A scoutfs metadata device dump tool, using qcow2 as the output format.
The tool understands basic metadata device block layout and reads blocks that are interesting, omitting (sparse) blocks that are not.
The blocks dumped are blocks that are not listed as freed, which is in most cases, all the relevant blocks that the filesystem uses to describe all the metadata. This also includes the data allocator blocks.
Any block that isn't marked as free is dumped, even if it's not reachable through any of the filesystem structures. These leaked blocks are interesting from a forensic perspective, at best.
Blocks are compressed in parallel to make sure we're reading at line rates as much as possible, and stream out to disk. IO uses io_uring which may be disabled on RHEL platforms. The sysctl command to enable it will be shown if that is detected.
From the project root, one can just run:
cargo run <META_DEV> <OUT>
To build a binary, use:
cargo build --release
To run the program, you generally would use it as follows:
sudo ./scoutfs-dump /dev/<blkdev> /path/to/out.qcow2
This code is licensed under the GPL-2.0 license. The qcow2 rust code is at https://github.com/ublk-org/qcow2-rs.