Content Status

From truxwiki.com
Jump to navigation Jump to search

When Truxton processes the contents of a file, several things can happen. These defined constants represent the state of the contents of a file in Truxton.

This information is also kept in the [ContentStatus] database table. It is used to set the [ContentStatusID] column of the [File] table.

Name Value Meaning
CONTENT_STATUS_UNKNOWN 0 We don't know what the status of the contents is.
CONTENT_STATUS_ORIGINAL 1 The contents came from the source media.
CONTENT_STATUS_VALID_DATA_LENGTH 2 In NTFS, space for a file can be allocated on the filesystem but not yet written to. The Valid Data Length is the offset into the file where the last byte was written.
CONTENT_STATUS_SPARSE_COLLAPSED 3 The contents are the non-spare regions of the file.
CONTENT_STATUS_ELIMINATED_BY_HASH 4 The contents were eliminated because the hash of the contents was found in a hash set.
CONTENT_STATUS_COPY_ELIMINATED 5 The contents are a copy of another file and therefore not stored.
CONTENT_STATUS_NOT_EXPORTED 6 When importing media from another Truxton instance, the contents were not exported by that other instance of Truxton.
CONTENT_STATUS_ELIMINATED_EMPTY 7 The file had an entropy of zero. Since it contains no information, the bytes were eliminated.
CONTENT_STATUS_LENGTH_NEEDS_RECALCULATING 99 This value is used during carving to calculate file lengths that span freespace regions.