Repository navigation
Render fixed-width array values - #100
Merged
williballenthin merged 1 commit intoOct 6, 2026
Merged
Conversation
get_variant_value only knows the UTF-16 string array (0x81). Any other array type raised KeyError, which the except IndexError around the lookup never caught, so the whole record failed to render. Add the arrays whose elements have a fixed size: 8 to 64-bit integers, float and double, GUID, FILETIME, SYSTEMTIME and hex 32/64. Each element is rendered by the existing node for its type, and the array comes out as <string> pieces like WstringArrayTypeNode. The lookup now catches KeyError.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
python-evtx renders one array value type, the UTF-16 string array (0x81). Any other array type raises KeyError in get_variant_value, so the record can't be rendered at all. The except there catches IndexError, which a dict lookup never raises, so the "not implemented" message never shows either.
This adds the array types with a fixed element size: 8 to 64-bit integers, float and double, GUID, FILETIME, SYSTEMTIME, and hex 32/64 (0x83 to 0x8a, 0x8b, 0x8c, 0x8f, 0x91, 0x92, 0x94, 0x95). Each element is rendered by the existing node for its type, and the array comes out as pieces, the same way WstringArrayTypeNode does it. Element sizes follow libyal's EVTX format documentation. Boolean, size_t, SID and ASCII string arrays are left alone. The except now catches KeyError.
Where I ran into it: Ntfs Operational events 10, 146 and 149, a Hyper-V Hypervisor Admin event, and TPM event 27 in Windows 11 System logs. Across 635 logs from four public test images and two Windows 11 captures (314,808 records), 344 records failed before and 1 after (an unrelated UTF-16 decode error). Every array value matched the Rust evtx parser's output, and every record that rendered before renders byte for byte the same.
New tests in tests/test_array_types.py. Full suite passes.