顯示具有 VMware 標籤的文章。 顯示所有文章
顯示具有 VMware 標籤的文章。 顯示所有文章

Windows Debugging 2 – Kernel Debugging with WinDbg and VMware

Windows Vista 之後已經不再將開機選項儲存於 boot.ini 中,而是改以 BCD (Boot Configuration Data) 儲存,因此以前透過編輯 boot.ini 啟動 Windows kernel debugging 的方法也得更新一下。這裡我們透過 bcdedit.exe 來編輯 BCD ,讓 Windows 啟動後可以進入 debug mode 。

VMware 設定

Debuggee 部分,和以前一樣使用 named piped 來替 guest OS 模擬 serial port (COM port)。

  1. 進入 guest OS 設定。 com port
  2. 新增硬體。
    com port 2
  3. 選擇 Serial Port 裝置。
    com port 3
  4. 選擇 named pipe 來模擬我們的 serial port。
    com port 4
  5. 替 named pipe 取一個名字,這個名字等會會被 WinDbg 使用。
    com port 5
  6. 最後別忘了把 Yield CPU on Poll 選項勾起。
    com port 6
  7. 完成新增後,請留意 VMware 替我們新增的 Serial Port 的編號,以上圖為例是:Serial Port 2 

Windows Boot 設定

  1. 使用 administrator 權限開啟一個 cmd。
    start cmd
  2. 透過 BCDEdit 編輯開機選項,使用 COM port (serial port)來做為 debugger 和 debuggee 間的溝通,debugport 的編號請根據 VMware 的 Serial Port 設定而定:
    bcdedit /dbgsettings serial debugport:2
  3. 複製現有的開機選項到 DebugEntr:
    bcdedit /copy {current} /d DebugEntry
    執行完該指令後,會出現一個 ID ,代表我們要複製出來的開機選項,該 ID 在每台電腦上都不太一樣。
  4. 調整開機選樣的順序:
    bcdedit /displayorder {current} {ID}
  5. 打開 debug 選項:
    bcdedit /debug {ID} ON
  6. 設定成預設開機選項:
    bcdedit /default {ID}
    bcdedit edit

 

Enable Debug Print

Vista之後,DbgPrintEx()、vDbgPrintEx()、vDbgPrintExWithPrefix()、KdPrintEx() 等選擇性的輸出函式預設是關閉的,要啟動的話,需要到 registry 上設定對應的 log level [3]:

到 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\Debug Print Filter 下新增 DEFAULT=dword:0000ffff
實際數值,依照需求而定,0000ffff 足以應付大多數用途。

Debug Print Filter

使用

在 bcdedit 設定完成後,重開機,便會看到新的開機選項 DebugEntry:

boot 1

選擇 DebugEntry 後,我們便可以在 debugger 的機器上的 cmd 執行下面指令來進行 kernel debugging,com_1 就是我們當初在 VMware guest OS 裡頭設定的名字:

windbg -b -k com:pipe,port=\\.\pipe\com_1,resets=0

停用驅動程式簽章增強(Disable Driver Signature Enforcement)

Vista 之後的 64-bit OS ,Microsoft 都會要求 drivers 必須有 WHQL 的認證才能啟動。這對於一般使用者來說可能沒有影響,但對於有在開發、測試 drivers 的人就會是個問題。

最簡單的方式是,開機時,使用 F8 進入進階模式:
boot 1
並選擇(停用驅動程式簽章增強)Disable Driver Signature Enforcement。
boot 2

Test Signing

若是 drivers 有 test sign ,那麼我們還可以使用 BCDEdit 來允許 testing sign driver 的載入[4]:
bcdedit /set TESTSIGNING ON
設定完成後,需要重開機。

要驗證 test sign 是否成功,可以使用 bcdedit 檢查,或是觀察桌面右下角的文字說明:

test signing

Reference

  1. Boot Parameters to Enable Debugging
    http://msdn.microsoft.com/en-us/library/windows/hardware/ff542279%28v=vs.85%29.aspx
  2. Kernel Debugging in Windows Vista
    http://msdn.microsoft.com/en-us/windows/hardware/gg487520
  3. Reading and Filtering Debugging Messages
    http://msdn.microsoft.com/en-us/library/windows/hardware/ff551519%28v=vs.85%29.aspx
  4. The TESTSIGNING Boot Configuration Option
    http://msdn.microsoft.com/en-us/library/windows/hardware/ff553484%28v=vs.85%29.aspx

