Tip: Checking TrueCrypt-Encrypted Drives

on 2013-05-05 automatically translated

The problem: by default, the operating system does not perform filesystem checks on TrueCrypt-encrypted partitions.

Filesystem checks are used to repair errors that may have occurred in the filesystem structure, for example due to system crashes at an inopportune moment. There are essentially two strategies for repairing or preventing these errors.

The first strategy relies on so-called transaction-based filesystems. Before every write operation, the write operation that is about to follow is recorded in a central location. The actual write operation is then performed, after which the note is removed. If the system crashes during the write operation, the note remains. The next time the filesystem is mounted, the note is used in an attempt to repair the error. With TrueCrypt drives, however, this can sometimes go wrong because the actual encryption is still in between and effectively acts as a buffer.

Nevertheless, there is a second strategy. After every X mounts (usually every 30th time), this performs a complete filesystem check at system startup, before the drive is mounted.

This complete check cannot take place on TrueCrypt systems, however, because they are not decrypted until far too late. That means you have to do it manually.

TrueCrypt-encrypted partitions work as follows: the /sdx9 partition is completely encrypted, meaning that the filesystem is encrypted as well. TrueCrypt translates this encrypted partition and provides an unencrypted partition at /dev/mapper/truecrypt1. Only this partition behaves like the other unencrypted partitions, such as /sda1. The /dev/mapper/truecrypt1 partition is then mounted in any directory using standard Linux tools, for example /home/ich/crypt.

To check the partition, you first have to make it available, i.e. save all open documents and preferably close the programs using them. Then unmount it with the umount command:

sudo umount /dev/mapper/truecrypt1

The check then works as follows:

sudo fsck /dev/mapper/truecrypt1

If everything goes smoothly, you will see a message similar to mine:

e2fsck 1.42.5 (29-Jul-2012)
Pool was mounted 130 times without being checked; check forced.
Pass 1: Checking inodes, blocks, and sizes
Pass 2: Checking directory structure
Pass 3: Checking directory connectivity
Pass 4: Checking reference counts
Pass 5: Checking group summary information
Pool: 96390/8323072 files (12.1% non-contiguous), 20707462/33280583 blocks

Afterwards, mount the partition again:

sudo mount /dev/mapper/truecrypt1 /home/ich/crypt

Anyone who mounted the partition with special parameters probably knows what they are doing and therefore does not need any further explanation.

In this case, everything went well for me. When I performed my last check a few years earlier, however, things looked different. At that time, fsck found around 100 errors, which it fortunately repaired automatically.

To avoid filesystem errors, you should also follow this tip:

When the system freezes, you should give Linux the opportunity to write all cached data to the hard drive instead of simply cutting the power by holding down the power button for five seconds. In most cases, the kernel is still quite responsive, even if that is not apparent from the outside.

To perform the so-called emergency sync, use the SysRq shortcuts:

Hold down Alt + Print Screen, then press R, E, I, S, U, B in sequence

R: Disable keyboard input

E, I: Send SIGTERM and SIGKILL to all processes, i.e. terminate all programs

S: Emergency sync, i.e. write all buffered data to the hard drive

U, B: Unmount all drives and then shut down

If you would like to try the key combination, you can safely use just the S part:

To see the kernel message, it is best to switch to a shell:

Ctrl + Alt + F1

Then perform the sync:

Alt + Print Screen + S

Then admire the message displayed, watch the hard-drive light while it is writing, and use

Ctrl + Alt + F7

to switch back to the graphical part of your Linux system.

∎

Comments