sg_ses finds an SES enclosure, decodes its diagnostic pages, and matches disk slots to their descriptors, all without changing anything. You will finish with a read-only workflow and a saved capture for later analysis, plus a clear boundary between inspection and commands that can change a locator LED or other enclosure state.
Allow about 15 minutes for inspection, plus time to identify the correct enclosure device in a real server. The examples use sg_ses from the sg3-utils package. On this machine the package is 1.46-3ubuntu4, while the installed program reports sg_ses version 2.48 20200501. The installed binary is the authority for option spelling and defaults here; the compressed manpage is the package's 1.46 documentation.
Run these commands as an ordinary user first:
$ sg_ses --version
version: 2.48 20200501
$ sg_ses --enumerate | sed -n '1,24p'
The second command prints the diagnostic pages and element abbreviations recognised by this build. Among the useful page names are cf for Configuration, es for Enclosure Status, ed for Element Descriptor, and aes for Additional Element Status. The command does not contact an enclosure, so it is a safe syntax check.
Checkpoint: if sg_ses is missing, stop here and install the distribution's sg3-utils package through your normal change process. Do not guess a device path or substitute a disk simply because it is a SCSI device.
sg_ses needs a SCSI generic or block-based SCSI address for an enclosure services device. Typical Linux paths are /dev/sg3 and /dev/bsg/6:0:2:0, but the number is host-specific. Use the device inventory and your enclosure documentation to select the enclosure processor or an exposed device with the SES capability. If you need to inspect candidates, use sg_inq from the same package and look for a device that identifies as an enclosure services processor or advertises enclosure services.
$ sg_inq /dev/sgN
$ sg_ses --readonly /dev/sgN
Replace /dev/sgN with the verified path. With no page option, this asks for the supported diagnostic pages. The --readonly option opens the device read-only; it is a useful extra guard while learning the enclosure. Depending on device permissions, the read may need elevation:
$ sudo sg_ses --readonly /dev/sgN
Use sudo only when the host denies access. It does not make an ordinary disk into an SES device. A SCSI error, an unsupported command, or an empty response is a reason to re-check the path and enclosure capability, not to try control options.
Start with the configuration and status pages:
$ sg_ses --readonly --page=cf /dev/sgN
$ sg_ses --readonly --page=es /dev/sgN
The configuration page describes the enclosure's element layout. The status page reports current element state. Output varies by vendor and hardware, so do not rely on a particular temperature, slot count, or line order. A successful command returns status 0; the useful verification is to inspect the decoded page name and the elements rather than to match a fixed transcript.
If the output is too large, ask for a joined view and then filter it:
$ sg_ses --readonly --join --filter /dev/sgN
--join correlates the Element Descriptor, Enclosure Status, and Additional Element Status pages. It can produce a great deal of output. --filter removes rows with no set status flags; giving it twice narrows the result further to elements associated with status=ok. Treat this as a display filter, not a health guarantee.
Element indexes are easy to misread because overall elements and individual elements share the SES layout. First read the element descriptors:
$ sg_ses --readonly --page=ed /dev/sgN
When the descriptor text is known, use it as a medium-level selector. This example asks for the SAS address associated with a named array device:
$ sg_ses --readonly --page=aes \
--descriptor='ArrayDevice07' --get=at_sas_addr --hex /dev/sgN
The descriptor must match the enclosure's Element Descriptor page, including spaces when present. Quote it when it contains whitespace or shell punctuation. For a known device slot, --dev-slot-num=SN is another selector. For a SAS end device, --sas-addr=SA selects the matching address; the value is hexadecimal and is not necessarily the disk's WWN.
If a joined result associates the wrong row with an AES descriptor, the enclosure may use the SES-2 and SES-3 element-index conventions differently. The installed tool provides --eiioe=auto as a heuristic and --eiioe=force to decode as though the field is set. Try auto only when the enclosure's AES interpretation is the problem, and record the choice in your notes.
A capture is useful when you need to compare an enclosure before and after a maintenance event or analyse it away from the live array. Write only the command's standard output to a file so warnings remain visible:
$ sg_ses --readonly --page=all -HHHH /dev/sgN > enclosure-state.hex
$ test -s enclosure-state.hex && printf '%s\n' 'capture created'
capture created
The quad-hex form emits ASCII hexadecimal that can be parsed again, with page names in comments. The command's diagnostics still go to standard error. Decode the saved state without sending SCSI commands:
$ sg_ses [email protected] --status --join
The device argument is unnecessary for file input and, if supplied, is ignored. The decoded view describes the moment of capture, not the enclosure's current state. Keep the file access-controlled if its descriptors or topology would be sensitive in your environment.
Warning: --set, --clear, --nickname, and --control can send a SCSI SEND DIAGNOSTIC command. They can change enclosure state. Do not paste a control example until you have verified the enclosure path, element selector, field, and desired recovery action.
A common, limited use is turning on a disk carrier's locate LED. The manpage's example uses an element descriptor and the ident field:
$ sudo sg_ses --descriptor='ArrayDevice07' --set=ident /dev/sgN
To request that field be cleared later:
$ sudo sg_ses --descriptor='ArrayDevice07' --clear=ident /dev/sgN
These commands perform a read-modify-write operation for the relevant control element. They do not provide a universal undo for every field, and a vendor may handle locator timing differently. Before changing anything other than a locator field, save a status capture and obtain the enclosure vendor's procedure. If a locator stays lit, repeat the verified --clear=ident command; if the enclosure reports an error, stop issuing writes and use its management procedure.
Changing a subenclosure nickname also writes state. The tool limits the nickname to 32 bytes and uses subenclosure identifier 0 when --nickid is omitted:
$ sudo sg_ses --control --nickname='Rack 12 shelf A' /dev/sgN
Do not use raw hex editing as a first attempt. The lower-level --raw and --data workflow requires a careful read, edit, and control write, including correct page headers and selection bits.
sudo, then fix device-group permissions if this is a recurring operational need.--enumerate and the device's supported-pages response.--index or --descriptor, or add --filter to a joined read.--eiioe=auto behaviour.sg_ses version.