Skip to content

104.2 Maintain the integrity of filesystems

Weight: 2

Candidates should be able to maintain a standard filesystem, as well as the extra data associated with a journaling filesystem.

Objectives

  • Verify the integrity of filesystems.
  • Monitor free space and inodes.
  • Repair simple filesystem problems.

Terms

du, df, fsck, e2fsck, mke2fs, tune2fs, xfs_repair, xfs_fsr, xfs_db

du & df

In many cases you want to find out about the free space of a disk, find how much space a directory is using, or check how many inodes are left.

The inode (index node) is a data structure in a Unix-style file system that describes a file-system object such as a file or a directory. Each inode stores the attributes and disk block locations of the object's data. File-system object attributes may include metadata (times of last change, access, modification), as well as owner and permission data. A directory is a list of inodes with their assigned names. The list includes an entry for itself, its parent, and each of its children.

Why inodes can run out separately from disk space:

   a filesystem has TWO limits

   blocks  = the actual space for file contents
   inodes  = the number of files it can hold at all

   millions of tiny files can use up every inode
   while most of the blocks are still free.
   df says "space available", writes still fail.

df

The diskfree command is used to find out about the free and used space on file systems.

nagato@funlife:~$ df -TH
Filesystem        Type      Size  Used Avail Use% Mounted on
/dev/sda2         ext4       23G   15G  7.7G  65% /
none              tmpfs     4.0K     0  4.0K   0% /sys/fs/cgroup
udev              devtmpfs  3.9G  4.0K  3.9G   1% /dev
tmpfs             tmpfs     788M  1.4M  786M   1% /run
none              tmpfs     5.0M  4.0K  5.0M   1% /run/lock
none              tmpfs     3.9G   19M  3.9G   1% /run/shm
none              tmpfs     100M   28K  100M   1% /run/user
/dev/mapper/chome ext4      243G  229G   14G  95% /home/nagato
/dev/sdb1         vfat      3.7G  7.8M  3.6G   1% /media/nagato/BA82-BECD

Here, the -T switch tells df to show the file system types and -H makes numbers human readable (in powers of 1000, for powers of 2 use -h).

That -h versus -H difference is small but real:

   -h   powers of 1024   1 GiB = 1073741824 bytes
   -H   powers of 1000   1 GB  = 1000000000 bytes

On some filesystems (like ext2 to ext4) we have a fixed number of inodes, so you may need to check the number of remaining inodes too. To do so, use the -i switch:

nagato@funlife:~$ df -i
Filesystem          Inodes  IUsed    IFree IUse% Mounted on
/dev/sda2          1531904 458616  1073288   30% /
none               1007533      4  1007529    1% /sys/fs/cgroup
udev               1003703    542  1003161    1% /dev
tmpfs              1007533    644  1006889    1% /run
none               1007533      3  1007530    1% /run/lock
none               1007533    162  1007371    1% /run/shm
none               1007533     33  1007500    1% /run/user
/dev/mapper/chome 16171008 269293 15901715    2% /home/nagato
/dev/sdb1                0      0        0     - /media/nagato/BA82-BECD

vfat file format has no inodes. There is no owner or access rights on vfat filesystems.

Look at the last line. /dev/sdb1 reports 0 inodes and - for the percentage, which is exactly the vfat point being made.

Several more df options: -t TYPE shows only one filesystem type and -x TYPE excludes one:

$ df -hx tmpfs
Filesystem Size Used Avail Use% Mounted on
udev 2.9G 0 2.9G 0% /dev
/dev/sda1 106G 25G 76G 25% /
/dev/sdb1 88M 1.6M 79M 2% /media/carol/part1
/dev/sdb3 82M 1.6M 74M 3% /media/carol/part3
/dev/sdb2 89M 1.9M 81M 3% /media/carol/part2
/dev/sdc1 299G 223G 76G 75% /media/carol/Samsung Externo
$ df -ht ext4
Filesystem Size Used Avail Use% Mounted on
/dev/sda1 106G 25G 76G 25% /
/dev/sdb1 88M 1.6M 79M 2% /media/carol/part1
/dev/sdb3 82M 1.6M 74M 3% /media/carol/part3
/dev/sdb2 89M 1.9M 81M 3% /media/carol/part2

Real world use for -x tmpfs: a plain df is cluttered with tmpfs entries that live in RAM and are not real disks. Excluding them leaves only the storage you actually care about.

