WinDBG内核调试仅偶尔启动问题排查求助
WinDBG内核调试连接不稳定问题排查
我遇到WinDBG内核调试并非每次启动都能正常运行的问题:约70%的启动次数中,WinDBG会先报告连接成功,但随即断开并显示Debuggee not connected。
相关观察信息
- 目标系统为Windows 11 22H2
- 两台机器均使用WinDBG
10.0.22621.755 - 通过命令
"C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\kdnet.exe" 192.168.2.1 50000配置内核调试 - 在目标机器上,使用建议的
windbg -k net:port=50000,key=...命令启动WinDBG - 多次重启目标计算机,未做任何更改,直到最终实现稳定连接
- WinDBG总会对目标计算机的启动做出反应并打印信息,但常常立即断开连接
- 如果调试器在Windows登录界面出现时仍保持连接,那么在重启被调试计算机前连接不会丢失
- 使用
WinDBG > Debug > Kernel connection > Cycle initial break无明显效果:连接失败时,WinDBG报告连接成功但不会中断,随后显示Debuggee not connected - 调试连接失败时,目标机器桌面右下角不会显示
Test Mode标识 - …但在设备管理器的网卡中仍能看到
This device has been reserved for use by Windows kernel debugger提示 - …且设备管理器中有时会出现
Microsoft Kernel Debug Network Adapter,有时则不会 - 使用
WinDBG > View > Verbose output未得到能解释断开原因的有效信息 - 从WinDBG先报告连接成功后显示
Debuggee not connected的情况来看,WinDBG知晓已断开连接,但未给出原因说明 - 连接失败时WinDBG的典型输出:
Verbose mode ON. Will breakin at next boot. Connected to target 192.168.2.2 on port 50000 on local IP 192.168.2.1. You can get the target MAC address by running .kdtargetmac command. - 两台机器均通过网线连接到同一路由器
- 根据SysInternals TCPView,调试器机器上仅有WinDBG监听端口50000
- Windows事件日志中未发现相关信息
- 已启用Windows启动日志并查看
C:\Windows\ntbtlog.txt,但未发现有效内容 - 尝试过
WinDBG > Debug > Break操作,但连接失败时该操作无效
问题
如何实现稳定连接?是否有高级日志可用于排查目标机器未启动调试的原因(我根据桌面右下角缺少Test Mode标识做出此判断)
更新1
kdnet命令输出:
Network debugging is supported on the following NICs: busparams=0.25.0, Intel(R) 82579LM Gigabit Network Connection, Plugged in.
既然调试偶尔能启动,说明网卡兼容,但问题是仅约15%的启动次数能成功。
你将调试器配置为在哪个阶段中断(虚拟机监控程序、加载器、启动阶段)?
我使用了WinDBG > Debug > Kernel connection > Cycle initial break。此前尝试未配置任何中断,希望手动执行WinDBG > Debug > Break,但同样无效。
当未显示Test Mode时,你是否查看过KD_DEBUGGER_ENABLED全局内核变量(需要在目标机器上使用Sysinternals的kd和livekd)?
(WinDBG) ? dwo(nt!KdDebuggerEnabled) Evaluate expression: 1 = 00000000`00000001
能否添加目标机器上
bcdedit /enum all的完整输出到帖子中?
