我在调试一个进程阻塞的时候,发现它阻塞在WriteFile那里,我用userdump把进程给dump出来,用windbg分析,只能得到handle和buffer等信息,但无法确认是哪个文件。
1、打印堆栈
0:019> kvChildEBP RetAddr Args to Child 583cb07c 7c827d3b 77e65598 00000120 00000000 ntdll!KiFastSystemCallRet (FPO: [0,0,0])583cb080 77e65598 00000120 00000000 00000000 ntdll!NtWriteFile+0xc (FPO: [9,0,0])583cb0e0 6d3d4ab3 00000120 583cb124 000000d1 kernel32!WriteFile+0xf7 (FPO: [Non-Fpo])WARNING: Stack unwind information not available. Following frames may be wrong.583cb100 6d3d442a 00000120 00000000 583cb124 java_6d3d0000!handleWrite+0x23583cd130 6d3d20ba 57214114 583cd1bc 583cd1b8 java_6d3d0000!VerifyClassCodesForMajorVersion+0x367583cd158 0093a27e 00214114 583cd1bc 583cd1b8 java_6d3d0000!Java_java_io_FileOutputStream_writeBytes+0x97
2、查看120这个handle
0:019> !handle 120 fHandle 00000120 Type File Attributes 0 GrantedAccess 0x120196: ReadControl,Synch Write/Add,Append/SubDir/CreatePipe,WriteEA,ReadAttr,WriteAttr HandleCount 2 PointerCount 5 No object specific information available
但我怎么获取这个handle到底指向哪个文件,另外由于情况特殊,无法动态调试,只能在死锁的时候dump出来,而且很不容易复现。