各位大牛,我最近在看过滤驱动,遇到点问题.......希望可以帮我看看
在IRP_MJ_READ 例程中,获得文件内容,可是总蓝屏...调试信息是
kd> !analyze -v
*******************************************************************************
* *
* Bugcheck Analysis *
* *
*******************************************************************************
MULTIPLE_IRP_COMPLETE_REQUESTS (44)
A driver has requested that an IRP be completed (IoCompleteRequest()), but
the packet has already been completed. This is a tough bug to find because
the easiest case, a driver actually attempted to complete its own packet
twice, is generally not what happened. Rather, two separate drivers each
believe that they own the packet, and each attempts to complete it. The
first actually works, and the second fails. Tracking down which drivers
in the system actually did this is difficult, generally because the trails
of the first driver have been covered by the second. However, the driver
stack for the current request can be found by examining the DeviceObject
fields in each of the stack locations.
Arguments:
Arg1: 8119b6d8, Address of the IRP
Arg2: 00001c13
Arg3: 00000000
Arg4: 00000000
IRP_MJ_READ 例程代码如下:
NTSTATUS
SfRead(
IN PDEVICE_OBJECT DeviceObject,
IN PIRP Irp
)
{
LARGE_INTEGER offset;
PIO_STACK_LOCATION irpsp = IoGetCurrentIrpStackLocation(Irp);
offset.QuadPart = irpsp->Parameters.Read.ByteOffset.QuadPart;
PFILE_OBJECT file_object = irpsp->FileObject;
PSFILTER_DEVICE_EXTENSION devExt = (PSFILTER_DEVICE_EXTENSION)DeviceObject->DeviceExtension;
//
// 现在还没有对自己设备的控制设备进行读操作,所以要返回错误
//
if (IS_MY_CONTROL_DEVICE_OBJECT(DeviceObject))
{
Irp->IoStatus.Status = STATUS_INVALID_DEVICE_REQUEST;
Irp->IoStatus.Information = 0;
IoCompleteRequest(Irp,IO_NO_INCREMENT);
return STATUS_INVALID_DEVICE_REQUEST;
}
if (devExt->StorageStackDeviceObject == NULL)
{
return SfPassThrough(DeviceObject,Irp);
}
// 对文件的读操作
/* switch (irpsp->MinorFunction)
{
case IRP_MN_NORMAL:
{
KEVENT waitEvent;
void *buffer;
ULONG Length;
NTSTATUS status;
KeInitializeEvent(&waitEvent,NotificationEvent,FALSE);
IoCopyCurrentIrpStackLocationToNext(Irp);
IoSetCompletionRoutine(Irp,SfReadCompletion,&waitEvent,true,true,true);
status = IoCallDriver(devExt->AttachedToDeviceObject,Irp);
if (STATUS_PENDING == status)
{
status = KeWaitForSingleObject(&waitEvent,Executive,KernelMode,FALSE,NULL);
}
if (Irp->IoStatus.Status == STATUS_SUCCESS)
{
if (Irp->MdlAddress != NULL)
buffer = MmGetSystemAddressForMdlSafe(Irp->MdlAddress,NormalPagePriority);
else
buffer = Irp->UserBuffer;
Length = Irp->IoStatus.Information;
}
Irp->IoStatus.Information = Length;
Irp->IoStatus.Status = STATUS_SUCCESS;
//移动文件指针,防止读取相同的位置
irpsp->FileObject->CurrentByteOffset.QuadPart = Length + offset.QuadPart;
IoCompleteRequest(Irp,IO_NO_INCREMENT);
return STATUS_SUCCESS;
}break;
}
*/
IoSkipCurrentIrpStackLocation(Irp);
return IoCallDriver(((PSFILTER_DEVICE_EXTENSION)DeviceObject->DeviceExtension)->AttachedToDeviceObject,Irp);
}
NTSTATUS
SfReadCompletion(
IN PDEVICE_OBJECT DeviceObject,
IN PIRP Irp,
IN PVOID Context
)
{
ASSERT(Context != NULL);
if (Irp->PendingReturned)
{
IoMarkIrpPending(Irp);
}
KeSetEvent((PKEVENT)Context, IO_NO_INCREMENT, FALSE);
return STATUS_MORE_PROCESSING_REQUIRED;
}
取消注释就蓝屏,不知道什么原因~~~~~~,,希望各位大牛能帮我看看.给点提示也好.
[课程]FART 脱壳王!加量不加价!FART作者讲授!