-
Notifications
You must be signed in to change notification settings - Fork 11
/
Copy pathandroid_system_log.py
96 lines (85 loc) · 2.96 KB
/
android_system_log.py
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
# coding=utf-8
from PA_runtime import *
def convert_to_timestamp(timestamp):
if len(str(timestamp)) == 13:
timestamp = int(str(timestamp)[0:10])
elif len(str(timestamp)) != 13 and len(str(timestamp)) != 10:
timestamp = 0
elif len(str(timestamp)) == 10:
timestamp = timestamp
ts = TimeStamp.FromUnixTime(timestamp, False)
if not ts.IsValidForSmartphone():
ts = None
return ts
def analyze_startup_time(node, extract_deleted, extract_source):
models = []
if node is None:
return
for item in node.Children:
try:
name = "SYSTEM_BOOT@"
if not item.Name.startswith(name):
continue
index = len(name)
pe = PoweringEvent()
pe.Deleted = item.Deleted
pe.Event.Value = pe.PowerEventType.On
pe.Element.Value = pe.PowerElementType.Device
ts = convert_to_timestamp(item.Name[index: item.Name.index(".")])
pe.TimeStamp.Value = ts
pe.Source.Value = "开机记录"
models.append(pe)
except:
pass
return models
def analyze_restart_time(node, extract_deleted, extract_source):
models = []
if node is None:
return
for item in node.Children:
try:
name = "SYSTEM_RESTART@"
if not item.Name.startswith(name):
continue
index = len(name)
pe = PoweringEvent()
pe.Deleted = item.Deleted
pe.Event.Value = pe.PowerEventType.Reset
pe.Element.Value = pe.PowerElementType.Device
ts = convert_to_timestamp(item.Name[index: item.Name.index(".")])
pe.TimeStamp.Value = ts
pe.Source.Value = "关机记录"
models.append(pe)
except:
pass
return models
def analyze_recovey_time(node, extract_deleted, extract_source):
models = []
if node is None:
return
for item in node.Children:
try:
name = "SYSTEM_RECOVERY_LOG@"
if not item.Name.startswith(name):
continue
index = len(name)
pe = PoweringEvent()
pe.Deleted = item.Deleted
pe.Event.Value = pe.PowerEventType.Recovery
pe.Element.Value = pe.PowerElementType.Device
ts = convert_to_timestamp(item.Name[index: item.Name.index(".")])
pe.TimeStamp.Value = ts
pe.Source.Value = "系统恢复记录"
models.append(pe)
except:
pass
return models
def analyze_system_log(node, extract_deleted, extract_source):
pr = ParserResults()
results = []
results.extend(analyze_startup_time(node, extract_deleted, extract_source))
results.extend(analyze_restart_time(node, extract_deleted, extract_source))
results.extend(analyze_recovey_time(node, extract_deleted, extract_source))
if results:
pr.Models.AddRange(results)
return pr