Andrew Case
483cb7e4ee
Add smear checks in MFT parsing code
2024-09-02 15:08:29 -05:00
ikelos and GitHub
517f46e833
Merge pull request #1245 from volatilityfoundation/issues/fix-broken-1173-vesion-bump
...
Bump the modules version number
2024-08-28 08:07:41 +01:00
Mike Auty
6a157a785f
Bump the modules version number
...
Pull-request #1173 bumped the version of the modules plugin (even though
this only needed to be a MINOR version bump, see
https://github.com/volatilityfoundation/volatility3/pull/1173#discussion_r1649614761 ), but failed
to verify that other plugins which relied on it were also updated to
make use of the new plugin. This was the version system working as
intended, but highlighted a review failure that the neither the author, nor the
reviewers, verified that the rest of the framework (specifically other plugins which
relied on modules) worked correctly with the new code (which this kind
of error is designed to fix).
Fixes #1244 .
2024-08-27 14:45:55 +01:00
ikelos and GitHub
c524d8a3d1
Merge pull request #1242 from volatilityfoundation/issues/fix-up-extension-verisioning
...
Remove get_vmlinux calls
2024-08-25 12:28:29 +01:00
Mike Auty
e97abae156
Remove get_vmlinux calls
...
Sorry, I know I asked for it, but I hadn't quite figured out what was
going on. Things in the symbols/linux code are considered part of the
framework, and therefore it's the framework version that should have been
bumped. Since the framework comes packages with LinuxUtilities we can
rely on the version numbers to be suitable. This cleans up the mess I
caused, sorry for the extra work! 5:S
2024-08-24 15:02:37 +01:00
ikelos and GitHub
966d23e301
Merge pull request #1233 from gcmoreira/linux_page_cache
...
Linux Page Cache and IDR
2024-08-24 14:43:35 +01:00
Gustavo Moreira
3bf9f8cec0
PR review fixes: Add typing info to pagecache.Files._follow_symlink()
2024-08-24 12:03:10 +10:00
Gustavo Moreira
90b327e632
PR review fixes: Make mountinfo.get_superblocks() a classmethod and adapt the code using it.
2024-08-24 11:45:29 +10:00
Gustavo Moreira
d627f243e2
PR review fixes: Add typing info to the get_inodes() class method.
2024-08-24 10:55:01 +10:00
Gustavo Moreira
d964e6f61d
PR review fixes: Check for LinuxUtilities version everywhere we use it
2024-08-24 02:06:06 +10:00
Gustavo Moreira
695635199e
PR review fixes: Avoid saving state in the pidhashtable plugin
2024-08-24 01:14:09 +10:00
Gustavo Moreira
3c70c1b9f7
PR review fixes: Use context and module_name instead of vmlinux in ebpf plugin
2024-08-24 00:58:04 +10:00
Gustavo Moreira
feae6a9aa0
PR review fixes: Use plugin's open method instead of the builtin open()
2024-08-24 00:42:52 +10:00
ikelos and GitHub
9bba6287a2
Merge pull request #1213 from forensicxlab/feature/lsof_inodes
...
Improvement: Linux/lsof
2024-08-22 23:45:20 +01:00
k1nd0ne
71cdca5883
Updating version + docstring
2024-08-22 16:45:04 +02:00
Mike Auty
8d7edfdca6
Bump as the release branch has been cut
2024-08-21 20:36:09 +01:00
ikelos and GitHub
4578434bbd
Merge pull request #1236 from sluke-nuix/issues/truecrypt_module_version
...
Update the modules.Modules version requirement.
2024-08-13 17:06:46 +01:00
Steven Luke
918584537f
Update the modules.Modules version requirement.
...
This is a response to PR [#1173 ](https://github.com/volatilityfoundation/volatility3/pull/1173 )
2024-08-13 08:34:35 -04:00
Gustavo Moreira
7efa2210a5
PR review fixes: Adjust LinuxUtilities version since we moved choose_id_storage() back to the IDStorage class.
2024-08-13 01:05:44 -07:00
Gustavo Moreira
f804b44ff6
Fix test.yaml, it should remove *.bin and not *.lime. There is no *.lime atm.
2024-08-13 01:00:57 -07:00
Gustavo Moreira and GitHub
b69c2c762c
Merge branch 'volatilityfoundation:develop' into linux_page_cache
2024-08-10 06:05:33 -03:00
Gustavo Moreira
8f9d565f63
PR review fixes: Fix minor typo to match verb form from other docstrings
2024-08-10 00:49:18 -07:00
Gustavo Moreira
17861618df
PR review fixes: Rename Tree to IDStorage. Move choose_id_storage() form LinuxUtilities to IDStorage. Use context and kernel_module_name instead of vmlinux
2024-08-10 00:13:38 -07:00
Gustavo Moreira
53f3d12341
linuxutilities code improvement. Remove code duplication
2024-08-09 23:35:41 -07:00
k1nd0ne
f22575669a
Modifications following the review
2024-08-09 10:20:28 +02:00
Gustavo Moreira
2c85ea525e
PR review fixes: Fix page extension object get_content() explicit returns mixed with implicit returns.
