KMDF 1.11中如何获取发起EvtIoDeviceControl请求的进程ID?
Getting Requestor Process ID in KMDF 1.11 (Before
WdfRequestGetRequestorProcessId) Got it, let's break this down. The WdfRequestGetRequestorProcessId() API wasn't added until KMDF 1.15, so it's no surprise you can't find it in 1.11. But don't worry—you can still get the requesting process ID by directly accessing the underlying IRP structure that KMDF wraps. Here's a safe, compatible way to do it in your EvtIoDeviceControlCallback:
Step-by-Step Implementation
- First, retrieve the raw IRP from the WDF request using
WdfRequestGetIoRequestPacket(). This gives you access to the native I/O request structure. - Extract the ETHREAD pointer from the IRP's
Tail.Overlay.Threadfield—this points to the thread that initiated the request. - Use the kernel API
PsGetThreadProcessId()to get the process ID associated with that thread.
Example Code
NTSTATUS EvtIoDeviceControlCallback( WDFQUEUE Queue, WDFREQUEST Request, size_t OutputBufferLength, size_t InputBufferLength, ULONG IoControlCode ) { NTSTATUS status = STATUS_SUCCESS; PIRP irp = WdfRequestGetIoRequestPacket(Request); if (!irp) { status = STATUS_INVALID_PARAMETER; WdfRequestComplete(Request, status); return status; } // Get the thread that sent the request PETHREAD requestingThread = irp->Tail.Overlay.Thread; if (!requestingThread) { status = STATUS_INVALID_PARAMETER; WdfRequestComplete(Request, status); return status; } // Retrieve the process ID from the thread HANDLE requestorPidHandle = PsGetThreadProcessId(requestingThread); ULONG requestorPid = (ULONG)requestorPidHandle; // Use the PID in your logic here... DbgPrint("Request from process ID: %lu\n", requestorPid); WdfRequestComplete(Request, status); return status; }
Key Notes
- Header Requirements: Make sure you include
ntddk.h(forPsGetThreadProcessId()) alongside your KMDF headers (wdf.h) to avoid compilation errors. - Safety: Accessing
irp->Tail.Overlay.Threadis safe within the context of yourEvtIoDeviceControlCallback—KMDF guarantees the request (and thus the IRP) is valid while the callback is executing. - Compatibility: This approach works across all KMDF versions back to 1.0, since
WdfRequestGetIoRequestPacket()andPsGetThreadProcessId()have been available for a long time.
This is essentially what WdfRequestGetRequestorProcessId() does under the hood in newer KMDF versions—you're just bypassing the KMDF wrapper to get the same information directly.
内容的提问来源于stack exchange,提问作者ImDevinC
相关产品推荐
相关产品推荐

