Database accidentally deleted with a bash scriptMonday morning mistake: sudo rm -rf --no-preserve-root /Accidentally formated external usb harddrive (500GB) with bootable iso (1GB), how can I recover my data?What is the difference between double and single square brackets in bash?Accidentally rm -rf /usr/* as root, what now?Damaged Disk with ESXi Data Store needs RecoveryHow to add a timestamp to bash script log?ZPOOL replace defective disk in exported poolHow to recover deleted root of linux system?Ubuntu OS recovery – accidentally deleted ld-linux-x86-64.so.2 from /lib64 folder in Ubuntu 14.04Restoring data after zfs destroySynology: How to restore data from an accidentally deleted volumeX (BTRFS)?
Some numbers are more equivalent than others
Reply 'no position' while the job posting is still there
Is a model fitted to data or is data fitted to a model?
Journal losing indexing services
Create all possible words using a set or letters
Is camera lens focus an exact point or a range?
Should I install hardwood flooring or cabinets first?
Can somebody explain Brexit in a few child-proof sentences?
Do varchar(max), nvarchar(max) and varbinary(max) columns affect select queries?
Is XSS in canonical link possible?
How do you respond to a colleague from another team when they're wrongly expecting that you'll help them?
Can we have a perfect cadence in a minor key?
How can "mimic phobia" be cured or prevented?
Schmidt decomposition - example
Python script not running correctly when launched with crontab
What is this type of notehead called?
MAXDOP Settings for SQL Server 2014
How do I repair my stair bannister?
Why has "pence" been used in this sentence, not "pences"?
How do we rationalize a person's sins being solely their own when we have traditions that blame entire nations for certain acts?
Open a doc from terminal, but not by its name
anything or something to eat
Question about alert, surprise, and crit failing
Can the Supreme Court overturn an impeachment?
Database accidentally deleted with a bash script
Monday morning mistake: sudo rm -rf --no-preserve-root /Accidentally formated external usb harddrive (500GB) with bootable iso (1GB), how can I recover my data?What is the difference between double and single square brackets in bash?Accidentally rm -rf /usr/* as root, what now?Damaged Disk with ESXi Data Store needs RecoveryHow to add a timestamp to bash script log?ZPOOL replace defective disk in exported poolHow to recover deleted root of linux system?Ubuntu OS recovery – accidentally deleted ld-linux-x86-64.so.2 from /lib64 folder in Ubuntu 14.04Restoring data after zfs destroySynology: How to restore data from an accidentally deleted volumeX (BTRFS)?
My developer committed a huge mistake and we cannot find our Mongo database anywhere in the server.
He logged into the server, and saved the following shell under ~/crontab/mongod_back.sh:

#!/bin/sh
DUMP=mongodump
OUT_DIR=/data/backup/mongod/tmp // 备份文件临时目录
TAR_DIR=/data/backup/mongod // 备份文件正式目录
DATE=`date +%Y_%m_%d_%H_%M_%S` // 备份文件将以备份对间保存
DB_USER=Guitang // 数库操作员
DB_PASS=qq■■■■■■■■■■■■■■■■■■■■■ // 数掘库操作员密码
DAYS=14 // 保留最新14天的份
TARBAK="mongod_bak_$DATE.tar.gz" // 备份文件命名格式
cd $OUT_DIR // 创建文件夹
rm -rf $OUT_DIR/* // 清空临时目录
mkdir -p $OUT_DIR/$DATE // 创建本次备份文件夹
$DUMP -d wecard -u $DB_USER -p $DB_PASS -o $OUT_DIR/$DATE // 执行备份命令
tar -zcvf $TAR_DIR/$TAR_BAK $OUT_DIR/$DATE // 将份文件打包放入正式
find $TAR_DIR/ -mtime +$DAYS -delete // 除14天前的旧备
And then he ran it and it outputted permission denied messages, so he pressed Ctrl+C. The server shut down automatically. He tried to restart it but got a grub error:

He contacted AliCloud, the engineer connected the disk to another working server so that he could check the disk. Looks like some folders are gone, including /data/ where the mongodb is!
