
    Xf/                         d dl Z d dlZd dlmZmZmZmZ d dlmZm	Z	m
Z
 d dlmZ d dlmZ d dlmZ d dlmZ  ej        e          Z G d d	e	j        j                  ZdS )
    N)CallableDictIterableList)
exceptions
interfaces	renderers)requirements)utility)format_hints)macc                   D   e Zd ZdZdZdZg dZed             Zede	de
ej        j        e	e
egef         geej        j                 f         fd            Zedd
ee         de
egef         fd            Zd Zed fdej        j        de	de
egef         deej        j                 fd            Zed fdej        j        de	de
egef         deej        j                 fd            Zed fdej        j        de	de
egef         deej        j                 fd            Zed fdej        j        de	de
egef         deej        j                 fd            Zed fdej        j        de	de
egef         deej        j                 fd            Zd Zd	S )PsListz=Lists the processes present in a particular mac memory image.)   r   r   )   r   r   )tasksallprocprocess_groupsessionspid_hash_tablec           	          t          j        ddddg          t          j        dt          j        d          t          j        d	d
| j        | j        d         d          t          j        ddt          d          gS )NkernelzKernel module for the OSIntel32Intel64)namedescriptionarchitecturesmacutils)   r   r   )r   	componentversionpslist_methodz!Method to determine for processesr   T)r   r   choicesdefaultoptionalpidzFilter on specific process IDs)r   r   element_typer%   )	r
   ModuleRequirementVersionRequirementr   MacUtilitiesChoiceRequirementpslist_methodsListRequirementint)clss    Z/home/panchajanya/Development/work/volatility3/volatility3/framework/plugins/mac/pslist.pyget_requirementszPsList.get_requirements   s     *6()4  
 +3+;Y   *$?**1-   (< 	  !
 	
    methodreturnc                    || j         vr| j         d         }|dk    r| j        }nG|dk    r| j        }n9|dk    r| j        }n+|dk    r| j        }n|dk    r| j        }nt          d          t                              d|            |S )	zReturns the list_tasks method based on the selector

        Args:
            method: Must be one fo the available methods in get_task_choices

        Returns:
            list_tasks method for listing tasks
        r   r   r   r   r   r   zImpossible method choice chosenzUsing method )	r,   list_tasks_allproclist_tasks_taskslist_tasks_process_grouplist_tasks_sessionslist_tasks_pid_hash_table
ValueErrorvollogdebug)r/   r3   
list_taskss      r0   get_list_taskszPsList.get_list_tasks3   s     +++'*FY/JJw-JJ&&5JJz!!0JJ'''6JJ>???-V--...r2   Npid_listc                 @    d }|pg }d |D             rfd}|}|S )Nc                     dS NF _s    r0   <lambda>z*PsList.create_pid_filter.<locals>.<lambda>V   s     r2   c                     g | ]}||S NrD   ).0xs     r0   
<listcomp>z,PsList.create_pid_filter.<locals>.<listcomp>Y   s    <<<Qamqmmmr2   c                     | j         vS rI   )p_pid)rK   filter_lists    r0   list_filterz-PsList.create_pid_filter.<locals>.list_filter\   s    wk11r2   rD   )r/   r@   filter_funcrP   rO   s       @r0   create_pid_filterzPsList.create_pid_filterT   sT    %o>r<<(<<< 	&2 2 2 2 2 &Kr2   c           
   #   P  K   |                      | j                            d| j        d                             } || j        | j        d         |                     | j                            dd                               D ]}t          j        |j        j	                  }t          j        |j                  }|j        }|j        }|j        }|j        j        }|j        j        }	t&          j                            ||	dz  z             }
|j        }d||||||
|ffV  d S )Nr"   r   r   r&   )rQ   g    .A)r?   configgetr,   contextrR   r   Hexvoloffsetr   array_to_stringp_commrN   p_uidp_gidp_starttv_sectv_usecdatetimefromtimestampp_ppid)selfr>   taskrY   r   r&   uidgidstart_time_secondsstart_time_microseconds
start_timeppids               r0   
_generatorzPsList._generatorb   s;     ((KOOOT-@-CDD
 

