The free OSR Learning Library has more than 50 articles on a wide variety of topics about writing and debugging device drivers and Minifilters. From introductory level to advanced. All the articles have been recently reviewed and updated, and are written using the clear and definitive style you've come to expect from OSR over the years.
Check out The OSR Learning Library at: https://www.osr.com/osr-learning-library/
Hello! Can anybody, please help me with my problem.
I decided to write a driver that will map zero virtual address to 0 physical page. To do this, I wrote dword 0x00000001 to VA 0xC0000000. After it, i check result:
kd> dd 0xC0000000
c0000000 00000001 00000000 00000000 00000000
kd> !pte 0
PDE at C0300000 PTE at C0000000
contains 2FA62867 contains 00000001
pfn 2fa62 ---DA--UWEV pfn 0 -------KREV
kd> !db 0
check VA 0:
kd> db 0
everything works in the kernel debugger. Now 0 VA is mapped to 0 physical address. I get the same result if I attach to program through the user mode debugger in guest vm. Its mean, that it work! But this only works in the debuggers, because, after that, when my program tries to read 0 and to get 0x53, it throws an exception, although now it should not be.
Tell me, please, what could be the problem? Could it be TLB? How i can view tlb from windbg?
P.S I'm testing on a Windows 7 x86 without PAF, for simplicity.
UPD: i solv it. I forget to set U/S fkag
|Upcoming OSR Seminars|
|OSR has suspended in-person seminars due to the Covid-19 outbreak. But, don't miss your training! Attend via the internet instead!|
|Kernel Debugging||30 January 2023||Live, Online|
|Developing Minifilters||20 March 2023||Live, Online|
|Internals & Software Drivers||17 April 2023||Live, Online|
|Writing WDF Drivers||22 May 2023||Live, Online|