e2scrub checks a mounted ext4 file system for corruption without ever unmounting it, using an LVM snapshot underneath. It finishes with a read-only corruption check for a mounted ext2, ext3 or ext4 filesystem, plus a clear way to interpret the result: the live filesystem stays mounted throughout while its metadata is examined through the snapshot.
Allow about fifteen minutes for preparation and command output, though the check itself depends on the size and condition of the filesystem. You need the e2scrub command from e2fsprogs, an LVM-backed filesystem, root access, and at least 256 MiB of unallocated space in the volume group. This guide uses the local e2fsprogs version 1.47.0-2.4~exp1ubuntu4.1.
Safety boundary: e2scrub checks metadata but does not repair corruption. If it finds errors, stop normal use of the filesystem and arrange an offline e2fsck as soon as possible. Do not run e2fsck against a mounted filesystem as a shortcut.
Check the package and binary before choosing a target. These are ordinary, read-only commands:
$ dpkg-query -W -f='${Package} ${Version}\n' e2fsprogs
e2fsprogs 1.47.0-2.4~exp1ubuntu4.1
$ command -v e2scrub
/usr/sbin/e2scrub
Your package revision and binary path may differ. The installed manual describes the command as e2scrub [OPTION] MOUNTPOINT | DEVICE: it accepts either a mounted filesystem's mountpoint or the block device of its LVM logical volume.
Checkpoint: do not continue until command -v e2scrub returns a real executable and the package is the one you expect.
Use findmnt to inspect the mountpoint, source device and filesystem type. Replace /srv/data with the mountpoint you intend to check:
$ findmnt -no SOURCE,FSTYPE,TARGET /srv/data
/dev/mapper/vg0-data ext4 /srv/data
The output must identify an ext2, ext3 or ext4 filesystem whose source is an LVM logical volume. If the source is a physical partition, a network filesystem or another filesystem type, this is not an e2scrub target: do not guess from a directory name.
Confirm the logical volume and volume group, still without changing anything:
$ sudo lvs -o vg_name,lv_name,lv_path,lv_size,lv_attr vg0/data
VG LV Path LSize Attr
vg0 data /dev/vg0/data 100g -wi-ao----
sudo is shown because LVM metadata may not be readable by an ordinary account. The logical volume needs a volume group with at least 256 MiB free for the temporary snapshot. Check that before starting:
$ sudo vgs -o vg_name,vg_free vg0
VG VFree
vg0 2.00g
If the free space is below 256 MiB, e2scrub will skip the logical volume. Free space inside the filesystem is not a substitute for unallocated space in the LVM volume group.
Run the dry-run form as root. -n prints the commands that would be executed but does not execute the check; it still needs root because e2scrub queries the system while building the plan:
$ sudo e2scrub -n /srv/data
# commands are printed here; exact output depends on the host
Read the preview rather than treating it as a generic success message. Check that the filesystem and logical volume are the ones you inspected. If the preview selects an unexpected device, stop and resolve the mount or LVM mapping first.
Checkpoint: you have confirmed the filesystem type, LVM path and available snapshot space, and the dry run names the intended target.
Start the real check with elevated privileges:
$ sudo e2scrub /srv/data
$ printf 'e2scrub exit status: %s\n' "$?"
e2scrub exit status: 0
The command creates a snapshot named after the logical volume with .e2scrub appended, then checks the snapshot. udev will not create the usual /dev/disk links for that snapshot. e2scrub attempts to remove snapshots before running, and it should remove its temporary snapshot as part of the normal run.
An exit status of zero is the useful success signal for this run. Keep the command output in your maintenance record, but do not assume a quiet terminal means a repair occurred: this tool checks and does not repair.
To check for a leftover snapshot after an interrupted or failed run:
$ sudo lvs -o vg_name,lv_name,lv_path,lv_attr vg0
# inspect the list for the expected .e2scrub logical volume
Do not remove an arbitrary logical volume. If a clearly identified e2scrub snapshot remains, use the dedicated cleanup mode in the next step.
Warning: -r removes the e2scrub snapshot and exits without checking anything. It is a state-changing operation. Use it only after lvs has shown that the named logical volume is the stale e2scrub snapshot for this filesystem:
$ sudo e2scrub -r /srv/data
$ printf 'cleanup exit status: %s\n' "$?"
cleanup exit status: 0
Verify that the snapshot is gone:
$ sudo lvs -o vg_name,lv_name,lv_path vg0
# the old data.e2scrub entry should no longer be listed
This cleanup does not repair the live filesystem and does not undo a completed filesystem check. If the snapshot cannot be removed, stop rather than deleting a similarly named logical volume by hand; ask the storage administrator to identify the exact device.
If the check finds no errors, the filesystem remains mounted and e2scrub may run fstrim when requested with -t. That option is not part of the default command. Trimming can affect storage behaviour, so use it only when it matches your device and maintenance policy:
$ sudo e2scrub -t /srv/data
# e2scrub checks the filesystem, then calls fstrim if no errors are found
If errors are found, e2scrub marks the filesystem as having errors. Take it offline and run e2fsck as soon as possible during an appropriate maintenance window. Unmount it first, stop services using it, and use the device path confirmed by findmnt:
$ sudo umount /srv/data
$ sudo e2fsck /dev/vg0/data
$ sudo mount /dev/vg0/data /srv/data
Those commands can interrupt services and e2fsck can modify filesystem metadata: they are recovery actions, not a routine e2scrub check. Follow your backup and outage procedure, and do not proceed if you cannot account for users of the mount. If the filesystem is left unrepaired, the manual says e2fsck will be run before the next mount.
vgs for at least 256 MiB of unallocated volume-group space, not merely free blocks in the filesystem.sudo. Even -n requires root because system queries still run.findmnt output with the path passed to e2scrub. Use the mountpoint or its LVM logical-volume device, not an arbitrary directory.lvs, then use e2scrub -r only when its identity is certain.sudo e2scrub -n identified the intended check..e2scrub snapshot was identified before cleanup.