From a3c50e8221ed39e399b500376cb448019f9403db Mon Sep 17 00:00:00 2001 From: Dave Lassalle Date: Sat, 3 Aug 2024 14:27:42 -0700 Subject: [PATCH] #816 - black fixes --- .../framework/plugins/windows/consoles.py | 3 ++- .../symbols/windows/extensions/consoles.py | 21 +++++++++++++------ 2 files changed, 17 insertions(+), 7 deletions(-) diff --git a/volatility3/framework/plugins/windows/consoles.py b/volatility3/framework/plugins/windows/consoles.py index 3b87734e7..9b41b2890 100644 --- a/volatility3/framework/plugins/windows/consoles.py +++ b/volatility3/framework/plugins/windows/consoles.py @@ -619,7 +619,8 @@ class Consoles(interfaces.plugins.PluginInterface): bucket_cmd, ) in command_history.get_commands(): try: - console_properties.append({ + console_properties.append( + { "level": 3, "name": f"_CONSOLE_INFORMATION.HistoryList.CommandHistory_{index}_Command_{cmd_index}", "address": bucket_cmd.vol.offset, diff --git a/volatility3/framework/symbols/windows/extensions/consoles.py b/volatility3/framework/symbols/windows/extensions/consoles.py index 74ea80e84..23670bb9b 100644 --- a/volatility3/framework/symbols/windows/extensions/consoles.py +++ b/volatility3/framework/symbols/windows/extensions/consoles.py @@ -23,9 +23,9 @@ class ROW(objects.StructType): 0x50, 0x60, 0x80, - 0xa8, - 0xc0, - 0xc8, + 0xA8, + 0xC0, + 0xC8, 0x98, 0xF8, 0xF0, @@ -226,7 +226,12 @@ class COMMAND(objects.StructType): """A Command Structure""" def is_valid(self): - if self.Length < 1 or self.Allocated < 1 or self.Length > 1024 or self.Allocated > 1024: + if ( + self.Length < 1 + or self.Allocated < 1 + or self.Length > 1024 + or self.Allocated > 1024 + ): return False return True @@ -256,7 +261,7 @@ class COMMAND_HISTORY(objects.StructType): @property def ProcessHandle(self): - """ Allow ProcessHandle to be referenced regardless of OS version """ + """Allow ProcessHandle to be referenced regardless of OS version""" return self.ConsoleProcessHandle.ProcessHandle def is_valid(self, max_history=50): @@ -269,7 +274,11 @@ class COMMAND_HISTORY(objects.StructType): return False # Process handle must be a valid pid - if self.ProcessHandle <= 0 or self.ProcessHandle > 0xFFFF or self.ProcessHandle % 4 != 0: + if ( + self.ProcessHandle <= 0 + or self.ProcessHandle > 0xFFFF + or self.ProcessHandle % 4 != 0 + ): return False return True