Support find the pool tag by text

This commit is contained in:
CORP\zengquan
2022-08-22 17:37:57 +08:00
parent 80881a7241
commit 4e611829f9
12 changed files with 258 additions and 35 deletions
+4 -1
View File
@@ -18,7 +18,10 @@ struct IRegView abstract {
};
struct IView {
virtual bool IsFindSupported() const {
return false;
}
virtual void DoFind(const CString& text,DWORD flags){}
};
struct QuickFindOptions {
+43 -3
View File
@@ -175,8 +175,6 @@ void CKernelPoolView::UpdateVisible() {
}
BOOL CKernelPoolView::PreTranslateMessage(MSG* pMsg) {
if (m_pFindDialog && m_pFindDialog->IsDialogMessageW(pMsg))
return TRUE;
return FALSE;
}
@@ -528,4 +526,46 @@ LRESULT CKernelPoolView::OnRBtnDown(UINT /*uMsg*/, WPARAM /*wParam*/, LPARAM /*l
return 0;
}
}
void CKernelPoolView::DoFind(const CString& text, DWORD flags) {
auto searchDown = flags & FR_DOWN;
int start = GetSelectedIndex();
CString find(text);
auto ignoreCase = !(flags & FR_MATCHCASE);
if (ignoreCase)
find.MakeLower();
int from = searchDown ? start + 1 : start - 1 + GetItemCount();
int to = searchDown ? GetItemCount() + start : start + 1;
int step = searchDown ? 1 : -1;
int findIndex = -1;
for (int i = from; i != to; i += step) {
int index = i % GetItemCount();
const auto& item = m_Tags[index];
CString text(item->Tag);
if (ignoreCase)
text.MakeLower();
if (text.Find(find) >= 0) {
findIndex = index;
break;
}
text = item->SourceName;
if (ignoreCase)
text.MakeLower();
if (text.Find(find) >= 0) {
findIndex = index;
break;
}
}
if (findIndex >= 0) {
SelectItem(findIndex);
}
else
AtlMessageBox(m_hWnd, L"Not found");
}
+9 -2
View File
@@ -40,7 +40,8 @@ struct CellColor :CellColorKey {
class CKernelPoolView :
public CWindowImpl<CKernelPoolView, CListViewCtrl>,
public CCustomDraw<CKernelPoolView>,
public CIdleHandler {
public CIdleHandler,
public IView{
public:
enum ColumnType {
TagName,
@@ -94,6 +95,12 @@ public:
BOOL OnIdle() override;
// IView
bool IsFindSupported() const override {
return true;
}
void DoFind(const CString& text, DWORD flags) override;
BEGIN_MSG_MAP(CKernelPoolView)
MESSAGE_HANDLER(WM_TIMER, OnTimer)
MESSAGE_HANDLER(WM_CREATE, OnCreate)
@@ -120,12 +127,12 @@ public:
void UpdatePaneText();
LRESULT OnRefresh(WORD /*wNotifyCode*/, WORD /*wID*/, HWND /*hWndCtl*/, BOOL& /*bHandled*/);
private:
std::unordered_map<CellColorKey, CellColor> m_CellColors;
int m_SortColumn = -1;
CImageList m_Images;
CFindReplaceDialog* m_pFindDialog{ nullptr };
int m_UpdateInterval = 1000;
size_t m_TotalPaged = 0, m_TotalNonPaged = 0;
std::unordered_map<ULONG, std::shared_ptr<TagItem>> m_TagsMap;
+16
View File
@@ -164,4 +164,20 @@ void CKernelView::InitUnloadedDriverTable() {
m_UnloadedDriverTable->Create(m_hWnd, rect, nullptr, WS_CHILD | WS_VSCROLL | WS_HSCROLL | WS_BORDER | WS_EX_LAYERED);
