С Safe тоже BSOD 
Вообще, в этом драйвере нужно получить адрес входного и выходного буферов для способов:
METHOD_BUFFERED
METHOD_NEITHER
METHOD_IN_DIRECT
METHOD_OUT_DIRECT
Для первых двух проблем нет (там нет и Mdl), а с Direct'ами - беда.
Падает прямо на MmGetSystemAddressForMdlSafe( Irp->MdlAddress, NormalPagePriority)
Если закоментить - не падает.
Обработка Direct:
| C++ | 1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
| case METHOD_IN_DIRECT:
{
DbgPrint( ("REQUEST: METHOD_IN_DIRECT"));
int InLength=0;
int OutLength=0;
PVOID InBuffer=0;
PVOID OutBuffer=0;
InBuffer = Irp->AssociatedIrp.SystemBuffer;
InLength = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.InputBufferLength;
OutBuffer = (PVOID)MmGetSystemAddressForMdlSafe( Irp->MdlAddress, NormalPagePriority);
OutLength = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.OutputBufferLength;
DbgPrint("InputBufferPtr: %08lx", (ULONG)InBuffer);
DbgPrint("InputBufferLen: %i", InLength);
DbgPrint("OutputBufferPtr: %08lx", (ULONG)OutBuffer);
DbgPrint("InputBufferLen: %i", OutLength);
return STATUS_SUCCESS;
break;
}
case METHOD_OUT_DIRECT:
{
DbgPrint( ("REQUEST: METHOD_OUT_DIRECT"));
int InLength=0;
int OutLength=0;
PVOID InBuffer=0;
PVOID OutBuffer=0;
InBuffer = Irp->AssociatedIrp.SystemBuffer;
InLength = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.InputBufferLength;
OutBuffer = MmGetSystemAddressForMdlSafe( Irp->MdlAddress, NormalPagePriority);
OutLength = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.OutputBufferLength;
DbgPrint("InputBufferPtr: %08lx", (ULONG)InBuffer);
DbgPrint("InputBufferLen: %i", InLength);
DbgPrint("OutputBufferPtr: %08lx", (ULONG)OutBuffer);
DbgPrint("InputBufferLen: %i", OutLength);
return STATUS_SUCCESS;
break;
} |
|
Пробовал поменять местами входной и выходной буферы при вызове DeviceIoControl - ничего не меняется
Добавлено через 2 минуты
(Если нужен сам драйвер)
| C++ | 1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
| #include "stdafx.h"
#define FILE_DEVICE_IOCTL 0x00008301
#define IOCTL_MY_NEITHER CTL_CODE(FILE_DEVICE_IOCTL, 0x800, METHOD_NEITHER, FILE_ANY_ACCESS)
#define IOCTL_MY_BUFFERED CTL_CODE(FILE_DEVICE_IOCTL, 0x801, METHOD_BUFFERED, FILE_ANY_ACCESS)
#define IOCTL_MY_INDIRECT CTL_CODE(FILE_DEVICE_IOCTL, 0x802, METHOD_IN_DIRECT, FILE_ANY_ACCESS)
#define IOCTL_MY_OUTDIRECT CTL_CODE(FILE_DEVICE_IOCTL, 0x803, METHOD_OUT_DIRECT, FILE_ANY_ACCESS)
/*
Цель работы - создать 4 обработчика событий и ловить эти события (они приходят в DeviceControl, где и парсятся)
Обработчик функции - показать понимание метода: вывести указатели на входной и выходной буферы, а также их размеры
Больше ничего делать не нужно
*/
void Lab3_5Unload(IN PDRIVER_OBJECT DriverObject);
NTSTATUS Lab3_5CreateClose(IN PDEVICE_OBJECT DeviceObject, IN PIRP Irp);
NTSTATUS Lab3_5DefaultHandler(IN PDEVICE_OBJECT DeviceObject, IN PIRP Irp);
NTSTATUS Control(IN PDEVICE_OBJECT DeviceObject, IN PIRP Irp);
#ifdef __cplusplus
extern "C" NTSTATUS DriverEntry(IN PDRIVER_OBJECT DriverObject, IN PUNICODE_STRING RegistryPath);
#endif
NTSTATUS Control(IN PDEVICE_OBJECT DeviceObject, IN PIRP Irp)
{
ULONG method = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.IoControlCode & 0x03L;
switch(method)
{
case METHOD_BUFFERED:
{
DbgPrint( ("REQUEST: METHOD_BUFFERED"));
int InLength=0;
int OutLength=0;
PVOID InBuffer=0;
PVOID OutBuffer=0;
InBuffer = Irp->AssociatedIrp.SystemBuffer;
InLength = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.InputBufferLength;
OutBuffer = Irp->AssociatedIrp.SystemBuffer;
OutLength = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.OutputBufferLength;
DbgPrint("InputBufferPtr: %08lx", (ULONG)InBuffer);
DbgPrint("InputBufferLen: %i", InLength);
DbgPrint("OutputBufferPtr: %08lx", (ULONG)OutBuffer);
DbgPrint("InputBufferLen: %i", OutLength);
return STATUS_SUCCESS;
break;
}
case METHOD_IN_DIRECT:
{
DbgPrint( ("REQUEST: METHOD_IN_DIRECT"));
int InLength=0;
int OutLength=0;
PVOID InBuffer=0;
PVOID OutBuffer=0;
InBuffer = Irp->AssociatedIrp.SystemBuffer;
InLength = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.InputBufferLength;
OutBuffer = (PVOID)MmGetSystemAddressForMdlSafe( Irp->MdlAddress, NormalPagePriority);
OutLength = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.OutputBufferLength;
DbgPrint("InputBufferPtr: %08lx", (ULONG)InBuffer);
DbgPrint("InputBufferLen: %i", InLength);
DbgPrint("OutputBufferPtr: %08lx", (ULONG)OutBuffer);
DbgPrint("InputBufferLen: %i", OutLength);
return STATUS_SUCCESS;
break;
}
case METHOD_OUT_DIRECT:
{
DbgPrint( ("REQUEST: METHOD_OUT_DIRECT"));
int InLength=0;
int OutLength=0;
PVOID InBuffer=0;
PVOID OutBuffer=0;
InBuffer = Irp->AssociatedIrp.SystemBuffer;
InLength = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.InputBufferLength;
OutBuffer = MmGetSystemAddressForMdlSafe( Irp->MdlAddress, NormalPagePriority);
OutLength = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.OutputBufferLength;
DbgPrint("InputBufferPtr: %08lx", (ULONG)InBuffer);
DbgPrint("InputBufferLen: %i", InLength);
DbgPrint("OutputBufferPtr: %08lx", (ULONG)OutBuffer);
DbgPrint("InputBufferLen: %i", OutLength);
return STATUS_SUCCESS;
break;
}
case METHOD_NEITHER:
{DbgPrint( ("REQUEST: METHOD_NEITHER"));
int InLength=0;
int OutLength=0;
PVOID InBuffer=0;
PVOID OutBuffer=0;
InBuffer = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.Type3InputBuffer;
InLength = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.InputBufferLength;
OutBuffer = Irp->UserBuffer;
OutLength = IoGetCurrentIrpStackLocation(Irp)->Parameters.DeviceIoControl.OutputBufferLength;
DbgPrint("InputBufferPtr: %08lx", (ULONG)InBuffer);
DbgPrint("InputBufferLen: %i", InLength);
DbgPrint("OutputBufferPtr: %08lx", (ULONG)OutBuffer);
DbgPrint("InputBufferLen: %i", OutLength);
return STATUS_SUCCESS;
break;
}
}
return STATUS_SUCCESS;
}
NTSTATUS DriverEntry(IN PDRIVER_OBJECT DriverObject, IN PUNICODE_STRING RegistryPath)
{
UNICODE_STRING DeviceName,Win32Device;
PDEVICE_OBJECT DeviceObject = NULL;
NTSTATUS status;
unsigned i;
RtlInitUnicodeString(&DeviceName,L"\\Device\\Lab3_50");
RtlInitUnicodeString(&Win32Device,L"\\DosDevices\\Lab3_50");
for (i = 0; i <= IRP_MJ_MAXIMUM_FUNCTION; i++)
DriverObject->MajorFunction[i] = Lab3_5DefaultHandler;
DriverObject->MajorFunction[IRP_MJ_CREATE] = Lab3_5CreateClose;
DriverObject->MajorFunction[IRP_MJ_CLOSE] = Lab3_5CreateClose;
DriverObject->MajorFunction[IRP_MJ_DEVICE_CONTROL] = Control;
DriverObject->DriverUnload = Lab3_5Unload;
status = IoCreateDevice(DriverObject,
0,
&DeviceName,
FILE_DEVICE_UNKNOWN,
0,
FALSE,
&DeviceObject);
if (!NT_SUCCESS(status))
return status;
if (!DeviceObject)
return STATUS_UNEXPECTED_IO_ERROR;
DeviceObject->Flags |= DO_DIRECT_IO;
DeviceObject->AlignmentRequirement = FILE_WORD_ALIGNMENT;
status = IoCreateSymbolicLink(&Win32Device, &DeviceName);
DeviceObject->Flags &= ~DO_DEVICE_INITIALIZING;
return STATUS_SUCCESS;
}
void Lab3_5Unload(IN PDRIVER_OBJECT DriverObject)
{
UNICODE_STRING Win32Device;
RtlInitUnicodeString(&Win32Device,L"\\DosDevices\\Lab3_50");
IoDeleteSymbolicLink(&Win32Device);
IoDeleteDevice(DriverObject->DeviceObject);
}
NTSTATUS Lab3_5CreateClose(IN PDEVICE_OBJECT DeviceObject, IN PIRP Irp)
{
Irp->IoStatus.Status = STATUS_SUCCESS;
Irp->IoStatus.Information = 0;
IoCompleteRequest(Irp, IO_NO_INCREMENT);
return STATUS_SUCCESS;
}
NTSTATUS Lab3_5DefaultHandler(IN PDEVICE_OBJECT DeviceObject, IN PIRP Irp)
{
Irp->IoStatus.Status = STATUS_NOT_SUPPORTED;
Irp->IoStatus.Information = 0;
IoCompleteRequest(Irp, IO_NO_INCREMENT);
return Irp->IoStatus.Status;
} |
|
Добавлено через 1 минуту
(
Добавлено через 2 минуты
(Если нужно: сами вызовы)
| C++ | 1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
| void CMFCApplication2Dlg::OnBnClickedButton10()
{
CString str1;
symbolic_link_name.GetWindowTextW(str1);
str1=L"\\\\.\\"+str1;
// TODO: добавьте свой код обработчика уведомлений
hFile = CreateFile(str1, // file to open
GENERIC_READ | GENERIC_WRITE, // open for reading
FILE_SHARE_WRITE, // share for reading
NULL, // default security
OPEN_EXISTING, // existing file only
FILE_ATTRIBUTE_NORMAL, // normal file
NULL); // no attr. template
