mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-30 05:24:52 +02:00
Remove the error checking in dlllist, we need to be throwing exceptions and handling them.
This commit is contained in:
@@ -13,12 +13,16 @@ class _ETHREAD(objects.Struct):
|
||||
"""Return the EPROCESS that owns this thread"""
|
||||
return self.ThreadsProcess.dereference(kernel_layer)
|
||||
|
||||
|
||||
class _UNICODE_STRING(objects.Struct):
|
||||
@property
|
||||
def String(self):
|
||||
if not self._context.memory[self.vol.layer_name].is_valid(self.Buffer):
|
||||
return ""
|
||||
return self.Buffer.dereference().cast("string", max_length = self.Length, errors = "replace", encoding = "utf16")
|
||||
# We explicitly do *not* catch errors here, we allow an exception to be thrown
|
||||
# (otherwise there's no way to determine anything went wrong)
|
||||
# It's up to the user of this method to catch exceptions
|
||||
return self.Buffer.dereference().cast("string", max_length = self.Length, errors = "replace",
|
||||
encoding = "utf16")
|
||||
|
||||
|
||||
class _EPROCESS(objects.Struct):
|
||||
def add_process_layer(self, context, config_prefix = None, preferred_name = None):
|
||||
@@ -66,14 +70,16 @@ class _EPROCESS(objects.Struct):
|
||||
|
||||
proc_layer = self._context.memory[proc_layer_name]
|
||||
if not proc_layer.is_valid(self.Peb):
|
||||
raise StopIteration
|
||||
raise StopIteration
|
||||
|
||||
sym_table = self.vol.type_name.split("!")[0]
|
||||
peb = self._context.object("{}!_PEB".format(sym_table), layer_name = proc_layer_name, offset = self.Peb)
|
||||
|
||||
for entry in peb.Ldr.InLoadOrderModuleList.to_list("{}!_LDR_DATA_TABLE_ENTRY".format(sym_table), "InLoadOrderLinks"):
|
||||
for entry in peb.Ldr.InLoadOrderModuleList.to_list("{}!_LDR_DATA_TABLE_ENTRY".format(sym_table),
|
||||
"InLoadOrderLinks"):
|
||||
yield entry
|
||||
|
||||
|
||||
class _LIST_ENTRY(objects.Struct, collections.abc.Iterable):
|
||||
def to_list(self, symbol_type, member, forward = True, sentinel = True, layer = None):
|
||||
"""Returns an iterator of the entries in the list"""
|
||||
|
||||
Reference in New Issue
Block a user