{"id":265,"date":"2011-02-09T17:04:36","date_gmt":"2011-02-09T09:04:36","guid":{"rendered":"http:\/\/blog.dynox.cn\/?p=265"},"modified":"2011-02-09T18:36:08","modified_gmt":"2011-02-09T10:36:08","slug":"%e6%85%8e%e7%94%a8mmsetaddressrangemodified","status":"publish","type":"post","link":"https:\/\/blog.dynox.cn\/?p=265","title":{"rendered":"\u614e\u7528MmSetAddressRangeModified"},"content":{"rendered":"<div class=\"gruber-markdown\"><p>MmSetAddressRangeModified\u7528\u6765\u8bbe\u7f6ePFN\u4e3adirty\/modified\uff0c\u5e76\u5c06PTE\u7684dirty\u4f4d\u6e05\u9664\u3002\u4f46\u9664\u6b64\u4e4b\u5916\uff0c\u8fd8\u6709\u4e2a\u4e0d\u660e\u663e\u7684\u526f\u4f5c\u7528\uff0c\u770b\u4e0b\u9762\u7684\u5206\u6790\uff1a<\/p>  <p><font size=\"1\">1: kd&gt; !pte 0xfffff880`0c9e6000      <br \/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; VA fffff8800c9e6000       <br \/>PXE @ FFFFF6FB7DBEDF88&#160;&#160;&#160;&#160; PPE at FFFFF6FB7DBF1000&#160;&#160;&#160; PDE at FFFFF6FB7E200320&#160;&#160;&#160; PTE at FFFFF6FC40064F30       <br \/>contains 000000003FE84863&#160; contains 000000003FE83863&#160; contains 0000000014516863&#160; contains 000000000FAD7963       <br \/>pfn 3fe84&#160;&#160;&#160;&#160;&#160; ---DA--KWEV&#160; pfn 3fe83&#160;&#160;&#160;&#160;&#160; ---DA--KWEV&#160; pfn 14516&#160;&#160;&#160;&#160;&#160; ---DA--KWEV&#160; pfn fad7&#160;&#160;&#160;&#160;&#160;&#160; -G-DA--K<font color=\"#ff0000\">W<\/font>EV<\/font><\/p>  <p>PTE entry \u72b6\u6001\u4e3adirty\uff0c\u5e76\u4e14\u662f\u53ef\u5199\u7684(writable)\u3002 \u518d\u770b\u8c03\u7528MmSetAddressRangeModified\u540e\u7684\u72b6\u6001\uff1a<\/p>  <p><font size=\"1\">1: kd&gt; !pte 0xfffff880`0c9e6000      <br \/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; VA fffff8800c9e6000       <br \/>PXE @ FFFFF6FB7DBEDF88&#160;&#160;&#160;&#160; PPE at FFFFF6FB7DBF1000&#160;&#160;&#160; PDE at FFFFF6FB7E200320&#160;&#160;&#160; PTE at FFFFF6FC40064F30       <br \/>contains 000000003FE84863&#160; contains 000000003FE83863&#160; contains 0000000014516863&#160; contains 000000000FAD7921       <br \/>pfn 3fe84&#160;&#160;&#160;&#160;&#160; ---DA--KWEV&#160; pfn 3fe83&#160;&#160;&#160;&#160;&#160; ---DA--KWEV&#160; pfn 14516&#160;&#160;&#160;&#160;&#160; ---DA--KWEV&#160; pfn fad7&#160;&#160;&#160;&#160;&#160;&#160; -G--A--K<font color=\"#ff0000\">R<\/font>EV<\/font><\/p>  <p>PTE entry\u7684dirty\u4f4d\u5df2\u88ab\u6e05\u9664\uff0c\u4f46\u662f\u6b64pte\u5df2\u88ab\u8bbe\u6210\u4e86readonly\u72b6\u6001\u4e86\u3002\u6240\u4ee5\u5982\u679c\u518d\u6709\u5199\u64cd\u4f5c\uff0c\u5fc5\u7136\u4f1a\u5bfc\u81f4page fault\u53d1\u751f\u3002<\/p>  <p>\u8fd9\u5c31\u662f\u6211\u66fe\u9047\u5230\u7684\u4e00\u4e2aExt2Fsd\u7684bug\uff1aExt2Fsd\u4e3a\u4e86\u5c06page