Corrupt a file system, detect it read-only, then repair it

applied · 45 min · Objective 4.1

Task

Damage an ext4 file system on purpose, detect the damage with a read-only check first, image the damaged volume before repairing it, then repair it and account for what the repair did -- including anything it moved to lost+found. This is the order the lesson insists on: look, copy, then change.

Steps

  1. Create the image, attach it, make an ext4 file system, mount it, create 300 small files in nested folders, and save their checksums to lab/fsck/before.txt. Unmount it.
  2. Corrupt it where fsck can see it, in the metadata: wipe one top-level folder's inode with debugfs -w -R 'clri /<folder>' <loop>, as a failed write to an inode table would. Random bytes written into the middle of the device usually land in free space or file contents, which fsck never examines -- it checks the structure, not what files contain -- so that damage would pass the check unseen.
  3. Run e2fsck -fn (read-only, no changes) and save the output to lab/fsck/check-readonly.txt.
  4. Copy the damaged image to a second file as the pre-repair image, and save sha256sum of it to lab/fsck/image.txt.
  5. Run e2fsck -fy to repair, save the output to lab/fsck/repair.txt, mount the file system, and save the checksums again to lab/fsck/after.txt and ls lost+found | wc -l to lab/fsck/lost-found.txt.

Verify

These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.

grep -Eic 'error|corrupt|inconsistenc|bad|wrong|fix' lab/fsck/check-readonly.txt
grep -Ec '^[0-9a-f]{64}' lab/fsck/image.txt
grep -Eic 'MODIFIED|fixed|Clear|Salvage' lab/fsck/repair.txt
awk '{print $1}' lab/fsck/before.txt | sort > /tmp/b; awk '{print $1}' lab/fsck/after.txt | sort > /tmp/a; comm -23 /tmp/b /tmp/a | wc -l
cat lab/fsck/lost-found.txt

The read-only check found problems without changing anything, the pre-repair image was taken, and the repair reported modifications. The fourth command counts files whose contents did not survive; it may not be zero, and that is the point of imaging first -- the image is the only copy of what the repair discarded.

Notes

On Windows, chkdsk without /f is the read-only check. On a real server, repeated corruption points at hardware -- disk, controller cache or memory -- which the repair does nothing to fix.

This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.