m_hwndArray[static_cast<int>(TabColumn::UnloadedDriverTable)] = m_UnloadedDriverTable->m_hWnd;
m_UnloadedDriverTable->ShowWindow(SW_HIDE);
}
IView* CKernelView::GetCurView() {
int index = 0;
index = m_TabCtrl.GetCurSel();
switch (static_cast<TabColumn>(index)) {
case TabColumn::PiDDBCacheTable:
return m_PiDDBCacheTable;
case TabColumn::UnloadedDriverTable:
break;
case TabColumn::KernelPoolTable:
return m_KernelPoolView;
}
return nullptr;
}
+2
View File
@@ -2,6 +2,7 @@
#include "PiDDBCacheTable.h"
#include "UnloadedDriverTable.h"
#include "KernelPoolView.h"
#include "Interfaces.h"
class CKernelView :
public CWindowImpl<CKernelView> {
@@ -25,6 +26,7 @@ public:
LRESULT OnSize(UINT /*uMsg*/, WPARAM /*wParam*/, LPARAM /*lParam*/, BOOL& /*bHandled*/);
LRESULT OnTcnSelChange(int, LPNMHDR hdr, BOOL&);
IView* GetCurView();
enum class TabColumn : int {
PiDDBCacheTable,UnloadedDriverTable,KernelPoolTable,
+90 -7
View File
@@ -311,6 +311,13 @@ LRESULT CMainFrame::OnCreate(UINT /*uMsg*/, WPARAM /*wParam*/, LPARAM /*lParam*/
HWND hWndCmdBar = m_CmdBar.Create(m_hWnd, rcDefault, nullptr, ATL_SIMPLE_CMDBAR_PANE_STYLE);
CMenuHandle hMenu = GetMenu();
if (SecurityHelper::IsRunningElevated()) {
hMenu.GetSubMenu(0).DeleteMenu(ID_FILE_RUNASADMIN, MF_BYCOMMAND);
CString text;
GetWindowText(text);
SetWindowText(text + L" (Administrator)");
}
UIAddMenu(hMenu);
/*m_CmdBar.AttachMenu(hMenu);
m_CmdBar.m_bAlphaImages = true;
@@ -318,8 +325,6 @@ LRESULT CMainFrame::OnCreate(UINT /*uMsg*/, WPARAM /*wParam*/, LPARAM /*lParam*/
InitCommandBar();
AddSimpleReBarBand(hWndCmdBar);
/*auto submenu = menu.GetSubMenu(1);
WCHAR text[64];
menu.GetMenuString(1, text, _countof(text), MF_BYPOSITION);
@@ -349,7 +354,7 @@ LRESULT CMainFrame::OnCreate(UINT /*uMsg*/, WPARAM /*wParam*/, LPARAM /*lParam*/
r.bottom = 25;
auto hTabCtrl = tabCtrl.Create(m_hWnd, &r, nullptr, WS_CHILDWINDOW | WS_VISIBLE | WS_CLIPSIBLINGS
| TCS_HOTTRACK | TCS_SINGLELINE | TCS_RIGHTJUSTIFY | TCS_TABS,
WS_EX_LEFT | WS_EX_LTRREADING | WS_EX_RIGHTSCROLLBAR | WS_EX_NOPARENTNOTIFY, TabId);
WS_EX_LEFT | WS_EX_LTRREADING | WS_EX_RIGHTSCROLLBAR | WS_EX_NOPARENTNOTIFY,TabId);
m_TabCtrl.SubclassWindow(hTabCtrl);
// 初始化选择夹
struct {
@@ -373,10 +378,8 @@ LRESULT CMainFrame::OnCreate(UINT /*uMsg*/, WPARAM /*wParam*/, LPARAM /*lParam*/
for (auto& col : columns) {
m_TabCtrl.InsertItem(i++, col.Name);
}
HFONT hFont = (HFONT)::GetStockObject(SYSTEM_FIXED_FONT);
m_TabCtrl.SetFont(hFont, true);
::DeleteObject(hFont);
AddSimpleReBarBand(m_TabCtrl);
m_TabCtrl.SetFont(g_hAppFont, true);
AddSimpleReBarBand(m_TabCtrl, nullptr, TRUE, 0, TRUE);
auto hWndToolBar = m_tb.Create(m_hWnd, nullptr, nullptr, ATL_SIMPLE_TOOLBAR_PANE_STYLE | TBSTYLE_LIST, 0, ATL_IDW_TOOLBAR);
m_tb.SetExtendedStyle(TBSTYLE_EX_MIXEDBUTTONS);
@@ -919,4 +922,84 @@ void CMainFrame::SaveSettings(PCWSTR filename) {
