Make several small typing information fixes.

This commit is contained in:
Mike Auty
2019-09-17 18:01:11 +01:00
parent 33451967b2
commit 7efe19224e
9 changed files with 29 additions and 26 deletions
+1 -1
View File
@@ -45,7 +45,7 @@ class Psaux(plugins.PluginInterface):
task_name = utility.array_to_string(task.p_comm)
args = []
args = [] # type: List[bytes]
while argc > 0:
try:
+2 -2
View File
@@ -3,7 +3,7 @@
#
import logging
from typing import Callable, Iterable, List
from typing import Callable, Iterable, List, Dict
from volatility.framework import renderers, interfaces, contexts
from volatility.framework.automagic import mac
@@ -77,7 +77,7 @@ class PsList(interfaces.plugins.PluginInterface):
proc = kernel.object_from_symbol(symbol_name = "allproc").lh_first
seen = {}
seen = {} # type: Dict[int, int]
while proc is not None and proc.vol.offset != 0:
if proc.vol.offset in seen:
vollog.log(logging.INFO, "Recursive process list detected (a result of non-atomic acquisition).")
+2 -2
View File
@@ -3,7 +3,7 @@
#
import logging
from typing import Callable, Iterable
from typing import Callable, Dict, Iterable
from volatility.framework import interfaces, contexts
from volatility.framework.automagic import mac
@@ -40,7 +40,7 @@ class Tasks(pslist.PsList):
queue_entry = kernel.object_from_symbol(symbol_name = "tasks")
seen = {}
seen = {} # type: Dict[int, int]
for task in queue_entry.walk_list(queue_entry, "tasks", "task"):
if task.vol.offset in seen:
vollog.log(logging.INFO, "Recursive process list detected (a result of non-atomic acquisition).")
@@ -3,7 +3,7 @@
#
import logging
from typing import List, Iterable, Tuple
from typing import List, Iterable, Tuple, Optional, Union
import volatility.framework.interfaces.plugins as interfaces_plugins
from volatility.framework import constants, exceptions, renderers, interfaces, symbols
@@ -62,7 +62,7 @@ class Callbacks(interfaces_plugins.PluginInterface):
@classmethod
def list_notify_routines(cls, context: interfaces.context.ContextInterface, layer_name: str, symbol_table: str,
callback_table_name: str) -> Iterable[Tuple[str, int, str]]:
callback_table_name: str) -> Iterable[Tuple[str, int, Optional[str]]]:
"""Lists all kernel notification routines.
Args:
@@ -114,7 +114,7 @@ class Callbacks(interfaces_plugins.PluginInterface):
@classmethod
def list_registry_callbacks(cls, context: interfaces.context.ContextInterface, layer_name: str, symbol_table: str,
callback_table_name: str) -> Iterable[Tuple[str, int, str]]:
callback_table_name: str) -> Iterable[Tuple[str, int, None]]:
"""Lists all registry callbacks.
Args:
@@ -193,7 +193,8 @@ class Callbacks(interfaces_plugins.PluginInterface):
try:
component = ntkrnlmp.object(
"string", absolute = True, offset = callback.Component, max_length = 64, errors = "replace")
"string", absolute = True, offset = callback.Component, max_length = 64, errors = "replace"
) # type: Union[interfaces.renderers.BaseAbsentValue, interfaces.objects.ObjectInterface]
except exceptions.InvalidAddressException:
component = renderers.UnreadableValue()
@@ -359,8 +359,8 @@ class PoolScanner(plugins.PluginInterface):
cookie = handles.Handles.find_cookie(context = context, layer_name = layer_name, symbol_table = symbol_table)
is_windows_10 = cls.is_windows_10(context = context, symbol_table = symbol_table)
is_windows_8_or_later = cls.is_windows_8_or_later(context = context, symbol_table = symbol_table)
is_windows_10 = cls.is_windows_10(context, symbol_table)
is_windows_8_or_later = cls.is_windows_8_or_later(context, symbol_table)
# start off with the primary virtual layer
scan_layer = layer_name
@@ -434,7 +434,7 @@ class PoolScanner(plugins.PluginInterface):
# We have to manually load a symbol table
if symbols.symbol_table_is_64bit(context, symbol_table):
is_win_7 = cls.is_windows_7(context = context, symbol_table = symbol_table)
is_win_7 = cls.is_windows_7(context, symbol_table)
if is_win_7:
pool_header_json_filename = "poolheader-x64-win7"
else:
@@ -4,7 +4,7 @@
import datetime
import logging
from typing import List, Sequence, Iterable, Tuple
from typing import List, Sequence, Iterable, Tuple, Union
from volatility.framework import objects, renderers, exceptions, interfaces, constants
from volatility.framework.configuration import requirements
@@ -36,8 +36,8 @@ class PrintKey(interfaces.plugins.PluginInterface):
]
@classmethod
def key_iterator(cls, hive: RegistryHive, node_path: Sequence[objects.StructType] = None,
recurse: bool = False) -> Iterable[Tuple[int, bool, datetime.datetime, str, bool, bytes]]:
def key_iterator(cls, hive: RegistryHive, node_path: Sequence[objects.StructType] = None, recurse: bool = False
) -> Iterable[Tuple[int, bool, datetime.datetime, str, bool, interfaces.objects.ObjectInterface]]:
"""Walks through a set of nodes from a given node (last one in
node_path). Avoids loops by not traversing into nodes already present
in the node_path.
@@ -112,7 +112,7 @@ class PrintKey(interfaces.plugins.PluginInterface):
value_node_name = renderers.UnreadableValue()
try:
value_data = str(node.decode_data())
value_data = str(node.decode_data()) # type: Union[interfaces.renderers.BaseAbsentValue, str]
except (ValueError, exceptions.InvalidAddressException, RegistryFormatException) as excp:
vollog.debug(excp)
value_data = renderers.UnreadableValue()