Firmware Boot Manager --------------------- identifier {fwbootmgr} timeout 0 Windows Boot Manager -------------------- identifier {bootmgr} device partition=\Device\HarddiskVolume1 path \EFI\Microsoft\Boot\bootmgfw.efi description Windows Boot Manager locale en-US inherit {globalsettings} default {current} resumeobject {aec6b6dd-bb3f-11ed-b0ad-d89d67cb10b5} displayorder {current} {d073bfac-c76b-11ed-b0db-843a4b6e6260} toolsdisplayorder {memdiag} timeout 3 Firmware Application (101fffff) ------------------------------- identifier {01757582-bf6b-11ed-b0cb-806e6f6e6963} device unknown path \EFI\ubuntu\shimx64.efi description ubuntu Firmware Application (101fffff) ------------------------------- identifier {04035df6-879f-11ed-b02a-806e6f6e6963} device unknown path \EFI\ubuntu\shimx64.efi description ubuntu Firmware Application (101fffff) ------------------------------- identifier {18bd1575-766c-11ec-9f5b-806e6f6e6963} description Notebook Ethernet Firmware Application (101fffff) ------------------------------- identifier {18bd1576-766c-11ec-9f5b-806e6f6e6963} description Notebook Upgrade Bay Firmware Application (101fffff) ------------------------------- identifier {18bd1577-766c-11ec-9f5b-806e6f6e6963} description Notebook Hard Drive Firmware Application (101fffff) ------------------------------- identifier {342f29a6-2a3d-11ed-af4a-806e6f6e6963} description Notebook Ethernet Firmware Application (101fffff) ------------------------------- identifier {a0ec6830-4dfe-11ed-af97-806e6f6e6963} device unknown path \EFI\ubuntu\shimx64.efi description ubuntu Windows Boot Loader ------------------- identifier {8da16dbd-bb62-11ed-b0bb-d89d67cb10b5} device ramdisk=[E:]\Recovery\WindowsRE\Winre.wim,{8da16dbe-bb62-11ed-b0bb-d89d67cb10b5} path \windows\system32\winload.efi description Windows Recovery Environment locale en-US inherit {bootloadersettings} displaymessage Recovery osdevice ramdisk=[E:]\Recovery\WindowsRE\Winre.wim,{8da16dbe-bb62-11ed-b0bb-d89d67cb10b5} systemroot \windows nx OptIn bootmenupolicy Standard winpe Yes Windows Boot Loader ------------------- identifier {current} device partition=C: path \WINDOWS\system32\winload.efi description Windows 11 locale en-US inherit {bootloadersettings} recoverysequence {8da16dbd-bb62-11ed-b0bb-d89d67cb10b5} displaymessageoverride Recovery recoveryenabled Yes isolatedcontext Yes allowedinmemorysettings 0x15000075 osdevice partition=C: systemroot \WINDOWS resumeobject {aec6b6dd-bb3f-11ed-b0ad-d89d67cb10b5} nx OptIn bootmenupolicy Standard bootlog Yes debug Yes Windows Boot Loader ------------------- identifier {d073bfac-c76b-11ed-b0db-843a4b6e6260} device partition=C: path \WINDOWS\system32\winload.efi description Win11 + Hyper-V locale en-US inherit {bootloadersettings} recoverysequence {8da16dbd-bb62-11ed-b0bb-d89d67cb10b5} displaymessageoverride Recovery recoveryenabled Yes isolatedcontext Yes allowedinmemorysettings 0x15000075 osdevice partition=C: systemroot \WINDOWS resumeobject {aec6b6dd-bb3f-11ed-b0ad-d89d67cb10b5} nx OptIn bootmenupolicy Standard hypervisorlaunchtype Auto Resume from Hibernate --------------------- identifier {aec6b6dd-bb3f-11ed-b0ad-d89d67cb10b5} device partition=C: path \WINDOWS\system32\winresume.efi description Windows Resume Application locale en-US inherit {resumeloadersettings} recoverysequence {8da16dbd-bb62-11ed-b0bb-d89d67cb10b5} recoveryenabled Yes isolatedcontext Yes allowedinmemorysettings 0x15000075 filedevice partition=C: custom:21000026 partition=C: filepath \hiberfil.sys bootmenupolicy Standard debugoptionenabled Yes Windows Memory Tester --------------------- identifier {memdiag} device partition=\Device\HarddiskVolume1 path \EFI\Microsoft\Boot\memtest.efi description Windows Memory Diagnostic locale en-US inherit {globalsettings} badmemoryaccess Yes EMS Settings ------------ identifier {emssettings} bootems No Debugger Settings ----------------- identifier {dbgsettings} busparams 0.25.0 key <snip> debugtype NET hostip <snip> port 50000 dhcp Yes RAM Defects ----------- identifier {badmemory} Global Settings --------------- identifier {globalsettings} inherit {dbgsettings} {emssettings} {badmemory} Boot Loader Settings -------------------- identifier {bootloadersettings} inherit {globalsettings} {hypervisorsettings} Hypervisor Settings ------------------- identifier {hypervisorsettings} hypervisordebugtype Serial hypervisordebugport 1 hypervisorbaudrate 115200 Resume Loader Settings ---------------------- identifier {resumeloadersettings} inherit {globalsettings} Device options -------------- identifier {8da16dbe-bb62-11ed-b0bb-d89d67cb10b5} description Windows Recovery ramdisksdidevice partition=E: ramdisksdipath \Recovery\WindowsRE\boot.sdi
内容的提问来源于stack exchange,提问作者Codeguard
相关产品推荐
相关产品推荐

