mirror of
https://github.com/mvt-project/mvt.git
synced 2026-09-11 12:18:57 +02:00
The `dumpsys settings` parser matched a single regex per line, which truncated every value that spans more than one line and, when `defaultSystemSet:` did not fall on the first line, left the trailing `default:` metadata inside the value. It also keyed results by setting name within a namespace, so a name recorded twice kept only the last row and a row without a `pkg:` field was dropped entirely. Replace it with a line loop that accumulates one record at a time and splits the `key:value` fields once the whole record has been read. Results become a list of records carrying the fields dumpsys prints: namespace, user, _id, name, value, pkg, default and defaultSystemSet, plus the per-setting change history. History timestamps are printed without a year, so they are resolved against the "ending at:" time of the section and serialized into the timeline. This shows which package changed a security-relevant setting, and when. The androidqf settings module shares this artifact, so it now emits the same record shape.
32 lines
1.1 KiB
Python
32 lines
1.1 KiB
Python
# Mobile Verification Toolkit (MVT)
|
|
# Copyright (c) 2021-2023 The MVT Authors.
|
|
# Use of this software is governed by the MVT License 1.1 that can be found at
|
|
# https://license.mvt.re/1.1/
|
|
|
|
from pathlib import Path
|
|
|
|
from mvt.android.modules.androidqf.aqf_settings import AQFSettings
|
|
from mvt.common.module import run_module
|
|
|
|
from ..utils import get_android_androidqf, list_files
|
|
|
|
|
|
class TestSettingsModule:
|
|
def test_parsing(self):
|
|
data_path = get_android_androidqf()
|
|
m = AQFSettings(target_path=data_path)
|
|
files = list_files(data_path)
|
|
parent_path = Path(data_path).absolute().parent.as_posix()
|
|
m.from_dir(parent_path, files)
|
|
run_module(m)
|
|
assert len(m.results) == 9
|
|
assert {result["namespace"] for result in m.results} == {"random"}
|
|
assert m.results[0] == {
|
|
"namespace": "random",
|
|
"user": None,
|
|
"name": "samsung_errorlog_agree",
|
|
"value": "0",
|
|
}
|
|
assert len(m.alertstore.alerts) == 1
|
|
assert "samsung_errorlog_agree" in m.alertstore.alerts[0].message
|