Read ext4 Superblock and Group Layout Details with dumpe2fs
You will finish with a read-only report of an ext2, ext3 or ext4 filesystem, plus a compact group-descriptor listing suitable for a script or a ticket. This guide uses the installed dumpe2fs from e2fsprogs 1.47.0. Allow about ten minutes for a normal inspection. You need the device or filesystem image, read access to it, and enough familiarity with the fact that the output describes on-disk metadata rather than mounted-file contents.
The route
Jump straight to the step you need, or tick off Done means at the end.
- 1. Identify the exact input
- 2. Read the superblock summary
- 3. Inspect group descriptors when layout matters
- 4. Produce a machine-readable group listing
- 5. Handle image files and recovery options carefully
- 6. Check an MMP-enabled filesystem only when required
- 7. Diagnose failures without escalating blindly
Checkpoint
Nothing in the normal workflow mounts, repairs, formats or changes the filesystem. The command does not require sudo merely because it is an administration tool. Add elevated privileges only if the device cannot be read by your account.
1. Identify the exact input
dumpe2fs takes one device or image pathname. A mounted filesystem can be inspected, but the manual warns that its displayed information may be old or inconsistent while the filesystem is changing. First identify the block device and its mount state without writing to either:
$ findmnt --source /dev/DEVICE
$ ls -l /dev/DEVICE
Replace /dev/DEVICE with the real path, such as a partition or logical-volume device. Do not guess from a directory name. If you already have an image file, use its path directly. An image produced by e2image is selected with -i, described in step 5.
For a filesystem that is mounted and busy, treat the report as a snapshot of metadata that may lag behind activity. For the most reliable maintenance report, use an offline copy or inspect during an agreed quiet period. Do not unmount a production filesystem just to make this example fit: unmounting can disrupt services and should have its own change and recovery plan.
2. Read the superblock summary
Use -h when you want the filesystem-wide facts without the detailed block-group sections:
$ dumpe2fs -h /dev/DEVICE
On this machine, the command begins with a version line and then reports fields such as the filesystem magic number, feature flags, block and inode counts, block size, filesystem state, journal inode and recent check times. The exact values depend on the filesystem. A successful command returns status 0.
For a harmless verification, capture the status immediately after the command:
$ status=$?
$ printf 'dumpe2fs exit status: %s\n' "$status"
Expected output for a readable, valid filesystem is dumpe2fs exit status: 0. A non-zero result means the report is not trustworthy. Keep the diagnostic text: causes include an unreadable input, an invalid or unreadable superblock, bad checksums, or an input that is in use by another node when -m is used.
3. Inspect group descriptors when layout matters
Run the full report when you need the superblock followed by block-group detail:
$ dumpe2fs /dev/DEVICE
This can be long on a large filesystem. Redirect it to a new evidence file if you need to attach it to a ticket. The redirection changes only the report file, not the filesystem:
$ dumpe2fs /dev/DEVICE > dumpe2fs-report.txt
$ test -s dumpe2fs-report.txt && sed -n '1,35p' dumpe2fs-report.txt
Do not use > with a valuable existing report unless overwriting it is intentional: the shell truncates the destination before dumpe2fs starts. Choose a new filename or copy the old report first. If the command fails, the new file may contain a partial report; label it as failed evidence rather than treating it as complete.
4. Produce a machine-readable group listing
The -g option prints group descriptors as colon-separated records. The fields are, in order: group number, first block, superblock location, group-descriptor block range, block bitmap, inode bitmap, and inode-table block range.
$ dumpe2fs -g /dev/DEVICE
On the temporary 32 MiB ext4 test image used for this guide, the data included this header and record shape:
group:block:super:gdt:bbitmap:ibitmap:itable
0:0:0:1-1:5:21:37
The numbers are not universal. A value of -1 means that the relevant superblock or descriptor range is not present for that group. Keep the header with the data when importing the output. If a parser needs hexadecimal block numbers, add -x:
$ dumpe2fs -gx /dev/DEVICE
Use this output for inventory or comparison, not as a substitute for filesystem repair. Do not edit the records and write them back: dumpe2fs has no write-back mode.
5. Handle image files and recovery options carefully
For an image created by e2image, add -i and pass the image pathname as the command's device argument:
$ dumpe2fs -i /path/to/filesystem.e2i
This tells dumpe2fs to read filesystem data from the e2image file. It does not reconstruct missing data and it does not convert an arbitrary disk image into an e2image. Check the image's provenance before drawing conclusions from it.
The -o superblock=NUMBER and -o blocksize=BYTES options are specialist recovery tools for examining badly corrupted filesystems. They are not routine alternatives to -h. A wrong superblock or block-size value can make the display misleading, so obtain the values from an appropriate recovery procedure and record exactly what you tried.
The -f option forces display when dumpe2fs does not understand some filesystem feature flags. The manual warns that the resulting display may be suspect. Treat forced output as diagnostic evidence only, and do not use it to justify a repair or a destructive rewrite.
6. Check an MMP-enabled filesystem only when required
The -m option checks whether the device is in use by another node when the filesystem's multiple-mount protection feature is enabled:
$ dumpe2fs -m /dev/DEVICE
$ printf 'MMP check status: %s\n' "$?"
A non-zero status is meaningful here: the manual includes use by another node among the possible errors. Do not run this check casually against a shared device and then ignore its result. Consult e2mmpstatus(8) for the fuller MMP procedure, and stop if the output indicates another node is using the filesystem. Never try to clear a protection signal by writing directly to filesystem metadata.
7. Diagnose failures without escalating blindly
If the command cannot read the input, check the path and permissions first:
$ stat /dev/DEVICE
$ id
$ sudo dumpe2fs -h /dev/DEVICE
The first two commands are ordinary read-only checks. The final command requires elevated privileges and should be used only if the earlier checks show that access is the problem. sudo does not repair a bad superblock, correct a wrong device, or make a mounted report consistent.
For an unknown feature flag, try neither -f nor a recovery option as a reflex. First record the e2fsprogs version and the exact error:
$ dumpe2fs -V
$ dumpe2fs -h /dev/DEVICE 2>&1 | tee dumpe2fs-error.txt
Compare the reported filesystem type, device identity and version with the maintenance record. If the device may be damaged, stop at evidence collection and use an approved backup or filesystem-repair procedure. dumpe2fs is an inspection command; it is not e2fsck.
Done means
- You inspected the intended device or image and recorded whether it was mounted.
- You captured a superblock summary with
dumpe2fs -hand checked its exit status. - You used
-gwhen group layout was relevant and preserved its header. - You treated mounted output, forced output and MMP failures as boundaries, not as permission to guess.
- You left the filesystem unchanged and kept any report with its command, version and input recorded.