mirror of
https://github.com/volatilityfoundation/volatility3.git
synced 2026-09-28 12:34:53 +02:00
@@ -339,7 +339,7 @@ if __name__ == "__main__":
|
||||
"--vol3path",
|
||||
type=str,
|
||||
default=os.path.join(os.getcwd(), "volatility3"),
|
||||
help="Path ot the volatility 3 directory",
|
||||
help="Path to the volatility 3 directory",
|
||||
)
|
||||
parser.add_argument(
|
||||
"--vol2path",
|
||||
|
||||
@@ -49,7 +49,7 @@ def hex_bytes_as_text(value: bytes, width: int = 16) -> str:
|
||||
output += "\n"
|
||||
printables = ""
|
||||
|
||||
# Handle leftovers when the length is not mutiple of width
|
||||
# Handle leftovers when the length is not a multiple of width
|
||||
if printables:
|
||||
padding = width - len(printables)
|
||||
output += " " * padding
|
||||
@@ -182,7 +182,7 @@ class LayerDataRenderer(CLITypeRenderer):
|
||||
output += "\n"
|
||||
printables = ""
|
||||
|
||||
# Handle leftovers when the length is not mutiple of width
|
||||
# Handle leftovers when the length is not a multiple of width
|
||||
if printables:
|
||||
padding = self.width - len(printables)
|
||||
output += " " * padding
|
||||
|
||||
@@ -485,7 +485,7 @@ class Volshell(interfaces.plugins.PluginInterface):
|
||||
return
|
||||
|
||||
if hasattr(volobject.vol, "members"):
|
||||
# display the header for this object, if the orginal object was just a type string, display the type information
|
||||
# display the header for this object, if the original object was just a type string, display the type information
|
||||
struct_header = f'{" " * dereference_count}{volobject.vol.type_name} ({volobject.vol.size} bytes)'
|
||||
if isinstance(object, str) and offset is None:
|
||||
suffix = ":"
|
||||
@@ -558,7 +558,7 @@ class Volshell(interfaces.plugins.PluginInterface):
|
||||
)
|
||||
|
||||
else: # simple type with no members, only one line to print
|
||||
# if the orginal object was just a type string, display the type information
|
||||
# if the original object was just a type string, display the type information
|
||||
if isinstance(object, str) and offset is None:
|
||||
print(self._display_simple_type(volobject, include_value=False))
|
||||
|
||||
|
||||
@@ -218,4 +218,4 @@ def clear_cache(complete=True):
|
||||
os.unlink(cache_filename)
|
||||
os.unlink(os.path.join(constants.CACHE_PATH, constants.IDENTIFIERS_FILENAME))
|
||||
except FileNotFoundError:
|
||||
vollog.log(constants.LOGLEVEL_VVVV, "Attempting to clear a non-existant cache")
|
||||
vollog.log(constants.LOGLEVEL_VVVV, "Attempting to clear a non-existent cache")
|
||||
|
||||
@@ -507,7 +507,7 @@ def load_cache_manager(cache_file: Optional[str] = None) -> CacheManagerInterfac
|
||||
cache_file = os.path.join(constants.CACHE_PATH, constants.IDENTIFIERS_FILENAME)
|
||||
# Different implementations of cache
|
||||
if not os.path.exists(cache_file):
|
||||
raise ValueError("Non-existant cache file provided")
|
||||
raise ValueError("Non-existent cache file provided")
|
||||
with open(cache_file, "rb") as fp:
|
||||
header = fp.read(4)
|
||||
if header not in [b"SQLi"]:
|
||||
|
||||
@@ -287,7 +287,7 @@ class Module(interfaces.context.ModuleInterface):
|
||||
symbol_name: Name of the symbol (within the module) to construct
|
||||
native_layer_name: Name of the layer in which constructed objects are made (for pointers)
|
||||
absolute: whether the symbol's address is absolute or relative to the module
|
||||
object_type: Override for the type from the symobl to use (or if the symbol type is missing)
|
||||
object_type: Override for the type from the symbol to use (or if the symbol type is missing)
|
||||
"""
|
||||
if constants.BANG not in symbol_name:
|
||||
symbol_name = self.symbol_table_name + constants.BANG + symbol_name
|
||||
|
||||
@@ -267,7 +267,7 @@ class ModuleInterface(interfaces.configuration.ConfigurableInterface):
|
||||
symbol_name: The name of a symbol (that must be present in the module's symbol table). The symbol's associated type will be used to construct an object at the symbol's offset.
