Windows NT Driver >> C/C++ >> File
DO_DIRECT_IO(PIO)
參考資訊:
1. Source Code
DO_DIRECT_IO的概念就是直接Mapping User Buffer,然後Driver使用該Mapped的MDL(Memory Description List)操作,相較於DO_BUFFERED_IO,因為不須I/O Manager更新回User Buffer,因此,效率會比較好,而如果Driver會操作到DMA(Direct Memory Access)記憶體的話,不適用此方式,雖然司徒目前還沒有寫過DMA相關的Windows Driver,不過依據Microsoft的說明文件來看,使用DMA的話,必須使用另一個API(MmGetMdlVirtualAddress)去取得DMA實體記憶體位址,反之,如果不是DMA的操作,就是PIO(Programmed I/O)方式。
參考如下微軟的圖表說明(IRP_MJ_READ):
記憶體指標:
IRP | Buffer | Length |
---|---|---|
IRP_MJ_READ | (MDL) MmGetSystemAddressForMdlSafe |
(MDL) MmGetMdlByteCount |
IRP_MJ_WRITE | (MDL) MmGetSystemAddressForMdlSafe |
(MDL) MmGetMdlByteCount |
main.c
#include <wdm.h> #define DEV_NAME L"\\Device\\MyDriver" #define SYM_NAME L"\\DosDevices\\MyDriver" char szBuffer[255]={0}; void Unload(PDRIVER_OBJECT pOurDriver) { UNICODE_STRING usSymboName; RtlInitUnicodeString(&usSymboName, L"\\DosDevices\\MyDriver"); IoDeleteSymbolicLink(&usSymboName); IoDeleteDevice(pOurDriver->DeviceObject); } NTSTATUS IrpFile(PDEVICE_OBJECT pOurDevice, PIRP pIrp) { PUCHAR pBuf; PIO_STACK_LOCATION psk = IoGetCurrentIrpStackLocation(pIrp); switch(psk->MajorFunction){ case IRP_MJ_CREATE: memset(szBuffer, 0, sizeof(szBuffer)); DbgPrint("IRP_MJ_CREATE"); break; case IRP_MJ_READ: pBuf = MmGetSystemAddressForMdlSafe(pIrp->MdlAddress, LowPagePriority); strcpy(pBuf, szBuffer); DbgPrint("IRP_MJ_READ"); pIrp->IoStatus.Status = STATUS_SUCCESS; pIrp->IoStatus.Information = strlen(szBuffer)+1; break; case IRP_MJ_WRITE: pBuf = MmGetSystemAddressForMdlSafe(pIrp->MdlAddress, LowPagePriority); strcpy(szBuffer, pBuf); DbgPrint("IRP_MJ_WRITE"); DbgPrint("Buffer: %s, Length: %d", szBuffer, psk->Parameters.Write.Length); pIrp->IoStatus.Status = STATUS_SUCCESS; pIrp->IoStatus.Information = strlen(szBuffer)+1; break; case IRP_MJ_CLOSE: DbgPrint("IRP_MJ_CLOSE"); break; } IoCompleteRequest(pIrp, IO_NO_INCREMENT); return STATUS_SUCCESS; } NTSTATUS DriverEntry(PDRIVER_OBJECT pOurDriver, PUNICODE_STRING pOurRegistry) { PDEVICE_OBJECT pOurDevice=NULL; UNICODE_STRING usDeviceName; UNICODE_STRING usSymboName; pOurDriver->MajorFunction[IRP_MJ_CREATE] = pOurDriver->MajorFunction[IRP_MJ_READ] = pOurDriver->MajorFunction[IRP_MJ_WRITE] = pOurDriver->MajorFunction[IRP_MJ_CLOSE] = IrpFile; pOurDriver->DriverUnload = Unload; RtlInitUnicodeString(&usDeviceName, L"\\Device\\MyDriver"); IoCreateDevice(pOurDriver, 0, &usDeviceName, FILE_DEVICE_UNKNOWN, 0, FALSE, &pOurDevice); RtlInitUnicodeString(&usSymboName, L"\\DosDevices\\MyDriver"); IoCreateSymbolicLink(&usSymboName, &usDeviceName); pOurDevice->Flags&= ~DO_DEVICE_INITIALIZING; pOurDevice->Flags|= DO_DIRECT_IO; return STATUS_SUCCESS; }
IrpFile()收到IRP_MJ_WRITE時,Driver複製User Buffer的內容到szBuffer,而收到IRP_MJ_READ時,將szBuffer內容又複製回User Buffer,完成暫存的功能,IoStatus.Information的數值就是ReadFile()或WriteFile()完成的長度。
app.cpp
#define INITGUID #include <windows.h> #include <strsafe.h> #include <setupapi.h> #include <stdio.h> #include <stdlib.h> int __cdecl main(int argc, char* argv[]) { HANDLE hFile = NULL; DWORD dwRet = 0; char szBuffer[255]={0}; hFile = CreateFile("\\\\.\\MyDriver", GENERIC_READ | GENERIC_WRITE, 0, NULL, OPEN_EXISTING, 0, NULL); if(hFile == INVALID_HANDLE_VALUE){ printf("failed to open mydriver"); return 1; } strncpy(szBuffer, "I am error", sizeof(szBuffer)); WriteFile(hFile, szBuffer, strlen(szBuffer) + 1, &dwRet, NULL); printf("WR: %s, %d\n", szBuffer, dwRet); memset(szBuffer, 0, sizeof(szBuffer)); ReadFile(hFile, szBuffer, sizeof(szBuffer), &dwRet, NULL); printf("RD: %s, %d\n", szBuffer, dwRet); CloseHandle(hFile); return 0; }
結果