
    XfG                     X   d dl Z d dlZd dlZd dlZd dlmZmZmZmZm	Z	 d dl
mZ d dlmZmZmZmZmZmZ d dlmZ  ej        e          Z G d dej                  Z G d d	e          Z G d
 dej                  Z G d dej        j                  Z G d dej                  ZdS )    N)DictListOptionalTupleUnion)PoolConstraint)	constants
exceptions
interfacesobjects	rendererssymbols)
conversionc                      e Zd ZdZ	 	 ddededee         dee         deej	        j
                 f
dZe ej                    d	ej        j        d
edeee         ee         f         fd                        Zd Zd Zd ZdS )POOL_HEADERz|A kernel pool allocation header.

    Exists at the base of the allocation and provides a tag that we can
    scan for.
    N
constraintuse_top_downkernel_symbol_tablenative_layer_namereturnc              #   &
  K   |j         }|j        du}| j        j                             t          j                  d         }t          j        |v r*|                    t          j                  dd         \  }}|r0| j        j                            |t          j        z   dz             }n/| j        j                            |t          j        z   dz             }| j        j	        }	|sK| j        
                    |t          j        z   |z   | j        j        | j        j        |	z   |          }
|
V  dS t          j        | j        |          rd}nd}|r|                    d          }|                    d	          }|                    d
          }|j        d
         d         j	        }|                     | j        |          \  }}d|vrdn|                    d          }t'          |          }| j        j        |	z   }t)          || j        |z            }| j        j        | j        j                                     |||z   d          }t1          d||          D ]s}|||z            }t2                              |||z   ||z   |z            dd          }d|cxk    rdk    sn Ld}d}t1          t7          |                    D ]}|d|z  z  r|||         z  }||k    rd}d}|r?||z
  dk     rt9          j        d|||z
  ||z
  dz                      \  }|||pd         z  }||z
  |cxk    r|k    rn nt=          j        t@          tB          j"                  5  | j        
                    |t          j        z   |z   | j        j        ||z   |z   |          }
|
#                                r|
V  ddd           n# 1 swxY w Y   udS | j        j                            |t          j        z   |z             j	        }|j$        rA|j$        D ]9}|| j        j                            |t          j        z   |z             j	        z  }:tK          j&        ||d          } | j        
                    |t          j        z   |z   | j        j        | j        j        | j        |z  z   | z
  |          }
t=          j        t@          tB          j"                  5  |
#                                r|
V  ddd           dS # 1 swxY w Y   dS )a  Carve an object or data structure from a kernel pool allocation

        Args:
            constraint: a PoolConstraint object used to get the pool allocation header object
            use_top_down: for delineating how a windows version finds the size of the object body
            kernel_symbol_table: in case objects of a different symbol table are scanned for
            native_layer_name: the name of the layer where the data originally lived

        Returns:
            An object as found from a POOL_HEADER
        Nr      _OBJECT_HEADER
layer_nameoffsetr         BodyInfoMaskPointerCount   PADDING_INFOT)padlittle)	byteordersigned   Fz<I   )up)'	type_nameobject_typevolsplitr	   BANG_contextsymbol_spaceget_typesizeobjectr   r   r   symbol_table_is_64bitrelative_child_offsetmembers"_calculate_optional_header_lengthsindexsummin	BlockSizelayersreadrangeint
from_byteslenstructunpack
contextlibsuppress	TypeErrorr
   InvalidAddressExceptionis_validadditional_structuresr   round)!selfr   r   r   r   r+   	executivesymbol_table_nameobject_header_typepool_header_size
mem_object	alignmentbody_offsetinfomask_offsetpointercount_offsetpointercount_sizeoptional_headerslengths_of_optional_headerspadding_availablemax_optional_headers_lengthstart_offset
addr_limitinfomask_dataaddrinfomask_valuepointercount_valuepadding_presentoptional_headers_lengthipadding_length	type_sizeadditional_structurerounded_sizes!                                    g/home/panchajanya/Development/work/volatility3/volatility3/framework/symbols/windows/extensions/pool.py
get_objectzPOOL_HEADER.get_object   s     & (	*$6	 H.44Y^DDQG>Y&&+4??9>+J+J1Q3+O(y  	!%!;!D!D#in47GG" "
 "&!;!D!D!IN25EE" "  8=  S	)--!IN2Y>8.x)99"3	 .  J  ,T]<MNN 			  B)0FFvNN"4"J"J:"V"V&8&N&N"' '# %7$>~$Nq$Q$V! ;;M#4 $/ &-=== D)//?? "
 /22M.N.N+  $x1AA /)1K 
 !% 4TX5H I N N *">D !O ! ! "!Z;; F- F-D%24/3I%JN),% 1248152/500 #+# *8 	* 	*& %'9>>>>Q>>>> &+O./+"3'B#C#CDD 7 7)Q!V4 737RST7UU3 $55526 &'N&   "99A==$,2M ) $"9!:<@"9=:"#=$!$- -) '*E-2+  55NNNN$NNNNN #,!:#E  - - &*]%9%9-	>J'+x':#'+#5#D.?	 &: & &
 &..00 -",,,,- - - - - - - - - - - - - - -wF- F-T !M6??%	6B   3 0:0P  ,!T]%?%H%H-	>AUU& &		  */	9NNN!]11%	6B#x28?T^i-GG,V&7	 2  
  (J4VWW ) )!**,, )(((() ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) ) )s%   'AO

O	O	 TT
T
contextrN   c                 L   g }g }dD ]}t          j        t          t          j                  5  | t
          j         d| }|j                            |          }|	                    |           |	                    |j
                   d d d            n# 1 swxY w Y   ||fS )N)	CREATOR_INFO	NAME_INFOHANDLE_INFO
QUOTA_INFOPROCESS_INFO
AUDIT_INFOEXTENDED_INFOHANDLE_REVOCATION_INFOr#   _OBJECT_HEADER_)rE   rF   AttributeErrorr
   SymbolErrorr	   r/   r1   r2   appendr3   )clsrj   rN   headerssizesheaderr+   header_types           rh   r8   z.POOL_HEADER._calculate_optional_header_lengths   s    
 

 	/ 	/F $^Z5KLL / /(Q).QQQQ  &2;;IFFv&&&[-.../ / / / / / / / / / / / / / / ~s   ABB	B	c                     | j         dk    S Nr   PoolTyperL   s    rh   is_free_poolzPOOL_HEADER.is_free_pool   s    }!!    c                 4    | j         dz  dk    o
| j         dk    S Nr   r   r   r   s    rh   is_paged_poolzPOOL_HEADER.is_paged_pool        }q A%;$-!*;;r   c                     | j         dz  dk    S Nr   r"   r   r   s    rh   is_nonpaged_poolzPOOL_HEADER.is_nonpaged_pool       }q A%%r   )NN)__name__
__module____qualname____doc__r   boolr   strr   r   ObjectInterfaceri   classmethod	functools	lru_cacherj   ContextInterfacer   r   r@   r8   r   r   r    r   rh   r   r      s          .2+/|) |)"|) |) &c]	|)
 $C=|) 
*$4	5|) |) |) |)| Y (9NQ	tCy$s)#	$    [:" " "< < <& & & & &r   r   c                       e Zd ZdZd Zd ZdS )POOL_HEADER_VISTAzA kernel pool allocation header, updated for Vista and later.

    Exists at the base of the allocation and provides a tag that we can
    scan for.
    c                     | j         dz  dk    S r   r   r   s    rh   r   zPOOL_HEADER_VISTA.is_paged_pool  r   r   c                 4    | j         dz  dk    o
| j         dk    S r   r   r   s    rh   r   z"POOL_HEADER_VISTA.is_nonpaged_pool  r   r   N)r   r   r   r   r   r   r   r   rh   r   r     s<         & & &< < < < <r   r   c                       e Zd ZU dZi Zeeef         ed<   d Zde	fdZ
de	fdZdefdZdeeej        j        f         fdZdeeej        j        f         fd	Zd
S )POOL_TRACKER_BIG_PAGESzA kernel big page pool tracker.pool_type_lookupc                 &   | j         j                            t          j                  d         }| j        j                            |t          j        z   dz             }|j        	                                D ]\  }}|| j
        vr
|| j
        |<   d S )Nr   
_POOL_TYPE)r-   r+   r.   r	   r/   r0   r1   get_enumerationchoicesitemsr   )rL   rN   pool_type_enumkvs        rh   _generate_pool_type_lookupz1POOL_TRACKER_BIG_PAGES._generate_pool_type_lookup  s     !H.44Y^DDQG3CC	.=
 
 #*0022 	- 	-DAq---+,%a(	- 	-r   r   c                     | j         dk    S r~   )Keyr   s    rh   rI   zPOOL_TRACKER_BIG_PAGES.is_valid"  s    x!|r   c                     | j         dz  dk    S )z;Returns if the allocation is freed (True) or in-use (False)r"   )Var   s    rh   is_freezPOOL_TRACKER_BIG_PAGES.is_free%  s    w{ar   c           	          t          j        | j        t          t          j        ddd                    }d                    d |D                       S )z-Returns the Key value as a 4 character stringr)   r%   F c                 P    g | ]#}d |cxk     rdk     rn nt          |          nd$S )       r   )chr).0xs     rh   
<listcomp>z2POOL_TRACKER_BIG_PAGES.get_key.<locals>.<listcomp>.  s:    JJJ1"q,,,,3,,,,,ABJJJr   )r   convert_value_to_datar   r@   DataFormatInfojoin)rL   	tag_bytess     rh   get_keyzPOOL_TRACKER_BIG_PAGES.get_key)  sO    1Hc71!XuEE
 
	 wwJJ	JJJKKKr   c                     t          | d          rC| j        s|                                  | j                            | j        d| j                   S t          j                    S )zBReturns the enum name for the PoolType value on applicable systemsr   zUnknown choice )hasattrr   r   getr   r   NotApplicableValuer   s    rh   get_pool_typez$POOL_TRACKER_BIG_PAGES.get_pool_type0  sq     4$$ 	2( 2//111(,,@@@   /111r   c                 X    	 | j         S # t          $ r t          j                    cY S w xY w)z5Returns the NumberOfBytes value on applicable systems)NumberOfBytesru   r   r   r   s    rh   get_number_of_bytesz*POOL_TRACKER_BIG_PAGES.get_number_of_bytes<  s@    	2%% 	2 	2 	2/11111	2s   	 ))N)r   r   r   r   r   r   r   __annotations__r   r   rI   r   r   r   r   r   BaseAbsentValuer   r@   r   r   r   rh   r   r     s         ))')d38n)))	- 	- 	-$             L L L L L
2uS**>*N%NO 
2 
2 
2 
22U3
0D0T+T%U 2 2 2 2 2 2r   r   c                       e Zd ZdZddZdS )ExecutiveObjectzyThis is used as a "mixin" that provides all kernel executive objects
    with a means of finding their own object header.r   OBJECT_HEADERc                    t           j        | j        j        vrt	          dt           j         d          | j        j                            t           j                  d         }| j        j                            |t           j        z   dz             	                    d          }| j        
                    |t           j        z   dz   | j        j        | j        j        |z
  | j        j                  S )N%Invalid symbol table name syntax (no  found)r   r   r   r   )r	   r/   r-   r+   
ValueErrorr.   r0   r1   r2   r6   r4   r   r   r   )rL   rN   rS   s      rh   get_object_headerz!ExecutiveObject.get_object_headerI  s    >!333O	OOO   !H.44Y^DDQGm099	.1AA
 



'
' 	 }##	.1AAx*8?[0"h8	 $ 
 
 	
r   N)r   r   )r   r   r   r   r   r   r   rh   r   r   E  s2        8 8
 
 
 