|
||||
native_layer_name: The native layer for objects that reference a different layer (if not the default provided during module construction)
|
||||
absolute: A boolean specifying whether the offset is absolute within the layer, or relative to the start of the module
|
||||
object_type: Override for the type from the symobl to use (or if the symbol type is missing)
|
||||
object_type: Override for the type from the symbol to use (or if the symbol type is missing)
|
||||
|
||||
Returns:
|
||||
The constructed object
|
||||
|
||||
@@ -136,7 +136,7 @@ class Intel(linear.LinearlyMappedLayer):
|
||||
return bool(entry & (1 << 6))
|
||||
|
||||
def canonicalize(self, addr: int) -> int:
|
||||
"""Canonicalizes an address by performing an appropiate sign extension on the higher addresses"""
|
||||
"""Canonicalizes an address by performing an appropriate sign extension on the higher addresses"""
|
||||
if self._bits_per_register <= self._maxvirtaddr:
|
||||
return addr & self.address_mask
|
||||
elif addr < (1 << self._maxvirtaddr - 1):
|
||||
|
||||
@@ -152,7 +152,7 @@ def bytes_to_decoded_string(
|
||||
"""
|
||||
Args:
|
||||
data: The `bytes` buffer containing the string of a string at offset 0
|
||||
encoding: An encoding value for the encoding paramater of `bytes.decode`
|
||||
encoding: An encoding value for the encoding parameter of `bytes.decode`
|
||||
errors: An errors value for the errors parameter of `bytes.decode`
|
||||
return_truncated: Dictates whether truncated strings should be returned or
|
||||
if a ValueError should be thrown if a truncated (broken) string was decoded
|
||||
|
||||
@@ -62,7 +62,7 @@ class LayerWriter(plugins.PluginInterface):
|
||||
Args:
|
||||
context: the context from which to read the memory layer
|
||||
layer_name: the name of the layer to write out
|
||||
preferred_name: a string with the preferred filename for hte file
|
||||
preferred_name: a string with the preferred filename for the file
|
||||
chunk_size: an optional size for the chunks that should be written (defaults to 0x500000)
|
||||
open_method: class for creating FileHandler context managers
|
||||
progress_callback: an optional function that takes a percentage and a string that displays output
|
||||
|
||||
@@ -29,7 +29,7 @@ class TaskData:
|
||||
|
||||
@dataclass
|
||||
class CapabilitiesData:
|
||||
"""Stores each set of capabilties for a task"""
|
||||
"""Stores each set of capabilities for a task"""
|
||||
|
||||
cap_inheritable: interfaces.objects.ObjectInterface
|
||||
cap_permitted: interfaces.objects.ObjectInterface
|
||||
|
||||
@@ -417,7 +417,7 @@ class NetfilterImp_to_4_3(AbstractNetfilter):
|
||||
|
||||
|
||||
class NetfilterImp_4_3_to_4_9(AbstractNetfilter):
|
||||
"""Netfilter hooks were added to network namepaces in 4.3.
|
||||
"""Netfilter hooks were added to network namespaces in 4.3.
|
||||
It is still implemented as a linked list of 'struct nf_hook_ops' type but inside a
|
||||
network namespace. One linked list per protocol per hook type.
|
||||
|
||||
@@ -611,7 +611,7 @@ class NetfilterImp_4_16_to_latest(NetfilterImp_4_14_to_4_16):
|
||||
class AbstractNetfilterNetDev(AbstractNetfilter):
|
||||
"""Base class to handle the Netfilter NetDev hooks.
|
||||
It won't be executed. It has some common functions to all Netfilter NetDev hook
|
||||
implementions.
