Skip to content

Render fixed-width array values - #100

Merged
williballenthin merged 1 commit into
williballenthin:masterfrom
abrignoni:render-fixed-width-arrays
Oct 6, 2026
Merged

williballenthin merged 1 commit into
williballenthin:masterfrom
abrignoni:render-fixed-width-arrays

Conversation

@abrignoni

Copy link
Copy Markdown
Contributor

python-evtx renders one array value type, the UTF-16 string array (0x81). Any other array type raises KeyError in get_variant_value, so the record can't be rendered at all. The except there catches IndexError, which a dict lookup never raises, so the "not implemented" message never shows either.

This adds the array types with a fixed element size: 8 to 64-bit integers, float and double, GUID, FILETIME, SYSTEMTIME, and hex 32/64 (0x83 to 0x8a, 0x8b, 0x8c, 0x8f, 0x91, 0x92, 0x94, 0x95). Each element is rendered by the existing node for its type, and the array comes out as pieces, the same way WstringArrayTypeNode does it. Element sizes follow libyal's EVTX format documentation. Boolean, size_t, SID and ASCII string arrays are left alone. The except now catches KeyError.

Where I ran into it: Ntfs Operational events 10, 146 and 149, a Hyper-V Hypervisor Admin event, and TPM event 27 in Windows 11 System logs. Across 635 logs from four public test images and two Windows 11 captures (314,808 records), 344 records failed before and 1 after (an unrelated UTF-16 decode error). Every array value matched the Rust evtx parser's output, and every record that rendered before renders byte for byte the same.

New tests in tests/test_array_types.py. Full suite passes.

get_variant_value only knows the UTF-16 string array (0x81). Any other
array type raised KeyError, which the except IndexError around the lookup
never caught, so the whole record failed to render.

Add the arrays whose elements have a fixed size: 8 to 64-bit integers,
float and double, GUID, FILETIME, SYSTEMTIME and hex 32/64. Each element
is rendered by the existing node for its type, and the array comes out
as <string> pieces like WstringArrayTypeNode. The lookup now catches
KeyError.

@williballenthin williballenthin left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

awesome!

@williballenthin
williballenthin merged commit c000744 into williballenthin:master Oct 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants