<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: INDEXF.SYS corrupted.. in Operating System - OpenVMS</title>
    <link>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896766#M80022</link>
    <description>Latest DFU is at&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.digiater.nl/dfu.html" target="_blank"&gt;http://www.digiater.nl/dfu.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;However I think it may be time to test your recovery strategy,</description>
    <pubDate>Tue, 14 Nov 2006 04:56:10 GMT</pubDate>
    <dc:creator>Ian Miller.</dc:creator>
    <dc:date>2006-11-14T04:56:10Z</dc:date>
    <item>
      <title>INDEXF.SYS corrupted..</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896763#M80019</link>
      <description>Hi All,&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;    Anyone encounter below error before? Tried the anal/disk/repair, no luck.. Need help..&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;PMAX01&amp;gt; dir /sec&lt;BR /&gt;&lt;BR /&gt;Directory PMAX01$DKB200:[000000]&lt;BR /&gt;&lt;BR /&gt;000000.DIR;1       file identification number check&lt;BR /&gt;BACKUP.SYS;1       file identification number check&lt;BR /&gt;BADBLK.SYS;1       file identification number check&lt;BR /&gt;BADLOG.SYS;1       file identification number check&lt;BR /&gt;BITMAP.SYS;1       file identification number check&lt;BR /&gt;CIM0.DIR;1         file identification number check&lt;BR /&gt;CIMCOMMON.DIR;1    file identification number check&lt;BR /&gt;CONTIN.SYS;1       file identification number check&lt;BR /&gt;CORIMG.SYS;1       file identification number check&lt;BR /&gt;INDEXF.SYS;1       file identification number check&lt;BR /&gt;JSS$V10.DIR;1      file identification number check&lt;BR /&gt;SECURITY.SYS;1     file identification number check&lt;BR /&gt;SYS0.DIR;1         file identification number check&lt;BR /&gt;SYSLOST.DIR;1      file identification number check&lt;BR /&gt;VOLSET.SYS;1       file identification number check&lt;BR /&gt;&lt;BR /&gt;Total of 15 files.&lt;BR /&gt;PMAX01&amp;gt; anal/disk /repair pmax01$dkb200:&lt;BR /&gt;%ANALDISK-F-OPENINDEX, error opening INDEXF.SYS, RVN 1&lt;BR /&gt;-SYSTEM-W-FILENUMCHK, file identification number check&lt;BR /&gt;</description>
      <pubDate>Sun, 12 Nov 2006 17:20:02 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896763#M80019</guid>
      <dc:creator>KW</dc:creator>
      <dc:date>2006-11-12T17:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: INDEXF.SYS corrupted..</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896764#M80020</link>
      <description>- Sound like BAD corruption. Possibly a program with LOGIO priv overwriting the first few blocks of the disk.&lt;BR /&gt;&lt;BR /&gt;- Since you can still do a dir/sec, I guess it is still mounted. This may help you find some data in  in-memory structures, but not too likely.&lt;BR /&gt;I would $MOUNT/FOR and DUMP/BLO=COUN=10.&lt;BR /&gt;See if you can recognize the data at all.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;- Dust of, or quickly aquire a "VMS File System Internals" book by Kirby McCoy ISBN 1-55558-056-4&lt;BR /&gt;&lt;BR /&gt;- Go locate a recent backup, you are likely to need it. If lucky you will not need the actual data, just the basic layout. Restore the backup to a 'spare' disk and dump the first few blocks to see what they should look like.&lt;BR /&gt;&lt;BR /&gt;Cluster 1, almost always starting at LBN 0 of the drive, starts with a boot block and a home block, followed by more homeblocks.&lt;BR /&gt;The homeblock (any homeblock copy), in the longword at offset 8 points to an alternate indexf.sys file header. This is potentially a key to volume recovery. You may be able to use that to reconstruct the real header... but I suspect the damage is bigger.&lt;BR /&gt;&lt;BR /&gt;I'm sure there are folks out there who are willign to help you recover the data, for a fee.&lt;BR /&gt;Your main assignment now is to figure out how good your backup is, and to get an impression of the extent of the damage.&lt;BR /&gt;&lt;BR /&gt;Good luck!&lt;BR /&gt;Hein van den Heuvel&lt;BR /&gt;HvdH Performance Consulting.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Sun, 12 Nov 2006 18:48:33 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896764#M80020</guid>
      <dc:creator>Hein van den Heuvel</dc:creator>
      <dc:date>2006-11-12T18:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: INDEXF.SYS corrupted..</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896765#M80021</link>
      <description>the tool DFU (from the freeware cd) can repair a lot more, and you get better messages about the problems.</description>
      <pubDate>Tue, 14 Nov 2006 04:17:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896765#M80021</guid>
      <dc:creator>Jeroen Hartgers_3</dc:creator>
      <dc:date>2006-11-14T04:17:35Z</dc:date>
    </item>
    <item>
      <title>Re: INDEXF.SYS corrupted..</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896766#M80022</link>
      <description>Latest DFU is at&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://www.digiater.nl/dfu.html" target="_blank"&gt;http://www.digiater.nl/dfu.html&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;However I think it may be time to test your recovery strategy,</description>
