Here's what I've been Digging at digg.com!

Wednesday, January 17, 2007

System recovery with Knoppix

Often when trying to recover a system, I need to look up some command for copying data to different devices. My 1337 skills are slacking these days, so I compiled a list of commands for data recovery and other commands that I will probably use in the future.

These are all commands that work in Knoppix, and I believe any other Linux distro.

Rescuing a non-booting Linux system

This is the most common scenario. Something goes haywire, and boom, no boot. No problem: boot up Knoppix and find all your local partitions nicely iconicized on the KDE desktop. (Or cruise the file tree to /mnt.) Click on the correct icon, and there are all your files. But they are wisely mounted read-only. Again, no problem: right-click the desktop icon to bring up a nice menu with a "Change read/write mode" option. This mounts the filesystem on the partition as read/write. Now you can edit any file.

The default user is knoppix. For operations that require root privileges, you need to su to root and assign a root password:

knoppix@ttyp0[knoppix]# su
root@ttyp0[knoppix]# passwd

To mount a filesystem read/write from the command line:

root@ttyp0[knoppix]# mount -t reiserfs -o rw /dev/hda5 /mnt/hda5

To unmount:

root@ttyp0[knoppix]# umount /mnt/hda5

If you get an error message "Could not unmount device, device is busy," something is reading the filesystem. Close files and cd out of the filesystem.

How do you know what mountpoint and filesystem to specify? Just read /etc/fstab:

root@ttyp0[knoppix]# cat /etc/fstab
...
# Added by Knoppix
/dev/hda5 /mnt/hda5 reiserfs noauto,users,exec 0 0

==============================================================
==============================================================
Hardware detection

Before going on a mad config file editing spree, it often pays to examine hardware information. Knoppix excels at this, as it has the latest editions of Linux's excellent hardware and system utilities: fdisk, lspci, iwconfig, ifconfig, dmesg, /proc, and so forth. (Checking hardware information is also handy for testing a system for Linux compatibility before you buy it. Sound cards, softmodems, and wireless NICs are especially troublesome; manufacturers often change the chipsets without changing the model numbers, and you need to know the chipsets to determine if Linux drivers are available. The Knoppix CD also contains a number of sound files, for quick sound testing, starting with "OpenMusic" on the welcome screen.)

* fdisk -l displays all partitions on all hard drives.
* lspci -v gives detailed information about every device and chipset connected to the PCI bus.
* cat /proc/cpuinfo tells exactly what CPU is installed.
* ifconfig displays, and also manipulates, network interface settings. Most commonly Ethernet cards and ppp, the modem interface.
* iwconfig is like ifconfig, but for wireless network cards.
* dmesg is interesting. man dmesg isn't all that helpful if you're not a kernel hacker. Just using dmesg | grep is a useful troubleshooting and system discovery tool. To see everything, run dmesg with no options.


==============================================================
==============================================================

Partitioning and formatting

First, install the second hard drive. Then boot Knoppix and open a root shell. If there are partitions already on the second disk, simply re-format whatever ones you need. Note that SCSI drives are designated sd, while IDE drives are hd. This command displays the existing disk partitions; be sure to use values appropriate for your system:

root@ttyp0[knoppix]# fdisk -l /dev/hdb

To format a disk partition:

root@ttyp0[knoppix]# mkfs.ext2 -c /dev/hdb1

This creates a plain-vanilla ext2 filesystem. -c checks for bad blocks. Of course, you can make it anything you like: ext3, ReiserFS, whatever:

root@ttyp0[knoppix]# mke2fs -j -c /dev/hdb1
root@ttyp0[knoppix]# mkreiserfs /dev/hdb1

What, no partitions? First, here's how to create them the command-line way, with fdisk. It's medium-safe to futz with fdisk, as changes are not written to disk until you give the command to do so. So, you can try different options and preview the partition table before committing to any changes. This sequence of commands creates a single partition:

root@ttyp0[knoppix]# fdisk /dev/hdb

Type "m" at any time to display a table of fdisk commands. Then, type "n" to create a new partition. Now, type "p" to create a primary partition. Hit Enter twice to accept the defaults. Or, if you don't want to use the whole disk, hit Enter once to accept the default starting point, then select the size you want:

+1000M

Hit "p" at any time to preview the new partition table. When everything looks good, press "w" to write the changes to disk. By default, fdisk creates a "type 83" partition, which means Linux. To see a list of partition types, press "l". To change the partition type, hit "t". Want to delete a partition? Easy as pie: press "d" and follow the prompts.


==============================================================
==============================================================

Copying files at the command line

Remember to create a directory to move files into:

# mkdir /mnt/hdb1/home/carla/backup
# cp -r /mnt/hda5/home/carla /mnt/hdb1/home/carla/backup


==============================================================
==============================================================


Cloning an entire drive

You'll need two hard drives the same size, or a destination drive larger than the source drive. Make sure no partitions are mounted on either drive. In this example /dev/hda is the source drive, /dev/hdb is the destination drive. The dd command makes an exact, byte-for-byte copy, including the MBR (master boot record):

# dd if=/dev/hda of=/dev/hdb



==============================================================
==============================================================

Mounting confusion

Are you losing track of what's mounted, and in what state? No problem, here comes /proc to the rescue:
# cat /proc/mounts

This displays all mounted filesystems, the filesystem types, read/write status, and other attributes. How many hard drives are on the system? One of these will tell you (and remember, SCSI drives are sd, IDE are hd):

# fdisk -l

or

# dmesg | grep hd

or

# dmesg | grep sd




==============================================================
==============================================================

Copying to CD

KDE and Knoppix make this easy. Assuming there is a CD writer on the system, simply right-click on the desktop icon for the partition containing your files, and you will see "Create Data CD with K3b." Do File > New Project, drag and drop the files you want to copy, and there you go. K3b is very good at autodetecting and autoconfiguring your CD drives; it should do it all for you. If something goes awry, please refer to the developerWorks article "Burning CDs on Linux", which also teaches how to burn CDs from the command line.


==============================================================
==============================================================


Copying to other media

Zip drives, floppy disks, and USB storage devices will be automatically recognized by Knoppix, and icons will be placed on the desktop. Simply make the drive you want to copy files to writeable, then drag and drop until it's all done.


==============================================================
==============================================================

Copying over the network


You can configure Knoppix to connect to a network, just like any other Linux. Knoppix has its own graphical configuration utility: on the main menu find Knoppix > Network/Internet. Again Knoppix's excellent hardware detection comes into play; it even works on wireless NICs (assuming it's a wireless NIC that is supported in Linux!). Simply answer a series of questions, and you're done.

It's just as easy from the command line. As root, run:

# netcardconfig

Once your network settings are configured, there are several options for transferring files. cp is fine for locally mounted filesystems. Copying files over an untrusted network should be done with scp (secure copy), and in fact Knoppix won't let you use anything else. scp uses ssh for encrypted file transfer and lets you move files without setting up NFS or Samba. You'll need an ssh server running somewhere on the network to receive the files. This command copies an entire directory:

# scp -rp /mnt/hda5/home/carla 192.168.1.5:/home/carla/tmp




==============================================================
==============================================================


SSH quickstart

What, you have no ssh server? If you really do not yet have ssh installed, here is a quick-start guide to running SSH. But before using it for even routine remote administration tasks, you should study ssh in more depth. Note also that there have been a number of important security patches issued recently.

OpenSSH comes with all major Linux distributions, and yours should already have it. (To find out, type locate sshd.) If not, download and install it. It doesn't need to be on a special machine; any Linux PC can run SSH. Start it up like so:

# /etc/init.d/ssh start

Then, all you need is for the same user to have accounts on both machines. Using root is easiest, but potentially dangerous. And, of course, you can create user accounts on Knoppix as needed, with useradd and passwd. Then run the scp command as in the example above, and there you go.

The first time you connect, you'll get a "The authenticity of host X can't be established...are you sure you want to continue connecting?" message. Answer "yes." It will ask for the root password of the SSH server, and then you're home free. To move files as a non-root user:

# scp -rp /mnt/hda5/home/carla carla@192.168.1.5:/home/carla/tmp



==============================================================
==============================================================


Open a root shell on the host system


This lets you operate on the host system, as though you were logged into it directly. Identify the partition the host system is on, then open a Knoppix root shell and mount it:

root@ttyp0[knoppix]# mount /dev/hda1 /mnt/hda1
root@ttyp0[knoppix]# chroot /mnt/hda1
root@Knoppix:/

0 comments: