Update the smartmontools Drive Database Safely
A drive that smartctl cannot identify is often just an outdated database, and update-smart-drivedb is the fix.
The route
Jump straight to the step you need, or tick off Done means at the end.
The examples match smartmontools 7.4, package version 7.4-2build1, installed on this machine. Verify the download before trusting it.
Allow about ten minutes. You need a shell, network access to the selected download source, and sudo access because the default database lives under /var/lib. The normal update does not restart smartd, but a later smartctl or smartd process may read the changed database.
Checkpoint
This guide changes one database file. It does not change drive firmware, run a SMART test, edit smartd.conf or install a different smartmontools package.
1. Confirm the installed tool and destination
Check which script will run and record the package version. These are ordinary, read-only commands:
$ command -v update-smart-drivedb
/usr/sbin/update-smart-drivedb
$ dpkg-query -W -f='${Package} ${Version}\n' smartmontools
smartmontools 7.4-2build1
$ update-smart-drivedb --help | sed -n '1,12p'
smartmontools 7.4 drive database update script
Usage: /usr/sbin/update-smart-drivedb [OPTIONS] [DESTFILE]
With no destination argument, the script updates /var/lib/smartmontools/drivedb/drivedb.h. Its source is the smartmontools 7.3 drive-database branch in this installed release. The script uses the first supported downloader it finds in PATH; here that is curl.
2. Preview the download
Use --dryrun before changing anything. It prints the commands that would download the database and its detached signature, but does not perform the download:
$ update-smart-drivedb --dryrun --branch 7.3
curl -s -f --max-redirs 0 -H Accept-Encoding: identity -o /var/lib/smartmontools/drivedb/drivedb.h.new https://svn.code.sf.net/p/smartmontools/code/branches/RELEASE_7_3_DRIVEDB/smartmontools/drivedb.h
curl -s -f --max-redirs 0 -H Accept-Encoding: identity -o /var/lib/smartmontools/drivedb/drivedb.h.new.raw.asc https://svn.code.sf.net/p/smartmontools/code/branches/RELEASE_7_3_DRIVEDB/smartmontools/drivedb.h.raw.asc
$ printf 'exit status: %s\n' "$?"
exit status: 0
--branch 7.3 makes the branch explicit; it is also the installed default. Do not use --trunk for a routine update: the manual says trunk is unsigned and therefore requires --no-verify.
3. Run the signed update
Warning
The next command changes the system database and normally needs elevated privileges. It downloads a new file, checks its OpenPGP signature, checks its syntax with /usr/sbin/smartctl, and only then replaces the current database:
$ sudo update-smart-drivedb
/var/lib/smartmontools/drivedb/drivedb.h 7.2/5225 updated to 7.2/5237
The version numbers above are examples from the manual, not a prediction for your next update. You may instead see an already-current message, or an error. A successful update returns status 0; an error returns status 1.
- Keep signature checking on. It uses the script's embedded OpenPGP key.
--no-verifyis a deliberate trust-boundary bypass, not a general fix for a failed update. - Do not reach for
--insecure. It disables certificate failure handling and should not be used merely to silence a TLS problem.
4. Verify the result and the rollback file
Inspect the database path and the syntax directly. Reading the files does not require sudo on a normal installation, although permissions vary:
$ stat -c '%n %s bytes' /var/lib/smartmontools/drivedb/drivedb.h
/var/lib/smartmontools/drivedb/drivedb.h 123456 bytes
$ sudo smartctl -B /var/lib/smartmontools/drivedb/drivedb.h --version
smartctl 7.4 2023-08-01 r5530
The smartctl command here is a syntax-check pattern: -B tells smartctl to read the specified drive database, and --version avoids probing a real device. Exact output depends on the file and build, so the useful result is a zero exit status and no database syntax error.
When the downloaded file differs, the script moves the previous database to /var/lib/smartmontools/drivedb/drivedb.h.old. If the downloaded content is identical, the old file is kept and the script may create the empty drivedb.h.lastcheck marker. Temporary rejected files can have names ending in .error.
5. Roll back one update
Warning
Rollback replaces the current database with the saved previous file. Check that the backup exists before doing it:
$ sudo test -r /var/lib/smartmontools/drivedb/drivedb.h.old
$ sudo update-smart-drivedb --force \
--file /var/lib/smartmontools/drivedb/drivedb.h.old
/var/lib/smartmontools/drivedb/drivedb.h 7.2/5237 downgraded to 7.2/5225
--force is required because the saved file reports an older version on the same branch. This is the undo path for the immediately preceding replacement. Before rolling back, copy the current database somewhere outside the managed directory if you may need both versions: the script's next replacement can overwrite the .old file.
6. Use a separate destination for testing
You can download into a path you control by supplying DESTFILE, useful for inspecting an update without touching the live database:
$ update-smart-drivedb --branch 7.3 \
/tmp/drivedb-7.3-test.h
/tmp/drivedb-7.3-test.h 7.2/5237 newly installed
$ smartctl -B /tmp/drivedb-7.3-test.h --version
smartctl 7.4 2023-08-01 r5530
The destination form still verifies the signed download and syntax unless you explicitly disable those checks. Remove the temporary file after inspection if it is no longer needed. Do not use --file with an untrusted file unless you understand it supplies the database content directly: a local file needs a matching signature unless --no-verify is supplied.
Done means
- Update succeeded or was already current.
update-smart-drivedbreported one of the two. - Checks ran. The download used signature verification and the installed
smartctlsyntax check. - Database loads.
/var/lib/smartmontools/drivedb/drivedb.his readable and loads withsmartctl -B. - Rollback state known. You know whether
drivedb.h.oldexists before making another replacement.