Difference between revisions of "Truxton file get disk offset"

From truxwiki.com
Jump to navigation Jump to search
(Created page with "This retrieves the byte offset into the original disk image where this file's contents began. It corresponds to the <code>PhysicalDiskOffset</code> column of the <code>File</c...")
 
Line 1: Line 1:
 
This retrieves the byte offset into the original disk image where this file's contents began.
 
This retrieves the byte offset into the original disk image where this file's contents began.
It corresponds to the <code>PhysicalDiskOffset</code> column of the <code>File</code> table.
+
It corresponds to the <code>PhysicalDiskOffset</code> column of the <code>[[File Table | File]]</code> table.
  
 
=Syntax=
 
=Syntax=
Line 12: Line 12:
  
 
=Return value=
 
=Return value=
The offset in the disk image where this file's contents began.
+
The byte offset in the disk image where this file's contents began.
  
 
=Sample=
 
=Sample=
 
 
<syntaxhighlight lang="C" highlight="10">
 
<syntaxhighlight lang="C" highlight="10">
 
int print_it(uint64_t truxton)
 
int print_it(uint64_t truxton)

Revision as of 06:33, 10 June 2020

This retrieves the byte offset into the original disk image where this file's contents began. It corresponds to the PhysicalDiskOffset column of the File table.

Syntax

uint64_t truxton_file_get_disk_offset( uint64_t file_handle );

Parameters

file_handle

The handle created by the truxton_file_open_id or truxton_file_open_md5 call.

Return value

The byte offset in the disk image where this file's contents began.

Sample

int print_it(uint64_t truxton)
{
   uint64_t file = truxton_file_open_md5(truxton, "9ec8fb6095c35eff2b236863b7caaf10");

   if ( file != 0 )
   {
      return(0);
   }

   uint64_t offset = truxton_file_get_disk_offset( file );

   printf( "File began at %" PRIu64 "\n", offset );
}

Note, the PRIu64 in the sample code above is the new standard way of formatting a 64-bit integer in C. Over the years, different compilers on different operating systems used different format specifiers for things, these PRI macros, along with some tricky string concatenation the compilers perform for you, allow you to maintain a single code base without a bunch of macro magic.