mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-30 21:44:52 +02:00
Make several small typing information fixes.
This commit is contained in:
@@ -45,7 +45,7 @@ class Psaux(plugins.PluginInterface):
|
||||
|
||||
task_name = utility.array_to_string(task.p_comm)
|
||||
|
||||
args = []
|
||||
args = [] # type: List[bytes]
|
||||
|
||||
while argc > 0:
|
||||
try:
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
#
|
||||
|
||||
import logging
|
||||
from typing import Callable, Iterable, List
|
||||
from typing import Callable, Iterable, List, Dict
|
||||
|
||||
from volatility.framework import renderers, interfaces, contexts
|
||||
from volatility.framework.automagic import mac
|
||||
@@ -77,7 +77,7 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
|
||||
proc = kernel.object_from_symbol(symbol_name = "allproc").lh_first
|
||||
|
||||
seen = {}
|
||||
seen = {} # type: Dict[int, int]
|
||||
while proc is not None and proc.vol.offset != 0:
|
||||
if proc.vol.offset in seen:
|
||||
vollog.log(logging.INFO, "Recursive process list detected (a result of non-atomic acquisition).")
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
#
|
||||
|
||||
import logging
|
||||
from typing import Callable, Iterable
|
||||
from typing import Callable, Dict, Iterable
|
||||
|
||||
from volatility.framework import interfaces, contexts
|
||||
from volatility.framework.automagic import mac
|
||||
@@ -40,7 +40,7 @@ class Tasks(pslist.PsList):
|
||||
|
||||
queue_entry = kernel.object_from_symbol(symbol_name = "tasks")
|
||||
|
||||
seen = {}
|
||||
seen = {} # type: Dict[int, int]
|
||||
for task in queue_entry.walk_list(queue_entry, "tasks", "task"):
|
||||
if task.vol.offset in seen:
|
||||
vollog.log(logging.INFO, "Recursive process list detected (a result of non-atomic acquisition).")
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
#
|
||||
|
||||
import logging
|
||||
from typing import List, Iterable, Tuple
|
||||
from typing import List, Iterable, Tuple, Optional, Union
|
||||
|
||||
import volatility.framework.interfaces.plugins as interfaces_plugins
|
||||
from volatility.framework import constants, exceptions, renderers, interfaces, symbols
|
||||
@@ -62,7 +62,7 @@ class Callbacks(interfaces_plugins.PluginInterface):
|
||||
|
||||
@classmethod
|
||||
def list_notify_routines(cls, context: interfaces.context.ContextInterface, layer_name: str, symbol_table: str,
|
||||
callback_table_name: str) -> Iterable[Tuple[str, int, str]]:
|
||||
callback_table_name: str) -> Iterable[Tuple[str, int, Optional[str]]]:
|
||||
"""Lists all kernel notification routines.
|
||||
|
||||
Args:
|
||||
@@ -114,7 +114,7 @@ class Callbacks(interfaces_plugins.PluginInterface):
|
||||
|
||||
@classmethod
|
||||
def list_registry_callbacks(cls, context: interfaces.context.ContextInterface, layer_name: str, symbol_table: str,
|
||||
callback_table_name: str) -> Iterable[Tuple[str, int, str]]:
|
||||
callback_table_name: str) -> Iterable[Tuple[str, int, None]]:
|
||||
"""Lists all registry callbacks.
|
||||
|
||||
Args:
|
||||
@@ -193,7 +193,8 @@ class Callbacks(interfaces_plugins.PluginInterface):
|
||||
|
||||
try:
|
||||
component = ntkrnlmp.object(
|
||||
"string", absolute = True, offset = callback.Component, max_length = 64, errors = "replace")
|
||||
"string", absolute = True, offset = callback.Component, max_length = 64, errors = "replace"
|
||||
) # type: Union[interfaces.renderers.BaseAbsentValue, interfaces.objects.ObjectInterface]
|
||||
except exceptions.InvalidAddressException:
|
||||
component = renderers.UnreadableValue()
|
||||
|
||||
|
||||
@@ -359,8 +359,8 @@ class PoolScanner(plugins.PluginInterface):
|
||||
|
||||
cookie = handles.Handles.find_cookie(context = context, layer_name = layer_name, symbol_table = symbol_table)
|
||||
|
||||
is_windows_10 = cls.is_windows_10(context = context, symbol_table = symbol_table)
|
||||
is_windows_8_or_later = cls.is_windows_8_or_later(context = context, symbol_table = symbol_table)
|
||||
is_windows_10 = cls.is_windows_10(context, symbol_table)
|
||||
is_windows_8_or_later = cls.is_windows_8_or_later(context, symbol_table)
|
||||
|
||||
# start off with the primary virtual layer
|
||||
scan_layer = layer_name
|
||||
@@ -434,7 +434,7 @@ class PoolScanner(plugins.PluginInterface):
|
||||
# We have to manually load a symbol table
|
||||
|
||||
if symbols.symbol_table_is_64bit(context, symbol_table):
|
||||
is_win_7 = cls.is_windows_7(context = context, symbol_table = symbol_table)
|
||||
is_win_7 = cls.is_windows_7(context, symbol_table)
|
||||
if is_win_7:
|
||||
pool_header_json_filename = "poolheader-x64-win7"
|
||||
else:
|
||||
|
||||
@@ -4,7 +4,7 @@
|
||||
|
||||
import datetime
|
||||
import logging
|
||||
from typing import List, Sequence, Iterable, Tuple
|
||||
from typing import List, Sequence, Iterable, Tuple, Union
|
||||
|
||||
from volatility.framework import objects, renderers, exceptions, interfaces, constants
|
||||
from volatility.framework.configuration import requirements
|
||||
@@ -36,8 +36,8 @@ class PrintKey(interfaces.plugins.PluginInterface):
|
||||
]
|
||||
|
||||
@classmethod
|
||||
def key_iterator(cls, hive: RegistryHive, node_path: Sequence[objects.StructType] = None,
|
||||
recurse: bool = False) -> Iterable[Tuple[int, bool, datetime.datetime, str, bool, bytes]]:
|
||||
def key_iterator(cls, hive: RegistryHive, node_path: Sequence[objects.StructType] = None, recurse: bool = False
|
||||
) -> Iterable[Tuple[int, bool, datetime.datetime, str, bool, interfaces.objects.ObjectInterface]]:
|
||||
"""Walks through a set of nodes from a given node (last one in
|
||||
node_path). Avoids loops by not traversing into nodes already present
|
||||
in the node_path.
|
||||
@@ -112,7 +112,7 @@ class PrintKey(interfaces.plugins.PluginInterface):
|
||||
value_node_name = renderers.UnreadableValue()
|
||||
|
||||
try:
|
||||
value_data = str(node.decode_data())
|
||||
value_data = str(node.decode_data()) # type: Union[interfaces.renderers.BaseAbsentValue, str]
|
||||
except (ValueError, exceptions.InvalidAddressException, RegistryFormatException) as excp:
|
||||
vollog.debug(excp)
|
||||
value_data = renderers.UnreadableValue()
|
||||
|
||||
Reference in New Issue
Block a user