參考資訊:
https://wasm.in/
http://four-f.narod.ru/
https://github.com/steward-fu/ddk
main.c
#include <wdm.h>
#define DEV_NAME L"\\Device\\MyDriver"
#define SYM_NAME L"\\DosDevices\\MyDriver"
#define IOCTL_TEST CTL_CODE(FILE_DEVICE_UNKNOWN, 0x800, METHOD_BUFFERED, FILE_ANY_ACCESS)
PDEVICE_OBJECT pNextDevice = NULL;
NTSTATUS AddDevice(PDRIVER_OBJECT pMyDriver, PDEVICE_OBJECT pPhyDevice)
{
PDEVICE_OBJECT pMyDevice = NULL;
UNICODE_STRING usSymbolName = { 0 };
UNICODE_STRING usDeviceName = { 0 };
RtlInitUnicodeString(&usDeviceName, DEV_NAME);
IoCreateDevice(pMyDriver, 0, &usDeviceName, FILE_DEVICE_UNKNOWN, 0, FALSE, &pMyDevice);
RtlInitUnicodeString(&usSymbolName, SYM_NAME);
IoCreateSymbolicLink(&usSymbolName, &usDeviceName);
pNextDevice = IoAttachDeviceToDeviceStack(pMyDevice, pPhyDevice);
pMyDevice->Flags &= ~DO_DEVICE_INITIALIZING;
pMyDevice->Flags |= DO_BUFFERED_IO;
return STATUS_SUCCESS;
}
void Unload(PDRIVER_OBJECT pMyDriver)
{
}
NTSTATUS IrpPnp(PDEVICE_OBJECT pMyDevice, PIRP pIrp)
{
UNICODE_STRING usSymbolName = { 0 };
PIO_STACK_LOCATION pStack = IoGetCurrentIrpStackLocation(pIrp);
if (pStack->MinorFunction == IRP_MN_REMOVE_DEVICE) {
RtlInitUnicodeString(&usSymbolName, SYM_NAME);
IoDeleteSymbolicLink(&usSymbolName);
IoDetachDevice(pNextDevice);
IoDeleteDevice(pMyDevice);
IoCompleteRequest(pIrp, IO_NO_INCREMENT);
return STATUS_SUCCESS;
}
IoSkipCurrentIrpStackLocation(pIrp);
return IoCallDriver(pNextDevice, pIrp);
}
NTSTATUS IrpIOCTL(PDEVICE_OBJECT pMyDevice, PIRP pIrp)
{
PIO_STACK_LOCATION pStack = IoGetCurrentIrpStackLocation(pIrp);
switch (pStack->Parameters.DeviceIoControl.IoControlCode) {
case IOCTL_TEST:
DbgPrint("IOCTL_TEST");
break;
}
IoCompleteRequest(pIrp, IO_NO_INCREMENT);
return STATUS_SUCCESS;
}
NTSTATUS IrpFile(PDEVICE_OBJECT pMyDevice, PIRP pIrp)
{
PIO_STACK_LOCATION pStack = IoGetCurrentIrpStackLocation(pIrp);
switch (pStack->MajorFunction) {
case IRP_MJ_CREATE:
DbgPrint("IRP_MJ_CREATE");
break;
case IRP_MJ_CLOSE:
DbgPrint("IRP_MJ_CLOSE");
break;
}
IoCompleteRequest(pIrp, IO_NO_INCREMENT);
return STATUS_SUCCESS;
}
NTSTATUS DriverEntry(PDRIVER_OBJECT pMyDriver, PUNICODE_STRING pMyRegistry)
{
pMyDriver->MajorFunction[IRP_MJ_PNP] = IrpPnp;
pMyDriver->MajorFunction[IRP_MJ_CREATE] = IrpFile;
pMyDriver->MajorFunction[IRP_MJ_CLOSE] = IrpFile;
pMyDriver->MajorFunction[IRP_MJ_DEVICE_CONTROL] = IrpIOCTL;
pMyDriver->DriverExtension->AddDevice = AddDevice;
pMyDriver->DriverUnload = Unload;
return STATUS_SUCCESS;
}
app.c
#include <windows.h>
#include <winioctl.h>
#include <stdio.h>
#include <stdlib.h>
#define IOCTL_TEST CTL_CODE(FILE_DEVICE_UNKNOWN, 0x800, METHOD_BUFFERED, FILE_ANY_ACCESS)
#define IOCTL_GET_BUF CTL_CODE(FILE_DEVICE_UNKNOWN, 0x800, METHOD_BUFFERED, FILE_ANY_ACCESS)
#define IOCTL_SET_BUF CTL_CODE(FILE_DEVICE_UNKNOWN, 0x801, METHOD_BUFFERED, FILE_ANY_ACCESS)
#define IOCTL_GET_DIR CTL_CODE(FILE_DEVICE_UNKNOWN, 0x800, METHOD_OUT_DIRECT, FILE_ANY_ACCESS)
#define IOCTL_SET_DIR CTL_CODE(FILE_DEVICE_UNKNOWN, 0x801, METHOD_IN_DIRECT, FILE_ANY_ACCESS)
#define IOCTL_GET_NEI CTL_CODE(FILE_DEVICE_UNKNOWN, 0x800, METHOD_NEITHER, FILE_ANY_ACCESS)
#define IOCTL_SET_NEI CTL_CODE(FILE_DEVICE_UNKNOWN, 0x801, METHOD_NEITHER, FILE_ANY_ACCESS)
int main(int argc, char **argv)
{
DWORD dwRet = 0;
HANDLE hFile = NULL;
char szBuffer[255] = { "I am error" };
hFile = CreateFile("\\\\.\\MyDriver", GENERIC_READ | GENERIC_WRITE, 0, NULL, OPEN_EXISTING, 0, NULL);
if (argc > 1) {
dwRet = strlen(szBuffer);
printf("SET: %s, %d\n", szBuffer, dwRet);
if (!strcmp(argv[1], "BUF")) {
DeviceIoControl(hFile, IOCTL_SET_BUF, szBuffer, dwRet, NULL, 0, &dwRet, NULL);
dwRet = 0;
memset(szBuffer, 0, sizeof(szBuffer));
DeviceIoControl(hFile, IOCTL_GET_BUF, NULL, 0, szBuffer, sizeof(szBuffer), &dwRet, NULL);
}
else if (!strcmp(argv[1], "DIR")) {
DeviceIoControl(hFile, IOCTL_SET_DIR, szBuffer, dwRet, NULL, 0, &dwRet, NULL);
dwRet = 0;
memset(szBuffer, 0, sizeof(szBuffer));
DeviceIoControl(hFile, IOCTL_GET_DIR, NULL, 0, szBuffer, sizeof(szBuffer), &dwRet, NULL);
}
else if (!strcmp(argv[1], "NEI")) {
DeviceIoControl(hFile, IOCTL_SET_NEI, szBuffer, dwRet, NULL, 0, &dwRet, NULL);
dwRet = 0;
memset(szBuffer, 0, sizeof(szBuffer));
DeviceIoControl(hFile, IOCTL_GET_NEI, NULL, 0, szBuffer, sizeof(szBuffer), &dwRet, NULL);
}
printf("GET: %s, %d\n", szBuffer, dwRet);
}
else {
DeviceIoControl(hFile, IOCTL_TEST, NULL, 0, NULL, 0, &dwRet, NULL);
}
CloseHandle(hFile);
return 0;
}
完成
