Skip to content

velociraptor: get_client_flow_results - optional artifact, no IndexError on multi-source artifacts (fixes #458) - #461

Open
chiefghost47 wants to merge 1 commit into
Shuffle:masterfrom
chiefghost47:velociraptor-fix-flow-results
Open

chiefghost47 wants to merge 1 commit into
Shuffle:masterfrom
chiefghost47:velociraptor-fix-flow-results

Conversation

@chiefghost47

Copy link
Copy Markdown
Contributor

Problem

get_client_flow_results raises IndexError: list index out of range for artifacts with more than
one source, e.g. Generic.Client.Info (#458). Without an artifact= argument, flow_results()
returns no rows for those, and the method returns results[0].

Fix

  • api.yaml: an optional artifact parameter on get_client_flow_results (an artifact name, or
    Artifact/Source, e.g. Generic.Client.Info/BasicInformation).
  • src/app.py:
    • when artifact is set, it is passed to flow_results() and all rows are returned;
    • when it is empty, the previous return value is kept (the first row), but an empty result now
      returns [] instead of raising IndexError.
  • artifact is checked against [A-Za-z0-9_.]+(/[A-Za-z0-9_.]+)? before it is placed in the query,
    so the new input cannot alter the VQL.

There is no behaviour change for existing workflows that get results today.

Testing

Against Velociraptor 0.77.3, calling the app's own methods in an image built with the repo's
Dockerfile:

Case Before After
Multi-source artifact (Generic.Client.Info), no artifact IndexError returns [], no exception
The same flow with artifact='Generic.Client.Info/BasicInformation' n/a returns the rows
artifact value x') FROM scope() -- n/a refused with ValueError before any query
Single-source artifact (Linux.Sys.Users), no artifact first row first row, unchanged

The test image also carried #457 (org_id) so the calls could run in a non-root org. Both PRs change
the get_client_flow_results signature, so whichever is merged second needs a one-line rebase. I'm
happy to do that.

Fixes #458

…ce artifacts (Shuffle#458)

Optional artifact parameter (Artifact or Artifact/Source, validated) is passed to
flow_results(); without it the previous return value is kept, but an empty result
returns [] instead of raising IndexError.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

velociraptor: get_client_flow_results raises IndexError for multi-source artifacts

1 participant