2024-08-08 02:03:28 -07:00
Gustavo Moreira
06508a4afb
PR review fixes: Fix the IDR's old kernel get_entries
2024-08-08 02:00:27 -07:00
Gustavo Moreira
7a8dea3356
PR review fixes: Code scanning complains about these unused variables. Let's comment them and adapt the FIXME message
2024-08-08 01:57:35 -07:00
Gustavo Moreira
0f3f338633
PR review fixes: Since the IDR, XArray and RadixTree can store any value, it renames the function names to a more generic name
2024-08-08 01:52:57 -07:00
Gustavo Moreira
ee10ba8abb
PR review fixes: Fix IDR explicit returns mixed with implicit returns and improve and fix code.
2024-08-08 01:46:53 -07:00
Gustavo Moreira
de6637c987
PR review fixes: ebpf plugin code improvement. Use the object_from_symbol() instead
2024-08-08 00:52:34 -07:00
Gustavo Moreira
46842981fb
PR review fixes: Use contextlib.suppress() instead of an empty exception handler
2024-08-07 00:24:58 -07:00
Gustavo Moreira
805b3514c3
PR review fixes: Fix page flags list method name, this was introduced earlier in another commit of this PR.
2024-08-07 00:23:19 -07:00
Gustavo Moreira
f737b88d03
PR review fixes: Improve _walk_dentry() and get_inodes() variable names, arguments and return values
2024-08-06 23:12:01 -07:00
Gustavo Moreira
c8cb4465da
PR review fixes: Remove filter function, it isn't needed
2024-08-06 23:08:21 -07:00
Gustavo Moreira
339a9a94f5
PR review fixes: pidhashtable plugin add missing typing.
2024-08-06 23:00:09 -07:00
ikelos and GitHub
6b739f6f6c
Merge pull request #1234 from dadokkio/patch-1
...
add args and kwargs to threads.py init
2024-08-06 22:20:18 +01:00
Arcuri Davide and GitHub
1e3e9e2c78
add args and kwargs to threads.py init
...
Without args and kwargs there were an issue with timeliner plugin that tried to pass additional parameters like progress_callback raising TypeError
2024-08-06 16:28:59 +02:00
Gustavo Moreira
7df0636f30
PR review fixes: Fix pidhashtable plugin explicit returns mixed with implicit returns
2024-08-06 04:57:33 -07:00
Gustavo Moreira
bd37aa3930
PR review fixes: Fix pidhashtable plugin
2024-08-06 04:48:49 -07:00
Gustavo Moreira
c9eb81c95f
PR review fixes: Improve eBPF extension objects: bpf_prog and added bpf_prog_aux. Apply changes to the EBPF and Sockstat plugins.
2024-08-06 04:40:48 -07:00
k1nd0ne
8d6fd3cd78
Moved get_inode_metadata, separated inode and FD processing, error handling precision
2024-08-05 14:28:43 +02:00
ikelos and GitHub
398198042f
Merge branch 'develop' into linux_page_cache
2024-08-04 13:44:37 +01:00
Gustavo Moreira
3e75c2ae9d
Fix @functools.cache . It's available since Python 3.9
2024-08-04 14:40:45 +10:00
Gustavo Moreira
cc04f665e3
Fix inode type
2024-08-03 23:47:28 +10:00
Gustavo Moreira
103537801e
Linux: Add a basic eBPF program enumeration plugin to test and demonstrate using the IDR abstraction
2024-08-03 21:44:38 +10:00
Gustavo Moreira
55212008f8
Linux: Add pidhashtable plugin. This is based on the vol2 plugin, removing ancient kernel support, curating code and enhancing comments, while using the new IDR abstraction included also in this effort.
2024-08-03 21:39:51 +10:00
Gustavo Moreira
ac27d6663a
Linux: Add two page cache plugins, linux.pagecache.Files and linux.pagecache.InodePages
2024-08-03 21:26:29 +10:00
Gustavo Moreira
41684478ad
Linux: Add page cache support, including abstractions like RadixTree, XArray, and IDR, to support both older and latest kernel versions
2024-08-03 21:21:49 +10:00
Gustavo Moreira
a369a9e23c
Linux: dentry object extension: Add a method to walk dentries subdirectories
2024-08-03 21:05:23 +10:00