Welcome to the most active Linux Forum on the web.
Go Back > Forums > Linux Forums > Linux - Hardware
User Name
Linux - Hardware This forum is for Hardware issues.
Having trouble installing a piece of hardware? Want to know if that peripheral is compatible with Linux?


  Search this Thread
Old 09-20-2006, 10:33 AM   #1
LQ Newbie
Registered: Nov 2003
Location: Ottawa, Canada
Distribution: Debian
Posts: 10

Rep: Reputation: 0
How to back up files off a failing hard drive?

Hello everyone. I have a 120GB drive (formatted with reiserfs) that is in the process of dying. I get strange errors (usually involving DriveNotReady and hda_dma) on the screen, and each new badblocks scan gives me more failed sectors, so I know the drive is on its way out.

I am trying to replace it with a new 250GB drive. I tried to use GNU parted to clone the drive, but the I/O errors prevent it from working. So, I'm trying to just copy as much of the failing hard drive's data as I can to the new one.

I'm currently using system rescue CD to boot the system. I have the old hard drive (/dev/hdb2) mounted on /mnt/temp2, and the new (/dev/hda2) mounted on /mnt/temp1.

I started with trying to use tar:

cd /mnt/temp2; tar cf - * (cd /mnt/temp1; tar xvpf -)
but that got through only about 30GB of the 110GB of data on the drive before it encountered some bad sectors and stopped. Further research (mostly here on forums) suggests that rsync might be able to do the same thing and skip all the already-transferred files (which would be nice, but is not required):

rsync -avlH --progress /mnt/temp2 /mnt/temp1
but I'm afraid that will also fail once it starts encountering I/O errors. I could try using find /mnt/temp2 -exec to start a separate instance of rsync for each file/directory/link it encounters, but that seems massively inefficient.

Can anyone suggest a method of copying the files from the failing hard drive to the new hard drive that
- will preserve all time/permission/owner/etc. metadata
- will not stall on I/O errors but will try to copy as many files as it can, and
- will give me a list of all files that had problems so I can concentrate on trying to recover those specific files?

I don't mind erasing those 30GB of files and starting over, but I would like to stress the drive as little as possible until I've gotten the data off of it.

Old 09-20-2006, 09:36 PM   #2
David the H.
Bash Guru
Registered: Jun 2004
Location: Osaka, Japan
Distribution: Arch + Xfce
Posts: 6,852

Rep: Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037
Does the system rescue CD come with ddrescue? If so, you can use it to copy the drive to a disk image. Unlike the regular dd command, ddrescue will do it's best to rescue bad blocks. If you can get a clean disk image copied, you can recover your actual data from there.
Old 09-22-2006, 09:03 AM   #3
LQ Newbie
Registered: Nov 2003
Location: Ottawa, Canada
Distribution: Debian
Posts: 10

Original Poster
Rep: Reputation: 0
Thumbs up ddrescue appears to be working well

Neither System Rescue CD nor Knoppix contain ddrescue (although both contain dd_rescue.) (There is a post on the System Rescue CD forums suggesting the inclusion of ddrescue, so it might be there eventually.) Knoppix has enough build tools that I was able to download the source from the ddrescue homepage and build it easily.

I am following the instructions I found on the TestDisk wiki, which are as follows:

# first, grab most of the error-free areas in a hurry:
ddrescue -B -n /dev/old_disk /dev/new_disk rescued.log
# then try to recover as much of the dicy areas as possible:
ddrescue -B -r 1 /dev/old_disk /dev/new_disk rescued.log
The first pass went through fine, the second is taking much longer. (I should note that I am getting the data from /dev/hdb2 directly, but writing to an image file on [mounted] /dev/hda2.) I'll post again with the results when it's done.
Old 09-25-2006, 03:11 PM   #4
LQ Newbie
Registered: Nov 2003
Location: Ottawa, Canada
Distribution: Debian
Posts: 10

Original Poster
Rep: Reputation: 0
ddrescue appears to have done the trick

The ddrescue appears to have pulled as much of the old, failing HD as can be -- I now have a 111GB image file on the new HD. It apparently encountered over 1600 errors doing the more in-depth scan, and the logfile is over 5kB, so it definitely did not go flawlessly.

