find by size, time and permissions
The tests that make find a housekeeping tool: files bigger than a size, older than a number of days, or with dangerous permissions.
What you will learn
- Select files by size with `-size` and its `+`/`-` and unit suffixes.
- Select files by age with `-mtime`, `-mmin` and `-newer`.
- Find permission problems with `-perm` and ownership with `-user`.
"The disk is full: what is big?" "What changed in the last hour?" "Which files can anyone write to?" These are the questions that bring administrators to find, and each has a test. They all share one convention for numbers: +N means more than N, -N means less than N, and plain N means exactly N. Combine them with the name and type tests from the last lesson.
Size
-size takes a number and a unit: c for bytes, k for kibibytes (1024 bytes), and b, the default, for old 512-byte blocks. find /var -size +100k lists everything over 100 KiB; -size +10k -size -100k is a range. GNU find also understands M and G, but the BusyBox one in this VM does not, so write megabytes as kibibytes: more than 1 MiB is -size +1024k. Because a forgotten unit means blocks, always write the unit.
Time
-mtime N looks at the modification time in whole days: -mtime +30 is "last changed more than 30 days ago" (old files you might archive), -mtime -1 is "changed within the last day". -mmin is the same in minutes: -mmin -60 is the last hour. -newer FILE compares with another file's timestamp, which is handy with touch: stamp a marker file, do something, then find / -newer marker shows exactly what changed in between.
Permissions and owner
Permissions are covered properly in module 5; for now it is enough to know they can be written as a number such as 644 or symbolically such as o+w (*others may write*). -perm 644 matches files with exactly that mode. -perm -MODE, with a dash, matches files that have at least those bits, whatever else is set: -perm -o+w (or -perm -002) finds world-writable files, a classic security check, and -perm -u+x finds files their owner can execute. -user NAME and -group NAME select by owner.
| Test | Meaning |
|---|---|
-size +100k | bigger than 100 KiB |
-size -20c | smaller than 20 bytes |
-mtime +30 | modified more than 30 days ago |
-mtime -1 / -mmin -60 | modified in the last day / hour |
-newer REF | modified after REF was |
-perm 644 | mode is exactly 644 |
-perm -o+w | at least writable by others |
-user root | owned by root |
~% cd /root/lab/l36
l36% find data -type f -size +100k
data/huge.bin
data/large.bin
l36% find logs -type f -mtime +30
logs/jan.log
logs/mar.log
l36% find share -type f -perm -o+w
share/public.txt
share/run.sh
Commands in this lesson
| Command | What it does |
|---|---|
find DIR -size +100k | Larger than 100 KiB (`c` bytes, `k` KiB). |
find DIR -size +1024k | Larger than 1 MiB (no `M` suffix here). |
find DIR -mtime +30 | Not modified for more than 30 days. |
find DIR -mmin -60 | Modified in the last hour. |
find DIR -newer FILE | Modified after FILE. |
find DIR -perm -o+w | World-writable entries. |
find DIR -user NAME | Owned by NAME. |
Quiz
What does `find . -size +100k` select?
- Files of exactly 100 KiB
- Files larger than 100 KiB
- Files smaller than 100 KiB
How do you ask this VM's `find` for files over 5 MiB?
- `-size +5M`
- `-size +5120k`
- `-size >5mb`
Which test finds files modified within the last 24 hours?
- `-mtime +1`
- `-mtime -1`
- `-mtime 24`
What is the difference between `-perm 666` and `-perm -666`?
- None
- The first needs exactly 666; the second at least those bits, so 777 also matches
- The second excludes those permissions
You `touch /tmp/marker`, install a program, then run `find / -newer /tmp/marker`. What do you get?
- The files created or changed by the installation
- Every file on the system
- Only `/tmp/marker`
Practice
Save into /root/lab/l36/big.txt the paths of the regular files under /root/lab/l36/data that are larger than 100 KiB.
Save into /root/lab/l36/old.txt the paths of the files under /root/lab/l36/logs that were last modified more than 30 days ago.
Security check: save into /root/lab/l36/writable.txt the paths of the files under /root/lab/l36/share that **anyone** (others) can write to, whatever their other permissions are.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.