
    [
#g)                         d dl Z d dlmZ d dlmZmZmZmZ d dlm	Z	m
Z
 d dlmZ d dlmZ d dlmZ d dlmZ  e j&                  e      Z ed	d
      Z G d dej.                        Zy)    N)
namedtuple)TupleListIterableUnion)	renderers
interfaces)requirements)plugins)linux)pslistMountInfoData)
mnt_id	parent_idst_devmnt_root_path	path_rootmnt_optsfieldsmnt_typedevnamesb_optsc                      e Zd ZdZdZdZedeej                  j                     fd       Zededeeeeeeee   ee   eeee   f
   f   fd       Ze	 ddeej&                  j(                     d	efd
       Z	 	 ddeej&                  j(                     dee   ded	edeeeef      f
dZedej0                  j2                  dedeej&                  j(                     fd       Zd Zy)	MountInfoz0Lists mount points on processes mount namespaces)   r   r   )   r   r   returnc                 l   t        j                  ddg d      t        j                  dt        j                  d      t        j
                  dt        j                  d	
      t        j                  ddt        d      t        j                  ddt        d      t        j                  dddd      gS )NkernelzLinux kernel)Intel32Intel64AArch64)namedescriptionarchitecturesr   )r   r   r   )r#   pluginversion
linuxutils)r   r   r   )r#   	componentr'   pidszFilter on specific process IDs.T)r#   r$   element_typeoptionalmntnszDFilter results by mount namespace. Otherwise, all of them are shown.mount-formatzShows a brief summary of the mount points information with similar output format to the older /proc/[pid]/mounts or the user-land command 'mount -l'.F)r#   r$   r,   default)r
   ModuleRequirementPluginRequirementr   PsListVersionRequirementr   LinuxUtilitiesListRequirementintBooleanRequirement)clss    _/home/panchajanya/Development/work/volatility3/volatility3/framework/plugins/linux/mountinfo.pyget_requirementszMountInfo.get_requirements*   s     ***?
 **fmmY ++!U-A-A9 ((= 	 ((4  ++#0 3!
 !	
    Nc                 .   |j                         }|syt        j                  j                  ||      }|sy|j	                         }|j                         }|j                  }|j                  j                  }|j                   d|j                   }	g }
|
j                  |j                                |
j                  |j                                g }|j                         r|j                  d|j                          |j!                         rj|j"                  j                  }|j                  d|        |j%                  |j&                  j(                        }|r||k7  r|j                  d|        |j+                         r|j                  d       |j-                         }|j/                         }|sd}g }|j                  |j                                |j                  |j                                t1        |||	|||
||||
      S )zuExtract various information about a mount point.
        It mimics the Linux kernel show_mountinfo function.
        N:zshared:zmaster:zpropagate_from:
unbindablenone)get_mnt_rootr   r4   get_path_mntpath
get_mnt_sbr   
mnt_parentmajorminorappendget_flags_accessextendget_flags_opts	is_sharedmnt_group_idis_slave
mnt_masterget_dominating_idfsrootis_unbindableget_typeget_devnamer   )r8   mnttaskmnt_rootr   r   
superblockr   r   r   r   r   masterdominating_idr   r   r   s                    r9   get_mountinfozMountInfo.get_mountinfoO   s    ##%((55dC@	 ^^%
jj..	$$%Qz'7'7&89 ,,./**,- ==?MMGC$4$4#567<<>^^00FMMGF8,-11$'',,?M&!8?@MM,'&&(//#Gz2245z0023
 	
