mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-30 05:24:52 +02:00
Linux/Mac: Log producer information
This commit is contained in:
@@ -142,11 +142,11 @@ class SymbolFinder(interfaces.automagic.AutomagicInterface):
|
||||
)
|
||||
|
||||
for _, banner in banner_list:
|
||||
vollog.debug(f"Identified banner: {repr(banner)}")
|
||||
symbol_files = self.banners.get(banner, None)
|
||||
if symbol_files:
|
||||
isf_path = symbol_files
|
||||
vollog.debug(f"Using symbol library: {symbol_files}")
|
||||
vollog.debug(f"Identified banner: {banner!r}")
|
||||
symbols_file = self.banners.get(banner, None)
|
||||
if symbols_file:
|
||||
isf_path = symbols_file
|
||||
vollog.debug(f"Using symbol library: {symbols_file}")
|
||||
clazz = self.symbol_class
|
||||
# Set the discovered options
|
||||
path_join = interfaces.configuration.path_join
|
||||
@@ -160,8 +160,29 @@ class SymbolFinder(interfaces.automagic.AutomagicInterface):
|
||||
path_join(config_path, requirement.name, "symbol_mask")
|
||||
] = layer.address_mask
|
||||
|
||||
# Keep track of the existing table names so we know which ones were added
|
||||
old_table_names = set(context.symbol_space._dict)
|
||||
|
||||
# Construct the appropriate symbol table
|
||||
requirement.construct(context, config_path)
|
||||
|
||||
new_table_names = context.symbol_space._dict.keys() - old_table_names
|
||||
# It should add only one symbol table. Ignore the next steps if it doesn't
|
||||
if len(new_table_names) == 1:
|
||||
new_table_name = new_table_names.pop()
|
||||
symbol_table = context.symbol_space._dict[new_table_name]
|
||||
producer = symbol_table.producer
|
||||
vollog.debug(
|
||||
f"producer_name: {producer.name}, producer_version: {producer.version_string}"
|
||||
)
|
||||
for category in symbol_table.metadata._json_data:
|
||||
vollog.debug(f"{category}:")
|
||||
for subkey in symbol_table.metadata._json_data[category]:
|
||||
subkey_item = ", ".join(
|
||||
f"{key}: '{value}'" for key, value in subkey.items()
|
||||
)
|
||||
vollog.debug(f"\t{subkey_item}")
|
||||
|
||||
break
|
||||
else:
|
||||
vollog.debug(f"Symbol library path not found for: {banner}")
|
||||
|
||||
@@ -738,10 +738,17 @@ class Version6Format(Version5Format):
|
||||
@property
|
||||
def metadata(self) -> Optional[interfaces.symbols.MetadataInterface]:
|
||||
"""Returns a MetadataInterface object."""
|
||||
if self._json_object.get("metadata", {}).get("windows"):
|
||||
return metadata.WindowsMetadata(self._json_object["metadata"]["windows"])
|
||||
if self._json_object.get("metadata", {}).get("linux"):
|
||||
return metadata.LinuxMetadata(self._json_object["metadata"]["linux"])
|
||||
if "metadata" not in self._json_object:
|
||||
return None
|
||||
|
||||
json_metadata = self._json_object["metadata"]
|
||||
if "windows" in json_metadata:
|
||||
return metadata.WindowsMetadata(json_metadata["windows"])
|
||||
if "linux" in json_metadata:
|
||||
return metadata.LinuxMetadata(json_metadata["linux"])
|
||||
if "mac" in json_metadata:
|
||||
return metadata.MacMetadata(json_metadata["mac"])
|
||||
|
||||
return None
|
||||
|
||||
|
||||
|
||||
@@ -18,10 +18,17 @@ class ProducerMetadata(interfaces.symbols.MetadataInterface):
|
||||
def name(self) -> Optional[str]:
|
||||
return self._json_data.get("name", None)
|
||||
|
||||
@property
|
||||
def version_string(self) -> str:
|
||||
"""Returns the ISF file producer's version as a string.
|
||||
If no version is present, an empty string is returned.
|
||||
"""
|
||||
return self._json_data.get("version", "")
|
||||
|
||||
@property
|
||||
def version(self) -> Optional[Tuple[int]]:
|
||||
"""Returns the version of the ISF file producer"""
|
||||
version = self._json_data.get("version", None)
|
||||
version = self.version_string()
|
||||
if not version:
|
||||
return None
|
||||
if all(x in "0123456789." for x in version):
|
||||
@@ -81,3 +88,7 @@ class WindowsMetadata(interfaces.symbols.MetadataInterface):
|
||||
|
||||
class LinuxMetadata(interfaces.symbols.MetadataInterface):
|
||||
"""Class to handle the metadata from a Linux symbol table."""
|
||||
|
||||
|
||||
class MacMetadata(interfaces.symbols.MetadataInterface):
|
||||
"""Class to handle the metadata from a Mac symbol table."""
|
||||
|
||||
Reference in New Issue
Block a user