Windows NT Driver >> C/C++ >> File

DO_DIRECT_IO(PIO)


參考資訊:
1. Source Code

DO_DIRECT_IO的概念就是直接Mapping User Buffer,然後Driver使用該Mapped的MDL(Memory Description List)操作,相較於DO_BUFFERED_IO,因為不須I/O Manager更新回User Buffer,因此,效率會比較好,而如果Driver會操作到DMA(Direct Memory Access)記憶體的話,不適用此方式,雖然司徒目前還沒有寫過DMA相關的Windows Driver,不過依據Microsoft的說明文件來看,使用DMA的話,必須使用另一個API(MmGetMdlVirtualAddress)去取得DMA實體記憶體位址,反之,如果不是DMA的操作,就是PIO(Programmed I/O)方式。

參考如下微軟的圖表說明(IRP_MJ_READ):

記憶體指標:

IRP Buffer Length
IRP_MJ_READ (MDL)
MmGetSystemAddressForMdlSafe
(MDL)
MmGetMdlByteCount
IRP_MJ_WRITE (MDL)
MmGetSystemAddressForMdlSafe
(MDL)
MmGetMdlByteCount

main.c

#include <wdm.h>

#define DEV_NAME L"\\Device\\MyDriver"
#define SYM_NAME L"\\DosDevices\\MyDriver"

char szBuffer[255]={0};

void Unload(PDRIVER_OBJECT pOurDriver)
{
  UNICODE_STRING usSymboName;
    
  RtlInitUnicodeString(&usSymboName, L"\\DosDevices\\MyDriver");
  IoDeleteSymbolicLink(&usSymboName);
  IoDeleteDevice(pOurDriver->DeviceObject);
}

NTSTATUS IrpFile(PDEVICE_OBJECT pOurDevice, PIRP pIrp)
{
  PUCHAR pBuf;
  PIO_STACK_LOCATION psk = IoGetCurrentIrpStackLocation(pIrp);

  switch(psk->MajorFunction){
  case IRP_MJ_CREATE:
    memset(szBuffer, 0, sizeof(szBuffer));
    DbgPrint("IRP_MJ_CREATE");
    break;
  case IRP_MJ_READ:
    pBuf = MmGetSystemAddressForMdlSafe(pIrp->MdlAddress, LowPagePriority);
    strcpy(pBuf, szBuffer);
    DbgPrint("IRP_MJ_READ");
    pIrp->IoStatus.Status = STATUS_SUCCESS;
    pIrp->IoStatus.Information = strlen(szBuffer)+1;
    break;
  case IRP_MJ_WRITE:
    pBuf = MmGetSystemAddressForMdlSafe(pIrp->MdlAddress, LowPagePriority);
    strcpy(szBuffer, pBuf);
    DbgPrint("IRP_MJ_WRITE");
    DbgPrint("Buffer: %s, Length: %d", szBuffer, psk->Parameters.Write.Length);
    pIrp->IoStatus.Status = STATUS_SUCCESS;
    pIrp->IoStatus.Information = strlen(szBuffer)+1;
    break;
  case IRP_MJ_CLOSE:
    DbgPrint("IRP_MJ_CLOSE");
    break;
  }
  IoCompleteRequest(pIrp, IO_NO_INCREMENT);
  return STATUS_SUCCESS;
}

NTSTATUS DriverEntry(PDRIVER_OBJECT pOurDriver, PUNICODE_STRING pOurRegistry)
{
  PDEVICE_OBJECT pOurDevice=NULL;
  UNICODE_STRING usDeviceName;
  UNICODE_STRING usSymboName;
  
  pOurDriver->MajorFunction[IRP_MJ_CREATE] =
  pOurDriver->MajorFunction[IRP_MJ_READ] =
  pOurDriver->MajorFunction[IRP_MJ_WRITE] =
  pOurDriver->MajorFunction[IRP_MJ_CLOSE] = IrpFile;
  pOurDriver->DriverUnload = Unload;
    
  RtlInitUnicodeString(&usDeviceName, L"\\Device\\MyDriver");
  IoCreateDevice(pOurDriver, 0, &usDeviceName, FILE_DEVICE_UNKNOWN, 0, FALSE, &pOurDevice);
  RtlInitUnicodeString(&usSymboName, L"\\DosDevices\\MyDriver");
  IoCreateSymbolicLink(&usSymboName, &usDeviceName);
  pOurDevice->Flags&= ~DO_DEVICE_INITIALIZING;
  pOurDevice->Flags|= DO_DIRECT_IO;
  return STATUS_SUCCESS;
}

IrpFile()收到IRP_MJ_WRITE時,Driver複製User Buffer的內容到szBuffer,而收到IRP_MJ_READ時,將szBuffer內容又複製回User Buffer,完成暫存的功能,IoStatus.Information的數值就是ReadFile()或WriteFile()完成的長度。

app.cpp

#define INITGUID
#include <windows.h>
#include <strsafe.h>
#include <setupapi.h>
#include <stdio.h>
#include <stdlib.h>

int __cdecl main(int argc, char* argv[])
{
  HANDLE hFile = NULL;
  DWORD dwRet = 0;
  char szBuffer[255]={0};

  hFile = CreateFile("\\\\.\\MyDriver", GENERIC_READ | GENERIC_WRITE, 0, NULL, OPEN_EXISTING, 0, NULL);
  if(hFile == INVALID_HANDLE_VALUE){
    printf("failed to open mydriver");
    return 1;
  }

  strncpy(szBuffer, "I am error", sizeof(szBuffer));
  WriteFile(hFile, szBuffer, strlen(szBuffer) + 1, &dwRet, NULL);
  printf("WR: %s, %d\n", szBuffer, dwRet);

  memset(szBuffer, 0, sizeof(szBuffer));
  ReadFile(hFile, szBuffer, sizeof(szBuffer), &dwRet, NULL);
  printf("RD: %s, %d\n", szBuffer, dwRet);
  CloseHandle(hFile);
  return 0;
}

結果


返回上一頁