SquashFS Structure
Squashfs is a high-compression, read-only filesystem designed for embedded systems and IoT devices. Its compact size and efficient storage make it ideal for use in environments with limited flash memory, such as Yocto-based embedded Linux distributions. Understanding its structure and features is critical for firmware analysis, as it often forms the root filesystem in IoT devices.
Squashfs Structure Overview¶
Squashfs organizes data into a hierarchical structure with the following key components:
- Super Block
The super block contains metadata about the filesystem, including: - Block size (e.g., 4KB or 16KB)
- Compression algorithm (e.g., LZ4, XZ, Zstandard)
- File count, inode count, and fragment count
- Timestamps and checksums for integrity verification
Example:
- Inode Table
Each file or directory is represented by an inode, which stores metadata such as: - File size and permissions
- Pointers to data blocks (fragments)
-
Timestamps (creation, modification, access)
-
Fragment Table
Compressed data is split into fragments, which are stored in the fragment table. Each fragment is a compressed block of data, often using algorithm-specific headers. -
Directory Entries
Directories are stored as regular files with special flags, containing entries that map filenames to inode indices.
Compression and Efficiency¶
Squashfs employs lossless compression to minimize storage usage. Key features include:
- Algorithm Flexibility: Supports multiple compression methods (e.g., LZ4 for speed, XZ for higher ratios).
- Streamlined Data Layout: Reduces overhead by eliminating redundant metadata compared to traditional filesystems.
- Trade-offs: Higher compression ratios may increase decompression latency, which is critical for real-time IoT applications.
Example:
# Mount a Squashfs image with LZ4 compression
sudo mount -t squashfs firmware.squashfs /mnt/squashfs
Mounting and Inspection¶
Squashfs images can be mounted temporarily for analysis:
-
Mounting: Use the
mountcommand with the-t squashfsoption.
-
Extracting Contents: Use
unsquashfsto extract files for deeper inspection.
-
Validation: Check for corruption or inconsistencies with
fsck.squashfs.
Integration in IoT Devices¶
Squashfs is widely used in IoT firmware due to:
- Storage Efficiency: Significantly reduces flash memory usage compared to uncompressed filesystems.
- Boot Performance: Pre-compressed data accelerates boot times.
- Read-Only Nature: Prevents accidental modifications, enhancing security and stability.
In Yocto-based systems, Squashfs is often used as the root filesystem, with tools like mkfs.squashfs generating images during the build process.
Key takeaways¶
- Squashfs uses a structured format with super blocks, inodes, fragments, and directory entries for efficient storage.
- Compression algorithms like LZ4 and XZ balance speed and ratio, critical for resource-constrained IoT devices.
- Mounting and extraction tools (
mount,unsquashfs) enable analysis of firmware components. - Its read-only design and compact size make it a staple in embedded Linux systems, including Yocto-based IoT firmware.