEFORE a Start-Stop activity stops, called with the activity and the event that caused the start. + + + + + Returns true if 'guid' follow the EventSouce style activity ID for the process with ID processID. + You can pass a process ID of 0 to this routine and it will do the best it can, but the possibility + of error is significantly higher (but still under .1%) + + + + + Assuming guid is an Activity Path, extract the process ID from it. + + + + + returns a string representation for the activity path. If the GUID is not an activity path then it returns + the normal string representation for a GUID. + + + + + We don't do a stop all processing associated with the stop event is done. Thus if we are not 'on' + the stop event, then you can do any deferred processing. + + + + + Try to process some predefined DiagnosticSource ("Microsoft.EntityFrameworkCore.BeforeExecuteCommand" and "Microsoft.AspNetCore.Hosting.BeginRequest") start events. + This will try to filter the events by "EventName", if failed it will return false without any further processing. + + Whether or not succeeded in processing the event + + + + fix ASP.NET receiving events + + + + + Look up a start-stop activity by its ID. Note that the 'activityID' needs to be unique for that instance + within a process. (across ALL start-stop activities, which means it may need components that encode its + provider and task). We pass the process ID as well so that it will be unique in the whole trace. + + + + + The encoding for a list of numbers used to make Activity Guids. Basically + we operate on nibbles (which are nice because they show up as hex digits). The + list is ended with a end nibble (0) and depending on the nibble value (Below) + the value is either encoded into nibble itself or it can spill over into the + bytes that follow. + + + + + An dense number that defines the identity of a StartStopActivity. Used to create side arrays + for StartStopActivity info. + + + + + An illegal index, sutable for a sentinal. + + + + + A StartStop reresents an activity between a start and stop event as generated by EvetSource. + + + + + The index (small dense numbers suitabilty for array indexing) for this activity. + + + + + The name of the activity (The Task name for the start-stop event as well as the activity ID) + + + + + Known Activity Type + + + + + If the activity has additional information associated with it (e.g. a URL), put it here. Can be null. + + + + + The Task name (the name prefix that is common to both the start and stop event) + + + + + The processID associated with this activity + + + + + The Activity ID (as a GUID) that matches the start and stop together. + + + + + The path of creators that created this activity. + + + + + The start-stop activity that created this activity (thus it makes a tree) + + + + + The TraceLog event Index, of the start event (you can get addition info) + + + + + The TraceLog event Index, of the stop event (you can get addition info) + + + + + The time in MSec from the start of the trace when the start event happened. + + + + + The duration of activity in MSec (diff between stop and start) + + + + + This activity has completed (the Stop event has been received). Thus Duration is valid. + + + + + Returns a stack on the outputStackSource which has a frame for each activity that + caused this activity, as well as the root of the given 'rootStack' (often a stack representing the process). + + + + + override. Gives the name and start time. + + + + + We don't update the state for the stop at the time of the stop, but at the next call to any of the StartStopActivityComputer APIs. + + + + + A TcpIpComputer keeps track of TCP/IP connections so that you can correlate individual reads and + writes with the connection info (like the IP address of each end), as well as data packets being + sent (if you have packet capture turned on). + + + + + Create a new GCRefernece computer from the stream of events 'source'. When 'source' is processed + you can call 'GetReferenceForGCAddress' to get stable ids for GC references. + + + + + + A ThreadTimeComputer does a simple simulation of what each thread is doing to create stack events that represent + CPU, blocked time, disk and Network activity. + + + + + Create a new ThreadTimeComputer + + + + + If set we compute thread time using Tasks + + + + + Track additional info on like EventName or so. + Default to true to keep backward compatibility. + + + + + If set we compute blocked time + + + + + If set we don't show ready thread information + + + + + If set we group by ASP.NET Request + + + + + If we spend less then this amount of time waiting for the CPU, don't bother showing it. + + + + + LIke the GroupByAspNetRequest but use start-stop activities instead of ASP.NET Requests as the grouping construct. + + + + + Don't show AwaitTime. For CPU only traces showing await time is misleading since + blocked time will not show up. + + + + + Generate the thread time stacks, outputting to 'stackSource'. + + + Optional filtered trace events. + + + + Updates it so that 'thread' is now working on newStartStop, which can be null which means that it is not working on any + start-stop task. + + + + + This can actually be called with any event that has a stack. Basically it will log a CPU sample whose + size is the time between the last such call and the current one. + + + + + Get the call stack for 'data' Note that you thread must be data.Thread(). We pass it just to save the lookup. + + + + + Returns a function that figures out the top (closest to stack root) frames for an event. Often + this returns null which means 'use the normal thread-process frames'. + Normally this stack is for the current time, but if 'getAtCreationTime' is true, it will compute the + stack at the time that the current activity was CREATED rather than the current time. This works + better for await time. + + + + + Represents all the information that we need to track for each thread. + + + + + Given and activity, return the ASP.NET Guid associated with it (or Guid.Empty if there is not one). + + + + + + Computes the ASP.NET Pseudo frames from the process frame through the thread frame (which includes all + the pseudo-frames for the ASP.NET groupings. + + + + + Indicates that the aspNet request represented by aspNetGuid is now being handled by the thread with index + newThreadIndex. Thus any old threads handling this request are 'cleared' and replaced with 'newThreadIndex' + If 'newThreadIndex == Invalid then the entry for aspNetGuid is removed. + + + + + Generate a stack that from the root looks like 'stackIndex followed by 'READIED BY TID(XXXX)' + followed by frames of 'readyThreadCallStack' (suffixed by READIED_BY) + + + + + NetworkInfo remembers useful information to tag blocked time that seems to be network related. + It is the value of the m_lastPacketForProcess table mapping threads to network information. + + + + + AspNetRequestInfo remembers everything we care about associate with an single ASP.NET request. + It is the value of the m_aspNetRequestInfo table. + + + + + Used to create UNKNOWN frames for start-stop activities. This is indexed by StartStopActivityIndex. + and for each start-stop activity indicates when unknown time starts. However if that activity still + has known activities associated with it then the number will be negative, and its value is the + ref-count of known activities (thus when it falls to 0, it we set it to the start of unknown time. + This is indexed by the TOP-MOST start-stop activity. + + + + + maps thread ID to the current TOP-MOST start-stop activity running on that thread. Used to updated m_unknownTimeStartMsec + to figure out when to put in UNKNOWN_ASYNC nodes. + + + + + Sadly, with AWAIT nodes might come into existance AFTER we would have normally identified + a region as having no thread/await working on it. Thus you have to be able to 'undo' ASYNC_UNKONWN + nodes. We solve this by remembering all of our ASYNC_UNKNOWN nodes on a list (basically provisional) + and only add them when the start-stop activity dies (when we know there can't be another AWAIT. + Note that we only care about TOP-MOST activities. + + + + + m_IRPToThread maps the I/O request to the thread that initiated it. This way we can associate + the disk read size and file with the thread that asked for it. + + + + + Maps processor number to the OS threadID of the thread that is using it. Allows you + to determine how (CPU) idle the machine is. + + + + + Using m_threadIDUsingProc, we compute how many processor are current doing nothing + + + + + Returns the TraceLog that is associated with the computer (at construction time) + + + + + Extension methods to enable TraceManagedProcess + + + + + Extension properties for TraceProcess that include necessary .NET values + + TODO This implementation is poor at idenitfying the ParentPID, 64bitness, and Start/End times + + + + + Returns the textual version of the .NET Framework + + + + + Returns the .NET startup flags + + + + + Date and time of when the runtime was built + This is useful when a more detailed version is not present + + + + + Garbage Collector (GC) specific details about this process + + + + + Fired on the start of a GC + + + + + Fired at the end of tha GC. Given the nature of the GC, it is possible that multiple GCs will be inflight at the same time. + + + + + Just-in-time compilation (JIT) specific details about this process + + + + + Fired when a managed method is starting to compile (jit) + + + + + Fired when a managed method is done compiling (jitting). Given the nature of the JIT, it is possible that multiple methods will be compiled at the same time. + + + + + An XML representation of the TraceEventProcess (for debugging) + + + + + Gathers relevant details about the processes in the event source + + + + + + Garbage Collector (GC) specific details about this process + + + + + Process view of GC statistics + + + + + Process view of GC generational statistics + + + + + Process view of all GCs + + + + + Just-in-time compilation (JIT) specific details about this process + + + + + Process view of JIT statistics + + + + + Process view of all methods jitted + + + + + + + + + + Primary GC information + + + + + Type of the GC, eg. NonConcurrent, Background or Foreground + + + + + Reason for the GC, eg. exhausted small heap, etc. + + + + + Generation of the heap collected. If you compare Generation at the start and stop GC events they may differ. + + + + + Time relative to the start of the trace. Useful for ordering + + + + + Duration of the GC, excluding the suspension time + + + + + Duration the EE suspended the process + + + + + Time the EE took to suspend all the threads + + + + + Percentage time the GC took compared to the process lifetime + + + + + The number of CPU samples gathered for the lifetime of this process + + + + + The number of CPU samples gathered during a GC + + + + + Mark time information per heap. Key is the heap number + + + + + Time since the last EE restart + + + + + Realtive time to the trace of when the GC pause began + + + + + Marks if the GC is in a completed state + + + + + Server GC histories + + + + + Amount of memory allocated since last GC. Requires GCAllocationTicks enabled. The + data is split into small and large heaps + + + + + Number of heaps. -1 is the default + + + + + Calculate the size of all pinned objects + + + + + + Percentage of the pinned objects created by the user + + + + + + Total time taken by the GC + + + + + + Friendly GC name including type, reason and generation + + + + + Heap size after GC (mb) + + + + + Amount of memory promoted with GC (mb) + + + + + Memory survival percentage by generation + + + + + + + Heap size by generation after GC (mb) + + + + + + + Heap fragmentation by generation (mb) + + + + + + + Percentage of heap fragmented by generation + + + + + + + Amount of memory at the start of the GC by generation (mb) + + + + + + + Amount of memory after the gc by generation (mb) + + + + + + + Memory promoted by generation (mb) + Note that in 4.0 TotalPromotedSize is not entirely accurate (since it doesn't + count the pins that got demoted. We could consider using the PerHeap event data + to compute the accurate promoted size. + In 4.5 this is accurate. + + + + + + + Heap budget by generation (mb) + + + + + + + Object size by generation after GC (mb) + + + + + + + Heap condemned reasons by GC + + + + + Identify the first and greatest condemned heap + + + + + + Indicates that the GC has low ephemeral space + + + + + + Indicates that the GC was not compacting + + + + + + Returns the condemned reason for this heap + + + + + + Per heap statistics + + + + + Sum of the pinned plug sizes + + + + + Sum of the user created pinned plug sizes + + + + + Per heap statstics + + + + + Large object heap wait threads + + + + + Process heap statistics + + + + + Free list efficiency statistics + + + + + Memory allocated since last GC (mb) + + + + + Ratio of heap size before and after + + + + + Ratio of allocations since last GC over time executed + + + + + Peak heap size before GCs (mb) + + + + + Per generation view of user allocated data + + + + + Heap size before gc (mb) + + + + + Per generation view of heap sizes before GC (mb) + + + + + This represents the percentage time spent paused for this GC since the last GC completed. + + + + + Get what's allocated into gen0 or gen3. For server GC this gets the total for + all heaps. + + + + + For a given heap, get what's allocated into gen0 or gen3. + We calculate this differently on 4.0, 4.5 Beta and 4.5 RC+. + The caveat with 4.0 and 4.5 Beta is that when survival rate is 0, + We don't know how to calculate the allocated - so we just use the + last GC's budget (We should indicate this in the tool) + + + + + Legacy properties that need to be refactored and removed + + + + + Condemned reasons are organized into the following groups. + Each group corresponds to one or more reasons. + Groups are organized in the way that they mean something to users. + + + + + Background GC allocation information + + + + + Span of thread work recorded by CSwitch or CPU Sample Profile events + + + + + Reason for an induced GC + + + + + CondemnedReason + + + + + Heap condemned reason + + + + + This records which reasons are used and the value. Since the biggest value + we need to record is the generation number a byte is sufficient. + + + + + Container for mark times + + + + + Per heap statistics + + + + + Process heap statistics + + + + + Per heap stastics + + + + + Approximations we do in this function for V4_5 and prior: + On 4.0 we didn't seperate free list from free obj, so we just use fragmentation (which is the sum) + as an approximation. This makes the efficiency value a bit larger than it actually is. + We don't actually update in for the older gen - this means we only know the out for the younger + gen which isn't necessarily all allocated into the older gen. So we could see cases where the + out is > 0, yet the older gen's free list doesn't change. Using the younger gen's out as an + approximation makes the efficiency value larger than it actually is. + + For V4_6 this requires no approximation. + + + + + + + Statistical garbage collector (GC) information about a managed process + + + + + Number of GC's for this process + + + + + Number of GC's which were induced, eg. GC.Collect, etc. + + + + + Total size of the pinned objects seen at collection time + + + + + Of all the memory that is current pinned, how much of it is from pinned objects + + + + + Number of GC's that contained pinned objects + + + + + Number of GC's that contained pin plugs + + + + + The longest pause duration (ms) + + + + + Avarege pause duration (ms) + + + + + Average heap size after a GC (mb) + + + + + Average peak heap size (mb) + + + + + Average exclusive cpu samples (ms) during GC's + + + + + Total GC pause time (ms) + + + + + Max suspend duration (ms), should be very small + + + + + Max peak heap size (mb) + + + + + Max allocation per second (mb/sec) + + + + + Total allocations in the process lifetime (mb) + + + + + Total exclusive cpu samples (ms) + + + + + Total memory promoted between generations (mb) + + + + + (obsolete) Total size of heaps after GC'ss (mb) + + + + + (obsolete) Total peak heap sizes (mb) + + + + + Indication if this process is interesting from a GC pov + + + + + List of finalizer objects + + + + + Percentage of time spent paused as compared to the process lifetime + + + + + + Running time of the process. Measured as time spent between first and last GC event observed + + + + + Means it detected that the ETW information is in a format it does not understand. + + + + + Indicator of if ServerGC is enabled (1). -1 indicates that not enough events have been processed to know for sure. + We don't necessarily have the GCSettings event (only fired at the beginning if we attach) + So we have to detect whether we are running server GC or not. + Till we get our first GlobalHeapHistory event which indicates whether we use server GC + or not this remains -1. + + + + + Number of heaps. -1 indicates that not enough events have been processed to know for sure. + + + + + Indicator if PerHeapHistories is present + + + + + Process statistics about JIT'd code + + + + + Number of JITT'd methods + + + + + Total cpu samples for this process + + + + + Number of methods JITT'd by foreground threads just prior to execution + + + + + Total time spent compiling methods on foreground threads + + + + + Number of methods JITT'd by the multicore JIT background threads + + + + + Total time spent compiling methods on background threads for multicore JIT + + + + + Number of methods JITT'd by the tiered compilation background threads + + + + + Total time spent compiling methods on background threads for tiered compilation + + + + + Total IL size for all JITT'd methods + + + + + Total native code size for all JITT'd methods + + + + + Indication if this is running on .NET 4.x+ + + + + + Indicates if this process has sufficient JIT activity to be interesting + + + + + Background JIT: Time Jit was aborted (ms) + + + + + Background JIT: Assembly name of last assembly loaded before JIT aborted + + + + + Background JIT: Relative start time of last assembly loaded before JIT aborted + + + + + Background JIT: Indication if the last assembly load was successful before JIT aborted + + + + + Background JIT: Thread id of the background JIT + + + + + Background JIT: Indication that background JIT events are enabled + + + + + List of successfully inlinded methods + + + + + List of failed inlined methods + + + + + Modules encountered while processing managed samples + + + + + List of modules whose symbols were not successfully loaded + + + + + Aggregate a method to be included in the statistics + + + + + + Legacgy + + + + + Uniquely represents a method within a process. + Used as a lookup key for data structures. + + + + + JIT inlining successes + + + + + JIT inlining failures + + + + + Per method information + + + + + Time taken to compile the method + + + + + IL size of method + + + + + Native code size of method + + + + + Relative start time of JIT'd method + + + + + Method name + + + + + Module name + + + + + Thread id where JIT'd + + + + + Indication of if it was JIT'd in the background + + + + + Indication of if it was JIT'd in the background and why + + + + + Amount of time the method was forcasted to JIT + + + + + Indication of if the background JIT request was blocked and why + + + + + Number of cpu samples for this method + + + + + The version id that is created by the runtime code versioning feature. This is an incrementing counter that starts at 0 for each method. + The ETW events historically name this as the ReJITID event parameter in the payload, but we have now co-opted its usage. + + + + + Legacy + + + + + TraceProcess Extension methods + + + + + Each process is given a unique index from 0 to TraceProcesses.Count-1 and unlike + the OS Process ID, is unambiguous (The OS process ID can be reused after a + process dies). ProcessIndex represents this index. By using an enum rather than an int + it allows stronger typing and reduces the potential for errors. + + It is expected that users of this library might keep arrays of size TraceProcesses.Count to store + additional data associated with a process in the trace. + + + + + + Returned when no appropriate Process exists. + + + + + A TraceProcesses instance represents the list of processes in the Event log. + + TraceProcesses are IEnumerable, and will return the processes in order of creation time. + + This is a copy of the reduced code from TraceLog!TraceProcesses (removal of elements that + depend on TraceLog - there is a lot of them) + + + + + The log associated with this collection of processes. + + + + + The count of the number of TraceProcess instances in the TraceProcesses list. + + + + + Each process that occurs in the log is given a unique index (which unlike the PID is unique), that + ranges from 0 to Count - 1. Return the TraceProcess for the given index. + + + + + An XML representation of the TraceEventProcesses (for debugging) + + + + + Enumerate all the processes that occurred in the trace log, ordered by creation time. + + + + + Given an OS process ID and a time, return the last TraceProcess that has the same process ID, + and whose offset start time is less than 'timeQPC'. If 'timeQPC' is during the thread's lifetime this + is guaranteed to be the correct process. Using timeQPC = TraceLog.sessionEndTimeQPC will return the + last process with the given PID, even if it had died. + + + + + TraceProcesses represents the entire ETL moduleFile log. At the node level it is organized by threads. + + The TraceProcesses also is where we put various caches that are independent of the process involved. + These include a cache for TraceModuleFile that represent native images that can be loaded into a + process, as well as the process lookup tables and a cache that remembers the last calls to + GetNameForAddress(). + + + + + A step towards a refactored TraceProcess that will move down the dependcy chain from + TraceLog to Source. This is only the portion of TraceProcess that is needed for ManagedProcess + to exist. Also note, that the surface area is intended to match 100% with + Microsoft.Diagnostics.Tracing.Etlx.TraceProcess. The namespace change is intention to avoid + collision of the name and to indicate that it is moving down the depdnency chain. + + This is a slightly modified copy of the code from TraceLog!TraceProcess + + + + + The OS process ID associated with the process. It is NOT unique across the whole log. Use + ProcessIndex for that. + + + + + The index into the logical array of TraceProcesses for this process. Unlike ProcessID (which + may be reused after the process dies, the process index is unique in the log. + + + + + This is a short name for the process. It is the image file name without the path or suffix. + + + + + The command line that started the process (may be empty string if unknown) + + + + + The path name of the EXE that started the process (may be empty string if unknown) + + + + + The time when the process started. Returns the time the trace started if the process existed when the trace started. + + + + + The time when the process started. Returns the time the trace started if the process existed when the trace started. + Returned as the number of MSec from the beginning of the trace. + + + + + The time when the process ended. Returns the time the trace ended if the process existed when the trace ended. + Returned as a DateTime + + + + + The time when the process ended. Returns the time the trace ended if the process existed when the trace ended. + Returned as the number of MSec from the beginning of the trace. + + + + + The process ID of the parent process + + + + + The process that started this process. Returns null if unknown. + + + + + If the process exited, the exit status of the process. Otherwise null. + + + + + The amount of CPU time spent in this process based on the kernel CPU sampling events. + + + + + Returns true if the process is a 64 bit process + + + + + The log file associated with the process. + + + + + Peak working set + + + + + Peak virtual size + + + + + A list of all the threads that occurred in this process. + + + + + Returns the list of modules that were loaded by the process. The modules may be managed or + native, and include native modules that were loaded event before the trace started. + + + + + Filters events to only those for a particular process. + + + + + Filters events to only that occurred during the time the process was alive. + + + + + + An XML representation of the TraceEventProcess (for debugging) + + + + + Dummy stubs so Microsoft.Diagnostics.Tracing.Etlx namespace is not necessary + + + + + The parsed metadata. + + + + + Information about the trace itself. + + + + + Information about a single stream in the trace. + + + + + The environment the trace was taken in. + + + + + A clock definition in the trace. + + + + + A definition of an event. + + + + + A manual parser for CtfMetadata. Eventually this should be replaced when CtfMetadata no longer + uses a custom, BNF style format. + + + + + The abstract metadata parser class. + + + + + The types that may be declared in CtfMetatdata. + + + + + This class represents the top level entry + + + + + A simple class to make parsing out properties easier. + + + + + Represents a type which has been referenced by name, but has not yet been resolved to a concrete type. + + + + + A DynamicTraceEventParser is a parser that understands how to read the embedded manifests that occur in the + dataStream (System.Diagnostics.Tracing.EventSources do this). + + See also TDHDynamicTraceEventParser which knows how to read the manifest that are registered globally with + the machine. + + + + + The event ID for the EventSource manifest emission event. + + + + + Create a new DynamicTraceEventParser (which can parse ETW providers that dump their manifests + to the ETW data stream) an attach it to the ETW data stream 'source'. + + + + + Returns a list of providers (their manifest) that this TraceParser knows about. + + + + + Given a manifest describing the provider add its information to the parser. + + + + + Utility method that stores all the manifests known to the DynamicTraceEventParser to the directory 'directoryPath' + + + + + Utility method that read all the manifests the directory 'directoryPath' into the parser. + Manifests must end in a .man or .manifest.xml suffix. It will throw an error if + the manifest is incorrect or using unsupported options. + + + + + Override. + + + + + This event, will be fired any time a new Provider is added to the table + of ETW providers known to this DynamicTraceEventParser. This includes + when the EventSource manifest events are encountered as well as any + explicit calls to AddDynamicProvider. (including ReadAllManifests). + + The Parser will filter out duplicate manifest events, however if an + old version of a provider's manifest is encountered, and later a newer + version is encountered, you can receive this event more than once for + a single provider. + + + + + override + + + + + Called on unhandled events to look for manifests. Returns true if we added a new manifest (which may have updated the lookup table) + + + + + Override + + + + + DynamicTraceEventData is an event that knows how to take runtime information to parse event fields (and payload) + + This meta-data is distilled down to a array of field names and an array of PayloadFetches which contain enough + information to find the field data in the payload blob. This meta-data is used in the + DynamicTraceEventData.PayloadNames and DynamicTraceEventData.PayloadValue methods. + + + + + Implements TraceEvent interface + + + + + Implements TraceEvent interface + + + + + Implements TraceEvent interface + + + + + Used by PayloadValue to represent a structure. It is basically a IDictionary with a ToString() that + returns the value as JSON. + + + + + Uses C style conventions to quote a string 'value' and append to the string builder 'sb'. + Thus all \ are turned into \\ and all " into \" + + + + + Implements TraceEvent interface + + + + + Implements TraceEvent interface + + + + + Returns the count of elements for the array represented by 'arrayInfo' + It also will adjust 'offset' so that it points at the beginning of the + array data (skips past the count). + + + + + Constructor for normal types, (int, string) ...) Also handles Enums (which are ints with a map) + + + + + Initialized a PayloadFetch for a given inType. REturns Size = DynamicTraceEventData.UNKNOWN_SIZE + if the type is unknown. + + + + + Returns a payload fetch for a Array. If you know the count, then you can give it. + + + + + Offset from the beginning of the struct. + + + + + LazyMap allow out to set a function that returns a map + instead of the map itself. This will be evaluated when the map + is fetched (which gives time for the map table to be populated. + + + + + This class is only used to pretty-print the manifest event itself. It is pretty special purpose + + + + + DynamicTraceEventParserState represents the state of a DynamicTraceEventParser that needs to be + serialized to a log file. It does NOT include information about what events are chosen but DOES contain + any other necessary information that came from the ETL data file. + + + + + A ProviderManifest represents the XML manifest associated with the provider. + + + + + Read a ProviderManifest from a stream + + + + + Read a ProviderManifest from a file. + + + + + Normally ProviderManifest will fail silently if there is a problem with the manifest. If + you want to see this error you can all this method to force it explicitly It will + throw if there is a problem parsing the manifest. + + + + + Writes the manifest to 'outputStream' (as UTF8 XML text) + + + + + Writes the manifest to a file 'filePath' (as a UTF8 XML) + + + + + + Set if this manifest came from the ETL data stream file. + + + + + The name of the ETW provider + + + + + The GUID that uniquey identifies the ETW provider + + + + + The version is defined as the sum of all the version numbers of event version numbers + the number of events defined. + This has the property that if you follow correct versioning protocol (all versions for a linear sequence where a new + versions is only modifies is predecessor by adding new events or INCREASING the version numbers of existing events) + then the version number defined below will always strictly increase. + + It turns out that .NET Core removed some events from the TplEtwProvider. To allow removal of truly old events + we also add 100* the largest event ID defined to the version number. That way if you add new events, even if you + removes some (less than 100) it will consider your 'better'. + + + + + This is an arbitrary id given when the Manifest is created that + identifies where the manifest came from (e.g. a file name or an event etc). + + + + + Returns true if the current manifest is better to use than 'otherManifest' A manifest is + better if it has a larger version number OR, they have the same version number and it is + physically larger (we assume what happened is people added more properties but did not + update the version field appropriately). + + + + + Retrieve manifest as one big string. Mostly for debugging + + + + + Retrieve the manifest as XML + + + + + For debugging + + + + + Call 'callback the the parsed templates for this provider. If 'callback' returns RejectProvider, bail early + Note that the DynamicTraceEventData passed to the delegate needs to be cloned if you use subscribe to it. + + + + + Returns the .NET type corresponding to the manifest type 'manifestTypeName' + Returns null if it could not be found. + + + + + Initialize the provider. This means to advance the instance variable 'reader' until it it is at the 'provider' node + in the XML. It also has the side effect of setting the name and guid. The rest waits until events are registered. + + + + + Keywords are passed to TraceEventSession.EnableProvider to enable particular sets of + + + + + Logging when garbage collections and finalization happen. + + + + + Events when GC handles are set or destroyed. + + + + + Logging when modules actually get loaded and unloaded. + + + + + Logging when Just in time (JIT) compilation occurs. + + + + + Logging when precompiled native (NGEN) images are loaded. + + + + + Indicates that on attach or module load , a rundown of all existing methods should be done + + + + + Indicates that on detach or process shutdown, a rundown of all existing methods should be done + + + + + Events associated with validating security restrictions. + + + + + Events for logging resource consumption on an app-domain level granularity + + + + + Logging of the internal workings of the Just In Time compiler. This is fairly verbose. + It details decisions about interesting optimization (like inlining and tail call) + + + + + Log information about code thunks that transition between managed and unmanaged code. + + + + + Log when lock contention occurs. (Monitor.Enters actually blocks) + + + + + Log exception processing. + + + + + Log events associated with the threadpool, and other threading events. + + + + + Dump the native to IL mapping of any method that is JIT compiled. (V4.5 runtimes and above). + + + + + If enabled will suppress the rundown of NGEN events on V4.0 runtime (has no effect on Pre-V4.0 runtimes). + + + + + Enables the 'BulkType' event + + + + + Enables the events associated with dumping the GC heap + + + + + Enables allocation sampling with the 'fast'. Sample to limit to 100 allocations per second per type. + This is good for most detailed performance investigations. Note that this DOES update the allocation + path to be slower and only works if the process start with this on. + + + + + Enables events associate with object movement or survival with each GC. + + + + + Triggers a GC. Can pass a 64 bit value that will be logged with the GC Start event so you know which GC you actually triggered. + + + + + Indicates that you want type names looked up and put into the events (not just meta-data tokens). + + + + + Enables allocation sampling with the 'slow' rate, Sample to limit to 5 allocations per second per type. + This is reasonable for monitoring. Note that this DOES update the allocation path to be slower + and only works if the process start with this on. + + + + + Turns on capturing the stack and type of object allocation made by the .NET Runtime. This is only + supported after V4.5.3 (Late 2014) This can be very verbose and you should seriously using GCSampledObjectAllocationHigh + instead (and GCSampledObjectAllocationLow for production scenarios). + + + + + This suppresses NGEN events on V4.0 (where you have NGEN PDBs), but not on V2.0 (which does not know about this + bit and also does not have NGEN PDBS). + + + + + TODO document + + + + + Also log the stack trace of events for which this is valuable. + + + + + This allows tracing work item transfer events (thread pool enqueue/dequeue/ioenqueue/iodequeue/a.o.) + + + + + .NET Debugger events + + + + + Events intended for monitoring on an ongoing basis. + + + + + Events that will dump PDBs of dynamically generated assemblies to the ETW stream. + + + + + Recommend default flags (good compromise on verbosity). + + + + + What is needed to get symbols for JIT compiled code. + + + + + This provides the flags commonly needed to take a heap .NET Heap snapshot with ETW. + + + + + Fetch the state object associated with this parser and cast it to + the ClrTraceEventParserState type. This state object contains any + informtion that you need from one event to another to decode events. + (typically ID->Name tables). + + + + + Note that this field is derived from teh TotalPromotedSize* fields. If nothing was promoted, it is possible + that this could give a number that is smaller than what GC/Start or GC/Stop would indicate. + + + + + Returns the edge at the given zero-based index (index less than Count). The returned BulkTypeValues + points the the data in GCBulkRootEdgeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the BulkTypeTraceData. It can only be used as long as + the BulkTypeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + On the desktop this is the Method Table Pointer + In project N this is the pointer to the EE Type + + + + + For Desktop this is the Module* + For project N it is image base for the module that the type lives in? + + + + + On desktop this is the Meta-data token? + On project N it is the RVA of the typeID + + + + + Note that this method returns the type name with generic parameters in .NET Runtime + syntax e.g. System.WeakReference`1[System.Diagnostics.Tracing.EtwSession] + + + + + Returns the edge at the given zero-based index (index less than Count). The returned GCBulkRootEdgeValues + points the the data in GCBulkRootEdgeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkEdgeTraceData. It can only be used as long as + the GCBulkEdgeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the range at the given zero-based index (index less than Count). The returned GCBulkRootConditionalWeakTableElementEdgeValues + points the the data in GCBulkRootConditionalWeakTableElementEdgeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkRootConditionalWeakTableElementEdgeTraceData. It can only be used as long as + the GCBulkRootConditionalWeakTableElementEdgeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the node at the given zero-based index (idx less than Count). The returned GCBulkNodeNodes + points the the data in GCBulkNodeTraceData so it cannot live beyond that lifetime. + + + + + This unsafe interface may go away. Use the 'Nodes(idx)' instead + + + + + This structure just POINTS at the data in the GCBulkNodeTraceData. It can only be used as long as + the GCBulkNodeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the 'idx' th edge. + The returned GCBulkEdgeEdges cannot live beyond the TraceEvent that it comes from. + + + + + This structure just POINTS at the data in the GCBulkNodeTraceData. It can only be used as long as + the GCBulkNodeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the range at the given zero-based index (index less than Count). The returned GCBulkSurvivingObjectRangesValues + points the the data in GCBulkSurvivingObjectRangesTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkEdgeTraceData. It can only be used as long as + the GCBulkEdgeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the range at the given zero-based index (index less than Count). The returned GCBulkSurvivingObjectRangesValues + points the the data in GCBulkSurvivingObjectRangesTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkEdgeTraceData. It can only be used as long as + the GCBulkEdgeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + We keep Heap history for every Generation in 'Gens' + + + + + Taken from gcrecords.h, used to differentiate heap expansion and compaction reasons + + + + + Version 0, PreciseVersion 0.1: Silverlight (x86) + 0:041> dt -r2 coreclr!WKS::gc_history_per_heap + +0x000 gen_data : [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B : [0 - 40), [40 - 80), [80 - 120), [120 - 160), [160 - 200) + +0x004 size_after : Uint4B/8B + +0x008 current_size : Uint4B/8B + +0x00c previous_size : Uint4B/8B + +0x010 fragmentation : Uint4B/8B + +0x014 in : Uint4B/8B + +0x018 out : Uint4B/8B + +0x01c new_allocation : Uint4B/8B + +0x020 surv : Uint4B/8B + +0x024 growth : Uint4B/8B + +0x0c8 mem_pressure : Uint4B : 200 + +0x0cc mechanisms : [2] Uint4B : 204 (expand), 208 (compact) + +0x0d4 gen_condemn_reasons : Uint4B : 212 + +0x0d8 heap_index : Uint4B : 216 + + clrInstanceId : byte : 220 + + Version 0, PreciseVersion 0.2: .NET 4.0 + 0:000> dt -r2 clr!WKS::gc_history_per_heap + +0x000 gen_data : [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B : [0 - 40), [40 - 80), [80 - 120), [120 - 160), [160 - 200) + +0x004 size_after : Uint4B/8B + +0x008 current_size : Uint4B/8B + +0x00c previous_size : Uint4B/8B + +0x010 fragmentation : Uint4B/8B + +0x014 in : Uint4B/8B + +0x018 out : Uint4B/8B + +0x01c new_allocation : Uint4B/8B + +0x020 surv : Uint4B/8B + +0x024 growth : Uint4B/8B + +0x0c8 mem_pressure : Uint4B : 200 + +0x0cc mechanisms : [3] Uint4B : 204 (expand), 208 (compact), 212 (concurrent_compact) + +0x0d8 gen_condemn_reasons : Uint4B : 216 + +0x0dc heap_index : Uint4B : 220 + + clrInstanceId : byte : 224 + + vm\gcrecord.h + Etw_GCDataPerHeapSpecial(...) + ... + EventDataDescCreate(EventData[0], gc_data_per_heap, datasize); + EventDataDescCreate(EventData[1], ClrInstanceId, sizeof(ClrInstanceId)); + + Version 1: ??? + + Version 2, PreciseVersion 2.1: .NET 4.5 (x86) + 0:000> dt -r2 WKS::gc_history_per_heap + clr!WKS::gc_history_per_heap + +0x000 gen_data : [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B : [0 - 40), [40 - 80), [80 - 120), [120 - 160), [160 - 200) + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c out : Uint4B/8B + +0x020 new_allocation : Uint4B/8B + +0x024 surv : Uint4B/8B + +0x0c8 gen_to_condemn_reasons : WKS::gen_to_condemn_tuning + +0x000 condemn_reasons_gen : Uint4B : 200 + +0x004 condemn_reasons_condition : Uint4B : 204 + +0x0d0 mem_pressure : Uint4B : 208 + +0x0d4 mechanisms : [2] Uint4B : 212 (expand), 216 (compact) + +0x0dc heap_index : Uint4B : 220 + + vm\gcrecord.h + Etw_GCDataPerHeapSpecial(...) + ... + EventDataDescCreate(EventData[0], gc_data_per_heap, datasize); + EventDataDescCreate(EventData[1], ClrInstanceId, sizeof(ClrInstanceId)); + + Version 2, PreciseVersion 2.2: .NET 4.5.2 (x86) + 0:000> dt -r2 WKS::gc_history_per_heap + clr!WKS::gc_history_per_heap + +0x000 gen_data : [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B : [0 - 40), [40 - 80), [80 - 120), [120 - 160), [160 - 200) + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c out : Uint4B/8B + +0x020 new_allocation : Uint4B/8B + +0x024 surv : Uint4B/8B + +0x0c8 gen_to_condemn_reasons : WKS::gen_to_condemn_tuning + +0x000 condemn_reasons_gen : Uint4B : 200 + +0x004 condemn_reasons_condition : Uint4B : 204 + +0x0d0 mem_pressure : Uint4B : 208 + +0x0d4 mechanisms : [2] Uint4B : 212 (expand), 216 (compact) + +0x0dc heap_index : Uint4B : 220 + +0x0e0 extra_gen0_committed : Uint8B : 224 + + vm\gcrecord.h + Etw_GCDataPerHeapSpecial(...) + ... + EventDataDescCreate(EventData[0], gc_data_per_heap, datasize); + EventDataDescCreate(EventData[1], ClrInstanceId, sizeof(ClrInstanceId)); + + Version 3: .NET 4.6 (x86) + 0:000> dt -r2 WKS::gc_history_per_heap + clr!WKS::gc_history_per_heap + +0x000 gen_data : [4] + WKS::gc_generation_data + +0x000 size_before : Uint4B/8B + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c pinned_surv : Uint4B/8B + +0x020 npinned_surv : Uint4B/8B + +0x024 new_allocation : Uint4B/8B + +0x0a0 maxgen_size_info : WKS::maxgen_size_increase + +0x000 free_list_allocated : Uint4B/8B + +0x004 free_list_rejected : Uint4B/8B + +0x008 end_seg_allocated : Uint4B/8B + +0x00c condemned_allocated : Uint4B/8B + +0x010 pinned_allocated : Uint4B/8B + +0x014 pinned_allocated_advance : Uint4B/8B + +0x018 running_free_list_efficiency : Uint4B/8B + +0x0bc gen_to_condemn_reasons : WKS::gen_to_condemn_tuning + +0x000 condemn_reasons_gen : Uint4B + +0x004 condemn_reasons_condition : Uint4B + +0x0c4 mechanisms : [2] Uint4B + +0x0cc machanism_bits : Uint4B + +0x0d0 heap_index : Uint4B + +0x0d4 extra_gen0_committed : Uint4B/8B + + pal\src\eventprovider\lttng\eventprovdotnetruntime.cpp + FireEtXplatGCPerHeapHistory_V3(...) + + tracepoint( + DotNETRuntime, + GCPerHeapHistory_V3, x86 offsets + ClrInstanceID, : 0 + (const size_t) FreeListAllocated, : 2 + (const size_t) FreeListRejected, : 6 + (const size_t) EndOfSegAllocated, : 10 + (const size_t) CondemnedAllocated, : 14 + (const size_t) PinnedAllocated, : 18 + (const size_t) PinnedAllocatedAdvance, : 22 + RunningFreeListEfficiency, : 26 + CondemnReasons0, : 30 + CondemnReasons1 : 34 + ); + tracepoint( + DotNETRuntime, + GCPerHeapHistory_V3_1, + CompactMechanisms, : 38 + ExpandMechanisms, : 42 + HeapIndex, : 46 + (const size_t) ExtraGen0Commit, : 50 + Count, : 54 (number of WKS::gc_generation_data's) + Arg15_Struct_Len_, : ?? not really sent + (const int*) Arg15_Struct_Pointer_ : [58 - 98), ... + ); + + Version 3 is now setup to allow "add to the end" scenarios + + + + + + Returns the condemned generation number + + + + + Returns the condemned condition + + + + + genNumber is a number from 0 to maxGenData-1. These are for generation 0, 1, 2, 3 = Large Object Heap + genNumber = 4 is that second pass for Gen 0. + + + + + Version 0: Silverlight (x86), .NET 4.0 + [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B + +0x004 size_after : Uint4B/8B + +0x008 current_size : Uint4B/8B + +0x00c previous_size : Uint4B/8B + +0x010 fragmentation : Uint4B/8B + +0x014 in : Uint4B/8B + +0x018 out : Uint4B/8B + +0x01c new_allocation : Uint4B/8B + +0x020 surv : Uint4B/8B + +0x024 growth : Uint4B/8B + + Version 1: ??? + + Version 2, PreciseVersion 2.1: .NET 4.5 (x86), .NET 4.5.2 (x86) + [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c out : Uint4B/8B + +0x020 new_allocation : Uint4B/8B + +0x024 surv : Uint4B/8B + + Version 3: .NET 4.6 (x86) + [4] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c pinned_surv : Uint4B/8B + +0x020 npinned_surv : Uint4B/8B + +0x024 new_allocation : Uint4B/8B + + + + + Size of the generation before the GC, includes fragmentation + + + + + Size of the generation after GC. Includes fragmentation + + + + + Size occupied by objects at the beginning of the GC, discounting fragmentation. + Only exits on 4.5 RC and beyond. + + + + + This is the fragmenation at the end of the GC. + + + + + Size occupied by objects, discounting fragmentation. + + + + + This is the free list space (ie, what's threaded onto the free list) at the beginning of the GC. + Only exits on 4.5 RC and beyond. + + + + + This is the free obj space (ie, what's free but not threaded onto the free list) at the beginning of the GC. + Only exits on 4.5 RC and beyond. + + + + + This is the free list space (ie, what's threaded onto the free list) at the end of the GC. + Only exits on 4.5 Beta and beyond. + + + + + This is the free obj space (ie, what's free but not threaded onto the free list) at the end of the GC. + Only exits on 4.5 Beta and beyond. + + + + + This is the amount that came into this generation on this GC + + + + + This is the number of bytes survived in this generation. + + + + + This is the new budget for the generation + + + + + This is the survival rate + + + + + Version 0: ??? + + Version 1: Silverlight (x86), .NET 4.0, .NET 4.5, .NET 4.5.2 + VM\gc.cpp + 0:041> dt -r3 WKS::gc_history_global + coreclr!WKS::gc_history_global + +0x000 final_youngest_desired : Uint4B/8B + +0x004 num_heaps : Uint4B + +0x008 condemned_generation : Int4B + +0x00c gen0_reduction_count : Int4B + +0x010 reason : + reason_alloc_soh = 0n0 + reason_induced = 0n1 + reason_lowmemory = 0n2 + reason_empty = 0n3 + reason_alloc_loh = 0n4 + reason_oos_soh = 0n5 + reason_oos_loh = 0n6 + reason_induced_noforce = 0n7 + reason_gcstress = 0n8 + reason_max = 0n9 + +0x014 global_mechanims_p : Uint4B + + FireEtwGCGlobalHeapHistory_V1(gc_data_global.final_youngest_desired, // upcast on 32bit to __int64 + gc_data_global.num_heaps, + gc_data_global.condemned_generation, + gc_data_global.gen0_reduction_count, + gc_data_global.reason, + gc_data_global.global_mechanims_p, + GetClrInstanceId()); + Version 2: .NET 4.6 + clr!WKS::gc_history_global + +0x000 final_youngest_desired : Uint4B/8B + +0x004 num_heaps : Uint4B + +0x008 condemned_generation : Int4B + +0x00c gen0_reduction_count : Int4B + +0x010 reason : + reason_alloc_soh = 0n0 + reason_induced = 0n1 + reason_lowmemory = 0n2 + reason_empty = 0n3 + reason_alloc_loh = 0n4 + reason_oos_soh = 0n5 + reason_oos_loh = 0n6 + reason_induced_noforce = 0n7 + reason_gcstress = 0n8 + reason_lowmemory_blocking = 0n9 + reason_induced_compacting = 0n10 + reason_lowmemory_host = 0n11 + reason_max = 0n12 + +0x014 pause_mode : Int4B + +0x018 mem_pressure : Uint4B + +0x01c global_mechanims_p : Uint4B + + FireEtwGCGlobalHeapHistory_V2(gc_data_global.final_youngest_desired, // upcast on 32bit to __int64 + gc_data_global.num_heaps, + gc_data_global.condemned_generation, + gc_data_global.gen0_reduction_count, + gc_data_global.reason, + gc_data_global.global_mechanims_p, + GetClrInstanceId()); + gc_data_global.pause_mode, + gc_data_global.mem_pressure); + + + + + + Gets the full type name including generic parameters in runtime syntax + For example System.WeakReference`1[System.Diagnostics.Tracing.EtwSession] + + + + + Returns the CCW at the given zero-based index (index less than Count). The returned GCBulkRootCCWValues + points the the data in GCBulkRootCCWTraceData so it cannot live beyond that lifetime. + + + + + Computes the size of one GCBulkRootCCWValues structure. + TODO FIX NOW Can rip out and make a constant 44 after 6/2014 + + + + + This structure just POINTS at the data in the GCBulkRootCCWTraceData. It can only be used as long as + the GCBulkRootCCWTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the edge at the given zero-based index (index less than Count). The returned GCBulkRCWValues + points the the data in GCBulkRCWTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkRCWTraceData. It can only be used as long as + the GCBulkRCWTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns 'idx'th static root. + The returned GCBulkRootStaticVarStatics cannot live beyond the TraceEvent that it comes from. + The implementation is highly tuned for sequential access. + + + + + This structure just POINTS at the data in the GCBulkRootStaticVarTraceData. It can only be used as long as + the GCBulkRootStaticVarTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Fetches the instruction pointer of a eventToStack frame 0 is the deepest frame, and the maximum should + be a thread offset routine (if you get a complete eventToStack). + + The index of the frame to fetch. 0 is the CPU EIP, 1 is the Caller of that + routine ... + The instruction pointer of the specified frame. + + + + Access to the instruction pointers as a unsafe memory blob + + + + + This is simply the file name part of the ModuleILPath. It is a convenience method. + + + + + Log events associated with the threadpool, and other threading events. + + + + + Dump the native to IL mapping of any method that is JIT compiled. (V4.5 runtimes and above). + + + + + This supresses NGEN events on V4.0 (where you have NGEN PDBs), but not on V2.0 (which does not know about this + bit and also does not have NGEN PDBS). + + + + + TODO document + + + + + Dump PDBs for dynamically generated modules. + + + + + ClrTraceEventParserState holds all information that is shared among all events that is + needed to decode Clr events. This class is registered with the source so that it will be + persisted. Things in here include + + * TypeID to TypeName mapping, + + + + + Returns the edge at the given zero-based index (index less than Count). The returned BulkNodeValues + points the the data in BulkNodeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the BulkNodeTraceData. It can only be used as long as + the BulkNodeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the edge at the given zero-based index (index less than Count). The returned BulkAttributeValues + points the the data in BulkAttributeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the BulkAttributeTraceData. It can only be used as long as + the BulkAttributeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the edge at the given zero-based index (index less than Count). The returned BulkEdgeValues + points the the data in BulkEdgeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the BulkNodeTraceData. It can only be used as long as + the BulkNodeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + The KernelTraceEventParser is a class that knows how to decode the 'standard' kernel events. + It exposes an event for each event of interest that users can subscribe to. + + see TraceEventParser for more + + + + + The special name for the Kernel session + + + + + This is passed to TraceEventSession.EnableKernelProvider to enable particular sets of + events. See http://msdn.microsoft.com/en-us/library/aa363784(VS.85).aspx for more information on them + + + + + Logs nothing + + + + + Logs the mapping of file IDs to actual (kernel) file names. + + + + + Loads the completion of Physical disk activity. + + + + + Logs native modules loads (LoadLibrary), and unloads + + + + + Logs all page faults that must fetch the data from the disk (hard faults) + + + + + Logs TCP/IP network send and receive events. + + + + + Logs process starts and stops. + + + + + Logs process performance counters (TODO When?) (Vista+ only) + see KernelTraceEventParser.ProcessPerfCtr, ProcessPerfCtrTraceData + + + + + Sampled based profiling (every msec) (Vista+ only) (expect 1K events per proc per second) + + + + + Logs threads starts and stops + + + + + log thread context switches (Vista only) (can be > 10K events per second) + + + + + log Disk operations (Vista+ only) + Generally not TOO volumous (typically less than 1K per second) (Stacks associated with this) + + + + + Thread Dispatcher (ReadyThread) (Vista+ only) (can be > 10K events per second) + + + + + log file FileOperationEnd (has status code) when they complete (even ones that do not actually + cause Disk I/O). (Vista+ only) + Generally not TOO volumous (typically less than 1K per second) (No stacks associated with these) + + + + + log the start of the File I/O operation as well as the end. (Vista+ only) + Generally not TOO volumous (typically less than 1K per second) + + + + + Logs all page faults (hard or soft) + Can be pretty volumous (> 1K per second) + + + + + Logs activity to the windows registry. + Can be pretty volumous (> 1K per second) + + + + + log calls to the OS (Vista+ only) + This is VERY volumous (can be > 100K events per second) + + + + + Log Virtual Alloc calls and VirtualFree. (Vista+ Only) + Generally not TOO volumous (typically less than 1K per second) + + + + + Log mapping of files into memmory (Win8 and above Only) + Generally low volume. + + + + + Logs Advanced Local Procedure call events. + + + + + log defered procedure calls (an Kernel mechanism for having work done asynchronously) (Vista+ only) + + + + + Device Driver logging (Vista+ only) + + + + + log hardware interrupts. (Vista+ only) + + + + + Disk I/O that was split (eg because of mirroring requirements) (Vista+ only) + + + + + Good default kernel flags. (TODO more detail) + + + + + These events are too verbose for normal use, but this give you a quick way of turing on 'interesting' events + This does not include SystemCall because it is 'too verbose' + + + + + Use this if you care about blocked time. + + + + + You mostly don't care about these unless you are dealing with OS internals. + + + + + All legal kernel events + + + + + These are the kernel events that are not allowed in containers. Can be subtracted out. + + + + + Turn on PMC (Precise Machine Counter) events. Only Win 8 + + + + + Kernel reference set events (like XPERF ReferenceSet). Fully works only on Win 8. + + + + + Events when thread priorities change. + + + + + Events when queuing and dequeuing from the I/O completion ports. + + + + + Handle creation and closing (for handle leaks) + + + + + These keywords can't be passed to the OS, they are defined by KernelTraceEventParser + + + + + What his parser should track by default. + + + + + Defines how kernel paths are converted to user paths. Setting it overrides the default path conversion mechanism. + + + + + Registers both ProcessStart and ProcessDCStart + + + + + Registers both ProcessEnd and ProcessDCStop + + + + + Registers both ThreadStart and ThreadDCStart + + + + + Registers both ThreadEnd and ThreadDCStop + + + + + Registers both ImageLoad and ImageDCStart + + + + + Registers both ImageUnload and ImageDCStop + + + + + Rasied every 0.5s with memory metrics of the current machine. + + + + + File names in ETW are the Kernel names, which need to be mapped to the drive specification users see. + This event indicates this mapping. + + + + + KernelTraceEventParserState holds all information that is shared among all events that is + needed to decode kernel events. This class is registered with the source so that it will be + persisted. Things in here include + + * FileID to FileName mapping, + * ThreadID to ProcessID mapping + * Kernel file name to user file name mapping + + + + + If you have a file object (per-open-file) in addition to a fileKey, try using both + to look up the file name. + + + + + This is for the circular buffer case. In that case we may not have thread starts (and thus we don't + have entries in threadIDtoProcessID). Because HistoryTable finds the FIRST entry GREATER than the + given threadID we NEGATE all times before we place it in this table. + + Also, because circular buffering is not the common case, we only add entries to this table if needed + (if we could not find the thread ID using threadIDtoProcessID). + + + + + Keeps track of the mapping from kernel names to file system names (drives) + + + + + Create a new KernelToUserDriveMapping that can look up kernel names for drives and map them to windows drive letters. + + + + + Returns the string representing the windows drive letter for the kernel drive name 'kernelName' + + + + + + + This is the number of minutes between the local time where the data was collected and UTC time. + It does NOT take Daylight savings time into account. + It is positive if your time zone is WEST of Greenwich. + + + + + Indicate that StartAddr and Win32StartAddr are a code addresses that needs symbolic information + + + + + We report a context switch from from the new thread. Thus NewThreadID == ThreadID. + + + + + The I/O Response Packet address. This represents the 'identity' of this particular I/O + + + + + This is the time since the I/O was initiated, in source.PerfFreq (QPC) ticks. + + + + + This is the actual time the disk spent servicing this IO. Same as elapsed time for real time providers. + + + + + The time since the I/O was initiated. + + + + + This is the time since the I/O was initiated, in source.PerfFreq (QPC) ticks. + + + + + The time since the I/O was initiated. + + + + + This is a handle that represents a file NAME (not an open file). + In the MSDN does this field is called FileObject. However in other events FileObject is something + returned from Create file and is different. Events have have both (and some do) use FileKey. Thus + I use FileKey uniformly to avoid confusion. + + + + + See the Windows CreateFile API CreateOptions for this + + + + + See Windows CreateFile API CreateDisposition for this. + + + + + See Windows CreateFile API ShareMode parameter + + + + + See windows CreateFile API ShareMode parameter + + + + + See Windows CreateFile function CreateDispostion parameter. + + + + + See Windows CreateFile function FlagsAndAttributes parameter. + TODO FIX NOW: these have not been validated yet. + + + + + The FileObject is the object for the Directory (used by CreateFile to open and passed to Close to close) + + + + + The FileKey is the object that represents the name of the directory. + + + + + This is the TimeDateStamp converted to a DateTime + TODO: daylight savings time seems to mess this up. + + + + + Indicate that ProgramCounter is a code address that needs symbolic information + + + + + The time spent during the page fault. + + + + + Indicate that the Address is a code address that needs symbolic information + + + + + This event is emitted by the Microsoft-Windows-Kernel-Memory with Keyword 0x40 KERNEL_MEM_KEYWORD_MEMINFO_EX every .5 seconds + + + + + Returns the edge at the given zero-based index (index less than Count). The returned MemoryProcessMemInfoValues + points the the data in MemoryProcessMemInfoTraceData so it cannot live beyond that lifetime. + + + + + The fields after 'Count' are the first value in the array of working sets. + + + + + This structure just POINTS at the data in the MemoryProcessMemInfoTraceData. It can only be used as long as + the MemoryProcessMemInfoTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + The fields after 'Count' are the first value in the array of working sets. + + + + + Are we currently executing a Deferred Procedure Call (a mechanism the kernel uses to + 'steal' a thread to run its own work). If this is true, the CPU time is really + not logically related to the process (it is kernel time). + + + + + Are we currently executing a Interrupt Service Routine? Like ExecutingDPC if this + is true the thread is really doing Kernel work, not work for the process. + + + + + NonProcess is true if ExecutingDPC or ExecutingISR is true. + + + + + The thread's current priority (higher is more likely to run). A normal thread with a normal base + priority is 8. + see http://msdn.microsoft.com/en-us/library/windows/desktop/ms685100(v=vs.85).aspx for more + + + + + Your scheduling If the thread is not part of a scheduling group, this is 0 (see callout.c) + + + + + Indicate that the Address is a code address that needs symbolic information + + + + + PMC (Precise Machine Counter) events are fired when a CPU counter trips. The the ProfileSource identifies + which counter it is. The PerfInfoCollectionStart events will tell you the count that was configured to trip + the event. + + + + + Indicate that Address is a code address that needs symbolic information + + + + + Indicate that the Address is a code address that needs symbolic information + + + + + Collects the call callStacks for some other event. + + (TODO: always for the event that preceded it on the same thread)? + + + + + The timestamp of the event which caused this stack walk using QueryPerformaceCounter + cycles as the tick. + + + + + Converts this to a time relative to the start of the trace in msec. + + + + + The total number of eventToStack frames collected. The Windows OS currently has a maximum of 96 frames. + + + + + Fetches the instruction pointer of a eventToStack frame 0 is the deepest frame, and the maximum should + be a thread offset routine (if you get a complete stack). + + The index of the frame to fetch. 0 is the CPU EIP, 1 is the Caller of that + routine ... + The instruction pointer of the specified frame. + + + + Access to the instruction pointers as a unsafe memory blob + + + + + StackWalkTraceData does not set Thread and process ID fields properly. if that. + + + + + To save space, stack walks in Win8 can be complressed. The stack walk event only has a + reference to a stack Key which is then looked up by StackWalkDefTraceData. + + + + + The timestamp of the event which caused this stack walk using QueryPerformaceCounter + cycles as the tick. + + + + + Converts this to a time relative to the start of the trace in msec. + + + + + Returns a key that can be used to look up the stack in KeyDelete or KeyRundown events + + + + + StackWalkTraceData does not set Thread and process ID fields properly. if that. + + + + + This event defines a stack and gives it a unique id (the StackKey), which StackWalkRefTraceData can point at. + + + + + Returns a key that can be used to look up the stack in KeyDelete or KeyRundown events + + + + + The total number of eventToStack frames collected. The Windows OS currently has a maximum of 96 frames. + + + + + Fetches the instruction pointer of a eventToStack frame 0 is the deepest frame, and the maximum should + be a thread offset routine (if you get a complete complete). + + The index of the frame to fetch. 0 is the CPU EIP, 1 is the Caller of that + routine ... + The instruction pointer of the specified frame. + + + + Access to the instruction pointers as a unsafe memory blob + + + + + e.g. c:\windows\system32 + + + + + .e.g c:\windows + + + + + Kernel traces have information about images that are loaded, however they don't have enough information + in the events themselves to unambigously look up PDBs without looking at the data inside the images. + This means that symbols can't be resolved unless you are on the same machine on which you gathered the data. + + XPERF solves this problem by adding new 'synthetic' events that it creates by looking at the trace and then + opening each DLL mentioned and extracting the information needed to look PDBS up on a symbol server (this + includes the PE file's TimeDateStamp as well as a PDB Guid, and 'pdbAge' that can be found in the DLLs header. + + These new events are added when XPERF runs the 'merge' command (or -d flag is passed). It is also exposed + through the KernelTraceControl.dll!CreateMergedTraceFile API. + + SymbolTraceEventParser is a parser for extra events. + + + + + The DbgIDRSDS event is added by XPERF for every Image load. It contains the 'PDB signature' for the DLL, + which is enough to unambiguously look the image's PDB up on a symbol server. + + + + + Every DLL has a Timestamp in the PE file itself that indicates when it is built. This event dumps this timestamp. + This timestamp is used to be as the 'signature' of the image and is used as a key to find the symbols, however + this has mostly be superseded by the DbgID/RSDS event. + + + + + The FileVersion event contains information from the file version resource that most DLLs have that indicated + detailed information about the exact version of the DLL. (What is in the File->Properties->Version property + page) + + + + + I don't really care about this one, but I need a definition in order to exclude it because it + has the same timestamp as a imageLoad event, and two events with the same timestamp confuse the + association between a stack and the event for the stack. + + + + + This event has a TRACE_EVENT_INFO as its payload, and allows you to decode an event + + + + + The event describes a Map (bitmap or ValueMap), and has a payload as follows + + GUID ProviderId; + EVENT_MAP_INFO EventMapInfo; + + + + + The value of the one string payload property. + + + + + Construct a TraceEvent template which has one string payload field with the given metadata and action + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + override + + + + + RegisteredTraceEventParser uses the standard windows provider database (TDH, what gets registered with wevtutil) + to find the names of events and fields of the events). + + + + + Create a new RegisteredTraceEventParser and attach it to the given TraceEventSource + + + + + Given a provider name that has been registered with the operating system, get + a string representing the ETW manifest for that provider. Note that this + manifest is not as rich as the original source manifest because some information + is not actually compiled into the binary manifest that is registered with the OS. + + + + + Given a provider GUID that has been registered with the operating system, get + a string representing the ETW manifest for that provider. Note that this + manifest is not as rich as the original source manifest because some information + is not actually compiled into the binary manifest that is registered with the OS. + + + + + Generates a space separated list of set of keywords 'keywordSet' using the table 'keywords' + It will generate new keyword names if needed and add them to 'keywords' if they are not present. + + + + + Class used to accumulate information about Tasks in the implementation of GetManifestForRegisteredProvider + + + + + Try to look up 'unknonwEvent using TDH or the TraceLogging mechanism. if 'mapTable' is non-null it will be used + look up the string names for fields that have bitsets or enumerated values. This is only need for the KernelTraceControl + case where the map information is logged as special events and can't be looked up with TDH APIs. + + + + + TdhEventParser takes the Trace Diagnostics Helper (TDH) TRACE_EVENT_INFO structure and + (passed as a byte*) and converts it to a DynamicTraceEventData which which + can be used to parse events of that type. You first create TdhEventParser and then + call ParseEventMetaData to do the parsing. + + + + + Creates a new parser from the TRACE_EVENT_INFO held in 'buffer'. Use + ParseEventMetaData to then parse it into a DynamicTraceEventData structure. + EventRecord can be null and mapTable if present allow the parser to resolve maps (enums), and can be null. + + + + + Actually performs the parsing of the TRACE_EVENT_INFO passed in the constructor + + + + + + Parses at most 'maxFields' fields starting at the current position. + Will return the parse fields in 'payloadNamesRet' and 'payloadFetchesRet' + Will return true if successful, false means an error occurred. + + + + + ExternalTraceEventParser is an abstract class that acts as a parser for any 'External' resolution + This include the TDH (RegisteredTraceEventParser) as well as the WPPTraceEventParser. + + + + + Create a new ExternalTraceEventParser and attach it to the given TraceEventSource + + + + + Override. + + + + + Override + + + + + Returns true if the RegisteredTraceEventParser would return 'template' in EnumerateTemplates + + + + + override + + + + + Register 'template' so that if there are any subscriptions to template they get registered with the source. + + + + + Used to look up Enums (provider x enumName); Very boring class. + + + + + TDHDynamicTraceEventParserState represents the state of a TDHDynamicTraceEventParser that needs to be + serialized to a log file. It does NOT include information about what events are chosen but DOES contain + any other necessary information that came from the ETL data file or the OS TDH APIs. + + + + + This defines what it means to be the same event. For manifest events it means provider and event ID + for classic, it means that taskGuid and opcode match. + + + + + Implements IFastSerializable interface + + + + + Implements IFastSerializable interface + + + + + This parser knows how to decode Windows Software Trace Preprocessor (WPP) events. In order to decode + the events it needs access to the TMF files that describe the events (these are created from the PDB at + build time). +
+ You will generally use this for the 'FormattedMessage' property of the event. +
+
+ + + Construct a new WPPTraceEventParser that is attached to 'source'. Once you do this the source + will understand WPP events. In particular you can subscribe to the Wpp.All event to get the + stream of WPP events in the source. For WppTraceEventParser to function, it needs the TMF + files for the events it will decode. You should pass the directory to find these TMF files + in 'TMFDirectory'. Each file should have the form of a GUID.tmf. + + + + + + + ETWReloggerTraceEventSource is designed to be able to write ETW files using an existing ETW input stream (either a file, files or real time session) as a basis. + The relogger capabilities only exist on Windows 8 OSes and beyond. + + The right way to think about this class is that it is just like ETWTraceEventSource, but it also has a output file associated with it, and WriteEvent APIs that + can be used to either copy events from the event stream (the common case), or inject new events (high level stats). + + + + + Create an ETWReloggerTraceEventSource that can takes its input from the family of etl files inputFileName + and can write them to the ETL file outputFileName (.kernel*.etl, .user*.etl .clr*.etl) + + This is a shortcut for ETWReloggerTraceEventSource(inputFileName, TraceEventSourceType.MergeAll, outputFileStream) + + + + + Create an ETWReloggerTraceEventSource that can takes its input from a variety of sources (either a single file, + a set of files, or a real time ETW session (based on 'type'), and can write these events to a new ETW output + file 'outputFileName. + + + + + The output file can use a compressed form or not. Compressed forms can only be read on Win8 and beyond. Defaults to true. + + + + + Writes an event from the input stream to the output stream of events. + + + + + Connect the given EventSource so any events logged from it will go to the output stream of events. + Once connected, you may only write events from this EventSource while processing the input stream + (that is during the callback of an input stream event), because the context for the EventSource event + (e.g. timestamp, proesssID, threadID ...) will be derived from the current event being processed by + the input stream. + + + + + Writes an event that did not exist previously into the data stream, The context data (time, process, thread, activity, comes from 'an existing event') + + + + + Writes an event that did not exist previously into the data stream, The context data (time, process, thread, activity, comes from 'an existing event') is given explicitly + + + + + implementing TraceEventDispatcher + + + + + implementing TraceEventDispatcher + + + + + Implements TraceEventDispatcher.Dispose + + + + + Implements TraceEventDispatcher.StopProcessing + + + + + This is used by the ConnectEventSource to route events from the EventSource to the relogger. + + + + + This is the class the Win32 APIs call back on. + + + + + A ETWTraceEventSource represents the stream of events that was collected from a + TraceEventSession (eg the ETL moduleFile, or the live session event stream). Like all + TraceEventSource, it logically represents a stream of TraceEvent s. Like all + TraceEventDispathers it supports a callback model where Parsers attach themselves to this + sources, and user callbacks defined on the parsers are called when the 'Process' method is called. + + * See also TraceEventDispatcher + * See also TraceEvent + * See also #ETWTraceEventSourceInternals + * See also #ETWTraceEventSourceFields + + + + + Open a ETW event trace moduleFile (ETL moduleFile) for processing. + + The ETL data moduleFile to open` + + + + Open a ETW event source for processing. This can either be a moduleFile or a real time ETW session + + + If type == ModuleFile this is the name of the moduleFile to open. + If type == Session this is the name of real time session to open. + + + + + Process all the files in 'fileNames' in order (that is all the events in the first + file are processed, then the second ...). Intended for parsing the 'Multi-File' collection mode. + + The list of files path names to process (in that order) + + + + Processes all the events in the data source, issuing callbacks that were subscribed to. See + #Introduction for more + + false If StopProcesing was called + + + + Reprocess a pre-constructed event which this processor has presumably created. Helpful to re-examine + "unknown" events, perhaps after a manifest has been received from the ETW stream. + Note when queuing events to reprocess you must Clone them first + or certain internal data may no longer be available and you may receive memory access violations. + + Event to re-process. + + + + The log moduleFile that is being processed (if present) + TODO: what does this do for Real time sessions? + + + + + The name of the session that generated the data. + + + + + The size of the log, will return 0 if it does not know. + + + + + returns the number of events that have been lost in this session. Note that this value is NOT updated + for real time sessions (it is a snapshot). Instead you need to use the TraceEventSession.EventsLost property. + + + + + Returns true if the Process can be called multiple times (if the Data source is from a + moduleFile, not a real time stream. + + + + + This routine is only useful/valid for real-time sessions. + + TraceEvent.TimeStamp internally is stored using a high resolution clock called the Query Performance Counter (QPC). + This clock is INDEPENDENT of the system clock used by DateTime. These two clocks are synchronized to within 2 msec at + session startup but they can drift from there (typically 2msec / min == 3 seconds / day). Thus if you have long + running real time session it becomes problematic to compare the timestamps with those in another session or something + timestamped with the system clock. SynchronizeClock will synchronize the TraceEvent.Timestamp clock with the system + clock again. If you do this right before you start another session, then the two sessions will be within 2 msec of + each other, and their timestamps will correlate. Doing it periodically (e.g. hourly), will keep things reasonably close. + + TODO: we can achieve perfect synchronization by exposing the QPC tick sync point so we could read the sync point + from one session and set that exact sync point for another session. + + + + + Options that can be passed to GetModulesNeedingSymbols + + + + + This is the default, where only NGEN images are included (since these are the only images whose PDBS typically + need to be resolved agressively AT COLLECTION TIME) + + + + + If set, this option indicates that non-NGEN images should also be included in the list of returned modules + + + + + Normally only modules what have a CPU or stack sample are included in the list of assemblies (thus you don't + unnecessarily have to generate NGEN PDBS for modules that will never be looked up). However if there are + events that have addresses that need resolving that this routine does not recognise, this option can be + set to insure that any module that was event LOADED is included. This is inefficient, but guarenteed to + be complete + + + + + Given an ETL file, returns a list of the full paths to DLLs that were loaded in the trace that need symbolic + information (PDBs) so that the stack traces and CPU samples can be properly resolved. By default this only + returns NGEN images since these are the ones that need to be resolved and generated at collection time. + + + + + Image data is a trivial record for image data, where it is keyed by the base address, processID and name. + + + + + Returns the size of pointer (8 or 4) for the operating system (not necessarily the process) + + + + + This is a little helper class that maps QueryPerformanceCounter (QPC) ticks to DateTime. There is an error of + a few msec, but as long as every one uses the same one, we probably don't care. + + + + + see Dispose pattern + + + + + see Dispose pattern + + + + + Used by real time TraceLog on Windows7. + If we have several real time sources we have them coming in on several threads, but we want the illusion that they + are one source (thus being processed one at a time). Thus we want a lock that is taken on every dispatch. + + + + + The kinds of data sources that can be opened (see ETWTraceEventSource) + + + + + Look for any files like *.etl or *.*.etl (the later holds things like *.kernel.etl or *.clrRundown.etl ...) + + + + + Look for a ETL moduleFile *.etl as the event data source + + + + + Use a real time session as the event data source. + + + + + EventPipeEventSource knows how to decode EventPipe (generated by the .NET core runtime). + Please see for details on the file format. + + By conventions files of such a format are given the .netperf suffix and are logically + very much like a ETL file in that they have a header that indicate things about + the trace as a whole, and a list of events. Like more modern ETL files the + file as a whole is self-describing. Some of the events are 'MetaData' events + that indicate the provider name, event name, and payload field names and types. + Ordinary events then point at these meta-data event so that logically all + events have a name some basic information (process, thread, timestamp, activity + ID) and user defined field names and values of various types. + + + + + This is the version number reader and writer (although we don't don't have a writer at the moment) + It MUST be updated (as well as MinimumReaderVersion), if breaking changes have been made. + If your changes are forward compatible (old readers can still read the new format) you + don't have to update the version number but it is useful to do so (while keeping MinimumReaderVersion unchanged) + so that readers can quickly determine what new content is available. + + + + + This field is only used for writers, and this code does not have writers so it is not used. + It should be set to Version unless changes since the last version are forward compatible + (old readers can still read this format), in which case this shoudl be unchanged. + + + + + This is the smallest version that the deserializer here can read. Currently + we are careful about backward compat so our deserializer can read anything that + has ever been produced. We may change this when we believe old writers basically + no longer exist (and we can remove that support code). + + + + + Give meta-data for an event, passed as a EventPipeEventMetaDataHeader and readerForParameters + which is a StreamReader that points at serialized parameter information, decode the meta-data + and record a template associated with this source. The readerForParameters is advanced beyond + the event parameters information. + + + + + Given the EventPipe metaData header and a stream pointing at the serialized meta-data for the parameters for the + event, create a new DynamicTraceEventData that knows how to parse that event. + ReaderForParameters.Current is advanced past the parameter information. + + + + + An EVentPipeEventBlock represents a block of events. It basicaly only has + one field, which is the size in bytes of the block. But when its FromStream + is called, it will perform the callbacks for the events (thus deserializing + it performs dispatch). + + + + + Private utility class. + + An EventPipeEventMetaDataHeader holds the information that can be shared among all + instances of an EventPipe event from a particular provider. Thus it contains + things like the event name, provider, It however does NOT contain the data + about the event parameters (the names of the fields and their types), That is + why this is a meta-data header and not all the meta-data. + + This class has two main functions + 1. The constructor takes a PinnedStreamReader and decodes the serialized metadata + so you can access the data conveniently (but it does not decode the parameter info) + 2. It remembers a EVENT_RECORD structure (from ETW) that contains this data) + and has a function GetEventRecordForEventData which converts from a + EventPipeEventHeader (the raw serialized data) to a EVENT_RECORD (which + is what TraceEvent needs to look up the event an pass it up the stack. + + + + + Creates a new MetaData instance from the serialized data at the current position of 'reader' + of length 'length'. This typically points at the PAYLOAD AREA of a meta-data events) + 'fileFormatVersionNumber' is the version number of the file as a whole + (since that affects the parsing of this data) and 'processID' is the process ID for the + whole stream (since it needs to be put into the EVENT_RECORD. + + When this constructor returns the reader has read up to the serialized information about + the parameters. We do this because this code does not know the best representation for + this parameter information and so it just lets other code handle it. + + + + + Given a EventPipeEventHeader takes a EventPipeEventHeader that is specific to an event, copies it + on top of the static information in its EVENT_RECORD which is specialized meta-data + and returns a pointer to it. Thus this makes the EventPipe look like an ETW provider from + the point of view of the upper level TraceEvent logic. + + + + + This is a number that is unique to this meta-data blob. It is expected to be a small integer + that starts at 1 (since 0 is reserved) and increases from there (thus an array can be used). + It is what is matched up with EventPipeEventHeader.MetaDataId + + + + + Reads the meta data for information specific to one event. + + + + + Private utility class. + + At the start of every event from an EventPipe is a header that contains + common fields like its size, threadID timestamp etc. EventPipeEventHeader + is the layout of this. Events have two variable sized parts: the user + defined fields, and the stack. EventPipEventHeader knows how to + decode these pieces (but provides no semantics for it. + + It is not a public type, but used in low level parsing of EventPipeEventSource. + + + + + Header Size is defined to be the number of bytes before the Payload bytes. + + + + + Fetches the instruction pointer of a eventToStack frame 0 is the deepest frame, and the maximum should + be a thread offset routine (if you get a complete eventToStack). + + The index of the frame to fetch. 0 is the CPU EIP, 1 is the Caller of that + routine ... + The instruction pointer of the specified frame. + + + + Access to the instruction pointers as a unsafe memory blob + + + + + SampleInfos of a set of stackSource by eventToStack. This represents the entire call tree. You create an empty one in using + the default constructor and use 'AddSample' to add stackSource to it. You traverse it by + + + + + Creates an empty call tree, indicating the scaling policy of the metric. You populate it by assigning a StackSOurce to the tree. + + + + + A CallTree is generated from a StackSource. Setting the StackSource causes the tree to become populated. + + + + + When calculating percentages, the PercentageBasis do we use as 100%. By default we use the + Inclusive time for the root, but that can be changed here. + + + + + Returns the root node of the call tree. + + + + + An upper bound for the node indexes in the call tree. (All indexes + are strictly less than this number) Thus ASSSUMING YOU DON'T ADD + NEW NODES, an array of this size can be used to index the nodes (and + thus lookup nodes by index or to store additional information about a node). + + + + + Get a CallerCalleeNode for the nodes in the call tree named 'nodeName' + + + + + Returns a list of nodes that have statistics rolled up by treeNode by ID. It is not + sorted by anything in particular. Note that ID is not quite the same thing as the + name. You can have two nodes that have different IDs but the same Name. These + will show up as two distinct entries in the resulting list. + + + + + Returns the list returned by the ByID property sorted by exclusive metric. + + + + + If there are any nodes that have strictly less than to 'minInclusiveMetric' + then remove the node, placing its samples into its parent (thus the parent's + exclusive metric goes up). + + If useWholeTraceMetric is true, nodes are only folded if their inclusive metric + OVER THE WHOLE TRACE is less than 'minInclusiveMetric'. If false, then a node + is folded if THAT NODE has less than the 'minInclusiveMetric' + + Thus if 'useWholeTraceMetric' == false then after calling this routine no + node will have less than minInclusiveMetric. + + + + + + Cause the children of each CallTreeNode in the CallTree to be sorted (accending) based on comparer + + + + + Sorting by InclusiveMetric Decending is so common, provide a shortcut. + + + + + When converting the InclusiveMetricByTime to a InclusiveMetricByTimeString you have to decide + how to scale the samples to the digits displayed in the string. This enum indicates this policy + + + + + The nodes in the calltree have histograms in time, all of these histograms share a controller that + contains sharable information. This propertly returns that TimeHistogramController + + + + + The nodes in the calltree have histograms indexed by scenario (which is user defiend), + all of these histograms share a controller that contains sharable information. + This propertly returns that ScenarioHistogramController + + + + + Turns off logic for computing call trees in parallel. Safer but slower. + + + This is off by default following indications of race conditions. + + + + + Break all links in the call tree to free as much memory as possible. + + + + + Write an XML representtaion of the CallTree to 'writer' + + + + + An XML representtaion of the CallTree (for debugging) + + + + + Traverse the subtree of 'treeNode' into the m_sumByID dictionary. We don't want to + double-count inclusive times, so we have to keep track of all callers currently on the + stack and we only add inclusive times for nodes that are not already on the stack. + + + + + ScalingPolicyKind represents the desired way to scale the metric in the samples. + + + + + This is the default. In this policy, 100% is chosen so that the histogram is scaled as best it can. + + + + + It assumes that the metric represents time + + + + + Represents a unique ID for a node in a call tree. Can be used to look up a call tree node easily. + It is a dense value (from 0 up to a maximum). + + + + + An Invalid Node Index. + + + + + A CallTreeNodeBase is the inforation in a CallTreeNode without parent or child relationships. + ByName nodes and Caller-Callee nodes need this because they either don't have or need different + parent-child relationships. + + + + + Returns a unique small, dense number (suitable for looking up in an array) that represents + this call tree node (unlike the ID, which more like the name of the frame of the node), so you + can have many nodes with the same name, but only one with the same index. See CallTree.GetNodeIndexLimit. + + + + + Create a CallTreeNodeBase (a CallTreeNode without children) which is a copy of another one. + + + + + The Frame name that this tree node represents. + + + + + Currently the same as Name, but could contain additional info. + Suitable for display but not for programmatic comparison. + + + + + The ID represents a most fine grained uniqueness associated with this node. It can represent + a method, but for sources that support 'goto source' functionality these IDs actually represent + particular lines (or more precisely program counter locations), within the method. Thus it is + very likely that there are call tree nodes that have the same name but different IDs. + + This can be StackSourceFrameIndex.Invalid for Caller-callee nodes (which have names, but no useful ID) + + If ID != Invalid, and the IDs are the same then the names are guaranteed to be the same. + + + + + The sum of the metric of all samples that are in this node or any child of this node (recursively) + + + + + The average metric of all samples that are in this node or any child of this node (recursively). + This is simply InclusiveMetric / InclusiveCount. + + + + + The sum of the metric of all samples that are in this node + + + + + The sum of the metric of all samples in this node that are there because they were folded (inlined). It is alwasy less than or equal to ExclusiveMetric. + + + + + The sum of the count of all samples that are in this node or any child of this node (recursively) + + + + + The sum of the count of all samples that are in this node + + + + + The sum of the count of all samples in this node that are there because they were folded (inlined). It is alwasy less than or equal to ExclusiveCount. + + + + + The inclusive metric, normalized to the total metric for the entire tree. + + + + + The exclusive metric, normalized to the total metric for the entire tree. + + + + + The exclusive folded metric, normalized to the total metric for the entire tree. + + + + + The time of the first sample for this node or any of its children (recursively) + + + + + The time of the first sample for this node or any of its children (recursively) + + + + + The time of the last sample for this node or any of its children (recursively) + + + + + The time of the last sample for this node or any of its children (recursively) + + + + + The difference between the first and last sample (in MSec). + + + + + The call tree that contains this node. + + + + + Returns the histogram that groups of samples associated with this node or any of its children by time buckets + + + + + Returns a string that represents the InclusiveMetricByTime Histogram by using character for every bucket (like PerfView) + + + + + Returns the histogram that groups of samples associated with this node or any of its children by scenario buckets + + + + + Returns a string that represents the InclusiveMetricByScenario Histogram by using character for every bucket (like PerfView) + + + + + Returns all the original stack samples in this node. If exclusive==true then just he + sample exclusively in this node are returned, otherwise it is the inclusive samples. + + If the original stack source that was used to create this CodeTreeNode was a FilterStackSource + then that filtering is removed in the returned Samples. + + Returns the total number of samples (the number of times 'callback' is called) + + If the callback returns false, the iteration over samples stops. + + + + + While 'GetSamples' can return all the samples in the tree, this is a relatively + inefficient way of representing the samples. Instead you can return a list of + trees whose samples represent all the samples. This is what GetTrees does. + It calls 'callback' on a set of trees that taken as a whole have all the samples + in 'node'. + + Note you ave to be careful when using this for inclusive summation of byname nodes because + you will get trees that 'overlap' (bname nodes might refer into the 'middle' of another + call tree). This can be avoided pretty easily by simply stopping inclusive traversal + whenever a tree node with that ID occurs (see GetSamples for an example). + + + + + Returns a string representing the set of XML attributes that can be added to another XML element. + + + + + An XML representation of the CallTreeNodeBase (for debugging) + + + + + The GUI sadly holds on to Call things in the model in its cache, and call tree nodes have linkes to whole + call tree. To avoid the GUI cache from holding on to the ENTIRE MODEL, we neuter the nodes when we are + done with them so that even if they are pointed to by the GUI cache it does not hold onto most of the + (dead) model. FreeMemory does this neutering. + + + + + Combines the 'this' node with 'otherNode'. If 'newOnStack' is true, then the inclusive + metrics are also updated. + + Note that I DON'T accumulate other.m_samples into this.m_samples. This is because we want to share + samples as much a possible. Thus nodes remember their samples by pointing at other call trees + and you fetch the samples by an inclusive walk of the tree. + + + + + To avoid double-counting for byname nodes, with we can be told to exclude any children with a particular ID + (the ID of the ByName node itself) if are doing the inclusive case. The goal is to count every reachable + tree exactly once. We do this by conceptually 'marking' each node with ID at the top level (when they are + enumerated as children of the Byname node), and thus any node with that excludeChildrenWithID is conceptually + marked if you encounter it as a child in the tree itself (so you should exclude it). The result is that + every node is visited exactly once (without the expense of having a 'visited' bit). + + + + + Represents a single treeNode in a CallTree + + Each node keeps all the sample with the same path to the root. + Each node also remembers its parent (caller) and children (callees). + The nodes also keeps the IDs of all its samples (so no information + is lost, just sorted by stack). You get at this through the + CallTreeNodeBase.GetSamples method. + + + + + The caller (parent) of this node + + + + + The nodes this node calls (its children). + + + + + Returns true if Callees is empty. + + + + + AllCallees is an extension of CallTreesNodes to support graphs (e.g. memory heaps). + It always starts with the 'normal' Callees, however in addition if we are + displaying a Graph, it will also children that were 'pruned' when the graph was + transformed into a tree. (by using StackSource.GetRefs). + + + + + Returns true if AllCallees is non-empty. + + + + + Returns true if the call trees came from a graph (thus AllCallees may be strictly larger than Callees) + + + + + Writes an XML representation of the call tree Node it 'writer' + + + + + Returns an XML representation of the call tree Node (for debugging); + + + + + Adds up the counts of all nodes called 'BROKEN' nodes in a particular tree node + + This is a utility function. + + + + + Creates a string that has spaces | and + signs that represent the indentation level + for the tree node. (Called from XAML) + + + + + Implements CallTreeNodesBase interface + + + + + Sort the childre of every node in the te + + + + + + Some calltrees already fill in their children, others do so lazily, in which case they + override this method. + + + + + Fold away any nodes having less than 'minInclusiveMetric'. If 'sumByID' is non-null then the + only nodes that have a less then the minInclusiveMetric for the whole trace are folded. + + + + + A CallerCalleeNode gives statistics that focus on a NAME. (unlike calltrees that use ID) + It takes all stackSource that have callStacks that include that treeNode and compute the metrics for + all the callers and all the callees for that treeNode. + + + + + Given a complete call tree, and a Name within that call tree to focus on, create a + CallerCalleeNode that represents the single Caller-Callee view for that treeNode. + + + + + The list of CallTreeNodeBase nodes that called the method represented by this CallerCalleeNode + + + + + The list of CallTreeNodeBase nodes that where called by the method represented by this CallerCalleeNode + + + + + wrtites an XML representation of the call tree Node it 'writer' + + + + + Returns an XML representation of the CallerCalleeNode (for debugging); + + + + + Implements CallTreeNodesBase interface + + + + + A caller callee view is a summation which centers around one 'focus' node which is represented by the CallerCalleeNode. + This node has a caller and callee list, and these nodes (as well as the CallerCalleNode itself) represent the aggregation + over the entire tree. + + AccumulateSamplesForNode is the routine that takes a part of a aggregated call tree (represented by 'treeNode' and adds + in the statistics for that call tree into the CallerCalleeNode aggregations (and its caller and callee lists). + + 'recursionsCount' is the number of times the focus node name has occurred in the path from 'treeNode' to the root. In + addition to setting the CallerCalleeNode aggregation, it also returns a 'weightedSummary' inclusive aggregation + FOR JUST treeNode (the CallerCalleNode is an aggregation over the entire call tree accumulated so far). + + The key problem for this routine to avoid is double counting of inclusive samples in the face of recursive functions. + Thus all samples are weighted by the recursion count before being included in 'weightedSummaryRet (as well as in + the CallerCalleeNode and its Callers and Callees). + + An important optimization is the ability to NOT create (but rather reuse) CallTreeNodes when returning weightedSummaryRet. + To accomplish this the weightedSummaryScaleRet is needed. To get the correct numerical value for weightedSummaryRet, you + actually have to scale values by weightedSummaryScaleRet before use. This allows us to represent weights of 0 (subtree has + no calls to the focus node), or cases where the subtree is completely uniform in its weighting (the subtree does not contain + any additional focus nodes), by simply returning the tree node itself and scaling it by the recursion count). + + isUniformRet is set to false if anyplace in 'treeNode' does not have the scaling factor weightedSummaryScaleRet. This + means the the caller cannot simply scale 'treeNode' by a weight to get weightedSummaryRet. + + + + + Find the Caller-Callee treeNode in 'elems' with name 'frameName'. Always succeeds because it + creates one if necessary. + + + + + AggregateCallTreeNode supports a multi-level caller-callee view. + + It does this by allow you to take any 'focus' node (typically a byname node) + and compute a tree of its callers and a tree of its callees. You do this + by passing the node of interested to either the 'CallerTree' or 'CalleeTrees'. + + The AggregateCallTreeNode remembers if if is a caller or callee node and its + 'Callees' method returns the children (which may in fact be Callers). + + What is nice about 'AggregateCallTreeNode is that it is lazy, and you only + form the part of the tree you actually explore. A classic 'caller-callee' + view is simply the caller and callee trees only explored to depth 1. + + + + + Given any node (typically a byName node, but it works on any node), Create a + tree rooted at 'node' that represents the callers of that node. + + + + + Given any node (typically a byName node, but it works on any node), Create a + tree rooted at 'node' that represents the callees of that node. + + + + + Calls 'callback' for each distinct call tree in this node. Note that the same + trees can overlap (in the case of recursive functions), so you need a mechanism + for visiting a tree only once. + + + + + Returns an XML representation of the AggregateCallTreeNode (for debugging); + + + + + Implementation of CallTreeNodeBase interface + + + + + Implementation of CallTreeNode interface + + + + + See m_callerOffset and MergeCallee for more. + + The 'this' node is a AggregateCallTree representing the 'callers' nodes. Like + MergeCallee the aggregate node represents a list of CallTreeNodes. However unlike + MergeCallee, the list of CallTreeNodes each represent a sample (a complete call stack) + and 'callerOffset' indicates how far 'up' that stack is the node of interest. + + + + + An aggregateCallTreeNode is exactly that, the sum of several callTrees + (each of which represent a number of individual samples). Thus we had to + take each sample (which is 'treenode' and merge it into the aggregate. + We do this one at a time. Thus we call MergeCallee for each calltree + in our list and we find the 'callees' of each of those nodes, and create + aggregates for the children (which is in calleeList). + + This routine is not recursive and does not touch most of the tree but + it does call SubtractOutTrees which is recursive and may look at a lot + of the tree (although we try to minimize this) + + + + + Traverse 'treeCallee' and subtract out the inclusive time for any tree that matches 'idToExclude' from the node 'statsRet'. + This is needed in AggregateCallTrees because the same trees from the focus node are in the list to aggregate, but are also + in the subtree's in various places (and thus are counted twice). We solve this by walking this subtree (in this routine) + and subtracting out any nodes that match 'idToExclude'. + + As an optimization this routine also sets the m_recurision bit 'statsRet' if anywhere in 'treeCallee' we do find an id to + exclude. That way in a common case (where there is no instances of 'idToExclude') we don't have to actualy walk the + tree the second time (we simply know that there is no adjustment necessary. + + + + + An AggregateCallTree remembers all its samples by maintaining a list of call trees + that actually contain the samples that the Aggregate represents. m_trees hold this. + + + + + AggregateCallTreeNode can represent either a 'callers' tree or a 'callees' tree. For + the 'callers' tree case the node represented by the aggregate does NOT have same ID as + the tree in the m_trees list. Instead the aggregate is some node 'up the chain' toward + the caller. m_callerOffset keeps track of this (it is the same number for all elements + in m_trees). + + For callee nodes, this number is not needed. Thus we use a illegal value (-1) to + represent that fact that the node is a callee node rather than a caller node. + + + + + A Histogram is logically an array of floating point values. Often they + represent frequency, but it can be some other metric. The X axis can + represent different things (time, scenario). It is the HisogramContoller + which understands what the X axis is. Histograms know their HistogramController + but not the reverse. + + Often Histograms are sparse (most array elements are zero), so the represnetation + is designed to optimzed for this case (an array of non-zero index, value pairs). + + + + + Create a new histogram. Every histogram needs a controller but these controllers + can be shared among many histograms. + + + + + Add a sample to this histogram. + + The sample to add. + + + + Add an amount to a bucket in this histogram. + + The amount to add to the bucket. + The bucket to add to. + + + + Computes this = this + histogram * weight in place (this is updated). + + + + + The number of buckets in this histogram. + + + + + The that controls this histogram. + + + + + Get the metric contained in a bucket. + + The bucket to retrieve. + The metric contained in that bucket. + + + + Make a copy of this histogram. + + An independent copy of this histogram. + + + + A string representation (for debugging) + + + + + + Create a histogram that is a copy of another histogram. + + The histogram to copy. + + + + Implementes IEnumerable interface + + + + + Implementes IEnumerable interface + + + + + Get an IEnumerable that can be used to enumerate the metrics stored in the buckets of this Histogram. + + + + + The controller for this histogram. + + + + + A Histogram is conceputually an array of floating point values. A Histogram Controller + contains all the information besides the values themselves need to understand the array + of floating point value. There are alot of Histograms, however they all tend to share + the same histogram controller. Thus Histograms know their Histogram controller, but not + the reverse. + + Thus HistogramContoller is a abstract class (we have one for time, and one for scenarios). + + HistogramControllers are responsible for: + + - Adding a sample to the histogram for a node (see ) + - Converting a histogram to its string representation see () + - Managing the size and scale of histograms and their corresponding display strings + + + + + The scale factor for histograms controlled by this HistogramController. + + + + + The number of buckets in each histogram controlled by this HistogramController. + + + + + The number of characters in the display string for histograms controlled by this HistogramController. + Buckets are a logial concept, where CharacterCount is a visual concept (how many you can see on the + screen right now). + + + + + The CallTree managed by this HistogramController. + + + + + Force recalculation of the scale parameter. + + + + + Add a sample to the histogram for a node. + + The histogram to add this sample to. Must be controlled by this HistogramController. + The sample to add. + + Overriding classes are responsible for extracting the metric, scaling the metric, + determining the appropriate bucket or buckets, and adding the metric to the histogram using . + + + + + Gets human-readable information about a range of histogram characters. + + The start character index (inclusive). + The end character index (exclusive). + The histogram. + A string containing information about the contents of that character range. + + + + Convert a histogram into its display string. + + The histogram to convert to a string. + A string suitable for GUI display. + + + + A utility function that turns an array of floats into a ASCII character graph. + + + + + A utility function that turns an array of floats into a ASCII character graph. + + + + + Initialize a new HistogramController. + + The CallTree that this HistogramController controls. + + + + Calculate the scale factor for this histogram. + + The scale factor for this histogram. + + + + Calculates an average scale factor for a histogram. + + The root histogram to calculate against. + A scale factor that will normalize the maximum value to 200%. + + + + The scale parameter. 0.0 if uncalculated. + + + + + An enum representing a displayed histogram bucket (one character in a histogram string). + + + + + A HistogramCharacterIndex can be used to represent error conditions + + + + + A that groups histograms by scenarios. + + + + + Initialize a new ScenarioHistogramController. + + The CallTree to manage. + An ordered array of scenario IDs to display. + The total number of possible scenarios that can be supplied by the underlying StackSource. + This number might be larger than the highest number in . + The names of the scenarios (for UI use). + + + + Get a list of scenarios contained in a given bucket. + + The bucket to look up. + The scenarios contained in that bucket. + + + + Get a list of scenarios contained in a given bucket range. + + The start of the bucket range (inclusive). + The end of the bucket range (exclusive). + The scenarios contained in that range of buckets. + + + + Add a sample to a histogram controlled by this HistogramController. + + The histogram to add the sample to. + The sample to add. + + + + Get the human-readable name for a scenario. + + The ID of the scenario to look up. + The human-readable name for that scenario. + + + + Get the human-readable names for all scenarios contained in a range of histogram characters. + + The (inclusive) start index of the range. + The (exclusive) end index of the range. + The histogram. + A comma-separated list of scenario names contained in that range. + + + + Convert a histogram into a string suitable for UI display. + + The histogram to convert. + A string representing the histogram that is suitable for UI display. + + + + Calculate the scale factor for all histograms controlled by this ScenarioHistogramController. + + + In the current implementation, returns a scale that normalizes 100% to half of the maximum value at the root. + + + + + An array mapping each scenario to a bucket. + + + + + An array mapping each bucket to a list of scenarios. + + + + + An array mapping each scenario to its name. + + + + + A HistogramController holds all the information to understand the buckets of a histogram + (basically everything except the array of metrics itself. For time this is the + start and end time + + + + + Create a new TimeHistogramController. + + The CallTree to control with this controller. + The start time of the histogram. + The end time of the histogram. + + + + The start time of the histogram. + + + + + The end time of the histogram. + + + + + Gets the start time for the histogram bucket represented by a character. + + The index of the character to look up. + The start time of the bucket represented by the character. + + + + The duration of time represented by each bucket. + + + + + Implements HistogramController interface + + + + + Implements HistogramController interface + + + + + Implements HistogramController interface + + + + + Implements HistogramController interface + + + + + This structure provides a clean API for a lightweight recursion stack guard to prevent StackOverflow exceptions + We do ultimately do a stack-overflow to prevent infinite recursion, but it is now under our + control and much larger than you may get on any one thread stack. + + + + + For recursive methods that need to process deep stacks, this constant defines the limit for recursion within + a single thread. After reaching this limit, methods need to trampoline to a new thread before continuing to + recurse. + + + + + To prevent run-away recursion, fail after this depth (in this case 20*400 = 8K) + + + + + The amount of recursion we have currently done. + + + + + Gets the recursion guard for entering a recursive method. + + + This is equivalent to the default value. + + + + + Gets an updated recursion guard for recursing into a method. + + + + + Gets an updated recursion guard for continuing execution on a new thread. + + + + + Gets a value indicating whether the current operation has exceeded the recursion depth for a single thread, + and needs to continue executing on a new thread. + + + + + exports provided StackSource to a https://www.speedscope.app/ format + schema: https://www.speedscope.app/file-format-schema.json + + + + + we want to identify the thread for every sample to prevent from + overlaping of samples for the concurrent code so we group the samples by Threads + this method also sorts the samples by relative time (ascending) + + + + + this method fixes the metrics of the samples to make sure they don't overlap + it's very common that following samples overlap by a very small number like 0.0000000000156 + we can't allow for that to happen because the SpeedScope can't draw such samples + + + + + all the samples that we have are leafs (last sample in the call stack) + this method expands those samples to full information + it walks the stack up to the begining and adds a sample for every method on the stack + it's required to build full information + + + + + this method aggregates all the singular samples to continuous events + example: samples for Main taken at time 0.1 0.2 0.3 0.4 0.5 + are gonna be translated to Main start at 0.1 stop at 0.5 + + + + + this method checks if both samples do NOT belong to the same profile event + + + + + this method adds a new profile event for provided samples + it also make sure that a profile event does not open and close at the same time (would be ignored by SpeedScope) + + + + + this method orders the profile events in the order required by SpeedScope + it's just the order of drawing the time graph + + + + + writes pre-calculated data to SpeedScope format + + + + + A stack source is a logically a list of StackSourceSamples. Each sample has a metric and stack (hence the name StackSource) + The stacks are represented as indexes that the StackSourceStacks base class can resolve into frame names and stack chains. + The result is very efficient (no string processing) way of processing the conceptual list of stack samples. + + + + + Call 'callback' on every sample in the StackSource. Will be done linearly and only + one callback will be active simultaneously. + + + + + Call 'callback' on every sample in the StackSource. Will be done linearly and only + one callback will be active simultaneously. + + + + + If this is overridden to return true, then during the 'Foeach' callback you can save references + to the samples you are given because they will not be overridden by the stack source. If this is + false you must make a copy of the sample if you with to remember it. + + + + + Also called 'callback' on every sample in the StackSource however there may be more than + one callback running simultaneously. Thus 'callback' must be thread-safe and the order + of the samples should not matter. If desiredParallelism == 0 (the default) then the + implementation will choose a good value of parallelism. + + + + + If this stack source is a source that simply groups another source, get the base source. It will return + itself if there is no base source. + + + + + If this source supports fetching the samples by index, this is how you get it. Like ForEach the sample that + is returned is not allowed to be modified. Also the returned sample will become invalid the next time GetSampleIndex + is called (we reuse the StackSourceSample on each call) + + + + + Returns the limit on stack samples indexes (all index are strictly less than this). Returns 0 if unknown. + + + + + Returns a time which is greater than or equal the timestamp of any sample in the StackSource. Returns 0 if unknown. + + + + + In addition to Time and Metric a sample can have a Scneario number associated with it. ScenarioCount + returns the number of such scnearios. Returning 0 implies no scenario support. + + + + + StackSources can optionally support a sampling rate. If the source supports it it will return + non-null for the current sampling rate (1 if it is doing nothing). Sampling is a way of speeding + things up. If you sample at a rate of 10, it means that only one out of every 10 samples is actually + produced by 'ForEach'. Note that it is expected that when the sampling rate is set the + source will correspondingly adjust the CountMultiplier, so that the total will look like no sampling + is occuring + + + + + If each 'callstack' is really a node in a graph (like MemoryGraphStackSource) + Then return true. If this returns true 'GetRefs' works. + + + + + Only used if IsGraphSource==true. If 'direction' is 'From' Calls 'callback' for node that is referred to FROM nodeIndex. + If 'direction' is 'To' then it calls 'callback' for every node that refers TO nodeIndex. This API returns references + that are not necessarily a tree (they can for DAGs or have cycles). + + + + + Dump the stack source to a file as XML. Used for debugging. + + + + + Dump the stack source to a TextWriter as XML. Used for debugging. + + + + + RefDirection represents the direction of the references in a heap graph. + + + + + Indicates that you are interested in referneces FROM the node of interest + + + + + Indicates that you are interested in referneces TO the node of interest + + + + + Samples have stacks (lists of frames, each frame contains a name) associated with them. This interface allows you to get + at this information. We don't use normal objects to represent these but rather give each stack (and frame) a unique + (dense) index. This has a number of advantages over using objects to represent the stack. + + * Indexes are very serialization friendly, and this data will be presisted. Thus indexes are the natural form for data on disk. + * It allows the data to be read from the serialized format (disk) lazily in a very straightfoward fashion, keeping only the + hottest elements in memory. + * Users of this API can associate additional data with the call stacks or frames trivially and efficiently simply by + having an array indexed by the stack or frame index. + + So effectively a StackSourceStacks is simply a set of 'Get' methods that allow you to look up information given a Stack or + frame index. + + + + + Given a call stack, return the call stack of the caller. This function can return StackSourceCallStackIndex.Discard + which means that this sample should be discarded. + + + + + For efficiency, m_frames are assumed have a integer ID instead of a string name that + is unique to the frame. Note that it is expected that GetFrameIndex(x) == GetFrameId(y) + then GetFrameName(x) == GetFrameName(y). The converse does NOT have to be true (you + can reused the same name for distinct m_frames, however this can be confusing to your + users, so be careful. + + + + + FilterStackSources can combine more than one frame into a given frame. It is useful to know + how many times this happened. Returning 0 means no combining happened. This metric does + not include grouping, but only folding. + + + + + Get the frame name from the FrameIndex. If 'verboseName' is true then full module path is included. + + + + + all StackSourceCallStackIndex are guaranteed to be less than this. Allocate an array of this size to associate side information + + + + + all StackSourceFrameIndex are guaranteed to be less than this. Allocate an array of this size to associate side information + + + + + True if it only has managed code stacks. Otherwise false. + + + + + Computes the depth (number of callers), associated with callStackIndex. This routine is O(n) and mostly useful for debugging. + + + + + Returns an XML string representation of a 'sample'. For debugging. + + + + + Returns an XML string representation of a 'callStackIndex'. For debugging. + + + + + StackSourceSample represents a single sample that has a stack. It has a number of predefined data items associate with it + including a stack, a metric and a time as well as other optional fields. Note that all its properties are read-write. + It is basically a named tuple. + + StackSource.ProductSamples push these. + + In general StackSourceSample are NOT immutable but expected to be overwritted frequently. Thus you need to copy + the sample if you want to keep a refernece to it. + + + + + The Stack associated with the sample + + + + + The metric (cost) associated with the sample + + + + + If the source supports fetching samples by some ID, then SampleIndex returns this ID for the sample and + GetSampleByIndex is the API that converts this index into a sample again. + + + + + The time associated with the sample. (can be left 0) + + + + + Normally the count of a sample is 1, however when you take a statistical sample, and you also have + other constraints (like you do when you are going a sample of heap memory), you may need to have the + count adjusted to something else. + + + + + A scenario is simply a integer that represents some group the sample belongs to. + + + + + Returns an XML string representing the sample + + + + + Returns an XML string representing the sample, howevever this one can actually expand the stack because it is given the source + + + + + Create a StackSourceSample which is associated with 'source'. + + + + + Copy a StackSourceSample from 'template' + + + + + + Identifies a particular sample from the sample source, it allows 3rd parties to attach additional + information to the sample by creating an array indexed by sampleIndex. + + + + + Returned when no appropriate Sample exists. + + + + + An opaque handle that are 1-1 with a complete call stack + + + + + + The first real call stack index (after the pseudo-ones before this) + + + + + Returned when no appropriate CallStack exists. (Top of stack) + + + + + Identifies a particular frame within a stack It represents a particular instruction pointer (IP) location + in the code or a group of such locations. + + + + + Pseduo-node representing the root of all stacks + + + + + Pseduo-frame that represents the caller of all broken stacks. + + + + + Unknown what to do (Must be before the 'special ones below') // Non negative represents normal m_frames (e.g. names of methods) + + + + + Profiling overhead (rundown) + + + + + The first real call stack index (after the pseudo-ones before this) + + + + + Should not happen (uninitialized) (also means completely folded away) + + + + + Sample has been filtered out (useful for filtering stack sources) + + + + + A StackSourceModuleIndex uniquely identifies a module to the stack source. + + + + + Start is where 'ordinary' module indexes start. + + + + + Invalid is a module index that is never used and can be used to signal error conditions. + + + + + This stack source takes another and copies out all its events. This allows you to 'replay' the source + efficiently when the original source only does this inefficiently. + + + + + Create a CopyStackSource that has no samples in it. It can never have samples so it is only useful as a placeholder. + + + + + Create a CopyStackSource that you can add samples which use indexes that 'sourceStacks' can decode. All samples + added to the stack source must only refer to this StackSourceStacks + + + + + Add a sample to stack source. it will clone 'sample' so sample can be overwritten after this method returns. + It is an error if 'sample' does not used the StackSourceStacks passed to the CopyStackSource at construction. + + + + + Create a clone of the given stack soruce. + + + + + + + Returns the StackSourceStacks that can interpret indexes for this stack source. + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Like CopyStackSource InternStackSource copies the samples. however unlike CopyStackSource + InternStackSource copies all the information in the stacks too (mapping stack indexes to names) + Thus it never refers to the original source again). It also interns the stacks making for + an efficient representation of the data. This is useful when the original source is expensive + to iterate over. + + + + + Compute the difference between two sources of stacks. + + + + + Compute only the delta of source from the baseline. This variation allows you to specify + the unfiltered names (the sourceStacks and baselineStacks) but otherwise keep the filtering. + + + + + Create a new stack source that can create things out of nothing. + + + + + Create a new InternStackSource + + + + + Returns the Interner, which is the class that holds the name->index mappings that that every + name has a unique index. + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + InternFullStackFromSource will take a call stack 'baseCallStackIndex' from the source 'source' and completely copy it into + the intern stack source (interning along the way of course). Logically baseCallStackIndex has NOTHING to do with any of the + call stack indexes in the intern stack source. + + + + + StackSourceInterner is a helper class that knows how to intern module, frame and call stacks. + + + + + Create a new StackSourceInterner. Optionally supply estimates on how many items you need and where the frame, callstack and module indexes start. + + + + + As an optimization, if you are done adding new nodes, then you can call this routine can abandon + some tables only needed during the interning phase. + + + + + The CallStackStartIndex value passed to the constructor + + + + + The FrameStartIndex value passed to the constructor + + + + + Given a StackSourceCallStackIndex return the StackSourceCallStackIndex of the caller + + + + + Given a StackSourceCallStackIndex return the StackSourceFrameIndex for the Frame associated + with the top call stack + + + + + Get a name from a frame index. If the frame index is a + + + + + Given a StackSourceFrameIndex return the StackSourceModuleIndex associated with the frame + + + + + + + If you intern frames as derived frames, when GetFrameName is called the interner needs to know + how to look up the derived frame from its index. This is the function that is called. + + It is called with the frame index and a boolean which indicates whether the full path of the module + should be specified, and returns the frame string. + + + + + Lookup or create a StackSourceModuleIndex for moduleName + + + + + Lookup or create a StackSourceFrameIndex for frame with the name frameName and the module identified by moduleIndex + + + + + You can also create frames out of other frames using this method. Given an existing frame, and + a suffix 'frameSuffix' + + + + + Lookup or create a StackSourceCallStackIndex for a call stack with the frame identified frameIndex and caller identified by callerIndex + + + + + The current number of unique frames that have been interned so far + + + + + The current number of unique call stacks that have been interned so far + + + + + A specialized hash table for interning. + It loosely follows the implementation of but with + several key allowances for known usage patterns: + 1. We don't store the hashcode on each entry on the assumption that values can be compared + as quickly as recomputing hash codes. The downside to that is that the hash codes must + be recomputed whenever the map is resized, but that is very cheap. + 2. We supply a single method (instead of a TryGetValue + followed by an Add) so that a hashcode computation is saved in the case of a "miss". + 3. We don't support removal. This means we don't need to keep track of a free list and neither + do we need sentinel values. This also allows us to use all 32 bits of the hash-code (where + uses only 31 bits, reserving -1 to indicate a freed + entry. The only sentinel value is in the array to indicate a free + bucket. + 4. We return an index (of the interned item) to the caller which can be used for constant-time + look-up in the table via . + 5. To free up memory, the caller can call . The entries themselves + are stored separately from the indexing parts of the table so that the latter can be dropped + easily. + + + + + Construct the intern map + + The estimated capacity of the map. + + + + Count of interned values. + + + + + Access an element by index. + + The zero-based index of the desired entry. + The entry at the requested index. + For performance, in Release mode we do no range checking on , so it is possible to + access an entry beyond but prior to the maximum capacity of the array. + was less than zero or greater than the capacity. + + + + Intern a value. If the same value has been seen before + then this returns the index of the previously seen entry. If not, a new entry + is added and this returns the index of the newly added entry. + + The candidate value. + The index of the interned entry. + This routine was called after calling . + + + + As an optimization, if you are done calling , then you can call this + to free up some memory. + + After calling this, you can still call . However, if you try to + call you will get a . + + + + Elements representing the structure of the hash table. The structure is + a collection of singly linked lists, one list per 'bucket' where a + bucket number is selected by taking the hash code of an incoming item + and mapping it onto the array (see ). + + + Caution: For a given , and + are UNRELATED to each other. Logically, you can + think of as being part of a value in the + table. (We don't actually do that in order to + support efficiently.) + To find the next element in the linked list, you should NOT simply + look at . Instead, you should first look up the + in the array indexed by + and look at the field of that. + + + + + Index into the array of the head item in the linked list or + -1 to indicate an empty bucket. + + + + + Index into the array of the next item in the linked list or + -1 to indicate that this is the last item. + + + + + TraceEventStackSource is an implementation of a StackSource for ETW information (TraceLog) + It takes a TraceEvents (which is a list of TraceEvents you get get from a TraceLog) and + implements that StackSource protocol for them. (thus any code needing a StackSource + can then work on it. + + The key to the implementation is how StackSourceFrameIndex and StackSourceCallStackIndex + (part of the StackSource protocol) are mapped to the Indexes in TraceLog. Here is + the mapping. + + TraceEventStackSource create the following meaning for the StackSourceCallStackIndex + + * The call stacks ID consists of the following ranges concatenated together. + * a small set of fixed Pseudo stacks (Start marks the end of these) + * CallStackIndex + * ThreadIndex + * ProcessIndex + * BrokenStacks (One per thread) + * Stacks for CPU samples without explicit stacks (we make 1 element stacks out of them) + + TraceEventStackSource create the following meaning for the StackSourceFrameIndex + + The frame ID consists of the following ranges concatenated together. + * a small fixed number of Pseudo frame (Broken, and Unknown) + * MaxCodeAddressIndex - something with a TraceCodeAddress. + * ThreadIndex - ETW stacks don't have a thread or process node, so we add them. + * ProcessIndex + + + + + Creates a new TraceEventStackSource given a list of events 'events' from a TraceLog + + + + + + Returns the TraceLog file that is associated with this stack source. + + + + + Normally addresses without symbolic names are listed as ?, however sometimes it is useful + to see the actual address as a hexadecimal number. Setting this will do that. + + + + + Looks up symbols for all modules that have an inclusive count >= minCount. + stackSource, if given, can be used to be the filter. If null, 'this' is used. + If stackSource is given, it needs to use the same indexes for frames as 'this'. + shouldLoadSymbols, if given, can be used to filter the modules. + + + + + Given a frame index, return the corresponding code address for it. This is useful for looking up line number information. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Returns a list of modules for the stack 'stackIdx'. It also updates the interning table stackModuleLists, so + that the entry cooresponding to stackIdx remembers the answer. This can speed up processing alot since many + stacks have the same prefixes to root. + + + + + A ModuleList is a linked list of modules. It is only used in GetModulesForStack and LookupWarmSymbols + + + + + This maps pseudo-stacks to their index (thus it is the inverse of m_pseudoStack; + + + + + Given a thread and a call stack that does not have a stack, make up a pseudo stack for it consisting of the code address, + the broken node, the thread and process. Will return -1 if it can't allocate another Pseudo-stack. + + + + + Like a TraceEventStackSource a MutableTraceEventStackSource allows you incorporate the stacks associated with + a TraceEvent as a sample in the StackSource. However in addition it allows you to create new frames for these + stacks on the fly as well as add samples that did not exist in the original TraceEvent stream. This gives you + a lot of flexibility to add additional data to the original stream of TraceEvents. + + Like TraceEventStackSource MutableTraceEventStackSource supports the GetFrameCodeAddress() method that allows + you to map from the StackSourceFrameIndex back its TraceLog code address (that lets you get at the source code and + line number for that frame). + + + + + Create a new MutableTraceEventStackSource that can represent stacks comming from any events in the given TraceLog with a stack. + You use the 'AddSample' and 'DoneAddingSamples' to specify exactly which stacks you want in your source. + + + + + After creating a MultableTraceEventStackSource, you add the samples you want using this AddSample API (you can reuse 'sample' + used as an argument to this routine. It makes a copy. The samples do NOT need to be added in time order (the MultableTraceEventStackSource + will sort them). When you done DoneAddingSamples must be called before using the + the MutableTraceEventStackSource as a stack source. + + + + + After calling 'AddSample' to add the samples that should belong to the source, DoneAddingSamples() should be called to + to complete the construction of the stack source. Only then can the reading API associated with the stack source be called. + + + + + The Interner is the class that allows you to make new indexes out of strings and other bits. + + + + + Returns a StackSourceCallStackIndex representing just one entry that represents the process 'process' + + + + + Returns a StackSourceCallStackIndex representing just two entries that represent 'thread' which has a parent of its process. + + + + + Returns a StackSourceCallStackIndex representing the call stack from the TraceLog represented by the CallStackIndex 'callStackIndex'. + If that stack is invalid, use 'thread' to at least return a call stack for the thread. + + + + + Returns a StackSourceCallStackIndex representing the call stack from the TraceLog represented by the CallStackIndex 'callStackIndex'. + Use the TraceEvent 'data' to find the stack if callStackIndex is invalid. + TODO data should be removed (or callstack derived from it) + + + + + A very simple IDictionary-like interface for remembering values in GetCallStack() + + + + + Fetches an value given a key + + + + + Sets a key-value pair + + + + + Find the StackSourceCallStackIndex for the TraceEvent call stack index 'callStackIndex' which has a top of its + stack (above the stack, where the thread and process would normally go) as 'top'. If callStackMap is non-null + it is used as an interning table for CallStackIndex -> StackSourceCallStackIndex. This can speed up the + transformation dramatically. It will still work if it is null. + + + + + + Create a frame name from a TraceLog code address. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + private + + + + + private + + + + + TraceEventSource is an abstract base class that represents the output of a ETW session (e.g. a ETL file + or ETLX file or a real time stream). This base class is NOT responsible for actually processing + the events, but contains methods for properties associated with the session + like its start and end time, filename, and characteristics of the machine it was collected on. + This class has two main subclasses: + * which implements a 'push' (callback) model and is the only mode for ETL files. + ETWTraceEventSource is the most interesting subclass of TraceEventDispatcher. + * see TraceLog which implements both a 'push' (callback) as well as pull (foreach) model but only works on ETLX files. + This is the end. + The normal user pattern is to create a TraceEventSource, create TraceEventParsers attached to the TraceEventSource, and then subscribe + event callbacks using the TraceEventParsers + + + + + For convenience, we provide a property returns a ClrTraceEventParser that knows + how to parse all the Common Language Runtime (CLR .NET) events into callbacks. + + + + + For convenience, we provide a property returns a KernelTraceEventParser that knows + how to parse all the Kernel events into callbacks. + + + + + For convenience, we provide a property returns a DynamicTraceEventParser that knows + how to parse all event providers that dynamically log their schemas into the event streams. + In particular, it knows how to parse any events from a System.Diagnostics.Tracing.EventSources. + + Note that the DynamicTraceEventParser has subsumed the functionality of RegisteredTraceEventParser + so any registered providers are also looked up here. + + + + + For convenience, we provide a property returns a RegisteredTraceEventParser that knows + how to parse all providers that are registered with the operating system. + + Because the DynamicTraceEventParser has will parse all providers that that RegisteredTraceEventParser + will parse, this function is obsolete, you should use Dynamic instead. + + + + + The time when session started logging. + + + + + The time that the session stopped logging. + + + + + The Session End time expressed as milliseconds from the start of the session + + + + + The difference between SessionEndTime and SessionStartTime; + + + + + The size of the trace, if it is known. Will return 0 if it is not known. + + + + + Returns the size of a pointer on the machine where events were collected (4 for 32 bit or 8 for 64 bit) + + + + + The number of events that were dropped (e.g. because the incoming event rate was too fast) + + + + + The number of processors on the machine doing the logging. + + + + + Cpu speed of the machine doing the logging. + + + + + The version of the windows operating system on the machine doing the logging. + + + + + Returns true if this is a real time session. + + + + + Time based threshold for how long data should be retained + by accumulates that are processing this TraceEventSource. + A value of 0, the default, indicates an infinite accumulation. + + + + + Check if a DataLifetime model is enabled + + True - lifetime tracking is enabled + False - lifetime tracking is not enabled + + + + Closes any files and cleans up any resources associated with this TraceEventSource + + + + + TraceEventSource supports attaching arbitrary user data to the source. This property returns a key-value bag of these attached values. + + One convention that has been established is that TraceEventParsers that need additional state to parse their events should + store them in UserData under the key 'parsers\(ParserName)' + + + + + + Dispose pattern + + + + + This is the high frequency tick clock on the processor (what QueryPerformanceCounter uses). + You should not need + + + + + Converts the Query Performance Counter (QPC) ticks to a number of milliseconds from the start of the trace. + + + + + Converts a Relative MSec time to the Query Performance Counter (QPC) ticks + + + + + Converts a DateTime to the Query Performance Counter (QPC) ticks + + + + + Converts the Query Performance Counter (QPC) ticks to a DateTime + + + + + Some events (like HardFault) do not have a thread ID or a process ID, but they MIGHT have a Stack + If they do try to get the ThreadID for the event from that. Return -1 if not successful. + This is intended to be overridden by the TraceLog class that has this additional information. + + + + + TraceEvent an abstract class represents the data from one event in the stream of events in a TraceEventSource. + The TraceEvent class has all the properties of an event that are common to all ETW events, including TimeStamp + ProviderGuid, ProcessID etc. Subclasses of TraceEvent then extend this abstract class to include properties + specific to a particular payload. + + An important architectural point is that TraceEvent classes are aggressively reused by default. The TraceEvent that is + passed to any TraceEventParser callback or in a foreach is ONLY valid for the duration for that callback (or one + iteration of the foreach). If you need save a copy of the event data, you must call the Clone() method to make + a copy. The IObservable interfaces (TraceEventParser.Observe* methods) however implicitly call Clone() so you + do not have to call Clone() when processing with IObservables (but these are slower). + + + + + + The GUID that uniquely identifies the Provider for this event. This can return Guid.Empty for classic (Pre-VISTA) ETW providers. + + + + + The name of the provider associated with the event. It may be of the form Provider(GUID) or UnknownProvider in some cases but is never null. + + + + + A name for the event. This is simply the concatenation of the task and opcode names (separated by a /). If the + event has no opcode, then the event name is just the task name. + + + + + Returns the provider-specific integer value that uniquely identifies event within the scope of + the provider. (Returns 0 for classic (Pre-VISTA) ETW providers). + + + + + Events for a given provider can be given a group identifier (integer) called a Task that indicates the + broad area within the provider that the event pertains to (for example the Kernel provider has + Tasks for Process, Threads, etc). + + + + + The human readable name for the event's task (group of related events) (eg. process, thread, + image, GC, ...). May return a string Task(GUID) or Task(TASK_NUM) if no good symbolic name is + available. It never returns null. + + + + + An opcode is a numeric identifier (integer) that identifies the particular event within the group of events + identified by the event's task. Often events have opcode 'Info' (0), which is the default. This value + is interpreted as having no-opcode (the task is sufficient to identify the event). + + Generally the most useful opcodes are the Start and Stop opcodes which are used to indicate the beginning and the + end of a interval of time. Many tools will match up start and stop opcodes automatically and compute durations. + + + + + + Returns the human-readable string name for the Opcode property. + + + + + The verbosity of the event (Fatal, Error, ..., Info, Verbose) + + + + + The version number for this event. The only compatible change to an event is to add new properties at the end. + When this is done the version numbers is incremented. + + + + + ETW Event providers can specify a 64 bit bitfield called 'keywords' that define provider-specific groups of + events which can be enabled and disabled independently. + Each event is given a keywords mask that identifies which groups the event belongs to. This property returns this mask. + + + + + A Channel is a identifier (integer) that defines an 'audience' for the event (admin, operational, ...). + Channels are only used for Windows Event Log integration. + + + + + The time of the event. You may find TimeStampRelativeMSec more convenient. + + + + + Returns a double representing the number of milliseconds since the beginning of the session. + + + + + The thread ID for the thread that logged the event + This field may return -1 for some events when the thread ID is not known. + + + + + The process ID of the process which logged the event. + This field may return -1 for some events when the process ID is not known. + + + + + Returns a short name for the process. This the image file name (without the path or extension), + or if that is not present, then the string 'Process(XXXX)' + + + + + The processor Number (from 0 to TraceEventSource.NumberOfProcessors) that logged this event. + event. + + + + + Get the size of a pointer associated with process that logged the event (thus it is 4 for a 32 bit process). + + + + + Conceptually every ETW event can be given a ActivityID (GUID) that uniquely identifies the logical + work being carried out (the activity). This property returns this GUID. Can return Guid.Empty + if the thread logging the event has no activity ID associated with it. + + + + + ETW supports the ability to take events with another GUID called the related activity that is either + causes or is caused by the current activity. This property returns that GUID (or Guid.Empty if the + event has not related activity. + + + + + Event Providers can define a 'message' for each event that are meant for human consumption. + FormattedMessage returns this string with the values of the payload filled in at the appropriate places. + It will return null if the event provider did not define a 'message' for this event + + + + + Creates and returns the value of the 'message' for the event with payload values substituted. + Payload values are formatted using the given formatProvider. + + + + + An EventIndex is a integer that is guaranteed to be unique for this event over the entire log. Its + primary purpose is to act as a key that allows side tables to be built up that allow value added + processing to 'attach' additional data to this particular event unambiguously. + This property is only set for ETLX file. For ETL or real time streams it returns 0 + EventIndex is currently a 4 byte quantity. This does limit this property to 4Gig of events + + + + + The TraceEventSource associated with this event. + + + + + Returns true if this event is from a Classic (Pre-VISTA) provider + + + + + Returns the names of all the manifest declared field names for the event. May be empty if the manifest is not available. + + + + + Given an index from 0 to PayloadNames.Length-1, return the value for that payload item as an object (boxed if necessary). + + + + + PayloadString is like PayloadValue(index).ToString(), however it can do a better job in some cases. In particular + if the payload is a enumeration or a bitfield and the manifest defined the enumeration values, then it will print the string name + of the enumeration value instead of the integer value. + + + + + Returns the index in 'PayloadNames for field 'propertyName'. Returns something less than 0 if not found. + + + + + PayloadByName fetches the value of a payload property by the name of the property. + It will return null if propertyName is not found. + This method is not intended to be used in performance critical code. + + + + + PayloadStringByName functions the same as PayloadByName, but uses PayloadString instead of PayloadValue. + It will return null if propertyName is not found. + This method is not intended to be used in performance critical code. + + + + + The size of the event-specific data payload. (see EventData) + Normally this property is not used because some TraceEventParser has built a subclass of + TraceEvent that parses the payload + + + + + Returns an array of bytes representing the event-specific payload associated with the event. + Normally this method is not used because some TraceEventParser has built a subclass of + TraceEvent that parses the payload + + + + + Gets the event data and puts it in 'targetBuffer' at 'targetStartIndex' and returns the resulting buffer. + If 'targetBuffer is null, it will allocate a buffer of the correct size. + Normally this method is not used because some TraceEventParser has built a subclass of + TraceEvent that parses the payload + + + + + The events passed to the callback functions only last as long as the callback, so if you need to + keep the information around after that you need to copy it. This method makes that copy. + This method is more expensive than copy out all the event data from the TraceEvent instance + to a type of your construction. + + + + + Pretty print the event. It uses XML syntax.. + + + + + Pretty print the event using XML syntax, formatting data using the supplied IFormatProvider + + + + + Write an XML representation to the stringBuilder sb and return it. + + + + + Writes an XML representation of the event to a StringBuilder sb, formatting data using the passed format provider. + Returns the StringBuilder. + + + + + Dumps a very verbose description of the event, including a dump of they payload bytes. It is in + XML format. This is very useful in debugging (put it in a watch window) when parsers are not + interpreting payloads properly. + + + + + EventTypeUserData is a field users get to use to attach their own data on a per-event-type basis. + + + + + Returns the raw IntPtr pointer to the data blob associated with the event. This is the way the + subclasses of TraceEvent get at the data to display it in a efficient (but unsafe) manner. + + + + + Create a template with the given event meta-data. Used by TraceParserGen. + + + + + Skip UTF8 string starting at 'offset' bytes into the payload blob. + + Offset just after the string + + + + Skip Unicode string starting at 'offset' bytes into the payload blob. + + Offset just after the string + + + + Skip 'stringCount' Unicode strings starting at 'offset' bytes into the payload blob. + + Offset just after the last string + + + + Skip a Security ID (SID) starting at 'offset' bytes into the payload blob. + + Offset just after the Security ID + + + + Trivial helper that allows you to get the Offset of a field independent of 32 vs 64 bit pointer size. + + The Offset as it would be on a 32 bit system + The number of pointer-sized fields that came before this field. + + + + + Computes the size of 'numPointers' pointers on the machine where the event was collected. + + + + + Given an Offset to a null terminated ASCII string in an event blob, return the string that is + held there. + + + + + Returns the string represented by a fixed length ASCII string starting at 'offset' of length 'charCount' + + + + + Given an Offset to a fixed sized string at 'offset', whose buffer size is 'charCount' + Returns the string value. A null in the string will terminate the string before the + end of the buffer. + + + + + Returns the encoding of a Version 6 IP address that has been serialized at 'offset' in the payload bytes. + + + + + Returns the GUID serialized at 'offset' in the payload bytes. + + + + + Get the DateTime that serialized (as a windows FILETIME) at 'offset' in the payload bytes. + + + + + Given an Offset to a null terminated Unicode string in an payload bytes, return the string that is + held there. + + + + + Give an offset to a byte array of size 'size' in the payload bytes, return a byte[] that contains + those bytes. + + + + + Returns a byte value that was serialized at 'offset' in the payload bytes + + + + + Returns a short value that was serialized at 'offset' in the payload bytes + + + + + Returns an int value that was serialized at 'offset' in the payload bytes + + + + + Returns a long value that was serialized at 'offset' in the payload bytes + + + + + Get something that is machine word sized for the provider that collected the data, but is an + integer (and not an address) + + + + + Gets something that is pointer sized for the provider that collected the data. + + + + + Returns an int float (single) that was serialized at 'offset' in the payload bytes + + + + + Returns an int double precision floating point value that was serialized at 'offset' in the payload bytes + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Prints a standard prefix for a event (includes the time of the event, the process ID and the + thread ID. + + + + + Because we want the ThreadID to be the ID of the CREATED thread, and the stack + associated with the event is the parentThreadID + + + + + Returns (or sets) the delegate associated with this event. + + + + + If this TraceEvent belongs to a parser that needs state, then this callback will set the state. + Parsers with state are reasonably rare, the main examples are KernelTraceEventParser and ClrTraceEventParser. + + + + + Returns the Timestamp for the event using Query Performance Counter (QPC) ticks. + The start time for the QPC tick counter is arbitrary and the units also vary. + + + + + A standard way for events to are that certain addresses are addresses in code and ideally have + symbolic information associated with them. Returns true if successful. + + + + + Was this written with the windows EventWriteString API? (see also EventDataAsString) + + + + + Used for binary searching of event IDs. Abstracts the size (currently a int, could go to long) + + + + + Returns true if the two traceEvents have the same identity. + + + + + Normally TraceEvent does not have unmanaged data, but if you call 'Clone' it will. + + + + + For debugging. dumps an array. If you specify a size of 0 (the default) it dumps the whole array. + + + + + If the event data looks like a unicode string, then return it. This is heuristic. (See also IsEventWriteString) + + + + + + Each TraceEvent items knows where it should Dispatch to. + ETWTraceEventSource.Dispatch calls this function to go to the right placed. By default we + do nothing. Typically a subclass just dispatches to another callback that passes itself to a + type-specific event callback. + + + + + This is a DEBUG-ONLY routine that allows a routine to do consistency checking in a debug build. + + + + + Validate that the events is not trash. + + + + + TraceEvent knows where to dispatch to. To support many subscriptions to the same event we chain + them. + + + + + The array of names for each property in the payload (in order). + + + + + Individual event providers can supply many different types of events. These are distinguished from each + other by a TraceEventID, which is just a 16 bit number. Its meaning is provider-specific. + + + + + Illegal is a EventID that is not used by a normal event. + + + + + Providers can define different audiences or Channels for an event (eg Admin, Developer ...). + It is only used for Windows Event log support. + + + + + The default channel. + + + + + There are certain classes of events (like start and stop) which are common across a broad variety of + event providers for which it is useful to treat uniformly (for example, determining the elapsed time + between a start and stop event). To facilitate this, event can have opcode which defines these + common operations. Below are the standard ones but providers can define additional ones. + + + + + Generic opcode that does not have specific semantics associated with it. + + + + + The entity (process, thread, ...) is starting + + + + + The entity (process, thread, ...) is stoping (ending) + + + + + The entity (process, thread, ...) did not terminate before data collection ended, so indicate + this at data collection termination time. + + + + + The entity (process, thread, ...) did not terminate before data collection ended, so indicate + this at data collection termination time. This is mostly for 'flight recorder' scenarios where + you only have the 'tail' of the data and would like to know about everything that existed. + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Indicates to a provider whether verbose events should be logged. + + + + + Always log the event (It also can mean that the provider decides the verbosity) You probably should not use it.... + + + + + Events that indicate critical conditions + + + + + Events that indicate error conditions + + + + + Events that indicate warning conditions + + + + + Events that indicate information + + + + + Events that verbose information + + + + + ETW defines the concept of a Keyword, which is a 64 bit bitfield. Each bit in the bitfield + represents some provider defined 'area' that is useful for filtering. When processing the events, it + is then possible to filter based on whether various bits in the bitfield are set. There are some + standard keywords, but most are provider specific. + + + + + No event groups (keywords) selected + + + + + All event groups (keywords) selected + + + + + Tasks are groups of related events for a given provider (for example Process, or Thread, Kernel Provider). + They are defined by the provider. + + + + + If you don't explicitly choose a task you get the default + + + + + EventIdex is a unsigned integer that is unique to a particular event. EventIndex is guaranteed to be + unique over the whole log. It is only used by ETLX files. + + Currently the event ID simply the index in the log file of the event. We don't however guarantee ordering. + In the future we may add new events to the log and given them IDs 'at the end' even if the events are not + at the end chronologically. + + + EventIndex is a 32 bit number limits it to 4Gig events in an ETLX file. + + + + + + Invalid is an EventIndex that will not be used by a normal event. + + + + + TraceEventSource has two roles. The first is the obvious one of providing some properties + like 'SessionStartTime' for clients. The other role is provide an interface for TraceEventParsers + to 'hook' to so that events can be decoded. ITraceParserServices is the API service for this + second role. It provides the methods that parsers register templates for subclasses of + the TraceEvent class that know how to parse particular events. + + + + + RegisterEventTemplate is the mechanism a particular event payload description 'template' + (a subclass of TraceEvent) is injected into the event processing stream. Once registered, an + event is 'parsed' simply by setting the 'rawData' field in the event. It is up to the template + then to take this raw data an present it in a useful way to the user (via properties). Note that + parsing is thus 'lazy' in no processing of the raw data is not done at event dispatch time but + only when the properties of an event are accessed. + + Ownership of the template transfers when this call is made. The source will modify this and + assumes it has exclusive use (thus you should clone the template if necessary). + + Another important aspect is that templates are reused by TraceEventSource aggressively. The + expectation is that no memory needs to be allocated during a normal dispatch + + + + + + UnregisterEventTemplate undoes the action of RegisterEventTemplate. Logically you would + pass the template to unregister, but typically you don't have that at unregistration time. + To avoid forcing clients to remember the templates they registered, UnregisterEventTemplate + takes three things that will uniquely identify the template to unregister. These are + the eventID, and provider ID and the Action (callback) for the template. + + + + + It is expected that when a subclass of TraceEventParser is created, it calls this + method on the source. This allows the source to do any Parser-specific initialization. + + + + + Indicates that this callback should be called on any unhandled event. The callback + returns true if the lookup should be retried after calling this (that is there is + the unhandled event was found). + + + + + Looks if any provider has registered an event with task with 'taskGuid'. Will return null if + there is no registered event. + + + + + Looks if any provider has registered with the given GUID OR has registered any task that matches + the GUID. Will return null if there is no registered event. + + + + + TraceEventParser Represents a class that knows how to decode particular set of events (typically + all the events of a single ETW provider). It is expected that subclasses of TraceEventParser + have a constructor that takes a TraceEventSource as an argument that 'attaches' th parser + to the TraceEventSource. TraceEventParsers break into two groups. + + * Those that work on a single provider, and thus the provider name is implicit in th parser. This is the common case. + The AddCallbackForEvent* methods are meant to be used for these TraceEventParsers + + * Those that work on multiple providers. There are only a handful of these (DynamicTraceEventParser, ...). + The AddCallbackForProviderEvent* methods which take 'Provider' parameters are meant to be used for these TraceEventParsers + + + In addition to the AddCallback* methods on TraceEventParser, there are also Observe* extension methods that + provide callbacks using the IObservable style. + + + + + + Get the source this TraceEventParser is attached to. + + + + + Subscribe to all the events this parser can parse. It is shorthand for AddCallback{TraceEvent}(value)/RemoveCallback(value) + + + + + A shortcut that adds 'callback' in the provider associated with this parser (ProvderName) and an event name 'eventName'. 'eventName' + can be null in which case any event that matches 'Action{T}' will call the callback. + 'eventName is of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + The callback alone is used as the subscription id for unregistration, so the callback delegate should be unique (by delegate comparison) + + + + + + Causes 'callback' to be called for any event in the provider associated with this parser (ProviderName) whose type is compatible with T and + whose eventName will pass 'eventNameFilter'. + + + + + Causes 'callback' to be called for any event in the provider associated with this parser (ProviderName) whose type is compatible with T and + whose eventName will pass 'eventNameFilter'. The eventNameFilter parameter can be null, in which case all events that are compatible + with T will be selected. + + eventNames passed to the filer are of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + + + + Causes 'callback' to be called for any event in the provider associated with this parser (ProviderName) whose type is compatible with T and + whose eventName will pass 'eventNameFilter'. The eventNameFilter parameter can be null, in which case all events that are compatible + with T will be selected. + + A 'subscriptionID' can be passed and this value along with the callback can be used + to uniquely identify subscription to remove using the 'RemoveCallback' API. If null is passed, then only the identity of the callback can + be used to identify the subscription to remove. + + eventNames passed to the filer are of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + + + + + A shortcut that adds 'callback' for the event in 'providerName' and an event name 'eventName' + The callback alone is used as the subscription id for unregistration, so the callback delegate should be unique (by delegate comparison) + + eventName is of the of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + + + + + Cause 'callback' to be called for any event that this parser recognizes for which the function 'eventsToObserve' + returns 'AcceptEvent'. The 'eventsToObserve is given both the provider name (first) and the event name and can return + 'AcceptEvent' 'RejectEvent' or 'RejectProvider' (in which case it may not be called again for that provider). + eventsToObserver can be null in which case all events that match the parser recognizes are selected. + + eventNames passed to the filer are of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + + Thus this method works for parsers that parse more than one provider (e.g. DynamicTraceEventParser). + + + + + + Cause 'callback' to be called for any event that this parser recognizes for which the function 'eventsToObserve' + returns 'AcceptEvent'. The 'eventsToObserve is given both the provider name (first) and the event name and can return + 'AcceptEvent' 'RejectEvent' or 'RejectProvider' (in which case it may not be called again for that provider). + eventsToObserver can be null in which case all events that match the parser recognizes are selected. + + eventNames passed to the filer are of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. /// + + Thus this method works for parsers that parse more than one provider (e.g. DynamicTraceEventParser). + + A subscriptionID can optionally be passed. This is used (along with the callback identity) to identify this to the 'RemoveCallback' If you + don't need to remove the callback or you will do it in bulk, you don't need this parameter. + + + + + + Remove all subscriptions added with 'AddCallback' (any overload), that is compatible with T, has a callback 'callback' and subscriptionId 'subscriptionId' + where 'subscriptionId' was the value that was optionally passed to 'AddCallback' to provide exactly this disambiguation. + + 'callback' or 'subscriptionId' can be null, in which case it acts as a wild card. Thus RemoveCallback{TraceEvent}(null, null) will remove all callbacks + that were registered through this parser. + + + + + + A static TraceEventParser is a parser where the set of events that can be subscribed to (and their payload fields) are known at + compile time. There are very few dynamic TraceEventParsers (DynamicTraceEventParser, RegisteredTraceEventParser and WPPTraceEventParser) + + + + + All TraceEventParsers invoke this constructor. If 'dontRegister' is true it is not registered with the source. + + + + + Normally a TraceEvent parser knows how to parse only one provider. If this is true + ProviderName returns the name of this provider. If the parser knows how to parse + more than one provider, this property returns null. + + + + + If the parser needs to persist data along with the events we put it in a separate object. + This object and then implement serialization functionality that allows it to be persisted (this is for ETLX support). + + + + + Returns a list of all templates currently existing (new ones can come in, but OnNewEventDefintion must be called + whenever that happens. Note that the returned templates MUST be cloned and do not have their source or parser state + fields set. These must be set as part of subscription (after you know if you care about them or not). + + eventsToObserver is given the provider name and event name and those events that return AcceptEvent will + have the 'callback' function called on that template. eventsToObserver can be null which mean all events. + + The returned template IS READ ONLY! If you need a read-write copy (typical), clone it first. + + + + + If the parser can change over time (it can add new definitions), It needs to support this interface. See EnumerateDynamicTemplates for details. + This function should be called any time a new event is now parsable by the parser. If it is guaranteed that the particular event is + definitely being ADDED (it never existed in the past), then you can set 'mayHaveExistedBefore' to false and save some time. + + It returns false if there are no definitions for that particular Provider (and thus you can skip callback if desired). + + + + + Given a subscription request, and a template that can now be parsed (and its state, which is just TraceEventParser.StateObj) + If subscription states that the template should be registered with the source, then do the registration. + + if 'mayHaveExistedBefore' means that this template definition may have been seen before (DynamicTraceEventParsers do this as + you may get newer versions dynamically registering themselves). In that case this should be set. If you can guaranteed that + a particular template (provider-eventID pair) will only be subscribed at most once you can set this to false. + + + + + Keeps track of a single 'AddCallback' request so it can be removed later. It also handles lazy addition of events. + + + + + Create a subscription request. 'eventsToObserve takes a provider name (first) and a event name and returns a three valued EventFilterResponse + value (accept, reject, reject provider) + + + + + The source that this parser is connected to. + + + + + EventFilterResponse is the set of responses a user-defined filtering routine, might return. This is used in the TraceEventParser.AddCallbackForProviderEvents method. + + + + + Not an interesting event, but other events in the same provider may be + + + + + No event in the provider will be accepted + + + + + An interesting event + + + + + A TraceEventDispatcher is a TraceEventSource that supports a callback model for dispatching events. + + + + + Obtains the correct TraceEventDispatcher for the given trace file name. + + A path to a trace file. + A TraceEventDispatcher for the given trace file. + + + + Subscribers to UnhandledEvent are called if no other hander has processed the event. It is + generally used in DEBUG builds to validate that events are getting to the source at all. + + + + + Subscribers to EveryEvent are called on every event in the trace. Normally you don't want + to subscribe to this but rather use a TraceEvenParser (which knows how to decode the payloads) + and subscribe to particular events through that. For example Using TraceEventSource.Dynamic.All + or TraceEventSource.Dynamic.All is more likely to be what you are looking for. AllEvents is only + an event callback of last resort, that only gives you the 'raw' data (common fields but no + payload). + + This is called AFTER any event-specific handlers. + + + + + + Subscribers to UnhandledEvent are called if no other hander has processed the event. It is + generally used in DEBUG builds to validate that events are getting to the source at all. + + + + + Subscribers to EveryEvent are called on every event in the trace. Normally you don't want + to subscribe to this but rather use a TraceEvenParser and subscribe to particular events + through that. + + This is called AFTER any event-specific handlers. + + + + + + Once a client has subscribed to the events of interest, calling Process actually causes + the callbacks to happen. + + Subclasses implementing this method should call 'OnCompleted' + before returning. + + + false If StopProcessing was called + + + + Calling StopProcessing in a callback when 'Process()' is running will indicate that processing + should be stopped immediately and that the Process() method should return. + + Note that this stop request will not be honored until the next event from the source. Thus + for real time sessions there is an indeterminate delay before the stop will complete. + If you need to force the stop you should instead call Dispose() on the session associated with + the real time session. This will cause the source to be shut down and thus also stop processing + (Process() will return) but is guaranteed to complete in a timely manner. + + + + + Subscribers of Completed will be called after processing is complete (right before TraceEventDispatcher.Process returns. + + + + + Wrap (or filter) the dispatch of every event from the TraceEventDispatcher stream. + Instead of calling the normal code it calls 'hook' with both the event to be dispatched + and the method the would normally do the processing. Thus the routine has + the option to call normal processing, surround it with things like a lock + or skip it entirely. This can be called more than once, in which case the last + hook method gets called first (which may end up calling the second ...) + + For example,here is an example that uses AddDispatchHook to + take a lock is taken whenever dispatch work is being performed. + + AddDispatchHook((anEvent, dispatcher) => { lock (this) { dispatcher(anEvent); } }); + + + + + Called when processing is complete. You can call this more than once if your not sure if it has already been called. + however we do guard against races. + + + + + Number of different events that have callbacks associated with them + + + + + Total number of callbacks that are registered. Even if they are for the same event. + + + + + + This is the routine that is called back when any event arrives. Basically it looks up the GUID + and the opcode associated with the event and finds right subclass of TraceEvent that + knows how to decode the packet, and calls its virtual TraceEvent.Dispatch method. Note + that TraceEvent does NOT have a copy of the data, but rather just a pointer to it. + This data is ONLY valid during the callback. + + + + + Lookup up the event based on its ProviderID (GUID) and EventId (Classic use the TaskId and the + Opcode field for lookup, but use these same fields (see ETWTraceEventSource.RawDispatchClassic) + + + + + Dispose pattern. + + + + + Dispose pattern + + + + + Inserts 'template' into the hash table, using 'providerGuid' and and 'eventID' as the key. + For Vista ETW events 'providerGuid' must match the provider GUID and the 'eventID' the ID filed. + For PreVist ETW events 'providerGuid must match the task GUID the 'eventID' is the Opcode + + + + + A helper for creating a set of related guids (knowing the providerGuid can can deduce the + 'taskNumber' member of this group. All we do is add the taskNumber to GUID as a number. + + + + + TraceEventParsers can use this template to define the event for the trivial case where the event has no user-defined payload + This is only useful to TraceEventParsers. + + + + + Construct a TraceEvent template which has no payload fields with the given metadata and action + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + Dispatches the event to the action associated with the template. + + + + + override + + + + + When the event has just a single string value associated with it, you can use this shared event + template rather than making an event-specific class. + + + + + The value of the one string payload property. + + + + + Construct a TraceEvent template which has one string payload field with the given metadata and action + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + override + + + + + UnhandledTraceEvent is a TraceEvent when is used when no manifest information is available for the event. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + override + + + + + implementation of TraceEvent Interface. + + + + + There is some work needed to prepare the generic unhandledTraceEvent that we defer + late (since we often don't care about unhandled events) + + TODO this is probably not worht the complexity... + + + + + ObservableExtensions defines methods on TraceEventParser that implement the IObservable protocol for implementing callbacks. + + + + + Returns an IObjservable that observes all events that 'parser' knows about that return a T. If eventName is + non-null, the event's name must match 'eventName', but if eventName is null, any event that returns a T is observed. + + This means that Observe{TraceEvent}(parser) will observe all events that the parser can parse. + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + + Returns an IObjservable that observes all events that 'parser' knows about that return a T and whose event + name matches the 'eventNameFilter' predicate. + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + Observe a particular event from a particular provider. If eventName is null, it will return every event from the provider + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + Given a predicate 'eventToObserve' which takes the name of a provider (which may be of the form Provider(GUID)) (first) and + an event name (which may be of the form EventID(NUM)) and indicates which events to observe, return an IObservable + that observes those events. + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. . + + + + + Returns an observable that observes all events from the event source 'source' + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + Returns an observable that observes all events from the event source 'source' which are not handled by a callback connected to 'source' + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + A TraceEventObservable is a helper class that implements the IObservable pattern for TraceEventDispatcher + (like ETWTraceEventDispatcher). It is called from the TraceEventParser.Observe*{T} methods. + + + + + + A TraceEventSubscription is helper class that hooks 'callback' and 'completedCallback' to the 'observable' and + unhooks them when 'Dispose' is called. + + + + + TraceEventNativeMethods contains the PINVOKE declarations needed + to get at the Win32 TraceEvent infrastructure. It is effectively + a port of evntrace.h to C# declarations. + + + + + Time zone info. Used as one field of TRACE_EVENT_LOGFILE, below. + Total struct size is 0xac. + + + + + EventTraceHeader structure used by EVENT_TRACE_PROPERTIES + + + + + EVENT_TRACE_PROPERTIES is a structure used by StartTrace, ControlTrace + however it can not be used directly in the definition of these functions + because extra information has to be hung off the end of the structure + before being passed. (LofFileNameOffset, LoggerNameOffset) + + + + + EventTraceHeader and structure used to defined EVENT_TRACE (the main packet) + I have simplified from the original struct definitions. I have + omitted alternate union-fields which we don't use. + + + + + EVENT_TRACE is the structure that represents a single 'packet' + of data repesenting a single event. + + + + + TRACE_LOGFILE_HEADER is a header used to define EVENT_TRACE_LOGFILEW. + Total struct size is 0x110. + + + + + EVENT_TRACE_LOGFILEW Main struct passed to OpenTrace() to be filled in. + It represents the collection of ETW events as a whole. + + + + + EventTraceHeader and structure used to define EVENT_TRACE_LOGFILE (the main packet on Vista and above) + I have simplified from the original struct definitions. I have + omitted alternate union-fields which we don't use. + + + + + Provides context information about the event + + + + + Defines the layout of an event that ETW delivers + + + + + Possible control commands (borrowed from EventSource) + + + + + Standard 'update' command to send additional information to a provider + + + + + Instructs an EventSource-based provider to send its manifest + + + + + A TraceEventSession represents a single ETW Tracing Session. A session is and event sink that + can enable or disable event logging from event providers). TraceEventSessions can log their + events either to a file, or by issuing callbacks when events arrive (a so-called 'real time' + session). + + Session are MACHINE wide and unlike most OS resources the operating system does NOT reclaim + them when the process that created it dies. By default TraceEventSession tries is best to + do this reclamation, but it is possible that for 'orphan' session to accidentally survive + if the process is ended abruptly (e.g. by the debugger or a user explicitly killing it). It is + possible to turn off TraceEventSession automatic reclamation by setting the StopOnDispose + property to false (its default is true). + + + Kernel events have additional restrictions. In particular there is a special API (EnableKernelProvider). + Before Windows 8, there was a restriction that kernel events could only be enabled from a session + with a special name (see KernelTraceEventParser.KernelSessionName) and thus there could only be a single + session that could log kernel events (and that session could not log non-kernel events). These + restrictions were dropped in windows 8. + + + + + + Create a new logging session sending the output to a given file. + + + The name of the session. Since session can exist beyond the lifetime of the process this name is + used to refer to the session from other processes after it is created. By default TraceEventSessions + do their best to close down if the TraceEventSession dies (see StopOnDispose), however if StopOnDispose + is set to false, the session can live on after process death, and you use the name to refer to it later. + + + The output moduleFile (by convention .ETL) to put the event data. If this is null, and CircularMB is set + to something non-zero, then it will do an in-memory circular buffer. You can get this buffer by + using the 'SetFileName()' method which dumps the data in the buffer. + + Additional flags that influence behavior. Note that the 'Create' option is implied for file mode sessions. + + + + Open a logging session. By default (if options is not specified) a new 'real time' session is created if + the session already existed it is closed and reopened (thus orphans are cleaned up on next use). By default + sessions are closed on Dispose, but if the destructor does not run it can produce 'orphan' session that will + live beyond the lifetime of the process. You can use the StopOnDispose property to force sessions to live + beyond the TraceEventSession that created them and use the TraceEventSessionOptions.Attach option to reattach + to these sessions. + + The name of the session to open. Should be unique across the machine. + Construction options. TraceEventSessionOptions.Attach indicates a desire to attach + to an existing session. + + + + Looks for an existing active session named 'sessionName; and returns the TraceEventSession associated with it if it exists. + Returns null if the session does not exist. You can use the GetActiveSessionNames() to get a list of names to pass to this method. + + + + + Enable a NON-KERNEL provider (see also EnableKernelProvider) which has a given provider name. + This API first checks if a published provider exists by that name, otherwise it + assumes it is an EventSouce and determines the provider Guid by hashing the name according to a + well known algorithm. Thus it will never return a failure for a incorrect spelling of the name. + + + The name of the provider. It must either be registered with the operating system (logman query providers returns it) + or it must be an EventSource (see GetEventSourceGuidFromName) + The verbosity to turn on + A bitvector representing the areas to turn on. Only the + low 32 bits are used by classic providers and passed as the 'flags' value. Zero + is a special value which is a provider defined default, which is usually 'everything' + Additional options for the provider (e.g. taking a stack trace), arguments ... + true if the session already existed and needed to be restarted. + + + + Enable a NON-KERNEL provider (see also EnableKernelProvider) which has a given provider Guid. + + + The Guid that represents the event provider enable. + The verbosity to turn on + A bitvector representing the areas to turn on. Only the + low 32 bits are used by classic providers and passed as the 'flags' value. Zero + is a special value which is a provider defined default, which is usually 'everything' + Additional options for the provider (e.g. taking a stack trace), arguments ... + true if the session already existed and needed to be restarted. + + + + Enable a NON-KERNEL provider (see also EnableKernelProvider) which has a given provider name. + This API first checks if a published provider exists by that name, otherwise it + assumes it is an EventSouce and determines the provider Guid by hashing the name according to a + well known algorithm. Thus it will never return a failure for a incorrect spelling of the name. + + + The name of the provider. It must either be registered with the operating system (logman query providers returns it) + or it must be an EventSource (see GetEventSourceGuidFromName) + The verbosity to turn on + A bitvector representing the areas to turn on. Only the + low 32 bits are used by classic providers and passed as the 'flags' value. Zero + is a special value which is a provider defined default, which is usually 'everything' + Additional options for the provider (e.g. taking a stack trace) + This is set of key-value strings that are passed to the provider + for provider-specific interpretation. Can be null if no additional args are needed. + If the special key-value pair 'Command'='SendManifest' is provided, then the 'SendManifest' + command will be sent (which causes EventSources to re-dump their manifest to the ETW log. + true if the session already existed and needed to be restarted. + + + + Enable a NON-KERNEL provider (see also EnableKernelProvider) represented by 'providerGuid'. + + + The Guid that represents the event provider enable. + The verbosity to turn on + A bitvector representing the areas to turn on. Only the + low 32 bits are used by classic providers and passed as the 'flags' value. Zero + is a special value which is a provider defined default, which is usually 'everything' + Additional options for the provider (e.g. taking a stack trace) + This is set of key-value strings that are passed to the provider + for provider-specific interpretation. Can be null if no additional args are needed. + If the special key-value pair 'Command'='SendManifest' is provided, then the 'SendManifest' + command will be sent (which causes EventSources to re-dump their manifest to the ETW log. + true if the session already existed and needed to be restarted. + + + + Enable an ETW provider, passing a raw blob of data to the provider as a Filter specification. + + Note that this routine is only provided to interact with old ETW providers that can interpret EVENT_FILTER_DESCRIPTOR data + but did not conform to the key-value string conventions. This allows this extra information to be passed to these old + providers. Ideally new providers follow the key-value convention and EnableProvider can be used. + + + + + Helper function that is useful when using EnableProvider with key value pairs. + Given a list of key-value pairs, create a dictionary of the keys mapping to the values. + + + + + Enable the kernel provider for the session. Before windows 8 this session must be called 'NT Kernel Session'. + This API is OK to call from one thread while Process() is being run on another + Specifies the particular kernel events of interest + + Specifies which events should have their stack traces captured when an event is logged + Returns true if the session existed before and was restarted (see TraceEventSession) + + + + + Turn on windows heap logging (stack for allocation) for a particular existing process. + + + + + Turn on windows heap logging for a particular EXE file name (just the file name, no directory, but it DOES include the .exe extension) + This API is OK to call from one thread while Process() is being run on another + + + + + + Disables a provider with the given provider ID completely + + + + + Disables a provider with the given name completely + + + + + Once started, event sessions will persist even after the process that created them dies. They will also be + implicitly stopped when the TraceEventSession is closed unless the StopOnDispose property is set to false. + This API is OK to call from one thread while Process() is being run on another + + + + + Close the session and clean up any resources associated with the session. It is OK to call this more than once. + This API is OK to call from one thread while Process() is being run on another. Calling Dispose is on + a real time session is the way you can force a real time session to stop in a timely manner. + + + + + Asks all providers to flush events to the session + This API is OK to call from one thread while Process() is being run on another + + + + + For either session create with a file name this method can be used to redirect the data to a + new file (so the previous one can be uploaded or processed offline), + + It can also be used for a in-memory circular buffer session (FileName == null and CircularMB != 0) + but its semantics is that simply writes the snapshot to the file (and closes it). It does not + actually make the FileName property become non-null because it only flushes the data, it does + not cause persistent redirection of the data stream. (it is like it auto-reverts). + + It is an error to call this on a real time session. (FileName == null and CircularMB == 0) + + The path to the file to write the data to. + + + + If set, whenever a SetFileName is called (causing a new ETL file to be created), force + a capture state for every provider that is currently turned on. This way the file + will be self-contained (will contain all the capture state information needed to decode events) + This setting is true by default. + + + + + Sends the CAPTURE_STATE command to the provider. This instructs the provider to log any events that are needed to + reconstruct important state that was set up before the session started. What is actually done is provider specific. + EventSources will re-dump their manifest on this command. + This API is OK to call from one thread while Process() is being run on another + + This routine only works Win7 and above, since previous versions don't have this concept. The providers also has + to support it. + + + The GUID that identifies the provider to send the CaptureState command to + The Keywords to send as part of the command (can influence what is sent back) + if non-zero, this is passed along to the provider as type of the filter data. + If non-null this is either an int, or a byte array and is passed along as filter data. + + + + When you issue a EnableProvider command, on windows 7 and above it can be done synchronously (that is you know that because + the EnableProvider returned that the provider actually got the command). However synchronous behavior means that + you may wait forever. This is the time EnableProvider waits until it gives up. Setting this + to 0 means asynchronous (fire and forget). The default is 10000 (wait 10 seconds) + Before windows 7 EnableProvider is always asynchronous. + + + + + If set then Stop() will be called automatically when this object is Disposed or Finalized by the GC. + This is true BY DEFAULT, so if you want your session to survive past the end of the process + you must set this to false. + + + + + Cause the log to be a circular buffer. The buffer size (in MegaBytes) is the value of this property. + Setting this to 0 will cause it to revert to non-circular mode. + The setter can only be called BEFORE any provider is enabled. + + + + + Cause the as a set of files with a given maximum size. The file name must end in .ETL and the + output is then a series of files of the form *NNN.ETL (That is it adds a number just before the + .etl suffix). If you make your file name *.user.etl then the output will be *.user1.etl, *.user2.etl ... + And the MergeInPlace command below will merge them all nicely. + + You can have more control over this by using a normal sequential file but use the SetFileName() + method to redirect the data to new files as needed. + + + + + Sets the size of the buffer the operating system should reserve to avoid lost packets. Starts out + as a very generous 64MB for files. If events are lost, this can be increased, but keep in mind that + no value will help if the average incoming rate is faster than the processing rate. + The setter can only be called BEFORE any provider is enabled. + + + + + This is the unit in which data is flushed in Kilobytes. By default it is 64 (KB). + By default a TraceEventSession will flush every second, and this amount of space will be transferred + to the file. Ideally it is smaller than the number data bytes you expect in a second from any + particular processor. It can't be less than 1K per processor on the machine. However if you make + it less than 64 (K) you will limit the size of the event that the process can send + (they will simply be discarded). + + + + + The rate at which CPU samples are collected. By default this is 1 (once a millisecond per CPU). + There is a lower bound on this (typically .125 Msec) + + + + + Indicate that this session should use compress the stacks to save space. + Must be set before any providers are enabled. Currently only works for kernel events. + + + + + The name of the session that can be used by other threads to attach to the session. + + + + + The name of the moduleFile that events are logged to. Null means the session is real time + or is a circular in-memory buffer. See also SetFileName() method. + + + + + If this is a real time session you can fetch the source associated with the session to start receiving events. + Currently does not work on file based sources (we expect you to wait until the file is complete). + + + + + Creating a TraceEventSession does not actually interact with the operating system until a + provider is enabled. At that point the session is considered active (OS state that survives a + process exit has been modified). IsActive returns true if the session is active. + + + + + + Returns the number of events that should have been delivered to this session but were lost + (typically because the incoming rate was too high). This value is up-to-date for real time + sessions. + + + + + Returns true if the session is logging to a circular buffer. This may be in-memory (FileName == null) + or to a file (FileName != null) + + + + + Returns true if the session is Real Time. This means it is not to a file, and not circular. + + + + + Returns true if this is a in-memory circular buffer (it is circular without an output file). + Use SetFileName() to dump the in-memory buffer to a file. + + + + + ETW trace sessions survive process shutdown. Thus you can attach to existing active sessions. + GetActiveSessionNames() returns a list of currently existing session names. These can be passed + to the TraceEventSession constructor to open it. + + A enumeration of strings, each of which is a name of a session + + + + It is sometimes useful to merge the contents of several ETL files into a single + output ETL file. This routine does that. It also will attach additional + information that will allow correct file name and symbolic lookup if the + ETL file is used on a machine other than the one that the data was collected on. + If you wish to transport the file to another machine you need to merge them, even + if you have only one file so that this extra information get incorporated. + + The input ETL files to merge + The output ETL file to produce. + Optional Additional options for the Merge (seeTraceEventMergeOptions) + + + + This variation of the Merge command takes the 'primary' etl file name (X.etl) + and will merge in any files that match .clr*.etl .user*.etl. and .kernel.etl. + + + + + Is the current process Elevated (allowed to turn on a ETW provider). This is useful because + you need to be elevated to enable providers on a TraceEventSession. + + + + + Set the Windows Debug Privilege. Useful because some event providers require this privilege, and + and it must be enabled explicitly (even if the process is elevated). + + + + + The 'properties' field is only the header information. There is 'tail' that is + required. 'ToUnmangedBuffer' fills in this tail properly. + + + + + Returns a sorted dictionary of names and Guids for every provider registered on the system. + + + + + sets up the EVENT_FILTER_DESCRIPTOR descr to represent the Event Ids in 'eventIds'. You are given the buffer + necessary for this (precomputed) for the EVENT_FILTER_EVENT_ID structure. 'enable' is true if this is to enable + (otherwise disable) the events, and descrType indicates the descriptor type (either EVENT_FILTER_TYPE_EVENT_ID or + EVENT_FILTER_TYPE_STACKWALK) + + + + + Computes the number of bytes needed for the EVENT_FILTER_EVENT_ID structure to represent 'eventIds' + return 0 if there is not need for the filter at all. + + + + + Cleans out all provider data associated with this session. + + + + + SetDataForSession sets the filter data for an ETW session by storing it in the registry. + This is basically a work-around for the fact that filter data does not get transmitted to + the provider if the provider is not alive at the time the controller issues the EnableProvider + call. We store in the registry and EventSource looks there for it if it is not present. + + Note that we support up to 'maxSession' etw sessions simultaneously active (having different + filter data). The function return a sessionIndex that indicates which of the 'slots' + was used to store the data. This routine also 'garbage collects' data for sessions that + have died without cleaning up their filter data. + + If 'data' is null, then it indicates that no data should be stored and the registry entry + is removed. + + If 'allSesions' is true it means that you want 'old style' data filtering that affects all ETW sessions + This is present only used for compatibilty + + the session index that will be used for this session. Returns -1 if an entry could not be found + + + + Given a mask of kernel flags, set the array stackTracingIds of size stackTracingIdsMax to match. + It returns the number of entries in stackTracingIds that were filled in. + + + + + Get a EVENT_TRACE_PROPERTIES structure suitable for passing the the ETW out of a 'buffer' which must be PropertiesSize bytes + in size. + + + + + Used in the TraceEventSession.Merge method + + + + + No special options + + + + + Compress the resulting file. + + + + + TraceEventProviderOptions represents all the optional arguments that can be passed to EnableProvider command. + + + + + Create new options object with no options set + + + + + Create new options object with a set of given provider arguments key-value pairs. There must be a even number + of strings provided and each pair forms a key-value pair that is passed to the AddArgument() operator. + + + + + Arguments are a set of key-value strings that are passed uninterpreted to the EventSource. These can be accessed + from the EventSource's command callback. + + + + + As a convenience, the 'Arguments' property can be modified by calling AddArgument that adds another Key-Value pair + to it. If 'Arguments' is not a IDictionary, it is replaced with an IDictionary with the same key-value pairs before + the new pair is added. + + + + + For EventSources, you pass arguments to the EventSource by using key value pairs (this 'Arguments' property). + However other ETW providers may expect arguments using another convention. RawArguments give a way of passing + raw bytes to the provider as arguments. This is only meant for compatibility with old providers. Setting + this property will cause the 'Arguments' property to be ignored. + + + + + Setting StackEnabled to true will cause all events in the provider to collect stacks when event are fired. + + + + + Setting ProcessIDFilter will limit the providers that receive the EnableCommand to those that match on of + the given Process IDs. + + + + + Setting ProcessNameFilter will limit the providers that receive the EnableCommand to those that match on of + the given Process names (a process name is the name of the EXE without the PATH but WITH the extension). + + + + + Setting EventIDs to Enable will enable a particular event of a provider by EventID (in addition to those + enabled by keywords). + + + + + Setting EventIDs to Enable will enable the collection of stacks for a event of a provider by EventID + (Has no effect if StacksEnabled is also set since that enable stacks for all events IDs) + + + + + Setting EventIDsToDisable to Enable will disable the event of a provider by EventID + This happens after keywords have been processed, so disabling overrides enabling. + + + + + Setting EventIDs to Enable will disable the collection of stacks for a event of a provider by EventID + Has no effect unless StacksEnabled is also set (since otherwise stack collection is off). + + + + + Make a deep copy of options and return it. + + + + + + This return true on OS version beyond 8.1 (windows Version 6.3). It means most of the + per-event filtering is supported. + + + + + This is the backing field for the lazily-computed property. + + + + + TraceEventSessionOptions indicates special handling when creating a TraceEventSession. + + + + + Create a new session, stop and recreated it if it already exists. This is the default. + + + + + Attach to an existing session, fail if the session does NOT already exist. + + + + + Normally if you create a session it will stop and restart it if it exists already. Setting + this flat will disable the 'stop and restart' behavior. This is useful if only a single + monitoring process is intended. + + + + + TraceEventProviders returns information about providers on the system. + + + + + Given the friendly name of a provider (e.g. Microsoft-Windows-DotNETRuntimeStress) return the + GUID for the provider. It does this by looking at all the PUBLISHED providers on the system + (that is those registered with wevtutuil). EventSources in particular do not register themselves + in this way (see GetEventSourceGuidFromName). Names are case insensitive. + It also checks to see if the name is an actual GUID and if so returns that. + Returns Guid.Empty on failure. + + + + + EventSources have a convention for converting its name to a GUID. Use this convention to + convert 'name' to a GUID. In this way you can get the provider GUID for a EventSource + however it can't check for misspellings. Names are case insensitive. + + + + + Finds the friendly name for 'providerGuid' Returns the Guid as a string if can't be found. + + + + + Returns true if 'providerGuid' can be an eventSource. If it says true, there is a 1/16 chance it is not. + However if it returns false, it is definitely not following EventSource Guid generation conventions. + + + + + Returns the Guid of every event provider that published its manifest on the machine. This is the + same list that the 'logman query providers' command will generate. It is pretty long (> 1000 entries) + + A event provider publishes a manifest by compiling its manifest into a special binary form and calling + the wevtutil utility. Typically EventSource do NOT publish their manifest but most operating + system provider do publish their manifest. + + + + + + Returns the GUID of all event provider that either has registered itself in a running process (that is + it CAN be enabled) or that a session has enabled (even if no instances of the provider exist in any process). + + This is a relatively small list (less than 1000), unlike GetPublishedProviders. + + + + + + Returns a list of provider GUIDs that are registered in a process with 'processID'. Useful for discovering + what providers are available for enabling for a particular process. + + + + + Returns a description of the keywords a particular provider provides. Only works if the provider has + published its manifest to the operating system. + Throws an exception if providerGuid is not found + + + + + Returns a list of TRACE_ENABLE_INFO structures that tell about each session (what keywords and level they are + set to, for the provider associated with 'providerGuid'. If 'processId != 0, then only providers in that process + are returned. + + + + + A list of these is returned by GetProviderKeywords + + + + + The name of the provider keyword. + + + + + The description for the keyword for the provider + + + + + the value (bitvector) for the keyword. + + + + + and XML representation for the ProviderDataItem (for debugging) + + + + + TraceEventProfileSources is the interface for the Windows processor CPU counter support + (e.g. causing a stack to be taken every N dcache misses, or branch mispredicts etc) + + Note that the interface to these is machine global (That is when you set these you + cause any session with the kernel PMCProfile keyword active to start emitting + PMCCounterProf events for each ProfileSouce that is enabled. + + /// + + + + Returns a dictionary of keyed by name of ProfileSourceInfo structures for all the CPU counters available on the machine. + + + + + Sets a single Profile Source (CPU machine counters) that will be used if PMC (Precise Machine Counters) + are turned on. The profileSourceID is the ID field from the ProfileSourceInfo returned from 'GetInfo()'. + and the profileSourceInterval is the interval between sampples (the number of events before a stack + is recoreded. If you need more that one (the OS allows up to 4 I think), use the variation of this + routine that takes two int[]. Calling this will clear all Profiler sources previously set (it is NOT + additive). + + + + + Sets the Profile Sources (CPU machine counters) that will be used if PMC (Precise Machine Counters) + are turned on. Each CPU counter is given a id (the profileSourceID) and has an interval + (the number of counts you skip for each event you log). You can get the human name for + all the supported CPU counters by calling GetProfileSourceInfo. Then choose the ones you want + and configure them here (the first array indicating the CPU counters to enable, and the second + array indicating the interval. The second array can be shorter then the first, in which case + the existing interval is used (it persists and has a default on boot). + + + + + Returned by GetProfileSourceInfo, describing the CPU counter (ProfileSource) available on the machine. + + + + + Human readable name of the CPU performance counter (eg BranchInstructions, TotalIssues ...) + + + + + The ID that can be passed to SetProfileSources + + + + + This many events are skipped for each sample that is actually recorded + + + + + The smallest Interval can be (typically 4K) + + + + + The largest Interval can be (typically maxInt). + + + + + These are options to EnableProvider + + + + + No options + + + + + Take a stack trace with the event + + + + + The data model for an Event trace log (ETL) file is simply a stream of events. More sophisticated + analysis typically needs a a richer data model then ETL files can provide, and this is the + motivation for the ETLX (Event Trace Log eXtended) file format. In particular any + analysis that needs non-sequential access to the events or manipulates stack traces associated + with events needs the additional support that the ETLX format provides. See the TraceEventProgrammers guide + for more on the capabilities of ETLX. + + The TraceLog class is the programmatic representation of an ETLX file. It represents the ETLX file as a whole. + + ETLX files are typically created from ETL files using the TraceLog.OpenOrCreate method or more explicitly + by the TraceLog.CreateFromEventTraceLogFile. + + + + + + Given the path to an ETW trace log file (ETL) file, create an ETLX file for the data. + If etlxFilePath is null the output name is derived from etlFilePath by changing its file extension to .ETLX. + The name of the ETLX file that was generated. + + + + + Open an ETLX or ETL file as a ETLX file. + + This routine assumes that you follow normal conventions of naming ETL files with the .ETL file extension + and ETLX files with the .ETLX file extension. It further assumes the ETLX file for a given ETL file + should be in a file named the same as the ETL file with the file extension changed. + + etlOrEtlxFilePath can be either the name of the ETL or ETLX file. If the ETLX file does not + exist or if it older than the corresponding ETL file then the ETLX file is regenerated with + the given options. However if an up-to-date ETLX file exists the conversion step is skipped. + + Ultimately the ETLX file is opened and the resulting TraceLog instance is returned. + + + + + + From a TraceEventSession, create a real time TraceLog Event Source. Like a ETWTraceEventSource a TraceLogEventSource + will deliver events in real time. However an TraceLogEventSource has an underlying Tracelog (which you can access with + the .Log Property) which lets you get at aggregated information (Processes, threads, images loaded, and perhaps most + importantly TraceEvent.CallStack() will work. Thus you can get real time stacks from events). + + Note that in order for native stacks to resolve symbolically, you need to have some Kernel events turned on (Image, and Process) + and only windows 8 has a session that allows both kernel and user mode events simultaneously. Thus this is most useful + on Win 8 systems. + + + + + Creates a ETLX file an Lttng Text file 'filePath'. + + + + + Creates a ETLX file an EventPipe 'filePath'. + + + + + Opens an existing Extended Trace Event log file (ETLX) file. See also TraceLog.OpenOrCreate. + + + + + All the events in the ETLX file. The returned TraceEvents instance supports IEnumerable so it can be used + in foreach statements, but it also supports other methods to further filter the evens before enumerating over them. + + Note that the TraceEvent returned from this IEnumerable may only be used for one iteration of the foreach. + (it is reused for the next event). If you need more lifetime than that you must call Clone() (see 'Lifetime + Constraints' in the programmers guide for more). + + + + + All the Processes that logged an event in the ETLX file. The returned TraceProcesses instance supports IEnumerable so it can be used + in foreach statements, but it also supports other methods to select particular a particular process. + + + + + All the Threads that logged an event in the ETLX file. The returned TraceThreads instance supports IEnumerable so it can be used + in foreach statements, but it also supports other methods to select particular thread. + + + + + All the module files (DLLs) that were loaded by some process in the ETLX file. The returned TraceModuleFiles instance supports IEnumerable so it can be used + in foreach statements, but it also supports other methods to select particular module file. + + + + + All the call stacks in the ETLX file. Normally you don't enumerate over these, but use you use other methods on TraceCallStacks + information about code addresses using CallStackIndexes. + + + + + All the code addresses in the ETLX file. Normally you don't enumerate over these, but use you use other methods on TraceCodeAddresses + information about code addresses using CodeAddressIndexes. + + + + + Summary statistics on the events in the ETX file. + + + + + If the event has a call stack associated with it, retrieve it. Returns null if there is not call stack associated with the event. + If you are retrieving many call stacks consider using GetCallStackIndexForEvent, as it is more efficient. + + + + + If the event has a call stack associated with it, retrieve CallStackIndex. Returns CallStackIndex.Invalid if there is not call stack associated with the event. + + + + + Events are given an Index (ID) that are unique across the whole TraceLog. They are not guaranteed + to be sequential, but they are guaranteed to be between 0 and MaxEventIndex. Ids can be used to + allow clients to associate additional information with event (with a side lookup table). See + TraceEvent.EventIndex and EventIndex for more + + + + + Given an eventIndex, get the event. This is relatively expensive because we need to create a + copy of the event that will not be reused by the TraceLog. Ideally you would not use this API + but rather use iterate over event using TraceEvents + + + + + The total number of events in the log. + + + + + The size of the log file in bytes. + + + + + override + + + + + The file path for the ETLX file associated with this TraceLog instance. + + + + + The machine on which the log was collected. Returns empty string if unknown. + + + + + The name of the Operating system. Returns empty string if unknown. + + + + + The build number information for the OS. Returns empty string if unknown. + + + + + The time the machine was booted. Returns DateTime.MinValue if it is unknown. + + + + + This is the number of minutes between the local time where the data was collected and UTC time. + It is negative if your time zone is WEST of Greenwich. This DOES take Daylights savings time into account + but might be a daylight savings time transition happens inside the trace. + May be unknown, in which case it returns null. + + + + + When an ETL file is 'merged', for every DLL in the trace information is added that allows the symbol + information (PDBS) to be identified unambiguously on a symbol server. This property returns true + if the ETLX file was created from an ETL file with this added information. + + + + + The size of the main memory (RAM) on the collection machine. Will return 0 if memory size is unknown + + + + + Are there any event in trace that has a call stack associated with it. + + + + + If Kernel CPU sampling events are turned on, CPU samples are taken at regular intervals (by default every MSec). + This property returns the time interval between samples. + + If the sampling interval was changed over the course of the trace, this property does not reflect that. It + returns the first value it had in the trace. + + + + + + Returns true if the machine running this code is the same as the machine where the trace data was collected. + + If this returns false, the path names references in the trace cannot be inspected (since they are on a different machine). + + + + + + There is a size limit for ETLX files. Thus it is possible that the data from the original ETL file was truncated. + This property returns true if this happened. + + + + + Returns the EvnetIndex (order in the file) of the first event that has a + timestamp smaller than its predecessor. Returns Invalid if there are no time inversions. + + + + + Returns all the TraceEventParsers associated with this log. + + + + + An XML fragment that gives useful summary information about the trace as a whole. + + + + + Create a new real time session called 'sessionName' and connect a TraceLog to it and return that TraceLog. + Functionality of TraceLog that does not depend on either remembering past EVENTS or require future + knowledge (e.g. stacks of kernel events), will 'just work'. + + + + + Removes all but the last 'keepCount' entries in 'growableArray' by sliding them down. + + + + + Forwards an event that was saved (cloned) to the dispatcher associated with the real time source. + + + + + Flushes any event that has waited around long enough + + + + + Given a process's virtual address 'address' and an event which acts as a + context (determines which process and what time in that process), return + a CodeAddressIndex (which represents a particular location in a particular + method in a particular DLL). It is possible that different addresses will + go to the same code address for the same address (in different contexts). + This is because DLLS where loaded in different places in different processes. + + + + + If an event has a field of type 'Address' the address can be converted to a symbolic value (a + TraceCodeAddress) by calling this function. C + + + + + Given an EventIndex for an event, retrieve the call stack associated with it + (that can be given to TraceCallStacks). Many events may not have associated + call stack in which case CallSTackIndex.Invalid is returned. + + + + + Given a eventIndex for a CSWTICH event, return the call stack index for the thread + that LOST the processor (the normal callStack is for the thread that GOT the CPU) + + + + + Given a source of events 'source' generated a ETLX file representing these events from them. This + file can then be opened with the TraceLog constructor. 'options' can be null. + + + + + SetupCallbacks installs all the needed callbacks for TraceLog Processing (stacks, process, thread, summaries etc) + on the TraceEventSource rawEvents. + + + + + Copies the events from the 'rawEvents' dispatcher to the output stream 'IStreamWriter'. It + also creates auxiliary data structures associated with the raw events (eg, processes, threads, + modules, address lookup maps... Basically any information that needs to be determined by + scanning over the events during TraceLog creation should hook in here. + + + + + This is a helper routine that adds the address 'address' in the event 'data' to the map from events + to this list of addresses. + + + + + Special logic to form MemInfoWSTraceData. We take the single event (which has + The working sets for every process in the system, an split them out into N events + each of which has the processID for the event set properly, and only has the + information for that process. The first 3 processes in the list are -1, -2, and -3 + that have special meaning. + + + + + Given just the stack event and the timestamp for the event the stack event is to attach to, find + the IncompleteStack for the event. If the event to attach to cannot be this will return null + but otherwise it will make an IncompleteStack entry if one does not already exist or it. + + As part of allocating an Incomplete stack, it will increment the stack counts for target event. + + + + + Do the processing necessary to attach the user mode stack 'userModeStack' to any of the stacks in listOfIncompleteKernelStacks. + It then clears this list. While doing this processing it will check to see if the target stack 'target' is in that list and + it will return true if it was. + + + + + Do the processing necessary to attach the user mode stack 'userModeStack' to any of the stacks in listOfIncompleteKernelStacks. + It then clears this list. While doing this processing it will check to see if the target stack 'target' is in that list and + it will return true if it was. + + + + + Called when we get a definition event (for either a user mode or kernel mode stack fragment). + + + + + Holds information about stacks associated with an event. This is a transient structure. We only need it + until all the information is collected for a particular event, at which point we can create a + CallStackIndex for the stack and eventsToStacks table. + + + + + Clear clears entires that typically don't get set when we only have 1 frame fragment + We can recycle the entries without setting these in that case. + + + + + Clear all entries that can potentially change every time. + + + + + Log the Kernel Stack fragment. We simply remember all the frames (converted to CodeAddressIndexes). + + + + + Log the kernel stack fragment. Returns true if all the pieces of the stack fragment are collected + (we don't have to log something on the thread). + + + + + + + + + + Determine if 'stackInfo' is complete and if so emit it to the 'eventsToStacks' array. If 'force' is true + then force what information there is out even if it is not complete (there is nothing else coming). + + Returns true if it was able to emit the stack + + + + + returns true if the IncompleteStack is dead (just waiting to be reused). + + + + + We track the stacks for when CSwitches block, this is the CSWITCH event where that blocking happened. + + + + + Put the thread that owns 'data' in to the category 'category. + + + + + Process any extended data (like Win7 style stack traces) associated with 'data' + returns true if the event should be considered a bookkeeping event. + + + + + Dispose pattern + + + + + Advance 'reader' until it point at a event that occurs on or after 'timeQPC'. on page + 'pageIndex'. If 'positions' is non-null, fill in that array. Also return the index in + 'positions' for the entry that was found. + + + + + We need a TraceEventDispatcher in the Enumerators for TraceLog that know how to LOOKUP an event + We don't actually dispatch through it. We do mutate the templates (to point a particular data + record), but once we are done with it we can reuse this TraceEventDispatcher again an again + (it is only concurrent access that is a problem). Thus we have an Allocate and Free pattern + to reuse them in the common case of sequential access. + + + + + + The context switch event gives the stack of the thread GETTING the CPU, but it is also very useful + to have this stack at the point of blocking. cswitchBlockingEventsToStacks gives this stack. + + + + + We need to remember the the EventIndexes of the events that were 'just before' this event so we can + associate eventToStack traces with the event that actually caused them. PastEventInfo does this. + + + + + Returns the previous Event on the 'threadID'. Events with -1 thread IDs are also always returned. + Returns PastEventInfoIndex.Invalid if there are not more events to consider. + + + + + Find the event event on thread threadID to the given QPC timestamp. If there is more than + one event with the same QPC, we use thread and processor number to disambiguate. + + + + + Add a new entry that associates the stack 'stackIndex' with the event with index 'eventIndex' + + + + + Represents a source for a TraceLog file (or real time stream). It is basically a TraceEventDispatcher + (TraceEventSource) but you can also get at the TraceLog for it as well. + + + + + Returns the TraceLog associated with this TraceLogEventSource. + + + + + Returns the event Index of the 'current' event (we post increment it so it is always one less) + + + + + override + + + + + override + + + + + override + + + + + TraceEventStats represents the summary statistics (counts) of all the events in the log. + + + + + The total number of distinct event types (there will be a TraceEventCounts for each distinct event Type) + + + + + An XML representation of the TraceEventStats (for Debugging) + + + + + Given an event 'data' look up the statistics for events that type. + + + + + TraceEventCount holds number of events (Counts) and the number of events with call stacks associated with them (StackCounts) for a particular event type. + It also has properties for looking up the event and provider names, but this information can only be complete if all the TraceEventParsers needed + were associated with the TraceLog instance. + + + + + + Returns a provider name for events in this TraceEventCounts. It may return a string with a GUID or even + UnknownProvider for classic ETW if the event is unknown to the TraceLog. + + + + + Returns a name for events in this TraceEventCounts. If the event is unknown to the Tracelog + it will return EventID(XXX) (for manifest based events) or Task(XXX)/Opcode(XXX) (for classic events) + + + + + Returns the payload names associated with this Event type. Returns null if the payload names are unknown. + + + + + Returns true the provider associated with this TraceEventCouts is a classic (not manifest based) ETW provider. + + + + + Returns the provider GUID of the events in this TraceEventCounts. Returns Guid.Empty if IsClassic + + + + + Returns the event ID of the events in this TraceEventCounts. Returns TraceEventID.Illegal if IsClassic + + + + + Returns the Task GUID of the events in this TraceEventCounts. Returns Guid.Empty if not IsClassic + + + + + Returns the Opcode of the events in the TraceEventCounts. Returns TraceEventOpcode.Info if not IsClassic + + + + + Returns the average size of the event specific payload data (not the whole event) for all events in the TraceEventsCounts. + + + + + Returns the number of events in the TraceEventCounts. + + + + + Returns the number of events in the TraceEventCounts that have stack traces associated with them. + + + + + Returns the full name of the event (ProviderName/EventName) + + + + + An XML representation of the top level statistics of the TraceEventCounts. + + + + + + GetHashCode + + + + + A TraceEvents represents a list of TraceEvent instances. It is IEnumerable<TraceEvent> but + also has additional useful ways of filtering the list. + + Note that the TraceEvent returned from this IEnumerable may only be used for one iteration of the foreach. + (it is reused for the next event). If you need more lifetime than that you must call Clone() (see 'Lifetime + Constraints' in the programmers guide for more). + + + + + Returns a list of events in the TraceEvents that return a payload of type T. Thus + ByEventType < TraceEvent > returns all events. + + + + + Returns a TraceEventDispatcher (a push model object on which you can register + callbacks for particular events) that will push all the vents in the TraceEvents. + + Note that the TraceEvent returned from this callback may only be used for the duration of the callback. + If you need more lifetime than that you must call Clone() (see 'Lifetime Constraints' in the programmers guide for more). + + + + + Returns a new list which is the same as the TraceEvents but the events are + delivered from last to first. This allows you to search backwards in the + event stream. + + + + + Filter the events by time. Both starTime and endTime are inclusive. + + + + + Filter the events by time. StartTimeRelativeMSec and endTimeRelativeMSec are relative to the SessionStartTime and are inclusive. + + + + + Create new list of Events that has all the events in the current TraceEvents + that pass the given predicate. + + + + + Returns the TraceLog associated with the events in the TraceEvents + + + + + Returns a time that is guaranteed to be before the first event in the TraceEvents list. + It is returned as DateTime + + + + + Returns a time that is guaranteed to be before the first event in the TraceEvents list. + It is returned as floating point number of MSec since the start of the TraceLog + + + + + Returns a time that is guaranteed to be after the last event in the TraceEvents list. + It is returned as DateTime + + + + + Returns a time that is guaranteed to be after the last event in the TraceEvents list. + It is returned as floating point number of MSec since the start of the TraceLog + + + + + Each process is given a unique index from 0 to TraceProcesses.Count-1 and unlike + the OS Process ID, is unambiguous (The OS process ID can be reused after a + process dies). ProcessIndex represents this index. By using an enum rather than an int + it allows stronger typing and reduces the potential for errors. + + It is expected that users of this library might keep arrays of size TraceProcesses.Count to store + additional data associated with a process in the trace. + + + + + + Returned when no appropriate Process exists. + + + + + A TraceProcesses instance represents the list of processes in the Event log. + + TraceProcesses are IEnumerable, and will return the processes in order of creation time. + + + + + The log associated with this collection of processes. + + + + + The count of the number of TraceProcess instances in the TraceProcesses list. + + + + + Each process that occurs in the log is given a unique index (which unlike the PID is unique), that + ranges from 0 to Count - 1. Return the TraceProcess for the given index. + + + + + Given an OS process ID and a time, return the last TraceProcess that has the same process ID, + and whose process start time is less than 'timeRelativeMSec'. + + If 'timeRelativeMSec' is during the processes's lifetime this is guaranteed to be the correct process. + for the given process ID since process IDs are unique during the lifetime of the process. + + If timeRelativeMSec == TraceLog.SessionDuration this method will return the last process with + the given process ID, even if it had died during the trace. + + + + + + Returns the last process in the log with the given process ID. Useful when the logging session + was stopped just after the processes completed (a common scenario). + + + + + Find the first process in the trace that has the process name 'processName' and whose process + start time is after the given point in time. + A process's name is the file name of the EXE without the extension. + Processes that began before the trace started have a start time of 0, Thus + specifying 0 for the time will include processes that began before the trace started. + + + + + + Find the last process in the trace that has the process name 'processName' and whose process + start time is after the given point in time. + A process's name is the file name of the EXE without the extension. + Processes that began before the trace started have a start time of 0, Thus + specifying 0 for the time will include processes that began before the trace started. + + + + + + An XML representation of the TraceEventProcesses (for debugging) + + + + + Enumerate all the processes that occurred in the trace log, ordered by creation time. + + + + + Given an OS process ID and a time, return the last TraceProcess that has the same process ID, + and whose offset start time is less than 'timeQPC'. If 'timeQPC' is during the thread's lifetime this + is guaranteed to be the correct process. Using timeQPC = TraceLog.sessionEndTimeQPC will return the + last process with the given PID, even if it had died. + + + + + TraceProcesses represents the entire ETL moduleFile log. At the node level it is organized by threads. + + The TraceProcesses also is where we put various caches that are independent of the process involved. + These include a cache for TraceModuleFile that represent native images that can be loaded into a + process, as well as the process lookup tables and a cache that remembers the last calls to + GetNameForAddress(). + + + + + A TraceProcess represents a process in the trace. + + + + + The OS process ID associated with the process. It is NOT unique across the whole log. Use + ProcessIndex for that. + + + + + The index into the logical array of TraceProcesses for this process. Unlike ProcessID (which + may be reused after the process dies, the process index is unique in the log. + + + + + This is a short name for the process. It is the image file name without the path or suffix. + + + + + The command line that started the process (may be empty string if unknown) + + + + + The path name of the EXE that started the process (may be empty string if unknown) + + + + + The time when the process started. Returns the time the trace started if the process existed when the trace started. + + + + + The time when the process started. Returns the time the trace started if the process existed when the trace started. + Returned as the number of MSec from the beginning of the trace. + + + + + The time when the process ended. Returns the time the trace ended if the process existed when the trace ended. + Returned as a DateTime + + + + + The time when the process ended. Returns the time the trace ended if the process existed when the trace ended. + Returned as the number of MSec from the beginning of the trace. + + + + + The process ID of the parent process + + + + + The process that started this process. Returns null if unknown Unlike ParentID + the chain of Parent's will never form a loop. + + + + + If the process exited, the exit status of the process. Otherwise null. + + + + + The amount of CPU time spent in this process based on the kernel CPU sampling events. + + + + + Returns true if the process is a 64 bit process + + + + + The log file associated with the process. + + + + + A list of all the threads that occurred in this process. + + + + + Returns the list of modules that were loaded by the process. The modules may be managed or + native, and include native modules that were loaded event before the trace started. + + + + + Filters events to only those for a particular process. + + + + + Filters events to only that occurred during the time the process was alive. + + + + + + An XML representation of the TraceEventProcess (for debugging) + + + + + Sets the 'Parent' field for the process (based on the ParentID). + + sentinel is internal to the implementation, external callers should always pass null. + TraceProcesses that have a parent==sentinel considered 'illegal' since it woudl form + a loop in the parent chain, which we definately don't want. + + + + + Create a new TraceProcess. It should only be done by log.CreateTraceProcess because + only TraceLog is responsible for generating a new ProcessIndex which we need. 'processIndex' + is a index that is unique for the whole log file (where as processID can be reused). + + + + + This table allows us to intern codeAddress so we only at most one distinct address per process. + + + + + We also keep track of those code addresses that are NOT yet resolved to at least a File (for JIT compiled + things this would be to a method + + + + + This is all the information needed to remember about at JIT compiled method (used in the jitMethods variable) + + + + + This table has a entry for each JIT compiled method that remembers its range. It is actually only needed + for the real time case, as the non-real time case you resolve code addresses on method unload/rundown and thus + don't need to remember the information. This table is NOT persisted in the ETLX file since is only needed + to convert raw addresses into TraceMethods. + + It is a array of arrays to make insertion efficient. Most of the time JIT methods will be added in + contiguous memory (thus will be in order), however from time to time things will 'jump around' to a new + segment. By having a list of lists, (which are in order in both lists) you can efficiently (log(N)) search + as well as insert. + + + + + Maps a newly scheduled "user" activity ID to the ActivityIndex of the + Activity. This keeps track of currently created/scheduled activities + that have not started yet, and for multi-trigger events, created/scheduled + activities that have not conclusively "died" (e.g. by having their "user" + activity ID reused by another activity). + + + + + Each thread is given a unique index from 0 to TraceThreads.Count-1 and unlike + the OS Thread ID, is unambiguous (The OS thread ID can be reused after a + thread dies). ThreadIndex represents this index. By using an enum rather than an int + it allows stronger typing and reduces the potential for errors. + + It is expected that users of this library might keep arrays of size TraceThreads.Count to store + additional data associated with a process in the trace. + + + + + + Returned when no appropriate Thread exists. + + + + + A TraceThreads represents the list of threads in a process. + + + + + Enumerate all the threads that occurred in the trace log. It does so in order of their thread + offset events in the log. + + + + + The count of the number of TraceThreads in the trace log. + + + + + Each thread that occurs in the log is given a unique index (which unlike the PID is unique), that + ranges from 0 to Count - 1. Return the TraceThread for the given index. + + + + + Given an OS thread ID and a time, return the last TraceThread that has the same thread ID, + and whose start time is less than 'timeRelativeMSec'. If 'timeRelativeMSec' is during the thread's lifetime this + is guaranteed to be the correct thread. + + + + + An XML representation of the TraceThreads (for debugging) + + + + + TraceThreads represents the collection of threads in a process. + + + + + + Get the thread for threadID and timeQPC. Create if necessary. If 'isThreadCreateEvent' is true, + then force the creation of a new thread EVEN if the thread exist since we KNOW it is a new thread + (and somehow we missed the threadEnd event). Process is the process associated with the thread. + It can be null if you really don't know the process ID. We will try to fill it in on another event + where we DO know the process id (ThreadEnd event). + + + + + A TraceThread represents a thread of execution in a process. + + + + + The OS process ID associated with the process. + + + + + The index into the logical array of TraceThreads for this process. Unlike ThreadId (which + may be reused after the thread dies) the T index is unique over the log. + + + + + The process associated with the thread. + + + + + The time when the thread started. Returns the time the trace started if the thread existed when the trace started. + Returned as a DateTime + + + + + The time when the thread started. Returns the time the trace started if the thread existed when the trace started. + Returned as the number of MSec from the beginning of the trace. + + + + + The time when the thread ended. Returns the time the trace ended if the thread existed when the trace ended. + Returned as a DateTime + + + + + The time when the thread ended. Returns the time the trace ended if the thread existed when the trace ended. + Returned as the number of MSec from the beginning of the trace. + + + + + The amount of CPU time spent on this thread based on the kernel CPU sampling events. + + + + + Filters events to only those for a particular thread. + + + + + Filters events to only those that occurred during the time a the thread was alive. + + + + + REturns the activity this thread was working on at the time instant 'relativeMsec' + + + + + Represents the "default" activity for the thread, the activity that no one has set + + + + + ThreadInfo is a string that identifies the thread symbolically. (e.g. .NET Threadpool, .NET GC) It may return null if there is no useful symbolic name. + + + + + VerboseThreadName is a name for the thread including the ThreadInfo and the CPU time used. + + + + + The base of the thread's stack. This is just past highest address in memory that is part of the stack + (we don't really know the lower bound (userStackLimit is this lower bound at the time the thread was created + which is not very useful). + + + + + An XML representation of the TraceThread (for debugging) + + + + + Create a new TraceProcess. It should only be done by log.CreateTraceProcess because + only TraceLog is responsible for generating a new ProcessIndex which we need. 'processIndex' + is a index that is unique for the whole log file (where as processID can be reused). + + + + + This is a list of the activities (snippet of threads) that have run on this + thread. They are ordered by time so you can binary search for your activity based + on timestamp. + + + + + We want to have the stack for when CSwtichs BLOCK as well as when they unblock. + this variable keeps track of the last blocking CSWITCH on this thread so that we can + compute this. It is only used during generation of a TraceLog file. + + + + + TraceLoadedModules represents the collection of modules (loaded DLLs or EXEs) in a + particular process. + + + + + The process in which this Module is loaded. + + + + + Returns the module which was mapped into memory at at 'timeRelativeMSec' and includes the address 'address' + Note that Jit compiled code is placed into memory that is not associated with the module and thus will not + be found by this method. + + + + + + Returns the module representing the unmanaged load of a particular fiele at a given time. + + + + + An XML representation of the TraceLoadedModules (for debugging) + + + + + Returns all modules in the process. Note that managed modules may appear twice + (once for the managed load and once for an unmanaged (LoadLibrary) load. + + + + + This function will find the module associated with 'address' at 'timeQPC' however it will only + find modules that are mapped in memory (module associated with JIT compiled methods will not be found). + + + + + Finds the index and module for an a given managed module ID. If not found, new module + should be inserted at index + 1; + + + + + Finds the index and module for an address that lives within the image. If the module + did not match the new entry should go at index+1. + + + + + A TraceLoadedModule represents a module (DLL or EXE) that was loaded into a process. It represents + the time that this module was mapped into the processes address space. + + + + + The address where the DLL or EXE was loaded. Will return 0 for managed modules without NGEN images. + + + + + The load time is the time the LoadLibrary was done if it was loaded from a file, otherwise is the + time the CLR loaded the module. Expressed as a DateTime + + + + + The load time is the time the LoadLibrary was done if it was loaded from a file, otherwise is the + time the CLR loaded the module. Expressed as as MSec from the beginning of the trace. + + + + + The load time is the time the FreeLibrary was done if it was unmanaged, otherwise is the + time the CLR unloaded the module. Expressed as a DateTime + + + + + The load time is the time the FreeLibrary was done if it was unmanaged, otherwise is the + time the CLR unloaded the module. Expressed as MSec from the beginning of the trace. + + + + + The process that loaded this module + + + + + An ID that uniquely identifies the module in within the process. Works for both the managed and unmanaged case. + + + + + If this managedModule was a file that was mapped into memory (eg LoadLibary), then ModuleFile points at + it. If a managed module does not have a file associated with it, this can be null. + + + + + Shortcut for ModuleFile.FilePath, but returns the empty string if ModuleFile is null + + + + + Shortcut for ModuleFile.Name, but returns the empty string if ModuleFile is null + + + + + Because .NET applications have AppDomains, a module that is loaded once from a process + perspective, might be loaded several times (once for each AppDomain) from a .NET perspective + This property returns the loadedModule record for the first such managed module + load associated with this load. + + + + + + An XML representation of the TraceLoadedModule (used for debugging) + + + + + + See IFastSerializable.ToStream. + + + + + See IFastSerializable.FromStream. + + + + + A TraceManagedModule represents the loading of a .NET module into .NET AppDomain. + It represents the time that that module an be used in the AppDomain. + + + + + The module ID that the .NET Runtime uses to identify the file (module) associated with this managed module + + + + + The Assembly ID that the .NET Runtime uses to identify the assembly associated with this managed module. + + + + + Returns true if the managed module was loaded AppDOmain Neutral (its code can be shared by all appdomains in the process. + + + + + If the managed module is an IL module that has an NGEN image, return it. + + + + + An XML representation of the TraceManagedModule (used for debugging) + + + + + CallStackIndex uniquely identifies a callstack within the log. Valid values are between 0 and + TraceCallStacks.Count-1. Thus, an array can be used to 'attach' data to a call stack. + + + + + Returned when no appropriate CallStack exists. + + + + + Call stacks are so common in most traces, that having a .NET object (a TraceEventCallStack) for + each one is often too expensive. As optimization, TraceLog also assigns a call stack index + to every call stack and this index uniquely identifies the call stack in a very light weight fashion. + + To be useful, however you need to be able to ask questions about a call stack index without creating + a TraceEventCallStack. This is the primary purpose of a TraceCallStacks (accessible from TraceLog.CallStacks). + It has a set of + methods that take a CallStackIndex and return properties of the call stack (like its caller or + its code address). + + + + + + Returns the count of call stack indexes (all Call Stack indexes are strictly less than this). + + + + + Given a call stack index, return the code address index representing the top most frame associated with it + + + + + Given a call stack index, look up the call stack index for caller. Returns CallStackIndex.Invalid at top of stack. + + + + + Given a call stack index, returns the number of callers for the call stack + + + + + Given a call stack index, returns a TraceCallStack for it. + + + + + Returns the TraceCodeAddresses instance that can resolve CodeAddressIndexes in the TraceLog + + + + + Given a call stack index, returns the ThreadIndex which represents the thread for the call stack + + + + + Given a call stack index, returns the TraceThread which represents the thread for the call stack + + + + + An XML representation of the TraceCallStacks (used for debugging) + + + + + IEnumerable Support + + + + + Used to 'undo' the effects of adding a eventToStack that you no longer want. This happens when we find + out that a eventToStack is actually got more callers in it (when a eventToStack is split). + + + + + + Returns an index that represents the 'threads' of the stack. It encodes the thread which owns this stack into this. + We encode this as -ThreadIndex - 2 (since -1 is the Invalid node) + + + + + A TraceCallStack is a structure that represents a call stack as a linked list. Each TraceCallStack + contains two properties, the CodeAddress for the current frame, and the TraceCallStack of the + caller of this frame. The Caller property will return null at the thread start frame. + + + + + Return the CallStackIndex that uniquely identifies this call stack in the TraceLog. + + + + + Returns the TraceCodeAddress for the current method frame in the linked list of frames. + + + + + The TraceCallStack for the caller of of the method represented by this call stack. Returns null at the end of the list. + + + + + The depth (count of callers) of this call stack. + + + + + An XML representation of the TraceCallStack (used for debugging) + + + + + Writes an XML representation of the TraceCallStack to the stringbuilder 'sb' + + + + + CodeAddressIndex uniquely identifies a symbolic codeAddress within the log . + Valid values are between 0 and TraceCodeAddresses.Count. Thus, an array + can be used to 'attach' data to a code address. + + + + + Returned when no appropriate Method exists. + + + + + Code addresses are so common in most traces, that having a .NET object (a TraceCodeAddress) for + each one is often too expensive. As optimization, TraceLog also assigns a code address index + to every code address and this index uniquely identifies the code address in a very light weight fashion. + + To be useful, however you need to be able to ask questions about a code address index without creating + a TraceCodeAddress. This is the primary purpose of a TraceCodeAddresses (accessible from TraceLog.CodeAddresses). + It has a set of + methods that take a CodeAddressIndex and return properties of the code address (like its method, address, and module file) + + + + + + Returns the count of code address indexes (all code address indexes are strictly less than this). + + + + + Given a code address index, return the name associated with it (the method name). It will + have the form MODULE!METHODNAME. If the module name is unknown a ? is used, and if the + method name is unknown a hexadecimal number is used as the method name. + + + + + Given a code address index, returns the virtual address of the code in the process. + + + + + Given a code address index, returns the index for the module file (representing the file's path) + + + + + Given a code address index, returns the index for the method associated with the code address (it may return MethodIndex.Invalid + if no method can be found). + + + + + Given a code address index, returns the module file (the DLL paths) associated with it + + + + + If the code address is associated with managed code, return the IL offset within the method. If the method + is unmanaged -1 is returned. To determine the IL offset the PDB for the NGEN image (for NGENed code) or the + correct .NET events (for JIT compiled code) must be present. If this information is not present -1 is returned. + + + + + Given a code address index, returns a TraceCodeAddress for it. + + + + + Returns the TraceMethods object that can look up information from MethodIndexes + + + + + Returns the TraceModuleFiles that can look up information about ModuleFileIndexes + + + + + Indicates the number of managed method records that were encountered. This is useful to understand if symbolic information 'mostly works'. + + + + + Initially CodeAddresses for unmanaged code will have no useful name. Calling LookupSymbolsForModule + lets you resolve the symbols for a particular file so that the TraceCodeAddresses for that DLL + will have Methods (useful names) associated with them. + + + + + A TraceCodeAddress can contain a method name, but does not contain number information. To + find line number information you must read the PDB again and fetch it. This is what + GetSoruceLine does. + + Given a SymbolReader (which knows how to look up PDBs) and a code address index (which + represent a particular point in execution), find a SourceLocation (which represents a + particular line number in a particular source file associated with the code address. + Returns null if anything goes wrong (and diagnostic information will be written to the + log file associated with the SymbolReader. + + + + + + The number of times a particular code address appears in the log. Unlike TraceCodeAddresses.Count, which tries + to share a code address as much as possible, TotalCodeAddresses counts the same code address in different + call stacks (and even if in the same stack) as distinct. This makes TotalCodeAddresses a better measure of + the 'popularity' of a particular address (which can factor into decisions about whether to call LookupSymbolsForModule) + + The sum of ModuleFile.CodeAddressesInModule for all modules should sum to this number. + + + + + + If set to true, will only use the name of the module and not the PDB GUID to confirm that a PDB is correct + for a given DLL. Setting this value is dangerous because it is easy for the PDB to be for a different + version of the DLL and thus give inaccurate method names. Nevertheless, if a log file has no PDB GUID + information associated with it, unsafe PDB matching is the only way to get at least some symbolic information. + + + + + Returns an XML representation of the TraceCodeAddresses (for debugging) + + + + + We expose ILToNativeMap internally so we can do diagnostics. + + + + + IEnumerable support. + + + + + Called when JIT CLR Rundown events are processed. It will look if there is any + address that falls into the range of the JIT compiled method and if so log the + symbolic information (otherwise we simply ignore it) + + + + + Adds a JScript method + + + + + Allows you to get a callback for each code address that is in the range from start to + start+length within the process 'process'. If 'considerResolved' is true' then the address range + is considered resolved and future calls to this routine will not find the addresses (since they are resolved). + + + + + Gets the symbolic information entry for 'address' which can be any address. If it falls in the + range of a symbol, then that symbolic information is returned. Regardless of whether symbolic + information is found, however, an entry is created for it, so every unique address has an entry + in this table. + + + + + All processes might have kernel addresses in them, this returns the kernel process (process ID == 0) if 'address' is a kernel address. + + + + + Sort from lowest address to highest address. + + + + + Do symbol resolution for all addresses in the log file. + + + + + Look up the SymbolModule (open PDB) for a given moduleFile. Will generate NGEN pdbs as needed. + + + + + Returns true if 'moduleFile' seems to be unchanged from the time the information about it + was generated. Logs messages to 'log' if it fails. + + + + + A CodeAddressInfo is the actual data stored in the ETLX file that represents a + TraceCodeAddress. It knows its Address in the process and it knows the + TraceModuleFile (which knows its base address), so it also knows its relative + address in the TraceModuleFile (which is what is needed to look up the value + in the PDB. + + Note that by the time that the CodeAddressInfo is persisted in the ETLX file + it no longer knows the process it originated from (thus separate processes + with the same address and same DLL file loaded at the same address can share + the same CodeAddressInfo. This is actually reasonably common, since OS tend + to load at their preferred base address. + + We also have to handle the managed case, in which case the CodeAddressInfo may + also know about the TraceMethod or the ILMapIndex (which remembers both the + method and the line numbers for managed code. + + However when the CodeAddressInfo is first created, we don't know the TraceModuleFile + so we also need to remember the Process + + + + + + This is only valid until MethodIndex or ModuleFileIndex is set. + + + + + Only for managed code. + + + + + Only for unmanaged code. TODO, this can be folded into methodOrProcessIlMap index and save a DWORD. + since if the method or IlMap is present then you can get the ModuelFile index from there. + + + + + This is a count of how many times this code address appears in any stack in the trace. + It is a measure of what popular the code address is (whether we should look up its symbols). + + + + + Find the ILToNativeMap for 'methodId' in process associated with 'processIndex' + and then remove it from the table (this is what you want to do when the method is unloaded) + + + + + Conceptually a TraceCodeAddress represents a particular point of execution within a particular + line of code in some source code. As a practical matter, they are represented two ways + depending on whether the code is managed or not. + * For native code (or NGened code), it is represented as a virtual address along with the loaded native + module that includes that address along with its load address. A code address does NOT + know its process because they can be shared among all processes that load a particular module + at a particular location. These code addresses will not have methods associated with them + unless symbols information (PDBS) are loaded for the module using the LookupSymbolsForModule. + + * For JIT compiled managed code, the address in a process is eagerly resolved into a method, module + and an IL offset and that is stored in the TraceCodeAddress. + + Sometimes it is impossible to even determine the module associated with a virtual + address in a process. These are represented as simply the virtual address. + + + Because code addresses are so numerous, consider using CodeAddressIndex instead of TraceCodeAddress + to represent a code address. Methods on TraceLog.CodeAddresses can access all the information + that would be in a TraceCodeAddress from a CodeAddressIndex without the overhead of creating + a TraceCodeAddress object. + + + + + + The CodeAddressIndex that uniquely identifies the same code address as this TraceCodeAddress + + + + + The Virtual address of the code address in the process. (Note that the process is unknown by the code address to allow for sharing) + + + + + The full name (Namespace name.class name.method name) of the method associated with this code address. + Returns the empty string if no method is associated with the code address. + + + + + Returns the TraceMethod associated with this code address or null if there is none. + + + + + If the TraceCodeAddress is associated with managed code, return the IL offset within the method. If the method + is unmanaged -1 is returned. To determine the IL offset the PDB for the NGEN image (for NGENed code) or the + correct .NET events (for JIT compiled code) must be present. If this information is not present -1 is returned. + + + + + A TraceCodeAddress can contain a method name, but does not contain number information. To + find line number information you must read the PDB again and fetch it. This is what + GetSoruceLine does. + + Given a SymbolReader (which knows how to look up PDBs) find a SourceLocation (which represents a + particular line number in a particular source file associated with the current TraceCodeAddress. + Returns null if anything goes wrong (and diagnostic information will be written to the + log file associated with the SymbolReader. + + + + + + Returns the TraceModuleFile representing the DLL path associated with this code address (or null if not known) + + + + + ModuleName is the name of the file without path or extension. + + + + + The full path name of the DLL associated with this code address. Returns empty string if not known. + + + + + The CodeAddresses container that this Code Address lives within + + + + + An XML representation for the CodeAddress (for debugging) + + + + + Writes an XML representation for the CodeAddress to the stringbuilder sb + + + + + MethodIndex uniquely identifies a method within the log. Valid values are between 0 and + TraceMethods.Count-1. Thus, an array can be used to 'attach' data to a method. + + + + + Returned when no appropriate Method exists. + + + + + Methods are so common in most traces, that having a .NET object (a TraceMethod) for + each one is often too expensive. As optimization, TraceLog also assigns a method index + to every method and this index uniquely identifies the method in a very light weight fashion. + + To be useful, however you need to be able to ask questions about a method index without creating + a TraceMethod. This is the primary purpose of a TraceMethods (accessible from TraceLog.CodeAddresses.Methods). + It has a set of + methods that take a MethodIndex and return properties of the method (like its name, and module file) + + + + + + Returns the count of method indexes. All MethodIndexes are strictly less than this. + + + + + Given a method index, if the method is managed return the IL meta data MethodToken (returns 0 for native code) + + + + + Given a method index, return the Method's RVA (offset from the base of the DLL in memory) (returns 0 for managed code) + + + + + Given a method index, return the index for the ModuleFile associated with the Method Index. + + + + + Given a method index, return the Full method name (Namespace.ClassName.MethodName) associated with the Method Index. + + + + + Given a method index, return a TraceMethod that also represents the method. + + + + + Returns an XML representation of the TraceMethods. + + + + + IEnumerable support + + + + + + A TraceMethod represents the symbolic information for a particular method. To maximizes haring a TraceMethod + has very little state, just the module and full method name. + + + + + Each Method in the TraceLog is given an index that uniquely identifies it. This return this index for this TraceMethod + + + + + The full name of the method (Namespace.ClassName.MethodName). + + + + + .Net runtime methods have a token (32 bit number) that uniquely identifies it in the meta data of the managed DLL. + This property returns this token. Returns 0 for unmanaged code or method not found. + + + + + For native code the RVA (relative virtual address, which is the offset from the base of the file in memory) + for the method in the file. Returns 0 for managed code or method not found; + + + + + Returns the index for the DLL ModuleFile (which represents its file path) associated with this method + + + + + Returns the ModuleFile (which represents its file path) associated with this method + + + + + A XML representation of the TraceMethod. (Used for debugging) + + + + + + Writes an XML representation of the TraceMethod to the stringbuilder 'sb' + + + + + + + A ModuleFileIndex represents a particular file path on the disk. It is a number + from 0 to MaxModuleFileIndex, which means that you can create a side array to hold + information about module files. + + You can look up information about the ModuleFile from the ModuleFiles type. + + + + + Returned when no appropriate ModuleFile exists. + + + + + TraceModuleFiles is the list of all the ModuleFiles in the trace. It is an IEnumerable. + + + + + Each file is given an index for quick lookup. Count is the + maximum such index (thus you can create an array that is 1-1 with the + files easily). + + + + + Given a ModuleFileIndex, find the TraceModuleFile which also represents it + + + + + Returns the TraceLog associated with this TraceModuleFiles + + + + + Returns an XML representation of the TraceModuleFiles + + + + + Enumerate all the files that occurred in the trace log. + + + + + We cache information about a native image load in a TraceModuleFile. Retrieve or create a new + cache entry associated with 'nativePath' and 'moduleImageBase'. 'moduleImageBase' can be 0 for managed assemblies + that were not loaded with LoadLibrary. + + + + + For a given file name, get the TraceModuleFile associated with it. + + + + + The TraceModuleFile represents a executable file that can be loaded into memory (either an EXE or a + DLL). It represents the path on disk as well as the location in memory where it loads (or + its ModuleID if it is a managed module), but not the load or unload time or the process in which + it was loaded (this allows them to be shared within the trace). + + + + + The ModuleFileIndex ID that uniquely identifies this module file. + + + + + The moduleFile name associated with the moduleFile. May be the empty string if the moduleFile has no moduleFile + (dynamically generated). For managed code, this is the IL moduleFile name. + + + + + This is the short name of the moduleFile (moduleFile name without extension). + + + + + Returns the address in memory where the dll was loaded. + + + + + Returns the size of the DLL when loaded in memory + + + + + Returns the address just past the memory the module uses. + + + + + The name of the symbol file (PDB file) associated with the DLL + + + + + Returns the GUID that uniquely identifies the symbol file (PDB file) for this DLL + + + + + Returns the age (which is a small integer), that is also needed to look up the symbol file (PDB file) on a symbol server. + + + + + Returns the file version string that is optionally embedded in the DLL's resources. Returns the empty string if not present. + + + + + Returns the product name recorded in the file version information. Returns empty string if not present + + + + + Returns a version string for the product as a whole (could include GIT source code hash). Returns empty string if not present + + + + + This is the checksum value in the PE header. Can be used to validate + that the file on disk is the same as the file from the trace. + + + + + This used to be called TimeDateStamp, but linkers may not use it as a + timestamp anymore because they want deterministic builds. It still is + useful as a unique ID for the image. + + + + + If the Product Version fields has a GIT Commit Hash component, this returns it, Otherwise it is empty. + + + + + Returns the time the DLL was built as a DateTime. Note that this may not + work if the build system uses deterministic builds (in which case timestamps + are not allowed. We may not be able to tell if this is a bad timestamp + but we include it because when it is timestamp it is useful. + + + + + The number of code addresses included in this module. This is useful for determining if + this module is worth having its symbolic information looked up or not. It is not + otherwise a particularly interesting metric. + + This number is defined as the number of appearances this module has in any stack + or any event with a code address (If the modules appears 5 times in a stack that + counts as 5 even though it is just one event's stack). + + + + + + If the module file was a managed native image, this is the IL file associated with it. + + + + + Returns an XML representation of the TraceModuleFile (for debugging) + + + + + A ActivityIndex uniquely identifies an Activity in the log. Valid values are between + 0 and Activities.Count-1. + + + + + valid activity indexes are non-negative integers + + + + + Representation of an Activity. An activity can be thought of as a unit of execution associated with + a task or workitem; it executes on one thread, and has a start and end time. An activity keeps track + of its "creator" or "caller" -- which is the activity that scheduled it. Using the "creator" link a + user can determine the chain of activities that led up to the current one. + + Given an event you can get the Activity for the event using the Activity() extension method. + + + + + Describes the kinds of known Activities (used for descriptive purposes alone) + + + + Invalid + + + + Default activity on a thread (when the thread does not execute any code on + behalf of anyone else) + + + + + An activity that was initiated by a Task.Run + + + + + An activity that's a task, but for which we didn't see a "Scheduled" event + + + + + An activity that allows correlation between the antecedent and continuation + + + + A thread started with Thread.Start + + + Native CLR threadpool workitem + + + Native CLR IO threadpool workitem + + + Managed threadpool workitem + + + Generic managed thread transfer + + + Managed async IO workitem + + + WinRT Dispatched workitem + + + + Used when we make up ones because we know that have to be there but we don't know enough to do more than that. + + + + + An activity that allows correlation between the antecedent and continuation + if have bit 5 set it means you auto-compete + + + + + Same as TaskWait, hwoever it auto-completes + + + + + Managed timer workitem + + + + A trace-wide unique id identifying an activity + + + The activity that initiated or caused the current one + + + + This return an unique string 'name' for the activity. It is a the Index followed by + a - followed by the TPL index (if available). It is a bit nicer since it gives + more information for debugging. + + + + + Computes the creator path back to root. + + + + The thread on which the activity is running + + + True if there may be multiple activities that were initiated by caller (e.g. managed Timers) + + + A descriptive label for the activity + TODO: eliminate and use ToString()? + + + + + A thread activity is the activity associate with an OS thread. It is special because it may + have a region that is disjoint. + + + + Time from beginning of trace (in msec) when activity started executing + + + Time from beginning of trace (in msec) when activity completed execution. Does not include children. + + + The event index of the TraceEvent instance that created/scheduled this activity + + + The call stack index of the TraceEvent instance that scheduled (caused the creation of) the activity + + + Time from beginning of trace (in msec) when activity was scheduled + + + + To use mainly for debugging + + + + + TraceLogOptions control the generation of a TraceLog (ETLX file) from an ETL file. + + + + + Creates a new object containing options for constructing a TraceLog file. + + + + + If non-null, this is a predicate that, given a file path to a dll, answers the question + whether the PDB associated with that DLL be looked up and its symbolic information added + to the TraceLog file as part of conversion. Symbols can be looked up afterward when + the file is later opened, so the default (which is to look up no symbols during + conversion) is typically OK. + + + + + Resolving symbols from a symbol server can take a long time. If + there is a DLL that always fails, it can be quite annoying because + it will always cause delays, By specifying only local symbols it + will only resolve the symbols if it can do so without the delay of network traffic. + Symbols that have been previously cached locally from a symbol + server count as local symbols. + + + + + By default symbols are only resolved if there are stacks associated with the trace. + Setting this option forces resolution even if there are no stacks. + + + + + Writes status to this log. Useful for debugging symbol issues. + + + + + If ConversionLogName is set, it indicates that any messages associated with creating the TraceLog should be written here. + + + + + ETL files typically contain a large number of 'bookkeeping' event for resolving names of files, or methods or to indicate information + about processes that existed when the trace was started (DCStart and DCStop events). By default these events are stripped from + the ETLX file because their information has already been used to do the bookkeeping as part of the conversion + + However sometimes it is useful to keep these events (typically for debugging TraceEvent itself) and setting this + property to true will cause every event in the ETL file to be copied as an event to the ETLX file. + + + + + + Sometimes ETL files are too big , and you just want to look at a fraction of it to speed things up + (or to keep file size under control). The MaxEventCount property allows that. 10M will produce a 3-4GB ETLX file. + 1M is a good value to keep ETLX file size under control. Note that that the conversion still scan the entire + original ETL file too look for bookkeeping events, however MaxEventCount events will be transfered to the ETLX + file as events. + + The default is 10M because ETLX has a restriction of 4GB in size. + + + + + + If an ETL file has too many events for efficient processing the first part of the trace can be skipped by setting this + property. Any event which happens before 'SkipMSec' into the session will be filtered out. This property is + intended to be used along with the MaxEventCount property to carve out a arbitrary chunk of time from an ETL + file as it is converted to an ETLX file. + + + + + If this delegate is non-null, it is called if there are any lost events or if the file was truncated. + It is passed a bool whether the ETLX file was truncated, as well as the number of lost events and the + total number of events in the ETLX file. You can throw if you want to abort. + + + + + If you have the manifests for particular providers, you can read them in explicitly by setting this directory. + All files of the form *.manifest.xml will be read into the DynamicTraceEventParser's database before conversion + starts. + + + + + If errors occur during conversion, just assume the traced ended at that point and continue. + + + + + The TraceEvent instances returned during the processing of a TraceLog have additional capabilities that these extension methods can access. + + + + + Finds the TraceProcess associated with a TraceEvent. + Guaranteed to be non-null for non-real-time sessions if the process ID is != -1 + + + + + Finds the TraceThread associated with a TraceEvent. + Guaranteed to be non-null for non-real-time sessions if the process ID is != -1 + + + + + Finds the TraceLog associated with a TraceEvent. + + + + + Finds the TraceCallStack associated with a TraceEvent. Returns null if the event does not have callstack. + + + + + Finds the CallStack index associated with a TraceEvent. Returns Invalid if the event does not have callstack. + + + + + Finds the CallStack index associated the blocking thread for CSwitch event + + + + + Finds the TraceCallStacks associated with a TraceEvent. + + + + + Finds the Activity associated with a TraceEvent + + + + + Finds the ActivityIndex associated with a TraceEvent + + + + + For a PageFaultTraceData event, gets the TraceCodeAddress associated with the ProgramCounter address. + + + + + For a PageFaultTraceData event, gets the CodeAddressIndex associated with the ProgramCounter address. + + + + + For a SampledProfileTraceData event, gets the TraceCodeAddress associated with the InstructionPointer address. + + + + + For a SampledProfileTraceData event, gets the CodeAddressIndex associated with the InstructionPointer address. + + + + + For a SysCallEnterTraceData event, gets the CodeAddressIndex associated with the SysCallAddress address. + + + + + For a PMCCounterProfTraceData event, gets the TraceCodeAddress associated with the InstructionPointer address. + + + + + For a PMCCounterProfTraceData event, gets the CodeAddressIndex associated with the InstructionPointer address. + + + + + For a ISRTraceData event, gets the CodeAddressIndex associated with the Routine address. + + + + + For a DPCTraceData event, gets the CodeAddressIndex associated with the Routine address. + + + + + TraceLoggingEvnetId is a class that manages assigning event IDs (small 64k numbers) + to TraceLogging Style events (which don't have them). Because TraceEvent uses EventIDs + so fundamentally this deficiency is very problematic. + + Arguably this should have been done by the ETW system itself. + + You use it by calling TestForTraceLoggingEventAndFixupIfNeeded on eventRecords. + You also have to explicitly call 'Dispose' when you are done with this class. + + + + + Checks to see if eventRecord has TraceLogging meta data associated with it (EVENT_HEADER_EXT_TYPE_EVENT_SCHEMA_TL) + and if so updates EventHeader.Id to be an event ID unique to that provider/opcode/meta-data blob. + + + + + cleans up native memory allocated by this routine. + + + + + Checks to see if this event has TraceLogging meta data associated with it (EVENT_HEADER_EXT_TYPE_EVENT_SCHEMA_TL) + and if so updates EventHeader.Id to be an event ID unique to that provider/opcode/meta-data blob. + + + + + given that 'eventRecord' is a TraceLogging event (with meta-data 'metaData'), return a eventID that is unique + to that provider/opcode/meta-data blob. + + + + + ProviderMetaDataKey is what we use to look up TraceLogging meta-data. It is + basically just GUID (representing the provider) an opcode (start/stop) and + a blob (representing the TraceLogging meta-data for an event) that knows how to + compare itself so it can be a key to a hash table. + + + + + A HistoryDictionary is designed to look up 'handles' (pointer sized quantities), that might get reused + over time (eg Process IDs, thread IDs). Thus it takes a handle AND A TIME, and finds the value + associated with that handle at that time. + + + + + Adds the association that 'id' has the value 'value' from 'startTime100ns' ONWARD until + it is supersede by the same id being added with a time that is after this. Thus if + I did Add(58, 1000, MyValue1), and add(58, 500, MyValue2) 'TryGetValue(58, 750, out val) will return + MyValue2 (since that value is 'in force' between time 500 and 1000. + + + + + Remove all entries associated with a given key (over all time). + + + + + ZippedETLWriter is a helper class used to compress ETW data (ETL files) + along with symbolic information (e.g. NGEN pdbs), as well as other optional + metadata (e.g. collection log files), into a single archive ready for + transfer to another machine. + + + + + Declares the intent to write a new ZIP archive that will + contain ETW file 'etlFilePath' in it as well as symbolic information (NGEN + pdbs) and possibly other information. log is a Text stream to send detailed + information to. + + This routine assumes by default (unless Merge is set to false) that the ETL + file needs to be merged before it is archived. It will also generate all + the NGEN pdbs needed for the archive. + + + You must call the WriteArchive method before any operations actually happen. + Up to that point is is just remembering instructions for WriteArchive to + follow. + + + + + + This is the name of the output archive. By default is the same as the ETL file name + with a .zip' suffix added (thus it will typically be .etl.zip). + + + + + If set this is where messages about progress and detailed error information goes. + While you dont; have to set this, it is a good idea to do so. + + + + + By default ZippedETL file will zip the ETL file itself and the NGEN pdbs associated with it. + You can add additional files to the archive by calling AddFile. In specififed 'archivePath' + is the path in the archive and defaults to just the file name of the original file path. + + + + + Actually do the work specified by the ZippedETLWriter constructors and other methods. + + + + + This is the symbol reader that is used to generate the NGEN Pdbs as needed + If it is not specififed one is created on the fly. + + + + + By default the ETL file is merged before being added to the archive. If + this is not necessary, you can set this to false. + + + + + Uses a compressed format for the ETL file. Normally off. + + + + + By default the symbol files (PDBs) are included in the ZIP file. If this + is not desired for whatever reason, this property can be set to false. + + + + + Do the work at low priority so as to avoid impacting the system. + + + + + Normally WriteArchive creates a ZIP archive. However it is possible that you only wish + to do the merging and NGEN symbol generation. Setting this property to false + will supress the final ZIP operation. + + + + + Normally if you ZIP you will delete the original ETL file. Setting this to false overrides this. + + + + + Returns the list of path names to the NGEN pdbs for any NGEN image in 'etlFile' that has + any samples in it. + + + + + ZippedETLReader is a helper class that unpacks the ZIP files generated + by the ZippedETLWriter class. It can be smart about placing the + symbolic information in these files on the SymbolReader's path so that + symbolic lookup 'just works'. + + + + + Declares the intent to unzip an .ETL.ZIP file that contain an compressed ETL file + (and NGEN pdbs) from the archive at 'zipFilePath'. If present, messages about + the unpacking go to 'log'. Note that this unpacking only happens when the + UnpackArchive() method is called. + + + + + If set messages about unpacking go here. + + + + + The name of the ETL file to extract (it is an error if there is not exactly 1). + If not present it is derived by changing the extension of the zip archive. + + + + + Where to put the symbols. + + + + + After setting any properties to override default behavior, calling this method + will actually do the unpacking. + + + + + A NativeSymbolModule represents symbol information for a native code module. + NativeSymbolModules can potentially represent Managed modules (which is why it is a subclass of that interface). + + NativeSymbolModule should just be the CONTRACT for Native Symbols (some subclass implements + it for a particular format like Windows PDBs), however today because we have only one file format we + simply implement Windows PDBS here. This can be factored out of this class when we + support other formats (e.g. Dwarf). + + To implmente support for Windows PDBs we use the Debug Interface Access (DIA). See + http://msdn.microsoft.com/library/x93ctkx8.aspx for more. I have only exposed what + I need, and the interface is quite large (and not super pretty). + + + + + Returns the name of the type allocated for a given relative virtual address. + Returns null if the given rva does not match a known heap allocation site. + + + + + Finds a (method) symbolic name for a given relative virtual address of some code. + Returns an empty string if a name could not be found. + + + + + Finds a (method) symbolic name for a given relative virtual address of some code. + Returns an empty string if a name could not be found. + symbolStartRva is set to the start of the symbol start + + + + + Fetches the source location (line number and file), given the relative virtual address (RVA) + of the location in the executable. + + + + + This overload of SourceLocationForRva like the one that takes only an RVA will return a source location + if it can. However this version has additional support for NGEN images. In the case of NGEN images + for .NET V4.6.1 or later), the NGEN images can't convert all the way back to a source location, but they + can convert the RVA back to IL artifacts (ilAssemblyName, methodMetadataToken, iloffset). THese can then + be used to look up the source line using the IL PDB. + + Thus if the return value from this is null, check to see if the ilAssemblyName is non-null, and if not + you can look up the source location using that information. + + + + + Managed code is shipped as IL, so RVA to NATIVE mapping can't be placed in the PDB. Instead + what is placed in the PDB is a mapping from a method's meta-data token and IL offset to source + line number. Thus if you have a metadata token and IL offset, you can again get a source location + + + + + The symbol representing the module as a whole. All global symbols are children of this symbol + + + + + The a unique identifier that is used to relate the DLL and its PDB. + + + + + Along with the PdbGuid, there is a small integer + call the age is also used to find the PDB (it represents the different + post link transformations the DLL has undergone). + + + + + A source file represents a source file from a PDB. This is not just a string + because the file has a build time path, a checksum, and it needs to be 'smart' + to copy down the file if requested. + + TODO We don't need this subclass. We can have SourceFile simply a container + that holds the BuildTimePath, hashType and hashValue. The lookup of the + source can then be put on NativeSymbolModule and called from SourceFile generically. + This makes the different symbol files more simmilar and is a nice simplification. + + + + + If the source file is directly available on the web (that is there is a Url that + can be used to fetch it with HTTP Get), then return that Url. If no such publishing + point exists this property will return null. + + + + + Try to fetch the source file associated with 'buildTimeFilePath' from the symbol server + information from the PDB from 'pdbPath'. Will return a path to the returned file (uses + SourceCacheDirectory associated symbol reader for context where to put the file), + or null if unsuccessful. + + There is a tool called pdbstr associated with srcsrv that basically does this. + pdbstr -r -s:srcsrv -p:PDBPATH + will dump it. + + The basic flow is + + There is a variables section and a files section + + The file section is a list of items separated by *. The first is the path, the rest are up to you + + You form a command by using the SRCSRVTRG variable and substituting variables %var1 where var1 is the first item in the * separated list + There are special operators %fnfile%(XXX), etc that manipulate the string XXX (get file name, translate \ to / ... + + If what is at the end is a valid URL it is looked up. + + + + + Parse the 'srcsrv' stream in a PDB file and return the target for SourceFile + represented by the 'this' pointer. This target is iether a ULR or a local file + path. + + You can dump the srcsrv stream using a tool called pdbstr + pdbstr -r -s:srcsrv -p:PDBPATH + + The target in this stream is called SRCSRVTRG and there is another variable SRCSRVCMD + which represents the command to run to fetch the soruce into SRCSRVTRG + + To form the target, the stream expect you to private a %targ% variable which is a directory + prefix to tell where to put the source file being fetched. If the source file is + available via a URL this variable is not needed. + + ********* This is a typical example of what is in a PDB with source server information. + SRCSRV: ini ------------------------------------------------ + VERSION=3 + INDEXVERSION=2 + VERCTRL=Team Foundation Server + DATETIME=Thu Mar 10 16:15:55 2016 + SRCSRV: variables ------------------------------------------ + TFS_EXTRACT_CMD=tf.exe view /version:%var4% /noprompt "$%var3%" /server:%fnvar%(%var2%) /output:%srcsrvtrg% + TFS_EXTRACT_TARGET=%targ%\%var2%%fnbksl%(%var3%)\%var4%\%fnfile%(%var1%) + VSTFDEVDIV_DEVDIV2=http://vstfdevdiv.redmond.corp.microsoft.com:8080/DevDiv2 + SRCSRVVERCTRL=tfs + SRCSRVERRDESC=access + SRCSRVERRVAR=var2 + SRCSRVTRG=%TFS_extract_target% + SRCSRVCMD=%TFS_extract_cmd% + SRCSRV: source files --------------------------------- ------ + f:\dd\externalapis\legacy\vctools\vc12\inc\cvconst.h*VSTFDEVDIV_DEVDIV2*/DevDiv/Fx/Rel/NetFxRel3Stage/externalapis/legacy/vctools/vc12/inc/cvconst.h*1363200 + f:\dd\externalapis\legacy\vctools\vc12\inc\cvinfo.h*VSTFDEVDIV_DEVDIV2*/DevDiv/Fx/Rel/NetFxRel3Stage/externalapis/legacy/vctools/vc12/inc/cvinfo.h*1363200 + f:\dd\externalapis\legacy\vctools\vc12\inc\vc\ammintrin.h*VSTFDEVDIV_DEVDIV2*/DevDiv/Fx/Rel/NetFxRel3Stage/externalapis/legacy/vctools/vc12/inc/vc/ammintrin.h*1363200 + SRCSRV: end ------------------------------------------------ + + ********* And here is a more modern one where the source code is available via a URL. + SRCSRV: ini ------------------------------------------------ + VERSION=2 + INDEXVERSION=2 + VERCTRL=http + SRCSRV: variables ------------------------------------------ + SRCSRVTRG=https://nuget.smbsrc.net/src/%fnfile%(%var1%)/%var2%/%fnfile%(%var1%) + SRCSRVCMD= + SRCSRVVERCTRL=http + SRCSRV: source files --------------------------------------- + c:\Users\rafalkrynski\Documents\Visual Studio 2012\Projects\DavidSymbolSourceTest\DavidSymbolSourceTest\Demo.cs*SQPvxWBMtvANyCp8Pd3OjoZEUgpKvjDVIY1WbaiFPMw= + SRCSRV: end ------------------------------------------------ + + + returns the target source file path + returns the command to fetch the target source file + Specify the value for %targ% variable. This is the + directory where source files can be fetched to. Typically the returned file is under this directory + If the value is null, %targ% variable be emtpy. This assumes that the resulting file is something + that does not need to be copied to the machine (either a URL or a file that already exists) + + + + Returns the location of the tf.exe executable or + + + + + + Gets the 'srcsvc' data stream from the PDB and return it in as a string. Returns null if it is not present. + + There is a tool called pdbstr associated with srcsrv that basically does this. + pdbstr -r -s:srcsrv -p:PDBPATH + will dump it. + + + + + For Project N modules it returns the list of pre merged IL assemblies and the corresponding mapping. + + + + + For ProjectN modules, gets the merged IL image embedded in the .PDB (only valid for single-file compilation) + + + + + For ProjectN modules, gets the pseudo-assembly embedded in the .PDB, if there is one. + + + + + + For ProjectN modules, gets the binary blob that describes the mapping from RVAs to methods. + + + + + For ProjectN modules, gets the binary blob that describes the mapping from RVAs to types. + + + + + + This static class contains the GetTypeName method for retrieving the type name of + a heap allocation site. + + See https://github.com/KirillOsenkov/Dia2Dump/blob/master/PrintSymbol.cpp for more details + + + + + Represents a single symbol in a PDB file. + + + + + The name for the symbol + + + + + The relative virtual address (offset from the image base when loaded in memory) of the symbol + + + + + The length of the memory that the symbol represents. + + + + + A small integer identifier tat is unique for that symbol in the DLL. + + + + + Decorated names are names that most closely resemble the source code (have overloading). + However when the linker does not directly support all the expressiveness of the + source language names are encoded to represent this. This return this encoded name. + + + + + Returns true if the two symbols live in the same linker section (e.g. text, data ...) + + + + + Returns the children of the symbol. Will return null if there are no children. + + + + + Returns the children of the symbol, with the given tag. Will return null if there are no children. + + + + + Compares the symbol by their relative virtual address (RVA) + + + + + override + + + + + SymPath is a class that knows how to parse _NT_SYMBOL_PATH syntax. + + + + + This allows you to set the _NT_SYMBOL_PATH as a from the windows environment. + + + + + This 'cleans up' a symbol path. In particular + Empty ones are replaced with good defaults (symweb or msdl) + All symbol server specs have local caches (%Temp%\SymbolCache if nothing else is specified). + + Note that this routine does NOT update _NT_SYMBOL_PATH. + + + + + Returns the string representing a symbol path for the 'standard' Microsoft symbol servers. + This returns the public msdl.microsoft.com server if outside Microsoft. + + + + + Create an empty symbol path + + + + + Create a symbol that represents 'path' (the standard semicolon separated list of locations) + + + + + Returns the List of elements in the symbol path. + + + + + Append all the elements in the semicolon separated list, 'path', to the symbol path represented by 'this'. + returns the 'this' pointer + + + + + append a new symbol path element to the beginning of the symbol path represented by 'this'. + returns the 'this' pointer + + + + + insert all the elements in the semicolon separated list, 'path' to the beginning of the symbol path represented by 'this'. + returns the 'this' pointer + + + + + insert a new symbol path element to the beginning of the symbol path represented by 'this'. + returns the 'this' pointer + + + + + If you need to cache files locally, put them here. It is defined + to be the first local path of a SRV* qualification or %TEMP%\SymbolCache + if not is present. + + + + + People can use symbol servers without a local cache. This is bad, add one if necessary. + + + + + Removes all references to remote paths. This insures that network issues don't cause grief. + + + + + Create a new symbol path which first search all machine local locations (either explicit location or symbol server cache locations) + followed by all non-local symbol server. This produces better behavior (If you can find it locally it will be fast) + + + + + Returns the string representation (semicolon separated) for the symbol path. + + + + + + Writes an XML representation of the symbol path to 'writer' + + + + + Checks to see 'computerName' exists (there is a Domain Names Service (DNS) reply to it) + This routine times out relative quickly (after 700 msec) if there is a problem reaching + the computer, and returns false. + + + + + This is the backing field for the lazily-computed property. + + + + + SymPathElement represents the text between the semicolons in a symbol path. It can be a symbol server specification or a simple directory path. + + SymPathElement follows functional conventions. After construction everything is read-only. + + + + + Returns true if this element of the symbol server path a symbol server specification + + + + + Returns the local cache for a symbol server specification. returns null if not specified + + + + + Returns location to look for symbols. This is either a directory specification or an URL (for symbol servers) + This can be null if it is not specified (for cache-only paths). + + + + + IsRemote returns true if it looks like the target is not on the local machine. + + + + + Returns the string repsentation for the symbol server path element (e.g. SRV*c:\temp*\\symbols\symbols) + + + + + Implements object interface + + + + + Implements object interface + + + + + A symbol reader represents something that can FIND pdbs (either on a symbol server or via a symbol path) + Its job is to find a full path a PDB. Then you can use OpenSymbolFile to get a SymbolReaderModule and do more. + + + + + Opens a new SymbolReader. All diagnostics messages about symbol lookup go to 'log'. + + + + + Finds the symbol file for 'exeFilePath' that exists on the current machine (we open + it to find the needed info). Uses the SymbolReader.SymbolPath (including Symbol servers) to + look up the PDB, and will download the PDB to the local cache if necessary. It will also + generate NGEN pdbs into the local symbol cache unless SymbolReaderFlags.NoNGenPDB is set. + + By default for NGEN images it returns the NGEN pdb. However if 'ilPDB' is true it returns + the IL PDB. + + Returns null if the pdb can't be found. + + + + + Find the complete PDB path, given just the simple name (filename + pdb extension) as well as its 'signature', + which uniquely identifies it (on symbol servers). Uses the SymbolReader.SymbolPath (including Symbol servers) to + look up the PDB, and will download the PDB to the local cache if necessary. + + A Guid of Empty, means 'unknown' and will match the first PDB that matches simple name. Thus it is unsafe. + + Returns null if the PDB could not be found + + The name of the PDB file (we only use the file name part) + The GUID that is embedded in the DLL in the debug information that allows matching the DLL and the PDB + Tools like BBT transform a DLL into another DLL (with the same GUID) the 'pdbAge' is a small integers + that indicates how many transformations were done + If you know the path to the DLL for this pdb add it here. That way we can probe next to the DLL + for the PDB file. + This is an optional string that identifies the file version (the 'Version' resource information. + It is used only to provided better error messages for the log. + + + + This API looks up an executable file, by its build-timestamp and size (on a symbol server), 'fileName' should be + a simple name (no directory), and you need the buildTimeStamp and sizeOfImage that are found in the PE header. + + Returns null if it cannot find anything. + + + + + Given the path name to a particular PDB file, load it so that you can resolve symbols in it. + + The name of the PDB file to open. + The SymbolReaderModule that represents the information in the symbol file (PDB) + + + + Like OpenSymbolFile, which opens a PDB, but this version will fail (return null) + if it is not WindowsSymbolModule. It is a shortcut for OpenSymbolFile as NativeSymbolModule + + + + + The symbol path used to look up PDB symbol files. Set when the reader is initialized. + + + + + The paths used to look up source files. defaults to _NT_SOURCE_PATH. + + + + + Where symbols are downloaded if needed. Derived from symbol path. It is the first + directory on the local machine in a SRV*DIR*LOC spec, and %TEMP%\SymbolCache otherwise. + + + + + The place where source is downloaded from a source server. + + + + + Is this symbol reader limited to just the local machine cache or not? + + + + + We call back on this when we find a PDB by probing in 'unsafe' locations (like next to the EXE or in the Built location) + If this function returns true, we assume that it is OK to use the PDB. + + + + + If set OnSymbolFileFound will be called when a PDB file is found. + It is passed the complete local file path, the PDB Guid (may be Guid.Empty) and PDB age. + + + + + A place to log additional messages + + + + + Given a full filename path to an NGEN image, insure that there is an NGEN image for it + in the symbol cache. If one already exists, this method simply returns that. If not + it is generated and placed in the symbol cache. When generating the PDB this routine + attempt to resolve line numbers, which DOES require looking up the PDB for the IL image. + Thus routine may do network accesses (to download IL PDBs). + + Note that FindSymbolFilePathForModule calls this, so normally you don't need to call + this method directly. + + By default it places the PDB in the SymbolCacheDirectory using normal symbol server + cache conventions (PDBNAME\Guid-AGE\Name). You can override this by specifying + the outputDirectory parameter. + + The full path name of the PDB generated for the NGEN image. + + + + + Given a NGEN (or ReadyToRun) imge 'ngenImageFullPath' and the PDB path + that we WANT it to generate generate the PDB. Returns either pdbPath + on success or null on failure. + + TODO can be removed when we properly publish the NGEN pdbs as part of build. + + + + + Called when you are done with the symbol reader. Currently does nothing. + + + + + Returns true if 'filePath' exists and is a PDB that has pdbGuid and pdbAge. + if pdbGuid == Guid.Empty, then the pdbGuid and pdbAge checks are skipped. + + + + + Fetches a file from the server 'serverPath' with pdb signature path 'pdbSigPath' (concatinate them with a / or \ separator + to form a complete URL or path name). It will place the file in 'fullDestPath' It will return true if successful + If 'contentTypeFilter is present, this predicate is called with the URL content type (e.g. application/octet-stream) + and if it returns false, it fails. This insures that things that are the wrong content type (e.g. redirects to + some sort of login) fail cleanly. + + You should probably be using GetFileFromServer + + path to server (e.g. \\symbols\symbols or http://symweb) + pdb path with signature (e.g clr.pdb/1E18F3E494DC464B943EA90F23E256432/clr.pdb) + the full path of where to put the file locally + if present this allows you to filter out urls that dont match this ContentType. + + + + Build the full uri from server path and pdb index path + + + + + This just copies a stream to a file path with logging. + + + + + Looks up 'fileIndexPath' on the server 'urlForServer' (concatenate to form complete URL) copying the file to + 'targetPath' and returning targetPath name there (thus it is always a local file). Unlike GetPhysicalFileFromServer, + GetFileFromServer understands how to deal with compressed files and file.ptr (redirection). + + targetPath or null if the file cannot be found. + + + + Deduce the path to where CLR.dll (and in particular NGEN.exe live for the NGEN image 'ngenImagepath') + Returns null if it can't be found. If the NGEN image is associated with a private runtime return + that value in 'privateVerStr' + + + + + We may be a 32 bit app which has File system redirection turned on + Morph System32 to SysNative in that case to bypass file system redirection + + + + + A SymbolModule represents a file that contains symbolic information + (a Windows PDB or Portable PDB). This is the interface that is independent + of what kind of symbolic file format you use. Becase portable PDBs only + support managed code, this shared interface is by necessity the interface + for managed code only (currently only Windows PDBs support native code). + + + + + This is the EXE associated with the Pdb. It may be null or an invalid path. It is used + to help look up source code (it is implicitly part of the Source Path search) + + + + + The path name to the PDB itself. Might be empty if the symbol information is in memory. + + + + + The Guid that is used to uniquely identify the DLL-PDB pair (used for symbol servers) + + + + + Fetches the SymbolReader assoicated with this SymbolModule. This is where shared + attributes (like SourcePath, SymbolPath etc) are found. + + + + + Given a method and an IL offset, return a source location (line number and file). + Returns null if it could not find it. + + + + + If the symbol file format supports SourceLink JSON this routine should be overriden + to return it. + + + + + Return a URL for 'buildTimeFilePath' using the source link mapping (that 'GetSourceLinkJson' fetched) + Returns null if there is URL using the SourceLink + + + + + + + Parses SourceLink information and returns a list of filepath -> url Prefix tuples. + + + + + A SourceLocation represents a point in the source code. That is the file and the line number. + + + + + The source file for the code + + + + + The line number for the code. + + + + + SymbolReaderFlags indicates preferences on how aggressively symbols should be looked up. + + + + + No options this is the common case, where you want to look up everything you can. + + + + + Only fetch the PDB if it lives in the symbolCacheDirectory (is local an is generated). + This will generate NGEN pdbs unless the NoNGenPDBs flag is set. + + + + + No NGEN PDB generation. + + + + + The path of the file at the time the source file was built. We also look here when looking for the source. + + + + + If the source file is directly available on the web (that is there is a Url that + can be used to fetch it with HTTP Get), then return that Url. If no such publishing + point exists this property will return null. + + + + + This may fetch things from the source server, and thus can be very slow, which is why it is not a property. + returns a path to the file on the local machine (often in some machine local cache). + If requireChecksumMatch == false then you can see if you have an exact match by calling ChecksumMatches + (and if there is a checksum with HasChecksum). + + + + + true if the PDB has a checksum for the data in the source file. + + + + + If GetSourceFile is called and 'requireChecksumMatch' == false then you can call this property to + determine if the checksum actually matched or not. This will return true if the original + PDB does not have a checksum (HasChecksum == false) + ; + + + + Look up the source from the source server. Returns null if it can't find the source + By default this simply uses the Url to look it up on the web. If 'Url' returns null + so does this. + + + + + Given 'fileName' which is a path to a file (which may not exist), set + _filePath and _checksumMatches appropriately. Namely _filePath should + always be the 'best' candidate for the source file path (matching checksum + wins, otherwise first existing file wins). + + Returns true if we have a perfect match (no additional probing needed). + + + + + Returns true if 'filePath' matches the checksum OR we don't have a checkdum + (thus if we pass what validity check we have). + + + + + General purpose utilities dealing with archiveFile system directories. + + + + + SafeCopy sourceDirectory to directoryToVersion recursively. The target directory does + no need to exist + + + + + SafeCopy all files from sourceDirectory to directoryToVersion. If searchOptions == AllDirectories + then the copy is recursive, otherwise it is just one level. The target directory does not + need to exist. + + + + + Clean is sort of a 'safe' recursive delete of a directory. It either deletes the + files or moves them to '*.deleting' names. It deletes directories that are completely + empty. Thus it will do a recursive delete when that is possible. There will only + be *.deleting files after this returns. It returns the number of files and directories + that could not be deleted. + + + + + Removes the oldest directories directly under 'directoryPath' so that + only 'numberToKeep' are left. + + Directory to removed old files from. + The number of files to keep. + true if there were no errors deleting files + + + + DirectoryUtilities.GetFiles is basicaly the same as Directory.GetFiles + however it returns IEnumerator, which means that it lazy. This is very important + for large directory trees. A searchPattern can be specified (Windows wildcard conventions) + that can be used to filter the set of archiveFile names returned. + + Suggested Usage + + foreach(string fileName in DirectoryUtilities.GetFiles("c:\", "*.txt")){ + Console.WriteLine(fileName); + } + + + The base directory to enumerate + A pattern to filter the names (windows filename wildcards * ?) + Indicate if the search is recursive or not. + The enumerator for all archiveFile names in the directory (recursively). + + + + Returns a lazy enumerable for every path in 'directoryName' that matchs 'searchPattern' (default is *)MO + + + + + General purpose utilities dealing with archiveFile system files. + + + + + GetLines works much like File.ReadAllLines, however instead of returning a + array of lines, it returns a IEnumerable so that the archiveFile is not read all + at once. This allows 'foreach' syntax to be used on very large files. + + Suggested Usage + + foreach(string lineNumber in FileUtilities.GetLines("largeFile.txt")){ + Console.WriteLine(lineNumber); + } + + The base directory to enumerate. + The enumerator for all lines in the archiveFile. + + + + Given archiveFile specifications possibly with wildcards in them + Returns an enumerator that returns each expanded archiveFile name in turn. + + If searchOpt is AllDirectories it does a recursive match. + + + + + Delete works much like File.Delete, except that it will succeed if the + archiveFile does not exist, and will rename the archiveFile so that even if the archiveFile + is locked the original archiveFile variable will be made available. + + It renames the archiveFile with a '[num].deleting'. These files might be left + behind. + + It returns true if it was completely successful. If there is a *.deleting + archiveFile left behind, it returns false. + + The variable of the archiveFile to delete + + + + Try to delete 'fileName' catching any exception. Returns true if successful. It will delete read-only files. + + + + + SafeCopy sourceFile to destinationFile. If the destination exists + used ForceDelete to get rid of it first. + + + + + Moves sourceFile to destinationFile. If the destination exists + used ForceDelete to get rid of it first. + + + + + Returns true if the two file have exactly the same content (as a stream of bytes). + + + + + Utilities associated with file name paths. + + + + + Given a path and a superdirectory path relativeToDirectory compute the relative path (the path from) relativeToDirectory + + + + + General utilities associated with streams. + + + + + Open the 'fromFilePath' and write its contents to 'toStream' + + + + + Open the 'toFilePath' for writing and write the contents of 'fromStream' to it + + + + + CopyStream simply copies 'fromStream' to 'toStream' + + + + + The important thing about these general utilities is that they have only dependencies on mscorlib and + System (they can be used from anywhere). + + + + + Given an XML element, remove the closing operator for it, so you can add new child elements to it by concatination. + + + + + Given an object 'obj' do ToString() on it, and then transform it so that all speical XML characters are escaped and return the result. + If 'quote' is true also surround the resulting object with double quotes. + + + + + A shortcut for XmlEscape(obj, true) (that is ToString the object, escape XML chars, and then surround with double quotes. + + + + + Create a doubly quoted string for the decimal integer value + + + + + Create a double quoted string for the hexidecimal value of 'value' + + + + + Create a double quoted string for the hexidecimal value of 'value' + + + + + Create a double quoted string for the hexidecimal value of 'value' + + + + + Create a double quoted string for the hexidecimal value of 'value' + + + + + Used to send the rawManifest into the event stream as a series of events. + + + + + Finds native DLLS next to the managed DLL that uses them. + + + + + ManifestModule.FullyQualifiedName returns this as file path if the assembly is loaded as byte array + + + + + Loads a native DLL with a filename-extension of 'simpleName' by adding the path of the currently executing assembly + + + + + + + Gets the name of the directory containing compiled binaries (DLLs) which have the same architecture as the + currently executing process. + + + + + This is the backing field for the lazily-computed property. + + + + + A StackSource that aggregates information from other StackSources into a single unified view. + + + Each StackSource has a name associated with it. The stacks for each StackSource will be grouped under + a pseudo-frame named the same as the source name. Source names are specified on initialization. + + + + + Initialize a new AggregateStackSource. + + An IEnumerable of KeyValuePairs mapping source names to StackSources. + + + + Enumerate samples with a callback function. + + The function to call on each sample. + + + + override + + + + + Enumerate samples for a given set of scenarios with a callback function. + + The function to call on each sample. + An array of length ScenarioCount. If scenariosIncluded[i] == true, include scenario i. + + + + Override + + + + + Look up a sample by index. + + The index of the sample to look up. + + The sample, if it can be found and all sub-sources support indexing; null otherwise. + + + + + Gets the index of the caller of a given call stack. + + The call stack to look up. + The caller, if it exists, otherwise. + + + + Get the frame index of a given call stack. + + The call stack to look up. + The frame index of the call stack, if it exists, otherwise. + + + + Gets the name of a frame. + + The frame to look up. + Whether to include full module paths. + The name of the frame. + + + + The total number of call stacks in this source. + + + + + The total number of frames in this source. + + + + + The total number of samples in this source. + + + + + The names for the scenarios. + + + + + override + + + + + override + + + + + Convert a StackSourceSample produced by a sub-source into one suitable for the aggregate source. + + The StackSourceSample to convert. + A place to but the returned sampled (will become the return value). + The index of the source from which the sample came. + The converted sample. + + If ConvertSample is called again, all previous samples produced by ConvertSample may no longer be used. + + + + + Friendly names of sources. + + + Name 0 is the name of the pseudo-source, which should not be used. + + + + + The list of sources. + + + Source 0 is the pseudo-source (identical to m_pseudo). + + + + + THis is the time of the first sample. It lets us normalize the time in the sample to be relative to this. + + + + + A StackSource to generate the pseudo-frames needed to group scenarios. + + + + + Initialize a new PseudoStackSource. + + The names of the frames. + + + + Gets the CallStackIndex of the call stack corresponding to a given source. + + The index of the source to look up. + The StackSourceCallStackIndex of a stack under which to group all call stacks for that source. + + + + Gets the index of the caller of a given call stack. + + The call stack to look up. + The caller, if it exists, otherwise. + + + + Get the frame index of a given call stack. + + The call stack to look up. + The frame index of the call stack, if it exists, otherwise. + + + + Gets the name of a frame. + + The frame to look up. + Whether to include full module paths. + The name of the frame. + + + + The total number of call stacks in this source. + + + + + The total number of frames in this source. + + + + + The names of the frames that this source generates. + + + + + Extension methods for type-safe IndexMap operations on StackSource*Index enums. + + + + + This is just a class that holds data. It does nothing except support an 'update' events + + + + + Constructs a Filter parameter class with all empty properties. + + + + + Create a Filter Parameters Structure form another one + + + + + + Set a Filter Parameters Structure form another one + + + + + Fetch Name + + + + + Fetch StartTimeRelativeMSec + + + + + Fetch EndTimeRelativeMSec + + + + + Fetch MinInclusiveTimePercent + + + + + Fetch FoldRegExs + + + + + Fetch IncludeRegExs + + + + + Fetch ExcludeRegExs + + + + + Fetch GroupRegExs + + + + + Fetch TypePriority + + + + + Fetch ScenarioList + + + + + Fetch Scenarios + + + + + override + + + + + override + + + + + TODO Document + + + + + Write out the FilterParameters to XML 'writer' + + + + + Create an XML representation of FilterParams as a string + + + + + + A FilterStackSouce morphs one stack filters or groups the stacks of one stack source to form a new + stack source. It is very powerful mechanism. + + + + + Create a new FilterStackSource. + + Specifies how to filter or group the stacks + The input source to morph + How to scale the data (as time or simply by size of data) + + + + Override + + + + + Override + + + + + override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Associated with every frame is a FrameInfo which is the computed answers associated with that frame name. + We cache these and so most of the time looking up frame information is just an array lookup. + + FrameInfo contains information that is ONLY dependent on the frame name (not the stack it came from), so + entry point groups and include patterns can not be completely processed at this point. Never returns null. + + + + + Generate the stack information for 'stack' and place it in stackInfoRet. Only called by GetStackInfo. + + + + + Returns the frame information for frameIndex. Never returns null. + + + + + This is just the parsed form of a grouping specification Pat->GroupNameTemplate (it has a pattern regular + expression and a group name that can have replacements) It is a trivial class + + + + + Experimentally we are going to special case the module entry pattern. + + + + + Parses a string into the GroupPattern structure that allows it to executed (matched). + + + + + Given the name of a frame, look it up in the group patterns and morph it to its group name. + If the group that matches is a entryGroup then set 'isEntryGroup'. Will return null if + no group matches 'frameName' + + + + + Holds parsed information about patterns for groups includes, excludes or folds. + + + + + Returns the index in the 'pats' array of the first pattern that matches 'str'. Returns -1 if no match. + + + + + returns true if set1 and set1 (as returned from MatchSet) are identical + + + + + Convert a string from my regular expression format (where you only have * and { } as grouping operators + and convert them to .NET regular expressions string + + + + + FrameInfo is all the information we need to associate with an Frame ID (to figure out what group/pattern it belongs to) + This includes what group it belongs to, the include patterns it matches whether to discard or fold it. It is + all the processing we can do with JUST the frame ID. + + Note that FrameInfo is reused by multiple stacks, which means that you should NOT update fields in it after initial creation. + + + + + This is what we return to the Stack crawler, it encodes either that we should filter the sample, + fold the frame, form a group, or the frameID that we have chosen to represent the group as a whole. + + + + + Represents all accumulated information about grouping for a particular stack. Effectively this is the + 'result' of applying the grouping and filtering to a particular stack. We cache the last 100 or so + of these because stacks tend to reuse the parts of the stack close the root. + + + + + The include patterns that have been matched by some frame in this stack. (ultimately we need all bits set). + Can be null, which means the empty set. + + + + + Represents a frame that does not match any pattern. Thus the default of simply returning the frame ID is appropriate + + + + + Represents a frame that should be discarded. + + + + + Represents a frame that should be folded into its caller. + + + + + We cache information about stacks we have previously seen so we can short-circuit work. + TODO make dynamic. + + Note when this value is 4096 some memory profiles are VERY sluggish. Don't make it too + small unless it is adaptive. + + + + + A class that maps contiguous indices from various sources from and to a single range of contiguous indices. + + + This is useful for aggregating indices used, for instance, in the interface for StackSource (StackSourceCallStackIndex / + StackSourceFrameIndex) in AggregateStackSource. This is an easy way, given the incoming StackSource*Index, to find the + aggregated source to query, and the corresponding StackSource*Index to send to the source. + + + With counts [3, 7, 5]: + 1 1 1 1 1 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 = Incoming index + __0__ ______1______ ____2____ = Source number + 0 1 2|0 1 2 3 4 5 6|0 1 2 3 4 = Offset + + + + + Initialize a new IndexMap with the specified counts. + + A list mapping an index to its corresponding count. + + + + Find the source for an index. + + The aggregate index to look up. + The source that belongs to. + + + + Find the offset into a given source of a given aggregate index. + + The aggregate index to look up. + The source to find the offset into. + The offset of into . + + + + Finds the index for a given source/offset pair. + + The source number of the item. + The offset into the corresponding source for the item. + The index corresponding to the pair of and . + + + + The total number of indices in the map. + + + + + The lookup table to convert indices to source/offset pairs. + + + This contains the cumulative count of indices that occurred before each source. + The last element is the total number of indices (equal to m_range). + + + + + The total number of indices in the map. + + + + + We remember the last source we looked up and check there first very likely they are next to one another. + + + + + A finite cache based with a least recently used algorithm for replacement. + It is meant to be fast (fast as a hashtable), and space efficient (not much + over the MaxEntry key-value pairs are stored. (only 8 bytes per entry additional). + + After reaching MaxEntry entries. It uses a roughly least-recently used + algorithm to pick a entry to recycle. To stay efficient it only searches + a finite time (up to 5 entries) for a entry that is older than 1/2 of the + entries in the table. + + It has the property that if you are in the maxEntries/2 most commonly fetched + things, you very unlikely to be evicted once you are in the cache. + + + + + maxEntries currently is only set in the constructor. Thus this is a finite sized cache + but is otherwise very efficient. Currently it uses ushorts internally so the number + of entries is limited to 64K (it silently limits it if you give maxEntries > 64K). + + + + + + Fetches the value from the cache with key 'key'. Returns default(T) if not present + + + + + Fetches the value from the cache with key 'key'. Returns false if not present. + + + + + Adds 'key' with value 'value' to the cache. + + + + + Removes all entries in the cache. + + + + + Sets the maxiumum number of key-value pairs the cache will keep. (after that old ones are remvoed). + + + + + Represents a null pointer (end of a linked list) + + + + + CommandOptions is a helper class for the Command class. It stores options + that affect the behavior of the execution of ETWCommands and is passes as a + parameter to the constructor of a Command. + + It is useful for these options be be on a separate class (rather than + on Command itself), because it is reasonably common to want to have a set + of options passed to several commands, which is not easily possible otherwise. + + + + + Can be assigned to the Timeout Property to indicate infinite timeout. + + + + + CommanOptions holds a set of options that can be passed to the constructor + to the Command Class as well as Command.Run* + + + + + Return a copy an existing set of command options + + The copy of the command options + + + + Normally commands will throw if the subprocess returns a non-zero + exit code. NoThrow suppresses this. + + + + + Updates the NoThrow propery and returns the updated commandOptions. + Updated command options + + + + + ShortHand for UseShellExecute and NoWait + + + + + Updates the Start propery and returns the updated commandOptions. + + + + + Normally commands are launched with CreateProcess. However it is + also possible use the Shell Start API. This causes Command to look + up the executable differently + + + + + Updates the Start propery and returns the updated commandOptions. + + + + + Indicates that you want to hide any new window created. + + + + + Updates the NoWindow propery and returns the updated commandOptions. + + + + + Indicates that you want don't want to wait for the command to complete. + + + + + Updates the NoWait propery and returns the updated commandOptions. + + + + + Indicates that the command must run at elevated Windows privledges (causes a new command window) + + + + + Updates the Elevate propery and returns the updated commandOptions. + + + + + By default commands have a 10 minute timeout (600,000 msec), If this + is inappropriate, the Timeout property can change this. Like all + timouts in .NET, it is in units of milliseconds, and you can use + CommandOptions.Infinite to indicate no timeout. + + + + + Updates the Timeout propery and returns the updated commandOptions. + CommandOptions.Infinite can be used for infinite + + + + + Indicates the string will be sent to Console.In for the subprocess. + + + + + Updates the Input propery and returns the updated commandOptions. + + + + + Indicates the current directory the subProcess will have. + + + + + Updates the CurrentDirectory propery and returns the updated commandOptions. + + + + + Indicates the standard output and error of the command should be redirected + to a archiveFile rather than being stored in Memory in the 'Output' property of the + command. + + + + + Updates the OutputFile propery and returns the updated commandOptions. + + + + + Indicates the standard output and error of the command should be redirected + to a a TextWriter rather than being stored in Memory in the 'Output' property + of the command. + + + + + Updates the OutputStream property and returns the updated commandOptions. + + + + + Gets the Environment variables that will be set in the subprocess that + differ from current process's environment variables. Any time a string + of the form %VAR% is found in a value of a environment variable it is + replaced with the value of the environment variable at the time the + command is launched. This is useful for example to update the PATH + environment variable eg. "%PATH%;someNewPath" + + + + + Adds the environment variable with the give value to the set of + environmetn variables to be passed to the sub-process and returns the + updated commandOptions. Any time a string + of the form %VAR% is found in a value of a environment variable it is + replaced with the value of the environment variable at the time the + command is launched. This is useful for example to update the PATH + environment variable eg. "%PATH%;someNewPath" + + + + + Command represents a running of a command lineNumber process. It is basically + a wrapper over System.Diagnostics.Process, which hides the complexitity + of System.Diagnostics.Process, and knows how to capture output and otherwise + makes calling commands very easy. + + + + + The time the process started. + + + + + Returns true if the process has exited. + + + + + The time the processed Exited. (HasExited should be true before calling) + + + + + The duration of the command (HasExited should be true before calling) + + + + + The operating system ID for the subprocess. + + + + + The process exit code for the subprocess. (HasExited should be true before calling) + Often this does not need to be checked because Command.Run will throw an exception + if it is not zero. However it is useful if the CommandOptions.NoThrow property + was set. + + + + + The standard output and standard error output from the command. This + is accumulated in real time so it can vary if the process is still running. + + This property is NOT available if the CommandOptions.OutputFile or CommandOptions.OutputStream + is specified since the output is being redirected there. If a large amount of output is + expected (> 1Meg), the Run.AddOutputStream(Stream) is recommended for retrieving it since + the large string is never materialized at one time. + + + + + Returns that CommandOptions structure that holds all the options that affect + the running of the command (like Timeout, Input ...) + + + + + Run 'commandLine', sending the output to the console, and wait for the command to complete. + This simulates what batch filedo when executing their commands. It is a bit more verbose + by default, however + + The command lineNumber to run as a subprocess + Additional qualifiers that control how the process is run + A Command structure that can be queried to determine ExitCode, Output, etc. + + + + Run 'commandLine' as a subprocess and waits for the command to complete. + Output is captured and placed in the 'Output' property of the returned Command + structure. + + The command lineNumber to run as a subprocess + Additional qualifiers that control how the process is run + A Command structure that can be queried to determine ExitCode, Output, etc. + + + + Launch a new command and returns the Command object that can be used to monitor + the restult. It does not wait for the command to complete, however you + can call 'Wait' to do that, or use the 'Run' or 'RunToConsole' methods. */ + + The command lineNumber to run as a subprocess + Additional qualifiers that control how the process is run + A Command structure that can be queried to determine ExitCode, Output, etc. + + + + Create a subprocess to run 'commandLine' with no special options. + The command lineNumber to run as a subprocess + + + + + Wait for a started process to complete (HasExited will be true on return) + + Wait returns that 'this' pointer. + + + + Throw a error if the command exited with a non-zero exit code + printing useful diagnostic information along with the thrown message. + This is useful when NoThrow is specified, and after post-processing + you determine that the command really did fail, and an normal + Command.Run failure was the appropriate action. + + An additional message to print in the throw (can be null) + + + + Get the underlying process object. Generally not used. + + + + + Kill the process (and any child processses (recursively) associated with the + running command). Note that it may not be able to kill everything it should + if the child-parent' chain is broken by a child that creates a subprocess and + then dies itself. This is reasonably uncommon, however. + + + + + Put double quotes around 'str' if necessary (handles quotes quotes. + + + + + Given a string 'commandExe' look for it on the path the way cmd.exe would. + Returns null if it was not found. + + + + + requiredOSVersion is a number that is the major version * 10 + minor. Thus + Win 10 == 100 + Win 8 == 62 + Win 7 == 61 + Vista == 60 + This returns true if true OS version is >= 'requiredOSVersion + + + + + The DiaLoader class knows how to load the msdia140.dll (the Debug Access Interface) (see docs at + http://msdn.microsoft.com/en-us/library/x93ctkx8.aspx), without it being registered as a COM object. + Basically it just called the DllGetClassObject interface directly. + + It has one public method 'GetDiaSourceObject' which knows how to create a IDiaDataSource object. + From there you can do anything you need. + + In order to get IDiaDataSource3 which includes'getStreamSize' API, you need to use the + vctools\langapi\idl\dia2_internal.idl file from devdiv to produce Dia2Lib.dll + + roughly what you need to do is + copy vctools\langapi\idl\dia2_internal.idl . + copy vctools\langapi\idl\dia2.idl . + copy vctools\langapi\include\cvconst.h . + Change dia2.idl to include interface IDiaDataSource3 inside library Dia2Lib->importlib->coclass DiaSource + midl dia2_internal.idl /D CC_DP_CXX + tlbimp dia2_internal.tlb + REM result is Dia2Lib.dll + + + + + Load the msdia100 dll and get a IDiaDataSource from it. This is your gateway to PDB reading. + + + + + Used to ensure the native library is loaded at least once prior to trying to use it. No protection is + included to avoid multiple loads, but this is not a problem since we aren't trying to unload the library + after use. + + + + + PEFile is a reader for the information in a Portable Exectable (PE) FILE. This is what EXEs and DLLs are. + + It can read both 32 and 64 bit PE files. + + + + + Create a new PEFile header reader that inspects the + + + + + The Header for the PE file. This contains the infor in a link /dump /headers + + + + + Looks up the debug signature information in the EXE. Returns true and sets the parameters if it is found. + + If 'first' is true then the first entry is returned, otherwise (by default) the last entry is used + (this is what debuggers do today). Thus NGEN images put the IL PDB last (which means debuggers + pick up that one), but we can set it to 'first' if we want the NGEN PDB. + + + + + Gets the File Version Information that is stored as a resource in the PE file. (This is what the + version tab a file's property page is populated with). + + + + + For side by side dlls, the manifest that decribes the binding information is stored as the RT_MANIFEST resource, and it + is an XML string. This routine returns this. + + + + + + Returns true if this is and NGEN or Ready-to-Run image (it has precompiled native code) + + + + + Returns true if file has a managed ready-to-run image. + + + + + Gets the major and minor ready-to-run version. returns true if ready-to-run. + + + + + Closes any file handles and cleans up resources. + + + + + A PEHeader is a reader of the data at the beginning of a PEFile. If the header bytes of a + PEFile are read or mapped into memory, this class can parse it when given a poitner to it. + It can read both 32 and 64 bit PE files. + + + + + Returns a PEHeader for void* pointer in memory. It does NO validity checking. + + + + + The total s,ize of the header, including section array of the the PE header. + + + + + Given a virtual address to data in a mapped PE file, return the relative virtual address (displacement from start of the image) + + + + + Given a relative virtual address (displacement from start of the image) return the virtual address to data in a mapped PE file + + + + + Given a relative virtual address (displacement from start of the image) return a offset in the file data for that data. + + + + + Returns true if this is PE file for a 64 bit architecture. + + + + + Returns true if this file contains managed code (might also contain native code). + + + + + Returns the 'Signature' of the PE HEader PE\0\0 = 0x4550, used for sanity checking. + + + + + The machine this PE file is intended to run on + + + + + PE files have a number of sections that represent regions of memory with the access permisions. This is the nubmer of such sections. + + + + + The the PE file was created represented as the number of seconds since Jan 1 1970 + + + + + The the PE file was created represented as a DateTime object + + + + + PointerToSymbolTable (see IMAGE_FILE_HEADER in PE File spec) + + + + + NumberOfSymbols (see IMAGE_FILE_HEADER PE File spec) + + + + + SizeOfOptionalHeader (see IMAGE_FILE_HEADER PE File spec) + + + + + Characteristics (see IMAGE_FILE_HEADER PE File spec) + + + + + Magic (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MajorLinkerVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MinorLinkerVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfCode (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfInitializedData (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfUninitializedData (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + AddressOfEntryPoint (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + BaseOfCode (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + ImageBase (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SectionAlignment (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + FileAlignment (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MajorOperatingSystemVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MinorOperatingSystemVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MajorImageVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MinorImageVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MajorSubsystemVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MinorSubsystemVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + Win32VersionValue (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfImage (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfHeaders (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + CheckSum (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + Subsystem (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + DllCharacteristics (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfStackReserve (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfStackCommit (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfHeapReserve (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfHeapCommit (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + LoaderFlags (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + NumberOfRvaAndSizes (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + Returns the data directory (virtual address an blob, of a data directory with index 'idx'. 14 are currently defined. + + + + + Returns the data directory for DLL Exports see PE file spec for more + + + + + Returns the data directory for DLL Imports see PE file spec for more + + + + + Returns the data directory for DLL Resources see PE file spec for more + + + + + Returns the data directory for DLL Exceptions see PE file spec for more + + + + + Returns the data directory for DLL securiy certificates (Authenticode) see PE file spec for more + + + + + Returns the data directory Image Base Relocations (RELOCS) see PE file spec for more + + + + + Returns the data directory for Debug information see PE file spec for more + + + + + Returns the data directory for DLL Exports see PE file spec for more + + + + + Returns the data directory for GlobalPointer (IA64) see PE file spec for more + + + + + Returns the data directory for THread local storage see PE file spec for more + + + + + Returns the data directory for Load Configuration see PE file spec for more + + + + + Returns the data directory for Bound Imports see PE file spec for more + + + + + Returns the data directory for the DLL Import Address Table (IAT) see PE file spec for more + + + + + Returns the data directory for Delayed Imports see PE file spec for more + + + + + see PE file spec for more .NET Runtime infomration. + + + + + The Machine types supported by the portable executable (PE) File format + + + + + Unknown machine type + + + + + Intel X86 CPU + + + + + Intel IA64 + + + + + ARM 32 bit + + + + + Arm 64 bit + + + + + Represents a Portable Executable (PE) Data directory. This is just a well known optional 'Blob' of memory (has a starting point and size) + + + + + The start of the data blob when the file is mapped into memory + + + + + The length of the data blob. + + + + + FileVersionInfo represents the extended version formation that is optionally placed in the PE file resource area. + + + + + The verison string + + + + + A PEBuffer represents a buffer (efficient) scanner of the + + +
+
diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/OSExtensions.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/OSExtensions.dll new file mode 100644 index 0000000..0018294 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/OSExtensions.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/TraceReloggerLib.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/TraceReloggerLib.dll new file mode 100644 index 0000000..1a8280b Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/net45/TraceReloggerLib.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Dia2Lib.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Dia2Lib.dll new file mode 100644 index 0000000..68b11b6 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Dia2Lib.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Microsoft.Diagnostics.FastSerialization.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Microsoft.Diagnostics.FastSerialization.dll new file mode 100644 index 0000000..56cf0d5 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Microsoft.Diagnostics.FastSerialization.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Microsoft.Diagnostics.FastSerialization.xml b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Microsoft.Diagnostics.FastSerialization.xml new file mode 100644 index 0000000..683b613 --- /dev/null +++ b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Microsoft.Diagnostics.FastSerialization.xml @@ -0,0 +1,1866 @@ + + + + Microsoft.Diagnostics.FastSerialization + + + + + A StreamLabel is a 32 bit integer that represents a position in a IStreamReader or + IStreamWriter. During writing it is generated by the IStreamWriter.GetLabel method an + consumed by the IStreamWriter.WriteLabel method. On reading you can use + IStreamReader.Current and and IStreamReader. + + + + + Represents a stream label that is not a valid value + + + + + IStreamWriter is meant to be a very simple streaming protocol. You can write integral types, + strings, and labels to the stream itself. + + IStreamWrite can be thought of a simplified System.IO.BinaryWriter, or maybe the writer + part of a System.IO.Stream with a few helpers for primitive types. + + See also IStreamReader + + + + + Write a byte to a stream + + + + + Write a short to a stream + + + + + Write an int to a stream + + + + + Write a long to a stream + + + + + Write a StreamLabel (a pointer to another part of the stream) to a stream + + + + + Write a string to a stream (supports null values). + + + + + Get the stream label for the current position (points at whatever is written next + + + + + + Write a SuffixLabel it must be the last thing written to the stream. The stream + guarantees that this value can be efficiently read at any time (probably by seeking + back from the end of the stream)). The idea is that when you generate a 'tableOfContents' + you can only do this after processing the data (and probably writing it out), If you + remember where you write this table of contents and then write a suffix label to it + as the last thing in the stream using this API, you guarantee that the reader can + efficiently seek to the end, read the value, and then goto that position. (See + IStreamReader.GotoSuffixLabel for more) + + + + IStreamReader is meant to be a very simple streaming protocol. You can read integral types, + strings, and labels to the stream itself. You can also goto labels you have read from the stream. + + IStreamReader can be thought of a simplified System.IO.BinaryReder, or maybe the reader + part of a System.IO.Stream with a few helpers for primitive types. + + See also IStreamWriter + + + + Read a byte from the stream + + + + + Read a short from the stream + + + + + Read an int from the stream + + + + + Read a long from the stream + + + + + Read a string from the stream. Can represent null strings + + + + + Read a span of bytes from the stream. + + + + + Read a StreamLabel (pointer to some other part of the stream) from the stream + + + + + Goto a location in the stream + + + + + Returns the current position in the stream. + + + + + Sometimes information is only known after writing the entire stream. This information can be put + on the end of the stream, but there needs to be a way of finding it relative to the end, rather + than from the beginning. A IStreamReader, however, does not actually let you go 'backwards' easily + because it does not guarantee the size what it writes out (it might compress). + + The solution is the concept of a 'suffixLabel' which is location in the stream where you can always + efficiently get to. + + It is written with a special API (WriteSuffixLabel that must be the last thing written. It is + expected that it simply write an uncompressed StreamLabel. It can then be used by using the + GotoSTreamLabel() method below. This goes to this well know position in the stream. We expect + this is implemented by seeking to the end of the stream, reading the uncompressed streamLabel, + and then seeking to that position. + + + + + Support for higher level operations on IStreamWriter and IStreamReader + + + + + Writes a Guid to stream 'writer' as sequence of 8 bytes + + + + + Reads a Guid to stream 'reader' as sequence of 8 bytes and returns it + + + + + Returns a StreamLabel that is the sum of label + offset. + + + + + Returns the difference between two stream labels (currently guarenteed to fit in an int) + + + + + Convenience method for skipping a a certain number of bytes in the stream. + + + + + Like a StreamLabel, a ForwardReference represents a pointer to a location in the stream. + However unlike a StreamLabel, the exact value in the stream does not need to be known at the + time the forward references is written. Instead the ID is written, and later that ID is + associated with the target location (using DefineForwardReference). + + + + + Returned when no appropriate ForwardReference exists. + + + + + #SerializerIntroduction see also #StreamLayout + + The Serializer class is a general purpose object graph serializer helper. While it does not have + any knowledge of the serialization format of individual object, it does impose conventions on how to + serialize support information like the header (which holds versioning information), a trailer (which + holds deferred pointer information), and how types are versioned. However these conventions are + intended to be very generic and thus this class can be used for essentially any serialization need. + + Goals: + * Allows full range of serialization, including subclassing and cyclic object graphs. + * Can be serialized and deserialized efficiently sequentially (no seeks MANDATED on read or + write). This allows the serializer to be used over pipes and other non-seekable devices). + * Pay for play (thus very efficient in simple cases (no subclassing or cyclic graphs). + * Ideally self-describing, and debuggable (output as XML if desired?) + + Versioning: + * We want the ability for new formats to accept old versions if objects wish to support old + formats + * Also wish to allow new formats to be read by OLD version if the new format is just an + 'extension' (data added to end of objects). This makes making new versions almost pain-free. + + Concepts: + * No-seek requirement + + The serialized form should be such that it can be deserialized efficiently in a serial fashion + (no seeks). This means all information needed to deserialize has to be 'just in time' (can't + be some table at the end). Pragmatically this means that type information (needed to create + instances), has to be output on first use, so it is available for the deserializer. + + * Laziness requirement + + While is should be possible to read the serialized for sequentially, we should also not force + it. It should be possible to have a large file that represents a persisted structure that can + be lazily brought into memory on demand. This means that all information needed to + deserialize must also be 'randomly available' and not depend on reading from the beginning. + Pragmatically this means that type information, and forward forwardReference information needs to + have a table in a well known Location at the end so that it can be found without having to + search the file sequentially. + + * Versioning requirement + + To allow OLD code to access NEW formats, it must be the case that the serialized form of + every instance knows how to 'skip' past any new data (even if it does not know its exact + size). To support this, objects have 'begin' and 'end' tags, which allows the deserializer to + skip the next object. + + * Polymorphism requirement + + Because the user of a filed may not know the exact instance stored there, in general objects + need to store the exact type of the instance. Thus they need to store a type identifier, this + can be folded into the 'begin' tag. + + * Arbitrary object graph (circularity) requirement (Forward references) + + The serializer needs to be able to serialize arbitrary object graphs, including those with + cycles in them. While you can do this without forward references, the system is more flexible + if it has the concept of a forward reference. Thus whenever a object reference is required, a + 'forward forwardReference' can be given instead. What gets serialized is simply an unique forward + reference index (index into an array), and at some later time that index is given its true + value. This can either happen with the target object is serialized (see + Serializer.Tags.ForwardDefintion) or at the end of the serialization in a forward + reference table (which allows forward references to be resolved without scanning then entire + file. + + * Contract between objects IFastSerializable.ToStream: + + The heart of the serialization and deserialization process the IFastSerializable + interface, which implements just two methods: ToStream (for serializing an object), and + FromStream (for deserializing and object). This interfaces is the mechanism by which objects + tell the serializer what data to store for an individual instance. However this core is not + enough. An object that implements IFastSerializable must also implement a default + constructor (constructor with no args), so that that deserializer can create the object (and + then call FromStream to populated it). + + The ToStream method is only responsible for serializing the data in the object, and by itself + is not sufficient to serialize an interconnected, polymorphic graph of objects. It needs + help from the Serializer and Deserialize to do this. Serializer takes on the + responsibility to deal with persisting type information (so that Deserialize can create + the correct type before IFastSerializable.FromStream is called). It is also the + serializer's responsibility to provide the mechanism for dealing with circular object graphs + and forward references. + + * Layout of a serialized object: A serialized object has the following basic format + + * If the object is the definition of a previous forward references, then the definition must + begin with a Serializer.Tags.ForwardDefintion tag followed by a forward forwardReference + index which is being defined. + * Serializer.Tags.BeginObject tag + * A reference to the SerializationType for the object. This reference CANNOT be a + forward forwardReference because its value is needed during the deserialization process before + forward references are resolved. + * All the data that that objects 'IFastSerializable.ToStream method wrote. This is the + heart of the deserialized data, and the object itself has a lot of control over this + format. + * Serializer.Tags.EndObject tag. This marks the end of the object. It quickly finds bugs + in ToStream FromStream mismatches, and also allows for V1 deserializers to skip past + additional fields added since V1. + + * Serializing Object references: + When an object forwardReference is serialized, any of the following may follow in the stream + + * Serializer.Tags.NullReference used to encode a null object forwardReference. + * Serializer.Tags.BeginObject or Serializer.Tags.ForwardDefintion, which indicates + that this the first time the target object has been referenced, and the target is being + serialized on the spot. + * Serializer.Tags.ObjectReference which indicates that the target object has already + been serialized and what follows is the StreamLabel of where the definition is. + * Serializer.Tags.ForwardReference followed by a new forward forwardReference index. This + indicates that the object is not yet serialized, but the serializer has chosen not to + immediately serialize the object. Ultimately this object will be defined, but has not + happened yet. + + * Serializing Types: + Types are simply objects of type SerializationType which contain enough information about + the type for the Deserializer to do its work (it full name and version number). They are + serialized just like all other types. The only thing special about it is that references to + types after the BeginObject tag must not be forward references. + + #StreamLayout: + The structure of the file as a whole is simply a list of objects. The first and last objects in + the file are part of the serialization infrastructure. + + Layout Synopsis + * Signature representing Serializer format + * EntryObject (most of the rest of the file) + * BeginObject tag + * Type for This object (which is a object of type SerializationType) + * BeginObject tag + * Type for SerializationType POSITION1 + * BeginObject tag + * Type for SerializationType + * ObjectReference tag // This is how our recursion ends. + * StreamLabel for POSITION1 + * Version Field for SerializationType + * Minimum Version Field for SerializationType + * FullName string for SerializationType + * EndObject tag + * Version field for EntryObject's type + * Minimum Version field for EntryObject's type + * FullName string for EntryObject's type + * EndObject tag + * Field1 + * Field2 + * V2_Field (this should be tagged so that it can be skipped by V1 deserializers. + * EndObject tag + * ForwardReferenceTable pseudo-object + * Count of forward references + * StreamLabel for forward ref 0 + * StreamLabel for forward ref 1. + * ... + * SerializationTrailer pseudo-object + * StreamLabel ForwardReferenceTable + * StreamLabel to SerializationTrailer + * End of stream + + + + + Create a serializer writes 'entryObject' to a file. + + + + + Create a serializer that writes to a . The serializer + will close the stream when it closes. + + + + + Create a serializer that writes to a . The + parameter determines whether the serializer will close the stream when it + closes. + + + + + Create a serializer that writes 'entryObject' another IStreamWriter + + + + + Write a bool to a stream + + + + + Write a byte to a stream + + + + + Write a short to a stream + + + + + Write an int to a stream + + + + + Write a long to a stream + + + + + Write a Guid to a stream + + + + + Write a string to a stream + + + + + Write a float to a stream + + + + + Write a double to a stream + + + + + Write a StreamLabel (pointer to some other part of the stream whose location is current known) to the stream + + + + + Write a ForwardReference (pointer to some other part of the stream that whose location is not currently known) to the stream + + + + + If the object is potentially aliased (multiple references to it), you should write it with this method. + + + + + To tune working set (or disk seeks), or to make the dump of the format more readable, it is + valuable to have control over which of several references to an object will actually cause it to + be serialized (by default the first encountered does it). + + WriteDefered allows you to write just a forwardReference to an object with the expectation that + somewhere later in the serialization process the object will be serialized. If no call to + WriteObject() occurs, then the object is serialized automatically before the stream is closed + (thus dangling references are impossible). + + + + + This is an optimized version of WriteObjectReference that can be used in some cases. + + If the object is not aliased (it has an 'owner' and only that owner has references to it (which + implies its lifetime is strictly less than its owners), then the serialization system does not + need to put the object in the 'interning' table. This saves a space (entries in the intern table + as well as 'SyncEntry' overhead of creating hash codes for object) as well as time (to create + that bookkeeping) for each object that is treated as private (which can add up if because it is + common that many objects are private). The private instances are also marked in the serialized + format so on reading there is a similar bookkeeping savings. + + The ultimate bits written by WritePrivateObject are the same as WriteObject. + + TODO Need a DEBUG mode where we detect if others besides the owner reference the object. + + + + + Create a ForwardReference. At some point before the end of the serialization, DefineForwardReference must be called on this value + + + + + + Define the ForwardReference forwardReference to point at the current write location. + + + + + + Write a byte preceded by a tag that indicates its a byte. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a byte. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a short. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a int. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a long. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a string. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a object. These should be read with the corresponding TryReadTagged operation + + + + + Writes the header for a skipping an arbitrary blob. THus it writes a Blob + tag and the size, and the caller must then write 'sizes' bytes of data in + some way. This allows you to create regions of arbitrary size that can + be skipped by old as well as new parsers. + + + + + + Writes an end tag (which is different from all others). This is useful + when you have a deferred region of tagged items. + + + + + Retrieve the underlying stream we are writing to. Generally the Write* methods are enough. + + + + + Completes the writing of the stream. + + + + + To help debug any serialization issues, you can write data to a side file called 'log.serialize.xml' + which can track exactly what serialization operations occurred. + + + + + Dispose pattern + + + + + Deserializer is a helper class that holds all the information needed to deserialize an object + graph as a whole (things like the table of objects already deserialized, and the list of types in + the object graph. + + see #SerializerIntroduction for more + + + + + Create a Deserializer that reads its data from a given file + + + + + Create a Deserializer that reads its data from a given System.IO.Stream. The stream will be closed when the Deserializer is done with it. + + + + + Create a Deserializer that reads its data from a given System.IO.Stream. The + parameter determines whether the deserializer will close the stream when it + closes. + + + + + Create a Deserializer that reads its data from a given IStreamReader. The stream will be closed when the Deserializer is done with it. + + + + + Returns the full name of the type of the entry object without actually creating it. + Will return null on failure. + + + + + GetEntryObject is the main deserialization entry point. The serialization stream always has an object that represents the stream as + a whole, called the entry object and this returns it and places it in 'ret' + + + + + GetEntryObject is the main deserialization entry point. The serialization stream always has an object that represents the stream as + a whole, called the entry object and this returns it and returns it + + + + + Read a bool from the stream + + + + + Read a byte from the stream + + + + + Read a short from the stream + + + + + Read an int from the stream + + + + + Read a long from the stream + + + + + Read a Guid from the stream + + + + + Read a float from the stream + + + + + Read a double from the stream + + + + + Read a string from the stream. Can represent null + + + + + d) from the stream + + + + + Read a IFastSerializable object from the stream and place it in ret + + + + + Read a IFastSerializable object from the stream and return it + + + + + Read a bool from the stream and return it + + + + + Read a byte from the stream and return it + + + + + Read a short from the stream and return it + + + + + Read an int from the stream and return it + + + + + Read a long from the stream and return it + + + + + Read a float from the stream and return it + + + + + Read a double from the stream and return it + + + + + Read in a string value and return it + + + + + Read in a StreamLabel (a pointer to some other part of the stream) and return it + + + + + Read in a ForwardReference (a pointer to some other part of the stream which was not known at the tie it was written) and return it + Use ResolveForwardReference to convert the ForwardReference to a StreamLabel + + + + + Given a forward reference find the StreamLabel (location in the stream) that it points at). + Normally this call preserves the current read location, but if you do don't care you can + set preserveCurrent as an optimization to make it more efficient. + + + + + Meant to be called from FromStream. It returns the version number of the + type being deserialized. It can be used so that new code can recognizes that it + is reading an old file format and adjust what it reads. + + + + + Meant to be called from FromStream. It returns the version number of the MinimumReaderVersion + of the type that was serialized. + + + + + The filename if read from a file or the stream name if read from a stream + + + + + If set this function is set, then it is called whenever a type name from the serialization + data is encountered. It is your you then need to look that up. If it is not present + it uses Type.GetType(string) which only checks the current assembly and mscorlib. + + + + + For every IFastSerializable object being deserialized, the Deserializer needs to create 'empty' objects + that 'FromStream' is invoked on. The Deserializer gets these 'empty' objects by calling a 'factory' + delegate for that type. Thus all types being deserialized must have a factory. + + RegisterFactory registers such a factory for particular 'type'. + + + + + For every IFastSerializable object being deserialized, the Deserializer needs to create 'empty' objects + that 'FromStream' is invoked on. The Deserializer gets these 'empty' objects by calling a 'factory' + delegate for that type. Thus all types being deserialized must have a factory. + + RegisterDefaultFactory registers a factory that is passed a type parameter and returns a new IFastSerialable object. + + + + + Try to read tagged value from the stream. If it is a tagged bool, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged byte, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged short, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged int, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged long, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged string, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read the header for a tagged blob of bytes. If Current points at a tagged + blob it succeeds and returns the size of the blob (the caller must read or skip + past it manually) If it is not a tagged blob it returns a size of 0 and resets + the read pointer to what it was before this method was called. + + + + + Try to read tagged value from the stream. If it is a tagged FastSerializable, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged FastSerializable, return it, otherwise leave the cursor unchanged and return null + + + + + Set the read position to the given StreamLabel + + + + + Set the read position to the given ForwardReference + + + + + Returns the current read position in the stream. + + + + + Fetch the underlying IStreamReader that the deserializer reads data from + + + + + Close the IStreamReader and free resources associated with the Deserializer + + + + + When we encounter a forward reference, we can either go to the forward reference table immediately and resolve it + (deferForwardReferences == false), or simply remember that that position needs to be fixed up and continue with + the deserialization. This later approach allows 'no seek' deserialization. This variable which scheme we do. + + + + + #DeferedRegionOverview. + + A DeferedRegion help make 'lazy' objects. You will have a DeferedRegion for each block of object you + wish to independently decide whether to deserialize lazily (typically you have one per object however + in the limit you can have one per field, it is up to you). + + When you call DeferedRegion.Write you give it a delegate that will write all the deferred fields. + The Write operation will place a forward reference in the stream that skips all the fields written, + then the fields themselves, then define the forward reference. This allows readers to skip the + deferred fields. + + When you call DeferedRegion.Read you also give it a delegate that reads all the deferred fields. + However when 'Read' instead of reading the fields it + + * remembers the deserializer, stream position, and reading delegate. + * it uses the forward reference to skip the region. + + When DeferedRegion.FinishRead is called, it first checks if the region was already restored. + If not it used the information to read in the deferred region and returns. Thus this FinishRead + should be called before any deferred field is used. + + + + + see #DeferedRegionOverview. + TODO more + + + + + See overview in DeferedRegion class comment. + This call indicates that the 'fromStream' delegate can deserialize a region of the object, which + was serialized with the DeferedRegion.Write method. The read skips the data for the region (thus + no objects associated with the region are created in memory) but the deferred object remembers + 'fromStream' and will call it when 'FinishRead()' is called. + + + + + FinishRead indicates that you need to deserialize the lazy region you defined with the 'Read' method. + If the region has already been deserialized, nothing is done. Otherwise when you call this + method the current position in the stream is put back to where it was when Read was called and the + 'fromStream' delegate registered in 'Read' is called to perform the deserialization. + + + + + Returns true if the FinsihRead() has already been called. + + + + + Get the deserializer assoicated with this DeferredRegion + + + + + Get the stream position when Read was called + + + + + This helper is just here to insure that FinishRead gets inlined + + + + + A type can opt into being serializable by implementing IFastSerializable and a default constructor + (constructor that takes not arguments). + + Conceptually all clients of IFastSerializable also implement IFastSerializableVersion + however the serializer will assume a default implementation of IFastSerializableVersion (that + Returns version 1 and assumes all versions are allowed to deserialize it. + + + + + Given a Serializer, write yourself to the output stream. Conceptually this routine is NOT + responsible for serializing its type information but only its field values. However it is + conceptually responsible for the full transitive closure of its fields. + + * For primitive fields, the choice is easy, simply call Serializer.Write + * For object fields there is a choice + * If is is only references by the enclosing object (eg and therefore field's lifetime is + identical to referencing object), then the Serialize.WritePrivateObject can be + used. This skips placing the object in the interning table (that insures it is written + exactly once). + * Otherwise call Serialize.WriteObject + * For value type fields (or collections of structs), you serialize the component fields. + * For collections, typically you serialize an integer inclusiveCountRet followed by each object. + + + + + + Given a reader, and a 'this' instance, made by calling the default constructor, create a fully + initialized instance of the object from the reader stream. The deserializer provides the extra + state needed to do this for cyclic object graphs. + + Note that it is legal for the instance to cache the deserializer and thus be 'lazy' about when + the actual deserialization happens (thus large persisted strucuture on the disk might stay on the + disk). + + Typically the FromStream implementation is an exact mirror of the ToStream implementation, where + there is a Read() for every Write(). + + + + + Objects implement IFastSerializableVersion to indicate what the current version is for writing + and which readers can read the current version. If this interface is not implemented a default is + provided (assuming version 1 for writing and MinimumVersion = 0). + + By default Serializer.WriteObject will place marks when the object ends and always skip to the + end even if the FromStream did not read all the object data. This allows considerable versioning + flexibility. Simply by placing the new data at the end of the existing serialization, new versions + of the type can be read by OLD deserializers (new fields will have the value determined by the + default constructor (typically 0 or null). This makes is relatively easy to keep MinimumVersion = 0 + (the ideal case). + + + + + This is the version number for the serialization CODE (that is the app decoding the format) + It should be incremented whenever a change is made to IFastSerializable.ToStream and the format + is publicly disseminated. It must not vary from instance to instance. This is pretty straightforward. + It defaults to 0 + + + + + At some point typically you give up allowing new versions of the read to read old wire formats + This is the Minimum version of the serialized data that this reader can deserialize. Trying + to read wire formats strictly smaller (older) than this will fail. Setting this to the current + version indicates that you don't care about ever reading data generated with an older version + of the code. + + If you set this to something other than your current version, you are obligated to insure that + your FromStream() method can handle all formats >= than this number. + + You can achieve this if you simply use the 'WriteTagged' and 'ReadTagged' APIs in your 'ToStream' + and 'FromStream' after your V1 AND you always add new fields to the end of your class. + This is the best practice. Thus + + void IFastSerializable.ToStream(Serializer serializer) + { + serializer.Write(Ver_1_Field1); + serializer.Write(Ver_1_Field2); + // ... + serializer.WriteTagged(Ver_2_Field1); + serializer.WriteTagged(Ver_2_Field2); + // ... + serializer.WriteTagged(Ver_3_Field1); + } + + void IFastSerializable.FromStream(Deserializer deserializer) + { + deserializer.Read(out Ver_1_Field1); + deserializer.Read(out Ver_1_Field2); + // ... + deserializer.TryReadTagged(ref Ver_2_Field1); // If data no present (old format) then Ver_2_Field1 not set. + deserializer.TryReadTagged(ref Ver_2_Field2); // ditto... + // ... + deserializer.TryReadTagged(ref Ver_3_Field1); + } + + Tagging outputs a byte tag in addition to the field itself. If that is a problem you can also use the + VersionBeingRead to find out what format is being read and write code that explicitly handles it. + Note however that this only gets you Backward compatibility (new readers can read the old format, but old readers + will still not be able to read the new format), which is why this is not the preferred method. + + void IFastSerializable.FromStream(Deserializer deserializer) + { + // We assume that MinVersionCanRead == 4 + // Deserialize things that are common to all versions (4 and earlier) + + if (deserializer.VersionBeingRead >= 5) + { + deserializer.Read(AVersion5Field); + if (deserializer.VersionBeingRead >= 5) + deserializer.ReadTagged(AVersion6Field); + } + } + + + + + This is the minimum version of a READER that can read this format. If you don't support forward + compatibility (old readers reading data generated by new readers) then this should be set to + the current version. + + If you set this to something besides the current version you are obligated to insure that your + ToStream() method ONLY adds fields at the end, AND that all of those added fields use the WriteTagged() + operations (which tags the data in a way that old readers can skip even if they don't know what it is) + In addition your FromStream() method must read these with the ReadTagged() deserializer APIs. + + See the comment in front of MinimumVersionCanRead for an example of using the WriteTagged() and ReadTagged() + methods. + + + + + Thrown when the deserializer detects an error. + + + + + Thown when a error occurs in serialization. + + + + + This is the version represents the version of both the reading + code and the version for the format for this type in serialized form. + See IFastSerializableVersion for more. + + + + + The version the the smallest (oldest) reader code that can read + this file format. Readers strictly less than this are rejected. + This allows support for forward compatbility. + See IFastSerializableVersion for more. + + + + + Create a IStreamReader (reads binary data) from a given byte buffer + + + + + Create a IStreamReader (reads binary data) from a given subregion of a byte buffer + + + + + The total length of bytes that this reader can read. + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Dispose pattern + + + + + Dispose pattern + + + + + A MemoryStreamReader is an implementation of the IStreamReader interface that works over a given byte[] array. + + + + + Create a IStreamReader (reads binary data) from a given byte buffer + + + + + Create a IStreamReader (reads binary data) from a given subregion of a byte buffer + + + + + The total length of bytes that this reader can read. + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Dispose pattern + + + + + Dispose pattern + + + + + A StreamWriter is an implementation of the IStreamWriter interface that generates a byte[] array. + + + + + Create IStreamWriter that writes its data to an internal byte[] buffer. It will grow as needed. + Call 'GetReader' to get a IStreamReader for the written bytes. + + Call 'GetBytes' call to get the raw array. Only the first 'Length' bytes are valid + + + + + Returns a IStreamReader that will read the written bytes. You cannot write additional bytes to the stream after making this call. + + + + + + The number of bytes written so far. + + + + + The array that holds the serialized data. + + + + + + Clears any data that was previously written. + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Dispose pattern + + + + + Dispose pattern + + + + + Makespace makes at least sizeof(long) bytes available (or throws OutOfMemory) + + + + + A IOStreamStreamReader hooks a MemoryStreamReader up to an input System.IO.Stream. + + + + + Create a new IOStreamStreamReader from the given file. + + + + + + Create a new IOStreamStreamReader from the given System.IO.Stream. Optionally you can specify the size of the read buffer + The stream will be closed by the IOStreamStreamReader when it is closed. + + + + + close the file or underlying stream and clean up + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of MemoryStreamReader + + + + + Dispose pattern + + + + + Fill the buffer, making sure at least 'minimum' byte are available to read. Throw an exception + if there are not that many bytes. + + + + + + A PinnedStreamReader is an IOStream reader that will pin its read buffer. + This allows it it support a 'GetPointer' API efficiently. The + GetPointer API lets you access data from the stream as raw byte + blobs without having to copy the data. + + + + + Create a new PinnedStreamReader that gets its data from a given file. You can optionally set the size of the read buffer. + + + + + Create a new PinnedStreamReader that gets its data from a given System.IO.Stream. You can optionally set the size of the read buffer. + The stream will be closed by the PinnedStreamReader when it is closed. + + + + + Clone the PinnnedStreamReader so that it reads from the same stream as this one. They will share the same + System.IO.Stream, but each will lock and seek when accessing that stream so they can both safely share it. + + + + + + Get a byte* pointer to the input buffer at 'Position' in the IReadStream that is at least 'length' bytes long. + (thus ptr to ptr+len is valid). Note that length cannot be larger than the buffer size passed to the reader + when it was constructed. + + + + + Get a byte* pointer to the input buffer at the current read position is at least 'length' bytes long. + (thus ptr to ptr+len is valid). Note that length cannot be larger than the buffer size passed to the reader + when it was constructed. + + + + + A IOStreamStreamWriter hooks a MemoryStreamWriter up to an output System.IO.Stream + + + + + Create a IOStreamStreamWriter that writes its data to a given file that it creates + + + + + + Create a IOStreamStreamWriter that writes its data to a System.IO.Stream + + + + + Flush any written data to the underlying System.IO.Stream + + + + + Insures the bytes in the stream are written to the stream and cleans up resources. + + + + + Access the underlying System.IO.Stream. You should avoid using this if at all possible. + + + + + Implementation of the MemoryStreamWriter interface + + + + + Implementation of the IStreamWriter interface + + + + + Implementation of the MemoryStreamWriter interface + + + + + Implementation of the MemoryStreamWriter interface + + + + + Implementation of the MemoryStreamWriter interface + + + + + Dispose pattern + + + + + A cheap version of List(T). The idea is to make it as cheap as if you did it 'by hand' using an array and + an int which represents the logical charCount. It is a struct to avoid an extra pointer dereference, so this + is really meant to be embedded in other structures. + + + + + Create a growable array with the given initial size it will grow as needed. There is also the + default constructor that assumes initialSize of 0 (and does not actually allocate the array. + + + + + + Fetch the element at the given index. Will throw an IndexOutOfRange exception otherwise + + + + + The number of elements in the array + + + + + Remove all elements in the array. + + + + + Add an item at the end of the array, growing as necessary. + + + + + + Add all items 'items' to the end of the array, growing as necessary. + + + + + + Insert 'item' directly at 'index', shifting all items >= index up. 'index' can be code:Count in + which case the item is appended to the end. Larger indexes are not allowed. + + + + + Remove 'count' elements starting at 'index' + + + + + Sets the 'index' element to 'value' growing the array if necessary (filling in default values if necessary). + + + + + Gets the value at 'index'. Never fails, will return 'default' if out of range. + + + + + Returns true if there are no elements in the array. + + + + + Remove the last element added and return it. Will throw if there are no elements. + + + + + + Returns the last element added Will throw if there are no elements. + + + + + Trims the size of the array so that no more than 'maxWaste' slots are wasted. Useful when + you know that the array has stopped growing. + + + + + Returns true if the Growable array was initialized by the default constructor + which has no capacity (and thus will cause growth on the first addition). + This method allows you to lazily set the compacity of your GrowableArray by + testing if it is of EmtpyCapacity, and if so set it to some useful capacity. + This avoids unecessary reallocs to get to a reasonable capacity. + + + + + A string representing the array. Only intended for debugging. + + + + + + Sets 'index' to the the smallest index such that all elements with index > 'idx' are > key. If + index does not match any elements a new element should always be placed AFTER index. Note that this + means that index may be -1 if the new element belongs in the first position. + + Returns true if the return index matched exactly (success) + + TODO FIX NOW harmonize with List.BinarySearch + + + + + Sort the range starting at 'index' of length 'count' using 'comparision' in assending order + + + + + Sort the whole array using 'comparison' in ascending order + + + + + Executes 'func' for each element in the GrowableArray and returns a GrowableArray + for the result. + + + + + Perform a linear search starting at 'startIndex'. If found return true and the index in 'index'. + It is legal that 'startIndex' is greater than the charCount, in which case, the search returns false + immediately. This allows a nice loop to find all items matching a pattern. + + + + + Returns the underlying array. Should not be used most of the time! + + + + + Implementation of foreach protocol + + + + + + Enumerator for foreach interface + + + + + implementation of IEnumerable interface + + + + + implementation of IEnumerable interface + + + + + Segmented list implementation, copied from Microsoft.Exchange.Collections. + + The type of the list element. + + This class implement a list which is allocated in segments, to avoid large lists to go into LOH. + + + + + Constructs SegmentedList. + + Segment size + + + + Constructs SegmentedList. + + Segment size + Initial capacity + + + + Returns the count of elements in the list. + + + + + Copy to Array + + Array copy + + + + Returns the last element on the list and removes it from it. + + The last element that was on the list. + + + + Returns true if this ICollection is read-only. + + + + + Gets or sets the given element in the list. + + Element index. + + + + Necessary if the list is being used as an array since it creates the segments lazily. + + + true if the segment is allocated and false otherwise + + + + Get slot of an element + + + + + + + + Adds new element at the end of the list. + + New element. + + + + Inserts new element at the given position in the list. + + Insert position. + New element to insert. + + + + Removes element at the given position in the list. + + Position of the element to remove. + + + + Performs a binary search in a sorted list. + + Element to search for. + Comparer to use. + Non-negative position of the element if found, negative binary complement of the position of the next element if not found. + The implementation was copied from CLR BinarySearch implementation. + + + + Performs a binary search in a sorted list. + + Element to search for. + The lowest index in which to search. + The highest index in which to search. + Comparer to use. + The index + + + + Sorts the list using default comparer for elements. + + + + + Sorts the list using specified comparer for elements. + + Comparer to use. + + + + Appends a range of elements from anothe list. + + Source list. + Start index in the source list. + Count of elements from the source list to append. + + + + Returns the enumerator. + + + + + Copy to Array + + Array copy + + + + CopyTo copies a collection into an Array, starting at a particular + index into the array. + + Destination array. + Destination array starting index. + + + + Copies the contents of the collection that are within a range into an Array, starting at a particular + index into the array. + + Destination array. + Destination array starting index. + The collection index from where the copying should start. + The collection index where the copying should end. + + + + Returns the enumerator. + + + + + Returns the enumerator. + + + + + Clears the list (removes all elements). + + + + + Check if ICollection contains the given element. + + Element to check. + + + + CopyTo copies a collection into an Array, starting at a particular + index into the array. + + Destination array. + Destination array starting index. + + + + Removes the given element from this ICollection. + + Element to remove. + + + + Shifts the tail of the list to make room for a new inserted element. + + Index of a new inserted element. + + + + Shifts the tail of the list to remove the element. + + Index of the removed element. + + + + Ensures that we have enough capacity for the given number of elements. + + Number of elements. + + + + Helper method for QuickSort. + + Comparer to use. + Position of the first element. + Position of the second element. + + + + QuickSort implementation. + + left boundary. + right boundary. + Comparer to use. + The implementation was copied from CLR QuickSort implementation. + + + + Enumerator over the segmented list. + + + + + Constructws the Enumerator. + + List to enumerate. + + + + Disposes the Enumerator. + + + + + Moves to the nest element in the list. + + True if move successful, false if there are no more elements. + + + + Returns the current element. + + + + + Returns the current element. + + + + + Resets the enumerator to initial state. + + + + diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Microsoft.Diagnostics.Tracing.TraceEvent.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Microsoft.Diagnostics.Tracing.TraceEvent.dll new file mode 100644 index 0000000..c79d04e Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Microsoft.Diagnostics.Tracing.TraceEvent.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Microsoft.Diagnostics.Tracing.TraceEvent.xml b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Microsoft.Diagnostics.Tracing.TraceEvent.xml new file mode 100644 index 0000000..f1522a3 --- /dev/null +++ b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/Microsoft.Diagnostics.Tracing.TraceEvent.xml @@ -0,0 +1,13649 @@ + + + + Microsoft.Diagnostics.Tracing.TraceEvent + + + + + BPerf Trace Log (BTL) are files generated by the CPU Samples Collector tool in https://github.com/Microsoft/BPerf + The layout of the file is as follows --> + + Format: + 4 byte integer describing compressed size + 4 byte integer describing uncompressed size + byte[compressed size] + + The byte array is a list of EVENT_RECORDs. Each Event_RECORD is aligned to 16-bytes. + + The EVENT_RECORD is laid out as a memory dump of the structure in memory. All pointers from + the structure are laid out successively in front of the EVENT_RECORD. + + The compression mechanism is using the NTDLL.RtlDecompressBufferEx Express Huffman procedure. + + + + + This constructor is used when the consumer has an offset within the BTL file that it would like to seek to. + + + + + This constructor is used when the consumer is supplying the buffers for reasons like buffer pooling. + + + + + An ActivityComputer is a state machine that track information about Activities. In particular, it can + compute a activity aware call stack. (GetCallStack). + + + + + Construct a new ActivityComputer that will process events from 'eventLog' and output activity - aware stacks to 'outputStackSource'. + + + + + Returns the TraceLog that is associated with the computer (at construction time) + + + + + Fires when an activity is first created (scheduled). The activity exists, and has an ID, but has not run yet. + + + + + First when an activity starts to run (using a thread). It fires after the start has logically happened. + so you are logically in the started activity. + + + + + Fires when the activity ends (no longer using a thread). It fires just BEFORE the task actually dies + (that is you ask the activity of the event being passed to 'Stop' it will still give the passed + activity as the answer). The first TraceActivity is the activity that was stopped, the second + is the activity that exists afer the stop completes. + + + + + Like OnStop but gets called AFTER the stop has completed (thus the current thread's activity has been updated) + The activity may be null, which indicates a failure to look up the activity being stopped (and thus the + thread's activity will be set to null). + + + + + AwaitUnblocks is a specialized form of the 'Start' event that fires when a task starts because + an AWAIT has ended. The start event also fires on awaits end and comes AFTER the AwaitUnblocks + event has been delivered. + + Not every AWAIT end causes a callback. Because an AWAIT begin happens for every FRAME you only + want a callback for the FIRST task (activity) created by parent of this activity. This is what + this callback does. + + AwaitUnblocks are often treated differently because you want to consider the time between the begin + (Activity Created) and awaitUnbock to be accounted for as on the critical path, whereas for 'normal' + tasks you normally don't think that time is interesting. + + + + + Fetches the current activity for 'thread' at the present time (the current event being dispatched). + Never returns null because there is always and activity (it may be the thread task). + This is arguably the main thing that this computer keeps track of. + + + + + Gets the default activity for a thread (the activity a thread is doing when the thread starts). + + + + + Maps an activity index back to its activity. + + + + + Returns a activity-aware call stackIndex associated with'ouputStackSource' for the call stack associated with 'data'. + Such activity-aware call stacks have pseudo-frame every time on thread causes another task to run code (because the + creator 'caused' the target code). + + If 'topFrames' is non-null, then this function is called with a Thread and is expected to return a CallStack index that + represents the thread-and-process nodes of the stack. This allows the returned stack to be have pseudo-frames + at the root of the stack. Typically this is used to represent the 'request' or other 'global' context. If it is not + present the thread and process are used to form these nodes. + + This needs to be a function mapping threads to the stack base rather than just the stack base because in the presence + of activities the thread at the 'base' whose 'top' you want may not be the one that 'data' started with, so the caller + needs to be prepared to answer the question about any thread. + + + + + Returns a StackSource call stack associated with outputStackSource for the activity 'activity' (that is the call stack at the + the time this activity was first created. This stack will have it 'top' defined by topFrames (by default just the thread and process frames) + + + + + This is not a call stack but rather the chain of ACTIVITIES (tasks), and can be formed even when call stacks + + Returns a Stack Source stack associated with outputStackSource where each frame is a task starting with 'activity' and + going back until the activity has no parent (e.g. the Thread's default activity). + + + + + If set, we don't assume that the top top frames are an attribute of the TOP THREAD (if they vary based on + the current activity, then you can't cache. Setting this disables caching. + + + + + Returns true if the call stack is in the thread pool parked (not running user code) + This means that the thread CAN'T be running an active activity and we can kill it. + + + + + This cache remembers Activity * CallStackIndex pairs and the result. + + + + + Remembers the current Activity for 'Get' and 'Put' operations. Needs to be set before Get or Put is called. + + + + + Gets the cache entry for the CurrnetActivityIndex with the call stack 'fromStackIndex' returns Invalid if + there is no entry. + + This is not passed the CurrentActivityIndex, so it can implement the CallStackMap interface + + + + + updates the cache entry for the CurrnetActivityIndex with the call stack 'fromStackIndex' with the value + 'toStackIndex' + + This is not passed the CurrentActivityIndex, so it can implement the CallStackMap interface + + + + + Creation handles ANY creation of a task. + + + + + Activity can be null, which means we could not figure out the activity we are stopping. + + + + + Get a trace wide ID for a TPL event. TPL tasks might be 'Scheduled' in the sense + that it might run independently on another thread. Tasks that do 'BeginWait and 'EndWait' + are not scheduled. The same ID might have both operating simultaneously (if you wait + on a scheduled task). Thus you need an independent ID for both. + + + + + if 'activity' has not creator (it is top-level), then return baseStack (near execution) followed by 'top' representing the thread-process frames. + + otherwise, find the fragment of 'baseStack' up to the point to enters the threadpool (the user code) and splice it to the stack of the creator + of the activity and return that. (thus returning your full user-stack). + + + + + Trims off frames that call ETW logic and return. If the pattern is not matched, we return callStackIndex + + + + + If the stack from 'startStack' (closest to execution) through 'stopStack' is the same as 'baseStack' return a non-invalid frame + indicating that it is recursive and should be dropped. The frame index returned is the name of the task on 'baseStack' that + begins the recursion (so you can update it if necessary) + + + + + Create a stack which is executing at 'startStack' and finds the region until 'stopStack', appending that (in order) to 'baseStack'. + + + + + Returns the point in 'callStackIndex' where the CLR thread pool transitions from + a thread pool worker to the work being done by the threadpool. + + Basically we find the closest to execution (furthest from thread-start) call to a 'Run' method + that shows we are running an independent task. + + + + + Used by TrimETWFrames and FindThreadPoolTransition to find particular frame names and place the information in 'm_methodFlags' + + + + + We look for various well known methods inside the Task library. This array maps method indexes + and returns a bitvector of 'kinds' of methods (Run, Schedule, ScheduleHelper). + + + + + A small number that you can get from the GetReferenceForGCAddress that is + invariant as the GC address moves around during GCs. Because this index + is small it can be used to store information about the GC reference in a + side growable array. + + + + + Indicates that the address is no longer alive. + + + + + This computer will keep track of GC references as they change over time + + + + + Create a new GCRefernece computer from the stream of events 'source'. When 'source' is processed + you can call 'GetReferenceForGCAddress' to get stable ids for GC references. + + + + + + Get a stable ID for a GcAddress. This ID can be compared for object identity. + This only works at the current point in time when scanning the source. + + + + + If you no longer need to track the GC reference, call this function to remove the tracking. + + + + + A EventPipeThreadTimeComputer does a simple simulation of what each thread is doing to create stack events that represent + CPU, blocked time + + + + + Create a new ThreadTimeComputer + + + + + If set we compute thread time using Tasks + + + + + Track additional info on like EventName or so. + Default to true to keep backward compatibility. + + + + + Use start-stop activities as the grouping construct. + + + + + Generate the thread time stacks, outputting to 'stackSource'. + + + Optional filtered trace events. + + + + Updates it so that 'thread' is now working on newStartStop, which can be null which means that it is not working on any + start-stop task. + + + + + This can actually be called with any event that has a stack. Basically it will log a CPU sample whose + size is the time between the last such call and the current one. + + + + + Get the call stack for 'data' Note that you thread must be data.Thread(). We pass it just to save the lookup. + + + + + Returns a function that figures out the top (closest to stack root) frames for an event. Often + this returns null which means 'use the normal thread-process frames'. + Normally this stack is for the current time, but if 'getAtCreationTime' is true, it will compute the + stack at the time that the current activity was CREATED rather than the current time. This works + better for await time. + + + + + Represents all the information that we need to track for each thread. + + + + + Used to create UNKNOWN frames for start-stop activities. This is indexed by StartStopActivityIndex. + and for each start-stop activity indicates when unknown time starts. However if that activity still + has known activities associated with it then the number will be negative, and its value is the + ref-count of known activities (thus when it falls to 0, it we set it to the start of unknown time. + This is indexed by the TOP-MOST start-stop activity. + + + + + maps thread ID to the current TOP-MOST start-stop activity running on that thread. Used to updated m_unknownTimeStartMsec + to figure out when to put in UNKNOWN_ASYNC nodes. + + + + + Sadly, with AWAIT nodes might come into existance AFTER we would have normally identified + a region as having no thread/await working on it. Thus you have to be able to 'undo' ASYNC_UNKONWN + nodes. We solve this by remembering all of our ASYNC_UNKNOWN nodes on a list (basically provisional) + and only add them when the start-stop activity dies (when we know there can't be another AWAIT. + Note that we only care about TOP-MOST activities. + + + + + Calculates stacks grouping them by the server request (e.g. ASP.NET) request they are for) + + + + + Create a new ServerRequest Computer. + + + + + The server request that we currently processing + + + + + A ServerRequest contains all the information we know about a server request (e.g. ASP.NET request) + + + + + Any URL associated with the request + + + + + If the request has a GUID associated with it to uniquely identify it, this is it + + + + + The time that the request started (or the earliest that we know about it) + + + + + Calculates start-stop activities (computes duration), It uses the 'standard' mechanism of using + ActivityIDs to corelate the start and stop (and any other events between the start and stop, + and use the RelatedActivityID on START events to indicate the creator of the activity, so you can + form nested start-stop activities. + + + + + Create a new ServerRequest Computer. + + + + + The current start-stop activity on the given thread. + If present 'context' is used to look up the current activityID and try to use that to repair missing Starts. + Basically if we can't figure out what StartStop activity the thread from just the threadID we can use the activityID + from the 'context' event to find it as a backup. + + + + + Gets the current Start-Stop activity for a given TraceActivity. + + + + + + + Returns a stack index representing the nesting of Start-Stop activities for the thread 'curThread' at the current time + (At this point of the current event for the computer). The stack starts with a frame for the process of the thread, then + has all the start-stop activity frames, then a frame representing 'topThread' which may not be the same as 'thread' since + 'topThread' is the thread that spawned the first task, not the currently executing thread. + + Normally this stack is for the current time, but if 'getAtCreationTime' is true, it will compute the + stack at the time that the current activity was CREATED rather than the current time. This works + better for await time + + + + + Gets a stack that represents the nesting of the Start-Stop tasks. curActivity can be null, in which case just he process node is returned. + + + + + If set, called AFTER a Start-Stop activity starts, called with the activity and the event that caused the start. + + + + + If set, called BEFORE a Start-Stop activity stops, called with the activity and the event that caused the start. + + + + + Returns true if 'guid' follow the EventSouce style activity ID for the process with ID processID. + You can pass a process ID of 0 to this routine and it will do the best it can, but the possibility + of error is significantly higher (but still under .1%) + + + + + Assuming guid is an Activity Path, extract the process ID from it. + + + + + returns a string representation for the activity path. If the GUID is not an activity path then it returns + the normal string representation for a GUID. + + + + + We don't do a stop all processing associated with the stop event is done. Thus if we are not 'on' + the stop event, then you can do any deferred processing. + + + + + Try to process some predefined DiagnosticSource ("Microsoft.EntityFrameworkCore.BeforeExecuteCommand" and "Microsoft.AspNetCore.Hosting.BeginRequest") start events. + This will try to filter the events by "EventName", if failed it will return false without any further processing. + + Whether or not succeeded in processing the event + + + + fix ASP.NET receiving events + + + + + Look up a start-stop activity by its ID. Note that the 'activityID' needs to be unique for that instance + within a process. (across ALL start-stop activities, which means it may need components that encode its + provider and task). We pass the process ID as well so that it will be unique in the whole trace. + + + + + The encoding for a list of numbers used to make Activity Guids. Basically + we operate on nibbles (which are nice because they show up as hex digits). The + list is ended with a end nibble (0) and depending on the nibble value (Below) + the value is either encoded into nibble itself or it can spill over into the + bytes that follow. + + + + + An dense number that defines the identity of a StartStopActivity. Used to create side arrays + for StartStopActivity info. + + + + + An illegal index, sutable for a sentinal. + + + + + A StartStop reresents an activity between a start and stop event as generated by EvetSource. + + + + + The index (small dense numbers suitabilty for array indexing) for this activity. + + + + + The name of the activity (The Task name for the start-stop event as well as the activity ID) + + + + + Known Activity Type + + + + + If the activity has additional information associated with it (e.g. a URL), put it here. Can be null. + + + + + The Task name (the name prefix that is common to both the start and stop event) + + + + + The processID associated with this activity + + + + + The Activity ID (as a GUID) that matches the start and stop together. + + + + + The path of creators that created this activity. + + + + + The start-stop activity that created this activity (thus it makes a tree) + + + + + The TraceLog event Index, of the start event (you can get addition info) + + + + + The TraceLog event Index, of the stop event (you can get addition info) + + + + + The time in MSec from the start of the trace when the start event happened. + + + + + The duration of activity in MSec (diff between stop and start) + + + + + This activity has completed (the Stop event has been received). Thus Duration is valid. + + + + + Returns a stack on the outputStackSource which has a frame for each activity that + caused this activity, as well as the root of the given 'rootStack' (often a stack representing the process). + + + + + override. Gives the name and start time. + + + + + We don't update the state for the stop at the time of the stop, but at the next call to any of the StartStopActivityComputer APIs. + + + + + A TcpIpComputer keeps track of TCP/IP connections so that you can correlate individual reads and + writes with the connection info (like the IP address of each end), as well as data packets being + sent (if you have packet capture turned on). + + + + + Create a new GCRefernece computer from the stream of events 'source'. When 'source' is processed + you can call 'GetReferenceForGCAddress' to get stable ids for GC references. + + + + + + A ThreadTimeComputer does a simple simulation of what each thread is doing to create stack events that represent + CPU, blocked time, disk and Network activity. + + + + + Create a new ThreadTimeComputer + + + + + If set we compute thread time using Tasks + + + + + Track additional info on like EventName or so. + Default to true to keep backward compatibility. + + + + + If set we compute blocked time + + + + + If set we don't show ready thread information + + + + + If set we group by ASP.NET Request + + + + + If we spend less then this amount of time waiting for the CPU, don't bother showing it. + + + + + LIke the GroupByAspNetRequest but use start-stop activities instead of ASP.NET Requests as the grouping construct. + + + + + Don't show AwaitTime. For CPU only traces showing await time is misleading since + blocked time will not show up. + + + + + Generate the thread time stacks, outputting to 'stackSource'. + + + Optional filtered trace events. + + + + Updates it so that 'thread' is now working on newStartStop, which can be null which means that it is not working on any + start-stop task. + + + + + This can actually be called with any event that has a stack. Basically it will log a CPU sample whose + size is the time between the last such call and the current one. + + + + + Get the call stack for 'data' Note that you thread must be data.Thread(). We pass it just to save the lookup. + + + + + Returns a function that figures out the top (closest to stack root) frames for an event. Often + this returns null which means 'use the normal thread-process frames'. + Normally this stack is for the current time, but if 'getAtCreationTime' is true, it will compute the + stack at the time that the current activity was CREATED rather than the current time. This works + better for await time. + + + + + Represents all the information that we need to track for each thread. + + + + + Given and activity, return the ASP.NET Guid associated with it (or Guid.Empty if there is not one). + + + + + + Computes the ASP.NET Pseudo frames from the process frame through the thread frame (which includes all + the pseudo-frames for the ASP.NET groupings. + + + + + Indicates that the aspNet request represented by aspNetGuid is now being handled by the thread with index + newThreadIndex. Thus any old threads handling this request are 'cleared' and replaced with 'newThreadIndex' + If 'newThreadIndex == Invalid then the entry for aspNetGuid is removed. + + + + + Generate a stack that from the root looks like 'stackIndex followed by 'READIED BY TID(XXXX)' + followed by frames of 'readyThreadCallStack' (suffixed by READIED_BY) + + + + + NetworkInfo remembers useful information to tag blocked time that seems to be network related. + It is the value of the m_lastPacketForProcess table mapping threads to network information. + + + + + AspNetRequestInfo remembers everything we care about associate with an single ASP.NET request. + It is the value of the m_aspNetRequestInfo table. + + + + + Used to create UNKNOWN frames for start-stop activities. This is indexed by StartStopActivityIndex. + and for each start-stop activity indicates when unknown time starts. However if that activity still + has known activities associated with it then the number will be negative, and its value is the + ref-count of known activities (thus when it falls to 0, it we set it to the start of unknown time. + This is indexed by the TOP-MOST start-stop activity. + + + + + maps thread ID to the current TOP-MOST start-stop activity running on that thread. Used to updated m_unknownTimeStartMsec + to figure out when to put in UNKNOWN_ASYNC nodes. + + + + + Sadly, with AWAIT nodes might come into existance AFTER we would have normally identified + a region as having no thread/await working on it. Thus you have to be able to 'undo' ASYNC_UNKONWN + nodes. We solve this by remembering all of our ASYNC_UNKNOWN nodes on a list (basically provisional) + and only add them when the start-stop activity dies (when we know there can't be another AWAIT. + Note that we only care about TOP-MOST activities. + + + + + m_IRPToThread maps the I/O request to the thread that initiated it. This way we can associate + the disk read size and file with the thread that asked for it. + + + + + Maps processor number to the OS threadID of the thread that is using it. Allows you + to determine how (CPU) idle the machine is. + + + + + Using m_threadIDUsingProc, we compute how many processor are current doing nothing + + + + + Returns the TraceLog that is associated with the computer (at construction time) + + + + + Extension methods to enable TraceManagedProcess + + + + + Extension properties for TraceProcess that include necessary .NET values + + TODO This implementation is poor at idenitfying the ParentPID, 64bitness, and Start/End times + + + + + Returns the textual version of the .NET Framework + + + + + Returns the .NET startup flags + + + + + Date and time of when the runtime was built + This is useful when a more detailed version is not present + + + + + Garbage Collector (GC) specific details about this process + + + + + Fired on the start of a GC + + + + + Fired at the end of tha GC. Given the nature of the GC, it is possible that multiple GCs will be inflight at the same time. + + + + + Just-in-time compilation (JIT) specific details about this process + + + + + Fired when a managed method is starting to compile (jit) + + + + + Fired when a managed method is done compiling (jitting). Given the nature of the JIT, it is possible that multiple methods will be compiled at the same time. + + + + + An XML representation of the TraceEventProcess (for debugging) + + + + + Gathers relevant details about the processes in the event source + + + + + + Garbage Collector (GC) specific details about this process + + + + + Process view of GC statistics + + + + + Process view of GC generational statistics + + + + + Process view of all GCs + + + + + Just-in-time compilation (JIT) specific details about this process + + + + + Process view of JIT statistics + + + + + Process view of all methods jitted + + + + + + + + + + Primary GC information + + + + + Type of the GC, eg. NonConcurrent, Background or Foreground + + + + + Reason for the GC, eg. exhausted small heap, etc. + + + + + Generation of the heap collected. If you compare Generation at the start and stop GC events they may differ. + + + + + Time relative to the start of the trace. Useful for ordering + + + + + Duration of the GC, excluding the suspension time + + + + + Duration the EE suspended the process + + + + + Time the EE took to suspend all the threads + + + + + Percentage time the GC took compared to the process lifetime + + + + + The number of CPU samples gathered for the lifetime of this process + + + + + The number of CPU samples gathered during a GC + + + + + Mark time information per heap. Key is the heap number + + + + + Time since the last EE restart + + + + + Realtive time to the trace of when the GC pause began + + + + + Marks if the GC is in a completed state + + + + + Server GC histories + + + + + Amount of memory allocated since last GC. Requires GCAllocationTicks enabled. The + data is split into small and large heaps + + + + + Number of heaps. -1 is the default + + + + + Calculate the size of all pinned objects + + + + + + Percentage of the pinned objects created by the user + + + + + + Total time taken by the GC + + + + + + Friendly GC name including type, reason and generation + + + + + Heap size after GC (mb) + + + + + Amount of memory promoted with GC (mb) + + + + + Memory survival percentage by generation + + + + + + + Heap size by generation after GC (mb) + + + + + + + Heap fragmentation by generation (mb) + + + + + + + Percentage of heap fragmented by generation + + + + + + + Amount of memory at the start of the GC by generation (mb) + + + + + + + Amount of memory after the gc by generation (mb) + + + + + + + Memory promoted by generation (mb) + Note that in 4.0 TotalPromotedSize is not entirely accurate (since it doesn't + count the pins that got demoted. We could consider using the PerHeap event data + to compute the accurate promoted size. + In 4.5 this is accurate. + + + + + + + Heap budget by generation (mb) + + + + + + + Object size by generation after GC (mb) + + + + + + + Heap condemned reasons by GC + + + + + Identify the first and greatest condemned heap + + + + + + Indicates that the GC has low ephemeral space + + + + + + Indicates that the GC was not compacting + + + + + + Returns the condemned reason for this heap + + + + + + Per heap statistics + + + + + Sum of the pinned plug sizes + + + + + Sum of the user created pinned plug sizes + + + + + Per heap statstics + + + + + Large object heap wait threads + + + + + Process heap statistics + + + + + Free list efficiency statistics + + + + + Memory allocated since last GC (mb) + + + + + Ratio of heap size before and after + + + + + Ratio of allocations since last GC over time executed + + + + + Peak heap size before GCs (mb) + + + + + Per generation view of user allocated data + + + + + Heap size before gc (mb) + + + + + Per generation view of heap sizes before GC (mb) + + + + + This represents the percentage time spent paused for this GC since the last GC completed. + + + + + Get what's allocated into gen0 or gen3. For server GC this gets the total for + all heaps. + + + + + For a given heap, get what's allocated into gen0 or gen3. + We calculate this differently on 4.0, 4.5 Beta and 4.5 RC+. + The caveat with 4.0 and 4.5 Beta is that when survival rate is 0, + We don't know how to calculate the allocated - so we just use the + last GC's budget (We should indicate this in the tool) + + + + + Legacy properties that need to be refactored and removed + + + + + Condemned reasons are organized into the following groups. + Each group corresponds to one or more reasons. + Groups are organized in the way that they mean something to users. + + + + + Background GC allocation information + + + + + Span of thread work recorded by CSwitch or CPU Sample Profile events + + + + + Reason for an induced GC + + + + + CondemnedReason + + + + + Heap condemned reason + + + + + This records which reasons are used and the value. Since the biggest value + we need to record is the generation number a byte is sufficient. + + + + + Container for mark times + + + + + Per heap statistics + + + + + Process heap statistics + + + + + Per heap stastics + + + + + Approximations we do in this function for V4_5 and prior: + On 4.0 we didn't seperate free list from free obj, so we just use fragmentation (which is the sum) + as an approximation. This makes the efficiency value a bit larger than it actually is. + We don't actually update in for the older gen - this means we only know the out for the younger + gen which isn't necessarily all allocated into the older gen. So we could see cases where the + out is > 0, yet the older gen's free list doesn't change. Using the younger gen's out as an + approximation makes the efficiency value larger than it actually is. + + For V4_6 this requires no approximation. + + + + + + + Statistical garbage collector (GC) information about a managed process + + + + + Number of GC's for this process + + + + + Number of GC's which were induced, eg. GC.Collect, etc. + + + + + Total size of the pinned objects seen at collection time + + + + + Of all the memory that is current pinned, how much of it is from pinned objects + + + + + Number of GC's that contained pinned objects + + + + + Number of GC's that contained pin plugs + + + + + The longest pause duration (ms) + + + + + Avarege pause duration (ms) + + + + + Average heap size after a GC (mb) + + + + + Average peak heap size (mb) + + + + + Average exclusive cpu samples (ms) during GC's + + + + + Total GC pause time (ms) + + + + + Max suspend duration (ms), should be very small + + + + + Max peak heap size (mb) + + + + + Max allocation per second (mb/sec) + + + + + Total allocations in the process lifetime (mb) + + + + + Total exclusive cpu samples (ms) + + + + + Total memory promoted between generations (mb) + + + + + (obsolete) Total size of heaps after GC'ss (mb) + + + + + (obsolete) Total peak heap sizes (mb) + + + + + Indication if this process is interesting from a GC pov + + + + + List of finalizer objects + + + + + Percentage of time spent paused as compared to the process lifetime + + + + + + Running time of the process. Measured as time spent between first and last GC event observed + + + + + Means it detected that the ETW information is in a format it does not understand. + + + + + Indicator of if ServerGC is enabled (1). -1 indicates that not enough events have been processed to know for sure. + We don't necessarily have the GCSettings event (only fired at the beginning if we attach) + So we have to detect whether we are running server GC or not. + Till we get our first GlobalHeapHistory event which indicates whether we use server GC + or not this remains -1. + + + + + Number of heaps. -1 indicates that not enough events have been processed to know for sure. + + + + + Indicator if PerHeapHistories is present + + + + + Process statistics about JIT'd code + + + + + Number of JITT'd methods + + + + + Total cpu samples for this process + + + + + Number of methods JITT'd by foreground threads just prior to execution + + + + + Total time spent compiling methods on foreground threads + + + + + Number of methods JITT'd by the multicore JIT background threads + + + + + Total time spent compiling methods on background threads for multicore JIT + + + + + Number of methods JITT'd by the tiered compilation background threads + + + + + Total time spent compiling methods on background threads for tiered compilation + + + + + Total IL size for all JITT'd methods + + + + + Total native code size for all JITT'd methods + + + + + Indication if this is running on .NET 4.x+ + + + + + Indicates if this process has sufficient JIT activity to be interesting + + + + + Background JIT: Time Jit was aborted (ms) + + + + + Background JIT: Assembly name of last assembly loaded before JIT aborted + + + + + Background JIT: Relative start time of last assembly loaded before JIT aborted + + + + + Background JIT: Indication if the last assembly load was successful before JIT aborted + + + + + Background JIT: Thread id of the background JIT + + + + + Background JIT: Indication that background JIT events are enabled + + + + + List of successfully inlinded methods + + + + + List of failed inlined methods + + + + + Modules encountered while processing managed samples + + + + + List of modules whose symbols were not successfully loaded + + + + + Aggregate a method to be included in the statistics + + + + + + Legacgy + + + + + Uniquely represents a method within a process. + Used as a lookup key for data structures. + + + + + JIT inlining successes + + + + + JIT inlining failures + + + + + Per method information + + + + + Time taken to compile the method + + + + + IL size of method + + + + + Native code size of method + + + + + Relative start time of JIT'd method + + + + + Method name + + + + + Module name + + + + + Thread id where JIT'd + + + + + Indication of if it was JIT'd in the background + + + + + Indication of if it was JIT'd in the background and why + + + + + Amount of time the method was forcasted to JIT + + + + + Indication of if the background JIT request was blocked and why + + + + + Number of cpu samples for this method + + + + + The version id that is created by the runtime code versioning feature. This is an incrementing counter that starts at 0 for each method. + The ETW events historically name this as the ReJITID event parameter in the payload, but we have now co-opted its usage. + + + + + Legacy + + + + + TraceProcess Extension methods + + + + + Each process is given a unique index from 0 to TraceProcesses.Count-1 and unlike + the OS Process ID, is unambiguous (The OS process ID can be reused after a + process dies). ProcessIndex represents this index. By using an enum rather than an int + it allows stronger typing and reduces the potential for errors. + + It is expected that users of this library might keep arrays of size TraceProcesses.Count to store + additional data associated with a process in the trace. + + + + + + Returned when no appropriate Process exists. + + + + + A TraceProcesses instance represents the list of processes in the Event log. + + TraceProcesses are IEnumerable, and will return the processes in order of creation time. + + This is a copy of the reduced code from TraceLog!TraceProcesses (removal of elements that + depend on TraceLog - there is a lot of them) + + + + + The log associated with this collection of processes. + + + + + The count of the number of TraceProcess instances in the TraceProcesses list. + + + + + Each process that occurs in the log is given a unique index (which unlike the PID is unique), that + ranges from 0 to Count - 1. Return the TraceProcess for the given index. + + + + + An XML representation of the TraceEventProcesses (for debugging) + + + + + Enumerate all the processes that occurred in the trace log, ordered by creation time. + + + + + Given an OS process ID and a time, return the last TraceProcess that has the same process ID, + and whose offset start time is less than 'timeQPC'. If 'timeQPC' is during the thread's lifetime this + is guaranteed to be the correct process. Using timeQPC = TraceLog.sessionEndTimeQPC will return the + last process with the given PID, even if it had died. + + + + + TraceProcesses represents the entire ETL moduleFile log. At the node level it is organized by threads. + + The TraceProcesses also is where we put various caches that are independent of the process involved. + These include a cache for TraceModuleFile that represent native images that can be loaded into a + process, as well as the process lookup tables and a cache that remembers the last calls to + GetNameForAddress(). + + + + + A step towards a refactored TraceProcess that will move down the dependcy chain from + TraceLog to Source. This is only the portion of TraceProcess that is needed for ManagedProcess + to exist. Also note, that the surface area is intended to match 100% with + Microsoft.Diagnostics.Tracing.Etlx.TraceProcess. The namespace change is intention to avoid + collision of the name and to indicate that it is moving down the depdnency chain. + + This is a slightly modified copy of the code from TraceLog!TraceProcess + + + + + The OS process ID associated with the process. It is NOT unique across the whole log. Use + ProcessIndex for that. + + + + + The index into the logical array of TraceProcesses for this process. Unlike ProcessID (which + may be reused after the process dies, the process index is unique in the log. + + + + + This is a short name for the process. It is the image file name without the path or suffix. + + + + + The command line that started the process (may be empty string if unknown) + + + + + The path name of the EXE that started the process (may be empty string if unknown) + + + + + The time when the process started. Returns the time the trace started if the process existed when the trace started. + + + + + The time when the process started. Returns the time the trace started if the process existed when the trace started. + Returned as the number of MSec from the beginning of the trace. + + + + + The time when the process ended. Returns the time the trace ended if the process existed when the trace ended. + Returned as a DateTime + + + + + The time when the process ended. Returns the time the trace ended if the process existed when the trace ended. + Returned as the number of MSec from the beginning of the trace. + + + + + The process ID of the parent process + + + + + The process that started this process. Returns null if unknown. + + + + + If the process exited, the exit status of the process. Otherwise null. + + + + + The amount of CPU time spent in this process based on the kernel CPU sampling events. + + + + + Returns true if the process is a 64 bit process + + + + + The log file associated with the process. + + + + + Peak working set + + + + + Peak virtual size + + + + + A list of all the threads that occurred in this process. + + + + + Returns the list of modules that were loaded by the process. The modules may be managed or + native, and include native modules that were loaded event before the trace started. + + + + + Filters events to only those for a particular process. + + + + + Filters events to only that occurred during the time the process was alive. + + + + + + An XML representation of the TraceEventProcess (for debugging) + + + + + Dummy stubs so Microsoft.Diagnostics.Tracing.Etlx namespace is not necessary + + + + + The parsed metadata. + + + + + Information about the trace itself. + + + + + Information about a single stream in the trace. + + + + + The environment the trace was taken in. + + + + + A clock definition in the trace. + + + + + A definition of an event. + + + + + A manual parser for CtfMetadata. Eventually this should be replaced when CtfMetadata no longer + uses a custom, BNF style format. + + + + + The abstract metadata parser class. + + + + + The types that may be declared in CtfMetatdata. + + + + + This class represents the top level entry + + + + + A simple class to make parsing out properties easier. + + + + + Represents a type which has been referenced by name, but has not yet been resolved to a concrete type. + + + + + A DynamicTraceEventParser is a parser that understands how to read the embedded manifests that occur in the + dataStream (System.Diagnostics.Tracing.EventSources do this). + + See also TDHDynamicTraceEventParser which knows how to read the manifest that are registered globally with + the machine. + + + + + The event ID for the EventSource manifest emission event. + + + + + Create a new DynamicTraceEventParser (which can parse ETW providers that dump their manifests + to the ETW data stream) an attach it to the ETW data stream 'source'. + + + + + Returns a list of providers (their manifest) that this TraceParser knows about. + + + + + Given a manifest describing the provider add its information to the parser. + + + + + Utility method that stores all the manifests known to the DynamicTraceEventParser to the directory 'directoryPath' + + + + + Utility method that read all the manifests the directory 'directoryPath' into the parser. + Manifests must end in a .man or .manifest.xml suffix. It will throw an error if + the manifest is incorrect or using unsupported options. + + + + + Override. + + + + + This event, will be fired any time a new Provider is added to the table + of ETW providers known to this DynamicTraceEventParser. This includes + when the EventSource manifest events are encountered as well as any + explicit calls to AddDynamicProvider. (including ReadAllManifests). + + The Parser will filter out duplicate manifest events, however if an + old version of a provider's manifest is encountered, and later a newer + version is encountered, you can receive this event more than once for + a single provider. + + + + + override + + + + + Called on unhandled events to look for manifests. Returns true if we added a new manifest (which may have updated the lookup table) + + + + + Override + + + + + DynamicTraceEventData is an event that knows how to take runtime information to parse event fields (and payload) + + This meta-data is distilled down to a array of field names and an array of PayloadFetches which contain enough + information to find the field data in the payload blob. This meta-data is used in the + DynamicTraceEventData.PayloadNames and DynamicTraceEventData.PayloadValue methods. + + + + + Implements TraceEvent interface + + + + + Implements TraceEvent interface + + + + + Implements TraceEvent interface + + + + + Used by PayloadValue to represent a structure. It is basically a IDictionary with a ToString() that + returns the value as JSON. + + + + + Uses C style conventions to quote a string 'value' and append to the string builder 'sb'. + Thus all \ are turned into \\ and all " into \" + + + + + Implements TraceEvent interface + + + + + Implements TraceEvent interface + + + + + Returns the count of elements for the array represented by 'arrayInfo' + It also will adjust 'offset' so that it points at the beginning of the + array data (skips past the count). + + + + + Constructor for normal types, (int, string) ...) Also handles Enums (which are ints with a map) + + + + + Initialized a PayloadFetch for a given inType. REturns Size = DynamicTraceEventData.UNKNOWN_SIZE + if the type is unknown. + + + + + Returns a payload fetch for a Array. If you know the count, then you can give it. + + + + + Offset from the beginning of the struct. + + + + + LazyMap allow out to set a function that returns a map + instead of the map itself. This will be evaluated when the map + is fetched (which gives time for the map table to be populated. + + + + + This class is only used to pretty-print the manifest event itself. It is pretty special purpose + + + + + DynamicTraceEventParserState represents the state of a DynamicTraceEventParser that needs to be + serialized to a log file. It does NOT include information about what events are chosen but DOES contain + any other necessary information that came from the ETL data file. + + + + + A ProviderManifest represents the XML manifest associated with the provider. + + + + + Read a ProviderManifest from a stream + + + + + Read a ProviderManifest from a file. + + + + + Normally ProviderManifest will fail silently if there is a problem with the manifest. If + you want to see this error you can all this method to force it explicitly It will + throw if there is a problem parsing the manifest. + + + + + Writes the manifest to 'outputStream' (as UTF8 XML text) + + + + + Writes the manifest to a file 'filePath' (as a UTF8 XML) + + + + + + Set if this manifest came from the ETL data stream file. + + + + + The name of the ETW provider + + + + + The GUID that uniquey identifies the ETW provider + + + + + The version is defined as the sum of all the version numbers of event version numbers + the number of events defined. + This has the property that if you follow correct versioning protocol (all versions for a linear sequence where a new + versions is only modifies is predecessor by adding new events or INCREASING the version numbers of existing events) + then the version number defined below will always strictly increase. + + It turns out that .NET Core removed some events from the TplEtwProvider. To allow removal of truly old events + we also add 100* the largest event ID defined to the version number. That way if you add new events, even if you + removes some (less than 100) it will consider your 'better'. + + + + + This is an arbitrary id given when the Manifest is created that + identifies where the manifest came from (e.g. a file name or an event etc). + + + + + Returns true if the current manifest is better to use than 'otherManifest' A manifest is + better if it has a larger version number OR, they have the same version number and it is + physically larger (we assume what happened is people added more properties but did not + update the version field appropriately). + + + + + Retrieve manifest as one big string. Mostly for debugging + + + + + Retrieve the manifest as XML + + + + + For debugging + + + + + Call 'callback the the parsed templates for this provider. If 'callback' returns RejectProvider, bail early + Note that the DynamicTraceEventData passed to the delegate needs to be cloned if you use subscribe to it. + + + + + Returns the .NET type corresponding to the manifest type 'manifestTypeName' + Returns null if it could not be found. + + + + + Initialize the provider. This means to advance the instance variable 'reader' until it it is at the 'provider' node + in the XML. It also has the side effect of setting the name and guid. The rest waits until events are registered. + + + + + Keywords are passed to TraceEventSession.EnableProvider to enable particular sets of + + + + + Logging when garbage collections and finalization happen. + + + + + Events when GC handles are set or destroyed. + + + + + Logging when modules actually get loaded and unloaded. + + + + + Logging when Just in time (JIT) compilation occurs. + + + + + Logging when precompiled native (NGEN) images are loaded. + + + + + Indicates that on attach or module load , a rundown of all existing methods should be done + + + + + Indicates that on detach or process shutdown, a rundown of all existing methods should be done + + + + + Events associated with validating security restrictions. + + + + + Events for logging resource consumption on an app-domain level granularity + + + + + Logging of the internal workings of the Just In Time compiler. This is fairly verbose. + It details decisions about interesting optimization (like inlining and tail call) + + + + + Log information about code thunks that transition between managed and unmanaged code. + + + + + Log when lock contention occurs. (Monitor.Enters actually blocks) + + + + + Log exception processing. + + + + + Log events associated with the threadpool, and other threading events. + + + + + Dump the native to IL mapping of any method that is JIT compiled. (V4.5 runtimes and above). + + + + + If enabled will suppress the rundown of NGEN events on V4.0 runtime (has no effect on Pre-V4.0 runtimes). + + + + + Enables the 'BulkType' event + + + + + Enables the events associated with dumping the GC heap + + + + + Enables allocation sampling with the 'fast'. Sample to limit to 100 allocations per second per type. + This is good for most detailed performance investigations. Note that this DOES update the allocation + path to be slower and only works if the process start with this on. + + + + + Enables events associate with object movement or survival with each GC. + + + + + Triggers a GC. Can pass a 64 bit value that will be logged with the GC Start event so you know which GC you actually triggered. + + + + + Indicates that you want type names looked up and put into the events (not just meta-data tokens). + + + + + Enables allocation sampling with the 'slow' rate, Sample to limit to 5 allocations per second per type. + This is reasonable for monitoring. Note that this DOES update the allocation path to be slower + and only works if the process start with this on. + + + + + Turns on capturing the stack and type of object allocation made by the .NET Runtime. This is only + supported after V4.5.3 (Late 2014) This can be very verbose and you should seriously using GCSampledObjectAllocationHigh + instead (and GCSampledObjectAllocationLow for production scenarios). + + + + + This suppresses NGEN events on V4.0 (where you have NGEN PDBs), but not on V2.0 (which does not know about this + bit and also does not have NGEN PDBS). + + + + + TODO document + + + + + Also log the stack trace of events for which this is valuable. + + + + + This allows tracing work item transfer events (thread pool enqueue/dequeue/ioenqueue/iodequeue/a.o.) + + + + + .NET Debugger events + + + + + Events intended for monitoring on an ongoing basis. + + + + + Events that will dump PDBs of dynamically generated assemblies to the ETW stream. + + + + + Recommend default flags (good compromise on verbosity). + + + + + What is needed to get symbols for JIT compiled code. + + + + + This provides the flags commonly needed to take a heap .NET Heap snapshot with ETW. + + + + + Fetch the state object associated with this parser and cast it to + the ClrTraceEventParserState type. This state object contains any + informtion that you need from one event to another to decode events. + (typically ID->Name tables). + + + + + Note that this field is derived from teh TotalPromotedSize* fields. If nothing was promoted, it is possible + that this could give a number that is smaller than what GC/Start or GC/Stop would indicate. + + + + + Returns the edge at the given zero-based index (index less than Count). The returned BulkTypeValues + points the the data in GCBulkRootEdgeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the BulkTypeTraceData. It can only be used as long as + the BulkTypeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + On the desktop this is the Method Table Pointer + In project N this is the pointer to the EE Type + + + + + For Desktop this is the Module* + For project N it is image base for the module that the type lives in? + + + + + On desktop this is the Meta-data token? + On project N it is the RVA of the typeID + + + + + Note that this method returns the type name with generic parameters in .NET Runtime + syntax e.g. System.WeakReference`1[System.Diagnostics.Tracing.EtwSession] + + + + + Returns the edge at the given zero-based index (index less than Count). The returned GCBulkRootEdgeValues + points the the data in GCBulkRootEdgeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkEdgeTraceData. It can only be used as long as + the GCBulkEdgeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the range at the given zero-based index (index less than Count). The returned GCBulkRootConditionalWeakTableElementEdgeValues + points the the data in GCBulkRootConditionalWeakTableElementEdgeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkRootConditionalWeakTableElementEdgeTraceData. It can only be used as long as + the GCBulkRootConditionalWeakTableElementEdgeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the node at the given zero-based index (idx less than Count). The returned GCBulkNodeNodes + points the the data in GCBulkNodeTraceData so it cannot live beyond that lifetime. + + + + + This unsafe interface may go away. Use the 'Nodes(idx)' instead + + + + + This structure just POINTS at the data in the GCBulkNodeTraceData. It can only be used as long as + the GCBulkNodeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the 'idx' th edge. + The returned GCBulkEdgeEdges cannot live beyond the TraceEvent that it comes from. + + + + + This structure just POINTS at the data in the GCBulkNodeTraceData. It can only be used as long as + the GCBulkNodeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the range at the given zero-based index (index less than Count). The returned GCBulkSurvivingObjectRangesValues + points the the data in GCBulkSurvivingObjectRangesTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkEdgeTraceData. It can only be used as long as + the GCBulkEdgeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the range at the given zero-based index (index less than Count). The returned GCBulkSurvivingObjectRangesValues + points the the data in GCBulkSurvivingObjectRangesTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkEdgeTraceData. It can only be used as long as + the GCBulkEdgeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + We keep Heap history for every Generation in 'Gens' + + + + + Taken from gcrecords.h, used to differentiate heap expansion and compaction reasons + + + + + Version 0, PreciseVersion 0.1: Silverlight (x86) + 0:041> dt -r2 coreclr!WKS::gc_history_per_heap + +0x000 gen_data : [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B : [0 - 40), [40 - 80), [80 - 120), [120 - 160), [160 - 200) + +0x004 size_after : Uint4B/8B + +0x008 current_size : Uint4B/8B + +0x00c previous_size : Uint4B/8B + +0x010 fragmentation : Uint4B/8B + +0x014 in : Uint4B/8B + +0x018 out : Uint4B/8B + +0x01c new_allocation : Uint4B/8B + +0x020 surv : Uint4B/8B + +0x024 growth : Uint4B/8B + +0x0c8 mem_pressure : Uint4B : 200 + +0x0cc mechanisms : [2] Uint4B : 204 (expand), 208 (compact) + +0x0d4 gen_condemn_reasons : Uint4B : 212 + +0x0d8 heap_index : Uint4B : 216 + + clrInstanceId : byte : 220 + + Version 0, PreciseVersion 0.2: .NET 4.0 + 0:000> dt -r2 clr!WKS::gc_history_per_heap + +0x000 gen_data : [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B : [0 - 40), [40 - 80), [80 - 120), [120 - 160), [160 - 200) + +0x004 size_after : Uint4B/8B + +0x008 current_size : Uint4B/8B + +0x00c previous_size : Uint4B/8B + +0x010 fragmentation : Uint4B/8B + +0x014 in : Uint4B/8B + +0x018 out : Uint4B/8B + +0x01c new_allocation : Uint4B/8B + +0x020 surv : Uint4B/8B + +0x024 growth : Uint4B/8B + +0x0c8 mem_pressure : Uint4B : 200 + +0x0cc mechanisms : [3] Uint4B : 204 (expand), 208 (compact), 212 (concurrent_compact) + +0x0d8 gen_condemn_reasons : Uint4B : 216 + +0x0dc heap_index : Uint4B : 220 + + clrInstanceId : byte : 224 + + vm\gcrecord.h + Etw_GCDataPerHeapSpecial(...) + ... + EventDataDescCreate(EventData[0], gc_data_per_heap, datasize); + EventDataDescCreate(EventData[1], ClrInstanceId, sizeof(ClrInstanceId)); + + Version 1: ??? + + Version 2, PreciseVersion 2.1: .NET 4.5 (x86) + 0:000> dt -r2 WKS::gc_history_per_heap + clr!WKS::gc_history_per_heap + +0x000 gen_data : [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B : [0 - 40), [40 - 80), [80 - 120), [120 - 160), [160 - 200) + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c out : Uint4B/8B + +0x020 new_allocation : Uint4B/8B + +0x024 surv : Uint4B/8B + +0x0c8 gen_to_condemn_reasons : WKS::gen_to_condemn_tuning + +0x000 condemn_reasons_gen : Uint4B : 200 + +0x004 condemn_reasons_condition : Uint4B : 204 + +0x0d0 mem_pressure : Uint4B : 208 + +0x0d4 mechanisms : [2] Uint4B : 212 (expand), 216 (compact) + +0x0dc heap_index : Uint4B : 220 + + vm\gcrecord.h + Etw_GCDataPerHeapSpecial(...) + ... + EventDataDescCreate(EventData[0], gc_data_per_heap, datasize); + EventDataDescCreate(EventData[1], ClrInstanceId, sizeof(ClrInstanceId)); + + Version 2, PreciseVersion 2.2: .NET 4.5.2 (x86) + 0:000> dt -r2 WKS::gc_history_per_heap + clr!WKS::gc_history_per_heap + +0x000 gen_data : [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B : [0 - 40), [40 - 80), [80 - 120), [120 - 160), [160 - 200) + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c out : Uint4B/8B + +0x020 new_allocation : Uint4B/8B + +0x024 surv : Uint4B/8B + +0x0c8 gen_to_condemn_reasons : WKS::gen_to_condemn_tuning + +0x000 condemn_reasons_gen : Uint4B : 200 + +0x004 condemn_reasons_condition : Uint4B : 204 + +0x0d0 mem_pressure : Uint4B : 208 + +0x0d4 mechanisms : [2] Uint4B : 212 (expand), 216 (compact) + +0x0dc heap_index : Uint4B : 220 + +0x0e0 extra_gen0_committed : Uint8B : 224 + + vm\gcrecord.h + Etw_GCDataPerHeapSpecial(...) + ... + EventDataDescCreate(EventData[0], gc_data_per_heap, datasize); + EventDataDescCreate(EventData[1], ClrInstanceId, sizeof(ClrInstanceId)); + + Version 3: .NET 4.6 (x86) + 0:000> dt -r2 WKS::gc_history_per_heap + clr!WKS::gc_history_per_heap + +0x000 gen_data : [4] + WKS::gc_generation_data + +0x000 size_before : Uint4B/8B + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c pinned_surv : Uint4B/8B + +0x020 npinned_surv : Uint4B/8B + +0x024 new_allocation : Uint4B/8B + +0x0a0 maxgen_size_info : WKS::maxgen_size_increase + +0x000 free_list_allocated : Uint4B/8B + +0x004 free_list_rejected : Uint4B/8B + +0x008 end_seg_allocated : Uint4B/8B + +0x00c condemned_allocated : Uint4B/8B + +0x010 pinned_allocated : Uint4B/8B + +0x014 pinned_allocated_advance : Uint4B/8B + +0x018 running_free_list_efficiency : Uint4B/8B + +0x0bc gen_to_condemn_reasons : WKS::gen_to_condemn_tuning + +0x000 condemn_reasons_gen : Uint4B + +0x004 condemn_reasons_condition : Uint4B + +0x0c4 mechanisms : [2] Uint4B + +0x0cc machanism_bits : Uint4B + +0x0d0 heap_index : Uint4B + +0x0d4 extra_gen0_committed : Uint4B/8B + + pal\src\eventprovider\lttng\eventprovdotnetruntime.cpp + FireEtXplatGCPerHeapHistory_V3(...) + + tracepoint( + DotNETRuntime, + GCPerHeapHistory_V3, x86 offsets + ClrInstanceID, : 0 + (const size_t) FreeListAllocated, : 2 + (const size_t) FreeListRejected, : 6 + (const size_t) EndOfSegAllocated, : 10 + (const size_t) CondemnedAllocated, : 14 + (const size_t) PinnedAllocated, : 18 + (const size_t) PinnedAllocatedAdvance, : 22 + RunningFreeListEfficiency, : 26 + CondemnReasons0, : 30 + CondemnReasons1 : 34 + ); + tracepoint( + DotNETRuntime, + GCPerHeapHistory_V3_1, + CompactMechanisms, : 38 + ExpandMechanisms, : 42 + HeapIndex, : 46 + (const size_t) ExtraGen0Commit, : 50 + Count, : 54 (number of WKS::gc_generation_data's) + Arg15_Struct_Len_, : ?? not really sent + (const int*) Arg15_Struct_Pointer_ : [58 - 98), ... + ); + + Version 3 is now setup to allow "add to the end" scenarios + + + + + + Returns the condemned generation number + + + + + Returns the condemned condition + + + + + genNumber is a number from 0 to maxGenData-1. These are for generation 0, 1, 2, 3 = Large Object Heap + genNumber = 4 is that second pass for Gen 0. + + + + + Version 0: Silverlight (x86), .NET 4.0 + [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B + +0x004 size_after : Uint4B/8B + +0x008 current_size : Uint4B/8B + +0x00c previous_size : Uint4B/8B + +0x010 fragmentation : Uint4B/8B + +0x014 in : Uint4B/8B + +0x018 out : Uint4B/8B + +0x01c new_allocation : Uint4B/8B + +0x020 surv : Uint4B/8B + +0x024 growth : Uint4B/8B + + Version 1: ??? + + Version 2, PreciseVersion 2.1: .NET 4.5 (x86), .NET 4.5.2 (x86) + [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c out : Uint4B/8B + +0x020 new_allocation : Uint4B/8B + +0x024 surv : Uint4B/8B + + Version 3: .NET 4.6 (x86) + [4] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c pinned_surv : Uint4B/8B + +0x020 npinned_surv : Uint4B/8B + +0x024 new_allocation : Uint4B/8B + + + + + Size of the generation before the GC, includes fragmentation + + + + + Size of the generation after GC. Includes fragmentation + + + + + Size occupied by objects at the beginning of the GC, discounting fragmentation. + Only exits on 4.5 RC and beyond. + + + + + This is the fragmenation at the end of the GC. + + + + + Size occupied by objects, discounting fragmentation. + + + + + This is the free list space (ie, what's threaded onto the free list) at the beginning of the GC. + Only exits on 4.5 RC and beyond. + + + + + This is the free obj space (ie, what's free but not threaded onto the free list) at the beginning of the GC. + Only exits on 4.5 RC and beyond. + + + + + This is the free list space (ie, what's threaded onto the free list) at the end of the GC. + Only exits on 4.5 Beta and beyond. + + + + + This is the free obj space (ie, what's free but not threaded onto the free list) at the end of the GC. + Only exits on 4.5 Beta and beyond. + + + + + This is the amount that came into this generation on this GC + + + + + This is the number of bytes survived in this generation. + + + + + This is the new budget for the generation + + + + + This is the survival rate + + + + + Version 0: ??? + + Version 1: Silverlight (x86), .NET 4.0, .NET 4.5, .NET 4.5.2 + VM\gc.cpp + 0:041> dt -r3 WKS::gc_history_global + coreclr!WKS::gc_history_global + +0x000 final_youngest_desired : Uint4B/8B + +0x004 num_heaps : Uint4B + +0x008 condemned_generation : Int4B + +0x00c gen0_reduction_count : Int4B + +0x010 reason : + reason_alloc_soh = 0n0 + reason_induced = 0n1 + reason_lowmemory = 0n2 + reason_empty = 0n3 + reason_alloc_loh = 0n4 + reason_oos_soh = 0n5 + reason_oos_loh = 0n6 + reason_induced_noforce = 0n7 + reason_gcstress = 0n8 + reason_max = 0n9 + +0x014 global_mechanims_p : Uint4B + + FireEtwGCGlobalHeapHistory_V1(gc_data_global.final_youngest_desired, // upcast on 32bit to __int64 + gc_data_global.num_heaps, + gc_data_global.condemned_generation, + gc_data_global.gen0_reduction_count, + gc_data_global.reason, + gc_data_global.global_mechanims_p, + GetClrInstanceId()); + Version 2: .NET 4.6 + clr!WKS::gc_history_global + +0x000 final_youngest_desired : Uint4B/8B + +0x004 num_heaps : Uint4B + +0x008 condemned_generation : Int4B + +0x00c gen0_reduction_count : Int4B + +0x010 reason : + reason_alloc_soh = 0n0 + reason_induced = 0n1 + reason_lowmemory = 0n2 + reason_empty = 0n3 + reason_alloc_loh = 0n4 + reason_oos_soh = 0n5 + reason_oos_loh = 0n6 + reason_induced_noforce = 0n7 + reason_gcstress = 0n8 + reason_lowmemory_blocking = 0n9 + reason_induced_compacting = 0n10 + reason_lowmemory_host = 0n11 + reason_max = 0n12 + +0x014 pause_mode : Int4B + +0x018 mem_pressure : Uint4B + +0x01c global_mechanims_p : Uint4B + + FireEtwGCGlobalHeapHistory_V2(gc_data_global.final_youngest_desired, // upcast on 32bit to __int64 + gc_data_global.num_heaps, + gc_data_global.condemned_generation, + gc_data_global.gen0_reduction_count, + gc_data_global.reason, + gc_data_global.global_mechanims_p, + GetClrInstanceId()); + gc_data_global.pause_mode, + gc_data_global.mem_pressure); + + + + + + Gets the full type name including generic parameters in runtime syntax + For example System.WeakReference`1[System.Diagnostics.Tracing.EtwSession] + + + + + Returns the CCW at the given zero-based index (index less than Count). The returned GCBulkRootCCWValues + points the the data in GCBulkRootCCWTraceData so it cannot live beyond that lifetime. + + + + + Computes the size of one GCBulkRootCCWValues structure. + TODO FIX NOW Can rip out and make a constant 44 after 6/2014 + + + + + This structure just POINTS at the data in the GCBulkRootCCWTraceData. It can only be used as long as + the GCBulkRootCCWTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the edge at the given zero-based index (index less than Count). The returned GCBulkRCWValues + points the the data in GCBulkRCWTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkRCWTraceData. It can only be used as long as + the GCBulkRCWTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns 'idx'th static root. + The returned GCBulkRootStaticVarStatics cannot live beyond the TraceEvent that it comes from. + The implementation is highly tuned for sequential access. + + + + + This structure just POINTS at the data in the GCBulkRootStaticVarTraceData. It can only be used as long as + the GCBulkRootStaticVarTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Fetches the instruction pointer of a eventToStack frame 0 is the deepest frame, and the maximum should + be a thread offset routine (if you get a complete eventToStack). + + The index of the frame to fetch. 0 is the CPU EIP, 1 is the Caller of that + routine ... + The instruction pointer of the specified frame. + + + + Access to the instruction pointers as a unsafe memory blob + + + + + This is simply the file name part of the ModuleILPath. It is a convenience method. + + + + + Log events associated with the threadpool, and other threading events. + + + + + Dump the native to IL mapping of any method that is JIT compiled. (V4.5 runtimes and above). + + + + + This supresses NGEN events on V4.0 (where you have NGEN PDBs), but not on V2.0 (which does not know about this + bit and also does not have NGEN PDBS). + + + + + TODO document + + + + + Dump PDBs for dynamically generated modules. + + + + + ClrTraceEventParserState holds all information that is shared among all events that is + needed to decode Clr events. This class is registered with the source so that it will be + persisted. Things in here include + + * TypeID to TypeName mapping, + + + + + Returns the edge at the given zero-based index (index less than Count). The returned BulkNodeValues + points the the data in BulkNodeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the BulkNodeTraceData. It can only be used as long as + the BulkNodeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the edge at the given zero-based index (index less than Count). The returned BulkAttributeValues + points the the data in BulkAttributeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the BulkAttributeTraceData. It can only be used as long as + the BulkAttributeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the edge at the given zero-based index (index less than Count). The returned BulkEdgeValues + points the the data in BulkEdgeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the BulkNodeTraceData. It can only be used as long as + the BulkNodeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + The KernelTraceEventParser is a class that knows how to decode the 'standard' kernel events. + It exposes an event for each event of interest that users can subscribe to. + + see TraceEventParser for more + + + + + The special name for the Kernel session + + + + + This is passed to TraceEventSession.EnableKernelProvider to enable particular sets of + events. See http://msdn.microsoft.com/en-us/library/aa363784(VS.85).aspx for more information on them + + + + + Logs nothing + + + + + Logs the mapping of file IDs to actual (kernel) file names. + + + + + Loads the completion of Physical disk activity. + + + + + Logs native modules loads (LoadLibrary), and unloads + + + + + Logs all page faults that must fetch the data from the disk (hard faults) + + + + + Logs TCP/IP network send and receive events. + + + + + Logs process starts and stops. + + + + + Logs process performance counters (TODO When?) (Vista+ only) + see KernelTraceEventParser.ProcessPerfCtr, ProcessPerfCtrTraceData + + + + + Sampled based profiling (every msec) (Vista+ only) (expect 1K events per proc per second) + + + + + Logs threads starts and stops + + + + + log thread context switches (Vista only) (can be > 10K events per second) + + + + + log Disk operations (Vista+ only) + Generally not TOO volumous (typically less than 1K per second) (Stacks associated with this) + + + + + Thread Dispatcher (ReadyThread) (Vista+ only) (can be > 10K events per second) + + + + + log file FileOperationEnd (has status code) when they complete (even ones that do not actually + cause Disk I/O). (Vista+ only) + Generally not TOO volumous (typically less than 1K per second) (No stacks associated with these) + + + + + log the start of the File I/O operation as well as the end. (Vista+ only) + Generally not TOO volumous (typically less than 1K per second) + + + + + Logs all page faults (hard or soft) + Can be pretty volumous (> 1K per second) + + + + + Logs activity to the windows registry. + Can be pretty volumous (> 1K per second) + + + + + log calls to the OS (Vista+ only) + This is VERY volumous (can be > 100K events per second) + + + + + Log Virtual Alloc calls and VirtualFree. (Vista+ Only) + Generally not TOO volumous (typically less than 1K per second) + + + + + Log mapping of files into memmory (Win8 and above Only) + Generally low volume. + + + + + Logs Advanced Local Procedure call events. + + + + + log defered procedure calls (an Kernel mechanism for having work done asynchronously) (Vista+ only) + + + + + Device Driver logging (Vista+ only) + + + + + log hardware interrupts. (Vista+ only) + + + + + Disk I/O that was split (eg because of mirroring requirements) (Vista+ only) + + + + + Good default kernel flags. (TODO more detail) + + + + + These events are too verbose for normal use, but this give you a quick way of turing on 'interesting' events + This does not include SystemCall because it is 'too verbose' + + + + + Use this if you care about blocked time. + + + + + You mostly don't care about these unless you are dealing with OS internals. + + + + + All legal kernel events + + + + + These are the kernel events that are not allowed in containers. Can be subtracted out. + + + + + Turn on PMC (Precise Machine Counter) events. Only Win 8 + + + + + Kernel reference set events (like XPERF ReferenceSet). Fully works only on Win 8. + + + + + Events when thread priorities change. + + + + + Events when queuing and dequeuing from the I/O completion ports. + + + + + Handle creation and closing (for handle leaks) + + + + + These keywords can't be passed to the OS, they are defined by KernelTraceEventParser + + + + + What his parser should track by default. + + + + + Defines how kernel paths are converted to user paths. Setting it overrides the default path conversion mechanism. + + + + + Registers both ProcessStart and ProcessDCStart + + + + + Registers both ProcessEnd and ProcessDCStop + + + + + Registers both ThreadStart and ThreadDCStart + + + + + Registers both ThreadEnd and ThreadDCStop + + + + + Registers both ImageLoad and ImageDCStart + + + + + Registers both ImageUnload and ImageDCStop + + + + + Rasied every 0.5s with memory metrics of the current machine. + + + + + File names in ETW are the Kernel names, which need to be mapped to the drive specification users see. + This event indicates this mapping. + + + + + KernelTraceEventParserState holds all information that is shared among all events that is + needed to decode kernel events. This class is registered with the source so that it will be + persisted. Things in here include + + * FileID to FileName mapping, + * ThreadID to ProcessID mapping + * Kernel file name to user file name mapping + + + + + If you have a file object (per-open-file) in addition to a fileKey, try using both + to look up the file name. + + + + + This is for the circular buffer case. In that case we may not have thread starts (and thus we don't + have entries in threadIDtoProcessID). Because HistoryTable finds the FIRST entry GREATER than the + given threadID we NEGATE all times before we place it in this table. + + Also, because circular buffering is not the common case, we only add entries to this table if needed + (if we could not find the thread ID using threadIDtoProcessID). + + + + + Keeps track of the mapping from kernel names to file system names (drives) + + + + + Create a new KernelToUserDriveMapping that can look up kernel names for drives and map them to windows drive letters. + + + + + Returns the string representing the windows drive letter for the kernel drive name 'kernelName' + + + + + + + This is the number of minutes between the local time where the data was collected and UTC time. + It does NOT take Daylight savings time into account. + It is positive if your time zone is WEST of Greenwich. + + + + + Indicate that StartAddr and Win32StartAddr are a code addresses that needs symbolic information + + + + + We report a context switch from from the new thread. Thus NewThreadID == ThreadID. + + + + + The I/O Response Packet address. This represents the 'identity' of this particular I/O + + + + + This is the time since the I/O was initiated, in source.PerfFreq (QPC) ticks. + + + + + This is the actual time the disk spent servicing this IO. Same as elapsed time for real time providers. + + + + + The time since the I/O was initiated. + + + + + This is the time since the I/O was initiated, in source.PerfFreq (QPC) ticks. + + + + + The time since the I/O was initiated. + + + + + This is a handle that represents a file NAME (not an open file). + In the MSDN does this field is called FileObject. However in other events FileObject is something + returned from Create file and is different. Events have have both (and some do) use FileKey. Thus + I use FileKey uniformly to avoid confusion. + + + + + See the Windows CreateFile API CreateOptions for this + + + + + See Windows CreateFile API CreateDisposition for this. + + + + + See Windows CreateFile API ShareMode parameter + + + + + See windows CreateFile API ShareMode parameter + + + + + See Windows CreateFile function CreateDispostion parameter. + + + + + See Windows CreateFile function FlagsAndAttributes parameter. + TODO FIX NOW: these have not been validated yet. + + + + + The FileObject is the object for the Directory (used by CreateFile to open and passed to Close to close) + + + + + The FileKey is the object that represents the name of the directory. + + + + + This is the TimeDateStamp converted to a DateTime + TODO: daylight savings time seems to mess this up. + + + + + Indicate that ProgramCounter is a code address that needs symbolic information + + + + + The time spent during the page fault. + + + + + Indicate that the Address is a code address that needs symbolic information + + + + + This event is emitted by the Microsoft-Windows-Kernel-Memory with Keyword 0x40 KERNEL_MEM_KEYWORD_MEMINFO_EX every .5 seconds + + + + + Returns the edge at the given zero-based index (index less than Count). The returned MemoryProcessMemInfoValues + points the the data in MemoryProcessMemInfoTraceData so it cannot live beyond that lifetime. + + + + + The fields after 'Count' are the first value in the array of working sets. + + + + + This structure just POINTS at the data in the MemoryProcessMemInfoTraceData. It can only be used as long as + the MemoryProcessMemInfoTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + The fields after 'Count' are the first value in the array of working sets. + + + + + Are we currently executing a Deferred Procedure Call (a mechanism the kernel uses to + 'steal' a thread to run its own work). If this is true, the CPU time is really + not logically related to the process (it is kernel time). + + + + + Are we currently executing a Interrupt Service Routine? Like ExecutingDPC if this + is true the thread is really doing Kernel work, not work for the process. + + + + + NonProcess is true if ExecutingDPC or ExecutingISR is true. + + + + + The thread's current priority (higher is more likely to run). A normal thread with a normal base + priority is 8. + see http://msdn.microsoft.com/en-us/library/windows/desktop/ms685100(v=vs.85).aspx for more + + + + + Your scheduling If the thread is not part of a scheduling group, this is 0 (see callout.c) + + + + + Indicate that the Address is a code address that needs symbolic information + + + + + PMC (Precise Machine Counter) events are fired when a CPU counter trips. The the ProfileSource identifies + which counter it is. The PerfInfoCollectionStart events will tell you the count that was configured to trip + the event. + + + + + Indicate that Address is a code address that needs symbolic information + + + + + Indicate that the Address is a code address that needs symbolic information + + + + + Collects the call callStacks for some other event. + + (TODO: always for the event that preceded it on the same thread)? + + + + + The timestamp of the event which caused this stack walk using QueryPerformaceCounter + cycles as the tick. + + + + + Converts this to a time relative to the start of the trace in msec. + + + + + The total number of eventToStack frames collected. The Windows OS currently has a maximum of 96 frames. + + + + + Fetches the instruction pointer of a eventToStack frame 0 is the deepest frame, and the maximum should + be a thread offset routine (if you get a complete stack). + + The index of the frame to fetch. 0 is the CPU EIP, 1 is the Caller of that + routine ... + The instruction pointer of the specified frame. + + + + Access to the instruction pointers as a unsafe memory blob + + + + + StackWalkTraceData does not set Thread and process ID fields properly. if that. + + + + + To save space, stack walks in Win8 can be complressed. The stack walk event only has a + reference to a stack Key which is then looked up by StackWalkDefTraceData. + + + + + The timestamp of the event which caused this stack walk using QueryPerformaceCounter + cycles as the tick. + + + + + Converts this to a time relative to the start of the trace in msec. + + + + + Returns a key that can be used to look up the stack in KeyDelete or KeyRundown events + + + + + StackWalkTraceData does not set Thread and process ID fields properly. if that. + + + + + This event defines a stack and gives it a unique id (the StackKey), which StackWalkRefTraceData can point at. + + + + + Returns a key that can be used to look up the stack in KeyDelete or KeyRundown events + + + + + The total number of eventToStack frames collected. The Windows OS currently has a maximum of 96 frames. + + + + + Fetches the instruction pointer of a eventToStack frame 0 is the deepest frame, and the maximum should + be a thread offset routine (if you get a complete complete). + + The index of the frame to fetch. 0 is the CPU EIP, 1 is the Caller of that + routine ... + The instruction pointer of the specified frame. + + + + Access to the instruction pointers as a unsafe memory blob + + + + + e.g. c:\windows\system32 + + + + + .e.g c:\windows + + + + + Kernel traces have information about images that are loaded, however they don't have enough information + in the events themselves to unambigously look up PDBs without looking at the data inside the images. + This means that symbols can't be resolved unless you are on the same machine on which you gathered the data. + + XPERF solves this problem by adding new 'synthetic' events that it creates by looking at the trace and then + opening each DLL mentioned and extracting the information needed to look PDBS up on a symbol server (this + includes the PE file's TimeDateStamp as well as a PDB Guid, and 'pdbAge' that can be found in the DLLs header. + + These new events are added when XPERF runs the 'merge' command (or -d flag is passed). It is also exposed + through the KernelTraceControl.dll!CreateMergedTraceFile API. + + SymbolTraceEventParser is a parser for extra events. + + + + + The DbgIDRSDS event is added by XPERF for every Image load. It contains the 'PDB signature' for the DLL, + which is enough to unambiguously look the image's PDB up on a symbol server. + + + + + Every DLL has a Timestamp in the PE file itself that indicates when it is built. This event dumps this timestamp. + This timestamp is used to be as the 'signature' of the image and is used as a key to find the symbols, however + this has mostly be superseded by the DbgID/RSDS event. + + + + + The FileVersion event contains information from the file version resource that most DLLs have that indicated + detailed information about the exact version of the DLL. (What is in the File->Properties->Version property + page) + + + + + I don't really care about this one, but I need a definition in order to exclude it because it + has the same timestamp as a imageLoad event, and two events with the same timestamp confuse the + association between a stack and the event for the stack. + + + + + This event has a TRACE_EVENT_INFO as its payload, and allows you to decode an event + + + + + The event describes a Map (bitmap or ValueMap), and has a payload as follows + + GUID ProviderId; + EVENT_MAP_INFO EventMapInfo; + + + + + The value of the one string payload property. + + + + + Construct a TraceEvent template which has one string payload field with the given metadata and action + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + override + + + + + RegisteredTraceEventParser uses the standard windows provider database (TDH, what gets registered with wevtutil) + to find the names of events and fields of the events). + + + + + Create a new RegisteredTraceEventParser and attach it to the given TraceEventSource + + + + + Given a provider name that has been registered with the operating system, get + a string representing the ETW manifest for that provider. Note that this + manifest is not as rich as the original source manifest because some information + is not actually compiled into the binary manifest that is registered with the OS. + + + + + Given a provider GUID that has been registered with the operating system, get + a string representing the ETW manifest for that provider. Note that this + manifest is not as rich as the original source manifest because some information + is not actually compiled into the binary manifest that is registered with the OS. + + + + + Generates a space separated list of set of keywords 'keywordSet' using the table 'keywords' + It will generate new keyword names if needed and add them to 'keywords' if they are not present. + + + + + Class used to accumulate information about Tasks in the implementation of GetManifestForRegisteredProvider + + + + + Try to look up 'unknonwEvent using TDH or the TraceLogging mechanism. if 'mapTable' is non-null it will be used + look up the string names for fields that have bitsets or enumerated values. This is only need for the KernelTraceControl + case where the map information is logged as special events and can't be looked up with TDH APIs. + + + + + TdhEventParser takes the Trace Diagnostics Helper (TDH) TRACE_EVENT_INFO structure and + (passed as a byte*) and converts it to a DynamicTraceEventData which which + can be used to parse events of that type. You first create TdhEventParser and then + call ParseEventMetaData to do the parsing. + + + + + Creates a new parser from the TRACE_EVENT_INFO held in 'buffer'. Use + ParseEventMetaData to then parse it into a DynamicTraceEventData structure. + EventRecord can be null and mapTable if present allow the parser to resolve maps (enums), and can be null. + + + + + Actually performs the parsing of the TRACE_EVENT_INFO passed in the constructor + + + + + + Parses at most 'maxFields' fields starting at the current position. + Will return the parse fields in 'payloadNamesRet' and 'payloadFetchesRet' + Will return true if successful, false means an error occurred. + + + + + ExternalTraceEventParser is an abstract class that acts as a parser for any 'External' resolution + This include the TDH (RegisteredTraceEventParser) as well as the WPPTraceEventParser. + + + + + Create a new ExternalTraceEventParser and attach it to the given TraceEventSource + + + + + Override. + + + + + Override + + + + + Returns true if the RegisteredTraceEventParser would return 'template' in EnumerateTemplates + + + + + override + + + + + Register 'template' so that if there are any subscriptions to template they get registered with the source. + + + + + Used to look up Enums (provider x enumName); Very boring class. + + + + + TDHDynamicTraceEventParserState represents the state of a TDHDynamicTraceEventParser that needs to be + serialized to a log file. It does NOT include information about what events are chosen but DOES contain + any other necessary information that came from the ETL data file or the OS TDH APIs. + + + + + This defines what it means to be the same event. For manifest events it means provider and event ID + for classic, it means that taskGuid and opcode match. + + + + + Implements IFastSerializable interface + + + + + Implements IFastSerializable interface + + + + + This parser knows how to decode Windows Software Trace Preprocessor (WPP) events. In order to decode + the events it needs access to the TMF files that describe the events (these are created from the PDB at + build time). +
+ You will generally use this for the 'FormattedMessage' property of the event. +
+
+ + + Construct a new WPPTraceEventParser that is attached to 'source'. Once you do this the source + will understand WPP events. In particular you can subscribe to the Wpp.All event to get the + stream of WPP events in the source. For WppTraceEventParser to function, it needs the TMF + files for the events it will decode. You should pass the directory to find these TMF files + in 'TMFDirectory'. Each file should have the form of a GUID.tmf. + + + + + + + ETWReloggerTraceEventSource is designed to be able to write ETW files using an existing ETW input stream (either a file, files or real time session) as a basis. + The relogger capabilities only exist on Windows 8 OSes and beyond. + + The right way to think about this class is that it is just like ETWTraceEventSource, but it also has a output file associated with it, and WriteEvent APIs that + can be used to either copy events from the event stream (the common case), or inject new events (high level stats). + + + + + Create an ETWReloggerTraceEventSource that can takes its input from the family of etl files inputFileName + and can write them to the ETL file outputFileName (.kernel*.etl, .user*.etl .clr*.etl) + + This is a shortcut for ETWReloggerTraceEventSource(inputFileName, TraceEventSourceType.MergeAll, outputFileStream) + + + + + Create an ETWReloggerTraceEventSource that can takes its input from a variety of sources (either a single file, + a set of files, or a real time ETW session (based on 'type'), and can write these events to a new ETW output + file 'outputFileName. + + + + + The output file can use a compressed form or not. Compressed forms can only be read on Win8 and beyond. Defaults to true. + + + + + Writes an event from the input stream to the output stream of events. + + + + + Connect the given EventSource so any events logged from it will go to the output stream of events. + Once connected, you may only write events from this EventSource while processing the input stream + (that is during the callback of an input stream event), because the context for the EventSource event + (e.g. timestamp, proesssID, threadID ...) will be derived from the current event being processed by + the input stream. + + + + + Writes an event that did not exist previously into the data stream, The context data (time, process, thread, activity, comes from 'an existing event') + + + + + Writes an event that did not exist previously into the data stream, The context data (time, process, thread, activity, comes from 'an existing event') is given explicitly + + + + + implementing TraceEventDispatcher + + + + + implementing TraceEventDispatcher + + + + + Implements TraceEventDispatcher.Dispose + + + + + Implements TraceEventDispatcher.StopProcessing + + + + + This is used by the ConnectEventSource to route events from the EventSource to the relogger. + + + + + This is the class the Win32 APIs call back on. + + + + + A ETWTraceEventSource represents the stream of events that was collected from a + TraceEventSession (eg the ETL moduleFile, or the live session event stream). Like all + TraceEventSource, it logically represents a stream of TraceEvent s. Like all + TraceEventDispathers it supports a callback model where Parsers attach themselves to this + sources, and user callbacks defined on the parsers are called when the 'Process' method is called. + + * See also TraceEventDispatcher + * See also TraceEvent + * See also #ETWTraceEventSourceInternals + * See also #ETWTraceEventSourceFields + + + + + Open a ETW event trace moduleFile (ETL moduleFile) for processing. + + The ETL data moduleFile to open` + + + + Open a ETW event source for processing. This can either be a moduleFile or a real time ETW session + + + If type == ModuleFile this is the name of the moduleFile to open. + If type == Session this is the name of real time session to open. + + + + + Process all the files in 'fileNames' in order (that is all the events in the first + file are processed, then the second ...). Intended for parsing the 'Multi-File' collection mode. + + The list of files path names to process (in that order) + + + + Processes all the events in the data source, issuing callbacks that were subscribed to. See + #Introduction for more + + false If StopProcesing was called + + + + Reprocess a pre-constructed event which this processor has presumably created. Helpful to re-examine + "unknown" events, perhaps after a manifest has been received from the ETW stream. + Note when queuing events to reprocess you must Clone them first + or certain internal data may no longer be available and you may receive memory access violations. + + Event to re-process. + + + + The log moduleFile that is being processed (if present) + TODO: what does this do for Real time sessions? + + + + + The name of the session that generated the data. + + + + + The size of the log, will return 0 if it does not know. + + + + + returns the number of events that have been lost in this session. Note that this value is NOT updated + for real time sessions (it is a snapshot). Instead you need to use the TraceEventSession.EventsLost property. + + + + + Returns true if the Process can be called multiple times (if the Data source is from a + moduleFile, not a real time stream. + + + + + This routine is only useful/valid for real-time sessions. + + TraceEvent.TimeStamp internally is stored using a high resolution clock called the Query Performance Counter (QPC). + This clock is INDEPENDENT of the system clock used by DateTime. These two clocks are synchronized to within 2 msec at + session startup but they can drift from there (typically 2msec / min == 3 seconds / day). Thus if you have long + running real time session it becomes problematic to compare the timestamps with those in another session or something + timestamped with the system clock. SynchronizeClock will synchronize the TraceEvent.Timestamp clock with the system + clock again. If you do this right before you start another session, then the two sessions will be within 2 msec of + each other, and their timestamps will correlate. Doing it periodically (e.g. hourly), will keep things reasonably close. + + TODO: we can achieve perfect synchronization by exposing the QPC tick sync point so we could read the sync point + from one session and set that exact sync point for another session. + + + + + Options that can be passed to GetModulesNeedingSymbols + + + + + This is the default, where only NGEN images are included (since these are the only images whose PDBS typically + need to be resolved agressively AT COLLECTION TIME) + + + + + If set, this option indicates that non-NGEN images should also be included in the list of returned modules + + + + + Normally only modules what have a CPU or stack sample are included in the list of assemblies (thus you don't + unnecessarily have to generate NGEN PDBS for modules that will never be looked up). However if there are + events that have addresses that need resolving that this routine does not recognise, this option can be + set to insure that any module that was event LOADED is included. This is inefficient, but guarenteed to + be complete + + + + + Given an ETL file, returns a list of the full paths to DLLs that were loaded in the trace that need symbolic + information (PDBs) so that the stack traces and CPU samples can be properly resolved. By default this only + returns NGEN images since these are the ones that need to be resolved and generated at collection time. + + + + + Image data is a trivial record for image data, where it is keyed by the base address, processID and name. + + + + + Returns the size of pointer (8 or 4) for the operating system (not necessarily the process) + + + + + This is a little helper class that maps QueryPerformanceCounter (QPC) ticks to DateTime. There is an error of + a few msec, but as long as every one uses the same one, we probably don't care. + + + + + see Dispose pattern + + + + + see Dispose pattern + + + + + Used by real time TraceLog on Windows7. + If we have several real time sources we have them coming in on several threads, but we want the illusion that they + are one source (thus being processed one at a time). Thus we want a lock that is taken on every dispatch. + + + + + The kinds of data sources that can be opened (see ETWTraceEventSource) + + + + + Look for any files like *.etl or *.*.etl (the later holds things like *.kernel.etl or *.clrRundown.etl ...) + + + + + Look for a ETL moduleFile *.etl as the event data source + + + + + Use a real time session as the event data source. + + + + + EventPipeEventSource knows how to decode EventPipe (generated by the .NET core runtime). + Please see for details on the file format. + + By conventions files of such a format are given the .netperf suffix and are logically + very much like a ETL file in that they have a header that indicate things about + the trace as a whole, and a list of events. Like more modern ETL files the + file as a whole is self-describing. Some of the events are 'MetaData' events + that indicate the provider name, event name, and payload field names and types. + Ordinary events then point at these meta-data event so that logically all + events have a name some basic information (process, thread, timestamp, activity + ID) and user defined field names and values of various types. + + + + + This is the version number reader and writer (although we don't don't have a writer at the moment) + It MUST be updated (as well as MinimumReaderVersion), if breaking changes have been made. + If your changes are forward compatible (old readers can still read the new format) you + don't have to update the version number but it is useful to do so (while keeping MinimumReaderVersion unchanged) + so that readers can quickly determine what new content is available. + + + + + This field is only used for writers, and this code does not have writers so it is not used. + It should be set to Version unless changes since the last version are forward compatible + (old readers can still read this format), in which case this shoudl be unchanged. + + + + + This is the smallest version that the deserializer here can read. Currently + we are careful about backward compat so our deserializer can read anything that + has ever been produced. We may change this when we believe old writers basically + no longer exist (and we can remove that support code). + + + + + Give meta-data for an event, passed as a EventPipeEventMetaDataHeader and readerForParameters + which is a StreamReader that points at serialized parameter information, decode the meta-data + and record a template associated with this source. The readerForParameters is advanced beyond + the event parameters information. + + + + + Given the EventPipe metaData header and a stream pointing at the serialized meta-data for the parameters for the + event, create a new DynamicTraceEventData that knows how to parse that event. + ReaderForParameters.Current is advanced past the parameter information. + + + + + An EVentPipeEventBlock represents a block of events. It basicaly only has + one field, which is the size in bytes of the block. But when its FromStream + is called, it will perform the callbacks for the events (thus deserializing + it performs dispatch). + + + + + Private utility class. + + An EventPipeEventMetaDataHeader holds the information that can be shared among all + instances of an EventPipe event from a particular provider. Thus it contains + things like the event name, provider, It however does NOT contain the data + about the event parameters (the names of the fields and their types), That is + why this is a meta-data header and not all the meta-data. + + This class has two main functions + 1. The constructor takes a PinnedStreamReader and decodes the serialized metadata + so you can access the data conveniently (but it does not decode the parameter info) + 2. It remembers a EVENT_RECORD structure (from ETW) that contains this data) + and has a function GetEventRecordForEventData which converts from a + EventPipeEventHeader (the raw serialized data) to a EVENT_RECORD (which + is what TraceEvent needs to look up the event an pass it up the stack. + + + + + Creates a new MetaData instance from the serialized data at the current position of 'reader' + of length 'length'. This typically points at the PAYLOAD AREA of a meta-data events) + 'fileFormatVersionNumber' is the version number of the file as a whole + (since that affects the parsing of this data) and 'processID' is the process ID for the + whole stream (since it needs to be put into the EVENT_RECORD. + + When this constructor returns the reader has read up to the serialized information about + the parameters. We do this because this code does not know the best representation for + this parameter information and so it just lets other code handle it. + + + + + Given a EventPipeEventHeader takes a EventPipeEventHeader that is specific to an event, copies it + on top of the static information in its EVENT_RECORD which is specialized meta-data + and returns a pointer to it. Thus this makes the EventPipe look like an ETW provider from + the point of view of the upper level TraceEvent logic. + + + + + This is a number that is unique to this meta-data blob. It is expected to be a small integer + that starts at 1 (since 0 is reserved) and increases from there (thus an array can be used). + It is what is matched up with EventPipeEventHeader.MetaDataId + + + + + Reads the meta data for information specific to one event. + + + + + Private utility class. + + At the start of every event from an EventPipe is a header that contains + common fields like its size, threadID timestamp etc. EventPipeEventHeader + is the layout of this. Events have two variable sized parts: the user + defined fields, and the stack. EventPipEventHeader knows how to + decode these pieces (but provides no semantics for it. + + It is not a public type, but used in low level parsing of EventPipeEventSource. + + + + + Header Size is defined to be the number of bytes before the Payload bytes. + + + + + Fetches the instruction pointer of a eventToStack frame 0 is the deepest frame, and the maximum should + be a thread offset routine (if you get a complete eventToStack). + + The index of the frame to fetch. 0 is the CPU EIP, 1 is the Caller of that + routine ... + The instruction pointer of the specified frame. + + + + Access to the instruction pointers as a unsafe memory blob + + + + + SampleInfos of a set of stackSource by eventToStack. This represents the entire call tree. You create an empty one in using + the default constructor and use 'AddSample' to add stackSource to it. You traverse it by + + + + + Creates an empty call tree, indicating the scaling policy of the metric. You populate it by assigning a StackSOurce to the tree. + + + + + A CallTree is generated from a StackSource. Setting the StackSource causes the tree to become populated. + + + + + When calculating percentages, the PercentageBasis do we use as 100%. By default we use the + Inclusive time for the root, but that can be changed here. + + + + + Returns the root node of the call tree. + + + + + An upper bound for the node indexes in the call tree. (All indexes + are strictly less than this number) Thus ASSSUMING YOU DON'T ADD + NEW NODES, an array of this size can be used to index the nodes (and + thus lookup nodes by index or to store additional information about a node). + + + + + Get a CallerCalleeNode for the nodes in the call tree named 'nodeName' + + + + + Returns a list of nodes that have statistics rolled up by treeNode by ID. It is not + sorted by anything in particular. Note that ID is not quite the same thing as the + name. You can have two nodes that have different IDs but the same Name. These + will show up as two distinct entries in the resulting list. + + + + + Returns the list returned by the ByID property sorted by exclusive metric. + + + + + If there are any nodes that have strictly less than to 'minInclusiveMetric' + then remove the node, placing its samples into its parent (thus the parent's + exclusive metric goes up). + + If useWholeTraceMetric is true, nodes are only folded if their inclusive metric + OVER THE WHOLE TRACE is less than 'minInclusiveMetric'. If false, then a node + is folded if THAT NODE has less than the 'minInclusiveMetric' + + Thus if 'useWholeTraceMetric' == false then after calling this routine no + node will have less than minInclusiveMetric. + + + + + + Cause the children of each CallTreeNode in the CallTree to be sorted (accending) based on comparer + + + + + Sorting by InclusiveMetric Decending is so common, provide a shortcut. + + + + + When converting the InclusiveMetricByTime to a InclusiveMetricByTimeString you have to decide + how to scale the samples to the digits displayed in the string. This enum indicates this policy + + + + + The nodes in the calltree have histograms in time, all of these histograms share a controller that + contains sharable information. This propertly returns that TimeHistogramController + + + + + The nodes in the calltree have histograms indexed by scenario (which is user defiend), + all of these histograms share a controller that contains sharable information. + This propertly returns that ScenarioHistogramController + + + + + Turns off logic for computing call trees in parallel. Safer but slower. + + + This is off by default following indications of race conditions. + + + + + Break all links in the call tree to free as much memory as possible. + + + + + Write an XML representtaion of the CallTree to 'writer' + + + + + An XML representtaion of the CallTree (for debugging) + + + + + Traverse the subtree of 'treeNode' into the m_sumByID dictionary. We don't want to + double-count inclusive times, so we have to keep track of all callers currently on the + stack and we only add inclusive times for nodes that are not already on the stack. + + + + + ScalingPolicyKind represents the desired way to scale the metric in the samples. + + + + + This is the default. In this policy, 100% is chosen so that the histogram is scaled as best it can. + + + + + It assumes that the metric represents time + + + + + Represents a unique ID for a node in a call tree. Can be used to look up a call tree node easily. + It is a dense value (from 0 up to a maximum). + + + + + An Invalid Node Index. + + + + + A CallTreeNodeBase is the inforation in a CallTreeNode without parent or child relationships. + ByName nodes and Caller-Callee nodes need this because they either don't have or need different + parent-child relationships. + + + + + Returns a unique small, dense number (suitable for looking up in an array) that represents + this call tree node (unlike the ID, which more like the name of the frame of the node), so you + can have many nodes with the same name, but only one with the same index. See CallTree.GetNodeIndexLimit. + + + + + Create a CallTreeNodeBase (a CallTreeNode without children) which is a copy of another one. + + + + + The Frame name that this tree node represents. + + + + + Currently the same as Name, but could contain additional info. + Suitable for display but not for programmatic comparison. + + + + + The ID represents a most fine grained uniqueness associated with this node. It can represent + a method, but for sources that support 'goto source' functionality these IDs actually represent + particular lines (or more precisely program counter locations), within the method. Thus it is + very likely that there are call tree nodes that have the same name but different IDs. + + This can be StackSourceFrameIndex.Invalid for Caller-callee nodes (which have names, but no useful ID) + + If ID != Invalid, and the IDs are the same then the names are guaranteed to be the same. + + + + + The sum of the metric of all samples that are in this node or any child of this node (recursively) + + + + + The average metric of all samples that are in this node or any child of this node (recursively). + This is simply InclusiveMetric / InclusiveCount. + + + + + The sum of the metric of all samples that are in this node + + + + + The sum of the metric of all samples in this node that are there because they were folded (inlined). It is alwasy less than or equal to ExclusiveMetric. + + + + + The sum of the count of all samples that are in this node or any child of this node (recursively) + + + + + The sum of the count of all samples that are in this node + + + + + The sum of the count of all samples in this node that are there because they were folded (inlined). It is alwasy less than or equal to ExclusiveCount. + + + + + The inclusive metric, normalized to the total metric for the entire tree. + + + + + The exclusive metric, normalized to the total metric for the entire tree. + + + + + The exclusive folded metric, normalized to the total metric for the entire tree. + + + + + The time of the first sample for this node or any of its children (recursively) + + + + + The time of the first sample for this node or any of its children (recursively) + + + + + The time of the last sample for this node or any of its children (recursively) + + + + + The time of the last sample for this node or any of its children (recursively) + + + + + The difference between the first and last sample (in MSec). + + + + + The call tree that contains this node. + + + + + Returns the histogram that groups of samples associated with this node or any of its children by time buckets + + + + + Returns a string that represents the InclusiveMetricByTime Histogram by using character for every bucket (like PerfView) + + + + + Returns the histogram that groups of samples associated with this node or any of its children by scenario buckets + + + + + Returns a string that represents the InclusiveMetricByScenario Histogram by using character for every bucket (like PerfView) + + + + + Returns all the original stack samples in this node. If exclusive==true then just he + sample exclusively in this node are returned, otherwise it is the inclusive samples. + + If the original stack source that was used to create this CodeTreeNode was a FilterStackSource + then that filtering is removed in the returned Samples. + + Returns the total number of samples (the number of times 'callback' is called) + + If the callback returns false, the iteration over samples stops. + + + + + While 'GetSamples' can return all the samples in the tree, this is a relatively + inefficient way of representing the samples. Instead you can return a list of + trees whose samples represent all the samples. This is what GetTrees does. + It calls 'callback' on a set of trees that taken as a whole have all the samples + in 'node'. + + Note you ave to be careful when using this for inclusive summation of byname nodes because + you will get trees that 'overlap' (bname nodes might refer into the 'middle' of another + call tree). This can be avoided pretty easily by simply stopping inclusive traversal + whenever a tree node with that ID occurs (see GetSamples for an example). + + + + + Returns a string representing the set of XML attributes that can be added to another XML element. + + + + + An XML representation of the CallTreeNodeBase (for debugging) + + + + + The GUI sadly holds on to Call things in the model in its cache, and call tree nodes have linkes to whole + call tree. To avoid the GUI cache from holding on to the ENTIRE MODEL, we neuter the nodes when we are + done with them so that even if they are pointed to by the GUI cache it does not hold onto most of the + (dead) model. FreeMemory does this neutering. + + + + + Combines the 'this' node with 'otherNode'. If 'newOnStack' is true, then the inclusive + metrics are also updated. + + Note that I DON'T accumulate other.m_samples into this.m_samples. This is because we want to share + samples as much a possible. Thus nodes remember their samples by pointing at other call trees + and you fetch the samples by an inclusive walk of the tree. + + + + + To avoid double-counting for byname nodes, with we can be told to exclude any children with a particular ID + (the ID of the ByName node itself) if are doing the inclusive case. The goal is to count every reachable + tree exactly once. We do this by conceptually 'marking' each node with ID at the top level (when they are + enumerated as children of the Byname node), and thus any node with that excludeChildrenWithID is conceptually + marked if you encounter it as a child in the tree itself (so you should exclude it). The result is that + every node is visited exactly once (without the expense of having a 'visited' bit). + + + + + Represents a single treeNode in a CallTree + + Each node keeps all the sample with the same path to the root. + Each node also remembers its parent (caller) and children (callees). + The nodes also keeps the IDs of all its samples (so no information + is lost, just sorted by stack). You get at this through the + CallTreeNodeBase.GetSamples method. + + + + + The caller (parent) of this node + + + + + The nodes this node calls (its children). + + + + + Returns true if Callees is empty. + + + + + AllCallees is an extension of CallTreesNodes to support graphs (e.g. memory heaps). + It always starts with the 'normal' Callees, however in addition if we are + displaying a Graph, it will also children that were 'pruned' when the graph was + transformed into a tree. (by using StackSource.GetRefs). + + + + + Returns true if AllCallees is non-empty. + + + + + Returns true if the call trees came from a graph (thus AllCallees may be strictly larger than Callees) + + + + + Writes an XML representation of the call tree Node it 'writer' + + + + + Returns an XML representation of the call tree Node (for debugging); + + + + + Adds up the counts of all nodes called 'BROKEN' nodes in a particular tree node + + This is a utility function. + + + + + Creates a string that has spaces | and + signs that represent the indentation level + for the tree node. (Called from XAML) + + + + + Implements CallTreeNodesBase interface + + + + + Sort the childre of every node in the te + + + + + + Some calltrees already fill in their children, others do so lazily, in which case they + override this method. + + + + + Fold away any nodes having less than 'minInclusiveMetric'. If 'sumByID' is non-null then the + only nodes that have a less then the minInclusiveMetric for the whole trace are folded. + + + + + A CallerCalleeNode gives statistics that focus on a NAME. (unlike calltrees that use ID) + It takes all stackSource that have callStacks that include that treeNode and compute the metrics for + all the callers and all the callees for that treeNode. + + + + + Given a complete call tree, and a Name within that call tree to focus on, create a + CallerCalleeNode that represents the single Caller-Callee view for that treeNode. + + + + + The list of CallTreeNodeBase nodes that called the method represented by this CallerCalleeNode + + + + + The list of CallTreeNodeBase nodes that where called by the method represented by this CallerCalleeNode + + + + + wrtites an XML representation of the call tree Node it 'writer' + + + + + Returns an XML representation of the CallerCalleeNode (for debugging); + + + + + Implements CallTreeNodesBase interface + + + + + A caller callee view is a summation which centers around one 'focus' node which is represented by the CallerCalleeNode. + This node has a caller and callee list, and these nodes (as well as the CallerCalleNode itself) represent the aggregation + over the entire tree. + + AccumulateSamplesForNode is the routine that takes a part of a aggregated call tree (represented by 'treeNode' and adds + in the statistics for that call tree into the CallerCalleeNode aggregations (and its caller and callee lists). + + 'recursionsCount' is the number of times the focus node name has occurred in the path from 'treeNode' to the root. In + addition to setting the CallerCalleeNode aggregation, it also returns a 'weightedSummary' inclusive aggregation + FOR JUST treeNode (the CallerCalleNode is an aggregation over the entire call tree accumulated so far). + + The key problem for this routine to avoid is double counting of inclusive samples in the face of recursive functions. + Thus all samples are weighted by the recursion count before being included in 'weightedSummaryRet (as well as in + the CallerCalleeNode and its Callers and Callees). + + An important optimization is the ability to NOT create (but rather reuse) CallTreeNodes when returning weightedSummaryRet. + To accomplish this the weightedSummaryScaleRet is needed. To get the correct numerical value for weightedSummaryRet, you + actually have to scale values by weightedSummaryScaleRet before use. This allows us to represent weights of 0 (subtree has + no calls to the focus node), or cases where the subtree is completely uniform in its weighting (the subtree does not contain + any additional focus nodes), by simply returning the tree node itself and scaling it by the recursion count). + + isUniformRet is set to false if anyplace in 'treeNode' does not have the scaling factor weightedSummaryScaleRet. This + means the the caller cannot simply scale 'treeNode' by a weight to get weightedSummaryRet. + + + + + Find the Caller-Callee treeNode in 'elems' with name 'frameName'. Always succeeds because it + creates one if necessary. + + + + + AggregateCallTreeNode supports a multi-level caller-callee view. + + It does this by allow you to take any 'focus' node (typically a byname node) + and compute a tree of its callers and a tree of its callees. You do this + by passing the node of interested to either the 'CallerTree' or 'CalleeTrees'. + + The AggregateCallTreeNode remembers if if is a caller or callee node and its + 'Callees' method returns the children (which may in fact be Callers). + + What is nice about 'AggregateCallTreeNode is that it is lazy, and you only + form the part of the tree you actually explore. A classic 'caller-callee' + view is simply the caller and callee trees only explored to depth 1. + + + + + Given any node (typically a byName node, but it works on any node), Create a + tree rooted at 'node' that represents the callers of that node. + + + + + Given any node (typically a byName node, but it works on any node), Create a + tree rooted at 'node' that represents the callees of that node. + + + + + Calls 'callback' for each distinct call tree in this node. Note that the same + trees can overlap (in the case of recursive functions), so you need a mechanism + for visiting a tree only once. + + + + + Returns an XML representation of the AggregateCallTreeNode (for debugging); + + + + + Implementation of CallTreeNodeBase interface + + + + + Implementation of CallTreeNode interface + + + + + See m_callerOffset and MergeCallee for more. + + The 'this' node is a AggregateCallTree representing the 'callers' nodes. Like + MergeCallee the aggregate node represents a list of CallTreeNodes. However unlike + MergeCallee, the list of CallTreeNodes each represent a sample (a complete call stack) + and 'callerOffset' indicates how far 'up' that stack is the node of interest. + + + + + An aggregateCallTreeNode is exactly that, the sum of several callTrees + (each of which represent a number of individual samples). Thus we had to + take each sample (which is 'treenode' and merge it into the aggregate. + We do this one at a time. Thus we call MergeCallee for each calltree + in our list and we find the 'callees' of each of those nodes, and create + aggregates for the children (which is in calleeList). + + This routine is not recursive and does not touch most of the tree but + it does call SubtractOutTrees which is recursive and may look at a lot + of the tree (although we try to minimize this) + + + + + Traverse 'treeCallee' and subtract out the inclusive time for any tree that matches 'idToExclude' from the node 'statsRet'. + This is needed in AggregateCallTrees because the same trees from the focus node are in the list to aggregate, but are also + in the subtree's in various places (and thus are counted twice). We solve this by walking this subtree (in this routine) + and subtracting out any nodes that match 'idToExclude'. + + As an optimization this routine also sets the m_recurision bit 'statsRet' if anywhere in 'treeCallee' we do find an id to + exclude. That way in a common case (where there is no instances of 'idToExclude') we don't have to actualy walk the + tree the second time (we simply know that there is no adjustment necessary. + + + + + An AggregateCallTree remembers all its samples by maintaining a list of call trees + that actually contain the samples that the Aggregate represents. m_trees hold this. + + + + + AggregateCallTreeNode can represent either a 'callers' tree or a 'callees' tree. For + the 'callers' tree case the node represented by the aggregate does NOT have same ID as + the tree in the m_trees list. Instead the aggregate is some node 'up the chain' toward + the caller. m_callerOffset keeps track of this (it is the same number for all elements + in m_trees). + + For callee nodes, this number is not needed. Thus we use a illegal value (-1) to + represent that fact that the node is a callee node rather than a caller node. + + + + + A Histogram is logically an array of floating point values. Often they + represent frequency, but it can be some other metric. The X axis can + represent different things (time, scenario). It is the HisogramContoller + which understands what the X axis is. Histograms know their HistogramController + but not the reverse. + + Often Histograms are sparse (most array elements are zero), so the represnetation + is designed to optimzed for this case (an array of non-zero index, value pairs). + + + + + Create a new histogram. Every histogram needs a controller but these controllers + can be shared among many histograms. + + + + + Add a sample to this histogram. + + The sample to add. + + + + Add an amount to a bucket in this histogram. + + The amount to add to the bucket. + The bucket to add to. + + + + Computes this = this + histogram * weight in place (this is updated). + + + + + The number of buckets in this histogram. + + + + + The that controls this histogram. + + + + + Get the metric contained in a bucket. + + The bucket to retrieve. + The metric contained in that bucket. + + + + Make a copy of this histogram. + + An independent copy of this histogram. + + + + A string representation (for debugging) + + + + + + Create a histogram that is a copy of another histogram. + + The histogram to copy. + + + + Implementes IEnumerable interface + + + + + Implementes IEnumerable interface + + + + + Get an IEnumerable that can be used to enumerate the metrics stored in the buckets of this Histogram. + + + + + The controller for this histogram. + + + + + A Histogram is conceputually an array of floating point values. A Histogram Controller + contains all the information besides the values themselves need to understand the array + of floating point value. There are alot of Histograms, however they all tend to share + the same histogram controller. Thus Histograms know their Histogram controller, but not + the reverse. + + Thus HistogramContoller is a abstract class (we have one for time, and one for scenarios). + + HistogramControllers are responsible for: + + - Adding a sample to the histogram for a node (see ) + - Converting a histogram to its string representation see () + - Managing the size and scale of histograms and their corresponding display strings + + + + + The scale factor for histograms controlled by this HistogramController. + + + + + The number of buckets in each histogram controlled by this HistogramController. + + + + + The number of characters in the display string for histograms controlled by this HistogramController. + Buckets are a logial concept, where CharacterCount is a visual concept (how many you can see on the + screen right now). + + + + + The CallTree managed by this HistogramController. + + + + + Force recalculation of the scale parameter. + + + + + Add a sample to the histogram for a node. + + The histogram to add this sample to. Must be controlled by this HistogramController. + The sample to add. + + Overriding classes are responsible for extracting the metric, scaling the metric, + determining the appropriate bucket or buckets, and adding the metric to the histogram using . + + + + + Gets human-readable information about a range of histogram characters. + + The start character index (inclusive). + The end character index (exclusive). + The histogram. + A string containing information about the contents of that character range. + + + + Convert a histogram into its display string. + + The histogram to convert to a string. + A string suitable for GUI display. + + + + A utility function that turns an array of floats into a ASCII character graph. + + + + + A utility function that turns an array of floats into a ASCII character graph. + + + + + Initialize a new HistogramController. + + The CallTree that this HistogramController controls. + + + + Calculate the scale factor for this histogram. + + The scale factor for this histogram. + + + + Calculates an average scale factor for a histogram. + + The root histogram to calculate against. + A scale factor that will normalize the maximum value to 200%. + + + + The scale parameter. 0.0 if uncalculated. + + + + + An enum representing a displayed histogram bucket (one character in a histogram string). + + + + + A HistogramCharacterIndex can be used to represent error conditions + + + + + A that groups histograms by scenarios. + + + + + Initialize a new ScenarioHistogramController. + + The CallTree to manage. + An ordered array of scenario IDs to display. + The total number of possible scenarios that can be supplied by the underlying StackSource. + This number might be larger than the highest number in . + The names of the scenarios (for UI use). + + + + Get a list of scenarios contained in a given bucket. + + The bucket to look up. + The scenarios contained in that bucket. + + + + Get a list of scenarios contained in a given bucket range. + + The start of the bucket range (inclusive). + The end of the bucket range (exclusive). + The scenarios contained in that range of buckets. + + + + Add a sample to a histogram controlled by this HistogramController. + + The histogram to add the sample to. + The sample to add. + + + + Get the human-readable name for a scenario. + + The ID of the scenario to look up. + The human-readable name for that scenario. + + + + Get the human-readable names for all scenarios contained in a range of histogram characters. + + The (inclusive) start index of the range. + The (exclusive) end index of the range. + The histogram. + A comma-separated list of scenario names contained in that range. + + + + Convert a histogram into a string suitable for UI display. + + The histogram to convert. + A string representing the histogram that is suitable for UI display. + + + + Calculate the scale factor for all histograms controlled by this ScenarioHistogramController. + + + In the current implementation, returns a scale that normalizes 100% to half of the maximum value at the root. + + + + + An array mapping each scenario to a bucket. + + + + + An array mapping each bucket to a list of scenarios. + + + + + An array mapping each scenario to its name. + + + + + A HistogramController holds all the information to understand the buckets of a histogram + (basically everything except the array of metrics itself. For time this is the + start and end time + + + + + Create a new TimeHistogramController. + + The CallTree to control with this controller. + The start time of the histogram. + The end time of the histogram. + + + + The start time of the histogram. + + + + + The end time of the histogram. + + + + + Gets the start time for the histogram bucket represented by a character. + + The index of the character to look up. + The start time of the bucket represented by the character. + + + + The duration of time represented by each bucket. + + + + + Implements HistogramController interface + + + + + Implements HistogramController interface + + + + + Implements HistogramController interface + + + + + Implements HistogramController interface + + + + + This structure provides a clean API for a lightweight recursion stack guard to prevent StackOverflow exceptions + We do ultimately do a stack-overflow to prevent infinite recursion, but it is now under our + control and much larger than you may get on any one thread stack. + + + + + For recursive methods that need to process deep stacks, this constant defines the limit for recursion within + a single thread. After reaching this limit, methods need to trampoline to a new thread before continuing to + recurse. + + + + + To prevent run-away recursion, fail after this depth (in this case 20*400 = 8K) + + + + + The amount of recursion we have currently done. + + + + + Gets the recursion guard for entering a recursive method. + + + This is equivalent to the default value. + + + + + Gets an updated recursion guard for recursing into a method. + + + + + Gets an updated recursion guard for continuing execution on a new thread. + + + + + Gets a value indicating whether the current operation has exceeded the recursion depth for a single thread, + and needs to continue executing on a new thread. + + + + + exports provided StackSource to a https://www.speedscope.app/ format + schema: https://www.speedscope.app/file-format-schema.json + + + + + we want to identify the thread for every sample to prevent from + overlaping of samples for the concurrent code so we group the samples by Threads + this method also sorts the samples by relative time (ascending) + + + + + this method fixes the metrics of the samples to make sure they don't overlap + it's very common that following samples overlap by a very small number like 0.0000000000156 + we can't allow for that to happen because the SpeedScope can't draw such samples + + + + + all the samples that we have are leafs (last sample in the call stack) + this method expands those samples to full information + it walks the stack up to the begining and adds a sample for every method on the stack + it's required to build full information + + + + + this method aggregates all the singular samples to continuous events + example: samples for Main taken at time 0.1 0.2 0.3 0.4 0.5 + are gonna be translated to Main start at 0.1 stop at 0.5 + + + + + this method checks if both samples do NOT belong to the same profile event + + + + + this method adds a new profile event for provided samples + it also make sure that a profile event does not open and close at the same time (would be ignored by SpeedScope) + + + + + this method orders the profile events in the order required by SpeedScope + it's just the order of drawing the time graph + + + + + writes pre-calculated data to SpeedScope format + + + + + A stack source is a logically a list of StackSourceSamples. Each sample has a metric and stack (hence the name StackSource) + The stacks are represented as indexes that the StackSourceStacks base class can resolve into frame names and stack chains. + The result is very efficient (no string processing) way of processing the conceptual list of stack samples. + + + + + Call 'callback' on every sample in the StackSource. Will be done linearly and only + one callback will be active simultaneously. + + + + + Call 'callback' on every sample in the StackSource. Will be done linearly and only + one callback will be active simultaneously. + + + + + If this is overridden to return true, then during the 'Foeach' callback you can save references + to the samples you are given because they will not be overridden by the stack source. If this is + false you must make a copy of the sample if you with to remember it. + + + + + Also called 'callback' on every sample in the StackSource however there may be more than + one callback running simultaneously. Thus 'callback' must be thread-safe and the order + of the samples should not matter. If desiredParallelism == 0 (the default) then the + implementation will choose a good value of parallelism. + + + + + If this stack source is a source that simply groups another source, get the base source. It will return + itself if there is no base source. + + + + + If this source supports fetching the samples by index, this is how you get it. Like ForEach the sample that + is returned is not allowed to be modified. Also the returned sample will become invalid the next time GetSampleIndex + is called (we reuse the StackSourceSample on each call) + + + + + Returns the limit on stack samples indexes (all index are strictly less than this). Returns 0 if unknown. + + + + + Returns a time which is greater than or equal the timestamp of any sample in the StackSource. Returns 0 if unknown. + + + + + In addition to Time and Metric a sample can have a Scneario number associated with it. ScenarioCount + returns the number of such scnearios. Returning 0 implies no scenario support. + + + + + StackSources can optionally support a sampling rate. If the source supports it it will return + non-null for the current sampling rate (1 if it is doing nothing). Sampling is a way of speeding + things up. If you sample at a rate of 10, it means that only one out of every 10 samples is actually + produced by 'ForEach'. Note that it is expected that when the sampling rate is set the + source will correspondingly adjust the CountMultiplier, so that the total will look like no sampling + is occuring + + + + + If each 'callstack' is really a node in a graph (like MemoryGraphStackSource) + Then return true. If this returns true 'GetRefs' works. + + + + + Only used if IsGraphSource==true. If 'direction' is 'From' Calls 'callback' for node that is referred to FROM nodeIndex. + If 'direction' is 'To' then it calls 'callback' for every node that refers TO nodeIndex. This API returns references + that are not necessarily a tree (they can for DAGs or have cycles). + + + + + Dump the stack source to a file as XML. Used for debugging. + + + + + Dump the stack source to a TextWriter as XML. Used for debugging. + + + + + RefDirection represents the direction of the references in a heap graph. + + + + + Indicates that you are interested in referneces FROM the node of interest + + + + + Indicates that you are interested in referneces TO the node of interest + + + + + Samples have stacks (lists of frames, each frame contains a name) associated with them. This interface allows you to get + at this information. We don't use normal objects to represent these but rather give each stack (and frame) a unique + (dense) index. This has a number of advantages over using objects to represent the stack. + + * Indexes are very serialization friendly, and this data will be presisted. Thus indexes are the natural form for data on disk. + * It allows the data to be read from the serialized format (disk) lazily in a very straightfoward fashion, keeping only the + hottest elements in memory. + * Users of this API can associate additional data with the call stacks or frames trivially and efficiently simply by + having an array indexed by the stack or frame index. + + So effectively a StackSourceStacks is simply a set of 'Get' methods that allow you to look up information given a Stack or + frame index. + + + + + Given a call stack, return the call stack of the caller. This function can return StackSourceCallStackIndex.Discard + which means that this sample should be discarded. + + + + + For efficiency, m_frames are assumed have a integer ID instead of a string name that + is unique to the frame. Note that it is expected that GetFrameIndex(x) == GetFrameId(y) + then GetFrameName(x) == GetFrameName(y). The converse does NOT have to be true (you + can reused the same name for distinct m_frames, however this can be confusing to your + users, so be careful. + + + + + FilterStackSources can combine more than one frame into a given frame. It is useful to know + how many times this happened. Returning 0 means no combining happened. This metric does + not include grouping, but only folding. + + + + + Get the frame name from the FrameIndex. If 'verboseName' is true then full module path is included. + + + + + all StackSourceCallStackIndex are guaranteed to be less than this. Allocate an array of this size to associate side information + + + + + all StackSourceFrameIndex are guaranteed to be less than this. Allocate an array of this size to associate side information + + + + + True if it only has managed code stacks. Otherwise false. + + + + + Computes the depth (number of callers), associated with callStackIndex. This routine is O(n) and mostly useful for debugging. + + + + + Returns an XML string representation of a 'sample'. For debugging. + + + + + Returns an XML string representation of a 'callStackIndex'. For debugging. + + + + + StackSourceSample represents a single sample that has a stack. It has a number of predefined data items associate with it + including a stack, a metric and a time as well as other optional fields. Note that all its properties are read-write. + It is basically a named tuple. + + StackSource.ProductSamples push these. + + In general StackSourceSample are NOT immutable but expected to be overwritted frequently. Thus you need to copy + the sample if you want to keep a refernece to it. + + + + + The Stack associated with the sample + + + + + The metric (cost) associated with the sample + + + + + If the source supports fetching samples by some ID, then SampleIndex returns this ID for the sample and + GetSampleByIndex is the API that converts this index into a sample again. + + + + + The time associated with the sample. (can be left 0) + + + + + Normally the count of a sample is 1, however when you take a statistical sample, and you also have + other constraints (like you do when you are going a sample of heap memory), you may need to have the + count adjusted to something else. + + + + + A scenario is simply a integer that represents some group the sample belongs to. + + + + + Returns an XML string representing the sample + + + + + Returns an XML string representing the sample, howevever this one can actually expand the stack because it is given the source + + + + + Create a StackSourceSample which is associated with 'source'. + + + + + Copy a StackSourceSample from 'template' + + + + + + Identifies a particular sample from the sample source, it allows 3rd parties to attach additional + information to the sample by creating an array indexed by sampleIndex. + + + + + Returned when no appropriate Sample exists. + + + + + An opaque handle that are 1-1 with a complete call stack + + + + + + The first real call stack index (after the pseudo-ones before this) + + + + + Returned when no appropriate CallStack exists. (Top of stack) + + + + + Identifies a particular frame within a stack It represents a particular instruction pointer (IP) location + in the code or a group of such locations. + + + + + Pseduo-node representing the root of all stacks + + + + + Pseduo-frame that represents the caller of all broken stacks. + + + + + Unknown what to do (Must be before the 'special ones below') // Non negative represents normal m_frames (e.g. names of methods) + + + + + Profiling overhead (rundown) + + + + + The first real call stack index (after the pseudo-ones before this) + + + + + Should not happen (uninitialized) (also means completely folded away) + + + + + Sample has been filtered out (useful for filtering stack sources) + + + + + A StackSourceModuleIndex uniquely identifies a module to the stack source. + + + + + Start is where 'ordinary' module indexes start. + + + + + Invalid is a module index that is never used and can be used to signal error conditions. + + + + + This stack source takes another and copies out all its events. This allows you to 'replay' the source + efficiently when the original source only does this inefficiently. + + + + + Create a CopyStackSource that has no samples in it. It can never have samples so it is only useful as a placeholder. + + + + + Create a CopyStackSource that you can add samples which use indexes that 'sourceStacks' can decode. All samples + added to the stack source must only refer to this StackSourceStacks + + + + + Add a sample to stack source. it will clone 'sample' so sample can be overwritten after this method returns. + It is an error if 'sample' does not used the StackSourceStacks passed to the CopyStackSource at construction. + + + + + Create a clone of the given stack soruce. + + + + + + + Returns the StackSourceStacks that can interpret indexes for this stack source. + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Like CopyStackSource InternStackSource copies the samples. however unlike CopyStackSource + InternStackSource copies all the information in the stacks too (mapping stack indexes to names) + Thus it never refers to the original source again). It also interns the stacks making for + an efficient representation of the data. This is useful when the original source is expensive + to iterate over. + + + + + Compute the difference between two sources of stacks. + + + + + Compute only the delta of source from the baseline. This variation allows you to specify + the unfiltered names (the sourceStacks and baselineStacks) but otherwise keep the filtering. + + + + + Create a new stack source that can create things out of nothing. + + + + + Create a new InternStackSource + + + + + Returns the Interner, which is the class that holds the name->index mappings that that every + name has a unique index. + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + InternFullStackFromSource will take a call stack 'baseCallStackIndex' from the source 'source' and completely copy it into + the intern stack source (interning along the way of course). Logically baseCallStackIndex has NOTHING to do with any of the + call stack indexes in the intern stack source. + + + + + StackSourceInterner is a helper class that knows how to intern module, frame and call stacks. + + + + + Create a new StackSourceInterner. Optionally supply estimates on how many items you need and where the frame, callstack and module indexes start. + + + + + As an optimization, if you are done adding new nodes, then you can call this routine can abandon + some tables only needed during the interning phase. + + + + + The CallStackStartIndex value passed to the constructor + + + + + The FrameStartIndex value passed to the constructor + + + + + Given a StackSourceCallStackIndex return the StackSourceCallStackIndex of the caller + + + + + Given a StackSourceCallStackIndex return the StackSourceFrameIndex for the Frame associated + with the top call stack + + + + + Get a name from a frame index. If the frame index is a + + + + + Given a StackSourceFrameIndex return the StackSourceModuleIndex associated with the frame + + + + + + + If you intern frames as derived frames, when GetFrameName is called the interner needs to know + how to look up the derived frame from its index. This is the function that is called. + + It is called with the frame index and a boolean which indicates whether the full path of the module + should be specified, and returns the frame string. + + + + + Lookup or create a StackSourceModuleIndex for moduleName + + + + + Lookup or create a StackSourceFrameIndex for frame with the name frameName and the module identified by moduleIndex + + + + + You can also create frames out of other frames using this method. Given an existing frame, and + a suffix 'frameSuffix' + + + + + Lookup or create a StackSourceCallStackIndex for a call stack with the frame identified frameIndex and caller identified by callerIndex + + + + + The current number of unique frames that have been interned so far + + + + + The current number of unique call stacks that have been interned so far + + + + + A specialized hash table for interning. + It loosely follows the implementation of but with + several key allowances for known usage patterns: + 1. We don't store the hashcode on each entry on the assumption that values can be compared + as quickly as recomputing hash codes. The downside to that is that the hash codes must + be recomputed whenever the map is resized, but that is very cheap. + 2. We supply a single method (instead of a TryGetValue + followed by an Add) so that a hashcode computation is saved in the case of a "miss". + 3. We don't support removal. This means we don't need to keep track of a free list and neither + do we need sentinel values. This also allows us to use all 32 bits of the hash-code (where + uses only 31 bits, reserving -1 to indicate a freed + entry. The only sentinel value is in the array to indicate a free + bucket. + 4. We return an index (of the interned item) to the caller which can be used for constant-time + look-up in the table via . + 5. To free up memory, the caller can call . The entries themselves + are stored separately from the indexing parts of the table so that the latter can be dropped + easily. + + + + + Construct the intern map + + The estimated capacity of the map. + + + + Count of interned values. + + + + + Access an element by index. + + The zero-based index of the desired entry. + The entry at the requested index. + For performance, in Release mode we do no range checking on , so it is possible to + access an entry beyond but prior to the maximum capacity of the array. + was less than zero or greater than the capacity. + + + + Intern a value. If the same value has been seen before + then this returns the index of the previously seen entry. If not, a new entry + is added and this returns the index of the newly added entry. + + The candidate value. + The index of the interned entry. + This routine was called after calling . + + + + As an optimization, if you are done calling , then you can call this + to free up some memory. + + After calling this, you can still call . However, if you try to + call you will get a . + + + + Elements representing the structure of the hash table. The structure is + a collection of singly linked lists, one list per 'bucket' where a + bucket number is selected by taking the hash code of an incoming item + and mapping it onto the array (see ). + + + Caution: For a given , and + are UNRELATED to each other. Logically, you can + think of as being part of a value in the + table. (We don't actually do that in order to + support efficiently.) + To find the next element in the linked list, you should NOT simply + look at . Instead, you should first look up the + in the array indexed by + and look at the field of that. + + + + + Index into the array of the head item in the linked list or + -1 to indicate an empty bucket. + + + + + Index into the array of the next item in the linked list or + -1 to indicate that this is the last item. + + + + + TraceEventStackSource is an implementation of a StackSource for ETW information (TraceLog) + It takes a TraceEvents (which is a list of TraceEvents you get get from a TraceLog) and + implements that StackSource protocol for them. (thus any code needing a StackSource + can then work on it. + + The key to the implementation is how StackSourceFrameIndex and StackSourceCallStackIndex + (part of the StackSource protocol) are mapped to the Indexes in TraceLog. Here is + the mapping. + + TraceEventStackSource create the following meaning for the StackSourceCallStackIndex + + * The call stacks ID consists of the following ranges concatenated together. + * a small set of fixed Pseudo stacks (Start marks the end of these) + * CallStackIndex + * ThreadIndex + * ProcessIndex + * BrokenStacks (One per thread) + * Stacks for CPU samples without explicit stacks (we make 1 element stacks out of them) + + TraceEventStackSource create the following meaning for the StackSourceFrameIndex + + The frame ID consists of the following ranges concatenated together. + * a small fixed number of Pseudo frame (Broken, and Unknown) + * MaxCodeAddressIndex - something with a TraceCodeAddress. + * ThreadIndex - ETW stacks don't have a thread or process node, so we add them. + * ProcessIndex + + + + + Creates a new TraceEventStackSource given a list of events 'events' from a TraceLog + + + + + + Returns the TraceLog file that is associated with this stack source. + + + + + Normally addresses without symbolic names are listed as ?, however sometimes it is useful + to see the actual address as a hexadecimal number. Setting this will do that. + + + + + Looks up symbols for all modules that have an inclusive count >= minCount. + stackSource, if given, can be used to be the filter. If null, 'this' is used. + If stackSource is given, it needs to use the same indexes for frames as 'this'. + shouldLoadSymbols, if given, can be used to filter the modules. + + + + + Given a frame index, return the corresponding code address for it. This is useful for looking up line number information. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Returns a list of modules for the stack 'stackIdx'. It also updates the interning table stackModuleLists, so + that the entry cooresponding to stackIdx remembers the answer. This can speed up processing alot since many + stacks have the same prefixes to root. + + + + + A ModuleList is a linked list of modules. It is only used in GetModulesForStack and LookupWarmSymbols + + + + + This maps pseudo-stacks to their index (thus it is the inverse of m_pseudoStack; + + + + + Given a thread and a call stack that does not have a stack, make up a pseudo stack for it consisting of the code address, + the broken node, the thread and process. Will return -1 if it can't allocate another Pseudo-stack. + + + + + Like a TraceEventStackSource a MutableTraceEventStackSource allows you incorporate the stacks associated with + a TraceEvent as a sample in the StackSource. However in addition it allows you to create new frames for these + stacks on the fly as well as add samples that did not exist in the original TraceEvent stream. This gives you + a lot of flexibility to add additional data to the original stream of TraceEvents. + + Like TraceEventStackSource MutableTraceEventStackSource supports the GetFrameCodeAddress() method that allows + you to map from the StackSourceFrameIndex back its TraceLog code address (that lets you get at the source code and + line number for that frame). + + + + + Create a new MutableTraceEventStackSource that can represent stacks comming from any events in the given TraceLog with a stack. + You use the 'AddSample' and 'DoneAddingSamples' to specify exactly which stacks you want in your source. + + + + + After creating a MultableTraceEventStackSource, you add the samples you want using this AddSample API (you can reuse 'sample' + used as an argument to this routine. It makes a copy. The samples do NOT need to be added in time order (the MultableTraceEventStackSource + will sort them). When you done DoneAddingSamples must be called before using the + the MutableTraceEventStackSource as a stack source. + + + + + After calling 'AddSample' to add the samples that should belong to the source, DoneAddingSamples() should be called to + to complete the construction of the stack source. Only then can the reading API associated with the stack source be called. + + + + + The Interner is the class that allows you to make new indexes out of strings and other bits. + + + + + Returns a StackSourceCallStackIndex representing just one entry that represents the process 'process' + + + + + Returns a StackSourceCallStackIndex representing just two entries that represent 'thread' which has a parent of its process. + + + + + Returns a StackSourceCallStackIndex representing the call stack from the TraceLog represented by the CallStackIndex 'callStackIndex'. + If that stack is invalid, use 'thread' to at least return a call stack for the thread. + + + + + Returns a StackSourceCallStackIndex representing the call stack from the TraceLog represented by the CallStackIndex 'callStackIndex'. + Use the TraceEvent 'data' to find the stack if callStackIndex is invalid. + TODO data should be removed (or callstack derived from it) + + + + + A very simple IDictionary-like interface for remembering values in GetCallStack() + + + + + Fetches an value given a key + + + + + Sets a key-value pair + + + + + Find the StackSourceCallStackIndex for the TraceEvent call stack index 'callStackIndex' which has a top of its + stack (above the stack, where the thread and process would normally go) as 'top'. If callStackMap is non-null + it is used as an interning table for CallStackIndex -> StackSourceCallStackIndex. This can speed up the + transformation dramatically. It will still work if it is null. + + + + + + Create a frame name from a TraceLog code address. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + private + + + + + private + + + + + TraceEventSource is an abstract base class that represents the output of a ETW session (e.g. a ETL file + or ETLX file or a real time stream). This base class is NOT responsible for actually processing + the events, but contains methods for properties associated with the session + like its start and end time, filename, and characteristics of the machine it was collected on. + This class has two main subclasses: + * which implements a 'push' (callback) model and is the only mode for ETL files. + ETWTraceEventSource is the most interesting subclass of TraceEventDispatcher. + * see TraceLog which implements both a 'push' (callback) as well as pull (foreach) model but only works on ETLX files. + This is the end. + The normal user pattern is to create a TraceEventSource, create TraceEventParsers attached to the TraceEventSource, and then subscribe + event callbacks using the TraceEventParsers + + + + + For convenience, we provide a property returns a ClrTraceEventParser that knows + how to parse all the Common Language Runtime (CLR .NET) events into callbacks. + + + + + For convenience, we provide a property returns a KernelTraceEventParser that knows + how to parse all the Kernel events into callbacks. + + + + + For convenience, we provide a property returns a DynamicTraceEventParser that knows + how to parse all event providers that dynamically log their schemas into the event streams. + In particular, it knows how to parse any events from a System.Diagnostics.Tracing.EventSources. + + Note that the DynamicTraceEventParser has subsumed the functionality of RegisteredTraceEventParser + so any registered providers are also looked up here. + + + + + For convenience, we provide a property returns a RegisteredTraceEventParser that knows + how to parse all providers that are registered with the operating system. + + Because the DynamicTraceEventParser has will parse all providers that that RegisteredTraceEventParser + will parse, this function is obsolete, you should use Dynamic instead. + + + + + The time when session started logging. + + + + + The time that the session stopped logging. + + + + + The Session End time expressed as milliseconds from the start of the session + + + + + The difference between SessionEndTime and SessionStartTime; + + + + + The size of the trace, if it is known. Will return 0 if it is not known. + + + + + Returns the size of a pointer on the machine where events were collected (4 for 32 bit or 8 for 64 bit) + + + + + The number of events that were dropped (e.g. because the incoming event rate was too fast) + + + + + The number of processors on the machine doing the logging. + + + + + Cpu speed of the machine doing the logging. + + + + + The version of the windows operating system on the machine doing the logging. + + + + + Returns true if this is a real time session. + + + + + Time based threshold for how long data should be retained + by accumulates that are processing this TraceEventSource. + A value of 0, the default, indicates an infinite accumulation. + + + + + Check if a DataLifetime model is enabled + + True - lifetime tracking is enabled + False - lifetime tracking is not enabled + + + + Closes any files and cleans up any resources associated with this TraceEventSource + + + + + TraceEventSource supports attaching arbitrary user data to the source. This property returns a key-value bag of these attached values. + + One convention that has been established is that TraceEventParsers that need additional state to parse their events should + store them in UserData under the key 'parsers\(ParserName)' + + + + + + Dispose pattern + + + + + This is the high frequency tick clock on the processor (what QueryPerformanceCounter uses). + You should not need + + + + + Converts the Query Performance Counter (QPC) ticks to a number of milliseconds from the start of the trace. + + + + + Converts a Relative MSec time to the Query Performance Counter (QPC) ticks + + + + + Converts a DateTime to the Query Performance Counter (QPC) ticks + + + + + Converts the Query Performance Counter (QPC) ticks to a DateTime + + + + + Some events (like HardFault) do not have a thread ID or a process ID, but they MIGHT have a Stack + If they do try to get the ThreadID for the event from that. Return -1 if not successful. + This is intended to be overridden by the TraceLog class that has this additional information. + + + + + TraceEvent an abstract class represents the data from one event in the stream of events in a TraceEventSource. + The TraceEvent class has all the properties of an event that are common to all ETW events, including TimeStamp + ProviderGuid, ProcessID etc. Subclasses of TraceEvent then extend this abstract class to include properties + specific to a particular payload. + + An important architectural point is that TraceEvent classes are aggressively reused by default. The TraceEvent that is + passed to any TraceEventParser callback or in a foreach is ONLY valid for the duration for that callback (or one + iteration of the foreach). If you need save a copy of the event data, you must call the Clone() method to make + a copy. The IObservable interfaces (TraceEventParser.Observe* methods) however implicitly call Clone() so you + do not have to call Clone() when processing with IObservables (but these are slower). + + + + + + The GUID that uniquely identifies the Provider for this event. This can return Guid.Empty for classic (Pre-VISTA) ETW providers. + + + + + The name of the provider associated with the event. It may be of the form Provider(GUID) or UnknownProvider in some cases but is never null. + + + + + A name for the event. This is simply the concatenation of the task and opcode names (separated by a /). If the + event has no opcode, then the event name is just the task name. + + + + + Returns the provider-specific integer value that uniquely identifies event within the scope of + the provider. (Returns 0 for classic (Pre-VISTA) ETW providers). + + + + + Events for a given provider can be given a group identifier (integer) called a Task that indicates the + broad area within the provider that the event pertains to (for example the Kernel provider has + Tasks for Process, Threads, etc). + + + + + The human readable name for the event's task (group of related events) (eg. process, thread, + image, GC, ...). May return a string Task(GUID) or Task(TASK_NUM) if no good symbolic name is + available. It never returns null. + + + + + An opcode is a numeric identifier (integer) that identifies the particular event within the group of events + identified by the event's task. Often events have opcode 'Info' (0), which is the default. This value + is interpreted as having no-opcode (the task is sufficient to identify the event). + + Generally the most useful opcodes are the Start and Stop opcodes which are used to indicate the beginning and the + end of a interval of time. Many tools will match up start and stop opcodes automatically and compute durations. + + + + + + Returns the human-readable string name for the Opcode property. + + + + + The verbosity of the event (Fatal, Error, ..., Info, Verbose) + + + + + The version number for this event. The only compatible change to an event is to add new properties at the end. + When this is done the version numbers is incremented. + + + + + ETW Event providers can specify a 64 bit bitfield called 'keywords' that define provider-specific groups of + events which can be enabled and disabled independently. + Each event is given a keywords mask that identifies which groups the event belongs to. This property returns this mask. + + + + + A Channel is a identifier (integer) that defines an 'audience' for the event (admin, operational, ...). + Channels are only used for Windows Event Log integration. + + + + + The time of the event. You may find TimeStampRelativeMSec more convenient. + + + + + Returns a double representing the number of milliseconds since the beginning of the session. + + + + + The thread ID for the thread that logged the event + This field may return -1 for some events when the thread ID is not known. + + + + + The process ID of the process which logged the event. + This field may return -1 for some events when the process ID is not known. + + + + + Returns a short name for the process. This the image file name (without the path or extension), + or if that is not present, then the string 'Process(XXXX)' + + + + + The processor Number (from 0 to TraceEventSource.NumberOfProcessors) that logged this event. + event. + + + + + Get the size of a pointer associated with process that logged the event (thus it is 4 for a 32 bit process). + + + + + Conceptually every ETW event can be given a ActivityID (GUID) that uniquely identifies the logical + work being carried out (the activity). This property returns this GUID. Can return Guid.Empty + if the thread logging the event has no activity ID associated with it. + + + + + ETW supports the ability to take events with another GUID called the related activity that is either + causes or is caused by the current activity. This property returns that GUID (or Guid.Empty if the + event has not related activity. + + + + + Event Providers can define a 'message' for each event that are meant for human consumption. + FormattedMessage returns this string with the values of the payload filled in at the appropriate places. + It will return null if the event provider did not define a 'message' for this event + + + + + Creates and returns the value of the 'message' for the event with payload values substituted. + Payload values are formatted using the given formatProvider. + + + + + An EventIndex is a integer that is guaranteed to be unique for this event over the entire log. Its + primary purpose is to act as a key that allows side tables to be built up that allow value added + processing to 'attach' additional data to this particular event unambiguously. + This property is only set for ETLX file. For ETL or real time streams it returns 0 + EventIndex is currently a 4 byte quantity. This does limit this property to 4Gig of events + + + + + The TraceEventSource associated with this event. + + + + + Returns true if this event is from a Classic (Pre-VISTA) provider + + + + + Returns the names of all the manifest declared field names for the event. May be empty if the manifest is not available. + + + + + Given an index from 0 to PayloadNames.Length-1, return the value for that payload item as an object (boxed if necessary). + + + + + PayloadString is like PayloadValue(index).ToString(), however it can do a better job in some cases. In particular + if the payload is a enumeration or a bitfield and the manifest defined the enumeration values, then it will print the string name + of the enumeration value instead of the integer value. + + + + + Returns the index in 'PayloadNames for field 'propertyName'. Returns something less than 0 if not found. + + + + + PayloadByName fetches the value of a payload property by the name of the property. + It will return null if propertyName is not found. + This method is not intended to be used in performance critical code. + + + + + PayloadStringByName functions the same as PayloadByName, but uses PayloadString instead of PayloadValue. + It will return null if propertyName is not found. + This method is not intended to be used in performance critical code. + + + + + The size of the event-specific data payload. (see EventData) + Normally this property is not used because some TraceEventParser has built a subclass of + TraceEvent that parses the payload + + + + + Returns an array of bytes representing the event-specific payload associated with the event. + Normally this method is not used because some TraceEventParser has built a subclass of + TraceEvent that parses the payload + + + + + Gets the event data and puts it in 'targetBuffer' at 'targetStartIndex' and returns the resulting buffer. + If 'targetBuffer is null, it will allocate a buffer of the correct size. + Normally this method is not used because some TraceEventParser has built a subclass of + TraceEvent that parses the payload + + + + + The events passed to the callback functions only last as long as the callback, so if you need to + keep the information around after that you need to copy it. This method makes that copy. + This method is more expensive than copy out all the event data from the TraceEvent instance + to a type of your construction. + + + + + Pretty print the event. It uses XML syntax.. + + + + + Pretty print the event using XML syntax, formatting data using the supplied IFormatProvider + + + + + Write an XML representation to the stringBuilder sb and return it. + + + + + Writes an XML representation of the event to a StringBuilder sb, formatting data using the passed format provider. + Returns the StringBuilder. + + + + + Dumps a very verbose description of the event, including a dump of they payload bytes. It is in + XML format. This is very useful in debugging (put it in a watch window) when parsers are not + interpreting payloads properly. + + + + + EventTypeUserData is a field users get to use to attach their own data on a per-event-type basis. + + + + + Returns the raw IntPtr pointer to the data blob associated with the event. This is the way the + subclasses of TraceEvent get at the data to display it in a efficient (but unsafe) manner. + + + + + Create a template with the given event meta-data. Used by TraceParserGen. + + + + + Skip UTF8 string starting at 'offset' bytes into the payload blob. + + Offset just after the string + + + + Skip Unicode string starting at 'offset' bytes into the payload blob. + + Offset just after the string + + + + Skip 'stringCount' Unicode strings starting at 'offset' bytes into the payload blob. + + Offset just after the last string + + + + Skip a Security ID (SID) starting at 'offset' bytes into the payload blob. + + Offset just after the Security ID + + + + Trivial helper that allows you to get the Offset of a field independent of 32 vs 64 bit pointer size. + + The Offset as it would be on a 32 bit system + The number of pointer-sized fields that came before this field. + + + + + Computes the size of 'numPointers' pointers on the machine where the event was collected. + + + + + Given an Offset to a null terminated ASCII string in an event blob, return the string that is + held there. + + + + + Returns the string represented by a fixed length ASCII string starting at 'offset' of length 'charCount' + + + + + Given an Offset to a fixed sized string at 'offset', whose buffer size is 'charCount' + Returns the string value. A null in the string will terminate the string before the + end of the buffer. + + + + + Returns the encoding of a Version 6 IP address that has been serialized at 'offset' in the payload bytes. + + + + + Returns the GUID serialized at 'offset' in the payload bytes. + + + + + Get the DateTime that serialized (as a windows FILETIME) at 'offset' in the payload bytes. + + + + + Given an Offset to a null terminated Unicode string in an payload bytes, return the string that is + held there. + + + + + Give an offset to a byte array of size 'size' in the payload bytes, return a byte[] that contains + those bytes. + + + + + Returns a byte value that was serialized at 'offset' in the payload bytes + + + + + Returns a short value that was serialized at 'offset' in the payload bytes + + + + + Returns an int value that was serialized at 'offset' in the payload bytes + + + + + Returns a long value that was serialized at 'offset' in the payload bytes + + + + + Get something that is machine word sized for the provider that collected the data, but is an + integer (and not an address) + + + + + Gets something that is pointer sized for the provider that collected the data. + + + + + Returns an int float (single) that was serialized at 'offset' in the payload bytes + + + + + Returns an int double precision floating point value that was serialized at 'offset' in the payload bytes + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Prints a standard prefix for a event (includes the time of the event, the process ID and the + thread ID. + + + + + Because we want the ThreadID to be the ID of the CREATED thread, and the stack + associated with the event is the parentThreadID + + + + + Returns (or sets) the delegate associated with this event. + + + + + If this TraceEvent belongs to a parser that needs state, then this callback will set the state. + Parsers with state are reasonably rare, the main examples are KernelTraceEventParser and ClrTraceEventParser. + + + + + Returns the Timestamp for the event using Query Performance Counter (QPC) ticks. + The start time for the QPC tick counter is arbitrary and the units also vary. + + + + + A standard way for events to are that certain addresses are addresses in code and ideally have + symbolic information associated with them. Returns true if successful. + + + + + Was this written with the windows EventWriteString API? (see also EventDataAsString) + + + + + Used for binary searching of event IDs. Abstracts the size (currently a int, could go to long) + + + + + Returns true if the two traceEvents have the same identity. + + + + + Normally TraceEvent does not have unmanaged data, but if you call 'Clone' it will. + + + + + For debugging. dumps an array. If you specify a size of 0 (the default) it dumps the whole array. + + + + + If the event data looks like a unicode string, then return it. This is heuristic. (See also IsEventWriteString) + + + + + + Each TraceEvent items knows where it should Dispatch to. + ETWTraceEventSource.Dispatch calls this function to go to the right placed. By default we + do nothing. Typically a subclass just dispatches to another callback that passes itself to a + type-specific event callback. + + + + + This is a DEBUG-ONLY routine that allows a routine to do consistency checking in a debug build. + + + + + Validate that the events is not trash. + + + + + TraceEvent knows where to dispatch to. To support many subscriptions to the same event we chain + them. + + + + + The array of names for each property in the payload (in order). + + + + + Individual event providers can supply many different types of events. These are distinguished from each + other by a TraceEventID, which is just a 16 bit number. Its meaning is provider-specific. + + + + + Illegal is a EventID that is not used by a normal event. + + + + + Providers can define different audiences or Channels for an event (eg Admin, Developer ...). + It is only used for Windows Event log support. + + + + + The default channel. + + + + + There are certain classes of events (like start and stop) which are common across a broad variety of + event providers for which it is useful to treat uniformly (for example, determining the elapsed time + between a start and stop event). To facilitate this, event can have opcode which defines these + common operations. Below are the standard ones but providers can define additional ones. + + + + + Generic opcode that does not have specific semantics associated with it. + + + + + The entity (process, thread, ...) is starting + + + + + The entity (process, thread, ...) is stoping (ending) + + + + + The entity (process, thread, ...) did not terminate before data collection ended, so indicate + this at data collection termination time. + + + + + The entity (process, thread, ...) did not terminate before data collection ended, so indicate + this at data collection termination time. This is mostly for 'flight recorder' scenarios where + you only have the 'tail' of the data and would like to know about everything that existed. + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Indicates to a provider whether verbose events should be logged. + + + + + Always log the event (It also can mean that the provider decides the verbosity) You probably should not use it.... + + + + + Events that indicate critical conditions + + + + + Events that indicate error conditions + + + + + Events that indicate warning conditions + + + + + Events that indicate information + + + + + Events that verbose information + + + + + ETW defines the concept of a Keyword, which is a 64 bit bitfield. Each bit in the bitfield + represents some provider defined 'area' that is useful for filtering. When processing the events, it + is then possible to filter based on whether various bits in the bitfield are set. There are some + standard keywords, but most are provider specific. + + + + + No event groups (keywords) selected + + + + + All event groups (keywords) selected + + + + + Tasks are groups of related events for a given provider (for example Process, or Thread, Kernel Provider). + They are defined by the provider. + + + + + If you don't explicitly choose a task you get the default + + + + + EventIdex is a unsigned integer that is unique to a particular event. EventIndex is guaranteed to be + unique over the whole log. It is only used by ETLX files. + + Currently the event ID simply the index in the log file of the event. We don't however guarantee ordering. + In the future we may add new events to the log and given them IDs 'at the end' even if the events are not + at the end chronologically. + + + EventIndex is a 32 bit number limits it to 4Gig events in an ETLX file. + + + + + + Invalid is an EventIndex that will not be used by a normal event. + + + + + TraceEventSource has two roles. The first is the obvious one of providing some properties + like 'SessionStartTime' for clients. The other role is provide an interface for TraceEventParsers + to 'hook' to so that events can be decoded. ITraceParserServices is the API service for this + second role. It provides the methods that parsers register templates for subclasses of + the TraceEvent class that know how to parse particular events. + + + + + RegisterEventTemplate is the mechanism a particular event payload description 'template' + (a subclass of TraceEvent) is injected into the event processing stream. Once registered, an + event is 'parsed' simply by setting the 'rawData' field in the event. It is up to the template + then to take this raw data an present it in a useful way to the user (via properties). Note that + parsing is thus 'lazy' in no processing of the raw data is not done at event dispatch time but + only when the properties of an event are accessed. + + Ownership of the template transfers when this call is made. The source will modify this and + assumes it has exclusive use (thus you should clone the template if necessary). + + Another important aspect is that templates are reused by TraceEventSource aggressively. The + expectation is that no memory needs to be allocated during a normal dispatch + + + + + + UnregisterEventTemplate undoes the action of RegisterEventTemplate. Logically you would + pass the template to unregister, but typically you don't have that at unregistration time. + To avoid forcing clients to remember the templates they registered, UnregisterEventTemplate + takes three things that will uniquely identify the template to unregister. These are + the eventID, and provider ID and the Action (callback) for the template. + + + + + It is expected that when a subclass of TraceEventParser is created, it calls this + method on the source. This allows the source to do any Parser-specific initialization. + + + + + Indicates that this callback should be called on any unhandled event. The callback + returns true if the lookup should be retried after calling this (that is there is + the unhandled event was found). + + + + + Looks if any provider has registered an event with task with 'taskGuid'. Will return null if + there is no registered event. + + + + + Looks if any provider has registered with the given GUID OR has registered any task that matches + the GUID. Will return null if there is no registered event. + + + + + TraceEventParser Represents a class that knows how to decode particular set of events (typically + all the events of a single ETW provider). It is expected that subclasses of TraceEventParser + have a constructor that takes a TraceEventSource as an argument that 'attaches' th parser + to the TraceEventSource. TraceEventParsers break into two groups. + + * Those that work on a single provider, and thus the provider name is implicit in th parser. This is the common case. + The AddCallbackForEvent* methods are meant to be used for these TraceEventParsers + + * Those that work on multiple providers. There are only a handful of these (DynamicTraceEventParser, ...). + The AddCallbackForProviderEvent* methods which take 'Provider' parameters are meant to be used for these TraceEventParsers + + + In addition to the AddCallback* methods on TraceEventParser, there are also Observe* extension methods that + provide callbacks using the IObservable style. + + + + + + Get the source this TraceEventParser is attached to. + + + + + Subscribe to all the events this parser can parse. It is shorthand for AddCallback{TraceEvent}(value)/RemoveCallback(value) + + + + + A shortcut that adds 'callback' in the provider associated with this parser (ProvderName) and an event name 'eventName'. 'eventName' + can be null in which case any event that matches 'Action{T}' will call the callback. + 'eventName is of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + The callback alone is used as the subscription id for unregistration, so the callback delegate should be unique (by delegate comparison) + + + + + + Causes 'callback' to be called for any event in the provider associated with this parser (ProviderName) whose type is compatible with T and + whose eventName will pass 'eventNameFilter'. + + + + + Causes 'callback' to be called for any event in the provider associated with this parser (ProviderName) whose type is compatible with T and + whose eventName will pass 'eventNameFilter'. The eventNameFilter parameter can be null, in which case all events that are compatible + with T will be selected. + + eventNames passed to the filer are of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + + + + Causes 'callback' to be called for any event in the provider associated with this parser (ProviderName) whose type is compatible with T and + whose eventName will pass 'eventNameFilter'. The eventNameFilter parameter can be null, in which case all events that are compatible + with T will be selected. + + A 'subscriptionID' can be passed and this value along with the callback can be used + to uniquely identify subscription to remove using the 'RemoveCallback' API. If null is passed, then only the identity of the callback can + be used to identify the subscription to remove. + + eventNames passed to the filer are of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + + + + + A shortcut that adds 'callback' for the event in 'providerName' and an event name 'eventName' + The callback alone is used as the subscription id for unregistration, so the callback delegate should be unique (by delegate comparison) + + eventName is of the of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + + + + + Cause 'callback' to be called for any event that this parser recognizes for which the function 'eventsToObserve' + returns 'AcceptEvent'. The 'eventsToObserve is given both the provider name (first) and the event name and can return + 'AcceptEvent' 'RejectEvent' or 'RejectProvider' (in which case it may not be called again for that provider). + eventsToObserver can be null in which case all events that match the parser recognizes are selected. + + eventNames passed to the filer are of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + + Thus this method works for parsers that parse more than one provider (e.g. DynamicTraceEventParser). + + + + + + Cause 'callback' to be called for any event that this parser recognizes for which the function 'eventsToObserve' + returns 'AcceptEvent'. The 'eventsToObserve is given both the provider name (first) and the event name and can return + 'AcceptEvent' 'RejectEvent' or 'RejectProvider' (in which case it may not be called again for that provider). + eventsToObserver can be null in which case all events that match the parser recognizes are selected. + + eventNames passed to the filer are of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. /// + + Thus this method works for parsers that parse more than one provider (e.g. DynamicTraceEventParser). + + A subscriptionID can optionally be passed. This is used (along with the callback identity) to identify this to the 'RemoveCallback' If you + don't need to remove the callback or you will do it in bulk, you don't need this parameter. + + + + + + Remove all subscriptions added with 'AddCallback' (any overload), that is compatible with T, has a callback 'callback' and subscriptionId 'subscriptionId' + where 'subscriptionId' was the value that was optionally passed to 'AddCallback' to provide exactly this disambiguation. + + 'callback' or 'subscriptionId' can be null, in which case it acts as a wild card. Thus RemoveCallback{TraceEvent}(null, null) will remove all callbacks + that were registered through this parser. + + + + + + A static TraceEventParser is a parser where the set of events that can be subscribed to (and their payload fields) are known at + compile time. There are very few dynamic TraceEventParsers (DynamicTraceEventParser, RegisteredTraceEventParser and WPPTraceEventParser) + + + + + All TraceEventParsers invoke this constructor. If 'dontRegister' is true it is not registered with the source. + + + + + Normally a TraceEvent parser knows how to parse only one provider. If this is true + ProviderName returns the name of this provider. If the parser knows how to parse + more than one provider, this property returns null. + + + + + If the parser needs to persist data along with the events we put it in a separate object. + This object and then implement serialization functionality that allows it to be persisted (this is for ETLX support). + + + + + Returns a list of all templates currently existing (new ones can come in, but OnNewEventDefintion must be called + whenever that happens. Note that the returned templates MUST be cloned and do not have their source or parser state + fields set. These must be set as part of subscription (after you know if you care about them or not). + + eventsToObserver is given the provider name and event name and those events that return AcceptEvent will + have the 'callback' function called on that template. eventsToObserver can be null which mean all events. + + The returned template IS READ ONLY! If you need a read-write copy (typical), clone it first. + + + + + If the parser can change over time (it can add new definitions), It needs to support this interface. See EnumerateDynamicTemplates for details. + This function should be called any time a new event is now parsable by the parser. If it is guaranteed that the particular event is + definitely being ADDED (it never existed in the past), then you can set 'mayHaveExistedBefore' to false and save some time. + + It returns false if there are no definitions for that particular Provider (and thus you can skip callback if desired). + + + + + Given a subscription request, and a template that can now be parsed (and its state, which is just TraceEventParser.StateObj) + If subscription states that the template should be registered with the source, then do the registration. + + if 'mayHaveExistedBefore' means that this template definition may have been seen before (DynamicTraceEventParsers do this as + you may get newer versions dynamically registering themselves). In that case this should be set. If you can guaranteed that + a particular template (provider-eventID pair) will only be subscribed at most once you can set this to false. + + + + + Keeps track of a single 'AddCallback' request so it can be removed later. It also handles lazy addition of events. + + + + + Create a subscription request. 'eventsToObserve takes a provider name (first) and a event name and returns a three valued EventFilterResponse + value (accept, reject, reject provider) + + + + + The source that this parser is connected to. + + + + + EventFilterResponse is the set of responses a user-defined filtering routine, might return. This is used in the TraceEventParser.AddCallbackForProviderEvents method. + + + + + Not an interesting event, but other events in the same provider may be + + + + + No event in the provider will be accepted + + + + + An interesting event + + + + + A TraceEventDispatcher is a TraceEventSource that supports a callback model for dispatching events. + + + + + Obtains the correct TraceEventDispatcher for the given trace file name. + + A path to a trace file. + A TraceEventDispatcher for the given trace file. + + + + Subscribers to UnhandledEvent are called if no other hander has processed the event. It is + generally used in DEBUG builds to validate that events are getting to the source at all. + + + + + Subscribers to EveryEvent are called on every event in the trace. Normally you don't want + to subscribe to this but rather use a TraceEvenParser (which knows how to decode the payloads) + and subscribe to particular events through that. For example Using TraceEventSource.Dynamic.All + or TraceEventSource.Dynamic.All is more likely to be what you are looking for. AllEvents is only + an event callback of last resort, that only gives you the 'raw' data (common fields but no + payload). + + This is called AFTER any event-specific handlers. + + + + + + Subscribers to UnhandledEvent are called if no other hander has processed the event. It is + generally used in DEBUG builds to validate that events are getting to the source at all. + + + + + Subscribers to EveryEvent are called on every event in the trace. Normally you don't want + to subscribe to this but rather use a TraceEvenParser and subscribe to particular events + through that. + + This is called AFTER any event-specific handlers. + + + + + + Once a client has subscribed to the events of interest, calling Process actually causes + the callbacks to happen. + + Subclasses implementing this method should call 'OnCompleted' + before returning. + + + false If StopProcessing was called + + + + Calling StopProcessing in a callback when 'Process()' is running will indicate that processing + should be stopped immediately and that the Process() method should return. + + Note that this stop request will not be honored until the next event from the source. Thus + for real time sessions there is an indeterminate delay before the stop will complete. + If you need to force the stop you should instead call Dispose() on the session associated with + the real time session. This will cause the source to be shut down and thus also stop processing + (Process() will return) but is guaranteed to complete in a timely manner. + + + + + Subscribers of Completed will be called after processing is complete (right before TraceEventDispatcher.Process returns. + + + + + Wrap (or filter) the dispatch of every event from the TraceEventDispatcher stream. + Instead of calling the normal code it calls 'hook' with both the event to be dispatched + and the method the would normally do the processing. Thus the routine has + the option to call normal processing, surround it with things like a lock + or skip it entirely. This can be called more than once, in which case the last + hook method gets called first (which may end up calling the second ...) + + For example,here is an example that uses AddDispatchHook to + take a lock is taken whenever dispatch work is being performed. + + AddDispatchHook((anEvent, dispatcher) => { lock (this) { dispatcher(anEvent); } }); + + + + + Called when processing is complete. You can call this more than once if your not sure if it has already been called. + however we do guard against races. + + + + + Number of different events that have callbacks associated with them + + + + + Total number of callbacks that are registered. Even if they are for the same event. + + + + + + This is the routine that is called back when any event arrives. Basically it looks up the GUID + and the opcode associated with the event and finds right subclass of TraceEvent that + knows how to decode the packet, and calls its virtual TraceEvent.Dispatch method. Note + that TraceEvent does NOT have a copy of the data, but rather just a pointer to it. + This data is ONLY valid during the callback. + + + + + Lookup up the event based on its ProviderID (GUID) and EventId (Classic use the TaskId and the + Opcode field for lookup, but use these same fields (see ETWTraceEventSource.RawDispatchClassic) + + + + + Dispose pattern. + + + + + Dispose pattern + + + + + Inserts 'template' into the hash table, using 'providerGuid' and and 'eventID' as the key. + For Vista ETW events 'providerGuid' must match the provider GUID and the 'eventID' the ID filed. + For PreVist ETW events 'providerGuid must match the task GUID the 'eventID' is the Opcode + + + + + A helper for creating a set of related guids (knowing the providerGuid can can deduce the + 'taskNumber' member of this group. All we do is add the taskNumber to GUID as a number. + + + + + TraceEventParsers can use this template to define the event for the trivial case where the event has no user-defined payload + This is only useful to TraceEventParsers. + + + + + Construct a TraceEvent template which has no payload fields with the given metadata and action + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + Dispatches the event to the action associated with the template. + + + + + override + + + + + When the event has just a single string value associated with it, you can use this shared event + template rather than making an event-specific class. + + + + + The value of the one string payload property. + + + + + Construct a TraceEvent template which has one string payload field with the given metadata and action + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + override + + + + + UnhandledTraceEvent is a TraceEvent when is used when no manifest information is available for the event. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + override + + + + + implementation of TraceEvent Interface. + + + + + There is some work needed to prepare the generic unhandledTraceEvent that we defer + late (since we often don't care about unhandled events) + + TODO this is probably not worht the complexity... + + + + + ObservableExtensions defines methods on TraceEventParser that implement the IObservable protocol for implementing callbacks. + + + + + Returns an IObjservable that observes all events that 'parser' knows about that return a T. If eventName is + non-null, the event's name must match 'eventName', but if eventName is null, any event that returns a T is observed. + + This means that Observe{TraceEvent}(parser) will observe all events that the parser can parse. + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + + Returns an IObjservable that observes all events that 'parser' knows about that return a T and whose event + name matches the 'eventNameFilter' predicate. + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + Observe a particular event from a particular provider. If eventName is null, it will return every event from the provider + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + Given a predicate 'eventToObserve' which takes the name of a provider (which may be of the form Provider(GUID)) (first) and + an event name (which may be of the form EventID(NUM)) and indicates which events to observe, return an IObservable + that observes those events. + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. . + + + + + Returns an observable that observes all events from the event source 'source' + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + Returns an observable that observes all events from the event source 'source' which are not handled by a callback connected to 'source' + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + A TraceEventObservable is a helper class that implements the IObservable pattern for TraceEventDispatcher + (like ETWTraceEventDispatcher). It is called from the TraceEventParser.Observe*{T} methods. + + + + + + A TraceEventSubscription is helper class that hooks 'callback' and 'completedCallback' to the 'observable' and + unhooks them when 'Dispose' is called. + + + + + TraceEventNativeMethods contains the PINVOKE declarations needed + to get at the Win32 TraceEvent infrastructure. It is effectively + a port of evntrace.h to C# declarations. + + + + + Time zone info. Used as one field of TRACE_EVENT_LOGFILE, below. + Total struct size is 0xac. + + + + + EventTraceHeader structure used by EVENT_TRACE_PROPERTIES + + + + + EVENT_TRACE_PROPERTIES is a structure used by StartTrace, ControlTrace + however it can not be used directly in the definition of these functions + because extra information has to be hung off the end of the structure + before being passed. (LofFileNameOffset, LoggerNameOffset) + + + + + EventTraceHeader and structure used to defined EVENT_TRACE (the main packet) + I have simplified from the original struct definitions. I have + omitted alternate union-fields which we don't use. + + + + + EVENT_TRACE is the structure that represents a single 'packet' + of data repesenting a single event. + + + + + TRACE_LOGFILE_HEADER is a header used to define EVENT_TRACE_LOGFILEW. + Total struct size is 0x110. + + + + + EVENT_TRACE_LOGFILEW Main struct passed to OpenTrace() to be filled in. + It represents the collection of ETW events as a whole. + + + + + EventTraceHeader and structure used to define EVENT_TRACE_LOGFILE (the main packet on Vista and above) + I have simplified from the original struct definitions. I have + omitted alternate union-fields which we don't use. + + + + + Provides context information about the event + + + + + Defines the layout of an event that ETW delivers + + + + + Possible control commands (borrowed from EventSource) + + + + + Standard 'update' command to send additional information to a provider + + + + + Instructs an EventSource-based provider to send its manifest + + + + + A TraceEventSession represents a single ETW Tracing Session. A session is and event sink that + can enable or disable event logging from event providers). TraceEventSessions can log their + events either to a file, or by issuing callbacks when events arrive (a so-called 'real time' + session). + + Session are MACHINE wide and unlike most OS resources the operating system does NOT reclaim + them when the process that created it dies. By default TraceEventSession tries is best to + do this reclamation, but it is possible that for 'orphan' session to accidentally survive + if the process is ended abruptly (e.g. by the debugger or a user explicitly killing it). It is + possible to turn off TraceEventSession automatic reclamation by setting the StopOnDispose + property to false (its default is true). + + + Kernel events have additional restrictions. In particular there is a special API (EnableKernelProvider). + Before Windows 8, there was a restriction that kernel events could only be enabled from a session + with a special name (see KernelTraceEventParser.KernelSessionName) and thus there could only be a single + session that could log kernel events (and that session could not log non-kernel events). These + restrictions were dropped in windows 8. + + + + + + Create a new logging session sending the output to a given file. + + + The name of the session. Since session can exist beyond the lifetime of the process this name is + used to refer to the session from other processes after it is created. By default TraceEventSessions + do their best to close down if the TraceEventSession dies (see StopOnDispose), however if StopOnDispose + is set to false, the session can live on after process death, and you use the name to refer to it later. + + + The output moduleFile (by convention .ETL) to put the event data. If this is null, and CircularMB is set + to something non-zero, then it will do an in-memory circular buffer. You can get this buffer by + using the 'SetFileName()' method which dumps the data in the buffer. + + Additional flags that influence behavior. Note that the 'Create' option is implied for file mode sessions. + + + + Open a logging session. By default (if options is not specified) a new 'real time' session is created if + the session already existed it is closed and reopened (thus orphans are cleaned up on next use). By default + sessions are closed on Dispose, but if the destructor does not run it can produce 'orphan' session that will + live beyond the lifetime of the process. You can use the StopOnDispose property to force sessions to live + beyond the TraceEventSession that created them and use the TraceEventSessionOptions.Attach option to reattach + to these sessions. + + The name of the session to open. Should be unique across the machine. + Construction options. TraceEventSessionOptions.Attach indicates a desire to attach + to an existing session. + + + + Looks for an existing active session named 'sessionName; and returns the TraceEventSession associated with it if it exists. + Returns null if the session does not exist. You can use the GetActiveSessionNames() to get a list of names to pass to this method. + + + + + Enable a NON-KERNEL provider (see also EnableKernelProvider) which has a given provider name. + This API first checks if a published provider exists by that name, otherwise it + assumes it is an EventSouce and determines the provider Guid by hashing the name according to a + well known algorithm. Thus it will never return a failure for a incorrect spelling of the name. + + + The name of the provider. It must either be registered with the operating system (logman query providers returns it) + or it must be an EventSource (see GetEventSourceGuidFromName) + The verbosity to turn on + A bitvector representing the areas to turn on. Only the + low 32 bits are used by classic providers and passed as the 'flags' value. Zero + is a special value which is a provider defined default, which is usually 'everything' + Additional options for the provider (e.g. taking a stack trace), arguments ... + true if the session already existed and needed to be restarted. + + + + Enable a NON-KERNEL provider (see also EnableKernelProvider) which has a given provider Guid. + + + The Guid that represents the event provider enable. + The verbosity to turn on + A bitvector representing the areas to turn on. Only the + low 32 bits are used by classic providers and passed as the 'flags' value. Zero + is a special value which is a provider defined default, which is usually 'everything' + Additional options for the provider (e.g. taking a stack trace), arguments ... + true if the session already existed and needed to be restarted. + + + + Enable a NON-KERNEL provider (see also EnableKernelProvider) which has a given provider name. + This API first checks if a published provider exists by that name, otherwise it + assumes it is an EventSouce and determines the provider Guid by hashing the name according to a + well known algorithm. Thus it will never return a failure for a incorrect spelling of the name. + + + The name of the provider. It must either be registered with the operating system (logman query providers returns it) + or it must be an EventSource (see GetEventSourceGuidFromName) + The verbosity to turn on + A bitvector representing the areas to turn on. Only the + low 32 bits are used by classic providers and passed as the 'flags' value. Zero + is a special value which is a provider defined default, which is usually 'everything' + Additional options for the provider (e.g. taking a stack trace) + This is set of key-value strings that are passed to the provider + for provider-specific interpretation. Can be null if no additional args are needed. + If the special key-value pair 'Command'='SendManifest' is provided, then the 'SendManifest' + command will be sent (which causes EventSources to re-dump their manifest to the ETW log. + true if the session already existed and needed to be restarted. + + + + Enable a NON-KERNEL provider (see also EnableKernelProvider) represented by 'providerGuid'. + + + The Guid that represents the event provider enable. + The verbosity to turn on + A bitvector representing the areas to turn on. Only the + low 32 bits are used by classic providers and passed as the 'flags' value. Zero + is a special value which is a provider defined default, which is usually 'everything' + Additional options for the provider (e.g. taking a stack trace) + This is set of key-value strings that are passed to the provider + for provider-specific interpretation. Can be null if no additional args are needed. + If the special key-value pair 'Command'='SendManifest' is provided, then the 'SendManifest' + command will be sent (which causes EventSources to re-dump their manifest to the ETW log. + true if the session already existed and needed to be restarted. + + + + Enable an ETW provider, passing a raw blob of data to the provider as a Filter specification. + + Note that this routine is only provided to interact with old ETW providers that can interpret EVENT_FILTER_DESCRIPTOR data + but did not conform to the key-value string conventions. This allows this extra information to be passed to these old + providers. Ideally new providers follow the key-value convention and EnableProvider can be used. + + + + + Helper function that is useful when using EnableProvider with key value pairs. + Given a list of key-value pairs, create a dictionary of the keys mapping to the values. + + + + + Enable the kernel provider for the session. Before windows 8 this session must be called 'NT Kernel Session'. + This API is OK to call from one thread while Process() is being run on another + Specifies the particular kernel events of interest + + Specifies which events should have their stack traces captured when an event is logged + Returns true if the session existed before and was restarted (see TraceEventSession) + + + + + Turn on windows heap logging (stack for allocation) for a particular existing process. + + + + + Turn on windows heap logging for a particular EXE file name (just the file name, no directory, but it DOES include the .exe extension) + This API is OK to call from one thread while Process() is being run on another + + + + + + Disables a provider with the given provider ID completely + + + + + Disables a provider with the given name completely + + + + + Once started, event sessions will persist even after the process that created them dies. They will also be + implicitly stopped when the TraceEventSession is closed unless the StopOnDispose property is set to false. + This API is OK to call from one thread while Process() is being run on another + + + + + Close the session and clean up any resources associated with the session. It is OK to call this more than once. + This API is OK to call from one thread while Process() is being run on another. Calling Dispose is on + a real time session is the way you can force a real time session to stop in a timely manner. + + + + + Asks all providers to flush events to the session + This API is OK to call from one thread while Process() is being run on another + + + + + For either session create with a file name this method can be used to redirect the data to a + new file (so the previous one can be uploaded or processed offline), + + It can also be used for a in-memory circular buffer session (FileName == null and CircularMB != 0) + but its semantics is that simply writes the snapshot to the file (and closes it). It does not + actually make the FileName property become non-null because it only flushes the data, it does + not cause persistent redirection of the data stream. (it is like it auto-reverts). + + It is an error to call this on a real time session. (FileName == null and CircularMB == 0) + + The path to the file to write the data to. + + + + If set, whenever a SetFileName is called (causing a new ETL file to be created), force + a capture state for every provider that is currently turned on. This way the file + will be self-contained (will contain all the capture state information needed to decode events) + This setting is true by default. + + + + + Sends the CAPTURE_STATE command to the provider. This instructs the provider to log any events that are needed to + reconstruct important state that was set up before the session started. What is actually done is provider specific. + EventSources will re-dump their manifest on this command. + This API is OK to call from one thread while Process() is being run on another + + This routine only works Win7 and above, since previous versions don't have this concept. The providers also has + to support it. + + + The GUID that identifies the provider to send the CaptureState command to + The Keywords to send as part of the command (can influence what is sent back) + if non-zero, this is passed along to the provider as type of the filter data. + If non-null this is either an int, or a byte array and is passed along as filter data. + + + + When you issue a EnableProvider command, on windows 7 and above it can be done synchronously (that is you know that because + the EnableProvider returned that the provider actually got the command). However synchronous behavior means that + you may wait forever. This is the time EnableProvider waits until it gives up. Setting this + to 0 means asynchronous (fire and forget). The default is 10000 (wait 10 seconds) + Before windows 7 EnableProvider is always asynchronous. + + + + + If set then Stop() will be called automatically when this object is Disposed or Finalized by the GC. + This is true BY DEFAULT, so if you want your session to survive past the end of the process + you must set this to false. + + + + + Cause the log to be a circular buffer. The buffer size (in MegaBytes) is the value of this property. + Setting this to 0 will cause it to revert to non-circular mode. + The setter can only be called BEFORE any provider is enabled. + + + + + Cause the as a set of files with a given maximum size. The file name must end in .ETL and the + output is then a series of files of the form *NNN.ETL (That is it adds a number just before the + .etl suffix). If you make your file name *.user.etl then the output will be *.user1.etl, *.user2.etl ... + And the MergeInPlace command below will merge them all nicely. + + You can have more control over this by using a normal sequential file but use the SetFileName() + method to redirect the data to new files as needed. + + + + + Sets the size of the buffer the operating system should reserve to avoid lost packets. Starts out + as a very generous 64MB for files. If events are lost, this can be increased, but keep in mind that + no value will help if the average incoming rate is faster than the processing rate. + The setter can only be called BEFORE any provider is enabled. + + + + + This is the unit in which data is flushed in Kilobytes. By default it is 64 (KB). + By default a TraceEventSession will flush every second, and this amount of space will be transferred + to the file. Ideally it is smaller than the number data bytes you expect in a second from any + particular processor. It can't be less than 1K per processor on the machine. However if you make + it less than 64 (K) you will limit the size of the event that the process can send + (they will simply be discarded). + + + + + The rate at which CPU samples are collected. By default this is 1 (once a millisecond per CPU). + There is a lower bound on this (typically .125 Msec) + + + + + Indicate that this session should use compress the stacks to save space. + Must be set before any providers are enabled. Currently only works for kernel events. + + + + + The name of the session that can be used by other threads to attach to the session. + + + + + The name of the moduleFile that events are logged to. Null means the session is real time + or is a circular in-memory buffer. See also SetFileName() method. + + + + + If this is a real time session you can fetch the source associated with the session to start receiving events. + Currently does not work on file based sources (we expect you to wait until the file is complete). + + + + + Creating a TraceEventSession does not actually interact with the operating system until a + provider is enabled. At that point the session is considered active (OS state that survives a + process exit has been modified). IsActive returns true if the session is active. + + + + + + Returns the number of events that should have been delivered to this session but were lost + (typically because the incoming rate was too high). This value is up-to-date for real time + sessions. + + + + + Returns true if the session is logging to a circular buffer. This may be in-memory (FileName == null) + or to a file (FileName != null) + + + + + Returns true if the session is Real Time. This means it is not to a file, and not circular. + + + + + Returns true if this is a in-memory circular buffer (it is circular without an output file). + Use SetFileName() to dump the in-memory buffer to a file. + + + + + ETW trace sessions survive process shutdown. Thus you can attach to existing active sessions. + GetActiveSessionNames() returns a list of currently existing session names. These can be passed + to the TraceEventSession constructor to open it. + + A enumeration of strings, each of which is a name of a session + + + + It is sometimes useful to merge the contents of several ETL files into a single + output ETL file. This routine does that. It also will attach additional + information that will allow correct file name and symbolic lookup if the + ETL file is used on a machine other than the one that the data was collected on. + If you wish to transport the file to another machine you need to merge them, even + if you have only one file so that this extra information get incorporated. + + The input ETL files to merge + The output ETL file to produce. + Optional Additional options for the Merge (seeTraceEventMergeOptions) + + + + This variation of the Merge command takes the 'primary' etl file name (X.etl) + and will merge in any files that match .clr*.etl .user*.etl. and .kernel.etl. + + + + + Is the current process Elevated (allowed to turn on a ETW provider). This is useful because + you need to be elevated to enable providers on a TraceEventSession. + + + + + Set the Windows Debug Privilege. Useful because some event providers require this privilege, and + and it must be enabled explicitly (even if the process is elevated). + + + + + The 'properties' field is only the header information. There is 'tail' that is + required. 'ToUnmangedBuffer' fills in this tail properly. + + + + + Returns a sorted dictionary of names and Guids for every provider registered on the system. + + + + + sets up the EVENT_FILTER_DESCRIPTOR descr to represent the Event Ids in 'eventIds'. You are given the buffer + necessary for this (precomputed) for the EVENT_FILTER_EVENT_ID structure. 'enable' is true if this is to enable + (otherwise disable) the events, and descrType indicates the descriptor type (either EVENT_FILTER_TYPE_EVENT_ID or + EVENT_FILTER_TYPE_STACKWALK) + + + + + Computes the number of bytes needed for the EVENT_FILTER_EVENT_ID structure to represent 'eventIds' + return 0 if there is not need for the filter at all. + + + + + Cleans out all provider data associated with this session. + + + + + SetDataForSession sets the filter data for an ETW session by storing it in the registry. + This is basically a work-around for the fact that filter data does not get transmitted to + the provider if the provider is not alive at the time the controller issues the EnableProvider + call. We store in the registry and EventSource looks there for it if it is not present. + + Note that we support up to 'maxSession' etw sessions simultaneously active (having different + filter data). The function return a sessionIndex that indicates which of the 'slots' + was used to store the data. This routine also 'garbage collects' data for sessions that + have died without cleaning up their filter data. + + If 'data' is null, then it indicates that no data should be stored and the registry entry + is removed. + + If 'allSesions' is true it means that you want 'old style' data filtering that affects all ETW sessions + This is present only used for compatibilty + + the session index that will be used for this session. Returns -1 if an entry could not be found + + + + Given a mask of kernel flags, set the array stackTracingIds of size stackTracingIdsMax to match. + It returns the number of entries in stackTracingIds that were filled in. + + + + + Get a EVENT_TRACE_PROPERTIES structure suitable for passing the the ETW out of a 'buffer' which must be PropertiesSize bytes + in size. + + + + + Used in the TraceEventSession.Merge method + + + + + No special options + + + + + Compress the resulting file. + + + + + TraceEventProviderOptions represents all the optional arguments that can be passed to EnableProvider command. + + + + + Create new options object with no options set + + + + + Create new options object with a set of given provider arguments key-value pairs. There must be a even number + of strings provided and each pair forms a key-value pair that is passed to the AddArgument() operator. + + + + + Arguments are a set of key-value strings that are passed uninterpreted to the EventSource. These can be accessed + from the EventSource's command callback. + + + + + As a convenience, the 'Arguments' property can be modified by calling AddArgument that adds another Key-Value pair + to it. If 'Arguments' is not a IDictionary, it is replaced with an IDictionary with the same key-value pairs before + the new pair is added. + + + + + For EventSources, you pass arguments to the EventSource by using key value pairs (this 'Arguments' property). + However other ETW providers may expect arguments using another convention. RawArguments give a way of passing + raw bytes to the provider as arguments. This is only meant for compatibility with old providers. Setting + this property will cause the 'Arguments' property to be ignored. + + + + + Setting StackEnabled to true will cause all events in the provider to collect stacks when event are fired. + + + + + Setting ProcessIDFilter will limit the providers that receive the EnableCommand to those that match on of + the given Process IDs. + + + + + Setting ProcessNameFilter will limit the providers that receive the EnableCommand to those that match on of + the given Process names (a process name is the name of the EXE without the PATH but WITH the extension). + + + + + Setting EventIDs to Enable will enable a particular event of a provider by EventID (in addition to those + enabled by keywords). + + + + + Setting EventIDs to Enable will enable the collection of stacks for a event of a provider by EventID + (Has no effect if StacksEnabled is also set since that enable stacks for all events IDs) + + + + + Setting EventIDsToDisable to Enable will disable the event of a provider by EventID + This happens after keywords have been processed, so disabling overrides enabling. + + + + + Setting EventIDs to Enable will disable the collection of stacks for a event of a provider by EventID + Has no effect unless StacksEnabled is also set (since otherwise stack collection is off). + + + + + Make a deep copy of options and return it. + + + + + + This return true on OS version beyond 8.1 (windows Version 6.3). It means most of the + per-event filtering is supported. + + + + + This is the backing field for the lazily-computed property. + + + + + TraceEventSessionOptions indicates special handling when creating a TraceEventSession. + + + + + Create a new session, stop and recreated it if it already exists. This is the default. + + + + + Attach to an existing session, fail if the session does NOT already exist. + + + + + Normally if you create a session it will stop and restart it if it exists already. Setting + this flat will disable the 'stop and restart' behavior. This is useful if only a single + monitoring process is intended. + + + + + TraceEventProviders returns information about providers on the system. + + + + + Given the friendly name of a provider (e.g. Microsoft-Windows-DotNETRuntimeStress) return the + GUID for the provider. It does this by looking at all the PUBLISHED providers on the system + (that is those registered with wevtutuil). EventSources in particular do not register themselves + in this way (see GetEventSourceGuidFromName). Names are case insensitive. + It also checks to see if the name is an actual GUID and if so returns that. + Returns Guid.Empty on failure. + + + + + EventSources have a convention for converting its name to a GUID. Use this convention to + convert 'name' to a GUID. In this way you can get the provider GUID for a EventSource + however it can't check for misspellings. Names are case insensitive. + + + + + Finds the friendly name for 'providerGuid' Returns the Guid as a string if can't be found. + + + + + Returns true if 'providerGuid' can be an eventSource. If it says true, there is a 1/16 chance it is not. + However if it returns false, it is definitely not following EventSource Guid generation conventions. + + + + + Returns the Guid of every event provider that published its manifest on the machine. This is the + same list that the 'logman query providers' command will generate. It is pretty long (> 1000 entries) + + A event provider publishes a manifest by compiling its manifest into a special binary form and calling + the wevtutil utility. Typically EventSource do NOT publish their manifest but most operating + system provider do publish their manifest. + + + + + + Returns the GUID of all event provider that either has registered itself in a running process (that is + it CAN be enabled) or that a session has enabled (even if no instances of the provider exist in any process). + + This is a relatively small list (less than 1000), unlike GetPublishedProviders. + + + + + + Returns a list of provider GUIDs that are registered in a process with 'processID'. Useful for discovering + what providers are available for enabling for a particular process. + + + + + Returns a description of the keywords a particular provider provides. Only works if the provider has + published its manifest to the operating system. + Throws an exception if providerGuid is not found + + + + + Returns a list of TRACE_ENABLE_INFO structures that tell about each session (what keywords and level they are + set to, for the provider associated with 'providerGuid'. If 'processId != 0, then only providers in that process + are returned. + + + + + A list of these is returned by GetProviderKeywords + + + + + The name of the provider keyword. + + + + + The description for the keyword for the provider + + + + + the value (bitvector) for the keyword. + + + + + and XML representation for the ProviderDataItem (for debugging) + + + + + TraceEventProfileSources is the interface for the Windows processor CPU counter support + (e.g. causing a stack to be taken every N dcache misses, or branch mispredicts etc) + + Note that the interface to these is machine global (That is when you set these you + cause any session with the kernel PMCProfile keyword active to start emitting + PMCCounterProf events for each ProfileSouce that is enabled. + + /// + + + + Returns a dictionary of keyed by name of ProfileSourceInfo structures for all the CPU counters available on the machine. + + + + + Sets a single Profile Source (CPU machine counters) that will be used if PMC (Precise Machine Counters) + are turned on. The profileSourceID is the ID field from the ProfileSourceInfo returned from 'GetInfo()'. + and the profileSourceInterval is the interval between sampples (the number of events before a stack + is recoreded. If you need more that one (the OS allows up to 4 I think), use the variation of this + routine that takes two int[]. Calling this will clear all Profiler sources previously set (it is NOT + additive). + + + + + Sets the Profile Sources (CPU machine counters) that will be used if PMC (Precise Machine Counters) + are turned on. Each CPU counter is given a id (the profileSourceID) and has an interval + (the number of counts you skip for each event you log). You can get the human name for + all the supported CPU counters by calling GetProfileSourceInfo. Then choose the ones you want + and configure them here (the first array indicating the CPU counters to enable, and the second + array indicating the interval. The second array can be shorter then the first, in which case + the existing interval is used (it persists and has a default on boot). + + + + + Returned by GetProfileSourceInfo, describing the CPU counter (ProfileSource) available on the machine. + + + + + Human readable name of the CPU performance counter (eg BranchInstructions, TotalIssues ...) + + + + + The ID that can be passed to SetProfileSources + + + + + This many events are skipped for each sample that is actually recorded + + + + + The smallest Interval can be (typically 4K) + + + + + The largest Interval can be (typically maxInt). + + + + + These are options to EnableProvider + + + + + No options + + + + + Take a stack trace with the event + + + + + The data model for an Event trace log (ETL) file is simply a stream of events. More sophisticated + analysis typically needs a a richer data model then ETL files can provide, and this is the + motivation for the ETLX (Event Trace Log eXtended) file format. In particular any + analysis that needs non-sequential access to the events or manipulates stack traces associated + with events needs the additional support that the ETLX format provides. See the TraceEventProgrammers guide + for more on the capabilities of ETLX. + + The TraceLog class is the programmatic representation of an ETLX file. It represents the ETLX file as a whole. + + ETLX files are typically created from ETL files using the TraceLog.OpenOrCreate method or more explicitly + by the TraceLog.CreateFromEventTraceLogFile. + + + + + + Given the path to an ETW trace log file (ETL) file, create an ETLX file for the data. + If etlxFilePath is null the output name is derived from etlFilePath by changing its file extension to .ETLX. + The name of the ETLX file that was generated. + + + + + Open an ETLX or ETL file as a ETLX file. + + This routine assumes that you follow normal conventions of naming ETL files with the .ETL file extension + and ETLX files with the .ETLX file extension. It further assumes the ETLX file for a given ETL file + should be in a file named the same as the ETL file with the file extension changed. + + etlOrEtlxFilePath can be either the name of the ETL or ETLX file. If the ETLX file does not + exist or if it older than the corresponding ETL file then the ETLX file is regenerated with + the given options. However if an up-to-date ETLX file exists the conversion step is skipped. + + Ultimately the ETLX file is opened and the resulting TraceLog instance is returned. + + + + + + From a TraceEventSession, create a real time TraceLog Event Source. Like a ETWTraceEventSource a TraceLogEventSource + will deliver events in real time. However an TraceLogEventSource has an underlying Tracelog (which you can access with + the .Log Property) which lets you get at aggregated information (Processes, threads, images loaded, and perhaps most + importantly TraceEvent.CallStack() will work. Thus you can get real time stacks from events). + + Note that in order for native stacks to resolve symbolically, you need to have some Kernel events turned on (Image, and Process) + and only windows 8 has a session that allows both kernel and user mode events simultaneously. Thus this is most useful + on Win 8 systems. + + + + + Creates a ETLX file an Lttng Text file 'filePath'. + + + + + Creates a ETLX file an EventPipe 'filePath'. + + + + + Opens an existing Extended Trace Event log file (ETLX) file. See also TraceLog.OpenOrCreate. + + + + + All the events in the ETLX file. The returned TraceEvents instance supports IEnumerable so it can be used + in foreach statements, but it also supports other methods to further filter the evens before enumerating over them. + + Note that the TraceEvent returned from this IEnumerable may only be used for one iteration of the foreach. + (it is reused for the next event). If you need more lifetime than that you must call Clone() (see 'Lifetime + Constraints' in the programmers guide for more). + + + + + All the Processes that logged an event in the ETLX file. The returned TraceProcesses instance supports IEnumerable so it can be used + in foreach statements, but it also supports other methods to select particular a particular process. + + + + + All the Threads that logged an event in the ETLX file. The returned TraceThreads instance supports IEnumerable so it can be used + in foreach statements, but it also supports other methods to select particular thread. + + + + + All the module files (DLLs) that were loaded by some process in the ETLX file. The returned TraceModuleFiles instance supports IEnumerable so it can be used + in foreach statements, but it also supports other methods to select particular module file. + + + + + All the call stacks in the ETLX file. Normally you don't enumerate over these, but use you use other methods on TraceCallStacks + information about code addresses using CallStackIndexes. + + + + + All the code addresses in the ETLX file. Normally you don't enumerate over these, but use you use other methods on TraceCodeAddresses + information about code addresses using CodeAddressIndexes. + + + + + Summary statistics on the events in the ETX file. + + + + + If the event has a call stack associated with it, retrieve it. Returns null if there is not call stack associated with the event. + If you are retrieving many call stacks consider using GetCallStackIndexForEvent, as it is more efficient. + + + + + If the event has a call stack associated with it, retrieve CallStackIndex. Returns CallStackIndex.Invalid if there is not call stack associated with the event. + + + + + Events are given an Index (ID) that are unique across the whole TraceLog. They are not guaranteed + to be sequential, but they are guaranteed to be between 0 and MaxEventIndex. Ids can be used to + allow clients to associate additional information with event (with a side lookup table). See + TraceEvent.EventIndex and EventIndex for more + + + + + Given an eventIndex, get the event. This is relatively expensive because we need to create a + copy of the event that will not be reused by the TraceLog. Ideally you would not use this API + but rather use iterate over event using TraceEvents + + + + + The total number of events in the log. + + + + + The size of the log file in bytes. + + + + + override + + + + + The file path for the ETLX file associated with this TraceLog instance. + + + + + The machine on which the log was collected. Returns empty string if unknown. + + + + + The name of the Operating system. Returns empty string if unknown. + + + + + The build number information for the OS. Returns empty string if unknown. + + + + + The time the machine was booted. Returns DateTime.MinValue if it is unknown. + + + + + This is the number of minutes between the local time where the data was collected and UTC time. + It is negative if your time zone is WEST of Greenwich. This DOES take Daylights savings time into account + but might be a daylight savings time transition happens inside the trace. + May be unknown, in which case it returns null. + + + + + When an ETL file is 'merged', for every DLL in the trace information is added that allows the symbol + information (PDBS) to be identified unambiguously on a symbol server. This property returns true + if the ETLX file was created from an ETL file with this added information. + + + + + The size of the main memory (RAM) on the collection machine. Will return 0 if memory size is unknown + + + + + Are there any event in trace that has a call stack associated with it. + + + + + If Kernel CPU sampling events are turned on, CPU samples are taken at regular intervals (by default every MSec). + This property returns the time interval between samples. + + If the sampling interval was changed over the course of the trace, this property does not reflect that. It + returns the first value it had in the trace. + + + + + + Returns true if the machine running this code is the same as the machine where the trace data was collected. + + If this returns false, the path names references in the trace cannot be inspected (since they are on a different machine). + + + + + + There is a size limit for ETLX files. Thus it is possible that the data from the original ETL file was truncated. + This property returns true if this happened. + + + + + Returns the EvnetIndex (order in the file) of the first event that has a + timestamp smaller than its predecessor. Returns Invalid if there are no time inversions. + + + + + Returns all the TraceEventParsers associated with this log. + + + + + An XML fragment that gives useful summary information about the trace as a whole. + + + + + Create a new real time session called 'sessionName' and connect a TraceLog to it and return that TraceLog. + Functionality of TraceLog that does not depend on either remembering past EVENTS or require future + knowledge (e.g. stacks of kernel events), will 'just work'. + + + + + Removes all but the last 'keepCount' entries in 'growableArray' by sliding them down. + + + + + Forwards an event that was saved (cloned) to the dispatcher associated with the real time source. + + + + + Flushes any event that has waited around long enough + + + + + Given a process's virtual address 'address' and an event which acts as a + context (determines which process and what time in that process), return + a CodeAddressIndex (which represents a particular location in a particular + method in a particular DLL). It is possible that different addresses will + go to the same code address for the same address (in different contexts). + This is because DLLS where loaded in different places in different processes. + + + + + If an event has a field of type 'Address' the address can be converted to a symbolic value (a + TraceCodeAddress) by calling this function. C + + + + + Given an EventIndex for an event, retrieve the call stack associated with it + (that can be given to TraceCallStacks). Many events may not have associated + call stack in which case CallSTackIndex.Invalid is returned. + + + + + Given a eventIndex for a CSWTICH event, return the call stack index for the thread + that LOST the processor (the normal callStack is for the thread that GOT the CPU) + + + + + Given a source of events 'source' generated a ETLX file representing these events from them. This + file can then be opened with the TraceLog constructor. 'options' can be null. + + + + + SetupCallbacks installs all the needed callbacks for TraceLog Processing (stacks, process, thread, summaries etc) + on the TraceEventSource rawEvents. + + + + + Copies the events from the 'rawEvents' dispatcher to the output stream 'IStreamWriter'. It + also creates auxiliary data structures associated with the raw events (eg, processes, threads, + modules, address lookup maps... Basically any information that needs to be determined by + scanning over the events during TraceLog creation should hook in here. + + + + + This is a helper routine that adds the address 'address' in the event 'data' to the map from events + to this list of addresses. + + + + + Special logic to form MemInfoWSTraceData. We take the single event (which has + The working sets for every process in the system, an split them out into N events + each of which has the processID for the event set properly, and only has the + information for that process. The first 3 processes in the list are -1, -2, and -3 + that have special meaning. + + + + + Given just the stack event and the timestamp for the event the stack event is to attach to, find + the IncompleteStack for the event. If the event to attach to cannot be this will return null + but otherwise it will make an IncompleteStack entry if one does not already exist or it. + + As part of allocating an Incomplete stack, it will increment the stack counts for target event. + + + + + Do the processing necessary to attach the user mode stack 'userModeStack' to any of the stacks in listOfIncompleteKernelStacks. + It then clears this list. While doing this processing it will check to see if the target stack 'target' is in that list and + it will return true if it was. + + + + + Do the processing necessary to attach the user mode stack 'userModeStack' to any of the stacks in listOfIncompleteKernelStacks. + It then clears this list. While doing this processing it will check to see if the target stack 'target' is in that list and + it will return true if it was. + + + + + Called when we get a definition event (for either a user mode or kernel mode stack fragment). + + + + + Holds information about stacks associated with an event. This is a transient structure. We only need it + until all the information is collected for a particular event, at which point we can create a + CallStackIndex for the stack and eventsToStacks table. + + + + + Clear clears entires that typically don't get set when we only have 1 frame fragment + We can recycle the entries without setting these in that case. + + + + + Clear all entries that can potentially change every time. + + + + + Log the Kernel Stack fragment. We simply remember all the frames (converted to CodeAddressIndexes). + + + + + Log the kernel stack fragment. Returns true if all the pieces of the stack fragment are collected + (we don't have to log something on the thread). + + + + + + + + + + Determine if 'stackInfo' is complete and if so emit it to the 'eventsToStacks' array. If 'force' is true + then force what information there is out even if it is not complete (there is nothing else coming). + + Returns true if it was able to emit the stack + + + + + returns true if the IncompleteStack is dead (just waiting to be reused). + + + + + We track the stacks for when CSwitches block, this is the CSWITCH event where that blocking happened. + + + + + Put the thread that owns 'data' in to the category 'category. + + + + + Process any extended data (like Win7 style stack traces) associated with 'data' + returns true if the event should be considered a bookkeeping event. + + + + + Dispose pattern + + + + + Advance 'reader' until it point at a event that occurs on or after 'timeQPC'. on page + 'pageIndex'. If 'positions' is non-null, fill in that array. Also return the index in + 'positions' for the entry that was found. + + + + + We need a TraceEventDispatcher in the Enumerators for TraceLog that know how to LOOKUP an event + We don't actually dispatch through it. We do mutate the templates (to point a particular data + record), but once we are done with it we can reuse this TraceEventDispatcher again an again + (it is only concurrent access that is a problem). Thus we have an Allocate and Free pattern + to reuse them in the common case of sequential access. + + + + + + The context switch event gives the stack of the thread GETTING the CPU, but it is also very useful + to have this stack at the point of blocking. cswitchBlockingEventsToStacks gives this stack. + + + + + We need to remember the the EventIndexes of the events that were 'just before' this event so we can + associate eventToStack traces with the event that actually caused them. PastEventInfo does this. + + + + + Returns the previous Event on the 'threadID'. Events with -1 thread IDs are also always returned. + Returns PastEventInfoIndex.Invalid if there are not more events to consider. + + + + + Find the event event on thread threadID to the given QPC timestamp. If there is more than + one event with the same QPC, we use thread and processor number to disambiguate. + + + + + Add a new entry that associates the stack 'stackIndex' with the event with index 'eventIndex' + + + + + Represents a source for a TraceLog file (or real time stream). It is basically a TraceEventDispatcher + (TraceEventSource) but you can also get at the TraceLog for it as well. + + + + + Returns the TraceLog associated with this TraceLogEventSource. + + + + + Returns the event Index of the 'current' event (we post increment it so it is always one less) + + + + + override + + + + + override + + + + + override + + + + + TraceEventStats represents the summary statistics (counts) of all the events in the log. + + + + + The total number of distinct event types (there will be a TraceEventCounts for each distinct event Type) + + + + + An XML representation of the TraceEventStats (for Debugging) + + + + + Given an event 'data' look up the statistics for events that type. + + + + + TraceEventCount holds number of events (Counts) and the number of events with call stacks associated with them (StackCounts) for a particular event type. + It also has properties for looking up the event and provider names, but this information can only be complete if all the TraceEventParsers needed + were associated with the TraceLog instance. + + + + + + Returns a provider name for events in this TraceEventCounts. It may return a string with a GUID or even + UnknownProvider for classic ETW if the event is unknown to the TraceLog. + + + + + Returns a name for events in this TraceEventCounts. If the event is unknown to the Tracelog + it will return EventID(XXX) (for manifest based events) or Task(XXX)/Opcode(XXX) (for classic events) + + + + + Returns the payload names associated with this Event type. Returns null if the payload names are unknown. + + + + + Returns true the provider associated with this TraceEventCouts is a classic (not manifest based) ETW provider. + + + + + Returns the provider GUID of the events in this TraceEventCounts. Returns Guid.Empty if IsClassic + + + + + Returns the event ID of the events in this TraceEventCounts. Returns TraceEventID.Illegal if IsClassic + + + + + Returns the Task GUID of the events in this TraceEventCounts. Returns Guid.Empty if not IsClassic + + + + + Returns the Opcode of the events in the TraceEventCounts. Returns TraceEventOpcode.Info if not IsClassic + + + + + Returns the average size of the event specific payload data (not the whole event) for all events in the TraceEventsCounts. + + + + + Returns the number of events in the TraceEventCounts. + + + + + Returns the number of events in the TraceEventCounts that have stack traces associated with them. + + + + + Returns the full name of the event (ProviderName/EventName) + + + + + An XML representation of the top level statistics of the TraceEventCounts. + + + + + + GetHashCode + + + + + A TraceEvents represents a list of TraceEvent instances. It is IEnumerable<TraceEvent> but + also has additional useful ways of filtering the list. + + Note that the TraceEvent returned from this IEnumerable may only be used for one iteration of the foreach. + (it is reused for the next event). If you need more lifetime than that you must call Clone() (see 'Lifetime + Constraints' in the programmers guide for more). + + + + + Returns a list of events in the TraceEvents that return a payload of type T. Thus + ByEventType < TraceEvent > returns all events. + + + + + Returns a TraceEventDispatcher (a push model object on which you can register + callbacks for particular events) that will push all the vents in the TraceEvents. + + Note that the TraceEvent returned from this callback may only be used for the duration of the callback. + If you need more lifetime than that you must call Clone() (see 'Lifetime Constraints' in the programmers guide for more). + + + + + Returns a new list which is the same as the TraceEvents but the events are + delivered from last to first. This allows you to search backwards in the + event stream. + + + + + Filter the events by time. Both starTime and endTime are inclusive. + + + + + Filter the events by time. StartTimeRelativeMSec and endTimeRelativeMSec are relative to the SessionStartTime and are inclusive. + + + + + Create new list of Events that has all the events in the current TraceEvents + that pass the given predicate. + + + + + Returns the TraceLog associated with the events in the TraceEvents + + + + + Returns a time that is guaranteed to be before the first event in the TraceEvents list. + It is returned as DateTime + + + + + Returns a time that is guaranteed to be before the first event in the TraceEvents list. + It is returned as floating point number of MSec since the start of the TraceLog + + + + + Returns a time that is guaranteed to be after the last event in the TraceEvents list. + It is returned as DateTime + + + + + Returns a time that is guaranteed to be after the last event in the TraceEvents list. + It is returned as floating point number of MSec since the start of the TraceLog + + + + + Each process is given a unique index from 0 to TraceProcesses.Count-1 and unlike + the OS Process ID, is unambiguous (The OS process ID can be reused after a + process dies). ProcessIndex represents this index. By using an enum rather than an int + it allows stronger typing and reduces the potential for errors. + + It is expected that users of this library might keep arrays of size TraceProcesses.Count to store + additional data associated with a process in the trace. + + + + + + Returned when no appropriate Process exists. + + + + + A TraceProcesses instance represents the list of processes in the Event log. + + TraceProcesses are IEnumerable, and will return the processes in order of creation time. + + + + + The log associated with this collection of processes. + + + + + The count of the number of TraceProcess instances in the TraceProcesses list. + + + + + Each process that occurs in the log is given a unique index (which unlike the PID is unique), that + ranges from 0 to Count - 1. Return the TraceProcess for the given index. + + + + + Given an OS process ID and a time, return the last TraceProcess that has the same process ID, + and whose process start time is less than 'timeRelativeMSec'. + + If 'timeRelativeMSec' is during the processes's lifetime this is guaranteed to be the correct process. + for the given process ID since process IDs are unique during the lifetime of the process. + + If timeRelativeMSec == TraceLog.SessionDuration this method will return the last process with + the given process ID, even if it had died during the trace. + + + + + + Returns the last process in the log with the given process ID. Useful when the logging session + was stopped just after the processes completed (a common scenario). + + + + + Find the first process in the trace that has the process name 'processName' and whose process + start time is after the given point in time. + A process's name is the file name of the EXE without the extension. + Processes that began before the trace started have a start time of 0, Thus + specifying 0 for the time will include processes that began before the trace started. + + + + + + Find the last process in the trace that has the process name 'processName' and whose process + start time is after the given point in time. + A process's name is the file name of the EXE without the extension. + Processes that began before the trace started have a start time of 0, Thus + specifying 0 for the time will include processes that began before the trace started. + + + + + + An XML representation of the TraceEventProcesses (for debugging) + + + + + Enumerate all the processes that occurred in the trace log, ordered by creation time. + + + + + Given an OS process ID and a time, return the last TraceProcess that has the same process ID, + and whose offset start time is less than 'timeQPC'. If 'timeQPC' is during the thread's lifetime this + is guaranteed to be the correct process. Using timeQPC = TraceLog.sessionEndTimeQPC will return the + last process with the given PID, even if it had died. + + + + + TraceProcesses represents the entire ETL moduleFile log. At the node level it is organized by threads. + + The TraceProcesses also is where we put various caches that are independent of the process involved. + These include a cache for TraceModuleFile that represent native images that can be loaded into a + process, as well as the process lookup tables and a cache that remembers the last calls to + GetNameForAddress(). + + + + + A TraceProcess represents a process in the trace. + + + + + The OS process ID associated with the process. It is NOT unique across the whole log. Use + ProcessIndex for that. + + + + + The index into the logical array of TraceProcesses for this process. Unlike ProcessID (which + may be reused after the process dies, the process index is unique in the log. + + + + + This is a short name for the process. It is the image file name without the path or suffix. + + + + + The command line that started the process (may be empty string if unknown) + + + + + The path name of the EXE that started the process (may be empty string if unknown) + + + + + The time when the process started. Returns the time the trace started if the process existed when the trace started. + + + + + The time when the process started. Returns the time the trace started if the process existed when the trace started. + Returned as the number of MSec from the beginning of the trace. + + + + + The time when the process ended. Returns the time the trace ended if the process existed when the trace ended. + Returned as a DateTime + + + + + The time when the process ended. Returns the time the trace ended if the process existed when the trace ended. + Returned as the number of MSec from the beginning of the trace. + + + + + The process ID of the parent process + + + + + The process that started this process. Returns null if unknown Unlike ParentID + the chain of Parent's will never form a loop. + + + + + If the process exited, the exit status of the process. Otherwise null. + + + + + The amount of CPU time spent in this process based on the kernel CPU sampling events. + + + + + Returns true if the process is a 64 bit process + + + + + The log file associated with the process. + + + + + A list of all the threads that occurred in this process. + + + + + Returns the list of modules that were loaded by the process. The modules may be managed or + native, and include native modules that were loaded event before the trace started. + + + + + Filters events to only those for a particular process. + + + + + Filters events to only that occurred during the time the process was alive. + + + + + + An XML representation of the TraceEventProcess (for debugging) + + + + + Sets the 'Parent' field for the process (based on the ParentID). + + sentinel is internal to the implementation, external callers should always pass null. + TraceProcesses that have a parent==sentinel considered 'illegal' since it woudl form + a loop in the parent chain, which we definately don't want. + + + + + Create a new TraceProcess. It should only be done by log.CreateTraceProcess because + only TraceLog is responsible for generating a new ProcessIndex which we need. 'processIndex' + is a index that is unique for the whole log file (where as processID can be reused). + + + + + This table allows us to intern codeAddress so we only at most one distinct address per process. + + + + + We also keep track of those code addresses that are NOT yet resolved to at least a File (for JIT compiled + things this would be to a method + + + + + This is all the information needed to remember about at JIT compiled method (used in the jitMethods variable) + + + + + This table has a entry for each JIT compiled method that remembers its range. It is actually only needed + for the real time case, as the non-real time case you resolve code addresses on method unload/rundown and thus + don't need to remember the information. This table is NOT persisted in the ETLX file since is only needed + to convert raw addresses into TraceMethods. + + It is a array of arrays to make insertion efficient. Most of the time JIT methods will be added in + contiguous memory (thus will be in order), however from time to time things will 'jump around' to a new + segment. By having a list of lists, (which are in order in both lists) you can efficiently (log(N)) search + as well as insert. + + + + + Maps a newly scheduled "user" activity ID to the ActivityIndex of the + Activity. This keeps track of currently created/scheduled activities + that have not started yet, and for multi-trigger events, created/scheduled + activities that have not conclusively "died" (e.g. by having their "user" + activity ID reused by another activity). + + + + + Each thread is given a unique index from 0 to TraceThreads.Count-1 and unlike + the OS Thread ID, is unambiguous (The OS thread ID can be reused after a + thread dies). ThreadIndex represents this index. By using an enum rather than an int + it allows stronger typing and reduces the potential for errors. + + It is expected that users of this library might keep arrays of size TraceThreads.Count to store + additional data associated with a process in the trace. + + + + + + Returned when no appropriate Thread exists. + + + + + A TraceThreads represents the list of threads in a process. + + + + + Enumerate all the threads that occurred in the trace log. It does so in order of their thread + offset events in the log. + + + + + The count of the number of TraceThreads in the trace log. + + + + + Each thread that occurs in the log is given a unique index (which unlike the PID is unique), that + ranges from 0 to Count - 1. Return the TraceThread for the given index. + + + + + Given an OS thread ID and a time, return the last TraceThread that has the same thread ID, + and whose start time is less than 'timeRelativeMSec'. If 'timeRelativeMSec' is during the thread's lifetime this + is guaranteed to be the correct thread. + + + + + An XML representation of the TraceThreads (for debugging) + + + + + TraceThreads represents the collection of threads in a process. + + + + + + Get the thread for threadID and timeQPC. Create if necessary. If 'isThreadCreateEvent' is true, + then force the creation of a new thread EVEN if the thread exist since we KNOW it is a new thread + (and somehow we missed the threadEnd event). Process is the process associated with the thread. + It can be null if you really don't know the process ID. We will try to fill it in on another event + where we DO know the process id (ThreadEnd event). + + + + + A TraceThread represents a thread of execution in a process. + + + + + The OS process ID associated with the process. + + + + + The index into the logical array of TraceThreads for this process. Unlike ThreadId (which + may be reused after the thread dies) the T index is unique over the log. + + + + + The process associated with the thread. + + + + + The time when the thread started. Returns the time the trace started if the thread existed when the trace started. + Returned as a DateTime + + + + + The time when the thread started. Returns the time the trace started if the thread existed when the trace started. + Returned as the number of MSec from the beginning of the trace. + + + + + The time when the thread ended. Returns the time the trace ended if the thread existed when the trace ended. + Returned as a DateTime + + + + + The time when the thread ended. Returns the time the trace ended if the thread existed when the trace ended. + Returned as the number of MSec from the beginning of the trace. + + + + + The amount of CPU time spent on this thread based on the kernel CPU sampling events. + + + + + Filters events to only those for a particular thread. + + + + + Filters events to only those that occurred during the time a the thread was alive. + + + + + REturns the activity this thread was working on at the time instant 'relativeMsec' + + + + + Represents the "default" activity for the thread, the activity that no one has set + + + + + ThreadInfo is a string that identifies the thread symbolically. (e.g. .NET Threadpool, .NET GC) It may return null if there is no useful symbolic name. + + + + + VerboseThreadName is a name for the thread including the ThreadInfo and the CPU time used. + + + + + The base of the thread's stack. This is just past highest address in memory that is part of the stack + (we don't really know the lower bound (userStackLimit is this lower bound at the time the thread was created + which is not very useful). + + + + + An XML representation of the TraceThread (for debugging) + + + + + Create a new TraceProcess. It should only be done by log.CreateTraceProcess because + only TraceLog is responsible for generating a new ProcessIndex which we need. 'processIndex' + is a index that is unique for the whole log file (where as processID can be reused). + + + + + This is a list of the activities (snippet of threads) that have run on this + thread. They are ordered by time so you can binary search for your activity based + on timestamp. + + + + + We want to have the stack for when CSwtichs BLOCK as well as when they unblock. + this variable keeps track of the last blocking CSWITCH on this thread so that we can + compute this. It is only used during generation of a TraceLog file. + + + + + TraceLoadedModules represents the collection of modules (loaded DLLs or EXEs) in a + particular process. + + + + + The process in which this Module is loaded. + + + + + Returns the module which was mapped into memory at at 'timeRelativeMSec' and includes the address 'address' + Note that Jit compiled code is placed into memory that is not associated with the module and thus will not + be found by this method. + + + + + + Returns the module representing the unmanaged load of a particular fiele at a given time. + + + + + An XML representation of the TraceLoadedModules (for debugging) + + + + + Returns all modules in the process. Note that managed modules may appear twice + (once for the managed load and once for an unmanaged (LoadLibrary) load. + + + + + This function will find the module associated with 'address' at 'timeQPC' however it will only + find modules that are mapped in memory (module associated with JIT compiled methods will not be found). + + + + + Finds the index and module for an a given managed module ID. If not found, new module + should be inserted at index + 1; + + + + + Finds the index and module for an address that lives within the image. If the module + did not match the new entry should go at index+1. + + + + + A TraceLoadedModule represents a module (DLL or EXE) that was loaded into a process. It represents + the time that this module was mapped into the processes address space. + + + + + The address where the DLL or EXE was loaded. Will return 0 for managed modules without NGEN images. + + + + + The load time is the time the LoadLibrary was done if it was loaded from a file, otherwise is the + time the CLR loaded the module. Expressed as a DateTime + + + + + The load time is the time the LoadLibrary was done if it was loaded from a file, otherwise is the + time the CLR loaded the module. Expressed as as MSec from the beginning of the trace. + + + + + The load time is the time the FreeLibrary was done if it was unmanaged, otherwise is the + time the CLR unloaded the module. Expressed as a DateTime + + + + + The load time is the time the FreeLibrary was done if it was unmanaged, otherwise is the + time the CLR unloaded the module. Expressed as MSec from the beginning of the trace. + + + + + The process that loaded this module + + + + + An ID that uniquely identifies the module in within the process. Works for both the managed and unmanaged case. + + + + + If this managedModule was a file that was mapped into memory (eg LoadLibary), then ModuleFile points at + it. If a managed module does not have a file associated with it, this can be null. + + + + + Shortcut for ModuleFile.FilePath, but returns the empty string if ModuleFile is null + + + + + Shortcut for ModuleFile.Name, but returns the empty string if ModuleFile is null + + + + + Because .NET applications have AppDomains, a module that is loaded once from a process + perspective, might be loaded several times (once for each AppDomain) from a .NET perspective + This property returns the loadedModule record for the first such managed module + load associated with this load. + + + + + + An XML representation of the TraceLoadedModule (used for debugging) + + + + + + See IFastSerializable.ToStream. + + + + + See IFastSerializable.FromStream. + + + + + A TraceManagedModule represents the loading of a .NET module into .NET AppDomain. + It represents the time that that module an be used in the AppDomain. + + + + + The module ID that the .NET Runtime uses to identify the file (module) associated with this managed module + + + + + The Assembly ID that the .NET Runtime uses to identify the assembly associated with this managed module. + + + + + Returns true if the managed module was loaded AppDOmain Neutral (its code can be shared by all appdomains in the process. + + + + + If the managed module is an IL module that has an NGEN image, return it. + + + + + An XML representation of the TraceManagedModule (used for debugging) + + + + + CallStackIndex uniquely identifies a callstack within the log. Valid values are between 0 and + TraceCallStacks.Count-1. Thus, an array can be used to 'attach' data to a call stack. + + + + + Returned when no appropriate CallStack exists. + + + + + Call stacks are so common in most traces, that having a .NET object (a TraceEventCallStack) for + each one is often too expensive. As optimization, TraceLog also assigns a call stack index + to every call stack and this index uniquely identifies the call stack in a very light weight fashion. + + To be useful, however you need to be able to ask questions about a call stack index without creating + a TraceEventCallStack. This is the primary purpose of a TraceCallStacks (accessible from TraceLog.CallStacks). + It has a set of + methods that take a CallStackIndex and return properties of the call stack (like its caller or + its code address). + + + + + + Returns the count of call stack indexes (all Call Stack indexes are strictly less than this). + + + + + Given a call stack index, return the code address index representing the top most frame associated with it + + + + + Given a call stack index, look up the call stack index for caller. Returns CallStackIndex.Invalid at top of stack. + + + + + Given a call stack index, returns the number of callers for the call stack + + + + + Given a call stack index, returns a TraceCallStack for it. + + + + + Returns the TraceCodeAddresses instance that can resolve CodeAddressIndexes in the TraceLog + + + + + Given a call stack index, returns the ThreadIndex which represents the thread for the call stack + + + + + Given a call stack index, returns the TraceThread which represents the thread for the call stack + + + + + An XML representation of the TraceCallStacks (used for debugging) + + + + + IEnumerable Support + + + + + Used to 'undo' the effects of adding a eventToStack that you no longer want. This happens when we find + out that a eventToStack is actually got more callers in it (when a eventToStack is split). + + + + + + Returns an index that represents the 'threads' of the stack. It encodes the thread which owns this stack into this. + We encode this as -ThreadIndex - 2 (since -1 is the Invalid node) + + + + + A TraceCallStack is a structure that represents a call stack as a linked list. Each TraceCallStack + contains two properties, the CodeAddress for the current frame, and the TraceCallStack of the + caller of this frame. The Caller property will return null at the thread start frame. + + + + + Return the CallStackIndex that uniquely identifies this call stack in the TraceLog. + + + + + Returns the TraceCodeAddress for the current method frame in the linked list of frames. + + + + + The TraceCallStack for the caller of of the method represented by this call stack. Returns null at the end of the list. + + + + + The depth (count of callers) of this call stack. + + + + + An XML representation of the TraceCallStack (used for debugging) + + + + + Writes an XML representation of the TraceCallStack to the stringbuilder 'sb' + + + + + CodeAddressIndex uniquely identifies a symbolic codeAddress within the log . + Valid values are between 0 and TraceCodeAddresses.Count. Thus, an array + can be used to 'attach' data to a code address. + + + + + Returned when no appropriate Method exists. + + + + + Code addresses are so common in most traces, that having a .NET object (a TraceCodeAddress) for + each one is often too expensive. As optimization, TraceLog also assigns a code address index + to every code address and this index uniquely identifies the code address in a very light weight fashion. + + To be useful, however you need to be able to ask questions about a code address index without creating + a TraceCodeAddress. This is the primary purpose of a TraceCodeAddresses (accessible from TraceLog.CodeAddresses). + It has a set of + methods that take a CodeAddressIndex and return properties of the code address (like its method, address, and module file) + + + + + + Returns the count of code address indexes (all code address indexes are strictly less than this). + + + + + Given a code address index, return the name associated with it (the method name). It will + have the form MODULE!METHODNAME. If the module name is unknown a ? is used, and if the + method name is unknown a hexadecimal number is used as the method name. + + + + + Given a code address index, returns the virtual address of the code in the process. + + + + + Given a code address index, returns the index for the module file (representing the file's path) + + + + + Given a code address index, returns the index for the method associated with the code address (it may return MethodIndex.Invalid + if no method can be found). + + + + + Given a code address index, returns the module file (the DLL paths) associated with it + + + + + If the code address is associated with managed code, return the IL offset within the method. If the method + is unmanaged -1 is returned. To determine the IL offset the PDB for the NGEN image (for NGENed code) or the + correct .NET events (for JIT compiled code) must be present. If this information is not present -1 is returned. + + + + + Given a code address index, returns a TraceCodeAddress for it. + + + + + Returns the TraceMethods object that can look up information from MethodIndexes + + + + + Returns the TraceModuleFiles that can look up information about ModuleFileIndexes + + + + + Indicates the number of managed method records that were encountered. This is useful to understand if symbolic information 'mostly works'. + + + + + Initially CodeAddresses for unmanaged code will have no useful name. Calling LookupSymbolsForModule + lets you resolve the symbols for a particular file so that the TraceCodeAddresses for that DLL + will have Methods (useful names) associated with them. + + + + + A TraceCodeAddress can contain a method name, but does not contain number information. To + find line number information you must read the PDB again and fetch it. This is what + GetSoruceLine does. + + Given a SymbolReader (which knows how to look up PDBs) and a code address index (which + represent a particular point in execution), find a SourceLocation (which represents a + particular line number in a particular source file associated with the code address. + Returns null if anything goes wrong (and diagnostic information will be written to the + log file associated with the SymbolReader. + + + + + + The number of times a particular code address appears in the log. Unlike TraceCodeAddresses.Count, which tries + to share a code address as much as possible, TotalCodeAddresses counts the same code address in different + call stacks (and even if in the same stack) as distinct. This makes TotalCodeAddresses a better measure of + the 'popularity' of a particular address (which can factor into decisions about whether to call LookupSymbolsForModule) + + The sum of ModuleFile.CodeAddressesInModule for all modules should sum to this number. + + + + + + If set to true, will only use the name of the module and not the PDB GUID to confirm that a PDB is correct + for a given DLL. Setting this value is dangerous because it is easy for the PDB to be for a different + version of the DLL and thus give inaccurate method names. Nevertheless, if a log file has no PDB GUID + information associated with it, unsafe PDB matching is the only way to get at least some symbolic information. + + + + + Returns an XML representation of the TraceCodeAddresses (for debugging) + + + + + We expose ILToNativeMap internally so we can do diagnostics. + + + + + IEnumerable support. + + + + + Called when JIT CLR Rundown events are processed. It will look if there is any + address that falls into the range of the JIT compiled method and if so log the + symbolic information (otherwise we simply ignore it) + + + + + Adds a JScript method + + + + + Allows you to get a callback for each code address that is in the range from start to + start+length within the process 'process'. If 'considerResolved' is true' then the address range + is considered resolved and future calls to this routine will not find the addresses (since they are resolved). + + + + + Gets the symbolic information entry for 'address' which can be any address. If it falls in the + range of a symbol, then that symbolic information is returned. Regardless of whether symbolic + information is found, however, an entry is created for it, so every unique address has an entry + in this table. + + + + + All processes might have kernel addresses in them, this returns the kernel process (process ID == 0) if 'address' is a kernel address. + + + + + Sort from lowest address to highest address. + + + + + Do symbol resolution for all addresses in the log file. + + + + + Look up the SymbolModule (open PDB) for a given moduleFile. Will generate NGEN pdbs as needed. + + + + + Returns true if 'moduleFile' seems to be unchanged from the time the information about it + was generated. Logs messages to 'log' if it fails. + + + + + A CodeAddressInfo is the actual data stored in the ETLX file that represents a + TraceCodeAddress. It knows its Address in the process and it knows the + TraceModuleFile (which knows its base address), so it also knows its relative + address in the TraceModuleFile (which is what is needed to look up the value + in the PDB. + + Note that by the time that the CodeAddressInfo is persisted in the ETLX file + it no longer knows the process it originated from (thus separate processes + with the same address and same DLL file loaded at the same address can share + the same CodeAddressInfo. This is actually reasonably common, since OS tend + to load at their preferred base address. + + We also have to handle the managed case, in which case the CodeAddressInfo may + also know about the TraceMethod or the ILMapIndex (which remembers both the + method and the line numbers for managed code. + + However when the CodeAddressInfo is first created, we don't know the TraceModuleFile + so we also need to remember the Process + + + + + + This is only valid until MethodIndex or ModuleFileIndex is set. + + + + + Only for managed code. + + + + + Only for unmanaged code. TODO, this can be folded into methodOrProcessIlMap index and save a DWORD. + since if the method or IlMap is present then you can get the ModuelFile index from there. + + + + + This is a count of how many times this code address appears in any stack in the trace. + It is a measure of what popular the code address is (whether we should look up its symbols). + + + + + Find the ILToNativeMap for 'methodId' in process associated with 'processIndex' + and then remove it from the table (this is what you want to do when the method is unloaded) + + + + + Conceptually a TraceCodeAddress represents a particular point of execution within a particular + line of code in some source code. As a practical matter, they are represented two ways + depending on whether the code is managed or not. + * For native code (or NGened code), it is represented as a virtual address along with the loaded native + module that includes that address along with its load address. A code address does NOT + know its process because they can be shared among all processes that load a particular module + at a particular location. These code addresses will not have methods associated with them + unless symbols information (PDBS) are loaded for the module using the LookupSymbolsForModule. + + * For JIT compiled managed code, the address in a process is eagerly resolved into a method, module + and an IL offset and that is stored in the TraceCodeAddress. + + Sometimes it is impossible to even determine the module associated with a virtual + address in a process. These are represented as simply the virtual address. + + + Because code addresses are so numerous, consider using CodeAddressIndex instead of TraceCodeAddress + to represent a code address. Methods on TraceLog.CodeAddresses can access all the information + that would be in a TraceCodeAddress from a CodeAddressIndex without the overhead of creating + a TraceCodeAddress object. + + + + + + The CodeAddressIndex that uniquely identifies the same code address as this TraceCodeAddress + + + + + The Virtual address of the code address in the process. (Note that the process is unknown by the code address to allow for sharing) + + + + + The full name (Namespace name.class name.method name) of the method associated with this code address. + Returns the empty string if no method is associated with the code address. + + + + + Returns the TraceMethod associated with this code address or null if there is none. + + + + + If the TraceCodeAddress is associated with managed code, return the IL offset within the method. If the method + is unmanaged -1 is returned. To determine the IL offset the PDB for the NGEN image (for NGENed code) or the + correct .NET events (for JIT compiled code) must be present. If this information is not present -1 is returned. + + + + + A TraceCodeAddress can contain a method name, but does not contain number information. To + find line number information you must read the PDB again and fetch it. This is what + GetSoruceLine does. + + Given a SymbolReader (which knows how to look up PDBs) find a SourceLocation (which represents a + particular line number in a particular source file associated with the current TraceCodeAddress. + Returns null if anything goes wrong (and diagnostic information will be written to the + log file associated with the SymbolReader. + + + + + + Returns the TraceModuleFile representing the DLL path associated with this code address (or null if not known) + + + + + ModuleName is the name of the file without path or extension. + + + + + The full path name of the DLL associated with this code address. Returns empty string if not known. + + + + + The CodeAddresses container that this Code Address lives within + + + + + An XML representation for the CodeAddress (for debugging) + + + + + Writes an XML representation for the CodeAddress to the stringbuilder sb + + + + + MethodIndex uniquely identifies a method within the log. Valid values are between 0 and + TraceMethods.Count-1. Thus, an array can be used to 'attach' data to a method. + + + + + Returned when no appropriate Method exists. + + + + + Methods are so common in most traces, that having a .NET object (a TraceMethod) for + each one is often too expensive. As optimization, TraceLog also assigns a method index + to every method and this index uniquely identifies the method in a very light weight fashion. + + To be useful, however you need to be able to ask questions about a method index without creating + a TraceMethod. This is the primary purpose of a TraceMethods (accessible from TraceLog.CodeAddresses.Methods). + It has a set of + methods that take a MethodIndex and return properties of the method (like its name, and module file) + + + + + + Returns the count of method indexes. All MethodIndexes are strictly less than this. + + + + + Given a method index, if the method is managed return the IL meta data MethodToken (returns 0 for native code) + + + + + Given a method index, return the Method's RVA (offset from the base of the DLL in memory) (returns 0 for managed code) + + + + + Given a method index, return the index for the ModuleFile associated with the Method Index. + + + + + Given a method index, return the Full method name (Namespace.ClassName.MethodName) associated with the Method Index. + + + + + Given a method index, return a TraceMethod that also represents the method. + + + + + Returns an XML representation of the TraceMethods. + + + + + IEnumerable support + + + + + + A TraceMethod represents the symbolic information for a particular method. To maximizes haring a TraceMethod + has very little state, just the module and full method name. + + + + + Each Method in the TraceLog is given an index that uniquely identifies it. This return this index for this TraceMethod + + + + + The full name of the method (Namespace.ClassName.MethodName). + + + + + .Net runtime methods have a token (32 bit number) that uniquely identifies it in the meta data of the managed DLL. + This property returns this token. Returns 0 for unmanaged code or method not found. + + + + + For native code the RVA (relative virtual address, which is the offset from the base of the file in memory) + for the method in the file. Returns 0 for managed code or method not found; + + + + + Returns the index for the DLL ModuleFile (which represents its file path) associated with this method + + + + + Returns the ModuleFile (which represents its file path) associated with this method + + + + + A XML representation of the TraceMethod. (Used for debugging) + + + + + + Writes an XML representation of the TraceMethod to the stringbuilder 'sb' + + + + + + + A ModuleFileIndex represents a particular file path on the disk. It is a number + from 0 to MaxModuleFileIndex, which means that you can create a side array to hold + information about module files. + + You can look up information about the ModuleFile from the ModuleFiles type. + + + + + Returned when no appropriate ModuleFile exists. + + + + + TraceModuleFiles is the list of all the ModuleFiles in the trace. It is an IEnumerable. + + + + + Each file is given an index for quick lookup. Count is the + maximum such index (thus you can create an array that is 1-1 with the + files easily). + + + + + Given a ModuleFileIndex, find the TraceModuleFile which also represents it + + + + + Returns the TraceLog associated with this TraceModuleFiles + + + + + Returns an XML representation of the TraceModuleFiles + + + + + Enumerate all the files that occurred in the trace log. + + + + + We cache information about a native image load in a TraceModuleFile. Retrieve or create a new + cache entry associated with 'nativePath' and 'moduleImageBase'. 'moduleImageBase' can be 0 for managed assemblies + that were not loaded with LoadLibrary. + + + + + For a given file name, get the TraceModuleFile associated with it. + + + + + The TraceModuleFile represents a executable file that can be loaded into memory (either an EXE or a + DLL). It represents the path on disk as well as the location in memory where it loads (or + its ModuleID if it is a managed module), but not the load or unload time or the process in which + it was loaded (this allows them to be shared within the trace). + + + + + The ModuleFileIndex ID that uniquely identifies this module file. + + + + + The moduleFile name associated with the moduleFile. May be the empty string if the moduleFile has no moduleFile + (dynamically generated). For managed code, this is the IL moduleFile name. + + + + + This is the short name of the moduleFile (moduleFile name without extension). + + + + + Returns the address in memory where the dll was loaded. + + + + + Returns the size of the DLL when loaded in memory + + + + + Returns the address just past the memory the module uses. + + + + + The name of the symbol file (PDB file) associated with the DLL + + + + + Returns the GUID that uniquely identifies the symbol file (PDB file) for this DLL + + + + + Returns the age (which is a small integer), that is also needed to look up the symbol file (PDB file) on a symbol server. + + + + + Returns the file version string that is optionally embedded in the DLL's resources. Returns the empty string if not present. + + + + + Returns the product name recorded in the file version information. Returns empty string if not present + + + + + Returns a version string for the product as a whole (could include GIT source code hash). Returns empty string if not present + + + + + This is the checksum value in the PE header. Can be used to validate + that the file on disk is the same as the file from the trace. + + + + + This used to be called TimeDateStamp, but linkers may not use it as a + timestamp anymore because they want deterministic builds. It still is + useful as a unique ID for the image. + + + + + If the Product Version fields has a GIT Commit Hash component, this returns it, Otherwise it is empty. + + + + + Returns the time the DLL was built as a DateTime. Note that this may not + work if the build system uses deterministic builds (in which case timestamps + are not allowed. We may not be able to tell if this is a bad timestamp + but we include it because when it is timestamp it is useful. + + + + + The number of code addresses included in this module. This is useful for determining if + this module is worth having its symbolic information looked up or not. It is not + otherwise a particularly interesting metric. + + This number is defined as the number of appearances this module has in any stack + or any event with a code address (If the modules appears 5 times in a stack that + counts as 5 even though it is just one event's stack). + + + + + + If the module file was a managed native image, this is the IL file associated with it. + + + + + Returns an XML representation of the TraceModuleFile (for debugging) + + + + + A ActivityIndex uniquely identifies an Activity in the log. Valid values are between + 0 and Activities.Count-1. + + + + + valid activity indexes are non-negative integers + + + + + Representation of an Activity. An activity can be thought of as a unit of execution associated with + a task or workitem; it executes on one thread, and has a start and end time. An activity keeps track + of its "creator" or "caller" -- which is the activity that scheduled it. Using the "creator" link a + user can determine the chain of activities that led up to the current one. + + Given an event you can get the Activity for the event using the Activity() extension method. + + + + + Describes the kinds of known Activities (used for descriptive purposes alone) + + + + Invalid + + + + Default activity on a thread (when the thread does not execute any code on + behalf of anyone else) + + + + + An activity that was initiated by a Task.Run + + + + + An activity that's a task, but for which we didn't see a "Scheduled" event + + + + + An activity that allows correlation between the antecedent and continuation + + + + A thread started with Thread.Start + + + Native CLR threadpool workitem + + + Native CLR IO threadpool workitem + + + Managed threadpool workitem + + + Generic managed thread transfer + + + Managed async IO workitem + + + WinRT Dispatched workitem + + + + Used when we make up ones because we know that have to be there but we don't know enough to do more than that. + + + + + An activity that allows correlation between the antecedent and continuation + if have bit 5 set it means you auto-compete + + + + + Same as TaskWait, hwoever it auto-completes + + + + + Managed timer workitem + + + + A trace-wide unique id identifying an activity + + + The activity that initiated or caused the current one + + + + This return an unique string 'name' for the activity. It is a the Index followed by + a - followed by the TPL index (if available). It is a bit nicer since it gives + more information for debugging. + + + + + Computes the creator path back to root. + + + + The thread on which the activity is running + + + True if there may be multiple activities that were initiated by caller (e.g. managed Timers) + + + A descriptive label for the activity + TODO: eliminate and use ToString()? + + + + + A thread activity is the activity associate with an OS thread. It is special because it may + have a region that is disjoint. + + + + Time from beginning of trace (in msec) when activity started executing + + + Time from beginning of trace (in msec) when activity completed execution. Does not include children. + + + The event index of the TraceEvent instance that created/scheduled this activity + + + The call stack index of the TraceEvent instance that scheduled (caused the creation of) the activity + + + Time from beginning of trace (in msec) when activity was scheduled + + + + To use mainly for debugging + + + + + TraceLogOptions control the generation of a TraceLog (ETLX file) from an ETL file. + + + + + Creates a new object containing options for constructing a TraceLog file. + + + + + If non-null, this is a predicate that, given a file path to a dll, answers the question + whether the PDB associated with that DLL be looked up and its symbolic information added + to the TraceLog file as part of conversion. Symbols can be looked up afterward when + the file is later opened, so the default (which is to look up no symbols during + conversion) is typically OK. + + + + + Resolving symbols from a symbol server can take a long time. If + there is a DLL that always fails, it can be quite annoying because + it will always cause delays, By specifying only local symbols it + will only resolve the symbols if it can do so without the delay of network traffic. + Symbols that have been previously cached locally from a symbol + server count as local symbols. + + + + + By default symbols are only resolved if there are stacks associated with the trace. + Setting this option forces resolution even if there are no stacks. + + + + + Writes status to this log. Useful for debugging symbol issues. + + + + + If ConversionLogName is set, it indicates that any messages associated with creating the TraceLog should be written here. + + + + + ETL files typically contain a large number of 'bookkeeping' event for resolving names of files, or methods or to indicate information + about processes that existed when the trace was started (DCStart and DCStop events). By default these events are stripped from + the ETLX file because their information has already been used to do the bookkeeping as part of the conversion + + However sometimes it is useful to keep these events (typically for debugging TraceEvent itself) and setting this + property to true will cause every event in the ETL file to be copied as an event to the ETLX file. + + + + + + Sometimes ETL files are too big , and you just want to look at a fraction of it to speed things up + (or to keep file size under control). The MaxEventCount property allows that. 10M will produce a 3-4GB ETLX file. + 1M is a good value to keep ETLX file size under control. Note that that the conversion still scan the entire + original ETL file too look for bookkeeping events, however MaxEventCount events will be transfered to the ETLX + file as events. + + The default is 10M because ETLX has a restriction of 4GB in size. + + + + + + If an ETL file has too many events for efficient processing the first part of the trace can be skipped by setting this + property. Any event which happens before 'SkipMSec' into the session will be filtered out. This property is + intended to be used along with the MaxEventCount property to carve out a arbitrary chunk of time from an ETL + file as it is converted to an ETLX file. + + + + + If this delegate is non-null, it is called if there are any lost events or if the file was truncated. + It is passed a bool whether the ETLX file was truncated, as well as the number of lost events and the + total number of events in the ETLX file. You can throw if you want to abort. + + + + + If you have the manifests for particular providers, you can read them in explicitly by setting this directory. + All files of the form *.manifest.xml will be read into the DynamicTraceEventParser's database before conversion + starts. + + + + + If errors occur during conversion, just assume the traced ended at that point and continue. + + + + + The TraceEvent instances returned during the processing of a TraceLog have additional capabilities that these extension methods can access. + + + + + Finds the TraceProcess associated with a TraceEvent. + Guaranteed to be non-null for non-real-time sessions if the process ID is != -1 + + + + + Finds the TraceThread associated with a TraceEvent. + Guaranteed to be non-null for non-real-time sessions if the process ID is != -1 + + + + + Finds the TraceLog associated with a TraceEvent. + + + + + Finds the TraceCallStack associated with a TraceEvent. Returns null if the event does not have callstack. + + + + + Finds the CallStack index associated with a TraceEvent. Returns Invalid if the event does not have callstack. + + + + + Finds the CallStack index associated the blocking thread for CSwitch event + + + + + Finds the TraceCallStacks associated with a TraceEvent. + + + + + Finds the Activity associated with a TraceEvent + + + + + Finds the ActivityIndex associated with a TraceEvent + + + + + For a PageFaultTraceData event, gets the TraceCodeAddress associated with the ProgramCounter address. + + + + + For a PageFaultTraceData event, gets the CodeAddressIndex associated with the ProgramCounter address. + + + + + For a SampledProfileTraceData event, gets the TraceCodeAddress associated with the InstructionPointer address. + + + + + For a SampledProfileTraceData event, gets the CodeAddressIndex associated with the InstructionPointer address. + + + + + For a SysCallEnterTraceData event, gets the CodeAddressIndex associated with the SysCallAddress address. + + + + + For a PMCCounterProfTraceData event, gets the TraceCodeAddress associated with the InstructionPointer address. + + + + + For a PMCCounterProfTraceData event, gets the CodeAddressIndex associated with the InstructionPointer address. + + + + + For a ISRTraceData event, gets the CodeAddressIndex associated with the Routine address. + + + + + For a DPCTraceData event, gets the CodeAddressIndex associated with the Routine address. + + + + + TraceLoggingEvnetId is a class that manages assigning event IDs (small 64k numbers) + to TraceLogging Style events (which don't have them). Because TraceEvent uses EventIDs + so fundamentally this deficiency is very problematic. + + Arguably this should have been done by the ETW system itself. + + You use it by calling TestForTraceLoggingEventAndFixupIfNeeded on eventRecords. + You also have to explicitly call 'Dispose' when you are done with this class. + + + + + Checks to see if eventRecord has TraceLogging meta data associated with it (EVENT_HEADER_EXT_TYPE_EVENT_SCHEMA_TL) + and if so updates EventHeader.Id to be an event ID unique to that provider/opcode/meta-data blob. + + + + + cleans up native memory allocated by this routine. + + + + + Checks to see if this event has TraceLogging meta data associated with it (EVENT_HEADER_EXT_TYPE_EVENT_SCHEMA_TL) + and if so updates EventHeader.Id to be an event ID unique to that provider/opcode/meta-data blob. + + + + + given that 'eventRecord' is a TraceLogging event (with meta-data 'metaData'), return a eventID that is unique + to that provider/opcode/meta-data blob. + + + + + ProviderMetaDataKey is what we use to look up TraceLogging meta-data. It is + basically just GUID (representing the provider) an opcode (start/stop) and + a blob (representing the TraceLogging meta-data for an event) that knows how to + compare itself so it can be a key to a hash table. + + + + + A HistoryDictionary is designed to look up 'handles' (pointer sized quantities), that might get reused + over time (eg Process IDs, thread IDs). Thus it takes a handle AND A TIME, and finds the value + associated with that handle at that time. + + + + + Adds the association that 'id' has the value 'value' from 'startTime100ns' ONWARD until + it is supersede by the same id being added with a time that is after this. Thus if + I did Add(58, 1000, MyValue1), and add(58, 500, MyValue2) 'TryGetValue(58, 750, out val) will return + MyValue2 (since that value is 'in force' between time 500 and 1000. + + + + + Remove all entries associated with a given key (over all time). + + + + + ZippedETLWriter is a helper class used to compress ETW data (ETL files) + along with symbolic information (e.g. NGEN pdbs), as well as other optional + metadata (e.g. collection log files), into a single archive ready for + transfer to another machine. + + + + + Declares the intent to write a new ZIP archive that will + contain ETW file 'etlFilePath' in it as well as symbolic information (NGEN + pdbs) and possibly other information. log is a Text stream to send detailed + information to. + + This routine assumes by default (unless Merge is set to false) that the ETL + file needs to be merged before it is archived. It will also generate all + the NGEN pdbs needed for the archive. + + + You must call the WriteArchive method before any operations actually happen. + Up to that point is is just remembering instructions for WriteArchive to + follow. + + + + + + This is the name of the output archive. By default is the same as the ETL file name + with a .zip' suffix added (thus it will typically be .etl.zip). + + + + + If set this is where messages about progress and detailed error information goes. + While you dont; have to set this, it is a good idea to do so. + + + + + By default ZippedETL file will zip the ETL file itself and the NGEN pdbs associated with it. + You can add additional files to the archive by calling AddFile. In specififed 'archivePath' + is the path in the archive and defaults to just the file name of the original file path. + + + + + Actually do the work specified by the ZippedETLWriter constructors and other methods. + + + + + This is the symbol reader that is used to generate the NGEN Pdbs as needed + If it is not specififed one is created on the fly. + + + + + By default the ETL file is merged before being added to the archive. If + this is not necessary, you can set this to false. + + + + + Uses a compressed format for the ETL file. Normally off. + + + + + By default the symbol files (PDBs) are included in the ZIP file. If this + is not desired for whatever reason, this property can be set to false. + + + + + Do the work at low priority so as to avoid impacting the system. + + + + + Normally WriteArchive creates a ZIP archive. However it is possible that you only wish + to do the merging and NGEN symbol generation. Setting this property to false + will supress the final ZIP operation. + + + + + Normally if you ZIP you will delete the original ETL file. Setting this to false overrides this. + + + + + Returns the list of path names to the NGEN pdbs for any NGEN image in 'etlFile' that has + any samples in it. + + + + + ZippedETLReader is a helper class that unpacks the ZIP files generated + by the ZippedETLWriter class. It can be smart about placing the + symbolic information in these files on the SymbolReader's path so that + symbolic lookup 'just works'. + + + + + Declares the intent to unzip an .ETL.ZIP file that contain an compressed ETL file + (and NGEN pdbs) from the archive at 'zipFilePath'. If present, messages about + the unpacking go to 'log'. Note that this unpacking only happens when the + UnpackArchive() method is called. + + + + + If set messages about unpacking go here. + + + + + The name of the ETL file to extract (it is an error if there is not exactly 1). + If not present it is derived by changing the extension of the zip archive. + + + + + Where to put the symbols. + + + + + After setting any properties to override default behavior, calling this method + will actually do the unpacking. + + + + + A NativeSymbolModule represents symbol information for a native code module. + NativeSymbolModules can potentially represent Managed modules (which is why it is a subclass of that interface). + + NativeSymbolModule should just be the CONTRACT for Native Symbols (some subclass implements + it for a particular format like Windows PDBs), however today because we have only one file format we + simply implement Windows PDBS here. This can be factored out of this class when we + support other formats (e.g. Dwarf). + + To implmente support for Windows PDBs we use the Debug Interface Access (DIA). See + http://msdn.microsoft.com/library/x93ctkx8.aspx for more. I have only exposed what + I need, and the interface is quite large (and not super pretty). + + + + + Returns the name of the type allocated for a given relative virtual address. + Returns null if the given rva does not match a known heap allocation site. + + + + + Finds a (method) symbolic name for a given relative virtual address of some code. + Returns an empty string if a name could not be found. + + + + + Finds a (method) symbolic name for a given relative virtual address of some code. + Returns an empty string if a name could not be found. + symbolStartRva is set to the start of the symbol start + + + + + Fetches the source location (line number and file), given the relative virtual address (RVA) + of the location in the executable. + + + + + This overload of SourceLocationForRva like the one that takes only an RVA will return a source location + if it can. However this version has additional support for NGEN images. In the case of NGEN images + for .NET V4.6.1 or later), the NGEN images can't convert all the way back to a source location, but they + can convert the RVA back to IL artifacts (ilAssemblyName, methodMetadataToken, iloffset). THese can then + be used to look up the source line using the IL PDB. + + Thus if the return value from this is null, check to see if the ilAssemblyName is non-null, and if not + you can look up the source location using that information. + + + + + Managed code is shipped as IL, so RVA to NATIVE mapping can't be placed in the PDB. Instead + what is placed in the PDB is a mapping from a method's meta-data token and IL offset to source + line number. Thus if you have a metadata token and IL offset, you can again get a source location + + + + + The symbol representing the module as a whole. All global symbols are children of this symbol + + + + + The a unique identifier that is used to relate the DLL and its PDB. + + + + + Along with the PdbGuid, there is a small integer + call the age is also used to find the PDB (it represents the different + post link transformations the DLL has undergone). + + + + + A source file represents a source file from a PDB. This is not just a string + because the file has a build time path, a checksum, and it needs to be 'smart' + to copy down the file if requested. + + TODO We don't need this subclass. We can have SourceFile simply a container + that holds the BuildTimePath, hashType and hashValue. The lookup of the + source can then be put on NativeSymbolModule and called from SourceFile generically. + This makes the different symbol files more simmilar and is a nice simplification. + + + + + If the source file is directly available on the web (that is there is a Url that + can be used to fetch it with HTTP Get), then return that Url. If no such publishing + point exists this property will return null. + + + + + Try to fetch the source file associated with 'buildTimeFilePath' from the symbol server + information from the PDB from 'pdbPath'. Will return a path to the returned file (uses + SourceCacheDirectory associated symbol reader for context where to put the file), + or null if unsuccessful. + + There is a tool called pdbstr associated with srcsrv that basically does this. + pdbstr -r -s:srcsrv -p:PDBPATH + will dump it. + + The basic flow is + + There is a variables section and a files section + + The file section is a list of items separated by *. The first is the path, the rest are up to you + + You form a command by using the SRCSRVTRG variable and substituting variables %var1 where var1 is the first item in the * separated list + There are special operators %fnfile%(XXX), etc that manipulate the string XXX (get file name, translate \ to / ... + + If what is at the end is a valid URL it is looked up. + + + + + Parse the 'srcsrv' stream in a PDB file and return the target for SourceFile + represented by the 'this' pointer. This target is iether a ULR or a local file + path. + + You can dump the srcsrv stream using a tool called pdbstr + pdbstr -r -s:srcsrv -p:PDBPATH + + The target in this stream is called SRCSRVTRG and there is another variable SRCSRVCMD + which represents the command to run to fetch the soruce into SRCSRVTRG + + To form the target, the stream expect you to private a %targ% variable which is a directory + prefix to tell where to put the source file being fetched. If the source file is + available via a URL this variable is not needed. + + ********* This is a typical example of what is in a PDB with source server information. + SRCSRV: ini ------------------------------------------------ + VERSION=3 + INDEXVERSION=2 + VERCTRL=Team Foundation Server + DATETIME=Thu Mar 10 16:15:55 2016 + SRCSRV: variables ------------------------------------------ + TFS_EXTRACT_CMD=tf.exe view /version:%var4% /noprompt "$%var3%" /server:%fnvar%(%var2%) /output:%srcsrvtrg% + TFS_EXTRACT_TARGET=%targ%\%var2%%fnbksl%(%var3%)\%var4%\%fnfile%(%var1%) + VSTFDEVDIV_DEVDIV2=http://vstfdevdiv.redmond.corp.microsoft.com:8080/DevDiv2 + SRCSRVVERCTRL=tfs + SRCSRVERRDESC=access + SRCSRVERRVAR=var2 + SRCSRVTRG=%TFS_extract_target% + SRCSRVCMD=%TFS_extract_cmd% + SRCSRV: source files --------------------------------- ------ + f:\dd\externalapis\legacy\vctools\vc12\inc\cvconst.h*VSTFDEVDIV_DEVDIV2*/DevDiv/Fx/Rel/NetFxRel3Stage/externalapis/legacy/vctools/vc12/inc/cvconst.h*1363200 + f:\dd\externalapis\legacy\vctools\vc12\inc\cvinfo.h*VSTFDEVDIV_DEVDIV2*/DevDiv/Fx/Rel/NetFxRel3Stage/externalapis/legacy/vctools/vc12/inc/cvinfo.h*1363200 + f:\dd\externalapis\legacy\vctools\vc12\inc\vc\ammintrin.h*VSTFDEVDIV_DEVDIV2*/DevDiv/Fx/Rel/NetFxRel3Stage/externalapis/legacy/vctools/vc12/inc/vc/ammintrin.h*1363200 + SRCSRV: end ------------------------------------------------ + + ********* And here is a more modern one where the source code is available via a URL. + SRCSRV: ini ------------------------------------------------ + VERSION=2 + INDEXVERSION=2 + VERCTRL=http + SRCSRV: variables ------------------------------------------ + SRCSRVTRG=https://nuget.smbsrc.net/src/%fnfile%(%var1%)/%var2%/%fnfile%(%var1%) + SRCSRVCMD= + SRCSRVVERCTRL=http + SRCSRV: source files --------------------------------------- + c:\Users\rafalkrynski\Documents\Visual Studio 2012\Projects\DavidSymbolSourceTest\DavidSymbolSourceTest\Demo.cs*SQPvxWBMtvANyCp8Pd3OjoZEUgpKvjDVIY1WbaiFPMw= + SRCSRV: end ------------------------------------------------ + + + returns the target source file path + returns the command to fetch the target source file + Specify the value for %targ% variable. This is the + directory where source files can be fetched to. Typically the returned file is under this directory + If the value is null, %targ% variable be emtpy. This assumes that the resulting file is something + that does not need to be copied to the machine (either a URL or a file that already exists) + + + + Returns the location of the tf.exe executable or + + + + + + Gets the 'srcsvc' data stream from the PDB and return it in as a string. Returns null if it is not present. + + There is a tool called pdbstr associated with srcsrv that basically does this. + pdbstr -r -s:srcsrv -p:PDBPATH + will dump it. + + + + + For Project N modules it returns the list of pre merged IL assemblies and the corresponding mapping. + + + + + For ProjectN modules, gets the merged IL image embedded in the .PDB (only valid for single-file compilation) + + + + + For ProjectN modules, gets the pseudo-assembly embedded in the .PDB, if there is one. + + + + + + For ProjectN modules, gets the binary blob that describes the mapping from RVAs to methods. + + + + + For ProjectN modules, gets the binary blob that describes the mapping from RVAs to types. + + + + + + This static class contains the GetTypeName method for retrieving the type name of + a heap allocation site. + + See https://github.com/KirillOsenkov/Dia2Dump/blob/master/PrintSymbol.cpp for more details + + + + + Represents a single symbol in a PDB file. + + + + + The name for the symbol + + + + + The relative virtual address (offset from the image base when loaded in memory) of the symbol + + + + + The length of the memory that the symbol represents. + + + + + A small integer identifier tat is unique for that symbol in the DLL. + + + + + Decorated names are names that most closely resemble the source code (have overloading). + However when the linker does not directly support all the expressiveness of the + source language names are encoded to represent this. This return this encoded name. + + + + + Returns true if the two symbols live in the same linker section (e.g. text, data ...) + + + + + Returns the children of the symbol. Will return null if there are no children. + + + + + Returns the children of the symbol, with the given tag. Will return null if there are no children. + + + + + Compares the symbol by their relative virtual address (RVA) + + + + + override + + + + + SymPath is a class that knows how to parse _NT_SYMBOL_PATH syntax. + + + + + This allows you to set the _NT_SYMBOL_PATH as a from the windows environment. + + + + + This 'cleans up' a symbol path. In particular + Empty ones are replaced with good defaults (symweb or msdl) + All symbol server specs have local caches (%Temp%\SymbolCache if nothing else is specified). + + Note that this routine does NOT update _NT_SYMBOL_PATH. + + + + + Returns the string representing a symbol path for the 'standard' Microsoft symbol servers. + This returns the public msdl.microsoft.com server if outside Microsoft. + + + + + Create an empty symbol path + + + + + Create a symbol that represents 'path' (the standard semicolon separated list of locations) + + + + + Returns the List of elements in the symbol path. + + + + + Append all the elements in the semicolon separated list, 'path', to the symbol path represented by 'this'. + returns the 'this' pointer + + + + + append a new symbol path element to the beginning of the symbol path represented by 'this'. + returns the 'this' pointer + + + + + insert all the elements in the semicolon separated list, 'path' to the beginning of the symbol path represented by 'this'. + returns the 'this' pointer + + + + + insert a new symbol path element to the beginning of the symbol path represented by 'this'. + returns the 'this' pointer + + + + + If you need to cache files locally, put them here. It is defined + to be the first local path of a SRV* qualification or %TEMP%\SymbolCache + if not is present. + + + + + People can use symbol servers without a local cache. This is bad, add one if necessary. + + + + + Removes all references to remote paths. This insures that network issues don't cause grief. + + + + + Create a new symbol path which first search all machine local locations (either explicit location or symbol server cache locations) + followed by all non-local symbol server. This produces better behavior (If you can find it locally it will be fast) + + + + + Returns the string representation (semicolon separated) for the symbol path. + + + + + + Writes an XML representation of the symbol path to 'writer' + + + + + Checks to see 'computerName' exists (there is a Domain Names Service (DNS) reply to it) + This routine times out relative quickly (after 700 msec) if there is a problem reaching + the computer, and returns false. + + + + + This is the backing field for the lazily-computed property. + + + + + SymPathElement represents the text between the semicolons in a symbol path. It can be a symbol server specification or a simple directory path. + + SymPathElement follows functional conventions. After construction everything is read-only. + + + + + Returns true if this element of the symbol server path a symbol server specification + + + + + Returns the local cache for a symbol server specification. returns null if not specified + + + + + Returns location to look for symbols. This is either a directory specification or an URL (for symbol servers) + This can be null if it is not specified (for cache-only paths). + + + + + IsRemote returns true if it looks like the target is not on the local machine. + + + + + Returns the string repsentation for the symbol server path element (e.g. SRV*c:\temp*\\symbols\symbols) + + + + + Implements object interface + + + + + Implements object interface + + + + + A symbol reader represents something that can FIND pdbs (either on a symbol server or via a symbol path) + Its job is to find a full path a PDB. Then you can use OpenSymbolFile to get a SymbolReaderModule and do more. + + + + + Opens a new SymbolReader. All diagnostics messages about symbol lookup go to 'log'. + + + + + Finds the symbol file for 'exeFilePath' that exists on the current machine (we open + it to find the needed info). Uses the SymbolReader.SymbolPath (including Symbol servers) to + look up the PDB, and will download the PDB to the local cache if necessary. It will also + generate NGEN pdbs into the local symbol cache unless SymbolReaderFlags.NoNGenPDB is set. + + By default for NGEN images it returns the NGEN pdb. However if 'ilPDB' is true it returns + the IL PDB. + + Returns null if the pdb can't be found. + + + + + Find the complete PDB path, given just the simple name (filename + pdb extension) as well as its 'signature', + which uniquely identifies it (on symbol servers). Uses the SymbolReader.SymbolPath (including Symbol servers) to + look up the PDB, and will download the PDB to the local cache if necessary. + + A Guid of Empty, means 'unknown' and will match the first PDB that matches simple name. Thus it is unsafe. + + Returns null if the PDB could not be found + + The name of the PDB file (we only use the file name part) + The GUID that is embedded in the DLL in the debug information that allows matching the DLL and the PDB + Tools like BBT transform a DLL into another DLL (with the same GUID) the 'pdbAge' is a small integers + that indicates how many transformations were done + If you know the path to the DLL for this pdb add it here. That way we can probe next to the DLL + for the PDB file. + This is an optional string that identifies the file version (the 'Version' resource information. + It is used only to provided better error messages for the log. + + + + This API looks up an executable file, by its build-timestamp and size (on a symbol server), 'fileName' should be + a simple name (no directory), and you need the buildTimeStamp and sizeOfImage that are found in the PE header. + + Returns null if it cannot find anything. + + + + + Given the path name to a particular PDB file, load it so that you can resolve symbols in it. + + The name of the PDB file to open. + The SymbolReaderModule that represents the information in the symbol file (PDB) + + + + Like OpenSymbolFile, which opens a PDB, but this version will fail (return null) + if it is not WindowsSymbolModule. It is a shortcut for OpenSymbolFile as NativeSymbolModule + + + + + The symbol path used to look up PDB symbol files. Set when the reader is initialized. + + + + + The paths used to look up source files. defaults to _NT_SOURCE_PATH. + + + + + Where symbols are downloaded if needed. Derived from symbol path. It is the first + directory on the local machine in a SRV*DIR*LOC spec, and %TEMP%\SymbolCache otherwise. + + + + + The place where source is downloaded from a source server. + + + + + Is this symbol reader limited to just the local machine cache or not? + + + + + We call back on this when we find a PDB by probing in 'unsafe' locations (like next to the EXE or in the Built location) + If this function returns true, we assume that it is OK to use the PDB. + + + + + If set OnSymbolFileFound will be called when a PDB file is found. + It is passed the complete local file path, the PDB Guid (may be Guid.Empty) and PDB age. + + + + + A place to log additional messages + + + + + Given a full filename path to an NGEN image, insure that there is an NGEN image for it + in the symbol cache. If one already exists, this method simply returns that. If not + it is generated and placed in the symbol cache. When generating the PDB this routine + attempt to resolve line numbers, which DOES require looking up the PDB for the IL image. + Thus routine may do network accesses (to download IL PDBs). + + Note that FindSymbolFilePathForModule calls this, so normally you don't need to call + this method directly. + + By default it places the PDB in the SymbolCacheDirectory using normal symbol server + cache conventions (PDBNAME\Guid-AGE\Name). You can override this by specifying + the outputDirectory parameter. + + The full path name of the PDB generated for the NGEN image. + + + + + Given a NGEN (or ReadyToRun) imge 'ngenImageFullPath' and the PDB path + that we WANT it to generate generate the PDB. Returns either pdbPath + on success or null on failure. + + TODO can be removed when we properly publish the NGEN pdbs as part of build. + + + + + Called when you are done with the symbol reader. Currently does nothing. + + + + + Returns true if 'filePath' exists and is a PDB that has pdbGuid and pdbAge. + if pdbGuid == Guid.Empty, then the pdbGuid and pdbAge checks are skipped. + + + + + Fetches a file from the server 'serverPath' with pdb signature path 'pdbSigPath' (concatinate them with a / or \ separator + to form a complete URL or path name). It will place the file in 'fullDestPath' It will return true if successful + If 'contentTypeFilter is present, this predicate is called with the URL content type (e.g. application/octet-stream) + and if it returns false, it fails. This insures that things that are the wrong content type (e.g. redirects to + some sort of login) fail cleanly. + + You should probably be using GetFileFromServer + + path to server (e.g. \\symbols\symbols or http://symweb) + pdb path with signature (e.g clr.pdb/1E18F3E494DC464B943EA90F23E256432/clr.pdb) + the full path of where to put the file locally + if present this allows you to filter out urls that dont match this ContentType. + + + + Build the full uri from server path and pdb index path + + + + + This just copies a stream to a file path with logging. + + + + + Looks up 'fileIndexPath' on the server 'urlForServer' (concatenate to form complete URL) copying the file to + 'targetPath' and returning targetPath name there (thus it is always a local file). Unlike GetPhysicalFileFromServer, + GetFileFromServer understands how to deal with compressed files and file.ptr (redirection). + + targetPath or null if the file cannot be found. + + + + Deduce the path to where CLR.dll (and in particular NGEN.exe live for the NGEN image 'ngenImagepath') + Returns null if it can't be found. If the NGEN image is associated with a private runtime return + that value in 'privateVerStr' + + + + + We may be a 32 bit app which has File system redirection turned on + Morph System32 to SysNative in that case to bypass file system redirection + + + + + A SymbolModule represents a file that contains symbolic information + (a Windows PDB or Portable PDB). This is the interface that is independent + of what kind of symbolic file format you use. Becase portable PDBs only + support managed code, this shared interface is by necessity the interface + for managed code only (currently only Windows PDBs support native code). + + + + + This is the EXE associated with the Pdb. It may be null or an invalid path. It is used + to help look up source code (it is implicitly part of the Source Path search) + + + + + The path name to the PDB itself. Might be empty if the symbol information is in memory. + + + + + The Guid that is used to uniquely identify the DLL-PDB pair (used for symbol servers) + + + + + Fetches the SymbolReader assoicated with this SymbolModule. This is where shared + attributes (like SourcePath, SymbolPath etc) are found. + + + + + Given a method and an IL offset, return a source location (line number and file). + Returns null if it could not find it. + + + + + If the symbol file format supports SourceLink JSON this routine should be overriden + to return it. + + + + + Return a URL for 'buildTimeFilePath' using the source link mapping (that 'GetSourceLinkJson' fetched) + Returns null if there is URL using the SourceLink + + + + + + + Parses SourceLink information and returns a list of filepath -> url Prefix tuples. + + + + + A SourceLocation represents a point in the source code. That is the file and the line number. + + + + + The source file for the code + + + + + The line number for the code. + + + + + SymbolReaderFlags indicates preferences on how aggressively symbols should be looked up. + + + + + No options this is the common case, where you want to look up everything you can. + + + + + Only fetch the PDB if it lives in the symbolCacheDirectory (is local an is generated). + This will generate NGEN pdbs unless the NoNGenPDBs flag is set. + + + + + No NGEN PDB generation. + + + + + The path of the file at the time the source file was built. We also look here when looking for the source. + + + + + If the source file is directly available on the web (that is there is a Url that + can be used to fetch it with HTTP Get), then return that Url. If no such publishing + point exists this property will return null. + + + + + This may fetch things from the source server, and thus can be very slow, which is why it is not a property. + returns a path to the file on the local machine (often in some machine local cache). + If requireChecksumMatch == false then you can see if you have an exact match by calling ChecksumMatches + (and if there is a checksum with HasChecksum). + + + + + true if the PDB has a checksum for the data in the source file. + + + + + If GetSourceFile is called and 'requireChecksumMatch' == false then you can call this property to + determine if the checksum actually matched or not. This will return true if the original + PDB does not have a checksum (HasChecksum == false) + ; + + + + Look up the source from the source server. Returns null if it can't find the source + By default this simply uses the Url to look it up on the web. If 'Url' returns null + so does this. + + + + + Given 'fileName' which is a path to a file (which may not exist), set + _filePath and _checksumMatches appropriately. Namely _filePath should + always be the 'best' candidate for the source file path (matching checksum + wins, otherwise first existing file wins). + + Returns true if we have a perfect match (no additional probing needed). + + + + + Returns true if 'filePath' matches the checksum OR we don't have a checkdum + (thus if we pass what validity check we have). + + + + + General purpose utilities dealing with archiveFile system directories. + + + + + SafeCopy sourceDirectory to directoryToVersion recursively. The target directory does + no need to exist + + + + + SafeCopy all files from sourceDirectory to directoryToVersion. If searchOptions == AllDirectories + then the copy is recursive, otherwise it is just one level. The target directory does not + need to exist. + + + + + Clean is sort of a 'safe' recursive delete of a directory. It either deletes the + files or moves them to '*.deleting' names. It deletes directories that are completely + empty. Thus it will do a recursive delete when that is possible. There will only + be *.deleting files after this returns. It returns the number of files and directories + that could not be deleted. + + + + + Removes the oldest directories directly under 'directoryPath' so that + only 'numberToKeep' are left. + + Directory to removed old files from. + The number of files to keep. + true if there were no errors deleting files + + + + DirectoryUtilities.GetFiles is basicaly the same as Directory.GetFiles + however it returns IEnumerator, which means that it lazy. This is very important + for large directory trees. A searchPattern can be specified (Windows wildcard conventions) + that can be used to filter the set of archiveFile names returned. + + Suggested Usage + + foreach(string fileName in DirectoryUtilities.GetFiles("c:\", "*.txt")){ + Console.WriteLine(fileName); + } + + + The base directory to enumerate + A pattern to filter the names (windows filename wildcards * ?) + Indicate if the search is recursive or not. + The enumerator for all archiveFile names in the directory (recursively). + + + + Returns a lazy enumerable for every path in 'directoryName' that matchs 'searchPattern' (default is *)MO + + + + + General purpose utilities dealing with archiveFile system files. + + + + + GetLines works much like File.ReadAllLines, however instead of returning a + array of lines, it returns a IEnumerable so that the archiveFile is not read all + at once. This allows 'foreach' syntax to be used on very large files. + + Suggested Usage + + foreach(string lineNumber in FileUtilities.GetLines("largeFile.txt")){ + Console.WriteLine(lineNumber); + } + + The base directory to enumerate. + The enumerator for all lines in the archiveFile. + + + + Given archiveFile specifications possibly with wildcards in them + Returns an enumerator that returns each expanded archiveFile name in turn. + + If searchOpt is AllDirectories it does a recursive match. + + + + + Delete works much like File.Delete, except that it will succeed if the + archiveFile does not exist, and will rename the archiveFile so that even if the archiveFile + is locked the original archiveFile variable will be made available. + + It renames the archiveFile with a '[num].deleting'. These files might be left + behind. + + It returns true if it was completely successful. If there is a *.deleting + archiveFile left behind, it returns false. + + The variable of the archiveFile to delete + + + + Try to delete 'fileName' catching any exception. Returns true if successful. It will delete read-only files. + + + + + SafeCopy sourceFile to destinationFile. If the destination exists + used ForceDelete to get rid of it first. + + + + + Moves sourceFile to destinationFile. If the destination exists + used ForceDelete to get rid of it first. + + + + + Returns true if the two file have exactly the same content (as a stream of bytes). + + + + + Utilities associated with file name paths. + + + + + Given a path and a superdirectory path relativeToDirectory compute the relative path (the path from) relativeToDirectory + + + + + General utilities associated with streams. + + + + + Open the 'fromFilePath' and write its contents to 'toStream' + + + + + Open the 'toFilePath' for writing and write the contents of 'fromStream' to it + + + + + CopyStream simply copies 'fromStream' to 'toStream' + + + + + The important thing about these general utilities is that they have only dependencies on mscorlib and + System (they can be used from anywhere). + + + + + Given an XML element, remove the closing operator for it, so you can add new child elements to it by concatination. + + + + + Given an object 'obj' do ToString() on it, and then transform it so that all speical XML characters are escaped and return the result. + If 'quote' is true also surround the resulting object with double quotes. + + + + + A shortcut for XmlEscape(obj, true) (that is ToString the object, escape XML chars, and then surround with double quotes. + + + + + Create a doubly quoted string for the decimal integer value + + + + + Create a double quoted string for the hexidecimal value of 'value' + + + + + Create a double quoted string for the hexidecimal value of 'value' + + + + + Create a double quoted string for the hexidecimal value of 'value' + + + + + Create a double quoted string for the hexidecimal value of 'value' + + + + + Used to send the rawManifest into the event stream as a series of events. + + + + + Finds native DLLS next to the managed DLL that uses them. + + + + + ManifestModule.FullyQualifiedName returns this as file path if the assembly is loaded as byte array + + + + + Loads a native DLL with a filename-extension of 'simpleName' by adding the path of the currently executing assembly + + + + + + + Gets the name of the directory containing compiled binaries (DLLs) which have the same architecture as the + currently executing process. + + + + + This is the backing field for the lazily-computed property. + + + + + A StackSource that aggregates information from other StackSources into a single unified view. + + + Each StackSource has a name associated with it. The stacks for each StackSource will be grouped under + a pseudo-frame named the same as the source name. Source names are specified on initialization. + + + + + Initialize a new AggregateStackSource. + + An IEnumerable of KeyValuePairs mapping source names to StackSources. + + + + Enumerate samples with a callback function. + + The function to call on each sample. + + + + override + + + + + Enumerate samples for a given set of scenarios with a callback function. + + The function to call on each sample. + An array of length ScenarioCount. If scenariosIncluded[i] == true, include scenario i. + + + + Override + + + + + Look up a sample by index. + + The index of the sample to look up. + + The sample, if it can be found and all sub-sources support indexing; null otherwise. + + + + + Gets the index of the caller of a given call stack. + + The call stack to look up. + The caller, if it exists, otherwise. + + + + Get the frame index of a given call stack. + + The call stack to look up. + The frame index of the call stack, if it exists, otherwise. + + + + Gets the name of a frame. + + The frame to look up. + Whether to include full module paths. + The name of the frame. + + + + The total number of call stacks in this source. + + + + + The total number of frames in this source. + + + + + The total number of samples in this source. + + + + + The names for the scenarios. + + + + + override + + + + + override + + + + + Convert a StackSourceSample produced by a sub-source into one suitable for the aggregate source. + + The StackSourceSample to convert. + A place to but the returned sampled (will become the return value). + The index of the source from which the sample came. + The converted sample. + + If ConvertSample is called again, all previous samples produced by ConvertSample may no longer be used. + + + + + Friendly names of sources. + + + Name 0 is the name of the pseudo-source, which should not be used. + + + + + The list of sources. + + + Source 0 is the pseudo-source (identical to m_pseudo). + + + + + THis is the time of the first sample. It lets us normalize the time in the sample to be relative to this. + + + + + A StackSource to generate the pseudo-frames needed to group scenarios. + + + + + Initialize a new PseudoStackSource. + + The names of the frames. + + + + Gets the CallStackIndex of the call stack corresponding to a given source. + + The index of the source to look up. + The StackSourceCallStackIndex of a stack under which to group all call stacks for that source. + + + + Gets the index of the caller of a given call stack. + + The call stack to look up. + The caller, if it exists, otherwise. + + + + Get the frame index of a given call stack. + + The call stack to look up. + The frame index of the call stack, if it exists, otherwise. + + + + Gets the name of a frame. + + The frame to look up. + Whether to include full module paths. + The name of the frame. + + + + The total number of call stacks in this source. + + + + + The total number of frames in this source. + + + + + The names of the frames that this source generates. + + + + + Extension methods for type-safe IndexMap operations on StackSource*Index enums. + + + + + This is just a class that holds data. It does nothing except support an 'update' events + + + + + Constructs a Filter parameter class with all empty properties. + + + + + Create a Filter Parameters Structure form another one + + + + + + Set a Filter Parameters Structure form another one + + + + + Fetch Name + + + + + Fetch StartTimeRelativeMSec + + + + + Fetch EndTimeRelativeMSec + + + + + Fetch MinInclusiveTimePercent + + + + + Fetch FoldRegExs + + + + + Fetch IncludeRegExs + + + + + Fetch ExcludeRegExs + + + + + Fetch GroupRegExs + + + + + Fetch TypePriority + + + + + Fetch ScenarioList + + + + + Fetch Scenarios + + + + + override + + + + + override + + + + + TODO Document + + + + + Write out the FilterParameters to XML 'writer' + + + + + Create an XML representation of FilterParams as a string + + + + + + A FilterStackSouce morphs one stack filters or groups the stacks of one stack source to form a new + stack source. It is very powerful mechanism. + + + + + Create a new FilterStackSource. + + Specifies how to filter or group the stacks + The input source to morph + How to scale the data (as time or simply by size of data) + + + + Override + + + + + Override + + + + + override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Associated with every frame is a FrameInfo which is the computed answers associated with that frame name. + We cache these and so most of the time looking up frame information is just an array lookup. + + FrameInfo contains information that is ONLY dependent on the frame name (not the stack it came from), so + entry point groups and include patterns can not be completely processed at this point. Never returns null. + + + + + Generate the stack information for 'stack' and place it in stackInfoRet. Only called by GetStackInfo. + + + + + Returns the frame information for frameIndex. Never returns null. + + + + + This is just the parsed form of a grouping specification Pat->GroupNameTemplate (it has a pattern regular + expression and a group name that can have replacements) It is a trivial class + + + + + Experimentally we are going to special case the module entry pattern. + + + + + Parses a string into the GroupPattern structure that allows it to executed (matched). + + + + + Given the name of a frame, look it up in the group patterns and morph it to its group name. + If the group that matches is a entryGroup then set 'isEntryGroup'. Will return null if + no group matches 'frameName' + + + + + Holds parsed information about patterns for groups includes, excludes or folds. + + + + + Returns the index in the 'pats' array of the first pattern that matches 'str'. Returns -1 if no match. + + + + + returns true if set1 and set1 (as returned from MatchSet) are identical + + + + + Convert a string from my regular expression format (where you only have * and { } as grouping operators + and convert them to .NET regular expressions string + + + + + FrameInfo is all the information we need to associate with an Frame ID (to figure out what group/pattern it belongs to) + This includes what group it belongs to, the include patterns it matches whether to discard or fold it. It is + all the processing we can do with JUST the frame ID. + + Note that FrameInfo is reused by multiple stacks, which means that you should NOT update fields in it after initial creation. + + + + + This is what we return to the Stack crawler, it encodes either that we should filter the sample, + fold the frame, form a group, or the frameID that we have chosen to represent the group as a whole. + + + + + Represents all accumulated information about grouping for a particular stack. Effectively this is the + 'result' of applying the grouping and filtering to a particular stack. We cache the last 100 or so + of these because stacks tend to reuse the parts of the stack close the root. + + + + + The include patterns that have been matched by some frame in this stack. (ultimately we need all bits set). + Can be null, which means the empty set. + + + + + Represents a frame that does not match any pattern. Thus the default of simply returning the frame ID is appropriate + + + + + Represents a frame that should be discarded. + + + + + Represents a frame that should be folded into its caller. + + + + + We cache information about stacks we have previously seen so we can short-circuit work. + TODO make dynamic. + + Note when this value is 4096 some memory profiles are VERY sluggish. Don't make it too + small unless it is adaptive. + + + + + A class that maps contiguous indices from various sources from and to a single range of contiguous indices. + + + This is useful for aggregating indices used, for instance, in the interface for StackSource (StackSourceCallStackIndex / + StackSourceFrameIndex) in AggregateStackSource. This is an easy way, given the incoming StackSource*Index, to find the + aggregated source to query, and the corresponding StackSource*Index to send to the source. + + + With counts [3, 7, 5]: + 1 1 1 1 1 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 = Incoming index + __0__ ______1______ ____2____ = Source number + 0 1 2|0 1 2 3 4 5 6|0 1 2 3 4 = Offset + + + + + Initialize a new IndexMap with the specified counts. + + A list mapping an index to its corresponding count. + + + + Find the source for an index. + + The aggregate index to look up. + The source that belongs to. + + + + Find the offset into a given source of a given aggregate index. + + The aggregate index to look up. + The source to find the offset into. + The offset of into . + + + + Finds the index for a given source/offset pair. + + The source number of the item. + The offset into the corresponding source for the item. + The index corresponding to the pair of and . + + + + The total number of indices in the map. + + + + + The lookup table to convert indices to source/offset pairs. + + + This contains the cumulative count of indices that occurred before each source. + The last element is the total number of indices (equal to m_range). + + + + + The total number of indices in the map. + + + + + We remember the last source we looked up and check there first very likely they are next to one another. + + + + + A finite cache based with a least recently used algorithm for replacement. + It is meant to be fast (fast as a hashtable), and space efficient (not much + over the MaxEntry key-value pairs are stored. (only 8 bytes per entry additional). + + After reaching MaxEntry entries. It uses a roughly least-recently used + algorithm to pick a entry to recycle. To stay efficient it only searches + a finite time (up to 5 entries) for a entry that is older than 1/2 of the + entries in the table. + + It has the property that if you are in the maxEntries/2 most commonly fetched + things, you very unlikely to be evicted once you are in the cache. + + + + + maxEntries currently is only set in the constructor. Thus this is a finite sized cache + but is otherwise very efficient. Currently it uses ushorts internally so the number + of entries is limited to 64K (it silently limits it if you give maxEntries > 64K). + + + + + + Fetches the value from the cache with key 'key'. Returns default(T) if not present + + + + + Fetches the value from the cache with key 'key'. Returns false if not present. + + + + + Adds 'key' with value 'value' to the cache. + + + + + Removes all entries in the cache. + + + + + Sets the maxiumum number of key-value pairs the cache will keep. (after that old ones are remvoed). + + + + + Represents a null pointer (end of a linked list) + + + + + CommandOptions is a helper class for the Command class. It stores options + that affect the behavior of the execution of ETWCommands and is passes as a + parameter to the constructor of a Command. + + It is useful for these options be be on a separate class (rather than + on Command itself), because it is reasonably common to want to have a set + of options passed to several commands, which is not easily possible otherwise. + + + + + Can be assigned to the Timeout Property to indicate infinite timeout. + + + + + CommanOptions holds a set of options that can be passed to the constructor + to the Command Class as well as Command.Run* + + + + + Return a copy an existing set of command options + + The copy of the command options + + + + Normally commands will throw if the subprocess returns a non-zero + exit code. NoThrow suppresses this. + + + + + Updates the NoThrow propery and returns the updated commandOptions. + Updated command options + + + + + ShortHand for UseShellExecute and NoWait + + + + + Updates the Start propery and returns the updated commandOptions. + + + + + Normally commands are launched with CreateProcess. However it is + also possible use the Shell Start API. This causes Command to look + up the executable differently + + + + + Updates the Start propery and returns the updated commandOptions. + + + + + Indicates that you want to hide any new window created. + + + + + Updates the NoWindow propery and returns the updated commandOptions. + + + + + Indicates that you want don't want to wait for the command to complete. + + + + + Updates the NoWait propery and returns the updated commandOptions. + + + + + Indicates that the command must run at elevated Windows privledges (causes a new command window) + + + + + Updates the Elevate propery and returns the updated commandOptions. + + + + + By default commands have a 10 minute timeout (600,000 msec), If this + is inappropriate, the Timeout property can change this. Like all + timouts in .NET, it is in units of milliseconds, and you can use + CommandOptions.Infinite to indicate no timeout. + + + + + Updates the Timeout propery and returns the updated commandOptions. + CommandOptions.Infinite can be used for infinite + + + + + Indicates the string will be sent to Console.In for the subprocess. + + + + + Updates the Input propery and returns the updated commandOptions. + + + + + Indicates the current directory the subProcess will have. + + + + + Updates the CurrentDirectory propery and returns the updated commandOptions. + + + + + Indicates the standard output and error of the command should be redirected + to a archiveFile rather than being stored in Memory in the 'Output' property of the + command. + + + + + Updates the OutputFile propery and returns the updated commandOptions. + + + + + Indicates the standard output and error of the command should be redirected + to a a TextWriter rather than being stored in Memory in the 'Output' property + of the command. + + + + + Updates the OutputStream property and returns the updated commandOptions. + + + + + Gets the Environment variables that will be set in the subprocess that + differ from current process's environment variables. Any time a string + of the form %VAR% is found in a value of a environment variable it is + replaced with the value of the environment variable at the time the + command is launched. This is useful for example to update the PATH + environment variable eg. "%PATH%;someNewPath" + + + + + Adds the environment variable with the give value to the set of + environmetn variables to be passed to the sub-process and returns the + updated commandOptions. Any time a string + of the form %VAR% is found in a value of a environment variable it is + replaced with the value of the environment variable at the time the + command is launched. This is useful for example to update the PATH + environment variable eg. "%PATH%;someNewPath" + + + + + Command represents a running of a command lineNumber process. It is basically + a wrapper over System.Diagnostics.Process, which hides the complexitity + of System.Diagnostics.Process, and knows how to capture output and otherwise + makes calling commands very easy. + + + + + The time the process started. + + + + + Returns true if the process has exited. + + + + + The time the processed Exited. (HasExited should be true before calling) + + + + + The duration of the command (HasExited should be true before calling) + + + + + The operating system ID for the subprocess. + + + + + The process exit code for the subprocess. (HasExited should be true before calling) + Often this does not need to be checked because Command.Run will throw an exception + if it is not zero. However it is useful if the CommandOptions.NoThrow property + was set. + + + + + The standard output and standard error output from the command. This + is accumulated in real time so it can vary if the process is still running. + + This property is NOT available if the CommandOptions.OutputFile or CommandOptions.OutputStream + is specified since the output is being redirected there. If a large amount of output is + expected (> 1Meg), the Run.AddOutputStream(Stream) is recommended for retrieving it since + the large string is never materialized at one time. + + + + + Returns that CommandOptions structure that holds all the options that affect + the running of the command (like Timeout, Input ...) + + + + + Run 'commandLine', sending the output to the console, and wait for the command to complete. + This simulates what batch filedo when executing their commands. It is a bit more verbose + by default, however + + The command lineNumber to run as a subprocess + Additional qualifiers that control how the process is run + A Command structure that can be queried to determine ExitCode, Output, etc. + + + + Run 'commandLine' as a subprocess and waits for the command to complete. + Output is captured and placed in the 'Output' property of the returned Command + structure. + + The command lineNumber to run as a subprocess + Additional qualifiers that control how the process is run + A Command structure that can be queried to determine ExitCode, Output, etc. + + + + Launch a new command and returns the Command object that can be used to monitor + the restult. It does not wait for the command to complete, however you + can call 'Wait' to do that, or use the 'Run' or 'RunToConsole' methods. */ + + The command lineNumber to run as a subprocess + Additional qualifiers that control how the process is run + A Command structure that can be queried to determine ExitCode, Output, etc. + + + + Create a subprocess to run 'commandLine' with no special options. + The command lineNumber to run as a subprocess + + + + + Wait for a started process to complete (HasExited will be true on return) + + Wait returns that 'this' pointer. + + + + Throw a error if the command exited with a non-zero exit code + printing useful diagnostic information along with the thrown message. + This is useful when NoThrow is specified, and after post-processing + you determine that the command really did fail, and an normal + Command.Run failure was the appropriate action. + + An additional message to print in the throw (can be null) + + + + Get the underlying process object. Generally not used. + + + + + Kill the process (and any child processses (recursively) associated with the + running command). Note that it may not be able to kill everything it should + if the child-parent' chain is broken by a child that creates a subprocess and + then dies itself. This is reasonably uncommon, however. + + + + + Put double quotes around 'str' if necessary (handles quotes quotes. + + + + + Given a string 'commandExe' look for it on the path the way cmd.exe would. + Returns null if it was not found. + + + + + requiredOSVersion is a number that is the major version * 10 + minor. Thus + Win 10 == 100 + Win 8 == 62 + Win 7 == 61 + Vista == 60 + This returns true if true OS version is >= 'requiredOSVersion + + + + + The DiaLoader class knows how to load the msdia140.dll (the Debug Access Interface) (see docs at + http://msdn.microsoft.com/en-us/library/x93ctkx8.aspx), without it being registered as a COM object. + Basically it just called the DllGetClassObject interface directly. + + It has one public method 'GetDiaSourceObject' which knows how to create a IDiaDataSource object. + From there you can do anything you need. + + In order to get IDiaDataSource3 which includes'getStreamSize' API, you need to use the + vctools\langapi\idl\dia2_internal.idl file from devdiv to produce Dia2Lib.dll + + roughly what you need to do is + copy vctools\langapi\idl\dia2_internal.idl . + copy vctools\langapi\idl\dia2.idl . + copy vctools\langapi\include\cvconst.h . + Change dia2.idl to include interface IDiaDataSource3 inside library Dia2Lib->importlib->coclass DiaSource + midl dia2_internal.idl /D CC_DP_CXX + tlbimp dia2_internal.tlb + REM result is Dia2Lib.dll + + + + + Load the msdia100 dll and get a IDiaDataSource from it. This is your gateway to PDB reading. + + + + + Used to ensure the native library is loaded at least once prior to trying to use it. No protection is + included to avoid multiple loads, but this is not a problem since we aren't trying to unload the library + after use. + + + + + PEFile is a reader for the information in a Portable Exectable (PE) FILE. This is what EXEs and DLLs are. + + It can read both 32 and 64 bit PE files. + + + + + Create a new PEFile header reader that inspects the + + + + + The Header for the PE file. This contains the infor in a link /dump /headers + + + + + Looks up the debug signature information in the EXE. Returns true and sets the parameters if it is found. + + If 'first' is true then the first entry is returned, otherwise (by default) the last entry is used + (this is what debuggers do today). Thus NGEN images put the IL PDB last (which means debuggers + pick up that one), but we can set it to 'first' if we want the NGEN PDB. + + + + + Gets the File Version Information that is stored as a resource in the PE file. (This is what the + version tab a file's property page is populated with). + + + + + For side by side dlls, the manifest that decribes the binding information is stored as the RT_MANIFEST resource, and it + is an XML string. This routine returns this. + + + + + + Returns true if this is and NGEN or Ready-to-Run image (it has precompiled native code) + + + + + Returns true if file has a managed ready-to-run image. + + + + + Gets the major and minor ready-to-run version. returns true if ready-to-run. + + + + + Closes any file handles and cleans up resources. + + + + + A PEHeader is a reader of the data at the beginning of a PEFile. If the header bytes of a + PEFile are read or mapped into memory, this class can parse it when given a poitner to it. + It can read both 32 and 64 bit PE files. + + + + + Returns a PEHeader for void* pointer in memory. It does NO validity checking. + + + + + The total s,ize of the header, including section array of the the PE header. + + + + + Given a virtual address to data in a mapped PE file, return the relative virtual address (displacement from start of the image) + + + + + Given a relative virtual address (displacement from start of the image) return the virtual address to data in a mapped PE file + + + + + Given a relative virtual address (displacement from start of the image) return a offset in the file data for that data. + + + + + Returns true if this is PE file for a 64 bit architecture. + + + + + Returns true if this file contains managed code (might also contain native code). + + + + + Returns the 'Signature' of the PE HEader PE\0\0 = 0x4550, used for sanity checking. + + + + + The machine this PE file is intended to run on + + + + + PE files have a number of sections that represent regions of memory with the access permisions. This is the nubmer of such sections. + + + + + The the PE file was created represented as the number of seconds since Jan 1 1970 + + + + + The the PE file was created represented as a DateTime object + + + + + PointerToSymbolTable (see IMAGE_FILE_HEADER in PE File spec) + + + + + NumberOfSymbols (see IMAGE_FILE_HEADER PE File spec) + + + + + SizeOfOptionalHeader (see IMAGE_FILE_HEADER PE File spec) + + + + + Characteristics (see IMAGE_FILE_HEADER PE File spec) + + + + + Magic (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MajorLinkerVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MinorLinkerVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfCode (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfInitializedData (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfUninitializedData (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + AddressOfEntryPoint (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + BaseOfCode (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + ImageBase (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SectionAlignment (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + FileAlignment (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MajorOperatingSystemVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MinorOperatingSystemVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MajorImageVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MinorImageVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MajorSubsystemVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MinorSubsystemVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + Win32VersionValue (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfImage (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfHeaders (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + CheckSum (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + Subsystem (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + DllCharacteristics (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfStackReserve (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfStackCommit (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfHeapReserve (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfHeapCommit (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + LoaderFlags (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + NumberOfRvaAndSizes (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + Returns the data directory (virtual address an blob, of a data directory with index 'idx'. 14 are currently defined. + + + + + Returns the data directory for DLL Exports see PE file spec for more + + + + + Returns the data directory for DLL Imports see PE file spec for more + + + + + Returns the data directory for DLL Resources see PE file spec for more + + + + + Returns the data directory for DLL Exceptions see PE file spec for more + + + + + Returns the data directory for DLL securiy certificates (Authenticode) see PE file spec for more + + + + + Returns the data directory Image Base Relocations (RELOCS) see PE file spec for more + + + + + Returns the data directory for Debug information see PE file spec for more + + + + + Returns the data directory for DLL Exports see PE file spec for more + + + + + Returns the data directory for GlobalPointer (IA64) see PE file spec for more + + + + + Returns the data directory for THread local storage see PE file spec for more + + + + + Returns the data directory for Load Configuration see PE file spec for more + + + + + Returns the data directory for Bound Imports see PE file spec for more + + + + + Returns the data directory for the DLL Import Address Table (IAT) see PE file spec for more + + + + + Returns the data directory for Delayed Imports see PE file spec for more + + + + + see PE file spec for more .NET Runtime infomration. + + + + + The Machine types supported by the portable executable (PE) File format + + + + + Unknown machine type + + + + + Intel X86 CPU + + + + + Intel IA64 + + + + + ARM 32 bit + + + + + Arm 64 bit + + + + + Represents a Portable Executable (PE) Data directory. This is just a well known optional 'Blob' of memory (has a starting point and size) + + + + + The start of the data blob when the file is mapped into memory + + + + + The length of the data blob. + + + + + FileVersionInfo represents the extended version formation that is optionally placed in the PE file resource area. + + + + + The verison string + + + + + A PEBuffer represents a buffer (efficient) scanner of the + + +
+
diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/OSExtensions.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/OSExtensions.dll new file mode 100644 index 0000000..49d7a56 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/OSExtensions.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/TraceReloggerLib.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/TraceReloggerLib.dll new file mode 100644 index 0000000..1a8280b Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard1.6/TraceReloggerLib.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Dia2Lib.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Dia2Lib.dll new file mode 100644 index 0000000..68b11b6 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Dia2Lib.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Microsoft.Diagnostics.FastSerialization.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Microsoft.Diagnostics.FastSerialization.dll new file mode 100644 index 0000000..56cf0d5 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Microsoft.Diagnostics.FastSerialization.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Microsoft.Diagnostics.FastSerialization.xml b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Microsoft.Diagnostics.FastSerialization.xml new file mode 100644 index 0000000..683b613 --- /dev/null +++ b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Microsoft.Diagnostics.FastSerialization.xml @@ -0,0 +1,1866 @@ + + + + Microsoft.Diagnostics.FastSerialization + + + + + A StreamLabel is a 32 bit integer that represents a position in a IStreamReader or + IStreamWriter. During writing it is generated by the IStreamWriter.GetLabel method an + consumed by the IStreamWriter.WriteLabel method. On reading you can use + IStreamReader.Current and and IStreamReader. + + + + + Represents a stream label that is not a valid value + + + + + IStreamWriter is meant to be a very simple streaming protocol. You can write integral types, + strings, and labels to the stream itself. + + IStreamWrite can be thought of a simplified System.IO.BinaryWriter, or maybe the writer + part of a System.IO.Stream with a few helpers for primitive types. + + See also IStreamReader + + + + + Write a byte to a stream + + + + + Write a short to a stream + + + + + Write an int to a stream + + + + + Write a long to a stream + + + + + Write a StreamLabel (a pointer to another part of the stream) to a stream + + + + + Write a string to a stream (supports null values). + + + + + Get the stream label for the current position (points at whatever is written next + + + + + + Write a SuffixLabel it must be the last thing written to the stream. The stream + guarantees that this value can be efficiently read at any time (probably by seeking + back from the end of the stream)). The idea is that when you generate a 'tableOfContents' + you can only do this after processing the data (and probably writing it out), If you + remember where you write this table of contents and then write a suffix label to it + as the last thing in the stream using this API, you guarantee that the reader can + efficiently seek to the end, read the value, and then goto that position. (See + IStreamReader.GotoSuffixLabel for more) + + + + IStreamReader is meant to be a very simple streaming protocol. You can read integral types, + strings, and labels to the stream itself. You can also goto labels you have read from the stream. + + IStreamReader can be thought of a simplified System.IO.BinaryReder, or maybe the reader + part of a System.IO.Stream with a few helpers for primitive types. + + See also IStreamWriter + + + + Read a byte from the stream + + + + + Read a short from the stream + + + + + Read an int from the stream + + + + + Read a long from the stream + + + + + Read a string from the stream. Can represent null strings + + + + + Read a span of bytes from the stream. + + + + + Read a StreamLabel (pointer to some other part of the stream) from the stream + + + + + Goto a location in the stream + + + + + Returns the current position in the stream. + + + + + Sometimes information is only known after writing the entire stream. This information can be put + on the end of the stream, but there needs to be a way of finding it relative to the end, rather + than from the beginning. A IStreamReader, however, does not actually let you go 'backwards' easily + because it does not guarantee the size what it writes out (it might compress). + + The solution is the concept of a 'suffixLabel' which is location in the stream where you can always + efficiently get to. + + It is written with a special API (WriteSuffixLabel that must be the last thing written. It is + expected that it simply write an uncompressed StreamLabel. It can then be used by using the + GotoSTreamLabel() method below. This goes to this well know position in the stream. We expect + this is implemented by seeking to the end of the stream, reading the uncompressed streamLabel, + and then seeking to that position. + + + + + Support for higher level operations on IStreamWriter and IStreamReader + + + + + Writes a Guid to stream 'writer' as sequence of 8 bytes + + + + + Reads a Guid to stream 'reader' as sequence of 8 bytes and returns it + + + + + Returns a StreamLabel that is the sum of label + offset. + + + + + Returns the difference between two stream labels (currently guarenteed to fit in an int) + + + + + Convenience method for skipping a a certain number of bytes in the stream. + + + + + Like a StreamLabel, a ForwardReference represents a pointer to a location in the stream. + However unlike a StreamLabel, the exact value in the stream does not need to be known at the + time the forward references is written. Instead the ID is written, and later that ID is + associated with the target location (using DefineForwardReference). + + + + + Returned when no appropriate ForwardReference exists. + + + + + #SerializerIntroduction see also #StreamLayout + + The Serializer class is a general purpose object graph serializer helper. While it does not have + any knowledge of the serialization format of individual object, it does impose conventions on how to + serialize support information like the header (which holds versioning information), a trailer (which + holds deferred pointer information), and how types are versioned. However these conventions are + intended to be very generic and thus this class can be used for essentially any serialization need. + + Goals: + * Allows full range of serialization, including subclassing and cyclic object graphs. + * Can be serialized and deserialized efficiently sequentially (no seeks MANDATED on read or + write). This allows the serializer to be used over pipes and other non-seekable devices). + * Pay for play (thus very efficient in simple cases (no subclassing or cyclic graphs). + * Ideally self-describing, and debuggable (output as XML if desired?) + + Versioning: + * We want the ability for new formats to accept old versions if objects wish to support old + formats + * Also wish to allow new formats to be read by OLD version if the new format is just an + 'extension' (data added to end of objects). This makes making new versions almost pain-free. + + Concepts: + * No-seek requirement + + The serialized form should be such that it can be deserialized efficiently in a serial fashion + (no seeks). This means all information needed to deserialize has to be 'just in time' (can't + be some table at the end). Pragmatically this means that type information (needed to create + instances), has to be output on first use, so it is available for the deserializer. + + * Laziness requirement + + While is should be possible to read the serialized for sequentially, we should also not force + it. It should be possible to have a large file that represents a persisted structure that can + be lazily brought into memory on demand. This means that all information needed to + deserialize must also be 'randomly available' and not depend on reading from the beginning. + Pragmatically this means that type information, and forward forwardReference information needs to + have a table in a well known Location at the end so that it can be found without having to + search the file sequentially. + + * Versioning requirement + + To allow OLD code to access NEW formats, it must be the case that the serialized form of + every instance knows how to 'skip' past any new data (even if it does not know its exact + size). To support this, objects have 'begin' and 'end' tags, which allows the deserializer to + skip the next object. + + * Polymorphism requirement + + Because the user of a filed may not know the exact instance stored there, in general objects + need to store the exact type of the instance. Thus they need to store a type identifier, this + can be folded into the 'begin' tag. + + * Arbitrary object graph (circularity) requirement (Forward references) + + The serializer needs to be able to serialize arbitrary object graphs, including those with + cycles in them. While you can do this without forward references, the system is more flexible + if it has the concept of a forward reference. Thus whenever a object reference is required, a + 'forward forwardReference' can be given instead. What gets serialized is simply an unique forward + reference index (index into an array), and at some later time that index is given its true + value. This can either happen with the target object is serialized (see + Serializer.Tags.ForwardDefintion) or at the end of the serialization in a forward + reference table (which allows forward references to be resolved without scanning then entire + file. + + * Contract between objects IFastSerializable.ToStream: + + The heart of the serialization and deserialization process the IFastSerializable + interface, which implements just two methods: ToStream (for serializing an object), and + FromStream (for deserializing and object). This interfaces is the mechanism by which objects + tell the serializer what data to store for an individual instance. However this core is not + enough. An object that implements IFastSerializable must also implement a default + constructor (constructor with no args), so that that deserializer can create the object (and + then call FromStream to populated it). + + The ToStream method is only responsible for serializing the data in the object, and by itself + is not sufficient to serialize an interconnected, polymorphic graph of objects. It needs + help from the Serializer and Deserialize to do this. Serializer takes on the + responsibility to deal with persisting type information (so that Deserialize can create + the correct type before IFastSerializable.FromStream is called). It is also the + serializer's responsibility to provide the mechanism for dealing with circular object graphs + and forward references. + + * Layout of a serialized object: A serialized object has the following basic format + + * If the object is the definition of a previous forward references, then the definition must + begin with a Serializer.Tags.ForwardDefintion tag followed by a forward forwardReference + index which is being defined. + * Serializer.Tags.BeginObject tag + * A reference to the SerializationType for the object. This reference CANNOT be a + forward forwardReference because its value is needed during the deserialization process before + forward references are resolved. + * All the data that that objects 'IFastSerializable.ToStream method wrote. This is the + heart of the deserialized data, and the object itself has a lot of control over this + format. + * Serializer.Tags.EndObject tag. This marks the end of the object. It quickly finds bugs + in ToStream FromStream mismatches, and also allows for V1 deserializers to skip past + additional fields added since V1. + + * Serializing Object references: + When an object forwardReference is serialized, any of the following may follow in the stream + + * Serializer.Tags.NullReference used to encode a null object forwardReference. + * Serializer.Tags.BeginObject or Serializer.Tags.ForwardDefintion, which indicates + that this the first time the target object has been referenced, and the target is being + serialized on the spot. + * Serializer.Tags.ObjectReference which indicates that the target object has already + been serialized and what follows is the StreamLabel of where the definition is. + * Serializer.Tags.ForwardReference followed by a new forward forwardReference index. This + indicates that the object is not yet serialized, but the serializer has chosen not to + immediately serialize the object. Ultimately this object will be defined, but has not + happened yet. + + * Serializing Types: + Types are simply objects of type SerializationType which contain enough information about + the type for the Deserializer to do its work (it full name and version number). They are + serialized just like all other types. The only thing special about it is that references to + types after the BeginObject tag must not be forward references. + + #StreamLayout: + The structure of the file as a whole is simply a list of objects. The first and last objects in + the file are part of the serialization infrastructure. + + Layout Synopsis + * Signature representing Serializer format + * EntryObject (most of the rest of the file) + * BeginObject tag + * Type for This object (which is a object of type SerializationType) + * BeginObject tag + * Type for SerializationType POSITION1 + * BeginObject tag + * Type for SerializationType + * ObjectReference tag // This is how our recursion ends. + * StreamLabel for POSITION1 + * Version Field for SerializationType + * Minimum Version Field for SerializationType + * FullName string for SerializationType + * EndObject tag + * Version field for EntryObject's type + * Minimum Version field for EntryObject's type + * FullName string for EntryObject's type + * EndObject tag + * Field1 + * Field2 + * V2_Field (this should be tagged so that it can be skipped by V1 deserializers. + * EndObject tag + * ForwardReferenceTable pseudo-object + * Count of forward references + * StreamLabel for forward ref 0 + * StreamLabel for forward ref 1. + * ... + * SerializationTrailer pseudo-object + * StreamLabel ForwardReferenceTable + * StreamLabel to SerializationTrailer + * End of stream + + + + + Create a serializer writes 'entryObject' to a file. + + + + + Create a serializer that writes to a . The serializer + will close the stream when it closes. + + + + + Create a serializer that writes to a . The + parameter determines whether the serializer will close the stream when it + closes. + + + + + Create a serializer that writes 'entryObject' another IStreamWriter + + + + + Write a bool to a stream + + + + + Write a byte to a stream + + + + + Write a short to a stream + + + + + Write an int to a stream + + + + + Write a long to a stream + + + + + Write a Guid to a stream + + + + + Write a string to a stream + + + + + Write a float to a stream + + + + + Write a double to a stream + + + + + Write a StreamLabel (pointer to some other part of the stream whose location is current known) to the stream + + + + + Write a ForwardReference (pointer to some other part of the stream that whose location is not currently known) to the stream + + + + + If the object is potentially aliased (multiple references to it), you should write it with this method. + + + + + To tune working set (or disk seeks), or to make the dump of the format more readable, it is + valuable to have control over which of several references to an object will actually cause it to + be serialized (by default the first encountered does it). + + WriteDefered allows you to write just a forwardReference to an object with the expectation that + somewhere later in the serialization process the object will be serialized. If no call to + WriteObject() occurs, then the object is serialized automatically before the stream is closed + (thus dangling references are impossible). + + + + + This is an optimized version of WriteObjectReference that can be used in some cases. + + If the object is not aliased (it has an 'owner' and only that owner has references to it (which + implies its lifetime is strictly less than its owners), then the serialization system does not + need to put the object in the 'interning' table. This saves a space (entries in the intern table + as well as 'SyncEntry' overhead of creating hash codes for object) as well as time (to create + that bookkeeping) for each object that is treated as private (which can add up if because it is + common that many objects are private). The private instances are also marked in the serialized + format so on reading there is a similar bookkeeping savings. + + The ultimate bits written by WritePrivateObject are the same as WriteObject. + + TODO Need a DEBUG mode where we detect if others besides the owner reference the object. + + + + + Create a ForwardReference. At some point before the end of the serialization, DefineForwardReference must be called on this value + + + + + + Define the ForwardReference forwardReference to point at the current write location. + + + + + + Write a byte preceded by a tag that indicates its a byte. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a byte. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a short. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a int. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a long. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a string. These should be read with the corresponding TryReadTagged operation + + + + + Write a byte preceded by a tag that indicates its a object. These should be read with the corresponding TryReadTagged operation + + + + + Writes the header for a skipping an arbitrary blob. THus it writes a Blob + tag and the size, and the caller must then write 'sizes' bytes of data in + some way. This allows you to create regions of arbitrary size that can + be skipped by old as well as new parsers. + + + + + + Writes an end tag (which is different from all others). This is useful + when you have a deferred region of tagged items. + + + + + Retrieve the underlying stream we are writing to. Generally the Write* methods are enough. + + + + + Completes the writing of the stream. + + + + + To help debug any serialization issues, you can write data to a side file called 'log.serialize.xml' + which can track exactly what serialization operations occurred. + + + + + Dispose pattern + + + + + Deserializer is a helper class that holds all the information needed to deserialize an object + graph as a whole (things like the table of objects already deserialized, and the list of types in + the object graph. + + see #SerializerIntroduction for more + + + + + Create a Deserializer that reads its data from a given file + + + + + Create a Deserializer that reads its data from a given System.IO.Stream. The stream will be closed when the Deserializer is done with it. + + + + + Create a Deserializer that reads its data from a given System.IO.Stream. The + parameter determines whether the deserializer will close the stream when it + closes. + + + + + Create a Deserializer that reads its data from a given IStreamReader. The stream will be closed when the Deserializer is done with it. + + + + + Returns the full name of the type of the entry object without actually creating it. + Will return null on failure. + + + + + GetEntryObject is the main deserialization entry point. The serialization stream always has an object that represents the stream as + a whole, called the entry object and this returns it and places it in 'ret' + + + + + GetEntryObject is the main deserialization entry point. The serialization stream always has an object that represents the stream as + a whole, called the entry object and this returns it and returns it + + + + + Read a bool from the stream + + + + + Read a byte from the stream + + + + + Read a short from the stream + + + + + Read an int from the stream + + + + + Read a long from the stream + + + + + Read a Guid from the stream + + + + + Read a float from the stream + + + + + Read a double from the stream + + + + + Read a string from the stream. Can represent null + + + + + d) from the stream + + + + + Read a IFastSerializable object from the stream and place it in ret + + + + + Read a IFastSerializable object from the stream and return it + + + + + Read a bool from the stream and return it + + + + + Read a byte from the stream and return it + + + + + Read a short from the stream and return it + + + + + Read an int from the stream and return it + + + + + Read a long from the stream and return it + + + + + Read a float from the stream and return it + + + + + Read a double from the stream and return it + + + + + Read in a string value and return it + + + + + Read in a StreamLabel (a pointer to some other part of the stream) and return it + + + + + Read in a ForwardReference (a pointer to some other part of the stream which was not known at the tie it was written) and return it + Use ResolveForwardReference to convert the ForwardReference to a StreamLabel + + + + + Given a forward reference find the StreamLabel (location in the stream) that it points at). + Normally this call preserves the current read location, but if you do don't care you can + set preserveCurrent as an optimization to make it more efficient. + + + + + Meant to be called from FromStream. It returns the version number of the + type being deserialized. It can be used so that new code can recognizes that it + is reading an old file format and adjust what it reads. + + + + + Meant to be called from FromStream. It returns the version number of the MinimumReaderVersion + of the type that was serialized. + + + + + The filename if read from a file or the stream name if read from a stream + + + + + If set this function is set, then it is called whenever a type name from the serialization + data is encountered. It is your you then need to look that up. If it is not present + it uses Type.GetType(string) which only checks the current assembly and mscorlib. + + + + + For every IFastSerializable object being deserialized, the Deserializer needs to create 'empty' objects + that 'FromStream' is invoked on. The Deserializer gets these 'empty' objects by calling a 'factory' + delegate for that type. Thus all types being deserialized must have a factory. + + RegisterFactory registers such a factory for particular 'type'. + + + + + For every IFastSerializable object being deserialized, the Deserializer needs to create 'empty' objects + that 'FromStream' is invoked on. The Deserializer gets these 'empty' objects by calling a 'factory' + delegate for that type. Thus all types being deserialized must have a factory. + + RegisterDefaultFactory registers a factory that is passed a type parameter and returns a new IFastSerialable object. + + + + + Try to read tagged value from the stream. If it is a tagged bool, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged byte, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged short, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged int, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged long, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged string, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read the header for a tagged blob of bytes. If Current points at a tagged + blob it succeeds and returns the size of the blob (the caller must read or skip + past it manually) If it is not a tagged blob it returns a size of 0 and resets + the read pointer to what it was before this method was called. + + + + + Try to read tagged value from the stream. If it is a tagged FastSerializable, return int in ret and return true, otherwise leave the cursor unchanged and return false + + + + + Try to read tagged value from the stream. If it is a tagged FastSerializable, return it, otherwise leave the cursor unchanged and return null + + + + + Set the read position to the given StreamLabel + + + + + Set the read position to the given ForwardReference + + + + + Returns the current read position in the stream. + + + + + Fetch the underlying IStreamReader that the deserializer reads data from + + + + + Close the IStreamReader and free resources associated with the Deserializer + + + + + When we encounter a forward reference, we can either go to the forward reference table immediately and resolve it + (deferForwardReferences == false), or simply remember that that position needs to be fixed up and continue with + the deserialization. This later approach allows 'no seek' deserialization. This variable which scheme we do. + + + + + #DeferedRegionOverview. + + A DeferedRegion help make 'lazy' objects. You will have a DeferedRegion for each block of object you + wish to independently decide whether to deserialize lazily (typically you have one per object however + in the limit you can have one per field, it is up to you). + + When you call DeferedRegion.Write you give it a delegate that will write all the deferred fields. + The Write operation will place a forward reference in the stream that skips all the fields written, + then the fields themselves, then define the forward reference. This allows readers to skip the + deferred fields. + + When you call DeferedRegion.Read you also give it a delegate that reads all the deferred fields. + However when 'Read' instead of reading the fields it + + * remembers the deserializer, stream position, and reading delegate. + * it uses the forward reference to skip the region. + + When DeferedRegion.FinishRead is called, it first checks if the region was already restored. + If not it used the information to read in the deferred region and returns. Thus this FinishRead + should be called before any deferred field is used. + + + + + see #DeferedRegionOverview. + TODO more + + + + + See overview in DeferedRegion class comment. + This call indicates that the 'fromStream' delegate can deserialize a region of the object, which + was serialized with the DeferedRegion.Write method. The read skips the data for the region (thus + no objects associated with the region are created in memory) but the deferred object remembers + 'fromStream' and will call it when 'FinishRead()' is called. + + + + + FinishRead indicates that you need to deserialize the lazy region you defined with the 'Read' method. + If the region has already been deserialized, nothing is done. Otherwise when you call this + method the current position in the stream is put back to where it was when Read was called and the + 'fromStream' delegate registered in 'Read' is called to perform the deserialization. + + + + + Returns true if the FinsihRead() has already been called. + + + + + Get the deserializer assoicated with this DeferredRegion + + + + + Get the stream position when Read was called + + + + + This helper is just here to insure that FinishRead gets inlined + + + + + A type can opt into being serializable by implementing IFastSerializable and a default constructor + (constructor that takes not arguments). + + Conceptually all clients of IFastSerializable also implement IFastSerializableVersion + however the serializer will assume a default implementation of IFastSerializableVersion (that + Returns version 1 and assumes all versions are allowed to deserialize it. + + + + + Given a Serializer, write yourself to the output stream. Conceptually this routine is NOT + responsible for serializing its type information but only its field values. However it is + conceptually responsible for the full transitive closure of its fields. + + * For primitive fields, the choice is easy, simply call Serializer.Write + * For object fields there is a choice + * If is is only references by the enclosing object (eg and therefore field's lifetime is + identical to referencing object), then the Serialize.WritePrivateObject can be + used. This skips placing the object in the interning table (that insures it is written + exactly once). + * Otherwise call Serialize.WriteObject + * For value type fields (or collections of structs), you serialize the component fields. + * For collections, typically you serialize an integer inclusiveCountRet followed by each object. + + + + + + Given a reader, and a 'this' instance, made by calling the default constructor, create a fully + initialized instance of the object from the reader stream. The deserializer provides the extra + state needed to do this for cyclic object graphs. + + Note that it is legal for the instance to cache the deserializer and thus be 'lazy' about when + the actual deserialization happens (thus large persisted strucuture on the disk might stay on the + disk). + + Typically the FromStream implementation is an exact mirror of the ToStream implementation, where + there is a Read() for every Write(). + + + + + Objects implement IFastSerializableVersion to indicate what the current version is for writing + and which readers can read the current version. If this interface is not implemented a default is + provided (assuming version 1 for writing and MinimumVersion = 0). + + By default Serializer.WriteObject will place marks when the object ends and always skip to the + end even if the FromStream did not read all the object data. This allows considerable versioning + flexibility. Simply by placing the new data at the end of the existing serialization, new versions + of the type can be read by OLD deserializers (new fields will have the value determined by the + default constructor (typically 0 or null). This makes is relatively easy to keep MinimumVersion = 0 + (the ideal case). + + + + + This is the version number for the serialization CODE (that is the app decoding the format) + It should be incremented whenever a change is made to IFastSerializable.ToStream and the format + is publicly disseminated. It must not vary from instance to instance. This is pretty straightforward. + It defaults to 0 + + + + + At some point typically you give up allowing new versions of the read to read old wire formats + This is the Minimum version of the serialized data that this reader can deserialize. Trying + to read wire formats strictly smaller (older) than this will fail. Setting this to the current + version indicates that you don't care about ever reading data generated with an older version + of the code. + + If you set this to something other than your current version, you are obligated to insure that + your FromStream() method can handle all formats >= than this number. + + You can achieve this if you simply use the 'WriteTagged' and 'ReadTagged' APIs in your 'ToStream' + and 'FromStream' after your V1 AND you always add new fields to the end of your class. + This is the best practice. Thus + + void IFastSerializable.ToStream(Serializer serializer) + { + serializer.Write(Ver_1_Field1); + serializer.Write(Ver_1_Field2); + // ... + serializer.WriteTagged(Ver_2_Field1); + serializer.WriteTagged(Ver_2_Field2); + // ... + serializer.WriteTagged(Ver_3_Field1); + } + + void IFastSerializable.FromStream(Deserializer deserializer) + { + deserializer.Read(out Ver_1_Field1); + deserializer.Read(out Ver_1_Field2); + // ... + deserializer.TryReadTagged(ref Ver_2_Field1); // If data no present (old format) then Ver_2_Field1 not set. + deserializer.TryReadTagged(ref Ver_2_Field2); // ditto... + // ... + deserializer.TryReadTagged(ref Ver_3_Field1); + } + + Tagging outputs a byte tag in addition to the field itself. If that is a problem you can also use the + VersionBeingRead to find out what format is being read and write code that explicitly handles it. + Note however that this only gets you Backward compatibility (new readers can read the old format, but old readers + will still not be able to read the new format), which is why this is not the preferred method. + + void IFastSerializable.FromStream(Deserializer deserializer) + { + // We assume that MinVersionCanRead == 4 + // Deserialize things that are common to all versions (4 and earlier) + + if (deserializer.VersionBeingRead >= 5) + { + deserializer.Read(AVersion5Field); + if (deserializer.VersionBeingRead >= 5) + deserializer.ReadTagged(AVersion6Field); + } + } + + + + + This is the minimum version of a READER that can read this format. If you don't support forward + compatibility (old readers reading data generated by new readers) then this should be set to + the current version. + + If you set this to something besides the current version you are obligated to insure that your + ToStream() method ONLY adds fields at the end, AND that all of those added fields use the WriteTagged() + operations (which tags the data in a way that old readers can skip even if they don't know what it is) + In addition your FromStream() method must read these with the ReadTagged() deserializer APIs. + + See the comment in front of MinimumVersionCanRead for an example of using the WriteTagged() and ReadTagged() + methods. + + + + + Thrown when the deserializer detects an error. + + + + + Thown when a error occurs in serialization. + + + + + This is the version represents the version of both the reading + code and the version for the format for this type in serialized form. + See IFastSerializableVersion for more. + + + + + The version the the smallest (oldest) reader code that can read + this file format. Readers strictly less than this are rejected. + This allows support for forward compatbility. + See IFastSerializableVersion for more. + + + + + Create a IStreamReader (reads binary data) from a given byte buffer + + + + + Create a IStreamReader (reads binary data) from a given subregion of a byte buffer + + + + + The total length of bytes that this reader can read. + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Dispose pattern + + + + + Dispose pattern + + + + + A MemoryStreamReader is an implementation of the IStreamReader interface that works over a given byte[] array. + + + + + Create a IStreamReader (reads binary data) from a given byte buffer + + + + + Create a IStreamReader (reads binary data) from a given subregion of a byte buffer + + + + + The total length of bytes that this reader can read. + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Dispose pattern + + + + + Dispose pattern + + + + + A StreamWriter is an implementation of the IStreamWriter interface that generates a byte[] array. + + + + + Create IStreamWriter that writes its data to an internal byte[] buffer. It will grow as needed. + Call 'GetReader' to get a IStreamReader for the written bytes. + + Call 'GetBytes' call to get the raw array. Only the first 'Length' bytes are valid + + + + + Returns a IStreamReader that will read the written bytes. You cannot write additional bytes to the stream after making this call. + + + + + + The number of bytes written so far. + + + + + The array that holds the serialized data. + + + + + + Clears any data that was previously written. + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Implementation of IStreamWriter + + + + + Dispose pattern + + + + + Dispose pattern + + + + + Makespace makes at least sizeof(long) bytes available (or throws OutOfMemory) + + + + + A IOStreamStreamReader hooks a MemoryStreamReader up to an input System.IO.Stream. + + + + + Create a new IOStreamStreamReader from the given file. + + + + + + Create a new IOStreamStreamReader from the given System.IO.Stream. Optionally you can specify the size of the read buffer + The stream will be closed by the IOStreamStreamReader when it is closed. + + + + + close the file or underlying stream and clean up + + + + + Implementation of IStreamReader + + + + + Implementation of IStreamReader + + + + + Implementation of MemoryStreamReader + + + + + Dispose pattern + + + + + Fill the buffer, making sure at least 'minimum' byte are available to read. Throw an exception + if there are not that many bytes. + + + + + + A PinnedStreamReader is an IOStream reader that will pin its read buffer. + This allows it it support a 'GetPointer' API efficiently. The + GetPointer API lets you access data from the stream as raw byte + blobs without having to copy the data. + + + + + Create a new PinnedStreamReader that gets its data from a given file. You can optionally set the size of the read buffer. + + + + + Create a new PinnedStreamReader that gets its data from a given System.IO.Stream. You can optionally set the size of the read buffer. + The stream will be closed by the PinnedStreamReader when it is closed. + + + + + Clone the PinnnedStreamReader so that it reads from the same stream as this one. They will share the same + System.IO.Stream, but each will lock and seek when accessing that stream so they can both safely share it. + + + + + + Get a byte* pointer to the input buffer at 'Position' in the IReadStream that is at least 'length' bytes long. + (thus ptr to ptr+len is valid). Note that length cannot be larger than the buffer size passed to the reader + when it was constructed. + + + + + Get a byte* pointer to the input buffer at the current read position is at least 'length' bytes long. + (thus ptr to ptr+len is valid). Note that length cannot be larger than the buffer size passed to the reader + when it was constructed. + + + + + A IOStreamStreamWriter hooks a MemoryStreamWriter up to an output System.IO.Stream + + + + + Create a IOStreamStreamWriter that writes its data to a given file that it creates + + + + + + Create a IOStreamStreamWriter that writes its data to a System.IO.Stream + + + + + Flush any written data to the underlying System.IO.Stream + + + + + Insures the bytes in the stream are written to the stream and cleans up resources. + + + + + Access the underlying System.IO.Stream. You should avoid using this if at all possible. + + + + + Implementation of the MemoryStreamWriter interface + + + + + Implementation of the IStreamWriter interface + + + + + Implementation of the MemoryStreamWriter interface + + + + + Implementation of the MemoryStreamWriter interface + + + + + Implementation of the MemoryStreamWriter interface + + + + + Dispose pattern + + + + + A cheap version of List(T). The idea is to make it as cheap as if you did it 'by hand' using an array and + an int which represents the logical charCount. It is a struct to avoid an extra pointer dereference, so this + is really meant to be embedded in other structures. + + + + + Create a growable array with the given initial size it will grow as needed. There is also the + default constructor that assumes initialSize of 0 (and does not actually allocate the array. + + + + + + Fetch the element at the given index. Will throw an IndexOutOfRange exception otherwise + + + + + The number of elements in the array + + + + + Remove all elements in the array. + + + + + Add an item at the end of the array, growing as necessary. + + + + + + Add all items 'items' to the end of the array, growing as necessary. + + + + + + Insert 'item' directly at 'index', shifting all items >= index up. 'index' can be code:Count in + which case the item is appended to the end. Larger indexes are not allowed. + + + + + Remove 'count' elements starting at 'index' + + + + + Sets the 'index' element to 'value' growing the array if necessary (filling in default values if necessary). + + + + + Gets the value at 'index'. Never fails, will return 'default' if out of range. + + + + + Returns true if there are no elements in the array. + + + + + Remove the last element added and return it. Will throw if there are no elements. + + + + + + Returns the last element added Will throw if there are no elements. + + + + + Trims the size of the array so that no more than 'maxWaste' slots are wasted. Useful when + you know that the array has stopped growing. + + + + + Returns true if the Growable array was initialized by the default constructor + which has no capacity (and thus will cause growth on the first addition). + This method allows you to lazily set the compacity of your GrowableArray by + testing if it is of EmtpyCapacity, and if so set it to some useful capacity. + This avoids unecessary reallocs to get to a reasonable capacity. + + + + + A string representing the array. Only intended for debugging. + + + + + + Sets 'index' to the the smallest index such that all elements with index > 'idx' are > key. If + index does not match any elements a new element should always be placed AFTER index. Note that this + means that index may be -1 if the new element belongs in the first position. + + Returns true if the return index matched exactly (success) + + TODO FIX NOW harmonize with List.BinarySearch + + + + + Sort the range starting at 'index' of length 'count' using 'comparision' in assending order + + + + + Sort the whole array using 'comparison' in ascending order + + + + + Executes 'func' for each element in the GrowableArray and returns a GrowableArray + for the result. + + + + + Perform a linear search starting at 'startIndex'. If found return true and the index in 'index'. + It is legal that 'startIndex' is greater than the charCount, in which case, the search returns false + immediately. This allows a nice loop to find all items matching a pattern. + + + + + Returns the underlying array. Should not be used most of the time! + + + + + Implementation of foreach protocol + + + + + + Enumerator for foreach interface + + + + + implementation of IEnumerable interface + + + + + implementation of IEnumerable interface + + + + + Segmented list implementation, copied from Microsoft.Exchange.Collections. + + The type of the list element. + + This class implement a list which is allocated in segments, to avoid large lists to go into LOH. + + + + + Constructs SegmentedList. + + Segment size + + + + Constructs SegmentedList. + + Segment size + Initial capacity + + + + Returns the count of elements in the list. + + + + + Copy to Array + + Array copy + + + + Returns the last element on the list and removes it from it. + + The last element that was on the list. + + + + Returns true if this ICollection is read-only. + + + + + Gets or sets the given element in the list. + + Element index. + + + + Necessary if the list is being used as an array since it creates the segments lazily. + + + true if the segment is allocated and false otherwise + + + + Get slot of an element + + + + + + + + Adds new element at the end of the list. + + New element. + + + + Inserts new element at the given position in the list. + + Insert position. + New element to insert. + + + + Removes element at the given position in the list. + + Position of the element to remove. + + + + Performs a binary search in a sorted list. + + Element to search for. + Comparer to use. + Non-negative position of the element if found, negative binary complement of the position of the next element if not found. + The implementation was copied from CLR BinarySearch implementation. + + + + Performs a binary search in a sorted list. + + Element to search for. + The lowest index in which to search. + The highest index in which to search. + Comparer to use. + The index + + + + Sorts the list using default comparer for elements. + + + + + Sorts the list using specified comparer for elements. + + Comparer to use. + + + + Appends a range of elements from anothe list. + + Source list. + Start index in the source list. + Count of elements from the source list to append. + + + + Returns the enumerator. + + + + + Copy to Array + + Array copy + + + + CopyTo copies a collection into an Array, starting at a particular + index into the array. + + Destination array. + Destination array starting index. + + + + Copies the contents of the collection that are within a range into an Array, starting at a particular + index into the array. + + Destination array. + Destination array starting index. + The collection index from where the copying should start. + The collection index where the copying should end. + + + + Returns the enumerator. + + + + + Returns the enumerator. + + + + + Clears the list (removes all elements). + + + + + Check if ICollection contains the given element. + + Element to check. + + + + CopyTo copies a collection into an Array, starting at a particular + index into the array. + + Destination array. + Destination array starting index. + + + + Removes the given element from this ICollection. + + Element to remove. + + + + Shifts the tail of the list to make room for a new inserted element. + + Index of a new inserted element. + + + + Shifts the tail of the list to remove the element. + + Index of the removed element. + + + + Ensures that we have enough capacity for the given number of elements. + + Number of elements. + + + + Helper method for QuickSort. + + Comparer to use. + Position of the first element. + Position of the second element. + + + + QuickSort implementation. + + left boundary. + right boundary. + Comparer to use. + The implementation was copied from CLR QuickSort implementation. + + + + Enumerator over the segmented list. + + + + + Constructws the Enumerator. + + List to enumerate. + + + + Disposes the Enumerator. + + + + + Moves to the nest element in the list. + + True if move successful, false if there are no more elements. + + + + Returns the current element. + + + + + Returns the current element. + + + + + Resets the enumerator to initial state. + + + + diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Microsoft.Diagnostics.Tracing.TraceEvent.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Microsoft.Diagnostics.Tracing.TraceEvent.dll new file mode 100644 index 0000000..b2fe791 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Microsoft.Diagnostics.Tracing.TraceEvent.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Microsoft.Diagnostics.Tracing.TraceEvent.xml b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Microsoft.Diagnostics.Tracing.TraceEvent.xml new file mode 100644 index 0000000..f1522a3 --- /dev/null +++ b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/Microsoft.Diagnostics.Tracing.TraceEvent.xml @@ -0,0 +1,13649 @@ + + + + Microsoft.Diagnostics.Tracing.TraceEvent + + + + + BPerf Trace Log (BTL) are files generated by the CPU Samples Collector tool in https://github.com/Microsoft/BPerf + The layout of the file is as follows --> + + Format: + 4 byte integer describing compressed size + 4 byte integer describing uncompressed size + byte[compressed size] + + The byte array is a list of EVENT_RECORDs. Each Event_RECORD is aligned to 16-bytes. + + The EVENT_RECORD is laid out as a memory dump of the structure in memory. All pointers from + the structure are laid out successively in front of the EVENT_RECORD. + + The compression mechanism is using the NTDLL.RtlDecompressBufferEx Express Huffman procedure. + + + + + This constructor is used when the consumer has an offset within the BTL file that it would like to seek to. + + + + + This constructor is used when the consumer is supplying the buffers for reasons like buffer pooling. + + + + + An ActivityComputer is a state machine that track information about Activities. In particular, it can + compute a activity aware call stack. (GetCallStack). + + + + + Construct a new ActivityComputer that will process events from 'eventLog' and output activity - aware stacks to 'outputStackSource'. + + + + + Returns the TraceLog that is associated with the computer (at construction time) + + + + + Fires when an activity is first created (scheduled). The activity exists, and has an ID, but has not run yet. + + + + + First when an activity starts to run (using a thread). It fires after the start has logically happened. + so you are logically in the started activity. + + + + + Fires when the activity ends (no longer using a thread). It fires just BEFORE the task actually dies + (that is you ask the activity of the event being passed to 'Stop' it will still give the passed + activity as the answer). The first TraceActivity is the activity that was stopped, the second + is the activity that exists afer the stop completes. + + + + + Like OnStop but gets called AFTER the stop has completed (thus the current thread's activity has been updated) + The activity may be null, which indicates a failure to look up the activity being stopped (and thus the + thread's activity will be set to null). + + + + + AwaitUnblocks is a specialized form of the 'Start' event that fires when a task starts because + an AWAIT has ended. The start event also fires on awaits end and comes AFTER the AwaitUnblocks + event has been delivered. + + Not every AWAIT end causes a callback. Because an AWAIT begin happens for every FRAME you only + want a callback for the FIRST task (activity) created by parent of this activity. This is what + this callback does. + + AwaitUnblocks are often treated differently because you want to consider the time between the begin + (Activity Created) and awaitUnbock to be accounted for as on the critical path, whereas for 'normal' + tasks you normally don't think that time is interesting. + + + + + Fetches the current activity for 'thread' at the present time (the current event being dispatched). + Never returns null because there is always and activity (it may be the thread task). + This is arguably the main thing that this computer keeps track of. + + + + + Gets the default activity for a thread (the activity a thread is doing when the thread starts). + + + + + Maps an activity index back to its activity. + + + + + Returns a activity-aware call stackIndex associated with'ouputStackSource' for the call stack associated with 'data'. + Such activity-aware call stacks have pseudo-frame every time on thread causes another task to run code (because the + creator 'caused' the target code). + + If 'topFrames' is non-null, then this function is called with a Thread and is expected to return a CallStack index that + represents the thread-and-process nodes of the stack. This allows the returned stack to be have pseudo-frames + at the root of the stack. Typically this is used to represent the 'request' or other 'global' context. If it is not + present the thread and process are used to form these nodes. + + This needs to be a function mapping threads to the stack base rather than just the stack base because in the presence + of activities the thread at the 'base' whose 'top' you want may not be the one that 'data' started with, so the caller + needs to be prepared to answer the question about any thread. + + + + + Returns a StackSource call stack associated with outputStackSource for the activity 'activity' (that is the call stack at the + the time this activity was first created. This stack will have it 'top' defined by topFrames (by default just the thread and process frames) + + + + + This is not a call stack but rather the chain of ACTIVITIES (tasks), and can be formed even when call stacks + + Returns a Stack Source stack associated with outputStackSource where each frame is a task starting with 'activity' and + going back until the activity has no parent (e.g. the Thread's default activity). + + + + + If set, we don't assume that the top top frames are an attribute of the TOP THREAD (if they vary based on + the current activity, then you can't cache. Setting this disables caching. + + + + + Returns true if the call stack is in the thread pool parked (not running user code) + This means that the thread CAN'T be running an active activity and we can kill it. + + + + + This cache remembers Activity * CallStackIndex pairs and the result. + + + + + Remembers the current Activity for 'Get' and 'Put' operations. Needs to be set before Get or Put is called. + + + + + Gets the cache entry for the CurrnetActivityIndex with the call stack 'fromStackIndex' returns Invalid if + there is no entry. + + This is not passed the CurrentActivityIndex, so it can implement the CallStackMap interface + + + + + updates the cache entry for the CurrnetActivityIndex with the call stack 'fromStackIndex' with the value + 'toStackIndex' + + This is not passed the CurrentActivityIndex, so it can implement the CallStackMap interface + + + + + Creation handles ANY creation of a task. + + + + + Activity can be null, which means we could not figure out the activity we are stopping. + + + + + Get a trace wide ID for a TPL event. TPL tasks might be 'Scheduled' in the sense + that it might run independently on another thread. Tasks that do 'BeginWait and 'EndWait' + are not scheduled. The same ID might have both operating simultaneously (if you wait + on a scheduled task). Thus you need an independent ID for both. + + + + + if 'activity' has not creator (it is top-level), then return baseStack (near execution) followed by 'top' representing the thread-process frames. + + otherwise, find the fragment of 'baseStack' up to the point to enters the threadpool (the user code) and splice it to the stack of the creator + of the activity and return that. (thus returning your full user-stack). + + + + + Trims off frames that call ETW logic and return. If the pattern is not matched, we return callStackIndex + + + + + If the stack from 'startStack' (closest to execution) through 'stopStack' is the same as 'baseStack' return a non-invalid frame + indicating that it is recursive and should be dropped. The frame index returned is the name of the task on 'baseStack' that + begins the recursion (so you can update it if necessary) + + + + + Create a stack which is executing at 'startStack' and finds the region until 'stopStack', appending that (in order) to 'baseStack'. + + + + + Returns the point in 'callStackIndex' where the CLR thread pool transitions from + a thread pool worker to the work being done by the threadpool. + + Basically we find the closest to execution (furthest from thread-start) call to a 'Run' method + that shows we are running an independent task. + + + + + Used by TrimETWFrames and FindThreadPoolTransition to find particular frame names and place the information in 'm_methodFlags' + + + + + We look for various well known methods inside the Task library. This array maps method indexes + and returns a bitvector of 'kinds' of methods (Run, Schedule, ScheduleHelper). + + + + + A small number that you can get from the GetReferenceForGCAddress that is + invariant as the GC address moves around during GCs. Because this index + is small it can be used to store information about the GC reference in a + side growable array. + + + + + Indicates that the address is no longer alive. + + + + + This computer will keep track of GC references as they change over time + + + + + Create a new GCRefernece computer from the stream of events 'source'. When 'source' is processed + you can call 'GetReferenceForGCAddress' to get stable ids for GC references. + + + + + + Get a stable ID for a GcAddress. This ID can be compared for object identity. + This only works at the current point in time when scanning the source. + + + + + If you no longer need to track the GC reference, call this function to remove the tracking. + + + + + A EventPipeThreadTimeComputer does a simple simulation of what each thread is doing to create stack events that represent + CPU, blocked time + + + + + Create a new ThreadTimeComputer + + + + + If set we compute thread time using Tasks + + + + + Track additional info on like EventName or so. + Default to true to keep backward compatibility. + + + + + Use start-stop activities as the grouping construct. + + + + + Generate the thread time stacks, outputting to 'stackSource'. + + + Optional filtered trace events. + + + + Updates it so that 'thread' is now working on newStartStop, which can be null which means that it is not working on any + start-stop task. + + + + + This can actually be called with any event that has a stack. Basically it will log a CPU sample whose + size is the time between the last such call and the current one. + + + + + Get the call stack for 'data' Note that you thread must be data.Thread(). We pass it just to save the lookup. + + + + + Returns a function that figures out the top (closest to stack root) frames for an event. Often + this returns null which means 'use the normal thread-process frames'. + Normally this stack is for the current time, but if 'getAtCreationTime' is true, it will compute the + stack at the time that the current activity was CREATED rather than the current time. This works + better for await time. + + + + + Represents all the information that we need to track for each thread. + + + + + Used to create UNKNOWN frames for start-stop activities. This is indexed by StartStopActivityIndex. + and for each start-stop activity indicates when unknown time starts. However if that activity still + has known activities associated with it then the number will be negative, and its value is the + ref-count of known activities (thus when it falls to 0, it we set it to the start of unknown time. + This is indexed by the TOP-MOST start-stop activity. + + + + + maps thread ID to the current TOP-MOST start-stop activity running on that thread. Used to updated m_unknownTimeStartMsec + to figure out when to put in UNKNOWN_ASYNC nodes. + + + + + Sadly, with AWAIT nodes might come into existance AFTER we would have normally identified + a region as having no thread/await working on it. Thus you have to be able to 'undo' ASYNC_UNKONWN + nodes. We solve this by remembering all of our ASYNC_UNKNOWN nodes on a list (basically provisional) + and only add them when the start-stop activity dies (when we know there can't be another AWAIT. + Note that we only care about TOP-MOST activities. + + + + + Calculates stacks grouping them by the server request (e.g. ASP.NET) request they are for) + + + + + Create a new ServerRequest Computer. + + + + + The server request that we currently processing + + + + + A ServerRequest contains all the information we know about a server request (e.g. ASP.NET request) + + + + + Any URL associated with the request + + + + + If the request has a GUID associated with it to uniquely identify it, this is it + + + + + The time that the request started (or the earliest that we know about it) + + + + + Calculates start-stop activities (computes duration), It uses the 'standard' mechanism of using + ActivityIDs to corelate the start and stop (and any other events between the start and stop, + and use the RelatedActivityID on START events to indicate the creator of the activity, so you can + form nested start-stop activities. + + + + + Create a new ServerRequest Computer. + + + + + The current start-stop activity on the given thread. + If present 'context' is used to look up the current activityID and try to use that to repair missing Starts. + Basically if we can't figure out what StartStop activity the thread from just the threadID we can use the activityID + from the 'context' event to find it as a backup. + + + + + Gets the current Start-Stop activity for a given TraceActivity. + + + + + + + Returns a stack index representing the nesting of Start-Stop activities for the thread 'curThread' at the current time + (At this point of the current event for the computer). The stack starts with a frame for the process of the thread, then + has all the start-stop activity frames, then a frame representing 'topThread' which may not be the same as 'thread' since + 'topThread' is the thread that spawned the first task, not the currently executing thread. + + Normally this stack is for the current time, but if 'getAtCreationTime' is true, it will compute the + stack at the time that the current activity was CREATED rather than the current time. This works + better for await time + + + + + Gets a stack that represents the nesting of the Start-Stop tasks. curActivity can be null, in which case just he process node is returned. + + + + + If set, called AFTER a Start-Stop activity starts, called with the activity and the event that caused the start. + + + + + If set, called BEFORE a Start-Stop activity stops, called with the activity and the event that caused the start. + + + + + Returns true if 'guid' follow the EventSouce style activity ID for the process with ID processID. + You can pass a process ID of 0 to this routine and it will do the best it can, but the possibility + of error is significantly higher (but still under .1%) + + + + + Assuming guid is an Activity Path, extract the process ID from it. + + + + + returns a string representation for the activity path. If the GUID is not an activity path then it returns + the normal string representation for a GUID. + + + + + We don't do a stop all processing associated with the stop event is done. Thus if we are not 'on' + the stop event, then you can do any deferred processing. + + + + + Try to process some predefined DiagnosticSource ("Microsoft.EntityFrameworkCore.BeforeExecuteCommand" and "Microsoft.AspNetCore.Hosting.BeginRequest") start events. + This will try to filter the events by "EventName", if failed it will return false without any further processing. + + Whether or not succeeded in processing the event + + + + fix ASP.NET receiving events + + + + + Look up a start-stop activity by its ID. Note that the 'activityID' needs to be unique for that instance + within a process. (across ALL start-stop activities, which means it may need components that encode its + provider and task). We pass the process ID as well so that it will be unique in the whole trace. + + + + + The encoding for a list of numbers used to make Activity Guids. Basically + we operate on nibbles (which are nice because they show up as hex digits). The + list is ended with a end nibble (0) and depending on the nibble value (Below) + the value is either encoded into nibble itself or it can spill over into the + bytes that follow. + + + + + An dense number that defines the identity of a StartStopActivity. Used to create side arrays + for StartStopActivity info. + + + + + An illegal index, sutable for a sentinal. + + + + + A StartStop reresents an activity between a start and stop event as generated by EvetSource. + + + + + The index (small dense numbers suitabilty for array indexing) for this activity. + + + + + The name of the activity (The Task name for the start-stop event as well as the activity ID) + + + + + Known Activity Type + + + + + If the activity has additional information associated with it (e.g. a URL), put it here. Can be null. + + + + + The Task name (the name prefix that is common to both the start and stop event) + + + + + The processID associated with this activity + + + + + The Activity ID (as a GUID) that matches the start and stop together. + + + + + The path of creators that created this activity. + + + + + The start-stop activity that created this activity (thus it makes a tree) + + + + + The TraceLog event Index, of the start event (you can get addition info) + + + + + The TraceLog event Index, of the stop event (you can get addition info) + + + + + The time in MSec from the start of the trace when the start event happened. + + + + + The duration of activity in MSec (diff between stop and start) + + + + + This activity has completed (the Stop event has been received). Thus Duration is valid. + + + + + Returns a stack on the outputStackSource which has a frame for each activity that + caused this activity, as well as the root of the given 'rootStack' (often a stack representing the process). + + + + + override. Gives the name and start time. + + + + + We don't update the state for the stop at the time of the stop, but at the next call to any of the StartStopActivityComputer APIs. + + + + + A TcpIpComputer keeps track of TCP/IP connections so that you can correlate individual reads and + writes with the connection info (like the IP address of each end), as well as data packets being + sent (if you have packet capture turned on). + + + + + Create a new GCRefernece computer from the stream of events 'source'. When 'source' is processed + you can call 'GetReferenceForGCAddress' to get stable ids for GC references. + + + + + + A ThreadTimeComputer does a simple simulation of what each thread is doing to create stack events that represent + CPU, blocked time, disk and Network activity. + + + + + Create a new ThreadTimeComputer + + + + + If set we compute thread time using Tasks + + + + + Track additional info on like EventName or so. + Default to true to keep backward compatibility. + + + + + If set we compute blocked time + + + + + If set we don't show ready thread information + + + + + If set we group by ASP.NET Request + + + + + If we spend less then this amount of time waiting for the CPU, don't bother showing it. + + + + + LIke the GroupByAspNetRequest but use start-stop activities instead of ASP.NET Requests as the grouping construct. + + + + + Don't show AwaitTime. For CPU only traces showing await time is misleading since + blocked time will not show up. + + + + + Generate the thread time stacks, outputting to 'stackSource'. + + + Optional filtered trace events. + + + + Updates it so that 'thread' is now working on newStartStop, which can be null which means that it is not working on any + start-stop task. + + + + + This can actually be called with any event that has a stack. Basically it will log a CPU sample whose + size is the time between the last such call and the current one. + + + + + Get the call stack for 'data' Note that you thread must be data.Thread(). We pass it just to save the lookup. + + + + + Returns a function that figures out the top (closest to stack root) frames for an event. Often + this returns null which means 'use the normal thread-process frames'. + Normally this stack is for the current time, but if 'getAtCreationTime' is true, it will compute the + stack at the time that the current activity was CREATED rather than the current time. This works + better for await time. + + + + + Represents all the information that we need to track for each thread. + + + + + Given and activity, return the ASP.NET Guid associated with it (or Guid.Empty if there is not one). + + + + + + Computes the ASP.NET Pseudo frames from the process frame through the thread frame (which includes all + the pseudo-frames for the ASP.NET groupings. + + + + + Indicates that the aspNet request represented by aspNetGuid is now being handled by the thread with index + newThreadIndex. Thus any old threads handling this request are 'cleared' and replaced with 'newThreadIndex' + If 'newThreadIndex == Invalid then the entry for aspNetGuid is removed. + + + + + Generate a stack that from the root looks like 'stackIndex followed by 'READIED BY TID(XXXX)' + followed by frames of 'readyThreadCallStack' (suffixed by READIED_BY) + + + + + NetworkInfo remembers useful information to tag blocked time that seems to be network related. + It is the value of the m_lastPacketForProcess table mapping threads to network information. + + + + + AspNetRequestInfo remembers everything we care about associate with an single ASP.NET request. + It is the value of the m_aspNetRequestInfo table. + + + + + Used to create UNKNOWN frames for start-stop activities. This is indexed by StartStopActivityIndex. + and for each start-stop activity indicates when unknown time starts. However if that activity still + has known activities associated with it then the number will be negative, and its value is the + ref-count of known activities (thus when it falls to 0, it we set it to the start of unknown time. + This is indexed by the TOP-MOST start-stop activity. + + + + + maps thread ID to the current TOP-MOST start-stop activity running on that thread. Used to updated m_unknownTimeStartMsec + to figure out when to put in UNKNOWN_ASYNC nodes. + + + + + Sadly, with AWAIT nodes might come into existance AFTER we would have normally identified + a region as having no thread/await working on it. Thus you have to be able to 'undo' ASYNC_UNKONWN + nodes. We solve this by remembering all of our ASYNC_UNKNOWN nodes on a list (basically provisional) + and only add them when the start-stop activity dies (when we know there can't be another AWAIT. + Note that we only care about TOP-MOST activities. + + + + + m_IRPToThread maps the I/O request to the thread that initiated it. This way we can associate + the disk read size and file with the thread that asked for it. + + + + + Maps processor number to the OS threadID of the thread that is using it. Allows you + to determine how (CPU) idle the machine is. + + + + + Using m_threadIDUsingProc, we compute how many processor are current doing nothing + + + + + Returns the TraceLog that is associated with the computer (at construction time) + + + + + Extension methods to enable TraceManagedProcess + + + + + Extension properties for TraceProcess that include necessary .NET values + + TODO This implementation is poor at idenitfying the ParentPID, 64bitness, and Start/End times + + + + + Returns the textual version of the .NET Framework + + + + + Returns the .NET startup flags + + + + + Date and time of when the runtime was built + This is useful when a more detailed version is not present + + + + + Garbage Collector (GC) specific details about this process + + + + + Fired on the start of a GC + + + + + Fired at the end of tha GC. Given the nature of the GC, it is possible that multiple GCs will be inflight at the same time. + + + + + Just-in-time compilation (JIT) specific details about this process + + + + + Fired when a managed method is starting to compile (jit) + + + + + Fired when a managed method is done compiling (jitting). Given the nature of the JIT, it is possible that multiple methods will be compiled at the same time. + + + + + An XML representation of the TraceEventProcess (for debugging) + + + + + Gathers relevant details about the processes in the event source + + + + + + Garbage Collector (GC) specific details about this process + + + + + Process view of GC statistics + + + + + Process view of GC generational statistics + + + + + Process view of all GCs + + + + + Just-in-time compilation (JIT) specific details about this process + + + + + Process view of JIT statistics + + + + + Process view of all methods jitted + + + + + + + + + + Primary GC information + + + + + Type of the GC, eg. NonConcurrent, Background or Foreground + + + + + Reason for the GC, eg. exhausted small heap, etc. + + + + + Generation of the heap collected. If you compare Generation at the start and stop GC events they may differ. + + + + + Time relative to the start of the trace. Useful for ordering + + + + + Duration of the GC, excluding the suspension time + + + + + Duration the EE suspended the process + + + + + Time the EE took to suspend all the threads + + + + + Percentage time the GC took compared to the process lifetime + + + + + The number of CPU samples gathered for the lifetime of this process + + + + + The number of CPU samples gathered during a GC + + + + + Mark time information per heap. Key is the heap number + + + + + Time since the last EE restart + + + + + Realtive time to the trace of when the GC pause began + + + + + Marks if the GC is in a completed state + + + + + Server GC histories + + + + + Amount of memory allocated since last GC. Requires GCAllocationTicks enabled. The + data is split into small and large heaps + + + + + Number of heaps. -1 is the default + + + + + Calculate the size of all pinned objects + + + + + + Percentage of the pinned objects created by the user + + + + + + Total time taken by the GC + + + + + + Friendly GC name including type, reason and generation + + + + + Heap size after GC (mb) + + + + + Amount of memory promoted with GC (mb) + + + + + Memory survival percentage by generation + + + + + + + Heap size by generation after GC (mb) + + + + + + + Heap fragmentation by generation (mb) + + + + + + + Percentage of heap fragmented by generation + + + + + + + Amount of memory at the start of the GC by generation (mb) + + + + + + + Amount of memory after the gc by generation (mb) + + + + + + + Memory promoted by generation (mb) + Note that in 4.0 TotalPromotedSize is not entirely accurate (since it doesn't + count the pins that got demoted. We could consider using the PerHeap event data + to compute the accurate promoted size. + In 4.5 this is accurate. + + + + + + + Heap budget by generation (mb) + + + + + + + Object size by generation after GC (mb) + + + + + + + Heap condemned reasons by GC + + + + + Identify the first and greatest condemned heap + + + + + + Indicates that the GC has low ephemeral space + + + + + + Indicates that the GC was not compacting + + + + + + Returns the condemned reason for this heap + + + + + + Per heap statistics + + + + + Sum of the pinned plug sizes + + + + + Sum of the user created pinned plug sizes + + + + + Per heap statstics + + + + + Large object heap wait threads + + + + + Process heap statistics + + + + + Free list efficiency statistics + + + + + Memory allocated since last GC (mb) + + + + + Ratio of heap size before and after + + + + + Ratio of allocations since last GC over time executed + + + + + Peak heap size before GCs (mb) + + + + + Per generation view of user allocated data + + + + + Heap size before gc (mb) + + + + + Per generation view of heap sizes before GC (mb) + + + + + This represents the percentage time spent paused for this GC since the last GC completed. + + + + + Get what's allocated into gen0 or gen3. For server GC this gets the total for + all heaps. + + + + + For a given heap, get what's allocated into gen0 or gen3. + We calculate this differently on 4.0, 4.5 Beta and 4.5 RC+. + The caveat with 4.0 and 4.5 Beta is that when survival rate is 0, + We don't know how to calculate the allocated - so we just use the + last GC's budget (We should indicate this in the tool) + + + + + Legacy properties that need to be refactored and removed + + + + + Condemned reasons are organized into the following groups. + Each group corresponds to one or more reasons. + Groups are organized in the way that they mean something to users. + + + + + Background GC allocation information + + + + + Span of thread work recorded by CSwitch or CPU Sample Profile events + + + + + Reason for an induced GC + + + + + CondemnedReason + + + + + Heap condemned reason + + + + + This records which reasons are used and the value. Since the biggest value + we need to record is the generation number a byte is sufficient. + + + + + Container for mark times + + + + + Per heap statistics + + + + + Process heap statistics + + + + + Per heap stastics + + + + + Approximations we do in this function for V4_5 and prior: + On 4.0 we didn't seperate free list from free obj, so we just use fragmentation (which is the sum) + as an approximation. This makes the efficiency value a bit larger than it actually is. + We don't actually update in for the older gen - this means we only know the out for the younger + gen which isn't necessarily all allocated into the older gen. So we could see cases where the + out is > 0, yet the older gen's free list doesn't change. Using the younger gen's out as an + approximation makes the efficiency value larger than it actually is. + + For V4_6 this requires no approximation. + + + + + + + Statistical garbage collector (GC) information about a managed process + + + + + Number of GC's for this process + + + + + Number of GC's which were induced, eg. GC.Collect, etc. + + + + + Total size of the pinned objects seen at collection time + + + + + Of all the memory that is current pinned, how much of it is from pinned objects + + + + + Number of GC's that contained pinned objects + + + + + Number of GC's that contained pin plugs + + + + + The longest pause duration (ms) + + + + + Avarege pause duration (ms) + + + + + Average heap size after a GC (mb) + + + + + Average peak heap size (mb) + + + + + Average exclusive cpu samples (ms) during GC's + + + + + Total GC pause time (ms) + + + + + Max suspend duration (ms), should be very small + + + + + Max peak heap size (mb) + + + + + Max allocation per second (mb/sec) + + + + + Total allocations in the process lifetime (mb) + + + + + Total exclusive cpu samples (ms) + + + + + Total memory promoted between generations (mb) + + + + + (obsolete) Total size of heaps after GC'ss (mb) + + + + + (obsolete) Total peak heap sizes (mb) + + + + + Indication if this process is interesting from a GC pov + + + + + List of finalizer objects + + + + + Percentage of time spent paused as compared to the process lifetime + + + + + + Running time of the process. Measured as time spent between first and last GC event observed + + + + + Means it detected that the ETW information is in a format it does not understand. + + + + + Indicator of if ServerGC is enabled (1). -1 indicates that not enough events have been processed to know for sure. + We don't necessarily have the GCSettings event (only fired at the beginning if we attach) + So we have to detect whether we are running server GC or not. + Till we get our first GlobalHeapHistory event which indicates whether we use server GC + or not this remains -1. + + + + + Number of heaps. -1 indicates that not enough events have been processed to know for sure. + + + + + Indicator if PerHeapHistories is present + + + + + Process statistics about JIT'd code + + + + + Number of JITT'd methods + + + + + Total cpu samples for this process + + + + + Number of methods JITT'd by foreground threads just prior to execution + + + + + Total time spent compiling methods on foreground threads + + + + + Number of methods JITT'd by the multicore JIT background threads + + + + + Total time spent compiling methods on background threads for multicore JIT + + + + + Number of methods JITT'd by the tiered compilation background threads + + + + + Total time spent compiling methods on background threads for tiered compilation + + + + + Total IL size for all JITT'd methods + + + + + Total native code size for all JITT'd methods + + + + + Indication if this is running on .NET 4.x+ + + + + + Indicates if this process has sufficient JIT activity to be interesting + + + + + Background JIT: Time Jit was aborted (ms) + + + + + Background JIT: Assembly name of last assembly loaded before JIT aborted + + + + + Background JIT: Relative start time of last assembly loaded before JIT aborted + + + + + Background JIT: Indication if the last assembly load was successful before JIT aborted + + + + + Background JIT: Thread id of the background JIT + + + + + Background JIT: Indication that background JIT events are enabled + + + + + List of successfully inlinded methods + + + + + List of failed inlined methods + + + + + Modules encountered while processing managed samples + + + + + List of modules whose symbols were not successfully loaded + + + + + Aggregate a method to be included in the statistics + + + + + + Legacgy + + + + + Uniquely represents a method within a process. + Used as a lookup key for data structures. + + + + + JIT inlining successes + + + + + JIT inlining failures + + + + + Per method information + + + + + Time taken to compile the method + + + + + IL size of method + + + + + Native code size of method + + + + + Relative start time of JIT'd method + + + + + Method name + + + + + Module name + + + + + Thread id where JIT'd + + + + + Indication of if it was JIT'd in the background + + + + + Indication of if it was JIT'd in the background and why + + + + + Amount of time the method was forcasted to JIT + + + + + Indication of if the background JIT request was blocked and why + + + + + Number of cpu samples for this method + + + + + The version id that is created by the runtime code versioning feature. This is an incrementing counter that starts at 0 for each method. + The ETW events historically name this as the ReJITID event parameter in the payload, but we have now co-opted its usage. + + + + + Legacy + + + + + TraceProcess Extension methods + + + + + Each process is given a unique index from 0 to TraceProcesses.Count-1 and unlike + the OS Process ID, is unambiguous (The OS process ID can be reused after a + process dies). ProcessIndex represents this index. By using an enum rather than an int + it allows stronger typing and reduces the potential for errors. + + It is expected that users of this library might keep arrays of size TraceProcesses.Count to store + additional data associated with a process in the trace. + + + + + + Returned when no appropriate Process exists. + + + + + A TraceProcesses instance represents the list of processes in the Event log. + + TraceProcesses are IEnumerable, and will return the processes in order of creation time. + + This is a copy of the reduced code from TraceLog!TraceProcesses (removal of elements that + depend on TraceLog - there is a lot of them) + + + + + The log associated with this collection of processes. + + + + + The count of the number of TraceProcess instances in the TraceProcesses list. + + + + + Each process that occurs in the log is given a unique index (which unlike the PID is unique), that + ranges from 0 to Count - 1. Return the TraceProcess for the given index. + + + + + An XML representation of the TraceEventProcesses (for debugging) + + + + + Enumerate all the processes that occurred in the trace log, ordered by creation time. + + + + + Given an OS process ID and a time, return the last TraceProcess that has the same process ID, + and whose offset start time is less than 'timeQPC'. If 'timeQPC' is during the thread's lifetime this + is guaranteed to be the correct process. Using timeQPC = TraceLog.sessionEndTimeQPC will return the + last process with the given PID, even if it had died. + + + + + TraceProcesses represents the entire ETL moduleFile log. At the node level it is organized by threads. + + The TraceProcesses also is where we put various caches that are independent of the process involved. + These include a cache for TraceModuleFile that represent native images that can be loaded into a + process, as well as the process lookup tables and a cache that remembers the last calls to + GetNameForAddress(). + + + + + A step towards a refactored TraceProcess that will move down the dependcy chain from + TraceLog to Source. This is only the portion of TraceProcess that is needed for ManagedProcess + to exist. Also note, that the surface area is intended to match 100% with + Microsoft.Diagnostics.Tracing.Etlx.TraceProcess. The namespace change is intention to avoid + collision of the name and to indicate that it is moving down the depdnency chain. + + This is a slightly modified copy of the code from TraceLog!TraceProcess + + + + + The OS process ID associated with the process. It is NOT unique across the whole log. Use + ProcessIndex for that. + + + + + The index into the logical array of TraceProcesses for this process. Unlike ProcessID (which + may be reused after the process dies, the process index is unique in the log. + + + + + This is a short name for the process. It is the image file name without the path or suffix. + + + + + The command line that started the process (may be empty string if unknown) + + + + + The path name of the EXE that started the process (may be empty string if unknown) + + + + + The time when the process started. Returns the time the trace started if the process existed when the trace started. + + + + + The time when the process started. Returns the time the trace started if the process existed when the trace started. + Returned as the number of MSec from the beginning of the trace. + + + + + The time when the process ended. Returns the time the trace ended if the process existed when the trace ended. + Returned as a DateTime + + + + + The time when the process ended. Returns the time the trace ended if the process existed when the trace ended. + Returned as the number of MSec from the beginning of the trace. + + + + + The process ID of the parent process + + + + + The process that started this process. Returns null if unknown. + + + + + If the process exited, the exit status of the process. Otherwise null. + + + + + The amount of CPU time spent in this process based on the kernel CPU sampling events. + + + + + Returns true if the process is a 64 bit process + + + + + The log file associated with the process. + + + + + Peak working set + + + + + Peak virtual size + + + + + A list of all the threads that occurred in this process. + + + + + Returns the list of modules that were loaded by the process. The modules may be managed or + native, and include native modules that were loaded event before the trace started. + + + + + Filters events to only those for a particular process. + + + + + Filters events to only that occurred during the time the process was alive. + + + + + + An XML representation of the TraceEventProcess (for debugging) + + + + + Dummy stubs so Microsoft.Diagnostics.Tracing.Etlx namespace is not necessary + + + + + The parsed metadata. + + + + + Information about the trace itself. + + + + + Information about a single stream in the trace. + + + + + The environment the trace was taken in. + + + + + A clock definition in the trace. + + + + + A definition of an event. + + + + + A manual parser for CtfMetadata. Eventually this should be replaced when CtfMetadata no longer + uses a custom, BNF style format. + + + + + The abstract metadata parser class. + + + + + The types that may be declared in CtfMetatdata. + + + + + This class represents the top level entry + + + + + A simple class to make parsing out properties easier. + + + + + Represents a type which has been referenced by name, but has not yet been resolved to a concrete type. + + + + + A DynamicTraceEventParser is a parser that understands how to read the embedded manifests that occur in the + dataStream (System.Diagnostics.Tracing.EventSources do this). + + See also TDHDynamicTraceEventParser which knows how to read the manifest that are registered globally with + the machine. + + + + + The event ID for the EventSource manifest emission event. + + + + + Create a new DynamicTraceEventParser (which can parse ETW providers that dump their manifests + to the ETW data stream) an attach it to the ETW data stream 'source'. + + + + + Returns a list of providers (their manifest) that this TraceParser knows about. + + + + + Given a manifest describing the provider add its information to the parser. + + + + + Utility method that stores all the manifests known to the DynamicTraceEventParser to the directory 'directoryPath' + + + + + Utility method that read all the manifests the directory 'directoryPath' into the parser. + Manifests must end in a .man or .manifest.xml suffix. It will throw an error if + the manifest is incorrect or using unsupported options. + + + + + Override. + + + + + This event, will be fired any time a new Provider is added to the table + of ETW providers known to this DynamicTraceEventParser. This includes + when the EventSource manifest events are encountered as well as any + explicit calls to AddDynamicProvider. (including ReadAllManifests). + + The Parser will filter out duplicate manifest events, however if an + old version of a provider's manifest is encountered, and later a newer + version is encountered, you can receive this event more than once for + a single provider. + + + + + override + + + + + Called on unhandled events to look for manifests. Returns true if we added a new manifest (which may have updated the lookup table) + + + + + Override + + + + + DynamicTraceEventData is an event that knows how to take runtime information to parse event fields (and payload) + + This meta-data is distilled down to a array of field names and an array of PayloadFetches which contain enough + information to find the field data in the payload blob. This meta-data is used in the + DynamicTraceEventData.PayloadNames and DynamicTraceEventData.PayloadValue methods. + + + + + Implements TraceEvent interface + + + + + Implements TraceEvent interface + + + + + Implements TraceEvent interface + + + + + Used by PayloadValue to represent a structure. It is basically a IDictionary with a ToString() that + returns the value as JSON. + + + + + Uses C style conventions to quote a string 'value' and append to the string builder 'sb'. + Thus all \ are turned into \\ and all " into \" + + + + + Implements TraceEvent interface + + + + + Implements TraceEvent interface + + + + + Returns the count of elements for the array represented by 'arrayInfo' + It also will adjust 'offset' so that it points at the beginning of the + array data (skips past the count). + + + + + Constructor for normal types, (int, string) ...) Also handles Enums (which are ints with a map) + + + + + Initialized a PayloadFetch for a given inType. REturns Size = DynamicTraceEventData.UNKNOWN_SIZE + if the type is unknown. + + + + + Returns a payload fetch for a Array. If you know the count, then you can give it. + + + + + Offset from the beginning of the struct. + + + + + LazyMap allow out to set a function that returns a map + instead of the map itself. This will be evaluated when the map + is fetched (which gives time for the map table to be populated. + + + + + This class is only used to pretty-print the manifest event itself. It is pretty special purpose + + + + + DynamicTraceEventParserState represents the state of a DynamicTraceEventParser that needs to be + serialized to a log file. It does NOT include information about what events are chosen but DOES contain + any other necessary information that came from the ETL data file. + + + + + A ProviderManifest represents the XML manifest associated with the provider. + + + + + Read a ProviderManifest from a stream + + + + + Read a ProviderManifest from a file. + + + + + Normally ProviderManifest will fail silently if there is a problem with the manifest. If + you want to see this error you can all this method to force it explicitly It will + throw if there is a problem parsing the manifest. + + + + + Writes the manifest to 'outputStream' (as UTF8 XML text) + + + + + Writes the manifest to a file 'filePath' (as a UTF8 XML) + + + + + + Set if this manifest came from the ETL data stream file. + + + + + The name of the ETW provider + + + + + The GUID that uniquey identifies the ETW provider + + + + + The version is defined as the sum of all the version numbers of event version numbers + the number of events defined. + This has the property that if you follow correct versioning protocol (all versions for a linear sequence where a new + versions is only modifies is predecessor by adding new events or INCREASING the version numbers of existing events) + then the version number defined below will always strictly increase. + + It turns out that .NET Core removed some events from the TplEtwProvider. To allow removal of truly old events + we also add 100* the largest event ID defined to the version number. That way if you add new events, even if you + removes some (less than 100) it will consider your 'better'. + + + + + This is an arbitrary id given when the Manifest is created that + identifies where the manifest came from (e.g. a file name or an event etc). + + + + + Returns true if the current manifest is better to use than 'otherManifest' A manifest is + better if it has a larger version number OR, they have the same version number and it is + physically larger (we assume what happened is people added more properties but did not + update the version field appropriately). + + + + + Retrieve manifest as one big string. Mostly for debugging + + + + + Retrieve the manifest as XML + + + + + For debugging + + + + + Call 'callback the the parsed templates for this provider. If 'callback' returns RejectProvider, bail early + Note that the DynamicTraceEventData passed to the delegate needs to be cloned if you use subscribe to it. + + + + + Returns the .NET type corresponding to the manifest type 'manifestTypeName' + Returns null if it could not be found. + + + + + Initialize the provider. This means to advance the instance variable 'reader' until it it is at the 'provider' node + in the XML. It also has the side effect of setting the name and guid. The rest waits until events are registered. + + + + + Keywords are passed to TraceEventSession.EnableProvider to enable particular sets of + + + + + Logging when garbage collections and finalization happen. + + + + + Events when GC handles are set or destroyed. + + + + + Logging when modules actually get loaded and unloaded. + + + + + Logging when Just in time (JIT) compilation occurs. + + + + + Logging when precompiled native (NGEN) images are loaded. + + + + + Indicates that on attach or module load , a rundown of all existing methods should be done + + + + + Indicates that on detach or process shutdown, a rundown of all existing methods should be done + + + + + Events associated with validating security restrictions. + + + + + Events for logging resource consumption on an app-domain level granularity + + + + + Logging of the internal workings of the Just In Time compiler. This is fairly verbose. + It details decisions about interesting optimization (like inlining and tail call) + + + + + Log information about code thunks that transition between managed and unmanaged code. + + + + + Log when lock contention occurs. (Monitor.Enters actually blocks) + + + + + Log exception processing. + + + + + Log events associated with the threadpool, and other threading events. + + + + + Dump the native to IL mapping of any method that is JIT compiled. (V4.5 runtimes and above). + + + + + If enabled will suppress the rundown of NGEN events on V4.0 runtime (has no effect on Pre-V4.0 runtimes). + + + + + Enables the 'BulkType' event + + + + + Enables the events associated with dumping the GC heap + + + + + Enables allocation sampling with the 'fast'. Sample to limit to 100 allocations per second per type. + This is good for most detailed performance investigations. Note that this DOES update the allocation + path to be slower and only works if the process start with this on. + + + + + Enables events associate with object movement or survival with each GC. + + + + + Triggers a GC. Can pass a 64 bit value that will be logged with the GC Start event so you know which GC you actually triggered. + + + + + Indicates that you want type names looked up and put into the events (not just meta-data tokens). + + + + + Enables allocation sampling with the 'slow' rate, Sample to limit to 5 allocations per second per type. + This is reasonable for monitoring. Note that this DOES update the allocation path to be slower + and only works if the process start with this on. + + + + + Turns on capturing the stack and type of object allocation made by the .NET Runtime. This is only + supported after V4.5.3 (Late 2014) This can be very verbose and you should seriously using GCSampledObjectAllocationHigh + instead (and GCSampledObjectAllocationLow for production scenarios). + + + + + This suppresses NGEN events on V4.0 (where you have NGEN PDBs), but not on V2.0 (which does not know about this + bit and also does not have NGEN PDBS). + + + + + TODO document + + + + + Also log the stack trace of events for which this is valuable. + + + + + This allows tracing work item transfer events (thread pool enqueue/dequeue/ioenqueue/iodequeue/a.o.) + + + + + .NET Debugger events + + + + + Events intended for monitoring on an ongoing basis. + + + + + Events that will dump PDBs of dynamically generated assemblies to the ETW stream. + + + + + Recommend default flags (good compromise on verbosity). + + + + + What is needed to get symbols for JIT compiled code. + + + + + This provides the flags commonly needed to take a heap .NET Heap snapshot with ETW. + + + + + Fetch the state object associated with this parser and cast it to + the ClrTraceEventParserState type. This state object contains any + informtion that you need from one event to another to decode events. + (typically ID->Name tables). + + + + + Note that this field is derived from teh TotalPromotedSize* fields. If nothing was promoted, it is possible + that this could give a number that is smaller than what GC/Start or GC/Stop would indicate. + + + + + Returns the edge at the given zero-based index (index less than Count). The returned BulkTypeValues + points the the data in GCBulkRootEdgeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the BulkTypeTraceData. It can only be used as long as + the BulkTypeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + On the desktop this is the Method Table Pointer + In project N this is the pointer to the EE Type + + + + + For Desktop this is the Module* + For project N it is image base for the module that the type lives in? + + + + + On desktop this is the Meta-data token? + On project N it is the RVA of the typeID + + + + + Note that this method returns the type name with generic parameters in .NET Runtime + syntax e.g. System.WeakReference`1[System.Diagnostics.Tracing.EtwSession] + + + + + Returns the edge at the given zero-based index (index less than Count). The returned GCBulkRootEdgeValues + points the the data in GCBulkRootEdgeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkEdgeTraceData. It can only be used as long as + the GCBulkEdgeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the range at the given zero-based index (index less than Count). The returned GCBulkRootConditionalWeakTableElementEdgeValues + points the the data in GCBulkRootConditionalWeakTableElementEdgeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkRootConditionalWeakTableElementEdgeTraceData. It can only be used as long as + the GCBulkRootConditionalWeakTableElementEdgeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the node at the given zero-based index (idx less than Count). The returned GCBulkNodeNodes + points the the data in GCBulkNodeTraceData so it cannot live beyond that lifetime. + + + + + This unsafe interface may go away. Use the 'Nodes(idx)' instead + + + + + This structure just POINTS at the data in the GCBulkNodeTraceData. It can only be used as long as + the GCBulkNodeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the 'idx' th edge. + The returned GCBulkEdgeEdges cannot live beyond the TraceEvent that it comes from. + + + + + This structure just POINTS at the data in the GCBulkNodeTraceData. It can only be used as long as + the GCBulkNodeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the range at the given zero-based index (index less than Count). The returned GCBulkSurvivingObjectRangesValues + points the the data in GCBulkSurvivingObjectRangesTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkEdgeTraceData. It can only be used as long as + the GCBulkEdgeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the range at the given zero-based index (index less than Count). The returned GCBulkSurvivingObjectRangesValues + points the the data in GCBulkSurvivingObjectRangesTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkEdgeTraceData. It can only be used as long as + the GCBulkEdgeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + We keep Heap history for every Generation in 'Gens' + + + + + Taken from gcrecords.h, used to differentiate heap expansion and compaction reasons + + + + + Version 0, PreciseVersion 0.1: Silverlight (x86) + 0:041> dt -r2 coreclr!WKS::gc_history_per_heap + +0x000 gen_data : [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B : [0 - 40), [40 - 80), [80 - 120), [120 - 160), [160 - 200) + +0x004 size_after : Uint4B/8B + +0x008 current_size : Uint4B/8B + +0x00c previous_size : Uint4B/8B + +0x010 fragmentation : Uint4B/8B + +0x014 in : Uint4B/8B + +0x018 out : Uint4B/8B + +0x01c new_allocation : Uint4B/8B + +0x020 surv : Uint4B/8B + +0x024 growth : Uint4B/8B + +0x0c8 mem_pressure : Uint4B : 200 + +0x0cc mechanisms : [2] Uint4B : 204 (expand), 208 (compact) + +0x0d4 gen_condemn_reasons : Uint4B : 212 + +0x0d8 heap_index : Uint4B : 216 + + clrInstanceId : byte : 220 + + Version 0, PreciseVersion 0.2: .NET 4.0 + 0:000> dt -r2 clr!WKS::gc_history_per_heap + +0x000 gen_data : [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B : [0 - 40), [40 - 80), [80 - 120), [120 - 160), [160 - 200) + +0x004 size_after : Uint4B/8B + +0x008 current_size : Uint4B/8B + +0x00c previous_size : Uint4B/8B + +0x010 fragmentation : Uint4B/8B + +0x014 in : Uint4B/8B + +0x018 out : Uint4B/8B + +0x01c new_allocation : Uint4B/8B + +0x020 surv : Uint4B/8B + +0x024 growth : Uint4B/8B + +0x0c8 mem_pressure : Uint4B : 200 + +0x0cc mechanisms : [3] Uint4B : 204 (expand), 208 (compact), 212 (concurrent_compact) + +0x0d8 gen_condemn_reasons : Uint4B : 216 + +0x0dc heap_index : Uint4B : 220 + + clrInstanceId : byte : 224 + + vm\gcrecord.h + Etw_GCDataPerHeapSpecial(...) + ... + EventDataDescCreate(EventData[0], gc_data_per_heap, datasize); + EventDataDescCreate(EventData[1], ClrInstanceId, sizeof(ClrInstanceId)); + + Version 1: ??? + + Version 2, PreciseVersion 2.1: .NET 4.5 (x86) + 0:000> dt -r2 WKS::gc_history_per_heap + clr!WKS::gc_history_per_heap + +0x000 gen_data : [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B : [0 - 40), [40 - 80), [80 - 120), [120 - 160), [160 - 200) + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c out : Uint4B/8B + +0x020 new_allocation : Uint4B/8B + +0x024 surv : Uint4B/8B + +0x0c8 gen_to_condemn_reasons : WKS::gen_to_condemn_tuning + +0x000 condemn_reasons_gen : Uint4B : 200 + +0x004 condemn_reasons_condition : Uint4B : 204 + +0x0d0 mem_pressure : Uint4B : 208 + +0x0d4 mechanisms : [2] Uint4B : 212 (expand), 216 (compact) + +0x0dc heap_index : Uint4B : 220 + + vm\gcrecord.h + Etw_GCDataPerHeapSpecial(...) + ... + EventDataDescCreate(EventData[0], gc_data_per_heap, datasize); + EventDataDescCreate(EventData[1], ClrInstanceId, sizeof(ClrInstanceId)); + + Version 2, PreciseVersion 2.2: .NET 4.5.2 (x86) + 0:000> dt -r2 WKS::gc_history_per_heap + clr!WKS::gc_history_per_heap + +0x000 gen_data : [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B : [0 - 40), [40 - 80), [80 - 120), [120 - 160), [160 - 200) + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c out : Uint4B/8B + +0x020 new_allocation : Uint4B/8B + +0x024 surv : Uint4B/8B + +0x0c8 gen_to_condemn_reasons : WKS::gen_to_condemn_tuning + +0x000 condemn_reasons_gen : Uint4B : 200 + +0x004 condemn_reasons_condition : Uint4B : 204 + +0x0d0 mem_pressure : Uint4B : 208 + +0x0d4 mechanisms : [2] Uint4B : 212 (expand), 216 (compact) + +0x0dc heap_index : Uint4B : 220 + +0x0e0 extra_gen0_committed : Uint8B : 224 + + vm\gcrecord.h + Etw_GCDataPerHeapSpecial(...) + ... + EventDataDescCreate(EventData[0], gc_data_per_heap, datasize); + EventDataDescCreate(EventData[1], ClrInstanceId, sizeof(ClrInstanceId)); + + Version 3: .NET 4.6 (x86) + 0:000> dt -r2 WKS::gc_history_per_heap + clr!WKS::gc_history_per_heap + +0x000 gen_data : [4] + WKS::gc_generation_data + +0x000 size_before : Uint4B/8B + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c pinned_surv : Uint4B/8B + +0x020 npinned_surv : Uint4B/8B + +0x024 new_allocation : Uint4B/8B + +0x0a0 maxgen_size_info : WKS::maxgen_size_increase + +0x000 free_list_allocated : Uint4B/8B + +0x004 free_list_rejected : Uint4B/8B + +0x008 end_seg_allocated : Uint4B/8B + +0x00c condemned_allocated : Uint4B/8B + +0x010 pinned_allocated : Uint4B/8B + +0x014 pinned_allocated_advance : Uint4B/8B + +0x018 running_free_list_efficiency : Uint4B/8B + +0x0bc gen_to_condemn_reasons : WKS::gen_to_condemn_tuning + +0x000 condemn_reasons_gen : Uint4B + +0x004 condemn_reasons_condition : Uint4B + +0x0c4 mechanisms : [2] Uint4B + +0x0cc machanism_bits : Uint4B + +0x0d0 heap_index : Uint4B + +0x0d4 extra_gen0_committed : Uint4B/8B + + pal\src\eventprovider\lttng\eventprovdotnetruntime.cpp + FireEtXplatGCPerHeapHistory_V3(...) + + tracepoint( + DotNETRuntime, + GCPerHeapHistory_V3, x86 offsets + ClrInstanceID, : 0 + (const size_t) FreeListAllocated, : 2 + (const size_t) FreeListRejected, : 6 + (const size_t) EndOfSegAllocated, : 10 + (const size_t) CondemnedAllocated, : 14 + (const size_t) PinnedAllocated, : 18 + (const size_t) PinnedAllocatedAdvance, : 22 + RunningFreeListEfficiency, : 26 + CondemnReasons0, : 30 + CondemnReasons1 : 34 + ); + tracepoint( + DotNETRuntime, + GCPerHeapHistory_V3_1, + CompactMechanisms, : 38 + ExpandMechanisms, : 42 + HeapIndex, : 46 + (const size_t) ExtraGen0Commit, : 50 + Count, : 54 (number of WKS::gc_generation_data's) + Arg15_Struct_Len_, : ?? not really sent + (const int*) Arg15_Struct_Pointer_ : [58 - 98), ... + ); + + Version 3 is now setup to allow "add to the end" scenarios + + + + + + Returns the condemned generation number + + + + + Returns the condemned condition + + + + + genNumber is a number from 0 to maxGenData-1. These are for generation 0, 1, 2, 3 = Large Object Heap + genNumber = 4 is that second pass for Gen 0. + + + + + Version 0: Silverlight (x86), .NET 4.0 + [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B + +0x004 size_after : Uint4B/8B + +0x008 current_size : Uint4B/8B + +0x00c previous_size : Uint4B/8B + +0x010 fragmentation : Uint4B/8B + +0x014 in : Uint4B/8B + +0x018 out : Uint4B/8B + +0x01c new_allocation : Uint4B/8B + +0x020 surv : Uint4B/8B + +0x024 growth : Uint4B/8B + + Version 1: ??? + + Version 2, PreciseVersion 2.1: .NET 4.5 (x86), .NET 4.5.2 (x86) + [5] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c out : Uint4B/8B + +0x020 new_allocation : Uint4B/8B + +0x024 surv : Uint4B/8B + + Version 3: .NET 4.6 (x86) + [4] WKS::gc_generation_data + +0x000 size_before : Uint4B/8B + +0x004 free_list_space_before : Uint4B/8B + +0x008 free_obj_space_before : Uint4B/8B + +0x00c size_after : Uint4B/8B + +0x010 free_list_space_after : Uint4B/8B + +0x014 free_obj_space_after : Uint4B/8B + +0x018 in : Uint4B/8B + +0x01c pinned_surv : Uint4B/8B + +0x020 npinned_surv : Uint4B/8B + +0x024 new_allocation : Uint4B/8B + + + + + Size of the generation before the GC, includes fragmentation + + + + + Size of the generation after GC. Includes fragmentation + + + + + Size occupied by objects at the beginning of the GC, discounting fragmentation. + Only exits on 4.5 RC and beyond. + + + + + This is the fragmenation at the end of the GC. + + + + + Size occupied by objects, discounting fragmentation. + + + + + This is the free list space (ie, what's threaded onto the free list) at the beginning of the GC. + Only exits on 4.5 RC and beyond. + + + + + This is the free obj space (ie, what's free but not threaded onto the free list) at the beginning of the GC. + Only exits on 4.5 RC and beyond. + + + + + This is the free list space (ie, what's threaded onto the free list) at the end of the GC. + Only exits on 4.5 Beta and beyond. + + + + + This is the free obj space (ie, what's free but not threaded onto the free list) at the end of the GC. + Only exits on 4.5 Beta and beyond. + + + + + This is the amount that came into this generation on this GC + + + + + This is the number of bytes survived in this generation. + + + + + This is the new budget for the generation + + + + + This is the survival rate + + + + + Version 0: ??? + + Version 1: Silverlight (x86), .NET 4.0, .NET 4.5, .NET 4.5.2 + VM\gc.cpp + 0:041> dt -r3 WKS::gc_history_global + coreclr!WKS::gc_history_global + +0x000 final_youngest_desired : Uint4B/8B + +0x004 num_heaps : Uint4B + +0x008 condemned_generation : Int4B + +0x00c gen0_reduction_count : Int4B + +0x010 reason : + reason_alloc_soh = 0n0 + reason_induced = 0n1 + reason_lowmemory = 0n2 + reason_empty = 0n3 + reason_alloc_loh = 0n4 + reason_oos_soh = 0n5 + reason_oos_loh = 0n6 + reason_induced_noforce = 0n7 + reason_gcstress = 0n8 + reason_max = 0n9 + +0x014 global_mechanims_p : Uint4B + + FireEtwGCGlobalHeapHistory_V1(gc_data_global.final_youngest_desired, // upcast on 32bit to __int64 + gc_data_global.num_heaps, + gc_data_global.condemned_generation, + gc_data_global.gen0_reduction_count, + gc_data_global.reason, + gc_data_global.global_mechanims_p, + GetClrInstanceId()); + Version 2: .NET 4.6 + clr!WKS::gc_history_global + +0x000 final_youngest_desired : Uint4B/8B + +0x004 num_heaps : Uint4B + +0x008 condemned_generation : Int4B + +0x00c gen0_reduction_count : Int4B + +0x010 reason : + reason_alloc_soh = 0n0 + reason_induced = 0n1 + reason_lowmemory = 0n2 + reason_empty = 0n3 + reason_alloc_loh = 0n4 + reason_oos_soh = 0n5 + reason_oos_loh = 0n6 + reason_induced_noforce = 0n7 + reason_gcstress = 0n8 + reason_lowmemory_blocking = 0n9 + reason_induced_compacting = 0n10 + reason_lowmemory_host = 0n11 + reason_max = 0n12 + +0x014 pause_mode : Int4B + +0x018 mem_pressure : Uint4B + +0x01c global_mechanims_p : Uint4B + + FireEtwGCGlobalHeapHistory_V2(gc_data_global.final_youngest_desired, // upcast on 32bit to __int64 + gc_data_global.num_heaps, + gc_data_global.condemned_generation, + gc_data_global.gen0_reduction_count, + gc_data_global.reason, + gc_data_global.global_mechanims_p, + GetClrInstanceId()); + gc_data_global.pause_mode, + gc_data_global.mem_pressure); + + + + + + Gets the full type name including generic parameters in runtime syntax + For example System.WeakReference`1[System.Diagnostics.Tracing.EtwSession] + + + + + Returns the CCW at the given zero-based index (index less than Count). The returned GCBulkRootCCWValues + points the the data in GCBulkRootCCWTraceData so it cannot live beyond that lifetime. + + + + + Computes the size of one GCBulkRootCCWValues structure. + TODO FIX NOW Can rip out and make a constant 44 after 6/2014 + + + + + This structure just POINTS at the data in the GCBulkRootCCWTraceData. It can only be used as long as + the GCBulkRootCCWTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the edge at the given zero-based index (index less than Count). The returned GCBulkRCWValues + points the the data in GCBulkRCWTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the GCBulkRCWTraceData. It can only be used as long as + the GCBulkRCWTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns 'idx'th static root. + The returned GCBulkRootStaticVarStatics cannot live beyond the TraceEvent that it comes from. + The implementation is highly tuned for sequential access. + + + + + This structure just POINTS at the data in the GCBulkRootStaticVarTraceData. It can only be used as long as + the GCBulkRootStaticVarTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Fetches the instruction pointer of a eventToStack frame 0 is the deepest frame, and the maximum should + be a thread offset routine (if you get a complete eventToStack). + + The index of the frame to fetch. 0 is the CPU EIP, 1 is the Caller of that + routine ... + The instruction pointer of the specified frame. + + + + Access to the instruction pointers as a unsafe memory blob + + + + + This is simply the file name part of the ModuleILPath. It is a convenience method. + + + + + Log events associated with the threadpool, and other threading events. + + + + + Dump the native to IL mapping of any method that is JIT compiled. (V4.5 runtimes and above). + + + + + This supresses NGEN events on V4.0 (where you have NGEN PDBs), but not on V2.0 (which does not know about this + bit and also does not have NGEN PDBS). + + + + + TODO document + + + + + Dump PDBs for dynamically generated modules. + + + + + ClrTraceEventParserState holds all information that is shared among all events that is + needed to decode Clr events. This class is registered with the source so that it will be + persisted. Things in here include + + * TypeID to TypeName mapping, + + + + + Returns the edge at the given zero-based index (index less than Count). The returned BulkNodeValues + points the the data in BulkNodeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the BulkNodeTraceData. It can only be used as long as + the BulkNodeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the edge at the given zero-based index (index less than Count). The returned BulkAttributeValues + points the the data in BulkAttributeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the BulkAttributeTraceData. It can only be used as long as + the BulkAttributeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + Returns the edge at the given zero-based index (index less than Count). The returned BulkEdgeValues + points the the data in BulkEdgeTraceData so it cannot live beyond that lifetime. + + + + + This structure just POINTS at the data in the BulkNodeTraceData. It can only be used as long as + the BulkNodeTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + The KernelTraceEventParser is a class that knows how to decode the 'standard' kernel events. + It exposes an event for each event of interest that users can subscribe to. + + see TraceEventParser for more + + + + + The special name for the Kernel session + + + + + This is passed to TraceEventSession.EnableKernelProvider to enable particular sets of + events. See http://msdn.microsoft.com/en-us/library/aa363784(VS.85).aspx for more information on them + + + + + Logs nothing + + + + + Logs the mapping of file IDs to actual (kernel) file names. + + + + + Loads the completion of Physical disk activity. + + + + + Logs native modules loads (LoadLibrary), and unloads + + + + + Logs all page faults that must fetch the data from the disk (hard faults) + + + + + Logs TCP/IP network send and receive events. + + + + + Logs process starts and stops. + + + + + Logs process performance counters (TODO When?) (Vista+ only) + see KernelTraceEventParser.ProcessPerfCtr, ProcessPerfCtrTraceData + + + + + Sampled based profiling (every msec) (Vista+ only) (expect 1K events per proc per second) + + + + + Logs threads starts and stops + + + + + log thread context switches (Vista only) (can be > 10K events per second) + + + + + log Disk operations (Vista+ only) + Generally not TOO volumous (typically less than 1K per second) (Stacks associated with this) + + + + + Thread Dispatcher (ReadyThread) (Vista+ only) (can be > 10K events per second) + + + + + log file FileOperationEnd (has status code) when they complete (even ones that do not actually + cause Disk I/O). (Vista+ only) + Generally not TOO volumous (typically less than 1K per second) (No stacks associated with these) + + + + + log the start of the File I/O operation as well as the end. (Vista+ only) + Generally not TOO volumous (typically less than 1K per second) + + + + + Logs all page faults (hard or soft) + Can be pretty volumous (> 1K per second) + + + + + Logs activity to the windows registry. + Can be pretty volumous (> 1K per second) + + + + + log calls to the OS (Vista+ only) + This is VERY volumous (can be > 100K events per second) + + + + + Log Virtual Alloc calls and VirtualFree. (Vista+ Only) + Generally not TOO volumous (typically less than 1K per second) + + + + + Log mapping of files into memmory (Win8 and above Only) + Generally low volume. + + + + + Logs Advanced Local Procedure call events. + + + + + log defered procedure calls (an Kernel mechanism for having work done asynchronously) (Vista+ only) + + + + + Device Driver logging (Vista+ only) + + + + + log hardware interrupts. (Vista+ only) + + + + + Disk I/O that was split (eg because of mirroring requirements) (Vista+ only) + + + + + Good default kernel flags. (TODO more detail) + + + + + These events are too verbose for normal use, but this give you a quick way of turing on 'interesting' events + This does not include SystemCall because it is 'too verbose' + + + + + Use this if you care about blocked time. + + + + + You mostly don't care about these unless you are dealing with OS internals. + + + + + All legal kernel events + + + + + These are the kernel events that are not allowed in containers. Can be subtracted out. + + + + + Turn on PMC (Precise Machine Counter) events. Only Win 8 + + + + + Kernel reference set events (like XPERF ReferenceSet). Fully works only on Win 8. + + + + + Events when thread priorities change. + + + + + Events when queuing and dequeuing from the I/O completion ports. + + + + + Handle creation and closing (for handle leaks) + + + + + These keywords can't be passed to the OS, they are defined by KernelTraceEventParser + + + + + What his parser should track by default. + + + + + Defines how kernel paths are converted to user paths. Setting it overrides the default path conversion mechanism. + + + + + Registers both ProcessStart and ProcessDCStart + + + + + Registers both ProcessEnd and ProcessDCStop + + + + + Registers both ThreadStart and ThreadDCStart + + + + + Registers both ThreadEnd and ThreadDCStop + + + + + Registers both ImageLoad and ImageDCStart + + + + + Registers both ImageUnload and ImageDCStop + + + + + Rasied every 0.5s with memory metrics of the current machine. + + + + + File names in ETW are the Kernel names, which need to be mapped to the drive specification users see. + This event indicates this mapping. + + + + + KernelTraceEventParserState holds all information that is shared among all events that is + needed to decode kernel events. This class is registered with the source so that it will be + persisted. Things in here include + + * FileID to FileName mapping, + * ThreadID to ProcessID mapping + * Kernel file name to user file name mapping + + + + + If you have a file object (per-open-file) in addition to a fileKey, try using both + to look up the file name. + + + + + This is for the circular buffer case. In that case we may not have thread starts (and thus we don't + have entries in threadIDtoProcessID). Because HistoryTable finds the FIRST entry GREATER than the + given threadID we NEGATE all times before we place it in this table. + + Also, because circular buffering is not the common case, we only add entries to this table if needed + (if we could not find the thread ID using threadIDtoProcessID). + + + + + Keeps track of the mapping from kernel names to file system names (drives) + + + + + Create a new KernelToUserDriveMapping that can look up kernel names for drives and map them to windows drive letters. + + + + + Returns the string representing the windows drive letter for the kernel drive name 'kernelName' + + + + + + + This is the number of minutes between the local time where the data was collected and UTC time. + It does NOT take Daylight savings time into account. + It is positive if your time zone is WEST of Greenwich. + + + + + Indicate that StartAddr and Win32StartAddr are a code addresses that needs symbolic information + + + + + We report a context switch from from the new thread. Thus NewThreadID == ThreadID. + + + + + The I/O Response Packet address. This represents the 'identity' of this particular I/O + + + + + This is the time since the I/O was initiated, in source.PerfFreq (QPC) ticks. + + + + + This is the actual time the disk spent servicing this IO. Same as elapsed time for real time providers. + + + + + The time since the I/O was initiated. + + + + + This is the time since the I/O was initiated, in source.PerfFreq (QPC) ticks. + + + + + The time since the I/O was initiated. + + + + + This is a handle that represents a file NAME (not an open file). + In the MSDN does this field is called FileObject. However in other events FileObject is something + returned from Create file and is different. Events have have both (and some do) use FileKey. Thus + I use FileKey uniformly to avoid confusion. + + + + + See the Windows CreateFile API CreateOptions for this + + + + + See Windows CreateFile API CreateDisposition for this. + + + + + See Windows CreateFile API ShareMode parameter + + + + + See windows CreateFile API ShareMode parameter + + + + + See Windows CreateFile function CreateDispostion parameter. + + + + + See Windows CreateFile function FlagsAndAttributes parameter. + TODO FIX NOW: these have not been validated yet. + + + + + The FileObject is the object for the Directory (used by CreateFile to open and passed to Close to close) + + + + + The FileKey is the object that represents the name of the directory. + + + + + This is the TimeDateStamp converted to a DateTime + TODO: daylight savings time seems to mess this up. + + + + + Indicate that ProgramCounter is a code address that needs symbolic information + + + + + The time spent during the page fault. + + + + + Indicate that the Address is a code address that needs symbolic information + + + + + This event is emitted by the Microsoft-Windows-Kernel-Memory with Keyword 0x40 KERNEL_MEM_KEYWORD_MEMINFO_EX every .5 seconds + + + + + Returns the edge at the given zero-based index (index less than Count). The returned MemoryProcessMemInfoValues + points the the data in MemoryProcessMemInfoTraceData so it cannot live beyond that lifetime. + + + + + The fields after 'Count' are the first value in the array of working sets. + + + + + This structure just POINTS at the data in the MemoryProcessMemInfoTraceData. It can only be used as long as + the MemoryProcessMemInfoTraceData is alive which (unless you cloned it) is only for the lifetime of the callback. + + + + + The fields after 'Count' are the first value in the array of working sets. + + + + + Are we currently executing a Deferred Procedure Call (a mechanism the kernel uses to + 'steal' a thread to run its own work). If this is true, the CPU time is really + not logically related to the process (it is kernel time). + + + + + Are we currently executing a Interrupt Service Routine? Like ExecutingDPC if this + is true the thread is really doing Kernel work, not work for the process. + + + + + NonProcess is true if ExecutingDPC or ExecutingISR is true. + + + + + The thread's current priority (higher is more likely to run). A normal thread with a normal base + priority is 8. + see http://msdn.microsoft.com/en-us/library/windows/desktop/ms685100(v=vs.85).aspx for more + + + + + Your scheduling If the thread is not part of a scheduling group, this is 0 (see callout.c) + + + + + Indicate that the Address is a code address that needs symbolic information + + + + + PMC (Precise Machine Counter) events are fired when a CPU counter trips. The the ProfileSource identifies + which counter it is. The PerfInfoCollectionStart events will tell you the count that was configured to trip + the event. + + + + + Indicate that Address is a code address that needs symbolic information + + + + + Indicate that the Address is a code address that needs symbolic information + + + + + Collects the call callStacks for some other event. + + (TODO: always for the event that preceded it on the same thread)? + + + + + The timestamp of the event which caused this stack walk using QueryPerformaceCounter + cycles as the tick. + + + + + Converts this to a time relative to the start of the trace in msec. + + + + + The total number of eventToStack frames collected. The Windows OS currently has a maximum of 96 frames. + + + + + Fetches the instruction pointer of a eventToStack frame 0 is the deepest frame, and the maximum should + be a thread offset routine (if you get a complete stack). + + The index of the frame to fetch. 0 is the CPU EIP, 1 is the Caller of that + routine ... + The instruction pointer of the specified frame. + + + + Access to the instruction pointers as a unsafe memory blob + + + + + StackWalkTraceData does not set Thread and process ID fields properly. if that. + + + + + To save space, stack walks in Win8 can be complressed. The stack walk event only has a + reference to a stack Key which is then looked up by StackWalkDefTraceData. + + + + + The timestamp of the event which caused this stack walk using QueryPerformaceCounter + cycles as the tick. + + + + + Converts this to a time relative to the start of the trace in msec. + + + + + Returns a key that can be used to look up the stack in KeyDelete or KeyRundown events + + + + + StackWalkTraceData does not set Thread and process ID fields properly. if that. + + + + + This event defines a stack and gives it a unique id (the StackKey), which StackWalkRefTraceData can point at. + + + + + Returns a key that can be used to look up the stack in KeyDelete or KeyRundown events + + + + + The total number of eventToStack frames collected. The Windows OS currently has a maximum of 96 frames. + + + + + Fetches the instruction pointer of a eventToStack frame 0 is the deepest frame, and the maximum should + be a thread offset routine (if you get a complete complete). + + The index of the frame to fetch. 0 is the CPU EIP, 1 is the Caller of that + routine ... + The instruction pointer of the specified frame. + + + + Access to the instruction pointers as a unsafe memory blob + + + + + e.g. c:\windows\system32 + + + + + .e.g c:\windows + + + + + Kernel traces have information about images that are loaded, however they don't have enough information + in the events themselves to unambigously look up PDBs without looking at the data inside the images. + This means that symbols can't be resolved unless you are on the same machine on which you gathered the data. + + XPERF solves this problem by adding new 'synthetic' events that it creates by looking at the trace and then + opening each DLL mentioned and extracting the information needed to look PDBS up on a symbol server (this + includes the PE file's TimeDateStamp as well as a PDB Guid, and 'pdbAge' that can be found in the DLLs header. + + These new events are added when XPERF runs the 'merge' command (or -d flag is passed). It is also exposed + through the KernelTraceControl.dll!CreateMergedTraceFile API. + + SymbolTraceEventParser is a parser for extra events. + + + + + The DbgIDRSDS event is added by XPERF for every Image load. It contains the 'PDB signature' for the DLL, + which is enough to unambiguously look the image's PDB up on a symbol server. + + + + + Every DLL has a Timestamp in the PE file itself that indicates when it is built. This event dumps this timestamp. + This timestamp is used to be as the 'signature' of the image and is used as a key to find the symbols, however + this has mostly be superseded by the DbgID/RSDS event. + + + + + The FileVersion event contains information from the file version resource that most DLLs have that indicated + detailed information about the exact version of the DLL. (What is in the File->Properties->Version property + page) + + + + + I don't really care about this one, but I need a definition in order to exclude it because it + has the same timestamp as a imageLoad event, and two events with the same timestamp confuse the + association between a stack and the event for the stack. + + + + + This event has a TRACE_EVENT_INFO as its payload, and allows you to decode an event + + + + + The event describes a Map (bitmap or ValueMap), and has a payload as follows + + GUID ProviderId; + EVENT_MAP_INFO EventMapInfo; + + + + + The value of the one string payload property. + + + + + Construct a TraceEvent template which has one string payload field with the given metadata and action + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + override + + + + + RegisteredTraceEventParser uses the standard windows provider database (TDH, what gets registered with wevtutil) + to find the names of events and fields of the events). + + + + + Create a new RegisteredTraceEventParser and attach it to the given TraceEventSource + + + + + Given a provider name that has been registered with the operating system, get + a string representing the ETW manifest for that provider. Note that this + manifest is not as rich as the original source manifest because some information + is not actually compiled into the binary manifest that is registered with the OS. + + + + + Given a provider GUID that has been registered with the operating system, get + a string representing the ETW manifest for that provider. Note that this + manifest is not as rich as the original source manifest because some information + is not actually compiled into the binary manifest that is registered with the OS. + + + + + Generates a space separated list of set of keywords 'keywordSet' using the table 'keywords' + It will generate new keyword names if needed and add them to 'keywords' if they are not present. + + + + + Class used to accumulate information about Tasks in the implementation of GetManifestForRegisteredProvider + + + + + Try to look up 'unknonwEvent using TDH or the TraceLogging mechanism. if 'mapTable' is non-null it will be used + look up the string names for fields that have bitsets or enumerated values. This is only need for the KernelTraceControl + case where the map information is logged as special events and can't be looked up with TDH APIs. + + + + + TdhEventParser takes the Trace Diagnostics Helper (TDH) TRACE_EVENT_INFO structure and + (passed as a byte*) and converts it to a DynamicTraceEventData which which + can be used to parse events of that type. You first create TdhEventParser and then + call ParseEventMetaData to do the parsing. + + + + + Creates a new parser from the TRACE_EVENT_INFO held in 'buffer'. Use + ParseEventMetaData to then parse it into a DynamicTraceEventData structure. + EventRecord can be null and mapTable if present allow the parser to resolve maps (enums), and can be null. + + + + + Actually performs the parsing of the TRACE_EVENT_INFO passed in the constructor + + + + + + Parses at most 'maxFields' fields starting at the current position. + Will return the parse fields in 'payloadNamesRet' and 'payloadFetchesRet' + Will return true if successful, false means an error occurred. + + + + + ExternalTraceEventParser is an abstract class that acts as a parser for any 'External' resolution + This include the TDH (RegisteredTraceEventParser) as well as the WPPTraceEventParser. + + + + + Create a new ExternalTraceEventParser and attach it to the given TraceEventSource + + + + + Override. + + + + + Override + + + + + Returns true if the RegisteredTraceEventParser would return 'template' in EnumerateTemplates + + + + + override + + + + + Register 'template' so that if there are any subscriptions to template they get registered with the source. + + + + + Used to look up Enums (provider x enumName); Very boring class. + + + + + TDHDynamicTraceEventParserState represents the state of a TDHDynamicTraceEventParser that needs to be + serialized to a log file. It does NOT include information about what events are chosen but DOES contain + any other necessary information that came from the ETL data file or the OS TDH APIs. + + + + + This defines what it means to be the same event. For manifest events it means provider and event ID + for classic, it means that taskGuid and opcode match. + + + + + Implements IFastSerializable interface + + + + + Implements IFastSerializable interface + + + + + This parser knows how to decode Windows Software Trace Preprocessor (WPP) events. In order to decode + the events it needs access to the TMF files that describe the events (these are created from the PDB at + build time). +
+ You will generally use this for the 'FormattedMessage' property of the event. +
+
+ + + Construct a new WPPTraceEventParser that is attached to 'source'. Once you do this the source + will understand WPP events. In particular you can subscribe to the Wpp.All event to get the + stream of WPP events in the source. For WppTraceEventParser to function, it needs the TMF + files for the events it will decode. You should pass the directory to find these TMF files + in 'TMFDirectory'. Each file should have the form of a GUID.tmf. + + + + + + + ETWReloggerTraceEventSource is designed to be able to write ETW files using an existing ETW input stream (either a file, files or real time session) as a basis. + The relogger capabilities only exist on Windows 8 OSes and beyond. + + The right way to think about this class is that it is just like ETWTraceEventSource, but it also has a output file associated with it, and WriteEvent APIs that + can be used to either copy events from the event stream (the common case), or inject new events (high level stats). + + + + + Create an ETWReloggerTraceEventSource that can takes its input from the family of etl files inputFileName + and can write them to the ETL file outputFileName (.kernel*.etl, .user*.etl .clr*.etl) + + This is a shortcut for ETWReloggerTraceEventSource(inputFileName, TraceEventSourceType.MergeAll, outputFileStream) + + + + + Create an ETWReloggerTraceEventSource that can takes its input from a variety of sources (either a single file, + a set of files, or a real time ETW session (based on 'type'), and can write these events to a new ETW output + file 'outputFileName. + + + + + The output file can use a compressed form or not. Compressed forms can only be read on Win8 and beyond. Defaults to true. + + + + + Writes an event from the input stream to the output stream of events. + + + + + Connect the given EventSource so any events logged from it will go to the output stream of events. + Once connected, you may only write events from this EventSource while processing the input stream + (that is during the callback of an input stream event), because the context for the EventSource event + (e.g. timestamp, proesssID, threadID ...) will be derived from the current event being processed by + the input stream. + + + + + Writes an event that did not exist previously into the data stream, The context data (time, process, thread, activity, comes from 'an existing event') + + + + + Writes an event that did not exist previously into the data stream, The context data (time, process, thread, activity, comes from 'an existing event') is given explicitly + + + + + implementing TraceEventDispatcher + + + + + implementing TraceEventDispatcher + + + + + Implements TraceEventDispatcher.Dispose + + + + + Implements TraceEventDispatcher.StopProcessing + + + + + This is used by the ConnectEventSource to route events from the EventSource to the relogger. + + + + + This is the class the Win32 APIs call back on. + + + + + A ETWTraceEventSource represents the stream of events that was collected from a + TraceEventSession (eg the ETL moduleFile, or the live session event stream). Like all + TraceEventSource, it logically represents a stream of TraceEvent s. Like all + TraceEventDispathers it supports a callback model where Parsers attach themselves to this + sources, and user callbacks defined on the parsers are called when the 'Process' method is called. + + * See also TraceEventDispatcher + * See also TraceEvent + * See also #ETWTraceEventSourceInternals + * See also #ETWTraceEventSourceFields + + + + + Open a ETW event trace moduleFile (ETL moduleFile) for processing. + + The ETL data moduleFile to open` + + + + Open a ETW event source for processing. This can either be a moduleFile or a real time ETW session + + + If type == ModuleFile this is the name of the moduleFile to open. + If type == Session this is the name of real time session to open. + + + + + Process all the files in 'fileNames' in order (that is all the events in the first + file are processed, then the second ...). Intended for parsing the 'Multi-File' collection mode. + + The list of files path names to process (in that order) + + + + Processes all the events in the data source, issuing callbacks that were subscribed to. See + #Introduction for more + + false If StopProcesing was called + + + + Reprocess a pre-constructed event which this processor has presumably created. Helpful to re-examine + "unknown" events, perhaps after a manifest has been received from the ETW stream. + Note when queuing events to reprocess you must Clone them first + or certain internal data may no longer be available and you may receive memory access violations. + + Event to re-process. + + + + The log moduleFile that is being processed (if present) + TODO: what does this do for Real time sessions? + + + + + The name of the session that generated the data. + + + + + The size of the log, will return 0 if it does not know. + + + + + returns the number of events that have been lost in this session. Note that this value is NOT updated + for real time sessions (it is a snapshot). Instead you need to use the TraceEventSession.EventsLost property. + + + + + Returns true if the Process can be called multiple times (if the Data source is from a + moduleFile, not a real time stream. + + + + + This routine is only useful/valid for real-time sessions. + + TraceEvent.TimeStamp internally is stored using a high resolution clock called the Query Performance Counter (QPC). + This clock is INDEPENDENT of the system clock used by DateTime. These two clocks are synchronized to within 2 msec at + session startup but they can drift from there (typically 2msec / min == 3 seconds / day). Thus if you have long + running real time session it becomes problematic to compare the timestamps with those in another session or something + timestamped with the system clock. SynchronizeClock will synchronize the TraceEvent.Timestamp clock with the system + clock again. If you do this right before you start another session, then the two sessions will be within 2 msec of + each other, and their timestamps will correlate. Doing it periodically (e.g. hourly), will keep things reasonably close. + + TODO: we can achieve perfect synchronization by exposing the QPC tick sync point so we could read the sync point + from one session and set that exact sync point for another session. + + + + + Options that can be passed to GetModulesNeedingSymbols + + + + + This is the default, where only NGEN images are included (since these are the only images whose PDBS typically + need to be resolved agressively AT COLLECTION TIME) + + + + + If set, this option indicates that non-NGEN images should also be included in the list of returned modules + + + + + Normally only modules what have a CPU or stack sample are included in the list of assemblies (thus you don't + unnecessarily have to generate NGEN PDBS for modules that will never be looked up). However if there are + events that have addresses that need resolving that this routine does not recognise, this option can be + set to insure that any module that was event LOADED is included. This is inefficient, but guarenteed to + be complete + + + + + Given an ETL file, returns a list of the full paths to DLLs that were loaded in the trace that need symbolic + information (PDBs) so that the stack traces and CPU samples can be properly resolved. By default this only + returns NGEN images since these are the ones that need to be resolved and generated at collection time. + + + + + Image data is a trivial record for image data, where it is keyed by the base address, processID and name. + + + + + Returns the size of pointer (8 or 4) for the operating system (not necessarily the process) + + + + + This is a little helper class that maps QueryPerformanceCounter (QPC) ticks to DateTime. There is an error of + a few msec, but as long as every one uses the same one, we probably don't care. + + + + + see Dispose pattern + + + + + see Dispose pattern + + + + + Used by real time TraceLog on Windows7. + If we have several real time sources we have them coming in on several threads, but we want the illusion that they + are one source (thus being processed one at a time). Thus we want a lock that is taken on every dispatch. + + + + + The kinds of data sources that can be opened (see ETWTraceEventSource) + + + + + Look for any files like *.etl or *.*.etl (the later holds things like *.kernel.etl or *.clrRundown.etl ...) + + + + + Look for a ETL moduleFile *.etl as the event data source + + + + + Use a real time session as the event data source. + + + + + EventPipeEventSource knows how to decode EventPipe (generated by the .NET core runtime). + Please see for details on the file format. + + By conventions files of such a format are given the .netperf suffix and are logically + very much like a ETL file in that they have a header that indicate things about + the trace as a whole, and a list of events. Like more modern ETL files the + file as a whole is self-describing. Some of the events are 'MetaData' events + that indicate the provider name, event name, and payload field names and types. + Ordinary events then point at these meta-data event so that logically all + events have a name some basic information (process, thread, timestamp, activity + ID) and user defined field names and values of various types. + + + + + This is the version number reader and writer (although we don't don't have a writer at the moment) + It MUST be updated (as well as MinimumReaderVersion), if breaking changes have been made. + If your changes are forward compatible (old readers can still read the new format) you + don't have to update the version number but it is useful to do so (while keeping MinimumReaderVersion unchanged) + so that readers can quickly determine what new content is available. + + + + + This field is only used for writers, and this code does not have writers so it is not used. + It should be set to Version unless changes since the last version are forward compatible + (old readers can still read this format), in which case this shoudl be unchanged. + + + + + This is the smallest version that the deserializer here can read. Currently + we are careful about backward compat so our deserializer can read anything that + has ever been produced. We may change this when we believe old writers basically + no longer exist (and we can remove that support code). + + + + + Give meta-data for an event, passed as a EventPipeEventMetaDataHeader and readerForParameters + which is a StreamReader that points at serialized parameter information, decode the meta-data + and record a template associated with this source. The readerForParameters is advanced beyond + the event parameters information. + + + + + Given the EventPipe metaData header and a stream pointing at the serialized meta-data for the parameters for the + event, create a new DynamicTraceEventData that knows how to parse that event. + ReaderForParameters.Current is advanced past the parameter information. + + + + + An EVentPipeEventBlock represents a block of events. It basicaly only has + one field, which is the size in bytes of the block. But when its FromStream + is called, it will perform the callbacks for the events (thus deserializing + it performs dispatch). + + + + + Private utility class. + + An EventPipeEventMetaDataHeader holds the information that can be shared among all + instances of an EventPipe event from a particular provider. Thus it contains + things like the event name, provider, It however does NOT contain the data + about the event parameters (the names of the fields and their types), That is + why this is a meta-data header and not all the meta-data. + + This class has two main functions + 1. The constructor takes a PinnedStreamReader and decodes the serialized metadata + so you can access the data conveniently (but it does not decode the parameter info) + 2. It remembers a EVENT_RECORD structure (from ETW) that contains this data) + and has a function GetEventRecordForEventData which converts from a + EventPipeEventHeader (the raw serialized data) to a EVENT_RECORD (which + is what TraceEvent needs to look up the event an pass it up the stack. + + + + + Creates a new MetaData instance from the serialized data at the current position of 'reader' + of length 'length'. This typically points at the PAYLOAD AREA of a meta-data events) + 'fileFormatVersionNumber' is the version number of the file as a whole + (since that affects the parsing of this data) and 'processID' is the process ID for the + whole stream (since it needs to be put into the EVENT_RECORD. + + When this constructor returns the reader has read up to the serialized information about + the parameters. We do this because this code does not know the best representation for + this parameter information and so it just lets other code handle it. + + + + + Given a EventPipeEventHeader takes a EventPipeEventHeader that is specific to an event, copies it + on top of the static information in its EVENT_RECORD which is specialized meta-data + and returns a pointer to it. Thus this makes the EventPipe look like an ETW provider from + the point of view of the upper level TraceEvent logic. + + + + + This is a number that is unique to this meta-data blob. It is expected to be a small integer + that starts at 1 (since 0 is reserved) and increases from there (thus an array can be used). + It is what is matched up with EventPipeEventHeader.MetaDataId + + + + + Reads the meta data for information specific to one event. + + + + + Private utility class. + + At the start of every event from an EventPipe is a header that contains + common fields like its size, threadID timestamp etc. EventPipeEventHeader + is the layout of this. Events have two variable sized parts: the user + defined fields, and the stack. EventPipEventHeader knows how to + decode these pieces (but provides no semantics for it. + + It is not a public type, but used in low level parsing of EventPipeEventSource. + + + + + Header Size is defined to be the number of bytes before the Payload bytes. + + + + + Fetches the instruction pointer of a eventToStack frame 0 is the deepest frame, and the maximum should + be a thread offset routine (if you get a complete eventToStack). + + The index of the frame to fetch. 0 is the CPU EIP, 1 is the Caller of that + routine ... + The instruction pointer of the specified frame. + + + + Access to the instruction pointers as a unsafe memory blob + + + + + SampleInfos of a set of stackSource by eventToStack. This represents the entire call tree. You create an empty one in using + the default constructor and use 'AddSample' to add stackSource to it. You traverse it by + + + + + Creates an empty call tree, indicating the scaling policy of the metric. You populate it by assigning a StackSOurce to the tree. + + + + + A CallTree is generated from a StackSource. Setting the StackSource causes the tree to become populated. + + + + + When calculating percentages, the PercentageBasis do we use as 100%. By default we use the + Inclusive time for the root, but that can be changed here. + + + + + Returns the root node of the call tree. + + + + + An upper bound for the node indexes in the call tree. (All indexes + are strictly less than this number) Thus ASSSUMING YOU DON'T ADD + NEW NODES, an array of this size can be used to index the nodes (and + thus lookup nodes by index or to store additional information about a node). + + + + + Get a CallerCalleeNode for the nodes in the call tree named 'nodeName' + + + + + Returns a list of nodes that have statistics rolled up by treeNode by ID. It is not + sorted by anything in particular. Note that ID is not quite the same thing as the + name. You can have two nodes that have different IDs but the same Name. These + will show up as two distinct entries in the resulting list. + + + + + Returns the list returned by the ByID property sorted by exclusive metric. + + + + + If there are any nodes that have strictly less than to 'minInclusiveMetric' + then remove the node, placing its samples into its parent (thus the parent's + exclusive metric goes up). + + If useWholeTraceMetric is true, nodes are only folded if their inclusive metric + OVER THE WHOLE TRACE is less than 'minInclusiveMetric'. If false, then a node + is folded if THAT NODE has less than the 'minInclusiveMetric' + + Thus if 'useWholeTraceMetric' == false then after calling this routine no + node will have less than minInclusiveMetric. + + + + + + Cause the children of each CallTreeNode in the CallTree to be sorted (accending) based on comparer + + + + + Sorting by InclusiveMetric Decending is so common, provide a shortcut. + + + + + When converting the InclusiveMetricByTime to a InclusiveMetricByTimeString you have to decide + how to scale the samples to the digits displayed in the string. This enum indicates this policy + + + + + The nodes in the calltree have histograms in time, all of these histograms share a controller that + contains sharable information. This propertly returns that TimeHistogramController + + + + + The nodes in the calltree have histograms indexed by scenario (which is user defiend), + all of these histograms share a controller that contains sharable information. + This propertly returns that ScenarioHistogramController + + + + + Turns off logic for computing call trees in parallel. Safer but slower. + + + This is off by default following indications of race conditions. + + + + + Break all links in the call tree to free as much memory as possible. + + + + + Write an XML representtaion of the CallTree to 'writer' + + + + + An XML representtaion of the CallTree (for debugging) + + + + + Traverse the subtree of 'treeNode' into the m_sumByID dictionary. We don't want to + double-count inclusive times, so we have to keep track of all callers currently on the + stack and we only add inclusive times for nodes that are not already on the stack. + + + + + ScalingPolicyKind represents the desired way to scale the metric in the samples. + + + + + This is the default. In this policy, 100% is chosen so that the histogram is scaled as best it can. + + + + + It assumes that the metric represents time + + + + + Represents a unique ID for a node in a call tree. Can be used to look up a call tree node easily. + It is a dense value (from 0 up to a maximum). + + + + + An Invalid Node Index. + + + + + A CallTreeNodeBase is the inforation in a CallTreeNode without parent or child relationships. + ByName nodes and Caller-Callee nodes need this because they either don't have or need different + parent-child relationships. + + + + + Returns a unique small, dense number (suitable for looking up in an array) that represents + this call tree node (unlike the ID, which more like the name of the frame of the node), so you + can have many nodes with the same name, but only one with the same index. See CallTree.GetNodeIndexLimit. + + + + + Create a CallTreeNodeBase (a CallTreeNode without children) which is a copy of another one. + + + + + The Frame name that this tree node represents. + + + + + Currently the same as Name, but could contain additional info. + Suitable for display but not for programmatic comparison. + + + + + The ID represents a most fine grained uniqueness associated with this node. It can represent + a method, but for sources that support 'goto source' functionality these IDs actually represent + particular lines (or more precisely program counter locations), within the method. Thus it is + very likely that there are call tree nodes that have the same name but different IDs. + + This can be StackSourceFrameIndex.Invalid for Caller-callee nodes (which have names, but no useful ID) + + If ID != Invalid, and the IDs are the same then the names are guaranteed to be the same. + + + + + The sum of the metric of all samples that are in this node or any child of this node (recursively) + + + + + The average metric of all samples that are in this node or any child of this node (recursively). + This is simply InclusiveMetric / InclusiveCount. + + + + + The sum of the metric of all samples that are in this node + + + + + The sum of the metric of all samples in this node that are there because they were folded (inlined). It is alwasy less than or equal to ExclusiveMetric. + + + + + The sum of the count of all samples that are in this node or any child of this node (recursively) + + + + + The sum of the count of all samples that are in this node + + + + + The sum of the count of all samples in this node that are there because they were folded (inlined). It is alwasy less than or equal to ExclusiveCount. + + + + + The inclusive metric, normalized to the total metric for the entire tree. + + + + + The exclusive metric, normalized to the total metric for the entire tree. + + + + + The exclusive folded metric, normalized to the total metric for the entire tree. + + + + + The time of the first sample for this node or any of its children (recursively) + + + + + The time of the first sample for this node or any of its children (recursively) + + + + + The time of the last sample for this node or any of its children (recursively) + + + + + The time of the last sample for this node or any of its children (recursively) + + + + + The difference between the first and last sample (in MSec). + + + + + The call tree that contains this node. + + + + + Returns the histogram that groups of samples associated with this node or any of its children by time buckets + + + + + Returns a string that represents the InclusiveMetricByTime Histogram by using character for every bucket (like PerfView) + + + + + Returns the histogram that groups of samples associated with this node or any of its children by scenario buckets + + + + + Returns a string that represents the InclusiveMetricByScenario Histogram by using character for every bucket (like PerfView) + + + + + Returns all the original stack samples in this node. If exclusive==true then just he + sample exclusively in this node are returned, otherwise it is the inclusive samples. + + If the original stack source that was used to create this CodeTreeNode was a FilterStackSource + then that filtering is removed in the returned Samples. + + Returns the total number of samples (the number of times 'callback' is called) + + If the callback returns false, the iteration over samples stops. + + + + + While 'GetSamples' can return all the samples in the tree, this is a relatively + inefficient way of representing the samples. Instead you can return a list of + trees whose samples represent all the samples. This is what GetTrees does. + It calls 'callback' on a set of trees that taken as a whole have all the samples + in 'node'. + + Note you ave to be careful when using this for inclusive summation of byname nodes because + you will get trees that 'overlap' (bname nodes might refer into the 'middle' of another + call tree). This can be avoided pretty easily by simply stopping inclusive traversal + whenever a tree node with that ID occurs (see GetSamples for an example). + + + + + Returns a string representing the set of XML attributes that can be added to another XML element. + + + + + An XML representation of the CallTreeNodeBase (for debugging) + + + + + The GUI sadly holds on to Call things in the model in its cache, and call tree nodes have linkes to whole + call tree. To avoid the GUI cache from holding on to the ENTIRE MODEL, we neuter the nodes when we are + done with them so that even if they are pointed to by the GUI cache it does not hold onto most of the + (dead) model. FreeMemory does this neutering. + + + + + Combines the 'this' node with 'otherNode'. If 'newOnStack' is true, then the inclusive + metrics are also updated. + + Note that I DON'T accumulate other.m_samples into this.m_samples. This is because we want to share + samples as much a possible. Thus nodes remember their samples by pointing at other call trees + and you fetch the samples by an inclusive walk of the tree. + + + + + To avoid double-counting for byname nodes, with we can be told to exclude any children with a particular ID + (the ID of the ByName node itself) if are doing the inclusive case. The goal is to count every reachable + tree exactly once. We do this by conceptually 'marking' each node with ID at the top level (when they are + enumerated as children of the Byname node), and thus any node with that excludeChildrenWithID is conceptually + marked if you encounter it as a child in the tree itself (so you should exclude it). The result is that + every node is visited exactly once (without the expense of having a 'visited' bit). + + + + + Represents a single treeNode in a CallTree + + Each node keeps all the sample with the same path to the root. + Each node also remembers its parent (caller) and children (callees). + The nodes also keeps the IDs of all its samples (so no information + is lost, just sorted by stack). You get at this through the + CallTreeNodeBase.GetSamples method. + + + + + The caller (parent) of this node + + + + + The nodes this node calls (its children). + + + + + Returns true if Callees is empty. + + + + + AllCallees is an extension of CallTreesNodes to support graphs (e.g. memory heaps). + It always starts with the 'normal' Callees, however in addition if we are + displaying a Graph, it will also children that were 'pruned' when the graph was + transformed into a tree. (by using StackSource.GetRefs). + + + + + Returns true if AllCallees is non-empty. + + + + + Returns true if the call trees came from a graph (thus AllCallees may be strictly larger than Callees) + + + + + Writes an XML representation of the call tree Node it 'writer' + + + + + Returns an XML representation of the call tree Node (for debugging); + + + + + Adds up the counts of all nodes called 'BROKEN' nodes in a particular tree node + + This is a utility function. + + + + + Creates a string that has spaces | and + signs that represent the indentation level + for the tree node. (Called from XAML) + + + + + Implements CallTreeNodesBase interface + + + + + Sort the childre of every node in the te + + + + + + Some calltrees already fill in their children, others do so lazily, in which case they + override this method. + + + + + Fold away any nodes having less than 'minInclusiveMetric'. If 'sumByID' is non-null then the + only nodes that have a less then the minInclusiveMetric for the whole trace are folded. + + + + + A CallerCalleeNode gives statistics that focus on a NAME. (unlike calltrees that use ID) + It takes all stackSource that have callStacks that include that treeNode and compute the metrics for + all the callers and all the callees for that treeNode. + + + + + Given a complete call tree, and a Name within that call tree to focus on, create a + CallerCalleeNode that represents the single Caller-Callee view for that treeNode. + + + + + The list of CallTreeNodeBase nodes that called the method represented by this CallerCalleeNode + + + + + The list of CallTreeNodeBase nodes that where called by the method represented by this CallerCalleeNode + + + + + wrtites an XML representation of the call tree Node it 'writer' + + + + + Returns an XML representation of the CallerCalleeNode (for debugging); + + + + + Implements CallTreeNodesBase interface + + + + + A caller callee view is a summation which centers around one 'focus' node which is represented by the CallerCalleeNode. + This node has a caller and callee list, and these nodes (as well as the CallerCalleNode itself) represent the aggregation + over the entire tree. + + AccumulateSamplesForNode is the routine that takes a part of a aggregated call tree (represented by 'treeNode' and adds + in the statistics for that call tree into the CallerCalleeNode aggregations (and its caller and callee lists). + + 'recursionsCount' is the number of times the focus node name has occurred in the path from 'treeNode' to the root. In + addition to setting the CallerCalleeNode aggregation, it also returns a 'weightedSummary' inclusive aggregation + FOR JUST treeNode (the CallerCalleNode is an aggregation over the entire call tree accumulated so far). + + The key problem for this routine to avoid is double counting of inclusive samples in the face of recursive functions. + Thus all samples are weighted by the recursion count before being included in 'weightedSummaryRet (as well as in + the CallerCalleeNode and its Callers and Callees). + + An important optimization is the ability to NOT create (but rather reuse) CallTreeNodes when returning weightedSummaryRet. + To accomplish this the weightedSummaryScaleRet is needed. To get the correct numerical value for weightedSummaryRet, you + actually have to scale values by weightedSummaryScaleRet before use. This allows us to represent weights of 0 (subtree has + no calls to the focus node), or cases where the subtree is completely uniform in its weighting (the subtree does not contain + any additional focus nodes), by simply returning the tree node itself and scaling it by the recursion count). + + isUniformRet is set to false if anyplace in 'treeNode' does not have the scaling factor weightedSummaryScaleRet. This + means the the caller cannot simply scale 'treeNode' by a weight to get weightedSummaryRet. + + + + + Find the Caller-Callee treeNode in 'elems' with name 'frameName'. Always succeeds because it + creates one if necessary. + + + + + AggregateCallTreeNode supports a multi-level caller-callee view. + + It does this by allow you to take any 'focus' node (typically a byname node) + and compute a tree of its callers and a tree of its callees. You do this + by passing the node of interested to either the 'CallerTree' or 'CalleeTrees'. + + The AggregateCallTreeNode remembers if if is a caller or callee node and its + 'Callees' method returns the children (which may in fact be Callers). + + What is nice about 'AggregateCallTreeNode is that it is lazy, and you only + form the part of the tree you actually explore. A classic 'caller-callee' + view is simply the caller and callee trees only explored to depth 1. + + + + + Given any node (typically a byName node, but it works on any node), Create a + tree rooted at 'node' that represents the callers of that node. + + + + + Given any node (typically a byName node, but it works on any node), Create a + tree rooted at 'node' that represents the callees of that node. + + + + + Calls 'callback' for each distinct call tree in this node. Note that the same + trees can overlap (in the case of recursive functions), so you need a mechanism + for visiting a tree only once. + + + + + Returns an XML representation of the AggregateCallTreeNode (for debugging); + + + + + Implementation of CallTreeNodeBase interface + + + + + Implementation of CallTreeNode interface + + + + + See m_callerOffset and MergeCallee for more. + + The 'this' node is a AggregateCallTree representing the 'callers' nodes. Like + MergeCallee the aggregate node represents a list of CallTreeNodes. However unlike + MergeCallee, the list of CallTreeNodes each represent a sample (a complete call stack) + and 'callerOffset' indicates how far 'up' that stack is the node of interest. + + + + + An aggregateCallTreeNode is exactly that, the sum of several callTrees + (each of which represent a number of individual samples). Thus we had to + take each sample (which is 'treenode' and merge it into the aggregate. + We do this one at a time. Thus we call MergeCallee for each calltree + in our list and we find the 'callees' of each of those nodes, and create + aggregates for the children (which is in calleeList). + + This routine is not recursive and does not touch most of the tree but + it does call SubtractOutTrees which is recursive and may look at a lot + of the tree (although we try to minimize this) + + + + + Traverse 'treeCallee' and subtract out the inclusive time for any tree that matches 'idToExclude' from the node 'statsRet'. + This is needed in AggregateCallTrees because the same trees from the focus node are in the list to aggregate, but are also + in the subtree's in various places (and thus are counted twice). We solve this by walking this subtree (in this routine) + and subtracting out any nodes that match 'idToExclude'. + + As an optimization this routine also sets the m_recurision bit 'statsRet' if anywhere in 'treeCallee' we do find an id to + exclude. That way in a common case (where there is no instances of 'idToExclude') we don't have to actualy walk the + tree the second time (we simply know that there is no adjustment necessary. + + + + + An AggregateCallTree remembers all its samples by maintaining a list of call trees + that actually contain the samples that the Aggregate represents. m_trees hold this. + + + + + AggregateCallTreeNode can represent either a 'callers' tree or a 'callees' tree. For + the 'callers' tree case the node represented by the aggregate does NOT have same ID as + the tree in the m_trees list. Instead the aggregate is some node 'up the chain' toward + the caller. m_callerOffset keeps track of this (it is the same number for all elements + in m_trees). + + For callee nodes, this number is not needed. Thus we use a illegal value (-1) to + represent that fact that the node is a callee node rather than a caller node. + + + + + A Histogram is logically an array of floating point values. Often they + represent frequency, but it can be some other metric. The X axis can + represent different things (time, scenario). It is the HisogramContoller + which understands what the X axis is. Histograms know their HistogramController + but not the reverse. + + Often Histograms are sparse (most array elements are zero), so the represnetation + is designed to optimzed for this case (an array of non-zero index, value pairs). + + + + + Create a new histogram. Every histogram needs a controller but these controllers + can be shared among many histograms. + + + + + Add a sample to this histogram. + + The sample to add. + + + + Add an amount to a bucket in this histogram. + + The amount to add to the bucket. + The bucket to add to. + + + + Computes this = this + histogram * weight in place (this is updated). + + + + + The number of buckets in this histogram. + + + + + The that controls this histogram. + + + + + Get the metric contained in a bucket. + + The bucket to retrieve. + The metric contained in that bucket. + + + + Make a copy of this histogram. + + An independent copy of this histogram. + + + + A string representation (for debugging) + + + + + + Create a histogram that is a copy of another histogram. + + The histogram to copy. + + + + Implementes IEnumerable interface + + + + + Implementes IEnumerable interface + + + + + Get an IEnumerable that can be used to enumerate the metrics stored in the buckets of this Histogram. + + + + + The controller for this histogram. + + + + + A Histogram is conceputually an array of floating point values. A Histogram Controller + contains all the information besides the values themselves need to understand the array + of floating point value. There are alot of Histograms, however they all tend to share + the same histogram controller. Thus Histograms know their Histogram controller, but not + the reverse. + + Thus HistogramContoller is a abstract class (we have one for time, and one for scenarios). + + HistogramControllers are responsible for: + + - Adding a sample to the histogram for a node (see ) + - Converting a histogram to its string representation see () + - Managing the size and scale of histograms and their corresponding display strings + + + + + The scale factor for histograms controlled by this HistogramController. + + + + + The number of buckets in each histogram controlled by this HistogramController. + + + + + The number of characters in the display string for histograms controlled by this HistogramController. + Buckets are a logial concept, where CharacterCount is a visual concept (how many you can see on the + screen right now). + + + + + The CallTree managed by this HistogramController. + + + + + Force recalculation of the scale parameter. + + + + + Add a sample to the histogram for a node. + + The histogram to add this sample to. Must be controlled by this HistogramController. + The sample to add. + + Overriding classes are responsible for extracting the metric, scaling the metric, + determining the appropriate bucket or buckets, and adding the metric to the histogram using . + + + + + Gets human-readable information about a range of histogram characters. + + The start character index (inclusive). + The end character index (exclusive). + The histogram. + A string containing information about the contents of that character range. + + + + Convert a histogram into its display string. + + The histogram to convert to a string. + A string suitable for GUI display. + + + + A utility function that turns an array of floats into a ASCII character graph. + + + + + A utility function that turns an array of floats into a ASCII character graph. + + + + + Initialize a new HistogramController. + + The CallTree that this HistogramController controls. + + + + Calculate the scale factor for this histogram. + + The scale factor for this histogram. + + + + Calculates an average scale factor for a histogram. + + The root histogram to calculate against. + A scale factor that will normalize the maximum value to 200%. + + + + The scale parameter. 0.0 if uncalculated. + + + + + An enum representing a displayed histogram bucket (one character in a histogram string). + + + + + A HistogramCharacterIndex can be used to represent error conditions + + + + + A that groups histograms by scenarios. + + + + + Initialize a new ScenarioHistogramController. + + The CallTree to manage. + An ordered array of scenario IDs to display. + The total number of possible scenarios that can be supplied by the underlying StackSource. + This number might be larger than the highest number in . + The names of the scenarios (for UI use). + + + + Get a list of scenarios contained in a given bucket. + + The bucket to look up. + The scenarios contained in that bucket. + + + + Get a list of scenarios contained in a given bucket range. + + The start of the bucket range (inclusive). + The end of the bucket range (exclusive). + The scenarios contained in that range of buckets. + + + + Add a sample to a histogram controlled by this HistogramController. + + The histogram to add the sample to. + The sample to add. + + + + Get the human-readable name for a scenario. + + The ID of the scenario to look up. + The human-readable name for that scenario. + + + + Get the human-readable names for all scenarios contained in a range of histogram characters. + + The (inclusive) start index of the range. + The (exclusive) end index of the range. + The histogram. + A comma-separated list of scenario names contained in that range. + + + + Convert a histogram into a string suitable for UI display. + + The histogram to convert. + A string representing the histogram that is suitable for UI display. + + + + Calculate the scale factor for all histograms controlled by this ScenarioHistogramController. + + + In the current implementation, returns a scale that normalizes 100% to half of the maximum value at the root. + + + + + An array mapping each scenario to a bucket. + + + + + An array mapping each bucket to a list of scenarios. + + + + + An array mapping each scenario to its name. + + + + + A HistogramController holds all the information to understand the buckets of a histogram + (basically everything except the array of metrics itself. For time this is the + start and end time + + + + + Create a new TimeHistogramController. + + The CallTree to control with this controller. + The start time of the histogram. + The end time of the histogram. + + + + The start time of the histogram. + + + + + The end time of the histogram. + + + + + Gets the start time for the histogram bucket represented by a character. + + The index of the character to look up. + The start time of the bucket represented by the character. + + + + The duration of time represented by each bucket. + + + + + Implements HistogramController interface + + + + + Implements HistogramController interface + + + + + Implements HistogramController interface + + + + + Implements HistogramController interface + + + + + This structure provides a clean API for a lightweight recursion stack guard to prevent StackOverflow exceptions + We do ultimately do a stack-overflow to prevent infinite recursion, but it is now under our + control and much larger than you may get on any one thread stack. + + + + + For recursive methods that need to process deep stacks, this constant defines the limit for recursion within + a single thread. After reaching this limit, methods need to trampoline to a new thread before continuing to + recurse. + + + + + To prevent run-away recursion, fail after this depth (in this case 20*400 = 8K) + + + + + The amount of recursion we have currently done. + + + + + Gets the recursion guard for entering a recursive method. + + + This is equivalent to the default value. + + + + + Gets an updated recursion guard for recursing into a method. + + + + + Gets an updated recursion guard for continuing execution on a new thread. + + + + + Gets a value indicating whether the current operation has exceeded the recursion depth for a single thread, + and needs to continue executing on a new thread. + + + + + exports provided StackSource to a https://www.speedscope.app/ format + schema: https://www.speedscope.app/file-format-schema.json + + + + + we want to identify the thread for every sample to prevent from + overlaping of samples for the concurrent code so we group the samples by Threads + this method also sorts the samples by relative time (ascending) + + + + + this method fixes the metrics of the samples to make sure they don't overlap + it's very common that following samples overlap by a very small number like 0.0000000000156 + we can't allow for that to happen because the SpeedScope can't draw such samples + + + + + all the samples that we have are leafs (last sample in the call stack) + this method expands those samples to full information + it walks the stack up to the begining and adds a sample for every method on the stack + it's required to build full information + + + + + this method aggregates all the singular samples to continuous events + example: samples for Main taken at time 0.1 0.2 0.3 0.4 0.5 + are gonna be translated to Main start at 0.1 stop at 0.5 + + + + + this method checks if both samples do NOT belong to the same profile event + + + + + this method adds a new profile event for provided samples + it also make sure that a profile event does not open and close at the same time (would be ignored by SpeedScope) + + + + + this method orders the profile events in the order required by SpeedScope + it's just the order of drawing the time graph + + + + + writes pre-calculated data to SpeedScope format + + + + + A stack source is a logically a list of StackSourceSamples. Each sample has a metric and stack (hence the name StackSource) + The stacks are represented as indexes that the StackSourceStacks base class can resolve into frame names and stack chains. + The result is very efficient (no string processing) way of processing the conceptual list of stack samples. + + + + + Call 'callback' on every sample in the StackSource. Will be done linearly and only + one callback will be active simultaneously. + + + + + Call 'callback' on every sample in the StackSource. Will be done linearly and only + one callback will be active simultaneously. + + + + + If this is overridden to return true, then during the 'Foeach' callback you can save references + to the samples you are given because they will not be overridden by the stack source. If this is + false you must make a copy of the sample if you with to remember it. + + + + + Also called 'callback' on every sample in the StackSource however there may be more than + one callback running simultaneously. Thus 'callback' must be thread-safe and the order + of the samples should not matter. If desiredParallelism == 0 (the default) then the + implementation will choose a good value of parallelism. + + + + + If this stack source is a source that simply groups another source, get the base source. It will return + itself if there is no base source. + + + + + If this source supports fetching the samples by index, this is how you get it. Like ForEach the sample that + is returned is not allowed to be modified. Also the returned sample will become invalid the next time GetSampleIndex + is called (we reuse the StackSourceSample on each call) + + + + + Returns the limit on stack samples indexes (all index are strictly less than this). Returns 0 if unknown. + + + + + Returns a time which is greater than or equal the timestamp of any sample in the StackSource. Returns 0 if unknown. + + + + + In addition to Time and Metric a sample can have a Scneario number associated with it. ScenarioCount + returns the number of such scnearios. Returning 0 implies no scenario support. + + + + + StackSources can optionally support a sampling rate. If the source supports it it will return + non-null for the current sampling rate (1 if it is doing nothing). Sampling is a way of speeding + things up. If you sample at a rate of 10, it means that only one out of every 10 samples is actually + produced by 'ForEach'. Note that it is expected that when the sampling rate is set the + source will correspondingly adjust the CountMultiplier, so that the total will look like no sampling + is occuring + + + + + If each 'callstack' is really a node in a graph (like MemoryGraphStackSource) + Then return true. If this returns true 'GetRefs' works. + + + + + Only used if IsGraphSource==true. If 'direction' is 'From' Calls 'callback' for node that is referred to FROM nodeIndex. + If 'direction' is 'To' then it calls 'callback' for every node that refers TO nodeIndex. This API returns references + that are not necessarily a tree (they can for DAGs or have cycles). + + + + + Dump the stack source to a file as XML. Used for debugging. + + + + + Dump the stack source to a TextWriter as XML. Used for debugging. + + + + + RefDirection represents the direction of the references in a heap graph. + + + + + Indicates that you are interested in referneces FROM the node of interest + + + + + Indicates that you are interested in referneces TO the node of interest + + + + + Samples have stacks (lists of frames, each frame contains a name) associated with them. This interface allows you to get + at this information. We don't use normal objects to represent these but rather give each stack (and frame) a unique + (dense) index. This has a number of advantages over using objects to represent the stack. + + * Indexes are very serialization friendly, and this data will be presisted. Thus indexes are the natural form for data on disk. + * It allows the data to be read from the serialized format (disk) lazily in a very straightfoward fashion, keeping only the + hottest elements in memory. + * Users of this API can associate additional data with the call stacks or frames trivially and efficiently simply by + having an array indexed by the stack or frame index. + + So effectively a StackSourceStacks is simply a set of 'Get' methods that allow you to look up information given a Stack or + frame index. + + + + + Given a call stack, return the call stack of the caller. This function can return StackSourceCallStackIndex.Discard + which means that this sample should be discarded. + + + + + For efficiency, m_frames are assumed have a integer ID instead of a string name that + is unique to the frame. Note that it is expected that GetFrameIndex(x) == GetFrameId(y) + then GetFrameName(x) == GetFrameName(y). The converse does NOT have to be true (you + can reused the same name for distinct m_frames, however this can be confusing to your + users, so be careful. + + + + + FilterStackSources can combine more than one frame into a given frame. It is useful to know + how many times this happened. Returning 0 means no combining happened. This metric does + not include grouping, but only folding. + + + + + Get the frame name from the FrameIndex. If 'verboseName' is true then full module path is included. + + + + + all StackSourceCallStackIndex are guaranteed to be less than this. Allocate an array of this size to associate side information + + + + + all StackSourceFrameIndex are guaranteed to be less than this. Allocate an array of this size to associate side information + + + + + True if it only has managed code stacks. Otherwise false. + + + + + Computes the depth (number of callers), associated with callStackIndex. This routine is O(n) and mostly useful for debugging. + + + + + Returns an XML string representation of a 'sample'. For debugging. + + + + + Returns an XML string representation of a 'callStackIndex'. For debugging. + + + + + StackSourceSample represents a single sample that has a stack. It has a number of predefined data items associate with it + including a stack, a metric and a time as well as other optional fields. Note that all its properties are read-write. + It is basically a named tuple. + + StackSource.ProductSamples push these. + + In general StackSourceSample are NOT immutable but expected to be overwritted frequently. Thus you need to copy + the sample if you want to keep a refernece to it. + + + + + The Stack associated with the sample + + + + + The metric (cost) associated with the sample + + + + + If the source supports fetching samples by some ID, then SampleIndex returns this ID for the sample and + GetSampleByIndex is the API that converts this index into a sample again. + + + + + The time associated with the sample. (can be left 0) + + + + + Normally the count of a sample is 1, however when you take a statistical sample, and you also have + other constraints (like you do when you are going a sample of heap memory), you may need to have the + count adjusted to something else. + + + + + A scenario is simply a integer that represents some group the sample belongs to. + + + + + Returns an XML string representing the sample + + + + + Returns an XML string representing the sample, howevever this one can actually expand the stack because it is given the source + + + + + Create a StackSourceSample which is associated with 'source'. + + + + + Copy a StackSourceSample from 'template' + + + + + + Identifies a particular sample from the sample source, it allows 3rd parties to attach additional + information to the sample by creating an array indexed by sampleIndex. + + + + + Returned when no appropriate Sample exists. + + + + + An opaque handle that are 1-1 with a complete call stack + + + + + + The first real call stack index (after the pseudo-ones before this) + + + + + Returned when no appropriate CallStack exists. (Top of stack) + + + + + Identifies a particular frame within a stack It represents a particular instruction pointer (IP) location + in the code or a group of such locations. + + + + + Pseduo-node representing the root of all stacks + + + + + Pseduo-frame that represents the caller of all broken stacks. + + + + + Unknown what to do (Must be before the 'special ones below') // Non negative represents normal m_frames (e.g. names of methods) + + + + + Profiling overhead (rundown) + + + + + The first real call stack index (after the pseudo-ones before this) + + + + + Should not happen (uninitialized) (also means completely folded away) + + + + + Sample has been filtered out (useful for filtering stack sources) + + + + + A StackSourceModuleIndex uniquely identifies a module to the stack source. + + + + + Start is where 'ordinary' module indexes start. + + + + + Invalid is a module index that is never used and can be used to signal error conditions. + + + + + This stack source takes another and copies out all its events. This allows you to 'replay' the source + efficiently when the original source only does this inefficiently. + + + + + Create a CopyStackSource that has no samples in it. It can never have samples so it is only useful as a placeholder. + + + + + Create a CopyStackSource that you can add samples which use indexes that 'sourceStacks' can decode. All samples + added to the stack source must only refer to this StackSourceStacks + + + + + Add a sample to stack source. it will clone 'sample' so sample can be overwritten after this method returns. + It is an error if 'sample' does not used the StackSourceStacks passed to the CopyStackSource at construction. + + + + + Create a clone of the given stack soruce. + + + + + + + Returns the StackSourceStacks that can interpret indexes for this stack source. + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Like CopyStackSource InternStackSource copies the samples. however unlike CopyStackSource + InternStackSource copies all the information in the stacks too (mapping stack indexes to names) + Thus it never refers to the original source again). It also interns the stacks making for + an efficient representation of the data. This is useful when the original source is expensive + to iterate over. + + + + + Compute the difference between two sources of stacks. + + + + + Compute only the delta of source from the baseline. This variation allows you to specify + the unfiltered names (the sourceStacks and baselineStacks) but otherwise keep the filtering. + + + + + Create a new stack source that can create things out of nothing. + + + + + Create a new InternStackSource + + + + + Returns the Interner, which is the class that holds the name->index mappings that that every + name has a unique index. + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + Implementation of the StackSource interface + + + + + InternFullStackFromSource will take a call stack 'baseCallStackIndex' from the source 'source' and completely copy it into + the intern stack source (interning along the way of course). Logically baseCallStackIndex has NOTHING to do with any of the + call stack indexes in the intern stack source. + + + + + StackSourceInterner is a helper class that knows how to intern module, frame and call stacks. + + + + + Create a new StackSourceInterner. Optionally supply estimates on how many items you need and where the frame, callstack and module indexes start. + + + + + As an optimization, if you are done adding new nodes, then you can call this routine can abandon + some tables only needed during the interning phase. + + + + + The CallStackStartIndex value passed to the constructor + + + + + The FrameStartIndex value passed to the constructor + + + + + Given a StackSourceCallStackIndex return the StackSourceCallStackIndex of the caller + + + + + Given a StackSourceCallStackIndex return the StackSourceFrameIndex for the Frame associated + with the top call stack + + + + + Get a name from a frame index. If the frame index is a + + + + + Given a StackSourceFrameIndex return the StackSourceModuleIndex associated with the frame + + + + + + + If you intern frames as derived frames, when GetFrameName is called the interner needs to know + how to look up the derived frame from its index. This is the function that is called. + + It is called with the frame index and a boolean which indicates whether the full path of the module + should be specified, and returns the frame string. + + + + + Lookup or create a StackSourceModuleIndex for moduleName + + + + + Lookup or create a StackSourceFrameIndex for frame with the name frameName and the module identified by moduleIndex + + + + + You can also create frames out of other frames using this method. Given an existing frame, and + a suffix 'frameSuffix' + + + + + Lookup or create a StackSourceCallStackIndex for a call stack with the frame identified frameIndex and caller identified by callerIndex + + + + + The current number of unique frames that have been interned so far + + + + + The current number of unique call stacks that have been interned so far + + + + + A specialized hash table for interning. + It loosely follows the implementation of but with + several key allowances for known usage patterns: + 1. We don't store the hashcode on each entry on the assumption that values can be compared + as quickly as recomputing hash codes. The downside to that is that the hash codes must + be recomputed whenever the map is resized, but that is very cheap. + 2. We supply a single method (instead of a TryGetValue + followed by an Add) so that a hashcode computation is saved in the case of a "miss". + 3. We don't support removal. This means we don't need to keep track of a free list and neither + do we need sentinel values. This also allows us to use all 32 bits of the hash-code (where + uses only 31 bits, reserving -1 to indicate a freed + entry. The only sentinel value is in the array to indicate a free + bucket. + 4. We return an index (of the interned item) to the caller which can be used for constant-time + look-up in the table via . + 5. To free up memory, the caller can call . The entries themselves + are stored separately from the indexing parts of the table so that the latter can be dropped + easily. + + + + + Construct the intern map + + The estimated capacity of the map. + + + + Count of interned values. + + + + + Access an element by index. + + The zero-based index of the desired entry. + The entry at the requested index. + For performance, in Release mode we do no range checking on , so it is possible to + access an entry beyond but prior to the maximum capacity of the array. + was less than zero or greater than the capacity. + + + + Intern a value. If the same value has been seen before + then this returns the index of the previously seen entry. If not, a new entry + is added and this returns the index of the newly added entry. + + The candidate value. + The index of the interned entry. + This routine was called after calling . + + + + As an optimization, if you are done calling , then you can call this + to free up some memory. + + After calling this, you can still call . However, if you try to + call you will get a . + + + + Elements representing the structure of the hash table. The structure is + a collection of singly linked lists, one list per 'bucket' where a + bucket number is selected by taking the hash code of an incoming item + and mapping it onto the array (see ). + + + Caution: For a given , and + are UNRELATED to each other. Logically, you can + think of as being part of a value in the + table. (We don't actually do that in order to + support efficiently.) + To find the next element in the linked list, you should NOT simply + look at . Instead, you should first look up the + in the array indexed by + and look at the field of that. + + + + + Index into the array of the head item in the linked list or + -1 to indicate an empty bucket. + + + + + Index into the array of the next item in the linked list or + -1 to indicate that this is the last item. + + + + + TraceEventStackSource is an implementation of a StackSource for ETW information (TraceLog) + It takes a TraceEvents (which is a list of TraceEvents you get get from a TraceLog) and + implements that StackSource protocol for them. (thus any code needing a StackSource + can then work on it. + + The key to the implementation is how StackSourceFrameIndex and StackSourceCallStackIndex + (part of the StackSource protocol) are mapped to the Indexes in TraceLog. Here is + the mapping. + + TraceEventStackSource create the following meaning for the StackSourceCallStackIndex + + * The call stacks ID consists of the following ranges concatenated together. + * a small set of fixed Pseudo stacks (Start marks the end of these) + * CallStackIndex + * ThreadIndex + * ProcessIndex + * BrokenStacks (One per thread) + * Stacks for CPU samples without explicit stacks (we make 1 element stacks out of them) + + TraceEventStackSource create the following meaning for the StackSourceFrameIndex + + The frame ID consists of the following ranges concatenated together. + * a small fixed number of Pseudo frame (Broken, and Unknown) + * MaxCodeAddressIndex - something with a TraceCodeAddress. + * ThreadIndex - ETW stacks don't have a thread or process node, so we add them. + * ProcessIndex + + + + + Creates a new TraceEventStackSource given a list of events 'events' from a TraceLog + + + + + + Returns the TraceLog file that is associated with this stack source. + + + + + Normally addresses without symbolic names are listed as ?, however sometimes it is useful + to see the actual address as a hexadecimal number. Setting this will do that. + + + + + Looks up symbols for all modules that have an inclusive count >= minCount. + stackSource, if given, can be used to be the filter. If null, 'this' is used. + If stackSource is given, it needs to use the same indexes for frames as 'this'. + shouldLoadSymbols, if given, can be used to filter the modules. + + + + + Given a frame index, return the corresponding code address for it. This is useful for looking up line number information. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Returns a list of modules for the stack 'stackIdx'. It also updates the interning table stackModuleLists, so + that the entry cooresponding to stackIdx remembers the answer. This can speed up processing alot since many + stacks have the same prefixes to root. + + + + + A ModuleList is a linked list of modules. It is only used in GetModulesForStack and LookupWarmSymbols + + + + + This maps pseudo-stacks to their index (thus it is the inverse of m_pseudoStack; + + + + + Given a thread and a call stack that does not have a stack, make up a pseudo stack for it consisting of the code address, + the broken node, the thread and process. Will return -1 if it can't allocate another Pseudo-stack. + + + + + Like a TraceEventStackSource a MutableTraceEventStackSource allows you incorporate the stacks associated with + a TraceEvent as a sample in the StackSource. However in addition it allows you to create new frames for these + stacks on the fly as well as add samples that did not exist in the original TraceEvent stream. This gives you + a lot of flexibility to add additional data to the original stream of TraceEvents. + + Like TraceEventStackSource MutableTraceEventStackSource supports the GetFrameCodeAddress() method that allows + you to map from the StackSourceFrameIndex back its TraceLog code address (that lets you get at the source code and + line number for that frame). + + + + + Create a new MutableTraceEventStackSource that can represent stacks comming from any events in the given TraceLog with a stack. + You use the 'AddSample' and 'DoneAddingSamples' to specify exactly which stacks you want in your source. + + + + + After creating a MultableTraceEventStackSource, you add the samples you want using this AddSample API (you can reuse 'sample' + used as an argument to this routine. It makes a copy. The samples do NOT need to be added in time order (the MultableTraceEventStackSource + will sort them). When you done DoneAddingSamples must be called before using the + the MutableTraceEventStackSource as a stack source. + + + + + After calling 'AddSample' to add the samples that should belong to the source, DoneAddingSamples() should be called to + to complete the construction of the stack source. Only then can the reading API associated with the stack source be called. + + + + + The Interner is the class that allows you to make new indexes out of strings and other bits. + + + + + Returns a StackSourceCallStackIndex representing just one entry that represents the process 'process' + + + + + Returns a StackSourceCallStackIndex representing just two entries that represent 'thread' which has a parent of its process. + + + + + Returns a StackSourceCallStackIndex representing the call stack from the TraceLog represented by the CallStackIndex 'callStackIndex'. + If that stack is invalid, use 'thread' to at least return a call stack for the thread. + + + + + Returns a StackSourceCallStackIndex representing the call stack from the TraceLog represented by the CallStackIndex 'callStackIndex'. + Use the TraceEvent 'data' to find the stack if callStackIndex is invalid. + TODO data should be removed (or callstack derived from it) + + + + + A very simple IDictionary-like interface for remembering values in GetCallStack() + + + + + Fetches an value given a key + + + + + Sets a key-value pair + + + + + Find the StackSourceCallStackIndex for the TraceEvent call stack index 'callStackIndex' which has a top of its + stack (above the stack, where the thread and process would normally go) as 'top'. If callStackMap is non-null + it is used as an interning table for CallStackIndex -> StackSourceCallStackIndex. This can speed up the + transformation dramatically. It will still work if it is null. + + + + + + Create a frame name from a TraceLog code address. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + Implementation of StackSource protocol. + + + + + private + + + + + private + + + + + TraceEventSource is an abstract base class that represents the output of a ETW session (e.g. a ETL file + or ETLX file or a real time stream). This base class is NOT responsible for actually processing + the events, but contains methods for properties associated with the session + like its start and end time, filename, and characteristics of the machine it was collected on. + This class has two main subclasses: + * which implements a 'push' (callback) model and is the only mode for ETL files. + ETWTraceEventSource is the most interesting subclass of TraceEventDispatcher. + * see TraceLog which implements both a 'push' (callback) as well as pull (foreach) model but only works on ETLX files. + This is the end. + The normal user pattern is to create a TraceEventSource, create TraceEventParsers attached to the TraceEventSource, and then subscribe + event callbacks using the TraceEventParsers + + + + + For convenience, we provide a property returns a ClrTraceEventParser that knows + how to parse all the Common Language Runtime (CLR .NET) events into callbacks. + + + + + For convenience, we provide a property returns a KernelTraceEventParser that knows + how to parse all the Kernel events into callbacks. + + + + + For convenience, we provide a property returns a DynamicTraceEventParser that knows + how to parse all event providers that dynamically log their schemas into the event streams. + In particular, it knows how to parse any events from a System.Diagnostics.Tracing.EventSources. + + Note that the DynamicTraceEventParser has subsumed the functionality of RegisteredTraceEventParser + so any registered providers are also looked up here. + + + + + For convenience, we provide a property returns a RegisteredTraceEventParser that knows + how to parse all providers that are registered with the operating system. + + Because the DynamicTraceEventParser has will parse all providers that that RegisteredTraceEventParser + will parse, this function is obsolete, you should use Dynamic instead. + + + + + The time when session started logging. + + + + + The time that the session stopped logging. + + + + + The Session End time expressed as milliseconds from the start of the session + + + + + The difference between SessionEndTime and SessionStartTime; + + + + + The size of the trace, if it is known. Will return 0 if it is not known. + + + + + Returns the size of a pointer on the machine where events were collected (4 for 32 bit or 8 for 64 bit) + + + + + The number of events that were dropped (e.g. because the incoming event rate was too fast) + + + + + The number of processors on the machine doing the logging. + + + + + Cpu speed of the machine doing the logging. + + + + + The version of the windows operating system on the machine doing the logging. + + + + + Returns true if this is a real time session. + + + + + Time based threshold for how long data should be retained + by accumulates that are processing this TraceEventSource. + A value of 0, the default, indicates an infinite accumulation. + + + + + Check if a DataLifetime model is enabled + + True - lifetime tracking is enabled + False - lifetime tracking is not enabled + + + + Closes any files and cleans up any resources associated with this TraceEventSource + + + + + TraceEventSource supports attaching arbitrary user data to the source. This property returns a key-value bag of these attached values. + + One convention that has been established is that TraceEventParsers that need additional state to parse their events should + store them in UserData under the key 'parsers\(ParserName)' + + + + + + Dispose pattern + + + + + This is the high frequency tick clock on the processor (what QueryPerformanceCounter uses). + You should not need + + + + + Converts the Query Performance Counter (QPC) ticks to a number of milliseconds from the start of the trace. + + + + + Converts a Relative MSec time to the Query Performance Counter (QPC) ticks + + + + + Converts a DateTime to the Query Performance Counter (QPC) ticks + + + + + Converts the Query Performance Counter (QPC) ticks to a DateTime + + + + + Some events (like HardFault) do not have a thread ID or a process ID, but they MIGHT have a Stack + If they do try to get the ThreadID for the event from that. Return -1 if not successful. + This is intended to be overridden by the TraceLog class that has this additional information. + + + + + TraceEvent an abstract class represents the data from one event in the stream of events in a TraceEventSource. + The TraceEvent class has all the properties of an event that are common to all ETW events, including TimeStamp + ProviderGuid, ProcessID etc. Subclasses of TraceEvent then extend this abstract class to include properties + specific to a particular payload. + + An important architectural point is that TraceEvent classes are aggressively reused by default. The TraceEvent that is + passed to any TraceEventParser callback or in a foreach is ONLY valid for the duration for that callback (or one + iteration of the foreach). If you need save a copy of the event data, you must call the Clone() method to make + a copy. The IObservable interfaces (TraceEventParser.Observe* methods) however implicitly call Clone() so you + do not have to call Clone() when processing with IObservables (but these are slower). + + + + + + The GUID that uniquely identifies the Provider for this event. This can return Guid.Empty for classic (Pre-VISTA) ETW providers. + + + + + The name of the provider associated with the event. It may be of the form Provider(GUID) or UnknownProvider in some cases but is never null. + + + + + A name for the event. This is simply the concatenation of the task and opcode names (separated by a /). If the + event has no opcode, then the event name is just the task name. + + + + + Returns the provider-specific integer value that uniquely identifies event within the scope of + the provider. (Returns 0 for classic (Pre-VISTA) ETW providers). + + + + + Events for a given provider can be given a group identifier (integer) called a Task that indicates the + broad area within the provider that the event pertains to (for example the Kernel provider has + Tasks for Process, Threads, etc). + + + + + The human readable name for the event's task (group of related events) (eg. process, thread, + image, GC, ...). May return a string Task(GUID) or Task(TASK_NUM) if no good symbolic name is + available. It never returns null. + + + + + An opcode is a numeric identifier (integer) that identifies the particular event within the group of events + identified by the event's task. Often events have opcode 'Info' (0), which is the default. This value + is interpreted as having no-opcode (the task is sufficient to identify the event). + + Generally the most useful opcodes are the Start and Stop opcodes which are used to indicate the beginning and the + end of a interval of time. Many tools will match up start and stop opcodes automatically and compute durations. + + + + + + Returns the human-readable string name for the Opcode property. + + + + + The verbosity of the event (Fatal, Error, ..., Info, Verbose) + + + + + The version number for this event. The only compatible change to an event is to add new properties at the end. + When this is done the version numbers is incremented. + + + + + ETW Event providers can specify a 64 bit bitfield called 'keywords' that define provider-specific groups of + events which can be enabled and disabled independently. + Each event is given a keywords mask that identifies which groups the event belongs to. This property returns this mask. + + + + + A Channel is a identifier (integer) that defines an 'audience' for the event (admin, operational, ...). + Channels are only used for Windows Event Log integration. + + + + + The time of the event. You may find TimeStampRelativeMSec more convenient. + + + + + Returns a double representing the number of milliseconds since the beginning of the session. + + + + + The thread ID for the thread that logged the event + This field may return -1 for some events when the thread ID is not known. + + + + + The process ID of the process which logged the event. + This field may return -1 for some events when the process ID is not known. + + + + + Returns a short name for the process. This the image file name (without the path or extension), + or if that is not present, then the string 'Process(XXXX)' + + + + + The processor Number (from 0 to TraceEventSource.NumberOfProcessors) that logged this event. + event. + + + + + Get the size of a pointer associated with process that logged the event (thus it is 4 for a 32 bit process). + + + + + Conceptually every ETW event can be given a ActivityID (GUID) that uniquely identifies the logical + work being carried out (the activity). This property returns this GUID. Can return Guid.Empty + if the thread logging the event has no activity ID associated with it. + + + + + ETW supports the ability to take events with another GUID called the related activity that is either + causes or is caused by the current activity. This property returns that GUID (or Guid.Empty if the + event has not related activity. + + + + + Event Providers can define a 'message' for each event that are meant for human consumption. + FormattedMessage returns this string with the values of the payload filled in at the appropriate places. + It will return null if the event provider did not define a 'message' for this event + + + + + Creates and returns the value of the 'message' for the event with payload values substituted. + Payload values are formatted using the given formatProvider. + + + + + An EventIndex is a integer that is guaranteed to be unique for this event over the entire log. Its + primary purpose is to act as a key that allows side tables to be built up that allow value added + processing to 'attach' additional data to this particular event unambiguously. + This property is only set for ETLX file. For ETL or real time streams it returns 0 + EventIndex is currently a 4 byte quantity. This does limit this property to 4Gig of events + + + + + The TraceEventSource associated with this event. + + + + + Returns true if this event is from a Classic (Pre-VISTA) provider + + + + + Returns the names of all the manifest declared field names for the event. May be empty if the manifest is not available. + + + + + Given an index from 0 to PayloadNames.Length-1, return the value for that payload item as an object (boxed if necessary). + + + + + PayloadString is like PayloadValue(index).ToString(), however it can do a better job in some cases. In particular + if the payload is a enumeration or a bitfield and the manifest defined the enumeration values, then it will print the string name + of the enumeration value instead of the integer value. + + + + + Returns the index in 'PayloadNames for field 'propertyName'. Returns something less than 0 if not found. + + + + + PayloadByName fetches the value of a payload property by the name of the property. + It will return null if propertyName is not found. + This method is not intended to be used in performance critical code. + + + + + PayloadStringByName functions the same as PayloadByName, but uses PayloadString instead of PayloadValue. + It will return null if propertyName is not found. + This method is not intended to be used in performance critical code. + + + + + The size of the event-specific data payload. (see EventData) + Normally this property is not used because some TraceEventParser has built a subclass of + TraceEvent that parses the payload + + + + + Returns an array of bytes representing the event-specific payload associated with the event. + Normally this method is not used because some TraceEventParser has built a subclass of + TraceEvent that parses the payload + + + + + Gets the event data and puts it in 'targetBuffer' at 'targetStartIndex' and returns the resulting buffer. + If 'targetBuffer is null, it will allocate a buffer of the correct size. + Normally this method is not used because some TraceEventParser has built a subclass of + TraceEvent that parses the payload + + + + + The events passed to the callback functions only last as long as the callback, so if you need to + keep the information around after that you need to copy it. This method makes that copy. + This method is more expensive than copy out all the event data from the TraceEvent instance + to a type of your construction. + + + + + Pretty print the event. It uses XML syntax.. + + + + + Pretty print the event using XML syntax, formatting data using the supplied IFormatProvider + + + + + Write an XML representation to the stringBuilder sb and return it. + + + + + Writes an XML representation of the event to a StringBuilder sb, formatting data using the passed format provider. + Returns the StringBuilder. + + + + + Dumps a very verbose description of the event, including a dump of they payload bytes. It is in + XML format. This is very useful in debugging (put it in a watch window) when parsers are not + interpreting payloads properly. + + + + + EventTypeUserData is a field users get to use to attach their own data on a per-event-type basis. + + + + + Returns the raw IntPtr pointer to the data blob associated with the event. This is the way the + subclasses of TraceEvent get at the data to display it in a efficient (but unsafe) manner. + + + + + Create a template with the given event meta-data. Used by TraceParserGen. + + + + + Skip UTF8 string starting at 'offset' bytes into the payload blob. + + Offset just after the string + + + + Skip Unicode string starting at 'offset' bytes into the payload blob. + + Offset just after the string + + + + Skip 'stringCount' Unicode strings starting at 'offset' bytes into the payload blob. + + Offset just after the last string + + + + Skip a Security ID (SID) starting at 'offset' bytes into the payload blob. + + Offset just after the Security ID + + + + Trivial helper that allows you to get the Offset of a field independent of 32 vs 64 bit pointer size. + + The Offset as it would be on a 32 bit system + The number of pointer-sized fields that came before this field. + + + + + Computes the size of 'numPointers' pointers on the machine where the event was collected. + + + + + Given an Offset to a null terminated ASCII string in an event blob, return the string that is + held there. + + + + + Returns the string represented by a fixed length ASCII string starting at 'offset' of length 'charCount' + + + + + Given an Offset to a fixed sized string at 'offset', whose buffer size is 'charCount' + Returns the string value. A null in the string will terminate the string before the + end of the buffer. + + + + + Returns the encoding of a Version 6 IP address that has been serialized at 'offset' in the payload bytes. + + + + + Returns the GUID serialized at 'offset' in the payload bytes. + + + + + Get the DateTime that serialized (as a windows FILETIME) at 'offset' in the payload bytes. + + + + + Given an Offset to a null terminated Unicode string in an payload bytes, return the string that is + held there. + + + + + Give an offset to a byte array of size 'size' in the payload bytes, return a byte[] that contains + those bytes. + + + + + Returns a byte value that was serialized at 'offset' in the payload bytes + + + + + Returns a short value that was serialized at 'offset' in the payload bytes + + + + + Returns an int value that was serialized at 'offset' in the payload bytes + + + + + Returns a long value that was serialized at 'offset' in the payload bytes + + + + + Get something that is machine word sized for the provider that collected the data, but is an + integer (and not an address) + + + + + Gets something that is pointer sized for the provider that collected the data. + + + + + Returns an int float (single) that was serialized at 'offset' in the payload bytes + + + + + Returns an int double precision floating point value that was serialized at 'offset' in the payload bytes + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Write the XML attribute 'attribName' with value 'value' to the string builder + + + + + Prints a standard prefix for a event (includes the time of the event, the process ID and the + thread ID. + + + + + Because we want the ThreadID to be the ID of the CREATED thread, and the stack + associated with the event is the parentThreadID + + + + + Returns (or sets) the delegate associated with this event. + + + + + If this TraceEvent belongs to a parser that needs state, then this callback will set the state. + Parsers with state are reasonably rare, the main examples are KernelTraceEventParser and ClrTraceEventParser. + + + + + Returns the Timestamp for the event using Query Performance Counter (QPC) ticks. + The start time for the QPC tick counter is arbitrary and the units also vary. + + + + + A standard way for events to are that certain addresses are addresses in code and ideally have + symbolic information associated with them. Returns true if successful. + + + + + Was this written with the windows EventWriteString API? (see also EventDataAsString) + + + + + Used for binary searching of event IDs. Abstracts the size (currently a int, could go to long) + + + + + Returns true if the two traceEvents have the same identity. + + + + + Normally TraceEvent does not have unmanaged data, but if you call 'Clone' it will. + + + + + For debugging. dumps an array. If you specify a size of 0 (the default) it dumps the whole array. + + + + + If the event data looks like a unicode string, then return it. This is heuristic. (See also IsEventWriteString) + + + + + + Each TraceEvent items knows where it should Dispatch to. + ETWTraceEventSource.Dispatch calls this function to go to the right placed. By default we + do nothing. Typically a subclass just dispatches to another callback that passes itself to a + type-specific event callback. + + + + + This is a DEBUG-ONLY routine that allows a routine to do consistency checking in a debug build. + + + + + Validate that the events is not trash. + + + + + TraceEvent knows where to dispatch to. To support many subscriptions to the same event we chain + them. + + + + + The array of names for each property in the payload (in order). + + + + + Individual event providers can supply many different types of events. These are distinguished from each + other by a TraceEventID, which is just a 16 bit number. Its meaning is provider-specific. + + + + + Illegal is a EventID that is not used by a normal event. + + + + + Providers can define different audiences or Channels for an event (eg Admin, Developer ...). + It is only used for Windows Event log support. + + + + + The default channel. + + + + + There are certain classes of events (like start and stop) which are common across a broad variety of + event providers for which it is useful to treat uniformly (for example, determining the elapsed time + between a start and stop event). To facilitate this, event can have opcode which defines these + common operations. Below are the standard ones but providers can define additional ones. + + + + + Generic opcode that does not have specific semantics associated with it. + + + + + The entity (process, thread, ...) is starting + + + + + The entity (process, thread, ...) is stoping (ending) + + + + + The entity (process, thread, ...) did not terminate before data collection ended, so indicate + this at data collection termination time. + + + + + The entity (process, thread, ...) did not terminate before data collection ended, so indicate + this at data collection termination time. This is mostly for 'flight recorder' scenarios where + you only have the 'tail' of the data and would like to know about everything that existed. + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Indicates to a provider whether verbose events should be logged. + + + + + Always log the event (It also can mean that the provider decides the verbosity) You probably should not use it.... + + + + + Events that indicate critical conditions + + + + + Events that indicate error conditions + + + + + Events that indicate warning conditions + + + + + Events that indicate information + + + + + Events that verbose information + + + + + ETW defines the concept of a Keyword, which is a 64 bit bitfield. Each bit in the bitfield + represents some provider defined 'area' that is useful for filtering. When processing the events, it + is then possible to filter based on whether various bits in the bitfield are set. There are some + standard keywords, but most are provider specific. + + + + + No event groups (keywords) selected + + + + + All event groups (keywords) selected + + + + + Tasks are groups of related events for a given provider (for example Process, or Thread, Kernel Provider). + They are defined by the provider. + + + + + If you don't explicitly choose a task you get the default + + + + + EventIdex is a unsigned integer that is unique to a particular event. EventIndex is guaranteed to be + unique over the whole log. It is only used by ETLX files. + + Currently the event ID simply the index in the log file of the event. We don't however guarantee ordering. + In the future we may add new events to the log and given them IDs 'at the end' even if the events are not + at the end chronologically. + + + EventIndex is a 32 bit number limits it to 4Gig events in an ETLX file. + + + + + + Invalid is an EventIndex that will not be used by a normal event. + + + + + TraceEventSource has two roles. The first is the obvious one of providing some properties + like 'SessionStartTime' for clients. The other role is provide an interface for TraceEventParsers + to 'hook' to so that events can be decoded. ITraceParserServices is the API service for this + second role. It provides the methods that parsers register templates for subclasses of + the TraceEvent class that know how to parse particular events. + + + + + RegisterEventTemplate is the mechanism a particular event payload description 'template' + (a subclass of TraceEvent) is injected into the event processing stream. Once registered, an + event is 'parsed' simply by setting the 'rawData' field in the event. It is up to the template + then to take this raw data an present it in a useful way to the user (via properties). Note that + parsing is thus 'lazy' in no processing of the raw data is not done at event dispatch time but + only when the properties of an event are accessed. + + Ownership of the template transfers when this call is made. The source will modify this and + assumes it has exclusive use (thus you should clone the template if necessary). + + Another important aspect is that templates are reused by TraceEventSource aggressively. The + expectation is that no memory needs to be allocated during a normal dispatch + + + + + + UnregisterEventTemplate undoes the action of RegisterEventTemplate. Logically you would + pass the template to unregister, but typically you don't have that at unregistration time. + To avoid forcing clients to remember the templates they registered, UnregisterEventTemplate + takes three things that will uniquely identify the template to unregister. These are + the eventID, and provider ID and the Action (callback) for the template. + + + + + It is expected that when a subclass of TraceEventParser is created, it calls this + method on the source. This allows the source to do any Parser-specific initialization. + + + + + Indicates that this callback should be called on any unhandled event. The callback + returns true if the lookup should be retried after calling this (that is there is + the unhandled event was found). + + + + + Looks if any provider has registered an event with task with 'taskGuid'. Will return null if + there is no registered event. + + + + + Looks if any provider has registered with the given GUID OR has registered any task that matches + the GUID. Will return null if there is no registered event. + + + + + TraceEventParser Represents a class that knows how to decode particular set of events (typically + all the events of a single ETW provider). It is expected that subclasses of TraceEventParser + have a constructor that takes a TraceEventSource as an argument that 'attaches' th parser + to the TraceEventSource. TraceEventParsers break into two groups. + + * Those that work on a single provider, and thus the provider name is implicit in th parser. This is the common case. + The AddCallbackForEvent* methods are meant to be used for these TraceEventParsers + + * Those that work on multiple providers. There are only a handful of these (DynamicTraceEventParser, ...). + The AddCallbackForProviderEvent* methods which take 'Provider' parameters are meant to be used for these TraceEventParsers + + + In addition to the AddCallback* methods on TraceEventParser, there are also Observe* extension methods that + provide callbacks using the IObservable style. + + + + + + Get the source this TraceEventParser is attached to. + + + + + Subscribe to all the events this parser can parse. It is shorthand for AddCallback{TraceEvent}(value)/RemoveCallback(value) + + + + + A shortcut that adds 'callback' in the provider associated with this parser (ProvderName) and an event name 'eventName'. 'eventName' + can be null in which case any event that matches 'Action{T}' will call the callback. + 'eventName is of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + The callback alone is used as the subscription id for unregistration, so the callback delegate should be unique (by delegate comparison) + + + + + + Causes 'callback' to be called for any event in the provider associated with this parser (ProviderName) whose type is compatible with T and + whose eventName will pass 'eventNameFilter'. + + + + + Causes 'callback' to be called for any event in the provider associated with this parser (ProviderName) whose type is compatible with T and + whose eventName will pass 'eventNameFilter'. The eventNameFilter parameter can be null, in which case all events that are compatible + with T will be selected. + + eventNames passed to the filer are of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + + + + Causes 'callback' to be called for any event in the provider associated with this parser (ProviderName) whose type is compatible with T and + whose eventName will pass 'eventNameFilter'. The eventNameFilter parameter can be null, in which case all events that are compatible + with T will be selected. + + A 'subscriptionID' can be passed and this value along with the callback can be used + to uniquely identify subscription to remove using the 'RemoveCallback' API. If null is passed, then only the identity of the callback can + be used to identify the subscription to remove. + + eventNames passed to the filer are of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + + + + + A shortcut that adds 'callback' for the event in 'providerName' and an event name 'eventName' + The callback alone is used as the subscription id for unregistration, so the callback delegate should be unique (by delegate comparison) + + eventName is of the of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + + + + + Cause 'callback' to be called for any event that this parser recognizes for which the function 'eventsToObserve' + returns 'AcceptEvent'. The 'eventsToObserve is given both the provider name (first) and the event name and can return + 'AcceptEvent' 'RejectEvent' or 'RejectProvider' (in which case it may not be called again for that provider). + eventsToObserver can be null in which case all events that match the parser recognizes are selected. + + eventNames passed to the filer are of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. + + + Thus this method works for parsers that parse more than one provider (e.g. DynamicTraceEventParser). + + + + + + Cause 'callback' to be called for any event that this parser recognizes for which the function 'eventsToObserve' + returns 'AcceptEvent'. The 'eventsToObserve is given both the provider name (first) and the event name and can return + 'AcceptEvent' 'RejectEvent' or 'RejectProvider' (in which case it may not be called again for that provider). + eventsToObserver can be null in which case all events that match the parser recognizes are selected. + + eventNames passed to the filer are of the form 'TaskName/OpcodeName' if the event has a non-trivial opcode, otherwise it is 'TaskName'. /// + + Thus this method works for parsers that parse more than one provider (e.g. DynamicTraceEventParser). + + A subscriptionID can optionally be passed. This is used (along with the callback identity) to identify this to the 'RemoveCallback' If you + don't need to remove the callback or you will do it in bulk, you don't need this parameter. + + + + + + Remove all subscriptions added with 'AddCallback' (any overload), that is compatible with T, has a callback 'callback' and subscriptionId 'subscriptionId' + where 'subscriptionId' was the value that was optionally passed to 'AddCallback' to provide exactly this disambiguation. + + 'callback' or 'subscriptionId' can be null, in which case it acts as a wild card. Thus RemoveCallback{TraceEvent}(null, null) will remove all callbacks + that were registered through this parser. + + + + + + A static TraceEventParser is a parser where the set of events that can be subscribed to (and their payload fields) are known at + compile time. There are very few dynamic TraceEventParsers (DynamicTraceEventParser, RegisteredTraceEventParser and WPPTraceEventParser) + + + + + All TraceEventParsers invoke this constructor. If 'dontRegister' is true it is not registered with the source. + + + + + Normally a TraceEvent parser knows how to parse only one provider. If this is true + ProviderName returns the name of this provider. If the parser knows how to parse + more than one provider, this property returns null. + + + + + If the parser needs to persist data along with the events we put it in a separate object. + This object and then implement serialization functionality that allows it to be persisted (this is for ETLX support). + + + + + Returns a list of all templates currently existing (new ones can come in, but OnNewEventDefintion must be called + whenever that happens. Note that the returned templates MUST be cloned and do not have their source or parser state + fields set. These must be set as part of subscription (after you know if you care about them or not). + + eventsToObserver is given the provider name and event name and those events that return AcceptEvent will + have the 'callback' function called on that template. eventsToObserver can be null which mean all events. + + The returned template IS READ ONLY! If you need a read-write copy (typical), clone it first. + + + + + If the parser can change over time (it can add new definitions), It needs to support this interface. See EnumerateDynamicTemplates for details. + This function should be called any time a new event is now parsable by the parser. If it is guaranteed that the particular event is + definitely being ADDED (it never existed in the past), then you can set 'mayHaveExistedBefore' to false and save some time. + + It returns false if there are no definitions for that particular Provider (and thus you can skip callback if desired). + + + + + Given a subscription request, and a template that can now be parsed (and its state, which is just TraceEventParser.StateObj) + If subscription states that the template should be registered with the source, then do the registration. + + if 'mayHaveExistedBefore' means that this template definition may have been seen before (DynamicTraceEventParsers do this as + you may get newer versions dynamically registering themselves). In that case this should be set. If you can guaranteed that + a particular template (provider-eventID pair) will only be subscribed at most once you can set this to false. + + + + + Keeps track of a single 'AddCallback' request so it can be removed later. It also handles lazy addition of events. + + + + + Create a subscription request. 'eventsToObserve takes a provider name (first) and a event name and returns a three valued EventFilterResponse + value (accept, reject, reject provider) + + + + + The source that this parser is connected to. + + + + + EventFilterResponse is the set of responses a user-defined filtering routine, might return. This is used in the TraceEventParser.AddCallbackForProviderEvents method. + + + + + Not an interesting event, but other events in the same provider may be + + + + + No event in the provider will be accepted + + + + + An interesting event + + + + + A TraceEventDispatcher is a TraceEventSource that supports a callback model for dispatching events. + + + + + Obtains the correct TraceEventDispatcher for the given trace file name. + + A path to a trace file. + A TraceEventDispatcher for the given trace file. + + + + Subscribers to UnhandledEvent are called if no other hander has processed the event. It is + generally used in DEBUG builds to validate that events are getting to the source at all. + + + + + Subscribers to EveryEvent are called on every event in the trace. Normally you don't want + to subscribe to this but rather use a TraceEvenParser (which knows how to decode the payloads) + and subscribe to particular events through that. For example Using TraceEventSource.Dynamic.All + or TraceEventSource.Dynamic.All is more likely to be what you are looking for. AllEvents is only + an event callback of last resort, that only gives you the 'raw' data (common fields but no + payload). + + This is called AFTER any event-specific handlers. + + + + + + Subscribers to UnhandledEvent are called if no other hander has processed the event. It is + generally used in DEBUG builds to validate that events are getting to the source at all. + + + + + Subscribers to EveryEvent are called on every event in the trace. Normally you don't want + to subscribe to this but rather use a TraceEvenParser and subscribe to particular events + through that. + + This is called AFTER any event-specific handlers. + + + + + + Once a client has subscribed to the events of interest, calling Process actually causes + the callbacks to happen. + + Subclasses implementing this method should call 'OnCompleted' + before returning. + + + false If StopProcessing was called + + + + Calling StopProcessing in a callback when 'Process()' is running will indicate that processing + should be stopped immediately and that the Process() method should return. + + Note that this stop request will not be honored until the next event from the source. Thus + for real time sessions there is an indeterminate delay before the stop will complete. + If you need to force the stop you should instead call Dispose() on the session associated with + the real time session. This will cause the source to be shut down and thus also stop processing + (Process() will return) but is guaranteed to complete in a timely manner. + + + + + Subscribers of Completed will be called after processing is complete (right before TraceEventDispatcher.Process returns. + + + + + Wrap (or filter) the dispatch of every event from the TraceEventDispatcher stream. + Instead of calling the normal code it calls 'hook' with both the event to be dispatched + and the method the would normally do the processing. Thus the routine has + the option to call normal processing, surround it with things like a lock + or skip it entirely. This can be called more than once, in which case the last + hook method gets called first (which may end up calling the second ...) + + For example,here is an example that uses AddDispatchHook to + take a lock is taken whenever dispatch work is being performed. + + AddDispatchHook((anEvent, dispatcher) => { lock (this) { dispatcher(anEvent); } }); + + + + + Called when processing is complete. You can call this more than once if your not sure if it has already been called. + however we do guard against races. + + + + + Number of different events that have callbacks associated with them + + + + + Total number of callbacks that are registered. Even if they are for the same event. + + + + + + This is the routine that is called back when any event arrives. Basically it looks up the GUID + and the opcode associated with the event and finds right subclass of TraceEvent that + knows how to decode the packet, and calls its virtual TraceEvent.Dispatch method. Note + that TraceEvent does NOT have a copy of the data, but rather just a pointer to it. + This data is ONLY valid during the callback. + + + + + Lookup up the event based on its ProviderID (GUID) and EventId (Classic use the TaskId and the + Opcode field for lookup, but use these same fields (see ETWTraceEventSource.RawDispatchClassic) + + + + + Dispose pattern. + + + + + Dispose pattern + + + + + Inserts 'template' into the hash table, using 'providerGuid' and and 'eventID' as the key. + For Vista ETW events 'providerGuid' must match the provider GUID and the 'eventID' the ID filed. + For PreVist ETW events 'providerGuid must match the task GUID the 'eventID' is the Opcode + + + + + A helper for creating a set of related guids (knowing the providerGuid can can deduce the + 'taskNumber' member of this group. All we do is add the taskNumber to GUID as a number. + + + + + TraceEventParsers can use this template to define the event for the trivial case where the event has no user-defined payload + This is only useful to TraceEventParsers. + + + + + Construct a TraceEvent template which has no payload fields with the given metadata and action + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + Dispatches the event to the action associated with the template. + + + + + override + + + + + When the event has just a single string value associated with it, you can use this shared event + template rather than making an event-specific class. + + + + + The value of the one string payload property. + + + + + Construct a TraceEvent template which has one string payload field with the given metadata and action + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + override + + + + + UnhandledTraceEvent is a TraceEvent when is used when no manifest information is available for the event. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + implementation of TraceEvent Interface. + + + + + override + + + + + implementation of TraceEvent Interface. + + + + + There is some work needed to prepare the generic unhandledTraceEvent that we defer + late (since we often don't care about unhandled events) + + TODO this is probably not worht the complexity... + + + + + ObservableExtensions defines methods on TraceEventParser that implement the IObservable protocol for implementing callbacks. + + + + + Returns an IObjservable that observes all events that 'parser' knows about that return a T. If eventName is + non-null, the event's name must match 'eventName', but if eventName is null, any event that returns a T is observed. + + This means that Observe{TraceEvent}(parser) will observe all events that the parser can parse. + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + + Returns an IObjservable that observes all events that 'parser' knows about that return a T and whose event + name matches the 'eventNameFilter' predicate. + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + Observe a particular event from a particular provider. If eventName is null, it will return every event from the provider + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + Given a predicate 'eventToObserve' which takes the name of a provider (which may be of the form Provider(GUID)) (first) and + an event name (which may be of the form EventID(NUM)) and indicates which events to observe, return an IObservable + that observes those events. + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. . + + + + + Returns an observable that observes all events from the event source 'source' + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + Returns an observable that observes all events from the event source 'source' which are not handled by a callback connected to 'source' + + Note that unlike the methods on TraceEventParser, the TraceEvent object returned is already Cloned() and thus can be + referenced for as long as you like. + + + + + A TraceEventObservable is a helper class that implements the IObservable pattern for TraceEventDispatcher + (like ETWTraceEventDispatcher). It is called from the TraceEventParser.Observe*{T} methods. + + + + + + A TraceEventSubscription is helper class that hooks 'callback' and 'completedCallback' to the 'observable' and + unhooks them when 'Dispose' is called. + + + + + TraceEventNativeMethods contains the PINVOKE declarations needed + to get at the Win32 TraceEvent infrastructure. It is effectively + a port of evntrace.h to C# declarations. + + + + + Time zone info. Used as one field of TRACE_EVENT_LOGFILE, below. + Total struct size is 0xac. + + + + + EventTraceHeader structure used by EVENT_TRACE_PROPERTIES + + + + + EVENT_TRACE_PROPERTIES is a structure used by StartTrace, ControlTrace + however it can not be used directly in the definition of these functions + because extra information has to be hung off the end of the structure + before being passed. (LofFileNameOffset, LoggerNameOffset) + + + + + EventTraceHeader and structure used to defined EVENT_TRACE (the main packet) + I have simplified from the original struct definitions. I have + omitted alternate union-fields which we don't use. + + + + + EVENT_TRACE is the structure that represents a single 'packet' + of data repesenting a single event. + + + + + TRACE_LOGFILE_HEADER is a header used to define EVENT_TRACE_LOGFILEW. + Total struct size is 0x110. + + + + + EVENT_TRACE_LOGFILEW Main struct passed to OpenTrace() to be filled in. + It represents the collection of ETW events as a whole. + + + + + EventTraceHeader and structure used to define EVENT_TRACE_LOGFILE (the main packet on Vista and above) + I have simplified from the original struct definitions. I have + omitted alternate union-fields which we don't use. + + + + + Provides context information about the event + + + + + Defines the layout of an event that ETW delivers + + + + + Possible control commands (borrowed from EventSource) + + + + + Standard 'update' command to send additional information to a provider + + + + + Instructs an EventSource-based provider to send its manifest + + + + + A TraceEventSession represents a single ETW Tracing Session. A session is and event sink that + can enable or disable event logging from event providers). TraceEventSessions can log their + events either to a file, or by issuing callbacks when events arrive (a so-called 'real time' + session). + + Session are MACHINE wide and unlike most OS resources the operating system does NOT reclaim + them when the process that created it dies. By default TraceEventSession tries is best to + do this reclamation, but it is possible that for 'orphan' session to accidentally survive + if the process is ended abruptly (e.g. by the debugger or a user explicitly killing it). It is + possible to turn off TraceEventSession automatic reclamation by setting the StopOnDispose + property to false (its default is true). + + + Kernel events have additional restrictions. In particular there is a special API (EnableKernelProvider). + Before Windows 8, there was a restriction that kernel events could only be enabled from a session + with a special name (see KernelTraceEventParser.KernelSessionName) and thus there could only be a single + session that could log kernel events (and that session could not log non-kernel events). These + restrictions were dropped in windows 8. + + + + + + Create a new logging session sending the output to a given file. + + + The name of the session. Since session can exist beyond the lifetime of the process this name is + used to refer to the session from other processes after it is created. By default TraceEventSessions + do their best to close down if the TraceEventSession dies (see StopOnDispose), however if StopOnDispose + is set to false, the session can live on after process death, and you use the name to refer to it later. + + + The output moduleFile (by convention .ETL) to put the event data. If this is null, and CircularMB is set + to something non-zero, then it will do an in-memory circular buffer. You can get this buffer by + using the 'SetFileName()' method which dumps the data in the buffer. + + Additional flags that influence behavior. Note that the 'Create' option is implied for file mode sessions. + + + + Open a logging session. By default (if options is not specified) a new 'real time' session is created if + the session already existed it is closed and reopened (thus orphans are cleaned up on next use). By default + sessions are closed on Dispose, but if the destructor does not run it can produce 'orphan' session that will + live beyond the lifetime of the process. You can use the StopOnDispose property to force sessions to live + beyond the TraceEventSession that created them and use the TraceEventSessionOptions.Attach option to reattach + to these sessions. + + The name of the session to open. Should be unique across the machine. + Construction options. TraceEventSessionOptions.Attach indicates a desire to attach + to an existing session. + + + + Looks for an existing active session named 'sessionName; and returns the TraceEventSession associated with it if it exists. + Returns null if the session does not exist. You can use the GetActiveSessionNames() to get a list of names to pass to this method. + + + + + Enable a NON-KERNEL provider (see also EnableKernelProvider) which has a given provider name. + This API first checks if a published provider exists by that name, otherwise it + assumes it is an EventSouce and determines the provider Guid by hashing the name according to a + well known algorithm. Thus it will never return a failure for a incorrect spelling of the name. + + + The name of the provider. It must either be registered with the operating system (logman query providers returns it) + or it must be an EventSource (see GetEventSourceGuidFromName) + The verbosity to turn on + A bitvector representing the areas to turn on. Only the + low 32 bits are used by classic providers and passed as the 'flags' value. Zero + is a special value which is a provider defined default, which is usually 'everything' + Additional options for the provider (e.g. taking a stack trace), arguments ... + true if the session already existed and needed to be restarted. + + + + Enable a NON-KERNEL provider (see also EnableKernelProvider) which has a given provider Guid. + + + The Guid that represents the event provider enable. + The verbosity to turn on + A bitvector representing the areas to turn on. Only the + low 32 bits are used by classic providers and passed as the 'flags' value. Zero + is a special value which is a provider defined default, which is usually 'everything' + Additional options for the provider (e.g. taking a stack trace), arguments ... + true if the session already existed and needed to be restarted. + + + + Enable a NON-KERNEL provider (see also EnableKernelProvider) which has a given provider name. + This API first checks if a published provider exists by that name, otherwise it + assumes it is an EventSouce and determines the provider Guid by hashing the name according to a + well known algorithm. Thus it will never return a failure for a incorrect spelling of the name. + + + The name of the provider. It must either be registered with the operating system (logman query providers returns it) + or it must be an EventSource (see GetEventSourceGuidFromName) + The verbosity to turn on + A bitvector representing the areas to turn on. Only the + low 32 bits are used by classic providers and passed as the 'flags' value. Zero + is a special value which is a provider defined default, which is usually 'everything' + Additional options for the provider (e.g. taking a stack trace) + This is set of key-value strings that are passed to the provider + for provider-specific interpretation. Can be null if no additional args are needed. + If the special key-value pair 'Command'='SendManifest' is provided, then the 'SendManifest' + command will be sent (which causes EventSources to re-dump their manifest to the ETW log. + true if the session already existed and needed to be restarted. + + + + Enable a NON-KERNEL provider (see also EnableKernelProvider) represented by 'providerGuid'. + + + The Guid that represents the event provider enable. + The verbosity to turn on + A bitvector representing the areas to turn on. Only the + low 32 bits are used by classic providers and passed as the 'flags' value. Zero + is a special value which is a provider defined default, which is usually 'everything' + Additional options for the provider (e.g. taking a stack trace) + This is set of key-value strings that are passed to the provider + for provider-specific interpretation. Can be null if no additional args are needed. + If the special key-value pair 'Command'='SendManifest' is provided, then the 'SendManifest' + command will be sent (which causes EventSources to re-dump their manifest to the ETW log. + true if the session already existed and needed to be restarted. + + + + Enable an ETW provider, passing a raw blob of data to the provider as a Filter specification. + + Note that this routine is only provided to interact with old ETW providers that can interpret EVENT_FILTER_DESCRIPTOR data + but did not conform to the key-value string conventions. This allows this extra information to be passed to these old + providers. Ideally new providers follow the key-value convention and EnableProvider can be used. + + + + + Helper function that is useful when using EnableProvider with key value pairs. + Given a list of key-value pairs, create a dictionary of the keys mapping to the values. + + + + + Enable the kernel provider for the session. Before windows 8 this session must be called 'NT Kernel Session'. + This API is OK to call from one thread while Process() is being run on another + Specifies the particular kernel events of interest + + Specifies which events should have their stack traces captured when an event is logged + Returns true if the session existed before and was restarted (see TraceEventSession) + + + + + Turn on windows heap logging (stack for allocation) for a particular existing process. + + + + + Turn on windows heap logging for a particular EXE file name (just the file name, no directory, but it DOES include the .exe extension) + This API is OK to call from one thread while Process() is being run on another + + + + + + Disables a provider with the given provider ID completely + + + + + Disables a provider with the given name completely + + + + + Once started, event sessions will persist even after the process that created them dies. They will also be + implicitly stopped when the TraceEventSession is closed unless the StopOnDispose property is set to false. + This API is OK to call from one thread while Process() is being run on another + + + + + Close the session and clean up any resources associated with the session. It is OK to call this more than once. + This API is OK to call from one thread while Process() is being run on another. Calling Dispose is on + a real time session is the way you can force a real time session to stop in a timely manner. + + + + + Asks all providers to flush events to the session + This API is OK to call from one thread while Process() is being run on another + + + + + For either session create with a file name this method can be used to redirect the data to a + new file (so the previous one can be uploaded or processed offline), + + It can also be used for a in-memory circular buffer session (FileName == null and CircularMB != 0) + but its semantics is that simply writes the snapshot to the file (and closes it). It does not + actually make the FileName property become non-null because it only flushes the data, it does + not cause persistent redirection of the data stream. (it is like it auto-reverts). + + It is an error to call this on a real time session. (FileName == null and CircularMB == 0) + + The path to the file to write the data to. + + + + If set, whenever a SetFileName is called (causing a new ETL file to be created), force + a capture state for every provider that is currently turned on. This way the file + will be self-contained (will contain all the capture state information needed to decode events) + This setting is true by default. + + + + + Sends the CAPTURE_STATE command to the provider. This instructs the provider to log any events that are needed to + reconstruct important state that was set up before the session started. What is actually done is provider specific. + EventSources will re-dump their manifest on this command. + This API is OK to call from one thread while Process() is being run on another + + This routine only works Win7 and above, since previous versions don't have this concept. The providers also has + to support it. + + + The GUID that identifies the provider to send the CaptureState command to + The Keywords to send as part of the command (can influence what is sent back) + if non-zero, this is passed along to the provider as type of the filter data. + If non-null this is either an int, or a byte array and is passed along as filter data. + + + + When you issue a EnableProvider command, on windows 7 and above it can be done synchronously (that is you know that because + the EnableProvider returned that the provider actually got the command). However synchronous behavior means that + you may wait forever. This is the time EnableProvider waits until it gives up. Setting this + to 0 means asynchronous (fire and forget). The default is 10000 (wait 10 seconds) + Before windows 7 EnableProvider is always asynchronous. + + + + + If set then Stop() will be called automatically when this object is Disposed or Finalized by the GC. + This is true BY DEFAULT, so if you want your session to survive past the end of the process + you must set this to false. + + + + + Cause the log to be a circular buffer. The buffer size (in MegaBytes) is the value of this property. + Setting this to 0 will cause it to revert to non-circular mode. + The setter can only be called BEFORE any provider is enabled. + + + + + Cause the as a set of files with a given maximum size. The file name must end in .ETL and the + output is then a series of files of the form *NNN.ETL (That is it adds a number just before the + .etl suffix). If you make your file name *.user.etl then the output will be *.user1.etl, *.user2.etl ... + And the MergeInPlace command below will merge them all nicely. + + You can have more control over this by using a normal sequential file but use the SetFileName() + method to redirect the data to new files as needed. + + + + + Sets the size of the buffer the operating system should reserve to avoid lost packets. Starts out + as a very generous 64MB for files. If events are lost, this can be increased, but keep in mind that + no value will help if the average incoming rate is faster than the processing rate. + The setter can only be called BEFORE any provider is enabled. + + + + + This is the unit in which data is flushed in Kilobytes. By default it is 64 (KB). + By default a TraceEventSession will flush every second, and this amount of space will be transferred + to the file. Ideally it is smaller than the number data bytes you expect in a second from any + particular processor. It can't be less than 1K per processor on the machine. However if you make + it less than 64 (K) you will limit the size of the event that the process can send + (they will simply be discarded). + + + + + The rate at which CPU samples are collected. By default this is 1 (once a millisecond per CPU). + There is a lower bound on this (typically .125 Msec) + + + + + Indicate that this session should use compress the stacks to save space. + Must be set before any providers are enabled. Currently only works for kernel events. + + + + + The name of the session that can be used by other threads to attach to the session. + + + + + The name of the moduleFile that events are logged to. Null means the session is real time + or is a circular in-memory buffer. See also SetFileName() method. + + + + + If this is a real time session you can fetch the source associated with the session to start receiving events. + Currently does not work on file based sources (we expect you to wait until the file is complete). + + + + + Creating a TraceEventSession does not actually interact with the operating system until a + provider is enabled. At that point the session is considered active (OS state that survives a + process exit has been modified). IsActive returns true if the session is active. + + + + + + Returns the number of events that should have been delivered to this session but were lost + (typically because the incoming rate was too high). This value is up-to-date for real time + sessions. + + + + + Returns true if the session is logging to a circular buffer. This may be in-memory (FileName == null) + or to a file (FileName != null) + + + + + Returns true if the session is Real Time. This means it is not to a file, and not circular. + + + + + Returns true if this is a in-memory circular buffer (it is circular without an output file). + Use SetFileName() to dump the in-memory buffer to a file. + + + + + ETW trace sessions survive process shutdown. Thus you can attach to existing active sessions. + GetActiveSessionNames() returns a list of currently existing session names. These can be passed + to the TraceEventSession constructor to open it. + + A enumeration of strings, each of which is a name of a session + + + + It is sometimes useful to merge the contents of several ETL files into a single + output ETL file. This routine does that. It also will attach additional + information that will allow correct file name and symbolic lookup if the + ETL file is used on a machine other than the one that the data was collected on. + If you wish to transport the file to another machine you need to merge them, even + if you have only one file so that this extra information get incorporated. + + The input ETL files to merge + The output ETL file to produce. + Optional Additional options for the Merge (seeTraceEventMergeOptions) + + + + This variation of the Merge command takes the 'primary' etl file name (X.etl) + and will merge in any files that match .clr*.etl .user*.etl. and .kernel.etl. + + + + + Is the current process Elevated (allowed to turn on a ETW provider). This is useful because + you need to be elevated to enable providers on a TraceEventSession. + + + + + Set the Windows Debug Privilege. Useful because some event providers require this privilege, and + and it must be enabled explicitly (even if the process is elevated). + + + + + The 'properties' field is only the header information. There is 'tail' that is + required. 'ToUnmangedBuffer' fills in this tail properly. + + + + + Returns a sorted dictionary of names and Guids for every provider registered on the system. + + + + + sets up the EVENT_FILTER_DESCRIPTOR descr to represent the Event Ids in 'eventIds'. You are given the buffer + necessary for this (precomputed) for the EVENT_FILTER_EVENT_ID structure. 'enable' is true if this is to enable + (otherwise disable) the events, and descrType indicates the descriptor type (either EVENT_FILTER_TYPE_EVENT_ID or + EVENT_FILTER_TYPE_STACKWALK) + + + + + Computes the number of bytes needed for the EVENT_FILTER_EVENT_ID structure to represent 'eventIds' + return 0 if there is not need for the filter at all. + + + + + Cleans out all provider data associated with this session. + + + + + SetDataForSession sets the filter data for an ETW session by storing it in the registry. + This is basically a work-around for the fact that filter data does not get transmitted to + the provider if the provider is not alive at the time the controller issues the EnableProvider + call. We store in the registry and EventSource looks there for it if it is not present. + + Note that we support up to 'maxSession' etw sessions simultaneously active (having different + filter data). The function return a sessionIndex that indicates which of the 'slots' + was used to store the data. This routine also 'garbage collects' data for sessions that + have died without cleaning up their filter data. + + If 'data' is null, then it indicates that no data should be stored and the registry entry + is removed. + + If 'allSesions' is true it means that you want 'old style' data filtering that affects all ETW sessions + This is present only used for compatibilty + + the session index that will be used for this session. Returns -1 if an entry could not be found + + + + Given a mask of kernel flags, set the array stackTracingIds of size stackTracingIdsMax to match. + It returns the number of entries in stackTracingIds that were filled in. + + + + + Get a EVENT_TRACE_PROPERTIES structure suitable for passing the the ETW out of a 'buffer' which must be PropertiesSize bytes + in size. + + + + + Used in the TraceEventSession.Merge method + + + + + No special options + + + + + Compress the resulting file. + + + + + TraceEventProviderOptions represents all the optional arguments that can be passed to EnableProvider command. + + + + + Create new options object with no options set + + + + + Create new options object with a set of given provider arguments key-value pairs. There must be a even number + of strings provided and each pair forms a key-value pair that is passed to the AddArgument() operator. + + + + + Arguments are a set of key-value strings that are passed uninterpreted to the EventSource. These can be accessed + from the EventSource's command callback. + + + + + As a convenience, the 'Arguments' property can be modified by calling AddArgument that adds another Key-Value pair + to it. If 'Arguments' is not a IDictionary, it is replaced with an IDictionary with the same key-value pairs before + the new pair is added. + + + + + For EventSources, you pass arguments to the EventSource by using key value pairs (this 'Arguments' property). + However other ETW providers may expect arguments using another convention. RawArguments give a way of passing + raw bytes to the provider as arguments. This is only meant for compatibility with old providers. Setting + this property will cause the 'Arguments' property to be ignored. + + + + + Setting StackEnabled to true will cause all events in the provider to collect stacks when event are fired. + + + + + Setting ProcessIDFilter will limit the providers that receive the EnableCommand to those that match on of + the given Process IDs. + + + + + Setting ProcessNameFilter will limit the providers that receive the EnableCommand to those that match on of + the given Process names (a process name is the name of the EXE without the PATH but WITH the extension). + + + + + Setting EventIDs to Enable will enable a particular event of a provider by EventID (in addition to those + enabled by keywords). + + + + + Setting EventIDs to Enable will enable the collection of stacks for a event of a provider by EventID + (Has no effect if StacksEnabled is also set since that enable stacks for all events IDs) + + + + + Setting EventIDsToDisable to Enable will disable the event of a provider by EventID + This happens after keywords have been processed, so disabling overrides enabling. + + + + + Setting EventIDs to Enable will disable the collection of stacks for a event of a provider by EventID + Has no effect unless StacksEnabled is also set (since otherwise stack collection is off). + + + + + Make a deep copy of options and return it. + + + + + + This return true on OS version beyond 8.1 (windows Version 6.3). It means most of the + per-event filtering is supported. + + + + + This is the backing field for the lazily-computed property. + + + + + TraceEventSessionOptions indicates special handling when creating a TraceEventSession. + + + + + Create a new session, stop and recreated it if it already exists. This is the default. + + + + + Attach to an existing session, fail if the session does NOT already exist. + + + + + Normally if you create a session it will stop and restart it if it exists already. Setting + this flat will disable the 'stop and restart' behavior. This is useful if only a single + monitoring process is intended. + + + + + TraceEventProviders returns information about providers on the system. + + + + + Given the friendly name of a provider (e.g. Microsoft-Windows-DotNETRuntimeStress) return the + GUID for the provider. It does this by looking at all the PUBLISHED providers on the system + (that is those registered with wevtutuil). EventSources in particular do not register themselves + in this way (see GetEventSourceGuidFromName). Names are case insensitive. + It also checks to see if the name is an actual GUID and if so returns that. + Returns Guid.Empty on failure. + + + + + EventSources have a convention for converting its name to a GUID. Use this convention to + convert 'name' to a GUID. In this way you can get the provider GUID for a EventSource + however it can't check for misspellings. Names are case insensitive. + + + + + Finds the friendly name for 'providerGuid' Returns the Guid as a string if can't be found. + + + + + Returns true if 'providerGuid' can be an eventSource. If it says true, there is a 1/16 chance it is not. + However if it returns false, it is definitely not following EventSource Guid generation conventions. + + + + + Returns the Guid of every event provider that published its manifest on the machine. This is the + same list that the 'logman query providers' command will generate. It is pretty long (> 1000 entries) + + A event provider publishes a manifest by compiling its manifest into a special binary form and calling + the wevtutil utility. Typically EventSource do NOT publish their manifest but most operating + system provider do publish their manifest. + + + + + + Returns the GUID of all event provider that either has registered itself in a running process (that is + it CAN be enabled) or that a session has enabled (even if no instances of the provider exist in any process). + + This is a relatively small list (less than 1000), unlike GetPublishedProviders. + + + + + + Returns a list of provider GUIDs that are registered in a process with 'processID'. Useful for discovering + what providers are available for enabling for a particular process. + + + + + Returns a description of the keywords a particular provider provides. Only works if the provider has + published its manifest to the operating system. + Throws an exception if providerGuid is not found + + + + + Returns a list of TRACE_ENABLE_INFO structures that tell about each session (what keywords and level they are + set to, for the provider associated with 'providerGuid'. If 'processId != 0, then only providers in that process + are returned. + + + + + A list of these is returned by GetProviderKeywords + + + + + The name of the provider keyword. + + + + + The description for the keyword for the provider + + + + + the value (bitvector) for the keyword. + + + + + and XML representation for the ProviderDataItem (for debugging) + + + + + TraceEventProfileSources is the interface for the Windows processor CPU counter support + (e.g. causing a stack to be taken every N dcache misses, or branch mispredicts etc) + + Note that the interface to these is machine global (That is when you set these you + cause any session with the kernel PMCProfile keyword active to start emitting + PMCCounterProf events for each ProfileSouce that is enabled. + + /// + + + + Returns a dictionary of keyed by name of ProfileSourceInfo structures for all the CPU counters available on the machine. + + + + + Sets a single Profile Source (CPU machine counters) that will be used if PMC (Precise Machine Counters) + are turned on. The profileSourceID is the ID field from the ProfileSourceInfo returned from 'GetInfo()'. + and the profileSourceInterval is the interval between sampples (the number of events before a stack + is recoreded. If you need more that one (the OS allows up to 4 I think), use the variation of this + routine that takes two int[]. Calling this will clear all Profiler sources previously set (it is NOT + additive). + + + + + Sets the Profile Sources (CPU machine counters) that will be used if PMC (Precise Machine Counters) + are turned on. Each CPU counter is given a id (the profileSourceID) and has an interval + (the number of counts you skip for each event you log). You can get the human name for + all the supported CPU counters by calling GetProfileSourceInfo. Then choose the ones you want + and configure them here (the first array indicating the CPU counters to enable, and the second + array indicating the interval. The second array can be shorter then the first, in which case + the existing interval is used (it persists and has a default on boot). + + + + + Returned by GetProfileSourceInfo, describing the CPU counter (ProfileSource) available on the machine. + + + + + Human readable name of the CPU performance counter (eg BranchInstructions, TotalIssues ...) + + + + + The ID that can be passed to SetProfileSources + + + + + This many events are skipped for each sample that is actually recorded + + + + + The smallest Interval can be (typically 4K) + + + + + The largest Interval can be (typically maxInt). + + + + + These are options to EnableProvider + + + + + No options + + + + + Take a stack trace with the event + + + + + The data model for an Event trace log (ETL) file is simply a stream of events. More sophisticated + analysis typically needs a a richer data model then ETL files can provide, and this is the + motivation for the ETLX (Event Trace Log eXtended) file format. In particular any + analysis that needs non-sequential access to the events or manipulates stack traces associated + with events needs the additional support that the ETLX format provides. See the TraceEventProgrammers guide + for more on the capabilities of ETLX. + + The TraceLog class is the programmatic representation of an ETLX file. It represents the ETLX file as a whole. + + ETLX files are typically created from ETL files using the TraceLog.OpenOrCreate method or more explicitly + by the TraceLog.CreateFromEventTraceLogFile. + + + + + + Given the path to an ETW trace log file (ETL) file, create an ETLX file for the data. + If etlxFilePath is null the output name is derived from etlFilePath by changing its file extension to .ETLX. + The name of the ETLX file that was generated. + + + + + Open an ETLX or ETL file as a ETLX file. + + This routine assumes that you follow normal conventions of naming ETL files with the .ETL file extension + and ETLX files with the .ETLX file extension. It further assumes the ETLX file for a given ETL file + should be in a file named the same as the ETL file with the file extension changed. + + etlOrEtlxFilePath can be either the name of the ETL or ETLX file. If the ETLX file does not + exist or if it older than the corresponding ETL file then the ETLX file is regenerated with + the given options. However if an up-to-date ETLX file exists the conversion step is skipped. + + Ultimately the ETLX file is opened and the resulting TraceLog instance is returned. + + + + + + From a TraceEventSession, create a real time TraceLog Event Source. Like a ETWTraceEventSource a TraceLogEventSource + will deliver events in real time. However an TraceLogEventSource has an underlying Tracelog (which you can access with + the .Log Property) which lets you get at aggregated information (Processes, threads, images loaded, and perhaps most + importantly TraceEvent.CallStack() will work. Thus you can get real time stacks from events). + + Note that in order for native stacks to resolve symbolically, you need to have some Kernel events turned on (Image, and Process) + and only windows 8 has a session that allows both kernel and user mode events simultaneously. Thus this is most useful + on Win 8 systems. + + + + + Creates a ETLX file an Lttng Text file 'filePath'. + + + + + Creates a ETLX file an EventPipe 'filePath'. + + + + + Opens an existing Extended Trace Event log file (ETLX) file. See also TraceLog.OpenOrCreate. + + + + + All the events in the ETLX file. The returned TraceEvents instance supports IEnumerable so it can be used + in foreach statements, but it also supports other methods to further filter the evens before enumerating over them. + + Note that the TraceEvent returned from this IEnumerable may only be used for one iteration of the foreach. + (it is reused for the next event). If you need more lifetime than that you must call Clone() (see 'Lifetime + Constraints' in the programmers guide for more). + + + + + All the Processes that logged an event in the ETLX file. The returned TraceProcesses instance supports IEnumerable so it can be used + in foreach statements, but it also supports other methods to select particular a particular process. + + + + + All the Threads that logged an event in the ETLX file. The returned TraceThreads instance supports IEnumerable so it can be used + in foreach statements, but it also supports other methods to select particular thread. + + + + + All the module files (DLLs) that were loaded by some process in the ETLX file. The returned TraceModuleFiles instance supports IEnumerable so it can be used + in foreach statements, but it also supports other methods to select particular module file. + + + + + All the call stacks in the ETLX file. Normally you don't enumerate over these, but use you use other methods on TraceCallStacks + information about code addresses using CallStackIndexes. + + + + + All the code addresses in the ETLX file. Normally you don't enumerate over these, but use you use other methods on TraceCodeAddresses + information about code addresses using CodeAddressIndexes. + + + + + Summary statistics on the events in the ETX file. + + + + + If the event has a call stack associated with it, retrieve it. Returns null if there is not call stack associated with the event. + If you are retrieving many call stacks consider using GetCallStackIndexForEvent, as it is more efficient. + + + + + If the event has a call stack associated with it, retrieve CallStackIndex. Returns CallStackIndex.Invalid if there is not call stack associated with the event. + + + + + Events are given an Index (ID) that are unique across the whole TraceLog. They are not guaranteed + to be sequential, but they are guaranteed to be between 0 and MaxEventIndex. Ids can be used to + allow clients to associate additional information with event (with a side lookup table). See + TraceEvent.EventIndex and EventIndex for more + + + + + Given an eventIndex, get the event. This is relatively expensive because we need to create a + copy of the event that will not be reused by the TraceLog. Ideally you would not use this API + but rather use iterate over event using TraceEvents + + + + + The total number of events in the log. + + + + + The size of the log file in bytes. + + + + + override + + + + + The file path for the ETLX file associated with this TraceLog instance. + + + + + The machine on which the log was collected. Returns empty string if unknown. + + + + + The name of the Operating system. Returns empty string if unknown. + + + + + The build number information for the OS. Returns empty string if unknown. + + + + + The time the machine was booted. Returns DateTime.MinValue if it is unknown. + + + + + This is the number of minutes between the local time where the data was collected and UTC time. + It is negative if your time zone is WEST of Greenwich. This DOES take Daylights savings time into account + but might be a daylight savings time transition happens inside the trace. + May be unknown, in which case it returns null. + + + + + When an ETL file is 'merged', for every DLL in the trace information is added that allows the symbol + information (PDBS) to be identified unambiguously on a symbol server. This property returns true + if the ETLX file was created from an ETL file with this added information. + + + + + The size of the main memory (RAM) on the collection machine. Will return 0 if memory size is unknown + + + + + Are there any event in trace that has a call stack associated with it. + + + + + If Kernel CPU sampling events are turned on, CPU samples are taken at regular intervals (by default every MSec). + This property returns the time interval between samples. + + If the sampling interval was changed over the course of the trace, this property does not reflect that. It + returns the first value it had in the trace. + + + + + + Returns true if the machine running this code is the same as the machine where the trace data was collected. + + If this returns false, the path names references in the trace cannot be inspected (since they are on a different machine). + + + + + + There is a size limit for ETLX files. Thus it is possible that the data from the original ETL file was truncated. + This property returns true if this happened. + + + + + Returns the EvnetIndex (order in the file) of the first event that has a + timestamp smaller than its predecessor. Returns Invalid if there are no time inversions. + + + + + Returns all the TraceEventParsers associated with this log. + + + + + An XML fragment that gives useful summary information about the trace as a whole. + + + + + Create a new real time session called 'sessionName' and connect a TraceLog to it and return that TraceLog. + Functionality of TraceLog that does not depend on either remembering past EVENTS or require future + knowledge (e.g. stacks of kernel events), will 'just work'. + + + + + Removes all but the last 'keepCount' entries in 'growableArray' by sliding them down. + + + + + Forwards an event that was saved (cloned) to the dispatcher associated with the real time source. + + + + + Flushes any event that has waited around long enough + + + + + Given a process's virtual address 'address' and an event which acts as a + context (determines which process and what time in that process), return + a CodeAddressIndex (which represents a particular location in a particular + method in a particular DLL). It is possible that different addresses will + go to the same code address for the same address (in different contexts). + This is because DLLS where loaded in different places in different processes. + + + + + If an event has a field of type 'Address' the address can be converted to a symbolic value (a + TraceCodeAddress) by calling this function. C + + + + + Given an EventIndex for an event, retrieve the call stack associated with it + (that can be given to TraceCallStacks). Many events may not have associated + call stack in which case CallSTackIndex.Invalid is returned. + + + + + Given a eventIndex for a CSWTICH event, return the call stack index for the thread + that LOST the processor (the normal callStack is for the thread that GOT the CPU) + + + + + Given a source of events 'source' generated a ETLX file representing these events from them. This + file can then be opened with the TraceLog constructor. 'options' can be null. + + + + + SetupCallbacks installs all the needed callbacks for TraceLog Processing (stacks, process, thread, summaries etc) + on the TraceEventSource rawEvents. + + + + + Copies the events from the 'rawEvents' dispatcher to the output stream 'IStreamWriter'. It + also creates auxiliary data structures associated with the raw events (eg, processes, threads, + modules, address lookup maps... Basically any information that needs to be determined by + scanning over the events during TraceLog creation should hook in here. + + + + + This is a helper routine that adds the address 'address' in the event 'data' to the map from events + to this list of addresses. + + + + + Special logic to form MemInfoWSTraceData. We take the single event (which has + The working sets for every process in the system, an split them out into N events + each of which has the processID for the event set properly, and only has the + information for that process. The first 3 processes in the list are -1, -2, and -3 + that have special meaning. + + + + + Given just the stack event and the timestamp for the event the stack event is to attach to, find + the IncompleteStack for the event. If the event to attach to cannot be this will return null + but otherwise it will make an IncompleteStack entry if one does not already exist or it. + + As part of allocating an Incomplete stack, it will increment the stack counts for target event. + + + + + Do the processing necessary to attach the user mode stack 'userModeStack' to any of the stacks in listOfIncompleteKernelStacks. + It then clears this list. While doing this processing it will check to see if the target stack 'target' is in that list and + it will return true if it was. + + + + + Do the processing necessary to attach the user mode stack 'userModeStack' to any of the stacks in listOfIncompleteKernelStacks. + It then clears this list. While doing this processing it will check to see if the target stack 'target' is in that list and + it will return true if it was. + + + + + Called when we get a definition event (for either a user mode or kernel mode stack fragment). + + + + + Holds information about stacks associated with an event. This is a transient structure. We only need it + until all the information is collected for a particular event, at which point we can create a + CallStackIndex for the stack and eventsToStacks table. + + + + + Clear clears entires that typically don't get set when we only have 1 frame fragment + We can recycle the entries without setting these in that case. + + + + + Clear all entries that can potentially change every time. + + + + + Log the Kernel Stack fragment. We simply remember all the frames (converted to CodeAddressIndexes). + + + + + Log the kernel stack fragment. Returns true if all the pieces of the stack fragment are collected + (we don't have to log something on the thread). + + + + + + + + + + Determine if 'stackInfo' is complete and if so emit it to the 'eventsToStacks' array. If 'force' is true + then force what information there is out even if it is not complete (there is nothing else coming). + + Returns true if it was able to emit the stack + + + + + returns true if the IncompleteStack is dead (just waiting to be reused). + + + + + We track the stacks for when CSwitches block, this is the CSWITCH event where that blocking happened. + + + + + Put the thread that owns 'data' in to the category 'category. + + + + + Process any extended data (like Win7 style stack traces) associated with 'data' + returns true if the event should be considered a bookkeeping event. + + + + + Dispose pattern + + + + + Advance 'reader' until it point at a event that occurs on or after 'timeQPC'. on page + 'pageIndex'. If 'positions' is non-null, fill in that array. Also return the index in + 'positions' for the entry that was found. + + + + + We need a TraceEventDispatcher in the Enumerators for TraceLog that know how to LOOKUP an event + We don't actually dispatch through it. We do mutate the templates (to point a particular data + record), but once we are done with it we can reuse this TraceEventDispatcher again an again + (it is only concurrent access that is a problem). Thus we have an Allocate and Free pattern + to reuse them in the common case of sequential access. + + + + + + The context switch event gives the stack of the thread GETTING the CPU, but it is also very useful + to have this stack at the point of blocking. cswitchBlockingEventsToStacks gives this stack. + + + + + We need to remember the the EventIndexes of the events that were 'just before' this event so we can + associate eventToStack traces with the event that actually caused them. PastEventInfo does this. + + + + + Returns the previous Event on the 'threadID'. Events with -1 thread IDs are also always returned. + Returns PastEventInfoIndex.Invalid if there are not more events to consider. + + + + + Find the event event on thread threadID to the given QPC timestamp. If there is more than + one event with the same QPC, we use thread and processor number to disambiguate. + + + + + Add a new entry that associates the stack 'stackIndex' with the event with index 'eventIndex' + + + + + Represents a source for a TraceLog file (or real time stream). It is basically a TraceEventDispatcher + (TraceEventSource) but you can also get at the TraceLog for it as well. + + + + + Returns the TraceLog associated with this TraceLogEventSource. + + + + + Returns the event Index of the 'current' event (we post increment it so it is always one less) + + + + + override + + + + + override + + + + + override + + + + + TraceEventStats represents the summary statistics (counts) of all the events in the log. + + + + + The total number of distinct event types (there will be a TraceEventCounts for each distinct event Type) + + + + + An XML representation of the TraceEventStats (for Debugging) + + + + + Given an event 'data' look up the statistics for events that type. + + + + + TraceEventCount holds number of events (Counts) and the number of events with call stacks associated with them (StackCounts) for a particular event type. + It also has properties for looking up the event and provider names, but this information can only be complete if all the TraceEventParsers needed + were associated with the TraceLog instance. + + + + + + Returns a provider name for events in this TraceEventCounts. It may return a string with a GUID or even + UnknownProvider for classic ETW if the event is unknown to the TraceLog. + + + + + Returns a name for events in this TraceEventCounts. If the event is unknown to the Tracelog + it will return EventID(XXX) (for manifest based events) or Task(XXX)/Opcode(XXX) (for classic events) + + + + + Returns the payload names associated with this Event type. Returns null if the payload names are unknown. + + + + + Returns true the provider associated with this TraceEventCouts is a classic (not manifest based) ETW provider. + + + + + Returns the provider GUID of the events in this TraceEventCounts. Returns Guid.Empty if IsClassic + + + + + Returns the event ID of the events in this TraceEventCounts. Returns TraceEventID.Illegal if IsClassic + + + + + Returns the Task GUID of the events in this TraceEventCounts. Returns Guid.Empty if not IsClassic + + + + + Returns the Opcode of the events in the TraceEventCounts. Returns TraceEventOpcode.Info if not IsClassic + + + + + Returns the average size of the event specific payload data (not the whole event) for all events in the TraceEventsCounts. + + + + + Returns the number of events in the TraceEventCounts. + + + + + Returns the number of events in the TraceEventCounts that have stack traces associated with them. + + + + + Returns the full name of the event (ProviderName/EventName) + + + + + An XML representation of the top level statistics of the TraceEventCounts. + + + + + + GetHashCode + + + + + A TraceEvents represents a list of TraceEvent instances. It is IEnumerable<TraceEvent> but + also has additional useful ways of filtering the list. + + Note that the TraceEvent returned from this IEnumerable may only be used for one iteration of the foreach. + (it is reused for the next event). If you need more lifetime than that you must call Clone() (see 'Lifetime + Constraints' in the programmers guide for more). + + + + + Returns a list of events in the TraceEvents that return a payload of type T. Thus + ByEventType < TraceEvent > returns all events. + + + + + Returns a TraceEventDispatcher (a push model object on which you can register + callbacks for particular events) that will push all the vents in the TraceEvents. + + Note that the TraceEvent returned from this callback may only be used for the duration of the callback. + If you need more lifetime than that you must call Clone() (see 'Lifetime Constraints' in the programmers guide for more). + + + + + Returns a new list which is the same as the TraceEvents but the events are + delivered from last to first. This allows you to search backwards in the + event stream. + + + + + Filter the events by time. Both starTime and endTime are inclusive. + + + + + Filter the events by time. StartTimeRelativeMSec and endTimeRelativeMSec are relative to the SessionStartTime and are inclusive. + + + + + Create new list of Events that has all the events in the current TraceEvents + that pass the given predicate. + + + + + Returns the TraceLog associated with the events in the TraceEvents + + + + + Returns a time that is guaranteed to be before the first event in the TraceEvents list. + It is returned as DateTime + + + + + Returns a time that is guaranteed to be before the first event in the TraceEvents list. + It is returned as floating point number of MSec since the start of the TraceLog + + + + + Returns a time that is guaranteed to be after the last event in the TraceEvents list. + It is returned as DateTime + + + + + Returns a time that is guaranteed to be after the last event in the TraceEvents list. + It is returned as floating point number of MSec since the start of the TraceLog + + + + + Each process is given a unique index from 0 to TraceProcesses.Count-1 and unlike + the OS Process ID, is unambiguous (The OS process ID can be reused after a + process dies). ProcessIndex represents this index. By using an enum rather than an int + it allows stronger typing and reduces the potential for errors. + + It is expected that users of this library might keep arrays of size TraceProcesses.Count to store + additional data associated with a process in the trace. + + + + + + Returned when no appropriate Process exists. + + + + + A TraceProcesses instance represents the list of processes in the Event log. + + TraceProcesses are IEnumerable, and will return the processes in order of creation time. + + + + + The log associated with this collection of processes. + + + + + The count of the number of TraceProcess instances in the TraceProcesses list. + + + + + Each process that occurs in the log is given a unique index (which unlike the PID is unique), that + ranges from 0 to Count - 1. Return the TraceProcess for the given index. + + + + + Given an OS process ID and a time, return the last TraceProcess that has the same process ID, + and whose process start time is less than 'timeRelativeMSec'. + + If 'timeRelativeMSec' is during the processes's lifetime this is guaranteed to be the correct process. + for the given process ID since process IDs are unique during the lifetime of the process. + + If timeRelativeMSec == TraceLog.SessionDuration this method will return the last process with + the given process ID, even if it had died during the trace. + + + + + + Returns the last process in the log with the given process ID. Useful when the logging session + was stopped just after the processes completed (a common scenario). + + + + + Find the first process in the trace that has the process name 'processName' and whose process + start time is after the given point in time. + A process's name is the file name of the EXE without the extension. + Processes that began before the trace started have a start time of 0, Thus + specifying 0 for the time will include processes that began before the trace started. + + + + + + Find the last process in the trace that has the process name 'processName' and whose process + start time is after the given point in time. + A process's name is the file name of the EXE without the extension. + Processes that began before the trace started have a start time of 0, Thus + specifying 0 for the time will include processes that began before the trace started. + + + + + + An XML representation of the TraceEventProcesses (for debugging) + + + + + Enumerate all the processes that occurred in the trace log, ordered by creation time. + + + + + Given an OS process ID and a time, return the last TraceProcess that has the same process ID, + and whose offset start time is less than 'timeQPC'. If 'timeQPC' is during the thread's lifetime this + is guaranteed to be the correct process. Using timeQPC = TraceLog.sessionEndTimeQPC will return the + last process with the given PID, even if it had died. + + + + + TraceProcesses represents the entire ETL moduleFile log. At the node level it is organized by threads. + + The TraceProcesses also is where we put various caches that are independent of the process involved. + These include a cache for TraceModuleFile that represent native images that can be loaded into a + process, as well as the process lookup tables and a cache that remembers the last calls to + GetNameForAddress(). + + + + + A TraceProcess represents a process in the trace. + + + + + The OS process ID associated with the process. It is NOT unique across the whole log. Use + ProcessIndex for that. + + + + + The index into the logical array of TraceProcesses for this process. Unlike ProcessID (which + may be reused after the process dies, the process index is unique in the log. + + + + + This is a short name for the process. It is the image file name without the path or suffix. + + + + + The command line that started the process (may be empty string if unknown) + + + + + The path name of the EXE that started the process (may be empty string if unknown) + + + + + The time when the process started. Returns the time the trace started if the process existed when the trace started. + + + + + The time when the process started. Returns the time the trace started if the process existed when the trace started. + Returned as the number of MSec from the beginning of the trace. + + + + + The time when the process ended. Returns the time the trace ended if the process existed when the trace ended. + Returned as a DateTime + + + + + The time when the process ended. Returns the time the trace ended if the process existed when the trace ended. + Returned as the number of MSec from the beginning of the trace. + + + + + The process ID of the parent process + + + + + The process that started this process. Returns null if unknown Unlike ParentID + the chain of Parent's will never form a loop. + + + + + If the process exited, the exit status of the process. Otherwise null. + + + + + The amount of CPU time spent in this process based on the kernel CPU sampling events. + + + + + Returns true if the process is a 64 bit process + + + + + The log file associated with the process. + + + + + A list of all the threads that occurred in this process. + + + + + Returns the list of modules that were loaded by the process. The modules may be managed or + native, and include native modules that were loaded event before the trace started. + + + + + Filters events to only those for a particular process. + + + + + Filters events to only that occurred during the time the process was alive. + + + + + + An XML representation of the TraceEventProcess (for debugging) + + + + + Sets the 'Parent' field for the process (based on the ParentID). + + sentinel is internal to the implementation, external callers should always pass null. + TraceProcesses that have a parent==sentinel considered 'illegal' since it woudl form + a loop in the parent chain, which we definately don't want. + + + + + Create a new TraceProcess. It should only be done by log.CreateTraceProcess because + only TraceLog is responsible for generating a new ProcessIndex which we need. 'processIndex' + is a index that is unique for the whole log file (where as processID can be reused). + + + + + This table allows us to intern codeAddress so we only at most one distinct address per process. + + + + + We also keep track of those code addresses that are NOT yet resolved to at least a File (for JIT compiled + things this would be to a method + + + + + This is all the information needed to remember about at JIT compiled method (used in the jitMethods variable) + + + + + This table has a entry for each JIT compiled method that remembers its range. It is actually only needed + for the real time case, as the non-real time case you resolve code addresses on method unload/rundown and thus + don't need to remember the information. This table is NOT persisted in the ETLX file since is only needed + to convert raw addresses into TraceMethods. + + It is a array of arrays to make insertion efficient. Most of the time JIT methods will be added in + contiguous memory (thus will be in order), however from time to time things will 'jump around' to a new + segment. By having a list of lists, (which are in order in both lists) you can efficiently (log(N)) search + as well as insert. + + + + + Maps a newly scheduled "user" activity ID to the ActivityIndex of the + Activity. This keeps track of currently created/scheduled activities + that have not started yet, and for multi-trigger events, created/scheduled + activities that have not conclusively "died" (e.g. by having their "user" + activity ID reused by another activity). + + + + + Each thread is given a unique index from 0 to TraceThreads.Count-1 and unlike + the OS Thread ID, is unambiguous (The OS thread ID can be reused after a + thread dies). ThreadIndex represents this index. By using an enum rather than an int + it allows stronger typing and reduces the potential for errors. + + It is expected that users of this library might keep arrays of size TraceThreads.Count to store + additional data associated with a process in the trace. + + + + + + Returned when no appropriate Thread exists. + + + + + A TraceThreads represents the list of threads in a process. + + + + + Enumerate all the threads that occurred in the trace log. It does so in order of their thread + offset events in the log. + + + + + The count of the number of TraceThreads in the trace log. + + + + + Each thread that occurs in the log is given a unique index (which unlike the PID is unique), that + ranges from 0 to Count - 1. Return the TraceThread for the given index. + + + + + Given an OS thread ID and a time, return the last TraceThread that has the same thread ID, + and whose start time is less than 'timeRelativeMSec'. If 'timeRelativeMSec' is during the thread's lifetime this + is guaranteed to be the correct thread. + + + + + An XML representation of the TraceThreads (for debugging) + + + + + TraceThreads represents the collection of threads in a process. + + + + + + Get the thread for threadID and timeQPC. Create if necessary. If 'isThreadCreateEvent' is true, + then force the creation of a new thread EVEN if the thread exist since we KNOW it is a new thread + (and somehow we missed the threadEnd event). Process is the process associated with the thread. + It can be null if you really don't know the process ID. We will try to fill it in on another event + where we DO know the process id (ThreadEnd event). + + + + + A TraceThread represents a thread of execution in a process. + + + + + The OS process ID associated with the process. + + + + + The index into the logical array of TraceThreads for this process. Unlike ThreadId (which + may be reused after the thread dies) the T index is unique over the log. + + + + + The process associated with the thread. + + + + + The time when the thread started. Returns the time the trace started if the thread existed when the trace started. + Returned as a DateTime + + + + + The time when the thread started. Returns the time the trace started if the thread existed when the trace started. + Returned as the number of MSec from the beginning of the trace. + + + + + The time when the thread ended. Returns the time the trace ended if the thread existed when the trace ended. + Returned as a DateTime + + + + + The time when the thread ended. Returns the time the trace ended if the thread existed when the trace ended. + Returned as the number of MSec from the beginning of the trace. + + + + + The amount of CPU time spent on this thread based on the kernel CPU sampling events. + + + + + Filters events to only those for a particular thread. + + + + + Filters events to only those that occurred during the time a the thread was alive. + + + + + REturns the activity this thread was working on at the time instant 'relativeMsec' + + + + + Represents the "default" activity for the thread, the activity that no one has set + + + + + ThreadInfo is a string that identifies the thread symbolically. (e.g. .NET Threadpool, .NET GC) It may return null if there is no useful symbolic name. + + + + + VerboseThreadName is a name for the thread including the ThreadInfo and the CPU time used. + + + + + The base of the thread's stack. This is just past highest address in memory that is part of the stack + (we don't really know the lower bound (userStackLimit is this lower bound at the time the thread was created + which is not very useful). + + + + + An XML representation of the TraceThread (for debugging) + + + + + Create a new TraceProcess. It should only be done by log.CreateTraceProcess because + only TraceLog is responsible for generating a new ProcessIndex which we need. 'processIndex' + is a index that is unique for the whole log file (where as processID can be reused). + + + + + This is a list of the activities (snippet of threads) that have run on this + thread. They are ordered by time so you can binary search for your activity based + on timestamp. + + + + + We want to have the stack for when CSwtichs BLOCK as well as when they unblock. + this variable keeps track of the last blocking CSWITCH on this thread so that we can + compute this. It is only used during generation of a TraceLog file. + + + + + TraceLoadedModules represents the collection of modules (loaded DLLs or EXEs) in a + particular process. + + + + + The process in which this Module is loaded. + + + + + Returns the module which was mapped into memory at at 'timeRelativeMSec' and includes the address 'address' + Note that Jit compiled code is placed into memory that is not associated with the module and thus will not + be found by this method. + + + + + + Returns the module representing the unmanaged load of a particular fiele at a given time. + + + + + An XML representation of the TraceLoadedModules (for debugging) + + + + + Returns all modules in the process. Note that managed modules may appear twice + (once for the managed load and once for an unmanaged (LoadLibrary) load. + + + + + This function will find the module associated with 'address' at 'timeQPC' however it will only + find modules that are mapped in memory (module associated with JIT compiled methods will not be found). + + + + + Finds the index and module for an a given managed module ID. If not found, new module + should be inserted at index + 1; + + + + + Finds the index and module for an address that lives within the image. If the module + did not match the new entry should go at index+1. + + + + + A TraceLoadedModule represents a module (DLL or EXE) that was loaded into a process. It represents + the time that this module was mapped into the processes address space. + + + + + The address where the DLL or EXE was loaded. Will return 0 for managed modules without NGEN images. + + + + + The load time is the time the LoadLibrary was done if it was loaded from a file, otherwise is the + time the CLR loaded the module. Expressed as a DateTime + + + + + The load time is the time the LoadLibrary was done if it was loaded from a file, otherwise is the + time the CLR loaded the module. Expressed as as MSec from the beginning of the trace. + + + + + The load time is the time the FreeLibrary was done if it was unmanaged, otherwise is the + time the CLR unloaded the module. Expressed as a DateTime + + + + + The load time is the time the FreeLibrary was done if it was unmanaged, otherwise is the + time the CLR unloaded the module. Expressed as MSec from the beginning of the trace. + + + + + The process that loaded this module + + + + + An ID that uniquely identifies the module in within the process. Works for both the managed and unmanaged case. + + + + + If this managedModule was a file that was mapped into memory (eg LoadLibary), then ModuleFile points at + it. If a managed module does not have a file associated with it, this can be null. + + + + + Shortcut for ModuleFile.FilePath, but returns the empty string if ModuleFile is null + + + + + Shortcut for ModuleFile.Name, but returns the empty string if ModuleFile is null + + + + + Because .NET applications have AppDomains, a module that is loaded once from a process + perspective, might be loaded several times (once for each AppDomain) from a .NET perspective + This property returns the loadedModule record for the first such managed module + load associated with this load. + + + + + + An XML representation of the TraceLoadedModule (used for debugging) + + + + + + See IFastSerializable.ToStream. + + + + + See IFastSerializable.FromStream. + + + + + A TraceManagedModule represents the loading of a .NET module into .NET AppDomain. + It represents the time that that module an be used in the AppDomain. + + + + + The module ID that the .NET Runtime uses to identify the file (module) associated with this managed module + + + + + The Assembly ID that the .NET Runtime uses to identify the assembly associated with this managed module. + + + + + Returns true if the managed module was loaded AppDOmain Neutral (its code can be shared by all appdomains in the process. + + + + + If the managed module is an IL module that has an NGEN image, return it. + + + + + An XML representation of the TraceManagedModule (used for debugging) + + + + + CallStackIndex uniquely identifies a callstack within the log. Valid values are between 0 and + TraceCallStacks.Count-1. Thus, an array can be used to 'attach' data to a call stack. + + + + + Returned when no appropriate CallStack exists. + + + + + Call stacks are so common in most traces, that having a .NET object (a TraceEventCallStack) for + each one is often too expensive. As optimization, TraceLog also assigns a call stack index + to every call stack and this index uniquely identifies the call stack in a very light weight fashion. + + To be useful, however you need to be able to ask questions about a call stack index without creating + a TraceEventCallStack. This is the primary purpose of a TraceCallStacks (accessible from TraceLog.CallStacks). + It has a set of + methods that take a CallStackIndex and return properties of the call stack (like its caller or + its code address). + + + + + + Returns the count of call stack indexes (all Call Stack indexes are strictly less than this). + + + + + Given a call stack index, return the code address index representing the top most frame associated with it + + + + + Given a call stack index, look up the call stack index for caller. Returns CallStackIndex.Invalid at top of stack. + + + + + Given a call stack index, returns the number of callers for the call stack + + + + + Given a call stack index, returns a TraceCallStack for it. + + + + + Returns the TraceCodeAddresses instance that can resolve CodeAddressIndexes in the TraceLog + + + + + Given a call stack index, returns the ThreadIndex which represents the thread for the call stack + + + + + Given a call stack index, returns the TraceThread which represents the thread for the call stack + + + + + An XML representation of the TraceCallStacks (used for debugging) + + + + + IEnumerable Support + + + + + Used to 'undo' the effects of adding a eventToStack that you no longer want. This happens when we find + out that a eventToStack is actually got more callers in it (when a eventToStack is split). + + + + + + Returns an index that represents the 'threads' of the stack. It encodes the thread which owns this stack into this. + We encode this as -ThreadIndex - 2 (since -1 is the Invalid node) + + + + + A TraceCallStack is a structure that represents a call stack as a linked list. Each TraceCallStack + contains two properties, the CodeAddress for the current frame, and the TraceCallStack of the + caller of this frame. The Caller property will return null at the thread start frame. + + + + + Return the CallStackIndex that uniquely identifies this call stack in the TraceLog. + + + + + Returns the TraceCodeAddress for the current method frame in the linked list of frames. + + + + + The TraceCallStack for the caller of of the method represented by this call stack. Returns null at the end of the list. + + + + + The depth (count of callers) of this call stack. + + + + + An XML representation of the TraceCallStack (used for debugging) + + + + + Writes an XML representation of the TraceCallStack to the stringbuilder 'sb' + + + + + CodeAddressIndex uniquely identifies a symbolic codeAddress within the log . + Valid values are between 0 and TraceCodeAddresses.Count. Thus, an array + can be used to 'attach' data to a code address. + + + + + Returned when no appropriate Method exists. + + + + + Code addresses are so common in most traces, that having a .NET object (a TraceCodeAddress) for + each one is often too expensive. As optimization, TraceLog also assigns a code address index + to every code address and this index uniquely identifies the code address in a very light weight fashion. + + To be useful, however you need to be able to ask questions about a code address index without creating + a TraceCodeAddress. This is the primary purpose of a TraceCodeAddresses (accessible from TraceLog.CodeAddresses). + It has a set of + methods that take a CodeAddressIndex and return properties of the code address (like its method, address, and module file) + + + + + + Returns the count of code address indexes (all code address indexes are strictly less than this). + + + + + Given a code address index, return the name associated with it (the method name). It will + have the form MODULE!METHODNAME. If the module name is unknown a ? is used, and if the + method name is unknown a hexadecimal number is used as the method name. + + + + + Given a code address index, returns the virtual address of the code in the process. + + + + + Given a code address index, returns the index for the module file (representing the file's path) + + + + + Given a code address index, returns the index for the method associated with the code address (it may return MethodIndex.Invalid + if no method can be found). + + + + + Given a code address index, returns the module file (the DLL paths) associated with it + + + + + If the code address is associated with managed code, return the IL offset within the method. If the method + is unmanaged -1 is returned. To determine the IL offset the PDB for the NGEN image (for NGENed code) or the + correct .NET events (for JIT compiled code) must be present. If this information is not present -1 is returned. + + + + + Given a code address index, returns a TraceCodeAddress for it. + + + + + Returns the TraceMethods object that can look up information from MethodIndexes + + + + + Returns the TraceModuleFiles that can look up information about ModuleFileIndexes + + + + + Indicates the number of managed method records that were encountered. This is useful to understand if symbolic information 'mostly works'. + + + + + Initially CodeAddresses for unmanaged code will have no useful name. Calling LookupSymbolsForModule + lets you resolve the symbols for a particular file so that the TraceCodeAddresses for that DLL + will have Methods (useful names) associated with them. + + + + + A TraceCodeAddress can contain a method name, but does not contain number information. To + find line number information you must read the PDB again and fetch it. This is what + GetSoruceLine does. + + Given a SymbolReader (which knows how to look up PDBs) and a code address index (which + represent a particular point in execution), find a SourceLocation (which represents a + particular line number in a particular source file associated with the code address. + Returns null if anything goes wrong (and diagnostic information will be written to the + log file associated with the SymbolReader. + + + + + + The number of times a particular code address appears in the log. Unlike TraceCodeAddresses.Count, which tries + to share a code address as much as possible, TotalCodeAddresses counts the same code address in different + call stacks (and even if in the same stack) as distinct. This makes TotalCodeAddresses a better measure of + the 'popularity' of a particular address (which can factor into decisions about whether to call LookupSymbolsForModule) + + The sum of ModuleFile.CodeAddressesInModule for all modules should sum to this number. + + + + + + If set to true, will only use the name of the module and not the PDB GUID to confirm that a PDB is correct + for a given DLL. Setting this value is dangerous because it is easy for the PDB to be for a different + version of the DLL and thus give inaccurate method names. Nevertheless, if a log file has no PDB GUID + information associated with it, unsafe PDB matching is the only way to get at least some symbolic information. + + + + + Returns an XML representation of the TraceCodeAddresses (for debugging) + + + + + We expose ILToNativeMap internally so we can do diagnostics. + + + + + IEnumerable support. + + + + + Called when JIT CLR Rundown events are processed. It will look if there is any + address that falls into the range of the JIT compiled method and if so log the + symbolic information (otherwise we simply ignore it) + + + + + Adds a JScript method + + + + + Allows you to get a callback for each code address that is in the range from start to + start+length within the process 'process'. If 'considerResolved' is true' then the address range + is considered resolved and future calls to this routine will not find the addresses (since they are resolved). + + + + + Gets the symbolic information entry for 'address' which can be any address. If it falls in the + range of a symbol, then that symbolic information is returned. Regardless of whether symbolic + information is found, however, an entry is created for it, so every unique address has an entry + in this table. + + + + + All processes might have kernel addresses in them, this returns the kernel process (process ID == 0) if 'address' is a kernel address. + + + + + Sort from lowest address to highest address. + + + + + Do symbol resolution for all addresses in the log file. + + + + + Look up the SymbolModule (open PDB) for a given moduleFile. Will generate NGEN pdbs as needed. + + + + + Returns true if 'moduleFile' seems to be unchanged from the time the information about it + was generated. Logs messages to 'log' if it fails. + + + + + A CodeAddressInfo is the actual data stored in the ETLX file that represents a + TraceCodeAddress. It knows its Address in the process and it knows the + TraceModuleFile (which knows its base address), so it also knows its relative + address in the TraceModuleFile (which is what is needed to look up the value + in the PDB. + + Note that by the time that the CodeAddressInfo is persisted in the ETLX file + it no longer knows the process it originated from (thus separate processes + with the same address and same DLL file loaded at the same address can share + the same CodeAddressInfo. This is actually reasonably common, since OS tend + to load at their preferred base address. + + We also have to handle the managed case, in which case the CodeAddressInfo may + also know about the TraceMethod or the ILMapIndex (which remembers both the + method and the line numbers for managed code. + + However when the CodeAddressInfo is first created, we don't know the TraceModuleFile + so we also need to remember the Process + + + + + + This is only valid until MethodIndex or ModuleFileIndex is set. + + + + + Only for managed code. + + + + + Only for unmanaged code. TODO, this can be folded into methodOrProcessIlMap index and save a DWORD. + since if the method or IlMap is present then you can get the ModuelFile index from there. + + + + + This is a count of how many times this code address appears in any stack in the trace. + It is a measure of what popular the code address is (whether we should look up its symbols). + + + + + Find the ILToNativeMap for 'methodId' in process associated with 'processIndex' + and then remove it from the table (this is what you want to do when the method is unloaded) + + + + + Conceptually a TraceCodeAddress represents a particular point of execution within a particular + line of code in some source code. As a practical matter, they are represented two ways + depending on whether the code is managed or not. + * For native code (or NGened code), it is represented as a virtual address along with the loaded native + module that includes that address along with its load address. A code address does NOT + know its process because they can be shared among all processes that load a particular module + at a particular location. These code addresses will not have methods associated with them + unless symbols information (PDBS) are loaded for the module using the LookupSymbolsForModule. + + * For JIT compiled managed code, the address in a process is eagerly resolved into a method, module + and an IL offset and that is stored in the TraceCodeAddress. + + Sometimes it is impossible to even determine the module associated with a virtual + address in a process. These are represented as simply the virtual address. + + + Because code addresses are so numerous, consider using CodeAddressIndex instead of TraceCodeAddress + to represent a code address. Methods on TraceLog.CodeAddresses can access all the information + that would be in a TraceCodeAddress from a CodeAddressIndex without the overhead of creating + a TraceCodeAddress object. + + + + + + The CodeAddressIndex that uniquely identifies the same code address as this TraceCodeAddress + + + + + The Virtual address of the code address in the process. (Note that the process is unknown by the code address to allow for sharing) + + + + + The full name (Namespace name.class name.method name) of the method associated with this code address. + Returns the empty string if no method is associated with the code address. + + + + + Returns the TraceMethod associated with this code address or null if there is none. + + + + + If the TraceCodeAddress is associated with managed code, return the IL offset within the method. If the method + is unmanaged -1 is returned. To determine the IL offset the PDB for the NGEN image (for NGENed code) or the + correct .NET events (for JIT compiled code) must be present. If this information is not present -1 is returned. + + + + + A TraceCodeAddress can contain a method name, but does not contain number information. To + find line number information you must read the PDB again and fetch it. This is what + GetSoruceLine does. + + Given a SymbolReader (which knows how to look up PDBs) find a SourceLocation (which represents a + particular line number in a particular source file associated with the current TraceCodeAddress. + Returns null if anything goes wrong (and diagnostic information will be written to the + log file associated with the SymbolReader. + + + + + + Returns the TraceModuleFile representing the DLL path associated with this code address (or null if not known) + + + + + ModuleName is the name of the file without path or extension. + + + + + The full path name of the DLL associated with this code address. Returns empty string if not known. + + + + + The CodeAddresses container that this Code Address lives within + + + + + An XML representation for the CodeAddress (for debugging) + + + + + Writes an XML representation for the CodeAddress to the stringbuilder sb + + + + + MethodIndex uniquely identifies a method within the log. Valid values are between 0 and + TraceMethods.Count-1. Thus, an array can be used to 'attach' data to a method. + + + + + Returned when no appropriate Method exists. + + + + + Methods are so common in most traces, that having a .NET object (a TraceMethod) for + each one is often too expensive. As optimization, TraceLog also assigns a method index + to every method and this index uniquely identifies the method in a very light weight fashion. + + To be useful, however you need to be able to ask questions about a method index without creating + a TraceMethod. This is the primary purpose of a TraceMethods (accessible from TraceLog.CodeAddresses.Methods). + It has a set of + methods that take a MethodIndex and return properties of the method (like its name, and module file) + + + + + + Returns the count of method indexes. All MethodIndexes are strictly less than this. + + + + + Given a method index, if the method is managed return the IL meta data MethodToken (returns 0 for native code) + + + + + Given a method index, return the Method's RVA (offset from the base of the DLL in memory) (returns 0 for managed code) + + + + + Given a method index, return the index for the ModuleFile associated with the Method Index. + + + + + Given a method index, return the Full method name (Namespace.ClassName.MethodName) associated with the Method Index. + + + + + Given a method index, return a TraceMethod that also represents the method. + + + + + Returns an XML representation of the TraceMethods. + + + + + IEnumerable support + + + + + + A TraceMethod represents the symbolic information for a particular method. To maximizes haring a TraceMethod + has very little state, just the module and full method name. + + + + + Each Method in the TraceLog is given an index that uniquely identifies it. This return this index for this TraceMethod + + + + + The full name of the method (Namespace.ClassName.MethodName). + + + + + .Net runtime methods have a token (32 bit number) that uniquely identifies it in the meta data of the managed DLL. + This property returns this token. Returns 0 for unmanaged code or method not found. + + + + + For native code the RVA (relative virtual address, which is the offset from the base of the file in memory) + for the method in the file. Returns 0 for managed code or method not found; + + + + + Returns the index for the DLL ModuleFile (which represents its file path) associated with this method + + + + + Returns the ModuleFile (which represents its file path) associated with this method + + + + + A XML representation of the TraceMethod. (Used for debugging) + + + + + + Writes an XML representation of the TraceMethod to the stringbuilder 'sb' + + + + + + + A ModuleFileIndex represents a particular file path on the disk. It is a number + from 0 to MaxModuleFileIndex, which means that you can create a side array to hold + information about module files. + + You can look up information about the ModuleFile from the ModuleFiles type. + + + + + Returned when no appropriate ModuleFile exists. + + + + + TraceModuleFiles is the list of all the ModuleFiles in the trace. It is an IEnumerable. + + + + + Each file is given an index for quick lookup. Count is the + maximum such index (thus you can create an array that is 1-1 with the + files easily). + + + + + Given a ModuleFileIndex, find the TraceModuleFile which also represents it + + + + + Returns the TraceLog associated with this TraceModuleFiles + + + + + Returns an XML representation of the TraceModuleFiles + + + + + Enumerate all the files that occurred in the trace log. + + + + + We cache information about a native image load in a TraceModuleFile. Retrieve or create a new + cache entry associated with 'nativePath' and 'moduleImageBase'. 'moduleImageBase' can be 0 for managed assemblies + that were not loaded with LoadLibrary. + + + + + For a given file name, get the TraceModuleFile associated with it. + + + + + The TraceModuleFile represents a executable file that can be loaded into memory (either an EXE or a + DLL). It represents the path on disk as well as the location in memory where it loads (or + its ModuleID if it is a managed module), but not the load or unload time or the process in which + it was loaded (this allows them to be shared within the trace). + + + + + The ModuleFileIndex ID that uniquely identifies this module file. + + + + + The moduleFile name associated with the moduleFile. May be the empty string if the moduleFile has no moduleFile + (dynamically generated). For managed code, this is the IL moduleFile name. + + + + + This is the short name of the moduleFile (moduleFile name without extension). + + + + + Returns the address in memory where the dll was loaded. + + + + + Returns the size of the DLL when loaded in memory + + + + + Returns the address just past the memory the module uses. + + + + + The name of the symbol file (PDB file) associated with the DLL + + + + + Returns the GUID that uniquely identifies the symbol file (PDB file) for this DLL + + + + + Returns the age (which is a small integer), that is also needed to look up the symbol file (PDB file) on a symbol server. + + + + + Returns the file version string that is optionally embedded in the DLL's resources. Returns the empty string if not present. + + + + + Returns the product name recorded in the file version information. Returns empty string if not present + + + + + Returns a version string for the product as a whole (could include GIT source code hash). Returns empty string if not present + + + + + This is the checksum value in the PE header. Can be used to validate + that the file on disk is the same as the file from the trace. + + + + + This used to be called TimeDateStamp, but linkers may not use it as a + timestamp anymore because they want deterministic builds. It still is + useful as a unique ID for the image. + + + + + If the Product Version fields has a GIT Commit Hash component, this returns it, Otherwise it is empty. + + + + + Returns the time the DLL was built as a DateTime. Note that this may not + work if the build system uses deterministic builds (in which case timestamps + are not allowed. We may not be able to tell if this is a bad timestamp + but we include it because when it is timestamp it is useful. + + + + + The number of code addresses included in this module. This is useful for determining if + this module is worth having its symbolic information looked up or not. It is not + otherwise a particularly interesting metric. + + This number is defined as the number of appearances this module has in any stack + or any event with a code address (If the modules appears 5 times in a stack that + counts as 5 even though it is just one event's stack). + + + + + + If the module file was a managed native image, this is the IL file associated with it. + + + + + Returns an XML representation of the TraceModuleFile (for debugging) + + + + + A ActivityIndex uniquely identifies an Activity in the log. Valid values are between + 0 and Activities.Count-1. + + + + + valid activity indexes are non-negative integers + + + + + Representation of an Activity. An activity can be thought of as a unit of execution associated with + a task or workitem; it executes on one thread, and has a start and end time. An activity keeps track + of its "creator" or "caller" -- which is the activity that scheduled it. Using the "creator" link a + user can determine the chain of activities that led up to the current one. + + Given an event you can get the Activity for the event using the Activity() extension method. + + + + + Describes the kinds of known Activities (used for descriptive purposes alone) + + + + Invalid + + + + Default activity on a thread (when the thread does not execute any code on + behalf of anyone else) + + + + + An activity that was initiated by a Task.Run + + + + + An activity that's a task, but for which we didn't see a "Scheduled" event + + + + + An activity that allows correlation between the antecedent and continuation + + + + A thread started with Thread.Start + + + Native CLR threadpool workitem + + + Native CLR IO threadpool workitem + + + Managed threadpool workitem + + + Generic managed thread transfer + + + Managed async IO workitem + + + WinRT Dispatched workitem + + + + Used when we make up ones because we know that have to be there but we don't know enough to do more than that. + + + + + An activity that allows correlation between the antecedent and continuation + if have bit 5 set it means you auto-compete + + + + + Same as TaskWait, hwoever it auto-completes + + + + + Managed timer workitem + + + + A trace-wide unique id identifying an activity + + + The activity that initiated or caused the current one + + + + This return an unique string 'name' for the activity. It is a the Index followed by + a - followed by the TPL index (if available). It is a bit nicer since it gives + more information for debugging. + + + + + Computes the creator path back to root. + + + + The thread on which the activity is running + + + True if there may be multiple activities that were initiated by caller (e.g. managed Timers) + + + A descriptive label for the activity + TODO: eliminate and use ToString()? + + + + + A thread activity is the activity associate with an OS thread. It is special because it may + have a region that is disjoint. + + + + Time from beginning of trace (in msec) when activity started executing + + + Time from beginning of trace (in msec) when activity completed execution. Does not include children. + + + The event index of the TraceEvent instance that created/scheduled this activity + + + The call stack index of the TraceEvent instance that scheduled (caused the creation of) the activity + + + Time from beginning of trace (in msec) when activity was scheduled + + + + To use mainly for debugging + + + + + TraceLogOptions control the generation of a TraceLog (ETLX file) from an ETL file. + + + + + Creates a new object containing options for constructing a TraceLog file. + + + + + If non-null, this is a predicate that, given a file path to a dll, answers the question + whether the PDB associated with that DLL be looked up and its symbolic information added + to the TraceLog file as part of conversion. Symbols can be looked up afterward when + the file is later opened, so the default (which is to look up no symbols during + conversion) is typically OK. + + + + + Resolving symbols from a symbol server can take a long time. If + there is a DLL that always fails, it can be quite annoying because + it will always cause delays, By specifying only local symbols it + will only resolve the symbols if it can do so without the delay of network traffic. + Symbols that have been previously cached locally from a symbol + server count as local symbols. + + + + + By default symbols are only resolved if there are stacks associated with the trace. + Setting this option forces resolution even if there are no stacks. + + + + + Writes status to this log. Useful for debugging symbol issues. + + + + + If ConversionLogName is set, it indicates that any messages associated with creating the TraceLog should be written here. + + + + + ETL files typically contain a large number of 'bookkeeping' event for resolving names of files, or methods or to indicate information + about processes that existed when the trace was started (DCStart and DCStop events). By default these events are stripped from + the ETLX file because their information has already been used to do the bookkeeping as part of the conversion + + However sometimes it is useful to keep these events (typically for debugging TraceEvent itself) and setting this + property to true will cause every event in the ETL file to be copied as an event to the ETLX file. + + + + + + Sometimes ETL files are too big , and you just want to look at a fraction of it to speed things up + (or to keep file size under control). The MaxEventCount property allows that. 10M will produce a 3-4GB ETLX file. + 1M is a good value to keep ETLX file size under control. Note that that the conversion still scan the entire + original ETL file too look for bookkeeping events, however MaxEventCount events will be transfered to the ETLX + file as events. + + The default is 10M because ETLX has a restriction of 4GB in size. + + + + + + If an ETL file has too many events for efficient processing the first part of the trace can be skipped by setting this + property. Any event which happens before 'SkipMSec' into the session will be filtered out. This property is + intended to be used along with the MaxEventCount property to carve out a arbitrary chunk of time from an ETL + file as it is converted to an ETLX file. + + + + + If this delegate is non-null, it is called if there are any lost events or if the file was truncated. + It is passed a bool whether the ETLX file was truncated, as well as the number of lost events and the + total number of events in the ETLX file. You can throw if you want to abort. + + + + + If you have the manifests for particular providers, you can read them in explicitly by setting this directory. + All files of the form *.manifest.xml will be read into the DynamicTraceEventParser's database before conversion + starts. + + + + + If errors occur during conversion, just assume the traced ended at that point and continue. + + + + + The TraceEvent instances returned during the processing of a TraceLog have additional capabilities that these extension methods can access. + + + + + Finds the TraceProcess associated with a TraceEvent. + Guaranteed to be non-null for non-real-time sessions if the process ID is != -1 + + + + + Finds the TraceThread associated with a TraceEvent. + Guaranteed to be non-null for non-real-time sessions if the process ID is != -1 + + + + + Finds the TraceLog associated with a TraceEvent. + + + + + Finds the TraceCallStack associated with a TraceEvent. Returns null if the event does not have callstack. + + + + + Finds the CallStack index associated with a TraceEvent. Returns Invalid if the event does not have callstack. + + + + + Finds the CallStack index associated the blocking thread for CSwitch event + + + + + Finds the TraceCallStacks associated with a TraceEvent. + + + + + Finds the Activity associated with a TraceEvent + + + + + Finds the ActivityIndex associated with a TraceEvent + + + + + For a PageFaultTraceData event, gets the TraceCodeAddress associated with the ProgramCounter address. + + + + + For a PageFaultTraceData event, gets the CodeAddressIndex associated with the ProgramCounter address. + + + + + For a SampledProfileTraceData event, gets the TraceCodeAddress associated with the InstructionPointer address. + + + + + For a SampledProfileTraceData event, gets the CodeAddressIndex associated with the InstructionPointer address. + + + + + For a SysCallEnterTraceData event, gets the CodeAddressIndex associated with the SysCallAddress address. + + + + + For a PMCCounterProfTraceData event, gets the TraceCodeAddress associated with the InstructionPointer address. + + + + + For a PMCCounterProfTraceData event, gets the CodeAddressIndex associated with the InstructionPointer address. + + + + + For a ISRTraceData event, gets the CodeAddressIndex associated with the Routine address. + + + + + For a DPCTraceData event, gets the CodeAddressIndex associated with the Routine address. + + + + + TraceLoggingEvnetId is a class that manages assigning event IDs (small 64k numbers) + to TraceLogging Style events (which don't have them). Because TraceEvent uses EventIDs + so fundamentally this deficiency is very problematic. + + Arguably this should have been done by the ETW system itself. + + You use it by calling TestForTraceLoggingEventAndFixupIfNeeded on eventRecords. + You also have to explicitly call 'Dispose' when you are done with this class. + + + + + Checks to see if eventRecord has TraceLogging meta data associated with it (EVENT_HEADER_EXT_TYPE_EVENT_SCHEMA_TL) + and if so updates EventHeader.Id to be an event ID unique to that provider/opcode/meta-data blob. + + + + + cleans up native memory allocated by this routine. + + + + + Checks to see if this event has TraceLogging meta data associated with it (EVENT_HEADER_EXT_TYPE_EVENT_SCHEMA_TL) + and if so updates EventHeader.Id to be an event ID unique to that provider/opcode/meta-data blob. + + + + + given that 'eventRecord' is a TraceLogging event (with meta-data 'metaData'), return a eventID that is unique + to that provider/opcode/meta-data blob. + + + + + ProviderMetaDataKey is what we use to look up TraceLogging meta-data. It is + basically just GUID (representing the provider) an opcode (start/stop) and + a blob (representing the TraceLogging meta-data for an event) that knows how to + compare itself so it can be a key to a hash table. + + + + + A HistoryDictionary is designed to look up 'handles' (pointer sized quantities), that might get reused + over time (eg Process IDs, thread IDs). Thus it takes a handle AND A TIME, and finds the value + associated with that handle at that time. + + + + + Adds the association that 'id' has the value 'value' from 'startTime100ns' ONWARD until + it is supersede by the same id being added with a time that is after this. Thus if + I did Add(58, 1000, MyValue1), and add(58, 500, MyValue2) 'TryGetValue(58, 750, out val) will return + MyValue2 (since that value is 'in force' between time 500 and 1000. + + + + + Remove all entries associated with a given key (over all time). + + + + + ZippedETLWriter is a helper class used to compress ETW data (ETL files) + along with symbolic information (e.g. NGEN pdbs), as well as other optional + metadata (e.g. collection log files), into a single archive ready for + transfer to another machine. + + + + + Declares the intent to write a new ZIP archive that will + contain ETW file 'etlFilePath' in it as well as symbolic information (NGEN + pdbs) and possibly other information. log is a Text stream to send detailed + information to. + + This routine assumes by default (unless Merge is set to false) that the ETL + file needs to be merged before it is archived. It will also generate all + the NGEN pdbs needed for the archive. + + + You must call the WriteArchive method before any operations actually happen. + Up to that point is is just remembering instructions for WriteArchive to + follow. + + + + + + This is the name of the output archive. By default is the same as the ETL file name + with a .zip' suffix added (thus it will typically be .etl.zip). + + + + + If set this is where messages about progress and detailed error information goes. + While you dont; have to set this, it is a good idea to do so. + + + + + By default ZippedETL file will zip the ETL file itself and the NGEN pdbs associated with it. + You can add additional files to the archive by calling AddFile. In specififed 'archivePath' + is the path in the archive and defaults to just the file name of the original file path. + + + + + Actually do the work specified by the ZippedETLWriter constructors and other methods. + + + + + This is the symbol reader that is used to generate the NGEN Pdbs as needed + If it is not specififed one is created on the fly. + + + + + By default the ETL file is merged before being added to the archive. If + this is not necessary, you can set this to false. + + + + + Uses a compressed format for the ETL file. Normally off. + + + + + By default the symbol files (PDBs) are included in the ZIP file. If this + is not desired for whatever reason, this property can be set to false. + + + + + Do the work at low priority so as to avoid impacting the system. + + + + + Normally WriteArchive creates a ZIP archive. However it is possible that you only wish + to do the merging and NGEN symbol generation. Setting this property to false + will supress the final ZIP operation. + + + + + Normally if you ZIP you will delete the original ETL file. Setting this to false overrides this. + + + + + Returns the list of path names to the NGEN pdbs for any NGEN image in 'etlFile' that has + any samples in it. + + + + + ZippedETLReader is a helper class that unpacks the ZIP files generated + by the ZippedETLWriter class. It can be smart about placing the + symbolic information in these files on the SymbolReader's path so that + symbolic lookup 'just works'. + + + + + Declares the intent to unzip an .ETL.ZIP file that contain an compressed ETL file + (and NGEN pdbs) from the archive at 'zipFilePath'. If present, messages about + the unpacking go to 'log'. Note that this unpacking only happens when the + UnpackArchive() method is called. + + + + + If set messages about unpacking go here. + + + + + The name of the ETL file to extract (it is an error if there is not exactly 1). + If not present it is derived by changing the extension of the zip archive. + + + + + Where to put the symbols. + + + + + After setting any properties to override default behavior, calling this method + will actually do the unpacking. + + + + + A NativeSymbolModule represents symbol information for a native code module. + NativeSymbolModules can potentially represent Managed modules (which is why it is a subclass of that interface). + + NativeSymbolModule should just be the CONTRACT for Native Symbols (some subclass implements + it for a particular format like Windows PDBs), however today because we have only one file format we + simply implement Windows PDBS here. This can be factored out of this class when we + support other formats (e.g. Dwarf). + + To implmente support for Windows PDBs we use the Debug Interface Access (DIA). See + http://msdn.microsoft.com/library/x93ctkx8.aspx for more. I have only exposed what + I need, and the interface is quite large (and not super pretty). + + + + + Returns the name of the type allocated for a given relative virtual address. + Returns null if the given rva does not match a known heap allocation site. + + + + + Finds a (method) symbolic name for a given relative virtual address of some code. + Returns an empty string if a name could not be found. + + + + + Finds a (method) symbolic name for a given relative virtual address of some code. + Returns an empty string if a name could not be found. + symbolStartRva is set to the start of the symbol start + + + + + Fetches the source location (line number and file), given the relative virtual address (RVA) + of the location in the executable. + + + + + This overload of SourceLocationForRva like the one that takes only an RVA will return a source location + if it can. However this version has additional support for NGEN images. In the case of NGEN images + for .NET V4.6.1 or later), the NGEN images can't convert all the way back to a source location, but they + can convert the RVA back to IL artifacts (ilAssemblyName, methodMetadataToken, iloffset). THese can then + be used to look up the source line using the IL PDB. + + Thus if the return value from this is null, check to see if the ilAssemblyName is non-null, and if not + you can look up the source location using that information. + + + + + Managed code is shipped as IL, so RVA to NATIVE mapping can't be placed in the PDB. Instead + what is placed in the PDB is a mapping from a method's meta-data token and IL offset to source + line number. Thus if you have a metadata token and IL offset, you can again get a source location + + + + + The symbol representing the module as a whole. All global symbols are children of this symbol + + + + + The a unique identifier that is used to relate the DLL and its PDB. + + + + + Along with the PdbGuid, there is a small integer + call the age is also used to find the PDB (it represents the different + post link transformations the DLL has undergone). + + + + + A source file represents a source file from a PDB. This is not just a string + because the file has a build time path, a checksum, and it needs to be 'smart' + to copy down the file if requested. + + TODO We don't need this subclass. We can have SourceFile simply a container + that holds the BuildTimePath, hashType and hashValue. The lookup of the + source can then be put on NativeSymbolModule and called from SourceFile generically. + This makes the different symbol files more simmilar and is a nice simplification. + + + + + If the source file is directly available on the web (that is there is a Url that + can be used to fetch it with HTTP Get), then return that Url. If no such publishing + point exists this property will return null. + + + + + Try to fetch the source file associated with 'buildTimeFilePath' from the symbol server + information from the PDB from 'pdbPath'. Will return a path to the returned file (uses + SourceCacheDirectory associated symbol reader for context where to put the file), + or null if unsuccessful. + + There is a tool called pdbstr associated with srcsrv that basically does this. + pdbstr -r -s:srcsrv -p:PDBPATH + will dump it. + + The basic flow is + + There is a variables section and a files section + + The file section is a list of items separated by *. The first is the path, the rest are up to you + + You form a command by using the SRCSRVTRG variable and substituting variables %var1 where var1 is the first item in the * separated list + There are special operators %fnfile%(XXX), etc that manipulate the string XXX (get file name, translate \ to / ... + + If what is at the end is a valid URL it is looked up. + + + + + Parse the 'srcsrv' stream in a PDB file and return the target for SourceFile + represented by the 'this' pointer. This target is iether a ULR or a local file + path. + + You can dump the srcsrv stream using a tool called pdbstr + pdbstr -r -s:srcsrv -p:PDBPATH + + The target in this stream is called SRCSRVTRG and there is another variable SRCSRVCMD + which represents the command to run to fetch the soruce into SRCSRVTRG + + To form the target, the stream expect you to private a %targ% variable which is a directory + prefix to tell where to put the source file being fetched. If the source file is + available via a URL this variable is not needed. + + ********* This is a typical example of what is in a PDB with source server information. + SRCSRV: ini ------------------------------------------------ + VERSION=3 + INDEXVERSION=2 + VERCTRL=Team Foundation Server + DATETIME=Thu Mar 10 16:15:55 2016 + SRCSRV: variables ------------------------------------------ + TFS_EXTRACT_CMD=tf.exe view /version:%var4% /noprompt "$%var3%" /server:%fnvar%(%var2%) /output:%srcsrvtrg% + TFS_EXTRACT_TARGET=%targ%\%var2%%fnbksl%(%var3%)\%var4%\%fnfile%(%var1%) + VSTFDEVDIV_DEVDIV2=http://vstfdevdiv.redmond.corp.microsoft.com:8080/DevDiv2 + SRCSRVVERCTRL=tfs + SRCSRVERRDESC=access + SRCSRVERRVAR=var2 + SRCSRVTRG=%TFS_extract_target% + SRCSRVCMD=%TFS_extract_cmd% + SRCSRV: source files --------------------------------- ------ + f:\dd\externalapis\legacy\vctools\vc12\inc\cvconst.h*VSTFDEVDIV_DEVDIV2*/DevDiv/Fx/Rel/NetFxRel3Stage/externalapis/legacy/vctools/vc12/inc/cvconst.h*1363200 + f:\dd\externalapis\legacy\vctools\vc12\inc\cvinfo.h*VSTFDEVDIV_DEVDIV2*/DevDiv/Fx/Rel/NetFxRel3Stage/externalapis/legacy/vctools/vc12/inc/cvinfo.h*1363200 + f:\dd\externalapis\legacy\vctools\vc12\inc\vc\ammintrin.h*VSTFDEVDIV_DEVDIV2*/DevDiv/Fx/Rel/NetFxRel3Stage/externalapis/legacy/vctools/vc12/inc/vc/ammintrin.h*1363200 + SRCSRV: end ------------------------------------------------ + + ********* And here is a more modern one where the source code is available via a URL. + SRCSRV: ini ------------------------------------------------ + VERSION=2 + INDEXVERSION=2 + VERCTRL=http + SRCSRV: variables ------------------------------------------ + SRCSRVTRG=https://nuget.smbsrc.net/src/%fnfile%(%var1%)/%var2%/%fnfile%(%var1%) + SRCSRVCMD= + SRCSRVVERCTRL=http + SRCSRV: source files --------------------------------------- + c:\Users\rafalkrynski\Documents\Visual Studio 2012\Projects\DavidSymbolSourceTest\DavidSymbolSourceTest\Demo.cs*SQPvxWBMtvANyCp8Pd3OjoZEUgpKvjDVIY1WbaiFPMw= + SRCSRV: end ------------------------------------------------ + + + returns the target source file path + returns the command to fetch the target source file + Specify the value for %targ% variable. This is the + directory where source files can be fetched to. Typically the returned file is under this directory + If the value is null, %targ% variable be emtpy. This assumes that the resulting file is something + that does not need to be copied to the machine (either a URL or a file that already exists) + + + + Returns the location of the tf.exe executable or + + + + + + Gets the 'srcsvc' data stream from the PDB and return it in as a string. Returns null if it is not present. + + There is a tool called pdbstr associated with srcsrv that basically does this. + pdbstr -r -s:srcsrv -p:PDBPATH + will dump it. + + + + + For Project N modules it returns the list of pre merged IL assemblies and the corresponding mapping. + + + + + For ProjectN modules, gets the merged IL image embedded in the .PDB (only valid for single-file compilation) + + + + + For ProjectN modules, gets the pseudo-assembly embedded in the .PDB, if there is one. + + + + + + For ProjectN modules, gets the binary blob that describes the mapping from RVAs to methods. + + + + + For ProjectN modules, gets the binary blob that describes the mapping from RVAs to types. + + + + + + This static class contains the GetTypeName method for retrieving the type name of + a heap allocation site. + + See https://github.com/KirillOsenkov/Dia2Dump/blob/master/PrintSymbol.cpp for more details + + + + + Represents a single symbol in a PDB file. + + + + + The name for the symbol + + + + + The relative virtual address (offset from the image base when loaded in memory) of the symbol + + + + + The length of the memory that the symbol represents. + + + + + A small integer identifier tat is unique for that symbol in the DLL. + + + + + Decorated names are names that most closely resemble the source code (have overloading). + However when the linker does not directly support all the expressiveness of the + source language names are encoded to represent this. This return this encoded name. + + + + + Returns true if the two symbols live in the same linker section (e.g. text, data ...) + + + + + Returns the children of the symbol. Will return null if there are no children. + + + + + Returns the children of the symbol, with the given tag. Will return null if there are no children. + + + + + Compares the symbol by their relative virtual address (RVA) + + + + + override + + + + + SymPath is a class that knows how to parse _NT_SYMBOL_PATH syntax. + + + + + This allows you to set the _NT_SYMBOL_PATH as a from the windows environment. + + + + + This 'cleans up' a symbol path. In particular + Empty ones are replaced with good defaults (symweb or msdl) + All symbol server specs have local caches (%Temp%\SymbolCache if nothing else is specified). + + Note that this routine does NOT update _NT_SYMBOL_PATH. + + + + + Returns the string representing a symbol path for the 'standard' Microsoft symbol servers. + This returns the public msdl.microsoft.com server if outside Microsoft. + + + + + Create an empty symbol path + + + + + Create a symbol that represents 'path' (the standard semicolon separated list of locations) + + + + + Returns the List of elements in the symbol path. + + + + + Append all the elements in the semicolon separated list, 'path', to the symbol path represented by 'this'. + returns the 'this' pointer + + + + + append a new symbol path element to the beginning of the symbol path represented by 'this'. + returns the 'this' pointer + + + + + insert all the elements in the semicolon separated list, 'path' to the beginning of the symbol path represented by 'this'. + returns the 'this' pointer + + + + + insert a new symbol path element to the beginning of the symbol path represented by 'this'. + returns the 'this' pointer + + + + + If you need to cache files locally, put them here. It is defined + to be the first local path of a SRV* qualification or %TEMP%\SymbolCache + if not is present. + + + + + People can use symbol servers without a local cache. This is bad, add one if necessary. + + + + + Removes all references to remote paths. This insures that network issues don't cause grief. + + + + + Create a new symbol path which first search all machine local locations (either explicit location or symbol server cache locations) + followed by all non-local symbol server. This produces better behavior (If you can find it locally it will be fast) + + + + + Returns the string representation (semicolon separated) for the symbol path. + + + + + + Writes an XML representation of the symbol path to 'writer' + + + + + Checks to see 'computerName' exists (there is a Domain Names Service (DNS) reply to it) + This routine times out relative quickly (after 700 msec) if there is a problem reaching + the computer, and returns false. + + + + + This is the backing field for the lazily-computed property. + + + + + SymPathElement represents the text between the semicolons in a symbol path. It can be a symbol server specification or a simple directory path. + + SymPathElement follows functional conventions. After construction everything is read-only. + + + + + Returns true if this element of the symbol server path a symbol server specification + + + + + Returns the local cache for a symbol server specification. returns null if not specified + + + + + Returns location to look for symbols. This is either a directory specification or an URL (for symbol servers) + This can be null if it is not specified (for cache-only paths). + + + + + IsRemote returns true if it looks like the target is not on the local machine. + + + + + Returns the string repsentation for the symbol server path element (e.g. SRV*c:\temp*\\symbols\symbols) + + + + + Implements object interface + + + + + Implements object interface + + + + + A symbol reader represents something that can FIND pdbs (either on a symbol server or via a symbol path) + Its job is to find a full path a PDB. Then you can use OpenSymbolFile to get a SymbolReaderModule and do more. + + + + + Opens a new SymbolReader. All diagnostics messages about symbol lookup go to 'log'. + + + + + Finds the symbol file for 'exeFilePath' that exists on the current machine (we open + it to find the needed info). Uses the SymbolReader.SymbolPath (including Symbol servers) to + look up the PDB, and will download the PDB to the local cache if necessary. It will also + generate NGEN pdbs into the local symbol cache unless SymbolReaderFlags.NoNGenPDB is set. + + By default for NGEN images it returns the NGEN pdb. However if 'ilPDB' is true it returns + the IL PDB. + + Returns null if the pdb can't be found. + + + + + Find the complete PDB path, given just the simple name (filename + pdb extension) as well as its 'signature', + which uniquely identifies it (on symbol servers). Uses the SymbolReader.SymbolPath (including Symbol servers) to + look up the PDB, and will download the PDB to the local cache if necessary. + + A Guid of Empty, means 'unknown' and will match the first PDB that matches simple name. Thus it is unsafe. + + Returns null if the PDB could not be found + + The name of the PDB file (we only use the file name part) + The GUID that is embedded in the DLL in the debug information that allows matching the DLL and the PDB + Tools like BBT transform a DLL into another DLL (with the same GUID) the 'pdbAge' is a small integers + that indicates how many transformations were done + If you know the path to the DLL for this pdb add it here. That way we can probe next to the DLL + for the PDB file. + This is an optional string that identifies the file version (the 'Version' resource information. + It is used only to provided better error messages for the log. + + + + This API looks up an executable file, by its build-timestamp and size (on a symbol server), 'fileName' should be + a simple name (no directory), and you need the buildTimeStamp and sizeOfImage that are found in the PE header. + + Returns null if it cannot find anything. + + + + + Given the path name to a particular PDB file, load it so that you can resolve symbols in it. + + The name of the PDB file to open. + The SymbolReaderModule that represents the information in the symbol file (PDB) + + + + Like OpenSymbolFile, which opens a PDB, but this version will fail (return null) + if it is not WindowsSymbolModule. It is a shortcut for OpenSymbolFile as NativeSymbolModule + + + + + The symbol path used to look up PDB symbol files. Set when the reader is initialized. + + + + + The paths used to look up source files. defaults to _NT_SOURCE_PATH. + + + + + Where symbols are downloaded if needed. Derived from symbol path. It is the first + directory on the local machine in a SRV*DIR*LOC spec, and %TEMP%\SymbolCache otherwise. + + + + + The place where source is downloaded from a source server. + + + + + Is this symbol reader limited to just the local machine cache or not? + + + + + We call back on this when we find a PDB by probing in 'unsafe' locations (like next to the EXE or in the Built location) + If this function returns true, we assume that it is OK to use the PDB. + + + + + If set OnSymbolFileFound will be called when a PDB file is found. + It is passed the complete local file path, the PDB Guid (may be Guid.Empty) and PDB age. + + + + + A place to log additional messages + + + + + Given a full filename path to an NGEN image, insure that there is an NGEN image for it + in the symbol cache. If one already exists, this method simply returns that. If not + it is generated and placed in the symbol cache. When generating the PDB this routine + attempt to resolve line numbers, which DOES require looking up the PDB for the IL image. + Thus routine may do network accesses (to download IL PDBs). + + Note that FindSymbolFilePathForModule calls this, so normally you don't need to call + this method directly. + + By default it places the PDB in the SymbolCacheDirectory using normal symbol server + cache conventions (PDBNAME\Guid-AGE\Name). You can override this by specifying + the outputDirectory parameter. + + The full path name of the PDB generated for the NGEN image. + + + + + Given a NGEN (or ReadyToRun) imge 'ngenImageFullPath' and the PDB path + that we WANT it to generate generate the PDB. Returns either pdbPath + on success or null on failure. + + TODO can be removed when we properly publish the NGEN pdbs as part of build. + + + + + Called when you are done with the symbol reader. Currently does nothing. + + + + + Returns true if 'filePath' exists and is a PDB that has pdbGuid and pdbAge. + if pdbGuid == Guid.Empty, then the pdbGuid and pdbAge checks are skipped. + + + + + Fetches a file from the server 'serverPath' with pdb signature path 'pdbSigPath' (concatinate them with a / or \ separator + to form a complete URL or path name). It will place the file in 'fullDestPath' It will return true if successful + If 'contentTypeFilter is present, this predicate is called with the URL content type (e.g. application/octet-stream) + and if it returns false, it fails. This insures that things that are the wrong content type (e.g. redirects to + some sort of login) fail cleanly. + + You should probably be using GetFileFromServer + + path to server (e.g. \\symbols\symbols or http://symweb) + pdb path with signature (e.g clr.pdb/1E18F3E494DC464B943EA90F23E256432/clr.pdb) + the full path of where to put the file locally + if present this allows you to filter out urls that dont match this ContentType. + + + + Build the full uri from server path and pdb index path + + + + + This just copies a stream to a file path with logging. + + + + + Looks up 'fileIndexPath' on the server 'urlForServer' (concatenate to form complete URL) copying the file to + 'targetPath' and returning targetPath name there (thus it is always a local file). Unlike GetPhysicalFileFromServer, + GetFileFromServer understands how to deal with compressed files and file.ptr (redirection). + + targetPath or null if the file cannot be found. + + + + Deduce the path to where CLR.dll (and in particular NGEN.exe live for the NGEN image 'ngenImagepath') + Returns null if it can't be found. If the NGEN image is associated with a private runtime return + that value in 'privateVerStr' + + + + + We may be a 32 bit app which has File system redirection turned on + Morph System32 to SysNative in that case to bypass file system redirection + + + + + A SymbolModule represents a file that contains symbolic information + (a Windows PDB or Portable PDB). This is the interface that is independent + of what kind of symbolic file format you use. Becase portable PDBs only + support managed code, this shared interface is by necessity the interface + for managed code only (currently only Windows PDBs support native code). + + + + + This is the EXE associated with the Pdb. It may be null or an invalid path. It is used + to help look up source code (it is implicitly part of the Source Path search) + + + + + The path name to the PDB itself. Might be empty if the symbol information is in memory. + + + + + The Guid that is used to uniquely identify the DLL-PDB pair (used for symbol servers) + + + + + Fetches the SymbolReader assoicated with this SymbolModule. This is where shared + attributes (like SourcePath, SymbolPath etc) are found. + + + + + Given a method and an IL offset, return a source location (line number and file). + Returns null if it could not find it. + + + + + If the symbol file format supports SourceLink JSON this routine should be overriden + to return it. + + + + + Return a URL for 'buildTimeFilePath' using the source link mapping (that 'GetSourceLinkJson' fetched) + Returns null if there is URL using the SourceLink + + + + + + + Parses SourceLink information and returns a list of filepath -> url Prefix tuples. + + + + + A SourceLocation represents a point in the source code. That is the file and the line number. + + + + + The source file for the code + + + + + The line number for the code. + + + + + SymbolReaderFlags indicates preferences on how aggressively symbols should be looked up. + + + + + No options this is the common case, where you want to look up everything you can. + + + + + Only fetch the PDB if it lives in the symbolCacheDirectory (is local an is generated). + This will generate NGEN pdbs unless the NoNGenPDBs flag is set. + + + + + No NGEN PDB generation. + + + + + The path of the file at the time the source file was built. We also look here when looking for the source. + + + + + If the source file is directly available on the web (that is there is a Url that + can be used to fetch it with HTTP Get), then return that Url. If no such publishing + point exists this property will return null. + + + + + This may fetch things from the source server, and thus can be very slow, which is why it is not a property. + returns a path to the file on the local machine (often in some machine local cache). + If requireChecksumMatch == false then you can see if you have an exact match by calling ChecksumMatches + (and if there is a checksum with HasChecksum). + + + + + true if the PDB has a checksum for the data in the source file. + + + + + If GetSourceFile is called and 'requireChecksumMatch' == false then you can call this property to + determine if the checksum actually matched or not. This will return true if the original + PDB does not have a checksum (HasChecksum == false) + ; + + + + Look up the source from the source server. Returns null if it can't find the source + By default this simply uses the Url to look it up on the web. If 'Url' returns null + so does this. + + + + + Given 'fileName' which is a path to a file (which may not exist), set + _filePath and _checksumMatches appropriately. Namely _filePath should + always be the 'best' candidate for the source file path (matching checksum + wins, otherwise first existing file wins). + + Returns true if we have a perfect match (no additional probing needed). + + + + + Returns true if 'filePath' matches the checksum OR we don't have a checkdum + (thus if we pass what validity check we have). + + + + + General purpose utilities dealing with archiveFile system directories. + + + + + SafeCopy sourceDirectory to directoryToVersion recursively. The target directory does + no need to exist + + + + + SafeCopy all files from sourceDirectory to directoryToVersion. If searchOptions == AllDirectories + then the copy is recursive, otherwise it is just one level. The target directory does not + need to exist. + + + + + Clean is sort of a 'safe' recursive delete of a directory. It either deletes the + files or moves them to '*.deleting' names. It deletes directories that are completely + empty. Thus it will do a recursive delete when that is possible. There will only + be *.deleting files after this returns. It returns the number of files and directories + that could not be deleted. + + + + + Removes the oldest directories directly under 'directoryPath' so that + only 'numberToKeep' are left. + + Directory to removed old files from. + The number of files to keep. + true if there were no errors deleting files + + + + DirectoryUtilities.GetFiles is basicaly the same as Directory.GetFiles + however it returns IEnumerator, which means that it lazy. This is very important + for large directory trees. A searchPattern can be specified (Windows wildcard conventions) + that can be used to filter the set of archiveFile names returned. + + Suggested Usage + + foreach(string fileName in DirectoryUtilities.GetFiles("c:\", "*.txt")){ + Console.WriteLine(fileName); + } + + + The base directory to enumerate + A pattern to filter the names (windows filename wildcards * ?) + Indicate if the search is recursive or not. + The enumerator for all archiveFile names in the directory (recursively). + + + + Returns a lazy enumerable for every path in 'directoryName' that matchs 'searchPattern' (default is *)MO + + + + + General purpose utilities dealing with archiveFile system files. + + + + + GetLines works much like File.ReadAllLines, however instead of returning a + array of lines, it returns a IEnumerable so that the archiveFile is not read all + at once. This allows 'foreach' syntax to be used on very large files. + + Suggested Usage + + foreach(string lineNumber in FileUtilities.GetLines("largeFile.txt")){ + Console.WriteLine(lineNumber); + } + + The base directory to enumerate. + The enumerator for all lines in the archiveFile. + + + + Given archiveFile specifications possibly with wildcards in them + Returns an enumerator that returns each expanded archiveFile name in turn. + + If searchOpt is AllDirectories it does a recursive match. + + + + + Delete works much like File.Delete, except that it will succeed if the + archiveFile does not exist, and will rename the archiveFile so that even if the archiveFile + is locked the original archiveFile variable will be made available. + + It renames the archiveFile with a '[num].deleting'. These files might be left + behind. + + It returns true if it was completely successful. If there is a *.deleting + archiveFile left behind, it returns false. + + The variable of the archiveFile to delete + + + + Try to delete 'fileName' catching any exception. Returns true if successful. It will delete read-only files. + + + + + SafeCopy sourceFile to destinationFile. If the destination exists + used ForceDelete to get rid of it first. + + + + + Moves sourceFile to destinationFile. If the destination exists + used ForceDelete to get rid of it first. + + + + + Returns true if the two file have exactly the same content (as a stream of bytes). + + + + + Utilities associated with file name paths. + + + + + Given a path and a superdirectory path relativeToDirectory compute the relative path (the path from) relativeToDirectory + + + + + General utilities associated with streams. + + + + + Open the 'fromFilePath' and write its contents to 'toStream' + + + + + Open the 'toFilePath' for writing and write the contents of 'fromStream' to it + + + + + CopyStream simply copies 'fromStream' to 'toStream' + + + + + The important thing about these general utilities is that they have only dependencies on mscorlib and + System (they can be used from anywhere). + + + + + Given an XML element, remove the closing operator for it, so you can add new child elements to it by concatination. + + + + + Given an object 'obj' do ToString() on it, and then transform it so that all speical XML characters are escaped and return the result. + If 'quote' is true also surround the resulting object with double quotes. + + + + + A shortcut for XmlEscape(obj, true) (that is ToString the object, escape XML chars, and then surround with double quotes. + + + + + Create a doubly quoted string for the decimal integer value + + + + + Create a double quoted string for the hexidecimal value of 'value' + + + + + Create a double quoted string for the hexidecimal value of 'value' + + + + + Create a double quoted string for the hexidecimal value of 'value' + + + + + Create a double quoted string for the hexidecimal value of 'value' + + + + + Used to send the rawManifest into the event stream as a series of events. + + + + + Finds native DLLS next to the managed DLL that uses them. + + + + + ManifestModule.FullyQualifiedName returns this as file path if the assembly is loaded as byte array + + + + + Loads a native DLL with a filename-extension of 'simpleName' by adding the path of the currently executing assembly + + + + + + + Gets the name of the directory containing compiled binaries (DLLs) which have the same architecture as the + currently executing process. + + + + + This is the backing field for the lazily-computed property. + + + + + A StackSource that aggregates information from other StackSources into a single unified view. + + + Each StackSource has a name associated with it. The stacks for each StackSource will be grouped under + a pseudo-frame named the same as the source name. Source names are specified on initialization. + + + + + Initialize a new AggregateStackSource. + + An IEnumerable of KeyValuePairs mapping source names to StackSources. + + + + Enumerate samples with a callback function. + + The function to call on each sample. + + + + override + + + + + Enumerate samples for a given set of scenarios with a callback function. + + The function to call on each sample. + An array of length ScenarioCount. If scenariosIncluded[i] == true, include scenario i. + + + + Override + + + + + Look up a sample by index. + + The index of the sample to look up. + + The sample, if it can be found and all sub-sources support indexing; null otherwise. + + + + + Gets the index of the caller of a given call stack. + + The call stack to look up. + The caller, if it exists, otherwise. + + + + Get the frame index of a given call stack. + + The call stack to look up. + The frame index of the call stack, if it exists, otherwise. + + + + Gets the name of a frame. + + The frame to look up. + Whether to include full module paths. + The name of the frame. + + + + The total number of call stacks in this source. + + + + + The total number of frames in this source. + + + + + The total number of samples in this source. + + + + + The names for the scenarios. + + + + + override + + + + + override + + + + + Convert a StackSourceSample produced by a sub-source into one suitable for the aggregate source. + + The StackSourceSample to convert. + A place to but the returned sampled (will become the return value). + The index of the source from which the sample came. + The converted sample. + + If ConvertSample is called again, all previous samples produced by ConvertSample may no longer be used. + + + + + Friendly names of sources. + + + Name 0 is the name of the pseudo-source, which should not be used. + + + + + The list of sources. + + + Source 0 is the pseudo-source (identical to m_pseudo). + + + + + THis is the time of the first sample. It lets us normalize the time in the sample to be relative to this. + + + + + A StackSource to generate the pseudo-frames needed to group scenarios. + + + + + Initialize a new PseudoStackSource. + + The names of the frames. + + + + Gets the CallStackIndex of the call stack corresponding to a given source. + + The index of the source to look up. + The StackSourceCallStackIndex of a stack under which to group all call stacks for that source. + + + + Gets the index of the caller of a given call stack. + + The call stack to look up. + The caller, if it exists, otherwise. + + + + Get the frame index of a given call stack. + + The call stack to look up. + The frame index of the call stack, if it exists, otherwise. + + + + Gets the name of a frame. + + The frame to look up. + Whether to include full module paths. + The name of the frame. + + + + The total number of call stacks in this source. + + + + + The total number of frames in this source. + + + + + The names of the frames that this source generates. + + + + + Extension methods for type-safe IndexMap operations on StackSource*Index enums. + + + + + This is just a class that holds data. It does nothing except support an 'update' events + + + + + Constructs a Filter parameter class with all empty properties. + + + + + Create a Filter Parameters Structure form another one + + + + + + Set a Filter Parameters Structure form another one + + + + + Fetch Name + + + + + Fetch StartTimeRelativeMSec + + + + + Fetch EndTimeRelativeMSec + + + + + Fetch MinInclusiveTimePercent + + + + + Fetch FoldRegExs + + + + + Fetch IncludeRegExs + + + + + Fetch ExcludeRegExs + + + + + Fetch GroupRegExs + + + + + Fetch TypePriority + + + + + Fetch ScenarioList + + + + + Fetch Scenarios + + + + + override + + + + + override + + + + + TODO Document + + + + + Write out the FilterParameters to XML 'writer' + + + + + Create an XML representation of FilterParams as a string + + + + + + A FilterStackSouce morphs one stack filters or groups the stacks of one stack source to form a new + stack source. It is very powerful mechanism. + + + + + Create a new FilterStackSource. + + Specifies how to filter or group the stacks + The input source to morph + How to scale the data (as time or simply by size of data) + + + + Override + + + + + Override + + + + + override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Override + + + + + Associated with every frame is a FrameInfo which is the computed answers associated with that frame name. + We cache these and so most of the time looking up frame information is just an array lookup. + + FrameInfo contains information that is ONLY dependent on the frame name (not the stack it came from), so + entry point groups and include patterns can not be completely processed at this point. Never returns null. + + + + + Generate the stack information for 'stack' and place it in stackInfoRet. Only called by GetStackInfo. + + + + + Returns the frame information for frameIndex. Never returns null. + + + + + This is just the parsed form of a grouping specification Pat->GroupNameTemplate (it has a pattern regular + expression and a group name that can have replacements) It is a trivial class + + + + + Experimentally we are going to special case the module entry pattern. + + + + + Parses a string into the GroupPattern structure that allows it to executed (matched). + + + + + Given the name of a frame, look it up in the group patterns and morph it to its group name. + If the group that matches is a entryGroup then set 'isEntryGroup'. Will return null if + no group matches 'frameName' + + + + + Holds parsed information about patterns for groups includes, excludes or folds. + + + + + Returns the index in the 'pats' array of the first pattern that matches 'str'. Returns -1 if no match. + + + + + returns true if set1 and set1 (as returned from MatchSet) are identical + + + + + Convert a string from my regular expression format (where you only have * and { } as grouping operators + and convert them to .NET regular expressions string + + + + + FrameInfo is all the information we need to associate with an Frame ID (to figure out what group/pattern it belongs to) + This includes what group it belongs to, the include patterns it matches whether to discard or fold it. It is + all the processing we can do with JUST the frame ID. + + Note that FrameInfo is reused by multiple stacks, which means that you should NOT update fields in it after initial creation. + + + + + This is what we return to the Stack crawler, it encodes either that we should filter the sample, + fold the frame, form a group, or the frameID that we have chosen to represent the group as a whole. + + + + + Represents all accumulated information about grouping for a particular stack. Effectively this is the + 'result' of applying the grouping and filtering to a particular stack. We cache the last 100 or so + of these because stacks tend to reuse the parts of the stack close the root. + + + + + The include patterns that have been matched by some frame in this stack. (ultimately we need all bits set). + Can be null, which means the empty set. + + + + + Represents a frame that does not match any pattern. Thus the default of simply returning the frame ID is appropriate + + + + + Represents a frame that should be discarded. + + + + + Represents a frame that should be folded into its caller. + + + + + We cache information about stacks we have previously seen so we can short-circuit work. + TODO make dynamic. + + Note when this value is 4096 some memory profiles are VERY sluggish. Don't make it too + small unless it is adaptive. + + + + + A class that maps contiguous indices from various sources from and to a single range of contiguous indices. + + + This is useful for aggregating indices used, for instance, in the interface for StackSource (StackSourceCallStackIndex / + StackSourceFrameIndex) in AggregateStackSource. This is an easy way, given the incoming StackSource*Index, to find the + aggregated source to query, and the corresponding StackSource*Index to send to the source. + + + With counts [3, 7, 5]: + 1 1 1 1 1 + 0 1 2 3 4 5 6 7 8 9 0 1 2 3 4 = Incoming index + __0__ ______1______ ____2____ = Source number + 0 1 2|0 1 2 3 4 5 6|0 1 2 3 4 = Offset + + + + + Initialize a new IndexMap with the specified counts. + + A list mapping an index to its corresponding count. + + + + Find the source for an index. + + The aggregate index to look up. + The source that belongs to. + + + + Find the offset into a given source of a given aggregate index. + + The aggregate index to look up. + The source to find the offset into. + The offset of into . + + + + Finds the index for a given source/offset pair. + + The source number of the item. + The offset into the corresponding source for the item. + The index corresponding to the pair of and . + + + + The total number of indices in the map. + + + + + The lookup table to convert indices to source/offset pairs. + + + This contains the cumulative count of indices that occurred before each source. + The last element is the total number of indices (equal to m_range). + + + + + The total number of indices in the map. + + + + + We remember the last source we looked up and check there first very likely they are next to one another. + + + + + A finite cache based with a least recently used algorithm for replacement. + It is meant to be fast (fast as a hashtable), and space efficient (not much + over the MaxEntry key-value pairs are stored. (only 8 bytes per entry additional). + + After reaching MaxEntry entries. It uses a roughly least-recently used + algorithm to pick a entry to recycle. To stay efficient it only searches + a finite time (up to 5 entries) for a entry that is older than 1/2 of the + entries in the table. + + It has the property that if you are in the maxEntries/2 most commonly fetched + things, you very unlikely to be evicted once you are in the cache. + + + + + maxEntries currently is only set in the constructor. Thus this is a finite sized cache + but is otherwise very efficient. Currently it uses ushorts internally so the number + of entries is limited to 64K (it silently limits it if you give maxEntries > 64K). + + + + + + Fetches the value from the cache with key 'key'. Returns default(T) if not present + + + + + Fetches the value from the cache with key 'key'. Returns false if not present. + + + + + Adds 'key' with value 'value' to the cache. + + + + + Removes all entries in the cache. + + + + + Sets the maxiumum number of key-value pairs the cache will keep. (after that old ones are remvoed). + + + + + Represents a null pointer (end of a linked list) + + + + + CommandOptions is a helper class for the Command class. It stores options + that affect the behavior of the execution of ETWCommands and is passes as a + parameter to the constructor of a Command. + + It is useful for these options be be on a separate class (rather than + on Command itself), because it is reasonably common to want to have a set + of options passed to several commands, which is not easily possible otherwise. + + + + + Can be assigned to the Timeout Property to indicate infinite timeout. + + + + + CommanOptions holds a set of options that can be passed to the constructor + to the Command Class as well as Command.Run* + + + + + Return a copy an existing set of command options + + The copy of the command options + + + + Normally commands will throw if the subprocess returns a non-zero + exit code. NoThrow suppresses this. + + + + + Updates the NoThrow propery and returns the updated commandOptions. + Updated command options + + + + + ShortHand for UseShellExecute and NoWait + + + + + Updates the Start propery and returns the updated commandOptions. + + + + + Normally commands are launched with CreateProcess. However it is + also possible use the Shell Start API. This causes Command to look + up the executable differently + + + + + Updates the Start propery and returns the updated commandOptions. + + + + + Indicates that you want to hide any new window created. + + + + + Updates the NoWindow propery and returns the updated commandOptions. + + + + + Indicates that you want don't want to wait for the command to complete. + + + + + Updates the NoWait propery and returns the updated commandOptions. + + + + + Indicates that the command must run at elevated Windows privledges (causes a new command window) + + + + + Updates the Elevate propery and returns the updated commandOptions. + + + + + By default commands have a 10 minute timeout (600,000 msec), If this + is inappropriate, the Timeout property can change this. Like all + timouts in .NET, it is in units of milliseconds, and you can use + CommandOptions.Infinite to indicate no timeout. + + + + + Updates the Timeout propery and returns the updated commandOptions. + CommandOptions.Infinite can be used for infinite + + + + + Indicates the string will be sent to Console.In for the subprocess. + + + + + Updates the Input propery and returns the updated commandOptions. + + + + + Indicates the current directory the subProcess will have. + + + + + Updates the CurrentDirectory propery and returns the updated commandOptions. + + + + + Indicates the standard output and error of the command should be redirected + to a archiveFile rather than being stored in Memory in the 'Output' property of the + command. + + + + + Updates the OutputFile propery and returns the updated commandOptions. + + + + + Indicates the standard output and error of the command should be redirected + to a a TextWriter rather than being stored in Memory in the 'Output' property + of the command. + + + + + Updates the OutputStream property and returns the updated commandOptions. + + + + + Gets the Environment variables that will be set in the subprocess that + differ from current process's environment variables. Any time a string + of the form %VAR% is found in a value of a environment variable it is + replaced with the value of the environment variable at the time the + command is launched. This is useful for example to update the PATH + environment variable eg. "%PATH%;someNewPath" + + + + + Adds the environment variable with the give value to the set of + environmetn variables to be passed to the sub-process and returns the + updated commandOptions. Any time a string + of the form %VAR% is found in a value of a environment variable it is + replaced with the value of the environment variable at the time the + command is launched. This is useful for example to update the PATH + environment variable eg. "%PATH%;someNewPath" + + + + + Command represents a running of a command lineNumber process. It is basically + a wrapper over System.Diagnostics.Process, which hides the complexitity + of System.Diagnostics.Process, and knows how to capture output and otherwise + makes calling commands very easy. + + + + + The time the process started. + + + + + Returns true if the process has exited. + + + + + The time the processed Exited. (HasExited should be true before calling) + + + + + The duration of the command (HasExited should be true before calling) + + + + + The operating system ID for the subprocess. + + + + + The process exit code for the subprocess. (HasExited should be true before calling) + Often this does not need to be checked because Command.Run will throw an exception + if it is not zero. However it is useful if the CommandOptions.NoThrow property + was set. + + + + + The standard output and standard error output from the command. This + is accumulated in real time so it can vary if the process is still running. + + This property is NOT available if the CommandOptions.OutputFile or CommandOptions.OutputStream + is specified since the output is being redirected there. If a large amount of output is + expected (> 1Meg), the Run.AddOutputStream(Stream) is recommended for retrieving it since + the large string is never materialized at one time. + + + + + Returns that CommandOptions structure that holds all the options that affect + the running of the command (like Timeout, Input ...) + + + + + Run 'commandLine', sending the output to the console, and wait for the command to complete. + This simulates what batch filedo when executing their commands. It is a bit more verbose + by default, however + + The command lineNumber to run as a subprocess + Additional qualifiers that control how the process is run + A Command structure that can be queried to determine ExitCode, Output, etc. + + + + Run 'commandLine' as a subprocess and waits for the command to complete. + Output is captured and placed in the 'Output' property of the returned Command + structure. + + The command lineNumber to run as a subprocess + Additional qualifiers that control how the process is run + A Command structure that can be queried to determine ExitCode, Output, etc. + + + + Launch a new command and returns the Command object that can be used to monitor + the restult. It does not wait for the command to complete, however you + can call 'Wait' to do that, or use the 'Run' or 'RunToConsole' methods. */ + + The command lineNumber to run as a subprocess + Additional qualifiers that control how the process is run + A Command structure that can be queried to determine ExitCode, Output, etc. + + + + Create a subprocess to run 'commandLine' with no special options. + The command lineNumber to run as a subprocess + + + + + Wait for a started process to complete (HasExited will be true on return) + + Wait returns that 'this' pointer. + + + + Throw a error if the command exited with a non-zero exit code + printing useful diagnostic information along with the thrown message. + This is useful when NoThrow is specified, and after post-processing + you determine that the command really did fail, and an normal + Command.Run failure was the appropriate action. + + An additional message to print in the throw (can be null) + + + + Get the underlying process object. Generally not used. + + + + + Kill the process (and any child processses (recursively) associated with the + running command). Note that it may not be able to kill everything it should + if the child-parent' chain is broken by a child that creates a subprocess and + then dies itself. This is reasonably uncommon, however. + + + + + Put double quotes around 'str' if necessary (handles quotes quotes. + + + + + Given a string 'commandExe' look for it on the path the way cmd.exe would. + Returns null if it was not found. + + + + + requiredOSVersion is a number that is the major version * 10 + minor. Thus + Win 10 == 100 + Win 8 == 62 + Win 7 == 61 + Vista == 60 + This returns true if true OS version is >= 'requiredOSVersion + + + + + The DiaLoader class knows how to load the msdia140.dll (the Debug Access Interface) (see docs at + http://msdn.microsoft.com/en-us/library/x93ctkx8.aspx), without it being registered as a COM object. + Basically it just called the DllGetClassObject interface directly. + + It has one public method 'GetDiaSourceObject' which knows how to create a IDiaDataSource object. + From there you can do anything you need. + + In order to get IDiaDataSource3 which includes'getStreamSize' API, you need to use the + vctools\langapi\idl\dia2_internal.idl file from devdiv to produce Dia2Lib.dll + + roughly what you need to do is + copy vctools\langapi\idl\dia2_internal.idl . + copy vctools\langapi\idl\dia2.idl . + copy vctools\langapi\include\cvconst.h . + Change dia2.idl to include interface IDiaDataSource3 inside library Dia2Lib->importlib->coclass DiaSource + midl dia2_internal.idl /D CC_DP_CXX + tlbimp dia2_internal.tlb + REM result is Dia2Lib.dll + + + + + Load the msdia100 dll and get a IDiaDataSource from it. This is your gateway to PDB reading. + + + + + Used to ensure the native library is loaded at least once prior to trying to use it. No protection is + included to avoid multiple loads, but this is not a problem since we aren't trying to unload the library + after use. + + + + + PEFile is a reader for the information in a Portable Exectable (PE) FILE. This is what EXEs and DLLs are. + + It can read both 32 and 64 bit PE files. + + + + + Create a new PEFile header reader that inspects the + + + + + The Header for the PE file. This contains the infor in a link /dump /headers + + + + + Looks up the debug signature information in the EXE. Returns true and sets the parameters if it is found. + + If 'first' is true then the first entry is returned, otherwise (by default) the last entry is used + (this is what debuggers do today). Thus NGEN images put the IL PDB last (which means debuggers + pick up that one), but we can set it to 'first' if we want the NGEN PDB. + + + + + Gets the File Version Information that is stored as a resource in the PE file. (This is what the + version tab a file's property page is populated with). + + + + + For side by side dlls, the manifest that decribes the binding information is stored as the RT_MANIFEST resource, and it + is an XML string. This routine returns this. + + + + + + Returns true if this is and NGEN or Ready-to-Run image (it has precompiled native code) + + + + + Returns true if file has a managed ready-to-run image. + + + + + Gets the major and minor ready-to-run version. returns true if ready-to-run. + + + + + Closes any file handles and cleans up resources. + + + + + A PEHeader is a reader of the data at the beginning of a PEFile. If the header bytes of a + PEFile are read or mapped into memory, this class can parse it when given a poitner to it. + It can read both 32 and 64 bit PE files. + + + + + Returns a PEHeader for void* pointer in memory. It does NO validity checking. + + + + + The total s,ize of the header, including section array of the the PE header. + + + + + Given a virtual address to data in a mapped PE file, return the relative virtual address (displacement from start of the image) + + + + + Given a relative virtual address (displacement from start of the image) return the virtual address to data in a mapped PE file + + + + + Given a relative virtual address (displacement from start of the image) return a offset in the file data for that data. + + + + + Returns true if this is PE file for a 64 bit architecture. + + + + + Returns true if this file contains managed code (might also contain native code). + + + + + Returns the 'Signature' of the PE HEader PE\0\0 = 0x4550, used for sanity checking. + + + + + The machine this PE file is intended to run on + + + + + PE files have a number of sections that represent regions of memory with the access permisions. This is the nubmer of such sections. + + + + + The the PE file was created represented as the number of seconds since Jan 1 1970 + + + + + The the PE file was created represented as a DateTime object + + + + + PointerToSymbolTable (see IMAGE_FILE_HEADER in PE File spec) + + + + + NumberOfSymbols (see IMAGE_FILE_HEADER PE File spec) + + + + + SizeOfOptionalHeader (see IMAGE_FILE_HEADER PE File spec) + + + + + Characteristics (see IMAGE_FILE_HEADER PE File spec) + + + + + Magic (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MajorLinkerVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MinorLinkerVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfCode (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfInitializedData (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfUninitializedData (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + AddressOfEntryPoint (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + BaseOfCode (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + ImageBase (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SectionAlignment (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + FileAlignment (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MajorOperatingSystemVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MinorOperatingSystemVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MajorImageVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MinorImageVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MajorSubsystemVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + MinorSubsystemVersion (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + Win32VersionValue (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfImage (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfHeaders (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + CheckSum (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + Subsystem (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + DllCharacteristics (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfStackReserve (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfStackCommit (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfHeapReserve (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + SizeOfHeapCommit (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + LoaderFlags (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + NumberOfRvaAndSizes (see IMAGE_OPTIONAL_HEADER32 or IMAGE_OPTIONAL_HEADER64 in PE File spec) + + + + + Returns the data directory (virtual address an blob, of a data directory with index 'idx'. 14 are currently defined. + + + + + Returns the data directory for DLL Exports see PE file spec for more + + + + + Returns the data directory for DLL Imports see PE file spec for more + + + + + Returns the data directory for DLL Resources see PE file spec for more + + + + + Returns the data directory for DLL Exceptions see PE file spec for more + + + + + Returns the data directory for DLL securiy certificates (Authenticode) see PE file spec for more + + + + + Returns the data directory Image Base Relocations (RELOCS) see PE file spec for more + + + + + Returns the data directory for Debug information see PE file spec for more + + + + + Returns the data directory for DLL Exports see PE file spec for more + + + + + Returns the data directory for GlobalPointer (IA64) see PE file spec for more + + + + + Returns the data directory for THread local storage see PE file spec for more + + + + + Returns the data directory for Load Configuration see PE file spec for more + + + + + Returns the data directory for Bound Imports see PE file spec for more + + + + + Returns the data directory for the DLL Import Address Table (IAT) see PE file spec for more + + + + + Returns the data directory for Delayed Imports see PE file spec for more + + + + + see PE file spec for more .NET Runtime infomration. + + + + + The Machine types supported by the portable executable (PE) File format + + + + + Unknown machine type + + + + + Intel X86 CPU + + + + + Intel IA64 + + + + + ARM 32 bit + + + + + Arm 64 bit + + + + + Represents a Portable Executable (PE) Data directory. This is just a well known optional 'Blob' of memory (has a starting point and size) + + + + + The start of the data blob when the file is mapped into memory + + + + + The length of the data blob. + + + + + FileVersionInfo represents the extended version formation that is optionally placed in the PE file resource area. + + + + + The verison string + + + + + A PEBuffer represents a buffer (efficient) scanner of the + + +
+
diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/OSExtensions.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/OSExtensions.dll new file mode 100644 index 0000000..49d7a56 Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/OSExtensions.dll differ diff --git a/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/TraceReloggerLib.dll b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/TraceReloggerLib.dll new file mode 100644 index 0000000..1a8280b Binary files /dev/null and b/Packages/Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42/lib/netstandard2.0/TraceReloggerLib.dll differ diff --git a/Packages/Newtonsoft.Json.13.0.1/.signature.p7s b/Packages/Newtonsoft.Json.13.0.1/.signature.p7s new file mode 100644 index 0000000..988b1e1 Binary files /dev/null and b/Packages/Newtonsoft.Json.13.0.1/.signature.p7s differ diff --git a/Packages/Newtonsoft.Json.13.0.1/LICENSE.md b/Packages/Newtonsoft.Json.13.0.1/LICENSE.md new file mode 100644 index 0000000..dfaadbe --- /dev/null +++ b/Packages/Newtonsoft.Json.13.0.1/LICENSE.md @@ -0,0 +1,20 @@ +The MIT License (MIT) + +Copyright (c) 2007 James Newton-King + +Permission is hereby granted, free of charge, to any person obtaining a copy of +this software and associated documentation files (the "Software"), to deal in +the Software without restriction, including without limitation the rights to +use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of +the Software, and to permit persons to whom the Software is furnished to do so, +subject to the following conditions: + +The above copyright notice and this permission notice shall be included in all +copies or substantial portions of the Software. + +THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR +IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS +FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR +COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER +IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN +CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE. diff --git a/Packages/Newtonsoft.Json.13.0.1/Newtonsoft.Json.13.0.1.nupkg b/Packages/Newtonsoft.Json.13.0.1/Newtonsoft.Json.13.0.1.nupkg new file mode 100644 index 0000000..9eb2ddd Binary files /dev/null and b/Packages/Newtonsoft.Json.13.0.1/Newtonsoft.Json.13.0.1.nupkg differ diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/net20/Newtonsoft.Json.dll b/Packages/Newtonsoft.Json.13.0.1/lib/net20/Newtonsoft.Json.dll new file mode 100644 index 0000000..d40ac9c Binary files /dev/null and b/Packages/Newtonsoft.Json.13.0.1/lib/net20/Newtonsoft.Json.dll differ diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/net20/Newtonsoft.Json.xml b/Packages/Newtonsoft.Json.13.0.1/lib/net20/Newtonsoft.Json.xml new file mode 100644 index 0000000..181504f --- /dev/null +++ b/Packages/Newtonsoft.Json.13.0.1/lib/net20/Newtonsoft.Json.xml @@ -0,0 +1,10335 @@ + + + + Newtonsoft.Json + + + + + Represents a BSON Oid (object id). + + + + + Gets or sets the value of the Oid. + + The value of the Oid. + + + + Initializes a new instance of the class. + + The Oid value. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized BSON data. + + + + + Gets or sets a value indicating whether binary data reading should be compatible with incorrect Json.NET 3.5 written binary. + + + true if binary data reading will be compatible with incorrect Json.NET 3.5 written binary; otherwise, false. + + + + + Gets or sets a value indicating whether the root object will be read as a JSON array. + + + true if the root object will be read as a JSON array; otherwise, false. + + + + + Gets or sets the used when reading values from BSON. + + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating BSON data. + + + + + Gets or sets the used when writing values to BSON. + When set to no conversion will occur. + + The used when writing values to BSON. + + + + Initializes a new instance of the class. + + The to write to. + + + + Initializes a new instance of the class. + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying stream. + + + + + Writes the end. + + The token. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes the beginning of a JSON array. + + + + + Writes the beginning of a JSON object. + + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value that represents a BSON object id. + + The Object ID value to write. + + + + Writes a BSON regex. + + The regex pattern. + The regex options. + + + + Specifies how constructors are used when initializing objects during deserialization by the . + + + + + First attempt to use the public default constructor, then fall back to a single parameterized constructor, then to the non-public default constructor. + + + + + Json.NET will use a non-public default constructor before falling back to a parameterized constructor. + + + + + Converts a binary value to and from a base 64 string value. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Creates a custom object. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Creates an object which will then be populated by the serializer. + + Type of the object. + The created object. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can write JSON. + + + true if this can write JSON; otherwise, false. + + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Provides a base class for converting a to and from JSON. + + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from the ISO 8601 date format (e.g. "2008-04-12T12:53Z"). + + + + + Gets or sets the date time styles used when converting a date to and from JSON. + + The date time styles used when converting a date to and from JSON. + + + + Gets or sets the date time format used when converting a date to and from JSON. + + The date time format used when converting a date to and from JSON. + + + + Gets or sets the culture used when converting a date to and from JSON. + + The culture used when converting a date to and from JSON. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Converts a to and from a JavaScript Date constructor (e.g. new Date(52231943)). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an to and from its name string value. + + + + + Gets or sets a value indicating whether the written enum text should be camel case. + The default value is false. + + true if the written enum text will be camel case; otherwise, false. + + + + Gets or sets the naming strategy used to resolve how enum text is written. + + The naming strategy used to resolve how enum text is written. + + + + Gets or sets a value indicating whether integer values are allowed when serializing and deserializing. + The default value is true. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class. + + true if the written enum text will be camel case; otherwise, false. + + + + Initializes a new instance of the class. + + The naming strategy used to resolve how enum text is written. + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from Unix epoch time + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from a string (e.g. "1.2.3.4"). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts XML to and from JSON. + + + + + Gets or sets the name of the root element to insert when deserializing to XML if the JSON structure has produced multiple root elements. + + The name of the deserialized root element. + + + + Gets or sets a value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + true if the array attribute is written to the XML; otherwise, false. + + + + Gets or sets a value indicating whether to write the root JSON object. + + true if the JSON root object is omitted; otherwise, false. + + + + Gets or sets a value indicating whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + true if special characters are encoded; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The calling serializer. + The value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Checks if the is a namespace attribute. + + Attribute name to test. + The attribute name prefix if it has one, otherwise an empty string. + true if attribute name is for a namespace attribute, otherwise false. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Specifies how dates are formatted when writing JSON text. + + + + + Dates are written in the ISO 8601 format, e.g. "2012-03-21T05:40Z". + + + + + Dates are written in the Microsoft JSON format, e.g. "\/Date(1198908717056)\/". + + + + + Specifies how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON text. + + + + + Date formatted strings are not parsed to a date type and are read as strings. + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Specifies how to treat the time value when converting between string and . + + + + + Treat as local time. If the object represents a Coordinated Universal Time (UTC), it is converted to the local time. + + + + + Treat as a UTC. If the object represents a local time, it is converted to a UTC. + + + + + Treat as a local time if a is being converted to a string. + If a string is being converted to , convert to a local time if a time zone is specified. + + + + + Time zone information should be preserved when converting. + + + + + The default JSON name table implementation. + + + + + Initializes a new instance of the class. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Adds the specified string into name table. + + The string to add. + This method is not thread-safe. + The resolved string. + + + + Specifies default value handling options for the . + + + + + + + + + Include members where the member value is the same as the member's default value when serializing objects. + Included members are written to JSON. Has no effect when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + so that it is not written to JSON. + This option will ignore all default values (e.g. null for objects and nullable types; 0 for integers, + decimals and floating point numbers; and false for booleans). The default value ignored can be changed by + placing the on the property. + + + + + Members with a default value but no JSON will be set to their default value when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + and set members to their default value when deserializing. + + + + + Specifies float format handling options when writing special floating point numbers, e.g. , + and with . + + + + + Write special floating point values as strings in JSON, e.g. "NaN", "Infinity", "-Infinity". + + + + + Write special floating point values as symbols in JSON, e.g. NaN, Infinity, -Infinity. + Note that this will produce non-valid JSON. + + + + + Write special floating point values as the property's default value in JSON, e.g. 0.0 for a property, null for a of property. + + + + + Specifies how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Floating point numbers are parsed to . + + + + + Floating point numbers are parsed to . + + + + + Specifies formatting options for the . + + + + + No special formatting is applied. This is the default. + + + + + Causes child objects to be indented according to the and settings. + + + + + Provides an interface for using pooled arrays. + + The array type content. + + + + Rent an array from the pool. This array must be returned when it is no longer needed. + + The minimum required length of the array. The returned array may be longer. + The rented array from the pool. This array must be returned when it is no longer needed. + + + + Return an array to the pool. + + The array that is being returned. + + + + Provides an interface to enable a class to return line and position information. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + The current line number or 0 if no line information is available (for example, when returns false). + + + + Gets the current line position. + + The current line position or 0 if no line information is available (for example, when returns false). + + + + Instructs the how to serialize the collection. + + + + + Gets or sets a value indicating whether null items are allowed in the collection. + + true if null items are allowed in the collection; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with a flag indicating whether the array can contain null items. + + A flag indicating whether the array can contain null items. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to use the specified constructor when deserializing that object. + + + + + Instructs the how to serialize the object. + + + + + Gets or sets the id. + + The id. + + + + Gets or sets the title. + + The title. + + + + Gets or sets the description. + + The description. + + + + Gets or sets the collection's items converter. + + The collection's items converter. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets a value that indicates whether to preserve object references. + + + true to keep object reference; otherwise, false. The default is false. + + + + + Gets or sets a value that indicates whether to preserve collection's items references. + + + true to keep collection's items object references; otherwise, false. The default is false. + + + + + Gets or sets the reference loop handling used when serializing the collection's items. + + The reference loop handling. + + + + Gets or sets the type name handling used when serializing the collection's items. + + The type name handling. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Provides methods for converting between .NET types and JSON types. + + + + + + + + Gets or sets a function that creates default . + Default settings are automatically used by serialization methods on , + and and on . + To serialize without using any default settings create a with + . + + + + + Represents JavaScript's boolean value true as a string. This field is read-only. + + + + + Represents JavaScript's boolean value false as a string. This field is read-only. + + + + + Represents JavaScript's null as a string. This field is read-only. + + + + + Represents JavaScript's undefined as a string. This field is read-only. + + + + + Represents JavaScript's positive infinity as a string. This field is read-only. + + + + + Represents JavaScript's negative infinity as a string. This field is read-only. + + + + + Represents JavaScript's NaN as a string. This field is read-only. + + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + The time zone handling when the date is converted to a string. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + The string escape handling. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Serializes the specified object to a JSON string. + + The object to serialize. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting. + + The object to serialize. + Indicates how the output should be formatted. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a collection of . + + The object to serialize. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting and a collection of . + + The object to serialize. + Indicates how the output should be formatted. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Deserializes the JSON to a .NET object. + + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to a .NET object using . + + The JSON to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The JSON to deserialize. + The of object being deserialized. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The type of the object to deserialize to. + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the given anonymous type. + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the given anonymous type using . + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The type of the object to deserialize to. + The JSON to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The type of the object to deserialize to. + The object to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The JSON to deserialize. + The type of the object to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The JSON to deserialize. + The type of the object to deserialize to. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Populates the object with values from the JSON string. + + The JSON to populate values from. + The target object to populate values onto. + + + + Populates the object with values from the JSON string using . + + The JSON to populate values from. + The target object to populate values onto. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + + + + Serializes the to a JSON string. + + The node to serialize. + A JSON string of the . + + + + Serializes the to a JSON string using formatting. + + The node to serialize. + Indicates how the output should be formatted. + A JSON string of the . + + + + Serializes the to a JSON string using formatting and omits the root object if is true. + + The node to serialize. + Indicates how the output should be formatted. + Omits writing the root object. + A JSON string of the . + + + + Deserializes the from a JSON string. + + The JSON string. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by . + + The JSON string. + The name of the root element to append when deserializing. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by + and writes a Json.NET array attribute for collections. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by , + writes a Json.NET array attribute for collections, and encodes special characters. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + + A value to indicate whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + The deserialized . + + + + Converts an object to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can read JSON. + + true if this can read JSON; otherwise, false. + + + + Gets a value indicating whether this can write JSON. + + true if this can write JSON; otherwise, false. + + + + Converts an object to and from JSON. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. If there is no existing value then null will be used. + The existing value has a value. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Instructs the to use the specified when serializing the member or class. + + + + + Gets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + + + + + Initializes a new instance of the class. + + Type of the . + + + + Initializes a new instance of the class. + + Type of the . + Parameter list to use when constructing the . Can be null. + + + + Represents a collection of . + + + + + Instructs the how to serialize the collection. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Instructs the to deserialize properties with no matching class member into the specified collection + and write values during serialization. + + + + + Gets or sets a value that indicates whether to write extension data when serializing the object. + + + true to write extension data when serializing the object; otherwise, false. The default is true. + + + + + Gets or sets a value that indicates whether to read extension data when deserializing the object. + + + true to read extension data when deserializing the object; otherwise, false. The default is true. + + + + + Initializes a new instance of the class. + + + + + Instructs the not to serialize the public field or public read/write property value. + + + + + Base class for a table of atomized string objects. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Instructs the how to serialize the object. + + + + + Gets or sets the member serialization. + + The member serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified member serialization. + + The member serialization. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to always serialize the member with the specified name. + + + + + Gets or sets the type used when serializing the property's collection items. + + The collection's items type. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the null value handling used when serializing this property. + + The null value handling. + + + + Gets or sets the default value handling used when serializing this property. + + The default value handling. + + + + Gets or sets the reference loop handling used when serializing this property. + + The reference loop handling. + + + + Gets or sets the object creation handling used when deserializing this property. + + The object creation handling. + + + + Gets or sets the type name handling used when serializing this property. + + The type name handling. + + + + Gets or sets whether this property's value is serialized as a reference. + + Whether this property's value is serialized as a reference. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets a value indicating whether this property is required. + + + A value indicating whether this property is required. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified name. + + Name of the property. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Specifies the state of the reader. + + + + + A read method has not been called. + + + + + The end of the file has been reached successfully. + + + + + Reader is at a property. + + + + + Reader is at the start of an object. + + + + + Reader is in an object. + + + + + Reader is at the start of an array. + + + + + Reader is in an array. + + + + + The method has been called. + + + + + Reader has just read a value. + + + + + Reader is at the start of a constructor. + + + + + Reader is in a constructor. + + + + + An error occurred that prevents the read operation from continuing. + + + + + The end of the file has been reached successfully. + + + + + Gets the current reader state. + + The current reader state. + + + + Gets or sets a value indicating whether the source should be closed when this reader is closed. + + + true to close the source when this reader is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether multiple pieces of JSON content can + be read from a continuous stream without erroring. + + + true to support reading multiple pieces of JSON content; otherwise false. + The default is false. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + Gets or sets how time zones are handled when reading JSON. + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Gets or sets how custom date formatted strings are parsed when reading JSON. + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets the type of the current JSON token. + + + + + Gets the text value of the current JSON token. + + + + + Gets the .NET type for the current JSON token. + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets or sets the culture used when reading JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Reads the next JSON token from the source. + + true if the next token was read successfully; false if there are no more tokens to read. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Skips the children of the current token. + + + + + Sets the current token. + + The new token. + + + + Sets the current token and value. + + The new token. + The value. + + + + Sets the current token and value. + + The new token. + The value. + A flag indicating whether the position index inside an array should be updated. + + + + Sets the state based on current token type. + + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Changes the reader's state to . + If is set to true, the source is also closed. + + + + + The exception thrown when an error occurs while reading JSON text. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Instructs the to always serialize the member, and to require that the member has a value. + + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Serializes and deserializes objects into and from the JSON format. + The enables you to control how objects are encoded into JSON. + + + + + Occurs when the errors during serialization and deserialization. + + + + + Gets or sets the used by the serializer when resolving references. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + + + + Gets or sets how reference loops (e.g. a class referencing itself) is handled. + The default value is . + + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets a collection that will be used during serialization. + + Collection that will be used during serialization. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets a value indicating whether there will be a check for additional JSON content after deserializing an object. + The default value is false. + + + true if there will be a check for additional JSON content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Creates a new instance. + The will not use default settings + from . + + + A new instance. + The will not use default settings + from . + + + + + Creates a new instance using the specified . + The will not use default settings + from . + + The settings to be applied to the . + + A new instance using the specified . + The will not use default settings + from . + + + + + Creates a new instance. + The will use default settings + from . + + + A new instance. + The will use default settings + from . + + + + + Creates a new instance using the specified . + The will use default settings + from as well as the specified . + + The settings to be applied to the . + + A new instance using the specified . + The will use default settings + from as well as the specified . + + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Deserializes the JSON structure contained by the specified . + + The that contains the JSON structure to deserialize. + The being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The type of the object to deserialize. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is Auto to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Specifies the settings on a object. + + + + + Gets or sets how reference loops (e.g. a class referencing itself) are handled. + The default value is . + + Reference loop handling. + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + Missing member handling. + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + Null value handling. + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + The default value handling. + + + + Gets or sets a collection that will be used during serialization. + + The converters. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + The preserve references handling. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + The type name handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + The contract resolver. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets the used by the serializer when resolving references. + + The reference resolver. + + + + Gets or sets a function that creates the used by the serializer when resolving references. + + A function that creates the used by the serializer when resolving references. + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the error handler called during serialization and deserialization. + + The error handler called during serialization and deserialization. + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets a value indicating whether there will be a check for additional content after deserializing an object. + The default value is false. + + + true if there will be a check for additional content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Represents a reader that provides fast, non-cached, forward-only access to JSON text data. + + + + + Initializes a new instance of the class with the specified . + + The containing the JSON data to read. + + + + Gets or sets the reader's property name table. + + + + + Gets or sets the reader's character buffer pool. + + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + + The current line number or 0 if no line information is available (for example, returns false). + + + + + Gets the current line position. + + + The current line position or 0 if no line information is available (for example, returns false). + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets or sets the writer's character array pool. + + + + + Gets or sets how many s to write for each level in the hierarchy when is set to . + + + + + Gets or sets which character to use to quote attribute values. + + + + + Gets or sets which character to use for indenting when is set to . + + + + + Gets or sets a value indicating whether object names will be surrounded with quotes. + + + + + Initializes a new instance of the class using the specified . + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying . + + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the specified end token. + + The end token to write. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Specifies the type of JSON token. + + + + + This is returned by the if a read method has not been called. + + + + + An object start token. + + + + + An array start token. + + + + + A constructor start token. + + + + + An object property name. + + + + + A comment. + + + + + Raw JSON. + + + + + An integer. + + + + + A float. + + + + + A string. + + + + + A boolean. + + + + + A null token. + + + + + An undefined token. + + + + + An object end token. + + + + + An array end token. + + + + + A constructor end token. + + + + + A Date. + + + + + Byte data. + + + + + + Represents a reader that provides validation. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Sets an event handler for receiving schema validation errors. + + + + + Gets the text value of the current JSON token. + + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + + Gets the type of the current JSON token. + + + + + + Gets the .NET type for the current JSON token. + + + + + + Initializes a new instance of the class that + validates the content returned from the given . + + The to read from while validating. + + + + Gets or sets the schema. + + The schema. + + + + Gets the used to construct this . + + The specified in the constructor. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a []. + + + A [] or null if the next JSON token is null. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets or sets a value indicating whether the destination should be closed when this writer is closed. + + + true to close the destination when this writer is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether the JSON should be auto-completed when this writer is closed. + + + true to auto-complete the JSON when this writer is closed; otherwise false. The default is true. + + + + + Gets the top. + + The top. + + + + Gets the state of the writer. + + + + + Gets the path of the writer. + + + + + Gets or sets a value indicating how JSON text output should be formatted. + + + + + Gets or sets how dates are written to JSON text. + + + + + Gets or sets how time zones are handled when writing JSON text. + + + + + Gets or sets how strings are escaped when writing JSON text. + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written to JSON text. + + + + + Gets or sets how and values are formatted when writing JSON text. + + + + + Gets or sets the culture used when writing JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the destination and also flushes the destination. + + + + + Closes this writer. + If is set to true, the destination is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the end of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the end of an array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end constructor. + + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes the end of the current JSON object or array. + + + + + Writes the current token and its children. + + The to read the token from. + + + + Writes the current token. + + The to read the token from. + A flag indicating whether the current token's children should be written. + + + + Writes the token and its value. + + The to write. + + The value to write. + A value is only required for tokens that have an associated value, e.g. the property name for . + null can be passed to the method for tokens that don't have a value, e.g. . + + + + + Writes the token. + + The to write. + + + + Writes the specified end token. + + The end token to write. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON without changing the writer's state. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Sets the state of the . + + The being written. + The value being written. + + + + The exception thrown when an error occurs while writing JSON text. + + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Specifies how JSON comments are handled when loading JSON. + + + + + Ignore comments. + + + + + Load comments as a with type . + + + + + Specifies how duplicate property names are handled when loading JSON. + + + + + Replace the existing value when there is a duplicate property. The value of the last property in the JSON object will be used. + + + + + Ignore the new value when there is a duplicate property. The value of the first property in the JSON object will be used. + + + + + Throw a when a duplicate property is encountered. + + + + + Contains the LINQ to JSON extension methods. + + + + + Returns a collection of tokens that contains the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the descendants of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, and the descendants of every token in the source collection. + + + + Returns a collection of child properties of every object in the source collection. + + An of that contains the source collection. + An of that contains the properties of every object in the source collection. + + + + Returns a collection of child values of every object in the source collection with the given key. + + An of that contains the source collection. + The token key. + An of that contains the values of every token in the source collection with the given key. + + + + Returns a collection of child values of every object in the source collection. + + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child values of every object in the source collection with the given key. + + The type to convert the values to. + An of that contains the source collection. + The token key. + An that contains the converted values of every token in the source collection with the given key. + + + + Returns a collection of converted child values of every object in the source collection. + + The type to convert the values to. + An of that contains the source collection. + An that contains the converted values of every token in the source collection. + + + + Converts the value. + + The type to convert the value to. + A cast as a of . + A converted value. + + + + Converts the value. + + The source collection type. + The type to convert the value to. + A cast as a of . + A converted value. + + + + Returns a collection of child tokens of every array in the source collection. + + The source collection type. + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child tokens of every array in the source collection. + + An of that contains the source collection. + The type to convert the values to. + The source collection type. + An that contains the converted values of every token in the source collection. + + + + Returns the input typed as . + + An of that contains the source collection. + The input typed as . + + + + Returns the input typed as . + + The source collection type. + An of that contains the source collection. + The input typed as . + + + + Represents a collection of objects. + + The type of token. + + + + Gets the of with the specified key. + + + + + + Represents a JSON array. + + + + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Loads an from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads an from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the at the specified index. + + + + + + Determines the index of a specific item in the . + + The object to locate in the . + + The index of if found in the list; otherwise, -1. + + + + + Inserts an item to the at the specified index. + + The zero-based index at which should be inserted. + The object to insert into the . + + is not a valid index in the . + + + + + Removes the item at the specified index. + + The zero-based index of the item to remove. + + is not a valid index in the . + + + + + Returns an enumerator that iterates through the collection. + + + A of that can be used to iterate through the collection. + + + + + Adds an item to the . + + The object to add to the . + + + + Removes all items from the . + + + + + Determines whether the contains a specific value. + + The object to locate in the . + + true if is found in the ; otherwise, false. + + + + + Copies the elements of the to an array, starting at a particular array index. + + The array. + Index of the array. + + + + Gets a value indicating whether the is read-only. + + true if the is read-only; otherwise, false. + + + + Removes the first occurrence of a specific object from the . + + The object to remove from the . + + true if was successfully removed from the ; otherwise, false. This method also returns false if is not found in the original . + + + + + Represents a JSON constructor. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets or sets the name of this constructor. + + The constructor name. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name. + + The constructor name. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a token that can contain other tokens. + + + + + Occurs when the list changes or an item in the list changes. + + + + + Occurs before an item is added to the collection. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Raises the event. + + The instance containing the event data. + + + + Raises the event. + + The instance containing the event data. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Get the first child token of this token. + + + A containing the first child token of the . + + + + + Get the last child token of this token. + + + A containing the last child token of the . + + + + + Returns a collection of the child tokens of this token, in document order. + + + An of containing the child tokens of this , in document order. + + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + + A containing the child values of this , in document order. + + + + + Returns a collection of the descendant tokens for this token in document order. + + An of containing the descendant tokens of the . + + + + Returns a collection of the tokens that contain this token, and all descendant tokens of this token, in document order. + + An of containing this token, and all the descendant tokens of the . + + + + Adds the specified content as children of this . + + The content to be added. + + + + Adds the specified content as the first children of this . + + The content to be added. + + + + Creates a that can be used to add tokens to the . + + A that is ready to have content written to it. + + + + Replaces the child nodes of this token with the specified content. + + The content. + + + + Removes the child nodes from this token. + + + + + Merge the specified content into this . + + The content to be merged. + + + + Merge the specified content into this using . + + The content to be merged. + The used to merge the content. + + + + Gets the count of child JSON tokens. + + The count of child JSON tokens. + + + + Represents a collection of objects. + + The type of token. + + + + An empty collection of objects. + + + + + Initializes a new instance of the struct. + + The enumerable. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Gets the of with the specified key. + + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Returns a hash code for this instance. + + + A hash code for this instance, suitable for use in hashing algorithms and data structures like a hash table. + + + + + Represents a JSON object. + + + + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Occurs when a property value changes. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Gets the node type for this . + + The type. + + + + Gets an of of this object's properties. + + An of of this object's properties. + + + + Gets a with the specified name. + + The property name. + A with the specified name or null. + + + + Gets the with the specified name. + The exact name will be searched for first and if no matching property is found then + the will be used to match a property. + + The property name. + One of the enumeration values that specifies how the strings will be compared. + A matched with the specified name or null. + + + + Gets a of of this object's property values. + + A of of this object's property values. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the with the specified property name. + + + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified property name. + + Name of the property. + The with the specified property name. + + + + Gets the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + One of the enumeration values that specifies how the strings will be compared. + The with the specified property name. + + + + Tries to get the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + The value. + One of the enumeration values that specifies how the strings will be compared. + true if a value was successfully retrieved; otherwise, false. + + + + Adds the specified property name. + + Name of the property. + The value. + + + + Determines whether the JSON object has the specified property name. + + Name of the property. + true if the JSON object has the specified property name; otherwise, false. + + + + Removes the property with the specified name. + + Name of the property. + true if item was successfully removed; otherwise, false. + + + + Tries to get the with the specified property name. + + Name of the property. + The value. + true if a value was successfully retrieved; otherwise, false. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Raises the event with the provided arguments. + + Name of the property. + + + + Represents a JSON property. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the property name. + + The property name. + + + + Gets or sets the property value. + + The property value. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a view of a . + + + + + Initializes a new instance of the class. + + The name. + + + + When overridden in a derived class, returns whether resetting an object changes its value. + + + true if resetting the component changes its value; otherwise, false. + + The component to test for reset capability. + + + + When overridden in a derived class, gets the current value of the property on a component. + + + The value of a property for a given component. + + The component with the property for which to retrieve the value. + + + + When overridden in a derived class, resets the value for this property of the component to the default value. + + The component with the property value that is to be reset to the default value. + + + + When overridden in a derived class, sets the value of the component to a different value. + + The component with the property value that is to be set. + The new value. + + + + When overridden in a derived class, determines a value indicating whether the value of this property needs to be persisted. + + + true if the property should be persisted; otherwise, false. + + The component with the property to be examined for persistence. + + + + When overridden in a derived class, gets the type of the component this property is bound to. + + + A that represents the type of component this property is bound to. + When the or + + methods are invoked, the object specified might be an instance of this type. + + + + + When overridden in a derived class, gets a value indicating whether this property is read-only. + + + true if the property is read-only; otherwise, false. + + + + + When overridden in a derived class, gets the type of the property. + + + A that represents the type of the property. + + + + + Gets the hash code for the name of the member. + + + + The hash code for the name of the member. + + + + + Represents a raw JSON string. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class. + + The raw json. + + + + Creates an instance of with the content of the reader's current token. + + The reader. + An instance of with the content of the reader's current token. + + + + Specifies the settings used when loading JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets how JSON comments are handled when loading JSON. + The default value is . + + The JSON comment handling. + + + + Gets or sets how JSON line info is handled when loading JSON. + The default value is . + + The JSON line info handling. + + + + Gets or sets how duplicate property names in JSON objects are handled when loading JSON. + The default value is . + + The JSON duplicate property name handling. + + + + Specifies the settings used when merging JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets the method used when merging JSON arrays. + + The method used when merging JSON arrays. + + + + Gets or sets how null value properties are merged. + + How null value properties are merged. + + + + Gets or sets the comparison used to match property names while merging. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + The comparison used to match property names while merging. + + + + Specifies the settings used when selecting JSON. + + + + + Gets or sets a flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + A flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + + + Represents an abstract JSON token. + + + + + Gets a comparer that can compare two tokens for value equality. + + A that can compare two nodes for value equality. + + + + Gets or sets the parent. + + The parent. + + + + Gets the root of this . + + The root of this . + + + + Gets the node type for this . + + The type. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Compares the values of two tokens, including the values of all descendant tokens. + + The first to compare. + The second to compare. + true if the tokens are equal; otherwise false. + + + + Gets the next sibling token of this node. + + The that contains the next sibling token. + + + + Gets the previous sibling token of this node. + + The that contains the previous sibling token. + + + + Gets the path of the JSON token. + + + + + Adds the specified content immediately after this token. + + A content object that contains simple content or a collection of content objects to be added after this token. + + + + Adds the specified content immediately before this token. + + A content object that contains simple content or a collection of content objects to be added before this token. + + + + Returns a collection of the ancestor tokens of this token. + + A collection of the ancestor tokens of this token. + + + + Returns a collection of tokens that contain this token, and the ancestors of this token. + + A collection of tokens that contain this token, and the ancestors of this token. + + + + Returns a collection of the sibling tokens after this token, in document order. + + A collection of the sibling tokens after this tokens, in document order. + + + + Returns a collection of the sibling tokens before this token, in document order. + + A collection of the sibling tokens before this token, in document order. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets the with the specified key converted to the specified type. + + The type to convert the token to. + The token key. + The converted token value. + + + + Get the first child token of this token. + + A containing the first child token of the . + + + + Get the last child token of this token. + + A containing the last child token of the . + + + + Returns a collection of the child tokens of this token, in document order. + + An of containing the child tokens of this , in document order. + + + + Returns a collection of the child tokens of this token, in document order, filtered by the specified type. + + The type to filter the child tokens on. + A containing the child tokens of this , in document order. + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + A containing the child values of this , in document order. + + + + Removes this token from its parent. + + + + + Replaces this token with the specified token. + + The value. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Returns the indented JSON for this token. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + The indented JSON for this token. + + + + + Returns the JSON for this token using the given formatting and converters. + + Indicates how the output should be formatted. + A collection of s which will be used when writing the token. + The JSON for this token using the given formatting and converters. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to []. + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from [] to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Creates a for this token. + + A that can be used to read this token and its descendants. + + + + Creates a from an object. + + The object that will be used to create . + A with the value of the specified object. + + + + Creates a from an object using the specified . + + The object that will be used to create . + The that will be used when reading the object. + A with the value of the specified object. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + An positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + Creates a from a . + + A positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A , or null. + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + A . + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + The used to select tokens. + A . + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + The used to select tokens. + An of that contains the selected elements. + + + + Creates a new instance of the . All child tokens are recursively cloned. + + A new instance of the . + + + + Adds an object to the annotation list of this . + + The annotation to add. + + + + Get the first annotation object of the specified type from this . + + The type of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets the first annotation object of the specified type from this . + + The of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets a collection of annotations of the specified type for this . + + The type of the annotations to retrieve. + An that contains the annotations for this . + + + + Gets a collection of annotations of the specified type for this . + + The of the annotations to retrieve. + An of that contains the annotations that match the specified type for this . + + + + Removes the annotations of the specified type from this . + + The type of annotations to remove. + + + + Removes the annotations of the specified type from this . + + The of annotations to remove. + + + + Compares tokens to determine whether they are equal. + + + + + Determines whether the specified objects are equal. + + The first object of type to compare. + The second object of type to compare. + + true if the specified objects are equal; otherwise, false. + + + + + Returns a hash code for the specified object. + + The for which a hash code is to be returned. + A hash code for the specified object. + The type of is a reference type and is null. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Gets the at the reader's current position. + + + + + Initializes a new instance of the class. + + The token to read from. + + + + Initializes a new instance of the class. + + The token to read from. + The initial path of the token. It is prepended to the returned . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Gets the path of the current JSON token. + + + + + Specifies the type of token. + + + + + No token type has been set. + + + + + A JSON object. + + + + + A JSON array. + + + + + A JSON constructor. + + + + + A JSON object property. + + + + + A comment. + + + + + An integer value. + + + + + A float value. + + + + + A string value. + + + + + A boolean value. + + + + + A null value. + + + + + An undefined value. + + + + + A date value. + + + + + A raw JSON value. + + + + + A collection of bytes value. + + + + + A Guid value. + + + + + A Uri value. + + + + + A TimeSpan value. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets the at the writer's current position. + + + + + Gets the token being written. + + The token being written. + + + + Initializes a new instance of the class writing to the given . + + The container being written to. + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the underlying . + + + + + Closes this writer. + If is set to true, the JSON is auto-completed. + + + Setting to true has no additional effect, since the underlying is a type that cannot be closed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end. + + The token. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes a value. + An error will be raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Represents a value in JSON (string, integer, date, etc). + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Creates a comment with the given value. + + The value. + A comment with the given value. + + + + Creates a string with the given value. + + The value. + A string with the given value. + + + + Creates a null value. + + A null value. + + + + Creates a undefined value. + + A undefined value. + + + + Gets the node type for this . + + The type. + + + + Gets or sets the underlying token value. + + The underlying token value. + + + + Writes this token to a . + + A into which this method will write. + A collection of s which will be used when writing the token. + + + + Indicates whether the current object is equal to another object of the same type. + + + true if the current object is equal to the parameter; otherwise, false. + + An object to compare with this object. + + + + Determines whether the specified is equal to the current . + + The to compare with the current . + + true if the specified is equal to the current ; otherwise, false. + + + + + Serves as a hash function for a particular type. + + + A hash code for the current . + + + + + Returns a that represents this instance. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format provider. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + The format provider. + + A that represents this instance. + + + + + Compares the current instance with another object of the same type and returns an integer that indicates whether the current instance precedes, follows, or occurs in the same position in the sort order as the other object. + + An object to compare with this instance. + + A 32-bit signed integer that indicates the relative order of the objects being compared. The return value has these meanings: + Value + Meaning + Less than zero + This instance is less than . + Zero + This instance is equal to . + Greater than zero + This instance is greater than . + + + is not of the same type as this instance. + + + + + Specifies how line information is handled when loading JSON. + + + + + Ignore line information. + + + + + Load line information. + + + + + Specifies how JSON arrays are merged together. + + + + Concatenate arrays. + + + Union arrays, skipping items that already exist. + + + Replace all array items. + + + Merge array items together, matched by index. + + + + Specifies how null value properties are merged. + + + + + The content's null value properties will be ignored during merging. + + + + + The content's null value properties will be merged. + + + + + Specifies the member serialization options for the . + + + + + All public members are serialized by default. Members can be excluded using or . + This is the default member serialization mode. + + + + + Only members marked with or are serialized. + This member serialization mode can also be set by marking the class with . + + + + + All public and private fields are serialized. Members can be excluded using or . + This member serialization mode can also be set by marking the class with + and setting IgnoreSerializableAttribute on to false. + + + + + Specifies metadata property handling options for the . + + + + + Read metadata properties located at the start of a JSON object. + + + + + Read metadata properties located anywhere in a JSON object. Note that this setting will impact performance. + + + + + Do not try to read metadata properties. + + + + + Specifies missing member handling options for the . + + + + + Ignore a missing member and do not attempt to deserialize it. + + + + + Throw a when a missing member is encountered during deserialization. + + + + + Specifies null value handling options for the . + + + + + + + + + Include null values when serializing and deserializing objects. + + + + + Ignore null values when serializing and deserializing objects. + + + + + Specifies how object creation is handled by the . + + + + + Reuse existing objects, create new objects when needed. + + + + + Only reuse existing objects. + + + + + Always create new objects. + + + + + Specifies reference handling options for the . + Note that references cannot be preserved when a value is set via a non-default constructor such as types that implement . + + + + + + + + Do not preserve references when serializing types. + + + + + Preserve references when serializing into a JSON object structure. + + + + + Preserve references when serializing into a JSON array structure. + + + + + Preserve references when serializing. + + + + + Specifies reference loop handling options for the . + + + + + Throw a when a loop is encountered. + + + + + Ignore loop references and do not serialize. + + + + + Serialize loop references. + + + + + Indicating whether a property is required. + + + + + The property is not required. The default state. + + + + + The property must be defined in JSON but can be a null value. + + + + + The property must be defined in JSON and cannot be a null value. + + + + + The property is not required but it cannot be a null value. + + + + + + Contains the JSON schema extension methods. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + true if the specified is valid; otherwise, false. + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + When this method returns, contains any error messages generated while validating. + + true if the specified is valid; otherwise, false. + + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + The validation event handler. + + + + + An in-memory representation of a JSON Schema. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the id. + + + + + Gets or sets the title. + + + + + Gets or sets whether the object is required. + + + + + Gets or sets whether the object is read-only. + + + + + Gets or sets whether the object is visible to users. + + + + + Gets or sets whether the object is transient. + + + + + Gets or sets the description of the object. + + + + + Gets or sets the types of values allowed by the object. + + The type. + + + + Gets or sets the pattern. + + The pattern. + + + + Gets or sets the minimum length. + + The minimum length. + + + + Gets or sets the maximum length. + + The maximum length. + + + + Gets or sets a number that the value should be divisible by. + + A number that the value should be divisible by. + + + + Gets or sets the minimum. + + The minimum. + + + + Gets or sets the maximum. + + The maximum. + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the minimum attribute (). + + A flag indicating whether the value can not equal the number defined by the minimum attribute (). + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the maximum attribute (). + + A flag indicating whether the value can not equal the number defined by the maximum attribute (). + + + + Gets or sets the minimum number of items. + + The minimum number of items. + + + + Gets or sets the maximum number of items. + + The maximum number of items. + + + + Gets or sets the of items. + + The of items. + + + + Gets or sets a value indicating whether items in an array are validated using the instance at their array position from . + + + true if items are validated using their array position; otherwise, false. + + + + + Gets or sets the of additional items. + + The of additional items. + + + + Gets or sets a value indicating whether additional items are allowed. + + + true if additional items are allowed; otherwise, false. + + + + + Gets or sets whether the array items must be unique. + + + + + Gets or sets the of properties. + + The of properties. + + + + Gets or sets the of additional properties. + + The of additional properties. + + + + Gets or sets the pattern properties. + + The pattern properties. + + + + Gets or sets a value indicating whether additional properties are allowed. + + + true if additional properties are allowed; otherwise, false. + + + + + Gets or sets the required property if this property is present. + + The required property if this property is present. + + + + Gets or sets the a collection of valid enum values allowed. + + A collection of valid enum values allowed. + + + + Gets or sets disallowed types. + + The disallowed types. + + + + Gets or sets the default value. + + The default value. + + + + Gets or sets the collection of that this schema extends. + + The collection of that this schema extends. + + + + Gets or sets the format. + + The format. + + + + Initializes a new instance of the class. + + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The object representing the JSON Schema. + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The to use when resolving schema references. + The object representing the JSON Schema. + + + + Load a from a string that contains JSON Schema. + + A that contains JSON Schema. + A populated from the string that contains JSON Schema. + + + + Load a from a string that contains JSON Schema using the specified . + + A that contains JSON Schema. + The resolver. + A populated from the string that contains JSON Schema. + + + + Writes this schema to a . + + A into which this method will write. + + + + Writes this schema to a using the specified . + + A into which this method will write. + The resolver used. + + + + Returns a that represents the current . + + + A that represents the current . + + + + + + Returns detailed information about the schema exception. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + + Generates a from a specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets how undefined schemas are handled by the serializer. + + + + + Gets or sets the contract resolver. + + The contract resolver. + + + + Generate a from the specified type. + + The type to generate a from. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + + Resolves from an id. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the loaded schemas. + + The loaded schemas. + + + + Initializes a new instance of the class. + + + + + Gets a for the specified reference. + + The id. + A for the specified reference. + + + + + The value types allowed by the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + No type specified. + + + + + String type. + + + + + Float type. + + + + + Integer type. + + + + + Boolean type. + + + + + Object type. + + + + + Array type. + + + + + Null type. + + + + + Any type. + + + + + + Specifies undefined schema Id handling options for the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Do not infer a schema Id. + + + + + Use the .NET type name as the schema Id. + + + + + Use the assembly qualified .NET type name as the schema Id. + + + + + + Returns detailed information related to the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the associated with the validation error. + + The JsonSchemaException associated with the validation error. + + + + Gets the path of the JSON location where the validation error occurred. + + The path of the JSON location where the validation error occurred. + + + + Gets the text description corresponding to the validation error. + + The text description. + + + + + Represents the callback method that will handle JSON schema validation events and the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + A camel case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Resolves member mappings for a type, camel casing property names. + + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used by to resolve a for a given . + + + + + Gets a value indicating whether members are being get and set using dynamic code generation. + This value is determined by the runtime permissions available. + + + true if using dynamic code generation; otherwise, false. + + + + + Gets or sets the default members search flags. + + The default members search flags. + + + + Gets or sets a value indicating whether compiler generated members should be serialized. + + + true if serialized compiler generated members; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore the interface when serializing and deserializing types. + + + true if the interface will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore the attribute when serializing and deserializing types. + + + true if the attribute will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore IsSpecified members when serializing and deserializing types. + + + true if the IsSpecified members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore ShouldSerialize members when serializing and deserializing types. + + + true if the ShouldSerialize members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets the naming strategy used to resolve how property names and dictionary keys are serialized. + + The naming strategy used to resolve how property names and dictionary keys are serialized. + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Gets the serializable members for the type. + + The type to get serializable members for. + The serializable members for the type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates the constructor parameters. + + The constructor to create properties for. + The type's member properties. + Properties for the given . + + + + Creates a for the given . + + The matching member property. + The constructor parameter. + A created for the given . + + + + Resolves the default for the contract. + + Type of the object. + The contract's default . + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Determines which contract type is created for the given type. + + Type of the object. + A for the given type. + + + + Creates properties for the given . + + The type to create properties for. + /// The member serialization mode for the type. + Properties for the given . + + + + Creates the used by the serializer to get and set values from a member. + + The member. + The used by the serializer to get and set values from a member. + + + + Creates a for the given . + + The member's parent . + The member to create a for. + A created for the given . + + + + Resolves the name of the property. + + Name of the property. + Resolved name of the property. + + + + Resolves the name of the extension data. By default no changes are made to extension data names. + + Name of the extension data. + Resolved name of the extension data. + + + + Resolves the key of the dictionary. By default is used to resolve dictionary keys. + + Key of the dictionary. + Resolved key of the dictionary. + + + + Gets the resolved name of the property. + + Name of the property. + Name of the property. + + + + The default naming strategy. Property names and dictionary keys are unchanged. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + The default serialization binder used when resolving and loading classes from type names. + + + + + Initializes a new instance of the class. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + The type of the object the formatter creates a new instance of. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Represents a trace writer that writes to the application's instances. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + + The that will be used to filter the trace messages passed to the writer. + + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Get and set values for a using dynamic methods. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Provides information surrounding an error. + + + + + Gets the error. + + The error. + + + + Gets the original object that caused the error. + + The original object that caused the error. + + + + Gets the member that caused the error. + + The member that caused the error. + + + + Gets the path of the JSON location where the error occurred. + + The path of the JSON location where the error occurred. + + + + Gets or sets a value indicating whether this is handled. + + true if handled; otherwise, false. + + + + Provides data for the Error event. + + + + + Gets the current object the error event is being raised against. + + The current object the error event is being raised against. + + + + Gets the error context. + + The error context. + + + + Initializes a new instance of the class. + + The current object. + The error context. + + + + Provides methods to get attributes. + + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Used by to resolve a for a given . + + + + + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used to resolve references when serializing and deserializing JSON by the . + + + + + Resolves a reference to its object. + + The serialization context. + The reference to resolve. + The object that was resolved from the reference. + + + + Gets the reference for the specified object. + + The serialization context. + The object to get a reference for. + The reference to the object. + + + + Determines whether the specified object is referenced. + + The serialization context. + The object to test for a reference. + + true if the specified object is referenced; otherwise, false. + + + + + Adds a reference to the specified object. + + The serialization context. + The reference. + The object to reference. + + + + Allows users to control class loading and mandate what class to load. + + + + + When implemented, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object + The type of the object the formatter creates a new instance of. + + + + When implemented, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Represents a trace writer. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + The that will be used to filter the trace messages passed to the writer. + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Provides methods to get and set values. + + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Contract details for a used by the . + + + + + Gets the of the collection items. + + The of the collection items. + + + + Gets a value indicating whether the collection type is a multidimensional array. + + true if the collection type is a multidimensional array; otherwise, false. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the collection values. + + true if the creator has a parameter with the collection values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the default collection items . + + The converter. + + + + Gets or sets a value indicating whether the collection items preserve object references. + + true if collection items preserve object references; otherwise, false. + + + + Gets or sets the collection item reference loop handling. + + The reference loop handling. + + + + Gets or sets the collection item type name handling. + + The type name handling. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Handles serialization callback events. + + The object that raised the callback event. + The streaming context. + + + + Handles serialization error callback events. + + The object that raised the callback event. + The streaming context. + The error context. + + + + Sets extension data for an object during deserialization. + + The object to set extension data on. + The extension data key. + The extension data value. + + + + Gets extension data for an object during serialization. + + The object to set extension data on. + + + + Contract details for a used by the . + + + + + Gets the underlying type for the contract. + + The underlying type for the contract. + + + + Gets or sets the type created during deserialization. + + The type created during deserialization. + + + + Gets or sets whether this type contract is serialized as a reference. + + Whether this type contract is serialized as a reference. + + + + Gets or sets the default for this contract. + + The converter. + + + + Gets the internally resolved for the contract's type. + This converter is used as a fallback converter when no other converter is resolved. + Setting will always override this converter. + + + + + Gets or sets all methods called immediately after deserialization of the object. + + The methods called immediately after deserialization of the object. + + + + Gets or sets all methods called during deserialization of the object. + + The methods called during deserialization of the object. + + + + Gets or sets all methods called after serialization of the object graph. + + The methods called after serialization of the object graph. + + + + Gets or sets all methods called before serialization of the object. + + The methods called before serialization of the object. + + + + Gets or sets all method called when an error is thrown during the serialization of the object. + + The methods called when an error is thrown during the serialization of the object. + + + + Gets or sets the default creator method used to create the object. + + The default creator method used to create the object. + + + + Gets or sets a value indicating whether the default creator is non-public. + + true if the default object creator is non-public; otherwise, false. + + + + Contract details for a used by the . + + + + + Gets or sets the dictionary key resolver. + + The dictionary key resolver. + + + + Gets the of the dictionary keys. + + The of the dictionary keys. + + + + Gets the of the dictionary values. + + The of the dictionary values. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the dictionary values. + + true if the creator has a parameter with the dictionary values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object constructor. + + The object constructor. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object member serialization. + + The member object serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets the object's properties. + + The object's properties. + + + + Gets a collection of instances that define the parameters used with . + + + + + Gets or sets the function used to create the object. When set this function will override . + This function is called with a collection of arguments which are defined by the collection. + + The function used to create the object. + + + + Gets or sets the extension data setter. + + + + + Gets or sets the extension data getter. + + + + + Gets or sets the extension data value type. + + + + + Gets or sets the extension data name resolver. + + The extension data name resolver. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Maps a JSON property to a .NET member or constructor parameter. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the type that declared this property. + + The type that declared this property. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets the name of the underlying member or parameter. + + The name of the underlying member or parameter. + + + + Gets the that will get and set the during serialization. + + The that will get and set the during serialization. + + + + Gets or sets the for this property. + + The for this property. + + + + Gets or sets the type of the property. + + The type of the property. + + + + Gets or sets the for the property. + If set this converter takes precedence over the contract converter for the property type. + + The converter. + + + + Gets or sets the member converter. + + The member converter. + + + + Gets or sets a value indicating whether this is ignored. + + true if ignored; otherwise, false. + + + + Gets or sets a value indicating whether this is readable. + + true if readable; otherwise, false. + + + + Gets or sets a value indicating whether this is writable. + + true if writable; otherwise, false. + + + + Gets or sets a value indicating whether this has a member attribute. + + true if has a member attribute; otherwise, false. + + + + Gets the default value. + + The default value. + + + + Gets or sets a value indicating whether this is required. + + A value indicating whether this is required. + + + + Gets a value indicating whether has a value specified. + + + + + Gets or sets a value indicating whether this property preserves object references. + + + true if this instance is reference; otherwise, false. + + + + + Gets or sets the property null value handling. + + The null value handling. + + + + Gets or sets the property default value handling. + + The default value handling. + + + + Gets or sets the property reference loop handling. + + The reference loop handling. + + + + Gets or sets the property object creation handling. + + The object creation handling. + + + + Gets or sets or sets the type name handling. + + The type name handling. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets a predicate used to determine whether the property should be deserialized. + + A predicate used to determine whether the property should be deserialized. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets an action used to set whether the property has been deserialized. + + An action used to set whether the property has been deserialized. + + + + Returns a that represents this instance. + + + A that represents this instance. + + + + + Gets or sets the converter used when serializing the property's collection items. + + The collection's items converter. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + A collection of objects. + + + + + Initializes a new instance of the class. + + The type. + + + + When implemented in a derived class, extracts the key from the specified element. + + The element from which to extract the key. + The key for the specified element. + + + + Adds a object. + + The property to add to the collection. + + + + Gets the closest matching object. + First attempts to get an exact case match of and then + a case insensitive match. + + Name of the property. + A matching property if found. + + + + Gets a property by property name. + + The name of the property to get. + Type property name string comparison. + A matching property if found. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Lookup and create an instance of the type described by the argument. + + The type to create. + Optional arguments to pass to an initializing constructor of the JsonConverter. + If null, the default constructor is used. + + + + A kebab case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Represents a trace writer that writes to memory. When the trace message limit is + reached then old trace messages will be removed as new messages are added. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + + The that will be used to filter the trace messages passed to the writer. + + + + + Initializes a new instance of the class. + + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Returns an enumeration of the most recent trace messages. + + An enumeration of the most recent trace messages. + + + + Returns a of the most recent trace messages. + + + A of the most recent trace messages. + + + + + A base class for resolving how property names and dictionary keys are serialized. + + + + + A flag indicating whether dictionary keys should be processed. + Defaults to false. + + + + + A flag indicating whether extension data names should be processed. + Defaults to false. + + + + + A flag indicating whether explicitly specified property names, + e.g. a property name customized with a , should be processed. + Defaults to false. + + + + + Gets the serialized name for a given property name. + + The initial property name. + A flag indicating whether the property has had a name explicitly specified. + The serialized property name. + + + + Gets the serialized name for a given extension data name. + + The initial extension data name. + The serialized extension data name. + + + + Gets the serialized key for a given dictionary key. + + The initial dictionary key. + The serialized dictionary key. + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Hash code calculation + + + + + + Object equality implementation + + + + + + + Compare to another NamingStrategy + + + + + + + Represents a method that constructs an object. + + The object type to create. + + + + When applied to a method, specifies that the method is called when an error occurs serializing an object. + + + + + Provides methods to get attributes from a , , or . + + + + + Initializes a new instance of the class. + + The instance to get attributes for. This parameter should be a , , or . + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Get and set values for a using reflection. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + A snake case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Specifies how strings are escaped when writing JSON text. + + + + + Only control characters (e.g. newline) are escaped. + + + + + All non-ASCII and control characters (e.g. newline) are escaped. + + + + + HTML (<, >, &, ', ") and control characters (e.g. newline) are escaped. + + + + + Indicates the method that will be used during deserialization for locating and loading assemblies. + + + + + In simple mode, the assembly used during deserialization need not match exactly the assembly used during serialization. Specifically, the version numbers need not match as the LoadWithPartialName method of the class is used to load the assembly. + + + + + In full mode, the assembly used during deserialization must match exactly the assembly used during serialization. The Load method of the class is used to load the assembly. + + + + + Specifies type name handling options for the . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Do not include the .NET type name when serializing types. + + + + + Include the .NET type name when serializing into a JSON object structure. + + + + + Include the .NET type name when serializing into a JSON array structure. + + + + + Always include the .NET type name when serializing. + + + + + Include the .NET type name when the type of the object being serialized is not the same as its declared type. + Note that this doesn't include the root serialized object by default. To include the root object's type name in JSON + you must specify a root type object with + or . + + + + + Determines whether the collection is null or empty. + + The collection. + + true if the collection is null or empty; otherwise, false. + + + + + Adds the elements of the specified collection to the specified generic . + + The list to add to. + The collection of elements to add. + + + + Converts the value to the specified type. If the value is unable to be converted, the + value is checked whether it assignable to the specified type. + + The value to convert. + The culture to use when converting. + The type to convert or cast the value to. + + The converted type. If conversion was unsuccessful, the initial value + is returned if assignable to the target type. + + + + + Helper class for serializing immutable collections. + Note that this is used by all builds, even those that don't support immutable collections, in case the DLL is GACed + https://github.com/JamesNK/Newtonsoft.Json/issues/652 + + + + + Provides a set of static (Shared in Visual Basic) methods for + querying objects that implement . + + + + + Returns the input typed as . + + + + + Returns an empty that has the + specified type argument. + + + + + Converts the elements of an to the + specified type. + + + + + Filters the elements of an based on a specified type. + + + + + Generates a sequence of integral numbers within a specified range. + + The value of the first integer in the sequence. + The number of sequential integers to generate. + + + + Generates a sequence that contains one repeated value. + + + + + Filters a sequence of values based on a predicate. + + + + + Filters a sequence of values based on a predicate. + Each element's index is used in the logic of the predicate function. + + + + + Projects each element of a sequence into a new form. + + + + + Projects each element of a sequence into a new form by + incorporating the element's index. + + + + + Projects each element of a sequence to an + and flattens the resulting sequences into one sequence. + + + + + Projects each element of a sequence to an , + and flattens the resulting sequences into one sequence. The + index of each source element is used in the projected form of + that element. + + + + + Projects each element of a sequence to an , + flattens the resulting sequences into one sequence, and invokes + a result selector function on each element therein. + + + + + Projects each element of a sequence to an , + flattens the resulting sequences into one sequence, and invokes + a result selector function on each element therein. The index of + each source element is used in the intermediate projected form + of that element. + + + + + Returns elements from a sequence as long as a specified condition is true. + + + + + Returns elements from a sequence as long as a specified condition is true. + The element's index is used in the logic of the predicate function. + + + + + Base implementation of First operator. + + + + + Returns the first element of a sequence. + + + + + Returns the first element in a sequence that satisfies a specified condition. + + + + + Returns the first element of a sequence, or a default value if + the sequence contains no elements. + + + + + Returns the first element of the sequence that satisfies a + condition or a default value if no such element is found. + + + + + Base implementation of Last operator. + + + + + Returns the last element of a sequence. + + + + + Returns the last element of a sequence that satisfies a + specified condition. + + + + + Returns the last element of a sequence, or a default value if + the sequence contains no elements. + + + + + Returns the last element of a sequence that satisfies a + condition or a default value if no such element is found. + + + + + Base implementation of Single operator. + + + + + Returns the only element of a sequence, and throws an exception + if there is not exactly one element in the sequence. + + + + + Returns the only element of a sequence that satisfies a + specified condition, and throws an exception if more than one + such element exists. + + + + + Returns the only element of a sequence, or a default value if + the sequence is empty; this method throws an exception if there + is more than one element in the sequence. + + + + + Returns the only element of a sequence that satisfies a + specified condition or a default value if no such element + exists; this method throws an exception if more than one element + satisfies the condition. + + + + + Returns the element at a specified index in a sequence. + + + + + Returns the element at a specified index in a sequence or a + default value if the index is out of range. + + + + + Inverts the order of the elements in a sequence. + + + + + Returns a specified number of contiguous elements from the start + of a sequence. + + + + + Bypasses a specified number of elements in a sequence and then + returns the remaining elements. + + + + + Bypasses elements in a sequence as long as a specified condition + is true and then returns the remaining elements. + + + + + Bypasses elements in a sequence as long as a specified condition + is true and then returns the remaining elements. The element's + index is used in the logic of the predicate function. + + + + + Returns the number of elements in a sequence. + + + + + Returns a number that represents how many elements in the + specified sequence satisfy a condition. + + + + + Returns a that represents the total number + of elements in a sequence. + + + + + Returns a that represents how many elements + in a sequence satisfy a condition. + + + + + Concatenates two sequences. + + + + + Creates a from an . + + + + + Creates an array from an . + + + + + Returns distinct elements from a sequence by using the default + equality comparer to compare values. + + + + + Returns distinct elements from a sequence by using a specified + to compare values. + + + + + Creates a from an + according to a specified key + selector function. + + + + + Creates a from an + according to a specified key + selector function and a key comparer. + + + + + Creates a from an + according to specified key + and element selector functions. + + + + + Creates a from an + according to a specified key + selector function, a comparer and an element selector function. + + + + + Groups the elements of a sequence according to a specified key + selector function. + + + + + Groups the elements of a sequence according to a specified key + selector function and compares the keys by using a specified + comparer. + + + + + Groups the elements of a sequence according to a specified key + selector function and projects the elements for each group by + using a specified function. + + + + + Groups the elements of a sequence according to a specified key + selector function and creates a result value from each group and + its key. + + + + + Groups the elements of a sequence according to a key selector + function. The keys are compared by using a comparer and each + group's elements are projected by using a specified function. + + + + + Groups the elements of a sequence according to a specified key + selector function and creates a result value from each group and + its key. The elements of each group are projected by using a + specified function. + + + + + Groups the elements of a sequence according to a specified key + selector function and creates a result value from each group and + its key. The keys are compared by using a specified comparer. + + + + + Groups the elements of a sequence according to a specified key + selector function and creates a result value from each group and + its key. Key values are compared by using a specified comparer, + and the elements of each group are projected by using a + specified function. + + + + + Applies an accumulator function over a sequence. + + + + + Applies an accumulator function over a sequence. The specified + seed value is used as the initial accumulator value. + + + + + Applies an accumulator function over a sequence. The specified + seed value is used as the initial accumulator value, and the + specified function is used to select the result value. + + + + + Produces the set union of two sequences by using the default + equality comparer. + + + + + Produces the set union of two sequences by using a specified + . + + + + + Returns the elements of the specified sequence or the type + parameter's default value in a singleton collection if the + sequence is empty. + + + + + Returns the elements of the specified sequence or the specified + value in a singleton collection if the sequence is empty. + + + + + Determines whether all elements of a sequence satisfy a condition. + + + + + Determines whether a sequence contains any elements. + + + + + Determines whether any element of a sequence satisfies a + condition. + + + + + Determines whether a sequence contains a specified element by + using the default equality comparer. + + + + + Determines whether a sequence contains a specified element by + using a specified . + + + + + Determines whether two sequences are equal by comparing the + elements by using the default equality comparer for their type. + + + + + Determines whether two sequences are equal by comparing their + elements by using a specified . + + + + + Base implementation for Min/Max operator. + + + + + Base implementation for Min/Max operator for nullable types. + + + + + Returns the minimum value in a generic sequence. + + + + + Invokes a transform function on each element of a generic + sequence and returns the minimum resulting value. + + + + + Returns the maximum value in a generic sequence. + + + + + Invokes a transform function on each element of a generic + sequence and returns the maximum resulting value. + + + + + Makes an enumerator seen as enumerable once more. + + + The supplied enumerator must have been started. The first element + returned is the element the enumerator was on when passed in. + DO NOT use this method if the caller must be a generator. It is + mostly safe among aggregate operations. + + + + + Sorts the elements of a sequence in ascending order according to a key. + + + + + Sorts the elements of a sequence in ascending order by using a + specified comparer. + + + + + Sorts the elements of a sequence in descending order according to a key. + + + + + Sorts the elements of a sequence in descending order by using a + specified comparer. + + + + + Performs a subsequent ordering of the elements in a sequence in + ascending order according to a key. + + + + + Performs a subsequent ordering of the elements in a sequence in + ascending order by using a specified comparer. + + + + + Performs a subsequent ordering of the elements in a sequence in + descending order, according to a key. + + + + + Performs a subsequent ordering of the elements in a sequence in + descending order by using a specified comparer. + + + + + Base implementation for Intersect and Except operators. + + + + + Produces the set intersection of two sequences by using the + default equality comparer to compare values. + + + + + Produces the set intersection of two sequences by using the + specified to compare values. + + + + + Produces the set difference of two sequences by using the + default equality comparer to compare values. + + + + + Produces the set difference of two sequences by using the + specified to compare values. + + + + + Creates a from an + according to a specified key + selector function. + + + + + Creates a from an + according to a specified key + selector function and key comparer. + + + + + Creates a from an + according to specified key + selector and element selector functions. + + + + + Creates a from an + according to a specified key + selector function, a comparer, and an element selector function. + + + + + Correlates the elements of two sequences based on matching keys. + The default equality comparer is used to compare keys. + + + + + Correlates the elements of two sequences based on matching keys. + The default equality comparer is used to compare keys. A + specified is used to compare keys. + + + + + Correlates the elements of two sequences based on equality of + keys and groups the results. The default equality comparer is + used to compare keys. + + + + + Correlates the elements of two sequences based on equality of + keys and groups the results. The default equality comparer is + used to compare keys. A specified + is used to compare keys. + + + + + Computes the sum of a sequence of values. + + + + + Computes the sum of a sequence of + values that are obtained by invoking a transform function on + each element of the input sequence. + + + + + Computes the average of a sequence of values. + + + + + Computes the average of a sequence of values + that are obtained by invoking a transform function on each + element of the input sequence. + + + + + Computes the sum of a sequence of nullable values. + + + + + Computes the sum of a sequence of nullable + values that are obtained by invoking a transform function on + each element of the input sequence. + + + + + Computes the average of a sequence of nullable values. + + + + + Computes the average of a sequence of nullable values + that are obtained by invoking a transform function on each + element of the input sequence. + + + + + Returns the minimum value in a sequence of nullable + values. + + + + + Invokes a transform function on each element of a sequence and + returns the minimum nullable value. + + + + + Returns the maximum value in a sequence of nullable + values. + + + + + Invokes a transform function on each element of a sequence and + returns the maximum nullable value. + + + + + Computes the sum of a sequence of values. + + + + + Computes the sum of a sequence of + values that are obtained by invoking a transform function on + each element of the input sequence. + + + + + Computes the average of a sequence of values. + + + + + Computes the average of a sequence of values + that are obtained by invoking a transform function on each + element of the input sequence. + + + + + Computes the sum of a sequence of nullable values. + + + + + Computes the sum of a sequence of nullable + values that are obtained by invoking a transform function on + each element of the input sequence. + + + + + Computes the average of a sequence of nullable values. + + + + + Computes the average of a sequence of nullable values + that are obtained by invoking a transform function on each + element of the input sequence. + + + + + Returns the minimum value in a sequence of nullable + values. + + + + + Invokes a transform function on each element of a sequence and + returns the minimum nullable value. + + + + + Returns the maximum value in a sequence of nullable + values. + + + + + Invokes a transform function on each element of a sequence and + returns the maximum nullable value. + + + + + Computes the sum of a sequence of nullable values. + + + + + Computes the sum of a sequence of + values that are obtained by invoking a transform function on + each element of the input sequence. + + + + + Computes the average of a sequence of values. + + + + + Computes the average of a sequence of values + that are obtained by invoking a transform function on each + element of the input sequence. + + + + + Computes the sum of a sequence of nullable values. + + + + + Computes the sum of a sequence of nullable + values that are obtained by invoking a transform function on + each element of the input sequence. + + + + + Computes the average of a sequence of nullable values. + + + + + Computes the average of a sequence of nullable values + that are obtained by invoking a transform function on each + element of the input sequence. + + + + + Returns the minimum value in a sequence of nullable + values. + + + + + Invokes a transform function on each element of a sequence and + returns the minimum nullable value. + + + + + Returns the maximum value in a sequence of nullable + values. + + + + + Invokes a transform function on each element of a sequence and + returns the maximum nullable value. + + + + + Computes the sum of a sequence of values. + + + + + Computes the sum of a sequence of + values that are obtained by invoking a transform function on + each element of the input sequence. + + + + + Computes the average of a sequence of values. + + + + + Computes the average of a sequence of values + that are obtained by invoking a transform function on each + element of the input sequence. + + + + + Computes the sum of a sequence of nullable values. + + + + + Computes the sum of a sequence of nullable + values that are obtained by invoking a transform function on + each element of the input sequence. + + + + + Computes the average of a sequence of nullable values. + + + + + Computes the average of a sequence of nullable values + that are obtained by invoking a transform function on each + element of the input sequence. + + + + + Returns the minimum value in a sequence of nullable + values. + + + + + Invokes a transform function on each element of a sequence and + returns the minimum nullable value. + + + + + Returns the maximum value in a sequence of nullable + values. + + + + + Invokes a transform function on each element of a sequence and + returns the maximum nullable value. + + + + + Computes the sum of a sequence of values. + + + + + Computes the sum of a sequence of + values that are obtained by invoking a transform function on + each element of the input sequence. + + + + + Computes the average of a sequence of values. + + + + + Computes the average of a sequence of values + that are obtained by invoking a transform function on each + element of the input sequence. + + + + + Computes the sum of a sequence of nullable values. + + + + + Computes the sum of a sequence of nullable + values that are obtained by invoking a transform function on + each element of the input sequence. + + + + + Computes the average of a sequence of nullable values. + + + + + Computes the average of a sequence of nullable values + that are obtained by invoking a transform function on each + element of the input sequence. + + + + + Returns the minimum value in a sequence of nullable + values. + + + + + Invokes a transform function on each element of a sequence and + returns the minimum nullable value. + + + + + Returns the maximum value in a sequence of nullable + values. + + + + + Invokes a transform function on each element of a sequence and + returns the maximum nullable value. + + + + + Represents a collection of objects that have a common key. + + + + + Gets the key of the . + + + + + Defines an indexer, size property, and Boolean search method for + data structures that map keys to + sequences of values. + + + + + Represents a sorted sequence. + + + + + Performs a subsequent ordering on the elements of an + according to a key. + + + + + Represents a collection of keys each mapped to one or more values. + + + + + Gets the number of key/value collection pairs in the . + + + + + Gets the collection of values indexed by the specified key. + + + + + Determines whether a specified key is in the . + + + + + Applies a transform function to each key and its associated + values and returns the results. + + + + + Returns a generic enumerator that iterates through the . + + + + + See issue #11 + for why this method is needed and cannot be expressed as a + lambda at the call site. + + + + + See issue #11 + for why this method is needed and cannot be expressed as a + lambda at the call site. + + + + + Gets the type of the typed collection's items. + + The type. + The type of the typed collection's items. + + + + Gets the member's underlying type. + + The member. + The underlying type of the member. + + + + Determines whether the property is an indexed property. + + The property. + + true if the property is an indexed property; otherwise, false. + + + + + Gets the member's value on the object. + + The member. + The target object. + The member's value on the object. + + + + Sets the member's value on the target object. + + The member. + The target. + The value. + + + + Determines whether the specified MemberInfo can be read. + + The MemberInfo to determine whether can be read. + /// if set to true then allow the member to be gotten non-publicly. + + true if the specified MemberInfo can be read; otherwise, false. + + + + + Determines whether the specified MemberInfo can be set. + + The MemberInfo to determine whether can be set. + if set to true then allow the member to be set non-publicly. + if set to true then allow the member to be set if read-only. + + true if the specified MemberInfo can be set; otherwise, false. + + + + + Builds a string. Unlike this class lets you reuse its internal buffer. + + + + + Determines whether the string is all white space. Empty string will return false. + + The string to test whether it is all white space. + + true if the string is all white space; otherwise, false. + + + + + Specifies the state of the . + + + + + An exception has been thrown, which has left the in an invalid state. + You may call the method to put the in the Closed state. + Any other method calls result in an being thrown. + + + + + The method has been called. + + + + + An object is being written. + + + + + An array is being written. + + + + + A constructor is being written. + + + + + A property is being written. + + + + + A write method has not been called. + + + + + This attribute allows us to define extension methods without + requiring .NET Framework 3.5. For more information, see the section, + Extension Methods in .NET Framework 2.0 Apps, + of Basic Instincts: Extension Methods + column in MSDN Magazine, + issue Nov 2007. + + + + Specifies that an output will not be null even if the corresponding type allows it. + + + Specifies that when a method returns , the parameter will not be null even if the corresponding type allows it. + + + Initializes the attribute with the specified return value condition. + + The return value condition. If the method returns this value, the associated parameter will not be null. + + + + Gets the return value condition. + + + Specifies that an output may be null even if the corresponding type disallows it. + + + Specifies that null is allowed as an input even if the corresponding type disallows it. + + + + Specifies that the method will not return if the associated Boolean parameter is passed the specified value. + + + + + Initializes a new instance of the class. + + + The condition parameter value. Code after the method will be considered unreachable by diagnostics if the argument to + the associated parameter matches this value. + + + + Gets the condition parameter value. + + + diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/net35/Newtonsoft.Json.dll b/Packages/Newtonsoft.Json.13.0.1/lib/net35/Newtonsoft.Json.dll new file mode 100644 index 0000000..fce555f Binary files /dev/null and b/Packages/Newtonsoft.Json.13.0.1/lib/net35/Newtonsoft.Json.dll differ diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/net35/Newtonsoft.Json.xml b/Packages/Newtonsoft.Json.13.0.1/lib/net35/Newtonsoft.Json.xml new file mode 100644 index 0000000..2da5ea0 --- /dev/null +++ b/Packages/Newtonsoft.Json.13.0.1/lib/net35/Newtonsoft.Json.xml @@ -0,0 +1,9483 @@ + + + + Newtonsoft.Json + + + + + Represents a BSON Oid (object id). + + + + + Gets or sets the value of the Oid. + + The value of the Oid. + + + + Initializes a new instance of the class. + + The Oid value. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized BSON data. + + + + + Gets or sets a value indicating whether binary data reading should be compatible with incorrect Json.NET 3.5 written binary. + + + true if binary data reading will be compatible with incorrect Json.NET 3.5 written binary; otherwise, false. + + + + + Gets or sets a value indicating whether the root object will be read as a JSON array. + + + true if the root object will be read as a JSON array; otherwise, false. + + + + + Gets or sets the used when reading values from BSON. + + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating BSON data. + + + + + Gets or sets the used when writing values to BSON. + When set to no conversion will occur. + + The used when writing values to BSON. + + + + Initializes a new instance of the class. + + The to write to. + + + + Initializes a new instance of the class. + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying stream. + + + + + Writes the end. + + The token. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes the beginning of a JSON array. + + + + + Writes the beginning of a JSON object. + + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value that represents a BSON object id. + + The Object ID value to write. + + + + Writes a BSON regex. + + The regex pattern. + The regex options. + + + + Specifies how constructors are used when initializing objects during deserialization by the . + + + + + First attempt to use the public default constructor, then fall back to a single parameterized constructor, then to the non-public default constructor. + + + + + Json.NET will use a non-public default constructor before falling back to a parameterized constructor. + + + + + Converts a binary value to and from a base 64 string value. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Creates a custom object. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Creates an object which will then be populated by the serializer. + + Type of the object. + The created object. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can write JSON. + + + true if this can write JSON; otherwise, false. + + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Provides a base class for converting a to and from JSON. + + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an Entity Framework to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from the ISO 8601 date format (e.g. "2008-04-12T12:53Z"). + + + + + Gets or sets the date time styles used when converting a date to and from JSON. + + The date time styles used when converting a date to and from JSON. + + + + Gets or sets the date time format used when converting a date to and from JSON. + + The date time format used when converting a date to and from JSON. + + + + Gets or sets the culture used when converting a date to and from JSON. + + The culture used when converting a date to and from JSON. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Converts a to and from a JavaScript Date constructor (e.g. new Date(52231943)). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an to and from its name string value. + + + + + Gets or sets a value indicating whether the written enum text should be camel case. + The default value is false. + + true if the written enum text will be camel case; otherwise, false. + + + + Gets or sets the naming strategy used to resolve how enum text is written. + + The naming strategy used to resolve how enum text is written. + + + + Gets or sets a value indicating whether integer values are allowed when serializing and deserializing. + The default value is true. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class. + + true if the written enum text will be camel case; otherwise, false. + + + + Initializes a new instance of the class. + + The naming strategy used to resolve how enum text is written. + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from Unix epoch time + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from a string (e.g. "1.2.3.4"). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts XML to and from JSON. + + + + + Gets or sets the name of the root element to insert when deserializing to XML if the JSON structure has produced multiple root elements. + + The name of the deserialized root element. + + + + Gets or sets a value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + true if the array attribute is written to the XML; otherwise, false. + + + + Gets or sets a value indicating whether to write the root JSON object. + + true if the JSON root object is omitted; otherwise, false. + + + + Gets or sets a value indicating whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + true if special characters are encoded; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The calling serializer. + The value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Checks if the is a namespace attribute. + + Attribute name to test. + The attribute name prefix if it has one, otherwise an empty string. + true if attribute name is for a namespace attribute, otherwise false. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Specifies how dates are formatted when writing JSON text. + + + + + Dates are written in the ISO 8601 format, e.g. "2012-03-21T05:40Z". + + + + + Dates are written in the Microsoft JSON format, e.g. "\/Date(1198908717056)\/". + + + + + Specifies how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON text. + + + + + Date formatted strings are not parsed to a date type and are read as strings. + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Specifies how to treat the time value when converting between string and . + + + + + Treat as local time. If the object represents a Coordinated Universal Time (UTC), it is converted to the local time. + + + + + Treat as a UTC. If the object represents a local time, it is converted to a UTC. + + + + + Treat as a local time if a is being converted to a string. + If a string is being converted to , convert to a local time if a time zone is specified. + + + + + Time zone information should be preserved when converting. + + + + + The default JSON name table implementation. + + + + + Initializes a new instance of the class. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Adds the specified string into name table. + + The string to add. + This method is not thread-safe. + The resolved string. + + + + Specifies default value handling options for the . + + + + + + + + + Include members where the member value is the same as the member's default value when serializing objects. + Included members are written to JSON. Has no effect when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + so that it is not written to JSON. + This option will ignore all default values (e.g. null for objects and nullable types; 0 for integers, + decimals and floating point numbers; and false for booleans). The default value ignored can be changed by + placing the on the property. + + + + + Members with a default value but no JSON will be set to their default value when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + and set members to their default value when deserializing. + + + + + Specifies float format handling options when writing special floating point numbers, e.g. , + and with . + + + + + Write special floating point values as strings in JSON, e.g. "NaN", "Infinity", "-Infinity". + + + + + Write special floating point values as symbols in JSON, e.g. NaN, Infinity, -Infinity. + Note that this will produce non-valid JSON. + + + + + Write special floating point values as the property's default value in JSON, e.g. 0.0 for a property, null for a of property. + + + + + Specifies how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Floating point numbers are parsed to . + + + + + Floating point numbers are parsed to . + + + + + Specifies formatting options for the . + + + + + No special formatting is applied. This is the default. + + + + + Causes child objects to be indented according to the and settings. + + + + + Provides an interface for using pooled arrays. + + The array type content. + + + + Rent an array from the pool. This array must be returned when it is no longer needed. + + The minimum required length of the array. The returned array may be longer. + The rented array from the pool. This array must be returned when it is no longer needed. + + + + Return an array to the pool. + + The array that is being returned. + + + + Provides an interface to enable a class to return line and position information. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + The current line number or 0 if no line information is available (for example, when returns false). + + + + Gets the current line position. + + The current line position or 0 if no line information is available (for example, when returns false). + + + + Instructs the how to serialize the collection. + + + + + Gets or sets a value indicating whether null items are allowed in the collection. + + true if null items are allowed in the collection; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with a flag indicating whether the array can contain null items. + + A flag indicating whether the array can contain null items. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to use the specified constructor when deserializing that object. + + + + + Instructs the how to serialize the object. + + + + + Gets or sets the id. + + The id. + + + + Gets or sets the title. + + The title. + + + + Gets or sets the description. + + The description. + + + + Gets or sets the collection's items converter. + + The collection's items converter. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets a value that indicates whether to preserve object references. + + + true to keep object reference; otherwise, false. The default is false. + + + + + Gets or sets a value that indicates whether to preserve collection's items references. + + + true to keep collection's items object references; otherwise, false. The default is false. + + + + + Gets or sets the reference loop handling used when serializing the collection's items. + + The reference loop handling. + + + + Gets or sets the type name handling used when serializing the collection's items. + + The type name handling. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Provides methods for converting between .NET types and JSON types. + + + + + + + + Gets or sets a function that creates default . + Default settings are automatically used by serialization methods on , + and and on . + To serialize without using any default settings create a with + . + + + + + Represents JavaScript's boolean value true as a string. This field is read-only. + + + + + Represents JavaScript's boolean value false as a string. This field is read-only. + + + + + Represents JavaScript's null as a string. This field is read-only. + + + + + Represents JavaScript's undefined as a string. This field is read-only. + + + + + Represents JavaScript's positive infinity as a string. This field is read-only. + + + + + Represents JavaScript's negative infinity as a string. This field is read-only. + + + + + Represents JavaScript's NaN as a string. This field is read-only. + + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + The time zone handling when the date is converted to a string. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + The string escape handling. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Serializes the specified object to a JSON string. + + The object to serialize. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting. + + The object to serialize. + Indicates how the output should be formatted. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a collection of . + + The object to serialize. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting and a collection of . + + The object to serialize. + Indicates how the output should be formatted. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Deserializes the JSON to a .NET object. + + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to a .NET object using . + + The JSON to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The JSON to deserialize. + The of object being deserialized. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The type of the object to deserialize to. + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the given anonymous type. + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the given anonymous type using . + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The type of the object to deserialize to. + The JSON to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The type of the object to deserialize to. + The object to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The JSON to deserialize. + The type of the object to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The JSON to deserialize. + The type of the object to deserialize to. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Populates the object with values from the JSON string. + + The JSON to populate values from. + The target object to populate values onto. + + + + Populates the object with values from the JSON string using . + + The JSON to populate values from. + The target object to populate values onto. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + + + + Serializes the to a JSON string. + + The node to serialize. + A JSON string of the . + + + + Serializes the to a JSON string using formatting. + + The node to serialize. + Indicates how the output should be formatted. + A JSON string of the . + + + + Serializes the to a JSON string using formatting and omits the root object if is true. + + The node to serialize. + Indicates how the output should be formatted. + Omits writing the root object. + A JSON string of the . + + + + Deserializes the from a JSON string. + + The JSON string. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by . + + The JSON string. + The name of the root element to append when deserializing. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by + and writes a Json.NET array attribute for collections. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by , + writes a Json.NET array attribute for collections, and encodes special characters. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + + A value to indicate whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + The deserialized . + + + + Serializes the to a JSON string. + + The node to convert to JSON. + A JSON string of the . + + + + Serializes the to a JSON string using formatting. + + The node to convert to JSON. + Indicates how the output should be formatted. + A JSON string of the . + + + + Serializes the to a JSON string using formatting and omits the root object if is true. + + The node to serialize. + Indicates how the output should be formatted. + Omits writing the root object. + A JSON string of the . + + + + Deserializes the from a JSON string. + + The JSON string. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by . + + The JSON string. + The name of the root element to append when deserializing. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by + and writes a Json.NET array attribute for collections. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by , + writes a Json.NET array attribute for collections, and encodes special characters. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + + A value to indicate whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + The deserialized . + + + + Converts an object to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can read JSON. + + true if this can read JSON; otherwise, false. + + + + Gets a value indicating whether this can write JSON. + + true if this can write JSON; otherwise, false. + + + + Converts an object to and from JSON. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. If there is no existing value then null will be used. + The existing value has a value. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Instructs the to use the specified when serializing the member or class. + + + + + Gets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + + + + + Initializes a new instance of the class. + + Type of the . + + + + Initializes a new instance of the class. + + Type of the . + Parameter list to use when constructing the . Can be null. + + + + Represents a collection of . + + + + + Instructs the how to serialize the collection. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Instructs the to deserialize properties with no matching class member into the specified collection + and write values during serialization. + + + + + Gets or sets a value that indicates whether to write extension data when serializing the object. + + + true to write extension data when serializing the object; otherwise, false. The default is true. + + + + + Gets or sets a value that indicates whether to read extension data when deserializing the object. + + + true to read extension data when deserializing the object; otherwise, false. The default is true. + + + + + Initializes a new instance of the class. + + + + + Instructs the not to serialize the public field or public read/write property value. + + + + + Base class for a table of atomized string objects. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Instructs the how to serialize the object. + + + + + Gets or sets the member serialization. + + The member serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified member serialization. + + The member serialization. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to always serialize the member with the specified name. + + + + + Gets or sets the type used when serializing the property's collection items. + + The collection's items type. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the null value handling used when serializing this property. + + The null value handling. + + + + Gets or sets the default value handling used when serializing this property. + + The default value handling. + + + + Gets or sets the reference loop handling used when serializing this property. + + The reference loop handling. + + + + Gets or sets the object creation handling used when deserializing this property. + + The object creation handling. + + + + Gets or sets the type name handling used when serializing this property. + + The type name handling. + + + + Gets or sets whether this property's value is serialized as a reference. + + Whether this property's value is serialized as a reference. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets a value indicating whether this property is required. + + + A value indicating whether this property is required. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified name. + + Name of the property. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Specifies the state of the reader. + + + + + A read method has not been called. + + + + + The end of the file has been reached successfully. + + + + + Reader is at a property. + + + + + Reader is at the start of an object. + + + + + Reader is in an object. + + + + + Reader is at the start of an array. + + + + + Reader is in an array. + + + + + The method has been called. + + + + + Reader has just read a value. + + + + + Reader is at the start of a constructor. + + + + + Reader is in a constructor. + + + + + An error occurred that prevents the read operation from continuing. + + + + + The end of the file has been reached successfully. + + + + + Gets the current reader state. + + The current reader state. + + + + Gets or sets a value indicating whether the source should be closed when this reader is closed. + + + true to close the source when this reader is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether multiple pieces of JSON content can + be read from a continuous stream without erroring. + + + true to support reading multiple pieces of JSON content; otherwise false. + The default is false. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + Gets or sets how time zones are handled when reading JSON. + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Gets or sets how custom date formatted strings are parsed when reading JSON. + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets the type of the current JSON token. + + + + + Gets the text value of the current JSON token. + + + + + Gets the .NET type for the current JSON token. + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets or sets the culture used when reading JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Reads the next JSON token from the source. + + true if the next token was read successfully; false if there are no more tokens to read. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Skips the children of the current token. + + + + + Sets the current token. + + The new token. + + + + Sets the current token and value. + + The new token. + The value. + + + + Sets the current token and value. + + The new token. + The value. + A flag indicating whether the position index inside an array should be updated. + + + + Sets the state based on current token type. + + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Changes the reader's state to . + If is set to true, the source is also closed. + + + + + The exception thrown when an error occurs while reading JSON text. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Instructs the to always serialize the member, and to require that the member has a value. + + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Serializes and deserializes objects into and from the JSON format. + The enables you to control how objects are encoded into JSON. + + + + + Occurs when the errors during serialization and deserialization. + + + + + Gets or sets the used by the serializer when resolving references. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + + + + Gets or sets how reference loops (e.g. a class referencing itself) is handled. + The default value is . + + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets a collection that will be used during serialization. + + Collection that will be used during serialization. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets a value indicating whether there will be a check for additional JSON content after deserializing an object. + The default value is false. + + + true if there will be a check for additional JSON content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Creates a new instance. + The will not use default settings + from . + + + A new instance. + The will not use default settings + from . + + + + + Creates a new instance using the specified . + The will not use default settings + from . + + The settings to be applied to the . + + A new instance using the specified . + The will not use default settings + from . + + + + + Creates a new instance. + The will use default settings + from . + + + A new instance. + The will use default settings + from . + + + + + Creates a new instance using the specified . + The will use default settings + from as well as the specified . + + The settings to be applied to the . + + A new instance using the specified . + The will use default settings + from as well as the specified . + + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Deserializes the JSON structure contained by the specified . + + The that contains the JSON structure to deserialize. + The being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The type of the object to deserialize. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is Auto to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Specifies the settings on a object. + + + + + Gets or sets how reference loops (e.g. a class referencing itself) are handled. + The default value is . + + Reference loop handling. + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + Missing member handling. + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + Null value handling. + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + The default value handling. + + + + Gets or sets a collection that will be used during serialization. + + The converters. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + The preserve references handling. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + The type name handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + The contract resolver. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets the used by the serializer when resolving references. + + The reference resolver. + + + + Gets or sets a function that creates the used by the serializer when resolving references. + + A function that creates the used by the serializer when resolving references. + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the error handler called during serialization and deserialization. + + The error handler called during serialization and deserialization. + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets a value indicating whether there will be a check for additional content after deserializing an object. + The default value is false. + + + true if there will be a check for additional content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Represents a reader that provides fast, non-cached, forward-only access to JSON text data. + + + + + Initializes a new instance of the class with the specified . + + The containing the JSON data to read. + + + + Gets or sets the reader's property name table. + + + + + Gets or sets the reader's character buffer pool. + + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + + The current line number or 0 if no line information is available (for example, returns false). + + + + + Gets the current line position. + + + The current line position or 0 if no line information is available (for example, returns false). + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets or sets the writer's character array pool. + + + + + Gets or sets how many s to write for each level in the hierarchy when is set to . + + + + + Gets or sets which character to use to quote attribute values. + + + + + Gets or sets which character to use for indenting when is set to . + + + + + Gets or sets a value indicating whether object names will be surrounded with quotes. + + + + + Initializes a new instance of the class using the specified . + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying . + + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the specified end token. + + The end token to write. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Specifies the type of JSON token. + + + + + This is returned by the if a read method has not been called. + + + + + An object start token. + + + + + An array start token. + + + + + A constructor start token. + + + + + An object property name. + + + + + A comment. + + + + + Raw JSON. + + + + + An integer. + + + + + A float. + + + + + A string. + + + + + A boolean. + + + + + A null token. + + + + + An undefined token. + + + + + An object end token. + + + + + An array end token. + + + + + A constructor end token. + + + + + A Date. + + + + + Byte data. + + + + + + Represents a reader that provides validation. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Sets an event handler for receiving schema validation errors. + + + + + Gets the text value of the current JSON token. + + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + + Gets the type of the current JSON token. + + + + + + Gets the .NET type for the current JSON token. + + + + + + Initializes a new instance of the class that + validates the content returned from the given . + + The to read from while validating. + + + + Gets or sets the schema. + + The schema. + + + + Gets the used to construct this . + + The specified in the constructor. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a []. + + + A [] or null if the next JSON token is null. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets or sets a value indicating whether the destination should be closed when this writer is closed. + + + true to close the destination when this writer is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether the JSON should be auto-completed when this writer is closed. + + + true to auto-complete the JSON when this writer is closed; otherwise false. The default is true. + + + + + Gets the top. + + The top. + + + + Gets the state of the writer. + + + + + Gets the path of the writer. + + + + + Gets or sets a value indicating how JSON text output should be formatted. + + + + + Gets or sets how dates are written to JSON text. + + + + + Gets or sets how time zones are handled when writing JSON text. + + + + + Gets or sets how strings are escaped when writing JSON text. + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written to JSON text. + + + + + Gets or sets how and values are formatted when writing JSON text. + + + + + Gets or sets the culture used when writing JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the destination and also flushes the destination. + + + + + Closes this writer. + If is set to true, the destination is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the end of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the end of an array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end constructor. + + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes the end of the current JSON object or array. + + + + + Writes the current token and its children. + + The to read the token from. + + + + Writes the current token. + + The to read the token from. + A flag indicating whether the current token's children should be written. + + + + Writes the token and its value. + + The to write. + + The value to write. + A value is only required for tokens that have an associated value, e.g. the property name for . + null can be passed to the method for tokens that don't have a value, e.g. . + + + + + Writes the token. + + The to write. + + + + Writes the specified end token. + + The end token to write. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON without changing the writer's state. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Sets the state of the . + + The being written. + The value being written. + + + + The exception thrown when an error occurs while writing JSON text. + + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Specifies how JSON comments are handled when loading JSON. + + + + + Ignore comments. + + + + + Load comments as a with type . + + + + + Specifies how duplicate property names are handled when loading JSON. + + + + + Replace the existing value when there is a duplicate property. The value of the last property in the JSON object will be used. + + + + + Ignore the new value when there is a duplicate property. The value of the first property in the JSON object will be used. + + + + + Throw a when a duplicate property is encountered. + + + + + Contains the LINQ to JSON extension methods. + + + + + Returns a collection of tokens that contains the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the descendants of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, and the descendants of every token in the source collection. + + + + Returns a collection of child properties of every object in the source collection. + + An of that contains the source collection. + An of that contains the properties of every object in the source collection. + + + + Returns a collection of child values of every object in the source collection with the given key. + + An of that contains the source collection. + The token key. + An of that contains the values of every token in the source collection with the given key. + + + + Returns a collection of child values of every object in the source collection. + + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child values of every object in the source collection with the given key. + + The type to convert the values to. + An of that contains the source collection. + The token key. + An that contains the converted values of every token in the source collection with the given key. + + + + Returns a collection of converted child values of every object in the source collection. + + The type to convert the values to. + An of that contains the source collection. + An that contains the converted values of every token in the source collection. + + + + Converts the value. + + The type to convert the value to. + A cast as a of . + A converted value. + + + + Converts the value. + + The source collection type. + The type to convert the value to. + A cast as a of . + A converted value. + + + + Returns a collection of child tokens of every array in the source collection. + + The source collection type. + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child tokens of every array in the source collection. + + An of that contains the source collection. + The type to convert the values to. + The source collection type. + An that contains the converted values of every token in the source collection. + + + + Returns the input typed as . + + An of that contains the source collection. + The input typed as . + + + + Returns the input typed as . + + The source collection type. + An of that contains the source collection. + The input typed as . + + + + Represents a collection of objects. + + The type of token. + + + + Gets the of with the specified key. + + + + + + Represents a JSON array. + + + + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Loads an from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads an from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the at the specified index. + + + + + + Determines the index of a specific item in the . + + The object to locate in the . + + The index of if found in the list; otherwise, -1. + + + + + Inserts an item to the at the specified index. + + The zero-based index at which should be inserted. + The object to insert into the . + + is not a valid index in the . + + + + + Removes the item at the specified index. + + The zero-based index of the item to remove. + + is not a valid index in the . + + + + + Returns an enumerator that iterates through the collection. + + + A of that can be used to iterate through the collection. + + + + + Adds an item to the . + + The object to add to the . + + + + Removes all items from the . + + + + + Determines whether the contains a specific value. + + The object to locate in the . + + true if is found in the ; otherwise, false. + + + + + Copies the elements of the to an array, starting at a particular array index. + + The array. + Index of the array. + + + + Gets a value indicating whether the is read-only. + + true if the is read-only; otherwise, false. + + + + Removes the first occurrence of a specific object from the . + + The object to remove from the . + + true if was successfully removed from the ; otherwise, false. This method also returns false if is not found in the original . + + + + + Represents a JSON constructor. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets or sets the name of this constructor. + + The constructor name. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name. + + The constructor name. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a token that can contain other tokens. + + + + + Occurs when the list changes or an item in the list changes. + + + + + Occurs before an item is added to the collection. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Raises the event. + + The instance containing the event data. + + + + Raises the event. + + The instance containing the event data. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Get the first child token of this token. + + + A containing the first child token of the . + + + + + Get the last child token of this token. + + + A containing the last child token of the . + + + + + Returns a collection of the child tokens of this token, in document order. + + + An of containing the child tokens of this , in document order. + + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + + A containing the child values of this , in document order. + + + + + Returns a collection of the descendant tokens for this token in document order. + + An of containing the descendant tokens of the . + + + + Returns a collection of the tokens that contain this token, and all descendant tokens of this token, in document order. + + An of containing this token, and all the descendant tokens of the . + + + + Adds the specified content as children of this . + + The content to be added. + + + + Adds the specified content as the first children of this . + + The content to be added. + + + + Creates a that can be used to add tokens to the . + + A that is ready to have content written to it. + + + + Replaces the child nodes of this token with the specified content. + + The content. + + + + Removes the child nodes from this token. + + + + + Merge the specified content into this . + + The content to be merged. + + + + Merge the specified content into this using . + + The content to be merged. + The used to merge the content. + + + + Gets the count of child JSON tokens. + + The count of child JSON tokens. + + + + Represents a collection of objects. + + The type of token. + + + + An empty collection of objects. + + + + + Initializes a new instance of the struct. + + The enumerable. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Gets the of with the specified key. + + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Returns a hash code for this instance. + + + A hash code for this instance, suitable for use in hashing algorithms and data structures like a hash table. + + + + + Represents a JSON object. + + + + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Occurs when a property value changes. + + + + + Occurs when a property value is changing. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Gets the node type for this . + + The type. + + + + Gets an of of this object's properties. + + An of of this object's properties. + + + + Gets a with the specified name. + + The property name. + A with the specified name or null. + + + + Gets the with the specified name. + The exact name will be searched for first and if no matching property is found then + the will be used to match a property. + + The property name. + One of the enumeration values that specifies how the strings will be compared. + A matched with the specified name or null. + + + + Gets a of of this object's property values. + + A of of this object's property values. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the with the specified property name. + + + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified property name. + + Name of the property. + The with the specified property name. + + + + Gets the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + One of the enumeration values that specifies how the strings will be compared. + The with the specified property name. + + + + Tries to get the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + The value. + One of the enumeration values that specifies how the strings will be compared. + true if a value was successfully retrieved; otherwise, false. + + + + Adds the specified property name. + + Name of the property. + The value. + + + + Determines whether the JSON object has the specified property name. + + Name of the property. + true if the JSON object has the specified property name; otherwise, false. + + + + Removes the property with the specified name. + + Name of the property. + true if item was successfully removed; otherwise, false. + + + + Tries to get the with the specified property name. + + Name of the property. + The value. + true if a value was successfully retrieved; otherwise, false. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Raises the event with the provided arguments. + + Name of the property. + + + + Raises the event with the provided arguments. + + Name of the property. + + + + Represents a JSON property. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the property name. + + The property name. + + + + Gets or sets the property value. + + The property value. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a view of a . + + + + + Initializes a new instance of the class. + + The name. + + + + When overridden in a derived class, returns whether resetting an object changes its value. + + + true if resetting the component changes its value; otherwise, false. + + The component to test for reset capability. + + + + When overridden in a derived class, gets the current value of the property on a component. + + + The value of a property for a given component. + + The component with the property for which to retrieve the value. + + + + When overridden in a derived class, resets the value for this property of the component to the default value. + + The component with the property value that is to be reset to the default value. + + + + When overridden in a derived class, sets the value of the component to a different value. + + The component with the property value that is to be set. + The new value. + + + + When overridden in a derived class, determines a value indicating whether the value of this property needs to be persisted. + + + true if the property should be persisted; otherwise, false. + + The component with the property to be examined for persistence. + + + + When overridden in a derived class, gets the type of the component this property is bound to. + + + A that represents the type of component this property is bound to. + When the or + + methods are invoked, the object specified might be an instance of this type. + + + + + When overridden in a derived class, gets a value indicating whether this property is read-only. + + + true if the property is read-only; otherwise, false. + + + + + When overridden in a derived class, gets the type of the property. + + + A that represents the type of the property. + + + + + Gets the hash code for the name of the member. + + + + The hash code for the name of the member. + + + + + Represents a raw JSON string. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class. + + The raw json. + + + + Creates an instance of with the content of the reader's current token. + + The reader. + An instance of with the content of the reader's current token. + + + + Specifies the settings used when loading JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets how JSON comments are handled when loading JSON. + The default value is . + + The JSON comment handling. + + + + Gets or sets how JSON line info is handled when loading JSON. + The default value is . + + The JSON line info handling. + + + + Gets or sets how duplicate property names in JSON objects are handled when loading JSON. + The default value is . + + The JSON duplicate property name handling. + + + + Specifies the settings used when merging JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets the method used when merging JSON arrays. + + The method used when merging JSON arrays. + + + + Gets or sets how null value properties are merged. + + How null value properties are merged. + + + + Gets or sets the comparison used to match property names while merging. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + The comparison used to match property names while merging. + + + + Specifies the settings used when selecting JSON. + + + + + Gets or sets a flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + A flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + + + Represents an abstract JSON token. + + + + + Gets a comparer that can compare two tokens for value equality. + + A that can compare two nodes for value equality. + + + + Gets or sets the parent. + + The parent. + + + + Gets the root of this . + + The root of this . + + + + Gets the node type for this . + + The type. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Compares the values of two tokens, including the values of all descendant tokens. + + The first to compare. + The second to compare. + true if the tokens are equal; otherwise false. + + + + Gets the next sibling token of this node. + + The that contains the next sibling token. + + + + Gets the previous sibling token of this node. + + The that contains the previous sibling token. + + + + Gets the path of the JSON token. + + + + + Adds the specified content immediately after this token. + + A content object that contains simple content or a collection of content objects to be added after this token. + + + + Adds the specified content immediately before this token. + + A content object that contains simple content or a collection of content objects to be added before this token. + + + + Returns a collection of the ancestor tokens of this token. + + A collection of the ancestor tokens of this token. + + + + Returns a collection of tokens that contain this token, and the ancestors of this token. + + A collection of tokens that contain this token, and the ancestors of this token. + + + + Returns a collection of the sibling tokens after this token, in document order. + + A collection of the sibling tokens after this tokens, in document order. + + + + Returns a collection of the sibling tokens before this token, in document order. + + A collection of the sibling tokens before this token, in document order. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets the with the specified key converted to the specified type. + + The type to convert the token to. + The token key. + The converted token value. + + + + Get the first child token of this token. + + A containing the first child token of the . + + + + Get the last child token of this token. + + A containing the last child token of the . + + + + Returns a collection of the child tokens of this token, in document order. + + An of containing the child tokens of this , in document order. + + + + Returns a collection of the child tokens of this token, in document order, filtered by the specified type. + + The type to filter the child tokens on. + A containing the child tokens of this , in document order. + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + A containing the child values of this , in document order. + + + + Removes this token from its parent. + + + + + Replaces this token with the specified token. + + The value. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Returns the indented JSON for this token. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + The indented JSON for this token. + + + + + Returns the JSON for this token using the given formatting and converters. + + Indicates how the output should be formatted. + A collection of s which will be used when writing the token. + The JSON for this token using the given formatting and converters. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to []. + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from [] to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Creates a for this token. + + A that can be used to read this token and its descendants. + + + + Creates a from an object. + + The object that will be used to create . + A with the value of the specified object. + + + + Creates a from an object using the specified . + + The object that will be used to create . + The that will be used when reading the object. + A with the value of the specified object. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + An positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + Creates a from a . + + A positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A , or null. + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + A . + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + The used to select tokens. + A . + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + The used to select tokens. + An of that contains the selected elements. + + + + Creates a new instance of the . All child tokens are recursively cloned. + + A new instance of the . + + + + Adds an object to the annotation list of this . + + The annotation to add. + + + + Get the first annotation object of the specified type from this . + + The type of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets the first annotation object of the specified type from this . + + The of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets a collection of annotations of the specified type for this . + + The type of the annotations to retrieve. + An that contains the annotations for this . + + + + Gets a collection of annotations of the specified type for this . + + The of the annotations to retrieve. + An of that contains the annotations that match the specified type for this . + + + + Removes the annotations of the specified type from this . + + The type of annotations to remove. + + + + Removes the annotations of the specified type from this . + + The of annotations to remove. + + + + Compares tokens to determine whether they are equal. + + + + + Determines whether the specified objects are equal. + + The first object of type to compare. + The second object of type to compare. + + true if the specified objects are equal; otherwise, false. + + + + + Returns a hash code for the specified object. + + The for which a hash code is to be returned. + A hash code for the specified object. + The type of is a reference type and is null. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Gets the at the reader's current position. + + + + + Initializes a new instance of the class. + + The token to read from. + + + + Initializes a new instance of the class. + + The token to read from. + The initial path of the token. It is prepended to the returned . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Gets the path of the current JSON token. + + + + + Specifies the type of token. + + + + + No token type has been set. + + + + + A JSON object. + + + + + A JSON array. + + + + + A JSON constructor. + + + + + A JSON object property. + + + + + A comment. + + + + + An integer value. + + + + + A float value. + + + + + A string value. + + + + + A boolean value. + + + + + A null value. + + + + + An undefined value. + + + + + A date value. + + + + + A raw JSON value. + + + + + A collection of bytes value. + + + + + A Guid value. + + + + + A Uri value. + + + + + A TimeSpan value. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets the at the writer's current position. + + + + + Gets the token being written. + + The token being written. + + + + Initializes a new instance of the class writing to the given . + + The container being written to. + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the underlying . + + + + + Closes this writer. + If is set to true, the JSON is auto-completed. + + + Setting to true has no additional effect, since the underlying is a type that cannot be closed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end. + + The token. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes a value. + An error will be raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Represents a value in JSON (string, integer, date, etc). + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Creates a comment with the given value. + + The value. + A comment with the given value. + + + + Creates a string with the given value. + + The value. + A string with the given value. + + + + Creates a null value. + + A null value. + + + + Creates a undefined value. + + A undefined value. + + + + Gets the node type for this . + + The type. + + + + Gets or sets the underlying token value. + + The underlying token value. + + + + Writes this token to a . + + A into which this method will write. + A collection of s which will be used when writing the token. + + + + Indicates whether the current object is equal to another object of the same type. + + + true if the current object is equal to the parameter; otherwise, false. + + An object to compare with this object. + + + + Determines whether the specified is equal to the current . + + The to compare with the current . + + true if the specified is equal to the current ; otherwise, false. + + + + + Serves as a hash function for a particular type. + + + A hash code for the current . + + + + + Returns a that represents this instance. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format provider. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + The format provider. + + A that represents this instance. + + + + + Compares the current instance with another object of the same type and returns an integer that indicates whether the current instance precedes, follows, or occurs in the same position in the sort order as the other object. + + An object to compare with this instance. + + A 32-bit signed integer that indicates the relative order of the objects being compared. The return value has these meanings: + Value + Meaning + Less than zero + This instance is less than . + Zero + This instance is equal to . + Greater than zero + This instance is greater than . + + + is not of the same type as this instance. + + + + + Specifies how line information is handled when loading JSON. + + + + + Ignore line information. + + + + + Load line information. + + + + + Specifies how JSON arrays are merged together. + + + + Concatenate arrays. + + + Union arrays, skipping items that already exist. + + + Replace all array items. + + + Merge array items together, matched by index. + + + + Specifies how null value properties are merged. + + + + + The content's null value properties will be ignored during merging. + + + + + The content's null value properties will be merged. + + + + + Specifies the member serialization options for the . + + + + + All public members are serialized by default. Members can be excluded using or . + This is the default member serialization mode. + + + + + Only members marked with or are serialized. + This member serialization mode can also be set by marking the class with . + + + + + All public and private fields are serialized. Members can be excluded using or . + This member serialization mode can also be set by marking the class with + and setting IgnoreSerializableAttribute on to false. + + + + + Specifies metadata property handling options for the . + + + + + Read metadata properties located at the start of a JSON object. + + + + + Read metadata properties located anywhere in a JSON object. Note that this setting will impact performance. + + + + + Do not try to read metadata properties. + + + + + Specifies missing member handling options for the . + + + + + Ignore a missing member and do not attempt to deserialize it. + + + + + Throw a when a missing member is encountered during deserialization. + + + + + Specifies null value handling options for the . + + + + + + + + + Include null values when serializing and deserializing objects. + + + + + Ignore null values when serializing and deserializing objects. + + + + + Specifies how object creation is handled by the . + + + + + Reuse existing objects, create new objects when needed. + + + + + Only reuse existing objects. + + + + + Always create new objects. + + + + + Specifies reference handling options for the . + Note that references cannot be preserved when a value is set via a non-default constructor such as types that implement . + + + + + + + + Do not preserve references when serializing types. + + + + + Preserve references when serializing into a JSON object structure. + + + + + Preserve references when serializing into a JSON array structure. + + + + + Preserve references when serializing. + + + + + Specifies reference loop handling options for the . + + + + + Throw a when a loop is encountered. + + + + + Ignore loop references and do not serialize. + + + + + Serialize loop references. + + + + + Indicating whether a property is required. + + + + + The property is not required. The default state. + + + + + The property must be defined in JSON but can be a null value. + + + + + The property must be defined in JSON and cannot be a null value. + + + + + The property is not required but it cannot be a null value. + + + + + + Contains the JSON schema extension methods. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + true if the specified is valid; otherwise, false. + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + When this method returns, contains any error messages generated while validating. + + true if the specified is valid; otherwise, false. + + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + The validation event handler. + + + + + An in-memory representation of a JSON Schema. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the id. + + + + + Gets or sets the title. + + + + + Gets or sets whether the object is required. + + + + + Gets or sets whether the object is read-only. + + + + + Gets or sets whether the object is visible to users. + + + + + Gets or sets whether the object is transient. + + + + + Gets or sets the description of the object. + + + + + Gets or sets the types of values allowed by the object. + + The type. + + + + Gets or sets the pattern. + + The pattern. + + + + Gets or sets the minimum length. + + The minimum length. + + + + Gets or sets the maximum length. + + The maximum length. + + + + Gets or sets a number that the value should be divisible by. + + A number that the value should be divisible by. + + + + Gets or sets the minimum. + + The minimum. + + + + Gets or sets the maximum. + + The maximum. + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the minimum attribute (). + + A flag indicating whether the value can not equal the number defined by the minimum attribute (). + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the maximum attribute (). + + A flag indicating whether the value can not equal the number defined by the maximum attribute (). + + + + Gets or sets the minimum number of items. + + The minimum number of items. + + + + Gets or sets the maximum number of items. + + The maximum number of items. + + + + Gets or sets the of items. + + The of items. + + + + Gets or sets a value indicating whether items in an array are validated using the instance at their array position from . + + + true if items are validated using their array position; otherwise, false. + + + + + Gets or sets the of additional items. + + The of additional items. + + + + Gets or sets a value indicating whether additional items are allowed. + + + true if additional items are allowed; otherwise, false. + + + + + Gets or sets whether the array items must be unique. + + + + + Gets or sets the of properties. + + The of properties. + + + + Gets or sets the of additional properties. + + The of additional properties. + + + + Gets or sets the pattern properties. + + The pattern properties. + + + + Gets or sets a value indicating whether additional properties are allowed. + + + true if additional properties are allowed; otherwise, false. + + + + + Gets or sets the required property if this property is present. + + The required property if this property is present. + + + + Gets or sets the a collection of valid enum values allowed. + + A collection of valid enum values allowed. + + + + Gets or sets disallowed types. + + The disallowed types. + + + + Gets or sets the default value. + + The default value. + + + + Gets or sets the collection of that this schema extends. + + The collection of that this schema extends. + + + + Gets or sets the format. + + The format. + + + + Initializes a new instance of the class. + + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The object representing the JSON Schema. + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The to use when resolving schema references. + The object representing the JSON Schema. + + + + Load a from a string that contains JSON Schema. + + A that contains JSON Schema. + A populated from the string that contains JSON Schema. + + + + Load a from a string that contains JSON Schema using the specified . + + A that contains JSON Schema. + The resolver. + A populated from the string that contains JSON Schema. + + + + Writes this schema to a . + + A into which this method will write. + + + + Writes this schema to a using the specified . + + A into which this method will write. + The resolver used. + + + + Returns a that represents the current . + + + A that represents the current . + + + + + + Returns detailed information about the schema exception. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + + Generates a from a specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets how undefined schemas are handled by the serializer. + + + + + Gets or sets the contract resolver. + + The contract resolver. + + + + Generate a from the specified type. + + The type to generate a from. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + + Resolves from an id. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the loaded schemas. + + The loaded schemas. + + + + Initializes a new instance of the class. + + + + + Gets a for the specified reference. + + The id. + A for the specified reference. + + + + + The value types allowed by the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + No type specified. + + + + + String type. + + + + + Float type. + + + + + Integer type. + + + + + Boolean type. + + + + + Object type. + + + + + Array type. + + + + + Null type. + + + + + Any type. + + + + + + Specifies undefined schema Id handling options for the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Do not infer a schema Id. + + + + + Use the .NET type name as the schema Id. + + + + + Use the assembly qualified .NET type name as the schema Id. + + + + + + Returns detailed information related to the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the associated with the validation error. + + The JsonSchemaException associated with the validation error. + + + + Gets the path of the JSON location where the validation error occurred. + + The path of the JSON location where the validation error occurred. + + + + Gets the text description corresponding to the validation error. + + The text description. + + + + + Represents the callback method that will handle JSON schema validation events and the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + A camel case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Resolves member mappings for a type, camel casing property names. + + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used by to resolve a for a given . + + + + + Gets a value indicating whether members are being get and set using dynamic code generation. + This value is determined by the runtime permissions available. + + + true if using dynamic code generation; otherwise, false. + + + + + Gets or sets the default members search flags. + + The default members search flags. + + + + Gets or sets a value indicating whether compiler generated members should be serialized. + + + true if serialized compiler generated members; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore the interface when serializing and deserializing types. + + + true if the interface will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore the attribute when serializing and deserializing types. + + + true if the attribute will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore IsSpecified members when serializing and deserializing types. + + + true if the IsSpecified members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore ShouldSerialize members when serializing and deserializing types. + + + true if the ShouldSerialize members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets the naming strategy used to resolve how property names and dictionary keys are serialized. + + The naming strategy used to resolve how property names and dictionary keys are serialized. + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Gets the serializable members for the type. + + The type to get serializable members for. + The serializable members for the type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates the constructor parameters. + + The constructor to create properties for. + The type's member properties. + Properties for the given . + + + + Creates a for the given . + + The matching member property. + The constructor parameter. + A created for the given . + + + + Resolves the default for the contract. + + Type of the object. + The contract's default . + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Determines which contract type is created for the given type. + + Type of the object. + A for the given type. + + + + Creates properties for the given . + + The type to create properties for. + /// The member serialization mode for the type. + Properties for the given . + + + + Creates the used by the serializer to get and set values from a member. + + The member. + The used by the serializer to get and set values from a member. + + + + Creates a for the given . + + The member's parent . + The member to create a for. + A created for the given . + + + + Resolves the name of the property. + + Name of the property. + Resolved name of the property. + + + + Resolves the name of the extension data. By default no changes are made to extension data names. + + Name of the extension data. + Resolved name of the extension data. + + + + Resolves the key of the dictionary. By default is used to resolve dictionary keys. + + Key of the dictionary. + Resolved key of the dictionary. + + + + Gets the resolved name of the property. + + Name of the property. + Name of the property. + + + + The default naming strategy. Property names and dictionary keys are unchanged. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + The default serialization binder used when resolving and loading classes from type names. + + + + + Initializes a new instance of the class. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + The type of the object the formatter creates a new instance of. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Represents a trace writer that writes to the application's instances. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + + The that will be used to filter the trace messages passed to the writer. + + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Get and set values for a using dynamic methods. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Provides information surrounding an error. + + + + + Gets the error. + + The error. + + + + Gets the original object that caused the error. + + The original object that caused the error. + + + + Gets the member that caused the error. + + The member that caused the error. + + + + Gets the path of the JSON location where the error occurred. + + The path of the JSON location where the error occurred. + + + + Gets or sets a value indicating whether this is handled. + + true if handled; otherwise, false. + + + + Provides data for the Error event. + + + + + Gets the current object the error event is being raised against. + + The current object the error event is being raised against. + + + + Gets the error context. + + The error context. + + + + Initializes a new instance of the class. + + The current object. + The error context. + + + + Provides methods to get attributes. + + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Used by to resolve a for a given . + + + + + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used to resolve references when serializing and deserializing JSON by the . + + + + + Resolves a reference to its object. + + The serialization context. + The reference to resolve. + The object that was resolved from the reference. + + + + Gets the reference for the specified object. + + The serialization context. + The object to get a reference for. + The reference to the object. + + + + Determines whether the specified object is referenced. + + The serialization context. + The object to test for a reference. + + true if the specified object is referenced; otherwise, false. + + + + + Adds a reference to the specified object. + + The serialization context. + The reference. + The object to reference. + + + + Allows users to control class loading and mandate what class to load. + + + + + When implemented, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object + The type of the object the formatter creates a new instance of. + + + + When implemented, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Represents a trace writer. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + The that will be used to filter the trace messages passed to the writer. + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Provides methods to get and set values. + + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Contract details for a used by the . + + + + + Gets the of the collection items. + + The of the collection items. + + + + Gets a value indicating whether the collection type is a multidimensional array. + + true if the collection type is a multidimensional array; otherwise, false. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the collection values. + + true if the creator has a parameter with the collection values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the default collection items . + + The converter. + + + + Gets or sets a value indicating whether the collection items preserve object references. + + true if collection items preserve object references; otherwise, false. + + + + Gets or sets the collection item reference loop handling. + + The reference loop handling. + + + + Gets or sets the collection item type name handling. + + The type name handling. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Handles serialization callback events. + + The object that raised the callback event. + The streaming context. + + + + Handles serialization error callback events. + + The object that raised the callback event. + The streaming context. + The error context. + + + + Sets extension data for an object during deserialization. + + The object to set extension data on. + The extension data key. + The extension data value. + + + + Gets extension data for an object during serialization. + + The object to set extension data on. + + + + Contract details for a used by the . + + + + + Gets the underlying type for the contract. + + The underlying type for the contract. + + + + Gets or sets the type created during deserialization. + + The type created during deserialization. + + + + Gets or sets whether this type contract is serialized as a reference. + + Whether this type contract is serialized as a reference. + + + + Gets or sets the default for this contract. + + The converter. + + + + Gets the internally resolved for the contract's type. + This converter is used as a fallback converter when no other converter is resolved. + Setting will always override this converter. + + + + + Gets or sets all methods called immediately after deserialization of the object. + + The methods called immediately after deserialization of the object. + + + + Gets or sets all methods called during deserialization of the object. + + The methods called during deserialization of the object. + + + + Gets or sets all methods called after serialization of the object graph. + + The methods called after serialization of the object graph. + + + + Gets or sets all methods called before serialization of the object. + + The methods called before serialization of the object. + + + + Gets or sets all method called when an error is thrown during the serialization of the object. + + The methods called when an error is thrown during the serialization of the object. + + + + Gets or sets the default creator method used to create the object. + + The default creator method used to create the object. + + + + Gets or sets a value indicating whether the default creator is non-public. + + true if the default object creator is non-public; otherwise, false. + + + + Contract details for a used by the . + + + + + Gets or sets the dictionary key resolver. + + The dictionary key resolver. + + + + Gets the of the dictionary keys. + + The of the dictionary keys. + + + + Gets the of the dictionary values. + + The of the dictionary values. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the dictionary values. + + true if the creator has a parameter with the dictionary values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object constructor. + + The object constructor. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object member serialization. + + The member object serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets the object's properties. + + The object's properties. + + + + Gets a collection of instances that define the parameters used with . + + + + + Gets or sets the function used to create the object. When set this function will override . + This function is called with a collection of arguments which are defined by the collection. + + The function used to create the object. + + + + Gets or sets the extension data setter. + + + + + Gets or sets the extension data getter. + + + + + Gets or sets the extension data value type. + + + + + Gets or sets the extension data name resolver. + + The extension data name resolver. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Maps a JSON property to a .NET member or constructor parameter. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the type that declared this property. + + The type that declared this property. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets the name of the underlying member or parameter. + + The name of the underlying member or parameter. + + + + Gets the that will get and set the during serialization. + + The that will get and set the during serialization. + + + + Gets or sets the for this property. + + The for this property. + + + + Gets or sets the type of the property. + + The type of the property. + + + + Gets or sets the for the property. + If set this converter takes precedence over the contract converter for the property type. + + The converter. + + + + Gets or sets the member converter. + + The member converter. + + + + Gets or sets a value indicating whether this is ignored. + + true if ignored; otherwise, false. + + + + Gets or sets a value indicating whether this is readable. + + true if readable; otherwise, false. + + + + Gets or sets a value indicating whether this is writable. + + true if writable; otherwise, false. + + + + Gets or sets a value indicating whether this has a member attribute. + + true if has a member attribute; otherwise, false. + + + + Gets the default value. + + The default value. + + + + Gets or sets a value indicating whether this is required. + + A value indicating whether this is required. + + + + Gets a value indicating whether has a value specified. + + + + + Gets or sets a value indicating whether this property preserves object references. + + + true if this instance is reference; otherwise, false. + + + + + Gets or sets the property null value handling. + + The null value handling. + + + + Gets or sets the property default value handling. + + The default value handling. + + + + Gets or sets the property reference loop handling. + + The reference loop handling. + + + + Gets or sets the property object creation handling. + + The object creation handling. + + + + Gets or sets or sets the type name handling. + + The type name handling. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets a predicate used to determine whether the property should be deserialized. + + A predicate used to determine whether the property should be deserialized. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets an action used to set whether the property has been deserialized. + + An action used to set whether the property has been deserialized. + + + + Returns a that represents this instance. + + + A that represents this instance. + + + + + Gets or sets the converter used when serializing the property's collection items. + + The collection's items converter. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + A collection of objects. + + + + + Initializes a new instance of the class. + + The type. + + + + When implemented in a derived class, extracts the key from the specified element. + + The element from which to extract the key. + The key for the specified element. + + + + Adds a object. + + The property to add to the collection. + + + + Gets the closest matching object. + First attempts to get an exact case match of and then + a case insensitive match. + + Name of the property. + A matching property if found. + + + + Gets a property by property name. + + The name of the property to get. + Type property name string comparison. + A matching property if found. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Lookup and create an instance of the type described by the argument. + + The type to create. + Optional arguments to pass to an initializing constructor of the JsonConverter. + If null, the default constructor is used. + + + + A kebab case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Represents a trace writer that writes to memory. When the trace message limit is + reached then old trace messages will be removed as new messages are added. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + + The that will be used to filter the trace messages passed to the writer. + + + + + Initializes a new instance of the class. + + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Returns an enumeration of the most recent trace messages. + + An enumeration of the most recent trace messages. + + + + Returns a of the most recent trace messages. + + + A of the most recent trace messages. + + + + + A base class for resolving how property names and dictionary keys are serialized. + + + + + A flag indicating whether dictionary keys should be processed. + Defaults to false. + + + + + A flag indicating whether extension data names should be processed. + Defaults to false. + + + + + A flag indicating whether explicitly specified property names, + e.g. a property name customized with a , should be processed. + Defaults to false. + + + + + Gets the serialized name for a given property name. + + The initial property name. + A flag indicating whether the property has had a name explicitly specified. + The serialized property name. + + + + Gets the serialized name for a given extension data name. + + The initial extension data name. + The serialized extension data name. + + + + Gets the serialized key for a given dictionary key. + + The initial dictionary key. + The serialized dictionary key. + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Hash code calculation + + + + + + Object equality implementation + + + + + + + Compare to another NamingStrategy + + + + + + + Represents a method that constructs an object. + + The object type to create. + + + + When applied to a method, specifies that the method is called when an error occurs serializing an object. + + + + + Provides methods to get attributes from a , , or . + + + + + Initializes a new instance of the class. + + The instance to get attributes for. This parameter should be a , , or . + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Get and set values for a using reflection. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + A snake case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Specifies how strings are escaped when writing JSON text. + + + + + Only control characters (e.g. newline) are escaped. + + + + + All non-ASCII and control characters (e.g. newline) are escaped. + + + + + HTML (<, >, &, ', ") and control characters (e.g. newline) are escaped. + + + + + Indicates the method that will be used during deserialization for locating and loading assemblies. + + + + + In simple mode, the assembly used during deserialization need not match exactly the assembly used during serialization. Specifically, the version numbers need not match as the LoadWithPartialName method of the class is used to load the assembly. + + + + + In full mode, the assembly used during deserialization must match exactly the assembly used during serialization. The Load method of the class is used to load the assembly. + + + + + Specifies type name handling options for the . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Do not include the .NET type name when serializing types. + + + + + Include the .NET type name when serializing into a JSON object structure. + + + + + Include the .NET type name when serializing into a JSON array structure. + + + + + Always include the .NET type name when serializing. + + + + + Include the .NET type name when the type of the object being serialized is not the same as its declared type. + Note that this doesn't include the root serialized object by default. To include the root object's type name in JSON + you must specify a root type object with + or . + + + + + Determines whether the collection is null or empty. + + The collection. + + true if the collection is null or empty; otherwise, false. + + + + + Adds the elements of the specified collection to the specified generic . + + The list to add to. + The collection of elements to add. + + + + Converts the value to the specified type. If the value is unable to be converted, the + value is checked whether it assignable to the specified type. + + The value to convert. + The culture to use when converting. + The type to convert or cast the value to. + + The converted type. If conversion was unsuccessful, the initial value + is returned if assignable to the target type. + + + + + Helper class for serializing immutable collections. + Note that this is used by all builds, even those that don't support immutable collections, in case the DLL is GACed + https://github.com/JamesNK/Newtonsoft.Json/issues/652 + + + + + Gets the type of the typed collection's items. + + The type. + The type of the typed collection's items. + + + + Gets the member's underlying type. + + The member. + The underlying type of the member. + + + + Determines whether the property is an indexed property. + + The property. + + true if the property is an indexed property; otherwise, false. + + + + + Gets the member's value on the object. + + The member. + The target object. + The member's value on the object. + + + + Sets the member's value on the target object. + + The member. + The target. + The value. + + + + Determines whether the specified MemberInfo can be read. + + The MemberInfo to determine whether can be read. + /// if set to true then allow the member to be gotten non-publicly. + + true if the specified MemberInfo can be read; otherwise, false. + + + + + Determines whether the specified MemberInfo can be set. + + The MemberInfo to determine whether can be set. + if set to true then allow the member to be set non-publicly. + if set to true then allow the member to be set if read-only. + + true if the specified MemberInfo can be set; otherwise, false. + + + + + Builds a string. Unlike this class lets you reuse its internal buffer. + + + + + Determines whether the string is all white space. Empty string will return false. + + The string to test whether it is all white space. + + true if the string is all white space; otherwise, false. + + + + + Specifies the state of the . + + + + + An exception has been thrown, which has left the in an invalid state. + You may call the method to put the in the Closed state. + Any other method calls result in an being thrown. + + + + + The method has been called. + + + + + An object is being written. + + + + + An array is being written. + + + + + A constructor is being written. + + + + + A property is being written. + + + + + A write method has not been called. + + + + Specifies that an output will not be null even if the corresponding type allows it. + + + Specifies that when a method returns , the parameter will not be null even if the corresponding type allows it. + + + Initializes the attribute with the specified return value condition. + + The return value condition. If the method returns this value, the associated parameter will not be null. + + + + Gets the return value condition. + + + Specifies that an output may be null even if the corresponding type disallows it. + + + Specifies that null is allowed as an input even if the corresponding type disallows it. + + + + Specifies that the method will not return if the associated Boolean parameter is passed the specified value. + + + + + Initializes a new instance of the class. + + + The condition parameter value. Code after the method will be considered unreachable by diagnostics if the argument to + the associated parameter matches this value. + + + + Gets the condition parameter value. + + + diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/net40/Newtonsoft.Json.dll b/Packages/Newtonsoft.Json.13.0.1/lib/net40/Newtonsoft.Json.dll new file mode 100644 index 0000000..978356d Binary files /dev/null and b/Packages/Newtonsoft.Json.13.0.1/lib/net40/Newtonsoft.Json.dll differ diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/net40/Newtonsoft.Json.xml b/Packages/Newtonsoft.Json.13.0.1/lib/net40/Newtonsoft.Json.xml new file mode 100644 index 0000000..7ac0cc6 --- /dev/null +++ b/Packages/Newtonsoft.Json.13.0.1/lib/net40/Newtonsoft.Json.xml @@ -0,0 +1,9683 @@ + + + + Newtonsoft.Json + + + + + Represents a BSON Oid (object id). + + + + + Gets or sets the value of the Oid. + + The value of the Oid. + + + + Initializes a new instance of the class. + + The Oid value. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized BSON data. + + + + + Gets or sets a value indicating whether binary data reading should be compatible with incorrect Json.NET 3.5 written binary. + + + true if binary data reading will be compatible with incorrect Json.NET 3.5 written binary; otherwise, false. + + + + + Gets or sets a value indicating whether the root object will be read as a JSON array. + + + true if the root object will be read as a JSON array; otherwise, false. + + + + + Gets or sets the used when reading values from BSON. + + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating BSON data. + + + + + Gets or sets the used when writing values to BSON. + When set to no conversion will occur. + + The used when writing values to BSON. + + + + Initializes a new instance of the class. + + The to write to. + + + + Initializes a new instance of the class. + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying stream. + + + + + Writes the end. + + The token. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes the beginning of a JSON array. + + + + + Writes the beginning of a JSON object. + + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value that represents a BSON object id. + + The Object ID value to write. + + + + Writes a BSON regex. + + The regex pattern. + The regex options. + + + + Specifies how constructors are used when initializing objects during deserialization by the . + + + + + First attempt to use the public default constructor, then fall back to a single parameterized constructor, then to the non-public default constructor. + + + + + Json.NET will use a non-public default constructor before falling back to a parameterized constructor. + + + + + Converts a binary value to and from a base 64 string value. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Creates a custom object. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Creates an object which will then be populated by the serializer. + + Type of the object. + The created object. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can write JSON. + + + true if this can write JSON; otherwise, false. + + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Provides a base class for converting a to and from JSON. + + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a F# discriminated union type to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an Entity Framework to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can write JSON. + + + true if this can write JSON; otherwise, false. + + + + + Converts a to and from the ISO 8601 date format (e.g. "2008-04-12T12:53Z"). + + + + + Gets or sets the date time styles used when converting a date to and from JSON. + + The date time styles used when converting a date to and from JSON. + + + + Gets or sets the date time format used when converting a date to and from JSON. + + The date time format used when converting a date to and from JSON. + + + + Gets or sets the culture used when converting a date to and from JSON. + + The culture used when converting a date to and from JSON. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Converts a to and from a JavaScript Date constructor (e.g. new Date(52231943)). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an to and from its name string value. + + + + + Gets or sets a value indicating whether the written enum text should be camel case. + The default value is false. + + true if the written enum text will be camel case; otherwise, false. + + + + Gets or sets the naming strategy used to resolve how enum text is written. + + The naming strategy used to resolve how enum text is written. + + + + Gets or sets a value indicating whether integer values are allowed when serializing and deserializing. + The default value is true. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class. + + true if the written enum text will be camel case; otherwise, false. + + + + Initializes a new instance of the class. + + The naming strategy used to resolve how enum text is written. + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from Unix epoch time + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from a string (e.g. "1.2.3.4"). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts XML to and from JSON. + + + + + Gets or sets the name of the root element to insert when deserializing to XML if the JSON structure has produced multiple root elements. + + The name of the deserialized root element. + + + + Gets or sets a value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + true if the array attribute is written to the XML; otherwise, false. + + + + Gets or sets a value indicating whether to write the root JSON object. + + true if the JSON root object is omitted; otherwise, false. + + + + Gets or sets a value indicating whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + true if special characters are encoded; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The calling serializer. + The value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Checks if the is a namespace attribute. + + Attribute name to test. + The attribute name prefix if it has one, otherwise an empty string. + true if attribute name is for a namespace attribute, otherwise false. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Specifies how dates are formatted when writing JSON text. + + + + + Dates are written in the ISO 8601 format, e.g. "2012-03-21T05:40Z". + + + + + Dates are written in the Microsoft JSON format, e.g. "\/Date(1198908717056)\/". + + + + + Specifies how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON text. + + + + + Date formatted strings are not parsed to a date type and are read as strings. + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Specifies how to treat the time value when converting between string and . + + + + + Treat as local time. If the object represents a Coordinated Universal Time (UTC), it is converted to the local time. + + + + + Treat as a UTC. If the object represents a local time, it is converted to a UTC. + + + + + Treat as a local time if a is being converted to a string. + If a string is being converted to , convert to a local time if a time zone is specified. + + + + + Time zone information should be preserved when converting. + + + + + The default JSON name table implementation. + + + + + Initializes a new instance of the class. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Adds the specified string into name table. + + The string to add. + This method is not thread-safe. + The resolved string. + + + + Specifies default value handling options for the . + + + + + + + + + Include members where the member value is the same as the member's default value when serializing objects. + Included members are written to JSON. Has no effect when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + so that it is not written to JSON. + This option will ignore all default values (e.g. null for objects and nullable types; 0 for integers, + decimals and floating point numbers; and false for booleans). The default value ignored can be changed by + placing the on the property. + + + + + Members with a default value but no JSON will be set to their default value when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + and set members to their default value when deserializing. + + + + + Specifies float format handling options when writing special floating point numbers, e.g. , + and with . + + + + + Write special floating point values as strings in JSON, e.g. "NaN", "Infinity", "-Infinity". + + + + + Write special floating point values as symbols in JSON, e.g. NaN, Infinity, -Infinity. + Note that this will produce non-valid JSON. + + + + + Write special floating point values as the property's default value in JSON, e.g. 0.0 for a property, null for a of property. + + + + + Specifies how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Floating point numbers are parsed to . + + + + + Floating point numbers are parsed to . + + + + + Specifies formatting options for the . + + + + + No special formatting is applied. This is the default. + + + + + Causes child objects to be indented according to the and settings. + + + + + Provides an interface for using pooled arrays. + + The array type content. + + + + Rent an array from the pool. This array must be returned when it is no longer needed. + + The minimum required length of the array. The returned array may be longer. + The rented array from the pool. This array must be returned when it is no longer needed. + + + + Return an array to the pool. + + The array that is being returned. + + + + Provides an interface to enable a class to return line and position information. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + The current line number or 0 if no line information is available (for example, when returns false). + + + + Gets the current line position. + + The current line position or 0 if no line information is available (for example, when returns false). + + + + Instructs the how to serialize the collection. + + + + + Gets or sets a value indicating whether null items are allowed in the collection. + + true if null items are allowed in the collection; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with a flag indicating whether the array can contain null items. + + A flag indicating whether the array can contain null items. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to use the specified constructor when deserializing that object. + + + + + Instructs the how to serialize the object. + + + + + Gets or sets the id. + + The id. + + + + Gets or sets the title. + + The title. + + + + Gets or sets the description. + + The description. + + + + Gets or sets the collection's items converter. + + The collection's items converter. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets a value that indicates whether to preserve object references. + + + true to keep object reference; otherwise, false. The default is false. + + + + + Gets or sets a value that indicates whether to preserve collection's items references. + + + true to keep collection's items object references; otherwise, false. The default is false. + + + + + Gets or sets the reference loop handling used when serializing the collection's items. + + The reference loop handling. + + + + Gets or sets the type name handling used when serializing the collection's items. + + The type name handling. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Provides methods for converting between .NET types and JSON types. + + + + + + + + Gets or sets a function that creates default . + Default settings are automatically used by serialization methods on , + and and on . + To serialize without using any default settings create a with + . + + + + + Represents JavaScript's boolean value true as a string. This field is read-only. + + + + + Represents JavaScript's boolean value false as a string. This field is read-only. + + + + + Represents JavaScript's null as a string. This field is read-only. + + + + + Represents JavaScript's undefined as a string. This field is read-only. + + + + + Represents JavaScript's positive infinity as a string. This field is read-only. + + + + + Represents JavaScript's negative infinity as a string. This field is read-only. + + + + + Represents JavaScript's NaN as a string. This field is read-only. + + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + The time zone handling when the date is converted to a string. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + The string escape handling. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Serializes the specified object to a JSON string. + + The object to serialize. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting. + + The object to serialize. + Indicates how the output should be formatted. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a collection of . + + The object to serialize. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting and a collection of . + + The object to serialize. + Indicates how the output should be formatted. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Deserializes the JSON to a .NET object. + + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to a .NET object using . + + The JSON to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The JSON to deserialize. + The of object being deserialized. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The type of the object to deserialize to. + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the given anonymous type. + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the given anonymous type using . + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The type of the object to deserialize to. + The JSON to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The type of the object to deserialize to. + The object to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The JSON to deserialize. + The type of the object to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The JSON to deserialize. + The type of the object to deserialize to. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Populates the object with values from the JSON string. + + The JSON to populate values from. + The target object to populate values onto. + + + + Populates the object with values from the JSON string using . + + The JSON to populate values from. + The target object to populate values onto. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + + + + Serializes the to a JSON string. + + The node to serialize. + A JSON string of the . + + + + Serializes the to a JSON string using formatting. + + The node to serialize. + Indicates how the output should be formatted. + A JSON string of the . + + + + Serializes the to a JSON string using formatting and omits the root object if is true. + + The node to serialize. + Indicates how the output should be formatted. + Omits writing the root object. + A JSON string of the . + + + + Deserializes the from a JSON string. + + The JSON string. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by . + + The JSON string. + The name of the root element to append when deserializing. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by + and writes a Json.NET array attribute for collections. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by , + writes a Json.NET array attribute for collections, and encodes special characters. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + + A value to indicate whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + The deserialized . + + + + Serializes the to a JSON string. + + The node to convert to JSON. + A JSON string of the . + + + + Serializes the to a JSON string using formatting. + + The node to convert to JSON. + Indicates how the output should be formatted. + A JSON string of the . + + + + Serializes the to a JSON string using formatting and omits the root object if is true. + + The node to serialize. + Indicates how the output should be formatted. + Omits writing the root object. + A JSON string of the . + + + + Deserializes the from a JSON string. + + The JSON string. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by . + + The JSON string. + The name of the root element to append when deserializing. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by + and writes a Json.NET array attribute for collections. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by , + writes a Json.NET array attribute for collections, and encodes special characters. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + + A value to indicate whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + The deserialized . + + + + Converts an object to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can read JSON. + + true if this can read JSON; otherwise, false. + + + + Gets a value indicating whether this can write JSON. + + true if this can write JSON; otherwise, false. + + + + Converts an object to and from JSON. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. If there is no existing value then null will be used. + The existing value has a value. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Instructs the to use the specified when serializing the member or class. + + + + + Gets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + + + + + Initializes a new instance of the class. + + Type of the . + + + + Initializes a new instance of the class. + + Type of the . + Parameter list to use when constructing the . Can be null. + + + + Represents a collection of . + + + + + Instructs the how to serialize the collection. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Instructs the to deserialize properties with no matching class member into the specified collection + and write values during serialization. + + + + + Gets or sets a value that indicates whether to write extension data when serializing the object. + + + true to write extension data when serializing the object; otherwise, false. The default is true. + + + + + Gets or sets a value that indicates whether to read extension data when deserializing the object. + + + true to read extension data when deserializing the object; otherwise, false. The default is true. + + + + + Initializes a new instance of the class. + + + + + Instructs the not to serialize the public field or public read/write property value. + + + + + Base class for a table of atomized string objects. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Instructs the how to serialize the object. + + + + + Gets or sets the member serialization. + + The member serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified member serialization. + + The member serialization. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to always serialize the member with the specified name. + + + + + Gets or sets the type used when serializing the property's collection items. + + The collection's items type. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the null value handling used when serializing this property. + + The null value handling. + + + + Gets or sets the default value handling used when serializing this property. + + The default value handling. + + + + Gets or sets the reference loop handling used when serializing this property. + + The reference loop handling. + + + + Gets or sets the object creation handling used when deserializing this property. + + The object creation handling. + + + + Gets or sets the type name handling used when serializing this property. + + The type name handling. + + + + Gets or sets whether this property's value is serialized as a reference. + + Whether this property's value is serialized as a reference. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets a value indicating whether this property is required. + + + A value indicating whether this property is required. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified name. + + Name of the property. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Specifies the state of the reader. + + + + + A read method has not been called. + + + + + The end of the file has been reached successfully. + + + + + Reader is at a property. + + + + + Reader is at the start of an object. + + + + + Reader is in an object. + + + + + Reader is at the start of an array. + + + + + Reader is in an array. + + + + + The method has been called. + + + + + Reader has just read a value. + + + + + Reader is at the start of a constructor. + + + + + Reader is in a constructor. + + + + + An error occurred that prevents the read operation from continuing. + + + + + The end of the file has been reached successfully. + + + + + Gets the current reader state. + + The current reader state. + + + + Gets or sets a value indicating whether the source should be closed when this reader is closed. + + + true to close the source when this reader is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether multiple pieces of JSON content can + be read from a continuous stream without erroring. + + + true to support reading multiple pieces of JSON content; otherwise false. + The default is false. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + Gets or sets how time zones are handled when reading JSON. + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Gets or sets how custom date formatted strings are parsed when reading JSON. + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets the type of the current JSON token. + + + + + Gets the text value of the current JSON token. + + + + + Gets the .NET type for the current JSON token. + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets or sets the culture used when reading JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Reads the next JSON token from the source. + + true if the next token was read successfully; false if there are no more tokens to read. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Skips the children of the current token. + + + + + Sets the current token. + + The new token. + + + + Sets the current token and value. + + The new token. + The value. + + + + Sets the current token and value. + + The new token. + The value. + A flag indicating whether the position index inside an array should be updated. + + + + Sets the state based on current token type. + + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Changes the reader's state to . + If is set to true, the source is also closed. + + + + + The exception thrown when an error occurs while reading JSON text. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Instructs the to always serialize the member, and to require that the member has a value. + + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Serializes and deserializes objects into and from the JSON format. + The enables you to control how objects are encoded into JSON. + + + + + Occurs when the errors during serialization and deserialization. + + + + + Gets or sets the used by the serializer when resolving references. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + + + + Gets or sets how reference loops (e.g. a class referencing itself) is handled. + The default value is . + + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets a collection that will be used during serialization. + + Collection that will be used during serialization. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets a value indicating whether there will be a check for additional JSON content after deserializing an object. + The default value is false. + + + true if there will be a check for additional JSON content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Creates a new instance. + The will not use default settings + from . + + + A new instance. + The will not use default settings + from . + + + + + Creates a new instance using the specified . + The will not use default settings + from . + + The settings to be applied to the . + + A new instance using the specified . + The will not use default settings + from . + + + + + Creates a new instance. + The will use default settings + from . + + + A new instance. + The will use default settings + from . + + + + + Creates a new instance using the specified . + The will use default settings + from as well as the specified . + + The settings to be applied to the . + + A new instance using the specified . + The will use default settings + from as well as the specified . + + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Deserializes the JSON structure contained by the specified . + + The that contains the JSON structure to deserialize. + The being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The type of the object to deserialize. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is Auto to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Specifies the settings on a object. + + + + + Gets or sets how reference loops (e.g. a class referencing itself) are handled. + The default value is . + + Reference loop handling. + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + Missing member handling. + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + Null value handling. + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + The default value handling. + + + + Gets or sets a collection that will be used during serialization. + + The converters. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + The preserve references handling. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + The type name handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + The contract resolver. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets the used by the serializer when resolving references. + + The reference resolver. + + + + Gets or sets a function that creates the used by the serializer when resolving references. + + A function that creates the used by the serializer when resolving references. + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the error handler called during serialization and deserialization. + + The error handler called during serialization and deserialization. + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets a value indicating whether there will be a check for additional content after deserializing an object. + The default value is false. + + + true if there will be a check for additional content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Represents a reader that provides fast, non-cached, forward-only access to JSON text data. + + + + + Initializes a new instance of the class with the specified . + + The containing the JSON data to read. + + + + Gets or sets the reader's property name table. + + + + + Gets or sets the reader's character buffer pool. + + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + + The current line number or 0 if no line information is available (for example, returns false). + + + + + Gets the current line position. + + + The current line position or 0 if no line information is available (for example, returns false). + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets or sets the writer's character array pool. + + + + + Gets or sets how many s to write for each level in the hierarchy when is set to . + + + + + Gets or sets which character to use to quote attribute values. + + + + + Gets or sets which character to use for indenting when is set to . + + + + + Gets or sets a value indicating whether object names will be surrounded with quotes. + + + + + Initializes a new instance of the class using the specified . + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying . + + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the specified end token. + + The end token to write. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Specifies the type of JSON token. + + + + + This is returned by the if a read method has not been called. + + + + + An object start token. + + + + + An array start token. + + + + + A constructor start token. + + + + + An object property name. + + + + + A comment. + + + + + Raw JSON. + + + + + An integer. + + + + + A float. + + + + + A string. + + + + + A boolean. + + + + + A null token. + + + + + An undefined token. + + + + + An object end token. + + + + + An array end token. + + + + + A constructor end token. + + + + + A Date. + + + + + Byte data. + + + + + + Represents a reader that provides validation. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Sets an event handler for receiving schema validation errors. + + + + + Gets the text value of the current JSON token. + + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + + Gets the type of the current JSON token. + + + + + + Gets the .NET type for the current JSON token. + + + + + + Initializes a new instance of the class that + validates the content returned from the given . + + The to read from while validating. + + + + Gets or sets the schema. + + The schema. + + + + Gets the used to construct this . + + The specified in the constructor. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a []. + + + A [] or null if the next JSON token is null. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets or sets a value indicating whether the destination should be closed when this writer is closed. + + + true to close the destination when this writer is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether the JSON should be auto-completed when this writer is closed. + + + true to auto-complete the JSON when this writer is closed; otherwise false. The default is true. + + + + + Gets the top. + + The top. + + + + Gets the state of the writer. + + + + + Gets the path of the writer. + + + + + Gets or sets a value indicating how JSON text output should be formatted. + + + + + Gets or sets how dates are written to JSON text. + + + + + Gets or sets how time zones are handled when writing JSON text. + + + + + Gets or sets how strings are escaped when writing JSON text. + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written to JSON text. + + + + + Gets or sets how and values are formatted when writing JSON text. + + + + + Gets or sets the culture used when writing JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the destination and also flushes the destination. + + + + + Closes this writer. + If is set to true, the destination is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the end of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the end of an array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end constructor. + + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes the end of the current JSON object or array. + + + + + Writes the current token and its children. + + The to read the token from. + + + + Writes the current token. + + The to read the token from. + A flag indicating whether the current token's children should be written. + + + + Writes the token and its value. + + The to write. + + The value to write. + A value is only required for tokens that have an associated value, e.g. the property name for . + null can be passed to the method for tokens that don't have a value, e.g. . + + + + + Writes the token. + + The to write. + + + + Writes the specified end token. + + The end token to write. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON without changing the writer's state. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Sets the state of the . + + The being written. + The value being written. + + + + The exception thrown when an error occurs while writing JSON text. + + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Specifies how JSON comments are handled when loading JSON. + + + + + Ignore comments. + + + + + Load comments as a with type . + + + + + Specifies how duplicate property names are handled when loading JSON. + + + + + Replace the existing value when there is a duplicate property. The value of the last property in the JSON object will be used. + + + + + Ignore the new value when there is a duplicate property. The value of the first property in the JSON object will be used. + + + + + Throw a when a duplicate property is encountered. + + + + + Contains the LINQ to JSON extension methods. + + + + + Returns a collection of tokens that contains the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the descendants of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, and the descendants of every token in the source collection. + + + + Returns a collection of child properties of every object in the source collection. + + An of that contains the source collection. + An of that contains the properties of every object in the source collection. + + + + Returns a collection of child values of every object in the source collection with the given key. + + An of that contains the source collection. + The token key. + An of that contains the values of every token in the source collection with the given key. + + + + Returns a collection of child values of every object in the source collection. + + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child values of every object in the source collection with the given key. + + The type to convert the values to. + An of that contains the source collection. + The token key. + An that contains the converted values of every token in the source collection with the given key. + + + + Returns a collection of converted child values of every object in the source collection. + + The type to convert the values to. + An of that contains the source collection. + An that contains the converted values of every token in the source collection. + + + + Converts the value. + + The type to convert the value to. + A cast as a of . + A converted value. + + + + Converts the value. + + The source collection type. + The type to convert the value to. + A cast as a of . + A converted value. + + + + Returns a collection of child tokens of every array in the source collection. + + The source collection type. + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child tokens of every array in the source collection. + + An of that contains the source collection. + The type to convert the values to. + The source collection type. + An that contains the converted values of every token in the source collection. + + + + Returns the input typed as . + + An of that contains the source collection. + The input typed as . + + + + Returns the input typed as . + + The source collection type. + An of that contains the source collection. + The input typed as . + + + + Represents a collection of objects. + + The type of token. + + + + Gets the of with the specified key. + + + + + + Represents a JSON array. + + + + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Loads an from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads an from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the at the specified index. + + + + + + Determines the index of a specific item in the . + + The object to locate in the . + + The index of if found in the list; otherwise, -1. + + + + + Inserts an item to the at the specified index. + + The zero-based index at which should be inserted. + The object to insert into the . + + is not a valid index in the . + + + + + Removes the item at the specified index. + + The zero-based index of the item to remove. + + is not a valid index in the . + + + + + Returns an enumerator that iterates through the collection. + + + A of that can be used to iterate through the collection. + + + + + Adds an item to the . + + The object to add to the . + + + + Removes all items from the . + + + + + Determines whether the contains a specific value. + + The object to locate in the . + + true if is found in the ; otherwise, false. + + + + + Copies the elements of the to an array, starting at a particular array index. + + The array. + Index of the array. + + + + Gets a value indicating whether the is read-only. + + true if the is read-only; otherwise, false. + + + + Removes the first occurrence of a specific object from the . + + The object to remove from the . + + true if was successfully removed from the ; otherwise, false. This method also returns false if is not found in the original . + + + + + Represents a JSON constructor. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets or sets the name of this constructor. + + The constructor name. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name. + + The constructor name. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a token that can contain other tokens. + + + + + Occurs when the list changes or an item in the list changes. + + + + + Occurs before an item is added to the collection. + + + + + Occurs when the items list of the collection has changed, or the collection is reset. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Raises the event. + + The instance containing the event data. + + + + Raises the event. + + The instance containing the event data. + + + + Raises the event. + + The instance containing the event data. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Get the first child token of this token. + + + A containing the first child token of the . + + + + + Get the last child token of this token. + + + A containing the last child token of the . + + + + + Returns a collection of the child tokens of this token, in document order. + + + An of containing the child tokens of this , in document order. + + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + + A containing the child values of this , in document order. + + + + + Returns a collection of the descendant tokens for this token in document order. + + An of containing the descendant tokens of the . + + + + Returns a collection of the tokens that contain this token, and all descendant tokens of this token, in document order. + + An of containing this token, and all the descendant tokens of the . + + + + Adds the specified content as children of this . + + The content to be added. + + + + Adds the specified content as the first children of this . + + The content to be added. + + + + Creates a that can be used to add tokens to the . + + A that is ready to have content written to it. + + + + Replaces the child nodes of this token with the specified content. + + The content. + + + + Removes the child nodes from this token. + + + + + Merge the specified content into this . + + The content to be merged. + + + + Merge the specified content into this using . + + The content to be merged. + The used to merge the content. + + + + Gets the count of child JSON tokens. + + The count of child JSON tokens. + + + + Represents a collection of objects. + + The type of token. + + + + An empty collection of objects. + + + + + Initializes a new instance of the struct. + + The enumerable. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Gets the of with the specified key. + + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Returns a hash code for this instance. + + + A hash code for this instance, suitable for use in hashing algorithms and data structures like a hash table. + + + + + Represents a JSON object. + + + + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Occurs when a property value changes. + + + + + Occurs when a property value is changing. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Gets the node type for this . + + The type. + + + + Gets an of of this object's properties. + + An of of this object's properties. + + + + Gets a with the specified name. + + The property name. + A with the specified name or null. + + + + Gets the with the specified name. + The exact name will be searched for first and if no matching property is found then + the will be used to match a property. + + The property name. + One of the enumeration values that specifies how the strings will be compared. + A matched with the specified name or null. + + + + Gets a of of this object's property values. + + A of of this object's property values. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the with the specified property name. + + + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified property name. + + Name of the property. + The with the specified property name. + + + + Gets the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + One of the enumeration values that specifies how the strings will be compared. + The with the specified property name. + + + + Tries to get the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + The value. + One of the enumeration values that specifies how the strings will be compared. + true if a value was successfully retrieved; otherwise, false. + + + + Adds the specified property name. + + Name of the property. + The value. + + + + Determines whether the JSON object has the specified property name. + + Name of the property. + true if the JSON object has the specified property name; otherwise, false. + + + + Removes the property with the specified name. + + Name of the property. + true if item was successfully removed; otherwise, false. + + + + Tries to get the with the specified property name. + + Name of the property. + The value. + true if a value was successfully retrieved; otherwise, false. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Raises the event with the provided arguments. + + Name of the property. + + + + Raises the event with the provided arguments. + + Name of the property. + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Represents a JSON property. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the property name. + + The property name. + + + + Gets or sets the property value. + + The property value. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a view of a . + + + + + Initializes a new instance of the class. + + The name. + + + + When overridden in a derived class, returns whether resetting an object changes its value. + + + true if resetting the component changes its value; otherwise, false. + + The component to test for reset capability. + + + + When overridden in a derived class, gets the current value of the property on a component. + + + The value of a property for a given component. + + The component with the property for which to retrieve the value. + + + + When overridden in a derived class, resets the value for this property of the component to the default value. + + The component with the property value that is to be reset to the default value. + + + + When overridden in a derived class, sets the value of the component to a different value. + + The component with the property value that is to be set. + The new value. + + + + When overridden in a derived class, determines a value indicating whether the value of this property needs to be persisted. + + + true if the property should be persisted; otherwise, false. + + The component with the property to be examined for persistence. + + + + When overridden in a derived class, gets the type of the component this property is bound to. + + + A that represents the type of component this property is bound to. + When the or + + methods are invoked, the object specified might be an instance of this type. + + + + + When overridden in a derived class, gets a value indicating whether this property is read-only. + + + true if the property is read-only; otherwise, false. + + + + + When overridden in a derived class, gets the type of the property. + + + A that represents the type of the property. + + + + + Gets the hash code for the name of the member. + + + + The hash code for the name of the member. + + + + + Represents a raw JSON string. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class. + + The raw json. + + + + Creates an instance of with the content of the reader's current token. + + The reader. + An instance of with the content of the reader's current token. + + + + Specifies the settings used when loading JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets how JSON comments are handled when loading JSON. + The default value is . + + The JSON comment handling. + + + + Gets or sets how JSON line info is handled when loading JSON. + The default value is . + + The JSON line info handling. + + + + Gets or sets how duplicate property names in JSON objects are handled when loading JSON. + The default value is . + + The JSON duplicate property name handling. + + + + Specifies the settings used when merging JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets the method used when merging JSON arrays. + + The method used when merging JSON arrays. + + + + Gets or sets how null value properties are merged. + + How null value properties are merged. + + + + Gets or sets the comparison used to match property names while merging. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + The comparison used to match property names while merging. + + + + Specifies the settings used when selecting JSON. + + + + + Gets or sets a flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + A flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + + + Represents an abstract JSON token. + + + + + Gets a comparer that can compare two tokens for value equality. + + A that can compare two nodes for value equality. + + + + Gets or sets the parent. + + The parent. + + + + Gets the root of this . + + The root of this . + + + + Gets the node type for this . + + The type. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Compares the values of two tokens, including the values of all descendant tokens. + + The first to compare. + The second to compare. + true if the tokens are equal; otherwise false. + + + + Gets the next sibling token of this node. + + The that contains the next sibling token. + + + + Gets the previous sibling token of this node. + + The that contains the previous sibling token. + + + + Gets the path of the JSON token. + + + + + Adds the specified content immediately after this token. + + A content object that contains simple content or a collection of content objects to be added after this token. + + + + Adds the specified content immediately before this token. + + A content object that contains simple content or a collection of content objects to be added before this token. + + + + Returns a collection of the ancestor tokens of this token. + + A collection of the ancestor tokens of this token. + + + + Returns a collection of tokens that contain this token, and the ancestors of this token. + + A collection of tokens that contain this token, and the ancestors of this token. + + + + Returns a collection of the sibling tokens after this token, in document order. + + A collection of the sibling tokens after this tokens, in document order. + + + + Returns a collection of the sibling tokens before this token, in document order. + + A collection of the sibling tokens before this token, in document order. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets the with the specified key converted to the specified type. + + The type to convert the token to. + The token key. + The converted token value. + + + + Get the first child token of this token. + + A containing the first child token of the . + + + + Get the last child token of this token. + + A containing the last child token of the . + + + + Returns a collection of the child tokens of this token, in document order. + + An of containing the child tokens of this , in document order. + + + + Returns a collection of the child tokens of this token, in document order, filtered by the specified type. + + The type to filter the child tokens on. + A containing the child tokens of this , in document order. + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + A containing the child values of this , in document order. + + + + Removes this token from its parent. + + + + + Replaces this token with the specified token. + + The value. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Returns the indented JSON for this token. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + The indented JSON for this token. + + + + + Returns the JSON for this token using the given formatting and converters. + + Indicates how the output should be formatted. + A collection of s which will be used when writing the token. + The JSON for this token using the given formatting and converters. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to []. + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from [] to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Creates a for this token. + + A that can be used to read this token and its descendants. + + + + Creates a from an object. + + The object that will be used to create . + A with the value of the specified object. + + + + Creates a from an object using the specified . + + The object that will be used to create . + The that will be used when reading the object. + A with the value of the specified object. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + An positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + Creates a from a . + + A positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A , or null. + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + A . + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + The used to select tokens. + A . + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + The used to select tokens. + An of that contains the selected elements. + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Creates a new instance of the . All child tokens are recursively cloned. + + A new instance of the . + + + + Adds an object to the annotation list of this . + + The annotation to add. + + + + Get the first annotation object of the specified type from this . + + The type of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets the first annotation object of the specified type from this . + + The of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets a collection of annotations of the specified type for this . + + The type of the annotations to retrieve. + An that contains the annotations for this . + + + + Gets a collection of annotations of the specified type for this . + + The of the annotations to retrieve. + An of that contains the annotations that match the specified type for this . + + + + Removes the annotations of the specified type from this . + + The type of annotations to remove. + + + + Removes the annotations of the specified type from this . + + The of annotations to remove. + + + + Compares tokens to determine whether they are equal. + + + + + Determines whether the specified objects are equal. + + The first object of type to compare. + The second object of type to compare. + + true if the specified objects are equal; otherwise, false. + + + + + Returns a hash code for the specified object. + + The for which a hash code is to be returned. + A hash code for the specified object. + The type of is a reference type and is null. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Gets the at the reader's current position. + + + + + Initializes a new instance of the class. + + The token to read from. + + + + Initializes a new instance of the class. + + The token to read from. + The initial path of the token. It is prepended to the returned . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Gets the path of the current JSON token. + + + + + Specifies the type of token. + + + + + No token type has been set. + + + + + A JSON object. + + + + + A JSON array. + + + + + A JSON constructor. + + + + + A JSON object property. + + + + + A comment. + + + + + An integer value. + + + + + A float value. + + + + + A string value. + + + + + A boolean value. + + + + + A null value. + + + + + An undefined value. + + + + + A date value. + + + + + A raw JSON value. + + + + + A collection of bytes value. + + + + + A Guid value. + + + + + A Uri value. + + + + + A TimeSpan value. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets the at the writer's current position. + + + + + Gets the token being written. + + The token being written. + + + + Initializes a new instance of the class writing to the given . + + The container being written to. + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the underlying . + + + + + Closes this writer. + If is set to true, the JSON is auto-completed. + + + Setting to true has no additional effect, since the underlying is a type that cannot be closed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end. + + The token. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes a value. + An error will be raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Represents a value in JSON (string, integer, date, etc). + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Creates a comment with the given value. + + The value. + A comment with the given value. + + + + Creates a string with the given value. + + The value. + A string with the given value. + + + + Creates a null value. + + A null value. + + + + Creates a undefined value. + + A undefined value. + + + + Gets the node type for this . + + The type. + + + + Gets or sets the underlying token value. + + The underlying token value. + + + + Writes this token to a . + + A into which this method will write. + A collection of s which will be used when writing the token. + + + + Indicates whether the current object is equal to another object of the same type. + + + true if the current object is equal to the parameter; otherwise, false. + + An object to compare with this object. + + + + Determines whether the specified is equal to the current . + + The to compare with the current . + + true if the specified is equal to the current ; otherwise, false. + + + + + Serves as a hash function for a particular type. + + + A hash code for the current . + + + + + Returns a that represents this instance. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format provider. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + The format provider. + + A that represents this instance. + + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Compares the current instance with another object of the same type and returns an integer that indicates whether the current instance precedes, follows, or occurs in the same position in the sort order as the other object. + + An object to compare with this instance. + + A 32-bit signed integer that indicates the relative order of the objects being compared. The return value has these meanings: + Value + Meaning + Less than zero + This instance is less than . + Zero + This instance is equal to . + Greater than zero + This instance is greater than . + + + is not of the same type as this instance. + + + + + Specifies how line information is handled when loading JSON. + + + + + Ignore line information. + + + + + Load line information. + + + + + Specifies how JSON arrays are merged together. + + + + Concatenate arrays. + + + Union arrays, skipping items that already exist. + + + Replace all array items. + + + Merge array items together, matched by index. + + + + Specifies how null value properties are merged. + + + + + The content's null value properties will be ignored during merging. + + + + + The content's null value properties will be merged. + + + + + Specifies the member serialization options for the . + + + + + All public members are serialized by default. Members can be excluded using or . + This is the default member serialization mode. + + + + + Only members marked with or are serialized. + This member serialization mode can also be set by marking the class with . + + + + + All public and private fields are serialized. Members can be excluded using or . + This member serialization mode can also be set by marking the class with + and setting IgnoreSerializableAttribute on to false. + + + + + Specifies metadata property handling options for the . + + + + + Read metadata properties located at the start of a JSON object. + + + + + Read metadata properties located anywhere in a JSON object. Note that this setting will impact performance. + + + + + Do not try to read metadata properties. + + + + + Specifies missing member handling options for the . + + + + + Ignore a missing member and do not attempt to deserialize it. + + + + + Throw a when a missing member is encountered during deserialization. + + + + + Specifies null value handling options for the . + + + + + + + + + Include null values when serializing and deserializing objects. + + + + + Ignore null values when serializing and deserializing objects. + + + + + Specifies how object creation is handled by the . + + + + + Reuse existing objects, create new objects when needed. + + + + + Only reuse existing objects. + + + + + Always create new objects. + + + + + Specifies reference handling options for the . + Note that references cannot be preserved when a value is set via a non-default constructor such as types that implement . + + + + + + + + Do not preserve references when serializing types. + + + + + Preserve references when serializing into a JSON object structure. + + + + + Preserve references when serializing into a JSON array structure. + + + + + Preserve references when serializing. + + + + + Specifies reference loop handling options for the . + + + + + Throw a when a loop is encountered. + + + + + Ignore loop references and do not serialize. + + + + + Serialize loop references. + + + + + Indicating whether a property is required. + + + + + The property is not required. The default state. + + + + + The property must be defined in JSON but can be a null value. + + + + + The property must be defined in JSON and cannot be a null value. + + + + + The property is not required but it cannot be a null value. + + + + + + Contains the JSON schema extension methods. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + true if the specified is valid; otherwise, false. + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + When this method returns, contains any error messages generated while validating. + + true if the specified is valid; otherwise, false. + + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + The validation event handler. + + + + + An in-memory representation of a JSON Schema. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the id. + + + + + Gets or sets the title. + + + + + Gets or sets whether the object is required. + + + + + Gets or sets whether the object is read-only. + + + + + Gets or sets whether the object is visible to users. + + + + + Gets or sets whether the object is transient. + + + + + Gets or sets the description of the object. + + + + + Gets or sets the types of values allowed by the object. + + The type. + + + + Gets or sets the pattern. + + The pattern. + + + + Gets or sets the minimum length. + + The minimum length. + + + + Gets or sets the maximum length. + + The maximum length. + + + + Gets or sets a number that the value should be divisible by. + + A number that the value should be divisible by. + + + + Gets or sets the minimum. + + The minimum. + + + + Gets or sets the maximum. + + The maximum. + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the minimum attribute (). + + A flag indicating whether the value can not equal the number defined by the minimum attribute (). + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the maximum attribute (). + + A flag indicating whether the value can not equal the number defined by the maximum attribute (). + + + + Gets or sets the minimum number of items. + + The minimum number of items. + + + + Gets or sets the maximum number of items. + + The maximum number of items. + + + + Gets or sets the of items. + + The of items. + + + + Gets or sets a value indicating whether items in an array are validated using the instance at their array position from . + + + true if items are validated using their array position; otherwise, false. + + + + + Gets or sets the of additional items. + + The of additional items. + + + + Gets or sets a value indicating whether additional items are allowed. + + + true if additional items are allowed; otherwise, false. + + + + + Gets or sets whether the array items must be unique. + + + + + Gets or sets the of properties. + + The of properties. + + + + Gets or sets the of additional properties. + + The of additional properties. + + + + Gets or sets the pattern properties. + + The pattern properties. + + + + Gets or sets a value indicating whether additional properties are allowed. + + + true if additional properties are allowed; otherwise, false. + + + + + Gets or sets the required property if this property is present. + + The required property if this property is present. + + + + Gets or sets the a collection of valid enum values allowed. + + A collection of valid enum values allowed. + + + + Gets or sets disallowed types. + + The disallowed types. + + + + Gets or sets the default value. + + The default value. + + + + Gets or sets the collection of that this schema extends. + + The collection of that this schema extends. + + + + Gets or sets the format. + + The format. + + + + Initializes a new instance of the class. + + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The object representing the JSON Schema. + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The to use when resolving schema references. + The object representing the JSON Schema. + + + + Load a from a string that contains JSON Schema. + + A that contains JSON Schema. + A populated from the string that contains JSON Schema. + + + + Load a from a string that contains JSON Schema using the specified . + + A that contains JSON Schema. + The resolver. + A populated from the string that contains JSON Schema. + + + + Writes this schema to a . + + A into which this method will write. + + + + Writes this schema to a using the specified . + + A into which this method will write. + The resolver used. + + + + Returns a that represents the current . + + + A that represents the current . + + + + + + Returns detailed information about the schema exception. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + + Generates a from a specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets how undefined schemas are handled by the serializer. + + + + + Gets or sets the contract resolver. + + The contract resolver. + + + + Generate a from the specified type. + + The type to generate a from. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + + Resolves from an id. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the loaded schemas. + + The loaded schemas. + + + + Initializes a new instance of the class. + + + + + Gets a for the specified reference. + + The id. + A for the specified reference. + + + + + The value types allowed by the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + No type specified. + + + + + String type. + + + + + Float type. + + + + + Integer type. + + + + + Boolean type. + + + + + Object type. + + + + + Array type. + + + + + Null type. + + + + + Any type. + + + + + + Specifies undefined schema Id handling options for the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Do not infer a schema Id. + + + + + Use the .NET type name as the schema Id. + + + + + Use the assembly qualified .NET type name as the schema Id. + + + + + + Returns detailed information related to the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the associated with the validation error. + + The JsonSchemaException associated with the validation error. + + + + Gets the path of the JSON location where the validation error occurred. + + The path of the JSON location where the validation error occurred. + + + + Gets the text description corresponding to the validation error. + + The text description. + + + + + Represents the callback method that will handle JSON schema validation events and the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + A camel case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Resolves member mappings for a type, camel casing property names. + + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used by to resolve a for a given . + + + + + Gets a value indicating whether members are being get and set using dynamic code generation. + This value is determined by the runtime permissions available. + + + true if using dynamic code generation; otherwise, false. + + + + + Gets or sets the default members search flags. + + The default members search flags. + + + + Gets or sets a value indicating whether compiler generated members should be serialized. + + + true if serialized compiler generated members; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore the interface when serializing and deserializing types. + + + true if the interface will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore the attribute when serializing and deserializing types. + + + true if the attribute will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore IsSpecified members when serializing and deserializing types. + + + true if the IsSpecified members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore ShouldSerialize members when serializing and deserializing types. + + + true if the ShouldSerialize members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets the naming strategy used to resolve how property names and dictionary keys are serialized. + + The naming strategy used to resolve how property names and dictionary keys are serialized. + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Gets the serializable members for the type. + + The type to get serializable members for. + The serializable members for the type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates the constructor parameters. + + The constructor to create properties for. + The type's member properties. + Properties for the given . + + + + Creates a for the given . + + The matching member property. + The constructor parameter. + A created for the given . + + + + Resolves the default for the contract. + + Type of the object. + The contract's default . + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Determines which contract type is created for the given type. + + Type of the object. + A for the given type. + + + + Creates properties for the given . + + The type to create properties for. + /// The member serialization mode for the type. + Properties for the given . + + + + Creates the used by the serializer to get and set values from a member. + + The member. + The used by the serializer to get and set values from a member. + + + + Creates a for the given . + + The member's parent . + The member to create a for. + A created for the given . + + + + Resolves the name of the property. + + Name of the property. + Resolved name of the property. + + + + Resolves the name of the extension data. By default no changes are made to extension data names. + + Name of the extension data. + Resolved name of the extension data. + + + + Resolves the key of the dictionary. By default is used to resolve dictionary keys. + + Key of the dictionary. + Resolved key of the dictionary. + + + + Gets the resolved name of the property. + + Name of the property. + Name of the property. + + + + The default naming strategy. Property names and dictionary keys are unchanged. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + The default serialization binder used when resolving and loading classes from type names. + + + + + Initializes a new instance of the class. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + The type of the object the formatter creates a new instance of. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Represents a trace writer that writes to the application's instances. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + + The that will be used to filter the trace messages passed to the writer. + + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Get and set values for a using dynamic methods. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Provides information surrounding an error. + + + + + Gets the error. + + The error. + + + + Gets the original object that caused the error. + + The original object that caused the error. + + + + Gets the member that caused the error. + + The member that caused the error. + + + + Gets the path of the JSON location where the error occurred. + + The path of the JSON location where the error occurred. + + + + Gets or sets a value indicating whether this is handled. + + true if handled; otherwise, false. + + + + Provides data for the Error event. + + + + + Gets the current object the error event is being raised against. + + The current object the error event is being raised against. + + + + Gets the error context. + + The error context. + + + + Initializes a new instance of the class. + + The current object. + The error context. + + + + Get and set values for a using dynamic methods. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Provides methods to get attributes. + + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Used by to resolve a for a given . + + + + + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used to resolve references when serializing and deserializing JSON by the . + + + + + Resolves a reference to its object. + + The serialization context. + The reference to resolve. + The object that was resolved from the reference. + + + + Gets the reference for the specified object. + + The serialization context. + The object to get a reference for. + The reference to the object. + + + + Determines whether the specified object is referenced. + + The serialization context. + The object to test for a reference. + + true if the specified object is referenced; otherwise, false. + + + + + Adds a reference to the specified object. + + The serialization context. + The reference. + The object to reference. + + + + Allows users to control class loading and mandate what class to load. + + + + + When implemented, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object + The type of the object the formatter creates a new instance of. + + + + When implemented, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Represents a trace writer. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + The that will be used to filter the trace messages passed to the writer. + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Provides methods to get and set values. + + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Contract details for a used by the . + + + + + Gets the of the collection items. + + The of the collection items. + + + + Gets a value indicating whether the collection type is a multidimensional array. + + true if the collection type is a multidimensional array; otherwise, false. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the collection values. + + true if the creator has a parameter with the collection values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the default collection items . + + The converter. + + + + Gets or sets a value indicating whether the collection items preserve object references. + + true if collection items preserve object references; otherwise, false. + + + + Gets or sets the collection item reference loop handling. + + The reference loop handling. + + + + Gets or sets the collection item type name handling. + + The type name handling. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Handles serialization callback events. + + The object that raised the callback event. + The streaming context. + + + + Handles serialization error callback events. + + The object that raised the callback event. + The streaming context. + The error context. + + + + Sets extension data for an object during deserialization. + + The object to set extension data on. + The extension data key. + The extension data value. + + + + Gets extension data for an object during serialization. + + The object to set extension data on. + + + + Contract details for a used by the . + + + + + Gets the underlying type for the contract. + + The underlying type for the contract. + + + + Gets or sets the type created during deserialization. + + The type created during deserialization. + + + + Gets or sets whether this type contract is serialized as a reference. + + Whether this type contract is serialized as a reference. + + + + Gets or sets the default for this contract. + + The converter. + + + + Gets the internally resolved for the contract's type. + This converter is used as a fallback converter when no other converter is resolved. + Setting will always override this converter. + + + + + Gets or sets all methods called immediately after deserialization of the object. + + The methods called immediately after deserialization of the object. + + + + Gets or sets all methods called during deserialization of the object. + + The methods called during deserialization of the object. + + + + Gets or sets all methods called after serialization of the object graph. + + The methods called after serialization of the object graph. + + + + Gets or sets all methods called before serialization of the object. + + The methods called before serialization of the object. + + + + Gets or sets all method called when an error is thrown during the serialization of the object. + + The methods called when an error is thrown during the serialization of the object. + + + + Gets or sets the default creator method used to create the object. + + The default creator method used to create the object. + + + + Gets or sets a value indicating whether the default creator is non-public. + + true if the default object creator is non-public; otherwise, false. + + + + Contract details for a used by the . + + + + + Gets or sets the dictionary key resolver. + + The dictionary key resolver. + + + + Gets the of the dictionary keys. + + The of the dictionary keys. + + + + Gets the of the dictionary values. + + The of the dictionary values. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the dictionary values. + + true if the creator has a parameter with the dictionary values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets the object's properties. + + The object's properties. + + + + Gets or sets the property name resolver. + + The property name resolver. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object constructor. + + The object constructor. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object member serialization. + + The member object serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets the object's properties. + + The object's properties. + + + + Gets a collection of instances that define the parameters used with . + + + + + Gets or sets the function used to create the object. When set this function will override . + This function is called with a collection of arguments which are defined by the collection. + + The function used to create the object. + + + + Gets or sets the extension data setter. + + + + + Gets or sets the extension data getter. + + + + + Gets or sets the extension data value type. + + + + + Gets or sets the extension data name resolver. + + The extension data name resolver. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Maps a JSON property to a .NET member or constructor parameter. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the type that declared this property. + + The type that declared this property. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets the name of the underlying member or parameter. + + The name of the underlying member or parameter. + + + + Gets the that will get and set the during serialization. + + The that will get and set the during serialization. + + + + Gets or sets the for this property. + + The for this property. + + + + Gets or sets the type of the property. + + The type of the property. + + + + Gets or sets the for the property. + If set this converter takes precedence over the contract converter for the property type. + + The converter. + + + + Gets or sets the member converter. + + The member converter. + + + + Gets or sets a value indicating whether this is ignored. + + true if ignored; otherwise, false. + + + + Gets or sets a value indicating whether this is readable. + + true if readable; otherwise, false. + + + + Gets or sets a value indicating whether this is writable. + + true if writable; otherwise, false. + + + + Gets or sets a value indicating whether this has a member attribute. + + true if has a member attribute; otherwise, false. + + + + Gets the default value. + + The default value. + + + + Gets or sets a value indicating whether this is required. + + A value indicating whether this is required. + + + + Gets a value indicating whether has a value specified. + + + + + Gets or sets a value indicating whether this property preserves object references. + + + true if this instance is reference; otherwise, false. + + + + + Gets or sets the property null value handling. + + The null value handling. + + + + Gets or sets the property default value handling. + + The default value handling. + + + + Gets or sets the property reference loop handling. + + The reference loop handling. + + + + Gets or sets the property object creation handling. + + The object creation handling. + + + + Gets or sets or sets the type name handling. + + The type name handling. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets a predicate used to determine whether the property should be deserialized. + + A predicate used to determine whether the property should be deserialized. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets an action used to set whether the property has been deserialized. + + An action used to set whether the property has been deserialized. + + + + Returns a that represents this instance. + + + A that represents this instance. + + + + + Gets or sets the converter used when serializing the property's collection items. + + The collection's items converter. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + A collection of objects. + + + + + Initializes a new instance of the class. + + The type. + + + + When implemented in a derived class, extracts the key from the specified element. + + The element from which to extract the key. + The key for the specified element. + + + + Adds a object. + + The property to add to the collection. + + + + Gets the closest matching object. + First attempts to get an exact case match of and then + a case insensitive match. + + Name of the property. + A matching property if found. + + + + Gets a property by property name. + + The name of the property to get. + Type property name string comparison. + A matching property if found. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Lookup and create an instance of the type described by the argument. + + The type to create. + Optional arguments to pass to an initializing constructor of the JsonConverter. + If null, the default constructor is used. + + + + A kebab case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Represents a trace writer that writes to memory. When the trace message limit is + reached then old trace messages will be removed as new messages are added. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + + The that will be used to filter the trace messages passed to the writer. + + + + + Initializes a new instance of the class. + + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Returns an enumeration of the most recent trace messages. + + An enumeration of the most recent trace messages. + + + + Returns a of the most recent trace messages. + + + A of the most recent trace messages. + + + + + A base class for resolving how property names and dictionary keys are serialized. + + + + + A flag indicating whether dictionary keys should be processed. + Defaults to false. + + + + + A flag indicating whether extension data names should be processed. + Defaults to false. + + + + + A flag indicating whether explicitly specified property names, + e.g. a property name customized with a , should be processed. + Defaults to false. + + + + + Gets the serialized name for a given property name. + + The initial property name. + A flag indicating whether the property has had a name explicitly specified. + The serialized property name. + + + + Gets the serialized name for a given extension data name. + + The initial extension data name. + The serialized extension data name. + + + + Gets the serialized key for a given dictionary key. + + The initial dictionary key. + The serialized dictionary key. + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Hash code calculation + + + + + + Object equality implementation + + + + + + + Compare to another NamingStrategy + + + + + + + Represents a method that constructs an object. + + The object type to create. + + + + When applied to a method, specifies that the method is called when an error occurs serializing an object. + + + + + Provides methods to get attributes from a , , or . + + + + + Initializes a new instance of the class. + + The instance to get attributes for. This parameter should be a , , or . + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Get and set values for a using reflection. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + A snake case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Specifies how strings are escaped when writing JSON text. + + + + + Only control characters (e.g. newline) are escaped. + + + + + All non-ASCII and control characters (e.g. newline) are escaped. + + + + + HTML (<, >, &, ', ") and control characters (e.g. newline) are escaped. + + + + + Indicates the method that will be used during deserialization for locating and loading assemblies. + + + + + In simple mode, the assembly used during deserialization need not match exactly the assembly used during serialization. Specifically, the version numbers need not match as the LoadWithPartialName method of the class is used to load the assembly. + + + + + In full mode, the assembly used during deserialization must match exactly the assembly used during serialization. The Load method of the class is used to load the assembly. + + + + + Specifies type name handling options for the . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Do not include the .NET type name when serializing types. + + + + + Include the .NET type name when serializing into a JSON object structure. + + + + + Include the .NET type name when serializing into a JSON array structure. + + + + + Always include the .NET type name when serializing. + + + + + Include the .NET type name when the type of the object being serialized is not the same as its declared type. + Note that this doesn't include the root serialized object by default. To include the root object's type name in JSON + you must specify a root type object with + or . + + + + + Determines whether the collection is null or empty. + + The collection. + + true if the collection is null or empty; otherwise, false. + + + + + Adds the elements of the specified collection to the specified generic . + + The list to add to. + The collection of elements to add. + + + + Converts the value to the specified type. If the value is unable to be converted, the + value is checked whether it assignable to the specified type. + + The value to convert. + The culture to use when converting. + The type to convert or cast the value to. + + The converted type. If conversion was unsuccessful, the initial value + is returned if assignable to the target type. + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic that returns a result + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic, but uses one of the arguments for + the result. + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic, but uses one of the arguments for + the result. + + + + + Returns a Restrictions object which includes our current restrictions merged + with a restriction limiting our type + + + + + Helper class for serializing immutable collections. + Note that this is used by all builds, even those that don't support immutable collections, in case the DLL is GACed + https://github.com/JamesNK/Newtonsoft.Json/issues/652 + + + + + Gets the type of the typed collection's items. + + The type. + The type of the typed collection's items. + + + + Gets the member's underlying type. + + The member. + The underlying type of the member. + + + + Determines whether the property is an indexed property. + + The property. + + true if the property is an indexed property; otherwise, false. + + + + + Gets the member's value on the object. + + The member. + The target object. + The member's value on the object. + + + + Sets the member's value on the target object. + + The member. + The target. + The value. + + + + Determines whether the specified MemberInfo can be read. + + The MemberInfo to determine whether can be read. + /// if set to true then allow the member to be gotten non-publicly. + + true if the specified MemberInfo can be read; otherwise, false. + + + + + Determines whether the specified MemberInfo can be set. + + The MemberInfo to determine whether can be set. + if set to true then allow the member to be set non-publicly. + if set to true then allow the member to be set if read-only. + + true if the specified MemberInfo can be set; otherwise, false. + + + + + Builds a string. Unlike this class lets you reuse its internal buffer. + + + + + Determines whether the string is all white space. Empty string will return false. + + The string to test whether it is all white space. + + true if the string is all white space; otherwise, false. + + + + + Specifies the state of the . + + + + + An exception has been thrown, which has left the in an invalid state. + You may call the method to put the in the Closed state. + Any other method calls result in an being thrown. + + + + + The method has been called. + + + + + An object is being written. + + + + + An array is being written. + + + + + A constructor is being written. + + + + + A property is being written. + + + + + A write method has not been called. + + + + Specifies that an output will not be null even if the corresponding type allows it. + + + Specifies that when a method returns , the parameter will not be null even if the corresponding type allows it. + + + Initializes the attribute with the specified return value condition. + + The return value condition. If the method returns this value, the associated parameter will not be null. + + + + Gets the return value condition. + + + Specifies that an output may be null even if the corresponding type disallows it. + + + Specifies that null is allowed as an input even if the corresponding type disallows it. + + + + Specifies that the method will not return if the associated Boolean parameter is passed the specified value. + + + + + Initializes a new instance of the class. + + + The condition parameter value. Code after the method will be considered unreachable by diagnostics if the argument to + the associated parameter matches this value. + + + + Gets the condition parameter value. + + + diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/net45/Newtonsoft.Json.dll b/Packages/Newtonsoft.Json.13.0.1/lib/net45/Newtonsoft.Json.dll new file mode 100644 index 0000000..7af125a Binary files /dev/null and b/Packages/Newtonsoft.Json.13.0.1/lib/net45/Newtonsoft.Json.dll differ diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/net45/Newtonsoft.Json.xml b/Packages/Newtonsoft.Json.13.0.1/lib/net45/Newtonsoft.Json.xml new file mode 100644 index 0000000..008e0ca --- /dev/null +++ b/Packages/Newtonsoft.Json.13.0.1/lib/net45/Newtonsoft.Json.xml @@ -0,0 +1,11305 @@ + + + + Newtonsoft.Json + + + + + Represents a BSON Oid (object id). + + + + + Gets or sets the value of the Oid. + + The value of the Oid. + + + + Initializes a new instance of the class. + + The Oid value. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized BSON data. + + + + + Gets or sets a value indicating whether binary data reading should be compatible with incorrect Json.NET 3.5 written binary. + + + true if binary data reading will be compatible with incorrect Json.NET 3.5 written binary; otherwise, false. + + + + + Gets or sets a value indicating whether the root object will be read as a JSON array. + + + true if the root object will be read as a JSON array; otherwise, false. + + + + + Gets or sets the used when reading values from BSON. + + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating BSON data. + + + + + Gets or sets the used when writing values to BSON. + When set to no conversion will occur. + + The used when writing values to BSON. + + + + Initializes a new instance of the class. + + The to write to. + + + + Initializes a new instance of the class. + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying stream. + + + + + Writes the end. + + The token. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes the beginning of a JSON array. + + + + + Writes the beginning of a JSON object. + + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value that represents a BSON object id. + + The Object ID value to write. + + + + Writes a BSON regex. + + The regex pattern. + The regex options. + + + + Specifies how constructors are used when initializing objects during deserialization by the . + + + + + First attempt to use the public default constructor, then fall back to a single parameterized constructor, then to the non-public default constructor. + + + + + Json.NET will use a non-public default constructor before falling back to a parameterized constructor. + + + + + Converts a binary value to and from a base 64 string value. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Creates a custom object. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Creates an object which will then be populated by the serializer. + + Type of the object. + The created object. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can write JSON. + + + true if this can write JSON; otherwise, false. + + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Provides a base class for converting a to and from JSON. + + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a F# discriminated union type to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an Entity Framework to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can write JSON. + + + true if this can write JSON; otherwise, false. + + + + + Converts a to and from the ISO 8601 date format (e.g. "2008-04-12T12:53Z"). + + + + + Gets or sets the date time styles used when converting a date to and from JSON. + + The date time styles used when converting a date to and from JSON. + + + + Gets or sets the date time format used when converting a date to and from JSON. + + The date time format used when converting a date to and from JSON. + + + + Gets or sets the culture used when converting a date to and from JSON. + + The culture used when converting a date to and from JSON. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Converts a to and from a JavaScript Date constructor (e.g. new Date(52231943)). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an to and from its name string value. + + + + + Gets or sets a value indicating whether the written enum text should be camel case. + The default value is false. + + true if the written enum text will be camel case; otherwise, false. + + + + Gets or sets the naming strategy used to resolve how enum text is written. + + The naming strategy used to resolve how enum text is written. + + + + Gets or sets a value indicating whether integer values are allowed when serializing and deserializing. + The default value is true. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class. + + true if the written enum text will be camel case; otherwise, false. + + + + Initializes a new instance of the class. + + The naming strategy used to resolve how enum text is written. + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from Unix epoch time + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from a string (e.g. "1.2.3.4"). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts XML to and from JSON. + + + + + Gets or sets the name of the root element to insert when deserializing to XML if the JSON structure has produced multiple root elements. + + The name of the deserialized root element. + + + + Gets or sets a value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + true if the array attribute is written to the XML; otherwise, false. + + + + Gets or sets a value indicating whether to write the root JSON object. + + true if the JSON root object is omitted; otherwise, false. + + + + Gets or sets a value indicating whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + true if special characters are encoded; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The calling serializer. + The value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Checks if the is a namespace attribute. + + Attribute name to test. + The attribute name prefix if it has one, otherwise an empty string. + true if attribute name is for a namespace attribute, otherwise false. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Specifies how dates are formatted when writing JSON text. + + + + + Dates are written in the ISO 8601 format, e.g. "2012-03-21T05:40Z". + + + + + Dates are written in the Microsoft JSON format, e.g. "\/Date(1198908717056)\/". + + + + + Specifies how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON text. + + + + + Date formatted strings are not parsed to a date type and are read as strings. + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Specifies how to treat the time value when converting between string and . + + + + + Treat as local time. If the object represents a Coordinated Universal Time (UTC), it is converted to the local time. + + + + + Treat as a UTC. If the object represents a local time, it is converted to a UTC. + + + + + Treat as a local time if a is being converted to a string. + If a string is being converted to , convert to a local time if a time zone is specified. + + + + + Time zone information should be preserved when converting. + + + + + The default JSON name table implementation. + + + + + Initializes a new instance of the class. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Adds the specified string into name table. + + The string to add. + This method is not thread-safe. + The resolved string. + + + + Specifies default value handling options for the . + + + + + + + + + Include members where the member value is the same as the member's default value when serializing objects. + Included members are written to JSON. Has no effect when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + so that it is not written to JSON. + This option will ignore all default values (e.g. null for objects and nullable types; 0 for integers, + decimals and floating point numbers; and false for booleans). The default value ignored can be changed by + placing the on the property. + + + + + Members with a default value but no JSON will be set to their default value when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + and set members to their default value when deserializing. + + + + + Specifies float format handling options when writing special floating point numbers, e.g. , + and with . + + + + + Write special floating point values as strings in JSON, e.g. "NaN", "Infinity", "-Infinity". + + + + + Write special floating point values as symbols in JSON, e.g. NaN, Infinity, -Infinity. + Note that this will produce non-valid JSON. + + + + + Write special floating point values as the property's default value in JSON, e.g. 0.0 for a property, null for a of property. + + + + + Specifies how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Floating point numbers are parsed to . + + + + + Floating point numbers are parsed to . + + + + + Specifies formatting options for the . + + + + + No special formatting is applied. This is the default. + + + + + Causes child objects to be indented according to the and settings. + + + + + Provides an interface for using pooled arrays. + + The array type content. + + + + Rent an array from the pool. This array must be returned when it is no longer needed. + + The minimum required length of the array. The returned array may be longer. + The rented array from the pool. This array must be returned when it is no longer needed. + + + + Return an array to the pool. + + The array that is being returned. + + + + Provides an interface to enable a class to return line and position information. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + The current line number or 0 if no line information is available (for example, when returns false). + + + + Gets the current line position. + + The current line position or 0 if no line information is available (for example, when returns false). + + + + Instructs the how to serialize the collection. + + + + + Gets or sets a value indicating whether null items are allowed in the collection. + + true if null items are allowed in the collection; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with a flag indicating whether the array can contain null items. + + A flag indicating whether the array can contain null items. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to use the specified constructor when deserializing that object. + + + + + Instructs the how to serialize the object. + + + + + Gets or sets the id. + + The id. + + + + Gets or sets the title. + + The title. + + + + Gets or sets the description. + + The description. + + + + Gets or sets the collection's items converter. + + The collection's items converter. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets a value that indicates whether to preserve object references. + + + true to keep object reference; otherwise, false. The default is false. + + + + + Gets or sets a value that indicates whether to preserve collection's items references. + + + true to keep collection's items object references; otherwise, false. The default is false. + + + + + Gets or sets the reference loop handling used when serializing the collection's items. + + The reference loop handling. + + + + Gets or sets the type name handling used when serializing the collection's items. + + The type name handling. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Provides methods for converting between .NET types and JSON types. + + + + + + + + Gets or sets a function that creates default . + Default settings are automatically used by serialization methods on , + and and on . + To serialize without using any default settings create a with + . + + + + + Represents JavaScript's boolean value true as a string. This field is read-only. + + + + + Represents JavaScript's boolean value false as a string. This field is read-only. + + + + + Represents JavaScript's null as a string. This field is read-only. + + + + + Represents JavaScript's undefined as a string. This field is read-only. + + + + + Represents JavaScript's positive infinity as a string. This field is read-only. + + + + + Represents JavaScript's negative infinity as a string. This field is read-only. + + + + + Represents JavaScript's NaN as a string. This field is read-only. + + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + The time zone handling when the date is converted to a string. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + The string escape handling. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Serializes the specified object to a JSON string. + + The object to serialize. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting. + + The object to serialize. + Indicates how the output should be formatted. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a collection of . + + The object to serialize. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting and a collection of . + + The object to serialize. + Indicates how the output should be formatted. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Deserializes the JSON to a .NET object. + + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to a .NET object using . + + The JSON to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The JSON to deserialize. + The of object being deserialized. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The type of the object to deserialize to. + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the given anonymous type. + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the given anonymous type using . + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The type of the object to deserialize to. + The JSON to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The type of the object to deserialize to. + The object to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The JSON to deserialize. + The type of the object to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The JSON to deserialize. + The type of the object to deserialize to. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Populates the object with values from the JSON string. + + The JSON to populate values from. + The target object to populate values onto. + + + + Populates the object with values from the JSON string using . + + The JSON to populate values from. + The target object to populate values onto. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + + + + Serializes the to a JSON string. + + The node to serialize. + A JSON string of the . + + + + Serializes the to a JSON string using formatting. + + The node to serialize. + Indicates how the output should be formatted. + A JSON string of the . + + + + Serializes the to a JSON string using formatting and omits the root object if is true. + + The node to serialize. + Indicates how the output should be formatted. + Omits writing the root object. + A JSON string of the . + + + + Deserializes the from a JSON string. + + The JSON string. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by . + + The JSON string. + The name of the root element to append when deserializing. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by + and writes a Json.NET array attribute for collections. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by , + writes a Json.NET array attribute for collections, and encodes special characters. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + + A value to indicate whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + The deserialized . + + + + Serializes the to a JSON string. + + The node to convert to JSON. + A JSON string of the . + + + + Serializes the to a JSON string using formatting. + + The node to convert to JSON. + Indicates how the output should be formatted. + A JSON string of the . + + + + Serializes the to a JSON string using formatting and omits the root object if is true. + + The node to serialize. + Indicates how the output should be formatted. + Omits writing the root object. + A JSON string of the . + + + + Deserializes the from a JSON string. + + The JSON string. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by . + + The JSON string. + The name of the root element to append when deserializing. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by + and writes a Json.NET array attribute for collections. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by , + writes a Json.NET array attribute for collections, and encodes special characters. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + + A value to indicate whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + The deserialized . + + + + Converts an object to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can read JSON. + + true if this can read JSON; otherwise, false. + + + + Gets a value indicating whether this can write JSON. + + true if this can write JSON; otherwise, false. + + + + Converts an object to and from JSON. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. If there is no existing value then null will be used. + The existing value has a value. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Instructs the to use the specified when serializing the member or class. + + + + + Gets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + + + + + Initializes a new instance of the class. + + Type of the . + + + + Initializes a new instance of the class. + + Type of the . + Parameter list to use when constructing the . Can be null. + + + + Represents a collection of . + + + + + Instructs the how to serialize the collection. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Instructs the to deserialize properties with no matching class member into the specified collection + and write values during serialization. + + + + + Gets or sets a value that indicates whether to write extension data when serializing the object. + + + true to write extension data when serializing the object; otherwise, false. The default is true. + + + + + Gets or sets a value that indicates whether to read extension data when deserializing the object. + + + true to read extension data when deserializing the object; otherwise, false. The default is true. + + + + + Initializes a new instance of the class. + + + + + Instructs the not to serialize the public field or public read/write property value. + + + + + Base class for a table of atomized string objects. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Instructs the how to serialize the object. + + + + + Gets or sets the member serialization. + + The member serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified member serialization. + + The member serialization. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to always serialize the member with the specified name. + + + + + Gets or sets the type used when serializing the property's collection items. + + The collection's items type. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the null value handling used when serializing this property. + + The null value handling. + + + + Gets or sets the default value handling used when serializing this property. + + The default value handling. + + + + Gets or sets the reference loop handling used when serializing this property. + + The reference loop handling. + + + + Gets or sets the object creation handling used when deserializing this property. + + The object creation handling. + + + + Gets or sets the type name handling used when serializing this property. + + The type name handling. + + + + Gets or sets whether this property's value is serialized as a reference. + + Whether this property's value is serialized as a reference. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets a value indicating whether this property is required. + + + A value indicating whether this property is required. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified name. + + Name of the property. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Asynchronously reads the next JSON token from the source. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns true if the next token was read successfully; false if there are no more tokens to read. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously skips the children of the current token. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a []. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the []. This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Specifies the state of the reader. + + + + + A read method has not been called. + + + + + The end of the file has been reached successfully. + + + + + Reader is at a property. + + + + + Reader is at the start of an object. + + + + + Reader is in an object. + + + + + Reader is at the start of an array. + + + + + Reader is in an array. + + + + + The method has been called. + + + + + Reader has just read a value. + + + + + Reader is at the start of a constructor. + + + + + Reader is in a constructor. + + + + + An error occurred that prevents the read operation from continuing. + + + + + The end of the file has been reached successfully. + + + + + Gets the current reader state. + + The current reader state. + + + + Gets or sets a value indicating whether the source should be closed when this reader is closed. + + + true to close the source when this reader is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether multiple pieces of JSON content can + be read from a continuous stream without erroring. + + + true to support reading multiple pieces of JSON content; otherwise false. + The default is false. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + Gets or sets how time zones are handled when reading JSON. + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Gets or sets how custom date formatted strings are parsed when reading JSON. + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets the type of the current JSON token. + + + + + Gets the text value of the current JSON token. + + + + + Gets the .NET type for the current JSON token. + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets or sets the culture used when reading JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Reads the next JSON token from the source. + + true if the next token was read successfully; false if there are no more tokens to read. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Skips the children of the current token. + + + + + Sets the current token. + + The new token. + + + + Sets the current token and value. + + The new token. + The value. + + + + Sets the current token and value. + + The new token. + The value. + A flag indicating whether the position index inside an array should be updated. + + + + Sets the state based on current token type. + + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Changes the reader's state to . + If is set to true, the source is also closed. + + + + + The exception thrown when an error occurs while reading JSON text. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Instructs the to always serialize the member, and to require that the member has a value. + + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Serializes and deserializes objects into and from the JSON format. + The enables you to control how objects are encoded into JSON. + + + + + Occurs when the errors during serialization and deserialization. + + + + + Gets or sets the used by the serializer when resolving references. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + + + + Gets or sets how reference loops (e.g. a class referencing itself) is handled. + The default value is . + + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets a collection that will be used during serialization. + + Collection that will be used during serialization. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets a value indicating whether there will be a check for additional JSON content after deserializing an object. + The default value is false. + + + true if there will be a check for additional JSON content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Creates a new instance. + The will not use default settings + from . + + + A new instance. + The will not use default settings + from . + + + + + Creates a new instance using the specified . + The will not use default settings + from . + + The settings to be applied to the . + + A new instance using the specified . + The will not use default settings + from . + + + + + Creates a new instance. + The will use default settings + from . + + + A new instance. + The will use default settings + from . + + + + + Creates a new instance using the specified . + The will use default settings + from as well as the specified . + + The settings to be applied to the . + + A new instance using the specified . + The will use default settings + from as well as the specified . + + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Deserializes the JSON structure contained by the specified . + + The that contains the JSON structure to deserialize. + The being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The type of the object to deserialize. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is Auto to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Specifies the settings on a object. + + + + + Gets or sets how reference loops (e.g. a class referencing itself) are handled. + The default value is . + + Reference loop handling. + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + Missing member handling. + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + Null value handling. + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + The default value handling. + + + + Gets or sets a collection that will be used during serialization. + + The converters. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + The preserve references handling. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + The type name handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + The contract resolver. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets the used by the serializer when resolving references. + + The reference resolver. + + + + Gets or sets a function that creates the used by the serializer when resolving references. + + A function that creates the used by the serializer when resolving references. + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the error handler called during serialization and deserialization. + + The error handler called during serialization and deserialization. + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets a value indicating whether there will be a check for additional content after deserializing an object. + The default value is false. + + + true if there will be a check for additional content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Represents a reader that provides fast, non-cached, forward-only access to JSON text data. + + + + + Asynchronously reads the next JSON token from the source. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns true if the next token was read successfully; false if there are no more tokens to read. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a []. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the []. This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Initializes a new instance of the class with the specified . + + The containing the JSON data to read. + + + + Gets or sets the reader's property name table. + + + + + Gets or sets the reader's character buffer pool. + + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + + The current line number or 0 if no line information is available (for example, returns false). + + + + + Gets the current line position. + + + The current line position or 0 if no line information is available (for example, returns false). + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Asynchronously flushes whatever is in the buffer to the destination and also flushes the destination. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the JSON value delimiter. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the specified end token. + + The end token to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously closes this writer. + If is set to true, the destination is also closed. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of the current JSON object or array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes indent characters. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes an indent space. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes raw JSON without changing the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a null value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the beginning of a JSON array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the beginning of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the start of a constructor with the given name. + + The name of the constructor. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes an undefined value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the given white space. + + The string of white space characters. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a [] value. + + The [] value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of an array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of a constructor. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Gets or sets the writer's character array pool. + + + + + Gets or sets how many s to write for each level in the hierarchy when is set to . + + + + + Gets or sets which character to use to quote attribute values. + + + + + Gets or sets which character to use for indenting when is set to . + + + + + Gets or sets a value indicating whether object names will be surrounded with quotes. + + + + + Initializes a new instance of the class using the specified . + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying . + + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the specified end token. + + The end token to write. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Specifies the type of JSON token. + + + + + This is returned by the if a read method has not been called. + + + + + An object start token. + + + + + An array start token. + + + + + A constructor start token. + + + + + An object property name. + + + + + A comment. + + + + + Raw JSON. + + + + + An integer. + + + + + A float. + + + + + A string. + + + + + A boolean. + + + + + A null token. + + + + + An undefined token. + + + + + An object end token. + + + + + An array end token. + + + + + A constructor end token. + + + + + A Date. + + + + + Byte data. + + + + + + Represents a reader that provides validation. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Sets an event handler for receiving schema validation errors. + + + + + Gets the text value of the current JSON token. + + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + + Gets the type of the current JSON token. + + + + + + Gets the .NET type for the current JSON token. + + + + + + Initializes a new instance of the class that + validates the content returned from the given . + + The to read from while validating. + + + + Gets or sets the schema. + + The schema. + + + + Gets the used to construct this . + + The specified in the constructor. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a []. + + + A [] or null if the next JSON token is null. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Asynchronously closes this writer. + If is set to true, the destination is also closed. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously flushes whatever is in the buffer to the destination and also flushes the destination. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the specified end token. + + The end token to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes indent characters. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the JSON value delimiter. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes an indent space. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes raw JSON without changing the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of the current JSON object or array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of an array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of a constructor. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a null value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the beginning of a JSON array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the start of a constructor with the given name. + + The name of the constructor. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the beginning of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the current token. + + The to read the token from. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the current token. + + The to read the token from. + A flag indicating whether the current token's children should be written. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the token and its value. + + The to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the token and its value. + + The to write. + + The value to write. + A value is only required for tokens that have an associated value, e.g. the property name for . + null can be passed to the method for tokens that don't have a value, e.g. . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a [] value. + + The [] value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes an undefined value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the given white space. + + The string of white space characters. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously ets the state of the . + + The being written. + The value being written. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Gets or sets a value indicating whether the destination should be closed when this writer is closed. + + + true to close the destination when this writer is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether the JSON should be auto-completed when this writer is closed. + + + true to auto-complete the JSON when this writer is closed; otherwise false. The default is true. + + + + + Gets the top. + + The top. + + + + Gets the state of the writer. + + + + + Gets the path of the writer. + + + + + Gets or sets a value indicating how JSON text output should be formatted. + + + + + Gets or sets how dates are written to JSON text. + + + + + Gets or sets how time zones are handled when writing JSON text. + + + + + Gets or sets how strings are escaped when writing JSON text. + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written to JSON text. + + + + + Gets or sets how and values are formatted when writing JSON text. + + + + + Gets or sets the culture used when writing JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the destination and also flushes the destination. + + + + + Closes this writer. + If is set to true, the destination is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the end of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the end of an array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end constructor. + + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes the end of the current JSON object or array. + + + + + Writes the current token and its children. + + The to read the token from. + + + + Writes the current token. + + The to read the token from. + A flag indicating whether the current token's children should be written. + + + + Writes the token and its value. + + The to write. + + The value to write. + A value is only required for tokens that have an associated value, e.g. the property name for . + null can be passed to the method for tokens that don't have a value, e.g. . + + + + + Writes the token. + + The to write. + + + + Writes the specified end token. + + The end token to write. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON without changing the writer's state. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Sets the state of the . + + The being written. + The value being written. + + + + The exception thrown when an error occurs while writing JSON text. + + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Specifies how JSON comments are handled when loading JSON. + + + + + Ignore comments. + + + + + Load comments as a with type . + + + + + Specifies how duplicate property names are handled when loading JSON. + + + + + Replace the existing value when there is a duplicate property. The value of the last property in the JSON object will be used. + + + + + Ignore the new value when there is a duplicate property. The value of the first property in the JSON object will be used. + + + + + Throw a when a duplicate property is encountered. + + + + + Contains the LINQ to JSON extension methods. + + + + + Returns a collection of tokens that contains the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the descendants of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, and the descendants of every token in the source collection. + + + + Returns a collection of child properties of every object in the source collection. + + An of that contains the source collection. + An of that contains the properties of every object in the source collection. + + + + Returns a collection of child values of every object in the source collection with the given key. + + An of that contains the source collection. + The token key. + An of that contains the values of every token in the source collection with the given key. + + + + Returns a collection of child values of every object in the source collection. + + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child values of every object in the source collection with the given key. + + The type to convert the values to. + An of that contains the source collection. + The token key. + An that contains the converted values of every token in the source collection with the given key. + + + + Returns a collection of converted child values of every object in the source collection. + + The type to convert the values to. + An of that contains the source collection. + An that contains the converted values of every token in the source collection. + + + + Converts the value. + + The type to convert the value to. + A cast as a of . + A converted value. + + + + Converts the value. + + The source collection type. + The type to convert the value to. + A cast as a of . + A converted value. + + + + Returns a collection of child tokens of every array in the source collection. + + The source collection type. + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child tokens of every array in the source collection. + + An of that contains the source collection. + The type to convert the values to. + The source collection type. + An that contains the converted values of every token in the source collection. + + + + Returns the input typed as . + + An of that contains the source collection. + The input typed as . + + + + Returns the input typed as . + + The source collection type. + An of that contains the source collection. + The input typed as . + + + + Represents a collection of objects. + + The type of token. + + + + Gets the of with the specified key. + + + + + + Represents a JSON array. + + + + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous load. The property contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous load. The property contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Loads an from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads an from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the at the specified index. + + + + + + Determines the index of a specific item in the . + + The object to locate in the . + + The index of if found in the list; otherwise, -1. + + + + + Inserts an item to the at the specified index. + + The zero-based index at which should be inserted. + The object to insert into the . + + is not a valid index in the . + + + + + Removes the item at the specified index. + + The zero-based index of the item to remove. + + is not a valid index in the . + + + + + Returns an enumerator that iterates through the collection. + + + A of that can be used to iterate through the collection. + + + + + Adds an item to the . + + The object to add to the . + + + + Removes all items from the . + + + + + Determines whether the contains a specific value. + + The object to locate in the . + + true if is found in the ; otherwise, false. + + + + + Copies the elements of the to an array, starting at a particular array index. + + The array. + Index of the array. + + + + Gets a value indicating whether the is read-only. + + true if the is read-only; otherwise, false. + + + + Removes the first occurrence of a specific object from the . + + The object to remove from the . + + true if was successfully removed from the ; otherwise, false. This method also returns false if is not found in the original . + + + + + Represents a JSON constructor. + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets or sets the name of this constructor. + + The constructor name. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name. + + The constructor name. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a token that can contain other tokens. + + + + + Occurs when the list changes or an item in the list changes. + + + + + Occurs before an item is added to the collection. + + + + + Occurs when the items list of the collection has changed, or the collection is reset. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Raises the event. + + The instance containing the event data. + + + + Raises the event. + + The instance containing the event data. + + + + Raises the event. + + The instance containing the event data. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Get the first child token of this token. + + + A containing the first child token of the . + + + + + Get the last child token of this token. + + + A containing the last child token of the . + + + + + Returns a collection of the child tokens of this token, in document order. + + + An of containing the child tokens of this , in document order. + + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + + A containing the child values of this , in document order. + + + + + Returns a collection of the descendant tokens for this token in document order. + + An of containing the descendant tokens of the . + + + + Returns a collection of the tokens that contain this token, and all descendant tokens of this token, in document order. + + An of containing this token, and all the descendant tokens of the . + + + + Adds the specified content as children of this . + + The content to be added. + + + + Adds the specified content as the first children of this . + + The content to be added. + + + + Creates a that can be used to add tokens to the . + + A that is ready to have content written to it. + + + + Replaces the child nodes of this token with the specified content. + + The content. + + + + Removes the child nodes from this token. + + + + + Merge the specified content into this . + + The content to be merged. + + + + Merge the specified content into this using . + + The content to be merged. + The used to merge the content. + + + + Gets the count of child JSON tokens. + + The count of child JSON tokens. + + + + Represents a collection of objects. + + The type of token. + + + + An empty collection of objects. + + + + + Initializes a new instance of the struct. + + The enumerable. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Gets the of with the specified key. + + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Returns a hash code for this instance. + + + A hash code for this instance, suitable for use in hashing algorithms and data structures like a hash table. + + + + + Represents a JSON object. + + + + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Occurs when a property value changes. + + + + + Occurs when a property value is changing. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Gets the node type for this . + + The type. + + + + Gets an of of this object's properties. + + An of of this object's properties. + + + + Gets a with the specified name. + + The property name. + A with the specified name or null. + + + + Gets the with the specified name. + The exact name will be searched for first and if no matching property is found then + the will be used to match a property. + + The property name. + One of the enumeration values that specifies how the strings will be compared. + A matched with the specified name or null. + + + + Gets a of of this object's property values. + + A of of this object's property values. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the with the specified property name. + + + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified property name. + + Name of the property. + The with the specified property name. + + + + Gets the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + One of the enumeration values that specifies how the strings will be compared. + The with the specified property name. + + + + Tries to get the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + The value. + One of the enumeration values that specifies how the strings will be compared. + true if a value was successfully retrieved; otherwise, false. + + + + Adds the specified property name. + + Name of the property. + The value. + + + + Determines whether the JSON object has the specified property name. + + Name of the property. + true if the JSON object has the specified property name; otherwise, false. + + + + Removes the property with the specified name. + + Name of the property. + true if item was successfully removed; otherwise, false. + + + + Tries to get the with the specified property name. + + Name of the property. + The value. + true if a value was successfully retrieved; otherwise, false. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Raises the event with the provided arguments. + + Name of the property. + + + + Raises the event with the provided arguments. + + Name of the property. + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Represents a JSON property. + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous creation. The + property returns a that contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous creation. The + property returns a that contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the property name. + + The property name. + + + + Gets or sets the property value. + + The property value. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a view of a . + + + + + Initializes a new instance of the class. + + The name. + + + + When overridden in a derived class, returns whether resetting an object changes its value. + + + true if resetting the component changes its value; otherwise, false. + + The component to test for reset capability. + + + + When overridden in a derived class, gets the current value of the property on a component. + + + The value of a property for a given component. + + The component with the property for which to retrieve the value. + + + + When overridden in a derived class, resets the value for this property of the component to the default value. + + The component with the property value that is to be reset to the default value. + + + + When overridden in a derived class, sets the value of the component to a different value. + + The component with the property value that is to be set. + The new value. + + + + When overridden in a derived class, determines a value indicating whether the value of this property needs to be persisted. + + + true if the property should be persisted; otherwise, false. + + The component with the property to be examined for persistence. + + + + When overridden in a derived class, gets the type of the component this property is bound to. + + + A that represents the type of component this property is bound to. + When the or + + methods are invoked, the object specified might be an instance of this type. + + + + + When overridden in a derived class, gets a value indicating whether this property is read-only. + + + true if the property is read-only; otherwise, false. + + + + + When overridden in a derived class, gets the type of the property. + + + A that represents the type of the property. + + + + + Gets the hash code for the name of the member. + + + + The hash code for the name of the member. + + + + + Represents a raw JSON string. + + + + + Asynchronously creates an instance of with the content of the reader's current token. + + The reader. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous creation. The + property returns an instance of with the content of the reader's current token. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class. + + The raw json. + + + + Creates an instance of with the content of the reader's current token. + + The reader. + An instance of with the content of the reader's current token. + + + + Specifies the settings used when loading JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets how JSON comments are handled when loading JSON. + The default value is . + + The JSON comment handling. + + + + Gets or sets how JSON line info is handled when loading JSON. + The default value is . + + The JSON line info handling. + + + + Gets or sets how duplicate property names in JSON objects are handled when loading JSON. + The default value is . + + The JSON duplicate property name handling. + + + + Specifies the settings used when merging JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets the method used when merging JSON arrays. + + The method used when merging JSON arrays. + + + + Gets or sets how null value properties are merged. + + How null value properties are merged. + + + + Gets or sets the comparison used to match property names while merging. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + The comparison used to match property names while merging. + + + + Specifies the settings used when selecting JSON. + + + + + Gets or sets a timeout that will be used when executing regular expressions. + + The timeout that will be used when executing regular expressions. + + + + Gets or sets a flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + A flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + + + Represents an abstract JSON token. + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Writes this token to a asynchronously. + + A into which this method will write. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously creates a from a . + + An positioned at the token to read into this . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains + the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Asynchronously creates a from a . + + An positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains + the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Asynchronously creates a from a . + + A positioned at the token to read into this . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Asynchronously creates a from a . + + A positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Gets a comparer that can compare two tokens for value equality. + + A that can compare two nodes for value equality. + + + + Gets or sets the parent. + + The parent. + + + + Gets the root of this . + + The root of this . + + + + Gets the node type for this . + + The type. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Compares the values of two tokens, including the values of all descendant tokens. + + The first to compare. + The second to compare. + true if the tokens are equal; otherwise false. + + + + Gets the next sibling token of this node. + + The that contains the next sibling token. + + + + Gets the previous sibling token of this node. + + The that contains the previous sibling token. + + + + Gets the path of the JSON token. + + + + + Adds the specified content immediately after this token. + + A content object that contains simple content or a collection of content objects to be added after this token. + + + + Adds the specified content immediately before this token. + + A content object that contains simple content or a collection of content objects to be added before this token. + + + + Returns a collection of the ancestor tokens of this token. + + A collection of the ancestor tokens of this token. + + + + Returns a collection of tokens that contain this token, and the ancestors of this token. + + A collection of tokens that contain this token, and the ancestors of this token. + + + + Returns a collection of the sibling tokens after this token, in document order. + + A collection of the sibling tokens after this tokens, in document order. + + + + Returns a collection of the sibling tokens before this token, in document order. + + A collection of the sibling tokens before this token, in document order. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets the with the specified key converted to the specified type. + + The type to convert the token to. + The token key. + The converted token value. + + + + Get the first child token of this token. + + A containing the first child token of the . + + + + Get the last child token of this token. + + A containing the last child token of the . + + + + Returns a collection of the child tokens of this token, in document order. + + An of containing the child tokens of this , in document order. + + + + Returns a collection of the child tokens of this token, in document order, filtered by the specified type. + + The type to filter the child tokens on. + A containing the child tokens of this , in document order. + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + A containing the child values of this , in document order. + + + + Removes this token from its parent. + + + + + Replaces this token with the specified token. + + The value. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Returns the indented JSON for this token. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + The indented JSON for this token. + + + + + Returns the JSON for this token using the given formatting and converters. + + Indicates how the output should be formatted. + A collection of s which will be used when writing the token. + The JSON for this token using the given formatting and converters. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to []. + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from [] to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Creates a for this token. + + A that can be used to read this token and its descendants. + + + + Creates a from an object. + + The object that will be used to create . + A with the value of the specified object. + + + + Creates a from an object using the specified . + + The object that will be used to create . + The that will be used when reading the object. + A with the value of the specified object. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + An positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + Creates a from a . + + A positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A , or null. + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + A . + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + The used to select tokens. + A . + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + The used to select tokens. + An of that contains the selected elements. + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Creates a new instance of the . All child tokens are recursively cloned. + + A new instance of the . + + + + Adds an object to the annotation list of this . + + The annotation to add. + + + + Get the first annotation object of the specified type from this . + + The type of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets the first annotation object of the specified type from this . + + The of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets a collection of annotations of the specified type for this . + + The type of the annotations to retrieve. + An that contains the annotations for this . + + + + Gets a collection of annotations of the specified type for this . + + The of the annotations to retrieve. + An of that contains the annotations that match the specified type for this . + + + + Removes the annotations of the specified type from this . + + The type of annotations to remove. + + + + Removes the annotations of the specified type from this . + + The of annotations to remove. + + + + Compares tokens to determine whether they are equal. + + + + + Determines whether the specified objects are equal. + + The first object of type to compare. + The second object of type to compare. + + true if the specified objects are equal; otherwise, false. + + + + + Returns a hash code for the specified object. + + The for which a hash code is to be returned. + A hash code for the specified object. + The type of is a reference type and is null. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Gets the at the reader's current position. + + + + + Initializes a new instance of the class. + + The token to read from. + + + + Initializes a new instance of the class. + + The token to read from. + The initial path of the token. It is prepended to the returned . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Gets the path of the current JSON token. + + + + + Specifies the type of token. + + + + + No token type has been set. + + + + + A JSON object. + + + + + A JSON array. + + + + + A JSON constructor. + + + + + A JSON object property. + + + + + A comment. + + + + + An integer value. + + + + + A float value. + + + + + A string value. + + + + + A boolean value. + + + + + A null value. + + + + + An undefined value. + + + + + A date value. + + + + + A raw JSON value. + + + + + A collection of bytes value. + + + + + A Guid value. + + + + + A Uri value. + + + + + A TimeSpan value. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets the at the writer's current position. + + + + + Gets the token being written. + + The token being written. + + + + Initializes a new instance of the class writing to the given . + + The container being written to. + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the underlying . + + + + + Closes this writer. + If is set to true, the JSON is auto-completed. + + + Setting to true has no additional effect, since the underlying is a type that cannot be closed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end. + + The token. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes a value. + An error will be raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Represents a value in JSON (string, integer, date, etc). + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Creates a comment with the given value. + + The value. + A comment with the given value. + + + + Creates a string with the given value. + + The value. + A string with the given value. + + + + Creates a null value. + + A null value. + + + + Creates a undefined value. + + A undefined value. + + + + Gets the node type for this . + + The type. + + + + Gets or sets the underlying token value. + + The underlying token value. + + + + Writes this token to a . + + A into which this method will write. + A collection of s which will be used when writing the token. + + + + Indicates whether the current object is equal to another object of the same type. + + + true if the current object is equal to the parameter; otherwise, false. + + An object to compare with this object. + + + + Determines whether the specified is equal to the current . + + The to compare with the current . + + true if the specified is equal to the current ; otherwise, false. + + + + + Serves as a hash function for a particular type. + + + A hash code for the current . + + + + + Returns a that represents this instance. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format provider. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + The format provider. + + A that represents this instance. + + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Compares the current instance with another object of the same type and returns an integer that indicates whether the current instance precedes, follows, or occurs in the same position in the sort order as the other object. + + An object to compare with this instance. + + A 32-bit signed integer that indicates the relative order of the objects being compared. The return value has these meanings: + Value + Meaning + Less than zero + This instance is less than . + Zero + This instance is equal to . + Greater than zero + This instance is greater than . + + + is not of the same type as this instance. + + + + + Specifies how line information is handled when loading JSON. + + + + + Ignore line information. + + + + + Load line information. + + + + + Specifies how JSON arrays are merged together. + + + + Concatenate arrays. + + + Union arrays, skipping items that already exist. + + + Replace all array items. + + + Merge array items together, matched by index. + + + + Specifies how null value properties are merged. + + + + + The content's null value properties will be ignored during merging. + + + + + The content's null value properties will be merged. + + + + + Specifies the member serialization options for the . + + + + + All public members are serialized by default. Members can be excluded using or . + This is the default member serialization mode. + + + + + Only members marked with or are serialized. + This member serialization mode can also be set by marking the class with . + + + + + All public and private fields are serialized. Members can be excluded using or . + This member serialization mode can also be set by marking the class with + and setting IgnoreSerializableAttribute on to false. + + + + + Specifies metadata property handling options for the . + + + + + Read metadata properties located at the start of a JSON object. + + + + + Read metadata properties located anywhere in a JSON object. Note that this setting will impact performance. + + + + + Do not try to read metadata properties. + + + + + Specifies missing member handling options for the . + + + + + Ignore a missing member and do not attempt to deserialize it. + + + + + Throw a when a missing member is encountered during deserialization. + + + + + Specifies null value handling options for the . + + + + + + + + + Include null values when serializing and deserializing objects. + + + + + Ignore null values when serializing and deserializing objects. + + + + + Specifies how object creation is handled by the . + + + + + Reuse existing objects, create new objects when needed. + + + + + Only reuse existing objects. + + + + + Always create new objects. + + + + + Specifies reference handling options for the . + Note that references cannot be preserved when a value is set via a non-default constructor such as types that implement . + + + + + + + + Do not preserve references when serializing types. + + + + + Preserve references when serializing into a JSON object structure. + + + + + Preserve references when serializing into a JSON array structure. + + + + + Preserve references when serializing. + + + + + Specifies reference loop handling options for the . + + + + + Throw a when a loop is encountered. + + + + + Ignore loop references and do not serialize. + + + + + Serialize loop references. + + + + + Indicating whether a property is required. + + + + + The property is not required. The default state. + + + + + The property must be defined in JSON but can be a null value. + + + + + The property must be defined in JSON and cannot be a null value. + + + + + The property is not required but it cannot be a null value. + + + + + + Contains the JSON schema extension methods. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + true if the specified is valid; otherwise, false. + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + When this method returns, contains any error messages generated while validating. + + true if the specified is valid; otherwise, false. + + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + The validation event handler. + + + + + An in-memory representation of a JSON Schema. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the id. + + + + + Gets or sets the title. + + + + + Gets or sets whether the object is required. + + + + + Gets or sets whether the object is read-only. + + + + + Gets or sets whether the object is visible to users. + + + + + Gets or sets whether the object is transient. + + + + + Gets or sets the description of the object. + + + + + Gets or sets the types of values allowed by the object. + + The type. + + + + Gets or sets the pattern. + + The pattern. + + + + Gets or sets the minimum length. + + The minimum length. + + + + Gets or sets the maximum length. + + The maximum length. + + + + Gets or sets a number that the value should be divisible by. + + A number that the value should be divisible by. + + + + Gets or sets the minimum. + + The minimum. + + + + Gets or sets the maximum. + + The maximum. + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the minimum attribute (). + + A flag indicating whether the value can not equal the number defined by the minimum attribute (). + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the maximum attribute (). + + A flag indicating whether the value can not equal the number defined by the maximum attribute (). + + + + Gets or sets the minimum number of items. + + The minimum number of items. + + + + Gets or sets the maximum number of items. + + The maximum number of items. + + + + Gets or sets the of items. + + The of items. + + + + Gets or sets a value indicating whether items in an array are validated using the instance at their array position from . + + + true if items are validated using their array position; otherwise, false. + + + + + Gets or sets the of additional items. + + The of additional items. + + + + Gets or sets a value indicating whether additional items are allowed. + + + true if additional items are allowed; otherwise, false. + + + + + Gets or sets whether the array items must be unique. + + + + + Gets or sets the of properties. + + The of properties. + + + + Gets or sets the of additional properties. + + The of additional properties. + + + + Gets or sets the pattern properties. + + The pattern properties. + + + + Gets or sets a value indicating whether additional properties are allowed. + + + true if additional properties are allowed; otherwise, false. + + + + + Gets or sets the required property if this property is present. + + The required property if this property is present. + + + + Gets or sets the a collection of valid enum values allowed. + + A collection of valid enum values allowed. + + + + Gets or sets disallowed types. + + The disallowed types. + + + + Gets or sets the default value. + + The default value. + + + + Gets or sets the collection of that this schema extends. + + The collection of that this schema extends. + + + + Gets or sets the format. + + The format. + + + + Initializes a new instance of the class. + + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The object representing the JSON Schema. + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The to use when resolving schema references. + The object representing the JSON Schema. + + + + Load a from a string that contains JSON Schema. + + A that contains JSON Schema. + A populated from the string that contains JSON Schema. + + + + Load a from a string that contains JSON Schema using the specified . + + A that contains JSON Schema. + The resolver. + A populated from the string that contains JSON Schema. + + + + Writes this schema to a . + + A into which this method will write. + + + + Writes this schema to a using the specified . + + A into which this method will write. + The resolver used. + + + + Returns a that represents the current . + + + A that represents the current . + + + + + + Returns detailed information about the schema exception. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + + Generates a from a specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets how undefined schemas are handled by the serializer. + + + + + Gets or sets the contract resolver. + + The contract resolver. + + + + Generate a from the specified type. + + The type to generate a from. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + + Resolves from an id. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the loaded schemas. + + The loaded schemas. + + + + Initializes a new instance of the class. + + + + + Gets a for the specified reference. + + The id. + A for the specified reference. + + + + + The value types allowed by the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + No type specified. + + + + + String type. + + + + + Float type. + + + + + Integer type. + + + + + Boolean type. + + + + + Object type. + + + + + Array type. + + + + + Null type. + + + + + Any type. + + + + + + Specifies undefined schema Id handling options for the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Do not infer a schema Id. + + + + + Use the .NET type name as the schema Id. + + + + + Use the assembly qualified .NET type name as the schema Id. + + + + + + Returns detailed information related to the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the associated with the validation error. + + The JsonSchemaException associated with the validation error. + + + + Gets the path of the JSON location where the validation error occurred. + + The path of the JSON location where the validation error occurred. + + + + Gets the text description corresponding to the validation error. + + The text description. + + + + + Represents the callback method that will handle JSON schema validation events and the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + A camel case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Resolves member mappings for a type, camel casing property names. + + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used by to resolve a for a given . + + + + + Gets a value indicating whether members are being get and set using dynamic code generation. + This value is determined by the runtime permissions available. + + + true if using dynamic code generation; otherwise, false. + + + + + Gets or sets the default members search flags. + + The default members search flags. + + + + Gets or sets a value indicating whether compiler generated members should be serialized. + + + true if serialized compiler generated members; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore the interface when serializing and deserializing types. + + + true if the interface will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore the attribute when serializing and deserializing types. + + + true if the attribute will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore IsSpecified members when serializing and deserializing types. + + + true if the IsSpecified members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore ShouldSerialize members when serializing and deserializing types. + + + true if the ShouldSerialize members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets the naming strategy used to resolve how property names and dictionary keys are serialized. + + The naming strategy used to resolve how property names and dictionary keys are serialized. + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Gets the serializable members for the type. + + The type to get serializable members for. + The serializable members for the type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates the constructor parameters. + + The constructor to create properties for. + The type's member properties. + Properties for the given . + + + + Creates a for the given . + + The matching member property. + The constructor parameter. + A created for the given . + + + + Resolves the default for the contract. + + Type of the object. + The contract's default . + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Determines which contract type is created for the given type. + + Type of the object. + A for the given type. + + + + Creates properties for the given . + + The type to create properties for. + /// The member serialization mode for the type. + Properties for the given . + + + + Creates the used by the serializer to get and set values from a member. + + The member. + The used by the serializer to get and set values from a member. + + + + Creates a for the given . + + The member's parent . + The member to create a for. + A created for the given . + + + + Resolves the name of the property. + + Name of the property. + Resolved name of the property. + + + + Resolves the name of the extension data. By default no changes are made to extension data names. + + Name of the extension data. + Resolved name of the extension data. + + + + Resolves the key of the dictionary. By default is used to resolve dictionary keys. + + Key of the dictionary. + Resolved key of the dictionary. + + + + Gets the resolved name of the property. + + Name of the property. + Name of the property. + + + + The default naming strategy. Property names and dictionary keys are unchanged. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + The default serialization binder used when resolving and loading classes from type names. + + + + + Initializes a new instance of the class. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + The type of the object the formatter creates a new instance of. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Represents a trace writer that writes to the application's instances. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + + The that will be used to filter the trace messages passed to the writer. + + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Get and set values for a using dynamic methods. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Provides information surrounding an error. + + + + + Gets the error. + + The error. + + + + Gets the original object that caused the error. + + The original object that caused the error. + + + + Gets the member that caused the error. + + The member that caused the error. + + + + Gets the path of the JSON location where the error occurred. + + The path of the JSON location where the error occurred. + + + + Gets or sets a value indicating whether this is handled. + + true if handled; otherwise, false. + + + + Provides data for the Error event. + + + + + Gets the current object the error event is being raised against. + + The current object the error event is being raised against. + + + + Gets the error context. + + The error context. + + + + Initializes a new instance of the class. + + The current object. + The error context. + + + + Get and set values for a using dynamic methods. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Provides methods to get attributes. + + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Used by to resolve a for a given . + + + + + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used to resolve references when serializing and deserializing JSON by the . + + + + + Resolves a reference to its object. + + The serialization context. + The reference to resolve. + The object that was resolved from the reference. + + + + Gets the reference for the specified object. + + The serialization context. + The object to get a reference for. + The reference to the object. + + + + Determines whether the specified object is referenced. + + The serialization context. + The object to test for a reference. + + true if the specified object is referenced; otherwise, false. + + + + + Adds a reference to the specified object. + + The serialization context. + The reference. + The object to reference. + + + + Allows users to control class loading and mandate what class to load. + + + + + When implemented, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object + The type of the object the formatter creates a new instance of. + + + + When implemented, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Represents a trace writer. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + The that will be used to filter the trace messages passed to the writer. + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Provides methods to get and set values. + + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Contract details for a used by the . + + + + + Gets the of the collection items. + + The of the collection items. + + + + Gets a value indicating whether the collection type is a multidimensional array. + + true if the collection type is a multidimensional array; otherwise, false. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the collection values. + + true if the creator has a parameter with the collection values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the default collection items . + + The converter. + + + + Gets or sets a value indicating whether the collection items preserve object references. + + true if collection items preserve object references; otherwise, false. + + + + Gets or sets the collection item reference loop handling. + + The reference loop handling. + + + + Gets or sets the collection item type name handling. + + The type name handling. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Handles serialization callback events. + + The object that raised the callback event. + The streaming context. + + + + Handles serialization error callback events. + + The object that raised the callback event. + The streaming context. + The error context. + + + + Sets extension data for an object during deserialization. + + The object to set extension data on. + The extension data key. + The extension data value. + + + + Gets extension data for an object during serialization. + + The object to set extension data on. + + + + Contract details for a used by the . + + + + + Gets the underlying type for the contract. + + The underlying type for the contract. + + + + Gets or sets the type created during deserialization. + + The type created during deserialization. + + + + Gets or sets whether this type contract is serialized as a reference. + + Whether this type contract is serialized as a reference. + + + + Gets or sets the default for this contract. + + The converter. + + + + Gets the internally resolved for the contract's type. + This converter is used as a fallback converter when no other converter is resolved. + Setting will always override this converter. + + + + + Gets or sets all methods called immediately after deserialization of the object. + + The methods called immediately after deserialization of the object. + + + + Gets or sets all methods called during deserialization of the object. + + The methods called during deserialization of the object. + + + + Gets or sets all methods called after serialization of the object graph. + + The methods called after serialization of the object graph. + + + + Gets or sets all methods called before serialization of the object. + + The methods called before serialization of the object. + + + + Gets or sets all method called when an error is thrown during the serialization of the object. + + The methods called when an error is thrown during the serialization of the object. + + + + Gets or sets the default creator method used to create the object. + + The default creator method used to create the object. + + + + Gets or sets a value indicating whether the default creator is non-public. + + true if the default object creator is non-public; otherwise, false. + + + + Contract details for a used by the . + + + + + Gets or sets the dictionary key resolver. + + The dictionary key resolver. + + + + Gets the of the dictionary keys. + + The of the dictionary keys. + + + + Gets the of the dictionary values. + + The of the dictionary values. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the dictionary values. + + true if the creator has a parameter with the dictionary values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets the object's properties. + + The object's properties. + + + + Gets or sets the property name resolver. + + The property name resolver. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object constructor. + + The object constructor. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object member serialization. + + The member object serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets the object's properties. + + The object's properties. + + + + Gets a collection of instances that define the parameters used with . + + + + + Gets or sets the function used to create the object. When set this function will override . + This function is called with a collection of arguments which are defined by the collection. + + The function used to create the object. + + + + Gets or sets the extension data setter. + + + + + Gets or sets the extension data getter. + + + + + Gets or sets the extension data value type. + + + + + Gets or sets the extension data name resolver. + + The extension data name resolver. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Maps a JSON property to a .NET member or constructor parameter. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the type that declared this property. + + The type that declared this property. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets the name of the underlying member or parameter. + + The name of the underlying member or parameter. + + + + Gets the that will get and set the during serialization. + + The that will get and set the during serialization. + + + + Gets or sets the for this property. + + The for this property. + + + + Gets or sets the type of the property. + + The type of the property. + + + + Gets or sets the for the property. + If set this converter takes precedence over the contract converter for the property type. + + The converter. + + + + Gets or sets the member converter. + + The member converter. + + + + Gets or sets a value indicating whether this is ignored. + + true if ignored; otherwise, false. + + + + Gets or sets a value indicating whether this is readable. + + true if readable; otherwise, false. + + + + Gets or sets a value indicating whether this is writable. + + true if writable; otherwise, false. + + + + Gets or sets a value indicating whether this has a member attribute. + + true if has a member attribute; otherwise, false. + + + + Gets the default value. + + The default value. + + + + Gets or sets a value indicating whether this is required. + + A value indicating whether this is required. + + + + Gets a value indicating whether has a value specified. + + + + + Gets or sets a value indicating whether this property preserves object references. + + + true if this instance is reference; otherwise, false. + + + + + Gets or sets the property null value handling. + + The null value handling. + + + + Gets or sets the property default value handling. + + The default value handling. + + + + Gets or sets the property reference loop handling. + + The reference loop handling. + + + + Gets or sets the property object creation handling. + + The object creation handling. + + + + Gets or sets or sets the type name handling. + + The type name handling. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets a predicate used to determine whether the property should be deserialized. + + A predicate used to determine whether the property should be deserialized. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets an action used to set whether the property has been deserialized. + + An action used to set whether the property has been deserialized. + + + + Returns a that represents this instance. + + + A that represents this instance. + + + + + Gets or sets the converter used when serializing the property's collection items. + + The collection's items converter. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + A collection of objects. + + + + + Initializes a new instance of the class. + + The type. + + + + When implemented in a derived class, extracts the key from the specified element. + + The element from which to extract the key. + The key for the specified element. + + + + Adds a object. + + The property to add to the collection. + + + + Gets the closest matching object. + First attempts to get an exact case match of and then + a case insensitive match. + + Name of the property. + A matching property if found. + + + + Gets a property by property name. + + The name of the property to get. + Type property name string comparison. + A matching property if found. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Lookup and create an instance of the type described by the argument. + + The type to create. + Optional arguments to pass to an initializing constructor of the JsonConverter. + If null, the default constructor is used. + + + + A kebab case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Represents a trace writer that writes to memory. When the trace message limit is + reached then old trace messages will be removed as new messages are added. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + + The that will be used to filter the trace messages passed to the writer. + + + + + Initializes a new instance of the class. + + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Returns an enumeration of the most recent trace messages. + + An enumeration of the most recent trace messages. + + + + Returns a of the most recent trace messages. + + + A of the most recent trace messages. + + + + + A base class for resolving how property names and dictionary keys are serialized. + + + + + A flag indicating whether dictionary keys should be processed. + Defaults to false. + + + + + A flag indicating whether extension data names should be processed. + Defaults to false. + + + + + A flag indicating whether explicitly specified property names, + e.g. a property name customized with a , should be processed. + Defaults to false. + + + + + Gets the serialized name for a given property name. + + The initial property name. + A flag indicating whether the property has had a name explicitly specified. + The serialized property name. + + + + Gets the serialized name for a given extension data name. + + The initial extension data name. + The serialized extension data name. + + + + Gets the serialized key for a given dictionary key. + + The initial dictionary key. + The serialized dictionary key. + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Hash code calculation + + + + + + Object equality implementation + + + + + + + Compare to another NamingStrategy + + + + + + + Represents a method that constructs an object. + + The object type to create. + + + + When applied to a method, specifies that the method is called when an error occurs serializing an object. + + + + + Provides methods to get attributes from a , , or . + + + + + Initializes a new instance of the class. + + The instance to get attributes for. This parameter should be a , , or . + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Get and set values for a using reflection. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + A snake case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Specifies how strings are escaped when writing JSON text. + + + + + Only control characters (e.g. newline) are escaped. + + + + + All non-ASCII and control characters (e.g. newline) are escaped. + + + + + HTML (<, >, &, ', ") and control characters (e.g. newline) are escaped. + + + + + Indicates the method that will be used during deserialization for locating and loading assemblies. + + + + + In simple mode, the assembly used during deserialization need not match exactly the assembly used during serialization. Specifically, the version numbers need not match as the LoadWithPartialName method of the class is used to load the assembly. + + + + + In full mode, the assembly used during deserialization must match exactly the assembly used during serialization. The Load method of the class is used to load the assembly. + + + + + Specifies type name handling options for the . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Do not include the .NET type name when serializing types. + + + + + Include the .NET type name when serializing into a JSON object structure. + + + + + Include the .NET type name when serializing into a JSON array structure. + + + + + Always include the .NET type name when serializing. + + + + + Include the .NET type name when the type of the object being serialized is not the same as its declared type. + Note that this doesn't include the root serialized object by default. To include the root object's type name in JSON + you must specify a root type object with + or . + + + + + Determines whether the collection is null or empty. + + The collection. + + true if the collection is null or empty; otherwise, false. + + + + + Adds the elements of the specified collection to the specified generic . + + The list to add to. + The collection of elements to add. + + + + Converts the value to the specified type. If the value is unable to be converted, the + value is checked whether it assignable to the specified type. + + The value to convert. + The culture to use when converting. + The type to convert or cast the value to. + + The converted type. If conversion was unsuccessful, the initial value + is returned if assignable to the target type. + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic that returns a result + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic, but uses one of the arguments for + the result. + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic, but uses one of the arguments for + the result. + + + + + Returns a Restrictions object which includes our current restrictions merged + with a restriction limiting our type + + + + + Helper class for serializing immutable collections. + Note that this is used by all builds, even those that don't support immutable collections, in case the DLL is GACed + https://github.com/JamesNK/Newtonsoft.Json/issues/652 + + + + + Gets the type of the typed collection's items. + + The type. + The type of the typed collection's items. + + + + Gets the member's underlying type. + + The member. + The underlying type of the member. + + + + Determines whether the property is an indexed property. + + The property. + + true if the property is an indexed property; otherwise, false. + + + + + Gets the member's value on the object. + + The member. + The target object. + The member's value on the object. + + + + Sets the member's value on the target object. + + The member. + The target. + The value. + + + + Determines whether the specified MemberInfo can be read. + + The MemberInfo to determine whether can be read. + /// if set to true then allow the member to be gotten non-publicly. + + true if the specified MemberInfo can be read; otherwise, false. + + + + + Determines whether the specified MemberInfo can be set. + + The MemberInfo to determine whether can be set. + if set to true then allow the member to be set non-publicly. + if set to true then allow the member to be set if read-only. + + true if the specified MemberInfo can be set; otherwise, false. + + + + + Builds a string. Unlike this class lets you reuse its internal buffer. + + + + + Determines whether the string is all white space. Empty string will return false. + + The string to test whether it is all white space. + + true if the string is all white space; otherwise, false. + + + + + Specifies the state of the . + + + + + An exception has been thrown, which has left the in an invalid state. + You may call the method to put the in the Closed state. + Any other method calls result in an being thrown. + + + + + The method has been called. + + + + + An object is being written. + + + + + An array is being written. + + + + + A constructor is being written. + + + + + A property is being written. + + + + + A write method has not been called. + + + + Specifies that an output will not be null even if the corresponding type allows it. + + + Specifies that when a method returns , the parameter will not be null even if the corresponding type allows it. + + + Initializes the attribute with the specified return value condition. + + The return value condition. If the method returns this value, the associated parameter will not be null. + + + + Gets the return value condition. + + + Specifies that an output may be null even if the corresponding type disallows it. + + + Specifies that null is allowed as an input even if the corresponding type disallows it. + + + + Specifies that the method will not return if the associated Boolean parameter is passed the specified value. + + + + + Initializes a new instance of the class. + + + The condition parameter value. Code after the method will be considered unreachable by diagnostics if the argument to + the associated parameter matches this value. + + + + Gets the condition parameter value. + + + diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/netstandard1.0/Newtonsoft.Json.dll b/Packages/Newtonsoft.Json.13.0.1/lib/netstandard1.0/Newtonsoft.Json.dll new file mode 100644 index 0000000..8464ac9 Binary files /dev/null and b/Packages/Newtonsoft.Json.13.0.1/lib/netstandard1.0/Newtonsoft.Json.dll differ diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/netstandard1.0/Newtonsoft.Json.xml b/Packages/Newtonsoft.Json.13.0.1/lib/netstandard1.0/Newtonsoft.Json.xml new file mode 100644 index 0000000..53b811c --- /dev/null +++ b/Packages/Newtonsoft.Json.13.0.1/lib/netstandard1.0/Newtonsoft.Json.xml @@ -0,0 +1,10993 @@ + + + + Newtonsoft.Json + + + + + Represents a BSON Oid (object id). + + + + + Gets or sets the value of the Oid. + + The value of the Oid. + + + + Initializes a new instance of the class. + + The Oid value. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized BSON data. + + + + + Gets or sets a value indicating whether binary data reading should be compatible with incorrect Json.NET 3.5 written binary. + + + true if binary data reading will be compatible with incorrect Json.NET 3.5 written binary; otherwise, false. + + + + + Gets or sets a value indicating whether the root object will be read as a JSON array. + + + true if the root object will be read as a JSON array; otherwise, false. + + + + + Gets or sets the used when reading values from BSON. + + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating BSON data. + + + + + Gets or sets the used when writing values to BSON. + When set to no conversion will occur. + + The used when writing values to BSON. + + + + Initializes a new instance of the class. + + The to write to. + + + + Initializes a new instance of the class. + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying stream. + + + + + Writes the end. + + The token. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes the beginning of a JSON array. + + + + + Writes the beginning of a JSON object. + + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value that represents a BSON object id. + + The Object ID value to write. + + + + Writes a BSON regex. + + The regex pattern. + The regex options. + + + + Specifies how constructors are used when initializing objects during deserialization by the . + + + + + First attempt to use the public default constructor, then fall back to a single parameterized constructor, then to the non-public default constructor. + + + + + Json.NET will use a non-public default constructor before falling back to a parameterized constructor. + + + + + Converts a binary value to and from a base 64 string value. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Creates a custom object. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Creates an object which will then be populated by the serializer. + + Type of the object. + The created object. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can write JSON. + + + true if this can write JSON; otherwise, false. + + + + + Provides a base class for converting a to and from JSON. + + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a F# discriminated union type to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can write JSON. + + + true if this can write JSON; otherwise, false. + + + + + Converts a to and from the ISO 8601 date format (e.g. "2008-04-12T12:53Z"). + + + + + Gets or sets the date time styles used when converting a date to and from JSON. + + The date time styles used when converting a date to and from JSON. + + + + Gets or sets the date time format used when converting a date to and from JSON. + + The date time format used when converting a date to and from JSON. + + + + Gets or sets the culture used when converting a date to and from JSON. + + The culture used when converting a date to and from JSON. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Converts a to and from a JavaScript Date constructor (e.g. new Date(52231943)). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an to and from its name string value. + + + + + Gets or sets a value indicating whether the written enum text should be camel case. + The default value is false. + + true if the written enum text will be camel case; otherwise, false. + + + + Gets or sets the naming strategy used to resolve how enum text is written. + + The naming strategy used to resolve how enum text is written. + + + + Gets or sets a value indicating whether integer values are allowed when serializing and deserializing. + The default value is true. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class. + + true if the written enum text will be camel case; otherwise, false. + + + + Initializes a new instance of the class. + + The naming strategy used to resolve how enum text is written. + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from Unix epoch time + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from a string (e.g. "1.2.3.4"). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts XML to and from JSON. + + + + + Gets or sets the name of the root element to insert when deserializing to XML if the JSON structure has produced multiple root elements. + + The name of the deserialized root element. + + + + Gets or sets a value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + true if the array attribute is written to the XML; otherwise, false. + + + + Gets or sets a value indicating whether to write the root JSON object. + + true if the JSON root object is omitted; otherwise, false. + + + + Gets or sets a value indicating whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + true if special characters are encoded; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The calling serializer. + The value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Checks if the is a namespace attribute. + + Attribute name to test. + The attribute name prefix if it has one, otherwise an empty string. + true if attribute name is for a namespace attribute, otherwise false. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Specifies how dates are formatted when writing JSON text. + + + + + Dates are written in the ISO 8601 format, e.g. "2012-03-21T05:40Z". + + + + + Dates are written in the Microsoft JSON format, e.g. "\/Date(1198908717056)\/". + + + + + Specifies how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON text. + + + + + Date formatted strings are not parsed to a date type and are read as strings. + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Specifies how to treat the time value when converting between string and . + + + + + Treat as local time. If the object represents a Coordinated Universal Time (UTC), it is converted to the local time. + + + + + Treat as a UTC. If the object represents a local time, it is converted to a UTC. + + + + + Treat as a local time if a is being converted to a string. + If a string is being converted to , convert to a local time if a time zone is specified. + + + + + Time zone information should be preserved when converting. + + + + + The default JSON name table implementation. + + + + + Initializes a new instance of the class. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Adds the specified string into name table. + + The string to add. + This method is not thread-safe. + The resolved string. + + + + Specifies default value handling options for the . + + + + + + + + + Include members where the member value is the same as the member's default value when serializing objects. + Included members are written to JSON. Has no effect when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + so that it is not written to JSON. + This option will ignore all default values (e.g. null for objects and nullable types; 0 for integers, + decimals and floating point numbers; and false for booleans). The default value ignored can be changed by + placing the on the property. + + + + + Members with a default value but no JSON will be set to their default value when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + and set members to their default value when deserializing. + + + + + Specifies float format handling options when writing special floating point numbers, e.g. , + and with . + + + + + Write special floating point values as strings in JSON, e.g. "NaN", "Infinity", "-Infinity". + + + + + Write special floating point values as symbols in JSON, e.g. NaN, Infinity, -Infinity. + Note that this will produce non-valid JSON. + + + + + Write special floating point values as the property's default value in JSON, e.g. 0.0 for a property, null for a of property. + + + + + Specifies how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Floating point numbers are parsed to . + + + + + Floating point numbers are parsed to . + + + + + Specifies formatting options for the . + + + + + No special formatting is applied. This is the default. + + + + + Causes child objects to be indented according to the and settings. + + + + + Provides an interface for using pooled arrays. + + The array type content. + + + + Rent an array from the pool. This array must be returned when it is no longer needed. + + The minimum required length of the array. The returned array may be longer. + The rented array from the pool. This array must be returned when it is no longer needed. + + + + Return an array to the pool. + + The array that is being returned. + + + + Provides an interface to enable a class to return line and position information. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + The current line number or 0 if no line information is available (for example, when returns false). + + + + Gets the current line position. + + The current line position or 0 if no line information is available (for example, when returns false). + + + + Instructs the how to serialize the collection. + + + + + Gets or sets a value indicating whether null items are allowed in the collection. + + true if null items are allowed in the collection; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with a flag indicating whether the array can contain null items. + + A flag indicating whether the array can contain null items. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to use the specified constructor when deserializing that object. + + + + + Instructs the how to serialize the object. + + + + + Gets or sets the id. + + The id. + + + + Gets or sets the title. + + The title. + + + + Gets or sets the description. + + The description. + + + + Gets or sets the collection's items converter. + + The collection's items converter. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets a value that indicates whether to preserve object references. + + + true to keep object reference; otherwise, false. The default is false. + + + + + Gets or sets a value that indicates whether to preserve collection's items references. + + + true to keep collection's items object references; otherwise, false. The default is false. + + + + + Gets or sets the reference loop handling used when serializing the collection's items. + + The reference loop handling. + + + + Gets or sets the type name handling used when serializing the collection's items. + + The type name handling. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Provides methods for converting between .NET types and JSON types. + + + + + + + + Gets or sets a function that creates default . + Default settings are automatically used by serialization methods on , + and and on . + To serialize without using any default settings create a with + . + + + + + Represents JavaScript's boolean value true as a string. This field is read-only. + + + + + Represents JavaScript's boolean value false as a string. This field is read-only. + + + + + Represents JavaScript's null as a string. This field is read-only. + + + + + Represents JavaScript's undefined as a string. This field is read-only. + + + + + Represents JavaScript's positive infinity as a string. This field is read-only. + + + + + Represents JavaScript's negative infinity as a string. This field is read-only. + + + + + Represents JavaScript's NaN as a string. This field is read-only. + + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + The time zone handling when the date is converted to a string. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + The string escape handling. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Serializes the specified object to a JSON string. + + The object to serialize. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting. + + The object to serialize. + Indicates how the output should be formatted. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a collection of . + + The object to serialize. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting and a collection of . + + The object to serialize. + Indicates how the output should be formatted. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Deserializes the JSON to a .NET object. + + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to a .NET object using . + + The JSON to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The JSON to deserialize. + The of object being deserialized. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The type of the object to deserialize to. + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the given anonymous type. + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the given anonymous type using . + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The type of the object to deserialize to. + The JSON to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The type of the object to deserialize to. + The object to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The JSON to deserialize. + The type of the object to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The JSON to deserialize. + The type of the object to deserialize to. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Populates the object with values from the JSON string. + + The JSON to populate values from. + The target object to populate values onto. + + + + Populates the object with values from the JSON string using . + + The JSON to populate values from. + The target object to populate values onto. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + + + + Serializes the to a JSON string. + + The node to convert to JSON. + A JSON string of the . + + + + Serializes the to a JSON string using formatting. + + The node to convert to JSON. + Indicates how the output should be formatted. + A JSON string of the . + + + + Serializes the to a JSON string using formatting and omits the root object if is true. + + The node to serialize. + Indicates how the output should be formatted. + Omits writing the root object. + A JSON string of the . + + + + Deserializes the from a JSON string. + + The JSON string. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by . + + The JSON string. + The name of the root element to append when deserializing. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by + and writes a Json.NET array attribute for collections. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by , + writes a Json.NET array attribute for collections, and encodes special characters. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + + A value to indicate whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + The deserialized . + + + + Converts an object to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can read JSON. + + true if this can read JSON; otherwise, false. + + + + Gets a value indicating whether this can write JSON. + + true if this can write JSON; otherwise, false. + + + + Converts an object to and from JSON. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. If there is no existing value then null will be used. + The existing value has a value. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Instructs the to use the specified when serializing the member or class. + + + + + Gets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + + + + + Initializes a new instance of the class. + + Type of the . + + + + Initializes a new instance of the class. + + Type of the . + Parameter list to use when constructing the . Can be null. + + + + Represents a collection of . + + + + + Instructs the how to serialize the collection. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Instructs the to deserialize properties with no matching class member into the specified collection + and write values during serialization. + + + + + Gets or sets a value that indicates whether to write extension data when serializing the object. + + + true to write extension data when serializing the object; otherwise, false. The default is true. + + + + + Gets or sets a value that indicates whether to read extension data when deserializing the object. + + + true to read extension data when deserializing the object; otherwise, false. The default is true. + + + + + Initializes a new instance of the class. + + + + + Instructs the not to serialize the public field or public read/write property value. + + + + + Base class for a table of atomized string objects. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Instructs the how to serialize the object. + + + + + Gets or sets the member serialization. + + The member serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified member serialization. + + The member serialization. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to always serialize the member with the specified name. + + + + + Gets or sets the type used when serializing the property's collection items. + + The collection's items type. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the null value handling used when serializing this property. + + The null value handling. + + + + Gets or sets the default value handling used when serializing this property. + + The default value handling. + + + + Gets or sets the reference loop handling used when serializing this property. + + The reference loop handling. + + + + Gets or sets the object creation handling used when deserializing this property. + + The object creation handling. + + + + Gets or sets the type name handling used when serializing this property. + + The type name handling. + + + + Gets or sets whether this property's value is serialized as a reference. + + Whether this property's value is serialized as a reference. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets a value indicating whether this property is required. + + + A value indicating whether this property is required. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified name. + + Name of the property. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Asynchronously reads the next JSON token from the source. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns true if the next token was read successfully; false if there are no more tokens to read. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously skips the children of the current token. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a []. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the []. This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Specifies the state of the reader. + + + + + A read method has not been called. + + + + + The end of the file has been reached successfully. + + + + + Reader is at a property. + + + + + Reader is at the start of an object. + + + + + Reader is in an object. + + + + + Reader is at the start of an array. + + + + + Reader is in an array. + + + + + The method has been called. + + + + + Reader has just read a value. + + + + + Reader is at the start of a constructor. + + + + + Reader is in a constructor. + + + + + An error occurred that prevents the read operation from continuing. + + + + + The end of the file has been reached successfully. + + + + + Gets the current reader state. + + The current reader state. + + + + Gets or sets a value indicating whether the source should be closed when this reader is closed. + + + true to close the source when this reader is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether multiple pieces of JSON content can + be read from a continuous stream without erroring. + + + true to support reading multiple pieces of JSON content; otherwise false. + The default is false. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + Gets or sets how time zones are handled when reading JSON. + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Gets or sets how custom date formatted strings are parsed when reading JSON. + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets the type of the current JSON token. + + + + + Gets the text value of the current JSON token. + + + + + Gets the .NET type for the current JSON token. + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets or sets the culture used when reading JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Reads the next JSON token from the source. + + true if the next token was read successfully; false if there are no more tokens to read. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Skips the children of the current token. + + + + + Sets the current token. + + The new token. + + + + Sets the current token and value. + + The new token. + The value. + + + + Sets the current token and value. + + The new token. + The value. + A flag indicating whether the position index inside an array should be updated. + + + + Sets the state based on current token type. + + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Changes the reader's state to . + If is set to true, the source is also closed. + + + + + The exception thrown when an error occurs while reading JSON text. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Instructs the to always serialize the member, and to require that the member has a value. + + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Serializes and deserializes objects into and from the JSON format. + The enables you to control how objects are encoded into JSON. + + + + + Occurs when the errors during serialization and deserialization. + + + + + Gets or sets the used by the serializer when resolving references. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + + + + Gets or sets how reference loops (e.g. a class referencing itself) is handled. + The default value is . + + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets a collection that will be used during serialization. + + Collection that will be used during serialization. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets a value indicating whether there will be a check for additional JSON content after deserializing an object. + The default value is false. + + + true if there will be a check for additional JSON content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Creates a new instance. + The will not use default settings + from . + + + A new instance. + The will not use default settings + from . + + + + + Creates a new instance using the specified . + The will not use default settings + from . + + The settings to be applied to the . + + A new instance using the specified . + The will not use default settings + from . + + + + + Creates a new instance. + The will use default settings + from . + + + A new instance. + The will use default settings + from . + + + + + Creates a new instance using the specified . + The will use default settings + from as well as the specified . + + The settings to be applied to the . + + A new instance using the specified . + The will use default settings + from as well as the specified . + + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Deserializes the JSON structure contained by the specified . + + The that contains the JSON structure to deserialize. + The being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The type of the object to deserialize. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is Auto to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Specifies the settings on a object. + + + + + Gets or sets how reference loops (e.g. a class referencing itself) are handled. + The default value is . + + Reference loop handling. + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + Missing member handling. + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + Null value handling. + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + The default value handling. + + + + Gets or sets a collection that will be used during serialization. + + The converters. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + The preserve references handling. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + The type name handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + The contract resolver. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets the used by the serializer when resolving references. + + The reference resolver. + + + + Gets or sets a function that creates the used by the serializer when resolving references. + + A function that creates the used by the serializer when resolving references. + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the error handler called during serialization and deserialization. + + The error handler called during serialization and deserialization. + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets a value indicating whether there will be a check for additional content after deserializing an object. + The default value is false. + + + true if there will be a check for additional content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Represents a reader that provides fast, non-cached, forward-only access to JSON text data. + + + + + Asynchronously reads the next JSON token from the source. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns true if the next token was read successfully; false if there are no more tokens to read. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a []. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the []. This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Initializes a new instance of the class with the specified . + + The containing the JSON data to read. + + + + Gets or sets the reader's property name table. + + + + + Gets or sets the reader's character buffer pool. + + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + + The current line number or 0 if no line information is available (for example, returns false). + + + + + Gets the current line position. + + + The current line position or 0 if no line information is available (for example, returns false). + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Asynchronously flushes whatever is in the buffer to the destination and also flushes the destination. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the JSON value delimiter. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the specified end token. + + The end token to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously closes this writer. + If is set to true, the destination is also closed. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of the current JSON object or array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes indent characters. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes an indent space. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes raw JSON without changing the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a null value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the beginning of a JSON array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the beginning of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the start of a constructor with the given name. + + The name of the constructor. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes an undefined value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the given white space. + + The string of white space characters. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a [] value. + + The [] value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of an array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of a constructor. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Gets or sets the writer's character array pool. + + + + + Gets or sets how many s to write for each level in the hierarchy when is set to . + + + + + Gets or sets which character to use to quote attribute values. + + + + + Gets or sets which character to use for indenting when is set to . + + + + + Gets or sets a value indicating whether object names will be surrounded with quotes. + + + + + Initializes a new instance of the class using the specified . + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying . + + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the specified end token. + + The end token to write. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Specifies the type of JSON token. + + + + + This is returned by the if a read method has not been called. + + + + + An object start token. + + + + + An array start token. + + + + + A constructor start token. + + + + + An object property name. + + + + + A comment. + + + + + Raw JSON. + + + + + An integer. + + + + + A float. + + + + + A string. + + + + + A boolean. + + + + + A null token. + + + + + An undefined token. + + + + + An object end token. + + + + + An array end token. + + + + + A constructor end token. + + + + + A Date. + + + + + Byte data. + + + + + + Represents a reader that provides validation. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Sets an event handler for receiving schema validation errors. + + + + + Gets the text value of the current JSON token. + + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + + Gets the type of the current JSON token. + + + + + + Gets the .NET type for the current JSON token. + + + + + + Initializes a new instance of the class that + validates the content returned from the given . + + The to read from while validating. + + + + Gets or sets the schema. + + The schema. + + + + Gets the used to construct this . + + The specified in the constructor. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a []. + + + A [] or null if the next JSON token is null. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Asynchronously closes this writer. + If is set to true, the destination is also closed. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously flushes whatever is in the buffer to the destination and also flushes the destination. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the specified end token. + + The end token to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes indent characters. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the JSON value delimiter. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes an indent space. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes raw JSON without changing the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of the current JSON object or array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of an array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of a constructor. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a null value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the beginning of a JSON array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the start of a constructor with the given name. + + The name of the constructor. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the beginning of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the current token. + + The to read the token from. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the current token. + + The to read the token from. + A flag indicating whether the current token's children should be written. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the token and its value. + + The to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the token and its value. + + The to write. + + The value to write. + A value is only required for tokens that have an associated value, e.g. the property name for . + null can be passed to the method for tokens that don't have a value, e.g. . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a [] value. + + The [] value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes an undefined value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the given white space. + + The string of white space characters. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously ets the state of the . + + The being written. + The value being written. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Gets or sets a value indicating whether the destination should be closed when this writer is closed. + + + true to close the destination when this writer is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether the JSON should be auto-completed when this writer is closed. + + + true to auto-complete the JSON when this writer is closed; otherwise false. The default is true. + + + + + Gets the top. + + The top. + + + + Gets the state of the writer. + + + + + Gets the path of the writer. + + + + + Gets or sets a value indicating how JSON text output should be formatted. + + + + + Gets or sets how dates are written to JSON text. + + + + + Gets or sets how time zones are handled when writing JSON text. + + + + + Gets or sets how strings are escaped when writing JSON text. + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written to JSON text. + + + + + Gets or sets how and values are formatted when writing JSON text. + + + + + Gets or sets the culture used when writing JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the destination and also flushes the destination. + + + + + Closes this writer. + If is set to true, the destination is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the end of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the end of an array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end constructor. + + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes the end of the current JSON object or array. + + + + + Writes the current token and its children. + + The to read the token from. + + + + Writes the current token. + + The to read the token from. + A flag indicating whether the current token's children should be written. + + + + Writes the token and its value. + + The to write. + + The value to write. + A value is only required for tokens that have an associated value, e.g. the property name for . + null can be passed to the method for tokens that don't have a value, e.g. . + + + + + Writes the token. + + The to write. + + + + Writes the specified end token. + + The end token to write. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON without changing the writer's state. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Sets the state of the . + + The being written. + The value being written. + + + + The exception thrown when an error occurs while writing JSON text. + + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class + with a specified error message, JSON path and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Specifies how JSON comments are handled when loading JSON. + + + + + Ignore comments. + + + + + Load comments as a with type . + + + + + Specifies how duplicate property names are handled when loading JSON. + + + + + Replace the existing value when there is a duplicate property. The value of the last property in the JSON object will be used. + + + + + Ignore the new value when there is a duplicate property. The value of the first property in the JSON object will be used. + + + + + Throw a when a duplicate property is encountered. + + + + + Contains the LINQ to JSON extension methods. + + + + + Returns a collection of tokens that contains the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the descendants of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, and the descendants of every token in the source collection. + + + + Returns a collection of child properties of every object in the source collection. + + An of that contains the source collection. + An of that contains the properties of every object in the source collection. + + + + Returns a collection of child values of every object in the source collection with the given key. + + An of that contains the source collection. + The token key. + An of that contains the values of every token in the source collection with the given key. + + + + Returns a collection of child values of every object in the source collection. + + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child values of every object in the source collection with the given key. + + The type to convert the values to. + An of that contains the source collection. + The token key. + An that contains the converted values of every token in the source collection with the given key. + + + + Returns a collection of converted child values of every object in the source collection. + + The type to convert the values to. + An of that contains the source collection. + An that contains the converted values of every token in the source collection. + + + + Converts the value. + + The type to convert the value to. + A cast as a of . + A converted value. + + + + Converts the value. + + The source collection type. + The type to convert the value to. + A cast as a of . + A converted value. + + + + Returns a collection of child tokens of every array in the source collection. + + The source collection type. + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child tokens of every array in the source collection. + + An of that contains the source collection. + The type to convert the values to. + The source collection type. + An that contains the converted values of every token in the source collection. + + + + Returns the input typed as . + + An of that contains the source collection. + The input typed as . + + + + Returns the input typed as . + + The source collection type. + An of that contains the source collection. + The input typed as . + + + + Represents a collection of objects. + + The type of token. + + + + Gets the of with the specified key. + + + + + + Represents a JSON array. + + + + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous load. The property contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous load. The property contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Loads an from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads an from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the at the specified index. + + + + + + Determines the index of a specific item in the . + + The object to locate in the . + + The index of if found in the list; otherwise, -1. + + + + + Inserts an item to the at the specified index. + + The zero-based index at which should be inserted. + The object to insert into the . + + is not a valid index in the . + + + + + Removes the item at the specified index. + + The zero-based index of the item to remove. + + is not a valid index in the . + + + + + Returns an enumerator that iterates through the collection. + + + A of that can be used to iterate through the collection. + + + + + Adds an item to the . + + The object to add to the . + + + + Removes all items from the . + + + + + Determines whether the contains a specific value. + + The object to locate in the . + + true if is found in the ; otherwise, false. + + + + + Copies the elements of the to an array, starting at a particular array index. + + The array. + Index of the array. + + + + Gets a value indicating whether the is read-only. + + true if the is read-only; otherwise, false. + + + + Removes the first occurrence of a specific object from the . + + The object to remove from the . + + true if was successfully removed from the ; otherwise, false. This method also returns false if is not found in the original . + + + + + Represents a JSON constructor. + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets or sets the name of this constructor. + + The constructor name. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name. + + The constructor name. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a token that can contain other tokens. + + + + + Occurs when the items list of the collection has changed, or the collection is reset. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Raises the event. + + The instance containing the event data. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Get the first child token of this token. + + + A containing the first child token of the . + + + + + Get the last child token of this token. + + + A containing the last child token of the . + + + + + Returns a collection of the child tokens of this token, in document order. + + + An of containing the child tokens of this , in document order. + + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + + A containing the child values of this , in document order. + + + + + Returns a collection of the descendant tokens for this token in document order. + + An of containing the descendant tokens of the . + + + + Returns a collection of the tokens that contain this token, and all descendant tokens of this token, in document order. + + An of containing this token, and all the descendant tokens of the . + + + + Adds the specified content as children of this . + + The content to be added. + + + + Adds the specified content as the first children of this . + + The content to be added. + + + + Creates a that can be used to add tokens to the . + + A that is ready to have content written to it. + + + + Replaces the child nodes of this token with the specified content. + + The content. + + + + Removes the child nodes from this token. + + + + + Merge the specified content into this . + + The content to be merged. + + + + Merge the specified content into this using . + + The content to be merged. + The used to merge the content. + + + + Gets the count of child JSON tokens. + + The count of child JSON tokens. + + + + Represents a collection of objects. + + The type of token. + + + + An empty collection of objects. + + + + + Initializes a new instance of the struct. + + The enumerable. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Gets the of with the specified key. + + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Returns a hash code for this instance. + + + A hash code for this instance, suitable for use in hashing algorithms and data structures like a hash table. + + + + + Represents a JSON object. + + + + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Occurs when a property value changes. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Gets the node type for this . + + The type. + + + + Gets an of of this object's properties. + + An of of this object's properties. + + + + Gets a with the specified name. + + The property name. + A with the specified name or null. + + + + Gets the with the specified name. + The exact name will be searched for first and if no matching property is found then + the will be used to match a property. + + The property name. + One of the enumeration values that specifies how the strings will be compared. + A matched with the specified name or null. + + + + Gets a of of this object's property values. + + A of of this object's property values. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the with the specified property name. + + + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified property name. + + Name of the property. + The with the specified property name. + + + + Gets the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + One of the enumeration values that specifies how the strings will be compared. + The with the specified property name. + + + + Tries to get the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + The value. + One of the enumeration values that specifies how the strings will be compared. + true if a value was successfully retrieved; otherwise, false. + + + + Adds the specified property name. + + Name of the property. + The value. + + + + Determines whether the JSON object has the specified property name. + + Name of the property. + true if the JSON object has the specified property name; otherwise, false. + + + + Removes the property with the specified name. + + Name of the property. + true if item was successfully removed; otherwise, false. + + + + Tries to get the with the specified property name. + + Name of the property. + The value. + true if a value was successfully retrieved; otherwise, false. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Raises the event with the provided arguments. + + Name of the property. + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Represents a JSON property. + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous creation. The + property returns a that contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous creation. The + property returns a that contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the property name. + + The property name. + + + + Gets or sets the property value. + + The property value. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a raw JSON string. + + + + + Asynchronously creates an instance of with the content of the reader's current token. + + The reader. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous creation. The + property returns an instance of with the content of the reader's current token. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class. + + The raw json. + + + + Creates an instance of with the content of the reader's current token. + + The reader. + An instance of with the content of the reader's current token. + + + + Specifies the settings used when loading JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets how JSON comments are handled when loading JSON. + The default value is . + + The JSON comment handling. + + + + Gets or sets how JSON line info is handled when loading JSON. + The default value is . + + The JSON line info handling. + + + + Gets or sets how duplicate property names in JSON objects are handled when loading JSON. + The default value is . + + The JSON duplicate property name handling. + + + + Specifies the settings used when merging JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets the method used when merging JSON arrays. + + The method used when merging JSON arrays. + + + + Gets or sets how null value properties are merged. + + How null value properties are merged. + + + + Gets or sets the comparison used to match property names while merging. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + The comparison used to match property names while merging. + + + + Specifies the settings used when selecting JSON. + + + + + Gets or sets a timeout that will be used when executing regular expressions. + + The timeout that will be used when executing regular expressions. + + + + Gets or sets a flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + A flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + + + Represents an abstract JSON token. + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Writes this token to a asynchronously. + + A into which this method will write. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously creates a from a . + + An positioned at the token to read into this . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains + the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Asynchronously creates a from a . + + An positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains + the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Asynchronously creates a from a . + + A positioned at the token to read into this . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Asynchronously creates a from a . + + A positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Gets a comparer that can compare two tokens for value equality. + + A that can compare two nodes for value equality. + + + + Gets or sets the parent. + + The parent. + + + + Gets the root of this . + + The root of this . + + + + Gets the node type for this . + + The type. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Compares the values of two tokens, including the values of all descendant tokens. + + The first to compare. + The second to compare. + true if the tokens are equal; otherwise false. + + + + Gets the next sibling token of this node. + + The that contains the next sibling token. + + + + Gets the previous sibling token of this node. + + The that contains the previous sibling token. + + + + Gets the path of the JSON token. + + + + + Adds the specified content immediately after this token. + + A content object that contains simple content or a collection of content objects to be added after this token. + + + + Adds the specified content immediately before this token. + + A content object that contains simple content or a collection of content objects to be added before this token. + + + + Returns a collection of the ancestor tokens of this token. + + A collection of the ancestor tokens of this token. + + + + Returns a collection of tokens that contain this token, and the ancestors of this token. + + A collection of tokens that contain this token, and the ancestors of this token. + + + + Returns a collection of the sibling tokens after this token, in document order. + + A collection of the sibling tokens after this tokens, in document order. + + + + Returns a collection of the sibling tokens before this token, in document order. + + A collection of the sibling tokens before this token, in document order. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets the with the specified key converted to the specified type. + + The type to convert the token to. + The token key. + The converted token value. + + + + Get the first child token of this token. + + A containing the first child token of the . + + + + Get the last child token of this token. + + A containing the last child token of the . + + + + Returns a collection of the child tokens of this token, in document order. + + An of containing the child tokens of this , in document order. + + + + Returns a collection of the child tokens of this token, in document order, filtered by the specified type. + + The type to filter the child tokens on. + A containing the child tokens of this , in document order. + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + A containing the child values of this , in document order. + + + + Removes this token from its parent. + + + + + Replaces this token with the specified token. + + The value. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Returns the indented JSON for this token. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + The indented JSON for this token. + + + + + Returns the JSON for this token using the given formatting and converters. + + Indicates how the output should be formatted. + A collection of s which will be used when writing the token. + The JSON for this token using the given formatting and converters. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to []. + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from [] to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Creates a for this token. + + A that can be used to read this token and its descendants. + + + + Creates a from an object. + + The object that will be used to create . + A with the value of the specified object. + + + + Creates a from an object using the specified . + + The object that will be used to create . + The that will be used when reading the object. + A with the value of the specified object. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + An positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + Creates a from a . + + A positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A , or null. + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + A . + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + The used to select tokens. + A . + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + The used to select tokens. + An of that contains the selected elements. + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Creates a new instance of the . All child tokens are recursively cloned. + + A new instance of the . + + + + Adds an object to the annotation list of this . + + The annotation to add. + + + + Get the first annotation object of the specified type from this . + + The type of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets the first annotation object of the specified type from this . + + The of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets a collection of annotations of the specified type for this . + + The type of the annotations to retrieve. + An that contains the annotations for this . + + + + Gets a collection of annotations of the specified type for this . + + The of the annotations to retrieve. + An of that contains the annotations that match the specified type for this . + + + + Removes the annotations of the specified type from this . + + The type of annotations to remove. + + + + Removes the annotations of the specified type from this . + + The of annotations to remove. + + + + Compares tokens to determine whether they are equal. + + + + + Determines whether the specified objects are equal. + + The first object of type to compare. + The second object of type to compare. + + true if the specified objects are equal; otherwise, false. + + + + + Returns a hash code for the specified object. + + The for which a hash code is to be returned. + A hash code for the specified object. + The type of is a reference type and is null. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Gets the at the reader's current position. + + + + + Initializes a new instance of the class. + + The token to read from. + + + + Initializes a new instance of the class. + + The token to read from. + The initial path of the token. It is prepended to the returned . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Gets the path of the current JSON token. + + + + + Specifies the type of token. + + + + + No token type has been set. + + + + + A JSON object. + + + + + A JSON array. + + + + + A JSON constructor. + + + + + A JSON object property. + + + + + A comment. + + + + + An integer value. + + + + + A float value. + + + + + A string value. + + + + + A boolean value. + + + + + A null value. + + + + + An undefined value. + + + + + A date value. + + + + + A raw JSON value. + + + + + A collection of bytes value. + + + + + A Guid value. + + + + + A Uri value. + + + + + A TimeSpan value. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets the at the writer's current position. + + + + + Gets the token being written. + + The token being written. + + + + Initializes a new instance of the class writing to the given . + + The container being written to. + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the underlying . + + + + + Closes this writer. + If is set to true, the JSON is auto-completed. + + + Setting to true has no additional effect, since the underlying is a type that cannot be closed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end. + + The token. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes a value. + An error will be raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Represents a value in JSON (string, integer, date, etc). + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Creates a comment with the given value. + + The value. + A comment with the given value. + + + + Creates a string with the given value. + + The value. + A string with the given value. + + + + Creates a null value. + + A null value. + + + + Creates a undefined value. + + A undefined value. + + + + Gets the node type for this . + + The type. + + + + Gets or sets the underlying token value. + + The underlying token value. + + + + Writes this token to a . + + A into which this method will write. + A collection of s which will be used when writing the token. + + + + Indicates whether the current object is equal to another object of the same type. + + + true if the current object is equal to the parameter; otherwise, false. + + An object to compare with this object. + + + + Determines whether the specified is equal to the current . + + The to compare with the current . + + true if the specified is equal to the current ; otherwise, false. + + + + + Serves as a hash function for a particular type. + + + A hash code for the current . + + + + + Returns a that represents this instance. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format provider. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + The format provider. + + A that represents this instance. + + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Compares the current instance with another object of the same type and returns an integer that indicates whether the current instance precedes, follows, or occurs in the same position in the sort order as the other object. + + An object to compare with this instance. + + A 32-bit signed integer that indicates the relative order of the objects being compared. The return value has these meanings: + Value + Meaning + Less than zero + This instance is less than . + Zero + This instance is equal to . + Greater than zero + This instance is greater than . + + + is not of the same type as this instance. + + + + + Specifies how line information is handled when loading JSON. + + + + + Ignore line information. + + + + + Load line information. + + + + + Specifies how JSON arrays are merged together. + + + + Concatenate arrays. + + + Union arrays, skipping items that already exist. + + + Replace all array items. + + + Merge array items together, matched by index. + + + + Specifies how null value properties are merged. + + + + + The content's null value properties will be ignored during merging. + + + + + The content's null value properties will be merged. + + + + + Specifies the member serialization options for the . + + + + + All public members are serialized by default. Members can be excluded using or . + This is the default member serialization mode. + + + + + Only members marked with or are serialized. + This member serialization mode can also be set by marking the class with . + + + + + All public and private fields are serialized. Members can be excluded using or . + This member serialization mode can also be set by marking the class with + and setting IgnoreSerializableAttribute on to false. + + + + + Specifies metadata property handling options for the . + + + + + Read metadata properties located at the start of a JSON object. + + + + + Read metadata properties located anywhere in a JSON object. Note that this setting will impact performance. + + + + + Do not try to read metadata properties. + + + + + Specifies missing member handling options for the . + + + + + Ignore a missing member and do not attempt to deserialize it. + + + + + Throw a when a missing member is encountered during deserialization. + + + + + Specifies null value handling options for the . + + + + + + + + + Include null values when serializing and deserializing objects. + + + + + Ignore null values when serializing and deserializing objects. + + + + + Specifies how object creation is handled by the . + + + + + Reuse existing objects, create new objects when needed. + + + + + Only reuse existing objects. + + + + + Always create new objects. + + + + + Specifies reference handling options for the . + Note that references cannot be preserved when a value is set via a non-default constructor such as types that implement . + + + + + + + + Do not preserve references when serializing types. + + + + + Preserve references when serializing into a JSON object structure. + + + + + Preserve references when serializing into a JSON array structure. + + + + + Preserve references when serializing. + + + + + Specifies reference loop handling options for the . + + + + + Throw a when a loop is encountered. + + + + + Ignore loop references and do not serialize. + + + + + Serialize loop references. + + + + + Indicating whether a property is required. + + + + + The property is not required. The default state. + + + + + The property must be defined in JSON but can be a null value. + + + + + The property must be defined in JSON and cannot be a null value. + + + + + The property is not required but it cannot be a null value. + + + + + + Contains the JSON schema extension methods. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + true if the specified is valid; otherwise, false. + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + When this method returns, contains any error messages generated while validating. + + true if the specified is valid; otherwise, false. + + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + The validation event handler. + + + + + An in-memory representation of a JSON Schema. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the id. + + + + + Gets or sets the title. + + + + + Gets or sets whether the object is required. + + + + + Gets or sets whether the object is read-only. + + + + + Gets or sets whether the object is visible to users. + + + + + Gets or sets whether the object is transient. + + + + + Gets or sets the description of the object. + + + + + Gets or sets the types of values allowed by the object. + + The type. + + + + Gets or sets the pattern. + + The pattern. + + + + Gets or sets the minimum length. + + The minimum length. + + + + Gets or sets the maximum length. + + The maximum length. + + + + Gets or sets a number that the value should be divisible by. + + A number that the value should be divisible by. + + + + Gets or sets the minimum. + + The minimum. + + + + Gets or sets the maximum. + + The maximum. + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the minimum attribute (). + + A flag indicating whether the value can not equal the number defined by the minimum attribute (). + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the maximum attribute (). + + A flag indicating whether the value can not equal the number defined by the maximum attribute (). + + + + Gets or sets the minimum number of items. + + The minimum number of items. + + + + Gets or sets the maximum number of items. + + The maximum number of items. + + + + Gets or sets the of items. + + The of items. + + + + Gets or sets a value indicating whether items in an array are validated using the instance at their array position from . + + + true if items are validated using their array position; otherwise, false. + + + + + Gets or sets the of additional items. + + The of additional items. + + + + Gets or sets a value indicating whether additional items are allowed. + + + true if additional items are allowed; otherwise, false. + + + + + Gets or sets whether the array items must be unique. + + + + + Gets or sets the of properties. + + The of properties. + + + + Gets or sets the of additional properties. + + The of additional properties. + + + + Gets or sets the pattern properties. + + The pattern properties. + + + + Gets or sets a value indicating whether additional properties are allowed. + + + true if additional properties are allowed; otherwise, false. + + + + + Gets or sets the required property if this property is present. + + The required property if this property is present. + + + + Gets or sets the a collection of valid enum values allowed. + + A collection of valid enum values allowed. + + + + Gets or sets disallowed types. + + The disallowed types. + + + + Gets or sets the default value. + + The default value. + + + + Gets or sets the collection of that this schema extends. + + The collection of that this schema extends. + + + + Gets or sets the format. + + The format. + + + + Initializes a new instance of the class. + + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The object representing the JSON Schema. + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The to use when resolving schema references. + The object representing the JSON Schema. + + + + Load a from a string that contains JSON Schema. + + A that contains JSON Schema. + A populated from the string that contains JSON Schema. + + + + Load a from a string that contains JSON Schema using the specified . + + A that contains JSON Schema. + The resolver. + A populated from the string that contains JSON Schema. + + + + Writes this schema to a . + + A into which this method will write. + + + + Writes this schema to a using the specified . + + A into which this method will write. + The resolver used. + + + + Returns a that represents the current . + + + A that represents the current . + + + + + + Returns detailed information about the schema exception. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + + Generates a from a specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets how undefined schemas are handled by the serializer. + + + + + Gets or sets the contract resolver. + + The contract resolver. + + + + Generate a from the specified type. + + The type to generate a from. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + + Resolves from an id. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the loaded schemas. + + The loaded schemas. + + + + Initializes a new instance of the class. + + + + + Gets a for the specified reference. + + The id. + A for the specified reference. + + + + + The value types allowed by the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + No type specified. + + + + + String type. + + + + + Float type. + + + + + Integer type. + + + + + Boolean type. + + + + + Object type. + + + + + Array type. + + + + + Null type. + + + + + Any type. + + + + + + Specifies undefined schema Id handling options for the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Do not infer a schema Id. + + + + + Use the .NET type name as the schema Id. + + + + + Use the assembly qualified .NET type name as the schema Id. + + + + + + Returns detailed information related to the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the associated with the validation error. + + The JsonSchemaException associated with the validation error. + + + + Gets the path of the JSON location where the validation error occurred. + + The path of the JSON location where the validation error occurred. + + + + Gets the text description corresponding to the validation error. + + The text description. + + + + + Represents the callback method that will handle JSON schema validation events and the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Allows users to control class loading and mandate what class to load. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object + The type of the object the formatter creates a new instance of. + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + A camel case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Resolves member mappings for a type, camel casing property names. + + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used by to resolve a for a given . + + + + + Gets a value indicating whether members are being get and set using dynamic code generation. + This value is determined by the runtime permissions available. + + + true if using dynamic code generation; otherwise, false. + + + + + Gets or sets a value indicating whether compiler generated members should be serialized. + + + true if serialized compiler generated members; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore IsSpecified members when serializing and deserializing types. + + + true if the IsSpecified members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore ShouldSerialize members when serializing and deserializing types. + + + true if the ShouldSerialize members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets the naming strategy used to resolve how property names and dictionary keys are serialized. + + The naming strategy used to resolve how property names and dictionary keys are serialized. + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Gets the serializable members for the type. + + The type to get serializable members for. + The serializable members for the type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates the constructor parameters. + + The constructor to create properties for. + The type's member properties. + Properties for the given . + + + + Creates a for the given . + + The matching member property. + The constructor parameter. + A created for the given . + + + + Resolves the default for the contract. + + Type of the object. + The contract's default . + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Determines which contract type is created for the given type. + + Type of the object. + A for the given type. + + + + Creates properties for the given . + + The type to create properties for. + /// The member serialization mode for the type. + Properties for the given . + + + + Creates the used by the serializer to get and set values from a member. + + The member. + The used by the serializer to get and set values from a member. + + + + Creates a for the given . + + The member's parent . + The member to create a for. + A created for the given . + + + + Resolves the name of the property. + + Name of the property. + Resolved name of the property. + + + + Resolves the name of the extension data. By default no changes are made to extension data names. + + Name of the extension data. + Resolved name of the extension data. + + + + Resolves the key of the dictionary. By default is used to resolve dictionary keys. + + Key of the dictionary. + Resolved key of the dictionary. + + + + Gets the resolved name of the property. + + Name of the property. + Name of the property. + + + + The default naming strategy. Property names and dictionary keys are unchanged. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + The default serialization binder used when resolving and loading classes from type names. + + + + + Initializes a new instance of the class. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + The type of the object the formatter creates a new instance of. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Provides information surrounding an error. + + + + + Gets the error. + + The error. + + + + Gets the original object that caused the error. + + The original object that caused the error. + + + + Gets the member that caused the error. + + The member that caused the error. + + + + Gets the path of the JSON location where the error occurred. + + The path of the JSON location where the error occurred. + + + + Gets or sets a value indicating whether this is handled. + + true if handled; otherwise, false. + + + + Provides data for the Error event. + + + + + Gets the current object the error event is being raised against. + + The current object the error event is being raised against. + + + + Gets the error context. + + The error context. + + + + Initializes a new instance of the class. + + The current object. + The error context. + + + + Get and set values for a using dynamic methods. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Provides methods to get attributes. + + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Used by to resolve a for a given . + + + + + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used to resolve references when serializing and deserializing JSON by the . + + + + + Resolves a reference to its object. + + The serialization context. + The reference to resolve. + The object that was resolved from the reference. + + + + Gets the reference for the specified object. + + The serialization context. + The object to get a reference for. + The reference to the object. + + + + Determines whether the specified object is referenced. + + The serialization context. + The object to test for a reference. + + true if the specified object is referenced; otherwise, false. + + + + + Adds a reference to the specified object. + + The serialization context. + The reference. + The object to reference. + + + + Allows users to control class loading and mandate what class to load. + + + + + When implemented, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object + The type of the object the formatter creates a new instance of. + + + + When implemented, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Represents a trace writer. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + The that will be used to filter the trace messages passed to the writer. + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Provides methods to get and set values. + + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Contract details for a used by the . + + + + + Gets the of the collection items. + + The of the collection items. + + + + Gets a value indicating whether the collection type is a multidimensional array. + + true if the collection type is a multidimensional array; otherwise, false. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the collection values. + + true if the creator has a parameter with the collection values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the default collection items . + + The converter. + + + + Gets or sets a value indicating whether the collection items preserve object references. + + true if collection items preserve object references; otherwise, false. + + + + Gets or sets the collection item reference loop handling. + + The reference loop handling. + + + + Gets or sets the collection item type name handling. + + The type name handling. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Handles serialization callback events. + + The object that raised the callback event. + The streaming context. + + + + Handles serialization error callback events. + + The object that raised the callback event. + The streaming context. + The error context. + + + + Sets extension data for an object during deserialization. + + The object to set extension data on. + The extension data key. + The extension data value. + + + + Gets extension data for an object during serialization. + + The object to set extension data on. + + + + Contract details for a used by the . + + + + + Gets the underlying type for the contract. + + The underlying type for the contract. + + + + Gets or sets the type created during deserialization. + + The type created during deserialization. + + + + Gets or sets whether this type contract is serialized as a reference. + + Whether this type contract is serialized as a reference. + + + + Gets or sets the default for this contract. + + The converter. + + + + Gets the internally resolved for the contract's type. + This converter is used as a fallback converter when no other converter is resolved. + Setting will always override this converter. + + + + + Gets or sets all methods called immediately after deserialization of the object. + + The methods called immediately after deserialization of the object. + + + + Gets or sets all methods called during deserialization of the object. + + The methods called during deserialization of the object. + + + + Gets or sets all methods called after serialization of the object graph. + + The methods called after serialization of the object graph. + + + + Gets or sets all methods called before serialization of the object. + + The methods called before serialization of the object. + + + + Gets or sets all method called when an error is thrown during the serialization of the object. + + The methods called when an error is thrown during the serialization of the object. + + + + Gets or sets the default creator method used to create the object. + + The default creator method used to create the object. + + + + Gets or sets a value indicating whether the default creator is non-public. + + true if the default object creator is non-public; otherwise, false. + + + + Contract details for a used by the . + + + + + Gets or sets the dictionary key resolver. + + The dictionary key resolver. + + + + Gets the of the dictionary keys. + + The of the dictionary keys. + + + + Gets the of the dictionary values. + + The of the dictionary values. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the dictionary values. + + true if the creator has a parameter with the dictionary values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets the object's properties. + + The object's properties. + + + + Gets or sets the property name resolver. + + The property name resolver. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object member serialization. + + The member object serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets the object's properties. + + The object's properties. + + + + Gets a collection of instances that define the parameters used with . + + + + + Gets or sets the function used to create the object. When set this function will override . + This function is called with a collection of arguments which are defined by the collection. + + The function used to create the object. + + + + Gets or sets the extension data setter. + + + + + Gets or sets the extension data getter. + + + + + Gets or sets the extension data value type. + + + + + Gets or sets the extension data name resolver. + + The extension data name resolver. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Maps a JSON property to a .NET member or constructor parameter. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the type that declared this property. + + The type that declared this property. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets the name of the underlying member or parameter. + + The name of the underlying member or parameter. + + + + Gets the that will get and set the during serialization. + + The that will get and set the during serialization. + + + + Gets or sets the for this property. + + The for this property. + + + + Gets or sets the type of the property. + + The type of the property. + + + + Gets or sets the for the property. + If set this converter takes precedence over the contract converter for the property type. + + The converter. + + + + Gets or sets the member converter. + + The member converter. + + + + Gets or sets a value indicating whether this is ignored. + + true if ignored; otherwise, false. + + + + Gets or sets a value indicating whether this is readable. + + true if readable; otherwise, false. + + + + Gets or sets a value indicating whether this is writable. + + true if writable; otherwise, false. + + + + Gets or sets a value indicating whether this has a member attribute. + + true if has a member attribute; otherwise, false. + + + + Gets the default value. + + The default value. + + + + Gets or sets a value indicating whether this is required. + + A value indicating whether this is required. + + + + Gets a value indicating whether has a value specified. + + + + + Gets or sets a value indicating whether this property preserves object references. + + + true if this instance is reference; otherwise, false. + + + + + Gets or sets the property null value handling. + + The null value handling. + + + + Gets or sets the property default value handling. + + The default value handling. + + + + Gets or sets the property reference loop handling. + + The reference loop handling. + + + + Gets or sets the property object creation handling. + + The object creation handling. + + + + Gets or sets or sets the type name handling. + + The type name handling. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets a predicate used to determine whether the property should be deserialized. + + A predicate used to determine whether the property should be deserialized. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets an action used to set whether the property has been deserialized. + + An action used to set whether the property has been deserialized. + + + + Returns a that represents this instance. + + + A that represents this instance. + + + + + Gets or sets the converter used when serializing the property's collection items. + + The collection's items converter. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + A collection of objects. + + + + + Initializes a new instance of the class. + + The type. + + + + When implemented in a derived class, extracts the key from the specified element. + + The element from which to extract the key. + The key for the specified element. + + + + Adds a object. + + The property to add to the collection. + + + + Gets the closest matching object. + First attempts to get an exact case match of and then + a case insensitive match. + + Name of the property. + A matching property if found. + + + + Gets a property by property name. + + The name of the property to get. + Type property name string comparison. + A matching property if found. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Lookup and create an instance of the type described by the argument. + + The type to create. + Optional arguments to pass to an initializing constructor of the JsonConverter. + If null, the default constructor is used. + + + + A kebab case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Represents a trace writer that writes to memory. When the trace message limit is + reached then old trace messages will be removed as new messages are added. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + + The that will be used to filter the trace messages passed to the writer. + + + + + Initializes a new instance of the class. + + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Returns an enumeration of the most recent trace messages. + + An enumeration of the most recent trace messages. + + + + Returns a of the most recent trace messages. + + + A of the most recent trace messages. + + + + + A base class for resolving how property names and dictionary keys are serialized. + + + + + A flag indicating whether dictionary keys should be processed. + Defaults to false. + + + + + A flag indicating whether extension data names should be processed. + Defaults to false. + + + + + A flag indicating whether explicitly specified property names, + e.g. a property name customized with a , should be processed. + Defaults to false. + + + + + Gets the serialized name for a given property name. + + The initial property name. + A flag indicating whether the property has had a name explicitly specified. + The serialized property name. + + + + Gets the serialized name for a given extension data name. + + The initial extension data name. + The serialized extension data name. + + + + Gets the serialized key for a given dictionary key. + + The initial dictionary key. + The serialized dictionary key. + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Hash code calculation + + + + + + Object equality implementation + + + + + + + Compare to another NamingStrategy + + + + + + + Represents a method that constructs an object. + + The object type to create. + + + + When applied to a method, specifies that the method is called when an error occurs serializing an object. + + + + + Provides methods to get attributes from a , , or . + + + + + Initializes a new instance of the class. + + The instance to get attributes for. This parameter should be a , , or . + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Get and set values for a using reflection. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + A snake case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Specifies how strings are escaped when writing JSON text. + + + + + Only control characters (e.g. newline) are escaped. + + + + + All non-ASCII and control characters (e.g. newline) are escaped. + + + + + HTML (<, >, &, ', ") and control characters (e.g. newline) are escaped. + + + + + Specifies what messages to output for the class. + + + + + Output no tracing and debugging messages. + + + + + Output error-handling messages. + + + + + Output warnings and error-handling messages. + + + + + Output informational messages, warnings, and error-handling messages. + + + + + Output all debugging and tracing messages. + + + + + Indicates the method that will be used during deserialization for locating and loading assemblies. + + + + + In simple mode, the assembly used during deserialization need not match exactly the assembly used during serialization. Specifically, the version numbers need not match as the LoadWithPartialName method of the class is used to load the assembly. + + + + + In full mode, the assembly used during deserialization must match exactly the assembly used during serialization. The Load method of the class is used to load the assembly. + + + + + Specifies type name handling options for the . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Do not include the .NET type name when serializing types. + + + + + Include the .NET type name when serializing into a JSON object structure. + + + + + Include the .NET type name when serializing into a JSON array structure. + + + + + Always include the .NET type name when serializing. + + + + + Include the .NET type name when the type of the object being serialized is not the same as its declared type. + Note that this doesn't include the root serialized object by default. To include the root object's type name in JSON + you must specify a root type object with + or . + + + + + Determines whether the collection is null or empty. + + The collection. + + true if the collection is null or empty; otherwise, false. + + + + + Adds the elements of the specified collection to the specified generic . + + The list to add to. + The collection of elements to add. + + + + Converts the value to the specified type. If the value is unable to be converted, the + value is checked whether it assignable to the specified type. + + The value to convert. + The culture to use when converting. + The type to convert or cast the value to. + + The converted type. If conversion was unsuccessful, the initial value + is returned if assignable to the target type. + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic that returns a result + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic, but uses one of the arguments for + the result. + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic, but uses one of the arguments for + the result. + + + + + Returns a Restrictions object which includes our current restrictions merged + with a restriction limiting our type + + + + + Helper class for serializing immutable collections. + Note that this is used by all builds, even those that don't support immutable collections, in case the DLL is GACed + https://github.com/JamesNK/Newtonsoft.Json/issues/652 + + + + + List of primitive types which can be widened. + + + + + Widening masks for primitive types above. + Index of the value in this array defines a type we're widening, + while the bits in mask define types it can be widened to (including itself). + + For example, value at index 0 defines a bool type, and it only has bit 0 set, + i.e. bool values can be assigned only to bool. + + + + + Checks if value of primitive type can be + assigned to parameter of primitive type . + + Source primitive type. + Target primitive type. + true if source type can be widened to target type, false otherwise. + + + + Checks if a set of values with given can be used + to invoke a method with specified . + + Method parameters. + Argument types. + Try to pack extra arguments into the last parameter when it is marked up with . + true if method can be called with given arguments, false otherwise. + + + + Compares two sets of parameters to determine + which one suits better for given argument types. + + + + + Returns a best method overload for given argument . + + List of method candidates. + Argument types. + Best method overload, or null if none matched. + + + + Gets the type of the typed collection's items. + + The type. + The type of the typed collection's items. + + + + Gets the member's underlying type. + + The member. + The underlying type of the member. + + + + Determines whether the property is an indexed property. + + The property. + + true if the property is an indexed property; otherwise, false. + + + + + Gets the member's value on the object. + + The member. + The target object. + The member's value on the object. + + + + Sets the member's value on the target object. + + The member. + The target. + The value. + + + + Determines whether the specified MemberInfo can be read. + + The MemberInfo to determine whether can be read. + /// if set to true then allow the member to be gotten non-publicly. + + true if the specified MemberInfo can be read; otherwise, false. + + + + + Determines whether the specified MemberInfo can be set. + + The MemberInfo to determine whether can be set. + if set to true then allow the member to be set non-publicly. + if set to true then allow the member to be set if read-only. + + true if the specified MemberInfo can be set; otherwise, false. + + + + + Builds a string. Unlike this class lets you reuse its internal buffer. + + + + + Determines whether the string is all white space. Empty string will return false. + + The string to test whether it is all white space. + + true if the string is all white space; otherwise, false. + + + + + Specifies the state of the . + + + + + An exception has been thrown, which has left the in an invalid state. + You may call the method to put the in the Closed state. + Any other method calls result in an being thrown. + + + + + The method has been called. + + + + + An object is being written. + + + + + An array is being written. + + + + + A constructor is being written. + + + + + A property is being written. + + + + + A write method has not been called. + + + + + Indicates the method that will be used during deserialization for locating and loading assemblies. + + + + + In simple mode, the assembly used during deserialization need not match exactly the assembly used during serialization. Specifically, the version numbers need not match as the method is used to load the assembly. + + + + + In full mode, the assembly used during deserialization must match exactly the assembly used during serialization. The is used to load the assembly. + + + + Specifies that an output will not be null even if the corresponding type allows it. + + + Specifies that when a method returns , the parameter will not be null even if the corresponding type allows it. + + + Initializes the attribute with the specified return value condition. + + The return value condition. If the method returns this value, the associated parameter will not be null. + + + + Gets the return value condition. + + + Specifies that an output may be null even if the corresponding type disallows it. + + + Specifies that null is allowed as an input even if the corresponding type disallows it. + + + + Specifies that the method will not return if the associated Boolean parameter is passed the specified value. + + + + + Initializes a new instance of the class. + + + The condition parameter value. Code after the method will be considered unreachable by diagnostics if the argument to + the associated parameter matches this value. + + + + Gets the condition parameter value. + + + diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/netstandard1.3/Newtonsoft.Json.dll b/Packages/Newtonsoft.Json.13.0.1/lib/netstandard1.3/Newtonsoft.Json.dll new file mode 100644 index 0000000..e59bef4 Binary files /dev/null and b/Packages/Newtonsoft.Json.13.0.1/lib/netstandard1.3/Newtonsoft.Json.dll differ diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/netstandard1.3/Newtonsoft.Json.xml b/Packages/Newtonsoft.Json.13.0.1/lib/netstandard1.3/Newtonsoft.Json.xml new file mode 100644 index 0000000..0770714 --- /dev/null +++ b/Packages/Newtonsoft.Json.13.0.1/lib/netstandard1.3/Newtonsoft.Json.xml @@ -0,0 +1,11115 @@ + + + + Newtonsoft.Json + + + + + Represents a BSON Oid (object id). + + + + + Gets or sets the value of the Oid. + + The value of the Oid. + + + + Initializes a new instance of the class. + + The Oid value. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized BSON data. + + + + + Gets or sets a value indicating whether binary data reading should be compatible with incorrect Json.NET 3.5 written binary. + + + true if binary data reading will be compatible with incorrect Json.NET 3.5 written binary; otherwise, false. + + + + + Gets or sets a value indicating whether the root object will be read as a JSON array. + + + true if the root object will be read as a JSON array; otherwise, false. + + + + + Gets or sets the used when reading values from BSON. + + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating BSON data. + + + + + Gets or sets the used when writing values to BSON. + When set to no conversion will occur. + + The used when writing values to BSON. + + + + Initializes a new instance of the class. + + The to write to. + + + + Initializes a new instance of the class. + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying stream. + + + + + Writes the end. + + The token. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes the beginning of a JSON array. + + + + + Writes the beginning of a JSON object. + + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value that represents a BSON object id. + + The Object ID value to write. + + + + Writes a BSON regex. + + The regex pattern. + The regex options. + + + + Specifies how constructors are used when initializing objects during deserialization by the . + + + + + First attempt to use the public default constructor, then fall back to a single parameterized constructor, then to the non-public default constructor. + + + + + Json.NET will use a non-public default constructor before falling back to a parameterized constructor. + + + + + Converts a binary value to and from a base 64 string value. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Creates a custom object. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Creates an object which will then be populated by the serializer. + + Type of the object. + The created object. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can write JSON. + + + true if this can write JSON; otherwise, false. + + + + + Provides a base class for converting a to and from JSON. + + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a F# discriminated union type to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can write JSON. + + + true if this can write JSON; otherwise, false. + + + + + Converts a to and from the ISO 8601 date format (e.g. "2008-04-12T12:53Z"). + + + + + Gets or sets the date time styles used when converting a date to and from JSON. + + The date time styles used when converting a date to and from JSON. + + + + Gets or sets the date time format used when converting a date to and from JSON. + + The date time format used when converting a date to and from JSON. + + + + Gets or sets the culture used when converting a date to and from JSON. + + The culture used when converting a date to and from JSON. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Converts a to and from a JavaScript Date constructor (e.g. new Date(52231943)). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an to and from its name string value. + + + + + Gets or sets a value indicating whether the written enum text should be camel case. + The default value is false. + + true if the written enum text will be camel case; otherwise, false. + + + + Gets or sets the naming strategy used to resolve how enum text is written. + + The naming strategy used to resolve how enum text is written. + + + + Gets or sets a value indicating whether integer values are allowed when serializing and deserializing. + The default value is true. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class. + + true if the written enum text will be camel case; otherwise, false. + + + + Initializes a new instance of the class. + + The naming strategy used to resolve how enum text is written. + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from Unix epoch time + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from a string (e.g. "1.2.3.4"). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts XML to and from JSON. + + + + + Gets or sets the name of the root element to insert when deserializing to XML if the JSON structure has produced multiple root elements. + + The name of the deserialized root element. + + + + Gets or sets a value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + true if the array attribute is written to the XML; otherwise, false. + + + + Gets or sets a value indicating whether to write the root JSON object. + + true if the JSON root object is omitted; otherwise, false. + + + + Gets or sets a value indicating whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + true if special characters are encoded; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The calling serializer. + The value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Checks if the is a namespace attribute. + + Attribute name to test. + The attribute name prefix if it has one, otherwise an empty string. + true if attribute name is for a namespace attribute, otherwise false. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Specifies how dates are formatted when writing JSON text. + + + + + Dates are written in the ISO 8601 format, e.g. "2012-03-21T05:40Z". + + + + + Dates are written in the Microsoft JSON format, e.g. "\/Date(1198908717056)\/". + + + + + Specifies how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON text. + + + + + Date formatted strings are not parsed to a date type and are read as strings. + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Specifies how to treat the time value when converting between string and . + + + + + Treat as local time. If the object represents a Coordinated Universal Time (UTC), it is converted to the local time. + + + + + Treat as a UTC. If the object represents a local time, it is converted to a UTC. + + + + + Treat as a local time if a is being converted to a string. + If a string is being converted to , convert to a local time if a time zone is specified. + + + + + Time zone information should be preserved when converting. + + + + + The default JSON name table implementation. + + + + + Initializes a new instance of the class. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Adds the specified string into name table. + + The string to add. + This method is not thread-safe. + The resolved string. + + + + Specifies default value handling options for the . + + + + + + + + + Include members where the member value is the same as the member's default value when serializing objects. + Included members are written to JSON. Has no effect when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + so that it is not written to JSON. + This option will ignore all default values (e.g. null for objects and nullable types; 0 for integers, + decimals and floating point numbers; and false for booleans). The default value ignored can be changed by + placing the on the property. + + + + + Members with a default value but no JSON will be set to their default value when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + and set members to their default value when deserializing. + + + + + Specifies float format handling options when writing special floating point numbers, e.g. , + and with . + + + + + Write special floating point values as strings in JSON, e.g. "NaN", "Infinity", "-Infinity". + + + + + Write special floating point values as symbols in JSON, e.g. NaN, Infinity, -Infinity. + Note that this will produce non-valid JSON. + + + + + Write special floating point values as the property's default value in JSON, e.g. 0.0 for a property, null for a of property. + + + + + Specifies how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Floating point numbers are parsed to . + + + + + Floating point numbers are parsed to . + + + + + Specifies formatting options for the . + + + + + No special formatting is applied. This is the default. + + + + + Causes child objects to be indented according to the and settings. + + + + + Provides an interface for using pooled arrays. + + The array type content. + + + + Rent an array from the pool. This array must be returned when it is no longer needed. + + The minimum required length of the array. The returned array may be longer. + The rented array from the pool. This array must be returned when it is no longer needed. + + + + Return an array to the pool. + + The array that is being returned. + + + + Provides an interface to enable a class to return line and position information. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + The current line number or 0 if no line information is available (for example, when returns false). + + + + Gets the current line position. + + The current line position or 0 if no line information is available (for example, when returns false). + + + + Instructs the how to serialize the collection. + + + + + Gets or sets a value indicating whether null items are allowed in the collection. + + true if null items are allowed in the collection; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with a flag indicating whether the array can contain null items. + + A flag indicating whether the array can contain null items. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to use the specified constructor when deserializing that object. + + + + + Instructs the how to serialize the object. + + + + + Gets or sets the id. + + The id. + + + + Gets or sets the title. + + The title. + + + + Gets or sets the description. + + The description. + + + + Gets or sets the collection's items converter. + + The collection's items converter. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets a value that indicates whether to preserve object references. + + + true to keep object reference; otherwise, false. The default is false. + + + + + Gets or sets a value that indicates whether to preserve collection's items references. + + + true to keep collection's items object references; otherwise, false. The default is false. + + + + + Gets or sets the reference loop handling used when serializing the collection's items. + + The reference loop handling. + + + + Gets or sets the type name handling used when serializing the collection's items. + + The type name handling. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Provides methods for converting between .NET types and JSON types. + + + + + + + + Gets or sets a function that creates default . + Default settings are automatically used by serialization methods on , + and and on . + To serialize without using any default settings create a with + . + + + + + Represents JavaScript's boolean value true as a string. This field is read-only. + + + + + Represents JavaScript's boolean value false as a string. This field is read-only. + + + + + Represents JavaScript's null as a string. This field is read-only. + + + + + Represents JavaScript's undefined as a string. This field is read-only. + + + + + Represents JavaScript's positive infinity as a string. This field is read-only. + + + + + Represents JavaScript's negative infinity as a string. This field is read-only. + + + + + Represents JavaScript's NaN as a string. This field is read-only. + + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + The time zone handling when the date is converted to a string. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + The string escape handling. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Serializes the specified object to a JSON string. + + The object to serialize. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting. + + The object to serialize. + Indicates how the output should be formatted. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a collection of . + + The object to serialize. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting and a collection of . + + The object to serialize. + Indicates how the output should be formatted. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Deserializes the JSON to a .NET object. + + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to a .NET object using . + + The JSON to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The JSON to deserialize. + The of object being deserialized. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The type of the object to deserialize to. + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the given anonymous type. + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the given anonymous type using . + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The type of the object to deserialize to. + The JSON to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The type of the object to deserialize to. + The object to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The JSON to deserialize. + The type of the object to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The JSON to deserialize. + The type of the object to deserialize to. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Populates the object with values from the JSON string. + + The JSON to populate values from. + The target object to populate values onto. + + + + Populates the object with values from the JSON string using . + + The JSON to populate values from. + The target object to populate values onto. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + + + + Serializes the to a JSON string. + + The node to serialize. + A JSON string of the . + + + + Serializes the to a JSON string using formatting. + + The node to serialize. + Indicates how the output should be formatted. + A JSON string of the . + + + + Serializes the to a JSON string using formatting and omits the root object if is true. + + The node to serialize. + Indicates how the output should be formatted. + Omits writing the root object. + A JSON string of the . + + + + Deserializes the from a JSON string. + + The JSON string. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by . + + The JSON string. + The name of the root element to append when deserializing. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by + and writes a Json.NET array attribute for collections. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by , + writes a Json.NET array attribute for collections, and encodes special characters. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + + A value to indicate whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + The deserialized . + + + + Serializes the to a JSON string. + + The node to convert to JSON. + A JSON string of the . + + + + Serializes the to a JSON string using formatting. + + The node to convert to JSON. + Indicates how the output should be formatted. + A JSON string of the . + + + + Serializes the to a JSON string using formatting and omits the root object if is true. + + The node to serialize. + Indicates how the output should be formatted. + Omits writing the root object. + A JSON string of the . + + + + Deserializes the from a JSON string. + + The JSON string. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by . + + The JSON string. + The name of the root element to append when deserializing. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by + and writes a Json.NET array attribute for collections. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by , + writes a Json.NET array attribute for collections, and encodes special characters. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + + A value to indicate whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + The deserialized . + + + + Converts an object to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can read JSON. + + true if this can read JSON; otherwise, false. + + + + Gets a value indicating whether this can write JSON. + + true if this can write JSON; otherwise, false. + + + + Converts an object to and from JSON. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. If there is no existing value then null will be used. + The existing value has a value. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Instructs the to use the specified when serializing the member or class. + + + + + Gets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + + + + + Initializes a new instance of the class. + + Type of the . + + + + Initializes a new instance of the class. + + Type of the . + Parameter list to use when constructing the . Can be null. + + + + Represents a collection of . + + + + + Instructs the how to serialize the collection. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Instructs the to deserialize properties with no matching class member into the specified collection + and write values during serialization. + + + + + Gets or sets a value that indicates whether to write extension data when serializing the object. + + + true to write extension data when serializing the object; otherwise, false. The default is true. + + + + + Gets or sets a value that indicates whether to read extension data when deserializing the object. + + + true to read extension data when deserializing the object; otherwise, false. The default is true. + + + + + Initializes a new instance of the class. + + + + + Instructs the not to serialize the public field or public read/write property value. + + + + + Base class for a table of atomized string objects. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Instructs the how to serialize the object. + + + + + Gets or sets the member serialization. + + The member serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified member serialization. + + The member serialization. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to always serialize the member with the specified name. + + + + + Gets or sets the type used when serializing the property's collection items. + + The collection's items type. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the null value handling used when serializing this property. + + The null value handling. + + + + Gets or sets the default value handling used when serializing this property. + + The default value handling. + + + + Gets or sets the reference loop handling used when serializing this property. + + The reference loop handling. + + + + Gets or sets the object creation handling used when deserializing this property. + + The object creation handling. + + + + Gets or sets the type name handling used when serializing this property. + + The type name handling. + + + + Gets or sets whether this property's value is serialized as a reference. + + Whether this property's value is serialized as a reference. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets a value indicating whether this property is required. + + + A value indicating whether this property is required. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified name. + + Name of the property. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Asynchronously reads the next JSON token from the source. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns true if the next token was read successfully; false if there are no more tokens to read. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously skips the children of the current token. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a []. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the []. This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Specifies the state of the reader. + + + + + A read method has not been called. + + + + + The end of the file has been reached successfully. + + + + + Reader is at a property. + + + + + Reader is at the start of an object. + + + + + Reader is in an object. + + + + + Reader is at the start of an array. + + + + + Reader is in an array. + + + + + The method has been called. + + + + + Reader has just read a value. + + + + + Reader is at the start of a constructor. + + + + + Reader is in a constructor. + + + + + An error occurred that prevents the read operation from continuing. + + + + + The end of the file has been reached successfully. + + + + + Gets the current reader state. + + The current reader state. + + + + Gets or sets a value indicating whether the source should be closed when this reader is closed. + + + true to close the source when this reader is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether multiple pieces of JSON content can + be read from a continuous stream without erroring. + + + true to support reading multiple pieces of JSON content; otherwise false. + The default is false. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + Gets or sets how time zones are handled when reading JSON. + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Gets or sets how custom date formatted strings are parsed when reading JSON. + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets the type of the current JSON token. + + + + + Gets the text value of the current JSON token. + + + + + Gets the .NET type for the current JSON token. + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets or sets the culture used when reading JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Reads the next JSON token from the source. + + true if the next token was read successfully; false if there are no more tokens to read. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Skips the children of the current token. + + + + + Sets the current token. + + The new token. + + + + Sets the current token and value. + + The new token. + The value. + + + + Sets the current token and value. + + The new token. + The value. + A flag indicating whether the position index inside an array should be updated. + + + + Sets the state based on current token type. + + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Changes the reader's state to . + If is set to true, the source is also closed. + + + + + The exception thrown when an error occurs while reading JSON text. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Instructs the to always serialize the member, and to require that the member has a value. + + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Serializes and deserializes objects into and from the JSON format. + The enables you to control how objects are encoded into JSON. + + + + + Occurs when the errors during serialization and deserialization. + + + + + Gets or sets the used by the serializer when resolving references. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + + + + Gets or sets how reference loops (e.g. a class referencing itself) is handled. + The default value is . + + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets a collection that will be used during serialization. + + Collection that will be used during serialization. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets a value indicating whether there will be a check for additional JSON content after deserializing an object. + The default value is false. + + + true if there will be a check for additional JSON content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Creates a new instance. + The will not use default settings + from . + + + A new instance. + The will not use default settings + from . + + + + + Creates a new instance using the specified . + The will not use default settings + from . + + The settings to be applied to the . + + A new instance using the specified . + The will not use default settings + from . + + + + + Creates a new instance. + The will use default settings + from . + + + A new instance. + The will use default settings + from . + + + + + Creates a new instance using the specified . + The will use default settings + from as well as the specified . + + The settings to be applied to the . + + A new instance using the specified . + The will use default settings + from as well as the specified . + + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Deserializes the JSON structure contained by the specified . + + The that contains the JSON structure to deserialize. + The being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The type of the object to deserialize. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is Auto to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Specifies the settings on a object. + + + + + Gets or sets how reference loops (e.g. a class referencing itself) are handled. + The default value is . + + Reference loop handling. + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + Missing member handling. + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + Null value handling. + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + The default value handling. + + + + Gets or sets a collection that will be used during serialization. + + The converters. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + The preserve references handling. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + The type name handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + The contract resolver. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets the used by the serializer when resolving references. + + The reference resolver. + + + + Gets or sets a function that creates the used by the serializer when resolving references. + + A function that creates the used by the serializer when resolving references. + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the error handler called during serialization and deserialization. + + The error handler called during serialization and deserialization. + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets a value indicating whether there will be a check for additional content after deserializing an object. + The default value is false. + + + true if there will be a check for additional content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Represents a reader that provides fast, non-cached, forward-only access to JSON text data. + + + + + Asynchronously reads the next JSON token from the source. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns true if the next token was read successfully; false if there are no more tokens to read. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a []. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the []. This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Initializes a new instance of the class with the specified . + + The containing the JSON data to read. + + + + Gets or sets the reader's property name table. + + + + + Gets or sets the reader's character buffer pool. + + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + + The current line number or 0 if no line information is available (for example, returns false). + + + + + Gets the current line position. + + + The current line position or 0 if no line information is available (for example, returns false). + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Asynchronously flushes whatever is in the buffer to the destination and also flushes the destination. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the JSON value delimiter. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the specified end token. + + The end token to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously closes this writer. + If is set to true, the destination is also closed. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of the current JSON object or array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes indent characters. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes an indent space. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes raw JSON without changing the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a null value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the beginning of a JSON array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the beginning of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the start of a constructor with the given name. + + The name of the constructor. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes an undefined value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the given white space. + + The string of white space characters. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a [] value. + + The [] value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of an array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of a constructor. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Gets or sets the writer's character array pool. + + + + + Gets or sets how many s to write for each level in the hierarchy when is set to . + + + + + Gets or sets which character to use to quote attribute values. + + + + + Gets or sets which character to use for indenting when is set to . + + + + + Gets or sets a value indicating whether object names will be surrounded with quotes. + + + + + Initializes a new instance of the class using the specified . + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying . + + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the specified end token. + + The end token to write. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Specifies the type of JSON token. + + + + + This is returned by the if a read method has not been called. + + + + + An object start token. + + + + + An array start token. + + + + + A constructor start token. + + + + + An object property name. + + + + + A comment. + + + + + Raw JSON. + + + + + An integer. + + + + + A float. + + + + + A string. + + + + + A boolean. + + + + + A null token. + + + + + An undefined token. + + + + + An object end token. + + + + + An array end token. + + + + + A constructor end token. + + + + + A Date. + + + + + Byte data. + + + + + + Represents a reader that provides validation. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Sets an event handler for receiving schema validation errors. + + + + + Gets the text value of the current JSON token. + + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + + Gets the type of the current JSON token. + + + + + + Gets the .NET type for the current JSON token. + + + + + + Initializes a new instance of the class that + validates the content returned from the given . + + The to read from while validating. + + + + Gets or sets the schema. + + The schema. + + + + Gets the used to construct this . + + The specified in the constructor. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a []. + + + A [] or null if the next JSON token is null. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Asynchronously closes this writer. + If is set to true, the destination is also closed. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously flushes whatever is in the buffer to the destination and also flushes the destination. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the specified end token. + + The end token to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes indent characters. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the JSON value delimiter. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes an indent space. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes raw JSON without changing the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of the current JSON object or array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of an array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of a constructor. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a null value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the beginning of a JSON array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the start of a constructor with the given name. + + The name of the constructor. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the beginning of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the current token. + + The to read the token from. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the current token. + + The to read the token from. + A flag indicating whether the current token's children should be written. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the token and its value. + + The to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the token and its value. + + The to write. + + The value to write. + A value is only required for tokens that have an associated value, e.g. the property name for . + null can be passed to the method for tokens that don't have a value, e.g. . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a [] value. + + The [] value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes an undefined value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the given white space. + + The string of white space characters. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously ets the state of the . + + The being written. + The value being written. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Gets or sets a value indicating whether the destination should be closed when this writer is closed. + + + true to close the destination when this writer is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether the JSON should be auto-completed when this writer is closed. + + + true to auto-complete the JSON when this writer is closed; otherwise false. The default is true. + + + + + Gets the top. + + The top. + + + + Gets the state of the writer. + + + + + Gets the path of the writer. + + + + + Gets or sets a value indicating how JSON text output should be formatted. + + + + + Gets or sets how dates are written to JSON text. + + + + + Gets or sets how time zones are handled when writing JSON text. + + + + + Gets or sets how strings are escaped when writing JSON text. + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written to JSON text. + + + + + Gets or sets how and values are formatted when writing JSON text. + + + + + Gets or sets the culture used when writing JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the destination and also flushes the destination. + + + + + Closes this writer. + If is set to true, the destination is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the end of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the end of an array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end constructor. + + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes the end of the current JSON object or array. + + + + + Writes the current token and its children. + + The to read the token from. + + + + Writes the current token. + + The to read the token from. + A flag indicating whether the current token's children should be written. + + + + Writes the token and its value. + + The to write. + + The value to write. + A value is only required for tokens that have an associated value, e.g. the property name for . + null can be passed to the method for tokens that don't have a value, e.g. . + + + + + Writes the token. + + The to write. + + + + Writes the specified end token. + + The end token to write. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON without changing the writer's state. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Sets the state of the . + + The being written. + The value being written. + + + + The exception thrown when an error occurs while writing JSON text. + + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class + with a specified error message, JSON path and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Specifies how JSON comments are handled when loading JSON. + + + + + Ignore comments. + + + + + Load comments as a with type . + + + + + Specifies how duplicate property names are handled when loading JSON. + + + + + Replace the existing value when there is a duplicate property. The value of the last property in the JSON object will be used. + + + + + Ignore the new value when there is a duplicate property. The value of the first property in the JSON object will be used. + + + + + Throw a when a duplicate property is encountered. + + + + + Contains the LINQ to JSON extension methods. + + + + + Returns a collection of tokens that contains the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the descendants of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, and the descendants of every token in the source collection. + + + + Returns a collection of child properties of every object in the source collection. + + An of that contains the source collection. + An of that contains the properties of every object in the source collection. + + + + Returns a collection of child values of every object in the source collection with the given key. + + An of that contains the source collection. + The token key. + An of that contains the values of every token in the source collection with the given key. + + + + Returns a collection of child values of every object in the source collection. + + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child values of every object in the source collection with the given key. + + The type to convert the values to. + An of that contains the source collection. + The token key. + An that contains the converted values of every token in the source collection with the given key. + + + + Returns a collection of converted child values of every object in the source collection. + + The type to convert the values to. + An of that contains the source collection. + An that contains the converted values of every token in the source collection. + + + + Converts the value. + + The type to convert the value to. + A cast as a of . + A converted value. + + + + Converts the value. + + The source collection type. + The type to convert the value to. + A cast as a of . + A converted value. + + + + Returns a collection of child tokens of every array in the source collection. + + The source collection type. + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child tokens of every array in the source collection. + + An of that contains the source collection. + The type to convert the values to. + The source collection type. + An that contains the converted values of every token in the source collection. + + + + Returns the input typed as . + + An of that contains the source collection. + The input typed as . + + + + Returns the input typed as . + + The source collection type. + An of that contains the source collection. + The input typed as . + + + + Represents a collection of objects. + + The type of token. + + + + Gets the of with the specified key. + + + + + + Represents a JSON array. + + + + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous load. The property contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous load. The property contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Loads an from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads an from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the at the specified index. + + + + + + Determines the index of a specific item in the . + + The object to locate in the . + + The index of if found in the list; otherwise, -1. + + + + + Inserts an item to the at the specified index. + + The zero-based index at which should be inserted. + The object to insert into the . + + is not a valid index in the . + + + + + Removes the item at the specified index. + + The zero-based index of the item to remove. + + is not a valid index in the . + + + + + Returns an enumerator that iterates through the collection. + + + A of that can be used to iterate through the collection. + + + + + Adds an item to the . + + The object to add to the . + + + + Removes all items from the . + + + + + Determines whether the contains a specific value. + + The object to locate in the . + + true if is found in the ; otherwise, false. + + + + + Copies the elements of the to an array, starting at a particular array index. + + The array. + Index of the array. + + + + Gets a value indicating whether the is read-only. + + true if the is read-only; otherwise, false. + + + + Removes the first occurrence of a specific object from the . + + The object to remove from the . + + true if was successfully removed from the ; otherwise, false. This method also returns false if is not found in the original . + + + + + Represents a JSON constructor. + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets or sets the name of this constructor. + + The constructor name. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name. + + The constructor name. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a token that can contain other tokens. + + + + + Occurs when the items list of the collection has changed, or the collection is reset. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Raises the event. + + The instance containing the event data. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Get the first child token of this token. + + + A containing the first child token of the . + + + + + Get the last child token of this token. + + + A containing the last child token of the . + + + + + Returns a collection of the child tokens of this token, in document order. + + + An of containing the child tokens of this , in document order. + + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + + A containing the child values of this , in document order. + + + + + Returns a collection of the descendant tokens for this token in document order. + + An of containing the descendant tokens of the . + + + + Returns a collection of the tokens that contain this token, and all descendant tokens of this token, in document order. + + An of containing this token, and all the descendant tokens of the . + + + + Adds the specified content as children of this . + + The content to be added. + + + + Adds the specified content as the first children of this . + + The content to be added. + + + + Creates a that can be used to add tokens to the . + + A that is ready to have content written to it. + + + + Replaces the child nodes of this token with the specified content. + + The content. + + + + Removes the child nodes from this token. + + + + + Merge the specified content into this . + + The content to be merged. + + + + Merge the specified content into this using . + + The content to be merged. + The used to merge the content. + + + + Gets the count of child JSON tokens. + + The count of child JSON tokens. + + + + Represents a collection of objects. + + The type of token. + + + + An empty collection of objects. + + + + + Initializes a new instance of the struct. + + The enumerable. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Gets the of with the specified key. + + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Returns a hash code for this instance. + + + A hash code for this instance, suitable for use in hashing algorithms and data structures like a hash table. + + + + + Represents a JSON object. + + + + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Occurs when a property value changes. + + + + + Occurs when a property value is changing. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Gets the node type for this . + + The type. + + + + Gets an of of this object's properties. + + An of of this object's properties. + + + + Gets a with the specified name. + + The property name. + A with the specified name or null. + + + + Gets the with the specified name. + The exact name will be searched for first and if no matching property is found then + the will be used to match a property. + + The property name. + One of the enumeration values that specifies how the strings will be compared. + A matched with the specified name or null. + + + + Gets a of of this object's property values. + + A of of this object's property values. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the with the specified property name. + + + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified property name. + + Name of the property. + The with the specified property name. + + + + Gets the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + One of the enumeration values that specifies how the strings will be compared. + The with the specified property name. + + + + Tries to get the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + The value. + One of the enumeration values that specifies how the strings will be compared. + true if a value was successfully retrieved; otherwise, false. + + + + Adds the specified property name. + + Name of the property. + The value. + + + + Determines whether the JSON object has the specified property name. + + Name of the property. + true if the JSON object has the specified property name; otherwise, false. + + + + Removes the property with the specified name. + + Name of the property. + true if item was successfully removed; otherwise, false. + + + + Tries to get the with the specified property name. + + Name of the property. + The value. + true if a value was successfully retrieved; otherwise, false. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Raises the event with the provided arguments. + + Name of the property. + + + + Raises the event with the provided arguments. + + Name of the property. + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Represents a JSON property. + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous creation. The + property returns a that contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous creation. The + property returns a that contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the property name. + + The property name. + + + + Gets or sets the property value. + + The property value. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a raw JSON string. + + + + + Asynchronously creates an instance of with the content of the reader's current token. + + The reader. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous creation. The + property returns an instance of with the content of the reader's current token. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class. + + The raw json. + + + + Creates an instance of with the content of the reader's current token. + + The reader. + An instance of with the content of the reader's current token. + + + + Specifies the settings used when loading JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets how JSON comments are handled when loading JSON. + The default value is . + + The JSON comment handling. + + + + Gets or sets how JSON line info is handled when loading JSON. + The default value is . + + The JSON line info handling. + + + + Gets or sets how duplicate property names in JSON objects are handled when loading JSON. + The default value is . + + The JSON duplicate property name handling. + + + + Specifies the settings used when merging JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets the method used when merging JSON arrays. + + The method used when merging JSON arrays. + + + + Gets or sets how null value properties are merged. + + How null value properties are merged. + + + + Gets or sets the comparison used to match property names while merging. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + The comparison used to match property names while merging. + + + + Specifies the settings used when selecting JSON. + + + + + Gets or sets a timeout that will be used when executing regular expressions. + + The timeout that will be used when executing regular expressions. + + + + Gets or sets a flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + A flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + + + Represents an abstract JSON token. + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Writes this token to a asynchronously. + + A into which this method will write. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously creates a from a . + + An positioned at the token to read into this . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains + the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Asynchronously creates a from a . + + An positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains + the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Asynchronously creates a from a . + + A positioned at the token to read into this . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Asynchronously creates a from a . + + A positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Gets a comparer that can compare two tokens for value equality. + + A that can compare two nodes for value equality. + + + + Gets or sets the parent. + + The parent. + + + + Gets the root of this . + + The root of this . + + + + Gets the node type for this . + + The type. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Compares the values of two tokens, including the values of all descendant tokens. + + The first to compare. + The second to compare. + true if the tokens are equal; otherwise false. + + + + Gets the next sibling token of this node. + + The that contains the next sibling token. + + + + Gets the previous sibling token of this node. + + The that contains the previous sibling token. + + + + Gets the path of the JSON token. + + + + + Adds the specified content immediately after this token. + + A content object that contains simple content or a collection of content objects to be added after this token. + + + + Adds the specified content immediately before this token. + + A content object that contains simple content or a collection of content objects to be added before this token. + + + + Returns a collection of the ancestor tokens of this token. + + A collection of the ancestor tokens of this token. + + + + Returns a collection of tokens that contain this token, and the ancestors of this token. + + A collection of tokens that contain this token, and the ancestors of this token. + + + + Returns a collection of the sibling tokens after this token, in document order. + + A collection of the sibling tokens after this tokens, in document order. + + + + Returns a collection of the sibling tokens before this token, in document order. + + A collection of the sibling tokens before this token, in document order. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets the with the specified key converted to the specified type. + + The type to convert the token to. + The token key. + The converted token value. + + + + Get the first child token of this token. + + A containing the first child token of the . + + + + Get the last child token of this token. + + A containing the last child token of the . + + + + Returns a collection of the child tokens of this token, in document order. + + An of containing the child tokens of this , in document order. + + + + Returns a collection of the child tokens of this token, in document order, filtered by the specified type. + + The type to filter the child tokens on. + A containing the child tokens of this , in document order. + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + A containing the child values of this , in document order. + + + + Removes this token from its parent. + + + + + Replaces this token with the specified token. + + The value. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Returns the indented JSON for this token. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + The indented JSON for this token. + + + + + Returns the JSON for this token using the given formatting and converters. + + Indicates how the output should be formatted. + A collection of s which will be used when writing the token. + The JSON for this token using the given formatting and converters. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to []. + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from [] to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Creates a for this token. + + A that can be used to read this token and its descendants. + + + + Creates a from an object. + + The object that will be used to create . + A with the value of the specified object. + + + + Creates a from an object using the specified . + + The object that will be used to create . + The that will be used when reading the object. + A with the value of the specified object. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + An positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + Creates a from a . + + A positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A , or null. + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + A . + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + The used to select tokens. + A . + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + The used to select tokens. + An of that contains the selected elements. + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Creates a new instance of the . All child tokens are recursively cloned. + + A new instance of the . + + + + Adds an object to the annotation list of this . + + The annotation to add. + + + + Get the first annotation object of the specified type from this . + + The type of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets the first annotation object of the specified type from this . + + The of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets a collection of annotations of the specified type for this . + + The type of the annotations to retrieve. + An that contains the annotations for this . + + + + Gets a collection of annotations of the specified type for this . + + The of the annotations to retrieve. + An of that contains the annotations that match the specified type for this . + + + + Removes the annotations of the specified type from this . + + The type of annotations to remove. + + + + Removes the annotations of the specified type from this . + + The of annotations to remove. + + + + Compares tokens to determine whether they are equal. + + + + + Determines whether the specified objects are equal. + + The first object of type to compare. + The second object of type to compare. + + true if the specified objects are equal; otherwise, false. + + + + + Returns a hash code for the specified object. + + The for which a hash code is to be returned. + A hash code for the specified object. + The type of is a reference type and is null. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Gets the at the reader's current position. + + + + + Initializes a new instance of the class. + + The token to read from. + + + + Initializes a new instance of the class. + + The token to read from. + The initial path of the token. It is prepended to the returned . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Gets the path of the current JSON token. + + + + + Specifies the type of token. + + + + + No token type has been set. + + + + + A JSON object. + + + + + A JSON array. + + + + + A JSON constructor. + + + + + A JSON object property. + + + + + A comment. + + + + + An integer value. + + + + + A float value. + + + + + A string value. + + + + + A boolean value. + + + + + A null value. + + + + + An undefined value. + + + + + A date value. + + + + + A raw JSON value. + + + + + A collection of bytes value. + + + + + A Guid value. + + + + + A Uri value. + + + + + A TimeSpan value. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets the at the writer's current position. + + + + + Gets the token being written. + + The token being written. + + + + Initializes a new instance of the class writing to the given . + + The container being written to. + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the underlying . + + + + + Closes this writer. + If is set to true, the JSON is auto-completed. + + + Setting to true has no additional effect, since the underlying is a type that cannot be closed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end. + + The token. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes a value. + An error will be raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Represents a value in JSON (string, integer, date, etc). + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Creates a comment with the given value. + + The value. + A comment with the given value. + + + + Creates a string with the given value. + + The value. + A string with the given value. + + + + Creates a null value. + + A null value. + + + + Creates a undefined value. + + A undefined value. + + + + Gets the node type for this . + + The type. + + + + Gets or sets the underlying token value. + + The underlying token value. + + + + Writes this token to a . + + A into which this method will write. + A collection of s which will be used when writing the token. + + + + Indicates whether the current object is equal to another object of the same type. + + + true if the current object is equal to the parameter; otherwise, false. + + An object to compare with this object. + + + + Determines whether the specified is equal to the current . + + The to compare with the current . + + true if the specified is equal to the current ; otherwise, false. + + + + + Serves as a hash function for a particular type. + + + A hash code for the current . + + + + + Returns a that represents this instance. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format provider. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + The format provider. + + A that represents this instance. + + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Compares the current instance with another object of the same type and returns an integer that indicates whether the current instance precedes, follows, or occurs in the same position in the sort order as the other object. + + An object to compare with this instance. + + A 32-bit signed integer that indicates the relative order of the objects being compared. The return value has these meanings: + Value + Meaning + Less than zero + This instance is less than . + Zero + This instance is equal to . + Greater than zero + This instance is greater than . + + + is not of the same type as this instance. + + + + + Specifies how line information is handled when loading JSON. + + + + + Ignore line information. + + + + + Load line information. + + + + + Specifies how JSON arrays are merged together. + + + + Concatenate arrays. + + + Union arrays, skipping items that already exist. + + + Replace all array items. + + + Merge array items together, matched by index. + + + + Specifies how null value properties are merged. + + + + + The content's null value properties will be ignored during merging. + + + + + The content's null value properties will be merged. + + + + + Specifies the member serialization options for the . + + + + + All public members are serialized by default. Members can be excluded using or . + This is the default member serialization mode. + + + + + Only members marked with or are serialized. + This member serialization mode can also be set by marking the class with . + + + + + All public and private fields are serialized. Members can be excluded using or . + This member serialization mode can also be set by marking the class with + and setting IgnoreSerializableAttribute on to false. + + + + + Specifies metadata property handling options for the . + + + + + Read metadata properties located at the start of a JSON object. + + + + + Read metadata properties located anywhere in a JSON object. Note that this setting will impact performance. + + + + + Do not try to read metadata properties. + + + + + Specifies missing member handling options for the . + + + + + Ignore a missing member and do not attempt to deserialize it. + + + + + Throw a when a missing member is encountered during deserialization. + + + + + Specifies null value handling options for the . + + + + + + + + + Include null values when serializing and deserializing objects. + + + + + Ignore null values when serializing and deserializing objects. + + + + + Specifies how object creation is handled by the . + + + + + Reuse existing objects, create new objects when needed. + + + + + Only reuse existing objects. + + + + + Always create new objects. + + + + + Specifies reference handling options for the . + Note that references cannot be preserved when a value is set via a non-default constructor such as types that implement . + + + + + + + + Do not preserve references when serializing types. + + + + + Preserve references when serializing into a JSON object structure. + + + + + Preserve references when serializing into a JSON array structure. + + + + + Preserve references when serializing. + + + + + Specifies reference loop handling options for the . + + + + + Throw a when a loop is encountered. + + + + + Ignore loop references and do not serialize. + + + + + Serialize loop references. + + + + + Indicating whether a property is required. + + + + + The property is not required. The default state. + + + + + The property must be defined in JSON but can be a null value. + + + + + The property must be defined in JSON and cannot be a null value. + + + + + The property is not required but it cannot be a null value. + + + + + + Contains the JSON schema extension methods. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + true if the specified is valid; otherwise, false. + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + When this method returns, contains any error messages generated while validating. + + true if the specified is valid; otherwise, false. + + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + The validation event handler. + + + + + An in-memory representation of a JSON Schema. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the id. + + + + + Gets or sets the title. + + + + + Gets or sets whether the object is required. + + + + + Gets or sets whether the object is read-only. + + + + + Gets or sets whether the object is visible to users. + + + + + Gets or sets whether the object is transient. + + + + + Gets or sets the description of the object. + + + + + Gets or sets the types of values allowed by the object. + + The type. + + + + Gets or sets the pattern. + + The pattern. + + + + Gets or sets the minimum length. + + The minimum length. + + + + Gets or sets the maximum length. + + The maximum length. + + + + Gets or sets a number that the value should be divisible by. + + A number that the value should be divisible by. + + + + Gets or sets the minimum. + + The minimum. + + + + Gets or sets the maximum. + + The maximum. + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the minimum attribute (). + + A flag indicating whether the value can not equal the number defined by the minimum attribute (). + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the maximum attribute (). + + A flag indicating whether the value can not equal the number defined by the maximum attribute (). + + + + Gets or sets the minimum number of items. + + The minimum number of items. + + + + Gets or sets the maximum number of items. + + The maximum number of items. + + + + Gets or sets the of items. + + The of items. + + + + Gets or sets a value indicating whether items in an array are validated using the instance at their array position from . + + + true if items are validated using their array position; otherwise, false. + + + + + Gets or sets the of additional items. + + The of additional items. + + + + Gets or sets a value indicating whether additional items are allowed. + + + true if additional items are allowed; otherwise, false. + + + + + Gets or sets whether the array items must be unique. + + + + + Gets or sets the of properties. + + The of properties. + + + + Gets or sets the of additional properties. + + The of additional properties. + + + + Gets or sets the pattern properties. + + The pattern properties. + + + + Gets or sets a value indicating whether additional properties are allowed. + + + true if additional properties are allowed; otherwise, false. + + + + + Gets or sets the required property if this property is present. + + The required property if this property is present. + + + + Gets or sets the a collection of valid enum values allowed. + + A collection of valid enum values allowed. + + + + Gets or sets disallowed types. + + The disallowed types. + + + + Gets or sets the default value. + + The default value. + + + + Gets or sets the collection of that this schema extends. + + The collection of that this schema extends. + + + + Gets or sets the format. + + The format. + + + + Initializes a new instance of the class. + + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The object representing the JSON Schema. + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The to use when resolving schema references. + The object representing the JSON Schema. + + + + Load a from a string that contains JSON Schema. + + A that contains JSON Schema. + A populated from the string that contains JSON Schema. + + + + Load a from a string that contains JSON Schema using the specified . + + A that contains JSON Schema. + The resolver. + A populated from the string that contains JSON Schema. + + + + Writes this schema to a . + + A into which this method will write. + + + + Writes this schema to a using the specified . + + A into which this method will write. + The resolver used. + + + + Returns a that represents the current . + + + A that represents the current . + + + + + + Returns detailed information about the schema exception. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + + Generates a from a specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets how undefined schemas are handled by the serializer. + + + + + Gets or sets the contract resolver. + + The contract resolver. + + + + Generate a from the specified type. + + The type to generate a from. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + + Resolves from an id. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the loaded schemas. + + The loaded schemas. + + + + Initializes a new instance of the class. + + + + + Gets a for the specified reference. + + The id. + A for the specified reference. + + + + + The value types allowed by the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + No type specified. + + + + + String type. + + + + + Float type. + + + + + Integer type. + + + + + Boolean type. + + + + + Object type. + + + + + Array type. + + + + + Null type. + + + + + Any type. + + + + + + Specifies undefined schema Id handling options for the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Do not infer a schema Id. + + + + + Use the .NET type name as the schema Id. + + + + + Use the assembly qualified .NET type name as the schema Id. + + + + + + Returns detailed information related to the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the associated with the validation error. + + The JsonSchemaException associated with the validation error. + + + + Gets the path of the JSON location where the validation error occurred. + + The path of the JSON location where the validation error occurred. + + + + Gets the text description corresponding to the validation error. + + The text description. + + + + + Represents the callback method that will handle JSON schema validation events and the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Allows users to control class loading and mandate what class to load. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object + The type of the object the formatter creates a new instance of. + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + A camel case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Resolves member mappings for a type, camel casing property names. + + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used by to resolve a for a given . + + + + + Gets a value indicating whether members are being get and set using dynamic code generation. + This value is determined by the runtime permissions available. + + + true if using dynamic code generation; otherwise, false. + + + + + Gets or sets a value indicating whether compiler generated members should be serialized. + + + true if serialized compiler generated members; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore the interface when serializing and deserializing types. + + + true if the interface will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore the attribute when serializing and deserializing types. + + + true if the attribute will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore IsSpecified members when serializing and deserializing types. + + + true if the IsSpecified members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore ShouldSerialize members when serializing and deserializing types. + + + true if the ShouldSerialize members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets the naming strategy used to resolve how property names and dictionary keys are serialized. + + The naming strategy used to resolve how property names and dictionary keys are serialized. + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Gets the serializable members for the type. + + The type to get serializable members for. + The serializable members for the type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates the constructor parameters. + + The constructor to create properties for. + The type's member properties. + Properties for the given . + + + + Creates a for the given . + + The matching member property. + The constructor parameter. + A created for the given . + + + + Resolves the default for the contract. + + Type of the object. + The contract's default . + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Determines which contract type is created for the given type. + + Type of the object. + A for the given type. + + + + Creates properties for the given . + + The type to create properties for. + /// The member serialization mode for the type. + Properties for the given . + + + + Creates the used by the serializer to get and set values from a member. + + The member. + The used by the serializer to get and set values from a member. + + + + Creates a for the given . + + The member's parent . + The member to create a for. + A created for the given . + + + + Resolves the name of the property. + + Name of the property. + Resolved name of the property. + + + + Resolves the name of the extension data. By default no changes are made to extension data names. + + Name of the extension data. + Resolved name of the extension data. + + + + Resolves the key of the dictionary. By default is used to resolve dictionary keys. + + Key of the dictionary. + Resolved key of the dictionary. + + + + Gets the resolved name of the property. + + Name of the property. + Name of the property. + + + + The default naming strategy. Property names and dictionary keys are unchanged. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + The default serialization binder used when resolving and loading classes from type names. + + + + + Initializes a new instance of the class. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + The type of the object the formatter creates a new instance of. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Provides information surrounding an error. + + + + + Gets the error. + + The error. + + + + Gets the original object that caused the error. + + The original object that caused the error. + + + + Gets the member that caused the error. + + The member that caused the error. + + + + Gets the path of the JSON location where the error occurred. + + The path of the JSON location where the error occurred. + + + + Gets or sets a value indicating whether this is handled. + + true if handled; otherwise, false. + + + + Provides data for the Error event. + + + + + Gets the current object the error event is being raised against. + + The current object the error event is being raised against. + + + + Gets the error context. + + The error context. + + + + Initializes a new instance of the class. + + The current object. + The error context. + + + + Get and set values for a using dynamic methods. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Provides methods to get attributes. + + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Used by to resolve a for a given . + + + + + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used to resolve references when serializing and deserializing JSON by the . + + + + + Resolves a reference to its object. + + The serialization context. + The reference to resolve. + The object that was resolved from the reference. + + + + Gets the reference for the specified object. + + The serialization context. + The object to get a reference for. + The reference to the object. + + + + Determines whether the specified object is referenced. + + The serialization context. + The object to test for a reference. + + true if the specified object is referenced; otherwise, false. + + + + + Adds a reference to the specified object. + + The serialization context. + The reference. + The object to reference. + + + + Allows users to control class loading and mandate what class to load. + + + + + When implemented, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object + The type of the object the formatter creates a new instance of. + + + + When implemented, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Represents a trace writer. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + The that will be used to filter the trace messages passed to the writer. + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Provides methods to get and set values. + + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Contract details for a used by the . + + + + + Gets the of the collection items. + + The of the collection items. + + + + Gets a value indicating whether the collection type is a multidimensional array. + + true if the collection type is a multidimensional array; otherwise, false. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the collection values. + + true if the creator has a parameter with the collection values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the default collection items . + + The converter. + + + + Gets or sets a value indicating whether the collection items preserve object references. + + true if collection items preserve object references; otherwise, false. + + + + Gets or sets the collection item reference loop handling. + + The reference loop handling. + + + + Gets or sets the collection item type name handling. + + The type name handling. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Handles serialization callback events. + + The object that raised the callback event. + The streaming context. + + + + Handles serialization error callback events. + + The object that raised the callback event. + The streaming context. + The error context. + + + + Sets extension data for an object during deserialization. + + The object to set extension data on. + The extension data key. + The extension data value. + + + + Gets extension data for an object during serialization. + + The object to set extension data on. + + + + Contract details for a used by the . + + + + + Gets the underlying type for the contract. + + The underlying type for the contract. + + + + Gets or sets the type created during deserialization. + + The type created during deserialization. + + + + Gets or sets whether this type contract is serialized as a reference. + + Whether this type contract is serialized as a reference. + + + + Gets or sets the default for this contract. + + The converter. + + + + Gets the internally resolved for the contract's type. + This converter is used as a fallback converter when no other converter is resolved. + Setting will always override this converter. + + + + + Gets or sets all methods called immediately after deserialization of the object. + + The methods called immediately after deserialization of the object. + + + + Gets or sets all methods called during deserialization of the object. + + The methods called during deserialization of the object. + + + + Gets or sets all methods called after serialization of the object graph. + + The methods called after serialization of the object graph. + + + + Gets or sets all methods called before serialization of the object. + + The methods called before serialization of the object. + + + + Gets or sets all method called when an error is thrown during the serialization of the object. + + The methods called when an error is thrown during the serialization of the object. + + + + Gets or sets the default creator method used to create the object. + + The default creator method used to create the object. + + + + Gets or sets a value indicating whether the default creator is non-public. + + true if the default object creator is non-public; otherwise, false. + + + + Contract details for a used by the . + + + + + Gets or sets the dictionary key resolver. + + The dictionary key resolver. + + + + Gets the of the dictionary keys. + + The of the dictionary keys. + + + + Gets the of the dictionary values. + + The of the dictionary values. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the dictionary values. + + true if the creator has a parameter with the dictionary values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets the object's properties. + + The object's properties. + + + + Gets or sets the property name resolver. + + The property name resolver. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object constructor. + + The object constructor. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object member serialization. + + The member object serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets the object's properties. + + The object's properties. + + + + Gets a collection of instances that define the parameters used with . + + + + + Gets or sets the function used to create the object. When set this function will override . + This function is called with a collection of arguments which are defined by the collection. + + The function used to create the object. + + + + Gets or sets the extension data setter. + + + + + Gets or sets the extension data getter. + + + + + Gets or sets the extension data value type. + + + + + Gets or sets the extension data name resolver. + + The extension data name resolver. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Maps a JSON property to a .NET member or constructor parameter. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the type that declared this property. + + The type that declared this property. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets the name of the underlying member or parameter. + + The name of the underlying member or parameter. + + + + Gets the that will get and set the during serialization. + + The that will get and set the during serialization. + + + + Gets or sets the for this property. + + The for this property. + + + + Gets or sets the type of the property. + + The type of the property. + + + + Gets or sets the for the property. + If set this converter takes precedence over the contract converter for the property type. + + The converter. + + + + Gets or sets the member converter. + + The member converter. + + + + Gets or sets a value indicating whether this is ignored. + + true if ignored; otherwise, false. + + + + Gets or sets a value indicating whether this is readable. + + true if readable; otherwise, false. + + + + Gets or sets a value indicating whether this is writable. + + true if writable; otherwise, false. + + + + Gets or sets a value indicating whether this has a member attribute. + + true if has a member attribute; otherwise, false. + + + + Gets the default value. + + The default value. + + + + Gets or sets a value indicating whether this is required. + + A value indicating whether this is required. + + + + Gets a value indicating whether has a value specified. + + + + + Gets or sets a value indicating whether this property preserves object references. + + + true if this instance is reference; otherwise, false. + + + + + Gets or sets the property null value handling. + + The null value handling. + + + + Gets or sets the property default value handling. + + The default value handling. + + + + Gets or sets the property reference loop handling. + + The reference loop handling. + + + + Gets or sets the property object creation handling. + + The object creation handling. + + + + Gets or sets or sets the type name handling. + + The type name handling. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets a predicate used to determine whether the property should be deserialized. + + A predicate used to determine whether the property should be deserialized. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets an action used to set whether the property has been deserialized. + + An action used to set whether the property has been deserialized. + + + + Returns a that represents this instance. + + + A that represents this instance. + + + + + Gets or sets the converter used when serializing the property's collection items. + + The collection's items converter. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + A collection of objects. + + + + + Initializes a new instance of the class. + + The type. + + + + When implemented in a derived class, extracts the key from the specified element. + + The element from which to extract the key. + The key for the specified element. + + + + Adds a object. + + The property to add to the collection. + + + + Gets the closest matching object. + First attempts to get an exact case match of and then + a case insensitive match. + + Name of the property. + A matching property if found. + + + + Gets a property by property name. + + The name of the property to get. + Type property name string comparison. + A matching property if found. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Lookup and create an instance of the type described by the argument. + + The type to create. + Optional arguments to pass to an initializing constructor of the JsonConverter. + If null, the default constructor is used. + + + + A kebab case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Represents a trace writer that writes to memory. When the trace message limit is + reached then old trace messages will be removed as new messages are added. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + + The that will be used to filter the trace messages passed to the writer. + + + + + Initializes a new instance of the class. + + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Returns an enumeration of the most recent trace messages. + + An enumeration of the most recent trace messages. + + + + Returns a of the most recent trace messages. + + + A of the most recent trace messages. + + + + + A base class for resolving how property names and dictionary keys are serialized. + + + + + A flag indicating whether dictionary keys should be processed. + Defaults to false. + + + + + A flag indicating whether extension data names should be processed. + Defaults to false. + + + + + A flag indicating whether explicitly specified property names, + e.g. a property name customized with a , should be processed. + Defaults to false. + + + + + Gets the serialized name for a given property name. + + The initial property name. + A flag indicating whether the property has had a name explicitly specified. + The serialized property name. + + + + Gets the serialized name for a given extension data name. + + The initial extension data name. + The serialized extension data name. + + + + Gets the serialized key for a given dictionary key. + + The initial dictionary key. + The serialized dictionary key. + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Hash code calculation + + + + + + Object equality implementation + + + + + + + Compare to another NamingStrategy + + + + + + + Represents a method that constructs an object. + + The object type to create. + + + + When applied to a method, specifies that the method is called when an error occurs serializing an object. + + + + + Provides methods to get attributes from a , , or . + + + + + Initializes a new instance of the class. + + The instance to get attributes for. This parameter should be a , , or . + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Get and set values for a using reflection. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + A snake case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Specifies how strings are escaped when writing JSON text. + + + + + Only control characters (e.g. newline) are escaped. + + + + + All non-ASCII and control characters (e.g. newline) are escaped. + + + + + HTML (<, >, &, ', ") and control characters (e.g. newline) are escaped. + + + + + Specifies what messages to output for the class. + + + + + Output no tracing and debugging messages. + + + + + Output error-handling messages. + + + + + Output warnings and error-handling messages. + + + + + Output informational messages, warnings, and error-handling messages. + + + + + Output all debugging and tracing messages. + + + + + Indicates the method that will be used during deserialization for locating and loading assemblies. + + + + + In simple mode, the assembly used during deserialization need not match exactly the assembly used during serialization. Specifically, the version numbers need not match as the LoadWithPartialName method of the class is used to load the assembly. + + + + + In full mode, the assembly used during deserialization must match exactly the assembly used during serialization. The Load method of the class is used to load the assembly. + + + + + Specifies type name handling options for the . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Do not include the .NET type name when serializing types. + + + + + Include the .NET type name when serializing into a JSON object structure. + + + + + Include the .NET type name when serializing into a JSON array structure. + + + + + Always include the .NET type name when serializing. + + + + + Include the .NET type name when the type of the object being serialized is not the same as its declared type. + Note that this doesn't include the root serialized object by default. To include the root object's type name in JSON + you must specify a root type object with + or . + + + + + Determines whether the collection is null or empty. + + The collection. + + true if the collection is null or empty; otherwise, false. + + + + + Adds the elements of the specified collection to the specified generic . + + The list to add to. + The collection of elements to add. + + + + Converts the value to the specified type. If the value is unable to be converted, the + value is checked whether it assignable to the specified type. + + The value to convert. + The culture to use when converting. + The type to convert or cast the value to. + + The converted type. If conversion was unsuccessful, the initial value + is returned if assignable to the target type. + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic that returns a result + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic, but uses one of the arguments for + the result. + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic, but uses one of the arguments for + the result. + + + + + Returns a Restrictions object which includes our current restrictions merged + with a restriction limiting our type + + + + + Helper class for serializing immutable collections. + Note that this is used by all builds, even those that don't support immutable collections, in case the DLL is GACed + https://github.com/JamesNK/Newtonsoft.Json/issues/652 + + + + + List of primitive types which can be widened. + + + + + Widening masks for primitive types above. + Index of the value in this array defines a type we're widening, + while the bits in mask define types it can be widened to (including itself). + + For example, value at index 0 defines a bool type, and it only has bit 0 set, + i.e. bool values can be assigned only to bool. + + + + + Checks if value of primitive type can be + assigned to parameter of primitive type . + + Source primitive type. + Target primitive type. + true if source type can be widened to target type, false otherwise. + + + + Checks if a set of values with given can be used + to invoke a method with specified . + + Method parameters. + Argument types. + Try to pack extra arguments into the last parameter when it is marked up with . + true if method can be called with given arguments, false otherwise. + + + + Compares two sets of parameters to determine + which one suits better for given argument types. + + + + + Returns a best method overload for given argument . + + List of method candidates. + Argument types. + Best method overload, or null if none matched. + + + + Gets the type of the typed collection's items. + + The type. + The type of the typed collection's items. + + + + Gets the member's underlying type. + + The member. + The underlying type of the member. + + + + Determines whether the property is an indexed property. + + The property. + + true if the property is an indexed property; otherwise, false. + + + + + Gets the member's value on the object. + + The member. + The target object. + The member's value on the object. + + + + Sets the member's value on the target object. + + The member. + The target. + The value. + + + + Determines whether the specified MemberInfo can be read. + + The MemberInfo to determine whether can be read. + /// if set to true then allow the member to be gotten non-publicly. + + true if the specified MemberInfo can be read; otherwise, false. + + + + + Determines whether the specified MemberInfo can be set. + + The MemberInfo to determine whether can be set. + if set to true then allow the member to be set non-publicly. + if set to true then allow the member to be set if read-only. + + true if the specified MemberInfo can be set; otherwise, false. + + + + + Builds a string. Unlike this class lets you reuse its internal buffer. + + + + + Determines whether the string is all white space. Empty string will return false. + + The string to test whether it is all white space. + + true if the string is all white space; otherwise, false. + + + + + Specifies the state of the . + + + + + An exception has been thrown, which has left the in an invalid state. + You may call the method to put the in the Closed state. + Any other method calls result in an being thrown. + + + + + The method has been called. + + + + + An object is being written. + + + + + An array is being written. + + + + + A constructor is being written. + + + + + A property is being written. + + + + + A write method has not been called. + + + + + Indicates the method that will be used during deserialization for locating and loading assemblies. + + + + + In simple mode, the assembly used during deserialization need not match exactly the assembly used during serialization. Specifically, the version numbers need not match as the method is used to load the assembly. + + + + + In full mode, the assembly used during deserialization must match exactly the assembly used during serialization. The is used to load the assembly. + + + + Specifies that an output will not be null even if the corresponding type allows it. + + + Specifies that when a method returns , the parameter will not be null even if the corresponding type allows it. + + + Initializes the attribute with the specified return value condition. + + The return value condition. If the method returns this value, the associated parameter will not be null. + + + + Gets the return value condition. + + + Specifies that an output may be null even if the corresponding type disallows it. + + + Specifies that null is allowed as an input even if the corresponding type disallows it. + + + + Specifies that the method will not return if the associated Boolean parameter is passed the specified value. + + + + + Initializes a new instance of the class. + + + The condition parameter value. Code after the method will be considered unreachable by diagnostics if the argument to + the associated parameter matches this value. + + + + Gets the condition parameter value. + + + diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/netstandard2.0/Newtonsoft.Json.dll b/Packages/Newtonsoft.Json.13.0.1/lib/netstandard2.0/Newtonsoft.Json.dll new file mode 100644 index 0000000..1ffeabe Binary files /dev/null and b/Packages/Newtonsoft.Json.13.0.1/lib/netstandard2.0/Newtonsoft.Json.dll differ diff --git a/Packages/Newtonsoft.Json.13.0.1/lib/netstandard2.0/Newtonsoft.Json.xml b/Packages/Newtonsoft.Json.13.0.1/lib/netstandard2.0/Newtonsoft.Json.xml new file mode 100644 index 0000000..e3f5ad0 --- /dev/null +++ b/Packages/Newtonsoft.Json.13.0.1/lib/netstandard2.0/Newtonsoft.Json.xml @@ -0,0 +1,11280 @@ + + + + Newtonsoft.Json + + + + + Represents a BSON Oid (object id). + + + + + Gets or sets the value of the Oid. + + The value of the Oid. + + + + Initializes a new instance of the class. + + The Oid value. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized BSON data. + + + + + Gets or sets a value indicating whether binary data reading should be compatible with incorrect Json.NET 3.5 written binary. + + + true if binary data reading will be compatible with incorrect Json.NET 3.5 written binary; otherwise, false. + + + + + Gets or sets a value indicating whether the root object will be read as a JSON array. + + + true if the root object will be read as a JSON array; otherwise, false. + + + + + Gets or sets the used when reading values from BSON. + + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Initializes a new instance of the class. + + The containing the BSON data to read. + if set to true the root object will be read as a JSON array. + The used when reading values from BSON. + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating BSON data. + + + + + Gets or sets the used when writing values to BSON. + When set to no conversion will occur. + + The used when writing values to BSON. + + + + Initializes a new instance of the class. + + The to write to. + + + + Initializes a new instance of the class. + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying stream. + + + + + Writes the end. + + The token. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes the beginning of a JSON array. + + + + + Writes the beginning of a JSON object. + + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value that represents a BSON object id. + + The Object ID value to write. + + + + Writes a BSON regex. + + The regex pattern. + The regex options. + + + + Specifies how constructors are used when initializing objects during deserialization by the . + + + + + First attempt to use the public default constructor, then fall back to a single parameterized constructor, then to the non-public default constructor. + + + + + Json.NET will use a non-public default constructor before falling back to a parameterized constructor. + + + + + Converts a binary value to and from a base 64 string value. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Creates a custom object. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Creates an object which will then be populated by the serializer. + + Type of the object. + The created object. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can write JSON. + + + true if this can write JSON; otherwise, false. + + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Provides a base class for converting a to and from JSON. + + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a F# discriminated union type to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an Entity Framework to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can write JSON. + + + true if this can write JSON; otherwise, false. + + + + + Converts a to and from the ISO 8601 date format (e.g. "2008-04-12T12:53Z"). + + + + + Gets or sets the date time styles used when converting a date to and from JSON. + + The date time styles used when converting a date to and from JSON. + + + + Gets or sets the date time format used when converting a date to and from JSON. + + The date time format used when converting a date to and from JSON. + + + + Gets or sets the culture used when converting a date to and from JSON. + + The culture used when converting a date to and from JSON. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Converts a to and from a JavaScript Date constructor (e.g. new Date(52231943)). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from JSON and BSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts an to and from its name string value. + + + + + Gets or sets a value indicating whether the written enum text should be camel case. + The default value is false. + + true if the written enum text will be camel case; otherwise, false. + + + + Gets or sets the naming strategy used to resolve how enum text is written. + + The naming strategy used to resolve how enum text is written. + + + + Gets or sets a value indicating whether integer values are allowed when serializing and deserializing. + The default value is true. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class. + + true if the written enum text will be camel case; otherwise, false. + + + + Initializes a new instance of the class. + + The naming strategy used to resolve how enum text is written. + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + + Initializes a new instance of the class. + + The of the used to write enum text. + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + true if integers are allowed when serializing and deserializing; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts a to and from Unix epoch time + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Converts a to and from a string (e.g. "1.2.3.4"). + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing property value of the JSON that is being converted. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Converts XML to and from JSON. + + + + + Gets or sets the name of the root element to insert when deserializing to XML if the JSON structure has produced multiple root elements. + + The name of the deserialized root element. + + + + Gets or sets a value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + true if the array attribute is written to the XML; otherwise, false. + + + + Gets or sets a value indicating whether to write the root JSON object. + + true if the JSON root object is omitted; otherwise, false. + + + + Gets or sets a value indicating whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + true if special characters are encoded; otherwise, false. + + + + Writes the JSON representation of the object. + + The to write to. + The calling serializer. + The value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Checks if the is a namespace attribute. + + Attribute name to test. + The attribute name prefix if it has one, otherwise an empty string. + true if attribute name is for a namespace attribute, otherwise false. + + + + Determines whether this instance can convert the specified value type. + + Type of the value. + + true if this instance can convert the specified value type; otherwise, false. + + + + + Specifies how dates are formatted when writing JSON text. + + + + + Dates are written in the ISO 8601 format, e.g. "2012-03-21T05:40Z". + + + + + Dates are written in the Microsoft JSON format, e.g. "\/Date(1198908717056)\/". + + + + + Specifies how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON text. + + + + + Date formatted strings are not parsed to a date type and are read as strings. + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed to . + + + + + Specifies how to treat the time value when converting between string and . + + + + + Treat as local time. If the object represents a Coordinated Universal Time (UTC), it is converted to the local time. + + + + + Treat as a UTC. If the object represents a local time, it is converted to a UTC. + + + + + Treat as a local time if a is being converted to a string. + If a string is being converted to , convert to a local time if a time zone is specified. + + + + + Time zone information should be preserved when converting. + + + + + The default JSON name table implementation. + + + + + Initializes a new instance of the class. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Adds the specified string into name table. + + The string to add. + This method is not thread-safe. + The resolved string. + + + + Specifies default value handling options for the . + + + + + + + + + Include members where the member value is the same as the member's default value when serializing objects. + Included members are written to JSON. Has no effect when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + so that it is not written to JSON. + This option will ignore all default values (e.g. null for objects and nullable types; 0 for integers, + decimals and floating point numbers; and false for booleans). The default value ignored can be changed by + placing the on the property. + + + + + Members with a default value but no JSON will be set to their default value when deserializing. + + + + + Ignore members where the member value is the same as the member's default value when serializing objects + and set members to their default value when deserializing. + + + + + Specifies float format handling options when writing special floating point numbers, e.g. , + and with . + + + + + Write special floating point values as strings in JSON, e.g. "NaN", "Infinity", "-Infinity". + + + + + Write special floating point values as symbols in JSON, e.g. NaN, Infinity, -Infinity. + Note that this will produce non-valid JSON. + + + + + Write special floating point values as the property's default value in JSON, e.g. 0.0 for a property, null for a of property. + + + + + Specifies how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Floating point numbers are parsed to . + + + + + Floating point numbers are parsed to . + + + + + Specifies formatting options for the . + + + + + No special formatting is applied. This is the default. + + + + + Causes child objects to be indented according to the and settings. + + + + + Provides an interface for using pooled arrays. + + The array type content. + + + + Rent an array from the pool. This array must be returned when it is no longer needed. + + The minimum required length of the array. The returned array may be longer. + The rented array from the pool. This array must be returned when it is no longer needed. + + + + Return an array to the pool. + + The array that is being returned. + + + + Provides an interface to enable a class to return line and position information. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + The current line number or 0 if no line information is available (for example, when returns false). + + + + Gets the current line position. + + The current line position or 0 if no line information is available (for example, when returns false). + + + + Instructs the how to serialize the collection. + + + + + Gets or sets a value indicating whether null items are allowed in the collection. + + true if null items are allowed in the collection; otherwise, false. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with a flag indicating whether the array can contain null items. + + A flag indicating whether the array can contain null items. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to use the specified constructor when deserializing that object. + + + + + Instructs the how to serialize the object. + + + + + Gets or sets the id. + + The id. + + + + Gets or sets the title. + + The title. + + + + Gets or sets the description. + + The description. + + + + Gets or sets the collection's items converter. + + The collection's items converter. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonContainer(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets a value that indicates whether to preserve object references. + + + true to keep object reference; otherwise, false. The default is false. + + + + + Gets or sets a value that indicates whether to preserve collection's items references. + + + true to keep collection's items object references; otherwise, false. The default is false. + + + + + Gets or sets the reference loop handling used when serializing the collection's items. + + The reference loop handling. + + + + Gets or sets the type name handling used when serializing the collection's items. + + The type name handling. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Provides methods for converting between .NET types and JSON types. + + + + + + + + Gets or sets a function that creates default . + Default settings are automatically used by serialization methods on , + and and on . + To serialize without using any default settings create a with + . + + + + + Represents JavaScript's boolean value true as a string. This field is read-only. + + + + + Represents JavaScript's boolean value false as a string. This field is read-only. + + + + + Represents JavaScript's null as a string. This field is read-only. + + + + + Represents JavaScript's undefined as a string. This field is read-only. + + + + + Represents JavaScript's positive infinity as a string. This field is read-only. + + + + + Represents JavaScript's negative infinity as a string. This field is read-only. + + + + + Represents JavaScript's NaN as a string. This field is read-only. + + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + The time zone handling when the date is converted to a string. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation using the specified. + + The value to convert. + The format the date will be converted to. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + The string delimiter character. + The string escape handling. + A JSON string representation of the . + + + + Converts the to its JSON string representation. + + The value to convert. + A JSON string representation of the . + + + + Serializes the specified object to a JSON string. + + The object to serialize. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting. + + The object to serialize. + Indicates how the output should be formatted. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a collection of . + + The object to serialize. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using formatting and a collection of . + + The object to serialize. + Indicates how the output should be formatted. + A collection of converters used while serializing. + A JSON string representation of the object. + + + + Serializes the specified object to a JSON string using . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + A JSON string representation of the object. + + + + + Serializes the specified object to a JSON string using a type, formatting and . + + The object to serialize. + Indicates how the output should be formatted. + The used to serialize the object. + If this is null, default serialization settings will be used. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + A JSON string representation of the object. + + + + + Deserializes the JSON to a .NET object. + + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to a .NET object using . + + The JSON to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The JSON to deserialize. + The of object being deserialized. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type. + + The type of the object to deserialize to. + The JSON to deserialize. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the given anonymous type. + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the given anonymous type using . + + + The anonymous type to deserialize to. This can't be specified + traditionally and must be inferred from the anonymous type passed + as a parameter. + + The JSON to deserialize. + The anonymous type object. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized anonymous type from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The type of the object to deserialize to. + The JSON to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The type of the object to deserialize to. + The object to deserialize. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using a collection of . + + The JSON to deserialize. + The type of the object to deserialize. + Converters to use while deserializing. + The deserialized object from the JSON string. + + + + Deserializes the JSON to the specified .NET type using . + + The JSON to deserialize. + The type of the object to deserialize to. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + The deserialized object from the JSON string. + + + + Populates the object with values from the JSON string. + + The JSON to populate values from. + The target object to populate values onto. + + + + Populates the object with values from the JSON string using . + + The JSON to populate values from. + The target object to populate values onto. + + The used to deserialize the object. + If this is null, default serialization settings will be used. + + + + + Serializes the to a JSON string. + + The node to serialize. + A JSON string of the . + + + + Serializes the to a JSON string using formatting. + + The node to serialize. + Indicates how the output should be formatted. + A JSON string of the . + + + + Serializes the to a JSON string using formatting and omits the root object if is true. + + The node to serialize. + Indicates how the output should be formatted. + Omits writing the root object. + A JSON string of the . + + + + Deserializes the from a JSON string. + + The JSON string. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by . + + The JSON string. + The name of the root element to append when deserializing. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by + and writes a Json.NET array attribute for collections. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by , + writes a Json.NET array attribute for collections, and encodes special characters. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + + A value to indicate whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + The deserialized . + + + + Serializes the to a JSON string. + + The node to convert to JSON. + A JSON string of the . + + + + Serializes the to a JSON string using formatting. + + The node to convert to JSON. + Indicates how the output should be formatted. + A JSON string of the . + + + + Serializes the to a JSON string using formatting and omits the root object if is true. + + The node to serialize. + Indicates how the output should be formatted. + Omits writing the root object. + A JSON string of the . + + + + Deserializes the from a JSON string. + + The JSON string. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by . + + The JSON string. + The name of the root element to append when deserializing. + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by + and writes a Json.NET array attribute for collections. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + The deserialized . + + + + Deserializes the from a JSON string nested in a root element specified by , + writes a Json.NET array attribute for collections, and encodes special characters. + + The JSON string. + The name of the root element to append when deserializing. + + A value to indicate whether to write the Json.NET array attribute. + This attribute helps preserve arrays when converting the written XML back to JSON. + + + A value to indicate whether to encode special characters when converting JSON to XML. + If true, special characters like ':', '@', '?', '#' and '$' in JSON property names aren't used to specify + XML namespaces, attributes or processing directives. Instead special characters are encoded and written + as part of the XML element name. + + The deserialized . + + + + Converts an object to and from JSON. + + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Gets a value indicating whether this can read JSON. + + true if this can read JSON; otherwise, false. + + + + Gets a value indicating whether this can write JSON. + + true if this can write JSON; otherwise, false. + + + + Converts an object to and from JSON. + + The object type to convert. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Writes the JSON representation of the object. + + The to write to. + The value. + The calling serializer. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. + The calling serializer. + The object value. + + + + Reads the JSON representation of the object. + + The to read from. + Type of the object. + The existing value of object being read. If there is no existing value then null will be used. + The existing value has a value. + The calling serializer. + The object value. + + + + Determines whether this instance can convert the specified object type. + + Type of the object. + + true if this instance can convert the specified object type; otherwise, false. + + + + + Instructs the to use the specified when serializing the member or class. + + + + + Gets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + + + + + Initializes a new instance of the class. + + Type of the . + + + + Initializes a new instance of the class. + + Type of the . + Parameter list to use when constructing the . Can be null. + + + + Represents a collection of . + + + + + Instructs the how to serialize the collection. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Instructs the to deserialize properties with no matching class member into the specified collection + and write values during serialization. + + + + + Gets or sets a value that indicates whether to write extension data when serializing the object. + + + true to write extension data when serializing the object; otherwise, false. The default is true. + + + + + Gets or sets a value that indicates whether to read extension data when deserializing the object. + + + true to read extension data when deserializing the object; otherwise, false. The default is true. + + + + + Initializes a new instance of the class. + + + + + Instructs the not to serialize the public field or public read/write property value. + + + + + Base class for a table of atomized string objects. + + + + + Gets a string containing the same characters as the specified range of characters in the given array. + + The character array containing the name to find. + The zero-based index into the array specifying the first character of the name. + The number of characters in the name. + A string containing the same characters as the specified range of characters in the given array. + + + + Instructs the how to serialize the object. + + + + + Gets or sets the member serialization. + + The member serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified member serialization. + + The member serialization. + + + + Initializes a new instance of the class with the specified container Id. + + The container Id. + + + + Instructs the to always serialize the member with the specified name. + + + + + Gets or sets the type used when serializing the property's collection items. + + The collection's items type. + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(ItemConverterType = typeof(MyContainerConverter), ItemConverterParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the of the . + + The of the . + + + + The parameter list to use when constructing the described by . + If null, the default constructor is used. + When non-null, there must be a constructor defined in the that exactly matches the number, + order, and type of these parameters. + + + + [JsonProperty(NamingStrategyType = typeof(MyNamingStrategy), NamingStrategyParameters = new object[] { 123, "Four" })] + + + + + + Gets or sets the null value handling used when serializing this property. + + The null value handling. + + + + Gets or sets the default value handling used when serializing this property. + + The default value handling. + + + + Gets or sets the reference loop handling used when serializing this property. + + The reference loop handling. + + + + Gets or sets the object creation handling used when deserializing this property. + + The object creation handling. + + + + Gets or sets the type name handling used when serializing this property. + + The type name handling. + + + + Gets or sets whether this property's value is serialized as a reference. + + Whether this property's value is serialized as a reference. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets a value indicating whether this property is required. + + + A value indicating whether this property is required. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class with the specified name. + + Name of the property. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Asynchronously reads the next JSON token from the source. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns true if the next token was read successfully; false if there are no more tokens to read. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously skips the children of the current token. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a []. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the []. This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously reads the next JSON token from the source as a . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the . This result will be null at the end of an array. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Specifies the state of the reader. + + + + + A read method has not been called. + + + + + The end of the file has been reached successfully. + + + + + Reader is at a property. + + + + + Reader is at the start of an object. + + + + + Reader is in an object. + + + + + Reader is at the start of an array. + + + + + Reader is in an array. + + + + + The method has been called. + + + + + Reader has just read a value. + + + + + Reader is at the start of a constructor. + + + + + Reader is in a constructor. + + + + + An error occurred that prevents the read operation from continuing. + + + + + The end of the file has been reached successfully. + + + + + Gets the current reader state. + + The current reader state. + + + + Gets or sets a value indicating whether the source should be closed when this reader is closed. + + + true to close the source when this reader is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether multiple pieces of JSON content can + be read from a continuous stream without erroring. + + + true to support reading multiple pieces of JSON content; otherwise false. + The default is false. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + Gets or sets how time zones are handled when reading JSON. + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + + + + + Gets or sets how custom date formatted strings are parsed when reading JSON. + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets the type of the current JSON token. + + + + + Gets the text value of the current JSON token. + + + + + Gets the .NET type for the current JSON token. + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets or sets the culture used when reading JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Reads the next JSON token from the source. + + true if the next token was read successfully; false if there are no more tokens to read. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the source as a of . + + A of . This method will return null at the end of an array. + + + + Skips the children of the current token. + + + + + Sets the current token. + + The new token. + + + + Sets the current token and value. + + The new token. + The value. + + + + Sets the current token and value. + + The new token. + The value. + A flag indicating whether the position index inside an array should be updated. + + + + Sets the state based on current token type. + + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Changes the reader's state to . + If is set to true, the source is also closed. + + + + + The exception thrown when an error occurs while reading JSON text. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Instructs the to always serialize the member, and to require that the member has a value. + + + + + The exception thrown when an error occurs during JSON serialization or deserialization. + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path, line number, line position, and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The line number indicating where the error occurred. + The line position indicating where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Serializes and deserializes objects into and from the JSON format. + The enables you to control how objects are encoded into JSON. + + + + + Occurs when the errors during serialization and deserialization. + + + + + Gets or sets the used by the serializer when resolving references. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when resolving type names. + + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + + + + Gets or sets how reference loops (e.g. a class referencing itself) is handled. + The default value is . + + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets a collection that will be used during serialization. + + Collection that will be used during serialization. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Gets a value indicating whether there will be a check for additional JSON content after deserializing an object. + The default value is false. + + + true if there will be a check for additional JSON content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Creates a new instance. + The will not use default settings + from . + + + A new instance. + The will not use default settings + from . + + + + + Creates a new instance using the specified . + The will not use default settings + from . + + The settings to be applied to the . + + A new instance using the specified . + The will not use default settings + from . + + + + + Creates a new instance. + The will use default settings + from . + + + A new instance. + The will use default settings + from . + + + + + Creates a new instance using the specified . + The will use default settings + from as well as the specified . + + The settings to be applied to the . + + A new instance using the specified . + The will use default settings + from as well as the specified . + + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Populates the JSON values onto the target object. + + The that contains the JSON structure to read values from. + The target object to populate values onto. + + + + Deserializes the JSON structure contained by the specified . + + The that contains the JSON structure to deserialize. + The being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The type of the object to deserialize. + The instance of being deserialized. + + + + Deserializes the JSON structure contained by the specified + into an instance of the specified type. + + The containing the object. + The of object being deserialized. + The instance of being deserialized. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + The type of the value being serialized. + This parameter is used when is Auto to write out the type name if the type of the value does not match. + Specifying the type is optional. + + + + + Serializes the specified and writes the JSON structure + using the specified . + + The used to write the JSON structure. + The to serialize. + + + + Specifies the settings on a object. + + + + + Gets or sets how reference loops (e.g. a class referencing itself) are handled. + The default value is . + + Reference loop handling. + + + + Gets or sets how missing members (e.g. JSON contains a property that isn't a member on the object) are handled during deserialization. + The default value is . + + Missing member handling. + + + + Gets or sets how objects are created during deserialization. + The default value is . + + The object creation handling. + + + + Gets or sets how null values are handled during serialization and deserialization. + The default value is . + + Null value handling. + + + + Gets or sets how default values are handled during serialization and deserialization. + The default value is . + + The default value handling. + + + + Gets or sets a collection that will be used during serialization. + + The converters. + + + + Gets or sets how object references are preserved by the serializer. + The default value is . + + The preserve references handling. + + + + Gets or sets how type name writing and reading is handled by the serializer. + The default value is . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + The type name handling. + + + + Gets or sets how metadata properties are used during deserialization. + The default value is . + + The metadata properties handling. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how a type name assembly is written and resolved by the serializer. + The default value is . + + The type name assembly format. + + + + Gets or sets how constructors are used during deserialization. + The default value is . + + The constructor handling. + + + + Gets or sets the contract resolver used by the serializer when + serializing .NET objects to JSON and vice versa. + + The contract resolver. + + + + Gets or sets the equality comparer used by the serializer when comparing references. + + The equality comparer. + + + + Gets or sets the used by the serializer when resolving references. + + The reference resolver. + + + + Gets or sets a function that creates the used by the serializer when resolving references. + + A function that creates the used by the serializer when resolving references. + + + + Gets or sets the used by the serializer when writing trace messages. + + The trace writer. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the used by the serializer when resolving type names. + + The binder. + + + + Gets or sets the error handler called during serialization and deserialization. + + The error handler called during serialization and deserialization. + + + + Gets or sets the used by the serializer when invoking serialization callback methods. + + The context. + + + + Gets or sets how and values are formatted when writing JSON text, + and the expected date format when reading JSON text. + The default value is "yyyy'-'MM'-'dd'T'HH':'mm':'ss.FFFFFFFK". + + + + + Gets or sets the maximum depth allowed when reading JSON. Reading past this depth will throw a . + A null value means there is no maximum. + The default value is 128. + + + + + Indicates how JSON text output is formatted. + The default value is . + + + + + Gets or sets how dates are written to JSON text. + The default value is . + + + + + Gets or sets how time zones are handled during serialization and deserialization. + The default value is . + + + + + Gets or sets how date formatted strings, e.g. "\/Date(1198908717056)\/" and "2012-03-21T05:40Z", are parsed when reading JSON. + The default value is . + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written as JSON. + The default value is . + + + + + Gets or sets how floating point numbers, e.g. 1.0 and 9.9, are parsed when reading JSON text. + The default value is . + + + + + Gets or sets how strings are escaped when writing JSON text. + The default value is . + + + + + Gets or sets the culture used when reading JSON. + The default value is . + + + + + Gets a value indicating whether there will be a check for additional content after deserializing an object. + The default value is false. + + + true if there will be a check for additional content after deserializing an object; otherwise, false. + + + + + Initializes a new instance of the class. + + + + + Represents a reader that provides fast, non-cached, forward-only access to JSON text data. + + + + + Asynchronously reads the next JSON token from the source. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns true if the next token was read successfully; false if there are no more tokens to read. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a []. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the []. This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a of . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the of . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously reads the next JSON token from the source as a . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous read. The + property returns the . This result will be null at the end of an array. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Initializes a new instance of the class with the specified . + + The containing the JSON data to read. + + + + Gets or sets the reader's property name table. + + + + + Gets or sets the reader's character buffer pool. + + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a []. + + A [] or null if the next JSON token is null. This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Gets a value indicating whether the class can return line information. + + + true if and can be provided; otherwise, false. + + + + + Gets the current line number. + + + The current line number or 0 if no line information is available (for example, returns false). + + + + + Gets the current line position. + + + The current line position or 0 if no line information is available (for example, returns false). + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Asynchronously flushes whatever is in the buffer to the destination and also flushes the destination. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the JSON value delimiter. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the specified end token. + + The end token to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously closes this writer. + If is set to true, the destination is also closed. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of the current JSON object or array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes indent characters. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes an indent space. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes raw JSON without changing the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a null value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the beginning of a JSON array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the beginning of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the start of a constructor with the given name. + + The name of the constructor. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes an undefined value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the given white space. + + The string of white space characters. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a [] value. + + The [] value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of an array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of a constructor. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes the end of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Asynchronously writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + Derived classes must override this method to get asynchronous behaviour. Otherwise it will + execute synchronously, returning an already-completed task. + + + + Gets or sets the writer's character array pool. + + + + + Gets or sets how many s to write for each level in the hierarchy when is set to . + + + + + Gets or sets which character to use to quote attribute values. + + + + + Gets or sets which character to use for indenting when is set to . + + + + + Gets or sets a value indicating whether object names will be surrounded with quotes. + + + + + Initializes a new instance of the class using the specified . + + The to write to. + + + + Flushes whatever is in the buffer to the underlying and also flushes the underlying . + + + + + Closes this writer. + If is set to true, the underlying is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the specified end token. + + The end token to write. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Specifies the type of JSON token. + + + + + This is returned by the if a read method has not been called. + + + + + An object start token. + + + + + An array start token. + + + + + A constructor start token. + + + + + An object property name. + + + + + A comment. + + + + + Raw JSON. + + + + + An integer. + + + + + A float. + + + + + A string. + + + + + A boolean. + + + + + A null token. + + + + + An undefined token. + + + + + An object end token. + + + + + An array end token. + + + + + A constructor end token. + + + + + A Date. + + + + + Byte data. + + + + + + Represents a reader that provides validation. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Sets an event handler for receiving schema validation errors. + + + + + Gets the text value of the current JSON token. + + + + + + Gets the depth of the current token in the JSON document. + + The depth of the current token in the JSON document. + + + + Gets the path of the current JSON token. + + + + + Gets the quotation mark character used to enclose the value of a string. + + + + + + Gets the type of the current JSON token. + + + + + + Gets the .NET type for the current JSON token. + + + + + + Initializes a new instance of the class that + validates the content returned from the given . + + The to read from while validating. + + + + Gets or sets the schema. + + The schema. + + + + Gets the used to construct this . + + The specified in the constructor. + + + + Changes the reader's state to . + If is set to true, the underlying is also closed. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a []. + + + A [] or null if the next JSON token is null. + + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying as a . + + A . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . This method will return null at the end of an array. + + + + Reads the next JSON token from the underlying as a of . + + A of . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Asynchronously closes this writer. + If is set to true, the destination is also closed. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously flushes whatever is in the buffer to the destination and also flushes the destination. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the specified end token. + + The end token to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes indent characters. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the JSON value delimiter. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes an indent space. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes raw JSON without changing the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of the current JSON object or array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of an array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of a constructor. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the end of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a null value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the beginning of a JSON array. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the start of a constructor with the given name. + + The name of the constructor. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the beginning of a JSON object. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the current token. + + The to read the token from. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the current token. + + The to read the token from. + A flag indicating whether the current token's children should be written. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the token and its value. + + The to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the token and its value. + + The to write. + + The value to write. + A value is only required for tokens that have an associated value, e.g. the property name for . + null can be passed to the method for tokens that don't have a value, e.g. . + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a [] value. + + The [] value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a value. + + The value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes a of value. + + The of value to write. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes an undefined value. + + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously writes the given white space. + + The string of white space characters. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Asynchronously ets the state of the . + + The being written. + The value being written. + The token to monitor for cancellation requests. The default value is . + A that represents the asynchronous operation. + The default behaviour is to execute synchronously, returning an already-completed task. Derived + classes can override this behaviour for true asynchronicity. + + + + Gets or sets a value indicating whether the destination should be closed when this writer is closed. + + + true to close the destination when this writer is closed; otherwise false. The default is true. + + + + + Gets or sets a value indicating whether the JSON should be auto-completed when this writer is closed. + + + true to auto-complete the JSON when this writer is closed; otherwise false. The default is true. + + + + + Gets the top. + + The top. + + + + Gets the state of the writer. + + + + + Gets the path of the writer. + + + + + Gets or sets a value indicating how JSON text output should be formatted. + + + + + Gets or sets how dates are written to JSON text. + + + + + Gets or sets how time zones are handled when writing JSON text. + + + + + Gets or sets how strings are escaped when writing JSON text. + + + + + Gets or sets how special floating point numbers, e.g. , + and , + are written to JSON text. + + + + + Gets or sets how and values are formatted when writing JSON text. + + + + + Gets or sets the culture used when writing JSON. Defaults to . + + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the destination and also flushes the destination. + + + + + Closes this writer. + If is set to true, the destination is also closed. + If is set to true, the JSON is auto-completed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the end of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the end of an array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end constructor. + + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + + + + Writes the property name of a name/value pair of a JSON object. + + The name of the property. + A flag to indicate whether the text should be escaped when it is written as a JSON property name. + + + + Writes the end of the current JSON object or array. + + + + + Writes the current token and its children. + + The to read the token from. + + + + Writes the current token. + + The to read the token from. + A flag indicating whether the current token's children should be written. + + + + Writes the token and its value. + + The to write. + + The value to write. + A value is only required for tokens that have an associated value, e.g. the property name for . + null can be passed to the method for tokens that don't have a value, e.g. . + + + + + Writes the token. + + The to write. + + + + Writes the specified end token. + + The end token to write. + + + + Writes indent characters. + + + + + Writes the JSON value delimiter. + + + + + Writes an indent space. + + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON without changing the writer's state. + + The raw JSON to write. + + + + Writes raw JSON where a value is expected and updates the writer's state. + + The raw JSON to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a of value. + + The of value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + An error will raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes the given white space. + + The string of white space characters. + + + + Releases unmanaged and - optionally - managed resources. + + true to release both managed and unmanaged resources; false to release only unmanaged resources. + + + + Sets the state of the . + + The being written. + The value being written. + + + + The exception thrown when an error occurs while writing JSON text. + + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + Initializes a new instance of the class + with a specified error message, JSON path and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The path to the JSON where the error occurred. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Specifies how JSON comments are handled when loading JSON. + + + + + Ignore comments. + + + + + Load comments as a with type . + + + + + Specifies how duplicate property names are handled when loading JSON. + + + + + Replace the existing value when there is a duplicate property. The value of the last property in the JSON object will be used. + + + + + Ignore the new value when there is a duplicate property. The value of the first property in the JSON object will be used. + + + + + Throw a when a duplicate property is encountered. + + + + + Contains the LINQ to JSON extension methods. + + + + + Returns a collection of tokens that contains the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the ancestors of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, the ancestors of every token in the source collection. + + + + Returns a collection of tokens that contains the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains the descendants of every token in the source collection. + + + + Returns a collection of tokens that contains every token in the source collection, and the descendants of every token in the source collection. + + The type of the objects in source, constrained to . + An of that contains the source collection. + An of that contains every token in the source collection, and the descendants of every token in the source collection. + + + + Returns a collection of child properties of every object in the source collection. + + An of that contains the source collection. + An of that contains the properties of every object in the source collection. + + + + Returns a collection of child values of every object in the source collection with the given key. + + An of that contains the source collection. + The token key. + An of that contains the values of every token in the source collection with the given key. + + + + Returns a collection of child values of every object in the source collection. + + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child values of every object in the source collection with the given key. + + The type to convert the values to. + An of that contains the source collection. + The token key. + An that contains the converted values of every token in the source collection with the given key. + + + + Returns a collection of converted child values of every object in the source collection. + + The type to convert the values to. + An of that contains the source collection. + An that contains the converted values of every token in the source collection. + + + + Converts the value. + + The type to convert the value to. + A cast as a of . + A converted value. + + + + Converts the value. + + The source collection type. + The type to convert the value to. + A cast as a of . + A converted value. + + + + Returns a collection of child tokens of every array in the source collection. + + The source collection type. + An of that contains the source collection. + An of that contains the values of every token in the source collection. + + + + Returns a collection of converted child tokens of every array in the source collection. + + An of that contains the source collection. + The type to convert the values to. + The source collection type. + An that contains the converted values of every token in the source collection. + + + + Returns the input typed as . + + An of that contains the source collection. + The input typed as . + + + + Returns the input typed as . + + The source collection type. + An of that contains the source collection. + The input typed as . + + + + Represents a collection of objects. + + The type of token. + + + + Gets the of with the specified key. + + + + + + Represents a JSON array. + + + + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous load. The property contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous load. The property contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Initializes a new instance of the class with the specified content. + + The contents of the array. + + + + Loads an from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads an from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the at the specified index. + + + + + + Determines the index of a specific item in the . + + The object to locate in the . + + The index of if found in the list; otherwise, -1. + + + + + Inserts an item to the at the specified index. + + The zero-based index at which should be inserted. + The object to insert into the . + + is not a valid index in the . + + + + + Removes the item at the specified index. + + The zero-based index of the item to remove. + + is not a valid index in the . + + + + + Returns an enumerator that iterates through the collection. + + + A of that can be used to iterate through the collection. + + + + + Adds an item to the . + + The object to add to the . + + + + Removes all items from the . + + + + + Determines whether the contains a specific value. + + The object to locate in the . + + true if is found in the ; otherwise, false. + + + + + Copies the elements of the to an array, starting at a particular array index. + + The array. + Index of the array. + + + + Gets a value indicating whether the is read-only. + + true if the is read-only; otherwise, false. + + + + Removes the first occurrence of a specific object from the . + + The object to remove from the . + + true if was successfully removed from the ; otherwise, false. This method also returns false if is not found in the original . + + + + + Represents a JSON constructor. + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets or sets the name of this constructor. + + The constructor name. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name and content. + + The constructor name. + The contents of the constructor. + + + + Initializes a new instance of the class with the specified name. + + The constructor name. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified key. + + The with the specified key. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a token that can contain other tokens. + + + + + Occurs when the list changes or an item in the list changes. + + + + + Occurs before an item is added to the collection. + + + + + Occurs when the items list of the collection has changed, or the collection is reset. + + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Raises the event. + + The instance containing the event data. + + + + Raises the event. + + The instance containing the event data. + + + + Raises the event. + + The instance containing the event data. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Get the first child token of this token. + + + A containing the first child token of the . + + + + + Get the last child token of this token. + + + A containing the last child token of the . + + + + + Returns a collection of the child tokens of this token, in document order. + + + An of containing the child tokens of this , in document order. + + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + + A containing the child values of this , in document order. + + + + + Returns a collection of the descendant tokens for this token in document order. + + An of containing the descendant tokens of the . + + + + Returns a collection of the tokens that contain this token, and all descendant tokens of this token, in document order. + + An of containing this token, and all the descendant tokens of the . + + + + Adds the specified content as children of this . + + The content to be added. + + + + Adds the specified content as the first children of this . + + The content to be added. + + + + Creates a that can be used to add tokens to the . + + A that is ready to have content written to it. + + + + Replaces the child nodes of this token with the specified content. + + The content. + + + + Removes the child nodes from this token. + + + + + Merge the specified content into this . + + The content to be merged. + + + + Merge the specified content into this using . + + The content to be merged. + The used to merge the content. + + + + Gets the count of child JSON tokens. + + The count of child JSON tokens. + + + + Represents a collection of objects. + + The type of token. + + + + An empty collection of objects. + + + + + Initializes a new instance of the struct. + + The enumerable. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Gets the of with the specified key. + + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Determines whether the specified is equal to this instance. + + The to compare with this instance. + + true if the specified is equal to this instance; otherwise, false. + + + + + Returns a hash code for this instance. + + + A hash code for this instance, suitable for use in hashing algorithms and data structures like a hash table. + + + + + Represents a JSON object. + + + + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous load. The + property returns a that contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Occurs when a property value changes. + + + + + Occurs when a property value is changing. + + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Initializes a new instance of the class with the specified content. + + The contents of the object. + + + + Gets the node type for this . + + The type. + + + + Gets an of of this object's properties. + + An of of this object's properties. + + + + Gets a with the specified name. + + The property name. + A with the specified name or null. + + + + Gets the with the specified name. + The exact name will be searched for first and if no matching property is found then + the will be used to match a property. + + The property name. + One of the enumeration values that specifies how the strings will be compared. + A matched with the specified name or null. + + + + Gets a of of this object's property values. + + A of of this object's property values. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets or sets the with the specified property name. + + + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + is not valid JSON. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + is not valid JSON. + + + + + + + + Creates a from an object. + + The object that will be used to create . + A with the values of the specified object. + + + + Creates a from an object. + + The object that will be used to create . + The that will be used to read the object. + A with the values of the specified object. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Gets the with the specified property name. + + Name of the property. + The with the specified property name. + + + + Gets the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + One of the enumeration values that specifies how the strings will be compared. + The with the specified property name. + + + + Tries to get the with the specified property name. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + Name of the property. + The value. + One of the enumeration values that specifies how the strings will be compared. + true if a value was successfully retrieved; otherwise, false. + + + + Adds the specified property name. + + Name of the property. + The value. + + + + Determines whether the JSON object has the specified property name. + + Name of the property. + true if the JSON object has the specified property name; otherwise, false. + + + + Removes the property with the specified name. + + Name of the property. + true if item was successfully removed; otherwise, false. + + + + Tries to get the with the specified property name. + + Name of the property. + The value. + true if a value was successfully retrieved; otherwise, false. + + + + Returns an enumerator that can be used to iterate through the collection. + + + A that can be used to iterate through the collection. + + + + + Raises the event with the provided arguments. + + Name of the property. + + + + Raises the event with the provided arguments. + + Name of the property. + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Represents a JSON property. + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous creation. The + property returns a that contains the JSON that was read from the specified . + + + + Asynchronously loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous creation. The + property returns a that contains the JSON that was read from the specified . + + + + Gets the container's children tokens. + + The container's children tokens. + + + + Gets the property name. + + The property name. + + + + Gets or sets the property value. + + The property value. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Gets the node type for this . + + The type. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Initializes a new instance of the class. + + The property name. + The property content. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Loads a from a . + + A that will be read for the content of the . + A that contains the JSON that was read from the specified . + + + + Loads a from a . + + A that will be read for the content of the . + The used to load the JSON. + If this is null, default load settings will be used. + A that contains the JSON that was read from the specified . + + + + Represents a view of a . + + + + + Initializes a new instance of the class. + + The name. + + + + When overridden in a derived class, returns whether resetting an object changes its value. + + + true if resetting the component changes its value; otherwise, false. + + The component to test for reset capability. + + + + When overridden in a derived class, gets the current value of the property on a component. + + + The value of a property for a given component. + + The component with the property for which to retrieve the value. + + + + When overridden in a derived class, resets the value for this property of the component to the default value. + + The component with the property value that is to be reset to the default value. + + + + When overridden in a derived class, sets the value of the component to a different value. + + The component with the property value that is to be set. + The new value. + + + + When overridden in a derived class, determines a value indicating whether the value of this property needs to be persisted. + + + true if the property should be persisted; otherwise, false. + + The component with the property to be examined for persistence. + + + + When overridden in a derived class, gets the type of the component this property is bound to. + + + A that represents the type of component this property is bound to. + When the or + + methods are invoked, the object specified might be an instance of this type. + + + + + When overridden in a derived class, gets a value indicating whether this property is read-only. + + + true if the property is read-only; otherwise, false. + + + + + When overridden in a derived class, gets the type of the property. + + + A that represents the type of the property. + + + + + Gets the hash code for the name of the member. + + + + The hash code for the name of the member. + + + + + Represents a raw JSON string. + + + + + Asynchronously creates an instance of with the content of the reader's current token. + + The reader. + The token to monitor for cancellation requests. The default value is . + A representing the asynchronous creation. The + property returns an instance of with the content of the reader's current token. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class. + + The raw json. + + + + Creates an instance of with the content of the reader's current token. + + The reader. + An instance of with the content of the reader's current token. + + + + Specifies the settings used when loading JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets how JSON comments are handled when loading JSON. + The default value is . + + The JSON comment handling. + + + + Gets or sets how JSON line info is handled when loading JSON. + The default value is . + + The JSON line info handling. + + + + Gets or sets how duplicate property names in JSON objects are handled when loading JSON. + The default value is . + + The JSON duplicate property name handling. + + + + Specifies the settings used when merging JSON. + + + + + Initializes a new instance of the class. + + + + + Gets or sets the method used when merging JSON arrays. + + The method used when merging JSON arrays. + + + + Gets or sets how null value properties are merged. + + How null value properties are merged. + + + + Gets or sets the comparison used to match property names while merging. + The exact property name will be searched for first and if no matching property is found then + the will be used to match a property. + + The comparison used to match property names while merging. + + + + Specifies the settings used when selecting JSON. + + + + + Gets or sets a timeout that will be used when executing regular expressions. + + The timeout that will be used when executing regular expressions. + + + + Gets or sets a flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + A flag that indicates whether an error should be thrown if + no tokens are found when evaluating part of the expression. + + + + + Represents an abstract JSON token. + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Writes this token to a asynchronously. + + A into which this method will write. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Asynchronously creates a from a . + + An positioned at the token to read into this . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains + the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Asynchronously creates a from a . + + An positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains + the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Asynchronously creates a from a . + + A positioned at the token to read into this . + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Asynchronously creates a from a . + + A positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + The token to monitor for cancellation requests. The default value is . + + A that represents the asynchronous creation. The + property returns a that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Gets a comparer that can compare two tokens for value equality. + + A that can compare two nodes for value equality. + + + + Gets or sets the parent. + + The parent. + + + + Gets the root of this . + + The root of this . + + + + Gets the node type for this . + + The type. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Compares the values of two tokens, including the values of all descendant tokens. + + The first to compare. + The second to compare. + true if the tokens are equal; otherwise false. + + + + Gets the next sibling token of this node. + + The that contains the next sibling token. + + + + Gets the previous sibling token of this node. + + The that contains the previous sibling token. + + + + Gets the path of the JSON token. + + + + + Adds the specified content immediately after this token. + + A content object that contains simple content or a collection of content objects to be added after this token. + + + + Adds the specified content immediately before this token. + + A content object that contains simple content or a collection of content objects to be added before this token. + + + + Returns a collection of the ancestor tokens of this token. + + A collection of the ancestor tokens of this token. + + + + Returns a collection of tokens that contain this token, and the ancestors of this token. + + A collection of tokens that contain this token, and the ancestors of this token. + + + + Returns a collection of the sibling tokens after this token, in document order. + + A collection of the sibling tokens after this tokens, in document order. + + + + Returns a collection of the sibling tokens before this token, in document order. + + A collection of the sibling tokens before this token, in document order. + + + + Gets the with the specified key. + + The with the specified key. + + + + Gets the with the specified key converted to the specified type. + + The type to convert the token to. + The token key. + The converted token value. + + + + Get the first child token of this token. + + A containing the first child token of the . + + + + Get the last child token of this token. + + A containing the last child token of the . + + + + Returns a collection of the child tokens of this token, in document order. + + An of containing the child tokens of this , in document order. + + + + Returns a collection of the child tokens of this token, in document order, filtered by the specified type. + + The type to filter the child tokens on. + A containing the child tokens of this , in document order. + + + + Returns a collection of the child values of this token, in document order. + + The type to convert the values to. + A containing the child values of this , in document order. + + + + Removes this token from its parent. + + + + + Replaces this token with the specified token. + + The value. + + + + Writes this token to a . + + A into which this method will write. + A collection of which will be used when writing the token. + + + + Returns the indented JSON for this token. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + The indented JSON for this token. + + + + + Returns the JSON for this token using the given formatting and converters. + + Indicates how the output should be formatted. + A collection of s which will be used when writing the token. + The JSON for this token using the given formatting and converters. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to []. + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to of . + + The value. + The result of the conversion. + + + + Performs an explicit conversion from to . + + The value. + The result of the conversion. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from [] to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from to . + + The value to create a from. + The initialized with the specified value. + + + + Performs an implicit conversion from of to . + + The value to create a from. + The initialized with the specified value. + + + + Creates a for this token. + + A that can be used to read this token and its descendants. + + + + Creates a from an object. + + The object that will be used to create . + A with the value of the specified object. + + + + Creates a from an object using the specified . + + The object that will be used to create . + The that will be used when reading the object. + A with the value of the specified object. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the . + + The object type that the token will be deserialized to. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates an instance of the specified .NET type from the using the specified . + + The object type that the token will be deserialized to. + The that will be used when creating the object. + The new object created from the JSON value. + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + An positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Load a from a string that contains JSON. + + A that contains JSON. + A populated from the string that contains JSON. + + + + Load a from a string that contains JSON. + + A that contains JSON. + The used to load the JSON. + If this is null, default load settings will be used. + A populated from the string that contains JSON. + + + + Creates a from a . + + A positioned at the token to read into this . + The used to load the JSON. + If this is null, default load settings will be used. + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Creates a from a . + + A positioned at the token to read into this . + + A that contains the token and its descendant tokens + that were read from the reader. The runtime type of the token is determined + by the token type of the first token encountered in the reader. + + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A , or null. + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + A . + + + + Selects a using a JSONPath expression. Selects the token that matches the object path. + + + A that contains a JSONPath expression. + + The used to select tokens. + A . + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + A flag to indicate whether an error should be thrown if no tokens are found when evaluating part of the expression. + An of that contains the selected elements. + + + + Selects a collection of elements using a JSONPath expression. + + + A that contains a JSONPath expression. + + The used to select tokens. + An of that contains the selected elements. + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Creates a new instance of the . All child tokens are recursively cloned. + + A new instance of the . + + + + Adds an object to the annotation list of this . + + The annotation to add. + + + + Get the first annotation object of the specified type from this . + + The type of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets the first annotation object of the specified type from this . + + The of the annotation to retrieve. + The first annotation object that matches the specified type, or null if no annotation is of the specified type. + + + + Gets a collection of annotations of the specified type for this . + + The type of the annotations to retrieve. + An that contains the annotations for this . + + + + Gets a collection of annotations of the specified type for this . + + The of the annotations to retrieve. + An of that contains the annotations that match the specified type for this . + + + + Removes the annotations of the specified type from this . + + The type of annotations to remove. + + + + Removes the annotations of the specified type from this . + + The of annotations to remove. + + + + Compares tokens to determine whether they are equal. + + + + + Determines whether the specified objects are equal. + + The first object of type to compare. + The second object of type to compare. + + true if the specified objects are equal; otherwise, false. + + + + + Returns a hash code for the specified object. + + The for which a hash code is to be returned. + A hash code for the specified object. + The type of is a reference type and is null. + + + + Represents a reader that provides fast, non-cached, forward-only access to serialized JSON data. + + + + + Gets the at the reader's current position. + + + + + Initializes a new instance of the class. + + The token to read from. + + + + Initializes a new instance of the class. + + The token to read from. + The initial path of the token. It is prepended to the returned . + + + + Reads the next JSON token from the underlying . + + + true if the next token was read successfully; false if there are no more tokens to read. + + + + + Gets the path of the current JSON token. + + + + + Specifies the type of token. + + + + + No token type has been set. + + + + + A JSON object. + + + + + A JSON array. + + + + + A JSON constructor. + + + + + A JSON object property. + + + + + A comment. + + + + + An integer value. + + + + + A float value. + + + + + A string value. + + + + + A boolean value. + + + + + A null value. + + + + + An undefined value. + + + + + A date value. + + + + + A raw JSON value. + + + + + A collection of bytes value. + + + + + A Guid value. + + + + + A Uri value. + + + + + A TimeSpan value. + + + + + Represents a writer that provides a fast, non-cached, forward-only way of generating JSON data. + + + + + Gets the at the writer's current position. + + + + + Gets the token being written. + + The token being written. + + + + Initializes a new instance of the class writing to the given . + + The container being written to. + + + + Initializes a new instance of the class. + + + + + Flushes whatever is in the buffer to the underlying . + + + + + Closes this writer. + If is set to true, the JSON is auto-completed. + + + Setting to true has no additional effect, since the underlying is a type that cannot be closed. + + + + + Writes the beginning of a JSON object. + + + + + Writes the beginning of a JSON array. + + + + + Writes the start of a constructor with the given name. + + The name of the constructor. + + + + Writes the end. + + The token. + + + + Writes the property name of a name/value pair on a JSON object. + + The name of the property. + + + + Writes a value. + An error will be raised if the value cannot be written as a single JSON token. + + The value to write. + + + + Writes a null value. + + + + + Writes an undefined value. + + + + + Writes raw JSON. + + The raw JSON to write. + + + + Writes a comment /*...*/ containing the specified text. + + Text to place inside the comment. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a [] value. + + The [] value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Writes a value. + + The value to write. + + + + Represents a value in JSON (string, integer, date, etc). + + + + + Writes this token to a asynchronously. + + A into which this method will write. + The token to monitor for cancellation requests. + A collection of which will be used when writing the token. + A that represents the asynchronous write operation. + + + + Initializes a new instance of the class from another object. + + A object to copy from. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Initializes a new instance of the class with the given value. + + The value. + + + + Gets a value indicating whether this token has child tokens. + + + true if this token has child values; otherwise, false. + + + + + Creates a comment with the given value. + + The value. + A comment with the given value. + + + + Creates a string with the given value. + + The value. + A string with the given value. + + + + Creates a null value. + + A null value. + + + + Creates a undefined value. + + A undefined value. + + + + Gets the node type for this . + + The type. + + + + Gets or sets the underlying token value. + + The underlying token value. + + + + Writes this token to a . + + A into which this method will write. + A collection of s which will be used when writing the token. + + + + Indicates whether the current object is equal to another object of the same type. + + + true if the current object is equal to the parameter; otherwise, false. + + An object to compare with this object. + + + + Determines whether the specified is equal to the current . + + The to compare with the current . + + true if the specified is equal to the current ; otherwise, false. + + + + + Serves as a hash function for a particular type. + + + A hash code for the current . + + + + + Returns a that represents this instance. + + + ToString() returns a non-JSON string value for tokens with a type of . + If you want the JSON for all token types then you should use . + + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format provider. + + A that represents this instance. + + + + + Returns a that represents this instance. + + The format. + The format provider. + + A that represents this instance. + + + + + Returns the responsible for binding operations performed on this object. + + The expression tree representation of the runtime value. + + The to bind this object. + + + + + Compares the current instance with another object of the same type and returns an integer that indicates whether the current instance precedes, follows, or occurs in the same position in the sort order as the other object. + + An object to compare with this instance. + + A 32-bit signed integer that indicates the relative order of the objects being compared. The return value has these meanings: + Value + Meaning + Less than zero + This instance is less than . + Zero + This instance is equal to . + Greater than zero + This instance is greater than . + + + is not of the same type as this instance. + + + + + Specifies how line information is handled when loading JSON. + + + + + Ignore line information. + + + + + Load line information. + + + + + Specifies how JSON arrays are merged together. + + + + Concatenate arrays. + + + Union arrays, skipping items that already exist. + + + Replace all array items. + + + Merge array items together, matched by index. + + + + Specifies how null value properties are merged. + + + + + The content's null value properties will be ignored during merging. + + + + + The content's null value properties will be merged. + + + + + Specifies the member serialization options for the . + + + + + All public members are serialized by default. Members can be excluded using or . + This is the default member serialization mode. + + + + + Only members marked with or are serialized. + This member serialization mode can also be set by marking the class with . + + + + + All public and private fields are serialized. Members can be excluded using or . + This member serialization mode can also be set by marking the class with + and setting IgnoreSerializableAttribute on to false. + + + + + Specifies metadata property handling options for the . + + + + + Read metadata properties located at the start of a JSON object. + + + + + Read metadata properties located anywhere in a JSON object. Note that this setting will impact performance. + + + + + Do not try to read metadata properties. + + + + + Specifies missing member handling options for the . + + + + + Ignore a missing member and do not attempt to deserialize it. + + + + + Throw a when a missing member is encountered during deserialization. + + + + + Specifies null value handling options for the . + + + + + + + + + Include null values when serializing and deserializing objects. + + + + + Ignore null values when serializing and deserializing objects. + + + + + Specifies how object creation is handled by the . + + + + + Reuse existing objects, create new objects when needed. + + + + + Only reuse existing objects. + + + + + Always create new objects. + + + + + Specifies reference handling options for the . + Note that references cannot be preserved when a value is set via a non-default constructor such as types that implement . + + + + + + + + Do not preserve references when serializing types. + + + + + Preserve references when serializing into a JSON object structure. + + + + + Preserve references when serializing into a JSON array structure. + + + + + Preserve references when serializing. + + + + + Specifies reference loop handling options for the . + + + + + Throw a when a loop is encountered. + + + + + Ignore loop references and do not serialize. + + + + + Serialize loop references. + + + + + Indicating whether a property is required. + + + + + The property is not required. The default state. + + + + + The property must be defined in JSON but can be a null value. + + + + + The property must be defined in JSON and cannot be a null value. + + + + + The property is not required but it cannot be a null value. + + + + + + Contains the JSON schema extension methods. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + true if the specified is valid; otherwise, false. + + + + + + Determines whether the is valid. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + When this method returns, contains any error messages generated while validating. + + true if the specified is valid; otherwise, false. + + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + + + + + Validates the specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + The source to test. + The schema to test with. + The validation event handler. + + + + + An in-memory representation of a JSON Schema. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the id. + + + + + Gets or sets the title. + + + + + Gets or sets whether the object is required. + + + + + Gets or sets whether the object is read-only. + + + + + Gets or sets whether the object is visible to users. + + + + + Gets or sets whether the object is transient. + + + + + Gets or sets the description of the object. + + + + + Gets or sets the types of values allowed by the object. + + The type. + + + + Gets or sets the pattern. + + The pattern. + + + + Gets or sets the minimum length. + + The minimum length. + + + + Gets or sets the maximum length. + + The maximum length. + + + + Gets or sets a number that the value should be divisible by. + + A number that the value should be divisible by. + + + + Gets or sets the minimum. + + The minimum. + + + + Gets or sets the maximum. + + The maximum. + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the minimum attribute (). + + A flag indicating whether the value can not equal the number defined by the minimum attribute (). + + + + Gets or sets a flag indicating whether the value can not equal the number defined by the maximum attribute (). + + A flag indicating whether the value can not equal the number defined by the maximum attribute (). + + + + Gets or sets the minimum number of items. + + The minimum number of items. + + + + Gets or sets the maximum number of items. + + The maximum number of items. + + + + Gets or sets the of items. + + The of items. + + + + Gets or sets a value indicating whether items in an array are validated using the instance at their array position from . + + + true if items are validated using their array position; otherwise, false. + + + + + Gets or sets the of additional items. + + The of additional items. + + + + Gets or sets a value indicating whether additional items are allowed. + + + true if additional items are allowed; otherwise, false. + + + + + Gets or sets whether the array items must be unique. + + + + + Gets or sets the of properties. + + The of properties. + + + + Gets or sets the of additional properties. + + The of additional properties. + + + + Gets or sets the pattern properties. + + The pattern properties. + + + + Gets or sets a value indicating whether additional properties are allowed. + + + true if additional properties are allowed; otherwise, false. + + + + + Gets or sets the required property if this property is present. + + The required property if this property is present. + + + + Gets or sets the a collection of valid enum values allowed. + + A collection of valid enum values allowed. + + + + Gets or sets disallowed types. + + The disallowed types. + + + + Gets or sets the default value. + + The default value. + + + + Gets or sets the collection of that this schema extends. + + The collection of that this schema extends. + + + + Gets or sets the format. + + The format. + + + + Initializes a new instance of the class. + + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The object representing the JSON Schema. + + + + Reads a from the specified . + + The containing the JSON Schema to read. + The to use when resolving schema references. + The object representing the JSON Schema. + + + + Load a from a string that contains JSON Schema. + + A that contains JSON Schema. + A populated from the string that contains JSON Schema. + + + + Load a from a string that contains JSON Schema using the specified . + + A that contains JSON Schema. + The resolver. + A populated from the string that contains JSON Schema. + + + + Writes this schema to a . + + A into which this method will write. + + + + Writes this schema to a using the specified . + + A into which this method will write. + The resolver used. + + + + Returns a that represents the current . + + + A that represents the current . + + + + + + Returns detailed information about the schema exception. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the line number indicating where the error occurred. + + The line number indicating where the error occurred. + + + + Gets the line position indicating where the error occurred. + + The line position indicating where the error occurred. + + + + Gets the path to the JSON where the error occurred. + + The path to the JSON where the error occurred. + + + + Initializes a new instance of the class. + + + + + Initializes a new instance of the class + with a specified error message. + + The error message that explains the reason for the exception. + + + + Initializes a new instance of the class + with a specified error message and a reference to the inner exception that is the cause of this exception. + + The error message that explains the reason for the exception. + The exception that is the cause of the current exception, or null if no inner exception is specified. + + + + Initializes a new instance of the class. + + The that holds the serialized object data about the exception being thrown. + The that contains contextual information about the source or destination. + The parameter is null. + The class name is null or is zero (0). + + + + + Generates a from a specified . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets how undefined schemas are handled by the serializer. + + + + + Gets or sets the contract resolver. + + The contract resolver. + + + + Generate a from the specified type. + + The type to generate a from. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + Generate a from the specified type. + + The type to generate a from. + The used to resolve schema references. + Specify whether the generated root will be nullable. + A generated from the specified type. + + + + + Resolves from an id. + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets or sets the loaded schemas. + + The loaded schemas. + + + + Initializes a new instance of the class. + + + + + Gets a for the specified reference. + + The id. + A for the specified reference. + + + + + The value types allowed by the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + No type specified. + + + + + String type. + + + + + Float type. + + + + + Integer type. + + + + + Boolean type. + + + + + Object type. + + + + + Array type. + + + + + Null type. + + + + + Any type. + + + + + + Specifies undefined schema Id handling options for the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Do not infer a schema Id. + + + + + Use the .NET type name as the schema Id. + + + + + Use the assembly qualified .NET type name as the schema Id. + + + + + + Returns detailed information related to the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + Gets the associated with the validation error. + + The JsonSchemaException associated with the validation error. + + + + Gets the path of the JSON location where the validation error occurred. + + The path of the JSON location where the validation error occurred. + + + + Gets the text description corresponding to the validation error. + + The text description. + + + + + Represents the callback method that will handle JSON schema validation events and the . + + + JSON Schema validation has been moved to its own package. See https://www.newtonsoft.com/jsonschema for more details. + + + + + + A camel case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Resolves member mappings for a type, camel casing property names. + + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used by to resolve a for a given . + + + + + Gets a value indicating whether members are being get and set using dynamic code generation. + This value is determined by the runtime permissions available. + + + true if using dynamic code generation; otherwise, false. + + + + + Gets or sets the default members search flags. + + The default members search flags. + + + + Gets or sets a value indicating whether compiler generated members should be serialized. + + + true if serialized compiler generated members; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore the interface when serializing and deserializing types. + + + true if the interface will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore the attribute when serializing and deserializing types. + + + true if the attribute will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore IsSpecified members when serializing and deserializing types. + + + true if the IsSpecified members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets a value indicating whether to ignore ShouldSerialize members when serializing and deserializing types. + + + true if the ShouldSerialize members will be ignored when serializing and deserializing types; otherwise, false. + + + + + Gets or sets the naming strategy used to resolve how property names and dictionary keys are serialized. + + The naming strategy used to resolve how property names and dictionary keys are serialized. + + + + Initializes a new instance of the class. + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Gets the serializable members for the type. + + The type to get serializable members for. + The serializable members for the type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates the constructor parameters. + + The constructor to create properties for. + The type's member properties. + Properties for the given . + + + + Creates a for the given . + + The matching member property. + The constructor parameter. + A created for the given . + + + + Resolves the default for the contract. + + Type of the object. + The contract's default . + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Creates a for the given type. + + Type of the object. + A for the given type. + + + + Determines which contract type is created for the given type. + + Type of the object. + A for the given type. + + + + Creates properties for the given . + + The type to create properties for. + /// The member serialization mode for the type. + Properties for the given . + + + + Creates the used by the serializer to get and set values from a member. + + The member. + The used by the serializer to get and set values from a member. + + + + Creates a for the given . + + The member's parent . + The member to create a for. + A created for the given . + + + + Resolves the name of the property. + + Name of the property. + Resolved name of the property. + + + + Resolves the name of the extension data. By default no changes are made to extension data names. + + Name of the extension data. + Resolved name of the extension data. + + + + Resolves the key of the dictionary. By default is used to resolve dictionary keys. + + Key of the dictionary. + Resolved key of the dictionary. + + + + Gets the resolved name of the property. + + Name of the property. + Name of the property. + + + + The default naming strategy. Property names and dictionary keys are unchanged. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + The default serialization binder used when resolving and loading classes from type names. + + + + + Initializes a new instance of the class. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + The type of the object the formatter creates a new instance of. + + + + + When overridden in a derived class, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Represents a trace writer that writes to the application's instances. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + + The that will be used to filter the trace messages passed to the writer. + + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Provides information surrounding an error. + + + + + Gets the error. + + The error. + + + + Gets the original object that caused the error. + + The original object that caused the error. + + + + Gets the member that caused the error. + + The member that caused the error. + + + + Gets the path of the JSON location where the error occurred. + + The path of the JSON location where the error occurred. + + + + Gets or sets a value indicating whether this is handled. + + true if handled; otherwise, false. + + + + Provides data for the Error event. + + + + + Gets the current object the error event is being raised against. + + The current object the error event is being raised against. + + + + Gets the error context. + + The error context. + + + + Initializes a new instance of the class. + + The current object. + The error context. + + + + Get and set values for a using dynamic methods. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Provides methods to get attributes. + + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Used by to resolve a for a given . + + + + + + + + + Resolves the contract for a given type. + + The type to resolve a contract for. + The contract for a given type. + + + + Used to resolve references when serializing and deserializing JSON by the . + + + + + Resolves a reference to its object. + + The serialization context. + The reference to resolve. + The object that was resolved from the reference. + + + + Gets the reference for the specified object. + + The serialization context. + The object to get a reference for. + The reference to the object. + + + + Determines whether the specified object is referenced. + + The serialization context. + The object to test for a reference. + + true if the specified object is referenced; otherwise, false. + + + + + Adds a reference to the specified object. + + The serialization context. + The reference. + The object to reference. + + + + Allows users to control class loading and mandate what class to load. + + + + + When implemented, controls the binding of a serialized object to a type. + + Specifies the name of the serialized object. + Specifies the name of the serialized object + The type of the object the formatter creates a new instance of. + + + + When implemented, controls the binding of a serialized object to a type. + + The type of the object the formatter creates a new instance of. + Specifies the name of the serialized object. + Specifies the name of the serialized object. + + + + Represents a trace writer. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + The that will be used to filter the trace messages passed to the writer. + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Provides methods to get and set values. + + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + Contract details for a used by the . + + + + + Gets the of the collection items. + + The of the collection items. + + + + Gets a value indicating whether the collection type is a multidimensional array. + + true if the collection type is a multidimensional array; otherwise, false. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the collection values. + + true if the creator has a parameter with the collection values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the default collection items . + + The converter. + + + + Gets or sets a value indicating whether the collection items preserve object references. + + true if collection items preserve object references; otherwise, false. + + + + Gets or sets the collection item reference loop handling. + + The reference loop handling. + + + + Gets or sets the collection item type name handling. + + The type name handling. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Handles serialization callback events. + + The object that raised the callback event. + The streaming context. + + + + Handles serialization error callback events. + + The object that raised the callback event. + The streaming context. + The error context. + + + + Sets extension data for an object during deserialization. + + The object to set extension data on. + The extension data key. + The extension data value. + + + + Gets extension data for an object during serialization. + + The object to set extension data on. + + + + Contract details for a used by the . + + + + + Gets the underlying type for the contract. + + The underlying type for the contract. + + + + Gets or sets the type created during deserialization. + + The type created during deserialization. + + + + Gets or sets whether this type contract is serialized as a reference. + + Whether this type contract is serialized as a reference. + + + + Gets or sets the default for this contract. + + The converter. + + + + Gets the internally resolved for the contract's type. + This converter is used as a fallback converter when no other converter is resolved. + Setting will always override this converter. + + + + + Gets or sets all methods called immediately after deserialization of the object. + + The methods called immediately after deserialization of the object. + + + + Gets or sets all methods called during deserialization of the object. + + The methods called during deserialization of the object. + + + + Gets or sets all methods called after serialization of the object graph. + + The methods called after serialization of the object graph. + + + + Gets or sets all methods called before serialization of the object. + + The methods called before serialization of the object. + + + + Gets or sets all method called when an error is thrown during the serialization of the object. + + The methods called when an error is thrown during the serialization of the object. + + + + Gets or sets the default creator method used to create the object. + + The default creator method used to create the object. + + + + Gets or sets a value indicating whether the default creator is non-public. + + true if the default object creator is non-public; otherwise, false. + + + + Contract details for a used by the . + + + + + Gets or sets the dictionary key resolver. + + The dictionary key resolver. + + + + Gets the of the dictionary keys. + + The of the dictionary keys. + + + + Gets the of the dictionary values. + + The of the dictionary values. + + + + Gets or sets the function used to create the object. When set this function will override . + + The function used to create the object. + + + + Gets a value indicating whether the creator has a parameter with the dictionary values. + + true if the creator has a parameter with the dictionary values; otherwise, false. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets the object's properties. + + The object's properties. + + + + Gets or sets the property name resolver. + + The property name resolver. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object constructor. + + The object constructor. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Gets or sets the object member serialization. + + The member object serialization. + + + + Gets or sets the missing member handling used when deserializing this object. + + The missing member handling. + + + + Gets or sets a value that indicates whether the object's properties are required. + + + A value indicating whether the object's properties are required. + + + + + Gets or sets how the object's properties with null values are handled during serialization and deserialization. + + How the object's properties with null values are handled during serialization and deserialization. + + + + Gets the object's properties. + + The object's properties. + + + + Gets a collection of instances that define the parameters used with . + + + + + Gets or sets the function used to create the object. When set this function will override . + This function is called with a collection of arguments which are defined by the collection. + + The function used to create the object. + + + + Gets or sets the extension data setter. + + + + + Gets or sets the extension data getter. + + + + + Gets or sets the extension data value type. + + + + + Gets or sets the extension data name resolver. + + The extension data name resolver. + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Maps a JSON property to a .NET member or constructor parameter. + + + + + Gets or sets the name of the property. + + The name of the property. + + + + Gets or sets the type that declared this property. + + The type that declared this property. + + + + Gets or sets the order of serialization of a member. + + The numeric order of serialization. + + + + Gets or sets the name of the underlying member or parameter. + + The name of the underlying member or parameter. + + + + Gets the that will get and set the during serialization. + + The that will get and set the during serialization. + + + + Gets or sets the for this property. + + The for this property. + + + + Gets or sets the type of the property. + + The type of the property. + + + + Gets or sets the for the property. + If set this converter takes precedence over the contract converter for the property type. + + The converter. + + + + Gets or sets the member converter. + + The member converter. + + + + Gets or sets a value indicating whether this is ignored. + + true if ignored; otherwise, false. + + + + Gets or sets a value indicating whether this is readable. + + true if readable; otherwise, false. + + + + Gets or sets a value indicating whether this is writable. + + true if writable; otherwise, false. + + + + Gets or sets a value indicating whether this has a member attribute. + + true if has a member attribute; otherwise, false. + + + + Gets the default value. + + The default value. + + + + Gets or sets a value indicating whether this is required. + + A value indicating whether this is required. + + + + Gets a value indicating whether has a value specified. + + + + + Gets or sets a value indicating whether this property preserves object references. + + + true if this instance is reference; otherwise, false. + + + + + Gets or sets the property null value handling. + + The null value handling. + + + + Gets or sets the property default value handling. + + The default value handling. + + + + Gets or sets the property reference loop handling. + + The reference loop handling. + + + + Gets or sets the property object creation handling. + + The object creation handling. + + + + Gets or sets or sets the type name handling. + + The type name handling. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets a predicate used to determine whether the property should be deserialized. + + A predicate used to determine whether the property should be deserialized. + + + + Gets or sets a predicate used to determine whether the property should be serialized. + + A predicate used to determine whether the property should be serialized. + + + + Gets or sets an action used to set whether the property has been deserialized. + + An action used to set whether the property has been deserialized. + + + + Returns a that represents this instance. + + + A that represents this instance. + + + + + Gets or sets the converter used when serializing the property's collection items. + + The collection's items converter. + + + + Gets or sets whether this property's collection items are serialized as a reference. + + Whether this property's collection items are serialized as a reference. + + + + Gets or sets the type name handling used when serializing the property's collection items. + + The collection's items type name handling. + + + + Gets or sets the reference loop handling used when serializing the property's collection items. + + The collection's items reference loop handling. + + + + A collection of objects. + + + + + Initializes a new instance of the class. + + The type. + + + + When implemented in a derived class, extracts the key from the specified element. + + The element from which to extract the key. + The key for the specified element. + + + + Adds a object. + + The property to add to the collection. + + + + Gets the closest matching object. + First attempts to get an exact case match of and then + a case insensitive match. + + Name of the property. + A matching property if found. + + + + Gets a property by property name. + + The name of the property to get. + Type property name string comparison. + A matching property if found. + + + + Contract details for a used by the . + + + + + Initializes a new instance of the class. + + The underlying type for the contract. + + + + Lookup and create an instance of the type described by the argument. + + The type to create. + Optional arguments to pass to an initializing constructor of the JsonConverter. + If null, the default constructor is used. + + + + A kebab case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Represents a trace writer that writes to memory. When the trace message limit is + reached then old trace messages will be removed as new messages are added. + + + + + Gets the that will be used to filter the trace messages passed to the writer. + For example a filter level of will exclude messages and include , + and messages. + + + The that will be used to filter the trace messages passed to the writer. + + + + + Initializes a new instance of the class. + + + + + Writes the specified trace level, message and optional exception. + + The at which to write this trace. + The trace message. + The trace exception. This parameter is optional. + + + + Returns an enumeration of the most recent trace messages. + + An enumeration of the most recent trace messages. + + + + Returns a of the most recent trace messages. + + + A of the most recent trace messages. + + + + + A base class for resolving how property names and dictionary keys are serialized. + + + + + A flag indicating whether dictionary keys should be processed. + Defaults to false. + + + + + A flag indicating whether extension data names should be processed. + Defaults to false. + + + + + A flag indicating whether explicitly specified property names, + e.g. a property name customized with a , should be processed. + Defaults to false. + + + + + Gets the serialized name for a given property name. + + The initial property name. + A flag indicating whether the property has had a name explicitly specified. + The serialized property name. + + + + Gets the serialized name for a given extension data name. + + The initial extension data name. + The serialized extension data name. + + + + Gets the serialized key for a given dictionary key. + + The initial dictionary key. + The serialized dictionary key. + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Hash code calculation + + + + + + Object equality implementation + + + + + + + Compare to another NamingStrategy + + + + + + + Represents a method that constructs an object. + + The object type to create. + + + + When applied to a method, specifies that the method is called when an error occurs serializing an object. + + + + + Provides methods to get attributes from a , , or . + + + + + Initializes a new instance of the class. + + The instance to get attributes for. This parameter should be a , , or . + + + + Returns a collection of all of the attributes, or an empty collection if there are no attributes. + + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Returns a collection of attributes, identified by type, or an empty collection if there are no attributes. + + The type of the attributes. + When true, look up the hierarchy chain for the inherited custom attribute. + A collection of s, or an empty collection. + + + + Get and set values for a using reflection. + + + + + Initializes a new instance of the class. + + The member info. + + + + Sets the value. + + The target to set the value on. + The value to set on the target. + + + + Gets the value. + + The target to get the value from. + The value. + + + + A snake case naming strategy. + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + + + Initializes a new instance of the class. + + + A flag indicating whether dictionary keys should be processed. + + + A flag indicating whether explicitly specified property names should be processed, + e.g. a property name customized with a . + + + A flag indicating whether extension data names should be processed. + + + + + Initializes a new instance of the class. + + + + + Resolves the specified property name. + + The property name to resolve. + The resolved property name. + + + + Specifies how strings are escaped when writing JSON text. + + + + + Only control characters (e.g. newline) are escaped. + + + + + All non-ASCII and control characters (e.g. newline) are escaped. + + + + + HTML (<, >, &, ', ") and control characters (e.g. newline) are escaped. + + + + + Indicates the method that will be used during deserialization for locating and loading assemblies. + + + + + In simple mode, the assembly used during deserialization need not match exactly the assembly used during serialization. Specifically, the version numbers need not match as the LoadWithPartialName method of the class is used to load the assembly. + + + + + In full mode, the assembly used during deserialization must match exactly the assembly used during serialization. The Load method of the class is used to load the assembly. + + + + + Specifies type name handling options for the . + + + should be used with caution when your application deserializes JSON from an external source. + Incoming types should be validated with a custom + when deserializing with a value other than . + + + + + Do not include the .NET type name when serializing types. + + + + + Include the .NET type name when serializing into a JSON object structure. + + + + + Include the .NET type name when serializing into a JSON array structure. + + + + + Always include the .NET type name when serializing. + + + + + Include the .NET type name when the type of the object being serialized is not the same as its declared type. + Note that this doesn't include the root serialized object by default. To include the root object's type name in JSON + you must specify a root type object with + or . + + + + + Determines whether the collection is null or empty. + + The collection. + + true if the collection is null or empty; otherwise, false. + + + + + Adds the elements of the specified collection to the specified generic . + + The list to add to. + The collection of elements to add. + + + + Converts the value to the specified type. If the value is unable to be converted, the + value is checked whether it assignable to the specified type. + + The value to convert. + The culture to use when converting. + The type to convert or cast the value to. + + The converted type. If conversion was unsuccessful, the initial value + is returned if assignable to the target type. + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic that returns a result + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic, but uses one of the arguments for + the result. + + + + + Helper method for generating a MetaObject which calls a + specific method on Dynamic, but uses one of the arguments for + the result. + + + + + Returns a Restrictions object which includes our current restrictions merged + with a restriction limiting our type + + + + + Helper class for serializing immutable collections. + Note that this is used by all builds, even those that don't support immutable collections, in case the DLL is GACed + https://github.com/JamesNK/Newtonsoft.Json/issues/652 + + + + + Gets the type of the typed collection's items. + + The type. + The type of the typed collection's items. + + + + Gets the member's underlying type. + + The member. + The underlying type of the member. + + + + Determines whether the property is an indexed property. + + The property. + + true if the property is an indexed property; otherwise, false. + + + + + Gets the member's value on the object. + + The member. + The target object. + The member's value on the object. + + + + Sets the member's value on the target object. + + The member. + The target. + The value. + + + + Determines whether the specified MemberInfo can be read. + + The MemberInfo to determine whether can be read. + /// if set to true then allow the member to be gotten non-publicly. + + true if the specified MemberInfo can be read; otherwise, false. + + + + + Determines whether the specified MemberInfo can be set. + + The MemberInfo to determine whether can be set. + if set to true then allow the member to be set non-publicly. + if set to true then allow the member to be set if read-only. + + true if the specified MemberInfo can be set; otherwise, false. + + + + + Builds a string. Unlike this class lets you reuse its internal buffer. + + + + + Determines whether the string is all white space. Empty string will return false. + + The string to test whether it is all white space. + + true if the string is all white space; otherwise, false. + + + + + Specifies the state of the . + + + + + An exception has been thrown, which has left the in an invalid state. + You may call the method to put the in the Closed state. + Any other method calls result in an being thrown. + + + + + The method has been called. + + + + + An object is being written. + + + + + An array is being written. + + + + + A constructor is being written. + + + + + A property is being written. + + + + + A write method has not been called. + + + + Specifies that an output will not be null even if the corresponding type allows it. + + + Specifies that when a method returns , the parameter will not be null even if the corresponding type allows it. + + + Initializes the attribute with the specified return value condition. + + The return value condition. If the method returns this value, the associated parameter will not be null. + + + + Gets the return value condition. + + + Specifies that an output may be null even if the corresponding type disallows it. + + + Specifies that null is allowed as an input even if the corresponding type disallows it. + + + + Specifies that the method will not return if the associated Boolean parameter is passed the specified value. + + + + + Initializes a new instance of the class. + + + The condition parameter value. Code after the method will be considered unreachable by diagnostics if the argument to + the associated parameter matches this value. + + + + Gets the condition parameter value. + + + diff --git a/Packages/Newtonsoft.Json.13.0.1/packageIcon.png b/Packages/Newtonsoft.Json.13.0.1/packageIcon.png new file mode 100644 index 0000000..10c06a5 Binary files /dev/null and b/Packages/Newtonsoft.Json.13.0.1/packageIcon.png differ diff --git a/Packages/NtApiDotNet.1.1.33/.signature.p7s b/Packages/NtApiDotNet.1.1.33/.signature.p7s new file mode 100644 index 0000000..958a6ba Binary files /dev/null and b/Packages/NtApiDotNet.1.1.33/.signature.p7s differ diff --git a/Packages/NtApiDotNet.1.1.33/NtApiDotNet.1.1.33.nupkg b/Packages/NtApiDotNet.1.1.33/NtApiDotNet.1.1.33.nupkg new file mode 100644 index 0000000..9fbe43a Binary files /dev/null and b/Packages/NtApiDotNet.1.1.33/NtApiDotNet.1.1.33.nupkg differ diff --git a/Packages/NtApiDotNet.1.1.33/lib/net461/NtApiDotNet.dll b/Packages/NtApiDotNet.1.1.33/lib/net461/NtApiDotNet.dll new file mode 100644 index 0000000..ba29045 Binary files /dev/null and b/Packages/NtApiDotNet.1.1.33/lib/net461/NtApiDotNet.dll differ diff --git a/Packages/NtApiDotNet.1.1.33/lib/net461/NtApiDotNet.xml b/Packages/NtApiDotNet.1.1.33/lib/net461/NtApiDotNet.xml new file mode 100644 index 0000000..c8ffc9e --- /dev/null +++ b/Packages/NtApiDotNet.1.1.33/lib/net461/NtApiDotNet.xml @@ -0,0 +1,51865 @@ + + + + NtApiDotNet + + + + + Result of an access check with specific access types. + + The access rights type, must be derived from an Enum. + + + + The NT status code from the access check. + + + + + The granted access mask from the check. + + + + + The granted access mapped to generic access mask. + + + + + The required privileges for this access. + + + + + The specific granted access mask from the check. + + + + + The specific granted access mapped to generic access mask. + + + + + Object type associated with the access. + + + + + The level of the object type if used. + + + + + Optional name for the object type. + + + + + When a result from an Audit Access Check indicates whether the + an audit needs to be generated on close. + + + + + Whether the access check was a success. + + + + + Get access check result as a specific access. + + The specific access results. + + + + Get access check result as a specific access. + + The specific access. + + + + Result of an access check. + + + + + Result of an access check with generic Enum access types. + + + + + Structure for an NT access mask. + + + + + The access mask's access bits. + + + + + Constructor. + + Access bits to use + + + + Implicit conversion from Int32. + + The access enumeration. + + + + Implicit conversion from UInt32. + + The access enumeration. + + + + Implicit conversion from enumerations. + + The access enumeration. + + + + Convert access mask to a generic access object. + + The generic access mask + + + + Convert access mask to a mandatory label policy + + The mandatory label policy + + + + Convert to a specific access right. + + The specific access right. + The converted value. + + + + Convert to a specific access right. + + The type of enumeration to convert to. + The converted value. + + + + Get whether this access mask is empty (i.e. it's 0) + + + + + Get whether this access mask has no access rights, i.e. not empty. + + + + + Get whether this access mask has generic access rights. + + + + + Get whether this access mask hash type specific access rights. + + + + + Get whether the current access mask is granted specific permissions. + + The access mask to check + True one or more access granted. + + + + Get whether the current access mask is granted all specific permissions. + + The access mask to check + True access all is granted. + + + + Bitwise AND operator. + + Access mask 1 + Access mask 2 + The new access mask. + + + + Bitwise OR operator. + + Access mask 1 + Access mask 2 + The new access mask. + + + + Bitwise AND operator. + + Access mask 1 + Access mask 2 + The new access mask. + + + + Bitwise OR operator. + + Access mask 1 + Access mask 2 + The new access mask. + + + + Equality operator. + + Access mask 1 + Access mask 2 + True if equal. + + + + Inequality operator. + + Access mask 1 + Access mask 2 + True if equal. + + + + Bitwise NOT operator. + + Access mask 1 + The new access mask. + + + + Overridden GetHashCode. + + The hash code. + + + + Overridden Equals. + + The object to compare against. + True if equal. + + + + Get an empty access mask. + + + + + Overridden ToString method. + + The access mask. + + + + ToString method. + + Format code for the access mask. + The formatting string. + + + + ToString method. + + Format code for the access mask. + The format provider. + The formatting string. + + + + Flags representing what generic access the entry maps to. + + + + + Not mapped to any access. + + + + + Mapped to read. + + + + + Mapped to write. + + + + + Mapped to execute. + + + + + Mapped to All. + + + + + A structure to hold an access mask to enum mapping. + + + + + The access mask. + + + + + The value of the access mask entry enumeration. + + + + + The generic access this maps to. + + + + + The optional SDK name. + + + + + Overridden ToString method. + + The string form of the entry. + + + + Class to represent an Access Control Entry (ACE) + + + + + Check if the ACE is an allowed ACE. + + + + + Check if the ACE is a denied ACE. + + + + + Check if the ACE is an Object ACE + + + + + Check if the ACE is a callback ACE + + + + + Check if ACE is a conditional ACE + + + + + Check if ACE is a resource attribute ACE. + + + + + Check if ACE is a mandatory label ACE. + + + + + Check if ACE is a compound ACE. + + + + + Check if ACE is an audit ACE. + + + + + Check if ACE is an access filter ACE. + + + + + Check if ACE is a process trust label ACE. + + + + + Check if ACE is a critical ACE. + + + + + Check if ACE is inherit only. + + + + + Check if ACE is inherited by objects. + + + + + Check if ACE is inherited by objects. + + + + + Get ACE type + + + + + Get ACE flags + + + + + Get ACE access mask + + + + + Get ACE Security Identifier + + + + + The type of compound ACE. When serialized always set to Impersonate. + + + + + Get the client SID in a compound ACE. + + + + + Get optional Object Type + + + + + Get optional Inherited Object Type + + + + + Optional application data. + + + + + Get conditional check if a conditional ace. + + + + + Get or set resource attribute. + + + + + Constructor + + ACE type + ACE flags + ACE access mask + ACE sid + + + + Convert ACE to a string + + The ACE as a string + + + + Convert ACE to a string + + An enumeration type to format the access mask + True to try and resolve SID to a name + The ACE as a string + + + + Clone this ACE. + + The cloned ACE. + + + + Get whether the current access mask is granted specific permissions. + + The access mask to check + True one or more access granted. + + + + Get whether the current access mask is granted all specific permissions. + + The access mask to check + True access all is granted. + + + + Get the common name of the object type. + + Specify the domain for the object type. + If true then expand the list of properties. + The common name of the object type, or the GUID as a string. + This function could be quite slow to query the first time. + + + + Get the common name of the object type. + + If true then expand the list of properties. + The common name of the object type, or the GUID as a string. + This will query the local domain, it could be quite slow to query the first time. + + + + Get the common name of the object type. + + The common name of the object type, or the GUID as a string. + This will query the local domain, it could be quite slow to query the first time. + + + + Get the common name of the inherited object type. + + Specify the domain for the object type. + The common name of the object type, or the GUID as a string. + This function could be quite slow to query the first time. + + + + Get the common name of the inherited object type. + + The common name of the object type, or the GUID as a string. + This will query the local domain, it could be quite slow to query the first time. + + + + Convert the ACE to a byte array. + + The ACE as a byte array. + + + + Compare ACE to another object. + + The other object. + True if the other object equals this ACE + + + + Get hash code. + + The hash code + + + + Equality operator + + Left ACE + Right ACE + True if the ACEs are equal + + + + Not Equal operator + + Left ACE + Right ACE + True if the ACEs are not equal + + + + Class to represent an Access Control List (ACL) + + + + + Constructor + + Pointer to a raw ACL in memory + True if the ACL was defaulted + + + + Constructor + + Buffer containing an ACL in memory + True if the ACL was defaulted + + + + Constructor for a NULL ACL + + True if the ACL was defaulted + + + + Constructor for an empty ACL + + + + + Constructor + + List of ACEs to add to ACL + True if the ACL was defaulted + + + + Constructor + + List of ACEs to add to ACL + + + + Constructor. + + An SDDL string to create the DACL from. + The SDDL string should be of the form D:(...) or S:(...), if you specify + both a DACL and a SACL then only the DACL will be used. + + + + Convert the ACL to a byte array + + The ACL as a byte array + + + + Convert the ACL to a safe buffer + + The safe buffer + + + + Add an ace to the ACL + + The ACE to add + + + + Add an access allowed ace to the ACL + + The ACE access mask + The ACE flags + The ACE SID + + + + Add an access allowed ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an access allowed ace to the ACL + + The ACE access mask + The ACE flags + The ACE SID + + + + Add an access allowed ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an access denied ace to the ACL + + The ACE access mask + The ACE flags + The ACE SID + + + + Add an access denied ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an access denied ace to the ACL + + The ACE access mask + The ACE flags + The ACE SID + + + + Add an access denied ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an audit ace to the ACL + + The ACE access mask + The ACE flags + The ACE SID + + + + Add an audit ace to the ACL + + The ACE access mask + The ACE flags + The ACE SID + + + + Add an audit success ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an audit success ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an audit fail ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an audit fail ace to the ACL + + The ACE access mask + The ACE SID + + + + Gets an indication if this ACL is canonical. + + Canonical means that deny ACEs are before allow ACEs. + True to canonicalize a DACL, otherwise a SACL. + True if the ACL is canonical. + + + + Gets an indication if this DACL is canonical. + + Canonical basically means that deny ACEs are before allow ACEs. + True if the ACL is canonical. + + + + Canonicalize the ACL. + + True to canonicalize a DACL, otherwise a SACL. + + + + Canonicalize the ACL (for use on DACLs only). + + The canonical ACL. + + + + Find the first ACE with a specified type. + + The type to find. + True to include inherit only ACEs. + The found ace. Returns null if not found. + + + + Find the first ACE with a specified type. Includes InheritOnly ACEs. + + The type to find. + The found ace. Returns null if not found. + + + + Find the all ACE with a specified type. + + The type to find. + True to include inherit only ACEs. + The found aces. + + + + Find the all ACE with a specified type. Includes InheritOnly ACEs. + + The type to find. + The found aces. + + + + Find the last ACE with a specified type. + + The type to find. + The found ace. Returns null if not found. + + + + Clone the ACL. Also clones all ACEs. + + The cloned ACL. + + + + Get or set whether the ACL was defaulted + + + + + Get or set whether the ACL is NULL (no security) + + + + + Get or set the protected flag. + + + + + Get or set the auto-inherited flag. + + + + + Get or set the auto-inherited required flag. + + + + + Get or set the ACL revision + + + + + Indicates the ACL has at least one conditional ACE. + + + + + Indicates the ACL has at least one object ACE. + + + + + Base class to represent an ALPC message. + + + + + Constructor. + + The port message header. + + + + Constructor. + + + + + Update the header length fields. + + The length of the valid data. + The maximum data length supported by the packet. + + + + Method to handle when ToSafeBuffer is called. + + The message buffer being created. + + + + Method to handle when FromSafeBuffer is called. + + The message buffer to initialize from.. + The ALPC port associated with this message. + + + + Get or set the header. + + + + + The process ID of the sender. + + + + + The thread ID of the sender. + + + + + Get total length of the message. + + + + + Get the allocated data length for the message. + + + + + Get data length of the message. + + + + + Get the message ID. + + + + + Get the callback ID. + + + + + Get the message type. + + + + + Get additional flags on message type. + + + + + Indicates that the message requires a reply (otherwise things can leak). + + + + + Indicates that the message requires a reply (obsolete). + + + + + Get direct status for the message. + + The direct status for the message. Returns STATUS_PENDING if the message is yet to be processed. + + + + Get the maximum size of a message minus the header size. + + + + + Create a safe buffer for this message. + + The safe buffer. + + + + Method to query information for a message. + + The information class. + The port which has processed the message. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + The port which has processed the message. + A default value for the query. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a fixed structure from the object. + + The type of structure to return. + The port which has processed the message. + The information class to query. + A default value for the query. + The result of the query. + Thrown on error. + + + + Query a fixed structure from the object. + + The type of structure to return. + The port which has processed the message. + The information class to query. + The result of the query. + Thrown on error. + + + + An ALPC message which holds a raw set of bytes. + + + + + Constructor. + + Data to initialize the message with. + Maximum length of the message buffer. + Specify a text encoding for the DataString property. + + + + Constructor. + + Data to initialize the message with. + Maximum length of the message buffer. + + + + Constructor. + + Data to initialize the message with. + + + + Constructor. + + Data to initialize the message with. + Specify a text encoding for the DataString property. + + + + Constructor. + + Total allocated length of the message buffer. + + + + Constructor. + + Total allocated length of the message buffer. + Specify a text encoding for the DataString property. + + + + Get or set the message data. + + When you set the data it'll update the DataLength and TotalLength fields. + + + + Get or set the message data as an encoding string. + + When you set the data it'll update the DataLength and TotalLength fields. + + + + Get or set the text encoding in this raw message. + + + + + Method to handle when FromSafeBuffer is called. + + The message buffer to initialize from.. + The ALPC port associated with this message. + + + + Method to handle when ToSafeBuffer is called. + + The message buffer being created. + + + + An ALPC message which holds a specific type with optional trailing data. + + The type representing the data. + + + + Constructor for a receive buffer. + + + + + Constructor for a receive buffer. + + Length of message. This will be rounded up to at least accomodate the header. + + + + Constructor for a send/receive buffer. + + The initial value to set. + Trailing data. + + + + Constructor for a send/receive buffer. + + The initial value to set. + + + + Get or set the type in the buffer. + + + + + Get or set any trailing data after the value. + + + + + Method to handle when FromSafeBuffer is called. + + The message buffer to initialize from.. + The ALPC port associated with this message. + + + + Method to handle when ToSafeBuffer is called. + + The message buffer being created. + + + + Class to represent a set of sending attributes. + + + + + Constructor. + + + + + Constructor. + + List of attributes to send. + + + + Add an attribute object. + + The attribute to add. + + + + Remove an attribute object. + + The attribute flag to remove. + + + + Remove an attribute object. + + The attribute to remove. + + + + Add a list of handles to the send attributes. + + The list of objects. + This method doesn't maintain a reference to the objects. You need to keep them alive elsewhere. + + + + Add a list of handles to the send attributes. + + The list of handles. + + + + Add a list of handles to the send attributes. + + The handle to add. + This method doesn't maintain a reference to the objects. You need to keep them alive elsewhere. + + + + Add a list of handles to the send attributes. + + The handle to add. + + + + Get the allocated attributes. + + + + + Class to represent a set of received attributes. + + + + + Constructor. Allocated space for all known attributes. + + + + + Constructor. + + + + + Get the allocated attributes. + + + + + Get the list of valid attributes. + + + + + Get a list of the valid attributes. + + + + + Get list of passed handles. + + + + + Get the mapped data view. If no view sent this property is invalid. + + + + + Get the security context. If no security context this property is invalid. + + + + + Dispose method. + + + + + Get a typed attribute. + + The type of attribute to get. + The attribute. Returns a default initialized object if not valid. + + + + Get an attribute. + + The attribute flag to get. + The attribute. Returns null if not found. + + + + Convert this set of attributes to a buffer to send. + + The send attributes. + + + + Convert this set of attributes to one which can be used to free on continuation required. + + The attributes to + The send attributes. + + + + Checks if an attribute flag is valid. + + The attribute to test. + True if the attribute is value. + + + + Base class to represent a message attribute. + + + + + The flag for this attribute. + + + + + Constructor. + + The single attribute flag which this represents. + + + + Class representing a security message attribute. + + + + + Constructor. + + + + + Security attribute flags. + + + + + Security quality of service. + + + + + Context handle. + + + + + Create an attribute which with create a handle automatically. + + The security quality of service. + The security message attribute. + + + + Class representing a security message attribute. + + + + + Constructor. + + + + + Token ID of token. + + + + + Authentication ID of token. + + + + + Modified ID of token + + + + + Class representing a security message attribute. + + + + + Constructor. + + + + + Port context. + + + + + Message context. + + + + + Sequence number. + + + + + Message ID. + + + + + Callback ID. + + + + + Class representing a data view message attribute. + + + + + Constructor. + + + + + View flags. + + + + + Handle to section. + + + + + View base. + + + + + View size. + + + + + Handle attribute entry. + + + + + Handle flags. + + + + + The NT object. + + + + + The object type for the handle. + + + + + Desired access for the handle. + + + + + Constructor. + + Handle attribute to initialize from. + + + + Constructor. + + Handle attribute to initialize from. + + + + Constructor. + + Information structure to initialize from. + + + + Constructor. + + + + + Constructor. + + The object to construct the entry from. Will take a copy of the handle. + + + + Class representing a handle message attribute. + + + + + Constructor. + + + + + Constructor. + + List of handle entries. + + + + Constructor. + + The handle entry. + + + + Constructor. + + List of objects to create the handle entries. + This constructor takes copies of the objects. + + + + Constructor. + + A single object to send. + This constructor takes copies of the object. + + + + List of handles in this attribute. + + + + + Class representing a direct message attribute. + + + + + Constructor. + + The event object. + + + + The event object. + + + + + Class representing a work on behalf of message attribute. + + + + + Constructor. + + + + + Thread ID. + + + + + Thread creation time (low). + + + + + Safe buffer to store an allocated set of ALPC atributes. + + + + + Get a pointer to an allocated attribute. Returns NULL if not available. + + The attribute to get. + The pointer to the attribute buffer, IntPtr.Zero if not found. + + + + Get an attribute as a structured type. + + The attribute type. + The attribute. + A buffer which represents the structured type. + Thrown if attribute doesn't exist. + + + + Create a new buffer with allocations for a specified set of attributes. + + The attributes to allocate. + The allocated buffed. + + + + Dispose the safe buffer. + + True if disposing + + + + Detaches the current buffer and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + Get the NULL buffer. + + + + + Class to represent an ALPC port section. + + + + + Handle to the port section. + + + + + Size of the port section. + + + + + The actual section size. + + + + + Create a new section view attribute. + + Specify the flags for the data view attribute. + The section view size. + True to throw on error. + The section view attribute. + + + + Create a new section view attribute. + + True to throw on error. + The section view attribute. + + + + Create a new section view attribute. + + Specify the flags for the data view attribute. + The section view size. + The section view attribute. + + + + Create a new section view attribute. + + The section view attribute. + + + + Dispose of the port section. + + + + + Supported windows verion + + + + + This should always be at the end. + + + + + Attribute to indicate the required version for a function. + Applied if the function needs a version greater than 7. + + + + + The supported version. + + + + + Constructor + + The supported version + + + + Attribute used for managed structures to indicate the start of data. + This is used in situations where the data immediately trail + + + + + Constructor + + The field name which indicates the first address of data. + + + + The field name which indicates the first address of data. + + + + + When allocating this structure always include the field in the total length calculation. + + + + + Class to represent an API set entry. + + + + + Flags for the entry. + + + + + The name of the API set. + + + + + The default host module. + + + + + Hash version of the name. + + + + + List of hosts. + + + + + Get host module for an import module. + + + + + + + Represents a single API set host. + + + + + The imported module this API set host applies to. + + + + + The module which implements this API set. + + + + + Is the host the default host. + + + + + Flags for API set namespace. + + + + + None. + + + + + The API set is sealed. + + + + + The API set is an extension. + + + + + Class to represent an API set namespace. + + + + + Flags for the namespace. + + + + + List of API set entries. + + + + + Get API set namespace from current process. + + + + + Gets an API set based on its name. + + The API set name. + The API set entry. Returns null if not found. + + + + Flags for a boundary descriptor + + + + + None + + + + + Automatically add the AppContainer package SID to the boundary + + + + + Class which represents a private namespace boundary descriptor + + + + + Constructor + + The name of the boundary + Additional flags for the boundary + + + + Constructor + + The name of the boundary + + + + Add a SID to the boundary descriptor. + + This SID is used in an access check when creating or deleting private namespaces. + The SID to add. + + + + Add an integrity level to the boundary descriptor. + + This integrity level is used in an access check when creating or deleting private namespaces. + The integrity level to add. + + + + Add a list of SIDs to the boundary descriptor. + + The SIDs to add. This can include normal and integrity level SIDs + + + + Add a list of SIDs to the boundary descriptor. + + The first SID to add + Additional SIDs + + + + The handle to the boundary descriptor. + + + + + Create a boundary descriptor from a string representation. + + A boundary descriptor string of the form [SID[:SID...]@]NAME where SID is an SDDL format SID. + The new boundary descriptor. + + + + Finalizer + + + + + Dispose + + + + + Some simple utilities to create structure buffers. + + + + + Create a buffer based on a passed type. + + The type to use in the structure buffer. + The value to initialize the buffer with. + Additional byte data after the structure. + Indicates if additional_size includes the structure size or not. + The new structure buffer. + + + + Create a buffer based on a passed type. + + The type to use in the structure buffer. + The value to initialize the buffer with. + The new structure buffer. + + + + Create a buffer based on a passed type. + + The type to use in the structure buffer. + The value to initialize the buffer with. + The new structure buffer. + + + + Create a buffer based on a passed type. + + The type to use in the structure buffer. + The value to initialize the buffer with. + Additional byte data after the structure. + Indicates if additional_size includes the structure size or not. + The new structure buffer. + + + + Create a buffer based on a byte array. + + The byte array for the buffer. + The safe buffer. + + + + Create an buffer from an array. + + The array element type, must be a value type. + The array of elements. + The allocated array buffer. + + + + Read a NUL terminated string for the byte offset. + + The buffer to read from. + The byte offset to read from. + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated byte string for the byte offset. + + The buffer to read from. + The byte offset to read from. + Text encoding for the string. + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated ANSI string for the byte offset. + + The buffer to read from. + The byte offset to read from. + The string read from the buffer without the NUL terminator + + + + Read a char array with length. + + The buffer to read from. + The number of characters to read. + The byte offset to read from. + The chars read from the buffer + + + + Read a Unicode string string with length. + + The buffer to read from. + The number of characters to read. + The byte offset to read from. + The string read from the buffer. + + + + Write char array. + + The buffer to write to. + The byte offset to write to. + The chars to write. + + + + Write unicode string. + + The buffer to write to. + The byte offset to write to. + The string value to write. + + + + Read bytes from buffer. + + The buffer to read from. + The byte offset to read from. + The number of bytes to read. + The byte array. + + + + Write bytes to a buffer. + + The buffer to write to. + The byte offset to write to. + The data to write. + + + + Get a structure buffer at a specific offset. + + The type of structure. + The buffer to map. + The offset into the buffer. + The structure buffer. + The returned buffer is not owned, therefore you need to maintain the original buffer while operating on this buffer. + + + + Creates a view of an existing safe buffer. + + The buffer to create a view on. + The offset from the start of the buffer. + The length of the view. + The buffer view. + Note that the returned buffer doesn't own the memory, therefore the original buffer + must be maintained for the lifetime of this buffer. + + + + Creates a view of an existing safe buffer. + + The buffer to create a view on. + The offset from the start of the buffer. + The length of the view. + True to make the view writable, false for read-only. + The buffer view. + Note that the returned buffer doesn't own the memory, therefore the original buffer + must be maintained for the lifetime of this buffer. + + + + Zero an entire buffer. + + The buffer to zero. + + + + Fill an entire buffer with a specific byte value. + + The buffer to full. + The fill value. + + + + Compare two buffers for equality. + + The left buffer. + The offset into the left buffer. + The right buffer. + The offset into the right buffer. + The length to compare. + True if the buffers are equal. + + + + Compare a buffer and a byte array for equality. + + The buffer. + The offset into the left buffer. + The compare byte array. + True if the buffers are equal. + + + + Find a byte array in a buffer. Returns all instances of the compare array. + + The buffer to find the data in. + Start offset in the buffer. + The comparison byte array. + A list of offsets into the buffer where the compare was found. + + + + Find a byte array in a buffer. Returns all instances of the compare array. + + The buffer to find the data in. + The comparison byte array. + A list of offsets into the buffer where the compare was found. + + + + Class to represent a Security Atttribute. + + + + + The name of the attribute. + + + + + The type of values. + + + + + The attribute flags. + + + + + The list of values. + + + + + The count of values. + + + + + Convert the attribute to a builder to modify it. + + The builder object. + + + + Convert the security attribute to an SDDL string. + + The security attribute as an SDDL string. + + + + Converts the attribute to a Resource Attribute ACE. + + The resource attribute ACE. + + + + Class to create a new user process using the native APIs. + + + + + Path to the executable to start. + + + + + Path to the executable to start which is passed in the process configuration. + + + + + Command line + + + + + Prepared environment block. + + + + + Title of the main window. + + + + + Path to DLLs. + + + + + Current directory for new process + + + + + Desktop information value + + + + + Shell information value + + + + + Runtime data. + + + + + Prohibited image characteristics for new process + + + + + Additional file access for opened executable file. + + + + + Process create flags. + + + + + Thread create flags. + + + + + Initialization flags + + + + + Parent process. + + + + + Restrict new child processes + + + + + Override restrict child process + + + + + Extra process/thread attributes + + + + + Added protected process protection level. + + The type of protected process. + The signer level. + + + + Return on error instead of throwing an exception. + + + + + Whether to terminate the process on dispose. + + + + + Specify a security descriptor for the process. + + + + + Specify a security descriptor for the initial thread. + + + + + Specify the primary token for the new process. + + + + + Access for process handle. + + + + + Access for thread handle. + + + + + Constructor + + + + + For the current process + + The new forked process result + + + + For the current process + + Process create flags. + Thread create flags. + The new forked process result + + + + For the current process + + Process create flags. + Thread create flags. + True to throw on error. + The new forked process result + + + + Start the new process based on the ImagePath parameter. + + The result of the process creation + + + + Start the new process + + The image path to the file to execute + The result of the process creation + + + + Result from a native create process call. + + + + + Handle to the process + + + + + Handle to the initial thread + + + + + Handle to the image file + + + + + Handle to the image section + + + + + Handle to the IFEO key (if it exists) + + + + + Image information + + + + + Client ID of process and thread + + + + + Process ID + + + + + Thread ID + + + + + Create status + + + + + True if create succeeded + + + + + Result of the create information + + + + + Creation state + + + + + Terminate the process + + Exit code for termination + + + + Resume initial thread + + The suspend count + + + + Set to true to terminate process on disposal + + + + + Finalizer + + + + + Dispose + + + + + The base class for a debug event. + + + + + Process ID for the event. + + + + + Thread ID for the event. + + + + + The event code. + + + + + Constructor. + + The current debug event. + The debug port associated with this event. + + + + Continue the debugged process. + + The continue status code. + True to throw on error. + The NT status code. + + + + Continue the debugged process. + + The continue status code. + + + + Continue the debugged process with a success code. + + + + + Dispose the event. + + + + + Debug event for the Create Process event. + + + + + Subsystem key for the process. + + + + + Handle to the process file (if available). + + + + + Base of image file. + + + + + Debug info file offset. + + + + + Debug info file size. + + + + + Subsystem key for the thread. + + + + + Start address of the thread. + + + + + Handle to the process (if available). + + + + + Handle to the thread (if available). + + + + + Dispose the event. + + + + + Debug event for the Create Thread event. + + + + + Subsystem key for the thread. + + + + + Start address of the thread. + + + + + Handle to the thread (if available). + + + + + Dispose the event. + + + + + Debug event for the Exit Thread event. + + + + + Exit status code. + + + + + Debug event for the Exit Process event. + + + + + Exit status code. + + + + + Debug event for load DLL event. + + + + + DLL file handle. + + + + + Base of loaded DLL. + + + + + Debug info offset. + + + + + Debug info size. + + + + + Address of name. + + + + + Dispose the event. + + + + + Debug event for unload DLL event. + + + + + Base of loaded DLL. + + + + + Debug event for exception event. + + + + + Indicates if this is a first chance exception. + + + + + Exception code. + + + + + Exception flags. + + + + + Pointer to next exception in the chain. + + + + + Address of exception. + + + + + Additional parameters for exception. + + + + + Debug event when we don't handle the state. + + + + + The raw debug event. + + + + + Represents a list where the elements can be trivially disposed in one go. + + An IDisposable implementing type + + + + Constructor + + + + + Constructor + + The initial capacity of the list + + + + Constructor + + A collection to initialize the list + + + + Add a resource to the list and return a reference to it. + + The type of resource to add. + The resource object. + The added resource. + + + + Add a resource to the list and return a reference to it. + + The type of resource to add. + The added resource. + + + + Convert this list to an array then clear it to the disposal no longer happens. + + The elements as an array. + After doing this the current list will be cleared. + + + + Detach a detachable reference and add it to the list. + + The type of resource to detach. + The detached resource. + + + + Dispose method + + + + + Implementation of disposable list which just accepts IDisposable objects. + + + + + Constructor + + + + + Constructor + + The initial capacity of the list + + + + Constructor + + A collection to initialize the list + + + + Adds a delegate which will be called when the list is disposed. + + The delegate to call on dispose. + This can be used to add more complex disposable. + + + + Disposable list of safe handles + + + + + Constructor + + + + + Constructor + + The initial capacity of the list + + + + Constructor + + A collection to initialize the list + + + + Move the handle list to a new disposable list. + + The list of handles which have been moved. + After doing this the current list will be cleared. + + + + Flags for an EA entry + + + + + No flags. + + + + + Processor must handle this EA. + + + + + A single EA entry. + + + + + Name of the entry + + + + + Data associated with the entry + + + + + Flags + + + + + Constructor + + The name of the entry + Data associated with the entry + Flags for entry. + + + + Constructor + + The name of the entry + Data associated with the entry + Flags for entry. + + + + Constructor + + The name of the entry + Data associated with the entry + Flags for entry. + + + + Get the EA buffer data as a string. + + The data as a string. + + + + Get the EA buffer data as an Int32. + + The data as an Int32. + + + + Convert entry to a string + + The entry as a string + + + + Class to create an Extended Attributes buffer for NtCreateFile + + + + + Constructor + + + + + Constructor + + List of entries to add. + + + + Constructor from a binary EA buffer + + The EA buffer to parse + + + + Constructor + + Existing buffer to copy. + + + + Add a new EA entry from an old entry. The data will be cloned. + + The entry to add. + + + + Add a new EA entry + + The name of the entry + The associated data, will be cloned + The entry flags. + + + + Add a new EA entry + + The name of the entry + The associated data + The entry flags. + + + + Add a new EA entry + + The name of the entry + The associated data + The entry flags. + + + + Get an entry by name. + + The name of the entry. + The found entry. + Thrown if no entry by that name. + + + + Remove an entry from the buffer. + + The entry to remove. + + + + Remove an entry from the buffer by name. + + The name of the entry. + Thrown if no entry by that name. + + + + Convert to a byte array + + The byte array + + + + Get the list of entries. + + + + + Get number of entries. + + + + + Get whether the buffer contains a specific entry. + + The name of the entry. + True if the buffer contains an entry with the name. + + + + Index to get an entry by name. + + The name of the entry. + The found entry. + Thrown if no entry by that name. + + + + Clear all entries. + + + + + Access rights generic mapping. + + + + + Mapping for Generic Read + + + + + Mapping for Generic Write + + + + + Mapping for Generic Execute + + + + + Mapping for Generic All + + + + + Map a generic access mask to a specific one. + + The generic mask to map. + The mapped mask. + + + + Get whether this generic mapping gives read access. + + The mask to check against. + True if we have read access. + + + + Get whether this generic mapping gives write access. + + The mask to check against. + True if we have write access. + + + + Get whether this generic mapping gives execute access. + + The mask to check against. + True if we have execute access. + + + + Get whether this generic mapping gives all access. + + The mask to check against. + True if we have all access. + + + + Try and unmap access mask to generic rights. + + The mask to unmap. + The unmapped mask. Any access which can be generic mapped is left in the mask as specific rights. + + + + Get the allowed access mask for a specified mandatory access policy. + + The mandatory access policy. + The allowed access mask for the policy. + In general NoWriteUp will always be set on the policy. + + + + Convert generic mapping to a string. + + The generic mapping as a string. + + + + Interface to abstract the kernel transaction manager support. + + + + + Get handle for the transaction. + + + + + Commit the transaction + + + + + Rollback the transaction + + + + + Enable the transaction for anything in the current thread context. + + The transaction context. This should be disposed to disable the transaction. + + + + Class to represent a mount point. + + + + + Symbolic link name. + + + + + Unique ID. + + + + + Device name. + + + + + Class to access mount point manager utilities. + + + + + Query the list of mount points. + + True to throw on error. + The list of mount points. + + + + Query the list of mount points. + + The list of mount points. + + + + Class to represent the USN journal data. + + + + + Flags for the USN journal change reason. + + + + + Class to represent a USN journal record. + + + + + Reference number of the file. + + + + + Reference number of the parent. + + + + + USN value. + + + + + Timestamp of entry. + + + + + Reason code. + + + + + Source info flags. + + + + + Security ID. + + + + + File attributes. + + + + + Filename. + + + + + Full path, if known. + + + + + Full Win32Path if known. + + + + + Flags for USN journal source information. + + + + + Class for methods relating to USN journal. + + + + + Read USN journal information. + + The handle to the volume to query. + True to throw on error. + The USN journal information. + + + + Read USN journal information. + + The handle to the volume to query. + The USN journal information. + + + + Read USN journal entries from the volume. + + The volume to read. + The start USN to read. + Last USN to read, exclusive. + Mask for what records to read. + The list of USN journal entries. + + + + Read all USN journal entries from the volume. + + The volume to read. + The list of USN journal entries. + + + + Read USN journal entries from the volume, unprivileged. + + The volume to read. + The start USN to read. + Last USN to read, exclusive. + Mask for what records to read. + The list of USN journal entries. + + + + Read USN journal entries from the volume, unprivileged. + + The volume to read. + The list of USN journal entries. + + + + An enumeration to reference a known SID. + + + + + NULL SID + + + + + Everyone SID + + + + + Local user SID + + + + + CREATOR OWNER SID + + + + + CREATOR GROUP SID + + + + + CREATOR OWNER SERVER SID + + + + + CREATOR OWNER SERVER SID + + + + + Service SID + + + + + ANONYMOUS LOGON SID + + + + + Authenticated Users SID + + + + + RESTRICTED SID + + + + + LOCAL SYSTEM SID + + + + + LOCAL SERVICE SID + + + + + NETWORK SERVICE SID + + + + + APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES SID + + + + + APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES + + + + + NT SERVICE\TrustedInstaller + + + + + BUILTIN\Users + + + + + BUILTIN\Administrators + + + + + APPLICATION PACKAGE AUTHORITY\Your Internet connection + + + + + APPLICATION PACKAGE AUTHORITY\Your Internet connection, including incoming connections from the Internet + + + + + APPLICATION PACKAGE AUTHORITY\Your home or work networks + + + + + APPLICATION PACKAGE AUTHORITY\Your pictures library + + + + + APPLICATION PACKAGE AUTHORITY\Your videos library + + + + + APPLICATION PACKAGE AUTHORITY\Your music library + + + + + APPLICATION PACKAGE AUTHORITY\Your documents library + + + + + APPLICATION PACKAGE AUTHORITY\Your Windows credentials + + + + + APPLICATION PACKAGE AUTHORITY\Software and hardware certificates or a smart card + + + + + APPLICATION PACKAGE AUTHORITY\Removable storage + + + + + APPLICATION PACKAGE AUTHORITY\Your Appointments + + + + + APPLICATION PACKAGE AUTHORITY\Your Contacts + + + + + APPLICATION PACKAGE AUTHORITY\Internet Explorer + + + + + Constrained Impersonation Capability + + + + + OWNER RIGHTS + + + + + NT AUTHORITY\SELF + + + + + NT AUTHORITY\WRITE RESTRICTED + + + + + BUILTIN\BUILTIN + + + + + NT AUTHORITY\INTERACTIVE + + + + + NT AUTHORITY\DIALUP + + + + + NT AUTHORITY\NETWORK + + + + + NT AUTHORITY\BATCH + + + + + NT AUTHORITY\PROXY + + + + + Static methods to get some known SIDs. + + + + + NULL SID + + + + + Everyone SID + + + + + Local user SID + + + + + CREATOR OWNER SID + + + + + CREATOR GROUP SID + + + + + CREATOR OWNER SERVER SID + + + + + CREATOR OWNER SERVER SID + + + + + Service SID + + + + + ANONYMOUS LOGON SID + + + + + Authenticated Users SID + + + + + RESTRICTED SID + + + + + NT AUTHORITY\WRITE RESTRICTED + + + + + BUILTIN\BUILTIN + + + + + NT AUTHORITY\INTERACTIVE + + + + + NT AUTHORITY\DIALUP + + + + + NT AUTHORITY\NETWORK + + + + + NT AUTHORITY\BATCH + + + + + NT AUTHORITY\PROXY + + + + + LOCAL SYSTEM SID + + + + + LOCAL SERVICE SID + + + + + NETWORK SERVICE SID + + + + + APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES SID + + + + + APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES + + + + + NT SERVICE\TrustedInstaller + + + + + BUILTIN\Users + + + + + BUILTIN\Administrators + + + + + APPLICATION PACKAGE AUTHORITY\Your Internet connection + + + + + APPLICATION PACKAGE AUTHORITY\Your Internet connection, including incoming connections from the Internet + + + + + APPLICATION PACKAGE AUTHORITY\Your home or work networks + + + + + APPLICATION PACKAGE AUTHORITY\Your pictures library + + + + + APPLICATION PACKAGE AUTHORITY\Your videos library + + + + + APPLICATION PACKAGE AUTHORITY\Your music library + + + + + APPLICATION PACKAGE AUTHORITY\Your documents library + + + + + APPLICATION PACKAGE AUTHORITY\Your Windows credentials + + + + + APPLICATION PACKAGE AUTHORITY\Software and hardware certificates or a smart card + + + + + APPLICATION PACKAGE AUTHORITY\Removable storage + + + + + APPLICATION PACKAGE AUTHORITY\Your Appointments + + + + + APPLICATION PACKAGE AUTHORITY\Your Contacts + + + + + APPLICATION PACKAGE AUTHORITY\Internet Explorer + + + + + Constrained Impersonation Capability + + + + + Get a known SID based on a specific enumeration. + + The enumerated sid value. + + + + + Class to represent an Access Control Entry for a Mandatory Label. + + + + + Constructor. + + Flags for the ACE. + The mandatory label policy. + The integrity level. + + + + Constructor from a raw integrity level. + + Flags for the ACE. + The mandatory label policy. + The integrity level sid. + + + + The policy for the mandatory label. + + + + + Get or set the integrity level + + + + + Convert ACE to a string. + + + + + + Class which represents a mapped file. + + + + + Native path to file. + + + + + Name of the file. + + + + + List of mapped sections. + + + + + Mapped base address of file. + + + + + Mapped size of file. + + + + + True if the mapped file is an image section. + + + + + Specified the signing level if an image (only on RS3+). + + + + + Class to represent memory information. + + + + + Base address of memory region. + + + + + Allocation base for memory region. + + + + + Initial allocation protection. + + + + + Region size. + + + + + Memory state. + + + + + Current memory protection. + + + + + Memory type. + + + + + The mapped image path, if an image. + + + + + The mapped image path name, if an image. + + + + + The region type. + + + + + Is this a software enclave. + + + + + Interface for a marshalled NDR conformant structure. + + This interface is primarily for internal use only. + + + + Gets the number of conformant dimensions, should be at least one. + + The number of conformant dimensions. + + + + Interface for a marshalled non-encapsulated NDR union. + + This interface is primarily for internal use only. + + + + Marshal the union to a stream. + + The selector for union arm. + The marshal stream. + + + + Interface for a marshalled NDR structure. + + This interface is primarily for internal use only. + + + + Marshal the stucture to a stream. + + The marshal stream. + + + + Unmarshal the structure from a stream. + + The unmarshal stream. + + + + Get the structure's alignment. + + + + + + Structure to represent a context handle. + + + + + Context handle attributes. + + + + + Context handle UUID. + + + + + Constructor. + + Context handle attributes. + Context handle UUID. + + + + Overidden ToString method. + + The handle as string. + + + + NDR integer representation. + + + + + NDR character representation. + + + + + NDR floating point representation. + + + + + Definition of the NDR data representation for an NDR stream. + + + + + The integer representation of the NDR data. + + + + + The character representation of the NDR data. + + + + + The floating representation of the NDR data. + + + + + A class which represents an embedded pointer. + + The underlying type. + + + + Operator to convert from a value to an embedded pointer. + + The value to point to. + + + + Operator to convert from an embedded pointer to a value. + + The embedded pointer. + + + + Overridden ToString method. + + The string form of the value. + + + + Get the value from the embedded pointer. + + The value of the pointer. + + + + Structure to represent an empty value. + + + + + Class to represent a 16 bit enumerated type. + + + + + Value of the structure. + + + + + Constructor. + + + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Equality operator. + + The left value. + The right value. + True if the values are equal. + + + + Inequality operator. + + The left value. + The right value. + True if the values are not-equal. + + + + Overridden ToString. + + The value as a string. + + + + ToString method. + + The formatting string. + The value as a string. + + + + IFormattable ToString. + + The formatting string. + Formatting provider. + The value as a string. + + + + Equals operator. + + The other enum16. + True if the values are equal. + + + + Compare + + + + + + + Overridden GetHashCode. + + The hash code of the enumeration. + + + + Structure which represents an NDR FC_INT3264 + + + + + Value of the structure. + + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Convert to a native IntPtr. + + The value to convert from. + + + + Overridden ToString. + + The value as a string. + + + + ToString method. + + The formatting string. + The value as a string. + + + + IFormattable ToString. + + The formatting string. + Formatting provider. + The value as a string. + + + + Structure which represents an NDR FC_UINT3264 + + + + + Value of the structure. + + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Convert to a native IntPtr. + + The value to convert from. + + + + Overridden ToString. + + The value as a string. + + + + ToString method. + + The formatting string. + The value as a string. + + + + IFormattable ToString. + + The formatting string. + Formatting provider. + The value as a string. + + + + Class to represent an NDR interface pointer. + + + + + The marshaled interface data. + + + + + Constructor. + + The marshaled interface data. + + + + A buffer to marshal NDR data to. + + This class is primarily for internal use only. + + + + Represents an NDR pickled type. + + + + + Constructor from a type 1 serialized buffer. + + The type 1 serialized encoded buffer. + + + + Convert the pickled type to a type 1 serialized encoded buffer. + + The type 1 serialized encoded buffer. + + + + Type for a synchronous NDR pipe. + + The base type of pipe blocks. + + + + The list of blocks for the pipe. + + + + + Constructor. + + The list of blocks to return. + + + + Constructor. + + A single block to return. + + + + Convert the pipe blocks to a flat array. + + The flat array. + + + + A buffer to unmarshal NDR data from. + + This class is primarily for internal use only. + + + + Place holder for unsupported types. + + + + + Class to represent a single COM proxy definition. + + + + + The name of the proxy interface. + + + + + The IID of the proxy interface. + + + + + The base IID of the proxy interface. + + + + + The number of dispatch methods on the interface. + + + + + List of parsed procedures for the interface. + + + + + Creates a proxy definition from a list of procedures. + + The name of the proxy interface. + The IID of the proxy interface. + The base IID of the proxy interface. + The total dispatch count for the proxy interface. + The list of parsed procedures for the proxy interface. + + + + + Expression element. + + + + + Overridden ToString method. + + The expression as a string. + + + + The expression type. + + + + + Is this operator element valid. + + + + + Operator expression element. + + + + + NDR format type of element. + + + + + NDR format type of element. + + + + + Offset, used for OP_EXPRESSION. + + + + + Parsed arguments. + + + + + Overridden ToString method. + + The expression as a string. + + + + Variable expression element. + + + + + Offset of the variable. + + + + + NDR format type of element. + + + + + Overridden ToString method. + + The expression as a string. + + + + Expression element. + + + + + NDR format type of element. + + + + + Offset of the variable. + + + + + The value of the constant. + + + + + Overridden ToString method. + + The expression as a string. + + + + An interface which can be implemented to handle formatting parsed NDR data. + + + + + Format a complex type using the current formatter. + + The complex type to format. + The formatted complex type. + + + + Format a procedure using the current formatter. + + The procedure to format. + The formatted procedure. + + + + Format a COM proxy using the current formatter. + + The COM proxy to format. + The formatted COM proxy. + + + + Format an RPC server interface using the current formatter. + + The RPC server. + The formatted RPC server interface. + + + + An base class which describes a text formatter for NDR data. + + + + This formatter generates data that the CPP compiler can (hopefully) understand, + at least it will serve as a good skeleton to support spinning up new projects easily. + + + + + Flags for the NDR formatter. + + + + + No flags. + + + + + Don't emit comments. + + + + + Default NDR formatter constructor. + + + + + Create the default formatter. + + Specify a dictionary of IIDs to names. + Function to demangle COM interface names during formatting. + Formatter flags. + The default formatter. + + + + Create the default formatter. + + Specify a dictionary of IIDs to names. + Function to demangle COM interface names during formatting. + The default formatter. + + + + Create the default formatter. + + Specify a dictionary of IIDs to names. + Formatter flags. + The default formatter. + + + + Create the default formatter. + + Specify a dictionary of IIDs to names. + The default formatter. + + + + Create the default formatter. + + Formatter flags. + The default formatter. + + + + Create the default formatter. + + The default formatter. + + + + NDR formatter constructor for CPP style output. + + + + + Create the CPP formatter. + + Specify a dictionary of IIDs to names. + Function to demangle COM interface names during formatting. + Formatter flags. + The CPP formatter. + + + + Create the CPP formatter. + + Specify a dictionary of IIDs to names. + Function to demangle COM interface names during formatting. + The CPPformatter. + + + + Create the CPP formatter. + + Specify a dictionary of IIDs to names. + Formatter flags. + The CPP formatter. + + + + Create the CPP formatter. + + Specify a dictionary of IIDs to names. + The CPP formatter. + + + + Create the default formatter. + + Formatter flags. + The CPP formatter. + + + + Create the default formatter. + + The CPP formatter. + + + + Flags for the parser. + + + + + No flags. + + + + + Ignore processing any complex user marshal types. + + + + + Resolve structure names, required private symbols. + + + + + Class to parse NDR data into a structured format. + + + + + Constructor. + + Memory reader to parse from. + Process to read from. + Specify a symbol resolver to use for looking up symbols. + Flags which affect the parsing operation. + + + + Constructor. + + Process to parse from. + Specify a symbol resolver to use for looking up symbols. + + + + Constructor. + + Process to parse from. + Specify a symbol resolver to use for looking up symbols. + Flags which affect the parsing operation. + + + + Constructor. + + Specify a symbol resolver to use for looking up symbols. + + + + Constructor. + + Process to parse from. + + + + Constructor. + + + + + Read COM proxy information from a ProxyFileInfo structure. + + The address of the ProxyFileInfo structure. + The list of parsed proxy definitions. + + + + Read COM proxy information from an array of pointers to ProxyFileInfo structures. + + The address of an array of pointers to ProxyFileInfo structures. The last pointer should be NULL. + The list of parsed proxy definitions. + + + + Read COM proxy information from a file. + + The path to the DLL containing the proxy. + Optional CLSID for the proxy class. + List of IIDs to parse. + The list of parsed proxy definitions. + + + + Read COM proxy information from a file. + + The path to the DLL containing the proxy. + Optional CLSID for the proxy class. + The list of parsed proxy definitions. + + + + Read COM proxy information from a file. + + The path to the DLL containing the proxy. + The list of parsed proxy definitions. + + + + Parse NDR content from an RPC_SERVER_INTERFACE structure in memory. + + Pointer to the RPC_SERVER_INTERFACE. + The parsed NDR content. + + + + Parse NDR content from an RPC_SERVER_INTERFACE structure in memory. + + Pointer to the RPC_SERVER_INTERFACE. + Base address of the library which contains the interface. + The parsed NDR content. + + + + Parse NDR content from an RPC_SERVER_INTERFACE structure in memory. Deprecated. + + Pointer to the RPC_SERVER_INTERFACE. + The parsed NDR content. + + + + Parse NDR content from an RPC_SERVER_INTERFACE structure in memory. + + The path to a DLL containing the RPC_SERVER_INTERFACE. + Offset to the RPC_SERVER_INTERFACE from the base of the DLL. + The parsed NDR content. + + + + Parse NDR procedures from an MIDL_SERVER_INFO structure in memory. + + Pointer to the MIDL_SERVER_INFO. + Number of dispatch functions to parse. + The start offset to parse from. This is used for COM where the first few proxy stubs are not implemented. + List of names for the valid procedures. Should either be null or a list equal in size to dispatch_count - start_offset. + The parsed NDR content. + + + + Parse NDR procedures from an MIDL_SERVER_INFO structure in memory. + + Pointer to the MIDL_SERVER_INFO. + Number of dispatch functions to parse. + The start offset to parse from. This is used for COM where the first few proxy stubs are not implemented. + The parsed NDR content. + + + + List of parsed types from the NDR. + + + + + List of parsed complex types from the NDR. + + + + + Parse NDR complex type information from a pickling structure. Used to extract explicit Encode/Decode method information. + + The process to read from. + Pointer to the MIDL_TYPE_PICKLING_INFO structure. + The pointer to the MIDL_STUB_DESC structure. + Pointers to the the format string to the start of the types. + Specify additional parser flags. + The list of complex types. + This function is used to extract type information for calls to NdrMesTypeDecode2. MIDL_TYPE_PICKLING_INFO is the second parameter, + MIDL_STUB_DESC is the third, the Type Offsets is the fourth parameter. + + + + Parse NDR complex type information from a pickling structure. Used to extract explicit Encode/Decode method information. + + The process to read from. + Pointer to the MIDL_TYPE_PICKLING_INFO structure. + The pointer to the MIDL_STUBLESS_PROXY_INFO structure. + Pointer to the type pickling offset table. + Index into type_pickling_offset_table array. + Specify additional parser flags. + The list of complex types. + This function is used to extract type information for calls to NdrMesTypeDecode3. MIDL_TYPE_PICKLING_INFO is the second parameter, + MIDL_STUBLESS_PROXY_INFO is the third, the type pickling offset table is the fourth and the type index is the fifth. + + + + Parse NDR complex type information from a pickling structure. Used to extract explicit Encode/Decode method information. + + The process to read from. + Pointer to the MIDL_TYPE_PICKLING_INFO structure. + The pointer to the MIDL_STUB_DESC structure. + Offsets into the format string to the start of the types. + Specify additional parser flags. + The list of complex types. + This function is used to extract type information for calls to NdrMesTypeDecode2. MIDL_TYPE_PICKLING_INFO is the second parameter, + MIDL_STUB_DESC is the third (minus the offset). + + + + Parse NDR complex type information from a pickling structure. Used to extract explicit Encode/Decode method information. + + The process to read from. + Pointer to the MIDL_TYPE_PICKLING_INFO structure. + The pointer to the MIDL_STUB_DESC structure. + Offsets into the format string to the start of the types. + The list of complex types. + This function is used to extract type information for calls to NdrMesTypeDecode2. MIDL_TYPE_PICKLING_INFO is the second parameter, + MIDL_STUB_DESC is the third (minus the offset). + + + + Parse NDR complex type information from a pickling structure. Used to extract explicit Encode/Decode method information. + + Pointer to the MIDL_TYPE_PICKLING_INFO structure. + The pointer to the MIDL_STUB_DESC structure. + Offsets into the format string to the start of the types. + The list of complex types. + This function is used to extract type information for calls to NdrMesTypeDecode2. MIDL_TYPE_PICKLING_INFO is the second parameter, + MIDL_STUB_DESC is the third (minus the offset). + + + + Exception thrown when NDR parsing fails. + + + + + Constructor. + + Exception message. + + + + Constructor. + + Exception message. + Inner exception to wrap. + + + + Class respresenting an RPC protocol sequence. + + + + + The protocol sequence for the endpoint. + + + + + The endpoint name. + + + + + A parsed NDR RPC_SERVER_INTERFACE structure. + + + + + The RPC interface GUID. + + + + + The RPC interface version. + + + + + The RPC transfer syntax GUID. + + + + + The RPC transfer syntax version. + + + + + List of parsed procedures. + + + + + List of protocol sequences. + + + + + Overridden ToString method. + + The string form of this class. + + + + NDR format character. + + + + + Class to build text strings for an NDR formatter. + + + + + Push an indent string on to the indent stack. + + The string to indent any new lines. + The current builder instance. + + + + Push an indent on to the indent stack. + + The character to indent with. + The number of indent characters. + The current builder instance. + + + + Pop the current indent off the indent stack. + + The current builder instance. + + + + Append a string to the builder. + + The string to append. + The current builder instance. + + + + Append a formatted string to the builder. + + The string format. + The array of arguments to the formatter. + The current builder instance. + + + + Append a new line to the builder. + + The current builder instance. + + + + Append a string to the builder with a new line. + + The string to append. + The current builder instance. + + + + Append a formatted string to the builder with a new line. + + The string format. + The array of arguments to the formatter. + The current builder instance. + + + + Overridden ToString method, returns the current state of the builder. + + The current stated of the builder. + + + + Utilities for NDR marshaling. + + + + + Specify NDR marshaler trace level. + + Specify the NDR marshaler trace level. + Verbose marshal stack details. + + + + Datalink address type. + + + + + Access rights for a firewall object. + + + + + Represents a firewall address and mask. + + + + + The IP address. + + + + + The mask. + + + + + Mask prefix length. + + + + + Overridden ToString method. + + The value and mask as a string. + + + + Address family when IP protocol is not specified. + + + + + IPv4 + + + + + IPv6 + + + + + Ethernet + + + + + None + + + + + Class to represent a firewall ALE endpoint. + + + + + The ID of the endpoint. + + + + + The local endpoint. + + + + + The remote endpoint. + + + + + The protocol type. + + + + + The LUID for the token associated with the endpoint. + + + + + The IPsec security association identifier. + + + + + The IPsec security association identifier to expire. + + + + + The IPsec status of the endpoint. + + + + + Flags. + + + + + Associated application. + + + + + Filename of AppId. + + + + + Enumeration for ALE layer types. + + + + + Class to represent a firewall callout object. + + + + + Flags for the callout. + + + + + Provider key. + + + + + Provider data. + + + + + Applicable layer key. + + + + + Callout ID. + + + + + Flags for a firewall callout. + + + + + Guids for pre-defined callouts. + + + + + Flags for classify output. + + + + + Class to represet the result of a classify operations. + + + + + Action type of the classify result. + + + + + Internal context. + + + + + ID of the filter. + + + + + Associated rights. + + + + + Classify flags. + + + + + Base class to implement common condition building operations. + + + + + Specify list of firewall filter conditions. + + + + + Add a condition. + + The match type for the condition. + The field key for the condition. + The value for the condition. + + + + Add a condition range. + + The field key for the condition. + The low value for the range. + The high value from the range. + + + + Add an executable filename condition. + + The match type for the condition. + The path to the file to use. + + + + Add an App ID condition. + + The match type for the condition. + The path to the file already converted to absolute format. + + + + Add a user ID security descriptor condition. + + The match type for the condition. + The security descriptor. + + + + Add a remote user ID security descriptor condition. + + The match type for the condition. + The security descriptor. + + + + Add a remote machine ID security descriptor condition. + + The match type for the condition. + The security descriptor. + + + + Add a IP protocol type condition. + + The match type for the condition. + The protocol type for the condition. + + + + Add a conditions flag condition. + + The match type for the condition. + The flags for the condition. + + + + Add IP address. + + The match type for the condition. + True to specify remote, false for local. + The low IP address. + + + + Add IP address range. + + True to specify remote, false for local. + The low IP address. + The high IP address. + + + + Add port range. + + True to specify remote, false for local. + The low port. + The high port. + + + + Add port. + + The match type for the condition. + True to specify remote, false for local. + The port. + + + + Add an IP endpoint. + + The match type for the condition. + True to specify remote, false for local. + The IP endpoint. + + + + Add token information. + + The match type. + The token. + + + + Add remote token information. + + The match type. + The token. + + + + Add remote machine token information. + + The match type. + The token. + + + + Add a package SID condition. + + The match type. + The package SID. + + + + Add a condition which excludes app containers. + + + + + Add a condition which includes app containers. + + + + + Adds details from a process, such as the process' App ID and package SID and token information. + + The match type. + The process. + + + + Adds details from a process, such as the process' App ID and package SID and token information. + + The match type. + The PID of the process. + + + + Add the RPC UUID. + + Match type. + The RPC UUID. + + + + Add a network event type. + + Match type. + Network event type. + + + + Constructor. + + + + + Firewall condition flags. + + + + + Guids for pre-defined firewall conditions. + + + + + Direction of stream for firewall. + + + + + Outbound flow. + + + + + Inbound flow. + + + + + Place holder for an empty value. + + + + + Overridden ToString method. + + The value as a string. + + + + Class to represent the firewall engine. + + + + + Open an instance of the engine. + + The server name for the firewall service. + RPC authentication service. Use default or WinNT. + Optional authentication credentials. + Optional session information. + True to throw on error. + The opened firewall engine. + + + + Open an instance of the engine. + + The server name for the firewall service. + RPC authentication service. Use default or WinNT. + Optional authentication credentials. + Optional session information. + The opened firewall engine. + + + + Open an instance of the engine. + + True to throw on error. + The opened firewall engine. + + + + Open an instance of the engine. + + The opened firewall engine. + + + + Open a dynamic instance of the engine. + + True to throw on error. + The opened firewall engine. + + + + Open a dynamic instance of the engine. + + The opened firewall engine. + + + + Get an engine option. + + The option to get. + True to throw on error. + The engine option's value. + + + + Get an engine option. + + The option to get. + The engine option's value. + + + + Get the current network event keywords setting. + + True to throw on error. + The network event keywords. + + + + Get the current network event keywords setting. + + The network event keywords. + + + + Get collect net events option. + + True to throw on error. + True if net events are being collected. + + + + Get collect net events option. + + True if net events are being collected. + + + + Set an engine option. + + The option to set. + The value to set. + True to throw on error. + The NT status code. + + + + Set an engine option. + + The option to set. + The value to set. + + + + Set network event keywords. + + The keywords to set. + True to throw on error. + The NT status code. + + + + Set network event keywords. + + The keywords to set. + + + + Set the collection net events engine option. + + True to enable collection. + True to throw on error. + The NT status code. + + + + Set the collection net events engine option. + + True to enable collection. + + + + Get a layer by its key. + + The key of the layer. + True to throw on error. + The firewall layer. + + + + Get a layer by its key. + + The key of the layer. + The firewall layer. + + + + Get a layer by its ID. + + The ID of the layer. + True to throw on error. + The firewall layer. + + + + Get a layer by its ID. + + The ID of the layer. + The firewall layer. + + + + Get a layer by its well-known key name. + + The well-known key name of the layer. + True to throw on error. + The firewall layer. + + + + Get a layer by its well-known key name. + + The well-known key name of the layer. + The firewall layer. + + + + Get a layer by an ALE layer type. + + The ALE layer type. + True to throw on error. + The firewall layer. + + + + Get a layer by an ALE layer type. + + The ALE layer type. + The firewall layer. + + + + Enumerate all layers. + + True to throw on error. + The list of layers. + + + + Enumerate all layers. + + The list of layers. + + + + Get a sub-layer by its key. + + The key of the sub-layer. + True to throw on error. + The firewall sub-layer. + + + + Get a sub-layer by its key. + + The key of the sub-layer. + The firewall sub-layer. + + + + Get a sub-layer by its well-known key name. + + The well-known key name of the sub-layer. + True to throw on error. + The firewall sub-layer. + + + + Get a sub-layer by its well-known key name. + + The well-known key name of the sub-layer. + The firewall sub-layer. + + + + Enumerate all sub-layers. + + True to throw on error. + The list of sub-layers. + + + + Enumerate all sub-layers. + + The list of sub-layers. + + + + Get a callout by its key. + + The key of the callout. + True to throw on error. + The firewall callout. + + + + Get a callout by its key. + + The key of the callout. + The firewall callout. + + + + Enumerate all callouts + + True to throw on error. + The list of callouts. + + + + Enumerate all callouts. + + The list of callouts. + + + + Get a filter by its key. + + The key of the filter. + True to throw on error. + The firewall filter. + + + + Get a filter by its key. + + The key of the filter. + The firewall filter. + + + + Get a filter by its id. + + The ID of the filter. + True to throw on error. + The firewall filter. + + + + Get a filter by its id. + + The ID of the filter. + The firewall filter. + + + + Enumerate filters + + Specify a template for enumerating the filters. + True to throw on error. + The list of filters. + + + + Enumerate filters + + Specify a template for enumerating the filters. + The list of filters. + + + + Enumerate all filters + + True to throw on error. + The list of filters. + + + + Enumerate all filters. + + The list of filters. + + + + Add a filter. + + The builder used to create the filter. + Optional security descriptor. + True to throw on error. + The added filter ID. + + + + Add a filter. + + The builder used to create the filter. + Optional security descriptor. + The added filter ID. + + + + Add a filter. + + The builder used to create the filter. + The added filter ID. + + + + Delete a filter. + + The filter key. + True to throw on error. + The NT status. + + + + Delete a filter. + + The filter key. + + + + Delete a filter. + + The filter ID. + True to throw on error. + The NT status. + + + + Delete a filter. + + The filter ID. + + + + Get a provider by its key. + + The key of the provider. + True to throw on error. + The firewall provider. + + + + Get a provider by its key. + + The key of the provider. + The firewall provider. + + + + Enumerate all providers. + + True to throw on error. + The list of providers. + + + + Enumerate all providers. + + The list of providers. + + + + Get the security descriptor for the IKE SA database. + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Get the security descriptor for the IKE SA database. + + What parts of the security descriptor to retrieve + The security descriptor + + + + Get the security descriptor for the IKE SA database. + + The security descriptor + + + + Enumerate all IKE security associatations. + + True to throw on error. + The list of IKE security associatations. + + + + Enumerate all IKE security associatations. + + The list of IKE security associatations. + + + + Get an IKE security association by its ID and lookup context. + + The ID of the security association. + Optional lookup context. + True to throw on error. + The IKE security association. + + + + Get an IKE security association by its ID and lookup context. + + The ID of the security association. + Optional lookup context. + The IKE security association. + + + + Classify a layer. + + The ID of the layer. + A list of incoming values. + True to throw on error. + The classify result. + + + + Classify a layer. + + The ID of the layer. + A list of incoming values. + The classify result. + + + + Enumerate IPSEC key managers. + + True to throw on error. + The list of registered key managers. + + + + Enumerate IPSEC key managers. + + The list of registered key managers. + + + + Get key manager component security descriptor. + + The security information to query. + True to throw on error. + The security descriptor. + + + + Get key manager component security descriptor. + + The security information to query. + The security descriptor. + + + + Open token from its modified ID. + + The token's modified ID. + The desired token access. + True to throw on error. + The opened token. + + + + Open token from its modified ID. + + The token's modified ID. + The desired token access. + The opened token. + + + + Enumerate all ALE endpoints. + + True to throw on error. + The list of ALE endpoints. + + + + Enumerate all ALE endpoints. + + The list of ALE endpoints. + + + + Get an ALE endpoint by its ID. + + The ID of the ALE endpoint. + True to throw on error. + The ALE endpoint. + + + + Get an ALE endpoint by its ID. + + The ID of the ALE endpoint. + The ALE endpoint. + + + + Get the ALE endpoint security. + + The security information to query for. + True to throw on error. + The security descriptor. + + + + Get the ALE endpoint security. + + The security information to query for. + The security descriptor. + + + + Enumerate all sessions. + + True to throw on error. + The list of sessions. + + + + Enumerate all sessions. + + The list of sessions. + + + + Enumerate all network events. + + Template to filter down enumeration. + True to throw on error. + The list of network events. + + + + Enumerate all network events. + + True to throw on error. + The list of network events. + + + + Enumerate all network events. + + Template to filter down enumeration. + The list of network events. + + + + Subscribe to read network event.s + + True to throw on error. + Optional template to filter enumeration. + The network event listener. + + + + Subscribe to read network event.s + + Optional template to filter enumeration. + The network event listener. + + + + Subscribe to read network event.s + + True to throw on error. + The network event listener. + + + + Begin a firewall transaction. + + Flags for the transaction. + True to throw on error. + The firewall transaction. + Disposing the transaction will cause it to abort. You should call Commit to use it. + + + + Enumerate all IPsec SA contexts. + + True to throw on error. + The list of SA contexts. + + + + Enumerate all IPsec SA contexts. + + The list of SA contexts. + + + + Get an IPsec SA context by its ID. + + The ID of the IPsec SA context. + True to throw on error. + The IPsec SA context. + + + + Get an IPsec SA context by its ID. + + The ID of the IPsec SA context. + The IPsec SA context. + + + + Begin a firewall transaction. + + Flags for the transaction. + The firewall transaction. + Disposing the transaction will cause it to abort. You should call Commit to use it. + + + + Begin a read/write firewall transaction. + + The firewall transaction. + Disposing the transaction will cause it to abort. You should call Commit to use it. + + + + Dispose the engine. + + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Engine option to query or set. + + + + + Represents a firewall field schema. + + + + + The field's key. + + + + + The name of the key if known. + + + + + The type of the field. + + + + + The data type of the field. + + + + + Field type. + + + + + A class to represent a firewall filter. + + + + + The filter action type. + + + + + The layer the filter applies to. + + + + + The name of the layer if known. + + + + + The sub-layer the filter applies to. + + + + + The name of the sub-layer if known. + + + + + The flags for the filter. + + + + + List of firewall conditions. + + + + + Original weight of the filter. + + + + + Provider key. + + + + + Provider data. + + + + + Filter identifier. + + + + + Effective weight of the filter. + + + + + Type of filter. + + + + + Key for the callout. + + + + + Name of the callout key if known. + + + + + Is the filter a callout. + + + + + Has the filter got an AppID condition. + + + + + Has the filter got an AppContainer package ID condition. + + + + + Has the filter got a condition to check for a user ID. + + + + + Has the filter got a condition to check for a remote user ID. + + + + + Get a layer for this filter. + + True to throw on error. + The firewall layer. + + + + Get a layer for this filter. + + The firewall layer. + + + + Get a sub-layer for this filter. + + True to throw on error. + The firewall sub-layer. + + + + Get a sub-layer for this filter. + + The firewall sub-layer. + + + + Check if filter has any condition of a specific type. + + The condition type to check. + True if the filter has a condition of the specified type. + + + + Get the filter condition for a GUID. + + The condition type to get. + The filter condition. + + + + Delete the filter. + + True to throw on error. + The NT status. + + + + Delete the filter. + + + + + Convert the filter into a builder so that it can be modified. + + The created builder. + + + + Access rights for a firewall filter. + + + + + A builder to create a new firewall filter. + + + + + The name of the filter. + + + + + The description of the filter. + + + + + The filter key. If empty will be automatically assigned. + + + + + The layer key. + + + + + The sub-layer key. + + + + + Flags for the filter. + + + + + Specify the initial weight. + + You need to specify an EMPTY, UINT64 or UINT8 value. + + + + Specify the action for this filter. + + + + + Specify the filter type GUID when not using a callout. + + + + + Specify callout key GUID when using a callout. + + + + + Specify provider key GUID. + + + + + Constructor. + + + + + Firewall filter condition. + + + + + The match type. + + + + + The key of the field. + + + + + The field key name. + + + + + The value for the condition + + + + + Constructor. + + The condition match type. + The field key. + The value. + + + + Overridden ToString method. + + The condition as a string. + + + + Options for enumerating a filter. + + + + + Specify the key for the layer to search for. + + + + + Specify the provider key. + + + + + Specify the flags for the enumeration. + + + + + Specify the action type. + + + + + Constructor. + + The layer key. + + + + Constructor. + + The ALE layer type.. + + + + Constructor. + + + + + Class to represent a firewall layer object. + + + + + Layer flags. + + + + + Default sub-layer key. + + + + + The layer ID. + + + + + List of fields. + + + + + Is builtin layer. + + + + + Is a user-mode layer. + + + + + Enumerate filters for this layer. + + True to throw on error. + The list of sorted filters. + + + + Enumerate filters for this layer. + + The list of sorted filters. + + + + Flags for a firewall layer. + + + + + Guids for pre-defined firewall layers. + + + + + Firewall filter match type. + + + + + Direction type for a network event. + + + + + Inbound + + + + + Outbound. + + + + + Forwarding + + + + + Loopback. + + + + + Base class for a firewall network event. + + + + + Type of network event. + + + + + Flags for values set. + + + + + Timestamp of the event. + + + + + Type of protocol. + + + + + Local endpoint. + + + + + Remote endpoint. + + + + + IPv6 Scope ID. + + + + + Connection AppID. + + + + + Connection user ID. + + + + + Address family. + + + + + Package SID. + + + + + Class to represent a network event capability allow. + + + + + AppContainer network capability. + + + + + Filter ID. + + + + + Indicates whether the packet originated from (or was heading to) the loopback adapter. + + + + + Class to represent a network event capability drop. + + + + + AppContainer network capability. + + + + + Filter ID. + + + + + Indicates whether the packet originated from (or was heading to) the loopback adapter. + + + + + Class to represent a firewall classification allow. + + + + + Filter ID. + + + + + Layer ID. + + + + + Reason for reauthorizing + + + + + The original profile the connection was received on. + + + + + The profile the error occurred on. + + + + + Indicates the direction of the packet transmission. + + + + + Indicates whether the packet originated from (or was heading to) the loopback adapter. + + + + + Class to represent a firewall classification drop. + + + + + Filter ID. + + + + + Layer ID. + + + + + Reason for reauthorizing + + + + + The original profile the connection was received on. + + + + + The profile the error occurred on. + + + + + Indicates the direction of the packet transmission. + + + + + Indicates whether the packet originated from (or was heading to) the loopback adapter. + + + + + GUID identifier of a vSwitch. + + + + + Transient source port of a packet within the vSwitch. + + + + + Transient destination port of a packet within the vSwitch. + + + + + Template for network event enumeration. + + + + + Start time for events. + + + + + End time for event.s + + + + + Constructor. + + + + + Flags for a network event. + + + + + Class to represent an IKEEXT extended mode failure event. + + + + + Windows error code for the failure + + + + + Point of failure + + + + + Flags for the failure event + + + + + IKE or Authip. + + + + + Extended mode mode state + + + + + Initiator or Responder + + + + + Authentication method + + + + + Hash (SHA thumbprint) of the end certificate corresponding to failures + that happen during building or validating certificate chains. + + + + + LUID for the MM SA + + + + + Quick mode filter ID + + + + + Name of local security principal that was authenticated, if available. + If not available, an empty string will be stored. + + + + + Name of remote security principal that was authenticated, if available. + If not available, an empty string will be stored. + + + + + Array of group SIDs corresponding to the local security principal that + was authenticated, if available. + + + + + Array of group SIDs corresponding to the remote security principal that + was authenticated, if available. + + + + + Class to represent an IKEEXT main mode failure event. + + + + + Windows error code for the failure + + + + + Point of failure + + + + + Flags for the failure event + + + + + IKE or Authip. + + + + + Main mode state + + + + + Initiator or Responder + + + + + Authentication method + + + + + Hash (SHA thumbprint) of the end certificate corresponding to failures + that happen during building or validating certificate chains. + + + + + LUID for the MM SA + + + + + Main mode filter ID + + + + + Name of local security principal that was authenticated, if available. + If not available, an empty string will be stored. + + + + + Name of remote security principal that was authenticated, if available. + If not available, an empty string will be stored. + + + + + Array of group SIDs corresponding to the local security principal that + was authenticated, if available. + + + + + Array of group SIDs corresponding to the remote security principal that + was authenticated, if available. + + + + + Class to represent an IKEEXT quick mode failure event. + + + + + Windows error code for the failure + + + + + Point of failure + + + + + IKE or Authip. + + + + + Main mode state + + + + + Initiator or Responder + + + + + Tunnel or transport mode. + + + + + Main mode filter ID + + + + + Local subnet address and mask. + + + + + Remote subnet address and mask. + + + + + Class to represent an IPsec kernel drop event. + + + + + Failure error code. + + + + + Connection direction. + + + + + Security parameter index. + + + + + Filter ID. + + + + + Layer ID. + + + + + Flags for network events to capture. + + + + + Class to listen for network events. + + + + + Read the next network event. + + Timeout in milliseconds. + Returns null if not event available, otherwise the next event. + + + + Read the next network event. Waiting indefinetely for the event. + + Returns null if not event available, otherwise the next event. + + + + Dispose the listener. + + + + + Type of network event. + + + + + AppContainer capability type. + + + + + Abstract class to represent a firewall object. + + + + + The object's key. + + + + + The object's name. + + + + + The object's description. + + + + + The object's key name. + + + + + The object's security descriptor. + + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + The firewall engine object must still be open. + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + The firewall engine object must still be open. + + + + Profile ID for the firewall. + + + + + Class to represent a firewall provider. + + + + + Name of the service which implements the provider. + + + + + Flags for the provider. + + + + + Provider data. + + + + + Flags for a firewall provider. + + + + + A firewall value range. + + + + + The low value. + + + + + The high value. + + + + + Overridden ToString method. + + The range as a string. + + + + Right action flags. + + + + + Class to represent a firewall session. + + + + + The session key. + + + + + Name of the session. + + + + + Description of the session. + + + + + Session flags. + + + + + Transaction wait timeout in ms. + + + + + The process ID of the session owner. + + + + + The user SID of the owner. + + + + + The name of the owner. + + + + + Is session kernel mode. + + + + + Constructor. Used when opening a session. + + The name of the session. + The description of the sesion. + Session flags. + Transaction timeout in ms. + + + + Constructor. Used when opening a session. + + Session flags. + + + + Class to represent a firewall sublayer. + + + + + Sub-layer flags. + + + + + The provider key. + + + + + Provider data. + + + + + Weight of the sub-layer. + + + + + Flags for a sub-layer. + + + + + Guids for pre-defined firewall sub-layers. + + + + + Token information for a condition. + + + + + The list of SIDs. + + + + + The list of restricted SIDs. + + + + + Capabilities. + + This is only used for local filtering. It's not used by WFP. + + + + Appcontainer SID. + + This is only used for local filtering. It's not used by WFP. + + + + User SID. + + This is only used for local filtering. It's not used by WFP. + + + + Constructor from a token. + + The token to constructo from. + + + + Constructor. + + The list of SIDs. + The list of restricted SIDs. + + + + Class to scope a firewall transaction. + + + + + Abort the transaction. + + True to throw on error. + The NT status code. + + + + Abort the transaction. + + + + + Commit the transaction. + + True to throw on error. + The NT status code. + + + + Commit the transaction. + + + + + Dispose the transaction. Will ca + + + + + Flags when creating a transaction. + + + + + No flags, creates a read/write transaction. + + + + + Read-only transaction. + + + + + Static class for firewall utility functions. + + + + + Name for fake NT type. + + + + + Name for fake filter NT type. + + + + + Get the NT type for the firewall. + + + + + Get the NT type for the firewall. + + + + + Get the generic mapping for a firewall object. + + The firewall object generic mapping. + + + + Get the generic mapping for a firewall filter object. + + The firewall filter object generic mapping. + + + + Get App ID from a filename. + + The filename to convert. + True to throw on error. + The App ID. + + + + Get App ID from a filename. + + The filename to convert. + The App ID. + + + + Get a list of known layer names. + + The list of known layer names. + + + + Get a list of known layer guids. + + The list of known layer guids. + + + + Get a known layer GUID from its name. + + The name of the layer. + The known layer GUID. + + + + Get a known callout GUID from its name. + + The name of the callout. + The known callout GUID. + + + + Get a list of known sub-layer names. + + The list of known sub-layer names. + + + + Get a list of known callout names. + + The list of known callout names. + + + + Get a list of known sub-layer guids. + + The list of known sub-layer guids. + + + + Get a known sub-layer GUID from its name. + + The name of the sub-layer. + The known sub-layer GUID. + + + + Get a layer GUID for an ALE layer enumeration. + + The ALE layer enumeration. + The ALE layer GUID. + + + + Firewall value. + + + + + Type of the value. + + + + + The raw value. + + + + + The context specific value, might be the same as the original. + + + + + Get a value which represents Empty. + + + + + Create a value from a security descriptor. + + The security descriptor. + The firewall value. + + + + Create a value from a SID. + + The SID. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The IPv4 address. + The IPv4 mask. + The firewall value. + + + + Create a value. + + The IPv6 address. + The prefix length. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a range value. + + The low value. + The high value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Overridden ToString method. + + The value as a string. + + + + Class to represent a certificate credential. + + + + + Certificate subject name. + + + + + Certificatehash. + + + + + Flags. + + + + + Certificate. + + + + + Overridden ToString method. + + The pair as a string. + + + + Class to represent an IKE credential. + + + + + Authentication method type. + + + + + Impersonation type. + + + + + Overridden ToString method. + + The pair as a string. + + + + Structure to represent a pair of credentials. + + + + + Local credentials. + + + + + Peer credentials. + + + + + Overridden ToString method. + + The pair as a string. + + + + IKEEXT EM failure flags. + + + + + Flag indicating that multiple IKE EM failure events have been reported that + should be correlated using the mmId field. + + + + + Flag indicating that the IKE EM failure event is a benign/expected failure + + + + + IKE extended mode states + + + + + Initial state. No EM packets have been sent to the peer yet. + + + + + State corresponding to the first EM roundtrip + + + + + State corresponding to the second EM roundtrip + + + + + State corresponding to the final EM roundtrip + + + + + State corresponding to the final EM roundtrip + + + + + EM has been completed + + + + + IKEEXT MM failure flags. + + + + + Flag indicating that the IKE MM failure event is a benign/expected failure. + + + + + Flag indicating that multiple IKE MM failure events have been reported that + should be correlated using the mmId field. + + + + + IKE main mode states + + + + + Initial state. No MM packets have been sent to the peer yet. + + + + + First roundtrip packet has been sent to the peer. + + + + + Second roundtrip packet has been sent to the peer, for SSPI auth. + + + + + Second roundtrip packet has been sent to the peer. + + + + + Final roundtrip packet has been sent to the peer. + + + + + MM has been completed. + + + + + IKE quick mode states + + + + + Initial state. No QM packets have been sent to the peer yet. + + + + + State corresponding to the first QM roundtrip + + + + + State corresponding to the final QM roundtrip + + + + + QM has been completed. + + + + + IKE main mode or quick mode SA role + + + + + SA is initiator + + + + + SA is responder + + + + + Class to represent an IKE name credential. + + + + + The credential principal name. + + + + + Overridden ToString method. + + The pair as a string. + + + + Class to represent an IKE pre-shared key credential. + + + + + The pre-shared key. + + + + + Key flags. + + + + + Class to represent an IKE security association. + + + + + ID for the security association. + + + + + Key module type. + + + + + The local address of the association. + + + + + The remote address of the association. + + + + + Initiator cookie. + + + + + Responder cookie. + + + + + IKE policy key, + + + + + Virtual interface tunnel ID. + + + + + Correlation key. + + + + + List of credentials. + + + + + Cipher algorithm for the security association. + + + + + Length of the key. + + + + + Number of rounds. + + + + + Integrity algorithm for the security association. + + + + + Maximum lifetime in seconds. + + + + + Diffie-Hellman group. + + + + + Quick mode limit. + + + + + IPsec auth config. + + + + + IPsec authentication type. + + + + + IPsec Cipher Configuration. + + + + + IPSec Cipher Type. + + + + + Type used for indicating where an IPsec failure occured. + + + + + No information available. + + + + + IPsec failure happened on local machine. + + + + + IPsec failure happened on remote machine. + + + + + Class to represent a IPsec identity + + + + + Main-mode target name. + + + + + Extended mode target name. + + + + + List of tokens. + + + + + Explicit credentials handle. + + + + + Logon ID. + + + + + Class to prepresent a key manager. + + + + + The manager's key. + + + + + The manager's name. + + + + + The manager's description. + + + + + The manager's flags. + + + + + The manager's dictation timeout hint. + + + + + Flags for IPsec key manager. + + + + + IPsec perfect forward secrecy group. + + + + + Class to represent the details of an IPsec security association. + + + + + Directory of SA. + + + + + Local endpoint. + + + + + Remote endpoint. + + + + + Traffic type. + + + + + Traffic type ID. + + + + + IP protocol type. + + + + + Interface LUID. + + + + + Real interface profile ID. + + + + + The SA bundle. + + + + + Local IPv4 UDP encapsulation port. + + + + + Remote IPv4 UDP encapsulation port. + + + + + Transport filter. + + + + + Virtual interface tunnel ID. + + + + + Traffic selector ID. + + + + + Overridden ToString method. + + The overridden ToString method. + + + + Class to represent a security association bundle. + + + + + Flags for the SA. + + + + + SA lifetime in seconds. + + + + + SA lifetime in KiB. + + + + + SA lifetime in packets. + + + + + Idle timeout. + + + + + ND allow clear timeout. + + + + + Identity for IPsec SA. + + + + + NAP context. + + + + + Quick-mode SA ID. + + + + + Key module key. + + + + + Key module state blob. + + + + + List of security association parameters. + + + + + Peer V4 private address. + + + + + Main-mode SA ID. + + + + + PFS group. + + + + + SA lookup context. + + + + + QM filter ID. + + + + + IPsec SA bundle flags. + + + + + Negotiation discovery is enabled in secure ring. + + + + + Negotiation discovery in enabled in the untrusted perimeter zone. + + + + + Peer is in untrusted perimeter zone ring and a network address translation (NAT) is in the way. Used with negotiation discovery. + + + + + Indicates that this is an SA for connections that require guaranteed encryption. + + + + + Indicates that this is an SA to an NLB server. + + + + + Indicates that this SA should bypass machine LUID verification. + + + + + Indicates that this SA should bypass impersonation LUID verification. + + + + + Indicates that this SA should bypass explicit credential handle matching. + + + + + Allows an SA formed with a peer name to carry traffic that does not have an associated peer target. + + + + + Clears the DontFragment bit on the outer IP header of an IPsec-tunneled packet. This flag is applicable only to tunnel mode SAs. + + + + + Default encapsulation ports (4500 and 4000) can be used when matching this SA with packets on outbound connections that do not have an associated IPsec-NAT-shim context. + + + + + Peer has negotiation discovery enabled, and is on a perimeter network. + + + + + Suppresses the duplicate SA deletion logic. THis logic is performed by the kernel when an outbound SA is added, to prevent unnecessary duplicate SAs. + + + + + Indicates that the peer computer supports negotiating a separate SA for connections that require guaranteed encryption. + + + + + Class to represent an IPsec security association context. + + + + + ID of the context. + + + + + Inbound security association. + + + + + Outbound security association. + + + + + Base security association class. + + + + + Index of the security parameter (SPI). + + + + + Transform type. + + + + + IPsec SA authentication information. + + + + + Type of authentication. + + + + + Authentication configuration. + + + + + Module ID for the crypto. + + + + + Authentication key. + + + + + IPsec SA authentication information. + + + + + Type of cipher. + + + + + Cipher configuration. + + + + + Module ID for the crypto. + + + + + Cipher key. + + + + + IPsec SA authentication information. + + + + + Type of authentication. + + + + + Authentication configuration. + + + + + Modify ID for the crypto. + + + + + Authentication key. + + + + + Type of cipher. + + + + + Cipher configuration. + + + + + Module ID for the crypto. + + + + + Cipher key. + + + + + Class to represent an IPsec token. + + + + + Type of token. + + + + + Token principal. + + + + + Token mode. + + + + + Handle to the token. + + + + + Get the token from the IKEEXT service. + + True to throw on error. + The token. + + + + Get the token from the IKEEXT service. + + The token. + + + + IPsec traffic type. + + + + + Network interface type. + + See https://www.iana.org/assignments/ianaiftype-mib + + + + Network layer address type. + + + + + Type of network tunnel. + + + + + Endpoint implementation for a HyperV socket. + + + + + Address family. + + + + + Protocol type for HyperV sockets. + + + + + Default constructor. + + + + + Constructor. + + + + + Get or set the service ID. + + + + + Get or set the VM ID. + + + + + Address family. + + + + + Serialize the socket address. + + The serialized address. + + + + Create a endpoint from a socket address. + + The socket address. + The created endpoint. + + + + Overridden ToString method. + + The endpoint as a string. + + + + Overridden equals method. + + The object to compare. + True if the objects are equal. + + + + Get endpoint hash code. + + The hashcode. + + + + GUIDs for HyperV Sockets. + + + + + Allows accepting connections from all partitions. + + + + + Broadcast. Send to all sockets. + + + + + Allows accepting connections form all child partitions. + + + + + Connect or bind to the loopback address. + + + + + Connect to the parent container. + + + + + Connect to the silo host container. + + + + + VSOCK template GUID. + + + + + Create an address for a VSOCK port. + + The VSOCK port. + The address. + + + + Checks if an address is a VSOCK address. + + The address to check. + True if a VSOCK address. + + + + Get the port for a VSOCK address. + + The address to query. + The VSOCK port. + Throw if not a valid VSOCK address. + + + + Convert an address to a string. + + The address to convert. + The converted address. If not symbolic name found will return the GUID as a string. + + + + Class to represent current socket security configuration. + + + + + Access token for the peer application. + + + + + Access token for the peer machine. + + + + + Socket security flags. + + + + + Security association ID for main mode. + + + + + Security association ID for quick mode. + + + + + Negotiation windows error. + + + + + Security association lookup context. Can be used to bypass security + checks for querying the security association information from the + firewall. + + + + + Dispose method. + + + + + Socket security IPsec flags. + + + + + Flags for querying socket security fields. + + + + + Flags for querying socket security information. + + + + + Socket security query flags. + + + + + Socket security setting flags. + + + + + Settings for socket security + + + + + The security flags. + + + + + The IPsec flags. + + + + + AuthIP MM policy key. + + + + + AuthIP QM policy key. + + + + + User credentials. + + + + + Authentication ID of a user, needs kernel mode to set. + + + + + Utilities for socket security. + + + + + Impersonate the socket's peer. + + The socket to impersonate. + Optional peer address. Only needed for datagram sockets. + True to throw on error. + The impersonation context. + + + + Impersonate the socket's peer. + + The socket to impersonate. + Optional peer address. Only needed for datagram sockets. + The impersonation context. + + + + Impersonate the socket's peer. + + The TCP client to impersonate. + True to throw on error. + The impersonation context. + + + + Impersonate the socket's peer. + + The TCP client to impersonate. + The impersonation context. + + + + Query the socket security information. + + The socket to query. + Optional peer address. Only needed for datagram sockets. + Optional desired access for peer tokens. If set to None then no tokens will be returned. + True to throw on error. + The socket security information. + + + + Query the socket security information. + + The socket to query. + Optional peer address. Only needed for datagram sockets. + Optional desired access for peer tokens. If set to None then no tokens will be returned. + The socket security information. + + + + Query the socket security information. + + The TCP client to query. + Optional desired access for peer tokens. If set to None then no tokens will be returned. + True to throw on error. + The socket security information. + + + + Query the socket security information. + + The TCP client to query. + Optional desired access for peer tokens. If set to None then no tokens will be returned. + The socket security information. + + + + Set the socket security information. + + The socket to set. + The security settings. + True to throw on error. + The NT status code. + + + + Set the socket security information. + + The socket to set. + The security settings. + + + + Set the socket security information. + + The TCP listener to set. + The security settings. + True to throw on error. + The NT status code. + + + + Set the socket security information. + + The TCP listener to set. + The security settings. + + + + Set the socket security information. + + The TCP client to set. + The security settings. + True to throw on error. + The NT status code. + + + + Set the socket security information. + + The TCP client to set. + The security settings. + + + + Set target peer for socket. + + The socket to set. + The target name. + Optional peer address. Only needed for datagram sockets. + True to throw on error. + The NT status code. + + + + Set target peer for socket. + + The socket to set. + The target name. + Optional peer address. Only needed for datagram sockets. + + + + Set target peer for socket. + + The socket to set. + The target name. + True to throw on error. + The NT status code. + + + + Set target peer for socket. + + The socket to set. + The target name. + + + + Set target peer for socket. + + The socket to set. + The target name. + True to throw on error. + The NT status code. + + + + Set target peer for socket. + + The socket to set. + The target name. + + + + Delete target peer for socket. + + The socket to set. + Peer address. + True to throw on error. + The NT status code. + + + + Security protocol for a socket. + + + + + Endpoint implementation for a AF_UNIX socket. + + + + + Default constructor. + + + + + Constructor. + + The path to the unix socket. + + + + Get or set the path. + + + + + Address family. + + + + + Serialize the socket address. + + The serialized address. + + + + Create a endpoint from a socket address. + + The socket address. + The created endpoint. + + + + Overridden ToString method. + + The endpoint as a string. + + + + Overridden equals method. + + The object to compare. + True if the objects are equal. + + + + Get endpoint hash code. + + The hashcode. + + + + A class to represent a TLS record. + + + + + TLS record type. + + + + + Version of protocol. + + + + + The record data. + + + + + Parse a TLS record from a binary reader. + + The reader to read from. + The parsed TLS record. + + + + Parse a TLS record from a byte array. + + The byte array. + The parsed TLS record. + + + + Type for a TLS record. + + + + + Change cipher spec. + + + + + Alert. + + + + + Handshake. + + + + + Application data. + + + + + Class to represent an ALPC port. + + + + + Disconnect this port. + + Disconection flags. + True to throw on error. + The NT status code. + + + + Disconnect this port. + + Disconection flags. + + + + Disconnect this port. + + + + + Cancel a message based on a context attribute. + + Cancellation flags. + The context attributes. + True to throw on error. + The NT status code. + + + + Cancel a message based on a context attribute. + + Cancellation flags. + The context attributes. + + + + Cancel a message based on a context attribute. + + The context attributes. + + + + Send and receive messages on an ALPC port. + + Send/Receive flags. + The message to send. Optional. + The attributes to send with the message. Optional. + The message to receive. Optional. + The attributes to receive with the message. Optional. + Time out for the send/receive. + True to throw on error. + The NT status code. + The attribute parameters will be repopulated with the attribute results. + + + + Send and receive messages on an ALPC port. + + Send/Receive flags. + The message to send. Optional. + The attributes to send with the message. Optional. + The message to receive. Optional. + The attributes to receive with the message. Optional. + Time out for the send/receive. + True if completed successfully, false if timed out. + Thrown on error. + + + + Send a message on an ALPC port. + + Send flags. + The message to send. Optional. + The attributes to send with the message. Optional. + Time out for the send/receive. + True to throw on error. + The NT status code. + The attribute parameters will be repopulated with the attribute results. + + + + Send a message on an ALPC port. + + Send flags. + The message to send. Optional. + The attributes to send with the message. Optional. + Time out for the send/receive. + The attribute parameters will be repopulated with the attribute results. + True if completed successfully, false if timed out. + Thrown on error. + + + + Send a message on an ALPC port. + + Send flags. + The message to send. Optional. + The attribute parameters will be repopulated with the attribute results. + + + + Receive a message on an ALPC port. + + Receive flags. + The maximum length to receive. + The attributes to receive with the message. Optional. + Time out for the send/receive. + True to throw on error. + The received message. + The attribute parameters will be repopulated with the attribute results. + + + + Receive a message on an ALPC port. + + Receive flags. + The maximum length to receive. + The attributes to receive with the message. Optional. + Time out for the send/receive. + The received message. + The attribute parameters will be repopulated with the attribute results. + + + + Receive a message on an ALPC port. + + Receive flags. + The maximum length to receive. + The attributes to receive with the message. Optional. + The received message. + The attribute parameters will be repopulated with the attribute results. + + + + Receive a message on an ALPC port. + + Receive flags. + The maximum length to receive. + The received message. + The attribute parameters will be repopulated with the attribute results. + + + + Receive a message on an ALPC port. + + Receive flags. + The attributes to receive with the message. Optional. + Time out for the send/receive. + True to throw on error. + The received message. + The attribute parameters will be repopulated with the attribute results. + The type of structure to receive. + + + + Receive a message on an ALPC port. + + Receive flags. + The attributes to receive with the message. Optional. + Time out for the send/receive. + The attribute parameters will be repopulated with the attribute results. + The type of structure to receive. + + + + Receive a message on an ALPC port. + + Receive flags. + The attributes to receive with the message. Optional. + The attribute parameters will be repopulated with the attribute results. + The type of structure to receive. + + + + Receive a message on an ALPC port. + + Receive flags. + The type of structure to receive. + + + + Impersonate client of port for a message. + + The message send by the client. + Impersonation flags. + Required impersonation level. Need to set RequiredImpersonationLevel flag as well. + True to throw on error. + Thread impersonation context. + + + + Impersonate client of port for a message. + + The message send by the client. + Impersonation flags. + Required impersonation level. Need to set RequiredImpersonationLevel flag as well. + Thread impersonation context. + + + + Impersonate client of port for a message. + + The message send by the client. + Thread impersonation context. + + + + Impersonate client container of port for a message. + + The message send by the client. + Impersonation flags. + True to throw on error. + Thread impersonation context. + + + + Impersonate client container of port for a message. + + The message send by the client. + Impersonation flags. + Thread impersonation context. + + + + Impersonate client container of port for a message. + + The message send by the client. + Thread impersonation context. + + + + Open the process of the message sender. + + The sent message. + Optional flags. Currently none defined. + The desired access for the process. + Optional object attributes. + True to throw on error. + The opened process object. + + + + Open the process of the message sender. + + The sent message. + Optional flags. Currently none defined. + The desired access for the process. + Optional object attributes. + The opened process object. + + + + Open the process of the message sender. + + The sent message. + The desired access for the process. + The opened process object. + + + + Open the process of the message sender with maximum privileges. + + The sent message. + The opened process object. + + + + Open the thread of the message sender. + + The sent message. + Optional flags. Currently none defined. + The desired access for the thread. + Optional object attributes. + True to throw on error. + The opened thread object. + + + + Open the thread of the message sender. + + The sent message. + Optional flags. Currently none defined. + The desired access for the thread. + Optional object attributes. + The opened thread object. + + + + Open the thread of the message sender. + + The sent message. + The desired access for the thread. + The opened thread object. + + + + Open the thread of the message sender with maximum privileges. + + The sent message. + The opened thread object. + + + + Associate an IO completion port with this ALPC port. + + The IO completion object. + Optional completion key. + True to throw on error. + The NT status code. + + + + Associate an IO completion port with this ALPC port. + + The IO completion object. + Optional completion key. + The NT status code. + + + + Check if the current SID matches the connected SID. + + The SID to compare. + True to throw on error. + True if the connected SID matches the specified SID. + + + + Check if the current SID matches the connected SID. + + The SID to compare. + True if the connected SID matches the specified SID. + + + + Create a new port section. + + Flags for the port section. + Optional backing section. + Size of the section to create. + True to throw on error. + The created port section. + + + + Create a new port section. + + Flags for the port section. + Optional backing section. + Size of the section to create. + The created port section. + + + + Create a new port section. + + Flags for the port section. + Size of the section to create. + The created port section. + + + + Create a new port section. + + Size of the section to create. + The created port section. + + + + Get a handle entry for a message. + + The handle index to get. + The associated message. + True to throw on error. + The ALPC handle entry. + + + + Get a handle entry for a message. + + The handle index to get. + The associated message. + The ALPC handle entry. + + + + Create a security context. + + Flags for the creation. + Security quality of service. + True to throw on error. + The created security context. + + + + Create a security context. + + Flags for the creation. + Security quality of service. + The created security context. + + + + Create a security context. + + Security quality of service. + The created security context. + + + + Create a security context. + + The created security context. + + + + Set port attribute flags. + + The flags to set. + True to throw on error. + The NT status code. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Port flags. + + + + + Port sequence number. + + + + + Port context. + + + + + Class to represent an ALPC client port. + + + + + Connect to an ALPC port. + + The path to the port. + Object attributes for the handle. Optional. + Attributes for the port. Optional. + Send flags for the initial connection message. + Required SID for the server. + Initial connection message. + Outbound message attributes. + Inbound message atributes. + Connect timeout. + True to throw on error. + The connected ALPC port. + + + + Connect to an ALPC port. + + The path to the port. + Object attributes for the handle. Optional. + Attributes for the port. Optional. + Send flags for the initial connection message. + Required SID for the server. + Initial connection message. + Outbound message attributes. + Inbound message atributes. + Connect timeout. + The connected ALPC port. + Thrown on error. + + + + Connect to an ALPC port. + + The name of the port to connect to. + Attributes for the port. + The connected ALPC port object. + + + + Connect to an ALPC port. + + Object attribute for the port name. + Object attributes for the handle. Optional. + Attributes for the port. Optional. + Send flags for the initial connection message. + Required security descriptor for the server. + Initial connection message. + Outbound message attributes. + Inbound message atributes. + Connect timeout. + True to throw on error. + The connected ALPC port. + Only available on Windows 8+. + + + + Connect to an ALPC port. + + Object attribute for the port name. + Object attributes for the handle. Optional. + Attributes for the port. Optional. + Send flags for the initial connection message. + Required security descriptor for the server. + Initial connection message. + Outbound message attributes. + Inbound message atributes. + Connect timeout. + The connected ALPC port. + Thrown on error. + + + + Connect to an ALPC port. + + Object attribute for the port name. + Attributes for the port. + The connected ALPC port object. + + + + Get the server process information. + + True to throw on error. + The process information. + + + + Get the server process information. + + The process information. + + + + Get the server process ID. + + + + + Get the server session ID. + + + + + Class to represent an ALPC server port. + + + + + Create an ALPC port. + + The object attributes for the port. + The attributes for the port. + True to throw on error. + The created object. + + + + Create an ALPC port. + + The object attributes for the port. + The attributes for the port. + The created object. + Thrown on error. + + + + Create an ALPC port. + + The name of the port to create. + The attributes for the port. + The created object. + Thrown on error. + + + + Accept a new connection on a port. + + The message send flags. + Object attributes. Optional. + The attributes for the port. + Port context. Optional. + Connect request message. + Connect request attributes. + True to accept the connection. + True to throw on error. + The accepted port. + + + + Accept a new connection on a port. + + The message send flags. + Object attributes. Optional. + The attributes for the port. + Port context. Optional. + Connect request message. + Connect request attributes. + True to accept the connection. + The accepted port. + + + + Accept a new connection on a port. + + The message send flags. + Connect request message. + Connect request attributes. + True to accept the connection. + The accepted port. + + + + Access rights for ALPC + + + + + ALPC Port Information Class + + + + + If set then object duplication won't complete. Used by RPC to ensure + multi-handle attributes don't fail when receiving. + + + + + Use in a reply to release the view. + + + + + Automatically release the view once it's passed to the receiver. + + + + + Make the data view secure. + + + + + When used all structures passed to kernel need to be 64 bit versions. + + + + + Static utilities for ALPC. + + + + + Wait for the result to complete. This could be waiting on an event + or the file handle. + + Wait timeout. Will cancel the operation if it times out. + Returns true if the wait completed successfully. + If true is returned then status and information can be read out. + + + + Wait for the result to complete asynchronously. This could be waiting on an event + or the file handle. + + Cancellation token. + Returns true if the wait completed successfully. + If true is returned then status and information can be read out. + + + + Return the status information field. + + Thrown if not complete. + + + + Return the status information field. (32 bit) + + Thrown if not complete. + + + + Get completion status code. + + Thrown if not complete. + + + + Returns true if the call is pending. + + + + + Dispose object. + + + + + Reset the file result so it can be reused. + + + + + Cancel the pending IO operation. + + + + + Cancel the pending IO operation. + + True to throw on error. + The NT status code. + + + + Class to handle NT atoms + + + + + Add a global atom name + + The name to add + Flags for the add. + True to throw on error. + A reference to the atom + + + + Add a global atom name + + The name to add + Flags for the add. + A reference to the atom + + + + Add a global atom name + + The name to add + True to throw on error. + A reference to the atom + + + + Add a global atom name + + The name to add + A reference to the atom + + + + Find a global atom by name. + + The name of the atom. + True to throw on error. + The found atom. + + + + Find a global atom by name. + + The name of the atom. + The found atom. + + + + Query if a global atom exists. + + The atom to check. + True if the atom exists. + + + + Query if the atom exists. + + The atom to check. + Specify true to check for a global atom, otherwise gets a user atom. + True if the atom exists. + + + + Open a global atom by number. + + The atom to open. + True to check atom exists. + True to open a global atom, otherwise a user atom. + True to throw on error. + The atom object. + + + + Open a global atom by number. + + The atom to open. + True to check atom exists. + True to throw on error. + The atom object. + + + + Open a global atom by number. + + The atom to open. + True to check atom exists. + The atom object. + + + + Open a global atom by number. + + The atom to open. + The atom object. + + + + Enumerate all atoms. + + An enumeration of all atoms on the system. + + + + Enumerate all global atoms. + + An enumeration of all atoms on the system. + + + + Delete a global atom. + + True to throw on error. + The NT status code. + + + + Delete a global atom. + + + + + Get the name of the atom. + + True to throw on error. + The name of the atom. + + + + The atom value + + + + + Get the name of the atom. + + The name of the atom + + + + If true indicates this is a global atom, otherwise it's a user atom. + + + + + Class representing a NT Debug object + + + + + Create a debug object + + The debug object name (can be null) + The root directory for relative names + Debug object flags. + The debug object + + + + Create a debug object + + Desired access for the debug object + Object attributes for debug object + Debug object flags. + The debug object + + + + Create a debug object + + Desired access for the debug object + Object attributes for debug object + Debug object flags. + True to throw an exception on error. + The NT status code and object result. + + + + Create a debug object + + The debug object + + + + Open a named debug object + + The debug object name + The root directory for relative names + Desired access for the debug object + The debug object + + + + Open a named debug object + + The object attributes to open. + Desired access for the debug object + The debug object + + + + Open a named debug object + + The object attributes to open. + Desired access for the debug object + True to throw an exception on error. + The NT status code and object result. + + + + Open the current thread's debug object. + + True to throw on error. + The opened debug object. Returns null if no object exists. + + + + Open the current thread's debug object. Returns null if no object exists. + + + + + Attach to an active process. + + The process to debug. + True to throw on error. + The NT status code. + + + + Attach to an active process. + + The process ID to debug. + True to throw on error. + The NT status code. + + + + Attach to an active process. + + The process to debug. + + + + Attach to an active process. + + The process ID to debug. + + + + Detach a process from this debug object. + + The process to remove. + True to throw on error. + The NT status code. + + + + Detach a process from this debug object. + + The process to remove. + + + + Detach a process from this debug object. + + The process ID to remove. + True to throw on error. + The NT status code. + + + + Detach a process from this debug object. + + The process ID to remove. + + + + Set kill process on close flag. + + The flag state. + True to throw on error. + The NT status code. + + + + Set kill process on close flag. + + The flag state. + + + + Continue the debugged process. + + The client ID for the process and thread IDs. + The continue status code. + True to throw on error. + The NT status code. + + + + Continue the debugged process. + + The process ID to continue. + The thread ID to continue. + The continue status code. + True to throw on error. + The NT status code. + + + + Continue the debugged process. + + The client ID for the process and thread IDs. + The continue status code. + + + + Continue the debugged process. + + The process ID to continue. + The thread ID to continue. + The continue status code. + + + + Continue the debugged process with a success code. + + The process ID to continue. + The thread ID to continue. + + + + Wait for a debug event. + + True to set the thread as alertable. + Wait timeout. + True to throw on error. + The debug event. + + + + Wait for a debug event. + + True to set the thread as alertable. + Wait timeout. + The debug event. + + + + Wait for a debug event. + + Wait timeout. + The debug event. + + + + Wait for a debug event. + + Wait timeout in milliseconds. + The debug event. + + + + Wait for a debug event. + + The debug event. + + + + Class which represents a desktop object. + + + + + Open a desktop by name. + + The object attributes for opening. + Flags for opening the desktop. + Desired access. + True to throw on error. + The instance of the desktop. + Thrown on error. + + + + Open a desktop by name. + + The object attributes for opening. + Flags for opening the desktop. + Desired access. + The instance of the desktop. + Thrown on error. + + + + Open a desktop by name. + + The name of the desktop. + Optional root object + An instance of NtDesktop. + Thrown on error. + + + + Open a desktop by name. + + The name of the desktop. + An instance of NtDesktop. + + + + Create a new desktop. + + The object attributes for opening. + Flags for opening the desktop. + Desired access. + True to throw on error. + Device name. + Device mode. + Heap size. + An instance of NtDesktop. + + + + Create a new desktop. + + The object attributes for opening. + Flags for opening the desktop. + Desired access. + Device name. + Device mode. + Heap size. + An instance of NtDesktop. + + + + Create a new desktop. + + The name of the desktop. + Optional root object + An instance of NtDesktop. + + + + Create a new desktop. + + The name of the desktop. + An instance of NtDesktop. + + + + Get the desktop for a thread. + + The thread ID of the thread. + True to throw on error. + The desktop result. + + + + Get the desktop for a thread. + + The thread ID of the thread. + The desktop result. + + + + Get desktop for current thread. + + + + + Get list of top level Windows for this Desktop. + + + + + Close the Desktop. This is different from normal Close as it destroys the Desktop. + + True to throw on error. + The NT status. + + + + NT Directory Object class + + + + + Open a directory object + + The object attributes to use for the open call. + Access rights for directory object + True to throw an exception on error. + The NT status code and object result. + Thrown on error and throw_on_error is true. + + + + Open a directory object + + The object attributes to use for the open call. + Access rights for directory object + The directory object + Throw on error + + + + Open a directory object by name + + The directory object to open + Optional root directory to parse from + Access rights for directory object + The directory object + Throw on error + + + + Open a directory object by name + + The directory object to open + Optional root directory to parse from + Access rights for directory object + True to throw an exception on error. + The directory object + Throw on error + + + + Open a directory object by full name + + The directory object to open + The directory object + Throw on error + + + + Create a directory object with a shadow + + The object attributes to create the directory with + The desired access to the directory + The shadow directory + Flags for creation. + True to throw an exception on error. + The NT status code and object result. + Thrown on error and throw_on_error is true. + + + + Create a directory object with a shadow + + The object attributes to create the directory with + The desired access to the directory + The shadow directory + True to throw an exception on error. + The NT status code and object result. + Thrown on error and throw_on_error is true. + + + + Create a directory object with a shadow + + The object attributes to create the directory with + The desired access to the directory + The shadow directory + Flags for creation. + The directory object + Thrown on error + + + + Create a directory object with a shadow + + The object attributes to create the directory with + The desired access to the directory + The shadow directory + The directory object + Thrown on error + + + + Create a directory object + + The directory object to create, if null will create a unnamed directory object + The desired access to the directory + Root directory from where to start the creation operation + The directory object + Thrown on error + + + + Create a directory object with a shadow + + The directory object to create, if null will create a unnamed directory object + The desired access to the directory + Root directory from where to start the creation operation + The shadow directory + The directory object + Thrown on error + + + + Create a directory object + + The directory object to create, if null will create a unnamed directory object + The directory object + Thrown on error + + + + Open a session directory. + + The session ID to open + Sub directory to open. + Desired access to open directory. + The directory object + Thrown on error + + + + Open the current session directory. + + The directory object + Thrown on error + + + + Open the current session directory. + + The directory object + Thrown on error + + + + Open basenamedobjects for a session. + + The session ID to open + The directory object + Thrown on error + + + + Open basenamedobjects for current session. + + The directory object + Thrown on error + + + + Get the based named object's directory for a session. + + The session ID + The based named object's directory. + + + + Get the based named object's directory for the current session. + + The based named object's directory. + + + + Get the a session's Windows object directory. + + The session id to use. + The path to the windows object directory. + + + + Get the current session's Windows object directory. + + The path to the windows object directory. + + + + Get the a session's Window Stations object directory. + + The session id to use. + The path to the window stations object directory. + + + + Get the current session's Window Stations object directory. + + The path to the window stations object directory. + + + + Open dos devices directory for a token. + + The directory object + Thrown on error + + + + Open dos devices directory for current effective token. + + The directory object + Thrown on error + + + + Create a private namespace directory. + + Object attributes for the directory + Boundary descriptor for the namespace + Desired access for the directory + True to throw an exception on error. + The directory object + Thrown on error + + + + Create a private namespace directory. + + Object attributes for the directory + Boundary descriptor for the namespace + Desired access for the directory + The directory object + Thrown on error + + + + Create a private namespace directory. + + Boundary descriptor for the namespace + The directory object + Thrown on error + + + + Open a private namespace directory. + + Object attributes for the directory + Boundary descriptor for the namespace + Desired access for the directory + True to throw an exception on error. + The directory object + Thrown on error + + + + Open a private namespace directory. + + Object attributes for the directory + Boundary descriptor for the namespace + Desired access for the directory + The directory object + Thrown on error + + + + Open a private namespace directory. + + Boundary descriptor for the namespace + The directory object + Thrown on error + + + + Returns whether a directory exists for this path. + + The path to the entry. + The root directory. + True if the directory exists for the specified path. + + + + Get the type of a directory entry by path. + + The path to the directory entry + The root object to look up if path is relative + The type name, or null if it can't be found. + + + + Query the directory for a list of entries. + + The list of entries. + Thrown on error + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + Specify the desired access for the directory + True to recurse into sub directories. + Specify max recursive depth. -1 to not set a limit. + True if all children were visited. + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + True to recurse into sub directories. + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + Specify the desired access for the directory + True to recurse into sub directories. + + + + Deletes a private namespace. If not a private namespace this does nothing. + + + + + Deletes a private namespace. If not a private namespace this does nothing. + + True to throw on error. + The NT status code. + + + + Get a directory entry based on a name. + + The name of the entry. + The typename to verify against, can be null. + True if look up is case sensitive. + The directory entry, or null if it can't be found. + + + + Get a directory entry based on a name. + + The name of the entry. + The directory entry, or null if it can't be found. + + + + Check whether a directory is exists relative to the current directory. + + Relative path to directory + True if the directory exists. + + + + Set the session ID for this directory to the current session. + + True to throw on error. + The NT status code. + Thrown on error. + Needs SeTcbPrivilege. + + + + Set the session object for this directory to the current session. + + True to throw on error. + The NT status code. + Thrown on error. + Needs SeTcbPrivilege. + + + + Returns whether this object is a container. + + + + + Directory access rights. + + + + + Base class to implement an enclave. + + + + + The base address of the enclave. + + + + + The type of enclave. + + + + + Dispose of the enclave. + + + + + Close the enclave. + + + + + Call a method in the enclave. + + The routine address to call. + The parameter to pass to the routine. + True to wait for a free thread. + True to throw on error. + The return value from the call. + + + + Call a method in the enclave. + + The routine address to call. + The parameter to pass to the routine. + True to wait for a free thread. + The return value from the call. + + + + Type of enclave. + + + + + Class to represent a VBS enclave. + + + + + Create a VBS enclave. + + The process to create the enclave in. + Size of the enclave. + Flags for the enclave. + Owner ID. Must be 32 bytes. + True to throw on error. + The created enclave. + + + + Create a VBS enclave. + + The process to create the enclave in. + Size of the enclave. + Flags for the enclave. + Owner ID. Must be 32 bytes. + The created enclave. + + + + Get a procedure address in the loaded enclave. + + The name of the procedure. + True to throw on error. + The address of the procedure. + + + + Get a procedure address in the loaded enclave. + + The name of the procedure. + The address of the procedure. + + + + Terminate the enclave. + + Flags for the terminate. + True to throw on error. + The NT status code. + + + + Terminate the enclave. + + Flags for the terminate. + The NT status code. + + + + Load a module into the enclave. + + The name of the module + Flags or path. + True to throw on error. + The NT status. + + + + Load a module into the enclave. + + The name of the module + Flags or path. + The NT status. + + + + Initialize the enclave. + + The number of threads to create. + True to throw on error. + The number of created threads. + + + + Initialize the enclave. + + The number of threads to create. + The number of created threads. + + + + Dispose of the enclave. + + + + + Class to represent a kernel transaction enlistment. + + + + + Create a new enlistment object. + + The object attributes + Desired access for the handle + Resource manager to handle the enlistment. + The transaction to enlist. + Optional create options. + Notification mask. + Enlistment key returned during notification. + True to throw an exception on error. + The created enlistment and NT status code. + + + + Create a new enlistment object. + + The object attributes + Desired access for the handle + Resource manager to handle the enlistment. + The transaction to enlist. + Optional create options. + Notification mask. + Enlistment key returned during notification. + The created enlistment. + + + + Open a existing new enlistment object. + + The object attributes + Desired access for the handle + Resource manager handling the enlistment. + ID of the enlistment to open. + True to throw an exception on error. + The opened enlistment and NT status code. + + + + Open a existing new enlistment object. + + The object attributes + Desired access for the handle + Resource manager handling the enlistment. + ID of the enlistment to open. + The opened enlistment. + + + + Get a default mask for creating an enlistment object. + + The creation option to get default mask for. + A default working mask. + + + + Commit complete enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Commit enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Preprepare complete enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Preprepare enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Prepare complete enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Prepare enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Rollback complete enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Rollback enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Read only enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Recover enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Single phase reject enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Commit complete enlistment. + + Optional virtual clock value. + + + + Commit enlistment. + + Optional virtual clock value. + + + + Preprepare complete enlistment. + + Optional virtual clock value. + + + + Preprepare enlistment. + + Optional virtual clock value. + + + + Prepare complete enlistment. + + Optional virtual clock value. + + + + Prepare enlistment. + + Optional virtual clock value. + + + + Rollback complete enlistment. + + Optional virtual clock value. + + + + Rollback enlistment. + + Optional virtual clock value. + + + + Read only enlistment. + + Optional virtual clock value. + + + + Recover enlistment. + + Optional virtual clock value. + + + + Single phase reject enlistment. + + Optional virtual clock value. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get enlistment ID. + + + + + Get associated transaction ID. + + + + + Get resource manager ID. + + + + + Get CRM enlistment ID. + + + + + Get CRM transaction manager ID. + + + + + Get CRM resource manager ID. + + + + + Get or set recovery information. + + + + + Class to represent an NT trace GUID. + + + + + Class representing a NT Event object + + + + + Create an event object + + The path to the event + The root object for relative path names + The type of the event + The initial state of the event + True to throw on error. + The event object + + + + Create an event object + + The path to the event + The root object for relative path names + The type of the event + The initial state of the event + The event object + + + + Create an event object + + The event object attributes + The type of the event + The initial state of the event + The desired access for the event + The event object + + + + Create an event object + + The event object attributes + The type of the event + The initial state of the event + The desired access for the event + True to throw an exception on error. + The NT status code and object result. + + + + Create an event object + + The path to the event + The type of the event + The initial state of the event + The event object + + + + Open an event object + + The path to the event + The root object for relative path names + The desired access for the event + The event object + + + + Open an event object + + The event object attributes + The desired access for the event + The event object. + + + + Open an event object + + The event object attributes + The desired access for the event + True to throw an exception on error. + The NT status code and object result. + + + + Open an event object + + The path to the event + The root object for relative path names + The event object + + + + Open an event object + + The path to the event + The event object + + + + Set the event state + + True to throw an exception on error. + The previous state of the event and NT status. + + + + Set the event state + + The previous state of the event + + + + Clear the event state + + True to throw an exception on error. + The NT status code. + + + + Clear the event state + + + + + Pulse the event state. + + True to throw an exception on error. + The previous state of the event and NT status. + + + + Pulse the event state. + + The previous state of the event + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get event type. + + + + + Get current event state. + + + + + Type of Event object. + + + + + Manual reset event. + + + + + Automatic reset event. + + + + + Exception class representing an NT status error. + + + + + Constructor + + Status result + + + + Returns the contained NT status code + + + + + Returns a string form of the NT status code. + + + + + Class representing a NT File object + + + + + Create a new file + + The object attributes + Desired access for the file + Attributes for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + Optional allocation size. + True to throw an exception on error. + The NT status code and object result. + + + + Create a new file + + The object attributes + Desired access for the file + Attributes for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + Optional allocation size. + The created/opened file object. + + + + Create a new file + + The object attributes + Desired access for the file + Attributes for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + True to throw an exception on error. + The NT status code and object result. + + + + Create a new file + + The object attributes + Desired access for the file + Attributes for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + The created/opened file object. + + + + Create a new file + + The path to the file + A root object to parse relative filenames + Desired access for the file + Attributes for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + True to throw an exception on error. + The created/opened file object. + + + + Create a new file + + The path to the file + A root object to parse relative filenames + Desired access for the file + Attributes for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + The created/opened file object. + + + + Create a new file + + The path to the file + Desired access for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + The created/opened file object. + + + + Create a new named pipe file + + The object attributes + Desired access for the file + Share access for the file + Open options for file + Disposition when opening the file + Pipe completion mode + Default timeout + Input quota + Maximum number of instances (-1 for infinite) + Output quota + Type of pipe to create + Pipe read mode + True to throw an exception on error. + The NT status code and object result. + Thrown on error. + + + + Create a new named pipe file + + The object attributes + Desired access for the file + Share access for the file + Open options for file + Disposition when opening the file + Pipe completion mode + Default timeout + Input quota + Maximum number of instances (-1 for infinite) + Output quota + Type of pipe to create + Pipe read mode + The file instance for the pipe. + Thrown on error. + + + + Create a new named pipe file + + The path to the pipe file + A root object to parse relative filenames + Desired access for the file + Share access for the file + Open options for file + Disposition when opening the file + Pipe completion mode + Default timeout + Input quota + Maximum number of instances (-1 for infinite) + Output quota + Type of pipe to create + Pipe read mode + True to throw an exception on error. + The file instance for the pipe. + Thrown on error. + + + + Create a new named pipe file + + The path to the pipe file + A root object to parse relative filenames + Desired access for the file + Share access for the file + Open options for file + Disposition when opening the file + Pipe completion mode + Default timeout + Input quota + Maximum number of instances (-1 for infinite) + Output quota + Type of pipe to create + Pipe read mode + The file instance for the pipe. + Thrown on error. + + + + Create an anonymous named pipe pair. + + True to throw on error. + The named pipe pair. + + + + Create an anonymous named pipe pair. + + The named pipe pair. + + + + Create a new named mailslot file + + The object attributes + Desired access for the file + Open options for file + Mailslot quota + Maximum message size (0 for any size) + Read Timeout. + True to throw on error. + The file instance for the mailslot. + Thrown on error. + + + + Create a new named mailslot file + + The object attributes + Desired access for the file + Open options for file + Mailslot quota + Maximum message size (0 for any size) + Read timeout in MS (<0 is infinite) + True to throw on error. + The file instance for the mailslot. + Thrown on error. + + + + Create a new named mailslot file + + The object attributes + Desired access for the file + Open options for file + Mailslot quota + Maximum message size (0 for any size) + Read timeout in MS ( <0 is infinite) + The file instance for the mailslot. + Thrown on error. + + + + Create a new named mailslot file + + The path to the mailslot file + A root object to parse relative filenames + Desired access for the file + Open options for file + Mailslot quota + Maximum message size (0 for any size) + Timeout in MS ( <0 is infinite) + The file instance for the mailslot. + Thrown on error. + + + + Open a file + + The object attributes + The desired access for the file handle + The file share access + File open options + True to throw an exception on error. + The NT status code and object result. + + + + Open a file + + The object attributesf + The desired access for the file handle + The file share access + File open options + The opened file + Thrown on error. + + + + Open a file + + The path to the file + The root directory if path is relative. + The desired access for the file handle + The file share access + File open options + True to throw an exception on error. + The opened file + Thrown on error. + + + + Open a file + + The path to the file + The root directory if path is relative. + The desired access for the file handle + The file share access + File open options + The opened file + Thrown on error. + + + + Open a file + + The path to the file + The root directory if path is relative. + The desired access for the file handle + The opened file + Thrown on error. + + + + Get the object ID of a file as a string + + The path to the file + The object ID as a string + Thrown on error. + + + + Open a file by its object ID + + A handle to the volume on which the file resides. + The object ID as a binary string + The desired access for the file + File share access + Open options. + True to throw on error + The opened file object + + + + Open a file by its object ID + + A handle to the volume on which the file resides. + The object ID as a binary string + The desired access for the file + File share access + Open options. + The opened file object + Thrown on error. + + + + Open a file by its ID + + A handle to the volume on which the file resides. + The file's ID. Can be a file reference number or an Object ID. + The desired access for the file + File share access + Open options. + True to throw on error + The opened file object + + + + Open a file by its ID + + A handle to the volume on which the file resides. + The file's ID. Can be a file reference number or an Object ID. + The desired access for the file + File share access + Open options. + The opened file object + + + + Open a file by its object ID + + A handle to the volume on which the file resides. + The file ID. + The desired access for the file + File share access + Open options. + True to throw on error + The opened file object + + + + Open a file by its file ID + + A handle to the volume on which the file resides. + The file ID. + The desired access for the file + File share access + Open options. + The opened file object + Thrown on error. + + + + Open a file by its file ID + + The path to the volume which contains the file. + The file ID. + The desired access for the file + File share access + Open options. + True to throw on error + The opened file object + + + + Open a file by its file ID + + The path to the volume which contains the file. + The file ID. + The desired access for the file + File share access + Open options. + The opened file object + + + + Delete a file + + The object attributes for the file. + True to throw an exception on error + The status result of the delete + + + + Delete a file + + The object attributes for the file. + + + + Delete a file + + The path to the file. + + + + Rename file. + + The file to rename. + The target NT path. + Thrown on error. + + + + Create a hardlink to another file. + + The file to hardlink to. + The desintation hardlink path. + Thrown on error. + + + + Create a mount point. + + The path to the mount point to create. + The substitute name to reparse to. + The print name to display (can be null). + + + + Create a symlink. + + The path to the mount point to create. + True to create a directory symlink, false for a file. + The substitute name to reparse to. + The print name to display. + Additional flags for the symlink. + + + + Get the reparse point buffer for the file. + + The path to the reparse point. + The reparse point buffer. + + + + Delete the reparse point buffer. + + The path to the reparse point. + The original reparse buffer. + + + + Query attributes of a file. + + The object attributes. + True to throw on error. + The file attributes. + + + + Query attributes of a file. + + The object attributes. + The file attributes. + + + + Query attributes of a file. + + The path to the file. + The root directory to parse from. + True to throw on error. + The file attributes. + + + + Query attributes of a file. + + The path to the file. + The root directory to parse from. + The file attributes. + + + + Query attributes of a file. + + The path to the file. + The file attributes. + + + + Send a Device IO Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Cancellation token to cancel the async operation. + True to throw on error. + Thrown on error. + The length of output bytes returned. + + + + Send a Device IO Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + Cancellation token to cancel the async operation. + True to throw on error. + The output buffer returned by the kernel. + + + + Send a Device IO Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Cancellation token to cancel the async operation. + Thrown on error. + The length of output bytes returned. + + + + Send a Device IO Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + Cancellation token to cancel the async operation. + The output buffer returned by the kernel. + + + + Send a File System Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Cancellation token to cancel the async operation. + True to throw on error. + Thrown on error. + The length of output bytes returned. + + + + Send a File System Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + Cancellation token to cancel the async operation. + True to throw on error. + The output buffer returned by the kernel. + + + + Send a File System Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Cancellation token to cancel the async operation. + Thrown on error. + The length of output bytes returned. + + + + Send a File System Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + Cancellation token to cancel the async operation. + The output buffer returned by the kernel. + + + + Send a Device IO Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Thrown on error. + The length of output bytes returned. + + + + Send a Device IO Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + The output buffer returned by the kernel. + + + + Send a File System Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Thrown on error. + The length of output bytes returned. + + + + Send a File System Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + The output buffer returned by the kernel. + + + + Send a Device IO Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + True to throw on error. + Thrown on error. + The length of output bytes returned. + + + + Send a Device IO Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + True to throw on error. + The output buffer returned by the kernel. + + + + Send a File System Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + True to throw on error. + Thrown on error. + The length of output bytes returned. + + + + Send a File System Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + True to throw on error. + The output buffer returned by the kernel. + + + + Send a Device IO Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + True to throw an exception on error. + Thrown on error. + The length of output bytes returned. + + + + Send a Device IO Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Thrown on error. + The length of output bytes returned. + + + + Send a Device IO Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + True to throw an exception on error. + The output buffer returned by the kernel. + + + + Send a Device IO Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + The output buffer returned by the kernel. + + + + Send an File System Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + True to throw an exception on error. + The length of output bytes returned. + Thrown on error. + + + + Send a File System Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + True to throw an exception on error. + The output buffer returned by the kernel. + + + + Send an File System Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + The length of output bytes returned. + Thrown on error. + + + + Send a File System Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + The output buffer returned by the kernel. + + + + Re-open an existing file for different access. + + The desired access for the file handle + The file share access + File open options + Flags for the object attributes. + True to throw an exception on error. + The NT status code and object result. + Thrown on error. + + + + Re-open an existing file for different access. + + The desired access for the file handle + The file share access + File open options + True to throw an exception on error. + The NT status code and object result. + Thrown on error. + + + + Re-open an exsiting file for different access. + + The desired access for the file handle + The file share access + File open options + The opened file + Thrown on error. + + + + Specify file disposition. + + True to set delete on close, false to clear delete on close. + True to throw on error. + The NT status code. + Thrown on error. + You can't prevent deletion if file opened with DeleteOnClose flag. + + + + Specify file disposition. + + True to set delete on close, false to clear delete on close. + Thrown on error. + You can't prevent deletion if file opened with DeleteOnClose flag. + + + + Delete the file. Must have been opened with DELETE access. + + True to throw on error. + The NT status code. + Thrown on error. + + + + Delete the file. Must have been opened with DELETE access. + + Thrown on error. + + + + Set disposition on the file (extended Windows version). + + True to throw on error. + Flags for SetDispositionEx call. + The NT status code. + Thrown on error. + + + + Set disposition on the file (extended Windows version). + + Flags for SetDispositionEx call. + Thrown on error. + + + + Delete the file (extended Windows version). Must have been opened with DELETE access. + + True to throw on error. + Flags for DeleteEx call. + The NT status code. + Thrown on error. + + + + Delete the file (extended Windows version). Must have been opened with DELETE access. + + Flags for DeleteEx call. + Thrown on error. + + + + Create a new hardlink to this file. + + The target NT path. + The root directory if linkname is relative + Thrown on error. + + + + Create a new hardlink to this file. + + The target absolute NT path. + Thrown on error. + + + + Create a new hardlink to this file. + + The target NT path. + The root directory if linkname is relative + If TRUE, replaces the target file if it exists. If FALSE, fails if the target file already exists. + True to throw on error. + The NT status code. + Thrown on error. + + + + Create a new hardlink to this file. + + The target NT path. + The root directory if linkname is relative + If TRUE, replaces the target file if it exists. If FALSE, fails if the target file already exists. + Thrown on error. + + + + Create a new hardlink to this file. + + The target NT path. + The root directory if linkname is relative + The flags associated to FileLinkInformationEx. + True to throw on error. + The NT status code. + Thrown on error. + + + + Create a new hardlink to this file. + + The target NT path. + The root directory if linkname is relative + The flags associated to FileLinkInformationEx. + Thrown on error. + + + + Rename file. + + The target NT path. + The root directory if new_name is relative + If TRUE, replaces the target file if it exists. If FALSE, fails if the target file already exists. + True to throw on error. + The NT status code. + Thrown on error. + + + + Rename file. + + The target NT path. + The root directory if new_name is relative + If TRUE, replaces the target file if it exists. If FALSE, fails if the target file already exists. + Thrown on error. + + + + Rename file. + + The target NT path. + The root directory if new_name is relative + Thrown on error. + + + + Rename this file with an absolute path. + + The target absolute NT path. + If TRUE, replace the target file if it exists. If FALSE, fails if the target file already exists. + Thrown on error. + + + + Rename this file with an absolute path. + + The target absolute NT path. + Thrown on error. + + + + Rename (extended Windows version) this file with an absolute path. + + The target absolute NT path. + The root directory if new_name is relative + The flags associated to FileRenameInformationEx. + True to throw on error. + The NT status code. + Thrown on error. + + + + Rename (extended Windows version) this file with an absolute path. + + The target absolute NT path. + The root directory if new_name is relative + The flags associated to FileRenameInformationEx. + Thrown on error. + + + + Rename (extended Windows version) this file with an absolute path. + + The target absolute NT path. + The flags associated to FileRenameInformationEx. + Thrown on error. + + + + Set an arbitrary reparse point. + + The reparse point data. + + + + Set an arbitrary reparse point. + + The reparse point data. + True to throw on error. + The NT status code. + + + + Set an arbitrary reparse point as a raw byte array. + + The reparse point data as a byte array. + + + + Set an arbitrary reparse point as a raw byte array. + + The reparse point data as a byte array. + True to throw on error. + The NT status code. + + + + Set an arbitrary reparse point. + + The reparse point data. + Flags for the reparse buffer. + Existing tag to check against. If no check required use 0. + Existing Guid to check against. If no check requested use empty GUID. + True to throw on error. + The NT status code. + + + + Set an arbitrary reparse point. + + The reparse point data. + Flags for the reparse buffer. + Existing tag to check against. If no check required use 0. + Existing Guid to check against. If no check requested use empty GUID. + + + + Set an arbitrary reparse point. + + The reparse point data. + Existing tag to check against. If no check required use 0. + + + + Set an arbitrary reparse point. + + The reparse point data.> + + + + Set a mount point on the current file object. + + The substitute name to reparse to. + The print name to display (can be null). + + + + Set a symlink on the current file object. + + The substitute name to reparse to. + The print name to display. + Additional flags for the symlink. + + + + Set a mount point on the current file object. + + The substitute name to reparse to. + The print name to display (can be null). + True to throw on error. + The NT status code. + + + + Set a symlink on the current file object. + + The substitute name to reparse to. + The print name to display. + Additional flags for the symlink. + True to throw on error. + The NT status code. + + + + Get the reparse point buffer for the file. + + True to throw on error. + The reparse point buffer. + + + + Get the reparse point buffer for the file. + + The reparse point buffer. + + + + Get the reparse point buffer for the file as a raw buffer. + + True to throw on error. + The reparse point buffer. + + + + Get the reparse point buffer for the file as a raw buffer. + + The reparse point buffer. + + + + Delete the reparse point buffer + + The reparse tag. + The NT status code. + True to throw on error. + + + + Delete the reparse point buffer + + The reparse tag. + + + + Delete the reparse point buffer + + The original reparse buffer. + True to throw on error. + + + + Delete the reparse point buffer + + The original reparse buffer. + + + + Get list of accessible files underneath a directory. + + Share access for file open + Options for open call. + The desired access for each file. + A file name mask (such as *.txt). Can be null. + Indicate what entries to return. + The list of files which can be access. + + + + Get list of accessible files underneath a directory. + + Share access for file open + Options for open call. + The desired access for each file. + The list of files which can be access. + + + + Query a directory for files. + + The list of directory entries. + + + + Query a directory for files. + + A file name mask (such as *.txt). Can be null. + Indicate what entries to return. + Specify what additional data to include in the directory entries. + The list of directory entries. You might need to cast the directories to the appropriate types if using include flags. + + + + Query a directory for files. + + A file name mask (such as *.txt). Can be null. + Indicate what entries to return. + The list of directory entries. + + + + Query a directory for files with file ID. + + A file name mask (such as *.txt). Can be null. + Indicate what entries to return. + Return placeholder parent and current directory entries. + The list of directory entries. + + + + Read data from a file with a length and position. + + The buffer to read to. + The position in the file to read. The position is optional. + True to throw on error. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position. + + The buffer to read to. + The position in the file to read. The position is optional. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position. + + The length of the read + The position in the file to read. The position is optional. + True to throw on error. + The read bytes, this can be smaller than length. + + + + Read data from a file with a length and position. + + The length of the read + The position in the file to read + The read bytes, this can be smaller than length. + + + + Read data from a file with a length. + + The length of the read + The read bytes, this can be smaller than length. + + + + Read data from a file with a length over a scatter set of pages. + + List of pages to read into. These pages must be Page Size aligned. + The length of the read + The position in the file to read. + True to throw on error. + The length of bytes read. + + + + Read data from a file with a length over a scatter set of pages. + + List of pages to read into. These pages must be Page Size aligned. + The length of the read + The position in the file to read. + The length of bytes read. + + + + Read data from a file with a length and position asynchronously. + + The buffer to read to. + The position in the file to read. The position is optional. + Cancellation token to cancel async operation. + True to throw on error. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position asynchronously. + + The buffer to read to. + The position in the file to read. The position is optional. + Cancellation token to cancel async operation. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position asynchronously. + + The length of the read + The position in the file to read. The position is optional. + Cancellation token to cancel async operation. + True to throw on error. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position asynchronously.. + + The length of the read + The position in the file to read + Cancellation token to cancel async operation. + The read bytes, this can be smaller than length. + + + + Read data from a file with a length and position asynchronously.. + + The length of the read + The position in the file to read + The read bytes, this can be smaller than length. + + + + Read data from a file with a length and position asynchronously. + + List of pages to read into. These pages must be Page Size aligned. + The length of the read + The position in the file to read. + Cancellation token to cancel async operation. + True to throw on error. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position asynchronously. + + List of pages to read into. These pages must be Page Size aligned. + The length of the read + The position in the file to read. + True to throw on error. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position asynchronously. + + List of pages to read into. These pages must be Page Size aligned. + The length of the read + The position in the file to read. + Cancellation token to cancel async operation. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position asynchronously. + + List of pages to read into. These pages must be Page Size aligned. + The length of the read + The position in the file to read. + The length of bytes read into the buffer. + + + + Write data to a file at a specific position asynchronously. + + The data to write as a buffer. + The position to write to. + Cancellation token to cancel async operation. + True to throw on error. + The number of bytes written + + + + Write data to a file at a specific position asynchronously. + + The data to write as a buffer. + The position to write to. + Cancellation token to cancel async operation. + The number of bytes written + + + + Write data to a file at a specific position asynchronously. + + The data to write. + The position to write to. + Cancellation token to cancel async operation. + The number of bytes written + + + + Write data to a file at a specific position asynchronously. + + The data to write + The position to write to + The number of bytes written + + + + Write data to a file at a specific position asynchronously. + + The data to write. + The position to write to. + Cancellation token to cancel async operation. + True to throw on error. + The number of bytes written + + + + Write data to a file at a specific position. + + The data to write + The position to write to. Optional + True to throw on error. + The number of bytes written. + + + + Write data to a file at a specific position. + + The data to write + The position to write to. Optional + The number of bytes written. + + + + Write data to a file at a specific position. + + The data to write + The position to write to. Optional + True to throw on error. + The number of bytes written. + + + + Write data to a file at a specific position. + + The data to write + The position to write to + The number of bytes written + + + + Write data to a file + + The data to write + The number of bytes written + + + + Write data to a file at a specific position gathered from a list of pages. + + List of pages to write. These pages must be page size aligned. + The length of the write. + The position to write to. + True to throw on error. + The number of bytes written. + + + + Write data to a file at a specific position gathered from a list of pages. + + List of pages to write. These pages must be page size aligned. + The length of the write. + The position to write to. + The number of bytes written. + + + + Write data to a file at a specific position asynchronously from a list of pages. + + List of pages to write. These pages must be page size aligned. + The length of the write. + The position to write to. + Cancellation token to cancel async operation. + True to throw on error. + The number of bytes written + + + + Write data to a file at a specific position asynchronously from a list of pages. + + List of pages to write. These pages must be page size aligned. + The length of the write. + The position to write to. + True to throw on error. + The number of bytes written + + + + Write data to a file at a specific position asynchronously from a list of pages. + + List of pages to write. These pages must be page size aligned. + The length of the write. + The position to write to. + Cancellation token to cancel async operation. + The number of bytes written + + + + Write data to a file at a specific position asynchronously from a list of pages. + + List of pages to write. These pages must be page size aligned. + The length of the write. + The position to write to. + The number of bytes written + + + + Lock part of a file. + + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + True to throw on error. + The NT status code. + + + + Lock part of a file. + + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + + + + Shared lock part of a file. + + The offset into the file to lock + The number of bytes to lock + + + + Lock part of a file asynchronously. + + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + Cancellation token to cancel async operation. + True to throw on error. + The NT status code. + + + + Lock part of a file asynchronously. + + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + Cancellation token to cancel async operation. + + + + Lock part of a file asynchronously. + + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + + + + Shared lock part of a file asynchronously. + + The offset into the file to lock + The number of bytes to lock + + + + Unlock part of a file previously locked with Lock + + The offset into the file to unlock + The number of bytes to unlock + Thrown on error. + + + + Unlock part of a file previously locked with Lock + + The offset into the file to unlock + The number of bytes to unlock + True to throw on error. + The NT status code. + + + + Convert this NtFile to a FileStream for reading/writing. + + The stream must be closed separately from the NtFile. + The file stream. + Thrown on error. + + + + Get the Win32 path name for the file. + + The flags to determine what path information to get. + The path. + Throw on error. + + + + Get the Win32 path name for the file. + + The flags to determine what path information to get. + True to throw on error. + The path. + + + + Oplock the file with a specific level. + + The level of oplock to set. + True to throw on error. + The oplock response level. + + + + Oplock the file with a specific level. + + The level of oplock to set. + The oplock response level. + + + + Oplock the file with a specific level. + + The level of oplock to set. + Cancellation token to cancel async operation. + True to throw on error. + The oplock response level. + + + + Oplock the file with a specific level. + + The level of oplock to set. + True to throw on error. + The oplock response level. + + + + Oplock the file with a specific level. + + The level of oplock to set. + Cancellation token to cancel async operation. + The oplock response level. + + + + Oplock the file with a specific level. + + The level of oplock to set. + The oplock response level. + + + + Acknowledge an oplock break. + + The acknowledgment level. + True to throw on error. + The NT status code. + Oplock break acknowledgement returns STATUS_PENDING. + + + + Acknowledge an oplock break. + + The acknowledgment level. + + + + Oplock the file with a specific level. + + The oplock cache level. + Specify additional flags for the request. + True to throw on error. + The result of the oplock request. + + + + Oplock the file with a specific level. + + The oplock cache level. + True to throw on error. + The result of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + Cancellation token to cancel async operation. + Specify additional flags for the request. + True to throw on error. + The request of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + Cancellation token to cancel async operation. + True to throw on error. + The request of the oplock request. + + + + Oplock the file with a specific lease level and flags. + + The oplock lease level. + Specify additional flags for the request. + The result of the oplock request. + + + + Oplock the file with a specific lease level and flags. + + The oplock lease level. + The result of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + Specify additional flags for the request. + Cancellation token to cancel async operation. + The request of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + Cancellation token to cancel async operation. + The request of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + True to throw on error. + The request of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + The response of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + Specify additional flags for the request. + The response of the oplock request. + + + + Acknowledge a lease oplock started with RequestOplockLease. + + True to complete acknowledgement on close. + True to throw on error. + The NT status code. + This breaks to None. If you want to request the new oplock level then request a new oplock. + + + + Acknowledge a lease oplock started with RequestOplockLease. + + True to complete acknowledgement on close. + + + + Acknowledge a lease oplock started with RequestOplockLease. + + + + + Oplock the file exclusively (no other users can access the file). + + True to throw on error. + The oplock response level. + + + + Oplock the file exclusively (no other users can access the file). + + The oplock response level. + + + + Oplock the file exclusively (no other users can access the file). + + Cancellation token to cancel async operation. + The oplock response level. + + + + Oplock the file exclusively (no other users can access the file). + + The oplock response level. + + + + Wait for an oplock break to complete. + + True to throw on error. + The NT status code. + + + + Wait for an oplock break to complete. + + The NT status code. + + + + Wait for an oplock break to complete. + + True to throw on error. + The NT status code. + + + + Wait for an oplock break to complete. + + The NT status code. + + + + Dispose. + + True is disposing. + + + + Try and cancel any pending asynchronous IO. + + + + + Get the extended attributes of a file. + + True to throw on error. + The extended attributes, empty if no extended attributes. + + + + Get the extended attributes of a file. + + The extended attributes, empty if no extended attributes. + + + + Set the extended attributes for a file. + + The EA buffer to set. + True to throw on error. + This will add entries if they no longer exist, + remove entries if the data is empty or update existing entires. + + + + Set the extended attributes for a file. + + The EA buffer to set. + This will add entries if they no longer exist, + remove entries if the data is empty or update existing entires. + + + + Set the extended attributes for a file. + + The name of the entry + The associated data + The entry flags. + + + + Set the extended attributes for a file. + + The name of the entry + The associated data + The entry flags. + + + + Set the extended attributes for a file. + + The name of the entry + The associated data + The entry flags. + + + + Remove an extended attributes entry for a file. + + The name of the entry + + + + Assign completion port to file. + + The completion port. + A key to associate with this completion. + + + + Check if a specific set of file directory access rights is granted + + The file directory access rights to check + True if all access rights are granted + + + + Get the cached signing level for a file. + + The cached signing level. + + + + Get the cached signing level for a file. + + The cached signing level. + + + + Get the cached singing level from the raw EA buffer. + + The cached signing level data. + Throw on error. + + + + Set the cached signing level for a file. + + Flags to set for the cache. + The signing level to cache + + + + Set the cached signing level for a file. + + Flags to set for the cache. + The signing level to cache + Optional directory path to look for catalog files. + + + + Set the cached signing level for a file. + + Flags to set for the cache. + The signing level to cache + Files for signature. + Optional directory path to look for catalog files. + + + + Set the cached signing level for a file. + + Flags to set for the cache. + The signing level to cache + Files for signature. + Optional directory path to look for catalog files. + True to throw on error. + + + + Set the end of file. + + The offset to the end of file. + + + + Set the valid data length of the file without zeroing. Needs SeManageVolumePrivilege. + + The length to set. + + + + Get list of hard link entries for a file. + + The list of entries. + + + + Get a list of stream entries for the current file. + + The list of streams. + + + + Visit all accessible streams under this file. + + A function to be called on every accessible stream. Return true to continue enumeration. + Specify the desired access for the streams. + The share access to open the streams with. + Additional options to open the s with. + True if all accessible streams were visited, false if not. + + + + Get list of process ids using this file. + + The list of process ids. + + + + Visit all accessible files under this directory. + + A function to be called on every accessible file. Return true to continue enumeration. + Specify the desired access for the files. + True to recurse into sub keys. + The share access to open the files with. + Specify max recursive depth. -1 to not set a limit. + Additional options to open the files with. + A file name mask (such as *.txt). Can be null. + Indicate what entries to return. + True if all accessible files were visited, false if not. + + + + Visit all accessible files under this directory. + + A function to be called on every accessible file. Return true to continue enumeration. + Specify the desired access for the files. + True to recurse into sub keys. + The share access to open the files with. + Specify max recursive depth. -1 to not set a limit. + Additional options to open the files with. + True if all accessible files were visited, false if not. + + + + Visit all accessible files under this directory. + + A function to be called on every accessible file. Return true to continue enumeration. + + + + Visit all accessible files under this directory. + + A function to be called on every accessible file. Return true to continue enumeration. + Specify the desired access for the files. + The share access to open the files with. + + + + Query whether a file is trusted for dynamic code. + + Returns true if the file is trusted. + + + + Set a file is trusted for dynamic code. + + + + + Set a file is trusted for dynamic code. + + True to throw on error. + The NT status code. + + + + Find files in a directory by the owner SID. + + The owner SID. + A list of files in the directory. + For this method to work you need Quota enabled on the volume. + + + + Get full change notifications. Will pick ex version if available and revert to old format if not. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + Wait timeout. + The list of changes. + + + + Get full change notifications. Will pick ex version if available and revert to old format if not. + + The filter of events to watch for. + True to watch all sub directories. + Wait timeout. + The list of changes. + + + + Get full change notifications asynchronously. Will pick ex version if available and revert to old format if not. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + Cancellation token. + The list of changes. + + + + Get full change notifications asynchronously. Will pick ex version if available and revert to old format if not. + + The filter of events to watch for. + True to watch all sub directories. + Cancellation token. + The list of changes. + + + + Get full change notifications asynchronously. Will pick ex version if available and revert to old format if not. + + The filter of events to watch for. + True to watch all sub directories. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + Wait timeout. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + Wait timeout. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + Cancellation token. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + Cancellation token. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + The list of changes. + + + + Get extended change notifications. + + The filter of events to watch for. + True to watch all sub directories. + Timeout to wait. + True to throw on error. + The list of changes. + + + + Get extended change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + Timeout to wait. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + Cancellation token. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + Cancellation token. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + The list of changes. + + + + Get the file attributes. + + True to throw on error. + The file attributes. + + + + Set the file attributes. + + The file attributes to set. + True to throw on error. + The NT status code. + + + + Get the creation time. + + True to throw on error. + The creation time. + + + + Get the last write time. + + True to throw on error. + The last write time. + + + + Get the change time time. + + True to throw on error. + The change time. + + + + Get the last access time. + + True to throw on error. + The last access time time. + + + + Set the file's creation time. + + The time to set. + True to throw on error. + The NT status code. + + + + Set the file's last access time. + + The time to set. + True to throw on error. + The NT status code. + + + + Set the file's last write time. + + The time to set. + True to throw on error. + The NT status code. + + + + Set the file's change time. + + The time to set. + True to throw on error. + The NT status code. + + + + Set the file position. + + The file position to set. + True to throw on error. + The NT status code. + + + + Get file information. + + + + + + + Query all reparse points from a volume. + + The list of reparse points. + You'll need to open the reparse database, which is typically \$Extend\$Reparse:$R:$INDEX_ALLOCATION on the volume. + + + + Query all object ids from a volume. + + The list of object ids. + You need to open the object ID database, which is typically \$Extend\$ObjId:$O:$INDEX_ALLOCATION on the volume. + + + + Get the Object ID buffer for a file. + + True to throw on error. + The object ID buffer. + + + + Get the Object ID create for a file. + + The object ID buffer. + + + + Get the Object ID buffer for a file. + + True to throw on error. + The object ID buffer. + + + + Get or create the Object ID for a file. + + The object ID buffer. + + + + Set Object ID and extended information. + + The Object ID buffer. + Only set the extended information. + True to throw on error. + The NT status code. + + + + Set Object ID and extended information. + + The Object ID buffer. + Only set the extended information. + The NT status code. + + + + Set Object ID and extended information. + + The Object ID GUID. + Extended info buffer, needs to be 48 bytes in size. + The NT status code. + + + + Set only Object ID extended information. + > + Extended info buffer, needs to be 48 bytes in size. + The NT status code. + + + + Delete the Object ID for a file. + + True to throw on error. + The NT status code. + + + + Delete the Object ID for a file. + + + + + Make the file sparse. + + True to make the file sparse. + True to throw on error. + The NT status code. + + + + Query if the driver is in the device stack for the device. + + The driver path. Can be a plain name of full object manager path, e.g. \Device\Blah. + True to throw on error. + True indicating driver in path. + + + + Query if the driver is in the device stack for the device. + + The driver path. + True indicating driver in path. + + + + Get filesystem and volume information. + + + + + Query a fixed buffer for a volume. + + The type to query. + The volume information class. + The returned type. + + + + Query a fixed buffer for a volume. + + The type to query. + The volume information class. + True to throw on error. + The returned type. + + + + Query a buffer for a volume. + + The type to query. + The volume information class. + True to throw on error. + The returned type. + + + + Query a buffer for a volume. + + The volume information class. + Initialization buffer. + True to throw on error. + The returned type. + + + + Query a buffer for a volume. + + The volume information class. + Initialization buffer. + The returned type. + + + + Query a buffer for a volume. + + The type to query. + The volume information class. + The returned type. + + + + Query a buffer for a volume. + + The volume information class. + The buffer for the query. Can be initialized. + True to throw on error. + The NT status code. + + + + Query a buffer for a volume. + + The volume information class. + The buffer for the query. Can be initialized. + + + + Set a buffer on a volume. + + The volume information class. + The buffer for the set. + True to throw on error. + The NT status code. + + + + Set a buffer on a volume. + + The volume information class. + The buffer for the set. + + + + Set a fixed value on a volume. + + The volume information class. + The fixed value to set. + True to throw on error. + The NT status code. + + + + Set a fixed value on a volume. + + The volume information class. + The fixed value to set. + + + + Query the quota entries for a volume. + + Return quote entries for the specified SIDs. + The list of quota entries. + + + + Query all quota entries for a volume. + + The list of quota entries. + + + + Set quota entries. + + The quota entries to set. + True to throw on error. + The NT status code. + + + + Set quota entries. + + The quota entries to set. + + + + Set quota entry. + + The quota entry to set. + + + + Set quota entry. + + The SID for the quota. + The quota limit to set. + The quota threshold to set. + + + + Get the file's full path. + + True to throw on error. + The file name. + + + + Get the file's normalized path. + + True to throw on error. + The file name. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get object ID for current file + + The object ID as a string + Thrown on error. + + + + Get object ID for current file as a number. + + The object ID as a number. + Thrown on error. + + + + Get or set the attributes of a file. + + The file attributes + Thrown on error. + + + + Get or set the creation time. + + + + + Get or set the last access time. + + + + + Get or set the last write time. + + + + + Get or set the change time. + + + + + Get file information, which is times, attributes and sizes. + + + + + Get or set the file as sparse. + + + + + Get whether this file represents a directory. + + + + + Get whether this file repsents a reparse point. + + + + + The result of opening the file, whether it was created, overwritten etc. + + + + + Get or set the current file position. + + + + + Get or sets the file's length + + + + + Get the file's allocation size. + + + + + Get the number of links. + + + + + Get whether delete is pending. + + + + + Get the Win32 path name for the file. + + The path, string.Empty on error. + + + + Get the low-level device type of the file. + + The file device type. + + + + Get the low-level device characteristics of the file. + + The file device characteristics. + + + + Get filesystem and volume information. + + + + + Get or set the file's compression format. + + + + + Gets whether the file is on a remote file system. + + + + + Get or set whether this file/directory is case sensitive. + + + + + Get or set whether this file/directory is case sensitive. + + + + + Get the file mode. + + + + + Get file access information. + + + + + Get the filename with the volume path. + + + + + Get the normalized filename with the volume path. + + + + + Get the associated short filename + + + + + Get the associated short filename + + + + + Get the normalized name. + + + + + Get or set the storage reserve ID. + + + + + Returns whether this object is a container. + + + + + Get or set the read only status of the file. + + + + + Is the file compressed. + + + + + Get remote protocol information. + + + + + Get the granted access as directory rights. + + + + + Get the file system control flags. + + + + + Get persist volume flags. + + + + + Return the status information field. (32 bit) + + + + + Class representing file information. + + + + + Time of creation. + + + + + Time of last access. + + + + + Time of last write. + + + + + Time of change. + + + + + Length of the file. + + + + + Length of the file, alias of EndOfFile. + + + + + Allocation size. + + + + + File attributes. + + + + + Has the file got a set of attributes set. + + The attributes to check. + True if it has the attributes. + + + + Is the file a directory. + + + + + Is the file a reparse point. + + + + + Class to represent a directory entry. + + + + + Index of the file. + + + + + File name. + + + + + Class to represent a directory entry with file IDs. + + + + + Length of any EA buffer. + + + + + The file reference number if known. + + + + + Class to represent a directory entry with short names. + + + + + Length of any EA buffer. + + + + + The short name of the file. + + + + + Class to represent a directory entry with short names and file ids. + + + + + Length of any EA buffer. + + + + + The short name of the file. + + + + + The file reference number if known. + + + + + Class to represent a file quota entry. + + + + + Class to represet a file object ID. + + + + + Full path to the file with the reparse point. + + + + + Win32 path to the file with the reparse point. + + + + + Reference number for the file. + + + + + The file's attributes. + + + + + The file's object ID. + + + + + The file's extended info. + + + + + File's birth volume ID. + + + + + File's birth object ID. + + + + + File's domain ID. + + + + + Class to represent a file reparse point. + + + + + Full path to the file with the reparse point. + + + + + Win32 path to the file with the reparse point. + + + + + Reference number for the file. + + + + + The file's attributes. + + + + + The reparse point buffer. + + + + + The reparse point tag. + + + + + Utility functions for files + + + + + Convert a DOS filename to an absolute NT filename + + The filename, can be relative + True to throw on error. + The NT filename + + + + Convert a DOS filename to an absolute NT filename + + The filename, can be relative + The NT filename + + + + Convert a DOS filename to an absolute NT filename + + List of paths to combine before converting. + The NT filename + + + + Convert a DOS filename to an NT filename and get as an ObjectAttributes structure + + The DOS filename. + The object attribute flags. + An optional security quality of service. + An optional security descriptor. + True to throw on error. + The object attributes + + + + Convert a DOS filename to an NT filename and get as an ObjectAttributes structure + + The DOS filename. + The object attribute flags. + An optional security quality of service. + An optional security descriptor. + The object attributes + + + + Convert a DOS filename to an NT filename and get as an ObjectAttributes structure + + The filename + The object attributes + + + + Convert a DOS filename to a UNICODE_STRING structure + + The DOS filename + The UNICODE_STRING + + + + Get type of DOS path + + The DOS filename + The type of DOS path + + + + Map directory access rights to file access rights. + + The directory access rights to map. + The mapped access rights. + + + + Convert a file ID long to a string. + + The file ID to convert + The string format of the file id. + + + + Convert a string to a file ID. + + The file ID as a string (must be 4 characters). + The file ID as a long. + + + + Get if a reparse tag is a Microsoft defined one. + + The reparse tag. + True if it's a Microsoft reparse tag. + + + + Get if a reparse tag is a name surrogate. + + The reparse tag. + True if it's a surrogate reparse tag. + + + + Get if a reparse tag is a directory which can have children. + + The reparse tag. + True if it's a directory reparse tag which can have children. + + + + Convert a directory access rights mask to a normal file access mask. + + The access to convert. + The converted access rights. + + + + Convert a file access rights mask to a directory file access mask. + + The access to convert. + The converted access rights. + + + + Enable or disable Wow64 FS redirection. + + True to enable FS redirection. + True to throw on error. + The old enable state. + + + + Enable or disable Wow64 FS redirection. + + True to enable FS redirection. + The old enable state. + + + + Split an allocated address into a list of pages. This can be used to pass to + ReadScatter or WriteGather file APIs. + + The base address to split. The address should be page aligned. + The length of bytes to split into pages. This will be rounded up to the next page boundary. + The list of pages. + + + + Split an allocated address into a list of pages. This can be used to pass to + ReadScatter or WriteGather file APIs. + + The allocated buffer to split. The address should be page aligned. + The buffer will be split up based on its length. Note that the length will be rounded up. + The list of pages. + + + + Attempt to convert an NT device filename to a DOS filename. + + The filename to convert. + The converted string. Returns a path prefixed with GLOBALROOT if it doesn't understand the format. + + + + Build a path for an open by ID file. + + The path to the volume. + The ID. + The bytes for the ID path. + + + + Build a path for a file ID volume. + + The path to the volume. + The file reference number. + The bytes for the file ID path. + + + + Build a path for an object ID volume. + + The path to the volume. + The file object ID. + The bytes for the file ID path. + + + + Generate a DOS filename from a full filename. + + The full filename. + True to allow extended characters. + Number of iterations of the algorithm to test. + True throw on error. + The DOS filename. + + + + Generate a DOS filename from a full filename. + + The full filename. + True to allow extended characters. + Number of iterations of the algorithm to test. + The DOS filename. + + + + Generate a DOS filename from a full filename. + + The full filename. + True to allow extended characters. + The DOS filename. + + + + Is the filename a legal 8dot3 name. + + The filename to check. + True if it's a legal 8dot3 name. + + + + Class representing a NT FilterConnectionPort object. Note this is just a dummy object for typing purposes. + + + + + A generic wrapper for any object, used if we don't know the type ahead of time. + + + + + Convert the generic object to the best typed object. + + The typed object. Can be NtGeneric if no better type is known. + + + + Convert the generic object to the best typed object. + + True to throw on error. + The typed object. Can be NtGeneric if no better type is known. + + + + Returns whether this object is a container. + + + + + Class to represent a system handle + + + + + The ID of the process holding the handle + + + + + Get the image path for the process which contains this handle. + + + + + Get name of the process which contains this handle. + + + + + The object type index + + + + + The object type name + + + + + The object type + + + + + The handle attribute flags. + + + + + The handle value + + + + + The address of the object. + + + + + The granted access mask + + + + + The granted access mask as a string. + + + + + The granted access mask as a string. + + + + + Whether the handle is inheritable. + + + + + Whether the handle is protected from close. + + + + + Whether the handle has write access. + + + + + Whether the handle has read access. + + + + + Whether the handle has execute access. + + + + + Whether the handle has full access. + + + + + The name of the object (needs to have set query access in constructor) + + + + + The security of the object (needs to have set query access in constructor) + + + + + Indicates if the handle was valid. + + This can cause the handle's values to be queried which can take time. + + + + Overridden ToString. + + The handle as a string. + + + + Get handle into the current process + + True to throw on error. + The handle to the object + + + + Get handle into the current process + + The handle to the object + + + + Close the handle in the original process. + + True throw on error. + The NT status code. + This is not recommended. + + + + Close the handle in the original process. + + This is not recommended. + + + + Class to call NT heap APIs. + + + + + Allocate a buffer from the heap. + + Heap flags. + Size of the allocation. + True to throw on error. + The allocated memory address. + + + + Allocate a buffer from the heap. + + Heap flags. + Size of the allocation. + The allocated memory address. + + + + Free a buffer from the heap. + + Heap flags. + Address of the allocation. + True to throw on error. + + + + Free a buffer from the heap. + + Heap flags. + Address of the allocation. + + + + Get the current process heap. + + + + + Class representing an NT IO Completion Port object + + + + + Create an IO Completion Port object + + The object attributes + The desired access for the event + Number of concurrent threads to process I/O packets. 0 for CPU count. + True to throw an exception on error. + The NT status code and object result. + Thrown on error. + + + + Create an IO Completion Port object + + The object attributes + The desired access for the event + Number of concurrent threads to process I/O packets. 0 for CPU count. + The IO Completion Port object. + Thrown on error. + + + + Create an IO Completion Port object + + The path to the IO Completion Port + The root object for relative path names + The desired access for the event + Number of concurrent threads to process I/O packets. 0 for CPU count. + The IO Completion Port object. + Thrown on error. + + + + Create an unnamed IO Completion Port object. + + The IO Completion Port object. + Thrown on error. + + + + Open an IO Completion Port object + + The object attributes + The desired access for the event + The IO Completion Port object. + Thrown on error. + + + + Open an IO Completion Port object + + The object attributes + The desired access for the event + True to throw an exception on error. + The NT status code and object result. + Thrown on error. + + + + Open an IO Completion Port object + + The path to the IO Completion Port + The root object for relative path names + The desired access for the event + The IO Completion Port object. + Thrown on error. + + + + Open an IO Completion Port object + + The path to the IO Completion Port + The IO Completion Port object. + Thrown on error. + + + + Remove a queued status from the queue. + + An optional timeout. + True to throw on error. + The completion result. + Thrown on error or timeout. + + + + Remove a queued status from the queue. + + An optional timeout. + The completion result. + Thrown on error or timeout. + + + + Remove multiple queued status from the queue. + + Maximum number of status to remove. + An optional timeout. + Indicate whether the wait is alertable. + True to throw on error. + Array of completion results. Length can be <= max_count. + + + + Remove multiple queued status from the queue. + + Maximum number of status to remove. + An optional timeout. + Indicate whether the wait is alertable. + Array of completion results. Length can be <= max_count. If timeout then returns an empty array. + + + + Remove multiple queued status from the queue. + + Maximum number of status to remove. + Array of completion results. Length can be <= max_count + + + + Remove a queued status from the queue. Wait for an infinite time for the result. + + The completion result. + + + + Add a queued status to the queue. + + The optional key context. + The optional APC context. + Status code + The information context. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Get current depth of IO Completion Port + + + + + Memory control method. + + + + + Buffered. + + + + + IN Direct. + + + + + OUT Direct. + + + + + Neither. + + + + + Access control flags. + + + + + Any access. + + + + + Read access. + + + + + Write access. + + + + + Represents a NT file IO control code. + + + + + Type of device + + + + + Function number + + + + + Buffering method + + + + + Access of file handle + + + + + Is the function number custom, i.e. has the top bit set. + + + + + Get a known name associated with this IO control code. + + + + + Constructor + + Type of device + Function number + Buffering method + Access of file handle + + + + Constructor + + Raw IO control code to convert. + + + + Static method to create an NtIoControlCode + + The conde as an integer. + The io control code. + + + + Convert the io control code to an Int32 + + The int32 version of the code + + + + Overriden hash code. + + The hash code. + + + + Overridden equals. + + The object to compare against. + True if equal. + + + + Overridden ToString method. + + The IO control code as a string. + + + + Format IO control code with an format specifier. + + The format specified. For example use X to format as a hexadecimal number. + The formatted string. + + + + Format the underlying IO control code with an format specifier. + + The format specified. For example use X to format as a hexadecimal number. + Format provider. + The formatted string. + + + + Class representing a NT Job object + + + + + Create a job object + + The object attributes + Desired access for job. + True to throw an exception on error. + The NT status code and object result. + + + + Create a job object + + The object attributes + Desired access for job. + The Job object. + + + + Create a job object + + The path to the job object (can be null) + The root object when path is relative + Desired access for job. + The Job object + + + + Create a job object + + The path to the job object (can be null) + The root object when path is relative + The Job object + + + + Create an unnamed job object + + The Job object + + + + Open a job object + + The object attributes + Desired access for job. + True to throw an exception on error. + The NT status code and object result. + + + + Open a job object + + The object attributes + Desired access for job. + The Job object + + + + Open a job object + + The path to the job object + The root object when path is relative + Desired access for the job object + The Job object + + + + Open a job object + + The path to the job object + The root object when path is relative + The Job object + + + + Create and initialize a Silo, + + Flags for root directory. + Desired access for the job. + Object attributes. + True to throw on error. + The Job object. + + + + Create and initialize a Silo, + + Flags for root directory. + Desired access for the job. + Object attributes. + The Job object. + + + + Create and initialize a Silo, + + Flags for root directory. + True to throw on error. + The Job object. + + + + Create an initialize a Silo, + + Flags for root directory. + The Job object. + + + + Create and initialize a Server Silo, + + Flags for root directory. + True to throw on error. + Path to the system root. + Event to signal when silo deleted. + True if a downlevel container. + Desired access for the job. + Object attributes. + The Job object. + + + + Create and initialize a Server Silo, + + Flags for root directory. + Path to the system root. + Event to signal when silo deleted. + True if a downlevel container. + Desired access for the job. + Object attributes. + The Job object. + + + + Create and initialize a Server Silo, + + Flags for root directory. + True to throw on error. + Path to the system root. + Event to signal when silo deleted. + True if a downlevel container. + The Job object. + + + + Create and initialize a Server Silo, + + Flags for root directory. + Path to the system root. + Event to signal when silo deleted. + True if a downlevel container. + The Job object. + + + + Convert Job object into a Silo + + True to throw on error. + The NT status code. + + + + Convert Job object into a Silo + + + + + Initialize a Silo, + + Flags for root directory. + True to throw on error. + The NT status code. + + + + Initialize a Silo, + + Flags for root directory. + + + + Initialize a Silo to a Server Silo. + + Event to signal when silo deleted. + True if a downlevel container. + True to throw on error. + The NT status code. + You must have set a system root and added a \Device directory (which shadows the real directory) to the silo object directory. + + + + Initialize a Silo to a Server Silo. + + Event to signal when silo deleted. + True if a downlevel container. + The NT status code. + + + + Create the silo's root object directory. + + The flags for the creation. + True to throw on error. + The NT status code. + + + + Create the silo's root object directory. + + The flags for the creation. + The NT status code. + + + + Assign a process to this job object. + + The process to assign. + + + + Assign a process to this job object. + + True to throw on error. + The process to assign. + The NT status code. + + + + Assign a process to this job object using current Job on Windows 1709+. + + + + + Assign a process to this job object using current Job on Windows 1709+. + + + + + Associate a completion port with the job. + + The completion port. + The key associated with the port. + + + + Terminate this job object. + + The termination status. + True to throw on error. + The NT status code. + + + + Terminate this job object. + + The termination status. + + + + Set the limit flags for the job. + + The limit flags. + True to throw on error. + The NT status code. + + + + Set the limit flags for the job. + + The limit flags. + + + + Set the Silo system root directory. + + The absolute path to the system root directory. + True to throw on error. + The system_root path must start with a capital drive letter and not end with a backslash. + The NT status code. + + + + Set the Silo system root directory. + + The absolute path to the system root directory. + The system_root path must start with a capital drive letter and not end with a backslash. + + + + Set the active process limit. + + The number of active processes in the job. + True to throw on error. + The NT status code. + + + + Set the active process limit. + + The number of active processes in the job. + + + + Set minimum and maximum working set size. + + The minimum working set size. + The maximum working set size. + True to throw on error. + The NT status code. + + + + Set minimum and maximum working set size. + + The minimum working set size. + The maximum working set size. + + + + Set the process memory limit. + + The memory limit for a process. + True to throw on error. + The NT status code. + + + + Set the process memory limit. + + The memory limit for a process. + The NT status code. + + + + Set the job memory limit. + + The memory limit for a job. + True to throw on error. + The NT status code. + + + + Set the job memory limit. + + The memory limit for a job. + The NT status code. + + + + Set the time limit for a process. + + The time limit for a process, in 100ns ticks. Set to 0 to clear the timeout. + True to throw on error. + The NT status code. + + + + Set the time limit for a process. + + The time limit for a process, in 100ns ticks. Set to 0 to clear the timeout. + + + + Set the time limit for a process. + + The time limit for a process. + True to throw on error. + The NT status code. + + + + Set the time limit for a process. + + The time limit for a process. + + + + Set the time limit for a job. + + The time limit for a job, in 100ns ticks. Set to 0 to clear timeout. + True to throw on error. + The NT status code. + + + + Set the time limit for a job. + + The time limit for a job, in 100ns ticks. Set to 0 to clear timeout. + + + + Set the time limit for a job. + + The time limit for a job. + True to throw on error. + The NT status code. + + + + Set the time limit for a job. + + The time limit for a job. + + + + Get list of process IDs in Job. + + True to throw on error. + The list of process IDs. + + + + Get list of process IDs in Job. + + The list of process IDs. + + + + Set UI Restriction Flags. + + The UI Restriction Flags. + True to throw on error. + The NT status code. + + + + Set UI Restriction Flags. + + The UI Restriction Flags. + The NT status code. + + + + Query Silo Root directory. + + True to throw on error. + The silo root directory. + + + + Get Silo basic information. + + True to throw on error. + The Silo Basic Information. + + + + Get Silo basic information. + + True to throw on error. + The Server Silo Basic Information. + + + + Get Silo user shared data. + + True to throw on error. + The Silo User Shared Data. + + + + Get whether this job object can be impersonated. + + True to throw on error. + True if the job object can be impersonated. + + + + Enable thread impersonation on this job object. + + True to throw on error. + The NT status code. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Get or set completion filter for job object. + + + + + The count of completions for the job. + + + + + Get or set the Maximum Bandwith NetRate limitation. + + + + + Get or set the DSCP Tag NetRate limitation. + + + + + Get or set the active process limit. + + + + + Get or set the active process limit. + + + + + Get or set the minimum working set size. + + + + + Get or set the maximum working set size. + + + + + Get or set the process time limit. + + + + + Get or set the process time limit. + + + + + Get or set the process memory limit. + + + + + Get or set the process memory limit. + + + + + Get used peak job memory used. + + + + + Get used peak job memory used. + + + + + Get or set the job limit flags. + + + + + Get or set the job UI Restriction flags. + + + + + Get or set whether job breakaway is allowed. + + + + + Get or set whether silenty job breakaway is allowed. + + + + + ID of container. + + + + + ID of container telemetry. + + + + + Job ID. + + + + + Get the Silo's Root Directory. + + + + + Get Silo basic information. + + + + + Get Silo basic information. + + + + + Get Silo user shared data. + + + + + Get or set the thread impersonation status. + + + + + Get whether this Job object is a silo. + + + + + Class to represent an NT Key object + + + + + Load a new hive + + The destination path + The path to the hive + Load flags + The opened root key + Thrown on error. + + + + Load a new hive + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Desired access for the root key + The opened root key + Thrown on error. + + + + Load a new hive + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Desired access for the root key + Key that this hive will be trusted for. + Event handle for key load. + True to throw an exception on error. + The NT status code and object result. + + + + Load a new hive and do not open the root key. + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Key that this hive will be trusted for. + Event handle for key load. + True to throw an exception on error. + The NT status code. + + + + Load a new hive + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Desired access for the root key + Key that this hive will be trusted for. + Event handle for key load. + The opened key. + + + + Load a new hive and do not open the root key. + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Key that this hive will be trusted for. + Event handle for key load. + + + + Load a new hive + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Desired access for the root key + True to throw an exception on error. + The NT status code and object result. + + + + Load a new hive + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Desired access for the root key + Token to open the hive files under. + Key that this hive will be trusted for. + Event handle for key load. + True to throw an exception on error. + The NT status code and object result. + + + + Load a new hive and do not open the root key. + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Token to open the hive files under. + Key that this hive will be trusted for. + Event handle for key load. + True to throw an exception on error. + The NT status code. + + + + Load a new hive + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Desired access for the root key + Token to open the hive files under. + Key that this hive will be trusted for. + Event handle for key load. + The loaded key. + + + + Load a new hive and do not open the root key. + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Token to open the hive files under. + Key that this hive will be trusted for. + Event handle for key load. + + + + Unload an existing hive. + + Object attributes for the key name + Unload flags + True to throw an exception on error. + The NT status code. + + + + Unload an existing hive. + + Path to key to unload. + Unload flags + Thrown on error. + + + + Unload an existing hive. + + Path to key to unload. + Thrown on error. + + + + Create a new Key + + Object attributes for the key name + Desired access for the root key + Create options + Optional transaction object. + True to throw an exception on error. + The NT status code and object result. + + + + Create a new Key + + Object attributes for the key name + Desired access for the root key + Create options + True to throw an exception on error. + The NT status code and object result. + + + + Create a new Key + + Object attributes for the key name + Desired access for the root key + Create options + The opened key + Thrown on error. + + + + Create a new Key + + Object attributes for the key name + Desired access for the root key + Create options + Optional transaction object. + The NT status code and object result. + + + + Create a new Key + + Path to the key to create + Root key if key_name is relative + Desired access for the root key + Create options + The opened key + Thrown on error. + + + + Try and open a Key + + Object attributes for the key name + Desired access for the root key + Open options. + Optional transaction object. + True to throw an exception on error. + The NT status code and object result. + + + + Try and open a Key + + Object attributes for the key name + Desired access for the root key + Open options. + True to throw an exception on error. + The NT status code and object result. + + + + Try and open a Key + + Path to the key to open + Root key if key_name is relative + Desired access for the root key + Open options. + Optional transaction object. + True to throw an exception on error. + The NT status code and object result. + + + + Try and open a Key + + Path to the key to open + Root key if key_name is relative + Desired access for the root key + Open options. + True to throw an exception on error. + The NT status code and object result. + + + + Open a Key + + Object attributes for the key name + Desired access for the root key + Open options. + The opened key + Thrown on error. + + + + Open a Key + + Object attributes for the key name + Desired access for the root key + Open options. + Optional transaction object. + The opened key + Thrown on error. + + + + Open a Key + + Path to the key to open + Root key if key_name is relative + Desired access for the root key + The opened key + Thrown on error. + + + + Query a license value. While technically not directly a registry key + it has many of the same properties such as using the same registry + value types. + + The name of the license value. + True to throw an exception on error + The license value key + + + + Query a license value. While technically not directly a registry key + it has many of the same properties such as using the same registry + value types. + + The name of the license value. + The license value key + + + + Create a registry key symbolic link + + Root key if path is relative + Path to the key to create + Target resistry path + The created symbolic link key + Thrown on error. + + + + Open the machine key + + The opened key with the maximum access allowed. + Thrown on error. + + + + Open the machine key + + The opened key with the maximum access allowed. + True to throw on error. + Thrown on error. + + + + Open the user key + + The opened key + Thrown on error. + + + + Open the user key + + The opened key with the maximum access allowed. + True to throw on error. + Thrown on error. + + + + Open a specific user key + + The SID of the user to open + The opened key + Thrown on error. + + + + Open the user key + + The SID of the user to open + True to throw on error. + The opened key with the maximum access allowed. + Thrown on error. + + + + Open the current user key + + The opened key + Thrown on error. + + + + Open the current user key + + True to throw on error. + The opened key with the maximum access allowed. + Thrown on error. + + + + Open the root key + + The opened key + Thrown on error. + + + + Open the root key + + The opened key with the maximum access allowed. + True to throw on error. + Thrown on error. + + + + Create a new Key + + Path to the key to create + The opened key + Thrown on error. + + + + Create a new Key + + Path to the key to create + Desired access for the root key + Create options + The opened key + Thrown on error. + + + + Delete the key + + True to throw on error. + + + + Delete the key + + + + + Set a resistry value + + The name of the value + The type of the value + The raw value data + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a resistry value + + The name of the value + The type of the value + The raw value data + Thrown on error. + + + + Set a string resistry value + + The name of the value + The type of the value + The value data + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a string resistry value as REG_SZ. + + The name of the value + The value data + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a string resistry value + + The name of the value + The type of the value + The value data + Thrown on error. + + + + Set a string resistry value as REG_SZ. + + The name of the value + The value data + Thrown on error. + + + + Set a list of strings as a resistry value. + + The name of the value + The list of strings to set. + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a list of strings as a resistry value. + + The name of the value + The list of strings to set. + Thrown on error. + + + + Set a DWORD resistry value + + The name of the value + The value data + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a DWORD resistry value + + The name of the value + The value data + True to set the value of big endian. + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a QWORD resistry value + + The name of the value + The value data + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a DWORD resistry value + + The name of the value + The value data + Thrown on error. + + + + Set a DWORD resistry value + + The name of the value + The value data + True to set the value of big endian. + Thrown on error. + + + + Set a QWORD resistry value + + The name of the value + The value data + Thrown on error. + + + + Delete a registry value + + The name of the value + True to throw on error. + Thrown on error. + The NT status code. + + + + Delete a registry value + + The name of the value + Thrown on error. + + + + Query a value by name + + The name of the value + True to throw on error + The value information + + + + Query a value by name + + The name of the value + The value information + Thrown on error. + + + + Query all values for this key + + A list of values + Thrown on error. + + + + Query all subkey entries. + + The list of subkey entries + Thrown on error. + + + + Query all subkey names + + The list of subkey names + Thrown on error. + + + + Return a list of subkeys which can be accessed. + + The required access rights for the subkeys + True to open link keys rather than following the link. + True to open keys with backup flag set. + The disposable list of subkeys. + + + + Return a list of subkeys which can be accessed. + + The required access rights for the subkeys + The disposable list of subkeys. + Thrown on error. + + + + Set a symbolic link target for this key (must have been created with + appropriate create flags) + + The symbolic link target. + True to throw on error. + The NT status code. + Thrown on error. + + + + Set a symbolic link target for this key (must have been created with + appropriate create flags) + + The symbolic link target. + + + + Get the symbolic link target for this key. + + True to throw on error. + The symbolic link target. + Thrown on error. + + + + Get the symbolic link target for this key. + + The symbolic link target. + Thrown on error. + + + + Open a key + + The path to the key to open + The opened key + Thrown on error. + + + + Open a key + + The path to the key to open + Access rights for the key + The opened key + Thrown on error. + + + + Open a key + + The path to the key to open + Access rights for the key + True to throw on error. + The opened key + Thrown on error. + + + + Open a key + + The path to the key to open + Access rights for the key + Key open options. + True to throw on error. + The opened key + Thrown on error. + + + + Reopen the key with different access rights. + + The access rights to reopen with. + Open options. + True to throw on error. + The opened key. + + + + Reopen the key with different access rights. + + The access rights to reopen with. + The object attributes to open with. + Open options. + True to throw on error. + The opened key. + + + + Reopen the key with different access rights. + + The access rights to reopen with. + Open options. + The opened key. + + + + Convert object to a .NET RegistryKey object + + The registry key object + + + + Rename key. + + The new name for the key. + True to throw on error. + The NT status code. + Thrown on error. + + + + Rename key. + + The new name for the key. + Thrown on error. + + + + Save the opened key into a file. + + The file to save to. + Save key flags + True to throw on error. + The NT status code. + Thrown on error. + + + + Save the opened key into a file. + + The file to save to. + Save key flags + + + + Save the opened key into a file. + + The file path to save to. + Save key flags + True to throw on error. + The NT status code. + Thrown on error. + + + + Save the opened key into a file. + + The file path to save to. + Save key flags + + + + Save the opened key into a file. + + The file path to save to. + + + + Restore key from a file. + + The file to restore from + Restore key flags + True to throw on error. + The NT status code. + Thrown on error. + + + + Restore key from a file. + + The file to restore from + Restore key flags + + + + Restore key from a file. + + The file path to restore from + Restore key flags + True to throw on error. + The NT status code. + Thrown on error. + + + + Restore key from a file. + + The file path to restore from + Restore key flags + + + + Restore key from a file. + + The file path to restore from + + + + Try and lock the registry key to prevent further modification. + + Note that this almost certainly never works from usermode, there's an explicit + check to prevent it in the kernel. + + + + Wait for a change on the registry key. + + Specify what changes will be notified. + True to watch the entire tree. + The status from the change notification. + Thrown on error. + + + + Wait for a change on thie registry key asynchronously. + + Specify what changes will be notified. + True to watch the entire tree. + The status from the change notification. + Thrown on error. + + + + Visit all accessible keys under this one. + + A function to be called on every accessible key. Return true to continue enumeration. + Specify the desired access for the keys. + True to recurse into sub keys. + Specify max recursive depth. -1 to not set a limit. + Open the key using backup privileges. + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + True to recurse into sub directories. + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + Specify the desired access for the directory + True to recurse into sub directories. + Open the key using backup privileges. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Get key last write time + + The last write time + Thrown on error. + + + + Get key subkey count + + The subkey count + Thrown on error. + + + + Get key value count + + The key value count + Thrown on error. + + + + Get the key title index + + The key title index + Thrown on error. + + + + Get the key class name + + The key class name + Thrown on error. + + + + Get the maximum key value name length + + The maximum key value name length + Thrown on error. + + + + Get the maximum key value data length + + The maximum key value data length + Thrown on error. + + + + Get the maximum subkey name length + + The maximum subkey name length + Thrown on error. + + + + Get the maximum class name length + + The maximum class name length + Thrown on error. + + + + Get the key path as a Win32 style one. If not possible returns + the original path. + + + + + The disposition when the key was created. + + + + + Indicates the handle is a special pre-defined one by the kernel. + + + + + Get or set virtualization flags. + + + + + Get or set key control flags. + + + + + Get or set wow64 flags. + + + + + Get key flags. + + + + + Indicates if this key is from a trusted hive. + + + + + Indicates if this key is a symbolic link. + + + + + Indicates if this key is volatile. + + + + + Get the name from NtQueryKey. + + + + + Returns whether this object is a container. + + + + + A key entry. + + + + + The name of the key. + + + + + The last write time. + + + + + The key's title index. + + + + + Class to represent a loaded hive from the Hive List. + + + + + Path to the root key. + + + + + Path to the hive file. + + + + + Utilities for registry keys. + + + + + Convert a Win32 style keyname such as HKEY_LOCAL_MACHINE\Path into a native key path. + + The win32 style keyname to convert. + The converted keyname. + Thrown if invalid name. + + + + Attempt to convert an NT style registry key name to Win32 form. + If it's not possible to convert the function will return the + original form. + + The NT path to convert. + The converted path, or original if it can't be converted. + + + + Query list of loaded hives from the Registry. + + Convert the file path to a DOS path. + The list of loaded hives. + + + + Query list of loaded hives from the Registry. + + The list of loaded hives. + + + + Class representing a single Key value + + + + + Name of the value + + + + + Type of the value + + + + + Raw data for the value + + + + + Title index for the value + + + + + Get the value as an object. + + + + + Convert the value to a string + + The value as a string + + + + Convert value to an object + + The value as an object + + + + LDR static methods. + + + + + Get address of a procedure in a mapped image. + + The handle to the mapped image. + The name of the procedure to find. + True to throw on error. + The procedure address. + + + + Get address of a procedure in a mapped image. + + The handle to the mapped image. + The name of the procedure to find. + The procedure address. + + + + Class to access NT locale information + + + + + Get mapped NLS section + + The type of section + The codepage number + True to throw on error. + The mapped section if it exists. + + + + Get mapped NLS section + + The type of section + The codepage number + The mapped section if it exists. + + + + Get default locale ID + + True if the locale should be the thread's, otherwise the systems + True to throw on error. + The locale ID + + + + Get default locale ID + + True if the locale should be the thread's, otherwise the systems + The locale ID + + + + Set default locale + + True if the locale should be the thread's, otherwise the systems + True to throw on error. + The locale ID + The NT status code. + + + + Set default locale + + True if the locale should be the thread's, otherwise the systems + The locale ID + + + + Class representing a NT File Mailslot client object + + + + + Set the mailslot read timeout. + + The timeout to set. + True to throw on error. + The NT Status code. + + + + Peek on the current status of the Mailslot. + + True to throw on error. + The peek status. + + + + Peek on the current status of the Mailslot. + + The peek status. + + + + Get or set the Read Timeout. + + + + + Get maximum message size. + + + + + Get mailslot quota. + + + + + Get next message size. + + + + + Get messages available. + + + + + Class representing a mapped section + + + + + The process which the section is mapped into + + + + + The valid length of the mapped section from the current position. + + This doesn't take into account the possibility of fragmented commits. + + + + Get full path for mapped section. + + + + + Query the memory protection setting for this mapping. + + + + + Get image signing level. + + + + + Get the base address of the mapped section. + + + + + Release the internal handle + + + + + + Checks if this mapped view represents the same file. + + The address to check. + True to throw on error. + True if the mapped view represents the same file. + + + + Checks if this mapped view represents the same file. + + The address to check. + True if the mapped view represents the same file. + + + + Detaches the current buffer and allocates a new one. + + Specify a new length for the detached buffer. Must be <= Length. + The detached buffer. + The original buffer will become invalid after this call. + + + + Class representing a NT Mutant object + + + + + Create a new mutant + + The path to the mutant + The root object if path is relative + True to set current thread as initial owner + The opened mutant + Thrown on error + + + + Create a new mutant + + Object attributes + True to set current thread as initial owner + Desired access for mutant + The opened mutant + Thrown on error + + + + Create a new mutant + + Object attributes + True to set current thread as initial owner + Desired access for mutant + True to throw an exception on error. + The NT status code and object result. + + + + Open a mutant + + The path to the mutant + The root object if path is relative + Desired access for mutant + The opened mutant + Thrown on error + + + + Open a mutant + + The path to the mutant + The root object if path is relative + The opened mutant + Thrown on error + + + + Open a mutant + + Object attributes + Desired access for mutant + The opened mutant + Thrown on error + + + + Open a mutant + + Object attributes + Desired access for mutant + True to throw an exception on error. + The NT status code and object result. + + + + Release the mutant + + True to throw on error. + The previous release count + + + + Release the mutant + + The previous release count + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Get the owner of the mutant. + + + + + Get current count. + + + + + Get wether mutant owned by current thread. + + + + + Get whether mutant is abandoned. + + + + + Pipe attribute type. + + + + + The pipe attributes. + + + + + The pipe connect attributes. + + + + + The pipe handle attributes. + + + + + Class to add additional methods to a file for a named pipe. This is a base class for server and client types. + + + + + Get a named attribute from the pipe. + + The attribute type to query. + The name of the attribute. + True to throw on error. + The attribute value as a byte array. + Thrown on error. + + + + Set a named attribute for a pipe. + + The attribute type to set. + The name of the attribute. + The value to set. + True to throw on error. + The status code for the attribute. + Thrown on error. + + + + Set a named attribute for a pipe. + + The attribute type to set. + The name of the attribute. + The value to set. + Thrown on error. + + + + Set a named attribute for a pipe. + + The attribute type to set. + The name of the attribute. + The value to set. + True to throw on error. + The status code for the attribute. + Thrown on error. + + + + Set a named attribute for a pipe. + + The attribute type to set. + The name of the attribute. + The value to set. + Thrown on error. + + + + Set a named attribute for a pipe. + + The attribute type to set. + The name of the attribute. + The value to set. + True to throw on error. + The status code for the attribute. + Thrown on error. + + + + Set a named attribute for a pipe. + + The attribute type to set. + The name of the attribute. + The value to set. + Thrown on error. + + + + Get a named attribute from the pipe. + + The attribute type to query. + The name of the attribute. + The attribute value as a byte array. + Thrown on error. + + + + Get a named attribute from the pipe as an integer. + + The attribute type to query. + The name of the attribute. + True to throw on error. + The attribute value as an integer. + Thrown on error. + + + + Get a named attribute from the pipe as an integer. + + The attribute type to query. + The name of the attribute. + The attribute value as an integer. + Thrown on error. + + + + Get a named attribute from the pipe as an integer. + + The attribute type to query. + The name of the attribute. + True to throw on error. + The attribute value as an integer. + Thrown on error. + + + + Get a named attribute from the pipe as an integer. + + The attribute type to query. + The name of the attribute. + The attribute value as an integer. + Thrown on error. + + + + Send and receive a message in one call. + + The input buffer to send. + The maximum output size. + True to throw on error. + The received buffer. + + + + Send and receive a message in one call. + + The input buffer to send. + The maximum output size. + The received buffer. + + + + Send and receive a message in one call. + + The input buffer to send. + The maximum output size. + True to throw on error. + The received buffer. + + + + Send and receive a message in one call. + + The input buffer to send. + The maximum output size. + The received buffer. + + + + Set pipe information flags. + + The read mode to set. + The completion mode. + True to throw on error. + The NT status code. + + + + Set pipe information flags. + + The read mode to set. + The completion mode. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Pipe completion mode. + + + + + Pipe read mode. + + + + + Pipe type. + + + + + Pipe configuration. + + + + + Maximum instances of the pipe, -1 is unlimited. + + + + + Current pipe instances. + + + + + Inbound quota. + + + + + Available bytes to read. + + + + + Outbound quota. + + + + + Available outbound quota. + + + + + Connect state of the named pipe. + + + + + Type of pipe endpoint. + + + + + Class to add additional methods to a file for a named pipe server. + + + + + Listen for a new connection to this named pipe server. + + + + + Listen for a new connection to this named pipe server asynchronously. + + An optional cancellation token. + The async task to complete. + + + + Listen for a new connection to this named pipe server asynchronously. + + The async task to complete. + + + + Disconnect this named pipe server. + + + + + Disconnect this named pipe server asynchronously. + + An optional cancellation token. + The async task to complete. + + + + Disconnect this named pipe server asynchronously. + + The async task to complete. + + + + Impersonate the client of the named pipe. + + The impersonation context. Dispose to revert to self. + + + + Get client process ID. + + + + + Get client session ID. If this is 0 then the client is local, otherwise it's set by the SMB server. + + + + + Get client computer name. + + + + + Get the default named pipe ACL for the current caller. + + The default named pipe ACL. + + + + Class to add additional methods to a file for a named pipe client. + + + + + Disables impersonation on a named pipe. + + + + + Get server process ID. + + + + + Get client session ID. + + + + + A pair of named pipes. + + + + + Read pipe for the pair. + + + + + Write pipe for the pair. + + + + + Base class for all NtObject types we handle + + + + + Get the basic information for the object. + + The basic information + + + + Base constructor + + Handle to the object + + + + Duplicate the internal handle to a new handle. + + Attribute flags for new handle + The source handle to duplicate + The source process to duplicate from + The desination process for the handle + Duplicate handle options + The access rights for the new handle + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate the internal handle to a new handle. + + The source handle to duplicate + The desination process for the handle + Duplicate handle options + The access rights for the new handle + The duplicated handle. + + + + Duplicate a handle from the current process to a new handle with the same access rights. + + The source handle to duplicate + The desination process for the handle + The duplicated handle. + + + + Duplicate a handle from and to the current process to a new handle with the same access rights. + + The source handle to duplicate + The duplicated handle. + + + + Duplicate a handle from and to the current process to a new handle with the same access rights. + + The source handle to duplicate + True to throw on error. + The duplicated handle. + + + + Duplicate a handle from and to the current process to a new handle with new access rights. + + The source handle to duplicate + The access for the new handle. + The duplicated handle. + + + + Indicates whether a specific type of kernel object can be opened. + + The kernel typename to check. + True if this type of object can be opened. + + + + Open an NT object with a specified type. + + The type to open. If null the method will try and lookup the appropriate type. + Object attributes for object. + Generic access rights to the object. + True to throw on error. + The opened object. + Thrown if an error occurred opening the object. + + + + Open an NT object with a specified type. + + The name of the type to open (e.g. Event). If null the method will try and lookup the appropriate type. + The path to the object to open. + A root directory to open from. + Generic access rights to the object. + Attributes to open the object. + Security quality of service. + True to throw on error. + The opened object. + Thrown if an error occurred opening the object. + + + + Open an NT object with a specified type. + + The name of the type to open (e.g. Event). If null the method will try and lookup the appropriate type. + The path to the object to open. + A root directory to open from. + Generic access rights to the object. + Attributes to open the object. + Security quality of service. + The opened object. + Thrown if an error occurred opening the object. + + + + Open an NT object with a specified type. + + The name of the type to open (e.g. Event). If null the method will try and lookup the appropriate type. + The path to the object to open. + A root directory to open from. + Generic access rights to the object. + The opened object. + Thrown if an error occurred opening the object. + Thrown if type of resource couldn't be found. + + + + Close a handle in another process. + + The source handle to close. + The source process containing the handle to close. + True to throw an exception on error. + The NT status code. + + + + Close a handle in another process. + + The source handle to close. + The source process containing the handle to close. + + + + Close a handle in another process by PID. + + The source handle to close. + The source process ID containing the handle to close. + True to throw an exception on error. + The NT status code. + + + + Close a handle in another process by PID. + + The source handle to close. + The source process ID containing the handle to close. + + + + Close a handle. + + The handle to close. + The NT status code. + + + + Close a handle. + + The handle to close. + The NT status code. + + + + Duplicate a handle to a new handle, potentially in a different process. + + Attribute flags for new handle + The source handle to duplicate + The source process to duplicate from + The desination process for the handle + Duplicate handle options + The access rights for the new handle + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate a handle to a new handle, potentially in a different process. + + Attribute flags for new handle + The source handle to duplicate + The source process to duplicate from + The desination process for the handle + Duplicate handle options + The access rights for the new handle + The NT status code and object result. + + + + Duplicate object. + + Access rights to duplicate with. + Attribute flags. + Duplicate options + True to throw an exception on error. + The duplicated object. + + + + Duplicate object. + + Access rights to duplicate with. + Attribute flags. + Duplicate options + The duplicated object. + + + + Duplicate object with specific access rights. + + Access rights to duplicate with. + The duplicated object. + + + + Duplicate object with same access rights. + + The duplicated object. + + + + Duplicate the object handle as a WaitHandle. + + The wait handle. + + + + Check if access is granted to a set of rights + + The access rights to check + True if all the access rights are granted + + + + Get security descriptor as a byte array + + What parts of the security descriptor to retrieve + The security descriptor + + + + Get security descriptor as a byte array + + What parts of the security descriptor to retrieve + True to throw on error. + The NT status result and security descriptor. + + + + Get security descriptor as a byte array + + Returns an array of bytes for the security descriptor + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + The NT status result. + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + The NT status code. + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Get the security descriptor as an SDDL string + + The security descriptor as an SDDL string + + + + Make the object a temporary object + + True to throw on error. + The NT status code. + + + + Make the object a temporary object + + + + + Make the object a permanent object + + True to throw on error. + The NT status code. + + + + Make the object a permanent object + + + + + Wait on the object to become signaled + + True to make the wait alertable + The time out + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + Thrown on error + + + + Wait on the object to become signaled + + The time out + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + Thrown on error + + + + Wait on the object to become signaled + + True to make the wait alertable + The time out in seconds + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + Thrown on error + + + + Wait on the object to become signaled + + The time out in seconds + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + Thrown on error + + + + Wait on the object to become signaled for an infinite time. + + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + Thrown on error + + + + Wait on the object to become signaled. + + Timeout in seconds. + Cancellation token for wait. + A task to wait on. If result is true then event was signaled. + + + + Wait on the object to become signaled. + + Timeout in seconds. + A task to wait on. If result is true then event was signaled. + + + + Wait on the object to become signaled. + Will wait an infinite time. + + A task to wait on. + + + + Convert an enumerable access rights to a string + + True to try and convert to generic rights where possible. + The string format of the access rights + + + + Convert an enumerable access rights to a string + + The string format of the access rights + + + + Check if this object is exactly the same as another using NtCompareObject. + + The object to compare against. + True if this is the same object. + Thrown on error. + This is only supported on Windows 10 and above. For one which works on everything use SameObject. + + + + Check if this object is exactly the same as another. + + The object to compare against. + True if this is the same object. + Thrown on error. + This function can be slow to run and unreliable. Use CompareObject is Windows 10 or above. + + + + Convert to a string + + The string form of the object + + + + Get full path to the object + + + + + Get the granted access as an unsigned integer + + + + + Get the security descriptor, with Dacl, Owner, Group and Label + + + + + Get the security descriptor as an SDDL string + + The security descriptor as an SDDL string + + + + The low-level handle to the object. + + + + + Get the NT type name for this object. + + The NT type name. + + + + Get the NtType for this object. + + The NtType for the type name + + + + Get the name of the object + + + + + Indicates if the handle can be used for synchronization. + + + + + Get object creation time. + + + + + Get the attribute flags for the object. + + + + + Get number of handles for this object. + + + + + Get reference count for this object. + + + + + Get or set whether the handle is inheritable. + + + + + Get or set whether the handle is protected from closing. + + + + + Get the object's address is kernel memory. + + As getting the address is expensive you need to pass the object to NtSystemInfo::ResolveObjectAddress to intialize. + + + + Returns whether this object is a container. + + + + + Returns whether this object is closed. + + + + + Virtual Dispose method. + + True if disposing, false if finalizing + + + + Finalizer + + + + + Dispose + + + + + Close handle + + + + + Generic access rights. + + + + + Options for duplicating objects. + + + + + Close the original handle. + + + + + Duplicate with the same access. + + + + + Duplicate with the same handle attributes. + + + + + Prevent duplicating handle above the existing access. + + + + + Information class for NtQueryObject + + + + + + Structure to return Object Name + + + + + Structure to return Object basic information + + + + + Type of kernel pool used for object allocation + + + + + Native structure used for getting type information. + + + + + Static utility methods. + + + + + Convert the safe handle to an array of bytes. + + The data contained in the allocaiton. + + + + Convert an NtStatus to an exception if the status is an error + + The NtStatus + The original NtStatus if not an error + Thrown if status is an error. + + + + Convert an NtStatus to an exception if the status is an error and throw_on_error is true. + + The NtStatus + True to throw an exception onerror. + The original NtStatus if not thrown + Thrown if status is an error and throw_on_error is true. + + + + Checks if the NtStatus value is a success + + The NtStatus value + True if a success + + + + Checks if the NtStatus value is an error. + + The NtStatus value + True if an error. + + + + Get the severity of the NTSTATUS. + + The NtStatus value + The severity. + + + + Get the facility of the NTSTATUS. + + The NtStatus value + The facility. + + + + Get the status code of the NTSTATUS. + + The NtStatus value. + The static code. + + + + Is an NTSTATUS a customer code. + + The NtStatus value + True if is a customer code. + + + + Is an NTSTATUS reserved. + + The NtStatus value + True if reserved. + + + + Build a status from it's component parts. + + The severity of the status code. + Is this a customer code? + Is this a reserved code? + The facility. + The status code. + + + + + Convert an NTSTATUS to a message description. + + The status to convert. + The message description, or an empty string if not found. + + + + Convert an integer to an NtStatus code. + + The integer status. + The converted code. + + + + Convert an enumerable access rights to a string + + The granted access mask. + Generic mapping for object type. + Enum type to convert to string. + True to try and convert to generic rights where possible. + The string format of the access rights + + + + Convert an IEnumerable to a Disposable List. + + + + + + + + Run a function on an NtResult and dispose the result afterwards. + + The underlying result type. + The result of the function. + The result. + The function to call. + The default value to return if an error occurred. + The result of func. + If result is not a success then the function is not called. + + + + Run a function on an NtResult and dispose the result afterwards. + + The underlying result type. + The result of the function. + The result. + The function to call. + The result of func. + If result is not a success then the function is not called. + + + + Run an action on an NtResult and dispose the result afterwards. + + The underlying result type. + The result. + The action to call. + If result is not a success then the action is not called. + + + + Run a function on an NtResult and dispose the result afterwards. + + The underlying result type. + The result of the function. + The result. + The function to call. + The result of func. + + + + Run an action on an NtResult and dispose the result afterwards. + + The underlying result type. + The result. + The action to call. + + + + Convert a handle to a known object type. + + The handle. + The object type. + + + + Convert a handle to a known object type. + + The handle. + True to own the handle. + The object type. + + + + Convert a handle to a known object type. + + The handle. + True to own the handle. + The object type. + + + + Map a DOS error to an NT status code. + + The DOS error. + The NT status code. + + + + Map a status to a DOS error code. Takes into account NTWIN32 + status codes. + + The status code. + The mapped DOS error. + + + + Get the last NT status code in this thread set for Win32 last error. + + The last NT status code. + + + + Create an NT result object. If status is successful then call function otherwise use default value. + + The result type. + The associated status code. + Throw an exception on error. + Function to call to create an instance of the result + The created result. + + + + Create a successful NT result object. + + The result type. + The result value. + The created result. + + + + Create an NT result object. If status is successful then call function otherwise use default value. + + The result type. + The associated status code. + Throw an exception on error. + Function to call to create an instance of the result + Function to call on error. + The created result. + + + + Create an NT result object. If status is successful then call function otherwise use default value. + + The result type. + The associated status code. + Throw an exception on error. + Function to call to create an instance of the result + The created result. + + + + A derived class to add some useful functions such as Duplicate + + The derived type to use as return values + An enum which represents the access mask values for the type + + + + Reopen object with different access rights. + + The desired access. + Additional attributes for open. + True to throw on error. + The reopened object. + + + + Reopen object with different access rights. + + The desired access. + True to throw on error. + The reopened object. + + + + Reopen object with different access rights. + + The desired access. + The reopened object. + + + + Duplicate object. + + Access rights to duplicate with. + Attribute flags. + Duplicate options + True to throw an exception on error. + The duplicated object. + + + + Duplicate object. + + Access rights to duplicate with. + Attribute flags. + Duplicate options + True to throw an exception on error. + The duplicated object. + + + + Duplicate object. + + Access rights to duplicate with. + Attribute flags. + Duplicate options + The duplicated object. + + + + Duplicate the object with specific access rights + + The access rights for the new handle + The duplicated object + + + + Duplicate the object with specific access rights + + The access rights for the new handle + True to throw an exception on error. + The duplicated object + + + + Duplicate the object with same access rights + + The duplicated object + + + + Duplicate the object with same access rights + + True to throw on error. + The duplicated object + + + + Get granted access for handle. + + Granted access + + + + Get generic granted access for handle. + + Generic Granted access + + + + Get the maximum permission access for this object based on a token + and it's security descriptor. + + The token to check against. + Returns 0 if can't read the security descriptor. + + + + Get the maximum permission access for this object based on the current token + and its security descriptor. + + Returns 0 if can't read the security descriptor. + + + + Check if a specific set of access rights is granted + + The access rights to check + True if all access rights are granted + + + + Create a new instance from a kernel handle + + The kernel handle + The new typed instance + + + + Create a new instance from a kernel handle + + The kernel handle + True to own the handle. + The new typed instance + + + + Create a new instance from a kernel handle. + + The kernel handle + The call doesn't own the handle. The returned object can't be used to close the handle. + The new typed instance + + + + Duplicate an instance from a process + + The process (with DupHandle access) + The handle value to duplicate + The access rights to duplicate with + The options for duplication. + The attribute flags for the new object. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from a process + + The process (with DupHandle access) + The handle value to duplicate + The access rights to duplicate with + The options for duplication. + The attribute flags for the new object. + The NT status code and object result. + + + + Duplicate an instance from a process + + The process (with DupHandle access) + The handle value to duplicate + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from a process + + The process ID + The handle value to duplicate + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from a process with a specified access rights. + + The process (with DupHandle access) + The handle value to duplicate + The access rights to duplicate. + The duplicated handle + + + + Duplicate an instance from a process + + The process ID + The handle value to duplicate + The access rights to duplicate with + The duplicated handle + + + + Duplicate an instance from a process with same access rights. + + The process (with DupHandle access) + The handle value to duplicate + The duplicated object. + + + + Duplicate an instance from a process with same access rights + + The process ID + The handle value to duplicate + The duplicated handle + + + + Duplicate an instance from current process to an other process + + The destination process (with DupHandle access) + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from current process to an other process + + The destination process (with DupHandle access) + The handle value to duplicate + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from current process to an other process + + The destination process ID + The handle value to duplicate + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from current process to an other process with a specified access rights. + + The destination process (with DupHandle access) + The handle value to duplicate + The access rights to duplicate. + The duplicated handle + + + + Duplicate an instance from current process to an other process + + The destination process ID + The handle value to duplicate + The access rights to duplicate with + The duplicated handle + + + + Duplicate an instance from current process to an other process with same access rights. + + The destination process (with DupHandle access) + The handle value to duplicate + The duplicated object. + + + + Duplicate an instance from current process to an other process with same access rights. + + The destination process (with DupHandle access) + The duplicated object. + + + + Duplicate an instance from current process to an other process with same access rights + + The destination process ID + The handle value to duplicate + The duplicated handle + + + + Duplicate an instance from current process to an other process with same access rights + + The destination process ID + The duplicated handle + + + + Duplicate an instance from a process to an other process + + The source process (with DupHandle access) + The handle value to duplicate + The destination process (with DupHandle access) + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from a process to an other process + + The source process ID + The handle value to duplicate + The destination process ID + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from a process to an other process with a specified access rights. + + The source process (with DupHandle access) + The handle value to duplicate + The destination process (with DupHandle access) + The access rights to duplicate. + The duplicated handle + + + + Duplicate an instance from a process to an other process + + The source process ID + The handle value to duplicate + The destination process ID + The access rights to duplicate with + The duplicated handle + + + + Duplicate an instance from a process to an other process with same access rights. + + The source process (with DupHandle access) + The handle value to duplicate + The destination process (with DupHandle access) + The duplicated object. + + + + Duplicate an instance from a process to an other process with same access rights + + The source process ID + The handle value to duplicate + The destination process ID + The duplicated handle + + + + Interface to generically query an object. + + + + + Interface to generically set an object. + + + + + A derived class to add some useful functions such as Duplicate as well as generic Query and Set information methods. + + The derived type to use as return values + An enum which represents the access mask values for the type + An enum which represents the information class for query. + An enum which represents the information class for set. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + The result of the query. + Thrown on error. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + The result of the query. + Thrown on error. + + + + Query an enumerated value from the object. + + The type of enum to return. + The base type for the enumeration. + The information class to query. + The result of the query. + Thrown on error. + + + + Query an enumerated value from the object. + + The type of enum to return. + The information class to query. + The result of the query. + Thrown on error. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Query the information class as an object. + + The information class. + The information class as an object. + If the information class doesn't have an explicit object type a raw byte query will be made. + + + + Query a variable buffer from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The information class to query. + A buffer to initialize the initial query. Can be null. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The information class to query. + A buffer to initialize the initial query. Can be null. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The information class to query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object and return as bytes. + + The information class to query. + A buffer to initialize the initial query. Can be null. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object and return as bytes. + + The information class to query. + A buffer to initialize the initial query. Can be null. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object and return as bytes. + + The information class to query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The type of structure to return. + The information class to query. + The result of the query. + Thrown on error. + + + + Set a value to the object. + + The type of structure to set. + The information class to set. + The value to set. If you specify a SafeBuffer then it'll be passed directly. + True to throw on error. + The NT status code of the set. + Thrown on error. + + + + Set a value to the object. + + The type of structure to set. + The information class to set. + The value to set. + The NT status code of the set. + Thrown on error. + + + + Set a value to the object from a buffer. + + The information class to set. + The value to set. + True to throw on error. + The NT status code of the set. + Thrown on error. + + + + Set a value to the object from a buffer.. + + The information class to set. + The value to set. + The NT status code of the set. + Thrown on error. + + + + Set a raw value to the object. + + The information class to set. + The raw value to set. + True to throw on error. + The NT status code of the set. + Thrown on error. + + + + Set a raw value to the object. + + The information class to set. + The raw value to set. + The NT status code of the set. + Thrown on error. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Overriddable method to determine the maximum brute force length for query. + + Information class to key on if needs to return different sizes. + The maximum bytes to brute force. Returning 0 will disable brute force. + + + + Overridable method to determine if the return length shouldn't be trusted for this info class when querying a variable buffer. + + Information class to key on. + True to trust the return length when querying a variable buffer. + + + + Class representing a NT Partition object + + + + + Create a partition object + + The object attributes + Optional parent parition. + Desired access for the partition. + The preferred node, -1 for any node. + True to throw an exception on error. + The NT status code and object result. + + + + Create a partition object + + The object attributes + Optional parent parition. + Desired access for the partition. + The preferred node, -1 for any node. + The NT status code and object result. + + + + Open a partition object + + The object attributes + Desired access for the partition. + True to throw an exception on error. + The NT status code and object result. + + + + Open a partition object + + The object attributes + Desired access for the partition. + The NT status code and object result. + + + + Class representing a NT Process object. + + + + + Gets all accessible processes on the system. + + The access desired for each process. + The list of accessible processes. + + + + Gets all accessible processes on the system. + + The access desired for each process. + True to get processes from system information rather than NtGetNextProcess + The list of accessible processes. + + + + Gets all accessible processes on the system in a particular session. + + The session ID. + The access desired for each process. + The list of accessible processes. + + + + Gets all accessible processes on the system in the current session session. + + The access desired for each process. + The list of accessible processes. + + + + Get first accessible process (used in combination with GetNextProcess) + + The access required for the process. + The accessible process, or null if one couldn't be opened. + + + + Open a process + + The process ID to open + Optional thread ID to verify the correct process is opened. + The desired access for the handle + True to throw an exception on error. + The NT status code and object result. + + + + Open a process + + The process ID to open + The desired access for the handle + True to throw an exception on error. + The NT status code and object result. + + + + Open a process + + The process ID to open + The desired access for the handle + The opened process + + + + Open a process + + The process ID to open + Optional thread ID to verify the correct process is opened. + The desired access for the handle + The opened process. + + + + Create a new process + + Optional object attributes. + Desired access for the new process. + The parent process + Creation flags + Handle to the executable image section + Debug port for the new process. + Access token for the new process. + True to throw on error. + The created process + + + + Create a new process + + Desired access for the new process. + Optional object attributes. + The parent process + Creation flags + Handle to the executable image section + Debug port for the new process. + Access token for the new process. + The created process + + + + Create a new process + + The parent process + Creation flags + Handle to the executable image section + Access token for the new process. + The created process + + + + Create a new process + + The parent process + Creation flags + Handle to the executable image section + The created process + + + + Create a new process + + Handle to the executable image section + Access token for the new process. + The created process + + + + Create a new process + + Handle to the executable image section + The created process + + + + Create a new process + + Optional object attributes. + Desired access for the new process. + The parent process + Creation flags + Handle to the executable image section + Debug port for the new process. + Access token for the new process. + True to throw on error. + The created process + This uses NtCreateProcessEx rather than NtCreateUserProcess + + + + Create a new process + + Desired access for the new process. + Optional object attributes. + The parent process + Creation flags + Handle to the executable image section + Debug port for the new process. + Access token for the new process. + The created process + + + + Create a new user process. + + The process configuration. + True to throw on error. + The result of the process creation + + + + Create a new user process. + + The process configuration. + The result of the process creation + + + + Fork a process. + + The process configuration. + True to throw on error. + The new forked process result + This uses NtCreateUserProcess. + + + + Fork a process. + + The process configuration. + The new forked process result + This uses NtCreateUserProcess. + + + + Open an actual handle to the current process rather than the pseudo one used for Current + + The process object + + + + Test whether a process can access another protected process. + + The current process. + The target process. + True if the process can be accessed. + + + + Reopen object with different access rights. + + The desired access. + Additional attributes for open. + True to throw on error. + The reopened object. + + + + Get next accessible process (used in combination with GetFirstProcess) + + The access required for the process. + The accessible process, or null if one couldn't be opened. + + + + Get previous accessible process (used in combination with GetFirstProcess) + + The access required for the process. + The accessible process, or null if one couldn't be opened. + + + + Get previous accessible process (used in combination with GetFirstProcess) + + The accessible process, or null if one couldn't be opened. + + + + Get first accessible thread for process. + + The desired access for the thread. + The first thread object, or null if not accessible threads. + + + + Get first accessible thread for process. + + The first thread object, or null if not accessible threads. + + + + Get accessible threads for a process. + + The desired access for the threads + The list of threads + + + + Get accessible threads for a process. + + The list of threads + + + + Read a partial PEB from the process. + + The read PEB structure. + + + + Create a new process + + Creation flags + Handle to the executable image section + The created process + This uses NtCreateProcessEx rather than NtCreateUserProcess + + + + Create a new process + + Optional object attributes. + Desired access for the new process. + Creation flags + Handle to the executable image section + Debug port for the new process. + Access token for the new process. + True to throw on error. + The created process + This uses NtCreateProcessEx rather than NtCreateUserProcess + + + + Create a new process + + Optional object attributes. + Desired access for the new process. + Creation flags + Handle to the executable image section + Debug port for the new process. + Access token for the new process. + The created process + This uses NtCreateProcessEx rather than NtCreateUserProcess + + + + Terminate the process + + The exit code for the termination + + + + Terminate the process + + The exit code for the termination + + + + Terminate the process + + The exit code for the termination + True to throw on error. + The NT status code. + + + + Get process image file path + + True to return the native image path, false for a Win32 style path + True to throw on error. + The process image file path + + + + Get process image file path + + True to return the native image path, false for a Win32 style path + The process image file path + + + + Get a mitigation policy raw value + + The policy to get + True to throw on error. + The raw policy value + + + + Get a mitigation policy raw value + + The policy to get + The raw policy value + + + + Get a mitigation policy as an enumeration. + + The policy to get. + True to throw on error. + The mitigation policy value + + + + Get a mitigation policy as an enumeration. + + The policy to get. + The mitigation policy value + + + + Get a mitigation policy raw value + + The policy to get + True to throw on error. + The raw policy value + + + + Get a mitigation policy raw value + + The policy to get + The raw policy value + + + + Set a mitigation policy raw value + + The policy to set + The value to set + True to throw on error. + The NT status code. + + + + Set a mitigation policy raw value + + The policy to set + The value to set + + + + Set a mitigation policy value from an enum. + + The policy to set + The value to set + True to throw on error. + The NT status code. + + + + Set a mitigation policy value from an enum. + + The policy to set + The value to set + + + + Set a mitigation policy raw value + + The policy to set + The value to set + True to throw on error. + The NT status code. + + + + Set a mitigation policy raw value + + The policy to set + The value to set + + + + Disable dynamic code policy on another process. + + + + + Suspend the entire process. + + True to throw on error. + The NT status code. + + + + Resume the entire process. + + True to throw on error. + The NT status code. + + + + Suspend the entire process. + + + + + Resume the entire process. + + + + + Open the process' token + + The process token. + + + + Open the process' token + + True to throw on error. + The process token. + + + + Open the process' token + + Desired access for token. + True to throw on error. + The process token. + + + + Set process access token. Process must be have not been started. + + The token to set. + True to throw on error. + The NT status code. + + + + Set process access token. Process must be have not been started. + + The token to set. + + + + Read memory from a process. + + The base address in the process. + The length to read. + If true ensure we read all bytes, otherwise throw on exception. + The array of bytes read from the location. + If a read is short then returns fewer bytes than requested. + Thrown on error. + + + + Read memory from a process. + + The base address in the process. + The length to read. + The array of bytes read from the location. + If a read is short then returns fewer bytes than requested. + Thrown on error. + + + + Write memory to a process. + + The base address in the process. + The data to write. + The number of bytes written to the location + Thrown on error. + + + + Read structured memory from a process. + + The base address in the process. + The read structure. + Thrown on error. + Type of structure to read. + + + + Write structured memory to a process. + + The base address in the process. + The data to write. + Thrown on error. + Type of structure to write. + + + + Read structured memory array from a process. + + The base address in the process. + The number of elements in the array to read. + The read structure. + Thrown on error. + Type of structure to read. + + + + Write structured memory array to a process. + + The base address in the process. + The data array to write. + Thrown on error. + Type of structure to write. + + + + Query memory information for a process. + + The base address. + The queries memory information. + Thrown on error. + + + + Query all memory information regions in process memory. + + The list of memory regions. + Specify memory types to filter on. + Set of flags which indicate the memory states to return. + Thrown on error. + + + + Query all memory information regions in process memory. + + The list of memory regions. + True to include free regions of memory. + Specify memory types to filter on. + Thrown on error. + + + + Query all memory information regions in process memory. + + The list of memory regions. + True to include free regions of memory. + Thrown on error. + + + + Query all memory information regions in process memory excluding free regions. + + The list of memory regions. + Thrown on error. + + + + Query a list of mapped images in a process. + + The list of mapped images + Thrown on error. + + + + Query a list of mapped files in a process. + + The list of mapped images + Thrown on error. + + + + Query a list of all mapped files and images in a process. + + The list of mapped images + Thrown on error. + + + + Allocate virtual memory in a process. + + Optional base address, if 0 will automatically select a base. + The region size to allocate. + The type of allocation. + The allocation protection. + True to throw on error. + The address of the allocated region. + Thrown on error. + + + + Allocate virtual memory in a process. + + Optional base address, if 0 will automatically select a base. + The region size to allocate. + The type of allocation. + The allocation protection. + The address of the allocated region. + Thrown on error. + + + + Allocate read/write virtual memory in a process. + + The region size to allocate. + The address of the allocated region. + Thrown on error. + + + + Free virtual emmory in a process. + + Base address of region to free + The size of the region. + The type to free. + Thrown on error. + + + + Free virtual emmory in a process. + + Base address of region to free + The size of the region. + The type to free. + True to throw on error. + Thrown on error. + + + + Change protection on a region of memory. + + The base address + The size of the memory region. + The new protection type. + The old protection for the region. + Thrown on error. + + + + Change protection on a region of memory. + + The base address + The size of the memory region. + The new protection type. + True to throw on error. + The old protection for the region. + Thrown on error. + + + + Flush instruction cache. + + The address to flush. + The number of bytes to flush/ + True to throw on error. + The NT status code. + + + + Flush instruction cache. + + The address to flush. + The number of bytes to flush/ + + + + Query working set information for an address in a process. + + The base address to query. + True to throw on error + The working set information. + Thrown on error. + + + + Query working set information for an address in a process. + + The base address to query. + The working set information. + Thrown on error. + + + + Set the process device map. + + The device map directory to set. + Note that due to a bug in the Wow64 layer this won't work in a 32 bit process on a 64 bit system. + + + + Set the process device map. + + The device map directory to set. + True to throw on error. + Note that due to a bug in the Wow64 layer this won't work in a 32 bit process on a 64 bit system. + + + + Set the process device map. + + The device map directory to set. + Note that due to a bug in the Wow64 layer this won't work in a 32 bit process on a 64 bit system. + + + + Set the process device map. + + The device map directory to set. + True to throw on error. + Note that due to a bug in the Wow64 layer this won't work in a 32 bit process on a 64 bit system. + + + + Open a process' debug object. + + True to throw on error. + The process' debug object. + + + + Open a process' debug object. + + The process' debug object. + + + + Queries whether process is backed by a specific file. + + File object opened with Synchronize and Execute access to test against. + True if the process is created from the image file. + + + + Open parent process by ID. + + The desired process access rights. + True to throw on error. + The opened process. + Thrown on error. + + + + Open parent process by ID. + + The desired process access rights. + The opened process. + Thrown on error. + + + + Open parent process by ID. + + The opened process. + Thrown on error. + + + + Open owner process by ID. + + The desired process access rights. + True to throw on error. + The opened process. + Thrown on error. + + + + Open owner process by ID. + + The desired process access rights. + The opened process. + Thrown on error. + + + + Open owner process by ID. + + The opened process. + Thrown on error. + + + + Get if process is in a job. + + A specific job to check + True if in specific job. + + + + Get if process is in a job. + + True if in a job. + + + + Get process handle table. + + The list of process handles. + + + + Get handles for process. + + Specify to all name/details to be queried from the handle. + Force file query for name/details for non-filesystem handles. + True to throw on error. + The list of handles. + This queries the handles from the process which does not contain the Object's addres in kernel memory. + + + + Get handles for process. + + Specify to all name/details to be queried from the handle. + True to throw on error. + The list of handles. + This queries the handles from the process which does not contain the Object's addres in kernel memory. + + + + Get handles for process. + + Specify to all name/details to be queried from the handle. + The list of handles. + This queries the handles from the process which does not contain the Object's addres in kernel memory. + + + + Get handles for process. + + The list of handles. + This queries the handles from the process which does not contain the Object's addres in kernel memory. + + + + Get the process handle table and try and get them as objects. + + True to only return named objects + A list of typenames to filter on (if empty then return all) + The list of handles as objects. + This function will drop handles it can't duplicate. + + + + Get the process handle table and try and get them as objects. + + The list of handles as objects. + This function will drop handles it can't duplicate. + + + + Open image section for process. + + True to throw on error. + The opened image section. + Should only work on the pseudo process handle. + + + + Open image section for process. + + The opened image section. + Should only work on the pseudo process handle. + + + + Unmap a section. + + The base address to unmap. + Flags for unmapping memory. + True to throw on error. + The NT status code. + + + + Unmap a section. + + The base address to unmap. + True to throw on error. + The NT status code. + + + + Unmap a section. + + The base address to unmap. + Flags for unmapping memory. + + + + Unmap a section. + + The base address to unmap. + + + + Get the user SID for the process. + + True to throw on error. + The user SID. + + + + Get the user SID for the process. + + The user SID. + + + + Get the integrity level for the process. + + True to throw on error. + The integerity level. + + + + Set process fault flags. + + The flags to set. + True to throw on error. + The NT status code for the operation. + + + + Set process fault flags. + + The flags to set. + The NT status code for the operation. + + + + Set the process exception port. + + The exception port to set. + Additional state flags. + True to throw on error. + The NT status code. + + + + Set the process exception port. + + The exception port to set. + True to throw on error. + The NT status code. + + + + Set the process exception port. + + The exception port to set. + The NT status code. + + + + Get the user process parameters. + + The user process parameters. + + + + Fork the process. + + Extra flags for fork. + True to throw on error. + The new forked process result. + This uses NtCreateProcessEx. + + + + Fork the process. + + Extra flags for fork. + The new forked process result. + This uses NtCreateProcessEx. + + + + Fork the process. + + The new forked process result. + This uses NtCreateProcessEx. + + + + Get the accessible job objects this process is in. + + This tries to find accessible Job handles. There's no guarantee that all Job objects will be found for the process. + The list of job objects. + + + + Set thread intelligence logging flags. + + The flags to set. + True to throw on error. + The NT status code. + + + + Set thread intelligence logging flags. + + The flags to set. + + + + Get the process security domain. + + True to throw on error. + The security domain. + + + + Get the process security domain. + + The security domain. + + + + Combine two process' security domains. + + The process to combine with. Needs QueryLimitedInformation. + True to throw on error. + The NT status code. + The current process need SetLimitedInformation access. + + + + Combine two process' security domains. + + The process to combine with. Needs QueryLimitedInformation. + The current process need SetLimitedInformation access. + + + + Get the session ID for the process. + + True to throw on error. + The session ID. + + + + Test whether the current process can access another protected process. + + The target process. + True if the process can be accessed. + + + + Get the environment from the process. + + List of environment variables. + + + + Get an environment variable by name. + + The name of the variable. + The value of the environment variable. Returns null if it doesn't exist. + Only returns the first variable with a case insensitive name. + + + + Revoke file handles for an AppContainer process. + + The device path for the files to revoke. + True to throw on error. + The NT status code. + + + + Revoke file handles for an AppContainer process. + + The device path for the files to revoke. + + + + Get the process command line. + + True to throw on error. + The process command line. + + + + Get the IO counters for the process. + + True to throw on error. + The IO counters. + + + + Create a VBS enclave. + + Size of the enclave. + Flags for the enclave. + Owner ID. Must be 32 bytes. + True to throw on error. + The created enclave. + + + + Create a VBS enclave. + + Size of the enclave. + Flags for the enclave. + Owner ID. Must be 32 bytes. + The created enclave. + + + + Get priority boost disable value. + + True to throw on error. + True if priority base + + + + Set priority boost disable value. + + True to disable priority boost. + True to throw on error. + The NT status code. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get the process' session ID + + + + + Get the process' ID + + + + + Get the process' parent process ID + + + + + Get the memory address of the PEB + + + + + Get the memory address of the PEB for a 32 bit process. + + If the process is 64 bit, or the OS is 32 bit this returns the same value as PebAddress. + + + + Get the base address of the process from the PEB. + + + + + Read flags from PEB. + + + + + Get the process' exit status. + + + + + Get the process' exit status as an NtStatus code. + + + + + Get the process' command line + + + + + Get the command line as parsed arguments. + + + + + Get process DEP status + + + + + Get whether process has a debug port. + + + + + + Get handle count. + + + + + Get break on termination flag. + + + + + Get or set debug flags. + + + + + Get or set execute flags. + + + + + Get IO priority. + + + + + Get secure cookie. + + + + + Get the process user. + + + + + Get the integrity level of the process. + + + + + Get process mitigations + + + + + Get extended process flags. + + + + + Get process window title (from Process Parameters). + + + + + Get process window flags (from Process Parameters). + + + + + Get the process subsystem type. + + + + + Get if the process is Wow64 + + + + + Get whether the process is 64bit. + + + + + Get whether LUID device maps are enabled. + + + + + Return whether this process is sandboxed. + + + + + Get or set the hard error mode. + + + + + Does the process has a child process restriction? + + + + + Gets whether the process is currently deleting. + + + + + Gets whether the process is secure. + + + + + Gets whether the process is protected. + + + + + Gets whether the process is a subsystem process. + + + + + Gets whether the process is frozen. + + + + + Get process protection information. + + + + + Query process section image information. + + + + + Get full image path name in native format + + + + + Get the Win32 image path. + + + + + Get owner process ID + + + + + Query the process token's full package name. + + + + + Get or set whether resource virtualization is enabled. + + + + + Get the security domain of the process. + + + + + Get the creation time of the process. + + + + + Get the exit time of the process. + + + + + Get the time spent in the kernel. + + + + + Get the time spent in user mode. + + + + + Get the time spent in the kernel in seconds. + + + + + Get the time spent in user mode. + + + + + Get the process IO counters. + + + + + Get or set priority boost disabled. + + + + + Get the current process. + + This only uses the pseudo handle, for the process. If you need a proper handle use OpenCurrent. + + + + Get the current PEB address. + + + + + Configuration for a new NT Process. + + + + + Path to the executable to start. + + + + + Path to the executable to start which is passed in the process configuration. + + This doesn't have to match ImagePath. + + + + Command line + + + + + Prepared environment block. + + + + + Title of the main window. + + + + + Path to DLLs. + + + + + Current directory for new process + + + + + Desktop information value + + + + + Shell information value + + + + + Runtime data. + + + + + Prohibited image characteristics for new process + + + + + Additional file access for opened executable file. + + + + + Process create flags. + + + + + Thread create flags. + + + + + Initialization flags + + + + + Parent process. + + + + + Specify child process mitigations. + + + + + Whether to terminate the process on dispose. + + + + + Specify a security descriptor for the process. + + + + + Specify a security descriptor for the initial thread. + + + + + Specify the primary token for the new process. + + + + + Access for process handle. + + + + + Access for thread handle. + + + + + Set protection level. + + + + + Set to create a trustlet. + + + + + Set to specify the configuration for the trustlet if Secure is set. + + + + + Capture additional information when NtProcess.Create returns. + + + + + Specify callback to update process parameters. + + + + + Redirection DLL path. Only supported from 1903. + + + + + Inheritable handles. + + + + + Debug object. + + + + + Toggle inherit handles process create flag. + + + + + Add an extra process/thread attribute. + + The process attribute to add. + The caller is responsible for disposing the attribute, this class does not hold a reference. + + + + Set protected process protection level. + + The type of protected process. + The signer level. + + + + Constructor + + + + + Result from creating a user process. + + + + + Handle to the process + + + + + Handle to the initial thread + + + + + Handle to the image file + + + + + Handle to the image section + + + + + Handle to the IFEO key (if it exists) + + + + + Image information + + + + + Client ID of process and thread + + + + + Process ID + + + + + Thread ID + + + + + Create status. + + + + + True if create succeeded. + + + + + DLL characterists if CreateState is FailMachineMismatch. + + + + + Creation state + + + + + Output flags if CreateStatus is Success. + + + + + Native user process parameters pointer if CreateStatus is Success. + + + + + Wow64 user process parameters pointer if CreateStatus is Success. + + + + + Current parameter flags if CreateStatus is Success. + + + + + PEB pointer if CreateStatus is Success. + + + + + Wow64 PEB pointer if CreateStatus is Success. + + + + + Manifest pointer if CreateStatus is Success. + + + + + Manifest size if CreateStatus is Success. + + + + + Set to true to terminate process on disposal + + + + + Terminate the process + + Exit code for termination + + + + Resume initial thread + + The suspend count + + + + Explicit conversion operator to an NtThread object. + + The win32 process + + + + Explicit conversion operator to an NtProcess object. + + The win32 process + + + + Dispose + + + + + Entry for a process environment block. + + + + + Name of the environment variable. + + + + + Value of the environment variable. + + + + + Constructor. + + Name of the environment variable. + Value of the environment variable. + + + + Class representing various process mitigations + + + + + Partial definition of the PEB + + + + + Partial definition of the PEB + + + + + Class which represents the configuration for a trustlet. + + + + + The ID of the trustlet. + + + + + The mailbox key. Must be 2 longs. + + + + + The collaboration ID. Must be 2 longs. + + + + + The VM ID. Must be 2 longs. + + + + + The TK sessio ID. Must be 4 longs. + + + + + Overridden ToString method. + + The object as a string. + + + + Create a trustlet configuration from an image file. + + The path to the image file. Should be a native path. + True to throw on error. + The trustlet configuration. + + + + Create a trustlet configuration from an image file. + + The path to the image file. Should be a win32 path. + The trustlet configuration. + + + + Constructor + + + + + Constructor + + The ID of the trustlet. + + + + Class to represent a registry transaction object + + + + + Create a transaction + + The object attributes + Desired access for the handle + True to throw an exception on error. + The NT status code and object result. + + + + Create a transaction + + The object attributes + Desired access for the handle + The opened transaction + + + + Create a transaction + + The path of the transaction + The root if path is relative + The opened transaction + + + + Create a transaction + + The path of the transaction + The opened transaction + + + + Create a transaction + + The opened transaction + + + + Open a transaction object. + + The path to the object + The root if path is relative + The desired access for the object + The opened object + + + + Open a transaction object. + + The object attributes for the object + The desired access for the object + True to throw an exception on error. + The NT status code and object result. + + + + Open a transaction object. + + The object attributes for the object + The desired access for the object + The opened object + + + + Open a transaction object. + + The path to the object + The opened object + + + + Commit the transaction + + + + + Rollback the transaction + + + + + Enable the transaction for anything in the current thread context. + + The transaction context. This should be disposed to disable the transaction. + + + + Class to represent a transaction resource manager. + + + + + Create a new resource manager object. + + The object attributes + Desired access for the handle + Creation options flags. + Optional transaction manager to assign the resource manager to. + Resource manager GUID. + Optional description. + True to throw an exception on error. + The NT status code and object result. + + + + Create a new resource manager object. + + The object attributes + Desired access for the handle + Creation options flags. + Optional transaction manager to assign the resource manager to. + Resource manager GUID. + Optional description. + The object result. + Thrown on error. + + + + Create a new resource manager object. + + The path to the resource manager. + The root if path is relative. + Desired access for the handle + Creation options flags. + Optional transaction manager to assign the resource manager to. + Resource manager GUID. + Optional description. + True to throw an exception on error. + The NT status code and object result. + + + + Create a new resource manager object. + + The path to the resource manager. + The root if path is relative. + Desired access for the handle + Creation options flags. + Optional transaction manager to assign the resource manager to. + Resource manager GUID. + Optional description. + The object result. + Thrown on error. + + + + Create a new volatile resource manager object. + + The path to the resource manager. + The root if path is relative. + Desired access for the handle + Optional transaction manager to assign the resource manager to. + Resource manager GUID. + The object result. + Thrown on error. + + + + Create a new volatile resource manager object. + + The path to the resource manager. + The root if path is relative. + Desired access for the handle + Optional transaction manager to assign the resource manager to. + The object result. + Thrown on error. + + + + Create a new volatile resource manager object. + + The path to the resource manager. + The root if path is relative. + Optional transaction manager to assign the resource manager to. + The object result. + Thrown on error. + + + + Create a new volatile resource manager object. + + The path to the resource manager. + Optional transaction manager to assign the resource manager to. + The object result. + Thrown on error. + + + + Create a new volatile resource manager object. + + Optional transaction manager to assign the resource manager to. + The object result. + Thrown on error. + + + + Opens an existing resource manager object. + + The object attributes + Desired access for the handle + Transaction manager which contains the resource manager. + Resource manager GUID. + True to throw an exception on error. + The NT status code and object result. + + + + Opens an existing resource manager object. + + The object attributes + Desired access for the handle + Transaction manager which contains the resource manager. + Resource manager GUID. + The object result. + Thrown on error. + + + + Recover the the transaction manager. + + True to throw on error. + The NT status code. + + + + Recover the the transaction manager. + + + + + Set an IO completion port on the resource manager. + + The IO completion port. + Associated completion key. + True to throw on error. + The NT status code. + + + + Set an IO completion port on the resource manager. + + The IO completion port. + Associated completion key. + + + + Get a notification synchronously. + + Optional timeout for getting the notification. + True to throw on error. + The transaction notification. + + + + Get a notification synchronously. + + Optional timeout for getting the notification. + The transaction notification. + + + + Get a notification synchronously waiting indefinetly. + + The transaction notification. + + + + Register protocol information. + + The ID of the protocol to register. + An opaque protocol buffer. + Optional create options. + True to throw on error. + The NT status code. + + + + Register protocol information. + + The ID of the protocol to register. + An opaque protocol buffer. + Optional create options. + + + + Complete propagation request. + + The cookie to identify the request. + An optional buffer to pass with the request. + True to throw on error. + The NT status code. + + + + Complete propagation request. + + The cookie to identify the request. + An optional buffer to pass with the request. + + + + Fail propagation request. + + The cookie to identify the request. + Optional NT status code for the failure. + True to throw on error. + The NT status code. + + + + Get a list of all accessible enlistment objects owned by this resource manager. + + The object attributes + The access for the enlistment objects. + The list of all accessible enlistment objects. + + + + Get a list of all accessible enlistment objects owned by this resource manager. + + The access for the enlistment objects. + The list of all accessible enlistment objects. + + + + Get a list of all accessible resource manager objects owned by this transaction manager. + + The list of all accessible resource manager objects. + + + + Create an enlistment in this resource manager. + + Desired access for the handle + The transaction to enlist. + Optional create options. + Notification mask. + Enlistment key returned during notification. + True to throw an exception on error. + The created enlistment and NT status code. + + + + Create an enlistment in this resource manager. + + Desired access for the handle + The transaction to enlist. + Optional create options. + Notification mask. + Enlistment key returned during notification. + The created enlistment. + + + + Create an enlistment in this resource manager. + + The transaction to enlist. + Notification mask. + Enlistment key returned during notification. + The created enlistment. + + + + Create an enlistment in this resource manager. + + The transaction to enlist. + Enlistment key returned during notification. + The created enlistment. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get the resource manager ID. + + + + + Get the description for the resource manager. + + + + + A structure to return the result of an NT system call with status. + This allows a function to return both a status code and a result + without having to resort to out parameters. + + The result type. + + + + The NT status code. + + + + + The result of the NT call. + + + + + Get the result object or throw an exception if status code is an error. + + The result NT result. + Thrown if status code is an error. + + + + Get the result object or a default value if an error occurred. + + The default value to return. + The result or the default if an error occurred. + + + + Get the result object or a default value if an error occurred. + + The result or the default if an error occurred. + + + + Is the result successful. + + + + + Map result to a different type. + + The different type to map to. + A function to map the result. + The mapped result. + + + + Map result to a different type. + + The different type to map to. + A function to map the result. + The mapped result. + + + + Cast result to a different type. + + The different type to cast to. + The mapped result. + + + + Forward the result and check for an exception. + + True to throw on error. + The forwarded result. + + + + Dispose result. + + + + + Create a result from an error. + + The error status code. + True to throw on error. + The result. + + + + Create a result. + + + Create a new result. + + + + Conversion operator from T to object. + + The result to convert. + + + + Compression format for RtlDecompressBuffer. + + + + + Class to represent a NT Section object + + + + + Create an Image section object + + The object attributes for the image section. + The file to create the image section from + The opened section + Thrown on error. + + + + Create an Image section object + + The object name to use for the image section. + Root directory for the object. + The file to create the image section from + The opened section + Thrown on error. + + + + Create an Image section object + + The object name to use for the image section. + The file to create the image section from + The opened section + Thrown on error. + + + + Create an Image section object + + The file to create the image section from + The opened section + Thrown on error. + + + + Create a data section from a file. + + The file to create from. + The created section object. + + + + Create a section object + + The object attributes + The desired access + Optional size of the section + The section protection + The section attributes. The lower 5 bits can be used to specify the NUMA node. + Optional backing file + True to throw an exception on error. + The NT status code and object result. + + + + Create a section object + + The object attributes + The desired access + Optional size of the section + The section protection + The section attributes + Optional backing file + The opened section + Thrown on error. + + + + Create a section object + + The path to the section + The root if path is relative + The desired access + Optional size of the section + The section protection + The section attributes. The lower 5 bits can be used to specify the NUMA node. + Optional backing file + The opened section + Thrown on error. + + + + Create a section object + + Size of the section + The opened section + Thrown on error. + + + + Create a section object + + The object attributes + The desired access + Optional size of the section + The section protection + The section attributes + Optional backing file + Extended parameters for section create. + True to throw an exception on error. + The NT status code and object result. + + + + Create a section object + + The object attributes + The desired access + Optional size of the section + The section protection + The section attributes + Optional backing file + Extended parameters for section create. + The NT status code and object result. + + + + Open a section object + + The object attributes for the section + The desired access for the sections + True to throw an exception on error. + The NT status code and object result. + + + + Open a section object + + The object attributes for the section + The desired access for the sections + The opened section + + + + Open a section object + + The path to the section + Root object if the path is relative + The desired access for the sections + The opened section + + + + Unmap a section in a specified process. + + The process to unmap the section. + The base address to unmap. + Flags for unmapping memory. + True to throw on error. + The NT status code. + + + + Unmap a section in a specified process. + + The process to unmap the section. + The base address to unmap. + True to throw on error. + The NT status code. + + + + Unmap a section in the current process. + + The base address to unmap. + True to throw on error. + The NT status code. + + + + Unmap a section in a specified process. + + The process to unmap the section. + The base address to unmap. + Flags for unmapping memory. + + + + Unmap a section in a specified process. + + The process to unmap the section. + The base address to unmap. + + + + Unmap a section in the current process. + + The base address to unmap. + + + + Map section Read/Write into a specific process + + The process to map into + The mapped section + + + + Map section Read Only into a specific process + + The process to map into + The mapped section + + + + Map section Read/Write into a specific process + + The process to map into + True to throw on error. + The mapped section + + + + Map section Read Only into a specific process + + The process to map into + True to throw on error. + The mapped section + + + + Map section Read Only into a current process + + The mapped section + + + + Map section Read Only into a current process + + True to throw on error. + The mapped section + + + + Map section Read/Write into a current process + + The mapped section + + + + Map section Read/Write into a current process + + True to throw on error. + The mapped section + + + + Map section into a specific process + + The process to map into + The protection of the mapping + The mapped section + + + + Map section into a specific process + + The process to map into + The protection of the mapping + True to throw on error. + The mapped section + + + + Map section into a specific process + + The process to map into + The protection of the mapping + Optional base address + Number of zero bits. + Size of pages to commit. + Offset into the section. + Optional view size + Allocation type. + Section inheritance type. + True to throw on error. + The mapped section + + + + Map section into a specific process + + The process to map into + The protection of the mapping + Optional base address + Number of zero bits. + Size of pages to commit. + Offset into the section. + Optional view size + Allocation type. + Section inheritance type. + The mapped section + + + + Map section into a specific process + + The process to map into + The protection of the mapping + Optional base address + Optional view size + The mapped section + + + + Map section into a specific process + + The process to map into + The protection of the mapping + Optional base address + Optional view size + True to throw on error. + The mapped section + + + + Map section into the current process + + The protection of the mapping + The mapped section + + + + Extend the section to a new size. + + The new size to extend to. + True to throw on error. + The new size. + Thrown on error. + + + + Extend the section to a new size. + + The new size to extend to. + The new size. + Thrown on error. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Get the size of the section + + + + + Get the attributes of the section + + + + + Get section image information. + + + + + Get original section base address. + + + + + Get relocation address. + + + + + Static class to access NT security manager routines. + + + + + Looks up the account name of a SID. + + The system name to lookup the SID on. + The SID to lookup + True to throw on error. + The name. + + + + Looks up the account name of a SID. + + The SID to lookup + True to throw on error. + The name. + + + + Looks up the account name of a SID. + + The SID to lookup + The SID name. + Thrown if lookup fails. + + + + Looks up the account name of a SID. + + The SID to lookup + True to throw on error. + The name. + + + + Looks up the account name of a SID. + + The SID to lookup + The name, or null if the lookup failed + + + + Looks up a capability SID to see if it's already known. + + The capability SID to lookup + The name of the capability, null if not found. + + + + Lookup a SID from a username. + + The system name to lookup the SID on. + The username, can be in the form domain\account. + True to throw on error. + The Security Identifier + Thrown if account cannot be found. + + + + Lookup a SID from a username. + + The system name to lookup the SID on. + The username, can be in the form domain\account. + The Security Identifier + Thrown if account cannot be found. + + + + Lookup a SID from a username. + + The username, can be in the form domain\account. + The Security Identifier + Thrown if account cannot be found. + + + + Lookup the name of a process trust SID. + + The trust sid to lookup. + The name of the trust sid. null if not found. + Thrown if trust_sid is not a trust sid. + + + + Try and lookup the moniker associated with a package sid. + + The package sid. + Returns the moniker name. If not found returns null. + Thrown if SID is not a package sid. + + + + Lookup a device capability SID name if known. + + The SID to lookup. + Returns the device capability name. If not found returns null. + Thrown if SID is not a package sid. + + + + Convert a package SID to a capability. + + The package SID to convert. + The package SID as a capability. + + + + Convert a security descriptor to SDDL string + + The security descriptor + Indicates what parts of the security descriptor to include + The SDDL string + Thrown if cannot convert to a SDDL string. + + + + Convert a security descriptor to SDDL string + + The security descriptor + Indicates what parts of the security descriptor to include + True to throw on errror. + The SDDL string + Thrown if cannot convert to a SDDL string. + + + + Convert an SDDL string to a binary security descriptor + + The SDDL string + True to throw on error. + The binary security descriptor + Thrown if cannot convert from a SDDL string. + + + + Convert an SDDL string to a binary security descriptor + + The SDDL string + The binary security descriptor + Thrown if cannot convert from a SDDL string. + + + + Convert an SDDL string to a binary security descriptor + + The SDDL string + True to throw on error. + The binary security descriptor + Thrown if cannot convert from a SDDL string. + + + + Convert an SDDL string to a binary security descriptor + + The SDDL string + The binary security descriptor + Thrown if cannot convert from a SDDL string. + + + + Convert an SDDL SID string to a Sid + + The SDDL SID string + True to throw on error. + The converted Sid + Thrown if cannot convert from a SDDL string. + + + + Convert an SDDL SID string to a Sid + + The SDDL SID string + The converted Sid + Thrown if cannot convert from a SDDL string. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + This function returns a list of results rather than a single entry. It should only be used + with object types. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + True to throw on error. + The list of access check results. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + This function returns a list of results rather than a single entry. It should only be used + with object types. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + The list of access check results. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + True to throw on error. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + True to throw on error. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + True to throw on error. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + True to throw on error. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + The allowed access mask as a unsigned integer. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + The type specific generic mapping (get from corresponding NtType entry). + The allowed access mask as a unsigned integer. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the maximum allowed access. + + The security descriptor + The access token. + The type specific generic mapping (get from corresponding NtType entry). + The maximum allowed access mask as a unsigned integer. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the maximum allowed access. + + The security descriptor + The access token. + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + The maximum allowed access mask as a unsigned integer. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + The type used to determine generic access mapping.. + The allowed access mask as a unsigned integer. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the maximum allowed access. + + The security descriptor + The access token. + The type used to determine generic access mapping.. + The allowed access mask as a unsigned integer. + Thrown if an error occurred in the access check. + + + + Get a security descriptor from a named object. + + The path to the resource (such as \BaseNamedObejct\ABC) + The type of resource, can be null to get the method to try and discover the correct type. + The named resource security descriptor. Returns null if can't open the resource. + + + + Do an access check between a security descriptor and a token to determine the allowed access and + audit the result. + + The name of the subsystem to audit. + The handle ID to audit. Used when issuing a close audit. + The object type name. + The name of the object. + Indicates if this is an object creation operation. + Type of audit. + Flags for the audit operation. + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + True to throw on error. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access and + audit the result. + + The name of the subsystem to audit. + The handle ID to audit. Used when issuing a close audit. + The object type name. + The name of the object. + Indicates if this is an object creation operation. + Type of audit. + Flags for the audit operation. + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access + and audit. This function returns a list of results rather than a single entry. It should only + be used with object types. + + The name of the subsystem to audit. + The handle ID to audit. Used when issuing a close audit. + The object type name. + The name of the object. + Indicates if this is an object creation operation. + Type of audit. + Flags for the audit operation. + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + True to throw on error. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access + and audit. This function returns a list of results rather than a single entry. It should only + be used with object types. + + The name of the subsystem to audit. + The handle ID to audit. Used when issuing a close audit. + The object type name. + The name of the object. + Indicates if this is an object creation operation. + Type of audit. + Flags for the audit operation. + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Get a SID for a specific mandatory integrity level. + + The mandatory integrity level. + The integrity SID + + + + Get a SID for a specific mandatory integrity level. + + The mandatory integrity level. + The integrity SID + + + + Checks if a SID is an integrity level SID + + The SID to check + True if an integrity SID + + + + Get the integrity level from an integrity SID + + The integrity SID + The token integrity level. + + + + Gets the SID for a service name. + + The service name. + The service SID. + Thrown on error. + + + + Checks if a SID is a service SID. + + The sid to check. + True if a service sid. + + + + Checks if a SID is a logon session SID. + + The sid to check. + True if a logon session sid. + + + + Checks if a SID is a process trust SID. + + The sid to check. + True if a process trust sid. + + + + Checks if a SID is a domain SID. + + The SID to check. + True if a domain SID. + + + + Checks if a SID is a domain SID and is a member of the local machine domain. + + The SID to check. + True if a domain SID. + + + + Checks if a SID is a capability SID. + + The sid to check. + True if a capability sid. + + + + Checks if a SID is a capbility group SID. + + The sid to check. + True if a capability group sid. + + + + Get a capability sid by name. + + The name of the capability. + True to throw on error. + The capability SID. + + + + Get a capability sid by name. + + The name of the capability. + The capability SID. + + + + Get a capability group sid by name. + + The name of the capability. + True to throw on error. + The capability SID. + + + + Get a capability group sid by name. + + The name of the capability. + The capability SID. + + + + Get the type of package sid. + + The sid to get type. + The package sid type, Unknown if invalid. + + + + Checks if a SID is a valid package SID. + + The sid to check. + True if a capability sid. + + + + Get the parent package SID for a child package SID. + + The child package SID. + The parent package SID. + Thrown if sid not a child package SID. + + + + Checks if a SID is a Scoped Policy ID SID. + + The SID to check. + True if a Scoped Policy ID SID. + + + + Converts conditional ACE data to an SDDL string + + The conditional application data. + True to throw on error. + The conditional ACE string. + + + + Converts conditional ACE data to an SDDL string + + The conditional application data. + The conditional ACE string. + + + + Converts a condition in SDDL format to an ACE application data. + + The condition in SDDL format. + The condition in ACE application data format. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in SDDL format. + Specify resource attributes to add to the check. + True to throw on error. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in SDDL format. + True to throw on error. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in SDDL format. + Specify resource attributes to add to the check. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in SDDL format. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in binary format. + Specify resource attributes to add to the check. + True to throw on error. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in binary format. + True to throw on error. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in binary format. + Specify resource attributes to add to the check. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in binary format. + True if the conditional expression was a success. + + + + Get the cached signing level for a file. + + The handle to the file to query. + The cached signing level. + + + + Get the cached signing level for a file. + + The handle to the file to query. + True to throw on error. + The cached signing level. + + + + Get the cached singing level from the raw EA buffer. + + The EA buffer to read the cached signing level from. + The cached signing level. + Throw on error. + + + + Set the cached signing level for a file. + + The handle to the file to set the cache on. + Flags to set for the cache. + The signing level to cache + A list of source file for the cache. + Optional directory path to look for catalog files. + + + + Set the cached signing level for a file. + + The handle to the file to set the cache on. + Flags to set for the cache. + The signing level to cache + A list of source file for the cache. + Optional directory path to look for catalog files. + True to throw on error. + + + + Compare two signing levels. + + The current level. + The signing level to compare against. + True if the current level is above or equal to the signing level. + + + + Get readable name for a SID, if known. This covers sources of names such as LSASS lookup, capability names and package names. + + The SID to lookup. + True to bypass the internal cache and get the current name. + The name for the SID. Returns the SDDL form if no other name is known. + + + + Get readable name for a SID, if known. This covers sources of names such as LSASS lookup, capability names and package names. + + The SID to lookup. + The name for the SID. Returns the SDDL form if no other name is known. + This function will cache name lookups, this means the name might not reflect what's currently in LSASS if it's been changed. + + + + Add a SID name to the local name cache. + + The SID to add. + The SID's domain name. + The name of the account. + The name user value. + + + + Remove a SID name from the local cache. + + The SID to remove. + + + + Clear the SID name cache. + + + + + Get a logon session SID from an ID. + + The logon session ID. + The new logon session SID. + + + + Get a new logon session SID. + + The new logon session SID. + + + + Get session id from logon session SID. + + The logon session SID. + The logon session ID. + + + + Get security descriptor as a byte array + + Handle to the object to query. + What parts of the security descriptor to retrieve + True to throw on error. + The NT status result and security descriptor as a buffer. + + + + Set the object's security descriptor + + Handle to the object to set. + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + The NT status result. + + + + Do a privilege check on a token. + + A handle to a token object. + The list of privileges to check. + True to require all necessary privileges. + True to throw on error. + The privilege check result. + + + + Get the access mask for querying a specific security information class. + + The information class. + The access mask for the information. + + + + Get the access mask for setting a specific security information class. + + The information class. + The access mask for the information. + + + + Get whether an ACE type is an allowed ACE type. + + The ACE type. + True if an allowed ACE type. + + + + Get whether an ACE type is a denied ACE type. + + The ACE type. + True if a denied ACE type. + + + + Get whether an ACE type is an object ACE type. + + The ACE type. + True if an object ACE type. + + + + Get whether an ACE type is an audit ACE type. + + The ACE type. + True if an audit ACE type. + + + + Get whether an ACE type is used int the SACL. + + The ACE type. + True if a system ACE type. + + + + Get whether an ACE type is a callback type. + + The ACE type. + True if a callback type. + + + + Convert an access rights type to a string. + + The access mask to convert + The enumeration type for the string conversion + Set to true to use SDK style names. + The string version of the access + + + + Convert an access rights type to a string. + + The access mask to convert + The enumeration type for the string conversion + The string version of the access + + + + Convert an access rights type to a string. + + The access mask to convert + The string version of the access + + + + Convert an access rights type to a string. + + The access mask to convert + Set to true to use SDK style names. + The string version of the access + + + + Convert an enumerable access rights to a string + + The access mask. + Enum type to convert to string. + Generic mapping for object type. + True to try and convert to generic rights where possible. + The string format of the access rights. Will return Full Access if not a generic access and has all rights and None if no access. + + + + Convert an enumerable access rights to a string + + The access mask. + Enum type to convert to string. + Generic mapping for object type. + True to try and convert to generic rights where possible. + Set to true to use SDK style names. + The string format of the access rights. Will return Full Access if not a generic access and has all rights and None if no access. + + + + Convert an ACE type to an SDK type string. + + The ACE type. + The ACE type as an SDK type string. + + + + Convert the ACE flags to an SDK type string. + + The ACE type as an SDK type string. + + + + Convert the security descriptor control flags to an SDK type string. + + The security descriptor control as an SDK type string. + + + + Get a Process Trust Level SID. + + The Trust Type. + The Trust Level. + The Process Trust Level SID. + + + + Generate audit event for an object open. + + The subsystem name. + Handle ID. + The typename of the object. + The name of the object. + The security descriptor set for the object. + The client token used to open the object. + Desired access for the open. + Granted access from the open. + Privileges used to open the object. + True if the object was created. + Specify whether access was granted. + True to throw on error. + A value indicating whether an event need to be generated on close. + + + + Generate audit event for an object open. + + The subsystem name. + Handle ID. + The typename of the object. + The name of the object. + The security descriptor set for the object. + The client token used to open the object. + Desired access for the open. + Granted access from the open. + Privileges used to open the object. + True if the object was created. + Specify whether access was granted. + A value indicating whether an event need to be generated on close. + + + + Generate audit event for an object close. + + The subsystem name. + Handle ID. + True indicates to generate on close. + True to throw on error. + The NT status code. + + + + Generate audit event for an object close. + + The subsystem name. + Handle ID. + True indicates to generate on close. + The NT status code. + + + + Generate audit event for an object deleted. + + The subsystem name. + Handle ID. + True indicates to generate on close. + True to throw on error. + The NT status code. + + + + Generate audit event for an object deleted. + + The subsystem name. + Handle ID. + True indicates to generate on close. + + + + Generate audit event for a privileges used with an object. + + The subsystem name. + Handle ID. + The client token used. + Desired access for the object. + Privileges used to open the object. + Specify whether access was granted. + True to throw on error. + The NT status code. + + + + Generate audit event for a privileges used with an object. + + The subsystem name. + Handle ID. + The client token used. + Desired access for the object. + Privileges used to open the object. + Specify whether access was granted. + + + + Generate audit event for a privileges used by a client. + + The subsystem name. + The client token used. + The name of the service. + Privileges used in the operation. + Specify whether access was granted. + True to throw on error. + The NT status code. + + + + Generate audit event for a privileges used by a client. + + The subsystem name. + The client token used. + The name of the service. + Privileges used in the operation. + Specify whether access was granted. + + + + Perform a capability check for a token. + + Specify the token handle. If null will use the effective token. + The name of the capability to check. + True to throw on error. + True if the token has the capability. + + + + Perform a capability check for a token. + + Specify the token handle. If null will use the effective token. + The name of the capability to check. + True if the token has the capability. + + + + Get GenericMapping for standard access rights. + + + + + Security information class for security descriptors. + + + + + ACE Flags. Note that the value isn't completely the same as + the real flags. + + + + + Class to represent a NT Semaphore object. + + + + + Create a semaphore object. + + The object attributes for the object + The desired access for the object + Initial count for semaphore + Maximum count for semaphore + True to throw an exception on error. + The NT status code and object result. + + + + Create a semaphore object. + + The object attributes for the object + The desired access for the object + Initial count for semaphore + Maximum count for semaphore + The opened object + + + + Create a semaphore object. + + The path to the object + The root if path is relative + Initial count for semaphore + /// Maximum count for semaphore + The opened object + + + + Open a semaphore object. + + The object attributes for the object + The desired access for the object + True to throw an exception on error. + The NT status code and object result. + + + + Open a semaphore object. + + The object attributes for the object + The desired access for the object + The opened object + + + + Open a semaphore object. + + The path to the object + The root if path is relative + The desired access for the object + The opened object + + + + Release the semaphore + + The release count + The previous count + + + + Release the semaphore + + The release count + True to throw an exception on error. + The previous count + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Current count of the semaphore. + + + + + Maximum count of the semaphore. + + + + + Semaphore access rights. + + + + + Class to represent a Session object + + + + + Open a session object. + + The object attributes + Desired access for the object + True to throw on error. + The open result. + + + + Open a session object. + + The object attributes + Desired access for the object + The open result. + + + + Open a session object. + + Name of the object + Optional root directory for lookup + Desired access for the object + The open result. + + + + NT status values + + + + + Class representing a NT SymbolicLink object + + + + + Create a symbolic link object. + + The path to the object + The root if path is relative + The desired access for the object + The target path + The opened object + + + + Create a symbolic link object. + + The object attributes for the object + The desired access for the object + The target path + True to throw an exception on error. + The NT status code and object result. + + + + Create a symbolic link object. + + The object attributes for the object + The desired access for the object + The target path + The opened object + + + + Create a symbolic link object. + + The path to the object + The root if path is relative + The target path + The opened object + + + + Create a symbolic link object. + + The path to the object + The target path + The opened object + + + + Open a symbolic link object. + + The path to the object + The root if path is relative + The desired access for the object + The opened object + + + + Open a symbolic link object. + + The path to the object + The root if path is relative + The desired access for the object + True to throw on error. + The opened object + + + + Open a symbolic link object. + + The object attributes for the object + The desired access for the object + True to throw an exception on error. + The NT status code and object result. + + + + Open a symbolic link object. + + The object attributes for the object + The desired access for the object + The opened object + + + + Open a symbolic link object. + + The path to the object + The root if path is relative + The opened object + + + + Open a symbolic link object. + + The path to the object + The opened object + + + + Resolve a symlink name to a final target. + + The name of the symlink to resolve. + True to throw on error. + The final target. + This function will return the last name which returns STATUS_OBJECT_TYPE_MISMATCH. Anything else is an error. + + + + Resolve a symlink name to a final target. + + The name of the symlink to resolve. + The final target. + This function will return the last name which returns STATUS_OBJECT_TYPE_MISMATCH. Anything else is an error. + + + + Get the symbolic link target. + + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Set access mask filter. + + The access mask to set. + True to throw on error. + The NT status code. + Needs SeTcbPrivilege. + + + + Set access mask filter. + + The access mask to set. + Needs SeTcbPrivilege. + + + + Set as a global link. + + True to throw on error. + The NT status code. + Needs SeTcbPrivilege. + + + + Set as a global link. + + Needs SeTcbPrivilege. + + + + Get the symbolic link target path. + + True to throw on error. + The target path. + + + + Class to access some NT system information + + + + + Get a list of handles + + A process ID to filter on. If -1 will get all handles + True to allow the handles returned to query for certain properties + True to force all file names to be queried. Otherwise limits to only DISK files. + The list of handles + The purpose of force_file_name to disable querying a file handle for its path unless it's on a FS volume. + This is because some non-file types can be in a locked state which causes the filename lookup to hang. + + + + Get a list of handles + + A process ID to filter on. If -1 will get all handles + True to allow the handles returned to query for certain properties + The list of handles + + + + Get a list of all handles + + The list of handles + + + + Get a list of threads for a specific process. + + The process ID to list. + True to throw on error. + The list of thread information. + + + + Get a list of threads for a specific process. + + The process ID to list. + The list of thread information. + + + + Get a list of all threads. + + The list of thread information. + + + + Get a list of all threads. + + The list of thread information. + + + + Get a list of threads for a specific process. + + The process ID to list. + True to throw on error. + The list of thread information. + + + + Get a list of threads for a specific process. + + The process ID to list. + The list of thread information. + + + + Get a list of all threads. + + The list of thread information. + + + + Get a list of all threads. + + The list of thread information. + + + + Get all process information for the system. + + The list of process information. + + + + Get all process information for the system. + + True to throw on error. + The list of process information. + + + + Get all process information for the system. + + The list of process information. + + + + Get all process information for the system. + + True to throw on error. + The list of process information. + + + + Get all process information for the system. + + The list of process information. + + + + Get all process information for the system. + + True to throw on error. + The list of process information. + + + + Get list of page filenames. + + The list of page file names. + + + + Create a kernel dump for current system. + + The path to the output file. + Flags + Page flags + + + + Query all system environment value names. + + A list of names of environment values + + + + Query all system environment value names and values. + + A list of names of environment values + + + + Query a single system environment value. + + The name of the value. + The associated vendor guid + True to throw on error. + The system environment value. + + + + Query a single system environment value. + + The name of the value. + The associated vendor guid + The system environment value. + + + + Set a system environment variable. + + The name of the variable. + The vendor GUID + The value to set + Attributes of the value + + + + Set a system environment variable. + + The name of the variable. + The vendor GUID + The value to set + Attributes of the value + + + + Set a system environment variable. + + The name of the variable. + The vendor GUID + The value to set + Attributes of the value + + + + Set a system environment variable. + + The name of the variable. + The vendor GUID + The value to set + Attributes of the value + + + + Allocate a LUID. + + The allocated LUID. + + + + Allocate a LUID. + + The allocated LUID. + + + + Get the addresses of a list of objects from the handle table and initialize the Address property. + + The list of objects to initialize. + + + + Get the address of an object in kernel memory from the handle table and initialize the Address property. + + The object. + + + + Get the address of an object in kernel memory from the handle table and initialize the Address property. + + The object. + Any remaining objects. + + + + Query whether a file is trusted for dynamic code. + + The handle to a file to query. + Pointer to a memory buffer containing the image. + The size of the in-memory buffer. + True if the file is trusted. + + + + Query whether a file is trusted for dynamic code. + + Pointer to a memory buffer containing the image. + The status code from the operation. Returns STATUS_SUCCESS is valid. + + + + Query whether a file is trusted for dynamic code. + + The handle to a file to query. + The status code from the operation. Returns STATUS_SUCCESS is valid. + + + + Set a file is trusted for dynamic code. + + The handle to a file to set. + The status code from the operation. + + + + Get list of root silos. + + The list of root silos. + + + + Set the ELAM certificate information. + + The signed file containing an ELAM certificate resource. + The NT status code. + + + + Query code integrity certificate information. + + The image file. + The type of check to make. + The NT status code. + + + + Query the image path from a process ID. + + The ID of the process. + True to throw on error. + The image path. + This method can be called without any permissions on the process. + + + + Query the image path from a process ID. + + The ID of the process. + The image path. + This method can be called without any permissions on the process. + + + + Get flags for isolated user mode. + + True to throw on error. + The ISO flags. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + The result of the query. + Thrown on error. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The information class to query. + A buffer to initialize the initial query. Can be null. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The information class to query. + A buffer to initialize the initial query. Can be null. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The information class to query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object and return as bytes. + + The information class to query. + A buffer to initialize the initial query. Can be null. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object and return as bytes. + + The information class to query. + A buffer to initialize the initial query. Can be null. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object and return as bytes. + + The information class to query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The type of structure to return. + The information class to query. + The result of the query. + Thrown on error. + + + + Set a value to the object. + + The type of structure to set. + The information class to set. + The value to set. If you specify a SafeBuffer then it'll be passed directly. + True to throw on error. + The NT status code of the set. + Thrown on error. + + + + Set a value to the object. + + The type of structure to set. + The information class to set. + The value to set. + The NT status code of the set. + Thrown on error. + + + + Set a value to the object from a buffer. + + The information class to set. + The value to set. + True to throw on error. + The NT status code of the set. + Thrown on error. + + + + Set a value to the object from a buffer.. + + The information class to set. + The value to set. + The NT status code of the set. + Thrown on error. + + + + Set a raw value to the object. + + The information class to set. + The raw value to set. + True to throw on error. + The NT status code of the set. + Thrown on error. + + + + Set a raw value to the object. + + The information class to set. + The raw value to set. + The NT status code of the set. + Thrown on error. + + + + Draw text on the background. + + The text to draw. + True to throw on error. + The NT status code. + + + + Draw text on the background. + + The text to draw. + + + + Display a string. + + The text to display. + True to throw on error. + The NT status code. + + + + Display a string. + + The text to display. + + + + Load a driver. + + The name of the driver service. + True to throw on error. + The NT status code. + + + + Unload a driver. + + The name of the driver service. + True to throw on error. + The NT status code. + + + + Get kernel modules. + + True to throw on error. + The list of kernel modules. + + + + Get kernel modules. + + The list of kernel modules. + + + + Get whether the kernel debugger is enabled. + + + + + Get whether the kernel debugger is not present. + + + + + Get current code integrity option settings. + + + + + Get code integrity policy. + + + + + Get code integrity unlock information. + + + + + Get all code integrity policies. + + + + + Get whether secure boot is enabled. + + + + + Get whether system supports secure boot. + + + + + Extract the secure boot policy. + + + + + Get system timer resolution. + + + + + Get system page size. + + + + + Get number of physical pages. + + + + + Get lowest page number. + + + + + Get highest page number. + + + + + Get allocation granularity. + + + + + Get minimum user mode address. + + + + + Get maximum user mode address. + + + + + Get active processor affinity mask. + + + + + Get number of processors. + + + + + Get system device information. + + + + + Get the system processor information. + + + + + Get the system emulation processor information. + + + + + Get the Isolated User Mode flags. + + + + + Get the NT product type. + + + + + + Get OS version info, + + + + + Get whether this is a multi-session SKU. + + True if multi-session. + + + + Get whether this there are multiple users in a session. + + True if multi-session. + + + + Query the system elevation flags. + + + + + Class to represent a NT Thread object + + + + + Create a new thread in a process. + + The object attributes for the thread object. + Desired access for the handle. + Process to create the thread in. + Address of the start routine. + Argument to pass to the thread. + Creation flags. + Zero bits for the stack address. + Size of the committed stack. + Maximum reserved stack size. + Optional attribute list. + True to throw on error + The created thread object. + This creates a native thread, not a Win32 thread. This might cause unexpected things to fail as they're not initialized. + + + + Create a new thread in a process. + + The object attributes for the thread object. + Desired access for the handle. + Process to create the thread in. + Address of the start routine. + Argument to pass to the thread. + Creation flags. + Zero bits for the stack address. + Size of the committed stack. + Maximum reserved stack size. + Optional attribute list. + The created thread object. + This creates a native thread, not a Win32 thread. This might cause unexpected things to fail as they're not initialized. + + + + Create a new thread in a process. + + Process to create the thread in. + Address of the start routine. + Argument to pass to the thread. + Creation flags. + Size of the committed stack. + True to throw on error + The created thread object. + This creates a native thread, not a Win32 thread. This might cause unexpected things to fail as they're not initialized. + + + + Create a new thread in a process. + + Process to create the thread in. + Address of the start routine. + Argument to pass to the thread. + Creation flags. + Size of the committed stack. + The created thread object. + This creates a native thread, not a Win32 thread. This might cause unexpected things to fail as they're not initialized. + + + + Open a thread + + The process ID containing the thread. + The thread ID to open + The desired access for the handle + True to throw an exception on error. + The NT status code and object result. + + + + Open a thread + + The thread ID to open + The desired access for the handle + True to throw an exception on error. + The NT status code and object result. + + + + Open a thread + + The process ID containing the thread. + The thread ID to open + The desired access for the handle + The NT status code and object result. + + + + Open a thread + + The thread ID to open + The desired access for the handle + The opened object + + + + Gets all accessible threads on the system. + + The desired access for each thread. + Get the thread list from system information. + The list of accessible threads. + + + + Gets all accessible threads on the system. + + The desired access for each thread. + The list of accessible threads. + + + + Get first thread for process. + + The process handle to get the threads. + The desired access for the thread. + The first thread, or null if no more available. + + + + Sleep the current thread + + Set if the thread should be alertable + The delay, negative values indicate relative times. + True to throw on error. + STATUS_ALERTED if the thread was alerted, other success or error code. + + + + Sleep the current thread + + Set if the thread should be alertable + The delay, negative values indicate relative times. + True if the thread was alerted before the delay expired. + + + + Sleep the current thread + + Set if the thread should be alertable + The delay, negative values indicate relative times. + True if the thread was alerted before the delay expired. + + + + Sleep the current thread for a specified number of milliseconds. + + The delay in milliseconds. + True if the thread was alerted before the delay expired. + + + + Open an actual handle to the current thread rather than the pseudo one used for Current + + The thread object + + + + Set the work on behalf ticket. + + The ticket to set. + True to throw on error. + The status code from the set. + + + + Set the work on behalf ticket. + + The ticket to set. + + + + Set the work on behalf ticket. + + The ticket to set. + True to throw on error. + The status code from the set. + + + + Set the work on behalf ticket. + + The ticket to set. + + + + Set the work on behalf ticket. + + The thread ID. + True to throw on error. + The NT status. + + + + Set the work on behalf ticket. + + The thread ID. + + + + Test alert status for the current thread. + + True to throw on error. + The NT status code. + + + + Test alert status for the current thread. + + + + + Attach a silo container to the current thread. + + The silo to attach. + True to throw on error. + The thread impersonation context. + + + + Attach a silo container to the current thread. + + The silo to attach. + The thread impersonation context. + + + + Detach container from the current thread. + + True to throw on error. + The NT status code. + + + + Detach container from the current thread. + + + + + Get XOR key for the work-on-behalf ticket. + + True to throw on error. + The XOR key. + + + + Get the current thread. + + This only uses the pseudo handle, for the thread. You can't use it in different threads. If you need to do that use OpenCurrent. + + + + + Get or set the work on behalf ticket for the current thread. + + + + + Get the work on behalf ticket xor key. + + + + + Reopen object with different access rights. + + The desired access. + Additional attributes for open. + True to throw on error. + The reopened object. + + + + Resume the thread. + + True to throw on error. + The suspend count + + + + Resume the thread. + + The suspend count + + + + Suspend the thread. + + True to throw on error. + The suspend count + + + + Suspend the thread + + The suspend count + + + + Terminate the thread + + True to throw on error. + The thread status exit code + The NT status code. + + + + Terminate the thread + + The thread status exit code + + + + Wake the thread from an alertable state. + + True to throw on error. + The NT status code. + + + + Wake the thread from an alertable state. + + + + + Wake the thread from an alertable state and resume the thread. + + True to throw on error. + The previous suspend count for the thread. + + + + Wake the thread from an alertable state and resume the thread. + + The previous suspend count for the thread. + + + + Hide the thread from debug events. + + True to throw on error. + The NT status code. + + + + Hide the thread from debug events. + + + + + The set the thread's impersonation token + + The impersonation token to set + True to throw on error. + The NT status code. + + + + The set the thread's impersonation token + + The impersonation token to set + + + + Impersonate the anonymous token + + True to throw on error. + The impersonation context. Dispose to revert to self + + + + Impersonate the anonymous token + + The impersonation context. Dispose to revert to self + + + + Impersonate a token + + True to throw on error. + The token to impersonate. + The impersonation context. Dispose to revert to self + + + + Impersonate a token + + The token to impersonate. + The impersonation context. Dispose to revert to self + + + + Impersonate another thread. + + The thread to impersonate. + The impersonation security quality of service. + True to throw on error. + The imperonsation context. Dispose to revert to self. + + + + Impersonate another thread's security context. + + The thread to impersonate. + The impersonation level for the token. + True to throw on error. + The imperonsation context. Dispose to revert to self. + + + + Impersonate another thread's security context. + + The thread to impersonate. + The impersonation level for the token. + The imperonsation context. Dispose to revert to self. + + + + Impersonate another thread's security context at impersonation level. + + The thread to impersonate. + True to throw on error. + The imperonsation context. Dispose to revert to self. + + + + Impersonate another thread's security context at impersonation level. + + The thread to impersonate. + The imperonsation context. Dispose to revert to self. + + + + Open the thread's token + + The token, null if no token available + + + + Queue a special user APC to the thread. + + The APC callback pointer. + Context parameter. + System argument 1. + System argument 2. + True to throw on error. + The NT status code. + + + + Queue a special user APC to the thread. + + The APC callback pointer. + Context parameter. + System argument 1. + System argument 2. + The NT status code. + + + + Queue a special user APC to the thread. + + The APC callback pointer. + Context parameter. + System argument 1. + System argument 2. + True to throw on error. + The NT status code. + + + + Queue a special user APC to the thread. + + The APC callback pointer. + Context parameter. + System argument 1. + System argument 2. + The NT status code. + + + + Queue a user APC to the thread. + + The APC callback pointer. + Context parameter. + System argument 1. + System argument 2. + True to throw on error. + The NT status code. + + + + Queue a user APC to the thread. + + The APC callback pointer. + Context parameter. + System argument 1. + System argument 2. + + + + Queue a user APC to the thread. + + The APC callback delegate. + Context parameter. + System argument 1. + System argument 2. + True to throw on error. + The NT status code. + This is only for APCs in the current process. You also must ensure the delegate is + valid at all times as this method doesn't take a reference to the delegate to prevent it being + garbage collected. + + + + Queue a user APC to the thread. + + The APC callback delegate. + Context parameter. + System argument 1. + System argument 2. + This is only for APCs in the current process. You also must ensure the delegate is + valid at all times as this method doesn't take a reference to the delegate to prevent it being + garbage collected. + + + + Get next thread for process relative to current thread. + + The process handle to get the threads. + The desired access for the thread. + The next thread, or null if no more available. + + + + Get the thread context. + + Flags for context parts to get. + True to throw on error. + An instance of an IContext object. Needs to be cast to correct type to access. + + + + Get the thread context. + + Flags for context parts to get. + An instance of an IContext object. Needs to be cast to correct type to access. + + + + Set the thread's context. + + The thread context to set. + True to throw on error. + The NT status code. + + + + Set the thread's context. + + The thread context to set. + + + + Get current waiting server information. + + True to throw on error. + The thread ALPC server information. + + + + Get current waiting server information. + + The thread ALPC server information. + + + + Get the process ID associated with the thread. + + True to throw on error. + The process ID. + + + + Get the thread ID. + + True to throw on error. + The thread ID. + + + + Cancel all synchronous IO for this thread. + + True to throw on error. + The NT status. + + + + Get a partial TEB for the thread. + + The partial TEB. + + + + Get the work on behalf ticket for a thread. + + True to throw on error. + The work on behalf ticket. + + + + Get the work on behalf ticket for a thread. + + The work on behalf ticket. + + + + Get the effective container ID for the thread. + + True to throw on error. + The effective container ID. + + + + Get priority boost disable value. + + True to throw on error. + True if priority base + + + + Set priority boost disable value. + + True to disable priority boost. + True to throw on error. + The NT status code. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get thread ID + + + + + Get process ID + + + + + Get name of process. + + + + + Get or set the thread's current priority + + + + + Get or set the thread's base priority + + + + + Get or set the thread's affinity mask. + + + + + Get the thread's TEB base address. + + + + + Get or set whether thread is allowed to create dynamic code. + + Set can only be done on the current thread. + + + + Get whether thread is impersonating another token. + + Note that this tries to open the thread's token and return true if it could open. A return of false + might just indicate that the caller doesn't have permission to open the token, not that it's not impersonating. + + + + Get name of the thread. + + + + + Get or set a thread's description. + + + + + Get the Win32 start address for the thread. + + + + + Get the current Instruction Pointer for the thread. + + + + + Get last system call on the thread. + + + + + Get the thread's suspend count. + + + + + Get whether the thread has pending IO. + + + + + Get the creation time of the thread. + + + + + Get the exit time of the thread (0 if not exited) + + + + + Get the time spent in the kernel. + + + + + Get the time spent in user mode. + + + + + Get thread information. + + + + + Get thread exit status. + + + + + Get thread exit status. + + + + + Get the effective container ID. + + Should be called on the current thread psuedo handle. + + + + Get or set priority boost disabled. + + + + + Delegate for APC callbacks. + + Context parameter. + System argument 1. + System argument 2. + + + + Class to represent an NT Timer object + + + + + Create a timer object + + The path to the event + The root object for relative path names + The type of the timer. + The timer object + + + + Create a timer object + + The timer object attributes + The type of the event + The desired access for the timer + The timer object + + + + Create a timer object + + The timer object attributes + The type of the timer + The desired access for the timer + True to throw an exception on error. + The NT status code and object result. + + + + Create a timer object + + The path to the timer + The type of the timer + The timer object + + + + Create a timer object + + The type of the timer + The timer object + + + + Create a timer object + + The timer object + + + + Open a timer object + + The path to the timer + The root object for relative path names + The desired access for the timer + The timer object + + + + Open a timer object + + The path to the timer + The root object for relative path names + The desired access for the timer + True to throw on error. + The timer object + + + + Open a timer object + + The timer object attributes + The desired access for the timer + The timer object. + + + + Open a timer object + + The event object attributes + The desired access for the timer + True to throw an exception on error. + The NT status code and object result. + + + + Open a timer object + + The path to the timer + The root object for relative path names + The timer object + + + + Open a timer object + + The path to the timer + The timer object + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Set timer state. + + The due time for the timer. + Optional APC routine. + Optional APC context pointer. + True to resume. + Period time. + True throw on error. + The NT result and previous state. + + + + Set timer state. + + The due time for the timer. + Optional APC routine. + Optional APC context pointer. + True to resume. + Period time. + The previous state. + + + + Set timer state. + + The due time for the timer. + The previous state. + + + + Set timer state in milliseconds. + + The due time for the timer in milliseconds. + The previous state. + + + + Cancel the timer. + + True to throw on error. + The previous state. + + + + Cancel the timer. + + The previous state. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Remaining time for the timer. + + + + + Signal state of the timer. + + + + + Delegate for Timer APC callbacks. + + Context parameter. + Low value of timer. + High value of timer. + + + + Enumeration for querying group list using QueryGroups. + + + + + The default group list. + + + + + The restrict group list. + + + + + The capability group list. + + + + + The device group list. + + + + + The restricted device list. + + + + + Specify type of security attributes to query. + + + + + Local security attributes. + + + + + User security attributes. + + + + + Restricted user security attributes. + + + + + Device security attributes. + + + + + Restricted device security attributes. + + + + + Singleton device security attributes. + + + + + Data from the TSA://ProcUnique security attribute. + + + + + The index entry for the process. + + + + + The value for the entry. + + + + + Class representing a Token object + + + + + Duplicate token as specific type. + + The token type + The impersonation level us type is Impersonation + Open with the desired access. + The object attributes for the token. + The security descriptor for the token. + If true then throw an exception on error. + The new token + Thrown on error + + + + Duplicate token as specific type. + + The token type + The impersonation level us type is Impersonation + Open with the desired access. + The object attributes for the token. + The security descriptor for the token. + The new token + Thrown on error + + + + Duplicate token as specific type. + + The token type + The impersonation level us type is Impersonation + Open with the desired access. + If true then throw an exception on error. + The new token + Thrown on error + + + + Duplicate token as specific type + + The token type + The impersonation level us type is Impersonation + Open with the desired access. + The new token + Thrown on error + + + + Duplicate the token as the same token type. + + The new token. + Thrown on error + + + + Duplicate the token as the same token type. + + True to throw on error. + The new token. + Thrown on error + + + + Duplicate token as an impersonation token with a specific level + + The token impersonation level + The new token + Thrown on error + + + + Set a privilege state + + The name of the privilege (e.g. SeDebugPrivilege) + True to enable the privilege, false to disable + True to throw on error. + True if successfully changed the state of the privilege + + + + Set a privilege state + + The name of the privilege (e.g. SeDebugPrivilege) + True to enable the privilege, false to disable + True if successfully changed the state of the privilege + + + + Set a privilege state + + The luid of the privilege + The privilege attributes to set. + True to throw on error. + True if successfully changed the state of the privilege + + + + Set a privilege state + + The luid of the privilege + The privilege attributes to set. + True if successfully changed the state of the privilege + + + + Set a privilege state + + The value of the privilege + The privilege attributes to set. + True to throw on error. + True if successfully changed the state of the privilege + + + + Set a privilege state + + The value of the privilege + The privilege attributes to set. + True if successfully changed the state of the privilege + + + + Remove a privilege. + + The value of the privilege to remove. + True if successfully removed the privilege. + + + + Remove a privilege. + + The LUID of the privilege to remove. + True if successfully removed the privilege. + + + + Create a LowBox token from the current token. + + The package SID + The created LowBox token. + Thrown on error. + + + + Create a LowBox token from the current token. + + The package SID + List of handles to capture with the token + The created LowBox token. + Thrown on error. + + + + Create a LowBox token from the current token. + + The package SID + List of handles to capture with the token + List of capability sids to add. + Desired token access. + The created LowBox token. + Thrown on error. + + + + Filter a token to remove groups/privileges and add restricted SIDs + + Filter token flags + List of SIDs to disable + List of privileges to delete + List of restricted SIDs to add + The new token. + + + + Filter a token to remove groups/privileges and add restricted SIDs + + Filter token flags + List of SIDs to disable + List of privileges to delete + List of restricted SIDs to add + The new token. + + + + Filter a token to remove privileges and groups. + + Filter token flags + The new filtered token. + + + + Set the state of a group + + The group SID to set + The attributes to set + + + + Set the state of a group + + The group SID to set + The attributes to set + True to throw on error. + The NT status code. + + + + Set the state of a group + + The groups to set + The attributes to set + True to throw on error. + The NT status code. + + + + Set the state of a group + + The groups to set + The attributes to set + + + + Reset all groups to their default state. + + True to throw on error. + The NT status code. + + + + Reset all groups to their default state. + + + + + Set the session ID of a token + + The session ID + + + + Set a token's default DACL + + The DACL to set. + + + + Set the origin logon session ID. + + The origin logon session ID. + + + + Set virtualization enabled + + True to enable virtualization + True to throw on error. + + + + Set virtualization enabled + + True to enable virtualization + + + + Set UI Access flag. + + True to enable UI Access. + + + + Get the linked token + + True to throw on error. + The linked token + + + + Get the linked token + + The linked token + + + + Set the linked token. + + The token to set. + Requires SeCreateTokenPrivilege. + + + + Impersonate the token. + + An impersonation context, dispose to revert to process token + Thrown on error. + + + + Impersonate the token. + + Impersonation level for token. + An impersonation context, dispose to revert to process token + Thrown on error. + + + + Run a function under impersonation. + + The return type. + The callback to run. + The return value from the callback. + Thrown on error. + + + + Run an action under impersonation. + + The callback to run. + Thrown on error. + + + + Run a function under impersonation. + + The return type. + The callback to run. + Impersonation level for token. + The return value from the callback. + Thrown on error. + + + + Run an action under impersonation. + + The callback to run. + Impersonation level for token. + Thrown on error. + + + + Get a security attribute by name. + + Specify the type of security attributes to query. + The name of the security attribute, such as WIN://PKG + The expected type of the security attribute. If None return ignore type check. + The security attribute or null if not found. + + + + Get a security attribute by name. + + The name of the security attribute, such as WIN://PKG + The expected type of the security attribute. If None return ignore type check. + The security attribute or null if not found. + + + + Get a security attribute by name. + + The name of the security attribute, such as WIN://PKG + The security attribute or null if not found. + + + + Get token's security attributes + + Specify the type of security attributes to query. + Throw on error. + The security attributes. + + + + Get token's security attributes. + + Throw on error. + The security attributes. + + + + Get token's security attributes + + Specify the type of security attributes to query. + The security attributes. + + + + Get token's security attributes + + The security attributes. + + + + Set security attributes on the token. + + The list of attributes. + The operation to perform on the attribute. + Throw on error. + The array of attributes aand operations must be the same size. You need SeTcbPrivilege to call this API. + The NT Status code. + + + + Set security attributes on the token. + + The list of attributes. + The operation to perform on the attribute. + The array of attributes aand operations must be the same size. You need SeTcbPrivilege to call this API. + + + + Add security attributes to the token. + + The list of attributes. + Throw on error. + You need SeTcbPrivilege to call this API. + The NT Status code. + + + + Add security attributes to the token. + + The list of attributes. + You need SeTcbPrivilege to call this API. + + + + Replace security attributes in the token. + + The list of attributes. + Throw on error. + You need SeTcbPrivilege to call this API. + The NT Status code. + + + + Replace security attributes in the token. + + The list of attributes. + You need SeTcbPrivilege to call this API. + + + + Replace all security attributes in the token. + + The list of attributes. + Throw on error. + You need SeTcbPrivilege to call this API. + The NT Status code. + + + + Replace security attributes in the token. + + The list of attributes. + You need SeTcbPrivilege to call this API. + + + + Remove security attributes by name. + + The attribute names to remove. + Throw on error. + The NT Status code. + + + + Remove security attributes by name. + + The attribute names to remove. + + + + Set the token's integrity level. + + The level to set. + + + + Set the token's integrity level. + + The level to set. + + + + Get the state of a privilege. + + The privilege to get the state of. + The privilege, or null if it can't be found + Thrown if can't query privileges + + + + Get the state of a privilege. + + The privilege to get the state of. + The privilege, or null if it can't be found + True to throw on error + Thrown if can't query privileges + + + + Compare two tokens. + + The other token to compare. + True if tokens are equal. + + + + Get the App Policy for this token. + + The type of app policy. + The policy value. + + + + Disable No Child process policy on the token. + + Needs SeTcbPrivilege. + + + + Query a list of groups from the token. + + The type of groups to query. + True to throw on error. + The list of groups. + + + + Query a list of groups from the token. + + The type of groups to query. + The list of groups. + + + + Get the user from the token. + + True to throw on error. + The user group information. + + + + Do a privilege check on a token. + + The list of privileges to check. + True to require all necessary privileges. + True to throw on error. + The privilege check result. + + + + Do a privilege check on a token. + + The list of privileges to check. + True to require all necessary privileges. + The privilege check result. + + + + Do a privilege check on a token. + + The list of privileges to check. + True to require all necessary privileges. + True to throw on error. + The privilege check result. + + + + Do a privilege check on a token. + + The list of privileges to check. + True to require all necessary privileges. + The privilege check result. + + + + Do a privilege check for a single privilege. + + The privilege to check. + True if the privilege is enabled. + + + + Do a privilege check for a single privilege. + + The privilege to check. + True if the privilege is enabled. + + + + Get token privileges. + + True to throw on error. + The list of privileges. + + + + Perform a capability check for a token. + + The name of the capability to check. + True to throw on error. + True if the token has the capability. + + + + Perform a capability check for a token. + + The name of the capability to check. + True if the token has the capability. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get the logon SID for the token. + + True to throw on error. + The logon SID. + + + + Get token user + + + + + Get token groups + + + + + Get list of enabled groups. + + + + + Get list of deny only groups. + + + + + Get count of groups in this token. + + + + + Get the authentication ID for the token + + + + + Get the token's type + + + + + Get the token's expiration time. + + + + + Get the Token's Id + + + + + Get the Token's modified Id. + + + + + Get/set the token's owner. + + + + + Get/set the token's primary group + + + + + Get/set the token's default DACL + + + + + Get the token's source + + + + + Get token's restricted sids + + + + + Get count of restricted sids + + + + + Get token's impersonation level + + + + + Get/set token's session ID + + + + + Get whether token has sandbox inert flag set. + + + + + Get/set token's origin + + + + + Get token's elevation type + + + + + Get whether token is elevated + + + + + Get whether token has restrictions + + + + + Get/set token UI access flag + + + + + Get or set whether virtualization is allowed + + + + + Get/set whether virtualization is enabled + + + + + Get whether token is restricted + + + + + Get whether token is write restricted. + + + + + Get whether token is filtered. + + + + + Get whether token is not low. + + + + + Token access flags. + + + + + Get whether token can be used for new child processes. + + + + + Get token capabilities. + + + + + Get or set the token mandatory policy + + + + + Get token logon sid + + + + + Get token's integrity level sid + + + + + Get token's App Container number. + + + + + Get or set token's integrity level. + + + + + Get token's security attributes + + + + + Get token's device claims. + + + + + Get token's user claims. + + + + + Get token's restricted user claims. + + Unsupported, at least on Windows 10. + + + + Get token's restricted user claims. + + Unsupported, at least on Windows 10. + + + + Get whether a token is an AppContainer token + + + + + Get whether the token is configured for low privilege. + + + + + Get token's AppContainer sid + + + + + Get token's AppContainer package name (if available). + Returns an empty string if not an AppContainer. + + + + + Get token's device groups + + + + + Get token's restricted device groups. + + + + + Get list of privileges for token + + The list of privileges + Thrown if can't query privileges + + + + Get full path to token + + + + + Get the token's trust level. Will be null if no trust level present. + + + + + Returns true if this is a pseudo token. + + + + + Get whether this token is a sandboxed token. + + + + + Query the token's full package name. + + + + + Query the token's appid. + + + + + Get the list of policies for this App. + + + + + Get the list of policies for this App in a table. + + + + + Get the BaseNamedObjects isolation prefix if enabled. + + + + + Get the token's package identity. + + + + + Get or set the token audit policy. + + Needs SeSecurityPrivilege to query and SeTcbPrivilege to set. + + + + Get or set if token is in a private namespace. + + + + + Get if the token is restricted. + + + + + Get the TSA://ProcUnique attribute. + + + + + Enable debug privilege for the current process token. + + True if set the debug privilege + + + + Enable a privilege of the effective token. + + The privilege to enable. + True if set the privilege. + + + + Open the process token of another process + + The process to open the token for + The desired access for the token + Attribute flags for the handle. + If true then throw an exception on error. + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + The desired access for the token + Attribute flags for the handle. + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + The desired access for the token + If true then throw an exception on error. + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + The desired access for the token + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + True to duplicate the token before returning + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + True to duplicate the token before returning + The desired access for the token + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + True to duplicate the token before returning + The desired access for the token + True to throw on error. + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + The opened token + Thrown if cannot open token + + + + Open the process token of the current process + + The opened token + Thrown if cannot open token + + + + Open the process token of the current process + + True to duplicate the token before returning + The opened token + Thrown if cannot open token + + + + Open the process token of the current process + + True to duplicate the token before returning + The desired access for the token + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The id of the process to open the token for + True to duplicate the token before returning + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The id of the process to open the token for + True to duplicate the token before returning + The desired access for the token + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The id of the process to open the token for + True to duplicate the token before returning + The desired access for the token + True to throw on error. + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The id of the process to open the token for + The opened token + Thrown if cannot open token + + + + Open the thread token + + The thread to open the token for + Open the token as the current identify rather than the impersonated one + The desired access for the token + If true then throw an exception on error. + The opened token result + Thrown if cannot open token + + + + Open the thread token + + The thread to open the token for + Open the token as the current identify rather than the impersonated one + True to duplicate the token before returning. + The desired access for the token + True to throw on error. + The opened token, if no token return null + Thrown if cannot open token + + + + Open the thread token + + The thread to open the token for + Open the token as the current identify rather than the impersonated one + True to duplicate the token before returning + The desired access for the token + The opened token, if no token return null + Thrown if cannot open token + + + + Open the thread token + + The ID of the thread to open the token for + Open the token as the current identify rather than the impersonated one + True to duplicate the token before returning + The desired access for the token + The opened token, if no token return null + Thrown if cannot open token + + + + Open the thread token + + The thread to open the token for + Open the token as the current identify rather than the impersonated one + True to duplicate the token before returning + The opened token, if no token return null + Thrown if cannot open token + + + + Open the thread token + + The thread to open the token for + The opened token, if no token return null + Thrown if cannot open token + + + + Open the current thread token + + True to duplicate the token before returning + The opened token, if no token return null + Thrown if cannot open token + + + + Open the current thread token + + The opened token, if no token return null + Thrown if cannot open token + + + + Open the effective token, thread if available or process + + The thread to open the token for + True to duplicate the token before returning + Desired access for token. + Open token as self. + True to throw on error. + The opened token + Thrown if cannot open token + + + + Open the effective token, thread if available or process + + The thread to open the token for + True to duplicate the token before returning + Desired access for token. + Open token as self. + The opened token + Thrown if cannot open token + + + + Open the effective token, thread if available or process + + The thread to open the token for + True to duplicate the token before returning + True to throw on error. + The opened token + Thrown if cannot open token + + + + Open the effective token, thread if available or process + + The thread to open the token for + True to duplicate the token before returning + The opened token + Thrown if cannot open token + + + + Open the current effective token, thread if available or process + + The opened token + Thrown if cannot open token + + + + Open the current effective token, thread if available or process + + True to throw on error. + The opened token + Thrown if cannot open token + + + + Create a token. Needs SeCreateTokenPrivilege. + + The desired access for the token. + Object attributes, used to pass SecurityDescriptor or SQOS for impersonation token. + The type of token. + The authentication ID for the token. + The expiration time for the token. + The user for the token. + The groups for the token. + The privileges for the token. + The owner of the token. + The primary group for the token. + The default dacl for the token. + The source for the token. + Optional device attributes. + Optional device groups. + Optional mandatory policy. + Optional user attributes. + True to throw on error. + The token object. + + + + Create a token. Needs SeCreateTokenPrivilege. + + The desired access for the token. + Object attributes, used to pass SecurityDescriptor or SQOS for impersonation token. + The type of token. + The authentication ID for the token. + The expiration time for the token. + The user for the token. + The groups for the token. + The privileges for the token. + The owner of the token. + The primary group for the token. + The default dacl for the token. + The source for the token. + Optional device attributes. + Optional device groups. + Optional mandatory policy. + Optional user attributes. + The token object. + + + + Create a token. Needs SeCreateTokenPrivilege. + + The desired access for the token. + Object attributes, used to pass SecurityDescriptor or SQOS for impersonation token. + The type of token. + The authentication ID for the token. + The expiration time for the token. + The user for the token. + The groups for the token. + The privileges for the token. + The owner of the token. + The primary group for the token. + The default dacl for the token. + The source for the token. + True to throw on error. + The token object. + + + + Create a token. Needs SeCreateTokenPrivilege. + + The desired access for the token. + Object attributes, used to pass SecurityDescriptor or SQOS for impersonation token. + The type of token. + The authentication ID for the token. + The expiration time for the token. + The user for the token. + The groups for the token. + The privileges for the token. + The owner of the token. + The primary group for the token. + The default dacl for the token. + The source for the token. + The token object. + + + + Create a token. Needs SeCreateTokenPrivilege. + + The user for the token. + The groups for the token. + The privileges for the token. + The token object. + + + + Create a token. Needs SeCreateTokenPrivilege. + + The user for the token. + The token object. + + + + Impersonate another process' token + + The impersonation level + Process ID of the other process + An impersonation context, dispose to revert to process token + + + + Get the current user. + + True to throw on error. + The current user. + + + + Do a single privilege check on the effective token. + + The privilege to check. + True to throw on error. + True if the privilege is enabled. + + + + Do a single privilege check on the effective token. + + The privilege to check. + True if the privilege is enabled. + + + + Get the current user. + + + + + Get authentication ID for LOCAL SYSTEM + + + + + Get authentication ID for LOCAL SERVICE + + + + + Get authentication ID for NETWORK SERVICE + + + + + Get authentication ID for ANONYMOUS + + + + + Get a pseudo handle to the primary token. + + Only useful for querying information. + + + + Get a pseudo handle to the impersonation token. + + Only useful for querying information. + + + + Get a pseudo handle to the effective token. + + Only useful for querying information. + + + + Static methods to interact with the ETW subsystem. + + + + + Issue a trace control request. + + The trace control function code. + The optional input buffer. + The optional output buffer. + True to throw on error. + The output length. + + + + Issue a trace control request. + + The trace control function code. + The optional input buffer. + The optional output buffer. + The output length. + + + + Access rights for Trace + + + + + The security trace provider GUID. + + + + + The default security GUID. + + + + + Class to represent a kernel transaction. + + + + + Create a transaction + + The object attributes + Desired access for the handle + True to throw an exception on error. + Transaction creation options. + Optional description of the transaction. + Isolation flags. + Isolation level. + Optional transaction timeout. + Optional transaction manager. + Optional UOW. + The NT status code and object result. + + + + Create a transaction + + The object attributes + Desired access for the handle + Transaction creation options. + Optional description of the transaction. + Isolation flags. + Isolation level. + Optional transaction timeout. + Optional transaction manager. + Optional UOW. + The NT status code and object result. + + + + Create a transaction + + The object attributes + Desired access for the handle + True to throw an exception on error. + The NT status code and object result. + + + + Create a transaction + + The object attributes + Desired access for the handle + The opened transaction + + + + Create a transaction + + The path of the transaction + The root if path is relative + Desired access for the handle + Transaction creation options. + Optional description of the transaction. + Isolation flags. + Isolation level. + Optional transaction timeout. + Optional transaction manager. + Optional UOW. + True to throw an exception on error. + The opened transaction + + + + Create a transaction + + The path of the transaction + The root if path is relative + Desired access for the handle + Transaction creation options. + Optional description of the transaction. + Isolation flags. + Isolation level. + Optional transaction timeout. + Optional transaction manager. + Optional UOW. + The opened transaction + + + + Create a transaction + + The path of the transaction + The root if path is relative + Desired access for the handle + True to throw an exception on error. + The opened transaction + + + + Create a transaction + + The path of the transaction + The root if path is relative + Desired access for the handle + The opened transaction + + + + Create a transaction + + The path of the transaction + The root if path is relative + The opened transaction + + + + Create a transaction + + The path of the transaction + The opened transaction + + + + Create a transaction + + The opened transaction + + + + Open a transaction object. + + The object attributes for the object + The desired access for the object + Optional transaction manager. + UOW Guid. + True to throw an exception on error. + The NT status code and object result. + + + + Open a transaction object. + + The object attributes for the object + The desired access for the object + Optional transaction manager. + UOW Guid. + The object result. + + + + Open a transaction object. + + The desired access for the object + Optional transaction manager. + UOW Guid. + The object result. + + + + Open a transaction object. + + Optional transaction manager. + UOW Guid. + The object result. + + + + Open a transaction object. + + UOW Guid. + The object result. + + + + Get a list of all accessible transaction objects. + + The object attributes for the object + Optional transaction manager. + The access for the transaction objects. + The list of all accessible transaction objects. + + + + Get a list of all accessible transaction objects. + + The access for the transaction objects. + The list of all accessible transaction objects. + + + + Get a list of all accessible transaction objects. + + The list of all accessible transaction objects. + + + + Get the current thread's transaction. + + + + + Commit the transaction + + Wait for transaction to commit. + True to throw an exception on error. + The NT status code. + + + + Commit the transaction + + Wait for transaction to commit. + + + + Commit the transaction + + + + + Rollback the transaction + + Wait for transaction to rollback. + True to throw an exception on error. + The NT status code. + + + + Rollback the transaction + + Wait for transaction to rollback. + + + + Rollback the transaction + + + + + Enable the transaction for anything in the current thread context. + + The transaction context. This should be disposed to disable the transaction. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get the ID of the transaction. + + + + + Get the Unit of Work ID of the transaction. Same as transaction ID. + + + + + Get the state of the transaction. + + + + + Get the outcome of the transaction. + + + + + Get or set the transaction description. + + + + + Get or set the transaction isolation level. + + + + + Get or set the transaction isolation flags. + + + + + Get or set transaction timeout. + + + + + Query list of enlistments for this transaction. + + + + + Query the superior enlistment for this transaction. + + + + + Class to represent a kernel transaction manager. + + + + + Create a new transaction manager object. + + The object attributes + Desired access for the handle + True to throw an exception on error. + The CLFS log file to create if not volatile. + Creation options flags. + Commit strength, set to 0. + The NT status code and object result. + + + + Create a new transaction manager object. + + The object attributes + Desired access for the handle + The CLFS log file to create if not volatile. + Creation options flags. + Commit strength, set to 0. + The object result. + + + + Create a new transaction manager object. + + The path to the transaction manager. + The root if path is relative. + Desired access for the handle + The CLFS log file to create if not volatile. + Creation options flags. + True to throw an exception on error. + The object result. + + + + Create a new transaction manager object. + + The path to the transaction manager. + The root if path is relative. + Desired access for the handle + The CLFS log file to create if not volatile. + Creation options flags. + The object result. + + + + Create a new volatile transaction manager object. + + The path to the transaction manager. + The root if path is relative. + Desired access for the handle + The object result. + + + + Create a new volatile transaction manager object. + + The path to the transaction manager. + The root if path is relative. + The object result. + + + + Create a new volatile transaction manager object. + + The path to the transaction manager. + The object result. + + + + Create a new volatile transaction manager object. + + The object result. + + + + Open a existing transaction manager object. + + The object attributes + Desired access for the handle + The CLFS log file to create if not volatile. + Identity of the transaction manager. + Open options flags. + True to throw an exception on error. + The NT status code and object result. + + + + Open a existing transaction manager object. + + The object attributes + Desired access for the handle + Identity of the transaction manager. + The CLFS log file to create if not volatile. + Open options flags. + The object result. + + + + Open an existing transaction manager object. + + The path to the transaction manager. + The root if path is relative. + Desired access for the handle + Identity of the transaction manager. + The CLFS log file to create if not volatile. + Open options flags. + True to throw an exception on error. + The object result. + + + + Open an existing transaction manager object. + + The path to the transaction manager. + The root if path is relative. + Desired access for the handle + Identity of the transaction manager. + The CLFS log file to create if not volatile. + Open options flags. + The object result. + + + + Open an existing transaction manager object. + + The path to the transaction manager. + The root if path is relative. + Desired access for the handle + The object result. + + + + Open an existing transaction manager object. + + The path to the transaction manager. + The root if path is relative. + The object result. + + + + Open an existing transaction manager object. + + The path to the transaction manager. + The object result. + + + + Rename transaction manager object. The new identity can be queried with the Identity property on the object. + + The path to the transaction log file. + The existing transaction manager identity. + True to throw an exception on error. + The NT status code + + + + Get a list of all accessible transaction manager objects. + + Object attributes for opened handle. + The access for the transaction manager objects. + Open options. + The list of all accessible transaction manager objects. + + + + Get a list of all accessible transaction manager objects. + + The access for the transaction manager objects. + The list of all accessible transaction manager objects. + + + + Get a list of all accessible transaction manager objects. + + The list of all accessible transaction manager objects. + + + + Get the Transaction Manager identity. + + + + + Get the Transaction Manager virtual clock. + + + + + Get the Transaction Manager log identity. + + + + + Get the Transaction Manager log path. + + + + + Get Transaction Manager last recovered Log Sequence Number. + + + + + Get whether the transaction manager is volatile. + + + + + Rename transaction manager object. The new identity can be queried with the Identity property on the object. + + True to throw an exception on error. + The NT status code + + + + Rename transaction manager object. The new identity can be queried with the Identity property on the object. + + + + + Recover the transaction manager. + + True to throw an exception on error. + The NT status code + + + + Recover the transaction manager. + + + + + Rollforward the transaction manager. + + Optional virtual block value to rollforward to. + True to throw an exception on error. + The NT status code + + + + Rollforward the transaction manager. + + True to throw an exception on error. + The NT status code + + + + Rollforward the transaction manager. + + Optional virtual block value to rollforward to. + + + + Rollforward the transaction manager. + + + + + Create a resource manager for this transaction manager. + + The resource manager GUID to assign. + Creation options. + True to throw on error. + The resource manager and NT status. + + + + Create a resource manager for this transaction manager. + + The resource manager GUID to assign. + Creation options. + The resource manager . + + + + Create a resource manager for this transaction manager. + + The resource manager GUID to assign. + The resource manager. + + + + Create a volatile resource manager for this transaction manager with a auto-generated GUID. + + The resource manager. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get a list of all accessible transaction objects owned by this transaction manager. + + The access for the transaction objects. + The list of all accessible transaction objects. + + + + Get a list of all accessible transaction objects owned by this transaction manager. + + The list of all accessible transaction objects. + + + + Get a list of all accessible resource manager objects owned by this transaction manager. + + Object attributes for opened handle. + The access for the resource manager objects. + The list of all accessible resource manager objects. + + + + Get a list of all accessible resource manager objects owned by this transaction manager. + + The access for the resource manager objects. + The list of all accessible resource manager objects. + + + + Get a list of all accessible resource manager objects owned by this transaction manager. + + The list of all accessible resource manager objects. + + + + General utilities for the kernel transaction manager. + + + + + Enumerate transaction objects of a specific type from a root handle. + + The root handle to enumearate from. + The type of object to query. + The list of enumerated transaction object GUIDs. + + + + Enumerate all transaction objects of a specific type. + + The type of object to query. + The list of enumerated transaction object GUIDs. + + + + Freeze all transactions. Needs SeRestorePrivilege. + + The freeze wait timeout. + The thaw wait timeout. + Throw exception on error. + The NT status code. + + + + Freeze all transactions. Needs SeRestorePrivilege. + + The freeze wait timeout. + The thaw wait timeout. + + + + Thaw transactions. Needs SeRestorePrivilege. + + Throw exception on error. + The NT status code. + + + + Thaw transactions. Needs SeRestorePrivilege. + + The NT status code. + + + + Class representing an NT object type + + + + + The name of the type + + + + + The mapping from generic to specific object rights + + + + + The valid access mask + + + + + True if the object needs security even if unnamed + + + + + Total number of objects (when originally retrieved) + + + + + Total number of handles (when originally retrieved) + + + + + Total paged pool usage (when originally retrieved) + + + + + Total non-paged pool usage (when originally retrieved) + + + + + Total name pool usage (when originally retrieved) + + + + + Total handle table usage (when originally retrieved) + + + + + Maximum number of objects (when originally retrieved) + + + + + Maximum number of handles (when originally retrieved) + + + + + Maximum paged pool usage (when originally retrieved) + + + + + Maximum non-paged pool usage (when originally retrieved) + + + + + Maximum name pool usage (when originally retrieved) + + + + + Maximum handle table usage (when originally retrieved) + + + + + The attributes flags which are invalid + + + + + Indicates whether handle count is mainted + + + + + Indicates the type list maintained + + + + + Indicates the type of pool used in allocations + + + + + Current paged pool usage + + + + + Current non-pages pool usage + + + + + Type Index + + + + + Generic Read Access rights + + + + + Generic Read Access rights + + + + + Generic Read Access rights + + + + + Generic Read Access rights + + + + + Get the maximum access mask for the type's default mandatory access policy. + + + + + Get implemented object type for this NT type. + + + + + Get the access rights enumerated type for this NT type. + + + + + Get the access rights enumerated type for this NT type if it's a container. + + There's only one known type at the moment which uses this, File. + + + + Can this type of open be opened by name + + + + + Get the valid access rights for this Type. + + + + + Get the valid read access rights for this Type. + + + + + Get the valid write access rights for this Type. + + + + + Get the valid execute access rights for this Type. + + + + + Get the valid all access rights for this Type. + + + + + Get the valid mandatory access rights for this Type. + + + + + Get defined query information classes for a type. + + + + + Get defined set information classes for a type. + + + + + Open this NT type by name (if CanOpen is true) + + The object attributes to open. + Desired access when opening. + True to throw an exception on error. + The NT status code and object result. + + + + Open this NT type by name (if CanOpen is true) + + The name of the object to open. + The root object for opening, if name is relative + Desired access when opening. + The created object. + Thrown on error + + + + Open this NT type by name (if CanOpen is true) + + The name of the object to open. + The root object for opening, if name is relative + The created object. + Thrown on error + + + + Open this NT type by name (if CanOpen is true) + + The name of the object to open. + The created object. + Thrown on error + + + + Get object from an existing handle. + + The existing handle. + The new object. + + + + Get object from an existing handle. + + The existing handle. + True to own the handle. + The new object. + + + + Get object from an existing handle. + + The existing handle. + The call doesn't own the handle. The returned object can't be used to close the handle. + The new object. + + + + Convert an enumerable access rights to a string + + True to use the container access type. + The granted access mask. + True to try and convert to generic rights where possible. + Set to true to use SDK style names. + The string format of the access rights + + + + Convert an enumerable access rights to a string + + True to use the container access type. + The granted access mask. + True to try and convert to generic rights where possible. + The string format of the access rights + + + + Convert an enumerable access rights to a string + + The granted access mask. + True to try and convert to generic rights where possible. + The string format of the access rights + + + + Convert an enumerable access rights to a string + + The granted access mask. + The string format of the access rights + + + + Checks if an access mask represents a read permission on this type + + The access mask to check + True if it has read permissions + + + + Checks if an access mask represents a write permission on this type + + The access mask to check + True if it has write permissions + + + + Checks if an access mask represents a execute permission on this type + + The access mask to check + True if it has execute permissions + + + + Checks if an access mask represents a full permission on this type + + The access mask to check + True if it has full permissions + + + + Map generic access rights to specific access rights for this type + + The access mask to map + The mapped access mask + + + + Unmap specific access rights to generic access rights for this type + + The access mask to unmap + The unmapped access mask + + + + Checks if an access mask is valid for access of this object type. + + The access mask to check + True if it valid access + + + + Get the maximum access mask for the type's default mandatory access policy. + + The allowed access mask for the type with the default policy. + + + + Overridden ToString method. + + Returns the type as a string. + + + + Create an NtType object by name. + + The name of the NT type. + This will always return a cached type. + Invalid NT type name. + + + + Get a type object by index + + The index + The object type, null if not found + + + + Get a type object by index + + The index, must be >= 0. + True to get a cached type, false to return a live types. + The object type, null if not found + + + + Get a type object by name + + The name of the type + True to create a fake type if needed. + True to get a cached type, false to return a live types. + The object type, null if not found + + + + Get a type object by name + + The name of the type + True to create a fake type if needed. + The object type, null if not found + + + + Get a type object by name + + The name of the type + The object type, null if not found + + + + Get a type object by a kernel handle. + + The kernel handle. + True to create a fake type if needed. + The object type, null if not found + + + + Get an NT type based on the implemented .NET type. + + A type derived from NtObject + True to get a cached type, false to return a live types. + The NtType represented by this .NET type. Note if a type is represented with multiple + names only return the first one we find. + Thrown if there exists no .NET type which maps to this type. + + + + Get an NT type based on the implemented .NET type. + + A type derived from NtObject + The NtType represented by this .NET type. Note if a type is represented with multiple + names only return the first one we find. + Thrown if there exists no .NET type which maps to this type. + + + + Get a fake type object. This can be used in access checking for operations which need an NtType object + but there's no real NT object. + + The name of the fake type. Informational only. + The GENERIC_MAPPING for security checking. + The access rights enumeration type. + The access rights enumeration type of the object is a container. + The mandatory label policy. + The fake NT type object. + + + + Get a fake type object. This can be used in access checking for operations which need an NtType object + but there's no real NT object. + + The name of the fake type. Informational only. + The GENERIC_MAPPING for security checking. + The access rights enumeration type. + The access rights enumeration type of the object is a container. + The fake NT type object. + + + + Get a fake type object. This can be used in access checking for operations which need an NtType object + but there's no real NT object. + + The name of the fake type. Informational only. + The GENERIC_MAPPING for security checking. + The access rights enumeration type. + The fake NT type object. + + + + Get a fake type object. This can be used in access checking for operations which need an NtType object + but there's no real NT object. + + The name of the fake type. Informational only. + The GENERIC_READ for security checking. + The GENERIC_WRITE for security checking. + The GENERIC_EXECUTE for security checking. + The GENERIC_ALL for security checking. + The access rights enumeration type. + The access rights enumeration type of the object is a container. + The fake NT type object. + + + + Get a fake type object. This can be used in access checking for operations which need an NtType object + but there's no real NT object. + + The name of the fake type. Informational only. + The GENERIC_READ for security checking. + The GENERIC_WRITE for security checking. + The GENERIC_EXECUTE for security checking. + The GENERIC_ALL for security checking. + The access rights enumeration type. + The fake NT type object. + + + + Get a list of all types. + + The list of types. + + + + Get a list of all types. + + True to get the cached list of types, false to return a live list of all types. + True to include fake types such as WNF or Service + The list of types. + + + + Get a list of all types. + + True to get the cached list of types, false to return a live list of all types. + The list of types. + + + + Get the NT type from a path. + + The object manager path. + Optional root object. + The NT type. Returns null if not available or unknown. + + + + Converted user process parameters. + + + + + Static class to access virtual memory functions of NT. + + + + + Query section name, + + The process to query from. + The base address to query. + True to throw on error + The result of the query. + + + + Query section name, + + The process to query from. + The base address to query. + The result of the query. + + + + Query memory information for a process. + + The process to query. + The base address. + True to throw on error. + The memory information for the region. + Thrown on error. + + + + Query memory information for a process. + + The process to query. + The base address. + The memory information for the region. + Thrown on error. + + + + Query all memory information regions in process memory. + + The list of memory regions. + Thrown on error. + + + + Query a list of mapped files in a process. + + The process to query. + The list of mapped images + Thrown on error. + + + + Read memory from a process. + + The process to read from. + The base address in the process. + The length to read. + The array of bytes read from the location. + If a read is short then returns fewer bytes than requested. + Thrown on error. + + + + Write memory to a process. + + The process to write to. + The base address in the process. + The data to write. + The number of bytes written to the location + Thrown on error. + + + + Read structured memory from a process. + + The process to read from. + The base address in the process. + The read structure. + Thrown on error. + Type of structure to read. + + + + Write structured memory to a process. + + The process to write to. + The base address in the process. + The data to write. + Thrown on error. + Type of structure to write. + + + + Read structured memory array from a process. + + The process to read from. + The base address in the process. + The number of elements in the array to read. + The read structure. + Thrown on error. + Type of structure to read. + + + + Write structured memory array to a process. + + The process to write to. + The base address in the process. + The data array to write. + Thrown on error. + Type of structure to write. + + + + Allocate virtual memory in a process. + + The process to allocate in. + Optional base address, if 0 will automatically select a base. + The region size to allocate. + The type of allocation. + The allocation protection. + True to throw on error. + The address of the allocated region. + Thrown on error. + + + + Allocate virtual memory in a process. + + The process to allocate in. + Optional base address, if 0 will automatically select a base. + The region size to allocate. + The type of allocation. + The allocation protection. + The address of the allocated region. + Thrown on error. + + + + Free virtual emmory in a process. + + The process to free in. + Base address of region to free + The size of the region. + The type to free. + Thrown on error. + + + + Free virtual emmory in a process. + + The process to free in. + Base address of region to free + The size of the region. + The type to free. + True to throw on error. + Thrown on error. + + + + Change protection on a region of memory. + + The process to change memory protection + The base address + The size of the memory region. + The new protection type. + The old protection for the region. + Thrown on error. + + + + Change protection on a region of memory. + + The process to change memory protection + The base address + The size of the memory region. + The new protection type. + True to throw on error. + The old protection for the region. + Thrown on error. + + + + Query working set information for an address in a process. + + The process to query. + The base address to query. + True to throw on error + The working set information. + Thrown on error. + + + + Query working set information for an address in a process. + + The process to query. + The base address to query. + The working set information. + Thrown on error. + + + + Query image information for an address in a process. + + The process to query. + The base address to query. + True to throw on error + The image information. + Thrown on error. + + + + Query image information for an address in a process. + + The process to query. + The base address to query. + The image information. + Thrown on error. + + + + Determine if two addresses are the same mapped file. + + The first address. + The second address. + True to throw on error. + True if the mapped memory is the same file. + + + + Determine if two addresses are the same mapped file. + + The first address. + The second address. + True if the mapped memory is the same file. + + + + Flush instruction cache. + + The process to flush the cache in. + The address to flush. + The number of bytes to flush/ + True to throw on error. + The NT status code. + + + + Flush instruction cache. + + The process to flush the cache in. + The address to flush. + The number of bytes to flush/ + + + + Native Wait methods. + + + + + Wait on a single object to become signaled + + The object to wait on + Whether the thread should be alertable + The timeout to wait for + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + + + + Wait on multiple objects to become signaled + + The objects to wait on + Whether the thread should be alerable + True to wait for all objects to be signaled + The timeout to wait for + The success status of the wait, such as STATUS_WAIT_OBJECT_0 or STATUS_TIMEOUT + + + + Signal an object then wait for another to become signaled. + + The object to signal + The object to wait on. + Whether the thread should be alertable + The timeout to wait for + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + + + + A .NET wait handle to use for interop. + + + + + Create a .NET wait handle from an object. + + The object to create the wait handle on + + + + Wait asynchronously for the handle to be signaled. + + Timeout in milliseconds. + Cancellation token for wait. + A task to wait on. If result is true then event was signaled. + + + + Wait asynchronously for the handle to be signaled. + + Timeout in milliseconds. + A task to wait on. If result is true then event was signaled. + + + + Wait asynchronously for the handle to be signaled. + Will wait an infinite time. + + A task to wait on. + + + + Class to represent an NT timeout + + + + + Get a timeout which will wait indefinitely. + + + + + Get a relative timeout in seconds. + + The number of seconds to wait. + An instance of the timeout class. + + + + Get a relative timeout in milliseconds. + + The number of milliseconds to wait. + An instance of the timeout class. + + + + Get an absolute time out from system start. + + The absolute time to wait until. + An instance of the timeout class. + + + + Get a relative time out from the current time. + + The relative time to wait in units of 100ns. + An instance of the timeout class. + + + + Create an absolute wait timeout from a datetime. + + The time for the timeout to complete. + An instance of the timeout class. + + + + The timeout as a long. + + + + + Overridden ToString method. + + The timeout as a string. + + + + Well-known IO Control codes. + + + + + Convert a control code to a known name. + + The control code. + The known name, or an empty string. + + + + Get a list of known control codes. + + The list of known control codes. + + + + Get a list of known control codes. + + The control code. + Thrown if can't find name. + + + + Structure to represent a Window. + + + + + The Window Handle. + + + + + Get Process ID for the Window. + + + + + Get the Thread ID for the Window. + + + + + Get the real owner Process ID of the Window. + + + + + Get the class name for the Window. + + + + + Send a message to the Window, Unicode. + + The message to send. + The WPARAM. + The LPARAM. + The send result. + + + + Send a message to the Window, ANSI. + + The message to send. + The WPARAM. + The LPARAM. + The send result. + + + + Post a message to the Window, Unicode. + + The message to send. + The WPARAM. + The LPARAM. + True to throw on error. + The send result. + + + + Post a message to the Window, Unicode. + + The message to send. + The WPARAM. + The LPARAM. + The send result. + + + + Send a message to the Window, ANSI. + + The message to send. + The WPARAM. + The LPARAM. + True to throw on error. + The send result. + + + + Send a message to the Window, ANSI. + + The message to send. + The WPARAM. + The LPARAM. + The send result. + + + + Constructor. + + Window handle. + + + + Constructor. + + Window handle. + + + + Get the NULL window handle. + + + + + Get the desktop window. + + + + + Get the broadcast window. + + + + + Get all Top Level windows. + + + + + Enumerate window handles. + + Desktop containing the Windows. Optional. + The parent Window. Optional. + True to enumerate child Windows. + Hide immersive Windows. + The thread ID that owns the Window. + True to throw on error. + The enumerated Window Handles. + + + + Enumerate window handles. + + Desktop containing the Windows. Optional. + The parent Window. Optional. + True to enumerate child Windows. + Hide immersive Windows. + The thread ID that owns the Window. + The enumerated Window Handles. + + + + Class which represents a window station object. + + + + + Open a window station by name. + + The object attributes for opening. + Desired access. + True to throw on error. + The instance of the window station + Thrown on error. + + + + Open a window station by name. + + The object attributes for opening. + Desired access. + The instance of the window station + Thrown on error. + + + + Open a window station by name. + + The name of the window station + Optional root object + The instance of the window station + Thrown on error. + + + + Open a window station by name. + + + The instance of the window station + Thrown on error. + + + + Create a Window Station by name. + + Object attributes for the Window Station. + Desired access for the Window Station. + Path to Keyboard DLL e.g. kbusa.dll. + Locale ID, e.g. 0x4090409. + Language ID e.g. 0x409. + True to throw on error. + The Window Station. + + + + Create a Window Station by name. + + Object attributes for the Window Station. + Desired access for the Window Station. + Path to Keyboard DLL e.g. kbusa.dll. + Locale ID, e.g. 0x4090409. + Language ID e.g. 0x409. + The Window Station. + + + + Create a Window Station by name. + + The name of the Window Station. + The Window Station. + + + + Get a list of desktops for this Window Station. + + + + + Enumerate name of Window Stations in current session. + + + + + Get a list of accessible Window Station objects. + + The desired access for the Window Stations. + The list of desktops. + + + + Get a list of accessible Window Station objects. + + The list of desktops. + + + + Get a list of accessible desktop objects. + + The desired access for the desktops. + The list of desktops. + + + + Get a list of accessible desktop objects. + + The list of desktops. + + + + Close the Window Stations. This is different from normal Close as it destroys the Window Station. + + True to throw on error. + The NT status. + + + + Set the Window Station for the Process. + + True to throw on error. + The NT status. + + + + Open the current process Window Station. + + True to throw on error. + The instance of the window station + The returned object is no owned by the caller. + Thrown on error. + + + + Open the current process Window Station. + + + + + Get the Window Station directory for a session. + + The session ID. + The path to the Window Station directory. + + + + Get the Window Station directory for the current session. + + The path to the Window Station directory. + + + + NT WNF object. + + + + + Get the generic mapping for a + + + + + Fake NT type name for WNF. + + + + + Create a new WNF state name. + + The lifetime of the name. + The scope of the data. + Whether to persist data. + Optional type ID. + Maximum state size. + Mandatory security descriptor. + True to throw on error. + The created object. + + + + Kernel derived key which is used to mask the state name. + + + + + Create a new WNF state name. + + The lifetime of the name. + The scope of the data. + Whether to persist data. + Optional type ID. + Maximum state size. + Mandatory security descriptor. + The created object. + + + + Open a state name. Doesn't check if it exists. + + The statename to open. + True to check state name exists. + True to throw on error. + The created object. + + + + Open a state name. Doesn't check if it exists. + + The statename to open. + True to check state name exists. + The created object. + + + + Open a state name. Doesn't check if it exists. + + The statename to open. + The created object. + + + + Open a state name. Doesn't check if it exists. + + The name to open. + True to check state name exists. + The created object. + + + + Open a state name. Doesn't check if it exists. + + The name to open. + The created object. + + + + Get registered notifications. + + The list of registered notifications. + + + + Get the state name for this WNF entry. + + + + + The state name decoded. + + + + + Get the associated lifetime for the state name. + + + + + Version of the WNF state name. + + + + + Data scope of WNF state name. + + + + + Is WNF state name persistent. + + + + + Unique identifier of WNF state name, + + + + + Get if the state has subscribers. + + + + + Get the security descriptor for this object, if known. + + + + + Get a name for the WNF notification. + + + + + Query state data for the WNF object. + + Optional Type ID. + Optional explicit scope. + True to throw on error. + The state data. + + + + Query state data for the WNF object. + + Optional Type ID. + Optional explicit scope. + The state data. + + + + Query state data for the WNF object. + + The state data. + + + + Update state data for the WNF object. + + The data to set. + Optional Type ID. + Optional explicit scope. + Optional matching changestamp. + True to throw on error. + The status from the update. + + + + Update state data for the WNF object. + + The data to set. + + + + Delete the state data for the WNF object. + + Optional explicit scope. + True to throw on error. + The NT status code. + + + + Delete the state data for the WNF object. + + Optional explicit scope. + + + + Delete the state data for the WNF object. + + + + + Overridden ToString method. + + The string representation. + + + + Get dictionary of well known WNF state names. + + This was dumped from perf_nt_c.dll 10.0.18362.1 using https://github.com/ionescu007/wnfun. + + + + Get the state name to name mappings. + + + + + Get the name to state name mappings. + + + + + Get the name of a state name if known. + + The state name. + The name of the state name, or null if unknown. + + + + Flags for OBJECT_ATTRIBUTES + + + + + None + + + + + Handle is protected from closing. + + + + + The handle created can be inherited + + + + + Audit handle close. + + + + + The object created is marked as permanent + + + + + The object must be created exclusively + + + + + The object name lookup should be done case insensitive + + + + + Open the object if it already exists + + + + + Open the object as a link + + + + + Create as a kernel handle (not used in user-mode) + + + + + Force an access check to occur (not used in user-mode) + + + + + Ignore impersonated device map when looking up object + + + + + Fail if a reparse is encountered + + + + + A class which represents OBJECT_ATTRIBUTES + + + + + Constructor. Sets flags to None + + + + + Constructor + + The name of the object + Attribute flags + + + + Constructor + + The name of the object + Attribute flags + A root object to lookup a relative path + + + + Constructor + + Attribute flags + + + + Constructor + + The name of the object + + + + Constructor + + An object ID. + The object attribute flags. + An optional root handle, can be SafeKernelObjectHandle.Null. Will duplicate the handle. + An optional security quality of service. + An optional security descriptor. + + + + Constructor + + The object name, can be null. + The object attribute flags. + An optional root handle, can be SafeKernelObjectHandle.Null. Will duplicate the handle. + An optional security quality of service. + An optional security descriptor. + + + + Constructor + + The object name, can be null. + The object attribute flags. + An optional root handle, Will duplicate the handle. + An optional security quality of service. + An optional security descriptor. + + + + Create an Object Attributes structure with a raw name. Useful for Object ID handling. + + The name of the object in raw bytes. + The object attribute flags. + An optional root handle, Will duplicate the handle. + An optional security quality of service. + An optional security descriptor. + The created object attributes. + + + + Dispose + + + + + Object type entry for an access check. + + + + + The object level. + + + + + The object type GUID. + + + + + The name of the object. + + + + + Constructor. + + + + + Constructor. + + The object type GUID. + The object level. + The name of the object type entry. + + + + Constructor. + + The object type GUID. + The object level. + + + + Constructor. + + The object type GUID. + + + + Overridden ToString method. + + The object formatted. + + + + This class allows a function to specify an optional Guid + + + + + Optional Guid + + + + + Constructor + + The GUID to initialize + + + + Constructor + + + + + Implicit conversion + + The value + + + + This class allows a function to specify an optional uint16. + + + + + Optional value + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value + + + + This class allows a function to specify an optional int32. + + + + + Optional value + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value + + + + This class allows a function to specify an optional int64. + + + + + Optional value + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value + + + + This class allows a function to specify an optional length as a SizeT + + + + + Optional length + + + + + Constructor + + The length value + + + + Constructor + + The length value + + + + Constructor + + The length value + + + + Implicit conversion + + The length value + + + + This class allows a function to specify an optional pointer. + + + + + Optional length + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value + + + + Optional value. + + + + + Optional value. + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value. + + + + Optional value. + + + + + Optional value. + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value. + + + + Optional value. + + + + + Optional value. + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value. + + + + Optional value. + + + + + Optional value. + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value. + + + + The result of a privilege check. + + + + + The list of privileges from the result. + + + + + The list of enabled privileges. + + + + + True indicates all privileges were held. + + + + + A single process module. + + + + + The module section. + + + + + Mapped base. + + + + + Image base. + + + + + Image size. + + + + + Flags. + + + + + Load order index. + + + + + Init order index. + + + + + Load count. + + + + + Full path name. + + + + + File name. + + + + + Reparse Tag value. + + + + + Base class for a reparse buffer. + + + + + The reparse tag in the buffer. + + + + + Function to initialize this class by parsing the reparse buffer data (not including header). + + The length of the data to read. + The stream to read from. + + + + Get reparse buffer data as a byte array (not including header). + + The reparse buffer data. + + + + Constructor. + + The reparse tag to assign. + + + + Get a reparse buffer from a byte array. + + The byte array to parse + The reparse buffer. + + + + Get a reparse buffer from a byte array. + + The byte array to parse + True to return an opaque buffer if + the tag isn't known, otherwise try and parse as a generic buffer + The reparse buffer. + + + + Convert reparse buffer to a byte array in REPARSE_DATA_BUFFER format. + + The reparse buffer as a byte array. + + + + Convert reparse buffer to a byte array in the REPARSE_DATA_BUFFER_EX format. + + Flags for the buffer. + Existing GUID to match against. + Existing tag to matcha against. + The reparse buffer as a byte array. + + + + Get if a reparse tag is a Microsoft defined one. + + + + + Get if a reparse tag is a name surrogate. + + True if it's a surrogate reparse tag. + + + + Get if a reparse tag is a directory. + + + + + Generic GUID reparse buffer. + + + + + Constructor. + + The reparse tag. + The reparse GUID + Additional reparse data. + + + + Constructor. + + The reparse tag. + The reparse GUID + Additional reparse data. + + + + The reparse GUID. + + + + + Additional reparse data. + + + + + Get reparse buffer data as a byte array (not including header). + + The reparse buffer data. + + + + Function to initialize this class by parsing the reparse buffer data (not including header). + + The length of the data to read. + The stream to read from. + + + + Reparse buffer with an opaque data blob. + + + + + Constructor. + + The reparse tag. + The opaque data blob. + + + + The opaque data blob. + + + + + Get reparse buffer data as a byte array (not including header). + + The reparse buffer data. + + + + Function to initialize this class by parsing the reparse buffer data (not including header). + + The length of the data to read. + The stream to read from. + + + + Reparse buffer for an NTFS mount point. + + + + + Constructor. + + Substitution name to reparse to when accessing mount point. + Printable name for the mount point. + + + + Substitution name to reparse to when accessing mount point. + + + + + Printable name for the mount point. + + + + + Function to initialize this class by parsing the reparse buffer data (not including header). + + The length of the data to read. + The stream to read from. + + + + Get reparse buffer data as a byte array (not including header). + + The reparse buffer data. + + + + Symlink flags. + + + + + None. + + + + + Substitution name is relative to the symlink. + + + + + Reparse buffer for an NTFS symlink. + + + + + Constructor. + + Substitution name to reparse to when accessing symlink. + Printable name for the symlink. + Symlink flags. + + + + Constructor. + + Substitution name to reparse to when accessing symlink. + Printable name for the symlink. + Symlink flags. + Create a global symlink rather than a normal symlink. + + + + Substitution name to reparse to when accessing symlink. + + + + + Printable name for the symlink. + + + + + Symlink flags. + + + + + Function to initialize this class by parsing the reparse buffer data (not including header). + + The length of the data to read. + The stream to read from. + + + + Get reparse buffer data as a byte array (not including header). + + The reparse buffer data. + + + + Application type for execution alias. + + + + + Desktop bridge application. + + + + + UWP type 1 + + + + + UWP type 2 + + + + + UWP type 3 + + + + + Reparse buffer for an execution alias. + + + + + The execution alias version. + + + + + The name of the application package. + + + + + The entry point in the package. + + + + + The target executable. + + + + + Application type for the alias. + + + + + Flags, obsolete. + + + + + Constructor. + + The execution alias version. + The name of the application package. + The entry point in the package. + The target executable. + Apptype for the alias. + + + + Get reparse buffer data as a byte array (not including header). + + The reparse buffer data. + + + + Function to initialize this class by parsing the reparse buffer data (not including header). + + The length of the data to read. + The stream to read from. + + + + Safe buffer for an ALPC data view. + + + + + Flags for the data view. + + + + + Get the port section handle. + + + + + Convert the section view to a message attribute. + + The message attribute. + + + + Release the data view handle. + + True if successfully released. + + + + Safe buffer to contain an ALPC port message. + + + + + Constructor. + + The port message header. + The total length of allocated memory excluding the header. + + + + Constructor. Creates a receive buffer with a set length. + + The total length of allocated memory excluding the header. + + + + Get a NULL safe buffer. + + + + + Detaches the current buffer and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + Safe handle for a port section. + + + + + Release handle. + + True if handle released successfully. + + + + Safe handle for an ALPC security context. + + + + + Attribute flags. + + + + + Security quality of service. + + + + + Get the security context as a message attribute. + + The message attribute. + + + + Get whether handle is invalid. + + + + + Release handle. + + True if handle released successfully. + + + + Revoke the security context attribute. + + True to throw on error. + The NT status code. + + + + Revoke the security context attribute. + + + + + Safe buffer to contain a list of structures. + + + + + The count of elements of the array. + + + + + Constructor. + + Array of elements. + Additional data to place after the array. + + + + Constructor. + + Array of elements. + + + + Get a reference to the additional data. + + + + + Get a NULL safe array buffer. + + + + + Dispose buffer. + + True if disposing. + + + + Safe buffer which acts as a base class for all other SafeBuffer types in the library. + + + + + Constructor + + Size of the buffer. + An existing pointer to a buffer. + Specify whether safe handle owns the buffer. + Inidicates if the underlying buffer is writable. + + + + Constructor + + Size of the buffer. + An existing pointer to a buffer. + Specify whether safe handle owns the buffer. + + + + Length of the allocation. + + + + + Length of the allocation as a long. + + + + + Get the length as an IntPtr + + + + + Convert the safe handle to an array of bytes. + + The data contained in the allocaiton. + + + + Read a NUL terminated string for the byte offset. + + The byte offset to read from. + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated string + + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated ANSI string for the byte offset. + + The byte offset to read from. + Text encoding for the string. + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated ANSI string + + Text encoding for the string. + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated ANSI string for the byte offset. + + The byte offset to read from. + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated ANSI string + + The string read from the buffer without the NUL terminator + + + + Read a unicode string from the buffer. + + The offset into the buffer to read. + The number of characters to read. + The read unicode string. + + + + Read a unicode string from the buffer. + + The number of characters to read. + The read unicode string. + + + + Write a unicode string to the buffer. + + The offset into the buffer to write. + The value to write. + + + + Write a unicode string to the buffer. + + The value to write. + + + + Read an array of bytes from the buffer. + + The offset into the buffer. + The number of bytes to read. + The read bytes. + + + + Read an array of bytes from the buffer. + + The number of bytes to read. + The read bytes. + + + + Write an array of bytes to the buffer. + + The offset into the buffer. + The bytes to write. + + + + Write an array of bytes to the buffer. + + The bytes to write. + + + + Read array from the buffer. + + The type to read. + The offset into the buffer. + The number of elements to read. + The read array. + + + + Read an array of complex structures which can contain references. Doing this from a buffer is a dangerous operation. + + The buffer type. + The offset into the buffer. + The number of elements. + The array structures. + This doesn't bounds check the buffer size for the array or embedded structures so could easily crash the application. + + + + Zero an entire buffer. + + + + + Fill an entire buffer with a specific byte value. + + The fill value. + + + + Get a structured buffer object at a specified offset. + + The type of structure. + The offset into the buffer. + The structured buffer object. + + + + Get the buffer as a memory stream + + + + + + Create a view accessor over the full buffer. + + The view accessor. + + + + Create a view accessor. + + Offset into the buffer + Size of view. + The view accessor. + + + + Create a view accessor. + + Offset into the buffer + Size of view. + True to make the view writable. False for read-only + The view accessor. + + + + A safe handle to an allocated global buffer. + + + + + Constructor + + Size of the buffer to allocate. + + + + Constructor + + The length of data to allocate. + The total length to reflect in the Length property. + + + + Constructor + + Size of the buffer. + An existing pointer to an existing HGLOBAL allocated buffer. + Specify whether safe handle owns the buffer. + + + + Constructor + + Initialization data for the buffer. + + + + Get a buffer which represents NULL. + + + + + Resize the SafeBuffer. + + + + + + Overridden ReleaseHandle method. + + True if successfully released the memory. + + + + Detaches the current buffer and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + Detaches the current buffer and allocates a new one. + + Specify a new length for the detached buffer. Must be <= Length. + The detached buffer. + The original buffer will become invalid after this call. + + + + Non-generic buffer to hold an IO_STATUS_BLOCK. + + + + + Constructor. + + + + + Get a buffer which represents NULL. + + + + + Safe handle which represents a kernel handle. + + + + + Constructor. + + An existing kernel handle. + True to own the kernel handle. + + + + Overridden ReleaseHandle method. + + True if successfully released the handle. + + + + Overridden IsInvalid method. + + + + + Get a handle which represents NULL. + + + + + Get or set whether the handle is inheritable. + + + + + Get or set whether the handle is protected from closing. + + + + + Get the NT type name for this handle. + + The NT type name. + + + + Overridden ToString method. + + The handle as a string. + + + + Class which is allocated from the process heap. + + + + + Constructor + + Size of the buffer to allocate. + + + + Constructor + + Initialization data for the buffer. + + + + Constructor + + The length of data to allocate. + The total length to reflect in the Length property. + + + + Constructor + + Size of the buffer. + An existing pointer to an existing HGLOBAL allocated buffer. + Specify whether safe handle owns the buffer. + + + + Get a buffer which represents NULL. + + + + + Overridden ReleaseHandle method. + + True if successfully released the memory. + + + + Detaches the current buffer and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + Detaches the current buffer and allocates a new one. + + Specify a new length for the detached buffer. Must be <= Length. + The detached buffer. + The original buffer will become invalid after this call. + + + + Safe SID buffer. + + This is used to return values from the RTL apis which need to be freed using RtlFreeSid + + + + Safe handle for an in/out structure buffer. + + The type of structure as the base of the memory allocation. + + + + Constructor + + Structure value to initialize the buffer. + + + + Constructor, initializes buffer with a default structure. + + + + + Constructor + + Size of the buffer. + An existing pointer to an existing HGLOBAL allocated buffer. + Specify whether safe handle owns the buffer. + + + + Constructor + + Additional data to add to structure buffer. + If true additional_size is added to structure size, otherwise reflects the total size. + An existing pointer to an existing HGLOBAL allocated buffer. + Specify whether safe handle owns the buffer. + + + + Constructor, initializes buffer with a default structure. + + Additional data to add to structure buffer. + If true additional_size is added to structure size, otherwise reflects the total size. + + + + Constructor + + Structure value to initialize the buffer. + Additional data to add to structure buffer. + If true additional_size is added to structure size, otherwise reflects the total size. + + + + Get a buffer which represents NULL. + + + + + Overridden ReleaseHandle method. + + True if successfully released the memory. + + + + Get or set the result structure in the memory buffer. + + + + + Get a reference to the additional data. + + + + + Detaches the current buffer and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + Detaches the current buffer and allocates a new one. + + Specify a new length for the detached buffer. Must be <= Length. + The detached buffer. + The original buffer will become invalid after this call. + + + + Safe buffer for a list of Token groups. + + + + + Constructor. + + The list of SID and attributes. + The list of allocated SIDs. + + + + NULL safe buffer. + + + + + Create a buffer from a list of groups. + + The group list. + The safe buffer. + + + + Dispose. + + True if disposing. + + + + Safe buffer for token privileges. + + + + + Constructor. + + List of privileges. + + + + NULL safe buffer. + + + + + Security descriptor control flags. + + + + + Security descriptor. + + + + + Discretionary access control list (can be null) + + + + + System access control list (can be null) + + + + + Owner (can be null) + + + + + Group (can be null) + + + + + Get or set Control flags. This is computed based on the current state of the SD. + + + + + Revision value + + + + + The resource manager control flags. + + + + + Get or set an associated NT type for this security descriptor. + + + + + Get or set mandatory label. Returns a medium label if it doesn't exist. + + + + + Get the process trust label. + + + + + Get list of access filters. + + + + + Get list of resource attributes. + + + + + Get the scoped policy ID. + + + + + Get or set the integrity level + + + + + Get or set the server security flag. + + + + + Get or set the DACL untrusted flag. + + + + + Get whether the DACL is present. + + + + + Get count of ACEs in DACL. + + + + + Get whether the SACL is present. + + + + + Get count of ACEs in DACL. + + + + + Indicates if the security descriptor was constructed from a self relative format. + + + + + Indicates if the SD's DACL is canonical. + + + + + Indicates if the SD's SACL is canonical. + + + + + Indicates if the SD's DACL is defaulted. + + + + + Indicates if the SD's SACL is defaulted. + + + + + Indicates if the SD's DACL is auto-inherited. + + + + + Indicates if the SD's SACL is auto-inherited. + + + + + Indicates if the SD came from a container. + + + + + Indicates the SD has audit ACEs present. + + + + + Indicates the SD has a mandatory label ACE present. + + + + + Indicates the SD has a NULL DACL. + + + + + Indicates the SD has a NULL SACL. + + + + + Get the access rights enum type for this SD based on the NT Type property. + + + + + Get the mandatory label. Returns null if it doesn't exist. + + True to include InheritOnly ACEs in the search. + The valid mandatory ACE for this security descriptor. Or null if it doesn't exist. + + + + Get the mandatory label. Returns null if it doesn't exist. + + The valid mandatory ACE for this security descriptor. Or null if it doesn't exist. + + + + Convert security descriptor to a byte array + + The binary security descriptor + + + + Convert security descriptor to SDDL string + + The parts of the security descriptor to return + True to throw on error. + The SDDL string + + + + Convert security descriptor to SDDL string + + The parts of the security descriptor to return + The SDDL string + + + + Convert security descriptor to SDDL string + + True to throw on error. + The SDDL string + + + + Convert security descriptor to SDDL string + + The SDDL string + + + + Converts the security to a base64 string. + + True to insert line breaks in the base64. + The relative SD as a base64 string. + + + + Converts the security to a base64 string. + + The relative SD as a base64 string. + + + + Convert security descriptor to a safe buffer. + + True to return an absolute security descriptor, false for self-relative. + True to throw on error. + A safe buffer for the security descriptor. + + + + Convert security descriptor to a safe buffer. + + True to return an absolute security descriptor, false for self-relative. + A safe buffer for the security descriptor. + + + + Convert security descriptor to a safe buffer. + + A safe buffer for the security descriptor. + This returns a self-relative security descriptor. + + + + Add an ACE to the DACL, creating the DACL if needed. + + The ACE to add to the DACL. + + + + Add an ACE to the SACL, creating the SACL if needed. + + The ACE to add to the SACL. + + + + Add an access allowed ACE to the DACL + + The access mask + The ACE flags + The SID in SDDL form + + + + Add an access allowed ACE to the DACL + + The access mask + The SID in SDDL form + + + + Add an access allowed ACE to the DACL + + The access mask + The ACE flags + The SID + + + + Add an access allowed ACE to the DACL + + The access mask + The SID + + + + Add an access denied ACE to the DACL + + The access mask + The ACE flags + The SID in SDDL form + + + + Add an access denied ACE to the DACL + + The access mask + The SID in SDDL form + + + + Add an access denied ACE to the DACL + + The access mask + The SID + + + + Add an access denied ACE to the DACL + + The access mask + The ACE flags + The SID + + + + Add an audit success ACE to the SACL + + The access mask + The SID in SDDL form + + + + Add an audit success ACE to the SACL + + The access mask + The SID + + + + Add an access denied ACE to the DACL + + The access mask + The SID in SDDL form + + + + Add an audit fail ACE to the SACL + + The access mask + The SID + + + + Add mandatory integrity label to SACL + + The integrity level + + + + Add mandatory integrity label to SACL + + The integrity level + The mandatory label policy + + + + Add mandatory integrity label to SACL + + The integrity level + The ACE flags. + The mandatory label policy + + + + Add mandatory integrity label to SACL + + The integrity label SID + The ACE flags. + The mandatory label policy + + + + Removes the mandatory label if it exists. + + + + + Map all generic access in this security descriptor to the default type specified by NtType. + + + + + Map all generic access in this security descriptor to a specific type. + + The type to get the generic mapping from. + + + + Map all generic access in this security descriptor to a specific type. + + The generic mapping. + + + + Unmap all generic access in this security descriptor to the default type specified by NtType. + + + + + Unmap all generic access in this security descriptor to a specific type. + + The type to get the generic mapping from. + + + + Unap all generic access in this security descriptor to a specific type. + + The generic mapping. + + + + Modifies a security descriptor from a new descriptor. + + The security descriptor to update with. + The parts of the security descriptor to update. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + True to throw on error. + The NT status code. + + + + Modifies a security descriptor from a new descriptor. + + The security descriptor to update with. + The parts of the security descriptor to update. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + + + + Converts the SD to an Auto-Inherit security descriptor. + + The parent security descriptor. + Optional object type GUID. + True if a directory. + Generic mapping for the object. + True to throw on error. + The NT status code. + + + + Converts the SD to an Auto-Inherit security descriptor. + + The parent security descriptor. + Optional object type GUID. + True if a directory. + Generic mapping for the object. + + + + Canonicalize the DACL if it exists. + + + + + Canonicalize the SACL if it exists. + + + + + Standardize security descriptor according to Active Directory rules. + + + + + Clone the security descriptor. + + The cloned security descriptor. + + + + Overridden ToString method. + + The security descriptor as an SDDL string. + + + + Constructor. + + Native pointer to security descriptor. + + + + Constructor. + + The process containing the security descriptor. + Native pointer to security descriptor. + + + + Constructor + + + + + Constructor. + + The NT type for the security descriptor. + + + + Constructor + + Binary form of security descriptor + Optional NT type for security descriptor. + + + + Constructor + + Binary form of security descriptor + + + + Constructor from a token default DACL and ownership values. + + The token to use for its default DACL. + + + + Constructor + + Base object for security descriptor + Token for determining user rights + True if a directory security descriptor + + + + Constructor from an SDDL string + + The SDDL string + Thrown if invalid SDDL + + + + Constructor from an SDDL string + + The SDDL string + Optional NT type for security descriptor. + Thrown if invalid SDDL + + + + Parse a security descriptor. + + Native pointer to security descriptor. + The NT type for the security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + Native pointer to security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + Safe buffer to security descriptor. + The NT type for the security descriptor. + True if the security descriptor is from a container. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + Safe buffer to security descriptor. + The NT type for the security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + Safe buffer to security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + Binary form of security descriptor + The NT type for the security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + Binary form of security descriptor + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + The SDDL form of the security descriptor. + The NT type for the security descriptor. + True if the security descriptor is from a container. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + The SDDL form of the security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor from a base64 string + + The base64 string. + The NT type for the security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor from a base64 string + + The base64 string. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor from a base64 string + + The base64 string. + The parsed Security Descriptor. + + + + Create a new security descriptor from a parent. + + The parent security descriptor. Can be null. + The creator security descriptor. + Optional list of object type GUIDs. + True if the objec to assign is a directory. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + True to throw on error. + The new security descriptor. + + + + Create a new security descriptor from a parent. + + The parent security descriptor. Can be null. + The creator security descriptor. + Optional list of object type GUIDs. + True if the objec to assign is a directory. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + The new security descriptor. + + + + Create a new security descriptor from a parent. + + The parent security descriptor. Can be null. + The creator security descriptor. + True if the objec to assign is a directory. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + True to throw on error. + The new security descriptor. + + + + Create a new security descriptor from a parent. + + The parent security descriptor. Can be null. + The creator security descriptor. + True if the objec to assign is a directory. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + The new security descriptor. + + + + Create a new security descriptor from a parent. + + The parent security descriptor. Can be null. + The creator security descriptor. + True if the objec to assign is a directory. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + True to throw on error. + The new security descriptor. + + + + Create a new security descriptor from a parent. + + The parent security descriptor. Can be null. + The creator security descriptor. + True if the objec to assign is a directory. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + The new security descriptor. + + + + A security descriptor SID which maintains defaulted state. + + + + + The SID. + + + + + Indicates whether the SID was defaulted or not. + + + + + Constructor from existing SID. + + The SID. + Whether the SID was defaulted or not. + + + + Convert to a string. + + The string form of the SID + + + + Clone the security descriptor SID. + + The cloned SID. + + + + The type of the security attribute name. + + + + + Class to represent an attribute name operand. + + + + + The type of attribute. + + + + + The name of the attribute. + + + + + Constructor. + + The type of the attribute. + The name of the attribute. + + + + Overridden ToString method. + + The object as a string. + + + + Class to represent a composite conditional operand. + + + + + List of operands. + + + + + Constructor. + + + + + Overridden ToString method. + + The object as a string. + + + + Class to represent a conditional expression. + + + + + Serialize the expression to a byte array. + + The expression as a byte array. + + + + Overridden ToString method. + + The object as a string. + + + + Parse a binary conditional expression. + + The data to parse. + True to throw on error. + The parsed conditional expression. + + + + Parse a binary conditional expression. + + The data to parse. + The parsed conditional expression. + + + + Parse an SDDL conditional expression. + + The SDDL expression to parse. + True to throw on error. + The parsed conditional expression. + + + + Parse an SDDL conditional expression. + + The SDDL expression to parse. + The parsed conditional expression. + + + + Get list of the conditional operands. + + + + + Size of conditional integer operand. + + + + + Sign of conditional integer operand. + + + + + Base of conditional integer operand. + + + + + Class to represent a conditional integer operand. + + + + + Size of the integer. + + + + + Value of the integer. + + + + + Sign of the integer. + + + + + Base of the integer. + + + + + Constructor. + + + + + Overridden ToString method. + + The object as a string. + + + + Class to represent an octet string conditional operand. + + + + + The value of the operand. + + + + + Constructor. + + The value of the operand. + + + + Overridden ToString method. + + The object as a string. + + + + Abstract class to represent a conditional expression operand. + + + + + Conditional operator type. + + + + + Class to represent a conditional operator operand. + + + + + The type of operator. + + + + + Constructor. + + The type of operator. + + + + Overridden ToString method. + + The object as a string. + + + + Class to represent a SID conditional operand. + + + + + The SID value. + + + + + Constructor. + + The SID value. + + + + Overridden ToString method. + + The object as a string. + + + + Class to represent a string conditional operand. + + + + + The string value. + + + + + Constructor. + + The string value. + + + + Overridden ToString method. + + The object as a string. + + + + Interface for an NT object to query and set a security descriptor. + + + + + Get the name of the object. + + + + + Get the NtType for this object. + + The NtType for the object. + + + + Get the object's security descriptor. + + + + + Get whether the object is a container. + + + + + Check if access is granted to a set of rights + + The access rights to check + True if all the access rights are granted + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + The NT status code. + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Class representing a Central Access Policy. + + + + + The CAP SID. + + + + + CAP Flags. + + + + + Name of the CAP. + + + + + Description of the CAP. + + + + + Change ID. Normally a date time when changed. + + + + + The list of rules associated with this policy. + + + + + Parse the policy from the registry. + + The base key for the registry policy. + True to throw on error. + The list of Central Access Policies. + + + + Parse the policy from the registry. + + True to throw on error. + The list of Central Access Policies. + + + + Parse the policy from the registry. + + The list of Central Access Policies. + + + + Parse the policy from the Local Security Authority. + + True to throw on error. + The list of Central Access Policies. + + + + Parse the policy from the Local Security Authority. + + The list of Central Access Policies. + + + + Class representing a Central Access Rule. + + + + + CAP Rule Flags. + + + + + Name of the CAP Rule. + + + + + Description of the CAP Rule. + + + + + Change ID. Normally a date time when changed. + + + + + Conditional Expression to determine who to applie the rule to. + + + + + The CAP Rule security descriptor. + + + + + The CAP Rule staged security descriptor. + + + + + Class to represent a Security Identifier. + + + + + Maximum size of a SID buffer. + + + + + The SIDs authority. + + + + + List of the SIDs sub authorities. + + + + + Get the account name of the SID or the SDDL form if no corresponding name. + + + + + Constructor for authority and sub authorities. + + The identifier authority. + The sub authorities. + + + + Constructor for authority and sub authorities. + + The identifier authority. + The sub authorities. + + + + Constructor from an unmanged buffer. + + A pointer to a buffer containing a valid SID. + Thrown if the buffer is not valid. + + + + Constructor from an unmanged buffer. + + A safe buffer containing a valid SID. + Thrown if the buffer is not valid. + + + + Constructor from a safe SID handle. + + A safe SID handle containing a valid SID. + Thrown if the buffer is not valid. + + + + Constructor from an manged buffer. + + A buffer containing a valid SID. + Thrown if the buffer is not valid. + + + + Constructor from existing Sid. + + The existing Sid. + + + + Constructor from an SDDL string. + + The SID in SDDL format. + + new Sid("S-1-0-0"); + new Sid("WD"); + + + + + + Constructor from a SID name. + + The SID name. + + + + Construct a SID from a binary reader. + + The binary reader. + + + + Convert the SID to a safe buffer. + + The safe buffer containing the SID. + + + + Convert to a managed byte array. + + The managed byte array. + + + + Compares two sids to see if their prefixes are the same. The sids must have the same number of subauthorities. + + The sid to compare against + True if the sids share a prefix. + + + + Compare two Sids. + + The other Sid to compare. + True if the Sids are equal. + + + + Equality operator. + + Sid 1 + Sid 2 + True if the Sids are equal. + + + + Inequality operator. + + Sid 1 + Sid 2 + True if the Sids are not equal. + + + + Get hash code. + + The hash code. + + + + Convert to an SDDL format string. + + The SDDL format string (e.g. S-1-1-0) + + + + Does this SID dominate another. + + The other SID. + True to throw on error. + True if the sid dominates. + + + + Does this SID dominate another. + + The other SID. + True if the sid dominates. + + + + Does this SID dominate another for trust. + + The other SID. + True to throw on error. + True if the sid dominates. + + + + Does this SID dominate another for trust. + + The other SID. + True if the sid dominates. + + + + Checks if the SID starts with the specified SID. + + The specified SID to check against. + True if the current SID starts with the specified SID. + + + + Create a SID relative to this one. + + The list of RIDs. + The relative SID. + + + + Create a SID sibling to this SID. + + The RIDs to replace the final RID with. + The sibling SID. + This replaces the final RID with one or more addditional RIDs. + + + + Get the SID name for this SID. + + True to bypass the SID name cache. + The SID name. + + + + Get the SID name for this SID. + + The SID name. + + + + Convert an SDDL SID string to a Sid + + The SDDL SID string + True to throw on error. + The converted Sid + Thrown if cannot convert from a SDDL string. + + + + Convert an SDDL SID string to a Sid + + The SDDL SID string + The converted Sid + Thrown if cannot convert from a SDDL string. + + + + Parse a byte array. + + The byte array to parse. + True to throw on error. + The parsed SID. + + + + Parse a byte array. + + The pointer to parse. + True to throw on error. + The parsed SID. + + + + Predefined security authorities + + + + + Represents an identifier authority for a SID. + + + + + Get a reference to the identifier authority. This can be used to modify the value + + + + + Constructor. + + + + + Construct from an existing authority array. + + The authority, must be 6 bytes in length. + Thrown if authority is not the correct length. + + + + Constructor from a simple predefined authority. + + The predefined authority. + + + + Construct from an Int64. + + The authority as an Int64. + + + + Compares authority to another. + + The other authority to compare against. + True if authority is equal. + + + + Get hash code. + + The authority hash code. + + + + Determines if this is a specific security authority. + + The security authority. + True if the security authority. + + + + Convert authority to a 64 bit integer. + + The authority as a 64 bit integer. + + + + Overridden ToString method. + + The security authority as a string. + + + + Source for a SID name. + + + + + SDDL string. + + + + + LSASS lookup. + + + + + Named capability. + + + + + Package name SID. + + + + + From a process trust level. + + + + + Well known SID. + + + + + Scoped policy SID. + + + + + Manually added name. + + + + + Represents a name for a SID. + + + + + The qualified name of the SID. Either the combination of + Domain and Name or the SDDL SID. + + + + + The domain name, if present. + + + + + The user name. + + + + + The source of name. + + + + + The use of the name. + + + + + The SDDL format of the SID. + + + + + Used for caching. Indicates the lookup name was denied rather than not available. + + + + + Disposable class to scope an impersonation context. + + + + + Revert impersonation back to the current user. + + + + + Class to represent the state of a token privilege + + + + + Privilege attributes + + + + + Privilege LUID + + + + + Get the token privilege value enum. + + + + + Get the name of the privilege + + The privilege name + + + + Get the display name/description of the privilege + + The display name + + + + Get whether privilege is enabled + + + + + Get whether privilege is enabled + + + + + Constructor + + The privilege LUID + The privilege attributes + + + + Constructor + + The privilege value + The privilege attributes + + + + Constructor + + The privilege name. + The privilege attributes + + + + Constructor + + The privilege name. + + + + Conver to a string + + The privilege name. + + + + Standard UNICODE_STRING class + + + + + Standard UNICODE_STRING class based on a SecureString class. + + + + + Structure to use when passing in a unicode string as a sub-structure with a seure string. + + + + + Standard ANSI_STRING class + + + + + This class is used when the UNICODE_STRING is an output parameter. + The allocatation of the buffer is handled elsewhere. + + + + + Convert unicode string to an array. + + The unicode string data as an array. + + + + This class is used when the UNICODE_STRING is an output parameter. + The allocatation of the buffer is handled elsewhere. + + + + + Structure to use when passing in a unicode string as a sub-structure. + + + + + This class is used when the UNICODE_STRING needs to be preallocated + and then returned back from a caller. + + + + + Implements a UnicodeString which contains raw bytes. + + + + + Constructor. + + The bytes for the name. + + + + Get a null safe buffer. + + + + + Class to represent a user group + + + + + The SID of the user group + + + + + The attributes of the user group + + + + + Get whether the user group is enabled + + + + + Get whether the user group is mandatory + + + + + Get whether the user group is used for deny only + + + + + Get the resolved name of the SID. + + + + + Constructor + + The SID + The attributes + + + + Constructor from a SID. + + The SID + + + + Constructor from a SID or account name. + + The SID or account name. + + + + Convert to a string + + The account name if available or the SDDL SID + + + + Basic utilities for ASN1 support. + + + + + Format an array of ASN.1 DER to a string. + + The ASN.1 data in DER format. + Initial identation depth. + The formatted DER data. + + + + Format an file containing of ASN.1 DER to a string. + + The path to the file containing ASN.1 data in DER format. + Initial identation depth. + The formatted DER data. + + + + Class to do basic ASN1 DER generation. + + + + + Constructor. + + The stream to write the DER data to. + + + + Constructor. + + + + + Write an object ID. + + The object ID to write. + + + + Write raw bytes to the stream. + + The bytes to write. + + + + Write an octet-string to the stream. + + The octet string. + + + + Write a NULL value. + + + + + Write a 32-bit integer. + + The integer value. + + + + Write a 64-bit integer. + + The integer value. + + + + Write an arbitrary integer. + + The integer value. + + + + Write a sequence based on the contents of another DER builder. + + The builder for the contents. + + + + Write a sequence based on the contents of another DER builder. + + The build function for the contents. + + + + Write a sequence based on the contents of another DER builder. + + Write a sequence of fixed values. + The build function for the contents. + + + + Create a sequence builder. + + The created builder. + You should call Close or dispose on the created builder to write the tag. + + + + Write an application specific tag with contents from the builder. + + The ID of the application specific tag. + The builder for the contents. + + + + Write an application specific tag with contents from the builder. + + The ID of the application specific tag. + The build function for the contents. + + + + Create an application specific builder. + + The ID of the application specific tag. + The created builder. + You should call Close or dispose on the created builder to write the tag. + + + + Write a context specific tag with specified contents. + + The ID of the context specific tag. + The contents of the context specific value. + + + + Write a context specific tag with contents from the builder. + + The ID of the context specific tag. + The builder for the contents. + + + + Write an application specific tag with contents from the builder. + + The ID of the context specific tag. + The build function for the contents. + + + + Create a context specific builder. + + The ID of the context specific tag. + The created builder. + You should call Close or dispose on the created builder to write the tag. + + + + Write a general encoded string. + + The string + The encoding to covert to. + + + + Write a general encoded string using ASCII encoding. + + The string + + + + Write a UTF8 string. + + The UTF8 string + + + + Write an IA5 string. + + The IA5 string + + + + Write a generalized time. + + The time to write. + + + + Convert builder to a byte array. + + The DER encoded data. + + + + A DER builder for a sub-structure.. + + You should call Close or dispose the builder to write the sub-structure. + + + + Close the builder and write its contents to the parent builder. + + + + + Static class for DER builder utility functions. + + + + + A basic ASN.1 DER parser to process Kerberos and SPNEGO Tokens. + + + + + Class containing known OID values. + + + + + Class to implement a scoped file lock. + + + + + Lock part of a file. + + The file to lock. + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + True to throw on error. + The NT status code. + + + + Lock part of a file. + + The file to lock. + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + The NT status code. + + + + Unlock the file. + + + + + IMemoryReader implementation for a process. + + + + + Class to compress and decompress buffers using RtlCompressionBuffer. + + + + + Decompress a buffer. + + The compression format used. + The compressed buffer. + The expected uncompressed length. + True to throw on error. + The uncompressed buffer. + + + + Decompress a buffer. + + The compression format used. + The compressed buffer. + The expected uncompressed length. + The uncompressed buffer. + + + + IMemoryReader implementation for a process. + + + + + Class which calls a delegate on dispose. + + + + + Constructor. + + The delegate to call on dispose. + + + + Dispose and call the action. + + + + + A container which can detach an innner reference. + + + + + + Get the contained value. + + + + + Detach the object so the original isn't disposed. + + Detached object. + + + + Miscellaneous utilities. + + + + + Convert a disposable object to a detachable object. + + The disposable object type. + The disposable object. + The disposable container. + + + + Utilities for reflection. + + + + + Get the SDK name for a type, if available. + + The type to get the name for. + The SDK name. Returns the name of the type if not available. + + + + Get the SDK name for an enum, if available. + + The enum to get the name for. + The SDK name. If the enum is a flags enum then will return the names joined with commas. + + + + Get the SDK name an object. + + The object to get the name from. If this isn't an Enum or Type then the Type of the object is used. + The SDK name. + + + + Class to create a view. This never owns the handle. + + + + + Detaches the current handle and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + A buffer which contains an array of GUID pointers. + + + + + The count of GUIDs. + + + + + Constructor. + + The list of GUIDs. + + + + Get NULL safe buffer. + + + + + Basic implementation of ARC4. + + + + + Encrypt, or decrypt an ARC4 stream. + + The data to encrypt/decrypt. + Offset into the data to decrypt. + Length of data to decrypt. + The key to decrypt. + The resulting bytes. + + + + Encrypt, or decrypt an ARC4 stream. + + The data to encrypt/decrypt. + The key to decrypt. + The resulting bytes. + + + + Basic implementation of MD4. + + + This could have called out to the CNG APIs or dug into the + internals of the existing .NET crypto APIs but as MD4 is so + simple and it doesn't need to be secure (seriously don't use + this). This uses the reference implementation from RFC1320. + + + + + Calculate the MD4 hash of an input. + + The input bytes. + The MD4 hash. + + + + Calculate the MD4 hash of a string. + + The input string. + Encoding for the string. + The MD4 hash. + + + + Calculate the MD4 hash of a unicode string. + + The input string. + The MD4 hash. + + + + Class to perform the n-fold operation for Kerberos key derivation. + + + + + Perform an n-fold operation. + + The input data as a string. + The output length in bytes. + The computed n-folded byte array. + + + + Perform an n-fold operation. + + The input data. + The output length in bytes. + The computed n-folded byte array. + + + + A tree of Object Types. + + + + + Constructor. + + Entries to setup in the tree. + + + + Contructor. + + The object type GUID. + The name of the root object. + + + + Contructor. + + The object type GUID. + + + + Contructor. + + The object type GUID as a string. + + + + List of child nodes in the tree. + + + + + The parent of this tree. + + + + + The Object Type GUID. + + + + + Optional access mask for use in access checking. + + + + + Optional label for this tree entry. + + + + + Indicates the number of total entries this tree contains. + + + + + Add a new object type to the tree. + + The object type. + The name of the node. + The added tree object. + + + + Add a new object type to the tree. + + The object type. + The added tree object. + + + + Add an existing node to the tree. + + The node to add. + + + + Add an existing list of nodes to the tree. + + The nodes to add. + + + + Removes all object types from the tree. + + The object type. + The removed tree object. + + + + Removes all object types from the tree. + + The object type. + The removed tree object. + + + + Remove the current tree entry from the parent. + + + + + Convert the tree to an array. + + The array of ObjectTypeEntry objects. + + + + Clone the object type tree. + + The cloned tree. + + + + Set the access mask of this tree node and all children. + + The mask to set. + + + + Remove access mask from this tree node and children and propgate that up the tree. + + The mask to remove. + + + + Find an object type tree entry based on a GUID. + + The object type GUID. + The first entry found, null if doesn't exist. + + + + Split the tree up to reduce the maximum number of entries. + + This will try and keep whole branches together if at all possible, + but might split them up. This could result in incorrect access checking. + The maximum number of entries per tree. + One or more split trees. + + + + Overridden ToString method. + + The object formatted. + + + + Encoding object which converts 1 to 1 with bytes. + + + + + Default instance of the encoding. + + + + + Get the encoding name. + + + + + Get byte count for characters. + + The character array. + Index into the array. + Number of characters in the array to use. + The number of bytes this character array requires. + + + + Get bytes for characters. + + The character array. + Index into the array. + Number of characters in the array to use. + The index into the byte array. + The byte array to copy into. + The number of bytes generated. + + + + Get the character count for bytes. + + The byte array. + Index into the array. + Number of bytes in the array to use. + The number of characters this byte array requires. + + + + Get byte count for characters. + + The character array. + Index into the array. + Number of bytes in the array to use. + The index into the byte array. + The byte array to copy into. + The number of characters generated. + + + + Get maximum bytes for a number of characters. + + + + + + + Get maximum characters for a number of bytes. + + + + + + + Indicates if the encoding is a single byte. + + + + + A single extract string instance. + + + + + The string value. + + + + + The offset in the buffer. + + + + + True if the string was 16-bit Unicode. + + + + + Source of the string. Empty if was from a byte array. + + + + + Overridden ToString method. + + The value of the extracted string. + + + + Specify types of strings to extract. + + + + + Extract ASCII strings. + + + + + Extract Unicode strings. + + + + + Class to build a hex dump from a stream of bytes. + + + + + Append an array of bytes to the hex dump. + + The byte array. + The length of the bytes to append from the array. + The start offset in the bytes to append. + + + + Append an array of bytes to the hex dump. + + The byte array. + + + + Append a file or part of a file. + + The path to the file. + The length of the file to append. If 0 will append all remaining data. + The start offset in the file to append. + + + + Append a file or part of a file. + + The path to the file. + + + + Complete the hex dump string. + + + + + Finish builder and convert to a string. + + The hex dump. + + + + Constructor. + + Print a header. + Print the address. + Print the ASCII text. + Hide repeating lines. + Offset for address printing. + + + + Constructor. + + The safe buffer to print. + The length to display. + The offset into the buffer to display. + Print a header. + Print the address. + Print the ASCII text. + Hide repeating lines. + + + + Constructor. + + The safe buffer to print. + Print a header. + Print the address. + Print the ASCII text. + Hide repeating lines. + + + + Constructor. + + The stream to print. + Print a header. + Print the address. + Print the ASCII text. + Hide repeating lines. + Offset for address printing. + + + + Constructor. + + + + + Parse a hex dump into a byte array. + + The hex string. Can contain non-hex characters. + The parsed string as a byte array. + This won't necessarily parse correctly an arbitary hex dump, but it will if you just use the hex of the bytes. + + + + Parse a hex string into a byte array. + + The hex string. Can contain non-hex characters. + The parsed string as a byte array. + True if the parse was successful. + This won't necessarily parse correctly an arbitary hex dump, but it will if you just use the hex of the bytes. + + + + Utility class to extract strings from a byte value. + + + + + Extracts strings from a binary buffer. + + The data to search. + The length of the data to search. + The minimum string length. + The offset into the data to search. + The type of strings to search for. + The list of extracted strings. + + + + Extracts strings from a binary buffer. + + The data to search. + The minimum string length. + The type of strings to search for. + The list of extracted strings. + + + + Extracts strings from a stream. + + The stream to extract strings from. + The minimum string length. + The type of strings to search for. + The list of extracted strings. + + + + Extracts strings from a file. + + The file to search. + The minimum string length. + The type of strings to search for. + The list of extracted strings. + + + + Extracts strings from a safe buffer. + + Safe buffer to extract the value from. + The minimum string length. + The type of strings to search for. + The list of extracted strings. + + + + Extracts strings from a safe buffer. + + Safe buffer to extract the value from. + The minimum string length. + The type of strings to search for. + The length of the data to search. + The offset into the data to search. + The list of extracted strings. + + + + Class to call NT functions for manipulating strings. + + + + + Upper case a character according to the internal NTDLL string routines. + + The character to upper case. + The upper case character. + + + + Upper case a string according to the internal NTDLL string routines. + + The string to upper case. + True to throw on error. + The upper case string. + + + + Upper case a string according to the internal NTDLL string routines. + + The string to upper case. + The upper case string. + + + + Lower case a character according to the internal NTDLL string routines. + + The character to lower case. + The lower case character. + + + + Lower case a string according to the internal NTDLL string routines. + + The string to lower case. + True to throw on error. + The lower case string. + + + + Lower case a string according to the internal NTDLL string routines. + + The string to lower case. + The lower case string. + + + + Builder for a claim security attribute. + + + + + Name of the security attribute. + + + + + Attribute flags. + + + + + The value type. + + + + + The current list of values. + + + + + Convert build to a claim attribute. + + + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + An existing attribute to clone. + The builder instance. + + + + A class which represents an AppContainer profile. + + + + + Create a new AppContainerProfile. + + The name of the AppContainer. + A display name. + An optional description. + An optional list of capability SIDs. + True to throw on error. + The created AppContainer profile. + If the profile already exists then it'll be opened instead. + + + + Create a new AppContainerProfile. + + The name of the AppContainer. + A display name. + An optional description. + An optional list of capability SIDs. + The created AppContainer profile. + If the profile already exists then it'll be opened instead. + + + + Create a temporary AppContainer profile. + + List of capabilities for the AppContainer profile. + The created AppContainer profile. + The profile will be marked to DeleteOnClose. In order to not leak the profile you + should wait till the process has exited and dispose this profile. + + + + Create a temporary AppContainer profile. + + The created AppContainer profile. + The profile will be marked to DeleteOnClose. In order to not leak the profile you + should wait till the process has exited and dispose this profile. + + + + Opens an AppContainerProfile. + + The name of the AppContainer. + True to throw no error. + The opened AppContainer profile. + This method doesn't check the profile exists. + + + + Opens an AppContainerProfile. + + The name of the AppContainer. + The opened AppContainer profile. + This method doesn't check the profile exists. + + + + Opens an AppContainerProfile and checks it exists. + + The name of the AppContainer. + True to throw no error. + The opened AppContainer profile. + This checks for the existence of the profile and also populates the additional information. + + + + Opens an AppContainerProfile and checks it exists. + + The name of the AppContainer. + The opened AppContainer profile. + This checks for the existence of the profile and also populates the additional information. + + + + Delete an existing profile. + + The AppContainer name. + True to throw on error. + The HRESULT from the delete operation. + + + + Delete an existing profile. + + The AppContainer name. + + + + Enumerate all AppContainer profiles. + + True to throw on error. + The list of appcontainer profiles. + + + + Enumerate all AppContainer profiles. + + The list of appcontainer profiles. + + + + Delete an existing profile. + + True to throw on error. + The HRESULT from the delete operation. + + + + Delete an existing profile. + + + + + Dispose of the AppContainer profile. If DeleteOnClose is set then the profile will be deleted. + + + + + Close an AppContainer profile. If DeleteOnClose is set then the profile will be deleted. + + + + + Open the AppContainer key. + + The desired access for the key. + True to throw on error. + The opened key. + + + + The AppContainer name. + + + + + The package SID + + + + + Path to the AppContainer profile directory. + + + + + Path to the AppContainer key. + + + + + Set to true to delete the profile when closed. + + + + + Get list of capabilities assigned to this AppContainer profile. + + + + + The display name for the AppContainer profile. + + + + + The description for the AppContainer profile. + + + + + Utilities for AppModel applications. + + + + + Activate an application from its Application Model ID. + + The app model ID. + Arguments for the activation. + True to throw on error. + The PID of the process. + + + + Activate an application from its Application Model ID. + + The app model ID. + Arguments for the activation. + The PID of the process. + + + + Get the list of package SIDs with a loopback exception. + + True to throw on error. + The list of package SIDs with a loopback exception. + + + + Get the list of package SIDs with a loopback exception. + + The list of package SIDs with a loopback exception. + + + + Add a loopback exception to the list. + + The package SID to add. + True to throw on error. + The NT status code. + + + + Add a loopback exception to the list. + + The package SID to add. + + + + Remove a loopback exception from the list. + + The package SID to remove. + True to throw on error. + The NT status code. + + + + Remove a loopback exception to the list. + + The package SID to remove. + + + + State of the console session. + + + + + User logged on to WinStation + + + + + WinStation connected to client + + + + + In the process of connecting to client + + + + + Shadowing another WinStation + + + + + WinStation logged on without client + + + + + Waiting for client to connect + + + + + WinStation is listening for connection + + + + + WinStation is being reset + + + + + WinStation is down due to error + + + + + WinStation in initialization + + + + + Class to represent a console session. + + + + + The session ID. + + + + + The Session Name. + + + + + The Username if any user authenticated. + + + + + The Domain Name for the User. + + + + + The Console Session State. + + + + + The hostname for the client. + + + + + The Farm name for Virtual Machine Farm. + + + + + Get the FQ User Name. + + + + + Type information for an array. + + + + + Get array element type. + + + + + Get number of array elements. + + + + + Type information for a base type. + + + + + Symbol information for a data value. + + + + + Address of the symbol. + + + + + Enumerated type value. + + + + + Name of the value. + + + + + The value as an int64. + + + + + Symbol information for an enumerated type. + + + + + Get the values for the enumerated type. + + + + + Class for a function parameter. + + + + + Name of the parameter. + + + + + Type of the parameter. + + + + + Type information for a function. + + + + + Type for the return type. + + + + + List of function parameters. + + + + + Interface for symbol type resolver. + + + + + Query types in a module. + + The base address of the module. + The list of types. + + + + Query names of types in a module. + + The base address of the module. + The list of type names. + + + + Get a type by name. + + The base address of the module containing the type. + The name of the type. + + + + + Query types by name + + The base address of the module containing the type. + A mask string for the type name. e.g. mod!ABC* + The list of types. + + + + Get the address of a symbol. + + The name of the symbol, should include the module name, e.g. modulename!MySymbol. + The symbol type. + + + + Get the address of a symbol. + + The address of the symbol. + The symbol type. + + + + Type information for a pointer value. + + + + + Get the type this pointer references. + + + + + Indicates this pointer is a reference. + + + + + The name of the symbol. + + + + + Class to represent a symbol information. + + + + + The name of the symbol. + + + + + Size of the symbol. + + + + + Get the loaded module for the symbol. + + + + + Type of the symbol. + + + + + Internal type index. + + + + + Overridden ToString method. + + Returns the symbol name. + + + + Enumeration for symbol type information. + + + + + None. + + + + + UDT. + + + + + Enumerated type. + + + + + A base type. + + + + + A function type. + + + + + A pointer type. + + + + + Undefined. + + + + + Flags for the symbol resolver. + + + + + No flags. + + + + + Trace symbol file loading + + + + + Disable resolving export symbols if no PDB can be found. + + + + + Enable a symbol server fallback. If the copy of dbghelp doesn't have a symsrv.dll + then download from a public symbol URL to a local cache directory during symbol + resolving. + + + + + Symbol information for a type. + + + + + Represents a member of a UDT. + + + + + The type of the member. + + + + + The name of the member. + + + + + The offset into the UDT. + + + + + The size of the member. + + + + + Represents a bit field member of a UDT. + + + + + If a bit field then this is the bit start position. + + + + + If a bit field this is the bit length. + + + + + Symbol information for an enumerated type. + + + + + The members of the UDT. + + + + + Indicates the UDT is a union. + + + + + Class to capture Win32 debug output. + + + + + Create an instance of the Win32 debug console. + + The session ID for the console. Set to 0 to capture global output. + True to throw on error. + The Win32 debug console. + + + + Create an instance of the Win32 debug console. + + The session ID for the console. Set to 0 to capture global output. + The Win32 debug console. + + + + Create an instance of the Win32 debug console for current session. + + True to throw on error. + The Win32 debug console. + + + + Create an instance of the Win32 debug console for current session. + + The Win32 debug console. + + + + Create an instance of the Win32 debug console for the global session. + + True to throw on error. + The Win32 debug console. + + + + Create an instance of the Win32 debug console for the global session. + + The Win32 debug console. + + + + Read a debug string from for the console asynchronously. + + The timeout in milliseconds. + Cancellation token. + The Win32 debug string. If timed out then Output property is null. + + + + Read a debug string from for the console asynchronously. + + The timeout in milliseconds. + The Win32 debug string. If timed out then Output property is null. + + + + Read a debug string from for the console asynchronously. + + The Win32 debug string. If timed out then Output property is null. + + + + Read a debug string from for the console. + + The timeout in milliseconds. + The Win32 debug string. If timed out then Output property is null. + + + + Read a debug string from for the console. + + The Win32 debug string. If timed out then Output property is null. + + + + Attach the debug console to another session. + + The session ID. + True to throw on error. + The NT status code. + + + + Attach the debug console to another session. + + The session ID. + + + + Dispose debug console. + + + + + Structure for a debug string event. + + + + + The process ID. + + + + + The output string. + + + + + Class to hold known bus type GUIDs. + + + + + Class to represent a device interface. + + + + + The name of the interface class. + + + + + The device interface GUID. + + + + + The list of device interface instances. + + + + + The list of all device interface properties. + + The device interface properties. + + + + Class containing well known device interface class GUIDs. + + + + + Convert interface class GUID to a string. + + + The name of the interface class GUID. + + + + Get the list of known interface GUIDs. + + The list of known interface guids. + + + + Class to represent a device interface instance. + + + + + The instance path to the device. + + + + + The raw device path. + + + + + The device interface class GUID. + + + + + The device instance ID for the device node. + + + + + Overridden ToString method. + + The Win32Path. + + + + The list of all device interface instance properties. + + The device interface instance properties. + + + + Device property types. + + + + + Class representing a device node. + + + + + The name of the device instance. + + + + + The device setup class GUID. + + + + + The device instance ID. + + + + + Get the device PDO name. + + + + + Get the device INF name. + + + + + Get the device INF path. + + + + + Get the device stack. + + + + + The the device stack as a list of driver paths. + + + + + Indicates if this is a per-session device. If null then not defined. + + + + + Indicates if this instance is present. + + + + + Indicates the name of the SCM service for the driver. + + + + + Get path to the driver. + + + + + Get driver start type. + + + + + Get the parent device node. + + The parent device node. Returns null if reached the root. + + + + List of upper filters. + + + + + List of lower filters. + + + + + Container ID. + + + + + Type of bus for the device. + + + + + Get if the device is a user-mode device. + + + + + The list of all device properties. + + The device properties. + + + + Get the setup class for this instance. + + Returns the setup class. + Thrown if invalid setup GUID. + + + + Get list of parent nodes. + + The list of parent nodes. + + + + Overridden ToString method. + + + + + + Optional security descriptor for device node. + + + + + Indicates the device node has a security descriptor. + + + + + Device property. + + + + + The name of the property, if known. + + + + + The FMTID Guid. + + + + + The PID. + + + + + The device property type. + + + + + Property data. + + + + + Format the data according to type. + + The formatted data. + + + + ToString method. + + The property as a string. + + + + Class to represent a device setup class. + + + + + The friendly name of the device. + + + + + The name of the device class. + + + + + The device class installer Guid. + + + + + The security descriptor for the device (if available). + + + + + Indicates the device setup class has a security descriptor. + + + + + The device type. + + + + + The device characteristics. + + + + + List of upper filters. + + + + + List of lower filters. + + + + + The list of all device setup properties. + + The device setup properties. + + + + Get device instances. + + Return all devices. + The list of devices instances. + + + + Get device instances. + + The list of devices instances. + + + + Enumerated type for device stack type. + + + + + Unknown type. + + + + + Entry is for the function driver. + + + + + Entry is for the bus driver. + + + + + Entry is for an upper filter. + + + + + Entry is for the lower filter. + + + + + Entry is for a filter. + + + + + Class to represent an entry on the stack. + + + + + Name of the driver. + + + + + Path to the driver. + + + + + Stack entry type. + + + + + Overridden ToString method. + + The name of the driver in the stack. + + + + Class to represent a node in a device tree. + + + + + List of child nodes. + + + + + Indicates if the node has any children. + + + + + Get the parent device node. + + The parent device node. Returns null if reached the root. + + + + Utilities for interacting with Device, Configuration and Setup APIs. + + + + + Get a list of device interfaces from an Interface GUID. + + The interface class GUID for the device. + Optional device ID. + True to get all devices, otherwise just present devices. + List of device interfaces. + + + + Get a list of present device interfaces from an Inteface GUID. + + The interface class GUID for the device. + List of device interfaces. + + + + Enumerate installer class GUIDs. + + The list of installer class GUIDs. + + + + Enumerate interface class GUIDs. + + The list of interface class GUIDs. + + + + Query the security descriptor for a device. + + The installer device class. + True to throw on error. + The security descriptor. + + + + Query the security descriptor for a device. + + The installer device class. + The security descriptor. + + + + Get list of registered device setup classes. + + The list of device setup classes. + + + + Get a device setup class by GUID. + + The class GUID. + The device setup class. + + + + Get list of registered device interfaces. + + True to return all devices. + The list of device interfaces. + + + + Get list of registered device interfaces. + + The list of device interfaces. + + + + Get a device interface class by GUID. + + The class GUID. + True to return all devices. + The device interface class. + + + + Get a device interface class by GUID. + + The class GUID. + The device interface class. + + + + Get list of device nodes. + + Return all devices including ones which aren't present. + The list of device nodes. + + + + Get list of present device nodes. + + The list of device entries. + + + + Get list of device entries. + + Specify the Device Setup Class GUID. + Only return present devices. + The list of device entries. + + + + Get list of present device entries. + + Specify the Device Setup Class GUID. + The list of device entries. + + + + Get the device node from a device ID. + + The instance ID to lookup.. + The device node. + + + + Get device tree. + + The device tree's root node. + + + + Get the node from a device instance ID. + + The instance ID to start from. + The root device node. + + + + Get all device interface instances. + + + + + Get all device interface instances for a given interface class GUID. + + + + + Get an interface instance from the interface instance path. + + The path to the interface symbolic link. e.g. \??\SOME$VALUE. + + + + Interface to indicate the device object has properties. + + + + + The list of all device properties. + + The device properties. + + + + Access rights for Active Directory Services. + + + + + Class to represent a binding to a directory service. + + + + + Crack one or more names on the domain controller. + + Flags for the cracking. + Format of the names. + Desired format of the names. + The list of names to crack. + True to throw on error. + The cracked names. + + + + Crack one or more names on the domain controller. + + Flags for the cracking. + Format of the names. + Desired format of the names. + The list of names to crack. + The cracked names. + + + + Crack a name on the domain controller. + + Flags for the cracking. + Format of the name. + Desired format of the name. + The name to crack. + True to throw on error. + The cracked name. + + + + Crack a name on the domain controller. + + Flags for the cracking. + Format of the name. + Desired format of the name. + The name to crack. + The cracked name. + + + + Get naming contexts for domain. + + True to throw on error. + The naming contexts. + + + + Get naming contexts for domain. + + The naming contexts. + + + + Bind to a directory service. + + The name of the domain controller. Can be null. + The DNS domain name. + True to throw on error. + The directory service binding. + + + + Bind to a directory service. + + The name of the domain controller. Can be null. + The DNS domain name. + The directory service binding. + + + + Bind to the current directory service. + + The directory service binding. + + + + Dispose the binding. + + + + + Class to represent an directory service extended right queries from the current domain. + + + + + The common name of the extended right. + + + + + The distinguished name for the extended right. + + + + + The domain name searched for this extended right. + + + + + The rights GUID for this extended right. + + + + + The list of applies to GUIDs. + + + + + The valid accesses for this extended right. + + + + + Get list of properties if a property set. + + + + + True if this a property set extended right. + + + + + True if this is a validated write extended right. + + + + + True if this is a control extended right. + + + + + Overridden ToString method. + + The name of the extended right. + + + + Convert the extended right to an object type tree. + + The tree of object types. + + + + Convert the extended right to an object type tree. + + The extended right to convert. + The tree of object types. + + + + Flags and settings from the dSHeuristics attribute. + + + + + The fSupFirstLastANR flag. + + + + + The fSupLastFirstANR flag. + + + + + The fDoListObject flag. + + + + + The fLDAPBlockAnonOps flag. + + + + + The fAllowAnonNSPI flag. + + + + + The fDontStandardizeSDs flag. + + + + + The raw value for the dsHeuristics attribute. + + + + + The domain where the value was read. + + + + + Directory services name error. + + + + + Directory services name flags. + + + + + Directory services name format. + + + + + Structure to represent a directory service name. + + + + + Status of the name. + + + + + Domain of the name. + + + + + Name of the name. + + + + + Native methods for directory services. + + + + + Object type level for a directory object. + + + + + Object type. + + + + + Property set type. + + + + + Property type. + + + + + Class to represent an a class which is referenced from another. For example auxiliary or superior classes. + + + + + The name of the class. + + + + + Whether the class is a system class. + + + + + Get the full schema class for this reference. + + The schema class. + + + + Class to represent a directory service schema attribute. + + + + + The attributes syntax. + + + + + The OM syntax. + + + + + The OM object class. + + + + + The name of the attribute syntax type if known. + + + + + The GUID of the containing property set, if it exists. + + + + + Indicates if the attribute is in a property set. + + + + + Class to represent a directory service schema class. + + + + + The subclass schema name. + + + + + List of attributes the class can contain. + + + + + The default security descriptor. + + + + + The default security descriptor in SDDL format. + + + + + The list of auxiliary classes for this class. + + + + + The category of schema class. + + + + + The list of possible superior classes for this class. + + + + + Possible inferiors of the class. + + + + + Structure to represent an attribute for a class. + + + + + The name of the attribute. + + + + + True if the attribute is required. + + + + + True if the attribute can only be modified by system. + + + + + Get the hash code for the attribute. + + The hash code. + + + + Check attributes for equality. + + The other attribute to check. + True if equal. + + + + Overridden ToString method. + + The name of the attribute. + + + + Represents the type of schema class. + + + + + Legacy class. + + + + + Structure class (can be created). + + + + + Abstract class. + + + + + Auxiliary class. + + + + + Base class for a schema class or attribute object. + + + + + The GUID of the schema class. + + + + + The name of the schema class. + + + + + The LDAP display name. + + + + + The object class for the schema class. + + + + + The distinguished name for the schema class. + + + + + The domain name searched for this schema class. + + + + + The admin description for the object. + + + + + Indicates if this schema object is system only. + + + + + Overridden ToString method. + + The name of the schema class. + + + + Convert the schema class to an object type tree. + + The tree of object types. + + + + Convert the extended right to an object type tree. + + The schema class to convert. + The tree of object types. + + + + Class to represent a security principal in the directory. + + + + + Distinguished name of the group. + + + + + The SID of the object. + + + + + Overridden Equals. + + The other object to test. + True if equal. + + + + Overridden GetHashCode. + + The hash code. + + + + User flags. + + + + + Class implementing various utilities for directory services. + + + + + Name for the fake Directory Service NT type. + + + + + Get the generic mapping for directory services. + + The directory services generic mapping. + + + + Get a fake NtType for Directory Services. + + The fake Directory Services NtType + + + + Get the default property set. + + + + + Get the schema class for a GUID. + + Specify the domain to get the schema class for. + The GUID for the schema class. + The schema class, or null if not found. + + + + Get the schema class for a GUID. + + The GUID for the schema class. + The schema class, or null if not found. + + + + Get the schema class for a LDAP name. + + Specify the domain to get the schema class for. + The LDAP name for the schema class. + The schema class, or null if not found. + + + + Get the schema class for a LDAP name. + + The LDAP name for the schema class. + The schema class, or null if not found. + + + + Get the inferior schema class for a LDAP name. + + Specify the domain to get the schema class for. + The LDAP name for the parent schema class. + The schema classes. + + + + Get the inferior schema class for a LDAP name. + + The LDAP name for the schema class. + The schema classes. + + + + Get the auxiliary schema classes for a LDAP name. + + Specify the domain to get the schema class for. + The LDAP name for the parent schema class. + The schema classes. + + + + Get the auxiliary schema classes for a LDAP name. + + The LDAP name for the schema class. + The schema classes. + + + + Get all schema classes. + + Specify the domain to get the schema classes for. + The list of schema classes. + + + + Get all schema classes. + + The list of schema classes. + + + + Get all schema classes in a hierarchy. + + Specify the domain to get the schema classes for. + Specify to include auxiliary classes in the list. + The name of the base schema class. + The list of schema classes. + + + + Get all schema classes in a hierarchy. + + Specify to include auxiliary classes in the list. + The name of the base schema class. + The list of schema classes. + + + + Get the common name of an schema object class. + + Specify the domain to get the schema class for. + The GUID for the schema class. + The common name of the schema class, or null if not found. + + + + Get the common name of an schema object class. + + The GUID for the schema class. + The common name of the schema class, or null if not found. + + + + Get the schema attribute for a GUID. + + Specify the domain to get the schema attribute for. + The GUID for the schema attribute. + The schema attribute, or null if not found. + + + + Get the schema attribute for a GUID. + + The GUID for the schema attribute. + The schema attribute, or null if not found. + + + + Get the schema attribute for a LDAP name. + + Specify the domain to get the schema attribute for. + The LDAP name for the schema attribute. + The schema attribute, or null if not found. + + + + Get the schema attribute for a LDAP name. + + The LDAP name for the schema attribute. + The schema attribute, or null if not found. + + + + Get all schema attributes. + + Specify the domain to get the schema attributes for. + The list of schema attributes. + + + + Get all schema attributes. + + The list of schema attributes. + + + + Get the common name of a schema attribute. + + Specify the domain to get the schema attribute for. + The GUID for the schema attribute. + The common name of the schema attribute, or null if not found. + + + + Get the common name of a schema attribute. + + The GUID for the schema attribute. + The common name of the schema attribute, or null if not found. + + + + Get the extended right name by GUID. + + Specify the domain for the extended right. + The GUID for the extended right. + If true and the right is a property set, expand the name. + The name of the extended right, or null if not found. + + + + Get the extended right name by GUID. + + The GUID for the extended right. + If true and the right is a property set, expand the name. + The name of the extended right, or null if not found. + + + + Get an extended right by GUID. + + Specify the domain to get the extended right for. + The GUID for the extended right. + The extended right, or null if not found. + + + + Get an extended right by GUID. + + The GUID for the extended right. + The extended right, or null if not found. + + + + Get an extended right by common name. + + Specify the domain to get the extended right for. + The common name for the extended right. + The extended right, or null if not found. + + + + Get an extended right by common name. + + The common name for the extended right. + The extended right, or null if not found. + + + + Get a list of all extended rights in the current domain. + + Specify the domain to get the extended rights from. + The list of extended rights. + + + + Get a list of all extended rights in the current domain. + + The list of extended rights. + + + + Get a list of extended rights applied to a schema class. + + Specify the domain to get the extended rights from. + The schema class identifier. + The list of extended rights applies to the schema class. + + + + Get a list of extended rights applied to a schema class in the current domain. + + The schema class identifier. + The list of extended rights applies to the schema class. + + + + Create an object type entry for an access check. + + The object type level. + The object type GUID. + An optional name. + The object type entry. + + + + Get the object SID from a directory object. + + The directory entry. + The object SID. Returns null if no object SID exists. + + + + Get the object SID from a directory object. + + The domain name for the object. + The distinguished name of the object. + The object SID. Returns null if no object SID exists. + + + + Get the object SID from a directory object. + + The distinguished name of the object. + The object SID. Returns null if no object SID exists. + + + + Get a directory object. + + The domain name for the object. + The distinguished name of the object. + The object entry. + + + + Get a directory object. + + The distinguished name of the object. + The object entry. + + + + Standardize security descriptor to the rules of Active Directory. + + The security descriptor. + The standardized security descriptor. + + + + Get the value for the dsHeuristics attribute. + + The domain to read the dsHeuristics from. + The dsHeuristics value. + + + + Get the value for the dsHeuristics attribute. + + The dsHeuristics value. + + + + Get the value for an object's sDRightsEffective attribute. + + The domain for the object. + The distinguished name of the object. + The sDRightsEffective value. + + + + Get the value for an object's sDRightsEffective attribute. + + The distinguished name of the object. + The sDRightsEffective value. + + + + Try and find the an object from its SID. + + Specify the domain to search. + The SID to find. + The distinguished name of the object, null if not found. + + + + Try and find the token groups for an object. + + Domain name for the lookup. + The distinguished name to find. + True to return all groups including BUILTIN on the server. False for just universal and global groups. + The list of member SIDs. + + + + Try and find the token groups for an object using the SID. + + Sid to use for the object. + True to return all groups including BUILTIN on the server. False for just universal and global groups. + The list of member SIDs. + + + + Try and find the membership of groups for a name. + + Domain name for the lookup. + The distinguished name to find as member. + The list of groups. + + + + Call to pre-cache the schema for a domain, could take a long time to load. + + The domain to cache. + True if the schema was cached successfully. + + + + Call to pre-cache the schema for the current domain, could take a long time to load. + + True if the schema was cached successfully. + + + + Interface to convert a directory object to a tree for access checking. + + + + + The name of the object. + + + + + The ID of the object. + + + + + Convert the schema class to an object type tree. + + The tree of object types. + + + + DLL characteristic flags. + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Image can handle a high entropy 64-bit virtual address space. + + + + + DLL can be relocated at load time. + + + + + Code Integrity checks are enforced. + + + + + Image is NX compatible. + + + + + Isolation aware, but do not isolate the image. + + + + + Does not use structured exception (SE) handling. No SE handler may be called in this image. + + + + + Do not bind the image. + + + + + Image must execute in an AppContainer. + + + + + A WDM driver. + + + + + Image supports Control Flow Guard. + + + + + Terminal Server aware. + + + + + CodeView debug data for an executable. + + + + + The magic identifier. + + + + + The unique identifier. + + + + + Age of debug information. + + + + + Path to PDB file. + + + + + Identifier path to use when looking up symbol file. + + + + + Get just the name of the PDB file. + + + + + Get the symbol server path. + + The symbol URL, either a local path or a remote URL. + The symbol server path. + + + + Single DLL export entry. + + + + + The name of the export. If an ordinal this is #ORD. + + + + + The ordinal number. + + + + + Address of the exported entry. Can be 0 if a forwarded function. + + + + + Name of the forwarder, if used. + + + + + Get the module this was exported from. + + + + + Overridden ToString method. + + The name of the export. + + + + Single DLL import. + + + + + The name of the DLL importing from. + + + + + List of DLL imported functions. + + + + + List of names imported. + + + + + Could of functions + + + + + True of the imports are delay loaded. + + + + + The path to the executable this import came from. + + + + + Overridden ToString method. + + The DLL name and count. + + + + Single DLL import function. + + + + + The name of the DLL importing from. + + + + + The name of the imported function. If an ordinal this is #ORD. + + + + + Address of the imported function. Can be 0 if not a bound DLL. + + + + + Ordinal of import, if imported by ordinal. -1 if not. + + + + + Overridden ToString method. + + The name of the imported function. + + + + Simple class for an event trace. + + + + + Write an empty event. + + + + + Dispose method. + + + + + Level for trace event. + + + + + Critical level. + + + + + Error level. + + + + + Warning level. + + + + + Information level. + + + + + Verbose level. + + + + + Descriptor for an enabled trace provider. + + + + + Pointer to descriptor data. + + + + + Size of descriptor data. + + + + + Type of descriptor data. + + + + + An Event Trace Log. + + + + + Enable a provider. + + The GUID of the provider. + The level for the events. + Any keywords to match. + All keywords to match. + The timeout. + List of optional descriptors. + True to throw on error. + The resulting status code. + + + + Get allocated session GUID. + + + + + Get name of the session. + + + + + Finalizer. + + + + + Dispose the event trace log. + + + + + Source of an event trace provider. + + + + + Unknown source. + + + + + From WMI. + + + + + From NtTraceControl. + + + + + From the security key. + + + + + Class to represent an Event Trace Provider. + + + + + The ID of the provider. + + + + + The name of the provider. + + + + + Whether the provider is defined as an XML file or a MOF. + + + + + The provider security descriptor (only available as admin). + + + + + Indicates the source of the provider. + + + + + Class to access event tracing methods. + + + + + Query security of an event. + + The event GUID to query. + True to throw on error. + The event security descriptor. + + + + Query security of an event. + + The event GUID to query. + The event security descriptor. + + + + Query the default security for events. + + True to throw on error. + The default security descriptor. + + + + Query the default security for events. + + The default security descriptor. + + + + Modify trace security. + + The event trace GUID. + The operation to perform. + The SID to set. + The access mask to set. + True to allow, false to deny. + True to throw on error. + The NT status code. + + + + Modify trace security. + + The event trace GUID. + The operation to perform. + The SID to set. + The access mask to set. + True to allow, false to deny. + + + + Adds DACL ACE for an event trace. + + The event trace GUID. + The SID to set. + The access mask to set. + True to allow, false to deny. + True to throw on error. + The NT status code. + + + + Adds DACL ACE for an event trace. + + The event trace GUID. + The SID to set. + The access mask to set. + True to allow, false to deny. + + + + Clears DACL and adds ACE for an event trace. + + The event trace GUID. + The SID to set. + The access mask to set. + True to allow, false to deny. + True to throw on error. + The NT status code. + + + + lears DACL and adds ACE for an event trace. + + The event trace GUID. + The SID to set. + The access mask to set. + True to allow, false to deny. + + + + Remove security for an event trace. + + The event trace GUID. + True to throw on error. + The NT status code. + + + + Remove security for an event trace. + + The event trace GUID. + + + + Register an event trace with a specific GUID. + + The event trace GUID. + True to throw on error. + The event trace. + + + + Start an event trace log. + + The path to the log file. + Session GUID. + The name of the logging session. + True to throw on error. + The event trace log. + + + + Start an event trace log. + + The path to the log file. + Session GUID. + The name of the logging session. + The event trace log. + + + + Register an event trace with a specific GUID. + + The event trace GUID. + The event trace. + + + + Get the list of registered trace GUIDs. + + The list of trace GUIDs. + + + + Get the list of registered trace providers. + + Specify true to return a list of cached providers. + The list of trace providers. + + + + Get the list of registered trace providers. + + The list of trace providers. + Returns a cached list of providers, if you want to check the current list use GetProviders(bool). + + + + Get the name of a provider. + + The ID of the provider. + The name of the provider. Returns null if the provider had no name or doesn't exist. + + + + Contains information about a manifest file. + + + + + True if parsing the XML manifest failed. + + + + + Full path to the manifest location. + + + + + The name of the manifest. + + + + + True if the manifest indicates UI access. + + + + + The execution level from the manifest. + + + + + True if the manifest indicates auto elevation. + + + + + The manifest XML. + + + + + True if the manifest indicates long path awareness. + + + + + Get the manifests from a file. + + The file to extract the manifests from. + The list of manifests. + + + + Overridden ToString method. + + The manifest as a string. + + + + A class to represent filter communication port. + + + + + Open a filter communications port. + + The port name, e.g. \FilterName + Make the handle synchronous. + Optional context data. + True to throw on error. + The filter communications port. + + + + Open a filter communications port. + + The port name, e.g. \FilterName + Make the handle synchronous. + Optional context data. + The filter communications port. + + + + Open a filter communications port. + + The port name, e.g. \FilterName + The filter communications port. + + + + Get message from port. + + The maximum message size to receive. + True to throw on error. + The returned message. + + + + Get message from port. + + The maximum message size to receive. + The returned message. + + + + Reply to message. + + The NT status code. + The message ID from GetMessage. + The data to send. + True to throw on error. + The NT status code. + + + + Reply to message. + + The NT status code. + The message ID from GetMessage. + The data to send. + + + + Send a message to the filter. + + The input buffer. + The output buffer. + True to throw on error. + The bytes in the output buffer. + + + + Send a message to the filter. + + The input buffer. + The output buffer. + The bytes in the output buffer. + + + + Send a message to the filter. + + The input buffer. + The maximum size of the output buffer. + true to throw on error. + The output buffer. + + + + Send a message to the filter. + + The input buffer. + The maximum size of the output buffer. + The output buffer. + + + + Class to represent a filter communications port message. + + + + + The message ID. + + + + + The returned data. + + + + + The length of the reply to send. + + + + + Class to represent a filter drive. + + + + + True if a mini-filter, false if a legacy-filter. + + + + + Flags, if any. + + + + + The frame ID. + + + + + Number of instances if a mini-filter. + + + + + Name of the filter driver. + + + + + Altitude of the filter driver. + + + + + Class to represent a mini-filter instance. + + + + + The name of the instance. + + + + + The altitude of the instance. + + + + + The volume name. + + + + + The filter name. + + + + + Filter filesystem type. + + + + + an UNKNOWN file system type + + + + + Microsoft's RAW file system (\FileSystem\RAW) + + + + + Microsoft's NTFS file system (\FileSystem\Ntfs) + + + + + Microsoft's FAT file system (\FileSystem\Fastfat) + + + + + Microsoft's CDFS file system (\FileSystem\Cdfs) + + + + + Microsoft's UDFS file system (\FileSystem\Udfs) + + + + + Microsoft's LanMan Redirector (\FileSystem\MRxSmb) + + + + + Microsoft's WebDav redirector (\FileSystem\MRxDav) + + + + + Microsoft's Terminal Server redirector (\Driver\rdpdr) + + + + + Microsoft's NFS file system (\FileSystem\NfsRdr) + + + + + Microsoft's NetWare redirector (\FileSystem\nwrdr) + + + + + Novell's NetWare redirector + + + + + The BsUDF CD-ROM driver (\FileSystem\BsUDF) + + + + + Microsoft's Mup redirector (\FileSystem\Mup) + + + + + Microsoft's WinFS redirector (\FileSystem\RsFxDrv) + + + + + Roxio's UDF writeable file system (\FileSystem\cdudf_xp) + + + + + Roxio's UDF readable file system (\FileSystem\UdfReadr_xp) + + + + + Roxio's DVD file system (\FileSystem\DVDVRRdr_xp) + + + + + Tacit FileSystem (\Device\TCFSPSE) + + + + + Microsoft's File system recognizer (\FileSystem\Fs_rec) + + + + + Nero's InCD file system (\FileSystem\InCDfs) + + + + + Nero's InCD FAT file system (\FileSystem\InCDFat) + + + + + Microsoft's EXFat FILE SYSTEM (\FileSystem\exfat) + + + + + PolyServ's file system (\FileSystem\psfs) + + + + + IBM General Parallel File System (\FileSystem\gpfs) + + + + + Microsoft's Named Pipe file system(\FileSystem\npfs) + + + + + Microsoft's Mailslot file system (\FileSystem\msfs) + + + + + Microsoft's Cluster Shared Volume file system (\FileSystem\csvfs) + + + + + Microsoft's ReFS file system (\FileSystem\Refs or \FileSystem\Refsv1) + + + + + OpenAFS file system (\Device\AFSRedirector) + + + + + Composite Image file system (\FileSystem\cimfs) + + + + + Methods for accessing Filter Manager information. + + + + + Enumerate the list of filter drivers. + + The list of filter drivers. + + + + Enumerate the list of filter driver instances. + + The name of the filter driver. + The list of filter driver instances. + + + + Enumerate the list of filter driver instances for all filter drivers. + + The list of filter driver instances. + + + + Enumerate the list of filter drivers attached to a volume. + + The name of volume, e.g. C:\ + The list of filter volume instances. + + + + Enumerate the list of filter drivers attached for all volumes. + + The list of filter volume instances. + + + + Enumerate the list of filter volumes. + + The list of filter volumes + + + + Attach a filter to a volume. + + The filter name. + The volume name. + Optional altitude of the filter. + Optional instance name. + True to throw on error. + The created instance name. + + + + Attach a filter to a volume. + + The filter name. + The volume name. + Optional altitude of the filter. + Optional instance name. + The created instance name. + + + + Attach a filter to a volume. + + The filter name. + The volume name. + Optional altitude of the filter. + The created instance name. + + + + Attach a filter to a volume. + + The filter name. + The volume name. + The created instance name. + + + + Attach a filter to a volume. + + The filter name. + The volume name. + Optional instance name. + True to throw on error. + The NT status code. + + + + Attach a filter to a volume. + + The filter name. + The volume name. + Optional instance name. + The NT status code. + + + + Attach a filter to a volume. + + The filter name. + The volume name. + The NT status code. + + + + Class to represent a filter volume. + + + + + Is the filter detached from the volume. + + + + + Filter frame ID. + + + + + Filesystem type. + + + + + Filter volume name. + + + + + Class which represents a section from a loaded PE file. + + + + + The name of the section. + + + + + Buffer to the data. + + + + + Relative Virtual address of the data from the library base. + + + + + Image section characteristics. + + + + + Get the data as an array. + + The data as an array. If can't read the section returns an empty array. + + + + Characteristic flags for image section. + + + + + None. + + + + + Section is code. + + + + + Section is initialized data. + + + + + Section is uninitialized data. + + + + + Section is shared. + + + + + Section is executable. + + + + + Section is readable. + + + + + Section is writable. + + + + + Class to represent a resource in an image. + + + + + The name of the resource. + + + + + The type of the resource. + + + + + The size of the resource. + + + + + Get the resource as a byte array. + + The resource as a byte array. + + + + Image resource type. + + + + + The name of the resource as a string. + + + + + The well known type, is available (otherwise set to UNKNOWN) + + + + + Overridden ToString method. + + The name of the type. + + + + Known image resource types. + + + + + Interface for a symbol resolver. + + + + + Get list of loaded modules. + + The list of loaded modules + Note this will cache the results so subsequent calls won't necessarily see new modules. + + + + Get list of loaded modules and optionally refresh the list. + + True to refresh the current cached list of modules. + The list of loaded modules + + + + Get module at an address. + + The address for the module. + The module, or null if not found. + Note this will cache the results so subsequent calls won't necessarily see new modules. + + + + Get module at an address. + + The address for the module. + True to refresh the current cached list of modules. + The module, or null if not found. + + + + Get a string representation of a relative address to a module. + + The address to get the string for, + The string form of the address, e.g. modulename+0x100 + Note this will cache the results so subsequent calls won't necessarily see new modules. + + + + Get a string representation of a relative address to a module. + + The address to get the string for, + True to refresh the current cached list of modules. + The string form of the address, e.g. modulename+0x100 + + + + Get the address of a symbol. + + The name of the symbol, should include the module name, e.g. modulename!MySymbol. + The address of the symbol + + + + Get the symbol name for an address. + + The address of the symbol. + The symbol name. + + + + Get the symbol name for an address, with no fallback. + + The address of the symbol. + If true then generate a fake symbol. + The symbol name. If |generate_fake_symbol| is true and the symbol doesn't exist one is generated based on module name. + + + + Get the symbol name for an address, with no fallback. + + The address of the symbol. + If true then generate a fake symbol. + If true then return only the name of the symbols (such as C++ symbol name) rather than full symbol. + The symbol name. If |generate_fake_symbol| is true and the symbol doesn't exist one is generated based on module name. + + + + Reload the list of modules for this symbol resolver. + + + + + Load a specific module into the symbol resolver. + + The path to the module. + The base address of the loaded module. + + + + Flags for loading a library. + + + + + None. + + + + + Don't resolve DLL references + + + + + Load library as a data file. + + + + + Load with an altered search path. + + + + + Ignore code authz level. + + + + + Load library as an image resource. + + + + + Load library as a data file exclusively. + + + + + Add the DLL's directory temporarily to the search list. + + + + + Search application directory for the DLL. + + + + + Search the user's directories for the DLL. + + + + + Search system32 for the DLL. + + + + + Search the default directories for the DLL. + + + + + Logon type + + + + + This is used to specify an undefined logon type + + + + + Interactively logged on (locally or remotely) + + + + + Accessing system via network + + + + + Started via a batch queue + + + + + Service started by service controller + + + + + Proxy logon + + + + + Unlock workstation + + + + + Network logon with cleartext credentials + + + + + Clone caller, new default credentials + + + + + Remove interactive. + + + + + Cached Interactive. + + + + + Cached Remote Interactive. + + + + + Cached unlock. + + + + + Specify what account rights to get. + + + + + Get all account rights. + + + + + Get all privilege account rights. + + + + + Get logon account rights. + + + + + Utilities for user logon. + + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + True to throw on error. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + Additional groups to add. Needs SeTcbPrivilege. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + Additional groups to add. Needs SeTcbPrivilege. + True to throw on error. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + Additional groups to add. Needs SeTcbPrivilege. + The logged on token. + + + + Logon user using Kerberos Ticket. + + The type of logon token. + The service ticket. + Optional TGT. + True to throw on error. + The logged on token. + + + + Logon user using Kerberos Ticket. + + The type of logon token. + The service ticket. + Optional TGT. + The logged on token. + + + + Logon user using Kerberos Ticket. + + The type of logon token. + The service ticket. + Optional TGT. + True to throw on error. + The logged on token. + + + + Logon user using Kerberos Ticket. + + The type of logon token. + The service ticket. + Optional TGT. + The logged on token. + + + + Logon user using S4U + + The username. + The user's realm. + The type of logon token. + The name of the auth package to user. + True to throw on error. + The logged on token. + + + + Logon user using S4U + + The username. + The user's realm. + The type of logon token. + The name of the auth package to user. + The logged on token. + + + + Logon user using S4U + + The username. + The user's realm. + The type of logon token. + The logged on token. + + + + Logon user using S4U + + The username. + The user's realm. + The type of logon token. + The logged on token. + + + + Get a logon session. + + The logon session ID. + True to thrown on error. + The logon session. + + + + Get a logon session. + + The logon session ID. + The logon session. + + + + Get the logon session LUIDs + + True throw on error. + The list of logon sessions. Only returns ones you can access. + + + + Get the logon session LUIDs + + The list of logon sessions. Only returns ones you can access. + + + + Get the logon sessions. + + True throw on error. + The list of logon sessions. Only returns ones you can access. + + + + Get the logon sessions. + + The list of logon sessions. + + + + Get account rights assigned to a SID. + + The SID to query. + True to throw on error. + The list of account rights. + + + + Get account rights assigned to a SID. + + The SID to query. + The list of account rights. + + + + Get SIDs associated with an account right. + + The name of the account right, such as SeImpersonatePrivilege. + True to throw on error. + The list of SIDs assigned to the account right. + + + + Get SIDs associated with an account right. + + The name of the account right, such as SeImpersonatePrivilege. + The list of SIDs assigned to the account right. + + + + Get SIDs associated with an account right. + + The account right privilege to query. + True to throw on error. + The list of SIDs assigned to the account right. + + + + Get SIDs associated with an account right. + + The account right privilege to query. + The list of SIDs assigned to the account right. + + + + Get SIDs associated with an account right. + + The logon account right to query. + True to throw on error. + The list of SIDs assigned to the account right. + + + + Get SIDs associated with an account right. + + The logon account right to query. + The list of SIDs assigned to the account right. + + + + Get account rights. + + Specify the type of account rights to get. + Account rights. + + + + Get all account rights. + + All account rights. + + + + Add account rights to the user. + + The user SID to add. + The list of account rights. + True to throw on error. + The NT status code. + + + + Add account rights to the user. + + The user SID to add. + The list of account rights. + The NT status code. + + + + Add account rights as privileges. + + The user SID to add. + The list of account privileges. + True to throw on error. + The NT status code. + + + + Add account rights as privileges. + + The user SID to add. + The list of account privileges. + + + + Add account rights as privileges. + + The user SID to add. + The list of account logon types. + True to throw on error. + The NT status code. + + + + Add account rights as privileges. + + The user SID to add. + The list of account logon types. + + + + Remove account rights from a user. + + The user SID to remove. + The list of account rights. + True to throw on error. + The NT status code. + + + + Remove account rights from a user. + + The user SID to remove. + The list of account rights. + + + + Remove account rights from a user. + + The user SID to remove. + The list of privileges. + True to throw on error. + The NT status code. + + + + Remove account rights from a user. + + The user SID to remove. + The list of account privileges. + + + + Remove account rights from a user. + + The user SID to remove. + The list of account rights. + True to throw on error. + The NT status code. + + + + Remove account rights from a user. + + The user SID to remove. + The list of account rights. + + + + Win32 memory utils. + + + + + Write memory to a process. + + The process to write to. + The base address in the process. + The data to write. + The number of bytes written to the location + Thrown on error. + + + + Write memory to a process. + + The process to write to. + The base address in the process. + The data to write. + The number of bytes written to the location + Thrown on error. + + + + Class to represent a TCP listener with process ID. + + + + Gets the local endpoint of a Transmission Control Protocol (TCP) connection. + An instance that contains the IP address and port on the local computer. + + + Gets the remote endpoint of a Transmission Control Protocol (TCP) connection. + An instance that contains the IP address and port on the remote computer. + + + Gets the state of this Transmission Control Protocol (TCP) connection. + One of the enumeration values. + + + + Get local address. + + + + + Get local port. + + + + + Get remote address. + + + + + Get remote port. + + + + + Gets the process ID of the listener on the local system. + + + + + Gets the time the socket was created. + + + + + Gets the owner of the module. This could be an executable path or a service name. + + + + + Class to represent a UDP listener with process ID. + + + + Gets the local endpoint of a Transmission Control Protocol (TCP) connection. + An instance that contains the IP address and port on the local computer. + + + + Get local address. + + + + + Get local port. + + + + + Gets the process ID of the listener on the local system. + + + + + Gets the time the socket was created. + + + + + Gets the owner of the module. This could be an executable path or a service name. + + + + + Gets if the UDP socket is bound to a specific port. + + + + + Utilities for Win32 network APIs. + + + + + Get a list of TCP listeners with process IDs. + + The address family to query. + True to throw on error. + The list of TCP listeners. + The built-in System.Net.NetworkInformation.SystemIPGlobalProperties.GetActiveTcpListeners doesn't expose the PID member so we have to reimplement it. + + + + Get a list of TCP listeners with process IDs. + + The address family to query. + The list of TCP listeners. + The built-in System.Net.NetworkInformation.SystemIPGlobalProperties.GetActiveTcpListeners doesn't expose the PID member so we have to reimplement it. + + + + Get a list of TCP listeners with process IDs. Returns both IPv4 and IPv6 listeners. + + The list of TCP listeners. + The built-in System.Net.NetworkInformation.SystemIPGlobalProperties.GetActiveTcpListeners doesn't expose the PID member so we have to reimplement it. + + + + Get a TCP listener for a TCP port. + + The address family of the IP address. + The TCP port. + The listener information, or null if not found. + + + + Get a list of UDP listeners with process IDs. + + The address family to query. + True to throw on error. + The list of UDP listeners. + + + + Get a list of UDP listeners with process IDs. + + The address family to query. + The list of UDP listeners. + + + + Get a list of UDP listeners with process IDs. Returns both IPv4 and IPv6 listeners. + + The list of UDP listeners. + + + + APPX Package Architecture. + + + + + X86 + + + + + ARM + + + + + X64 + + + + + Neutral + + + + + ARM64 + + + + + APPX Package Origin. + + + + + Unknown origin. + + + + + Unsigned. + + + + + Inbox. + + + + + Store. + + + + + Developer unsigned. + + + + + Developer signed. + + + + + Line-of-business. + + + + + Class which represents an AppContainer package identity. + + + + + Process architecture. + + + + + Package version. + + + + + Package family name. + + + + + Publisher (not always available). + + + + + Resource ID. + + + + + Published ID. + + + + + Full package name. + + + + + Package origin. + + + + + Package family name. + + + + + Package install path. + + + + + The list of application model IDs. + + + + + Get the GetStagedPackageOrigin method as a delegate. It's supposed to be exposed by kernel32, + but actually doesn't seem to be. + + + + + + Create from a package full name. + + The package full name. + Query for full information (needs to be installed for the current user). + True to throw on error. + The package identity. + + + + Create from a package full name. + + The package full name. + Query for full information (needs to be installed for the current user). + The package identity. + + + + Create from a token. + + The AppContainer token. + Query for full information (needs to be installed for the current user). + True to throw on error. + The package identity. + + + + Create from a token. + + The AppContainer token. + Query for full information (needs to be installed for the current user). + The package identity. + + + + Class to represent a printer object. + + + + + Dispose the printer object. + + + + + Open a printer or server. + + The name of the printer or server. If this is null or empty then it's the local server. + The desired access on the printer. + True to throw on error. + The opened printer. + + + + Open a printer. + + The name of the printer. + The desired access on the printer. + The opened printer. + + + + Open a printer. + + The name of the printer. + The opened printer. + + + + Get security descriptor for the printer. + + True to throw on error. + The printer's security descriptor. + + + + Get security descriptor for the printer. + + The printer's security descriptor. + + + + Access rights for a print spooler object. + + + + + Utils for print spooler. + + + + + Name for the fake printer NT type. + + + + + Name for the fake print server NT type. + + + + + Name for the fake print server NT type. + + + + + Get the generic mapping for printer objects. + + The printer objects generic mapping. + + + + Get the generic mapping for job objects. + + The job objects generic mapping. + + + + Get the generic mapping for server objects. + + The server objects generic mapping. + + + + Get the appropriate NT type for the printer path. + + The printer path, e.g. \\server\printer. + The NT type. + + + + Class representing an RPC ALPC server. + + + + + The PID of the process which contains the ALPC server. + + + + + The name of the process which contains the ALPC server. + + + + + List of known endpoints potentially accessible via this RPC server. + + + + + The number of endpoints. + + + + + The name of the ALPC server. + + + + + The security descriptor of the ALPC server. + + + + + Get RPC ALPC servers for a specific process. + + The ID of the process. + The list of RPC ALPC servers. + If the process is suspended or frozen this call can hang. + + + + Get a list of all RPC ALPC servers. + + This works by discovering any server ALPC ports owned by the process and querying for interfaces. + This will ignore any frozen processes (primarily UWP) as they can't respond to the endpoint enumeration. + The list of RPC ALPC servers. + + + + Get the RPC ALPC server for an ALPC port object path. + + The object manager path to the ALPC port. + The ALPC RPC server. + Needs an API which is only available from Windows 10 19H1. + + + + Overridden ToString method. + + Formatted string. + + + + Generic RPC client. + + + + + Constructor. + + The interface ID. + Version of the interface. + + + + Constructor. + + The RPC server to bind to. + + + + Send and receive an RPC message. + + The procedure number. + Marshal NDR buffer for the call. + Unmarshal NDR buffer for the result. + + + + Class to represent an RPC endpoint. + + + + + The interface ID of the endpoint. + + + + + The interface version. + + + + + The object UUID. + + + + + Optional annotation. + + + + + RPC binding string. + + + + + Endpoint protocol sequence. + + + + + Endpoint network address. + + + + + Endpoint name. + + + + + Endpoint network options. + + + + + The endpoint path. + + + + + Indicates this endpoint is registered with the endpoint mapper. + + + + + Overridden ToString method. + + String form of the object. + + + + Get information about the server process. + + + + + + Static class to access information from the RPC mapper. + + + + + Query all endpoints registered on the local system. + + List of endpoints. + + + + Query all endpoints registered based on a binding string. + + The binding string for the server to search on. If null or empty will search localhost. + List of endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint. + + The binding string for the server to search on. If null or empty will search localhost. + Interface UUID to lookup. + Interface version lookup. + The list of registered RPC endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint. + + Interface UUID to lookup. + Interface version lookup. + The list of registered RPC endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint ignoring the version. + + The binding string for the server to search on. If null or empty will search localhost. + Interface UUID to lookup. + The list of registered RPC endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint ignoring the version. + + Interface UUID to lookup. + The list of registered RPC endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint. + + The server interface. + The list of registered RPC endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint via ALPC. + + Interface UUID to lookup. + Interface version lookup. + The list of registered RPC endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint via ALPC. + + The server interface. + The list of registered RPC endpoints. + + + + Query for endpoints for a RPC binding. + + The ALPC port to query. Can be a full path as long as it contains \RPC Control\ somewhere. + True to throw on error. + The list of endpoints on the RPC binding. + + + + Query for endpoints for a RPC binding. + + The ALPC port to query. Can be a full path as long as it contains \RPC Control\ somewhere. + The list of endpoints on the RPC binding. + + + + Query for endpoints for a RPC binding. + + The RPC binding to query, e.g. ncalrpc:[PORT] + True to throw on error. + The list of endpoints on the RPC binding. + + + + Query for endpoints for a RPC binding. + + The RPC binding to query, e.g. ncalrpc:[PORT] + The list of endpoints on the RPC binding. + + + + Resolve the local binding string for this service from the local Endpoint Mapper and return the endpoint. + + The protocol sequence to lookup. + Interface UUID to lookup. + Interface version lookup. + The mapped endpoint. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + + + + Resolve the local binding string for this service from the local Endpoint Mapper and return the endpoint. + + The protocol sequence to lookup. + The network address for the lookup. + Interface UUID to lookup. + Interface version lookup. + The mapped endpoint. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + + + + Resolve the local binding string for this service from the local Endpoint Mapper and return the endpoint. + + The string binding to map. + Interface UUID to lookup. + Interface version lookup. + The mapped endpoint. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + + + + Resolve the local binding string for this service from the local Endpoint Mapper and return the ALPC port path. + + Interface UUID to lookup. + Interface version lookup. + The mapped endpoint. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + + + + Resolve the local binding string for this service from the local Endpoint Mapper and return the ALPC port path. + + The server interface. + The mapped endpoint. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + + + + Finds ALPC endpoints which allows for the server binding. This brute forces all ALPC ports to try and find + something which will accept the bind. + + This could hang if the ALPC port is owned by a suspended process. + Interface UUID to lookup. + Interface version lookup. + A list of RPC endpoints which can bind the interface. + Throws on error. + + + + Finds an ALPC endpoint which allows for the server binding. This brute forces all ALPC ports to try and find + something which will accept the bind. + + This could hang if the ALPC port is owned by a suspended process. + Interface UUID to lookup. + Interface version lookup. + The first RPC endpoints which can bind the interface. Throws exception if nothing found. + Throws on error. + + + + Resolve the binding string for this service from the Endpoint Mapper. + + The binding string to map. + Interface UUID to lookup. + Interface version lookup. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + The RPC binding string. Empty string if it doesn't exist or the lookup failed. + + + + Resolve the binding string for this service from the the Endpoint Mapper. + + The protocol sequence to lookup. + The network address to lookup the endpoint. + Interface UUID to lookup. + Interface version lookup. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + The RPC binding string. Empty string if it doesn't exist or the lookup failed. + + + + Resolve the binding string for this service from the local Endpoint Mapper. + + The protocol sequence to lookup. + Interface UUID to lookup. + Interface version lookup. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + The RPC binding string. Empty string if it doesn't exist or the lookup failed. + + + + A class to represent an RPC server. + + + + + Resolve the current running endpoint for this server. + + + + + + Format the RPC server as text. + + The formatted RPC server. + + + + Format the RPC server as text. + + True to remove comments from the output. + The formatted RPC server. + + + + Format the RPC server as text. + + True to remove comments from the output. + Formating using C++ pseduo syntax. + The formatted RPC server. + + + + Serialize the RPC server to a stream. + + The stream to hold the serialized server. + Only use the output of this method with the Deserialize method. No guarantees of compatibility is made between + versions of the library or the specific format used. + + + + Serialize the RPC server to a byte array. + + The serialized data. + Only use the output of this method with the Deserialize method. No guarantees of compatibility is made between + versions of the library or the specific format used. + + + + The RPC server interface UUID. + + + + + The RPC server interface version. + + + + + The RPC transfer syntax GUID. + + + + + The RPC transfer syntax version. + + + + + The number of RPC procedures. + + + + + The list of RPC procedures. + + + + + The NDR RPC server. + + + + + List of parsed complext types. + + + + + Path to the PE file this server came from (if known) + + + + + Name of the the PE file this server came from (if known) + + + + + Offset into the PE file this server was parsed from. + + + + + Name of the service this server would run in (if known). + + + + + Display name of the service this server would run in (if known). + + + + + True if the service is currently running. + + + + + List of endpoints for this service if running. + + + + + Count of endpoints for this service if running. + + + + + This parsed interface represents a client. + + + + + Parse all RPC servers from a PE file. + + The PE file to parse. + Path to a DBGHELP DLL to resolve symbols. + Symbol path for DBGHELP + This only works for PE files with the same bitness as the current process. + A list of parsed RPC server. + + + + Parse all RPC servers from a PE file. + + The PE file to parse. + Path to a DBGHELP DLL to resolve symbols. + Symbol path for DBGHELP + True to parse client RPC interfaces. + This only works for PE files with the same bitness as the current process. + A list of parsed RPC server. + + + + Parse all RPC servers from a PE file. + + The PE file to parse. + Path to a DBGHELP DLL to resolve symbols. + Symbol path for DBGHELP + True to parse client RPC interfaces. + Ignore symbol resolving. + This only works for PE files with the same bitness as the current process. + A list of parsed RPC server. + + + + Parse all RPC servers from a PE file. + + The PE file to parse. + Path to a DBGHELP DLL to resolve symbols. + Symbol path for DBGHELP + Flags for the RPC parser. + This only works for PE files with the same bitness as the current process. + A list of parsed RPC server. + + + + Deserialize an RPC server instance from a stream. + + The stream to deserialize from. + The RPC server instance. + The data used by this method should only use the output from serialize. No guarantees of compatibility is made between + versions of the library or the specific format used. + + + + Deserialize an RPC server instance from a byte array. + + The byte array to deserialize from. + The RPC server instance. + The data used by this method should only use the output from serialize. No guarantees of compatibility is made between + versions of the library or the specific format used. + + + + Get the default RPC server security descriptor. + + The default security descriptor. + + + + Flags for the RPC server parser. + + + + + None. + + + + + Parse client entries. + + + + + Ignore symbols when parsing. + + + + + Try and resolve structure names. Needs private symbols. + + + + + Enable a symbol server fallback. If the copy of dbghelp doesn't have a symsrv.dll + then download from a public symbol URL to a local cache directory during symbol + resolving. + + + + + Base class for a RPC client. + + + + + Constructor. + + The interface ID. + Version of the interface. + + + + Constructor. + + The interface ID as a string. + Major version of the interface. + Minor version of the interface. + + + + Send and receive an RPC message. + + The procedure number. + The NDR data representation. + Marshal NDR buffer for the call. + List of handles marshaled into the buffer. + Unmarshal NDR buffer for the result. + + + + Method to call to check if the transport supports synchronous pipes. + + + + + Method to call to check if the transport supports asynchronous pipes. + + + + + Get whether the client is connected or not. + + + + + Get the endpoint that we connected to. + + + + + Get the protocol sequence that we connected to. + + + + + Get or set the current Object UUID used for calls. + + + + + The RPC interface ID. + + + + + The RPC interface version. + + + + + Get the client transport object. + + + + + Connect the client to a RPC endpoint. + + The endpoint for RPC server. + The transport security for the connection. + + + + Connect the client to a RPC endpoint. + + The endpoint for RPC server. + The security quality of service for the connection. + + + + Connect the client to a RPC endpoint. + + The protocol sequence for the transport. + The endpoint for the protocol sequence. + The network address for the protocol sequence. + The security quality of service for the connection. + + + + Connect the client to a RPC endpoint. + + The protocol sequence for the transport. + The endpoint for the protocol sequence. + The network address for the protocol sequence. + The transport security for the connection. + + + + Connect the client to a RPC endpoint. + + The protocol sequence for the transport. + The endpoint for the protocol sequence. + The security quality of service for the connection. + + + + Connect the client to a RPC endpoint. + + The protocol sequence for the transport. + The endpoint for the protocol sequence. + The transport security for the connection. + + + + Connect the client to an ALPC RPC port. + + The path to the ALPC RPC port. + The security quality of service for the port. + + + + Connect the client to a RPC endpoint. + + The binding string for the RPC server. + The transport security for the connection. + + + + Connect the client to an ALPC RPC port. + + The path to the ALPC RPC port. If an empty string the endpoint will be looked up in the endpoint mapper. + + + + Connect the client to an ALPC RPC port. + + The ALPC endpoint will be looked up in the endpoint mapper. + + + + Dispose of the client. + + + + + Disconnect the client. + + + + + Builder to create an RPC client from an RpcServer class. + + + + + Build a source file for the RPC client. + + The RPC server to base the client on. + Additional builder arguments. + The code generation options, can be null. + The code dom provider, such as CSharpDomProvider + The source code file. + + + + Build a C# source file for the RPC client. + + The RPC server to base the client on. + Additional builder arguments. + The C# source code file. + + + + Build a C# source file for the RPC client. + + The RPC server to base the client on. + The C# source code file. + + + + Build a source file for RPC complex types. + + The RPC complex types to build the encoders from. + Name of the decoder class. Can be null or empty to use default. + Name of the encoder class. Can be null or empty to use default. + Name of the generated namespace. Null or empty specified no namespace. + The code generation options, can be null. + The code dom provider, such as CSharpDomProvider + True to wrap complex decoders in a unique pointer. + The source code file. + + + + Build a source file for RPC complex types. + + The RPC complex types to build the encoders from. + Name of the decoder class. Can be null or empty to use default. + Name of the encoder class. Can be null or empty to use default. + Name of the generated namespace. Null or empty specified no namespace. + The code generation options, can be null. + The code dom provider, such as CSharpDomProvider + The source code file. + + + + Build a source file for RPC complex types. + + The RPC complex types to build the encoders from. + Name of the decoder class. Can be null or empty to use default. + Name of the encoder class. Can be null or empty to use default. + Name of the generated namespace. Null or empty specified no namespace. + True to wrap complex decoders in a unique pointer. + The source code file. + + + + Build a source file for RPC complex types. + + The RPC complex types to build the encoders from. + Name of the decoder class. Can be null or empty to use default. + Name of the encoder class. Can be null or empty to use default. + Name of the generated namespace. Null or empty specified no namespace. + The source code file. + + + + Build a source file for RPC complex types. + + The RPC complex types to build the encoders from. + The C# source code file. + + + + Compile an in-memory assembly for the RPC client. + + The RPC server to base the client on. + Additional builder arguments. + True to ignore cached assemblies. + Code DOM provider to compile the assembly. + The compiled assembly. + This method will cache the results of the compilation against the RpcServer. + + + + Compile an in-memory assembly for the RPC client. + + The RPC server to base the client on. + Additional builder arguments. + True to ignore cached assemblies. + The compiled assembly. + This method will cache the results of the compilation against the RpcServer. + + + + Compile an in-memory assembly for the RPC client. + + The RPC server to base the client on. + Additional builder arguments. + The compiled assembly. + This method will cache the results of the compilation against the RpcServer. + + + + Compile an in-memory assembly for the RPC client. + + The RPC server to base the client on. + True to ignore cached assemblies. + The compiled assembly. + This method will cache the results of the compilation against the RpcServer. + + + + Compile an in-memory assembly for the RPC client. + + The RPC server to base the client on. + The compiled assembly. + This method will cache the results of the compilation against the RpcServer. + + + + Create an instance of an RPC client. + + The RPC server to base the client on. + True to ignore cached assemblies. + Additional builder arguments. + Code DOM provider to compile the assembly. + The created RPC client. + This method will cache the results of the compilation against the RpcServer. + + + + Create an instance of an RPC client. + + The RPC server to base the client on. + True to ignore cached assemblies. + Additional builder arguments. + The created RPC client. + This method will cache the results of the compilation against the RpcServer. + + + + Create an instance of an RPC client. + + The RPC server to base the client on. + Additional builder arguments. + The created RPC client. + This method will cache the results of the compilation against the RpcServer. + + + + Create an instance of an RPC client. + + The RPC server to base the client on. + The created RPC client. + This method will cache the results of the compilation against the RpcServer. + + + + Flags for the RPC client builder. + + + + + None. + + + + + Generate public properties on the client to create defined complex types. + + If not specified then constructors will be defined on the types themselves. + + + + Insert breakpoints into the start of every generated method. Also enables debugging. + + + + + Disable calculated correlation information. This will prevent automatic updating of array and + string lengths based on other parameters or fields. This might result in unexpected behavior or + call failures. This won't disable correlations for union types or constant correlations. + + + + + Don't emit any namespace, normally not specifying a namespace will auto-generate one. + + + + + Output FC_CHAR as if the original compiler had specified unsigned char types. Basically converts + System.SByte to System.Byte where needed which makes the methods easier to use. + + + + + Return ref/out parameters via a structure rather than requiring ref/out parameters in client + methods. + + + + + When using StructureReturn hide the original out/ref methods. + + + + + Generate encode/decode methods for complex types. + + + + + Exclude any text in the source code which can change between generations. + + + + + Wrap complex type decoders with a unique pointer. + + + + + Marshal pipe parameters using arrays. + + + + + Arguments for the RPC client builder. + + + + + Builder flags. + + + + + The namespace for the client class. + + + + + The class name of the client. + + + + + The class name of the complex type encoding class. + + + + + The class name of the complex type decoder class. + + + + + Enable debugging on built code. + + + + + GetHashCode implementation. + + The hash code. + + + + Equals implementation. + + The object to compare against. + True if the object is equal. + + + + Response data from an RPC client call. + + + + + The marshaled NDR data from the response. + + + + + Any object handles returned in the response. (only for ALPC). + + + + + Indicates the NDR data representation for the response. + + + + + Class to represent details about a server process. + + + + + The server process ID. + + + + + The server session ID. + + + + + The name of the process. + + + + + Get the process image path. + + + + + Overridden ToString method. + + + + + + Some addition internal utilities for RPC code. + + + + + Specify RPC trace level. + + Specify the RPC trace level. + This dumps NDR data. Verbose dumps the binary data. + + + + Specify RPC transport trace level. + + Specify the RPC transport trace level. + Verbose dumps the transport binary data. + + + + Helper to dereference a type. + + The type to dereference. + The value to dereference. + The dereferenced result. + + + + Helper to dereference a type. + + The type to dereference. + The value to dereference. + The dereferenced result. + + + + Helper to check for NULL. + + The type to check. + The object to check. + The name of the value to check. + The checked value. + + + + Helper to check for NULL. + + The type to check. + The object to check. + The name of the value to check. + The checked value. + + + + Helper to check for NULL. + + The type to check. + The object to check. + The name of the value to check. + The checked value. + + + + Helper to dereference a type. + + The type to dereference. + The value to dereference. + The dereferenced result. + + + + Helper to perform a plus unary operation. + + The value to apply the operator to. + The result. + + + + Helper to perform a minus unary operation. + + The value to apply the operator to. + The result. + + + + Helper to perform a complement unary operation. + + The value to apply the operator to. + The result. + + + + Perform a ternary operation. + + The condition to evaluate as != 0. + The result if true. + The result if false. + The result. + + + + Perform ADD. + + The left operand. + The right operand. + The result. + + + + Perform SUB. + + The left operand. + The right operand. + The result. + + + + Perform MUL. + + The left operand. + The right operand. + The result. + + + + Perform DIV. + + The left operand. + The right operand. + The result. + + + + Perform MOD. + + The left operand. + The right operand. + The result. + + + + Perform Bitwise AND. + + The left operand. + The right operand. + The result. + + + + Perform Bitwise OR. + + The left operand. + The right operand. + The result. + + + + Perform bitwise XOR. Needed as Code DOM doesn't support XOR. + + The left operand. + The right operand. + The result. + + + + Perform bitwise LEFTSHIFT. + + The left operand. + The right operand. + The result. + + + + Perform bitwise RIGHTSHIFT. + + The left operand. + The right operand. + The result. + + + + Perform logical AND. + + The left operand. + The right operand. + The result. + + + + Perform logical OR. + + The left operand. + The right operand. + The result. + + + + Perform EQUAL. + + The left operand. + The right operand. + The result. + + + + Perform NOTEQUAL. + + The left operand. + The right operand. + The result. + + + + Perform GREATER. + + The left operand. + The right operand. + The result. + + + + Perform GREATEREQUAL. + + The left operand. + The right operand. + The result. + + + + Perform LESS. + + The left operand. + The right operand. + The result. + + + + Perform LESSEQUAL. + + The left operand. + The right operand. + Returns left LESSEQUAL right. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The nullable value + True if value has a value set. + + + + Convert value to a boolean. + + The nullable value + True if value has a value set. + + + + Compose a string binding from its parts. + + The object UUID. + The protocol sequence. + The network address. + The endpoint. + The options. + The composed binding string. + + + + Interface to implement an RPC client transport. + + + + + Bind the RPC transport to a specified interface. + + The interface ID to bind to. + The interface version to bind to. + The transfer syntax to use. + The transfer syntax version to use. + + + + Send and receive an RPC message. + + The procedure number. + The object UUID for the call. + NDR data representation. + Marshal NDR buffer for the call. + List of handles marshaled into the buffer. + Client response from the send. + + + + Add and authenticate a new security context. + + The transport security for the context. + The created security context. + + + + Disconnect the transport. + + + + + Get whether the client is connected or not. + + + + + Get the endpoint the client is connected to. + + + + + Get the transport protocol sequence. + + + + + Get whether the client has been authenticated. + + + + + Get the transport's authentication type. + + + + + Get the transport's authentication level. + + + + + Get information about the local server process, if known. + + + + + Get the current Call ID. + + + + + Indicates if this connection supported multiple security context. + + + + + Get the list of negotiated security context. + + + + + Get or set the current security context. + + + + + Get whether the transport supports synchronous pipes. + + + + + RPC client transport over ALPC. + + + + + Constructor. + + The path to connect. The format depends on the transport. + The security quality of service for the connection. + + + + Constructor. + + The path to connect. The format depends on the transport. + The security quality of service for the connection. + Timeout for connection. + + + + Bind the RPC transport to an interface. + + The interface ID to bind to. + The interface version to bind to. + The transfer syntax to use. + The transfer syntax version to use. + + + + Send and receive an RPC message. + + The procedure number. + The object UUID for the call. + NDR data representation. + Marshal NDR buffer for the call. + List of handles marshaled into the buffer. + Client response from the send. + + + + Dispose of the client. + + + + + Disconnect the client. + + + + + Add and authenticate a new security context. + + The transport security for the context. + The created security context. + + + + Get whether the client is connected or not. + + + + + Get the ALPC port path that we connected to. + + + + + Get the current Call ID. + + + + + Get the transport protocol sequence. + + + + + Get information about the local server process, if known. + + + + + Get whether the client has been authenticated. + + + + + Get the transports authentication type. + + + + + Get the transports authentication level. + + + + + Indicates if this connection supported multiple security context. + + + + + Get the list of negotiated security context. + + + + + Get or set the current security context. + + + + + Get whether the transport supports synchronous pipes. + + + + + Flags to specify RPC authentication capabilities. + + + + + None. + + + + + Enable mutual authentication. + + + + + Enable a NULL session authentication. + + + + + Enable delegation of credentials if supported. + + + + + Authentication level for RPC transport. + + + + + Default. + + + + + None. + + + + + Connect only. + + + + + Call only. + + + + + Packet only. + + + + + Packet integrity. + + + + + Packer privacy and integrity. + + + + + RPC authentication type. + + + + + Default. Uses WinNT. + + + + + No authentication. + + + + + DCE private. + + + + + DCE public. + + + + + DEC public. + + + + + SPNEGO authentication. + + + + + WinNT authentication, i.e. NTLM. + + + + + Secure channel. + + + + + Kerberos. + + + + + DPA. + + + + + MSN. + + + + + Digest. + + + + + Kernel. + + + + + SPNEGO extender. + + + + + PKU2U + + + + + LiveSSP + + + + + LiveXP SSP. + + + + + CloudAP. + + + + + Netlogon. + + + + + MS Online. + + + + + Message Queue. + + + + + Interface to implement an RPC client transport factory. + + + + + Connect a new RPC client transport. + + The RPC endpoint. + The transport security for the connection. + The connected transport. + + + + Factory for RPC client transports. + + + + + Add a new transport factory. + + The protocol sequence to add. + The transport factory. + + + + Connect a client transport from an endpoint. + + The RPC endpoint. + The security quality of service for the connection. + The connected client transport. + Thrown if protocol sequence unsupported. + Other exceptions depending on the connection. + + + + Connect a client transport from an endpoint. + + The RPC endpoint. + The transport security for the connection. + The connected client transport. + Thrown if protocol sequence unsupported. + Other exceptions depending on the connection. + + + + Base class for a DCE/RPC connected client transport. This implements the common functions + of the DCE/RPC specs for connected network based RPC transports. + + + + + Constructor. + + The initial maximum receive fragment length. + The initial maximum send fragment length. + The transport security for the connection. + The data representation. + + + + Read the next fragment from the transport. + + The maximum receive fragment length. + The read fragment. + + + + Write the fragment to the transport. + + The fragment to write. + True if successfully wrote the fragment. + + + + Get whether the client is connected or not. + + + + + Get the endpoint the client is connected to. + + + + + Get the transport protocol sequence. + + + + + Get information about the server process, if known. + + + + + Get whether the client has been authenticated. + + + + + Get the transports authentication type. + + + + + Get the transports authentication level. + + + + + Get the transport authentication context. + + + + + Indicates if this connection supported multiple security context. + + + + + Get the list of negotiated security context. + + + + + Get or set the current security context. + + + + + Get the current Call ID. + + + + + Get maximum receive fragment. + + + + + Get maximum send fragment. + + + + + Get association group ID. + + + + + Get whether the transport supports synchronous pipes. + + + + + Bind the RPC transport to a specified interface. + + The interface ID to bind to. + The interface version to bind to. + The transfer syntax to use. + The transfer syntax version to use. + + + + Add and authenticate a new security context. + + The transport security for the context. + The created security context. + + + + Send and receive an RPC message. + + The procedure number. + The object UUID for the call. + NDR data representation. + Marshal NDR buffer for the call. + List of handles marshaled into the buffer. + Client response from the send. + + + + Disconnect the transport. + + + + + Enable or disable bind time feature negotiation. You need to enable this to + use multiple security context. + + Should be set before connecting an RPC client. + + + + Dispose the transport. + + + + + Extended error information. + + + + + Computer name. + + + + + Process ID. + + + + + Timestamp. + + + + + Generating component. + + + + + Status code. + + + + + Detection location. + + + + + Flags. + + + + + Extra parameters. + + + + + Exception for RPC fault conditions. + + + + + Constructor. + + The RPC status code. + + + + Get extended error information. + + + + + RPC client transport over HyperV sockets. + + + + + Constructor. + + The HyperV socket endpoint to connect to. + The transport security for the connection. + + + + Get the transport protocol sequence. + + + + + RPC client transport over named pipes. + + + + + Constructor. + + The NT pipe path to connect. e.g. \??\pipe\ABC. + The transport security for the connection. + + + + Dispose of the client. + + + + + Disconnect the client. + + + + + Read the next fragment from the transport. + + The maximum receive fragment length. + The read fragment. + + + + Write the fragment to the transport. + + The fragment to write. + True if successfully wrote the fragment. + + + + Get whether the client is connected or not. + + + + + Get the named pipe port path that we connected to. + + + + + Get the transport protocol sequence. + + + + + Get information about the local server process, if known. + + + + + Class to implement a RPC client transport based on a stream. + + + + + Constructor. + + The stream to use to communicate with the transport. + The initial maximum receive fragment length. + The initial maximum send fragment length. + The transport security for the connection. + The data representation. + + + + Read the next fragment from the transport. + + The maximum receive fragment length. + The read fragment. + + + + Write the fragment to the transport. + + The fragment to write. + True if successfully wrote the fragment. + + + + Class to implement RPC over a stream based socket. + + + + + Constructor. + + The socket to use to communicate. + The initial maximum receive fragment length. + The initial maximum send fragment length. + The transport security for the connection. + The data representation. + + + + Disconnect the client. + + + + + Dispose of the client. + + + + + Get whether the client is connected or not. + + + + + Get the named pipe port path that we connected to. + + + + + RPC client transport over TCP/IP; + + + + + Get the server process information. + + The server process information. + + + + Constructor. + + The hostname to connect to. + The TCP port to connect to. + The transport security for the connection. + + + + Get the transport protocol sequence. + + + + + Get information about the local server process, if known. + + + + + Exception generated by the RPC transport. + + + + + Constructor. + + + + + Constructor. + + Exception message. + + + + Constructor. + + Exception message. + Inner exception. + + + + Class to represent the RPC transport security. + + + + + Security quality of service. + + + + + Authentication level. + + + + + Authentication type. + + + + + Authentication credentials. + + + + + The SPN for the authentication. + + + + + Authentication capabilities. + + + + + Constructor. + + Factory to create a non-standard authentication context. + You can use this version to create a mechanism to pass existing tokens such as pass-the-hash or sending arbitrary Kerberos tickets. + + + + Constructor. + + Security quality of service. + + + + Query the service principal name for the server. + + The binding string for the server. + The authentication service to query. + True to throw on error. + The service principal name. + + + + Query the service principal name for the server. + + The binding string for the server. + The authentication service to query. + The service principal name. + + + + Class to represent an RPC transport security context. + + + + + The ID of the security context. + + + + + The RPC transport security settings. + + + + + The authentication context. + + + + + The negotiated authentication type. + + + + + The authentication level. + + + + + Dummy class to mark the old name as obsolete. + + + + + Detaches the current buffer and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + Safe handle for a loaded library. + + + + + Constructor + + The handle to the library + True if the handle is owned by this object. + + + + Release handle. + + True if handle released. + + + + Get the address of an exported function, throw if the function doesn't exist. + + The name of the exported function. + True to throw on error. + Pointer to the exported function. + Thrown if the name doesn't exist. + + + + Get the address of an exported function from an ordinal. + + The ordinal of the exported function. + True to throw on error. + Pointer to the exported function. + Thrown if the ordinal doesn't exist. + + + + Get the address of an exported function. + + The name of the exported function. + Pointer to the exported function, or IntPtr.Zero if it can't be found. + + + + Get the address of an exported function from an ordinal. + + The ordinal of the exported function. + Pointer to the exported function, or IntPtr.Zero if it can't be found. + + + + Get a delegate which points to an unmanaged function. + + The delegate type. + The name of the function to lookup. + True to throw on error. + The delegate. + + + + Get a delegate which points to an unmanaged function. + + The delegate type. The name of the delegate is used to lookup the name of the function. + True to throw on error. + The delegate. + + + + Get a delegate which points to an unmanaged function. + + The delegate type. + The name of the function to lookup. + The delegate. + + + + Get a delegate which points to an unmanaged function. + + The delegate type. The name of the delegate is used to lookup the name of the function. + The delegate. + + + + Pin the library into memory. This prevents FreeLibrary unloading the library until + the process exits. + + + + + Parse a library's delayed import information. + + A dictionary containing the location of import information keyed against the IAT address. + + + + Get the image sections from a loaded library. + + The list of image sections. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type of the resource. + True to throw on error. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type name of the resource. + True to throw on error. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The well known type of the resource. + True to throw on error. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type of the resource. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type name of the resource. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The well known type of the resource. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type of the resource. + True to throw on error. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type name of the resource. + True to throw on error. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The well known type of the resource. + True to throw on error. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type of the resource. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type name of the resource. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The well known type of the resource. + The bytes for the resource. + + + + Get list of resource types from the loaded library. + + The list of resource types. + + + + Get list of resource types from the loaded library. + + The type for the resources. + True to load the resource data. + The list of resource types. + + + + Get list of resource types from the loaded library. + + The type for the resources. + The list of resource types. + This always loads resource data into memory. + + + + Get list of resource types from the loaded library. + + The typename for the resources. + True to load the resource data. + The list of resource types. + + + + Get list of resource types from the loaded library. + + The typename for the resources. + The list of resource types. + This always loads resource data into memory. + + + + Get list of resource types from the loaded library. + + The well known type for the resources. + True to load the resource data. + The list of resource types. + + + + Get list of resource types from the loaded library. + + The well known type for the resources. + The list of resource types. + This always loads resource data into memory. + + + + Get list of resource types from the loaded library. + + True to load the resource data. + The list of resource types. + + + + Get list of resource types from the loaded library. + + The list of resource types. + This always loads resource data into memory. + + + + Load a string for the library's string resource table. + + The ID of the string. + True to throw on error. + The loaded string. + + + + Load a string for the library's string resource table. + + The ID of the string. + The loaded string. + + + + Increases the reference count and returns a new instance. + + + + + + Get path to loaded module. + + + + + Get the module name. + + + + + Whether this library is mapped as an image. + + + + + Whether this library is mapped as a datafile. + + + + + Get current mapped image base. + + + + + Get original image base address. + + + + + Get image entry point RVA. + + + + + Get image entry point address as mapped. + + + + + Get whether the image is 64 bit or not. + + + + + Get the image's DLL characteristics flags. + + + + + Get exports from the DLL. + + + + + Get imports from the DLL. + + + + + Return resolved API set imports for the DLL. + + + + + Get CodeView Debug Data from DLL. + + + + + Get image signing level. + + + + + Get embedded enclave configuration. + + + + + Load a library into memory. + + The path to the library. + Additonal flags to pass to LoadLibraryEx + True to throw on error. + Handle to the loaded library. + + + + Load a library into memory. + + The path to the library. + Additonal flags to pass to LoadLibraryEx + Handle to the loaded library. + + + + Load a library into memory. + + The path to the library. + Handle to the loaded library. + + + + Get the handle to an existing loading library by name. + + The name of the module. + The handle to the loaded library. + Thrown if the module can't be found. + This will take a reference on the library, you should dispose the handle after use. + + + + Get the handle to an existing loading library by name. + + The name of the module. + The handle to the loaded library. Returns Null if not found. + This will take a reference on the library, you should dispose the handle after use. + + + + Get the handle to an existing loading library by an address in the module. + + An address inside the module. + The handle to the loaded library, null if the address isn't inside a valid module. + This will take a reference on the library, you should dispose the handle after use. + + + + Pin the library into memory. This prevents FreeLibrary unloading the library until + the process exits. + + The name of the module to pin. + + + + Pin the library into memory. This prevents FreeLibrary unloading the library until + the process exits. + + The address of the module to pin. + + + + NULL load library handle. + + + + + Represents an impersonation safe win32 exception, which resolves the win32 message when Message is called. + + + + + Constructor. + + + + + Constructor. + + Win32 error. + + + + The message for the exception. + + + + + Access rights for system audit policy. + + + + + System Audit Category. + + + + + System Audit Category. + + + + + The user for the per-user category. + + + + + System Audit Category base class. + + + + + The ID of the category. + + + + + The name of the category. + + + + + List of sub categories. + + + + + Convert to string. + + The name of the category. + + + + Set audit policy on all sub categories. + + The flags to set. + True to throw on error. + The audit policy flags. + + + + Set audit policy on all sub categories. + + The flags to set. + The audit policy flags. + + + + Type of global SACL to query or set. + + + + + File type. + + + + + Key type. + + + + + Policy audit event type. + + + + + Audit policy flags. + + + + + Set unchanged. + + + + + Audit on success. + + + + + Audit on failure. + + + + + Audit nothing. + + + + + Per user policy flags. + + + + + Set unchanged. + + + + + Audit on success included. + + + + + Audit on success excluded. + + + + + Audit on failure included. + + + + + Audit on failure excluded. + + + + + Audit nothing. + + + + + Utilities for security auditing policy. + + + + + Name for the fake Audit NT type. + + + + + Get the generic mapping for directory services. + + The directory services generic mapping. + + + + Get a fake NtType for System Audit Policy. + + The fake Directory Services NtType + + + + Query the Auditing Security Descriptor. + + The security information to query. + True to throw on error. + The security descriptor. + + + + Query the Auditing Security Descriptor. + + The security information to query. + The security descriptor. + + + + Query the Auditing Security Descriptor. + + The security descriptor. + + + + Set the Auditing Security Descriptor. + + The security information to set. + The security descriptor to set. + True to throw on error. + The NT status code. + + + + Set the Auditing Security Descriptor. + + The security information to set. + The security descriptor to set. + The NT status code. + + + + Query the global SACL. + + The global SACL type. + True to throw on error. + The global SACL in a Security Descriptor. + + + + Query the global SACL. + + The global SACL type. + The global SACL in a Security Descriptor. + + + + Set the global SACL. + + The global SACL type. + The SACL to set in an Security Descriptor. + True to throw on error. + The NT status code. + + + + Set the global SACL. + + The global SACL type. + The SACL to set in an Security Descriptor. + The NT status code. + + + + Get list of Audit Policy categories. + + True to throw on error. + The list of categories. + + + + Get list of Audit Policy categories. + + The list of categories. + + + + Get a single category. + + The category type. + The audit category. + + + + Get a single category. + + The category GUID. + The audit category. + + + + Get all per-user categories for denied users. + + True to throw on error. + The list of per-user categories. + + + + Get all per-user categories for denied users. + + The list of per-user categories. + + + + Get list of per-user Audit Policy categories. + + The user SID to query. + True to throw on error. + The list of categories. + + + + Get list of per-user Audit Policy categories. + + The user SID to query. + The list of categories. + + + + Get a single per-user category. + + The user SID to query. + The category type. + The audit category. + + + + Get a single per-user category. + + The user SID to query. + The category GUID. + The audit category. + + + + Class representing an Audit Sub Category. + + + + + The category. + + + + + Class representing an Audit Sub Category. + + + + + The category. + + + + + The user for the per-user category. + + + + + Class representing an Audit Sub Category. Base class. + + Enum type for the Policy flags. + + + + The ID of the sub category. + + + + + The name of the sub category. + + + + + The Current Audit Policy + + + + + Convert to string. + + The name of the subcategory. + + + + Query audit policy. + + True to throw on error. + The audit policy flags. + + + + Set audit policy. + + The flags to set. + True to throw on error. + The audit policy flags. + + + + Set audit policy. + + The flags to set. + The audit policy flags. + + + + Authentication token constructed from ASN1. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The ASN1 authentication token. + True if this is a token from a client. + The token count number. + True if parsed successfully. + + + + Base class for authentication credentials. + + + + + Security data representation. + + + + + Native representation. + + + + + Network representation. + + + + + Credital flags. + + + + + Inbound credentials. + + + + + Outbound credentials. + + + + + Both credentials direction. + + + + + Default. + + + + + Auto logon restricted. Don't use automatic credentials. + + + + + Only process policy. + + + + + Initialize context request flags. + + + + + Initialize context return flags. + + + + + Access context request flags. + + + + + Accept context return flags. + + + + + Security package capability flags. + + + + + Supports integrity on messages + + + + + Supports privacy (confidentiality) + + + + + Only security token needed + + + + + Datagram RPC support + + + + + Connection oriented RPC support + + + + + Full 3-leg required for re-auth. + + + + + Server side functionality not available + + + + + Supports extended error msgs + + + + + Supports impersonation + + + + + Accepts Win32 names + + + + + Supports stream semantics + + + + + Can be used by the negotiate package + + + + + GSS Compatibility Available + + + + + Supports common LsaLogonUser + + + + + Token Buffers are in ASCII + + + + + Package can fragment to fit + + + + + Package can perform mutual authentication + + + + + Package can delegate + + + + + Supports integrity readonly checksum buffers. + + + + + Package supports restricted callers + + + + + This package extends SPNEGO, there is at most one + + + + + This package is negotiated under the NegoExtender + + + + + This package receives all calls from appcontainer apps + + + + + this package receives calls from appcontainer apps + if the following checks succeed + 1. Caller has domain auth capability or + 2. Target is a proxy server or + 3. The caller has supplied creds + + + + + This package is running with Credential Guard enabled + + + + + this package supports reliable detection of loopback + 1.) The client and server see the same sequence of tokens + 2.) The server enforces a unique exchange for each + non-anonymous authentication. (Replay detection) + + + + + Impersonation context for a server authentication. + + + + + Base class which represents an authentication key. + + + + + An authentication package entry. + + + + + Authentication package name for MSV1.0 + + + + + Authentication package name for Kerberos. + + + + + Authentication package name for Negotiate. + + + + + Authentication package name for NTLM. + + + + + Authentication package name for Digest. + + + + + Authentication package name for SChannel. + + + + + Authentication package name for CredSSP. + + + + + Capabilities of the package. + + + + + Version of the package. + + + + + RPC DCE ID. + + + + + Max token size. + + + + + Name of the package. + + + + + Comment for the package. + + + + + Get authentication packages. + + The list of authentication packages. + + + + Get authentication package names. + + The list of authentication package names. + + + + Get an authentication package by name. + + The name of the package. + The authentication package. + + + + Base class to represent an authentication token. + + + + + Decrypt the Authentication Token using a keyset. + + The set of keys to decrypt the + The decrypted token, or the same token if nothing could be decrypted. + + + + Convert the authentication token to a byte array. + + The byte array. + + + + Get the length of the token in bytes. + + + + + Format the authentication token. + + The token as a formatted string. + + + + Constructor. + + The authentication token data. + + + + Parse a structured authentication token. + + The authentication context. + The token to parse. + The parsed authentication token. If can't parse any other format returns + a raw AuthenticationToken. + + + + Parse a structured authentication token. + + The package name to parse as. + True if the token is from a client. + The token to parse. + The parsed authentication token. If can't parse any other format returns + a raw AuthenticationToken. + + + + Class to represent a client authentication context. + + + + + The current authentication token. + + + + + Whether the authentication is done. + + + + + Current request attribute flags. + + + + + Current return attribute flags. + + + + + Current data representation. + + + + + Current target name. + + + + + Current channel binding. + + + + + Current status flags. + + + + + Expiry of the authentication. + + + + + Get the Session Key for this context. + + + + + Get the maximum signature size of this context. + + + + + Get the size of the security trailer for this context. + + + + + Size of any header when using a stream protocol such as Schannel. + + + + + Size of any trailer when using a stream protocol such as Schannel. + + + + + Number of buffers needed when using a stream protocol such as Schannel. + + + + + Maximum message size when using a stream protocol such as Schannel. + + + + + Preferred block size when using a stream protocol such as Schannel. + + + + + Get the local certificate. Only used for Schannel related authentication. + + + + + Get the remote certificate. Only used for Schannel related authentication. + + + + + Get the last token status for the client context. + + + + + Get the name of the authentication package. + + + + + Get connection information for the schannel connection. + + + + + Get whether the authentication context is for loopback. + + + + + Get or set whether the context owns the credentials object or not. If true + then the credentials are disposed with the context. + + + + + Constructor. + + Credential handle. + Request attribute flags. + Target SPN (optional). + Data representation. + Optional channel binding token. + Specify to default initialize the context. Must call Continue with an auth token to initialize. + + + + Constructor. + + Credential handle. + Request attribute flags. + Target SPN (optional). + Data representation. + Optional channel binding token. + + + + Constructor. + + Credential handle. + Request attribute flags. + Target SPN (optional). + Data representation. + + + + Constructor. + + Credential handle. + Request attribute flags. + Data representation. + + + + Constructor. + + Credential handle. + + + + Continue the authentication with the server token. + + The server token to continue authentication. + + + + Continue the authentication.. + + The server token to continue authentication. + Additional input buffers for the continue, does not need to include the token. + + + + Continue the authentication. + + The server token to continue authentication. + Additional input buffers for the continue, does not need to include the token. + Additional output buffers, does not need to include the token. + + + + Continue the authentication without any token. + + Input buffers for the continue. Does not contain a token. + Specify additional output buffers, does not need to include the token. + True to throw on error. + This sends the input buffers directly to the initialize call, it does not contain any token. + + + + Continue the authentication without any token. + + Input buffers for the continue. Does not contain a token. + Specify additional output buffers, does not need to include the token. + This sends the input buffers directly to the initialize call, it does not contain any token. + + + + Continue the authentication. Will not pass any buffers to the initialize call. + + + + + Make a signature for this context. + + The message buffers to sign. + The sequence number. + The signature blob. + + + + Make a signature for this context. + + The message to sign. + The sequence number. + The signature blob. + + + + Verify a signature for this context. + + The message to verify. + The signature blob for the message. + The sequence number. + True if the signature is valid, otherwise false. + + + + Verify a signature for this context. + + The messages to verify. + The signature blob for the message. + The sequence number. + True if the signature is valid, otherwise false. + + + + Encrypt a message for this context. + + The message to encrypt. + Quality of protection flags. + The encrypted message. + The sequence number. + + + + Encrypt a message for this context. + + The messages to encrypt. + Quality of protection flags. + The signature for the messages. + The messages are encrypted in place. You can add buffers with the ReadOnly flag to prevent them being encrypted. + The sequence number. + + + + Encrypt a message for this context with no specific signature. + + The messages to encrypt. + Quality of protection flags. + The sequence number. + The messages are encrypted in place. You can add buffers with the ReadOnly flag to prevent them being encrypted. + If you need to return a signature then it must be specified in a buffer. + + + + Decrypt a message for this context. + + The message to decrypt. + The sequence number. + The decrypted message. + + + + Decrypt a message for this context. + + The messages to decrypt. + The sequence number. + The signature for the messages. + The messages are decrypted in place. You can add buffers with the ReadOnly flag to prevent them being decrypted. + + + + Decrypt a message for this context. + + The messages to decrypt. + The sequence number. + The messages are decrypted in place. You can add buffers with the ReadOnly flag to prevent them being decrypted. + If you need to specify a signature you need to add a buffer. + + + + Query the context's package info. + + The authentication package info, + + + + Export and delete the current security context. + + The exported security context. + The security context will not longer be usable afterwards. + + + + Dispose the client context. + + + + + Finalizer. + + + + + Class to represent a credential handle. + + + + + Name of the authentication package used. + + + + + Expiry of the credentials. + + + + + Constructor. + + User principal. + The package name. + Optional authentication ID for the user. + Credential user flags. + Optional authentication data. + + + + Create a new credential handle. + + User principal. + The package name. + Optional authentication ID for the user. + Credential user flags. + Optional credentials. + The credential handle. + + + + Create a new credential handle. + + The package name. + Optional authentication ID for the user. + Credential user flags. + Optional credentials. + The credential handle. + + + + Create a new credential handle. + + The package name. + Credential user flags. + Optional credentials. + The credential handle. + + + + Create a new credential handle. + + The package name. + Credential user flags. + The credential handle. + + + + Dispose. + + + + + Finalizer. + + + + + Credentials for the CredSSP package. + + This is only needed if you must have both schannel and user credentials. Otherwise use UserCredentials or SchannelCredentials. + + + + Constructor. + + The credentials for the Schannel connection. + The credentials for the user. + + + + Constructor. + + The credentials for the user. + + + + Authentication token for a digest token. + + + + + The digest token as a string. + + + + + Format the authentication token. + + + + + + An encrypted message. + + + + + The encrypted message. + + + + + The signature for the message. + + + + + Constructor. + + The encrypted message. + The signature for the message. + + + + Class to represent an exported security context. + + + + + The name of the package for this security context. + + + + + The serialized context. + + + + + The context's token. + + + + + Dispose the exported context. + + + + + A class which represents an GSS-API Token. + + + + + Interface for authentication contexts. + + + + + The current authentication token. + + + + + Whether the authentication is done. + + + + + Expiry of the authentication. + + + + + Session key for the context. + + + + + Make a signature for this context. + + The message to sign. + The sequence number. + The signature blob. + + + + Verify a signature for this context. + + The message to verify. + The signature blob for the message. + The sequence number. + True if the signature is valid, otherwise false. + + + + Make a signature for this context. + + The message buffers to sign. + The sequence number. + The signature blob. + + + + Verify a signature for this context. + + The messages to verify. + The signature blob for the message. + The sequence number. + True if the signature is valid, otherwise false. + + + + Encrypt a message for this context. + + The message to encrypt. + Quality of protection flags. + The encrypted message. + The sequence number. + + + + Encrypt a message for this context. + + The messages to encrypt. + Quality of protection flags. + The signature for the messages. + The messages are encrypted in place. You can add buffers with the ReadOnly flag to prevent them being encrypted. + The sequence number. + + + + Encrypt a message for this context with no specific signature. + + The messages to encrypt. + Quality of protection flags. + The sequence number. + The messages are encrypted in place. You can add buffers with the ReadOnly flag to prevent them being encrypted. + If you need to return a signature then it must be specified in a buffer. + + + + Decrypt a message for this context. + + The message to decrypt. + The sequence number. + The decrypted message. + + + + Decrypt a message for this context. + + The messages to decrypt. + The signature for the messages. + The sequence number. + The messages are decrypted in place. You can add buffers with the ReadOnly flag to prevent them being decrypted. + + + + Decrypt a message for this context. + + The messages to decrypt. + The sequence number. + The messages are decrypted in place. You can add buffers with the ReadOnly flag to prevent them being decrypted. + If you need to specify a signature you need to add a buffer. + + + + Export and delete the current security context. + + The exported security context. + The security context will not longer be usable afterwards. + + + + Query the context's package info. + + The authentication package info, + + + + Get the name of the authentication package. + + + + + Continue the authentication with the token. + + The token to continue authentication. + + + + Continue the authentication.. + + The token to continue authentication. + Additional input buffers for the continue, does not need to include the token. + + + + Continue the authentication. + + The token to continue authentication. + Additional input buffers for the continue, does not need to include the token. + Specify additional output buffers, does not need to include the token. + + + + Continue the authentication. + + Additional input buffers for the continue. Does not contain a token. + Specify additional output buffers, does not need to include the token. + This sends the input buffers directly to the initialize call, it does not contain any token. + + + + Continue the authentication. Will not pass any buffers to the accept call. + + + + + Get the maximum signature size of this context. + + + + + Get the size of the security trailer for this context. + + + + + Interface for a client authentication context. + + + + + Get the last token status for the client context. + + + + + Placeholder interface for a server authentication context. + + + + + Utilities for building Kerberos structures. + + + + + Class to represent a Kerberos AP Reply. + + + + + Encrypted mutual authentication data. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Decrypt the Authentication Token using a keyset. + + The set of keys to decrypt the + The decrypted token, or the same token if nothing could be decrypted. + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The Negotiate authentication token. + Parsed DER Values. + + + + Encrypted part for AP-REP messages. + + + + + Client uS. + + + + + Client time. + + + + + Subkey. + + + + + Sequence number. + + + + + Options for AP Request + + + + + None. + + + + + Use Session Key. + + + + + Mutual authentication required. + + + + + Class to represent a Kerberos AP Request. + + + + + AP Request Options. + + + + + The Kerberos Ticket. + + + + + Authenticator data. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Decrypt the Authentication Token using a keyset. + + The set of keys to decrypt the + The decrypted token, or the same token if nothing could be decrypted. + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The Negotiate authentication token. + Parsed DER Values. + + + + A single kerberos key. + + + + + The Key encryption type. + + + + + The key. + + + + + The key name type. + + + + + The Realm for the key. + + + + + The name components for the key. + + + + + Principal name as a string. + + + + + Timestamp when key was created. + + + + + Key Version Number (KVNO). + + + + + Constructor. + + The Key encryption type. + The key. + The key name type. + The Realm for the key. + The name components for the key. + Timestamp when key was created. + Key Version Number (KVNO). + + + + Constructor. + + The Key encryption type. + The key. + The key name type. + The Realm for the key. + The name components for the key. + Timestamp when key was created. + Key Version Number (KVNO). + + + + Constructor. + + The Key encryption type. + The key. + The key name type. + Principal for key, in form TYPE/name@realm. + Timestamp when key was created. + Key Version Number (KVNO). + + + + Constructor. + + The Key encryption type. + The key as a hex string. + The key name type. + Principal for key, in form TYPE/name@realm. + Timestamp when key was created. + Key Version Number (KVNO). + + + + Derive a key from a password. + + Not all encryption types are supported. + The key encryption to use. + The password to derice from. + Iterations for the password derivation. + The key name type. + Principal for key, in form TYPE/name@realm. + Salt for the key. + Key Version Number (KVNO). + + + + + Authentication Token for Kerberos. + + + + + Protocol version. + + + + + Message type. + + + + + Parse bytes into a kerberos token. + + The kerberos token in bytes. + The Kerberos token. + + + + Try and parse data into an Kerberos authentication token. + + The data to parse. + The Kerberos authentication token. + True if this is a token from a client. + The token count number. + True if parsed successfully. + + + + Class to represent an unencrypted kerberos authenticator. + + + + + Authenticator version. + + + + + Client realm. + + + + + Client name. + + + + + Checksum value. + + + + + Client uS. + + + + + Client time. + + + + + Subkey. + + + + + Sequence number. + + + + + Authorization data. + + + + + Type of Authorization Data. + + + + + Class representing Kerberos authentication data. + + + + + Type of authentication data. + + + + + Data bytes. + + + + + Flags for the AD-AUTH-DATA-AP-OPTIONS authorization data. + + + + + Class to represent the AD-AUTH-DATA-AP-OPTIONS authorization data. + + + + + Flags for the AD-AUTH-DATA-AP-OPTIONS authorization data. + + + + + Class to represent AD_ETYPE_NEGOTIATION type. + + + + + List of supported encryption types. + + + + + Class to represent a KERB_LOCAL authorization data value. + + + + + The security context identifier for the KERB_LOCAL value. + + + + + Class to represent AD_WIN2K_PAC type. + + + + + List of PAC entries. + + + + + Source of a set of claims. + + + + + From Active Directory. + + + + + From a certificate. + + + + + A single claim set. + + + + + The source of the claims array. + + + + + The list of claim attributes. + + + + + Class representing a Claims Set in the PAC. + + + + + List of claims arrays. + + + + + Class to represent PAC Client Info. + + + + + Client ID. + + + + + Name of client. + + + + + Class to represent PAC Device Info. + + + + + Sid of the Device. + + + + + Primary group SID. + + + + + List of account groups. + + + + + List of extra SIDs. + + + + + List of domain groups. + + + + + Type for the PAC Entry. + + + + + Single PAC Entry. + + + + + Type of PAC entry. + + + + + The PAC data. + + + + + User account control flags. + + + + + User flags for kerberos authentication. + + + + + Class to represent PAC Logon Information. + + + + + Logon time. + + + + + Logoff time. + + + + + Kick off time. + + + + + Time password last set. + + + + + Time password can change. + + + + + Time password must change. + + + + + Effective name. + + + + + Full name. + + + + + Logon script path. + + + + + Profile path. + + + + + Home directory path. + + + + + Home directory drive. + + + + + Logon count. + + + + + Bad password count. + + + + + User SID. + + + + + Primary group SID. + + + + + Group list. + + + + + User flags. + + + + + User session key. + + + + + Logon server name. + + + + + Logon domain name. + + + + + Logon domain sid. + + + + + Extra SIDs. + + + + + User account control flags. + + + + + Resource domain group SID. + + + + + Resource groups. + + + + + Class to represent a PAC signature. + + + + + Signature type. + + + + + Signature. + + + + + Read-only Domain Controller Identifier. + + + + + Flags for the UPN_DNS_INFO. + + + + + No flags. + + + + + The user has no UPN. + + + + + Class to represent UPN_DNS_INFO. + + + + + Flags. + + + + + The User Principal Name. + + + + + The DNS Domain Name. + + + + + Flags for KerberosAuthorizationDataRestrictionEntry + + + + + Full UAC token. + + + + + Limited UAC token. + + + + + Class to represent the KERB_AD_RESTRICTION_ENTRY AD type. + + + + + Flags. + + + + + Token IL. + + + + + Machine ID. + + + + + Class to represent the AD-AUTH-DATA-TARGET-NAME authorization data. + + + + + The target name. + + + + + Class to represent a Kerberos Checksum. + + + + + Type of kerberos checksum. + + + + + The checksum value. + + + + + Flags for GSSAPI Checksum. + + + + + A kerberos checksum in GSS API Format. + + + + + Channel binding hash. + + + + + Flags for checksum. + + + + + Delegation option identifier. + + + + + KRB_CRED structure when in delegation. + + + + + Additional extension data. + + + + + Kerberos Checksum Type. + + + + + Class representing a KRB-CRED structure. + + + + + List of tickets in this credential. + + + + + Encrypted part contains sesssion keys etc. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Decrypt the Authentication Token using a keyset. + + The set of keys to decrypt the + The decrypted token, or the same token if nothing could be decrypted. + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The Negotiate authentication token. + Parsed DER Values. + + + + Class to represent Kerberos Encrypted Data. + + + + + Encryption type for the CipherText. + + + + + Key version number. + + + + + Cipher Text. + + + + + Kerberos Encryption Type. + + + + + Class to represent a Kerberos Error. + + + + + Client time. + + + + + Client micro-seconds. + + + + + Server time. + + + + + Server micro-seconds. + + + + + Error code. + + + + + Client realm. + + + + + Client name. + + + + + Server realm. + + + + + Server name, + + + + + Error text. + + + + + Error data. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Create a new KRB-ERROR authentication token. + + Optional client time. + Server time. + Error code. + Optional client realm. + Optional client name. + Server realm + Server name. + Optional error text. + Optional error data. + The KRB-ERROR authentication token. + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The Negotiate authentication token. + Parsed DER Values. + + + + Kerberos Error Type. + + + + + Class to represent a cached external ticket. + + + + + Service name. + + + + + Target name. + + + + + Client name. + + + + + Domain name. + + + + + Target domain name. + + + + + Alt target domain name. + + + + + Session key for ticket. + + + + + Ticket flags. + + + + + Additional reserved flags. + + + + + Key expiration time. + + + + + Ticket start time. + + + + + Ticket end time. + + + + + Ticket renew time. + + + + + Time skew. + + + + + Ticket. + + + + + Type of Kerberos Host Address. + + + + + Class representing a Kerberos Host Address. + + + + + Type of host address. + + + + + Address bytes. + + + + + ToString Method. + + The formatted string. + + + + A set of Kerberos Keys. + + + + + Get keys which match the encryption type. + + The encryption type. + The list of keys which match the encryption type. + + + + Add a key to the key set. + + The key to add. + True if the key was added, false if the key already existed. + + + + Remove a key from the key set. + + The key to remove. + True if the key was removed. + + + + Find a key based on various parameters. + + The encryption type. + The name type. + The principal. + The key version. + + + + + Read keys from a MIT KeyTab file. + + The file stream. + The key set. + Throw if invalid file. + + + + Read keys from a MIT KeyTab file. + + The file path. + The key set. + Throw if invalid file. + + + + Constructor. + + + + + Constructor. + + The single kerberos key. + + + + Constructor. + + A list of kerberos keys. + + + + Key usage for kernel encryption. + + + + + Kerberos Message Type. + + + + + Kerberos Name Type. + + + + + Kerberos Pre-Authentication Data Types. + + + + + A Kerberos Principal Name. + + + + + The name type. + + + + + The names for the principal. + + + + + Full name. + + + + + ToString method. + + String of the object. + + + + Get principal name with a realm. + + The realm for the principal. + The principal. + + + + Constructor. + + The type of the principal name. + The list of names for the principal. + + + + Class to represent a User to User TGT Reply. + + + + + The Kerberos Ticket. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Decrypt the Authentication Token using a keyset. + + The set of keys to decrypt the + The decrypted token, or the same token if nothing could be decrypted. + + + + Create a new TGT-REP authentication token. + + The TGT ticket to embed in the token. + The + + + + Create a new TGT-REP authentication token. + + The TGT ticket to embed in the token. + The + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The Negotiate authentication token. + Parsed DER Values. + + + + Class to represent a User to User TGT Request. + + + + + Realm. + + + + + Server name. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Create a new TGT-REQ authentication token. + + Optional realm string. + Optional server name. + The new TGT-REQ authentication token. + + + + Create a new TGT-REQ authentication token without the GSS-API wrapper. + + Optional realm string. + Optional server name. + The new TGT-REQ authentication token. + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The Negotiate authentication token. + Parsed DER Values. + + + + Class to represent a Kerberos ticket. + + + + + Version number for the ticket. + + + + + Realm. + + + + + Server name. + + + + + Encrypted data for the ticket. + + + + + Get the principal for the ticket. + + + + + Indicates that the ticket has been decrypted. + + + + + Decrypt the kerberos ticket. + + The Kerberos key set containing the keys. + The key usage for the decryption. + The decrypted kerberos ticket. + + + + Format the ticket to a string. + + The ticket as a string. + + + + Convert the ticket to an array. + + The ticket as an array. + + + + Class to query the Kerberos Ticket Cache from LSASS. + + + + + Get a Kerberos Ticket. + + The target service for the Ticket. + True to only query for cached tickets. + True to throw on error. + The Kerberos Ticket. + + + + Get a Kerberos Ticket. + + The target service for the Ticket. + True to only query for cached tickets. + The Kerberos Ticket. + + + + Get a Kerberos Ticket. + + The target service for the Ticket. + The Kerberos Ticket. + + + + Query Kerberos Ticket cache. + + The Logon Session ID to query. + True to throw on error. + The list of cached tickets. + + + + Query Kerberos Ticket cache. + + The Logon Session ID to query. + The list of cached tickets. + + + + Query Kerberos Ticket cache for the current logon session. + + The list of cached tickets. + + + + Flags for a Kerberos Ticket. + + + + + Class to represent a Decrypted Kerberos ticket. + + + + + Ticket flags. + + + + + Client Realm. + + + + + Client name. + + + + + Authentication time, + + + + + Start time. + + + + + End time. + + + + + Renew till time. + + + + + The kerberos session key. + + + + + The ticket transited type information. + + + + + List of host addresses for ticket. + + + + + List of authorization data. + + + + + The supported transited encoding types. + + + + + None. + + + + + X.500 Compress. + + + + + Class to represent a Kerberos Transiting Encoding. + + + + + Transited encoding type. + + + + + Transited encoding data. + + + + + Utilities for Kerberos authentication. + + + + + Read keys from a MIT KeyTab file. + + The file stream. + The list of keys. + Throw if invalid file. + + + + Read keys from a MIT KeyTab file. + + The file path. + The list of keys. + Throw if invalid file. + + + + Write keys to a MIT KeyTab file. + + The file stream. + List of key entries. + + + + Write keys to a MIT KeyTab file. + + The file path. + List of key entries. + + + + Generate an MIT KeyTab file. + + List of key entries. + The keytab file as bytes. + + + + Class to represent a Local Logon Session. + + + + + Logon/Authentication ID for session. + + + + + Username. + + + + + Logon domain. + + + + + Get the FQ User Name. + + + + + Authentication package. + + + + + Logon type. + + + + + Session ID. + + + + + User SID. + + + + + Logon Time. + + + + + Logon Server. + + + + + DNS Domain Name. + + + + + User Principal Name. + + + + + User Flags. + + + + + Last successful logon. + + + + + Last failed logon. + + + + + Count of failed logon attempts. + + + + + Logon script path. + + + + + Profile path. + + + + + Home directory. + + + + + Home directory drive. + + + + + Logoff time. + + + + + Kickoff Time. + + + + + Time password last set. + + + + + Password can change. + + + + + Password must change. + + + + + Get a logon session. + + The logon session ID. + True to thrown on error. + The logon session. + + + + Get the logon session LUIDs + + True throw on error. + The list of logon sessions. Only returns ones you can access. + + + + Get the logon sessions. + + True throw on error. + The list of logon sessions. Only returns ones you can access. + + + + Class to represent an LSA logon handle. + + + + + Connect to the LSA untrusted. + + True to throw on error. + The LSA logon handle. + + + + Connect to the LSA untrusted. + + The LSA logon handle. + + + + Connect to LSA and register as a logon process. + + The arbitrary name of the process. + True to throw on error. + The LSA logon handle. + + + + Connect to LSA and register as a logon process. + + The arbitrary name of the process. + The LSA logon handle. + + + + Logon a user. + + The type of logon. + The authentication package to use. + The name of the origin. + The token source context. + The authentication credentials buffer. + Additional local groups. + True to throw on error. + The LSA logon result. + + + + Logon a user. + + The type of logon. + The authentication package to use. + The name of the origin. + The token source context. + The authentication credentials buffer. + Additional local groups. + The LSA logon result. + + + + Dispose of the LSA logon handle. + + + + + Result from an LsaLogonUser call. + + + + + The user's token. + + + + + The user's profile information. Format depends on the authentication package. + + + + + The authentication ID of the logon session. + + + + + Paged pool quota. + + + + + Non paged pool quota. + + + + + Minimum working set size. + + + + + Maximum working set size. + + + + + Page file limit. + + + + + Process time limit. + + + + + Dispose the LSA logon result. + + + + + SPNEGO Authentication Token. + + + + + The negotiated authentication token. + + + + + Optional message integrity code. + + + + + Decrypt the Authentication Token using a keyset. + + The set of keys to decrypt the + The decrypted token, or the same token if nothing could be decrypted. + + + + Format the authentication token. + + The token as a formatted string. + + + + Parse bytes into a negotiate token. + + The negotiate token in bytes. + The Negotiate token. + + + + Try and parse data into an Negotiate authentication token. + + The data to parse. + The Negotiate authentication token. + True if this is a token from a client. + The token count number. + True if parsed successfully. + + + + Flags for negotiation context. + + + + + Class to represent the negTokenInit message in SPNEGO. + + + + + List of supported negotiation mechanisms. + + + + + Context flags. + + + + + State of the Negotiate state. + + + + + Negotiate completed. + + + + + Negotiate incomplete. + + + + + Negotiate rejected. + + + + + Request Message Integrity Code. + + + + + Class to represent the negTokenResp message in SPNEGO. + + + + + Supported mechanism for the token, optional. + + + + + Current state of the negotiation. + + + + + Class to represent an NTLM AUTHENTICATE token for NTLMv1. + + + + + Domain name. + + + + + Workstation name. + + + + + Username. + + + + + NTLM version. + + + + + Encrypted session key. + + + + + LM Challenge Response. + + + + + LM Challenge Response. + + + + + Message integrity code. + + + + + Message integrity code offset into the token data. + + + + + Format the authentication token. + + The formatted token. + + + + Class to represent an NTLM AUTHENTICATE token for NTLMv2. + + + + + NT Proof Response. + + + + + Challenge version. + + + + + Maximum challenge version. + + + + + Reserved field. + + + + + Reserved field. + + + + + Timestamp. + + + + + Client challenge. + + + + + Reserved field. + + + + + NTLM Target Information. + + + + + Flags for NTLM negotiation. + + + + + NTLM message type. + + + + + Base class to represent an NTLM authentication token. + + + + + Type of NTLM message. + + + + + NTLM negotitation flags. + + + + + Try and parse data into an NTLM authentication token. + + The data to parse. + The NTLM authentication token. + True if this is a token from a client. + The token count number. + True if parsed successfully. + + + + Try and parse data into an NTLM authentication token. + + The data to parse. + The NTLM authentication token. + + + + The type of the AV_PAIR. + + + + + MS AV Flags. + + + + + An NTLM AV_PAIR. + + + + + The type of the AV Pair value. + + + + + An NTLM AV_PAIR with a string value. + + + + + The string value. + + + + + ToString method. + + Pair as a string. + + + + An NTLM AV_PAIR with a timestamp value; + + + + + The timestamp value. + + + + + ToString method. + + Pair as a string. + + + + An NTLM AV_PAIR with a bytes value. + + + + + The value. + + + + + ToString method. + + Pair as a string. + + + + An NTLM AV_PAIR with a flags value. + + + + + The value. + + + + + ToString method. + + Pair as a string. + + + + An NTLM AV_PAIR with a flags value. + + + + + The the Z4 data. + + + + + Custom data blob. + + + + + Machine ID. + + + + + ToString method. + + Pair as a string. + + + + Class to represent an NTLM CHALLENGE token. + + + + + Target name. + + + + + Server challenge. + + + + + Reserved. + + + + + NTLM version. + + + + + NTLM Target Information. + + + + + Format the authentication token. + + The formatted token. + + + + Class to represent an NTLM NEGOTIATE token. + + + + + Domain name. + + + + + Workstation name. + + + + + NTLM version. + + + + + Format the authentication token. + + The formatted token. + + + + Algorithm identifiers for the crypto APIs and Schannel. + + + + + Authentication token for Schannel and CredSSP. + + This is a simple parser for the TLS record format. + + + + List of TLS records. + + + + + Format the authentication token. + + The token as a formatted string. + + + + Try and parse data into an SChannel authentication token. + + The data to parse. + The SChannel authentication token. + True if this is a token from a client. + The token count number. + True if parsed successfully. + + + + Negotiated connection information for Schannel. + + + + + The protocol used by Schannel. + + + + + The negotitated cipher algorithm. + + + + + The negotiated cipher strength in bits. + + + + + The negotiated hash algorithm. + + + + + The negotiated hash string. + + + + + The negotiated key exchange algorithm. + + + + + The negotiated key exchange strength. + + + + + Credentials for the Schannel package. + + + + + Lifespan of a session in milliseconds. + + + + + Specify flags for credentials. + + + + + Specify the supported protocols. + + + + + Set the minimum cipher strength. + + + + + Set the maximum cipher strength. + + + + + Add a certificate the the credentials. This should contain a private key. + + The certificate to add. + + + + Add an algorithm type to the credentials. + + The algorithm type. + + + + Dispose the credentials. + + + + + Flags for the Schannel credentials. + + + + + Protocol type for Schannel. + + + + + Flags for message encryption. + + + + + None. + + + + + Wrap out of bound data. + + + + + Wrap but don't encrypt. + + + + + Class to represent a server authentication context. + + + + + The current authentication token. + + + + + Whether the authentication is done. + + + + + Current request attributes. + + + + + Current data representation. + + + + + Current channel bindings. + + + + + Current return attributes. + + + + + Current status flags. + + + + + Expiry of the authentication. + + + + + Get the client name supplied by the Client. + + + + + Get the Session Key for this context. + + + + + Get the maximum signature size of this context. + + + + + Get the size of the security trailer for this context. + + + + + Size of any header when using a stream protocol such as Schannel. + + + + + Size of any trailer when using a stream protocol such as Schannel. + + + + + Number of buffers needed when using a stream protocol such as Schannel. + + + + + Maximum message size when using a stream protocol such as Schannel. + + + + + Preferred block size when using a stream protocol such as Schannel. + + + + + Get the name of the authentication package. + + + + + Get connection information for the schannel connection. + + + + + Get the local certificate. Only used for Schannel related authentication. + + + + + Get the remote certificate. Only used for Schannel related authentication. + + + + + Get whether the authentication context is for loopback. + + + + + Get or set whether the context owns the credentials object or not. If true + then the credentials are disposed with the context. + + + + + Get an access token for the authenticated user. + + The user's access token. + + + + Impersonate the security context. + + The disposable context to revert the impersonation. + + + + Continue the authentication with the client token. + + The client token to continue authentication. + + + + Continue the authentication.. + + The client token to continue authentication. + Specify additional input buffers, does not need to include the token. + + + + Continue the authentication. + + The client token to continue authentication. + Specify additional input buffers, does not need to include the token. + Specify additional output buffers, does not need to include the token. + + + + Continue the authentication. + + Additional input buffers for the continue. Does not contain a token. + Specify additional output buffers, does not need to include the token. + True to throw on error. + This sends the input buffers directly to the initialize call, it does not contain any token. + + + + Continue the authentication. + + Additional input buffers for the continue. Does not contain a token. + Specify additional output buffers, does not need to include the token. + This sends the input buffers directly to the initialize call, it does not contain any token. + + + + Continue the authentication. Will not pass any buffers to the accept call. + + + + + Make a signature for this context. + + The message buffers to sign. + The sequence number. + The signature blob. + + + + Make a signature for this context. + + The message to sign. + The sequence number. + The signature blob. + + + + Verify a signature for this context. + + The message to verify. + The signature blob for the message. + The sequence number. + True if the signature is valid, otherwise false. + + + + Verify a signature for this context. + + The messages to verify. + The signature blob for the message. + The sequence number. + True if the signature is valid, otherwise false. + + + + Encrypt a message for this context. + + The message to encrypt. + Quality of protection flags. + The encrypted message. + The sequence number. + + + + Encrypt a message for this context. + + The messages to encrypt. + Quality of protection flags. + The signature for the messages. + The messages are encrypted in place. You can add buffers with the ReadOnly flag to prevent them being encrypted. + The sequence number. + + + + Encrypt a message for this context with no specific signature. + + The messages to encrypt. + Quality of protection flags. + The sequence number. + The messages are encrypted in place. You can add buffers with the ReadOnly flag to prevent them being encrypted. + If you need to return a signature then it must be specified in a buffer. + + + + Decrypt a message for this context. + + The messages to decrypt. + The sequence number. + The signature for the messages. + The messages are decrypted in place. You can add buffers with the ReadOnly flag to prevent them being decrypted. + + + + Decrypt a message for this context. + + The messages to decrypt. + The sequence number. + The messages are decrypted in place. You can add buffers with the ReadOnly flag to prevent them being decrypted. + If you need to specify a signature you need to add a buffer. + + + + Decrypt a message for this context. + + The message to decrypt. + The sequence number. + The decrypted message. + + + + Query the context's package info. + + The authentication package info, + + + + Export and delete the current security context. + + The exported security context. + The security context will not longer be usable afterwards. + + + + Constructor. + + Credential handle. + Request attribute flags. + Optional channel binding token. + Data representation. + + + + Constructor. + + Credential handle. + Request attribute flags. + Data representation. + + + + Constructor. + + Credential handle. + + + + Dispose the client context. + + + + + Finalizer. + + + + + Class to represent a service principal name. + + + + + SPN service class. + + + + + SPN service name. + + + + + SPN instance name. + + + + + SPN instance port. + + + + + SPN referrer. + + + + + Constructor. + + The service class name. + The name of the instance. + + + + Parse an SPN string to a class. + + The SPN string. + The parsed class. + Thrown in invalid SPN. + + + + Try and parse an SPN string to a class. + + The SPN string. + The result class. + True if the SPN was parsed successfully. + Thrown in invalid SPN. + + + + Convert SPN to a string. + + The SPN string. + + + + Class to hold user credentials. + + + + + The user name. + + + + + The domain. + + + + + The password as a secure string. + + + + + Constructor. + + Username. + Domain name. + Password. + + + + Set the password as in plain text. + + The password in plain text. + + + + Constructor. + + Username. + Domain name. + Password. + + + + Constructor. + + Username. + Domain name. + + + + Constructor. + + Username. + + + + Constructor. + + + + + Dispose method. + + + + + Class to represent a single authenticode certificate entry. + + + + + The list of certificates in the entry. + + + + + Whethe the entry contains page hashes. + + + + + Utilities for authenticode. + + + + + Get certificates from a PE file. + + The PE file. + True the throw on error. + The list of authenticode certificate entries. + + + + Get certificates from a PE file. + + The path to the PE file. + True the throw on error. + The list of authenticode certificate entries. + + + + Get certificates from a PE file. + + The path to the PE file, native path format. + The list of authenticode certificate entries. + + + + Gets wether the PE file has page hash entries. + + The path to the PE file, native path format. + True if the file contains page hashes. + + + + Query ELAM information from a driver's resource section. + + The path to the file. + True to throw on error. + The ELAM information if present. + + + + Query ELAM information from a driver's resource section. + + The path to the file. + The ELAM information if present. + + + + Get the VSM enclave configuration. + + The path to the file. + True to throw on error. + The VSM enclave configuration. + + + + Get the VSM enclave configuration. + + The path to the file. + The VSM enclave configuration. + + + + ELAM information. + + + + + The hash of the certificate. + + + + + The hash algorithm. + + + + + List of optional EKUs. + + + + + Overridden ToString method. + + The ELAM information as a string. + + + + Class to represent a VSM enclave configuration. + + + + + Minimum required configuration size. + + + + + Policy flags. + + + + + List of enclave imports. + + + + + Family ID. + + + + + Image ID. + + + + + Image version. + + + + + Security version. + + + + + Size of the enclave. + + + + + Number of threads for the enclave. + + + + + Enclave flags. + + + + + Is the enclave debuggable. + + + + + Is this a primary image. + + + + + Path to the image file. + + + + + Name of the image file. + + + + + ToString method. + + The object as a string. + + + + Class to represent an enclave import. + + + + + Match type for the import. + + + + + Minimum security version. + + + + + Unique or author ID. + + + + + Family ID. + + + + + Image ID. + + + + + Import name. + + + + + ToString method. + + The name of the import. + + + + Image policy entry. + + + + + Type of entry. + + + + + Policy ID. + + + + + Value of entry. + + + + + Image policy ID. + + + + + Class to represnt image policy metadata. + + + + + Version of the metadata. + + + + + The ID of the trustlet. + + + + + The optional policies for the trustlet. + + + + + Overridden ToString method. + + The object as a string. + + + + Extract image policy metadata from an image file. + + The path to the image file. Should be a win32 path. + True to throw on error. + The image policy metadata. + + + + Extract image policy metadata from an image file. + + The path to the image file. Should be a win32 path. + The image policy metadata. + + + + Access check result from AuthZ. + + + + + The Win32 error code from the access check. + + + + + Class to represent an AuthZ client context. + + + + + Get AuthZ user + + + + + Get AuthZ context groups. + + + + + Get AuthZ context restricted SIDs. + + + + + Get AuthZ context device groups. + + + + + Get AuthZ context capability SIDs. + + + + + Get AuthZ context's security attributes + + + + + Get AuthZ context's device claims. + + + + + Get AuthZ context's user claims. + + + + + Get list of privileges for the AuthZ context. + + The list of privileges + Thrown if can't query privileges + + + + Get AppContainer SID. + + + + + Indicates if this context is connected to a remote access server. + + + + + Set AppContainer Information to Context. + + The package SID. + List of capabilities. + True to throw on error + The NT status code. + + + + Set AppContainer Information to Context. + + The package SID. + List of capabilities. + + + + Modify groups in the context. + + The type of group to modify. + The list of groups to modify. + The list of operations. Should be same size of group list. + True to throw on error. + The NT status code. + + + + Modify groups in the context. + + The type of group to modify. + The list of groups to modify. + The list of operations. Should be same size of group list. + + + + Modify groups in the context. + + The type of group to modify. + The list of SIDs to modify. + The attributes for the SIDs. + The operation for the SIDs. + + + + Modify groups in the context. + + The type of group to modify. + The list of SIDs to modify. + The operation for the SIDs. + + + + Add a SID to the context. + + The SID to add. + + + + Add a Device SID to the context. + + The SID to add. + + + + Add a Device SID to the context. + + The SID to add. + + + + Add a list of SIDs to the context. + + The list of SIDS. + + + + Get list of groups for the AuthZ context. + + The group type. + True to throw on error. + The list of groups. + + + + Get list of groups for the AuthZ context. + + The group type. + The list of groups. + + + + Get the user from the AuthZ context. + + True to throw on error. + The user group information. + + + + Get the AppContainer SID from the AuthZ context. + + True to throw on error. + The AppContainer SID. + + + + Get AuthZ context's security attributes + + Specify the type of security attributes to query. + Throw on error. + The security attributes. + + + + Get token privileges. + + True to throw on error. + The list of privileges. + + + + Perform an Access Check. + + The security descriptor for the check. + Optional list of security descriptors to merge. + The desired access. + Optional Principal SID. + Optional list of object types. + NT Type for access checking. + True to throw on error. + The list of access check results. + The list of object types is restricted to 256 entries for remote access checks. + + + + Perform an Access Check. + + The security descriptor for the check. + Optional list of security descriptors to merge. + The desired access. + Optional Principal SID. + Optional list of object types. + NT Type for access checking. + The list of access check results. + The list of object types is restricted to 256 entries for remote access checks. + + + + Dispose client context. + + + + + Clone the current context. + + True to throw on error. + The new client context. + + + + Clone the current context. + + The new client context. + + + + Flags to initialize a client context from a SID. + + + + + None. + + + + + Skip gathering token groups. + + + + + Require S4U logon. + + + + + Computer token privileges. + + + + + Specify the type of SIDs. + + + + + Normal Group SIDs. + + + + + Restricted SIDs. + + + + + Device Group SIDs. + + + + + Capability SIDs. + + + + + Delegate to handle a callback ACE. + + The ACE to handle. + True if the ACE should be processed. + + + + Class to represent a AuthZ Resource Manager. + + + + + The name of the resource manager if any. + + + + + Indicates if this resource manager is connected to a remote access server. + + + + + Dispose the resource manager. + + + + + Create a client context from a Token. + + The token to create the context from. + True to throw on error. + The created client context. + + + + Create a client context from a Token. + + The token to create the context from. + The created client context. + + + + Create a client context from a Token. + + The sid to create the context from. + Flags for intialization. + True to throw on error. + The created client context. + + + + Create a client context from a Token. + + The sid to create the context from. + Flags for intialization. + The created client context. + + + + Create a new AuthZ resource manager. + + The name of the resource manager, optional. + Optional flags for the resource manager. + Optional callback to handle callback ACEs. + True to throw on error. + The created AuthZ resource manager. + + + + Create a new AuthZ resource manager. + + The name of the resource manager, optional. + Optional flags for the resource manager. + Optional callback to handle callback ACEs. + The created AuthZ resource manager. + + + + Create a new AuthZ resource manager. Will not enable auditing. + + The created AuthZ resource manager. + + + + Create a remote AuthZ resource manager from a raw binding string. + + The RPC string binding for the server. + The SPN for the server. + True to throw on error. + The created AuthZ resource manager. + + + + Create a remote AuthZ resource manager from a raw binding string. + + The RPC string binding for the server. + The SPN for the server. + The created AuthZ resource manager. + + + + Create a remote AuthZ resource manager from a raw binding string. + + The address of the server. + The SPN for the server. + Specify the type of + True to throw on error. + The created AuthZ resource manager. + + + + Create a remote AuthZ resource manager from a raw binding string. + + The network address of the server. + The SPN for the server. + Specify the type of + The created AuthZ resource manager. + + + + Initialization flags for resource manager. + + + + + None + + + + + Disable auditing. + + + + + Initialize using impersonation token. + + + + + Disable central access policies. + + + + + Type of remote service to access. + + + + + Default, no evaluation of CAPs. + + + + + Evaluates CAPs. + + + + + Security Attribute type. + + + + + Token Security Attributes. + + + + + Device Claims. + + + + + User Claims. + + + + + SID operation for an AuthZ client context. + + + + + None. + + + + + Replace all SIDs. + + + + + Add SIDs. + + + + + Delete SIDs. + + + + + Replace SIDs. + + + + + Progress invoke setting for tree security. + + + + + The source of inheritance for a resource. + + + + + The depth between the resource and the parent. + + + + + The name of the ancestor. + + + + + The security descriptor if accessible. + + + + + The original ACE which was inherited. + + + + + The SID of the original ACE. + + + + + Access mask as a formatted string. + + + + + Generic access mask as a formatted string. + + + + + The type of the ACE. + + + + + The object type of the ACE. + + + + + The inherited object type. + + + + + Enumeration for object type. + + + + + Tree security mode. + + + + + Progress function for tree named security info. + + The name of the object. + The operation status. + The current invoke setting. + True if security is set. + The invoke setting. Return original invoke_setting if no change. + + + + Base security buffer storage. + + + + + Type of the security buffer. + + + + + Is the buffer read-only. + + + + + Is the buffer read-only with checksum. + + + + + Convert to buffer back to an array. + + The buffer as an array. + + + + Overridden ToString method. + + The buffer as a string. + + + + Class to represent a security buffer we expect to be allocated by the SSPI. + + + + + Constructor. + + The type of the buffer. + + + + Convert to buffer back to an array. + + The buffer as an array. + + + + Security buffer for a channel binding. + + + + + Constructor. + + The channel bindings token. + + + + Convert to buffer back to an array. + + The buffer as an array. + + + + A security buffer which can be an input and output. + + If you create with the ReadOnly or ReadOnlyWithCheck types then the + array will not be updated. + + + + Constructor. + + The type of buffer. + The data for the input. + + + + Constructor. + + The type of buffer. + The data for the input. + The offset into the array. + Number of bytes in the input. + + + + Convert to buffer back to an array. + + The buffer as an array. + + + + A security buffer which can only be an output. + + + + + Constructor. + + The type of buffer. + The size of the output buffer. + + + + Convert to buffer back to an array. + + The buffer as an array. + + + + A security buffer which takes a raw pointer. The lifetime of the pointer + should be managed manually by the caller. + + + + + Constructor. + + The type of buffer. + The raw pointer. + The size of the raw pointer. + + + + The size of the buffer. + + + + + The pointer for the buffer. The lifetime needs to be manually managed. + + + + + This will free pointer using the SSPI APIs. Used to release automatically allocated + buffers. If you control the value of the Pointer you don't need to release it. + + + + + Convert to buffer back to an array. + + The buffer as an array. + + + + Security buffer type. + + + + + Class to represent a credential manager credential. + + + + + Credential flags. + + + + + Credential type. + + + + + Target name for the credentials. + + + + + Comment for the credentials. + + + + + Time the credentials was last written. + + + + + Credential blob. + + + + + Credential as a string, if available. + + + + + Credential persistence. + + + + + Credential attributes. + + + + + Target alias. + + + + + Username. + + + + + Class to represent a credential attribute. + + + + + Attribute keyword. + + + + + Attribute flags. + + + + + Attribute value. + + + + + Overridden ToString method. + + + + + + Flags for a credential attribute. + + + + + No flags. + + + + + Flags for enumeration credentials. + + + + + None. + + + + + Get all credentials. + + + + + Flags for a credential. + + + + + Class to access credential manager APIs. + + + + + Get credentials for user from credential manager. + + A filter for the target name, for example DOMAIN*. If null or empty returns all credentials. + Flags for the enumeration. + True to throw on error. + The list of credentials. + + + + Get credentials for user from credential manager. + + A filter for the target name, for example DOMAIN*. If null or empty returns all credentials. + Flags for the enumeration. + The list of credentials. + + + + Get credentials for user from credential manager. + + A filter for the target name, for example DOMAIN*. If null or empty returns all credentials. + The list of credentials. + + + + Get all credentials for user from credential manager. + + The list of credentials. + + + + Get a credential by name. + + The name of the credential. + The type of credential. + True to throw on error. + The read credential. + + + + Get a credential by name. + + The name of the credential. + The type of credential. + The read credential. + + + + Backup a user's credentials. + + The user's token. + The key for the data, typically a unicode password. Optional + True if the key is already encoded. + Caller needs SeTrustedCredmanAccessPrivilege enabled. + + + + Specify credential persistence. + + + + + Identifies the type of credentials. + + + + + Information class for a SAM domain object. + + + + + Logon32 provider + + + + + Default. + + + + + Windows NT 3.5. + + + + + Windows NT 4.0. + + + + + Windows NT 5.0. + + + + + Virtual provider. + + + + + Logon UserFlags. + + + + + Indicates the last client token status for the client context. + + + + + Yes it's the last token. + + + + + No it's not the last token. + + + + + It might be, who knows? + + + + + Status code for SSPI interface calls. + + + + + Class to represent an Account Right assigned to a user. + + + + + The name of the account right. + + + + + The display name, if known. + + + + + Get list of SIDS assigned to this access right. + + + + + ToString method. + + The name of the account right. + + + + List of account rights. Not the same as privileges. + + + + + Class to represent an LSA account object. + + + + + Get the account SID. + + + + + Get or set system access flags. + + + + + Get account privileges. + + + + + Get system access flags. + + True to throw on error. + The system access flags. + + + + Set system access flags. + + The flags to set. + True to throw on error. + The system access flags. + + + + Enumerate privileges for the account. + + True to throw on error. + The list of token privileges. + + + + Access rights for an LSA account. + + + + + Flags for looking up SIDs by name. + + + + + Flags for looking up SID names. + + + + + Base class for an LSA object. + + + + + Get the NT type for the object. + + + + + Get the object name for the object. + + + + + Get whether the object is a container. + + + + + Get the object's security descriptor. + + + + + Is an access mask granted to the object. + + The access to check. + True if all access is granted. + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + The NT status code. + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + + + + Delete the object. + + True to throw on error. + The NT status code. + + + + Delete the object. + + + + + Get the system name for the policy. + + + + + Dispose the policy. + + + + + Class to represent the LSA policy. + + + + + Lookup names for SIDs. + + The list of SIDs to lookup. + True to throw on error. + The list of looked up SID names. + + + + Lookup names for SIDs. + + The list of SIDs to lookup. + The list of looked up SID names. + + + + Lookup name for a SID. + + The SID to lookup. + + + + + Lookup names for SIDs. + + The list of SIDs to lookup. + Lookup options flags. + True to throw on error. + The list of looked up SID names. + + + + Lookup names for SIDs. + + The list of SIDs to lookup. + Lookup options flags. + The list of looked up SID names. + + + + Lookup names from the LSA policy. + + The names to lookup. + Flags for the lookup. + True to throw on error. + The list of SID names. + + + + Lookup names from the LSA policy. + + The names to lookup. + Flags for the lookup. + The list of SID names. + + + + Lookup names from the LSA policy. + + The names to lookup. + The list of SID names. + + + + Lookup names from the LSA policy. + + The name to lookup. + The looked up SID name. + + + + Enumerate accounts with a user right. + + The name of the user right. + True to throw on error. + The list of SIDs with the user right. + + + + Enumerate accounts with a user right. + + The name of the user right. + The list of SIDs with the user right. + + + + Enumerate account rights for a SID. + + The SID to enumerate for. + True to throw on error. + The list of assigned account rights. + + + + Enumerate account rights for a SID. + + The SID to enumerate for. + The list of assigned account rights. + + + + Add account rights to an account. + + The SID of the account. + The list of account rights to add. + True to throw on error. + The NT status code. + + + + Add account rights to an account. + + The SID of the account. + The list of account rights to add. + + + + Remove account rights from an account. + + The SID of the account. + True to remove all rights. + The account rights to add. + True to throw on error. + The NT status code. + + + + Remove account rights from an account. + + The SID of the account. + True to remove all rights. + The account rights to add. + + + + Retrieve LSA privilege data. + + The name of the key. + True to throw on error. + The private data as bytes. + + + + Retrieve LSA privilege data. + + The name of the key. + The private data as bytes. + + + + Store LSA private data. + + The name of the key. + The data to store. If you pass null then the value will be deleted. + True to throw on error. + The NT status code. + + + + Store LSA private data. + + The name of the key. + The data to store. If you pass null then the value will be deleted. + + + + Open an LSA secret object. + + The name of the secret. + The desired access for the secret. + True to throw on error. + The opened secret. + + + + Open an LSA secret object. + + The name of the secret. + The desired access for the secret. + The opened secret. + + + + Open an LSA secret object with maximum access. + + The name of the secret. + The opened secret. + + + + Create an LSA secret object. + + The name of the secret. + The desired access for the secret. + True to throw on error. + The created secret. + + + + Create an LSA secret object. + + The name of the secret. + The desired access for the secret. + The created secret. + + + + Create an LSA secret object with maximum access. + + The name of the secret. + The created secret. + + + + Delete an LSA secret object. + + The name of the secret. + True to throw on error. + The NT status code. + + + + Delete an LSA secret object. + + The name of the secret. + + + + Open an LSA account object. + + The SID of the account. + The desired access for the account. + True to throw on error. + The opened account. + + + + Open an LSA account object. + + The SID of the account. + The desired access for the account. + The opened account. + + + + Open an LSA account object with maximum access. + + The SID of the account. + The opened account. + + + + Create an LSA account object. + + The SID of the account. + The desired access for the account. + True to throw on error. + The created account. + + + + Create an LSA account object. + + The SID of the account. + The desired access for the account. + The created account. + + + + Create an LSA account object with maximum access. + + The SID of the account. + The created account. + + + + Delete an LSA account object. + + The SID of the account. + True to throw on error. + The NT status code. + + + + Delete an LSA account object. + + The SID of the account. + + + + Enumerate account SIDs in policy. + + True to throw on error. + The list of account SIDs. + + + + Enumerate account SIDs in policy. + + The list of account SIDs. + + + + Enumerate and open accessible account objects in policy. + + The desired access for the opened accounts. + True to throw on error. + The list of accessible accounts. + + + + Enumerate and open accessible account objects in policy. + + The desired access for the opened accounts. + + + + Enumerate and open accessible account objects in policy with maximum access. + + + + + Enumerate trusted domain information. + + True to throw on error. + The list of trusted domain information. + + + + Enumerate trusted domain information. + + The list of trusted domain information. + + + + Open trusted domain object. + + The SID of the trusted domain. + The desired access for the object. + True to throw on error. + The trusted domain object. + + + + Open trusted domain object. + + The SID of the trusted domain. + The desired access for the object. + The trusted domain object. + + + + Open trusted domain object. + + The name of the trusted domain. + The desired access for the object. + True to throw on error. + The trusted domain object. + + + + Open trusted domain object. + + The name of the trusted domain. + The desired access for the object. + The trusted domain object. + + + + Enumerate and open accessible trusted domain objects in policy. + + The desired access for the opened trusted domains. + True to throw on error. + The list of accessible trusted domains. + + + + Enumerate and open accessible trusted domain objects in policy. + + The desired access for the opened trusted domains. + The list of accessible trusted domains. + + + + Enumerate and open accessible trusted domain objects in policy. + + The list of accessible trusted domains. + + + + Open an LSA policy. + + The system name for the LSA. + The desired access on the policy. + True to throw on error. + The opened policy. + + + + Open an LSA policy. + + The desired access on the policy. + True to throw on error. + The opened policy. + + + + Open an LSA policy. + + The system name for the LSA. + The desired access on the policy. + The opened policy. + + + + Open an LSA policy. + + The desired access on the policy. + The opened policy. + + + + Open an LSA policy with maximum allowed access. + + The opened policy. + + + + Access rights for the LSA policy. + + + + + Utilities for an LSA policy. + + + + + The name of the fake NT type for a LSA policy. + + + + + The name of the fake NT type for a LSA secret. + + + + + The name of the fake NT type for a LSA account. + + + + + The name of the fake NT type for a LSA trusted domain. + + + + + Generic generic mapping for LSA policy security. + + The generic mapping for the LSA policy. + + + + Generic generic mapping for LSA secret security. + + The generic mapping for the LSA secret. + + + + Generic generic mapping for LSA account security. + + The generic mapping for the LSA account. + + + + Generic generic mapping for LSA trusted domain security. + + The generic mapping for the LSA trusted domain. + + + + Class to represent an LSA secret. + + + + + Query the value of the secret. + + True to throw on error. + The value of the secret. + + + + Query the value of the secret. + + The value of the secret. + + + + Query the current value of the secret. + + True to throw on error. + The current value of the secret. + + + + Query the current value of the secret. + + The current value of the secret. + + + + Query the old value of the secret. + + True to throw on error. + The old value of the secret. + + + + Query the old value of the secret. + + The old value of the secret. + + + + Set the value of the secret. + + The current value to set. + The old value to set. + True to throw on error. + The NT status code. + + + + Set the value of the secret. + + The current value to set. + The old value to set. + + + + Access rights for an LSA secret. + + + + + Class to represent an LSA secret value. + + + + + The current value of the secret. + + + + + The set time for the current value. + + + + + The old value of the secret. + + + + + The set time for the old value. + + + + + Flags for an account's system access. + + + + + Trust attribute flags for a trusted domain. + + + + + Direction of trust for a trusted domain. + + + + + Class to represent an LSA trusted domain. + + + + + Flat name (NETBIOS) of domain. + + + + + Domain SID. + + + + + Name of the domain. + + + + + Domain trust direction. + + + + + Domain trust type. + + + + + Domain trust attributes. + + + + + Access rights for an LSA trusted domain. + + + + + Information for a trusted domain. + + + + + DNS name of domain. + + + + + Flat name (NETBIOS) of domain. + + + + + Domain SID. + + + + + Domain trust direction. + + + + + Domain trust type. + + + + + Domain trust attributes. + + + + + Trust type for a trusted domain. + + + + + Class to represent a SAM alias. + + + + + Get members of the alias. + + True to throw on error. + The list of alias members. + + + + Get members of the alias. + + The list of alias members. + + + + The alias name. + + + + + The SID of the alias. + + + + + Access rights for a SAM alias object. + + + + + Class to represent a SAM domain object. + + + + + The domain name. + + + + + The domain SID. + + + + + Get domain password information + + + + + Lookup names in a domain. + + The list of names to lookup. + True to throw on error. + The list of looked up SID names. + + + + Lookup names in a domain. + + The list of names to lookup. + The list of looked up SID names. + + + + Lookup a name in a domain. + + The name to lookup. + True to throw on error. + The SID name. + + + + Lookup a name in a domain. + + The name to lookup. + The SID name. + + + + Lookup relative IDs in a domain. + + The list of relative IDs to lookup. + True to throw on error. + The list of looked up SID names. + + + + Lookup relative IDs in a domain. + + The list of relative IDs to lookup. + The list of looked up SID names. + + + + Lookup a rid in a domain. + + The relative ID to lookup. + True to throw on error. + The SID name. + + + + Lookup a rid in a domain. + + The relative ID to lookup. + The SID name. + + + + Enumerate users in a domain. + + User account control flags. + True to throw on error. + The list of users. + + + + Enumerate users in a domain. + + User account control flags. + The list of users. + + + + Enumerate users in a domain. + + The list of users. + + + + Enumerate groups in a domain. + + True to throw on error. + The list of groups. + + + + Enumerate groups in a domain. + + The list of groups. + + + + Enumerate aliases in a domain. + + True to throw on error. + The list of aliases. + + + + Enumerate aliases in a domain. + + The list of aliases. + + + + Get alias membership for a set of SIDs. + + The SIDs to check. + True to throw on error. + The alias enumeration. + + + + Get alias membership for a set of SIDs. + + The SIDs to check. + The alias enumeration. + + + + Get alias membership for a SID. + + The SID to check. + The alias enumeration. + + + + Open a user by relative ID. + + The user ID for the user. + The desired access for the user object. + True to throw on error. + The SAM user object. + + + + Open a user by relative ID. + + The user ID for the user. + The desired access for the user object. + The SAM user object. + + + + Open a user by SID. + + The sid for the user. + The desired access for the user object. + True to throw on error. + The SAM user object. + + + + Open a user by SID. + + The sid for the user. + The desired access for the user object. + The SAM user object. + + + + Open a user by name. + + The user name for the user. + The desired access for the user object. + True to throw on error. + The SAM user object. + + + + Open a user by name. + + The user name for the user. + The desired access for the user object. + The SAM user object. + + + + Open a group by relative ID. + + The ID for the group. + The desired access for the group object. + True to throw on error. + The SAM group object. + + + + Open a group by relative ID. + + The ID for the group. + The desired access for the group object. + The SAM group object. + + + + Open a group by SID. + + The sid for the group. + The desired access for the group object. + True to throw on error. + The SAM group object. + + + + Open a group by SID. + + The sid for the group. + The desired access for the group object. + The SAM group object. + + + + Open a group by name. + + The name for the group. + The desired access for the group object. + True to throw on error. + The SAM group object. + + + + Open a group by name. + + The name for the group. + The desired access for the group object. + The SAM group object. + + + + Create a new group object. + + The name of the group. + The desired access for the group object. + True to throw on error. + The SAM group object. + + + + Create a new group object. + + The name of the group. + The desired access for the group object. + The SAM group object. + + + + Create a new group object. + + The name of the group. + The SAM group object. + + + + Create a new user in the SAM. + + The name of the user. + The type of account. + Desired access for new user. + True to throw on error. + The SAM user object. + + + + Create a new user in the SAM. + + The name of the user. + The type of account. + Desired access for new user. + The SAM user object. + + + + Open an alias by relative ID. + + The ID for the alias. + The desired access for the alias object. + True to throw on error. + The SAM alias object. + + + + Open an alias by relative ID. + + The ID for the alias. + The desired access for the alias object. + The SAM alias object. + + + + Open an alias by SID. + + The sid for the alias. + The desired access for the alias object. + True to throw on error. + The SAM alias object. + + + + Open an alias by SID. + + The sid for the alias. + The desired access for the alias object. + The SAM alias object. + + + + Open an alias by name. + + The name for the alias. + The desired access for the alias object. + True to throw on error. + The SAM alias object. + + + + Open an alias by name. + + The name for the alias. + The desired access for the alias object. + The SAM alias object. + + + + Enumerate and open accessible user objects. + + User account control flags. + The desired access for the opened users. + True to throw on error. + The list of accessible users. + + + + Enumerate and open accessible user objects. + + User account control flags. + The desired access for the opened users. + The list of accessible users. + + + + Enumerate and open accessible user objects with maximum access. + + The list of accessible users. + + + + Enumerate and open accessible group objects. + + The desired access for the opened groups. + True to throw on error. + The list of accessible groups. + + + + Enumerate and open accessible group objects. + + The desired access for the opened groups. + The list of accessible groups. + + + + Enumerate and open accessible group objects with maximum access. + + The list of accessible groups. + + + + Enumerate and open accessible alias objects. + + The desired access for the opened aliases. + True to throw on error. + The list of accessible aliases. + + + + Enumerate and open accessible alias objects. + + The desired access for the opened aliases. + The list of accessible aliases. + + + + Enumerate and open accessible alias objects with maximum access. + + The list of accessible aliases. + + + + Convert a RID to a SID for the current object. + + The relative ID. + True to throw on error. + The converted SID. + + + + Convert a RID to a SID for the current object. + + The relative ID. + The converted SID. + + + + Get password information. + + True to throw on error. + + + + + Access rights for a SAM domain object. + + + + + The domain password policy. + + + + + Minimum password length. + + + + + Password history length. + + + + + Password properties flags. + + + + + Maximum password age. + + + + + Minimum password age. + + + + + Flags for password properties. + + + + + Class to represent a SAM group. + + + + + Get members of the group. + + True to throw on error. + The list of group members. + + + + Get members of the group. + + The list of group members. + + + + Query group attribute flags. + + True to throw on error. + The group attribute flags. + + + + Set the group attribute flags. + + The attributes to set. + True to throw on error. + The NT status code. + + + + Delete the group object. + + True to throw on error. + The NT status code. + + + + Delete the group object. + + + + + The group name. + + + + + The SID of the group. + + + + + Get or set the group attribute flags. + + + + + Access rights for the SAM group. + + + + + Membership entry for a group. + + + + + The group relative ID. + + + + + The attributes for the group. + + + + + Base class for a SAM object. + + + + + The name of the server that we've connected to. + + + + + Get the NT type for the object. + + + + + Get the object name for the object. + + + + + Get whether the object is a container. + + + + + Get the object's security descriptor. + + + + + Is an access mask granted to the object. + + The access to check. + True if all access is granted. + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + The NT status code. + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + + + + Dispose the policy. + + + + + Represents information for a SAM relative value. + + + + + The name of the domain. + + + + + The RID of the domain. + + + + + Class to represent a connection to a SAM server. + + + + + Enumerate domains in the SAM. + + True to throw on error. + The list of domains. + + + + Enumerate domains in the SAM. + + The list of domains. + + + + Lookup the domain SID for a domain name. + + The name of the domain. + True to throw on error. + The domain SID. + + + + Lookup the domain SID for a domain name. + + The name of the domain. + The domain SID. + + + + Open a SAM domain object. + + The domain SID. + The desired access for the object. + True to throw on error. + The SAM domain object. + + + + Open a SAM domain object. + + The domain SID. + The desired access for the object. + The SAM domain object. + + + + Open a SAM domain object. + + The name of the domain. + The desired access for the object. + True to throw on error. + The SAM domain object. + + + + Open a SAM domain object. + + The name of the domain. + The desired access for the object. + The SAM domain object. + + + + Enumerate and open accessible domain objects. + + The desired access for the opened domains. + True to throw on error. + The list of accessible domains. + + + + Enumerate and open accessible domain objects. + + The desired access for the opened domains. + The list of accessible domains. + + + + Opens the builtin domain on the server. + + The desired access for the object. + True to throw on error. + The SAM domain object. + + + + Opens the builtin domain on the server. + + The desired access for the object. + The SAM domain object. + + + + Opens the user domain on the server. + + The desired access for the object. + True to throw on error. + The SAM domain object. + + + + Opens the user domain on the server. + + The desired access for the object. + The SAM domain object. + + + + Connect to a SAM server. + + The name of the server. Set to null for local connection. + The desired access on the SAM server. + True to throw on error. + The server connection. + + + + Connect to a SAM server. + + The name of the server. Set to null for local connection. + The desired access on the SAM server. + The server connection. + + + + Connect to a SAM server. + + The desired access on the SAM server. + The server connection. + + + + Connect to a SAM server with maximum access. + + The server connection. + + + + Access rights for the SAM server. + + + + + Class to represent a SAM user. + + + + + Get full name for the user. + + True to throw on error. + The full name of the user. + + + + Get home directory for the user. + + True to throw on error. + The home directory of the user. + + + + Get primary group ID for the user. + + True to throw on error. + The primary group ID of the user. + + + + Get user account control flags for the user. + + True to throw on error. + The user account control flags of the user. + + + + Change a user's password. + + The old password. + The new password. + True to throw on error. + The NT status code. + + + + Change a user's password. + + The old password. + The new password. + + + + Set a user's password. + + The password to set. + Whether the password has expired. + True to throw on error. + The NT status code. + + + + Set a user's password. + + The password to set. + Whether the password has expired. + + + + The user name. + + + + + The SID of the user. + + + + + Get full name for the user. + + + + + Get home directory for the user. + + + + + Get user account control flags for the user. + + + + + Is the account disabled? + + + + + Get the primary group SID. + + + + + Access rights for a SAM user object. + + + + + Type of user account to create. + + + + + A user account. + + + + + A workstation trust account. + + + + + A server trust account. + + + + + A temporary duplicate account. + + + + + Inter domain trust account. + + + + + User account control flags. + + + + + Security utilities which call the Win32 APIs. + + + + + Set security using a named object. + + The name of the object. + The type of named object. + The security information to set. + The security descriptor to set. + True to throw on error. + The NT status code. + + + + Set security using a named object. + + The name of the object. + The type of named object. + The security information to set. + The security descriptor to set. + Specify to indicate when to execute progress function. + The security operation to perform on the tree. + Progress function. + + + + Set security using a named object. + + The name of the object. + The type of named object. + The security information to set. + The security descriptor to set. + Specify to indicate when to execute progress function. + The security operation to perform on the tree. + Progress function. + True to throw on error. + The NT status code. + + + + Set security using a named object. + + The name of the object. + The type of named object. + The security information to set. + The security descriptor to set. + The Win32 Error Code. + + + + Set security using an object handle. + + The handle of the object. + The type of object. + The security information to set. + The security descriptor to set. + True to throw on error. + The NT status code. + + + + Set security using an object handle. + + The handle of the object. + The type of object. + The security information to set. + The security descriptor to set. + + + + Set security using an object handle. + + The handle of the object. + The type of object. + The security information to set. + The security descriptor to set. + True to throw on error. + The NT status code. + + + + Set security using an object handle. + + The handle of the object. + The type of object. + The security information to set. + The security descriptor to set. + + + + Reset security using a named object. + + The name of the object. + The type of named object. + The security information to set. + The security descriptor to set. + True to keep explicit ACEs. + Specify to indicate when to execute progress function. + Progress function. + + + + Reset security using a named object. + + The name of the object. + The type of named object. + The security information to set. + The security descriptor to set. + Specify to indicate when to execute progress function. + True to keep explicit ACEs. + Progress function. + True to throw on error. + The NT status code. + + + + Get the source of inherited ACEs. + + The name of the resource. + The type of the resource. + Whether the resource is a container. + Optional list of object types. + The security descriptor for the resource. + True to check the SACL otherwise checks the DACL. + Generic mapping for the resource. + Query security descriptors for sources. + True to throw on error. + The list of inheritance sources. + + + + Get the source of inherited ACEs. + + The name of the resource. + The type of the resource. + Whether the resource is a container. + Optional list of object types. + The security descriptor for the resource. + True to check the SACL otherwise checks the DACL. + Generic mapping for the resource. + Query security descriptors for sources. + The list of inheritance sources. + + + + Get the security descriptor for a named resource. + + The name of the resource. + The type of the resource. + The security information to get. + True to throw on error. + The security descriptor. + + + + Get the security descriptor for a named resource. + + The name of the resource. + The type of the resource. + The security information to get. + The security descriptor. + + + + Get the security descriptor for a resource. + + The handle to the resource. + The type of the resource. + The security information to get. + True to throw on error. + The security descriptor. + + + + Get the security descriptor for a resource. + + The handle to the resource. + The type of the resource. + The security information to get. + The security descriptor. + + + + Get the NT type for a SE Object Type. + + The type of the resource. + The NT type if known, otherwise null. + + + + Lookup a privilege display name. + + The system name to do the lookup on. + The privilege name. + The display name. Empty string on error. + + + + Add a SID to name mapping with LSA. + + The domain name for the SID. The SID must be in the NT authority. + The account name for the SID. Can be null for a domain SID. + The SID to add. + True to throw on error. + The NT status result. + + + + Add a SID to name mapping with LSA. + + The domain name for the SID. + The account name for the SID. Can be null for a domain SID. + The SID to add. + The NT status result. + + + + Remove a SID to name mapping with LSA. + + The domain name for the SID. + The account name for the SID. Can be null for a domain SID. + True to throw on error. + The NT status result. + + + + Remove a SID to name mapping with LSA. + + The domain name for the SID. + The account name for the SID. Can be null for a domain SID. + The NT status result. + + + + Remove a SID to name mapping with LSA. + + The SID to remove. + The NT status result. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + True to throw on error. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + Additional groups to add. Needs SeTcbPrivilege. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + Additional groups to add. Needs SeTcbPrivilege. + True to throw on error. + The logged on token. + + + + Lookup a SID's internet name. + + The SID to lookup. + True to throw on error. + The name of the sid as an internet account. + This still might return the normal NT4 style account name if the user is not an internet user. + + + + Lookup a SID's internet name. + + The SID to lookup. + The name of the sid as an internet account. + This still might return the normal NT4 style account name if the user is not an internet user. + + + + Retrieve LSA private data. + + The system containing the LSA instance. + The name of the key. + True to throw on error. + The private data as bytes. + + + + Retrieve LSA private data. + + The system containing the LSA instance. + The name of the key. + The private data as bytes. + + + + Retrieve LSA private data. + + The name of the key. + The private data as bytes. + + + + Store LSA private data. + + The system containing the LSA instance. + The name of the key. + The data to store. + True to throw on error. + The NT status code. + + + + Store LSA private data. + + The system containing the LSA instance. + The name of the key. + The data to store. + + + + Store LSA private data. + + The name of the key. + The data to store. + + + + Delete LSA private data. + + The system containing the LSA instance. + The name of the key. + True to throw on error. + The NT status code. + + + + Delete LSA private data. + + The system containing the LSA instance. + The name of the key. + + + + Delete LSA private data. + + The name of the key. + + + + Virtual Key enumeration. + + + + + Left mouse button + + + + + Right mouse button + + + + + Control-break processing + + + + + Middle mouse button (three-button mouse) + + + + + Windows 2000/XP: X1 mouse button + + + + + Windows 2000/XP: X2 mouse button + + + + + BACKSPACE key + + + + + TAB key + + + + + CLEAR key + + + + + ENTER key + + + + + SHIFT key + + + + + CTRL key + + + + + ALT key + + + + + PAUSE key + + + + + CAPS LOCK key + + + + + Input Method Editor (IME) Kana mode + + + + + IME Hangul mode + + + + + IME Junja mode + + + + + IME final mode + + + + + IME Hanja mode + + + + + IME Kanji mode + + + + + ESC key + + + + + IME convert + + + + + IME nonconvert + + + + + IME accept + + + + + IME mode change request + + + + + SPACEBAR + + + + + PAGE UP key + + + + + PAGE DOWN key + + + + + END key + + + + + HOME key + + + + + LEFT ARROW key + + + + + UP ARROW key + + + + + RIGHT ARROW key + + + + + DOWN ARROW key + + + + + SELECT key + + + + + PRINT key + + + + + EXECUTE key + + + + + PRINT SCREEN key + + + + + INS key + + + + + DEL key + + + + + HELP key + + + + + 0 key + + + + + 1 key + + + + + 2 key + + + + + 3 key + + + + + 4 key + + + + + 5 key + + + + + 6 key + + + + + 7 key + + + + + 8 key + + + + + 9 key + + + + + A key + + + + + B key + + + + + C key + + + + + D key + + + + + E key + + + + + F key + + + + + G key + + + + + H key + + + + + I key + + + + + J key + + + + + K key + + + + + L key + + + + + M key + + + + + N key + + + + + O key + + + + + P key + + + + + Q key + + + + + R key + + + + + S key + + + + + T key + + + + + U key + + + + + V key + + + + + W key + + + + + X key + + + + + Y key + + + + + Z key + + + + + Left Windows key (Microsoft Natural keyboard) + + + + + Right Windows key (Natural keyboard) + + + + + Applications key (Natural keyboard) + + + + + Computer Sleep key + + + + + Numeric keypad 0 key + + + + + Numeric keypad 1 key + + + + + Numeric keypad 2 key + + + + + Numeric keypad 3 key + + + + + Numeric keypad 4 key + + + + + Numeric keypad 5 key + + + + + Numeric keypad 6 key + + + + + Numeric keypad 7 key + + + + + Numeric keypad 8 key + + + + + Numeric keypad 9 key + + + + + Multiply key + + + + + Add key + + + + + Separator key + + + + + Subtract key + + + + + Decimal key + + + + + Divide key + + + + + F1 key + + + + + F2 key + + + + + F3 key + + + + + F4 key + + + + + F5 key + + + + + F6 key + + + + + F7 key + + + + + F8 key + + + + + F9 key + + + + + F10 key + + + + + F11 key + + + + + F12 key + + + + + F13 key + + + + + F14 key + + + + + F15 key + + + + + F16 key + + + + + F17 key + + + + + F18 key + + + + + F19 key + + + + + F20 key + + + + + F21 key + + + + + F22 key, (PPC only) Key used to lock device. + + + + + F23 key + + + + + F24 key + + + + + NUM LOCK key + + + + + SCROLL LOCK key + + + + + Left SHIFT key + + + + + Right SHIFT key + + + + + Left CONTROL key + + + + + Right CONTROL key + + + + + Left MENU key + + + + + Right MENU key + + + + + Windows 2000/XP: Browser Back key + + + + + Windows 2000/XP: Browser Forward key + + + + + Windows 2000/XP: Browser Refresh key + + + + + Windows 2000/XP: Browser Stop key + + + + + Windows 2000/XP: Browser Search key + + + + + Windows 2000/XP: Browser Favorites key + + + + + Windows 2000/XP: Browser Start and Home key + + + + + Windows 2000/XP: Volume Mute key + + + + + Windows 2000/XP: Volume Down key + + + + + Windows 2000/XP: Volume Up key + + + + + Windows 2000/XP: Next Track key + + + + + Windows 2000/XP: Previous Track key + + + + + Windows 2000/XP: Stop Media key + + + + + Windows 2000/XP: Play/Pause Media key + + + + + Windows 2000/XP: Start Mail key + + + + + Windows 2000/XP: Select Media key + + + + + Windows 2000/XP: Start Application 1 key + + + + + Windows 2000/XP: Start Application 2 key + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Windows 2000/XP: For any country/region, the '+' key + + + + + Windows 2000/XP: For any country/region, the ',' key + + + + + Windows 2000/XP: For any country/region, the '-' key + + + + + Windows 2000/XP: For any country/region, the '.' key + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Windows 2000/XP: Either the angle bracket key or the backslash key on the RT 102-key keyboard + + + + + Windows 95/98/Me, Windows NT 4.0, Windows 2000/XP: IME PROCESS key + + + + + Windows 2000/XP: Used to pass Unicode characters as if they were keystrokes. + The VK_PACKET key is the low word of a 32-bit Virtual Key value used for non-keyboard input methods. For more information, + see Remark in KEYBDINPUT, SendInput, WM_KEYDOWN, and WM_KEYUP + + + + + Attn key + + + + + CrSel key + + + + + ExSel key + + + + + Erase EOF key + + + + + Play key + + + + + Zoom key + + + + + Reserved + + + + + PA1 key + + + + + Clear key + + + + + Class representing the information about a service. + + + + + The name of the service. + + + + + The security descriptor of the service. + + + + + The list of triggers for the service. + + + + + The service SID setting. + + + + + The service launch protected setting. + + + + + The service required privileges. + + + + + The service type. + + + + + Service start type. + + + + + Error control. + + + + + Binary path name. + + + + + Load order group. + + + + + Tag ID for load order. + + + + + Dependencies. + + + + + Display name. + + + + + Service start name. For user mode services this is the username, for drivers it's the driver name. + + + + + Indicates this service is set to delayed automatic start. + + + + + The user name this service runs under. + + + + + Type of service host when using Win32Share. + + + + + Service main function when using Win32Share. + + + + + Image path for the service. + + + + + Get name of the target image, either the ServiceDll or ImagePath. + + + + + Service DLL if a shared process server. + + + + + The name of the machine this service was found on. + + + + + Indicates if this service process is grouped with others. + + + + + Class to represent custom data for a service trigger. + + + + + The type of data. + + + + + The raw custom data. + + + + + The custom data as a string. + + + + + The custom data as an array of strings (only useful for String type). + + + + + Overidden ToString method. + + The data as a string. + + + + Trigger information for a service. + + + + + The type of service trigger. + + + + + The service trigger action. + + + + + The sub-type GUID. + + + + + The description of the sub type. + + + + + Custom data. + + + + + Overridden ToString method. + + The trigger as a string. + + + + Trigger the service. + + + + + Service trigger type. + + + + + Represents an action that the service control manager can perform. + + + + + The action to be performed. + + + + + The time to wait before performing the specified action, in milliseconds. + + + + The action to be performed. + The time to wait before performing the specified action, in milliseconds. + + + + Utilities for accessing services. + + + + + The name of the fake NT type for a service. + + + + + The name of the fake NT type for the SCM. + + + + + Get the generic mapping for the SCM. + + The SCM generic mapping. + + + + Get the generic mapping for a service. + + The service generic mapping. + + + + Get the security descriptor of the SCM. + + The SCM security descriptor. + + + + Get the security descriptor of the SCM. + + The name of a target computer. Can be null or empty to specify local machine. + Parts of the security descriptor to return. + True to throw on error. + The SCM security descriptor. + + + + Get the security descriptor of the SCM. + + The name of a target computer. Can be null or empty to specify local machine. + Parts of the security descriptor to return. + The SCM security descriptor. + + + + Get the security descriptor of the SCM. + + Parts of the security descriptor to return. + True to throw on error. + The SCM security descriptor. + + + + Get the security descriptor of the SCM. + + Parts of the security descriptor to return. + The SCM security descriptor. + + + + Get the security descriptor for a service. + + The name of the service. + Parts of the security descriptor to return. + True to throw on error. + The name of a target computer. Can be null or empty to specify local machine. + The security descriptor. + + + + Get the security descriptor for a service. + + The name of the service. + Parts of the security descriptor to return. + The name of a target computer. Can be null or empty to specify local machine. + The security descriptor. + + + + Get the security descriptor for a service. + + The name of the service. + Parts of the security descriptor to return. + True to throw on error. + The security descriptor. + + + + Get the security descriptor for a service. + + The name of the service. + Parts of the security descriptor to return. + The security descriptor. + + + + Set the SCM security descriptor. + + The name of a target computer. Can be null or empty to specify local machine. + The security descriptor to set. + The parts of the security descriptor to set. + True to throw on error. + The NT status code. + + + + Set the SCM security descriptor. + + The name of a target computer. Can be null or empty to specify local machine. + The security descriptor to set. + The parts of the security descriptor to set. + + + + Set the SCM security descriptor. + + The security descriptor to set. + The parts of the security descriptor to set. + True to throw on error. + The NT status code. + + + + Set the SCM security descriptor. + + The security descriptor to set. + The parts of the security descriptor to set. + + + + Get the information about a service. + + The name of the service. + The name of a target computer. Can be null or empty to specify local machine. + True to throw on error. + The service information. + + + + Get the information about a service. + + The name of the service. + The name of a target computer. Can be null or empty to specify local machine. + The service information. + + + + Get the information about a service. + + The name of the service. + True to throw on error. + The service information. + + + + Set the security descriptor for a service. + + The name of the service. + The name of a target computer. Can be null or empty to specify local machine. + The security descriptor to set. + The security information to set. + True to throw on error. + The NT status. + + + + Set the security descriptor for a service. + + The name of the service. + The name of a target computer. Can be null or empty to specify local machine. + The security descriptor to set. + The security information to set. + + + + Set the security descriptor for a service. + + The name of the service. + The security descriptor to set. + The security information to set. + True to throw on error. + The NT status. + + + + Set the security descriptor for a service. + + The name of the service. + The security descriptor to set. + The security information to set. + + + + Get the information about a service. + + The name of the service. + The service information. + + + + Get the information about all services. + + The name of a target computer. Can be null or empty to specify local machine. + The types of services to return. + The list of service information. + + + + Get the information about all services. + + The types of services to return. + The list of service information. + + + + Get the PID of a running service. + + The name of the service. + Returns the PID of the running service, or 0 if not running. + Thrown on error. + + + + Get the PIDs of a list of running service. + + The names of the services. + Returns the PID of the running service, or 0 if not running. + Thrown on error. + + + + Get a running service by name. + + The name of the service. + The name of a target computer. Can be null or empty to specify local machine. + True to throw on error. + The running service. + This will return active and non-active services as well as drivers. + + + + Get a running service by name. + + The name of the service. + The name of a target computer. Can be null or empty to specify local machine. + The running service. + This will return active and non-active services as well as drivers. + + + + Get a running service by name. + + The name of the service. + The running service. + True to throw on error. + This will return active and non-active services as well as drivers. + + + + Get a running service by name. + + The name of the service. + The running service. + This will return active and non-active services as well as drivers. + + + + Get a list of all registered services. + + The name of a target computer. Can be null or empty to specify local machine. + Specify state of services to get. + Specify the type filter for services. + A list of registered services. + + + + Get a list of all registered services. + + Specify state of services to get. + Specify the type filter for services. + A list of registered services. + + + + Get flags for all user service types. + + The flags for user service types. + + + + Get flags for all kernel driver types. + + The flags for kernel driver types. + + + + Get a list of all registered services. + + A list of registered services. + + + + Get a list of all active running services with their process IDs. + + A list of all active running services with process IDs. + + + + Get a list of all drivers. + + A list of all drivers. + + + + Get a list of all active running drivers. + + A list of all active running drivers. + + + + Get a list of all services and drivers. + + A list of all services and drivers. + + + + Get a list of all services and drivers. + + A list of all services and drivers. + + + + Get a fake NtType for a service. + + Service returns the service type, SCM returns SCM type. + The fake service NtType. Returns null if not a recognized type. + + + + Create a new service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + True to throw on error. + The registered service information. + + + + Create a new service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + The registered service information. + + + + Create a new service. + + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + True to throw on error. + The registered service information. + + + + Create a new service. + + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + The registered service information. + + + + Delete a service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + True to throw on error. + The NT status. + + + + Delete a service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The NT status. + + + + Delete a service. + + The name of the service. + True to throw on error. + The NT status. + + + + Delete a service. + + The name of the service. + + + + Send a control code to a service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The control code to send. If >= 128 will be sent as a custom control code. + True to throw on error. + The NT status code. + + + + Send a control code to a service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The control code to send. If >= 128 will be sent as a custom control code. + + + + Send a control code to a service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The control code to send. If >= 128 will be sent as a custom control code. + + + + Send a control code to a service. + + The name of the service. + The control code to send. If >= 128 will be sent as a custom control code. + + + + Send a control code to a service. + + The name of the service. + The control code to send. If >= 128 will be sent as a custom control code. + + + + Change service configuration. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + Load group order. + The tag ID. + List of service dependencies. + The username for the service. + Password for the username if needed. + True to throw on error. + The NT status code. + + + + Change service configuration. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + The tag ID. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + + + + Change service configuration. + + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + The tag ID. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + True to throw on error. + The NT status code. + + + + Change service configuration. + + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + The tag ID. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + + + + Start a service by name. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + Optional arguments to pass to the service. + True to throw on error. + The status code for the service. + + + + Start a service by name. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + Optional arguments to pass to the service. + + + + Start a service by name. + + The name of the service. + Optional arguments to pass to the service. + True to throw on error. + The status code for the service. + + + + Start a service by name. + + The name of the service. + Optional arguments to pass to the service. + The status code for the service. + + + + Set a service's SID type. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The SID type to set. + True to throw on error. + The NT status code. + + + + Set a service's SID type. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The SID type to set. + + + + Set a service's SID type. + + The name of the service. + The SID type to set. + True to throw on error. + The NT status code. + + + + Set a service's SID type. + + The name of the service. + The SID type to set. + + + + Set a service's delayed auto-start. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + If true, the service is started after other auto-start services are started plus a short delay. Otherwise, the service is started during system boot. + True to throw on error. + The NT status code. + + + + + + + + + + + + + + + Set a service's failure recover actions. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + Actions to be performed on service failure. +
If this value is null, is ignored. +
If this value is empty, the reset period and array of failure actions are deleted. + The time after which to reset the failure count to zero if there are no failures, in seconds. Specify -1 to indicate that this value should never be reset. + The command line of the process for the CreateProcess function to execute in response to the command run service controller action. +
This process runs under the same account as the service. +
If this value is null, the command is unchanged. +
If the value is an empty string (""), the command is deleted and no program is run when the service fails. + The message to be broadcast to server users before rebooting in response to the reboot action service controller action. +
If this value is null, the reboot message is unchanged. +
If the value is an empty string (""), the reboot message is deleted and no message is broadcast. +
This member can specify a localized string using the following format: @[path]dllname,-strID +
The string with identifier strID is loaded from dllname; path is optional. + True to throw on error. + The NT status code. +
+ + + + + + + + + + + + + + Set a service's required privileges. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The required privileges. + True to throw on error. + The NT status code. + + + + Set a service's required privileges. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The required privileges. + + + + Set a service's required privileges. + + The name of the service. + The required privileges. + True to throw on error. + The NT status code. + + + + Set a service's required privileges. + + The name of the service. + The required privileges. + + + + Set a service's launch protected type. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The protected type. + True to throw on error. + The NT status code. + + + + Set a service's launch protected type. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The protected type. + + + + Set a service's required privileges. + + The name of the service. + The protected type. + True to throw on error. + The NT status code. + + + + Set a service's SID type. + + The name of the service. + The protected type. + + + + A service trigger for an ETW event. + + + + + The security descriptor for the ETW event. Needs administrator privileges. + + + + + Trigger the service. + + + + + Service trigger for firewall port interface. + + + + + The port for the firewall service trigger. + + + + + The protocol for the firewall service trigger. + + + + + The protocol for the firewall service trigger. + + + + + The protocol for the firewall service trigger. + + + + + Service trigger for a named pipe. + + + + + The path to the named pipe. + + + + + Service trigger for an RPC interface. + + + + + List of interface ID for the RPC server. + + + + + Class to represent a handle to the SCM. + + + + + Active services database. + + + + + Failed services database. + + + + + Open an instance of the SCM. + + The machine name for the SCM. + The database name. Specify SERVICES_ACTIVE_DATABASE or SERVICES_FAILED_DATABASE. + If null then SERVICES_ACTIVE_DATABASE is used. + The desired access for the SCM connection. + True to throw on error. + The SCM instance. + + + + Open an instance of the SCM. + + The machine name for the SCM. + The database name. Specify SERVICES_ACTIVE_DATABASE or SERVICES_FAILED_DATABASE. + If null then SERVICES_ACTIVE_DATABASE is used. + The desired access for the SCM connection. + The SCM instance. + + + + Open an instance of the SCM. + + The machine name for the SCM. + The desired access for the SCM connection. + The SCM instance. + + + + Get the Win32 services for the SCM. + + The state of the services to return. + The types of services to return. + True throw on error. + The list of services. + SCM must have been opened with EnumerateService access. + + + + Get the Win32 services for the SCM. + + The state of the services to return. + The types of services to return. + The list of services. + SCM must have been opened with EnumerateService access. + + + + Dispose the object. + + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + + + + Service trigger for a WNF event. + + + + + The WNF name. + + + + + Represents a loaded module from the symbol resolver. + + + + + The name of the module. + + + + + The base address of the module. + + + + + The image size of the module. + + + + + Get the path to the loaded PDB file is known. + + + + + True indicates this module only has export symbols. + + + + + Query names of types for this module. + + The list of type names. + + + + Query types in a module. + + The list of types. + + + + Get a type by name. + + The name of the type. + + + + + Query types by name + + A mask string for the type name. e.g. mod!ABC* + The list of types. + + + + Returns the name of the module. + + The name of the module. + + + + Static class for creating symbolic resolvers. + + + + + Create a new instance of a symbol resolver. + + The process in which the symbols should be resolved. + The path to dbghelp.dll, ideally should use the one which comes with Debugging Tools for Windows. + The symbol path. + Flags for the symbol resolver. + A text writer for output when specifying the TraceSymbolLoading flag. + The instance of a symbol resolver. Should be disposed when finished. + + + + Create a new instance of a symbol resolver. + + The process in which the symbols should be resolved. + The path to dbghelp.dll, ideally should use the one which comes with Debugging Tools for Windows. + The symbol path. + The instance of a symbol resolver. Should be disposed when finished. + + + + Create a new instance of a symbol resolver. Uses the system dbghelp library and symbol path + from _NT_SYMBOL_PATH environment variable. + + The process in which the symbols should be resolved. + The instance of a symbol resolver. Should be disposed when finished. + + + + Enumeration for safer level. + + + + + Constrained. + + + + + Fully trusted. + + + + + Normal user. + + + + + Untrusted. + + + + + Class to access tokens through various mechanisms. + + + + + Logon a user using S4U + + The username. + The user's realm. + + The logged on token. + + + + Get the anonymous token. + + The access rights for the opened token. + The anonymous token. + + + + Get the anonymous token. + + The anonymous token. + + + + Logon a user. + + The username. + The user's domain. + The user's password. + The logon token's type. + Optional list of additonal groups to add. + The logged on token. + + + + Logon a user. + + The username. + The user's domain. + The user's password. + The logon token's type. + Optional list of additonal groups to add. + The Logon provider. + The logged on token. + + + + Logon a user. + + The username. + The user's domain. + The user's password. + The logon token's type. + Optional list of additonal groups to add. + The Logon provider. + True to throw on error. + The logged on token. + + + + Open the current clipboard token. + + + + + + + + Get the token from the clipboard. + + The access rights for the opened token. + The clipboard token. + + + + Get the token from the clipboard. + + The clipboard token. + + + + Derive a package sid from a name. + + The name of the package. + True to throw on error. + The derived Sid + + + + Derive a package sid from a name. + + The name of the package. + The derived Sid + + + + Derive a restricted package sid from an existing pacakge sid. + + The base package sid. + The restricted name for the sid. + True to throw on error. + The derived Sid. + + + + Derive a restricted package sid from an existing pacakge sid. + + The base package sid. + The restricted name for the sid. + The derived Sid. + + + + Derive a restricted package sid from an existing package sid. + + The base package name. + The restricted name for the sid. + The derived Sid. + + + + Get the package SID from a name. + + The name of the package, can be either an SDDL SID or a package name. + The derived SID. + + + + Get a safer token. + + The base token. + The safer level to use. + True to make the token inert. + The safer token. + + + + Get session token for a session ID. + + The session ID. + The session token. + + + + Get tokens for all logged on sessions. + + Needs SeTcbPrivilege to work. + The list of session tokens. + + + + Create an AppContainer token using the CreateAppContainerToken API. + + The token to base the new token on. Can be null. + The AppContainer package SID. + List of capabilities. + True to throw on error. + The appcontainer token. + This exported function was only introduced in RS3 + + + + Create an AppContainer token using the CreateAppContainerToken API. + + The token to base the new token on. Can be null. + The AppContainer package SID. + List of capabilities. + The appcontainer token. + This exported function was only introduced in RS3 + + + + Create an AppContainer token using the CreateAppContainerToken API. + + The AppContainer package SID. + List of capabilities. + The appcontainer token. + This exported function was only introduced in RS3 + + + + Win32 Error Codes. + + + + + Flags for DefineDosDevice + + + + + None + + + + + Specify a raw target path + + + + + Remove existing definition + + + + + Only remove exact matches to the target + + + + + Don't broadcast changes to the system + + + + + Disposition values for CreateFile. + + + + + Create a new file. Fail if it exists. + + + + + Always create a new file, overwrite if it exists. + + + + + Open a file, fail if it doesn't exist. + + + + + Open a file, create if it doesn't exist. + + + + + Truncate existing file. + + + + + Flags for GetWin32PathName. + + + + + No flags. + + + + + GUID format. + + + + + NT format. + + + + + No specific format. + + + + + Opened file name. + + + + + Class representing a win32 process. + + + + + Create process with a token. + + The token to create the process with. + The process configuration. + The created win32 process. + + + + Create process with a token. + + The token to create the process with. + The path to the executable. + The process command line. + Process creation flags. + The desktop name. + The created win32 process. + + + + Create process with a token from a user logon. + + The username. + The user's domain. + The user's password. + Logon flags. + The process configuration. + The created win32 process. + + + + Create process with a token from a user logon. + + The user's credentials. + Logon flags. + The process configuration. + True to throw on error. + The created win32 process. + + + + Create process with a token from a user logon. + + The user's credentials. + Logon flags. + The process configuration. + The created win32 process. + + + + Create process with a token from a user logon. + + The username. + The user's domain. + The user's password. + Logon flags. + The process configuration. + The created win32 process. + + + + Create process with a token from a user logon. + + The username. + The user's domain. + The user's password. + Logon flags. + The path to the executable. + The process command line. + Process creation flags. + The desktop name. + The created win32 process. + + + + Create process with a token. + + The token to create the process with. + The process configuration. + The created win32 process. + + + + Create process. + + The process configuration. + The created win32 process. + + + + Create process. + + Optional parent process. + The path to the executable. + The process command line. + Process creation flags. + The desktop name. + The created win32 process. + + + + Dispose the process. + + + + + Resume the entire process. + + + + + Suspend the entire process. + + + + + Terminate the process + + The exit code for the termination + + + + The handle to the process. + + + + + The handle to the initial thread. + + + + + The process ID of the process. + + + + + The thread ID of the initial thread. + + + + + True to terminate process when disposed. + + + + + Get the process' exit status. + + + + + Get the process' exit status as an NtStatus code. + + + + + Explicit conversion operator to an NtThread object. + + The win32 process + + + + Explicit conversion operator to an NtProcess object. + + The win32 process + + + + Specify the CreateProcess API to use with a Token. + + + + + Use CreateProcessAsUser, if that fails use CreateProcessWithToken. + + + + + Use only CreateProcessAsUser. + + + + + User only CreateProcessWithToken. + + + + + Win32 process creation configuration. + + + + + Specify security descriptor of process. + + + + + Specify process handle is inheritable. + + + + + Specify security descriptor of thread. + + + + + Specify thread handle is inheritable. + + + + + Specify to inherit handles. + + + + + Specify parent process. + + + + + Specify path to application executable. + + + + + Specify command line. + + + + + Specify creation flags. + + + + + Specify environment block. + + + + + Specify current directory. + + + + + Specify desktop name. + + + + + Specify window title. + + + + + True to terminate the process when it's disposed. + + + + + Specify the mitigation options. + + + + + Specify the mitigation options 2. + + + + + Specify win32k filter flags. + + + + + Specify win32k filter level. + + + + + Specify PP level. + + + + + Specify list of handles to inherit. + + + + + Specify the appcontainer Sid. + + + + + Specify the appcontainer capabilities. + + + + + Specify LPAC. + + + + + Restrict the process from creating child processes. + + + + + Override child process creation restriction. + + + + + Set child process mitigation flags. + + + + + Specify new process policy when creating a desktop bridge application. + + + + + Specify a token to use for the new process. + + + + + Specify a stdin handle for the new process (you must inherit the handle). + + + + + Specify a stdout handle for the new process (you must inherit the handle). + + + + + Specify a stderror handle for the new process (you must inherit the handle). + + + + + Specify the package name to use. + + + + + Specify handle to pseudo console. + + + + + Specify Base Named Objects isolation prefix. + + + + + Specify the safe open prompt original claim. + + + + + When specifying the debug flags use this debug object instead of the current thread's object. + + + + + When specified do not fallback to using CreateProcessWithToken if CreateProcessWithUser fails. + + + + + Specify additional extended flags. + + + + + Specify list of handles to inherit. + + + + + Specify a service window station and desktop. + + + + + Specify authentication credentials for CreateProcessWithLogon. + + + + + Specify logon flags for the Credentials or when calling CreateProcessWithToken. + + + + + Specify the type of API to call when specifying a token. + + + + + Specify component filter flags. + + + + + Add an object's handle to the list of inherited handles. + + The object to add. + The raw handle value. + Note that this doesn't maintain a reference to the object. It should be kept + alive until the process has been created. + + + + Add an AppContainer capability by name. + + The name of the capability. + + + + Add an AppContainer capability by name. + + The capability SID. + + + + Set AppContainer SID from a package name. + + The package name. + + + + Constructor. + + + + + Flags for create process. + + + + + No flags. + + + + + Debug process. + + + + + Debug only this process. + + + + + Create suspended. + + + + + Detach process. + + + + + Create a new console. + + + + + Normal priority class. + + + + + Idle priority class. + + + + + High priority class. + + + + + Realtime priority class. + + + + + Create a new process group. + + + + + Create from a unicode environment. + + + + + Create a separate WOW VDM. + + + + + Share the WOW VDM. + + + + + Force DOS process. + + + + + Below normal priority class. + + + + + Above normal priority class. + + + + + Inherit parent affinity. + + + + + Inherit caller priority (deprecated) + + + + + Create a protected process. + + + + + Specify extended startup information is present. + + + + + Process mode background begin. + + + + + Process mode background end. + + + + + Create a secure process. + + + + + Breakaway from a job object. + + + + + Preserve code authz level. + + + + + Default error mode. + + + + + No window. + + + + + Profile user. + + + + + Profile kernel. + + + + + Profile server. + + + + + Ignore system default. + + + + + Flags for CreateProcessWithLogon + + + + + No flags. + + + + + With a profile. + + + + + Using network credentials. + + + + + Win32k filter flags. + + + + + No flags. + + + + + Enable filter. + + + + + Audit filter. + + + + + Flags for create thread. + + + + + No flags. + + + + + Create suspended. + + + + + Stack size is a reservation. + + + + + Specify PPL level. + + + + + None + + + + + Safe level as parent. + + + + + Tcb PPL + + + + + Windows PP + + + + + Windows PPL + + + + + Antimalware PPL + + + + + LSA PPL + + + + + Tcb PP + + + + + Code Generation PPL + + + + + Authenticode PP + + + + + App PPL + + + + + Extended process flags. + + + + + No flags. + + + + + Log elevation failure. + + + + + Ignore elevation requirements. + + + + + Force job breakaway (needs TCB privilege). + + + + + Process mitigation option flags. + + + + + Process mitigation option 2 flags. + + + + + Class representing a service instance. + + + + + The name of the service. + + + + + The description of the service. + + + + + Type of service. + + + + + Image path for the service. + + + + + Command line for the service. + + + + + Service DLL if a shared process server. + + + + + Current service status. + + + + + What controls are accepted by the service. + + + + + Whether the service can be stopped. + + + + + The Win32 exit code. + + + + + The service specific exit code, if Win32ExitCode is Win32Error.ERROR_SERVICE_SPECIFIC_ERROR. + + + + + The checkpoint while starting. + + + + + Waiting hint time. + + + + + Service flags. + + + + + Process ID of the running service. + + + + + The security descriptor of the service. + + + + + The list of triggers for the service. + + + + + The service SID type. + + + + + The service launch protected setting. + + + + + The service required privileges. + + + + + Service start type. + + + + + Whether the service is a delayed auto start service. + + + + + Error control. + + + + + Load order group. + + + + + Tag ID for load order. + + + + + Dependencies. + + + + + The user name this service runs under. + + + + + Type of service host when using Win32Share. + + + + + Service main function when using Win32Share. + + + + + Indicates if this service process is grouped with others. + + + + + The name of the machine this service was found on. + + + + + Overridden ToString method. + + The name of the service. + + + + Utilities for Win32 APIs. + + + + + Get a mask dictionary for a type. + + The enumerated type to query for names. + The valid access. + A dictionary mapping a mask value to a name. + + + + Get a mask dictionary for a type. + + The enumerated type to query for names. + The valid access. + Specify to get the SDK name instead of a formatting enumerated name. + A dictionary mapping a mask value to a name. + + + + Display the edit security dialog. + + Parent window handle. + NT object to display the security. + The name of the object to display. + True to force the UI to read only. + + + + Display the edit security dialog. + + Parent window handle. + The name of the object to display. + The security descriptor to display. + The NT type of the object. + + + + Display the edit security dialog. + + Parent window handle. + The name of the object to display. + The security descriptor to display. + An enumerated type for the access mask. + Generic mapping for the access rights. + Valid access mask for the access rights. + + + + Define a new DOS device. + + The dos device flags. + The device name to define. + The target path. + + + + Get Windows INVALID_HANDLE_VALUE. + + + + + Parse a command line into arguments. + + The parsed command line. + The list of arguments. + + + + Get the image path from a command line. + + The command line to parse. + The image path, returns the original command line if can't find a valid image path. + + + + Get Win32 path name for a file. + + The file to get the path from. + Flags for the path to return. + True to throw on error. + The win32 path. + + + + Get Win32 path name for a file. + + The file to get the path from. + Flags for the path to return. + The win32 path. + + + + Format a message. + + The module containing the message. + The ID of the message. + The message. Empty string on error. + + + + Format a message. + + The ID of the message. + The message. Empty string on error. + + + + Open a file with the Win32 CreateFile API. + + The filename to open. + The desired access. + The share mode. + Optional security descriptor. + True to set the handle as inheritable. + Creation disposition. + Flags and attributes. + Optional template file. + True to throw on error. + The opened file handle. + + + + Open a file with the Win32 CreateFile API. + + The filename to open. + The desired access. + The share mode. + Optional security descriptor. + True to set the handle as inheritable. + Creation disposition. + Flags and attributes. + Optional template file. + The opened file handle. + + + + Open a file with the Win32 CreateFile API. + + The filename to open. + The desired access. + The share mode. + Creation disposition. + Flags and attributes. + True to throw on error. + The opened file handle. + + + + Open a file with the Win32 CreateFile API. + + The filename to open. + The desired access. + The share mode. + Creation disposition. + Flags and attributes. + The opened file handle. + + + + Send key down events. + + The key codes to send. + + + + Send key down events. + + The key codes to send. + + + + Send key down then up events. + + The key codes to send. + This will send all keys down first, then all up. + + + + This creates a Window Station using the User32 API. + + The name of the Window Station. + The Window Station. + + + + Create a remote thread. + + The process to create the thread in. + The thread security descriptor. + Whether the handle should be inherited. + The size of the stack. 0 for default. + Start address for the thread. + Parameter to pass to the thread. + The flags for the thread creation. + True to throw on error. + The created thread. + Thrown on error. + + + + Create a remote thread. + + The process to create the thread in. + The thread security descriptor. + Whether the handle should be inherited. + The size of the stack. 0 for default. + Start address for the thread. + Parameter to pass to the thread. + The flags for the thread creation. + The created thread. + Thrown on error. + + + + Create a remote thread. + + The process to create the thread in. + Start address for the thread. + Parameter to pass to the thread. + The flags for the thread creation. + The created thread. + Thrown on error. + + + + Get a list of all console sessions. + + True to throw on error. + The list of console sessions. + + + + Get a list of all console sessions. + + The list of console sessions. + + + + Write debug string to output. + + The debug string to write. + +
+
diff --git a/Packages/NtApiDotNet.1.1.33/lib/netstandard2.0/NtApiDotNet.dll b/Packages/NtApiDotNet.1.1.33/lib/netstandard2.0/NtApiDotNet.dll new file mode 100644 index 0000000..71ce735 Binary files /dev/null and b/Packages/NtApiDotNet.1.1.33/lib/netstandard2.0/NtApiDotNet.dll differ diff --git a/Packages/NtApiDotNet.1.1.33/lib/netstandard2.0/NtApiDotNet.xml b/Packages/NtApiDotNet.1.1.33/lib/netstandard2.0/NtApiDotNet.xml new file mode 100644 index 0000000..c8ffc9e --- /dev/null +++ b/Packages/NtApiDotNet.1.1.33/lib/netstandard2.0/NtApiDotNet.xml @@ -0,0 +1,51865 @@ + + + + NtApiDotNet + + + + + Result of an access check with specific access types. + + The access rights type, must be derived from an Enum. + + + + The NT status code from the access check. + + + + + The granted access mask from the check. + + + + + The granted access mapped to generic access mask. + + + + + The required privileges for this access. + + + + + The specific granted access mask from the check. + + + + + The specific granted access mapped to generic access mask. + + + + + Object type associated with the access. + + + + + The level of the object type if used. + + + + + Optional name for the object type. + + + + + When a result from an Audit Access Check indicates whether the + an audit needs to be generated on close. + + + + + Whether the access check was a success. + + + + + Get access check result as a specific access. + + The specific access results. + + + + Get access check result as a specific access. + + The specific access. + + + + Result of an access check. + + + + + Result of an access check with generic Enum access types. + + + + + Structure for an NT access mask. + + + + + The access mask's access bits. + + + + + Constructor. + + Access bits to use + + + + Implicit conversion from Int32. + + The access enumeration. + + + + Implicit conversion from UInt32. + + The access enumeration. + + + + Implicit conversion from enumerations. + + The access enumeration. + + + + Convert access mask to a generic access object. + + The generic access mask + + + + Convert access mask to a mandatory label policy + + The mandatory label policy + + + + Convert to a specific access right. + + The specific access right. + The converted value. + + + + Convert to a specific access right. + + The type of enumeration to convert to. + The converted value. + + + + Get whether this access mask is empty (i.e. it's 0) + + + + + Get whether this access mask has no access rights, i.e. not empty. + + + + + Get whether this access mask has generic access rights. + + + + + Get whether this access mask hash type specific access rights. + + + + + Get whether the current access mask is granted specific permissions. + + The access mask to check + True one or more access granted. + + + + Get whether the current access mask is granted all specific permissions. + + The access mask to check + True access all is granted. + + + + Bitwise AND operator. + + Access mask 1 + Access mask 2 + The new access mask. + + + + Bitwise OR operator. + + Access mask 1 + Access mask 2 + The new access mask. + + + + Bitwise AND operator. + + Access mask 1 + Access mask 2 + The new access mask. + + + + Bitwise OR operator. + + Access mask 1 + Access mask 2 + The new access mask. + + + + Equality operator. + + Access mask 1 + Access mask 2 + True if equal. + + + + Inequality operator. + + Access mask 1 + Access mask 2 + True if equal. + + + + Bitwise NOT operator. + + Access mask 1 + The new access mask. + + + + Overridden GetHashCode. + + The hash code. + + + + Overridden Equals. + + The object to compare against. + True if equal. + + + + Get an empty access mask. + + + + + Overridden ToString method. + + The access mask. + + + + ToString method. + + Format code for the access mask. + The formatting string. + + + + ToString method. + + Format code for the access mask. + The format provider. + The formatting string. + + + + Flags representing what generic access the entry maps to. + + + + + Not mapped to any access. + + + + + Mapped to read. + + + + + Mapped to write. + + + + + Mapped to execute. + + + + + Mapped to All. + + + + + A structure to hold an access mask to enum mapping. + + + + + The access mask. + + + + + The value of the access mask entry enumeration. + + + + + The generic access this maps to. + + + + + The optional SDK name. + + + + + Overridden ToString method. + + The string form of the entry. + + + + Class to represent an Access Control Entry (ACE) + + + + + Check if the ACE is an allowed ACE. + + + + + Check if the ACE is a denied ACE. + + + + + Check if the ACE is an Object ACE + + + + + Check if the ACE is a callback ACE + + + + + Check if ACE is a conditional ACE + + + + + Check if ACE is a resource attribute ACE. + + + + + Check if ACE is a mandatory label ACE. + + + + + Check if ACE is a compound ACE. + + + + + Check if ACE is an audit ACE. + + + + + Check if ACE is an access filter ACE. + + + + + Check if ACE is a process trust label ACE. + + + + + Check if ACE is a critical ACE. + + + + + Check if ACE is inherit only. + + + + + Check if ACE is inherited by objects. + + + + + Check if ACE is inherited by objects. + + + + + Get ACE type + + + + + Get ACE flags + + + + + Get ACE access mask + + + + + Get ACE Security Identifier + + + + + The type of compound ACE. When serialized always set to Impersonate. + + + + + Get the client SID in a compound ACE. + + + + + Get optional Object Type + + + + + Get optional Inherited Object Type + + + + + Optional application data. + + + + + Get conditional check if a conditional ace. + + + + + Get or set resource attribute. + + + + + Constructor + + ACE type + ACE flags + ACE access mask + ACE sid + + + + Convert ACE to a string + + The ACE as a string + + + + Convert ACE to a string + + An enumeration type to format the access mask + True to try and resolve SID to a name + The ACE as a string + + + + Clone this ACE. + + The cloned ACE. + + + + Get whether the current access mask is granted specific permissions. + + The access mask to check + True one or more access granted. + + + + Get whether the current access mask is granted all specific permissions. + + The access mask to check + True access all is granted. + + + + Get the common name of the object type. + + Specify the domain for the object type. + If true then expand the list of properties. + The common name of the object type, or the GUID as a string. + This function could be quite slow to query the first time. + + + + Get the common name of the object type. + + If true then expand the list of properties. + The common name of the object type, or the GUID as a string. + This will query the local domain, it could be quite slow to query the first time. + + + + Get the common name of the object type. + + The common name of the object type, or the GUID as a string. + This will query the local domain, it could be quite slow to query the first time. + + + + Get the common name of the inherited object type. + + Specify the domain for the object type. + The common name of the object type, or the GUID as a string. + This function could be quite slow to query the first time. + + + + Get the common name of the inherited object type. + + The common name of the object type, or the GUID as a string. + This will query the local domain, it could be quite slow to query the first time. + + + + Convert the ACE to a byte array. + + The ACE as a byte array. + + + + Compare ACE to another object. + + The other object. + True if the other object equals this ACE + + + + Get hash code. + + The hash code + + + + Equality operator + + Left ACE + Right ACE + True if the ACEs are equal + + + + Not Equal operator + + Left ACE + Right ACE + True if the ACEs are not equal + + + + Class to represent an Access Control List (ACL) + + + + + Constructor + + Pointer to a raw ACL in memory + True if the ACL was defaulted + + + + Constructor + + Buffer containing an ACL in memory + True if the ACL was defaulted + + + + Constructor for a NULL ACL + + True if the ACL was defaulted + + + + Constructor for an empty ACL + + + + + Constructor + + List of ACEs to add to ACL + True if the ACL was defaulted + + + + Constructor + + List of ACEs to add to ACL + + + + Constructor. + + An SDDL string to create the DACL from. + The SDDL string should be of the form D:(...) or S:(...), if you specify + both a DACL and a SACL then only the DACL will be used. + + + + Convert the ACL to a byte array + + The ACL as a byte array + + + + Convert the ACL to a safe buffer + + The safe buffer + + + + Add an ace to the ACL + + The ACE to add + + + + Add an access allowed ace to the ACL + + The ACE access mask + The ACE flags + The ACE SID + + + + Add an access allowed ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an access allowed ace to the ACL + + The ACE access mask + The ACE flags + The ACE SID + + + + Add an access allowed ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an access denied ace to the ACL + + The ACE access mask + The ACE flags + The ACE SID + + + + Add an access denied ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an access denied ace to the ACL + + The ACE access mask + The ACE flags + The ACE SID + + + + Add an access denied ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an audit ace to the ACL + + The ACE access mask + The ACE flags + The ACE SID + + + + Add an audit ace to the ACL + + The ACE access mask + The ACE flags + The ACE SID + + + + Add an audit success ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an audit success ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an audit fail ace to the ACL + + The ACE access mask + The ACE SID + + + + Add an audit fail ace to the ACL + + The ACE access mask + The ACE SID + + + + Gets an indication if this ACL is canonical. + + Canonical means that deny ACEs are before allow ACEs. + True to canonicalize a DACL, otherwise a SACL. + True if the ACL is canonical. + + + + Gets an indication if this DACL is canonical. + + Canonical basically means that deny ACEs are before allow ACEs. + True if the ACL is canonical. + + + + Canonicalize the ACL. + + True to canonicalize a DACL, otherwise a SACL. + + + + Canonicalize the ACL (for use on DACLs only). + + The canonical ACL. + + + + Find the first ACE with a specified type. + + The type to find. + True to include inherit only ACEs. + The found ace. Returns null if not found. + + + + Find the first ACE with a specified type. Includes InheritOnly ACEs. + + The type to find. + The found ace. Returns null if not found. + + + + Find the all ACE with a specified type. + + The type to find. + True to include inherit only ACEs. + The found aces. + + + + Find the all ACE with a specified type. Includes InheritOnly ACEs. + + The type to find. + The found aces. + + + + Find the last ACE with a specified type. + + The type to find. + The found ace. Returns null if not found. + + + + Clone the ACL. Also clones all ACEs. + + The cloned ACL. + + + + Get or set whether the ACL was defaulted + + + + + Get or set whether the ACL is NULL (no security) + + + + + Get or set the protected flag. + + + + + Get or set the auto-inherited flag. + + + + + Get or set the auto-inherited required flag. + + + + + Get or set the ACL revision + + + + + Indicates the ACL has at least one conditional ACE. + + + + + Indicates the ACL has at least one object ACE. + + + + + Base class to represent an ALPC message. + + + + + Constructor. + + The port message header. + + + + Constructor. + + + + + Update the header length fields. + + The length of the valid data. + The maximum data length supported by the packet. + + + + Method to handle when ToSafeBuffer is called. + + The message buffer being created. + + + + Method to handle when FromSafeBuffer is called. + + The message buffer to initialize from.. + The ALPC port associated with this message. + + + + Get or set the header. + + + + + The process ID of the sender. + + + + + The thread ID of the sender. + + + + + Get total length of the message. + + + + + Get the allocated data length for the message. + + + + + Get data length of the message. + + + + + Get the message ID. + + + + + Get the callback ID. + + + + + Get the message type. + + + + + Get additional flags on message type. + + + + + Indicates that the message requires a reply (otherwise things can leak). + + + + + Indicates that the message requires a reply (obsolete). + + + + + Get direct status for the message. + + The direct status for the message. Returns STATUS_PENDING if the message is yet to be processed. + + + + Get the maximum size of a message minus the header size. + + + + + Create a safe buffer for this message. + + The safe buffer. + + + + Method to query information for a message. + + The information class. + The port which has processed the message. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + The port which has processed the message. + A default value for the query. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a fixed structure from the object. + + The type of structure to return. + The port which has processed the message. + The information class to query. + A default value for the query. + The result of the query. + Thrown on error. + + + + Query a fixed structure from the object. + + The type of structure to return. + The port which has processed the message. + The information class to query. + The result of the query. + Thrown on error. + + + + An ALPC message which holds a raw set of bytes. + + + + + Constructor. + + Data to initialize the message with. + Maximum length of the message buffer. + Specify a text encoding for the DataString property. + + + + Constructor. + + Data to initialize the message with. + Maximum length of the message buffer. + + + + Constructor. + + Data to initialize the message with. + + + + Constructor. + + Data to initialize the message with. + Specify a text encoding for the DataString property. + + + + Constructor. + + Total allocated length of the message buffer. + + + + Constructor. + + Total allocated length of the message buffer. + Specify a text encoding for the DataString property. + + + + Get or set the message data. + + When you set the data it'll update the DataLength and TotalLength fields. + + + + Get or set the message data as an encoding string. + + When you set the data it'll update the DataLength and TotalLength fields. + + + + Get or set the text encoding in this raw message. + + + + + Method to handle when FromSafeBuffer is called. + + The message buffer to initialize from.. + The ALPC port associated with this message. + + + + Method to handle when ToSafeBuffer is called. + + The message buffer being created. + + + + An ALPC message which holds a specific type with optional trailing data. + + The type representing the data. + + + + Constructor for a receive buffer. + + + + + Constructor for a receive buffer. + + Length of message. This will be rounded up to at least accomodate the header. + + + + Constructor for a send/receive buffer. + + The initial value to set. + Trailing data. + + + + Constructor for a send/receive buffer. + + The initial value to set. + + + + Get or set the type in the buffer. + + + + + Get or set any trailing data after the value. + + + + + Method to handle when FromSafeBuffer is called. + + The message buffer to initialize from.. + The ALPC port associated with this message. + + + + Method to handle when ToSafeBuffer is called. + + The message buffer being created. + + + + Class to represent a set of sending attributes. + + + + + Constructor. + + + + + Constructor. + + List of attributes to send. + + + + Add an attribute object. + + The attribute to add. + + + + Remove an attribute object. + + The attribute flag to remove. + + + + Remove an attribute object. + + The attribute to remove. + + + + Add a list of handles to the send attributes. + + The list of objects. + This method doesn't maintain a reference to the objects. You need to keep them alive elsewhere. + + + + Add a list of handles to the send attributes. + + The list of handles. + + + + Add a list of handles to the send attributes. + + The handle to add. + This method doesn't maintain a reference to the objects. You need to keep them alive elsewhere. + + + + Add a list of handles to the send attributes. + + The handle to add. + + + + Get the allocated attributes. + + + + + Class to represent a set of received attributes. + + + + + Constructor. Allocated space for all known attributes. + + + + + Constructor. + + + + + Get the allocated attributes. + + + + + Get the list of valid attributes. + + + + + Get a list of the valid attributes. + + + + + Get list of passed handles. + + + + + Get the mapped data view. If no view sent this property is invalid. + + + + + Get the security context. If no security context this property is invalid. + + + + + Dispose method. + + + + + Get a typed attribute. + + The type of attribute to get. + The attribute. Returns a default initialized object if not valid. + + + + Get an attribute. + + The attribute flag to get. + The attribute. Returns null if not found. + + + + Convert this set of attributes to a buffer to send. + + The send attributes. + + + + Convert this set of attributes to one which can be used to free on continuation required. + + The attributes to + The send attributes. + + + + Checks if an attribute flag is valid. + + The attribute to test. + True if the attribute is value. + + + + Base class to represent a message attribute. + + + + + The flag for this attribute. + + + + + Constructor. + + The single attribute flag which this represents. + + + + Class representing a security message attribute. + + + + + Constructor. + + + + + Security attribute flags. + + + + + Security quality of service. + + + + + Context handle. + + + + + Create an attribute which with create a handle automatically. + + The security quality of service. + The security message attribute. + + + + Class representing a security message attribute. + + + + + Constructor. + + + + + Token ID of token. + + + + + Authentication ID of token. + + + + + Modified ID of token + + + + + Class representing a security message attribute. + + + + + Constructor. + + + + + Port context. + + + + + Message context. + + + + + Sequence number. + + + + + Message ID. + + + + + Callback ID. + + + + + Class representing a data view message attribute. + + + + + Constructor. + + + + + View flags. + + + + + Handle to section. + + + + + View base. + + + + + View size. + + + + + Handle attribute entry. + + + + + Handle flags. + + + + + The NT object. + + + + + The object type for the handle. + + + + + Desired access for the handle. + + + + + Constructor. + + Handle attribute to initialize from. + + + + Constructor. + + Handle attribute to initialize from. + + + + Constructor. + + Information structure to initialize from. + + + + Constructor. + + + + + Constructor. + + The object to construct the entry from. Will take a copy of the handle. + + + + Class representing a handle message attribute. + + + + + Constructor. + + + + + Constructor. + + List of handle entries. + + + + Constructor. + + The handle entry. + + + + Constructor. + + List of objects to create the handle entries. + This constructor takes copies of the objects. + + + + Constructor. + + A single object to send. + This constructor takes copies of the object. + + + + List of handles in this attribute. + + + + + Class representing a direct message attribute. + + + + + Constructor. + + The event object. + + + + The event object. + + + + + Class representing a work on behalf of message attribute. + + + + + Constructor. + + + + + Thread ID. + + + + + Thread creation time (low). + + + + + Safe buffer to store an allocated set of ALPC atributes. + + + + + Get a pointer to an allocated attribute. Returns NULL if not available. + + The attribute to get. + The pointer to the attribute buffer, IntPtr.Zero if not found. + + + + Get an attribute as a structured type. + + The attribute type. + The attribute. + A buffer which represents the structured type. + Thrown if attribute doesn't exist. + + + + Create a new buffer with allocations for a specified set of attributes. + + The attributes to allocate. + The allocated buffed. + + + + Dispose the safe buffer. + + True if disposing + + + + Detaches the current buffer and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + Get the NULL buffer. + + + + + Class to represent an ALPC port section. + + + + + Handle to the port section. + + + + + Size of the port section. + + + + + The actual section size. + + + + + Create a new section view attribute. + + Specify the flags for the data view attribute. + The section view size. + True to throw on error. + The section view attribute. + + + + Create a new section view attribute. + + True to throw on error. + The section view attribute. + + + + Create a new section view attribute. + + Specify the flags for the data view attribute. + The section view size. + The section view attribute. + + + + Create a new section view attribute. + + The section view attribute. + + + + Dispose of the port section. + + + + + Supported windows verion + + + + + This should always be at the end. + + + + + Attribute to indicate the required version for a function. + Applied if the function needs a version greater than 7. + + + + + The supported version. + + + + + Constructor + + The supported version + + + + Attribute used for managed structures to indicate the start of data. + This is used in situations where the data immediately trail + + + + + Constructor + + The field name which indicates the first address of data. + + + + The field name which indicates the first address of data. + + + + + When allocating this structure always include the field in the total length calculation. + + + + + Class to represent an API set entry. + + + + + Flags for the entry. + + + + + The name of the API set. + + + + + The default host module. + + + + + Hash version of the name. + + + + + List of hosts. + + + + + Get host module for an import module. + + + + + + + Represents a single API set host. + + + + + The imported module this API set host applies to. + + + + + The module which implements this API set. + + + + + Is the host the default host. + + + + + Flags for API set namespace. + + + + + None. + + + + + The API set is sealed. + + + + + The API set is an extension. + + + + + Class to represent an API set namespace. + + + + + Flags for the namespace. + + + + + List of API set entries. + + + + + Get API set namespace from current process. + + + + + Gets an API set based on its name. + + The API set name. + The API set entry. Returns null if not found. + + + + Flags for a boundary descriptor + + + + + None + + + + + Automatically add the AppContainer package SID to the boundary + + + + + Class which represents a private namespace boundary descriptor + + + + + Constructor + + The name of the boundary + Additional flags for the boundary + + + + Constructor + + The name of the boundary + + + + Add a SID to the boundary descriptor. + + This SID is used in an access check when creating or deleting private namespaces. + The SID to add. + + + + Add an integrity level to the boundary descriptor. + + This integrity level is used in an access check when creating or deleting private namespaces. + The integrity level to add. + + + + Add a list of SIDs to the boundary descriptor. + + The SIDs to add. This can include normal and integrity level SIDs + + + + Add a list of SIDs to the boundary descriptor. + + The first SID to add + Additional SIDs + + + + The handle to the boundary descriptor. + + + + + Create a boundary descriptor from a string representation. + + A boundary descriptor string of the form [SID[:SID...]@]NAME where SID is an SDDL format SID. + The new boundary descriptor. + + + + Finalizer + + + + + Dispose + + + + + Some simple utilities to create structure buffers. + + + + + Create a buffer based on a passed type. + + The type to use in the structure buffer. + The value to initialize the buffer with. + Additional byte data after the structure. + Indicates if additional_size includes the structure size or not. + The new structure buffer. + + + + Create a buffer based on a passed type. + + The type to use in the structure buffer. + The value to initialize the buffer with. + The new structure buffer. + + + + Create a buffer based on a passed type. + + The type to use in the structure buffer. + The value to initialize the buffer with. + The new structure buffer. + + + + Create a buffer based on a passed type. + + The type to use in the structure buffer. + The value to initialize the buffer with. + Additional byte data after the structure. + Indicates if additional_size includes the structure size or not. + The new structure buffer. + + + + Create a buffer based on a byte array. + + The byte array for the buffer. + The safe buffer. + + + + Create an buffer from an array. + + The array element type, must be a value type. + The array of elements. + The allocated array buffer. + + + + Read a NUL terminated string for the byte offset. + + The buffer to read from. + The byte offset to read from. + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated byte string for the byte offset. + + The buffer to read from. + The byte offset to read from. + Text encoding for the string. + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated ANSI string for the byte offset. + + The buffer to read from. + The byte offset to read from. + The string read from the buffer without the NUL terminator + + + + Read a char array with length. + + The buffer to read from. + The number of characters to read. + The byte offset to read from. + The chars read from the buffer + + + + Read a Unicode string string with length. + + The buffer to read from. + The number of characters to read. + The byte offset to read from. + The string read from the buffer. + + + + Write char array. + + The buffer to write to. + The byte offset to write to. + The chars to write. + + + + Write unicode string. + + The buffer to write to. + The byte offset to write to. + The string value to write. + + + + Read bytes from buffer. + + The buffer to read from. + The byte offset to read from. + The number of bytes to read. + The byte array. + + + + Write bytes to a buffer. + + The buffer to write to. + The byte offset to write to. + The data to write. + + + + Get a structure buffer at a specific offset. + + The type of structure. + The buffer to map. + The offset into the buffer. + The structure buffer. + The returned buffer is not owned, therefore you need to maintain the original buffer while operating on this buffer. + + + + Creates a view of an existing safe buffer. + + The buffer to create a view on. + The offset from the start of the buffer. + The length of the view. + The buffer view. + Note that the returned buffer doesn't own the memory, therefore the original buffer + must be maintained for the lifetime of this buffer. + + + + Creates a view of an existing safe buffer. + + The buffer to create a view on. + The offset from the start of the buffer. + The length of the view. + True to make the view writable, false for read-only. + The buffer view. + Note that the returned buffer doesn't own the memory, therefore the original buffer + must be maintained for the lifetime of this buffer. + + + + Zero an entire buffer. + + The buffer to zero. + + + + Fill an entire buffer with a specific byte value. + + The buffer to full. + The fill value. + + + + Compare two buffers for equality. + + The left buffer. + The offset into the left buffer. + The right buffer. + The offset into the right buffer. + The length to compare. + True if the buffers are equal. + + + + Compare a buffer and a byte array for equality. + + The buffer. + The offset into the left buffer. + The compare byte array. + True if the buffers are equal. + + + + Find a byte array in a buffer. Returns all instances of the compare array. + + The buffer to find the data in. + Start offset in the buffer. + The comparison byte array. + A list of offsets into the buffer where the compare was found. + + + + Find a byte array in a buffer. Returns all instances of the compare array. + + The buffer to find the data in. + The comparison byte array. + A list of offsets into the buffer where the compare was found. + + + + Class to represent a Security Atttribute. + + + + + The name of the attribute. + + + + + The type of values. + + + + + The attribute flags. + + + + + The list of values. + + + + + The count of values. + + + + + Convert the attribute to a builder to modify it. + + The builder object. + + + + Convert the security attribute to an SDDL string. + + The security attribute as an SDDL string. + + + + Converts the attribute to a Resource Attribute ACE. + + The resource attribute ACE. + + + + Class to create a new user process using the native APIs. + + + + + Path to the executable to start. + + + + + Path to the executable to start which is passed in the process configuration. + + + + + Command line + + + + + Prepared environment block. + + + + + Title of the main window. + + + + + Path to DLLs. + + + + + Current directory for new process + + + + + Desktop information value + + + + + Shell information value + + + + + Runtime data. + + + + + Prohibited image characteristics for new process + + + + + Additional file access for opened executable file. + + + + + Process create flags. + + + + + Thread create flags. + + + + + Initialization flags + + + + + Parent process. + + + + + Restrict new child processes + + + + + Override restrict child process + + + + + Extra process/thread attributes + + + + + Added protected process protection level. + + The type of protected process. + The signer level. + + + + Return on error instead of throwing an exception. + + + + + Whether to terminate the process on dispose. + + + + + Specify a security descriptor for the process. + + + + + Specify a security descriptor for the initial thread. + + + + + Specify the primary token for the new process. + + + + + Access for process handle. + + + + + Access for thread handle. + + + + + Constructor + + + + + For the current process + + The new forked process result + + + + For the current process + + Process create flags. + Thread create flags. + The new forked process result + + + + For the current process + + Process create flags. + Thread create flags. + True to throw on error. + The new forked process result + + + + Start the new process based on the ImagePath parameter. + + The result of the process creation + + + + Start the new process + + The image path to the file to execute + The result of the process creation + + + + Result from a native create process call. + + + + + Handle to the process + + + + + Handle to the initial thread + + + + + Handle to the image file + + + + + Handle to the image section + + + + + Handle to the IFEO key (if it exists) + + + + + Image information + + + + + Client ID of process and thread + + + + + Process ID + + + + + Thread ID + + + + + Create status + + + + + True if create succeeded + + + + + Result of the create information + + + + + Creation state + + + + + Terminate the process + + Exit code for termination + + + + Resume initial thread + + The suspend count + + + + Set to true to terminate process on disposal + + + + + Finalizer + + + + + Dispose + + + + + The base class for a debug event. + + + + + Process ID for the event. + + + + + Thread ID for the event. + + + + + The event code. + + + + + Constructor. + + The current debug event. + The debug port associated with this event. + + + + Continue the debugged process. + + The continue status code. + True to throw on error. + The NT status code. + + + + Continue the debugged process. + + The continue status code. + + + + Continue the debugged process with a success code. + + + + + Dispose the event. + + + + + Debug event for the Create Process event. + + + + + Subsystem key for the process. + + + + + Handle to the process file (if available). + + + + + Base of image file. + + + + + Debug info file offset. + + + + + Debug info file size. + + + + + Subsystem key for the thread. + + + + + Start address of the thread. + + + + + Handle to the process (if available). + + + + + Handle to the thread (if available). + + + + + Dispose the event. + + + + + Debug event for the Create Thread event. + + + + + Subsystem key for the thread. + + + + + Start address of the thread. + + + + + Handle to the thread (if available). + + + + + Dispose the event. + + + + + Debug event for the Exit Thread event. + + + + + Exit status code. + + + + + Debug event for the Exit Process event. + + + + + Exit status code. + + + + + Debug event for load DLL event. + + + + + DLL file handle. + + + + + Base of loaded DLL. + + + + + Debug info offset. + + + + + Debug info size. + + + + + Address of name. + + + + + Dispose the event. + + + + + Debug event for unload DLL event. + + + + + Base of loaded DLL. + + + + + Debug event for exception event. + + + + + Indicates if this is a first chance exception. + + + + + Exception code. + + + + + Exception flags. + + + + + Pointer to next exception in the chain. + + + + + Address of exception. + + + + + Additional parameters for exception. + + + + + Debug event when we don't handle the state. + + + + + The raw debug event. + + + + + Represents a list where the elements can be trivially disposed in one go. + + An IDisposable implementing type + + + + Constructor + + + + + Constructor + + The initial capacity of the list + + + + Constructor + + A collection to initialize the list + + + + Add a resource to the list and return a reference to it. + + The type of resource to add. + The resource object. + The added resource. + + + + Add a resource to the list and return a reference to it. + + The type of resource to add. + The added resource. + + + + Convert this list to an array then clear it to the disposal no longer happens. + + The elements as an array. + After doing this the current list will be cleared. + + + + Detach a detachable reference and add it to the list. + + The type of resource to detach. + The detached resource. + + + + Dispose method + + + + + Implementation of disposable list which just accepts IDisposable objects. + + + + + Constructor + + + + + Constructor + + The initial capacity of the list + + + + Constructor + + A collection to initialize the list + + + + Adds a delegate which will be called when the list is disposed. + + The delegate to call on dispose. + This can be used to add more complex disposable. + + + + Disposable list of safe handles + + + + + Constructor + + + + + Constructor + + The initial capacity of the list + + + + Constructor + + A collection to initialize the list + + + + Move the handle list to a new disposable list. + + The list of handles which have been moved. + After doing this the current list will be cleared. + + + + Flags for an EA entry + + + + + No flags. + + + + + Processor must handle this EA. + + + + + A single EA entry. + + + + + Name of the entry + + + + + Data associated with the entry + + + + + Flags + + + + + Constructor + + The name of the entry + Data associated with the entry + Flags for entry. + + + + Constructor + + The name of the entry + Data associated with the entry + Flags for entry. + + + + Constructor + + The name of the entry + Data associated with the entry + Flags for entry. + + + + Get the EA buffer data as a string. + + The data as a string. + + + + Get the EA buffer data as an Int32. + + The data as an Int32. + + + + Convert entry to a string + + The entry as a string + + + + Class to create an Extended Attributes buffer for NtCreateFile + + + + + Constructor + + + + + Constructor + + List of entries to add. + + + + Constructor from a binary EA buffer + + The EA buffer to parse + + + + Constructor + + Existing buffer to copy. + + + + Add a new EA entry from an old entry. The data will be cloned. + + The entry to add. + + + + Add a new EA entry + + The name of the entry + The associated data, will be cloned + The entry flags. + + + + Add a new EA entry + + The name of the entry + The associated data + The entry flags. + + + + Add a new EA entry + + The name of the entry + The associated data + The entry flags. + + + + Get an entry by name. + + The name of the entry. + The found entry. + Thrown if no entry by that name. + + + + Remove an entry from the buffer. + + The entry to remove. + + + + Remove an entry from the buffer by name. + + The name of the entry. + Thrown if no entry by that name. + + + + Convert to a byte array + + The byte array + + + + Get the list of entries. + + + + + Get number of entries. + + + + + Get whether the buffer contains a specific entry. + + The name of the entry. + True if the buffer contains an entry with the name. + + + + Index to get an entry by name. + + The name of the entry. + The found entry. + Thrown if no entry by that name. + + + + Clear all entries. + + + + + Access rights generic mapping. + + + + + Mapping for Generic Read + + + + + Mapping for Generic Write + + + + + Mapping for Generic Execute + + + + + Mapping for Generic All + + + + + Map a generic access mask to a specific one. + + The generic mask to map. + The mapped mask. + + + + Get whether this generic mapping gives read access. + + The mask to check against. + True if we have read access. + + + + Get whether this generic mapping gives write access. + + The mask to check against. + True if we have write access. + + + + Get whether this generic mapping gives execute access. + + The mask to check against. + True if we have execute access. + + + + Get whether this generic mapping gives all access. + + The mask to check against. + True if we have all access. + + + + Try and unmap access mask to generic rights. + + The mask to unmap. + The unmapped mask. Any access which can be generic mapped is left in the mask as specific rights. + + + + Get the allowed access mask for a specified mandatory access policy. + + The mandatory access policy. + The allowed access mask for the policy. + In general NoWriteUp will always be set on the policy. + + + + Convert generic mapping to a string. + + The generic mapping as a string. + + + + Interface to abstract the kernel transaction manager support. + + + + + Get handle for the transaction. + + + + + Commit the transaction + + + + + Rollback the transaction + + + + + Enable the transaction for anything in the current thread context. + + The transaction context. This should be disposed to disable the transaction. + + + + Class to represent a mount point. + + + + + Symbolic link name. + + + + + Unique ID. + + + + + Device name. + + + + + Class to access mount point manager utilities. + + + + + Query the list of mount points. + + True to throw on error. + The list of mount points. + + + + Query the list of mount points. + + The list of mount points. + + + + Class to represent the USN journal data. + + + + + Flags for the USN journal change reason. + + + + + Class to represent a USN journal record. + + + + + Reference number of the file. + + + + + Reference number of the parent. + + + + + USN value. + + + + + Timestamp of entry. + + + + + Reason code. + + + + + Source info flags. + + + + + Security ID. + + + + + File attributes. + + + + + Filename. + + + + + Full path, if known. + + + + + Full Win32Path if known. + + + + + Flags for USN journal source information. + + + + + Class for methods relating to USN journal. + + + + + Read USN journal information. + + The handle to the volume to query. + True to throw on error. + The USN journal information. + + + + Read USN journal information. + + The handle to the volume to query. + The USN journal information. + + + + Read USN journal entries from the volume. + + The volume to read. + The start USN to read. + Last USN to read, exclusive. + Mask for what records to read. + The list of USN journal entries. + + + + Read all USN journal entries from the volume. + + The volume to read. + The list of USN journal entries. + + + + Read USN journal entries from the volume, unprivileged. + + The volume to read. + The start USN to read. + Last USN to read, exclusive. + Mask for what records to read. + The list of USN journal entries. + + + + Read USN journal entries from the volume, unprivileged. + + The volume to read. + The list of USN journal entries. + + + + An enumeration to reference a known SID. + + + + + NULL SID + + + + + Everyone SID + + + + + Local user SID + + + + + CREATOR OWNER SID + + + + + CREATOR GROUP SID + + + + + CREATOR OWNER SERVER SID + + + + + CREATOR OWNER SERVER SID + + + + + Service SID + + + + + ANONYMOUS LOGON SID + + + + + Authenticated Users SID + + + + + RESTRICTED SID + + + + + LOCAL SYSTEM SID + + + + + LOCAL SERVICE SID + + + + + NETWORK SERVICE SID + + + + + APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES SID + + + + + APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES + + + + + NT SERVICE\TrustedInstaller + + + + + BUILTIN\Users + + + + + BUILTIN\Administrators + + + + + APPLICATION PACKAGE AUTHORITY\Your Internet connection + + + + + APPLICATION PACKAGE AUTHORITY\Your Internet connection, including incoming connections from the Internet + + + + + APPLICATION PACKAGE AUTHORITY\Your home or work networks + + + + + APPLICATION PACKAGE AUTHORITY\Your pictures library + + + + + APPLICATION PACKAGE AUTHORITY\Your videos library + + + + + APPLICATION PACKAGE AUTHORITY\Your music library + + + + + APPLICATION PACKAGE AUTHORITY\Your documents library + + + + + APPLICATION PACKAGE AUTHORITY\Your Windows credentials + + + + + APPLICATION PACKAGE AUTHORITY\Software and hardware certificates or a smart card + + + + + APPLICATION PACKAGE AUTHORITY\Removable storage + + + + + APPLICATION PACKAGE AUTHORITY\Your Appointments + + + + + APPLICATION PACKAGE AUTHORITY\Your Contacts + + + + + APPLICATION PACKAGE AUTHORITY\Internet Explorer + + + + + Constrained Impersonation Capability + + + + + OWNER RIGHTS + + + + + NT AUTHORITY\SELF + + + + + NT AUTHORITY\WRITE RESTRICTED + + + + + BUILTIN\BUILTIN + + + + + NT AUTHORITY\INTERACTIVE + + + + + NT AUTHORITY\DIALUP + + + + + NT AUTHORITY\NETWORK + + + + + NT AUTHORITY\BATCH + + + + + NT AUTHORITY\PROXY + + + + + Static methods to get some known SIDs. + + + + + NULL SID + + + + + Everyone SID + + + + + Local user SID + + + + + CREATOR OWNER SID + + + + + CREATOR GROUP SID + + + + + CREATOR OWNER SERVER SID + + + + + CREATOR OWNER SERVER SID + + + + + Service SID + + + + + ANONYMOUS LOGON SID + + + + + Authenticated Users SID + + + + + RESTRICTED SID + + + + + NT AUTHORITY\WRITE RESTRICTED + + + + + BUILTIN\BUILTIN + + + + + NT AUTHORITY\INTERACTIVE + + + + + NT AUTHORITY\DIALUP + + + + + NT AUTHORITY\NETWORK + + + + + NT AUTHORITY\BATCH + + + + + NT AUTHORITY\PROXY + + + + + LOCAL SYSTEM SID + + + + + LOCAL SERVICE SID + + + + + NETWORK SERVICE SID + + + + + APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES SID + + + + + APPLICATION PACKAGE AUTHORITY\ALL RESTRICTED APPLICATION PACKAGES + + + + + NT SERVICE\TrustedInstaller + + + + + BUILTIN\Users + + + + + BUILTIN\Administrators + + + + + APPLICATION PACKAGE AUTHORITY\Your Internet connection + + + + + APPLICATION PACKAGE AUTHORITY\Your Internet connection, including incoming connections from the Internet + + + + + APPLICATION PACKAGE AUTHORITY\Your home or work networks + + + + + APPLICATION PACKAGE AUTHORITY\Your pictures library + + + + + APPLICATION PACKAGE AUTHORITY\Your videos library + + + + + APPLICATION PACKAGE AUTHORITY\Your music library + + + + + APPLICATION PACKAGE AUTHORITY\Your documents library + + + + + APPLICATION PACKAGE AUTHORITY\Your Windows credentials + + + + + APPLICATION PACKAGE AUTHORITY\Software and hardware certificates or a smart card + + + + + APPLICATION PACKAGE AUTHORITY\Removable storage + + + + + APPLICATION PACKAGE AUTHORITY\Your Appointments + + + + + APPLICATION PACKAGE AUTHORITY\Your Contacts + + + + + APPLICATION PACKAGE AUTHORITY\Internet Explorer + + + + + Constrained Impersonation Capability + + + + + Get a known SID based on a specific enumeration. + + The enumerated sid value. + + + + + Class to represent an Access Control Entry for a Mandatory Label. + + + + + Constructor. + + Flags for the ACE. + The mandatory label policy. + The integrity level. + + + + Constructor from a raw integrity level. + + Flags for the ACE. + The mandatory label policy. + The integrity level sid. + + + + The policy for the mandatory label. + + + + + Get or set the integrity level + + + + + Convert ACE to a string. + + + + + + Class which represents a mapped file. + + + + + Native path to file. + + + + + Name of the file. + + + + + List of mapped sections. + + + + + Mapped base address of file. + + + + + Mapped size of file. + + + + + True if the mapped file is an image section. + + + + + Specified the signing level if an image (only on RS3+). + + + + + Class to represent memory information. + + + + + Base address of memory region. + + + + + Allocation base for memory region. + + + + + Initial allocation protection. + + + + + Region size. + + + + + Memory state. + + + + + Current memory protection. + + + + + Memory type. + + + + + The mapped image path, if an image. + + + + + The mapped image path name, if an image. + + + + + The region type. + + + + + Is this a software enclave. + + + + + Interface for a marshalled NDR conformant structure. + + This interface is primarily for internal use only. + + + + Gets the number of conformant dimensions, should be at least one. + + The number of conformant dimensions. + + + + Interface for a marshalled non-encapsulated NDR union. + + This interface is primarily for internal use only. + + + + Marshal the union to a stream. + + The selector for union arm. + The marshal stream. + + + + Interface for a marshalled NDR structure. + + This interface is primarily for internal use only. + + + + Marshal the stucture to a stream. + + The marshal stream. + + + + Unmarshal the structure from a stream. + + The unmarshal stream. + + + + Get the structure's alignment. + + + + + + Structure to represent a context handle. + + + + + Context handle attributes. + + + + + Context handle UUID. + + + + + Constructor. + + Context handle attributes. + Context handle UUID. + + + + Overidden ToString method. + + The handle as string. + + + + NDR integer representation. + + + + + NDR character representation. + + + + + NDR floating point representation. + + + + + Definition of the NDR data representation for an NDR stream. + + + + + The integer representation of the NDR data. + + + + + The character representation of the NDR data. + + + + + The floating representation of the NDR data. + + + + + A class which represents an embedded pointer. + + The underlying type. + + + + Operator to convert from a value to an embedded pointer. + + The value to point to. + + + + Operator to convert from an embedded pointer to a value. + + The embedded pointer. + + + + Overridden ToString method. + + The string form of the value. + + + + Get the value from the embedded pointer. + + The value of the pointer. + + + + Structure to represent an empty value. + + + + + Class to represent a 16 bit enumerated type. + + + + + Value of the structure. + + + + + Constructor. + + + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Equality operator. + + The left value. + The right value. + True if the values are equal. + + + + Inequality operator. + + The left value. + The right value. + True if the values are not-equal. + + + + Overridden ToString. + + The value as a string. + + + + ToString method. + + The formatting string. + The value as a string. + + + + IFormattable ToString. + + The formatting string. + Formatting provider. + The value as a string. + + + + Equals operator. + + The other enum16. + True if the values are equal. + + + + Compare + + + + + + + Overridden GetHashCode. + + The hash code of the enumeration. + + + + Structure which represents an NDR FC_INT3264 + + + + + Value of the structure. + + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Convert to a native IntPtr. + + The value to convert from. + + + + Overridden ToString. + + The value as a string. + + + + ToString method. + + The formatting string. + The value as a string. + + + + IFormattable ToString. + + The formatting string. + Formatting provider. + The value as a string. + + + + Structure which represents an NDR FC_UINT3264 + + + + + Value of the structure. + + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Constructor. + + The value to construct from. + + + + Convert to a native IntPtr. + + The value to convert from. + + + + Overridden ToString. + + The value as a string. + + + + ToString method. + + The formatting string. + The value as a string. + + + + IFormattable ToString. + + The formatting string. + Formatting provider. + The value as a string. + + + + Class to represent an NDR interface pointer. + + + + + The marshaled interface data. + + + + + Constructor. + + The marshaled interface data. + + + + A buffer to marshal NDR data to. + + This class is primarily for internal use only. + + + + Represents an NDR pickled type. + + + + + Constructor from a type 1 serialized buffer. + + The type 1 serialized encoded buffer. + + + + Convert the pickled type to a type 1 serialized encoded buffer. + + The type 1 serialized encoded buffer. + + + + Type for a synchronous NDR pipe. + + The base type of pipe blocks. + + + + The list of blocks for the pipe. + + + + + Constructor. + + The list of blocks to return. + + + + Constructor. + + A single block to return. + + + + Convert the pipe blocks to a flat array. + + The flat array. + + + + A buffer to unmarshal NDR data from. + + This class is primarily for internal use only. + + + + Place holder for unsupported types. + + + + + Class to represent a single COM proxy definition. + + + + + The name of the proxy interface. + + + + + The IID of the proxy interface. + + + + + The base IID of the proxy interface. + + + + + The number of dispatch methods on the interface. + + + + + List of parsed procedures for the interface. + + + + + Creates a proxy definition from a list of procedures. + + The name of the proxy interface. + The IID of the proxy interface. + The base IID of the proxy interface. + The total dispatch count for the proxy interface. + The list of parsed procedures for the proxy interface. + + + + + Expression element. + + + + + Overridden ToString method. + + The expression as a string. + + + + The expression type. + + + + + Is this operator element valid. + + + + + Operator expression element. + + + + + NDR format type of element. + + + + + NDR format type of element. + + + + + Offset, used for OP_EXPRESSION. + + + + + Parsed arguments. + + + + + Overridden ToString method. + + The expression as a string. + + + + Variable expression element. + + + + + Offset of the variable. + + + + + NDR format type of element. + + + + + Overridden ToString method. + + The expression as a string. + + + + Expression element. + + + + + NDR format type of element. + + + + + Offset of the variable. + + + + + The value of the constant. + + + + + Overridden ToString method. + + The expression as a string. + + + + An interface which can be implemented to handle formatting parsed NDR data. + + + + + Format a complex type using the current formatter. + + The complex type to format. + The formatted complex type. + + + + Format a procedure using the current formatter. + + The procedure to format. + The formatted procedure. + + + + Format a COM proxy using the current formatter. + + The COM proxy to format. + The formatted COM proxy. + + + + Format an RPC server interface using the current formatter. + + The RPC server. + The formatted RPC server interface. + + + + An base class which describes a text formatter for NDR data. + + + + This formatter generates data that the CPP compiler can (hopefully) understand, + at least it will serve as a good skeleton to support spinning up new projects easily. + + + + + Flags for the NDR formatter. + + + + + No flags. + + + + + Don't emit comments. + + + + + Default NDR formatter constructor. + + + + + Create the default formatter. + + Specify a dictionary of IIDs to names. + Function to demangle COM interface names during formatting. + Formatter flags. + The default formatter. + + + + Create the default formatter. + + Specify a dictionary of IIDs to names. + Function to demangle COM interface names during formatting. + The default formatter. + + + + Create the default formatter. + + Specify a dictionary of IIDs to names. + Formatter flags. + The default formatter. + + + + Create the default formatter. + + Specify a dictionary of IIDs to names. + The default formatter. + + + + Create the default formatter. + + Formatter flags. + The default formatter. + + + + Create the default formatter. + + The default formatter. + + + + NDR formatter constructor for CPP style output. + + + + + Create the CPP formatter. + + Specify a dictionary of IIDs to names. + Function to demangle COM interface names during formatting. + Formatter flags. + The CPP formatter. + + + + Create the CPP formatter. + + Specify a dictionary of IIDs to names. + Function to demangle COM interface names during formatting. + The CPPformatter. + + + + Create the CPP formatter. + + Specify a dictionary of IIDs to names. + Formatter flags. + The CPP formatter. + + + + Create the CPP formatter. + + Specify a dictionary of IIDs to names. + The CPP formatter. + + + + Create the default formatter. + + Formatter flags. + The CPP formatter. + + + + Create the default formatter. + + The CPP formatter. + + + + Flags for the parser. + + + + + No flags. + + + + + Ignore processing any complex user marshal types. + + + + + Resolve structure names, required private symbols. + + + + + Class to parse NDR data into a structured format. + + + + + Constructor. + + Memory reader to parse from. + Process to read from. + Specify a symbol resolver to use for looking up symbols. + Flags which affect the parsing operation. + + + + Constructor. + + Process to parse from. + Specify a symbol resolver to use for looking up symbols. + + + + Constructor. + + Process to parse from. + Specify a symbol resolver to use for looking up symbols. + Flags which affect the parsing operation. + + + + Constructor. + + Specify a symbol resolver to use for looking up symbols. + + + + Constructor. + + Process to parse from. + + + + Constructor. + + + + + Read COM proxy information from a ProxyFileInfo structure. + + The address of the ProxyFileInfo structure. + The list of parsed proxy definitions. + + + + Read COM proxy information from an array of pointers to ProxyFileInfo structures. + + The address of an array of pointers to ProxyFileInfo structures. The last pointer should be NULL. + The list of parsed proxy definitions. + + + + Read COM proxy information from a file. + + The path to the DLL containing the proxy. + Optional CLSID for the proxy class. + List of IIDs to parse. + The list of parsed proxy definitions. + + + + Read COM proxy information from a file. + + The path to the DLL containing the proxy. + Optional CLSID for the proxy class. + The list of parsed proxy definitions. + + + + Read COM proxy information from a file. + + The path to the DLL containing the proxy. + The list of parsed proxy definitions. + + + + Parse NDR content from an RPC_SERVER_INTERFACE structure in memory. + + Pointer to the RPC_SERVER_INTERFACE. + The parsed NDR content. + + + + Parse NDR content from an RPC_SERVER_INTERFACE structure in memory. + + Pointer to the RPC_SERVER_INTERFACE. + Base address of the library which contains the interface. + The parsed NDR content. + + + + Parse NDR content from an RPC_SERVER_INTERFACE structure in memory. Deprecated. + + Pointer to the RPC_SERVER_INTERFACE. + The parsed NDR content. + + + + Parse NDR content from an RPC_SERVER_INTERFACE structure in memory. + + The path to a DLL containing the RPC_SERVER_INTERFACE. + Offset to the RPC_SERVER_INTERFACE from the base of the DLL. + The parsed NDR content. + + + + Parse NDR procedures from an MIDL_SERVER_INFO structure in memory. + + Pointer to the MIDL_SERVER_INFO. + Number of dispatch functions to parse. + The start offset to parse from. This is used for COM where the first few proxy stubs are not implemented. + List of names for the valid procedures. Should either be null or a list equal in size to dispatch_count - start_offset. + The parsed NDR content. + + + + Parse NDR procedures from an MIDL_SERVER_INFO structure in memory. + + Pointer to the MIDL_SERVER_INFO. + Number of dispatch functions to parse. + The start offset to parse from. This is used for COM where the first few proxy stubs are not implemented. + The parsed NDR content. + + + + List of parsed types from the NDR. + + + + + List of parsed complex types from the NDR. + + + + + Parse NDR complex type information from a pickling structure. Used to extract explicit Encode/Decode method information. + + The process to read from. + Pointer to the MIDL_TYPE_PICKLING_INFO structure. + The pointer to the MIDL_STUB_DESC structure. + Pointers to the the format string to the start of the types. + Specify additional parser flags. + The list of complex types. + This function is used to extract type information for calls to NdrMesTypeDecode2. MIDL_TYPE_PICKLING_INFO is the second parameter, + MIDL_STUB_DESC is the third, the Type Offsets is the fourth parameter. + + + + Parse NDR complex type information from a pickling structure. Used to extract explicit Encode/Decode method information. + + The process to read from. + Pointer to the MIDL_TYPE_PICKLING_INFO structure. + The pointer to the MIDL_STUBLESS_PROXY_INFO structure. + Pointer to the type pickling offset table. + Index into type_pickling_offset_table array. + Specify additional parser flags. + The list of complex types. + This function is used to extract type information for calls to NdrMesTypeDecode3. MIDL_TYPE_PICKLING_INFO is the second parameter, + MIDL_STUBLESS_PROXY_INFO is the third, the type pickling offset table is the fourth and the type index is the fifth. + + + + Parse NDR complex type information from a pickling structure. Used to extract explicit Encode/Decode method information. + + The process to read from. + Pointer to the MIDL_TYPE_PICKLING_INFO structure. + The pointer to the MIDL_STUB_DESC structure. + Offsets into the format string to the start of the types. + Specify additional parser flags. + The list of complex types. + This function is used to extract type information for calls to NdrMesTypeDecode2. MIDL_TYPE_PICKLING_INFO is the second parameter, + MIDL_STUB_DESC is the third (minus the offset). + + + + Parse NDR complex type information from a pickling structure. Used to extract explicit Encode/Decode method information. + + The process to read from. + Pointer to the MIDL_TYPE_PICKLING_INFO structure. + The pointer to the MIDL_STUB_DESC structure. + Offsets into the format string to the start of the types. + The list of complex types. + This function is used to extract type information for calls to NdrMesTypeDecode2. MIDL_TYPE_PICKLING_INFO is the second parameter, + MIDL_STUB_DESC is the third (minus the offset). + + + + Parse NDR complex type information from a pickling structure. Used to extract explicit Encode/Decode method information. + + Pointer to the MIDL_TYPE_PICKLING_INFO structure. + The pointer to the MIDL_STUB_DESC structure. + Offsets into the format string to the start of the types. + The list of complex types. + This function is used to extract type information for calls to NdrMesTypeDecode2. MIDL_TYPE_PICKLING_INFO is the second parameter, + MIDL_STUB_DESC is the third (minus the offset). + + + + Exception thrown when NDR parsing fails. + + + + + Constructor. + + Exception message. + + + + Constructor. + + Exception message. + Inner exception to wrap. + + + + Class respresenting an RPC protocol sequence. + + + + + The protocol sequence for the endpoint. + + + + + The endpoint name. + + + + + A parsed NDR RPC_SERVER_INTERFACE structure. + + + + + The RPC interface GUID. + + + + + The RPC interface version. + + + + + The RPC transfer syntax GUID. + + + + + The RPC transfer syntax version. + + + + + List of parsed procedures. + + + + + List of protocol sequences. + + + + + Overridden ToString method. + + The string form of this class. + + + + NDR format character. + + + + + Class to build text strings for an NDR formatter. + + + + + Push an indent string on to the indent stack. + + The string to indent any new lines. + The current builder instance. + + + + Push an indent on to the indent stack. + + The character to indent with. + The number of indent characters. + The current builder instance. + + + + Pop the current indent off the indent stack. + + The current builder instance. + + + + Append a string to the builder. + + The string to append. + The current builder instance. + + + + Append a formatted string to the builder. + + The string format. + The array of arguments to the formatter. + The current builder instance. + + + + Append a new line to the builder. + + The current builder instance. + + + + Append a string to the builder with a new line. + + The string to append. + The current builder instance. + + + + Append a formatted string to the builder with a new line. + + The string format. + The array of arguments to the formatter. + The current builder instance. + + + + Overridden ToString method, returns the current state of the builder. + + The current stated of the builder. + + + + Utilities for NDR marshaling. + + + + + Specify NDR marshaler trace level. + + Specify the NDR marshaler trace level. + Verbose marshal stack details. + + + + Datalink address type. + + + + + Access rights for a firewall object. + + + + + Represents a firewall address and mask. + + + + + The IP address. + + + + + The mask. + + + + + Mask prefix length. + + + + + Overridden ToString method. + + The value and mask as a string. + + + + Address family when IP protocol is not specified. + + + + + IPv4 + + + + + IPv6 + + + + + Ethernet + + + + + None + + + + + Class to represent a firewall ALE endpoint. + + + + + The ID of the endpoint. + + + + + The local endpoint. + + + + + The remote endpoint. + + + + + The protocol type. + + + + + The LUID for the token associated with the endpoint. + + + + + The IPsec security association identifier. + + + + + The IPsec security association identifier to expire. + + + + + The IPsec status of the endpoint. + + + + + Flags. + + + + + Associated application. + + + + + Filename of AppId. + + + + + Enumeration for ALE layer types. + + + + + Class to represent a firewall callout object. + + + + + Flags for the callout. + + + + + Provider key. + + + + + Provider data. + + + + + Applicable layer key. + + + + + Callout ID. + + + + + Flags for a firewall callout. + + + + + Guids for pre-defined callouts. + + + + + Flags for classify output. + + + + + Class to represet the result of a classify operations. + + + + + Action type of the classify result. + + + + + Internal context. + + + + + ID of the filter. + + + + + Associated rights. + + + + + Classify flags. + + + + + Base class to implement common condition building operations. + + + + + Specify list of firewall filter conditions. + + + + + Add a condition. + + The match type for the condition. + The field key for the condition. + The value for the condition. + + + + Add a condition range. + + The field key for the condition. + The low value for the range. + The high value from the range. + + + + Add an executable filename condition. + + The match type for the condition. + The path to the file to use. + + + + Add an App ID condition. + + The match type for the condition. + The path to the file already converted to absolute format. + + + + Add a user ID security descriptor condition. + + The match type for the condition. + The security descriptor. + + + + Add a remote user ID security descriptor condition. + + The match type for the condition. + The security descriptor. + + + + Add a remote machine ID security descriptor condition. + + The match type for the condition. + The security descriptor. + + + + Add a IP protocol type condition. + + The match type for the condition. + The protocol type for the condition. + + + + Add a conditions flag condition. + + The match type for the condition. + The flags for the condition. + + + + Add IP address. + + The match type for the condition. + True to specify remote, false for local. + The low IP address. + + + + Add IP address range. + + True to specify remote, false for local. + The low IP address. + The high IP address. + + + + Add port range. + + True to specify remote, false for local. + The low port. + The high port. + + + + Add port. + + The match type for the condition. + True to specify remote, false for local. + The port. + + + + Add an IP endpoint. + + The match type for the condition. + True to specify remote, false for local. + The IP endpoint. + + + + Add token information. + + The match type. + The token. + + + + Add remote token information. + + The match type. + The token. + + + + Add remote machine token information. + + The match type. + The token. + + + + Add a package SID condition. + + The match type. + The package SID. + + + + Add a condition which excludes app containers. + + + + + Add a condition which includes app containers. + + + + + Adds details from a process, such as the process' App ID and package SID and token information. + + The match type. + The process. + + + + Adds details from a process, such as the process' App ID and package SID and token information. + + The match type. + The PID of the process. + + + + Add the RPC UUID. + + Match type. + The RPC UUID. + + + + Add a network event type. + + Match type. + Network event type. + + + + Constructor. + + + + + Firewall condition flags. + + + + + Guids for pre-defined firewall conditions. + + + + + Direction of stream for firewall. + + + + + Outbound flow. + + + + + Inbound flow. + + + + + Place holder for an empty value. + + + + + Overridden ToString method. + + The value as a string. + + + + Class to represent the firewall engine. + + + + + Open an instance of the engine. + + The server name for the firewall service. + RPC authentication service. Use default or WinNT. + Optional authentication credentials. + Optional session information. + True to throw on error. + The opened firewall engine. + + + + Open an instance of the engine. + + The server name for the firewall service. + RPC authentication service. Use default or WinNT. + Optional authentication credentials. + Optional session information. + The opened firewall engine. + + + + Open an instance of the engine. + + True to throw on error. + The opened firewall engine. + + + + Open an instance of the engine. + + The opened firewall engine. + + + + Open a dynamic instance of the engine. + + True to throw on error. + The opened firewall engine. + + + + Open a dynamic instance of the engine. + + The opened firewall engine. + + + + Get an engine option. + + The option to get. + True to throw on error. + The engine option's value. + + + + Get an engine option. + + The option to get. + The engine option's value. + + + + Get the current network event keywords setting. + + True to throw on error. + The network event keywords. + + + + Get the current network event keywords setting. + + The network event keywords. + + + + Get collect net events option. + + True to throw on error. + True if net events are being collected. + + + + Get collect net events option. + + True if net events are being collected. + + + + Set an engine option. + + The option to set. + The value to set. + True to throw on error. + The NT status code. + + + + Set an engine option. + + The option to set. + The value to set. + + + + Set network event keywords. + + The keywords to set. + True to throw on error. + The NT status code. + + + + Set network event keywords. + + The keywords to set. + + + + Set the collection net events engine option. + + True to enable collection. + True to throw on error. + The NT status code. + + + + Set the collection net events engine option. + + True to enable collection. + + + + Get a layer by its key. + + The key of the layer. + True to throw on error. + The firewall layer. + + + + Get a layer by its key. + + The key of the layer. + The firewall layer. + + + + Get a layer by its ID. + + The ID of the layer. + True to throw on error. + The firewall layer. + + + + Get a layer by its ID. + + The ID of the layer. + The firewall layer. + + + + Get a layer by its well-known key name. + + The well-known key name of the layer. + True to throw on error. + The firewall layer. + + + + Get a layer by its well-known key name. + + The well-known key name of the layer. + The firewall layer. + + + + Get a layer by an ALE layer type. + + The ALE layer type. + True to throw on error. + The firewall layer. + + + + Get a layer by an ALE layer type. + + The ALE layer type. + The firewall layer. + + + + Enumerate all layers. + + True to throw on error. + The list of layers. + + + + Enumerate all layers. + + The list of layers. + + + + Get a sub-layer by its key. + + The key of the sub-layer. + True to throw on error. + The firewall sub-layer. + + + + Get a sub-layer by its key. + + The key of the sub-layer. + The firewall sub-layer. + + + + Get a sub-layer by its well-known key name. + + The well-known key name of the sub-layer. + True to throw on error. + The firewall sub-layer. + + + + Get a sub-layer by its well-known key name. + + The well-known key name of the sub-layer. + The firewall sub-layer. + + + + Enumerate all sub-layers. + + True to throw on error. + The list of sub-layers. + + + + Enumerate all sub-layers. + + The list of sub-layers. + + + + Get a callout by its key. + + The key of the callout. + True to throw on error. + The firewall callout. + + + + Get a callout by its key. + + The key of the callout. + The firewall callout. + + + + Enumerate all callouts + + True to throw on error. + The list of callouts. + + + + Enumerate all callouts. + + The list of callouts. + + + + Get a filter by its key. + + The key of the filter. + True to throw on error. + The firewall filter. + + + + Get a filter by its key. + + The key of the filter. + The firewall filter. + + + + Get a filter by its id. + + The ID of the filter. + True to throw on error. + The firewall filter. + + + + Get a filter by its id. + + The ID of the filter. + The firewall filter. + + + + Enumerate filters + + Specify a template for enumerating the filters. + True to throw on error. + The list of filters. + + + + Enumerate filters + + Specify a template for enumerating the filters. + The list of filters. + + + + Enumerate all filters + + True to throw on error. + The list of filters. + + + + Enumerate all filters. + + The list of filters. + + + + Add a filter. + + The builder used to create the filter. + Optional security descriptor. + True to throw on error. + The added filter ID. + + + + Add a filter. + + The builder used to create the filter. + Optional security descriptor. + The added filter ID. + + + + Add a filter. + + The builder used to create the filter. + The added filter ID. + + + + Delete a filter. + + The filter key. + True to throw on error. + The NT status. + + + + Delete a filter. + + The filter key. + + + + Delete a filter. + + The filter ID. + True to throw on error. + The NT status. + + + + Delete a filter. + + The filter ID. + + + + Get a provider by its key. + + The key of the provider. + True to throw on error. + The firewall provider. + + + + Get a provider by its key. + + The key of the provider. + The firewall provider. + + + + Enumerate all providers. + + True to throw on error. + The list of providers. + + + + Enumerate all providers. + + The list of providers. + + + + Get the security descriptor for the IKE SA database. + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Get the security descriptor for the IKE SA database. + + What parts of the security descriptor to retrieve + The security descriptor + + + + Get the security descriptor for the IKE SA database. + + The security descriptor + + + + Enumerate all IKE security associatations. + + True to throw on error. + The list of IKE security associatations. + + + + Enumerate all IKE security associatations. + + The list of IKE security associatations. + + + + Get an IKE security association by its ID and lookup context. + + The ID of the security association. + Optional lookup context. + True to throw on error. + The IKE security association. + + + + Get an IKE security association by its ID and lookup context. + + The ID of the security association. + Optional lookup context. + The IKE security association. + + + + Classify a layer. + + The ID of the layer. + A list of incoming values. + True to throw on error. + The classify result. + + + + Classify a layer. + + The ID of the layer. + A list of incoming values. + The classify result. + + + + Enumerate IPSEC key managers. + + True to throw on error. + The list of registered key managers. + + + + Enumerate IPSEC key managers. + + The list of registered key managers. + + + + Get key manager component security descriptor. + + The security information to query. + True to throw on error. + The security descriptor. + + + + Get key manager component security descriptor. + + The security information to query. + The security descriptor. + + + + Open token from its modified ID. + + The token's modified ID. + The desired token access. + True to throw on error. + The opened token. + + + + Open token from its modified ID. + + The token's modified ID. + The desired token access. + The opened token. + + + + Enumerate all ALE endpoints. + + True to throw on error. + The list of ALE endpoints. + + + + Enumerate all ALE endpoints. + + The list of ALE endpoints. + + + + Get an ALE endpoint by its ID. + + The ID of the ALE endpoint. + True to throw on error. + The ALE endpoint. + + + + Get an ALE endpoint by its ID. + + The ID of the ALE endpoint. + The ALE endpoint. + + + + Get the ALE endpoint security. + + The security information to query for. + True to throw on error. + The security descriptor. + + + + Get the ALE endpoint security. + + The security information to query for. + The security descriptor. + + + + Enumerate all sessions. + + True to throw on error. + The list of sessions. + + + + Enumerate all sessions. + + The list of sessions. + + + + Enumerate all network events. + + Template to filter down enumeration. + True to throw on error. + The list of network events. + + + + Enumerate all network events. + + True to throw on error. + The list of network events. + + + + Enumerate all network events. + + Template to filter down enumeration. + The list of network events. + + + + Subscribe to read network event.s + + True to throw on error. + Optional template to filter enumeration. + The network event listener. + + + + Subscribe to read network event.s + + Optional template to filter enumeration. + The network event listener. + + + + Subscribe to read network event.s + + True to throw on error. + The network event listener. + + + + Begin a firewall transaction. + + Flags for the transaction. + True to throw on error. + The firewall transaction. + Disposing the transaction will cause it to abort. You should call Commit to use it. + + + + Enumerate all IPsec SA contexts. + + True to throw on error. + The list of SA contexts. + + + + Enumerate all IPsec SA contexts. + + The list of SA contexts. + + + + Get an IPsec SA context by its ID. + + The ID of the IPsec SA context. + True to throw on error. + The IPsec SA context. + + + + Get an IPsec SA context by its ID. + + The ID of the IPsec SA context. + The IPsec SA context. + + + + Begin a firewall transaction. + + Flags for the transaction. + The firewall transaction. + Disposing the transaction will cause it to abort. You should call Commit to use it. + + + + Begin a read/write firewall transaction. + + The firewall transaction. + Disposing the transaction will cause it to abort. You should call Commit to use it. + + + + Dispose the engine. + + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Engine option to query or set. + + + + + Represents a firewall field schema. + + + + + The field's key. + + + + + The name of the key if known. + + + + + The type of the field. + + + + + The data type of the field. + + + + + Field type. + + + + + A class to represent a firewall filter. + + + + + The filter action type. + + + + + The layer the filter applies to. + + + + + The name of the layer if known. + + + + + The sub-layer the filter applies to. + + + + + The name of the sub-layer if known. + + + + + The flags for the filter. + + + + + List of firewall conditions. + + + + + Original weight of the filter. + + + + + Provider key. + + + + + Provider data. + + + + + Filter identifier. + + + + + Effective weight of the filter. + + + + + Type of filter. + + + + + Key for the callout. + + + + + Name of the callout key if known. + + + + + Is the filter a callout. + + + + + Has the filter got an AppID condition. + + + + + Has the filter got an AppContainer package ID condition. + + + + + Has the filter got a condition to check for a user ID. + + + + + Has the filter got a condition to check for a remote user ID. + + + + + Get a layer for this filter. + + True to throw on error. + The firewall layer. + + + + Get a layer for this filter. + + The firewall layer. + + + + Get a sub-layer for this filter. + + True to throw on error. + The firewall sub-layer. + + + + Get a sub-layer for this filter. + + The firewall sub-layer. + + + + Check if filter has any condition of a specific type. + + The condition type to check. + True if the filter has a condition of the specified type. + + + + Get the filter condition for a GUID. + + The condition type to get. + The filter condition. + + + + Delete the filter. + + True to throw on error. + The NT status. + + + + Delete the filter. + + + + + Convert the filter into a builder so that it can be modified. + + The created builder. + + + + Access rights for a firewall filter. + + + + + A builder to create a new firewall filter. + + + + + The name of the filter. + + + + + The description of the filter. + + + + + The filter key. If empty will be automatically assigned. + + + + + The layer key. + + + + + The sub-layer key. + + + + + Flags for the filter. + + + + + Specify the initial weight. + + You need to specify an EMPTY, UINT64 or UINT8 value. + + + + Specify the action for this filter. + + + + + Specify the filter type GUID when not using a callout. + + + + + Specify callout key GUID when using a callout. + + + + + Specify provider key GUID. + + + + + Constructor. + + + + + Firewall filter condition. + + + + + The match type. + + + + + The key of the field. + + + + + The field key name. + + + + + The value for the condition + + + + + Constructor. + + The condition match type. + The field key. + The value. + + + + Overridden ToString method. + + The condition as a string. + + + + Options for enumerating a filter. + + + + + Specify the key for the layer to search for. + + + + + Specify the provider key. + + + + + Specify the flags for the enumeration. + + + + + Specify the action type. + + + + + Constructor. + + The layer key. + + + + Constructor. + + The ALE layer type.. + + + + Constructor. + + + + + Class to represent a firewall layer object. + + + + + Layer flags. + + + + + Default sub-layer key. + + + + + The layer ID. + + + + + List of fields. + + + + + Is builtin layer. + + + + + Is a user-mode layer. + + + + + Enumerate filters for this layer. + + True to throw on error. + The list of sorted filters. + + + + Enumerate filters for this layer. + + The list of sorted filters. + + + + Flags for a firewall layer. + + + + + Guids for pre-defined firewall layers. + + + + + Firewall filter match type. + + + + + Direction type for a network event. + + + + + Inbound + + + + + Outbound. + + + + + Forwarding + + + + + Loopback. + + + + + Base class for a firewall network event. + + + + + Type of network event. + + + + + Flags for values set. + + + + + Timestamp of the event. + + + + + Type of protocol. + + + + + Local endpoint. + + + + + Remote endpoint. + + + + + IPv6 Scope ID. + + + + + Connection AppID. + + + + + Connection user ID. + + + + + Address family. + + + + + Package SID. + + + + + Class to represent a network event capability allow. + + + + + AppContainer network capability. + + + + + Filter ID. + + + + + Indicates whether the packet originated from (or was heading to) the loopback adapter. + + + + + Class to represent a network event capability drop. + + + + + AppContainer network capability. + + + + + Filter ID. + + + + + Indicates whether the packet originated from (or was heading to) the loopback adapter. + + + + + Class to represent a firewall classification allow. + + + + + Filter ID. + + + + + Layer ID. + + + + + Reason for reauthorizing + + + + + The original profile the connection was received on. + + + + + The profile the error occurred on. + + + + + Indicates the direction of the packet transmission. + + + + + Indicates whether the packet originated from (or was heading to) the loopback adapter. + + + + + Class to represent a firewall classification drop. + + + + + Filter ID. + + + + + Layer ID. + + + + + Reason for reauthorizing + + + + + The original profile the connection was received on. + + + + + The profile the error occurred on. + + + + + Indicates the direction of the packet transmission. + + + + + Indicates whether the packet originated from (or was heading to) the loopback adapter. + + + + + GUID identifier of a vSwitch. + + + + + Transient source port of a packet within the vSwitch. + + + + + Transient destination port of a packet within the vSwitch. + + + + + Template for network event enumeration. + + + + + Start time for events. + + + + + End time for event.s + + + + + Constructor. + + + + + Flags for a network event. + + + + + Class to represent an IKEEXT extended mode failure event. + + + + + Windows error code for the failure + + + + + Point of failure + + + + + Flags for the failure event + + + + + IKE or Authip. + + + + + Extended mode mode state + + + + + Initiator or Responder + + + + + Authentication method + + + + + Hash (SHA thumbprint) of the end certificate corresponding to failures + that happen during building or validating certificate chains. + + + + + LUID for the MM SA + + + + + Quick mode filter ID + + + + + Name of local security principal that was authenticated, if available. + If not available, an empty string will be stored. + + + + + Name of remote security principal that was authenticated, if available. + If not available, an empty string will be stored. + + + + + Array of group SIDs corresponding to the local security principal that + was authenticated, if available. + + + + + Array of group SIDs corresponding to the remote security principal that + was authenticated, if available. + + + + + Class to represent an IKEEXT main mode failure event. + + + + + Windows error code for the failure + + + + + Point of failure + + + + + Flags for the failure event + + + + + IKE or Authip. + + + + + Main mode state + + + + + Initiator or Responder + + + + + Authentication method + + + + + Hash (SHA thumbprint) of the end certificate corresponding to failures + that happen during building or validating certificate chains. + + + + + LUID for the MM SA + + + + + Main mode filter ID + + + + + Name of local security principal that was authenticated, if available. + If not available, an empty string will be stored. + + + + + Name of remote security principal that was authenticated, if available. + If not available, an empty string will be stored. + + + + + Array of group SIDs corresponding to the local security principal that + was authenticated, if available. + + + + + Array of group SIDs corresponding to the remote security principal that + was authenticated, if available. + + + + + Class to represent an IKEEXT quick mode failure event. + + + + + Windows error code for the failure + + + + + Point of failure + + + + + IKE or Authip. + + + + + Main mode state + + + + + Initiator or Responder + + + + + Tunnel or transport mode. + + + + + Main mode filter ID + + + + + Local subnet address and mask. + + + + + Remote subnet address and mask. + + + + + Class to represent an IPsec kernel drop event. + + + + + Failure error code. + + + + + Connection direction. + + + + + Security parameter index. + + + + + Filter ID. + + + + + Layer ID. + + + + + Flags for network events to capture. + + + + + Class to listen for network events. + + + + + Read the next network event. + + Timeout in milliseconds. + Returns null if not event available, otherwise the next event. + + + + Read the next network event. Waiting indefinetely for the event. + + Returns null if not event available, otherwise the next event. + + + + Dispose the listener. + + + + + Type of network event. + + + + + AppContainer capability type. + + + + + Abstract class to represent a firewall object. + + + + + The object's key. + + + + + The object's name. + + + + + The object's description. + + + + + The object's key name. + + + + + The object's security descriptor. + + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + The firewall engine object must still be open. + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + The firewall engine object must still be open. + + + + Profile ID for the firewall. + + + + + Class to represent a firewall provider. + + + + + Name of the service which implements the provider. + + + + + Flags for the provider. + + + + + Provider data. + + + + + Flags for a firewall provider. + + + + + A firewall value range. + + + + + The low value. + + + + + The high value. + + + + + Overridden ToString method. + + The range as a string. + + + + Right action flags. + + + + + Class to represent a firewall session. + + + + + The session key. + + + + + Name of the session. + + + + + Description of the session. + + + + + Session flags. + + + + + Transaction wait timeout in ms. + + + + + The process ID of the session owner. + + + + + The user SID of the owner. + + + + + The name of the owner. + + + + + Is session kernel mode. + + + + + Constructor. Used when opening a session. + + The name of the session. + The description of the sesion. + Session flags. + Transaction timeout in ms. + + + + Constructor. Used when opening a session. + + Session flags. + + + + Class to represent a firewall sublayer. + + + + + Sub-layer flags. + + + + + The provider key. + + + + + Provider data. + + + + + Weight of the sub-layer. + + + + + Flags for a sub-layer. + + + + + Guids for pre-defined firewall sub-layers. + + + + + Token information for a condition. + + + + + The list of SIDs. + + + + + The list of restricted SIDs. + + + + + Capabilities. + + This is only used for local filtering. It's not used by WFP. + + + + Appcontainer SID. + + This is only used for local filtering. It's not used by WFP. + + + + User SID. + + This is only used for local filtering. It's not used by WFP. + + + + Constructor from a token. + + The token to constructo from. + + + + Constructor. + + The list of SIDs. + The list of restricted SIDs. + + + + Class to scope a firewall transaction. + + + + + Abort the transaction. + + True to throw on error. + The NT status code. + + + + Abort the transaction. + + + + + Commit the transaction. + + True to throw on error. + The NT status code. + + + + Commit the transaction. + + + + + Dispose the transaction. Will ca + + + + + Flags when creating a transaction. + + + + + No flags, creates a read/write transaction. + + + + + Read-only transaction. + + + + + Static class for firewall utility functions. + + + + + Name for fake NT type. + + + + + Name for fake filter NT type. + + + + + Get the NT type for the firewall. + + + + + Get the NT type for the firewall. + + + + + Get the generic mapping for a firewall object. + + The firewall object generic mapping. + + + + Get the generic mapping for a firewall filter object. + + The firewall filter object generic mapping. + + + + Get App ID from a filename. + + The filename to convert. + True to throw on error. + The App ID. + + + + Get App ID from a filename. + + The filename to convert. + The App ID. + + + + Get a list of known layer names. + + The list of known layer names. + + + + Get a list of known layer guids. + + The list of known layer guids. + + + + Get a known layer GUID from its name. + + The name of the layer. + The known layer GUID. + + + + Get a known callout GUID from its name. + + The name of the callout. + The known callout GUID. + + + + Get a list of known sub-layer names. + + The list of known sub-layer names. + + + + Get a list of known callout names. + + The list of known callout names. + + + + Get a list of known sub-layer guids. + + The list of known sub-layer guids. + + + + Get a known sub-layer GUID from its name. + + The name of the sub-layer. + The known sub-layer GUID. + + + + Get a layer GUID for an ALE layer enumeration. + + The ALE layer enumeration. + The ALE layer GUID. + + + + Firewall value. + + + + + Type of the value. + + + + + The raw value. + + + + + The context specific value, might be the same as the original. + + + + + Get a value which represents Empty. + + + + + Create a value from a security descriptor. + + The security descriptor. + The firewall value. + + + + Create a value from a SID. + + The SID. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The IPv4 address. + The IPv4 mask. + The firewall value. + + + + Create a value. + + The IPv6 address. + The prefix length. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a range value. + + The low value. + The high value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Create a value. + + The value. + The firewall value. + + + + Overridden ToString method. + + The value as a string. + + + + Class to represent a certificate credential. + + + + + Certificate subject name. + + + + + Certificatehash. + + + + + Flags. + + + + + Certificate. + + + + + Overridden ToString method. + + The pair as a string. + + + + Class to represent an IKE credential. + + + + + Authentication method type. + + + + + Impersonation type. + + + + + Overridden ToString method. + + The pair as a string. + + + + Structure to represent a pair of credentials. + + + + + Local credentials. + + + + + Peer credentials. + + + + + Overridden ToString method. + + The pair as a string. + + + + IKEEXT EM failure flags. + + + + + Flag indicating that multiple IKE EM failure events have been reported that + should be correlated using the mmId field. + + + + + Flag indicating that the IKE EM failure event is a benign/expected failure + + + + + IKE extended mode states + + + + + Initial state. No EM packets have been sent to the peer yet. + + + + + State corresponding to the first EM roundtrip + + + + + State corresponding to the second EM roundtrip + + + + + State corresponding to the final EM roundtrip + + + + + State corresponding to the final EM roundtrip + + + + + EM has been completed + + + + + IKEEXT MM failure flags. + + + + + Flag indicating that the IKE MM failure event is a benign/expected failure. + + + + + Flag indicating that multiple IKE MM failure events have been reported that + should be correlated using the mmId field. + + + + + IKE main mode states + + + + + Initial state. No MM packets have been sent to the peer yet. + + + + + First roundtrip packet has been sent to the peer. + + + + + Second roundtrip packet has been sent to the peer, for SSPI auth. + + + + + Second roundtrip packet has been sent to the peer. + + + + + Final roundtrip packet has been sent to the peer. + + + + + MM has been completed. + + + + + IKE quick mode states + + + + + Initial state. No QM packets have been sent to the peer yet. + + + + + State corresponding to the first QM roundtrip + + + + + State corresponding to the final QM roundtrip + + + + + QM has been completed. + + + + + IKE main mode or quick mode SA role + + + + + SA is initiator + + + + + SA is responder + + + + + Class to represent an IKE name credential. + + + + + The credential principal name. + + + + + Overridden ToString method. + + The pair as a string. + + + + Class to represent an IKE pre-shared key credential. + + + + + The pre-shared key. + + + + + Key flags. + + + + + Class to represent an IKE security association. + + + + + ID for the security association. + + + + + Key module type. + + + + + The local address of the association. + + + + + The remote address of the association. + + + + + Initiator cookie. + + + + + Responder cookie. + + + + + IKE policy key, + + + + + Virtual interface tunnel ID. + + + + + Correlation key. + + + + + List of credentials. + + + + + Cipher algorithm for the security association. + + + + + Length of the key. + + + + + Number of rounds. + + + + + Integrity algorithm for the security association. + + + + + Maximum lifetime in seconds. + + + + + Diffie-Hellman group. + + + + + Quick mode limit. + + + + + IPsec auth config. + + + + + IPsec authentication type. + + + + + IPsec Cipher Configuration. + + + + + IPSec Cipher Type. + + + + + Type used for indicating where an IPsec failure occured. + + + + + No information available. + + + + + IPsec failure happened on local machine. + + + + + IPsec failure happened on remote machine. + + + + + Class to represent a IPsec identity + + + + + Main-mode target name. + + + + + Extended mode target name. + + + + + List of tokens. + + + + + Explicit credentials handle. + + + + + Logon ID. + + + + + Class to prepresent a key manager. + + + + + The manager's key. + + + + + The manager's name. + + + + + The manager's description. + + + + + The manager's flags. + + + + + The manager's dictation timeout hint. + + + + + Flags for IPsec key manager. + + + + + IPsec perfect forward secrecy group. + + + + + Class to represent the details of an IPsec security association. + + + + + Directory of SA. + + + + + Local endpoint. + + + + + Remote endpoint. + + + + + Traffic type. + + + + + Traffic type ID. + + + + + IP protocol type. + + + + + Interface LUID. + + + + + Real interface profile ID. + + + + + The SA bundle. + + + + + Local IPv4 UDP encapsulation port. + + + + + Remote IPv4 UDP encapsulation port. + + + + + Transport filter. + + + + + Virtual interface tunnel ID. + + + + + Traffic selector ID. + + + + + Overridden ToString method. + + The overridden ToString method. + + + + Class to represent a security association bundle. + + + + + Flags for the SA. + + + + + SA lifetime in seconds. + + + + + SA lifetime in KiB. + + + + + SA lifetime in packets. + + + + + Idle timeout. + + + + + ND allow clear timeout. + + + + + Identity for IPsec SA. + + + + + NAP context. + + + + + Quick-mode SA ID. + + + + + Key module key. + + + + + Key module state blob. + + + + + List of security association parameters. + + + + + Peer V4 private address. + + + + + Main-mode SA ID. + + + + + PFS group. + + + + + SA lookup context. + + + + + QM filter ID. + + + + + IPsec SA bundle flags. + + + + + Negotiation discovery is enabled in secure ring. + + + + + Negotiation discovery in enabled in the untrusted perimeter zone. + + + + + Peer is in untrusted perimeter zone ring and a network address translation (NAT) is in the way. Used with negotiation discovery. + + + + + Indicates that this is an SA for connections that require guaranteed encryption. + + + + + Indicates that this is an SA to an NLB server. + + + + + Indicates that this SA should bypass machine LUID verification. + + + + + Indicates that this SA should bypass impersonation LUID verification. + + + + + Indicates that this SA should bypass explicit credential handle matching. + + + + + Allows an SA formed with a peer name to carry traffic that does not have an associated peer target. + + + + + Clears the DontFragment bit on the outer IP header of an IPsec-tunneled packet. This flag is applicable only to tunnel mode SAs. + + + + + Default encapsulation ports (4500 and 4000) can be used when matching this SA with packets on outbound connections that do not have an associated IPsec-NAT-shim context. + + + + + Peer has negotiation discovery enabled, and is on a perimeter network. + + + + + Suppresses the duplicate SA deletion logic. THis logic is performed by the kernel when an outbound SA is added, to prevent unnecessary duplicate SAs. + + + + + Indicates that the peer computer supports negotiating a separate SA for connections that require guaranteed encryption. + + + + + Class to represent an IPsec security association context. + + + + + ID of the context. + + + + + Inbound security association. + + + + + Outbound security association. + + + + + Base security association class. + + + + + Index of the security parameter (SPI). + + + + + Transform type. + + + + + IPsec SA authentication information. + + + + + Type of authentication. + + + + + Authentication configuration. + + + + + Module ID for the crypto. + + + + + Authentication key. + + + + + IPsec SA authentication information. + + + + + Type of cipher. + + + + + Cipher configuration. + + + + + Module ID for the crypto. + + + + + Cipher key. + + + + + IPsec SA authentication information. + + + + + Type of authentication. + + + + + Authentication configuration. + + + + + Modify ID for the crypto. + + + + + Authentication key. + + + + + Type of cipher. + + + + + Cipher configuration. + + + + + Module ID for the crypto. + + + + + Cipher key. + + + + + Class to represent an IPsec token. + + + + + Type of token. + + + + + Token principal. + + + + + Token mode. + + + + + Handle to the token. + + + + + Get the token from the IKEEXT service. + + True to throw on error. + The token. + + + + Get the token from the IKEEXT service. + + The token. + + + + IPsec traffic type. + + + + + Network interface type. + + See https://www.iana.org/assignments/ianaiftype-mib + + + + Network layer address type. + + + + + Type of network tunnel. + + + + + Endpoint implementation for a HyperV socket. + + + + + Address family. + + + + + Protocol type for HyperV sockets. + + + + + Default constructor. + + + + + Constructor. + + + + + Get or set the service ID. + + + + + Get or set the VM ID. + + + + + Address family. + + + + + Serialize the socket address. + + The serialized address. + + + + Create a endpoint from a socket address. + + The socket address. + The created endpoint. + + + + Overridden ToString method. + + The endpoint as a string. + + + + Overridden equals method. + + The object to compare. + True if the objects are equal. + + + + Get endpoint hash code. + + The hashcode. + + + + GUIDs for HyperV Sockets. + + + + + Allows accepting connections from all partitions. + + + + + Broadcast. Send to all sockets. + + + + + Allows accepting connections form all child partitions. + + + + + Connect or bind to the loopback address. + + + + + Connect to the parent container. + + + + + Connect to the silo host container. + + + + + VSOCK template GUID. + + + + + Create an address for a VSOCK port. + + The VSOCK port. + The address. + + + + Checks if an address is a VSOCK address. + + The address to check. + True if a VSOCK address. + + + + Get the port for a VSOCK address. + + The address to query. + The VSOCK port. + Throw if not a valid VSOCK address. + + + + Convert an address to a string. + + The address to convert. + The converted address. If not symbolic name found will return the GUID as a string. + + + + Class to represent current socket security configuration. + + + + + Access token for the peer application. + + + + + Access token for the peer machine. + + + + + Socket security flags. + + + + + Security association ID for main mode. + + + + + Security association ID for quick mode. + + + + + Negotiation windows error. + + + + + Security association lookup context. Can be used to bypass security + checks for querying the security association information from the + firewall. + + + + + Dispose method. + + + + + Socket security IPsec flags. + + + + + Flags for querying socket security fields. + + + + + Flags for querying socket security information. + + + + + Socket security query flags. + + + + + Socket security setting flags. + + + + + Settings for socket security + + + + + The security flags. + + + + + The IPsec flags. + + + + + AuthIP MM policy key. + + + + + AuthIP QM policy key. + + + + + User credentials. + + + + + Authentication ID of a user, needs kernel mode to set. + + + + + Utilities for socket security. + + + + + Impersonate the socket's peer. + + The socket to impersonate. + Optional peer address. Only needed for datagram sockets. + True to throw on error. + The impersonation context. + + + + Impersonate the socket's peer. + + The socket to impersonate. + Optional peer address. Only needed for datagram sockets. + The impersonation context. + + + + Impersonate the socket's peer. + + The TCP client to impersonate. + True to throw on error. + The impersonation context. + + + + Impersonate the socket's peer. + + The TCP client to impersonate. + The impersonation context. + + + + Query the socket security information. + + The socket to query. + Optional peer address. Only needed for datagram sockets. + Optional desired access for peer tokens. If set to None then no tokens will be returned. + True to throw on error. + The socket security information. + + + + Query the socket security information. + + The socket to query. + Optional peer address. Only needed for datagram sockets. + Optional desired access for peer tokens. If set to None then no tokens will be returned. + The socket security information. + + + + Query the socket security information. + + The TCP client to query. + Optional desired access for peer tokens. If set to None then no tokens will be returned. + True to throw on error. + The socket security information. + + + + Query the socket security information. + + The TCP client to query. + Optional desired access for peer tokens. If set to None then no tokens will be returned. + The socket security information. + + + + Set the socket security information. + + The socket to set. + The security settings. + True to throw on error. + The NT status code. + + + + Set the socket security information. + + The socket to set. + The security settings. + + + + Set the socket security information. + + The TCP listener to set. + The security settings. + True to throw on error. + The NT status code. + + + + Set the socket security information. + + The TCP listener to set. + The security settings. + + + + Set the socket security information. + + The TCP client to set. + The security settings. + True to throw on error. + The NT status code. + + + + Set the socket security information. + + The TCP client to set. + The security settings. + + + + Set target peer for socket. + + The socket to set. + The target name. + Optional peer address. Only needed for datagram sockets. + True to throw on error. + The NT status code. + + + + Set target peer for socket. + + The socket to set. + The target name. + Optional peer address. Only needed for datagram sockets. + + + + Set target peer for socket. + + The socket to set. + The target name. + True to throw on error. + The NT status code. + + + + Set target peer for socket. + + The socket to set. + The target name. + + + + Set target peer for socket. + + The socket to set. + The target name. + True to throw on error. + The NT status code. + + + + Set target peer for socket. + + The socket to set. + The target name. + + + + Delete target peer for socket. + + The socket to set. + Peer address. + True to throw on error. + The NT status code. + + + + Security protocol for a socket. + + + + + Endpoint implementation for a AF_UNIX socket. + + + + + Default constructor. + + + + + Constructor. + + The path to the unix socket. + + + + Get or set the path. + + + + + Address family. + + + + + Serialize the socket address. + + The serialized address. + + + + Create a endpoint from a socket address. + + The socket address. + The created endpoint. + + + + Overridden ToString method. + + The endpoint as a string. + + + + Overridden equals method. + + The object to compare. + True if the objects are equal. + + + + Get endpoint hash code. + + The hashcode. + + + + A class to represent a TLS record. + + + + + TLS record type. + + + + + Version of protocol. + + + + + The record data. + + + + + Parse a TLS record from a binary reader. + + The reader to read from. + The parsed TLS record. + + + + Parse a TLS record from a byte array. + + The byte array. + The parsed TLS record. + + + + Type for a TLS record. + + + + + Change cipher spec. + + + + + Alert. + + + + + Handshake. + + + + + Application data. + + + + + Class to represent an ALPC port. + + + + + Disconnect this port. + + Disconection flags. + True to throw on error. + The NT status code. + + + + Disconnect this port. + + Disconection flags. + + + + Disconnect this port. + + + + + Cancel a message based on a context attribute. + + Cancellation flags. + The context attributes. + True to throw on error. + The NT status code. + + + + Cancel a message based on a context attribute. + + Cancellation flags. + The context attributes. + + + + Cancel a message based on a context attribute. + + The context attributes. + + + + Send and receive messages on an ALPC port. + + Send/Receive flags. + The message to send. Optional. + The attributes to send with the message. Optional. + The message to receive. Optional. + The attributes to receive with the message. Optional. + Time out for the send/receive. + True to throw on error. + The NT status code. + The attribute parameters will be repopulated with the attribute results. + + + + Send and receive messages on an ALPC port. + + Send/Receive flags. + The message to send. Optional. + The attributes to send with the message. Optional. + The message to receive. Optional. + The attributes to receive with the message. Optional. + Time out for the send/receive. + True if completed successfully, false if timed out. + Thrown on error. + + + + Send a message on an ALPC port. + + Send flags. + The message to send. Optional. + The attributes to send with the message. Optional. + Time out for the send/receive. + True to throw on error. + The NT status code. + The attribute parameters will be repopulated with the attribute results. + + + + Send a message on an ALPC port. + + Send flags. + The message to send. Optional. + The attributes to send with the message. Optional. + Time out for the send/receive. + The attribute parameters will be repopulated with the attribute results. + True if completed successfully, false if timed out. + Thrown on error. + + + + Send a message on an ALPC port. + + Send flags. + The message to send. Optional. + The attribute parameters will be repopulated with the attribute results. + + + + Receive a message on an ALPC port. + + Receive flags. + The maximum length to receive. + The attributes to receive with the message. Optional. + Time out for the send/receive. + True to throw on error. + The received message. + The attribute parameters will be repopulated with the attribute results. + + + + Receive a message on an ALPC port. + + Receive flags. + The maximum length to receive. + The attributes to receive with the message. Optional. + Time out for the send/receive. + The received message. + The attribute parameters will be repopulated with the attribute results. + + + + Receive a message on an ALPC port. + + Receive flags. + The maximum length to receive. + The attributes to receive with the message. Optional. + The received message. + The attribute parameters will be repopulated with the attribute results. + + + + Receive a message on an ALPC port. + + Receive flags. + The maximum length to receive. + The received message. + The attribute parameters will be repopulated with the attribute results. + + + + Receive a message on an ALPC port. + + Receive flags. + The attributes to receive with the message. Optional. + Time out for the send/receive. + True to throw on error. + The received message. + The attribute parameters will be repopulated with the attribute results. + The type of structure to receive. + + + + Receive a message on an ALPC port. + + Receive flags. + The attributes to receive with the message. Optional. + Time out for the send/receive. + The attribute parameters will be repopulated with the attribute results. + The type of structure to receive. + + + + Receive a message on an ALPC port. + + Receive flags. + The attributes to receive with the message. Optional. + The attribute parameters will be repopulated with the attribute results. + The type of structure to receive. + + + + Receive a message on an ALPC port. + + Receive flags. + The type of structure to receive. + + + + Impersonate client of port for a message. + + The message send by the client. + Impersonation flags. + Required impersonation level. Need to set RequiredImpersonationLevel flag as well. + True to throw on error. + Thread impersonation context. + + + + Impersonate client of port for a message. + + The message send by the client. + Impersonation flags. + Required impersonation level. Need to set RequiredImpersonationLevel flag as well. + Thread impersonation context. + + + + Impersonate client of port for a message. + + The message send by the client. + Thread impersonation context. + + + + Impersonate client container of port for a message. + + The message send by the client. + Impersonation flags. + True to throw on error. + Thread impersonation context. + + + + Impersonate client container of port for a message. + + The message send by the client. + Impersonation flags. + Thread impersonation context. + + + + Impersonate client container of port for a message. + + The message send by the client. + Thread impersonation context. + + + + Open the process of the message sender. + + The sent message. + Optional flags. Currently none defined. + The desired access for the process. + Optional object attributes. + True to throw on error. + The opened process object. + + + + Open the process of the message sender. + + The sent message. + Optional flags. Currently none defined. + The desired access for the process. + Optional object attributes. + The opened process object. + + + + Open the process of the message sender. + + The sent message. + The desired access for the process. + The opened process object. + + + + Open the process of the message sender with maximum privileges. + + The sent message. + The opened process object. + + + + Open the thread of the message sender. + + The sent message. + Optional flags. Currently none defined. + The desired access for the thread. + Optional object attributes. + True to throw on error. + The opened thread object. + + + + Open the thread of the message sender. + + The sent message. + Optional flags. Currently none defined. + The desired access for the thread. + Optional object attributes. + The opened thread object. + + + + Open the thread of the message sender. + + The sent message. + The desired access for the thread. + The opened thread object. + + + + Open the thread of the message sender with maximum privileges. + + The sent message. + The opened thread object. + + + + Associate an IO completion port with this ALPC port. + + The IO completion object. + Optional completion key. + True to throw on error. + The NT status code. + + + + Associate an IO completion port with this ALPC port. + + The IO completion object. + Optional completion key. + The NT status code. + + + + Check if the current SID matches the connected SID. + + The SID to compare. + True to throw on error. + True if the connected SID matches the specified SID. + + + + Check if the current SID matches the connected SID. + + The SID to compare. + True if the connected SID matches the specified SID. + + + + Create a new port section. + + Flags for the port section. + Optional backing section. + Size of the section to create. + True to throw on error. + The created port section. + + + + Create a new port section. + + Flags for the port section. + Optional backing section. + Size of the section to create. + The created port section. + + + + Create a new port section. + + Flags for the port section. + Size of the section to create. + The created port section. + + + + Create a new port section. + + Size of the section to create. + The created port section. + + + + Get a handle entry for a message. + + The handle index to get. + The associated message. + True to throw on error. + The ALPC handle entry. + + + + Get a handle entry for a message. + + The handle index to get. + The associated message. + The ALPC handle entry. + + + + Create a security context. + + Flags for the creation. + Security quality of service. + True to throw on error. + The created security context. + + + + Create a security context. + + Flags for the creation. + Security quality of service. + The created security context. + + + + Create a security context. + + Security quality of service. + The created security context. + + + + Create a security context. + + The created security context. + + + + Set port attribute flags. + + The flags to set. + True to throw on error. + The NT status code. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Port flags. + + + + + Port sequence number. + + + + + Port context. + + + + + Class to represent an ALPC client port. + + + + + Connect to an ALPC port. + + The path to the port. + Object attributes for the handle. Optional. + Attributes for the port. Optional. + Send flags for the initial connection message. + Required SID for the server. + Initial connection message. + Outbound message attributes. + Inbound message atributes. + Connect timeout. + True to throw on error. + The connected ALPC port. + + + + Connect to an ALPC port. + + The path to the port. + Object attributes for the handle. Optional. + Attributes for the port. Optional. + Send flags for the initial connection message. + Required SID for the server. + Initial connection message. + Outbound message attributes. + Inbound message atributes. + Connect timeout. + The connected ALPC port. + Thrown on error. + + + + Connect to an ALPC port. + + The name of the port to connect to. + Attributes for the port. + The connected ALPC port object. + + + + Connect to an ALPC port. + + Object attribute for the port name. + Object attributes for the handle. Optional. + Attributes for the port. Optional. + Send flags for the initial connection message. + Required security descriptor for the server. + Initial connection message. + Outbound message attributes. + Inbound message atributes. + Connect timeout. + True to throw on error. + The connected ALPC port. + Only available on Windows 8+. + + + + Connect to an ALPC port. + + Object attribute for the port name. + Object attributes for the handle. Optional. + Attributes for the port. Optional. + Send flags for the initial connection message. + Required security descriptor for the server. + Initial connection message. + Outbound message attributes. + Inbound message atributes. + Connect timeout. + The connected ALPC port. + Thrown on error. + + + + Connect to an ALPC port. + + Object attribute for the port name. + Attributes for the port. + The connected ALPC port object. + + + + Get the server process information. + + True to throw on error. + The process information. + + + + Get the server process information. + + The process information. + + + + Get the server process ID. + + + + + Get the server session ID. + + + + + Class to represent an ALPC server port. + + + + + Create an ALPC port. + + The object attributes for the port. + The attributes for the port. + True to throw on error. + The created object. + + + + Create an ALPC port. + + The object attributes for the port. + The attributes for the port. + The created object. + Thrown on error. + + + + Create an ALPC port. + + The name of the port to create. + The attributes for the port. + The created object. + Thrown on error. + + + + Accept a new connection on a port. + + The message send flags. + Object attributes. Optional. + The attributes for the port. + Port context. Optional. + Connect request message. + Connect request attributes. + True to accept the connection. + True to throw on error. + The accepted port. + + + + Accept a new connection on a port. + + The message send flags. + Object attributes. Optional. + The attributes for the port. + Port context. Optional. + Connect request message. + Connect request attributes. + True to accept the connection. + The accepted port. + + + + Accept a new connection on a port. + + The message send flags. + Connect request message. + Connect request attributes. + True to accept the connection. + The accepted port. + + + + Access rights for ALPC + + + + + ALPC Port Information Class + + + + + If set then object duplication won't complete. Used by RPC to ensure + multi-handle attributes don't fail when receiving. + + + + + Use in a reply to release the view. + + + + + Automatically release the view once it's passed to the receiver. + + + + + Make the data view secure. + + + + + When used all structures passed to kernel need to be 64 bit versions. + + + + + Static utilities for ALPC. + + + + + Wait for the result to complete. This could be waiting on an event + or the file handle. + + Wait timeout. Will cancel the operation if it times out. + Returns true if the wait completed successfully. + If true is returned then status and information can be read out. + + + + Wait for the result to complete asynchronously. This could be waiting on an event + or the file handle. + + Cancellation token. + Returns true if the wait completed successfully. + If true is returned then status and information can be read out. + + + + Return the status information field. + + Thrown if not complete. + + + + Return the status information field. (32 bit) + + Thrown if not complete. + + + + Get completion status code. + + Thrown if not complete. + + + + Returns true if the call is pending. + + + + + Dispose object. + + + + + Reset the file result so it can be reused. + + + + + Cancel the pending IO operation. + + + + + Cancel the pending IO operation. + + True to throw on error. + The NT status code. + + + + Class to handle NT atoms + + + + + Add a global atom name + + The name to add + Flags for the add. + True to throw on error. + A reference to the atom + + + + Add a global atom name + + The name to add + Flags for the add. + A reference to the atom + + + + Add a global atom name + + The name to add + True to throw on error. + A reference to the atom + + + + Add a global atom name + + The name to add + A reference to the atom + + + + Find a global atom by name. + + The name of the atom. + True to throw on error. + The found atom. + + + + Find a global atom by name. + + The name of the atom. + The found atom. + + + + Query if a global atom exists. + + The atom to check. + True if the atom exists. + + + + Query if the atom exists. + + The atom to check. + Specify true to check for a global atom, otherwise gets a user atom. + True if the atom exists. + + + + Open a global atom by number. + + The atom to open. + True to check atom exists. + True to open a global atom, otherwise a user atom. + True to throw on error. + The atom object. + + + + Open a global atom by number. + + The atom to open. + True to check atom exists. + True to throw on error. + The atom object. + + + + Open a global atom by number. + + The atom to open. + True to check atom exists. + The atom object. + + + + Open a global atom by number. + + The atom to open. + The atom object. + + + + Enumerate all atoms. + + An enumeration of all atoms on the system. + + + + Enumerate all global atoms. + + An enumeration of all atoms on the system. + + + + Delete a global atom. + + True to throw on error. + The NT status code. + + + + Delete a global atom. + + + + + Get the name of the atom. + + True to throw on error. + The name of the atom. + + + + The atom value + + + + + Get the name of the atom. + + The name of the atom + + + + If true indicates this is a global atom, otherwise it's a user atom. + + + + + Class representing a NT Debug object + + + + + Create a debug object + + The debug object name (can be null) + The root directory for relative names + Debug object flags. + The debug object + + + + Create a debug object + + Desired access for the debug object + Object attributes for debug object + Debug object flags. + The debug object + + + + Create a debug object + + Desired access for the debug object + Object attributes for debug object + Debug object flags. + True to throw an exception on error. + The NT status code and object result. + + + + Create a debug object + + The debug object + + + + Open a named debug object + + The debug object name + The root directory for relative names + Desired access for the debug object + The debug object + + + + Open a named debug object + + The object attributes to open. + Desired access for the debug object + The debug object + + + + Open a named debug object + + The object attributes to open. + Desired access for the debug object + True to throw an exception on error. + The NT status code and object result. + + + + Open the current thread's debug object. + + True to throw on error. + The opened debug object. Returns null if no object exists. + + + + Open the current thread's debug object. Returns null if no object exists. + + + + + Attach to an active process. + + The process to debug. + True to throw on error. + The NT status code. + + + + Attach to an active process. + + The process ID to debug. + True to throw on error. + The NT status code. + + + + Attach to an active process. + + The process to debug. + + + + Attach to an active process. + + The process ID to debug. + + + + Detach a process from this debug object. + + The process to remove. + True to throw on error. + The NT status code. + + + + Detach a process from this debug object. + + The process to remove. + + + + Detach a process from this debug object. + + The process ID to remove. + True to throw on error. + The NT status code. + + + + Detach a process from this debug object. + + The process ID to remove. + + + + Set kill process on close flag. + + The flag state. + True to throw on error. + The NT status code. + + + + Set kill process on close flag. + + The flag state. + + + + Continue the debugged process. + + The client ID for the process and thread IDs. + The continue status code. + True to throw on error. + The NT status code. + + + + Continue the debugged process. + + The process ID to continue. + The thread ID to continue. + The continue status code. + True to throw on error. + The NT status code. + + + + Continue the debugged process. + + The client ID for the process and thread IDs. + The continue status code. + + + + Continue the debugged process. + + The process ID to continue. + The thread ID to continue. + The continue status code. + + + + Continue the debugged process with a success code. + + The process ID to continue. + The thread ID to continue. + + + + Wait for a debug event. + + True to set the thread as alertable. + Wait timeout. + True to throw on error. + The debug event. + + + + Wait for a debug event. + + True to set the thread as alertable. + Wait timeout. + The debug event. + + + + Wait for a debug event. + + Wait timeout. + The debug event. + + + + Wait for a debug event. + + Wait timeout in milliseconds. + The debug event. + + + + Wait for a debug event. + + The debug event. + + + + Class which represents a desktop object. + + + + + Open a desktop by name. + + The object attributes for opening. + Flags for opening the desktop. + Desired access. + True to throw on error. + The instance of the desktop. + Thrown on error. + + + + Open a desktop by name. + + The object attributes for opening. + Flags for opening the desktop. + Desired access. + The instance of the desktop. + Thrown on error. + + + + Open a desktop by name. + + The name of the desktop. + Optional root object + An instance of NtDesktop. + Thrown on error. + + + + Open a desktop by name. + + The name of the desktop. + An instance of NtDesktop. + + + + Create a new desktop. + + The object attributes for opening. + Flags for opening the desktop. + Desired access. + True to throw on error. + Device name. + Device mode. + Heap size. + An instance of NtDesktop. + + + + Create a new desktop. + + The object attributes for opening. + Flags for opening the desktop. + Desired access. + Device name. + Device mode. + Heap size. + An instance of NtDesktop. + + + + Create a new desktop. + + The name of the desktop. + Optional root object + An instance of NtDesktop. + + + + Create a new desktop. + + The name of the desktop. + An instance of NtDesktop. + + + + Get the desktop for a thread. + + The thread ID of the thread. + True to throw on error. + The desktop result. + + + + Get the desktop for a thread. + + The thread ID of the thread. + The desktop result. + + + + Get desktop for current thread. + + + + + Get list of top level Windows for this Desktop. + + + + + Close the Desktop. This is different from normal Close as it destroys the Desktop. + + True to throw on error. + The NT status. + + + + NT Directory Object class + + + + + Open a directory object + + The object attributes to use for the open call. + Access rights for directory object + True to throw an exception on error. + The NT status code and object result. + Thrown on error and throw_on_error is true. + + + + Open a directory object + + The object attributes to use for the open call. + Access rights for directory object + The directory object + Throw on error + + + + Open a directory object by name + + The directory object to open + Optional root directory to parse from + Access rights for directory object + The directory object + Throw on error + + + + Open a directory object by name + + The directory object to open + Optional root directory to parse from + Access rights for directory object + True to throw an exception on error. + The directory object + Throw on error + + + + Open a directory object by full name + + The directory object to open + The directory object + Throw on error + + + + Create a directory object with a shadow + + The object attributes to create the directory with + The desired access to the directory + The shadow directory + Flags for creation. + True to throw an exception on error. + The NT status code and object result. + Thrown on error and throw_on_error is true. + + + + Create a directory object with a shadow + + The object attributes to create the directory with + The desired access to the directory + The shadow directory + True to throw an exception on error. + The NT status code and object result. + Thrown on error and throw_on_error is true. + + + + Create a directory object with a shadow + + The object attributes to create the directory with + The desired access to the directory + The shadow directory + Flags for creation. + The directory object + Thrown on error + + + + Create a directory object with a shadow + + The object attributes to create the directory with + The desired access to the directory + The shadow directory + The directory object + Thrown on error + + + + Create a directory object + + The directory object to create, if null will create a unnamed directory object + The desired access to the directory + Root directory from where to start the creation operation + The directory object + Thrown on error + + + + Create a directory object with a shadow + + The directory object to create, if null will create a unnamed directory object + The desired access to the directory + Root directory from where to start the creation operation + The shadow directory + The directory object + Thrown on error + + + + Create a directory object + + The directory object to create, if null will create a unnamed directory object + The directory object + Thrown on error + + + + Open a session directory. + + The session ID to open + Sub directory to open. + Desired access to open directory. + The directory object + Thrown on error + + + + Open the current session directory. + + The directory object + Thrown on error + + + + Open the current session directory. + + The directory object + Thrown on error + + + + Open basenamedobjects for a session. + + The session ID to open + The directory object + Thrown on error + + + + Open basenamedobjects for current session. + + The directory object + Thrown on error + + + + Get the based named object's directory for a session. + + The session ID + The based named object's directory. + + + + Get the based named object's directory for the current session. + + The based named object's directory. + + + + Get the a session's Windows object directory. + + The session id to use. + The path to the windows object directory. + + + + Get the current session's Windows object directory. + + The path to the windows object directory. + + + + Get the a session's Window Stations object directory. + + The session id to use. + The path to the window stations object directory. + + + + Get the current session's Window Stations object directory. + + The path to the window stations object directory. + + + + Open dos devices directory for a token. + + The directory object + Thrown on error + + + + Open dos devices directory for current effective token. + + The directory object + Thrown on error + + + + Create a private namespace directory. + + Object attributes for the directory + Boundary descriptor for the namespace + Desired access for the directory + True to throw an exception on error. + The directory object + Thrown on error + + + + Create a private namespace directory. + + Object attributes for the directory + Boundary descriptor for the namespace + Desired access for the directory + The directory object + Thrown on error + + + + Create a private namespace directory. + + Boundary descriptor for the namespace + The directory object + Thrown on error + + + + Open a private namespace directory. + + Object attributes for the directory + Boundary descriptor for the namespace + Desired access for the directory + True to throw an exception on error. + The directory object + Thrown on error + + + + Open a private namespace directory. + + Object attributes for the directory + Boundary descriptor for the namespace + Desired access for the directory + The directory object + Thrown on error + + + + Open a private namespace directory. + + Boundary descriptor for the namespace + The directory object + Thrown on error + + + + Returns whether a directory exists for this path. + + The path to the entry. + The root directory. + True if the directory exists for the specified path. + + + + Get the type of a directory entry by path. + + The path to the directory entry + The root object to look up if path is relative + The type name, or null if it can't be found. + + + + Query the directory for a list of entries. + + The list of entries. + Thrown on error + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + Specify the desired access for the directory + True to recurse into sub directories. + Specify max recursive depth. -1 to not set a limit. + True if all children were visited. + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + True to recurse into sub directories. + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + Specify the desired access for the directory + True to recurse into sub directories. + + + + Deletes a private namespace. If not a private namespace this does nothing. + + + + + Deletes a private namespace. If not a private namespace this does nothing. + + True to throw on error. + The NT status code. + + + + Get a directory entry based on a name. + + The name of the entry. + The typename to verify against, can be null. + True if look up is case sensitive. + The directory entry, or null if it can't be found. + + + + Get a directory entry based on a name. + + The name of the entry. + The directory entry, or null if it can't be found. + + + + Check whether a directory is exists relative to the current directory. + + Relative path to directory + True if the directory exists. + + + + Set the session ID for this directory to the current session. + + True to throw on error. + The NT status code. + Thrown on error. + Needs SeTcbPrivilege. + + + + Set the session object for this directory to the current session. + + True to throw on error. + The NT status code. + Thrown on error. + Needs SeTcbPrivilege. + + + + Returns whether this object is a container. + + + + + Directory access rights. + + + + + Base class to implement an enclave. + + + + + The base address of the enclave. + + + + + The type of enclave. + + + + + Dispose of the enclave. + + + + + Close the enclave. + + + + + Call a method in the enclave. + + The routine address to call. + The parameter to pass to the routine. + True to wait for a free thread. + True to throw on error. + The return value from the call. + + + + Call a method in the enclave. + + The routine address to call. + The parameter to pass to the routine. + True to wait for a free thread. + The return value from the call. + + + + Type of enclave. + + + + + Class to represent a VBS enclave. + + + + + Create a VBS enclave. + + The process to create the enclave in. + Size of the enclave. + Flags for the enclave. + Owner ID. Must be 32 bytes. + True to throw on error. + The created enclave. + + + + Create a VBS enclave. + + The process to create the enclave in. + Size of the enclave. + Flags for the enclave. + Owner ID. Must be 32 bytes. + The created enclave. + + + + Get a procedure address in the loaded enclave. + + The name of the procedure. + True to throw on error. + The address of the procedure. + + + + Get a procedure address in the loaded enclave. + + The name of the procedure. + The address of the procedure. + + + + Terminate the enclave. + + Flags for the terminate. + True to throw on error. + The NT status code. + + + + Terminate the enclave. + + Flags for the terminate. + The NT status code. + + + + Load a module into the enclave. + + The name of the module + Flags or path. + True to throw on error. + The NT status. + + + + Load a module into the enclave. + + The name of the module + Flags or path. + The NT status. + + + + Initialize the enclave. + + The number of threads to create. + True to throw on error. + The number of created threads. + + + + Initialize the enclave. + + The number of threads to create. + The number of created threads. + + + + Dispose of the enclave. + + + + + Class to represent a kernel transaction enlistment. + + + + + Create a new enlistment object. + + The object attributes + Desired access for the handle + Resource manager to handle the enlistment. + The transaction to enlist. + Optional create options. + Notification mask. + Enlistment key returned during notification. + True to throw an exception on error. + The created enlistment and NT status code. + + + + Create a new enlistment object. + + The object attributes + Desired access for the handle + Resource manager to handle the enlistment. + The transaction to enlist. + Optional create options. + Notification mask. + Enlistment key returned during notification. + The created enlistment. + + + + Open a existing new enlistment object. + + The object attributes + Desired access for the handle + Resource manager handling the enlistment. + ID of the enlistment to open. + True to throw an exception on error. + The opened enlistment and NT status code. + + + + Open a existing new enlistment object. + + The object attributes + Desired access for the handle + Resource manager handling the enlistment. + ID of the enlistment to open. + The opened enlistment. + + + + Get a default mask for creating an enlistment object. + + The creation option to get default mask for. + A default working mask. + + + + Commit complete enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Commit enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Preprepare complete enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Preprepare enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Prepare complete enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Prepare enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Rollback complete enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Rollback enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Read only enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Recover enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Single phase reject enlistment. + + Optional virtual clock value. + True to throw on error. + The NT status code. + + + + Commit complete enlistment. + + Optional virtual clock value. + + + + Commit enlistment. + + Optional virtual clock value. + + + + Preprepare complete enlistment. + + Optional virtual clock value. + + + + Preprepare enlistment. + + Optional virtual clock value. + + + + Prepare complete enlistment. + + Optional virtual clock value. + + + + Prepare enlistment. + + Optional virtual clock value. + + + + Rollback complete enlistment. + + Optional virtual clock value. + + + + Rollback enlistment. + + Optional virtual clock value. + + + + Read only enlistment. + + Optional virtual clock value. + + + + Recover enlistment. + + Optional virtual clock value. + + + + Single phase reject enlistment. + + Optional virtual clock value. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get enlistment ID. + + + + + Get associated transaction ID. + + + + + Get resource manager ID. + + + + + Get CRM enlistment ID. + + + + + Get CRM transaction manager ID. + + + + + Get CRM resource manager ID. + + + + + Get or set recovery information. + + + + + Class to represent an NT trace GUID. + + + + + Class representing a NT Event object + + + + + Create an event object + + The path to the event + The root object for relative path names + The type of the event + The initial state of the event + True to throw on error. + The event object + + + + Create an event object + + The path to the event + The root object for relative path names + The type of the event + The initial state of the event + The event object + + + + Create an event object + + The event object attributes + The type of the event + The initial state of the event + The desired access for the event + The event object + + + + Create an event object + + The event object attributes + The type of the event + The initial state of the event + The desired access for the event + True to throw an exception on error. + The NT status code and object result. + + + + Create an event object + + The path to the event + The type of the event + The initial state of the event + The event object + + + + Open an event object + + The path to the event + The root object for relative path names + The desired access for the event + The event object + + + + Open an event object + + The event object attributes + The desired access for the event + The event object. + + + + Open an event object + + The event object attributes + The desired access for the event + True to throw an exception on error. + The NT status code and object result. + + + + Open an event object + + The path to the event + The root object for relative path names + The event object + + + + Open an event object + + The path to the event + The event object + + + + Set the event state + + True to throw an exception on error. + The previous state of the event and NT status. + + + + Set the event state + + The previous state of the event + + + + Clear the event state + + True to throw an exception on error. + The NT status code. + + + + Clear the event state + + + + + Pulse the event state. + + True to throw an exception on error. + The previous state of the event and NT status. + + + + Pulse the event state. + + The previous state of the event + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get event type. + + + + + Get current event state. + + + + + Type of Event object. + + + + + Manual reset event. + + + + + Automatic reset event. + + + + + Exception class representing an NT status error. + + + + + Constructor + + Status result + + + + Returns the contained NT status code + + + + + Returns a string form of the NT status code. + + + + + Class representing a NT File object + + + + + Create a new file + + The object attributes + Desired access for the file + Attributes for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + Optional allocation size. + True to throw an exception on error. + The NT status code and object result. + + + + Create a new file + + The object attributes + Desired access for the file + Attributes for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + Optional allocation size. + The created/opened file object. + + + + Create a new file + + The object attributes + Desired access for the file + Attributes for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + True to throw an exception on error. + The NT status code and object result. + + + + Create a new file + + The object attributes + Desired access for the file + Attributes for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + The created/opened file object. + + + + Create a new file + + The path to the file + A root object to parse relative filenames + Desired access for the file + Attributes for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + True to throw an exception on error. + The created/opened file object. + + + + Create a new file + + The path to the file + A root object to parse relative filenames + Desired access for the file + Attributes for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + The created/opened file object. + + + + Create a new file + + The path to the file + Desired access for the file + Share access for the file + Open options for file + Disposition when opening the file + Extended Attributes buffer + The created/opened file object. + + + + Create a new named pipe file + + The object attributes + Desired access for the file + Share access for the file + Open options for file + Disposition when opening the file + Pipe completion mode + Default timeout + Input quota + Maximum number of instances (-1 for infinite) + Output quota + Type of pipe to create + Pipe read mode + True to throw an exception on error. + The NT status code and object result. + Thrown on error. + + + + Create a new named pipe file + + The object attributes + Desired access for the file + Share access for the file + Open options for file + Disposition when opening the file + Pipe completion mode + Default timeout + Input quota + Maximum number of instances (-1 for infinite) + Output quota + Type of pipe to create + Pipe read mode + The file instance for the pipe. + Thrown on error. + + + + Create a new named pipe file + + The path to the pipe file + A root object to parse relative filenames + Desired access for the file + Share access for the file + Open options for file + Disposition when opening the file + Pipe completion mode + Default timeout + Input quota + Maximum number of instances (-1 for infinite) + Output quota + Type of pipe to create + Pipe read mode + True to throw an exception on error. + The file instance for the pipe. + Thrown on error. + + + + Create a new named pipe file + + The path to the pipe file + A root object to parse relative filenames + Desired access for the file + Share access for the file + Open options for file + Disposition when opening the file + Pipe completion mode + Default timeout + Input quota + Maximum number of instances (-1 for infinite) + Output quota + Type of pipe to create + Pipe read mode + The file instance for the pipe. + Thrown on error. + + + + Create an anonymous named pipe pair. + + True to throw on error. + The named pipe pair. + + + + Create an anonymous named pipe pair. + + The named pipe pair. + + + + Create a new named mailslot file + + The object attributes + Desired access for the file + Open options for file + Mailslot quota + Maximum message size (0 for any size) + Read Timeout. + True to throw on error. + The file instance for the mailslot. + Thrown on error. + + + + Create a new named mailslot file + + The object attributes + Desired access for the file + Open options for file + Mailslot quota + Maximum message size (0 for any size) + Read timeout in MS (<0 is infinite) + True to throw on error. + The file instance for the mailslot. + Thrown on error. + + + + Create a new named mailslot file + + The object attributes + Desired access for the file + Open options for file + Mailslot quota + Maximum message size (0 for any size) + Read timeout in MS ( <0 is infinite) + The file instance for the mailslot. + Thrown on error. + + + + Create a new named mailslot file + + The path to the mailslot file + A root object to parse relative filenames + Desired access for the file + Open options for file + Mailslot quota + Maximum message size (0 for any size) + Timeout in MS ( <0 is infinite) + The file instance for the mailslot. + Thrown on error. + + + + Open a file + + The object attributes + The desired access for the file handle + The file share access + File open options + True to throw an exception on error. + The NT status code and object result. + + + + Open a file + + The object attributesf + The desired access for the file handle + The file share access + File open options + The opened file + Thrown on error. + + + + Open a file + + The path to the file + The root directory if path is relative. + The desired access for the file handle + The file share access + File open options + True to throw an exception on error. + The opened file + Thrown on error. + + + + Open a file + + The path to the file + The root directory if path is relative. + The desired access for the file handle + The file share access + File open options + The opened file + Thrown on error. + + + + Open a file + + The path to the file + The root directory if path is relative. + The desired access for the file handle + The opened file + Thrown on error. + + + + Get the object ID of a file as a string + + The path to the file + The object ID as a string + Thrown on error. + + + + Open a file by its object ID + + A handle to the volume on which the file resides. + The object ID as a binary string + The desired access for the file + File share access + Open options. + True to throw on error + The opened file object + + + + Open a file by its object ID + + A handle to the volume on which the file resides. + The object ID as a binary string + The desired access for the file + File share access + Open options. + The opened file object + Thrown on error. + + + + Open a file by its ID + + A handle to the volume on which the file resides. + The file's ID. Can be a file reference number or an Object ID. + The desired access for the file + File share access + Open options. + True to throw on error + The opened file object + + + + Open a file by its ID + + A handle to the volume on which the file resides. + The file's ID. Can be a file reference number or an Object ID. + The desired access for the file + File share access + Open options. + The opened file object + + + + Open a file by its object ID + + A handle to the volume on which the file resides. + The file ID. + The desired access for the file + File share access + Open options. + True to throw on error + The opened file object + + + + Open a file by its file ID + + A handle to the volume on which the file resides. + The file ID. + The desired access for the file + File share access + Open options. + The opened file object + Thrown on error. + + + + Open a file by its file ID + + The path to the volume which contains the file. + The file ID. + The desired access for the file + File share access + Open options. + True to throw on error + The opened file object + + + + Open a file by its file ID + + The path to the volume which contains the file. + The file ID. + The desired access for the file + File share access + Open options. + The opened file object + + + + Delete a file + + The object attributes for the file. + True to throw an exception on error + The status result of the delete + + + + Delete a file + + The object attributes for the file. + + + + Delete a file + + The path to the file. + + + + Rename file. + + The file to rename. + The target NT path. + Thrown on error. + + + + Create a hardlink to another file. + + The file to hardlink to. + The desintation hardlink path. + Thrown on error. + + + + Create a mount point. + + The path to the mount point to create. + The substitute name to reparse to. + The print name to display (can be null). + + + + Create a symlink. + + The path to the mount point to create. + True to create a directory symlink, false for a file. + The substitute name to reparse to. + The print name to display. + Additional flags for the symlink. + + + + Get the reparse point buffer for the file. + + The path to the reparse point. + The reparse point buffer. + + + + Delete the reparse point buffer. + + The path to the reparse point. + The original reparse buffer. + + + + Query attributes of a file. + + The object attributes. + True to throw on error. + The file attributes. + + + + Query attributes of a file. + + The object attributes. + The file attributes. + + + + Query attributes of a file. + + The path to the file. + The root directory to parse from. + True to throw on error. + The file attributes. + + + + Query attributes of a file. + + The path to the file. + The root directory to parse from. + The file attributes. + + + + Query attributes of a file. + + The path to the file. + The file attributes. + + + + Send a Device IO Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Cancellation token to cancel the async operation. + True to throw on error. + Thrown on error. + The length of output bytes returned. + + + + Send a Device IO Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + Cancellation token to cancel the async operation. + True to throw on error. + The output buffer returned by the kernel. + + + + Send a Device IO Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Cancellation token to cancel the async operation. + Thrown on error. + The length of output bytes returned. + + + + Send a Device IO Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + Cancellation token to cancel the async operation. + The output buffer returned by the kernel. + + + + Send a File System Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Cancellation token to cancel the async operation. + True to throw on error. + Thrown on error. + The length of output bytes returned. + + + + Send a File System Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + Cancellation token to cancel the async operation. + True to throw on error. + The output buffer returned by the kernel. + + + + Send a File System Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Cancellation token to cancel the async operation. + Thrown on error. + The length of output bytes returned. + + + + Send a File System Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + Cancellation token to cancel the async operation. + The output buffer returned by the kernel. + + + + Send a Device IO Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Thrown on error. + The length of output bytes returned. + + + + Send a Device IO Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + The output buffer returned by the kernel. + + + + Send a File System Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Thrown on error. + The length of output bytes returned. + + + + Send a File System Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + The output buffer returned by the kernel. + + + + Send a Device IO Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + True to throw on error. + Thrown on error. + The length of output bytes returned. + + + + Send a Device IO Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + True to throw on error. + The output buffer returned by the kernel. + + + + Send a File System Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + True to throw on error. + Thrown on error. + The length of output bytes returned. + + + + Send a File System Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + True to throw on error. + The output buffer returned by the kernel. + + + + Send a Device IO Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + True to throw an exception on error. + Thrown on error. + The length of output bytes returned. + + + + Send a Device IO Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + Thrown on error. + The length of output bytes returned. + + + + Send a Device IO Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + True to throw an exception on error. + The output buffer returned by the kernel. + + + + Send a Device IO Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + The output buffer returned by the kernel. + + + + Send an File System Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + True to throw an exception on error. + The length of output bytes returned. + Thrown on error. + + + + Send a File System Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + True to throw an exception on error. + The output buffer returned by the kernel. + + + + Send an File System Control code to the file driver + + The control code + Input buffer can be null + Output buffer can be null + The length of output bytes returned. + Thrown on error. + + + + Send a File System Control code to the file driver. + + The control code + Input buffer can be null + Maximum output buffer size + The output buffer returned by the kernel. + + + + Re-open an existing file for different access. + + The desired access for the file handle + The file share access + File open options + Flags for the object attributes. + True to throw an exception on error. + The NT status code and object result. + Thrown on error. + + + + Re-open an existing file for different access. + + The desired access for the file handle + The file share access + File open options + True to throw an exception on error. + The NT status code and object result. + Thrown on error. + + + + Re-open an exsiting file for different access. + + The desired access for the file handle + The file share access + File open options + The opened file + Thrown on error. + + + + Specify file disposition. + + True to set delete on close, false to clear delete on close. + True to throw on error. + The NT status code. + Thrown on error. + You can't prevent deletion if file opened with DeleteOnClose flag. + + + + Specify file disposition. + + True to set delete on close, false to clear delete on close. + Thrown on error. + You can't prevent deletion if file opened with DeleteOnClose flag. + + + + Delete the file. Must have been opened with DELETE access. + + True to throw on error. + The NT status code. + Thrown on error. + + + + Delete the file. Must have been opened with DELETE access. + + Thrown on error. + + + + Set disposition on the file (extended Windows version). + + True to throw on error. + Flags for SetDispositionEx call. + The NT status code. + Thrown on error. + + + + Set disposition on the file (extended Windows version). + + Flags for SetDispositionEx call. + Thrown on error. + + + + Delete the file (extended Windows version). Must have been opened with DELETE access. + + True to throw on error. + Flags for DeleteEx call. + The NT status code. + Thrown on error. + + + + Delete the file (extended Windows version). Must have been opened with DELETE access. + + Flags for DeleteEx call. + Thrown on error. + + + + Create a new hardlink to this file. + + The target NT path. + The root directory if linkname is relative + Thrown on error. + + + + Create a new hardlink to this file. + + The target absolute NT path. + Thrown on error. + + + + Create a new hardlink to this file. + + The target NT path. + The root directory if linkname is relative + If TRUE, replaces the target file if it exists. If FALSE, fails if the target file already exists. + True to throw on error. + The NT status code. + Thrown on error. + + + + Create a new hardlink to this file. + + The target NT path. + The root directory if linkname is relative + If TRUE, replaces the target file if it exists. If FALSE, fails if the target file already exists. + Thrown on error. + + + + Create a new hardlink to this file. + + The target NT path. + The root directory if linkname is relative + The flags associated to FileLinkInformationEx. + True to throw on error. + The NT status code. + Thrown on error. + + + + Create a new hardlink to this file. + + The target NT path. + The root directory if linkname is relative + The flags associated to FileLinkInformationEx. + Thrown on error. + + + + Rename file. + + The target NT path. + The root directory if new_name is relative + If TRUE, replaces the target file if it exists. If FALSE, fails if the target file already exists. + True to throw on error. + The NT status code. + Thrown on error. + + + + Rename file. + + The target NT path. + The root directory if new_name is relative + If TRUE, replaces the target file if it exists. If FALSE, fails if the target file already exists. + Thrown on error. + + + + Rename file. + + The target NT path. + The root directory if new_name is relative + Thrown on error. + + + + Rename this file with an absolute path. + + The target absolute NT path. + If TRUE, replace the target file if it exists. If FALSE, fails if the target file already exists. + Thrown on error. + + + + Rename this file with an absolute path. + + The target absolute NT path. + Thrown on error. + + + + Rename (extended Windows version) this file with an absolute path. + + The target absolute NT path. + The root directory if new_name is relative + The flags associated to FileRenameInformationEx. + True to throw on error. + The NT status code. + Thrown on error. + + + + Rename (extended Windows version) this file with an absolute path. + + The target absolute NT path. + The root directory if new_name is relative + The flags associated to FileRenameInformationEx. + Thrown on error. + + + + Rename (extended Windows version) this file with an absolute path. + + The target absolute NT path. + The flags associated to FileRenameInformationEx. + Thrown on error. + + + + Set an arbitrary reparse point. + + The reparse point data. + + + + Set an arbitrary reparse point. + + The reparse point data. + True to throw on error. + The NT status code. + + + + Set an arbitrary reparse point as a raw byte array. + + The reparse point data as a byte array. + + + + Set an arbitrary reparse point as a raw byte array. + + The reparse point data as a byte array. + True to throw on error. + The NT status code. + + + + Set an arbitrary reparse point. + + The reparse point data. + Flags for the reparse buffer. + Existing tag to check against. If no check required use 0. + Existing Guid to check against. If no check requested use empty GUID. + True to throw on error. + The NT status code. + + + + Set an arbitrary reparse point. + + The reparse point data. + Flags for the reparse buffer. + Existing tag to check against. If no check required use 0. + Existing Guid to check against. If no check requested use empty GUID. + + + + Set an arbitrary reparse point. + + The reparse point data. + Existing tag to check against. If no check required use 0. + + + + Set an arbitrary reparse point. + + The reparse point data.> + + + + Set a mount point on the current file object. + + The substitute name to reparse to. + The print name to display (can be null). + + + + Set a symlink on the current file object. + + The substitute name to reparse to. + The print name to display. + Additional flags for the symlink. + + + + Set a mount point on the current file object. + + The substitute name to reparse to. + The print name to display (can be null). + True to throw on error. + The NT status code. + + + + Set a symlink on the current file object. + + The substitute name to reparse to. + The print name to display. + Additional flags for the symlink. + True to throw on error. + The NT status code. + + + + Get the reparse point buffer for the file. + + True to throw on error. + The reparse point buffer. + + + + Get the reparse point buffer for the file. + + The reparse point buffer. + + + + Get the reparse point buffer for the file as a raw buffer. + + True to throw on error. + The reparse point buffer. + + + + Get the reparse point buffer for the file as a raw buffer. + + The reparse point buffer. + + + + Delete the reparse point buffer + + The reparse tag. + The NT status code. + True to throw on error. + + + + Delete the reparse point buffer + + The reparse tag. + + + + Delete the reparse point buffer + + The original reparse buffer. + True to throw on error. + + + + Delete the reparse point buffer + + The original reparse buffer. + + + + Get list of accessible files underneath a directory. + + Share access for file open + Options for open call. + The desired access for each file. + A file name mask (such as *.txt). Can be null. + Indicate what entries to return. + The list of files which can be access. + + + + Get list of accessible files underneath a directory. + + Share access for file open + Options for open call. + The desired access for each file. + The list of files which can be access. + + + + Query a directory for files. + + The list of directory entries. + + + + Query a directory for files. + + A file name mask (such as *.txt). Can be null. + Indicate what entries to return. + Specify what additional data to include in the directory entries. + The list of directory entries. You might need to cast the directories to the appropriate types if using include flags. + + + + Query a directory for files. + + A file name mask (such as *.txt). Can be null. + Indicate what entries to return. + The list of directory entries. + + + + Query a directory for files with file ID. + + A file name mask (such as *.txt). Can be null. + Indicate what entries to return. + Return placeholder parent and current directory entries. + The list of directory entries. + + + + Read data from a file with a length and position. + + The buffer to read to. + The position in the file to read. The position is optional. + True to throw on error. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position. + + The buffer to read to. + The position in the file to read. The position is optional. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position. + + The length of the read + The position in the file to read. The position is optional. + True to throw on error. + The read bytes, this can be smaller than length. + + + + Read data from a file with a length and position. + + The length of the read + The position in the file to read + The read bytes, this can be smaller than length. + + + + Read data from a file with a length. + + The length of the read + The read bytes, this can be smaller than length. + + + + Read data from a file with a length over a scatter set of pages. + + List of pages to read into. These pages must be Page Size aligned. + The length of the read + The position in the file to read. + True to throw on error. + The length of bytes read. + + + + Read data from a file with a length over a scatter set of pages. + + List of pages to read into. These pages must be Page Size aligned. + The length of the read + The position in the file to read. + The length of bytes read. + + + + Read data from a file with a length and position asynchronously. + + The buffer to read to. + The position in the file to read. The position is optional. + Cancellation token to cancel async operation. + True to throw on error. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position asynchronously. + + The buffer to read to. + The position in the file to read. The position is optional. + Cancellation token to cancel async operation. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position asynchronously. + + The length of the read + The position in the file to read. The position is optional. + Cancellation token to cancel async operation. + True to throw on error. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position asynchronously.. + + The length of the read + The position in the file to read + Cancellation token to cancel async operation. + The read bytes, this can be smaller than length. + + + + Read data from a file with a length and position asynchronously.. + + The length of the read + The position in the file to read + The read bytes, this can be smaller than length. + + + + Read data from a file with a length and position asynchronously. + + List of pages to read into. These pages must be Page Size aligned. + The length of the read + The position in the file to read. + Cancellation token to cancel async operation. + True to throw on error. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position asynchronously. + + List of pages to read into. These pages must be Page Size aligned. + The length of the read + The position in the file to read. + True to throw on error. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position asynchronously. + + List of pages to read into. These pages must be Page Size aligned. + The length of the read + The position in the file to read. + Cancellation token to cancel async operation. + The length of bytes read into the buffer. + + + + Read data from a file with a length and position asynchronously. + + List of pages to read into. These pages must be Page Size aligned. + The length of the read + The position in the file to read. + The length of bytes read into the buffer. + + + + Write data to a file at a specific position asynchronously. + + The data to write as a buffer. + The position to write to. + Cancellation token to cancel async operation. + True to throw on error. + The number of bytes written + + + + Write data to a file at a specific position asynchronously. + + The data to write as a buffer. + The position to write to. + Cancellation token to cancel async operation. + The number of bytes written + + + + Write data to a file at a specific position asynchronously. + + The data to write. + The position to write to. + Cancellation token to cancel async operation. + The number of bytes written + + + + Write data to a file at a specific position asynchronously. + + The data to write + The position to write to + The number of bytes written + + + + Write data to a file at a specific position asynchronously. + + The data to write. + The position to write to. + Cancellation token to cancel async operation. + True to throw on error. + The number of bytes written + + + + Write data to a file at a specific position. + + The data to write + The position to write to. Optional + True to throw on error. + The number of bytes written. + + + + Write data to a file at a specific position. + + The data to write + The position to write to. Optional + The number of bytes written. + + + + Write data to a file at a specific position. + + The data to write + The position to write to. Optional + True to throw on error. + The number of bytes written. + + + + Write data to a file at a specific position. + + The data to write + The position to write to + The number of bytes written + + + + Write data to a file + + The data to write + The number of bytes written + + + + Write data to a file at a specific position gathered from a list of pages. + + List of pages to write. These pages must be page size aligned. + The length of the write. + The position to write to. + True to throw on error. + The number of bytes written. + + + + Write data to a file at a specific position gathered from a list of pages. + + List of pages to write. These pages must be page size aligned. + The length of the write. + The position to write to. + The number of bytes written. + + + + Write data to a file at a specific position asynchronously from a list of pages. + + List of pages to write. These pages must be page size aligned. + The length of the write. + The position to write to. + Cancellation token to cancel async operation. + True to throw on error. + The number of bytes written + + + + Write data to a file at a specific position asynchronously from a list of pages. + + List of pages to write. These pages must be page size aligned. + The length of the write. + The position to write to. + True to throw on error. + The number of bytes written + + + + Write data to a file at a specific position asynchronously from a list of pages. + + List of pages to write. These pages must be page size aligned. + The length of the write. + The position to write to. + Cancellation token to cancel async operation. + The number of bytes written + + + + Write data to a file at a specific position asynchronously from a list of pages. + + List of pages to write. These pages must be page size aligned. + The length of the write. + The position to write to. + The number of bytes written + + + + Lock part of a file. + + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + True to throw on error. + The NT status code. + + + + Lock part of a file. + + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + + + + Shared lock part of a file. + + The offset into the file to lock + The number of bytes to lock + + + + Lock part of a file asynchronously. + + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + Cancellation token to cancel async operation. + True to throw on error. + The NT status code. + + + + Lock part of a file asynchronously. + + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + Cancellation token to cancel async operation. + + + + Lock part of a file asynchronously. + + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + + + + Shared lock part of a file asynchronously. + + The offset into the file to lock + The number of bytes to lock + + + + Unlock part of a file previously locked with Lock + + The offset into the file to unlock + The number of bytes to unlock + Thrown on error. + + + + Unlock part of a file previously locked with Lock + + The offset into the file to unlock + The number of bytes to unlock + True to throw on error. + The NT status code. + + + + Convert this NtFile to a FileStream for reading/writing. + + The stream must be closed separately from the NtFile. + The file stream. + Thrown on error. + + + + Get the Win32 path name for the file. + + The flags to determine what path information to get. + The path. + Throw on error. + + + + Get the Win32 path name for the file. + + The flags to determine what path information to get. + True to throw on error. + The path. + + + + Oplock the file with a specific level. + + The level of oplock to set. + True to throw on error. + The oplock response level. + + + + Oplock the file with a specific level. + + The level of oplock to set. + The oplock response level. + + + + Oplock the file with a specific level. + + The level of oplock to set. + Cancellation token to cancel async operation. + True to throw on error. + The oplock response level. + + + + Oplock the file with a specific level. + + The level of oplock to set. + True to throw on error. + The oplock response level. + + + + Oplock the file with a specific level. + + The level of oplock to set. + Cancellation token to cancel async operation. + The oplock response level. + + + + Oplock the file with a specific level. + + The level of oplock to set. + The oplock response level. + + + + Acknowledge an oplock break. + + The acknowledgment level. + True to throw on error. + The NT status code. + Oplock break acknowledgement returns STATUS_PENDING. + + + + Acknowledge an oplock break. + + The acknowledgment level. + + + + Oplock the file with a specific level. + + The oplock cache level. + Specify additional flags for the request. + True to throw on error. + The result of the oplock request. + + + + Oplock the file with a specific level. + + The oplock cache level. + True to throw on error. + The result of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + Cancellation token to cancel async operation. + Specify additional flags for the request. + True to throw on error. + The request of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + Cancellation token to cancel async operation. + True to throw on error. + The request of the oplock request. + + + + Oplock the file with a specific lease level and flags. + + The oplock lease level. + Specify additional flags for the request. + The result of the oplock request. + + + + Oplock the file with a specific lease level and flags. + + The oplock lease level. + The result of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + Specify additional flags for the request. + Cancellation token to cancel async operation. + The request of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + Cancellation token to cancel async operation. + The request of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + True to throw on error. + The request of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + The response of the oplock request. + + + + Oplock the file with a specific level and flags. + + The oplock level. + Specify additional flags for the request. + The response of the oplock request. + + + + Acknowledge a lease oplock started with RequestOplockLease. + + True to complete acknowledgement on close. + True to throw on error. + The NT status code. + This breaks to None. If you want to request the new oplock level then request a new oplock. + + + + Acknowledge a lease oplock started with RequestOplockLease. + + True to complete acknowledgement on close. + + + + Acknowledge a lease oplock started with RequestOplockLease. + + + + + Oplock the file exclusively (no other users can access the file). + + True to throw on error. + The oplock response level. + + + + Oplock the file exclusively (no other users can access the file). + + The oplock response level. + + + + Oplock the file exclusively (no other users can access the file). + + Cancellation token to cancel async operation. + The oplock response level. + + + + Oplock the file exclusively (no other users can access the file). + + The oplock response level. + + + + Wait for an oplock break to complete. + + True to throw on error. + The NT status code. + + + + Wait for an oplock break to complete. + + The NT status code. + + + + Wait for an oplock break to complete. + + True to throw on error. + The NT status code. + + + + Wait for an oplock break to complete. + + The NT status code. + + + + Dispose. + + True is disposing. + + + + Try and cancel any pending asynchronous IO. + + + + + Get the extended attributes of a file. + + True to throw on error. + The extended attributes, empty if no extended attributes. + + + + Get the extended attributes of a file. + + The extended attributes, empty if no extended attributes. + + + + Set the extended attributes for a file. + + The EA buffer to set. + True to throw on error. + This will add entries if they no longer exist, + remove entries if the data is empty or update existing entires. + + + + Set the extended attributes for a file. + + The EA buffer to set. + This will add entries if they no longer exist, + remove entries if the data is empty or update existing entires. + + + + Set the extended attributes for a file. + + The name of the entry + The associated data + The entry flags. + + + + Set the extended attributes for a file. + + The name of the entry + The associated data + The entry flags. + + + + Set the extended attributes for a file. + + The name of the entry + The associated data + The entry flags. + + + + Remove an extended attributes entry for a file. + + The name of the entry + + + + Assign completion port to file. + + The completion port. + A key to associate with this completion. + + + + Check if a specific set of file directory access rights is granted + + The file directory access rights to check + True if all access rights are granted + + + + Get the cached signing level for a file. + + The cached signing level. + + + + Get the cached signing level for a file. + + The cached signing level. + + + + Get the cached singing level from the raw EA buffer. + + The cached signing level data. + Throw on error. + + + + Set the cached signing level for a file. + + Flags to set for the cache. + The signing level to cache + + + + Set the cached signing level for a file. + + Flags to set for the cache. + The signing level to cache + Optional directory path to look for catalog files. + + + + Set the cached signing level for a file. + + Flags to set for the cache. + The signing level to cache + Files for signature. + Optional directory path to look for catalog files. + + + + Set the cached signing level for a file. + + Flags to set for the cache. + The signing level to cache + Files for signature. + Optional directory path to look for catalog files. + True to throw on error. + + + + Set the end of file. + + The offset to the end of file. + + + + Set the valid data length of the file without zeroing. Needs SeManageVolumePrivilege. + + The length to set. + + + + Get list of hard link entries for a file. + + The list of entries. + + + + Get a list of stream entries for the current file. + + The list of streams. + + + + Visit all accessible streams under this file. + + A function to be called on every accessible stream. Return true to continue enumeration. + Specify the desired access for the streams. + The share access to open the streams with. + Additional options to open the s with. + True if all accessible streams were visited, false if not. + + + + Get list of process ids using this file. + + The list of process ids. + + + + Visit all accessible files under this directory. + + A function to be called on every accessible file. Return true to continue enumeration. + Specify the desired access for the files. + True to recurse into sub keys. + The share access to open the files with. + Specify max recursive depth. -1 to not set a limit. + Additional options to open the files with. + A file name mask (such as *.txt). Can be null. + Indicate what entries to return. + True if all accessible files were visited, false if not. + + + + Visit all accessible files under this directory. + + A function to be called on every accessible file. Return true to continue enumeration. + Specify the desired access for the files. + True to recurse into sub keys. + The share access to open the files with. + Specify max recursive depth. -1 to not set a limit. + Additional options to open the files with. + True if all accessible files were visited, false if not. + + + + Visit all accessible files under this directory. + + A function to be called on every accessible file. Return true to continue enumeration. + + + + Visit all accessible files under this directory. + + A function to be called on every accessible file. Return true to continue enumeration. + Specify the desired access for the files. + The share access to open the files with. + + + + Query whether a file is trusted for dynamic code. + + Returns true if the file is trusted. + + + + Set a file is trusted for dynamic code. + + + + + Set a file is trusted for dynamic code. + + True to throw on error. + The NT status code. + + + + Find files in a directory by the owner SID. + + The owner SID. + A list of files in the directory. + For this method to work you need Quota enabled on the volume. + + + + Get full change notifications. Will pick ex version if available and revert to old format if not. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + Wait timeout. + The list of changes. + + + + Get full change notifications. Will pick ex version if available and revert to old format if not. + + The filter of events to watch for. + True to watch all sub directories. + Wait timeout. + The list of changes. + + + + Get full change notifications asynchronously. Will pick ex version if available and revert to old format if not. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + Cancellation token. + The list of changes. + + + + Get full change notifications asynchronously. Will pick ex version if available and revert to old format if not. + + The filter of events to watch for. + True to watch all sub directories. + Cancellation token. + The list of changes. + + + + Get full change notifications asynchronously. Will pick ex version if available and revert to old format if not. + + The filter of events to watch for. + True to watch all sub directories. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + Wait timeout. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + Wait timeout. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + Cancellation token. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + Cancellation token. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + The list of changes. + + + + Get extended change notifications. + + The filter of events to watch for. + True to watch all sub directories. + Timeout to wait. + True to throw on error. + The list of changes. + + + + Get extended change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + Timeout to wait. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + Cancellation token. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + True to throw on error. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + Cancellation token. + The list of changes. + + + + Get change notifications. + + The filter of events to watch for. + True to watch all sub directories. + The list of changes. + + + + Get the file attributes. + + True to throw on error. + The file attributes. + + + + Set the file attributes. + + The file attributes to set. + True to throw on error. + The NT status code. + + + + Get the creation time. + + True to throw on error. + The creation time. + + + + Get the last write time. + + True to throw on error. + The last write time. + + + + Get the change time time. + + True to throw on error. + The change time. + + + + Get the last access time. + + True to throw on error. + The last access time time. + + + + Set the file's creation time. + + The time to set. + True to throw on error. + The NT status code. + + + + Set the file's last access time. + + The time to set. + True to throw on error. + The NT status code. + + + + Set the file's last write time. + + The time to set. + True to throw on error. + The NT status code. + + + + Set the file's change time. + + The time to set. + True to throw on error. + The NT status code. + + + + Set the file position. + + The file position to set. + True to throw on error. + The NT status code. + + + + Get file information. + + + + + + + Query all reparse points from a volume. + + The list of reparse points. + You'll need to open the reparse database, which is typically \$Extend\$Reparse:$R:$INDEX_ALLOCATION on the volume. + + + + Query all object ids from a volume. + + The list of object ids. + You need to open the object ID database, which is typically \$Extend\$ObjId:$O:$INDEX_ALLOCATION on the volume. + + + + Get the Object ID buffer for a file. + + True to throw on error. + The object ID buffer. + + + + Get the Object ID create for a file. + + The object ID buffer. + + + + Get the Object ID buffer for a file. + + True to throw on error. + The object ID buffer. + + + + Get or create the Object ID for a file. + + The object ID buffer. + + + + Set Object ID and extended information. + + The Object ID buffer. + Only set the extended information. + True to throw on error. + The NT status code. + + + + Set Object ID and extended information. + + The Object ID buffer. + Only set the extended information. + The NT status code. + + + + Set Object ID and extended information. + + The Object ID GUID. + Extended info buffer, needs to be 48 bytes in size. + The NT status code. + + + + Set only Object ID extended information. + > + Extended info buffer, needs to be 48 bytes in size. + The NT status code. + + + + Delete the Object ID for a file. + + True to throw on error. + The NT status code. + + + + Delete the Object ID for a file. + + + + + Make the file sparse. + + True to make the file sparse. + True to throw on error. + The NT status code. + + + + Query if the driver is in the device stack for the device. + + The driver path. Can be a plain name of full object manager path, e.g. \Device\Blah. + True to throw on error. + True indicating driver in path. + + + + Query if the driver is in the device stack for the device. + + The driver path. + True indicating driver in path. + + + + Get filesystem and volume information. + + + + + Query a fixed buffer for a volume. + + The type to query. + The volume information class. + The returned type. + + + + Query a fixed buffer for a volume. + + The type to query. + The volume information class. + True to throw on error. + The returned type. + + + + Query a buffer for a volume. + + The type to query. + The volume information class. + True to throw on error. + The returned type. + + + + Query a buffer for a volume. + + The volume information class. + Initialization buffer. + True to throw on error. + The returned type. + + + + Query a buffer for a volume. + + The volume information class. + Initialization buffer. + The returned type. + + + + Query a buffer for a volume. + + The type to query. + The volume information class. + The returned type. + + + + Query a buffer for a volume. + + The volume information class. + The buffer for the query. Can be initialized. + True to throw on error. + The NT status code. + + + + Query a buffer for a volume. + + The volume information class. + The buffer for the query. Can be initialized. + + + + Set a buffer on a volume. + + The volume information class. + The buffer for the set. + True to throw on error. + The NT status code. + + + + Set a buffer on a volume. + + The volume information class. + The buffer for the set. + + + + Set a fixed value on a volume. + + The volume information class. + The fixed value to set. + True to throw on error. + The NT status code. + + + + Set a fixed value on a volume. + + The volume information class. + The fixed value to set. + + + + Query the quota entries for a volume. + + Return quote entries for the specified SIDs. + The list of quota entries. + + + + Query all quota entries for a volume. + + The list of quota entries. + + + + Set quota entries. + + The quota entries to set. + True to throw on error. + The NT status code. + + + + Set quota entries. + + The quota entries to set. + + + + Set quota entry. + + The quota entry to set. + + + + Set quota entry. + + The SID for the quota. + The quota limit to set. + The quota threshold to set. + + + + Get the file's full path. + + True to throw on error. + The file name. + + + + Get the file's normalized path. + + True to throw on error. + The file name. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get object ID for current file + + The object ID as a string + Thrown on error. + + + + Get object ID for current file as a number. + + The object ID as a number. + Thrown on error. + + + + Get or set the attributes of a file. + + The file attributes + Thrown on error. + + + + Get or set the creation time. + + + + + Get or set the last access time. + + + + + Get or set the last write time. + + + + + Get or set the change time. + + + + + Get file information, which is times, attributes and sizes. + + + + + Get or set the file as sparse. + + + + + Get whether this file represents a directory. + + + + + Get whether this file repsents a reparse point. + + + + + The result of opening the file, whether it was created, overwritten etc. + + + + + Get or set the current file position. + + + + + Get or sets the file's length + + + + + Get the file's allocation size. + + + + + Get the number of links. + + + + + Get whether delete is pending. + + + + + Get the Win32 path name for the file. + + The path, string.Empty on error. + + + + Get the low-level device type of the file. + + The file device type. + + + + Get the low-level device characteristics of the file. + + The file device characteristics. + + + + Get filesystem and volume information. + + + + + Get or set the file's compression format. + + + + + Gets whether the file is on a remote file system. + + + + + Get or set whether this file/directory is case sensitive. + + + + + Get or set whether this file/directory is case sensitive. + + + + + Get the file mode. + + + + + Get file access information. + + + + + Get the filename with the volume path. + + + + + Get the normalized filename with the volume path. + + + + + Get the associated short filename + + + + + Get the associated short filename + + + + + Get the normalized name. + + + + + Get or set the storage reserve ID. + + + + + Returns whether this object is a container. + + + + + Get or set the read only status of the file. + + + + + Is the file compressed. + + + + + Get remote protocol information. + + + + + Get the granted access as directory rights. + + + + + Get the file system control flags. + + + + + Get persist volume flags. + + + + + Return the status information field. (32 bit) + + + + + Class representing file information. + + + + + Time of creation. + + + + + Time of last access. + + + + + Time of last write. + + + + + Time of change. + + + + + Length of the file. + + + + + Length of the file, alias of EndOfFile. + + + + + Allocation size. + + + + + File attributes. + + + + + Has the file got a set of attributes set. + + The attributes to check. + True if it has the attributes. + + + + Is the file a directory. + + + + + Is the file a reparse point. + + + + + Class to represent a directory entry. + + + + + Index of the file. + + + + + File name. + + + + + Class to represent a directory entry with file IDs. + + + + + Length of any EA buffer. + + + + + The file reference number if known. + + + + + Class to represent a directory entry with short names. + + + + + Length of any EA buffer. + + + + + The short name of the file. + + + + + Class to represent a directory entry with short names and file ids. + + + + + Length of any EA buffer. + + + + + The short name of the file. + + + + + The file reference number if known. + + + + + Class to represent a file quota entry. + + + + + Class to represet a file object ID. + + + + + Full path to the file with the reparse point. + + + + + Win32 path to the file with the reparse point. + + + + + Reference number for the file. + + + + + The file's attributes. + + + + + The file's object ID. + + + + + The file's extended info. + + + + + File's birth volume ID. + + + + + File's birth object ID. + + + + + File's domain ID. + + + + + Class to represent a file reparse point. + + + + + Full path to the file with the reparse point. + + + + + Win32 path to the file with the reparse point. + + + + + Reference number for the file. + + + + + The file's attributes. + + + + + The reparse point buffer. + + + + + The reparse point tag. + + + + + Utility functions for files + + + + + Convert a DOS filename to an absolute NT filename + + The filename, can be relative + True to throw on error. + The NT filename + + + + Convert a DOS filename to an absolute NT filename + + The filename, can be relative + The NT filename + + + + Convert a DOS filename to an absolute NT filename + + List of paths to combine before converting. + The NT filename + + + + Convert a DOS filename to an NT filename and get as an ObjectAttributes structure + + The DOS filename. + The object attribute flags. + An optional security quality of service. + An optional security descriptor. + True to throw on error. + The object attributes + + + + Convert a DOS filename to an NT filename and get as an ObjectAttributes structure + + The DOS filename. + The object attribute flags. + An optional security quality of service. + An optional security descriptor. + The object attributes + + + + Convert a DOS filename to an NT filename and get as an ObjectAttributes structure + + The filename + The object attributes + + + + Convert a DOS filename to a UNICODE_STRING structure + + The DOS filename + The UNICODE_STRING + + + + Get type of DOS path + + The DOS filename + The type of DOS path + + + + Map directory access rights to file access rights. + + The directory access rights to map. + The mapped access rights. + + + + Convert a file ID long to a string. + + The file ID to convert + The string format of the file id. + + + + Convert a string to a file ID. + + The file ID as a string (must be 4 characters). + The file ID as a long. + + + + Get if a reparse tag is a Microsoft defined one. + + The reparse tag. + True if it's a Microsoft reparse tag. + + + + Get if a reparse tag is a name surrogate. + + The reparse tag. + True if it's a surrogate reparse tag. + + + + Get if a reparse tag is a directory which can have children. + + The reparse tag. + True if it's a directory reparse tag which can have children. + + + + Convert a directory access rights mask to a normal file access mask. + + The access to convert. + The converted access rights. + + + + Convert a file access rights mask to a directory file access mask. + + The access to convert. + The converted access rights. + + + + Enable or disable Wow64 FS redirection. + + True to enable FS redirection. + True to throw on error. + The old enable state. + + + + Enable or disable Wow64 FS redirection. + + True to enable FS redirection. + The old enable state. + + + + Split an allocated address into a list of pages. This can be used to pass to + ReadScatter or WriteGather file APIs. + + The base address to split. The address should be page aligned. + The length of bytes to split into pages. This will be rounded up to the next page boundary. + The list of pages. + + + + Split an allocated address into a list of pages. This can be used to pass to + ReadScatter or WriteGather file APIs. + + The allocated buffer to split. The address should be page aligned. + The buffer will be split up based on its length. Note that the length will be rounded up. + The list of pages. + + + + Attempt to convert an NT device filename to a DOS filename. + + The filename to convert. + The converted string. Returns a path prefixed with GLOBALROOT if it doesn't understand the format. + + + + Build a path for an open by ID file. + + The path to the volume. + The ID. + The bytes for the ID path. + + + + Build a path for a file ID volume. + + The path to the volume. + The file reference number. + The bytes for the file ID path. + + + + Build a path for an object ID volume. + + The path to the volume. + The file object ID. + The bytes for the file ID path. + + + + Generate a DOS filename from a full filename. + + The full filename. + True to allow extended characters. + Number of iterations of the algorithm to test. + True throw on error. + The DOS filename. + + + + Generate a DOS filename from a full filename. + + The full filename. + True to allow extended characters. + Number of iterations of the algorithm to test. + The DOS filename. + + + + Generate a DOS filename from a full filename. + + The full filename. + True to allow extended characters. + The DOS filename. + + + + Is the filename a legal 8dot3 name. + + The filename to check. + True if it's a legal 8dot3 name. + + + + Class representing a NT FilterConnectionPort object. Note this is just a dummy object for typing purposes. + + + + + A generic wrapper for any object, used if we don't know the type ahead of time. + + + + + Convert the generic object to the best typed object. + + The typed object. Can be NtGeneric if no better type is known. + + + + Convert the generic object to the best typed object. + + True to throw on error. + The typed object. Can be NtGeneric if no better type is known. + + + + Returns whether this object is a container. + + + + + Class to represent a system handle + + + + + The ID of the process holding the handle + + + + + Get the image path for the process which contains this handle. + + + + + Get name of the process which contains this handle. + + + + + The object type index + + + + + The object type name + + + + + The object type + + + + + The handle attribute flags. + + + + + The handle value + + + + + The address of the object. + + + + + The granted access mask + + + + + The granted access mask as a string. + + + + + The granted access mask as a string. + + + + + Whether the handle is inheritable. + + + + + Whether the handle is protected from close. + + + + + Whether the handle has write access. + + + + + Whether the handle has read access. + + + + + Whether the handle has execute access. + + + + + Whether the handle has full access. + + + + + The name of the object (needs to have set query access in constructor) + + + + + The security of the object (needs to have set query access in constructor) + + + + + Indicates if the handle was valid. + + This can cause the handle's values to be queried which can take time. + + + + Overridden ToString. + + The handle as a string. + + + + Get handle into the current process + + True to throw on error. + The handle to the object + + + + Get handle into the current process + + The handle to the object + + + + Close the handle in the original process. + + True throw on error. + The NT status code. + This is not recommended. + + + + Close the handle in the original process. + + This is not recommended. + + + + Class to call NT heap APIs. + + + + + Allocate a buffer from the heap. + + Heap flags. + Size of the allocation. + True to throw on error. + The allocated memory address. + + + + Allocate a buffer from the heap. + + Heap flags. + Size of the allocation. + The allocated memory address. + + + + Free a buffer from the heap. + + Heap flags. + Address of the allocation. + True to throw on error. + + + + Free a buffer from the heap. + + Heap flags. + Address of the allocation. + + + + Get the current process heap. + + + + + Class representing an NT IO Completion Port object + + + + + Create an IO Completion Port object + + The object attributes + The desired access for the event + Number of concurrent threads to process I/O packets. 0 for CPU count. + True to throw an exception on error. + The NT status code and object result. + Thrown on error. + + + + Create an IO Completion Port object + + The object attributes + The desired access for the event + Number of concurrent threads to process I/O packets. 0 for CPU count. + The IO Completion Port object. + Thrown on error. + + + + Create an IO Completion Port object + + The path to the IO Completion Port + The root object for relative path names + The desired access for the event + Number of concurrent threads to process I/O packets. 0 for CPU count. + The IO Completion Port object. + Thrown on error. + + + + Create an unnamed IO Completion Port object. + + The IO Completion Port object. + Thrown on error. + + + + Open an IO Completion Port object + + The object attributes + The desired access for the event + The IO Completion Port object. + Thrown on error. + + + + Open an IO Completion Port object + + The object attributes + The desired access for the event + True to throw an exception on error. + The NT status code and object result. + Thrown on error. + + + + Open an IO Completion Port object + + The path to the IO Completion Port + The root object for relative path names + The desired access for the event + The IO Completion Port object. + Thrown on error. + + + + Open an IO Completion Port object + + The path to the IO Completion Port + The IO Completion Port object. + Thrown on error. + + + + Remove a queued status from the queue. + + An optional timeout. + True to throw on error. + The completion result. + Thrown on error or timeout. + + + + Remove a queued status from the queue. + + An optional timeout. + The completion result. + Thrown on error or timeout. + + + + Remove multiple queued status from the queue. + + Maximum number of status to remove. + An optional timeout. + Indicate whether the wait is alertable. + True to throw on error. + Array of completion results. Length can be <= max_count. + + + + Remove multiple queued status from the queue. + + Maximum number of status to remove. + An optional timeout. + Indicate whether the wait is alertable. + Array of completion results. Length can be <= max_count. If timeout then returns an empty array. + + + + Remove multiple queued status from the queue. + + Maximum number of status to remove. + Array of completion results. Length can be <= max_count + + + + Remove a queued status from the queue. Wait for an infinite time for the result. + + The completion result. + + + + Add a queued status to the queue. + + The optional key context. + The optional APC context. + Status code + The information context. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Get current depth of IO Completion Port + + + + + Memory control method. + + + + + Buffered. + + + + + IN Direct. + + + + + OUT Direct. + + + + + Neither. + + + + + Access control flags. + + + + + Any access. + + + + + Read access. + + + + + Write access. + + + + + Represents a NT file IO control code. + + + + + Type of device + + + + + Function number + + + + + Buffering method + + + + + Access of file handle + + + + + Is the function number custom, i.e. has the top bit set. + + + + + Get a known name associated with this IO control code. + + + + + Constructor + + Type of device + Function number + Buffering method + Access of file handle + + + + Constructor + + Raw IO control code to convert. + + + + Static method to create an NtIoControlCode + + The conde as an integer. + The io control code. + + + + Convert the io control code to an Int32 + + The int32 version of the code + + + + Overriden hash code. + + The hash code. + + + + Overridden equals. + + The object to compare against. + True if equal. + + + + Overridden ToString method. + + The IO control code as a string. + + + + Format IO control code with an format specifier. + + The format specified. For example use X to format as a hexadecimal number. + The formatted string. + + + + Format the underlying IO control code with an format specifier. + + The format specified. For example use X to format as a hexadecimal number. + Format provider. + The formatted string. + + + + Class representing a NT Job object + + + + + Create a job object + + The object attributes + Desired access for job. + True to throw an exception on error. + The NT status code and object result. + + + + Create a job object + + The object attributes + Desired access for job. + The Job object. + + + + Create a job object + + The path to the job object (can be null) + The root object when path is relative + Desired access for job. + The Job object + + + + Create a job object + + The path to the job object (can be null) + The root object when path is relative + The Job object + + + + Create an unnamed job object + + The Job object + + + + Open a job object + + The object attributes + Desired access for job. + True to throw an exception on error. + The NT status code and object result. + + + + Open a job object + + The object attributes + Desired access for job. + The Job object + + + + Open a job object + + The path to the job object + The root object when path is relative + Desired access for the job object + The Job object + + + + Open a job object + + The path to the job object + The root object when path is relative + The Job object + + + + Create and initialize a Silo, + + Flags for root directory. + Desired access for the job. + Object attributes. + True to throw on error. + The Job object. + + + + Create and initialize a Silo, + + Flags for root directory. + Desired access for the job. + Object attributes. + The Job object. + + + + Create and initialize a Silo, + + Flags for root directory. + True to throw on error. + The Job object. + + + + Create an initialize a Silo, + + Flags for root directory. + The Job object. + + + + Create and initialize a Server Silo, + + Flags for root directory. + True to throw on error. + Path to the system root. + Event to signal when silo deleted. + True if a downlevel container. + Desired access for the job. + Object attributes. + The Job object. + + + + Create and initialize a Server Silo, + + Flags for root directory. + Path to the system root. + Event to signal when silo deleted. + True if a downlevel container. + Desired access for the job. + Object attributes. + The Job object. + + + + Create and initialize a Server Silo, + + Flags for root directory. + True to throw on error. + Path to the system root. + Event to signal when silo deleted. + True if a downlevel container. + The Job object. + + + + Create and initialize a Server Silo, + + Flags for root directory. + Path to the system root. + Event to signal when silo deleted. + True if a downlevel container. + The Job object. + + + + Convert Job object into a Silo + + True to throw on error. + The NT status code. + + + + Convert Job object into a Silo + + + + + Initialize a Silo, + + Flags for root directory. + True to throw on error. + The NT status code. + + + + Initialize a Silo, + + Flags for root directory. + + + + Initialize a Silo to a Server Silo. + + Event to signal when silo deleted. + True if a downlevel container. + True to throw on error. + The NT status code. + You must have set a system root and added a \Device directory (which shadows the real directory) to the silo object directory. + + + + Initialize a Silo to a Server Silo. + + Event to signal when silo deleted. + True if a downlevel container. + The NT status code. + + + + Create the silo's root object directory. + + The flags for the creation. + True to throw on error. + The NT status code. + + + + Create the silo's root object directory. + + The flags for the creation. + The NT status code. + + + + Assign a process to this job object. + + The process to assign. + + + + Assign a process to this job object. + + True to throw on error. + The process to assign. + The NT status code. + + + + Assign a process to this job object using current Job on Windows 1709+. + + + + + Assign a process to this job object using current Job on Windows 1709+. + + + + + Associate a completion port with the job. + + The completion port. + The key associated with the port. + + + + Terminate this job object. + + The termination status. + True to throw on error. + The NT status code. + + + + Terminate this job object. + + The termination status. + + + + Set the limit flags for the job. + + The limit flags. + True to throw on error. + The NT status code. + + + + Set the limit flags for the job. + + The limit flags. + + + + Set the Silo system root directory. + + The absolute path to the system root directory. + True to throw on error. + The system_root path must start with a capital drive letter and not end with a backslash. + The NT status code. + + + + Set the Silo system root directory. + + The absolute path to the system root directory. + The system_root path must start with a capital drive letter and not end with a backslash. + + + + Set the active process limit. + + The number of active processes in the job. + True to throw on error. + The NT status code. + + + + Set the active process limit. + + The number of active processes in the job. + + + + Set minimum and maximum working set size. + + The minimum working set size. + The maximum working set size. + True to throw on error. + The NT status code. + + + + Set minimum and maximum working set size. + + The minimum working set size. + The maximum working set size. + + + + Set the process memory limit. + + The memory limit for a process. + True to throw on error. + The NT status code. + + + + Set the process memory limit. + + The memory limit for a process. + The NT status code. + + + + Set the job memory limit. + + The memory limit for a job. + True to throw on error. + The NT status code. + + + + Set the job memory limit. + + The memory limit for a job. + The NT status code. + + + + Set the time limit for a process. + + The time limit for a process, in 100ns ticks. Set to 0 to clear the timeout. + True to throw on error. + The NT status code. + + + + Set the time limit for a process. + + The time limit for a process, in 100ns ticks. Set to 0 to clear the timeout. + + + + Set the time limit for a process. + + The time limit for a process. + True to throw on error. + The NT status code. + + + + Set the time limit for a process. + + The time limit for a process. + + + + Set the time limit for a job. + + The time limit for a job, in 100ns ticks. Set to 0 to clear timeout. + True to throw on error. + The NT status code. + + + + Set the time limit for a job. + + The time limit for a job, in 100ns ticks. Set to 0 to clear timeout. + + + + Set the time limit for a job. + + The time limit for a job. + True to throw on error. + The NT status code. + + + + Set the time limit for a job. + + The time limit for a job. + + + + Get list of process IDs in Job. + + True to throw on error. + The list of process IDs. + + + + Get list of process IDs in Job. + + The list of process IDs. + + + + Set UI Restriction Flags. + + The UI Restriction Flags. + True to throw on error. + The NT status code. + + + + Set UI Restriction Flags. + + The UI Restriction Flags. + The NT status code. + + + + Query Silo Root directory. + + True to throw on error. + The silo root directory. + + + + Get Silo basic information. + + True to throw on error. + The Silo Basic Information. + + + + Get Silo basic information. + + True to throw on error. + The Server Silo Basic Information. + + + + Get Silo user shared data. + + True to throw on error. + The Silo User Shared Data. + + + + Get whether this job object can be impersonated. + + True to throw on error. + True if the job object can be impersonated. + + + + Enable thread impersonation on this job object. + + True to throw on error. + The NT status code. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Get or set completion filter for job object. + + + + + The count of completions for the job. + + + + + Get or set the Maximum Bandwith NetRate limitation. + + + + + Get or set the DSCP Tag NetRate limitation. + + + + + Get or set the active process limit. + + + + + Get or set the active process limit. + + + + + Get or set the minimum working set size. + + + + + Get or set the maximum working set size. + + + + + Get or set the process time limit. + + + + + Get or set the process time limit. + + + + + Get or set the process memory limit. + + + + + Get or set the process memory limit. + + + + + Get used peak job memory used. + + + + + Get used peak job memory used. + + + + + Get or set the job limit flags. + + + + + Get or set the job UI Restriction flags. + + + + + Get or set whether job breakaway is allowed. + + + + + Get or set whether silenty job breakaway is allowed. + + + + + ID of container. + + + + + ID of container telemetry. + + + + + Job ID. + + + + + Get the Silo's Root Directory. + + + + + Get Silo basic information. + + + + + Get Silo basic information. + + + + + Get Silo user shared data. + + + + + Get or set the thread impersonation status. + + + + + Get whether this Job object is a silo. + + + + + Class to represent an NT Key object + + + + + Load a new hive + + The destination path + The path to the hive + Load flags + The opened root key + Thrown on error. + + + + Load a new hive + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Desired access for the root key + The opened root key + Thrown on error. + + + + Load a new hive + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Desired access for the root key + Key that this hive will be trusted for. + Event handle for key load. + True to throw an exception on error. + The NT status code and object result. + + + + Load a new hive and do not open the root key. + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Key that this hive will be trusted for. + Event handle for key load. + True to throw an exception on error. + The NT status code. + + + + Load a new hive + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Desired access for the root key + Key that this hive will be trusted for. + Event handle for key load. + The opened key. + + + + Load a new hive and do not open the root key. + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Key that this hive will be trusted for. + Event handle for key load. + + + + Load a new hive + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Desired access for the root key + True to throw an exception on error. + The NT status code and object result. + + + + Load a new hive + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Desired access for the root key + Token to open the hive files under. + Key that this hive will be trusted for. + Event handle for key load. + True to throw an exception on error. + The NT status code and object result. + + + + Load a new hive and do not open the root key. + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Token to open the hive files under. + Key that this hive will be trusted for. + Event handle for key load. + True to throw an exception on error. + The NT status code. + + + + Load a new hive + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Desired access for the root key + Token to open the hive files under. + Key that this hive will be trusted for. + Event handle for key load. + The loaded key. + + + + Load a new hive and do not open the root key. + + Object attributes for the key name + Object attributes for the path to the hive file + Load flags + Token to open the hive files under. + Key that this hive will be trusted for. + Event handle for key load. + + + + Unload an existing hive. + + Object attributes for the key name + Unload flags + True to throw an exception on error. + The NT status code. + + + + Unload an existing hive. + + Path to key to unload. + Unload flags + Thrown on error. + + + + Unload an existing hive. + + Path to key to unload. + Thrown on error. + + + + Create a new Key + + Object attributes for the key name + Desired access for the root key + Create options + Optional transaction object. + True to throw an exception on error. + The NT status code and object result. + + + + Create a new Key + + Object attributes for the key name + Desired access for the root key + Create options + True to throw an exception on error. + The NT status code and object result. + + + + Create a new Key + + Object attributes for the key name + Desired access for the root key + Create options + The opened key + Thrown on error. + + + + Create a new Key + + Object attributes for the key name + Desired access for the root key + Create options + Optional transaction object. + The NT status code and object result. + + + + Create a new Key + + Path to the key to create + Root key if key_name is relative + Desired access for the root key + Create options + The opened key + Thrown on error. + + + + Try and open a Key + + Object attributes for the key name + Desired access for the root key + Open options. + Optional transaction object. + True to throw an exception on error. + The NT status code and object result. + + + + Try and open a Key + + Object attributes for the key name + Desired access for the root key + Open options. + True to throw an exception on error. + The NT status code and object result. + + + + Try and open a Key + + Path to the key to open + Root key if key_name is relative + Desired access for the root key + Open options. + Optional transaction object. + True to throw an exception on error. + The NT status code and object result. + + + + Try and open a Key + + Path to the key to open + Root key if key_name is relative + Desired access for the root key + Open options. + True to throw an exception on error. + The NT status code and object result. + + + + Open a Key + + Object attributes for the key name + Desired access for the root key + Open options. + The opened key + Thrown on error. + + + + Open a Key + + Object attributes for the key name + Desired access for the root key + Open options. + Optional transaction object. + The opened key + Thrown on error. + + + + Open a Key + + Path to the key to open + Root key if key_name is relative + Desired access for the root key + The opened key + Thrown on error. + + + + Query a license value. While technically not directly a registry key + it has many of the same properties such as using the same registry + value types. + + The name of the license value. + True to throw an exception on error + The license value key + + + + Query a license value. While technically not directly a registry key + it has many of the same properties such as using the same registry + value types. + + The name of the license value. + The license value key + + + + Create a registry key symbolic link + + Root key if path is relative + Path to the key to create + Target resistry path + The created symbolic link key + Thrown on error. + + + + Open the machine key + + The opened key with the maximum access allowed. + Thrown on error. + + + + Open the machine key + + The opened key with the maximum access allowed. + True to throw on error. + Thrown on error. + + + + Open the user key + + The opened key + Thrown on error. + + + + Open the user key + + The opened key with the maximum access allowed. + True to throw on error. + Thrown on error. + + + + Open a specific user key + + The SID of the user to open + The opened key + Thrown on error. + + + + Open the user key + + The SID of the user to open + True to throw on error. + The opened key with the maximum access allowed. + Thrown on error. + + + + Open the current user key + + The opened key + Thrown on error. + + + + Open the current user key + + True to throw on error. + The opened key with the maximum access allowed. + Thrown on error. + + + + Open the root key + + The opened key + Thrown on error. + + + + Open the root key + + The opened key with the maximum access allowed. + True to throw on error. + Thrown on error. + + + + Create a new Key + + Path to the key to create + The opened key + Thrown on error. + + + + Create a new Key + + Path to the key to create + Desired access for the root key + Create options + The opened key + Thrown on error. + + + + Delete the key + + True to throw on error. + + + + Delete the key + + + + + Set a resistry value + + The name of the value + The type of the value + The raw value data + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a resistry value + + The name of the value + The type of the value + The raw value data + Thrown on error. + + + + Set a string resistry value + + The name of the value + The type of the value + The value data + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a string resistry value as REG_SZ. + + The name of the value + The value data + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a string resistry value + + The name of the value + The type of the value + The value data + Thrown on error. + + + + Set a string resistry value as REG_SZ. + + The name of the value + The value data + Thrown on error. + + + + Set a list of strings as a resistry value. + + The name of the value + The list of strings to set. + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a list of strings as a resistry value. + + The name of the value + The list of strings to set. + Thrown on error. + + + + Set a DWORD resistry value + + The name of the value + The value data + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a DWORD resistry value + + The name of the value + The value data + True to set the value of big endian. + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a QWORD resistry value + + The name of the value + The value data + True to throw on error. + Thrown on error. + The NT status code. + + + + Set a DWORD resistry value + + The name of the value + The value data + Thrown on error. + + + + Set a DWORD resistry value + + The name of the value + The value data + True to set the value of big endian. + Thrown on error. + + + + Set a QWORD resistry value + + The name of the value + The value data + Thrown on error. + + + + Delete a registry value + + The name of the value + True to throw on error. + Thrown on error. + The NT status code. + + + + Delete a registry value + + The name of the value + Thrown on error. + + + + Query a value by name + + The name of the value + True to throw on error + The value information + + + + Query a value by name + + The name of the value + The value information + Thrown on error. + + + + Query all values for this key + + A list of values + Thrown on error. + + + + Query all subkey entries. + + The list of subkey entries + Thrown on error. + + + + Query all subkey names + + The list of subkey names + Thrown on error. + + + + Return a list of subkeys which can be accessed. + + The required access rights for the subkeys + True to open link keys rather than following the link. + True to open keys with backup flag set. + The disposable list of subkeys. + + + + Return a list of subkeys which can be accessed. + + The required access rights for the subkeys + The disposable list of subkeys. + Thrown on error. + + + + Set a symbolic link target for this key (must have been created with + appropriate create flags) + + The symbolic link target. + True to throw on error. + The NT status code. + Thrown on error. + + + + Set a symbolic link target for this key (must have been created with + appropriate create flags) + + The symbolic link target. + + + + Get the symbolic link target for this key. + + True to throw on error. + The symbolic link target. + Thrown on error. + + + + Get the symbolic link target for this key. + + The symbolic link target. + Thrown on error. + + + + Open a key + + The path to the key to open + The opened key + Thrown on error. + + + + Open a key + + The path to the key to open + Access rights for the key + The opened key + Thrown on error. + + + + Open a key + + The path to the key to open + Access rights for the key + True to throw on error. + The opened key + Thrown on error. + + + + Open a key + + The path to the key to open + Access rights for the key + Key open options. + True to throw on error. + The opened key + Thrown on error. + + + + Reopen the key with different access rights. + + The access rights to reopen with. + Open options. + True to throw on error. + The opened key. + + + + Reopen the key with different access rights. + + The access rights to reopen with. + The object attributes to open with. + Open options. + True to throw on error. + The opened key. + + + + Reopen the key with different access rights. + + The access rights to reopen with. + Open options. + The opened key. + + + + Convert object to a .NET RegistryKey object + + The registry key object + + + + Rename key. + + The new name for the key. + True to throw on error. + The NT status code. + Thrown on error. + + + + Rename key. + + The new name for the key. + Thrown on error. + + + + Save the opened key into a file. + + The file to save to. + Save key flags + True to throw on error. + The NT status code. + Thrown on error. + + + + Save the opened key into a file. + + The file to save to. + Save key flags + + + + Save the opened key into a file. + + The file path to save to. + Save key flags + True to throw on error. + The NT status code. + Thrown on error. + + + + Save the opened key into a file. + + The file path to save to. + Save key flags + + + + Save the opened key into a file. + + The file path to save to. + + + + Restore key from a file. + + The file to restore from + Restore key flags + True to throw on error. + The NT status code. + Thrown on error. + + + + Restore key from a file. + + The file to restore from + Restore key flags + + + + Restore key from a file. + + The file path to restore from + Restore key flags + True to throw on error. + The NT status code. + Thrown on error. + + + + Restore key from a file. + + The file path to restore from + Restore key flags + + + + Restore key from a file. + + The file path to restore from + + + + Try and lock the registry key to prevent further modification. + + Note that this almost certainly never works from usermode, there's an explicit + check to prevent it in the kernel. + + + + Wait for a change on the registry key. + + Specify what changes will be notified. + True to watch the entire tree. + The status from the change notification. + Thrown on error. + + + + Wait for a change on thie registry key asynchronously. + + Specify what changes will be notified. + True to watch the entire tree. + The status from the change notification. + Thrown on error. + + + + Visit all accessible keys under this one. + + A function to be called on every accessible key. Return true to continue enumeration. + Specify the desired access for the keys. + True to recurse into sub keys. + Specify max recursive depth. -1 to not set a limit. + Open the key using backup privileges. + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + True to recurse into sub directories. + + + + Visit all accessible directories under this one. + + A function to be called on every accessible directory. Return true to continue enumeration. + Specify the desired access for the directory + True to recurse into sub directories. + Open the key using backup privileges. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Get key last write time + + The last write time + Thrown on error. + + + + Get key subkey count + + The subkey count + Thrown on error. + + + + Get key value count + + The key value count + Thrown on error. + + + + Get the key title index + + The key title index + Thrown on error. + + + + Get the key class name + + The key class name + Thrown on error. + + + + Get the maximum key value name length + + The maximum key value name length + Thrown on error. + + + + Get the maximum key value data length + + The maximum key value data length + Thrown on error. + + + + Get the maximum subkey name length + + The maximum subkey name length + Thrown on error. + + + + Get the maximum class name length + + The maximum class name length + Thrown on error. + + + + Get the key path as a Win32 style one. If not possible returns + the original path. + + + + + The disposition when the key was created. + + + + + Indicates the handle is a special pre-defined one by the kernel. + + + + + Get or set virtualization flags. + + + + + Get or set key control flags. + + + + + Get or set wow64 flags. + + + + + Get key flags. + + + + + Indicates if this key is from a trusted hive. + + + + + Indicates if this key is a symbolic link. + + + + + Indicates if this key is volatile. + + + + + Get the name from NtQueryKey. + + + + + Returns whether this object is a container. + + + + + A key entry. + + + + + The name of the key. + + + + + The last write time. + + + + + The key's title index. + + + + + Class to represent a loaded hive from the Hive List. + + + + + Path to the root key. + + + + + Path to the hive file. + + + + + Utilities for registry keys. + + + + + Convert a Win32 style keyname such as HKEY_LOCAL_MACHINE\Path into a native key path. + + The win32 style keyname to convert. + The converted keyname. + Thrown if invalid name. + + + + Attempt to convert an NT style registry key name to Win32 form. + If it's not possible to convert the function will return the + original form. + + The NT path to convert. + The converted path, or original if it can't be converted. + + + + Query list of loaded hives from the Registry. + + Convert the file path to a DOS path. + The list of loaded hives. + + + + Query list of loaded hives from the Registry. + + The list of loaded hives. + + + + Class representing a single Key value + + + + + Name of the value + + + + + Type of the value + + + + + Raw data for the value + + + + + Title index for the value + + + + + Get the value as an object. + + + + + Convert the value to a string + + The value as a string + + + + Convert value to an object + + The value as an object + + + + LDR static methods. + + + + + Get address of a procedure in a mapped image. + + The handle to the mapped image. + The name of the procedure to find. + True to throw on error. + The procedure address. + + + + Get address of a procedure in a mapped image. + + The handle to the mapped image. + The name of the procedure to find. + The procedure address. + + + + Class to access NT locale information + + + + + Get mapped NLS section + + The type of section + The codepage number + True to throw on error. + The mapped section if it exists. + + + + Get mapped NLS section + + The type of section + The codepage number + The mapped section if it exists. + + + + Get default locale ID + + True if the locale should be the thread's, otherwise the systems + True to throw on error. + The locale ID + + + + Get default locale ID + + True if the locale should be the thread's, otherwise the systems + The locale ID + + + + Set default locale + + True if the locale should be the thread's, otherwise the systems + True to throw on error. + The locale ID + The NT status code. + + + + Set default locale + + True if the locale should be the thread's, otherwise the systems + The locale ID + + + + Class representing a NT File Mailslot client object + + + + + Set the mailslot read timeout. + + The timeout to set. + True to throw on error. + The NT Status code. + + + + Peek on the current status of the Mailslot. + + True to throw on error. + The peek status. + + + + Peek on the current status of the Mailslot. + + The peek status. + + + + Get or set the Read Timeout. + + + + + Get maximum message size. + + + + + Get mailslot quota. + + + + + Get next message size. + + + + + Get messages available. + + + + + Class representing a mapped section + + + + + The process which the section is mapped into + + + + + The valid length of the mapped section from the current position. + + This doesn't take into account the possibility of fragmented commits. + + + + Get full path for mapped section. + + + + + Query the memory protection setting for this mapping. + + + + + Get image signing level. + + + + + Get the base address of the mapped section. + + + + + Release the internal handle + + + + + + Checks if this mapped view represents the same file. + + The address to check. + True to throw on error. + True if the mapped view represents the same file. + + + + Checks if this mapped view represents the same file. + + The address to check. + True if the mapped view represents the same file. + + + + Detaches the current buffer and allocates a new one. + + Specify a new length for the detached buffer. Must be <= Length. + The detached buffer. + The original buffer will become invalid after this call. + + + + Class representing a NT Mutant object + + + + + Create a new mutant + + The path to the mutant + The root object if path is relative + True to set current thread as initial owner + The opened mutant + Thrown on error + + + + Create a new mutant + + Object attributes + True to set current thread as initial owner + Desired access for mutant + The opened mutant + Thrown on error + + + + Create a new mutant + + Object attributes + True to set current thread as initial owner + Desired access for mutant + True to throw an exception on error. + The NT status code and object result. + + + + Open a mutant + + The path to the mutant + The root object if path is relative + Desired access for mutant + The opened mutant + Thrown on error + + + + Open a mutant + + The path to the mutant + The root object if path is relative + The opened mutant + Thrown on error + + + + Open a mutant + + Object attributes + Desired access for mutant + The opened mutant + Thrown on error + + + + Open a mutant + + Object attributes + Desired access for mutant + True to throw an exception on error. + The NT status code and object result. + + + + Release the mutant + + True to throw on error. + The previous release count + + + + Release the mutant + + The previous release count + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Get the owner of the mutant. + + + + + Get current count. + + + + + Get wether mutant owned by current thread. + + + + + Get whether mutant is abandoned. + + + + + Pipe attribute type. + + + + + The pipe attributes. + + + + + The pipe connect attributes. + + + + + The pipe handle attributes. + + + + + Class to add additional methods to a file for a named pipe. This is a base class for server and client types. + + + + + Get a named attribute from the pipe. + + The attribute type to query. + The name of the attribute. + True to throw on error. + The attribute value as a byte array. + Thrown on error. + + + + Set a named attribute for a pipe. + + The attribute type to set. + The name of the attribute. + The value to set. + True to throw on error. + The status code for the attribute. + Thrown on error. + + + + Set a named attribute for a pipe. + + The attribute type to set. + The name of the attribute. + The value to set. + Thrown on error. + + + + Set a named attribute for a pipe. + + The attribute type to set. + The name of the attribute. + The value to set. + True to throw on error. + The status code for the attribute. + Thrown on error. + + + + Set a named attribute for a pipe. + + The attribute type to set. + The name of the attribute. + The value to set. + Thrown on error. + + + + Set a named attribute for a pipe. + + The attribute type to set. + The name of the attribute. + The value to set. + True to throw on error. + The status code for the attribute. + Thrown on error. + + + + Set a named attribute for a pipe. + + The attribute type to set. + The name of the attribute. + The value to set. + Thrown on error. + + + + Get a named attribute from the pipe. + + The attribute type to query. + The name of the attribute. + The attribute value as a byte array. + Thrown on error. + + + + Get a named attribute from the pipe as an integer. + + The attribute type to query. + The name of the attribute. + True to throw on error. + The attribute value as an integer. + Thrown on error. + + + + Get a named attribute from the pipe as an integer. + + The attribute type to query. + The name of the attribute. + The attribute value as an integer. + Thrown on error. + + + + Get a named attribute from the pipe as an integer. + + The attribute type to query. + The name of the attribute. + True to throw on error. + The attribute value as an integer. + Thrown on error. + + + + Get a named attribute from the pipe as an integer. + + The attribute type to query. + The name of the attribute. + The attribute value as an integer. + Thrown on error. + + + + Send and receive a message in one call. + + The input buffer to send. + The maximum output size. + True to throw on error. + The received buffer. + + + + Send and receive a message in one call. + + The input buffer to send. + The maximum output size. + The received buffer. + + + + Send and receive a message in one call. + + The input buffer to send. + The maximum output size. + True to throw on error. + The received buffer. + + + + Send and receive a message in one call. + + The input buffer to send. + The maximum output size. + The received buffer. + + + + Set pipe information flags. + + The read mode to set. + The completion mode. + True to throw on error. + The NT status code. + + + + Set pipe information flags. + + The read mode to set. + The completion mode. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Pipe completion mode. + + + + + Pipe read mode. + + + + + Pipe type. + + + + + Pipe configuration. + + + + + Maximum instances of the pipe, -1 is unlimited. + + + + + Current pipe instances. + + + + + Inbound quota. + + + + + Available bytes to read. + + + + + Outbound quota. + + + + + Available outbound quota. + + + + + Connect state of the named pipe. + + + + + Type of pipe endpoint. + + + + + Class to add additional methods to a file for a named pipe server. + + + + + Listen for a new connection to this named pipe server. + + + + + Listen for a new connection to this named pipe server asynchronously. + + An optional cancellation token. + The async task to complete. + + + + Listen for a new connection to this named pipe server asynchronously. + + The async task to complete. + + + + Disconnect this named pipe server. + + + + + Disconnect this named pipe server asynchronously. + + An optional cancellation token. + The async task to complete. + + + + Disconnect this named pipe server asynchronously. + + The async task to complete. + + + + Impersonate the client of the named pipe. + + The impersonation context. Dispose to revert to self. + + + + Get client process ID. + + + + + Get client session ID. If this is 0 then the client is local, otherwise it's set by the SMB server. + + + + + Get client computer name. + + + + + Get the default named pipe ACL for the current caller. + + The default named pipe ACL. + + + + Class to add additional methods to a file for a named pipe client. + + + + + Disables impersonation on a named pipe. + + + + + Get server process ID. + + + + + Get client session ID. + + + + + A pair of named pipes. + + + + + Read pipe for the pair. + + + + + Write pipe for the pair. + + + + + Base class for all NtObject types we handle + + + + + Get the basic information for the object. + + The basic information + + + + Base constructor + + Handle to the object + + + + Duplicate the internal handle to a new handle. + + Attribute flags for new handle + The source handle to duplicate + The source process to duplicate from + The desination process for the handle + Duplicate handle options + The access rights for the new handle + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate the internal handle to a new handle. + + The source handle to duplicate + The desination process for the handle + Duplicate handle options + The access rights for the new handle + The duplicated handle. + + + + Duplicate a handle from the current process to a new handle with the same access rights. + + The source handle to duplicate + The desination process for the handle + The duplicated handle. + + + + Duplicate a handle from and to the current process to a new handle with the same access rights. + + The source handle to duplicate + The duplicated handle. + + + + Duplicate a handle from and to the current process to a new handle with the same access rights. + + The source handle to duplicate + True to throw on error. + The duplicated handle. + + + + Duplicate a handle from and to the current process to a new handle with new access rights. + + The source handle to duplicate + The access for the new handle. + The duplicated handle. + + + + Indicates whether a specific type of kernel object can be opened. + + The kernel typename to check. + True if this type of object can be opened. + + + + Open an NT object with a specified type. + + The type to open. If null the method will try and lookup the appropriate type. + Object attributes for object. + Generic access rights to the object. + True to throw on error. + The opened object. + Thrown if an error occurred opening the object. + + + + Open an NT object with a specified type. + + The name of the type to open (e.g. Event). If null the method will try and lookup the appropriate type. + The path to the object to open. + A root directory to open from. + Generic access rights to the object. + Attributes to open the object. + Security quality of service. + True to throw on error. + The opened object. + Thrown if an error occurred opening the object. + + + + Open an NT object with a specified type. + + The name of the type to open (e.g. Event). If null the method will try and lookup the appropriate type. + The path to the object to open. + A root directory to open from. + Generic access rights to the object. + Attributes to open the object. + Security quality of service. + The opened object. + Thrown if an error occurred opening the object. + + + + Open an NT object with a specified type. + + The name of the type to open (e.g. Event). If null the method will try and lookup the appropriate type. + The path to the object to open. + A root directory to open from. + Generic access rights to the object. + The opened object. + Thrown if an error occurred opening the object. + Thrown if type of resource couldn't be found. + + + + Close a handle in another process. + + The source handle to close. + The source process containing the handle to close. + True to throw an exception on error. + The NT status code. + + + + Close a handle in another process. + + The source handle to close. + The source process containing the handle to close. + + + + Close a handle in another process by PID. + + The source handle to close. + The source process ID containing the handle to close. + True to throw an exception on error. + The NT status code. + + + + Close a handle in another process by PID. + + The source handle to close. + The source process ID containing the handle to close. + + + + Close a handle. + + The handle to close. + The NT status code. + + + + Close a handle. + + The handle to close. + The NT status code. + + + + Duplicate a handle to a new handle, potentially in a different process. + + Attribute flags for new handle + The source handle to duplicate + The source process to duplicate from + The desination process for the handle + Duplicate handle options + The access rights for the new handle + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate a handle to a new handle, potentially in a different process. + + Attribute flags for new handle + The source handle to duplicate + The source process to duplicate from + The desination process for the handle + Duplicate handle options + The access rights for the new handle + The NT status code and object result. + + + + Duplicate object. + + Access rights to duplicate with. + Attribute flags. + Duplicate options + True to throw an exception on error. + The duplicated object. + + + + Duplicate object. + + Access rights to duplicate with. + Attribute flags. + Duplicate options + The duplicated object. + + + + Duplicate object with specific access rights. + + Access rights to duplicate with. + The duplicated object. + + + + Duplicate object with same access rights. + + The duplicated object. + + + + Duplicate the object handle as a WaitHandle. + + The wait handle. + + + + Check if access is granted to a set of rights + + The access rights to check + True if all the access rights are granted + + + + Get security descriptor as a byte array + + What parts of the security descriptor to retrieve + The security descriptor + + + + Get security descriptor as a byte array + + What parts of the security descriptor to retrieve + True to throw on error. + The NT status result and security descriptor. + + + + Get security descriptor as a byte array + + Returns an array of bytes for the security descriptor + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + The NT status result. + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + The NT status code. + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Get the security descriptor as an SDDL string + + The security descriptor as an SDDL string + + + + Make the object a temporary object + + True to throw on error. + The NT status code. + + + + Make the object a temporary object + + + + + Make the object a permanent object + + True to throw on error. + The NT status code. + + + + Make the object a permanent object + + + + + Wait on the object to become signaled + + True to make the wait alertable + The time out + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + Thrown on error + + + + Wait on the object to become signaled + + The time out + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + Thrown on error + + + + Wait on the object to become signaled + + True to make the wait alertable + The time out in seconds + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + Thrown on error + + + + Wait on the object to become signaled + + The time out in seconds + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + Thrown on error + + + + Wait on the object to become signaled for an infinite time. + + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + Thrown on error + + + + Wait on the object to become signaled. + + Timeout in seconds. + Cancellation token for wait. + A task to wait on. If result is true then event was signaled. + + + + Wait on the object to become signaled. + + Timeout in seconds. + A task to wait on. If result is true then event was signaled. + + + + Wait on the object to become signaled. + Will wait an infinite time. + + A task to wait on. + + + + Convert an enumerable access rights to a string + + True to try and convert to generic rights where possible. + The string format of the access rights + + + + Convert an enumerable access rights to a string + + The string format of the access rights + + + + Check if this object is exactly the same as another using NtCompareObject. + + The object to compare against. + True if this is the same object. + Thrown on error. + This is only supported on Windows 10 and above. For one which works on everything use SameObject. + + + + Check if this object is exactly the same as another. + + The object to compare against. + True if this is the same object. + Thrown on error. + This function can be slow to run and unreliable. Use CompareObject is Windows 10 or above. + + + + Convert to a string + + The string form of the object + + + + Get full path to the object + + + + + Get the granted access as an unsigned integer + + + + + Get the security descriptor, with Dacl, Owner, Group and Label + + + + + Get the security descriptor as an SDDL string + + The security descriptor as an SDDL string + + + + The low-level handle to the object. + + + + + Get the NT type name for this object. + + The NT type name. + + + + Get the NtType for this object. + + The NtType for the type name + + + + Get the name of the object + + + + + Indicates if the handle can be used for synchronization. + + + + + Get object creation time. + + + + + Get the attribute flags for the object. + + + + + Get number of handles for this object. + + + + + Get reference count for this object. + + + + + Get or set whether the handle is inheritable. + + + + + Get or set whether the handle is protected from closing. + + + + + Get the object's address is kernel memory. + + As getting the address is expensive you need to pass the object to NtSystemInfo::ResolveObjectAddress to intialize. + + + + Returns whether this object is a container. + + + + + Returns whether this object is closed. + + + + + Virtual Dispose method. + + True if disposing, false if finalizing + + + + Finalizer + + + + + Dispose + + + + + Close handle + + + + + Generic access rights. + + + + + Options for duplicating objects. + + + + + Close the original handle. + + + + + Duplicate with the same access. + + + + + Duplicate with the same handle attributes. + + + + + Prevent duplicating handle above the existing access. + + + + + Information class for NtQueryObject + + + + + + Structure to return Object Name + + + + + Structure to return Object basic information + + + + + Type of kernel pool used for object allocation + + + + + Native structure used for getting type information. + + + + + Static utility methods. + + + + + Convert the safe handle to an array of bytes. + + The data contained in the allocaiton. + + + + Convert an NtStatus to an exception if the status is an error + + The NtStatus + The original NtStatus if not an error + Thrown if status is an error. + + + + Convert an NtStatus to an exception if the status is an error and throw_on_error is true. + + The NtStatus + True to throw an exception onerror. + The original NtStatus if not thrown + Thrown if status is an error and throw_on_error is true. + + + + Checks if the NtStatus value is a success + + The NtStatus value + True if a success + + + + Checks if the NtStatus value is an error. + + The NtStatus value + True if an error. + + + + Get the severity of the NTSTATUS. + + The NtStatus value + The severity. + + + + Get the facility of the NTSTATUS. + + The NtStatus value + The facility. + + + + Get the status code of the NTSTATUS. + + The NtStatus value. + The static code. + + + + Is an NTSTATUS a customer code. + + The NtStatus value + True if is a customer code. + + + + Is an NTSTATUS reserved. + + The NtStatus value + True if reserved. + + + + Build a status from it's component parts. + + The severity of the status code. + Is this a customer code? + Is this a reserved code? + The facility. + The status code. + + + + + Convert an NTSTATUS to a message description. + + The status to convert. + The message description, or an empty string if not found. + + + + Convert an integer to an NtStatus code. + + The integer status. + The converted code. + + + + Convert an enumerable access rights to a string + + The granted access mask. + Generic mapping for object type. + Enum type to convert to string. + True to try and convert to generic rights where possible. + The string format of the access rights + + + + Convert an IEnumerable to a Disposable List. + + + + + + + + Run a function on an NtResult and dispose the result afterwards. + + The underlying result type. + The result of the function. + The result. + The function to call. + The default value to return if an error occurred. + The result of func. + If result is not a success then the function is not called. + + + + Run a function on an NtResult and dispose the result afterwards. + + The underlying result type. + The result of the function. + The result. + The function to call. + The result of func. + If result is not a success then the function is not called. + + + + Run an action on an NtResult and dispose the result afterwards. + + The underlying result type. + The result. + The action to call. + If result is not a success then the action is not called. + + + + Run a function on an NtResult and dispose the result afterwards. + + The underlying result type. + The result of the function. + The result. + The function to call. + The result of func. + + + + Run an action on an NtResult and dispose the result afterwards. + + The underlying result type. + The result. + The action to call. + + + + Convert a handle to a known object type. + + The handle. + The object type. + + + + Convert a handle to a known object type. + + The handle. + True to own the handle. + The object type. + + + + Convert a handle to a known object type. + + The handle. + True to own the handle. + The object type. + + + + Map a DOS error to an NT status code. + + The DOS error. + The NT status code. + + + + Map a status to a DOS error code. Takes into account NTWIN32 + status codes. + + The status code. + The mapped DOS error. + + + + Get the last NT status code in this thread set for Win32 last error. + + The last NT status code. + + + + Create an NT result object. If status is successful then call function otherwise use default value. + + The result type. + The associated status code. + Throw an exception on error. + Function to call to create an instance of the result + The created result. + + + + Create a successful NT result object. + + The result type. + The result value. + The created result. + + + + Create an NT result object. If status is successful then call function otherwise use default value. + + The result type. + The associated status code. + Throw an exception on error. + Function to call to create an instance of the result + Function to call on error. + The created result. + + + + Create an NT result object. If status is successful then call function otherwise use default value. + + The result type. + The associated status code. + Throw an exception on error. + Function to call to create an instance of the result + The created result. + + + + A derived class to add some useful functions such as Duplicate + + The derived type to use as return values + An enum which represents the access mask values for the type + + + + Reopen object with different access rights. + + The desired access. + Additional attributes for open. + True to throw on error. + The reopened object. + + + + Reopen object with different access rights. + + The desired access. + True to throw on error. + The reopened object. + + + + Reopen object with different access rights. + + The desired access. + The reopened object. + + + + Duplicate object. + + Access rights to duplicate with. + Attribute flags. + Duplicate options + True to throw an exception on error. + The duplicated object. + + + + Duplicate object. + + Access rights to duplicate with. + Attribute flags. + Duplicate options + True to throw an exception on error. + The duplicated object. + + + + Duplicate object. + + Access rights to duplicate with. + Attribute flags. + Duplicate options + The duplicated object. + + + + Duplicate the object with specific access rights + + The access rights for the new handle + The duplicated object + + + + Duplicate the object with specific access rights + + The access rights for the new handle + True to throw an exception on error. + The duplicated object + + + + Duplicate the object with same access rights + + The duplicated object + + + + Duplicate the object with same access rights + + True to throw on error. + The duplicated object + + + + Get granted access for handle. + + Granted access + + + + Get generic granted access for handle. + + Generic Granted access + + + + Get the maximum permission access for this object based on a token + and it's security descriptor. + + The token to check against. + Returns 0 if can't read the security descriptor. + + + + Get the maximum permission access for this object based on the current token + and its security descriptor. + + Returns 0 if can't read the security descriptor. + + + + Check if a specific set of access rights is granted + + The access rights to check + True if all access rights are granted + + + + Create a new instance from a kernel handle + + The kernel handle + The new typed instance + + + + Create a new instance from a kernel handle + + The kernel handle + True to own the handle. + The new typed instance + + + + Create a new instance from a kernel handle. + + The kernel handle + The call doesn't own the handle. The returned object can't be used to close the handle. + The new typed instance + + + + Duplicate an instance from a process + + The process (with DupHandle access) + The handle value to duplicate + The access rights to duplicate with + The options for duplication. + The attribute flags for the new object. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from a process + + The process (with DupHandle access) + The handle value to duplicate + The access rights to duplicate with + The options for duplication. + The attribute flags for the new object. + The NT status code and object result. + + + + Duplicate an instance from a process + + The process (with DupHandle access) + The handle value to duplicate + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from a process + + The process ID + The handle value to duplicate + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from a process with a specified access rights. + + The process (with DupHandle access) + The handle value to duplicate + The access rights to duplicate. + The duplicated handle + + + + Duplicate an instance from a process + + The process ID + The handle value to duplicate + The access rights to duplicate with + The duplicated handle + + + + Duplicate an instance from a process with same access rights. + + The process (with DupHandle access) + The handle value to duplicate + The duplicated object. + + + + Duplicate an instance from a process with same access rights + + The process ID + The handle value to duplicate + The duplicated handle + + + + Duplicate an instance from current process to an other process + + The destination process (with DupHandle access) + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from current process to an other process + + The destination process (with DupHandle access) + The handle value to duplicate + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from current process to an other process + + The destination process ID + The handle value to duplicate + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from current process to an other process with a specified access rights. + + The destination process (with DupHandle access) + The handle value to duplicate + The access rights to duplicate. + The duplicated handle + + + + Duplicate an instance from current process to an other process + + The destination process ID + The handle value to duplicate + The access rights to duplicate with + The duplicated handle + + + + Duplicate an instance from current process to an other process with same access rights. + + The destination process (with DupHandle access) + The handle value to duplicate + The duplicated object. + + + + Duplicate an instance from current process to an other process with same access rights. + + The destination process (with DupHandle access) + The duplicated object. + + + + Duplicate an instance from current process to an other process with same access rights + + The destination process ID + The handle value to duplicate + The duplicated handle + + + + Duplicate an instance from current process to an other process with same access rights + + The destination process ID + The duplicated handle + + + + Duplicate an instance from a process to an other process + + The source process (with DupHandle access) + The handle value to duplicate + The destination process (with DupHandle access) + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from a process to an other process + + The source process ID + The handle value to duplicate + The destination process ID + The access rights to duplicate with + The options for duplication. + True to throw an exception on error. + The NT status code and object result. + + + + Duplicate an instance from a process to an other process with a specified access rights. + + The source process (with DupHandle access) + The handle value to duplicate + The destination process (with DupHandle access) + The access rights to duplicate. + The duplicated handle + + + + Duplicate an instance from a process to an other process + + The source process ID + The handle value to duplicate + The destination process ID + The access rights to duplicate with + The duplicated handle + + + + Duplicate an instance from a process to an other process with same access rights. + + The source process (with DupHandle access) + The handle value to duplicate + The destination process (with DupHandle access) + The duplicated object. + + + + Duplicate an instance from a process to an other process with same access rights + + The source process ID + The handle value to duplicate + The destination process ID + The duplicated handle + + + + Interface to generically query an object. + + + + + Interface to generically set an object. + + + + + A derived class to add some useful functions such as Duplicate as well as generic Query and Set information methods. + + The derived type to use as return values + An enum which represents the access mask values for the type + An enum which represents the information class for query. + An enum which represents the information class for set. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + The result of the query. + Thrown on error. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + The result of the query. + Thrown on error. + + + + Query an enumerated value from the object. + + The type of enum to return. + The base type for the enumeration. + The information class to query. + The result of the query. + Thrown on error. + + + + Query an enumerated value from the object. + + The type of enum to return. + The information class to query. + The result of the query. + Thrown on error. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Query the information class as an object. + + The information class. + The information class as an object. + If the information class doesn't have an explicit object type a raw byte query will be made. + + + + Query a variable buffer from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The information class to query. + A buffer to initialize the initial query. Can be null. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The information class to query. + A buffer to initialize the initial query. Can be null. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The information class to query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object and return as bytes. + + The information class to query. + A buffer to initialize the initial query. Can be null. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object and return as bytes. + + The information class to query. + A buffer to initialize the initial query. Can be null. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object and return as bytes. + + The information class to query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The type of structure to return. + The information class to query. + The result of the query. + Thrown on error. + + + + Set a value to the object. + + The type of structure to set. + The information class to set. + The value to set. If you specify a SafeBuffer then it'll be passed directly. + True to throw on error. + The NT status code of the set. + Thrown on error. + + + + Set a value to the object. + + The type of structure to set. + The information class to set. + The value to set. + The NT status code of the set. + Thrown on error. + + + + Set a value to the object from a buffer. + + The information class to set. + The value to set. + True to throw on error. + The NT status code of the set. + Thrown on error. + + + + Set a value to the object from a buffer.. + + The information class to set. + The value to set. + The NT status code of the set. + Thrown on error. + + + + Set a raw value to the object. + + The information class to set. + The raw value to set. + True to throw on error. + The NT status code of the set. + Thrown on error. + + + + Set a raw value to the object. + + The information class to set. + The raw value to set. + The NT status code of the set. + Thrown on error. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Overriddable method to determine the maximum brute force length for query. + + Information class to key on if needs to return different sizes. + The maximum bytes to brute force. Returning 0 will disable brute force. + + + + Overridable method to determine if the return length shouldn't be trusted for this info class when querying a variable buffer. + + Information class to key on. + True to trust the return length when querying a variable buffer. + + + + Class representing a NT Partition object + + + + + Create a partition object + + The object attributes + Optional parent parition. + Desired access for the partition. + The preferred node, -1 for any node. + True to throw an exception on error. + The NT status code and object result. + + + + Create a partition object + + The object attributes + Optional parent parition. + Desired access for the partition. + The preferred node, -1 for any node. + The NT status code and object result. + + + + Open a partition object + + The object attributes + Desired access for the partition. + True to throw an exception on error. + The NT status code and object result. + + + + Open a partition object + + The object attributes + Desired access for the partition. + The NT status code and object result. + + + + Class representing a NT Process object. + + + + + Gets all accessible processes on the system. + + The access desired for each process. + The list of accessible processes. + + + + Gets all accessible processes on the system. + + The access desired for each process. + True to get processes from system information rather than NtGetNextProcess + The list of accessible processes. + + + + Gets all accessible processes on the system in a particular session. + + The session ID. + The access desired for each process. + The list of accessible processes. + + + + Gets all accessible processes on the system in the current session session. + + The access desired for each process. + The list of accessible processes. + + + + Get first accessible process (used in combination with GetNextProcess) + + The access required for the process. + The accessible process, or null if one couldn't be opened. + + + + Open a process + + The process ID to open + Optional thread ID to verify the correct process is opened. + The desired access for the handle + True to throw an exception on error. + The NT status code and object result. + + + + Open a process + + The process ID to open + The desired access for the handle + True to throw an exception on error. + The NT status code and object result. + + + + Open a process + + The process ID to open + The desired access for the handle + The opened process + + + + Open a process + + The process ID to open + Optional thread ID to verify the correct process is opened. + The desired access for the handle + The opened process. + + + + Create a new process + + Optional object attributes. + Desired access for the new process. + The parent process + Creation flags + Handle to the executable image section + Debug port for the new process. + Access token for the new process. + True to throw on error. + The created process + + + + Create a new process + + Desired access for the new process. + Optional object attributes. + The parent process + Creation flags + Handle to the executable image section + Debug port for the new process. + Access token for the new process. + The created process + + + + Create a new process + + The parent process + Creation flags + Handle to the executable image section + Access token for the new process. + The created process + + + + Create a new process + + The parent process + Creation flags + Handle to the executable image section + The created process + + + + Create a new process + + Handle to the executable image section + Access token for the new process. + The created process + + + + Create a new process + + Handle to the executable image section + The created process + + + + Create a new process + + Optional object attributes. + Desired access for the new process. + The parent process + Creation flags + Handle to the executable image section + Debug port for the new process. + Access token for the new process. + True to throw on error. + The created process + This uses NtCreateProcessEx rather than NtCreateUserProcess + + + + Create a new process + + Desired access for the new process. + Optional object attributes. + The parent process + Creation flags + Handle to the executable image section + Debug port for the new process. + Access token for the new process. + The created process + + + + Create a new user process. + + The process configuration. + True to throw on error. + The result of the process creation + + + + Create a new user process. + + The process configuration. + The result of the process creation + + + + Fork a process. + + The process configuration. + True to throw on error. + The new forked process result + This uses NtCreateUserProcess. + + + + Fork a process. + + The process configuration. + The new forked process result + This uses NtCreateUserProcess. + + + + Open an actual handle to the current process rather than the pseudo one used for Current + + The process object + + + + Test whether a process can access another protected process. + + The current process. + The target process. + True if the process can be accessed. + + + + Reopen object with different access rights. + + The desired access. + Additional attributes for open. + True to throw on error. + The reopened object. + + + + Get next accessible process (used in combination with GetFirstProcess) + + The access required for the process. + The accessible process, or null if one couldn't be opened. + + + + Get previous accessible process (used in combination with GetFirstProcess) + + The access required for the process. + The accessible process, or null if one couldn't be opened. + + + + Get previous accessible process (used in combination with GetFirstProcess) + + The accessible process, or null if one couldn't be opened. + + + + Get first accessible thread for process. + + The desired access for the thread. + The first thread object, or null if not accessible threads. + + + + Get first accessible thread for process. + + The first thread object, or null if not accessible threads. + + + + Get accessible threads for a process. + + The desired access for the threads + The list of threads + + + + Get accessible threads for a process. + + The list of threads + + + + Read a partial PEB from the process. + + The read PEB structure. + + + + Create a new process + + Creation flags + Handle to the executable image section + The created process + This uses NtCreateProcessEx rather than NtCreateUserProcess + + + + Create a new process + + Optional object attributes. + Desired access for the new process. + Creation flags + Handle to the executable image section + Debug port for the new process. + Access token for the new process. + True to throw on error. + The created process + This uses NtCreateProcessEx rather than NtCreateUserProcess + + + + Create a new process + + Optional object attributes. + Desired access for the new process. + Creation flags + Handle to the executable image section + Debug port for the new process. + Access token for the new process. + The created process + This uses NtCreateProcessEx rather than NtCreateUserProcess + + + + Terminate the process + + The exit code for the termination + + + + Terminate the process + + The exit code for the termination + + + + Terminate the process + + The exit code for the termination + True to throw on error. + The NT status code. + + + + Get process image file path + + True to return the native image path, false for a Win32 style path + True to throw on error. + The process image file path + + + + Get process image file path + + True to return the native image path, false for a Win32 style path + The process image file path + + + + Get a mitigation policy raw value + + The policy to get + True to throw on error. + The raw policy value + + + + Get a mitigation policy raw value + + The policy to get + The raw policy value + + + + Get a mitigation policy as an enumeration. + + The policy to get. + True to throw on error. + The mitigation policy value + + + + Get a mitigation policy as an enumeration. + + The policy to get. + The mitigation policy value + + + + Get a mitigation policy raw value + + The policy to get + True to throw on error. + The raw policy value + + + + Get a mitigation policy raw value + + The policy to get + The raw policy value + + + + Set a mitigation policy raw value + + The policy to set + The value to set + True to throw on error. + The NT status code. + + + + Set a mitigation policy raw value + + The policy to set + The value to set + + + + Set a mitigation policy value from an enum. + + The policy to set + The value to set + True to throw on error. + The NT status code. + + + + Set a mitigation policy value from an enum. + + The policy to set + The value to set + + + + Set a mitigation policy raw value + + The policy to set + The value to set + True to throw on error. + The NT status code. + + + + Set a mitigation policy raw value + + The policy to set + The value to set + + + + Disable dynamic code policy on another process. + + + + + Suspend the entire process. + + True to throw on error. + The NT status code. + + + + Resume the entire process. + + True to throw on error. + The NT status code. + + + + Suspend the entire process. + + + + + Resume the entire process. + + + + + Open the process' token + + The process token. + + + + Open the process' token + + True to throw on error. + The process token. + + + + Open the process' token + + Desired access for token. + True to throw on error. + The process token. + + + + Set process access token. Process must be have not been started. + + The token to set. + True to throw on error. + The NT status code. + + + + Set process access token. Process must be have not been started. + + The token to set. + + + + Read memory from a process. + + The base address in the process. + The length to read. + If true ensure we read all bytes, otherwise throw on exception. + The array of bytes read from the location. + If a read is short then returns fewer bytes than requested. + Thrown on error. + + + + Read memory from a process. + + The base address in the process. + The length to read. + The array of bytes read from the location. + If a read is short then returns fewer bytes than requested. + Thrown on error. + + + + Write memory to a process. + + The base address in the process. + The data to write. + The number of bytes written to the location + Thrown on error. + + + + Read structured memory from a process. + + The base address in the process. + The read structure. + Thrown on error. + Type of structure to read. + + + + Write structured memory to a process. + + The base address in the process. + The data to write. + Thrown on error. + Type of structure to write. + + + + Read structured memory array from a process. + + The base address in the process. + The number of elements in the array to read. + The read structure. + Thrown on error. + Type of structure to read. + + + + Write structured memory array to a process. + + The base address in the process. + The data array to write. + Thrown on error. + Type of structure to write. + + + + Query memory information for a process. + + The base address. + The queries memory information. + Thrown on error. + + + + Query all memory information regions in process memory. + + The list of memory regions. + Specify memory types to filter on. + Set of flags which indicate the memory states to return. + Thrown on error. + + + + Query all memory information regions in process memory. + + The list of memory regions. + True to include free regions of memory. + Specify memory types to filter on. + Thrown on error. + + + + Query all memory information regions in process memory. + + The list of memory regions. + True to include free regions of memory. + Thrown on error. + + + + Query all memory information regions in process memory excluding free regions. + + The list of memory regions. + Thrown on error. + + + + Query a list of mapped images in a process. + + The list of mapped images + Thrown on error. + + + + Query a list of mapped files in a process. + + The list of mapped images + Thrown on error. + + + + Query a list of all mapped files and images in a process. + + The list of mapped images + Thrown on error. + + + + Allocate virtual memory in a process. + + Optional base address, if 0 will automatically select a base. + The region size to allocate. + The type of allocation. + The allocation protection. + True to throw on error. + The address of the allocated region. + Thrown on error. + + + + Allocate virtual memory in a process. + + Optional base address, if 0 will automatically select a base. + The region size to allocate. + The type of allocation. + The allocation protection. + The address of the allocated region. + Thrown on error. + + + + Allocate read/write virtual memory in a process. + + The region size to allocate. + The address of the allocated region. + Thrown on error. + + + + Free virtual emmory in a process. + + Base address of region to free + The size of the region. + The type to free. + Thrown on error. + + + + Free virtual emmory in a process. + + Base address of region to free + The size of the region. + The type to free. + True to throw on error. + Thrown on error. + + + + Change protection on a region of memory. + + The base address + The size of the memory region. + The new protection type. + The old protection for the region. + Thrown on error. + + + + Change protection on a region of memory. + + The base address + The size of the memory region. + The new protection type. + True to throw on error. + The old protection for the region. + Thrown on error. + + + + Flush instruction cache. + + The address to flush. + The number of bytes to flush/ + True to throw on error. + The NT status code. + + + + Flush instruction cache. + + The address to flush. + The number of bytes to flush/ + + + + Query working set information for an address in a process. + + The base address to query. + True to throw on error + The working set information. + Thrown on error. + + + + Query working set information for an address in a process. + + The base address to query. + The working set information. + Thrown on error. + + + + Set the process device map. + + The device map directory to set. + Note that due to a bug in the Wow64 layer this won't work in a 32 bit process on a 64 bit system. + + + + Set the process device map. + + The device map directory to set. + True to throw on error. + Note that due to a bug in the Wow64 layer this won't work in a 32 bit process on a 64 bit system. + + + + Set the process device map. + + The device map directory to set. + Note that due to a bug in the Wow64 layer this won't work in a 32 bit process on a 64 bit system. + + + + Set the process device map. + + The device map directory to set. + True to throw on error. + Note that due to a bug in the Wow64 layer this won't work in a 32 bit process on a 64 bit system. + + + + Open a process' debug object. + + True to throw on error. + The process' debug object. + + + + Open a process' debug object. + + The process' debug object. + + + + Queries whether process is backed by a specific file. + + File object opened with Synchronize and Execute access to test against. + True if the process is created from the image file. + + + + Open parent process by ID. + + The desired process access rights. + True to throw on error. + The opened process. + Thrown on error. + + + + Open parent process by ID. + + The desired process access rights. + The opened process. + Thrown on error. + + + + Open parent process by ID. + + The opened process. + Thrown on error. + + + + Open owner process by ID. + + The desired process access rights. + True to throw on error. + The opened process. + Thrown on error. + + + + Open owner process by ID. + + The desired process access rights. + The opened process. + Thrown on error. + + + + Open owner process by ID. + + The opened process. + Thrown on error. + + + + Get if process is in a job. + + A specific job to check + True if in specific job. + + + + Get if process is in a job. + + True if in a job. + + + + Get process handle table. + + The list of process handles. + + + + Get handles for process. + + Specify to all name/details to be queried from the handle. + Force file query for name/details for non-filesystem handles. + True to throw on error. + The list of handles. + This queries the handles from the process which does not contain the Object's addres in kernel memory. + + + + Get handles for process. + + Specify to all name/details to be queried from the handle. + True to throw on error. + The list of handles. + This queries the handles from the process which does not contain the Object's addres in kernel memory. + + + + Get handles for process. + + Specify to all name/details to be queried from the handle. + The list of handles. + This queries the handles from the process which does not contain the Object's addres in kernel memory. + + + + Get handles for process. + + The list of handles. + This queries the handles from the process which does not contain the Object's addres in kernel memory. + + + + Get the process handle table and try and get them as objects. + + True to only return named objects + A list of typenames to filter on (if empty then return all) + The list of handles as objects. + This function will drop handles it can't duplicate. + + + + Get the process handle table and try and get them as objects. + + The list of handles as objects. + This function will drop handles it can't duplicate. + + + + Open image section for process. + + True to throw on error. + The opened image section. + Should only work on the pseudo process handle. + + + + Open image section for process. + + The opened image section. + Should only work on the pseudo process handle. + + + + Unmap a section. + + The base address to unmap. + Flags for unmapping memory. + True to throw on error. + The NT status code. + + + + Unmap a section. + + The base address to unmap. + True to throw on error. + The NT status code. + + + + Unmap a section. + + The base address to unmap. + Flags for unmapping memory. + + + + Unmap a section. + + The base address to unmap. + + + + Get the user SID for the process. + + True to throw on error. + The user SID. + + + + Get the user SID for the process. + + The user SID. + + + + Get the integrity level for the process. + + True to throw on error. + The integerity level. + + + + Set process fault flags. + + The flags to set. + True to throw on error. + The NT status code for the operation. + + + + Set process fault flags. + + The flags to set. + The NT status code for the operation. + + + + Set the process exception port. + + The exception port to set. + Additional state flags. + True to throw on error. + The NT status code. + + + + Set the process exception port. + + The exception port to set. + True to throw on error. + The NT status code. + + + + Set the process exception port. + + The exception port to set. + The NT status code. + + + + Get the user process parameters. + + The user process parameters. + + + + Fork the process. + + Extra flags for fork. + True to throw on error. + The new forked process result. + This uses NtCreateProcessEx. + + + + Fork the process. + + Extra flags for fork. + The new forked process result. + This uses NtCreateProcessEx. + + + + Fork the process. + + The new forked process result. + This uses NtCreateProcessEx. + + + + Get the accessible job objects this process is in. + + This tries to find accessible Job handles. There's no guarantee that all Job objects will be found for the process. + The list of job objects. + + + + Set thread intelligence logging flags. + + The flags to set. + True to throw on error. + The NT status code. + + + + Set thread intelligence logging flags. + + The flags to set. + + + + Get the process security domain. + + True to throw on error. + The security domain. + + + + Get the process security domain. + + The security domain. + + + + Combine two process' security domains. + + The process to combine with. Needs QueryLimitedInformation. + True to throw on error. + The NT status code. + The current process need SetLimitedInformation access. + + + + Combine two process' security domains. + + The process to combine with. Needs QueryLimitedInformation. + The current process need SetLimitedInformation access. + + + + Get the session ID for the process. + + True to throw on error. + The session ID. + + + + Test whether the current process can access another protected process. + + The target process. + True if the process can be accessed. + + + + Get the environment from the process. + + List of environment variables. + + + + Get an environment variable by name. + + The name of the variable. + The value of the environment variable. Returns null if it doesn't exist. + Only returns the first variable with a case insensitive name. + + + + Revoke file handles for an AppContainer process. + + The device path for the files to revoke. + True to throw on error. + The NT status code. + + + + Revoke file handles for an AppContainer process. + + The device path for the files to revoke. + + + + Get the process command line. + + True to throw on error. + The process command line. + + + + Get the IO counters for the process. + + True to throw on error. + The IO counters. + + + + Create a VBS enclave. + + Size of the enclave. + Flags for the enclave. + Owner ID. Must be 32 bytes. + True to throw on error. + The created enclave. + + + + Create a VBS enclave. + + Size of the enclave. + Flags for the enclave. + Owner ID. Must be 32 bytes. + The created enclave. + + + + Get priority boost disable value. + + True to throw on error. + True if priority base + + + + Set priority boost disable value. + + True to disable priority boost. + True to throw on error. + The NT status code. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get the process' session ID + + + + + Get the process' ID + + + + + Get the process' parent process ID + + + + + Get the memory address of the PEB + + + + + Get the memory address of the PEB for a 32 bit process. + + If the process is 64 bit, or the OS is 32 bit this returns the same value as PebAddress. + + + + Get the base address of the process from the PEB. + + + + + Read flags from PEB. + + + + + Get the process' exit status. + + + + + Get the process' exit status as an NtStatus code. + + + + + Get the process' command line + + + + + Get the command line as parsed arguments. + + + + + Get process DEP status + + + + + Get whether process has a debug port. + + + + + + Get handle count. + + + + + Get break on termination flag. + + + + + Get or set debug flags. + + + + + Get or set execute flags. + + + + + Get IO priority. + + + + + Get secure cookie. + + + + + Get the process user. + + + + + Get the integrity level of the process. + + + + + Get process mitigations + + + + + Get extended process flags. + + + + + Get process window title (from Process Parameters). + + + + + Get process window flags (from Process Parameters). + + + + + Get the process subsystem type. + + + + + Get if the process is Wow64 + + + + + Get whether the process is 64bit. + + + + + Get whether LUID device maps are enabled. + + + + + Return whether this process is sandboxed. + + + + + Get or set the hard error mode. + + + + + Does the process has a child process restriction? + + + + + Gets whether the process is currently deleting. + + + + + Gets whether the process is secure. + + + + + Gets whether the process is protected. + + + + + Gets whether the process is a subsystem process. + + + + + Gets whether the process is frozen. + + + + + Get process protection information. + + + + + Query process section image information. + + + + + Get full image path name in native format + + + + + Get the Win32 image path. + + + + + Get owner process ID + + + + + Query the process token's full package name. + + + + + Get or set whether resource virtualization is enabled. + + + + + Get the security domain of the process. + + + + + Get the creation time of the process. + + + + + Get the exit time of the process. + + + + + Get the time spent in the kernel. + + + + + Get the time spent in user mode. + + + + + Get the time spent in the kernel in seconds. + + + + + Get the time spent in user mode. + + + + + Get the process IO counters. + + + + + Get or set priority boost disabled. + + + + + Get the current process. + + This only uses the pseudo handle, for the process. If you need a proper handle use OpenCurrent. + + + + Get the current PEB address. + + + + + Configuration for a new NT Process. + + + + + Path to the executable to start. + + + + + Path to the executable to start which is passed in the process configuration. + + This doesn't have to match ImagePath. + + + + Command line + + + + + Prepared environment block. + + + + + Title of the main window. + + + + + Path to DLLs. + + + + + Current directory for new process + + + + + Desktop information value + + + + + Shell information value + + + + + Runtime data. + + + + + Prohibited image characteristics for new process + + + + + Additional file access for opened executable file. + + + + + Process create flags. + + + + + Thread create flags. + + + + + Initialization flags + + + + + Parent process. + + + + + Specify child process mitigations. + + + + + Whether to terminate the process on dispose. + + + + + Specify a security descriptor for the process. + + + + + Specify a security descriptor for the initial thread. + + + + + Specify the primary token for the new process. + + + + + Access for process handle. + + + + + Access for thread handle. + + + + + Set protection level. + + + + + Set to create a trustlet. + + + + + Set to specify the configuration for the trustlet if Secure is set. + + + + + Capture additional information when NtProcess.Create returns. + + + + + Specify callback to update process parameters. + + + + + Redirection DLL path. Only supported from 1903. + + + + + Inheritable handles. + + + + + Debug object. + + + + + Toggle inherit handles process create flag. + + + + + Add an extra process/thread attribute. + + The process attribute to add. + The caller is responsible for disposing the attribute, this class does not hold a reference. + + + + Set protected process protection level. + + The type of protected process. + The signer level. + + + + Constructor + + + + + Result from creating a user process. + + + + + Handle to the process + + + + + Handle to the initial thread + + + + + Handle to the image file + + + + + Handle to the image section + + + + + Handle to the IFEO key (if it exists) + + + + + Image information + + + + + Client ID of process and thread + + + + + Process ID + + + + + Thread ID + + + + + Create status. + + + + + True if create succeeded. + + + + + DLL characterists if CreateState is FailMachineMismatch. + + + + + Creation state + + + + + Output flags if CreateStatus is Success. + + + + + Native user process parameters pointer if CreateStatus is Success. + + + + + Wow64 user process parameters pointer if CreateStatus is Success. + + + + + Current parameter flags if CreateStatus is Success. + + + + + PEB pointer if CreateStatus is Success. + + + + + Wow64 PEB pointer if CreateStatus is Success. + + + + + Manifest pointer if CreateStatus is Success. + + + + + Manifest size if CreateStatus is Success. + + + + + Set to true to terminate process on disposal + + + + + Terminate the process + + Exit code for termination + + + + Resume initial thread + + The suspend count + + + + Explicit conversion operator to an NtThread object. + + The win32 process + + + + Explicit conversion operator to an NtProcess object. + + The win32 process + + + + Dispose + + + + + Entry for a process environment block. + + + + + Name of the environment variable. + + + + + Value of the environment variable. + + + + + Constructor. + + Name of the environment variable. + Value of the environment variable. + + + + Class representing various process mitigations + + + + + Partial definition of the PEB + + + + + Partial definition of the PEB + + + + + Class which represents the configuration for a trustlet. + + + + + The ID of the trustlet. + + + + + The mailbox key. Must be 2 longs. + + + + + The collaboration ID. Must be 2 longs. + + + + + The VM ID. Must be 2 longs. + + + + + The TK sessio ID. Must be 4 longs. + + + + + Overridden ToString method. + + The object as a string. + + + + Create a trustlet configuration from an image file. + + The path to the image file. Should be a native path. + True to throw on error. + The trustlet configuration. + + + + Create a trustlet configuration from an image file. + + The path to the image file. Should be a win32 path. + The trustlet configuration. + + + + Constructor + + + + + Constructor + + The ID of the trustlet. + + + + Class to represent a registry transaction object + + + + + Create a transaction + + The object attributes + Desired access for the handle + True to throw an exception on error. + The NT status code and object result. + + + + Create a transaction + + The object attributes + Desired access for the handle + The opened transaction + + + + Create a transaction + + The path of the transaction + The root if path is relative + The opened transaction + + + + Create a transaction + + The path of the transaction + The opened transaction + + + + Create a transaction + + The opened transaction + + + + Open a transaction object. + + The path to the object + The root if path is relative + The desired access for the object + The opened object + + + + Open a transaction object. + + The object attributes for the object + The desired access for the object + True to throw an exception on error. + The NT status code and object result. + + + + Open a transaction object. + + The object attributes for the object + The desired access for the object + The opened object + + + + Open a transaction object. + + The path to the object + The opened object + + + + Commit the transaction + + + + + Rollback the transaction + + + + + Enable the transaction for anything in the current thread context. + + The transaction context. This should be disposed to disable the transaction. + + + + Class to represent a transaction resource manager. + + + + + Create a new resource manager object. + + The object attributes + Desired access for the handle + Creation options flags. + Optional transaction manager to assign the resource manager to. + Resource manager GUID. + Optional description. + True to throw an exception on error. + The NT status code and object result. + + + + Create a new resource manager object. + + The object attributes + Desired access for the handle + Creation options flags. + Optional transaction manager to assign the resource manager to. + Resource manager GUID. + Optional description. + The object result. + Thrown on error. + + + + Create a new resource manager object. + + The path to the resource manager. + The root if path is relative. + Desired access for the handle + Creation options flags. + Optional transaction manager to assign the resource manager to. + Resource manager GUID. + Optional description. + True to throw an exception on error. + The NT status code and object result. + + + + Create a new resource manager object. + + The path to the resource manager. + The root if path is relative. + Desired access for the handle + Creation options flags. + Optional transaction manager to assign the resource manager to. + Resource manager GUID. + Optional description. + The object result. + Thrown on error. + + + + Create a new volatile resource manager object. + + The path to the resource manager. + The root if path is relative. + Desired access for the handle + Optional transaction manager to assign the resource manager to. + Resource manager GUID. + The object result. + Thrown on error. + + + + Create a new volatile resource manager object. + + The path to the resource manager. + The root if path is relative. + Desired access for the handle + Optional transaction manager to assign the resource manager to. + The object result. + Thrown on error. + + + + Create a new volatile resource manager object. + + The path to the resource manager. + The root if path is relative. + Optional transaction manager to assign the resource manager to. + The object result. + Thrown on error. + + + + Create a new volatile resource manager object. + + The path to the resource manager. + Optional transaction manager to assign the resource manager to. + The object result. + Thrown on error. + + + + Create a new volatile resource manager object. + + Optional transaction manager to assign the resource manager to. + The object result. + Thrown on error. + + + + Opens an existing resource manager object. + + The object attributes + Desired access for the handle + Transaction manager which contains the resource manager. + Resource manager GUID. + True to throw an exception on error. + The NT status code and object result. + + + + Opens an existing resource manager object. + + The object attributes + Desired access for the handle + Transaction manager which contains the resource manager. + Resource manager GUID. + The object result. + Thrown on error. + + + + Recover the the transaction manager. + + True to throw on error. + The NT status code. + + + + Recover the the transaction manager. + + + + + Set an IO completion port on the resource manager. + + The IO completion port. + Associated completion key. + True to throw on error. + The NT status code. + + + + Set an IO completion port on the resource manager. + + The IO completion port. + Associated completion key. + + + + Get a notification synchronously. + + Optional timeout for getting the notification. + True to throw on error. + The transaction notification. + + + + Get a notification synchronously. + + Optional timeout for getting the notification. + The transaction notification. + + + + Get a notification synchronously waiting indefinetly. + + The transaction notification. + + + + Register protocol information. + + The ID of the protocol to register. + An opaque protocol buffer. + Optional create options. + True to throw on error. + The NT status code. + + + + Register protocol information. + + The ID of the protocol to register. + An opaque protocol buffer. + Optional create options. + + + + Complete propagation request. + + The cookie to identify the request. + An optional buffer to pass with the request. + True to throw on error. + The NT status code. + + + + Complete propagation request. + + The cookie to identify the request. + An optional buffer to pass with the request. + + + + Fail propagation request. + + The cookie to identify the request. + Optional NT status code for the failure. + True to throw on error. + The NT status code. + + + + Get a list of all accessible enlistment objects owned by this resource manager. + + The object attributes + The access for the enlistment objects. + The list of all accessible enlistment objects. + + + + Get a list of all accessible enlistment objects owned by this resource manager. + + The access for the enlistment objects. + The list of all accessible enlistment objects. + + + + Get a list of all accessible resource manager objects owned by this transaction manager. + + The list of all accessible resource manager objects. + + + + Create an enlistment in this resource manager. + + Desired access for the handle + The transaction to enlist. + Optional create options. + Notification mask. + Enlistment key returned during notification. + True to throw an exception on error. + The created enlistment and NT status code. + + + + Create an enlistment in this resource manager. + + Desired access for the handle + The transaction to enlist. + Optional create options. + Notification mask. + Enlistment key returned during notification. + The created enlistment. + + + + Create an enlistment in this resource manager. + + The transaction to enlist. + Notification mask. + Enlistment key returned during notification. + The created enlistment. + + + + Create an enlistment in this resource manager. + + The transaction to enlist. + Enlistment key returned during notification. + The created enlistment. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get the resource manager ID. + + + + + Get the description for the resource manager. + + + + + A structure to return the result of an NT system call with status. + This allows a function to return both a status code and a result + without having to resort to out parameters. + + The result type. + + + + The NT status code. + + + + + The result of the NT call. + + + + + Get the result object or throw an exception if status code is an error. + + The result NT result. + Thrown if status code is an error. + + + + Get the result object or a default value if an error occurred. + + The default value to return. + The result or the default if an error occurred. + + + + Get the result object or a default value if an error occurred. + + The result or the default if an error occurred. + + + + Is the result successful. + + + + + Map result to a different type. + + The different type to map to. + A function to map the result. + The mapped result. + + + + Map result to a different type. + + The different type to map to. + A function to map the result. + The mapped result. + + + + Cast result to a different type. + + The different type to cast to. + The mapped result. + + + + Forward the result and check for an exception. + + True to throw on error. + The forwarded result. + + + + Dispose result. + + + + + Create a result from an error. + + The error status code. + True to throw on error. + The result. + + + + Create a result. + + + Create a new result. + + + + Conversion operator from T to object. + + The result to convert. + + + + Compression format for RtlDecompressBuffer. + + + + + Class to represent a NT Section object + + + + + Create an Image section object + + The object attributes for the image section. + The file to create the image section from + The opened section + Thrown on error. + + + + Create an Image section object + + The object name to use for the image section. + Root directory for the object. + The file to create the image section from + The opened section + Thrown on error. + + + + Create an Image section object + + The object name to use for the image section. + The file to create the image section from + The opened section + Thrown on error. + + + + Create an Image section object + + The file to create the image section from + The opened section + Thrown on error. + + + + Create a data section from a file. + + The file to create from. + The created section object. + + + + Create a section object + + The object attributes + The desired access + Optional size of the section + The section protection + The section attributes. The lower 5 bits can be used to specify the NUMA node. + Optional backing file + True to throw an exception on error. + The NT status code and object result. + + + + Create a section object + + The object attributes + The desired access + Optional size of the section + The section protection + The section attributes + Optional backing file + The opened section + Thrown on error. + + + + Create a section object + + The path to the section + The root if path is relative + The desired access + Optional size of the section + The section protection + The section attributes. The lower 5 bits can be used to specify the NUMA node. + Optional backing file + The opened section + Thrown on error. + + + + Create a section object + + Size of the section + The opened section + Thrown on error. + + + + Create a section object + + The object attributes + The desired access + Optional size of the section + The section protection + The section attributes + Optional backing file + Extended parameters for section create. + True to throw an exception on error. + The NT status code and object result. + + + + Create a section object + + The object attributes + The desired access + Optional size of the section + The section protection + The section attributes + Optional backing file + Extended parameters for section create. + The NT status code and object result. + + + + Open a section object + + The object attributes for the section + The desired access for the sections + True to throw an exception on error. + The NT status code and object result. + + + + Open a section object + + The object attributes for the section + The desired access for the sections + The opened section + + + + Open a section object + + The path to the section + Root object if the path is relative + The desired access for the sections + The opened section + + + + Unmap a section in a specified process. + + The process to unmap the section. + The base address to unmap. + Flags for unmapping memory. + True to throw on error. + The NT status code. + + + + Unmap a section in a specified process. + + The process to unmap the section. + The base address to unmap. + True to throw on error. + The NT status code. + + + + Unmap a section in the current process. + + The base address to unmap. + True to throw on error. + The NT status code. + + + + Unmap a section in a specified process. + + The process to unmap the section. + The base address to unmap. + Flags for unmapping memory. + + + + Unmap a section in a specified process. + + The process to unmap the section. + The base address to unmap. + + + + Unmap a section in the current process. + + The base address to unmap. + + + + Map section Read/Write into a specific process + + The process to map into + The mapped section + + + + Map section Read Only into a specific process + + The process to map into + The mapped section + + + + Map section Read/Write into a specific process + + The process to map into + True to throw on error. + The mapped section + + + + Map section Read Only into a specific process + + The process to map into + True to throw on error. + The mapped section + + + + Map section Read Only into a current process + + The mapped section + + + + Map section Read Only into a current process + + True to throw on error. + The mapped section + + + + Map section Read/Write into a current process + + The mapped section + + + + Map section Read/Write into a current process + + True to throw on error. + The mapped section + + + + Map section into a specific process + + The process to map into + The protection of the mapping + The mapped section + + + + Map section into a specific process + + The process to map into + The protection of the mapping + True to throw on error. + The mapped section + + + + Map section into a specific process + + The process to map into + The protection of the mapping + Optional base address + Number of zero bits. + Size of pages to commit. + Offset into the section. + Optional view size + Allocation type. + Section inheritance type. + True to throw on error. + The mapped section + + + + Map section into a specific process + + The process to map into + The protection of the mapping + Optional base address + Number of zero bits. + Size of pages to commit. + Offset into the section. + Optional view size + Allocation type. + Section inheritance type. + The mapped section + + + + Map section into a specific process + + The process to map into + The protection of the mapping + Optional base address + Optional view size + The mapped section + + + + Map section into a specific process + + The process to map into + The protection of the mapping + Optional base address + Optional view size + True to throw on error. + The mapped section + + + + Map section into the current process + + The protection of the mapping + The mapped section + + + + Extend the section to a new size. + + The new size to extend to. + True to throw on error. + The new size. + Thrown on error. + + + + Extend the section to a new size. + + The new size to extend to. + The new size. + Thrown on error. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Get the size of the section + + + + + Get the attributes of the section + + + + + Get section image information. + + + + + Get original section base address. + + + + + Get relocation address. + + + + + Static class to access NT security manager routines. + + + + + Looks up the account name of a SID. + + The system name to lookup the SID on. + The SID to lookup + True to throw on error. + The name. + + + + Looks up the account name of a SID. + + The SID to lookup + True to throw on error. + The name. + + + + Looks up the account name of a SID. + + The SID to lookup + The SID name. + Thrown if lookup fails. + + + + Looks up the account name of a SID. + + The SID to lookup + True to throw on error. + The name. + + + + Looks up the account name of a SID. + + The SID to lookup + The name, or null if the lookup failed + + + + Looks up a capability SID to see if it's already known. + + The capability SID to lookup + The name of the capability, null if not found. + + + + Lookup a SID from a username. + + The system name to lookup the SID on. + The username, can be in the form domain\account. + True to throw on error. + The Security Identifier + Thrown if account cannot be found. + + + + Lookup a SID from a username. + + The system name to lookup the SID on. + The username, can be in the form domain\account. + The Security Identifier + Thrown if account cannot be found. + + + + Lookup a SID from a username. + + The username, can be in the form domain\account. + The Security Identifier + Thrown if account cannot be found. + + + + Lookup the name of a process trust SID. + + The trust sid to lookup. + The name of the trust sid. null if not found. + Thrown if trust_sid is not a trust sid. + + + + Try and lookup the moniker associated with a package sid. + + The package sid. + Returns the moniker name. If not found returns null. + Thrown if SID is not a package sid. + + + + Lookup a device capability SID name if known. + + The SID to lookup. + Returns the device capability name. If not found returns null. + Thrown if SID is not a package sid. + + + + Convert a package SID to a capability. + + The package SID to convert. + The package SID as a capability. + + + + Convert a security descriptor to SDDL string + + The security descriptor + Indicates what parts of the security descriptor to include + The SDDL string + Thrown if cannot convert to a SDDL string. + + + + Convert a security descriptor to SDDL string + + The security descriptor + Indicates what parts of the security descriptor to include + True to throw on errror. + The SDDL string + Thrown if cannot convert to a SDDL string. + + + + Convert an SDDL string to a binary security descriptor + + The SDDL string + True to throw on error. + The binary security descriptor + Thrown if cannot convert from a SDDL string. + + + + Convert an SDDL string to a binary security descriptor + + The SDDL string + The binary security descriptor + Thrown if cannot convert from a SDDL string. + + + + Convert an SDDL string to a binary security descriptor + + The SDDL string + True to throw on error. + The binary security descriptor + Thrown if cannot convert from a SDDL string. + + + + Convert an SDDL string to a binary security descriptor + + The SDDL string + The binary security descriptor + Thrown if cannot convert from a SDDL string. + + + + Convert an SDDL SID string to a Sid + + The SDDL SID string + True to throw on error. + The converted Sid + Thrown if cannot convert from a SDDL string. + + + + Convert an SDDL SID string to a Sid + + The SDDL SID string + The converted Sid + Thrown if cannot convert from a SDDL string. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + This function returns a list of results rather than a single entry. It should only be used + with object types. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + True to throw on error. + The list of access check results. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + This function returns a list of results rather than a single entry. It should only be used + with object types. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + The list of access check results. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + True to throw on error. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + True to throw on error. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + True to throw on error. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + True to throw on error. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + The allowed access mask as a unsigned integer. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + The type specific generic mapping (get from corresponding NtType entry). + The allowed access mask as a unsigned integer. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the maximum allowed access. + + The security descriptor + The access token. + The type specific generic mapping (get from corresponding NtType entry). + The maximum allowed access mask as a unsigned integer. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the maximum allowed access. + + The security descriptor + The access token. + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + The maximum allowed access mask as a unsigned integer. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access. + + The security descriptor + The access token. + The set of access rights to check against + The type used to determine generic access mapping.. + The allowed access mask as a unsigned integer. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the maximum allowed access. + + The security descriptor + The access token. + The type used to determine generic access mapping.. + The allowed access mask as a unsigned integer. + Thrown if an error occurred in the access check. + + + + Get a security descriptor from a named object. + + The path to the resource (such as \BaseNamedObejct\ABC) + The type of resource, can be null to get the method to try and discover the correct type. + The named resource security descriptor. Returns null if can't open the resource. + + + + Do an access check between a security descriptor and a token to determine the allowed access and + audit the result. + + The name of the subsystem to audit. + The handle ID to audit. Used when issuing a close audit. + The object type name. + The name of the object. + Indicates if this is an object creation operation. + Type of audit. + Flags for the audit operation. + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + True to throw on error. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access and + audit the result. + + The name of the subsystem to audit. + The handle ID to audit. Used when issuing a close audit. + The object type name. + The name of the object. + Indicates if this is an object creation operation. + Type of audit. + Flags for the audit operation. + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access + and audit. This function returns a list of results rather than a single entry. It should only + be used with object types. + + The name of the subsystem to audit. + The handle ID to audit. Used when issuing a close audit. + The object type name. + The name of the object. + Indicates if this is an object creation operation. + Type of audit. + Flags for the audit operation. + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + True to throw on error. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Do an access check between a security descriptor and a token to determine the allowed access + and audit. This function returns a list of results rather than a single entry. It should only + be used with object types. + + The name of the subsystem to audit. + The handle ID to audit. Used when issuing a close audit. + The object type name. + The name of the object. + Indicates if this is an object creation operation. + Type of audit. + Flags for the audit operation. + The security descriptor + The access token. + The set of access rights to check against + An optional principal SID used to replace the SELF SID in a security descriptor. + The type specific generic mapping (get from corresponding NtType entry). + List of object types to check against. + The result of the access check. + Thrown if an error occurred in the access check. + + + + Get a SID for a specific mandatory integrity level. + + The mandatory integrity level. + The integrity SID + + + + Get a SID for a specific mandatory integrity level. + + The mandatory integrity level. + The integrity SID + + + + Checks if a SID is an integrity level SID + + The SID to check + True if an integrity SID + + + + Get the integrity level from an integrity SID + + The integrity SID + The token integrity level. + + + + Gets the SID for a service name. + + The service name. + The service SID. + Thrown on error. + + + + Checks if a SID is a service SID. + + The sid to check. + True if a service sid. + + + + Checks if a SID is a logon session SID. + + The sid to check. + True if a logon session sid. + + + + Checks if a SID is a process trust SID. + + The sid to check. + True if a process trust sid. + + + + Checks if a SID is a domain SID. + + The SID to check. + True if a domain SID. + + + + Checks if a SID is a domain SID and is a member of the local machine domain. + + The SID to check. + True if a domain SID. + + + + Checks if a SID is a capability SID. + + The sid to check. + True if a capability sid. + + + + Checks if a SID is a capbility group SID. + + The sid to check. + True if a capability group sid. + + + + Get a capability sid by name. + + The name of the capability. + True to throw on error. + The capability SID. + + + + Get a capability sid by name. + + The name of the capability. + The capability SID. + + + + Get a capability group sid by name. + + The name of the capability. + True to throw on error. + The capability SID. + + + + Get a capability group sid by name. + + The name of the capability. + The capability SID. + + + + Get the type of package sid. + + The sid to get type. + The package sid type, Unknown if invalid. + + + + Checks if a SID is a valid package SID. + + The sid to check. + True if a capability sid. + + + + Get the parent package SID for a child package SID. + + The child package SID. + The parent package SID. + Thrown if sid not a child package SID. + + + + Checks if a SID is a Scoped Policy ID SID. + + The SID to check. + True if a Scoped Policy ID SID. + + + + Converts conditional ACE data to an SDDL string + + The conditional application data. + True to throw on error. + The conditional ACE string. + + + + Converts conditional ACE data to an SDDL string + + The conditional application data. + The conditional ACE string. + + + + Converts a condition in SDDL format to an ACE application data. + + The condition in SDDL format. + The condition in ACE application data format. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in SDDL format. + Specify resource attributes to add to the check. + True to throw on error. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in SDDL format. + True to throw on error. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in SDDL format. + Specify resource attributes to add to the check. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in SDDL format. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in binary format. + Specify resource attributes to add to the check. + True to throw on error. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in binary format. + True to throw on error. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in binary format. + Specify resource attributes to add to the check. + True if the conditional expression was a success. + + + + Evaluate a condition ACE expression. + + The Token to check against. + The conditional expression in binary format. + True if the conditional expression was a success. + + + + Get the cached signing level for a file. + + The handle to the file to query. + The cached signing level. + + + + Get the cached signing level for a file. + + The handle to the file to query. + True to throw on error. + The cached signing level. + + + + Get the cached singing level from the raw EA buffer. + + The EA buffer to read the cached signing level from. + The cached signing level. + Throw on error. + + + + Set the cached signing level for a file. + + The handle to the file to set the cache on. + Flags to set for the cache. + The signing level to cache + A list of source file for the cache. + Optional directory path to look for catalog files. + + + + Set the cached signing level for a file. + + The handle to the file to set the cache on. + Flags to set for the cache. + The signing level to cache + A list of source file for the cache. + Optional directory path to look for catalog files. + True to throw on error. + + + + Compare two signing levels. + + The current level. + The signing level to compare against. + True if the current level is above or equal to the signing level. + + + + Get readable name for a SID, if known. This covers sources of names such as LSASS lookup, capability names and package names. + + The SID to lookup. + True to bypass the internal cache and get the current name. + The name for the SID. Returns the SDDL form if no other name is known. + + + + Get readable name for a SID, if known. This covers sources of names such as LSASS lookup, capability names and package names. + + The SID to lookup. + The name for the SID. Returns the SDDL form if no other name is known. + This function will cache name lookups, this means the name might not reflect what's currently in LSASS if it's been changed. + + + + Add a SID name to the local name cache. + + The SID to add. + The SID's domain name. + The name of the account. + The name user value. + + + + Remove a SID name from the local cache. + + The SID to remove. + + + + Clear the SID name cache. + + + + + Get a logon session SID from an ID. + + The logon session ID. + The new logon session SID. + + + + Get a new logon session SID. + + The new logon session SID. + + + + Get session id from logon session SID. + + The logon session SID. + The logon session ID. + + + + Get security descriptor as a byte array + + Handle to the object to query. + What parts of the security descriptor to retrieve + True to throw on error. + The NT status result and security descriptor as a buffer. + + + + Set the object's security descriptor + + Handle to the object to set. + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + The NT status result. + + + + Do a privilege check on a token. + + A handle to a token object. + The list of privileges to check. + True to require all necessary privileges. + True to throw on error. + The privilege check result. + + + + Get the access mask for querying a specific security information class. + + The information class. + The access mask for the information. + + + + Get the access mask for setting a specific security information class. + + The information class. + The access mask for the information. + + + + Get whether an ACE type is an allowed ACE type. + + The ACE type. + True if an allowed ACE type. + + + + Get whether an ACE type is a denied ACE type. + + The ACE type. + True if a denied ACE type. + + + + Get whether an ACE type is an object ACE type. + + The ACE type. + True if an object ACE type. + + + + Get whether an ACE type is an audit ACE type. + + The ACE type. + True if an audit ACE type. + + + + Get whether an ACE type is used int the SACL. + + The ACE type. + True if a system ACE type. + + + + Get whether an ACE type is a callback type. + + The ACE type. + True if a callback type. + + + + Convert an access rights type to a string. + + The access mask to convert + The enumeration type for the string conversion + Set to true to use SDK style names. + The string version of the access + + + + Convert an access rights type to a string. + + The access mask to convert + The enumeration type for the string conversion + The string version of the access + + + + Convert an access rights type to a string. + + The access mask to convert + The string version of the access + + + + Convert an access rights type to a string. + + The access mask to convert + Set to true to use SDK style names. + The string version of the access + + + + Convert an enumerable access rights to a string + + The access mask. + Enum type to convert to string. + Generic mapping for object type. + True to try and convert to generic rights where possible. + The string format of the access rights. Will return Full Access if not a generic access and has all rights and None if no access. + + + + Convert an enumerable access rights to a string + + The access mask. + Enum type to convert to string. + Generic mapping for object type. + True to try and convert to generic rights where possible. + Set to true to use SDK style names. + The string format of the access rights. Will return Full Access if not a generic access and has all rights and None if no access. + + + + Convert an ACE type to an SDK type string. + + The ACE type. + The ACE type as an SDK type string. + + + + Convert the ACE flags to an SDK type string. + + The ACE type as an SDK type string. + + + + Convert the security descriptor control flags to an SDK type string. + + The security descriptor control as an SDK type string. + + + + Get a Process Trust Level SID. + + The Trust Type. + The Trust Level. + The Process Trust Level SID. + + + + Generate audit event for an object open. + + The subsystem name. + Handle ID. + The typename of the object. + The name of the object. + The security descriptor set for the object. + The client token used to open the object. + Desired access for the open. + Granted access from the open. + Privileges used to open the object. + True if the object was created. + Specify whether access was granted. + True to throw on error. + A value indicating whether an event need to be generated on close. + + + + Generate audit event for an object open. + + The subsystem name. + Handle ID. + The typename of the object. + The name of the object. + The security descriptor set for the object. + The client token used to open the object. + Desired access for the open. + Granted access from the open. + Privileges used to open the object. + True if the object was created. + Specify whether access was granted. + A value indicating whether an event need to be generated on close. + + + + Generate audit event for an object close. + + The subsystem name. + Handle ID. + True indicates to generate on close. + True to throw on error. + The NT status code. + + + + Generate audit event for an object close. + + The subsystem name. + Handle ID. + True indicates to generate on close. + The NT status code. + + + + Generate audit event for an object deleted. + + The subsystem name. + Handle ID. + True indicates to generate on close. + True to throw on error. + The NT status code. + + + + Generate audit event for an object deleted. + + The subsystem name. + Handle ID. + True indicates to generate on close. + + + + Generate audit event for a privileges used with an object. + + The subsystem name. + Handle ID. + The client token used. + Desired access for the object. + Privileges used to open the object. + Specify whether access was granted. + True to throw on error. + The NT status code. + + + + Generate audit event for a privileges used with an object. + + The subsystem name. + Handle ID. + The client token used. + Desired access for the object. + Privileges used to open the object. + Specify whether access was granted. + + + + Generate audit event for a privileges used by a client. + + The subsystem name. + The client token used. + The name of the service. + Privileges used in the operation. + Specify whether access was granted. + True to throw on error. + The NT status code. + + + + Generate audit event for a privileges used by a client. + + The subsystem name. + The client token used. + The name of the service. + Privileges used in the operation. + Specify whether access was granted. + + + + Perform a capability check for a token. + + Specify the token handle. If null will use the effective token. + The name of the capability to check. + True to throw on error. + True if the token has the capability. + + + + Perform a capability check for a token. + + Specify the token handle. If null will use the effective token. + The name of the capability to check. + True if the token has the capability. + + + + Get GenericMapping for standard access rights. + + + + + Security information class for security descriptors. + + + + + ACE Flags. Note that the value isn't completely the same as + the real flags. + + + + + Class to represent a NT Semaphore object. + + + + + Create a semaphore object. + + The object attributes for the object + The desired access for the object + Initial count for semaphore + Maximum count for semaphore + True to throw an exception on error. + The NT status code and object result. + + + + Create a semaphore object. + + The object attributes for the object + The desired access for the object + Initial count for semaphore + Maximum count for semaphore + The opened object + + + + Create a semaphore object. + + The path to the object + The root if path is relative + Initial count for semaphore + /// Maximum count for semaphore + The opened object + + + + Open a semaphore object. + + The object attributes for the object + The desired access for the object + True to throw an exception on error. + The NT status code and object result. + + + + Open a semaphore object. + + The object attributes for the object + The desired access for the object + The opened object + + + + Open a semaphore object. + + The path to the object + The root if path is relative + The desired access for the object + The opened object + + + + Release the semaphore + + The release count + The previous count + + + + Release the semaphore + + The release count + True to throw an exception on error. + The previous count + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Current count of the semaphore. + + + + + Maximum count of the semaphore. + + + + + Semaphore access rights. + + + + + Class to represent a Session object + + + + + Open a session object. + + The object attributes + Desired access for the object + True to throw on error. + The open result. + + + + Open a session object. + + The object attributes + Desired access for the object + The open result. + + + + Open a session object. + + Name of the object + Optional root directory for lookup + Desired access for the object + The open result. + + + + NT status values + + + + + Class representing a NT SymbolicLink object + + + + + Create a symbolic link object. + + The path to the object + The root if path is relative + The desired access for the object + The target path + The opened object + + + + Create a symbolic link object. + + The object attributes for the object + The desired access for the object + The target path + True to throw an exception on error. + The NT status code and object result. + + + + Create a symbolic link object. + + The object attributes for the object + The desired access for the object + The target path + The opened object + + + + Create a symbolic link object. + + The path to the object + The root if path is relative + The target path + The opened object + + + + Create a symbolic link object. + + The path to the object + The target path + The opened object + + + + Open a symbolic link object. + + The path to the object + The root if path is relative + The desired access for the object + The opened object + + + + Open a symbolic link object. + + The path to the object + The root if path is relative + The desired access for the object + True to throw on error. + The opened object + + + + Open a symbolic link object. + + The object attributes for the object + The desired access for the object + True to throw an exception on error. + The NT status code and object result. + + + + Open a symbolic link object. + + The object attributes for the object + The desired access for the object + The opened object + + + + Open a symbolic link object. + + The path to the object + The root if path is relative + The opened object + + + + Open a symbolic link object. + + The path to the object + The opened object + + + + Resolve a symlink name to a final target. + + The name of the symlink to resolve. + True to throw on error. + The final target. + This function will return the last name which returns STATUS_OBJECT_TYPE_MISMATCH. Anything else is an error. + + + + Resolve a symlink name to a final target. + + The name of the symlink to resolve. + The final target. + This function will return the last name which returns STATUS_OBJECT_TYPE_MISMATCH. Anything else is an error. + + + + Get the symbolic link target. + + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Set access mask filter. + + The access mask to set. + True to throw on error. + The NT status code. + Needs SeTcbPrivilege. + + + + Set access mask filter. + + The access mask to set. + Needs SeTcbPrivilege. + + + + Set as a global link. + + True to throw on error. + The NT status code. + Needs SeTcbPrivilege. + + + + Set as a global link. + + Needs SeTcbPrivilege. + + + + Get the symbolic link target path. + + True to throw on error. + The target path. + + + + Class to access some NT system information + + + + + Get a list of handles + + A process ID to filter on. If -1 will get all handles + True to allow the handles returned to query for certain properties + True to force all file names to be queried. Otherwise limits to only DISK files. + The list of handles + The purpose of force_file_name to disable querying a file handle for its path unless it's on a FS volume. + This is because some non-file types can be in a locked state which causes the filename lookup to hang. + + + + Get a list of handles + + A process ID to filter on. If -1 will get all handles + True to allow the handles returned to query for certain properties + The list of handles + + + + Get a list of all handles + + The list of handles + + + + Get a list of threads for a specific process. + + The process ID to list. + True to throw on error. + The list of thread information. + + + + Get a list of threads for a specific process. + + The process ID to list. + The list of thread information. + + + + Get a list of all threads. + + The list of thread information. + + + + Get a list of all threads. + + The list of thread information. + + + + Get a list of threads for a specific process. + + The process ID to list. + True to throw on error. + The list of thread information. + + + + Get a list of threads for a specific process. + + The process ID to list. + The list of thread information. + + + + Get a list of all threads. + + The list of thread information. + + + + Get a list of all threads. + + The list of thread information. + + + + Get all process information for the system. + + The list of process information. + + + + Get all process information for the system. + + True to throw on error. + The list of process information. + + + + Get all process information for the system. + + The list of process information. + + + + Get all process information for the system. + + True to throw on error. + The list of process information. + + + + Get all process information for the system. + + The list of process information. + + + + Get all process information for the system. + + True to throw on error. + The list of process information. + + + + Get list of page filenames. + + The list of page file names. + + + + Create a kernel dump for current system. + + The path to the output file. + Flags + Page flags + + + + Query all system environment value names. + + A list of names of environment values + + + + Query all system environment value names and values. + + A list of names of environment values + + + + Query a single system environment value. + + The name of the value. + The associated vendor guid + True to throw on error. + The system environment value. + + + + Query a single system environment value. + + The name of the value. + The associated vendor guid + The system environment value. + + + + Set a system environment variable. + + The name of the variable. + The vendor GUID + The value to set + Attributes of the value + + + + Set a system environment variable. + + The name of the variable. + The vendor GUID + The value to set + Attributes of the value + + + + Set a system environment variable. + + The name of the variable. + The vendor GUID + The value to set + Attributes of the value + + + + Set a system environment variable. + + The name of the variable. + The vendor GUID + The value to set + Attributes of the value + + + + Allocate a LUID. + + The allocated LUID. + + + + Allocate a LUID. + + The allocated LUID. + + + + Get the addresses of a list of objects from the handle table and initialize the Address property. + + The list of objects to initialize. + + + + Get the address of an object in kernel memory from the handle table and initialize the Address property. + + The object. + + + + Get the address of an object in kernel memory from the handle table and initialize the Address property. + + The object. + Any remaining objects. + + + + Query whether a file is trusted for dynamic code. + + The handle to a file to query. + Pointer to a memory buffer containing the image. + The size of the in-memory buffer. + True if the file is trusted. + + + + Query whether a file is trusted for dynamic code. + + Pointer to a memory buffer containing the image. + The status code from the operation. Returns STATUS_SUCCESS is valid. + + + + Query whether a file is trusted for dynamic code. + + The handle to a file to query. + The status code from the operation. Returns STATUS_SUCCESS is valid. + + + + Set a file is trusted for dynamic code. + + The handle to a file to set. + The status code from the operation. + + + + Get list of root silos. + + The list of root silos. + + + + Set the ELAM certificate information. + + The signed file containing an ELAM certificate resource. + The NT status code. + + + + Query code integrity certificate information. + + The image file. + The type of check to make. + The NT status code. + + + + Query the image path from a process ID. + + The ID of the process. + True to throw on error. + The image path. + This method can be called without any permissions on the process. + + + + Query the image path from a process ID. + + The ID of the process. + The image path. + This method can be called without any permissions on the process. + + + + Get flags for isolated user mode. + + True to throw on error. + The ISO flags. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + The result of the query. + Thrown on error. + + + + Query a fixed structure from the object. + + The type of structure to return. + The information class to query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The information class to query. + A buffer to initialize the initial query. Can be null. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The information class to query. + A buffer to initialize the initial query. Can be null. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The information class to query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object and return as bytes. + + The information class to query. + A buffer to initialize the initial query. Can be null. + True to throw on error. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object and return as bytes. + + The information class to query. + A buffer to initialize the initial query. Can be null. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object and return as bytes. + + The information class to query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The type of structure to return. + The information class to query. + A default value for the query. + The result of the query. + Thrown on error. + + + + Query a variable buffer from the object. + + The type of structure to return. + The information class to query. + The result of the query. + Thrown on error. + + + + Set a value to the object. + + The type of structure to set. + The information class to set. + The value to set. If you specify a SafeBuffer then it'll be passed directly. + True to throw on error. + The NT status code of the set. + Thrown on error. + + + + Set a value to the object. + + The type of structure to set. + The information class to set. + The value to set. + The NT status code of the set. + Thrown on error. + + + + Set a value to the object from a buffer. + + The information class to set. + The value to set. + True to throw on error. + The NT status code of the set. + Thrown on error. + + + + Set a value to the object from a buffer.. + + The information class to set. + The value to set. + The NT status code of the set. + Thrown on error. + + + + Set a raw value to the object. + + The information class to set. + The raw value to set. + True to throw on error. + The NT status code of the set. + Thrown on error. + + + + Set a raw value to the object. + + The information class to set. + The raw value to set. + The NT status code of the set. + Thrown on error. + + + + Draw text on the background. + + The text to draw. + True to throw on error. + The NT status code. + + + + Draw text on the background. + + The text to draw. + + + + Display a string. + + The text to display. + True to throw on error. + The NT status code. + + + + Display a string. + + The text to display. + + + + Load a driver. + + The name of the driver service. + True to throw on error. + The NT status code. + + + + Unload a driver. + + The name of the driver service. + True to throw on error. + The NT status code. + + + + Get kernel modules. + + True to throw on error. + The list of kernel modules. + + + + Get kernel modules. + + The list of kernel modules. + + + + Get whether the kernel debugger is enabled. + + + + + Get whether the kernel debugger is not present. + + + + + Get current code integrity option settings. + + + + + Get code integrity policy. + + + + + Get code integrity unlock information. + + + + + Get all code integrity policies. + + + + + Get whether secure boot is enabled. + + + + + Get whether system supports secure boot. + + + + + Extract the secure boot policy. + + + + + Get system timer resolution. + + + + + Get system page size. + + + + + Get number of physical pages. + + + + + Get lowest page number. + + + + + Get highest page number. + + + + + Get allocation granularity. + + + + + Get minimum user mode address. + + + + + Get maximum user mode address. + + + + + Get active processor affinity mask. + + + + + Get number of processors. + + + + + Get system device information. + + + + + Get the system processor information. + + + + + Get the system emulation processor information. + + + + + Get the Isolated User Mode flags. + + + + + Get the NT product type. + + + + + + Get OS version info, + + + + + Get whether this is a multi-session SKU. + + True if multi-session. + + + + Get whether this there are multiple users in a session. + + True if multi-session. + + + + Query the system elevation flags. + + + + + Class to represent a NT Thread object + + + + + Create a new thread in a process. + + The object attributes for the thread object. + Desired access for the handle. + Process to create the thread in. + Address of the start routine. + Argument to pass to the thread. + Creation flags. + Zero bits for the stack address. + Size of the committed stack. + Maximum reserved stack size. + Optional attribute list. + True to throw on error + The created thread object. + This creates a native thread, not a Win32 thread. This might cause unexpected things to fail as they're not initialized. + + + + Create a new thread in a process. + + The object attributes for the thread object. + Desired access for the handle. + Process to create the thread in. + Address of the start routine. + Argument to pass to the thread. + Creation flags. + Zero bits for the stack address. + Size of the committed stack. + Maximum reserved stack size. + Optional attribute list. + The created thread object. + This creates a native thread, not a Win32 thread. This might cause unexpected things to fail as they're not initialized. + + + + Create a new thread in a process. + + Process to create the thread in. + Address of the start routine. + Argument to pass to the thread. + Creation flags. + Size of the committed stack. + True to throw on error + The created thread object. + This creates a native thread, not a Win32 thread. This might cause unexpected things to fail as they're not initialized. + + + + Create a new thread in a process. + + Process to create the thread in. + Address of the start routine. + Argument to pass to the thread. + Creation flags. + Size of the committed stack. + The created thread object. + This creates a native thread, not a Win32 thread. This might cause unexpected things to fail as they're not initialized. + + + + Open a thread + + The process ID containing the thread. + The thread ID to open + The desired access for the handle + True to throw an exception on error. + The NT status code and object result. + + + + Open a thread + + The thread ID to open + The desired access for the handle + True to throw an exception on error. + The NT status code and object result. + + + + Open a thread + + The process ID containing the thread. + The thread ID to open + The desired access for the handle + The NT status code and object result. + + + + Open a thread + + The thread ID to open + The desired access for the handle + The opened object + + + + Gets all accessible threads on the system. + + The desired access for each thread. + Get the thread list from system information. + The list of accessible threads. + + + + Gets all accessible threads on the system. + + The desired access for each thread. + The list of accessible threads. + + + + Get first thread for process. + + The process handle to get the threads. + The desired access for the thread. + The first thread, or null if no more available. + + + + Sleep the current thread + + Set if the thread should be alertable + The delay, negative values indicate relative times. + True to throw on error. + STATUS_ALERTED if the thread was alerted, other success or error code. + + + + Sleep the current thread + + Set if the thread should be alertable + The delay, negative values indicate relative times. + True if the thread was alerted before the delay expired. + + + + Sleep the current thread + + Set if the thread should be alertable + The delay, negative values indicate relative times. + True if the thread was alerted before the delay expired. + + + + Sleep the current thread for a specified number of milliseconds. + + The delay in milliseconds. + True if the thread was alerted before the delay expired. + + + + Open an actual handle to the current thread rather than the pseudo one used for Current + + The thread object + + + + Set the work on behalf ticket. + + The ticket to set. + True to throw on error. + The status code from the set. + + + + Set the work on behalf ticket. + + The ticket to set. + + + + Set the work on behalf ticket. + + The ticket to set. + True to throw on error. + The status code from the set. + + + + Set the work on behalf ticket. + + The ticket to set. + + + + Set the work on behalf ticket. + + The thread ID. + True to throw on error. + The NT status. + + + + Set the work on behalf ticket. + + The thread ID. + + + + Test alert status for the current thread. + + True to throw on error. + The NT status code. + + + + Test alert status for the current thread. + + + + + Attach a silo container to the current thread. + + The silo to attach. + True to throw on error. + The thread impersonation context. + + + + Attach a silo container to the current thread. + + The silo to attach. + The thread impersonation context. + + + + Detach container from the current thread. + + True to throw on error. + The NT status code. + + + + Detach container from the current thread. + + + + + Get XOR key for the work-on-behalf ticket. + + True to throw on error. + The XOR key. + + + + Get the current thread. + + This only uses the pseudo handle, for the thread. You can't use it in different threads. If you need to do that use OpenCurrent. + + + + + Get or set the work on behalf ticket for the current thread. + + + + + Get the work on behalf ticket xor key. + + + + + Reopen object with different access rights. + + The desired access. + Additional attributes for open. + True to throw on error. + The reopened object. + + + + Resume the thread. + + True to throw on error. + The suspend count + + + + Resume the thread. + + The suspend count + + + + Suspend the thread. + + True to throw on error. + The suspend count + + + + Suspend the thread + + The suspend count + + + + Terminate the thread + + True to throw on error. + The thread status exit code + The NT status code. + + + + Terminate the thread + + The thread status exit code + + + + Wake the thread from an alertable state. + + True to throw on error. + The NT status code. + + + + Wake the thread from an alertable state. + + + + + Wake the thread from an alertable state and resume the thread. + + True to throw on error. + The previous suspend count for the thread. + + + + Wake the thread from an alertable state and resume the thread. + + The previous suspend count for the thread. + + + + Hide the thread from debug events. + + True to throw on error. + The NT status code. + + + + Hide the thread from debug events. + + + + + The set the thread's impersonation token + + The impersonation token to set + True to throw on error. + The NT status code. + + + + The set the thread's impersonation token + + The impersonation token to set + + + + Impersonate the anonymous token + + True to throw on error. + The impersonation context. Dispose to revert to self + + + + Impersonate the anonymous token + + The impersonation context. Dispose to revert to self + + + + Impersonate a token + + True to throw on error. + The token to impersonate. + The impersonation context. Dispose to revert to self + + + + Impersonate a token + + The token to impersonate. + The impersonation context. Dispose to revert to self + + + + Impersonate another thread. + + The thread to impersonate. + The impersonation security quality of service. + True to throw on error. + The imperonsation context. Dispose to revert to self. + + + + Impersonate another thread's security context. + + The thread to impersonate. + The impersonation level for the token. + True to throw on error. + The imperonsation context. Dispose to revert to self. + + + + Impersonate another thread's security context. + + The thread to impersonate. + The impersonation level for the token. + The imperonsation context. Dispose to revert to self. + + + + Impersonate another thread's security context at impersonation level. + + The thread to impersonate. + True to throw on error. + The imperonsation context. Dispose to revert to self. + + + + Impersonate another thread's security context at impersonation level. + + The thread to impersonate. + The imperonsation context. Dispose to revert to self. + + + + Open the thread's token + + The token, null if no token available + + + + Queue a special user APC to the thread. + + The APC callback pointer. + Context parameter. + System argument 1. + System argument 2. + True to throw on error. + The NT status code. + + + + Queue a special user APC to the thread. + + The APC callback pointer. + Context parameter. + System argument 1. + System argument 2. + The NT status code. + + + + Queue a special user APC to the thread. + + The APC callback pointer. + Context parameter. + System argument 1. + System argument 2. + True to throw on error. + The NT status code. + + + + Queue a special user APC to the thread. + + The APC callback pointer. + Context parameter. + System argument 1. + System argument 2. + The NT status code. + + + + Queue a user APC to the thread. + + The APC callback pointer. + Context parameter. + System argument 1. + System argument 2. + True to throw on error. + The NT status code. + + + + Queue a user APC to the thread. + + The APC callback pointer. + Context parameter. + System argument 1. + System argument 2. + + + + Queue a user APC to the thread. + + The APC callback delegate. + Context parameter. + System argument 1. + System argument 2. + True to throw on error. + The NT status code. + This is only for APCs in the current process. You also must ensure the delegate is + valid at all times as this method doesn't take a reference to the delegate to prevent it being + garbage collected. + + + + Queue a user APC to the thread. + + The APC callback delegate. + Context parameter. + System argument 1. + System argument 2. + This is only for APCs in the current process. You also must ensure the delegate is + valid at all times as this method doesn't take a reference to the delegate to prevent it being + garbage collected. + + + + Get next thread for process relative to current thread. + + The process handle to get the threads. + The desired access for the thread. + The next thread, or null if no more available. + + + + Get the thread context. + + Flags for context parts to get. + True to throw on error. + An instance of an IContext object. Needs to be cast to correct type to access. + + + + Get the thread context. + + Flags for context parts to get. + An instance of an IContext object. Needs to be cast to correct type to access. + + + + Set the thread's context. + + The thread context to set. + True to throw on error. + The NT status code. + + + + Set the thread's context. + + The thread context to set. + + + + Get current waiting server information. + + True to throw on error. + The thread ALPC server information. + + + + Get current waiting server information. + + The thread ALPC server information. + + + + Get the process ID associated with the thread. + + True to throw on error. + The process ID. + + + + Get the thread ID. + + True to throw on error. + The thread ID. + + + + Cancel all synchronous IO for this thread. + + True to throw on error. + The NT status. + + + + Get a partial TEB for the thread. + + The partial TEB. + + + + Get the work on behalf ticket for a thread. + + True to throw on error. + The work on behalf ticket. + + + + Get the work on behalf ticket for a thread. + + The work on behalf ticket. + + + + Get the effective container ID for the thread. + + True to throw on error. + The effective container ID. + + + + Get priority boost disable value. + + True to throw on error. + True if priority base + + + + Set priority boost disable value. + + True to disable priority boost. + True to throw on error. + The NT status code. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get thread ID + + + + + Get process ID + + + + + Get name of process. + + + + + Get or set the thread's current priority + + + + + Get or set the thread's base priority + + + + + Get or set the thread's affinity mask. + + + + + Get the thread's TEB base address. + + + + + Get or set whether thread is allowed to create dynamic code. + + Set can only be done on the current thread. + + + + Get whether thread is impersonating another token. + + Note that this tries to open the thread's token and return true if it could open. A return of false + might just indicate that the caller doesn't have permission to open the token, not that it's not impersonating. + + + + Get name of the thread. + + + + + Get or set a thread's description. + + + + + Get the Win32 start address for the thread. + + + + + Get the current Instruction Pointer for the thread. + + + + + Get last system call on the thread. + + + + + Get the thread's suspend count. + + + + + Get whether the thread has pending IO. + + + + + Get the creation time of the thread. + + + + + Get the exit time of the thread (0 if not exited) + + + + + Get the time spent in the kernel. + + + + + Get the time spent in user mode. + + + + + Get thread information. + + + + + Get thread exit status. + + + + + Get thread exit status. + + + + + Get the effective container ID. + + Should be called on the current thread psuedo handle. + + + + Get or set priority boost disabled. + + + + + Delegate for APC callbacks. + + Context parameter. + System argument 1. + System argument 2. + + + + Class to represent an NT Timer object + + + + + Create a timer object + + The path to the event + The root object for relative path names + The type of the timer. + The timer object + + + + Create a timer object + + The timer object attributes + The type of the event + The desired access for the timer + The timer object + + + + Create a timer object + + The timer object attributes + The type of the timer + The desired access for the timer + True to throw an exception on error. + The NT status code and object result. + + + + Create a timer object + + The path to the timer + The type of the timer + The timer object + + + + Create a timer object + + The type of the timer + The timer object + + + + Create a timer object + + The timer object + + + + Open a timer object + + The path to the timer + The root object for relative path names + The desired access for the timer + The timer object + + + + Open a timer object + + The path to the timer + The root object for relative path names + The desired access for the timer + True to throw on error. + The timer object + + + + Open a timer object + + The timer object attributes + The desired access for the timer + The timer object. + + + + Open a timer object + + The event object attributes + The desired access for the timer + True to throw an exception on error. + The NT status code and object result. + + + + Open a timer object + + The path to the timer + The root object for relative path names + The timer object + + + + Open a timer object + + The path to the timer + The timer object + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Set timer state. + + The due time for the timer. + Optional APC routine. + Optional APC context pointer. + True to resume. + Period time. + True throw on error. + The NT result and previous state. + + + + Set timer state. + + The due time for the timer. + Optional APC routine. + Optional APC context pointer. + True to resume. + Period time. + The previous state. + + + + Set timer state. + + The due time for the timer. + The previous state. + + + + Set timer state in milliseconds. + + The due time for the timer in milliseconds. + The previous state. + + + + Cancel the timer. + + True to throw on error. + The previous state. + + + + Cancel the timer. + + The previous state. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Remaining time for the timer. + + + + + Signal state of the timer. + + + + + Delegate for Timer APC callbacks. + + Context parameter. + Low value of timer. + High value of timer. + + + + Enumeration for querying group list using QueryGroups. + + + + + The default group list. + + + + + The restrict group list. + + + + + The capability group list. + + + + + The device group list. + + + + + The restricted device list. + + + + + Specify type of security attributes to query. + + + + + Local security attributes. + + + + + User security attributes. + + + + + Restricted user security attributes. + + + + + Device security attributes. + + + + + Restricted device security attributes. + + + + + Singleton device security attributes. + + + + + Data from the TSA://ProcUnique security attribute. + + + + + The index entry for the process. + + + + + The value for the entry. + + + + + Class representing a Token object + + + + + Duplicate token as specific type. + + The token type + The impersonation level us type is Impersonation + Open with the desired access. + The object attributes for the token. + The security descriptor for the token. + If true then throw an exception on error. + The new token + Thrown on error + + + + Duplicate token as specific type. + + The token type + The impersonation level us type is Impersonation + Open with the desired access. + The object attributes for the token. + The security descriptor for the token. + The new token + Thrown on error + + + + Duplicate token as specific type. + + The token type + The impersonation level us type is Impersonation + Open with the desired access. + If true then throw an exception on error. + The new token + Thrown on error + + + + Duplicate token as specific type + + The token type + The impersonation level us type is Impersonation + Open with the desired access. + The new token + Thrown on error + + + + Duplicate the token as the same token type. + + The new token. + Thrown on error + + + + Duplicate the token as the same token type. + + True to throw on error. + The new token. + Thrown on error + + + + Duplicate token as an impersonation token with a specific level + + The token impersonation level + The new token + Thrown on error + + + + Set a privilege state + + The name of the privilege (e.g. SeDebugPrivilege) + True to enable the privilege, false to disable + True to throw on error. + True if successfully changed the state of the privilege + + + + Set a privilege state + + The name of the privilege (e.g. SeDebugPrivilege) + True to enable the privilege, false to disable + True if successfully changed the state of the privilege + + + + Set a privilege state + + The luid of the privilege + The privilege attributes to set. + True to throw on error. + True if successfully changed the state of the privilege + + + + Set a privilege state + + The luid of the privilege + The privilege attributes to set. + True if successfully changed the state of the privilege + + + + Set a privilege state + + The value of the privilege + The privilege attributes to set. + True to throw on error. + True if successfully changed the state of the privilege + + + + Set a privilege state + + The value of the privilege + The privilege attributes to set. + True if successfully changed the state of the privilege + + + + Remove a privilege. + + The value of the privilege to remove. + True if successfully removed the privilege. + + + + Remove a privilege. + + The LUID of the privilege to remove. + True if successfully removed the privilege. + + + + Create a LowBox token from the current token. + + The package SID + The created LowBox token. + Thrown on error. + + + + Create a LowBox token from the current token. + + The package SID + List of handles to capture with the token + The created LowBox token. + Thrown on error. + + + + Create a LowBox token from the current token. + + The package SID + List of handles to capture with the token + List of capability sids to add. + Desired token access. + The created LowBox token. + Thrown on error. + + + + Filter a token to remove groups/privileges and add restricted SIDs + + Filter token flags + List of SIDs to disable + List of privileges to delete + List of restricted SIDs to add + The new token. + + + + Filter a token to remove groups/privileges and add restricted SIDs + + Filter token flags + List of SIDs to disable + List of privileges to delete + List of restricted SIDs to add + The new token. + + + + Filter a token to remove privileges and groups. + + Filter token flags + The new filtered token. + + + + Set the state of a group + + The group SID to set + The attributes to set + + + + Set the state of a group + + The group SID to set + The attributes to set + True to throw on error. + The NT status code. + + + + Set the state of a group + + The groups to set + The attributes to set + True to throw on error. + The NT status code. + + + + Set the state of a group + + The groups to set + The attributes to set + + + + Reset all groups to their default state. + + True to throw on error. + The NT status code. + + + + Reset all groups to their default state. + + + + + Set the session ID of a token + + The session ID + + + + Set a token's default DACL + + The DACL to set. + + + + Set the origin logon session ID. + + The origin logon session ID. + + + + Set virtualization enabled + + True to enable virtualization + True to throw on error. + + + + Set virtualization enabled + + True to enable virtualization + + + + Set UI Access flag. + + True to enable UI Access. + + + + Get the linked token + + True to throw on error. + The linked token + + + + Get the linked token + + The linked token + + + + Set the linked token. + + The token to set. + Requires SeCreateTokenPrivilege. + + + + Impersonate the token. + + An impersonation context, dispose to revert to process token + Thrown on error. + + + + Impersonate the token. + + Impersonation level for token. + An impersonation context, dispose to revert to process token + Thrown on error. + + + + Run a function under impersonation. + + The return type. + The callback to run. + The return value from the callback. + Thrown on error. + + + + Run an action under impersonation. + + The callback to run. + Thrown on error. + + + + Run a function under impersonation. + + The return type. + The callback to run. + Impersonation level for token. + The return value from the callback. + Thrown on error. + + + + Run an action under impersonation. + + The callback to run. + Impersonation level for token. + Thrown on error. + + + + Get a security attribute by name. + + Specify the type of security attributes to query. + The name of the security attribute, such as WIN://PKG + The expected type of the security attribute. If None return ignore type check. + The security attribute or null if not found. + + + + Get a security attribute by name. + + The name of the security attribute, such as WIN://PKG + The expected type of the security attribute. If None return ignore type check. + The security attribute or null if not found. + + + + Get a security attribute by name. + + The name of the security attribute, such as WIN://PKG + The security attribute or null if not found. + + + + Get token's security attributes + + Specify the type of security attributes to query. + Throw on error. + The security attributes. + + + + Get token's security attributes. + + Throw on error. + The security attributes. + + + + Get token's security attributes + + Specify the type of security attributes to query. + The security attributes. + + + + Get token's security attributes + + The security attributes. + + + + Set security attributes on the token. + + The list of attributes. + The operation to perform on the attribute. + Throw on error. + The array of attributes aand operations must be the same size. You need SeTcbPrivilege to call this API. + The NT Status code. + + + + Set security attributes on the token. + + The list of attributes. + The operation to perform on the attribute. + The array of attributes aand operations must be the same size. You need SeTcbPrivilege to call this API. + + + + Add security attributes to the token. + + The list of attributes. + Throw on error. + You need SeTcbPrivilege to call this API. + The NT Status code. + + + + Add security attributes to the token. + + The list of attributes. + You need SeTcbPrivilege to call this API. + + + + Replace security attributes in the token. + + The list of attributes. + Throw on error. + You need SeTcbPrivilege to call this API. + The NT Status code. + + + + Replace security attributes in the token. + + The list of attributes. + You need SeTcbPrivilege to call this API. + + + + Replace all security attributes in the token. + + The list of attributes. + Throw on error. + You need SeTcbPrivilege to call this API. + The NT Status code. + + + + Replace security attributes in the token. + + The list of attributes. + You need SeTcbPrivilege to call this API. + + + + Remove security attributes by name. + + The attribute names to remove. + Throw on error. + The NT Status code. + + + + Remove security attributes by name. + + The attribute names to remove. + + + + Set the token's integrity level. + + The level to set. + + + + Set the token's integrity level. + + The level to set. + + + + Get the state of a privilege. + + The privilege to get the state of. + The privilege, or null if it can't be found + Thrown if can't query privileges + + + + Get the state of a privilege. + + The privilege to get the state of. + The privilege, or null if it can't be found + True to throw on error + Thrown if can't query privileges + + + + Compare two tokens. + + The other token to compare. + True if tokens are equal. + + + + Get the App Policy for this token. + + The type of app policy. + The policy value. + + + + Disable No Child process policy on the token. + + Needs SeTcbPrivilege. + + + + Query a list of groups from the token. + + The type of groups to query. + True to throw on error. + The list of groups. + + + + Query a list of groups from the token. + + The type of groups to query. + The list of groups. + + + + Get the user from the token. + + True to throw on error. + The user group information. + + + + Do a privilege check on a token. + + The list of privileges to check. + True to require all necessary privileges. + True to throw on error. + The privilege check result. + + + + Do a privilege check on a token. + + The list of privileges to check. + True to require all necessary privileges. + The privilege check result. + + + + Do a privilege check on a token. + + The list of privileges to check. + True to require all necessary privileges. + True to throw on error. + The privilege check result. + + + + Do a privilege check on a token. + + The list of privileges to check. + True to require all necessary privileges. + The privilege check result. + + + + Do a privilege check for a single privilege. + + The privilege to check. + True if the privilege is enabled. + + + + Do a privilege check for a single privilege. + + The privilege to check. + True if the privilege is enabled. + + + + Get token privileges. + + True to throw on error. + The list of privileges. + + + + Perform a capability check for a token. + + The name of the capability to check. + True to throw on error. + True if the token has the capability. + + + + Perform a capability check for a token. + + The name of the capability to check. + True if the token has the capability. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get the logon SID for the token. + + True to throw on error. + The logon SID. + + + + Get token user + + + + + Get token groups + + + + + Get list of enabled groups. + + + + + Get list of deny only groups. + + + + + Get count of groups in this token. + + + + + Get the authentication ID for the token + + + + + Get the token's type + + + + + Get the token's expiration time. + + + + + Get the Token's Id + + + + + Get the Token's modified Id. + + + + + Get/set the token's owner. + + + + + Get/set the token's primary group + + + + + Get/set the token's default DACL + + + + + Get the token's source + + + + + Get token's restricted sids + + + + + Get count of restricted sids + + + + + Get token's impersonation level + + + + + Get/set token's session ID + + + + + Get whether token has sandbox inert flag set. + + + + + Get/set token's origin + + + + + Get token's elevation type + + + + + Get whether token is elevated + + + + + Get whether token has restrictions + + + + + Get/set token UI access flag + + + + + Get or set whether virtualization is allowed + + + + + Get/set whether virtualization is enabled + + + + + Get whether token is restricted + + + + + Get whether token is write restricted. + + + + + Get whether token is filtered. + + + + + Get whether token is not low. + + + + + Token access flags. + + + + + Get whether token can be used for new child processes. + + + + + Get token capabilities. + + + + + Get or set the token mandatory policy + + + + + Get token logon sid + + + + + Get token's integrity level sid + + + + + Get token's App Container number. + + + + + Get or set token's integrity level. + + + + + Get token's security attributes + + + + + Get token's device claims. + + + + + Get token's user claims. + + + + + Get token's restricted user claims. + + Unsupported, at least on Windows 10. + + + + Get token's restricted user claims. + + Unsupported, at least on Windows 10. + + + + Get whether a token is an AppContainer token + + + + + Get whether the token is configured for low privilege. + + + + + Get token's AppContainer sid + + + + + Get token's AppContainer package name (if available). + Returns an empty string if not an AppContainer. + + + + + Get token's device groups + + + + + Get token's restricted device groups. + + + + + Get list of privileges for token + + The list of privileges + Thrown if can't query privileges + + + + Get full path to token + + + + + Get the token's trust level. Will be null if no trust level present. + + + + + Returns true if this is a pseudo token. + + + + + Get whether this token is a sandboxed token. + + + + + Query the token's full package name. + + + + + Query the token's appid. + + + + + Get the list of policies for this App. + + + + + Get the list of policies for this App in a table. + + + + + Get the BaseNamedObjects isolation prefix if enabled. + + + + + Get the token's package identity. + + + + + Get or set the token audit policy. + + Needs SeSecurityPrivilege to query and SeTcbPrivilege to set. + + + + Get or set if token is in a private namespace. + + + + + Get if the token is restricted. + + + + + Get the TSA://ProcUnique attribute. + + + + + Enable debug privilege for the current process token. + + True if set the debug privilege + + + + Enable a privilege of the effective token. + + The privilege to enable. + True if set the privilege. + + + + Open the process token of another process + + The process to open the token for + The desired access for the token + Attribute flags for the handle. + If true then throw an exception on error. + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + The desired access for the token + Attribute flags for the handle. + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + The desired access for the token + If true then throw an exception on error. + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + The desired access for the token + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + True to duplicate the token before returning + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + True to duplicate the token before returning + The desired access for the token + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + True to duplicate the token before returning + The desired access for the token + True to throw on error. + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The process to open the token for + The opened token + Thrown if cannot open token + + + + Open the process token of the current process + + The opened token + Thrown if cannot open token + + + + Open the process token of the current process + + True to duplicate the token before returning + The opened token + Thrown if cannot open token + + + + Open the process token of the current process + + True to duplicate the token before returning + The desired access for the token + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The id of the process to open the token for + True to duplicate the token before returning + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The id of the process to open the token for + True to duplicate the token before returning + The desired access for the token + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The id of the process to open the token for + True to duplicate the token before returning + The desired access for the token + True to throw on error. + The opened token + Thrown if cannot open token + + + + Open the process token of another process + + The id of the process to open the token for + The opened token + Thrown if cannot open token + + + + Open the thread token + + The thread to open the token for + Open the token as the current identify rather than the impersonated one + The desired access for the token + If true then throw an exception on error. + The opened token result + Thrown if cannot open token + + + + Open the thread token + + The thread to open the token for + Open the token as the current identify rather than the impersonated one + True to duplicate the token before returning. + The desired access for the token + True to throw on error. + The opened token, if no token return null + Thrown if cannot open token + + + + Open the thread token + + The thread to open the token for + Open the token as the current identify rather than the impersonated one + True to duplicate the token before returning + The desired access for the token + The opened token, if no token return null + Thrown if cannot open token + + + + Open the thread token + + The ID of the thread to open the token for + Open the token as the current identify rather than the impersonated one + True to duplicate the token before returning + The desired access for the token + The opened token, if no token return null + Thrown if cannot open token + + + + Open the thread token + + The thread to open the token for + Open the token as the current identify rather than the impersonated one + True to duplicate the token before returning + The opened token, if no token return null + Thrown if cannot open token + + + + Open the thread token + + The thread to open the token for + The opened token, if no token return null + Thrown if cannot open token + + + + Open the current thread token + + True to duplicate the token before returning + The opened token, if no token return null + Thrown if cannot open token + + + + Open the current thread token + + The opened token, if no token return null + Thrown if cannot open token + + + + Open the effective token, thread if available or process + + The thread to open the token for + True to duplicate the token before returning + Desired access for token. + Open token as self. + True to throw on error. + The opened token + Thrown if cannot open token + + + + Open the effective token, thread if available or process + + The thread to open the token for + True to duplicate the token before returning + Desired access for token. + Open token as self. + The opened token + Thrown if cannot open token + + + + Open the effective token, thread if available or process + + The thread to open the token for + True to duplicate the token before returning + True to throw on error. + The opened token + Thrown if cannot open token + + + + Open the effective token, thread if available or process + + The thread to open the token for + True to duplicate the token before returning + The opened token + Thrown if cannot open token + + + + Open the current effective token, thread if available or process + + The opened token + Thrown if cannot open token + + + + Open the current effective token, thread if available or process + + True to throw on error. + The opened token + Thrown if cannot open token + + + + Create a token. Needs SeCreateTokenPrivilege. + + The desired access for the token. + Object attributes, used to pass SecurityDescriptor or SQOS for impersonation token. + The type of token. + The authentication ID for the token. + The expiration time for the token. + The user for the token. + The groups for the token. + The privileges for the token. + The owner of the token. + The primary group for the token. + The default dacl for the token. + The source for the token. + Optional device attributes. + Optional device groups. + Optional mandatory policy. + Optional user attributes. + True to throw on error. + The token object. + + + + Create a token. Needs SeCreateTokenPrivilege. + + The desired access for the token. + Object attributes, used to pass SecurityDescriptor or SQOS for impersonation token. + The type of token. + The authentication ID for the token. + The expiration time for the token. + The user for the token. + The groups for the token. + The privileges for the token. + The owner of the token. + The primary group for the token. + The default dacl for the token. + The source for the token. + Optional device attributes. + Optional device groups. + Optional mandatory policy. + Optional user attributes. + The token object. + + + + Create a token. Needs SeCreateTokenPrivilege. + + The desired access for the token. + Object attributes, used to pass SecurityDescriptor or SQOS for impersonation token. + The type of token. + The authentication ID for the token. + The expiration time for the token. + The user for the token. + The groups for the token. + The privileges for the token. + The owner of the token. + The primary group for the token. + The default dacl for the token. + The source for the token. + True to throw on error. + The token object. + + + + Create a token. Needs SeCreateTokenPrivilege. + + The desired access for the token. + Object attributes, used to pass SecurityDescriptor or SQOS for impersonation token. + The type of token. + The authentication ID for the token. + The expiration time for the token. + The user for the token. + The groups for the token. + The privileges for the token. + The owner of the token. + The primary group for the token. + The default dacl for the token. + The source for the token. + The token object. + + + + Create a token. Needs SeCreateTokenPrivilege. + + The user for the token. + The groups for the token. + The privileges for the token. + The token object. + + + + Create a token. Needs SeCreateTokenPrivilege. + + The user for the token. + The token object. + + + + Impersonate another process' token + + The impersonation level + Process ID of the other process + An impersonation context, dispose to revert to process token + + + + Get the current user. + + True to throw on error. + The current user. + + + + Do a single privilege check on the effective token. + + The privilege to check. + True to throw on error. + True if the privilege is enabled. + + + + Do a single privilege check on the effective token. + + The privilege to check. + True if the privilege is enabled. + + + + Get the current user. + + + + + Get authentication ID for LOCAL SYSTEM + + + + + Get authentication ID for LOCAL SERVICE + + + + + Get authentication ID for NETWORK SERVICE + + + + + Get authentication ID for ANONYMOUS + + + + + Get a pseudo handle to the primary token. + + Only useful for querying information. + + + + Get a pseudo handle to the impersonation token. + + Only useful for querying information. + + + + Get a pseudo handle to the effective token. + + Only useful for querying information. + + + + Static methods to interact with the ETW subsystem. + + + + + Issue a trace control request. + + The trace control function code. + The optional input buffer. + The optional output buffer. + True to throw on error. + The output length. + + + + Issue a trace control request. + + The trace control function code. + The optional input buffer. + The optional output buffer. + The output length. + + + + Access rights for Trace + + + + + The security trace provider GUID. + + + + + The default security GUID. + + + + + Class to represent a kernel transaction. + + + + + Create a transaction + + The object attributes + Desired access for the handle + True to throw an exception on error. + Transaction creation options. + Optional description of the transaction. + Isolation flags. + Isolation level. + Optional transaction timeout. + Optional transaction manager. + Optional UOW. + The NT status code and object result. + + + + Create a transaction + + The object attributes + Desired access for the handle + Transaction creation options. + Optional description of the transaction. + Isolation flags. + Isolation level. + Optional transaction timeout. + Optional transaction manager. + Optional UOW. + The NT status code and object result. + + + + Create a transaction + + The object attributes + Desired access for the handle + True to throw an exception on error. + The NT status code and object result. + + + + Create a transaction + + The object attributes + Desired access for the handle + The opened transaction + + + + Create a transaction + + The path of the transaction + The root if path is relative + Desired access for the handle + Transaction creation options. + Optional description of the transaction. + Isolation flags. + Isolation level. + Optional transaction timeout. + Optional transaction manager. + Optional UOW. + True to throw an exception on error. + The opened transaction + + + + Create a transaction + + The path of the transaction + The root if path is relative + Desired access for the handle + Transaction creation options. + Optional description of the transaction. + Isolation flags. + Isolation level. + Optional transaction timeout. + Optional transaction manager. + Optional UOW. + The opened transaction + + + + Create a transaction + + The path of the transaction + The root if path is relative + Desired access for the handle + True to throw an exception on error. + The opened transaction + + + + Create a transaction + + The path of the transaction + The root if path is relative + Desired access for the handle + The opened transaction + + + + Create a transaction + + The path of the transaction + The root if path is relative + The opened transaction + + + + Create a transaction + + The path of the transaction + The opened transaction + + + + Create a transaction + + The opened transaction + + + + Open a transaction object. + + The object attributes for the object + The desired access for the object + Optional transaction manager. + UOW Guid. + True to throw an exception on error. + The NT status code and object result. + + + + Open a transaction object. + + The object attributes for the object + The desired access for the object + Optional transaction manager. + UOW Guid. + The object result. + + + + Open a transaction object. + + The desired access for the object + Optional transaction manager. + UOW Guid. + The object result. + + + + Open a transaction object. + + Optional transaction manager. + UOW Guid. + The object result. + + + + Open a transaction object. + + UOW Guid. + The object result. + + + + Get a list of all accessible transaction objects. + + The object attributes for the object + Optional transaction manager. + The access for the transaction objects. + The list of all accessible transaction objects. + + + + Get a list of all accessible transaction objects. + + The access for the transaction objects. + The list of all accessible transaction objects. + + + + Get a list of all accessible transaction objects. + + The list of all accessible transaction objects. + + + + Get the current thread's transaction. + + + + + Commit the transaction + + Wait for transaction to commit. + True to throw an exception on error. + The NT status code. + + + + Commit the transaction + + Wait for transaction to commit. + + + + Commit the transaction + + + + + Rollback the transaction + + Wait for transaction to rollback. + True to throw an exception on error. + The NT status code. + + + + Rollback the transaction + + Wait for transaction to rollback. + + + + Rollback the transaction + + + + + Enable the transaction for anything in the current thread context. + + The transaction context. This should be disposed to disable the transaction. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get the ID of the transaction. + + + + + Get the Unit of Work ID of the transaction. Same as transaction ID. + + + + + Get the state of the transaction. + + + + + Get the outcome of the transaction. + + + + + Get or set the transaction description. + + + + + Get or set the transaction isolation level. + + + + + Get or set the transaction isolation flags. + + + + + Get or set transaction timeout. + + + + + Query list of enlistments for this transaction. + + + + + Query the superior enlistment for this transaction. + + + + + Class to represent a kernel transaction manager. + + + + + Create a new transaction manager object. + + The object attributes + Desired access for the handle + True to throw an exception on error. + The CLFS log file to create if not volatile. + Creation options flags. + Commit strength, set to 0. + The NT status code and object result. + + + + Create a new transaction manager object. + + The object attributes + Desired access for the handle + The CLFS log file to create if not volatile. + Creation options flags. + Commit strength, set to 0. + The object result. + + + + Create a new transaction manager object. + + The path to the transaction manager. + The root if path is relative. + Desired access for the handle + The CLFS log file to create if not volatile. + Creation options flags. + True to throw an exception on error. + The object result. + + + + Create a new transaction manager object. + + The path to the transaction manager. + The root if path is relative. + Desired access for the handle + The CLFS log file to create if not volatile. + Creation options flags. + The object result. + + + + Create a new volatile transaction manager object. + + The path to the transaction manager. + The root if path is relative. + Desired access for the handle + The object result. + + + + Create a new volatile transaction manager object. + + The path to the transaction manager. + The root if path is relative. + The object result. + + + + Create a new volatile transaction manager object. + + The path to the transaction manager. + The object result. + + + + Create a new volatile transaction manager object. + + The object result. + + + + Open a existing transaction manager object. + + The object attributes + Desired access for the handle + The CLFS log file to create if not volatile. + Identity of the transaction manager. + Open options flags. + True to throw an exception on error. + The NT status code and object result. + + + + Open a existing transaction manager object. + + The object attributes + Desired access for the handle + Identity of the transaction manager. + The CLFS log file to create if not volatile. + Open options flags. + The object result. + + + + Open an existing transaction manager object. + + The path to the transaction manager. + The root if path is relative. + Desired access for the handle + Identity of the transaction manager. + The CLFS log file to create if not volatile. + Open options flags. + True to throw an exception on error. + The object result. + + + + Open an existing transaction manager object. + + The path to the transaction manager. + The root if path is relative. + Desired access for the handle + Identity of the transaction manager. + The CLFS log file to create if not volatile. + Open options flags. + The object result. + + + + Open an existing transaction manager object. + + The path to the transaction manager. + The root if path is relative. + Desired access for the handle + The object result. + + + + Open an existing transaction manager object. + + The path to the transaction manager. + The root if path is relative. + The object result. + + + + Open an existing transaction manager object. + + The path to the transaction manager. + The object result. + + + + Rename transaction manager object. The new identity can be queried with the Identity property on the object. + + The path to the transaction log file. + The existing transaction manager identity. + True to throw an exception on error. + The NT status code + + + + Get a list of all accessible transaction manager objects. + + Object attributes for opened handle. + The access for the transaction manager objects. + Open options. + The list of all accessible transaction manager objects. + + + + Get a list of all accessible transaction manager objects. + + The access for the transaction manager objects. + The list of all accessible transaction manager objects. + + + + Get a list of all accessible transaction manager objects. + + The list of all accessible transaction manager objects. + + + + Get the Transaction Manager identity. + + + + + Get the Transaction Manager virtual clock. + + + + + Get the Transaction Manager log identity. + + + + + Get the Transaction Manager log path. + + + + + Get Transaction Manager last recovered Log Sequence Number. + + + + + Get whether the transaction manager is volatile. + + + + + Rename transaction manager object. The new identity can be queried with the Identity property on the object. + + True to throw an exception on error. + The NT status code + + + + Rename transaction manager object. The new identity can be queried with the Identity property on the object. + + + + + Recover the transaction manager. + + True to throw an exception on error. + The NT status code + + + + Recover the transaction manager. + + + + + Rollforward the transaction manager. + + Optional virtual block value to rollforward to. + True to throw an exception on error. + The NT status code + + + + Rollforward the transaction manager. + + True to throw an exception on error. + The NT status code + + + + Rollforward the transaction manager. + + Optional virtual block value to rollforward to. + + + + Rollforward the transaction manager. + + + + + Create a resource manager for this transaction manager. + + The resource manager GUID to assign. + Creation options. + True to throw on error. + The resource manager and NT status. + + + + Create a resource manager for this transaction manager. + + The resource manager GUID to assign. + Creation options. + The resource manager . + + + + Create a resource manager for this transaction manager. + + The resource manager GUID to assign. + The resource manager. + + + + Create a volatile resource manager for this transaction manager with a auto-generated GUID. + + The resource manager. + + + + Method to query information for this object type. + + The information class. + The buffer to return data in. + Return length from the query. + The NT status code for the query. + + + + Method to set information for this object type. + + The information class. + The buffer to set data from. + The NT status code for the set. + + + + Query the information class as an object. + + The information class. + True to throw on error. + The information class as an object. + + + + Get a list of all accessible transaction objects owned by this transaction manager. + + The access for the transaction objects. + The list of all accessible transaction objects. + + + + Get a list of all accessible transaction objects owned by this transaction manager. + + The list of all accessible transaction objects. + + + + Get a list of all accessible resource manager objects owned by this transaction manager. + + Object attributes for opened handle. + The access for the resource manager objects. + The list of all accessible resource manager objects. + + + + Get a list of all accessible resource manager objects owned by this transaction manager. + + The access for the resource manager objects. + The list of all accessible resource manager objects. + + + + Get a list of all accessible resource manager objects owned by this transaction manager. + + The list of all accessible resource manager objects. + + + + General utilities for the kernel transaction manager. + + + + + Enumerate transaction objects of a specific type from a root handle. + + The root handle to enumearate from. + The type of object to query. + The list of enumerated transaction object GUIDs. + + + + Enumerate all transaction objects of a specific type. + + The type of object to query. + The list of enumerated transaction object GUIDs. + + + + Freeze all transactions. Needs SeRestorePrivilege. + + The freeze wait timeout. + The thaw wait timeout. + Throw exception on error. + The NT status code. + + + + Freeze all transactions. Needs SeRestorePrivilege. + + The freeze wait timeout. + The thaw wait timeout. + + + + Thaw transactions. Needs SeRestorePrivilege. + + Throw exception on error. + The NT status code. + + + + Thaw transactions. Needs SeRestorePrivilege. + + The NT status code. + + + + Class representing an NT object type + + + + + The name of the type + + + + + The mapping from generic to specific object rights + + + + + The valid access mask + + + + + True if the object needs security even if unnamed + + + + + Total number of objects (when originally retrieved) + + + + + Total number of handles (when originally retrieved) + + + + + Total paged pool usage (when originally retrieved) + + + + + Total non-paged pool usage (when originally retrieved) + + + + + Total name pool usage (when originally retrieved) + + + + + Total handle table usage (when originally retrieved) + + + + + Maximum number of objects (when originally retrieved) + + + + + Maximum number of handles (when originally retrieved) + + + + + Maximum paged pool usage (when originally retrieved) + + + + + Maximum non-paged pool usage (when originally retrieved) + + + + + Maximum name pool usage (when originally retrieved) + + + + + Maximum handle table usage (when originally retrieved) + + + + + The attributes flags which are invalid + + + + + Indicates whether handle count is mainted + + + + + Indicates the type list maintained + + + + + Indicates the type of pool used in allocations + + + + + Current paged pool usage + + + + + Current non-pages pool usage + + + + + Type Index + + + + + Generic Read Access rights + + + + + Generic Read Access rights + + + + + Generic Read Access rights + + + + + Generic Read Access rights + + + + + Get the maximum access mask for the type's default mandatory access policy. + + + + + Get implemented object type for this NT type. + + + + + Get the access rights enumerated type for this NT type. + + + + + Get the access rights enumerated type for this NT type if it's a container. + + There's only one known type at the moment which uses this, File. + + + + Can this type of open be opened by name + + + + + Get the valid access rights for this Type. + + + + + Get the valid read access rights for this Type. + + + + + Get the valid write access rights for this Type. + + + + + Get the valid execute access rights for this Type. + + + + + Get the valid all access rights for this Type. + + + + + Get the valid mandatory access rights for this Type. + + + + + Get defined query information classes for a type. + + + + + Get defined set information classes for a type. + + + + + Open this NT type by name (if CanOpen is true) + + The object attributes to open. + Desired access when opening. + True to throw an exception on error. + The NT status code and object result. + + + + Open this NT type by name (if CanOpen is true) + + The name of the object to open. + The root object for opening, if name is relative + Desired access when opening. + The created object. + Thrown on error + + + + Open this NT type by name (if CanOpen is true) + + The name of the object to open. + The root object for opening, if name is relative + The created object. + Thrown on error + + + + Open this NT type by name (if CanOpen is true) + + The name of the object to open. + The created object. + Thrown on error + + + + Get object from an existing handle. + + The existing handle. + The new object. + + + + Get object from an existing handle. + + The existing handle. + True to own the handle. + The new object. + + + + Get object from an existing handle. + + The existing handle. + The call doesn't own the handle. The returned object can't be used to close the handle. + The new object. + + + + Convert an enumerable access rights to a string + + True to use the container access type. + The granted access mask. + True to try and convert to generic rights where possible. + Set to true to use SDK style names. + The string format of the access rights + + + + Convert an enumerable access rights to a string + + True to use the container access type. + The granted access mask. + True to try and convert to generic rights where possible. + The string format of the access rights + + + + Convert an enumerable access rights to a string + + The granted access mask. + True to try and convert to generic rights where possible. + The string format of the access rights + + + + Convert an enumerable access rights to a string + + The granted access mask. + The string format of the access rights + + + + Checks if an access mask represents a read permission on this type + + The access mask to check + True if it has read permissions + + + + Checks if an access mask represents a write permission on this type + + The access mask to check + True if it has write permissions + + + + Checks if an access mask represents a execute permission on this type + + The access mask to check + True if it has execute permissions + + + + Checks if an access mask represents a full permission on this type + + The access mask to check + True if it has full permissions + + + + Map generic access rights to specific access rights for this type + + The access mask to map + The mapped access mask + + + + Unmap specific access rights to generic access rights for this type + + The access mask to unmap + The unmapped access mask + + + + Checks if an access mask is valid for access of this object type. + + The access mask to check + True if it valid access + + + + Get the maximum access mask for the type's default mandatory access policy. + + The allowed access mask for the type with the default policy. + + + + Overridden ToString method. + + Returns the type as a string. + + + + Create an NtType object by name. + + The name of the NT type. + This will always return a cached type. + Invalid NT type name. + + + + Get a type object by index + + The index + The object type, null if not found + + + + Get a type object by index + + The index, must be >= 0. + True to get a cached type, false to return a live types. + The object type, null if not found + + + + Get a type object by name + + The name of the type + True to create a fake type if needed. + True to get a cached type, false to return a live types. + The object type, null if not found + + + + Get a type object by name + + The name of the type + True to create a fake type if needed. + The object type, null if not found + + + + Get a type object by name + + The name of the type + The object type, null if not found + + + + Get a type object by a kernel handle. + + The kernel handle. + True to create a fake type if needed. + The object type, null if not found + + + + Get an NT type based on the implemented .NET type. + + A type derived from NtObject + True to get a cached type, false to return a live types. + The NtType represented by this .NET type. Note if a type is represented with multiple + names only return the first one we find. + Thrown if there exists no .NET type which maps to this type. + + + + Get an NT type based on the implemented .NET type. + + A type derived from NtObject + The NtType represented by this .NET type. Note if a type is represented with multiple + names only return the first one we find. + Thrown if there exists no .NET type which maps to this type. + + + + Get a fake type object. This can be used in access checking for operations which need an NtType object + but there's no real NT object. + + The name of the fake type. Informational only. + The GENERIC_MAPPING for security checking. + The access rights enumeration type. + The access rights enumeration type of the object is a container. + The mandatory label policy. + The fake NT type object. + + + + Get a fake type object. This can be used in access checking for operations which need an NtType object + but there's no real NT object. + + The name of the fake type. Informational only. + The GENERIC_MAPPING for security checking. + The access rights enumeration type. + The access rights enumeration type of the object is a container. + The fake NT type object. + + + + Get a fake type object. This can be used in access checking for operations which need an NtType object + but there's no real NT object. + + The name of the fake type. Informational only. + The GENERIC_MAPPING for security checking. + The access rights enumeration type. + The fake NT type object. + + + + Get a fake type object. This can be used in access checking for operations which need an NtType object + but there's no real NT object. + + The name of the fake type. Informational only. + The GENERIC_READ for security checking. + The GENERIC_WRITE for security checking. + The GENERIC_EXECUTE for security checking. + The GENERIC_ALL for security checking. + The access rights enumeration type. + The access rights enumeration type of the object is a container. + The fake NT type object. + + + + Get a fake type object. This can be used in access checking for operations which need an NtType object + but there's no real NT object. + + The name of the fake type. Informational only. + The GENERIC_READ for security checking. + The GENERIC_WRITE for security checking. + The GENERIC_EXECUTE for security checking. + The GENERIC_ALL for security checking. + The access rights enumeration type. + The fake NT type object. + + + + Get a list of all types. + + The list of types. + + + + Get a list of all types. + + True to get the cached list of types, false to return a live list of all types. + True to include fake types such as WNF or Service + The list of types. + + + + Get a list of all types. + + True to get the cached list of types, false to return a live list of all types. + The list of types. + + + + Get the NT type from a path. + + The object manager path. + Optional root object. + The NT type. Returns null if not available or unknown. + + + + Converted user process parameters. + + + + + Static class to access virtual memory functions of NT. + + + + + Query section name, + + The process to query from. + The base address to query. + True to throw on error + The result of the query. + + + + Query section name, + + The process to query from. + The base address to query. + The result of the query. + + + + Query memory information for a process. + + The process to query. + The base address. + True to throw on error. + The memory information for the region. + Thrown on error. + + + + Query memory information for a process. + + The process to query. + The base address. + The memory information for the region. + Thrown on error. + + + + Query all memory information regions in process memory. + + The list of memory regions. + Thrown on error. + + + + Query a list of mapped files in a process. + + The process to query. + The list of mapped images + Thrown on error. + + + + Read memory from a process. + + The process to read from. + The base address in the process. + The length to read. + The array of bytes read from the location. + If a read is short then returns fewer bytes than requested. + Thrown on error. + + + + Write memory to a process. + + The process to write to. + The base address in the process. + The data to write. + The number of bytes written to the location + Thrown on error. + + + + Read structured memory from a process. + + The process to read from. + The base address in the process. + The read structure. + Thrown on error. + Type of structure to read. + + + + Write structured memory to a process. + + The process to write to. + The base address in the process. + The data to write. + Thrown on error. + Type of structure to write. + + + + Read structured memory array from a process. + + The process to read from. + The base address in the process. + The number of elements in the array to read. + The read structure. + Thrown on error. + Type of structure to read. + + + + Write structured memory array to a process. + + The process to write to. + The base address in the process. + The data array to write. + Thrown on error. + Type of structure to write. + + + + Allocate virtual memory in a process. + + The process to allocate in. + Optional base address, if 0 will automatically select a base. + The region size to allocate. + The type of allocation. + The allocation protection. + True to throw on error. + The address of the allocated region. + Thrown on error. + + + + Allocate virtual memory in a process. + + The process to allocate in. + Optional base address, if 0 will automatically select a base. + The region size to allocate. + The type of allocation. + The allocation protection. + The address of the allocated region. + Thrown on error. + + + + Free virtual emmory in a process. + + The process to free in. + Base address of region to free + The size of the region. + The type to free. + Thrown on error. + + + + Free virtual emmory in a process. + + The process to free in. + Base address of region to free + The size of the region. + The type to free. + True to throw on error. + Thrown on error. + + + + Change protection on a region of memory. + + The process to change memory protection + The base address + The size of the memory region. + The new protection type. + The old protection for the region. + Thrown on error. + + + + Change protection on a region of memory. + + The process to change memory protection + The base address + The size of the memory region. + The new protection type. + True to throw on error. + The old protection for the region. + Thrown on error. + + + + Query working set information for an address in a process. + + The process to query. + The base address to query. + True to throw on error + The working set information. + Thrown on error. + + + + Query working set information for an address in a process. + + The process to query. + The base address to query. + The working set information. + Thrown on error. + + + + Query image information for an address in a process. + + The process to query. + The base address to query. + True to throw on error + The image information. + Thrown on error. + + + + Query image information for an address in a process. + + The process to query. + The base address to query. + The image information. + Thrown on error. + + + + Determine if two addresses are the same mapped file. + + The first address. + The second address. + True to throw on error. + True if the mapped memory is the same file. + + + + Determine if two addresses are the same mapped file. + + The first address. + The second address. + True if the mapped memory is the same file. + + + + Flush instruction cache. + + The process to flush the cache in. + The address to flush. + The number of bytes to flush/ + True to throw on error. + The NT status code. + + + + Flush instruction cache. + + The process to flush the cache in. + The address to flush. + The number of bytes to flush/ + + + + Native Wait methods. + + + + + Wait on a single object to become signaled + + The object to wait on + Whether the thread should be alertable + The timeout to wait for + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + + + + Wait on multiple objects to become signaled + + The objects to wait on + Whether the thread should be alerable + True to wait for all objects to be signaled + The timeout to wait for + The success status of the wait, such as STATUS_WAIT_OBJECT_0 or STATUS_TIMEOUT + + + + Signal an object then wait for another to become signaled. + + The object to signal + The object to wait on. + Whether the thread should be alertable + The timeout to wait for + The success status of the wait, such as STATUS_SUCCESS or STATUS_TIMEOUT + + + + A .NET wait handle to use for interop. + + + + + Create a .NET wait handle from an object. + + The object to create the wait handle on + + + + Wait asynchronously for the handle to be signaled. + + Timeout in milliseconds. + Cancellation token for wait. + A task to wait on. If result is true then event was signaled. + + + + Wait asynchronously for the handle to be signaled. + + Timeout in milliseconds. + A task to wait on. If result is true then event was signaled. + + + + Wait asynchronously for the handle to be signaled. + Will wait an infinite time. + + A task to wait on. + + + + Class to represent an NT timeout + + + + + Get a timeout which will wait indefinitely. + + + + + Get a relative timeout in seconds. + + The number of seconds to wait. + An instance of the timeout class. + + + + Get a relative timeout in milliseconds. + + The number of milliseconds to wait. + An instance of the timeout class. + + + + Get an absolute time out from system start. + + The absolute time to wait until. + An instance of the timeout class. + + + + Get a relative time out from the current time. + + The relative time to wait in units of 100ns. + An instance of the timeout class. + + + + Create an absolute wait timeout from a datetime. + + The time for the timeout to complete. + An instance of the timeout class. + + + + The timeout as a long. + + + + + Overridden ToString method. + + The timeout as a string. + + + + Well-known IO Control codes. + + + + + Convert a control code to a known name. + + The control code. + The known name, or an empty string. + + + + Get a list of known control codes. + + The list of known control codes. + + + + Get a list of known control codes. + + The control code. + Thrown if can't find name. + + + + Structure to represent a Window. + + + + + The Window Handle. + + + + + Get Process ID for the Window. + + + + + Get the Thread ID for the Window. + + + + + Get the real owner Process ID of the Window. + + + + + Get the class name for the Window. + + + + + Send a message to the Window, Unicode. + + The message to send. + The WPARAM. + The LPARAM. + The send result. + + + + Send a message to the Window, ANSI. + + The message to send. + The WPARAM. + The LPARAM. + The send result. + + + + Post a message to the Window, Unicode. + + The message to send. + The WPARAM. + The LPARAM. + True to throw on error. + The send result. + + + + Post a message to the Window, Unicode. + + The message to send. + The WPARAM. + The LPARAM. + The send result. + + + + Send a message to the Window, ANSI. + + The message to send. + The WPARAM. + The LPARAM. + True to throw on error. + The send result. + + + + Send a message to the Window, ANSI. + + The message to send. + The WPARAM. + The LPARAM. + The send result. + + + + Constructor. + + Window handle. + + + + Constructor. + + Window handle. + + + + Get the NULL window handle. + + + + + Get the desktop window. + + + + + Get the broadcast window. + + + + + Get all Top Level windows. + + + + + Enumerate window handles. + + Desktop containing the Windows. Optional. + The parent Window. Optional. + True to enumerate child Windows. + Hide immersive Windows. + The thread ID that owns the Window. + True to throw on error. + The enumerated Window Handles. + + + + Enumerate window handles. + + Desktop containing the Windows. Optional. + The parent Window. Optional. + True to enumerate child Windows. + Hide immersive Windows. + The thread ID that owns the Window. + The enumerated Window Handles. + + + + Class which represents a window station object. + + + + + Open a window station by name. + + The object attributes for opening. + Desired access. + True to throw on error. + The instance of the window station + Thrown on error. + + + + Open a window station by name. + + The object attributes for opening. + Desired access. + The instance of the window station + Thrown on error. + + + + Open a window station by name. + + The name of the window station + Optional root object + The instance of the window station + Thrown on error. + + + + Open a window station by name. + + + The instance of the window station + Thrown on error. + + + + Create a Window Station by name. + + Object attributes for the Window Station. + Desired access for the Window Station. + Path to Keyboard DLL e.g. kbusa.dll. + Locale ID, e.g. 0x4090409. + Language ID e.g. 0x409. + True to throw on error. + The Window Station. + + + + Create a Window Station by name. + + Object attributes for the Window Station. + Desired access for the Window Station. + Path to Keyboard DLL e.g. kbusa.dll. + Locale ID, e.g. 0x4090409. + Language ID e.g. 0x409. + The Window Station. + + + + Create a Window Station by name. + + The name of the Window Station. + The Window Station. + + + + Get a list of desktops for this Window Station. + + + + + Enumerate name of Window Stations in current session. + + + + + Get a list of accessible Window Station objects. + + The desired access for the Window Stations. + The list of desktops. + + + + Get a list of accessible Window Station objects. + + The list of desktops. + + + + Get a list of accessible desktop objects. + + The desired access for the desktops. + The list of desktops. + + + + Get a list of accessible desktop objects. + + The list of desktops. + + + + Close the Window Stations. This is different from normal Close as it destroys the Window Station. + + True to throw on error. + The NT status. + + + + Set the Window Station for the Process. + + True to throw on error. + The NT status. + + + + Open the current process Window Station. + + True to throw on error. + The instance of the window station + The returned object is no owned by the caller. + Thrown on error. + + + + Open the current process Window Station. + + + + + Get the Window Station directory for a session. + + The session ID. + The path to the Window Station directory. + + + + Get the Window Station directory for the current session. + + The path to the Window Station directory. + + + + NT WNF object. + + + + + Get the generic mapping for a + + + + + Fake NT type name for WNF. + + + + + Create a new WNF state name. + + The lifetime of the name. + The scope of the data. + Whether to persist data. + Optional type ID. + Maximum state size. + Mandatory security descriptor. + True to throw on error. + The created object. + + + + Kernel derived key which is used to mask the state name. + + + + + Create a new WNF state name. + + The lifetime of the name. + The scope of the data. + Whether to persist data. + Optional type ID. + Maximum state size. + Mandatory security descriptor. + The created object. + + + + Open a state name. Doesn't check if it exists. + + The statename to open. + True to check state name exists. + True to throw on error. + The created object. + + + + Open a state name. Doesn't check if it exists. + + The statename to open. + True to check state name exists. + The created object. + + + + Open a state name. Doesn't check if it exists. + + The statename to open. + The created object. + + + + Open a state name. Doesn't check if it exists. + + The name to open. + True to check state name exists. + The created object. + + + + Open a state name. Doesn't check if it exists. + + The name to open. + The created object. + + + + Get registered notifications. + + The list of registered notifications. + + + + Get the state name for this WNF entry. + + + + + The state name decoded. + + + + + Get the associated lifetime for the state name. + + + + + Version of the WNF state name. + + + + + Data scope of WNF state name. + + + + + Is WNF state name persistent. + + + + + Unique identifier of WNF state name, + + + + + Get if the state has subscribers. + + + + + Get the security descriptor for this object, if known. + + + + + Get a name for the WNF notification. + + + + + Query state data for the WNF object. + + Optional Type ID. + Optional explicit scope. + True to throw on error. + The state data. + + + + Query state data for the WNF object. + + Optional Type ID. + Optional explicit scope. + The state data. + + + + Query state data for the WNF object. + + The state data. + + + + Update state data for the WNF object. + + The data to set. + Optional Type ID. + Optional explicit scope. + Optional matching changestamp. + True to throw on error. + The status from the update. + + + + Update state data for the WNF object. + + The data to set. + + + + Delete the state data for the WNF object. + + Optional explicit scope. + True to throw on error. + The NT status code. + + + + Delete the state data for the WNF object. + + Optional explicit scope. + + + + Delete the state data for the WNF object. + + + + + Overridden ToString method. + + The string representation. + + + + Get dictionary of well known WNF state names. + + This was dumped from perf_nt_c.dll 10.0.18362.1 using https://github.com/ionescu007/wnfun. + + + + Get the state name to name mappings. + + + + + Get the name to state name mappings. + + + + + Get the name of a state name if known. + + The state name. + The name of the state name, or null if unknown. + + + + Flags for OBJECT_ATTRIBUTES + + + + + None + + + + + Handle is protected from closing. + + + + + The handle created can be inherited + + + + + Audit handle close. + + + + + The object created is marked as permanent + + + + + The object must be created exclusively + + + + + The object name lookup should be done case insensitive + + + + + Open the object if it already exists + + + + + Open the object as a link + + + + + Create as a kernel handle (not used in user-mode) + + + + + Force an access check to occur (not used in user-mode) + + + + + Ignore impersonated device map when looking up object + + + + + Fail if a reparse is encountered + + + + + A class which represents OBJECT_ATTRIBUTES + + + + + Constructor. Sets flags to None + + + + + Constructor + + The name of the object + Attribute flags + + + + Constructor + + The name of the object + Attribute flags + A root object to lookup a relative path + + + + Constructor + + Attribute flags + + + + Constructor + + The name of the object + + + + Constructor + + An object ID. + The object attribute flags. + An optional root handle, can be SafeKernelObjectHandle.Null. Will duplicate the handle. + An optional security quality of service. + An optional security descriptor. + + + + Constructor + + The object name, can be null. + The object attribute flags. + An optional root handle, can be SafeKernelObjectHandle.Null. Will duplicate the handle. + An optional security quality of service. + An optional security descriptor. + + + + Constructor + + The object name, can be null. + The object attribute flags. + An optional root handle, Will duplicate the handle. + An optional security quality of service. + An optional security descriptor. + + + + Create an Object Attributes structure with a raw name. Useful for Object ID handling. + + The name of the object in raw bytes. + The object attribute flags. + An optional root handle, Will duplicate the handle. + An optional security quality of service. + An optional security descriptor. + The created object attributes. + + + + Dispose + + + + + Object type entry for an access check. + + + + + The object level. + + + + + The object type GUID. + + + + + The name of the object. + + + + + Constructor. + + + + + Constructor. + + The object type GUID. + The object level. + The name of the object type entry. + + + + Constructor. + + The object type GUID. + The object level. + + + + Constructor. + + The object type GUID. + + + + Overridden ToString method. + + The object formatted. + + + + This class allows a function to specify an optional Guid + + + + + Optional Guid + + + + + Constructor + + The GUID to initialize + + + + Constructor + + + + + Implicit conversion + + The value + + + + This class allows a function to specify an optional uint16. + + + + + Optional value + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value + + + + This class allows a function to specify an optional int32. + + + + + Optional value + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value + + + + This class allows a function to specify an optional int64. + + + + + Optional value + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value + + + + This class allows a function to specify an optional length as a SizeT + + + + + Optional length + + + + + Constructor + + The length value + + + + Constructor + + The length value + + + + Constructor + + The length value + + + + Implicit conversion + + The length value + + + + This class allows a function to specify an optional pointer. + + + + + Optional length + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value + + + + Optional value. + + + + + Optional value. + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value. + + + + Optional value. + + + + + Optional value. + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value. + + + + Optional value. + + + + + Optional value. + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value. + + + + Optional value. + + + + + Optional value. + + + + + Constructor + + The value + + + + Constructor + + + + + Implicit conversion + + The value. + + + + The result of a privilege check. + + + + + The list of privileges from the result. + + + + + The list of enabled privileges. + + + + + True indicates all privileges were held. + + + + + A single process module. + + + + + The module section. + + + + + Mapped base. + + + + + Image base. + + + + + Image size. + + + + + Flags. + + + + + Load order index. + + + + + Init order index. + + + + + Load count. + + + + + Full path name. + + + + + File name. + + + + + Reparse Tag value. + + + + + Base class for a reparse buffer. + + + + + The reparse tag in the buffer. + + + + + Function to initialize this class by parsing the reparse buffer data (not including header). + + The length of the data to read. + The stream to read from. + + + + Get reparse buffer data as a byte array (not including header). + + The reparse buffer data. + + + + Constructor. + + The reparse tag to assign. + + + + Get a reparse buffer from a byte array. + + The byte array to parse + The reparse buffer. + + + + Get a reparse buffer from a byte array. + + The byte array to parse + True to return an opaque buffer if + the tag isn't known, otherwise try and parse as a generic buffer + The reparse buffer. + + + + Convert reparse buffer to a byte array in REPARSE_DATA_BUFFER format. + + The reparse buffer as a byte array. + + + + Convert reparse buffer to a byte array in the REPARSE_DATA_BUFFER_EX format. + + Flags for the buffer. + Existing GUID to match against. + Existing tag to matcha against. + The reparse buffer as a byte array. + + + + Get if a reparse tag is a Microsoft defined one. + + + + + Get if a reparse tag is a name surrogate. + + True if it's a surrogate reparse tag. + + + + Get if a reparse tag is a directory. + + + + + Generic GUID reparse buffer. + + + + + Constructor. + + The reparse tag. + The reparse GUID + Additional reparse data. + + + + Constructor. + + The reparse tag. + The reparse GUID + Additional reparse data. + + + + The reparse GUID. + + + + + Additional reparse data. + + + + + Get reparse buffer data as a byte array (not including header). + + The reparse buffer data. + + + + Function to initialize this class by parsing the reparse buffer data (not including header). + + The length of the data to read. + The stream to read from. + + + + Reparse buffer with an opaque data blob. + + + + + Constructor. + + The reparse tag. + The opaque data blob. + + + + The opaque data blob. + + + + + Get reparse buffer data as a byte array (not including header). + + The reparse buffer data. + + + + Function to initialize this class by parsing the reparse buffer data (not including header). + + The length of the data to read. + The stream to read from. + + + + Reparse buffer for an NTFS mount point. + + + + + Constructor. + + Substitution name to reparse to when accessing mount point. + Printable name for the mount point. + + + + Substitution name to reparse to when accessing mount point. + + + + + Printable name for the mount point. + + + + + Function to initialize this class by parsing the reparse buffer data (not including header). + + The length of the data to read. + The stream to read from. + + + + Get reparse buffer data as a byte array (not including header). + + The reparse buffer data. + + + + Symlink flags. + + + + + None. + + + + + Substitution name is relative to the symlink. + + + + + Reparse buffer for an NTFS symlink. + + + + + Constructor. + + Substitution name to reparse to when accessing symlink. + Printable name for the symlink. + Symlink flags. + + + + Constructor. + + Substitution name to reparse to when accessing symlink. + Printable name for the symlink. + Symlink flags. + Create a global symlink rather than a normal symlink. + + + + Substitution name to reparse to when accessing symlink. + + + + + Printable name for the symlink. + + + + + Symlink flags. + + + + + Function to initialize this class by parsing the reparse buffer data (not including header). + + The length of the data to read. + The stream to read from. + + + + Get reparse buffer data as a byte array (not including header). + + The reparse buffer data. + + + + Application type for execution alias. + + + + + Desktop bridge application. + + + + + UWP type 1 + + + + + UWP type 2 + + + + + UWP type 3 + + + + + Reparse buffer for an execution alias. + + + + + The execution alias version. + + + + + The name of the application package. + + + + + The entry point in the package. + + + + + The target executable. + + + + + Application type for the alias. + + + + + Flags, obsolete. + + + + + Constructor. + + The execution alias version. + The name of the application package. + The entry point in the package. + The target executable. + Apptype for the alias. + + + + Get reparse buffer data as a byte array (not including header). + + The reparse buffer data. + + + + Function to initialize this class by parsing the reparse buffer data (not including header). + + The length of the data to read. + The stream to read from. + + + + Safe buffer for an ALPC data view. + + + + + Flags for the data view. + + + + + Get the port section handle. + + + + + Convert the section view to a message attribute. + + The message attribute. + + + + Release the data view handle. + + True if successfully released. + + + + Safe buffer to contain an ALPC port message. + + + + + Constructor. + + The port message header. + The total length of allocated memory excluding the header. + + + + Constructor. Creates a receive buffer with a set length. + + The total length of allocated memory excluding the header. + + + + Get a NULL safe buffer. + + + + + Detaches the current buffer and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + Safe handle for a port section. + + + + + Release handle. + + True if handle released successfully. + + + + Safe handle for an ALPC security context. + + + + + Attribute flags. + + + + + Security quality of service. + + + + + Get the security context as a message attribute. + + The message attribute. + + + + Get whether handle is invalid. + + + + + Release handle. + + True if handle released successfully. + + + + Revoke the security context attribute. + + True to throw on error. + The NT status code. + + + + Revoke the security context attribute. + + + + + Safe buffer to contain a list of structures. + + + + + The count of elements of the array. + + + + + Constructor. + + Array of elements. + Additional data to place after the array. + + + + Constructor. + + Array of elements. + + + + Get a reference to the additional data. + + + + + Get a NULL safe array buffer. + + + + + Dispose buffer. + + True if disposing. + + + + Safe buffer which acts as a base class for all other SafeBuffer types in the library. + + + + + Constructor + + Size of the buffer. + An existing pointer to a buffer. + Specify whether safe handle owns the buffer. + Inidicates if the underlying buffer is writable. + + + + Constructor + + Size of the buffer. + An existing pointer to a buffer. + Specify whether safe handle owns the buffer. + + + + Length of the allocation. + + + + + Length of the allocation as a long. + + + + + Get the length as an IntPtr + + + + + Convert the safe handle to an array of bytes. + + The data contained in the allocaiton. + + + + Read a NUL terminated string for the byte offset. + + The byte offset to read from. + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated string + + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated ANSI string for the byte offset. + + The byte offset to read from. + Text encoding for the string. + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated ANSI string + + Text encoding for the string. + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated ANSI string for the byte offset. + + The byte offset to read from. + The string read from the buffer without the NUL terminator + + + + Read a NUL terminated ANSI string + + The string read from the buffer without the NUL terminator + + + + Read a unicode string from the buffer. + + The offset into the buffer to read. + The number of characters to read. + The read unicode string. + + + + Read a unicode string from the buffer. + + The number of characters to read. + The read unicode string. + + + + Write a unicode string to the buffer. + + The offset into the buffer to write. + The value to write. + + + + Write a unicode string to the buffer. + + The value to write. + + + + Read an array of bytes from the buffer. + + The offset into the buffer. + The number of bytes to read. + The read bytes. + + + + Read an array of bytes from the buffer. + + The number of bytes to read. + The read bytes. + + + + Write an array of bytes to the buffer. + + The offset into the buffer. + The bytes to write. + + + + Write an array of bytes to the buffer. + + The bytes to write. + + + + Read array from the buffer. + + The type to read. + The offset into the buffer. + The number of elements to read. + The read array. + + + + Read an array of complex structures which can contain references. Doing this from a buffer is a dangerous operation. + + The buffer type. + The offset into the buffer. + The number of elements. + The array structures. + This doesn't bounds check the buffer size for the array or embedded structures so could easily crash the application. + + + + Zero an entire buffer. + + + + + Fill an entire buffer with a specific byte value. + + The fill value. + + + + Get a structured buffer object at a specified offset. + + The type of structure. + The offset into the buffer. + The structured buffer object. + + + + Get the buffer as a memory stream + + + + + + Create a view accessor over the full buffer. + + The view accessor. + + + + Create a view accessor. + + Offset into the buffer + Size of view. + The view accessor. + + + + Create a view accessor. + + Offset into the buffer + Size of view. + True to make the view writable. False for read-only + The view accessor. + + + + A safe handle to an allocated global buffer. + + + + + Constructor + + Size of the buffer to allocate. + + + + Constructor + + The length of data to allocate. + The total length to reflect in the Length property. + + + + Constructor + + Size of the buffer. + An existing pointer to an existing HGLOBAL allocated buffer. + Specify whether safe handle owns the buffer. + + + + Constructor + + Initialization data for the buffer. + + + + Get a buffer which represents NULL. + + + + + Resize the SafeBuffer. + + + + + + Overridden ReleaseHandle method. + + True if successfully released the memory. + + + + Detaches the current buffer and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + Detaches the current buffer and allocates a new one. + + Specify a new length for the detached buffer. Must be <= Length. + The detached buffer. + The original buffer will become invalid after this call. + + + + Non-generic buffer to hold an IO_STATUS_BLOCK. + + + + + Constructor. + + + + + Get a buffer which represents NULL. + + + + + Safe handle which represents a kernel handle. + + + + + Constructor. + + An existing kernel handle. + True to own the kernel handle. + + + + Overridden ReleaseHandle method. + + True if successfully released the handle. + + + + Overridden IsInvalid method. + + + + + Get a handle which represents NULL. + + + + + Get or set whether the handle is inheritable. + + + + + Get or set whether the handle is protected from closing. + + + + + Get the NT type name for this handle. + + The NT type name. + + + + Overridden ToString method. + + The handle as a string. + + + + Class which is allocated from the process heap. + + + + + Constructor + + Size of the buffer to allocate. + + + + Constructor + + Initialization data for the buffer. + + + + Constructor + + The length of data to allocate. + The total length to reflect in the Length property. + + + + Constructor + + Size of the buffer. + An existing pointer to an existing HGLOBAL allocated buffer. + Specify whether safe handle owns the buffer. + + + + Get a buffer which represents NULL. + + + + + Overridden ReleaseHandle method. + + True if successfully released the memory. + + + + Detaches the current buffer and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + Detaches the current buffer and allocates a new one. + + Specify a new length for the detached buffer. Must be <= Length. + The detached buffer. + The original buffer will become invalid after this call. + + + + Safe SID buffer. + + This is used to return values from the RTL apis which need to be freed using RtlFreeSid + + + + Safe handle for an in/out structure buffer. + + The type of structure as the base of the memory allocation. + + + + Constructor + + Structure value to initialize the buffer. + + + + Constructor, initializes buffer with a default structure. + + + + + Constructor + + Size of the buffer. + An existing pointer to an existing HGLOBAL allocated buffer. + Specify whether safe handle owns the buffer. + + + + Constructor + + Additional data to add to structure buffer. + If true additional_size is added to structure size, otherwise reflects the total size. + An existing pointer to an existing HGLOBAL allocated buffer. + Specify whether safe handle owns the buffer. + + + + Constructor, initializes buffer with a default structure. + + Additional data to add to structure buffer. + If true additional_size is added to structure size, otherwise reflects the total size. + + + + Constructor + + Structure value to initialize the buffer. + Additional data to add to structure buffer. + If true additional_size is added to structure size, otherwise reflects the total size. + + + + Get a buffer which represents NULL. + + + + + Overridden ReleaseHandle method. + + True if successfully released the memory. + + + + Get or set the result structure in the memory buffer. + + + + + Get a reference to the additional data. + + + + + Detaches the current buffer and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + Detaches the current buffer and allocates a new one. + + Specify a new length for the detached buffer. Must be <= Length. + The detached buffer. + The original buffer will become invalid after this call. + + + + Safe buffer for a list of Token groups. + + + + + Constructor. + + The list of SID and attributes. + The list of allocated SIDs. + + + + NULL safe buffer. + + + + + Create a buffer from a list of groups. + + The group list. + The safe buffer. + + + + Dispose. + + True if disposing. + + + + Safe buffer for token privileges. + + + + + Constructor. + + List of privileges. + + + + NULL safe buffer. + + + + + Security descriptor control flags. + + + + + Security descriptor. + + + + + Discretionary access control list (can be null) + + + + + System access control list (can be null) + + + + + Owner (can be null) + + + + + Group (can be null) + + + + + Get or set Control flags. This is computed based on the current state of the SD. + + + + + Revision value + + + + + The resource manager control flags. + + + + + Get or set an associated NT type for this security descriptor. + + + + + Get or set mandatory label. Returns a medium label if it doesn't exist. + + + + + Get the process trust label. + + + + + Get list of access filters. + + + + + Get list of resource attributes. + + + + + Get the scoped policy ID. + + + + + Get or set the integrity level + + + + + Get or set the server security flag. + + + + + Get or set the DACL untrusted flag. + + + + + Get whether the DACL is present. + + + + + Get count of ACEs in DACL. + + + + + Get whether the SACL is present. + + + + + Get count of ACEs in DACL. + + + + + Indicates if the security descriptor was constructed from a self relative format. + + + + + Indicates if the SD's DACL is canonical. + + + + + Indicates if the SD's SACL is canonical. + + + + + Indicates if the SD's DACL is defaulted. + + + + + Indicates if the SD's SACL is defaulted. + + + + + Indicates if the SD's DACL is auto-inherited. + + + + + Indicates if the SD's SACL is auto-inherited. + + + + + Indicates if the SD came from a container. + + + + + Indicates the SD has audit ACEs present. + + + + + Indicates the SD has a mandatory label ACE present. + + + + + Indicates the SD has a NULL DACL. + + + + + Indicates the SD has a NULL SACL. + + + + + Get the access rights enum type for this SD based on the NT Type property. + + + + + Get the mandatory label. Returns null if it doesn't exist. + + True to include InheritOnly ACEs in the search. + The valid mandatory ACE for this security descriptor. Or null if it doesn't exist. + + + + Get the mandatory label. Returns null if it doesn't exist. + + The valid mandatory ACE for this security descriptor. Or null if it doesn't exist. + + + + Convert security descriptor to a byte array + + The binary security descriptor + + + + Convert security descriptor to SDDL string + + The parts of the security descriptor to return + True to throw on error. + The SDDL string + + + + Convert security descriptor to SDDL string + + The parts of the security descriptor to return + The SDDL string + + + + Convert security descriptor to SDDL string + + True to throw on error. + The SDDL string + + + + Convert security descriptor to SDDL string + + The SDDL string + + + + Converts the security to a base64 string. + + True to insert line breaks in the base64. + The relative SD as a base64 string. + + + + Converts the security to a base64 string. + + The relative SD as a base64 string. + + + + Convert security descriptor to a safe buffer. + + True to return an absolute security descriptor, false for self-relative. + True to throw on error. + A safe buffer for the security descriptor. + + + + Convert security descriptor to a safe buffer. + + True to return an absolute security descriptor, false for self-relative. + A safe buffer for the security descriptor. + + + + Convert security descriptor to a safe buffer. + + A safe buffer for the security descriptor. + This returns a self-relative security descriptor. + + + + Add an ACE to the DACL, creating the DACL if needed. + + The ACE to add to the DACL. + + + + Add an ACE to the SACL, creating the SACL if needed. + + The ACE to add to the SACL. + + + + Add an access allowed ACE to the DACL + + The access mask + The ACE flags + The SID in SDDL form + + + + Add an access allowed ACE to the DACL + + The access mask + The SID in SDDL form + + + + Add an access allowed ACE to the DACL + + The access mask + The ACE flags + The SID + + + + Add an access allowed ACE to the DACL + + The access mask + The SID + + + + Add an access denied ACE to the DACL + + The access mask + The ACE flags + The SID in SDDL form + + + + Add an access denied ACE to the DACL + + The access mask + The SID in SDDL form + + + + Add an access denied ACE to the DACL + + The access mask + The SID + + + + Add an access denied ACE to the DACL + + The access mask + The ACE flags + The SID + + + + Add an audit success ACE to the SACL + + The access mask + The SID in SDDL form + + + + Add an audit success ACE to the SACL + + The access mask + The SID + + + + Add an access denied ACE to the DACL + + The access mask + The SID in SDDL form + + + + Add an audit fail ACE to the SACL + + The access mask + The SID + + + + Add mandatory integrity label to SACL + + The integrity level + + + + Add mandatory integrity label to SACL + + The integrity level + The mandatory label policy + + + + Add mandatory integrity label to SACL + + The integrity level + The ACE flags. + The mandatory label policy + + + + Add mandatory integrity label to SACL + + The integrity label SID + The ACE flags. + The mandatory label policy + + + + Removes the mandatory label if it exists. + + + + + Map all generic access in this security descriptor to the default type specified by NtType. + + + + + Map all generic access in this security descriptor to a specific type. + + The type to get the generic mapping from. + + + + Map all generic access in this security descriptor to a specific type. + + The generic mapping. + + + + Unmap all generic access in this security descriptor to the default type specified by NtType. + + + + + Unmap all generic access in this security descriptor to a specific type. + + The type to get the generic mapping from. + + + + Unap all generic access in this security descriptor to a specific type. + + The generic mapping. + + + + Modifies a security descriptor from a new descriptor. + + The security descriptor to update with. + The parts of the security descriptor to update. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + True to throw on error. + The NT status code. + + + + Modifies a security descriptor from a new descriptor. + + The security descriptor to update with. + The parts of the security descriptor to update. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + + + + Converts the SD to an Auto-Inherit security descriptor. + + The parent security descriptor. + Optional object type GUID. + True if a directory. + Generic mapping for the object. + True to throw on error. + The NT status code. + + + + Converts the SD to an Auto-Inherit security descriptor. + + The parent security descriptor. + Optional object type GUID. + True if a directory. + Generic mapping for the object. + + + + Canonicalize the DACL if it exists. + + + + + Canonicalize the SACL if it exists. + + + + + Standardize security descriptor according to Active Directory rules. + + + + + Clone the security descriptor. + + The cloned security descriptor. + + + + Overridden ToString method. + + The security descriptor as an SDDL string. + + + + Constructor. + + Native pointer to security descriptor. + + + + Constructor. + + The process containing the security descriptor. + Native pointer to security descriptor. + + + + Constructor + + + + + Constructor. + + The NT type for the security descriptor. + + + + Constructor + + Binary form of security descriptor + Optional NT type for security descriptor. + + + + Constructor + + Binary form of security descriptor + + + + Constructor from a token default DACL and ownership values. + + The token to use for its default DACL. + + + + Constructor + + Base object for security descriptor + Token for determining user rights + True if a directory security descriptor + + + + Constructor from an SDDL string + + The SDDL string + Thrown if invalid SDDL + + + + Constructor from an SDDL string + + The SDDL string + Optional NT type for security descriptor. + Thrown if invalid SDDL + + + + Parse a security descriptor. + + Native pointer to security descriptor. + The NT type for the security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + Native pointer to security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + Safe buffer to security descriptor. + The NT type for the security descriptor. + True if the security descriptor is from a container. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + Safe buffer to security descriptor. + The NT type for the security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + Safe buffer to security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + Binary form of security descriptor + The NT type for the security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + Binary form of security descriptor + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + The SDDL form of the security descriptor. + The NT type for the security descriptor. + True if the security descriptor is from a container. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor. + + The SDDL form of the security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor from a base64 string + + The base64 string. + The NT type for the security descriptor. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor from a base64 string + + The base64 string. + True to throw on error. + The parsed Security Descriptor. + + + + Parse a security descriptor from a base64 string + + The base64 string. + The parsed Security Descriptor. + + + + Create a new security descriptor from a parent. + + The parent security descriptor. Can be null. + The creator security descriptor. + Optional list of object type GUIDs. + True if the objec to assign is a directory. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + True to throw on error. + The new security descriptor. + + + + Create a new security descriptor from a parent. + + The parent security descriptor. Can be null. + The creator security descriptor. + Optional list of object type GUIDs. + True if the objec to assign is a directory. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + The new security descriptor. + + + + Create a new security descriptor from a parent. + + The parent security descriptor. Can be null. + The creator security descriptor. + True if the objec to assign is a directory. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + True to throw on error. + The new security descriptor. + + + + Create a new security descriptor from a parent. + + The parent security descriptor. Can be null. + The creator security descriptor. + True if the objec to assign is a directory. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + The new security descriptor. + + + + Create a new security descriptor from a parent. + + The parent security descriptor. Can be null. + The creator security descriptor. + True if the objec to assign is a directory. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + True to throw on error. + The new security descriptor. + + + + Create a new security descriptor from a parent. + + The parent security descriptor. Can be null. + The creator security descriptor. + True if the objec to assign is a directory. + Auto inherit flags. + Optional token for the security descriptor. + Generic mapping. + The new security descriptor. + + + + A security descriptor SID which maintains defaulted state. + + + + + The SID. + + + + + Indicates whether the SID was defaulted or not. + + + + + Constructor from existing SID. + + The SID. + Whether the SID was defaulted or not. + + + + Convert to a string. + + The string form of the SID + + + + Clone the security descriptor SID. + + The cloned SID. + + + + The type of the security attribute name. + + + + + Class to represent an attribute name operand. + + + + + The type of attribute. + + + + + The name of the attribute. + + + + + Constructor. + + The type of the attribute. + The name of the attribute. + + + + Overridden ToString method. + + The object as a string. + + + + Class to represent a composite conditional operand. + + + + + List of operands. + + + + + Constructor. + + + + + Overridden ToString method. + + The object as a string. + + + + Class to represent a conditional expression. + + + + + Serialize the expression to a byte array. + + The expression as a byte array. + + + + Overridden ToString method. + + The object as a string. + + + + Parse a binary conditional expression. + + The data to parse. + True to throw on error. + The parsed conditional expression. + + + + Parse a binary conditional expression. + + The data to parse. + The parsed conditional expression. + + + + Parse an SDDL conditional expression. + + The SDDL expression to parse. + True to throw on error. + The parsed conditional expression. + + + + Parse an SDDL conditional expression. + + The SDDL expression to parse. + The parsed conditional expression. + + + + Get list of the conditional operands. + + + + + Size of conditional integer operand. + + + + + Sign of conditional integer operand. + + + + + Base of conditional integer operand. + + + + + Class to represent a conditional integer operand. + + + + + Size of the integer. + + + + + Value of the integer. + + + + + Sign of the integer. + + + + + Base of the integer. + + + + + Constructor. + + + + + Overridden ToString method. + + The object as a string. + + + + Class to represent an octet string conditional operand. + + + + + The value of the operand. + + + + + Constructor. + + The value of the operand. + + + + Overridden ToString method. + + The object as a string. + + + + Abstract class to represent a conditional expression operand. + + + + + Conditional operator type. + + + + + Class to represent a conditional operator operand. + + + + + The type of operator. + + + + + Constructor. + + The type of operator. + + + + Overridden ToString method. + + The object as a string. + + + + Class to represent a SID conditional operand. + + + + + The SID value. + + + + + Constructor. + + The SID value. + + + + Overridden ToString method. + + The object as a string. + + + + Class to represent a string conditional operand. + + + + + The string value. + + + + + Constructor. + + The string value. + + + + Overridden ToString method. + + The object as a string. + + + + Interface for an NT object to query and set a security descriptor. + + + + + Get the name of the object. + + + + + Get the NtType for this object. + + The NtType for the object. + + + + Get the object's security descriptor. + + + + + Get whether the object is a container. + + + + + Check if access is granted to a set of rights + + The access rights to check + True if all the access rights are granted + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + The NT status code. + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Class representing a Central Access Policy. + + + + + The CAP SID. + + + + + CAP Flags. + + + + + Name of the CAP. + + + + + Description of the CAP. + + + + + Change ID. Normally a date time when changed. + + + + + The list of rules associated with this policy. + + + + + Parse the policy from the registry. + + The base key for the registry policy. + True to throw on error. + The list of Central Access Policies. + + + + Parse the policy from the registry. + + True to throw on error. + The list of Central Access Policies. + + + + Parse the policy from the registry. + + The list of Central Access Policies. + + + + Parse the policy from the Local Security Authority. + + True to throw on error. + The list of Central Access Policies. + + + + Parse the policy from the Local Security Authority. + + The list of Central Access Policies. + + + + Class representing a Central Access Rule. + + + + + CAP Rule Flags. + + + + + Name of the CAP Rule. + + + + + Description of the CAP Rule. + + + + + Change ID. Normally a date time when changed. + + + + + Conditional Expression to determine who to applie the rule to. + + + + + The CAP Rule security descriptor. + + + + + The CAP Rule staged security descriptor. + + + + + Class to represent a Security Identifier. + + + + + Maximum size of a SID buffer. + + + + + The SIDs authority. + + + + + List of the SIDs sub authorities. + + + + + Get the account name of the SID or the SDDL form if no corresponding name. + + + + + Constructor for authority and sub authorities. + + The identifier authority. + The sub authorities. + + + + Constructor for authority and sub authorities. + + The identifier authority. + The sub authorities. + + + + Constructor from an unmanged buffer. + + A pointer to a buffer containing a valid SID. + Thrown if the buffer is not valid. + + + + Constructor from an unmanged buffer. + + A safe buffer containing a valid SID. + Thrown if the buffer is not valid. + + + + Constructor from a safe SID handle. + + A safe SID handle containing a valid SID. + Thrown if the buffer is not valid. + + + + Constructor from an manged buffer. + + A buffer containing a valid SID. + Thrown if the buffer is not valid. + + + + Constructor from existing Sid. + + The existing Sid. + + + + Constructor from an SDDL string. + + The SID in SDDL format. + + new Sid("S-1-0-0"); + new Sid("WD"); + + + + + + Constructor from a SID name. + + The SID name. + + + + Construct a SID from a binary reader. + + The binary reader. + + + + Convert the SID to a safe buffer. + + The safe buffer containing the SID. + + + + Convert to a managed byte array. + + The managed byte array. + + + + Compares two sids to see if their prefixes are the same. The sids must have the same number of subauthorities. + + The sid to compare against + True if the sids share a prefix. + + + + Compare two Sids. + + The other Sid to compare. + True if the Sids are equal. + + + + Equality operator. + + Sid 1 + Sid 2 + True if the Sids are equal. + + + + Inequality operator. + + Sid 1 + Sid 2 + True if the Sids are not equal. + + + + Get hash code. + + The hash code. + + + + Convert to an SDDL format string. + + The SDDL format string (e.g. S-1-1-0) + + + + Does this SID dominate another. + + The other SID. + True to throw on error. + True if the sid dominates. + + + + Does this SID dominate another. + + The other SID. + True if the sid dominates. + + + + Does this SID dominate another for trust. + + The other SID. + True to throw on error. + True if the sid dominates. + + + + Does this SID dominate another for trust. + + The other SID. + True if the sid dominates. + + + + Checks if the SID starts with the specified SID. + + The specified SID to check against. + True if the current SID starts with the specified SID. + + + + Create a SID relative to this one. + + The list of RIDs. + The relative SID. + + + + Create a SID sibling to this SID. + + The RIDs to replace the final RID with. + The sibling SID. + This replaces the final RID with one or more addditional RIDs. + + + + Get the SID name for this SID. + + True to bypass the SID name cache. + The SID name. + + + + Get the SID name for this SID. + + The SID name. + + + + Convert an SDDL SID string to a Sid + + The SDDL SID string + True to throw on error. + The converted Sid + Thrown if cannot convert from a SDDL string. + + + + Convert an SDDL SID string to a Sid + + The SDDL SID string + The converted Sid + Thrown if cannot convert from a SDDL string. + + + + Parse a byte array. + + The byte array to parse. + True to throw on error. + The parsed SID. + + + + Parse a byte array. + + The pointer to parse. + True to throw on error. + The parsed SID. + + + + Predefined security authorities + + + + + Represents an identifier authority for a SID. + + + + + Get a reference to the identifier authority. This can be used to modify the value + + + + + Constructor. + + + + + Construct from an existing authority array. + + The authority, must be 6 bytes in length. + Thrown if authority is not the correct length. + + + + Constructor from a simple predefined authority. + + The predefined authority. + + + + Construct from an Int64. + + The authority as an Int64. + + + + Compares authority to another. + + The other authority to compare against. + True if authority is equal. + + + + Get hash code. + + The authority hash code. + + + + Determines if this is a specific security authority. + + The security authority. + True if the security authority. + + + + Convert authority to a 64 bit integer. + + The authority as a 64 bit integer. + + + + Overridden ToString method. + + The security authority as a string. + + + + Source for a SID name. + + + + + SDDL string. + + + + + LSASS lookup. + + + + + Named capability. + + + + + Package name SID. + + + + + From a process trust level. + + + + + Well known SID. + + + + + Scoped policy SID. + + + + + Manually added name. + + + + + Represents a name for a SID. + + + + + The qualified name of the SID. Either the combination of + Domain and Name or the SDDL SID. + + + + + The domain name, if present. + + + + + The user name. + + + + + The source of name. + + + + + The use of the name. + + + + + The SDDL format of the SID. + + + + + Used for caching. Indicates the lookup name was denied rather than not available. + + + + + Disposable class to scope an impersonation context. + + + + + Revert impersonation back to the current user. + + + + + Class to represent the state of a token privilege + + + + + Privilege attributes + + + + + Privilege LUID + + + + + Get the token privilege value enum. + + + + + Get the name of the privilege + + The privilege name + + + + Get the display name/description of the privilege + + The display name + + + + Get whether privilege is enabled + + + + + Get whether privilege is enabled + + + + + Constructor + + The privilege LUID + The privilege attributes + + + + Constructor + + The privilege value + The privilege attributes + + + + Constructor + + The privilege name. + The privilege attributes + + + + Constructor + + The privilege name. + + + + Conver to a string + + The privilege name. + + + + Standard UNICODE_STRING class + + + + + Standard UNICODE_STRING class based on a SecureString class. + + + + + Structure to use when passing in a unicode string as a sub-structure with a seure string. + + + + + Standard ANSI_STRING class + + + + + This class is used when the UNICODE_STRING is an output parameter. + The allocatation of the buffer is handled elsewhere. + + + + + Convert unicode string to an array. + + The unicode string data as an array. + + + + This class is used when the UNICODE_STRING is an output parameter. + The allocatation of the buffer is handled elsewhere. + + + + + Structure to use when passing in a unicode string as a sub-structure. + + + + + This class is used when the UNICODE_STRING needs to be preallocated + and then returned back from a caller. + + + + + Implements a UnicodeString which contains raw bytes. + + + + + Constructor. + + The bytes for the name. + + + + Get a null safe buffer. + + + + + Class to represent a user group + + + + + The SID of the user group + + + + + The attributes of the user group + + + + + Get whether the user group is enabled + + + + + Get whether the user group is mandatory + + + + + Get whether the user group is used for deny only + + + + + Get the resolved name of the SID. + + + + + Constructor + + The SID + The attributes + + + + Constructor from a SID. + + The SID + + + + Constructor from a SID or account name. + + The SID or account name. + + + + Convert to a string + + The account name if available or the SDDL SID + + + + Basic utilities for ASN1 support. + + + + + Format an array of ASN.1 DER to a string. + + The ASN.1 data in DER format. + Initial identation depth. + The formatted DER data. + + + + Format an file containing of ASN.1 DER to a string. + + The path to the file containing ASN.1 data in DER format. + Initial identation depth. + The formatted DER data. + + + + Class to do basic ASN1 DER generation. + + + + + Constructor. + + The stream to write the DER data to. + + + + Constructor. + + + + + Write an object ID. + + The object ID to write. + + + + Write raw bytes to the stream. + + The bytes to write. + + + + Write an octet-string to the stream. + + The octet string. + + + + Write a NULL value. + + + + + Write a 32-bit integer. + + The integer value. + + + + Write a 64-bit integer. + + The integer value. + + + + Write an arbitrary integer. + + The integer value. + + + + Write a sequence based on the contents of another DER builder. + + The builder for the contents. + + + + Write a sequence based on the contents of another DER builder. + + The build function for the contents. + + + + Write a sequence based on the contents of another DER builder. + + Write a sequence of fixed values. + The build function for the contents. + + + + Create a sequence builder. + + The created builder. + You should call Close or dispose on the created builder to write the tag. + + + + Write an application specific tag with contents from the builder. + + The ID of the application specific tag. + The builder for the contents. + + + + Write an application specific tag with contents from the builder. + + The ID of the application specific tag. + The build function for the contents. + + + + Create an application specific builder. + + The ID of the application specific tag. + The created builder. + You should call Close or dispose on the created builder to write the tag. + + + + Write a context specific tag with specified contents. + + The ID of the context specific tag. + The contents of the context specific value. + + + + Write a context specific tag with contents from the builder. + + The ID of the context specific tag. + The builder for the contents. + + + + Write an application specific tag with contents from the builder. + + The ID of the context specific tag. + The build function for the contents. + + + + Create a context specific builder. + + The ID of the context specific tag. + The created builder. + You should call Close or dispose on the created builder to write the tag. + + + + Write a general encoded string. + + The string + The encoding to covert to. + + + + Write a general encoded string using ASCII encoding. + + The string + + + + Write a UTF8 string. + + The UTF8 string + + + + Write an IA5 string. + + The IA5 string + + + + Write a generalized time. + + The time to write. + + + + Convert builder to a byte array. + + The DER encoded data. + + + + A DER builder for a sub-structure.. + + You should call Close or dispose the builder to write the sub-structure. + + + + Close the builder and write its contents to the parent builder. + + + + + Static class for DER builder utility functions. + + + + + A basic ASN.1 DER parser to process Kerberos and SPNEGO Tokens. + + + + + Class containing known OID values. + + + + + Class to implement a scoped file lock. + + + + + Lock part of a file. + + The file to lock. + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + True to throw on error. + The NT status code. + + + + Lock part of a file. + + The file to lock. + The offset into the file to lock + The number of bytes to lock + True to fail immediately if the lock can't be taken + True to do an exclusive lock + The NT status code. + + + + Unlock the file. + + + + + IMemoryReader implementation for a process. + + + + + Class to compress and decompress buffers using RtlCompressionBuffer. + + + + + Decompress a buffer. + + The compression format used. + The compressed buffer. + The expected uncompressed length. + True to throw on error. + The uncompressed buffer. + + + + Decompress a buffer. + + The compression format used. + The compressed buffer. + The expected uncompressed length. + The uncompressed buffer. + + + + IMemoryReader implementation for a process. + + + + + Class which calls a delegate on dispose. + + + + + Constructor. + + The delegate to call on dispose. + + + + Dispose and call the action. + + + + + A container which can detach an innner reference. + + + + + + Get the contained value. + + + + + Detach the object so the original isn't disposed. + + Detached object. + + + + Miscellaneous utilities. + + + + + Convert a disposable object to a detachable object. + + The disposable object type. + The disposable object. + The disposable container. + + + + Utilities for reflection. + + + + + Get the SDK name for a type, if available. + + The type to get the name for. + The SDK name. Returns the name of the type if not available. + + + + Get the SDK name for an enum, if available. + + The enum to get the name for. + The SDK name. If the enum is a flags enum then will return the names joined with commas. + + + + Get the SDK name an object. + + The object to get the name from. If this isn't an Enum or Type then the Type of the object is used. + The SDK name. + + + + Class to create a view. This never owns the handle. + + + + + Detaches the current handle and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + A buffer which contains an array of GUID pointers. + + + + + The count of GUIDs. + + + + + Constructor. + + The list of GUIDs. + + + + Get NULL safe buffer. + + + + + Basic implementation of ARC4. + + + + + Encrypt, or decrypt an ARC4 stream. + + The data to encrypt/decrypt. + Offset into the data to decrypt. + Length of data to decrypt. + The key to decrypt. + The resulting bytes. + + + + Encrypt, or decrypt an ARC4 stream. + + The data to encrypt/decrypt. + The key to decrypt. + The resulting bytes. + + + + Basic implementation of MD4. + + + This could have called out to the CNG APIs or dug into the + internals of the existing .NET crypto APIs but as MD4 is so + simple and it doesn't need to be secure (seriously don't use + this). This uses the reference implementation from RFC1320. + + + + + Calculate the MD4 hash of an input. + + The input bytes. + The MD4 hash. + + + + Calculate the MD4 hash of a string. + + The input string. + Encoding for the string. + The MD4 hash. + + + + Calculate the MD4 hash of a unicode string. + + The input string. + The MD4 hash. + + + + Class to perform the n-fold operation for Kerberos key derivation. + + + + + Perform an n-fold operation. + + The input data as a string. + The output length in bytes. + The computed n-folded byte array. + + + + Perform an n-fold operation. + + The input data. + The output length in bytes. + The computed n-folded byte array. + + + + A tree of Object Types. + + + + + Constructor. + + Entries to setup in the tree. + + + + Contructor. + + The object type GUID. + The name of the root object. + + + + Contructor. + + The object type GUID. + + + + Contructor. + + The object type GUID as a string. + + + + List of child nodes in the tree. + + + + + The parent of this tree. + + + + + The Object Type GUID. + + + + + Optional access mask for use in access checking. + + + + + Optional label for this tree entry. + + + + + Indicates the number of total entries this tree contains. + + + + + Add a new object type to the tree. + + The object type. + The name of the node. + The added tree object. + + + + Add a new object type to the tree. + + The object type. + The added tree object. + + + + Add an existing node to the tree. + + The node to add. + + + + Add an existing list of nodes to the tree. + + The nodes to add. + + + + Removes all object types from the tree. + + The object type. + The removed tree object. + + + + Removes all object types from the tree. + + The object type. + The removed tree object. + + + + Remove the current tree entry from the parent. + + + + + Convert the tree to an array. + + The array of ObjectTypeEntry objects. + + + + Clone the object type tree. + + The cloned tree. + + + + Set the access mask of this tree node and all children. + + The mask to set. + + + + Remove access mask from this tree node and children and propgate that up the tree. + + The mask to remove. + + + + Find an object type tree entry based on a GUID. + + The object type GUID. + The first entry found, null if doesn't exist. + + + + Split the tree up to reduce the maximum number of entries. + + This will try and keep whole branches together if at all possible, + but might split them up. This could result in incorrect access checking. + The maximum number of entries per tree. + One or more split trees. + + + + Overridden ToString method. + + The object formatted. + + + + Encoding object which converts 1 to 1 with bytes. + + + + + Default instance of the encoding. + + + + + Get the encoding name. + + + + + Get byte count for characters. + + The character array. + Index into the array. + Number of characters in the array to use. + The number of bytes this character array requires. + + + + Get bytes for characters. + + The character array. + Index into the array. + Number of characters in the array to use. + The index into the byte array. + The byte array to copy into. + The number of bytes generated. + + + + Get the character count for bytes. + + The byte array. + Index into the array. + Number of bytes in the array to use. + The number of characters this byte array requires. + + + + Get byte count for characters. + + The character array. + Index into the array. + Number of bytes in the array to use. + The index into the byte array. + The byte array to copy into. + The number of characters generated. + + + + Get maximum bytes for a number of characters. + + + + + + + Get maximum characters for a number of bytes. + + + + + + + Indicates if the encoding is a single byte. + + + + + A single extract string instance. + + + + + The string value. + + + + + The offset in the buffer. + + + + + True if the string was 16-bit Unicode. + + + + + Source of the string. Empty if was from a byte array. + + + + + Overridden ToString method. + + The value of the extracted string. + + + + Specify types of strings to extract. + + + + + Extract ASCII strings. + + + + + Extract Unicode strings. + + + + + Class to build a hex dump from a stream of bytes. + + + + + Append an array of bytes to the hex dump. + + The byte array. + The length of the bytes to append from the array. + The start offset in the bytes to append. + + + + Append an array of bytes to the hex dump. + + The byte array. + + + + Append a file or part of a file. + + The path to the file. + The length of the file to append. If 0 will append all remaining data. + The start offset in the file to append. + + + + Append a file or part of a file. + + The path to the file. + + + + Complete the hex dump string. + + + + + Finish builder and convert to a string. + + The hex dump. + + + + Constructor. + + Print a header. + Print the address. + Print the ASCII text. + Hide repeating lines. + Offset for address printing. + + + + Constructor. + + The safe buffer to print. + The length to display. + The offset into the buffer to display. + Print a header. + Print the address. + Print the ASCII text. + Hide repeating lines. + + + + Constructor. + + The safe buffer to print. + Print a header. + Print the address. + Print the ASCII text. + Hide repeating lines. + + + + Constructor. + + The stream to print. + Print a header. + Print the address. + Print the ASCII text. + Hide repeating lines. + Offset for address printing. + + + + Constructor. + + + + + Parse a hex dump into a byte array. + + The hex string. Can contain non-hex characters. + The parsed string as a byte array. + This won't necessarily parse correctly an arbitary hex dump, but it will if you just use the hex of the bytes. + + + + Parse a hex string into a byte array. + + The hex string. Can contain non-hex characters. + The parsed string as a byte array. + True if the parse was successful. + This won't necessarily parse correctly an arbitary hex dump, but it will if you just use the hex of the bytes. + + + + Utility class to extract strings from a byte value. + + + + + Extracts strings from a binary buffer. + + The data to search. + The length of the data to search. + The minimum string length. + The offset into the data to search. + The type of strings to search for. + The list of extracted strings. + + + + Extracts strings from a binary buffer. + + The data to search. + The minimum string length. + The type of strings to search for. + The list of extracted strings. + + + + Extracts strings from a stream. + + The stream to extract strings from. + The minimum string length. + The type of strings to search for. + The list of extracted strings. + + + + Extracts strings from a file. + + The file to search. + The minimum string length. + The type of strings to search for. + The list of extracted strings. + + + + Extracts strings from a safe buffer. + + Safe buffer to extract the value from. + The minimum string length. + The type of strings to search for. + The list of extracted strings. + + + + Extracts strings from a safe buffer. + + Safe buffer to extract the value from. + The minimum string length. + The type of strings to search for. + The length of the data to search. + The offset into the data to search. + The list of extracted strings. + + + + Class to call NT functions for manipulating strings. + + + + + Upper case a character according to the internal NTDLL string routines. + + The character to upper case. + The upper case character. + + + + Upper case a string according to the internal NTDLL string routines. + + The string to upper case. + True to throw on error. + The upper case string. + + + + Upper case a string according to the internal NTDLL string routines. + + The string to upper case. + The upper case string. + + + + Lower case a character according to the internal NTDLL string routines. + + The character to lower case. + The lower case character. + + + + Lower case a string according to the internal NTDLL string routines. + + The string to lower case. + True to throw on error. + The lower case string. + + + + Lower case a string according to the internal NTDLL string routines. + + The string to lower case. + The lower case string. + + + + Builder for a claim security attribute. + + + + + Name of the security attribute. + + + + + Attribute flags. + + + + + The value type. + + + + + The current list of values. + + + + + Convert build to a claim attribute. + + + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + The name of the security attribute. + The attribute flags. + The value for the attribute. + The builder instance. + + + + Create a claim security attribute builder. + + An existing attribute to clone. + The builder instance. + + + + A class which represents an AppContainer profile. + + + + + Create a new AppContainerProfile. + + The name of the AppContainer. + A display name. + An optional description. + An optional list of capability SIDs. + True to throw on error. + The created AppContainer profile. + If the profile already exists then it'll be opened instead. + + + + Create a new AppContainerProfile. + + The name of the AppContainer. + A display name. + An optional description. + An optional list of capability SIDs. + The created AppContainer profile. + If the profile already exists then it'll be opened instead. + + + + Create a temporary AppContainer profile. + + List of capabilities for the AppContainer profile. + The created AppContainer profile. + The profile will be marked to DeleteOnClose. In order to not leak the profile you + should wait till the process has exited and dispose this profile. + + + + Create a temporary AppContainer profile. + + The created AppContainer profile. + The profile will be marked to DeleteOnClose. In order to not leak the profile you + should wait till the process has exited and dispose this profile. + + + + Opens an AppContainerProfile. + + The name of the AppContainer. + True to throw no error. + The opened AppContainer profile. + This method doesn't check the profile exists. + + + + Opens an AppContainerProfile. + + The name of the AppContainer. + The opened AppContainer profile. + This method doesn't check the profile exists. + + + + Opens an AppContainerProfile and checks it exists. + + The name of the AppContainer. + True to throw no error. + The opened AppContainer profile. + This checks for the existence of the profile and also populates the additional information. + + + + Opens an AppContainerProfile and checks it exists. + + The name of the AppContainer. + The opened AppContainer profile. + This checks for the existence of the profile and also populates the additional information. + + + + Delete an existing profile. + + The AppContainer name. + True to throw on error. + The HRESULT from the delete operation. + + + + Delete an existing profile. + + The AppContainer name. + + + + Enumerate all AppContainer profiles. + + True to throw on error. + The list of appcontainer profiles. + + + + Enumerate all AppContainer profiles. + + The list of appcontainer profiles. + + + + Delete an existing profile. + + True to throw on error. + The HRESULT from the delete operation. + + + + Delete an existing profile. + + + + + Dispose of the AppContainer profile. If DeleteOnClose is set then the profile will be deleted. + + + + + Close an AppContainer profile. If DeleteOnClose is set then the profile will be deleted. + + + + + Open the AppContainer key. + + The desired access for the key. + True to throw on error. + The opened key. + + + + The AppContainer name. + + + + + The package SID + + + + + Path to the AppContainer profile directory. + + + + + Path to the AppContainer key. + + + + + Set to true to delete the profile when closed. + + + + + Get list of capabilities assigned to this AppContainer profile. + + + + + The display name for the AppContainer profile. + + + + + The description for the AppContainer profile. + + + + + Utilities for AppModel applications. + + + + + Activate an application from its Application Model ID. + + The app model ID. + Arguments for the activation. + True to throw on error. + The PID of the process. + + + + Activate an application from its Application Model ID. + + The app model ID. + Arguments for the activation. + The PID of the process. + + + + Get the list of package SIDs with a loopback exception. + + True to throw on error. + The list of package SIDs with a loopback exception. + + + + Get the list of package SIDs with a loopback exception. + + The list of package SIDs with a loopback exception. + + + + Add a loopback exception to the list. + + The package SID to add. + True to throw on error. + The NT status code. + + + + Add a loopback exception to the list. + + The package SID to add. + + + + Remove a loopback exception from the list. + + The package SID to remove. + True to throw on error. + The NT status code. + + + + Remove a loopback exception to the list. + + The package SID to remove. + + + + State of the console session. + + + + + User logged on to WinStation + + + + + WinStation connected to client + + + + + In the process of connecting to client + + + + + Shadowing another WinStation + + + + + WinStation logged on without client + + + + + Waiting for client to connect + + + + + WinStation is listening for connection + + + + + WinStation is being reset + + + + + WinStation is down due to error + + + + + WinStation in initialization + + + + + Class to represent a console session. + + + + + The session ID. + + + + + The Session Name. + + + + + The Username if any user authenticated. + + + + + The Domain Name for the User. + + + + + The Console Session State. + + + + + The hostname for the client. + + + + + The Farm name for Virtual Machine Farm. + + + + + Get the FQ User Name. + + + + + Type information for an array. + + + + + Get array element type. + + + + + Get number of array elements. + + + + + Type information for a base type. + + + + + Symbol information for a data value. + + + + + Address of the symbol. + + + + + Enumerated type value. + + + + + Name of the value. + + + + + The value as an int64. + + + + + Symbol information for an enumerated type. + + + + + Get the values for the enumerated type. + + + + + Class for a function parameter. + + + + + Name of the parameter. + + + + + Type of the parameter. + + + + + Type information for a function. + + + + + Type for the return type. + + + + + List of function parameters. + + + + + Interface for symbol type resolver. + + + + + Query types in a module. + + The base address of the module. + The list of types. + + + + Query names of types in a module. + + The base address of the module. + The list of type names. + + + + Get a type by name. + + The base address of the module containing the type. + The name of the type. + + + + + Query types by name + + The base address of the module containing the type. + A mask string for the type name. e.g. mod!ABC* + The list of types. + + + + Get the address of a symbol. + + The name of the symbol, should include the module name, e.g. modulename!MySymbol. + The symbol type. + + + + Get the address of a symbol. + + The address of the symbol. + The symbol type. + + + + Type information for a pointer value. + + + + + Get the type this pointer references. + + + + + Indicates this pointer is a reference. + + + + + The name of the symbol. + + + + + Class to represent a symbol information. + + + + + The name of the symbol. + + + + + Size of the symbol. + + + + + Get the loaded module for the symbol. + + + + + Type of the symbol. + + + + + Internal type index. + + + + + Overridden ToString method. + + Returns the symbol name. + + + + Enumeration for symbol type information. + + + + + None. + + + + + UDT. + + + + + Enumerated type. + + + + + A base type. + + + + + A function type. + + + + + A pointer type. + + + + + Undefined. + + + + + Flags for the symbol resolver. + + + + + No flags. + + + + + Trace symbol file loading + + + + + Disable resolving export symbols if no PDB can be found. + + + + + Enable a symbol server fallback. If the copy of dbghelp doesn't have a symsrv.dll + then download from a public symbol URL to a local cache directory during symbol + resolving. + + + + + Symbol information for a type. + + + + + Represents a member of a UDT. + + + + + The type of the member. + + + + + The name of the member. + + + + + The offset into the UDT. + + + + + The size of the member. + + + + + Represents a bit field member of a UDT. + + + + + If a bit field then this is the bit start position. + + + + + If a bit field this is the bit length. + + + + + Symbol information for an enumerated type. + + + + + The members of the UDT. + + + + + Indicates the UDT is a union. + + + + + Class to capture Win32 debug output. + + + + + Create an instance of the Win32 debug console. + + The session ID for the console. Set to 0 to capture global output. + True to throw on error. + The Win32 debug console. + + + + Create an instance of the Win32 debug console. + + The session ID for the console. Set to 0 to capture global output. + The Win32 debug console. + + + + Create an instance of the Win32 debug console for current session. + + True to throw on error. + The Win32 debug console. + + + + Create an instance of the Win32 debug console for current session. + + The Win32 debug console. + + + + Create an instance of the Win32 debug console for the global session. + + True to throw on error. + The Win32 debug console. + + + + Create an instance of the Win32 debug console for the global session. + + The Win32 debug console. + + + + Read a debug string from for the console asynchronously. + + The timeout in milliseconds. + Cancellation token. + The Win32 debug string. If timed out then Output property is null. + + + + Read a debug string from for the console asynchronously. + + The timeout in milliseconds. + The Win32 debug string. If timed out then Output property is null. + + + + Read a debug string from for the console asynchronously. + + The Win32 debug string. If timed out then Output property is null. + + + + Read a debug string from for the console. + + The timeout in milliseconds. + The Win32 debug string. If timed out then Output property is null. + + + + Read a debug string from for the console. + + The Win32 debug string. If timed out then Output property is null. + + + + Attach the debug console to another session. + + The session ID. + True to throw on error. + The NT status code. + + + + Attach the debug console to another session. + + The session ID. + + + + Dispose debug console. + + + + + Structure for a debug string event. + + + + + The process ID. + + + + + The output string. + + + + + Class to hold known bus type GUIDs. + + + + + Class to represent a device interface. + + + + + The name of the interface class. + + + + + The device interface GUID. + + + + + The list of device interface instances. + + + + + The list of all device interface properties. + + The device interface properties. + + + + Class containing well known device interface class GUIDs. + + + + + Convert interface class GUID to a string. + + + The name of the interface class GUID. + + + + Get the list of known interface GUIDs. + + The list of known interface guids. + + + + Class to represent a device interface instance. + + + + + The instance path to the device. + + + + + The raw device path. + + + + + The device interface class GUID. + + + + + The device instance ID for the device node. + + + + + Overridden ToString method. + + The Win32Path. + + + + The list of all device interface instance properties. + + The device interface instance properties. + + + + Device property types. + + + + + Class representing a device node. + + + + + The name of the device instance. + + + + + The device setup class GUID. + + + + + The device instance ID. + + + + + Get the device PDO name. + + + + + Get the device INF name. + + + + + Get the device INF path. + + + + + Get the device stack. + + + + + The the device stack as a list of driver paths. + + + + + Indicates if this is a per-session device. If null then not defined. + + + + + Indicates if this instance is present. + + + + + Indicates the name of the SCM service for the driver. + + + + + Get path to the driver. + + + + + Get driver start type. + + + + + Get the parent device node. + + The parent device node. Returns null if reached the root. + + + + List of upper filters. + + + + + List of lower filters. + + + + + Container ID. + + + + + Type of bus for the device. + + + + + Get if the device is a user-mode device. + + + + + The list of all device properties. + + The device properties. + + + + Get the setup class for this instance. + + Returns the setup class. + Thrown if invalid setup GUID. + + + + Get list of parent nodes. + + The list of parent nodes. + + + + Overridden ToString method. + + + + + + Optional security descriptor for device node. + + + + + Indicates the device node has a security descriptor. + + + + + Device property. + + + + + The name of the property, if known. + + + + + The FMTID Guid. + + + + + The PID. + + + + + The device property type. + + + + + Property data. + + + + + Format the data according to type. + + The formatted data. + + + + ToString method. + + The property as a string. + + + + Class to represent a device setup class. + + + + + The friendly name of the device. + + + + + The name of the device class. + + + + + The device class installer Guid. + + + + + The security descriptor for the device (if available). + + + + + Indicates the device setup class has a security descriptor. + + + + + The device type. + + + + + The device characteristics. + + + + + List of upper filters. + + + + + List of lower filters. + + + + + The list of all device setup properties. + + The device setup properties. + + + + Get device instances. + + Return all devices. + The list of devices instances. + + + + Get device instances. + + The list of devices instances. + + + + Enumerated type for device stack type. + + + + + Unknown type. + + + + + Entry is for the function driver. + + + + + Entry is for the bus driver. + + + + + Entry is for an upper filter. + + + + + Entry is for the lower filter. + + + + + Entry is for a filter. + + + + + Class to represent an entry on the stack. + + + + + Name of the driver. + + + + + Path to the driver. + + + + + Stack entry type. + + + + + Overridden ToString method. + + The name of the driver in the stack. + + + + Class to represent a node in a device tree. + + + + + List of child nodes. + + + + + Indicates if the node has any children. + + + + + Get the parent device node. + + The parent device node. Returns null if reached the root. + + + + Utilities for interacting with Device, Configuration and Setup APIs. + + + + + Get a list of device interfaces from an Interface GUID. + + The interface class GUID for the device. + Optional device ID. + True to get all devices, otherwise just present devices. + List of device interfaces. + + + + Get a list of present device interfaces from an Inteface GUID. + + The interface class GUID for the device. + List of device interfaces. + + + + Enumerate installer class GUIDs. + + The list of installer class GUIDs. + + + + Enumerate interface class GUIDs. + + The list of interface class GUIDs. + + + + Query the security descriptor for a device. + + The installer device class. + True to throw on error. + The security descriptor. + + + + Query the security descriptor for a device. + + The installer device class. + The security descriptor. + + + + Get list of registered device setup classes. + + The list of device setup classes. + + + + Get a device setup class by GUID. + + The class GUID. + The device setup class. + + + + Get list of registered device interfaces. + + True to return all devices. + The list of device interfaces. + + + + Get list of registered device interfaces. + + The list of device interfaces. + + + + Get a device interface class by GUID. + + The class GUID. + True to return all devices. + The device interface class. + + + + Get a device interface class by GUID. + + The class GUID. + The device interface class. + + + + Get list of device nodes. + + Return all devices including ones which aren't present. + The list of device nodes. + + + + Get list of present device nodes. + + The list of device entries. + + + + Get list of device entries. + + Specify the Device Setup Class GUID. + Only return present devices. + The list of device entries. + + + + Get list of present device entries. + + Specify the Device Setup Class GUID. + The list of device entries. + + + + Get the device node from a device ID. + + The instance ID to lookup.. + The device node. + + + + Get device tree. + + The device tree's root node. + + + + Get the node from a device instance ID. + + The instance ID to start from. + The root device node. + + + + Get all device interface instances. + + + + + Get all device interface instances for a given interface class GUID. + + + + + Get an interface instance from the interface instance path. + + The path to the interface symbolic link. e.g. \??\SOME$VALUE. + + + + Interface to indicate the device object has properties. + + + + + The list of all device properties. + + The device properties. + + + + Access rights for Active Directory Services. + + + + + Class to represent a binding to a directory service. + + + + + Crack one or more names on the domain controller. + + Flags for the cracking. + Format of the names. + Desired format of the names. + The list of names to crack. + True to throw on error. + The cracked names. + + + + Crack one or more names on the domain controller. + + Flags for the cracking. + Format of the names. + Desired format of the names. + The list of names to crack. + The cracked names. + + + + Crack a name on the domain controller. + + Flags for the cracking. + Format of the name. + Desired format of the name. + The name to crack. + True to throw on error. + The cracked name. + + + + Crack a name on the domain controller. + + Flags for the cracking. + Format of the name. + Desired format of the name. + The name to crack. + The cracked name. + + + + Get naming contexts for domain. + + True to throw on error. + The naming contexts. + + + + Get naming contexts for domain. + + The naming contexts. + + + + Bind to a directory service. + + The name of the domain controller. Can be null. + The DNS domain name. + True to throw on error. + The directory service binding. + + + + Bind to a directory service. + + The name of the domain controller. Can be null. + The DNS domain name. + The directory service binding. + + + + Bind to the current directory service. + + The directory service binding. + + + + Dispose the binding. + + + + + Class to represent an directory service extended right queries from the current domain. + + + + + The common name of the extended right. + + + + + The distinguished name for the extended right. + + + + + The domain name searched for this extended right. + + + + + The rights GUID for this extended right. + + + + + The list of applies to GUIDs. + + + + + The valid accesses for this extended right. + + + + + Get list of properties if a property set. + + + + + True if this a property set extended right. + + + + + True if this is a validated write extended right. + + + + + True if this is a control extended right. + + + + + Overridden ToString method. + + The name of the extended right. + + + + Convert the extended right to an object type tree. + + The tree of object types. + + + + Convert the extended right to an object type tree. + + The extended right to convert. + The tree of object types. + + + + Flags and settings from the dSHeuristics attribute. + + + + + The fSupFirstLastANR flag. + + + + + The fSupLastFirstANR flag. + + + + + The fDoListObject flag. + + + + + The fLDAPBlockAnonOps flag. + + + + + The fAllowAnonNSPI flag. + + + + + The fDontStandardizeSDs flag. + + + + + The raw value for the dsHeuristics attribute. + + + + + The domain where the value was read. + + + + + Directory services name error. + + + + + Directory services name flags. + + + + + Directory services name format. + + + + + Structure to represent a directory service name. + + + + + Status of the name. + + + + + Domain of the name. + + + + + Name of the name. + + + + + Native methods for directory services. + + + + + Object type level for a directory object. + + + + + Object type. + + + + + Property set type. + + + + + Property type. + + + + + Class to represent an a class which is referenced from another. For example auxiliary or superior classes. + + + + + The name of the class. + + + + + Whether the class is a system class. + + + + + Get the full schema class for this reference. + + The schema class. + + + + Class to represent a directory service schema attribute. + + + + + The attributes syntax. + + + + + The OM syntax. + + + + + The OM object class. + + + + + The name of the attribute syntax type if known. + + + + + The GUID of the containing property set, if it exists. + + + + + Indicates if the attribute is in a property set. + + + + + Class to represent a directory service schema class. + + + + + The subclass schema name. + + + + + List of attributes the class can contain. + + + + + The default security descriptor. + + + + + The default security descriptor in SDDL format. + + + + + The list of auxiliary classes for this class. + + + + + The category of schema class. + + + + + The list of possible superior classes for this class. + + + + + Possible inferiors of the class. + + + + + Structure to represent an attribute for a class. + + + + + The name of the attribute. + + + + + True if the attribute is required. + + + + + True if the attribute can only be modified by system. + + + + + Get the hash code for the attribute. + + The hash code. + + + + Check attributes for equality. + + The other attribute to check. + True if equal. + + + + Overridden ToString method. + + The name of the attribute. + + + + Represents the type of schema class. + + + + + Legacy class. + + + + + Structure class (can be created). + + + + + Abstract class. + + + + + Auxiliary class. + + + + + Base class for a schema class or attribute object. + + + + + The GUID of the schema class. + + + + + The name of the schema class. + + + + + The LDAP display name. + + + + + The object class for the schema class. + + + + + The distinguished name for the schema class. + + + + + The domain name searched for this schema class. + + + + + The admin description for the object. + + + + + Indicates if this schema object is system only. + + + + + Overridden ToString method. + + The name of the schema class. + + + + Convert the schema class to an object type tree. + + The tree of object types. + + + + Convert the extended right to an object type tree. + + The schema class to convert. + The tree of object types. + + + + Class to represent a security principal in the directory. + + + + + Distinguished name of the group. + + + + + The SID of the object. + + + + + Overridden Equals. + + The other object to test. + True if equal. + + + + Overridden GetHashCode. + + The hash code. + + + + User flags. + + + + + Class implementing various utilities for directory services. + + + + + Name for the fake Directory Service NT type. + + + + + Get the generic mapping for directory services. + + The directory services generic mapping. + + + + Get a fake NtType for Directory Services. + + The fake Directory Services NtType + + + + Get the default property set. + + + + + Get the schema class for a GUID. + + Specify the domain to get the schema class for. + The GUID for the schema class. + The schema class, or null if not found. + + + + Get the schema class for a GUID. + + The GUID for the schema class. + The schema class, or null if not found. + + + + Get the schema class for a LDAP name. + + Specify the domain to get the schema class for. + The LDAP name for the schema class. + The schema class, or null if not found. + + + + Get the schema class for a LDAP name. + + The LDAP name for the schema class. + The schema class, or null if not found. + + + + Get the inferior schema class for a LDAP name. + + Specify the domain to get the schema class for. + The LDAP name for the parent schema class. + The schema classes. + + + + Get the inferior schema class for a LDAP name. + + The LDAP name for the schema class. + The schema classes. + + + + Get the auxiliary schema classes for a LDAP name. + + Specify the domain to get the schema class for. + The LDAP name for the parent schema class. + The schema classes. + + + + Get the auxiliary schema classes for a LDAP name. + + The LDAP name for the schema class. + The schema classes. + + + + Get all schema classes. + + Specify the domain to get the schema classes for. + The list of schema classes. + + + + Get all schema classes. + + The list of schema classes. + + + + Get all schema classes in a hierarchy. + + Specify the domain to get the schema classes for. + Specify to include auxiliary classes in the list. + The name of the base schema class. + The list of schema classes. + + + + Get all schema classes in a hierarchy. + + Specify to include auxiliary classes in the list. + The name of the base schema class. + The list of schema classes. + + + + Get the common name of an schema object class. + + Specify the domain to get the schema class for. + The GUID for the schema class. + The common name of the schema class, or null if not found. + + + + Get the common name of an schema object class. + + The GUID for the schema class. + The common name of the schema class, or null if not found. + + + + Get the schema attribute for a GUID. + + Specify the domain to get the schema attribute for. + The GUID for the schema attribute. + The schema attribute, or null if not found. + + + + Get the schema attribute for a GUID. + + The GUID for the schema attribute. + The schema attribute, or null if not found. + + + + Get the schema attribute for a LDAP name. + + Specify the domain to get the schema attribute for. + The LDAP name for the schema attribute. + The schema attribute, or null if not found. + + + + Get the schema attribute for a LDAP name. + + The LDAP name for the schema attribute. + The schema attribute, or null if not found. + + + + Get all schema attributes. + + Specify the domain to get the schema attributes for. + The list of schema attributes. + + + + Get all schema attributes. + + The list of schema attributes. + + + + Get the common name of a schema attribute. + + Specify the domain to get the schema attribute for. + The GUID for the schema attribute. + The common name of the schema attribute, or null if not found. + + + + Get the common name of a schema attribute. + + The GUID for the schema attribute. + The common name of the schema attribute, or null if not found. + + + + Get the extended right name by GUID. + + Specify the domain for the extended right. + The GUID for the extended right. + If true and the right is a property set, expand the name. + The name of the extended right, or null if not found. + + + + Get the extended right name by GUID. + + The GUID for the extended right. + If true and the right is a property set, expand the name. + The name of the extended right, or null if not found. + + + + Get an extended right by GUID. + + Specify the domain to get the extended right for. + The GUID for the extended right. + The extended right, or null if not found. + + + + Get an extended right by GUID. + + The GUID for the extended right. + The extended right, or null if not found. + + + + Get an extended right by common name. + + Specify the domain to get the extended right for. + The common name for the extended right. + The extended right, or null if not found. + + + + Get an extended right by common name. + + The common name for the extended right. + The extended right, or null if not found. + + + + Get a list of all extended rights in the current domain. + + Specify the domain to get the extended rights from. + The list of extended rights. + + + + Get a list of all extended rights in the current domain. + + The list of extended rights. + + + + Get a list of extended rights applied to a schema class. + + Specify the domain to get the extended rights from. + The schema class identifier. + The list of extended rights applies to the schema class. + + + + Get a list of extended rights applied to a schema class in the current domain. + + The schema class identifier. + The list of extended rights applies to the schema class. + + + + Create an object type entry for an access check. + + The object type level. + The object type GUID. + An optional name. + The object type entry. + + + + Get the object SID from a directory object. + + The directory entry. + The object SID. Returns null if no object SID exists. + + + + Get the object SID from a directory object. + + The domain name for the object. + The distinguished name of the object. + The object SID. Returns null if no object SID exists. + + + + Get the object SID from a directory object. + + The distinguished name of the object. + The object SID. Returns null if no object SID exists. + + + + Get a directory object. + + The domain name for the object. + The distinguished name of the object. + The object entry. + + + + Get a directory object. + + The distinguished name of the object. + The object entry. + + + + Standardize security descriptor to the rules of Active Directory. + + The security descriptor. + The standardized security descriptor. + + + + Get the value for the dsHeuristics attribute. + + The domain to read the dsHeuristics from. + The dsHeuristics value. + + + + Get the value for the dsHeuristics attribute. + + The dsHeuristics value. + + + + Get the value for an object's sDRightsEffective attribute. + + The domain for the object. + The distinguished name of the object. + The sDRightsEffective value. + + + + Get the value for an object's sDRightsEffective attribute. + + The distinguished name of the object. + The sDRightsEffective value. + + + + Try and find the an object from its SID. + + Specify the domain to search. + The SID to find. + The distinguished name of the object, null if not found. + + + + Try and find the token groups for an object. + + Domain name for the lookup. + The distinguished name to find. + True to return all groups including BUILTIN on the server. False for just universal and global groups. + The list of member SIDs. + + + + Try and find the token groups for an object using the SID. + + Sid to use for the object. + True to return all groups including BUILTIN on the server. False for just universal and global groups. + The list of member SIDs. + + + + Try and find the membership of groups for a name. + + Domain name for the lookup. + The distinguished name to find as member. + The list of groups. + + + + Call to pre-cache the schema for a domain, could take a long time to load. + + The domain to cache. + True if the schema was cached successfully. + + + + Call to pre-cache the schema for the current domain, could take a long time to load. + + True if the schema was cached successfully. + + + + Interface to convert a directory object to a tree for access checking. + + + + + The name of the object. + + + + + The ID of the object. + + + + + Convert the schema class to an object type tree. + + The tree of object types. + + + + DLL characteristic flags. + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Reserved + + + + + Image can handle a high entropy 64-bit virtual address space. + + + + + DLL can be relocated at load time. + + + + + Code Integrity checks are enforced. + + + + + Image is NX compatible. + + + + + Isolation aware, but do not isolate the image. + + + + + Does not use structured exception (SE) handling. No SE handler may be called in this image. + + + + + Do not bind the image. + + + + + Image must execute in an AppContainer. + + + + + A WDM driver. + + + + + Image supports Control Flow Guard. + + + + + Terminal Server aware. + + + + + CodeView debug data for an executable. + + + + + The magic identifier. + + + + + The unique identifier. + + + + + Age of debug information. + + + + + Path to PDB file. + + + + + Identifier path to use when looking up symbol file. + + + + + Get just the name of the PDB file. + + + + + Get the symbol server path. + + The symbol URL, either a local path or a remote URL. + The symbol server path. + + + + Single DLL export entry. + + + + + The name of the export. If an ordinal this is #ORD. + + + + + The ordinal number. + + + + + Address of the exported entry. Can be 0 if a forwarded function. + + + + + Name of the forwarder, if used. + + + + + Get the module this was exported from. + + + + + Overridden ToString method. + + The name of the export. + + + + Single DLL import. + + + + + The name of the DLL importing from. + + + + + List of DLL imported functions. + + + + + List of names imported. + + + + + Could of functions + + + + + True of the imports are delay loaded. + + + + + The path to the executable this import came from. + + + + + Overridden ToString method. + + The DLL name and count. + + + + Single DLL import function. + + + + + The name of the DLL importing from. + + + + + The name of the imported function. If an ordinal this is #ORD. + + + + + Address of the imported function. Can be 0 if not a bound DLL. + + + + + Ordinal of import, if imported by ordinal. -1 if not. + + + + + Overridden ToString method. + + The name of the imported function. + + + + Simple class for an event trace. + + + + + Write an empty event. + + + + + Dispose method. + + + + + Level for trace event. + + + + + Critical level. + + + + + Error level. + + + + + Warning level. + + + + + Information level. + + + + + Verbose level. + + + + + Descriptor for an enabled trace provider. + + + + + Pointer to descriptor data. + + + + + Size of descriptor data. + + + + + Type of descriptor data. + + + + + An Event Trace Log. + + + + + Enable a provider. + + The GUID of the provider. + The level for the events. + Any keywords to match. + All keywords to match. + The timeout. + List of optional descriptors. + True to throw on error. + The resulting status code. + + + + Get allocated session GUID. + + + + + Get name of the session. + + + + + Finalizer. + + + + + Dispose the event trace log. + + + + + Source of an event trace provider. + + + + + Unknown source. + + + + + From WMI. + + + + + From NtTraceControl. + + + + + From the security key. + + + + + Class to represent an Event Trace Provider. + + + + + The ID of the provider. + + + + + The name of the provider. + + + + + Whether the provider is defined as an XML file or a MOF. + + + + + The provider security descriptor (only available as admin). + + + + + Indicates the source of the provider. + + + + + Class to access event tracing methods. + + + + + Query security of an event. + + The event GUID to query. + True to throw on error. + The event security descriptor. + + + + Query security of an event. + + The event GUID to query. + The event security descriptor. + + + + Query the default security for events. + + True to throw on error. + The default security descriptor. + + + + Query the default security for events. + + The default security descriptor. + + + + Modify trace security. + + The event trace GUID. + The operation to perform. + The SID to set. + The access mask to set. + True to allow, false to deny. + True to throw on error. + The NT status code. + + + + Modify trace security. + + The event trace GUID. + The operation to perform. + The SID to set. + The access mask to set. + True to allow, false to deny. + + + + Adds DACL ACE for an event trace. + + The event trace GUID. + The SID to set. + The access mask to set. + True to allow, false to deny. + True to throw on error. + The NT status code. + + + + Adds DACL ACE for an event trace. + + The event trace GUID. + The SID to set. + The access mask to set. + True to allow, false to deny. + + + + Clears DACL and adds ACE for an event trace. + + The event trace GUID. + The SID to set. + The access mask to set. + True to allow, false to deny. + True to throw on error. + The NT status code. + + + + lears DACL and adds ACE for an event trace. + + The event trace GUID. + The SID to set. + The access mask to set. + True to allow, false to deny. + + + + Remove security for an event trace. + + The event trace GUID. + True to throw on error. + The NT status code. + + + + Remove security for an event trace. + + The event trace GUID. + + + + Register an event trace with a specific GUID. + + The event trace GUID. + True to throw on error. + The event trace. + + + + Start an event trace log. + + The path to the log file. + Session GUID. + The name of the logging session. + True to throw on error. + The event trace log. + + + + Start an event trace log. + + The path to the log file. + Session GUID. + The name of the logging session. + The event trace log. + + + + Register an event trace with a specific GUID. + + The event trace GUID. + The event trace. + + + + Get the list of registered trace GUIDs. + + The list of trace GUIDs. + + + + Get the list of registered trace providers. + + Specify true to return a list of cached providers. + The list of trace providers. + + + + Get the list of registered trace providers. + + The list of trace providers. + Returns a cached list of providers, if you want to check the current list use GetProviders(bool). + + + + Get the name of a provider. + + The ID of the provider. + The name of the provider. Returns null if the provider had no name or doesn't exist. + + + + Contains information about a manifest file. + + + + + True if parsing the XML manifest failed. + + + + + Full path to the manifest location. + + + + + The name of the manifest. + + + + + True if the manifest indicates UI access. + + + + + The execution level from the manifest. + + + + + True if the manifest indicates auto elevation. + + + + + The manifest XML. + + + + + True if the manifest indicates long path awareness. + + + + + Get the manifests from a file. + + The file to extract the manifests from. + The list of manifests. + + + + Overridden ToString method. + + The manifest as a string. + + + + A class to represent filter communication port. + + + + + Open a filter communications port. + + The port name, e.g. \FilterName + Make the handle synchronous. + Optional context data. + True to throw on error. + The filter communications port. + + + + Open a filter communications port. + + The port name, e.g. \FilterName + Make the handle synchronous. + Optional context data. + The filter communications port. + + + + Open a filter communications port. + + The port name, e.g. \FilterName + The filter communications port. + + + + Get message from port. + + The maximum message size to receive. + True to throw on error. + The returned message. + + + + Get message from port. + + The maximum message size to receive. + The returned message. + + + + Reply to message. + + The NT status code. + The message ID from GetMessage. + The data to send. + True to throw on error. + The NT status code. + + + + Reply to message. + + The NT status code. + The message ID from GetMessage. + The data to send. + + + + Send a message to the filter. + + The input buffer. + The output buffer. + True to throw on error. + The bytes in the output buffer. + + + + Send a message to the filter. + + The input buffer. + The output buffer. + The bytes in the output buffer. + + + + Send a message to the filter. + + The input buffer. + The maximum size of the output buffer. + true to throw on error. + The output buffer. + + + + Send a message to the filter. + + The input buffer. + The maximum size of the output buffer. + The output buffer. + + + + Class to represent a filter communications port message. + + + + + The message ID. + + + + + The returned data. + + + + + The length of the reply to send. + + + + + Class to represent a filter drive. + + + + + True if a mini-filter, false if a legacy-filter. + + + + + Flags, if any. + + + + + The frame ID. + + + + + Number of instances if a mini-filter. + + + + + Name of the filter driver. + + + + + Altitude of the filter driver. + + + + + Class to represent a mini-filter instance. + + + + + The name of the instance. + + + + + The altitude of the instance. + + + + + The volume name. + + + + + The filter name. + + + + + Filter filesystem type. + + + + + an UNKNOWN file system type + + + + + Microsoft's RAW file system (\FileSystem\RAW) + + + + + Microsoft's NTFS file system (\FileSystem\Ntfs) + + + + + Microsoft's FAT file system (\FileSystem\Fastfat) + + + + + Microsoft's CDFS file system (\FileSystem\Cdfs) + + + + + Microsoft's UDFS file system (\FileSystem\Udfs) + + + + + Microsoft's LanMan Redirector (\FileSystem\MRxSmb) + + + + + Microsoft's WebDav redirector (\FileSystem\MRxDav) + + + + + Microsoft's Terminal Server redirector (\Driver\rdpdr) + + + + + Microsoft's NFS file system (\FileSystem\NfsRdr) + + + + + Microsoft's NetWare redirector (\FileSystem\nwrdr) + + + + + Novell's NetWare redirector + + + + + The BsUDF CD-ROM driver (\FileSystem\BsUDF) + + + + + Microsoft's Mup redirector (\FileSystem\Mup) + + + + + Microsoft's WinFS redirector (\FileSystem\RsFxDrv) + + + + + Roxio's UDF writeable file system (\FileSystem\cdudf_xp) + + + + + Roxio's UDF readable file system (\FileSystem\UdfReadr_xp) + + + + + Roxio's DVD file system (\FileSystem\DVDVRRdr_xp) + + + + + Tacit FileSystem (\Device\TCFSPSE) + + + + + Microsoft's File system recognizer (\FileSystem\Fs_rec) + + + + + Nero's InCD file system (\FileSystem\InCDfs) + + + + + Nero's InCD FAT file system (\FileSystem\InCDFat) + + + + + Microsoft's EXFat FILE SYSTEM (\FileSystem\exfat) + + + + + PolyServ's file system (\FileSystem\psfs) + + + + + IBM General Parallel File System (\FileSystem\gpfs) + + + + + Microsoft's Named Pipe file system(\FileSystem\npfs) + + + + + Microsoft's Mailslot file system (\FileSystem\msfs) + + + + + Microsoft's Cluster Shared Volume file system (\FileSystem\csvfs) + + + + + Microsoft's ReFS file system (\FileSystem\Refs or \FileSystem\Refsv1) + + + + + OpenAFS file system (\Device\AFSRedirector) + + + + + Composite Image file system (\FileSystem\cimfs) + + + + + Methods for accessing Filter Manager information. + + + + + Enumerate the list of filter drivers. + + The list of filter drivers. + + + + Enumerate the list of filter driver instances. + + The name of the filter driver. + The list of filter driver instances. + + + + Enumerate the list of filter driver instances for all filter drivers. + + The list of filter driver instances. + + + + Enumerate the list of filter drivers attached to a volume. + + The name of volume, e.g. C:\ + The list of filter volume instances. + + + + Enumerate the list of filter drivers attached for all volumes. + + The list of filter volume instances. + + + + Enumerate the list of filter volumes. + + The list of filter volumes + + + + Attach a filter to a volume. + + The filter name. + The volume name. + Optional altitude of the filter. + Optional instance name. + True to throw on error. + The created instance name. + + + + Attach a filter to a volume. + + The filter name. + The volume name. + Optional altitude of the filter. + Optional instance name. + The created instance name. + + + + Attach a filter to a volume. + + The filter name. + The volume name. + Optional altitude of the filter. + The created instance name. + + + + Attach a filter to a volume. + + The filter name. + The volume name. + The created instance name. + + + + Attach a filter to a volume. + + The filter name. + The volume name. + Optional instance name. + True to throw on error. + The NT status code. + + + + Attach a filter to a volume. + + The filter name. + The volume name. + Optional instance name. + The NT status code. + + + + Attach a filter to a volume. + + The filter name. + The volume name. + The NT status code. + + + + Class to represent a filter volume. + + + + + Is the filter detached from the volume. + + + + + Filter frame ID. + + + + + Filesystem type. + + + + + Filter volume name. + + + + + Class which represents a section from a loaded PE file. + + + + + The name of the section. + + + + + Buffer to the data. + + + + + Relative Virtual address of the data from the library base. + + + + + Image section characteristics. + + + + + Get the data as an array. + + The data as an array. If can't read the section returns an empty array. + + + + Characteristic flags for image section. + + + + + None. + + + + + Section is code. + + + + + Section is initialized data. + + + + + Section is uninitialized data. + + + + + Section is shared. + + + + + Section is executable. + + + + + Section is readable. + + + + + Section is writable. + + + + + Class to represent a resource in an image. + + + + + The name of the resource. + + + + + The type of the resource. + + + + + The size of the resource. + + + + + Get the resource as a byte array. + + The resource as a byte array. + + + + Image resource type. + + + + + The name of the resource as a string. + + + + + The well known type, is available (otherwise set to UNKNOWN) + + + + + Overridden ToString method. + + The name of the type. + + + + Known image resource types. + + + + + Interface for a symbol resolver. + + + + + Get list of loaded modules. + + The list of loaded modules + Note this will cache the results so subsequent calls won't necessarily see new modules. + + + + Get list of loaded modules and optionally refresh the list. + + True to refresh the current cached list of modules. + The list of loaded modules + + + + Get module at an address. + + The address for the module. + The module, or null if not found. + Note this will cache the results so subsequent calls won't necessarily see new modules. + + + + Get module at an address. + + The address for the module. + True to refresh the current cached list of modules. + The module, or null if not found. + + + + Get a string representation of a relative address to a module. + + The address to get the string for, + The string form of the address, e.g. modulename+0x100 + Note this will cache the results so subsequent calls won't necessarily see new modules. + + + + Get a string representation of a relative address to a module. + + The address to get the string for, + True to refresh the current cached list of modules. + The string form of the address, e.g. modulename+0x100 + + + + Get the address of a symbol. + + The name of the symbol, should include the module name, e.g. modulename!MySymbol. + The address of the symbol + + + + Get the symbol name for an address. + + The address of the symbol. + The symbol name. + + + + Get the symbol name for an address, with no fallback. + + The address of the symbol. + If true then generate a fake symbol. + The symbol name. If |generate_fake_symbol| is true and the symbol doesn't exist one is generated based on module name. + + + + Get the symbol name for an address, with no fallback. + + The address of the symbol. + If true then generate a fake symbol. + If true then return only the name of the symbols (such as C++ symbol name) rather than full symbol. + The symbol name. If |generate_fake_symbol| is true and the symbol doesn't exist one is generated based on module name. + + + + Reload the list of modules for this symbol resolver. + + + + + Load a specific module into the symbol resolver. + + The path to the module. + The base address of the loaded module. + + + + Flags for loading a library. + + + + + None. + + + + + Don't resolve DLL references + + + + + Load library as a data file. + + + + + Load with an altered search path. + + + + + Ignore code authz level. + + + + + Load library as an image resource. + + + + + Load library as a data file exclusively. + + + + + Add the DLL's directory temporarily to the search list. + + + + + Search application directory for the DLL. + + + + + Search the user's directories for the DLL. + + + + + Search system32 for the DLL. + + + + + Search the default directories for the DLL. + + + + + Logon type + + + + + This is used to specify an undefined logon type + + + + + Interactively logged on (locally or remotely) + + + + + Accessing system via network + + + + + Started via a batch queue + + + + + Service started by service controller + + + + + Proxy logon + + + + + Unlock workstation + + + + + Network logon with cleartext credentials + + + + + Clone caller, new default credentials + + + + + Remove interactive. + + + + + Cached Interactive. + + + + + Cached Remote Interactive. + + + + + Cached unlock. + + + + + Specify what account rights to get. + + + + + Get all account rights. + + + + + Get all privilege account rights. + + + + + Get logon account rights. + + + + + Utilities for user logon. + + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + True to throw on error. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + Additional groups to add. Needs SeTcbPrivilege. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + Additional groups to add. Needs SeTcbPrivilege. + True to throw on error. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + Additional groups to add. Needs SeTcbPrivilege. + The logged on token. + + + + Logon user using Kerberos Ticket. + + The type of logon token. + The service ticket. + Optional TGT. + True to throw on error. + The logged on token. + + + + Logon user using Kerberos Ticket. + + The type of logon token. + The service ticket. + Optional TGT. + The logged on token. + + + + Logon user using Kerberos Ticket. + + The type of logon token. + The service ticket. + Optional TGT. + True to throw on error. + The logged on token. + + + + Logon user using Kerberos Ticket. + + The type of logon token. + The service ticket. + Optional TGT. + The logged on token. + + + + Logon user using S4U + + The username. + The user's realm. + The type of logon token. + The name of the auth package to user. + True to throw on error. + The logged on token. + + + + Logon user using S4U + + The username. + The user's realm. + The type of logon token. + The name of the auth package to user. + The logged on token. + + + + Logon user using S4U + + The username. + The user's realm. + The type of logon token. + The logged on token. + + + + Logon user using S4U + + The username. + The user's realm. + The type of logon token. + The logged on token. + + + + Get a logon session. + + The logon session ID. + True to thrown on error. + The logon session. + + + + Get a logon session. + + The logon session ID. + The logon session. + + + + Get the logon session LUIDs + + True throw on error. + The list of logon sessions. Only returns ones you can access. + + + + Get the logon session LUIDs + + The list of logon sessions. Only returns ones you can access. + + + + Get the logon sessions. + + True throw on error. + The list of logon sessions. Only returns ones you can access. + + + + Get the logon sessions. + + The list of logon sessions. + + + + Get account rights assigned to a SID. + + The SID to query. + True to throw on error. + The list of account rights. + + + + Get account rights assigned to a SID. + + The SID to query. + The list of account rights. + + + + Get SIDs associated with an account right. + + The name of the account right, such as SeImpersonatePrivilege. + True to throw on error. + The list of SIDs assigned to the account right. + + + + Get SIDs associated with an account right. + + The name of the account right, such as SeImpersonatePrivilege. + The list of SIDs assigned to the account right. + + + + Get SIDs associated with an account right. + + The account right privilege to query. + True to throw on error. + The list of SIDs assigned to the account right. + + + + Get SIDs associated with an account right. + + The account right privilege to query. + The list of SIDs assigned to the account right. + + + + Get SIDs associated with an account right. + + The logon account right to query. + True to throw on error. + The list of SIDs assigned to the account right. + + + + Get SIDs associated with an account right. + + The logon account right to query. + The list of SIDs assigned to the account right. + + + + Get account rights. + + Specify the type of account rights to get. + Account rights. + + + + Get all account rights. + + All account rights. + + + + Add account rights to the user. + + The user SID to add. + The list of account rights. + True to throw on error. + The NT status code. + + + + Add account rights to the user. + + The user SID to add. + The list of account rights. + The NT status code. + + + + Add account rights as privileges. + + The user SID to add. + The list of account privileges. + True to throw on error. + The NT status code. + + + + Add account rights as privileges. + + The user SID to add. + The list of account privileges. + + + + Add account rights as privileges. + + The user SID to add. + The list of account logon types. + True to throw on error. + The NT status code. + + + + Add account rights as privileges. + + The user SID to add. + The list of account logon types. + + + + Remove account rights from a user. + + The user SID to remove. + The list of account rights. + True to throw on error. + The NT status code. + + + + Remove account rights from a user. + + The user SID to remove. + The list of account rights. + + + + Remove account rights from a user. + + The user SID to remove. + The list of privileges. + True to throw on error. + The NT status code. + + + + Remove account rights from a user. + + The user SID to remove. + The list of account privileges. + + + + Remove account rights from a user. + + The user SID to remove. + The list of account rights. + True to throw on error. + The NT status code. + + + + Remove account rights from a user. + + The user SID to remove. + The list of account rights. + + + + Win32 memory utils. + + + + + Write memory to a process. + + The process to write to. + The base address in the process. + The data to write. + The number of bytes written to the location + Thrown on error. + + + + Write memory to a process. + + The process to write to. + The base address in the process. + The data to write. + The number of bytes written to the location + Thrown on error. + + + + Class to represent a TCP listener with process ID. + + + + Gets the local endpoint of a Transmission Control Protocol (TCP) connection. + An instance that contains the IP address and port on the local computer. + + + Gets the remote endpoint of a Transmission Control Protocol (TCP) connection. + An instance that contains the IP address and port on the remote computer. + + + Gets the state of this Transmission Control Protocol (TCP) connection. + One of the enumeration values. + + + + Get local address. + + + + + Get local port. + + + + + Get remote address. + + + + + Get remote port. + + + + + Gets the process ID of the listener on the local system. + + + + + Gets the time the socket was created. + + + + + Gets the owner of the module. This could be an executable path or a service name. + + + + + Class to represent a UDP listener with process ID. + + + + Gets the local endpoint of a Transmission Control Protocol (TCP) connection. + An instance that contains the IP address and port on the local computer. + + + + Get local address. + + + + + Get local port. + + + + + Gets the process ID of the listener on the local system. + + + + + Gets the time the socket was created. + + + + + Gets the owner of the module. This could be an executable path or a service name. + + + + + Gets if the UDP socket is bound to a specific port. + + + + + Utilities for Win32 network APIs. + + + + + Get a list of TCP listeners with process IDs. + + The address family to query. + True to throw on error. + The list of TCP listeners. + The built-in System.Net.NetworkInformation.SystemIPGlobalProperties.GetActiveTcpListeners doesn't expose the PID member so we have to reimplement it. + + + + Get a list of TCP listeners with process IDs. + + The address family to query. + The list of TCP listeners. + The built-in System.Net.NetworkInformation.SystemIPGlobalProperties.GetActiveTcpListeners doesn't expose the PID member so we have to reimplement it. + + + + Get a list of TCP listeners with process IDs. Returns both IPv4 and IPv6 listeners. + + The list of TCP listeners. + The built-in System.Net.NetworkInformation.SystemIPGlobalProperties.GetActiveTcpListeners doesn't expose the PID member so we have to reimplement it. + + + + Get a TCP listener for a TCP port. + + The address family of the IP address. + The TCP port. + The listener information, or null if not found. + + + + Get a list of UDP listeners with process IDs. + + The address family to query. + True to throw on error. + The list of UDP listeners. + + + + Get a list of UDP listeners with process IDs. + + The address family to query. + The list of UDP listeners. + + + + Get a list of UDP listeners with process IDs. Returns both IPv4 and IPv6 listeners. + + The list of UDP listeners. + + + + APPX Package Architecture. + + + + + X86 + + + + + ARM + + + + + X64 + + + + + Neutral + + + + + ARM64 + + + + + APPX Package Origin. + + + + + Unknown origin. + + + + + Unsigned. + + + + + Inbox. + + + + + Store. + + + + + Developer unsigned. + + + + + Developer signed. + + + + + Line-of-business. + + + + + Class which represents an AppContainer package identity. + + + + + Process architecture. + + + + + Package version. + + + + + Package family name. + + + + + Publisher (not always available). + + + + + Resource ID. + + + + + Published ID. + + + + + Full package name. + + + + + Package origin. + + + + + Package family name. + + + + + Package install path. + + + + + The list of application model IDs. + + + + + Get the GetStagedPackageOrigin method as a delegate. It's supposed to be exposed by kernel32, + but actually doesn't seem to be. + + + + + + Create from a package full name. + + The package full name. + Query for full information (needs to be installed for the current user). + True to throw on error. + The package identity. + + + + Create from a package full name. + + The package full name. + Query for full information (needs to be installed for the current user). + The package identity. + + + + Create from a token. + + The AppContainer token. + Query for full information (needs to be installed for the current user). + True to throw on error. + The package identity. + + + + Create from a token. + + The AppContainer token. + Query for full information (needs to be installed for the current user). + The package identity. + + + + Class to represent a printer object. + + + + + Dispose the printer object. + + + + + Open a printer or server. + + The name of the printer or server. If this is null or empty then it's the local server. + The desired access on the printer. + True to throw on error. + The opened printer. + + + + Open a printer. + + The name of the printer. + The desired access on the printer. + The opened printer. + + + + Open a printer. + + The name of the printer. + The opened printer. + + + + Get security descriptor for the printer. + + True to throw on error. + The printer's security descriptor. + + + + Get security descriptor for the printer. + + The printer's security descriptor. + + + + Access rights for a print spooler object. + + + + + Utils for print spooler. + + + + + Name for the fake printer NT type. + + + + + Name for the fake print server NT type. + + + + + Name for the fake print server NT type. + + + + + Get the generic mapping for printer objects. + + The printer objects generic mapping. + + + + Get the generic mapping for job objects. + + The job objects generic mapping. + + + + Get the generic mapping for server objects. + + The server objects generic mapping. + + + + Get the appropriate NT type for the printer path. + + The printer path, e.g. \\server\printer. + The NT type. + + + + Class representing an RPC ALPC server. + + + + + The PID of the process which contains the ALPC server. + + + + + The name of the process which contains the ALPC server. + + + + + List of known endpoints potentially accessible via this RPC server. + + + + + The number of endpoints. + + + + + The name of the ALPC server. + + + + + The security descriptor of the ALPC server. + + + + + Get RPC ALPC servers for a specific process. + + The ID of the process. + The list of RPC ALPC servers. + If the process is suspended or frozen this call can hang. + + + + Get a list of all RPC ALPC servers. + + This works by discovering any server ALPC ports owned by the process and querying for interfaces. + This will ignore any frozen processes (primarily UWP) as they can't respond to the endpoint enumeration. + The list of RPC ALPC servers. + + + + Get the RPC ALPC server for an ALPC port object path. + + The object manager path to the ALPC port. + The ALPC RPC server. + Needs an API which is only available from Windows 10 19H1. + + + + Overridden ToString method. + + Formatted string. + + + + Generic RPC client. + + + + + Constructor. + + The interface ID. + Version of the interface. + + + + Constructor. + + The RPC server to bind to. + + + + Send and receive an RPC message. + + The procedure number. + Marshal NDR buffer for the call. + Unmarshal NDR buffer for the result. + + + + Class to represent an RPC endpoint. + + + + + The interface ID of the endpoint. + + + + + The interface version. + + + + + The object UUID. + + + + + Optional annotation. + + + + + RPC binding string. + + + + + Endpoint protocol sequence. + + + + + Endpoint network address. + + + + + Endpoint name. + + + + + Endpoint network options. + + + + + The endpoint path. + + + + + Indicates this endpoint is registered with the endpoint mapper. + + + + + Overridden ToString method. + + String form of the object. + + + + Get information about the server process. + + + + + + Static class to access information from the RPC mapper. + + + + + Query all endpoints registered on the local system. + + List of endpoints. + + + + Query all endpoints registered based on a binding string. + + The binding string for the server to search on. If null or empty will search localhost. + List of endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint. + + The binding string for the server to search on. If null or empty will search localhost. + Interface UUID to lookup. + Interface version lookup. + The list of registered RPC endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint. + + Interface UUID to lookup. + Interface version lookup. + The list of registered RPC endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint ignoring the version. + + The binding string for the server to search on. If null or empty will search localhost. + Interface UUID to lookup. + The list of registered RPC endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint ignoring the version. + + Interface UUID to lookup. + The list of registered RPC endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint. + + The server interface. + The list of registered RPC endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint via ALPC. + + Interface UUID to lookup. + Interface version lookup. + The list of registered RPC endpoints. + + + + Query for endpoints registered on the local system for an RPC endpoint via ALPC. + + The server interface. + The list of registered RPC endpoints. + + + + Query for endpoints for a RPC binding. + + The ALPC port to query. Can be a full path as long as it contains \RPC Control\ somewhere. + True to throw on error. + The list of endpoints on the RPC binding. + + + + Query for endpoints for a RPC binding. + + The ALPC port to query. Can be a full path as long as it contains \RPC Control\ somewhere. + The list of endpoints on the RPC binding. + + + + Query for endpoints for a RPC binding. + + The RPC binding to query, e.g. ncalrpc:[PORT] + True to throw on error. + The list of endpoints on the RPC binding. + + + + Query for endpoints for a RPC binding. + + The RPC binding to query, e.g. ncalrpc:[PORT] + The list of endpoints on the RPC binding. + + + + Resolve the local binding string for this service from the local Endpoint Mapper and return the endpoint. + + The protocol sequence to lookup. + Interface UUID to lookup. + Interface version lookup. + The mapped endpoint. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + + + + Resolve the local binding string for this service from the local Endpoint Mapper and return the endpoint. + + The protocol sequence to lookup. + The network address for the lookup. + Interface UUID to lookup. + Interface version lookup. + The mapped endpoint. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + + + + Resolve the local binding string for this service from the local Endpoint Mapper and return the endpoint. + + The string binding to map. + Interface UUID to lookup. + Interface version lookup. + The mapped endpoint. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + + + + Resolve the local binding string for this service from the local Endpoint Mapper and return the ALPC port path. + + Interface UUID to lookup. + Interface version lookup. + The mapped endpoint. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + + + + Resolve the local binding string for this service from the local Endpoint Mapper and return the ALPC port path. + + The server interface. + The mapped endpoint. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + + + + Finds ALPC endpoints which allows for the server binding. This brute forces all ALPC ports to try and find + something which will accept the bind. + + This could hang if the ALPC port is owned by a suspended process. + Interface UUID to lookup. + Interface version lookup. + A list of RPC endpoints which can bind the interface. + Throws on error. + + + + Finds an ALPC endpoint which allows for the server binding. This brute forces all ALPC ports to try and find + something which will accept the bind. + + This could hang if the ALPC port is owned by a suspended process. + Interface UUID to lookup. + Interface version lookup. + The first RPC endpoints which can bind the interface. Throws exception if nothing found. + Throws on error. + + + + Resolve the binding string for this service from the Endpoint Mapper. + + The binding string to map. + Interface UUID to lookup. + Interface version lookup. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + The RPC binding string. Empty string if it doesn't exist or the lookup failed. + + + + Resolve the binding string for this service from the the Endpoint Mapper. + + The protocol sequence to lookup. + The network address to lookup the endpoint. + Interface UUID to lookup. + Interface version lookup. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + The RPC binding string. Empty string if it doesn't exist or the lookup failed. + + + + Resolve the binding string for this service from the local Endpoint Mapper. + + The protocol sequence to lookup. + Interface UUID to lookup. + Interface version lookup. + This only will return a valid value if the service is running and registered with the Endpoint Mapper. It can also hang. + The RPC binding string. Empty string if it doesn't exist or the lookup failed. + + + + A class to represent an RPC server. + + + + + Resolve the current running endpoint for this server. + + + + + + Format the RPC server as text. + + The formatted RPC server. + + + + Format the RPC server as text. + + True to remove comments from the output. + The formatted RPC server. + + + + Format the RPC server as text. + + True to remove comments from the output. + Formating using C++ pseduo syntax. + The formatted RPC server. + + + + Serialize the RPC server to a stream. + + The stream to hold the serialized server. + Only use the output of this method with the Deserialize method. No guarantees of compatibility is made between + versions of the library or the specific format used. + + + + Serialize the RPC server to a byte array. + + The serialized data. + Only use the output of this method with the Deserialize method. No guarantees of compatibility is made between + versions of the library or the specific format used. + + + + The RPC server interface UUID. + + + + + The RPC server interface version. + + + + + The RPC transfer syntax GUID. + + + + + The RPC transfer syntax version. + + + + + The number of RPC procedures. + + + + + The list of RPC procedures. + + + + + The NDR RPC server. + + + + + List of parsed complext types. + + + + + Path to the PE file this server came from (if known) + + + + + Name of the the PE file this server came from (if known) + + + + + Offset into the PE file this server was parsed from. + + + + + Name of the service this server would run in (if known). + + + + + Display name of the service this server would run in (if known). + + + + + True if the service is currently running. + + + + + List of endpoints for this service if running. + + + + + Count of endpoints for this service if running. + + + + + This parsed interface represents a client. + + + + + Parse all RPC servers from a PE file. + + The PE file to parse. + Path to a DBGHELP DLL to resolve symbols. + Symbol path for DBGHELP + This only works for PE files with the same bitness as the current process. + A list of parsed RPC server. + + + + Parse all RPC servers from a PE file. + + The PE file to parse. + Path to a DBGHELP DLL to resolve symbols. + Symbol path for DBGHELP + True to parse client RPC interfaces. + This only works for PE files with the same bitness as the current process. + A list of parsed RPC server. + + + + Parse all RPC servers from a PE file. + + The PE file to parse. + Path to a DBGHELP DLL to resolve symbols. + Symbol path for DBGHELP + True to parse client RPC interfaces. + Ignore symbol resolving. + This only works for PE files with the same bitness as the current process. + A list of parsed RPC server. + + + + Parse all RPC servers from a PE file. + + The PE file to parse. + Path to a DBGHELP DLL to resolve symbols. + Symbol path for DBGHELP + Flags for the RPC parser. + This only works for PE files with the same bitness as the current process. + A list of parsed RPC server. + + + + Deserialize an RPC server instance from a stream. + + The stream to deserialize from. + The RPC server instance. + The data used by this method should only use the output from serialize. No guarantees of compatibility is made between + versions of the library or the specific format used. + + + + Deserialize an RPC server instance from a byte array. + + The byte array to deserialize from. + The RPC server instance. + The data used by this method should only use the output from serialize. No guarantees of compatibility is made between + versions of the library or the specific format used. + + + + Get the default RPC server security descriptor. + + The default security descriptor. + + + + Flags for the RPC server parser. + + + + + None. + + + + + Parse client entries. + + + + + Ignore symbols when parsing. + + + + + Try and resolve structure names. Needs private symbols. + + + + + Enable a symbol server fallback. If the copy of dbghelp doesn't have a symsrv.dll + then download from a public symbol URL to a local cache directory during symbol + resolving. + + + + + Base class for a RPC client. + + + + + Constructor. + + The interface ID. + Version of the interface. + + + + Constructor. + + The interface ID as a string. + Major version of the interface. + Minor version of the interface. + + + + Send and receive an RPC message. + + The procedure number. + The NDR data representation. + Marshal NDR buffer for the call. + List of handles marshaled into the buffer. + Unmarshal NDR buffer for the result. + + + + Method to call to check if the transport supports synchronous pipes. + + + + + Method to call to check if the transport supports asynchronous pipes. + + + + + Get whether the client is connected or not. + + + + + Get the endpoint that we connected to. + + + + + Get the protocol sequence that we connected to. + + + + + Get or set the current Object UUID used for calls. + + + + + The RPC interface ID. + + + + + The RPC interface version. + + + + + Get the client transport object. + + + + + Connect the client to a RPC endpoint. + + The endpoint for RPC server. + The transport security for the connection. + + + + Connect the client to a RPC endpoint. + + The endpoint for RPC server. + The security quality of service for the connection. + + + + Connect the client to a RPC endpoint. + + The protocol sequence for the transport. + The endpoint for the protocol sequence. + The network address for the protocol sequence. + The security quality of service for the connection. + + + + Connect the client to a RPC endpoint. + + The protocol sequence for the transport. + The endpoint for the protocol sequence. + The network address for the protocol sequence. + The transport security for the connection. + + + + Connect the client to a RPC endpoint. + + The protocol sequence for the transport. + The endpoint for the protocol sequence. + The security quality of service for the connection. + + + + Connect the client to a RPC endpoint. + + The protocol sequence for the transport. + The endpoint for the protocol sequence. + The transport security for the connection. + + + + Connect the client to an ALPC RPC port. + + The path to the ALPC RPC port. + The security quality of service for the port. + + + + Connect the client to a RPC endpoint. + + The binding string for the RPC server. + The transport security for the connection. + + + + Connect the client to an ALPC RPC port. + + The path to the ALPC RPC port. If an empty string the endpoint will be looked up in the endpoint mapper. + + + + Connect the client to an ALPC RPC port. + + The ALPC endpoint will be looked up in the endpoint mapper. + + + + Dispose of the client. + + + + + Disconnect the client. + + + + + Builder to create an RPC client from an RpcServer class. + + + + + Build a source file for the RPC client. + + The RPC server to base the client on. + Additional builder arguments. + The code generation options, can be null. + The code dom provider, such as CSharpDomProvider + The source code file. + + + + Build a C# source file for the RPC client. + + The RPC server to base the client on. + Additional builder arguments. + The C# source code file. + + + + Build a C# source file for the RPC client. + + The RPC server to base the client on. + The C# source code file. + + + + Build a source file for RPC complex types. + + The RPC complex types to build the encoders from. + Name of the decoder class. Can be null or empty to use default. + Name of the encoder class. Can be null or empty to use default. + Name of the generated namespace. Null or empty specified no namespace. + The code generation options, can be null. + The code dom provider, such as CSharpDomProvider + True to wrap complex decoders in a unique pointer. + The source code file. + + + + Build a source file for RPC complex types. + + The RPC complex types to build the encoders from. + Name of the decoder class. Can be null or empty to use default. + Name of the encoder class. Can be null or empty to use default. + Name of the generated namespace. Null or empty specified no namespace. + The code generation options, can be null. + The code dom provider, such as CSharpDomProvider + The source code file. + + + + Build a source file for RPC complex types. + + The RPC complex types to build the encoders from. + Name of the decoder class. Can be null or empty to use default. + Name of the encoder class. Can be null or empty to use default. + Name of the generated namespace. Null or empty specified no namespace. + True to wrap complex decoders in a unique pointer. + The source code file. + + + + Build a source file for RPC complex types. + + The RPC complex types to build the encoders from. + Name of the decoder class. Can be null or empty to use default. + Name of the encoder class. Can be null or empty to use default. + Name of the generated namespace. Null or empty specified no namespace. + The source code file. + + + + Build a source file for RPC complex types. + + The RPC complex types to build the encoders from. + The C# source code file. + + + + Compile an in-memory assembly for the RPC client. + + The RPC server to base the client on. + Additional builder arguments. + True to ignore cached assemblies. + Code DOM provider to compile the assembly. + The compiled assembly. + This method will cache the results of the compilation against the RpcServer. + + + + Compile an in-memory assembly for the RPC client. + + The RPC server to base the client on. + Additional builder arguments. + True to ignore cached assemblies. + The compiled assembly. + This method will cache the results of the compilation against the RpcServer. + + + + Compile an in-memory assembly for the RPC client. + + The RPC server to base the client on. + Additional builder arguments. + The compiled assembly. + This method will cache the results of the compilation against the RpcServer. + + + + Compile an in-memory assembly for the RPC client. + + The RPC server to base the client on. + True to ignore cached assemblies. + The compiled assembly. + This method will cache the results of the compilation against the RpcServer. + + + + Compile an in-memory assembly for the RPC client. + + The RPC server to base the client on. + The compiled assembly. + This method will cache the results of the compilation against the RpcServer. + + + + Create an instance of an RPC client. + + The RPC server to base the client on. + True to ignore cached assemblies. + Additional builder arguments. + Code DOM provider to compile the assembly. + The created RPC client. + This method will cache the results of the compilation against the RpcServer. + + + + Create an instance of an RPC client. + + The RPC server to base the client on. + True to ignore cached assemblies. + Additional builder arguments. + The created RPC client. + This method will cache the results of the compilation against the RpcServer. + + + + Create an instance of an RPC client. + + The RPC server to base the client on. + Additional builder arguments. + The created RPC client. + This method will cache the results of the compilation against the RpcServer. + + + + Create an instance of an RPC client. + + The RPC server to base the client on. + The created RPC client. + This method will cache the results of the compilation against the RpcServer. + + + + Flags for the RPC client builder. + + + + + None. + + + + + Generate public properties on the client to create defined complex types. + + If not specified then constructors will be defined on the types themselves. + + + + Insert breakpoints into the start of every generated method. Also enables debugging. + + + + + Disable calculated correlation information. This will prevent automatic updating of array and + string lengths based on other parameters or fields. This might result in unexpected behavior or + call failures. This won't disable correlations for union types or constant correlations. + + + + + Don't emit any namespace, normally not specifying a namespace will auto-generate one. + + + + + Output FC_CHAR as if the original compiler had specified unsigned char types. Basically converts + System.SByte to System.Byte where needed which makes the methods easier to use. + + + + + Return ref/out parameters via a structure rather than requiring ref/out parameters in client + methods. + + + + + When using StructureReturn hide the original out/ref methods. + + + + + Generate encode/decode methods for complex types. + + + + + Exclude any text in the source code which can change between generations. + + + + + Wrap complex type decoders with a unique pointer. + + + + + Marshal pipe parameters using arrays. + + + + + Arguments for the RPC client builder. + + + + + Builder flags. + + + + + The namespace for the client class. + + + + + The class name of the client. + + + + + The class name of the complex type encoding class. + + + + + The class name of the complex type decoder class. + + + + + Enable debugging on built code. + + + + + GetHashCode implementation. + + The hash code. + + + + Equals implementation. + + The object to compare against. + True if the object is equal. + + + + Response data from an RPC client call. + + + + + The marshaled NDR data from the response. + + + + + Any object handles returned in the response. (only for ALPC). + + + + + Indicates the NDR data representation for the response. + + + + + Class to represent details about a server process. + + + + + The server process ID. + + + + + The server session ID. + + + + + The name of the process. + + + + + Get the process image path. + + + + + Overridden ToString method. + + + + + + Some addition internal utilities for RPC code. + + + + + Specify RPC trace level. + + Specify the RPC trace level. + This dumps NDR data. Verbose dumps the binary data. + + + + Specify RPC transport trace level. + + Specify the RPC transport trace level. + Verbose dumps the transport binary data. + + + + Helper to dereference a type. + + The type to dereference. + The value to dereference. + The dereferenced result. + + + + Helper to dereference a type. + + The type to dereference. + The value to dereference. + The dereferenced result. + + + + Helper to check for NULL. + + The type to check. + The object to check. + The name of the value to check. + The checked value. + + + + Helper to check for NULL. + + The type to check. + The object to check. + The name of the value to check. + The checked value. + + + + Helper to check for NULL. + + The type to check. + The object to check. + The name of the value to check. + The checked value. + + + + Helper to dereference a type. + + The type to dereference. + The value to dereference. + The dereferenced result. + + + + Helper to perform a plus unary operation. + + The value to apply the operator to. + The result. + + + + Helper to perform a minus unary operation. + + The value to apply the operator to. + The result. + + + + Helper to perform a complement unary operation. + + The value to apply the operator to. + The result. + + + + Perform a ternary operation. + + The condition to evaluate as != 0. + The result if true. + The result if false. + The result. + + + + Perform ADD. + + The left operand. + The right operand. + The result. + + + + Perform SUB. + + The left operand. + The right operand. + The result. + + + + Perform MUL. + + The left operand. + The right operand. + The result. + + + + Perform DIV. + + The left operand. + The right operand. + The result. + + + + Perform MOD. + + The left operand. + The right operand. + The result. + + + + Perform Bitwise AND. + + The left operand. + The right operand. + The result. + + + + Perform Bitwise OR. + + The left operand. + The right operand. + The result. + + + + Perform bitwise XOR. Needed as Code DOM doesn't support XOR. + + The left operand. + The right operand. + The result. + + + + Perform bitwise LEFTSHIFT. + + The left operand. + The right operand. + The result. + + + + Perform bitwise RIGHTSHIFT. + + The left operand. + The right operand. + The result. + + + + Perform logical AND. + + The left operand. + The right operand. + The result. + + + + Perform logical OR. + + The left operand. + The right operand. + The result. + + + + Perform EQUAL. + + The left operand. + The right operand. + The result. + + + + Perform NOTEQUAL. + + The left operand. + The right operand. + The result. + + + + Perform GREATER. + + The left operand. + The right operand. + The result. + + + + Perform GREATEREQUAL. + + The left operand. + The right operand. + The result. + + + + Perform LESS. + + The left operand. + The right operand. + The result. + + + + Perform LESSEQUAL. + + The left operand. + The right operand. + Returns left LESSEQUAL right. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The value + True if value != 0. + + + + Convert value to a boolean. + + The nullable value + True if value has a value set. + + + + Convert value to a boolean. + + The nullable value + True if value has a value set. + + + + Compose a string binding from its parts. + + The object UUID. + The protocol sequence. + The network address. + The endpoint. + The options. + The composed binding string. + + + + Interface to implement an RPC client transport. + + + + + Bind the RPC transport to a specified interface. + + The interface ID to bind to. + The interface version to bind to. + The transfer syntax to use. + The transfer syntax version to use. + + + + Send and receive an RPC message. + + The procedure number. + The object UUID for the call. + NDR data representation. + Marshal NDR buffer for the call. + List of handles marshaled into the buffer. + Client response from the send. + + + + Add and authenticate a new security context. + + The transport security for the context. + The created security context. + + + + Disconnect the transport. + + + + + Get whether the client is connected or not. + + + + + Get the endpoint the client is connected to. + + + + + Get the transport protocol sequence. + + + + + Get whether the client has been authenticated. + + + + + Get the transport's authentication type. + + + + + Get the transport's authentication level. + + + + + Get information about the local server process, if known. + + + + + Get the current Call ID. + + + + + Indicates if this connection supported multiple security context. + + + + + Get the list of negotiated security context. + + + + + Get or set the current security context. + + + + + Get whether the transport supports synchronous pipes. + + + + + RPC client transport over ALPC. + + + + + Constructor. + + The path to connect. The format depends on the transport. + The security quality of service for the connection. + + + + Constructor. + + The path to connect. The format depends on the transport. + The security quality of service for the connection. + Timeout for connection. + + + + Bind the RPC transport to an interface. + + The interface ID to bind to. + The interface version to bind to. + The transfer syntax to use. + The transfer syntax version to use. + + + + Send and receive an RPC message. + + The procedure number. + The object UUID for the call. + NDR data representation. + Marshal NDR buffer for the call. + List of handles marshaled into the buffer. + Client response from the send. + + + + Dispose of the client. + + + + + Disconnect the client. + + + + + Add and authenticate a new security context. + + The transport security for the context. + The created security context. + + + + Get whether the client is connected or not. + + + + + Get the ALPC port path that we connected to. + + + + + Get the current Call ID. + + + + + Get the transport protocol sequence. + + + + + Get information about the local server process, if known. + + + + + Get whether the client has been authenticated. + + + + + Get the transports authentication type. + + + + + Get the transports authentication level. + + + + + Indicates if this connection supported multiple security context. + + + + + Get the list of negotiated security context. + + + + + Get or set the current security context. + + + + + Get whether the transport supports synchronous pipes. + + + + + Flags to specify RPC authentication capabilities. + + + + + None. + + + + + Enable mutual authentication. + + + + + Enable a NULL session authentication. + + + + + Enable delegation of credentials if supported. + + + + + Authentication level for RPC transport. + + + + + Default. + + + + + None. + + + + + Connect only. + + + + + Call only. + + + + + Packet only. + + + + + Packet integrity. + + + + + Packer privacy and integrity. + + + + + RPC authentication type. + + + + + Default. Uses WinNT. + + + + + No authentication. + + + + + DCE private. + + + + + DCE public. + + + + + DEC public. + + + + + SPNEGO authentication. + + + + + WinNT authentication, i.e. NTLM. + + + + + Secure channel. + + + + + Kerberos. + + + + + DPA. + + + + + MSN. + + + + + Digest. + + + + + Kernel. + + + + + SPNEGO extender. + + + + + PKU2U + + + + + LiveSSP + + + + + LiveXP SSP. + + + + + CloudAP. + + + + + Netlogon. + + + + + MS Online. + + + + + Message Queue. + + + + + Interface to implement an RPC client transport factory. + + + + + Connect a new RPC client transport. + + The RPC endpoint. + The transport security for the connection. + The connected transport. + + + + Factory for RPC client transports. + + + + + Add a new transport factory. + + The protocol sequence to add. + The transport factory. + + + + Connect a client transport from an endpoint. + + The RPC endpoint. + The security quality of service for the connection. + The connected client transport. + Thrown if protocol sequence unsupported. + Other exceptions depending on the connection. + + + + Connect a client transport from an endpoint. + + The RPC endpoint. + The transport security for the connection. + The connected client transport. + Thrown if protocol sequence unsupported. + Other exceptions depending on the connection. + + + + Base class for a DCE/RPC connected client transport. This implements the common functions + of the DCE/RPC specs for connected network based RPC transports. + + + + + Constructor. + + The initial maximum receive fragment length. + The initial maximum send fragment length. + The transport security for the connection. + The data representation. + + + + Read the next fragment from the transport. + + The maximum receive fragment length. + The read fragment. + + + + Write the fragment to the transport. + + The fragment to write. + True if successfully wrote the fragment. + + + + Get whether the client is connected or not. + + + + + Get the endpoint the client is connected to. + + + + + Get the transport protocol sequence. + + + + + Get information about the server process, if known. + + + + + Get whether the client has been authenticated. + + + + + Get the transports authentication type. + + + + + Get the transports authentication level. + + + + + Get the transport authentication context. + + + + + Indicates if this connection supported multiple security context. + + + + + Get the list of negotiated security context. + + + + + Get or set the current security context. + + + + + Get the current Call ID. + + + + + Get maximum receive fragment. + + + + + Get maximum send fragment. + + + + + Get association group ID. + + + + + Get whether the transport supports synchronous pipes. + + + + + Bind the RPC transport to a specified interface. + + The interface ID to bind to. + The interface version to bind to. + The transfer syntax to use. + The transfer syntax version to use. + + + + Add and authenticate a new security context. + + The transport security for the context. + The created security context. + + + + Send and receive an RPC message. + + The procedure number. + The object UUID for the call. + NDR data representation. + Marshal NDR buffer for the call. + List of handles marshaled into the buffer. + Client response from the send. + + + + Disconnect the transport. + + + + + Enable or disable bind time feature negotiation. You need to enable this to + use multiple security context. + + Should be set before connecting an RPC client. + + + + Dispose the transport. + + + + + Extended error information. + + + + + Computer name. + + + + + Process ID. + + + + + Timestamp. + + + + + Generating component. + + + + + Status code. + + + + + Detection location. + + + + + Flags. + + + + + Extra parameters. + + + + + Exception for RPC fault conditions. + + + + + Constructor. + + The RPC status code. + + + + Get extended error information. + + + + + RPC client transport over HyperV sockets. + + + + + Constructor. + + The HyperV socket endpoint to connect to. + The transport security for the connection. + + + + Get the transport protocol sequence. + + + + + RPC client transport over named pipes. + + + + + Constructor. + + The NT pipe path to connect. e.g. \??\pipe\ABC. + The transport security for the connection. + + + + Dispose of the client. + + + + + Disconnect the client. + + + + + Read the next fragment from the transport. + + The maximum receive fragment length. + The read fragment. + + + + Write the fragment to the transport. + + The fragment to write. + True if successfully wrote the fragment. + + + + Get whether the client is connected or not. + + + + + Get the named pipe port path that we connected to. + + + + + Get the transport protocol sequence. + + + + + Get information about the local server process, if known. + + + + + Class to implement a RPC client transport based on a stream. + + + + + Constructor. + + The stream to use to communicate with the transport. + The initial maximum receive fragment length. + The initial maximum send fragment length. + The transport security for the connection. + The data representation. + + + + Read the next fragment from the transport. + + The maximum receive fragment length. + The read fragment. + + + + Write the fragment to the transport. + + The fragment to write. + True if successfully wrote the fragment. + + + + Class to implement RPC over a stream based socket. + + + + + Constructor. + + The socket to use to communicate. + The initial maximum receive fragment length. + The initial maximum send fragment length. + The transport security for the connection. + The data representation. + + + + Disconnect the client. + + + + + Dispose of the client. + + + + + Get whether the client is connected or not. + + + + + Get the named pipe port path that we connected to. + + + + + RPC client transport over TCP/IP; + + + + + Get the server process information. + + The server process information. + + + + Constructor. + + The hostname to connect to. + The TCP port to connect to. + The transport security for the connection. + + + + Get the transport protocol sequence. + + + + + Get information about the local server process, if known. + + + + + Exception generated by the RPC transport. + + + + + Constructor. + + + + + Constructor. + + Exception message. + + + + Constructor. + + Exception message. + Inner exception. + + + + Class to represent the RPC transport security. + + + + + Security quality of service. + + + + + Authentication level. + + + + + Authentication type. + + + + + Authentication credentials. + + + + + The SPN for the authentication. + + + + + Authentication capabilities. + + + + + Constructor. + + Factory to create a non-standard authentication context. + You can use this version to create a mechanism to pass existing tokens such as pass-the-hash or sending arbitrary Kerberos tickets. + + + + Constructor. + + Security quality of service. + + + + Query the service principal name for the server. + + The binding string for the server. + The authentication service to query. + True to throw on error. + The service principal name. + + + + Query the service principal name for the server. + + The binding string for the server. + The authentication service to query. + The service principal name. + + + + Class to represent an RPC transport security context. + + + + + The ID of the security context. + + + + + The RPC transport security settings. + + + + + The authentication context. + + + + + The negotiated authentication type. + + + + + The authentication level. + + + + + Dummy class to mark the old name as obsolete. + + + + + Detaches the current buffer and allocates a new one. + + The detached buffer. + The original buffer will become invalid after this call. + + + + Safe handle for a loaded library. + + + + + Constructor + + The handle to the library + True if the handle is owned by this object. + + + + Release handle. + + True if handle released. + + + + Get the address of an exported function, throw if the function doesn't exist. + + The name of the exported function. + True to throw on error. + Pointer to the exported function. + Thrown if the name doesn't exist. + + + + Get the address of an exported function from an ordinal. + + The ordinal of the exported function. + True to throw on error. + Pointer to the exported function. + Thrown if the ordinal doesn't exist. + + + + Get the address of an exported function. + + The name of the exported function. + Pointer to the exported function, or IntPtr.Zero if it can't be found. + + + + Get the address of an exported function from an ordinal. + + The ordinal of the exported function. + Pointer to the exported function, or IntPtr.Zero if it can't be found. + + + + Get a delegate which points to an unmanaged function. + + The delegate type. + The name of the function to lookup. + True to throw on error. + The delegate. + + + + Get a delegate which points to an unmanaged function. + + The delegate type. The name of the delegate is used to lookup the name of the function. + True to throw on error. + The delegate. + + + + Get a delegate which points to an unmanaged function. + + The delegate type. + The name of the function to lookup. + The delegate. + + + + Get a delegate which points to an unmanaged function. + + The delegate type. The name of the delegate is used to lookup the name of the function. + The delegate. + + + + Pin the library into memory. This prevents FreeLibrary unloading the library until + the process exits. + + + + + Parse a library's delayed import information. + + A dictionary containing the location of import information keyed against the IAT address. + + + + Get the image sections from a loaded library. + + The list of image sections. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type of the resource. + True to throw on error. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type name of the resource. + True to throw on error. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The well known type of the resource. + True to throw on error. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type of the resource. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type name of the resource. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The well known type of the resource. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type of the resource. + True to throw on error. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type name of the resource. + True to throw on error. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The well known type of the resource. + True to throw on error. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type of the resource. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The type name of the resource. + The bytes for the resource. + + + + Load the resource's bytes from the module. + + The name of the resource. + The well known type of the resource. + The bytes for the resource. + + + + Get list of resource types from the loaded library. + + The list of resource types. + + + + Get list of resource types from the loaded library. + + The type for the resources. + True to load the resource data. + The list of resource types. + + + + Get list of resource types from the loaded library. + + The type for the resources. + The list of resource types. + This always loads resource data into memory. + + + + Get list of resource types from the loaded library. + + The typename for the resources. + True to load the resource data. + The list of resource types. + + + + Get list of resource types from the loaded library. + + The typename for the resources. + The list of resource types. + This always loads resource data into memory. + + + + Get list of resource types from the loaded library. + + The well known type for the resources. + True to load the resource data. + The list of resource types. + + + + Get list of resource types from the loaded library. + + The well known type for the resources. + The list of resource types. + This always loads resource data into memory. + + + + Get list of resource types from the loaded library. + + True to load the resource data. + The list of resource types. + + + + Get list of resource types from the loaded library. + + The list of resource types. + This always loads resource data into memory. + + + + Load a string for the library's string resource table. + + The ID of the string. + True to throw on error. + The loaded string. + + + + Load a string for the library's string resource table. + + The ID of the string. + The loaded string. + + + + Increases the reference count and returns a new instance. + + + + + + Get path to loaded module. + + + + + Get the module name. + + + + + Whether this library is mapped as an image. + + + + + Whether this library is mapped as a datafile. + + + + + Get current mapped image base. + + + + + Get original image base address. + + + + + Get image entry point RVA. + + + + + Get image entry point address as mapped. + + + + + Get whether the image is 64 bit or not. + + + + + Get the image's DLL characteristics flags. + + + + + Get exports from the DLL. + + + + + Get imports from the DLL. + + + + + Return resolved API set imports for the DLL. + + + + + Get CodeView Debug Data from DLL. + + + + + Get image signing level. + + + + + Get embedded enclave configuration. + + + + + Load a library into memory. + + The path to the library. + Additonal flags to pass to LoadLibraryEx + True to throw on error. + Handle to the loaded library. + + + + Load a library into memory. + + The path to the library. + Additonal flags to pass to LoadLibraryEx + Handle to the loaded library. + + + + Load a library into memory. + + The path to the library. + Handle to the loaded library. + + + + Get the handle to an existing loading library by name. + + The name of the module. + The handle to the loaded library. + Thrown if the module can't be found. + This will take a reference on the library, you should dispose the handle after use. + + + + Get the handle to an existing loading library by name. + + The name of the module. + The handle to the loaded library. Returns Null if not found. + This will take a reference on the library, you should dispose the handle after use. + + + + Get the handle to an existing loading library by an address in the module. + + An address inside the module. + The handle to the loaded library, null if the address isn't inside a valid module. + This will take a reference on the library, you should dispose the handle after use. + + + + Pin the library into memory. This prevents FreeLibrary unloading the library until + the process exits. + + The name of the module to pin. + + + + Pin the library into memory. This prevents FreeLibrary unloading the library until + the process exits. + + The address of the module to pin. + + + + NULL load library handle. + + + + + Represents an impersonation safe win32 exception, which resolves the win32 message when Message is called. + + + + + Constructor. + + + + + Constructor. + + Win32 error. + + + + The message for the exception. + + + + + Access rights for system audit policy. + + + + + System Audit Category. + + + + + System Audit Category. + + + + + The user for the per-user category. + + + + + System Audit Category base class. + + + + + The ID of the category. + + + + + The name of the category. + + + + + List of sub categories. + + + + + Convert to string. + + The name of the category. + + + + Set audit policy on all sub categories. + + The flags to set. + True to throw on error. + The audit policy flags. + + + + Set audit policy on all sub categories. + + The flags to set. + The audit policy flags. + + + + Type of global SACL to query or set. + + + + + File type. + + + + + Key type. + + + + + Policy audit event type. + + + + + Audit policy flags. + + + + + Set unchanged. + + + + + Audit on success. + + + + + Audit on failure. + + + + + Audit nothing. + + + + + Per user policy flags. + + + + + Set unchanged. + + + + + Audit on success included. + + + + + Audit on success excluded. + + + + + Audit on failure included. + + + + + Audit on failure excluded. + + + + + Audit nothing. + + + + + Utilities for security auditing policy. + + + + + Name for the fake Audit NT type. + + + + + Get the generic mapping for directory services. + + The directory services generic mapping. + + + + Get a fake NtType for System Audit Policy. + + The fake Directory Services NtType + + + + Query the Auditing Security Descriptor. + + The security information to query. + True to throw on error. + The security descriptor. + + + + Query the Auditing Security Descriptor. + + The security information to query. + The security descriptor. + + + + Query the Auditing Security Descriptor. + + The security descriptor. + + + + Set the Auditing Security Descriptor. + + The security information to set. + The security descriptor to set. + True to throw on error. + The NT status code. + + + + Set the Auditing Security Descriptor. + + The security information to set. + The security descriptor to set. + The NT status code. + + + + Query the global SACL. + + The global SACL type. + True to throw on error. + The global SACL in a Security Descriptor. + + + + Query the global SACL. + + The global SACL type. + The global SACL in a Security Descriptor. + + + + Set the global SACL. + + The global SACL type. + The SACL to set in an Security Descriptor. + True to throw on error. + The NT status code. + + + + Set the global SACL. + + The global SACL type. + The SACL to set in an Security Descriptor. + The NT status code. + + + + Get list of Audit Policy categories. + + True to throw on error. + The list of categories. + + + + Get list of Audit Policy categories. + + The list of categories. + + + + Get a single category. + + The category type. + The audit category. + + + + Get a single category. + + The category GUID. + The audit category. + + + + Get all per-user categories for denied users. + + True to throw on error. + The list of per-user categories. + + + + Get all per-user categories for denied users. + + The list of per-user categories. + + + + Get list of per-user Audit Policy categories. + + The user SID to query. + True to throw on error. + The list of categories. + + + + Get list of per-user Audit Policy categories. + + The user SID to query. + The list of categories. + + + + Get a single per-user category. + + The user SID to query. + The category type. + The audit category. + + + + Get a single per-user category. + + The user SID to query. + The category GUID. + The audit category. + + + + Class representing an Audit Sub Category. + + + + + The category. + + + + + Class representing an Audit Sub Category. + + + + + The category. + + + + + The user for the per-user category. + + + + + Class representing an Audit Sub Category. Base class. + + Enum type for the Policy flags. + + + + The ID of the sub category. + + + + + The name of the sub category. + + + + + The Current Audit Policy + + + + + Convert to string. + + The name of the subcategory. + + + + Query audit policy. + + True to throw on error. + The audit policy flags. + + + + Set audit policy. + + The flags to set. + True to throw on error. + The audit policy flags. + + + + Set audit policy. + + The flags to set. + The audit policy flags. + + + + Authentication token constructed from ASN1. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The ASN1 authentication token. + True if this is a token from a client. + The token count number. + True if parsed successfully. + + + + Base class for authentication credentials. + + + + + Security data representation. + + + + + Native representation. + + + + + Network representation. + + + + + Credital flags. + + + + + Inbound credentials. + + + + + Outbound credentials. + + + + + Both credentials direction. + + + + + Default. + + + + + Auto logon restricted. Don't use automatic credentials. + + + + + Only process policy. + + + + + Initialize context request flags. + + + + + Initialize context return flags. + + + + + Access context request flags. + + + + + Accept context return flags. + + + + + Security package capability flags. + + + + + Supports integrity on messages + + + + + Supports privacy (confidentiality) + + + + + Only security token needed + + + + + Datagram RPC support + + + + + Connection oriented RPC support + + + + + Full 3-leg required for re-auth. + + + + + Server side functionality not available + + + + + Supports extended error msgs + + + + + Supports impersonation + + + + + Accepts Win32 names + + + + + Supports stream semantics + + + + + Can be used by the negotiate package + + + + + GSS Compatibility Available + + + + + Supports common LsaLogonUser + + + + + Token Buffers are in ASCII + + + + + Package can fragment to fit + + + + + Package can perform mutual authentication + + + + + Package can delegate + + + + + Supports integrity readonly checksum buffers. + + + + + Package supports restricted callers + + + + + This package extends SPNEGO, there is at most one + + + + + This package is negotiated under the NegoExtender + + + + + This package receives all calls from appcontainer apps + + + + + this package receives calls from appcontainer apps + if the following checks succeed + 1. Caller has domain auth capability or + 2. Target is a proxy server or + 3. The caller has supplied creds + + + + + This package is running with Credential Guard enabled + + + + + this package supports reliable detection of loopback + 1.) The client and server see the same sequence of tokens + 2.) The server enforces a unique exchange for each + non-anonymous authentication. (Replay detection) + + + + + Impersonation context for a server authentication. + + + + + Base class which represents an authentication key. + + + + + An authentication package entry. + + + + + Authentication package name for MSV1.0 + + + + + Authentication package name for Kerberos. + + + + + Authentication package name for Negotiate. + + + + + Authentication package name for NTLM. + + + + + Authentication package name for Digest. + + + + + Authentication package name for SChannel. + + + + + Authentication package name for CredSSP. + + + + + Capabilities of the package. + + + + + Version of the package. + + + + + RPC DCE ID. + + + + + Max token size. + + + + + Name of the package. + + + + + Comment for the package. + + + + + Get authentication packages. + + The list of authentication packages. + + + + Get authentication package names. + + The list of authentication package names. + + + + Get an authentication package by name. + + The name of the package. + The authentication package. + + + + Base class to represent an authentication token. + + + + + Decrypt the Authentication Token using a keyset. + + The set of keys to decrypt the + The decrypted token, or the same token if nothing could be decrypted. + + + + Convert the authentication token to a byte array. + + The byte array. + + + + Get the length of the token in bytes. + + + + + Format the authentication token. + + The token as a formatted string. + + + + Constructor. + + The authentication token data. + + + + Parse a structured authentication token. + + The authentication context. + The token to parse. + The parsed authentication token. If can't parse any other format returns + a raw AuthenticationToken. + + + + Parse a structured authentication token. + + The package name to parse as. + True if the token is from a client. + The token to parse. + The parsed authentication token. If can't parse any other format returns + a raw AuthenticationToken. + + + + Class to represent a client authentication context. + + + + + The current authentication token. + + + + + Whether the authentication is done. + + + + + Current request attribute flags. + + + + + Current return attribute flags. + + + + + Current data representation. + + + + + Current target name. + + + + + Current channel binding. + + + + + Current status flags. + + + + + Expiry of the authentication. + + + + + Get the Session Key for this context. + + + + + Get the maximum signature size of this context. + + + + + Get the size of the security trailer for this context. + + + + + Size of any header when using a stream protocol such as Schannel. + + + + + Size of any trailer when using a stream protocol such as Schannel. + + + + + Number of buffers needed when using a stream protocol such as Schannel. + + + + + Maximum message size when using a stream protocol such as Schannel. + + + + + Preferred block size when using a stream protocol such as Schannel. + + + + + Get the local certificate. Only used for Schannel related authentication. + + + + + Get the remote certificate. Only used for Schannel related authentication. + + + + + Get the last token status for the client context. + + + + + Get the name of the authentication package. + + + + + Get connection information for the schannel connection. + + + + + Get whether the authentication context is for loopback. + + + + + Get or set whether the context owns the credentials object or not. If true + then the credentials are disposed with the context. + + + + + Constructor. + + Credential handle. + Request attribute flags. + Target SPN (optional). + Data representation. + Optional channel binding token. + Specify to default initialize the context. Must call Continue with an auth token to initialize. + + + + Constructor. + + Credential handle. + Request attribute flags. + Target SPN (optional). + Data representation. + Optional channel binding token. + + + + Constructor. + + Credential handle. + Request attribute flags. + Target SPN (optional). + Data representation. + + + + Constructor. + + Credential handle. + Request attribute flags. + Data representation. + + + + Constructor. + + Credential handle. + + + + Continue the authentication with the server token. + + The server token to continue authentication. + + + + Continue the authentication.. + + The server token to continue authentication. + Additional input buffers for the continue, does not need to include the token. + + + + Continue the authentication. + + The server token to continue authentication. + Additional input buffers for the continue, does not need to include the token. + Additional output buffers, does not need to include the token. + + + + Continue the authentication without any token. + + Input buffers for the continue. Does not contain a token. + Specify additional output buffers, does not need to include the token. + True to throw on error. + This sends the input buffers directly to the initialize call, it does not contain any token. + + + + Continue the authentication without any token. + + Input buffers for the continue. Does not contain a token. + Specify additional output buffers, does not need to include the token. + This sends the input buffers directly to the initialize call, it does not contain any token. + + + + Continue the authentication. Will not pass any buffers to the initialize call. + + + + + Make a signature for this context. + + The message buffers to sign. + The sequence number. + The signature blob. + + + + Make a signature for this context. + + The message to sign. + The sequence number. + The signature blob. + + + + Verify a signature for this context. + + The message to verify. + The signature blob for the message. + The sequence number. + True if the signature is valid, otherwise false. + + + + Verify a signature for this context. + + The messages to verify. + The signature blob for the message. + The sequence number. + True if the signature is valid, otherwise false. + + + + Encrypt a message for this context. + + The message to encrypt. + Quality of protection flags. + The encrypted message. + The sequence number. + + + + Encrypt a message for this context. + + The messages to encrypt. + Quality of protection flags. + The signature for the messages. + The messages are encrypted in place. You can add buffers with the ReadOnly flag to prevent them being encrypted. + The sequence number. + + + + Encrypt a message for this context with no specific signature. + + The messages to encrypt. + Quality of protection flags. + The sequence number. + The messages are encrypted in place. You can add buffers with the ReadOnly flag to prevent them being encrypted. + If you need to return a signature then it must be specified in a buffer. + + + + Decrypt a message for this context. + + The message to decrypt. + The sequence number. + The decrypted message. + + + + Decrypt a message for this context. + + The messages to decrypt. + The sequence number. + The signature for the messages. + The messages are decrypted in place. You can add buffers with the ReadOnly flag to prevent them being decrypted. + + + + Decrypt a message for this context. + + The messages to decrypt. + The sequence number. + The messages are decrypted in place. You can add buffers with the ReadOnly flag to prevent them being decrypted. + If you need to specify a signature you need to add a buffer. + + + + Query the context's package info. + + The authentication package info, + + + + Export and delete the current security context. + + The exported security context. + The security context will not longer be usable afterwards. + + + + Dispose the client context. + + + + + Finalizer. + + + + + Class to represent a credential handle. + + + + + Name of the authentication package used. + + + + + Expiry of the credentials. + + + + + Constructor. + + User principal. + The package name. + Optional authentication ID for the user. + Credential user flags. + Optional authentication data. + + + + Create a new credential handle. + + User principal. + The package name. + Optional authentication ID for the user. + Credential user flags. + Optional credentials. + The credential handle. + + + + Create a new credential handle. + + The package name. + Optional authentication ID for the user. + Credential user flags. + Optional credentials. + The credential handle. + + + + Create a new credential handle. + + The package name. + Credential user flags. + Optional credentials. + The credential handle. + + + + Create a new credential handle. + + The package name. + Credential user flags. + The credential handle. + + + + Dispose. + + + + + Finalizer. + + + + + Credentials for the CredSSP package. + + This is only needed if you must have both schannel and user credentials. Otherwise use UserCredentials or SchannelCredentials. + + + + Constructor. + + The credentials for the Schannel connection. + The credentials for the user. + + + + Constructor. + + The credentials for the user. + + + + Authentication token for a digest token. + + + + + The digest token as a string. + + + + + Format the authentication token. + + + + + + An encrypted message. + + + + + The encrypted message. + + + + + The signature for the message. + + + + + Constructor. + + The encrypted message. + The signature for the message. + + + + Class to represent an exported security context. + + + + + The name of the package for this security context. + + + + + The serialized context. + + + + + The context's token. + + + + + Dispose the exported context. + + + + + A class which represents an GSS-API Token. + + + + + Interface for authentication contexts. + + + + + The current authentication token. + + + + + Whether the authentication is done. + + + + + Expiry of the authentication. + + + + + Session key for the context. + + + + + Make a signature for this context. + + The message to sign. + The sequence number. + The signature blob. + + + + Verify a signature for this context. + + The message to verify. + The signature blob for the message. + The sequence number. + True if the signature is valid, otherwise false. + + + + Make a signature for this context. + + The message buffers to sign. + The sequence number. + The signature blob. + + + + Verify a signature for this context. + + The messages to verify. + The signature blob for the message. + The sequence number. + True if the signature is valid, otherwise false. + + + + Encrypt a message for this context. + + The message to encrypt. + Quality of protection flags. + The encrypted message. + The sequence number. + + + + Encrypt a message for this context. + + The messages to encrypt. + Quality of protection flags. + The signature for the messages. + The messages are encrypted in place. You can add buffers with the ReadOnly flag to prevent them being encrypted. + The sequence number. + + + + Encrypt a message for this context with no specific signature. + + The messages to encrypt. + Quality of protection flags. + The sequence number. + The messages are encrypted in place. You can add buffers with the ReadOnly flag to prevent them being encrypted. + If you need to return a signature then it must be specified in a buffer. + + + + Decrypt a message for this context. + + The message to decrypt. + The sequence number. + The decrypted message. + + + + Decrypt a message for this context. + + The messages to decrypt. + The signature for the messages. + The sequence number. + The messages are decrypted in place. You can add buffers with the ReadOnly flag to prevent them being decrypted. + + + + Decrypt a message for this context. + + The messages to decrypt. + The sequence number. + The messages are decrypted in place. You can add buffers with the ReadOnly flag to prevent them being decrypted. + If you need to specify a signature you need to add a buffer. + + + + Export and delete the current security context. + + The exported security context. + The security context will not longer be usable afterwards. + + + + Query the context's package info. + + The authentication package info, + + + + Get the name of the authentication package. + + + + + Continue the authentication with the token. + + The token to continue authentication. + + + + Continue the authentication.. + + The token to continue authentication. + Additional input buffers for the continue, does not need to include the token. + + + + Continue the authentication. + + The token to continue authentication. + Additional input buffers for the continue, does not need to include the token. + Specify additional output buffers, does not need to include the token. + + + + Continue the authentication. + + Additional input buffers for the continue. Does not contain a token. + Specify additional output buffers, does not need to include the token. + This sends the input buffers directly to the initialize call, it does not contain any token. + + + + Continue the authentication. Will not pass any buffers to the accept call. + + + + + Get the maximum signature size of this context. + + + + + Get the size of the security trailer for this context. + + + + + Interface for a client authentication context. + + + + + Get the last token status for the client context. + + + + + Placeholder interface for a server authentication context. + + + + + Utilities for building Kerberos structures. + + + + + Class to represent a Kerberos AP Reply. + + + + + Encrypted mutual authentication data. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Decrypt the Authentication Token using a keyset. + + The set of keys to decrypt the + The decrypted token, or the same token if nothing could be decrypted. + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The Negotiate authentication token. + Parsed DER Values. + + + + Encrypted part for AP-REP messages. + + + + + Client uS. + + + + + Client time. + + + + + Subkey. + + + + + Sequence number. + + + + + Options for AP Request + + + + + None. + + + + + Use Session Key. + + + + + Mutual authentication required. + + + + + Class to represent a Kerberos AP Request. + + + + + AP Request Options. + + + + + The Kerberos Ticket. + + + + + Authenticator data. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Decrypt the Authentication Token using a keyset. + + The set of keys to decrypt the + The decrypted token, or the same token if nothing could be decrypted. + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The Negotiate authentication token. + Parsed DER Values. + + + + A single kerberos key. + + + + + The Key encryption type. + + + + + The key. + + + + + The key name type. + + + + + The Realm for the key. + + + + + The name components for the key. + + + + + Principal name as a string. + + + + + Timestamp when key was created. + + + + + Key Version Number (KVNO). + + + + + Constructor. + + The Key encryption type. + The key. + The key name type. + The Realm for the key. + The name components for the key. + Timestamp when key was created. + Key Version Number (KVNO). + + + + Constructor. + + The Key encryption type. + The key. + The key name type. + The Realm for the key. + The name components for the key. + Timestamp when key was created. + Key Version Number (KVNO). + + + + Constructor. + + The Key encryption type. + The key. + The key name type. + Principal for key, in form TYPE/name@realm. + Timestamp when key was created. + Key Version Number (KVNO). + + + + Constructor. + + The Key encryption type. + The key as a hex string. + The key name type. + Principal for key, in form TYPE/name@realm. + Timestamp when key was created. + Key Version Number (KVNO). + + + + Derive a key from a password. + + Not all encryption types are supported. + The key encryption to use. + The password to derice from. + Iterations for the password derivation. + The key name type. + Principal for key, in form TYPE/name@realm. + Salt for the key. + Key Version Number (KVNO). + + + + + Authentication Token for Kerberos. + + + + + Protocol version. + + + + + Message type. + + + + + Parse bytes into a kerberos token. + + The kerberos token in bytes. + The Kerberos token. + + + + Try and parse data into an Kerberos authentication token. + + The data to parse. + The Kerberos authentication token. + True if this is a token from a client. + The token count number. + True if parsed successfully. + + + + Class to represent an unencrypted kerberos authenticator. + + + + + Authenticator version. + + + + + Client realm. + + + + + Client name. + + + + + Checksum value. + + + + + Client uS. + + + + + Client time. + + + + + Subkey. + + + + + Sequence number. + + + + + Authorization data. + + + + + Type of Authorization Data. + + + + + Class representing Kerberos authentication data. + + + + + Type of authentication data. + + + + + Data bytes. + + + + + Flags for the AD-AUTH-DATA-AP-OPTIONS authorization data. + + + + + Class to represent the AD-AUTH-DATA-AP-OPTIONS authorization data. + + + + + Flags for the AD-AUTH-DATA-AP-OPTIONS authorization data. + + + + + Class to represent AD_ETYPE_NEGOTIATION type. + + + + + List of supported encryption types. + + + + + Class to represent a KERB_LOCAL authorization data value. + + + + + The security context identifier for the KERB_LOCAL value. + + + + + Class to represent AD_WIN2K_PAC type. + + + + + List of PAC entries. + + + + + Source of a set of claims. + + + + + From Active Directory. + + + + + From a certificate. + + + + + A single claim set. + + + + + The source of the claims array. + + + + + The list of claim attributes. + + + + + Class representing a Claims Set in the PAC. + + + + + List of claims arrays. + + + + + Class to represent PAC Client Info. + + + + + Client ID. + + + + + Name of client. + + + + + Class to represent PAC Device Info. + + + + + Sid of the Device. + + + + + Primary group SID. + + + + + List of account groups. + + + + + List of extra SIDs. + + + + + List of domain groups. + + + + + Type for the PAC Entry. + + + + + Single PAC Entry. + + + + + Type of PAC entry. + + + + + The PAC data. + + + + + User account control flags. + + + + + User flags for kerberos authentication. + + + + + Class to represent PAC Logon Information. + + + + + Logon time. + + + + + Logoff time. + + + + + Kick off time. + + + + + Time password last set. + + + + + Time password can change. + + + + + Time password must change. + + + + + Effective name. + + + + + Full name. + + + + + Logon script path. + + + + + Profile path. + + + + + Home directory path. + + + + + Home directory drive. + + + + + Logon count. + + + + + Bad password count. + + + + + User SID. + + + + + Primary group SID. + + + + + Group list. + + + + + User flags. + + + + + User session key. + + + + + Logon server name. + + + + + Logon domain name. + + + + + Logon domain sid. + + + + + Extra SIDs. + + + + + User account control flags. + + + + + Resource domain group SID. + + + + + Resource groups. + + + + + Class to represent a PAC signature. + + + + + Signature type. + + + + + Signature. + + + + + Read-only Domain Controller Identifier. + + + + + Flags for the UPN_DNS_INFO. + + + + + No flags. + + + + + The user has no UPN. + + + + + Class to represent UPN_DNS_INFO. + + + + + Flags. + + + + + The User Principal Name. + + + + + The DNS Domain Name. + + + + + Flags for KerberosAuthorizationDataRestrictionEntry + + + + + Full UAC token. + + + + + Limited UAC token. + + + + + Class to represent the KERB_AD_RESTRICTION_ENTRY AD type. + + + + + Flags. + + + + + Token IL. + + + + + Machine ID. + + + + + Class to represent the AD-AUTH-DATA-TARGET-NAME authorization data. + + + + + The target name. + + + + + Class to represent a Kerberos Checksum. + + + + + Type of kerberos checksum. + + + + + The checksum value. + + + + + Flags for GSSAPI Checksum. + + + + + A kerberos checksum in GSS API Format. + + + + + Channel binding hash. + + + + + Flags for checksum. + + + + + Delegation option identifier. + + + + + KRB_CRED structure when in delegation. + + + + + Additional extension data. + + + + + Kerberos Checksum Type. + + + + + Class representing a KRB-CRED structure. + + + + + List of tickets in this credential. + + + + + Encrypted part contains sesssion keys etc. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Decrypt the Authentication Token using a keyset. + + The set of keys to decrypt the + The decrypted token, or the same token if nothing could be decrypted. + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The Negotiate authentication token. + Parsed DER Values. + + + + Class to represent Kerberos Encrypted Data. + + + + + Encryption type for the CipherText. + + + + + Key version number. + + + + + Cipher Text. + + + + + Kerberos Encryption Type. + + + + + Class to represent a Kerberos Error. + + + + + Client time. + + + + + Client micro-seconds. + + + + + Server time. + + + + + Server micro-seconds. + + + + + Error code. + + + + + Client realm. + + + + + Client name. + + + + + Server realm. + + + + + Server name, + + + + + Error text. + + + + + Error data. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Create a new KRB-ERROR authentication token. + + Optional client time. + Server time. + Error code. + Optional client realm. + Optional client name. + Server realm + Server name. + Optional error text. + Optional error data. + The KRB-ERROR authentication token. + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The Negotiate authentication token. + Parsed DER Values. + + + + Kerberos Error Type. + + + + + Class to represent a cached external ticket. + + + + + Service name. + + + + + Target name. + + + + + Client name. + + + + + Domain name. + + + + + Target domain name. + + + + + Alt target domain name. + + + + + Session key for ticket. + + + + + Ticket flags. + + + + + Additional reserved flags. + + + + + Key expiration time. + + + + + Ticket start time. + + + + + Ticket end time. + + + + + Ticket renew time. + + + + + Time skew. + + + + + Ticket. + + + + + Type of Kerberos Host Address. + + + + + Class representing a Kerberos Host Address. + + + + + Type of host address. + + + + + Address bytes. + + + + + ToString Method. + + The formatted string. + + + + A set of Kerberos Keys. + + + + + Get keys which match the encryption type. + + The encryption type. + The list of keys which match the encryption type. + + + + Add a key to the key set. + + The key to add. + True if the key was added, false if the key already existed. + + + + Remove a key from the key set. + + The key to remove. + True if the key was removed. + + + + Find a key based on various parameters. + + The encryption type. + The name type. + The principal. + The key version. + + + + + Read keys from a MIT KeyTab file. + + The file stream. + The key set. + Throw if invalid file. + + + + Read keys from a MIT KeyTab file. + + The file path. + The key set. + Throw if invalid file. + + + + Constructor. + + + + + Constructor. + + The single kerberos key. + + + + Constructor. + + A list of kerberos keys. + + + + Key usage for kernel encryption. + + + + + Kerberos Message Type. + + + + + Kerberos Name Type. + + + + + Kerberos Pre-Authentication Data Types. + + + + + A Kerberos Principal Name. + + + + + The name type. + + + + + The names for the principal. + + + + + Full name. + + + + + ToString method. + + String of the object. + + + + Get principal name with a realm. + + The realm for the principal. + The principal. + + + + Constructor. + + The type of the principal name. + The list of names for the principal. + + + + Class to represent a User to User TGT Reply. + + + + + The Kerberos Ticket. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Decrypt the Authentication Token using a keyset. + + The set of keys to decrypt the + The decrypted token, or the same token if nothing could be decrypted. + + + + Create a new TGT-REP authentication token. + + The TGT ticket to embed in the token. + The + + + + Create a new TGT-REP authentication token. + + The TGT ticket to embed in the token. + The + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The Negotiate authentication token. + Parsed DER Values. + + + + Class to represent a User to User TGT Request. + + + + + Realm. + + + + + Server name. + + + + + Format the Authentication Token. + + The Formatted Token. + + + + Create a new TGT-REQ authentication token. + + Optional realm string. + Optional server name. + The new TGT-REQ authentication token. + + + + Create a new TGT-REQ authentication token without the GSS-API wrapper. + + Optional realm string. + Optional server name. + The new TGT-REQ authentication token. + + + + Try and parse data into an ASN1 authentication token. + + The data to parse. + The Negotiate authentication token. + Parsed DER Values. + + + + Class to represent a Kerberos ticket. + + + + + Version number for the ticket. + + + + + Realm. + + + + + Server name. + + + + + Encrypted data for the ticket. + + + + + Get the principal for the ticket. + + + + + Indicates that the ticket has been decrypted. + + + + + Decrypt the kerberos ticket. + + The Kerberos key set containing the keys. + The key usage for the decryption. + The decrypted kerberos ticket. + + + + Format the ticket to a string. + + The ticket as a string. + + + + Convert the ticket to an array. + + The ticket as an array. + + + + Class to query the Kerberos Ticket Cache from LSASS. + + + + + Get a Kerberos Ticket. + + The target service for the Ticket. + True to only query for cached tickets. + True to throw on error. + The Kerberos Ticket. + + + + Get a Kerberos Ticket. + + The target service for the Ticket. + True to only query for cached tickets. + The Kerberos Ticket. + + + + Get a Kerberos Ticket. + + The target service for the Ticket. + The Kerberos Ticket. + + + + Query Kerberos Ticket cache. + + The Logon Session ID to query. + True to throw on error. + The list of cached tickets. + + + + Query Kerberos Ticket cache. + + The Logon Session ID to query. + The list of cached tickets. + + + + Query Kerberos Ticket cache for the current logon session. + + The list of cached tickets. + + + + Flags for a Kerberos Ticket. + + + + + Class to represent a Decrypted Kerberos ticket. + + + + + Ticket flags. + + + + + Client Realm. + + + + + Client name. + + + + + Authentication time, + + + + + Start time. + + + + + End time. + + + + + Renew till time. + + + + + The kerberos session key. + + + + + The ticket transited type information. + + + + + List of host addresses for ticket. + + + + + List of authorization data. + + + + + The supported transited encoding types. + + + + + None. + + + + + X.500 Compress. + + + + + Class to represent a Kerberos Transiting Encoding. + + + + + Transited encoding type. + + + + + Transited encoding data. + + + + + Utilities for Kerberos authentication. + + + + + Read keys from a MIT KeyTab file. + + The file stream. + The list of keys. + Throw if invalid file. + + + + Read keys from a MIT KeyTab file. + + The file path. + The list of keys. + Throw if invalid file. + + + + Write keys to a MIT KeyTab file. + + The file stream. + List of key entries. + + + + Write keys to a MIT KeyTab file. + + The file path. + List of key entries. + + + + Generate an MIT KeyTab file. + + List of key entries. + The keytab file as bytes. + + + + Class to represent a Local Logon Session. + + + + + Logon/Authentication ID for session. + + + + + Username. + + + + + Logon domain. + + + + + Get the FQ User Name. + + + + + Authentication package. + + + + + Logon type. + + + + + Session ID. + + + + + User SID. + + + + + Logon Time. + + + + + Logon Server. + + + + + DNS Domain Name. + + + + + User Principal Name. + + + + + User Flags. + + + + + Last successful logon. + + + + + Last failed logon. + + + + + Count of failed logon attempts. + + + + + Logon script path. + + + + + Profile path. + + + + + Home directory. + + + + + Home directory drive. + + + + + Logoff time. + + + + + Kickoff Time. + + + + + Time password last set. + + + + + Password can change. + + + + + Password must change. + + + + + Get a logon session. + + The logon session ID. + True to thrown on error. + The logon session. + + + + Get the logon session LUIDs + + True throw on error. + The list of logon sessions. Only returns ones you can access. + + + + Get the logon sessions. + + True throw on error. + The list of logon sessions. Only returns ones you can access. + + + + Class to represent an LSA logon handle. + + + + + Connect to the LSA untrusted. + + True to throw on error. + The LSA logon handle. + + + + Connect to the LSA untrusted. + + The LSA logon handle. + + + + Connect to LSA and register as a logon process. + + The arbitrary name of the process. + True to throw on error. + The LSA logon handle. + + + + Connect to LSA and register as a logon process. + + The arbitrary name of the process. + The LSA logon handle. + + + + Logon a user. + + The type of logon. + The authentication package to use. + The name of the origin. + The token source context. + The authentication credentials buffer. + Additional local groups. + True to throw on error. + The LSA logon result. + + + + Logon a user. + + The type of logon. + The authentication package to use. + The name of the origin. + The token source context. + The authentication credentials buffer. + Additional local groups. + The LSA logon result. + + + + Dispose of the LSA logon handle. + + + + + Result from an LsaLogonUser call. + + + + + The user's token. + + + + + The user's profile information. Format depends on the authentication package. + + + + + The authentication ID of the logon session. + + + + + Paged pool quota. + + + + + Non paged pool quota. + + + + + Minimum working set size. + + + + + Maximum working set size. + + + + + Page file limit. + + + + + Process time limit. + + + + + Dispose the LSA logon result. + + + + + SPNEGO Authentication Token. + + + + + The negotiated authentication token. + + + + + Optional message integrity code. + + + + + Decrypt the Authentication Token using a keyset. + + The set of keys to decrypt the + The decrypted token, or the same token if nothing could be decrypted. + + + + Format the authentication token. + + The token as a formatted string. + + + + Parse bytes into a negotiate token. + + The negotiate token in bytes. + The Negotiate token. + + + + Try and parse data into an Negotiate authentication token. + + The data to parse. + The Negotiate authentication token. + True if this is a token from a client. + The token count number. + True if parsed successfully. + + + + Flags for negotiation context. + + + + + Class to represent the negTokenInit message in SPNEGO. + + + + + List of supported negotiation mechanisms. + + + + + Context flags. + + + + + State of the Negotiate state. + + + + + Negotiate completed. + + + + + Negotiate incomplete. + + + + + Negotiate rejected. + + + + + Request Message Integrity Code. + + + + + Class to represent the negTokenResp message in SPNEGO. + + + + + Supported mechanism for the token, optional. + + + + + Current state of the negotiation. + + + + + Class to represent an NTLM AUTHENTICATE token for NTLMv1. + + + + + Domain name. + + + + + Workstation name. + + + + + Username. + + + + + NTLM version. + + + + + Encrypted session key. + + + + + LM Challenge Response. + + + + + LM Challenge Response. + + + + + Message integrity code. + + + + + Message integrity code offset into the token data. + + + + + Format the authentication token. + + The formatted token. + + + + Class to represent an NTLM AUTHENTICATE token for NTLMv2. + + + + + NT Proof Response. + + + + + Challenge version. + + + + + Maximum challenge version. + + + + + Reserved field. + + + + + Reserved field. + + + + + Timestamp. + + + + + Client challenge. + + + + + Reserved field. + + + + + NTLM Target Information. + + + + + Flags for NTLM negotiation. + + + + + NTLM message type. + + + + + Base class to represent an NTLM authentication token. + + + + + Type of NTLM message. + + + + + NTLM negotitation flags. + + + + + Try and parse data into an NTLM authentication token. + + The data to parse. + The NTLM authentication token. + True if this is a token from a client. + The token count number. + True if parsed successfully. + + + + Try and parse data into an NTLM authentication token. + + The data to parse. + The NTLM authentication token. + + + + The type of the AV_PAIR. + + + + + MS AV Flags. + + + + + An NTLM AV_PAIR. + + + + + The type of the AV Pair value. + + + + + An NTLM AV_PAIR with a string value. + + + + + The string value. + + + + + ToString method. + + Pair as a string. + + + + An NTLM AV_PAIR with a timestamp value; + + + + + The timestamp value. + + + + + ToString method. + + Pair as a string. + + + + An NTLM AV_PAIR with a bytes value. + + + + + The value. + + + + + ToString method. + + Pair as a string. + + + + An NTLM AV_PAIR with a flags value. + + + + + The value. + + + + + ToString method. + + Pair as a string. + + + + An NTLM AV_PAIR with a flags value. + + + + + The the Z4 data. + + + + + Custom data blob. + + + + + Machine ID. + + + + + ToString method. + + Pair as a string. + + + + Class to represent an NTLM CHALLENGE token. + + + + + Target name. + + + + + Server challenge. + + + + + Reserved. + + + + + NTLM version. + + + + + NTLM Target Information. + + + + + Format the authentication token. + + The formatted token. + + + + Class to represent an NTLM NEGOTIATE token. + + + + + Domain name. + + + + + Workstation name. + + + + + NTLM version. + + + + + Format the authentication token. + + The formatted token. + + + + Algorithm identifiers for the crypto APIs and Schannel. + + + + + Authentication token for Schannel and CredSSP. + + This is a simple parser for the TLS record format. + + + + List of TLS records. + + + + + Format the authentication token. + + The token as a formatted string. + + + + Try and parse data into an SChannel authentication token. + + The data to parse. + The SChannel authentication token. + True if this is a token from a client. + The token count number. + True if parsed successfully. + + + + Negotiated connection information for Schannel. + + + + + The protocol used by Schannel. + + + + + The negotitated cipher algorithm. + + + + + The negotiated cipher strength in bits. + + + + + The negotiated hash algorithm. + + + + + The negotiated hash string. + + + + + The negotiated key exchange algorithm. + + + + + The negotiated key exchange strength. + + + + + Credentials for the Schannel package. + + + + + Lifespan of a session in milliseconds. + + + + + Specify flags for credentials. + + + + + Specify the supported protocols. + + + + + Set the minimum cipher strength. + + + + + Set the maximum cipher strength. + + + + + Add a certificate the the credentials. This should contain a private key. + + The certificate to add. + + + + Add an algorithm type to the credentials. + + The algorithm type. + + + + Dispose the credentials. + + + + + Flags for the Schannel credentials. + + + + + Protocol type for Schannel. + + + + + Flags for message encryption. + + + + + None. + + + + + Wrap out of bound data. + + + + + Wrap but don't encrypt. + + + + + Class to represent a server authentication context. + + + + + The current authentication token. + + + + + Whether the authentication is done. + + + + + Current request attributes. + + + + + Current data representation. + + + + + Current channel bindings. + + + + + Current return attributes. + + + + + Current status flags. + + + + + Expiry of the authentication. + + + + + Get the client name supplied by the Client. + + + + + Get the Session Key for this context. + + + + + Get the maximum signature size of this context. + + + + + Get the size of the security trailer for this context. + + + + + Size of any header when using a stream protocol such as Schannel. + + + + + Size of any trailer when using a stream protocol such as Schannel. + + + + + Number of buffers needed when using a stream protocol such as Schannel. + + + + + Maximum message size when using a stream protocol such as Schannel. + + + + + Preferred block size when using a stream protocol such as Schannel. + + + + + Get the name of the authentication package. + + + + + Get connection information for the schannel connection. + + + + + Get the local certificate. Only used for Schannel related authentication. + + + + + Get the remote certificate. Only used for Schannel related authentication. + + + + + Get whether the authentication context is for loopback. + + + + + Get or set whether the context owns the credentials object or not. If true + then the credentials are disposed with the context. + + + + + Get an access token for the authenticated user. + + The user's access token. + + + + Impersonate the security context. + + The disposable context to revert the impersonation. + + + + Continue the authentication with the client token. + + The client token to continue authentication. + + + + Continue the authentication.. + + The client token to continue authentication. + Specify additional input buffers, does not need to include the token. + + + + Continue the authentication. + + The client token to continue authentication. + Specify additional input buffers, does not need to include the token. + Specify additional output buffers, does not need to include the token. + + + + Continue the authentication. + + Additional input buffers for the continue. Does not contain a token. + Specify additional output buffers, does not need to include the token. + True to throw on error. + This sends the input buffers directly to the initialize call, it does not contain any token. + + + + Continue the authentication. + + Additional input buffers for the continue. Does not contain a token. + Specify additional output buffers, does not need to include the token. + This sends the input buffers directly to the initialize call, it does not contain any token. + + + + Continue the authentication. Will not pass any buffers to the accept call. + + + + + Make a signature for this context. + + The message buffers to sign. + The sequence number. + The signature blob. + + + + Make a signature for this context. + + The message to sign. + The sequence number. + The signature blob. + + + + Verify a signature for this context. + + The message to verify. + The signature blob for the message. + The sequence number. + True if the signature is valid, otherwise false. + + + + Verify a signature for this context. + + The messages to verify. + The signature blob for the message. + The sequence number. + True if the signature is valid, otherwise false. + + + + Encrypt a message for this context. + + The message to encrypt. + Quality of protection flags. + The encrypted message. + The sequence number. + + + + Encrypt a message for this context. + + The messages to encrypt. + Quality of protection flags. + The signature for the messages. + The messages are encrypted in place. You can add buffers with the ReadOnly flag to prevent them being encrypted. + The sequence number. + + + + Encrypt a message for this context with no specific signature. + + The messages to encrypt. + Quality of protection flags. + The sequence number. + The messages are encrypted in place. You can add buffers with the ReadOnly flag to prevent them being encrypted. + If you need to return a signature then it must be specified in a buffer. + + + + Decrypt a message for this context. + + The messages to decrypt. + The sequence number. + The signature for the messages. + The messages are decrypted in place. You can add buffers with the ReadOnly flag to prevent them being decrypted. + + + + Decrypt a message for this context. + + The messages to decrypt. + The sequence number. + The messages are decrypted in place. You can add buffers with the ReadOnly flag to prevent them being decrypted. + If you need to specify a signature you need to add a buffer. + + + + Decrypt a message for this context. + + The message to decrypt. + The sequence number. + The decrypted message. + + + + Query the context's package info. + + The authentication package info, + + + + Export and delete the current security context. + + The exported security context. + The security context will not longer be usable afterwards. + + + + Constructor. + + Credential handle. + Request attribute flags. + Optional channel binding token. + Data representation. + + + + Constructor. + + Credential handle. + Request attribute flags. + Data representation. + + + + Constructor. + + Credential handle. + + + + Dispose the client context. + + + + + Finalizer. + + + + + Class to represent a service principal name. + + + + + SPN service class. + + + + + SPN service name. + + + + + SPN instance name. + + + + + SPN instance port. + + + + + SPN referrer. + + + + + Constructor. + + The service class name. + The name of the instance. + + + + Parse an SPN string to a class. + + The SPN string. + The parsed class. + Thrown in invalid SPN. + + + + Try and parse an SPN string to a class. + + The SPN string. + The result class. + True if the SPN was parsed successfully. + Thrown in invalid SPN. + + + + Convert SPN to a string. + + The SPN string. + + + + Class to hold user credentials. + + + + + The user name. + + + + + The domain. + + + + + The password as a secure string. + + + + + Constructor. + + Username. + Domain name. + Password. + + + + Set the password as in plain text. + + The password in plain text. + + + + Constructor. + + Username. + Domain name. + Password. + + + + Constructor. + + Username. + Domain name. + + + + Constructor. + + Username. + + + + Constructor. + + + + + Dispose method. + + + + + Class to represent a single authenticode certificate entry. + + + + + The list of certificates in the entry. + + + + + Whethe the entry contains page hashes. + + + + + Utilities for authenticode. + + + + + Get certificates from a PE file. + + The PE file. + True the throw on error. + The list of authenticode certificate entries. + + + + Get certificates from a PE file. + + The path to the PE file. + True the throw on error. + The list of authenticode certificate entries. + + + + Get certificates from a PE file. + + The path to the PE file, native path format. + The list of authenticode certificate entries. + + + + Gets wether the PE file has page hash entries. + + The path to the PE file, native path format. + True if the file contains page hashes. + + + + Query ELAM information from a driver's resource section. + + The path to the file. + True to throw on error. + The ELAM information if present. + + + + Query ELAM information from a driver's resource section. + + The path to the file. + The ELAM information if present. + + + + Get the VSM enclave configuration. + + The path to the file. + True to throw on error. + The VSM enclave configuration. + + + + Get the VSM enclave configuration. + + The path to the file. + The VSM enclave configuration. + + + + ELAM information. + + + + + The hash of the certificate. + + + + + The hash algorithm. + + + + + List of optional EKUs. + + + + + Overridden ToString method. + + The ELAM information as a string. + + + + Class to represent a VSM enclave configuration. + + + + + Minimum required configuration size. + + + + + Policy flags. + + + + + List of enclave imports. + + + + + Family ID. + + + + + Image ID. + + + + + Image version. + + + + + Security version. + + + + + Size of the enclave. + + + + + Number of threads for the enclave. + + + + + Enclave flags. + + + + + Is the enclave debuggable. + + + + + Is this a primary image. + + + + + Path to the image file. + + + + + Name of the image file. + + + + + ToString method. + + The object as a string. + + + + Class to represent an enclave import. + + + + + Match type for the import. + + + + + Minimum security version. + + + + + Unique or author ID. + + + + + Family ID. + + + + + Image ID. + + + + + Import name. + + + + + ToString method. + + The name of the import. + + + + Image policy entry. + + + + + Type of entry. + + + + + Policy ID. + + + + + Value of entry. + + + + + Image policy ID. + + + + + Class to represnt image policy metadata. + + + + + Version of the metadata. + + + + + The ID of the trustlet. + + + + + The optional policies for the trustlet. + + + + + Overridden ToString method. + + The object as a string. + + + + Extract image policy metadata from an image file. + + The path to the image file. Should be a win32 path. + True to throw on error. + The image policy metadata. + + + + Extract image policy metadata from an image file. + + The path to the image file. Should be a win32 path. + The image policy metadata. + + + + Access check result from AuthZ. + + + + + The Win32 error code from the access check. + + + + + Class to represent an AuthZ client context. + + + + + Get AuthZ user + + + + + Get AuthZ context groups. + + + + + Get AuthZ context restricted SIDs. + + + + + Get AuthZ context device groups. + + + + + Get AuthZ context capability SIDs. + + + + + Get AuthZ context's security attributes + + + + + Get AuthZ context's device claims. + + + + + Get AuthZ context's user claims. + + + + + Get list of privileges for the AuthZ context. + + The list of privileges + Thrown if can't query privileges + + + + Get AppContainer SID. + + + + + Indicates if this context is connected to a remote access server. + + + + + Set AppContainer Information to Context. + + The package SID. + List of capabilities. + True to throw on error + The NT status code. + + + + Set AppContainer Information to Context. + + The package SID. + List of capabilities. + + + + Modify groups in the context. + + The type of group to modify. + The list of groups to modify. + The list of operations. Should be same size of group list. + True to throw on error. + The NT status code. + + + + Modify groups in the context. + + The type of group to modify. + The list of groups to modify. + The list of operations. Should be same size of group list. + + + + Modify groups in the context. + + The type of group to modify. + The list of SIDs to modify. + The attributes for the SIDs. + The operation for the SIDs. + + + + Modify groups in the context. + + The type of group to modify. + The list of SIDs to modify. + The operation for the SIDs. + + + + Add a SID to the context. + + The SID to add. + + + + Add a Device SID to the context. + + The SID to add. + + + + Add a Device SID to the context. + + The SID to add. + + + + Add a list of SIDs to the context. + + The list of SIDS. + + + + Get list of groups for the AuthZ context. + + The group type. + True to throw on error. + The list of groups. + + + + Get list of groups for the AuthZ context. + + The group type. + The list of groups. + + + + Get the user from the AuthZ context. + + True to throw on error. + The user group information. + + + + Get the AppContainer SID from the AuthZ context. + + True to throw on error. + The AppContainer SID. + + + + Get AuthZ context's security attributes + + Specify the type of security attributes to query. + Throw on error. + The security attributes. + + + + Get token privileges. + + True to throw on error. + The list of privileges. + + + + Perform an Access Check. + + The security descriptor for the check. + Optional list of security descriptors to merge. + The desired access. + Optional Principal SID. + Optional list of object types. + NT Type for access checking. + True to throw on error. + The list of access check results. + The list of object types is restricted to 256 entries for remote access checks. + + + + Perform an Access Check. + + The security descriptor for the check. + Optional list of security descriptors to merge. + The desired access. + Optional Principal SID. + Optional list of object types. + NT Type for access checking. + The list of access check results. + The list of object types is restricted to 256 entries for remote access checks. + + + + Dispose client context. + + + + + Clone the current context. + + True to throw on error. + The new client context. + + + + Clone the current context. + + The new client context. + + + + Flags to initialize a client context from a SID. + + + + + None. + + + + + Skip gathering token groups. + + + + + Require S4U logon. + + + + + Computer token privileges. + + + + + Specify the type of SIDs. + + + + + Normal Group SIDs. + + + + + Restricted SIDs. + + + + + Device Group SIDs. + + + + + Capability SIDs. + + + + + Delegate to handle a callback ACE. + + The ACE to handle. + True if the ACE should be processed. + + + + Class to represent a AuthZ Resource Manager. + + + + + The name of the resource manager if any. + + + + + Indicates if this resource manager is connected to a remote access server. + + + + + Dispose the resource manager. + + + + + Create a client context from a Token. + + The token to create the context from. + True to throw on error. + The created client context. + + + + Create a client context from a Token. + + The token to create the context from. + The created client context. + + + + Create a client context from a Token. + + The sid to create the context from. + Flags for intialization. + True to throw on error. + The created client context. + + + + Create a client context from a Token. + + The sid to create the context from. + Flags for intialization. + The created client context. + + + + Create a new AuthZ resource manager. + + The name of the resource manager, optional. + Optional flags for the resource manager. + Optional callback to handle callback ACEs. + True to throw on error. + The created AuthZ resource manager. + + + + Create a new AuthZ resource manager. + + The name of the resource manager, optional. + Optional flags for the resource manager. + Optional callback to handle callback ACEs. + The created AuthZ resource manager. + + + + Create a new AuthZ resource manager. Will not enable auditing. + + The created AuthZ resource manager. + + + + Create a remote AuthZ resource manager from a raw binding string. + + The RPC string binding for the server. + The SPN for the server. + True to throw on error. + The created AuthZ resource manager. + + + + Create a remote AuthZ resource manager from a raw binding string. + + The RPC string binding for the server. + The SPN for the server. + The created AuthZ resource manager. + + + + Create a remote AuthZ resource manager from a raw binding string. + + The address of the server. + The SPN for the server. + Specify the type of + True to throw on error. + The created AuthZ resource manager. + + + + Create a remote AuthZ resource manager from a raw binding string. + + The network address of the server. + The SPN for the server. + Specify the type of + The created AuthZ resource manager. + + + + Initialization flags for resource manager. + + + + + None + + + + + Disable auditing. + + + + + Initialize using impersonation token. + + + + + Disable central access policies. + + + + + Type of remote service to access. + + + + + Default, no evaluation of CAPs. + + + + + Evaluates CAPs. + + + + + Security Attribute type. + + + + + Token Security Attributes. + + + + + Device Claims. + + + + + User Claims. + + + + + SID operation for an AuthZ client context. + + + + + None. + + + + + Replace all SIDs. + + + + + Add SIDs. + + + + + Delete SIDs. + + + + + Replace SIDs. + + + + + Progress invoke setting for tree security. + + + + + The source of inheritance for a resource. + + + + + The depth between the resource and the parent. + + + + + The name of the ancestor. + + + + + The security descriptor if accessible. + + + + + The original ACE which was inherited. + + + + + The SID of the original ACE. + + + + + Access mask as a formatted string. + + + + + Generic access mask as a formatted string. + + + + + The type of the ACE. + + + + + The object type of the ACE. + + + + + The inherited object type. + + + + + Enumeration for object type. + + + + + Tree security mode. + + + + + Progress function for tree named security info. + + The name of the object. + The operation status. + The current invoke setting. + True if security is set. + The invoke setting. Return original invoke_setting if no change. + + + + Base security buffer storage. + + + + + Type of the security buffer. + + + + + Is the buffer read-only. + + + + + Is the buffer read-only with checksum. + + + + + Convert to buffer back to an array. + + The buffer as an array. + + + + Overridden ToString method. + + The buffer as a string. + + + + Class to represent a security buffer we expect to be allocated by the SSPI. + + + + + Constructor. + + The type of the buffer. + + + + Convert to buffer back to an array. + + The buffer as an array. + + + + Security buffer for a channel binding. + + + + + Constructor. + + The channel bindings token. + + + + Convert to buffer back to an array. + + The buffer as an array. + + + + A security buffer which can be an input and output. + + If you create with the ReadOnly or ReadOnlyWithCheck types then the + array will not be updated. + + + + Constructor. + + The type of buffer. + The data for the input. + + + + Constructor. + + The type of buffer. + The data for the input. + The offset into the array. + Number of bytes in the input. + + + + Convert to buffer back to an array. + + The buffer as an array. + + + + A security buffer which can only be an output. + + + + + Constructor. + + The type of buffer. + The size of the output buffer. + + + + Convert to buffer back to an array. + + The buffer as an array. + + + + A security buffer which takes a raw pointer. The lifetime of the pointer + should be managed manually by the caller. + + + + + Constructor. + + The type of buffer. + The raw pointer. + The size of the raw pointer. + + + + The size of the buffer. + + + + + The pointer for the buffer. The lifetime needs to be manually managed. + + + + + This will free pointer using the SSPI APIs. Used to release automatically allocated + buffers. If you control the value of the Pointer you don't need to release it. + + + + + Convert to buffer back to an array. + + The buffer as an array. + + + + Security buffer type. + + + + + Class to represent a credential manager credential. + + + + + Credential flags. + + + + + Credential type. + + + + + Target name for the credentials. + + + + + Comment for the credentials. + + + + + Time the credentials was last written. + + + + + Credential blob. + + + + + Credential as a string, if available. + + + + + Credential persistence. + + + + + Credential attributes. + + + + + Target alias. + + + + + Username. + + + + + Class to represent a credential attribute. + + + + + Attribute keyword. + + + + + Attribute flags. + + + + + Attribute value. + + + + + Overridden ToString method. + + + + + + Flags for a credential attribute. + + + + + No flags. + + + + + Flags for enumeration credentials. + + + + + None. + + + + + Get all credentials. + + + + + Flags for a credential. + + + + + Class to access credential manager APIs. + + + + + Get credentials for user from credential manager. + + A filter for the target name, for example DOMAIN*. If null or empty returns all credentials. + Flags for the enumeration. + True to throw on error. + The list of credentials. + + + + Get credentials for user from credential manager. + + A filter for the target name, for example DOMAIN*. If null or empty returns all credentials. + Flags for the enumeration. + The list of credentials. + + + + Get credentials for user from credential manager. + + A filter for the target name, for example DOMAIN*. If null or empty returns all credentials. + The list of credentials. + + + + Get all credentials for user from credential manager. + + The list of credentials. + + + + Get a credential by name. + + The name of the credential. + The type of credential. + True to throw on error. + The read credential. + + + + Get a credential by name. + + The name of the credential. + The type of credential. + The read credential. + + + + Backup a user's credentials. + + The user's token. + The key for the data, typically a unicode password. Optional + True if the key is already encoded. + Caller needs SeTrustedCredmanAccessPrivilege enabled. + + + + Specify credential persistence. + + + + + Identifies the type of credentials. + + + + + Information class for a SAM domain object. + + + + + Logon32 provider + + + + + Default. + + + + + Windows NT 3.5. + + + + + Windows NT 4.0. + + + + + Windows NT 5.0. + + + + + Virtual provider. + + + + + Logon UserFlags. + + + + + Indicates the last client token status for the client context. + + + + + Yes it's the last token. + + + + + No it's not the last token. + + + + + It might be, who knows? + + + + + Status code for SSPI interface calls. + + + + + Class to represent an Account Right assigned to a user. + + + + + The name of the account right. + + + + + The display name, if known. + + + + + Get list of SIDS assigned to this access right. + + + + + ToString method. + + The name of the account right. + + + + List of account rights. Not the same as privileges. + + + + + Class to represent an LSA account object. + + + + + Get the account SID. + + + + + Get or set system access flags. + + + + + Get account privileges. + + + + + Get system access flags. + + True to throw on error. + The system access flags. + + + + Set system access flags. + + The flags to set. + True to throw on error. + The system access flags. + + + + Enumerate privileges for the account. + + True to throw on error. + The list of token privileges. + + + + Access rights for an LSA account. + + + + + Flags for looking up SIDs by name. + + + + + Flags for looking up SID names. + + + + + Base class for an LSA object. + + + + + Get the NT type for the object. + + + + + Get the object name for the object. + + + + + Get whether the object is a container. + + + + + Get the object's security descriptor. + + + + + Is an access mask granted to the object. + + The access to check. + True if all access is granted. + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + The NT status code. + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + + + + Delete the object. + + True to throw on error. + The NT status code. + + + + Delete the object. + + + + + Get the system name for the policy. + + + + + Dispose the policy. + + + + + Class to represent the LSA policy. + + + + + Lookup names for SIDs. + + The list of SIDs to lookup. + True to throw on error. + The list of looked up SID names. + + + + Lookup names for SIDs. + + The list of SIDs to lookup. + The list of looked up SID names. + + + + Lookup name for a SID. + + The SID to lookup. + + + + + Lookup names for SIDs. + + The list of SIDs to lookup. + Lookup options flags. + True to throw on error. + The list of looked up SID names. + + + + Lookup names for SIDs. + + The list of SIDs to lookup. + Lookup options flags. + The list of looked up SID names. + + + + Lookup names from the LSA policy. + + The names to lookup. + Flags for the lookup. + True to throw on error. + The list of SID names. + + + + Lookup names from the LSA policy. + + The names to lookup. + Flags for the lookup. + The list of SID names. + + + + Lookup names from the LSA policy. + + The names to lookup. + The list of SID names. + + + + Lookup names from the LSA policy. + + The name to lookup. + The looked up SID name. + + + + Enumerate accounts with a user right. + + The name of the user right. + True to throw on error. + The list of SIDs with the user right. + + + + Enumerate accounts with a user right. + + The name of the user right. + The list of SIDs with the user right. + + + + Enumerate account rights for a SID. + + The SID to enumerate for. + True to throw on error. + The list of assigned account rights. + + + + Enumerate account rights for a SID. + + The SID to enumerate for. + The list of assigned account rights. + + + + Add account rights to an account. + + The SID of the account. + The list of account rights to add. + True to throw on error. + The NT status code. + + + + Add account rights to an account. + + The SID of the account. + The list of account rights to add. + + + + Remove account rights from an account. + + The SID of the account. + True to remove all rights. + The account rights to add. + True to throw on error. + The NT status code. + + + + Remove account rights from an account. + + The SID of the account. + True to remove all rights. + The account rights to add. + + + + Retrieve LSA privilege data. + + The name of the key. + True to throw on error. + The private data as bytes. + + + + Retrieve LSA privilege data. + + The name of the key. + The private data as bytes. + + + + Store LSA private data. + + The name of the key. + The data to store. If you pass null then the value will be deleted. + True to throw on error. + The NT status code. + + + + Store LSA private data. + + The name of the key. + The data to store. If you pass null then the value will be deleted. + + + + Open an LSA secret object. + + The name of the secret. + The desired access for the secret. + True to throw on error. + The opened secret. + + + + Open an LSA secret object. + + The name of the secret. + The desired access for the secret. + The opened secret. + + + + Open an LSA secret object with maximum access. + + The name of the secret. + The opened secret. + + + + Create an LSA secret object. + + The name of the secret. + The desired access for the secret. + True to throw on error. + The created secret. + + + + Create an LSA secret object. + + The name of the secret. + The desired access for the secret. + The created secret. + + + + Create an LSA secret object with maximum access. + + The name of the secret. + The created secret. + + + + Delete an LSA secret object. + + The name of the secret. + True to throw on error. + The NT status code. + + + + Delete an LSA secret object. + + The name of the secret. + + + + Open an LSA account object. + + The SID of the account. + The desired access for the account. + True to throw on error. + The opened account. + + + + Open an LSA account object. + + The SID of the account. + The desired access for the account. + The opened account. + + + + Open an LSA account object with maximum access. + + The SID of the account. + The opened account. + + + + Create an LSA account object. + + The SID of the account. + The desired access for the account. + True to throw on error. + The created account. + + + + Create an LSA account object. + + The SID of the account. + The desired access for the account. + The created account. + + + + Create an LSA account object with maximum access. + + The SID of the account. + The created account. + + + + Delete an LSA account object. + + The SID of the account. + True to throw on error. + The NT status code. + + + + Delete an LSA account object. + + The SID of the account. + + + + Enumerate account SIDs in policy. + + True to throw on error. + The list of account SIDs. + + + + Enumerate account SIDs in policy. + + The list of account SIDs. + + + + Enumerate and open accessible account objects in policy. + + The desired access for the opened accounts. + True to throw on error. + The list of accessible accounts. + + + + Enumerate and open accessible account objects in policy. + + The desired access for the opened accounts. + + + + Enumerate and open accessible account objects in policy with maximum access. + + + + + Enumerate trusted domain information. + + True to throw on error. + The list of trusted domain information. + + + + Enumerate trusted domain information. + + The list of trusted domain information. + + + + Open trusted domain object. + + The SID of the trusted domain. + The desired access for the object. + True to throw on error. + The trusted domain object. + + + + Open trusted domain object. + + The SID of the trusted domain. + The desired access for the object. + The trusted domain object. + + + + Open trusted domain object. + + The name of the trusted domain. + The desired access for the object. + True to throw on error. + The trusted domain object. + + + + Open trusted domain object. + + The name of the trusted domain. + The desired access for the object. + The trusted domain object. + + + + Enumerate and open accessible trusted domain objects in policy. + + The desired access for the opened trusted domains. + True to throw on error. + The list of accessible trusted domains. + + + + Enumerate and open accessible trusted domain objects in policy. + + The desired access for the opened trusted domains. + The list of accessible trusted domains. + + + + Enumerate and open accessible trusted domain objects in policy. + + The list of accessible trusted domains. + + + + Open an LSA policy. + + The system name for the LSA. + The desired access on the policy. + True to throw on error. + The opened policy. + + + + Open an LSA policy. + + The desired access on the policy. + True to throw on error. + The opened policy. + + + + Open an LSA policy. + + The system name for the LSA. + The desired access on the policy. + The opened policy. + + + + Open an LSA policy. + + The desired access on the policy. + The opened policy. + + + + Open an LSA policy with maximum allowed access. + + The opened policy. + + + + Access rights for the LSA policy. + + + + + Utilities for an LSA policy. + + + + + The name of the fake NT type for a LSA policy. + + + + + The name of the fake NT type for a LSA secret. + + + + + The name of the fake NT type for a LSA account. + + + + + The name of the fake NT type for a LSA trusted domain. + + + + + Generic generic mapping for LSA policy security. + + The generic mapping for the LSA policy. + + + + Generic generic mapping for LSA secret security. + + The generic mapping for the LSA secret. + + + + Generic generic mapping for LSA account security. + + The generic mapping for the LSA account. + + + + Generic generic mapping for LSA trusted domain security. + + The generic mapping for the LSA trusted domain. + + + + Class to represent an LSA secret. + + + + + Query the value of the secret. + + True to throw on error. + The value of the secret. + + + + Query the value of the secret. + + The value of the secret. + + + + Query the current value of the secret. + + True to throw on error. + The current value of the secret. + + + + Query the current value of the secret. + + The current value of the secret. + + + + Query the old value of the secret. + + True to throw on error. + The old value of the secret. + + + + Query the old value of the secret. + + The old value of the secret. + + + + Set the value of the secret. + + The current value to set. + The old value to set. + True to throw on error. + The NT status code. + + + + Set the value of the secret. + + The current value to set. + The old value to set. + + + + Access rights for an LSA secret. + + + + + Class to represent an LSA secret value. + + + + + The current value of the secret. + + + + + The set time for the current value. + + + + + The old value of the secret. + + + + + The set time for the old value. + + + + + Flags for an account's system access. + + + + + Trust attribute flags for a trusted domain. + + + + + Direction of trust for a trusted domain. + + + + + Class to represent an LSA trusted domain. + + + + + Flat name (NETBIOS) of domain. + + + + + Domain SID. + + + + + Name of the domain. + + + + + Domain trust direction. + + + + + Domain trust type. + + + + + Domain trust attributes. + + + + + Access rights for an LSA trusted domain. + + + + + Information for a trusted domain. + + + + + DNS name of domain. + + + + + Flat name (NETBIOS) of domain. + + + + + Domain SID. + + + + + Domain trust direction. + + + + + Domain trust type. + + + + + Domain trust attributes. + + + + + Trust type for a trusted domain. + + + + + Class to represent a SAM alias. + + + + + Get members of the alias. + + True to throw on error. + The list of alias members. + + + + Get members of the alias. + + The list of alias members. + + + + The alias name. + + + + + The SID of the alias. + + + + + Access rights for a SAM alias object. + + + + + Class to represent a SAM domain object. + + + + + The domain name. + + + + + The domain SID. + + + + + Get domain password information + + + + + Lookup names in a domain. + + The list of names to lookup. + True to throw on error. + The list of looked up SID names. + + + + Lookup names in a domain. + + The list of names to lookup. + The list of looked up SID names. + + + + Lookup a name in a domain. + + The name to lookup. + True to throw on error. + The SID name. + + + + Lookup a name in a domain. + + The name to lookup. + The SID name. + + + + Lookup relative IDs in a domain. + + The list of relative IDs to lookup. + True to throw on error. + The list of looked up SID names. + + + + Lookup relative IDs in a domain. + + The list of relative IDs to lookup. + The list of looked up SID names. + + + + Lookup a rid in a domain. + + The relative ID to lookup. + True to throw on error. + The SID name. + + + + Lookup a rid in a domain. + + The relative ID to lookup. + The SID name. + + + + Enumerate users in a domain. + + User account control flags. + True to throw on error. + The list of users. + + + + Enumerate users in a domain. + + User account control flags. + The list of users. + + + + Enumerate users in a domain. + + The list of users. + + + + Enumerate groups in a domain. + + True to throw on error. + The list of groups. + + + + Enumerate groups in a domain. + + The list of groups. + + + + Enumerate aliases in a domain. + + True to throw on error. + The list of aliases. + + + + Enumerate aliases in a domain. + + The list of aliases. + + + + Get alias membership for a set of SIDs. + + The SIDs to check. + True to throw on error. + The alias enumeration. + + + + Get alias membership for a set of SIDs. + + The SIDs to check. + The alias enumeration. + + + + Get alias membership for a SID. + + The SID to check. + The alias enumeration. + + + + Open a user by relative ID. + + The user ID for the user. + The desired access for the user object. + True to throw on error. + The SAM user object. + + + + Open a user by relative ID. + + The user ID for the user. + The desired access for the user object. + The SAM user object. + + + + Open a user by SID. + + The sid for the user. + The desired access for the user object. + True to throw on error. + The SAM user object. + + + + Open a user by SID. + + The sid for the user. + The desired access for the user object. + The SAM user object. + + + + Open a user by name. + + The user name for the user. + The desired access for the user object. + True to throw on error. + The SAM user object. + + + + Open a user by name. + + The user name for the user. + The desired access for the user object. + The SAM user object. + + + + Open a group by relative ID. + + The ID for the group. + The desired access for the group object. + True to throw on error. + The SAM group object. + + + + Open a group by relative ID. + + The ID for the group. + The desired access for the group object. + The SAM group object. + + + + Open a group by SID. + + The sid for the group. + The desired access for the group object. + True to throw on error. + The SAM group object. + + + + Open a group by SID. + + The sid for the group. + The desired access for the group object. + The SAM group object. + + + + Open a group by name. + + The name for the group. + The desired access for the group object. + True to throw on error. + The SAM group object. + + + + Open a group by name. + + The name for the group. + The desired access for the group object. + The SAM group object. + + + + Create a new group object. + + The name of the group. + The desired access for the group object. + True to throw on error. + The SAM group object. + + + + Create a new group object. + + The name of the group. + The desired access for the group object. + The SAM group object. + + + + Create a new group object. + + The name of the group. + The SAM group object. + + + + Create a new user in the SAM. + + The name of the user. + The type of account. + Desired access for new user. + True to throw on error. + The SAM user object. + + + + Create a new user in the SAM. + + The name of the user. + The type of account. + Desired access for new user. + The SAM user object. + + + + Open an alias by relative ID. + + The ID for the alias. + The desired access for the alias object. + True to throw on error. + The SAM alias object. + + + + Open an alias by relative ID. + + The ID for the alias. + The desired access for the alias object. + The SAM alias object. + + + + Open an alias by SID. + + The sid for the alias. + The desired access for the alias object. + True to throw on error. + The SAM alias object. + + + + Open an alias by SID. + + The sid for the alias. + The desired access for the alias object. + The SAM alias object. + + + + Open an alias by name. + + The name for the alias. + The desired access for the alias object. + True to throw on error. + The SAM alias object. + + + + Open an alias by name. + + The name for the alias. + The desired access for the alias object. + The SAM alias object. + + + + Enumerate and open accessible user objects. + + User account control flags. + The desired access for the opened users. + True to throw on error. + The list of accessible users. + + + + Enumerate and open accessible user objects. + + User account control flags. + The desired access for the opened users. + The list of accessible users. + + + + Enumerate and open accessible user objects with maximum access. + + The list of accessible users. + + + + Enumerate and open accessible group objects. + + The desired access for the opened groups. + True to throw on error. + The list of accessible groups. + + + + Enumerate and open accessible group objects. + + The desired access for the opened groups. + The list of accessible groups. + + + + Enumerate and open accessible group objects with maximum access. + + The list of accessible groups. + + + + Enumerate and open accessible alias objects. + + The desired access for the opened aliases. + True to throw on error. + The list of accessible aliases. + + + + Enumerate and open accessible alias objects. + + The desired access for the opened aliases. + The list of accessible aliases. + + + + Enumerate and open accessible alias objects with maximum access. + + The list of accessible aliases. + + + + Convert a RID to a SID for the current object. + + The relative ID. + True to throw on error. + The converted SID. + + + + Convert a RID to a SID for the current object. + + The relative ID. + The converted SID. + + + + Get password information. + + True to throw on error. + + + + + Access rights for a SAM domain object. + + + + + The domain password policy. + + + + + Minimum password length. + + + + + Password history length. + + + + + Password properties flags. + + + + + Maximum password age. + + + + + Minimum password age. + + + + + Flags for password properties. + + + + + Class to represent a SAM group. + + + + + Get members of the group. + + True to throw on error. + The list of group members. + + + + Get members of the group. + + The list of group members. + + + + Query group attribute flags. + + True to throw on error. + The group attribute flags. + + + + Set the group attribute flags. + + The attributes to set. + True to throw on error. + The NT status code. + + + + Delete the group object. + + True to throw on error. + The NT status code. + + + + Delete the group object. + + + + + The group name. + + + + + The SID of the group. + + + + + Get or set the group attribute flags. + + + + + Access rights for the SAM group. + + + + + Membership entry for a group. + + + + + The group relative ID. + + + + + The attributes for the group. + + + + + Base class for a SAM object. + + + + + The name of the server that we've connected to. + + + + + Get the NT type for the object. + + + + + Get the object name for the object. + + + + + Get whether the object is a container. + + + + + Get the object's security descriptor. + + + + + Is an access mask granted to the object. + + The access to check. + True if all access is granted. + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + The NT status code. + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + + + + Dispose the policy. + + + + + Represents information for a SAM relative value. + + + + + The name of the domain. + + + + + The RID of the domain. + + + + + Class to represent a connection to a SAM server. + + + + + Enumerate domains in the SAM. + + True to throw on error. + The list of domains. + + + + Enumerate domains in the SAM. + + The list of domains. + + + + Lookup the domain SID for a domain name. + + The name of the domain. + True to throw on error. + The domain SID. + + + + Lookup the domain SID for a domain name. + + The name of the domain. + The domain SID. + + + + Open a SAM domain object. + + The domain SID. + The desired access for the object. + True to throw on error. + The SAM domain object. + + + + Open a SAM domain object. + + The domain SID. + The desired access for the object. + The SAM domain object. + + + + Open a SAM domain object. + + The name of the domain. + The desired access for the object. + True to throw on error. + The SAM domain object. + + + + Open a SAM domain object. + + The name of the domain. + The desired access for the object. + The SAM domain object. + + + + Enumerate and open accessible domain objects. + + The desired access for the opened domains. + True to throw on error. + The list of accessible domains. + + + + Enumerate and open accessible domain objects. + + The desired access for the opened domains. + The list of accessible domains. + + + + Opens the builtin domain on the server. + + The desired access for the object. + True to throw on error. + The SAM domain object. + + + + Opens the builtin domain on the server. + + The desired access for the object. + The SAM domain object. + + + + Opens the user domain on the server. + + The desired access for the object. + True to throw on error. + The SAM domain object. + + + + Opens the user domain on the server. + + The desired access for the object. + The SAM domain object. + + + + Connect to a SAM server. + + The name of the server. Set to null for local connection. + The desired access on the SAM server. + True to throw on error. + The server connection. + + + + Connect to a SAM server. + + The name of the server. Set to null for local connection. + The desired access on the SAM server. + The server connection. + + + + Connect to a SAM server. + + The desired access on the SAM server. + The server connection. + + + + Connect to a SAM server with maximum access. + + The server connection. + + + + Access rights for the SAM server. + + + + + Class to represent a SAM user. + + + + + Get full name for the user. + + True to throw on error. + The full name of the user. + + + + Get home directory for the user. + + True to throw on error. + The home directory of the user. + + + + Get primary group ID for the user. + + True to throw on error. + The primary group ID of the user. + + + + Get user account control flags for the user. + + True to throw on error. + The user account control flags of the user. + + + + Change a user's password. + + The old password. + The new password. + True to throw on error. + The NT status code. + + + + Change a user's password. + + The old password. + The new password. + + + + Set a user's password. + + The password to set. + Whether the password has expired. + True to throw on error. + The NT status code. + + + + Set a user's password. + + The password to set. + Whether the password has expired. + + + + The user name. + + + + + The SID of the user. + + + + + Get full name for the user. + + + + + Get home directory for the user. + + + + + Get user account control flags for the user. + + + + + Is the account disabled? + + + + + Get the primary group SID. + + + + + Access rights for a SAM user object. + + + + + Type of user account to create. + + + + + A user account. + + + + + A workstation trust account. + + + + + A server trust account. + + + + + A temporary duplicate account. + + + + + Inter domain trust account. + + + + + User account control flags. + + + + + Security utilities which call the Win32 APIs. + + + + + Set security using a named object. + + The name of the object. + The type of named object. + The security information to set. + The security descriptor to set. + True to throw on error. + The NT status code. + + + + Set security using a named object. + + The name of the object. + The type of named object. + The security information to set. + The security descriptor to set. + Specify to indicate when to execute progress function. + The security operation to perform on the tree. + Progress function. + + + + Set security using a named object. + + The name of the object. + The type of named object. + The security information to set. + The security descriptor to set. + Specify to indicate when to execute progress function. + The security operation to perform on the tree. + Progress function. + True to throw on error. + The NT status code. + + + + Set security using a named object. + + The name of the object. + The type of named object. + The security information to set. + The security descriptor to set. + The Win32 Error Code. + + + + Set security using an object handle. + + The handle of the object. + The type of object. + The security information to set. + The security descriptor to set. + True to throw on error. + The NT status code. + + + + Set security using an object handle. + + The handle of the object. + The type of object. + The security information to set. + The security descriptor to set. + + + + Set security using an object handle. + + The handle of the object. + The type of object. + The security information to set. + The security descriptor to set. + True to throw on error. + The NT status code. + + + + Set security using an object handle. + + The handle of the object. + The type of object. + The security information to set. + The security descriptor to set. + + + + Reset security using a named object. + + The name of the object. + The type of named object. + The security information to set. + The security descriptor to set. + True to keep explicit ACEs. + Specify to indicate when to execute progress function. + Progress function. + + + + Reset security using a named object. + + The name of the object. + The type of named object. + The security information to set. + The security descriptor to set. + Specify to indicate when to execute progress function. + True to keep explicit ACEs. + Progress function. + True to throw on error. + The NT status code. + + + + Get the source of inherited ACEs. + + The name of the resource. + The type of the resource. + Whether the resource is a container. + Optional list of object types. + The security descriptor for the resource. + True to check the SACL otherwise checks the DACL. + Generic mapping for the resource. + Query security descriptors for sources. + True to throw on error. + The list of inheritance sources. + + + + Get the source of inherited ACEs. + + The name of the resource. + The type of the resource. + Whether the resource is a container. + Optional list of object types. + The security descriptor for the resource. + True to check the SACL otherwise checks the DACL. + Generic mapping for the resource. + Query security descriptors for sources. + The list of inheritance sources. + + + + Get the security descriptor for a named resource. + + The name of the resource. + The type of the resource. + The security information to get. + True to throw on error. + The security descriptor. + + + + Get the security descriptor for a named resource. + + The name of the resource. + The type of the resource. + The security information to get. + The security descriptor. + + + + Get the security descriptor for a resource. + + The handle to the resource. + The type of the resource. + The security information to get. + True to throw on error. + The security descriptor. + + + + Get the security descriptor for a resource. + + The handle to the resource. + The type of the resource. + The security information to get. + The security descriptor. + + + + Get the NT type for a SE Object Type. + + The type of the resource. + The NT type if known, otherwise null. + + + + Lookup a privilege display name. + + The system name to do the lookup on. + The privilege name. + The display name. Empty string on error. + + + + Add a SID to name mapping with LSA. + + The domain name for the SID. The SID must be in the NT authority. + The account name for the SID. Can be null for a domain SID. + The SID to add. + True to throw on error. + The NT status result. + + + + Add a SID to name mapping with LSA. + + The domain name for the SID. + The account name for the SID. Can be null for a domain SID. + The SID to add. + The NT status result. + + + + Remove a SID to name mapping with LSA. + + The domain name for the SID. + The account name for the SID. Can be null for a domain SID. + True to throw on error. + The NT status result. + + + + Remove a SID to name mapping with LSA. + + The domain name for the SID. + The account name for the SID. Can be null for a domain SID. + The NT status result. + + + + Remove a SID to name mapping with LSA. + + The SID to remove. + The NT status result. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + True to throw on error. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + Additional groups to add. Needs SeTcbPrivilege. + The logged on token. + + + + Logon a user with a username and password. + + The username. + The user's domain. + The user's password. + The type of logon token. + The Logon provider. + Additional groups to add. Needs SeTcbPrivilege. + True to throw on error. + The logged on token. + + + + Lookup a SID's internet name. + + The SID to lookup. + True to throw on error. + The name of the sid as an internet account. + This still might return the normal NT4 style account name if the user is not an internet user. + + + + Lookup a SID's internet name. + + The SID to lookup. + The name of the sid as an internet account. + This still might return the normal NT4 style account name if the user is not an internet user. + + + + Retrieve LSA private data. + + The system containing the LSA instance. + The name of the key. + True to throw on error. + The private data as bytes. + + + + Retrieve LSA private data. + + The system containing the LSA instance. + The name of the key. + The private data as bytes. + + + + Retrieve LSA private data. + + The name of the key. + The private data as bytes. + + + + Store LSA private data. + + The system containing the LSA instance. + The name of the key. + The data to store. + True to throw on error. + The NT status code. + + + + Store LSA private data. + + The system containing the LSA instance. + The name of the key. + The data to store. + + + + Store LSA private data. + + The name of the key. + The data to store. + + + + Delete LSA private data. + + The system containing the LSA instance. + The name of the key. + True to throw on error. + The NT status code. + + + + Delete LSA private data. + + The system containing the LSA instance. + The name of the key. + + + + Delete LSA private data. + + The name of the key. + + + + Virtual Key enumeration. + + + + + Left mouse button + + + + + Right mouse button + + + + + Control-break processing + + + + + Middle mouse button (three-button mouse) + + + + + Windows 2000/XP: X1 mouse button + + + + + Windows 2000/XP: X2 mouse button + + + + + BACKSPACE key + + + + + TAB key + + + + + CLEAR key + + + + + ENTER key + + + + + SHIFT key + + + + + CTRL key + + + + + ALT key + + + + + PAUSE key + + + + + CAPS LOCK key + + + + + Input Method Editor (IME) Kana mode + + + + + IME Hangul mode + + + + + IME Junja mode + + + + + IME final mode + + + + + IME Hanja mode + + + + + IME Kanji mode + + + + + ESC key + + + + + IME convert + + + + + IME nonconvert + + + + + IME accept + + + + + IME mode change request + + + + + SPACEBAR + + + + + PAGE UP key + + + + + PAGE DOWN key + + + + + END key + + + + + HOME key + + + + + LEFT ARROW key + + + + + UP ARROW key + + + + + RIGHT ARROW key + + + + + DOWN ARROW key + + + + + SELECT key + + + + + PRINT key + + + + + EXECUTE key + + + + + PRINT SCREEN key + + + + + INS key + + + + + DEL key + + + + + HELP key + + + + + 0 key + + + + + 1 key + + + + + 2 key + + + + + 3 key + + + + + 4 key + + + + + 5 key + + + + + 6 key + + + + + 7 key + + + + + 8 key + + + + + 9 key + + + + + A key + + + + + B key + + + + + C key + + + + + D key + + + + + E key + + + + + F key + + + + + G key + + + + + H key + + + + + I key + + + + + J key + + + + + K key + + + + + L key + + + + + M key + + + + + N key + + + + + O key + + + + + P key + + + + + Q key + + + + + R key + + + + + S key + + + + + T key + + + + + U key + + + + + V key + + + + + W key + + + + + X key + + + + + Y key + + + + + Z key + + + + + Left Windows key (Microsoft Natural keyboard) + + + + + Right Windows key (Natural keyboard) + + + + + Applications key (Natural keyboard) + + + + + Computer Sleep key + + + + + Numeric keypad 0 key + + + + + Numeric keypad 1 key + + + + + Numeric keypad 2 key + + + + + Numeric keypad 3 key + + + + + Numeric keypad 4 key + + + + + Numeric keypad 5 key + + + + + Numeric keypad 6 key + + + + + Numeric keypad 7 key + + + + + Numeric keypad 8 key + + + + + Numeric keypad 9 key + + + + + Multiply key + + + + + Add key + + + + + Separator key + + + + + Subtract key + + + + + Decimal key + + + + + Divide key + + + + + F1 key + + + + + F2 key + + + + + F3 key + + + + + F4 key + + + + + F5 key + + + + + F6 key + + + + + F7 key + + + + + F8 key + + + + + F9 key + + + + + F10 key + + + + + F11 key + + + + + F12 key + + + + + F13 key + + + + + F14 key + + + + + F15 key + + + + + F16 key + + + + + F17 key + + + + + F18 key + + + + + F19 key + + + + + F20 key + + + + + F21 key + + + + + F22 key, (PPC only) Key used to lock device. + + + + + F23 key + + + + + F24 key + + + + + NUM LOCK key + + + + + SCROLL LOCK key + + + + + Left SHIFT key + + + + + Right SHIFT key + + + + + Left CONTROL key + + + + + Right CONTROL key + + + + + Left MENU key + + + + + Right MENU key + + + + + Windows 2000/XP: Browser Back key + + + + + Windows 2000/XP: Browser Forward key + + + + + Windows 2000/XP: Browser Refresh key + + + + + Windows 2000/XP: Browser Stop key + + + + + Windows 2000/XP: Browser Search key + + + + + Windows 2000/XP: Browser Favorites key + + + + + Windows 2000/XP: Browser Start and Home key + + + + + Windows 2000/XP: Volume Mute key + + + + + Windows 2000/XP: Volume Down key + + + + + Windows 2000/XP: Volume Up key + + + + + Windows 2000/XP: Next Track key + + + + + Windows 2000/XP: Previous Track key + + + + + Windows 2000/XP: Stop Media key + + + + + Windows 2000/XP: Play/Pause Media key + + + + + Windows 2000/XP: Start Mail key + + + + + Windows 2000/XP: Select Media key + + + + + Windows 2000/XP: Start Application 1 key + + + + + Windows 2000/XP: Start Application 2 key + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Windows 2000/XP: For any country/region, the '+' key + + + + + Windows 2000/XP: For any country/region, the ',' key + + + + + Windows 2000/XP: For any country/region, the '-' key + + + + + Windows 2000/XP: For any country/region, the '.' key + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Used for miscellaneous characters; it can vary by keyboard. + + + + + Windows 2000/XP: Either the angle bracket key or the backslash key on the RT 102-key keyboard + + + + + Windows 95/98/Me, Windows NT 4.0, Windows 2000/XP: IME PROCESS key + + + + + Windows 2000/XP: Used to pass Unicode characters as if they were keystrokes. + The VK_PACKET key is the low word of a 32-bit Virtual Key value used for non-keyboard input methods. For more information, + see Remark in KEYBDINPUT, SendInput, WM_KEYDOWN, and WM_KEYUP + + + + + Attn key + + + + + CrSel key + + + + + ExSel key + + + + + Erase EOF key + + + + + Play key + + + + + Zoom key + + + + + Reserved + + + + + PA1 key + + + + + Clear key + + + + + Class representing the information about a service. + + + + + The name of the service. + + + + + The security descriptor of the service. + + + + + The list of triggers for the service. + + + + + The service SID setting. + + + + + The service launch protected setting. + + + + + The service required privileges. + + + + + The service type. + + + + + Service start type. + + + + + Error control. + + + + + Binary path name. + + + + + Load order group. + + + + + Tag ID for load order. + + + + + Dependencies. + + + + + Display name. + + + + + Service start name. For user mode services this is the username, for drivers it's the driver name. + + + + + Indicates this service is set to delayed automatic start. + + + + + The user name this service runs under. + + + + + Type of service host when using Win32Share. + + + + + Service main function when using Win32Share. + + + + + Image path for the service. + + + + + Get name of the target image, either the ServiceDll or ImagePath. + + + + + Service DLL if a shared process server. + + + + + The name of the machine this service was found on. + + + + + Indicates if this service process is grouped with others. + + + + + Class to represent custom data for a service trigger. + + + + + The type of data. + + + + + The raw custom data. + + + + + The custom data as a string. + + + + + The custom data as an array of strings (only useful for String type). + + + + + Overidden ToString method. + + The data as a string. + + + + Trigger information for a service. + + + + + The type of service trigger. + + + + + The service trigger action. + + + + + The sub-type GUID. + + + + + The description of the sub type. + + + + + Custom data. + + + + + Overridden ToString method. + + The trigger as a string. + + + + Trigger the service. + + + + + Service trigger type. + + + + + Represents an action that the service control manager can perform. + + + + + The action to be performed. + + + + + The time to wait before performing the specified action, in milliseconds. + + + + The action to be performed. + The time to wait before performing the specified action, in milliseconds. + + + + Utilities for accessing services. + + + + + The name of the fake NT type for a service. + + + + + The name of the fake NT type for the SCM. + + + + + Get the generic mapping for the SCM. + + The SCM generic mapping. + + + + Get the generic mapping for a service. + + The service generic mapping. + + + + Get the security descriptor of the SCM. + + The SCM security descriptor. + + + + Get the security descriptor of the SCM. + + The name of a target computer. Can be null or empty to specify local machine. + Parts of the security descriptor to return. + True to throw on error. + The SCM security descriptor. + + + + Get the security descriptor of the SCM. + + The name of a target computer. Can be null or empty to specify local machine. + Parts of the security descriptor to return. + The SCM security descriptor. + + + + Get the security descriptor of the SCM. + + Parts of the security descriptor to return. + True to throw on error. + The SCM security descriptor. + + + + Get the security descriptor of the SCM. + + Parts of the security descriptor to return. + The SCM security descriptor. + + + + Get the security descriptor for a service. + + The name of the service. + Parts of the security descriptor to return. + True to throw on error. + The name of a target computer. Can be null or empty to specify local machine. + The security descriptor. + + + + Get the security descriptor for a service. + + The name of the service. + Parts of the security descriptor to return. + The name of a target computer. Can be null or empty to specify local machine. + The security descriptor. + + + + Get the security descriptor for a service. + + The name of the service. + Parts of the security descriptor to return. + True to throw on error. + The security descriptor. + + + + Get the security descriptor for a service. + + The name of the service. + Parts of the security descriptor to return. + The security descriptor. + + + + Set the SCM security descriptor. + + The name of a target computer. Can be null or empty to specify local machine. + The security descriptor to set. + The parts of the security descriptor to set. + True to throw on error. + The NT status code. + + + + Set the SCM security descriptor. + + The name of a target computer. Can be null or empty to specify local machine. + The security descriptor to set. + The parts of the security descriptor to set. + + + + Set the SCM security descriptor. + + The security descriptor to set. + The parts of the security descriptor to set. + True to throw on error. + The NT status code. + + + + Set the SCM security descriptor. + + The security descriptor to set. + The parts of the security descriptor to set. + + + + Get the information about a service. + + The name of the service. + The name of a target computer. Can be null or empty to specify local machine. + True to throw on error. + The service information. + + + + Get the information about a service. + + The name of the service. + The name of a target computer. Can be null or empty to specify local machine. + The service information. + + + + Get the information about a service. + + The name of the service. + True to throw on error. + The service information. + + + + Set the security descriptor for a service. + + The name of the service. + The name of a target computer. Can be null or empty to specify local machine. + The security descriptor to set. + The security information to set. + True to throw on error. + The NT status. + + + + Set the security descriptor for a service. + + The name of the service. + The name of a target computer. Can be null or empty to specify local machine. + The security descriptor to set. + The security information to set. + + + + Set the security descriptor for a service. + + The name of the service. + The security descriptor to set. + The security information to set. + True to throw on error. + The NT status. + + + + Set the security descriptor for a service. + + The name of the service. + The security descriptor to set. + The security information to set. + + + + Get the information about a service. + + The name of the service. + The service information. + + + + Get the information about all services. + + The name of a target computer. Can be null or empty to specify local machine. + The types of services to return. + The list of service information. + + + + Get the information about all services. + + The types of services to return. + The list of service information. + + + + Get the PID of a running service. + + The name of the service. + Returns the PID of the running service, or 0 if not running. + Thrown on error. + + + + Get the PIDs of a list of running service. + + The names of the services. + Returns the PID of the running service, or 0 if not running. + Thrown on error. + + + + Get a running service by name. + + The name of the service. + The name of a target computer. Can be null or empty to specify local machine. + True to throw on error. + The running service. + This will return active and non-active services as well as drivers. + + + + Get a running service by name. + + The name of the service. + The name of a target computer. Can be null or empty to specify local machine. + The running service. + This will return active and non-active services as well as drivers. + + + + Get a running service by name. + + The name of the service. + The running service. + True to throw on error. + This will return active and non-active services as well as drivers. + + + + Get a running service by name. + + The name of the service. + The running service. + This will return active and non-active services as well as drivers. + + + + Get a list of all registered services. + + The name of a target computer. Can be null or empty to specify local machine. + Specify state of services to get. + Specify the type filter for services. + A list of registered services. + + + + Get a list of all registered services. + + Specify state of services to get. + Specify the type filter for services. + A list of registered services. + + + + Get flags for all user service types. + + The flags for user service types. + + + + Get flags for all kernel driver types. + + The flags for kernel driver types. + + + + Get a list of all registered services. + + A list of registered services. + + + + Get a list of all active running services with their process IDs. + + A list of all active running services with process IDs. + + + + Get a list of all drivers. + + A list of all drivers. + + + + Get a list of all active running drivers. + + A list of all active running drivers. + + + + Get a list of all services and drivers. + + A list of all services and drivers. + + + + Get a list of all services and drivers. + + A list of all services and drivers. + + + + Get a fake NtType for a service. + + Service returns the service type, SCM returns SCM type. + The fake service NtType. Returns null if not a recognized type. + + + + Create a new service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + True to throw on error. + The registered service information. + + + + Create a new service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + The registered service information. + + + + Create a new service. + + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + True to throw on error. + The registered service information. + + + + Create a new service. + + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + The registered service information. + + + + Delete a service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + True to throw on error. + The NT status. + + + + Delete a service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The NT status. + + + + Delete a service. + + The name of the service. + True to throw on error. + The NT status. + + + + Delete a service. + + The name of the service. + + + + Send a control code to a service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The control code to send. If >= 128 will be sent as a custom control code. + True to throw on error. + The NT status code. + + + + Send a control code to a service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The control code to send. If >= 128 will be sent as a custom control code. + + + + Send a control code to a service. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The control code to send. If >= 128 will be sent as a custom control code. + + + + Send a control code to a service. + + The name of the service. + The control code to send. If >= 128 will be sent as a custom control code. + + + + Send a control code to a service. + + The name of the service. + The control code to send. If >= 128 will be sent as a custom control code. + + + + Change service configuration. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + Load group order. + The tag ID. + List of service dependencies. + The username for the service. + Password for the username if needed. + True to throw on error. + The NT status code. + + + + Change service configuration. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + The tag ID. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + + + + Change service configuration. + + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + The tag ID. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + True to throw on error. + The NT status code. + + + + Change service configuration. + + The name of the service. + The display name for the service. + The service type. + The service start type. + Error control. + Path to the service executable. + The tag ID. + Load group order. + List of service dependencies. + The username for the service. + Password for the username if needed. + + + + Start a service by name. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + Optional arguments to pass to the service. + True to throw on error. + The status code for the service. + + + + Start a service by name. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + Optional arguments to pass to the service. + + + + Start a service by name. + + The name of the service. + Optional arguments to pass to the service. + True to throw on error. + The status code for the service. + + + + Start a service by name. + + The name of the service. + Optional arguments to pass to the service. + The status code for the service. + + + + Set a service's SID type. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The SID type to set. + True to throw on error. + The NT status code. + + + + Set a service's SID type. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The SID type to set. + + + + Set a service's SID type. + + The name of the service. + The SID type to set. + True to throw on error. + The NT status code. + + + + Set a service's SID type. + + The name of the service. + The SID type to set. + + + + Set a service's delayed auto-start. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + If true, the service is started after other auto-start services are started plus a short delay. Otherwise, the service is started during system boot. + True to throw on error. + The NT status code. + + + + + + + + + + + + + + + Set a service's failure recover actions. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + Actions to be performed on service failure. +
