mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-30 05:24:52 +02:00
linux: page_cache: enhance early inconsistency detection
This commit is contained in:
@@ -861,17 +861,15 @@ class PageCache:
|
||||
"""
|
||||
layer = self.vmlinux.context.layers[self.vmlinux.layer_name]
|
||||
for page_addr in self._idstorage.get_entries(self._page_cache.i_pages):
|
||||
if not page_addr:
|
||||
continue
|
||||
|
||||
if not layer.is_valid(page_addr):
|
||||
continue
|
||||
error_msg = f"Invalid cached page address at {page_addr:#x}, aborting"
|
||||
vollog.error(error_msg)
|
||||
raise exceptions.LinuxPageCacheException(error_msg)
|
||||
|
||||
page = self.vmlinux.object("page", offset=page_addr, absolute=True)
|
||||
if not page.is_valid():
|
||||
vollog.error(
|
||||
f"Invalid cached page at {page.vol.offset:#x}, aborting",
|
||||
)
|
||||
break
|
||||
error_msg = f"Invalid cached page at {page_addr:#x}, aborting"
|
||||
vollog.error(error_msg)
|
||||
raise exceptions.LinuxPageCacheException(error_msg)
|
||||
|
||||
yield page
|
||||
|
||||
@@ -2513,6 +2513,11 @@ class inode(objects.StructType):
|
||||
page_content (bytes): The page content
|
||||
"""
|
||||
for page_obj in self.get_pages():
|
||||
if page_obj.mapping != self.i_mapping:
|
||||
vollog.warning(
|
||||
f"Cached page at {page_obj.vol.offset:#x} has a mismatched address space with the inode. Skipping page"
|
||||
)
|
||||
continue
|
||||
page_index = int(page_obj.index)
|
||||
page_content = page_obj.get_content()
|
||||
if page_content:
|
||||
@@ -2524,7 +2529,7 @@ class address_space(objects.StructType):
|
||||
def i_pages(self):
|
||||
"""Returns the appropriate member containing the page cache tree"""
|
||||
if self.has_member("i_pages"):
|
||||
# Kernel >= 4.17
|
||||
# Kernel >= 4.17 b93b016313b3ba8003c3b8bb71f569af91f19fc7
|
||||
return self.member("i_pages")
|
||||
elif self.has_member("page_tree"):
|
||||
# Kernel < 4.17
|
||||
|
||||
Reference in New Issue
Block a user