Skip to content

SquashFS Structure

Squashfs is a high-compression, read-only filesystem designed for embedded systems and IoT devices. Its compact size and efficient storage make it ideal for use in environments with limited flash memory, such as Yocto-based embedded Linux distributions. Understanding its structure and features is critical for firmware analysis, as it often forms the root filesystem in IoT devices.


Squashfs Structure Overview

Squashfs organizes data into a hierarchical structure with the following key components:

  1. Super Block
    The super block contains metadata about the filesystem, including:
  2. Block size (e.g., 4KB or 16KB)
  3. Compression algorithm (e.g., LZ4, XZ, Zstandard)
  4. File count, inode count, and fragment count
  5. Timestamps and checksums for integrity verification

Example:

# Extract super block information using `fsck.squashfs`  
fsck.squashfs -v firmware.squashfs

  1. Inode Table
    Each file or directory is represented by an inode, which stores metadata such as:
  2. File size and permissions
  3. Pointers to data blocks (fragments)
  4. Timestamps (creation, modification, access)

  5. Fragment Table
    Compressed data is split into fragments, which are stored in the fragment table. Each fragment is a compressed block of data, often using algorithm-specific headers.

  6. Directory Entries
    Directories are stored as regular files with special flags, containing entries that map filenames to inode indices.


Compression and Efficiency

Squashfs employs lossless compression to minimize storage usage. Key features include:

  • Algorithm Flexibility: Supports multiple compression methods (e.g., LZ4 for speed, XZ for higher ratios).
  • Streamlined Data Layout: Reduces overhead by eliminating redundant metadata compared to traditional filesystems.
  • Trade-offs: Higher compression ratios may increase decompression latency, which is critical for real-time IoT applications.

Example:

# Mount a Squashfs image with LZ4 compression  
sudo mount -t squashfs firmware.squashfs /mnt/squashfs


Mounting and Inspection

Squashfs images can be mounted temporarily for analysis:

  1. Mounting: Use the mount command with the -t squashfs option.

    sudo mount -t squashfs -o loop firmware.squashfs /mnt/squashfs
    

  2. Extracting Contents: Use unsquashfs to extract files for deeper inspection.

    unsquashfs firmware.squashfs
    

  3. Validation: Check for corruption or inconsistencies with fsck.squashfs.


Integration in IoT Devices

Squashfs is widely used in IoT firmware due to:

  • Storage Efficiency: Significantly reduces flash memory usage compared to uncompressed filesystems.
  • Boot Performance: Pre-compressed data accelerates boot times.
  • Read-Only Nature: Prevents accidental modifications, enhancing security and stability.

In Yocto-based systems, Squashfs is often used as the root filesystem, with tools like mkfs.squashfs generating images during the build process.


Key takeaways

  • Squashfs uses a structured format with super blocks, inodes, fragments, and directory entries for efficient storage.
  • Compression algorithms like LZ4 and XZ balance speed and ratio, critical for resource-constrained IoT devices.
  • Mounting and extraction tools (mount, unsquashfs) enable analysis of firmware components.
  • Its read-only design and compact size make it a staple in embedded Linux systems, including Yocto-based IoT firmware.