pub struct Vfs { /* private fields */ }Expand description
The engine handle: the reader openers plus the resolver.
Implementations§
Source§impl Vfs
impl Vfs
Sourcepub fn new() -> Self
pub fn new() -> Self
A Vfs with every fleet reader registered (default_openers).
Sourcepub fn open(&self, path: &Path) -> VfsResult<Evidence>
pub fn open(&self, path: &Path) -> VfsResult<Evidence>
Open evidence at path: resolve the base byte source (an EWF container by
path, or a raw file), then recurse container/volume/filesystem layers and
mount the first filesystem found. A source nothing recognizes yields an
Evidence with fs: None — a genuinely clean unknown, not an error.
Sourcepub fn open_source(&self, source: DynSource) -> VfsResult<Option<DynFs>>
pub fn open_source(&self, source: DynSource) -> VfsResult<Option<DynFs>>
Resolve a filesystem directly from a byte source — an in-memory buffer, a
nested image, or a carved region. Ok(None) when nothing recognizes it.
Sourcepub fn snapshots(&self, path: &Path) -> VfsResult<Vec<SnapshotView>>
pub fn snapshots(&self, path: &Path) -> VfsResult<Vec<SnapshotView>>
Enumerate an APFS volume’s snapshots as a time-indexed [H] cohort. The
path is resolved through any container/volume-system nesting to its APFS
filesystem (exactly as Vfs::open does), then apfs-core lists the
snapshot-metadata tree. Evidence with no APFS filesystem yields an empty
cohort — a genuinely clean “no APFS snapshots here”, not an error.
The returned cohort is a Vec<SnapshotView> (the list form of the richer
state_history_forensic::TemporalCohort<H>, adopted here once the generic
HistoricalSource wiring lands); each view carries an EpochTag derived
from the snapshot’s create_time and a re-openable PathSpec locator.
§Errors
The bootstrap/decoding errors of resolving the path, or an apfs-core decode failure while walking the snapshot-metadata tree.
Sourcepub fn open_snapshot(&self, path: &Path, xid: u64) -> VfsResult<Evidence>
pub fn open_snapshot(&self, path: &Path, xid: u64) -> VfsResult<Evidence>
Re-mount one APFS snapshot by its transaction xid — the end-to-end
counterpart to a SnapshotView locator. Resolves the path to its APFS
filesystem, then mounts the volume state frozen at xid (the live volume
for its own xid, else the retained snapshot). The returned Evidence
carries the snapshot-topped locator and the mounted point-in-time
filesystem.
§Errors
VfsError::Bootstrap if the path resolves to no filesystem;
VfsError::Unsupported if the resolved filesystem is not APFS; or an
apfs-core decode failure (including VfsError::Decode for an unknown
xid).
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for Vfs
impl !UnwindSafe for Vfs
impl Freeze for Vfs
impl Send for Vfs
impl Sync for Vfs
impl Unpin for Vfs
impl UnsafeUnpin for Vfs
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more