Safely Discard Unneeded Blocks with blkdiscard

blkdiscard tells a block device to drop the content of a sector range outright, before an SSD is retired or thin storage is reclaimed. It is also the tool to fear on the wrong device: the command is destructive, data in the selected range is lost, and there is no undo operation.

Allow about fifteen minutes for the checks and another maintenance window for the actual operation. You need util-linux, a shell, the correct block-device path, and a backup or other recovery plan for anything in the range. The examples use /dev/DEVICE as an obvious placeholder: do not paste it unchanged.

Warning: Do not run a discard against a mounted filesystem, a device containing live swap, a whole disk that still contains useful partitions, or any path you have not independently identified. Most discard commands need elevated privileges. If you are unsure which device owns the data, stop before step 4.

1. Check the executable and its version

Start with read-only checks. They do not need sudo:

$ command -v blkdiscard
/usr/sbin/blkdiscard
$ blkdiscard --version
blkdiscard from util-linux 2.41.3
$ dpkg-query -W -f='${Package} ${Version}\n' util-linux
util-linux 2.39.3-9ubuntu6.6

Versions can differ when a locally installed executable shadows the distribution package. The executable's --version output describes the program you will run; the package query describes the package database. The installed manpage on this host is generated from util-linux 2.39.3, so recheck these values on another machine before relying on version-specific behaviour.

Checkpoint: Confirm that the command path and version are the ones you expect. The local help also confirms the available options:

$ blkdiscard --help
Usage:
 blkdiscard [options] <device>

Discard the content of sectors on a device.

2. Identify the exact block device

Use lsblk to map names, sizes, filesystem types and mountpoints. This is an ordinary command:

$ lsblk -o NAME,PATH,SIZE,TYPE,FSTYPE,MOUNTPOINTS
NAME        PATH           SIZE TYPE FSTYPE MOUNTPOINTS
nvme0n1     /dev/nvme0n1  465.8G disk
|-nvme0n1p1 /dev/nvme0n1p1  512M part vfat   /boot/efi
`-nvme0n1p3 /dev/nvme0n1p3 465.3G part ext4   /

Use your own output, not the illustration, to choose the path: a partition path and its parent disk are different targets. If the target has a mountpoint, stop and unmount it during an approved maintenance window before discarding. Check active mounts explicitly if the output is unclear:

$ findmnt --source /dev/DEVICE

No output means findmnt found no matching mounted source. It does not prove the device is safe: check layered storage, swap, containers and services that may hold it open. For LVM, device-mapper, RAID or a virtual machine disk, identify the owning layer and use that system's maintenance procedure.

3. Choose a range and check alignment

With no range options, blkdiscard targets the whole device. Avoid that default unless the complete device is intentionally being retired or reinitialised. For a partial operation, --offset is the byte position where discarding starts and --length is the number of bytes from there.

For example, this describes a one-gibibyte range beginning at the start of a confirmed, unmounted test device:

$ sudo blkdiscard --verbose --offset 0 --length 1GiB /dev/DEVICE

Do not run that example until /dev/DEVICE has been replaced with the exact target and the range has been approved. The verbose output reports the aligned offset and length. If alignment or the device boundary is wrong, correct the values rather than adding --force: a length extending beyond the device is clipped at the device boundary, but relying on clipping makes a destructive command harder to review.

4. Perform the discard during a maintenance window

Once the target is unmounted and the range is confirmed, run the command with the least privilege needed. sudo is normally required:

$ sudo blkdiscard --verbose --offset 0 --length 1GiB /dev/DEVICE
$ printf 'exit status: %s\n' "$?"
exit status: 0

Status 0 means the requested operation completed; it does not restore files or prove a filesystem was correctly detached. Preserve the terminal output and record the exact device, offset, length and time for change control.

Warning: since util-linux 2.36, the normal operation opens the block device exclusively to reduce collisions with a mounted filesystem or another kernel subsystem. The --force option disables that exclusive access and other checking. It is not a repair switch and is unsafe as a response to a confusing error: use it only when the storage design explicitly requires shared access and you understand the consequences.

5. Handle unsupported devices and special modes

Neither --secure nor --zeroout makes a wrong device safe.

6. Verify without pretending discard is reversible

Check the recorded exit status and the device's state after the maintenance work:

$ printf 'exit status: %s\n' "$?"
exit status: 0
$ lsblk -o NAME,PATH,SIZE,TYPE,FSTYPE,MOUNTPOINTS /dev/DEVICE
$ findmnt --source /dev/DEVICE

The final findmnt check should stay empty if the device was meant to remain unmounted. lsblk confirms identity and topology, not the contents of discarded sectors. A normal discard is a storage hint whose effect depends on the device and its controller: if you need evidential sanitisation, use a disposal method designed and documented for that storage type rather than treating discard as secure erasure.

Recovery: There is no undo command. Recovery means restoring the affected data from a verified backup or recreating the device from known-good configuration. If a filesystem was accidentally discarded, stop writing to the device, preserve it for specialist recovery, and follow your incident process.

Done means