help with ddrescue and ddrutility

eli_singer

n00b
Joined
Jul 7, 2013
Messages
17
Hi there,
i'm trying to rescue data from a few drives.
after consulting i was referred to ddrescue for cloning and than for ddrutility for finding out which files are messed up.
i have no Linux experience at all, i'm on Windows. i am trying to learn but there is so much information that i need some guidance.

my plan is to use Ubuntu Rescue Remix 12.04 (current version) to boot from a CD or a usb drive, and then use ddrescue that is supposed to be on it to clone the drive.
i read this: http://keystoneisit.blogspot.co.il/2011/08/clone-failing-windows-hard-disk-with.html
which explains what to do but i'm still confused, mostly about the syntax. there's this:
'sudo ddrescue -v -r 3 /dev/sda /dev/sdb logfile'
according to ddrescue manual, the '-v' prints the version number of ddrescue on the standard output and exit. i'm not sure why i need this and i want to make sure that this is correct.
'-r 3' means it will try to read bad sectors 3 times?

assuming this works, i now have a log file somewhere. but where is it? if i'm doing this all from a CD than it can't even write to it... should i make a bootable USB drive for this? where will it save it then?

next i need to use ddrutility which i'm not sure how to use. i have the latest version of it. can i add it to the Ubuntu Rescue Remix image somehow? i understand that the current release of Ubuntu Rescue Remix has an old version of it. if not, how should i use it? and how should i point it to the logfile?
further more, i am unsure of the syntax to use with this tool. any help here would be much appreciated.

thanks,

Eli
 
There is a difference between '-v' and '-V' lower/capital. Lower is enables verbose output, capital prints version and exists. Yeah -r is is how many tries on when it gets a read error.

Be sure you know which device is when when using dd, you can easily write over the wrong drive. Don't just blindly use /dev/sda /dev/sdb, you need to replace that with your actual drives.

When you open terminal you can run 'pwd' and it'll print your current directory, probably like /home/someuser. If you run ddrescue with 'logfile' it'l create a file 'logfile' in your currect directory, so /home/someuser/logfile. You can replace logfile iwth '/some/full/path/and/file.name' to put log where ever you want.

If you are booting off a CD you if you write to /home the writes are just stored in memory, soon as you reboot they're gone. You have to either copy logfile to a real drive somewhere or open up Firefox or whatever the LiveCD has (I assume it'll give you a desktop) and email the file to yourself.

You can't do anything bad unless you get the hdds backwards, so that is only thing to be super careful about.

It might be easiest to unplug the SATA cables to HDDs, boot to LiveCD, then run 'ls /dev/sd?' to list devices.. if you are booting off a usbkey you might see sda, that'll then be the usbkey. Plug in cable to one of the HDDs and after a few seconds run 'ls /dev/sd?' again and you should see something new, that'll be the HDD you just plugged in. And then finally plug in the other HDD and repeat. You'll then know which device is which.

Alternatively if your hdds are different makes/models you can also look at:
ls -l /dev/disk/by-id/



When you run ddrescue /devs/sdX /dev/sdY, X is the old hdd you want to get data off, Y is the new hdd you are copying stuff to.
 
Also, it is often a good idea to do a two-pass ddrescue run. First a quick pass, then a -r 3 pass. Something like this (obviously change the devices and logfile location to match your system):

Code:
# ddrescue --force --no-split /dev/sda /dev/sdb /root/logfile
# ddrescue --force --direct --max-retries=3 /dev/sda /dev/sdb /root/logfile
 
Before you go off with these utilities, can you elaborate what the problem with the original drives or filesystems is?

In general a plain dd often does well enough unless you want to do something specific about hard read errors other than just replacing bad sectors with zeros.
 
In general a plain dd often does well enough unless you want to do something specific about hard read errors other than just replacing bad sectors with zeros.

Bad advice.

If there is any suspicion that there are bad sectors, then ddrescue is a much better choice than dd. With dd, the read could get stuck on a series of bad sectors and keep retrying while the HDD dies. ddrescue is much more likely to skip over the series of bad sectors and continue rescuing data.
 
Bad advice.

If there is any suspicion that there are bad sectors, then ddrescue is a much better choice than dd. With dd, the read could get stuck on a series of bad sectors and keep retrying while the HDD dies. ddrescue is much more likely to skip over the series of bad sectors and continue rescuing data.

A decade ago or so I was burned by this mistake while trying to recover a disk for a friend. Although back then I did not know about ddrescue.
 
thank you very much for all the useful information.

my problem is a messed up RAID 10 array of 4 drives. i want to backup all the drives before trying to fix the array, hence the need for ddrescue.

what does "force --no-split" command means exactly? and why not try the r- 3 command from the beginning? if there are't any bad sectors than it should't linger on them right?

the hot plug advice for identifying the drives sounds pretty fail-safe, i think i'll go for that.

i still don't know how to use ddrutility, any help here would be great.

and again, thank you very much for your answers, i wouldn't have a clue what to do without a supporting community. it's a great time we live in :)

Eli
 
If you do not think there are any bad sectors, what do you think caused your array to be "messed up", and exactly how is it "messed up"?

You should read the ddrescue manual and tutorial. If you still do not understand after reading them, ask your questions again.

ddrutility is a more obscure program which I have not used. It is not clear to me that it will be any help to you. But no need to worry about that until later.
 
i had drives breaking from the array repeatedly until i got 3 out of 4 drives who broke from the array and it started to trey and rebuild them.
i don't know for sure that there are any bad sectors but i very well might have.
it could also be a problem with my RAID Controller.

in any case, i think that backing it all up is a good idea before trying to do anything else with the drives.

i did read ddrescue manual but still, your replies made it more clear.
i could't find a manual for ddrutility and that's why i'm asking help on that also. i believe that when i'll do the backup with ddrescue i'll need to know which files are damaged, and that's what ddrutility is suppose to do isn't it?
if there is a better alternative i'd be happy to know about it.

Eli
 
You were running a hardware RAID 10 on Windows? With what hardware?

I'm assuming you have already disconnected the power and data cables to the HDDs. If not, you should. Don't do anything to change or degrade the original drives until you have gotten as much data as possible off them.

Beyond that, you need a much better understanding of what happened. Having 3 of 4 drives drop out of the array likely indicates that it is not the drives themselves that are bad. Could be your RAID card, or PSU related, or cable issues, or motherboard issues. Or just some configuration got changed inadvertently. Whatever it is, I would not connect the drives again to the same system unless you are sure you know the cause of the problem.

Ideally, you should use a separate, known-good computer to clone the HDDs. If you have 4 spare HDDs available, then using ddrescue to clone as much of the 4 drives as possible is a good idea. Just use the commands I already mentioned for each drive (but be sure to change the drive letters and log location as required)
 
i'm using IBM m1050 RAID Controller, i disconnected everything and i want to do all of the mentioned actions on another system.
it's not the PSU (swithed it to a new one during that period).
i also think that the drives are probably ok which kind of reassures me that i could still get the data back...

i also have a lot of the data backed up on different drives so even if i'll get some bad files, if i can identify them, i hope i could restore them or just copy them from my backed-up version given it's from the data that is backed up...

i do have 4 drives to copy everything into.

Eli
 
ok, so here's an update!

i ran ddrescue, all 4 drives are now backed up, 0 errors. that's a good sign.
i connected all the drives to the machine, not through the controller of course, and i ran RecliaMe Free RAID Recovery tool on them. this is what i got:

ReclaiMeFreeInstructionsforR-Studio_zps9bf41904.jpg
[/URL][/IMG]


the full text there says:

"This is a plain-text general description of the reconstructed array layout.

The array type is RAID0 (also called Stripe Set).
The array consists of 2 disks.

The disks are ordered as follows:
#00: Disk 2 - ATA Hitachi HDS72404, Serial number 1311PAG641PJ, \\.\PhysicalDrive2
#01: Disk 4 - ATA Hitachi HDS72404, Serial number 1331PAGYNHGS, \\.\PhysicalDrive4

Block size is 64.0 KB , same as 128 sectors.
The data starts at sector (LBA) 0 (this is often called "offset" or "start offset").


These instructions are provided for R-Studio version 5.1
1. Launch R-Studio

2. On the toolbar, click "Create Virtual RAID". Then, select "Create Virtual Block RAID" from the dropdown menu.

3. Right click the disk list on the right, select "Add Disk 2 - ATA Hitachi HDS72404 : 1311PAG641PJ" from the pop-up menu.
4. Right click the disk list on the right, select "Add Disk 4 - ATA Hitachi HDS72404 : 1331PAGYNHGS" from the pop-up menu.


5. On the right side of the R-Studio window, set "RAID type" to "RAID0 (Stripe set)".
6. Below that, set "Block size" to "64 KB".
7. In the "Parents" table, enter "0 Sectors" as "Offset" in all rows.

8. Below the RAID diagram, click "Apply".
9. On the left panel, "Virtual Block RAID 1" is the newly created RAID. Double click it to start recovery.
[/I][/I]


well, i got stuck on number 3 (underlined). the problem is that R-Studio doesn't recognize any of the drives! it looks like this:

R-Studionodisks_zpse9012140.jpg
[/URL][/IMG]

so any ideas as to how to make r-studio see the drives? or maybe there's another way to do this?

Eli
 
Back
Top