You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

KMDF 1.11中如何获取发起EvtIoDeviceControl请求的进程ID?

Getting Requestor Process ID in KMDF 1.11 (Before WdfRequestGetRequestorProcessId)

Got it, let's break this down. The WdfRequestGetRequestorProcessId() API wasn't added until KMDF 1.15, so it's no surprise you can't find it in 1.11. But don't worry—you can still get the requesting process ID by directly accessing the underlying IRP structure that KMDF wraps. Here's a safe, compatible way to do it in your EvtIoDeviceControlCallback:

Step-by-Step Implementation

  • First, retrieve the raw IRP from the WDF request using WdfRequestGetIoRequestPacket(). This gives you access to the native I/O request structure.
  • Extract the ETHREAD pointer from the IRP's Tail.Overlay.Thread field—this points to the thread that initiated the request.
  • Use the kernel API PsGetThreadProcessId() to get the process ID associated with that thread.

Example Code

NTSTATUS EvtIoDeviceControlCallback(
    WDFQUEUE Queue,
    WDFREQUEST Request,
    size_t OutputBufferLength,
    size_t InputBufferLength,
    ULONG IoControlCode
)
{
    NTSTATUS status = STATUS_SUCCESS;
    PIRP irp = WdfRequestGetIoRequestPacket(Request);

    if (!irp) {
        status = STATUS_INVALID_PARAMETER;
        WdfRequestComplete(Request, status);
        return status;
    }

    // Get the thread that sent the request
    PETHREAD requestingThread = irp->Tail.Overlay.Thread;
    if (!requestingThread) {
        status = STATUS_INVALID_PARAMETER;
        WdfRequestComplete(Request, status);
        return status;
    }

    // Retrieve the process ID from the thread
    HANDLE requestorPidHandle = PsGetThreadProcessId(requestingThread);
    ULONG requestorPid = (ULONG)requestorPidHandle;

    // Use the PID in your logic here...
    DbgPrint("Request from process ID: %lu\n", requestorPid);

    WdfRequestComplete(Request, status);
    return status;
}

Key Notes

  • Header Requirements: Make sure you include ntddk.h (for PsGetThreadProcessId()) alongside your KMDF headers (wdf.h) to avoid compilation errors.
  • Safety: Accessing irp->Tail.Overlay.Thread is safe within the context of your EvtIoDeviceControlCallback—KMDF guarantees the request (and thus the IRP) is valid while the callback is executing.
  • Compatibility: This approach works across all KMDF versions back to 1.0, since WdfRequestGetIoRequestPacket() and PsGetThreadProcessId() have been available for a long time.

This is essentially what WdfRequestGetRequestorProcessId() does under the hood in newer KMDF versions—you're just bypassing the KMDF wrapper to get the same information directly.

内容的提问来源于stack exchange,提问作者ImDevinC

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 03:44:06