Corrupt a file system, detect it read-only, then repair it
Task
Damage an ext4 file system on purpose, detect the damage with a read-only check first, image the damaged volume before repairing it, then repair it and account for what the repair did -- including anything it moved to lost+found. This is the order the lesson insists on: look, copy, then change.
Steps
- Create the image, attach it, make an ext4 file system, mount it, create 300 small files in nested folders, and save their checksums to
lab/fsck/before.txt. Unmount it. - Corrupt it where fsck can see it, in the metadata: wipe one top-level folder's inode with
debugfs -w -R 'clri /<folder>' <loop>, as a failed write to an inode table would. Random bytes written into the middle of the device usually land in free space or file contents, which fsck never examines -- it checks the structure, not what files contain -- so that damage would pass the check unseen. - Run
e2fsck -fn(read-only, no changes) and save the output tolab/fsck/check-readonly.txt. - Copy the damaged image to a second file as the pre-repair image, and save
sha256sumof it tolab/fsck/image.txt. - Run
e2fsck -fyto repair, save the output tolab/fsck/repair.txt, mount the file system, and save the checksums again tolab/fsck/after.txtandls lost+found | wc -ltolab/fsck/lost-found.txt.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
grep -Eic 'error|corrupt|inconsistenc|bad|wrong|fix' lab/fsck/check-readonly.txt
grep -Ec '^[0-9a-f]{64}' lab/fsck/image.txt
grep -Eic 'MODIFIED|fixed|Clear|Salvage' lab/fsck/repair.txt
awk '{print $1}' lab/fsck/before.txt | sort > /tmp/b; awk '{print $1}' lab/fsck/after.txt | sort > /tmp/a; comm -23 /tmp/b /tmp/a | wc -l
cat lab/fsck/lost-found.txt
The read-only check found problems without changing anything, the pre-repair image was taken, and the repair reported modifications. The fourth command counts files whose contents did not survive; it may not be zero, and that is the point of imaging first -- the image is the only copy of what the repair discarded.
Notes
On Windows, chkdsk without /f is the read-only check. On a real server, repeated corruption points at hardware -- disk, controller cache or memory -- which the repair does nothing to fix.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.