ThemeColor(L"条件断点颜色",g_myColor[Magenta]),
};
SaveColors(filename, L"TableColor", Colors, _countof(Colors));
}
LRESULT CMainFrame::OnEditFind(WORD, WORD, HWND, BOOL&) {
int index = m_TabCtrl.GetCurSel();
m_hWndClient = m_hwndArray[index];
switch (static_cast<TabColumn>(index)) {
case TabColumn::Process:
//m_pProcTable->ShowWindow(SW_SHOW);
//m_pProcTable->SetFocus();
break;
case TabColumn::Network:
/*m_pNetTable->ShowWindow(SW_SHOW);
m_pNetTable->SetFocus();*/
break;
case TabColumn::KernelModule:
/* m_pKernelModuleTable->ShowWindow(SW_SHOW);
m_pKernelModuleTable->SetFocus();*/
break;
case TabColumn::Driver:
/*m_pDriverTable->ShowWindow(SW_SHOW);
m_pDriverTable->SetFocus();*/
break;
case TabColumn::Registry:
//m_RegView.ShowWindow(SW_SHOW);
break;
case TabColumn::Device:
//m_DevView.ShowWindow(SW_SHOW);
break;
case TabColumn::Windows:
//m_WinView.ShowWindow(SW_SHOW);
break;
case TabColumn::KernelHook:
//m_KernelHookView.ShowWindow(SW_SHOW);
break;
case TabColumn::Service:
/*m_pServiceTable->ShowWindow(SW_SHOW);
m_pServiceTable->SetFocus();*/
break;
case TabColumn::Kernel:
{
m_IView = m_KernelView->GetCurView();
if (m_IView && m_IView->IsFindSupported()) {
if (!m_pFindDlg) {
m_pFindDlg = new CFindReplaceDialog;
m_pFindDlg->Create(TRUE, m_FindText, nullptr, FR_DOWN, m_hWnd);
}
if (!m_pFindDlg->IsWindowVisible()) {
m_pFindDlg->ShowWindow(SW_SHOW);
}
m_pFindDlg->BringWindowToTop();
m_pFindDlg->SetFocus();
}
break;
}
case TabColumn::Config:
//m_SysConfigView.ShowWindow(SW_SHOW);
break;
case TabColumn::Etw:
//m_pEtwView->ShowWindow(SW_SHOW);
break;
default:
break;
}
return 0;
}
LRESULT CMainFrame::OnFindReplaceMessage(UINT /*uMsg*/, WPARAM id, LPARAM lParam, BOOL& handled) {
auto fr = reinterpret_cast<FINDREPLACE*>(lParam);
if (fr->Flags & FR_DIALOGTERM) {
m_pFindDlg->DestroyWindow();
m_pFindDlg = nullptr;
return 0;
}
m_FindText = fr->lpstrFindWhat;
m_FindFlags = fr->Flags;
m_IView->DoFind(m_FindText, m_FindFlags);
return 0;
}
+13 -3
View File
@@ -111,10 +111,12 @@ public:
COMMAND_ID_HANDLER(ID_SEARCH_QUICKFIND,OnQuickFind)
COMMAND_ID_HANDLER(ID_OPTIONS_COLORS,OnColors)
COMMAND_ID_HANDLER(ID_OPTIONS_FONT, OnOptionsFont)
MESSAGE_HANDLER(CFindReplaceDialog::GetFindReplaceMsg(), OnFindReplaceMessage)
COMMAND_ID_HANDLER(ID_EDIT_FIND, OnEditFind)
COMMAND_RANGE_HANDLER(0x8000, 0xefff, OnForwardToActiveView)
NOTIFY_HANDLER(TabId, TCN_SELCHANGE, OnTcnSelChange)
CHAIN_MSG_MAP(CAutoUpdateUI<CMainFrame>)
CHAIN_MSG_MAP(CFrameWindowImpl<CMainFrame>)
COMMAND_RANGE_HANDLER(0x8000,0xefff,OnForwardToActiveView)
REFLECT_NOTIFICATIONS()
END_MSG_MAP()
public:
@@ -132,6 +134,9 @@ public:
LRESULT OnTimer(UINT /*uMsg*/, WPARAM /*wParam*/, LPARAM /*lParam*/, BOOL& /*bHandled*/);
LRESULT OnAppAbout(WORD /*wNotifyCode*/, WORD /*wID*/, HWND /*hWndCtl*/, BOOL& /*bHandled*/);
