diff --git a/volatility/cli/__init__.py b/volatility/cli/__init__.py index 5e47b93af..b1e346a74 100644 --- a/volatility/cli/__init__.py +++ b/volatility/cli/__init__.py @@ -59,9 +59,10 @@ class CommandLine(object): ctx.config["pslist.primary.page_map_offset"] = 0x39000 ctx.config["pslist.offset"] = 0x823c87c0 - if dldr.validate_dependencies(dependencies, context = ctx, path = plugin.__name__.lower()): + path = plugin.__name__.lower() + if dldr.validate_dependencies(dependencies, context = ctx, path = path): # Construct and run the plugin - plugin(ctx).run() + plugin(ctx, path).run() def main(): diff --git a/volatility/framework/configuration/depresolver.py b/volatility/framework/configuration/depresolver.py index 327dfc767..447f7e106 100644 --- a/volatility/framework/configuration/depresolver.py +++ b/volatility/framework/configuration/depresolver.py @@ -47,7 +47,7 @@ class DataLayerDependencyResolver(validity.ValidityRoutines): node_path = path + configuration.CONFIG_SEPARATOR + node.requirement.name if isinstance(node, Node) and not node.requirement.optional: node_config = context.config.branch(node_path) - for branch, subtree in node.branches.items(): + for possible_layer, subtree in node.branches.items(): if self.validate_dependencies(subtree, context, path = node_path): # Generate a layer name layer_name = node.requirement.name @@ -58,7 +58,7 @@ class DataLayerDependencyResolver(validity.ValidityRoutines): # Construct the layer requirement_dict = node_config.data - context.add_layer(branch(context, layer_name, **requirement_dict)) + context.add_layer(possible_layer(context, node_path, layer_name, **requirement_dict)) context.config[node_path] = layer_name break else: diff --git a/volatility/framework/interfaces/configuration.py b/volatility/framework/interfaces/configuration.py index ad0db1456..e520324c8 100644 --- a/volatility/framework/interfaces/configuration.py +++ b/volatility/framework/interfaces/configuration.py @@ -2,6 +2,7 @@ import collections from abc import ABCMeta, abstractmethod from volatility.framework import validity +from volatility.framework.interfaces import context as context_interface __author__ = 'mike' @@ -168,10 +169,27 @@ class HierarchicalDict(collections.Mapping): return self._subdict[key] -class Configurable(object): +class Configurable(validity.ValidityRoutines): """Class to allow objects to have requirements and populate the context config tree""" + def __init__(self, context, config_path): + validity.ValidityRoutines.__init__(self) + self._context = self._check_type(context, context_interface.ContextInterface) + self._config_path = self._check_type(config_path, str) + + @property + def context(self): + return self._context + + @property + def config_path(self): + return self._config_path + @classmethod def get_schema(cls): """Returns a list of configuration schema nodes for this object""" return [] + + @property + def config(self): + return self._context.config.branch(self._config_path) diff --git a/volatility/framework/interfaces/layers.py b/volatility/framework/interfaces/layers.py index e97350968..7581e0396 100644 --- a/volatility/framework/interfaces/layers.py +++ b/volatility/framework/interfaces/layers.py @@ -4,23 +4,22 @@ Created on 4 May 2013 @author: mike """ -from volatility.framework import validity, exceptions +from volatility.framework import exceptions, validity # We can't just import interfaces because we'd have a cycle going from volatility.framework.interfaces import configuration -from volatility.framework.interfaces import context as context_module from abc import ABCMeta, abstractmethod, abstractproperty -class DataLayerInterface(validity.ValidityRoutines, configuration.Configurable, metaclass = ABCMeta): +class DataLayerInterface(configuration.Configurable, validity.ValidityRoutines, metaclass = ABCMeta): """A Layer that directly holds data (and does not translate it""" metadata = {"type": "interface"} - def __init__(self, context, name): + def __init__(self, context, config_path, name): + validity.ValidityRoutines.