pub struct Vfs { /* private fields */ }Expand description
The engine handle: the reader openers plus the resolver.
Implementations§
Source§impl Vfs
impl Vfs
Sourcepub fn new() -> Self
pub fn new() -> Self
A Vfs with every fleet reader registered (default_openers).
Sourcepub fn open(&self, path: &Path) -> VfsResult<Evidence>
pub fn open(&self, path: &Path) -> VfsResult<Evidence>
Open evidence at path: resolve the base byte source (an EWF container by
path, or a raw file), then recurse container/volume/filesystem layers and
mount the first filesystem found. A source nothing recognizes yields an
Evidence with fs: None — a genuinely clean unknown, not an error.
Sourcepub fn open_all(&self, path: &Path) -> VfsResult<Vec<Evidence>>
pub fn open_all(&self, path: &Path) -> VfsResult<Vec<Evidence>>
Open evidence at path and surface every partition, not just the
first filesystem Vfs::open finds. The first top-level volume system
that claims the base source is forked into one Evidence per volume
that resolves to a filesystem — so a Windows GPT disk yields both its FAT
EFI System Partition and its NTFS Windows volume, instead of stopping at
slot 0. The per-volume container/encryption/filesystem descent is
delegated to the resolver (self.openers.open(..) at depth 1), exactly as
Vfs::open descends a single volume.
A volume that resolves to no filesystem (an MSR reservation, empty space)
is dropped, so the caller only sees mountable partitions. When no volume
system claims the base — a bare volume, a container wrapping one
filesystem, an encrypted volume — this returns a single-element Vec
identical to Vfs::open, preserving the one-filesystem behavior.
§Errors
Propagates the bootstrap error of resolving the base source, a source read
error while sniffing, or a prober open/decode failure raised after a
positive probe verdict.
Sourcepub fn open_source(&self, source: DynSource) -> VfsResult<Option<DynFs>>
pub fn open_source(&self, source: DynSource) -> VfsResult<Option<DynFs>>
Resolve a filesystem directly from a byte source — an in-memory buffer, a
nested image, or a carved region. Ok(None) when nothing recognizes it.
Sourcepub fn snapshots(&self, path: &Path) -> VfsResult<Vec<SnapshotView>>
pub fn snapshots(&self, path: &Path) -> VfsResult<Vec<SnapshotView>>
Enumerate an APFS volume’s snapshots as a time-indexed [H] cohort. The
path is resolved through any container/volume-system nesting to its APFS
filesystem (exactly as Vfs::open does), then apfs-core lists the
snapshot-metadata tree. Evidence with no APFS filesystem yields an empty
cohort — a genuinely clean “no APFS snapshots here”, not an error.
The returned cohort is a Vec<SnapshotView> (the list form of the richer
state_history_forensic::TemporalCohort<H>, adopted here once the generic
HistoricalSource wiring lands); each view carries an EpochTag derived
from the snapshot’s create_time and a re-openable Locator locator.
§Errors
The bootstrap/decoding errors of resolving the path, or an apfs-core decode failure while walking the snapshot-metadata tree.
Sourcepub fn open_snapshot(&self, path: &Path, xid: u64) -> VfsResult<Evidence>
pub fn open_snapshot(&self, path: &Path, xid: u64) -> VfsResult<Evidence>
Re-mount one APFS snapshot by its transaction xid — the end-to-end
counterpart to a SnapshotView locator. Resolves the path to its APFS
filesystem, then mounts the volume state frozen at xid (the live volume
for its own xid, else the retained snapshot). The returned Evidence
carries the snapshot-topped locator and the mounted point-in-time
filesystem.
§Errors
VfsError::Bootstrap if the path resolves to no filesystem;
VfsError::Unsupported if the resolved filesystem is not APFS; or an
apfs-core decode failure (including VfsError::Decode for an unknown
xid).
Trait Implementations§
Auto Trait Implementations§
impl !RefUnwindSafe for Vfs
impl !UnwindSafe for Vfs
impl Freeze for Vfs
impl Send for Vfs
impl Sync for Vfs
impl Unpin for Vfs
impl UnsafeUnpin for Vfs
Blanket Implementations§
Source§impl<T> BorrowMut<T> for Twhere
T: ?Sized,
impl<T> BorrowMut<T> for Twhere
T: ?Sized,
Source§fn borrow_mut(&mut self) -> &mut T
fn borrow_mut(&mut self) -> &mut T
Source§impl<T> IntoEither for T
impl<T> IntoEither for T
Source§fn into_either(self, into_left: bool) -> Either<Self, Self>
fn into_either(self, into_left: bool) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left is true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read moreSource§fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
fn into_either_with<F>(self, into_left: F) -> Either<Self, Self>
self into a Left variant of Either<Self, Self>
if into_left(&self) returns true.
Converts self into a Right variant of Either<Self, Self>
otherwise. Read more