Change the signature for add_process_layer to match linux.

This commit is contained in:
Mike Auty
2018-05-07 17:45:40 +01:00
parent a05dbe708d
commit 2cb5435911
2 changed files with 4 additions and 5 deletions
@@ -389,12 +389,11 @@ class _UNICODE_STRING(objects.Struct):
class _EPROCESS(generic.GenericIntelProcess):
def add_process_layer(self,
context: interfaces.context.ContextInterface,
config_prefix: str = None,
preferred_name: str = None):
"""Constructs a new layer based on the process's DirectoryTableBase"""
parent_layer = context.memory[self.vol.layer_name]
parent_layer = self._context.memory[self.vol.layer_name]
if not isinstance(parent_layer, intel.Intel):
# We can't get bits_per_register unless we're an intel space (since that's not defined at the higher layer)
@@ -408,7 +407,7 @@ class _EPROCESS(generic.GenericIntelProcess):
dtb = dtb & ((1 << parent_layer.bits_per_register) - 1)
# Add the constructed layer and return the name
return self._add_process_layer(context, dtb, config_prefix, preferred_name)
return self._add_process_layer(self._context, dtb, config_prefix, preferred_name)
def load_order_modules(self) -> typing.Iterable[int]:
"""Generator for DLLs in the order that they were loaded"""
@@ -416,7 +415,7 @@ class _EPROCESS(generic.GenericIntelProcess):
if constants.BANG not in self.vol.type_name:
raise ValueError("Invalid symbol table name syntax (no {} found)".format(constants.BANG))
proc_layer_name = self.add_process_layer(self._context)
proc_layer_name = self.add_process_layer()
proc_layer = self._context.memory[proc_layer_name]
if not proc_layer.is_valid(self.Peb):
+1 -1
View File
@@ -26,7 +26,7 @@ class VadDump(interfaces_plugins.PluginInterface):
process_name = utility.array_to_string(proc.ImageFileName)
# TODO: what kind of exceptions could this raise and what should we do?
proc_layer_name = proc.add_process_layer(self.context)
proc_layer_name = proc.add_process_layer()
proc_layer = self.context.memory[proc_layer_name]
for vad in plugin.list_vads(proc):