 JLK!..t{ud/K/KLL
 
 
 	G 	GD
 "%dho66F*4;77D*C*C*C!%!4&*l&:#!*88"%<s%BB J ;DvtS#sJEFFFFF%	G 	Gr2   c                     dS rC   rD   rE   s    r0   rG   zPsList.<lambda>       u r2   rV   kernel_module_namerQ   c              #   <  K   |j         |         }|j        |j                 }|                    d          j        }i }||j        j        dk    r|j        j        |v r't                              t          j
        d           dS d||j        j        <   |                    |j        j        |j        j                  r ||          s|V  	 |j        j                                        }n# t           j        $ r Y dS w xY w||j        j        dk    dS dS dS dS )a  Lists all the processes in the primary layer based on the allproc method

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            kernel_module_name: The name of the the kernel module on which to operate
            filter_func: A function which takes a process object and returns True if the process should be ignored/filtered

        Returns:
            The list of process objects from the processes linked list after filtering
        r   symbol_nameNr   ERecursive process list detected (a result of non-atomic acquisition).r   )moduleslayers
layer_nameobject_from_symbollh_firstrX   rY   r<   logloggingINFOis_validsizep_listle_nextdereferencer   InvalidAddressException)r/   rV   ro   rQ   r   kernel_layerprocseens           r0   r6   zPsList.list_tasks_allproc{   sJ     $ !34~f&78((Y(??H!48?a#7#7x$&&

L[   ()TX_%$$  !k$'' 


{*66885   # 48?a#7#7#7#7#7#7s   C. .D Dc                     dS rC   rD   rE   s    r0   rG   zPsList.<lambda>   rn   r2   c              #   .  K   |j         |         }|j        |j                 }|                    d          }i }|                    |dd          D ]}|j        j        |v r(t                              t          j
        d            dS d||j        j        <   	 |j                                                            d          }	n# t          j        $ r Y w xY w|                    |	j        j        |	j        j                  r ||	          s|	V  dS )a  Lists all the tasks in the primary layer based on the tasks queue

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            kernel_module_name: The name of the the kernel module on which to operate
            filter_func: A function which takes a task object and returns True if the task should be ignored/filtered

        Returns:
            The list of task objects from the `layer_name` layer's `tasks` list after filtering
        r   rq   re   rs   r   r   N)rt   ru   rv   rw   	walk_listrX   rY   r<   ry   rz   r{   bsd_infor   castr   r   r|   r}   )
r/   rV   ro   rQ   r   r   queue_entryr   re   r   s
             r0   r7   zPsList.list_tasks_tasks   s>     " !34~f&78//G/DD!))+wGG 	 	Dx$&&

L[   ()TX_%}002277??5    $$  !k$'' 


%	 	s   ,CCCc                     dS rC   rD   rE   s    r0   rG   zPsList.<lambda>   rn   r2   c              #     K   |j         |         }|                    d          }|                    d          }|                    d||dz   |                    d                    }|D ]W}t          j                            |d          D ]4}	|	j                                        r ||	j                  s	|	j        V  5Xd	S )
a  Lists all the tasks in the primary layer using sessions

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            kernel_module_name: The name of the the kernel module on which to operate
            filter_func: A function which takes a task object and returns True if the task should be ignored/filtered

        Returns:
            The list of task objects from the `layer_name` layer's `tasks` list after filtering
        sesshashrq   sesshashtblarrayr   sesshashheadobject_typerY   countsubtypes_hashN)	rt   rw   objectget_typer   r*   walk_list_heads_leaderis_readable)
r/   rV   ro   rQ   r   
table_sizer   
proc_array	proc_listr   s
             r0   r9   zPsList.list_tasks_sessions   s      " !34..:.FF
//M/JJ]]q.OON33	 # 
 

 $ 	( 	(I(77	8LL ( (=,,.. ({{4=7Q7Q (-'''(	( 	(r2   c                     dS rC   rD   rE   s    r0   rG   zPsList.<lambda>   rn   r2   c              #     K   |j         |         }|                    d          }|                    d          }|                    d||dz   |                    d                    }|D ]\}t          j                            |d          D ]9}	t          j                            |	j        d	          D ]}
 ||
          s|
V  :]d
S )a  Lists all the tasks in the primary layer using process groups

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            kernel_module_name: The name of the the kernel module on which to operate
            filter_func: A function which takes a task object and returns True if the task should be ignored/filtered

        Returns:
            The list of task objects from the `layer_name` layer's `tasks` list after filtering
        pgrphashrq   pgrphashtblr   r   pgrphashheadr   pg_hashp_pglistN)rt   rw   r   r   r   r*   r   
pg_members)r/   rV   ro   rQ   r   r   r   r   r   pgrpr   s              r0   r8   zPsList.list_tasks_process_group   s     " !34..:.FF
//M/JJ]]q.OON33	 # 
 

 $ 	# 	#I(77	9MM # #,;;OZ  # #D ';t,, #"


	##	# 	#r2   c                     dS rC   rD   rE   s    r0   rG   zPsList.<lambda>"  rn   r2   c              #   H  K   |j         |         }|                    d          }|                    d          }|                    d||dz   |                    d                    }|D ]4}t          j                            |d          D ]}	 ||	          s|	V  5d	S )
a  Lists all the tasks in the primary layer using the pid hash table

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            kernel_module_name: The name of the the kernel module on which to operate
            filter_func: A function which takes a task object and returns True if the task should be ignored/filtered

        Returns:
            The list of task objects from the `layer_name` layer's `tasks` list after filtering
        pidhashrq   
pidhashtblr   r   pidhashheadr   p_hashN)rt   rw   r   r   r   r*   r   )
r/   rV   ro   rQ   r   r   r   r   r   r   s
             r0   r:   z PsList.list_tasks_pid_hash_table  s      $ !34..9.EE
..<.HH
]]q.OOM22	 # 
 

 $ 	 	I(77	8LL  "{4(( JJJ	 	r2   c           
          t          j        dt          j        fdt          fdt
          fdt
          fdt
          fdt          j        fdt
          fg|                                           S )NOFFSETNAMEPIDUIDGIDz
Start TimePPID)r	   TreeGridr   rW   strr.   ra   rl   )rd   s    r0   runz
PsList.runA  sd    !<+,x01 OO
 
 	
r2   rI   )__name__
__module____qualname____doc___required_framework_version_versionr,   classmethodr1   r   r   r   rV   ContextInterfacer.   boolr   objectsObjectInterfacer?   r   rR   rl   r6   r7   r9   r8   r:   r   rD   r2   r0   r   r      s9       GG"+HXXXN
 
 [
2 C H			,c8SE4K3HI#34	6-    [@  c hud{>S    [G G G2 
 .=_	* *#4*  * seTk*	*
 
*$4	5* * * [*X 
 .=_	) )#4)  ) seTk*	)
 
*$4	5) ) ) [)V 
 .=_	 (  (#4 (   ( seTk*	 (
 
*$4	5 (  (  ( [ (D 
 .=_	## ###4##  ## seTk*	##
 
*$4	5## ## ## [##J 
 .=_	! !#4!  ! seTk*	!
 
*$4	5! ! ! [!F
 
 
 
 
r2   r   )ra   rz   typingr   r   r   r   volatility3.frameworkr   r   r	   #volatility3.framework.configurationr
   volatility3.framework.objectsr   volatility3.framework.renderersr   volatility3.framework.symbolsr   	getLoggerr   r<   pluginsPluginInterfacer   rD   r2   r0   <module>r      s   
   1 1 1 1 1 1 1 1 1 1 1 1 C C C C C C C C C C < < < < < < 1 1 1 1 1 1 8 8 8 8 8 8 - - - - - -		8	$	${
 {
 {
 {
 {
Z/ {
 {
 {
 {
 {
r2   