驅動程式 - Windows Driver Model (WDM) - 使用範例 - C/C++ (DDK) - Use Thread



參考資訊:
https://wasm.in/
http://four-f.narod.ru/
https://github.com/steward-fu/ddk

main.c

#include <wdm.h>
 
#define IOCTL_START CTL_CODE(FILE_DEVICE_UNKNOWN, 0x800, METHOD_BUFFERED, FILE_ANY_ACCESS)
#define IOCTL_STOP  CTL_CODE(FILE_DEVICE_UNKNOWN, 0x801, METHOD_BUFFERED, FILE_ANY_ACCESS)
 
#define DEV_NAME L"\\Device\\MyDriver"
#define SYM_NAME L"\\DosDevices\\MyDriver"
 
PVOID pThread = NULL;
volatile BOOLEAN bExit = FALSE;
PDEVICE_OBJECT pNextDevice = NULL;
 
VOID MyThread(PVOID pParam)
{
    LARGE_INTEGER stTime;
 
    stTime.HighPart |= -1;
    stTime.LowPart = -10000000;
    DbgPrint("Current process: %s", (char*)((ULONG)IoGetCurrentProcess() + 0x174));
    while (bExit != TRUE) {
        KeDelayExecutionThread(KernelMode, FALSE, &stTime);
        DbgPrint("Sleep 1s");
    }
    DbgPrint("Exit MyThread");
    PsTerminateSystemThread(STATUS_SUCCESS);
}
 
NTSTATUS AddDevice(PDRIVER_OBJECT pMyDriver, PDEVICE_OBJECT pPhyDevice)
{
    PDEVICE_OBJECT pMyDevice = NULL;
    UNICODE_STRING usDeviceName = { 0 };
    UNICODE_STRING usSymbolName = { 0 };
 
    RtlInitUnicodeString(&usDeviceName, DEV_NAME);
    IoCreateDevice(pMyDriver, 0, &usDeviceName, FILE_DEVICE_UNKNOWN, 0, FALSE, &pMyDevice);
    RtlInitUnicodeString(&usSymbolName, SYM_NAME);
    IoCreateSymbolicLink(&usSymbolName, &usDeviceName);
    pNextDevice = IoAttachDeviceToDeviceStack(pMyDevice, pPhyDevice);
    pMyDevice->Flags &= ~DO_DEVICE_INITIALIZING;
    pMyDevice->Flags |= DO_BUFFERED_IO;
    return STATUS_SUCCESS;
}
 
void Unload(PDRIVER_OBJECT pMyDriver)
{
    pMyDriver = pMyDriver;
}
 
NTSTATUS IrpPnp(PDEVICE_OBJECT pMyDevice, PIRP pIrp)
{
    UNICODE_STRING usSymbolName = { 0 };
    PIO_STACK_LOCATION pStack = IoGetCurrentIrpStackLocation(pIrp);
 
    if (pStack->MinorFunction == IRP_MN_REMOVE_DEVICE) {
        RtlInitUnicodeString(&usSymbolName, SYM_NAME);
        IoDeleteSymbolicLink(&usSymbolName);
        IoDetachDevice(pNextDevice);
        IoDeleteDevice(pMyDevice);
        IoCompleteRequest(pIrp, IO_NO_INCREMENT);
        return STATUS_SUCCESS;
    }
    IoSkipCurrentIrpStackLocation(pIrp);
    return IoCallDriver(pNextDevice, pIrp);
}
 
NTSTATUS IrpIOCTL(PDEVICE_OBJECT pMyDevice, PIRP pIrp)
{
    HANDLE hThread = NULL;
    NTSTATUS status = STATUS_SUCCESS;
    PIO_STACK_LOCATION pStack = IoGetCurrentIrpStackLocation(pIrp);
 
    switch (pStack->Parameters.DeviceIoControl.IoControlCode) {
    case IOCTL_START:
        DbgPrint("IOCTL_START");
        bExit = FALSE;
         
        // User Thread
        status = PsCreateSystemThread(&hThread, THREAD_ALL_ACCESS, NULL, (PHANDLE)-1, NULL, MyThread, (PVOID)pMyDevice);
         
        // System Thread
        //status = PsCreateSystemThread(&hThread, THREAD_ALL_ACCESS, NULL, NULL, NULL, MyThread, pMyDevice);
         
        if (status == STATUS_SUCCESS) {
            ObReferenceObjectByHandle(hThread, THREAD_ALL_ACCESS, NULL, KernelMode, &pThread, NULL);
            ZwClose(hThread);
        }
        break;
    case IOCTL_STOP:
        DbgPrint("IOCTL_STOP");
        bExit = TRUE;
        if (pThread != NULL) {
            KeWaitForSingleObject(pThread, Executive, KernelMode, FALSE, NULL);
            ObDereferenceObject(pThread);
        }
        break;
    }
    pIrp->IoStatus.Information = 0;
    pIrp->IoStatus.Status = STATUS_SUCCESS;
    IoCompleteRequest(pIrp, IO_NO_INCREMENT);
    return STATUS_SUCCESS;
}
 
NTSTATUS IrpFile(PDEVICE_OBJECT pMyDevice, PIRP pIrp)
{
    PIO_STACK_LOCATION pStack = IoGetCurrentIrpStackLocation(pIrp);
 
    switch (pStack->MajorFunction) {
    case IRP_MJ_CREATE:
        DbgPrint("IRP_MJ_CREATE");
        break;
    case IRP_MJ_CLOSE:
        DbgPrint("IRP_MJ_CLOSE");
        break;
    }
    IoCompleteRequest(pIrp, IO_NO_INCREMENT);
    return STATUS_SUCCESS;
}

NTSTATUS DriverEntry(PDRIVER_OBJECT pMyDriver, PUNICODE_STRING pMyRegistry)
{
    pMyDriver->MajorFunction[IRP_MJ_PNP]            = IrpPnp;
    pMyDriver->MajorFunction[IRP_MJ_CREATE]         = IrpFile;
    pMyDriver->MajorFunction[IRP_MJ_CLOSE]          = IrpFile;
    pMyDriver->MajorFunction[IRP_MJ_DEVICE_CONTROL] = IrpIOCTL;
    pMyDriver->DriverExtension->AddDevice = AddDevice;
    pMyDriver->DriverUnload = Unload;
    return STATUS_SUCCESS;
}

app.c

#include <windows.h>
#include <winioctl.h>
#include <stdio.h>
#include <stdlib.h>
 
#define IOCTL_START CTL_CODE(FILE_DEVICE_UNKNOWN, 0x800, METHOD_BUFFERED, FILE_ANY_ACCESS)
#define IOCTL_STOP  CTL_CODE(FILE_DEVICE_UNKNOWN, 0x801, METHOD_BUFFERED, FILE_ANY_ACCESS)
 
int main(int argc, char **argv)
{
    DWORD dwRet = 0;
    HANDLE hFile = NULL;
 
    hFile = CreateFile("\\\\.\\MyDriver", GENERIC_READ | GENERIC_WRITE, 0, NULL, OPEN_EXISTING, 0, NULL);
    DeviceIoControl(hFile, IOCTL_START, NULL, 0, NULL, 0, &dwRet, NULL);
    Sleep(3000);
    DeviceIoControl(hFile, IOCTL_STOP, NULL, 0, NULL, 0, &dwRet, NULL);
    CloseHandle(hFile);
    return 0;
}

完成