|
||||
implementations.
|
||||
|
||||
Netfilter NetDev hooks are set per network device which belongs to a network
|
||||
namespace.
|
||||
|
||||
@@ -48,7 +48,7 @@ class FtraceOpsFlags(Enum):
|
||||
@dataclass
|
||||
class ParsedFtraceOps:
|
||||
"""Parsed ftrace_ops struct representation, containing a selection of forensics valuable
|
||||
informations."""
|
||||
information."""
|
||||
|
||||
ftrace_ops_offset: int
|
||||
callback_symbol: str
|
||||
|
||||
@@ -21,7 +21,7 @@ vollog = logging.getLogger(__name__)
|
||||
@dataclass
|
||||
class ParsedTracepointFunc:
|
||||
"""Parsed tracepoint_func struct, containing a selection of forensics valuable
|
||||
informations."""
|
||||
information."""
|
||||
|
||||
tracepoint_name: str
|
||||
tracepoint_address: int
|
||||
|
||||
@@ -91,7 +91,7 @@ class VmaRegExScan(plugins.PluginInterface):
|
||||
):
|
||||
result_data = proc_layer.read(offset, self.MAXSIZE_DEFAULT, pad=True)
|
||||
|
||||
# reapply the regex in order to extact just the match
|
||||
# reapply the regex in order to extract just the match
|
||||
regex_result = re.match(regex_pattern, result_data)
|
||||
|
||||
if regex_result:
|
||||
|
||||
@@ -56,7 +56,7 @@ class PsList(interfaces.plugins.PluginInterface):
|
||||
"""Returns the list_tasks method based on the selector
|
||||
|
||||
Args:
|
||||
method: Must be one fo the available methods in get_task_choices
|
||||
method: Must be one of the available methods in get_task_choices
|
||||
|
||||
Returns:
|
||||
list_tasks method for listing tasks
|
||||
|
||||
@@ -56,7 +56,7 @@ class RegExScan(plugins.PluginInterface):
|
||||
):
|
||||
result_data = layer.read(offset, self.MAXSIZE_DEFAULT, pad=True)
|
||||
|
||||
# reapply the regex in order to extact just the match
|
||||
# reapply the regex in order to extract just the match
|
||||
regex_result = re.match(regex_pattern, result_data)
|
||||
|
||||
if regex_result:
|
||||
|
||||
@@ -54,7 +54,7 @@ class PageStartScanner(interfaces.layers.ScannerInterface):
|
||||
|
||||
|
||||
class Vmscan(plugins.PluginInterface):
|
||||
"""Scans for Intel VT-d structues and generates VM volatility configs for them"""
|
||||
"""Scans for Intel VT-d structures and generates VM volatility configs for them"""
|
||||
|
||||
_required_framework_version = (2, 2, 0)
|
||||
_version = (1, 0, 0)
|
||||
|
||||
@@ -42,7 +42,7 @@ syscall_finder_type.__doc__ = """
|
||||
This type is used to specify how malicious system call invocations should be found.
|
||||
|
||||
`get_syscall_target_address` is optionally used to extract the address containing the malicious 'syscall' instruction
|
||||
`wants_syscall_inst` whether or not this method expects the 'syscall' instrunction directly within the malicious code block
|
||||
`wants_syscall_inst` whether or not this method expects the 'syscall' instruction directly within the malicious code block
|
||||
`rule` the opcode string to search for the malicious syscall instructions
|
||||
`invalid_ops` instructions that only appear in invalid code blocks. Stops processing of the code block when encountered.
