Why is it dangerous to run e2fsck against an ext4 filesystem that is currently mounted read-write?

LPIC-1 Exam 101-500, objective 104. Devices, Linux filesystems, filesystem hierarchy standard medium

Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.

Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.

How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.

The options

Correct The kernel keeps changing on-disk structures while e2fsck reads and rewrites them, so the tool can act on a stale picture and corrupt the filesystem.

Correct. e2fsck assumes it is the only writer. A live filesystem violates that assumption, and repairs computed from inconsistent reads can destroy good data.

Not correct e2fsck simply refuses to start on any mounted filesystem, so nothing can be checked.

Wrong, and this is the dangerous misconception. e2fsck notices the mount and prints a warning, then asks 'Do you really want to continue?'; answer yes at a terminal and it goes ahead and checks the live filesystem. It aborts outright only when there is no terminal to ask on. The safety is a warning you can override, not a hard block.

Not correct e2fsck can only read ext2, so running it on ext4 silently downgrades the filesystem.

Wrong. e2fsck handles ext2, ext3 and ext4; it is the shared checker for the whole ext family and changes no feature flags on its own.

Not correct It clears the journal, which forces a full mkfs before the filesystem can be mounted again.

Wrong. Recovering or replaying the journal is a normal part of checking an ext3/ext4 filesystem and never requires re-creating it.

Why

Check filesystems offline: unmount them, or boot to rescue/single-user mode, or mark the root filesystem for checking at the next boot. Read-only mounts are the only reasonably safe live case. XFS behaves the same way — xfs_repair refuses a mounted filesystem outright.

Where this comes from

Cited
LPI exam objective 104.2
What it says
Verify the integrity of filesystems with fsck and e2fsck.

Practise this

Reading one question is not practice. The trainer will draw a short set from objective 104 and space the ones you get wrong.

Practise LPIC-1 Exam 101-500

More questions on this objective

All questions on Devices, Linux filesystems, filesystem hierarchy standard

Practise LPIC-1 Exam 101-500