Repository navigation
TSKVolumeSystem bytes_per_sector #45
Description
Activity
- addedquestionThis issue is a questionThis issue is a question
on Jul 22, 2015 Is there a way to find and set the bytes per sector for a TSKVolumeSystem?Not at the moment. I would also need to check if and how that can be propagated in pytsk and TSK.
os_path_spec = path_spec_factory.Factory.NewPathSpec( dfvfs_definitions.TYPE_INDICATOR_OS, location='\\\\.\\PHYSICALDRIVE1' )Since Python os does not support
\.\PhysicalDrive1as a file, dfvfs TYPE_INDICATOR_OS uses pysmdev instead. Also see: https://github.com/log2timeline/dfvfs/blob/master/dfvfs/file_io/os_file_io.py#L65Hence try:
import pysmdev smdev_handle = pysmdev.handle() smdev_handle.open('\\\\.\\PHYSICALDRIVE1') print(smdev_handle.bytes_per_sector) smdev_handle.close()
Generated a 4k MBR test image
mmls test_data/mbr_4k_sector.raw DOS Partition Table Offset Sector: 0 Units are in 512-byte sectors Slot Start End Length Description 000: Meta 0000000000 0000000000 0000000001 Primary Table (#0) 001: ------- 0000000000 0000000000 0000000001 Unallocated 002: 000:000 0000000001 0000000017 0000000017 Linux (0x83) 003: Meta 0000000018 0000001023 0000001006 DOS Extended (0x05) 004: ------- 0000000018 0000008191 0000008174 UnallocatedBy default mmls (and therefore assuming libtsk/pytsk as well) this as 512 bytes per sector. With a manual override:
mmls -b 4096 test_data/mbr_4k_sector.raw DOS Partition Table Offset Sector: 0 Units are in 4096-byte sectors Slot Start End Length Description 000: Meta 0000000000 0000000000 0000000001 Primary Table (#0) 001: ------- 0000000000 0000000000 0000000001 Unallocated 002: 000:000 0000000001 0000000017 0000000017 Linux (0x83) 003: Meta 0000000018 0000001023 0000001006 DOS Extended (0x05) 004: Meta 0000000018 0000000018 0000000001 Extended Table (#1) 005: ------- 0000000018 0000000018 0000000001 Unallocated 006: 001:000 0000000019 0000000035 0000000017 Linux (0x83) 007: ------- 0000000036 0000001023 0000000988 UnallocatedTo consider:
- support manual override of sector size?
- add sector size detection in dfVFS to work around limitation in libtsk/pytsk?
- alternative MBR support also see Improve volume system support #83
Looks like sleuthkit has a long standing issue about this sleuthkit/sleuthkit#752
changes to allow pytsk to set sector size https://github.com/py4n6/pytsk/pull/149/changes via Img_Info constructor
Cannot use SleuthKit for reliable MBR block size detection:
mmls -b 4096 test_data/mbr.raw DOS Partition Table Offset Sector: 0 Units are in 4096-byte sectors Slot Start End Length Description 000: Meta 0000000000 0000000000 0000000001 Primary Table (#0) 001: ------- 0000000000 0000000000 0000000001 Unallocated 002: 000:000 0000000001 0000000129 0000000129 Linux (0x83) 003: Meta 0000000130 0000008191 0000008062 DOS Extended (0x05) 004: ------- 0000000130 0000001023 0000000894 UnallocatedFor reliable detection this should fail
mmls test_data/mbr.raw DOS Partition Table Offset Sector: 0 Units are in 512-byte sectors Slot Start End Length Description 000: Meta 0000000000 0000000000 0000000001 Primary Table (#0) 001: ------- 0000000000 0000000000 0000000001 Unallocated 002: 000:000 0000000001 0000000129 0000000129 Linux (0x83) 003: Meta 0000000130 0000008191 0000008062 DOS Extended (0x05) 004: Meta 0000000130 0000000130 0000000001 Extended Table (#1) 005: ------- 0000000130 0000000130 0000000001 Unallocated 006: 001:000 0000000131 0000000259 0000000129 Linux (0x83) 007: ------- 0000000260 0000008191 0000007932 UnallocatedAlternative option is to add sector_size to SourceScanner - this might be also needed as fallback for situation where the sector size cannot be detected
- linked a pull request that will close this issueChanges to support non 512 block sizes with TSK partition #822
on Jul 17, 2026 Changes in #822 to set sector_size manually
I have a drive that has geometry with 4096 bytes per sector.
When I create a TSKVolumeSystem, and feed it the volume_system_path_spec of TYPE_INDICATOR_TSK_PARTITION, it shows that the TSKVolumeSystem.bytes_per_sector attribute as 512. This interns shows the incorrect offset for the partitions.
Is there a way to find and set the bytes per sector for a TSKVolumeSystem?
Here is what FTK Imager shows for the drive:

Partition Start Sector [2048]:

Offset then to partition is 2048 * 4096 = 8388608
I see in dfvfs TSKVolumeSystem._Parse() there is:
self.bytes_per_sector = tsk_partition.TSKVolumeGetBytesPerSector(tsk_volume)
Am I not passing something or are the BytesPerSector not being found correctly?
Here is output and an example code I used.