 
 
r   r   c                       e Zd ZdZdefdZ	 d	deeef         dede	e         fdZ
edej        j        fd            ZdS )
r   zA class for the headers for executive kernel objects, which contains
    quota information, ownership details, naming data, and ACLs.r   c                 f    	 | j         dk    s| j         dk     rdS n# t          j        $ r Y dS w xY wdS )z!Determine if the object is valid.r(   r   FT)r!   r
   rH   r   s    rh   rI   zOBJECT_HEADER.is_valid^  sY    	 9,,0AA0E0Eu 1F1 	 	 	55	 ts    ..Ntype_mapcookiec                 r   | j                             dd          | j         j        S 	 | j        j        j        | j        d<   nj# t          $ r] 	 | j         j        dz	  |z  | j	        z  dz  }n# t          t          f$ r
 | j	        }Y nw xY w|                    |          | j        d<   Y nw xY w| j         j        S )zAcross all Windows versions, the _OBJECT_HEADER embeds details on
        the type of object (i.e. process, file) but the way its embedded
        differs between versions.

        This API abstracts away those details.
        object_header_object_typeNr      )r-   r   r   TypeNameString_volru   r   	TypeIndexrG   )rL   r   r   
type_indexs       rh   get_object_typezOBJECT_HEADER.get_object_typel  s     8<<3T::F855	N59Y^5JDI122 	N 	N 	N,#x!3v=NRVV

"I. , , ,!^


, 6>\\*5M5MDI1222	N x11s5   A 
B*A,+B*,BB*B B*)B*c                    t           j        | j        j        vrt	          dt           j         d          | j        j                            t           j                  d         }|| j        j        v r| j        j        |         }n|| j        j        | j        j	                 }|j
                            dd           }|t          d| j        j                   | j                            || j        j        |          }	 | j        }na# t          $ rT d}|                    d          j        }| j        ||d	z
  z  z  }|                    d
| j        j	        ||z             }Y nw xY w|dk    r7t	          d                    | j        j        | j        j                            |                    d| j        j        | j        j        |z
  | j        j	        d          }	|	S )Nr   r   r   kernel_virtual_offsetz0Could not find kernel_virtual_offset for layer: )r   r   r   ObpInfoMaskToOffsetr"   zunsigned charzDCould not find _OBJECT_HEADER_NAME_INFO for object at {} of layer {}_OBJECT_HEADER_NAME_INFOT)r   r   r   absolute)r	   r/   r-   r+   r   r.   r0   modulesr=   r   configr   ru   r   moduleNameInfoOffset
get_symboladdressr    r4   formatr   )
rL   rN   ntkrnlmplayerkvoheader_offsetname_info_bitr   calculated_indexr{   s
             rh   NameInfozOBJECT_HEADER.NameInfo  s   >!333O	OOO   !H.44Y^DDQG 555},->?HHM()CDE,""#:DAAC{$\txGZ\\  
 }++!dh.A# ,  H	 /MM 	 	 	M))*?@@HG#}QRAR0ST$OO85!11 ,  MMM	 AV]]HOTX%8    &x*8?]2"h8 ! 
 
 s   D AE)(E))N)r   r   r   r   r   rI   r   r@   r   r   r   propertyr   r   r   r   r   r   rh   r   r   Z  s        D D$     7;2 2S#X2032	#2 2 2 26 5*,< 5 5 5 X5 5 5r   r   )rE   r   loggingrC   typingr   r   r   r   r   'volatility3.plugins.windows.poolscannerr   volatility3.frameworkr	   r
   r   r   r   r   volatility3.framework.renderersr   	getLoggerr   vollog
StructTyper   r   r   r   r   r   r   r   rh   <module>r      s             5 5 5 5 5 5 5 5 5 5 5 5 5 5 B B B B B B                7 6 6 6 6 6		8	$	$k& k& k& k& k&'$ k& k& k&\< < < < < < < <02 02 02 02 02W/ 02 02 02f
 
 
 
 
j(8 
 
 
*c c c c cG& c c c c cr   