
    XfG                     n   d dl Z d dlZd dlZd dlZd dlmZmZmZmZm	Z	 d dl
mZ d dlmZmZmZmZmZmZ d dlmZ  ej*                  e      Z G d dej0                        Z G d d	e      Z G d
 dej0                        Z G d dej                   j8                        Z G d dej0                        Zy)    N)DictListOptionalTupleUnion)PoolConstraint)	constants
exceptions
interfacesobjects	rendererssymbols)
conversionc                      e Zd ZdZ	 	 ddededee   dee   deej                  j                     f
dZe ej                         d	ej                  j                   d
edeee   ee   f   fd              Zd Zd Zd Zy)POOL_HEADERz|A kernel pool allocation header.

    Exists at the base of the allocation and provides a tag that we can
    scan for.
    N
constraintuse_top_downkernel_symbol_tablenative_layer_namereturnc              #   2  K   |j                   }|j                  du}| j                  j                   j                  t        j
                        d   }t        j
                  |v r%|j                  t        j
                        dd \  }}|r:| j                  j                  j                  |t        j
                  z   dz         }n9| j                  j                  j                  |t        j
                  z   dz         }| j                  j                  }	|sc| j                  j                  |t        j
                  z   |z   | j                  j                  | j                  j                  |	z   |      }
|
 yt        j                  | j                  |      rd}nd}|rj|j                  d      }|j                  d	      }|j                  d
      }|j                   d
   d   j                  }| j#                  | j                  |      \  }}d|vrdn|j%                  d      }t'        |      }| j                  j                  |	z   }t)        || j*                  |z        }| j                  j,                  | j                  j                     j/                  |||z   d      }t1        d||      D ]T  }|||z      }t2        j5                  |||z   ||z   |z    dd      }d|cxkD  rdk\  sn >d}d}t1        t7        |            D ]  }|d|z  z  s|||   z  }||k(  sd} d}|r9||z
  dk  rt9        j:                  d|||z
  ||z
  dz          \  }|||xs d   z  }||z
  |cxk\  r|kD  rn nt=        j>                  t@        tB        jD                        5  | j                  j                  |t        j
                  z   |z   | j                  j                  ||z   |z   |      }
|
jG                         r|
 ddd       W y| j                  j                  j                  |t        j
                  z   |z         j                  }|jH                  rW|jH                  D ]H  }|| j                  j                  j                  |t        j
                  z   |z         j                  z  }J tK        jL                  ||d      } | j                  j                  |t        j
                  z   |z   | j                  j                  | j                  j                  | j*                  |z  z   | z
  |      }
t=        j>                  t@        tB        jD                        5  |
jG                         r|
 ddd       y# 1 sw Y   xY w# 1 sw Y   yxY ww)a  Carve an object or data structure from a kernel pool allocation

        Args:
            constraint: a PoolConstraint object used to get the pool allocation header object
            use_top_down: for delineating how a windows version finds the size of the object body
            kernel_symbol_table: in case objects of a different symbol table are scanned for
            native_layer_name: the name of the layer where the data originally lived

