Extract and Inspect an Initramfs Safely with unmkinitramfs
You will unpack a Linux initramfs into a directory you choose, inspect its files, and remove the extracted copy when you finish. The original image in /boot is only read. This is useful when checking modules, firmware, hooks, boot scripts or an image that may be involved in an early-boot failure.
The route
Jump straight to the step you need, or tick off Done means at the end.
Allow about ten minutes for a normal image, plus time and disk space for the extracted files. The example below uses the installed unmkinitramfs from initramfs-tools-core 0.142ubuntu25.8. You need a shell, enough free space for an extracted image, and read access to the image. The extraction itself normally needs no elevated privileges if the destination is writable by you.
Safety boundary
This guide does not rebuild, replace or boot an initramfs. Do not use the image path as the destination. Extract into a new directory so that inspection cannot overwrite the source image or an existing system tree.
1. Check the installed command
Start with the local help and package version. These are ordinary read-only commands:
$ command -v unmkinitramfs
/usr/bin/unmkinitramfs
$ dpkg-query -W -f='${Package} ${Version}\n' initramfs-tools-core
initramfs-tools-core 0.142ubuntu25.8
$ unmkinitramfs -h
Usage: unmkinitramfs [-v] initramfs-file directory
Options:
-v Display verbose messages about extraction
The syntax has two positional arguments: the input initramfs and the output directory. -v is optional and prints names as files are extracted. The command's short help is the most reliable description of the binary installed on your machine; package versions can differ.
2. Choose the image and a disposable destination
List the available images before choosing one. The first command only reads directory metadata:
$ ls -lh /boot/initrd.img*
lrwxrwxrwx 1 root root 28 ... /boot/initrd.img -> initrd.img-6.8.0-142-generic
-rw-r--r-- 1 root root 73M ... /boot/initrd.img-6.8.0-139-generic
-rw-r--r-- 1 root root 73M ... /boot/initrd.img-6.8.0-142-generic
A pathname ending in /boot/initrd.img may be a symbolic link to the image selected as current. For a repeatable investigation, use the versioned file explicitly. Replace 6.8.0-142-generic below with a filename that exists on your host:
$ IMAGE=/boot/initrd.img-6.8.0-142-generic
$ DEST=/tmp/initramfs-6.8.0-142-generic
$ test -r "$IMAGE" && printf 'input is readable: %s\n' "$IMAGE"
input is readable: /boot/initrd.img-6.8.0-142-generic
Choose a destination that does not already contain files you care about. The program creates the directory when needed, but it does not make an existing destination disposable. If DEST points at a shared or privileged directory, stop and choose another path.
3. Extract without changing the boot image
Run the extraction as your normal user:
$ unmkinitramfs "$IMAGE" "$DEST"
$ printf 'exit status: %s\n' "$?"
exit status: 0
An exit status of zero means the command completed its extraction pipeline. It does not mean that every file is meaningful for your kernel problem, so inspect the result before drawing a conclusion. A non-zero status means the extraction did not complete cleanly. Check the input path, destination permissions, free space and the command's diagnostic text.
Checkpoint
Confirm that the output is a directory and that it has content:
$ test -d "$DEST" && find "$DEST" -mindepth 1 -maxdepth 1 -printf '%f\n' | sort
early
early2
early3
main
The exact list depends on the image. A simple compressed image may extract directly into the destination. The current Ubuntu script also separates an uncompressed prepended cpio archive into directories such as early, early2 and early3, then places the regular compressed archive under main.
This is an installed-script behaviour, not a promise that every older package has the same layout. The manpage describes the image as potentially containing multiple segments and says they are passed to cpio in order; it also records limitations for more complex multi-segment images.
4. Inspect the files that matter
Start with a shallow listing, then narrow the search to the question you are investigating:
$ find "$DEST" -maxdepth 3 -printf '%y %p\n' | sort | head -40
$ find "$DEST" -type f \( -name '*.ko' -o -name '*.conf' -o -name '*.sh' \) -print | head -40
$ find "$DEST" -type f -path '*/etc/*' -print | sort | head -40
Do not assume that every path is in main. Firmware or early CPU microcode may be in one of the early directories, while the normal initramfs tree is under main. Compare paths and file contents with the kernel version you selected. A file being present in an image is evidence of inclusion, not proof that the kernel will load it or that a boot hook will use it.
For a quick read-only content check, use standard tools against the extracted copy:
$ test -f "$DEST/main/init" && sed -n '1,40p' "$DEST/main/init"
$ find "$DEST" -type f -name '*.ko' -print | wc -l
42
The exact files and count vary by host. Avoid running scripts from the extracted tree. An initramfs contains boot-time programs and configuration, but extraction does not make those files safe to execute as ordinary user commands.
5. Use verbose mode when the layout is unclear
When you need to see what the command is sending through extraction, repeat the operation into a second empty destination with -v:
$ VERBOSE_DEST=/tmp/initramfs-verbose
$ unmkinitramfs -v "$IMAGE" "$VERBOSE_DEST" | head -30
.
kernel
kernel/x86
kernel/x86/microcode
kernel/x86/microcode/AuthenticAMD.bin
Verbose output can be very large. Piping it to head may close the pipe early and make the shell report status 141 even though the displayed beginning is useful. For a complete log, redirect it to a temporary file instead:
$ unmkinitramfs -v "$IMAGE" "$VERBOSE_DEST" >/tmp/unmkinitramfs-files.txt
$ sed -n '1,30p' /tmp/unmkinitramfs-files.txt
This second extraction consumes more disk space. Do not start it if the first output already fills the filesystem.
6. Remove only the disposable copies
After inspection, check the target before deleting it. Removal is destructive and the extracted files are not recoverable from the command itself:
$ printf 'about to remove: %s\n' "$DEST"
about to remove: /tmp/initramfs-6.8.0-142-generic
$ test "$DEST" = /tmp/initramfs-6.8.0-142-generic
$ rm -rf -- "$DEST"
$ test ! -e "$DEST" && printf 'extracted copy removed\n'
extracted copy removed
Only remove the explicit temporary destination you chose. If you need the evidence later, copy selected files to a documented case directory before cleanup. The original /boot/initrd.img-... file is not changed by extraction or by removing the destination.
Done means
- You confirmed the installed package and command syntax.
- You selected a real initramfs image and a separate writable destination.
unmkinitramfsreturned status 0 and produced inspectable files.- You accounted for
early*andmaindirectories where the installed script created them. - You inspected copies only and did not execute extracted boot scripts.
- You removed only the disposable output, or recorded why it was retained.