Difference between revisions of "Truxton file get disk offset"
Jump to navigation
Jump to search
(Created page with "This retrieves the byte offset into the original disk image where this file's contents began. It corresponds to the <code>PhysicalDiskOffset</code> column of the <code>File</c...") |
|||
| Line 1: | Line 1: | ||
This retrieves the byte offset into the original disk image where this file's contents began. | This retrieves the byte offset into the original disk image where this file's contents began. | ||
| − | It corresponds to the <code>PhysicalDiskOffset</code> column of the <code>File</code> table. | + | It corresponds to the <code>PhysicalDiskOffset</code> column of the <code>[[File Table | File]]</code> table. |
=Syntax= | =Syntax= | ||
| Line 12: | Line 12: | ||
=Return value= | =Return value= | ||
| − | The offset in the disk image where this file's contents began. | + | The byte offset in the disk image where this file's contents began. |
=Sample= | =Sample= | ||
| − | |||
<syntaxhighlight lang="C" highlight="10"> | <syntaxhighlight lang="C" highlight="10"> | ||
int print_it(uint64_t truxton) | int print_it(uint64_t truxton) | ||
Revision as of 06:33, 10 June 2020
This retrieves the byte offset into the original disk image where this file's contents began.
It corresponds to the PhysicalDiskOffset column of the File table.
Syntax
uint64_t truxton_file_get_disk_offset( uint64_t file_handle );
Parameters
file_handle
The handle created by the truxton_file_open_id or truxton_file_open_md5 call.
Return value
The byte offset in the disk image where this file's contents began.
Sample
int print_it(uint64_t truxton)
{
uint64_t file = truxton_file_open_md5(truxton, "9ec8fb6095c35eff2b236863b7caaf10");
if ( file != 0 )
{
return(0);
}
uint64_t offset = truxton_file_get_disk_offset( file );
printf( "File began at %" PRIu64 "\n", offset );
}
Note, the PRIu64 in the sample code above is the new standard way of formatting a 64-bit integer in C.
Over the years, different compilers on different operating systems used different format specifiers for things, these PRI macros, along with some tricky string concatenation the compilers perform for you, allow you to maintain a single code base without a bunch of macro magic.