        Returns:
            An object as found from a POOL_HEADER
        Nr      _OBJECT_HEADER
layer_nameoffsetr         BodyInfoMaskPointerCount   PADDING_INFOT)padlittle)	byteordersigned   Fz<I   )up)'	type_nameobject_typevolsplitr	   BANG_contextsymbol_spaceget_typesizeobjectr   r   r   symbol_table_is_64bitrelative_child_offsetmembers"_calculate_optional_header_lengthsindexsummin	BlockSizelayersreadrangeint
from_byteslenstructunpack
contextlibsuppress	TypeErrorr
   InvalidAddressExceptionis_validadditional_structuresr   round)!selfr   r   r   r   r+   	executivesymbol_table_nameobject_header_typepool_header_size
mem_object	alignmentbody_offsetinfomask_offsetpointercount_offsetpointercount_sizeoptional_headerslengths_of_optional_headerspadding_availablemax_optional_headers_lengthstart_offset
addr_limitinfomask_dataaddrinfomask_valuepointercount_valuepadding_presentoptional_headers_lengthipadding_length	type_sizeadditional_structurerounded_sizes!                                    g/home/panchajanya/Development/work/volatility3/volatility3/framework/symbols/windows/extensions/pool.py
get_objectzPOOL_HEADER.get_object   s    & ((	**$6	 HH..44Y^^DQG>>Y&+4??9>>+J1Q+O(y !%!;!;!D!D#inn47GG"
 "&!;!;!D!D!INN25EE"  88== --!INN2Y>88..xx)99"3	 . J  ,,T]]<MN		 0FFvN"4"J"J:"V&8&N&N"'# %7$>$>~$Nq$Q$V$V! ;;MM#4$/ &-== )//? "
 /22M.N+  $xx1AA /)1K
 !% 4 4TXX5H5H I N N *">D !O ! "!Z; F-D%24/3I%JN),% 1248152/50 #+# *8 	*& %'9>Q> &+O./+"3'B#CD 7)Q!V437RST7UU3 $5526	7 &'N&  "99A=$,2MM ) $"9!:<@"9=:"#=$-) '*E-2+  55N$N #,,!:#E#E - &*]]%9%9-	>J'+xx':':#'+#5#D.?	 &: &
 &..0",,- -wF-T !MM66??%	6B$  330:0P0P ,!T]]%?%?%H%H-	>AUU&$	
  *//	9N!]]11%	6B#xx2288??T^^i-GG,V&7	 2 
  ((J4V4VW )!**,(() )C- -B) )sE   LVV#A;VA"U> E V V5	V>V	VVVcontextrN   c                 V   g }g }dD ]  }t        j                  t        t        j                        5  | t
        j                   d| }|j                  j                  |      }|j                  |       |j                  |j                         d d d         ||fS # 1 sw Y   xY w)N)	CREATOR_INFO	NAME_INFOHANDLE_INFO
QUOTA_INFOPROCESS_INFO
AUDIT_INFOEXTENDED_INFOHANDLE_REVOCATION_INFOr#   _OBJECT_HEADER_)rE   rF   AttributeErrorr
   SymbolErrorr	   r/   r1   r2   appendr3   )clsrj   rN   headerssizesheaderr+   header_types           rh   r8   z.POOL_HEADER._calculate_optional_header_lengths   s    
 

 	/F $$^Z5K5KL /())..)9Q  &22;;IFv&[--./ /	/, ~/ /s   ABB(	c                      | j                   dk(  S Nr   PoolTyperL   s    rh   is_free_poolzPOOL_HEADER.is_free_pool   s    }}!!    c                 H    | j                   dz  dk(  xr | j                   dkD  S Nr   r   r   r   s    rh   is_paged_poolzPOOL_HEADER.is_paged_pool   $    }}q A%;$--!*;;r   c                 &    | j                   dz  dk(  S Nr   r"   r   r   s    rh   is_nonpaged_poolzPOOL_HEADER.is_nonpaged_pool       }}q A%%r   )NN)__name__
__module____qualname____doc__r   boolr   strr   r   ObjectInterfaceri   classmethod	functools	lru_cacherj   ContextInterfacer   r   r@   r8   r   r   r    r   rh   r   r      s     .2+/|)"|) |) &c]	|)
 $C=|) 
*$$44	5|)| Y ((99NQ	tCy$s)#	$  :"<&r   r   c                       e Zd ZdZd Zd Zy)POOL_HEADER_VISTAzA kernel pool allocation header, updated for Vista and later.