Now, the difficult part -- trying to turn the logfile into a coherent list of files that are corrupted beyond recovery. If there are no irreplaceable files in that list, I can just restore the image, reinstall some applications, and be on my way.

A search of the bug-ddrescue list shows I might need a Perl script called '', but I'll have to request that from the list.
Old 09-26-2006, 09:59 PM   #5
LQ Newbie
Registered: Nov 2005
Location: Cary, NC USA
Distribution: Scientific Linux 6.1, Scientific Linux 7, Ubuntu, Parted Magic; formerly Mandrake 10.1, etc.
Posts: 7

Rep: Reputation: 0

You can get,,,, and a lot of other ddrescue-related Perl scripts
by downloading them from my server, here:

www dot burtonsys dot com slash download slash

(Sorry, I've been a "member" here for nearly a year, but this
annoying web site still won't let me post URLs, so change
" dot " to "." and change " slash " to "/" to turn the above
into a usable URL.)

First, I recommend that you look closely at the ddrescue
logfile. One sector is 0x200 bytes. So if the "-" status
logfile entries are all multiples of 0x1000 then what you
are seeing is the result of whole cluster at-a-time reads
failing. You can probably use a "raw" device to get ddrescue
to read individual sectors, which will reduce the number
of bad sectors considerably. However, use of raw devices
depends very much on what OS version you are running, which
makes it difficult to tell you just what commands are

If your hard disk drive is not in NTFS format, then I can't
offer much help identifying the damaged files. But if your
hard disk drive is in NTFS format, then here's what I would
do if I were you:

1) Copy the entire rescued disk image to a scratch drive.

2) Save a copy of the partition table, like this:
fdisk -lu drive.ima >fdisk-lu_output.txt
fdisk -lu /dev/hdd >fdisk-lu_output.txt
(or whatever)

2) Use (formerly called to generate a .bat
script of 'nfi' commands from the ddrescue logfile. Call the .bat
script "nficmds.bat":
perl -w nficmds.bat - fdisk-lu_output.txt drive.log

or if you used SpinRite (probably via
perl -w nficmds.bat SPIN_LOG.3 fdisk-lu_output.txt log_before_SR log_after_SR
SPIN_LOG.3 is the spinrite log file (extension varies),
log_before_SR is the ddrescue logfile saved before running SpinRite,
log_after_SR is the ddrescue logfile created after running SpinRite

3) Copy the nficmds.bat file to a thumb drive or diskette.

3.1) If you don't already have Microsoft's nfi ("NTFS File
Sector Information Utility") then get it, too:

www dot google dot com slash search?

4) Attach the scratch drive to a Windows computer as a 2nd
drive ("E:" for this example), and start the computer.

Do NOT let Windows check the drive during startup, because
if you do then you won't get to capture the list of file names
that it mentions when checking the drive.

5) If the drive letter doesn't match the drive letter in
nficmds.bat, then edit nficmds.bat and fix the drive letters.

6) (This step is optional; if you get tired of acknowledging
the pop-up boxes then you can skip steps 6 and 7.)

Run nficmds.bat on the Windows computer, redirecting the
output into a text file:

nficmds.bat >nfioutput.txt

7) Process nfioutput.txt using, to produced a
"damaged files report," and various other reports:

perl -w -f -d -r -i -u nfioutput.txt

8) In a Windows XP or Win2000 command-prompt window do:

chkdsk /f E: >c:\errors1.log.txt

(c:\errors1.log.txt is effectively another damaged files report.)

9a & 9b) Save the output files produced in steps 6 and 7. Then
repeat steps 6 and 7. (Because of the chkdsk you did in step 8
nfi is less likely to produce pop-up messages which you must

10) Your (not necessarily complete) list of damaged files is
the combined list of files found in steps 7, 8, and 9b.