__init__(self) + configuration.Configurable.__init__(self, context, config_path) self._check_type(name, str) - self._check_type(context, context_module.ContextInterface) self._name = name - self._context = context @property def name(self): diff --git a/volatility/framework/interfaces/plugins.py b/volatility/framework/interfaces/plugins.py index af8672fd3..b84d82e45 100644 --- a/volatility/framework/interfaces/plugins.py +++ b/volatility/framework/interfaces/plugins.py @@ -23,14 +23,13 @@ from volatility.framework.interfaces import context as context_interface # The plugin accepts the context and modifies as necessary # The plugin runs and produces a TreeGrid output -class PluginInterface(validity.ValidityRoutines, configuration_interface.Configurable, metaclass = ABCMeta): +class PluginInterface(configuration_interface.Configurable, validity.ValidityRoutines, metaclass = ABCMeta): """Class that defines the interface all Plugins must maintain""" - def __init__(self, context): + def __init__(self, context, config_path): validity.ValidityRoutines.__init__(self) - configuration_interface.Configurable.__init__(self) + configuration_interface.Configurable.__init__(self, context, config_path) self._check_type(context, context_interface.ContextInterface) - self._context = context # self.validate_inputs() @property @@ -42,12 +41,6 @@ class PluginInterface(validity.ValidityRoutines, configuration_interface.Configu """Returns a list of configuration schema items""" return [] - @property - def config(self, core = False): - if core: - return self._context.config.get("core") - return self._context.config.get(self.__class__.__name__) - def validate_inputs(self): for option in self.get_schema(): if not option.optional: diff --git a/volatility/framework/layers/intel.py b/volatility/framework/layers/intel.py index 1f0cf9700..274bd73f3 100644 --- a/volatility/framework/layers/intel.py +++ b/volatility/framework/layers/intel.py @@ -17,8 +17,8 @@ class Intel(interfaces.layers.TranslationLayerInterface): "architecture": "ia32" } - def __init__(self, context, name, page_map_offset, memory_layer, swap_layer = None): - interfaces.layers.TranslationLayerInterface.__init__(self, context, name) + def __init__(self, context, config_path, name, page_map_offset, memory_layer, swap_layer = None): + interfaces.layers.TranslationLayerInterface.__init__(self, context, config_path, name) self._base_layer = memory_layer self._page_map_offset = page_map_offset # All Intel address spaces work on 4096 byte pages diff --git a/volatility/framework/layers/physical.py b/volatility/framework/layers/physical.py index 871f14c00..eaa4edeaa 100644 --- a/volatility/framework/layers/physical.py +++ b/volatility/framework/layers/physical.py @@ -14,8 +14,8 @@ class BufferDataLayer(interfaces.layers.DataLayerInterface): metadata = {"type": "physical"} - def __init__(self, context, name, buffer): - interfaces.layers.DataLayerInterface.__init__(self, context, name) + def __init__(self, context, config_path, name, buffer): + interfaces.layers.DataLayerInterface.__init__(self, context, config_path, name) self._buffer = self._check_type(buffer, bytes) @property @@ -55,8 +55,8 @@ class FileLayer(interfaces.layers.DataLayerInterface): metadata = {"type": "physical"} - def __init__(self, context, name, filename): - interfaces.layers.DataLayerInterface.__init__(self, context, name) + def __init__(self, context, config_path, name, filename): + interfaces.layers.DataLayerInterface.__init__(self, context, config_path, name) self._file = open(filename, "r+b") self._size = os.path.getsize(filename) diff --git a/volatility/plugins/windows/pslist.py b/volatility/plugins/windows/pslist.py index 1afae24f2..293ee4530 100644 --- a/volatility/plugins/windows/pslist.py +++ b/volatility/plugins/windows/pslist.py @@ -30,6 +30,6 @@ class PsList(plugins.PluginInterface): def run(self): eproc = self.kernel_process_from_physical_process(self.context, 'physical', 'intel', - self.config.get_value('offset')) + self.config['offset']) for proc in eproc.ActiveProcessLinks: print(proc.UniqueProcessId)