/ Rescue

Linux not booting? How to find the cause and fix it

Short answer. Most Linux boot failures after an update come from four things: an initramfs that failed to build (often because /boot was full), a missing bootloader entry, a changed disk UUID in /etc/fstab, or a failing disk. Boot a rescue USB, mount the installed system read-only, read the last boot's journal and the package log, then rebuild the initramfs and bootloader from a chroot. Check the disk's health first: never run repairs on a disk that is failing.

Step by step

  1. Boot a rescue system and stay read-only

    Start the machine from a rescue USB stick instead of the installed system. Agentic Rescue mounts nothing writable on its own. Until you know the cause, keep it that way.

  2. Check the disk before anything else

    Read the SMART data and look for I/O errors in the kernel log. If the disk reports reallocated or pending sectors, or dmesg shows I/O errors, stop here and image the disk to another one with ddrescue before any repair.

    smartctl -a /dev/nvme0n1
    dmesg | grep -iE 'i/o error|ata[0-9].*error|nvme.*error'
    ddrescue -d /dev/nvme0n1 /media/backup/disk.img /media/backup/disk.map
  3. Find, unlock and mount the installed system

    Unlock LUKS, activate LVM and RAID, import ZFS pools, then mount the root filesystem read-only. For Btrfs, mount the root subvolume (often @). On Agentic Rescue, rescue-mount does all of this and mounts at /mnt.

    cryptsetup open /dev/nvme0n1p2 root
    vgchange -ay
    mount -o ro,subvol=@ /dev/mapper/root /mnt
  4. Read the journal of the failed boot

    The installed system's journal usually names the problem: a missing module, a filesystem that could not be mounted, a unit that failed. List the boots and read the warnings of the last one.

    journalctl -D /mnt/var/log/journal --list-boots
    journalctl -D /mnt/var/log/journal -b -1 -p warning
  5. See what changed

    The package manager's log shows what the last update installed and whether a hook failed. Look for errors right after a kernel update, and check whether /boot is full.

    tail -n 80 /mnt/var/log/pacman.log            # Arch and derivatives
    less /mnt/var/log/apt/history.log             # Debian, Ubuntu
    df -h /mnt/boot
  6. Match the cause

    • initramfs missing or broken: rebuild it (step 7). Free space on /boot first if it is full.
    • Bootloader entry missing: check efibootmgr -v, then reinstall or update the bootloader.
    • fstab points at a UUID that no longer exists: compare blkid with /mnt/etc/fstab and fix the line.
    • Filesystem errors: check without writing first: e2fsck -n, btrfs check --readonly, xfs_repair -n.
    • NixOS: pick the previous generation in the boot menu. It is still there.
  7. Repair from a chroot

    Remount writable, back up every file before you edit it, enter the installed system and rebuild with its own tools. arch-chroot works for any distribution; on NixOS use nixos-enter.

    mount -o remount,rw /mnt
    arch-chroot /mnt

Rebuild commands by distribution

Run these inside the chroot from step 7.

DistributioninitramfsBootloader
Arch, EndeavourOS, CachyOSmkinitcpio -Pgrub-mkconfig -o /boot/grub/grub.cfg or bootctl update
Debian, Ubuntu, Mintupdate-initramfs -u -k allupdate-grub
Fedoradracut --regenerate-all --forcegrub2-mkconfig -o /boot/grub2/grub.cfg
NixOSbuilt with the systemnixos-rebuild boot (inside nixos-enter)

Then leave the chroot, run sync, unmount everything under /mnt and reboot.

Questions

Will I lose data when I repair a system that does not boot?

Not if you work read-only first. Mounting read-only, reading logs and checking SMART data changes nothing. Data is at risk from repair runs of fsck or btrfs check, from partitioning tools, and from writing to a failing disk. Copy what matters off the disk before any of those.

Do I have to reinstall Linux?

Rarely. A failed initramfs, a lost bootloader entry or a wrong fstab line are fixed with one or two commands from a chroot. Reinstalling is the answer when the disk itself is failing, and then only after imaging it.

Why does Linux stop booting after an update?

Because an update rebuilds the initramfs and the bootloader configuration. If /boot runs out of space, a kernel module is missing, or the update was interrupted, the new kernel has nothing usable to start with. The package manager's log shows which step failed.