Warning: file_get_contents(/data/phpspider/zhask/data//catemap/4/c/68.json): failed to open stream: No such file or directory in /data/phpspider/zhask/libs/function.php on line 167

Warning: Invalid argument supplied for foreach() in /data/phpspider/zhask/libs/tag.function.php on line 1116

Notice: Undefined index: in /data/phpspider/zhask/libs/function.php on line 180

Warning: array_chunk() expects parameter 1 to be array, null given in /data/phpspider/zhask/libs/function.php on line 181
C 为什么在Windows 8下NDIS_STATUS_失败时NdisFRegisterFilterDriver失败?_C_Windows_Driver_Ndis - Fatal编程技术网

C 为什么在Windows 8下NDIS_STATUS_失败时NdisFRegisterFilterDriver失败?

C 为什么在Windows 8下NDIS_STATUS_失败时NdisFRegisterFilterDriver失败?,c,windows,driver,ndis,C,Windows,Driver,Ndis,各位。我正在开发NDIS 6过滤器驱动程序(LWF)。DriverEntry例程中的NdisFRegisterFilterDriver调用失败,NDIS_STATUS_失败。这只发生在Win8 x86上,驱动程序通常可以在Win7 x86下运行。真奇怪。我见过这条线,但没有用: 这是我的DriverEntry例程和inf文件 _Use_decl_annotations_ NTSTATUS DriverEntry( IN PDRIVER_OBJECT DriverObject,

各位。我正在开发NDIS 6过滤器驱动程序(LWF)。DriverEntry例程中的NdisFRegisterFilterDriver调用失败,NDIS_STATUS_失败。这只发生在Win8 x86上,驱动程序通常可以在Win7 x86下运行。真奇怪。我见过这条线,但没有用:

这是我的DriverEntry例程和inf文件

_Use_decl_annotations_
NTSTATUS
DriverEntry(
    IN PDRIVER_OBJECT DriverObject,
    IN PUNICODE_STRING RegistryPath
    )
{
    NDIS_FILTER_DRIVER_CHARACTERISTICS FChars;
    NTSTATUS Status = STATUS_SUCCESS;
//  NDIS_STRING FriendlyName = NDIS_STRING_CONST("WinPcap NDIS LightWeight Filter");
//  NDIS_STRING UniqueName   = NDIS_STRING_CONST("{5cbf81bd-5055-47cd-9055-a76b2b4e2637}"); //unique name, quid name
//  NDIS_STRING ServiceName = NDIS_STRING_CONST("npf6x"); //this to match the service name in the INF
    NDIS_STRING FriendlyName = RTL_CONSTANT_STRING(L"WinPcap NDIS LightWeight Filter");
    NDIS_STRING UniqueName   = RTL_CONSTANT_STRING(L"{5cbf81bd-5055-47cd-9055-a76b2b4e2637}"); //unique name, quid name
    NDIS_STRING ServiceName = RTL_CONSTANT_STRING(L"npf6x"); //this to match the service name in the INF
    WCHAR* bindT;
    PKEY_VALUE_PARTIAL_INFORMATION tcpBindingsP;
    UNICODE_STRING macName;
    ULONG OsMajorVersion, OsMinorVersion;

    TRACE_ENTER();

    UNREFERENCED_PARAMETER(RegistryPath);

    FilterDriverObject = DriverObject;

    //
    // Get OS version and store it in a global variable. 
    //
    // Note: both RtlGetVersion() and PsGetVersion() are documented to always return success.
    //
    //  OsVersion.dwOSVersionInfoSize = sizeof(OsVersion);
    //  RtlGetVersion(&OsVersion);
    //
    PsGetVersion(&OsMajorVersion, &OsMinorVersion, NULL, NULL);
    TRACE_MESSAGE2(PACKET_DEBUG_INIT, "OS Version: %d.%d\n", OsMajorVersion, OsMinorVersion);


    NdisInitUnicodeString(&g_NPF_Prefix, g_NPF_PrefixBuffer);

    //
    // Get number of CPUs and save it
    //
#ifdef NDIS620
    g_NCpu = NdisGroupMaxProcessorCount(ALL_PROCESSOR_GROUPS);
#else
    g_NCpu = NdisSystemProcessorCount();
#endif

    //
    // TODO: Most handlers are optional, however, this sample includes them
    // all for illustrative purposes.  If you do not need a particular 
    // handler, set it to NULL and NDIS will more efficiently pass the
    // operation through on your behalf.
    //


    //
    // Register as a service with NDIS
    //
//  NdisZeroMemory(&FChars, NDIS_SIZEOF_FILTER_DRIVER_CHARACTERISTICS_REVISION_1);
//  FChars.Header.Type = NDIS_OBJECT_TYPE_FILTER_DRIVER_CHARACTERISTICS;
//  FChars.Header.Size = NDIS_SIZEOF_FILTER_DRIVER_CHARACTERISTICS_REVISION_1;
//  FChars.Header.Revision = NDIS_FILTER_CHARACTERISTICS_REVISION_1;

    //
    // Register as a service with NDIS
    //
    NdisZeroMemory(&FChars, sizeof(NDIS_FILTER_DRIVER_CHARACTERISTICS));
    FChars.Header.Type = NDIS_OBJECT_TYPE_FILTER_DRIVER_CHARACTERISTICS;
    FChars.Header.Size = sizeof(NDIS_FILTER_DRIVER_CHARACTERISTICS);
#if NDIS_SUPPORT_NDIS61
    FChars.Header.Revision = NDIS_FILTER_CHARACTERISTICS_REVISION_2;
#else
    FChars.Header.Revision = NDIS_FILTER_CHARACTERISTICS_REVISION_1;
#endif

    FChars.MajorNdisVersion = NDIS_FILTER_MAJOR_VERSION;
    FChars.MinorNdisVersion = NDIS_FILTER_MINOR_VERSION;
    FChars.MajorDriverVersion = 1;
    FChars.MinorDriverVersion = 0;
    FChars.Flags = 0;

    FChars.FriendlyName = FriendlyName;
    FChars.UniqueName = UniqueName;
    FChars.ServiceName = ServiceName;

    FChars.SetOptionsHandler = NPF_RegisterOptions;
    FChars.AttachHandler = NPF_Attach;
    FChars.DetachHandler = NPF_Detach;
    FChars.RestartHandler = NPF_Restart;
    FChars.PauseHandler = NPF_Pause;
    FChars.SetFilterModuleOptionsHandler = NPF_SetModuleOptions;
    FChars.OidRequestHandler = NPF_OidRequest;
    FChars.OidRequestCompleteHandler = NPF_OidRequestComplete;
    FChars.CancelOidRequestHandler = NPF_CancelOidRequest;

    FChars.SendNetBufferListsHandler = NPF_SendEx;
    FChars.ReturnNetBufferListsHandler = NPF_ReturnEx;
    FChars.SendNetBufferListsCompleteHandler = NPF_SendCompleteEx;
    FChars.ReceiveNetBufferListsHandler = NPF_TapEx;
    FChars.DevicePnPEventNotifyHandler = NPF_DevicePnPEventNotify;
    FChars.NetPnPEventHandler = NPF_NetPnPEvent;
    FChars.StatusHandler = NPF_Status;
    FChars.CancelSendNetBufferListsHandler = NPF_CancelSendNetBufferLists;

    DriverObject->DriverUnload = NPF_Unload;

    //
    // Initialize spin locks
    //
    //NdisAllocateSpinLock(&FilterListLock);

    //InitializeListHead(&FilterModuleList);


    // 
    // Standard device driver entry points stuff.
    //
    DriverObject->MajorFunction[IRP_MJ_CREATE] = NPF_OpenAdapter;
    DriverObject->MajorFunction[IRP_MJ_CLOSE] = NPF_CloseAdapter;
    DriverObject->MajorFunction[IRP_MJ_CLEANUP] = NPF_Cleanup; 
    DriverObject->MajorFunction[IRP_MJ_READ] = NPF_Read;
    DriverObject->MajorFunction[IRP_MJ_WRITE] = NPF_Write;
    DriverObject->MajorFunction[IRP_MJ_DEVICE_CONTROL] = NPF_IoControl;

    bindP = getAdaptersList();

    if (bindP == NULL)
    {
        TRACE_MESSAGE(PACKET_DEBUG_INIT, "Adapters not found in the registry, try to copy the bindings of TCP-IP.");

        tcpBindingsP = getTcpBindings();

        if (tcpBindingsP == NULL)
        {
            TRACE_MESSAGE(PACKET_DEBUG_INIT, "TCP-IP not found, quitting.");
            goto RegistryError;
        }

        bindP = (WCHAR *)tcpBindingsP;
        bindT = (WCHAR *)(tcpBindingsP->Data);
    }
    else
    {
        bindT = bindP;
    }

    for (; *bindT != UNICODE_NULL; bindT += (macName.Length + sizeof(UNICODE_NULL)) / sizeof(WCHAR))
    {
        RtlInitUnicodeString(&macName, bindT);
        NPF_CreateDevice(DriverObject, &macName);
    }


    Status = NdisFRegisterFilterDriver(DriverObject,
        (NDIS_HANDLE) FilterDriverObject,
        &FChars,
        &FilterDriverHandle);
    if (Status != NDIS_STATUS_SUCCESS)
    {
        TRACE_MESSAGE(PACKET_DEBUG_INIT, "Failed to register filter with NDIS.");
        TRACE_EXIT();
        return Status;
    }


    TRACE_EXIT();
    return STATUS_SUCCESS;

    RegistryError :

    Status = STATUS_UNSUCCESSFUL;
    TRACE_EXIT();
    return(Status);
}
inf文件:

;-------------------------------------------------------------------------
; NPF6X.INF -- NPF NDIS 6.x LightWeight Filter Driver
;
; Copyright (c) 2013, InSecure.Com, LLC.  All rights reserved.
;------------------------------------------------------------------------
[version]
Signature       = "$Windows NT$"
Class           = NetService
ClassGUID       = {4D36E974-E325-11CE-BFC1-08002BE10318}
CatalogFile     = npf6x.cat
Provider        = %Insecure%
DriverVer=08/18/2013,0.31.43.389


[Manufacturer]
%Insecure%=Insecure,NTx86,NTia64,NTamd64

[Insecure.NTx86]
%NPF6x_Desc%=Install, INSECURE_NPF6X

[Insecure.NTia64]
%NPF6x_Desc%=Install, INSECURE_NPF6X

[Insecure.NTamd64]
%NPF6x_Desc%=Install, INSECURE_NPF6X

;-------------------------------------------------------------------------
; Installation Section
;-------------------------------------------------------------------------
[Install]
AddReg=Inst_Ndi
Characteristics=0x40000
NetCfgInstanceId="{5cbf81bd-5055-47cd-9055-a76b2b4e2637}"
Copyfiles = npf6x.copyfiles.sys

[SourceDisksNames]
1=%NPF6x_Desc%,"",,

[SourceDisksFiles]
npf6x.sys=1

[DestinationDirs]
DefaultDestDir=12
npf6x.copyfiles.sys=12

[npf6x.copyfiles.sys]
npf6x.sys,,,2


;-------------------------------------------------------------------------
; Ndi installation support
;-------------------------------------------------------------------------
[Inst_Ndi]
HKR, Ndi,Service,,"npf6x"
HKR, Ndi,CoServices,0x00010000,"npf6x"
HKR, Ndi,HelpText,,%NPF6X_HelpText%
HKR, Ndi,FilterClass,, compression


; For a Monitoring filter, use this:
;     HKR, Ndi,FilterType,0x00010001, 1 ; Monitoring filter
; For a Modifying filter, use this:
;     HKR, Ndi,FilterType,0x00010001, 2 ; Modifying filter
HKR, Ndi,FilterType,0x00010001,2


HKR, Ndi\Interfaces,UpperRange,,"noupper"
HKR, Ndi\Interfaces,LowerRange,,"nolower"


; TODO: Ensure that the list of media types below is correct.  Typically,
; filters include "ethernet".  Filters may also include "ppip" to include
; native WWAN stacks, but you must be prepared to handle the packet framing.
; Possible values are listed on MSDN, but common values include:
;     ethernet, wan, ppip, wlan
HKR, Ndi\Interfaces, FilterMediaTypes,,"ethernet, wan, ppip, wlan"


; For a Mandatory filter, use this:
;     HKR, Ndi,FilterRunType,0x00010001, 1 ; Mandatory filter
; For an Optional filter, use this:
;     HKR, Ndi,FilterRunType,0x00010001, 2 ; Optional filter
HKR, Ndi,FilterRunType,0x00010001, 2 ; Optional filter


; By default, Mandatory filters unbind all protocols when they are
; installed/uninstalled, while Optional filters merely pause the stack.  If you
; would like to override this behavior, you can include these options.  These
; options only take effect with 6.30 filters on Windows "8" or later.
; To prevent a full unbind, and merely pause/restart protocols:
;     HKR, Ndi,UnbindOnAttach,0x00010001, 0 ; Do not unbind during FilterAttach
;     HKR, Ndi,UnbindOnDetach,0x00010001, 0 ; Do not unbind during FilterDetach
; To force a full unbind/bind (which includes pause/restart, of course):
;     HKR, Ndi,UnbindOnAttach,0x00010001, 1 ; Unbind during FilterAttach
;     HKR, Ndi,UnbindOnDetach,0x00010001, 1 ; Unbind during FilterDetach
;

;-------------------------------------------------------------------------
; Service installation support
;-------------------------------------------------------------------------
[Install.Services]
AddService=npf,,NPF6X_Service_Inst

[NPF6X_Service_Inst]
DisplayName     = %NPF6x_Desc%
ServiceType     = 1 ;SERVICE_KERNEL_DRIVER
StartType       = 3 ;SERVICE_DEMAND_START
ErrorControl    = 1 ;SERVICE_ERROR_NORMAL
ServiceBinary   = %12%\npf6x.sys
LoadOrderGroup  = NDIS
Description     = %NPF6x_Desc%

[Install.Remove.Services]
DelService=npf,0x200 ; SPSVCINST_STOPSERVICE

[NdisImPlatformBindingOptions.reg]
; By default, when an LBFO team or Bridge is created, all filters will be
; unbound from the underlying members and bound to the TNic(s). This keyword
; allows a component to opt out of the default behavior
; To prevent binding this filter to the TNic(s):
;   HKR, Parameters, NdisImPlatformBindingOptions,0x00010001,1 ; Do not bind to TNic
; To prevent unbinding this filter from underlying members:
;   HKR, Parameters, NdisImPlatformBindingOptions,0x00010001,2 ; Do not unbind from Members
; To prevent both binding to TNic and unbinding from members:
;   HKR, Parameters, NdisImPlatformBindingOptions,0x00010001,3 ; Do not bind to TNic or unbind from Members
HKR, Parameters, NdisImPlatformBindingOptions,0x00010001,0 ; Subscribe to default behavior

[Strings]
Insecure = "Nmap Project"
NPF6X_Desc = "WinPcap Lightweight Filter Driver (NPF)"
NPF6X_HelpText = "A NDIS 6 kernel filter driver to support packet capturing under Windows 7 & Windows 8"

以下是我将遵循的诊断步骤:

  • 将NetCfgInstanceId更改为,与示例驱动程序使用的
    {5cbf81bd…}
    GUID不同,这一点非常重要

  • 检查过滤器是否已安装。从中使用bindview。或者查看
    HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}{
    您的NetCfgInstanceId
    }\Ndi
    ,并验证是否存在筛选器驱动程序的条目。NDIS需要在该键下具有
    FilterType
    FilterRunType

  • 检查您的
    NPF\u RegisterOptions
    例程是否被调用,如果是,它是否返回
    NDIS\u STATUS\u SUCCESS

  • 如前所述,启用NDIS跟踪。可能会有一条信息性消息,说明NDIS未能注册筛选器驱动程序的原因。(虽然说实话,我们没有我想要的那么多跟踪。)注意,在Windows 8和更高版本上,您不再需要下载TMF文件,因为TMF内置在NDIS.PDB中,调试器会自动为您下载

  • 在调用
    NdisFRegisterFilterDriver
    期间,NDIS将调用多个内部例程。尝试在每个断点上设置断点,以查看调用了哪些断点以及它们返回的状态代码。(注意,在x86上,
    eax
    寄存器通常保存返回值,因此在这些子例程返回到
    NdisFRegisterFilterDriver
    后,您可以检查
    eax
    寄存器

    • ndisCreateFilterDriverRegistry
    • ndisReadFilterDriverRegistry
    • ndisFInvokeSetOptions

  • 以下是我将遵循的诊断步骤:

  • 将NetCfgInstanceId更改为,与示例驱动程序使用的
    {5cbf81bd…}
    GUID不同,这一点非常重要

  • 检查是否确实安装了筛选器。使用bindview from。或查看
    HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e974-e325-11ce-bfc1-08002be10318}{
    您的NetCfgInstanceId
    }\Ndi
    并验证是否存在筛选器驱动程序的条目。Ndi需要在该键下具有
    FilterType
    FilterRunType

  • 检查您的
    NPF\u RegisterOptions
    例程是否被调用,如果是,它是否返回
    NDIS\u STATUS\u SUCCESS

  • 如前所述,启用NDIS跟踪。可能会有一条关于NDIS未通过筛选器驱动程序注册的原因的信息性消息。(尽管说实话,我们没有我想要的那么多跟踪。)请注意,在Windows 8及更高版本上,您不再需要下载TMF文件,因为TMF内置在NDIS.PDB中,调试器会自动为您下载

  • 在调用
    NdisFRegisterFilterDriver
    期间,NDIS将调用多个内部例程。请尝试在每个例程上设置断点,以查看调用了哪些断点以及它们返回的状态代码。(注意,在x86上,
    eax
    寄存器通常保存返回值,因此在这些子例程返回到
    NdisFRegisterFilterDriver
    后,您可以检查
    eax
    寄存器

    • ndisCreateFilterDriverRegistry
    • ndisReadFilterDriverRegistry
    • ndisFInvokeSetOptions

  • 在ini文件中修改此值,可能有用:


    StartType=1

    在ini文件中修改此值,可能有用:


    StartType=1

    1)我已经更改了GUID,您可以看到我的最后四位数字已更改为“2637”,但现在我使用GUID生成器获取全新的GUID,问题仍然存在。2)我在注册表中找到了GUID条目,筛选器类型为2,FilterRunType为2。3)未调用NPF_注册表选项,因为NdisFRegisterFilterDriver函数永远不会成功。4)我在这三个函数上设置了断点,ndisCreateFilterDriverRegistry返回c0000001代码(NDIS_STATUS_FAILURE)。其他两个函数从未被调用。5)我执行了“!wmitrace.start ndis”命令,并执行了NdisFRegisterFilterDriver调用,它返回c0000001错误,但我没有看到任何消息文本内容。也许我使用了错误的命令?嗨,Jeffery,问题似乎已经解决了,结果是NDIS_筛选器_驱动程序_特征中的ServiceName必须与“AddService”和“DelService”名称相同。我对这两个地方用了不同的名字。奇怪的是,这个NdisFRegisterFilterDriver失败问题只发生在Win8下。Win7对此用法没有问题。解决此问题后,“net start npf”命令可以正常执行,但旧问题“在Windows8下不调用FilterAttach”仍然存在。我希望您在这里再次查看一个旧的未解决线程:1)我已经更改了GUID,您可以看到我的最后四位数字已更改为“2637”,但现在我使用GUID生成器获得了一个全新的GUID,问题仍然存在。2) 我在注册表中找到了GUID项,筛选器类型为2,FilterRunType为2。3) 未调用NPF_RegisterOptions,因为NdisFRegisterFilterDriver函数从未成功。4)我在三个函数上设置了断点,ndisCreateFilterDriverRegistry返回c0000001代码(NDIS_状态_失败)。其他两个函数从未调用过。5)我执行了“!wmitrace.start ndis”命令,然后