LFCS — Linux Foundation System Administrator
When Does the Shell Do It For You
In one line
Most of the reasons a command behaves differently from what you expect on the exam come not from the command but from what the shell did before it ran the command. When expansion happens, file descriptors, and the expression syntax of find — these three are the backbone of the essential commands domain.
Why this exists
You ran rm -f /var/log/*.gz and the files are not deleted. You suspect rm, but the culprit is not rm. The one that turns a wildcard into an actual list of files is the shell, and the shell finishes that job before calling the command. If no file matches, the shell passes the literal text *.gz as the argument, and rm answers that no file has that name.
The meaning of quotes splits here too. Double quotes keep variable expansion alive and block only word splitting and filename expansion. Single quotes block everything. When you handle a path that contains a space and leave out the double quotes, one argument is split into two. That is why the exam has problems with spaces in paths.
How it works
Redirection is file descriptor manipulation. Every process starts with 0 (standard input), 1 (standard output), and 2 (standard error). > out.txt means "change where descriptor 1 points to this file", and 2>&1 means "duplicate descriptor 2 to wherever 1 points right now".
The reason order matters is exactly this "right now".
| Notation | Result |
|---|---|
cmd > f 2>&1 |
Change 1 to f, then duplicate 2 to f → both go to the file |
cmd 2>&1 > f |
Duplicate 2 to the terminal, then change only 1 to f → errors go to the screen |
find is not a command but an expression language. -name, -size, -mtime, and -perm are not options but predicates that return true or false, and when you list them they are joined by an implicit AND. -print and -exec are predicates too, just predicates with side effects. So if you use -o for OR and leave out the parentheses, the precedence goes wrong and the wrong files get caught.
Numeric arguments come with a sign rule. -mtime 30 means "exactly the 30-days-ago interval", -mtime +30 means "older than 30 days", and -mtime -30 means "within 30 days". -perm 644 is an exact match, -perm -644 includes all of those bits, and -perm /644 includes at least one of them. This is the spot where the most points are lost on the exam.
What it looks like in the field
The author's write-up on file descriptors has a case like this. A log file was deleted by mistake, but the process that had it open was still alive. The directory entry was gone, but even when the link count reaches 0, the kernel does not reclaim the blocks while an open descriptor remains. So simply copying /proc/<PID>/fd/<번호> (the placeholder is the descriptor number) was enough to restore the content. Conversely, using the same property you can empty the space while keeping the process alive with truncate -s 0 /proc/<PID>/fd/<번호>, but if you pick the wrong number, a perfectly healthy file is gone.
In pipelines, yes | head -1 is the textbook case. When head finishes first, yes writes to a pipe with no reader and dies from SIGPIPE. That is normal behavior. And one principle the author's shell articles stress repeatedly — do not parse ls output; iterate with a glob. The moment a file name contains a space or a newline, parsing ls is silently wrong.
Keeping your hands from freezing in the exam room
The LFCS is an exam where you solve tasks by hand in two hours, so knowing something and typing it within the time limit are different things. If you get just a few things into your fingers, the time shrinks a lot.
Decide where you will look at documentation. There is no internet, but there are man and --help.
If you only learn to search with / inside man and go to the next match with n, finding one option takes a few seconds. And if you do not
know that you can find a command backward from a word with man -k, you spend minutes on a single command whose name you cannot remember.
Check what cannot be undone first. rm, mkfs, dd, and > do not ask.
Redirection in particular empties the target file the moment you press enter, before the command runs. So a form that reads the original
and writes to the same file always destroys the content. Go through an intermediate file or use an in-place editing option.
Take a copy before you change anything. When you edit a configuration file, making a dated copy takes 2 seconds, and without it reverting takes minutes. It is the same in the exam and in practice.
Verification is part of the task. A task that says to turn on a service has two different settings, the one running now and the one that comes up after a reboot, and they ask about both. A task that says to create a user usually includes the shell, the home directory, and the group. The 30 seconds you spend checking once more at the point where you think you have answered is far cheaper than finding the wrong answers after you have solved everything.
Finally, if you get stuck, move on. Scoring is partial credit, so while you cling to one task, two tasks you could have solved slip by. When you move on, note what you left behind, and come back if time remains.
What you will do in the next lab
You build a directory tree in /root/lfcs-ess/ and check for yourself the inode difference between hard links and symbolic links. You combine find with size, time, and permission conditions to pull lists, compress the same directory with gzip and xz and compare the sizes. At the end you create a patch with diff -u and apply it to a copy. In the following lab you process a log you made yourself with grep, sed, awk, jq, and yq.