* Re: [linux-lvm] Lost partition table --> Lost 4th PV partition on disk - how to find the partition bounderies
2006-10-29 11:46 [linux-lvm] Lost partition table --> Lost 4th PV partition on disk - how to find the partition bounderies gklima
@ 2006-10-29 15:07 ` gklima
2006-10-29 19:06 ` Luca Berra
2006-10-30 11:13 ` Lars Ellenberg
2 siblings, 0 replies; 6+ messages in thread
From: gklima @ 2006-10-29 15:07 UTC (permalink / raw)
To: LVM general discussion and development
Tried gpart -f -n s
--> force full diskscan + address by sectors
gave me the following after a long time waiting:
dev(/dev/hda) mss(512) chs(12161/255/63)(LBA) #s(195366465) size(95393mb)
Primary partition(1)
type: 000(0x00)(unused)
size: 0mb #s(0) s(0-0)
chs: (0/0/0)-(0/0/0)d (0/0/0)-(0/0/0)r
hex: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Primary partition(2)
type: 000(0x00)(unused)
size: 0mb #s(0) s(0-0)
chs: (0/0/0)-(0/0/0)d (0/0/0)-(0/0/0)r
hex: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Primary partition(3)
type: 000(0x00)(unused)
size: 0mb #s(0) s(0-0)
chs: (0/0/0)-(0/0/0)d (0/0/0)-(0/0/0)r
hex: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Primary partition(4)
type: 000(0x00)(unused)
size: 0mb #s(0) s(0-0)
chs: (0/0/0)-(0/0/0)d (0/0/0)-(0/0/0)r
hex: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Begin scan...
Possible partition(Windows NT/W2K FS), size(14001mb), offset(0mb)
type: 007(0x07)(OS/2 HPFS, NTFS, QNX or Advanced UNIX)
size: 14001mb #s(28675960) s(63-28676022)
chs: (0/1/1)-(1023/254/63)d (0/1/1)-(1784/254/61)r
hex: 00 01 01 00 07 FE FF FF 3F 00 00 00 78 8F B5 01
Possible partition(Windows NT/W2K FS), size(14001mb), offset(14001mb)
type: 007(0x07)(OS/2 HPFS, NTFS, QNX or Advanced UNIX)
size: 14001mb #s(28675960) s(28676024-57351983)
chs: (1023/254/63)-(1023/254/63)d (1784/254/63)-(3569/253/60)r
hex: 00 FE FF FF 07 FE FF FF B8 8F B5 01 78 8F B5 01
Possible partition(Windows NT/W2K FS), size(15267mb), offset(15267mb)
type: 007(0x07)(OS/2 HPFS, NTFS, QNX or Advanced UNIX)
size: 15267mb #s(31268096) s(31268159-62536254)
chs: (1023/254/63)-(1023/254/63)d (1946/89/63)-(3892/178/61)r
hex: 00 FE FF FF 07 FE FF FF 3F 1D DD 01 00 1D DD 01
Possible partition(Windows NT/W2K FS), size(9730mb), offset(15267mb)
type: 007(0x07)(OS/2 HPFS, NTFS, QNX or Advanced UNIX)
size: 9730mb #s(19928152) s(31268160-51196311)
chs: (1023/254/63)-(1023/254/63)d (1946/90/1)-(3186/209/55)r
hex: 00 FE FF FF 07 FE FF FF 40 1D DD 01 58 14 30 01
Possible partition(Windows NT/W2K FS), size(9730mb), offset(24998mb)
type: 007(0x07)(OS/2 HPFS, NTFS, QNX or Advanced UNIX)
size: 9730mb #s(19928152) s(51196319-71124470)
chs: (1023/254/63)-(1023/254/63)d (3186/209/63)-(4427/74/54)r
hex: 00 FE FF FF 07 FE FF FF 9F 31 0D 03 58 14 30 01
Possible partition(Linux ext2), size(36mb), offset(24998mb)
type: 131(0x83)(Linux ext2 filesystem)
size: 36mb #s(75600) s(51196320-51271919)
chs: (1023/254/63)-(1023/254/63)d (3186/210/1)-(3191/134/63)r
hex: 00 FE FF FF 83 FE FF FF A0 31 0D 03 50 27 01 00
Possible partition(Linux swap), size(1500mb), offset(26059mb)
type: 130(0x82)(Linux swap or Solaris/x86)
size: 1500mb #s(3072000) s(53369456-56441455)
chs: (1023/254/63)-(1023/254/63)d (3322/24/15)-(3513/81/8)r
hex: 00 FE FF FF 82 FE FF FF 70 5A 2E 03 00 E0 2E 00
End scan.
