How 7-Zip Inspects FAT32 and NTFS Boot Sectors

7-Zip can parse and extract files directly from raw disk images, such as .img, .dd, or uncompressed virtual disk formats, without requiring administrative privileges or mounting the image through the operating system. It achieves this by acting as a stream-level file system parser. By scanning the disk image for partition tables and reading the partition boot records—specifically the BIOS Parameter Block (BPB) for FAT32 and NTFS—7-Zip interprets the geometry and file tables of the raw data directly within its internal archive handlers.

Partition Detection and Offset Calculation

When opening a raw disk dump, 7-Zip first determines whether the file represents an entire partitioned disk or a standalone partition.

  1. Full Disk Images (MBR/GPT): 7-Zip checks sector 0 (LBA 0) for Master Boot Record (MBR) structures, verifying the 0x55AA signature at offset 0x1FE and evaluating the partition table entries starting at offset 0x1BE. For GUID Partition Tables (GPT), it reads LBA 1 to find the "EFI PART" signature and parse the partition arrays. Once a partition is identified, 7-Zip calculates the starting byte offset of that partition within the raw dump.
  2. Raw Partition Dumps: If the image is a direct dump of a single volume rather than an entire drive, the boot sector sits directly at byte offset 0.

Once the partition offset is established, 7-Zip routes the stream to the appropriate format handler: NtsfHandler for NTFS or FatHandler for FAT/FAT32.

Parsing the NTFS Boot Sector

To read an NTFS partition, 7-Zip examines the Volume Boot Record (VBR) located at the first sector of the partition:

  • Signature Verification: It checks byte offset 0x03 for the 8-byte OEM identifier string "NTFS ". It also verifies the standard boot record end-of-sector marker 0x55AA at offset 0x1FE.
  • Geometry Extraction: 7-Zip reads the BIOS Parameter Block (BPB) to determine basic volume layout:
    • Bytes per sector at offset 0x0B (typically 512 or 4096).
    • Sectors per cluster at offset 0x0D (determining the cluster size).
  • **Locating the Master File Table (\(MFT):** The critical step occurs at offset `0x30`, where the starting cluster number of the Master File Table (\)MFT) is stored as a 64-bit integer. 7-Zip multiplies this cluster number by the sectors-per-cluster and bytes-per-sector values, adding the partition's starting offset.
  • **Reading \(MFT Records:** Using this calculated byte address, 7-Zip reads record 0 of the `\)MFT, parses its standard 1024-byte record structure, evaluates the FILEmagic bytes, and tracks the$DATA` attribute runs to map out the entire file system hierarchy.

Parsing the FAT32 Boot Sector

For FAT32 partitions, 7-Zip inspects the extended BPB within the volume boot record:

  • Signature Verification: 7-Zip looks for the standard jump instructions at offset 0x00 (0xEB or 0xE9), checks for the file system string "FAT32 " at offset 0x52, and validates the 0x55AA signature at offset 0x1FE.
  • Geometry and Reserved Space: It extracts fundamental layout values:
    • Bytes per sector at offset 0x0B.
    • Sectors per cluster at offset 0x0D.
    • Reserved sector count at offset 0x0E. This dictates the exact offset where the File Allocation Tables (FAT) begin.
    • Number of FATs at offset 0x10 (typically 2).
  • Extended BPB Fields:
    • Sectors per FAT at offset 0x24 (a 32-bit value defining the size of each FAT).
    • Root Directory starting cluster at offset 0x2C (typically cluster 2).
  • Data Region Mapping: 7-Zip calculates the start of the data region using the formula: \[\text{Data Start Offset} = (\text{Reserved Sectors} + (\text{Number of FATs} \times \text{Sectors Per FAT})) \times \text{Bytes Per Sector}\] With the data start offset and the root directory cluster known, 7-Zip follows the cluster chains in the FAT table to read directory entries (0x20-byte structures) and reconstruct the directory tree for browsing and extraction.