Home / Alt manpages / dumpe2fs(8)

  • dumpe2fs(8)
  • Admin command
  • linux

Read ext4 Superblock and Group Layout Details with dumpe2fs

You will finish with a read-only report of an ext2, ext3 or ext4 filesystem, plus a compact group-descriptor listing suitable for a script or a ticket. This guide uses the installed dumpe2fs from e2fsprogs 1.47.0. Allow about ten minutes for a normal inspection. You need the device or filesystem image, read access to it, and enough familiarity with the fact that the output describes on-disk metadata rather than mounted-file contents.

Checkpoint

Nothing in the normal workflow mounts, repairs, formats or changes the filesystem. The command does not require sudo merely because it is an administration tool. Add elevated privileges only if the device cannot be read by your account.

1. Identify the exact input

dumpe2fs takes one device or image pathname. A mounted filesystem can be inspected, but the manual warns that its displayed information may be old or inconsistent while the filesystem is changing. First identify the block device and its mount state without writing to either:

$ findmnt --source /dev/DEVICE
$ ls -l /dev/DEVICE

Replace /dev/DEVICE with the real path, such as a partition or logical-volume device. Do not guess from a directory name. If you already have an image file, use its path directly. An image produced by e2image is selected with -i, described in step 5.

For a filesystem that is mounted and busy, treat the report as a snapshot of metadata that may lag behind activity. For the most reliable maintenance report, use an offline copy or inspect during an agreed quiet period. Do not unmount a production filesystem just to make this example fit: unmounting can disrupt services and should have its own change and recovery plan.

2. Read the superblock summary

Use -h when you want the filesystem-wide facts without the detailed block-group sections:

$ dumpe2fs -h /dev/DEVICE

On this machine, the command begins with a version line and then reports fields such as the filesystem magic number, feature flags, block and inode counts, block size, filesystem state, journal inode and recent check times. The exact values depend on the filesystem. A successful command returns status 0.

For a harmless verification, capture the status immediately after the command:

$ status=$?
$ printf 'dumpe2fs exit status: %s\n' "$status"

Expected output for a readable, valid filesystem is dumpe2fs exit status: 0. A non-zero result means the report is not trustworthy. Keep the diagnostic text: causes include an unreadable input, an invalid or unreadable superblock, bad checksums, or an input that is in use by another node when -m is used.

3. Inspect group descriptors when layout matters

Run the full report when you need the superblock followed by block-group detail:

$ dumpe2fs /dev/DEVICE

This can be long on a large filesystem. Redirect it to a new evidence file if you need to attach it to a ticket. The redirection changes only the report file, not the filesystem:

$ dumpe2fs /dev/DEVICE > dumpe2fs-report.txt
$ test -s dumpe2fs-report.txt && sed -n '1,35p' dumpe2fs-report.txt

Do not use > with a valuable existing report unless overwriting it is intentional: the shell truncates the destination before dumpe2fs starts. Choose a new filename or copy the old report first. If the command fails, the new file may contain a partial report; label it as failed evidence rather than treating it as complete.

4. Produce a machine-readable group listing

The -g option prints group descriptors as colon-separated records. The fields are, in order: group number, first block, superblock location, group-descriptor block range, block bitmap, inode bitmap, and inode-table block range.

$ dumpe2fs -g /dev/DEVICE

On the temporary 32 MiB ext4 test image used for this guide, the data included this header and record shape:

group:block:super:gdt:bbitmap:ibitmap:itable
0:0:0:1-1:5:21:37

The numbers are not universal. A value of -1 means that the relevant superblock or descriptor range is not present for that group. Keep the header with the data when importing the output. If a parser needs hexadecimal block numbers, add -x:

$ dumpe2fs -gx /dev/DEVICE

Use this output for inventory or comparison, not as a substitute for filesystem repair. Do not edit the records and write them back: dumpe2fs has no write-back mode.

5. Handle image files and recovery options carefully

For an image created by e2image, add -i and pass the image pathname as the command's device argument:

$ dumpe2fs -i /path/to/filesystem.e2i

This tells dumpe2fs to read filesystem data from the e2image file. It does not reconstruct missing data and it does not convert an arbitrary disk image into an e2image. Check the image's provenance before drawing conclusions from it.

The -o superblock=NUMBER and -o blocksize=BYTES options are specialist recovery tools for examining badly corrupted filesystems. They are not routine alternatives to -h. A wrong superblock or block-size value can make the display misleading, so obtain the values from an appropriate recovery procedure and record exactly what you tried.

The -f option forces display when dumpe2fs does not understand some filesystem feature flags. The manual warns that the resulting display may be suspect. Treat forced output as diagnostic evidence only, and do not use it to justify a repair or a destructive rewrite.

6. Check an MMP-enabled filesystem only when required

The -m option checks whether the device is in use by another node when the filesystem's multiple-mount protection feature is enabled:

$ dumpe2fs -m /dev/DEVICE
$ printf 'MMP check status: %s\n' "$?"

A non-zero status is meaningful here: the manual includes use by another node among the possible errors. Do not run this check casually against a shared device and then ignore its result. Consult e2mmpstatus(8) for the fuller MMP procedure, and stop if the output indicates another node is using the filesystem. Never try to clear a protection signal by writing directly to filesystem metadata.

7. Diagnose failures without escalating blindly

If the command cannot read the input, check the path and permissions first:

$ stat /dev/DEVICE
$ id
$ sudo dumpe2fs -h /dev/DEVICE

The first two commands are ordinary read-only checks. The final command requires elevated privileges and should be used only if the earlier checks show that access is the problem. sudo does not repair a bad superblock, correct a wrong device, or make a mounted report consistent.

For an unknown feature flag, try neither -f nor a recovery option as a reflex. First record the e2fsprogs version and the exact error:

$ dumpe2fs -V
$ dumpe2fs -h /dev/DEVICE 2>&1 | tee dumpe2fs-error.txt

Compare the reported filesystem type, device identity and version with the maintenance record. If the device may be damaged, stop at evidence collection and use an approved backup or filesystem-repair procedure. dumpe2fs is an inspection command; it is not e2fsck.

Done means

  • You inspected the intended device or image and recorded whether it was mounted.
  • You captured a superblock summary with dumpe2fs -h and checked its exit status.
  • You used -g when group layout was relevant and preserved its header.
  • You treated mounted output, forced output and MMP failures as boundaries, not as permission to guess.
  • You left the filesystem unchanged and kept any report with its command, version and input recorded.