BTH_DEVICE_INFO_LIST IOCTL 执行

问题描述

我正在尝试为此执行 IOCTL_BTH_GET_DEVICE_INFO,作为初学者,我编写了以下代码

#include <ntddk.h>
#include <stdio.h>
#include <conio.h>
#include <stdlib.h>
#include <ntddk.h>
#include <wdf.h>
#include <initguid.h> 
#include <ntstrsafe.h>
#include <bthdef.h>
#include <ntintsafe.h>
#include <bthguid.h>
#include <bthioctl.h>
#include <sdpnode.h>
#include <bthddi.h>
#include <bthsdpddi.h>
#include <bthsdpdef.h>
#include <wdfobject.h>
#include <wdfdriver.h>
#include <wdm.h>

DRIVER_INITIALIZE DriverEntry;
EVT_WDF_DRIVER_DEVICE_ADD KmdfHelloWorldEvtDeviceAdd;
UNICODE_STRING DeviceName = RTL_CONSTANT_STRING(L"\\Device\\MyDeivce123");
PDEVICE_OBJECT DeviceObject = NULL;
UNICODE_STRING SymLinkName = RTL_CONSTANT_STRING(L"\\??\mydevicelink123");
NTSTATUS BleDispatchCreate(PDEVICE_OBJECT device_obj,PIRP Irp)
{
KdPrint((" Inside BleDispatchCreate "));
KdPrint((" BleDispatchCreate Execution complete"));
//need to return status
return STATUS_SUCCESS;
}

NTSTATUS BleDispatchDeviceControl(PDEVICE_OBJECT device_obj,PIRP Irp)
{
KdPrint((" Inside BleDispatchDeviceControl "));

KdPrint((" BleDispatchDeviceControl Execution complete"));
//need to return status
return STATUS_SUCCESS;
}
//removed Unload function
NTSTATUS BleTest(PDEVICE_OBJECT device_obj,PIRP Irp)
{
PBTH_DEVICE_INFO_LIST PBLRI = (PBTH_DEVICE_INFO_LIST)Irp- >AssociatedIrp.SystemBuffer;
NTSTATUS status = STATUS_SUCCESS;
PIO_STACK_LOCATION irp_sl = IoGetCurrentIrpStackLocation(Irp);
KdPrint(("Number of devices are before i/ocall  %lu",PBLRI->numOfDevices));
status = IoCallDriver(device_obj,Irp);
if (status == STATUS_SUCCESS) {
    KdPrint(("IOCALLDRIVER  SUCCESS : \n "));
    KdPrint(("Number of devices are %lu",PBLRI->numOfDevices));
}
else {
    KdPrint(("Driver call Failed!\r\n"));
    return status;
}
return status;
}
NTSTATUS DriverEntry(_In_ PDRIVER_OBJECT DriverObject,_In_ PUNICODE_STRING 
RegistryPath) {
NTSTATUS status = STATUS_SUCCESS;
int i;
DriverObject->DriverUnload = Unload;

status = IoCreateDevice(DriverObject,&DeviceName,FILE_DEVICE_BLUETOOTH,FILE_CHARACTERISTIC_PNP_DEVICE,FALSE,&DeviceObject);
if (!NT_SUCCESS(status)){
    KdPrint(("creating device failed \n "));
    return status;
}else
    KdPrint(("Device creation successful\r\n"));
status = IoCreateSymbolicLink(&SymLinkName,&DeviceName);
if (!NT_SUCCESS(status)){
    KdPrint(("creating symbolic link failed \n"));
    IoDeleteDevice(DeviceObject);
    return status;
}else
    KdPrint(("Symbolic link creation successful\r\n"));
DriverObject->MajorFunction[IRP_MJ_DEVICE_CONTROL] = 
BleDispatchDeviceControl;
/********fill IRP *****************************/
PIRP Irp = NULL;
ULONG IoControlCode = IOCTL_BTH_GET_DEVICE_INFO;
ULONG InputBufferLength = sizeof(BTH_DEVICE_INFO_LIST);
BTH_DEVICE_INFO_LIST  InputBuffer;
ULONG OutputBufferLength = sizeof(BTH_DEVICE_INFO_LIST);
BTH_DEVICE_INFO_LIST  OutputBuffer;
BOOLEAN InternalDeviceIoControl = FALSE;
PKEVENT Event = NULL;
IO_STATUS_BLOCK ISB;
PIO_STATUS_BLOCK IoStatusBlock = &ISB;
Irp = IoBuildDeviceIoControlRequest(IoControlCode,DeviceObject,&InputBuffer,InputBufferLength,&OutputBuffer,OutputBufferLength,InternalDeviceIoControl,Event,IoStatusBlock);
/* IO_COMPLETION_ROUTINE CdDevCtrlCompletionRoutine;
NTSTATUS
    CdDevCtrlCompletionRoutine(
        _In_ PDEVICE_OBJECT DeviceObject,_In_ PIRP Irp,_In_reads_opt_(_Inexpressible_("varies")) PVOID Contxt
    );*/
BleTest(DeviceObject,Irp);
KdPrint(("Driver LOAD ENDS returning success \n "));
return status;
}

输出日志文件是

  • 设备创建成功
  • 符号链接创建成功
  • I/O 调用前的设备数量 1313444832
  • BleDispatchDeviceControl 内部
  • BleDispatchDeviceControl 执行完成
  • IOCALLDRIVER 成功:
  • 设备数量为 1313444832
  • 驱动程序加载结束返回成功
  • 驱动卸载调用

在我看来它打印了一些垃圾值。请指出我在 init 中犯的错误?我是这个领域的初学者。如果这个帖子不清楚,请指出我。我会尽量使它更简洁。

解决方法

您提供的代码不完整,DeviceObjectOutputBufferLengthdevice_obj 未定义。所以我没有办法测试它,我会告诉你我目前看到的问题,但如果他们无法修复错误,请Minimal Reproducible Example

  1. InputBufferOutputBuffer 目前表示一个包含 sizeof(BTH_DEVICE_INFO_LIST) 元素的数组,元素类型为 PVOID,这显然是错误的。它们应该是 BTH_DEVICE_INFO_LIST Input; BTH_DEVICE_INFO_LIST Output;,然后以这种方式使用它们 &Input &Output。但是这个问题应该不会影响结果,只会占用更多的栈空间,没有意义。

  2. \InternalDeviceIoControl 我不确定这里的“\”是什么意思。

  3. Irp 可能是异步的,根据 the MSDN description,如果您将 NULL 传递给 Event 参数,您必须提供一个 IoCompletion 例程。

  4. MSDN 没有说 IoStatusBlock 参数允许 NULL,所以请始终传递一个指向 IO_STATUS_BLOCK 类型变量的指针。

  5. IoCallDriver 的返回值是多少? STATUS_PENDING 还是别的什么?

  6. (*PBLRI).numOfDevices 改为 PBLRI->numOfDevices 会更好。

您面临的错误很可能是由于第 3 点造成的,因此请考虑提供一个 IoCompletion 例程或传递一个已初始化的 KEVENT 变量,然后等待 Irp 完成。

相关问答

错误1:Request method ‘DELETE‘ not supported 错误还原:...
错误1:启动docker镜像时报错:Error response from daemon:...
错误1:private field ‘xxx‘ is never assigned 按Alt...
报错如下,通过源不能下载,最后警告pip需升级版本 Requirem...