Read

Module 4 · Finding things

find by size, time and permissions

The tests that make find a housekeeping tool: files bigger than a size, older than a number of days, or with dangerous permissions.

What you will learn

  • Select files by size with `-size` and its `+`/`-` and unit suffixes.
  • Select files by age with `-mtime`, `-mmin` and `-newer`.
  • Find permission problems with `-perm` and ownership with `-user`.

"The disk is full: what is big?" "What changed in the last hour?" "Which files can anyone write to?" These are the questions that bring administrators to find, and each has a test. They all share one convention for numbers: +N means more than N, -N means less than N, and plain N means exactly N. Combine them with the name and type tests from the last lesson.

Size

-size takes a number and a unit: c for bytes, k for kibibytes (1024 bytes), and b, the default, for old 512-byte blocks. find /var -size +100k lists everything over 100 KiB; -size +10k -size -100k is a range. GNU find also understands M and G, but the BusyBox one in this VM does not, so write megabytes as kibibytes: more than 1 MiB is -size +1024k. Because a forgotten unit means blocks, always write the unit.

Time

-mtime N looks at the modification time in whole days: -mtime +30 is "last changed more than 30 days ago" (old files you might archive), -mtime -1 is "changed within the last day". -mmin is the same in minutes: -mmin -60 is the last hour. -newer FILE compares with another file's timestamp, which is handy with touch: stamp a marker file, do something, then find / -newer marker shows exactly what changed in between.

Permissions and owner

Permissions are covered properly in module 5; for now it is enough to know they can be written as a number such as 644 or symbolically such as o+w (*others may write*). -perm 644 matches files with exactly that mode. -perm -MODE, with a dash, matches files that have at least those bits, whatever else is set: -perm -o+w (or -perm -002) finds world-writable files, a classic security check, and -perm -u+x finds files their owner can execute. -user NAME and -group NAME select by owner.

TestMeaning
-size +100kbigger than 100 KiB
-size -20csmaller than 20 bytes
-mtime +30modified more than 30 days ago
-mtime -1 / -mmin -60modified in the last day / hour
-newer REFmodified after REF was
-perm 644mode is exactly 644
-perm -o+wat least writable by others
-user rootowned by root
~% cd /root/lab/l36
l36% find data -type f -size +100k
data/huge.bin
data/large.bin
l36% find logs -type f -mtime +30
logs/jan.log
logs/mar.log
l36% find share -type f -perm -o+w
share/public.txt
share/run.sh

Commands in this lesson

CommandWhat it does
find DIR -size +100kLarger than 100 KiB (`c` bytes, `k` KiB).
find DIR -size +1024kLarger than 1 MiB (no `M` suffix here).
find DIR -mtime +30Not modified for more than 30 days.
find DIR -mmin -60Modified in the last hour.
find DIR -newer FILEModified after FILE.
find DIR -perm -o+wWorld-writable entries.
find DIR -user NAMEOwned by NAME.

Quiz

  1. What does `find . -size +100k` select?

    • Files of exactly 100 KiB
    • Files larger than 100 KiB
    • Files smaller than 100 KiB
  2. How do you ask this VM's `find` for files over 5 MiB?

    • `-size +5M`
    • `-size +5120k`
    • `-size >5mb`
  3. Which test finds files modified within the last 24 hours?

    • `-mtime +1`
    • `-mtime -1`
    • `-mtime 24`
  4. What is the difference between `-perm 666` and `-perm -666`?

    • None
    • The first needs exactly 666; the second at least those bits, so 777 also matches
    • The second excludes those permissions
  5. You `touch /tmp/marker`, install a program, then run `find / -newer /tmp/marker`. What do you get?

    • The files created or changed by the installation
    • Every file on the system
    • Only `/tmp/marker`

Practice

  1. Save into /root/lab/l36/big.txt the paths of the regular files under /root/lab/l36/data that are larger than 100 KiB.

  2. Save into /root/lab/l36/old.txt the paths of the files under /root/lab/l36/logs that were last modified more than 30 days ago.

  3. Security check: save into /root/lab/l36/writable.txt the paths of the files under /root/lab/l36/share that **anyone** (others) can write to, whatever their other permissions are.

Open this lesson in the app to do the tasks in a real Linux machine and have them checked.