{"id":874,"date":"2012-09-11T00:44:06","date_gmt":"2012-09-10T16:44:06","guid":{"rendered":"http:\/\/blog.dynox.cn\/?p=874"},"modified":"2017-10-18T23:49:12","modified_gmt":"2017-10-18T15:49:12","slug":"%e8%93%9d%e5%b1%8f%ef%bc%8c%e8%b0%81%e4%b9%8b%e8%bf%87%ef%bc%9f","status":"publish","type":"post","link":"https:\/\/blog.dynox.cn\/?p=874","title":{"rendered":"\u84dd\u5c4f\uff0c\u8c01\u4e4b\u8fc7\uff1f"},"content":{"rendered":"<div class=\"gruber-markdown\"><p><span style=\"font-size: small;\">Bug\u603b\u80fd\u5728\u4f60\u610f\u60f3\u4e0d\u5230\u7684\u5730\u65b9\u7ed9\u4f60\u4e2a\u63aa\u624b\u4e0d\u53ca\uff0c\u53ea\u662f\u5b83\u6240\u5e26\u6765\u5e76\u4e0d\u662f\u60ca\u559c\uff0c\u800c\u662fBlue Screen Of Death !<\/span><\/p>\n<p><span style=\"font-size: small;\">\u65e2\u5982\u6b64\uff0c\u53ea\u80fd\u5175\u6765\u5c06\u6321\u3002<\/span><\/p>\n<p><span style=\"font-size: small;\">\u5148\u4ecb\u7ecd\u4e00\u4e0b\u7a0b\u5e8f\u7684\u5927\u4f53\u6d41\u7a0b\uff1a<\/span><\/p>\n<pre><code class=\"prettyprint\" class=\"language-c\">NTSTATUS\nXXXProcessDirents(\u2026)\n{    \n    do {\n        KeEnterCriticalRegion();\n        ExAcquireResourceSharedLite(&amp;amp;fcb-&amp;gt;Resource, TRUE);\n\n        \/* access several members of fcb structure *\/\n        ExReleaseResourceLite(&amp;amp;fcb-&amp;gt;Resource);\n        KeLeaveCriticalRegion();\n\n\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0   XXXXProcessDirent(\u2026);\n\n    } while (list_is_not_empty(\u2026.));\n\n    return status;\n}\n\nNTSTATUS\nXXXXProcessDirent(\u2026)\n{\n    HANDLE handle = NULL;\n    XXXX_FILE_HEADE fileHead;\n    \u2026\u2026\n\n    \/* open file *\/\n    status = ZwCreateFile(&amp;handle, GENERIC_READ, &amp;oa, &amp;iosb, NULL, 0,\n                          FILE_SHARE_READ | FILE_SHARE_WRITE | FILE_SHARE_DELETE,\n                          FILE_OPEN, 0, NULL, 0);\n\n    \/* read file header*\/\n    status = ZwReadFile(handle, ioevent, NULL, NULL, &amp;amp;iosb, (PVOID)&amp;fileHead,\n                        sizeof(XXXX_FILE_HEADE), &amp;offset, NULL);\n\n    \/* check whether file is interesting to us *\/\n    if (status == STATUS_SUCCESS &amp;&amp; iosb.Information == sizeof(\u2026\u2026)) {\n        \/* it\u2019s my taste, haha *\/\n    }\n\n    \/* close file, not interested in it any more *\/\n\n    if (handle){\n        ZwClose(handle);\n    }\n\n    return status;\n}<\/code><\/pre>\n<p><span style=\"font-size: small;\">\u8fc7\u7a0b\u6bd4\u8f83\u7b80\u5355\uff0c<strong>XXXProcessDirents()<\/strong>\u4f1a\u5faa\u73af\u8c03\u7528<strong>XXXProcessDirent()<\/strong>\uff0c\u76f4\u81f3\u5217\u8868\u4e2d\u6240\u6709\u9879\u5168\u68c0\u67e5\u5b8c\u6bd5\u3002<\/span><\/p>\n<p><span style=\"font-size: small;\">\u4e0b\u9762\u518d\u6765\u770bwindbg\u5206\u6790\u5427\uff1a<\/span><\/p>\n<pre><code class=\"prettyprint\" class=\"language-c\">1: kd&gt; !analyze -v\n*******************************************************************************\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 *\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 Bugcheck Analysis\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 *\n*\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 *\n*******************************************************************************\n\nIRQL_NOT_LESS_OR_EQUAL (a)\nAn attempt was made to access a pageable (or completely invalid) address at an\ninterrupt request level (IRQL) that is too high.\u00a0 This is usually\ncaused by drivers using improper addresses.\nIf a kernel debugger is available get the stack backtrace.\nArguments:\nArg1: 0abc9867, memory referenced\nArg2: 00000002, IRQL\nArg3: 00000001, bitfield :\nbit 0 : value 0 = read operation, 1 = write operation\nbit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)\nArg4: 806e7a2a, address which referenced memory\n\nDebugging Details:\n------------------\n\nWRITE_ADDRESS:\u00a0 0abc9867\n\nCURRENT_IRQL:\u00a0 2\n\nFAULTING_IP:\nhal!KeAcquireInStackQueuedSpinLock+3a\n806e7a2a 8902\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 mov\u00a0\u00a0\u00a0\u00a0 dword ptr [edx],eax\n\nDEFAULT_BUCKET_ID:\u00a0 DRIVER_FAULT\n\nBUGCHECK_STR:\u00a0 0xA\n\nPROCESS_NAME:\u00a0 System\n\nTRAP_FRAME:\u00a0 b9019bbc -- (.trap 0xffffffffb9019bbc)\nErrCode = 00000002\neax=b9019c40 ebx=00000000 ecx=c0000211 edx=0abc9867 esi=c0000128 edi=8842d268\neip=806e7a2a esp=b9019c30 ebp=b9019c68 iopl=0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 nv up ei ng nz na pe nc\ncs=0008\u00a0 ss=0010\u00a0 ds=0023\u00a0 es=0023\u00a0 fs=0030\u00a0 gs=0000\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 efl=00010286\nhal!KeAcquireInStackQueuedSpinLock+0x3a:\n806e7a2a 8902\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0\u00a0 mov\u00a0\u00a0\u00a0\u00a0 dword ptr [edx],eax\u00a0 ds:0023:0abc9867=????????\nResetting default scope\n\nLAST_CONTROL_TRANSFER:\u00a0 from 806e7a2a to 80544768\n\nSTACK_TEXT:\nb9019bbc 806e7a2a badb0d00 0abc9867 804f4e77 nt!KiTrap0E+0x238\nb9019c68 806e7ef2 00000000 00000000 b9019c80 hal!KeAcquireInStackQueuedSpinLock+0x3a\nb9019c68 b9019d24 00000000 00000000 b9019c80 hal!HalpApcInterrupt+0xc6\nWARNING: Frame IP not in any known module. Following frames may be wrong.\nb9019cf0 80535873 00000000 8896fb20 00000000 0xb9019d24\nb9019d10 b79d87ff ba668a30 8859b7e8 00000440 nt!ExReleaseResourceLite+0x8d\nb9019d2c b79d8a5c 8a3ff2f0 00000003 ba6685f0 XXXXX!XXXProcessDirents+0xef\nb9019d88 b79e163a e2f6b170 00000001 00000001 XXXXX!XXXKernelQueryDirectory+0x20c\nb9019ddc 8054616e b79e1530 88a8ae00 00000000 nt!PspSystemThreadStartup+0x34\n00000000 00000000 00000000 00000000 00000000 nt!KiThreadStartup+0x16<\/code><\/pre>\n<p><span style=\"font-size: small;\">\u95ee\u9898\u51fa\u5728\u7cfb\u7edf\u51fd\u6570ExReleaseResourceLite()\u53caKeAcquireInStackQueuedSpinLock()\u4e0a\uff0c\u4e14\u7a0b\u5e8f\u8981\u5199\u7684\u5730\u5740\u4e3a0abc9867 \uff0c\u660e\u663e\u4e0d\u5bf9\uff0c\u6240\u4ee5\u6b64\u5904\u53ef\u505a\u6808\u635f\u574f\u63a8\u65ad\u3002<\/span><\/p>\n<p><span style=\"font-size: small;\">\u7b2c\u4e00\u5acc\u7591\u8981\u8003\u8651\u7684\u662f\uff0c<strong>XXXProcessDirents()<\/strong>\u4e2d\u6709\u9501\u4fdd\u62a4\u7684\u90e8\u5206\uff0c\u6b64\u90e8\u5206\u662f\u679c\u771f\u662f\u6700\u5bb9\u6613\u9020\u6210\u6808\u635f\u574fbuffer\u590d\u5236\u64cd\u4f5c\u3002\u4f46\u7ecf\u8fc7\u4ed4\u7ec6\u68c0\u67e5\u53ca\u6d4b\u8bd5\uff0c\u4fbf\u6392\u9664\u4e86\u6b64\u90e8\u5206\u51fa\u9519\u7684\u53ef\u80fd\u3002<\/span><\/p>\n<p><span style=\"font-size: small;\">\u5728\u6392\u9664<span style=\"font-size: small;\">\u7b2c\u4e00\u5acc\u7591\u540e\uff0c\u5c31\u6ca1\u6709\u660e\u663e\u76ee\u6807\u4e86\u3002\u53ea\u597d\u518d\u63a5\u7740\u770bwindbg log\uff1a<\/span><\/span><\/p>\n<p><span style=\"font-size: small;\">\u8c8c\u4f3cKeAcquireInStackQueuedSpinLock()\u8981\u5199\u7684\u5730\u5740\u662fLockHandle\u7684LockQueue-&gt;Next\uff0c\u800cLockHandle\u4e00\u822c\u90fd\u5728\u4ece\u5f53\u524d\u5806\u6808\u5206\u914d\u7684\uff0c\u7531\u6b64\u53ef\u80af\u5b9a\u4e4b\u524d\u5bf9\u4e8e\u6808\u635f\u574f\u7684\u63a8\u65ad\u3002\u53ef\u95ee\u9898\u662f\uff0c\u662f\u8c01\u5bfc\u81f4\u7684\u6808\u635f\u574f\u3002<\/span><\/p>\n<p><span style=\"font-size: small;\">Stack\u4e2d\u6709hal!HalpApcInterrupt()\u8c03\u7528\u8bb0\u5f55\uff0c\u5b83\u662f\u5904\u7406APC\u7684\u8f6f\u4e2d\u65ad\u3002hal!HalpApcInterrupt()\u4f1a\u4e00\u822c\u4f1a\u8c03\u7528nt!KiDeliverApc()\u6765\u5904\u7406\u7ebf\u7a0b\u7684APC\u961f\u5217\u3002\u4f46\u5f53ExReleaseResourceLite()\u8c03\u7528\u7684\u65f6\u5019\uff0c\u7ebf\u7a0b\u8fd8\u5904\u4e8e\u4e34\u754c\u533a\u5185\uff08Critical Section\uff09\uff0c\u6b64\u65f6User mode APC\u53caKernel mode normal APC\u90fd\u4f1a\u88ab\u7981\u6b62\u7684\uff0c\u4f46Kernel mode special APC\u4e0d\u4f1a\u3002<\/span><\/p>\n<p><span style=\"font-size: small;\">Kernel Special APC\u6700\u5e38\u89c1\u7684\u60c5\u51b5\u4fbf\u662f\u7531IoCompleteRequest()\u6dfb\u52a0\u7684\uff1a\u5728APC Level\u4e2d\u8c03\u7528IopCompleteRequest()\u4ee5\u5904\u7406Irp\u7684Stage 2\u7684\u6e05\u7406\u5de5\u4f5c\u3002<\/span><\/p>\n<p><span style=\"font-size: small;\">\u81f3\u6b64\uff0c\u95ee\u9898\u7ec8\u4e8e\u6709\u4e9b\u7709\u76ee\u4e86\u3002\u5206\u6790\u4ee3\u7801\u4e2d\u552f\u4e00\u6709\u53ef\u80fd\u5bfc\u81f4APC\u6dfb\u52a0\u7684\u5730\u65b9\u5c31\u5728\u51fd\u6570<strong>XXXXProcessDirent()<\/strong>\u4e2d\u7684ZwReadFile()\u8c03\u7528\uff0c<\/span><span style=\"font-size: small;\">\u800c\u4e14fileHead\u6b63\u662f\u4e8e\u5806\u6808\u4e2d\u5206\u914d\u7684\u3002<\/span><\/p>\n<p><span style=\"font-size: small;\">\u60f3\u5230\u6b64\u5904\uff0c\u6b64bug\u7684\u6839\u636e\u539f\u56e0\u4fbf\u4ed8\u51fa\u6c34\u9762\uff1a<\/span><\/p>\n<p><span style=\"font-size: small;\"><strong>XXXXProcessDirent()<\/strong>\u6ca1\u6709\u5904\u7406ZwReadFile()\u8fd4\u56deSTATUS_PENDING\u7684\u60c5\u51b5\uff0c\u6b64\u60c5\u5f62\u4e0b\uff0c<strong>XXXXProcessDirent()<\/strong>\u9000\u51fa\u5e76\u7ee7\u7eed\u6267\u884c\uff0c\u800c\u4e4b\u524d\u7684ZwReadFile()\u7684IRP\u5b8c\u6210\u64cd\u4f5c\u4e5f\u5728\u540c\u65f6\u8fdb\u884c\uff08\u8fd8\u6ca1\u6709\u5b8c\u6210\uff09\uff0c\u5e76\u4e14\u6b64\u5b8c\u6210\u64cd\u4f5c\u6240\u8981\u5199\u7684fileHead\u5730\u5740\uff0c\u6b63\u662f\u65e9\u5df2\u88ab\u56de\u6536\u5e76\u52a0\u4ee5\u91cd\u7528\u7684\u5f53\u524d\u6808\u3002<\/span><\/p>\n<p><span style=\"font-size: small;\">\u641e\u6e05\u695a\u4e4b\u540e\uff0c\u4fbf\u5728\u8c03\u7528ZwReadFile()\u540e\uff0c\u7279\u522b\u9488\u5bf9STATUS_PENING\u7684\u60c5\u51b5\u6765\u8c03\u7528ZwWaitForSingleObject()\u4ee5\u786e\u4fdd\u8bfb\u64cd\u4f5c\u5168\u90e8\u5b8c\u6210\u540e\uff0c\u518d\u8fdb\u884c\u4e0b\u4e00\u6b65\u64cd\u4f5c\u3002<\/span><\/p>\n<p><span style=\"font-size: small;\">\u5230\u6b64\uff0c\u95ee\u9898\u89e3\u51b3\uff01<\/span><\/p>\n<p><span style=\"font-size: small;\">\u4e00\u4e2a\u84dd\u5c4f\u7684\u95ee\u9898\uff0c\u7adf\u7136\u5982\u6b64\u4e4b\u7ed5\uff0c\u4e0d\u7981\u8ba9\u6211\u60f3\u8d77\u5218\u9707\u4e91\u7684\u300a\u4e00\u53e5\u9876\u4e00\u4e07\u53e5\u300b\uff0c\u53ea\u662f\u8fd9\u80fd\u9876\u4e00\u4e07\u53e5\u7684\u4e00\u53e5\u5230\u5e95\u662f\u54ea\u53e5\u5462\uff1f<\/span><\/p>\n<p>&lt;\u4e0b\u4e00\u6b65\u6253\u7b97\u5199\u5199APC\u76f8\u5173\u7684\u4e1c\u897f\uff0c\u64cd\u4f5c\u7cfb\u7edf\u5c06APC\u9690\u85cf\u5f97\u592a\u6df1\uff0c\u603b\u8ba9\u4eba\u6349\u6478\u4e0d\u5b9a\uff01&gt;<\/p><\/div>","protected":false},"excerpt":{"rendered":"<p>Bug\u603b\u80fd\u5728\u4f60\u610f\u60f3\u4e0d\u5230\u7684\u5730\u65b9\u7ed9\u4f60\u4e2a\u63aa\u624b\u4e0d\u53ca\uff0c\u53ea\u662f\u5b83\u6240\u5e26\u6765\u5e76\u4e0d\u662f\u60ca\u559c\uff0c\u800c\u662fBlue Screen Of Deat [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[9],"tags":[425,187,65,394,280],"views":25584,"_links":{"self":[{"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=\/wp\/v2\/posts\/874"}],"collection":[{"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=874"}],"version-history":[{"count":5,"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=\/wp\/v2\/posts\/874\/revisions"}],"predecessor-version":[{"id":1619,"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=\/wp\/v2\/posts\/874\/revisions\/1619"}],"wp:attachment":[{"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=874"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=874"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.dynox.cn\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=874"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}