- We don't understand how the script could destroy the disk including
/data/; - And of course, is it possible to get the
/data/back?
PS: He did not take snapshot of the disk before.
PS2: As people mention "backups" a lot, we have lots of users and data coming these 2 days, the purpose of this action was to backup them, then they turned out to be entirely deleted.
filesystems shell ubuntu-14.04 data-recovery disaster-recovery
add a comment |
My developer committed a huge mistake and we cannot find our Mongo database anywhere in the server.
He logged into the server, and saved the following shell under ~/crontab/mongod_back.sh:

#!/bin/sh
DUMP=mongodump
OUT_DIR=/data/backup/mongod/tmp // 备份文件临时目录
TAR_DIR=/data/backup/mongod // 备份文件正式目录
DATE=`date +%Y_%m_%d_%H_%M_%S` // 备份文件将以备份对间保存
DB_USER=Guitang // 数库操作员
DB_PASS=qq■■■■■■■■■■■■■■■■■■■■■ // 数掘库操作员密码
DAYS=14 // 保留最新14天的份
TARBAK="mongod_bak_$DATE.tar.gz" // 备份文件命名格式
cd $OUT_DIR // 创建文件夹
rm -rf $OUT_DIR/* // 清空临时目录
mkdir -p $OUT_DIR/$DATE // 创建本次备份文件夹
$DUMP -d wecard -u $DB_USER -p $DB_PASS -o $OUT_DIR/$DATE // 执行备份命令
tar -zcvf $TAR_DIR/$TAR_BAK $OUT_DIR/$DATE // 将份文件打包放入正式
find $TAR_DIR/ -mtime +$DAYS -delete // 除14天前的旧备
And then he ran it and it outputted permission denied messages, so he pressed Ctrl+C. The server shut down automatically. He tried to restart it but got a grub error:

He contacted AliCloud, the engineer connected the disk to another working server so that he could check the disk. Looks like some folders are gone, including /data/ where the mongodb is!
- We don't understand how the script could destroy the disk including
/data/; - And of course, is it possible to get the
/data/back?
PS: He did not take snapshot of the disk before.
PS2: As people mention "backups" a lot, we have lots of users and data coming these 2 days, the purpose of this action was to backup them, then they turned out to be entirely deleted.
filesystems shell ubuntu-14.04 data-recovery disaster-recovery
1
Your script has no error checking. If the linecd $OUT_DIRfails, it's going to delete everything in the current path, which may well be/. This is why you have backups - use them.
– Jenny D
8 hours ago
2
Possible duplicate of Monday morning mistake: sudo rm -rf --no-preserve-root /
– Jenny D
8 hours ago
He run the shell under~/crontab/, how couldrmorfind -deletedelete folders under/?
– SoftTimur
8 hours ago
Make a raw backup of the full hard disk before yo do anything, this will increase your low changes for data recovery
– Ferrybig
4 hours ago
2
Wow - did this script get into your version control system? Did it go through peer review?rm -rf $OUT_DIR/*really? And why was the script not tested on a non-production server? Once you have restored from backup you have many critical procedural failings to address here before automating anything else. I hope you're not too hard on your developer over it, as a result (though they also have quite a bit to answer for)
– Lightness Races in Orbit
1 hour ago
add a comment |
My developer committed a huge mistake and we cannot find our Mongo database anywhere in the server.
He logged into the server, and saved the following shell under ~/crontab/mongod_back.sh:

#!/bin/sh
DUMP=mongodump
OUT_DIR=/data/backup/mongod/tmp // 备份文件临时目录
TAR_DIR=/data/backup/mongod // 备份文件正式目录
DATE=`date +%Y_%m_%d_%H_%M_%S` // 备份文件将以备份对间保存
DB_USER=Guitang // 数库操作员
DB_PASS=qq■■■■■■■■■■■■■■■■■■■■■ // 数掘库操作员密码
DAYS=14 // 保留最新14天的份
TARBAK="mongod_bak_$DATE.tar.gz" // 备份文件命名格式
cd $OUT_DIR // 创建文件夹
rm -rf $OUT_DIR/* // 清空临时目录
mkdir -p $OUT_DIR/$DATE // 创建本次备份文件夹
$DUMP -d wecard -u $DB_USER -p $DB_PASS -o $OUT_DIR/$DATE // 执行备份命令
tar -zcvf $TAR_DIR/$TAR_BAK $OUT_DIR/$DATE // 将份文件打包放入正式
find $TAR_DIR/ -mtime +$DAYS -delete // 除14天前的旧备
And then he ran it and it outputted permission denied messages, so he pressed Ctrl+C. The server shut down automatically. He tried to restart it but got a grub error:

He contacted AliCloud, the engineer connected the disk to another working server so that he could check the disk. Looks like some folders are gone, including /data/ where the mongodb is!
- We don't understand how the script could destroy the disk including
/data/; - And of course, is it possible to get the
/data/back?
PS: He did not take snapshot of the disk before.
PS2: As people mention "backups" a lot, we have lots of users and data coming these 2 days, the purpose of this action was to backup them, then they turned out to be entirely deleted.
filesystems shell ubuntu-14.04 data-recovery disaster-recovery
My developer committed a huge mistake and we cannot find our Mongo database anywhere in the server.
He logged into the server, and saved the following shell under ~/crontab/mongod_back.sh:

#!/bin/sh
DUMP=mongodump
OUT_DIR=/data/backup/mongod/tmp // 备份文件临时目录
TAR_DIR=/data/backup/mongod // 备份文件正式目录
DATE=`date +%Y_%m_%d_%H_%M_%S` // 备份文件将以备份对间保存
DB_USER=Guitang // 数库操作员
DB_PASS=qq■■■■■■■■■■■■■■■■■■■■■ // 数掘库操作员密码
DAYS=14 // 保留最新14天的份
TARBAK="mongod_bak_$DATE.tar.gz" // 备份文件命名格式
cd $OUT_DIR // 创建文件夹
rm -rf $OUT_DIR/* // 清空临时目录
mkdir -p $OUT_DIR/$DATE // 创建本次备份文件夹
$DUMP -d wecard -u $DB_USER -p $DB_PASS -o $OUT_DIR/$DATE // 执行备份命令
tar -zcvf $TAR_DIR/$TAR_BAK $OUT_DIR/$DATE // 将份文件打包放入正式
find $TAR_DIR/ -mtime +$DAYS -delete // 除14天前的旧备
And then he ran it and it outputted permission denied messages, so he pressed Ctrl+C. The server shut down automatically. He tried to restart it but got a grub error:

He contacted AliCloud, the engineer connected the disk to another working server so that he could check the disk. Looks like some folders are gone, including /data/ where the mongodb is!
- We don't understand how the script could destroy the disk including
/data/; - And of course, is it possible to get the
/data/back?
PS: He did not take snapshot of the disk before.
PS2: As people mention "backups" a lot, we have lots of users and data coming these 2 days, the purpose of this action was to backup them, then they turned out to be entirely deleted.
filesystems shell ubuntu-14.04 data-recovery disaster-recovery
filesystems shell ubuntu-14.04 data-recovery disaster-recovery
edited 8 mins ago
SoftTimur
asked 8 hours ago
SoftTimurSoftTimur
1087
1087
1
Your script has no error checking. If the linecd $OUT_DIRfails, it's going to delete everything in the current path, which may well be/. This is why you have backups - use them.
– Jenny D
8 hours ago
2
Possible duplicate of Monday morning mistake: sudo rm -rf --no-preserve-root /
– Jenny D
8 hours ago
He run the shell under~/crontab/, how couldrmorfind -deletedelete folders under/?
– SoftTimur
8 hours ago
Make a raw backup of the full hard disk before yo do anything, this will increase your low changes for data recovery
– Ferrybig
4 hours ago
2
Wow - did this script get into your version control system? Did it go through peer review?rm -rf $OUT_DIR/*really? And why was the script not tested on a non-production server? Once you have restored from backup you have many critical procedural failings to address here before automating anything else. I hope you're not too hard on your developer over it, as a result (though they also have quite a bit to answer for)
– Lightness Races in Orbit
1 hour ago
add a comment |
1
Your script has no error checking. If the linecd $OUT_DIRfails, it's going to delete everything in the current path, which may well be/. This is why you have backups - use them.
– Jenny D
8 hours ago
2
Possible duplicate of Monday morning mistake: sudo rm -rf --no-preserve-root /
– Jenny D
8 hours ago
He run the shell under~/crontab/, how couldrmorfind -deletedelete folders under/?
– SoftTimur
8 hours ago
Make a raw backup of the full hard disk before yo do anything, this will increase your low changes for data recovery
– Ferrybig
4 hours ago
2
Wow - did this script get into your version control system? Did it go through peer review?rm -rf $OUT_DIR/*really? And why was the script not tested on a non-production server? Once you have restored from backup you have many critical procedural failings to address here before automating anything else. I hope you're not too hard on your developer over it, as a result (though they also have quite a bit to answer for)
– Lightness Races in Orbit
1 hour ago
1
1
Your script has no error checking. If the line
cd $OUT_DIR fails, it's going to delete everything in the current path, which may well be / . This is why you have backups - use them.– Jenny D
8 hours ago
Your script has no error checking. If the line
cd $OUT_DIR fails, it's going to delete everything in the current path, which may well be / . This is why you have backups - use them.– Jenny D
8 hours ago
2
2
Possible duplicate of Monday morning mistake: sudo rm -rf --no-preserve-root /
– Jenny D
8 hours ago
Possible duplicate of Monday morning mistake: sudo rm -rf --no-preserve-root /
– Jenny D
8 hours ago
He run the shell under
~/crontab/, how could rm or find -delete delete folders under /?– SoftTimur
8 hours ago
He run the shell under
~/crontab/, how could rm or find -delete delete folders under /?– SoftTimur
8 hours ago
Make a raw backup of the full hard disk before yo do anything, this will increase your low changes for data recovery
– Ferrybig
4 hours ago
Make a raw backup of the full hard disk before yo do anything, this will increase your low changes for data recovery
– Ferrybig
4 hours ago
2
2
Wow - did this script get into your version control system? Did it go through peer review?
rm -rf $OUT_DIR/* really? And why was the script not tested on a non-production server? Once you have restored from backup you have many critical procedural failings to address here before automating anything else. I hope you're not too hard on your developer over it, as a result (though they also have quite a bit to answer for)– Lightness Races in Orbit
1 hour ago
Wow - did this script get into your version control system? Did it go through peer review?
rm -rf $OUT_DIR/* really? And why was the script not tested on a non-production server? Once you have restored from backup you have many critical procedural failings to address here before automating anything else. I hope you're not too hard on your developer over it, as a result (though they also have quite a bit to answer for)– Lightness Races in Orbit
1 hour ago
add a comment |
3 Answers
3
active
oldest
votes
Easy enough. The // sequence isn't a comment in bash (# is).
The statement OUT_DIR=x // text had no effect*.
Thus what was finally executed was rm -rf /*. The directories that the user couldn't remove gave permission errors, but some directories placed directly underneath / apparently could be removed. You need to restore from backup.
* The peculiar form of bash statement A=b c d e f is roughly similar to:
export A=b
c d e f
unset A
Hence script suceeded to do this:
export OUT_DIR=/data/mongo/tmp
// some text # gives error as `//` isn't an executable file!
unset OUT_DIR
add a comment |
1) He erroneously assumed that // was a bash comment. It is not, only # is.
The shell interpreted // text as a normal command, and did not find a binary called //, and did nothing.
