TT Lab
Get started
Learn Learning paths Courses

Storage and Mounts

Tracking Capacity and inodes

Continue in TT Lab

Goal

Create situations where df and du give different answers, and check how inode consumption, sparse files, and hard links affect capacity calculations.

Why it matters

df asks the filesystem, and du walks the directories and counts. So a file whose name is gone (removed with rm but still open by a process) is caught by df but not by du. The disagreement between the two values is itself a powerful clue. And to recover that file, you have to copy it from /proc/PID/fd before you restart the process — the moment you restart, the chance is gone. Even when capacity is urgent, your first action is copying.

Steps

  1. Create the /root/usage directory, and save the df -h output as /root/usage/df-block.txt and the df -i output as /root/usage/df-inode.txt.
  2. Sort the directory sizes under /root down to depth 1 from largest to smallest and save them as /root/usage/du-top.txt.
  3. Create 3000 empty files under /root/usage/many, and write the number of files in that directory, as a single number on one line, in /root/usage/filecount.txt.
  4. Create /root/usage/sparse.img as a 100MiB sparse file, and write its logical size and its actual usage, one per line (in bytes, logical first), in /root/usage/sparse.txt. The two values must differ.
  5. Create a file that was deleted but is still open. Write at least 5MiB to /root/usage/ghost.log, start a background process that keeps that file open, and then remove the file name. Then save the line in which (deleted) appears in that process's /proc/<PID>/fd listing to /root/usage/deleted.txt.
  6. Write 1MiB to /root/usage/orig.dat and create a hard link /root/usage/link.dat. Write the inode number and the link count of the two files in /root/usage/hardlink.txt in the format <inode> <링크수> (inode, then link count), one line for each. The inodes on the two lines must be the same.
  7. Save the files under /root/usage whose size is 1MiB or more to /root/usage/big.txt, in descending order of size, in the format <바이트> <경로> (size in bytes, then path).
  8. Create /root/usage/report.txt with the following 4 lines. FILES=<3번 값> / SPARSE_DIFF=yes / GHOST_PID=<5번에서 파일을 열고 있는 프로세스의 PID> / SAME_INODE=yes (the placeholders are the value from step 3 and the PID of the process that has the file open in step 5)

Notes

Block and inode usage

Create the /root/usage directory, and save the df -h output as /root/usage/df-block.txt and the df -i output as /root/usage/df-inode.txt.

df has a separate option for human-readable units and a separate option for looking at inodes.

Find the big directories

Sort the directory sizes under /root down to depth 1 from largest to smallest and save them as /root/usage/du-top.txt.

If you limit the depth, you can narrow down from the top. Use the option that keeps it from crossing into other filesystems as well.

Create many small files in bulk

Create 3000 empty files under /root/usage/many, and write the number of files in that directory, as a single number on one line, in /root/usage/filecount.txt.

Counting files and looking at inode usage are different things. Compare before and after creation.

The two sizes of a sparse file

Create /root/usage/sparse.img as a 100MiB sparse file, and write its logical size and its actual usage, one per line (in bytes, logical first), in /root/usage/sparse.txt. The two values must differ.

du counts actual usage by default. To see the logical size, you need a separate option.

Reproduce a deleted open file

Create a file that was deleted but is still open. Write at least 5MiB to /root/usage/ghost.log, start a background process that keeps that file open, and then remove the file name. Then save the line in which (deleted) appears in that process's /proc/<PID>/fd listing to /root/usage/deleted.txt.

Keep the process that has the file open running in the background and then remove only the name. A marker remains on the fd symlink under /proc.

Hard links and du

Write 1MiB to /root/usage/orig.dat and create a hard link /root/usage/link.dat. Write the inode number and the link count of the two files in /root/usage/hardlink.txt in the format <inode> <링크수> (inode, then link count), one line for each. The inodes on the two lines must be the same.

Check how many times du counts when several names point to the same inode. You see the link count with stat.

List of big files

Save the files under /root/usage whose size is 1MiB or more to /root/usage/big.txt, in descending order of size, in the format <바이트> <경로> (size in bytes, then path).

The -size of find accepts unit suffixes. To print the size and the path together, use -printf.

Capacity investigation report

Create /root/usage/report.txt with the following 4 lines. FILES=<3번 값> / SPARSE_DIFF=yes / GHOST_PID=<5번에서 파일을 열고 있는 프로세스의 PID> / SAME_INODE=yes (the placeholders are the value from step 3 and the PID of the process that has the file open in step 5)

Gather the results of the earlier steps as key=value. You can get the size of a deleted open file by running stat on its /proc path.