Reading Notebook: 11-March-10
Comments in italics are mine and express my own views, thoughts and opinions
Windows Internals by M. Russinovich, D. Solomon and A. Ionescu:
Clock cycle counter for measuring CPU activity (p. 382)
Process Explorer usage to inspect hung threads (p. 383) - useful for coupled processes (http://www.dumpanalysis.org/blog/index.php/2007/09/26/crash-dump-analysis-patterns-part-28/) and could be great with simultaneous WinDbg session to inspect wait chains (http://www.dumpanalysis.org/blog/index.php/2009/02/17/wait-chain-patterns/)
Process Explorer shows both thread and WOW64 thread stacks on x64 (p. 384)
Thread stack and context query limitations for protected processes (pp. 384 - 386)
Thread pool mechanism was moved into kernel space in Vista (p. 387)
TpWorkerFactory and I/O completion ports and KQUEUE (pp. 387 - 388) - see also a “brief guide” to I/O completion ports: http://www.dumpanalysis.org/blog/index.php/2007/11/27/understanding-io-completion-ports/
The mystery of ntdll!TppWorkerThread in stack traces (pp. 389 - 390)