In bash, when you have a variable assignment (OUT_DIR=/data/backup/mongod/tmp) directly preceding a command (// text), it only sets the variable while running the command. Therefore, it unsets OUT_DIR immediately, and when the rm line is reached, OUT_DIR is now unset, and rm -rf / is now called, deleting everything you have permission to delete.
2) The solution is the same as all rm -rf / cases: restore from backup. There is no other solution because you do not have physical access to the hard drive.
New contributor
Ray Wu is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
why having physical access to the hard drive may help to restore?
– SoftTimur
1 hour ago
Possible forensics, professional hard drive recovery methods. I know this because I know thatrm -rfis not extremely secure, and doesn't overwrite the hard drive.
– Ray Wu
1 hour ago
@SoftTimurrmusually just "unlinks" files but the data is still physically there until overwritten. This is why professionals can "undelete" sometimes if they have physical access and you haven't done lots of things with the disk after the catastrophe occurred. If you don't have backups, that's the best you can hope for.
– Lightness Races in Orbit
18 mins ago
add a comment |
1) Bash comments start with #. Sorry for your loss.
2) Restore from backup is the only way to proceed here, unfortunately.
New contributor
RMPJ is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
add a comment |
Your Answer
StackExchange.ready(function()
var channelOptions =
tags: "".split(" "),
id: "2"
;
initTagRenderer("".split(" "), "".split(" "), channelOptions);
StackExchange.using("externalEditor", function()
// Have to fire editor after snippets, if snippets enabled
if (StackExchange.settings.snippets.snippetsEnabled)
StackExchange.using("snippets", function()
createEditor();
);
else
createEditor();
);
function createEditor()
StackExchange.prepareEditor(
heartbeatType: 'answer',
autoActivateHeartbeat: false,
convertImagesToLinks: true,
noModals: true,
showLowRepImageUploadWarning: true,
reputationToPostImages: 10,
bindNavPrevention: true,
postfix: "",
imageUploader:
brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
allowUrls: true
,
onDemand: true,
discardSelector: ".discard-answer"
,immediatelyShowMarkdownHelp:true
);
);
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
var $window = $(window),
onScroll = function(e)
var $elem = $('.new-login-left'),
docViewTop = $window.scrollTop(),
docViewBottom = docViewTop + $window.height(),
elemTop = $elem.offset().top,
elemBottom = elemTop + $elem.height();
if ((docViewTop elemBottom))
StackExchange.using('gps', function() StackExchange.gps.track('embedded_signup_form.view', location: 'question_page' ); );
$window.unbind('scroll', onScroll);
;
$window.on('scroll', onScroll);
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f959707%2fdatabase-accidentally-deleted-with-a-bash-script%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
3 Answers
3
active
oldest
votes
3 Answers
3
active
oldest
votes
active
oldest
votes
active
oldest
votes
Easy enough. The // sequence isn't a comment in bash (# is).
The statement OUT_DIR=x // text had no effect*.
Thus what was finally executed was rm -rf /*. The directories that the user couldn't remove gave permission errors, but some directories placed directly underneath / apparently could be removed. You need to restore from backup.
* The peculiar form of bash statement A=b c d e f is roughly similar to:
export A=b
c d e f
unset A
Hence script suceeded to do this:
export OUT_DIR=/data/mongo/tmp
// some text # gives error as `//` isn't an executable file!
unset OUT_DIR
add a comment |
Easy enough. The // sequence isn't a comment in bash (# is).
The statement OUT_DIR=x // text had no effect*.
Thus what was finally executed was rm -rf /*. The directories that the user couldn't remove gave permission errors, but some directories placed directly underneath / apparently could be removed. You need to restore from backup.
* The peculiar form of bash statement A=b c d e f is roughly similar to:
export A=b
c d e f
unset A
Hence script suceeded to do this:
export OUT_DIR=/data/mongo/tmp
// some text # gives error as `//` isn't an executable file!
unset OUT_DIR
add a comment |
Easy enough. The // sequence isn't a comment in bash (# is).