    Exists at the base of the allocation and provides a tag that we can
    scan for.
    c                 &    | j                   dz  dk(  S r   r   r   s    rh   r   zPOOL_HEADER_VISTA.is_paged_pool  r   r   c                 H    | j                   dz  dk(  xr | j                   dkD  S r   r   r   s    rh   r   z"POOL_HEADER_VISTA.is_nonpaged_pool  r   r   N)r   r   r   r   r   r   r   r   rh   r   r     s    &<r   r   c                       e Zd ZU dZi Zeeef   ed<   d Zde	fdZ
de	fdZdefdZdeeej                  j                   f   fdZdeeej                  j                   f   fd	Zy
)POOL_TRACKER_BIG_PAGESzA kernel big page pool tracker.pool_type_lookupc                 b   | j                   j                  j                  t        j                        d   }| j
                  j                  j                  |t        j                  z   dz         }|j                  j                         D ]#  \  }}|| j                  vs|| j                  |<   % y )Nr   
_POOL_TYPE)r-   r+   r.   r	   r/   r0   r1   get_enumerationchoicesitemsr   )rL   rN   pool_type_enumkvs        rh   _generate_pool_type_lookupz1POOL_TRACKER_BIG_PAGES._generate_pool_type_lookup  s     !HH..44Y^^DQG33CC	.=
 #**002 	-DAq---+,%%a(	-r   r   c                      | j                   dkD  S r~   )Keyr   s    rh   rI   zPOOL_TRACKER_BIG_PAGES.is_valid"  s    xx!|r   c                 &    | j                   dz  dk(  S )z;Returns if the allocation is freed (True) or in-use (False)r"   )Var   s    rh   is_freezPOOL_TRACKER_BIG_PAGES.is_free%  s    ww{ar   c           	          t        j                  | j                  t        t        j                  ddd            }dj                  |D cg c]  }d|cxk  rdk  rn nt        |      nd c}      S c c}w )z-Returns the Key value as a 4 character stringr)   r%   F        )r   convert_value_to_datar   r@   DataFormatInfojoinchr)rL   	tag_bytesxs      rh   get_keyzPOOL_TRACKER_BIG_PAGES.get_key)  s^    11HHc711!XuE
	 ww	J1"q,3,AB6JKKJs   
"A3c                     t        | d      rO| j                  s| j                          | j                  j                  | j                  d| j                         S t        j                         S )zBReturns the enum name for the PoolType value on applicable systemsr   zUnknown choice )hasattrr   r   getr   r   NotApplicableValuer   s    rh   get_pool_typez$POOL_TRACKER_BIG_PAGES.get_pool_type0  sa     4$((//1((,,@  //11r   c                 b    	 | j                   S # t        $ r t        j                         cY S w xY w)z5Returns the NumberOfBytes value on applicable systems)NumberOfBytesru   r   r   r   s    rh   get_number_of_bytesz*POOL_TRACKER_BIG_PAGES.get_number_of_bytes<  s1    	2%%% 	2//11	2s    ..N)r   r   r   r   r   r   r   __annotations__r   r   rI   r   r   r   r   r   BaseAbsentValuer   r@   r   r   r   rh   r   r     s    )')d38n)	-$    L L
2uS**>*>*N*N%NO 
22U3
0D0D0T0T+T%U 2r   r   c                       e Zd ZdZddZy)ExecutiveObjectzyThis is used as a "mixin" that provides all kernel executive objects
    with a means of finding their own object header.c                 h   t         j                  | j                  j                  vrt	        dt         j                   d      | j                  j                  j                  t         j                        d   }| j                  j                  j                  |t         j                  z   dz         j                  d      }| j                  j                  |t         j                  z   dz   | j                  j                  | j                  j                  |z
  | j                  j                        S )N%Invalid symbol table name syntax (no  found)r   r   r   r   )r	   r/   r-   r+   
ValueErrorr.   r0   r1   r2   r6   r4   r   r   r   )rL   rN   rS   s      rh   get_object_headerz!ExecutiveObject.get_object_headerI  s    >>!3!337	7GwO  !HH..44Y^^DQGmm0099	.1AA