Checking partitions...
* Warning: Discarded 5 overlapping partition guesses.
Partition(OS/2 HPFS, NTFS, QNX or Advanced UNIX): primary
type: 007(0x07)(OS/2 HPFS, NTFS, QNX or Advanced UNIX)
size: 14001mb #s(28675960) s(63-28676022)
chs: (0/1/1)-(1023/254/63)d (0/1/1)-(1784/254/61)r
hex: 00 01 01 00 07 FE FF FF 3F 00 00 00 78 8F B5 01
Partition(OS/2 HPFS, NTFS, QNX or Advanced UNIX): primary
type: 007(0x07)(OS/2 HPFS, NTFS, QNX or Advanced UNIX)
size: 14001mb #s(28675960) s(28676024-57351983)
chs: (1023/254/63)-(1023/254/63)d (1784/254/63)-(3569/253/60)r
hex: 00 FE FF FF 07 FE FF FF B8 8F B5 01 78 8F B5 01
Ok.
Guessed primary partition table:
Primary partition(1)
type: 007(0x07)(OS/2 HPFS, NTFS, QNX or Advanced UNIX)
size: 14001mb #s(28675960) s(63-28676022)
chs: (0/1/1)-(1023/254/63)d (0/1/1)-(1784/254/61)r
hex: 00 01 01 00 07 FE FF FF 3F 00 00 00 78 8F B5 01
Primary partition(2)
type: 007(0x07)(OS/2 HPFS, NTFS, QNX or Advanced UNIX)
size: 14001mb #s(28675960) s(28676024-57351983)
chs: (1023/254/63)-(1023/254/63)d (1784/254/63)-(3569/253/60)r
hex: 00 FE FF FF 07 FE FF FF B8 8F B5 01 78 8F B5 01
Primary partition(3)
type: 000(0x00)(unused)
size: 0mb #s(0) s(0-0)
chs: (0/0/0)-(0/0/0)d (0/0/0)-(0/0/0)r
hex: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
Primary partition(4)
type: 000(0x00)(unused)
size: 0mb #s(0) s(0-0)
chs: (0/0/0)-(0/0/0)d (0/0/0)-(0/0/0)r
hex: 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00
regards
georg
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [linux-lvm] Lost partition table --> Lost 4th PV partition on disk - how to find the partition bounderies
2006-10-29 11:46 [linux-lvm] Lost partition table --> Lost 4th PV partition on disk - how to find the partition bounderies gklima
2006-10-29 15:07 ` gklima
@ 2006-10-29 19:06 ` Luca Berra
2006-10-29 19:33 ` gklima
2006-10-30 11:13 ` Lars Ellenberg
2 siblings, 1 reply; 6+ messages in thread
From: Luca Berra @ 2006-10-29 19:06 UTC (permalink / raw)
To: linux-lvm
On Sun, Oct 29, 2006 at 12:46:15PM +0100, gklima@cosy.sbg.ac.at wrote:
>Hi!
>
>I've a laptop with root lvm2 and lost my partitioning table (all zeros).
>But the data on the disk (4th partition) should be fine since I've only
>messed with the primary patition table.
i had some success in the past with
http://www.cgsecurity.org/wiki/TestDisk
--
Luca Berra -- bluca@comedia.it
Communication Media & Services S.r.l.
/"\
\ / ASCII RIBBON CAMPAIGN
X AGAINST HTML MAIL
/ \
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [linux-lvm] Lost partition table --> Lost 4th PV partition on disk - how to find the partition bounderies
2006-10-29 11:46 [linux-lvm] Lost partition table --> Lost 4th PV partition on disk - how to find the partition bounderies gklima
2006-10-29 15:07 ` gklima
2006-10-29 19:06 ` Luca Berra
@ 2006-10-30 11:13 ` Lars Ellenberg
2006-10-30 21:49 ` gklima
2 siblings, 1 reply; 6+ messages in thread
From: Lars Ellenberg @ 2006-10-30 11:13 UTC (permalink / raw)
To: LVM general discussion and development
/ 2006-10-29 12:46:15 +0100
\ gklima@cosy.sbg.ac.at:
> the layout of the disk was/is as follows:
> 1) ntfs ~10G
> 2) ntfs ~10G
> 3) ext3 36mb linux-boot
> 4) PV of lvm2 which had 72046800 blocks as of /proc/partition the last
> time lvm2 worked
>
> layout by fdisk after the win xp partitoning and ghost coping with a still
> working lvm2 PV on partition 4
>
> 1) 1-1703
> 2) 1704-3186
> 3) 3187-3192
> 4) 3192-12161
which is cylinders.
> The VG is called "vg"
> and the approximately layout is as follows:
>
> root lv 500M (bin, sbin, etc, lib, ......)
> swap lv 1500M encrypted
> and then var usr opt distfiles portage and so on.....
> 255 heads, 63 sectors/track, 12161 cylinders, total 195371568 sectors
> Possible partition(Linux ext2), size(36mb), offset(24998mb)
> type: 131(0x83)(Linux ext2 filesystem)
> size: 36mb #s(75600) s(51196320-51271919)
> chs: (1023/254/63)-(1023/254/63)d (3186/210/1)-(3191/134/63)r
> hex: 00 FE FF FF 83 FE FF FF A0 31 0D 03 50 27 01 00
so, here we are: this is obviously your "linux-boot".
the next recognized sector appears to be from swap.
so we know:
51271919 end sector of "linux-boot"
which is consistent with your remembered cylinders above:
> 4) 3192-12161
to find the exact sector offset of your pv,
have a knoppix (or some other live-cd) handy.
do
perl -e '$s= 51271919; $o = 512*$s;
sysseek(STDIN,$o,0) = $o or die "seek: $!\n";
while(1) {
sysread STDIN,$_,512;
last if /^.{24}LVM2/;
last if ++$s > 1000000;
}
print "start sector of pv appears to be",$s-1,"\n";
'
use
sfdisk -d /dev/hda > dummy
vi dummy
sfdisk -uS /dev/hda < dummy
to put some partition table back in place.
dummy would look similar to
-----
# partition table of /dev/hda
unit: sectors
/dev/hda1 : start= 63, size= 28675960, Id= 7, bootable
/dev/hda2 : start= 31268160, size= 19928152, Id= 7
/dev/hda3 : start= 51196320, size= 75600, Id=83
/dev/hda4 : start= 51277968, size=144093600, Id=8e
-----
I inserted the values that your "big scan" found out,
but decided slightly different what to discard because of overlap,
and added the information you gave about
> 4) PV of lvm2 which had 72046800 blocks as of /proc/partition the last
> time lvm2 worked
(total sectors 195371568 - 2*72046800 == 51277968), as it is consitent
with the offsets of the 36mb partition and the swap signature found by
the big scan as well as the additional context you provided.
hda1 and hda2 are likely slightly wrong,
as between those is some unused space.
hda3 is most likely correct, and hda4 would be your pv,
and my guess is that it is correct, too.
if the perl snipplet above confirms that
(start sector 51277968), go for it.
cheers.
--
: Lars Ellenberg Tel +43-1-8178292-55 :
: LINBIT Information Technologies GmbH Fax +43-1-8178292-82 :
: Schoenbrunner Str. 244, A-1120 Vienna/Europe http://www.linbit.com :
^ permalink raw reply [flat|nested] 6+ messages in thread* Re: [linux-lvm] Lost partition table --> Lost 4th PV partition on disk - how to find the partition bounderies
2006-10-30 11:13 ` Lars Ellenberg
@ 2006-10-30 21:49 ` gklima
0 siblings, 0 replies; 6+ messages in thread
From: gklima @ 2006-10-30 21:49 UTC (permalink / raw)
To: LVM general discussion and development
> /dev/hda4 : start= 51277968, size=144093600, Id=8e
I now found the correct starting sector: 51271920
The main clue I needed was the magic /^.{24}LVM2/, thanks for that!
and a friend of me who rewrote your code in python:
code by Michael Gschwanter:
#!/usr/bin/python
import re,sys
isLVM = re.compile("^.{24}LVM2") # This is how the Sector should look like
if __name__=="__main__":
args = sys.argv
device = args[1]
startSector = int(args[2])
howMuch = int(args[3])
endSector = startSector + howMuch
print "Searching for LVM2 on %s. From Sector %d to
%d"%(device,startSector,endSector)
dev = file(device,"r") # Read only, just for Security
dev.seek(startSector * 512)
t = 0
while t < howMuch:
sectorData = dev.read(512)
m = isLVM.search(sectorData)
if m:
print "We found the Start sector of the pv@%d\n"%(startSector+t)
break
t = t + 1
dev.close()
Usage: ./findlvm.py /dev/<deindevice> startSector maximumSectorsToTry
just used the output sector minus one!
Great thanks to all who tried and helped to save my data!!!
Georg
^ permalink raw reply [flat|nested] 6+ messages in thread