Add in UnresolvedTemplate type.

This template type allows objects that have not been able to be resolved
to exist within the symbol system.  It emits a debug message on creation
so that intermediate format developers can identify potential issues,
but does not raise an exception so as to allow partial tables to be
used.

If the UnresolvedTemplate is called (to create an object) before the
symbol has been added to the symbolspace, it will fail with a
SymbolError (as thrown by the individual SymbolTable).  For this reason,
the class has been made private to the SymbolSpace class to prevent
unexpected use.
This commit is contained in:
Mike Auty
2016-10-30 16:54:12 +00:00
parent 287baeb03a
commit d1b58143fe
3 changed files with 73 additions and 4 deletions
+18 -2
View File
@@ -3,8 +3,12 @@ Created on 1 Mar 2013
@author: mike
"""
import logging
from volatility.framework import interfaces, validity
from volatility.framework.exceptions import SymbolError
vollog = logging.getLogger(__name__)
class ObjectTemplate(interfaces.objects.Template, validity.ValidityRoutines):
@@ -44,8 +48,6 @@ class ObjectTemplate(interfaces.objects.Template, validity.ValidityRoutines):
def replace_child(self, old_child, new_child):
"""A function for replacing one child with another
We pass in the kwargs directly so they can be changed
"""
return self.vol.object_class.VolTemplateProxy.replace_child(self, old_child, new_child)
@@ -68,6 +70,20 @@ class ReferenceTemplate(interfaces.objects.Template):
It should not return any attributes
"""
@property
def children(self):
return []
@property
def _unresolved(self, *args, **kwargs):
"""Referenced symbols must be appropriately resolved before they can provide information such as size
This is because the size request has no context within which to determine the actual symbol structure.
"""
raise SymbolError("Template {0} contains no information about its structure".format(self.vol.type_name))
size = property(_unresolved)
replace_child = relative_child_offset = _unresolved
def __call__(self, context, object_info):
template = context.symbol_space.get_type(self.vol.type_name)
return template(context = context, object_info = object_info)