And --output= picks exactly which columns to print, in the order you name them:

$ df -h --output=target,source,fstype,pcent
Mounted on Filesystem Type Use%
/dev udev devtmpfs 0%
/run tmpfs tmpfs 1%
/ /dev/sda1 ext4 25%
/dev/shm tmpfs tmpfs 32%
/media/carol/part1 /dev/sdb1 ext4 2%

The block fields are source, fstype, size, used, avail, pcent and target. The inode fields are itotal, iused, iavail and ipcent:

$ df --output=source,fstype,itotal,iused,ipcent
Filesystem Type Inodes IUsed IUse%
udev devtmpfs 735764 593 1%
tmpfs tmpfs 744858 1048 1%
/dev/sda1 ext4 7069696 318651 5%

du

The diskusage command shows the used space of directories and files. The common switches are:

switch usage
-h print sizes in powers of 1024 (e.g., 1023M)
-H print sizes in powers of 1000 (e.g., 1.1G)
-c show the grand total
--max-depth 2 Calculate all but show only 2 directories deep
-s Only shows the summary and not all the directories one by one
nagato@funlife:~/w/lpic$ du
16    ./101
701456    ./done
701464    ./Logo/chert
704588    ./Logo
12    ./data
12    ./100
9432884    .
nagato@funlife:~/w/lpic$ du -c
16    ./101
701456    ./done
701464    ./Logo/chert
704588    ./Logo
12    ./data
12    ./100
9432884    .
9432884    total
nagato@funlife:~/w/lpic$ du -hs
9.0G    .

In many cases when I want to see what uses my server's space, I use something like $ sudo du /home -h --max-depth 1

The core difference between the two commands:

   du  works on FILES and DIRECTORIES
       "how much is this folder using?"
       walks the tree, adds up file sizes

   df  works on FILESYSTEMS
       "how full is this disk?"
       asks the filesystem for its own totals

This is why they can disagree. A deleted file still held open by a running process no longer appears to du, but its space is still counted by df.

Three more du options: -a shows every file, not just directories:

$ du -ah
432K ./geminoid.jpg
508K ./Linear_B_Hero.jpg
468K ./LG-G8S-ThinQ-Mirror-White.jpg
656K ./LG-G8S-ThinQ-Range.jpg
60K ./Stranger3_Titulo.png
4.8M .

-S (capital) separates a directory's own files from its subdirectories. Compare these two:

$ du -h
4.8M ./Temp
6.0M .
$ du -Sh
4.8M ./Temp
1.3M .

The first says the current directory totals 6.0 MB including Temp. The second says its own files are only 1.3 MB. Note that -s and -S are different options, since command line letters are case sensitive.

--exclude="PATTERN" leaves files out of the count:

$ du -ah --exclude="*.bin"
124K ./ASM68K.EXE
36K ./fixheadr.exe
4.0K ./README.txt
4.0K ./Built.bat
8.0K ./Contra_Main.asm
180K .

-d N is the same as --max-depth N, and that limiting the depth does not change the totals, it only hides the deeper lines.

checking file systems

fsck

If anything bad happens to your filesystem (say the power suddenly goes down) you will have a corrupted file system. The general command to fix this is fsck. Technically this command is a front end for many commands:

nagato@funlife:~$ ls /sbin/*fsck*
/sbin/dosfsck       /sbin/fsck.ext2     /sbin/fsck.fat     /sbin/fsck.vfat
/sbin/e2fsck       /sbin/fsck.ext3     /sbin/fsck.minix
/sbin/fsck       /sbin/fsck.ext4     /sbin/fsck.msdos
/sbin/fsck.cramfs  /sbin/fsck.ext4dev  /sbin/fsck.nfs

Some of these are just hardlinks to the e2fsck command.

   you type:  fsck /dev/sdb1
                 |
                 |  fsck looks at the filesystem type
                 v
        +--------+---------+---------+
        |        |         |         |
   e2fsck   fsck.vfat  fsck.minix  ...
   (ext2/3/4)

   fsck itself checks nothing. It picks the right tool.

