Add wdm.h DDI docs for GetRuntimeAttestationReport structures - #1679
Open
John Kennedy (GrantMeStrength) wants to merge 1 commit into
Open
John Kennedy (GrantMeStrength) wants to merge 1 commit into
John Kennedy (GrantMeStrength) wants to merge 1 commit into
Conversation
Add driver-facing DDI reference documentation for the 11 data structures and enumeration used by GetRuntimeAttestationReport as they appear in the wdm.h driver header. This is the kernel/driver companion to the Win32 winnt.h documentation. New files (wdk-ddi-src/content/wdm/): - ne-wdm-runtime_report_type.md - ns-wdm-runtime_report_package_header.md - ns-wdm-runtime_report_digest_header.md - ns-wdm-runtime_report_header.md - ns-wdm-driver_info_entry.md - ns-wdm-driver_runtime_report.md - ns-wdm-code_integrity_runtime_report.md - ns-wdm-code_integrity_report_generation_header.md - ns-wdm-code_integrity_report_record_header.md - ns-wdm-hotpatch_info_entry.md - ns-wdm-hotpatch_runtime_report.md Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Copilot-Session: c71365b6-f808-47df-a842-93fd44b2da08
John Kennedy (GrantMeStrength)
marked this pull request as ready for review
July 25, 2026 00:12
John Kennedy (GrantMeStrength)
marked this pull request as draft
July 25, 2026 00:19
John Kennedy (GrantMeStrength)
marked this pull request as ready for review
July 25, 2026 00:25
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds driver-facing DDI reference documentation for the 11 data structures and enumeration used by GetRuntimeAttestationReport, as they appear in the wdm.h driver header. This is the kernel/driver companion to the Win32 PR that documents the same types under winnt.h; field prose matches the app-facing docs in substance, with only header/metadata differing.
All field descriptions are derived faithfully from the source header's inline comments — no invented behavior, values, sizes, or IRQL/usage notes.
New files (
wdk-ddi-src/content/wdm/)ne-wdm-runtime_report_type.mdRUNTIME_REPORT_TYPEns-wdm-runtime_report_package_header.mdRUNTIME_REPORT_PACKAGE_HEADERns-wdm-runtime_report_digest_header.mdRUNTIME_REPORT_DIGEST_HEADERns-wdm-runtime_report_header.mdRUNTIME_REPORT_HEADERns-wdm-driver_info_entry.mdDRIVER_INFO_ENTRYns-wdm-driver_runtime_report.mdDRIVER_RUNTIME_REPORTns-wdm-code_integrity_runtime_report.mdCODE_INTEGRITY_RUNTIME_REPORTns-wdm-code_integrity_report_generation_header.mdCODE_INTEGRITY_REPORT_GENERATION_HEADERns-wdm-code_integrity_report_record_header.mdCODE_INTEGRITY_REPORT_RECORD_HEADERns-wdm-hotpatch_info_entry.mdHOTPATCH_INFO_ENTRYns-wdm-hotpatch_runtime_report.mdHOTPATCH_RUNTIME_REPORTNotes / for reviewer confirmation
tech.rootset tokernel(mirrors neighboring general kernelns-wdm-*structs).req.irqlleft blank (no IRQL info in header; these are data-structure definitions).req.include-headerset toWdm.h(matches existing samples).RuntimeReportTypeMaxdocumented as a sentinel/count marker (no explicit value in header, = 3), not a real report type.Flagsunions inDRIVER_INFO_ENTRYandDRIVER_RUNTIME_REPORTdocumented member-by-member (incl.AsUInt16). Variable-length trailing arrays and the per-driver dynamic buffer layout are explained in## -remarks.GetRuntimeAttestationReport.Draft — do not merge.