beamfs v3: An EM-Resilient Linux Filesystem under Read-Path Fault Injection, with an Audit of the Injector
beamfs is a Linux filesystem that stores every data block as a capsule of sixteen interleaved Reed-Solomon RS(255,239) codewords, decodes on every read, and refuses a read it cannot vouch for. This report measures beamfs 0.1.26 (commit 1bf151d) on Linux 7.3-rc5. Of the 734 tests of the xfstests auto group, all 122 that ran on x86-64 passed, and 122 of the 123 that ran on aarch64; xfstests declined the others, most of them for features beamfs does not implement, and these are counted apart, not as passes. Under single-bit upsets injected into read bios by the emufi injector, on a four-node aarch64 cluster and on USB flash media, beamfs never returned wrong data: it returned the correct file in every exercised case but one, absorbing up to 265 flips during one read of a 256 KiB file, and in that one refused the read, after a flip in an indirect pointer. In the same runs ext4 and ext3 returned silently corrupted data after 1 and 2 to 3 flips respectively, and btrfs refused the read. We audit the injector itself. On this kernel emufi 0.8.1 logs one of its two read hooks one bio before the block it flips; reconstructing the hook of every flip explains all 60 corrections the kernel reported and bounds the load at 2 erroneous symbols per codeword and per decode, against eight correctable. The campaign therefore exercises detection and correction end to end, not the correction limit. Redundancy (btrfs DUP data, ZFS with two copies) also returns correct data, for a full copy; beamfs does it on one medium for 7% of capacity, while its indirect pointers, in the default configuration, are less protected than ext4's checksummed extent blocks. We set out what beamfs brings, what it costs, and what v4 takes on. Scope, after the project's normative statement: beamfs is designed against Family A perturbations (stochastic electromagnetic single-bit and multi-bit upsets, aging silicon bit-rot, environmental radiation, rowhammer-class single-cell flips); Family B perturbations (adversarial bursts exceeding 256 octets per sub-block, IEMI at scale, voltage-glitch attacks at scale) are not claimed. This report measures a subset of Family A. Every number in it is generated from signed run records and cross-checked before typesetting. Files. beamfs-v3.pdf is the report. beamfs-v3-workspace.tar.xz is the whole workspace: the LaTeX sources, the scripts that generate every number, table and figure, the derived data, and the raw run records (data/raw, 2532 files, frozen by data/raw/SHA256SUMS, SHA-256 6f2e4a77fea51ca737b0bdfc3b7892e730c2041ac57ab7213fa8a824a98b9667). With them is what the measurements ran on and what ran them: the two root images, compressed with xz, which decompressed have the SHA-256 the appendix gives (x86-64 af9d860b, aarch64 1d60a1be), and the two kernels; for each architecture, an archive of the kernel configuration, the image and license manifests, the SPDX document, the Yocto configuration with the commit of every layer, and the libvirt definition of every node with its QEMU version; and the source trees, at the commits used, of the Yocto layer (9d43172, which carries beamfs, mkfs.beamfs, fsck.beamfs and emufi 0.8.1 as built), of the xfstests harness (2.5.1, b22ecb4), of the bench, beamfs-bench (661e8aa, 60155f3 and 607716e, for runs 2, 3 and 4), and of the Gentoo ebuilds that install the harness and the bench. README.txt describes every file and how to check it; SHA256SUMS gives the SHA-256 of every file. Code. beamfs at tag beamfs-v3 (commit 2ee922d, which adds this report to the measured code at commit 1bf151d): https://github.com/roastercode/beamfs. xfstests harness beamfs-xfstests 2.5.1, commit b22ecb4: https://github.com/roastercode/beamfs-xfstests. Credentials and licenses. The images are for isolated virtual machines and carry test credentials that are public by design: a password for root and hpcadmin, a release SSH key, a MUNGE key, and SSH host keys generated at build time. README.txt lists them; do not reuse them. The images contain free software under its own licenses; README.txt gives the corresponding sources and a written offer for them.
Authors
- Aurelien Desbrieres (ORCID: https://orcid.org/0009-0002-0912-9487)
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-09
- DOI
- https://doi.org/10.5281/zenodo.23253350
- Primary Topic
- Advanced Data Storage Technologies
- Type
- article
- Field-Weighted Citation Impact
- 0.00