mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-29 13:04:58 +02:00
Merge pull request #475 from f-block/develop
Temporary workaround for changes in transition PTE
This commit is contained in:
@@ -329,5 +329,11 @@ class WindowsIntelPAE(WindowsMixin, IntelPAE):
|
||||
|
||||
class WindowsIntel32e(WindowsMixin, Intel32e):
|
||||
|
||||
# TODO: Fix appropriately in a future release.
|
||||
# Currently just a temprorary workaround to deal with custom bit flag
|
||||
# in the PFN field for pages in transition state.
|
||||
# See https://github.com/volatilityfoundation/volatility3/pull/475
|
||||
_maxphyaddr = 45
|
||||
|
||||
def _translate(self, offset: int) -> Tuple[int, int, str]:
|
||||
return self._translate_swap(self, offset, self._bits_per_register // 2)
|
||||
|
||||
@@ -972,7 +972,12 @@ class CONTROL_AREA(objects.StructType):
|
||||
|
||||
# If the entry is not a valid physical address then see if it is in transition.
|
||||
elif mmpte.u.Trans.Transition == 1:
|
||||
physoffset = mmpte.u.Trans.PageFrameNumber << 12
|
||||
# TODO: Fix appropriately in a future release.
|
||||
# Currently just a temprorary workaround to deal with custom bit flag
|
||||
# in the PFN field for pages in transition state.
|
||||
# See https://github.com/volatilityfoundation/volatility3/pull/475
|
||||
physoffset = (mmpte.u.Trans.PageFrameNumber & (( 1 << 33 ) - 1 ) ) << 12
|
||||
|
||||
yield physoffset, file_offset, self.PAGE_SIZE
|
||||
|
||||
# Go to the next PTE entry
|
||||
|
||||
Reference in New Issue
Block a user