
    Xf/                         d dl Z d dlZd dlmZmZmZmZ d dlmZm	Z	m
Z
 d dlmZ d dlmZ d dlmZ d dlmZ  ej&                  e      Z G d d	e	j,                  j.                        Zy)
    N)CallableDictIterableList)
exceptions
interfaces	renderers)requirements)utility)format_hints)macc                      e Zd ZdZdZdZg dZed        Zede	de
ej                  j                  e	e
egef   geej"                  j$                     f   fd       Zedd
ee   de
egef   fd       Zd Zed fdej                  j                  de	de
egef   deej"                  j$                     fd       Zed fdej                  j                  de	de
egef   deej"                  j$                     fd       Zed fdej                  j                  de	de
egef   deej"                  j$                     fd       Zed fdej                  j                  de	de
egef   deej"                  j$                     fd       Zed fdej                  j                  de	de
egef   deej"                  j$                     fd       Zd Zy	)PsListz=Lists the processes present in a particular mac memory image.)   r   r   )   r   r   )tasksallprocprocess_groupsessionspid_hash_tablec           	         t        j                  ddddg      t        j                  dt        j                  d      t        j
                  d	d
| j                  | j                  d   d      t        j                  ddt        d      gS )NkernelzKernel module for the OSIntel32Intel64)namedescriptionarchitecturesmacutils)   r   r   )r   	componentversionpslist_methodz!Method to determine for processesr   T)r   r   choicesdefaultoptionalpidzFilter on specific process IDs)r   r   element_typer%   )	r
   ModuleRequirementVersionRequirementr   MacUtilitiesChoiceRequirementpslist_methodsListRequirementint)clss    Z/home/panchajanya/Development/work/volatility3/volatility3/framework/plugins/mac/pslist.pyget_requirementszPsList.get_requirements   s     **6()4
 ++3+;+;Y **$?****1- ((< 	!
 	
    methodreturnc                 :   || j                   vr| j                   d   }|dk(  r| j                  }nS|dk(  r| j                  }nA|dk(  r| j                  }n/|dk(  r| j                  }n|dk(  r| j
                  }nt        d      t        j                  d|        |S )	zReturns the list_tasks method based on the selector

        Args:
            method: Must be one fo the available methods in get_task_choices

        Returns:
            list_tasks method for listing tasks
        r   r   r   r   r   r   zImpossible method choice chosenzUsing method )	r,   list_tasks_allproclist_tasks_taskslist_tasks_process_grouplist_tasks_sessionslist_tasks_pid_hash_table
ValueErrorvollogdebug)r/   r3   
list_taskss      r0   get_list_taskszPsList.get_list_tasks3   s     +++''*FY//Jw--J&55Jz!00J''66J>??}VH-.r2   Npid_listc                 \    d }|xs g }|D cg c]  }||	 c}rfd}|}|S c c}w )Nc                      yNF _s    r0   <lambda>z*PsList.create_pid_filter.<locals>.<lambda>V       r2   c                      | j                   vS N)p_pid)xfilter_lists    r0   list_filterz-PsList.create_pid_filter.<locals>.list_filter\   s    wwk11r2   rD   )r/   r@   filter_funcrL   rN   rM   s        @r0   create_pid_filterzPsList.create_pid_filterT   s?    %>r"*<Qamq<2 &K =s   ))c           
   #     K   | j                  | j                  j                  d| j                  d               } || j                  | j                  d   | j                  | j                  j                  dd                   D ]  }t        j                  |j                  j                        }t        j                  |j                        }|j                  }|j                  }|j                  }|j                   j"                  }|j                   j$                  }	t&        j&                  j)                  ||	dz  z         }
|j*                  }d||||||
|ff  y w)Nr"   r   r   r&   )rO   g    .A)r?   configgetr,   contextrP   r   Hexvoloffsetr   array_to_stringp_commrK   p_uidp_gidp_starttv_sectv_usecdatetimefromtimestampp_ppid)selfr>   taskrW   r   r&   uidgidstart_time_secondsstart_time_microseconds
start_timeppids               r0   
_generatorzPsList._generatorb   s-    ((KKOOOT-@-@-CD

 LLKK!..t{{ud/KL
 	GD
 "%%dhhoo6F**4;;7D**C**C**C!%!4!4&*ll&:&:#!**88"%<s%BBJ ;;DvtS#sJEFF%	Gs   E E"c                      yrC   rD   rE   s    r0   rG   zPsList.<lambda>   rH   r2   rT   kernel_module_namerO   c              #     K   |j                   |   }|j                  |j                     }|j                  d      j                  }i }||j
                  j                  dk7  r|j
                  j                  |v r%t        j                  t        j                  d       yd||j
                  j                  <   |j                  |j
                  j                  |j
                  j                        r ||      s| 	 |j                  j                  j                         }||j
                  j                  dk7  ryyyy# t         j"                  $ r Y yw xY ww)a  Lists all the processes in the primary layer based on the allproc method

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            kernel_module_name: The name of the the kernel module on which to operate
            filter_func: A function which takes a process object and returns True if the process should be ignored/filtered

        Returns:
            The list of process objects from the processes linked list after filtering
        r   symbol_nameNr   ERecursive process list detected (a result of non-atomic acquisition).r   )moduleslayers
layer_nameobject_from_symbollh_firstrV   rW   r<   logloggingINFOis_validsizep_listle_nextdereferencer   InvalidAddressException)r/   rT   rl   rO   r   kernel_layerprocseens           r0   r6   zPsList.list_tasks_allproc{   s!    $ !34~~f&7&78((Y(?HH!488??a#7xx$&

LL[ ()TXX__%$$!$'
{{**668! 488??a#7#7" 55 s0   C>E$E %EEEEEEc                      yrC   rD   rE   s    r0   rG   zPsList.<lambda>   rH   r2   c              #   x  K   |j                   |   }|j                  |j                     }|j                  d      }i }|j	                  |dd      D ]  }|j
                  j                  |v r&t        j                  t        j                  d        yd||j
                  j                  <   	 |j                  j                         j                  d      }	|j!                  |	j
                  j                  |	j
                  j"                        s ||	      r|	  y# t        j                  $ r Y w xY ww)a  Lists all the tasks in the primary layer based on the tasks queue

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            kernel_module_name: The name of the the kernel module on which to operate
            filter_func: A function which takes a task object and returns True if the task should be ignored/filtered

        Returns:
            The list of task objects from the `layer_name` layer's `tasks` list after filtering
        r   rn   rc   rp   r   r   N)rq   rr   rs   rt   	walk_listrV   rW   r<   rv   rw   rx   bsd_infor}   castr   r~   ry   rz   )
r/   rT   rl   rO   r   r   queue_entryr   rc   r   s
             r0   r7   zPsList.list_tasks_tasks   s    " !34~~f&7&78//G/D!))+wG 	Dxx$&

LL[ ()TXX__%}}00277? $$!$'
%	 55 s6   B*D:-)D!:D:D:D:!D74D:6D77D:c                      yrC   rD   rE   s    r0   rG   zPsList.<lambda>   rH   r2   c              #     K   |j                   |   }|j                  d      }|j                  d      }|j                  d||dz   |j                  d            }|D ]c  }t        j
                  j                  |d      D ]>  }	|	j                  j                         s ||	j                        r1|	j                   @ e y	w)
a  Lists all the tasks in the primary layer using sessions

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            kernel_module_name: The name of the the kernel module on which to operate
            filter_func: A function which takes a task object and returns True if the task should be ignored/filtered

        Returns:
            The list of task objects from the `layer_name` layer's `tasks` list after filtering
        sesshashrn   sesshashtblarrayr   sesshashheadobject_typerW   countsubtypes_hashN)	rq   rt   objectget_typer   r*   walk_list_heads_leaderis_readable)
r/   rT   rl   rO   r   
table_sizer   
proc_array	proc_listr   s
             r0   r9   zPsList.list_tasks_sessions   s     " !34..:.F
//M/J]]q.OON3	 # 

 $ 	(I((77	8L (==,,.{4==7Q--'(	(s   BC C3Cc                      yrC   rD   rE   s    r0   rG   zPsList.<lambda>   rH   r2   c              #     K   |j                   |   }|j                  d      }|j                  d      }|j                  d||dz   |j                  d            }|D ]c  }t        j
                  j                  |d      D ]>  }	t        j
                  j                  |	j                  d	      D ]  }
 ||
      r|
  @ e y
w)a  Lists all the tasks in the primary layer using process groups

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            kernel_module_name: The name of the the kernel module on which to operate
            filter_func: A function which takes a task object and returns True if the task should be ignored/filtered

        Returns:
            The list of task objects from the `layer_name` layer's `tasks` list after filtering
        pgrphashrn   pgrphashtblr   r   pgrphashheadr   pg_hashp_pglistN)rq   rt   r   r   r   r*   r   
pg_members)r/   rT   rl   rO   r   r   r   r   r   pgrpr   s              r0   r8   zPsList.list_tasks_process_group   s     " !34..:.F
//M/J]]q.OON3	 # 

 $ 	#I((77	9M #,,;;OOZ #D 't,"
	##	#s   B8C;Cc                      yrC   rD   rE   s    r0   rG   zPsList.<lambda>"  rH   r2   c              #   2  K   |j                   |   }|j                  d      }|j                  d      }|j                  d||dz   |j                  d            }|D ]4  }t        j
                  j                  |d      D ]  }	 ||	      r|	  6 y	w)
a  Lists all the tasks in the primary layer using the pid hash table

        Args:
            context: The context to retrieve required elements (layers, symbol tables) from
            kernel_module_name: The name of the the kernel module on which to operate
            filter_func: A function which takes a task object and returns True if the task should be ignored/filtered

        Returns:
            The list of task objects from the `layer_name` layer's `tasks` list after filtering
        pidhashrn   
pidhashtblr   r   pidhashheadr   p_hashN)rq   rt   r   r   r   r*   r   )
r/   rT   rl   rO   r   r   r   r   r   r   s
             r0   r:   z PsList.list_tasks_pid_hash_table  s     $ !34..9.E
..<.H
]]q.OOM2	 # 

 $ 	I((77	8L "4(J	s   BB	Bc           
          t        j                  dt        j                  fdt        fdt
        fdt
        fdt
        fdt        j                  fdt
        fg| j                               S )NOFFSETNAMEPIDUIDGIDz
Start TimePPID)r	   TreeGridr   rU   strr.   r_   rj   )rb   s    r0   runz
PsList.runA  se    !!<++,x001 OO
 	
r2   rJ   )__name__
__module____qualname____doc___required_framework_version_versionr,   classmethodr1   r   r   r   rT   ContextInterfacer.   boolr   objectsObjectInterfacer?   r   rP   rj   r6   r7   r9   r8   r:   r   rD   r2   r0   r   r      s   G"+HXN
 
2 C H				,	,c8SE4K3HI##334	6-  @ c hud{>S  G2 
 .=	*##44*  * seTk*	*
 
*$$44	5* *X 
 .=	)##44)  ) seTk*	)
 
*$$44	5) )V 
 .=	 (##44 (   ( seTk*	 (
 
*$$44	5 (  (D 
 .=	####44##  ## seTk*	##
 
*$$44	5## ##J 
 .=	!##44!  ! seTk*	!
 
*$$44	5! !F
r2   r   )r_   rw   typingr   r   r   r   volatility3.frameworkr   r   r	   #volatility3.framework.configurationr
   volatility3.framework.objectsr   volatility3.framework.renderersr   volatility3.framework.symbolsr   	getLoggerr   r<   pluginsPluginInterfacer   rD   r2   r0   <module>r      sQ   
   1 1 C C < 1 8 -			8	${
Z// {
r2   