forked from Velocidex/velociraptor
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathresult_sets.go
87 lines (68 loc) · 1.49 KB
/
result_sets.go
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
package reporting
import (
"encoding/binary"
"io"
"time"
"www.velocidex.com/golang/velociraptor/json"
"www.velocidex.com/golang/vfilter"
)
type ContainerResultSetWriter struct {
idx_fd io.WriteCloser
fd io.WriteCloser
offset uint64
}
func (self *ContainerResultSetWriter) Close() {
self.idx_fd.Close()
self.fd.Close()
}
func (self *ContainerResultSetWriter) WriteJSONL(b []byte) (int, error) {
value := self.offset | (1 << 40)
err := binary.Write(self.idx_fd, binary.LittleEndian, value)
if err != nil {
return 0, err
}
n, err := self.fd.Write(b)
if err != nil {
return n, err
}
self.offset += uint64(n)
return n, nil
}
func (self *ContainerResultSetWriter) Write(row vfilter.Row) error {
value := self.offset | (1 << 40)
err := binary.Write(self.idx_fd, binary.LittleEndian, value)
if err != nil {
return err
}
serialized, err := json.Marshal(row)
if err != nil {
return err
}
n, err := self.fd.Write(serialized)
if err != nil {
return err
}
self.offset += uint64(n)
n, err = self.fd.Write([]byte("\n"))
if err != nil {
return err
}
self.offset += uint64(n)
return nil
}
func NewResultSetWriter(container *Container, filename string) (
*ContainerResultSetWriter, error) {
fd, err := container.Create(filename, time.Time{})
if err != nil {
return nil, err
}
idx_fd, err := container.Create(filename+".index", time.Time{})
if err != nil {
fd.Close()
return nil, err
}
return &ContainerResultSetWriter{
fd: fd,
idx_fd: idx_fd,
}, nil
}