Commit Graph
807 Commits
Author SHA1 Message Date
Mike Auty b470ff3715 Recent changes affect the API (layer.mapping and InvalidAddressException) so get in the habit of bumping the version. 2016-07-02 16:30:44 +01:00
Mike Auty be54ea0dda Fix minor docstring typo. 2016-07-02 16:24:17 +01:00
Mike Auty 90fa5574b4 Add in the initial scanning framework. 2016-07-02 15:49:00 +01:00
Mike Auty c626bebb59 Convert mapping to a generator rather than a list. It must still return in sorted order. 2016-07-02 15:48:09 +01:00
Mike Auty fc34850345 Implement mapping with ignore_errors to get a (sorted) list of valid chunks in a layer. 2016-07-02 15:39:36 +01:00
Mike Auty 46190e37a9 Fix padding error in base read function. 2016-07-02 15:30:40 +01:00
Mike Auty 98fff4616c Add in linted spacing by pycharm. 2016-07-02 14:55:52 +01:00
Mike Auty 8c6e7918ee Fix up one missing exception change. 2016-07-02 14:53:41 +01:00
Mike Auty 5290baf73d Make InvalidAddress exceptions more useful. 2016-07-02 13:31:36 +01:00
Mike Auty 14e8346730 Merge branch 'master' of github.com:volatilityfoundation/volatility3 2016-07-02 12:34:19 +01:00
Mike Auty 0c56c494ae Support saving/loading configs to a (JSON) string. 2016-07-02 12:34:09 +01:00
Nick L. Petroni, Jr 02f26e7829 lime.py: improve check -- empty lists evaluate to False 2016-05-26 17:39:54 -04:00
Nick L. Petroni, Jr 2686487e6f lime.py: first working version
- moved segment loading out of __init__(), now happens on first use
- fixed mapping() to return the correct chunk_size
- self._base_layer is a string, not a layer
2016-05-26 17:39:54 -04:00
Nick L. Petroni, Jr f9a950bb39 added LIME translation layer 2016-05-26 17:39:54 -04:00
Mike Auty 633225edb2 Minor reformatting by pycharm for line length. 2016-05-26 09:14:37 +01:00
Mike Auty 472132e574 Clarify and verify that the memory_layer parameter is the name of the memory layer, not the layer itself. 2016-05-26 09:14:09 +01:00
Mike Auty d882f93fee Move the length check, and require a non-zero length to protect is_valid. 2016-05-22 19:23:15 +01:00
Mike Auty 9faa13820a Since we're a forensics program, make sure we only read unless we know the user REALLY wants to write. 2016-05-22 19:21:24 +01:00
Mike Auty 16bed2aa94 Allow specifying a table_name for get_symbols_by_location. 2016-05-22 16:02:30 +01:00
Mike Auty e0b7f0b5f0 Add in helper functions for symbolspaces/symboltables to locate specific symbols. 2016-05-22 15:57:48 +01:00
Mike Auty fea6e0820a Convert to using a BANG variable for the symbol name delimiter.
Whilst it's easy to do now (because we don't yet use it many places)
convert the ! delimiter into a variable.
2016-05-22 15:26:31 +01:00
Mike Auty 34b81a5265 Add in Unions
Since a Union is identical to a Struct (and at the moment a struct
doesn't enforce non-overlapping members), these are identical and a
Union is a descendent of Struct.  If this ever becomes a problem there
is a filthy way to fix it, but it's really bad and will likely cause
more subtle and difficult to diagnose problems.  Stick with inheritance.
2016-05-22 12:03:46 +01:00
Mike Auty 659bfc1670 Add in Symbol class to properly represent programming symbols. 2016-05-22 11:54:44 +01:00
Mike Auty 2d23c93def Completely refactor constants and structures to symbols and types. 2016-05-22 11:51:06 +01:00
Mike Auty 7a62e74996 Refactor the translation method out of the TranslationLayer, since it's not always applicable/useful. Contemplate a rename of the TranslationLayer now it doesn't actually translate. 5;) 2016-04-10 11:54:32 +01:00
Mike Auty 8e49c66049 Ensure we don't find bogus DTBs, but do still allow non-usr-count DTBs. 2016-02-27 14:11:40 +00:00
Mike Auty 9fce3a4b1f Tidy up the tests and add a bit of error checking to the dtb finder. 2016-02-27 11:53:44 +00:00
Mike Auty b06306f884 Fix reducing the tuple mid sorting. 2016-02-27 01:50:38 +00:00
Mike Auty 445031c880 Unfix the self-referential checker. 2016-02-27 01:43:03 +00:00
Mike Auty 29e75339df Fix the self-referential checker again. 2016-02-27 01:40:01 +00:00
Mike Auty dbcb59e0e9 Fix the self-referential checker. 2016-02-27 01:38:29 +00:00
Mike Auty 8ab1dedd44 Change the output to hide the ordering data, and fix up the standalone tool a little bit. 2016-02-26 20:36:57 +00:00
Mike Auty afd28575ca Re-check constraints when building the tree, in case they change. Also comment on why we don't use that when trimming the possibilties for windows automagic. 2016-02-25 22:03:49 +00:00
Mike Auty d6cc66cb77 Add in self referential checker, should windows change what it does. 2016-02-23 10:16:27 +00:00
Mike Auty 1fd8eecebd Ensure we take into account ignored/NX bits when DTB finding. 2016-02-23 10:15:50 +00:00
Mike Auty 644a028ee4 Fix up the dtbfinder output a little. 2016-02-22 01:54:19 +00:00
Mike Auty 7ba06d0448 If we've tried scanning for the DTB, and we don't find in other arches, remove them as possibilities. 2016-02-22 01:47:09 +00:00
Mike Auty 187325f74e Convert the dtbfinding code into a standalone tool and remove the dtbfinder.py. 2016-02-22 01:46:36 +00:00
Mike Auty ff11f27c75 Fix up the automagic dtb finder to visit internal tree nodes, and to set the right variable! 2016-02-22 01:05:50 +00:00
Mike Auty 0298df3569 Convert visitors to HierarchicalVisitors, keeping a stack of children's results for the dependency resolver. 2016-02-22 01:05:16 +00:00
Mike Auty ba9eb0716a Make output on requirement nodes a little more readable. 2016-02-22 01:03:41 +00:00
Mike Auty bacc8c5539 Move to a HierarchicalVisitor pattern. 2016-02-22 01:02:29 +00:00
Mike Auty a123572701 Add in debugging tools for the dependency tree. 2016-02-21 01:24:34 +00:00
Mike Auty 665ba8946b Fix a logic error in the resolver that meant it might not visit every node. 2016-02-21 01:19:42 +00:00
Mike Auty c6a3c2d6b1 Add in the automagic and allow mid-deptree resolution (without trying to re-fulfill already populated requirements). 2016-02-21 00:42:04 +00:00
Mike Auty 9d7e777c28 Fix up the validity class and enable short_circuiting. 2016-02-21 00:17:44 +00:00
Mike Auty 01ac22bac2 Ensure that the success or failure does not affect the ability for a visitor to change the shortcircuiting. 2016-02-20 23:35:16 +00:00
Mike Auty a9ff081da5 Fix a few bugs and re-add a visitor pattern for traversing the tree. 2016-02-20 23:01:41 +00:00
Mike Auty 71b540f6db Draft up a system to tag the configuration tree with useful information based on the context so far. 2016-02-20 21:36:12 +00:00
Mike Auty 1e8c55bfdd Remove all the visitor pattern stuff, that's likely to bloat rather than help. 2016-02-20 21:35:31 +00:00