cache\u9501\u5b9a\uff0c\u521b\u5efa\u4e86MDL\u5e76\u91cd\u65b0\u6620\u5c04\u5230\u7cfb\u7edf\u7a7a\u95f4\uff08\u8c03\u7528MmMapLockedPagesSpecifyCache\uff09\u3002\u65b0\u6620\u5c04\u7684va\u5177\u6709dirty\u53cawritable\u5c5e\u6027\uff0c\u6545\u6b64va\u5728spinlock \uff08DISPATCH_LEVEL\uff09\u4e0b\u8fdb\u884c\u5199\u64cd\u4f5c\u4e0d\u4f1a\u5bfc\u81f4\u4efb\u4f55\u5f02\u5e38\u3002\u4f46\u5728\u63d0\u4ea4\u6539\u52a8\u8fc7\u7a0b\u4e2d\uff0cExt2Fsd\u8c03\u7528\u4e86MmSetAddressRangeModified\uff0c\u8c03\u7528\u540eMmSetAddressRangeModified\u4f1a\u5c06\u6b64pte\u8bbe\u7f6e\u4e3areadonly\uff0c\u5982\u679c\u4e0b\u4e00\u6b21\u7684\u5199\u64cd\u4f5c\u6b63\u597d\u5728spinlock\u4e0b\uff08DISPATCH_LEVEL\uff09\uff0c\u5c06\u4f1a\u5bfc\u81f4BSOD: DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)\uff0c\u5982\u679c\u5728\u83b7\u53d6spinlock\u524d\u66fe\u6267\u884c\u8fc7\u5199\u64cd\u4f5c\uff08IRQL &lt; DISPATCH_LEVEL\uff09\uff0c\u5219\u4f1a\u6b63\u5e38\u89e6\u53d1page fault\uff0c\u7136\u540eMmAccessFault\u4f1a\u91cd\u7f6epte\u4e3awriteable\uff0c\u5e76\u8bbe\u7f6edirty\u4f4d\uff0c\u6b64\u540e\u5982\u679c\u518d\u8fdb\u5165DISPATCH_LEVEL\uff0c\u5bf9\u6b64va\u8fdb\u884c\u5199\u64cd\u4f5c\u4fbf\u4e0d\u4f1a\u89e6\u53d1page fault\u4e86\u3002\u8fd9\u5c31\u6784\u6210\u4e86\u4e00\u5b9a\u7684\u968f\u673a\u6027\u548c\u9690\u853d\u6027\uff0c\u7ed9\u8c03\u8bd5\u5e26\u6765\u4e86\u5f88\u5927\u7684\u9ebb\u70e6\u3002<\/p>  <p>\u660e\u767d\u4e86\u95ee\u9898\u6240\u5728\uff0c\u4e0d\u59a8\u518d\u505a\u4e2a\u5b9e\u9a8c\uff1a\u5982\u679c\u624b\u5de5\u5c06\u6b64pte\u8bbe\u4e3awriteable\u7684\uff0c\u518d\u8fdb\u884c\u5199\u64cd\u4f5c\uff0ccpu\u5e94\u8be5\u76f4\u63a5\u7f6epte\u4e3adirty\uff0c\u800c\u4e0d\u5fc5\u8c03\u7528OS\uff08\u5373page fault\uff09\u3002<\/p>  <p>\u5bf9va 0xfffffa60`04ae7000 \u8c03\u7528MmSetAddressRangeModified\u540e\uff0c<\/p>  <p><font size=\"1\">1: kd&gt; !pte 0xfffffa60`04ae7000      <br \/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; VA fffffa6004ae7000       <br \/>PXE @ FFFFF6FB7DBEDFA0&#160;&#160;&#160;&#160; PPE at FFFFF6FB7DBF4C00&#160;&#160;&#160; PDE at FFFFF6FB7E980128&#160;&#160;&#160; PTE at FFFFF6FD30025738       <br \/>contains 000000007FFC4863&#160; contains 000000007FFC3863&#160; contains 00000000539A2863&#160; contains 00000000149AD921       <br \/>pfn 7ffc4&#160;&#160;&#160;&#160;&#160; ---DA--KWEV&#160; pfn 7ffc3&#160;&#160;&#160;&#160;&#160; ---DA--KWEV&#160; pfn 539a2&#160;&#160;&#160;&#160;&#160; ---DA--KWEV&#160; pfn 149ad&#160;&#160;&#160;&#160;&#160; -G--A\u2014K<font color=\"#ff0000\">R<\/font>EV<\/font><\/p>  <p>\u624b\u5de5\u4fee\u6539 0xfffffa60`04ae7000\u4e3awriteable\uff0c\u4e0d\u5fc5\u7f6edirty\u6807\u5fd7\uff1a    <br \/><font size=\"1\">1: kd&gt; dq FFFFF6FD30025738 l1      <br \/>fffff6fd`30025738&#160; 00000000`149ad921<\/font><\/p>  <p><font size=\"1\">1: kd&gt; eb FFFFF6FD30025738 23      <br \/>1: kd&gt; !pte 0xfffffa60`04ae7000       <br \/>&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160; VA fffffa6004ae7000       <br \/>PXE @ FFFFF6FB7DBEDFA0&#160;&#160;&#160;&#160; PPE at FFFFF6FB7DBF4C00&#160;&#160;&#160; PDE at FFFFF6FB7E980128&#160;&#160;&#160; PTE at FFFFF6FD30025738       <br \/>contains 000000007FFC4863&#160; contains 000000007FFC3863&#160; contains 00000000539A2863&#160; contains 00000000149AD923       <br \/>pfn 7ffc4&#160;&#160;&#160;&#160;&#160; ---DA--KWEV&#160; pfn 7ffc3&#160;&#160;&#160;&#160;&#160; ---DA--KWEV&#160; pfn 539a2&#160;&#160;&#160;&#160;&#160; ---DA--KWEV&#160; pfn 149ad&#160;&#160;&#160;&#160;&#160; -G--A--K<font color=\"#ff0000\">W<\/font>EV<\/font><\/p>  <p>\u5728\u8fdb\u884c\u5199\u64cd\u4f5c\u524d\u53ef\u4ee5\u5bf9KiPageFault\u6216MmAccessFault\u8bbe\u7f6e\u65ad\u70b9\uff0c\u7136\u540e\u8fdb\u884c\u5b9e\u9a8c\u3002\u770b\u65ad\u70b9\u4f1a\u4e0d\u4f1a\u89e6\u53d1\uff0c\u64cd\u4f5c\u540e\u518d\u68c0\u67e5\u4e00\u4e0bpte\u7684dirty\u6807\u5fd7\u662f\u4e0d\u662f\u5df2\u7ecf\u8bbe\u7f6e\u4e86\u3002\u5177\u4f53\u5b9e\u9a8c\u7ed3\u679c\uff0c\u5c31\u7559\u7ed9\u8bfb\u8005\u81ea\u5df1\u53bb\u9a8c\u8bc1\u4e86\u3002<\/p>  <p>\u5728DISPATCH_LEVEL\u4e2d\u64cd\u4f5cpaged va\u65e0\u8bba\u662f\u5df2\u5c06\u5176page\u9501\u5b9a\u8fd8\u662f\u91cd\u65b0\u6620\u5c04\u8fc7\uff0c\u90fd\u6709\u70b9\u5982\u5c65\u8584\u51b0\u7684\u611f\u89c9\uff0c\u7279\u522b\u662f\u5bf9file cache\uff0cCache Manager\u7684\u4e0d\u5c11\u5185\u90e8\u64cd\u4f5c\u90fd\u4f1a\u66f4\u6539pte\u7684\u5c5e\u6027\u6216\u8c03\u7528MmSetAddressRangeModified\uff0c\u5230\u5904\u90fd\u53ef\u80fd\u6709\u9677\u9631\u3002\u6240\u4ee5\u6700\u4fdd\u9669\u7684\u65b9\u5f0f\u8fd8\u662f\u4e0d\u7528spinlock <img decoding=\"async\" style=\"border-bottom-style: none; border-right-style: none; border-top-style: none; border-left-style: none\" class=\"wlEmoticon wlEmoticon-smile\" alt=\"\u5fae\u7b11\" src=\"https:\/\/blog.dynox.cn\/wp-content\/uploads\/2011\/02\/wlEmoticon-smile.png\" \/><\/p><\/div>","protected":false},"excerpt":{"rendered":"<p>MmSetAddressRangeModified\u7528\u6765\u8bbe\u7f6ePFN\u4e3adirty\/modified\uff0c\u5e76\u5c06PTE\u7684d [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[9],"tags":[187,185,183,182,184,186,65],"views":2288,"_links":{"self":[{"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=\/wp\/v2\/posts\/265"}],"collection":[{"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=265"}],"version-history":[{"count":3,"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=\/wp\/v2\/posts\/265\/revisions"}],"predecessor-version":[{"id":267,"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=\/wp\/v2\/posts\/265\/revisions\/267"}],"wp:attachment":[{"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=265"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=265"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=265"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}