mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-08-28 10:49:42 +02:00
Extensions: Removes the get_raw_dpc method from KTIMER
This removes the `get_raw_dpc` method from the `KTIMER` extension class. This method was inaccurate in that it actually returns the masked pointer value instead of the full 64-bit value encoded in that member, which is required in order to correctly decode the 'real' pointer. The invocation of `get_raw_dpc()` was replaced with `self.Dpc.get_raw_value()`, which was added in the previous commit.
This commit is contained in:
@@ -1220,15 +1220,6 @@ class KTIMER(objects.StructType):
|
||||
return "Yes"
|
||||
return "-"
|
||||
|
||||
def get_raw_dpc(self):
|
||||
"""Returns the encoded DPC as an unsigned long long since the pointer is actually encoded"""
|
||||
if symbols.symbol_table_is_64bit(
|
||||
context=self._context, symbol_table_name=self.get_symbol_table_name()
|
||||
):
|
||||
return self.Dpc.cast("unsigned long long")
|
||||
else:
|
||||
return self.Dpc.cast("unsigned long")
|
||||
|
||||
def valid_type(self):
|
||||
return self.Header.Type in self.VALID_TYPES
|
||||
|
||||
@@ -1263,7 +1254,7 @@ class KTIMER(objects.StructType):
|
||||
)
|
||||
|
||||
low_byte = (wait_never) & 0xFF
|
||||
entry = utility.rol(self.get_raw_dpc() ^ wait_never, low_byte)
|
||||
entry = utility.rol(self.Dpc.get_raw_value() ^ wait_never, low_byte)
|
||||
swap_xor = self._context.layers[self.vol.native_layer_name].canonicalize(
|
||||
self.vol.offset
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user