LRESULT OnFindReplaceMessage(UINT /*uMsg*/, WPARAM id, LPARAM lParam, BOOL& handled);
LRESULT OnMonitorStop(WORD /*wNotifyCode*/, WORD /*wID*/, HWND /*hWndCtl*/, BOOL& /*bHandled*/);
LRESULT OnMonitorPause(WORD /*wNotifyCode*/, WORD /*wID*/, HWND /*hWndCtl*/, BOOL& /*bHandled*/);
LRESULT OnMonitorStart(WORD /*wNotifyCode*/, WORD /*wID*/, HWND /*hWndCtl*/, BOOL& /*bHandled*/);
@@ -139,7 +144,7 @@ public:
LRESULT OnQuickFind(WORD /*wNotifyCode*/, WORD /*wID*/, HWND /*hWndCtl*/, BOOL& /*bHandled*/);
LRESULT OnColors(WORD /*wNotifyCode*/, WORD /*wID*/, HWND /*hWndCtl*/, BOOL& /*bHandled*/);
LRESULT OnOptionsFont(WORD /*wNotifyCode*/, WORD /*wID*/, HWND /*hWndCtl*/, BOOL& /*bHandled*/);
LRESULT OnEditFind(WORD, WORD, HWND, BOOL&);
private:
void InitProcessToolBar(CToolBarCtrl& tb);
@@ -167,7 +172,7 @@ private:
CDeviceManagerView m_DevView;
CWindowsView m_WinView;
CKernelHookView m_KernelHookView;
CKernelView* m_KernelView;
CKernelView* m_KernelView{ nullptr };
CSystemConfigDlg m_SysConfigView;
@@ -187,4 +192,9 @@ private:
CommandManager m_CmdMgr;
CEdit m_Edit;
bool m_AllowModify{ true };
CFindReplaceDialog* m_pFindDlg{ nullptr };
inline static CString m_FindText;
inline static DWORD m_FindFlags{ 0 };
inline static IView* m_IView;
};
+41
View File
@@ -238,4 +238,45 @@ LRESULT CPiDDBCacheTable::OnRefresh(WORD /*wNotifyCode*/, WORD /*wID*/, HWND /*h
Refresh();
return TRUE;
}
void CPiDDBCacheTable::DoFind(const CString& text, DWORD flags) {
auto searchDown = flags & FR_DOWN;
int start = m_Table.data.selected;
CString find(text);
auto ignoreCase = !(flags & FR_MATCHCASE);
if (ignoreCase)
find.MakeLower();
int from = searchDown ? start + 1 : start - 1 + m_Table.data.n;
int to = searchDown ? m_Table.data.n + start : start + 1;
int step = searchDown ? 1 : -1;
int findIndex = -1;
for (int i = from; i != to; i += step) {
int index = i % m_Table.data.n;
const auto& item = m_Table.data.info[i];
CString text(item.DriverName.c_str());
if (ignoreCase)
text.MakeLower();
if (text.Find(find) >= 0) {
findIndex = index;
break;
}
text.Format(L"0x%X ", item.TimeDateStamp);
if (ignoreCase)
text.MakeLower();
if (text.Find(find) >= 0) {
findIndex = index;
break;
}
}
if (findIndex >= 0) {
}
else
AtlMessageBox(m_hWnd, L"Not found");
}
+8 -2
View File
@@ -1,7 +1,7 @@
#pragma once
#include "Table.h"
#include "resource.h"
#include "Interfaces.h"
struct PiDDBCacheInfo {
std::wstring DriverName;
@@ -11,7 +11,8 @@ struct PiDDBCacheInfo {
class CPiDDBCacheTable :
public CTable<PiDDBCacheInfo>,
public CWindowImpl<CPiDDBCacheTable> {
public CWindowImpl<CPiDDBCacheTable>,
public IView{
public:
DECLARE_WND_CLASS_EX(NULL, CS_DBLCLKS | CS_VREDRAW | CS_HREDRAW,COLOR_WINDOW);
@@ -19,6 +20,11 @@ public:
int ParseTableEntry(CString& s, char& mask, int& select, PiDDBCacheInfo& info, int column);
bool CompareItems(const PiDDBCacheInfo& s1, const PiDDBCacheInfo& s2, int col, bool asc);
// IView
bool IsFindSupported() const override {
return true;
}
void DoFind(const CString& text, DWORD flags) override;
BEGIN_MSG_MAP(CPiDDBCacheTable)
MESSAGE_HANDLER(WM_DESTROY, OnDestroy)
-2
View File
@@ -212,8 +212,6 @@ public:
return t.pid;
}
static void Addsorteddata(const T& t);
static void Deletesorteddata(ulong addr);
+30 -14
View File
@@ -733,6 +733,10 @@ BEGIN
MENUITEM "&Run as Administrator", ID_FILE_RUNASADMIN
MENUITEM "E&xit", IDM_EXIT
END
POPUP "&Edit"
BEGIN
MENUITEM "&Find...\tCtrl+F", ID_EDIT_FIND
END
POPUP "&Options"
BEGIN
MENUITEM "&Always on Top", ID_OPTIONS_ALWAYSONTOP
@@ -854,6 +858,17 @@ IDI_GOTO ICON "res\\goto.ico"
IDR_POOLTAG TXT "res\\pooltag.txt"
/////////////////////////////////////////////////////////////////////////////
//
// String Table
//
STRINGTABLE
BEGIN
ID_EDIT_FIND "Find the specified text\nFind"
END
#endif // Chinese (Simplified, PRC) resources
/////////////////////////////////////////////////////////////////////////////
@@ -1232,20 +1247,21 @@ END
IDR_MAINFRAME ACCELERATORS
BEGIN
"N", ID_FILE_NEW, VIRTKEY, CONTROL
"O", ID_FILE_OPEN, VIRTKEY, CONTROL
"S", ID_FILE_SAVE, VIRTKEY, CONTROL
"P", ID_FILE_PRINT, VIRTKEY, CONTROL
"Z", ID_EDIT_UNDO, VIRTKEY, CONTROL
"X", ID_EDIT_CUT, VIRTKEY, CONTROL
"C", ID_EDIT_COPY, VIRTKEY, CONTROL
"V", ID_EDIT_PASTE, VIRTKEY, CONTROL
VK_BACK, ID_EDIT_UNDO, VIRTKEY, ALT
VK_DELETE, ID_EDIT_CUT, VIRTKEY, SHIFT
VK_INSERT, ID_EDIT_COPY, VIRTKEY, CONTROL
VK_INSERT, ID_EDIT_PASTE, VIRTKEY, SHIFT
VK_F6, ID_NEXT_PANE, VIRTKEY
VK_F6, ID_PREV_PANE, VIRTKEY, SHIFT
"C", ID_EDIT_COPY, VIRTKEY, CONTROL, NOINVERT
VK_INSERT, ID_EDIT_COPY, VIRTKEY, CONTROL, NOINVERT
VK_DELETE, ID_EDIT_CUT, VIRTKEY, SHIFT, NOINVERT
"X", ID_EDIT_CUT, VIRTKEY, CONTROL, NOINVERT
"V", ID_EDIT_PASTE, VIRTKEY, CONTROL, NOINVERT
VK_INSERT, ID_EDIT_PASTE, VIRTKEY, SHIFT, NOINVERT
VK_BACK, ID_EDIT_UNDO, VIRTKEY, ALT, NOINVERT
"Z", ID_EDIT_UNDO, VIRTKEY, CONTROL, NOINVERT
"N", ID_FILE_NEW, VIRTKEY, CONTROL, NOINVERT
"O", ID_FILE_OPEN, VIRTKEY, CONTROL, NOINVERT
"P", ID_FILE_PRINT, VIRTKEY, CONTROL, NOINVERT
"S", ID_FILE_SAVE, VIRTKEY, CONTROL, NOINVERT
VK_F6, ID_NEXT_PANE, VIRTKEY, NOINVERT
VK_F6, ID_PREV_PANE, VIRTKEY, SHIFT, NOINVERT
"F", ID_EDIT_FIND, VIRTKEY, CONTROL, NOINVERT
END
+2 -1
View File
@@ -340,13 +340,14 @@
#define ID_OPTIONS_COLORS 32936
#define ID_OPTIONS_FONT 32937
#define ID_POOLTAG_REFRESH 32938
#define ID_EDIT_FIND32939 32939
// Next default values for new objects
//
#ifdef APSTUDIO_INVOKED
#ifndef APSTUDIO_READONLY_SYMBOLS
#define _APS_NEXT_RESOURCE_VALUE 278
#define _APS_NEXT_COMMAND_VALUE 32939
#define _APS_NEXT_COMMAND_VALUE 32942
#define _APS_NEXT_CONTROL_VALUE 1093
#define _APS_NEXT_SYMED_VALUE 101
#endif