Truxton file get disk offset
Jump to navigation
Jump to search
This retrieves the byte offset into the original disk image where this file's contents began.
It corresponds to the [PhysicalDiskOffset] column of the [File] table.
Syntax
uint64_t truxton_file_get_disk_offset( uint64_t file_handle );
Parameters
file_handle
The handle created by the truxton_file_open_id or truxton_file_open_md5 call.
Return value
The byte offset in the disk image where this file's contents began.
Sample
void print_it( uint64_t truxton )
{
uint64_t file = truxton_file_open_md5( truxton, "9ec8fb6095c35eff2b236863b7caaf10" );
if ( file != 0 )
{
return;
}
uint64_t offset = truxton_file_get_disk_offset( file );
printf( "File began at %" PRIu64 "\n", offset );
truxton_file_free( file );
}
Note, the PRIu64 in the sample code above is the new standard way of formatting a 64-bit integer in C.
Over the years, different compilers on different operating systems used different format specifiers for things, these PRI macros, along with some tricky string concatenation the compilers perform for you, allow you to maintain a single code base without a bunch of macro magic.