-
Notifications
You must be signed in to change notification settings - Fork 596
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
LVM/LVM2 Volume Support #7888
Comments
I think it may be related. Please also see @arisjr and @joachimmetz implemented several fixes and improvements in TSK LVM support and it is waiting review from the TSK team here: sleuthkit/sleuthkit#2820 |
Unfortunately the whole pool layer and integration with TSK framework is scarcely documented see: sleuthkit/sleuthkit#2748 |
Thanks. Do you think this is an autopsy issue or a TSK issue? Do you have a small disk image that we can replicate it with? |
The current plan is to start cleaning things up in a few weeks, As soon as we get some tooling in place to allow us to verify the correctness of patches. So what I would really like is some kind of self test that fails right now and that then passes when the patches supplied. |
@simsong I think the changes pending in sleuthkit/sleuthkit#2748 will likely address the immediate issue, but the TSK pool layer documentation and implementation could benefit from some love and attention |
AFAIK @arisjr generated a few ones to reproduce the issue and test the fixes he sent to @joachimmetz for review who later created sleuthkit/sleuthkit#2820, not sure if @arisjr still has the test images. |
Hello, Right now I could find this two small and simple images that could be tested with the PR. Simple test disk with lvm Ubuntu server default installation Thanks and regards |
just ran into the same |
I noticed that Autopsy seems to have issues with LVM volumes on Linux images. The image file is added, and you'll probably get the boot partition, but nothing else. All other partitions show up as unknown/unallocated and aren't browsable. Notice there's no root, home, etc, var, etc.
This is the same disk viewed in FTK, just to show it isn't a corrupted disk or something. You can see the beginning of dev, etc, and the rest of a Linux file system.
Tip for anyone else having this issue, right click and create disk as is shown in that screenshot, and you can open that disk in Autopsy.
I don't know if this is related to sepinf-inc/IPED#587 which seems to be a downstream issue for Sleuthkit, which may be a downstream issue for Autopsy. Given that I can see references to libvslvm in Autopsy though, I'm hoping the issue may be the same (build is not linking) and it will be an easy fix.
The text was updated successfully, but these errors were encountered: