From 17e0b04cb35f44612ecfc07ef7d154eec013c5be Mon Sep 17 00:00:00 2001 From: Gustavo Moreira Date: Fri, 10 Dec 2021 12:20:51 +1100 Subject: [PATCH 1/6] undefined glob module --- volatility3/cli/volshell/__init__.py | 1 + 1 file changed, 1 insertion(+) diff --git a/volatility3/cli/volshell/__init__.py b/volatility3/cli/volshell/__init__.py index f2375c774..94f735ba0 100644 --- a/volatility3/cli/volshell/__init__.py +++ b/volatility3/cli/volshell/__init__.py @@ -7,6 +7,7 @@ import json import logging import os import sys +import glob import volatility3.plugins import volatility3.symbols From 36ac92c11c868490891a53b285b4a9f9093a18d6 Mon Sep 17 00:00:00 2001 From: Gustavo Moreira Date: Fri, 10 Dec 2021 12:27:53 +1100 Subject: [PATCH 2/6] undefined `layers` module --- volatility3/framework/automagic/symbol_finder.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/volatility3/framework/automagic/symbol_finder.py b/volatility3/framework/automagic/symbol_finder.py index 72dc071a5..143abd02e 100644 --- a/volatility3/framework/automagic/symbol_finder.py +++ b/volatility3/framework/automagic/symbol_finder.py @@ -5,7 +5,7 @@ import logging from typing import Any, Iterable, List, Tuple, Type, Optional, Callable -from volatility3.framework import interfaces, constants +from volatility3.framework import interfaces, constants, layers from volatility3.framework.automagic import symbol_cache from volatility3.framework.configuration import requirements from volatility3.framework.layers import scanners From 8e7aff4ad8e14b77d6b792fbc5581499ee89640b Mon Sep 17 00:00:00 2001 From: Gustavo Moreira Date: Fri, 10 Dec 2021 13:09:41 +1100 Subject: [PATCH 3/6] `not in` please --- development/stock-linux-json.py | 2 +- volatility3/cli/__init__.py | 2 +- volatility3/framework/layers/resources.py | 2 +- volatility3/framework/plugins/linux/check_creds.py | 2 +- volatility3/framework/plugins/mac/list_files.py | 4 ++-- 5 files changed, 6 insertions(+), 6 deletions(-) diff --git a/development/stock-linux-json.py b/development/stock-linux-json.py index c863d41e4..877f78e1c 100644 --- a/development/stock-linux-json.py +++ b/development/stock-linux-json.py @@ -87,7 +87,7 @@ class Downloader: output_filename = 'unknown-kernel.json' for named_file in named_files: prefix = '--system-map' - if not 'System' in named_files[named_file]: + if 'System' not in named_files[named_file]: prefix = '--elf' output_filename = './' + '-'.join((named_file.split('/')[-1]).split('-')[2:])[:-4] + '.json.xz' args += [prefix, named_files[named_file]] diff --git a/volatility3/cli/__init__.py b/volatility3/cli/__init__.py index 608fdf79c..2c5e13211 100644 --- a/volatility3/cli/__init__.py +++ b/volatility3/cli/__init__.py @@ -543,7 +543,7 @@ class CommandLine: self._file = io.open(fd, mode = 'w+b') CLIFileHandler.__init__(self, filename) for item in dir(self._file): - if not item.startswith('_') and not item in ['closed', 'close', 'mode', 'name']: + if not item.startswith('_') and item not in ('closed', 'close', 'mode', 'name'): setattr(self, item, getattr(self._file, item)) def __getattr__(self, item): diff --git a/volatility3/framework/layers/resources.py b/volatility3/framework/layers/resources.py index b6ef1b6ba..7ace25290 100644 --- a/volatility3/framework/layers/resources.py +++ b/volatility3/framework/layers/resources.py @@ -82,7 +82,7 @@ class ResourceAccessor(object): """Determines whether a URLs contents should be cached""" parsed_url = urllib.parse.urlparse(url) - return self._enable_cache and not parsed_url.scheme in self._non_cached_schemes() + return self._enable_cache and parsed_url.scheme not in self._non_cached_schemes() @staticmethod def _non_cached_schemes() -> List[str]: diff --git a/volatility3/framework/plugins/linux/check_creds.py b/volatility3/framework/plugins/linux/check_creds.py index 613469eed..9bc1a067d 100644 --- a/volatility3/framework/plugins/linux/check_creds.py +++ b/volatility3/framework/plugins/linux/check_creds.py @@ -44,7 +44,7 @@ class Check_creds(interfaces.plugins.PluginInterface): cred_addr = task.cred.dereference().vol.offset - if not cred_addr in creds: + if cred_addr not in creds: creds[cred_addr] = [] creds[cred_addr].append(task.pid) diff --git a/volatility3/framework/plugins/mac/list_files.py b/volatility3/framework/plugins/mac/list_files.py index 19f28b18f..8bae986b7 100644 --- a/volatility3/framework/plugins/mac/list_files.py +++ b/volatility3/framework/plugins/mac/list_files.py @@ -72,7 +72,7 @@ class List_Files(plugins.PluginInterface): key = vnode.vol.offset added = False - if not key in loop_vnodes: + if key not in loop_vnodes: # We can't do anything with a no-name vnode v_name = cls._vnode_name(vnode) if v_name is None: @@ -108,7 +108,7 @@ class List_Files(plugins.PluginInterface): added = True parent = cls._get_parent(context, vnode) - while parent and not parent in loop_vnodes: + while parent and parent not in loop_vnodes: if not cls._walk_vnode(context, parent, loop_vnodes): break From e1942976bf95d0952d020dccd504c43751dee8a9 Mon Sep 17 00:00:00 2001 From: Gustavo Moreira Date: Fri, 10 Dec 2021 12:24:22 +1100 Subject: [PATCH 4/6] wrong comparison with None --- volatility3/framework/plugins/linux/check_syscall.py | 2 +- volatility3/framework/symbols/windows/extensions/__init__.py | 4 ++-- 2 files changed, 3 insertions(+), 3 deletions(-) diff --git a/volatility3/framework/plugins/linux/check_syscall.py b/volatility3/framework/plugins/linux/check_syscall.py index 729a0bec6..87d252cd5 100644 --- a/volatility3/framework/plugins/linux/check_syscall.py +++ b/volatility3/framework/plugins/linux/check_syscall.py @@ -152,7 +152,7 @@ class Check_syscall(plugins.PluginInterface): except exceptions.SymbolError: ia32_symbol = None - if ia32_symbol != None: + if ia32_symbol is not None: ia32_info = self._get_table_info(vmlinux, "ia32_sys_call_table", ptr_sz) tables.append(("32bit", ia32_info)) diff --git a/volatility3/framework/symbols/windows/extensions/__init__.py b/volatility3/framework/symbols/windows/extensions/__init__.py index ae7c45d04..55f237581 100755 --- a/volatility3/framework/symbols/windows/extensions/__init__.py +++ b/volatility3/framework/symbols/windows/extensions/__init__.py @@ -84,7 +84,7 @@ class MMVAD_SHORT(objects.StructType): if tag in ["VadS", "VadF"]: target = "_MMVAD_SHORT" - elif tag != None and tag.startswith("Vad"): + elif tag is not None and tag.startswith("Vad"): target = "_MMVAD" elif depth == 0: # the root node at depth 0 is allowed to not have a tag @@ -651,7 +651,7 @@ class EPROCESS(generic.GenericIntelProcess, pool.ExecutiveObject): except AttributeError: return False - return value != 0 and value != None + return not value def get_vad_root(self): From d2ad867d1e422579e3ef024d342bfeb0658a054f Mon Sep 17 00:00:00 2001 From: Gustavo Moreira Date: Fri, 10 Dec 2021 13:20:43 +1100 Subject: [PATCH 5/6] my mistake, it should be negated twice to get True when is valid --- volatility3/framework/symbols/windows/extensions/__init__.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/volatility3/framework/symbols/windows/extensions/__init__.py b/volatility3/framework/symbols/windows/extensions/__init__.py index 55f237581..7c931f148 100755 --- a/volatility3/framework/symbols/windows/extensions/__init__.py +++ b/volatility3/framework/symbols/windows/extensions/__init__.py @@ -651,7 +651,7 @@ class EPROCESS(generic.GenericIntelProcess, pool.ExecutiveObject): except AttributeError: return False - return not value + return not not value def get_vad_root(self): From c5c1f355ef7dd20a024a5358db7f7ae758187af7 Mon Sep 17 00:00:00 2001 From: Gustavo Moreira Date: Mon, 13 Dec 2021 09:51:25 +1100 Subject: [PATCH 6/6] Changing `not not` for a more explicit if statement --- volatility3/framework/symbols/windows/extensions/__init__.py | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/volatility3/framework/symbols/windows/extensions/__init__.py b/volatility3/framework/symbols/windows/extensions/__init__.py index 7c931f148..84c47e733 100755 --- a/volatility3/framework/symbols/windows/extensions/__init__.py +++ b/volatility3/framework/symbols/windows/extensions/__init__.py @@ -651,7 +651,10 @@ class EPROCESS(generic.GenericIntelProcess, pool.ExecutiveObject): except AttributeError: return False - return not not value + if value: + return True + + return False def get_vad_root(self):