NotifyCreateFile Event

Fires when a file or directory has been created.


virtual int FireNotifyCreateFile(CBFilterNotifyCreateFileEventParams *e);
typedef struct {
const char *FileName;
int DesiredAccess;
int Attributes;
int ShareMode;
int Options;
int CreateDisposition;
int Status;
int ResultCode; int reserved; } CBFilterNotifyCreateFileEventParams;
virtual INT FireNotifyCreateFile(CBFilterNotifyCreateFileEventParams *e);
typedef struct {
INT DesiredAccess;
INT Attributes;
INT ShareMode;
INT Options;
INT CreateDisposition;
INT Status;
INT ResultCode; INT reserved; } CBFilterNotifyCreateFileEventParams;


This event fires when the file or directory specified by FileName has been created. Please refer to the File Create/Open Events topic for more information about how the class determines whether to fire this event or NotifyOpenFile.

Applications only need to handle this event if they've added a standard filter rule that includes the FS_NE_CREATE flag. Please note that applications must have the FilterOwnRequests configuration setting enabled if they wish to filter their own file/directory creation requests.

The DesiredAccess, Attributes, ShareMode, Options, and CreateDisposition parameters reflect the values that were passed for the similarly-named parameters of the Windows API's CreateFile function (or, more accurately, the values carried by the IRP_MJ_CREATE IRP). Please refer to Microsoft's documentation for more information.

To determine whether the request was for a file or a directory, compare Attributes against the Windows API's FILE_ATTRIBUTE_DIRECTORY constant, like so:

// Check whether the request is for a file or a directory.
FILE_ATTRIBUTE_DIRECTORY will be present if it was specified by the calling process or if the existing filesystem entry is a directory.

To determine whether a file will be deleted when its last handle is closed, compare Options against the Windows API's FILE_FLAG_DELETE_ON_CLOSE constant, like so:

// Check whether the file will be deleted on close.

The Status parameter contains an NT status code that indicates the outcome of the operation; 0 indicates success. To convert this value to a Win32 error code, call the NtStatusToWin32Error method. Please note that this event won't fire for failed requests unless the ProcessFailedRequests property is enabled.

The ResultCode parameter will always be 0 when the event is fired. If the event cannot be handled in a "successful" manner for some reason, set it to a non-zero value to report an appropriate error. Note, however, that this event fires after the operation has already completed, so reporting an error won't actually affect the operation itself. Please refer to the Error Reporting and Handling topic for more information.

This event is fired asynchronously; please refer to the Event Types topic for more information.

Copyright (c) 2021 Callback Technologies, Inc. - All rights reserved.
CBFS Filter 2020 C++ Edition - Version 20.0 [Build 7836]