SKETCH OF HOW RESEARCH MIGHT CONTINUE AND RESULTS BE PRESENTED

NtCreatePartition

This function creates a memory partition.

Declaration

NTSTATUS 
NtCreatePartition (
    HANDLE ParentPartitionHandle, 
    HANDLE *PartitionHandle, 
    ULONG DesiredAccess, 
    POBJECT_ATTRIBUTES ObjectAttributes, 
    ULONG Node);

Parameters

The ParentPartitionHandle argument is a handle to a memory partition that is to be the parent of the created partition. This argument can be NULL to represent the system partition. If a parent is specified, the handle must have the MEMORY_PARTITION_MODIFY_ACCESS permission.

The PartitionHandle argument is the address of a variable that is to receive a handle to the created partition.

The DesiredAccess argument is an access mask of generic, standard and specific rights that are wanted to the created partition. The specific rights MEMORY_PARTITION_QUERY_ACCESS (0x01) and MEMORY_PARTITION_MODIFY_ACCESS (0x02) are defined in WDM.H and WINNT.H.

The ObjectAttributes argument specifies a name and other properties for the created partition.

The Node argument selects a Non-Uniform Memory Access (NUMA) node. It can be 0xFFFFFFFF to select the node for the current thread’s ideal processor.

Return Value

The function returns STATUS_SUCCESS if successful, else a negative error code.

Availability

The NtCreatePartition function and its alias ZwCreatePartition are exported by name from NTDLL in version 10.0 and higher. In kernel mode, where ZwCreatePartition is a stub and NtCreatePartition is the implementation, neither is exported.

For all practical effect, the functions are available only in 64-bit Windows. As exports from the 32-bit NTDLL, they do exist, but only to return STATUS_NOT_SUPPORTED.

Documentation Status

Neither NtCreatePartition nor its alias is documented. The ZWAPI.H file in the Windows Driver Kit (WDK) for Windows 10 declares ZwCreatePartition but omits the Node argument.

Behaviour

The following implementation notes are from inspection of the kernel from the original release of Windows 10.

TO BE DONE