mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-22 01:24:51 +02:00
Plugins: Add back in the checks because the filter might trip them
This commit is contained in:
@@ -109,6 +109,8 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
|
||||
kernel = contexts.Module(context, darwin_symbols, layer_name, 0)
|
||||
|
||||
kernel_layer = context.layers[layer_name]
|
||||
|
||||
proc = kernel.object_from_symbol(symbol_name = "allproc").lh_first
|
||||
|
||||
seen = {} # type: Dict[int, int]
|
||||
@@ -119,7 +121,7 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
else:
|
||||
seen[proc.vol.offset] = 1
|
||||
|
||||
if not filter_func(proc):
|
||||
if kernel_layer.is_valid(proc.vol.offset, proc.vol.size) and not filter_func(proc):
|
||||
yield proc
|
||||
|
||||
try:
|
||||
@@ -148,6 +150,8 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
|
||||
kernel = contexts.Module(context, darwin_symbols, layer_name, 0)
|
||||
|
||||
kernel_layer = context.layers[layer_name]
|
||||
|
||||
queue_entry = kernel.object_from_symbol(symbol_name = "tasks")
|
||||
|
||||
seen = {} # type: Dict[int, int]
|
||||
@@ -163,7 +167,7 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
except exceptions.PagedInvalidAddressException:
|
||||
continue
|
||||
|
||||
if not filter_func(proc):
|
||||
if kernel_layer.is_valid(proc.vol.offset, proc.vol.size) and not filter_func(proc):
|
||||
yield proc
|
||||
|
||||
@classmethod
|
||||
|
||||
Reference in New Issue
Block a user