Skip to main content

LogOp

Enum LogOp 

Source
pub enum LogOp {
Show 36 variants Noop, CompensationLogRecord, InitializeFileRecordSegment, DeallocateFileRecordSegment, WriteEndOfFileRecordSegment, CreateAttribute, DeleteAttribute, UpdateResidentValue, UpdateNonResidentValue, UpdateMappingPairs, DeleteDirtyClusters, SetNewAttributeSizes, AddIndexEntryRoot, DeleteIndexEntryRoot, AddIndexEntryAllocation, DeleteIndexEntryAllocation, WriteEndOfIndexBuffer, SetIndexEntryVcnRoot, SetIndexEntryVcnAllocation, UpdateFileNameRoot, UpdateFileNameAllocation, SetBitsInNonResidentBitMap, ClearBitsInNonResidentBitMap, HotFix, EndTopLevelAction, PrepareTransaction, CommitTransaction, ForgetTransaction, OpenNonResidentAttribute, OpenAttributeTableDump, AttributeNamesDump, DirtyPageTableDump, TransactionTableDump, UpdateRecordDataRoot, UpdateRecordDataAllocation, Unknown(u16),
}
Expand description

An NTFS $LogFile (LFS) redo/undo operation code.

These are the NTFS log-file-service operations (Brian Carrier, File System Forensic Analysis). The code→operation mapping is transcribed verbatim from the _SolveUndoRedoCodes function in jschicht’s LogFileParser — the exact lookup its GUI runs to label the RedoOP/UndoOP columns — so this enum’s mapping is identical to that tool’s by construction. Names use the canonical spelling (LogFileParser carries a few typos, e.g. “Segement”); the invariant shared with the tool is the numeric code, not the label. A code outside the documented 0x00..=0x22 range is surfaced verbatim via LogOp::Unknown, never silently mapped.

Variants§

§

Noop

§

CompensationLogRecord

§

InitializeFileRecordSegment

§

DeallocateFileRecordSegment

§

WriteEndOfFileRecordSegment

§

CreateAttribute

§

DeleteAttribute

§

UpdateResidentValue

§

UpdateNonResidentValue

§

UpdateMappingPairs

§

DeleteDirtyClusters

§

SetNewAttributeSizes

§

AddIndexEntryRoot

§

DeleteIndexEntryRoot

§

AddIndexEntryAllocation

§

DeleteIndexEntryAllocation

§

WriteEndOfIndexBuffer

§

SetIndexEntryVcnRoot

§

SetIndexEntryVcnAllocation

§

UpdateFileNameRoot

§

UpdateFileNameAllocation

§

SetBitsInNonResidentBitMap

§

ClearBitsInNonResidentBitMap

§

HotFix

§

EndTopLevelAction

§

PrepareTransaction

§

CommitTransaction

§

ForgetTransaction

§

OpenNonResidentAttribute

§

OpenAttributeTableDump

§

AttributeNamesDump

§

DirtyPageTableDump

§

TransactionTableDump

§

UpdateRecordDataRoot

§

UpdateRecordDataAllocation

§

Unknown(u16)

A code outside the documented 0x00..=0x22 range, surfaced verbatim.

Implementations§

Source§

impl LogOp

Source

pub fn from_u16(code: u16) -> Self

Map a raw 16-bit redo/undo operation code to its operation.

Source

pub fn code(self) -> u16

The raw 16-bit operation code (inverse of LogOp::from_u16).

Trait Implementations§

Source§

impl Clone for LogOp

Source§

fn clone(&self) -> LogOp

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Copy for LogOp

Source§

impl Debug for LogOp

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Eq for LogOp

Source§

impl PartialEq for LogOp

Source§

fn eq(&self, other: &LogOp) -> bool

Equality operator ==. Read more
1.0.0 (const: unstable) · Source§

fn ne(&self, other: &Rhs) -> bool

Inequality operator !=. Read more
Source§

impl StructuralPartialEq for LogOp

Auto Trait Implementations§

§

impl Freeze for LogOp

§

impl RefUnwindSafe for LogOp

§

impl Send for LogOp

§

impl Sync for LogOp

§

impl Unpin for LogOp

§

impl UnsafeUnpin for LogOp

§

impl UnwindSafe for LogOp

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.