ISO images (.iso)

An "ISO" is the simplest disc image: the user data of every sector, in order, with nothing else. It has no header, no table of contents and no metadata. Its name comes from the ISO 9660 file system that CD-ROMs usually carry, but the file format itself has nothing to do with ISO 9660. An .iso can just as well contain UDF, HFS, or no file system at all.

This page covers what an .iso file is, what it can and cannot represent, the variants found in the wild, and the structure of the ISO 9660 and UDF file systems usually found inside one, since recognising them is how readers detect and validate ISO files.


1. The file format #

offset 0                  sector (LBA) 0, 2048 bytes of user data
offset 2048               sector 1
...
offset n × 2048           sector n
...
file size = number of sectors × 2048
  • CD: the file contains the 2048-byte user data of each sector of one data track (Mode 1, or Mode 2 Form 1), starting at the track's index 1. For a normal single-track CD-ROM that is LBA 0 to the last sector before the lead-out. (Some tools end a few sectors early, or late, around TAO run-out blocks.)
  • DVD / Blu-ray: the file contains every 2048-byte sector of the data area, from LBA 0 (PSN 0x30000 on DVD) to the end. Dual-layer discs are stored layer 0 then layer 1, with no marker at the layer break.

That's all there is. The file is a byte-exact copy of what an operating system sees when it reads the disc as a block device (/dev/sr0 on Linux, \\.\CdRom0 on Windows). "Making an ISO" is often literally dd if=/dev/sr0 of=disc.iso bs=2048.

1.1 What an ISO cannot hold #

Lost Consequence
Other tracks Audio tracks of a Mixed Mode CD and any second data track are gone.
Other sessions Only one session's track is captured (see Sessions §6.1).
Track 1 pregap and all gaps Usually harmless.
Sync, header, subheader, EDC/ECC Can be regenerated for Mode 1. For Mode 2, the subheaders (file/channel/submode) are lost, which breaks XA streaming discs such as PlayStation games, Video CDs and CD-i.
Mode 2 Form 2 sectors Their 2324 bytes do not fit into 2048. A cooked read of a Form 2 sector either fails or returns truncated data. So Video CD MPEG streams, PlayStation XA audio and STR video are lost or corrupted.
Subchannel MCN, ISRC, index marks, CD+G, and protection data are lost.
TOC, CONTROL flags The reader must assume one Mode 1 data track.
DVD structures (PFI, DMI, copyright info, BCA) and the layer break position A burner has to guess the layer break, and region/copy-protection flags are gone.
Unreadable or deliberately damaged sectors Represented as zeros or omitted. Copy protections relying on them fail.

Given those limits, an ISO is an excellent format for ordinary single-track Mode 1 CD-ROMs and for DVDs/BDs without protection. It is a poor one for anything else.


2. Variants: ISO files that aren't 2048 bytes per sector #

Some tools write files with an .iso extension that contain other sector sizes. Readers like libmirage detect them by trying each candidate size and looking for a file system signature at sector 16 (lib/cdemu/libmirage/images/image-iso/parser.c):

Bytes per sector Data starts at offset in each sector What it is
2048 0 Normal ISO (Mode 1 / Form 1 user data)
2332 8 Mode 2: subheader + data + EDC/ECC minus last 4 bytes
2336 8 Mode 2: subheader + data + EDC/ECC (everything after the header)
2352 16 Raw Mode 1 sectors (a "raw ISO", really a single-track BIN)
2352 24 Raw Mode 2 Form 1 sectors
+ 0, 16 or 96 – Each of the above may be followed by 16 bytes of Q subchannel or 96 bytes of P–W subchannel per sector

Detection works like this:

  1. The file size must be a multiple of the full sector size (main + subchannel).
  2. Read 16 bytes at 16 × full_sector_size + data_offset.
  3. Accept if they start with an ISO 9660 / UDF volume descriptor signature (01 'CD001' 01, or 00 'BEA01' 01), or a High Sierra signature (section 3.6).
  4. If nothing matches but the size is a multiple of 2352, assume a raw audio track.

For 96-byte subchannel, the parser decides between interleaved and linear layout by checking which interpretation gives a valid Q CRC (see Subchannels §6.5).

Two console formats also use 2048-byte .iso files without ISO 9660: Nintendo GameCube and Wii dumps. They are detected by magic numbers at fixed offsets (0xC2339F3D at offset 0x1C for GameCube, 0x5D1C9EA3 at offset 0x18 for Wii).

Other extensions with the same contents: .img (sometimes; not to be confused with CloneCD's .img), .bin without a cue, .udf, .cdr (macOS DVD/CD master, which is a raw 2048-byte image).


3. ISO 9660, the file system inside #

ISO 9660 (= ECMA-119) is the original CD-ROM file system, derived from the 1986 High Sierra format. Even DVDs that use UDF often carry an ISO 9660 "bridge" copy for compatibility. Every data CD-ROM since the late 1980s uses it or one of its extensions.

3.1 Overall layout #

LBA 0–15     System Area (32 KiB). Not used by ISO 9660 itself. Free for boot code, partition maps,
             hybrid HFS/APM headers, or console boot data (e.g. PlayStation license data, Sega IP.BIN).
LBA 16       Volume Descriptor Set: one or more 2048-byte descriptors, ending with a Terminator.
             (Primary, then optional Boot Record, Supplementary (Joliet), Enhanced, Partition…)
...          Path tables (L-type and M-type), directory extents, file data.

All sizes and positions are in logical blocks (normally 2048 bytes, as given in the PVD) and are LBAs.

3.2 Byte orders and string types #

ISO 9660 was designed to be read on any CPU. Most numeric fields are therefore stored in both byte orders:

  • int16_LSB-MSB (4 bytes): little-endian copy then big-endian copy, e.g. 2048 → 00 08 08 00.
  • int32_LSB-MSB (8 bytes): e.g. 22 → 16 00 00 00 00 00 00 16.

A reader can use either half. Mismatched halves suggest a damaged or hand-crafted image.

Text fields are padded with spaces (0x20):

  • a-characters: A–Z 0–9 _ ! " % & ' ( ) * + , - . / : ; < = > ? and space;
  • d-characters: A–Z 0–9 _ only. Volume identifiers and file names are restricted to these in strict ISO 9660.

3.3 Volume descriptors #

Every descriptor is one sector:

0x000  1     Type: 0 = Boot Record, 1 = Primary, 2 = Supplementary/Enhanced, 3 = Partition, 255 = Terminator
0x001  5     Standard identifier "CD001"
0x006  1     Version (1; Enhanced VD uses 2)
0x007  2041  Type-specific

The Primary Volume Descriptor (LBA 16) #

Offset Size Field
0 1 Type = 1
1 5 CD001
6 1 Version = 1
7 1 unused (0)
8 32 System identifier (a-chars), e.g. PLAYSTATION, APPLE COMPUTER, INC., TYPE: 0002
40 32 Volume identifier (d-chars): the disc label
72 8 unused
80 8 Volume space size: total logical blocks (both-endian int32)
88 32 unused (escape sequences in a Supplementary VD: %/@, %/C, %/E = Joliet UCS-2 levels 1–3)
120 4 Volume set size (both-endian int16)
124 4 Volume sequence number (both-endian int16)
128 4 Logical block size (both-endian int16), almost always 2048
132 8 Path table size in bytes (both-endian int32)
140 4 Location of type-L path table (LE int32)
144 4 Location of optional type-L path table
148 4 Location of type-M path table (BE int32)
152 4 Location of optional type-M path table
156 34 Root directory record (see 3.4)
190 128 Volume set identifier
318 128 Publisher identifier
446 128 Data preparer identifier
574 128 Application identifier
702 37 Copyright file identifier
739 37 Abstract file identifier
776 37 Bibliographic file identifier
813 17 Volume creation date/time (YYYYMMDDHHMMSScc ASCII + 1-byte GMT offset in 15-min units)
830 17 Volume modification date/time
847 17 Volume expiration date/time
864 17 Volume effective date/time
881 1 File structure version = 1
882 1 reserved
883 512 Application use (CD-ROM XA discs put CD-XA001 at offset 1024 of the sector = 141 into this field)
1395 653 reserved

The volume space size is a useful sanity check for an image. It should be ≤ the number of sectors in the file (or track). If it's larger, the image is truncated.

Other descriptors #

  • Boot Record (type 0): for El Torito bootable CDs, the boot system identifier is EL TORITO SPECIFICATION, and a 4-byte LBA at offset 71 points to the Boot Catalog, which lists boot images (floppy emulation, hard-disk emulation, or no-emulation; BIOS or EFI platform IDs).
  • Supplementary Volume Descriptor (type 2): same layout as the PVD, but with its own root directory. Joliet uses one, with file names in UCS-2 big-endian (up to 64 characters) and escape sequences at offset 88. Windows reads the Joliet tree when present.
  • Volume Descriptor Set Terminator (type 255): ends the list. Readers scan from LBA 16 until they hit it.

3.4 Directory records #

Directories are files whose content is a sequence of variable-length directory records. A record never crosses a sector boundary: the remainder of a sector is zero-padded.