|
||||
`termination_ops` instructions that are expected to be present in the code block and that stop processing
|
||||
@@ -116,7 +116,7 @@ class DirectSystemCalls(interfaces.plugins.PluginInterface):
|
||||
address: int,
|
||||
) -> Optional[Tuple[str, "capstone._cs_insn"]]:
|
||||
"""
|
||||
Determines if the bytes starting at `data` represent a valid syscall instrunction invocation block
|
||||
Determines if the bytes starting at `data` represent a valid syscall instruction invocation block
|
||||
|
||||
To maliciously invoke the system call instruction, malware must do each of the following:
|
||||
|
||||
|
||||
@@ -85,7 +85,7 @@ class Threads(thrdscan.ThrdScan):
|
||||
# previous methods for determining if a thread was a kernel thread
|
||||
# such as bit fields and flags are not stable in Win10+
|
||||
# so we check if the thread is from the kernel itself or one its child
|
||||
# kernel processes (MemCompression, Regsitry, ...)
|
||||
# kernel processes (MemCompression, Registry, ...)
|
||||
if pid != 4 and ppid != 4:
|
||||
continue
|
||||
|
||||
|
||||
@@ -37,7 +37,7 @@ filter_modules_type = Dict[str, filter_module_info]
|
||||
found_symbols_module = List[Tuple[str, int]]
|
||||
found_symbols_type = Dict[str, found_symbols_module]
|
||||
|
||||
# used to hold informatin about a range (VAD or kernel module)
|
||||
# used to hold information about a range (VAD or kernel module)
|
||||
# (start address, size, file path)
|
||||
range_type = Tuple[int, int, str]
|
||||
ranges_type = List[range_type]
|
||||
@@ -243,7 +243,7 @@ class PESymbols(interfaces.plugins.PluginInterface):
|
||||
_required_framework_version = (2, 7, 0)
|
||||
|
||||
# 2.0.0 - changed signature of get_kernel_modules, get_all_vads_with_file_paths, addresses_for_process_symbols, get_process_modules
|
||||
# 3.0.0 - find_symbols wil now throw a ValueError if the provided wanted symbol information does not follow the spec
|
||||
# 3.0.0 - find_symbols will now throw a ValueError if the provided wanted symbol information does not follow the spec
|
||||
_version = (3, 0, 0)
|
||||
|
||||
# used for special handling of the kernel PDB file. See later notes
|
||||
@@ -649,7 +649,7 @@ class PESymbols(interfaces.plugins.PluginInterface):
|
||||
and wanted_addresses_identifier not in wanted_symbols
|
||||
):
|
||||
vollog.warning(
|
||||
"Invalid `wanted_symbols` sent to `find_symbols`. addresses and names keys both misssing."
|
||||
"Invalid `wanted_symbols` sent to `find_symbols`. addresses and names keys both missing."
|
||||
)
|
||||
return
|
||||
|
||||
@@ -671,7 +671,7 @@ class PESymbols(interfaces.plugins.PluginInterface):
|
||||
for value_index, wanted_value in enumerate(all_wanted):
|
||||
symbol_value = symbol_getter(wanted_value)
|
||||
if symbol_value:
|
||||
# yield out deleteion key, deletion index, symbol name, symbol address
|
||||
# yield out deletion key, deletion index, symbol name, symbol address
|
||||
if symbol_key == wanted_names_identifier:
|
||||
yield symbol_key, wanted_value, symbol_value
|
||||
else:
|
||||
|
||||
@@ -118,7 +118,7 @@ class ProcessGhosting(interfaces.plugins.PluginInterface):
|
||||
|
||||
Args:
|
||||
proc:
|
||||
mapped_files: A dictionary mapping vad base addreses to the path and vad instance for the process
|
||||
mapped_files: A dictionary mapping vad base addresses to the path and vad instance for the process
|
||||
|
||||
Return:
|
||||
A Generator of tuples of the file object address, the delete pending state, delete on close state, base address of the VAD, and the path
|
||||
|
||||
@@ -355,7 +355,7 @@ class Hashdump(interfaces.plugins.PluginInterface):
|
||||
@classmethod
|
||||
def get_bootkey(cls, syshive: registry_layer.RegistryHive) -> Optional[bytes]:
|
||||
"""
|
||||
Returns the scrambled bootkey necesary to decrypt hashes
|
||||
Returns the scrambled bootkey necessary to decrypt hashes
|
||||
"""
|
||||
cs = 1
|
||||
lsa_base = f"ControlSet{cs:03}" + "\\Control\\Lsa"
|
||||
|
||||
@@ -602,7 +602,7 @@ def decode_sid(data: bytes) -> Optional[str]:
|
||||
Decodes a windows SID from variable-length raw bytes
|
||||
|
||||
Returns the string representation of the SID if decoding was successful, or None
|
||||
if the data could not be parsed due to an insufficent number of bytes.
