深入解析Windows操作系统(Windows Internals) 4th Edition 读书备忘录

AWE: Address Windowsing Extension,地址窗口扩展,使用32位应用程序可以访问多达64GB的虚拟内存。

访问3G内存:在boot.ini中,添加/3GB和/USERVA,应用程序设置“大地址空间感知”标志。

64位Windows虚拟内存划分:用户空间8192GB,系统空间6657GB。

WinDbg符号路径设置:srv*c:/symbols*http://msdl.microsoft.com/download/symbols

Windows支持处理器数目:HKLM/SYSTEM/CurrentControlSet/Control/SessionManager/LicensedProcessors

Windows安装过程中拷贝的文件列表:Windows/Repair/Setup.log

是否安装了PAE内核:HKLM/SYSTEM/CurrentControlSet/Control/Session Management/PhysicalAddressExtension值是否为1。

客户端或服务器版本信息:HKLM/SYSTEM/CurrentControlSet/Control/ProductOptions键下的ProductType和ProductSuite

会话管理器(Smss.exe)配置信息:HKLM/SYSTEM/CurrentControlSet/Control/Session Manager

会话初始进程:HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/Userinit (默认为userinit.exe)

外壳程序:HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/Winlogon/Shell (默认为explorer.exe)

系统服务:HKLM/SYSTEM/CurrentControlSet/Services

未处理异常过滤器:HKLM/SOFTWARE/Microsoft/Windows NT/CurrentVersion/AeDebug

 

深入学习Windows必读,详细讲解有关Windows内部原理的方方面面。 By Mark E. Russinovich, David A. Solomon Chapter 1. Concepts and Tools Windows Operating System Versions Foundation Concepts and Terms Digging into Windows Internals Conclusion Chapter 2. System Architecture Requirements and Design Goals Operating System Model Architecture Overview Key System Components Conclusion Chapter 3. System Mechanisms Trap Dispatching Object Manager Synchronization System Worker Threads Windows Global Flags Local Procedure Calls (LPCs) Kernel Event Tracing Wow64 Conclusion Chapter 4. Management Mechanisms The Registry Services Windows Management Instrumentation Conclusion Chapter 5. Startup and Shutdown Boot Process Troubleshooting Boot and Startup Problems Shutdown Conclusion Chapter 6. Processes, Threads, and Jobs Process Internals Flow of CreateProcess Thread Internals Examining Thread Activity Thread Scheduling Job Objects Conclusion Chapter 7. Memory Management Introduction to the Memory Manager Services the Memory Manager Provides System Memory Pools Virtual Address Space Layouts Address Translation Page Fault Handling Virtual Address Descriptors Section Objects Working Sets Logical Prefetcher Page Frame Number Database Conclusion Chapter 8. Security Security Ratings Trusted Computer System Evaluation Critiera The Common Criteria Security System Components Protecting Objects Account Rights and Privileges Security Auditing Logon Software Restriction Policies Conclusion Chapter 9. I/O System I/O System Components Device Drivers I/O Processing The Plug and Play (PnP) Manager The Power Manager Conclusion Chapter 10. Storage Management Storage Terminology Disk Drivers Volume Management Conclusion Chapter 11. Cache Manager Key Features of the Cache Manager Cache Virtual Memory Management Cache Size Cache Data Structures File System Interfaces Fast I/O Read Ahead and Write Behind Conclusion Chapter 12. File Systems Windows File System Formats File System Driver Architecture Troubleshooting File System Problems NTFS Design Goals and Features NTFS File System Driver NTFS On-Disk Structure NTFS Recovery Support Encrypting File System Security Conclusion Chapter 13. Networking Windows Networking Architecture Networking APIs Multiple Redirector Support Name Resolution Protocol Drivers NDIS Drivers Binding Layered Network Services Conclusion Chapter 14. Crash Dump Analysis Why Does Windows Crash? The Blue Screen Crash Dump Files Windows Error Reporting Online Crash Analysis Basic Crash Dump Analysis Using Crash Troubleshooting Tools Advanced Crash Dump Analysis Glossary Index
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值