Merge pull request #475 from f-block/develop

Temporary workaround for changes in transition PTE
This commit is contained in:
ikelos
2021-05-12 20:22:09 +01:00
committed by GitHub
2 changed files with 12 additions and 1 deletions
+6
View File
@@ -329,5 +329,11 @@ class WindowsIntelPAE(WindowsMixin, IntelPAE):
class WindowsIntel32e(WindowsMixin, Intel32e):
# TODO: Fix appropriately in a future release.
# Currently just a temprorary workaround to deal with custom bit flag
# in the PFN field for pages in transition state.
# See https://github.com/volatilityfoundation/volatility3/pull/475
_maxphyaddr = 45
def _translate(self, offset: int) -> Tuple[int, int, str]:
return self._translate_swap(self, offset, self._bits_per_register // 2)
@@ -972,7 +972,12 @@ class CONTROL_AREA(objects.StructType):
# If the entry is not a valid physical address then see if it is in transition.
elif mmpte.u.Trans.Transition == 1:
physoffset = mmpte.u.Trans.PageFrameNumber << 12
# TODO: Fix appropriately in a future release.
# Currently just a temprorary workaround to deal with custom bit flag
# in the PFN field for pages in transition state.
# See https://github.com/volatilityfoundation/volatility3/pull/475
physoffset = (mmpte.u.Trans.PageFrameNumber & (( 1 << 33 ) - 1 ) ) << 12
yield physoffset, file_offset, self.PAGE_SIZE
# Go to the next PTE entry