mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-23 18:14:51 +02:00
Moving thread type check methods to the task object
This commit is contained in:
@@ -3,7 +3,7 @@
|
||||
#
|
||||
from typing import Callable, Iterable, List, Any, Tuple
|
||||
|
||||
from volatility3.framework import renderers, interfaces, constants
|
||||
from volatility3.framework import renderers, interfaces
|
||||
from volatility3.framework.configuration import requirements
|
||||
from volatility3.framework.objects import utility
|
||||
from volatility3.framework.symbols import linux
|
||||
@@ -57,18 +57,6 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
else:
|
||||
return lambda _: False
|
||||
|
||||
@staticmethod
|
||||
def task_is_kernel_thread(task: interfaces.objects.ObjectInterface) -> bool:
|
||||
return (task.flags & constants.linux.PF_KTHREAD) != 0
|
||||
|
||||
@staticmethod
|
||||
def task_is_thread_group_leader(task: interfaces.objects.ObjectInterface) -> bool:
|
||||
return task.tgid == task.pid
|
||||
|
||||
@staticmethod
|
||||
def task_is_user_thread(task: interfaces.objects.ObjectInterface) -> bool:
|
||||
return task.tgid != task.pid
|
||||
|
||||
def _get_task_fields(
|
||||
self,
|
||||
task: interfaces.objects.ObjectInterface,
|
||||
@@ -89,9 +77,9 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
ppid = task.parent.tgid if task.parent else 0
|
||||
name = utility.array_to_string(task.comm)
|
||||
if decorate_comm:
|
||||
if self.task_is_kernel_thread(task):
|
||||
if task.is_kernel_thread:
|
||||
name = f"[{name}]"
|
||||
elif self.task_is_user_thread(task):
|
||||
elif task.is_user_thread:
|
||||
name = f"{{{name}}}"
|
||||
|
||||
task_fields = (pid, tid, ppid, name)
|
||||
@@ -154,7 +142,7 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
next_task = task.thread_group.next
|
||||
while current_task is None or current_task.vol.offset != task.vol.offset:
|
||||
current_task = linux.LinuxUtilities.container_of(next_task, "task_struct", "thread_group", vmlinux)
|
||||
if cls.task_is_thread_group_leader(current_task):
|
||||
if current_task.is_thread_group_leader:
|
||||
# Making sure the first task yielded is the Task Group Leader
|
||||
yield current_task
|
||||
elif include_threads:
|
||||
|
||||
@@ -201,6 +201,33 @@ class task_struct(generic.GenericIntelProcess):
|
||||
|
||||
yield (start, end - start)
|
||||
|
||||
@property
|
||||
def is_kernel_thread(self) -> bool:
|
||||
"""Checks if this task is a kernel thread.
|
||||
|
||||
Returns:
|
||||
bool: True, if this task is a kernel thread. Otherwise, False.
|
||||
"""
|
||||
return (self.flags & constants.linux.PF_KTHREAD) != 0
|
||||
|
||||
@property
|
||||
def is_thread_group_leader(self) -> bool:
|
||||
"""Checks if this task is a thread group leader.
|
||||
|
||||
Returns:
|
||||
bool: True, if this task is a thread group leader. Otherwise, False.
|
||||
"""
|
||||
return self.tgid == self.pid
|
||||
|
||||
@property
|
||||
def is_user_thread(self) -> bool:
|
||||
"""Checks if this task is a user thread.
|
||||
|
||||
Returns:
|
||||
bool: True, if this task is a user thread. Otherwise, False.
|
||||
"""
|
||||
return not self.is_kernel_thread and self.tgid != self.pid
|
||||
|
||||
|
||||
class fs_struct(objects.StructType):
|
||||
|
||||
|
||||
Reference in New Issue
Block a user