在MASM汇编文件中调用KeRaiseIrqlToDpcLevel遇未解析外部符号问题
问题描述
尝试调用KeRaiseIrqlToDpcLevel函数,根据微软文档,该函数位于hal.lib中,若不在则也会在ntoskrnl.lib中。已在代码中包含对应的.inc和.lib文件,却仍收到**"unresolved external symbol KeRaiseIrqlToDpcLevel referenced inside..."**错误。
汇编代码
INCLUDE C:\masm32\include\ntoskrnl.inc INCLUDE C:\masm32\include\hal.inc INCLUDELIB C:\masm32\lib\ntoskrnl.lib INCLUDELIB C:\masm32\lib\hal.lib EXTERN KeRaiseIrqlToDpcLevel:PROC PUBLIC TestFunction TestFunction PROC CALL KeRaiseIrqlToDpcLevel RET TestFunction ENDP END
VCXPROJ配置文件
<?xml version="1.0" encoding="utf-8"?> <Project DefaultTargets="Build" ToolsVersion="12.0" xmlns="http://schemas.microsoft.com/developer/msbuild/2003"> <ItemGroup Label="ProjectConfigurations"> <ProjectConfiguration Include="Debug|x64"> <Configuration>Debug</Configuration> <Platform>x64</Platform> </ProjectConfiguration> <ProjectConfiguration Include="Release|x64"> <Configuration>Release</Configuration> <Platform>x64</Platform> </ProjectConfiguration> </ItemGroup> <PropertyGroup Label="Globals"> <ProjectGuid>{96189790-291B-46B6-8818-C4716A65E93C}</ProjectGuid> <TemplateGuid>{1bc93793-694f-48fe-9372-81e2b05556fd}</TemplateGuid> <TargetFrameworkVersion>v4.5</TargetFrameworkVersion> <MinimumVisualStudioVersion>12.0</MinimumVisualStudioVersion> <Configuration>Debug</Configuration> <Platform Condition="'$(Platform)' == ''">x64</Platform> <RootNamespace>Necrobyte</RootNamespace> <WindowsTargetPlatformVersion>$(LatestTargetPlatformVersion)</WindowsTargetPlatformVersion> </PropertyGroup> <Import Project="$(VCTargetsPath)\Microsoft.Cpp.Default.props" /> <PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'" Label="Configuration"> <TargetVersion>Windows10</TargetVersion> <UseDebugLibraries>true</UseDebugLibraries> <PlatformToolset>WindowsKernelModeDriver10.0</PlatformToolset> <ConfigurationType>Driver</ConfigurationType> <DriverType>KMDF</DriverType> <DriverTargetPlatform>Universal</DriverTargetPlatform> </PropertyGroup> <PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'" Label="Configuration"> <TargetVersion>Windows10</TargetVersion> <UseDebugLibraries>false</UseDebugLibraries> <PlatformToolset>WindowsKernelModeDriver10.0</PlatformToolset> <ConfigurationType>Driver</ConfigurationType> <DriverType>KMDF</DriverType> <DriverTargetPlatform>Universal</DriverTargetPlatform> </PropertyGroup> <Import Project="$(VCTargetsPath)\Microsoft.Cpp.props" /> <ImportGroup Label="PropertySheets"> <Import Project="$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props" Condition="exists('$(UserRootDir)\Microsoft.Cpp.$(Platform).user.props')" Label="LocalAppDataPlatform" /> </ImportGroup> <PropertyGroup Label="UserMacros" /> <PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'"> <DebuggerFlavor>DbgengKernelDebugger</DebuggerFlavor> <OutDir>..\bin\</OutDir> <!--<IntDir>..\bin\$(Configuration)\Junk\</IntDir>--> </PropertyGroup> <PropertyGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'"> <DebuggerFlavor>DbgengKernelDebugger</DebuggerFlavor> <OutDir>..\bin\</OutDir> <!--<IntDir>..\bin\$(Configuration)\Junk\</IntDir>--> </PropertyGroup> <ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'"> <DriverSign> <FileDigestAlgorithm>sha256</FileDigestAlgorithm> </DriverSign> <Link> <AdditionalDependencies>$(DDK_LIB_PATH)ntoskrnl.lib;$(DDK_LIB_PATH)netio.lib;$(DDK_LIB_PATH)hal.lib;C:\Program Files (x86)\Windows Kits\10\Lib\10.0.22621.0\km\x64\hal.lib;%(AdditionalDependencies)</AdditionalDependencies> </Link> </ItemDefinitionGroup> <ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'"> <DriverSign> <FileDigestAlgorithm>sha256</FileDigestAlgorithm> </DriverSign> <Link> <AdditionalDependencies>$(DDK_LIB_PATH)ntoskrnl.lib;$(DDK_LIB_PATH)netio.lib;$(DDK_LIB_PATH)hal.lib;%(AdditionalDependencies)</AdditionalDependencies> </Link> </ItemDefinitionGroup> <ItemGroup> <FilesToPackage Include="$(TargetPath)" /> </ItemGroup> <ItemGroup> <ClCompile Include="..\src\**\*.c"/> </ItemGroup> <ItemGroup> <MASM Include="..\src\**\*.asm" /> </ItemGroup> <Import Project="$(VCTargetsPath)\Microsoft.Cpp.targets" /> </Project>
问题原因分析
- MASM32库文件不匹配:MASM32主要面向用户态程序,其提供的内核头文件和库与WDK(Windows驱动工具包)的内核态文件存在差异,可能导致符号名不匹配或函数未正确导出。
- 链接库路径与版本冲突:VCXPROJ中重复指定了多个
hal.lib路径,可能存在版本不兼容,导致链接器无法找到正确的符号。 - 汇编编译选项未适配内核态:未配置MASM使用内核态的编译参数,可能导致符号声明与库中的导出格式不一致。
解决方案
1. 替换为WDK官方头文件和库
修改汇编代码,使用WDK提供的内核态头文件与库(路径根据你的SDK版本调整):
INCLUDE "C:\Program Files (x86)\Windows Kits\10\Include\10.0.22621.0\km\ntoskrnl.inc" INCLUDE "C:\Program Files (x86)\Windows Kits\10\Include\10.0.22621.0\km\hal.inc" INCLUDELIB "C:\Program Files (x86)\Windows Kits\10\Lib\10.0.22621.0\km\x64\ntoskrnl.lib" INCLUDELIB "C:\Program Files (x86)\Windows Kits\10\Lib\10.0.22621.0\km\x64\hal.lib" EXTERN KeRaiseIrqlToDpcLevel:PROC PUBLIC TestFunction TestFunction PROC CALL KeRaiseIrqlToDpcLevel RET TestFunction ENDP END
2. 修正VCXPROJ链接配置
- 简化
AdditionalDependencies,依赖WDK自动路径:<AdditionalDependencies>ntoskrnl.lib;hal.lib;netio.lib;%(AdditionalDependencies)</AdditionalDependencies> - 添加MASM内核态编译配置:
<ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Debug|x64'"> <!-- 保留原有配置 --> <MASM> <IncludePath>$(DDK_INC_PATH);%(IncludePath)</IncludePath> <TargetMachine>X64</TargetMachine> </MASM> </ItemDefinitionGroup> <ItemDefinitionGroup Condition="'$(Configuration)|$(Platform)'=='Release|x64'"> <!-- 保留原有配置 --> <MASM> <IncludePath>$(DDK_INC_PATH);%(IncludePath)</IncludePath> <TargetMachine>X64</TargetMachine> </MASM> </ItemDefinitionGroup>
3. 验证库中的符号存在性
打开VS x64开发者命令提示符,使用dumpbin工具检查库是否包含目标符号:
dumpbin /exports "C:\Program Files (x86)\Windows Kits\10\Lib\10.0.22621.0\km\x64\hal.lib" | findstr KeRaiseIrqlToDpcLevel
若输出为空,检查ntoskrnl.lib:
dumpbin /exports "C:\Program Files (x86)\Windows Kits\10\Lib\10.0.22621.0\km\x64\ntoskrnl.lib" | findstr KeRaiseIrqlToDpcLevel
内容的提问来源于stack exchange,提问作者trapstar
相关产品推荐
相关产品推荐

