You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

判断文件是否存在打开的文件映射——有无更简洁的实现方法?

Checking for Active File Mappings/Views on an Open File

Great question! The SetEndOfFile workaround works, but it's definitely clunky—modifying the file just to check its state feels like a hack. Here are a couple cleaner, non-intrusive approaches:

1. Enumerate System Handles with NtQuerySystemInformation

This method lets you inspect all active handles in the system to see if any are section objects (the kernel-level objects behind file mappings) linked to your target file. Here's a high-level breakdown:

  • Call NtQuerySystemInformation with the SystemHandleInformation class to get a list of all system handles.
  • For each handle, resolve which process it belongs to, then use NtQueryObject to check if the handle is a Section object.
  • For section handles, query their underlying file object (using NtQuerySection with SectionBasicInformation) and compare it to your target file's handle/information.

While this requires a bit more code, it's non-intrusive (no file modifications) and gives you precise details about existing mappings. Note that you'll need the SE_DEBUG_NAME privilege to inspect handles from other processes.

2. Use GetFileInformationByHandleEx with FileProcessIdsUsingFileInformation

First, use GetFileInformationByHandleEx with the FileProcessIdsUsingFileInformation flag to get all processes that have the file open. Then, for each process:

  • Enumerate its handles (again using NtQuerySystemInformation for precision).
  • Check if any of those handles are section objects tied to your file.

This narrows down the processes you need to inspect, making the enumeration faster than scanning every handle in the system.

3. Lightweight Alternative: SetFileValidData (Still Intrusive, But Faster)

If you don't mind a minor system call that doesn't actually modify the file's content (unlike SetEndOfFile), you can use SetFileValidData. This API attempts to mark a range of the file as valid, and it will fail with ERROR_USER_MAPPED_FILE if there are active mappings. The catch? You need administrative privileges to call it, and it still touches file metadata.

Quick Comparison

MethodIntrusive?Privileges NeededComplexity
SetEndOfFileYes (temporarily modifies file size)NoneLow
NtQuerySystemInformation EnumerationNoSE_DEBUG_NAMEMedium
SetFileValidDataMinimal (metadata only)AdminLow

For most cases, the handle enumeration method is the cleanest long-term solution—even if it requires a bit more code, it avoids touching the file entirely and gives you full visibility into what's mapping it.

内容的提问来源于stack exchange,提问作者H. Arlinghaus

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:19:23