Repository navigation
fix(extract): recover nested firmware filesystems with native decoders - #108
Merged
Merged
Conversation
Follow nested containers and decode legacy SquashFS layouts with bounded native readers. Separate traversal, format parsing, staged output, and artifact reporting so filesystem support can grow without expanding CLI orchestration. Keep fallback available for incomplete recovery, reject filename collisions, and distinguish recovered rootfs trees from intermediate evidence. Add regression coverage and document limits; local validation recovered 11 firmware inputs and two ZIP entry paths with matching file contents and symlink targets.
Keep the native recovery changes alongside upstream retry handling and installation fixes. Resolve the changelog conflict by retaining both sets of additions and fixes. Validation: 1,996 workspace tests passed with one ignored fixture; formatting, clippy, kernel-profile, runtime-data, and 16 installer checks passed. Rebuilt firmware extraction recovered 11 images and two ZIP inputs; 21,351 file contents and symlink targets matched reference extraction.
adi0x90
marked this pull request as ready for review
September 25, 2026 19:20
This was referenced Sep 26, 2026
Open
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Firmware extraction could stop after carving an image without recovering its root filesystem. Nested containers, older SquashFS layouts, and legacy LZMA blocks also left supported-looking inputs undecoded.
This adds recursive native recovery and explicit recovery outcomes. For example, the WNAP320 vendor ZIP now traverses ZIP → TAR → big-endian SquashFS 3.1 and recovers 938 regular files and 197 symlinks on case-sensitive storage.
Changes
artifactsandrecovery_statuswhile preserving existing fields.--extractor nativestays native.Verification
cargo fmt --all --checkcargo clippy --workspace --all-targets -- -D warningscargo test --workspace— 1,996 passed, 0 failed, 1 ignored local-fixture testcargo test -p firmware-analysis-toolkit --test test_kernel_profile_consistency— 4 passedpython3 scripts/build-runtime-data-bundle.py --check— 33 files verifiedValidation was repeated after integration with current
master. Local firmware validation recovered rootfs trees from all 11 saved inputs and both tested vendor ZIP entry paths. Across the 11 images, 21,351 regular-file contents and symlink targets matched independent reference extraction with no missing or differing entries. ZIP entry paths reproduced the corresponding raw-input inventories.The four previously failing raw inputs completed in 0.23–0.67 seconds per optimized CLI run on macOS arm64 with case-sensitive APFS. These are single-run measurements, not a controlled benchmark. Vendor firmware and extracted trees are not included in this PR.
Notes
xt_MARK.koandxt_mark.ko; a collision now reports partial recovery and does not publish that rootfs tree.files_onlyandpartialmay still exit successfully for compatibility. Automation should inspectrecovery_statusandrootfs.