A common switch during boot is -A, which tells fsck to check all file systems in /etc/fstab, ordered by passno in that file, which is the 6th field. File systems with a passno of 0 will not be checked during the boot.

root@funlife:~# fsck /dev/sdb
fsck from util-linux 2.25.1
e2fsck 1.42.10 (18-May-2014)
/dev/sdb is in use.
e2fsck: Cannot continue, aborting.

root@funlife:~# umount /dev/sdb
umount: /dev/sdb: not mounted
root@funlife:~# umount /dev/sdb1
root@funlife:~# fsck /dev/sdb
fsck from util-linux 2.25.1
e2fsck 1.42.10 (18-May-2014)
ext2fs_open2: Bad magic number in super-block
fsck.ext2: Superblock invalid, trying backup blocks...
fsck.ext2: Bad magic number in super-block while trying to open /dev/sdb

The superblock could not be read or does not describe a valid ext2/ext3/ext4
filesystem.  If the device is valid and it really contains an ext2/ext3/ext4
filesystem (and not swap or ufs or something else), then the superblock
is corrupt, and you might try running e2fsck with an alternate superblock:
    e2fsck -b 8193 <device>
 or
    e2fsck -b 32768 <device>

The first attempt failed with /dev/sdb is in use, and that refusal is a protection. Never run fsck on a mounted filesystem. Doing it anyway can destroy data. Unmount first.

The second attempt tells a different story. Bad magic number in super-block means the superblock is damaged or the device holds no ext filesystem at all. Note the suggestion at the end, e2fsck -b 8193, which points e2fsck at one of the backup superblocks created at format time. This is the same list mke2fs printed in 104.1.

You can also check filesystems by UUID (find them with the blkid command) or by label:

root@funlife:~# blkid
/dev/sda1: LABEL="movies"
/dev/sdb1: UUID="BA82-BECD" TYPE="vfat" PARTUUID="381add66-01"
root@funlife:~# fsck LABEL=movies
fsck from util-linux 2.25.1
root@funlife:~# fsck UUID="BA82-BECD"
fsck from util-linux 2.25.1
fsck.fat 3.0.26 (2014-03-07)
/dev/sdb1: 14 files, 1972/945094 clusters

Use -N to see what command or test is going to be executed without actually running it:

root@funlife:~# fsck -N UUID="BA82-BECD"
fsck from util-linux 2.25.1
[/sbin/fsck.vfat (1) -- /dev/sdb1] fsck.vfat /dev/sdb1

That output shows the dispatch happening: fsck resolved the UUID to /dev/sdb1, saw it was vfat, and would have called fsck.vfat.

If you want to check an XFS filesystem, you have to use the xfs_check command.

Some versions have a -a for automatically fixing all found issues, but it is not recommended.

The other main fsck options:

  • -A check every filesystem listed in /etc/fstab
  • -C show a progress bar, ext2/3/4 only
  • -N print what would be done and exit
  • -R with -A, skip the root filesystem
  • -V verbose
  • -t TYPE force a filesystem type, as in fsck -t vfat /dev/sdc

Real world use for -N: checking exactly which tool fsck will call on an unfamiliar disk before letting it touch anything.

e2fsck

e2fsck is used to check the ext2/ext3/ext4 family of file systems. For ext3 and ext4 file systems that use a journal, if the system has been shut down uncleanly without any errors, then normally, after replaying the committed transactions in the journal, the file system should be marked as clean. Hence, for file systems that use journaling, e2fsck will normally replay the journal and exit, unless its superblock indicates that further checking is required.

The device is a block device (e.g., /dev/sdc1) or a file containing the file system.

Note that in general it is not safe to run e2fsck on mounted file systems. The only exception is if the -n option is specified, and -c, -l, or -L options are not specified. However, even if it is safe to do so, the results printed by e2fsck are not valid if the file system is mounted. If e2fsck asks whether or not you should check a file system which is mounted, the only correct answer is "no". Only experts who really know what they are doing should consider answering this question in any other way.

If e2fsck is run in interactive mode (meaning that none of -y, -n, or -p are specified), the program will ask the user to fix each problem found in the file system. A response of 'y' will fix the error, 'n' will leave the error unfixed, and 'a' will fix the problem and all subsequent problems. Pressing Enter will proceed with the default response, which is printed before the question mark. Pressing Control-C terminates e2fsck immediately.

This is the practical reason journaling matters so much. On ext2, a crash means e2fsck walks the whole filesystem asking you about every problem it finds. On ext3 or ext4, it replays the journal and is finished in seconds.

