From d829028a36ab12b83cfa29256586ced2092a23c3 Mon Sep 17 00:00:00 2001 From: Mike Auty Date: Fri, 5 Oct 2018 00:16:42 +0100 Subject: [PATCH] Apply various type annotation/bug fixes. --- volatility/framework/automagic/linux.py | 2 +- volatility/framework/interfaces/context.py | 1 + volatility/framework/plugins/__init__.py | 4 ++-- volatility/framework/symbols/windows/extensions/pe.py | 2 +- volatility/plugins/timeliner.py | 4 ++-- volatility/plugins/windows/moddump.py | 1 - volatility/plugins/windows/registry/userassist.py | 4 ++-- volatility/plugins/windows/verinfo.py | 5 +++-- 8 files changed, 12 insertions(+), 11 deletions(-) diff --git a/volatility/framework/automagic/linux.py b/volatility/framework/automagic/linux.py index 42dc87de7..b198243c1 100644 --- a/volatility/framework/automagic/linux.py +++ b/volatility/framework/automagic/linux.py @@ -18,7 +18,7 @@ class LinuxSymbolFinder(interfaces.automagic.AutomagicInterface): context: interfaces.context.ContextInterface, config_path: str) -> None: super().__init__(context, config_path) - self._requirements = [] # type: typing.List[typing.Tuple[str, str, interfaces.configuration.ConstructableRequirementInterface]] + self._requirements = [] # type: typing.List[typing.Tuple[str, interfaces.configuration.ConstructableRequirementInterface]] self._linux_banners_ = {} # type: linux_symbol_cache.LinuxBanners @property diff --git a/volatility/framework/interfaces/context.py b/volatility/framework/interfaces/context.py index b3a7ef814..ed1fd0d6f 100644 --- a/volatility/framework/interfaces/context.py +++ b/volatility/framework/interfaces/context.py @@ -58,6 +58,7 @@ class ContextInterface(object, metaclass = ABCMeta): symbol: typing.Union[str, 'interfaces.objects.Template'], layer_name: str, offset: int, + native_layer_name: str = None, **arguments): """Object factory, takes a context, symbol, offset and optional layer_name diff --git a/volatility/framework/plugins/__init__.py b/volatility/framework/plugins/__init__.py index 6f1c43b45..6e95389ad 100644 --- a/volatility/framework/plugins/__init__.py +++ b/volatility/framework/plugins/__init__.py @@ -1,7 +1,7 @@ import logging import typing -from volatility.framework import interfaces, automagic, exceptions, constants +from volatility.framework import interfaces, automagic, exceptions, constants, validity vollog = logging.getLogger(__name__) @@ -10,7 +10,7 @@ def run_plugin(context: interfaces.context.ContextInterface, automagics: typing.List[interfaces.automagic.AutomagicInterface], plugin: typing.Type[interfaces.plugins.PluginInterface], base_config_path: str, - progress_callback: interfaces.layers.ProgressValue, + progress_callback: validity.ProgressCallback, file_consumer: interfaces.plugins.FileConsumerInterface) -> interfaces.plugins.PluginInterface: """Constructs a plugin object based on the parameters diff --git a/volatility/framework/symbols/windows/extensions/pe.py b/volatility/framework/symbols/windows/extensions/pe.py index f2991df45..9599bd5ce 100644 --- a/volatility/framework/symbols/windows/extensions/pe.py +++ b/volatility/framework/symbols/windows/extensions/pe.py @@ -77,7 +77,7 @@ class _IMAGE_DOS_HEADER(objects.Struct): newval = struct.pack(nt_header.OptionalHeader.ImageBase.vol.struct_format, int(self.vol.offset)) return raw_data[:image_base_offset] + newval + raw_data[image_base_offset + member_size:] - def reconstruct(self) -> typing.Tuple[int, bytes]: + def reconstruct(self) -> typing.Generator[typing.Tuple[int, bytes], None, None]: """This method generates the content necessary to reconstruct a PE file from memory. It preserves slack space (similar to the old --memory) and automatically fixes the ImageBase in the output PE file. diff --git a/volatility/plugins/timeliner.py b/volatility/plugins/timeliner.py index a951adbce..3bca79cfd 100644 --- a/volatility/plugins/timeliner.py +++ b/volatility/plugins/timeliner.py @@ -27,7 +27,7 @@ class TimeLinerInterface(object, metaclass = abc.ABCMeta): @abc.abstractmethod def generate_timeline(self) -> typing.Generator[ - typing.Tuple[str, TimeLinerType, datetime.datetime, TimeLinerType], None, None]: + typing.Tuple[str, TimeLinerType, datetime.datetime], None, None]: """Method generates Tuples of (description, timestamp_type, timestamp) These need not be generated in any particular order, sorting will be done later @@ -45,7 +45,7 @@ class Timeliner(interfaces.plugins.PluginInterface): @classmethod def get_usable_plugins(cls, selected_list: typing.List[str] = None) \ - -> typing.List[typing.Type[TimeLinerInterface]]: + -> typing.List[typing.Type]: # Initialize for the run plugin_list = list(framework.class_subclasses(TimeLinerInterface)) diff --git a/volatility/plugins/windows/moddump.py b/volatility/plugins/windows/moddump.py index a78146d9a..f531cf3e2 100644 --- a/volatility/plugins/windows/moddump.py +++ b/volatility/plugins/windows/moddump.py @@ -46,7 +46,6 @@ class ModDump(interfaces_plugins.PluginInterface): seen_ids = [] # type: typing.List[interfaces.objects.ObjectInterface] filter_func = pslist.PsList.create_filter(pids or []) - result = [] for proc in pslist.PsList.list_processes(context = context, layer_name = layer_name, symbol_table = symbol_table, diff --git a/volatility/plugins/windows/registry/userassist.py b/volatility/plugins/windows/registry/userassist.py index 61095f4f7..edc6527de 100644 --- a/volatility/plugins/windows/registry/userassist.py +++ b/volatility/plugins/windows/registry/userassist.py @@ -113,7 +113,7 @@ class UserAssist(interfaces_plugins.PluginInterface): return self.context.symbol_space.get_type( self.config['nt_symbols'] + constants.BANG + "_KUSER_SHARED_DATA").has_member('CookiePad') - def list_userassist(self, hive: RegistryHive) -> typing.Generator: + def list_userassist(self, hive: RegistryHive): """Generate userassist data for a registry hive.""" hive_name = hive.hive.cast(self.config["nt_symbols"] + constants.BANG + "_CMHIVE").get_name() @@ -155,7 +155,7 @@ class UserAssist(interfaces_plugins.PluginInterface): renderers.NotApplicableValue(), renderers.NotApplicableValue(), renderers.NotApplicableValue(), - renderers.NotApplicableValue())) + renderers.NotApplicableValue())) # type: typing.Tuple[int, typing.Tuple[format_hints.Hex, typing.Any, typing.Any, typing.Any, typing.Any, typing.Any, typing.Any, typing.Any, typing.Any, typing.Any, typing.Any, typing.Any]] yield result # output any subkeys under Count diff --git a/volatility/plugins/windows/verinfo.py b/volatility/plugins/windows/verinfo.py index 0440ae93d..2fae681a6 100644 --- a/volatility/plugins/windows/verinfo.py +++ b/volatility/plugins/windows/verinfo.py @@ -37,7 +37,7 @@ class VerInfo(interfaces_plugins.PluginInterface): context: interfaces.context.ContextInterface, pe_table_name: str, layer_name: str, - base_address: int) -> typing.Optional[typing.Tuple[int]]: + base_address: int) -> typing.Tuple[int, int, int, int]: """Get File and Product version information from PE files Args: @@ -95,7 +95,8 @@ class VerInfo(interfaces_plugins.PluginInterface): BaseDllName = renderers.UnreadableValue() session_layer_name = moddump.ModDump.find_session_layer(self.context, session_layers, mod.DllBase) - (major, minor, product, build) = [renderers.NotAvailableValue()] * 4 + (major, minor, product, build) = [ + renderers.NotAvailableValue()] * 4 # type: typing.Tuple[typing.Union[int, interfaces.renderers.BaseAbsentValue],typing.Union[int, interfaces.renderers.BaseAbsentValue],typing.Union[int, interfaces.renderers.BaseAbsentValue],typing.Union[int, interfaces.renderers.BaseAbsentValue]] try: (major, minor, product, build) = self.get_version_information(self._context, pe_table_name,