Jefferson
JFFS2 filesystem extraction tool.
Installation
You can install Jefferson from PyPi with the following command:
pip install --user jefferson
Usage
jefferson filesystem.img -d outdir
Features
- big-endian and little-endian support with auto-detection
- zlib, rtime, LZMA, and LZO compression support
- CRC checks - for now only enforced on
hdr_crc - extraction of symlinks, directories, files, and device nodes
- detection/handling of duplicate inode numbers. Occurs if multiple JFFS2 filesystems are found in one file and causes
jeffersonto treat segments as separate filesystems
Development
The package is maintained with Poetry. If you want to contribute, we recommend you follow these steps:
git clone https://github.com/onekey-sec/jefferson.git
cd jefferson
poetry install
poetry run jefferson
You can install Poetry by following this guide
Release files for jefferson 0.4.8
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| jefferson-0.4.8.tar.gz | 6.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| jefferson-0.4.8-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 15.3 kB
Release files / jefferson-0.4.8.tar.gz
| Download URL | jefferson-0.4.8.tar.gz |
|---|---|
| Size | 6.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
269edb74a9c89b69415a8ece852b193a9565251ec9f92f8b4ccf70082ec2ce71
|
|
BLAKE2b-256 checksum How to use checksums |
f54e4ed99ac8d89090fae572188e59a4114d337076bfac5928992c3531002790
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency logRelease files / jefferson-0.4.8-py3-none-any.whl
| Download URL | jefferson-0.4.8-py3-none-any.whl |
|---|---|
| Size | 8.7 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
30db339fb6203f83631dfc27b39a145a13a62f538cf95d83d241a04593e6edc0
|
|
BLAKE2b-256 checksum How to use checksums |
f4a2e4d62bcd0f5d610a7eb7f89957b3f7d5e1c7efb725d2c375a3d0784c706c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 22, 2026.
Transparency log