The options that make it run without asking:

  • -p fix automatically, but stop and describe anything needing a human
  • -y answer yes to everything
  • -n answer no to everything, and mount read-only so nothing can change
  • -f force a check even if the filesystem is marked clean

-n is the safe one to reach for first. It tells you what is wrong without changing anything.

mke2fs

mke2fs is used to create an ext2, ext3, or ext4 filesystem, usually in a disk partition. The device is the special file corresponding to the device (e.g. /dev/hdXX). blocks-count is the number of blocks on the device. If omitted, mke2fs automatically figures out the file system size. If called as mkfs.ext3 a journal is created as if the -j option was specified.

The defaults for the newly created filesystem, if not overridden by options, are controlled by the /etc/mke2fs.conf configuration file. See the mke2fs.conf(5) manual page for more details.

tune2fs

This is a command to tune ext file systems. It can show information and set many options. The -l option lists the current configs:

nagato@funlife:~$ sudo tune2fs -l /dev/sda2
tune2fs 1.42.10 (18-May-2014)
Filesystem volume name:   <none>
Last mounted on:          /
Filesystem UUID:          1651a94e-0b4e-47fb-aca0-f77e05714617
Filesystem magic number:  0xEF53
Filesystem revision #:    1 (dynamic)
Filesystem features:      has_journal ext_attr resize_inode dir_index filetype needs_recovery extent flex_bg sparse_super large_file huge_file uninit_bg dir_nlink extra_isize
Filesystem flags:         signed_directory_hash
Default mount options:    user_xattr acl
Filesystem state:         clean
Errors behavior:          Continue
Filesystem OS type:       Linux
Inode count:              1531904
Block count:              6123046
Reserved block count:     306152
Free blocks:              2302702
Free inodes:              1073461
First block:              0
Block size:               4096
Fragment size:            4096
Reserved GDT blocks:      1022
Blocks per group:         32768
Fragments per group:      32768
Inodes per group:         8192
Inode blocks per group:   512
Flex block group size:    16
Filesystem created:       Mon Dec  1 10:21:42 2014
Last mount time:          Sat Jan 31 17:21:51 2015
Last write time:          Sat Jan 31 17:21:51 2015
Mount count:              32
Maximum mount count:      -1
Last checked:             Mon Dec  1 10:21:42 2014
Check interval:           0 (<none>)
Lifetime writes:          103 GB
Reserved blocks uid:      0 (user root)
Reserved blocks gid:      0 (group root)
First inode:              11
Inode size:              256
Required extra isize:     28
Desired extra isize:      28
Journal inode:            8
First orphan inode:       786620
Default directory hash:   half_md4
Directory Hash Seed:      16c38a41-e709-4e04-b1c2-8a79d71ea7e8
Journal backup:           inode blocks

The lines worth picking out of that block:

  • Filesystem features: has_journal ... = this is an ext3 or ext4, since ext2 has no journal.
  • Filesystem state: clean = it was unmounted properly last time.
  • Errors behavior: Continue = what the kernel does when it hits an error.
  • Mount count: 32 and Maximum mount count: -1 = it has been mounted 32 times, and -1 means automatic checks by mount count are switched off.
  • Reserved block count: 306152 = about 5% of the disk is held back for root, so a full disk does not stop root from logging in and fixing it.

The settings you can change with tune2fs:

  • -c N set the maximum mount count, after which the filesystem is checked at the next boot
  • -C N set the current mount count. Note -c and -C are different
  • -i N set a time interval between checks, with d, w or m for days, weeks or months, so -i 10d checks every ten days. Zero disables it
  • -L LABEL set a label, up to 16 characters
  • -U UUID set the UUID
  • -e BEHAVIOUR set what the kernel does on error: continue, remount-ro or panic
  • -j add a journal, which converts an ext2 filesystem into ext3
  • -J size=, -J location=, -J device= control the journal, and can be combined with commas
  • -f force, which should be used with great care

The -j conversion is the neat one:

   # tune2fs -j /dev/sda1

   ext2 (no journal)  --->  ext3 (has a journal)

   then mount it as type ext3, or the journal is ignored

Real world use for -e remount-ro: on a machine holding important data, this makes the kernel switch the filesystem to read-only the moment an error appears, stopping further writes before more damage is done.

debugfs

This is an interactive tool for debugging an ext filesystem. It opens the filesystem in read-only mode unless we tell it not to (with the -w option). It can un-delete files and directories.

