Skip to content

Latest commit

 

History

1 Commit

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 

Repository files navigation

What is this?

A scoutfs metadata device dump tool, using qcow2 as the output format.

How does it work?

The tool understands basic metadata device block layout and reads blocks that are interesting, omitting (sparse) blocks that are not.

The blocks dumped are blocks that are not listed as freed, which is in most cases, all the relevant blocks that the filesystem uses to describe all the metadata. This also includes the data allocator blocks.

Any block that isn't marked as free is dumped, even if it's not reachable through any of the filesystem structures. These leaked blocks are interesting from a forensic perspective, at best.

Blocks are compressed in parallel to make sure we're reading at line rates as much as possible, and stream out to disk. IO uses io_uring which may be disabled on RHEL platforms. The sysctl command to enable it will be shown if that is detected.

How do I use it?

From the project root, one can just run:

    cargo run <META_DEV> <OUT>

To build a binary, use:

    cargo build --release

To run the program, you generally would use it as follows:

    sudo ./scoutfs-dump /dev/<blkdev> /path/to/out.qcow2

Anything else?

This code is licensed under the GPL-2.0 license. The qcow2 rust code is at https://github.com/ublk-org/qcow2-rs.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages