mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-29 04:54:51 +02:00
Add in initial version of _LIST_ENTRY.
This commit is contained in:
@@ -7,3 +7,27 @@ class _ETHREAD(objects.Struct):
|
||||
def owning_process(self, kernel_layer = None):
|
||||
"""Return the EPROCESS that owns this thread"""
|
||||
return self.ThreadsProcess.dereference(kernel_layer)
|
||||
|
||||
|
||||
class _LIST_ENTRY(objects.Struct):
|
||||
def to_list(self, structure, member, forward = True, sentinel = True, layer = None):
|
||||
"""Returns an iterator of the entries in the list"""
|
||||
|
||||
if layer is None:
|
||||
layer = self._layer_name
|
||||
|
||||
relative_offset = self._context.symbolspace.relative_child_offset(structure, member)
|
||||
|
||||
direction = 'BLink'
|
||||
if forward:
|
||||
direction = 'FLink'
|
||||
link = getattr(self, direction).dereference()
|
||||
|
||||
seen = set()
|
||||
while link.offset not in seen:
|
||||
|
||||
object = self._context.Object(structure, layer, offset = link.offset)
|
||||
yield object
|
||||
|
||||
seen.add(link.offset)
|
||||
link = getattr(link, direction).dereference()
|
||||
|
||||
Reference in New Issue
Block a user