See Also

  1. Windows Debugging – Kernel Debugging with WinDbg and VMware
    http://keikoblog.blogspot.com/2009/03/windows-debugging-kernel-debugging-with.html

VMware 64-bit Guest OS Support

去年聖誕節買的 x201 ,下單前還特別注意 CPU 是否支援 Virtualization ,直到上個月拿來跑 64 bit guest OS 時,才發現 Windows 會進入開機、當機的無窮迴圈。後來才發現一些小眉角,尤其是在筆電上:

  1. 不是 64-bit OS 就可以直接支援 64-bit guest OS ,必須 CPU 有支援 VT 才行。
  2. 大多數筆電的 VT 預設值都是關閉,必須進入 BIOS 啟動。
  3. 在 BIOS 中,若有 Hardware data execution 之類的 H/W security 功能最好也關閉。
  4. 部分筆電,像是 Lenovo x201 ,要讓上述設定生效,還必須將電池、電源移除,按下電源開關,進行放電, BIOS 的改動才會生效。

測試方式

如果不確定 CPU 是否支援 VT ,可以到 Intel/AMS 的網站查詢,像是 Intel Processor Spec. Finder 或 AMD Desktop Processor。

Processor Check for 64-Bit Compatibility

[感謝 Allen Lai 提醒]

VMware 提供了一個快速的檢測工具——Processor Check for 64-Bit Compatibility,雖然已經很久沒更新了,不過它的結果明確易懂,像是下圖就說明:Processor Check for 64-Bit Compatibility

不過根據說明文件,它目前只支援特定的 processors ,而且還有幾項是 experimental support:

  • AMD™ Athlon™ 64, revision D or later
  • AMD Opteron™, revision E or later
  • AMD Turion™ 64, revision E or later
  • AMD Sempron™, 64-bit-capable revision D or later (experimental support)
  • Intel™ EM64T VT-capable processors (experimental support)

VMware CPU Identification Utility

或是利用 VMware 的 CPU Identification Utility ,這是個 可用來開機的 ISO 檔,使用時只需要掛載進 VMware 即可 。

未啟動 VT 時的輸出:

CPU Identification Utility (Before)

啟動 VT 後:

CPU Identification Utility

上面的圖是 x201 開啟 VT 後的結果,根據說明文件和實驗,似乎紅框裡有一個是 Yes ,就可以支援 64-bit guest OS 。根據 Allen Lai 的測試,即使 64-bit LongMode 顯示 YES ,也並非能支援 64-bit guest OS。所以目前還沒有比較好的解讀方式 … 大概只是方便你把結果丟到 support 或 community 去發問 …

最後要注意的是,當 CPU features 設定改變後,都可能讓已經建立好的 snapshots 出問題。

Reference

  1. VMware Shared Utility: http://www.vmware.com/download/shared_utilities.html
  2. Ensuring your hardware is functioning correctly: http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1003690
  3. Ensuring Virtualization Technology is enabled on your VMware host: http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1003944
  4. Hardware and firmware requirements for 64-bit Guest Operating Systems: http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1003945
  5. Intel Processor Spec. Finder: http://ark.intel.com/Default.aspx
  6. AMD Desktop Processor: http://products.amd.com/en-us/desktopcpuresult.aspx

更新

2011/4/26: 補上 x201 未啟動 VT 的 VMware CPU Identification 結果截圖。

2011/4/27: 補充 Allen Lai 的連結和測試工具 Processor Check for 64-Bit Compatibility 。

MiniFilter InstanceSetupCallback is not called?

一般來說,MiniFilter 的 InstanceSetupCallback 會在 filter manager 把 minifilter attache 到 volume 後呼叫。如果沒有的話,可以檢查一下 minifilter 的 INF 是否把 instance fla...