If this value is null, is ignored. +
If this value is empty, the reset period and array of failure actions are deleted. + The time after which to reset the failure count to zero if there are no failures, in seconds. Specify -1 to indicate that this value should never be reset. + The command line of the process for the CreateProcess function to execute in response to the command run service controller action. +
This process runs under the same account as the service. +
If this value is null, the command is unchanged. +
If the value is an empty string (""), the command is deleted and no program is run when the service fails. + The message to be broadcast to server users before rebooting in response to the reboot action service controller action. +
If this value is null, the reboot message is unchanged. +
If the value is an empty string (""), the reboot message is deleted and no message is broadcast. +
This member can specify a localized string using the following format: @[path]dllname,-strID +
The string with identifier strID is loaded from dllname; path is optional. + True to throw on error. + The NT status code. +
+ + + + + + + + + + + + + + Set a service's required privileges. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The required privileges. + True to throw on error. + The NT status code. + + + + Set a service's required privileges. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The required privileges. + + + + Set a service's required privileges. + + The name of the service. + The required privileges. + True to throw on error. + The NT status code. + + + + Set a service's required privileges. + + The name of the service. + The required privileges. + + + + Set a service's launch protected type. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The protected type. + True to throw on error. + The NT status code. + + + + Set a service's launch protected type. + + The name of a target computer. Can be null or empty to specify local machine. + The name of the service. + The protected type. + + + + Set a service's required privileges. + + The name of the service. + The protected type. + True to throw on error. + The NT status code. + + + + Set a service's SID type. + + The name of the service. + The protected type. + + + + A service trigger for an ETW event. + + + + + The security descriptor for the ETW event. Needs administrator privileges. + + + + + Trigger the service. + + + + + Service trigger for firewall port interface. + + + + + The port for the firewall service trigger. + + + + + The protocol for the firewall service trigger. + + + + + The protocol for the firewall service trigger. + + + + + The protocol for the firewall service trigger. + + + + + Service trigger for a named pipe. + + + + + The path to the named pipe. + + + + + Service trigger for an RPC interface. + + + + + List of interface ID for the RPC server. + + + + + Class to represent a handle to the SCM. + + + + + Active services database. + + + + + Failed services database. + + + + + Open an instance of the SCM. + + The machine name for the SCM. + The database name. Specify SERVICES_ACTIVE_DATABASE or SERVICES_FAILED_DATABASE. + If null then SERVICES_ACTIVE_DATABASE is used. + The desired access for the SCM connection. + True to throw on error. + The SCM instance. + + + + Open an instance of the SCM. + + The machine name for the SCM. + The database name. Specify SERVICES_ACTIVE_DATABASE or SERVICES_FAILED_DATABASE. + If null then SERVICES_ACTIVE_DATABASE is used. + The desired access for the SCM connection. + The SCM instance. + + + + Open an instance of the SCM. + + The machine name for the SCM. + The desired access for the SCM connection. + The SCM instance. + + + + Get the Win32 services for the SCM. + + The state of the services to return. + The types of services to return. + True throw on error. + The list of services. + SCM must have been opened with EnumerateService access. + + + + Get the Win32 services for the SCM. + + The state of the services to return. + The types of services to return. + The list of services. + SCM must have been opened with EnumerateService access. + + + + Dispose the object. + + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + True to throw on error. + The security descriptor + + + + Get the security descriptor specifying which parts to retrieve + + What parts of the security descriptor to retrieve + The security descriptor + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + True to throw on error. + + + + Set the object's security descriptor + + The security descriptor to set. + What parts of the security descriptor to set + + + + Service trigger for a WNF event. + + + + + The WNF name. + + + + + Represents a loaded module from the symbol resolver. + + + + + The name of the module. + + + + + The base address of the module. + + + + + The image size of the module. + + + + + Get the path to the loaded PDB file is known. + + + + + True indicates this module only has export symbols. + + + + + Query names of types for this module. + + The list of type names. + + + + Query types in a module. + + The list of types. + + + + Get a type by name. + + The name of the type. + + + + + Query types by name + + A mask string for the type name. e.g. mod!ABC* + The list of types. + + + + Returns the name of the module. + + The name of the module. + + + + Static class for creating symbolic resolvers. + + + + + Create a new instance of a symbol resolver. + + The process in which the symbols should be resolved. + The path to dbghelp.dll, ideally should use the one which comes with Debugging Tools for Windows. + The symbol path. + Flags for the symbol resolver. + A text writer for output when specifying the TraceSymbolLoading flag. + The instance of a symbol resolver. Should be disposed when finished. + + + + Create a new instance of a symbol resolver. + + The process in which the symbols should be resolved. + The path to dbghelp.dll, ideally should use the one which comes with Debugging Tools for Windows. + The symbol path. + The instance of a symbol resolver. Should be disposed when finished. + + + + Create a new instance of a symbol resolver. Uses the system dbghelp library and symbol path + from _NT_SYMBOL_PATH environment variable. + + The process in which the symbols should be resolved. + The instance of a symbol resolver. Should be disposed when finished. + + + + Enumeration for safer level. + + + + + Constrained. + + + + + Fully trusted. + + + + + Normal user. + + + + + Untrusted. + + + + + Class to access tokens through various mechanisms. + + + + + Logon a user using S4U + + The username. + The user's realm. + + The logged on token. + + + + Get the anonymous token. + + The access rights for the opened token. + The anonymous token. + + + + Get the anonymous token. + + The anonymous token. + + + + Logon a user. + + The username. + The user's domain. + The user's password. + The logon token's type. + Optional list of additonal groups to add. + The logged on token. + + + + Logon a user. + + The username. + The user's domain. + The user's password. + The logon token's type. + Optional list of additonal groups to add. + The Logon provider. + The logged on token. + + + + Logon a user. + + The username. + The user's domain. + The user's password. + The logon token's type. + Optional list of additonal groups to add. + The Logon provider. + True to throw on error. + The logged on token. + + + + Open the current clipboard token. + + + + + + + + Get the token from the clipboard. + + The access rights for the opened token. + The clipboard token. + + + + Get the token from the clipboard. + + The clipboard token. + + + + Derive a package sid from a name. + + The name of the package. + True to throw on error. + The derived Sid + + + + Derive a package sid from a name. + + The name of the package. + The derived Sid + + + + Derive a restricted package sid from an existing pacakge sid. + + The base package sid. + The restricted name for the sid. + True to throw on error. + The derived Sid. + + + + Derive a restricted package sid from an existing pacakge sid. + + The base package sid. + The restricted name for the sid. + The derived Sid. + + + + Derive a restricted package sid from an existing package sid. + + The base package name. + The restricted name for the sid. + The derived Sid. + + + + Get the package SID from a name. + + The name of the package, can be either an SDDL SID or a package name. + The derived SID. + + + + Get a safer token. + + The base token. + The safer level to use. + True to make the token inert. + The safer token. + + + + Get session token for a session ID. + + The session ID. + The session token. + + + + Get tokens for all logged on sessions. + + Needs SeTcbPrivilege to work. + The list of session tokens. + + + + Create an AppContainer token using the CreateAppContainerToken API. + + The token to base the new token on. Can be null. + The AppContainer package SID. + List of capabilities. + True to throw on error. + The appcontainer token. + This exported function was only introduced in RS3 + + + + Create an AppContainer token using the CreateAppContainerToken API. + + The token to base the new token on. Can be null. + The AppContainer package SID. + List of capabilities. + The appcontainer token. + This exported function was only introduced in RS3 + + + + Create an AppContainer token using the CreateAppContainerToken API. + + The AppContainer package SID. + List of capabilities. + The appcontainer token. + This exported function was only introduced in RS3 + + + + Win32 Error Codes. + + + + + Flags for DefineDosDevice + + + + + None + + + + + Specify a raw target path + + + + + Remove existing definition + + + + + Only remove exact matches to the target + + + + + Don't broadcast changes to the system + + + + + Disposition values for CreateFile. + + + + + Create a new file. Fail if it exists. + + + + + Always create a new file, overwrite if it exists. + + + + + Open a file, fail if it doesn't exist. + + + + + Open a file, create if it doesn't exist. + + + + + Truncate existing file. + + + + + Flags for GetWin32PathName. + + + + + No flags. + + + + + GUID format. + + + + + NT format. + + + + + No specific format. + + + + + Opened file name. + + + + + Class representing a win32 process. + + + + + Create process with a token. + + The token to create the process with. + The process configuration. + The created win32 process. + + + + Create process with a token. + + The token to create the process with. + The path to the executable. + The process command line. + Process creation flags. + The desktop name. + The created win32 process. + + + + Create process with a token from a user logon. + + The username. + The user's domain. + The user's password. + Logon flags. + The process configuration. + The created win32 process. + + + + Create process with a token from a user logon. + + The user's credentials. + Logon flags. + The process configuration. + True to throw on error. + The created win32 process. + + + + Create process with a token from a user logon. + + The user's credentials. + Logon flags. + The process configuration. + The created win32 process. + + + + Create process with a token from a user logon. + + The username. + The user's domain. + The user's password. + Logon flags. + The process configuration. + The created win32 process. + + + + Create process with a token from a user logon. + + The username. + The user's domain. + The user's password. + Logon flags. + The path to the executable. + The process command line. + Process creation flags. + The desktop name. + The created win32 process. + + + + Create process with a token. + + The token to create the process with. + The process configuration. + The created win32 process. + + + + Create process. + + The process configuration. + The created win32 process. + + + + Create process. + + Optional parent process. + The path to the executable. + The process command line. + Process creation flags. + The desktop name. + The created win32 process. + + + + Dispose the process. + + + + + Resume the entire process. + + + + + Suspend the entire process. + + + + + Terminate the process + + The exit code for the termination + + + + The handle to the process. + + + + + The handle to the initial thread. + + + + + The process ID of the process. + + + + + The thread ID of the initial thread. + + + + + True to terminate process when disposed. + + + + + Get the process' exit status. + + + + + Get the process' exit status as an NtStatus code. + + + + + Explicit conversion operator to an NtThread object. + + The win32 process + + + + Explicit conversion operator to an NtProcess object. + + The win32 process + + + + Specify the CreateProcess API to use with a Token. + + + + + Use CreateProcessAsUser, if that fails use CreateProcessWithToken. + + + + + Use only CreateProcessAsUser. + + + + + User only CreateProcessWithToken. + + + + + Win32 process creation configuration. + + + + + Specify security descriptor of process. + + + + + Specify process handle is inheritable. + + + + + Specify security descriptor of thread. + + + + + Specify thread handle is inheritable. + + + + + Specify to inherit handles. + + + + + Specify parent process. + + + + + Specify path to application executable. + + + + + Specify command line. + + + + + Specify creation flags. + + + + + Specify environment block. + + + + + Specify current directory. + + + + + Specify desktop name. + + + + + Specify window title. + + + + + True to terminate the process when it's disposed. + + + + + Specify the mitigation options. + + + + + Specify the mitigation options 2. + + + + + Specify win32k filter flags. + + + + + Specify win32k filter level. + + + + + Specify PP level. + + + + + Specify list of handles to inherit. + + + + + Specify the appcontainer Sid. + + + + + Specify the appcontainer capabilities. + + + + + Specify LPAC. + + + + + Restrict the process from creating child processes. + + + + + Override child process creation restriction. + + + + + Set child process mitigation flags. + + + + + Specify new process policy when creating a desktop bridge application. + + + + + Specify a token to use for the new process. + + + + + Specify a stdin handle for the new process (you must inherit the handle). + + + + + Specify a stdout handle for the new process (you must inherit the handle). + + + + + Specify a stderror handle for the new process (you must inherit the handle). + + + + + Specify the package name to use. + + + + + Specify handle to pseudo console. + + + + + Specify Base Named Objects isolation prefix. + + + + + Specify the safe open prompt original claim. + + + + + When specifying the debug flags use this debug object instead of the current thread's object. + + + + + When specified do not fallback to using CreateProcessWithToken if CreateProcessWithUser fails. + + + + + Specify additional extended flags. + + + + + Specify list of handles to inherit. + + + + + Specify a service window station and desktop. + + + + + Specify authentication credentials for CreateProcessWithLogon. + + + + + Specify logon flags for the Credentials or when calling CreateProcessWithToken. + + + + + Specify the type of API to call when specifying a token. + + + + + Specify component filter flags. + + + + + Add an object's handle to the list of inherited handles. + + The object to add. + The raw handle value. + Note that this doesn't maintain a reference to the object. It should be kept + alive until the process has been created. + + + + Add an AppContainer capability by name. + + The name of the capability. + + + + Add an AppContainer capability by name. + + The capability SID. + + + + Set AppContainer SID from a package name. + + The package name. + + + + Constructor. + + + + + Flags for create process. + + + + + No flags. + + + + + Debug process. + + + + + Debug only this process. + + + + + Create suspended. + + + + + Detach process. + + + + + Create a new console. + + + + + Normal priority class. + + + + + Idle priority class. + + + + + High priority class. + + + + + Realtime priority class. + + + + + Create a new process group. + + + + + Create from a unicode environment. + + + + + Create a separate WOW VDM. + + + + + Share the WOW VDM. + + + + + Force DOS process. + + + + + Below normal priority class. + + + + + Above normal priority class. + + + + + Inherit parent affinity. + + + + + Inherit caller priority (deprecated) + + + + + Create a protected process. + + + + + Specify extended startup information is present. + + + + + Process mode background begin. + + + + + Process mode background end. + + + + + Create a secure process. + + + + + Breakaway from a job object. + + + + + Preserve code authz level. + + + + + Default error mode. + + + + + No window. + + + + + Profile user. + + + + + Profile kernel. + + + + + Profile server. + + + + + Ignore system default. + + + + + Flags for CreateProcessWithLogon + + + + + No flags. + + + + + With a profile. + + + + + Using network credentials. + + + + + Win32k filter flags. + + + + + No flags. + + + + + Enable filter. + + + + + Audit filter. + + + + + Flags for create thread. + + + + + No flags. + + + + + Create suspended. + + + + + Stack size is a reservation. + + + + + Specify PPL level. + + + + + None + + + + + Safe level as parent. + + + + + Tcb PPL + + + + + Windows PP + + + + + Windows PPL + + + + + Antimalware PPL + + + + + LSA PPL + + + + + Tcb PP + + + + + Code Generation PPL + + + + + Authenticode PP + + + + + App PPL + + + + + Extended process flags. + + + + + No flags. + + + + + Log elevation failure. + + + + + Ignore elevation requirements. + + + + + Force job breakaway (needs TCB privilege). + + + + + Process mitigation option flags. + + + + + Process mitigation option 2 flags. + + + + + Class representing a service instance. + + + + + The name of the service. + + + + + The description of the service. + + + + + Type of service. + + + + + Image path for the service. + + + + + Command line for the service. + + + + + Service DLL if a shared process server. + + + + + Current service status. + + + + + What controls are accepted by the service. + + + + + Whether the service can be stopped. + + + + + The Win32 exit code. + + + + + The service specific exit code, if Win32ExitCode is Win32Error.ERROR_SERVICE_SPECIFIC_ERROR. + + + + + The checkpoint while starting. + + + + + Waiting hint time. + + + + + Service flags. + + + + + Process ID of the running service. + + + + + The security descriptor of the service. + + + + + The list of triggers for the service. + + + + + The service SID type. + + + + + The service launch protected setting. + + + + + The service required privileges. + + + + + Service start type. + + + + + Whether the service is a delayed auto start service. + + + + + Error control. + + + + + Load order group. + + + + + Tag ID for load order. + + + + + Dependencies. + + + + + The user name this service runs under. + + + + + Type of service host when using Win32Share. + + + + + Service main function when using Win32Share. + + + + + Indicates if this service process is grouped with others. + + + + + The name of the machine this service was found on. + + + + + Overridden ToString method. + + The name of the service. + + + + Utilities for Win32 APIs. + + + + + Get a mask dictionary for a type. + + The enumerated type to query for names. + The valid access. + A dictionary mapping a mask value to a name. + + + + Get a mask dictionary for a type. + + The enumerated type to query for names. + The valid access. + Specify to get the SDK name instead of a formatting enumerated name. + A dictionary mapping a mask value to a name. + + + + Display the edit security dialog. + + Parent window handle. + NT object to display the security. + The name of the object to display. + True to force the UI to read only. + + + + Display the edit security dialog. + + Parent window handle. + The name of the object to display. + The security descriptor to display. + The NT type of the object. + + + + Display the edit security dialog. + + Parent window handle. + The name of the object to display. + The security descriptor to display. + An enumerated type for the access mask. + Generic mapping for the access rights. + Valid access mask for the access rights. + + + + Define a new DOS device. + + The dos device flags. + The device name to define. + The target path. + + + + Get Windows INVALID_HANDLE_VALUE. + + + + + Parse a command line into arguments. + + The parsed command line. + The list of arguments. + + + + Get the image path from a command line. + + The command line to parse. + The image path, returns the original command line if can't find a valid image path. + + + + Get Win32 path name for a file. + + The file to get the path from. + Flags for the path to return. + True to throw on error. + The win32 path. + + + + Get Win32 path name for a file. + + The file to get the path from. + Flags for the path to return. + The win32 path. + + + + Format a message. + + The module containing the message. + The ID of the message. + The message. Empty string on error. + + + + Format a message. + + The ID of the message. + The message. Empty string on error. + + + + Open a file with the Win32 CreateFile API. + + The filename to open. + The desired access. + The share mode. + Optional security descriptor. + True to set the handle as inheritable. + Creation disposition. + Flags and attributes. + Optional template file. + True to throw on error. + The opened file handle. + + + + Open a file with the Win32 CreateFile API. + + The filename to open. + The desired access. + The share mode. + Optional security descriptor. + True to set the handle as inheritable. + Creation disposition. + Flags and attributes. + Optional template file. + The opened file handle. + + + + Open a file with the Win32 CreateFile API. + + The filename to open. + The desired access. + The share mode. + Creation disposition. + Flags and attributes. + True to throw on error. + The opened file handle. + + + + Open a file with the Win32 CreateFile API. + + The filename to open. + The desired access. + The share mode. + Creation disposition. + Flags and attributes. + The opened file handle. + + + + Send key down events. + + The key codes to send. + + + + Send key down events. + + The key codes to send. + + + + Send key down then up events. + + The key codes to send. + This will send all keys down first, then all up. + + + + This creates a Window Station using the User32 API. + + The name of the Window Station. + The Window Station. + + + + Create a remote thread. + + The process to create the thread in. + The thread security descriptor. + Whether the handle should be inherited. + The size of the stack. 0 for default. + Start address for the thread. + Parameter to pass to the thread. + The flags for the thread creation. + True to throw on error. + The created thread. + Thrown on error. + + + + Create a remote thread. + + The process to create the thread in. + The thread security descriptor. + Whether the handle should be inherited. + The size of the stack. 0 for default. + Start address for the thread. + Parameter to pass to the thread. + The flags for the thread creation. + The created thread. + Thrown on error. + + + + Create a remote thread. + + The process to create the thread in. + Start address for the thread. + Parameter to pass to the thread. + The flags for the thread creation. + The created thread. + Thrown on error. + + + + Get a list of all console sessions. + + True to throw on error. + The list of console sessions. + + + + Get a list of all console sessions. + + The list of console sessions. + + + + Write debug string to output. + + The debug string to write. + +
+
diff --git a/README.md b/README.md new file mode 100644 index 0000000..8f16ec2 --- /dev/null +++ b/README.md @@ -0,0 +1,42 @@ +[![GitHub release][release-img]][release] +[![License][license-img]][license] + + +A GUI tool for scanning RPC communication through Event Tracing for Windows (ETW). +The tool was published as part of a research on RPC communication between the host and a Windows container. + +## Overview +RPCMon can help researchers to get a high level view over an RPC communication between processes. It was built like Procmon for easy usage, and uses James Forshaw .NET library for RPC. RPCMon can show you the RPC functions being called, the process who called them, and other relevant information. +RPCMon uses a hardcoded RPC dictionary for fast RPC information processing which contains information about RPC modules. It also have an option to build an RPC database so it will be updated from your computer in case some details are missing in the hardcoded RPC dictionary. + + +## Usage + +Double click the EXE binary and you will get the GUI Windows. +RPCMon needs a DB to be able to get the details on the RPC functions, without a DB you will have missing information. +To load the DB, press on `DB -> Load DB...` and choose your DB. You can a DB we added to this project: `/DB/RPC_UUID_Map_Windows10_1909_18363.1977.rpcdb.json`. + +## Features +* A detailed overview of RPC functions activity. +* Build an RPC database to parse RPC modules or use hardcoded database. +* Filter\highlight rows based on cells. +* Bold specific rows. + +## Demo + +https://user-images.githubusercontent.com/11998736/165285471-e143eebd-bfbf-49a2-8e70-107f083c60fc.mp4 + + +## License +Copyright (c) 2022 CyberArk Software Ltd. All rights reserved +This repository is licensed under Apache-2.0 License - see [`LICENSE`](LICENSE) for more details. + + +## References: +For more comments, suggestions or questions, you can contact Eviatar Gerzi ([@g3rzi](https://twitter.com/g3rzi)) and CyberArk Labs. + +[release-img]: https://img.shields.io/github/release/cyberark/RPCMon.svg +[release]: https://github.com/cyberark/RPCMon/releases + +[license-img]: https://img.shields.io/github/license/cyberark/RPCMon.svg +[license]: https://github.com/cyberark/RPCMon/blob/master/LICENSE diff --git a/RPCMon.sln b/RPCMon.sln new file mode 100644 index 0000000..d3117c7 --- /dev/null +++ b/RPCMon.sln @@ -0,0 +1,25 @@ + +Microsoft Visual Studio Solution File, Format Version 12.00 +# Visual Studio 15 +VisualStudioVersion = 15.0.28307.1259 +MinimumVisualStudioVersion = 10.0.40219.1 +Project("{FAE04EC0-301F-11D3-BF4B-00C04F79EFBC}") = "RPCMon", "RPCMon\RPCMon.csproj", "{9DE6BB01-5955-4EE7-BD74-B47AEC15EFBB}" +EndProject +Global + GlobalSection(SolutionConfigurationPlatforms) = preSolution + Debug|Any CPU = Debug|Any CPU + Release|Any CPU = Release|Any CPU + EndGlobalSection + GlobalSection(ProjectConfigurationPlatforms) = postSolution + {9DE6BB01-5955-4EE7-BD74-B47AEC15EFBB}.Debug|Any CPU.ActiveCfg = Debug|Any CPU + {9DE6BB01-5955-4EE7-BD74-B47AEC15EFBB}.Debug|Any CPU.Build.0 = Debug|Any CPU + {9DE6BB01-5955-4EE7-BD74-B47AEC15EFBB}.Release|Any CPU.ActiveCfg = Release|Any CPU + {9DE6BB01-5955-4EE7-BD74-B47AEC15EFBB}.Release|Any CPU.Build.0 = Release|Any CPU + EndGlobalSection + GlobalSection(SolutionProperties) = preSolution + HideSolutionNode = FALSE + EndGlobalSection + GlobalSection(ExtensibilityGlobals) = postSolution + SolutionGuid = {3E5F2A9C-F3C4-44CA-BA75-CD69F673F609} + EndGlobalSection +EndGlobal diff --git a/RPCMon/App.config b/RPCMon/App.config new file mode 100644 index 0000000..731f6de --- /dev/null +++ b/RPCMon/App.config @@ -0,0 +1,6 @@ + + + + + + \ No newline at end of file diff --git a/RPCMon/ColumnFilter.Designer.cs b/RPCMon/ColumnFilter.Designer.cs new file mode 100644 index 0000000..98ee6ad --- /dev/null +++ b/RPCMon/ColumnFilter.Designer.cs @@ -0,0 +1,268 @@ +namespace RPCMon +{ + partial class ColumnFilter + { + /// + /// Required designer variable. + /// + private System.ComponentModel.IContainer components = null; + + /// + /// Clean up any resources being used. + /// + /// true if managed resources should be disposed; otherwise, false. + protected override void Dispose(bool disposing) + { + if (disposing && (components != null)) + { + components.Dispose(); + } + base.Dispose(disposing); + } + + #region Windows Form Designer generated code + + /// + /// Required method for Designer support - do not modify + /// the contents of this method with the code editor. + /// + private void InitializeComponent() + { + this.label1 = new System.Windows.Forms.Label(); + this.comboBoxSearchByColumn = new System.Windows.Forms.ComboBox(); + this.comboBoxRelation = new System.Windows.Forms.ComboBox(); + this.comboBoxValue = new System.Windows.Forms.ComboBox(); + this.listViewColumnFilters = new System.Windows.Forms.ListView(); + this.columnHeaderColumn = ((System.Windows.Forms.ColumnHeader)(new System.Windows.Forms.ColumnHeader())); + this.columnHeaderRelation = ((System.Windows.Forms.ColumnHeader)(new System.Windows.Forms.ColumnHeader())); + this.columnHeaderValue = ((System.Windows.Forms.ColumnHeader)(new System.Windows.Forms.ColumnHeader())); + this.columnHeaderAction = ((System.Windows.Forms.ColumnHeader)(new System.Windows.Forms.ColumnHeader())); + this.comboBoxAction = new System.Windows.Forms.ComboBox(); + this.buttonOK = new System.Windows.Forms.Button(); + this.buttonCancel = new System.Windows.Forms.Button(); + this.buttonAdd = new System.Windows.Forms.Button(); + this.buttonRemove = new System.Windows.Forms.Button(); + this.labelThen = new System.Windows.Forms.Label(); + this.buttonReset = new System.Windows.Forms.Button(); + this.SuspendLayout(); + // + // label1 + // + this.label1.AutoSize = true; + this.label1.Location = new System.Drawing.Point(12, 9); + this.label1.Name = "label1"; + this.label1.Size = new System.Drawing.Size(205, 13); + this.label1.TabIndex = 0; + this.label1.Text = "Display entried matching these conditions:"; + // + // comboBoxSearchByColumn + // + this.comboBoxSearchByColumn.BackColor = System.Drawing.SystemColors.Window; + this.comboBoxSearchByColumn.DropDownStyle = System.Windows.Forms.ComboBoxStyle.DropDownList; + this.comboBoxSearchByColumn.FormattingEnabled = true; + this.comboBoxSearchByColumn.Items.AddRange(new object[] { + "PID", + "TID", + "ProcessName", + "UUID", + "Module", + "ModulePath", + "ProceduresCount", + "Service", + "Function", + "NetworkAddress", + "Protocol", + "Endpoint", + "Options", + "AuthenticationLevel", + "AuthenticationService", + "ImpersonationLevel"}); + this.comboBoxSearchByColumn.Location = new System.Drawing.Point(12, 25); + this.comboBoxSearchByColumn.Name = "comboBoxSearchByColumn"; + this.comboBoxSearchByColumn.Size = new System.Drawing.Size(121, 21); + this.comboBoxSearchByColumn.TabIndex = 1; + // + // comboBoxRelation + // + this.comboBoxRelation.DropDownStyle = System.Windows.Forms.ComboBoxStyle.DropDownList; + this.comboBoxRelation.FormattingEnabled = true; + this.comboBoxRelation.Items.AddRange(new object[] { + "contains", + "is", + "begins with", + "ends with"}); + this.comboBoxRelation.Location = new System.Drawing.Point(140, 26); + this.comboBoxRelation.Name = "comboBoxRelation"; + this.comboBoxRelation.Size = new System.Drawing.Size(87, 21); + this.comboBoxRelation.TabIndex = 2; + // + // comboBoxValue + // + this.comboBoxValue.Anchor = ((System.Windows.Forms.AnchorStyles)(((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Left) + | System.Windows.Forms.AnchorStyles.Right))); + this.comboBoxValue.FormattingEnabled = true; + this.comboBoxValue.Location = new System.Drawing.Point(244, 25); + this.comboBoxValue.Name = "comboBoxValue"; + this.comboBoxValue.Size = new System.Drawing.Size(412, 21); + this.comboBoxValue.TabIndex = 3; + // + // listViewColumnFilters + // + this.listViewColumnFilters.Anchor = ((System.Windows.Forms.AnchorStyles)((((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Bottom) + | System.Windows.Forms.AnchorStyles.Left) + | System.Windows.Forms.AnchorStyles.Right))); + this.listViewColumnFilters.CheckBoxes = true; + this.listViewColumnFilters.Columns.AddRange(new System.Windows.Forms.ColumnHeader[] { + this.columnHeaderColumn, + this.columnHeaderRelation, + this.columnHeaderValue, + this.columnHeaderAction}); + this.listViewColumnFilters.HideSelection = false; + this.listViewColumnFilters.Location = new System.Drawing.Point(15, 85); + this.listViewColumnFilters.Name = "listViewColumnFilters"; + this.listViewColumnFilters.Size = new System.Drawing.Size(776, 312); + this.listViewColumnFilters.TabIndex = 4; + this.listViewColumnFilters.UseCompatibleStateImageBehavior = false; + this.listViewColumnFilters.View = System.Windows.Forms.View.Details; + this.listViewColumnFilters.MouseDoubleClick += new System.Windows.Forms.MouseEventHandler(this.listViewColumnFilters_MouseDoubleClick); + // + // columnHeaderColumn + // + this.columnHeaderColumn.Text = "Column"; + this.columnHeaderColumn.Width = 92; + // + // columnHeaderRelation + // + this.columnHeaderRelation.Text = "Relation"; + // + // columnHeaderValue + // + this.columnHeaderValue.Text = "Value"; + // + // columnHeaderAction + // + this.columnHeaderAction.Text = "Action"; + // + // comboBoxAction + // + this.comboBoxAction.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Right))); + this.comboBoxAction.DropDownStyle = System.Windows.Forms.ComboBoxStyle.DropDownList; + this.comboBoxAction.FormattingEnabled = true; + this.comboBoxAction.Items.AddRange(new object[] { + "Include", + "Exclude"}); + this.comboBoxAction.Location = new System.Drawing.Point(704, 25); + this.comboBoxAction.Name = "comboBoxAction"; + this.comboBoxAction.Size = new System.Drawing.Size(84, 21); + this.comboBoxAction.TabIndex = 5; + // + // buttonOK + // + this.buttonOK.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Bottom | System.Windows.Forms.AnchorStyles.Right))); + this.buttonOK.Location = new System.Drawing.Point(623, 415); + this.buttonOK.Name = "buttonOK"; + this.buttonOK.Size = new System.Drawing.Size(75, 23); + this.buttonOK.TabIndex = 6; + this.buttonOK.Text = "OK"; + this.buttonOK.UseVisualStyleBackColor = true; + this.buttonOK.Click += new System.EventHandler(this.buttonOK_Click); + // + // buttonCancel + // + this.buttonCancel.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Bottom | System.Windows.Forms.AnchorStyles.Right))); + this.buttonCancel.Location = new System.Drawing.Point(713, 415); + this.buttonCancel.Name = "buttonCancel"; + this.buttonCancel.Size = new System.Drawing.Size(75, 23); + this.buttonCancel.TabIndex = 7; + this.buttonCancel.Text = "Cancel"; + this.buttonCancel.UseVisualStyleBackColor = true; + this.buttonCancel.Click += new System.EventHandler(this.buttonCancel_Click); + // + // buttonAdd + // + this.buttonAdd.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Right))); + this.buttonAdd.Location = new System.Drawing.Point(623, 56); + this.buttonAdd.Name = "buttonAdd"; + this.buttonAdd.Size = new System.Drawing.Size(75, 23); + this.buttonAdd.TabIndex = 8; + this.buttonAdd.Text = "Add"; + this.buttonAdd.UseVisualStyleBackColor = true; + this.buttonAdd.Click += new System.EventHandler(this.buttonAdd_Click); + // + // buttonRemove + // + this.buttonRemove.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Right))); + this.buttonRemove.Location = new System.Drawing.Point(713, 56); + this.buttonRemove.Name = "buttonRemove"; + this.buttonRemove.Size = new System.Drawing.Size(75, 23); + this.buttonRemove.TabIndex = 9; + this.buttonRemove.Text = "Remove"; + this.buttonRemove.UseVisualStyleBackColor = true; + this.buttonRemove.Click += new System.EventHandler(this.buttonRemove_Click); + // + // labelThen + // + this.labelThen.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Right))); + this.labelThen.AutoSize = true; + this.labelThen.Location = new System.Drawing.Point(662, 28); + this.labelThen.Name = "labelThen"; + this.labelThen.Size = new System.Drawing.Size(28, 13); + this.labelThen.TabIndex = 10; + this.labelThen.Text = "then"; + // + // buttonReset + // + this.buttonReset.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Right))); + this.buttonReset.Location = new System.Drawing.Point(15, 56); + this.buttonReset.Name = "buttonReset"; + this.buttonReset.Size = new System.Drawing.Size(75, 23); + this.buttonReset.TabIndex = 11; + this.buttonReset.Text = "Reset"; + this.buttonReset.UseVisualStyleBackColor = true; + this.buttonReset.Click += new System.EventHandler(this.buttonReset_Click); + // + // ColumnFilter + // + this.AutoScaleDimensions = new System.Drawing.SizeF(6F, 13F); + this.AutoScaleMode = System.Windows.Forms.AutoScaleMode.Font; + this.ClientSize = new System.Drawing.Size(800, 450); + this.Controls.Add(this.buttonReset); + this.Controls.Add(this.labelThen); + this.Controls.Add(this.buttonRemove); + this.Controls.Add(this.buttonAdd); + this.Controls.Add(this.buttonCancel); + this.Controls.Add(this.buttonOK); + this.Controls.Add(this.comboBoxAction); + this.Controls.Add(this.listViewColumnFilters); + this.Controls.Add(this.comboBoxValue); + this.Controls.Add(this.comboBoxRelation); + this.Controls.Add(this.comboBoxSearchByColumn); + this.Controls.Add(this.label1); + this.Name = "ColumnFilter"; + this.ShowIcon = false; + this.Text = "RPCMon Filter"; + this.ResumeLayout(false); + this.PerformLayout(); + + } + + #endregion + + private System.Windows.Forms.Label label1; + private System.Windows.Forms.ComboBox comboBoxSearchByColumn; + private System.Windows.Forms.ComboBox comboBoxRelation; + private System.Windows.Forms.ComboBox comboBoxValue; + private System.Windows.Forms.ListView listViewColumnFilters; + private System.Windows.Forms.ColumnHeader columnHeaderColumn; + private System.Windows.Forms.ColumnHeader columnHeaderRelation; + private System.Windows.Forms.ColumnHeader columnHeaderValue; + private System.Windows.Forms.ColumnHeader columnHeaderAction; + private System.Windows.Forms.ComboBox comboBoxAction; + private System.Windows.Forms.Button buttonOK; + private System.Windows.Forms.Button buttonCancel; + private System.Windows.Forms.Button buttonAdd; + private System.Windows.Forms.Button buttonRemove; + private System.Windows.Forms.Label labelThen; + private System.Windows.Forms.Button buttonReset; + } +} \ No newline at end of file diff --git a/RPCMon/ColumnFilter.cs b/RPCMon/ColumnFilter.cs new file mode 100644 index 0000000..c01a047 --- /dev/null +++ b/RPCMon/ColumnFilter.cs @@ -0,0 +1,128 @@ +using System; +using System.Collections.Generic; +using System.ComponentModel; +using System.Data; +using System.Drawing; +using System.Linq; +using System.Text; +using System.Threading.Tasks; +using System.Windows.Forms; +using static System.Windows.Forms.ListViewItem; + +namespace RPCMon +{ + public delegate void FilterOKEventHandler(ListView i_listViewColumnFilter); + + public partial class ColumnFilter : Form + { + private DataGridView m_DataGridView; + public event FilterOKEventHandler FilterOKUpdate; + public ColumnFilter(ref ListView i_ListViewColumnFilter) + { + InitializeComponentWrapper(); + + foreach (ListViewItem item in i_ListViewColumnFilter.Items) + { + ListViewItem clonedItem = (ListViewItem)item.Clone(); + this.listViewColumnFilters.Items.Add(clonedItem); + } + } + + public virtual void OnFilterOKUpdate(ListView i_listViewColumnFilter) + { + if (FilterOKUpdate != null) + { + FilterOKUpdate.Invoke(i_listViewColumnFilter); + } + } + + private void InitializeComponentWrapper() + { + InitializeComponent(); + this.comboBoxSearchByColumn.SelectedIndex = 0; + this.comboBoxRelation.SelectedIndex = 0; + this.comboBoxAction.SelectedIndex = 0; + this.listViewColumnFilters.FullRowSelect = true; + } + + public ColumnFilter(ref DataGridView i_DataGridView) + { + m_DataGridView = i_DataGridView; + InitializeComponentWrapper(); + } + + private void buttonOK_Click(object sender, EventArgs e) + { + OnFilterOKUpdate(this.listViewColumnFilters); + this.Close(); + } + + private void buttonCancel_Click(object sender, EventArgs e) + { + this.Close(); + } + + // DUPLICATED function in FormHighlighting + // Maybe create a shared function in Utils but it threw an exception for "type initializer" + private bool isRowExist(string i_Column, string i_Relation, string i_Value, string i_Action) + { + bool isExist = false; + string newRow = i_Column + i_Relation + i_Value + i_Action; + foreach (ListViewItem item in listViewColumnFilters.Items) + { + string rawRow = ""; + foreach (ListViewSubItem subItem in item.SubItems) + { + rawRow += subItem.Text; + } + + if (newRow == rawRow) + { + isExist = true; + break; + } + + } + + return isExist; + } + + private void buttonAdd_Click(object sender, EventArgs e) + { + if (!isRowExist(comboBoxSearchByColumn.Text, comboBoxRelation.Text, comboBoxValue.Text, comboBoxAction.Text)) + { + ListViewItem item = new ListViewItem(comboBoxSearchByColumn.Text); + item.SubItems.Add(comboBoxRelation.Text); + item.SubItems.Add(comboBoxValue.Text); + item.SubItems.Add(comboBoxAction.Text); + item.Checked = true; + this.listViewColumnFilters.Items.Add(item); + } + } + + private void buttonRemove_Click(object sender, EventArgs e) + { + foreach (ListViewItem item in this.listViewColumnFilters.SelectedItems) + { + item.Remove(); + } + } + + private void listViewColumnFilters_MouseDoubleClick(object sender, MouseEventArgs e) + { + foreach (ListViewItem item in ((ListView)sender).SelectedItems) + { + this.comboBoxSearchByColumn.Text = item.SubItems[0].Text; + this.comboBoxRelation.Text = item.SubItems[1].Text; + this.comboBoxValue.Text = item.SubItems[2].Text; + this.comboBoxAction.Text = item.SubItems[3].Text; + item.Remove(); + } + } + + private void buttonReset_Click(object sender, EventArgs e) + { + listViewColumnFilters.Items.Clear(); + } + } +} diff --git a/RPCMon/ColumnFilter.resx b/RPCMon/ColumnFilter.resx new file mode 100644 index 0000000..1af7de1 --- /dev/null +++ b/RPCMon/ColumnFilter.resx @@ -0,0 +1,120 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + text/microsoft-resx + + + 2.0 + + + System.Resources.ResXResourceReader, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + + System.Resources.ResXResourceWriter, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + \ No newline at end of file diff --git a/RPCMon/ColumnSelection.Designer.cs b/RPCMon/ColumnSelection.Designer.cs new file mode 100644 index 0000000..6b1ecb7 --- /dev/null +++ b/RPCMon/ColumnSelection.Designer.cs @@ -0,0 +1,362 @@ +namespace RPCMon +{ + partial class ColumnSelection + { + /// + /// Required designer variable. + /// + private System.ComponentModel.IContainer components = null; + + /// + /// Clean up any resources being used. + /// + /// true if managed resources should be disposed; otherwise, false. + protected override void Dispose(bool disposing) + { + if (disposing && (components != null)) + { + components.Dispose(); + } + base.Dispose(disposing); + } + + #region Windows Form Designer generated code + + /// + /// Required method for Designer support - do not modify + /// the contents of this method with the code editor. + /// + private void InitializeComponent() + { + this.groupBoxProcessManagement = new System.Windows.Forms.GroupBox(); + this.checkBoxProcessName = new System.Windows.Forms.CheckBox(); + this.checkBoxTID = new System.Windows.Forms.CheckBox(); + this.checkBoxPID = new System.Windows.Forms.CheckBox(); + this.label1 = new System.Windows.Forms.Label(); + this.groupBoxRPC = new System.Windows.Forms.GroupBox(); + this.checkBoxImpersonationLevel = new System.Windows.Forms.CheckBox(); + this.checkBoxAuthenticationLevel = new System.Windows.Forms.CheckBox(); + this.checkBoxAuthenticationService = new System.Windows.Forms.CheckBox(); + this.checkBoxOptions = new System.Windows.Forms.CheckBox(); + this.checkBoxEndpoint = new System.Windows.Forms.CheckBox(); + this.checkBoxProtocol = new System.Windows.Forms.CheckBox(); + this.checkBoxNetworkAddress = new System.Windows.Forms.CheckBox(); + this.checkBoxService = new System.Windows.Forms.CheckBox(); + this.checkBoxUUID = new System.Windows.Forms.CheckBox(); + this.buttonOK = new System.Windows.Forms.Button(); + this.buttonCancel = new System.Windows.Forms.Button(); + this.groupBoxRPCServer = new System.Windows.Forms.GroupBox(); + this.checkBoxModulePath = new System.Windows.Forms.CheckBox(); + this.checkBoxModule = new System.Windows.Forms.CheckBox(); + this.checkBoxProceduresCount = new System.Windows.Forms.CheckBox(); + this.checkBoxFunction = new System.Windows.Forms.CheckBox(); + this.groupBoxProcessManagement.SuspendLayout(); + this.groupBoxRPC.SuspendLayout(); + this.groupBoxRPCServer.SuspendLayout(); + this.SuspendLayout(); + // + // groupBoxProcessManagement + // + this.groupBoxProcessManagement.Controls.Add(this.checkBoxProcessName); + this.groupBoxProcessManagement.Controls.Add(this.checkBoxTID); + this.groupBoxProcessManagement.Controls.Add(this.checkBoxPID); + this.groupBoxProcessManagement.Location = new System.Drawing.Point(12, 47); + this.groupBoxProcessManagement.Name = "groupBoxProcessManagement"; + this.groupBoxProcessManagement.Size = new System.Drawing.Size(272, 77); + this.groupBoxProcessManagement.TabIndex = 0; + this.groupBoxProcessManagement.TabStop = false; + this.groupBoxProcessManagement.Text = "RPC Client"; + // + // checkBoxProcessName + // + this.checkBoxProcessName.AutoSize = true; + this.checkBoxProcessName.Checked = true; + this.checkBoxProcessName.CheckState = System.Windows.Forms.CheckState.Checked; + this.checkBoxProcessName.Location = new System.Drawing.Point(6, 53); + this.checkBoxProcessName.Name = "checkBoxProcessName"; + this.checkBoxProcessName.Size = new System.Drawing.Size(92, 17); + this.checkBoxProcessName.TabIndex = 2; + this.checkBoxProcessName.Text = "ProcessName"; + this.checkBoxProcessName.UseVisualStyleBackColor = true; + // + // checkBoxTID + // + this.checkBoxTID.AutoSize = true; + this.checkBoxTID.Checked = true; + this.checkBoxTID.CheckState = System.Windows.Forms.CheckState.Checked; + this.checkBoxTID.Location = new System.Drawing.Point(132, 30); + this.checkBoxTID.Name = "checkBoxTID"; + this.checkBoxTID.Size = new System.Drawing.Size(44, 17); + this.checkBoxTID.TabIndex = 1; + this.checkBoxTID.Text = "TID"; + this.checkBoxTID.UseVisualStyleBackColor = true; + // + // checkBoxPID + // + this.checkBoxPID.AutoSize = true; + this.checkBoxPID.Checked = true; + this.checkBoxPID.CheckState = System.Windows.Forms.CheckState.Checked; + this.checkBoxPID.Location = new System.Drawing.Point(7, 30); + this.checkBoxPID.Name = "checkBoxPID"; + this.checkBoxPID.Size = new System.Drawing.Size(44, 17); + this.checkBoxPID.TabIndex = 0; + this.checkBoxPID.Text = "PID"; + this.checkBoxPID.UseVisualStyleBackColor = true; + // + // label1 + // + this.label1.AutoSize = true; + this.label1.Location = new System.Drawing.Point(12, 19); + this.label1.Name = "label1"; + this.label1.Size = new System.Drawing.Size(243, 13); + this.label1.TabIndex = 1; + this.label1.Text = "Select columns to appear in the Procnoid window:"; + // + // groupBoxRPC + // + this.groupBoxRPC.Controls.Add(this.checkBoxImpersonationLevel); + this.groupBoxRPC.Controls.Add(this.checkBoxAuthenticationLevel); + this.groupBoxRPC.Controls.Add(this.checkBoxAuthenticationService); + this.groupBoxRPC.Controls.Add(this.checkBoxOptions); + this.groupBoxRPC.Controls.Add(this.checkBoxEndpoint); + this.groupBoxRPC.Controls.Add(this.checkBoxProtocol); + this.groupBoxRPC.Controls.Add(this.checkBoxNetworkAddress); + this.groupBoxRPC.Location = new System.Drawing.Point(12, 253); + this.groupBoxRPC.Name = "groupBoxRPC"; + this.groupBoxRPC.Size = new System.Drawing.Size(272, 122); + this.groupBoxRPC.TabIndex = 3; + this.groupBoxRPC.TabStop = false; + this.groupBoxRPC.Text = "RPC Misc"; + // + // checkBoxImpersonationLevel + // + this.checkBoxImpersonationLevel.AutoSize = true; + this.checkBoxImpersonationLevel.Checked = true; + this.checkBoxImpersonationLevel.CheckState = System.Windows.Forms.CheckState.Checked; + this.checkBoxImpersonationLevel.Location = new System.Drawing.Point(8, 97); + this.checkBoxImpersonationLevel.Name = "checkBoxImpersonationLevel"; + this.checkBoxImpersonationLevel.Size = new System.Drawing.Size(118, 17); + this.checkBoxImpersonationLevel.TabIndex = 8; + this.checkBoxImpersonationLevel.Text = "ImpersonationLevel"; + this.checkBoxImpersonationLevel.UseVisualStyleBackColor = true; + // + // checkBoxAuthenticationLevel + // + this.checkBoxAuthenticationLevel.AutoSize = true; + this.checkBoxAuthenticationLevel.Location = new System.Drawing.Point(7, 74); + this.checkBoxAuthenticationLevel.Name = "checkBoxAuthenticationLevel"; + this.checkBoxAuthenticationLevel.Size = new System.Drawing.Size(120, 17); + this.checkBoxAuthenticationLevel.TabIndex = 7; + this.checkBoxAuthenticationLevel.Text = "AuthenticationLevel"; + this.checkBoxAuthenticationLevel.UseVisualStyleBackColor = true; + // + // checkBoxAuthenticationService + // + this.checkBoxAuthenticationService.AutoSize = true; + this.checkBoxAuthenticationService.Location = new System.Drawing.Point(133, 74); + this.checkBoxAuthenticationService.Name = "checkBoxAuthenticationService"; + this.checkBoxAuthenticationService.Size = new System.Drawing.Size(130, 17); + this.checkBoxAuthenticationService.TabIndex = 6; + this.checkBoxAuthenticationService.Text = "AuthenticationService"; + this.checkBoxAuthenticationService.UseVisualStyleBackColor = true; + // + // checkBoxOptions + // + this.checkBoxOptions.AutoSize = true; + this.checkBoxOptions.Location = new System.Drawing.Point(133, 51); + this.checkBoxOptions.Name = "checkBoxOptions"; + this.checkBoxOptions.Size = new System.Drawing.Size(62, 17); + this.checkBoxOptions.TabIndex = 5; + this.checkBoxOptions.Text = "Options"; + this.checkBoxOptions.UseVisualStyleBackColor = true; + // + // checkBoxEndpoint + // + this.checkBoxEndpoint.AutoSize = true; + this.checkBoxEndpoint.Checked = true; + this.checkBoxEndpoint.CheckState = System.Windows.Forms.CheckState.Checked; + this.checkBoxEndpoint.Location = new System.Drawing.Point(7, 51); + this.checkBoxEndpoint.Name = "checkBoxEndpoint"; + this.checkBoxEndpoint.Size = new System.Drawing.Size(68, 17); + this.checkBoxEndpoint.TabIndex = 4; + this.checkBoxEndpoint.Text = "Endpoint"; + this.checkBoxEndpoint.UseVisualStyleBackColor = true; + // + // checkBoxProtocol + // + this.checkBoxProtocol.AutoSize = true; + this.checkBoxProtocol.Checked = true; + this.checkBoxProtocol.CheckState = System.Windows.Forms.CheckState.Checked; + this.checkBoxProtocol.Location = new System.Drawing.Point(133, 28); + this.checkBoxProtocol.Name = "checkBoxProtocol"; + this.checkBoxProtocol.Size = new System.Drawing.Size(65, 17); + this.checkBoxProtocol.TabIndex = 3; + this.checkBoxProtocol.Text = "Protocol"; + this.checkBoxProtocol.UseVisualStyleBackColor = true; + // + // checkBoxNetworkAddress + // + this.checkBoxNetworkAddress.AutoSize = true; + this.checkBoxNetworkAddress.Location = new System.Drawing.Point(7, 28); + this.checkBoxNetworkAddress.Name = "checkBoxNetworkAddress"; + this.checkBoxNetworkAddress.Size = new System.Drawing.Size(104, 17); + this.checkBoxNetworkAddress.TabIndex = 2; + this.checkBoxNetworkAddress.Text = "NetworkAddress"; + this.checkBoxNetworkAddress.UseVisualStyleBackColor = true; + // + // checkBoxService + // + this.checkBoxService.AutoSize = true; + this.checkBoxService.Checked = true; + this.checkBoxService.CheckState = System.Windows.Forms.CheckState.Checked; + this.checkBoxService.Location = new System.Drawing.Point(132, 76); + this.checkBoxService.Name = "checkBoxService"; + this.checkBoxService.Size = new System.Drawing.Size(62, 17); + this.checkBoxService.TabIndex = 1; + this.checkBoxService.Text = "Service"; + this.checkBoxService.UseVisualStyleBackColor = true; + // + // checkBoxUUID + // + this.checkBoxUUID.AutoSize = true; + this.checkBoxUUID.Checked = true; + this.checkBoxUUID.CheckState = System.Windows.Forms.CheckState.Checked; + this.checkBoxUUID.Location = new System.Drawing.Point(6, 30); + this.checkBoxUUID.Name = "checkBoxUUID"; + this.checkBoxUUID.Size = new System.Drawing.Size(53, 17); + this.checkBoxUUID.TabIndex = 0; + this.checkBoxUUID.Text = "UUID"; + this.checkBoxUUID.UseVisualStyleBackColor = true; + // + // buttonOK + // + this.buttonOK.Location = new System.Drawing.Point(113, 391); + this.buttonOK.Name = "buttonOK"; + this.buttonOK.Size = new System.Drawing.Size(75, 23); + this.buttonOK.TabIndex = 4; + this.buttonOK.Text = "OK"; + this.buttonOK.UseVisualStyleBackColor = true; + this.buttonOK.Click += new System.EventHandler(this.buttonOK_Click); + // + // buttonCancel + // + this.buttonCancel.Location = new System.Drawing.Point(209, 391); + this.buttonCancel.Name = "buttonCancel"; + this.buttonCancel.Size = new System.Drawing.Size(75, 23); + this.buttonCancel.TabIndex = 5; + this.buttonCancel.Text = "Cancel"; + this.buttonCancel.UseVisualStyleBackColor = true; + this.buttonCancel.Click += new System.EventHandler(this.buttonCancel_Click); + // + // groupBoxRPCServer + // + this.groupBoxRPCServer.Controls.Add(this.checkBoxFunction); + this.groupBoxRPCServer.Controls.Add(this.checkBoxModulePath); + this.groupBoxRPCServer.Controls.Add(this.checkBoxModule); + this.groupBoxRPCServer.Controls.Add(this.checkBoxProceduresCount); + this.groupBoxRPCServer.Controls.Add(this.checkBoxUUID); + this.groupBoxRPCServer.Controls.Add(this.checkBoxService); + this.groupBoxRPCServer.Location = new System.Drawing.Point(12, 139); + this.groupBoxRPCServer.Name = "groupBoxRPCServer"; + this.groupBoxRPCServer.Size = new System.Drawing.Size(272, 108); + this.groupBoxRPCServer.TabIndex = 3; + this.groupBoxRPCServer.TabStop = false; + this.groupBoxRPCServer.Text = "RPC Server"; + // + // checkBoxModulePath + // + this.checkBoxModulePath.AutoSize = true; + this.checkBoxModulePath.Location = new System.Drawing.Point(6, 53); + this.checkBoxModulePath.Name = "checkBoxModulePath"; + this.checkBoxModulePath.Size = new System.Drawing.Size(83, 17); + this.checkBoxModulePath.TabIndex = 2; + this.checkBoxModulePath.Text = "ModulePath"; + this.checkBoxModulePath.UseVisualStyleBackColor = true; + // + // checkBoxModule + // + this.checkBoxModule.AutoSize = true; + this.checkBoxModule.Checked = true; + this.checkBoxModule.CheckState = System.Windows.Forms.CheckState.Checked; + this.checkBoxModule.Location = new System.Drawing.Point(132, 30); + this.checkBoxModule.Name = "checkBoxModule"; + this.checkBoxModule.Size = new System.Drawing.Size(61, 17); + this.checkBoxModule.TabIndex = 1; + this.checkBoxModule.Text = "Module"; + this.checkBoxModule.UseVisualStyleBackColor = true; + // + // checkBoxProceduresCount + // + this.checkBoxProceduresCount.AutoSize = true; + this.checkBoxProceduresCount.Location = new System.Drawing.Point(132, 53); + this.checkBoxProceduresCount.Name = "checkBoxProceduresCount"; + this.checkBoxProceduresCount.Size = new System.Drawing.Size(108, 17); + this.checkBoxProceduresCount.TabIndex = 0; + this.checkBoxProceduresCount.Text = "ProceduresCount"; + this.checkBoxProceduresCount.UseVisualStyleBackColor = true; + // + // checkBoxFunction + // + this.checkBoxFunction.AutoSize = true; + this.checkBoxFunction.Checked = true; + this.checkBoxFunction.CheckState = System.Windows.Forms.CheckState.Checked; + this.checkBoxFunction.Location = new System.Drawing.Point(7, 76); + this.checkBoxFunction.Name = "checkBoxFunction"; + this.checkBoxFunction.Size = new System.Drawing.Size(67, 17); + this.checkBoxFunction.TabIndex = 3; + this.checkBoxFunction.Text = "Function"; + this.checkBoxFunction.UseVisualStyleBackColor = true; + // + // ColumnSelection + // + this.AutoScaleDimensions = new System.Drawing.SizeF(6F, 13F); + this.AutoScaleMode = System.Windows.Forms.AutoScaleMode.Font; + this.ClientSize = new System.Drawing.Size(292, 425); + this.Controls.Add(this.groupBoxRPCServer); + this.Controls.Add(this.buttonCancel); + this.Controls.Add(this.buttonOK); + this.Controls.Add(this.groupBoxRPC); + this.Controls.Add(this.label1); + this.Controls.Add(this.groupBoxProcessManagement); + this.MaximizeBox = false; + this.MinimizeBox = false; + this.Name = "ColumnSelection"; + this.ShowIcon = false; + this.Text = "RPC Monitor Column Selection"; + this.groupBoxProcessManagement.ResumeLayout(false); + this.groupBoxProcessManagement.PerformLayout(); + this.groupBoxRPC.ResumeLayout(false); + this.groupBoxRPC.PerformLayout(); + this.groupBoxRPCServer.ResumeLayout(false); + this.groupBoxRPCServer.PerformLayout(); + this.ResumeLayout(false); + this.PerformLayout(); + + } + + #endregion + + private System.Windows.Forms.GroupBox groupBoxProcessManagement; + private System.Windows.Forms.CheckBox checkBoxProcessName; + private System.Windows.Forms.CheckBox checkBoxTID; + private System.Windows.Forms.CheckBox checkBoxPID; + private System.Windows.Forms.Label label1; + private System.Windows.Forms.GroupBox groupBoxRPC; + private System.Windows.Forms.CheckBox checkBoxImpersonationLevel; + private System.Windows.Forms.CheckBox checkBoxAuthenticationLevel; + private System.Windows.Forms.CheckBox checkBoxAuthenticationService; + private System.Windows.Forms.CheckBox checkBoxOptions; + private System.Windows.Forms.CheckBox checkBoxEndpoint; + private System.Windows.Forms.CheckBox checkBoxProtocol; + private System.Windows.Forms.CheckBox checkBoxNetworkAddress; + private System.Windows.Forms.CheckBox checkBoxService; + private System.Windows.Forms.CheckBox checkBoxUUID; + private System.Windows.Forms.Button buttonOK; + private System.Windows.Forms.Button buttonCancel; + private System.Windows.Forms.GroupBox groupBoxRPCServer; + private System.Windows.Forms.CheckBox checkBoxFunction; + private System.Windows.Forms.CheckBox checkBoxModulePath; + private System.Windows.Forms.CheckBox checkBoxModule; + private System.Windows.Forms.CheckBox checkBoxProceduresCount; + } +} \ No newline at end of file diff --git a/RPCMon/ColumnSelection.cs b/RPCMon/ColumnSelection.cs new file mode 100644 index 0000000..1c22156 --- /dev/null +++ b/RPCMon/ColumnSelection.cs @@ -0,0 +1,41 @@ +using System; +using System.Collections.Generic; +using System.ComponentModel; +using System.Data; +using System.Drawing; +using System.Linq; +using System.Text; +using System.Threading.Tasks; +using System.Windows.Forms; + +namespace RPCMon +{ + public delegate void selectColumnsEventHandler(GroupBox i_RPCClient, GroupBox i_RPCServer, GroupBox i_RPCMisc); + public partial class ColumnSelection : Form + { + public event selectColumnsEventHandler selectColumnsUpdate; + public ColumnSelection() + { + InitializeComponent(); + } + + public virtual void OnselectColumnsUpdate(GroupBox i_RPCClient, GroupBox i_RPCServer, GroupBox i_RPCMisc) + { + if (selectColumnsUpdate != null) + { + selectColumnsUpdate.Invoke(i_RPCClient, i_RPCServer, i_RPCMisc); + } + } + + private void buttonCancel_Click(object sender, EventArgs e) + { + this.Close(); + } + + private void buttonOK_Click(object sender, EventArgs e) + { + OnselectColumnsUpdate(groupBoxProcessManagement, groupBoxRPCServer, groupBoxRPC); + this.Close(); + } + } +} diff --git a/RPCMon/ColumnSelection.resx b/RPCMon/ColumnSelection.resx new file mode 100644 index 0000000..1af7de1 --- /dev/null +++ b/RPCMon/ColumnSelection.resx @@ -0,0 +1,120 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + text/microsoft-resx + + + 2.0 + + + System.Resources.ResXResourceReader, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + + System.Resources.ResXResourceWriter, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + \ No newline at end of file diff --git a/RPCMon/Control/Engine.cs b/RPCMon/Control/Engine.cs new file mode 100644 index 0000000..ec89f20 --- /dev/null +++ b/RPCMon/Control/Engine.cs @@ -0,0 +1,311 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Linq; +using System.Text; +using System.Threading.Tasks; +using Newtonsoft.Json; + +namespace RPCMon.Control +{ + public delegate void BuildRPCDBEventHandler(string i_File, string i_FileStatus, int i_NumOfFilesWithRPC, int i_TotalNumberOfFiles); + public delegate void DoneRPCSearchEventHandler(List> i_RPCServers); + static class Engine + { + public static event BuildRPCDBEventHandler BuildRPCDBStatusUpdate; + public static event DoneRPCSearchEventHandler DoneRPCSearchUpdate; + private const string m_SymbolsPath = @"srv*c:\symbols*http://msdl.microsoft.com/download/symbols"; + private static List> m_RPCServersDB; + private static string m_DbgHelp = @"C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\dbghelp.dll"; + private static int m_TotalNumberOfFiles, m_NumOfFilesWithRPC; + private const string c_FolderToSearch = @"C:\Windows\"; + private static bool m_IsDoneRPCSearch = false; + private static Dictionary m_ExcludedFoldersMap = new Dictionary(); + public static void StopRPCSearch() + { + m_IsDoneRPCSearch = true; + } + + public static string DbgHelpFilePath + { + get { return m_DbgHelp; } + set { m_DbgHelp = value; } + } + + public static void BuildRPCDataBase(string i_FolderToSearch, string i_SavedFilePath, bool i_Recursive, string[] i_ExcludedFolders, params string[] i_Extensions) + { + m_TotalNumberOfFiles = 0; + m_NumOfFilesWithRPC = 0; + m_IsDoneRPCSearch = false; + m_RPCServersDB = new List>(); + if (i_FolderToSearch == "") + { + i_FolderToSearch = c_FolderToSearch; + } + + m_ExcludedFoldersMap.Clear(); + foreach (string folder in i_ExcludedFolders) + { + m_ExcludedFoldersMap.Add(folder.ToLower(), true); + } + + buildRPCServersList(i_FolderToSearch, i_Recursive, i_Extensions); + + OnDoneRPCSearchUpdate(m_RPCServersDB); + saveDBAsJson(m_RPCServersDB, i_SavedFilePath); + + // var a = NtApiDotNet.Win32.RpcAlpcServer.GetAlpcServers(); + } + + private static void saveDBAsJson(List> i_RPCList, string i_FileName) + { + int i = 0; + Dictionary rpcDB = new Dictionary(); + foreach (IEnumerable rpcServerEnumerator in i_RPCList) + { + foreach (NtApiDotNet.Win32.RpcServer rpcServer in rpcServerEnumerator) + { + // Maybe it is not enough to check only by UUID and add version to the check. + // But it will require to change the key. + if (rpcDB.ContainsKey(rpcServer.InterfaceId.ToString())) + { + continue; + } + + i = 0; + List functions = new List(); + foreach (var function in rpcServer.Procedures) + { + functions.Add(function.Name); + // We are assuming the functions are already in order, but are they? + // It is better to check with ProcNum of each function + //if (i != function.ProcNum) + //{ + // int b = 2; + //} + i += 1; + } + + RPCServerInfo serverInfo = new RPCServerInfo( + rpcServer.Name, + rpcServer.FilePath, + rpcServer.InterfaceId.ToString(), + rpcServer.Offset, + rpcServer.ProcedureCount, + functions, + rpcServer.ServiceName, + rpcServer.IsServiceRunning + ); + + rpcDB.Add(rpcServer.InterfaceId.ToString(), serverInfo); + } + } + + + string json = JsonConvert.SerializeObject(rpcDB); + + File.WriteAllText(i_FileName, json); + + } + + public static void OnDoneRPCSearchUpdate(List> i_RPCServers) + { + if (DoneRPCSearchUpdate != null) + { + DoneRPCSearchUpdate.Invoke(i_RPCServers); + } + } + + public static void OnBuildRPCDBStatusUpdate(string i_File, string i_FileStatus, int i_NumOfFilesWithRPC, int i_TotalNumberOfFiles) + { + if (BuildRPCDBStatusUpdate != null) + { + BuildRPCDBStatusUpdate.Invoke(i_File, i_FileStatus, i_NumOfFilesWithRPC, i_TotalNumberOfFiles); + } + } + + public static IEnumerable GetFilesByExtensions(this DirectoryInfo dir, params string[] extensions) + { + if (extensions == null) + throw new ArgumentNullException("extensions"); + IEnumerable files = dir.EnumerateFiles(); + return files.Where(f => extensions.Contains(f.Extension)); + } + + private static bool isBinaryMZFile(string i_FileName) + { + bool isBinary = false; + int numBytesToRead = 2; + int numBytesRead = 0; + byte[] bytes = new byte[2]; + int n; + using (FileStream fsSource = new FileStream(i_FileName, FileMode.Open, FileAccess.Read)) + { + n = fsSource.Read(bytes, numBytesRead, numBytesToRead); + } + + //const Int32 BufferSize = 4; + //using (var fileStream = File.OpenRead(name)) + //{ + // using (var streamReader = new StreamReader(fileStream, Encoding.UTF8, true, BufferSize)) + // { + // String line; + // line = streamReader.ReadLine(); + // int a = line.Length; + // } + //} + + // 77 = 'M', 90 = 'Z' + if (n > 0 && bytes[0] == 77 && bytes[1] == 90) + { + isBinary = true; + } + + return isBinary; + } + + // Original: https://stackoverflow.com/questions/172544/ignore-folders-files-when-directory-getfiles-is-denied-access + // https://docs.microsoft.com/en-us/dotnet/csharp/programming-guide/file-system/how-to-iterate-through-a-directory-tree + private static void buildRPCServersList(string root, bool isRecursive, params string[] extensions) + { + // Data structure to hold names of subfolders to be + // examined for files. + Stack dirs = new Stack(10); + IEnumerable rpcServer = Enumerable.Empty(); + if (!System.IO.Directory.Exists(root)) + { + throw new ArgumentException(); + } + dirs.Push(root); + + while (dirs.Count > 0) + { + if (m_IsDoneRPCSearch) + { + break; + } + + string currentDir = dirs.Pop(); + if (m_ExcludedFoldersMap.ContainsKey(currentDir.ToLower())) + { + continue; + } + //updateStatusToolStrip(currentDir); + string[] subDirs; + try + { + subDirs = System.IO.Directory.GetDirectories(currentDir); + } + // An UnauthorizedAccessException exception will be thrown if we do not have + // discovery permission on a folder or file. It may or may not be acceptable + // to ignore the exception and continue enumerating the remaining files and + // folders. It is also possible (but unlikely) that a DirectoryNotFound exception + // will be raised. This will happen if currentDir has been deleted by + // another application or thread after our call to Directory.Exists. The + // choice of which exceptions to catch depends entirely on the specific task + // you are intending to perform and also on how much you know with certainty + // about the systems on which this code will run. + catch (UnauthorizedAccessException e) + { + //Console.WriteLine(e.Message); + continue; + } + catch (System.IO.DirectoryNotFoundException e) + { + //Console.WriteLine(e.Message); + continue; + } + + //string[] files = null; + IEnumerable files; + try + { + //files = System.IO.Directory.GetFiles(currentDir, extension); + DirectoryInfo dInfo = new DirectoryInfo(currentDir); + files = dInfo.GetFilesByExtensions(extensions); + m_TotalNumberOfFiles += files.Count(); + } + + catch (UnauthorizedAccessException e) + { + + //Console.WriteLine(e.Message); + continue; + } + + catch (System.IO.DirectoryNotFoundException e) + { + //Console.WriteLine(e.Message); + continue; + } + // Perform the required action on each file here. + // Modify this block to perform your required task. + foreach (FileInfo file in files) + { + if (m_IsDoneRPCSearch) + { + break; + } + + try + { + + // Eviatar: Error when trying to load this file. There are more. + // string name = @"C:\Windows\winsxs\x86_wcf-system.identitymodel_b03f5f7f11d50a3a_10.0.19041.1_none_e690fdc7d17e3f70\System.IdentityModel.dll"; + // We are doing this check to avoid the uncatchable exception of Bad Image + // It won't help against the file C:\Windows\winsxs\x86_microsoft-windows-n..nd-syswow64-payload_31bf3856ad364e35_1.0.19041.1_none_beac3411b23832d5\compobj.dll + // which have "MZ" in the beginning but Bad Image. I add work around to execlude some folders. + // The "MZ" is not enough because there are files like + // C:\Windows\winsxs\x86_microsoft-windows-n..nd-syswow64-payload_31bf3856ad364e35_1.0.19041.1_none_beac3411b23832d5\compobj.dll + // Which have bad image and starts with "MZ". The workaround might be by trying to load it as data file first and if succeed call the ParsePe function. + + //if (isBinaryMZFile(file.FullName)) + if (Win32NativeMethods.isSucceedLoadLibrary(file.FullName, LoadLibraryFlags.LoadLibraryAsDataFile)) + { + rpcServer = NtApiDotNet.Win32.RpcServer.ParsePeFile(file.FullName, m_DbgHelp, m_SymbolsPath, NtApiDotNet.Win32.RpcServerParserFlags.None); + } + + if (rpcServer.Count() > 0) + { + m_RPCServersDB.Add(rpcServer); + m_NumOfFilesWithRPC += 1; + OnBuildRPCDBStatusUpdate(file.FullName, "Yes", m_NumOfFilesWithRPC, m_TotalNumberOfFiles); + } else + { + OnBuildRPCDBStatusUpdate(file.FullName, "No", m_NumOfFilesWithRPC, m_TotalNumberOfFiles); + } + //ManifestInfo info = Engine.GetManifestInfo(file); + /*if (info != null && (String.Empty != info.Level + info.uiAccess + info.autoElevate + info.dpiAware)) + { + if (UserMatchesFilters(info)) + { + //if(isFilteredByCheckboxes(info)){ + updateTable(info, file); + } + }*/ + } + catch (System.IO.FileNotFoundException e) + { + // If file was deleted by a separate application + // or thread since the call to TraverseTree() + // then just continue. + //Console.WriteLine(e.Message); + continue; + } + } + + if (!isRecursive) + { + break; + } + + // Push the subdirectories onto the stack for traversal. + // This could also be done before handing the files. + foreach (string str in subDirs) + dirs.Push(str); + } + + //this.toolStripStatusLabel1.Text = "Done"; + } + } +} diff --git a/RPCMon/Control/Microsoft-Windows-RPC.cs b/RPCMon/Control/Microsoft-Windows-RPC.cs new file mode 100644 index 0000000..c0bc789 --- /dev/null +++ b/RPCMon/Control/Microsoft-Windows-RPC.cs @@ -0,0 +1,1428 @@ +// +using System; +using System.Diagnostics; +using System.Diagnostics.Tracing; +using System.Text; +using Microsoft.Diagnostics.Tracing; +using Address = System.UInt64; + +#pragma warning disable 1591 // disable warnings on XML comments not being present + +// This code was automatically generated by the TraceParserGen tool, which converts +// an ETW event manifest into strongly typed C# classes. +namespace Microsoft.Diagnostics.Tracing.Parsers +{ + using Microsoft.Diagnostics.Tracing.Parsers.MicrosoftWindowsRPC; + + [System.CodeDom.Compiler.GeneratedCode("traceparsergen", "2.0")] + public sealed class MicrosoftWindowsRPCTraceEventParser : TraceEventParser + { + public static string ProviderName = "Microsoft-Windows-RPC"; + public static Guid ProviderGuid = new Guid(unchecked((int)0x6ad52b32), unchecked((short)0xd609), unchecked((short)0x4be9), 0xae, 0x07, 0xce, 0x8d, 0xae, 0x93, 0x7e, 0x39); + public enum Keywords : long + { + }; + + public MicrosoftWindowsRPCTraceEventParser(TraceEventSource source) : base(source) { } + + public event Action Debug + { + add + { + //source.RegisterEventTemplate(new DebugArgs_V1TraceData(value, 4, 3, "Debug", DebugTaskGuid, 0, "", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new DebugArgs_V1TraceData(value, 4, 3, "Debug", Guid.Empty, 0, "", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 4, DebugTaskGuid); + source.UnregisterEventTemplate(value, 4, Guid.Empty); + } + } + public event Action Debug10 + { + add + { + //source.RegisterEventTemplate(new Debug10Args_V1TraceData(value, 10, 3, "Debug", DebugTaskGuid, 0, "", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new Debug10Args_V1TraceData(value, 10, 3, "Debug", Guid.Empty, 0, "", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 10, DebugTaskGuid); + source.UnregisterEventTemplate(value, 10, Guid.Empty); + } + } + public event Action Debug11 + { + add + { + //source.RegisterEventTemplate(new Debug10Args_V1TraceData(value, 11, 3, "Debug", DebugTaskGuid, 0, "", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new Debug10Args_V1TraceData(value, 11, 3, "Debug", Guid.Empty, 0, "", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 11, DebugTaskGuid); + source.UnregisterEventTemplate(value, 11, Guid.Empty); + } + } + public event Action DebugStart + { + add + { + //source.RegisterEventTemplate(new DebugStartArgs_V1TraceData(value, 12, 3, "Debug", DebugTaskGuid, 1, "Start", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new DebugStartArgs_V1TraceData(value, 12, 3, "Debug", Guid.Empty, 1, "Start", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 12, DebugTaskGuid); + source.UnregisterEventTemplate(value, 12, Guid.Empty); + } + } + public event Action DebugStop + { + add + { + //source.RegisterEventTemplate(new DebugStopArgs_V1TraceData(value, 13, 3, "Debug", DebugTaskGuid, 2, "Stop", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new DebugStopArgs_V1TraceData(value, 13, 3, "Debug", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 13, DebugTaskGuid); + source.UnregisterEventTemplate(value, 13, Guid.Empty); + } + } + public event Action FunctionTraceStart + { + add + { + //source.RegisterEventTemplate(new FunctionTraceStartArgs_V1TraceData(value, 14, 4, "FunctionTrace", FunctionTraceTaskGuid, 1, "Start", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new FunctionTraceStartArgs_V1TraceData(value, 14, 4, "FunctionTrace", Guid.Empty, 1, "Start", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 14, FunctionTraceTaskGuid); + source.UnregisterEventTemplate(value, 14, Guid.Empty); + } + } + public event Action FunctionTraceStart16 + { + add + { + //source.RegisterEventTemplate(new FunctionTraceStart16Args_V1TraceData(value, 16, 4, "FunctionTrace", FunctionTraceTaskGuid, 1, "Start", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new FunctionTraceStart16Args_V1TraceData(value, 16, 4, "FunctionTrace", Guid.Empty, 1, "Start", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 16, FunctionTraceTaskGuid); + source.UnregisterEventTemplate(value, 16, Guid.Empty); + } + } + public event Action FunctionTraceStop + { + add + { + //source.RegisterEventTemplate(new FunctionTraceStopArgs_V1TraceData(value, 15, 4, "FunctionTrace", FunctionTraceTaskGuid, 2, "Stop", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new FunctionTraceStopArgs_V1TraceData(value, 15, 4, "FunctionTrace", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 15, FunctionTraceTaskGuid); + source.UnregisterEventTemplate(value, 15, Guid.Empty); + } + } + public event Action RpcClientCallStart + { + add + { + //source.RegisterEventTemplate(new RpcClientCallStartArgs_V1TraceData(value, 5, 1, "RpcClientCall", RpcClientCallTaskGuid, 1, "Start", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new RpcClientCallStartArgs_V1TraceData(value, 5, 1, "RpcClientCall", Guid.Empty, 1, "Start", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 5, RpcClientCallTaskGuid); + source.UnregisterEventTemplate(value, 5, Guid.Empty); + + } + } + public event Action RpcClientCallStop + { + add + { + //source.RegisterEventTemplate(new RpcClientCallStopArgs_V1TraceData(value, 1, 1, "RpcClientCall", RpcClientCallTaskGuid, 2, "Stop", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new RpcClientCallStopArgs_V1TraceData(value, 1, 1, "RpcClientCall", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 1, RpcClientCallTaskGuid); + source.UnregisterEventTemplate(value, 1, Guid.Empty); + } + } + public event Action RpcClientCallStop7 + { + add + { + //source.RegisterEventTemplate(new RpcClientCallStop7Args_V1TraceData(value, 7, 1, "RpcClientCall", RpcClientCallTaskGuid, 2, "Stop", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new RpcClientCallStop7Args_V1TraceData(value, 7, 1, "RpcClientCall", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 7, RpcClientCallTaskGuid); + source.UnregisterEventTemplate(value, 7, Guid.Empty); + } + } + public event Action RpcServerCall + { + add + { + //source.RegisterEventTemplate(new RpcServerCallArgs_V1TraceData(value, 2, 2, "RpcServerCall", RpcServerCallTaskGuid, 0, "", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new RpcServerCallArgs_V1TraceData(value, 2, 2, "RpcServerCall", Guid.Empty, 0, "", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 2, RpcServerCallTaskGuid); + source.UnregisterEventTemplate(value, 2, Guid.Empty); + } + } + public event Action RpcServerCallStart + { + add + { + //source.RegisterEventTemplate(new RpcServerCallStartArgs_V1TraceData(value, 6, 2, "RpcServerCall", RpcServerCallTaskGuid, 1, "Start", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new RpcServerCallStartArgs_V1TraceData(value, 6, 2, "RpcServerCall", Guid.Empty, 1, "Start", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 6, RpcServerCallTaskGuid); + source.UnregisterEventTemplate(value, 6, Guid.Empty); + } + } + public event Action RpcServerCallStop + { + add + { + //source.RegisterEventTemplate(new RpcClientCallStop7Args_V1TraceData(value, 8, 2, "RpcServerCall", RpcServerCallTaskGuid, 2, "Stop", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new RpcClientCallStop7Args_V1TraceData(value, 8, 2, "RpcServerCall", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 8, RpcServerCallTaskGuid); + source.UnregisterEventTemplate(value, 8, Guid.Empty); + } + } + public event Action task_0 + { + add + { + //source.RegisterEventTemplate(new task_0Args_V1TraceData(value, 3, 0, "task_0", task_0TaskGuid, 0, "", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new task_0Args_V1TraceData(value, 3, 0, "task_0", Guid.Empty, 0, "", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 3, task_0TaskGuid); + source.UnregisterEventTemplate(value, 3, Guid.Empty); + } + } + public event Action task_09 + { + add + { + //source.RegisterEventTemplate(new RpcClientCallStop7Args_V1TraceData(value, 9, 0, "task_0", task_0TaskGuid, 0, "", ProviderGuid, ProviderName)); + source.RegisterEventTemplate(new RpcClientCallStop7Args_V1TraceData(value, 9, 0, "task_0", Guid.Empty, 0, "", ProviderGuid, ProviderName)); + } + remove + { + //source.UnregisterEventTemplate(value, 9, task_0TaskGuid); + source.UnregisterEventTemplate(value, 9, Guid.Empty); + } + } + + #region private + protected override string GetProviderName() { return ProviderName; } + + static private DebugArgs_V1TraceData DebugTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new DebugArgs_V1TraceData(action, 4, 3, "Debug", Guid.Empty, 0, "", ProviderGuid, ProviderName); + } + static private Debug10Args_V1TraceData Debug10Template(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new Debug10Args_V1TraceData(action, 10, 3, "Debug", Guid.Empty, 0, "", ProviderGuid, ProviderName); + } + static private Debug10Args_V1TraceData Debug11Template(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new Debug10Args_V1TraceData(action, 11, 3, "Debug", Guid.Empty, 0, "", ProviderGuid, ProviderName); + } + static private DebugStartArgs_V1TraceData DebugStartTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new DebugStartArgs_V1TraceData(action, 12, 3, "Debug", Guid.Empty, 1, "Start", ProviderGuid, ProviderName); + } + static private DebugStopArgs_V1TraceData DebugStopTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new DebugStopArgs_V1TraceData(action, 13, 3, "Debug", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName); + } + static private FunctionTraceStartArgs_V1TraceData FunctionTraceStartTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new FunctionTraceStartArgs_V1TraceData(action, 14, 4, "FunctionTrace", Guid.Empty, 1, "Start", ProviderGuid, ProviderName); + } + static private FunctionTraceStart16Args_V1TraceData FunctionTraceStart16Template(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new FunctionTraceStart16Args_V1TraceData(action, 16, 4, "FunctionTrace", Guid.Empty, 1, "Start", ProviderGuid, ProviderName); + } + static private FunctionTraceStopArgs_V1TraceData FunctionTraceStopTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new FunctionTraceStopArgs_V1TraceData(action, 15, 4, "FunctionTrace", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName); + } + static private RpcClientCallStartArgs_V1TraceData RpcClientCallStartTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcClientCallStartArgs_V1TraceData(action, 5, 1, "RpcClientCall", Guid.Empty, 1, "Start", ProviderGuid, ProviderName); + } + static private RpcClientCallStopArgs_V1TraceData RpcClientCallStopTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcClientCallStopArgs_V1TraceData(action, 1, 1, "RpcClientCall", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName); + } + static private RpcClientCallStop7Args_V1TraceData RpcClientCallStop7Template(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcClientCallStop7Args_V1TraceData(action, 7, 1, "RpcClientCall", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName); + } + static private RpcServerCallArgs_V1TraceData RpcServerCallTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcServerCallArgs_V1TraceData(action, 2, 2, "RpcServerCall", Guid.Empty, 0, "", ProviderGuid, ProviderName); + } + static private RpcServerCallStartArgs_V1TraceData RpcServerCallStartTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcServerCallStartArgs_V1TraceData(action, 6, 2, "RpcServerCall", Guid.Empty, 1, "Start", ProviderGuid, ProviderName); + } + static private RpcClientCallStop7Args_V1TraceData RpcServerCallStopTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcClientCallStop7Args_V1TraceData(action, 8, 2, "RpcServerCall", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName); + } + static private task_0Args_V1TraceData task_0Template(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new task_0Args_V1TraceData(action, 3, 0, "task_0", Guid.Empty, 0, "", ProviderGuid, ProviderName); + } + static private RpcClientCallStop7Args_V1TraceData task_09Template(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcClientCallStop7Args_V1TraceData(action, 9, 0, "task_0", Guid.Empty, 0, "", ProviderGuid, ProviderName); + } + + static private volatile TraceEvent[] s_templates; + protected override void EnumerateTemplates(Func eventsToObserve, Action callback) + { + if (s_templates == null) + { + var templates = new TraceEvent[16]; + templates[0] = new RpcClientCallStopArgs_V1TraceData(null, 1, 1, "RpcClientCall", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName); + templates[1] = new RpcServerCallArgs_V1TraceData(null, 2, 2, "RpcServerCall", Guid.Empty, 0, "", ProviderGuid, ProviderName); + templates[2] = new task_0Args_V1TraceData(null, 3, 0, "task_0", Guid.Empty, 0, "", ProviderGuid, ProviderName); + templates[3] = new DebugArgs_V1TraceData(null, 4, 3, "Debug", Guid.Empty, 0, "", ProviderGuid, ProviderName); + templates[4] = new RpcClientCallStartArgs_V1TraceData(null, 5, 1, "RpcClientCall", Guid.Empty, 1, "Start", ProviderGuid, ProviderName); + templates[5] = new RpcServerCallStartArgs_V1TraceData(null, 6, 2, "RpcServerCall", Guid.Empty, 1, "Start", ProviderGuid, ProviderName); + templates[6] = new RpcClientCallStop7Args_V1TraceData(null, 7, 1, "RpcClientCall", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName); + templates[7] = new RpcClientCallStop7Args_V1TraceData(null, 8, 2, "RpcServerCall", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName); + templates[8] = new RpcClientCallStop7Args_V1TraceData(null, 9, 0, "task_0", Guid.Empty, 0, "", ProviderGuid, ProviderName); + templates[9] = new Debug10Args_V1TraceData(null, 10, 3, "Debug", Guid.Empty, 0, "", ProviderGuid, ProviderName); + templates[10] = new Debug10Args_V1TraceData(null, 11, 3, "Debug", Guid.Empty, 0, "", ProviderGuid, ProviderName); + templates[11] = new DebugStartArgs_V1TraceData(null, 12, 3, "Debug", Guid.Empty, 1, "Start", ProviderGuid, ProviderName); + templates[12] = new DebugStopArgs_V1TraceData(null, 13, 3, "Debug", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName); + templates[13] = new FunctionTraceStartArgs_V1TraceData(null, 14, 4, "FunctionTrace", Guid.Empty, 1, "Start", ProviderGuid, ProviderName); + templates[14] = new FunctionTraceStopArgs_V1TraceData(null, 15, 4, "FunctionTrace", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName); + templates[15] = new FunctionTraceStart16Args_V1TraceData(null, 16, 4, "FunctionTrace", Guid.Empty, 1, "Start", ProviderGuid, ProviderName); + s_templates = templates; + } + foreach (var template in s_templates) + if (eventsToObserve == null || eventsToObserve(template.ProviderName, template.EventName) == EventFilterResponse.AcceptEvent) + callback(template); + } + + #endregion + } +} + +namespace Microsoft.Diagnostics.Tracing.Parsers.MicrosoftWindowsRPC +{ + public sealed class DebugArgs_V1TraceData : TraceEvent + { + public SubjectTypes Subject { get { return (SubjectTypes)GetByteAt(0); } } + public int Verb { get { return GetByteAt(1); } } + public long SubjectPointer { get { return GetInt64At(2); } } + public long ObjectPointer { get { return GetInt64At(10); } } + public long DataPointer { get { return GetInt64At(18); } } + + #region Private + internal DebugArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 26)); + Debug.Assert(!(Version > 1 && EventDataLength < 26)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "Subject", Subject); + XmlAttrib(sb, "Verb", Verb); + XmlAttrib(sb, "SubjectPointer", SubjectPointer); + XmlAttrib(sb, "ObjectPointer", ObjectPointer); + XmlAttrib(sb, "DataPointer", DataPointer); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "Subject", "Verb", "SubjectPointer", "ObjectPointer", "DataPointer" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return Subject; + case 1: + return Verb; + case 2: + return SubjectPointer; + case 3: + return ObjectPointer; + case 4: + return DataPointer; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class Debug10Args_V1TraceData : TraceEvent + { + public long SubjectPointer { get { return GetInt64At(0); } } + public int FragmentSize { get { return GetInt32At(8); } } + public byte[] Fragment { get { return GetByteArrayAt(12, FragmentSize); } } + + #region Private + internal Debug10Args_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 0 + (FragmentSize * 1) + 12)); + Debug.Assert(!(Version > 1 && EventDataLength < 0 + (FragmentSize * 1) + 12)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "SubjectPointer", SubjectPointer); + XmlAttrib(sb, "FragmentSize", FragmentSize); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "SubjectPointer", "FragmentSize", "Fragment" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return SubjectPointer; + case 1: + return FragmentSize; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class DebugStartArgs_V1TraceData : TraceEvent + { + public int ObjectType { get { return GetInt32At(0); } } + public int Operation { get { return GetInt32At(4); } } + public long Address { get { return GetInt64At(8); } } + public long Data { get { return GetInt64At(16); } } + + #region Private + internal DebugStartArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 24)); + Debug.Assert(!(Version > 1 && EventDataLength < 24)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "ObjectType", ObjectType); + XmlAttrib(sb, "Operation", Operation); + XmlAttrib(sb, "Address", Address); + XmlAttrib(sb, "Data", Data); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "ObjectType", "Operation", "Address", "Data" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return ObjectType; + case 1: + return Operation; + case 2: + return Address; + case 3: + return Data; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class DebugStopArgs_V1TraceData : TraceEvent + { + public RpcHttp2ObjectTypes ObjectType { get { return (RpcHttp2ObjectTypes)GetInt32At(0); } } + public int Operation { get { return GetInt32At(4); } } + public long Address { get { return GetInt64At(8); } } + public long Data { get { return GetInt64At(16); } } + + #region Private + internal DebugStopArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 24)); + Debug.Assert(!(Version > 1 && EventDataLength < 24)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "ObjectType", ObjectType); + XmlAttrib(sb, "Operation", Operation); + XmlAttrib(sb, "Address", Address); + XmlAttrib(sb, "Data", Data); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "ObjectType", "Operation", "Address", "Data" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return ObjectType; + case 1: + return Operation; + case 2: + return Address; + case 3: + return Data; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class FunctionTraceStartArgs_V1TraceData : TraceEvent + { + public Guid InterfaceUuid { get { return GetGuidAt(0); } } + public Guid TypeMgrUuid { get { return GetGuidAt(16); } } + public int Flags { get { return GetInt32At(32); } } + public int MaxCalls { get { return GetInt32At(36); } } + public int SDSize { get { return GetInt32At(40); } } + public byte[] SD { get { return GetByteArrayAt(44, SDSize); } } + + #region Private + internal FunctionTraceStartArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 0 + (SDSize * 1) + 44)); + Debug.Assert(!(Version > 1 && EventDataLength < 0 + (SDSize * 1) + 44)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "InterfaceUuid", InterfaceUuid); + XmlAttrib(sb, "TypeMgrUuid", TypeMgrUuid); + XmlAttrib(sb, "Flags", Flags); + XmlAttrib(sb, "MaxCalls", MaxCalls); + XmlAttrib(sb, "SDSize", SDSize); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "InterfaceUuid", "TypeMgrUuid", "Flags", "MaxCalls", "SDSize", "SD" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return InterfaceUuid; + case 1: + return TypeMgrUuid; + case 2: + return Flags; + case 3: + return MaxCalls; + case 4: + return SDSize; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class FunctionTraceStart16Args_V1TraceData : TraceEvent + { + public string Protocol { get { return GetUnicodeStringAt(0); } } + public string Endpoint { get { return GetUnicodeStringAt(SkipUnicodeString(0)); } } + public string NetworkAddress { get { return GetUnicodeStringAt(SkipUnicodeString(SkipUnicodeString(0))); } } + public int PendingQueueSize { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(0)))); } } + public int EndpointFlags { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(0))) + 4); } } + public int NicFlags { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(0))) + 8); } } + + #region Private + internal FunctionTraceStart16Args_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(0))) + 12)); + Debug.Assert(!(Version > 1 && EventDataLength < SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(0))) + 12)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "Protocol", Protocol); + XmlAttrib(sb, "Endpoint", Endpoint); + XmlAttrib(sb, "NetworkAddress", NetworkAddress); + XmlAttrib(sb, "PendingQueueSize", PendingQueueSize); + XmlAttrib(sb, "EndpointFlags", EndpointFlags); + XmlAttrib(sb, "NicFlags", NicFlags); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "Protocol", "Endpoint", "NetworkAddress", "PendingQueueSize", "EndpointFlags", "NicFlags" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return Protocol; + case 1: + return Endpoint; + case 2: + return NetworkAddress; + case 3: + return PendingQueueSize; + case 4: + return EndpointFlags; + case 5: + return NicFlags; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class FunctionTraceStopArgs_V1TraceData : TraceEvent + { + public Guid InterfaceUuid { get { return GetGuidAt(0); } } + public Guid TypeMgrUuid { get { return GetGuidAt(16); } } + public int Flags { get { return GetInt32At(32); } } + public int MaxCalls { get { return GetInt32At(36); } } + + #region Private + internal FunctionTraceStopArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 40)); + Debug.Assert(!(Version > 1 && EventDataLength < 40)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "InterfaceUuid", InterfaceUuid); + XmlAttrib(sb, "TypeMgrUuid", TypeMgrUuid); + XmlAttrib(sb, "Flags", Flags); + XmlAttrib(sb, "MaxCalls", MaxCalls); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "InterfaceUuid", "TypeMgrUuid", "Flags", "MaxCalls" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return InterfaceUuid; + case 1: + return TypeMgrUuid; + case 2: + return Flags; + case 3: + return MaxCalls; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class RpcClientCallStartArgs_V1TraceData : TraceEvent + { + public Guid InterfaceUuid { get { return GetGuidAt(0); } } + public int ProcNum { get { return GetInt32At(16); } } + public ProtocolSequences Protocol { get { return (ProtocolSequences)GetInt32At(20); } } + public string NetworkAddress { get { return GetUnicodeStringAt(24); } } + public string Endpoint { get { return GetUnicodeStringAt(SkipUnicodeString(24)); } } + public string Options { get { return GetUnicodeStringAt(SkipUnicodeString(SkipUnicodeString(24))); } } + public int AuthenticationLevel { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24)))); } } + public AuthenticationServices AuthenticationService { get { return (AuthenticationServices)GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24))) + 4); } } + public int ImpersonationLevel { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24))) + 8); } } + + #region Private + internal RpcClientCallStartArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24))) + 12)); + Debug.Assert(!(Version > 1 && EventDataLength < SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24))) + 12)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "InterfaceUuid", InterfaceUuid); + XmlAttrib(sb, "ProcNum", ProcNum); + XmlAttrib(sb, "Protocol", Protocol); + XmlAttrib(sb, "NetworkAddress", NetworkAddress); + XmlAttrib(sb, "Endpoint", Endpoint); + XmlAttrib(sb, "Options", Options); + XmlAttrib(sb, "AuthenticationLevel", AuthenticationLevel); + XmlAttrib(sb, "AuthenticationService", AuthenticationService); + XmlAttrib(sb, "ImpersonationLevel", ImpersonationLevel); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "InterfaceUuid", "ProcNum", "Protocol", "NetworkAddress", "Endpoint", "Options", "AuthenticationLevel", "AuthenticationService", "ImpersonationLevel" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return InterfaceUuid; + case 1: + return ProcNum; + case 2: + return Protocol; + case 3: + return NetworkAddress; + case 4: + return Endpoint; + case 5: + return Options; + case 6: + return AuthenticationLevel; + case 7: + return AuthenticationService; + case 8: + return ImpersonationLevel; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class RpcClientCallStopArgs_V1TraceData : TraceEvent + { + public string ImageName { get { return GetUnicodeStringAt(0); } } + public string ComputerName { get { return GetUnicodeStringAt(SkipUnicodeString(0)); } } + public int ProcessID { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(0))); } } + // Skipping TimeStamp + public int GeneratingComponent { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(0)) + 4); } } + public int Status { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(0)) + 8); } } + public int DetectionLocation { get { return GetInt16At(SkipUnicodeString(SkipUnicodeString(0)) + 12); } } + public int Flags { get { return GetInt16At(SkipUnicodeString(SkipUnicodeString(0)) + 14); } } + public int NumberOfParameters { get { return GetInt16At(SkipUnicodeString(SkipUnicodeString(0)) + 16); } } + public long Params(int arrayIndex) { return GetInt64At(SkipUnicodeString(SkipUnicodeString(0)) + 18 + (arrayIndex * HostOffset(8, 0))); } + + #region Private + internal RpcClientCallStopArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != SkipUnicodeString(SkipUnicodeString(0)) + 18)); + Debug.Assert(!(Version > 1 && EventDataLength < SkipUnicodeString(SkipUnicodeString(0)) + 18)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "ImageName", ImageName); + XmlAttrib(sb, "ComputerName", ComputerName); + XmlAttrib(sb, "ProcessID", ProcessID); + XmlAttrib(sb, "GeneratingComponent", GeneratingComponent); + XmlAttrib(sb, "Status", Status); + XmlAttrib(sb, "DetectionLocation", DetectionLocation); + XmlAttrib(sb, "Flags", Flags); + XmlAttrib(sb, "NumberOfParameters", NumberOfParameters); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "ImageName", "ComputerName", "ProcessID", "GeneratingComponent", "Status", "DetectionLocation", "Flags", "NumberOfParameters", "Params" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return ImageName; + case 1: + return ComputerName; + case 2: + return ProcessID; + case 3: + return GeneratingComponent; + case 4: + return Status; + case 5: + return DetectionLocation; + case 6: + return Flags; + case 7: + return NumberOfParameters; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class RpcClientCallStop7Args_V1TraceData : TraceEvent + { + public int Status { get { return GetInt32At(0); } } + + #region Private + internal RpcClientCallStop7Args_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 4)); + Debug.Assert(!(Version > 1 && EventDataLength < 4)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "Status", Status); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "Status" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return Status; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class RpcServerCallArgs_V1TraceData : TraceEvent + { + public string ImangeName { get { return GetUnicodeStringAt(0); } } + public Guid InterfaceUuid { get { return GetGuidAt(SkipUnicodeString(0)); } } + public Guid FilterKey { get { return GetGuidAt(SkipUnicodeString(0) + 16); } } + + #region Private + internal RpcServerCallArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != SkipUnicodeString(0) + 32)); + Debug.Assert(!(Version > 1 && EventDataLength < SkipUnicodeString(0) + 32)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "ImangeName", ImangeName); + XmlAttrib(sb, "InterfaceUuid", InterfaceUuid); + XmlAttrib(sb, "FilterKey", FilterKey); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "ImangeName", "InterfaceUuid", "FilterKey" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return ImangeName; + case 1: + return InterfaceUuid; + case 2: + return FilterKey; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class RpcServerCallStartArgs_V1TraceData : TraceEvent + { + public Guid InterfaceUuid { get { return GetGuidAt(0); } } + public int ProcNum { get { return GetInt32At(16); } } + public int Protocol { get { return GetInt32At(20); } } + public string NetworkAddress { get { return GetUnicodeStringAt(24); } } + public string Endpoint { get { return GetUnicodeStringAt(SkipUnicodeString(24)); } } + public string Options { get { return GetUnicodeStringAt(SkipUnicodeString(SkipUnicodeString(24))); } } + public int AuthenticationLevel { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24)))); } } + public int AuthenticationService { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24))) + 4); } } + public ImpersonationLevels ImpersonationLevel { get { return (ImpersonationLevels)GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24))) + 8); } } + + #region Private + internal RpcServerCallStartArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24))) + 12)); + Debug.Assert(!(Version > 1 && EventDataLength < SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24))) + 12)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "InterfaceUuid", InterfaceUuid); + XmlAttrib(sb, "ProcNum", ProcNum); + XmlAttrib(sb, "Protocol", Protocol); + XmlAttrib(sb, "NetworkAddress", NetworkAddress); + XmlAttrib(sb, "Endpoint", Endpoint); + XmlAttrib(sb, "Options", Options); + XmlAttrib(sb, "AuthenticationLevel", AuthenticationLevel); + XmlAttrib(sb, "AuthenticationService", AuthenticationService); + XmlAttrib(sb, "ImpersonationLevel", ImpersonationLevel); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "InterfaceUuid", "ProcNum", "Protocol", "NetworkAddress", "Endpoint", "Options", "AuthenticationLevel", "AuthenticationService", "ImpersonationLevel" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return InterfaceUuid; + case 1: + return ProcNum; + case 2: + return Protocol; + case 3: + return NetworkAddress; + case 4: + return Endpoint; + case 5: + return Options; + case 6: + return AuthenticationLevel; + case 7: + return AuthenticationService; + case 8: + return ImpersonationLevel; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class task_0Args_V1TraceData : TraceEvent + { + public string ImageName { get { return GetUnicodeStringAt(0); } } + public int DetectionLocation { get { return GetInt16At(SkipUnicodeString(0)); } } + public int Status { get { return GetInt32At(SkipUnicodeString(0) + 2); } } + public int AdditionalData1 { get { return GetInt32At(SkipUnicodeString(0) + 6); } } + public int AdditionalData2 { get { return GetInt32At(SkipUnicodeString(0) + 10); } } + + #region Private + internal task_0Args_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != SkipUnicodeString(0) + 14)); + Debug.Assert(!(Version > 1 && EventDataLength < SkipUnicodeString(0) + 14)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action)value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "ImageName", ImageName); + XmlAttrib(sb, "DetectionLocation", DetectionLocation); + XmlAttrib(sb, "Status", Status); + XmlAttrib(sb, "AdditionalData1", AdditionalData1); + XmlAttrib(sb, "AdditionalData2", AdditionalData2); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "ImageName", "DetectionLocation", "Status", "AdditionalData1", "AdditionalData2" }; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return ImageName; + case 1: + return DetectionLocation; + case 2: + return Status; + case 3: + return AdditionalData1; + case 4: + return AdditionalData2; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public enum AuthenticationServices + { + Negotiate = 0x9, + NTLM = 0xa, + SChannel = 0xe, + Kerberos = 0x10, + Kernel = 0x14, + } + public enum ImpersonationLevels + { + Default = 0x0, + Anonymous = 0x1, + Identify = 0x2, + Impersonate = 0x3, + Delegate = 0x4, + } + public enum ProtocolSequences + { + TCP = 0x1, + NamedPipes = 0x2, + LRPC = 0x3, + RPCHTTP = 0x4, + } + public enum RpcHttp2ObjectTypes + { + SOCKET_CHANNEL = 0x1, + PROXY_SOCKET_CHANNEL = 0x2, + CHANNEL = 0x3, + BOTTOM_CHANNEL = 0x4, + IIS_CHANNEL = 0x5, + RAW_CONNECTION = 0x6, + INITIAL_RAW_CONNECTION = 0x7, + IIS_SENDER_CHANNEL = 0x8, + ENDPOINT_RECEIVER = 0x9, + PLUG_CHANNEL = 0xa, + CLIENT_VC = 0xb, + SERVER_VC = 0xc, + INPROXY_VC = 0xd, + OUTPROXY_VC = 0xe, + PROXY_VC = 0xf, + CDATA_ORIGINATOR = 0x10, + CLIENT_CHANNEL = 0x11, + CALLBACK = 0x12, + FLOW_CONTROL_SENDER = 0x13, + WINHTTP_CALLBACK = 0x14, + WINHTTP_CHANNEL = 0x15, + WINHTTP_RAW = 0x16, + PROXY_RECEIVER = 0x17, + SERVER_CHANNEL = 0x18, + FRAGMENT_RECEIVER = 0x19, + } + public enum SubjectTypes + { + ASSOC = 0x2e, + HTTPv2 = 0x32, + SASSOC = 0x41, + BCACHE2 = 0x42, + SCALL = 0x43, + ADDRESS = 0x44, + ENGINE = 0x45, + CAUSAL_F = 0x46, + GC = 0x47, + HEAP = 0x48, + EEINFO = 0x49, + ALPC = 0x4c, + RESERVED_MEM = 0x4d, + SCONN = 0x4e, + CORRUPT = 0x4f, + PROVIDER = 0x50, + SECCRED = 0x53, + STABLE = 0x54, + PROTOCOL = 0x57, + CASSOC = 0x61, + BCACHE = 0x62, + CCALL = 0x63, + TP_ALPC = 0x64, + CENDPOINT = 0x65, + TP_CALLBACK = 0x66, + HANDLE = 0x68, + IF = 0x69, + TP_IO = 0x6a, + TP_WORK = 0x6b, + CTXHANDLE = 0x6c, + MUTEX = 0x6d, + CCONN = 0x6e, + TRANS_CONN = 0x6f, + PACKET = 0x70, + REFOBJ = 0x72, + SSECCTX = 0x73, + THREAD = 0x74, + TP_TIMER = 0x75, + EVENT = 0x76, + TP_WAIT = 0x77, + EXCEPT = 0x78, + } +} diff --git a/RPCMon/Control/RPCServerInfo.cs b/RPCMon/Control/RPCServerInfo.cs new file mode 100644 index 0000000..a1ab44a --- /dev/null +++ b/RPCMon/Control/RPCServerInfo.cs @@ -0,0 +1,138 @@ +using System; +using System.Collections.Generic; +using System.Linq; +using System.Text; +using System.Threading.Tasks; + +namespace RPCMon.Control +{ + class RPCServerInfo + { + private string m_Module; + private string m_ModulePath; + private string m_InterfaceId; + private long m_InterfaceStructOffset; + private int m_ProceduresCount; + private List m_Procedures; + private string m_Service; + private bool m_IsServiceRunning; + + public RPCServerInfo(string i_Module, string i_ModulePath, string i_InterfaceId, + long i_InterfaceStructOffset, int i_ProceduresCount, List i_Procedures, string i_Service, bool + i_IsServiceRunning) + { + m_Module = i_Module; + m_ModulePath = i_ModulePath; + m_InterfaceId = i_InterfaceId; + m_InterfaceStructOffset = i_InterfaceStructOffset; + m_ProceduresCount = i_ProceduresCount; + m_Procedures = i_Procedures; + m_Service = i_Service; + m_IsServiceRunning = i_IsServiceRunning; + } + + public string Module + { + get + { + return m_Module; + } + + set + { + m_Module = value; + } + } + + public string ModulePath + { + get + { + return m_ModulePath; + } + + set + { + m_ModulePath = value; + } + } + + public string InterfaceId + { + get + { + return m_InterfaceId; + } + + set + { + m_InterfaceId = value; + } + } + + public long InterfaceStructOffset + { + get + { + return m_InterfaceStructOffset; + } + + set + { + m_InterfaceStructOffset = value; + } + } + + public int ProceduresCount + { + get + { + return m_ProceduresCount; + } + + set + { + m_ProceduresCount = value; + } + } + + public List Procedures + { + get + { + return m_Procedures; + } + + set + { + m_Procedures = value; + } + } + + public string Service + { + get + { + return m_Service; + } + + set + { + m_Service = value; + } + } + + public bool IsServiceRunning + { + get + { + return m_IsServiceRunning; + } + + set + { + m_IsServiceRunning = value; + } + } + } +} diff --git a/RPCMon/Control/Win32NativeMethods.cs b/RPCMon/Control/Win32NativeMethods.cs new file mode 100644 index 0000000..2f59220 --- /dev/null +++ b/RPCMon/Control/Win32NativeMethods.cs @@ -0,0 +1,80 @@ +using System; +using System.Collections.Generic; +using System.Linq; +using System.Runtime.InteropServices; +using System.Text; +using System.Threading.Tasks; +using NtApiDotNet.Win32; + +namespace RPCMon.Control +{ + + public static class Win32NativeMethods + { + [DllImport("kernel32.dll", CharSet = CharSet.Unicode, SetLastError = true)] + internal static extern SafeLoadLibraryHandle LoadLibraryEx(string name, IntPtr reserved, LoadLibraryFlags flags); + public static bool isSucceedLoadLibrary(string i_Name, LoadLibraryFlags flags) + { + bool isSuceed = false; + SafeLoadLibraryHandle ret = LoadLibraryEx(i_Name, IntPtr.Zero, flags); + if (!ret.IsInvalid) + { + isSuceed = true; + } + + return isSuceed; + } + } + + public enum LoadLibraryFlags + { + /// + /// None. + /// + None = 0, + /// + /// Don't resolve DLL references + /// + DontResolveDllReferences = 0x00000001, + /// + /// Load library as a data file. + /// + LoadLibraryAsDataFile = 0x00000002, + /// + /// Load with an altered search path. + /// + LoadWithAlteredSearchPath = 0x00000008, + /// + /// Ignore code authz level. + /// + LoadIgnoreCodeAuthzLevel = 0x00000010, + /// + /// Load library as an image resource. + /// + LoadLibraryAsImageResource = 0x00000020, + /// + /// Load library as a data file exclusively. + /// + LoadLibraryAsDataFileExclusive = 0x00000040, + /// + /// Add the DLL's directory temporarily to the search list. + /// + LoadLibrarySearchDllLoadDir = 0x00000100, + /// + /// Search application directory for the DLL. + /// + LoadLibrarySearchApplicationDir = 0x00000200, + /// + /// Search the user's directories for the DLL. + /// + LoadLibrarySearchUserDirs = 0x00000400, + /// + /// Search system32 for the DLL. + /// + LoadLibrarySearchSystem32 = 0x00000800, + /// + /// Search the default directories for the DLL. + /// + LoadLibrarySearchDefaultDirs = 0x00001000, + } +} diff --git a/RPCMon/Form1.Designer.cs b/RPCMon/Form1.Designer.cs new file mode 100644 index 0000000..b6f63a7 --- /dev/null +++ b/RPCMon/Form1.Designer.cs @@ -0,0 +1,509 @@ +namespace RPCMon +{ + partial class Form1 + { + /// + /// Required designer variable. + /// + private System.ComponentModel.IContainer components = null; + + /// + /// Clean up any resources being used. + /// + /// true if managed resources should be disposed; otherwise, false. + protected override void Dispose(bool disposing) + { + if (disposing && (components != null)) + { + components.Dispose(); + } + base.Dispose(disposing); + } + + #region Windows Form Designer generated code + + /// + /// Required method for Designer support - do not modify + /// the contents of this method with the code editor. + /// + private void InitializeComponent() + { + this.components = new System.ComponentModel.Container(); + System.ComponentModel.ComponentResourceManager resources = new System.ComponentModel.ComponentResourceManager(typeof(Form1)); + this.menuStrip1 = new System.Windows.Forms.MenuStrip(); + this.fileToolStripMenuItem = new System.Windows.Forms.ToolStripMenuItem(); + this.saveToolStripMenuItem = new System.Windows.Forms.ToolStripMenuItem(); + this.dBToolStripMenuItem = new System.Windows.Forms.ToolStripMenuItem(); + this.loadDBToolStripMenuItemLoadDB = new System.Windows.Forms.ToolStripMenuItem(); + this.buildDBToolStripMenuItem = new System.Windows.Forms.ToolStripMenuItem(); + this.optionsToolStripMenuItem = new System.Windows.Forms.ToolStripMenuItem(); + this.setDbgHelpFilePathToolStripMenuItem = new System.Windows.Forms.ToolStripMenuItem(); + this.helpToolStripMenuItem = new System.Windows.Forms.ToolStripMenuItem(); + this.aboutToolStripMenuItem = new System.Windows.Forms.ToolStripMenuItem(); + this.toolStrip1 = new System.Windows.Forms.ToolStrip(); + this.toolStripButtonStart = new System.Windows.Forms.ToolStripButton(); + this.toolStripButtonClear = new System.Windows.Forms.ToolStripButton(); + this.toolStripButtonFilter = new System.Windows.Forms.ToolStripButton(); + this.toolStripButtonFind = new System.Windows.Forms.ToolStripButton(); + this.toolStripButtonHighlight = new System.Windows.Forms.ToolStripButton(); + this.toolStripButtonGrid = new System.Windows.Forms.ToolStripButton(); + this.toolStripButtonRemoveDuplicate = new System.Windows.Forms.ToolStripButton(); + this.dataGridView1 = new System.Windows.Forms.DataGridView(); + this.ColumnPID = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnTID = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnProcessName = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnUUID = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnModule = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnModulePath = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnProceduresCount = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnService = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnFunction = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnNetworkAddress = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnProtocol = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnEndpoint = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnOptions = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnAuthenticationLevel = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnAuthenticationService = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.ColumnImpersonationLevel = new System.Windows.Forms.DataGridViewTextBoxColumn(); + this.statusStrip1 = new System.Windows.Forms.StatusStrip(); + this.toolStripStatusLabelTotalEvents = new System.Windows.Forms.ToolStripStatusLabel(); + this.toolStripStatusLabelDBPath = new System.Windows.Forms.ToolStripStatusLabel(); + this.toolTipDBPath = new System.Windows.Forms.ToolTip(this.components); + this.contextMenuStripRightClickGridView = new System.Windows.Forms.ContextMenuStrip(this.components); + this.copyRowToolStripMenuItem = new System.Windows.Forms.ToolStripMenuItem(); + this.copyCellToolStripMenuItem = new System.Windows.Forms.ToolStripMenuItem(); + this.menuStrip1.SuspendLayout(); + this.toolStrip1.SuspendLayout(); + ((System.ComponentModel.ISupportInitialize)(this.dataGridView1)).BeginInit(); + this.statusStrip1.SuspendLayout(); + this.contextMenuStripRightClickGridView.SuspendLayout(); + this.SuspendLayout(); + // + // menuStrip1 + // + this.menuStrip1.ImageScalingSize = new System.Drawing.Size(20, 20); + this.menuStrip1.Items.AddRange(new System.Windows.Forms.ToolStripItem[] { + this.fileToolStripMenuItem, + this.dBToolStripMenuItem, + this.optionsToolStripMenuItem, + this.helpToolStripMenuItem}); + this.menuStrip1.Location = new System.Drawing.Point(0, 0); + this.menuStrip1.Name = "menuStrip1"; + this.menuStrip1.Size = new System.Drawing.Size(828, 24); + this.menuStrip1.TabIndex = 0; + this.menuStrip1.Text = "menuStrip1"; + // + // fileToolStripMenuItem + // + this.fileToolStripMenuItem.DropDownItems.AddRange(new System.Windows.Forms.ToolStripItem[] { + this.saveToolStripMenuItem}); + this.fileToolStripMenuItem.Name = "fileToolStripMenuItem"; + this.fileToolStripMenuItem.Size = new System.Drawing.Size(37, 20); + this.fileToolStripMenuItem.Text = "File"; + // + // saveToolStripMenuItem + // + this.saveToolStripMenuItem.Name = "saveToolStripMenuItem"; + this.saveToolStripMenuItem.Size = new System.Drawing.Size(107, 22); + this.saveToolStripMenuItem.Text = "Save..."; + this.saveToolStripMenuItem.Click += new System.EventHandler(this.saveToolStripMenuItem_Click); + // + // dBToolStripMenuItem + // + this.dBToolStripMenuItem.DropDownItems.AddRange(new System.Windows.Forms.ToolStripItem[] { + this.loadDBToolStripMenuItemLoadDB, + this.buildDBToolStripMenuItem}); + this.dBToolStripMenuItem.Name = "dBToolStripMenuItem"; + this.dBToolStripMenuItem.Size = new System.Drawing.Size(34, 20); + this.dBToolStripMenuItem.Text = "DB"; + // + // loadDBToolStripMenuItemLoadDB + // + this.loadDBToolStripMenuItemLoadDB.Name = "loadDBToolStripMenuItemLoadDB"; + this.loadDBToolStripMenuItemLoadDB.Size = new System.Drawing.Size(128, 22); + this.loadDBToolStripMenuItemLoadDB.Text = "Load DB..."; + this.loadDBToolStripMenuItemLoadDB.Click += new System.EventHandler(this.loadDBToolStripMenuItemLoadDB_Click); + // + // buildDBToolStripMenuItem + // + this.buildDBToolStripMenuItem.Name = "buildDBToolStripMenuItem"; + this.buildDBToolStripMenuItem.Size = new System.Drawing.Size(128, 22); + this.buildDBToolStripMenuItem.Text = "Build DB..."; + this.buildDBToolStripMenuItem.Click += new System.EventHandler(this.buildDBToolStripMenuItem_Click); + // + // optionsToolStripMenuItem + // + this.optionsToolStripMenuItem.DropDownItems.AddRange(new System.Windows.Forms.ToolStripItem[] { + this.setDbgHelpFilePathToolStripMenuItem}); + this.optionsToolStripMenuItem.Name = "optionsToolStripMenuItem"; + this.optionsToolStripMenuItem.Size = new System.Drawing.Size(61, 20); + this.optionsToolStripMenuItem.Text = "Options"; + // + // setDbgHelpFilePathToolStripMenuItem + // + this.setDbgHelpFilePathToolStripMenuItem.Name = "setDbgHelpFilePathToolStripMenuItem"; + this.setDbgHelpFilePathToolStripMenuItem.Size = new System.Drawing.Size(197, 22); + this.setDbgHelpFilePathToolStripMenuItem.Text = "Set DbgHelp File Path..."; + this.setDbgHelpFilePathToolStripMenuItem.Click += new System.EventHandler(this.setDbgHelpFilePathToolStripMenuItem_Click); + // + // helpToolStripMenuItem + // + this.helpToolStripMenuItem.DropDownItems.AddRange(new System.Windows.Forms.ToolStripItem[] { + this.aboutToolStripMenuItem}); + this.helpToolStripMenuItem.Name = "helpToolStripMenuItem"; + this.helpToolStripMenuItem.Size = new System.Drawing.Size(44, 20); + this.helpToolStripMenuItem.Text = "Help"; + // + // aboutToolStripMenuItem + // + this.aboutToolStripMenuItem.Name = "aboutToolStripMenuItem"; + this.aboutToolStripMenuItem.Size = new System.Drawing.Size(116, 22); + this.aboutToolStripMenuItem.Text = "About..."; + this.aboutToolStripMenuItem.Click += new System.EventHandler(this.aboutToolStripMenuItem_Click); + // + // toolStrip1 + // + this.toolStrip1.ImageScalingSize = new System.Drawing.Size(20, 20); + this.toolStrip1.Items.AddRange(new System.Windows.Forms.ToolStripItem[] { + this.toolStripButtonStart, + this.toolStripButtonClear, + this.toolStripButtonFilter, + this.toolStripButtonFind, + this.toolStripButtonHighlight, + this.toolStripButtonGrid, + this.toolStripButtonRemoveDuplicate}); + this.toolStrip1.Location = new System.Drawing.Point(0, 24); + this.toolStrip1.Name = "toolStrip1"; + this.toolStrip1.Size = new System.Drawing.Size(828, 27); + this.toolStrip1.TabIndex = 1; + this.toolStrip1.Text = "toolStrip1"; + // + // toolStripButtonStart + // + this.toolStripButtonStart.DisplayStyle = System.Windows.Forms.ToolStripItemDisplayStyle.Image; + this.toolStripButtonStart.Image = global::RPCMon.Properties.Resources.startIcon; + this.toolStripButtonStart.ImageTransparentColor = System.Drawing.Color.Magenta; + this.toolStripButtonStart.Name = "toolStripButtonStart"; + this.toolStripButtonStart.Size = new System.Drawing.Size(24, 24); + this.toolStripButtonStart.Text = "Capture"; + this.toolStripButtonStart.ToolTipText = "Capture"; + this.toolStripButtonStart.Click += new System.EventHandler(this.toolStripButtonStart_Click); + // + // toolStripButtonClear + // + this.toolStripButtonClear.DisplayStyle = System.Windows.Forms.ToolStripItemDisplayStyle.Image; + this.toolStripButtonClear.Image = global::RPCMon.Properties.Resources.eraser; + this.toolStripButtonClear.ImageTransparentColor = System.Drawing.Color.Magenta; + this.toolStripButtonClear.Name = "toolStripButtonClear"; + this.toolStripButtonClear.Size = new System.Drawing.Size(24, 24); + this.toolStripButtonClear.Text = "Clear (Ctrl+X)"; + this.toolStripButtonClear.Click += new System.EventHandler(this.toolStripButtonClear_Click); + // + // toolStripButtonFilter + // + this.toolStripButtonFilter.DisplayStyle = System.Windows.Forms.ToolStripItemDisplayStyle.Image; + this.toolStripButtonFilter.Image = global::RPCMon.Properties.Resources.filter; + this.toolStripButtonFilter.ImageTransparentColor = System.Drawing.Color.Magenta; + this.toolStripButtonFilter.Name = "toolStripButtonFilter"; + this.toolStripButtonFilter.Size = new System.Drawing.Size(24, 24); + this.toolStripButtonFilter.Text = "Filter (Ctrl+L)"; + this.toolStripButtonFilter.ToolTipText = "Filter (Ctrl+L)"; + this.toolStripButtonFilter.Click += new System.EventHandler(this.toolStripButtonFilter_Click); + // + // toolStripButtonFind + // + this.toolStripButtonFind.DisplayStyle = System.Windows.Forms.ToolStripItemDisplayStyle.Image; + this.toolStripButtonFind.Image = global::RPCMon.Properties.Resources.find; + this.toolStripButtonFind.ImageTransparentColor = System.Drawing.Color.Magenta; + this.toolStripButtonFind.Name = "toolStripButtonFind"; + this.toolStripButtonFind.Size = new System.Drawing.Size(24, 24); + this.toolStripButtonFind.Text = "Find (Ctrl+F)"; + this.toolStripButtonFind.Click += new System.EventHandler(this.toolStripButtonFind_Click); + // + // toolStripButtonHighlight + // + this.toolStripButtonHighlight.DisplayStyle = System.Windows.Forms.ToolStripItemDisplayStyle.Image; + this.toolStripButtonHighlight.Image = global::RPCMon.Properties.Resources.highlighter; + this.toolStripButtonHighlight.ImageTransparentColor = System.Drawing.Color.Magenta; + this.toolStripButtonHighlight.Name = "toolStripButtonHighlight"; + this.toolStripButtonHighlight.Size = new System.Drawing.Size(24, 24); + this.toolStripButtonHighlight.Text = "HighLight (Ctrl+H)"; + this.toolStripButtonHighlight.Click += new System.EventHandler(this.toolStripButtonHighlight_Click); + // + // toolStripButtonGrid + // + this.toolStripButtonGrid.DisplayStyle = System.Windows.Forms.ToolStripItemDisplayStyle.Image; + this.toolStripButtonGrid.Image = global::RPCMon.Properties.Resources.grid_disable; + this.toolStripButtonGrid.ImageTransparentColor = System.Drawing.Color.Magenta; + this.toolStripButtonGrid.Name = "toolStripButtonGrid"; + this.toolStripButtonGrid.Size = new System.Drawing.Size(24, 24); + this.toolStripButtonGrid.Text = "Show Grid"; + this.toolStripButtonGrid.Click += new System.EventHandler(this.toolStripButtonGrid_Click); + // + // toolStripButtonRemoveDuplicate + // + this.toolStripButtonRemoveDuplicate.DisplayStyle = System.Windows.Forms.ToolStripItemDisplayStyle.Image; + this.toolStripButtonRemoveDuplicate.Image = global::RPCMon.Properties.Resources.duplicate_disable; + this.toolStripButtonRemoveDuplicate.ImageTransparentColor = System.Drawing.Color.Magenta; + this.toolStripButtonRemoveDuplicate.Name = "toolStripButtonRemoveDuplicate"; + this.toolStripButtonRemoveDuplicate.Size = new System.Drawing.Size(24, 24); + this.toolStripButtonRemoveDuplicate.Text = "Remove Duplicate Rows"; + this.toolStripButtonRemoveDuplicate.Click += new System.EventHandler(this.toolStripButtonRemoveDuplicate_Click); + // + // dataGridView1 + // + this.dataGridView1.AllowUserToAddRows = false; + this.dataGridView1.Anchor = ((System.Windows.Forms.AnchorStyles)((((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Bottom) + | System.Windows.Forms.AnchorStyles.Left) + | System.Windows.Forms.AnchorStyles.Right))); + this.dataGridView1.AutoSizeColumnsMode = System.Windows.Forms.DataGridViewAutoSizeColumnsMode.Fill; + this.dataGridView1.ColumnHeadersHeightSizeMode = System.Windows.Forms.DataGridViewColumnHeadersHeightSizeMode.AutoSize; + this.dataGridView1.Columns.AddRange(new System.Windows.Forms.DataGridViewColumn[] { + this.ColumnPID, + this.ColumnTID, + this.ColumnProcessName, + this.ColumnUUID, + this.ColumnModule, + this.ColumnModulePath, + this.ColumnProceduresCount, + this.ColumnService, + this.ColumnFunction, + this.ColumnNetworkAddress, + this.ColumnProtocol, + this.ColumnEndpoint, + this.ColumnOptions, + this.ColumnAuthenticationLevel, + this.ColumnAuthenticationService, + this.ColumnImpersonationLevel}); + this.dataGridView1.Location = new System.Drawing.Point(0, 51); + this.dataGridView1.Name = "dataGridView1"; + this.dataGridView1.ReadOnly = true; + this.dataGridView1.Size = new System.Drawing.Size(828, 486); + this.dataGridView1.TabIndex = 3; + this.dataGridView1.CellMouseClick += new System.Windows.Forms.DataGridViewCellMouseEventHandler(this.dataGridView1_CellMouseClick); + this.dataGridView1.ColumnHeaderMouseClick += new System.Windows.Forms.DataGridViewCellMouseEventHandler(this.dataGridView1_ColumnHeaderMouseClick); + // + // ColumnPID + // + this.ColumnPID.HeaderText = "PID"; + this.ColumnPID.Name = "ColumnPID"; + this.ColumnPID.ReadOnly = true; + // + // ColumnTID + // + this.ColumnTID.HeaderText = "TID"; + this.ColumnTID.Name = "ColumnTID"; + this.ColumnTID.ReadOnly = true; + // + // ColumnProcessName + // + this.ColumnProcessName.HeaderText = "ProcessName"; + this.ColumnProcessName.Name = "ColumnProcessName"; + this.ColumnProcessName.ReadOnly = true; + // + // ColumnUUID + // + this.ColumnUUID.HeaderText = "UUID"; + this.ColumnUUID.Name = "ColumnUUID"; + this.ColumnUUID.ReadOnly = true; + // + // ColumnModule + // + this.ColumnModule.HeaderText = "Module"; + this.ColumnModule.Name = "ColumnModule"; + this.ColumnModule.ReadOnly = true; + // + // ColumnModulePath + // + this.ColumnModulePath.HeaderText = "ModulePath"; + this.ColumnModulePath.Name = "ColumnModulePath"; + this.ColumnModulePath.ReadOnly = true; + this.ColumnModulePath.Visible = false; + // + // ColumnProceduresCount + // + this.ColumnProceduresCount.HeaderText = "ProceduresCount"; + this.ColumnProceduresCount.Name = "ColumnProceduresCount"; + this.ColumnProceduresCount.ReadOnly = true; + this.ColumnProceduresCount.Visible = false; + // + // ColumnService + // + this.ColumnService.HeaderText = "Service"; + this.ColumnService.Name = "ColumnService"; + this.ColumnService.ReadOnly = true; + // + // ColumnFunction + // + this.ColumnFunction.HeaderText = "Function"; + this.ColumnFunction.Name = "ColumnFunction"; + this.ColumnFunction.ReadOnly = true; + // + // ColumnNetworkAddress + // + this.ColumnNetworkAddress.HeaderText = "NetworkAddress"; + this.ColumnNetworkAddress.Name = "ColumnNetworkAddress"; + this.ColumnNetworkAddress.ReadOnly = true; + this.ColumnNetworkAddress.Visible = false; + // + // ColumnProtocol + // + this.ColumnProtocol.HeaderText = "Protocol"; + this.ColumnProtocol.Name = "ColumnProtocol"; + this.ColumnProtocol.ReadOnly = true; + // + // ColumnEndpoint + // + this.ColumnEndpoint.HeaderText = "Endpoint"; + this.ColumnEndpoint.Name = "ColumnEndpoint"; + this.ColumnEndpoint.ReadOnly = true; + // + // ColumnOptions + // + this.ColumnOptions.HeaderText = "Options"; + this.ColumnOptions.Name = "ColumnOptions"; + this.ColumnOptions.ReadOnly = true; + this.ColumnOptions.Visible = false; + // + // ColumnAuthenticationLevel + // + this.ColumnAuthenticationLevel.HeaderText = "AuthenticationLevel"; + this.ColumnAuthenticationLevel.Name = "ColumnAuthenticationLevel"; + this.ColumnAuthenticationLevel.ReadOnly = true; + this.ColumnAuthenticationLevel.Visible = false; + // + // ColumnAuthenticationService + // + this.ColumnAuthenticationService.HeaderText = "AuthenticationService"; + this.ColumnAuthenticationService.Name = "ColumnAuthenticationService"; + this.ColumnAuthenticationService.ReadOnly = true; + this.ColumnAuthenticationService.Visible = false; + // + // ColumnImpersonationLevel + // + this.ColumnImpersonationLevel.HeaderText = "ImpersonationLevel"; + this.ColumnImpersonationLevel.Name = "ColumnImpersonationLevel"; + this.ColumnImpersonationLevel.ReadOnly = true; + // + // statusStrip1 + // + this.statusStrip1.Items.AddRange(new System.Windows.Forms.ToolStripItem[] { + this.toolStripStatusLabelTotalEvents, + this.toolStripStatusLabelDBPath}); + this.statusStrip1.Location = new System.Drawing.Point(0, 538); + this.statusStrip1.Name = "statusStrip1"; + this.statusStrip1.Size = new System.Drawing.Size(828, 24); + this.statusStrip1.TabIndex = 4; + this.statusStrip1.Text = "statusStrip1"; + // + // toolStripStatusLabelTotalEvents + // + this.toolStripStatusLabelTotalEvents.BorderSides = System.Windows.Forms.ToolStripStatusLabelBorderSides.Right; + this.toolStripStatusLabelTotalEvents.Name = "toolStripStatusLabelTotalEvents"; + this.toolStripStatusLabelTotalEvents.Size = new System.Drawing.Size(85, 19); + this.toolStripStatusLabelTotalEvents.Text = "Total events: 0"; + // + // toolStripStatusLabelDBPath + // + this.toolStripStatusLabelDBPath.Name = "toolStripStatusLabelDBPath"; + this.toolStripStatusLabelDBPath.Size = new System.Drawing.Size(49, 19); + this.toolStripStatusLabelDBPath.Text = "DB File: "; + this.toolStripStatusLabelDBPath.MouseLeave += new System.EventHandler(this.toolStripStatusLabelDBPath_MouseLeave); + this.toolStripStatusLabelDBPath.MouseHover += new System.EventHandler(this.toolStripStatusLabelDBPath_MouseHover); + // + // contextMenuStripRightClickGridView + // + this.contextMenuStripRightClickGridView.Items.AddRange(new System.Windows.Forms.ToolStripItem[] { + this.copyRowToolStripMenuItem, + this.copyCellToolStripMenuItem}); + this.contextMenuStripRightClickGridView.Name = "contextMenuStripRightClickGridView"; + this.contextMenuStripRightClickGridView.Size = new System.Drawing.Size(129, 48); + // + // copyRowToolStripMenuItem + // + this.copyRowToolStripMenuItem.Name = "copyRowToolStripMenuItem"; + this.copyRowToolStripMenuItem.Size = new System.Drawing.Size(128, 22); + this.copyRowToolStripMenuItem.Text = "Copy Row"; + this.copyRowToolStripMenuItem.Click += new System.EventHandler(this.copyRowToolStripMenuItem_Click); + // + // copyCellToolStripMenuItem + // + this.copyCellToolStripMenuItem.Name = "copyCellToolStripMenuItem"; + this.copyCellToolStripMenuItem.Size = new System.Drawing.Size(128, 22); + this.copyCellToolStripMenuItem.Text = "Copy Cell"; + this.copyCellToolStripMenuItem.Click += new System.EventHandler(this.copyCellToolStripMenuItem_Click); + // + // Form1 + // + this.AutoScaleDimensions = new System.Drawing.SizeF(6F, 13F); + this.AutoScaleMode = System.Windows.Forms.AutoScaleMode.Font; + this.ClientSize = new System.Drawing.Size(828, 562); + this.Controls.Add(this.statusStrip1); + this.Controls.Add(this.dataGridView1); + this.Controls.Add(this.toolStrip1); + this.Controls.Add(this.menuStrip1); + this.Icon = ((System.Drawing.Icon)(resources.GetObject("$this.Icon"))); + this.MainMenuStrip = this.menuStrip1; + this.Name = "Form1"; + this.Text = "RPCMon - RPC Monitor Based Windows Events"; + this.Shown += new System.EventHandler(this.Form1_Shown); + this.menuStrip1.ResumeLayout(false); + this.menuStrip1.PerformLayout(); + this.toolStrip1.ResumeLayout(false); + this.toolStrip1.PerformLayout(); + ((System.ComponentModel.ISupportInitialize)(this.dataGridView1)).EndInit(); + this.statusStrip1.ResumeLayout(false); + this.statusStrip1.PerformLayout(); + this.contextMenuStripRightClickGridView.ResumeLayout(false); + this.ResumeLayout(false); + this.PerformLayout(); + + } + + #endregion + + private System.Windows.Forms.MenuStrip menuStrip1; + private System.Windows.Forms.ToolStripMenuItem fileToolStripMenuItem; + private System.Windows.Forms.ToolStripMenuItem helpToolStripMenuItem; + private System.Windows.Forms.ToolStrip toolStrip1; + private System.Windows.Forms.ToolStripButton toolStripButtonStart; + private System.Windows.Forms.ToolStripButton toolStripButtonFilter; + private System.Windows.Forms.DataGridView dataGridView1; + private System.Windows.Forms.ToolStripMenuItem aboutToolStripMenuItem; + private System.Windows.Forms.ToolStripButton toolStripButtonClear; + private System.Windows.Forms.ToolStripButton toolStripButtonFind; + private System.Windows.Forms.StatusStrip statusStrip1; + private System.Windows.Forms.ToolStripStatusLabel toolStripStatusLabelTotalEvents; + private System.Windows.Forms.ToolStripStatusLabel toolStripStatusLabelDBPath; + private System.Windows.Forms.ToolStripButton toolStripButtonHighlight; + private System.Windows.Forms.ToolStripMenuItem saveToolStripMenuItem; + private System.Windows.Forms.ToolTip toolTipDBPath; + private System.Windows.Forms.ToolStripMenuItem dBToolStripMenuItem; + private System.Windows.Forms.ToolStripMenuItem loadDBToolStripMenuItemLoadDB; + private System.Windows.Forms.ContextMenuStrip contextMenuStripRightClickGridView; + private System.Windows.Forms.ToolStripMenuItem copyRowToolStripMenuItem; + private System.Windows.Forms.ToolStripMenuItem copyCellToolStripMenuItem; + private System.Windows.Forms.ToolStripMenuItem buildDBToolStripMenuItem; + private System.Windows.Forms.ToolStripButton toolStripButtonGrid; + private System.Windows.Forms.ToolStripButton toolStripButtonRemoveDuplicate; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnPID; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnTID; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnProcessName; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnUUID; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnModule; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnModulePath; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnProceduresCount; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnService; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnFunction; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnNetworkAddress; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnProtocol; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnEndpoint; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnOptions; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnAuthenticationLevel; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnAuthenticationService; + private System.Windows.Forms.DataGridViewTextBoxColumn ColumnImpersonationLevel; + private System.Windows.Forms.ToolStripMenuItem optionsToolStripMenuItem; + private System.Windows.Forms.ToolStripMenuItem setDbgHelpFilePathToolStripMenuItem; + } +} + diff --git a/RPCMon/Form1.cs b/RPCMon/Form1.cs new file mode 100644 index 0000000..de695af --- /dev/null +++ b/RPCMon/Form1.cs @@ -0,0 +1,1032 @@ +using System; +using System.Collections.Generic; +using System.ComponentModel; +using System.Data; +using System.Diagnostics; +using System.Drawing; +using System.IO; +using System.Linq; +using System.Text; +using System.Threading; +using System.Threading.Tasks; +using System.Windows.Forms; +using Microsoft.Diagnostics.Tracing.Parsers; +using Microsoft.Diagnostics.Tracing.Session; +using Newtonsoft.Json; +using Microsoft.Diagnostics.Tracing.Parsers.MicrosoftWindowsRPC; +using RPCMon.Control; +using System.Reflection; + +namespace RPCMon +{ + public partial class Form1 : Form + { + TraceEventSession m_TraceSession; + private static Dictionary m_ProcessPIDsDictionary = new Dictionary(); + private string m_RPCDBPath = ""; + private static Dictionary> m_RPCDB; + private bool m_IsCaptureButtonPressed = false; + private Thread m_CaptureThread; + private int m_TotalNumberOfEvents = 0; + private const string RPC_DB_KEY_Module = "Module"; + private const string RPC_DB_KEY_ModulePath = "ModulePath"; + private const string RPC_DB_KEY_ProceduresCount = "ProceduresCount"; + private const string RPC_DB_KEY_Service = "Service"; + private const string RPC_DB_KEY_Procedures = "Procedures"; + private const string NA_STRING = "N\\A"; + private string m_LastSearchValue; + private ListView m_LastListViewColumnFilter = new ListView(); + private ListView m_LastListViewHighlighFilter = new ListView(); + int m_CurrentRowIndexRightClick, m_CurrentColumnIndexRightClick; + + public Form1() + { + InitializeComponent(); + + this.m_RPCDBPath = getDBFromCurrentFolder(); + this.toolStripStatusLabelDBPath.Text = "DB File: " + Path.GetFileName(this.m_RPCDBPath); + Process[] processCollection = Process.GetProcesses(); + foreach (Process p in processCollection) + { + m_ProcessPIDsDictionary.Add(p.Id, p.ProcessName); + } + + + //Thread t1 = new Thread(checkIdDBGHelpExist); + //t1.Start(); + + //dummRowsForDebug(); + //DataGridViewRow row = new DataGridViewRow(); + //DataGridViewCellCollection cells = new DataGridViewCellCollection(row); + //dataGridView1.Rows.Add(cells); + //dataGridView1.Rows[0].Cells[0].Value = ""; + + //https://10tec.com/articles/why-datagridview-slow.aspx + //if (!System.Windows.Forms.SystemInformation.TerminalServerSession) + //{ + // Type dgvType = dataGridView1.GetType(); + // PropertyInfo pi = dgvType.GetProperty("DoubleBuffered", + // BindingFlags.Instance | BindingFlags.NonPublic); + // pi.SetValue(dataGridView1, value, null); + //} + + // Remove grid from gridview + //this.dataGridView1.AdvancedCellBorderStyle.All = DataGridViewAdvancedCellBorderStyle.None; + + // https://stackoverflow.com/a/10277205/2153777 + // For better performance when scrolling the DataGridView + + typeof(DataGridView).InvokeMember( + "DoubleBuffered", + BindingFlags.NonPublic | BindingFlags.Instance | BindingFlags.SetProperty, + null, + dataGridView1, + new object[] { true }); + } + + private void checkIdDBGHelpExist() + { + if (!File.Exists(Engine.DbgHelpFilePath)) + { + MessageBox.Show("Can't find DbgHelp file: " + Engine.DbgHelpFilePath + ".\nGo to \"Option | Set DbgHelp File Path\" and set it.", "DbgHelp File Path"); + } + } + + private string getDBFromCurrentFolder() + { + string dbFile = "** No DataBase File ! **"; + string currentFolder = Directory.GetCurrentDirectory(); + string[] files = Directory.GetFiles(currentFolder); + foreach (string file in files) + { + if (file.EndsWith(".rpcdb.json")) + { + dbFile = file; + break; + } + } + + return dbFile; + } + + public static string getFunctionName(string uuid, int i_functionID) + { + try + { + var value = m_RPCDB[uuid][RPC_DB_KEY_Procedures]; + List list = value.ToObject>(); + return list[i_functionID]; + } + catch + { + return NA_STRING; + } + } + + private void dummRowsForDebug() + { + DataGridViewRow row = new DataGridViewRow(); + row.CreateCells(dataGridView1); + + row.Cells[(int)Utils.eColumnNames.PID].Value = "1234"; + row.Cells[(int)Utils.eColumnNames.TID].Value = "543"; + row.Cells[(int)Utils.eColumnNames.UUID].Value = ""; + row.Cells[(int)Utils.eColumnNames.Function].Value = "func1"; + row.Cells[(int)Utils.eColumnNames.ProcessName].Value = "Process1"; + row.Cells[(int)Utils.eColumnNames.NetworkAddress].Value = "n1"; + row.Cells[(int)Utils.eColumnNames.Protocol].Value = "protocol1"; + row.Cells[(int)Utils.eColumnNames.Endpoint].Value = "endpoint1"; + + row.Cells[(int)Utils.eColumnNames.Options].Value = "option1"; + row.Cells[(int)Utils.eColumnNames.AuthenticationLevel].Value = "auth1"; + row.Cells[(int)Utils.eColumnNames.AuthenticationService].Value = "authS1"; + row.Cells[(int)Utils.eColumnNames.ImpersonationLevel].Value = "imper1"; + row.DefaultCellStyle.Font = new Font(dataGridView1.DefaultCellStyle.Font, FontStyle.Regular); + dataGridView1.Rows.Add(row); + for (int i = 0; i < 16000; i++) + { + row = new DataGridViewRow(); + row.CreateCells(dataGridView1); + + row.Cells[(int)Utils.eColumnNames.PID].Value = "654"; + row.Cells[(int)Utils.eColumnNames.TID].Value = "222"; + row.Cells[(int)Utils.eColumnNames.UUID].Value = ""; + row.Cells[(int)Utils.eColumnNames.Function].Value = "func2"; + row.Cells[(int)Utils.eColumnNames.ProcessName].Value = "Process2"; + row.Cells[(int)Utils.eColumnNames.NetworkAddress].Value = "n2"; + row.Cells[(int)Utils.eColumnNames.Protocol].Value = "protocol2"; + row.Cells[(int)Utils.eColumnNames.Endpoint].Value = "endpoint2"; + + row.Cells[(int)Utils.eColumnNames.Options].Value = "option2"; + row.Cells[(int)Utils.eColumnNames.AuthenticationLevel].Value = "auth2"; + row.Cells[(int)Utils.eColumnNames.AuthenticationService].Value = "authS2"; + row.Cells[(int)Utils.eColumnNames.ImpersonationLevel].Value = "imper2"; + row.DefaultCellStyle.Font = new Font(dataGridView1.DefaultCellStyle.Font, FontStyle.Regular); + dataGridView1.Rows.Add(row); + + + } + } + + private void startEventTracing() + { + if (File.Exists(m_RPCDBPath)) + { + string jsonText = File.ReadAllText(m_RPCDBPath); + m_RPCDB = JsonConvert.DeserializeObject>>(jsonText); + } else + { + m_RPCDB = new Dictionary>(); + } + + using (var session = new TraceEventSession("MySimpleSession")) + { + + m_TraceSession = session; + + session.EnableProvider("Microsoft-Windows-RPC", Microsoft.Diagnostics.Tracing.TraceEventLevel.Verbose); + var parser = new MicrosoftWindowsRPCTraceEventParser(session.Source); + + // Do we want to include more events? server events? + + parser.RpcClientCallStart += e2 => + { + // addEventToListView(e2); + addEventToDataGridView(e2); + + /* + // Throws an error "Cross-thread operation not valid: Control 'textBox1' accessed from a thread other than the thread it was created on." + string funcName = getFunctionName(e2.InterfaceUuid.ToString(), e2.ProcNum); + ListViewItem item = new ListViewItem(e2.ProcessID.ToString()); + item.SubItems.Add(e2.ThreadID.ToString()); + item.SubItems.Add(e2.InterfaceUuid.ToString()); + item.SubItems.Add(funcName); + listView1.Items.Add(item);*/ + // Console.WriteLine($"{e2.ID} {funcName}"); + }; + session.Source.Process(); + } + } + + private void setRpcFields(ref DataGridViewRow i_Row, string i_UUID) + { + if (m_RPCDB.ContainsKey(i_UUID)) + { + i_Row.Cells[(int)Utils.eColumnNames.Module].Value = m_RPCDB[i_UUID][RPC_DB_KEY_Module]; + i_Row.Cells[(int)Utils.eColumnNames.ModulePath].Value = m_RPCDB[i_UUID][RPC_DB_KEY_ModulePath]; + i_Row.Cells[(int)Utils.eColumnNames.ProceduresCount].Value = m_RPCDB[i_UUID][RPC_DB_KEY_ProceduresCount]; + i_Row.Cells[(int)Utils.eColumnNames.Service].Value = m_RPCDB[i_UUID][RPC_DB_KEY_Service]; + } + else + { + i_Row.Cells[(int)Utils.eColumnNames.Module].Value = NA_STRING; + i_Row.Cells[(int)Utils.eColumnNames.ModulePath].Value = NA_STRING; + i_Row.Cells[(int)Utils.eColumnNames.ProceduresCount].Value = NA_STRING; + i_Row.Cells[(int)Utils.eColumnNames.Service].Value = NA_STRING; + } + } + + // https://docs.microsoft.com/en-us/dotnet/desktop/winforms/controls/how-to-make-thread-safe-calls?view=netdesktop-6.0 + private delegate void addEventToDataGridViewCallBack(Microsoft.Diagnostics.Tracing.Parsers.MicrosoftWindowsRPC.RpcClientCallStartArgs_V1TraceData i_Event); + private void addEventToDataGridView(Microsoft.Diagnostics.Tracing.Parsers.MicrosoftWindowsRPC.RpcClientCallStartArgs_V1TraceData i_Event) + { + if (this.InvokeRequired) + { + addEventToDataGridViewCallBack s = new addEventToDataGridViewCallBack(addEventToDataGridView); + this.Invoke(s, i_Event); + } + else + { + string funcName = getFunctionName(i_Event.InterfaceUuid.ToString(), i_Event.ProcNum); + + //DataGridViewRow row = (DataGridViewRow)dataGridView1.Rows[0].Clone(); + DataGridViewRow row = new DataGridViewRow(); + row.CreateCells(dataGridView1); + //dataGridView1.Rows.Add(cells); + //dataGridView1.Rows[0].Cells[0].Value = ""; + + row.Cells[(int)Utils.eColumnNames.PID].Value = i_Event.ProcessID.ToString(); + row.Cells[(int)Utils.eColumnNames.TID].Value = i_Event.ThreadID.ToString(); + setProcessName(i_Event, ref row); + + row.Cells[(int)Utils.eColumnNames.UUID].Value = i_Event.InterfaceUuid.ToString(); + if (i_Event.InterfaceUuid.ToString() != null && i_Event.InterfaceUuid.ToString() != "") + { + setRpcFields(ref row, i_Event.InterfaceUuid.ToString()); + } + + row.Cells[(int)Utils.eColumnNames.Function].Value = funcName; + + row.Cells[(int)Utils.eColumnNames.NetworkAddress].Value = i_Event.NetworkAddress.ToString(); + row.Cells[(int)Utils.eColumnNames.Protocol].Value = i_Event.Protocol.ToString(); + row.Cells[(int)Utils.eColumnNames.Endpoint].Value = i_Event.Endpoint.ToString(); + + row.Cells[(int)Utils.eColumnNames.Options].Value = i_Event.Options.ToString(); + row.Cells[(int)Utils.eColumnNames.AuthenticationLevel].Value = i_Event.AuthenticationLevel.ToString(); + row.Cells[(int)Utils.eColumnNames.AuthenticationService].Value = i_Event.AuthenticationService.ToString(); + row.Cells[(int)Utils.eColumnNames.ImpersonationLevel].Value = i_Event.ImpersonationLevel.ToString(); + row.DefaultCellStyle.Font = new Font(dataGridView1.DefaultCellStyle.Font, FontStyle.Regular); + dataGridView1.Rows.Add(row); + this.m_TotalNumberOfEvents += 1; + this.toolStripStatusLabelTotalEvents.Text = "Total events: " + this.m_TotalNumberOfEvents; + } + } + + private void setProcessName(Microsoft.Diagnostics.Tracing.Parsers.MicrosoftWindowsRPC.RpcClientCallStartArgs_V1TraceData i_Event, ref DataGridViewRow row) + { + if (i_Event.ProcessName == "") + { + if (m_ProcessPIDsDictionary.ContainsKey(i_Event.ProcessID)) + { + row.Cells[(int)Utils.eColumnNames.ProcessName].Value = m_ProcessPIDsDictionary[i_Event.ProcessID]; + } + else + { + try + { + using (var p = Process.GetProcessById(i_Event.ProcessID)) + { + row.Cells[(int)Utils.eColumnNames.ProcessName].Value = p.ProcessName; + m_ProcessPIDsDictionary.Add(p.Id, p.ProcessName); + } + } + catch + { + row.Cells[(int)Utils.eColumnNames.ProcessName].Value = "N\\A"; + m_ProcessPIDsDictionary.Add(i_Event.ProcessID, "N\\A"); + } + + } + + } + else + { + row.Cells[(int)Utils.eColumnNames.ProcessName].Value = i_Event.ProcessName; + } + } + + private void toolStripButtonStart_Click(object sender, EventArgs e) + { + if (!m_IsCaptureButtonPressed) + { + toolStripButtonStart.Image = global::RPCMon.Properties.Resources.pause_button; + m_IsCaptureButtonPressed = true; + + m_CaptureThread = new Thread(new ThreadStart(startEventTracing)); + + m_CaptureThread.Start(); + } + else + { + toolStripButtonStart.Image = global::RPCMon.Properties.Resources.startIcon; + m_IsCaptureButtonPressed = false; + m_TraceSession.Source.StopProcessing(); + m_TraceSession.Dispose(); + m_CaptureThread.Abort(); + } + + } + + /*private void toolStripButtonStop_Click(object sender, EventArgs e) + { + m_TraceSession.Source.StopProcessing(); + m_TraceSession.Dispose(); + + }*/ + + private void toolStripButtonFilter_Click(object sender, EventArgs e) + { + openColumnFilterWindow(); + } + + private void openColumnFilterWindow() + { + //ColumnFilter columnFilter = new ColumnFilter(listView1); + // ColumnFilter columnFilter = new ColumnFilter(ref dataGridView1); + ColumnFilter columnFilter = new ColumnFilter(ref m_LastListViewColumnFilter); + columnFilter.FilterOKUpdate += new FilterOKEventHandler(ColumnFilter_OKFilter); + columnFilter.ShowDialog(); + } + + private void openColumnSelectionWindow() + { + //ColumnFilter columnFilter = new ColumnFilter(listView1); + ColumnSelection columnSelection = new ColumnSelection(); + columnSelection.selectColumnsUpdate += new selectColumnsEventHandler(this.ColumnSelection_selectColumnsUpdate); + columnSelection.ShowDialog(); + } + + private void openFindWindow() + { + FormSearch findWindow = new FormSearch(); + findWindow.searchForMatch += new searchEventHandler(FindWindow_searchForMatch); + findWindow.ShowDialog(); + } + + private void openHighlightWindows() + { + FormHighlighting hightlightWindow = new FormHighlighting(ref m_LastListViewHighlighFilter); + hightlightWindow.hightlightRowsUpdate += HightlightWindow_hightlightRowsUpdate; + hightlightWindow.ShowDialog(); + } + + private void buildDBToolStripMenuItem_Click(object sender, EventArgs e) + { + FormBuildDB buildDBForm = new FormBuildDB(); + //hightlightWindow.hightlightRowsUpdate += HightlightWindow_hightlightRowsUpdate; + buildDBForm.ShowDialog(); + } + + private void HightlightWindow_hightlightRowsUpdate(ListView i_ListView) + { + filterRowsByFilterRules(i_ListView, Utils.eFormNames.FormHighlighFilter); + //int columnCounter = 0; + //foreach (DataGridViewRow row in this.dataGridView1.Rows) + //{ + // if (columnCounter != this.dataGridView1.Rows.Count - 1) + // { + // foreach (ListViewItem rule in i_ListView.Items) + // { + // if (rule.Checked) + // { + // DataGridViewCell cellValueFromGridViewCell = row.Cells["Column" + rule.SubItems[0].Text]; + // string valueFromFilter = rule.SubItems[(int)Utils.eFilterNames.Value].Text; + // if (rule.SubItems[(int)Utils.eFilterNames.Relation].Text == "contains") + // { + + // if ((cellValueFromGridViewCell.Value.ToString()).Contains(valueFromFilter)) + // { + // if (rule.SubItems[(int)Utils.eFilterNames.Action].Text == "Include") + // { + // this.dataGridView1.Rows[row.Index].DefaultCellStyle.BackColor = Color.Cyan; + // } + // else + // { + // this.dataGridView1.Rows[row.Index].DefaultCellStyle.BackColor = Color.White; + + // } + // } + // else + // { + // this.dataGridView1.Rows[row.Index].DefaultCellStyle.BackColor = Color.White; + // } + + // } + + // } + // } + // } + + // columnCounter++; + //} + + //m_LastListViewHighlighFilter = i_ListView; + } + + private void cleanAllSelectedCells() + { + for (int i = 0; i < dataGridView1.SelectedCells.Count; i++) + { + dataGridView1.SelectedCells[i].Selected = false; + } + } + + + private void FindWindow_searchForMatch(string i_SearchString, bool i_SearchDown, bool i_MatchWholeWord, bool i_MatchSensitive) + { + int startIndex = 0; + m_LastSearchValue = i_SearchString; + bool foundMatch = false; + int step = 1; + if (!i_SearchDown) + { + step = -1; + } + + if (dataGridView1.SelectedRows != null && dataGridView1.SelectedRows.Count > 0) + { + DataGridViewRow selectedRow = dataGridView1.SelectedRows[0]; + startIndex = selectedRow.Index; + } + + if (dataGridView1.SelectedCells != null && dataGridView1.SelectedCells.Count > 0) + { + DataGridViewCell selectedCell = dataGridView1.SelectedCells[0]; + startIndex = selectedCell.RowIndex; + } + + startIndex += 1; + for (int i = startIndex; i < dataGridView1.Rows.Count; i+= step) + { + + if (step + i < 0) + { + break; + } + + foreach (DataGridViewCell cell in dataGridView1.Rows[i].Cells) + { + if (cell.Value != null && cell.Value.ToString().Contains(i_SearchString)) + { + cleanAllSelectedCells(); + dataGridView1.Rows[i].Selected = true; + foundMatch = true; + break; + } + } + + if (foundMatch) + { + break; + } + + } + + if (!foundMatch) + { + MessageBox.Show(string.Format("Cannot find string \"{0}\"", i_SearchString), "RPC Monitor", MessageBoxButtons.OK, MessageBoxIcon.Exclamation); + } + } + + private void modifyColumnSelection(DataGridViewColumn i_Column, GroupBox i_GroupBox) + { + foreach (CheckBox checkBox in i_GroupBox.Controls) + { + if (checkBox.Text == i_Column.HeaderText) + { + if (checkBox.Checked) + { + dataGridView1.Columns[i_Column.Index].Visible = true; + } + else + { + dataGridView1.Columns[i_Column.Index].Visible = false; + } + } + } + } + private void ColumnSelection_selectColumnsUpdate(GroupBox i_RPCClient, GroupBox i_RPCServer, GroupBox i_RPCMisc) + { + foreach (DataGridViewColumn column in dataGridView1.Columns) + { + modifyColumnSelection(column, i_RPCClient); + modifyColumnSelection(column, i_RPCServer); + modifyColumnSelection(column, i_RPCMisc); + } + } + + private Color getHighlighColorIfRequired(string i_Action) + { + Color resultColor = Color.White; + if (i_Action == "Include") + { + resultColor = Color.Cyan; + } + + return resultColor; + } + + private void filterRowBasedOnForm(Utils.eFormNames i_FormName, int i_RowIndex, string i_Action) + { + if (i_FormName == Utils.eFormNames.FormColumnFilter) + { + this.dataGridView1.Rows[i_RowIndex].Visible = (i_Action == "Include"); + } + else + { + this.dataGridView1.Rows[i_RowIndex].DefaultCellStyle.BackColor = getHighlighColorIfRequired(i_Action); + } + } + + private void hideFilterRowBasedOnForm(Utils.eFormNames i_FormName, int i_RowIndex) + { + if (i_FormName == Utils.eFormNames.FormColumnFilter) + { + this.dataGridView1.Rows[i_RowIndex].Visible = false; + } + else + { + this.dataGridView1.Rows[i_RowIndex].DefaultCellStyle.BackColor = Color.White; + } + } + + private void filterRowsByFilterRules(ListView i_ListView, Utils.eFormNames i_FormName) + { + // TODO: What happens if one row is alrady Filtered\Highlight? It will hide it. Need to fix it + // so there will be OR between the rules + int rowCounter = 0; + foreach (DataGridViewRow row in this.dataGridView1.Rows) + { + if (rowCounter <= this.dataGridView1.Rows.Count - 1) + { + foreach (ListViewItem rule in i_ListView.Items) + { + if (rule.Checked) + { + DataGridViewCell cellValueFromGridViewCell = row.Cells["Column" + rule.SubItems[0].Text]; + string valueFromFilter = rule.SubItems[(int)Utils.eFilterNames.Value].Text; + if (rule.SubItems[(int)Utils.eFilterNames.Relation].Text == "contains") + { + if ((cellValueFromGridViewCell.Value.ToString()).Contains(valueFromFilter)) + { + + filterRowBasedOnForm(i_FormName, row.Index, rule.SubItems[(int)Utils.eFilterNames.Action].Text); + + //if (i_FormName == Utils.eFormNames.FormColumnFilter) + //{ + // this.dataGridView1.Rows[row.Index].Visible = (rule.SubItems[(int)Utils.eFilterNames.Action].Text == "Include"); + + //} else + //{ + // this.dataGridView1.Rows[row.Index].DefaultCellStyle.BackColor = getHighlighColorIfRequired(rule.SubItems[(int)Utils.eFilterNames.Action].Text); + //} + } + else + { + + hideFilterRowBasedOnForm(i_FormName, row.Index); + //if (i_FormName == Utils.eFormNames.FormColumnFilter) + //{ + // this.dataGridView1.Rows[row.Index].Visible = false; + //} + //else + //{ + // this.dataGridView1.Rows[row.Index].DefaultCellStyle.BackColor = Color.White; + //} + } + + } + else if (rule.SubItems[(int)Utils.eFilterNames.Relation].Text == "is") + { + if (cellValueFromGridViewCell.Value.ToString() == valueFromFilter) + { + filterRowBasedOnForm(i_FormName, row.Index, rule.SubItems[(int)Utils.eFilterNames.Action].Text); + // this.dataGridView1.Rows[row.Index].Visible = (rule.SubItems[(int)Utils.eFilterNames.Action].Text == "Include"); + } + else + { + hideFilterRowBasedOnForm(i_FormName, row.Index); + //this.dataGridView1.Rows[row.Index].Visible = false; + } + } + else if (rule.SubItems[(int)Utils.eFilterNames.Relation].Text == "begins with") + { + + if (cellValueFromGridViewCell.Value.ToString().StartsWith(valueFromFilter)) + { + filterRowBasedOnForm(i_FormName, row.Index, rule.SubItems[(int)Utils.eFilterNames.Action].Text); + //this.dataGridView1.Rows[row.Index].Visible = (rule.SubItems[(int)Utils.eFilterNames.Action].Text == "Include"); + } + else + { + hideFilterRowBasedOnForm(i_FormName, row.Index); + //this.dataGridView1.Rows[row.Index].Visible = false; + } + } + else if (rule.SubItems[(int)Utils.eFilterNames.Relation].Text == "ends with") + { + + if (cellValueFromGridViewCell.Value.ToString().EndsWith(valueFromFilter)) + { + filterRowBasedOnForm(i_FormName, row.Index, rule.SubItems[(int)Utils.eFilterNames.Action].Text); + //this.dataGridView1.Rows[row.Index].Visible = (rule.SubItems[(int)Utils.eFilterNames.Action].Text == "Include"); + } + else + { + hideFilterRowBasedOnForm(i_FormName, row.Index); + //this.dataGridView1.Rows[row.Index].Visible = false; + } + } + + } + } + } + + rowCounter++; + } + + if (i_FormName == Utils.eFormNames.FormColumnFilter) + { + m_LastListViewColumnFilter = i_ListView; + } else + { + m_LastListViewHighlighFilter = i_ListView; + } + } + + private void ColumnFilter_OKFilter(ListView i_ListView) + { + + filterRowsByFilterRules(i_ListView, Utils.eFormNames.FormColumnFilter); + //int rowCounter = 0; + //bool shouldInclude = false; + //foreach (DataGridViewRow row in this.dataGridView1.Rows) + //{ + // if (rowCounter <= this.dataGridView1.Rows.Count - 1) + // { + // foreach (ListViewItem rule in i_ListView.Items) + // { + // if (rule.Checked) + // { + // DataGridViewCell cellValueFromGridViewCell = row.Cells["Column" + rule.SubItems[0].Text]; + // string valueFromFilter = rule.SubItems[(int)Utils.eFilterNames.Value].Text; + // if (rule.SubItems[(int)Utils.eFilterNames.Relation].Text == "contains") + // { + // if ((cellValueFromGridViewCell.Value.ToString()).Contains(valueFromFilter)) + // { + // this.dataGridView1.Rows[row.Index].Visible = (rule.SubItems[(int)Utils.eFilterNames.Action].Text == "Include"); + // } + // else + // { + // this.dataGridView1.Rows[row.Index].Visible = false; + // } + + // } else if (rule.SubItems[(int)Utils.eFilterNames.Relation].Text == "is") + // { + // if (cellValueFromGridViewCell.Value.ToString() == valueFromFilter) + // { + // this.dataGridView1.Rows[row.Index].Visible = (rule.SubItems[(int)Utils.eFilterNames.Action].Text == "Include"); + // } + // else + // { + // this.dataGridView1.Rows[row.Index].Visible = false; + // } + // } else if (rule.SubItems[(int)Utils.eFilterNames.Relation].Text == "begins with") { + + // if (cellValueFromGridViewCell.Value.ToString().StartsWith(valueFromFilter)) + // { + // this.dataGridView1.Rows[row.Index].Visible = (rule.SubItems[(int)Utils.eFilterNames.Action].Text == "Include"); + // } + // else + // { + // this.dataGridView1.Rows[row.Index].Visible = false; + // } + // } + // else if (rule.SubItems[(int)Utils.eFilterNames.Relation].Text == "ends with") + // { + + // if (cellValueFromGridViewCell.Value.ToString().EndsWith(valueFromFilter)) + // { + // this.dataGridView1.Rows[row.Index].Visible = (rule.SubItems[(int)Utils.eFilterNames.Action].Text == "Include"); + // } + // else + // { + // this.dataGridView1.Rows[row.Index].Visible = false; + // } + // } + + // } + // } + // } + + // rowCounter++; + //} + + //m_LastListViewColumnFilter = i_ListView; + } + + protected override bool ProcessCmdKey(ref Message msg, Keys keyData) + { + bool result = false; + + if (keyData == (Keys.Control | Keys.L)) + { + openColumnFilterWindow(); + result = true; + } else if (keyData == (Keys.Control | Keys.B)) + { + Font boldFont = new Font(dataGridView1.DefaultCellStyle.Font, FontStyle.Bold); + Font font = new Font(dataGridView1.DefaultCellStyle.Font, FontStyle.Regular); + + foreach (DataGridViewCell cell in dataGridView1.SelectedCells) + { + + if (!dataGridView1.Rows[cell.RowIndex].DefaultCellStyle.Font.Bold) + { + font = boldFont; + } + + dataGridView1.Rows[cell.RowIndex].DefaultCellStyle.Font = font; + } + + foreach (DataGridViewRow selectedRow in dataGridView1.SelectedRows) + { + + if (!selectedRow.DefaultCellStyle.Font.Bold) + { + font = boldFont; + } + + dataGridView1.Rows[selectedRow.Index].DefaultCellStyle.Font = font; + + } + result = true; + } else if (keyData == (Keys.Control | Keys.F)) + { + openFindWindow(); + result = true; + } else if (keyData == (Keys.Control | Keys.H)) + { + openHighlightWindows(); + result = true; + } + else if (keyData == (Keys.F3)) + { + // We need to implement the options for the search + FindWindow_searchForMatch(m_LastSearchValue, true, false, false); + } else if (keyData == (Keys.Shift | Keys.F3)) + { + // We need to implement the options for the search + FindWindow_searchForMatch(m_LastSearchValue, false, false, false); + } + + return result; + } + + private void dataGridView1_ColumnHeaderMouseClick(object sender, DataGridViewCellMouseEventArgs e) + { + if (e.Button == System.Windows.Forms.MouseButtons.Right) { + openColumnSelectionWindow(); + } + } + + /// + /// Right Click On Data Grid View + /// + /// + /// + private void dataGridView1_CellMouseClick(object sender, DataGridViewCellMouseEventArgs e) + { + if (e.Button == System.Windows.Forms.MouseButtons.Right) + { + m_CurrentRowIndexRightClick = e.RowIndex; + m_CurrentColumnIndexRightClick = e.ColumnIndex; + contextMenuStripRightClickGridView.Show(Cursor.Position.X, Cursor.Position.Y); + } + } + + private void copyRowToolStripMenuItem_Click(object sender, EventArgs e) + { + string copiedRow = ""; + + foreach (DataGridViewCell cell in dataGridView1.Rows[m_CurrentRowIndexRightClick].Cells) + { + copiedRow += cell.Value + " "; + } + + if (copiedRow != "") + { + System.Windows.Forms.Clipboard.SetText(copiedRow); + } + } + + private void copyCellToolStripMenuItem_Click(object sender, EventArgs e) + { + string copiedCell = ""; + if (dataGridView1.Rows[m_CurrentRowIndexRightClick] != null) + { + if (dataGridView1.Rows[m_CurrentRowIndexRightClick].Cells[m_CurrentColumnIndexRightClick].Value != null) + { + copiedCell = dataGridView1.Rows[m_CurrentRowIndexRightClick].Cells[m_CurrentColumnIndexRightClick].Value.ToString(); + } + } + + if (copiedCell != "") + { + System.Windows.Forms.Clipboard.SetText(copiedCell); + } + } + + private void toolStripButtonClear_Click(object sender, EventArgs e) + { + dataGridView1.Rows.Clear(); + dataGridView1.Refresh(); + } + + private void aboutToolStripMenuItem_Click(object sender, EventArgs e) + { + MessageBox.Show("Authors: Eviatar Gerzi (@g3rzi) and Yaniv Yakobovich\nVersion: 1.0\n\nCopyright (c) 2022 CyberArk Software Ltd. All rights reserved", "About"); + } + + private void toolStripButtonFind_Click(object sender, EventArgs e) + { + openFindWindow(); + } + + private void toolStripButtonHighlight_Click(object sender, EventArgs e) + { + openHighlightWindows(); + } + + // Taken from https://stackoverflow.com/a/26259909/2153777 + private void saveDataGridViewToCSV(string filename) + { + DataGridView tempDataGridView = dataGridView1; + foreach (DataGridViewColumn column in tempDataGridView.Columns) + { + tempDataGridView.Columns[column.Index].Visible = true; + } + // Choose whether to write header. Use EnableWithoutHeaderText instead to omit header. + tempDataGridView.ClipboardCopyMode = DataGridViewClipboardCopyMode.EnableAlwaysIncludeHeaderText; + // Select all the cells + tempDataGridView.SelectAll(); + // Copy selected cells to DataObject + DataObject dataObject = tempDataGridView.GetClipboardContent(); + // Get the text of the DataObject, and serialize it to a file + File.WriteAllText(filename, dataObject.GetText(TextDataFormat.CommaSeparatedValue)); + } + + private void saveToolStripMenuItem_Click(object sender, EventArgs e) + { + SaveFileDialog saveDialog = new SaveFileDialog(); + saveDialog.Title = "Save results as CSV"; + saveDialog.InitialDirectory = @"c:\"; + saveDialog.Filter = "CSV files (*.csv)|*.csv|All files (*.*)|*.*"; + saveDialog.FilterIndex = 2; + saveDialog.RestoreDirectory = true; + if (saveDialog.ShowDialog() == DialogResult.OK) + { + saveDataGridViewToCSV(saveDialog.FileName); + } + } + + private void toolStripStatusLabelDBPath_MouseHover(object sender, EventArgs e) + { + toolTipDBPath.Show(this.m_RPCDBPath, + this.statusStrip1, + new Point(toolStripStatusLabelDBPath.Bounds.Left, + toolStripStatusLabelDBPath.Bounds.Top + 20)); + } + + private void toolStripStatusLabelDBPath_MouseLeave(object sender, EventArgs e) + { + toolTipDBPath.Hide(this.statusStrip1); + } + + private void loadDBToolStripMenuItemLoadDB_Click(object sender, EventArgs e) + { + OpenFileDialog loadDBDialog = new OpenFileDialog(); + loadDBDialog.Title = "Load RPC DataBase"; + loadDBDialog.InitialDirectory = @"c:\"; + loadDBDialog.Filter = "JSON files (*.json)|*.json|All files (*.*)|*.*"; + loadDBDialog.FilterIndex = 1; + loadDBDialog.RestoreDirectory = true; + if (loadDBDialog.ShowDialog() == DialogResult.OK) + { + this.m_RPCDBPath = loadDBDialog.FileName; + updateToolStripStatusLabelDBPath(loadDBDialog.FileName); + } + } + + private bool m_IsGridButtonPressed = false; + private void toolStripButtonGrid_Click(object sender, EventArgs e) + { + if (!m_IsGridButtonPressed) + { + toolStripButtonGrid.Image = global::RPCMon.Properties.Resources.grid; + m_IsGridButtonPressed = true; + this.dataGridView1.AdvancedCellBorderStyle.All = DataGridViewAdvancedCellBorderStyle.None; + + } + else + { + toolStripButtonGrid.Image = global::RPCMon.Properties.Resources.grid_disable; + m_IsGridButtonPressed = false; + this.dataGridView1.AdvancedCellBorderStyle.All = DataGridViewAdvancedCellBorderStyle.Single; + } + } + + private void hideOrShowAllRows(bool i_ShowAll) + { + foreach (DataGridViewRow row in dataGridView1.Rows) + { + if (i_ShowAll) + { + dataGridView1.Rows[row.Index].Visible = true; + } + else + { + dataGridView1.Rows[row.Index].Visible = false; + } + } + } + + private bool m_IsRemoveDuplicateButtonPressed = false; + private void toolStripButtonRemoveDuplicate_Click(object sender, EventArgs e) + { + if (!m_IsRemoveDuplicateButtonPressed) + { + toolStripButtonRemoveDuplicate.Image = global::RPCMon.Properties.Resources.duplicate; + m_IsRemoveDuplicateButtonPressed = true; + Dictionary dict = new Dictionary(); + string rawRow; + + foreach (DataGridViewRow row in dataGridView1.Rows) + { + rawRow = ""; + // Maybe can be reforma with the Copy function + foreach (DataGridViewCell cell in dataGridView1.Rows[row.Index].Cells) + { + rawRow += cell.Value + " "; + } + + if (!dict.ContainsKey(rawRow)) + { + dict.Add(rawRow, row.Index); + } + } + + hideOrShowAllRows(false); + foreach (int index in dict.Values) + { + dataGridView1.Rows[index].Visible = true; + } + + //https://stackoverflow.com/questions/28336370/how-to-remove-duplicate-row-from-datagridview-in-c + //DataTable items = new DataTable(); + //items.Columns.Add("PID"); + //items.Columns.Add("TID"); + //for (int i = 0; i < dataGridView1.Rows.Count; i++) + //{ + // DataRow rw = items.NewRow(); + // rw[0] = dataGridView1.Rows[i].Cells[0].Value.ToString(); + // rw[1] = dataGridView1.Rows[i].Cells[1].Value.ToString(); + // var a = rw["PID"]; + // if (!items.Rows.Cast().Any(row => row["PID"].Equals(rw["PID"]) && row["TID"].Equals(rw["TID"]))) + // items.Rows.Add(rw); + //} + //dataGridView1.DataSource = items; + } + else + { + toolStripButtonRemoveDuplicate.Image = global::RPCMon.Properties.Resources.duplicate_disable; + m_IsRemoveDuplicateButtonPressed = false; + hideOrShowAllRows(true); + } + } + + private void setDbgHelpFilePathToolStripMenuItem_Click(object sender, EventArgs e) + { + FileDialog fileDialog = new OpenFileDialog(); + fileDialog.Title = "Set DbgHelp File Path"; + fileDialog.InitialDirectory = @"c:\"; + fileDialog.Filter = "DLL files (*.dll)|*.dll|All files (*.*)|*.*"; + fileDialog.FilterIndex = 1; + fileDialog.RestoreDirectory = true; + if (fileDialog.ShowDialog() == DialogResult.OK) + { + Engine.DbgHelpFilePath = fileDialog.FileName; + } + } + + private void Form1_Shown(object sender, EventArgs e) + { + checkIdDBGHelpExist(); + } + + private void updateToolStripStatusLabelDBPath(string i_DBPath) + { + this.toolStripStatusLabelDBPath.Text = "DB File: " + Path.GetFileName(this.m_RPCDBPath); + } + } +} diff --git a/RPCMon/Form1.resx b/RPCMon/Form1.resx new file mode 100644 index 0000000..9feb3e3 --- /dev/null +++ b/RPCMon/Form1.resx @@ -0,0 +1,2132 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + text/microsoft-resx + + + 2.0 + + + System.Resources.ResXResourceReader, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + + System.Resources.ResXResourceWriter, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + + 17, 17 + + + 132, 17 + + + True + + + True + + + True + + + True + + + True + + + True + + + True + + + True + + + True + + + True + + + True + + + True + + + True + + + True + + + True + + + True + + + 237, 17 + + + 353, 17 + + + 483, 17 + + + 64 + + + + + AAABAAYAAAAAAAEAIABxQQAAZgAAAICAAAABACAAKAgBANdBAABAQAAAAQAgAChCAAD/SQEAMDAAAAEA + IACoJQAAJ4wBACAgAAABACAAqBAAAM+xAQAQEAAAAQAgAGgEAAB3wgEAiVBORw0KGgoAAAANSUhEUgAA + AQAAAAEACAYAAABccqhmAABBOElEQVR42u2deZgcVdW431tVvc7WM5nJvodAFkhCEkiALICAoJBMwgfE + FRQFXJBPRUVwQ1AQ9ef2KYIoYEQhCpmAsqgQSEIIgWxAQiCE7GSbpSeZ3rvr/v6onkz37Et3V8/MfZ+n + n0y6q6tOVdc5dc49554LCoVCoVAoFAqFQqFQKPoDwm4BFN1k2WFwuApA+hCiAhgFDAYGJF9lzf52AG7A + mfzblXwBRJKvGBAFwsm/a4Ga5Cv170PAHqQ8CsJPLBLgykF2XxFFN1AGIJ+p8gNoSFkCTEaIycCpWMo+ + CqgASgCvTRIGgXrgKLAn+XoLKbcixFaQ9QjNZGGJvddR0SbKAOQTVX4HMBKYDpwJTE6+RtD7fisJ7Ae2 + Jl/rkXIjQuyh0hezWziFRW+7qfoOK+pBSjcwDZgNnAXMBIZjuel9kSiWUdgArAXWIeUmNC2ivAR7UAYg + l1T5DWA8cB5wETAf8Nktls34gZeAfwMrgR1U+uJ2C9VfUAYgm6zwgym9CHE+8FHgfGAM1iCcoiUxYBfw + AvBPpFyJJoIs9NktV59FGYBssLyuFCHOAxYDl2CNwiu6Ti3wDPAEUq5kUWmd3QL1NZQByAQrJdTXe4CL + gSXAh7DSb4rMUQM8DzwKPEtJSYjz1O3bU9QV7AlVfg0ppyHEp4ArgaF2i9RPOAg8BixFE5tZUGLaLVBv + RRmArmLl5suwnvTXYI3iq5jeHmLAFqR8CHgUTdSo8YKuoQxAV6iqmwDiOizFL7VbHEUadcDDSHk/i0rf + tluY3oIyAB1RVWeAmAvciDWg57ZbpM6gi8aXQAOEsH5skfK3Ka1tG/3nhARTShLS+lvafRLdIww8C/wa + 5GoqS1VKsR2UAWiL5XUGQlQC38Cqyssbig3BYLdgmFtjuEcw0KUxyCUY5NIY6BIUG4ICA7y6oEC3/tUE + OARoQuDUrB8+alpKHklaglACgglJMCEJxOF4XFIdlRyJSA5HTA5HJAfDJvtCkkMRk+qoPGFE8pT1wE+R + sopFyhC0hjIAzanyO4FK4JtYJbm2XCOnBj6HYEKhzqQijclFOhOKNMYVaAxwCtyapch2kJAQTkiOxSV7 + QpLtxxNsO27ydkOCbcdMDkUsI5InSGATcA+wnEpf1G6B8gllABqx6vAXA7dgDezllEJDMLVYZ3apzsxS + neklOmMLNIxO/kIRE2qjJnUxaIhLjidfx+KS43FLaSOm9cQOm5ar79EFAnAn/y00oMiwPIgiQ1BoWEao + 1CEoNESnbhYJHApL3jyW4DV/glfrEmz0JzgQzouB+s3Az9DE31lQogwBygBAlV/HqtD7EVYtfk6uiVuD + 04p1LhxocF65wUyfTrHDitebk5AQSEgOhiU7Agl2ByS7gia7giZ7QyZHIpL6mCQmIWbKjMXvejJscGgC + rw4VLo1hbsFor8aY5GtsgfVvkdG2RxJKSLY3mLxUHeeF6gRrauLUxWzzEBo9gluR8r8sKk3YJUg+0L8N + QJX/NOBO4FIg6w61U4N5AwwWDnFwyUCDsQVaqz/AkYhky7EEr/sTbKlP8E6DyZ6gaafStItbF4z0CE4q + 0Di1yPJgTi/RGePV0Fs5wbqYZGV1nKqDcZ4+HKMmast5mcDTwHeo9G2x9wraR/80AFX+YcB3sNJ5WR3V + 14DxhRqfHOHkE8MdjPamK31cwqGwyeraBC8ejbO6Ns7uoCSckBkdhffoghEewSiPNYZgCKiPS/aHLG+i + PpbZ4zk0qHAKziw1OK9c5/xyg3EFGp5mFqE+JnnqUJw/7Y2ytjZOJPeRQgR4GLiDSt/+nB/dZvqXAbDi + /M8DP8BqppE1BNbT/qsnOblkoCPNPU5IeM2f4J+HYjx9OM7W4wmiWbjxvbpg8RCDywY7mFWqM9LbusdR + F5Nsqk/w36Nx/rIvxr5Q5oURwEivxvnlBgsGG5xfYVCcMsAhgTePJfjV+1Ee3R+zYxCxGrgdIe5jYUm/ + 6VfQPwzAP48L4okzgV9gzb3P2nkLYO4AgzsnujinzEBLHikh4e3jCf68L8ayAzH2hc2spdAKDcGXxzj5 + 0hgnwzwa4YRkR8BkTU2C9wJW+i5mSkqdguFujbPKdKaW6JQ6BKGEZNmBGD/eEWFHQ3YexwIodgg+PNDg + MyOdzB+gp3kGe0Mmd70b4eF9MUK5NQQSK3V4E5q2ngXF+RlzZZC+bwCsmXnfB26gqQdeVhjl0bhrkpsr + hjlOjN5HTXjiYIzf7YqyrjZOtsP4M0t17pvqYVqJzv6Qye93R3lkf4w9QbNdF7/UIbhooMFXxro4u0yn + Lib59rYwD+yJkm0dHFegcc1IJ9eNcjLQ1XRLbqpP8M2tYf57NOcp/AjweyS3s8jXp2cg9l0D8ES9QJMX + A7/HarOVNTQBi4Y4uHeKh4rkDRxMSB7aG+P/7YzwfsDMSVXdkmEOHjzdi0Tys/ei3L0j0mVXWhPw0UEG + vznNw0ivxgN7onzpjRCxHMTmxYbg6pEOvnGSixEeK2aKS/jlzgg/2B4hkPuwYC9wA6Z4lsUlfdIb6JsG + oMpfCNwNXEeWJ+oI4EcT3XxjvAtDWD7kc0fifHtbmM31ucswXT7UwdLpHo7H4fL1QdbUtnxqji/QmDPA + YKTHyunvC0teromzvRVXf6BL8OhML+eWG9y3O8qNb4SI50gFBjgF3zjJxU3jXLiTYyera+IsXh+kOvcZ + gxjwAEJ8k4UlDbk+eLbpWwZghR8kc4H7gInZPpxDwM9P9fDlsU4E4I9JbtkW5g97ojktkT21WGfNnALC + JlzySoBNzQzPOWU6d0x0M2+A0SItl5CwpjbO97dHeKk63WgUG4InzvTyoQqDr70V5hc7I7k7KWCmT+eP + p3uYUqwDVkhw2bqgXUVF7wDXI+VLLOo788D6jgFYUe9EytuAb5HlWL+R2052ccdEt/U0DZkseDWY06c+ + WD/gM2cVcEGFwWWvBnjmcDztsy+NcXLPZDdOTbD8YIwnD8V4p8EKSU4u0LhssIPLhzpISPjO22F+/l4k + LVypcApenV9IqUMwZWVDVjIE7VFsCP48w8PCwZYj93JtggtebsCmwsII8FOEuIOFfaOSsG8YgCr/cGAp + cG6uDnmGT2ftvEIMAbuDJhetDbAjkPu7ct4AgxfOKWDZgRif2BBMU95PjbDGBHYETD69Ichr/taN07QS + nT9P9zC5SOcLb4S4f3f6vX3lMAePzvTyi50Rvv5WOOfn6NJg6QwvVwy1jMCd70b47tu5lyOFVcAnqfTt + s1OITGDTdJIMUuW/AKvF9Lm5OqQA7pjoxhDWINWnNgZtUX6AJcMtpfjNrvQnd7lT8NPJHmqiko+uC7Sp + /ACb6xN8dF2QgxGTuya5GexOfy6sOBjj/YDJ5UMcePTcn2PEhM9tCp0Yq/jyGCfD3LbeuvOAtVT5L7RT + iEzQew1Ald9Flf87WHO/R+Ty0GMKNM4tNwD46/4oa2rsKSfXBcwt0/kgbLK+Ll2GK4c5GOQSfH97mPc7 + YZz2hUxu2xahzCH45PD0ZQkiJjx9OM6oZP2/HRyLW+MrYE1QWjzUsEWOFIYDz1Dl/y5V/pyEnNmgdxqA + qroSYBnwQyDnz6RpxTqu5JX76377isZcmmCER2N7g9kiV39uuUEgLnnyUOdz6E8fiVEfk8wf0FK5th23 + DMzYAvtumReOxjkUtk50VqntBgCse+924O8sr/PZLUx36H0GYHndKSBWAwuwaQxjUIqL3Jmna7bQBRQY + gvpWqouGujUCCTjahRrjuqg1hbh5CABWcxCAQt2+YaOGuKQ6eT7lzrwZvhLAZQixmir/BLuF6Sq9xwA8 + UQ9V/vkI8SJwmp2i1KbkoofYGIsmpKWYA1pRhuqIiVuHks42FMAqIfbootXZeT6HtZ9juSoGaAWPLihO + ylGffzMjTwVWsrzuPJb3nuLB3mEAHq8WaPLzWItEDLZbnC31iRMlvVcMs68hcNiUvB8wmVTUFJI0sqY2 + QbFhlfd2lvPKDQY4Ba+0UkQ03acjgXeyND+gM8wq1U9UCG7Icbq1kwxGiKcR4npW+PPGRWmP/DcAVX4d + 3fg+cC/gsVscgB0Bkw3JUfXPjHQwociey2hKeLE6ToVTMK9Z3L7sQIzjcckPJrhb9RCaU2wIfjTRTSgh + eaTZuEahIbiowuDdBjPndQCNODW4M1lzEUpIVhzM2wl7buC3SO6gqs6GnEnXyG8DYPXn+xXwfWwY7GuL + hITvbw9jSijQBX+b4WWQyx6Dv3R/jLiEm8e70qr89oZMbn8nwkkFGlWzvIxuZ/R+hEdj+SwvE4o07toR + 4b1m4xqfHuFguEdj6b5oVqYtd4Qh4J5Jbs4us26Bh/fFbPVEOoEO3Abit8l7OG/JG6VqQZXfA/wR+Cx5 + WLD0fsBksFtjpk9nsFvj/AqDpw7FaMjxxLUjEcnEIp2FQxzsDsq0SsTX6hIUGoIrhjq5eoSTMqcgmJCE + E1avgCnFOl8Y4+L+aR4mFurctzvKd5KGrZGxXo2lM7wci0s+tzlEMMeet5Est75xnAuBFYJ8/PWgXZWA + XWUGcDJLbnmaR+/OS5cl7xQLgOV1PoT4K1Yf/rzFqwv+MsPDoiHWOMDekMkNW0Jp5bi5YLhHY928AkoM + wZWvBXnmSPrxrxrm4PYJbk4pbN0L2NFgcse7YZbui7XY779me5lcpPPxDUGWHcjtPTzaq/H7qR4+nBzH + 2BM0uWRdgLeP9w7tT+E5JB/Lx6nF+WcAlteVIMRy4Dy7RekMHl3wx9M9LBnmONFr/497otz+TpjDkdyN + VJ9VpvPUrAKcGnx+c4i/fxBLe5J7dcE5ZTrnlhsMdQuEgINhyaqaOC9VJ1pMG55YpPHYTC+TinRu3Rbm + p83mCGQTpwbXjHTywwnuE6HVjoDJpesCvJvfrn97vAxyAZWltXYLkkp+GQDryf8EvUT5GzEE3DTOxQ8n + uPAmA/GjUcndOyI8uCeas2aeZ5XpLD+zgAqn4LEPYnx7W5g9wa4pTIEhuGG0k++f4sKjixPKnwscAj48 + 0MEPJriY4bOiUwk8/kGML70R4kgODWqWeBkpL2VRqd9uQRrJHwPQy578rXFmqc6vTvMwq1Q/cWEPRyR/ + 3BPlvt1R9oWy3xhktFfjN1M8fGSQQTAuefxgjAf2xNhcnyAQb73xp1ODUV6Nq4Y6+NwoJ6O8GjsDJl98 + I8R/jsSzLnORIbh8qIObxjqZUqyfaKN2MCz5/vYwD+6N5qwXQQ5YiZSLWFRab7cgkC8GoMpfjFXa+2G7 + RekphoCPD3fyvVNcjEspmw2b8N8jcR7aF+W5I3EasnhH6wIWD3Hwv+NczC61FKomKtngT7AzYFIbs9YO + KDKsOH+Gz2rhLbDi7Pv3RLl3V3Y9F13ADJ/O1SOcXD7UkZZFOR6X3Lc7yk92ROxoAJILViLl4nzwBOw3 + AFV+L/A4cLHdomSSAl1wxTAHXx3n5NSipqeaBKqjkv8eifPkoRj/PRqnNpadNfYMAWeU6nx0kINzyw1O + K9bwaAI9uTZg42pBB0KSF6vj/OdonGezaJy8umCmT2fBYIMFgx2Mabby0dGI5IE9Ue5Nekt9nOeRciGL + SgN2CmGvAbBypA8CH7dVjixiCPhQhcHVI5xcOtigqFlpbiAh2VxvsrI6zovVcTb6E1l78hYbgiFuQUFy + sdCwCUciJkcjmV0ToBGXBpOKdOYM0PlQhcGsUoPBzeolEhJeqYvz8N4YTxyMpZVZ9wMeAz5t53qF9hmA + FfUaUv4cuMlWOXLIQJegcrCDyqEO5pTpLYyBBAJxyXsBk1frrLX1ttQneD9o0hCXthThdAZNWJOEhrgF + pxbrzPDpzCrVmVJstRpvPn8oalqzC588FGfZgRjbGxJZ7zycp0jg/5Dyq3YtUWaP4i07DE7XLcCPbZPB + Zga6BOeXG1w40GBOmcH4Qq3NCxFKWPP13wuY7Agk2BWU7ApY6wIejpjURmXWV9TRhTUhqMIpGO7RTqwP + OK5A4+RC6/+ljrZ/ysMRyfo6a23A547E2H48N52SewESuI1o5C6uHJTzg+de+azGnddi1fbbN5Mmj3Bo + MNytMXeAwexSnTNKdcYXaBQ72l+RNyEhZkJMSvwxyZGI5GhUUheTHI81rQzcEJfEkwuHSjhRRecQVoii + Cau3gEu3woTG1YGLHVDh1BjoEpQ7rcU/HZrA0cFdE0pIDoQlrydXB15bG+fNY2auF/noTcSBGxD8kYW+ + nB449wagyn8u1qy+rK7J19spcwrGF2hMKtKZVKQxuUjnpEKN4W7RYn09u0hIOBQxeT9gsu24ydvHTbYe + T/Bug8n+kEmeRiz5Shi4hErfi7k8aG7vpCr/ScBLwNCcHreP4BDg1ASD3eLE8tzDPBqDXIJBLsFAl8ZA + p6DQEDi0xqW9QRfWsuONmYhG+2EmlxGXyb8TstFTgJi0nuQ1UcnhiORwxORwRHIo3LQ0+b6QSTAhiZmZ + WY5cwQfAfCp97+XqgLkzAMvrCpPNPGbk7Jj9FF2AWxN4dGvpbpdmvdeo+E5h/RGXYCKR0lL4eFLpwwkI + mTInqwEpWrABKc9lUWlOFiHJjQFYUe9Ayofow+k+hSKD/BUhrsnFKsW56Qcg5deAj+XkWApF7+djSZ3J + Otn3AKr884H/AnnRxlWh6CXEgQuo9L2UzYNk1wBU+QdhLdoxNqvHUSj6Ju8DZ1PpO5ytA2QvBFhepwP3 + o5RfoeguY4H7k7qUFbJnAIT4MlbvfoVC0X0WJHUpK2QnBKjynwG8CHizJbhC0Y8IAudS6Xst0zvOvAGo + qnOBWAtMz8GFUSj6CxtBnk1laUbbM2U2BHjyGCBuRSm/QpFppoO41dKxzJHZ1JyZmAHi5lxeFYWip3TH + DRZd/qD77nbK924u0uU/a0xzU/L/CU3TelSFnbkQoMrvBlYDMzuzuS6aatOb4xCtfyAEbc5E01JKXVs9 + VhtyONoQQgBGO/tr61guTbR5Xm7N6sbbQnZosbRXk3xgtHE9XFrr11BglQC3JbuzrWOJdo6lt34Nu3ss + pybavL4urfUbs3HWYmsY7Z1Xh8dq+aF1rNa/Ywgw2pDDqbV9b7S1jKQmRPvHEqn/F3GHRmOF4GVCiOfp + Ad3yAKSUNwDXJf8rAHcoId17QnJ0c+Ed7SiRaPOz1qfBCtq+uEK0vcqJJmhnf61/2N6xUifWKBQ5xqBJ + b3scwnc3BBgCnJ76hkcXTChUWqFQ9CZUea6iXdoLMKVs+zvtfq+L+2v3O+182Fanw5iEeBszHcNm6w1a + TWiz61LMtKZStyZbONG6eGayIWtrRE1abZEmsb4jAacmQhcPNI7SQ7prAGqBnQBHInJATVT6WtsoIWWb + vd7CZuYuDNBmt5mEhLb6TEbN1uWTkjbXnovLtqfJRtq5ESJt3AiNnXra2l9rh7Lk697NLbt8c7f9G0ba + +A0T7ZxTrK1zAiJtHCienKrcpgxtXfO+PZ3ZBQwHNvdkJ93y2aWUOqB/emOocNmB6MtxyYTWt0N1hVEo + ssc2hDiThSXdbi3erUEEIURCCBFdui96fcRkQkJaVr/5Sym/QpFVJiHlV3qyg+6P2lkz/d4Cyu2+CgpF + P6YaOLW7Mwa7l0ZYKQG+jlJ+hcJuyoGvJ3Wyy3TPAPj9o4Hr7T5zhUIBwPVJnewy3TMAQtwKFNt91gqF + AoDipE52ma6PAVT5JwOvAR67z1qhUJwgBJxBpW9rV77UNQ9ghV8AN6OUX6HINzzAN3jyWJce6l0zAJIx + wFV2n6lCoWiVKzETXWrB19UxgBtRT3+FIl/xgOhSXUDn3YUq/xBgK1Bq91kqFIo2qQcmUen7oDMbd8UD + +DxK+RWKfKcEuKGzG3fOA1heV4QQ7wKD7T47hULRIUeAk6n01Xe0Yec8ACEWoZRfoegtDAQu78yGHRuA + J+s1uuBSKBSKvOB6njreoX53bABMOQM4w+6zUSgUXWI6iUSHetu+Aajyg9X7T3UOUih6Fwbw+aQOt0lH + HkAZcIXdZ6JQKLrF/2DpcJt0ZAD+ByutoFAoeh8lWDrcJm0bgP/GAZbYfQYKhaJHLEnqcqu0bQAaGsYB + s+2WXqFQ9IjZSV1ulbYNgGQhqu5foejteJK63CqtG4AVfg2h3H+Fok8gWMIKf6u63roBMOV4YIbdcisU + iowwI6nTLWjdAAixgEwvHa5QKOxCS+p0Kx80x1p//CN2S6xQKDLKR5K6nUZLA5BIDEG5/wpFX2NGUrfT + aGkAhJgLFNktrUKhyChFSd1OI90APF4NcKndkioUiqxwaVLHT5BuAHTDAC60W0qFQpEVLkQz0ib2pRsA + KSeiGn8oFH2VwSAnpr6RbgBaiREUCkUfopmONx8EnGe3fAqFIquk6XiTAajyO4FZdkunUCiyyqykrgPp + HsBYYJjd0ikUiqwyDEvXgdRWX1LORgiH3dJlk7FejTkDUk4ZMKVEAlKCmXxPSkhICCQkh8KSfWGT+pgk + 0c4S7CM9GueWG2n7NVP2C2BKCJuSUAKqo5J9IZO6qHX8ruDWYGapwfnlOuMLdcocgqgpqY5Kth43ebE6 + zlvHEsQ72PGnRzhbfd+UkscPxgm1c8IXDzQY6Gq9Wvw/R2McDHdvvXpF1nEg5WxgO6QaACGm2y1Ztjm7 + TOfh6V2f4RxMSN44ZvLbXRH+tj/WqiGY4ev6vhvikuer43zv7QhvHEt0uL0h4JqRTr42zsXEoranapjA + yzVxbn8nwvNH224G8dB0T5sLQ+xdE2BVTevfdWnw8HQvA12tf/vCtSYHw20fV2EzQpwOPASNIcAKP8BU + u+XKV7y6YHapzp+ne7l/qge964uqt0qhIVg42MHLcwuoHNK+81XmFKyYVcD90zztKj9YP+rcAQZPzy7g + tpNd3ZL3woFt94E9vUSn3Jmhi6Cwg6mNzUKtO0nTdeBUu6XKdwTw2VFOvjjG2eN9pVJoCB463cNpxXqr + nxcZgidnFfCRQUYXFnMEpwZ3THTz5bGuLst0YUXbBuDccgNN6X9v5jSE0KAxBIjHRyBEWY922Ut58lCM + 3UFJQloxvgR0AS5NMNqrMW+ATpGRfrd//SQXD+6N0dBBkP3vI3G2HU+QkJb77tIFZQ7BGaU6o71amjKX + OAR3THRR+WowbR+agPumejinLN04xEz41+EY/zocZ1fQpNAQzC3T+fRIJxUpT2cB/Giii/8eibH1uEln + mZZ8yldH089RAB+qUF3iezllmOZIYLf1SwoxxW6J7OLe3VGePdx2vDq5SOeFcwrS4t1RHo3pJXqbMXIj + S/dF+cv+WIv3PTp84yQX3z/FnfYk/eggByUOQX2sSek+MsjBlcPSw4P6mGTJ60GeOxJPG0BccTDGr9+P + 8sSZXmb4mgxGgS746jgXn9scaldeU3JCHpcGcwYYVB1Ml7/YITizVEfR2xFTgN2NwaSK/9tg6/EE9+6O + tni/ozi8PUIJ+NG7EZ6vTjcghoBTU/YrgG+e5EyL4RMSrt4Y4tlmyt/I3pDJla8H8cfSP71imKOFJ9Oc + 3cF0D6G1MOBMn05xyn52BjrvVaRS4hDM9OlcPtTBx4c7uLDCYLRX69R4RZlDUOFqeqUmI0ocgrkDDD4x + 3MHCIQ4mFmk4VLjSEmHpfOMvfJLd8uQzzRUDLGXtCQkJa2riLZSs1KkBVkZguEfjnLL0z1fVxHnqcKzd + fb8fMFl+MMa55Qav1CZYXRPnldoE4UT7IcvqmjhjC5rGN84tNzAEaenE5u7/yuo44wo6PyYytkDjmye5 + WDTE0SKLEDHhrWMJfv5ehL9/EGszjblilpepJU1eyCc2hPjP0RjfPdnNtaOcDErZb1zC6/4E39oa7tBj + 62ecBE0GYFwPdtTnmVrc8mnfmlHoKkPdLfcbNZvu+g9VtBxs+/uBGGYnUuxf2BIinqxn6CxvHDM5GpFU + JBXolEKNkV6N91Oe8s0N1gvVcT43qmMDIICrhjm4f5qnTU/EpVnp1EdmellyKMZnN4WoibY8AY8u0vZR + 4RQ8M7vgRB1GKoaA2aU6z57lZdF6K2xSAEmd16g65gCG2y1NvnJhhcG1zW5wf0yy3t9x3r49hrgFCwa3 + TP3tSTEs00rSY21TwmudPG7E7JryA9THJRvqm/avC5ifUjg1zK2lhT4NcclrdZ2TZ+EQBw9P93YYhoBl + LBYMdvCPM7y4OxET3D3J3aryp+LRBT+d7MalOl02MpyqYw4DzFKg1G5p7OKbJ7n4xDAnCdlUkacLQbED + xnk1JhbpLeLSB/ZEORrpWLtcmsCT/LIGGJo1IDfDp3PXJBdD3Ok73hU02ZHytB3tTf88IdMNRKYxJbxU + HefilBqAiwYaPLjXGgM5u0w/cT4A6+oSNHTCygx0CR6Y5sGZonwJCU8cjPHIvhg1McnUYo2vn+RijLdp + o3PLDX400cXNb4XbrZascAmiJtz+Tpil+2JUR00+VG7wp+netIzIqcVW5eRbnSi66geUgllqAOX04xZg + 55V3LaX17yNxvrc93Kltf3qqmx9MsHLwmgBDCAoNq7CoORK4e0ckzb0vbTZ6ZQKh7Ok/poQXmw1Mnldu + oCWPfUEz9//F6jidqWO+aayLASmKKIHvvB3mnveazndNDSw/GOPZswrS6iGuH+3kd7uiHQ42fvWtEL/b + 1TRY+8/Dcb7zdpj7pjZVZwpgfIGmDIBFEVCuAWOgS/Ul/ZKDYZNb3w6z4NUAoU7eP6UOwXCPxnCPxlC3 + xkCXaFX5AZYdiPGnPenZBmcr1TYyiyX2EisESM0gVDgFp/t0HBppbrbEiv87wq3DkmZpzJdrEi2MHcAH + YckX3wilDf4V6IIrhrZfJbkvZPLg3pYDoyur4y0GEn0qJdCIAMZowJCe7qk3Y8rkq43P32kwuXRdgAnP + N3DXuxEiGX4CxyX8fneUazYGW9yswWbutYZVQ5BNYiasrW2ycJqwFH+kR+Pkwib33B+TbKnv+GKM8GiM + 8qYH3n//INrm9mtrEy3CnPkdeGk7A2arE5ca4rJF5kNVMKYxpDEE6Ldc9XqQ54/GKXFYsfl3T3alpZhO + KdS4aZyL9XXBLu87kJBEzSYDY0qIJWcDHoyYrK9LsHRfrM2JQIfDLW/eQS6N6mh2Xdjnj8b5yKAmpbuw + wiDQzDqtrU0QTMi0moDWGOlpmdt/61jbhsOUsL3BZFxBk9EY4mr/GIfbGI+JmXQ4I7KfU97vDUBDQlIX + s167g9ZU2mfPKmBmSiXdhRUGz55dwIVrA9RGO39H3fxWmGUfxE5MCTaTabmIKTs1Qv9us7hXFzC5WGPr + 8Y4NwOVDHMwvtyr5VtfGiXXBc1lVE8ekqVnETJ/eIkZ8sRPuP7ReLxHpII/Z/GneUSagLa/MlJ0aoujP + lGtAhd1S5BM1UcknNgRb5J+nl+g8MsObNpLdEQ1xSW3UMi71McnxuCSY6Jzyg1Uo1JzKwR23bBDAJ0Y4 + uHGsk+fPKeDARcU8dLqnzem7zdl63EzzPgY4RYsBwJWdNAC1sZYnW9pBHF7RbKbh0Q7iLuXVd5sKjX7u + AbTGuw0m39rWMvX04YEGN4zO7EzA9lhdE2/h3l422GBCYftWaEKRlpbKq3AJLh7kSJtj0B6hhGR9XbqC + p8bOhyOStzs5seiDkGzxRD97QNsxfaEhmNRsVmRHk5iUAeg25coAtMGf9kT556F0JbBm1rnTctXZJGLC + vbsiae8VGqLdZhylDsEfp3nT8vUAjx6IdmkA84XqtsOMdXXxFgOUbXEwYrKtmQJ/arijzX4Cnx7haOEB + PNtR9Z6yAN2lXKMfFwG1hwS+8maII82ewIWG4JenuXs8F6Cz/N+uKLuajYqfWarz8txCPjnCQanDmgxT + ZFiVhS/OKeCsZlOHj8Ulv9oZ7cph243xV1Z3fhDSlPDnfenHHu7R+OtML4NTCqE0AZcOMrhrkjtt27eP + m6p8N3uUGkCf7gPYE3YHTW7eGuLh6d60h8ylgxxcNczBI/tj3d53Z6mJSj69McS/z0p/qp9UoLF0upe4 + tFJyhYbA3YZj8s2t4RZGpCO2NyQ4GDYZ0mynCQmrOhn/N/KHPVGuH+1kUlH6wOrW84p4vjpObVRyarHO + WaV6WqgRNeHmraF2exO2i/IMOsKhoQxAuzyyP8aKZnPiNQH/71RPWnVbNllTE+eq10OtDqgZAsqdrSu/ + KeGXOyM8sKdrT3+wlG9NbcsnvdV4tGtpyFACrnwtxP5mZYxlTqvI5/rRTs4pS1f+hITvbQ/zzOHuP/2V + /neIQwO63iWzH2FKuPHNMIeahQIDXYJ7JrtzdpM9dSjG3NUBXqqOd2o24JGI5AtvhPj61nCXJwU18kIr + DUVfro0T7UYx1NbjCea/HOA/R+MdpuYOhq1MzD07Ij1K4wmUEegAjwHkbljbZnYHTf52IP1p3pn21ftD + JjdsDnHV8HRnySEEQ90aB8Im+0Mt9707lNks9LbjCS5YG+CcMoOPDXcwd4DBMLfA0CxD1RCHjfUJ/nU4 + xt8PxFq082rO3/bHECkasiuYvv2/j8b52/5YmhY92izsCZu0OO+2CnPeD5h85JUAcwYYfHK4gzkDDIa4 + BQLL49h6PMGKg3Ee3hdtdRpwI88diafVSKyrbd1LiJjw+AcxvCkDNu93s4FJH8UpqPKHga53jVTkBS7N + mlwUMa30XW8rfPHo1uzLQLz3yd4HiBgo5e/VRMyOK+vyGWtiVe+Vv5fj0oBIj3ejUCh6IxENyH4uS6FQ + 5CMxDeh6jkihUPQFohoQ6vFuFApFbySkQgCFov8SUwZAoei/xDSgzm4pFAqFLdRpQLXdUigUCluoVgZA + oei/VGvAUbulUCgUtnBUeQAKRf9FhQAKRT+mWgMO2i2FQqGwhYMasAs1HUuh6G9IYFdjCHDcbmkUCkVO + OY4VAmh1qGIghaK/UQdanUZlcQzYb7c0CoUip+ynsjjW2Et2p93SKBSKnLITmtZ/fM9uaRQKRU55D5oM + wBa7pVEoFDlEWjpvGQAp37BbHoVCkUssnbcMgGHsA2rtFkmhUOSEWjRtLzQaADORAN6yWyqFQpET3kRK + ExoNwEIfqHEAhaK/sIVKH9A0CAhSbrRbKoVCkQOk3NT4Z5MBEGIdqj+gQtHXiSV1HUgzAOwCDtgtnUKh + yCoHkroOpBqAhb4I8Krd0ikUiqzyalLXgVQDYLHabukUCkVWSdNxZQAUiv5FOwZAiLeBw3ZLqFAossLh + pI6fIN0AxGMx4D92S6lQKLLCf5I6foJ0A3B5OcC/7JZSoVBkhX8ldfwEWotNpFwFNNgtqUKhyCgNSd1O + o6UBMM0PgA12S6tQKDLKhqRup9HSAFw+AOBpu6VVKBQZ5emkbqehtbHxk4Bpt8QKhSIjmFg63YLWDYCU + 7wKbUCgUfYFNSZ1uQesGYFGpCfzNbqkVCkVG+FtSp1ugtfOlFUDYbskVCkWPCGPpcqu0bQAKC98D1qFQ + KNrFqwtWzPJyxVAHwm5hWrIuqcut0rYBuMAAeMxu6RWKfOf2CS4WDHbwt5le7p/mocSRV2bgsaQut4rW + wZf/Dhyz+wwygbOjM1UA4HMIRnrUxeosHxlkcNNYFwC6gM+NcvL6/ELmDjB6uOeMcAzk39vboP1fWoga + LCPQqzmtWOet84r4whhnPrpoeYMh4OHpHl6dX8iCwQ67xcl7KpyC30/14GimRScVaPz7LC8/nODGZa8t + fRyh1bS3QfviLSwBuB+I23oaPcDnEDwyw8P4Qo3fTvHwp9M9lBjKDLTGV8a6uGywg8EuwfIzvdw1yY1H + V9eqNQwBv5/mYUQb3pJbF3z3FBcvzilkcpEtViCOlPcndbhNOpZME68Dr9txBj1FE/CLU92cVqwDIIBr + Rjp5/pwCTi5Ubm4q00p07pzoOuEhaQJuGe/i6dneNm/y/sznRzmpTPGSjscln9sU4t2G9Gzb7FKdNXML + uW60kxzb0o1oxmsdbdTxL7ugxAR+n1PRM8RnRzq5ZqSzxfszfDqvzC1k8VDl5gIUG4KHTve0+rQ/t9xg + /fxCPjooL2LavGBykcZPT3WjJS+XBG7ZFuaPe6OcuaqB+3dHScim7X0OwX1TPfzjDC/D3DkzpvexsCjR + 0Uadk0bKJ4BDuZI8E5xeovOzye6098yUH6XMKXh0hpcfT3L3+wHCH01yM7VEP/H/hrhMu4EHuwRPnFnA + HRPUtSowBA9O91KQYiyfOhTjvt1RAOpjki9sCXHV60EORWTadyuHOFg3r4DLBmc9XXgEeLwzG3bu51xU + ehy4N7syZ45iQ/CXGd60dMxzR+Jc/lqQwyk/ikODb4938dSsAobmzjLnFQsHO/jSmCYvKWrCgleDXLMx + iD/WdK2cGnznFBf/ml3Qr0OCOye4OMPXZCz3hkxu2BJKM5gm8PgHMWa+2MBTh2KkmoHhHo3lZ3r57dSs + pgvvo9JX35kNu/JL/gGoy5bEmUIX8OspbialDLzsD5lcuylE1cEYc1Y3sK4u3TO6aKDBy3MLOKdM7+rh + ejUjPRr3TvWkPY3ueS/Cyuo4f9kfY+6aAJvr06/VBRUGa+cWcGGF0e8yKpcMNLgxmfIDSEi4YUuIg2HZ + 6vYHwiaL1wf5yhshjsebttEFfGG0kzVzCphdmvF7rp4uhOydP/qjdzew5JbBwOxMS5xJrhvt5NbxbkTy + 7oyYcNXrQbYcs27k2pjk0f0xypyC6SX6ie18DsHHhjs4HofX/AlkN4/fW9AFLDvDm+b6r6qJc92WMI33 + 6pGI5K/7Y1S4BNNSrlWxQ3DVMCeagFfqEmlPv77KMLdG1SwvvpSn9i/ej/C7XdF2v2cC6/0JnjocZ4ZP + Z3iK9zTQpfGpEU4ksD5z1/F+Kn2dTt13zfwsuWUHcB2Ql6NnU0t0HjvDi0tr+pF++E6Yh/emL3gUk/DM + kTj7QpLzK4wT2zs0wYcHGowr0HmhOk6kD0+I/vpJLm4Y3eT6+2OSS9cFOdIsbo2a8K/DcfaGJOelXCtd + wPxyg5k+g5XVibQnXF9DE/CXGR7OKG0aCH3Nn+Azm0JEO3mPNBpTDZhVapzICBgCzqswmF9usKYmQW2s + R9cxBPIaHv1Jpz31rgVz1ooieVkeXOoQ/GW6J21w5rkjce56N9Lq09yU8Ke9Uc57OcA7KakbTcCnRjh4 + 6ZyCtDCiLzG7VOf2Cemu7E1vhngv0PrdbEp4cG+UeasDvHGsKSQQwCWDDNbNK+C88r6bJfjSGCeXpaT8 + GuKSazYGaeii0QsmJLe+HebiVwLsSLnWApg3wODV+YVcO6pHxWrL0PT3u/KFrnkAj94NS255D/gMeeQF + aMAfTvdyQUXTTbgnaLJwfZD6DizqwbDksQMxxhdqnFKkn7j4g90aS4Y52RU0eft433EFig3BP2cXMCRl + 0PMv+6Pc2YahTOVwRPK3AzGGuAVTiptCgpJkSCCBdbWJPtVJ5vQSnaUzmrxKCXz1zTDPHOl+bdzuoMkj + +2MMdgtOK9ZPpBM9uuDSQQ4mFemsrokT6DCJl0YIuIaFJUe68qWuj0A8evdRltwyCpjRoyubQa4b7eTW + k5ueaFETrngtmPa0ao9gwhq1jZowZ0CTe+bVBYuHOijQBWtq4vR2L1cT8JspHi4a2GQodwZMFq0PEurk + zRYx4clDcQ5GJOeWN4UEhgYfqjCYWqLzYk2chl5bO9pEgS54cpaXkd4mY/n4BzFufTvcYyMXSljXcXuD + yfwBBgXJ6lQhYHKxzlXDHLx93GzTK2uFh6j0/amrcnTPx5Xyx+TJJKGZPp2fpuT7JXDHO2FWVnftDoxL + +PG7ES57NZA2qqsL+MZ4F0+fVZDLIo6scOVQB59JKYwKJSSf2RTq0Etqjinh/t1Rzl0TYNvxdMuxYLCD + V+bmzWSYbiOAHzerj9gfMvnillDGHgSmhMcOxDhzVQPPHomneWAjPBpPzirgV6e5Key4dP1YUie7TPfu + aJ9vN3BfZi5D9ylxCJbO8FKUcoGeORznnvci3dqfBP59JM45qxtYU9NkQARwXrnB2nkFnNtLY93RXo3f + TPGklaP++N0Iq2u6/6jeWJ9gzuoAj+xPz3WP9mo8d5aXb5zkQuulucLLBjv4YrP6iM9tDnE0mnk3cHfQ + 5LJ1AW5+K5w2ruDQrPkZq+cUMNPXrrN+X1Inu0z3kpAP3w5LbnkDuAbwZvyKdAJDwB+meTk/RSH3h0w+ + ui7AsR66n/6Y5NEDcXwOwQxfU4xW4hB8bLiT4wnY4O89sa5bg8dmeplc3PRzv1gd5/otoR6fQ9iEFYdi + HIlI5g1Iz6hcMNBgSrHOyuoux7O2MsxtPX1TC3V+9l6E+3dHe7DX9jGxUqpPH44zq0xPG6MZ7Nb45AgH + UdO675qlC6uBT3GJJ9Cd43a/CuHRuwMsucUAPpS1q9IO149x8q3xTZNXwsm4/60MDdjFJTx7OM77QZML + UtJfhoAPDzQ4uVDnP0d6R6rwlvEurh3V9DQ7EpEsXB+kJkNPM4mVFnu+Os78AQYDnMl4FphYpLN4iIP1 + dQn2h/N/EMUhYOlMLzNSnriv+RNcvSmYkzGgwxHJI/tjODSYXWqcePg4NMFFAw1mlxmsrkmkVmneSaXv + 2e4er2dBrRC/BrZm/7KkM9Nn1fmnCn/79jAvdDHu7wgTWLovxrw1AbYeT09/LRnmYM3cAqYU53f14JwB + Bt85pWmMxJRw45shdnZ+cKnTrK9LcNbqBh47kB4SjCvQeP6cAv53nIt8n4l941hX2sQnf0zymY1Bwjn0 + YBrikm9tDXPJKwHeb/Y7XVBh8Nr8Qj453IEu2JbUwW7T85+jyv8RrJ7jOdGEMqdg9ZwCJhU1He6Zw3EW + vBrIqoUucwjun+bh8mYzCP3JyR/Nb/p8YIBTsHZuYdrU5z/tjfK5TaGsyqoLS5F+NNGFN2XQQQLLDsT4 + 4hsharMQS/eU6T6dVXMK0mpJPr85xAN7suf6d0SFU/CrKR6WDEufQGRK2B00/zvGKxZqmhbs7v57Pqwt + 5TNAVS4uhi7gt1M8acq/K2hy7ebMjcy2RW1MsuT1IDdvDae5/T6HNfHoF6fmV/MMTcAvT/WkKf/W4yZf + fyucdUOVkPDLnRHOfzmQlsYSwFXDHKybW8iZma+B7xHFhuDB09MLyZYdiPGnvfYpP8DRqOSTG4J8ekN6 + yKYJGFugRYBY9/eeCQ8AoMo/HqtpSHE2L8aXxjj5zZSmySsxEy5YG2BVD0ayu8MFFQYPTfe0SAuurI5z + 9cYQ+0L2Dwx8aoSTh073nIghIybMW9PA+rrcjsYNdAnuneph8ZB0z+l4XPLtbWF+tyuaF57T76Z4+ELK + qP+uoMlZqxrSZo/azUkFGvdN8zQOfB+RUs7UNG1fT/aZGTP88VtrkVKQxQHBWaVWRZYzpSLrtrfD/HV/ + jwxgt3g/aPLYgTgzSnVGpxSJjPFqXDXMwZZjJruD9hmBUwo1/nGm94T7LYFbt4X5+we5v1aBBPzjgxgN + cZgzQMeR/P1cmuCSQQ5OLrQKhzpbiJQNLh/q4O5JTQ0+YhkeUM4UtTFrPsFor/bC1BL9u5qmre/pPjPn + s1b53cBqYGamT7zUIVg7r5AJKe7sPw/FWfxagJiNv5FXF9wx0cVXx7nSLmQ4Ad/bHubnOyNpTUhygUuD + 588pTJva/O8jcS57NdDpiSvZYu4Ag6XTPYzypntOW4+bfHJDsMXU41wwwqOxfl4hg91Nv+BdOyLcti37 + oVI32QScTaUvI4v2ZK60rdIXBnkD0O0BidYwBNw71ZOm/LuDJtduDtqq/GBN7rj5rTAffz2YNovLrcNP + JrtZNtN7IiWWCwTwvVPcacp/OCK5dnPnZ61lk9U1cc5Y1cCKg+meyOQijdVzCnLeN8+hwQPTPGnK/3Jt + nB++k7fKHwSuy5TyQyYNAICmbwB+lsld3jDayZXDmuLHsAnXbAq1mLZqFxJ49EAsWRabPuB1+VAHL83J + XarwvHKDm09Kn+X3pTdC7M+DMYlGjkYkV7we5NZt4TSjVGgI7p3i4YFpnrTKzmxy01gXF6bMi6iPWY09 + c5ny6yI/Q9My2qA381e6qs4FYi0wvae7ml2q88I5BWmj69/YGuZn3Sz1zTbFhuB3Uz18fHh6yqYhLvni + GyEe2R/LWkgw0CV4dV5h2pjEb3dF+fIbIbsvS5vMG2Dw51ZDggSf2BBiSxZDglmlOitT7i1TwrWbQzxk + 86h/O2wEeTaVpRm9+TM/u8USsMehQJlT8NB0b5ryP3Uozq925qfyAxxLzhP/+lvpqcJCQ/Dg6V5+eaon + KwtF6AJ+fZonTfnfPJbg29vye23XVTVxzl4d4NlmU2snF+m8dE4BV7fS0TkTFBuCPzbrgrzsgxhL9+Wt + 8geBGzKt/JANAwBQ6XsNuLW7X9cF3DfVwykpcf/7AZPPbQ7Ss4Yp2Scu4Rc7I1y4NsCelEyAVRzj5IVz + Chnjzexlv3aUk6uGNW9YEeoVXXo+CJtcui7Ad7eHCacYzRKHlZd/YJqH4gyGBJqAn5/qZnJKLcnOgMmX + 3gjlc2uzW5M6lXGyOb/1/4CnuvPFL41xpvXsj5hwdR7F/Z1hdU2cOWsCLcqTzy6zFoq4sCIzswonF2n8 + ZFJ6+/PvbY+w0YYR9e6SkHDnOxEWvBrgg3D6OMq1o5y8cE4BEzPUnWnxkPQp0VETrtucn5WJSZ7C0qWs + kD0DUOlLIOV1wK6ufO2sMp27J3lOCNaY71+T42KfTLA/ZHLxKwHu2RFJ81yGugX/ml3ArSe76ElnaK9u + hUmpjSqfOhTj1+/nb5jUHv85EmfmSwH+3SwkmOHTWTfPqn/vyfTisV5rebjUTMNdOyIZn0OSQXYh5XVU + +rJmzbPb4WJR6SHgWjq5tuAAp+Ch0714UgbNnzwY49d5HPd3RMy0Vo35xOtB6mLpc73vnOjm0R6kCm+f + 4EqbJ/5B2OQLW8L57Mp2yMGwyYJXA/zwnXSjWZxckOO3Uzxp8ws6i0PAfdM8DHQ1fXdNTYK7d+TtvRUH + rk3qUNbIfoubSt9K4AfQfmrVSMb9qbXrOwMmn98Syvu4vyMk8PcPYpy1qoFN9emzChcPdfDKvMK06aed + 4SODDG4a15Tyi0vLlT0Qzp+UX3eJmPD97WEWrAuknY8hrLTwS3O6HhJ8Y7wrrWdkTVTy2U1BwvlpLSXw + g6TuZJXc9LiS8h5gWXubfHmsKy3uDyUk12wKcrQXxf0d8U6DyfkvB/jzvvT69/EFGs+fXcBnRnauI+xg + l7XWXGr48Nv3Izx9OG9d2W7x7JE4Z68K8GIzF32mT2fNnEKuGNq5JbbOLtO5LaVnpAS+9lY4rTNvnrEs + qTNZJzcVKo/9xGTJLc8CFwNDmn98Tpk1ucaZEuB9a1uEZQdyX7uebcImrDgYpyYqmV9unDhnty5YMMTB + QJfGqppEm5V7hoClM7xpPeo3+BN8amOI/B3H6j71casTsSYEZ5U1NWz1JBu2Vrg0XqpOtOkl+hxWF+TB + KRO3lu6LckcnuiDbxEZgMYtKc5LDze38VWvW4EukGIFyp2DdvELGFTT9QE8cjLHktfxP+fWUc8p0/jLD + m5a/B1hXl+BjrwdbnVB041gnvzytaZD0WFwyb3XgxMpHfRUBXDrYwR+meRjkSr9t19YmuGZjsMUT3WoX + 7+GzKaP+7wVMZq1qyNdR/4PAfCp9O3J1wNy2ubVO7ONAGJri/lTl3xkwuWFz74/7O8PLtVYHneY95meX + WqPelzZbkntaic5dk9xpGZJbtoX7vPI3nutTh2LMWtXQYvr32WU6r8wrZNGQ9JDgY8MdXD2iSfnDJnx2 + U96m/MLAx3Op/JBrAwAgeBH4MhC/aZyLRSlxfzAhuXpjMCudV/OVQ2FJ5asBfvxuJG1y06DkktzfOdmF + U4MiQ/CnZg0rqg7GstqoMh/ZEzS55JUg9+yIpDWBGeAUPHaGl5+f6salWVOzf3Vas5Tfu3mbTo4DNyZ1 + I6fY08Jm2WGuG1/0619N8dzYGJo1Dsz8shen/HrKgsEO/ni6h/JmacF/HopzOGKmNfbcEzSZvaqhxRr0 + /YnFQxz8bmrLkGBNTRxDE2kr775UHeeiV+yfEt0GtxGN/JgrB+X8wLYYANM0Bwkh1gAnNb73+Acxrno9 + 2Ktz2JnglELNGuRrJy0YM+GyVwM814PlqfoKYws0/jLDy1nttBirjkrOWtXQlVV2coUEfoc0b2JRmS1x + XM4bs0kpdSHEn4GzG9/bEbDWUW/o+6Fsh9REra4vQ9yCqSnr76Xy850Rft/PXP+2qItJ/rY/hke3Vt1t + fr1MrPqIl2ry8ub6B8jrWVRmmyXPqQEwTRMhxNeAr6S8Hfz4huAbbx4zh9p1EfKNmIR/Ho5zICy5sMKB + kTJSs64uwWc39Y9B0s4Sk1YZ8bsBkw8PNNLSyUv3RbnznbwMK18APkZlqa3ztXMaAkgp5wHPAp7Gt4D/ + FVX+PyPEE8B5dl6MfGTuAIOHp3sY49U4FpfMWtXA9jzrVZdPzPDpLJ3uZWKRxjsNJmevzsuU30qkXMyi + Ur/dguTMAEgpAR4Erk457jIp5Sc0TYuzvK4EIZajjEALBroEt53sZnN9ggfzt2FF3uBzCH4yyc1D+6K8 + Upt3rv8qpFzAotJ6uwWBHHsApmm6hBC3YvUK2C2lnK1pWs2JDZbX+ZQnoOjDrE0qf03Pd5UZcp4FkFb7 + 8A9LKY9qmrahxQbKE1D0TV4GuYDK0lq7BUklf5ayScXyBP4KXGK3KApFBngOycdY5KuzW5Dm5L4SsDNY + gyOXA49Avs7ZUCg6RAKPAYvzUfkhXw0AQKUvBHwW+J3doigU3eR+4NNU+jK6VkYmyV8DAFDpiwI3AbcD + eTecq1C0QQL4EcgvJe/hvCU/xwCa83i1QDc+B/wacPd0dwpFFgkDX0PT7mNBcd4XbPQOAwCwvA7gXIR4 + FMj9rAmFomMOY013f4FKn92ydIreYwAaqfJPAP4BTLZbFIUihW3A/1Dpe9tuQbpCfo8BtEalbzswF3ga + lSFQ2I/Euhfn9Dblh95oAAAqfXVYaUI1OKiwkwTwQ+Dy5D3Z6+h9IUBzqvwXAX8EhtstiqJfcQC4lkrf + c3YL0hN6vwEAqPKPAJYC8+0WRdEvWA18kkrfXrsF6Sm9MwRoTqVvH0JchOWO5eXkb0WfIALciRAX9AXl + h77iATSywg+SucB9wES7xVH0Kd4BrkfKl1hUarcsGaNvGYBGqvyFwN3AdYCjh3tT9G9iwAMI8U0WljTY + LUym6ZsGAOCJeoEmLwZ+D4y0WxxFr2QvcAOmeJbFJX0y5dx3DUAjy/2lCH4AXA+4erg3Rf8gAtyH5Af5 + OosvU/R9AwDw5DFBwpyF4JfAmf3mvBVdRQKvAf+Lpq1jQXGffOqn0r8UYUW9AylvAL4HlNstjiKvqAHu + RMrfsag0r2fwZZL+ZQAaseoGvgd8ChUW9HciWI1nfkilb4/dwuSa/mkAGqnyTwPuAD5CX6mJUHQWE6tF + /Xep9G20Wxi76N8GAGB5nQ58CCF+BMxAXZO+jgQ2AbcB/6HS16/nkqibvZEqvwNYDNwCTLNbHEVWeBO4 + B00sY0FJv4nz20MZgOZU+Z3AIixDMBV1jXo7EtgC3I0QVSwsUaXiKaibuy0sj+By4BvAdLvFUXSLjcBP + gcep9MXsFiYfUQagIyxDMB+4EfgwKmuQ70SAf2P1j3xJKX77KAPQFZbXTUKIz2Otb9h3ZoT0DfzAn5Hy + fhaVbrVbmN6CMgBdxZpxOAC4CrgGa8BQTTiyhxiwBSkfAh5DatUsLrFbpl6FMgA9ocqvIeU0hPgUcCUw + 1G6R+gkHsVbcWYomNrOgJO/bb+crygBkgpUS6us9wMXAEuBDwAC7xepj1ADPA48Cz1JSEuI8dfv2FHUF + s8HyulKEOA+rruASoMxukXoptcAzwBNIuZJFpX16Zp4dKAOQTVb4wZRehDgf+ChwPjAGNWbQFjFgF/AC + 8E+kXIkmgiz02S1Xn0UZgFxS5TeA8cB5wEVY6UWf3WLZjB94CSt1txLYQaUvbrdQ/QVlAOxiRT1I6cbK + IswGzgJmYrU3d9otXpaIAvuBDcBaYB1SbkLTIixUo/d2oAxAPmEVHY3Eqjw8E2v5s8nACHrfbyWxlH1r + 8rUeKTcixB5VnJM/9Labqn9R5QfQkLIEmIwQk4FTgVHJVwVQAnhtkjAI1ANHgT3J11tIuRUhtoKsR2im + errnL8oA9FaWHQaHqwCkDyEqsAzCYKz04wCszEPq3w6spdWdyb9dNJU1R5KvGJabHk7+XYuVfqtp9vch + YA9SHgXhJxYJcKVasFmhUCgUCoVCoVAoFAqFQqFQKPKO/w8RrF9q+bIugwAAAABJRU5ErkJggigAAACA + AAAAAAEAAAEAIAAAAAAAAAABABEXAAARFwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAO+vAAPwsAAT8LAALvCwAELwsABU8LAAZ/CwAHDwsAB28LAAffCwAH3w + sAB28LAAcPCwAGfwsABU8LAAQvCwAC7wsAAT768AAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAAfCwAB7wsABQ8LAAfPCwAKjwsADR8LAA7fCwAPzw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAPzw + sADt8LAA0fCwAKjwsAB98LAAUfCwAB7wsAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAAHwsAAl8LAAavCwAKrw + sADh8LAA/fCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA/fCwAOHw + sACq8LAAavCwACXwsAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAA768ABPCwAD3wsACQ8LAA2/CwAP7wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA/vCwANvwsACQ8LAAPe+vAAQA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAB8LAAMPCwAJDwsADl8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA5fCwAJDwsAAw8bIAAQAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADvrwAK8LAAZPCwAMzw + sAD+8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP7wsADN8LAAZe+vAAsAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsAAX8LAAhfCwAOrwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA6vCwAIXw + sAAXAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAX8LAAi/CwAPPwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAPPwsACL8LAAGAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADw + sAAM8LAAfvCwAPLwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsADy8LAAf/CwAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAADxsQAB8LAAXvCwAOTwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA5fCwAF/v + rwABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAKfCwAL7w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAL7wsAApAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA8LAAA/CwAHbwsAD38LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAPfwsAB38bEAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwACLwsADD8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADE8LAAIgAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsABS8LAA7/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADw8LAAUgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAE8LAAj/CwAP7wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD+8LAAj/CwAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAA768AEPCwALnwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAufCwABEAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwACHwsADW8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA1/CwACIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADw + sAAt8LAA5PCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA5fCwAC4A + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAD///8S/v7+DQAAAAAAAAAA8LAAN/CwAO3wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA7fCwADoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA////Kv///97///+l/v7+AfCwADfw + sADv8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LIF//TDPf/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsQT/88A0//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA8PCwADkAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAD///8Q////2v/////76LaQ8LAA7/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//K4Gv/87cT///77//TDPv/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8bcW//vrv//+/PX/874t//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA7/CwADYAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD///8y////9v789v/z + vzH/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/0xD///vfm/////////////fbg//G1Ev/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//TDPf/99uL////////////8 + 8ND/8bMJ//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA6vCwACcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAPCwABn31Xbj//////3z2P/xtQ//8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAH/99R0///9+v////7/+NyN//nhnv// + ////+uSp//CwAf/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CxAv/31Hb///35/////v/53pb/++i1///////53ZH/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA3fCwABkA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAJ8LAAx/CwAf/6 + 5Kf///////rkp//wsAH/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8bUP//rlq////////vvx//XKVf/wsAD/8bQM//3z1///////9s9i//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/xthT/+uey///////++vD/9ctZ//CwAP/x + txf//vfm///+/f/0x0v/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAx/CwAAkAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA768AAfCwAKDwsAD/8LAA//G1D//989n///////bQaf/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//O+Lf/989f///////zy1P/yvSn/8LAA//CwAP/w + sAD/88Az///9+P/++/L/8rwn//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/88I5//313////////PDP//K8J//wsAD/8LAA//CwAP/0xkn///79//745//xtxj/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAAoO+vAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsABu8LAA//CwAP/w + sAD/8LAA//O/Mf/+/Pb//vz2//PAMv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/1 + zFv//vvz///////646b/8bQN//CwAP/wsAD/8LAA//CwAP/wsAD/99R0///////878r/8LIH//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LEC//fTcf///fj////+//ngm//xswr/8LAA//CwAP/w + sAD/8LAA//CwAP/43I7///////votf/wsQL/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAbgAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA8LAAM/CwAPfwsAD/8LAA//CwAP/wsAD/8LAA//bQZ////////fPa//G1D//w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsgf/+d2T/////v///fn/99Ju//CwAf/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsQP/++m5///////424n/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//G1Ef/6 + 5q3///////778v/2zV3/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CzCP/88M7///////fSb//w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD38LAAMwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAA3wsADZ8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAB//rjpf//////+uSp//CwAf/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8rkd//ztxf// + /////fbj//PCO//wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/yuBr//vjp///+/P/0 + xUT/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/zwDX//fTc///////88dP/870r//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//O9K//+/PT//vz2//O/L//wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADZ8LAADQAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADysgAA8LAAlfCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bQO//3z2P// + ////9tFq//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//TFRP/++Oj///////vqvf/xtxj/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/1yE7////9//324//xtxX/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAH/9tFs///99/// + ////+eGg//G0DP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//bQaP// + /////PHT//GzCv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsACV8rIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAEHwsAD88LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/878v//789f///ff/88A0//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CxAv/31Xn///77///+/f/4 + 2oj/8LEF//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/5 + 3pT///////rmr//wsAL/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8bUP//rkqf///////vz0//bOYv/wsAH/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAB//rmr///////+d6U//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAPzw + sABCAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsAAJ8LAA2vCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/9s9l///////99Nv/8bUQ//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/xtRH/+uaw///////++u//9clR//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//GzCv/88dL///////bQaf/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//O/Mf/989r///////3y1v/z + vi7/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8bYV//335P////7/9chO//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bMJ//nfmO7///9WAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAH3wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAH/+uOj///////65av/8LAB//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/878w//302v///////PHQ//K8Jv/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//O+Lv/+/PX//vz0//O9K//wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAf/20Gf//vz2///////646X/8bQN//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/9MVF///+/P/++On/8rga//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//O/L//8 + 8dH///////7899v+/v4EAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsAAh8LAA9PCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/xtA3//fLX///////20mz/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//bOYP/+/PT///////niov/xtAz/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//bSbP///////PDP//GzCf/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/xtA3/+uOl///////+/Pb/9tBn//CwAf/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/+NuK///////76bn/8LEC//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CxA//31HP///z3///////657H/8bgZ9PCwACEAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/78AAPCwAKPwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/zvi7//vz1///9+P/z + wDX/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CzCP/535j////+///99//20Wr/8LAB//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LEC//rnsv//////+NyQ//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/874u//3y1v///////fTa//O/Mv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsgf//O/M///////3 + 03L/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/yuR7/++q8///////+ + +/P/9tBn//CxAv/wsAD/8LAAo/+/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsAAu8LAA/PCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/2z2P///////303f/xtRD/8LAA//CwAP/wsAD/8LAA//CwAP/y + uiD//O7J///////99uH/88E4//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bcW//335f// + /v3/9MdK//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//bOYv/+/PT///////rlqv/xtQ//8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/yvCf//vvz///9+P/zvzH/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/9ctY//757f///////O7J//K8J//wsAD/8LAA//CwAP/wsAD88LAALgAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LEAAPCwALDwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/6 + 4qL///////rmrf/wsAH/8LAA//CwAP/wsAD/9MZI//756///////++m5//G3Fv/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/9MZH///+/P/+9+f/8bcY//CwAP/wsAD/8LAA//G0DP/5 + 4qD////+///9+P/20mz/8LAB//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/2 + z2T///////3y1v/xswv/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bUQ//rio/////7///77//jYgv/w + sgb/8LAA//CwAP/wsAD/8LAA//CwAP/wsACw8rIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsAAs8LAA/fCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//G0DP/98tb///////bSbv/wsAD/8LED//fXfv// + /vz///79//jZhP/wsQT/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/+NuM///////76LX/8LEC//CwAP/zvSv//PHT///////99d3/88E1//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAf/65av///////nfmP/wsAD/8LAA//CwAP/w + sAD/8LAA//TEP//99d////////303P/zwjv/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP3w + sAAtAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAKHwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//O+LP/+/PT///34//THSf/76LX///////767v/1yE3/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsgf//O/M///////30m//9s1e//778/// + ////+uav//G1Ef/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//G2Ev/99uL////+//XJUf/wsAD/8LAA//CyB//42oj///78/////v/54Z7/8bQO//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAKMAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsAAb8LAA+fCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//bOYf/////////+///////8 + 8M7/8rsj//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/yvSn//vvz///+/P////7///35//fTcv/wsAL/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//TEQP///vz//vnr//K4G//z + vSr//PDN///////++ev/9cpT//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA+vCwABwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAH/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//nioP//////+eGe//GzCv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/20Gb///////314P/z + wjn/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//jZhv///////fLV//789v//////++m4//K4Gv/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAgAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsAAF8LAA4/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bQL//XJUv/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAf/303L/8bYU//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LIF//zuyf// + /////vz2//bSbv/wsQL/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsADj77AABQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAErwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8rsl//vswP/zvSv/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsABKAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA8LAAo/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAKMAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAAvwsADy8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA8vCwAAsA + AAAAAAAAAAAAAAAAAAAA8LAATvCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAATgAAAAAAAAAAAAAAAAAAAADwsACZ8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sACZAAAAAAAAAAAAAAAA8bEAAfCwAOLwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAOLxsQABAAAAAAAAAADwsAAm8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwACYAAAAAAAAAAPCwAGPwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAYwAAAAAAAAAA8LAAoPCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsACgAAAAAPCxAADwsADU8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwANTwsAAA8LAACfCwAPrw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA+vCwAAnwsAAz8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAM/CwAFnw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsABZ8LAAe/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAHvw + sACd8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAnPCwALfwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAC38LAAy/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAMvwsADf8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA3/CwAO7wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADu8LAA9PCwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAPTwsAD68LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA+vCwAP3wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LIG//CxA//wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LIF//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD98LAA9/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/yvCb//PHT//zx0//yuR7/8LAA//CwAP/wsAD/8LIH//vpt//88dP/++m5//CyB//4 + 24v//PHT//jckP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/xswv/+NiA//302/// + /fj//vz1//zux//1zFn/8LAB//CwAP/wsAD/9tBp//zx0//43ZD/8LAA//K7I//88dP//PHT//TDP//w + sAD/99Rz//zx0//42Yb/8LAA//CwAP/wswn/+Nd///303f///fj//vnr//ngmv/xtxb/8LAA//CwAP/1 + ylT//PHT//rmrf/wsAD/8LAA//CzCP/878z//PHT//K9Kf/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAPfwsADw8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//O+Lv////////////K7JP/w + sAD/8LAA//CwAP/42YP////////////1y1b/8LAA//rkqP//////+uau//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8bUP//zvzP/////////////9+f///v3////////////3137/8LAA//CwAP/3 + 13////////rmr//wsAD/9s9l////////////+NqH//CwAP/424z///////niov/wsAD/8LEC//vpuf// + //////77//zw0P/++vD///////302//xthP/8LAA//bQZv///////PHR//CwAP/wsAD/8bMJ//789/// + ////878y//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA8PCwAOjwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/874u////////////8rsk//CwAP/wsAD/88A1///9+v//////+uex//CwAf/w + sAD/+uSo///////65q7/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/54Jz///////778v/1 + ylP/8LIG//G3F//65ar////////+/P/zviz/8LAA//fXf///////+uav//CwAP/65Kf////////////8 + 7sf/8LAA//jbjP//////+eKi//CwAP/1yE/////////9+P/zwjr/8LAA//G2E//98tb///////jbjP/w + sAD/9tBm///////88dH/8LAA//CwAP/xswn//vz2///////zvzL/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADo8LAA1fCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/zvi7////////////y + uyT/8LAA//GzCf/88dP///////757f/yuR3/8LAA//CwAP/65Kj///////rmrv/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8bYT///9+f//////99Nw//CwAP/wsAD/8LAA//GzC//++Oj///36//bRaf/w + sAD/99d////////65q//8LEC//335f/////////+///9+f/xtQ//+NuM///////54qL/8LAA//ndkf// + ////++i0//CwAP/wsAD/8LAA//bSbv///////fLW//CwAP/20Gb///////zx0f/wsAD/8LAA//GzCf/+ + /Pb///////O/Mv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwANXwsADB8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//O+Lv////////////O9K//yuR3/+uWr///////++u7/9MM9//CwAP/w + sAD/8LAA//rkqP///////fLX//fXf//31nz/99Ny//XKU//xtAv/8LAA//CwAP/0x0r//////////v/y + uiD/8LAA//CwAP/wsAD/8LAA//PCOf/xthL/8LAA//CwAP/313////////rmr//yvSn///////746f/8 + 7sj///////THSv/424z///////niov/wsAD/+eKi///////54Z//8LAA//CwAP/wsAD/9ctY///////+ + +On/8LAA//bQZv///////PHS//CwAP/wsAD/8bMJ///89///////878y//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAwfCwAKvw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/874u//////// + ///////+//////////////////zuyP/1zFv/8LEC//CwAP/wsAD/+uSo//////////////////////// + //////////335P/zvi3/8LAA//bOYf////////78//CyCP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//fXf///////+uav//bRav//////+uSo//jYgP//////+NuL//jbjP//////+eKi//CwAP/4 + 2IL///////zvzP/wsAD/8LAA//CwAP/42YX///////zvy//wsAD/9tBm///////++Oj/8LEC//CwAP/x + tRD///77///////zvzH/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsACr8LAAjPCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/zvi7////////////989j//PDP//zw0P/99eD////+///////5 + 3ZP/8LAA//CwAP/65Kj///////zy1P/31Xb/99Z6//nfl//+/PT///////zx0P/wsAH/9c1c//////// + /vz/8LMI//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/99d////////65rD/+uWr///////2 + z2T/88I8///////88M3/+NuM///////54qL/8LAA//K8J////vr///////jaiP/yuyP/9ctZ//779P// + ////9tFp//CwAP/20Gb////////////31Xf/8bMK//bQZ/////////////K6H//wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAIzw + sABq8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//O+Lv// + //////////K7JP/wsAD/8LAA//CwAP/303L////////++//xtxj/8LAA//rkqP//////+uau//CwAP/w + sAD/8LAA//bQZv////////////K4G//0wzz////////////yvCf/8LAA//CwAP/wsAD/8LAA//CxAv/w + sAD/8LAA//CwAP/313////////votf/++Oj////+//K6If/wsgf//vrw///+/P/54Z////////niov/w + sAD/8LAA//bQaf///vz///////////////////////nioP/wsQL/8LAA//bQZv///////PHS//767/// + ///////////////87cT/8LEC//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAavCwAEjwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/874u////////////8rsk//CwAP/wsAD/8LAA//PBOP// + //////////PANP/wsAD/+uSo///////65q7/8LAA//CwAP/wsAD/9chP////////////8rsi//CyB//+ + +u////////jYg//wsAD/8LAA//CwAP/xswn//fTb//vsw//1yEz/8LAA//fXf////////fXf///////9 + 9Nr/8LAB//CwAP/757P///////313f//////+eKi//CwAP/wsAD/8LAA//O+L//424v/+uWr//nfl//0 + x0r/8LAB//CwAP/wsAD/88A1//jZhP/1y1f/8rsj//jcjf/65ar/99Z8//G1EP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sABH8LAAHPCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/z + vi7////////////2z2P/9MZG//TGRv/1yVL/++zB/////////ff/8bYT//CwAP/65Kj///////ztxf/0 + xkf/9MdK//bPZP/99d7///////756v/wsQT/8LAA//fWfP////////77//fXff/yvSr/88E3//votf// + //////78//O/Mv/wsAD/99d///////////7///////nfl//wsAD/8LAA//fSb//////////////////5 + 4qL/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CvABvysgAB8LAA6/CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//O+Lv////////////////////////////////// + //////////jZg//wsAD/8LAA//rkqP///////////////////////////////////vz/9cxb//CwAP/w + sAD/8LED//riov///////////////////////////////f/31nv/8LAA//CwAP/313////////////// + ////9cpT//CwAP/wsAD/874s/////v////////////niov/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sADr8bEAAQAAAADwsAC88LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8rof//rmr//65q7/+uat//rlq//65ar/+uOm//jcjf/0x0r/8LAB//CwAP/wsAD/99Rz//rmrv/6 + 5a3/+uWr//rlqv/646P/+NyN//PBOP/wsAD/8LAA//CwAP/wsAD/8LAB//XJUP/65q7//fLW//zx0v/6 + 5Kf/9MVC//CwAP/wsAD/8LAA//XLV//65q//+uav//rmrv/xtRL/8LAA//CwAP/wsQL/+uOk//rmr//6 + 5q//9tJv//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwALwAAAAAAAAAAPCwAILwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAAggAAAAAAAAAA8LAARPCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsABEAAAAAAAAAADvrwAM8LAA+fCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA+e+vAAwAAAAAAAAAAOytAADwsAC+8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAC+7K0AAAAAAAAAAAAAAAAAAPCwAHPw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAHMAAAAAAAAAAAAAAAAAAAAA8LAAJ/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAJwAAAAAAAAAAAAAAAAAAAADw + sQAB8LAAz/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAM/wsQABAAAAAAAAAAAAAAAAAAAAAAAAAADwsAB28LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAdgAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAPCwAB7wsAD78LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAPvwsAAeAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAAPCwALLwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAs/CwAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA8LAASvCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsABLAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADvrwAD8LAA2fCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA2vCwAAQAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsABl8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsABnAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAAnw + sADl8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA5fCwAAkAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAG/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsABvAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAA8LAACPCwAN7wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA3vCwAAgAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAX/CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsABfAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAP///x3//fl099R18fbSbf/20m3/9tFr//bQaP/20Gj/9tBo//bPZP/2z2P/9s9j//bOYf/2 + zV//9s1f//XNXv/1zFr/9cxa//XMWv/1y1b/9ctW//XLVv/1ylP/9clR//XJUf/1yVD/9chN//XITf/1 + yE3/9MZI//TGSP/0xkj/9MVF//TFRP/0xUT/9MRC//TEP//0xD//9MM///PCO//zwjv/88I7//PBN//z + wTb/88E2//PANP/zvzL/878y//O/Mf/zvi3/874t//O+Lf/yvSr/8r0p//K9Kf/yvCf/8rsk//K7JP/y + uyP/8rog//K6IP/yuiD/8rkc//K5HP/yuRz/8bga//G3GP/xtxj/8bcX//G2FP/xthT/8bYU//G1EP/x + tRD/8bUQ//G0Dv/xtAz/8bQM//GzC//wsgj/8LII//CyCP/wsQT/8LEE//CxBP/wsQL/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAx/GxAAMAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA////QP////////////////////// + //////////////////////////////////////////////////////////////////////////////// + //////////////////////////////////////////////////////////////////////////////// + //////////////////////////////////////////////////////////////////////////////// + ///////////////////////////////////////////////////////////////////////+/////v// + //7////+/////v////7///79///+/f///v3///79///+/f///v3///78///+/P///vz///78///++/// + /vv///77///++////vv///77///++////vr///76///9+f/+/Pb//vz2//789v/++/H//vvx//778f/+ + +u7//vnt//757f/++ev//vjo//746P/++Oj//ffk//335P/99+T//fbh//313//99d///fXe//302//9 + 9Nv//fTa//3y1v/99uCbAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAD///8a////Z////2r54Z+s9tFs//bSbP/303D/99Nw//fTcP/31HT/99R1//fUdf/3 + 1Xf/99Z5//fWef/31nr/99d+//fXfv/3137/+NiB//jYgv/42IL/+NmE//jah//42of/+NqH//jbi//4 + 24v/+NuL//jcjv/43ZD/+N2Q//ndkf/53pT/+d6U//nelP/535j/+d+Z//nfmf/54Jv/+eGd//nhnf/5 + 4Z7/+uKi//riov/64qL/+uOl//rkp//65Kf/+uSo//rlq//65av/+uWr//rmr//65q//+uav//rnsv/7 + 6LT/++i0//votf/76bn/++m5//vpuf/76r3/++u9//vrvf/768D/++zC//vswv/77ML//O3G//ztxv/8 + 7cb//O/K//zvy//878v//O/N//zwz//88M///PDP//zy1P/88tT//PLU//3z1//989j//fPY//3z2v/9 + 9N3//fTd//303f/99uH//fbh//324f/99+T//vfl//735f/+9+b//vjq//746v/++Or//vrt//767v/+ + +u7//vrw//778v/++/L//vvz//789v/+/Pb//vz2///9+v///vv////+/P///58AAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAA3w + sADd8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAH/8LAB//CwAf/wsAH/8LAB//CwAf/wsAH/8LAB//CwAf/wsAH/8LAB//CwAf/wsAH/8LAC//CwAv/w + sAL/8LEC//CxAt3xuiAO/v7+AQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAELwsAD98LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD98LAAQgAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAPCwAIjwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAIgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAABvCwAMXwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADF8LAABgAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA8LAAH/CwAOjwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA6PCwAB8AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAP/CwAPnw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAf/xtAv/870q//TGRv/1zV3/99Nx//fXf//4 + 24v/+d2R//nelf/53pX/+d2S//jbjP/42IH/99Rz//bOYP/0x0n/878v//G1D//wsQL/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAPnwsAA/AAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAZ/CwAP7wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAf/yuiD/9ctY//jcjf/7 + 6rr//fbj///+/f////7///36//756//989f//O7J//vqvP/76LX/+uex//rnsf/76LT/++q6//ztxv/8 + 8tT//vjo///9+f////7////+//746f/77MH/+d6W//bOYf/yvSn/8LEC//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD+8LAAZwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADp + qgAA8LAAgvCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LIG//TGR//535j//fTd/////v/++vD/++u+//jcj//2z2X/9MRA//K6IP/wsgj/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LIF//K4G//zwjr/9s1e//jaiP/7 + 6Lb//vjq/////v/+9+b/+uOk//XKVP/xtAv/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAIPpqgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAB8LAAmfCwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8rgb//jahv/99+X///36//vrv//31HT/878x//CxBP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAf/zvy//99Nx//nelP/535b/99Z5//TCO//w + sQP/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsQL/8rwo//bQaf/657L//vz1//767//5 + 35j/8r0p//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sACb8LAAAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsAAD8LAAofCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bQO//jbiv// + /Pb//fTb//fTcv/xtxj/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/z + wTX/++zC//votv/20mz/9MZG//TFRP/2z2P/+uSo//zwzv/1yE3/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/xtA7/9s9i//zvy////vv/+eKh//K4Gv/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAo++vAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADvrwAE8LAAo/CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//O+Lf/989n//fbj//XNXf/wsQT/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/9ctX//zvzP/zvzL/8LAA//G2FP/0x0n/9MdK//G2Ff/w + sAD/8rog//vpuv/31nr/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAB//TGR//88dP//vjq//TGRv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAKbv + rwAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAADvrwAE8LAAmfCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/yvCj//vnr//rnsf/x + thL/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//O/Mf/8 + 8M3/8bYS//CwAf/31Xj//PHT//nek//53ZL//PHS//fWfP/wsAH/8LIH//votv/1ylT/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CyCP/53pP///z3//TFRf/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsACa8K8ABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADw + sAAB8LAAhvCwAP7wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAB//vswv/76rv/8LIG//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/+uWs//TEQP/wsAD/9s5h//rlrP/wsgj/8LAA//CwAP/w + sgf/+uSo//bQZv/wsAD/8rke//zwzf/wsAL/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAf/535b//fbj//GzCv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD+8LAAh/CwAAIA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADsrQAA8LAAZ/CwAPnwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/yuiD////+//PANP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CxA//9 + 89j/8LEC//CwAP/87cX/8rkc//CwAP/wsAD/8LAA//CwAP/xtxj//O7J//CwAP/wsAD/++zB//K4G//w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//G2E/// + /ff/9MZI//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA+fCwAGjwsQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA8LAAQvCwAOvwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//O+L///////8rgb//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LIG//zy1P/wsAD/8LAA//zx0//wsgj/8LAA//CwAP/w + sAD/8LAA//CyBv/88tT/8LAA//CwAP/657D/8r0p//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LED//767v/1y1f/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAOzwsABDAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAIfCwAMjw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bMJ//756//3 + 1Xb/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAH//PHS//G1D//wsAD/+d+Z//XNXf/wsAD/8LAA//CwAP/wsAD/9ctY//nhnv/wsAD/8LEC//zx0//x + tA3/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/1 + yE3///77//K7Iv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsADJ8LAAIQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAB/CwAJHwsAD98LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/9tFr///89//1yE7/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/3133/99Z7//CwAP/xtxj//PDN//fVd//y + uyX/8rsk//fUdf/88M//8rga//CwAP/1yVL/+uOm//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/878x//746v/53pT/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD98LAAkvCwAAcAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAA8LEAAPCwAEjwsADj8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAH/+NmG///9+v/42of/8bQM//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//GzC//87sj/9cpV//CwAP/xtQ//99V4//vpuP/76bj/99Z5//G1EP/wsAD/88I5//zy1P/y + uR3/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LEF//bSbf/+ + +/P/+uSp//CyB//wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA4/CwAEnvrwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwABPwsACg8LAA/fCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/9ctX//746P/99uL/99Nx//G1EP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//G3Fv/76rz/+eCc//K8J//w + sAD/8LAA//CwAP/wsAD/8rga//jZhf/8783/8r0p//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8bMJ//bNXv/88dP//vvz//fUc//wsQP/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA/fCwAKDwrwATAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAPO0AADwsABA8LAA1PCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8bUQ//jYf//++Or//vvz//rjpP/1yVH/8bQO//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CxA//1zFn/++u+//zx0f/757P/+uew//zvzP/87sn/9tJs//GzCf/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsgj/9MVE//nelf/++ev//vvz//nek//y + uRz/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwANXw + sABB8rIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADw + sAAH8LAAb/CwAOvwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//GzCv/1 + zFr/++i1//789v///ff/++zD//jahv/1yVD/8roi//CxBP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8bQM//K8J//yvSr/8bUQ//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsQL/8rkc//TGSP/3 + 137/++m4//778v///vv/++zC//bRaf/xthL/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAOzwsABw8LAABwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAEvCwAInwsADz8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bUP//XITf/43I3//O3G//789P// + //7//vvy//zx0f/657D/+d6U//fXff/20Gn/9cxb//XITf/0xkf/9MRC//TEQf/0xkb/9MdM//XLWf/2 + 0Gb/99Z6//jdkP/65av//O/M//757f////7///35//zwz//535f/9ctX//G3F//wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAPPwsACL8LAAEwAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAPCwABfwsACI8LAA8fCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LIH//K9Kf/1ylP/99V3//nfmP/76LT//O/K//313v/+ + +er//vz1///9+f///v3////9///9+v/+/Pb//vns//324f/88M7/++m3//nhnf/31nz/9cxa//O/MP/x + swv/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAPHwsACJ8LAAFwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADw + sAAR8LAAdPCwAN/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CxAv/wsgX/8LIG//CyB//wsgf/8LIG//CyBf/w + sQP/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAN/wsAB08LAAEQAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAABfCwAE3wsACu8LAA+fCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA+fCwAK/w + sABO768ABQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAP+/AADwsAAW8LAAavCwAL3wsAD78LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD78LAAvfCwAGrwsAAW/78AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAA8LEAAPCwABXwsABd8LAAo/CwAOfwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAOfwsACj8LAAXfCwABXwsQAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAAvCwACrw + sABj8LAAnPCwANDwsAD38LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAPfwsADQ8LAAnPCwAGPw + sAAq768AAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAAO+vAAXwsAAp8LAAUfCwAHHw + sACQ8LAArfCwAMHwsADU8LAA5/CwAO/wsAD28LAA/PCwAPzwsAD28LAA7/CwAObwsADU8LAAwfCwAK3w + sACQ8LAAcfCwAFHwsAAp8LAABfGxAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA//////////// + ///////////////////////////////////////+AAB/////////////////gAAAAf////////////// + +AAAAAAf/////////////8AAAAAAA/////////////4AAAAAAAB////////////4AAAAAAAAH/////// + ////4AAAAAAAAAf//////////4AAAAAAAAAB//////////4AAAAAAAAAAH/////////4AAAAAAAAAAAf + ////////8AAAAAAAAAAAD////////8AAAAAAAAAAAAP///////+AAAAAAAAAAAAB////////AAAAAAAA + AAAAAP///////AAAAAAAAAAAAAA///////gAAAAAAAAAAAAAH//////wAAAAAAAAAAAAAA//////4AAA + AAAAAAAAAAAH/////MAAAAAAAAAAAAAAA/////gAAAAAAAAAAAAAAAH////4AAAAAAAAAAAAAAAA//// + /AAAAAAAAAAAAAAAAH////wAAAAAAAAAAAAAAAA////4AAAAAAAAAAAAAAAAH///8AAAAAAAAAAAAAAA + AA////AAAAAAAAAAAAAAAAAP///gAAAAAAAAAAAAAAAAB///wAAAAAAAAAAAAAAAAAP//4AAAAAAAAAA + AAAAAAAB//+AAAAAAAAAAAAAAAAAAf//AAAAAAAAAAAAAAAAAAD//wAAAAAAAAAAAAAAAAAAf/4AAAAA + AAAAAAAAAAAAAH/8AAAAAAAAAAAAAAAAAAA//AAAAAAAAAAAAAAAAAAAP/gAAAAAAAAAAAAAAAAAAB/4 + AAAAAAAAAAAAAAAAAAAf+AAAAAAAAAAAAAAAAAAAH/AAAAAAAAAAAAAAAAAAAA/wAAAAAAAAAAAAAAAA + AAAP4AAAAAAAAAAAAAAAAAAAB+AAAAAAAAAAAAAAAAAAAAfgAAAAAAAAAAAAAAAAAAAHwAAAAAAAAAAA + AAAAAAAAA8AAAAAAAAAAAAAAAAAAAAPAAAAAAAAAAAAAAAAAAAADgAAAAAAAAAAAAAAAAAAAAYAAAAAA + AAAAAAAAAAAAAAGAAAAAAAAAAAAAAAAAAAABgAAAAAAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAIAAAAAAAAAAAAAAAAAAAAGAAAAAAAAAAAAAAAAAAAABgAAAAAAAAAAAAAAAAAAAAYAAAAAA + AAAAAAAAAAAAAAGAAAAAAAAAAAAAAAAAAAABwAAAAAAAAAAAAAAAAAAAA8AAAAAAAAAAAAAAAAAAAAPA + AAAAAAAAAAAAAAAAAAAD4AAAAAAAAAAAAAAAAAAAB+AAAAAAAAAAAAAAAAAAAAfgAAAAAAAAAAAAAAAA + AAAH8AAAAAAAAAAAAAAAAAAAD/AAAAAAAAAAAAAAAAAAAA/4AAAAAAAAAAAAAAAAAAAf+AAAAAAAAAAA + AAAAAAAAH/wAAAAAAAAAAAAAAAAAAD/8AAAAAAAAAAAAAAAAAAA//gAAAAAAAAAAAAAAAAAAf/wAAAAA + AAAAAAAAAAAAAH/8AAAAAAAAAAAAAAAAAAD//AAAAAAAAAAAAAAAAAAA//+AAAAAAAAAAAAAAAAAAP// + wAAAAAAAAAAAAAAAAAP//+AAAAAAAAAAAAAAAAAH///gAAAAAAAAAAAAAAAAB///8AAAAAAAAAAAAAAA + AA////gAAAAAAAAAAAAAAAAf///8AAAAAAAAAAAAAAAAP////AAAAAAAAAAAAAAAAD////4AAAAAAAAA + AAAAAAB/////AAAAAAAAAAAAAAAA/////4AAAAAAAAAAAAAAAf/////AAAAAAAAAAAAAAAP/////4AAA + AAAAAAAAAAAH//////AAAAAAAAAAAAAAD//////8AAAAAAAAAAAAAD///////gAAAAAAAAAAAAB///// + //8AAAAAAAAAAAAA////////gAAAAAAAAAAAAf///////+AAAAAAAAAAAAf////////wAAAAAAAAAAAP + /////////AAAAAAAAAAAP/////////8AAAAAAAAAAP//////////wAAAAAAAAAP///////////AAAAAA + AAAP///////////8AAAAAAAAP////////////wAAAAAAAP/////////////gAAAAAAf///////////// + /gAAAAB////////////////gAAAH//////////////////////////////////////////////////8o + AAAAQAAAAIAAAAABACAAAAAAAABAAAARFwAAERcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAADwsAAc8LAASfCwAHDwsACP8LAApfCwALXw + sAC88LAAvPCwALXwsACl8LAAj/CwAHDwsABJ8LAAHPCwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAQ8LAAW/CwAKPwsADi8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADi8LAAo/CwAFvw + sAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA768AA/CwAEzwsACv8LAA+PCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA+PCwAK/wsABN768AAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAG8LAAZfCwANvw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwANvwsABl8LAABgAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPGxAADw + sABT8LAA2/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwANzwsABU768AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAPCwAB7wsAC38LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwALfwsAAeAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAPCwAFnwsADw8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA8PCwAFkA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA768ABPCwAJPwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAAk/CwAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAC/CwALbwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAC38LAADAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAP///wr///9p8LEFDvCwAMTw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8bUR//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//G0Dv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAMbw + sAAOAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD/ + //8E////wPfTct/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/9clQ//767//0yEz/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//XITf/++e3/9MRC//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAAw/CwAAoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA8LAAAvK8JrD99d//874u//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsQT/+NqI//zwz//1yE7//fXg//G4Gf/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LIF//jbiv/88ND/9ctY//303f/x + thP/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsACv8LAAAgAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAIPwsAD/9MZG//3y1f/xtA3/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/xtxf/++u9//riof/xswr/8LAA//bQaP/7 + 6bn/8LEC//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8rkd//ztxP/5 + 4Z3/8bMK//CwAP/31HX/+uat//CwAf/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAIMA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAEbwsAD98LAA//CwAP/4 + 2YP/+uOk//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/zwjr//fTd//bQaf/w + sAD/8LAA//CwAP/wsAH/+uav//fTcv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/9MdJ//314P/2zV//8LAA//CwAP/wsAD/8LEC//vqu//2z2X/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD98LAARgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwABDw + sADk8LAA//CwAP/wsAD/8LED//vrv//2z2X/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAf/2 + 0m7//fTb//PBNv/wsAD/8LAA//CwAP/wsAD/8LAA//G2FP/99N3/878x//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsQT/+NmF//zx0//zvSv/8LAA//CwAP/wsAD/8LAA//CwAP/yuBr//fXg//K8KP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAOTwsAARAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsACY8LAA//CwAP/wsAD/8LAA//CwAP/yuBr//fXf//O/L//wsAD/8LAA//CwAP/w + sAD/8LAA//G0DP/65Kb/++m5//G2FP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/9MVC//zy1P/x + swv/8LAA//CwAP/wsAD/8LAA//CwAP/yuBr/++vA//riov/xtAz/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//XJT//878z/8LIG//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/0xUL//fXeyP7+/gEA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAx8LAA/PCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//TFRP/9 + 8tb/8bQN//CwAP/wsAD/8LAA//K8KP/88dL/+NmD//CxA//wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/42oj/+eCa//CwAP/wsAD/8LAA//CwAP/0xUT//fXf//bPZP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/+d+X//jbi//wsAD/8LAA//CwAP/wsAD/8LAA//CyB//4 + 24z//PLU//PAM/zwsAAxAAAAAAAAAAAAAAAAAAAAAAAAAADwsQAA8LAAtvCwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/+NiB//rjpv/wsAD/8LAA//XKVf/99eD/9MdM//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LIG//zuyf/1yVL/8LAA//CxA//42ID//fLW//O+L//w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//GzCv/88tP/9MVE//CwAP/w + sAD/8LAA//O+Lf/88M//+d6U//GzCv/wsAD/8LAAtvKyAAAAAAAAAAAAAAAAAAAAAAAA8LAAM/CwAP7w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CxA//7673/9tFs//jcjf/8783/8rsi//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/yuyX//fXg//PANP/7 + 6rz/+uSn//G0Df/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/878w//313v/xthT/8LEC//fTcf/99d//9MdJ//CwAP/wsAD/8LAA//CwAP7wsAA0AAAAAAAAAAAA + AAAAAAAAAPCwAKTwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bgY//745//5 + 4Z3/8bMJ//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//bOYP/+/Pb/9tFp//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/303H/++m3//vqu//65q//8bYV//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAApQAAAAAAAAAAAAAAAPCwABTwsAD48LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/xtxf/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8roh//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAB//rlq//2z2T/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAPjwsAAUAAAAAAAAAADwsABo8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAaAAAAAAAAAAA8LAAufCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwALkA + AAAA8LAACvCwAPjwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD48LAACvCwAEHwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAEHwsAB28LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAB28LAAo/CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAAovCwAMXwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAMXwsADg8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADg8LAA8/CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA8/CwAPvw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAPvwsAD98LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//GzCf/20Wn/8LIH//CwAP/zvy//9s9j//K7JP/1y1n/8LAA//CwAP/wsAD/8LAA//CxA//1 + y1f/99d+//TGSP/wsAD/8rga//XLWf/xswn/9tFp//G1EP/1yVH/8roh//CxAv/1y1f/99Z6//O+LP/w + sAD/9MdK//O9K//wsQL/9tBo//GzCv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD98LAA9vCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/xtxf///////G2Ev/xtA3//fXf//jYgv/1ylT//fLW//CwAP/w + sAD/8LAA//CwAP/54Z3//PHR//jZhf/++Or/9tFp//TEP//989f/9MVD///////1ylT//O3F//XJUf/4 + 2IL//O/L//fUdf/++ez/8rwo//rnsv/20Gn/8LEE///++//xuBn/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA9vCwAOXwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bcX///////yuBv/+uKi//ztxv/w + sgf/9cpU//324f/0wz//878x//CxA//xtxf///79//K7JP/wsAD/9MdL//XNXf/0xD///fPX//jZhP/+ + +ev/+d6U//ztxf/1yVH//O/M//XKVf/wsAD/+uex//fTcP/657L/9tBp//CxBf///vv/8bgZ//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAOXw + sADN8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//G3F/// + /////vjp//757P/87sj/8rwl//XKVP/+/PT/++q8//324v/76bj/878w/////v/wsQT/8LAA//CwAP/w + sAD/9MQ///3z1//87cX/99Ny//3y1v/87cX/9clR//rkqP/53pX/8rof//313v/1yE3/+uey//nfmP/y + uiD////+//G2FP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsADN8LAArPCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/xtxf///////G2Ev/wsAD/+uWq//ndkv/1ylT//fLW//CwAP/zvi3///////K6IP// + /vv/8r0q//CwAP/zwjn/9MVE//TEP//99+T//vrw//GzCv/++Of//fXf//XJUf/yuBr/+uat//zw0P/3 + 1nv/8LAB//jah//43I///PDN//nelP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAArPCwAILwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bcX///////65ar/+uOl//767//2z2P/9cpU//768P/6 + 46T//PDQ//zw0P/wsAH/+NqI//313f/535j//vns//bRav/0xD////////vquv/wsAD/+uOm///////1 + yVH/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAIHwsABP8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CyCP/1y1f/9ctW//XKVP/z + wTb/8LAA//K5Hf/1y1f/9cpV//TITP/xtA7/8LAA//CwAP/0xED/9tFq//PCOv/wsAD/8bcW//XLV//z + vzD/8LAA//K9Kf/1y1f/8rkc//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sABP8LAAFPCwAP3wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD98LAAFOytAADwsADM8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAzOytAAAAAAAA8LAAffCwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAH0AAAAAAAAAAPCwACXw + sAD+8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP7w + sAAlAAAAAAAAAADwsAAA8LAAv/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAC/8LAAAAAAAAAAAAAAAAAAAPCwAFDwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAUQAAAAAAAAAAAAAAAAAAAADwsAAC8LAA1PCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA1PCwAAIAAAAAAAAAAAAAAAAA + AAAAAAAAAPCwAFHwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAFEA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD///10++m5/Pvotf/76LT/+uey//rnsf/65q//+uav//rlrf/6 + 5az/+uWq//rkqf/65Kj/+uOm//rjpf/646T/+uKi//niof/54Z//+eGe//nhnf/54Jv/+eCa//nfmP/5 + 35f/+d+W//nelP/53pP/+d2S//jdkP/43I//+NyN//jbjP/424v/+NuJ//jaiP/42ob/+NmG//jZhP/4 + 2IP/+NiC//jYgP/313//99d9//fWfP/31nv/99V5//fVeP/31Xb/99R1//fUdP/303L/99Nx//fTcP/2 + 0m7/9tJt//bQZ9jxsQABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA////IPvqu0nzwTj288E4//PCOf/z + wjr/9MM8//TDPf/0wz//9MRA//TEQf/0xUP/9MVD//TGRv/0xkb/9MZI//THSf/0x0r/9MhM//XITf/1 + yE//9clQ//XJUf/1ylP/9cpU//XKVf/1y1f/9ctY//XMWv/1zFr/9c1c//XNXf/2zV//9s5g//bOYf/2 + z2P/9s9k//bPZf/20Gf/9tBo//bRav/20Wv/9tFs//bSbv/20m7/99Nx//fTcf/31HP/99R0//fUdf/3 + 1Xf/99V4//fWev/31nv/99Z8//jYgvb+/PdrAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAA8LAAcvCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAByAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAPCwAAHwsACz8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsACz8LAAAQAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAEPCwANfwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LMI//PCOf/2 + 0Gj/+NuM//riov/646T/+uOj//rjo//646P/+uOk//riov/43I//9tFr//TDPv/xswv/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sADX8LAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADw + sAAh8LAA5fCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CyB//1 + zVz/+uOm//nioP/20m3/9MM9//G3GP/wsQL/8LAA//K8KP/0x0v/874t//CwAf/wsAH/8bcV//PCOv/2 + 0Gj/+eGd//rkqP/2z2X/8bMK//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsADm8LAAIQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAPCwACrwsADo8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//TFRf/657D/9cpU//CyBv/wsAD/8LAA//CwAP/wsAD/8bcW//fXff/1yE7/9MZH//TGSP/3 + 133/8rkf//CwAP/wsAD/8LAA//CwAP/wsQT/9MdM//rmrv/1ylL/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADp8LAAKwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAJ/CwAODwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//PCO//535f/8LEF//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//fWe//y + uR3/+NiA//THSf/313//8rkc//fXff/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsQL/+NqI//TITP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADh8LAAKAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADw + sAAa8LAAyfCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/53ZP/8bYU//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CxAv/20Wv/9tBm//GzCf/wsAD/8LII//bQZ//1zVz/8bUR//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CyBv/54qH/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADK8LAAGgAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAPCwAAjwsACY8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/9ctY//bSb//w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/99V2//O+LP/20Gj/8bYS//bQZ//zvi7/99Rz//CxA//w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/1zFr/9tJs//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sACY8LAACAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LEAAPCwAE/wsADn8LAA//CwAP/w + sAD/8LAA//CwAP/31Hb/+d+X//K6IP/wsAD/8LAA//CwAP/wsAD/8LAA//PCOv/20Wv/870r//XMXP/y + vSn/9s9j//TGRv/wsAD/8LAA//CwAP/wsAD/8LAA//K4Gv/43I7/+NmE//CxAv/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAOfwsABQ768AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAA8LAAEPCwAJLwsAD68LAA//CwAP/wsAD/8LAA//K7JP/43ZD/+uSo//fTcv/zwTb/8bMJ//CwAP/w + sAD/8bcX//bQZ//20m3/9tFp//K5Hf/wsAD/8LAA//CyB//zvzH/9tJs//rjpv/535b/874s//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA+vCwAJPwsAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAJ/CwAKTwsAD88LAA//CwAP/wsAD/8LAA//CxBP/z + wTf/99Nw//ngm//646T/+uOk//rjo//54qD/+eGf//nioP/64qP/+uOk//rjpP/54Z3/99R1//TCPP/w + sgb/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD88LAApPCwACcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAIfCwAIzw + sADp8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAH/8LED//CxBP/wsQP/8LAB//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAOnwsACM8LAAIQAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA8LAABvCwAErwsACb8LAA4vCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADi8LAAm/CwAErwsAAGAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAAHwsAAj8LAAW/CwAInw + sACw8LAAz/CwAOXwsAD18LAA/PCwAPzwsAD18LAA5fCwAM/wsACw8LAAifCwAFvwsAAj768AAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAP//////////////AAD///// + //gAAB//////wAAAA/////8AAAAA/////AAAAAA////4AAAAAB////AAAAAAD///wAAAAAAD//+AAAAA + AAH//AAAAAAAAP/8AAAAAAAAf/wAAAAAAAA//AAAAAAAAD/4AAAAAAAAH/AAAAAAAAAP8AAAAAAAAAfg + AAAAAAAAB8AAAAAAAAADwAAAAAAAAAPAAAAAAAAAA4AAAAAAAAABgAAAAAAAAAGAAAAAAAAAAQAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAACAAAAAAAAAAYAAAAAAAAABgAAAAAAAAAHAAAAAAAAAA8AAAAAAAAAD4AAAAAAAAAfg + AAAAAAAAB+AAAAAAAAAP+AAAAAAAAB/4AAAAAAAAH/wAAAAAAAA//gAAAAAAAH//AAAAAAAA//+AAAAA + AAH//8AAAAAAA///4AAAAAAH///wAAAAAA////wAAAAAP////wAAAAD/////wAAAA//////wAAAP//// + //4AAH//////////////KAAAADAAAABgAAAAAQAgAAAAAAAAJAAAERcAABEXAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA768AAPCwAAXwsAAM8LAAD/CwAA/wsAAM8LAABe+vAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsAAE8LAAMvCwAHHwsACm8LAAz/CwAOnwsAD28LAA/fCwAP3wsAD28LAA6fCwAM/w + sACm8LAAcvCwADLwsAAEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA8LAALPCwAI/wsADh8LAA/vCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP7wsADh8LAAj/CwAC0AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA8LAAAfCwADzwsAC68LAA/vCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP7wsAC68LAAPfCwAAEA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAe8LAAqvCwAP3wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA/fCwAKrwsAAeAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAFrwsADt8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADt8LAAWwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAG8LAAkvCwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAJPwsAAGAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA////E/CwAArwsACv8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sACw8LAACgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD///8A////nPTHScTw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CxBP/42YX/9s5f//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//XKU//424r/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAAtfCwAAYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADw + sAAC8bcYn/vquv/xthT/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bcX//rmrv/2 + zV7/+uaw//K8Jv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsgj/+NuM//jbi//4 + 3I3/9clS//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAJ7wsAACAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsABs8LAA/vPANP/65Kb/8LED//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/z + wjr/++m4//O+Lf/wsAD/8rkd//votf/wsgj/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//K6If/7 + 57P/9clR//CwAP/wswj/++i2//K4G//wsAD/8LAA//CwAP/wsAD/8LAA//CwAP7wsABsAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAPCwACzwsAD18LAA//CwAP/20Wv/99Rz//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//bRbP/646T/8bUQ//CwAP/wsAD/8LAA//XKU//42ob/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/9chN//votv/yuyP/8LAA//CwAP/wsAD/8rwo//rmr//wsQP/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD18LAALAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAAvCwAMPwsAD/8LAA//CwAP/wsAH/+uKi//PCOv/w + sAD/8LAA//CwAP/xtA3/+eGe//fUdP/wsAL/8LAA//CwAP/wsAD/8LAA//CwAP/53pT/9MVF//CwAP/w + sAD/8LAA//CyB//42oj/+N2Q//CyBv/wsAD/8LAA//CwAP/wsAD/8LAA//bPZP/31Hb/8LAA//CwAP/w + sAD/8LAA//CwAP/zwDX/++m33vPCOgIAAAAAAAAAAAAAAAAAAAAA8LAAVvCwAP/wsAD/8LAA//CwAP/w + sAD/8bUP//vquv/xtxX/8LAA//K8KP/76bf/9MRB//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/x + tAz/++m4//G2FP/wsAD/8rke//rnsv/1ylX/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CxAv/6 + 4qL/88E1//CwAP/wsAD/8LEE//fVef/64qL/8bYV//CwAFYAAAAAAAAAAAAAAADwsAAE8LAA0vCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//PAM//65Kj/9cpV//vnsv/yuRz/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/878x//rkpv/0x0v/++m3//K7Jf/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/xthT/++q6//G0C//yuiH/+uey//bOX//wsQL/8LAA//CwANPwsAAEAAAAAAAAAADw + sABJ8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/20Gf/+NyO//CyBf/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//fSb//53pb/8bMJ//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/9MRA//vqvP/657L/8rsi//CwAP/wsAD/8LAA//CwAP/w + sABKAAAAAO+vAADwsACs8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAf/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//TEQf/wsgX/8LAA//CwAP/w + sAD/8LAA//CwAP/wsACs768AAPCwAA7wsADy8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADy8LAADvCwAErwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAASvCwAIXwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAhfCwALTw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAAtPCwANjwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA2PCwAO/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA7/CwAPvwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA+/CwAPzwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/99R1//CyCP/yuBv/99Z8//TGSP/zwTb/8LAA//CwAP/w + sQT/99Jv//ngmv/0wz7/8rgb//XMWv/1ylX/88E4//fTcP/wsgj/9tJu//ndkf/yuyX/9MdL//O+LP/0 + xkj/874u//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA/PCwAPLw + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD//PHQ//G1EP/65q//9s5i//fXf//2 + zmL/8LAB//CwAP/20Wz/+d+X//O/Mf/77cP/88E3//niov/87sj/+d+W//zuyP/1yU//+uKj//PBNv/7 + 6rv/+NmG//XITv/32ID/9clS//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA8vCwAN3wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD//PHQ//vswv/9 + 9uL/88A1//fXf//88tT//O7J//bRaf/64qH/9MVE//CwAP/wsQT/878w//votP/76bj/++u///zuyP/1 + yE//+uKi//PAMv/7673/+NmG//bRav/43ZD/9clQ//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA3fCwALvwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD//PHQ//G3Fv/0yEz/+uWs//fXf//20Gf/88A0//zux//313z/99V3//G0DP/313z/88E2//757f/3 + 1Xb/+uSm//324f/xswr/9tJu//nelf/yuyX/9MhM//fUdf/53ZL/8bUR//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAu/CwAI/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/+eGe//rns//657H/9MVD//bOYP/76bf/++i0//XITv/xtA3/+eCb//vqvP/2 + 0m7/8rsk//vswf/zviz/9clS//vpuP/wsgb/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAj/CwAFbwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAVvCwABbw + sAD48LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD48LAAFu+vAADwsAC88LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAC8768AAAAAAADwsABd8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsABdAAAAAAAAAADwsAAJ8LAA4/CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAOPwsAAKAAAAAAAAAAAAAAAA8LAAcPCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAHAAAAAAAAAAAAAAAAAA + AAAA/ffkSPjbiv342of/+NqG//jZhf/42YP/+NiC//jYgP/413//99d+//fXfP/31nv/99Z6//fVeP/3 + 1Xf/99R2//fUdP/31HP/99Ny//fTcP/30m//9tJt//bRbP/20Wv/9tFp//bQaP/20Gb/9s9l//bPZP/2 + z2P/9s5h//bOYP/2zV7/9c1d//XMXP/1zFr/9cxZ//XLWP/1y1b/9cpV//XKVP/1yVL/9MhM6fCwAAgA + AAAAAAAAAAAAAAAAAAAA////EvfUdlfyvSr8870r//O+LP/zvi3/878v//O/MP/zvzH/88Az//PANP/z + wTX/88E3//PBOP/zwjn/88I7//TDPP/0wz3/9MM///TEQP/0xEL/9MVD//TFRP/0xUX/9MZH//TGSP/0 + x0r/9MdL//XITP/1yE7/9chP//XJUP/1yVL/9cpT//XKVP/1y1b/9ctX//XLWP/1zFr/9cxb//XNXP/2 + zV/8++3FagAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAADwsACP8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsACP8LAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAI8LAAwPCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//G0DP/0wz3/9s9l//fWev/3 + 1nv/99Z6//fWev/31nv/9tJu//THS//yuBr/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAMDwsAAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAA8LAAEvCwANPwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CyBf/1y1j/+NiB//fTcv/0 + wz//8bcW//CxAv/zwTf/9clS//TGSP/xswn/8bQN//O/Mf/2z2P/+NiA//fTcP/xthX/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA1PCwABMAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAPCwABrwsADR8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8bQN//jbi//z + vzD/8LAA//CwAP/wsAD/8LAA//XKVf/0yEz/9cpU//XITf/2zmH/8bMJ//CwAP/wsAD/8LAA//G2Ff/3 + 13//88A1//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADS8LAAGgAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAU8LAAvfCwAP/wsAD/8LAA//CwAP/w + sAD/9tBm//K4G//wsAD/8LAA//CwAP/wsAD/8LAB//XKUv/1y1f/8LAA//TGRv/yuyX/9MRA//CwAP/w + sAD/8LAA//CwAP/wsAH/+NiA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAL3wsAAUAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAABfCwAIrw + sAD78LAA//CwAP/wsAD/878x//bSbP/wsQL/8LAA//CwAP/wsAD/8LAA//XNXf/1yVH/9MZI//bPY//0 + wz3/8rsk//CwAP/wsAD/8LAA//CwAP/zwTb/9tFq//CwAP/wsAD/8LAA//CwAP/wsAD78LAAivCwAAUA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAPCwAADwsABA8LAA0/CwAP/wsAD/8LAA//PBOP/42YT/9ctY//G2FP/wsAD/8LAA//K6If/1 + zFn/9cxZ//XKVf/0wz7/8LAA//CwAP/xswn/9MQ///fXf//2zmD/8LEC//CwAP/wsAD/8LAA//CwANPw + sABA8bEAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAB/CwAGrwsADi8LAA//CwAP/wsAL/8r0q//bRaf/3 + 1nz/99Z7//fWe//31nn/99Z8//fWef/31nv/99Z7//fWfP/31HT/9MRB//CyBv/wsAD/8LAA//CwAP/w + sADj8LAAa/CwAAcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAH8LAAW/CwAL/w + sAD58LAA//CwAP/wsAD/8LAA//CwAP/wsAH/8LED//CxAv/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD58LAAv/CwAFvwsAAHAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAO+vAADwsAAc8LAAYfCwAKHwsADV8LAA9PCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAPTw + sADV8LAAofCwAGHwsAAc768AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADvrwAB8LAAC/CwAB/wsAAz8LAAPfCwAD3w + sAAz8LAAH/CwAAvwsAABAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAP//8A///wAA//8AAP//AAD//AAAP/8AAP/gAAAH + /wAA/8AAAAP/AAD/gAAAAf8AAP4AAAAAfwAA+AAAAAA/AADwAAAAAB8AAPAAAAAADwAA8AAAAAAPAADg + AAAAAAcAAMAAAAAAAwAAwAAAAAADAACAAAAAAAEAAIAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACAAAAAAAEAAIAAAAAA + AQAAwAAAAAADAADAAAAAAAMAAMAAAAAABwAA4AAAAAAHAADwAAAAAA8AAPgAAAAAHwAA/AAAAAA/AAD+ + AAAAAH8AAP8AAAAA/wAA/4AAAAH/AAD/4AAAB/8AAP/4AAAf/wAA//4AAH//AAD//+AH//8AACgAAAAg + AAAAQAAAAAEAIAAAAAAAABAAABEXAAARFwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAH8LAALvCwAE3wsABc8LAAXPCwAE3wsAAu8LAABwAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAPCwABTwsABu8LAAv/CwAPjwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD48LAAv/CwAG7wsAAUAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAPCwABXwsACR8LAA9vCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAPbwsACS8LAAFQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsABa8LAA7fCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADt8LAAWgAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAADwsAAD8LAAk/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAk/CwAAMA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA////TvK7JazwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8bYU//XKU//wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//XJUv/xtRD/8LAA//CwAP/w + sAD/8LAApvCwAAIAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADxtAyN+NuK//CxA//wsAD/8LAA//CwAP/w + sAD/8LAA//PBNv/42IH/9s9l//PANf/wsAD/8LAA//CwAP/wsAD/8LAA//CyB//31nz/9chN//jZhP/w + sAD/8LAA//CwAP/wsAD/8LAAjQAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAT/CwAP7yuiL/99Ny//CwAP/w + sAD/8LAA//CwAP/2zmH/9s1f//CwAP/wsAD/+NmE//G0DP/wsAD/8LAA//CwAP/yuyL/+NuK//G3GP/w + sAD/88E2//XMW//wsAD/8LAA//CwAP/wsAD+8LAATwAAAAAAAAAAAAAAAPCwAAzwsADl8LAA//CwAP/1 + yU//9MVF//CwAP/xswr/+NiC//PANP/wsAD/8LAA//CwAP/xtRH/+NiA//CwAP/wsAD/9clP//fTcf/w + sQP/8LAA//CwAP/wsAD/9tJt//K7JP/wsAD/8LAA//K7Jf/42YXw8LEFDAAAAAAAAAAA8LAAevCwAP/w + sAD/8LAA//CwAP/31nr/9MM+//jaif/xthP/8LAA//CwAP/wsAD/8LAA//CwAP/0wz3/9cxZ//fWev/0 + xUT/8LAA//CwAP/wsAD/8LAA//CwAP/wsQL/+NuJ//CyBf/2zV//9tFr//CxAv/wsAB6AAAAAPCwAAXw + sADn8LAA//CwAP/wsAD/8LAA//CyBv/20Gf/8LEC//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/2 + zV7/8rga//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/yuRz/+eKg//O/Mf/wsAD/8LAA//CwAOfw + sAAF8LAASPCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAEjwsACQ8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAAkPCwAMbwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADG8LAA6fCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAOnwsAD78LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA+/CwAPzwsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/2zmL/8bMK//fXff/20Wr/8LAA//CwAP/303L/+NyN//O/Mf/2zV//99Rz//bOYv/2 + 0Wr/+NiC//THSf/yvCf/9s5h//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD88LAA7PCwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//jbi//646T/99Jv//nhn//42YP/9MRA//jaif/xthP/88E3//vrvv/6 + 57L/+NuL//nfl//20Wv/+NqI//THSf/424n/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAOzw + sADL8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/+NuL//XLWP/646T/+eCc//bQaP/31nz/+uKj//fSb//0 + x0v//fbj//bQZv/54qD/878y//XKU//yuyL/9ctX//K7Jf/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAAy/CwAJjwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/xtxj/8r0r//G0Df/yuR3/8rwo//CxA//x + tRD/8r0p//CyBf/yuiL/8bMK//K5Hf/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsACY8LAAUvCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAFLwsAAJ8LAA7/CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsADv8LAACQAAAADwsACJ8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAIoAAAAAAAAAAPnelTH1zFv+9cxZ//XLWP/1 + y1f/9ctW//XKVP/1ylP/9clR//XJUP/1yE//9chN//TITP/0x0v/9MdJ//TGSP/0xkb/9MVF//TFRP/0 + xUL/9MRB//TEQP/0wz7/9MM9//PCPP/zwjr/88I5//PBN//zwDP18LAAFAAAAAAAAAAA////CPTEP2zy + uRz/8rke//K6H//yuiD/8roi//K7I//yuyT/8rwm//K8J//yvCj/8r0q//O9K//zviz/874u//O/L//z + vzD/878y//PAM//zwDT/88E2//PBN//zwjj/88I6//PCO//0wzz/9MM+//fXfXUAAAAAAAAAAAAAAAAA + AAAA8LAAAPCwAKbwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//G1EP/0wz3/9clR//XJUv/1 + yVL/9MhM//K9Kv/wsQP/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsACm8LAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAA8LAACPCwAL7wsAD/8LAA//CwAP/wsAD/8LAA//TDP//1y1f/9MVD//G3Ff/y + vCX/9MRC//TDPf/xtA3/8r0o//XJUv/1zFr/8bYV//CwAP/wsAD/8LAA//CwAP/wsAD/8LAAvvCwAAgA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAACvCwALHwsAD/8LAA//CwAP/zwDP/874s//CwAP/w + sAD/8LAB//XMWv/zwDX/9MVC//PCO//wsAD/8LAA//CwAP/2zV//8LAA//CwAP/wsAD/8LAA//CwALHw + sAAKAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAAvCwAHnwsAD58LAA//G3Fv/2 + zV//8LMI//CwAP/wsAD/9clS//TEQP/0xkj/878v//CwAP/wsAD/8r0q//XKU//wsAD/8LAA//CwAPnw + sAB68LAAAgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwACnw + sACx8LAA/vGzCf/1yE//9cpU//XJUv/1y1f/+NmF//fTcv/1yVL/9cpT//XKVf/zvzH/8LAA//CwAP7w + sACx8LAAKQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAADwsAAr8LAAjvCwAN/wsAD/8LAA//CwAP/wsQL/8LAB//CwAP/wsAD/8LAA//CwAN/w + sACO8LAAKwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA8LAAAPCwACDwsABO8LAAbfCwAHzwsAB88LAAbfCwAE7w + sAAg768AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA//AP//+AAf/+ + AAB//AAAP/AAAA/gAAAH4AAAB8AAAAOAAAABgAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAIAAAAGAAAABgAAAA8AAAAPgAAAH8AAAD/gAAB/+AAB//4AB///gB/8o + AAAAEAAAACAAAAABACAAAAAAAAAEAAARFwAAERcAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAAXw + sABL8LAAi/CwAKrwsACq8LAAi/CwAEvwsAAFAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAFfw + sADh8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA4fCwAFcAAAAAAAAAAAAAAAAAAAAA////E/GzC5Dw + sAD/8LAA//CwAP/yuBr/8LAA//CwAP/wsAD/8LAA//G4Gf/wsAD/8LAAj/CwAAEAAAAAAAAAAPCxBHf0 + xkj/8LAA//CwAP/0wz3/88I6//O/Mf/wsAD/8bMJ//THSf/0xEL/8bcX//CwAP/wsAB3AAAAAPCwACLw + sAD48bYU//TEP//0x0r/8bQN//CwAP/zwDP/88A1//TEQf/wsAH/8LAA//TGR//xuBn/9MVF+/CwACLw + sACN8LAA//CwAP/yuBv/8LAB//CwAP/wsAD/8LAA//K5Hv/wsAD/8LAA//CwAP/wsgf/88A0//CwAP/w + sACN8LAA1fCwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA1fCwAPjwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAPjwsAD68LAA//CwAP/zwjv/9tBm//bPY//1yE//9MRC//jdkP/31nz/99Nw//XLV//w + sAD/8LAA//CwAP/wsAD68LAA2PCwAP/wsAD/8r0p//XITf/1yVL/9chN//PCOv/1zV3/9MI8//K5Hf/y + uh//8LAA//CwAP/wsAD/8LAA2PCwAJLwsAD/8LAA//CwAP/wsAD/8LAA//CwAP/wsAD/8LAA//CwAP/w + sAD/8LAA//CwAP/wsAD/8LAA//CwAJLyvCcv874t//O+LP/yvSr/8r0p//K8KP/yvCb/8rsl//K7JP/y + uyL/8roh//K6H//yuR7/8rkd//K4Gv3wsAAo////AvK4G4TxtQ//8bUQ//G2Ev/xthP/8rwo//TDP//0 + wz//8rsk//K4Gv/yuBv/8rkd//K5Hv/zwTiHAAAAAAAAAADwsAAC8LAAnvCwAP/xtA3/878w//G3Fv/0 + wz3/878y//K5H//zwDP/8LAA//CwAP/wsACe8LAAAgAAAAAAAAAAAAAAAPCwAAHwsABn8LIG6/O/MP/y + vSn/9cxc//XIT//yvSr/870r//CwAOvwsABn8LAAAQAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAPCwAAvw + sABb8LAAm/CwAbrwsAC68LAAm/CwAFvwsAALAAAAAAAAAAAAAAAAAAAAAPAPAADgBwAAgAEAAIABAAAA + AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABAACAAQAAwAMAAPAPAAA= + + + \ No newline at end of file diff --git a/RPCMon/FormBuildDB.Designer.cs b/RPCMon/FormBuildDB.Designer.cs new file mode 100644 index 0000000..4c1dc01 --- /dev/null +++ b/RPCMon/FormBuildDB.Designer.cs @@ -0,0 +1,287 @@ +using System.Drawing; +using System.Windows.Forms; + +namespace RPCMon +{ + partial class FormBuildDB + { + /// + /// Required designer variable. + /// + private System.ComponentModel.IContainer components = null; + + /// + /// Clean up any resources being used. + /// + /// true if managed resources should be disposed; otherwise, false. + protected override void Dispose(bool disposing) + { + if (disposing && (components != null)) + { + components.Dispose(); + } + base.Dispose(disposing); + } + + #region Windows Form Designer generated code + + /// + /// Required method for Designer support - do not modify + /// the contents of this method with the code editor. + /// + private void InitializeComponent() + { + this.components = new System.ComponentModel.Container(); + System.ComponentModel.ComponentResourceManager resources = new System.ComponentModel.ComponentResourceManager(typeof(FormBuildDB)); + this.buttonBuild = new System.Windows.Forms.Button(); + this.labelRPCFolder = new System.Windows.Forms.Label(); + this.textBoxFolderForRPC = new System.Windows.Forms.TextBox(); + this.checkBoxRecursive = new System.Windows.Forms.CheckBox(); + this.comboBox1 = new System.Windows.Forms.ComboBox(); + this.listViewRPCFiles = new System.Windows.Forms.ListView(); + this.columnHeaderFileName = ((System.Windows.Forms.ColumnHeader)(new System.Windows.Forms.ColumnHeader())); + this.columnHeaderHasRpc = ((System.Windows.Forms.ColumnHeader)(new System.Windows.Forms.ColumnHeader())); + this.buttonStop = new System.Windows.Forms.Button(); + this.statusStrip1 = new System.Windows.Forms.StatusStrip(); + this.toolStripStatusLabelTotalFiles = new System.Windows.Forms.ToolStripStatusLabel(); + this.toolStripStatusLabelRPCFiles = new System.Windows.Forms.ToolStripStatusLabel(); + this.label1 = new System.Windows.Forms.Label(); + this.textBoxSaveFile = new System.Windows.Forms.TextBox(); + this.buttonJumpFolder = new System.Windows.Forms.Button(); + this.toolTipJumpButton = new System.Windows.Forms.ToolTip(this.components); + this.buttonClear = new System.Windows.Forms.Button(); + this.textBoxExcludedFolders = new System.Windows.Forms.TextBox(); + this.label2 = new System.Windows.Forms.Label(); + this.statusStrip1.SuspendLayout(); + this.SuspendLayout(); + // + // buttonBuild + // + this.buttonBuild.Location = new System.Drawing.Point(12, 100); + this.buttonBuild.Name = "buttonBuild"; + this.buttonBuild.Size = new System.Drawing.Size(75, 23); + this.buttonBuild.TabIndex = 0; + this.buttonBuild.Text = "Build"; + this.buttonBuild.UseVisualStyleBackColor = true; + this.buttonBuild.Click += new System.EventHandler(this.buttonBuild_Click); + // + // labelRPCFolder + // + this.labelRPCFolder.AutoSize = true; + this.labelRPCFolder.Location = new System.Drawing.Point(12, 23); + this.labelRPCFolder.Name = "labelRPCFolder"; + this.labelRPCFolder.Size = new System.Drawing.Size(82, 13); + this.labelRPCFolder.TabIndex = 1; + this.labelRPCFolder.Text = "Folder for RPC: "; + // + // textBoxFolderForRPC + // + this.textBoxFolderForRPC.Location = new System.Drawing.Point(100, 20); + this.textBoxFolderForRPC.Name = "textBoxFolderForRPC"; + this.textBoxFolderForRPC.Size = new System.Drawing.Size(244, 20); + this.textBoxFolderForRPC.TabIndex = 2; + this.textBoxFolderForRPC.Text = "C:\\Windows"; + // + // checkBoxRecursive + // + this.checkBoxRecursive.AutoSize = true; + this.checkBoxRecursive.Location = new System.Drawing.Point(100, 46); + this.checkBoxRecursive.Name = "checkBoxRecursive"; + this.checkBoxRecursive.Size = new System.Drawing.Size(74, 17); + this.checkBoxRecursive.TabIndex = 3; + this.checkBoxRecursive.Text = "Recursive"; + this.checkBoxRecursive.UseVisualStyleBackColor = true; + // + // comboBox1 + // + this.comboBox1.DropDownStyle = System.Windows.Forms.ComboBoxStyle.DropDownList; + this.comboBox1.FormattingEnabled = true; + this.comboBox1.Items.AddRange(new object[] { + "All", + "*.exe", + "*.dll", + "*.com"}); + this.comboBox1.Location = new System.Drawing.Point(359, 19); + this.comboBox1.Name = "comboBox1"; + this.comboBox1.Size = new System.Drawing.Size(121, 21); + this.comboBox1.TabIndex = 5; + // + // listViewRPCFiles + // + this.listViewRPCFiles.Anchor = ((System.Windows.Forms.AnchorStyles)((((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Bottom) + | System.Windows.Forms.AnchorStyles.Left) + | System.Windows.Forms.AnchorStyles.Right))); + this.listViewRPCFiles.Columns.AddRange(new System.Windows.Forms.ColumnHeader[] { + this.columnHeaderFileName, + this.columnHeaderHasRpc}); + this.listViewRPCFiles.HideSelection = false; + this.listViewRPCFiles.Location = new System.Drawing.Point(2, 178); + this.listViewRPCFiles.Name = "listViewRPCFiles"; + this.listViewRPCFiles.Size = new System.Drawing.Size(555, 314); + this.listViewRPCFiles.TabIndex = 8; + this.listViewRPCFiles.UseCompatibleStateImageBehavior = false; + this.listViewRPCFiles.View = System.Windows.Forms.View.Details; + this.listViewRPCFiles.ColumnClick += new System.Windows.Forms.ColumnClickEventHandler(this.listViewRPCFiles_ColumnClick); + // + // columnHeaderFileName + // + this.columnHeaderFileName.Text = "File Name"; + this.columnHeaderFileName.Width = 125; + // + // columnHeaderHasRpc + // + this.columnHeaderHasRpc.Text = "Has RPC?"; + this.columnHeaderHasRpc.Width = 83; + // + // buttonStop + // + this.buttonStop.Location = new System.Drawing.Point(100, 100); + this.buttonStop.Name = "buttonStop"; + this.buttonStop.Size = new System.Drawing.Size(75, 23); + this.buttonStop.TabIndex = 9; + this.buttonStop.Text = "Stop"; + this.buttonStop.UseVisualStyleBackColor = true; + this.buttonStop.Click += new System.EventHandler(this.buttonStop_Click); + // + // statusStrip1 + // + this.statusStrip1.Items.AddRange(new System.Windows.Forms.ToolStripItem[] { + this.toolStripStatusLabelTotalFiles, + this.toolStripStatusLabelRPCFiles}); + this.statusStrip1.Location = new System.Drawing.Point(0, 498); + this.statusStrip1.Name = "statusStrip1"; + this.statusStrip1.Size = new System.Drawing.Size(555, 24); + this.statusStrip1.TabIndex = 10; + this.statusStrip1.Text = "statusStrip1"; + // + // toolStripStatusLabelTotalFiles + // + this.toolStripStatusLabelTotalFiles.BorderSides = System.Windows.Forms.ToolStripStatusLabelBorderSides.Right; + this.toolStripStatusLabelTotalFiles.Name = "toolStripStatusLabelTotalFiles"; + this.toolStripStatusLabelTotalFiles.Size = new System.Drawing.Size(125, 19); + this.toolStripStatusLabelTotalFiles.Text = "Total Searched Files: 0"; + // + // toolStripStatusLabelRPCFiles + // + this.toolStripStatusLabelRPCFiles.Name = "toolStripStatusLabelRPCFiles"; + this.toolStripStatusLabelRPCFiles.Size = new System.Drawing.Size(67, 19); + this.toolStripStatusLabelRPCFiles.Text = "RPC Files: 0"; + // + // label1 + // + this.label1.AutoSize = true; + this.label1.Location = new System.Drawing.Point(12, 141); + this.label1.Name = "label1"; + this.label1.Size = new System.Drawing.Size(88, 13); + this.label1.TabIndex = 11; + this.label1.Text = "Saved File Path: "; + // + // textBoxSaveFile + // + this.textBoxSaveFile.Anchor = ((System.Windows.Forms.AnchorStyles)(((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Left) + | System.Windows.Forms.AnchorStyles.Right))); + this.textBoxSaveFile.Location = new System.Drawing.Point(100, 138); + this.textBoxSaveFile.Name = "textBoxSaveFile"; + this.textBoxSaveFile.Size = new System.Drawing.Size(400, 20); + this.textBoxSaveFile.TabIndex = 12; + // + // buttonJumpFolder + // + this.buttonJumpFolder.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Right))); + this.buttonJumpFolder.BackColor = System.Drawing.Color.Transparent; + this.buttonJumpFolder.BackgroundImageLayout = System.Windows.Forms.ImageLayout.Stretch; + this.buttonJumpFolder.FlatAppearance.BorderSize = 0; + this.buttonJumpFolder.FlatStyle = System.Windows.Forms.FlatStyle.Flat; + this.buttonJumpFolder.Image = ((System.Drawing.Image)(resources.GetObject("buttonJumpFolder.Image"))); + this.buttonJumpFolder.Location = new System.Drawing.Point(506, 136); + this.buttonJumpFolder.Name = "buttonJumpFolder"; + this.buttonJumpFolder.Size = new System.Drawing.Size(25, 22); + this.buttonJumpFolder.TabIndex = 13; + this.buttonJumpFolder.TabStop = false; + this.buttonJumpFolder.UseVisualStyleBackColor = false; + this.buttonJumpFolder.Click += new System.EventHandler(this.button1_Click); + this.buttonJumpFolder.MouseLeave += new System.EventHandler(this.buttonJumpFolder_MouseLeave); + this.buttonJumpFolder.MouseHover += new System.EventHandler(this.buttonJumpFolder_MouseHover); + // + // buttonClear + // + this.buttonClear.Location = new System.Drawing.Point(191, 100); + this.buttonClear.Name = "buttonClear"; + this.buttonClear.Size = new System.Drawing.Size(75, 23); + this.buttonClear.TabIndex = 14; + this.buttonClear.Text = "Clear"; + this.buttonClear.UseVisualStyleBackColor = true; + this.buttonClear.Click += new System.EventHandler(this.buttonClear_Click); + // + // textBoxExcludedFolders + // + this.textBoxExcludedFolders.Location = new System.Drawing.Point(100, 69); + this.textBoxExcludedFolders.Name = "textBoxExcludedFolders"; + this.textBoxExcludedFolders.Size = new System.Drawing.Size(244, 20); + this.textBoxExcludedFolders.TabIndex = 16; + this.textBoxExcludedFolders.Text = "C:\\Windows\\WinSxS"; + // + // label2 + // + this.label2.AutoSize = true; + this.label2.Location = new System.Drawing.Point(12, 72); + this.label2.Name = "label2"; + this.label2.Size = new System.Drawing.Size(88, 13); + this.label2.TabIndex = 15; + this.label2.Text = "Exclude Folders: "; + // + // FormBuildDB + // + this.AutoScaleDimensions = new System.Drawing.SizeF(6F, 13F); + this.AutoScaleMode = System.Windows.Forms.AutoScaleMode.Font; + this.ClientSize = new System.Drawing.Size(555, 522); + this.Controls.Add(this.textBoxExcludedFolders); + this.Controls.Add(this.label2); + this.Controls.Add(this.buttonClear); + this.Controls.Add(this.buttonJumpFolder); + this.Controls.Add(this.textBoxSaveFile); + this.Controls.Add(this.label1); + this.Controls.Add(this.statusStrip1); + this.Controls.Add(this.buttonStop); + this.Controls.Add(this.listViewRPCFiles); + this.Controls.Add(this.comboBox1); + this.Controls.Add(this.checkBoxRecursive); + this.Controls.Add(this.textBoxFolderForRPC); + this.Controls.Add(this.labelRPCFolder); + this.Controls.Add(this.buttonBuild); + this.MaximizeBox = false; + this.MinimizeBox = false; + this.Name = "FormBuildDB"; + this.ShowIcon = false; + this.Text = "Build DB"; + this.FormClosing += new System.Windows.Forms.FormClosingEventHandler(this.FormBuildDB_FormClosing); + this.statusStrip1.ResumeLayout(false); + this.statusStrip1.PerformLayout(); + this.ResumeLayout(false); + this.PerformLayout(); + + } + + #endregion + + private System.Windows.Forms.Button buttonBuild; + private System.Windows.Forms.Label labelRPCFolder; + private System.Windows.Forms.TextBox textBoxFolderForRPC; + private System.Windows.Forms.CheckBox checkBoxRecursive; + private System.Windows.Forms.ComboBox comboBox1; + private System.Windows.Forms.ListView listViewRPCFiles; + private System.Windows.Forms.ColumnHeader columnHeaderFileName; + private System.Windows.Forms.ColumnHeader columnHeaderHasRpc; + private System.Windows.Forms.Button buttonStop; + private System.Windows.Forms.StatusStrip statusStrip1; + private System.Windows.Forms.ToolStripStatusLabel toolStripStatusLabelTotalFiles; + private System.Windows.Forms.ToolStripStatusLabel toolStripStatusLabelRPCFiles; + private System.Windows.Forms.Label label1; + private System.Windows.Forms.TextBox textBoxSaveFile; + private System.Windows.Forms.Button buttonJumpFolder; + private ToolTip toolTipJumpButton; + private Button buttonClear; + private TextBox textBoxExcludedFolders; + private Label label2; + } +} \ No newline at end of file diff --git a/RPCMon/FormBuildDB.cs b/RPCMon/FormBuildDB.cs new file mode 100644 index 0000000..3037309 --- /dev/null +++ b/RPCMon/FormBuildDB.cs @@ -0,0 +1,233 @@ +using System; +using System.Collections.Generic; +using System.ComponentModel; +using System.Data; +using System.Diagnostics; +using System.Drawing; +using System.Drawing.Text; +using System.IO; +using System.Linq; +using System.Text; +using System.Threading; +using System.Threading.Tasks; +using System.Windows.Forms; +using RPCMon.Control; + +namespace RPCMon +{ + public partial class FormBuildDB : Form + { + private ListViewColumnSorter m_LvwColumnSorter; + private const string c_DBDefaultName = "RPC_DB"; + public FormBuildDB() + { + InitializeComponent(); + m_LvwColumnSorter = new ListViewColumnSorter(); + this.listViewRPCFiles.ListViewItemSorter = m_LvwColumnSorter; + + this.textBoxSaveFile.Text = generateDBName(); + this.comboBox1.SelectedIndex = 0; + this.buttonJumpFolder.Image = (Image)(new Bitmap(global::RPCMon.Properties.Resources.share, new Size(15, 15))); + this.buttonJumpFolder.TabStop = false; + this.buttonJumpFolder.FlatStyle = FlatStyle.Flat; + this.buttonJumpFolder.FlatAppearance.BorderSize = 0; + } + + private string generateDBName() + { + string newPathNoExtension = Path.Combine(Directory.GetCurrentDirectory(), c_DBDefaultName); + int num = 0; + bool isExist = false; + while (!isExist) + { + if (File.Exists(newPathNoExtension + num.ToString() + ".rpcdb.json")) + { + num += 1; + } else + { + isExist = true; + newPathNoExtension = newPathNoExtension + num.ToString(); + } + } + + return newPathNoExtension + ".rpcdb.json"; + } + + //public Thread m_SearchingRPCThread; + //CancellationTokenSource cts = new CancellationTokenSource(); + private void buttonBuild_Click(object sender, EventArgs e) + { + Engine.BuildRPCDBStatusUpdate -= Engine_BuildRPCDBStatusUpdate; + Engine.DoneRPCSearchUpdate -= Engine_DoneRPCSearchUpdate; + Engine.BuildRPCDBStatusUpdate += Engine_BuildRPCDBStatusUpdate; + Engine.DoneRPCSearchUpdate += Engine_DoneRPCSearchUpdate; + //string[] extensions = {".exe", ".dll", ".com" }; + string[] extensions = new string[1]; + switch (comboBox1.Text) + { + case (".exe"): + extensions[0] = ".exe"; + break; + case (".dll"): + extensions[0] = ".exe"; + break; + case (".com"): + extensions[0] = ".com"; + break; + default: + extensions = new string[3]{ ".exe", ".dll", ".com" }; + break; + } + + string[] excludedFolders = textBoxExcludedFolders.Text.Split(';'); + + ThreadPool.QueueUserWorkItem(o => Engine.BuildRPCDataBase(textBoxFolderForRPC.Text, textBoxSaveFile.Text, checkBoxRecursive.Checked, excludedFolders, extensions)); + + //ThreadPool.QueueUserWorkItem(o => + //{ CancellationToken token = (CancellationToken)o; + + // while (!token.IsCancellationRequested) + // { + // Engine.BuildRPCDataBase(textBoxFolderForRPC.Text); + // } + + //ThreadPool.QueueUserWorkItem(s => + //{ + // CancellationToken token = (CancellationToken)s; + // if (token.IsCancellationRequested) + // return; + // Engine.BuildRPCDataBase(textBoxFolderForRPC.Text); + // token.WaitHandle.WaitOne(1000); + //}, cts.Token); + + //}, cts.Token); + //List> rpcList = Engine.BuildRPCDataBase(textBoxFolderForRPC.Text); + //var rpcList = Engine.BuildRPCDataBase(textBoxFolderForRPC.Text); + + //MessageBox.Show("Done!", "Creating DB", MessageBoxButtons.OK); + // progressBar1.Refre + } + + private void Engine_DoneRPCSearchUpdate(List> i_RPCServers) + { + MessageBox.Show("Done!", "Creating DB", MessageBoxButtons.OK); + //progressBar1.Value = progressBar1.Maximum; + } + + //private void Engine_BuildRPCDBStatusUpdate(string i_File, string i_FileStatus, int i_NumOfFilesWithRPC, int i_TotalNumberOfFiles) + //{ + // //textBoxLogs.Text += "\n" + i_FileStatus; + // ListViewItem item = new ListViewItem(i_File); + // item.SubItems.Add(i_FileStatus); + // listViewRPCFiles.Items.Add(item); + // progressBar1.Value += (int)((i_NumOfFilesWithRPC / i_TotalNumberOfFiles)*100); + //} + + + private delegate void buildRPCDBStatusUpdateCallBack(string i_File, string i_FileStatus, int i_NumOfFilesWithRPC, int i_TotalNumberOfFiles); + private void Engine_BuildRPCDBStatusUpdate(string i_File, string i_FileStatus, int i_NumOfFilesWithRPC, int i_TotalNumberOfFiles) + { + + if (this.InvokeRequired) + { + buildRPCDBStatusUpdateCallBack s = new buildRPCDBStatusUpdateCallBack(Engine_BuildRPCDBStatusUpdate); + this.Invoke(s, i_File, i_FileStatus, i_NumOfFilesWithRPC, i_TotalNumberOfFiles); + } + else + { + ListViewItem item = new ListViewItem(i_File); + item.SubItems.Add(i_FileStatus); + listViewRPCFiles.Items.Add(item); + if (i_FileStatus == "Yes") + { + item.BackColor = Color.Cyan; + } + + toolStripStatusLabelRPCFiles.Text = "RPC Files: " + i_NumOfFilesWithRPC.ToString(); + toolStripStatusLabelTotalFiles.Text = "Total Searched Files: " + i_TotalNumberOfFiles.ToString(); + // progressBar1.Value += (int)(((double)i_NumOfFilesWithRPC / (double)i_TotalNumberOfFiles) * 100); + //progressBar1.Maximum += progressBar1.Value; + } + } + + private void buttonStop_Click(object sender, EventArgs e) + { + Engine.StopRPCSearch(); + // cts.Cancel(); + //if (m_SearchingRPCThread != null) + //{ + // m_SearchingRPCThread.Abort(); + //} + } + + // https://docs.microsoft.com/en-us/troubleshoot/developer/visualstudio/csharp/general/sort-listview-by-column + private void listViewRPCFiles_ColumnClick(object sender, ColumnClickEventArgs e) + { + // Determine if clicked column is already the column that is being sorted. + if (e.Column == m_LvwColumnSorter.SortColumn) + { + // Reverse the current sort direction for this column. + if (m_LvwColumnSorter.Order == SortOrder.Ascending) + { + m_LvwColumnSorter.Order = SortOrder.Descending; + } + else + { + m_LvwColumnSorter.Order = SortOrder.Ascending; + } + } + else + { + // Set the column number that is to be sorted; default to ascending. + m_LvwColumnSorter.SortColumn = e.Column; + m_LvwColumnSorter.Order = SortOrder.Ascending; + } + + this.listViewRPCFiles.Sort(); + } + + private void FormBuildDB_FormClosing(object sender, FormClosingEventArgs e) + { + Engine.StopRPCSearch(); + } + + private void button1_Click(object sender, EventArgs e) + { + string directory = Path.GetDirectoryName(textBoxSaveFile.Text); + if (Directory.Exists(directory)) + { + ProcessStartInfo startInfo = new ProcessStartInfo + { + Arguments = directory, + FileName = "explorer.exe" + }; + + Process.Start(startInfo); + } + else + { + MessageBox.Show(string.Format("{0} Directory does not exist!", directory)); + } + } + + private void buttonJumpFolder_MouseHover(object sender, EventArgs e) + { + toolTipJumpButton.Show("Jump to Saved Folder", buttonJumpFolder); + } + + private void buttonJumpFolder_MouseLeave(object sender, EventArgs e) + { + toolTipJumpButton.Hide(buttonJumpFolder); + } + + private void buttonClear_Click(object sender, EventArgs e) + { + listViewRPCFiles.Items.Clear(); + Engine.BuildRPCDBStatusUpdate -= Engine_BuildRPCDBStatusUpdate; + Engine.DoneRPCSearchUpdate -= Engine_DoneRPCSearchUpdate; + + toolStripStatusLabelRPCFiles.Text = "RPC Files: "; + toolStripStatusLabelTotalFiles.Text = "Total Searched Files: 0"; + } + } +} diff --git a/RPCMon/FormBuildDB.resx b/RPCMon/FormBuildDB.resx new file mode 100644 index 0000000..550f7cf --- /dev/null +++ b/RPCMon/FormBuildDB.resx @@ -0,0 +1,138 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + text/microsoft-resx + + + 2.0 + + + System.Resources.ResXResourceReader, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + + System.Resources.ResXResourceWriter, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + + 17, 17 + + + + + iVBORw0KGgoAAAANSUhEUgAAAA8AAAAPCAYAAAA71pVKAAAABGdBTUEAALGPC/xhBQAAAAlwSFlzAAAO + wwAADsMBx2+oZAAAATJJREFUOE9joAvwP3PX1ufcvf76+nomqBDxwPfsfQ/f8w/+e59/0Fv//z/EABvd + AGMrnYAYZGys5iMClgSC0CsvJfwuPIzzOXtvCUgzCPude9DPADIAqPivpU7gHSB9BIYttQNNQRr9Lj4o + hWlAxz7nH0wDag78b6ETkAG2Bgn4nH0QDFT0F10TMsap2ff8/dfYNMCw96WHxlg1+1x84AxT5HP+/pvg + S3f1gAEWBBPzO/vQBKwQm2bfc/eLwRrPPZgPFQKHNtCgP76XH1hDhXBoPns3B6j5OjxKgMDnzF057yuP + zKBcCMCmub7+P1P8/fscUC5ugCvAcAEb7QAfS52AjWAOqZqttAMyrbQDr0M4QM1AgcdA0y4Qg0FqgXqu + QTSr+0lZ6wS6koJttf1lGRgYGACEyfG98X+pIQAAAABJRU5ErkJggg== + + + + 133, 17 + + \ No newline at end of file diff --git a/RPCMon/FormHighlighting.Designer.cs b/RPCMon/FormHighlighting.Designer.cs new file mode 100644 index 0000000..b3083a0 --- /dev/null +++ b/RPCMon/FormHighlighting.Designer.cs @@ -0,0 +1,269 @@ +namespace RPCMon +{ + partial class FormHighlighting + { + /// + /// Required designer variable. + /// + private System.ComponentModel.IContainer components = null; + + /// + /// Clean up any resources being used. + /// + /// true if managed resources should be disposed; otherwise, false. + protected override void Dispose(bool disposing) + { + if (disposing && (components != null)) + { + components.Dispose(); + } + base.Dispose(disposing); + } + + #region Windows Form Designer generated code + + /// + /// Required method for Designer support - do not modify + /// the contents of this method with the code editor. + /// + private void InitializeComponent() + { + this.labelHighlight = new System.Windows.Forms.Label(); + this.comboBoxColumn = new System.Windows.Forms.ComboBox(); + this.comboBoxRelation = new System.Windows.Forms.ComboBox(); + this.comboBoxValue = new System.Windows.Forms.ComboBox(); + this.labelThen = new System.Windows.Forms.Label(); + this.comboBoxAction = new System.Windows.Forms.ComboBox(); + this.listViewHighlights = new System.Windows.Forms.ListView(); + this.columnHeaderColumn = ((System.Windows.Forms.ColumnHeader)(new System.Windows.Forms.ColumnHeader())); + this.columnHeaderRelation = ((System.Windows.Forms.ColumnHeader)(new System.Windows.Forms.ColumnHeader())); + this.columnHeaderValue = ((System.Windows.Forms.ColumnHeader)(new System.Windows.Forms.ColumnHeader())); + this.columnHeaderAction = ((System.Windows.Forms.ColumnHeader)(new System.Windows.Forms.ColumnHeader())); + this.buttonOK = new System.Windows.Forms.Button(); + this.buttonCancel = new System.Windows.Forms.Button(); + this.buttonAdd = new System.Windows.Forms.Button(); + this.buttonRemove = new System.Windows.Forms.Button(); + this.buttonReset = new System.Windows.Forms.Button(); + this.SuspendLayout(); + // + // labelHighlight + // + this.labelHighlight.AutoSize = true; + this.labelHighlight.Location = new System.Drawing.Point(12, 9); + this.labelHighlight.Name = "labelHighlight"; + this.labelHighlight.Size = new System.Drawing.Size(211, 13); + this.labelHighlight.TabIndex = 0; + this.labelHighlight.Text = "Highlight entries matching these conditions:"; + // + // comboBoxColumn + // + this.comboBoxColumn.DropDownStyle = System.Windows.Forms.ComboBoxStyle.DropDownList; + this.comboBoxColumn.FormattingEnabled = true; + this.comboBoxColumn.Items.AddRange(new object[] { + "PID", + "TID", + "ProcessName", + "UUID", + "Module", + "ModulePath", + "ProceduresCount", + "Service", + "Function", + "NetworkAddress", + "Protocol", + "Endpoint", + "Options", + "AuthenticationLevel", + "AuthenticationService", + "ImpersonationLevel"}); + this.comboBoxColumn.Location = new System.Drawing.Point(12, 25); + this.comboBoxColumn.Name = "comboBoxColumn"; + this.comboBoxColumn.Size = new System.Drawing.Size(121, 21); + this.comboBoxColumn.TabIndex = 1; + // + // comboBoxRelation + // + this.comboBoxRelation.DropDownStyle = System.Windows.Forms.ComboBoxStyle.DropDownList; + this.comboBoxRelation.FormattingEnabled = true; + this.comboBoxRelation.Items.AddRange(new object[] { + "contains", + "is", + "begins with", + "ends with"}); + this.comboBoxRelation.Location = new System.Drawing.Point(139, 25); + this.comboBoxRelation.Name = "comboBoxRelation"; + this.comboBoxRelation.Size = new System.Drawing.Size(71, 21); + this.comboBoxRelation.TabIndex = 2; + // + // comboBoxValue + // + this.comboBoxValue.Anchor = ((System.Windows.Forms.AnchorStyles)(((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Left) + | System.Windows.Forms.AnchorStyles.Right))); + this.comboBoxValue.FormattingEnabled = true; + this.comboBoxValue.Location = new System.Drawing.Point(216, 25); + this.comboBoxValue.Name = "comboBoxValue"; + this.comboBoxValue.Size = new System.Drawing.Size(297, 21); + this.comboBoxValue.TabIndex = 3; + // + // labelThen + // + this.labelThen.Anchor = ((System.Windows.Forms.AnchorStyles)(((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Left) + | System.Windows.Forms.AnchorStyles.Right))); + this.labelThen.AutoSize = true; + this.labelThen.Location = new System.Drawing.Point(519, 25); + this.labelThen.Name = "labelThen"; + this.labelThen.Size = new System.Drawing.Size(28, 13); + this.labelThen.TabIndex = 4; + this.labelThen.Text = "then"; + // + // comboBoxAction + // + this.comboBoxAction.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Right))); + this.comboBoxAction.DropDownStyle = System.Windows.Forms.ComboBoxStyle.DropDownList; + this.comboBoxAction.FormattingEnabled = true; + this.comboBoxAction.Items.AddRange(new object[] { + "Include", + "Exclude"}); + this.comboBoxAction.Location = new System.Drawing.Point(557, 22); + this.comboBoxAction.Name = "comboBoxAction"; + this.comboBoxAction.Size = new System.Drawing.Size(71, 21); + this.comboBoxAction.TabIndex = 5; + // + // listViewHighlights + // + this.listViewHighlights.Anchor = ((System.Windows.Forms.AnchorStyles)((((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Bottom) + | System.Windows.Forms.AnchorStyles.Left) + | System.Windows.Forms.AnchorStyles.Right))); + this.listViewHighlights.CheckBoxes = true; + this.listViewHighlights.Columns.AddRange(new System.Windows.Forms.ColumnHeader[] { + this.columnHeaderColumn, + this.columnHeaderRelation, + this.columnHeaderValue, + this.columnHeaderAction}); + this.listViewHighlights.HideSelection = false; + this.listViewHighlights.Location = new System.Drawing.Point(12, 85); + this.listViewHighlights.Name = "listViewHighlights"; + this.listViewHighlights.Size = new System.Drawing.Size(619, 267); + this.listViewHighlights.TabIndex = 6; + this.listViewHighlights.UseCompatibleStateImageBehavior = false; + this.listViewHighlights.View = System.Windows.Forms.View.Details; + this.listViewHighlights.MouseDoubleClick += new System.Windows.Forms.MouseEventHandler(this.listViewHighlights_MouseDoubleClick); + // + // columnHeaderColumn + // + this.columnHeaderColumn.Text = "Column"; + // + // columnHeaderRelation + // + this.columnHeaderRelation.Text = "Relation"; + // + // columnHeaderValue + // + this.columnHeaderValue.Text = "Value"; + // + // columnHeaderAction + // + this.columnHeaderAction.Text = "Action"; + // + // buttonOK + // + this.buttonOK.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Bottom | System.Windows.Forms.AnchorStyles.Right))); + this.buttonOK.Location = new System.Drawing.Point(472, 358); + this.buttonOK.Name = "buttonOK"; + this.buttonOK.Size = new System.Drawing.Size(75, 23); + this.buttonOK.TabIndex = 7; + this.buttonOK.Text = "OK"; + this.buttonOK.UseVisualStyleBackColor = true; + this.buttonOK.Click += new System.EventHandler(this.buttonOK_Click); + // + // buttonCancel + // + this.buttonCancel.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Bottom | System.Windows.Forms.AnchorStyles.Right))); + this.buttonCancel.Location = new System.Drawing.Point(553, 358); + this.buttonCancel.Name = "buttonCancel"; + this.buttonCancel.Size = new System.Drawing.Size(75, 23); + this.buttonCancel.TabIndex = 8; + this.buttonCancel.Text = "Cancel"; + this.buttonCancel.UseVisualStyleBackColor = true; + this.buttonCancel.Click += new System.EventHandler(this.buttonCancel_Click); + // + // buttonAdd + // + this.buttonAdd.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Right))); + this.buttonAdd.Location = new System.Drawing.Point(472, 56); + this.buttonAdd.Name = "buttonAdd"; + this.buttonAdd.Size = new System.Drawing.Size(75, 23); + this.buttonAdd.TabIndex = 9; + this.buttonAdd.Text = "Add"; + this.buttonAdd.UseVisualStyleBackColor = true; + this.buttonAdd.Click += new System.EventHandler(this.buttonAdd_Click); + // + // buttonRemove + // + this.buttonRemove.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Right))); + this.buttonRemove.Location = new System.Drawing.Point(553, 56); + this.buttonRemove.Name = "buttonRemove"; + this.buttonRemove.Size = new System.Drawing.Size(75, 23); + this.buttonRemove.TabIndex = 10; + this.buttonRemove.Text = "Remove"; + this.buttonRemove.UseVisualStyleBackColor = true; + this.buttonRemove.Click += new System.EventHandler(this.buttonRemove_Click); + // + // buttonReset + // + this.buttonReset.Anchor = ((System.Windows.Forms.AnchorStyles)((System.Windows.Forms.AnchorStyles.Top | System.Windows.Forms.AnchorStyles.Right))); + this.buttonReset.Location = new System.Drawing.Point(12, 56); + this.buttonReset.Name = "buttonReset"; + this.buttonReset.Size = new System.Drawing.Size(75, 23); + this.buttonReset.TabIndex = 11; + this.buttonReset.Text = "Reset"; + this.buttonReset.UseVisualStyleBackColor = true; + this.buttonReset.Click += new System.EventHandler(this.buttonReset_Click); + // + // FormHighlighting + // + this.AutoScaleDimensions = new System.Drawing.SizeF(6F, 13F); + this.AutoScaleMode = System.Windows.Forms.AutoScaleMode.Font; + this.ClientSize = new System.Drawing.Size(643, 393); + this.Controls.Add(this.buttonReset); + this.Controls.Add(this.buttonRemove); + this.Controls.Add(this.buttonAdd); + this.Controls.Add(this.buttonCancel); + this.Controls.Add(this.buttonOK); + this.Controls.Add(this.listViewHighlights); + this.Controls.Add(this.comboBoxAction); + this.Controls.Add(this.labelThen); + this.Controls.Add(this.comboBoxValue); + this.Controls.Add(this.comboBoxRelation); + this.Controls.Add(this.comboBoxColumn); + this.Controls.Add(this.labelHighlight); + this.MaximizeBox = false; + this.MinimizeBox = false; + this.Name = "FormHighlighting"; + this.ShowIcon = false; + this.Text = "RPC Monitor Highlighting"; + this.ResumeLayout(false); + this.PerformLayout(); + + } + + #endregion + + private System.Windows.Forms.Label labelHighlight; + private System.Windows.Forms.ComboBox comboBoxColumn; + private System.Windows.Forms.ComboBox comboBoxRelation; + private System.Windows.Forms.ComboBox comboBoxValue; + private System.Windows.Forms.Label labelThen; + private System.Windows.Forms.ComboBox comboBoxAction; + private System.Windows.Forms.ListView listViewHighlights; + private System.Windows.Forms.Button buttonOK; + private System.Windows.Forms.Button buttonCancel; + private System.Windows.Forms.Button buttonAdd; + private System.Windows.Forms.Button buttonRemove; + private System.Windows.Forms.ColumnHeader columnHeaderColumn; + private System.Windows.Forms.ColumnHeader columnHeaderRelation; + private System.Windows.Forms.ColumnHeader columnHeaderValue; + private System.Windows.Forms.ColumnHeader columnHeaderAction; + private System.Windows.Forms.Button buttonReset; + } +} \ No newline at end of file diff --git a/RPCMon/FormHighlighting.cs b/RPCMon/FormHighlighting.cs new file mode 100644 index 0000000..e8fbe08 --- /dev/null +++ b/RPCMon/FormHighlighting.cs @@ -0,0 +1,122 @@ +using System; +using System.Collections.Generic; +using System.ComponentModel; +using System.Data; +using System.Drawing; +using System.Linq; +using System.Text; +using System.Threading.Tasks; +using System.Windows.Forms; +using static System.Windows.Forms.ListViewItem; + +namespace RPCMon +{ + public delegate void highlightRowsEventHandler(ListView i_ListView); + public partial class FormHighlighting : Form + { + public event highlightRowsEventHandler hightlightRowsUpdate; + + public FormHighlighting(ref ListView i_ListViewHighlighFilter) + { + InitializeComponentWrapper(); + + foreach (ListViewItem item in i_ListViewHighlighFilter.Items) + { + ListViewItem clonedItem = (ListViewItem)item.Clone(); + this.listViewHighlights.Items.Add(clonedItem); + } + } + + private void InitializeComponentWrapper() + { + InitializeComponent(); + this.comboBoxColumn.SelectedIndex = 0; + this.comboBoxRelation.SelectedIndex = 0; + this.comboBoxAction.SelectedIndex = 0; + this.listViewHighlights.FullRowSelect = true; + } + + + // DUPLICATED function in ColumnFilter + // Maybe create a shared function in Utils but it threw an exception for "type initializer" + private bool isRowExist(string i_Column, string i_Relation, string i_Value, string i_Action) + { + bool isExist = false; + string newRow = i_Column + i_Relation + i_Value + i_Action; + foreach (ListViewItem item in listViewHighlights.Items) + { + string rawRow = ""; + foreach (ListViewSubItem subItem in item.SubItems) + { + rawRow += subItem.Text; + } + + if (newRow == rawRow) + { + isExist = true; + break; + } + + } + + return isExist; + } + + private void buttonAdd_Click(object sender, EventArgs e) + { + if (!isRowExist(comboBoxColumn.Text, comboBoxRelation.Text, comboBoxValue.Text, comboBoxAction.Text)) + { + ListViewItem item = new ListViewItem(comboBoxColumn.Text); + item.SubItems.Add(comboBoxRelation.Text); + item.SubItems.Add(comboBoxValue.Text); + item.SubItems.Add(comboBoxAction.Text); + item.Checked = true; + this.listViewHighlights.Items.Add(item); + } + } + + private void buttonCancel_Click(object sender, EventArgs e) + { + this.Close(); + } + + private void buttonRemove_Click(object sender, EventArgs e) + { + foreach (ListViewItem item in this.listViewHighlights.SelectedItems) + { + item.Remove(); + } + } + + private void listViewHighlights_MouseDoubleClick(object sender, MouseEventArgs e) + { + foreach (ListViewItem item in ((ListView)sender).SelectedItems) + { + this.comboBoxColumn.Text = item.SubItems[0].Text; + this.comboBoxRelation.Text = item.SubItems[1].Text; + this.comboBoxValue.Text = item.SubItems[2].Text; + this.comboBoxAction.Text = item.SubItems[3].Text; + item.Remove(); + } + } + + public virtual void OnHighlightRowsUpdate(ListView i_ListView) + { + if (hightlightRowsUpdate != null) + { + hightlightRowsUpdate.Invoke(i_ListView); + } + } + + private void buttonOK_Click(object sender, EventArgs e) + { + OnHighlightRowsUpdate(listViewHighlights); + this.Close(); + } + + private void buttonReset_Click(object sender, EventArgs e) + { + this.listViewHighlights.Clear(); + } + } +} diff --git a/RPCMon/FormHighlighting.resx b/RPCMon/FormHighlighting.resx new file mode 100644 index 0000000..1af7de1 --- /dev/null +++ b/RPCMon/FormHighlighting.resx @@ -0,0 +1,120 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + text/microsoft-resx + + + 2.0 + + + System.Resources.ResXResourceReader, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + + System.Resources.ResXResourceWriter, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + \ No newline at end of file diff --git a/RPCMon/FormSearch.Designer.cs b/RPCMon/FormSearch.Designer.cs new file mode 100644 index 0000000..dc6a122 --- /dev/null +++ b/RPCMon/FormSearch.Designer.cs @@ -0,0 +1,143 @@ +namespace RPCMon +{ + partial class FormSearch + { + /// + /// Required designer variable. + /// + private System.ComponentModel.IContainer components = null; + + /// + /// Clean up any resources being used. + /// + /// true if managed resources should be disposed; otherwise, false. + protected override void Dispose(bool disposing) + { + if (disposing && (components != null)) + { + components.Dispose(); + } + base.Dispose(disposing); + } + + #region Windows Form Designer generated code + + /// + /// Required method for Designer support - do not modify + /// the contents of this method with the code editor. + /// + private void InitializeComponent() + { + this.label1 = new System.Windows.Forms.Label(); + this.comboBox1 = new System.Windows.Forms.ComboBox(); + this.buttonFind = new System.Windows.Forms.Button(); + this.buttonCancel = new System.Windows.Forms.Button(); + this.groupBoxDirection = new System.Windows.Forms.GroupBox(); + this.radioButtonUp = new System.Windows.Forms.RadioButton(); + this.radioButtonDown = new System.Windows.Forms.RadioButton(); + this.groupBoxDirection.SuspendLayout(); + this.SuspendLayout(); + // + // label1 + // + this.label1.AutoSize = true; + this.label1.Location = new System.Drawing.Point(13, 13); + this.label1.Name = "label1"; + this.label1.Size = new System.Drawing.Size(56, 13); + this.label1.TabIndex = 0; + this.label1.Text = "Find what:"; + // + // comboBox1 + // + this.comboBox1.FormattingEnabled = true; + this.comboBox1.Location = new System.Drawing.Point(76, 13); + this.comboBox1.Name = "comboBox1"; + this.comboBox1.Size = new System.Drawing.Size(215, 21); + this.comboBox1.TabIndex = 1; + // + // buttonFind + // + this.buttonFind.Location = new System.Drawing.Point(314, 11); + this.buttonFind.Name = "buttonFind"; + this.buttonFind.Size = new System.Drawing.Size(75, 23); + this.buttonFind.TabIndex = 2; + this.buttonFind.Text = "Find Next"; + this.buttonFind.UseVisualStyleBackColor = true; + this.buttonFind.Click += new System.EventHandler(this.buttonFind_Click); + // + // buttonCancel + // + this.buttonCancel.Location = new System.Drawing.Point(314, 53); + this.buttonCancel.Name = "buttonCancel"; + this.buttonCancel.Size = new System.Drawing.Size(75, 23); + this.buttonCancel.TabIndex = 3; + this.buttonCancel.Text = "Cancel"; + this.buttonCancel.UseVisualStyleBackColor = true; + this.buttonCancel.Click += new System.EventHandler(this.buttonCancel_Click); + // + // groupBoxDirection + // + this.groupBoxDirection.Controls.Add(this.radioButtonDown); + this.groupBoxDirection.Controls.Add(this.radioButtonUp); + this.groupBoxDirection.Location = new System.Drawing.Point(178, 53); + this.groupBoxDirection.Name = "groupBoxDirection"; + this.groupBoxDirection.Size = new System.Drawing.Size(113, 63); + this.groupBoxDirection.TabIndex = 4; + this.groupBoxDirection.TabStop = false; + this.groupBoxDirection.Text = "Direction"; + // + // radioButtonUp + // + this.radioButtonUp.AutoSize = true; + this.radioButtonUp.Location = new System.Drawing.Point(7, 29); + this.radioButtonUp.Name = "radioButtonUp"; + this.radioButtonUp.Size = new System.Drawing.Size(39, 17); + this.radioButtonUp.TabIndex = 0; + this.radioButtonUp.Text = "Up"; + this.radioButtonUp.UseVisualStyleBackColor = true; + // + // radioButtonDown + // + this.radioButtonDown.AutoSize = true; + this.radioButtonDown.Checked = true; + this.radioButtonDown.Location = new System.Drawing.Point(52, 29); + this.radioButtonDown.Name = "radioButtonDown"; + this.radioButtonDown.Size = new System.Drawing.Size(53, 17); + this.radioButtonDown.TabIndex = 1; + this.radioButtonDown.TabStop = true; + this.radioButtonDown.Text = "Down"; + this.radioButtonDown.UseVisualStyleBackColor = true; + // + // FormSearch + // + this.AutoScaleDimensions = new System.Drawing.SizeF(6F, 13F); + this.AutoScaleMode = System.Windows.Forms.AutoScaleMode.Font; + this.ClientSize = new System.Drawing.Size(415, 144); + this.Controls.Add(this.groupBoxDirection); + this.Controls.Add(this.buttonCancel); + this.Controls.Add(this.buttonFind); + this.Controls.Add(this.comboBox1); + this.Controls.Add(this.label1); + this.MaximizeBox = false; + this.MinimizeBox = false; + this.Name = "FormSearch"; + this.ShowIcon = false; + this.Text = "Find"; + this.groupBoxDirection.ResumeLayout(false); + this.groupBoxDirection.PerformLayout(); + this.ResumeLayout(false); + this.PerformLayout(); + + } + + #endregion + + private System.Windows.Forms.Label label1; + private System.Windows.Forms.ComboBox comboBox1; + private System.Windows.Forms.Button buttonFind; + private System.Windows.Forms.Button buttonCancel; + private System.Windows.Forms.GroupBox groupBoxDirection; + private System.Windows.Forms.RadioButton radioButtonDown; + private System.Windows.Forms.RadioButton radioButtonUp; + } +} \ No newline at end of file diff --git a/RPCMon/FormSearch.cs b/RPCMon/FormSearch.cs new file mode 100644 index 0000000..91966a9 --- /dev/null +++ b/RPCMon/FormSearch.cs @@ -0,0 +1,43 @@ +using System; +using System.Collections.Generic; +using System.ComponentModel; +using System.Data; +using System.Drawing; +using System.Linq; +using System.Text; +using System.Threading.Tasks; +using System.Windows.Forms; + +namespace RPCMon +{ + public delegate void searchEventHandler(string i_SearchString, bool i_SearchDown, bool i_MatchWholeWord, bool i_MatchSensitive); + public partial class FormSearch : Form + { + //internal searchEventHandler searchForMatch; + + public event searchEventHandler searchForMatch; + + public FormSearch() + { + InitializeComponent(); + } + + private void buttonCancel_Click(object sender, EventArgs e) + { + this.Close(); + } + + public virtual void OnSearchForMatch(string i_SearchString, bool i_SearchDown, bool i_MatchWholeWord, bool i_MatchSensitive) + { + if (searchForMatch != null) + { + searchForMatch.Invoke(i_SearchString, i_SearchDown, i_MatchWholeWord, i_MatchSensitive); + } + } + + private void buttonFind_Click(object sender, EventArgs e) + { + OnSearchForMatch(comboBox1.Text, radioButtonDown.Checked, false, false); + } + } +} diff --git a/RPCMon/FormSearch.resx b/RPCMon/FormSearch.resx new file mode 100644 index 0000000..1af7de1 --- /dev/null +++ b/RPCMon/FormSearch.resx @@ -0,0 +1,120 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + text/microsoft-resx + + + 2.0 + + + System.Resources.ResXResourceReader, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + + System.Resources.ResXResourceWriter, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + \ No newline at end of file diff --git a/RPCMon/ListViewColumnSorter.cs b/RPCMon/ListViewColumnSorter.cs new file mode 100644 index 0000000..cd9f99d --- /dev/null +++ b/RPCMon/ListViewColumnSorter.cs @@ -0,0 +1,105 @@ +using System.Collections; +using System.Windows.Forms; + +namespace RPCMon +{ + // https://stackoverflow.com/a/25761349/2153777 + public class ListViewColumnSorter : IComparer + { + /// + /// Specifies the column to be sorted + /// + private int ColumnToSort; + + /// + /// Specifies the order in which to sort (i.e. 'Ascending'). + /// + private SortOrder OrderOfSort; + + /// + /// Case insensitive comparer object + /// + private CaseInsensitiveComparer ObjectCompare; + + /// + /// Class constructor. Initializes various elements + /// + public ListViewColumnSorter() + { + // Initialize the column to '0' + ColumnToSort = 0; + + // Initialize the sort order to 'none' + OrderOfSort = SortOrder.None; + + // Initialize the CaseInsensitiveComparer object + ObjectCompare = new CaseInsensitiveComparer(); + } + + /// + /// This method is inherited from the IComparer interface. It compares the two objects passed using a case insensitive comparison. + /// + /// First object to be compared + /// Second object to be compared + /// The result of the comparison. "0" if equal, negative if 'x' is less than 'y' and positive if 'x' is greater than 'y' + public int Compare(object x, object y) + { + int compareResult; + ListViewItem listviewX, listviewY; + + // Cast the objects to be compared to ListViewItem objects + listviewX = (ListViewItem)x; + listviewY = (ListViewItem)y; + + // Compare the two items + compareResult = ObjectCompare.Compare(listviewX.SubItems[ColumnToSort].Text, listviewY.SubItems[ColumnToSort].Text); + + // Calculate correct return value based on object comparison + if (OrderOfSort == SortOrder.Ascending) + { + // Ascending sort is selected, return normal result of compare operation + return compareResult; + } + else if (OrderOfSort == SortOrder.Descending) + { + // Descending sort is selected, return negative result of compare operation + return (-compareResult); + } + else + { + // Return '0' to indicate they are equal + return 0; + } + } + + /// + /// Gets or sets the number of the column to which to apply the sorting operation (Defaults to '0'). + /// + public int SortColumn + { + set + { + ColumnToSort = value; + } + get + { + return ColumnToSort; + } + } + + /// + /// Gets or sets the order of sorting to apply (for example, 'Ascending' or 'Descending'). + /// + public SortOrder Order + { + set + { + OrderOfSort = value; + } + get + { + return OrderOfSort; + } + } + } +} diff --git a/RPCMon/Program.cs b/RPCMon/Program.cs new file mode 100644 index 0000000..a0216dd --- /dev/null +++ b/RPCMon/Program.cs @@ -0,0 +1,22 @@ +using System; +using System.Collections.Generic; +using System.Linq; +using System.Threading.Tasks; +using System.Windows.Forms; + +namespace RPCMon +{ + static class Program + { + /// + /// The main entry point for the application. + /// + [STAThread] + static void Main() + { + Application.EnableVisualStyles(); + Application.SetCompatibleTextRenderingDefault(false); + Application.Run(new Form1()); + } + } +} diff --git a/RPCMon/Properties/AssemblyInfo.cs b/RPCMon/Properties/AssemblyInfo.cs new file mode 100644 index 0000000..884a165 --- /dev/null +++ b/RPCMon/Properties/AssemblyInfo.cs @@ -0,0 +1,36 @@ +using System.Reflection; +using System.Runtime.CompilerServices; +using System.Runtime.InteropServices; + +// General Information about an assembly is controlled through the following +// set of attributes. Change these attribute values to modify the information +// associated with an assembly. +[assembly: AssemblyTitle("RPCMon")] +[assembly: AssemblyDescription("")] +[assembly: AssemblyConfiguration("")] +[assembly: AssemblyCompany("")] +[assembly: AssemblyProduct("RPCMon")] +[assembly: AssemblyCopyright("Copyright © 2022")] +[assembly: AssemblyTrademark("")] +[assembly: AssemblyCulture("")] + +// Setting ComVisible to false makes the types in this assembly not visible +// to COM components. If you need to access a type in this assembly from +// COM, set the ComVisible attribute to true on that type. +[assembly: ComVisible(false)] + +// The following GUID is for the ID of the typelib if this project is exposed to COM +[assembly: Guid("9de6bb01-5955-4ee7-bd74-b47aec15efbb")] + +// Version information for an assembly consists of the following four values: +// +// Major Version +// Minor Version +// Build Number +// Revision +// +// You can specify all the values or you can default the Build and Revision Numbers +// by using the '*' as shown below: +// [assembly: AssemblyVersion("1.0.*")] +[assembly: AssemblyVersion("1.0.0.0")] +[assembly: AssemblyFileVersion("1.0.0.0")] diff --git a/RPCMon/Properties/Resources.Designer.cs b/RPCMon/Properties/Resources.Designer.cs new file mode 100644 index 0000000..3471ce2 --- /dev/null +++ b/RPCMon/Properties/Resources.Designer.cs @@ -0,0 +1,183 @@ +//------------------------------------------------------------------------------ +// +// This code was generated by a tool. +// Runtime Version:4.0.30319.42000 +// +// Changes to this file may cause incorrect behavior and will be lost if +// the code is regenerated. +// +//------------------------------------------------------------------------------ + +namespace RPCMon.Properties { + using System; + + + /// + /// A strongly-typed resource class, for looking up localized strings, etc. + /// + // This class was auto-generated by the StronglyTypedResourceBuilder + // class via a tool like ResGen or Visual Studio. + // To add or remove a member, edit your .ResX file then rerun ResGen + // with the /str option, or rebuild your VS project. + [global::System.CodeDom.Compiler.GeneratedCodeAttribute("System.Resources.Tools.StronglyTypedResourceBuilder", "15.0.0.0")] + [global::System.Diagnostics.DebuggerNonUserCodeAttribute()] + [global::System.Runtime.CompilerServices.CompilerGeneratedAttribute()] + internal class Resources { + + private static global::System.Resources.ResourceManager resourceMan; + + private static global::System.Globalization.CultureInfo resourceCulture; + + [global::System.Diagnostics.CodeAnalysis.SuppressMessageAttribute("Microsoft.Performance", "CA1811:AvoidUncalledPrivateCode")] + internal Resources() { + } + + /// + /// Returns the cached ResourceManager instance used by this class. + /// + [global::System.ComponentModel.EditorBrowsableAttribute(global::System.ComponentModel.EditorBrowsableState.Advanced)] + internal static global::System.Resources.ResourceManager ResourceManager { + get { + if (object.ReferenceEquals(resourceMan, null)) { + global::System.Resources.ResourceManager temp = new global::System.Resources.ResourceManager("RPCMon.Properties.Resources", typeof(Resources).Assembly); + resourceMan = temp; + } + return resourceMan; + } + } + + /// + /// Overrides the current thread's CurrentUICulture property for all + /// resource lookups using this strongly typed resource class. + /// + [global::System.ComponentModel.EditorBrowsableAttribute(global::System.ComponentModel.EditorBrowsableState.Advanced)] + internal static global::System.Globalization.CultureInfo Culture { + get { + return resourceCulture; + } + set { + resourceCulture = value; + } + } + + /// + /// Looks up a localized resource of type System.Drawing.Bitmap. + /// + internal static System.Drawing.Bitmap duplicate { + get { + object obj = ResourceManager.GetObject("duplicate", resourceCulture); + return ((System.Drawing.Bitmap)(obj)); + } + } + + /// + /// Looks up a localized resource of type System.Drawing.Bitmap. + /// + internal static System.Drawing.Bitmap duplicate_disable { + get { + object obj = ResourceManager.GetObject("duplicate-disable", resourceCulture); + return ((System.Drawing.Bitmap)(obj)); + } + } + + /// + /// Looks up a localized resource of type System.Drawing.Bitmap. + /// + internal static System.Drawing.Bitmap eraser { + get { + object obj = ResourceManager.GetObject("eraser", resourceCulture); + return ((System.Drawing.Bitmap)(obj)); + } + } + + /// + /// Looks up a localized resource of type System.Drawing.Bitmap. + /// + internal static System.Drawing.Bitmap filter { + get { + object obj = ResourceManager.GetObject("filter", resourceCulture); + return ((System.Drawing.Bitmap)(obj)); + } + } + + /// + /// Looks up a localized resource of type System.Drawing.Bitmap. + /// + internal static System.Drawing.Bitmap find { + get { + object obj = ResourceManager.GetObject("find", resourceCulture); + return ((System.Drawing.Bitmap)(obj)); + } + } + + /// + /// Looks up a localized resource of type System.Drawing.Bitmap. + /// + internal static System.Drawing.Bitmap grid { + get { + object obj = ResourceManager.GetObject("grid", resourceCulture); + return ((System.Drawing.Bitmap)(obj)); + } + } + + /// + /// Looks up a localized resource of type System.Drawing.Bitmap. + /// + internal static System.Drawing.Bitmap grid_disable { + get { + object obj = ResourceManager.GetObject("grid-disable", resourceCulture); + return ((System.Drawing.Bitmap)(obj)); + } + } + + /// + /// Looks up a localized resource of type System.Drawing.Bitmap. + /// + internal static System.Drawing.Bitmap highlighter { + get { + object obj = ResourceManager.GetObject("highlighter", resourceCulture); + return ((System.Drawing.Bitmap)(obj)); + } + } + + /// + /// Looks up a localized resource of type System.Drawing.Bitmap. + /// + internal static System.Drawing.Bitmap pause_button { + get { + object obj = ResourceManager.GetObject("pause-button", resourceCulture); + return ((System.Drawing.Bitmap)(obj)); + } + } + + /// + /// Looks up a localized resource of type System.Drawing.Bitmap. + /// + internal static System.Drawing.Bitmap share { + get { + object obj = ResourceManager.GetObject("share", resourceCulture); + return ((System.Drawing.Bitmap)(obj)); + } + } + + /// + /// Looks up a localized resource of type System.Drawing.Bitmap. + /// + internal static System.Drawing.Bitmap startIcon { + get { + object obj = ResourceManager.GetObject("startIcon", resourceCulture); + return ((System.Drawing.Bitmap)(obj)); + } + } + + /// + /// Looks up a localized resource of type System.Drawing.Bitmap. + /// + internal static System.Drawing.Bitmap stopIcon { + get { + object obj = ResourceManager.GetObject("stopIcon", resourceCulture); + return ((System.Drawing.Bitmap)(obj)); + } + } + } +} diff --git a/RPCMon/Properties/Resources.resx b/RPCMon/Properties/Resources.resx new file mode 100644 index 0000000..eea5faa --- /dev/null +++ b/RPCMon/Properties/Resources.resx @@ -0,0 +1,157 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + text/microsoft-resx + + + 2.0 + + + System.Resources.ResXResourceReader, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + + System.Resources.ResXResourceWriter, System.Windows.Forms, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b77a5c561934e089 + + + + ..\Resources\grid.png;System.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a + + + ..\Resources\filter.png;System.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a + + + ..\Resources\grid-disable.png;System.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a + + + ..\Resources\highlighter.png;System.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a + + + ..\Resources\find.png;System.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a + + + ..\Resources\stopIcon.png;System.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a + + + ..\Resources\pause-button.png;System.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a + + + ..\Resources\share.png;System.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a + + + ..\Resources\startIcon.png;System.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a + + + ..\Resources\eraser.png;System.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a + + + ..\Resources\duplicate.png;System.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a + + + ..\Resources\duplicate-disable.png;System.Drawing.Bitmap, System.Drawing, Version=4.0.0.0, Culture=neutral, PublicKeyToken=b03f5f7f11d50a3a + + \ No newline at end of file diff --git a/RPCMon/Properties/Settings.Designer.cs b/RPCMon/Properties/Settings.Designer.cs new file mode 100644 index 0000000..26ced86 --- /dev/null +++ b/RPCMon/Properties/Settings.Designer.cs @@ -0,0 +1,30 @@ +//------------------------------------------------------------------------------ +// +// This code was generated by a tool. +// Runtime Version:4.0.30319.42000 +// +// Changes to this file may cause incorrect behavior and will be lost if +// the code is regenerated. +// +//------------------------------------------------------------------------------ + +namespace RPCMon.Properties +{ + + + [global::System.Runtime.CompilerServices.CompilerGeneratedAttribute()] + [global::System.CodeDom.Compiler.GeneratedCodeAttribute("Microsoft.VisualStudio.Editors.SettingsDesigner.SettingsSingleFileGenerator", "11.0.0.0")] + internal sealed partial class Settings : global::System.Configuration.ApplicationSettingsBase + { + + private static Settings defaultInstance = ((Settings)(global::System.Configuration.ApplicationSettingsBase.Synchronized(new Settings()))); + + public static Settings Default + { + get + { + return defaultInstance; + } + } + } +} diff --git a/RPCMon/Properties/Settings.settings b/RPCMon/Properties/Settings.settings new file mode 100644 index 0000000..3964565 --- /dev/null +++ b/RPCMon/Properties/Settings.settings @@ -0,0 +1,7 @@ + + + + + + + diff --git a/RPCMon/RPCMon.csproj b/RPCMon/RPCMon.csproj new file mode 100644 index 0000000..a54f9b8 --- /dev/null +++ b/RPCMon/RPCMon.csproj @@ -0,0 +1,185 @@ + + + + + Debug + AnyCPU + {9DE6BB01-5955-4EE7-BD74-B47AEC15EFBB} + WinExe + RPCMon + RPCMon + v4.6.1 + 512 + true + true + + + x64 + true + full + false + bin\Debug\ + DEBUG;TRACE + prompt + 4 + true + + + AnyCPU + pdbonly + true + bin\Release\ + TRACE + prompt + 4 + + + + ..\Packages\Microsoft.Diagnostics.Tracing.TraceEvent.2.0.42\lib\net45\Microsoft.Diagnostics.Tracing.TraceEvent.dll + + + ..\Packages\Newtonsoft.Json.13.0.1\lib\net45\Newtonsoft.Json.dll + + + ..\packages\NtApiDotNet.1.1.33\lib\net461\NtApiDotNet.dll + + + + + + + + + + + + + + + + + + Form + + + ColumnFilter.cs + + + Form + + + ColumnSelection.cs + + + + + + + Form + + + Form1.cs + + + Form + + + FormBuildDB.cs + + + Form + + + FormHighlighting.cs + + + Form + + + FormSearch.cs + + + + + + + ColumnFilter.cs + + + ColumnSelection.cs + + + Form1.cs + + + FormBuildDB.cs + + + FormHighlighting.cs + + + FormSearch.cs + + + ResXFileCodeGenerator + Resources.Designer.cs + Designer + + + True + Resources.resx + True + + + + SettingsSingleFileGenerator + Settings.Designer.cs + + + True + Settings.settings + True + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/RPCMon/Resources/duplicate-disable.png b/RPCMon/Resources/duplicate-disable.png new file mode 100644 index 0000000..5d188d1 Binary files /dev/null and b/RPCMon/Resources/duplicate-disable.png differ diff --git a/RPCMon/Resources/duplicate.png b/RPCMon/Resources/duplicate.png new file mode 100644 index 0000000..20d629b Binary files /dev/null and b/RPCMon/Resources/duplicate.png differ diff --git a/RPCMon/Resources/eraser.png b/RPCMon/Resources/eraser.png new file mode 100644 index 0000000..31a1be3 Binary files /dev/null and b/RPCMon/Resources/eraser.png differ diff --git a/RPCMon/Resources/filter.png b/RPCMon/Resources/filter.png new file mode 100644 index 0000000..801f84e Binary files /dev/null and b/RPCMon/Resources/filter.png differ diff --git a/RPCMon/Resources/find.png b/RPCMon/Resources/find.png new file mode 100644 index 0000000..bf35c01 Binary files /dev/null and b/RPCMon/Resources/find.png differ diff --git a/RPCMon/Resources/grid-disable.png b/RPCMon/Resources/grid-disable.png new file mode 100644 index 0000000..9d4ca26 Binary files /dev/null and b/RPCMon/Resources/grid-disable.png differ diff --git a/RPCMon/Resources/grid.png b/RPCMon/Resources/grid.png new file mode 100644 index 0000000..24133b5 Binary files /dev/null and b/RPCMon/Resources/grid.png differ diff --git a/RPCMon/Resources/highlighter.png b/RPCMon/Resources/highlighter.png new file mode 100644 index 0000000..5f62dbd Binary files /dev/null and b/RPCMon/Resources/highlighter.png differ diff --git a/RPCMon/Resources/pause-button.png b/RPCMon/Resources/pause-button.png new file mode 100644 index 0000000..64432c5 Binary files /dev/null and b/RPCMon/Resources/pause-button.png differ diff --git a/RPCMon/Resources/share.png b/RPCMon/Resources/share.png new file mode 100644 index 0000000..d30bd6b Binary files /dev/null and b/RPCMon/Resources/share.png differ diff --git a/RPCMon/Resources/startIcon.png b/RPCMon/Resources/startIcon.png new file mode 100644 index 0000000..15dceb4 Binary files /dev/null and b/RPCMon/Resources/startIcon.png differ diff --git a/RPCMon/Resources/stopIcon.png b/RPCMon/Resources/stopIcon.png new file mode 100644 index 0000000..32177b3 Binary files /dev/null and b/RPCMon/Resources/stopIcon.png differ diff --git a/RPCMon/Utils.cs b/RPCMon/Utils.cs new file mode 100644 index 0000000..f9b34d3 --- /dev/null +++ b/RPCMon/Utils.cs @@ -0,0 +1,66 @@ +using System; +using System.Collections.Generic; +using System.Linq; +using System.Text; +using System.Threading.Tasks; + + +namespace RPCMon +{ + public class Utils + { + public const int MAIN_GRID_MAX_COLUMNS = 16; + + public enum eColumnNames + { + PID = 0, + TID, + ProcessName, + UUID, + Module, + ModulePath, + ProceduresCount, + Service, + Function, + NetworkAddress, + Protocol, + Endpoint, + Options, + AuthenticationLevel, + AuthenticationService, + ImpersonationLevel, + + } + + public enum eFilterNames + { + Column, Relation, Value, Action + } + + public enum eFormNames + { + FormColumnFilter, + FormHighlighFilter + } + + public static readonly Dictionary m_ColumnMapToIndex = new Dictionary() + { + { eColumnNames.PID.ToString(), (int)eColumnNames.PID }, + { eColumnNames.TID.ToString(), (int)eColumnNames.TID }, + { eColumnNames.ProcessName.ToString(), (int)eColumnNames.ProcessName }, + { eColumnNames.UUID.ToString(), (int)eColumnNames.UUID }, + { eColumnNames.Module.ToString(), (int)eColumnNames.Module }, + { eColumnNames.ModulePath.ToString() , (int)eColumnNames.ModulePath }, + { eColumnNames.UUID.ToString(), (int)eColumnNames.UUID }, + { eColumnNames.UUID.ToString(), (int)eColumnNames.UUID }, + { eColumnNames.Function.ToString(), (int)eColumnNames.Function }, + { eColumnNames.NetworkAddress.ToString(), (int)eColumnNames.NetworkAddress }, + { eColumnNames.Protocol.ToString(), (int)eColumnNames.Protocol}, + { eColumnNames.Endpoint.ToString(), (int)eColumnNames.Endpoint}, + { eColumnNames.Options.ToString(), (int)eColumnNames.Options}, + { eColumnNames.AuthenticationLevel.ToString(), (int)eColumnNames.AuthenticationLevel}, + { eColumnNames.AuthenticationService.ToString(), (int)eColumnNames.AuthenticationService}, + { eColumnNames.ImpersonationLevel.ToString(), (int)eColumnNames.ImpersonationLevel} + }; + } +} diff --git a/RPCMon/packages.config b/RPCMon/packages.config new file mode 100644 index 0000000..33bb74f --- /dev/null +++ b/RPCMon/packages.config @@ -0,0 +1,4 @@ + + + + \ No newline at end of file diff --git a/TraceParser/Microsoft-Windows-RPC.cs b/TraceParser/Microsoft-Windows-RPC.cs new file mode 100644 index 0000000..392e01a --- /dev/null +++ b/TraceParser/Microsoft-Windows-RPC.cs @@ -0,0 +1,1395 @@ +// +using System; +using System.Diagnostics; +using System.Diagnostics.Tracing; +using System.Text; +using Microsoft.Diagnostics.Tracing; +using Address = System.UInt64; + +#pragma warning disable 1591 // disable warnings on XML comments not being present + +// This code was automatically generated by the TraceParserGen tool, which converts +// an ETW event manifest into strongly typed C# classes. +namespace Microsoft.Diagnostics.Tracing.Parsers +{ + using Microsoft.Diagnostics.Tracing.Parsers.MicrosoftWindowsRPC; + + [System.CodeDom.Compiler.GeneratedCode("traceparsergen", "2.0")] + public sealed class MicrosoftWindowsRPCTraceEventParser : TraceEventParser + { + public static string ProviderName = "Microsoft-Windows-RPC"; + public static Guid ProviderGuid = new Guid(unchecked((int) 0x6ad52b32), unchecked((short) 0xd609), unchecked((short) 0x4be9), 0xae, 0x07, 0xce, 0x8d, 0xae, 0x93, 0x7e, 0x39); + public enum Keywords : long + { + }; + + public MicrosoftWindowsRPCTraceEventParser(TraceEventSource source) : base(source) {} + + public event Action Debug + { + add + { + RegisterTemplate(new DebugArgs_V1TraceData(value, 4, 3, "Debug", DebugTaskGuid, 0, "", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 4, DebugTaskGuid); + } + } + public event Action Debug10 + { + add + { + RegisterTemplate(new Debug10Args_V1TraceData(value, 10, 3, "Debug", DebugTaskGuid, 0, "", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 10, DebugTaskGuid); + } + } + public event Action Debug11 + { + add + { + RegisterTemplate(new Debug10Args_V1TraceData(value, 11, 3, "Debug", DebugTaskGuid, 0, "", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 11, DebugTaskGuid); + } + } + public event Action DebugStart + { + add + { + RegisterTemplate(new DebugStartArgs_V1TraceData(value, 12, 3, "Debug", DebugTaskGuid, 1, "Start", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 12, DebugTaskGuid); + } + } + public event Action DebugStop + { + add + { + RegisterTemplate(new DebugStopArgs_V1TraceData(value, 13, 3, "Debug", DebugTaskGuid, 2, "Stop", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 13, DebugTaskGuid); + } + } + public event Action FunctionTraceStart + { + add + { + RegisterTemplate(new FunctionTraceStartArgs_V1TraceData(value, 14, 4, "FunctionTrace", FunctionTraceTaskGuid, 1, "Start", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 14, FunctionTraceTaskGuid); + } + } + public event Action FunctionTraceStart16 + { + add + { + RegisterTemplate(new FunctionTraceStart16Args_V1TraceData(value, 16, 4, "FunctionTrace", FunctionTraceTaskGuid, 1, "Start", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 16, FunctionTraceTaskGuid); + } + } + public event Action FunctionTraceStop + { + add + { + RegisterTemplate(new FunctionTraceStopArgs_V1TraceData(value, 15, 4, "FunctionTrace", FunctionTraceTaskGuid, 2, "Stop", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 15, FunctionTraceTaskGuid); + } + } + public event Action RpcClientCallStart + { + add + { + RegisterTemplate(new RpcClientCallStartArgs_V1TraceData(value, 5, 1, "RpcClientCall", RpcClientCallTaskGuid, 1, "Start", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 5, RpcClientCallTaskGuid); + } + } + public event Action RpcClientCallStop + { + add + { + RegisterTemplate(new RpcClientCallStopArgs_V1TraceData(value, 1, 1, "RpcClientCall", RpcClientCallTaskGuid, 2, "Stop", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 1, RpcClientCallTaskGuid); + } + } + public event Action RpcClientCallStop7 + { + add + { + RegisterTemplate(new RpcClientCallStop7Args_V1TraceData(value, 7, 1, "RpcClientCall", RpcClientCallTaskGuid, 2, "Stop", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 7, RpcClientCallTaskGuid); + } + } + public event Action RpcServerCall + { + add + { + RegisterTemplate(new RpcServerCallArgs_V1TraceData(value, 2, 2, "RpcServerCall", RpcServerCallTaskGuid, 0, "", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 2, RpcServerCallTaskGuid); + } + } + public event Action RpcServerCallStart + { + add + { + RegisterTemplate(new RpcServerCallStartArgs_V1TraceData(value, 6, 2, "RpcServerCall", RpcServerCallTaskGuid, 1, "Start", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 6, RpcServerCallTaskGuid); + } + } + public event Action RpcServerCallStop + { + add + { + RegisterTemplate(new RpcClientCallStop7Args_V1TraceData(value, 8, 2, "RpcServerCall", RpcServerCallTaskGuid, 2, "Stop", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 8, RpcServerCallTaskGuid); + } + } + public event Action task_0 + { + add + { + RegisterTemplate(new task_0Args_V1TraceData(value, 3, 0, "task_0", task_0TaskGuid, 0, "", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 3, task_0TaskGuid); + } + } + public event Action task_09 + { + add + { + RegisterTemplate(new RpcClientCallStop7Args_V1TraceData(value, 9, 0, "task_0", task_0TaskGuid, 0, "", ProviderGuid, ProviderName)); + } + remove + { + source.UnregisterEventTemplate(value, 9, task_0TaskGuid); + } + } + + #region private + protected override string GetProviderName() { return ProviderName; } + + static private DebugArgs_V1TraceData DebugTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new DebugArgs_V1TraceData(action, 4, 3, "Debug", Guid.Empty, 0, "", ProviderGuid, ProviderName ); + } + static private Debug10Args_V1TraceData Debug10Template(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new Debug10Args_V1TraceData(action, 10, 3, "Debug", Guid.Empty, 0, "", ProviderGuid, ProviderName ); + } + static private Debug10Args_V1TraceData Debug11Template(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new Debug10Args_V1TraceData(action, 11, 3, "Debug", Guid.Empty, 0, "", ProviderGuid, ProviderName ); + } + static private DebugStartArgs_V1TraceData DebugStartTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new DebugStartArgs_V1TraceData(action, 12, 3, "Debug", Guid.Empty, 1, "Start", ProviderGuid, ProviderName ); + } + static private DebugStopArgs_V1TraceData DebugStopTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new DebugStopArgs_V1TraceData(action, 13, 3, "Debug", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName ); + } + static private FunctionTraceStartArgs_V1TraceData FunctionTraceStartTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new FunctionTraceStartArgs_V1TraceData(action, 14, 4, "FunctionTrace", Guid.Empty, 1, "Start", ProviderGuid, ProviderName ); + } + static private FunctionTraceStart16Args_V1TraceData FunctionTraceStart16Template(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new FunctionTraceStart16Args_V1TraceData(action, 16, 4, "FunctionTrace", Guid.Empty, 1, "Start", ProviderGuid, ProviderName ); + } + static private FunctionTraceStopArgs_V1TraceData FunctionTraceStopTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new FunctionTraceStopArgs_V1TraceData(action, 15, 4, "FunctionTrace", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName ); + } + static private RpcClientCallStartArgs_V1TraceData RpcClientCallStartTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcClientCallStartArgs_V1TraceData(action, 5, 1, "RpcClientCall", Guid.Empty, 1, "Start", ProviderGuid, ProviderName ); + } + static private RpcClientCallStopArgs_V1TraceData RpcClientCallStopTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcClientCallStopArgs_V1TraceData(action, 1, 1, "RpcClientCall", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName ); + } + static private RpcClientCallStop7Args_V1TraceData RpcClientCallStop7Template(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcClientCallStop7Args_V1TraceData(action, 7, 1, "RpcClientCall", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName ); + } + static private RpcServerCallArgs_V1TraceData RpcServerCallTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcServerCallArgs_V1TraceData(action, 2, 2, "RpcServerCall", Guid.Empty, 0, "", ProviderGuid, ProviderName ); + } + static private RpcServerCallStartArgs_V1TraceData RpcServerCallStartTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcServerCallStartArgs_V1TraceData(action, 6, 2, "RpcServerCall", Guid.Empty, 1, "Start", ProviderGuid, ProviderName ); + } + static private RpcClientCallStop7Args_V1TraceData RpcServerCallStopTemplate(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcClientCallStop7Args_V1TraceData(action, 8, 2, "RpcServerCall", Guid.Empty, 2, "Stop", ProviderGuid, ProviderName ); + } + static private task_0Args_V1TraceData task_0Template(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new task_0Args_V1TraceData(action, 3, 0, "task_0", Guid.Empty, 0, "", ProviderGuid, ProviderName ); + } + static private RpcClientCallStop7Args_V1TraceData task_09Template(Action action) + { // action, eventid, taskid, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName + return new RpcClientCallStop7Args_V1TraceData(action, 9, 0, "task_0", Guid.Empty, 0, "", ProviderGuid, ProviderName ); + } + + static private volatile TraceEvent[] s_templates; + protected override void EnumerateTemplates(Func eventsToObserve, Action callback) + { + if (s_templates == null) + { + var templates = new TraceEvent[16]; + templates[0] = new RpcClientCallStopTraceData(null, 1, 1, "RpcClientCall", RpcClientCallTaskGuid, 2, "Stop", ProviderGuid, ProviderName); + templates[1] = new RpcServerCallTraceData(null, 2, 2, "RpcServerCall", RpcServerCallTaskGuid, 0, "", ProviderGuid, ProviderName); + templates[2] = new task_0TraceData(null, 3, 0, "task_0", task_0TaskGuid, 0, "", ProviderGuid, ProviderName); + templates[3] = new DebugTraceData(null, 4, 3, "Debug", DebugTaskGuid, 0, "", ProviderGuid, ProviderName); + templates[4] = new RpcClientCallStartTraceData(null, 5, 1, "RpcClientCall", RpcClientCallTaskGuid, 1, "Start", ProviderGuid, ProviderName); + templates[5] = new RpcServerCallStartTraceData(null, 6, 2, "RpcServerCall", RpcServerCallTaskGuid, 1, "Start", ProviderGuid, ProviderName); + templates[6] = new RpcClientCallStopTraceData(null, 7, 1, "RpcClientCall", RpcClientCallTaskGuid, 2, "Stop", ProviderGuid, ProviderName); + templates[7] = new RpcServerCallStopTraceData(null, 8, 2, "RpcServerCall", RpcServerCallTaskGuid, 2, "Stop", ProviderGuid, ProviderName); + templates[8] = new task_0TraceData(null, 9, 0, "task_0", task_0TaskGuid, 0, "", ProviderGuid, ProviderName); + templates[9] = new DebugTraceData(null, 10, 3, "Debug", DebugTaskGuid, 0, "", ProviderGuid, ProviderName); + templates[10] = new DebugTraceData(null, 11, 3, "Debug", DebugTaskGuid, 0, "", ProviderGuid, ProviderName); + templates[11] = new DebugStartTraceData(null, 12, 3, "Debug", DebugTaskGuid, 1, "Start", ProviderGuid, ProviderName); + templates[12] = new DebugStopTraceData(null, 13, 3, "Debug", DebugTaskGuid, 2, "Stop", ProviderGuid, ProviderName); + templates[13] = new FunctionTraceStartTraceData(null, 14, 4, "FunctionTrace", FunctionTraceTaskGuid, 1, "Start", ProviderGuid, ProviderName); + templates[14] = new FunctionTraceStopTraceData(null, 15, 4, "FunctionTrace", FunctionTraceTaskGuid, 2, "Stop", ProviderGuid, ProviderName); + templates[15] = new FunctionTraceStartTraceData(null, 16, 4, "FunctionTrace", FunctionTraceTaskGuid, 1, "Start", ProviderGuid, ProviderName); + s_templates = templates; + } + foreach (var template in s_templates) + if (eventsToObserve == null || eventsToObserve(template.ProviderName, template.EventName) == EventFilterResponse.AcceptEvent) + callback(template); + } + + #endregion + } +} + +namespace Microsoft.Diagnostics.Tracing.Parsers.MicrosoftWindowsRPC +{ + public sealed class DebugArgs_V1TraceData : TraceEvent + { + public SubjectTypes Subject { get { return (SubjectTypes)GetByteAt(0); } } + public int Verb { get { return GetByteAt(1); } } + public long SubjectPointer { get { return GetInt64At(2); } } + public long ObjectPointer { get { return GetInt64At(10); } } + public long DataPointer { get { return GetInt64At(18); } } + + #region Private + internal DebugArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 26)); + Debug.Assert(!(Version > 1 && EventDataLength < 26)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "Subject", Subject); + XmlAttrib(sb, "Verb", Verb); + XmlAttrib(sb, "SubjectPointer", SubjectPointer); + XmlAttrib(sb, "ObjectPointer", ObjectPointer); + XmlAttrib(sb, "DataPointer", DataPointer); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "Subject", "Verb", "SubjectPointer", "ObjectPointer", "DataPointer"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return Subject; + case 1: + return Verb; + case 2: + return SubjectPointer; + case 3: + return ObjectPointer; + case 4: + return DataPointer; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class Debug10Args_V1TraceData : TraceEvent + { + public long SubjectPointer { get { return GetInt64At(0); } } + public int FragmentSize { get { return GetInt32At(8); } } + public byte[] Fragment { get { return GetByteArrayAt(12, FragmentSize); } } + + #region Private + internal Debug10Args_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 0+ (FragmentSize*1)+12)); + Debug.Assert(!(Version > 1 && EventDataLength < 0+ (FragmentSize*1)+12)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "SubjectPointer", SubjectPointer); + XmlAttrib(sb, "FragmentSize", FragmentSize); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "SubjectPointer", "FragmentSize", "Fragment"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return SubjectPointer; + case 1: + return FragmentSize; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class DebugStartArgs_V1TraceData : TraceEvent + { + public int ObjectType { get { return GetInt32At(0); } } + public int Operation { get { return GetInt32At(4); } } + public long Address { get { return GetInt64At(8); } } + public long Data { get { return GetInt64At(16); } } + + #region Private + internal DebugStartArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 24)); + Debug.Assert(!(Version > 1 && EventDataLength < 24)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "ObjectType", ObjectType); + XmlAttrib(sb, "Operation", Operation); + XmlAttrib(sb, "Address", Address); + XmlAttrib(sb, "Data", Data); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "ObjectType", "Operation", "Address", "Data"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return ObjectType; + case 1: + return Operation; + case 2: + return Address; + case 3: + return Data; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class DebugStopArgs_V1TraceData : TraceEvent + { + public RpcHttp2ObjectTypes ObjectType { get { return (RpcHttp2ObjectTypes)GetInt32At(0); } } + public int Operation { get { return GetInt32At(4); } } + public long Address { get { return GetInt64At(8); } } + public long Data { get { return GetInt64At(16); } } + + #region Private + internal DebugStopArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 24)); + Debug.Assert(!(Version > 1 && EventDataLength < 24)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "ObjectType", ObjectType); + XmlAttrib(sb, "Operation", Operation); + XmlAttrib(sb, "Address", Address); + XmlAttrib(sb, "Data", Data); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "ObjectType", "Operation", "Address", "Data"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return ObjectType; + case 1: + return Operation; + case 2: + return Address; + case 3: + return Data; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class FunctionTraceStartArgs_V1TraceData : TraceEvent + { + public Guid InterfaceUuid { get { return GetGuidAt(0); } } + public Guid TypeMgrUuid { get { return GetGuidAt(16); } } + public int Flags { get { return GetInt32At(32); } } + public int MaxCalls { get { return GetInt32At(36); } } + public int SDSize { get { return GetInt32At(40); } } + public byte[] SD { get { return GetByteArrayAt(44, SDSize); } } + + #region Private + internal FunctionTraceStartArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 0+ (SDSize*1)+44)); + Debug.Assert(!(Version > 1 && EventDataLength < 0+ (SDSize*1)+44)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "InterfaceUuid", InterfaceUuid); + XmlAttrib(sb, "TypeMgrUuid", TypeMgrUuid); + XmlAttrib(sb, "Flags", Flags); + XmlAttrib(sb, "MaxCalls", MaxCalls); + XmlAttrib(sb, "SDSize", SDSize); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "InterfaceUuid", "TypeMgrUuid", "Flags", "MaxCalls", "SDSize", "SD"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return InterfaceUuid; + case 1: + return TypeMgrUuid; + case 2: + return Flags; + case 3: + return MaxCalls; + case 4: + return SDSize; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class FunctionTraceStart16Args_V1TraceData : TraceEvent + { + public string Protocol { get { return GetUnicodeStringAt(0); } } + public string Endpoint { get { return GetUnicodeStringAt(SkipUnicodeString(0)); } } + public string NetworkAddress { get { return GetUnicodeStringAt(SkipUnicodeString(SkipUnicodeString(0))); } } + public int PendingQueueSize { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(0)))); } } + public int EndpointFlags { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(0)))+4); } } + public int NicFlags { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(0)))+8); } } + + #region Private + internal FunctionTraceStart16Args_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(0)))+12)); + Debug.Assert(!(Version > 1 && EventDataLength < SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(0)))+12)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "Protocol", Protocol); + XmlAttrib(sb, "Endpoint", Endpoint); + XmlAttrib(sb, "NetworkAddress", NetworkAddress); + XmlAttrib(sb, "PendingQueueSize", PendingQueueSize); + XmlAttrib(sb, "EndpointFlags", EndpointFlags); + XmlAttrib(sb, "NicFlags", NicFlags); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "Protocol", "Endpoint", "NetworkAddress", "PendingQueueSize", "EndpointFlags", "NicFlags"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return Protocol; + case 1: + return Endpoint; + case 2: + return NetworkAddress; + case 3: + return PendingQueueSize; + case 4: + return EndpointFlags; + case 5: + return NicFlags; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class FunctionTraceStopArgs_V1TraceData : TraceEvent + { + public Guid InterfaceUuid { get { return GetGuidAt(0); } } + public Guid TypeMgrUuid { get { return GetGuidAt(16); } } + public int Flags { get { return GetInt32At(32); } } + public int MaxCalls { get { return GetInt32At(36); } } + + #region Private + internal FunctionTraceStopArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 40)); + Debug.Assert(!(Version > 1 && EventDataLength < 40)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "InterfaceUuid", InterfaceUuid); + XmlAttrib(sb, "TypeMgrUuid", TypeMgrUuid); + XmlAttrib(sb, "Flags", Flags); + XmlAttrib(sb, "MaxCalls", MaxCalls); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "InterfaceUuid", "TypeMgrUuid", "Flags", "MaxCalls"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return InterfaceUuid; + case 1: + return TypeMgrUuid; + case 2: + return Flags; + case 3: + return MaxCalls; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class RpcClientCallStartArgs_V1TraceData : TraceEvent + { + public Guid InterfaceUuid { get { return GetGuidAt(0); } } + public int ProcNum { get { return GetInt32At(16); } } + public ProtocolSequences Protocol { get { return (ProtocolSequences)GetInt32At(20); } } + public string NetworkAddress { get { return GetUnicodeStringAt(24); } } + public string Endpoint { get { return GetUnicodeStringAt(SkipUnicodeString(24)); } } + public string Options { get { return GetUnicodeStringAt(SkipUnicodeString(SkipUnicodeString(24))); } } + public int AuthenticationLevel { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24)))); } } + public AuthenticationServices AuthenticationService { get { return (AuthenticationServices)GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24)))+4); } } + public int ImpersonationLevel { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24)))+8); } } + + #region Private + internal RpcClientCallStartArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24)))+12)); + Debug.Assert(!(Version > 1 && EventDataLength < SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24)))+12)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "InterfaceUuid", InterfaceUuid); + XmlAttrib(sb, "ProcNum", ProcNum); + XmlAttrib(sb, "Protocol", Protocol); + XmlAttrib(sb, "NetworkAddress", NetworkAddress); + XmlAttrib(sb, "Endpoint", Endpoint); + XmlAttrib(sb, "Options", Options); + XmlAttrib(sb, "AuthenticationLevel", AuthenticationLevel); + XmlAttrib(sb, "AuthenticationService", AuthenticationService); + XmlAttrib(sb, "ImpersonationLevel", ImpersonationLevel); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "InterfaceUuid", "ProcNum", "Protocol", "NetworkAddress", "Endpoint", "Options", "AuthenticationLevel", "AuthenticationService", "ImpersonationLevel"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return InterfaceUuid; + case 1: + return ProcNum; + case 2: + return Protocol; + case 3: + return NetworkAddress; + case 4: + return Endpoint; + case 5: + return Options; + case 6: + return AuthenticationLevel; + case 7: + return AuthenticationService; + case 8: + return ImpersonationLevel; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class RpcClientCallStopArgs_V1TraceData : TraceEvent + { + public string ImageName { get { return GetUnicodeStringAt(0); } } + public string ComputerName { get { return GetUnicodeStringAt(SkipUnicodeString(0)); } } + public int ProcessID { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(0))); } } + // Skipping TimeStamp + public int GeneratingComponent { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(0))+4); } } + public int Status { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(0))+8); } } + public int DetectionLocation { get { return GetInt16At(SkipUnicodeString(SkipUnicodeString(0))+12); } } + public int Flags { get { return GetInt16At(SkipUnicodeString(SkipUnicodeString(0))+14); } } + public int NumberOfParameters { get { return GetInt16At(SkipUnicodeString(SkipUnicodeString(0))+16); } } + public long Params(int arrayIndex) { return GetInt64At(SkipUnicodeString(SkipUnicodeString(0))+18 + (arrayIndex * HostOffset(8, 0))); } + + #region Private + internal RpcClientCallStopArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != SkipUnicodeString(SkipUnicodeString(0))+18)); + Debug.Assert(!(Version > 1 && EventDataLength < SkipUnicodeString(SkipUnicodeString(0))+18)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "ImageName", ImageName); + XmlAttrib(sb, "ComputerName", ComputerName); + XmlAttrib(sb, "ProcessID", ProcessID); + XmlAttrib(sb, "GeneratingComponent", GeneratingComponent); + XmlAttrib(sb, "Status", Status); + XmlAttrib(sb, "DetectionLocation", DetectionLocation); + XmlAttrib(sb, "Flags", Flags); + XmlAttrib(sb, "NumberOfParameters", NumberOfParameters); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "ImageName", "ComputerName", "ProcessID", "GeneratingComponent", "Status", "DetectionLocation", "Flags", "NumberOfParameters", "Params"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return ImageName; + case 1: + return ComputerName; + case 2: + return ProcessID; + case 3: + return GeneratingComponent; + case 4: + return Status; + case 5: + return DetectionLocation; + case 6: + return Flags; + case 7: + return NumberOfParameters; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class RpcClientCallStop7Args_V1TraceData : TraceEvent + { + public int Status { get { return GetInt32At(0); } } + + #region Private + internal RpcClientCallStop7Args_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != 4)); + Debug.Assert(!(Version > 1 && EventDataLength < 4)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "Status", Status); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "Status"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return Status; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class RpcServerCallArgs_V1TraceData : TraceEvent + { + public string ImangeName { get { return GetUnicodeStringAt(0); } } + public Guid InterfaceUuid { get { return GetGuidAt(SkipUnicodeString(0)); } } + public Guid FilterKey { get { return GetGuidAt(SkipUnicodeString(0)+16); } } + + #region Private + internal RpcServerCallArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != SkipUnicodeString(0)+32)); + Debug.Assert(!(Version > 1 && EventDataLength < SkipUnicodeString(0)+32)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "ImangeName", ImangeName); + XmlAttrib(sb, "InterfaceUuid", InterfaceUuid); + XmlAttrib(sb, "FilterKey", FilterKey); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "ImangeName", "InterfaceUuid", "FilterKey"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return ImangeName; + case 1: + return InterfaceUuid; + case 2: + return FilterKey; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class RpcServerCallStartArgs_V1TraceData : TraceEvent + { + public Guid InterfaceUuid { get { return GetGuidAt(0); } } + public int ProcNum { get { return GetInt32At(16); } } + public int Protocol { get { return GetInt32At(20); } } + public string NetworkAddress { get { return GetUnicodeStringAt(24); } } + public string Endpoint { get { return GetUnicodeStringAt(SkipUnicodeString(24)); } } + public string Options { get { return GetUnicodeStringAt(SkipUnicodeString(SkipUnicodeString(24))); } } + public int AuthenticationLevel { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24)))); } } + public int AuthenticationService { get { return GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24)))+4); } } + public ImpersonationLevels ImpersonationLevel { get { return (ImpersonationLevels)GetInt32At(SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24)))+8); } } + + #region Private + internal RpcServerCallStartArgs_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24)))+12)); + Debug.Assert(!(Version > 1 && EventDataLength < SkipUnicodeString(SkipUnicodeString(SkipUnicodeString(24)))+12)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "InterfaceUuid", InterfaceUuid); + XmlAttrib(sb, "ProcNum", ProcNum); + XmlAttrib(sb, "Protocol", Protocol); + XmlAttrib(sb, "NetworkAddress", NetworkAddress); + XmlAttrib(sb, "Endpoint", Endpoint); + XmlAttrib(sb, "Options", Options); + XmlAttrib(sb, "AuthenticationLevel", AuthenticationLevel); + XmlAttrib(sb, "AuthenticationService", AuthenticationService); + XmlAttrib(sb, "ImpersonationLevel", ImpersonationLevel); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "InterfaceUuid", "ProcNum", "Protocol", "NetworkAddress", "Endpoint", "Options", "AuthenticationLevel", "AuthenticationService", "ImpersonationLevel"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return InterfaceUuid; + case 1: + return ProcNum; + case 2: + return Protocol; + case 3: + return NetworkAddress; + case 4: + return Endpoint; + case 5: + return Options; + case 6: + return AuthenticationLevel; + case 7: + return AuthenticationService; + case 8: + return ImpersonationLevel; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public sealed class task_0Args_V1TraceData : TraceEvent + { + public string ImageName { get { return GetUnicodeStringAt(0); } } + public int DetectionLocation { get { return GetInt16At(SkipUnicodeString(0)); } } + public int Status { get { return GetInt32At(SkipUnicodeString(0)+2); } } + public int AdditionalData1 { get { return GetInt32At(SkipUnicodeString(0)+6); } } + public int AdditionalData2 { get { return GetInt32At(SkipUnicodeString(0)+10); } } + + #region Private + internal task_0Args_V1TraceData(Action action, int eventID, int task, string taskName, Guid taskGuid, int opcode, string opcodeName, Guid providerGuid, string providerName) + : base(eventID, task, taskName, taskGuid, opcode, opcodeName, providerGuid, providerName) + { + Action = action; + } + protected override void Dispatch() + { + Action(this); + } + protected override void Validate() + { + Debug.Assert(!(Version == 1 && EventDataLength != SkipUnicodeString(0)+14)); + Debug.Assert(!(Version > 1 && EventDataLength < SkipUnicodeString(0)+14)); + } + protected override Delegate Target + { + get { return Action; } + set { Action = (Action) value; } + } + public override StringBuilder ToXml(StringBuilder sb) + { + Prefix(sb); + XmlAttrib(sb, "ImageName", ImageName); + XmlAttrib(sb, "DetectionLocation", DetectionLocation); + XmlAttrib(sb, "Status", Status); + XmlAttrib(sb, "AdditionalData1", AdditionalData1); + XmlAttrib(sb, "AdditionalData2", AdditionalData2); + sb.Append("/>"); + return sb; + } + + public override string[] PayloadNames + { + get + { + if (payloadNames == null) + payloadNames = new string[] { "ImageName", "DetectionLocation", "Status", "AdditionalData1", "AdditionalData2"}; + return payloadNames; + } + } + + public override object PayloadValue(int index) + { + switch (index) + { + case 0: + return ImageName; + case 1: + return DetectionLocation; + case 2: + return Status; + case 3: + return AdditionalData1; + case 4: + return AdditionalData2; + default: + Debug.Assert(false, "Bad field index"); + return null; + } + } + + public static ulong GetKeywords() { return 0; } + public static string GetProviderName() { return "Microsoft-Windows-RPC"; } + public static Guid GetProviderGuid() { return new Guid("6ad52b32-d609-4be9-ae07-ce8dae937e39"); } + private event Action Action; + #endregion + } + public enum AuthenticationServices + { + Negotiate = 0x9, + NTLM = 0xa, + SChannel = 0xe, + Kerberos = 0x10, + Kernel = 0x14, + } + public enum ImpersonationLevels + { + Default = 0x0, + Anonymous = 0x1, + Identify = 0x2, + Impersonate = 0x3, + Delegate = 0x4, + } + public enum ProtocolSequences + { + TCP = 0x1, + NamedPipes = 0x2, + LRPC = 0x3, + RPCHTTP = 0x4, + } + public enum RpcHttp2ObjectTypes + { + SOCKET_CHANNEL = 0x1, + PROXY_SOCKET_CHANNEL = 0x2, + CHANNEL = 0x3, + BOTTOM_CHANNEL = 0x4, + IIS_CHANNEL = 0x5, + RAW_CONNECTION = 0x6, + INITIAL_RAW_CONNECTION = 0x7, + IIS_SENDER_CHANNEL = 0x8, + ENDPOINT_RECEIVER = 0x9, + PLUG_CHANNEL = 0xa, + CLIENT_VC = 0xb, + SERVER_VC = 0xc, + INPROXY_VC = 0xd, + OUTPROXY_VC = 0xe, + PROXY_VC = 0xf, + CDATA_ORIGINATOR = 0x10, + CLIENT_CHANNEL = 0x11, + CALLBACK = 0x12, + FLOW_CONTROL_SENDER = 0x13, + WINHTTP_CALLBACK = 0x14, + WINHTTP_CHANNEL = 0x15, + WINHTTP_RAW = 0x16, + PROXY_RECEIVER = 0x17, + SERVER_CHANNEL = 0x18, + FRAGMENT_RECEIVER = 0x19, + } + public enum SubjectTypes + { + ASSOC = 0x2e, + HTTPv2 = 0x32, + SASSOC = 0x41, + BCACHE2 = 0x42, + SCALL = 0x43, + ADDRESS = 0x44, + ENGINE = 0x45, + CAUSAL_F = 0x46, + GC = 0x47, + HEAP = 0x48, + EEINFO = 0x49, + ALPC = 0x4c, + RESERVED_MEM = 0x4d, + SCONN = 0x4e, + CORRUPT = 0x4f, + PROVIDER = 0x50, + SECCRED = 0x53, + STABLE = 0x54, + PROTOCOL = 0x57, + CASSOC = 0x61, + BCACHE = 0x62, + CCALL = 0x63, + TP_ALPC = 0x64, + CENDPOINT = 0x65, + TP_CALLBACK = 0x66, + HANDLE = 0x68, + IF = 0x69, + TP_IO = 0x6a, + TP_WORK = 0x6b, + CTXHANDLE = 0x6c, + MUTEX = 0x6d, + CCONN = 0x6e, + TRANS_CONN = 0x6f, + PACKET = 0x70, + REFOBJ = 0x72, + SSECCTX = 0x73, + THREAD = 0x74, + TP_TIMER = 0x75, + EVENT = 0x76, + TP_WAIT = 0x77, + EXCEPT = 0x78, + } +} diff --git a/TraceParser/Microsoft-Windows-RPC.xml b/TraceParser/Microsoft-Windows-RPC.xml new file mode 100644 index 0000000..549472d --- /dev/null +++ b/TraceParser/Microsoft-Windows-RPC.xml @@ -0,0 +1,314 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/TraceParser/TraceParserGen.exe b/TraceParser/TraceParserGen.exe new file mode 100644 index 0000000..7b84582 Binary files /dev/null and b/TraceParser/TraceParserGen.exe differ diff --git a/TraceParser/TraceParserGen.exe.config b/TraceParser/TraceParserGen.exe.config new file mode 100644 index 0000000..6c301d3 --- /dev/null +++ b/TraceParser/TraceParserGen.exe.config @@ -0,0 +1,6 @@ + + + + + + \ No newline at end of file diff --git a/TraceParser/TraceParserGen.pdb b/TraceParser/TraceParserGen.pdb new file mode 100644 index 0000000..6eacc4a Binary files /dev/null and b/TraceParser/TraceParserGen.pdb differ diff --git a/TraceParser/TraceParserGen.xml b/TraceParser/TraceParserGen.xml new file mode 100644 index 0000000..d0d37ce --- /dev/null +++ b/TraceParser/TraceParserGen.xml @@ -0,0 +1,1191 @@ + + + + TraceParserGen + + + + + A ProviderManifest represents the XML manifest associated with the provider. + + + + + The name of the ETW provider + + + + + The GUID that uniquely identifies the ETW provider + + + + + The events for the + + + + + returns the name of the keyword which has the bit position bitPos + (bitPos is 0 through 63). It may return null if there is no + keyword name for 'bitPos'. + + + + + returns a string that is the best human readable representation of the keyword set + represented by 'keywords'. It the concatenation of all the keyword names separated + by a comma, as well as a hexadecimal number (if there is anything that can't be + represented by names). + + + + + For debugging + + + + + Read a ProviderManifest from a stream + + + + + Adds an opcode with a given name to the database. 'taskId' can be GlobalScope + if the opcode works for any task. 'manifestName' is the name in the manifest (e.g. "win:Stop") + and 'name' is the name that you will print (e.g. "Stop"). If manifestName is null then + name and manifest name are considered the same. + + + + + An event represents the Event Element in the manifest. It describes the meta-data of one ETW event + + + + + A convenience method that returns the keywords as symbol names (comma separated) + + + + + The fields associated with this event. This can be null if there are no fields. + + + + + The event name is synthesis (concatenation) of the Task and Opcode names. This is never null. + + + + + Technically the Symbol attribute on an event is not part of the model (it is not stored in the binary manifest) + but if it is present, it can be used to create better names. This value can be null. + + + + + Technically the name of the Template for the fields on an event is not part of the model (it is not stored in the binary manifest) + but if it is present, it can be used to create better names. This value can be null. + + + + + Get the line number in the file. Used for error messages. + + + + + We need a two pass system where after all the definitions are parsed, we go back and link + up uses to their defs. This routine does this for Events. + + + + + A field represents one field in a ETW event + + + + + The name of the field. + + + + + If the type is a structure, then this points at its type. 'Enumeration' and 'Type' will be null in this case. + + + + + If Type is a integral type, then Enumeration can be set which gives values either + a bitfield or a enumerated type for the values of the parameter. Otherwise it is null. + + + + + If the type is 'built in' then it has a string name, and this is it. This is null for structs and an integer type for Enumerations. + + + + + There is no Array type. Instead all field can have a 'Count' which might be a number + (for fixed sized arrays) or a name of a Field (for variable sized arrays). This + can be null, which means the field is not an array. + + + + + If set, it indicates that the integer value should be pretty-printed as hexadecimal rather than decimal. + + + + + A struct represents a composite type and can be used in field definitions + + + + + Then name of the type of the structure as a whole. + + + + + A Enumeration represents an enumerated type and can be used in field definitions. + + + + + Things that really should be in System.Array but aren't + + + + + Concatinate two arrays and return the new array result. + + Concatinated array. + + + + Return a new array that has a range of elements removed. + + The array to removed elements from. It is NOT modified. + The index of the first element that will be removed. + The number of elements to be removed. + The shorted array. + + + + Return a new array where a range as been removed and replace with a range from another array. + + The source array to be manipulated. It is NOT modified. + The first element of sourceArray to remove. + The number of elements to remove. Elements after this exist in the + return array + The array that will provide the elements to splice into soruceArray. + The first element in insertArray to splice in. + The number of elements from insertArray to splice in. + The new array that has had the removal range replaced with the insert range. + + + + CommandOptions is a helper class for the Command class. It stores options + that affect the behavior of the execution of Commands and is passes as a + parapeter to the constuctor of a Command. + + It is useful for these options be be on a separate class (rather than + on Command itself), because it is reasonably common to want to have a set + of options passed to several commands, which is not easily possible otherwise. + + + + + Can be assigned to the Timeout Property to indicate infinite timeout. + + + + + CommanOptions holds a set of options that can be passed to the constructor + to the Command Class as well as Command.Run* + + + + + Return a copy an existing set of command options + + The copy of the command options + + + + Normally commands will throw if the subprocess returns a non-zero + exit code. NoThrow suppresses this. + + + + + Updates the NoThrow propery and returns the updated commandOptions. + + Updated command options + + + + Normally commands are launched with CreateProcess. However it is + also possible use the Shell Start API. This causes Command to look + up the executable differnetly as well as no wait for the command to + compete before returning. + + + + + Updates the Start propery and returns the updated commandOptions. + + + + + By default commands have a 10 minute timeout (600,000 msec), If this + is inappropriate, the Timeout property can change this. Like all + timouts in .NET, it is in units of milliseconds, and you can use + CommandOptions.Infinite to indicate no timeout. + + + + + Updates the Timeout propery and returns the updated commandOptions. + + + + + Indicates the string will be sent to Console.In for the subprocess. + + + + + Updates the Input propery and returns the updated commandOptions. + + + + + Indicates the current directory the subProcess will have. + + + + + Updates the CurrentDirectory propery and returns the updated commandOptions. + + + + + Indicates the standard output and error of the command should be redirected + to a archiveFile rather than being stored in memory in the 'Output' property of the + command. + + + + + Updates the OutputFile propery and returns the updated commandOptions. + + + + + Indicates the standard output and error of the command should be redirected + to a a TextWriter rather than being stored in memory in the 'Output' property + of the command. + + + + + Updates the OutputStream propery and returns the updated commandOptions. + + + + + Gets the Environment variables that will be set in the subprocess that + differ from current process's environment variables. Any time a string + of the form %VAR% is found in a value of a environment variable it is + replaced with the value of the environment variable at the time the + command is launched. This is useful for example to update the PATH + environment variable eg. "%PATH%;someNewPath" + + + + + Adds the environment variable with the give value to the set of + environmetn variables to be passed to the sub-process and returns the + updated commandOptions. Any time a string + of the form %VAR% is found in a value of a environment variable it is + replaced with the value of the environment variable at the time the + command is launched. This is useful for example to update the PATH + environment variable eg. "%PATH%;someNewPath" + + + + + Command represents a running of a command lineNumber process. It is basically + a wrapper over System.Diagnostics.Process, which hides the complexitity + of System.Diagnostics.Process, and knows how to capture output and otherwise + makes calling commands very easy. + + + + + The time the process started. + + + + + returns true if the process has exited. + + + + + The time the processed Exited. (HasExited should be true before calling) + + + + + The duration of the command (HasExited should be true before calling) + + + + + The operating system ID for the subprocess. + + + + + The process exit code for the subprocess. (HasExited should be true before calling) + Often this does not need to be checked because Command.Run will throw an exception + if it is not zero. However it is useful if the CommandOptions.NoThrow property + was set. + + + + + The standard output and standard error output from the command. This + is accumulated in real time so it can vary if the process is still running. + + This property is NOT available if the CommandOptions.OutputFile or CommandOptions.OutputStream + is specified since the output is being redirected there. If a large amoutn of output is + expected (> 1Meg), the Run.AddOutputStream(Stream) is recommended for retrieving it since + the large string is never materialized at one time. + + + + + Returns that CommandOptions structure that holds all the options that affect + the running of the command (like Timeout, Input ...) + + + + + Run 'commandLine', sending the output to the console, and wait for the command to complete. + This simulates what batch filedo when executing their commands. It is a bit more verbose + by default, however + + The command lineNumber to run as a subprocess + Additional qualifiers that control how the process is run + A Command structure that can be queried to determine ExitCode, Output, etc. + + + + Run 'commandLine' as a subprocess and waits for the command to complete. + Output is captured and placed in the 'Output' property of the returned Command + structure. + + The command lineNumber to run as a subprocess + Additional qualifiers that control how the process is run + A Command structure that can be queried to determine ExitCode, Output, etc. + + + + Launch a new command and returns the Command object that can be used to monitor + the restult. It does not wait for the command to complete, however you + can call 'Wait' to do that, or use the 'Run' or 'RunToConsole' methods. */ + + The command lineNumber to run as a subprocess + Additional qualifiers that control how the process is run + A Command structure that can be queried to determine ExitCode, Output, etc. + + + + Create a subprocess to run 'commandLine' with no special options. + The command lineNumber to run as a subprocess + + + + + Wait for a started process to complete (HasExited will be true on return) + + Wait returns that 'this' pointer. + + + + Throw a error if the command exited with a non-zero exit code + printing useful diagnostic information along with the thrown message. + This is useful when NoThrow is specified, and after post-processing + you determine that the command really did fail, and an normal + Command.Run failure was the appropriate action. + + An additional message to print in the throw (can be null) + + + + Get the underlying process object. Generally not used. + + + + + Kill the process (and any child processses (recursively) associated with the + running command). Note that it may not be able to kill everything it should + if the child-parent' chain is broken by a child that creates a subprocess and + then dies itself. This is reasonably uncommon, however. + + + + + Kill the process (and any child processses (recursively) associated with the + running command). Note that it may not be able to kill everything it should + if the child-parent' chain is broken by a child that creates a subprocess and + then dies itself. This is reasonably uncommon, however. + + + + + #Overview + + The code:CommandLineParser is a utility for parsing command lines. Command lines consist of three basic + entities. A command can have any (or none) of the following (separated by whitespace of any size). + + * PARAMETERS - this are non-space strings. They are positional (logicaly they are numbered). Strings + with space can be specified by enclosing in double quotes. + + * QUALIFERS - Qualifiers are name-value pairs. The following syntax is supported. + * -QUALIFER + * -QUALIFER:VALUE + * -QUALIFER=VALUE + * -QUALIFER VALUE + + The end of a value is delimited by space. Again values with spaces can be encoded by enclosing them + the value (or the whole qualifer-value string), in double quotes. The first form (where a value is + not specified is only available for boolean qualifers, and boolean values can not use the form where + the qualifer and value are separated by space. The '/' character can also be used instead of the '-' + to begin a qualifier. + + Unlike parameters, qualifers are NOT ordered. They may occur in any order with respect to the + parameters or other qualifers and THAT ORDER IS NOT COMMUNICATED THROUGH THE PARSER. Thus it is not + possible to have qualifers that only apply to specific parameters. + + * PARAMETER SET SPECIFIER - A parameter set is optional argument that looks like a boolean qualifier + (however if NoDashOnParameterSets is set the dash is not need, so it is looks like a parameter), + that is special in that it decides what qualifers and positional parameters are allowed. See + code:#ParameterSets for more + + #ParameterSets + + Parameter sets are an OPTIONAL facility of code:CommandLineParser that allow more complex command lines + to be specified accurately. It not uncommon for a EXE to have several 'commands' that are logically + independent of one another. For example a for example For example a program might have 'checkin' + 'checkout' 'list' commands, and each of these commands has a different set of parameters that are needed + and qualifers that are allowed. (for example checkout will take a list of file names, list needs nothing, + and checkin needs a comment). Additionally some qualifers (like say -dataBaseName can apply to any of hte + commands). Thus You would like to say that the following command lines are legal + + * EXE -checkout MyFile1 MyFile -dataBaseName:MyDatabase + * EXE -dataBaseName:MyDatabase -list + * EXE -comment "Specifying the comment first" -checkin + * EXE -checkin -comment "Specifying the comment afterward" + + But the following are not + + * EXE -checkout + * EXE -checkout -comment "hello" + * EXE -list MyFile + + You do this by specifying 'checkout', 'list' and 'checkin' as paramters sets. On the command line they + look like boolean qualifers, however they have additional sematantics. They must come before any + positional parameters (because they affect whether the parameters are allowed and what they are named), + and they are mutually exclusive. Each parameter set gets its own set of parameter definitions, and + qualifilers can either be associated with a particular parameter set (like -comment) or global to all + parameter sets (like -dataBaseName) . + + By default parameter set specifiers look like a boolean specifier (begin with a '-' or '/'), however + because it is common practice to NOT have a dash for commands, there there is a Property + code:CommandLineParser.NoDashOnParameterSets that indicates that the dash is not used. If this was + specified then the following command would be legal. + + * EXE checkout MyFile1 MyFile -dataBaseName:MyDatabase + + #DefaultParameterSet + + One parameters set (which has the empty string name), is special in that it is used when no other + parmeter set is matched. This is the default parameter set. For example, if -checkout was defined to be + the default parameter set, then the following would be legal. + + * EXE Myfile1 Myfile + + And would implicitly mean 'checkout' Myfile1, Myfile2 + + If no parameter sets are defined, then all qualifiers and paramters are in the default parameter set. + + ------------------------------------------------------------------------- + #Syntatic ambiguities + + Because whitespace can separate a qualifier from its value AND Qualifier from each other, and because + parameter values might start with a dash (and thus look like qualifers), the syntax is ambiguous. It is + disambigutated with the following rules. + * The command line is parsed into 'arguments' that are spearated by whitespace. Any string enclosed + in "" will be a single argument even if it has embedded whitespace. Double quote characters can + be specified by \" (and a \" literal can be specified by \\" etc). + * Arguments are parsed into qualifiers. This parsing stops if a '--' argument is found. Thus all + qualifers must come before any '--' argument but parameters that begin with - can be specified by + placing them after the '--' argument, + * Qualifers are parsed. Because spaces can be used to separate a qualifer from its value, the type of + the qualifer must be known to parse it. Boolean values never consume an additional parameter, and + non-boolean qualifiers ALWAYS consume the next argument (if there is no : or =). If the empty + string is to be specified, it must use the ':' or '=' form. Moreover it is illegal for the values + that begin with '-' to use space as a separator. They must instead use the ':' or '=' form. This + is because it is too confusing for humans to parse (values look like qualifiers). + * Parameters are parsed. Whatever arguments that were not used by qualifers are parameters. + + -------------------------------------------------------------------------------------------- + #DefiningParametersAndQualifiers + + The following example shows the steps for defining the parameters and qualifers for the example. Note + that the order is important. Qualifers that apply to all commands must be specified first, then each + parameter set then finally the default parameter set. Most steps are optional. + + class CommandLineParserExample1 + { + enum Command { checkout, checkin, list }; + static void Main() + { + string dataBaseName = "myDefaultDataBase"; + string comment = ""; + Command command = checkout; + string[] fileNames = null; + + // Step 1 define the parser. + CommandLineParser commandLineParser = new CommandLineParser(); // by default uses Environment.CommandLine + + // Step 2 (optional) define qualifiers that apply to all parameter sets. + commandLineParser.DefineOptionalParameter("dataBaseName", ref dataBaseName, "Help for database."); + + // Step 3A define the checkin command this includes all parameters and qualifers specific to this command + commandLineParser.DefineParameterSet("checkin", ref command, Command.checkin, "Help for checkin."); + commandLineParser.DefineOptionalQualifers("comment", ref comment, "Help for -comment."); + + // Step 3B define the list command this includes all parameters and qualifers specific to this command + commandLineParser.DefineParameterSet("list", ref command, Command.list, "Help for list."); + + // Step 4 (optional) define the default parameter set (in this case checkout). + commandLineParser.DefineDefaultParameterSet("checkout", ref command, Command.checkout, "Help for checkout."); + commandLineParser.DefineParamter("fileNames", ref fileNames, "Help for fileNames."); + + // Step 5, do final validation (look for undefined qualifiers, extra parameters ... + commandLineParser.CompleteValidation(); + + // Step 6 use the parsed values + Console.WriteLine("Got {0} {1} {2} {3} {4}", dataBaseName, command, comment, string.Join(',', fileNames)); + } + } + + #RequiredAndOptional + + Parameters and qualifiers can be specified as required (the default), or optional. Makeing the default + required was choses to make any mistakes 'obvious' since the parser will fail if a required parameter is + not present (if the default was optional, it would be easy to make what should have been a required + qualifer optional, leading to business logic failiure). + + #ParsedValues + + The class was designed maximize programmer convinience. For each parameter, only one call is needed to + both define the parameter, its help message, and retrive its (strong typed) value. For example + + * int count = 5; + * parser.DefineOptionalQualifer("count", ref count, "help for optional debugs qualifer"); + + Defines a qualifer 'count' and will place its value in the local variable 'count' as a integer. Default + values are supported by doing nothing, so in the example above the default value will be 5. + + Types supported: The parser will support any type that has a static method called 'Parse' taking one + string argument and returning that type. This is true for all primtive types, DateTime, Enumerations, and + any user defined type that follows this convention. + + Array types: The parser has special knowedge of arrays. If the type of a qualifer is an array, then the + string value is assumed to be a ',' separated list of strings which will be parsed as the element type of + the array. In addition to the ',' syntax, it is also legal to specify the qualifer more than once. For + example given the defintion + + * int[] counts; + * parser.DefineOptionalQualifer("counts", ref counts, "help for optional counts qualifier"); + + The command line + + * EXE -counts 5 SomeArg -counts 6 -counts:7 + + Is the same as + + * EXE -counts:5,6,7 SomeArg + + If a qualifier or parameter is an array type and is required, then the array must have at least one + element. If it is optional, then the array can be empty (but in all cases, the array is created, thus + null is never returned by the command line parser). + + By default is it is illegal for a non-array qualifer to be specified more than once. It is however + possible to override this behavior by setting the LastQualiferWins property before defining the qualifer. + + ------------------------------------------------------------------------- + #Misc + + Qualifier can have more than one string form (typically a long and a short form). These are specified + with the code:DefineAliases method. + + After defining all the qualifers and parameters, it is necessary to call the parser to check for the user + specifying a qualifer (or parameter) that does not exist. This is the purpose of the + code:CompleteValidation method. + + When an error is detected at runtime an instance of code:CommandLineParserException is thrown. The error + message in this exception was designed to be suitable to print to the user directly. + + #CommandLineHelp + + The parser also can generate help that is correct for the qualifer and parameter definitions. This can be + accessed from the code:CommandLineParser.GetHelp method. It is also possible to get the help for just a + particular Parameter set with code:CommandLineParser.GetHelpForParameterSet. This help includes command + line syntax, whether the qualifer or parameter is optional or a list, the types of the qualifers and + parameters, the help text, and default values. The help text comes from the 'Define' Methods, and is + properly word-wrapped. Newlines in the help text indicate new paragraphs. + + #AutomaticExceptionProcessingAndHelp + + In the CommandLineParserExample1, while the command line parser did a lot of the work there is still work + needed to make the application user friendly that pretty much all applications need. These include + + * Call the code:CommandLineParser constructor and code:CommandLineParser.CompleteValidation + * Catch any code:CommandLineParserException and print a friendly message + * Define a -? qualifer and wire it up to print the help. + + Since this is stuff that all applications will likely need the + code:CommandLineParser.ParseForConsoleApplication was created to do all of this for you, thus making it + super-easy to make a production quality parser (and concentrate on getting your application logic instead + of command line parsing. Here is an example which defines a 'Ping' command. If you will notice there are + very few lines of code that are not expressing something very specific to this applications. This is how + it should be! + + class CommandLineParserExample2 + { + static void Main() + { + CommandLineParser.ParseForConsoleApplication(delegate(CommandLineParser commandLineParser) + { + // Step 1: Initialize to the defaults + string Host = null; + int Timeout = 1000; + bool Forever = false; + + // Step 2: Define the paramters, in this case there is only the default parameter set. + CommandLineParser.ParseForConsoleApplication(args, delegate(CommandLineParser parser) + { + parser.DefineOptionalQualifier("Timeout", ref Timeout, "Timeout in milliseconds to wait for each reply."); + parser.DefineOptionalQualifier("Forever", ref Forever, "Ping forever."); + parser.DefineDefaultParameterSet("Ping sends a network request to a host to reply to the message (to check for liveness)."); + parser.DefineParameter("Host", ref Host, "The Host to send a ping message to."); + }); + + // Step 3, use the parameters + Console.WriteLine("Got {0} {1} {2} {3}", Host, Timeout, Forever); + }); + } + } + + Using local variables for the parsed arguments if fine when the program is not complex and the values + don't need to be passed around to many routines. In general, however it is often a better idea to + create a class whose sole purpose is to act as a repository for the parsed arguments. This also nicely + separates all command line processing into a single class. This is how the ping example would look in + that style. Notice that the main program no longer holds any command line processing logic. and that + 'commandLine' can be passed to other routines in bulk easily. + + class CommandLineParserExample3 + { + static void Main() + { + CommandLine commandLine = new CommandLine(); + Console.WriteLine("Got {0} {1} {2} {3}", commandLine.Host, commandLine.Timeout, commandLine.Forever); + } + } + class CommandLine + { + public CommandLine() + { + CommandLineParser.ParseForConsoleApplication(args, delegate(CommandLineParser parser) + { + parser.DefineOptionalQualifier("Timeout", ref Timeout, "Timeout in milliseconds to wait for each reply."); + parser.DefineOptionalQualifier("Forever", ref Forever, "Ping forever."); + parser.DefineDefaultParameterSet("Ping sends a network request to a host to reply to the message (to check for liveness)."); + parser.DefineParameter("Host", ref Host, "The Host to send a ping message to."); + }); + } + public string Host = null; + public int Timeout = 1000; + public bool Forever = false; + }; + + see code:#Overview for more + + + + + If you are building a console Application, there is a common structure to parsing arguments. You want + the text formated and output for console windows, and you want /? to be wired up to do this. All + errors should be caught and displayed in a nice way. + + parseBody is the body of the parsing that this outer shell does not provide. + in this delegate, you should be defining all the command line parameters using calls to Define* methods. + + + + + Qualifiers are command line parameters of the form -NAME:VALUE where NAME is an alphanumeric name and + VALUE is a string. The parser also accepts -NAME: VALUE and -NAME VALUE but not -NAME : VALUE For + boolan parameters, the VALUE can be dropped (which means true), and a empty string VALUE means false. + Thus -NAME means the same as -NAME:true and -NAME: means the same as -NAME:false (and boolean + qualifiers DONT allow -NAME true or -NAME false). + + The types that are supported are any type that has a static 'Parse' function that takes a string + (this includes all primitive types as well as DateTime, and Enumerations, as well as arrays of + parsable types (values are comma separated without space). + + See code:#DefiningParametersAndQualifiers + See code:#Overview + Text to print for this qualifer. It will be word-wrapped. Newlines indicate + new paragraphs. + + + + + Like code:DeclareOptionalQualifier except it is an error if this parameter is not on the command line. + Text to print for this qualifer. It will be word-wrapped. Newlines indicate + new paragraphs. + + + + + DefineParameter declares an unnamed parameter (basically any parameter that is not a + qualifier). These are given ordinal numbers (starting at 0). You should declare the parameter in the + desired order. + + See code:#DefiningParametersAndQualifiers + See code:#Overview + Text to print for this qualifer. It will be word-wrapped. Newlines indicate + new paragraphs. + + + + + Like code:DeclareParameter except it is an error if this parameter is not on the command line. + These must come after non-optional (required) parameters. + Text to print for this qualifer. It will be word-wrapped. Newlines indicate + new paragraphs. + + + + + A parameter set defines on of a set of 'commands' that decides how to parse the rest of the command + line. If this 'command' is present on the command line then 'val' is assigned to 'retVal'. + Typically 'retVal' is a variable of a enumerated type (one for each command), and 'val' is one + specific value of that enumeration. + + * See code:#ParameterSets + * See code:#DefiningParametersAndQualifiers + * See code:#Overview + Text to print for this qualifer. It will be word-wrapped. Newlines indicate + new paragraphs. + + + + + There is one special parameter set called the default parameter set (whose names is empty) which is + used when a command line does not have one of defined parameter sets. It is always present, even if + this method is not called, so alling this method is optional, however, by calling this method you can + add help text for this case. If present this call must be AFTER all other parameter set + definitions. + + * See code:#DefaultParameterSet + * See code:#DefiningParametersAndQualifiers + * See code:#Overview + Text to print for this qualifer. It will be word-wrapped. Newlines indicate + new paragraphs. + + + + + This variation of DefineDefaultParameterSet has a 'retVal' and 'val' parameters. If the command + line does not match any of the other parameter set defintions, then 'val' is asigned to 'retVal'. + Typically 'retVal' is a variable of a enumerated type and 'val' is a value of that type. + + * See code:DefineDefaultParameterSet for more. + Text to print for this qualifer. It will be word-wrapped. Newlines indicate + new paragraphs. + + + + + Specify additional aliases for an named parameter. This call must come BEFORE the definition, since + the defintion is the operation that causes the parsing to happen. + + + + + By default parameter set specifiers must look like a qualifer (begin with a -), however setting + code:NoDashOnParameterSets will define a parameter set marker not to have any special prefix (just + the name itself. + + + + + If the positional parameters might look like named parameters (typically happens when the tail of the + command line is literal text), it is useful to stop the search for named parameters at the first + positional parameter. This property enables this behavior for the current parameter set. + + + + + By default qualifers may being with a - or a / character. Setting code:QualifiersUseOnlyDash will + make / invalid qualifer marker (only - can be used) + + + + + By default, a non-list qualifier can not be specified more than once (since one or the other will + have to be ignored. Normally an error is thrown. Setting code:LastQualiferWins makes it legal, and + the last qualifer is the one that is used. + + + + + Check for any paramters that the user specified but that were not defined by a Define*Parameter call + and throw an exception if any are found. + + + + + Return a string giving the help for the command, word wrapped at 'maxLineWidth' + + + + + Return the string representing the help for a single paramter set. If displayGlobalQualifiers is + true than qualifers that apply to all parameter sets is also included, otheriwse it is just the + parameters and qualifers that are specific to that parameters set. + + + + + Find the locations of all arguments that look like named parameters. + + + + + Run time parsing error throw this exception. These are expected to be caught and the error message + printed out to the user. Thus the messages should be 'user friendly'. + + + + + This exception represents a compile time error in the command line parsing. These should not happen in + correctly written programs. + + + + + Given a list of arguments, from 'startAt' to the end of 'arguments' quote any + arguments that have spaces in them so that the resulting command lineNumber has + been turned back into a string that could be passed to a subprocess. + + The command lineNumber arguments parsed as space sparated token. + The index in 'arguments' of the sub-array of interest (typically 0). + + A string that represents the original commannd lineNumber string before being parsed + into array of space separated arguments + + + + + General purpose utilities dealing with archiveFile system directories. + + + + + SafeCopy sourceDirectory to directoryToVersion recursively. The target directory does + no need to exist + + + + + SafeCopy all files from sourceDirectory to directoryToVersion. If searchOptions == AllDirectories + then the copy is recursive, otherwise it is just one level. The target directory does not + need to exist. + + + + + Clean is sort of a 'safe' recursive delete of a directory. It either deletes the + files or moves them to '*.deleting' names. It deletes directories that are completely + empty. Thus it will do a recursive delete when that is possible. There will only + be *.deleting files after this returns. It returns the number of files and directories + that could not be deleted. + + + + + Removes the oldest directories directly under 'directoryPath' so that + only 'numberToKeep' are left. + + Directory to removed old files from. + The number of files to keep. + true if there were no errors deleting files + + + + DirectoryUtilities.GetFiles is basically the same as Directory.GetFiles + however it returns IEnumerator, which means that it lazy. This is very important + for large directory trees. A searchPattern can be specified (Windows wildcard conventions) + that can be used to filter the set of archiveFile names returned. + + Suggested Usage + + foreach(string fileName in DirectoryUtilities.GetFiles("c:\", "*.txt")){ + Console.WriteLine(fileName); + } + + + The base directory to enumerate + A pattern to filter the names (windows filename wildcards * ?) + Indicate if the search is recursive or not. + The enumerator for all archiveFile names in the directory (recursively). + + + + General purpose utilities dealing with archiveFile system files. + + + + + GetLines works much like File.ReadAllLines, however instead of returning a + array of lines, it returns a IEnumerable so that the archiveFile is not read all + at once. This allows 'foreach' syntax to be used on very large files. + + Suggested Usage + + foreach(string lineNumber in FileUtilities.GetLines("largeFile.txt")){ + Console.WriteLine(lineNumber); + } + + The base directory to enumerate. + The enumerator for all lines in the archiveFile. + + + + Given archiveFile specifications possibly with wildcards in them + return an enumerator that returns each expanded archiveFile name in turn. + + If searchOpt is AllDirectories it does a recursive match. + + + + + Delete works much like File.Delete, except that it will succeed if the + archiveFile does not exist, and will rename the archiveFile so that even if the archiveFile + is locked the original archiveFile variable will be made available. + + It renames the archiveFile with a '[num].deleting'. These files might be left + behind. + + It returns true if it was competely successful. If there is a *.deleting + archiveFile left behind, it returns false. + + The variable of the archiveFile to delete + + + + Try to delete 'fileName' catching any exception. Returns true + if successful. It will delete read-only files. + + + + + SafeCopy sourceFile to destinationFile. If the destination exists + used ForceDelete to get rid of it first. + + + + + Moves sourceFile to destinationFile. If the destination exists + used ForceDelete to get rid of it first. + + + + + CopyStream simply copies 'fromStream' to 'toStream' + + + + + Privides a quick HTML users guide. + + + + + Displayes an the embeded HTML user's guide in a browser. + + true if successful. + + + + A trivial routine, but we want to share even trivial common code. + + + + + This program generates C# code for manipulating ETW events given the event XML schema definition + + + + + + Counts the number of newlines in 'str' from 'startIndex' of length 'length' + + + + + EventSourceFinder is a class that can find all the EventSources in a file and can + + + + + The code:CommandLine class holds the parsed form of all the command line arguments. It is + intialized by handing it the 'args' array for main, and it has a public field for each named argument + (eg -debug). See code:#CommandLineDefinitions for the code that defines the arguments (and the help + strings associated with them). + + See code:CommandLineParser for more on parser itself. + + + + + Given an eventName, return a list of all events with that name. Warns if two events + with the same name have different Ids, and retnames the event to be unique. + + + + + + + + This is the prefix for any class names. Users can override this, but by default + it is the last component (components separated by -) of the provider name. Users + can override this however. + + + + + If set then it assumes that the generated class should be internal and not public. + + + + + If true it will cause the generation of a 'state' class associated with the parser to hold information needed from one event to the next + + + + + Once you have set all the properties you wish, you can actually geneate a TraceEventParser to a + particular output file by calling this routine. + + + + + Change convention from ETW_KEYWORD_SESSION" to Session + + + + + Generate the *Template helper functions as well as the EnumerateTemplates operation. + + + + + + Emit the C# events that allow you to get callback + + + + + Accumulate all the information needed to fetch a field by field name. Also compute the assert that + we will use to confirm the payload length is good. + + + + + Generate all the enumeration types needed by the class defintions. + + + + + + returns C# code that will generate 'guid' in an efficient way (initializing by string is + inefficient). + + + + + Find all the information needed to create a payload decode class for a template (including offsets + of the fields) and returns it as a list of 'FieldInfo' structures. + + + + + Returns a string representing the C# code that will fetch the property for any of the versions described by 'versions'. + 'totalVersions' is the maximum number of versions that the event (not just the property) has. + + + + + ensures that the name is a valid CSharp Identifier. + + + + + Represents all the information needed to decode a specific version of a field of a event payload. + + + + + Returns string representing code that returns a 'default' value (a value to return when the value + does not exist in the payload. This is 0 for numeric values and null for string values. + + + + + + Returns a string representing the offset of whatever is directly after this field. + This method is static so that it can be called on a null field, which is convenient in several places. + + + + + + This is the last component (- separted) of the provider name. It decides what your TraceParserGen is named + + + + + All the information from the manifest file. + + + + + We group events together by version during the processing. + + + +