' 	 }}##	.1AAxx**88??[0"hh88	 $ 
 	
r   N)r   OBJECT_HEADER)r   r   r   r   r   r   r   rh   r   r   E  s    8
r   r   c                       e Zd ZdZdefdZ	 d	deeef   dede	e   fdZ
edej                  j                  fd       Zy)
r   zA class for the headers for executive kernel objects, which contains
    quota information, ownership details, naming data, and ACLs.r   c                 x    	 | j                   dkD  s| j                   dk  ry	 y# t        j                  $ r Y yw xY w)z!Determine if the object is valid.r(   r   FT)r!   r
   rH   r   s    rh   rI   zOBJECT_HEADER.is_valid^  sJ    	  9,0A0AA0E 1F
  11 		s   # 99Ntype_mapcookiec                    | j                   j                  dd      | j                   j                  S 	 | j                  j                  j
                  | j                  d<   | j                   j                  S # t        $ r 	 | j                   j                  dz	  |z  | j                  z  dz  }n!# t        t        f$ r | j                  }Y nw xY w|j                  |      | j                  d<   Y | j                   j                  S w xY w)zAcross all Windows versions, the _OBJECT_HEADER embeds details on
        the type of object (i.e. process, file) but the way its embedded
        differs between versions.

        This API abstracts away those details.
        object_header_object_typeNr      )r-   r   r   TypeNameString_volru   r   	TypeIndexrG   )rL   r   r   
type_indexs       rh   get_object_typezOBJECT_HEADER.get_object_typel  s     88<<3T:F88555	N59YY^^5J5JDII12 xx111  	N,#xx!3v=NRVV
"I. ,!^^
, 6>\\*5MDII12xx111	Ns5   -A7 7	D,B.-D.C	DC!DDc                    t         j                  | j                  j                  vrt	        dt         j                   d      | j                  j                  j                  t         j                        d   }|| j                  j                  v r| j                  j                  |   }n| j                  j                  | j                  j                     }|j                  j                  dd       }|"t        d| j                  j                         | j                  j                  || j                  j                  |      }	 | j                  }|dk(  rCt	        dj)                  | j                  j*                  | j                  j                              |j'                  d| j                  j                  | j                  j*                  |z
  | j                  j                  d      }	|	S # t        $ ra d}|j!                  d      j"                  }| j$                  ||d	z
  z  z  }|j'                  d
| j                  j                  ||z         }Y w xY w)Nr   r   r   kernel_virtual_offsetz0Could not find kernel_virtual_offset for layer: )r   r   r   ObpInfoMaskToOffsetr"   zunsigned charzDCould not find _OBJECT_HEADER_NAME_INFO for object at {} of layer {}_OBJECT_HEADER_NAME_INFOT)r   r   r   absolute)r	   r/   r-   r+   r   r.   r0   modulesr=   r   configr   ru   r   moduleNameInfoOffset
get_symboladdressr    r4   formatr   )
rL   rN   ntkrnlmplayerkvoheader_offsetname_info_bitr   calculated_indexr{   s
             rh   NameInfozOBJECT_HEADER.NameInfo  s   >>!3!337	7GwO  !HH..44Y^^DQG 5 55}},,->?HMM(()C)CDE,,""#:DAC{$FtxxGZGZF[\ 
 }}++!dhh.A.A# , H	 //M AV]]HHOOTXX%8%8  &xx**88??]2"hh88 ! 
 7  	M))*?@HHG#}}QRAR0ST$OO8855!11 , M	s   G7 7A&I! I!)N)r   r   r   r   r   rI   r   r@   r   r   r   propertyr   r   r   r   r   r   rh   r   r   Z  si    D$  7;2S#X2032	#26 5*,,<< 5 5r   r   )rE   r   loggingrC   typingr   r   r   r   r   'volatility3.plugins.windows.poolscannerr   volatility3.frameworkr	   r
   r   r   r   r   volatility3.framework.renderersr   	getLoggerr   vollog
StructTyper   r   r   r   r   r   r   r   rh   <module>r      s        5 5 B  7			8	$k&'$$ k&\< <02W// 02f
j((88 
*cG&& cr   