Repository navigation
Added fiwalk disk image demo - #40
Conversation
…sults to an output file
| with open(imageFile, "rb") as ifs: | ||
| fwOutBuffer = fiwalk.fiwalk_xml_stream(imagefile=ifs) | ||
| fwOut = fwOutBuffer.read() | ||
|
|
||
| # Write dfxml to output file | ||
| with io.open(outFile, "wb") as fOut: | ||
| fOut.write(fwOut) |
There was a problem hiding this comment.
Thanks for the contribution. My concern about this is that it requires the entire XML stream to be buffered in RAM at once (in fwOut) but there may be no realistic way to do this. It will fail for large images, however, unless run on systems with a huge amount of available memory. (The XML format is not very efficient.)
There was a problem hiding this comment.
If there's a more efficient way to do this I'm all for it, because yes I can see how this could easily go wrong for large images. I've never worked with io.BufferedReader objects before though, and I'm not quite sure how to do this.
There was a problem hiding this comment.
I don't think this changes the status quo for how DFXML has been implemented to date. The read-write library dfxml/objects.py does some full-in-memory string construction as well.
My litmus test (not to include in CI!) would probably be seeing if this can run against the NPS 2TB image.
There was a problem hiding this comment.
It’s complicated. I believe there is an iterator in the dfxml package that runs fiwalk as a sub process , parses it with Expat, and calls a provided call back with an object as the argument. This is the interface that all of my code used. But that was 10 years ago.
|
@ajnelson - What's your take? Do we want this, or do we want a more efficient example? |
|
I'm having a look at this now. It looks like |
|
This branch contains two things:
Now, reviewing the other demo apps, there are other memory-efficient demonstrations that use the read-only SAX model. See e.g. The main contribution of I think the demo's worth including within DFXML because there doesn't seem to be a demonstration of If you agree, @bitsgalore , would you mind merging the |
|
@ajnelson-nist With some delay I just added some comments, let me know if this is what you had in mind. As an aside, for my own use case, in the end I decided to wrap the fiwalk tool directly in a custom wrapper using the Anyway, I'll leave it up to your whether you want to proceed with merging this PR or not. |
|
Thank you for the summary. I will merge this once CI finishes. It's good to have the extra annotated demo, and I personally favor more type-annotating. |
Added demo that shows how to use fiwalk on a disk image and report results to an output file