From 78cd3c84c0a48143654cbd516f6623d84aa35e39 Mon Sep 17 00:00:00 2001 From: Mike Auty Date: Sat, 16 Jan 2016 21:38:00 +0000 Subject: [PATCH] Add in a NativeSymbolTable validator. --- volatility/cli/__init__.py | 3 +++ volatility/framework/configuration/depresolver.py | 8 +++++++- volatility/framework/configuration/requirements.py | 6 ++++++ volatility/framework/interfaces/layers.py | 2 +- volatility/framework/symbols/windows/xp_sp2.py | 10 +++++----- 5 files changed, 22 insertions(+), 7 deletions(-) diff --git a/volatility/cli/__init__.py b/volatility/cli/__init__.py index 084074963..326dfd983 100644 --- a/volatility/cli/__init__.py +++ b/volatility/cli/__init__.py @@ -7,6 +7,7 @@ import volatility.plugins from volatility.cli import argparse_adapter from volatility.framework import plugins, contexts from volatility.framework.configuration import depresolver +from volatility.framework.configuration.depresolver import DependencyError __author__ = 'mike' @@ -53,6 +54,8 @@ class CommandLine(object): if dldr.validate_dependencies(dependencies, context = ctx, path = config_path): # Construct and run the plugin plugin(ctx, config_path).run() + else: + raise DependencyError("Unable to validate all the dependencies, please check configuration parameters") def main(): diff --git a/volatility/framework/configuration/depresolver.py b/volatility/framework/configuration/depresolver.py index 7b94ce3a4..8756859a0 100644 --- a/volatility/framework/configuration/depresolver.py +++ b/volatility/framework/configuration/depresolver.py @@ -1,3 +1,5 @@ +import logging + import volatility.framework as framework import volatility.framework.validity as validity from volatility.framework.interfaces import configuration @@ -60,12 +62,16 @@ class DependencyResolver(validity.ValidityRoutines): provider.fulfill(context, node.requirement, node_path) break else: + logging.debug("Unable to fulfill requirement " + repr(node.requirement)) return False try: value = context.config[node_path] node.requirement.validate(value, context) - except BaseException as e: + except Exception as e: if not node.requirement.optional: + logging.debug( + "Unable to fulfill non-optional requirement " + repr(node.requirement) + + " [" + str(e) + "]") return False return True diff --git a/volatility/framework/configuration/requirements.py b/volatility/framework/configuration/requirements.py index 8dbd08512..79926b46a 100644 --- a/volatility/framework/configuration/requirements.py +++ b/volatility/framework/configuration/requirements.py @@ -59,6 +59,12 @@ class SymbolRequirement(config_interface.ConstraintInterface): raise IndexError((value or "") + " is not present in the symbol space") +class NativeSymbolRequirement(SymbolRequirement): + def validate(self, value, context): + if not isinstance(value, str): + raise TypeError("SymbolRequirement only accepts string labels") + + class ChoiceRequirement(config_interface.RequirementInterface): """Allows one from a choice of strings""" diff --git a/volatility/framework/interfaces/layers.py b/volatility/framework/interfaces/layers.py index 701cb51e2..d6d2bfaea 100644 --- a/volatility/framework/interfaces/layers.py +++ b/volatility/framework/interfaces/layers.py @@ -79,7 +79,7 @@ class DataLayerInterface(configuration.ProviderInterface, validity.ValidityRouti # Construct the layer requirement_dict = node_config.data - print("Requirement_dict", cls, requirement_dict) + print("Requirement_dict", requirement_dict) context.add_layer(cls(context, config_path, layer_name, **requirement_dict)) context.config[config_path] = layer_name diff --git a/volatility/framework/symbols/windows/xp_sp2.py b/volatility/framework/symbols/windows/xp_sp2.py index 906812687..0aaaa3a4c 100644 --- a/volatility/framework/symbols/windows/xp_sp2.py +++ b/volatility/framework/symbols/windows/xp_sp2.py @@ -1,7 +1,7 @@ import importlib -import volatility.framework.configuration.requirements from volatility.framework import interfaces +from volatility.framework.configuration import requirements from volatility.framework.symbols import vtypes, native from volatility.framework.symbols.windows import basic @@ -13,6 +13,7 @@ class X86NativeSymbolProvider(interfaces.symbols.SymbolTableProviderInterface): @classmethod def fulfill(cls, context, requirement, config_path): context.symbol_space.natives = native.x86NativeTable + context.config[config_path] = "natives" class WindowsKernelSymbolProvider(interfaces.symbols.SymbolTableProviderInterface): @@ -61,7 +62,6 @@ class XPSP2WindowsKernelSymbolProvider(WindowsKernelSymbolProvider): @classmethod def get_schema(cls): - return [volatility.framework.configuration.requirements.SymbolRequirement("natives", - description = "Native Symbols for x86", - constraints = {"type": "natives", - "architecture": "ia32"})] + return [requirements.NativeSymbolRequirement("natives", description = "Native Symbols for x86", + constraints = {"type": "natives", + "architecture": "ia32"})]