|
||||
if the data could not be parsed due to an insufficient number of bytes.
|
||||
"""
|
||||
try:
|
||||
revision, subid_count, id_authority = struct.unpack(
|
||||
@@ -817,7 +817,7 @@ class TaskTrigger:
|
||||
_ = reader.read_u4() # timeout seconds
|
||||
|
||||
repetition_interval_secs = reader.read_u4()
|
||||
_ = reader.read_u4() # reptition duration seconds
|
||||
_ = reader.read_u4() # repetition duration seconds
|
||||
_ = reader.read_u4() # repetition duration seconds 2
|
||||
|
||||
_ = reader.read_bool() # stop at duration end
|
||||
|
||||
@@ -236,7 +236,7 @@ class ShimcacheMem(interfaces.plugins.PluginInterface, timeliner.TimeLinerInterf
|
||||
2) Iterate over every 4/8 bytes (depending on OS bitness) in the .data
|
||||
section and test for the following:
|
||||
a) offset represents a valid RTL_AVL_TABLE object
|
||||
b) RTL_AVL_TABLE is preceeded by an ERESOURCE object
|
||||
b) RTL_AVL_TABLE is preceded by an ERESOURCE object
|
||||
c) RTL_AVL_TABLE is followed by the beginning of the SHIM LRU list
|
||||
|
||||
:param context: The context to retrieve required elements (layers, symbol tables) from
|
||||
|
||||
@@ -129,7 +129,7 @@ class SuspiciousThreads(interfaces.plugins.PluginInterface):
|
||||
):
|
||||
yield (
|
||||
vad_path,
|
||||
"VAD at base address ({vad_base:#x}) hosting this thread maps an application executable that is not the process exectuable",
|
||||
"VAD at base address ({vad_base:#x}) hosting this thread maps an application executable that is not the process executable",
|
||||
)
|
||||
|
||||
def _enumerate_processes(
|
||||
|
||||
@@ -86,7 +86,7 @@ class VadRegExScan(plugins.PluginInterface):
|
||||
):
|
||||
result_data = proc_layer.read(offset, self.MAXSIZE_DEFAULT, pad=True)
|
||||
|
||||
# reapply the regex in order to extact just the match
|
||||
# reapply the regex in order to extract just the match
|
||||
regex_result = re.match(regex_pattern, result_data)
|
||||
|
||||
if regex_result:
|
||||
|
||||
@@ -93,7 +93,7 @@ class Disassembly(interfaces.renderers.BasicType):
|
||||
class LayerData(interfaces.renderers.BasicType):
|
||||
"""Layer data
|
||||
|
||||
This requires the contex to be passed in, in case plugins want to use multiple contexts
|
||||
This requires the context to be passed in, in case plugins want to use multiple contexts
|
||||
and to ensure the TreeGrid interface doesn't change, since this would break all existing plugins
|
||||
"""
|
||||
|
||||
|
||||
@@ -515,7 +515,7 @@ class LinuxUtilities(interfaces.configuration.VersionableInterface):
|
||||
vmlinux: interfaces.context.ModuleInterface,
|
||||
) -> Optional[interfaces.objects.ObjectInterface]:
|
||||
"""Cast a member of a structure out to the containing structure.
|
||||
It mimicks the Linux kernel macro container_of() see include/linux.kernel.h
|
||||
It mimics the Linux kernel macro container_of() see include/linux.kernel.h
|
||||
|
||||
Args:
|
||||
addr: The pointer to the member.
|
||||
|
||||
@@ -984,9 +984,9 @@ class maple_tree(objects.StructType):
|
||||
current_depth + 1,
|
||||
)
|
||||
else:
|
||||
# unkown maple node type
|
||||
# unknown maple node type
|
||||
raise AttributeError(
|
||||
f"Unkown Maple Tree node type {node_type} at offset {hex(pointer)}."
|
||||
f"Unknown Maple Tree node type {node_type} at offset {hex(pointer)}."
|
||||
)
|
||||
|
||||
|
||||
@@ -2295,7 +2295,7 @@ class kernel_cap_t(kernel_cap_struct):
|
||||
|
||||
|
||||
class Timespec64Abstract(abc.ABC):
|
||||
"""Abstract class to handle all required timespec64 operations, convertions and
|
||||
"""Abstract class to handle all required timespec64 operations, conversions and
|
||||
adjustments."""
|
||||
|
||||
@classmethod
|
||||
@@ -2391,7 +2391,7 @@ class Timespec64Abstract(abc.ABC):
|
||||
|
||||
|
||||
class Timespec64Concrete(Timespec64Abstract):
|
||||
"""Handle all required timespec64 operations, convertions and adjustments.
|
||||
"""Handle all required timespec64 operations, conversions and adjustments.
|
||||
This is used to dynamically create timespec64-like objects, each with its own variables
|
||||
and the same methods as a timespec64 object extension.
|
||||
"""
|
||||
@@ -2402,7 +2402,7 @@ class Timespec64Concrete(Timespec64Abstract):
|
||||
|
||||
|
||||
class timespec64(Timespec64Abstract, objects.StructType):
|
||||
"""Handle all required timespec64 operations, convertions and adjustments.
|
||||
"""Handle all required timespec64 operations, conversions and adjustments.
|
||||
This works as an extension of the timespec64 object while maintaining the same methods
|
||||
as a Timespec64Concrete object.
|
||||
"""
|
||||
@@ -2770,7 +2770,7 @@ class IDR(objects.StructType):
|
||||
vmlinux = linux.LinuxUtilities.get_module_from_volobj_type(self._context, self)
|
||||
if not vmlinux.get_type("idr_layer").has_member("layer"):
|
||||
vollog.info(
|
||||
"Unsupported IDR implementation, it should be a very very old kernel, probabably < 2.6"
|
||||
"Unsupported IDR implementation, it should be a very very old kernel, probably < 2.6"
|
||||
)
|
||||
return None
|
||||
|
||||
|
||||
@@ -65,7 +65,7 @@ class net_device(objects.StructType):
|
||||
hwaddr = parent_layer.read(self.dev_addr, self.addr_len, pad=True)
|
||||
except exceptions.InvalidAddressException:
|
||||
vollog.debug(
|
||||
f"Unable to read network inteface mac address from {self.dev_addr:#x}"
|
||||
f"Unable to read network interface mac address from {self.dev_addr:#x}"
|
||||
)
|
||||
return None
|
||||
|
||||
@@ -255,10 +255,10 @@ class net_device(objects.StructType):
|
||||
return None
|
||||
|
||||
def get_queue_length(self) -> int:
|
||||
"""Return the netwrok device transmision qeueue length (qlen)
|
||||
"""Return the network device transmission queue length (qlen)
|
||||
|
||||
Returns:
|
||||
int: the netwrok device transmision qeueue length (qlen)
|
||||
int: the network device transmission queue length (qlen)
|
||||
"""
|
||||
return self.tx_queue_len
|
||||
|
||||
|
||||
@@ -121,7 +121,7 @@ class _KallsymsIO:
|
||||
self._endian = endian
|
||||
|
||||
def read(self, size: int) -> bytes:
|
||||
"""Return 'size' bytes from the current postion"""
|
||||
"""Return 'size' bytes from the current position"""
|
||||
layer = self._context.layers[self._layer_name]
|
||||
buf = layer.read(offset=self._position, length=size)
|
||||
self._position += size
|
||||
|
||||
@@ -21,7 +21,7 @@ from volatility3.framework.symbols.linux import extensions
|
||||
|
||||
vollog = logging.getLogger(__name__)
|
||||
|
||||
# This module is responsbile for producing an ELF file of a kernel module (LKM) loaded in memory
|
||||
# This module is responsible for producing an ELF file of a kernel module (LKM) loaded in memory
|
||||
# This extraction task is quite complicated as the Linux kernel discards the ELF header at load time
|
||||
# Due to this, to support static analysis, we must create an ELF header and proper file based on the sections
|
||||
# There are also several other significant complications that we must deal with when trying to extract an LKM
|
||||
@@ -423,7 +423,7 @@ class ModuleExtract(interfaces.configuration.VersionableInterface):
|
||||
)
|
||||
if not data:
|
||||
vollog.debug(
|
||||
f"Coult not construct a symbol table for module at {module.vol.offset}. Cannot recover."