if (hFile == INVALID_HANDLE_VALUE)
{
hFile=NULL;
outprint.AddString(L"An error has occured while opening device");
return;
}
else
outprint.AddString(L"Sucessfully opened");
BOOL result=TRUE;
VOID* Inbuffer[20];
DWORD nInBufferSize = 0;
VOID* Outbuffer[20];
DWORD nOutBufferSize = 0;
DWORD lpBytesReturned;
// IOCTL_MY_NEITHER
result = DeviceIoControl
(
hFile,
IOCTL_MY_NEITHER,
L"Testhf",
sizeof(L"Testhf"),
&Outbuffer,
nOutBufferSize,
&lpBytesReturned,
NULL
);
if (result==TRUE)
outprint.AddString(L"IOCTL_MY_NEITHER - OK");
else
outprint.AddString(L"IOCTL_MY_NEITHER - FAILURE");
//IOCTL_MY_BUFFERED
result = DeviceIoControl
(
hFile,
IOCTL_MY_BUFFERED,
L"Testhf",
sizeof(L"Testhf"),
&Outbuffer,
nOutBufferSize,
&lpBytesReturned,
NULL
);
if (result==TRUE)
outprint.AddString(L"IOCTL_MY_BUFFERED - OK");
else
outprint.AddString(L"IOCTL_MY_BUFFERED - FAILURE");
// IOCTL_MY_INDIRECT
result = DeviceIoControl
(
hFile,
IOCTL_MY_INDIRECT,
L"Testhf",
sizeof(L"Testhf"),
&Outbuffer,
nOutBufferSize,
&lpBytesReturned,
NULL
);
if (result==TRUE)
outprint.AddString(L"IOCTL_MY_INDIRECT - OK");
else
outprint.AddString(L"IOCTL_MY_INDIRECT - FAILURE");
//IOCTL_MY_OUTDIRECT
result = DeviceIoControl
(
hFile,
L"Testhf",
sizeof(L"Testhf"),
IOCTL_MY_OUTDIRECT,
&Outbuffer,
nOutBufferSize,
&lpBytesReturned,
NULL
);
if (result==TRUE)
outprint.AddString(L"IOCTL_MY_OUTDIRECT - OK");
else
outprint.AddString(L"IOCTL_MY_OUTDIRECT - FAILURE");
//IOCTL_UNK_NEITHER
result = DeviceIoControl
(
hFile,
IOCTL_UNK_NEITHER,
L"Testhf",
sizeof(L"Testhf"),
&Outbuffer,
nOutBufferSize,
&lpBytesReturned,
NULL
);
if (result==TRUE)
outprint.AddString(L"IOCTL_UNK_NEITHER - OK");
else
outprint.AddString(L"IOCTL_UNK_NEITHER - FAILURE");
//IOCTL_UNK_BUFFERED
result = DeviceIoControl
(
hFile,
IOCTL_UNK_BUFFERED,
L"Testhf",
sizeof(L"Testhf"),
&Outbuffer,
nOutBufferSize,
&lpBytesReturned,
NULL
);
if (result==TRUE)
outprint.AddString(L"IOCTL_UNK_BUFFERED - OK");
else
outprint.AddString(L"IOCTL_UNK_BUFFERED - FAILURE");
//IOCTL_UNK_INDIRECT
result = DeviceIoControl
(
hFile,
IOCTL_UNK_INDIRECT,
L"Testhf",
sizeof(L"Testhf"),
&Outbuffer,
nOutBufferSize,
&lpBytesReturned,
NULL
);
if (result==TRUE)
outprint.AddString(L"IOCTL_UNK_INDIRECT - OK");
else
outprint.AddString(L"IOCTL_UNK_INDIRECT - FAILURE");
//IOCTL_UNK_OUTDIRECT
result = DeviceIoControl
(
hFile,
IOCTL_UNK_OUTDIRECT,
L"Testhf",
sizeof(L"Testhf"),
&Outbuffer,
nOutBufferSize,
&lpBytesReturned,
NULL
);
if (result==TRUE)
outprint.AddString(L"IOCTL_UNK_OUTDIRECT - OK");
else
outprint.AddString(L"IOCTL_UNK_OUTDIRECT - FAILURE");
} |
|
Добавлено через 36 минут
Разобрался!
Длину выходного буфера нужно указывать ненулевую.
И все пойдет.
Тему можно закрывать
Добавлено через 24 секунды
Тема закрыта
0
|