Difference between revisions of "Truxton file get disk offset"
Jump to navigation
Jump to search
(→Sample) |
|||
| Line 28: | Line 28: | ||
printf( "File began at %" PRIu64 "\n", offset ); | printf( "File began at %" PRIu64 "\n", offset ); | ||
| + | |||
| + | truxton_file_free( file ); | ||
} | } | ||
</syntaxhighlight> | </syntaxhighlight> | ||
Revision as of 04:03, 13 June 2020
This retrieves the byte offset into the original disk image where this file's contents began.
It corresponds to the PhysicalDiskOffset column of the File table.
Syntax
uint64_t truxton_file_get_disk_offset( uint64_t file_handle );
Parameters
file_handle
The handle created by the truxton_file_open_id or truxton_file_open_md5 call.
Return value
The byte offset in the disk image where this file's contents began.
Sample
int print_it(uint64_t truxton)
{
uint64_t file = truxton_file_open_md5(truxton, "9ec8fb6095c35eff2b236863b7caaf10");
if ( file != 0 )
{
return(0);
}
uint64_t offset = truxton_file_get_disk_offset( file );
printf( "File began at %" PRIu64 "\n", offset );
truxton_file_free( file );
}
Note, the PRIu64 in the sample code above is the new standard way of formatting a 64-bit integer in C.
Over the years, different compilers on different operating systems used different format specifiers for things, these PRI macros, along with some tricky string concatenation the compilers perform for you, allow you to maintain a single code base without a bunch of macro magic.