Offset Size Field
0 1 Length of this record (LEN_DR)
1 1 Extended attribute record length (usually 0)
2 8 Location of extent (LBA, both-endian)
10 8 Data length in bytes (both-endian)
18 7 Recording date/time (years since 1900, month, day, hour, minute, second, GMT offset)
25 1 File flags: bit 0 hidden, bit 1 directory, bit 2 associated file, bit 3 record format, bit 4 protection, bit 7 multi-extent (file continues in the next record)
26 1 File unit size (interleaved files)
27 1 Interleave gap size
28 4 Volume sequence number (both-endian int16)
32 1 Length of file identifier (LEN_FI)
33 LEN_FI File identifier: NAME.EXT;1 for files (";1" is a version number). 0x00 = "this directory", 0x01 = "parent directory"
– 0/1 Padding byte if LEN_FI is even
– rest System use area: Rock Ridge / SUSP entries, CD-ROM XA attributes (14 bytes: owner/group IDs, permissions, XA signature, file number, used to mark Form 2 / interleaved files), Apple extensions

The first two records in every directory are . (0x00) and .. (0x01). The root's location comes from the PVD's embedded root record.

3.5 Path tables #

A path table lists every directory (not files) with its extent location and parent index. It is stored twice, little-endian (type L) and big-endian (type M), so a reader can find a deep directory without walking the tree. Each entry has: name length (1), extended attribute length (1), extent LBA (4), parent directory number (2), name (padded to even length).

3.6 Interchange levels and limits #

Level File names Other limits
1 8.3 (d-characters), directory names 8 characters each file is one contiguous extent
2 up to 31 characters –
3 up to 31 characters files may be fragmented into multiple extents (multi-extent flag)

Common to all levels: directory depth ≤ 8 levels (relaxed by Rock Ridge and later amendments), and file size < 4 GiB per extent (32-bit length). Level 3 multi-extent files can exceed that.

High Sierra (the 1986 predecessor) uses the identifier CDROM at offset 9 instead of CD001 at offset 1, with slightly different field positions. libmirage recognises it by the value 16 encoded both-endian at offset 1 (10 00 00 00 00 00 00 10).

3.7 Extensions #

  • Rock Ridge (IEEE P1282, via SUSP, the System Use Sharing Protocol): POSIX permissions, owners, long names, symlinks and device files, stored in the system use area. Linux discs use it.
  • Joliet (Microsoft): Unicode long names via a Supplementary VD.
  • El Torito: booting, as above.
  • Apple ISO 9660 extensions and hybrid HFS: Mac resource forks and Finder info. Hybrid discs put an HFS volume header in the System Area.
  • ISO 9660:1999 / Enhanced VD (version 2): relaxed names (up to 207 bytes), deeper trees.

4. UDF, the DVD-era file system #

DVDs (and many later CDs) use UDF (Universal Disk Format, an OSTA profile of ECMA-167). DVD-Video requires UDF 1.02, usually together with an ISO 9660 bridge describing the same files. Blu-ray uses UDF 2.50/2.60.

UDF also starts at sector 16, with a Volume Recognition Sequence (VRS) of 2048-byte descriptors in the same 5-byte-identifier style as ISO 9660:

LBA 16..   "BEA01"  (Beginning Extended Area)
           "NSR02" or "NSR03"  (UDF 1.x/2.x present; ECMA-167 2nd/3rd ed.)
           "TEA01"  (Terminating Extended Area)
           (ISO 9660 "CD001" descriptors may come before BEA01 on a bridge disc)
LBA 256    Anchor Volume Descriptor Pointer (AVDP), also at the last sector and last−256

The AVDP points to the Volume Descriptor Sequence (Primary VD, Partition Descriptor, Logical Volume Descriptor, …), which leads to the File Set Descriptor and then to File Entries (similar to inodes) and File Identifier Descriptors (directory entries). All UDF descriptors begin with a 16-byte descriptor tag (tag identifier, version, checksum, serial, CRC, location). That makes them easy to recognise and validate.

For image detection, the VRS signatures BEA01/NSR0x are what matter. libmirage checks for 00 'BEA01' 01 at sector 16, the same way it checks for CD001.


5. Converting to and from ISO #

From To ISO Notes
BIN MODE1/2352, CloneCD .img, MDF 0x930 Mode 1 track take bytes 0x010..0x810 of each sector First check the track is Mode 1 (header byte 15 = 1).
BIN MODE2/2352, Mode 2 Form 1 track take bytes 0x018..0x818 Only valid if every sector is Form 1 (subheader byte 0x012 bit 5 clear). Form 2 sectors can't be represented.
BIN MODE2/2336 take bytes 0x008..0x808 of each 2336-byte sector same caveat
MDF DVD track (0x800) copy as-is Loses PFI, DMI, BCA and the layer break.
Multi-track CD extract track 1 only Audio and later sessions are dropped.

The reverse direction, ISO → raw BIN (MODE1/2352), means regenerating sync, header, EDC and ECC for each sector. The algorithm is on the EDC/ECC page. The result is bit-identical to the original only if the original disc had no deliberately corrupt sectors.


Sources #