Validation
How each format reader is tested, what a status means, and what will be published for labs.
Test images
Test images are made by the software that writes each format, not by InVitro:
| Windows | NTFS, FAT, exFAT, UDF, VHDX |
|---|---|
| Linux kernel and mkfs tools | ext2/3/4, XFS, Btrfs, F2FS, UBIFS, JFFS2, ReiserFS, UFS |
| ewfacquire | E01 |
| qemu-img | QCOW2 |
| cryptsetup | LUKS1, LUKS2 |
| genisoimage, xorriso, mkudffs | Optical filesystems |
Oracles
What InVitro reads is compared file by file and hash by hash with an independent reader: Windows itself, the Linux kernel driver, or libewf for E01.
Corruption campaigns
Each parser is also fed mutated and truncated copies of those images. A damaged structure must be refused or flagged, never served as good, and no parser may crash or hang. Every decoder has tests with input that is certainly corrupt, so a reader that accepts garbage fails its tests.
Statuses
Statuses travel with the bytes into previews, hashes, exports and reports.
| Status | Meaning |
|---|---|
| Good | Read from the source, and verified where the format has a checksum. |
| Unreadable | The device or image could not return these sectors. |
| Checksum failed | Read, but the format's own checksum does not match. |
| Locked | Encrypted, with no key supplied yet. |
| Unrecorded or unavailable | Never written (past the end of an optical session, for example), or missing, such as a lost segment of a split image. |
A compressed or encrypted stream that fails to decode is reported as a decode failure.
Limits
- Optical acquisition is validated on a simulated drive built from real disc images.
- UBIFS and JFFS2 are validated on clean MTD dumps. Raw NAND dumps with spare areas and ECC are not supported.
- All validation is done on images, never on live media.
For labs, at release
- A validation pack: the test images, the tool that made each, the expected file lists and per-file SHA-256, InVitro's measured results and error rates, and the corruption results. Updated every release.
- A matrix mapping SWGDE 18-Q-001 requirements to the pack's test cases.
- An ISO/IEC 17025 method-validation template prefilled with our results.
- Runs of the NIST CFTT procedures for disk imaging, deleted file recovery and carving, published as they are done.