mirror of
https://github.com/nikaiw/VMkatz
synced 2026-09-25 07:51:06 +00:00
Fix VDI parent resolution and coalesce_pages overflow
- VDI: search for location= attribute AFTER the UUID match, not in a window that extends 200 bytes before it. Prevents picking a location from a different HardDisk entry in multi-disk .vbox files. - dump: use saturating_add/sub in coalesce_pages to prevent u64 overflow on kernel addresses near 0xFFFFFFFFFFFFF000.
This commit is contained in:
+3
-2
@@ -160,8 +160,9 @@ fn parse_vbox_for_disk(
|
||||
// Format: <HardDisk uuid="{UUID}" location="path" ...>
|
||||
let needle = format!("uuid=\"{{{}}}", parent_uuid_str);
|
||||
let idx = content.find(&needle)?;
|
||||
// Find location attribute near this uuid
|
||||
let region = &content[idx.saturating_sub(200)..content.len().min(idx + 500)];
|
||||
// Find location attribute AFTER the UUID match (not before, to avoid picking
|
||||
// a location from a different HardDisk entry earlier in the XML)
|
||||
let region = &content[idx..content.len().min(idx + 500)];
|
||||
let loc_marker = "location=\"";
|
||||
let loc_start = region.find(loc_marker)? + loc_marker.len();
|
||||
let loc_end = region[loc_start..].find('"')? + loc_start;
|
||||
|
||||
+5
-5
@@ -205,23 +205,23 @@ fn coalesce_pages(sorted_vas: &[u64]) -> Vec<MemoryRegion> {
|
||||
}
|
||||
|
||||
let mut start = sorted_vas[0];
|
||||
let mut end = start + 0x1000;
|
||||
let mut end = start.saturating_add(0x1000);
|
||||
|
||||
for &va in &sorted_vas[1..] {
|
||||
if va == end {
|
||||
end += 0x1000;
|
||||
end = end.saturating_add(0x1000);
|
||||
} else {
|
||||
regions.push(MemoryRegion {
|
||||
start_va: start,
|
||||
size: end - start,
|
||||
size: end.saturating_sub(start),
|
||||
});
|
||||
start = va;
|
||||
end = va + 0x1000;
|
||||
end = va.saturating_add(0x1000);
|
||||
}
|
||||
}
|
||||
regions.push(MemoryRegion {
|
||||
start_va: start,
|
||||
size: end - start,
|
||||
size: end.saturating_sub(start),
|
||||
});
|
||||
|
||||
regions
|
||||
|
||||
Reference in New Issue
Block a user