Troubleshooting¶
CLI¶
'x' is not a valid PE file
The file has no valid MZ/PE signature, or the headers point outside the file. Check with xxd -l 64 x. Truncated downloads and non-PE formats (ELF, Mach-O, MSI, CAB) produce this error. The exit code is 1.
unknown option: … or unexpected extra argument
Options come before the file, and only one file is allowed per run. File names starting with - need a path prefix: ./-odd.exe. To process many files, see batch processing.
--set failed: unknown field or bad value
- Field names are case-sensitive and must match the
--headersoutput exactly (OptionalHeader.…, notOptional_Header.…). - Numeric values are hex without
0x, unless aCell:address ends in:dec. - A new name or string must fit in the old one's space (length limits).
- Derived columns (Demangled name, bar columns) can't be edited.
The output with --save is huge
The report is still printed. Add a narrow filter (--headers) or redirect stdout: > /dev/null.
--similarity never finds anything
- The CLI and GUI keep separate databases (
ppee-cli.similarity.dbandppee.similarity.db). - On a read-only location, the DB can't be created: PPEE warns on stderr and reports
"available": false. - In Docker, the DB disappears with the container unless you persist it.
warning: --strings will collect N strings using about M MB
The file contains a very large number of strings. PPEE continues anyway. Leave out --strings, or post-filter the output with jq.
update check: … on stderr (Windows)
The startup update check couldn't run (offline or behind a proxy). Pass --no-update-check.
--analysis prints nothing
No analyzer recognised the file. Analysis exists for .NET, Go, Rust and NativeAOT builds only; a native C/C++ binary has none, and in JSON analysis.runtimes is empty. Stripped or obfuscated builds may also hide their markers, so the absence of a runtime isn't proof the file wasn't built with one.
Docker¶
failed to load '/data/…'
The path must be the container path. Mount the folder (-v "$PWD:/data:ro") and pass /data/<file>.
Git Bash on Windows mangles /data/... paths
Prefix the command with MSYS_NO_PATHCONV=1, or use PowerShell.
GUI¶
Blank or garbled window in a VM or over RDP (Windows)
PPEE falls back to its GDI software renderer when Direct3D 9 isn't available. If the fallback isn't triggered, update the VM's display driver or enable 3D acceleration.
The Linux GUI doesn't start: GLFW error / OpenGL
PPEE needs OpenGL 3. Over SSH, use X forwarding with GLX support, or run the CLI instead. On headless servers, use ppee-cli.
File → Open does nothing on Linux
The file chooser uses zenity. Install it (sudo apt install zenity) or open files by drag and drop or from the command line.
Refresh doesn't show changes I made to the file outside PPEE
Refresh (F5) rebuilds the views from the file as held in memory, so your unsaved edits survive. It does not re-read the disk. To load an updated file, close the tab and open it again.
A 32-bit PPEE on 64-bit Windows opened the wrong System32 file
It doesn't: PPEE turns off WOW64 file-system redirection while opening, saving and reading file information, so the System32 file you pick is the one you get, not its SysWOW64 twin.
The GUI keeps a CPU core busy
It shouldn't. PPEE waits for input between frames and only redraws continuously for about a second after input, while a background job (hashing, the deep pass) runs, or while an animation (toasts, the status ticker) is playing. If you still see constant CPU use, note what is on screen and report it.
Settings aren't saved
ppee.ini is written next to the executable. Make sure that folder is writable, which isn't the case under C:\Program Files for a standard user.
Shell integration fails on Windows
Run PPEE as Administrator once to register or unregister the menu. See Shell Integration.