TRACE 2.1.0
New
- Btrfs (#13) —
the default file system of Fedora and openSUSE. Every subvolume and
snapshot, zlib / LZO / zstd compression, sparse files, and one disk of a
RAID1 read on its own. Tested against fox-it/dissect.btrfs's published
values and a real Fedora 44 install, where every tree node and data
sector matched its stored checksum and 22,831 installed files matched
the RPM database. - Each image gets the modules that can find something in it. The
Analysis Modules dialog lists the case's images with what each holds
(GPT · FAT16, Btrfs · Linux); one selection for all of them, or one per
image. A module that cannot find anything in an image is greyed out
there, with the reason — the NTFS module is no longer run on a Linux
disk. - File system timeline — created, modified, accessed and changed
times of every file and folder on ext, Btrfs, XFS, HFS+, APFS, FAT and
exFAT now reach the Timeline (until now only NTFS's did). FAT and exFAT
times carry no time zone and are shown as local. - Linux: the system (release, host name, time zone), user accounts and
who can use sudo, software installed and removed (dnf, apt), SSH hosts
and keys. Persistence now reads Linux (systemd, cron, SysV, Upstart,
rc.local, ld.so.preload, autostart, SSH keys) and macOS (launch agents
and daemons), graded by what they start. - Crash log — a crash now leaves its stack in
crash.log, and the next
start says so intrace.log.
Fixed
- QCOW2: compressed images (as distributions and
qemu-img convert -c
write them) read about half their data as zeros through libqcow. TRACE
now reads QCOW2 itself. - Carving "unallocated space only" carved live files on APFS, XFS and
Btrfs and reported them as recovered: free space is now taken from each
file system's own records. Inside LVM, LUKS and FileVault, where free
space cannot be told from used, the partition is skipped and the log
says so. - Listing search found nothing on QCOW2, VHD, VMDK, DMG, AFF4, AD1 /
L01, BitLocker, LVM, APFS, XFS or Btrfs evidence; it now searches every
image. Search results open on the image they came from, names starting
with a dot and links are found, and clicking a FAT, exFAT, ext or Btrfs
partition lists its files. - Empty files no longer show as read errors; links on XFS and APFS read as
their target.
Requirements
backports.zstd(Python 3.10–3.13; wheels for every platform) reads
zstd-compressed data about 45 times faster.
Full Changelog: v2.0.0...v2.1.0