mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-29 13:04:58 +02:00
Add in a NativeSymbolTable validator.
This commit is contained in:
@@ -7,6 +7,7 @@ import volatility.plugins
|
||||
from volatility.cli import argparse_adapter
|
||||
from volatility.framework import plugins, contexts
|
||||
from volatility.framework.configuration import depresolver
|
||||
from volatility.framework.configuration.depresolver import DependencyError
|
||||
|
||||
__author__ = 'mike'
|
||||
|
||||
@@ -53,6 +54,8 @@ class CommandLine(object):
|
||||
if dldr.validate_dependencies(dependencies, context = ctx, path = config_path):
|
||||
# Construct and run the plugin
|
||||
plugin(ctx, config_path).run()
|
||||
else:
|
||||
raise DependencyError("Unable to validate all the dependencies, please check configuration parameters")
|
||||
|
||||
|
||||
def main():
|
||||
|
||||
@@ -1,3 +1,5 @@
|
||||
import logging
|
||||
|
||||
import volatility.framework as framework
|
||||
import volatility.framework.validity as validity
|
||||
from volatility.framework.interfaces import configuration
|
||||
@@ -60,12 +62,16 @@ class DependencyResolver(validity.ValidityRoutines):
|
||||
provider.fulfill(context, node.requirement, node_path)
|
||||
break
|
||||
else:
|
||||
logging.debug("Unable to fulfill requirement " + repr(node.requirement))
|
||||
return False
|
||||
try:
|
||||
value = context.config[node_path]
|
||||
node.requirement.validate(value, context)
|
||||
except BaseException as e:
|
||||
except Exception as e:
|
||||
if not node.requirement.optional:
|
||||
logging.debug(
|
||||
"Unable to fulfill non-optional requirement " + repr(node.requirement) +
|
||||
" [" + str(e) + "]")
|
||||
return False
|
||||
return True
|
||||
|
||||
|
||||
@@ -59,6 +59,12 @@ class SymbolRequirement(config_interface.ConstraintInterface):
|
||||
raise IndexError((value or "") + " is not present in the symbol space")
|
||||
|
||||
|
||||
class NativeSymbolRequirement(SymbolRequirement):
|
||||
def validate(self, value, context):
|
||||
if not isinstance(value, str):
|
||||
raise TypeError("SymbolRequirement only accepts string labels")
|
||||
|
||||
|
||||
class ChoiceRequirement(config_interface.RequirementInterface):
|
||||
"""Allows one from a choice of strings"""
|
||||
|
||||
|
||||
@@ -79,7 +79,7 @@ class DataLayerInterface(configuration.ProviderInterface, validity.ValidityRouti
|
||||
|
||||
# Construct the layer
|
||||
requirement_dict = node_config.data
|
||||
print("Requirement_dict", cls, requirement_dict)
|
||||
print("Requirement_dict", requirement_dict)
|
||||
context.add_layer(cls(context, config_path, layer_name, **requirement_dict))
|
||||
context.config[config_path] = layer_name
|
||||
|
||||
|
||||
@@ -1,7 +1,7 @@
|
||||
import importlib
|
||||
|
||||
import volatility.framework.configuration.requirements
|
||||
from volatility.framework import interfaces
|
||||
from volatility.framework.configuration import requirements
|
||||
from volatility.framework.symbols import vtypes, native
|
||||
from volatility.framework.symbols.windows import basic
|
||||
|
||||
@@ -13,6 +13,7 @@ class X86NativeSymbolProvider(interfaces.symbols.SymbolTableProviderInterface):
|
||||
@classmethod
|
||||
def fulfill(cls, context, requirement, config_path):
|
||||
context.symbol_space.natives = native.x86NativeTable
|
||||
context.config[config_path] = "natives"
|
||||
|
||||
|
||||
class WindowsKernelSymbolProvider(interfaces.symbols.SymbolTableProviderInterface):
|
||||
@@ -61,7 +62,6 @@ class XPSP2WindowsKernelSymbolProvider(WindowsKernelSymbolProvider):
|
||||
|
||||
@classmethod
|
||||
def get_schema(cls):
|
||||
return [volatility.framework.configuration.requirements.SymbolRequirement("natives",
|
||||
description = "Native Symbols for x86",
|
||||
constraints = {"type": "natives",
|
||||
"architecture": "ia32"})]
|
||||
return [requirements.NativeSymbolRequirement("natives", description = "Native Symbols for x86",
|
||||
constraints = {"type": "natives",
|
||||
"architecture": "ia32"})]
|
||||
|
||||
Reference in New Issue
Block a user