Merge pull request #1696 from volatilityfoundation/fix_symbol_table_api

Fix symbol table PDB API that mixes returns, None values, and exceptions
This commit is contained in:
ikelos
2025-03-10 19:37:50 +00:00
committed by GitHub
2 changed files with 7 additions and 5 deletions
@@ -649,10 +649,6 @@ class NetStat(interfaces.plugins.PluginInterface, timeliner.TimeLinerInterface):
vollog.error("Unable to locate symbols for the memory image's tcpip module")
return
if not tcpip_symbol_table:
vollog.error("Unable to reconstruct symbol table for tcpip.sys")
return
for netw_obj in self.list_sockets(
self.context,
kernel.layer_name,
@@ -409,6 +409,12 @@ class PDBUtility(interfaces.configuration.VersionableInterface):
_, symbol_table_name = cls._modtable_from_pdb(
context, config_path, layer_name, pdb_name, module_offset, module_size
)
if symbol_table_name is None:
raise exceptions.SymbolSpaceError(
f"Symbol table could not be reconstructed for module {pdb_name}"
)
return symbol_table_name
@classmethod
@@ -439,7 +445,7 @@ class PDBUtility(interfaces.configuration.VersionableInterface):
)
if not guids:
raise exceptions.VolatilityException(
raise exceptions.SymbolSpaceError(
f"Did not find GUID of {pdb_name} in module @ 0x{module_offset:x}!"
)