|
||||
f"Could not construct a symbol table for module at {module.vol.offset}. Cannot recover."
|
||||
)
|
||||
return None, None, None
|
||||
|
||||
@@ -469,7 +469,7 @@ class ModuleExtract(interfaces.configuration.VersionableInterface):
|
||||
e_shentsize_int = 64
|
||||
header_size = 64
|
||||
|
||||
e_type = struct.pack("<H", 1) # relocateble
|
||||
e_type = struct.pack("<H", 1) # relocatable
|
||||
e_machine = struct.pack("<H", e_machine_int)
|
||||
e_version = struct.pack("<I", 1)
|
||||
e_entry = b"\x00" * int(
|
||||
@@ -762,7 +762,7 @@ class ModuleExtract(interfaces.configuration.VersionableInterface):
|
||||
# ndex into the string table
|
||||
name_index += len(name) + 1
|
||||
|
||||
# concatanate the header and section bytes
|
||||
# concatenate the header and section bytes
|
||||
sections_headers += header_bytes
|
||||
sections_data += section_data
|
||||
|
||||
|
||||
@@ -418,7 +418,7 @@ class Modules(interfaces.configuration.VersionableInterface):
|
||||
):
|
||||
vollog.warning(
|
||||
f"Module addresses aren't aligned to {module_address_alignment} bytes. "
|
||||
"Switching to 1 byte aligment scan method."
|
||||
"Switching to 1 byte alignment scan method."
|
||||
)
|
||||
module_address_alignment = 1
|
||||
|
||||
@@ -641,7 +641,7 @@ class Modules(interfaces.configuration.VersionableInterface):
|
||||
|
||||
kernel = context.modules[vmlinux_name]
|
||||
|
||||
# For arrays, recusively get the value of each member as the type can be different
|
||||
# For arrays, recursively get the value of each member as the type can be different
|
||||
if param_func == getters["param_array_get"]:
|
||||
array = param.arr
|
||||
|
||||
@@ -862,7 +862,7 @@ class ModuleGathererKernel(ModuleGathererInterface):
|
||||
) -> ModuleGathererInterface.gatherer_return_type:
|
||||
"""
|
||||
Returns a ModuleInfo instance that encodes the kernel
|
||||
This is required to map function pointers to the kerenl executable
|
||||
This is required to map function pointers to the kernel executable
|
||||
"""
|
||||
kernel = context.modules[kernel_module_name]
|
||||
|
||||
|
||||
@@ -168,7 +168,7 @@ class SCREEN_INFORMATION(objects.StructType):
|
||||
|
||||
@param truncate: True if the empty rows at the
|
||||
end (i.e. bottom) of the screen buffer should be
|
||||
supressed.
|
||||
suppressed.
|
||||
"""
|
||||
rows = []
|
||||
|
||||
|
||||
@@ -146,7 +146,7 @@ class GUIExtensions(interfaces.configuration.VersionableInterface):
|
||||
self, window, max_windows
|
||||
) -> Generator[Tuple[interfaces.objects.ObjectInterface, str], None, None]:
|
||||
"""
|
||||
Recusively walks and yields the adjacent and child windows
|
||||
Recursively walks and yields the adjacent and child windows
|
||||
"""
|
||||
seen_windows = set()
|
||||
seen_children = set()
|
||||
|
||||
Reference in New Issue
Block a user