11) It is also possible to use the output of
to "get smarter" with ddrescue. For example, it produces a
free-space sector list, in ddrescue logfile format, called
unimportant.log, which you can merge into the regular ddrescue
logfile, to make a subsequent ddrescue run pretend that those
unused sectors were already rescued, so that you don't waste
time trying to recover them.

BTW, that's why you copied the recovered disk or image to a
scratch drive in step 1 -- because Windows changes the drive
when it examines it (and drastically changes it when doing
chkdsk!), which would prevents you from later restarting the
rescue process using ddrescue. But since you only let Windows
touch a scratch copy, Windows can't mess up the original.

To merge the "unimportant.log" file (free-space sector list)
produced by, you can use the script
("DDRescue LOGfile logical .OR.").

Note: one trick that I've done is to edit nfioutput.txt before
processing it with, to make it look like some
files that I don't care about, e.g., hiberfil.sys and
swapfile.sys, are part of the NTFS partition's free-space.
Then, after merges unimportant.log, ddrescue's
logfile will indicate that those other unimportant files are
already recovered, so ddrescue won't waste time trying to
recover them.

12 & on) Then you can resume the ddrescue recovery process,
perhaps just targetting the most important disk areas, before
going back to step 1.

For lots more instructions, see the comments in the various
Perl scripts.

dave340 at burtonsys dot com but please no spam

P.S. -- If you know of (or write) the equivalent of 'nfi' for
FAT32 (or other file systems), or to run under Linux instead
of under Windows, then please tell me!!
Old 09-26-2006, 10:46 PM   #6
David the H.
Bash Guru
Registered: Jun 2004
Location: Osaka, Japan
Distribution: Arch + Xfce
Posts: 6,852

Rep: Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037Reputation: 2037
You should be able to mount the disk image using the "-loop" loopback option and manually check or rescue important files. Although with 100GB+ of data that might be a bit impractical.

ncdave, you need to have 5 posts before you're allowed to link to other pages. It's an anti-spam defense.
Old 10-05-2006, 01:25 PM   #7
LQ Newbie
Registered: Nov 2003
Location: Ottawa, Canada
Distribution: Debian
Posts: 10

Original Poster
Rep: Reputation: 0
Fixed up now

The script told me that the 1688 errors only totaled about 800kB of lost data, but didn't give me any way to convert the sector numbers to filenames.

I posted[1] on the ddrescue mailing list to ask how to do the conversion, and was referred to a HOWTO[2] with instructions. Unfortunately, the HOWTO is for ext2/ext3 filesystems and the debugfs command used is specific to ext2/ext3. I tried asking[3] the reiserfs mailing list, but found that there is no equivalent command for reiserfs.

I ended up following the instructions[4] in a previous post to the reiserfs list, and ran find /mnt/old_disk -type f -exec cat {} > /dev/null \; . This found only 3 files had problems with reading & writing to /dev/null (two of which were in my Firefox cache, so really no problems there).

I copied the files out of the disk image using the original tar command, and deleted the 3 files. One quick re-LILO later, and the system boot and is pretty much running fine. I haven't done a thorough system check yet, but thus far it seems OK.

Hopefully this thread will be of use to anyone else who has a disk failure on a reiserfs system.



backup, drive, failing, hard

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Does this mean a physically failing hard drive? whysyn Linux - Hardware 9 07-20-2006 07:27 PM
my hard drive or my optical drive is failing fatblueduck Linux - Hardware 7 01-28-2006 08:30 PM
hard drive failing, how can I create an image of my drive? oily_rags SUSE / openSUSE 6 07-07-2005 02:19 PM
Is my hard drive failing? HGeneAnthony General 1 11-23-2004 01:37 AM
Failing hard drive--need to copy Phathead Linux - Hardware 2 03-10-2004 12:59 PM > Forums > Linux Forums > Linux - Hardware

All times are GMT -5. The time now is 03:48 AM.

Main Menu
Write for LQ is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration