Module 2 · Files and directories
File types, stat and what a file really is
The seven kinds of file Linux knows, the inode behind every name, and how to tell what a file contains when its extension lies.
What you will learn
- Read a file's type from the first character of `ls -l` and from `ls -F`.
- Explain what an inode is and see its number and metadata with `ls -i` and `ls -l --full-time`.
- Identify a file's real format from its first bytes with `head -c` and `od` or `hexdump`.
"In Unix, everything is a file" is half a slogan and half a design. Directories, terminals, disks, the random-number generator and the pipes between programs all appear in the filesystem with a name, and you open, read and write them with the same tools. They are not all the *same kind* of file, though, and the very first character of ls -l tells you which kind you are looking at.
| Char | Type | `ls -F` mark | Example here |
|---|---|---|---|
- | Regular file: text, image, program… | none (* if executable) | /etc/passwd |
d | Directory | / | /etc |
l | Symbolic link (a pointer to another path) | @ | /bin/sh -> busybox |
c | Character device (byte stream) | none | /dev/null, /dev/tty |
b | Block device (disk-like) | none | /dev/loop0 |
p | Named pipe (FIFO) | | | made with mkfifo |
s | Socket | = | none in this VM |
~% ls -l /etc/passwd /dev/null /dev/loop0 /bin/sh
lrwxrwxrwx 1 root root 7 Jun 3 2018 /bin/sh -> busybox
brw------- 1 root root 7, 0 Oct 7 20:01 /dev/loop0
crw-rw-rw- 1 root root 1, 3 Oct 7 20:01 /dev/null
-rw-r--r-- 1 root root 340 Jun 3 2018 /etc/passwd
~% ls -ld /etc
drwxr-xr-x 5 root root 0 Jun 3 2018 /etc
Names, inodes and metadata
A file is really two things. The inode is a record, identified by a number, that holds everything about the file except its name: type, permissions, owner, size, three timestamps and where the data lives. The name is just a directory entry pointing to an inode. That is why mv is instant (only the entry moves) and why one file can have several names, called hard links (lesson 91). ls -i shows the inode number; the second column of ls -l is how many names point to it.
The three timestamps are mtime (contents last modified; what ls -l shows), atime (last read; ls -lu) and ctime (inode last changed, for example by chmod; ls -lc). ls -l --full-time prints them to the second. On most distributions the stat FILE command dumps the whole inode in one go; this BusyBox build does not include stat, so here ls with these options is how you read the metadata.
What is inside: magic numbers
Linux does not care about extensions. photo.jpg can hold text and notes.txt can be a program; the name is only a hint for humans. Most binary formats, however, start with a fixed signature called a magic number, so the first few bytes reveal the truth. Read them with head -c 4 FILE | od -c or hexdump -C FILE | head -n 1. On full distributions the file command does this lookup for you; it is not installed here, which makes this a good moment to see how it works.
~% head -c 4 /bin/busybox | od -c
0000000 177 E L F
0000004
~% hexdump -C /root/lab/l19/files/photo.txt | head -n 1
00000000 89 50 4e 47 0d 0a 1a 0a 30 30 30 30 |.PNG....0000|
| First bytes | Format |
|---|---|
7f 45 4c 46 (\177 E L F) | Linux program (ELF) |
89 50 4e 47 (\211 P N G) | PNG image |
ff d8 ff | JPEG image |
1f 8b | gzip-compressed data |
#! | Script (the rest of the line names its interpreter) |
Commands in this lesson
| Command | What it does |
|---|---|
ls -l FILE | First character = file type. |
ls -F | Mark types: `/` dir, `@` link, `*` executable, `|` pipe. |
ls -i FILE | Show the inode number. |
ls -l --full-time FILE | Exact modification time (`-lu` atime, `-lc` ctime). |
head -c 4 FILE | od -c | Show the first bytes as characters. |
hexdump -C FILE | head -n 1 | First 16 bytes in hex and text. |
Quiz
`ls -l` shows `lrwxrwxrwx ... sh -> busybox`. What is `sh`?
- A directory
- A symbolic link pointing to `busybox`
- A copy of `busybox`
What does the leading `c` in `crw-rw-rw- ... /dev/null` mean?
- Compressed file
- Character device
- Copy-protected
Which of these is NOT stored in a file's inode?
- Its size
- Its name
- Its permissions
A file called `report.pdf` starts with the bytes `7f 45 4c 46`. What is it really?
- A PDF document
- A Linux program (ELF)
- A PNG image
Which `ls` option shows the inode number?
- `-i`
- `-n`
- `-F`
Practice
/root/lab/l19/box holds four entries: `alpha`, `beta`, `gamma` and `delta`. Exactly one of them is a symbolic link. Find out which and create an empty file with that same name inside /root/lab/l19/answer.
In /root/lab/l19/files, the names lie: `photo.txt`, `notes.png` and `data.jpg`. Exactly one of them is really a PNG image. Inspect their first bytes, then create an empty file with the PNG's name inside /root/lab/l19/answer.
Show the inode number of /etc/passwd.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.