root@funlife:~# debugfs /dev/sda2
debugfs 1.42.10 (18-May-2014)
debugfs:  cd /etc/        <-- cd
debugfs:  pwd            <-- show were am I
[pwd]   INODE: 524289  PATH: /etc
[root]  INODE:      2  PATH: /
debugfs:  stat passwd        <-- show data on one file
Inode: 527187   Type: regular    Mode:  0644   Flags: 0x80000
Generation: 1875144872    Version: 0x00000000:00000001
User:     0   Group:     0   Size: 2145
File ACL: 0    Directory ACL: 0
Links: 1   Blockcount: 8
Fragment:  Address: 0    Number: 0    Size: 0
 ctime: 0x548d4241:a7b196fc -- Sun Dec 14 11:24:41 2014
 atime: 0x54cc635b:6acfc148 -- Sat Jan 31 08:38:43 2015
 mtime: 0x548d4241:a01076f8 -- Sun Dec 14 11:24:41 2014
crtime: 0x548d4241:9f1c52f8 -- Sun Dec 14 11:24:41 2014
Size of extra inode fields: 28
EXTENTS:
(0):2188172
debugfs:  ncheck 527187        <-- node check an inode
Inode    Pathname  
527187    /etc/passwd
debugfs:  q            <-- quit

Note [root] INODE: 2. Inode 2 is always the root directory of an ext filesystem. Also note the three times on the passwd file: ctime when the inode last changed, atime when it was last read, and mtime when its contents last changed. These are the same three times find searches with -ctime, -atime and -mtime from 103.3.

Superblock

Unix systems use superblocks to save filesystem metadata. Most of the time this block is located at the beginning of the file system and replicated in other locations too. The -n option of mke2fs displays superblock locations:

# mke2fs -n /dev/sda7
mke2fs 1.41.9 (22-Aug-2009)
Filesystem label=
OS type: Linux
Block size=4096 (log=2)
Fragment size=4096 (log=2)
7159808 inodes, 28637862 blocks
1431893 blocks (5.00%) reserved for the super user
First data block=0
Maximum filesystem blocks=4294967296
874 block groups
32768 blocks per group, 32768 fragments per group
8192 inodes per group
Superblock backups stored on blocks:
    32768, 98304, 163840, 229376, 294912, 819200, 884736, 1605632, 2654208,
    4096000, 7962624, 11239424, 20480000, 23887872

This ties the whole section together. The superblock holds the master record of the filesystem, so if it is damaged nothing can be read. That is why copies are scattered across the disk, and why fsck suggested e2fsck -b 8193 earlier. Remember that -n here does not create anything, it just prints what would be done, so this is safe to run on a formatted disk to find the backup locations.

xfs tools

Note: in some distros, xfs tools are not installed by default and you might need to install the xfsprogs package.

This is the same as tune2fs but for xfs file systems.

xfs_info should be used on mounted file systems.

Command usage
xfs_info display information
xfs_growfs expand file system
xfs_admin change parameters on XFS file systems
xfs_repair repair the problems. Please note that the filesystem under repair should be unmounted
xfs_db checks and debugs the filesystem. xfs_db is used to examine an XFS filesystem. Under rare circumstances it can also be used to modify an XFS filesystem, but that task is normally left to xfs_repair or to scripts such as xfs_admin that run xfs_db
xfs_fsr filesystem reorganizer for XFS. When invoked with no arguments xfs_fsr reorganizes all regular files in all mounted filesystems. xfs_fsr makes many cycles over /etc/mtab, each time making a single pass over each XFS filesystem. Each pass goes through and selects files that have the largest number of extents. It attempts to defragment the top 10% of these files on each pass

The mapping from the ext tools to the XFS tools:

   ext                XFS
   ---------------------------------
   fsck / e2fsck      xfs_repair
   tune2fs -l         xfs_info
   tune2fs            xfs_admin
   debugfs            xfs_db
   resize2fs          xfs_growfs
   (no equivalent)    xfs_fsr

xfs_repair -n does a check without changing anything, which is the XFS equivalent of e2fsck -n:

# xfs_repair -n /dev/sdb1
Phase 1 - find and verify superblock...
Phase 2 - using internal log
  - zero log...
  - scan filesystem freespace and inode maps...
  - found root inode chunk
Phase 3 - for each AG...
  - scan (but do not clear) agi unlinked lists...
  - process known inodes and perform inode discovery...
  - agno = 0
  - agno = 1
  - agno = 2
  - agno = 3
  - process newly discovered inodes...
Phase 4 - check for duplicate blocks...
  - setting up duplicate extent list...
  - check for inodes claiming duplicate blocks...
No modify flag set, skipping phase 5
Phase 6 - check inode connectivity...
  - traversing filesystem ...
  - traversal finished ...
  - moving disconnected inodes to lost+found ...
Phase 7 - verify link counts...
No modify flag set, skipping filesystem flush and exiting.