r;   tasksfiltered_by_pidsc              #     K   t               }| D ]  }|rD|j                  r8|j                  j                  r"|j                  r|j                  j                  sJ|j                  j                  }	 |j                         }|j                         D ]6  }|s+t        |j                        }||v r|j                  |       |||f 8  y # t        $ r t        j                         }Y kw xY ww)N)setrP   rQ   nsproxymnt_ns	get_inodeAttributeErrorr   NotAvailableValueget_mount_pointsr6   r   add)r\   r]   seen_mountpointsrV   mnt_namespace	mnt_ns_idmountr   s           r9   _get_tasks_mountpointsz MountInfo._get_tasks_mountpoints   s     
 5DGGGGLLLLLL''  LL//M:)335	 '779 ( .F!11 (,,V4E9,, :%  " :%779	:s+   A-C/0C AC/C,)C/+C,,C/
mnt_ns_idsmount_formatc              #     K   d}| j                  ||      D ]  \  }}}|rt        |t        j                        rd}t        |t        j                        s|r||vrG| j	                  ||      }	|	\|rvt               }
|
j                  |	j                         |
j                  |	j                         dj                  |
      }|	j                  |	j                  |	j                  |g}ndj                  |	j                        }dj                  |	j                        }dj                  |	j                        }|	j                  |	j                  |	j                   |	j"                  |	j                  |||	j                  |	j                  |g
}|g}|r|j%                  |j&                         |j)                  |       d|f  |rt*        j-                  d       y y w)NFT, r   zSCould not filter by mount namespace id. This field is not available in this kernel.)rk   
isinstancer   rd   r[   r_   updater   r   joinr   r   r   r   r   r   r   r   rG   pidrI   vollogwarning)selfr\   rl   rm   r]   show_filter_warningrV   rU   ri   mnt_infoall_optsall_opts_strextra_fields_valuesmnt_opts_str
fields_strsb_opts_strfields_valuess                    r9   
_generatorzMountInfo._generator   s     $$($?$?#%
 D#y jI4O4OP&*# y)*E*EFZ/))#t4H5 1 12 0 01"xx1 $$&&%% 	'#  #xx(9(9: XXhoo6
!hhx'7'78 OO&&OO**&& %%$$'# 'KM$$TXX.  !45m$$i%
l NNe s   GG!contextvmlinux_module_namec              #   R  K   t         j                  j                  ||      }t               }| j	                  |      D ]e  \  }}}t
        j                  j                  ||      }|s*|j                         }	|	r|	|v rA|j                  |	       |	j                         |f g yw)aZ  Yield file system superblocks based on the task's mounted filesystems.

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            vmlinux_module_name: The name of the kernel module on which to operate

        Yields:
            super_block: Kernel's struct super_block object
        N)r   r2   
list_tasksr_   rk   r   r4   rA   rC   rf   dereference)
r8   r   r   r\   seen_sb_ptrrV   rU   
_mnt_ns_idr   sb_ptrs
             r9   get_superblockszMountInfo.get_superblocks   s       ((2EFe%(%?%?%F!D#z,,99$DI^^%FV{2OOF#$$&	11 &Gs   B%B'c                    | j                   j                  d      }| j                   j                  d      }| j                   j                  d      }t        j                  j	                  |      }t        j                  j                  | j                  | j                   d   |      }dt        fg}|r|j                  dt        f       d}nd	}| j                   j                  d      rd
t        fdt        fdt        fdt        fg}nHdt        fdt        fdt        fdt        fdt        fdt        fdt        fdt        fdt        fdt        fg
}|j                  |       t        j                  || j                  ||||            S )Nr*   r-   r.   r   )filter_func	MNT_NS_IDPIDTFDEVNAMEPATHFSTYPEMNT_OPTSzMOUNT ID	PARENT_IDzMAJOR:MINORROOTMOUNT_POINTMOUNT_OPTIONSFIELDS	MOUNT_SRC
SB_OPTIONS)configgetr   r2   create_pid_filterr   r   r6   rG   strrI   r   TreeGridr   )	rw   r*   mount_ns_idsrm   
pid_filterr\   columnsr]   extra_columnss	            r9   runzMountInfo.run  sk   {{v&{{w/{{~6]]44T:
((LL$++h/Z ) 
  %& NNE3<(#$;;??>*C 3S!	M S!c"$$ #&33c"s#M 	}%!!OOE<?OP
 	
r;   )F)FF)__name__
__module____qualname____doc___required_framework_version_versionclassmethodr   r	   configurationRequirementInterfacer:   r   r   r6   r   r[   staticmethodr   objectsObjectInterfaceboolrk   r   r   ContextInterfacer   r    r;   r9   r   r   #   s   :"+H"
j&>&>&S&S!T "
 "
H @
	eCc3T#YS	3TRUYVWW
@
 @
D  "'"-
**::;"-"- "-P #!&A
**::;A IA 	A
 A 
%U
#	$AF 2##442 !2 
*$$44	5	2 2<.
r;   r   )loggingcollectionsr   typingr   r   r   r   volatility3.frameworkr   r	   #volatility3.framework.configurationr
    volatility3.framework.interfacesr   volatility3.framework.symbolsr   volatility3.plugins.linuxr   	getLoggerr   ru   r   PluginInterfacer   r   r;   r9   <module>r      s\   
  " / / 7 < 4 / , 
		8	$"d
'' d
r;   