Fix MultipleProcessesReturned caused by parent PID reuse #939
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
As said in #679 and #938 - PPIDs are not guaranteed to be real and can be reused. On the other hand, initial enumeration of processes is done in order of EPROCESS linked list, so new processes should be further in list than older ones.
It means that if we have situation like:
taskhost is further on list, so PPID of csrss.exe is phantom (and should be treated as process without parent) and the real children of PPID 336 are placed further in list.
In this PR:
MissingParentProcessError
because we shouldn't throw an exception in that case: even if something weird happened with parent, we still have valuable information for newly created process that can be tracked - there is no point to throw whole entry because of that.closes #679, closes #938