我一直想给一个司机打电话。我编写了DriverEntry方法,在该方法中,我初始化了指向驱动程序的驱动程序名称和符号岭。
// UNICODE_STRING DriverName, SymbolName; // Driver registry paths
...
// Driver Entrypoint
NTSTATUS
DriverEntry(PDRIVER_OBJECT pDriverObject, PUNICODE_STRING pRegistryPath) {
Q_UNUSED(pRegistryPath);
DbgPrintEx(0, 0, "Driver Loaded\n");
// The PsSetLoadImageNotifyRoutine routine registers a driver-supplied
// callback that is subsequently notified whenever
// an image is loaded (or mapped into memory).
PsSetLoadImageNotifyRoutine(ImageLoadCallback);
// initialize driver name
RtlInitUnicodeString(&DriverName, L"\\Device\\Explorer");
// initialize symbolic link
RtlInitUnicodeString(&SymbolName, L"\\DosDevices\\Explorer");
IoCreateDevice(pDriverObject, 0, &SymbolName, FILE_DEVICE_UNKNOWN,
FILE_DEVICE_SECURE_OPEN, FALSE, &pDeviceObject);
IoCreateSymbolicLink(&DriverName, &SymbolName);
pDriverObject->MajorFunction[IRP_MJ_CREATE] = CreateCall;
pDriverObject->MajorFunction[IRP_MJ_CLOSE] = CloseCall;
pDriverObject->MajorFunction[IRP_MJ_DEVICE_CONTROL] = IoControl;
pDriverObject->DriverUnload = UnloadDriver;
pDeviceObject->Flags |= DO_DIRECT_IO;
pDeviceObject->Flags &= ~DO_DEVICE_INITIALIZING;
return STATUS_SUCCESS;
}当我加载驱动程序时(使用OSR驱动程序加载器,也可以使用cmd完成,方法是将驱动程序注册为新服务),我将在DebugView (允许查看内核调试日志的sysinternals工具)中获得预期的输出。

现在,我需要确保设备和符号链接都存在于Windows对象目录中。要做到这一点,我使用WinObj (来自sysinternals的另一个工具),下面是输出
让我困惑的是,符号链接位于设备文件夹中,而不是全局??中。设备中的符号链接

全球设备??

现在终于打电话给司机了。为此我使用c++,这是我的代码,
class Test
{
public:
HANDLE hDriver; // Handle to driver
// Initializer
Test::Test(LPCSTR RegistryPath)
{
LPCSTR path = "\\\\.\\Explorer";
hDriver = CreateFileA(path, GENERIC_READ | GENERIC_WRITE,
FILE_SHARE_READ | FILE_SHARE_WRITE, 0, OPEN_EXISTING, 0, 0);
if (hDriver == INVALID_HANDLE_VALUE)
{
// Handle the error.
char result = GetLastError();
bool zadek = false;
}
}问题是我找不到司机的有效手柄。无论我使用什么路径,hDriver的值总是0x000000000000a0或0xffffff。我使用createFileA是因为我想访问系统内存。
我犯了什么大错特错吗?
发布于 2019-02-22 17:53:55
我应该说,自从我上一次写设备驱动程序以来,已经有8-9年了,但我的头绪是:
0xa0 for hDriver,它是一个有效的句柄值。IRP_MJ_DEVICE_CONTROL的回调。L"\\??\\Explorer"或L"\\GLOBAL??\\Explorer"作为符号链接。DriverName用于IoCreateDevice。IoCreateSymbolicLink传递不正确的参数。所以您的代码应该变成这样:
...
// initialize driver name
RtlInitUnicodeString(&DriverName, L"\\Device\\Explorer");
// initialize symbolic link
RtlInitUnicodeString(&SymbolName, L"\\??\\Explorer");
IoCreateDevice(pDriverObject, 0, &DriverName, FILE_DEVICE_UNKNOWN,
FILE_DEVICE_SECURE_OPEN, FALSE, &pDeviceObject);
IoCreateSymbolicLink(&SymbolName, &DriverName);
...https://stackoverflow.com/questions/54832148
复制相似问题