Note the lines saying No modify flag set. That is -n doing its job. Phase 5 was skipped entirely, and nothing was written. Running the same command without -n performs the repairs.

Other xfs_repair options:

  • -l LOGDEV and -r RTDEV for filesystems whose log or realtime section is on a separate device
  • -m N limit memory use to N megabytes. By default it will scale up to 75% of system RAM
  • -d dangerous mode, allowing repair of a read-only mounted filesystem
  • -v verbose, and -v -v for more
  • -L zero out a dirty log. This is a last resort and can cause data loss

xfs_db opens an interactive prompt like parted, with help listing the commands. xfs_fsr defragments, running for two hours by default over every mounted writable XFS filesystem listed in /etc/mtab.

Repairing

We used fsck for showing file system information, but it is designed to fix file systems too. If the boot time check finds a problem, you will be put into a command line to fix the problems.

On non-journaling file systems (ext2) fsck will show you many questions about each block, and you have to say y if you want it to fix them. On journaling file systems (ext3, ext4, xfs) fsck has much less to do.

For xfs file systems, we have the xfs_check command.

An important switch is -n, which causes these commands not to fix anything and just show what was going to be done.

Other tools

For the LPIC exam, it is good to know about these commands.

filesystem command usage
ext tune2fs Show or set ext2 and ext3 parameters or even set the journaling options
ext dumpe2fs Prints the super block and block group descriptor information for an ext2 or ext3 filesystem
ext debugfs Is an interactive file system debugger. Use it to examine or change the state of an ext2 or ext3 file system
reiserfs reiserfstune show and set parameters
reiserfs debugreiserfs Prints the super block and block group descriptor information
XFS xfs_info display information
XFS xfs_growfs expand file system
XFS xfs_admin change parameters on XFS file systems
XFS xfs_repair repair the problems
XFS xfs_db checks and debugs the filesystem

Summary

I have a Linux system where filesystems can fill up or become damaged, and this objective is about watching for both. For space I have two commands that answer different questions. du walks files and directories and tells me what is using space inside a folder, with -h for readable sizes, -s for a summary line, -a to include every file, -S to separate a directory's own files from its subdirectories, --max-depth to limit how deep the listing goes, and --exclude to skip a pattern. df asks each mounted filesystem for its own totals, with -h or -H for readable numbers, -T to add the type column, -t and -x to include or exclude a type, and --output= to choose exactly which columns appear.

The second thing to watch is inodes, using df -i. A filesystem has two separate limits, blocks for the actual file contents and inodes for how many files can exist at all, so a disk holding millions of tiny files can run out of inodes while df still reports free space. Filesystems like vfat have no inodes at all, and that is also why they carry no ownership or permission information.

For checking and repairing, fsck is the front end that looks at the filesystem type and calls the right tool underneath, which for the ext family is e2fsck. The rule I must not break is never running it on a mounted filesystem, and fsck normally refuses anyway. Useful options are -N to show what would run without running it, -A to check everything in /etc/fstab in passno order, and on e2fsck itself -n to report without changing, -p to fix automatically, -y to say yes to everything and -f to force a check on a filesystem already marked clean. The reason this is usually quick is journaling: after a crash on ext3 or ext4 the journal is replayed and the check ends, while ext2 has to be walked block by block.

For tuning I use tune2fs, with -l to print every parameter of an ext filesystem and options like -c and -i to control automatic checks, -L and -U to set a label or UUID, -e to say whether the kernel continues, remounts read-only or panics on an error, and -j to add a journal and turn an ext2 filesystem into ext3. debugfs opens an ext filesystem interactively and can even recover deleted files. Underneath it all sits the superblock, the master record of the filesystem, which is copied to several places at format time. mke2fs -n prints those backup locations without changing anything, and e2fsck -b uses one of them when the main superblock is unreadable. For XFS the same jobs have different names: xfs_repair instead of fsck, xfs_info and xfs_admin instead of tune2fs, xfs_db instead of debugfs, xfs_growfs to grow and xfs_fsr to defragment.