Bug 1262641 - hivexsh failed to open Windows registry hive
hivexsh failed to open Windows registry hive
Status: CLOSED NOTABUG
Product: Red Hat Enterprise Linux 6
Classification: Red Hat
Component: hivex (Show other bugs)
6.7
x86_64 Linux
unspecified Severity unspecified
: rc
: ---
Assigned To: Richard W.M. Jones
Virtualization Bugs
:
Depends On:
Blocks:
  Show dependency treegraph
 
Reported: 2015-09-13 15:37 EDT by Mykola Ivanets
Modified: 2015-09-14 05:15 EDT (History)
1 user (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed: 2015-09-14 05:15:24 EDT
Type: Bug
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)
Compressed Windows registry hive (47.83 KB, application/x-gzip)
2015-09-13 15:37 EDT, Mykola Ivanets
no flags Details

  None (edit)
Description Mykola Ivanets 2015-09-13 15:37:14 EDT
Created attachment 1073001 [details]
Compressed Windows registry hive

Description of problem:
hivexsh failed to open certain Windows registry hive. Here is an output of the following command 'hivexsh -d SOFTWARE':

hivex_open: created handle 0x19c3030
hivex_open: mapped file at 0x7fd50ebf7000
hivex: SOFTWARE: not a Windows NT Registry hive file
hivexsh: failed to open hive file: SOFTWARE: Operation not supported


Version-Release number of selected component (if applicable):
1.3.3

How reproducible:
Try to load attached hive with hivexsh

Steps to Reproduce:
1. Load attached hive

Actual results:
An error is displayed: "hivexsh failed to open certain Windows registry hive"

Expected results:
A hive is successfully loaded

Additional info:
It is SOFTWARE hive from Windows 8
Comment 2 Mykola Ivanets 2015-09-13 16:09:25 EDT
It is also reproduced on CentOS 7.1 with hivex 1.3.10
Comment 3 Richard W.M. Jones 2015-09-13 16:12:31 EDT
The hive is missing the first 0x2700000 bytes (about 40 MB), which
all appear as zeros.  A normal hive file -- as far as we know -- would
begin with the magic signature "regf" followed by a header.

See:

  https://github.com/libguestfs/hivex/blob/master/lib/tools/visualizer.ml#L55

for the kind of thing we expect at the start of the hive.

The file contains some 'hbin' sections.

While it is possible this is some kind of hive we have never seen
before, I suspect that actually the file is corrupt.
Comment 4 Mykola Ivanets 2015-09-13 16:29:10 EDT
Interesting... The hive was taken from offline image of Windows 8. The image was set up and running under Virtual Box on CentOS 6.7. And OS VM is working. I will try to setup VM once again and post result here.
Comment 5 Mykola Ivanets 2015-09-13 19:00:39 EDT
Richard, I repeated all steps from the scratch (starting from installing fresh copy of the Windows 8) and it appeared that everything works as expected. As you said header of registry hive is 'regf' and this time hivex reads it without a problem. You can close or delete this ticket.
Comment 6 Richard W.M. Jones 2015-09-14 05:15:24 EDT
Thanks for checking.  Closing per comment 5.

Note You need to log in before you can comment on or make changes to this bug.