The statement OUT_DIR=x // text had no effect*.
Thus what was finally executed was rm -rf /*. The directories that the user couldn't remove gave permission errors, but some directories placed directly underneath / apparently could be removed. You need to restore from backup.
* The peculiar form of bash statement A=b c d e f is roughly similar to:
export A=b
c d e f
unset A
Hence script suceeded to do this:
export OUT_DIR=/data/mongo/tmp
// some text # gives error as `//` isn't an executable file!
unset OUT_DIR
Easy enough. The // sequence isn't a comment in bash (# is).
The statement OUT_DIR=x // text had no effect*.
Thus what was finally executed was rm -rf /*. The directories that the user couldn't remove gave permission errors, but some directories placed directly underneath / apparently could be removed. You need to restore from backup.
* The peculiar form of bash statement A=b c d e f is roughly similar to:
export A=b
c d e f
unset A
Hence script suceeded to do this:
export OUT_DIR=/data/mongo/tmp
// some text # gives error as `//` isn't an executable file!
unset OUT_DIR
edited 34 mins ago
Lightness Races in Orbit
273416
273416
answered 7 hours ago
kubanczykkubanczyk
10.3k22744
10.3k22744
add a comment |
add a comment |
1) He erroneously assumed that // was a bash comment. It is not, only # is.
The shell interpreted // text as a normal command, and did not find a binary called //, and did nothing.
In bash, when you have a variable assignment (OUT_DIR=/data/backup/mongod/tmp) directly preceding a command (// text), it only sets the variable while running the command. Therefore, it unsets OUT_DIR immediately, and when the rm line is reached, OUT_DIR is now unset, and rm -rf / is now called, deleting everything you have permission to delete.
2) The solution is the same as all rm -rf / cases: restore from backup. There is no other solution because you do not have physical access to the hard drive.
New contributor
Ray Wu is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
why having physical access to the hard drive may help to restore?
– SoftTimur
1 hour ago
Possible forensics, professional hard drive recovery methods. I know this because I know thatrm -rfis not extremely secure, and doesn't overwrite the hard drive.
– Ray Wu
1 hour ago
@SoftTimurrmusually just "unlinks" files but the data is still physically there until overwritten. This is why professionals can "undelete" sometimes if they have physical access and you haven't done lots of things with the disk after the catastrophe occurred. If you don't have backups, that's the best you can hope for.
– Lightness Races in Orbit
18 mins ago
add a comment |
1) He erroneously assumed that // was a bash comment. It is not, only # is.
The shell interpreted // text as a normal command, and did not find a binary called //, and did nothing.
In bash, when you have a variable assignment (OUT_DIR=/data/backup/mongod/tmp) directly preceding a command (// text), it only sets the variable while running the command. Therefore, it unsets OUT_DIR immediately, and when the rm line is reached, OUT_DIR is now unset, and rm -rf / is now called, deleting everything you have permission to delete.
2) The solution is the same as all rm -rf / cases: restore from backup. There is no other solution because you do not have physical access to the hard drive.
New contributor
Ray Wu is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
why having physical access to the hard drive may help to restore?
– SoftTimur
1 hour ago
Possible forensics, professional hard drive recovery methods. I know this because I know thatrm -rfis not extremely secure, and doesn't overwrite the hard drive.
– Ray Wu
1 hour ago
@SoftTimurrmusually just "unlinks" files but the data is still physically there until overwritten. This is why professionals can "undelete" sometimes if they have physical access and you haven't done lots of things with the disk after the catastrophe occurred. If you don't have backups, that's the best you can hope for.
– Lightness Races in Orbit
18 mins ago
add a comment |
1) He erroneously assumed that // was a bash comment. It is not, only # is.
The shell interpreted // text as a normal command, and did not find a binary called //, and did nothing.
In bash, when you have a variable assignment (OUT_DIR=/data/backup/mongod/tmp) directly preceding a command (// text), it only sets the variable while running the command. Therefore, it unsets OUT_DIR immediately, and when the rm line is reached, OUT_DIR is now unset, and rm -rf / is now called, deleting everything you have permission to delete.
2) The solution is the same as all rm -rf / cases: restore from backup. There is no other solution because you do not have physical access to the hard drive.
New contributor
Ray Wu is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
1) He erroneously assumed that // was a bash comment. It is not, only # is.
The shell interpreted // text as a normal command, and did not find a binary called //, and did nothing.
In bash, when you have a variable assignment (OUT_DIR=/data/backup/mongod/tmp) directly preceding a command (// text), it only sets the variable while running the command. Therefore, it unsets OUT_DIR immediately, and when the rm line is reached, OUT_DIR is now unset, and rm -rf / is now called, deleting everything you have permission to delete.
2) The solution is the same as all rm -rf / cases: restore from backup. There is no other solution because you do not have physical access to the hard drive.
New contributor
Ray Wu is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
New contributor
Ray Wu is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
answered 1 hour ago
Ray WuRay Wu
211
211
New contributor
Ray Wu is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
New contributor
Ray Wu is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
Ray Wu is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
why having physical access to the hard drive may help to restore?
– SoftTimur
1 hour ago
Possible forensics, professional hard drive recovery methods. I know this because I know thatrm -rfis not extremely secure, and doesn't overwrite the hard drive.
– Ray Wu
1 hour ago
@SoftTimurrmusually just "unlinks" files but the data is still physically there until overwritten. This is why professionals can "undelete" sometimes if they have physical access and you haven't done lots of things with the disk after the catastrophe occurred. If you don't have backups, that's the best you can hope for.
– Lightness Races in Orbit
18 mins ago
add a comment |
why having physical access to the hard drive may help to restore?
– SoftTimur
1 hour ago
Possible forensics, professional hard drive recovery methods. I know this because I know thatrm -rfis not extremely secure, and doesn't overwrite the hard drive.
– Ray Wu
1 hour ago
@SoftTimurrmusually just "unlinks" files but the data is still physically there until overwritten. This is why professionals can "undelete" sometimes if they have physical access and you haven't done lots of things with the disk after the catastrophe occurred. If you don't have backups, that's the best you can hope for.
– Lightness Races in Orbit
18 mins ago
why having physical access to the hard drive may help to restore?
– SoftTimur
1 hour ago
why having physical access to the hard drive may help to restore?
– SoftTimur
1 hour ago
Possible forensics, professional hard drive recovery methods. I know this because I know that
rm -rf is not extremely secure, and doesn't overwrite the hard drive.– Ray Wu
1 hour ago
Possible forensics, professional hard drive recovery methods. I know this because I know that
rm -rf is not extremely secure, and doesn't overwrite the hard drive.– Ray Wu
1 hour ago
@SoftTimur
rm usually just "unlinks" files but the data is still physically there until overwritten. This is why professionals can "undelete" sometimes if they have physical access and you haven't done lots of things with the disk after the catastrophe occurred. If you don't have backups, that's the best you can hope for.– Lightness Races in Orbit
18 mins ago
@SoftTimur
rm usually just "unlinks" files but the data is still physically there until overwritten. This is why professionals can "undelete" sometimes if they have physical access and you haven't done lots of things with the disk after the catastrophe occurred. If you don't have backups, that's the best you can hope for.– Lightness Races in Orbit
18 mins ago
add a comment |
1) Bash comments start with #. Sorry for your loss.
2) Restore from backup is the only way to proceed here, unfortunately.
New contributor
RMPJ is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
add a comment |
1) Bash comments start with #. Sorry for your loss.
2) Restore from backup is the only way to proceed here, unfortunately.
New contributor
RMPJ is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
add a comment |
1) Bash comments start with #. Sorry for your loss.
2) Restore from backup is the only way to proceed here, unfortunately.
New contributor
RMPJ is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
1) Bash comments start with #. Sorry for your loss.
2) Restore from backup is the only way to proceed here, unfortunately.
New contributor
RMPJ is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
New contributor
RMPJ is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
answered 45 mins ago
RMPJRMPJ
111
111
New contributor
RMPJ is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
New contributor
RMPJ is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
RMPJ is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.
add a comment |
add a comment |
Thanks for contributing an answer to Server Fault!
- Please be sure to answer the question. Provide details and share your research!
But avoid …
- Asking for help, clarification, or responding to other answers.
- Making statements based on opinion; back them up with references or personal experience.
To learn more, see our tips on writing great answers.
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
var $window = $(window),
onScroll = function(e)
var $elem = $('.new-login-left'),
docViewTop = $window.scrollTop(),
docViewBottom = docViewTop + $window.height(),
elemTop = $elem.offset().top,
elemBottom = elemTop + $elem.height();
if ((docViewTop elemBottom))
StackExchange.using('gps', function() StackExchange.gps.track('embedded_signup_form.view', location: 'question_page' ); );
$window.unbind('scroll', onScroll);
;
$window.on('scroll', onScroll);
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
StackExchange.ready(
function ()
StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fserverfault.com%2fquestions%2f959707%2fdatabase-accidentally-deleted-with-a-bash-script%23new-answer', 'question_page');
);
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
var $window = $(window),
onScroll = function(e)
var $elem = $('.new-login-left'),
docViewTop = $window.scrollTop(),
docViewBottom = docViewTop + $window.height(),
elemTop = $elem.offset().top,
elemBottom = elemTop + $elem.height();
if ((docViewTop elemBottom))
StackExchange.using('gps', function() StackExchange.gps.track('embedded_signup_form.view', location: 'question_page' ); );
$window.unbind('scroll', onScroll);
;
$window.on('scroll', onScroll);
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
var $window = $(window),
onScroll = function(e)
var $elem = $('.new-login-left'),
docViewTop = $window.scrollTop(),
docViewBottom = docViewTop + $window.height(),
elemTop = $elem.offset().top,
elemBottom = elemTop + $elem.height();
if ((docViewTop elemBottom))
StackExchange.using('gps', function() StackExchange.gps.track('embedded_signup_form.view', location: 'question_page' ); );
$window.unbind('scroll', onScroll);
;
$window.on('scroll', onScroll);
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Sign up or log in
StackExchange.ready(function ()
StackExchange.helpers.onClickDraftSave('#login-link');
var $window = $(window),
onScroll = function(e)
var $elem = $('.new-login-left'),
docViewTop = $window.scrollTop(),
docViewBottom = docViewTop + $window.height(),
elemTop = $elem.offset().top,
elemBottom = elemTop + $elem.height();
if ((docViewTop elemBottom))
StackExchange.using('gps', function() StackExchange.gps.track('embedded_signup_form.view', location: 'question_page' ); );
$window.unbind('scroll', onScroll);
;
$window.on('scroll', onScroll);
);
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Sign up using Google
Sign up using Facebook
Sign up using Email and Password
Post as a guest
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
Required, but never shown
1
Your script has no error checking. If the line
cd $OUT_DIRfails, it's going to delete everything in the current path, which may well be/. This is why you have backups - use them.– Jenny D
8 hours ago
2
Possible duplicate of Monday morning mistake: sudo rm -rf --no-preserve-root /
– Jenny D
8 hours ago
He run the shell under
~/crontab/, how couldrmorfind -deletedelete folders under/?– SoftTimur
8 hours ago
Make a raw backup of the full hard disk before yo do anything, this will increase your low changes for data recovery
– Ferrybig
4 hours ago
2
Wow - did this script get into your version control system? Did it go through peer review?
rm -rf $OUT_DIR/*really? And why was the script not tested on a non-production server? Once you have restored from backup you have many critical procedural failings to address here before automating anything else. I hope you're not too hard on your developer over it, as a result (though they also have quite a bit to answer for)– Lightness Races in Orbit
1 hour ago