How 7-Zip Opens CramFS and SquashFS Images

7-Zip processes CramFS and SquashFS Linux filesystem images by treating them as standard read-only compressed archives, eliminating the need to mount them through a Linux virtual file system. By detecting unique filesystem signatures, parsing superblock metadata, and executing internal decompression algorithms, 7-Zip reconstructs directory structures and extracts file contents directly across different operating systems.

Format Detection and Header Verification

When an image file is opened, 7-Zip scans the initial bytes to identify the specific file system signature, known as the "magic number."

  • For CramFS, 7-Zip looks for the 32-bit magic number 0x28cd3d45 at the beginning of the superblock.
  • For SquashFS, it detects the signature 0x73717368 (standard) or its byte-swapped variations to account for endianness (little-endian vs. big-endian) across architectures like x86, ARM, or MIPS.

Once the magic signature is verified, 7-Zip evaluates the superblock parameters, which describe the filesystem’s block size, flags, creation time, and relative byte offsets to metadata tables.

Parsing Directory Structures and Metadata

Instead of loading kernel drivers, 7-Zip parses filesystem metadata in user space to create an in-memory virtual directory tree:

  1. Inode Processing: 7-Zip reads the inode tables to retrieve standard file attributes such as file sizes, symbolic links, file permissions, and directory trees.
  2. Directory Tables: It navigates directory entries sequentially. For SquashFS, this requires reading the directory table headers, resolving compression chunks, and mapping directory entry offsets to their respective parent paths.
  3. Block Offset Mapping: Files are mapped to specific data blocks. SquashFS often splits data across uniform full blocks and smaller "fragment blocks" to maximize compression efficiency; 7-Zip parses the fragment table to locate and combine these remnants.

Block Decompression

Both filesystems compress data in segmented blocks rather than as a single contiguous stream. 7-Zip extracts files on a per-block basis using internal decompression libraries:

  • CramFS: Data blocks are primarily compressed using the standard zlib (DEFLATE) algorithm. 7-Zip passes each compressed block through its internal DEFLATE decoder and writes the resulting output to reconstruct the file.
  • SquashFS: Depending on the filesystem version (most commonly SquashFS 4.0), the blocks may be compressed using gzip (DEFLATE), LZMA, LZMA2, XZ, or LZO. 7-Zip reads the compression type flag directly from the superblock, feeds the metadata and file blocks into the corresponding decompression routine, and buffers the output.

Extraction and Presentation

After decoding the metadata, 7-Zip presents the contents in its user interface or command-line utility as a standard hierarchical archive. When a user requests an extraction, 7-Zip seeks to the target byte offsets in the image, decompresses only the blocks required for the selected files, and writes the reconstructed payloads to the destination path.