@@ -56,9 +56,9 @@ func TestCreateFile(t *testing.T) {
5656 Tid : 2484 ,
5757 PID : 859 ,
5858 Kparams : kevent.Kparams {
59- kparams .FileObject : {Name : kparams .FileObject , Type : kparams .Uint64 , Value : kparams .Hex ("12456738026482168384" )},
59+ kparams .FileObject : {Name : kparams .FileObject , Type : kparams .HexInt64 , Value : kparams .Hex ("12456738026482168384" )},
6060 kparams .FileName : {Name : kparams .FileName , Type : kparams .UnicodeString , Value : "\\ Device\\ HarddiskVolume2\\ Windows\\ system32\\ user32.dll" },
61- kparams .FileIrpPtr : {Name : kparams .FileIrpPtr , Type : kparams .Uint64 , Value : kparams .Hex ("1234543123112321" )},
61+ kparams .FileIrpPtr : {Name : kparams .FileIrpPtr , Type : kparams .HexInt64 , Value : kparams .Hex ("1234543123112321" )},
6262 },
6363 })
6464 require .NoError (t , err )
@@ -68,12 +68,12 @@ func TestCreateFile(t *testing.T) {
6868 Tid : 2484 ,
6969 PID : 859 ,
7070 Kparams : kevent.Kparams {
71- kparams .FileObject : {Name : kparams .FileObject , Type : kparams .Uint64 , Value : kparams .Hex ("18446738026482168384" )},
71+ kparams .FileObject : {Name : kparams .FileObject , Type : kparams .HexInt64 , Value : kparams .Hex ("18446738026482168384" )},
7272 kparams .ThreadID : {Name : kparams .ThreadID , Type : kparams .Uint32 , Value : uint32 (1484 )},
7373 kparams .FileCreateOptions : {Name : kparams .FileCreateOptions , Type : kparams .Uint32 , Value : uint32 (1223456 )},
7474 kparams .FileName : {Name : kparams .FileName , Type : kparams .UnicodeString , Value : "\\ Device\\ HarddiskVolume2\\ Windows\\ system32\\ kernel32.dll" },
7575 kparams .FileShareMask : {Name : kparams .FileShareMask , Type : kparams .Uint32 , Value : uint32 (5 )},
76- kparams .FileIrpPtr : {Name : kparams .FileIrpPtr , Type : kparams .Uint64 , Value : kparams .Hex ("1234543123112321" )},
76+ kparams .FileIrpPtr : {Name : kparams .FileIrpPtr , Type : kparams .HexInt64 , Value : kparams .Hex ("1234543123112321" )},
7777 },
7878 }
7979 devMapper .On ("Convert" , "\\ Device\\ HarddiskVolume2\\ Windows\\ system32\\ kernel32.dll" ).Return (fmt .Sprintf ("%s\\ system32\\ kernel32.dll" , sysRoot ))
@@ -89,10 +89,10 @@ func TestCreateFile(t *testing.T) {
8989 Tid : 2484 ,
9090 PID : 859 ,
9191 Kparams : kevent.Kparams {
92- kparams .FileObject : {Name : kparams .FileObject , Type : kparams .Uint64 , Value : kparams .Hex ("18446738026482168384" )},
92+ kparams .FileObject : {Name : kparams .FileObject , Type : kparams .HexInt64 , Value : kparams .Hex ("18446738026482168384" )},
9393 kparams .ThreadID : {Name : kparams .ThreadID , Type : kparams .Uint32 , Value : uint32 (1484 )},
94- kparams .FileIrpPtr : {Name : kparams .FileIrpPtr , Type : kparams .Uint64 , Value : kparams .Hex ("1234543123112321" )},
95- kparams .FileExtraInfo : {Name : kparams .FileExtraInfo , Type : kparams .Uint8 , Value : kparams . Hex ( "2" )},
94+ kparams .FileIrpPtr : {Name : kparams .FileIrpPtr , Type : kparams .HexInt64 , Value : kparams .Hex ("1234543123112321" )},
95+ kparams .FileExtraInfo : {Name : kparams .FileExtraInfo , Type : kparams .Uint64 , Value : uint64 ( 2 )},
9696 },
9797 }
9898 kevt1 , _ , err = fsi .Intercept (opEnd )
@@ -125,7 +125,7 @@ func TestRundownFile(t *testing.T) {
125125 Tid : 2484 ,
126126 PID : 859 ,
127127 Kparams : kevent.Kparams {
128- kparams .FileObject : {Name : kparams .FileObject , Type : kparams .Uint64 , Value : kparams .Hex ("124567380264" )},
128+ kparams .FileObject : {Name : kparams .FileObject , Type : kparams .HexInt64 , Value : kparams .Hex ("124567380264" )},
129129 kparams .FileName : {Name : kparams .FileName , Type : kparams .UnicodeString , Value : "\\ Device\\ HarddiskVolume2\\ Windows\\ system32\\ user32.dll" },
130130 },
131131 })
@@ -155,7 +155,7 @@ func TestDeleteFile(t *testing.T) {
155155 Tid : 2484 ,
156156 PID : 859 ,
157157 Kparams : kevent.Kparams {
158- kparams .FileObject : {Name : kparams .FileObject , Type : kparams .Uint64 , Value : kparams .Hex ("12456738026482168384" )},
158+ kparams .FileObject : {Name : kparams .FileObject , Type : kparams .HexInt64 , Value : kparams .Hex ("12456738026482168384" )},
159159 kparams .FileName : {Name : kparams .FileName , Type : kparams .UnicodeString , Value : "\\ Device\\ HarddiskVolume2\\ Windows\\ system32\\ user32.dll" },
160160 },
161161 })
@@ -166,8 +166,8 @@ func TestDeleteFile(t *testing.T) {
166166 Tid : 2484 ,
167167 PID : 859 ,
168168 Kparams : kevent.Kparams {
169- kparams .FileObject : {Name : kparams .FileObject , Type : kparams .Uint64 , Value : kparams .Hex ("12456738026482168384" )},
170- kparams .FileKey : {Name : kparams .FileKey , Type : kparams .Uint64 , Value : kparams .Hex ("12456738026482168384" )},
169+ kparams .FileObject : {Name : kparams .FileObject , Type : kparams .HexInt64 , Value : kparams .Hex ("12456738026482168384" )},
170+ kparams .FileKey : {Name : kparams .FileKey , Type : kparams .HexInt64 , Value : kparams .Hex ("12456738026482168384" )},
171171 kparams .ThreadID : {Name : kparams .ThreadID , Type : kparams .Uint32 , Value : uint32 (1484 )},
172172 },
173173 }
0 commit comments