From 2cf35b91ee95540c514ad5eca85920c2982001fa Mon Sep 17 00:00:00 2001 From: Mike Auty Date: Tue, 10 Mar 2026 12:03:45 +0000 Subject: [PATCH] Attempt to fix the local filepath not being detected correctly --- volatility3/framework/automagic/symbol_cache.py | 10 +++++++--- 1 file changed, 7 insertions(+), 3 deletions(-) diff --git a/volatility3/framework/automagic/symbol_cache.py b/volatility3/framework/automagic/symbol_cache.py index ff75e86c6..f0029d0f5 100644 --- a/volatility3/framework/automagic/symbol_cache.py +++ b/volatility3/framework/automagic/symbol_cache.py @@ -6,6 +6,7 @@ import datetime import json import logging import os +import pathlib import sqlite3 import urllib import urllib.parse @@ -495,9 +496,12 @@ class SqliteCache(CacheManagerInterface): vollog.debug( f"Duplicate entry for identifier {row['identifier']}: {row['location']} and {output[row['identifier']]}" ) - local_filepath = self._get_local_filepath(row["location"]) - if local_filepath and not local_filepath.startswith( - tuple(constants.SYMBOL_BASEPATHS) + local_filepath = pathlib.Path(self._get_local_filepath(row["location"])) + if local_filepath and not any( + [ + local_filepath.is_relative_to(basepath) + for basepath in constants.SYMBOL_BASEPATHS + ] ): vollog.debug( f"Location {row['location']} was not in the registered symbol paths and therefore not in the identifier dictionary"