4 releases

0.1.5 Apr 27, 2020
0.1.4 Apr 12, 2020
0.1.2 Apr 1, 2020
0.1.1 Mar 30, 2020

#11 in #manner

43 downloads per month
Used in 3 crates

MIT license

67KB
2K SLoC

C 1.5K SLoC // 0.0% comments C++ 393 SLoC Rust 87 SLoC Prolog 19 SLoC Shell 14 SLoC

A library to read/write memory to Windows running inside of KVM

wintools.h and mem.h provide most of the functions callable to interract with the Windows VM, while hlapi abstracts everything in a bit simpler to use manner (requires C++).

Rust bindings are available in a separate repository.

Compiling

Minimum language standard: C99 The current example project is in C++, requiring at least C++11 with template support, but the C version also exists, which works fine on a C99 compiler.

Use meson and ninja to compile the example programs

Use make to compile the kernel module

Performance

Internal (QEMU inject) mode is roughly 5 times faster than external mode. However, it is possible to use the kernel module to map the memory space of QEMU into the external process, mitigating the performance penalty. Also, when performing larger reads, the memcpy quickly reaches its peak speed and external mode begins to catch up. Performance numbers are shown below.

alt text

Frequent issues

Make sure to use the Q35 chipset on the KVM guest, unless it is running Windows XP. Otherwise, the library may not work correctly. Kmod mapping is not guaranteed to work properly or for extended periods of time if the VM is not set up to use hugepages.

Licensing note

While most of the codebase is under the MIT license, the kernel module (kmem.c file) is licensed under GNU GPLv2.

Dependencies

~0–2.2MB
~44K SLoC