      <pubDate>Tue, 14 Nov 2006 04:56:10 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896766#M80022</guid>
      <dc:creator>Ian Miller.</dc:creator>
      <dc:date>2006-11-14T04:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: INDEXF.SYS corrupted..</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896767#M80023</link>
      <description>KW,&lt;BR /&gt;&lt;BR /&gt;As has been noted, this can get VERY tricky, VERY VERY fast.&lt;BR /&gt;&lt;BR /&gt;The First Step (and most important rule): DO NOT DO ANYTHING that will write to the disk. And I do mean ANYTHING. Do a SHOW DEV/FULL on the device and save all of the output.&lt;BR /&gt;&lt;BR /&gt;The Second Step: Immediately copy any critically important files BEFORE dismounting the disk.&lt;BR /&gt;&lt;BR /&gt;Third Step: Make a PHYSICAL backup of the drive. From this point on, treat the original drive as if it were evidence in a criminal case: Remove it from active use, and take steps to ensure that it is not accidentilly used. &lt;BR /&gt;&lt;BR /&gt;Then restore the PHYSICAL backup that was taken to a scratch drive, and take a look at what data is in the HOME BLOCK (LBN 1) and the BOOT BLOCK (LBN 0). As I believe Hein mentioned, somebody with LOGIO probably overwrote the disk, it is important to identify how this was done to prevent a recurrence.&lt;BR /&gt;&lt;BR /&gt;Then, it is a matter of recreating enough of the disk structure to attempt recovery of the files, if the data is still intact.&lt;BR /&gt;&lt;BR /&gt;Having done this process during my career, it  can be done, but it does take time. If the actual data is intact, and the damage does not extend too far, excellent results are possible, but there are no guarantees.&lt;BR /&gt;&lt;BR /&gt;In terms of recovery, the most important question is: How valuable is the data, as compared to restoring the volume to a new disk from the most recent backup. In any event, I still strongly recommend identifying how this happened to prevent a repeated incident.&lt;BR /&gt;&lt;BR /&gt;- Bob Gezelter, &lt;A href="http://www.rlgsc.com" target="_blank"&gt;http://www.rlgsc.com&lt;/A&gt;</description>
      <pubDate>Tue, 14 Nov 2006 05:53:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896767#M80023</guid>
      <dc:creator>Robert Gezelter</dc:creator>
      <dc:date>2006-11-14T05:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: INDEXF.SYS corrupted..</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896768#M80024</link>
      <description>All masters,&lt;BR /&gt;&lt;BR /&gt;   I never got the opportunity to try out all the useful steps, the production had put on pressure to receovery everything within few hours. I worked through the night, directly replaced a new disk and restore all the data from the backup tape - at least tested the backup and recovery steps works :)&lt;BR /&gt;  "Possibly a program with LOGIO priv overwriting the first few blocks of the disk." This is very useful info, the next steps need to find out why this happended and how to present it. Any clue how to investicate this?&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Tue, 14 Nov 2006 06:41:35 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896768#M80024</guid>
      <dc:creator>KW</dc:creator>
      <dc:date>2006-11-14T06:41:35Z</dc:date>
    </item>
    <item>
      <title>Re: INDEXF.SYS corrupted..</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896769#M80025</link>
      <description>KW,&lt;BR /&gt;&lt;BR /&gt;without the data from the corrupted disk, which you could look at by dumping the blocks and trying to draw conclusions from the contents to guess about which application might have written that data, it won't be possible to make an educated guess at what might have happened.&lt;BR /&gt;&lt;BR /&gt;You could still dig through .LOG files from the relevant period of time (minutes or hours before the problem has been first detected) to try to spot anything unusual.&lt;BR /&gt;&lt;BR /&gt;Volker.</description>
      <pubDate>Tue, 14 Nov 2006 06:53:00 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896769#M80025</guid>
      <dc:creator>Volker Halle</dc:creator>
      <dc:date>2006-11-14T06:53:00Z</dc:date>
    </item>
    <item>
      <title>Re: INDEXF.SYS corrupted..</title>
      <link>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896770#M80026</link>
      <description>KW,&lt;BR /&gt;&lt;BR /&gt;From your followup posting "... directly replaced a new disk and restore all the data from the backup tape - ..."&lt;BR /&gt;&lt;BR /&gt;If there is not a miscommunication here, and you retained the original corrupted disk unaltered, then it may be possible to identify what happened.&lt;BR /&gt;&lt;BR /&gt;Please confirm that the original disk is preserved.&lt;BR /&gt;&lt;BR /&gt;- Bob Gezelter, &lt;A href="http://www.rlgsc.com" target="_blank"&gt;http://www.rlgsc.com&lt;/A&gt;</description>
      <pubDate>Tue, 14 Nov 2006 07:29:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-openvms/indexf-sys-corrupted/m-p/3896770#M80026</guid>
      <dc:creator>Robert Gezelter</dc:creator>
      <dc:date>2006-11-14T07:29:29Z</dc:date>
    </item>
  </channel>
</rss>

