Advanced Debugging
About AdvDbg Consult Train Services Products Tools Community Contact  
欢迎光临 高端调试 登录 | 注册 | FAQ
 
  ACPI调试
Linux内核调试
Windows内核调试
 
  调试战役
调试原理
新工具观察
 
  Linux
Windows Vista
Windows
 
  Linux驱动
WDF
WDM
 
  PCI Express
PCI/PCI-X
USB
无线通信协议
 
  64位CPU
ARM
IA-32
  CPU Info Center
 
  ACPI标准
系统认证
Desktop
服务器
 
  Embedded Linux
嵌入式开发工具
VxWorks
WinCE
嵌入式Windows
 
  格蠹调试套件(GDK)
  格蠹学院
  小朱书店
  老雷的微博
  《软件调试》
  《格蠹汇编》
  《软件调试(第二版)》
沪ICP备11027180号-1

Windows内核调试

帖子发起人: Jane1970   发起时间: 2009-11-05 17:04 下午   回复: 2

Print Search
帖子排序:    
   2009-11-05, 17:04 下午
Jane1970 离线,最后访问时间: 2009/8/28 10:13:52 Jane1970

发帖数前500位
注册: 2009-08-28
发 贴: 3
Tongue Tied [:S] 请教:在windbg中使用!lpc port命令失败!
Reply Quote
环境:XP professional 2002 sp3,windbg 6.11.0001
使用kernel debug 到本地的模式,现场:
lkd>  .sympath SRV*C:\WINDOWS\Symbols*http://msdl.microsoft.com/download/symbols
DBGHELP: Symbol Search Path: srv*c:\windows\symbols*http://msdl.microsoft.com/download/symbols
DBGHELP: Symbol Search Path: srv*c:\windows\symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\WINDOWS\Symbols*http://msdl.microsoft.com/download/symbols
Expanded Symbol search path is: srv*c:\windows\symbols*http://msdl.microsoft.com/download/symbols
Symbol search path is: SRV*C:\WINDOWS\Symbols*http://msdl.microsoft.com/download/symbols
Expanded Symbol search path is: srv*c:\windows\symbols*http://msdl.microsoft.com/download/symbols
lkd> !sym noisy
lkd> !sym noisy
noisy mode - symbol prompts on
noisy mode - symbol prompts on
lkd>  !lmi nt
lkd>  !lmi nt
Loaded Module Info: [nt]
         Module: ntkrnlmp
   Base Address: 804d8000
     Image Name: ntkrnlmp.exe
   Machine Type: 332 (I386)
     Time Stamp: 4a783d8a Tue Aug 04 21:54:18 2009
           Size: 228000
       CheckSum: 20fd8d
Characteristics: 10e  perf
Debug Data Dirs: Type  Size     VA  Pointer
             CODEVIEW    25, 76ad0,   760d0 RSDS - GUID: {79D38DEF-79B7-454A-9D61-504200179432}
               Age: 2, Pdb: ntkrnlmp.pdb
                CLSID     4, 76acc,   760cc [Data not mapped]
     Image Type: MEMORY   - Image read successfully from loaded memory.
    Symbol Type: PDB      - Symbols loaded successfully from symbol server.
                 c:\windows\symbols\ntkrnlmp.pdb\79D38DEF79B7454A9D615042001794322\ntkrnlmp.pdb
    Load Report: public symbols , not source indexed
                 c:\windows\symbols\ntkrnlmp.pdb\79D38DEF79B7454A9D615042001794322\ntkrnlmp.pdb
Loaded Module Info: [nt]
         Module: ntkrnlmp
   Base Address: 804d8000
     Image Name: ntkrnlmp.exe
   Machine Type: 332 (I386)
     Time Stamp: 4a783d8a Tue Aug 04 21:54:18 2009
           Size: 228000
       CheckSum: 20fd8d
Characteristics: 10e  perf
Debug Data Dirs: Type  Size     VA  Pointer
             CODEVIEW    25, 76ad0,   760d0 RSDS - GUID: {79D38DEF-79B7-454A-9D61-504200179432}
               Age: 2, Pdb: ntkrnlmp.pdb
                CLSID     4, 76acc,   760cc [Data not mapped]
     Image Type: MEMORY   - Image read successfully from loaded memory.
    Symbol Type: PDB      - Symbols loaded successfully from symbol server.
                 c:\windows\symbols\ntkrnlmp.pdb\79D38DEF79B7454A9D615042001794322\ntkrnlmp.pdb
    Load Report: public symbols , not source indexed
                 c:\windows\symbols\ntkrnlmp.pdb\79D38DEF79B7454A9D615042001794322\ntkrnlmp.pdb
lkd> .reload /f nt
lkd> .reload /f nt
DBGHELP: nt - public symbols 
         c:\windows\symbols\ntkrnlmp.pdb\79D38DEF79B7454A9D615042001794322\ntkrnlmp.pdb
DBGHELP: nt - public symbols 
         c:\windows\symbols\ntkrnlmp.pdb\79D38DEF79B7454A9D615042001794322\ntkrnlmp.pdb
lkd> !lpc port
lkd> !lpc port
Port type     Port address  Connection port  Connected port  Name
-------------------------------------------------------------------------------
*** objects of the same type are only linked together if the 4000 flag is set in NtGlobalFlags
*** objects of the same type are only linked together if the 4000 flag is set in NtGlobalFlags
Scanned 829 port objects
Port type     Port address  Connection port  Connected port  Name
-------------------------------------------------------------------------------
*** objects of the same type are only linked together if the 4000 flag is set in NtGlobalFlags
*** objects of the same type are only linked together if the 4000 flag is set in NtGlobalFlags
Scanned 829 port objects


IP 地址: 已记录   报告
   2009-11-06, 09:26 上午
aeezguo 离线,最后访问时间: 2010/4/21 7:25:59 guozf

发帖数前10位
男
注册: 2008-12-06
HK
发 贴: 68
Re: 请教:在windbg中使用!lpc port命令失败!
Reply Quote
楼主好像用local debug吧。
可以拭拭双机调试或者用虚拟机调试.
IP 地址: 已记录   报告
   2009-11-06, 15:03 下午
Jane1970 离线,最后访问时间: 2009/8/28 10:13:52 Jane1970

发帖数前500位
注册: 2009-08-28
发 贴: 3
Re: 用虚拟机调试也不行AH!
Reply Quote
现场:
kd> !lpc port
Port type Port address Connection port Connected port Name
*** objects of the same type are only linked together if the 4000 flag is set in NtGlobalFlags
*** objects of the same type are only linked together if the 4000 flag is set in NtGlobalFlags
Scanned 254 port objects
kd>!gflag
Current NtGlobalFlag contents :0x00000000
kd>!gflag +0x4000
New NtGlobalFlag contents: 0x00004000
otl - Maintain a list of objects for each type
kd> !lpc port
Port type Port address Connection port Connected port Name
*** objects of the same type are only linked together if the 4000 flag is set in NtGlobalFlags
*** objects of the same type are only linked together if the 4000 flag is set in NtGlobalFlags
Scanned 254 port objects
IP 地址: 已记录   报告
高端调试 » 软件调试 » Windows内核调试 » Re: 用虚拟机调试也不行AH!

 
Legal Notice Privacy Statement Corporate Governance Corporate Governance
(C)2004-2020 ADVDBG.ORG All Rights Reserved.