Prepare an ext Filesystem for Recovery with mklost+found

mklost+found pre-builds the space that e2fsck needs to dump files it can no longer link back to their names. It creates a lost+found directory in whatever directory you run it from and pre-allocates blocks for it, so e2fsck can place a large batch of recovered files without needing to allocate data blocks mid-recovery.

This guide uses the mklost+found shipped by e2fsprogs 1.47.0. It has no command-line options. Allow about five minutes for the checks and command, plus time to identify the correct mounted filesystem. The command changes the filesystem, so work from an intended mount point and keep a recovery window if the filesystem matters.

Before you start

You need a mounted Linux second extended filesystem (ext2, ext3 or ext4), permission to create a directory at its root, and the e2fsprogs package, which supplies both mklost+found and e2fsck. Do not guess the mount point from a device name; check the mounted path first.

This utility is for a mounted filesystem. It is not a formatting command and it does not repair anything. Do not use it as a substitute for e2fsck, especially while the filesystem is mounted and in active use.

1. Identify the filesystem and mount point

Choose the filesystem whose root should contain lost+found. Replace the example path with the real mount point. The first command is ordinary inspection and needs no elevated privileges:

$ findmnt --target /srv/data
$ stat -f -c 'mount=%m type=%T' /srv/data

findmnt should show the device and filesystem type for /srv/data. The stat check confirms the path is a filesystem mount and reports its type. Stop if the path is not the filesystem you meant to change, or if it is not an ext filesystem.

A common distraction is running the command from your home directory and then looking for the result under the mount point. The utility uses the current working directory, so change into the mount point explicitly in the same shell session:

$ cd -- /srv/data
$ pwd
/srv/data

Checkpoint: confirm the target

Before creating anything, verify that pwd prints the filesystem root you intend to prepare. On a server, also confirm the path is not a bind mount or a temporary test mount standing in for the real data volume.

2. Check for an existing directory

Inspect the target before invoking the command:

$ ls -ld -- ./lost+found
ls: cannot access './lost+found': No such file or directory

That is the usual missing-directory result. If the directory already exists, do not remove it just to rerun the command: it may already be prepared, or it may hold recovered files from an earlier repair. Inspect it and preserve its contents unless you have a separate, verified reason to clean it up.

Do not create a plain empty directory with mkdir and assume the job is done. The whole point of mklost+found is pre-allocating directory blocks for recovery, and a bare mkdir gives you none of that.

Checkpoint: inspect before changing

At this point, pwd names the intended mount point and lost+found is either absent or understood. If either check is wrong, stop here and correct the path.

3. Create the recovery directory

Run the command with no arguments. Creating a directory at the root of a mounted filesystem usually needs root, so use sudo when your account lacks write permission there:

$ sudo mklost+found

On success, this version normally produces no output and returns you straight to the prompt. There are no flags to select a size or another directory: the synopsis is simply mklost+found, and typing an option gets it rejected.

If the command reports that the path is not a valid target, recheck the mount and filesystem type. If it reports permission denied, confirm the current directory with pwd and use the appropriate privilege. Do not run it in a different directory merely because that one happens to be writable.

4. Verify the result

Check that the directory exists and belongs to the filesystem you selected:

$ ls -ld -- ./lost+found
drwx------ 2 root root 16384 Sep 25 12:00 ./lost+found
$ findmnt --target ./lost+found
/srv/data /dev/mapper/data ext4 rw,relatime

The owner, mode, timestamp, block count and device will vary. What matters is that the path exists beneath the intended mount point and findmnt resolves it to the intended filesystem. An empty listing from ls is not a problem: filesystem-checking tools populate it later, only when needed.

You can also confirm the installed command and package version without changing anything:

$ mklost+found --help
mklost+found 1.47.0 (5-Feb-2023)
Usage: mklost+found

On this release, that help invocation actually exits non-zero because the program has no options, even though the version and synopsis it prints are useful. Treat the directory check, not that diagnostic exit status, as the real success test.

Safety and recovery

Creating lost+found is normally low risk, but it consumes filesystem metadata and pre-allocated directory blocks. Do not run it on an unmounted block device, on a directory that is merely a staging folder, or against an invented mount point. The command takes no device argument, so the current directory is the entire safety boundary.

If you created the directory on the wrong mounted filesystem and it is still empty, verify the path again, then remove only that exact directory with elevated privileges:

$ cd -- /the/wrong/mount
$ findmnt --target .
$ ls -la -- ./lost+found
$ sudo rmdir -- ./lost+found

Warning: rmdir refuses to remove a non-empty directory. Do not replace it with rm -rf: that could delete recovered files or other data. If the directory contains files, stop and work out whether they are needed before taking any further action. Removing a correctly prepared directory is also a regression, so leave it in place unless there is a documented reason to undo it.

Done means