The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Show effective kernel arguments | cat /proc/cmdline | View examples |
| Inspect boot loader status | bootctl status | View examples |
| Identify the running kernel | uname -r | View examples |
| List recorded boots | journalctl --list-boots | View examples |
| Read previous boot errors | journalctl --boot=-1 --priority=warning --no-pager | View examples |
| Read current kernel boot log | journalctl --dmesg --boot --no-pager | View examples |
| Summarize boot time | systemd-analyze time | View examples |
| Show critical chain | systemd-analyze critical-chain | View examples |
| Rank unit activation time | systemd-analyze blame | View examples |
| Inspect initrd dependencies | systemctl list-dependencies initrd.target | View examples |
| List a dracut image | lsinitrd /boot/initramfs-$(uname -r).img | View examples |
| List an initramfs-tools image | lsinitramfs /boot/initrd.img-$(uname -r) | View examples |
| Print detected dracut arguments | dracut --print-cmdline | View examples |
| Inspect a newly built image | lsinitrd /tmp/initramfs-test.img | View examples |
| Boot to emergency target | systemd.unit=emergency.target | View examples |
| Pause in dracut initramfs | rd.break=pre-mount | View examples |
Linux boot crosses firmware, boot loader, kernel, initramfs, real-root transition, and the service manager. Troubleshoot by locating the failing boundary before changing configuration: preserve the failed boot's logs, read the effective command line, inspect the image paired with that kernel, and test one reversible hypothesis. Boot loader, storage, encryption, and initramfs changes can make a host unbootable, so retain a known-good kernel and verified rescue access.
Step by step
Detailed examples
Identify the last successful boot stage and exact artifacts
A blank display before the kernel starts, an initramfs storage prompt, an emergency shell, and a late failed service have different owners. Record firmware/loader status where available, the running or selected kernel release, command line, root filesystem identity, and initramfs filename. bootctl describes systemd-boot environments; its absence does not imply a boot fault on GRUB or other loaders.
uname -r
cat /proc/cmdline
findmnt --target / --output SOURCE,FSTYPE,OPTIONS
bootctl status 2>/dev/null || true Preserve evidence from the failed boot before it rotates
Persistent journal storage makes previous boots addressable by ID or offset. Start with warning priority, then expand around a concrete unit, device, or timestamp; priority filters can omit useful context. Kernel messages explain probing and root discovery, while userspace records show mounts, generators, dependencies, and service failures. Copy evidence off-host before rebuilding images or repeatedly rebooting.
journalctl --list-boots
journalctl --boot=-1 --priority=warning --no-pager
journalctl --dmesg --boot=-1 --no-pager
systemctl --failed --no-pager Distinguish a slow unit from the path that delayed readiness
systemd-analyze time summarizes broad phases. blame ranks activation duration but ignores whether work ran in parallel and can mislead for device units or Type=simple services. critical-chain follows ordering dependencies toward the selected target. Confirm suspected delays with unit status, dependencies, and monotonic journal timestamps before changing timeouts.
systemd-analyze time
systemd-analyze critical-chain
systemd-analyze blame | head -n 25
systemctl list-dependencies --after multi-user.target Inspect the image paired with the selected kernel
The initramfs must include drivers, firmware hooks, storage assembly, encryption, and configuration needed to discover the real root. Image naming and tooling differ: dracut commonly provides lsinitrd, while initramfs-tools provides lsinitramfs. Inspect rather than unpacking into a privileged directory, and compare the boot loader's selected kernel and image—not merely uname -r after a fallback boot.
lsinitrd /boot/initramfs-$(uname -r).img | grep -E 'crypt|lvm|mdraid|nvme'
# Debian/Ubuntu alternative:
lsinitramfs /boot/initrd.img-$(uname -r) | grep -E 'crypt|lvm|mdraid|nvme' Build a staged initramfs before replacing boot-critical files
Use the distribution's supported generator and configuration directories; dracut and initramfs-tools are not interchangeable. First verify free space, package/kernel alignment, root-device arguments, and required drivers. Generate to a separate path, inspect it, and only then use the distribution workflow to install it. Never overwrite the only known-good image, and update boot loader configuration only when that platform requires it.
df -h /boot /tmp
dracut --print-cmdline
sudo dracut --kver "$(uname -r)" --force /tmp/initramfs-test.img
lsinitrd /tmp/initramfs-test.img | less
# This creates a test image only; it does not make the system boot it. Use one-time recovery arguments and keep an exit route
Edit the boot entry for one boot rather than persisting experimental parameters. systemd.unit=emergency.target reaches a minimal userspace environment after root is available; dracut rd.break positions stop within supported dracut images. Recovery shells commonly run as root and may expose encrypted or sensitive storage. Mount filesystems read-only where possible, document every change, and reboot back to a known-good entry after testing.
# Add only in the boot loader's one-time editor; do not persist blindly.
systemd.unit=emergency.target
# On a dracut-based image, stop before the real root mount:
rd.break=pre-mount
# Remove the argument on the next boot after collecting evidence. Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



