Skip to content

Troubleshooting

CLI

'x' is not a valid PE file

The file has no valid MZ/PE signature, or the headers point outside the file. Check with xxd -l 64 x. Truncated downloads and non-PE formats (ELF, Mach-O, MSI, CAB) produce this error. The exit code is 1.

unknown option: … or unexpected extra argument

Options come before the file, and only one file is allowed per run. File names starting with - need a path prefix: ./-odd.exe. To process many files, see batch processing.

--set failed: unknown field or bad value
  • Field names are case-sensitive and must match the --headers output exactly (OptionalHeader.…, not Optional_Header.…).
  • Numeric values are hex without 0x, unless a Cell: address ends in :dec.
  • A new name or string must fit in the old one's space (length limits).
  • Derived columns (Demangled name, bar columns) can't be edited.
The output with --save is huge

The report is still printed. Add a narrow filter (--headers) or redirect stdout: > /dev/null.

--similarity never finds anything
  • The CLI and GUI keep separate databases (ppee-cli.similarity.db and ppee.similarity.db).
  • On a read-only location, the DB can't be created: PPEE warns on stderr and reports "available": false.
  • In Docker, the DB disappears with the container unless you persist it.
warning: --strings will collect N strings using about M MB

The file contains a very large number of strings. PPEE continues anyway. Leave out --strings, or post-filter the output with jq.

update check: … on stderr (Windows)

The startup update check couldn't run (offline or behind a proxy). Pass --no-update-check.

--analysis prints nothing

No analyzer recognised the file. Analysis exists for .NET, Go, Rust and NativeAOT builds only; a native C/C++ binary has none, and in JSON analysis.runtimes is empty. Stripped or obfuscated builds may also hide their markers, so the absence of a runtime isn't proof the file wasn't built with one.

Docker

failed to load '/data/…'

The path must be the container path. Mount the folder (-v "$PWD:/data:ro") and pass /data/<file>.

Git Bash on Windows mangles /data/... paths

Prefix the command with MSYS_NO_PATHCONV=1, or use PowerShell.

GUI

Blank or garbled window in a VM or over RDP (Windows)

PPEE falls back to its GDI software renderer when Direct3D 9 isn't available. If the fallback isn't triggered, update the VM's display driver or enable 3D acceleration.

The Linux GUI doesn't start: GLFW error / OpenGL

PPEE needs OpenGL 3. Over SSH, use X forwarding with GLX support, or run the CLI instead. On headless servers, use ppee-cli.

File → Open does nothing on Linux

The file chooser uses zenity. Install it (sudo apt install zenity) or open files by drag and drop or from the command line.

Refresh doesn't show changes I made to the file outside PPEE

Refresh (F5) rebuilds the views from the file as held in memory, so your unsaved edits survive. It does not re-read the disk. To load an updated file, close the tab and open it again.

A 32-bit PPEE on 64-bit Windows opened the wrong System32 file

It doesn't: PPEE turns off WOW64 file-system redirection while opening, saving and reading file information, so the System32 file you pick is the one you get, not its SysWOW64 twin.

The GUI keeps a CPU core busy

It shouldn't. PPEE waits for input between frames and only redraws continuously for about a second after input, while a background job (hashing, the deep pass) runs, or while an animation (toasts, the status ticker) is playing. If you still see constant CPU use, note what is on screen and report it.

Settings aren't saved

ppee.ini is written next to the executable. Make sure that folder is writable, which isn't the case under C:\Program Files for a standard user.

Shell integration fails on Windows

Run PPEE as Administrator once to register or unregister the menu. See Shell Integration.

MCP

See MCP setup → Troubleshooting.