MCPcopy Create free account
hub / github.com/ComodoSecurity/openedr / updateFileRules

Method updateFileRules

edrav2/iprj/libsysmon/src/controller.cpp:625–656  ·  view source on GitHub ↗

Source from the content-addressed store, hash-verified

623//
624//
625void SystemMonitorController::updateFileRules(Variant vParams)
626{
627 TRACE_BEGIN;
628
629 // Normalize passed rules[].path
630 if (vParams.get("rules", Variant()).isSequenceLike())
631 {
632 auto pFileInformation = queryInterface<sys::win::IFileInformation>(queryService("fileDataProvider"));
633
634 // Clone before modification
635 vParams = vParams.clone();
636
637 Variant vRules = vParams.get("rules", Variant());
638 for (auto vRule : vRules)
639 {
640 Variant vPath;
641 CMD_TRY
642 {
643 vPath = vRule.get("path", Variant());
644 if (!vPath.isString())
645 continue;
646 std::wstring sPath = vPath;
647 std::wstring sNtPath = pFileInformation->normalizePathName(sPath, {}, sys::win::PathType::NtPath);
648 vRule.put("path", sNtPath);
649 }
650 CMD_PREPARE_CATCH
651 catch (error::Exception& e)
652 {
653 e.log(SL, FMT("Can't normalize path <" << vPath << ">"));
654 }
655 }
656 }
657
658 // Call IOCTL
659 std::vector<uint8_t> data;

Callers

nothing calls this directly

Calls 8

queryServiceFunction · 0.85
isSequenceLikeMethod · 0.80
normalizePathNameMethod · 0.80
VariantClass · 0.50
getMethod · 0.45
cloneMethod · 0.45
isStringMethod · 0.45
putMethod · 0.45

Tested by

no test coverage detected