OnCallReady

Lesson 1.3 · First Login · 22 min read

The tree

In plain words

Picture one giant tree. Every branch, twig and leaf grows from a single trunk, and you describe any leaf by the route from the trunk: trunk, big branch, small branch, leaf. You can also describe it from where you are sitting: "two twigs up from me, then left".

Linux files work the same way. The trunk is /. A full route like /var/log/syslog is an absolute path and means the same from anywhere. A route like log/syslog is relative to where you stand, which pwd tells you. Even extra disks are just new branches grafted onto the same tree, never a separate tree with a letter like C:. ls -la is you looking at one branch closely, including the leaves whose names start with a dot.

A teammate says "the config is in /etc/nginx, the logs are in /var/log". With no Finder window, you need to get there by typing, see what is there, and read the one line ls prints about each file. This lesson is that.

What you need to know already: 1.1 Where you are (prompt, home directory, ~).

Files, directories, paths

A file holds data: text, a program, an image. A directory is a folder: it holds files and other directories. A path is the address of a file, written as directory names joined by /: /var/log/syslog means "the file syslog, in the directory log, in the directory var, at the top".

One tree, no drive letters

Everything hangs off one top directory called / (say "root" - not the same thing as the root user). A USB stick, a second disk, a network share - they all appear inside the tree, at a directory called a mount point (lesson 1.20). There is no C:, and there is no "outside the tree".

/            the top of everything
├── etc      configuration. Plain text files. You will live here.
├── var      data that changes: logs, databases, caches
├── home     users' home directories - /home/learner
├── usr      installed programs and their files
├── proc     not on any disk: the kernel's live view of running programs
└── srv      data this machine serves to others

Moving around: pwd, cd, ls

The extra words after a command (/var/log in cd /var/log) are its arguments: what the command should work on.

Absolute vs relative

An absolute path starts with /: /var/log/syslog. It means the same thing no matter where you are standing.

A relative path does not start with /: log/syslog means "from wherever I am now". Standing in /var, it means /var/log/syslog. Standing in your home, it means /home/learner/log/syslog - probably nothing. This is exactly how the day-one "second labs folder" bug happened (next lesson).

Four shorthands worth knowing cold:

Reading ls -l

ls -l (long format) prints one line per file with its details:

drwxr-xr-x 2 learner learner 4096 Sep 14 17:43 labs
│└┬┘└┬┘└┬┘ │ └──┬──┘ └──┬──┘ └─┬┘ └────┬───┘ └┬─┘
│ │  │  │  │    │       │      │       │      name
│ │  │  │  │    │       │      │       last modified
│ │  │  │  │    │       │      size in bytes
│ │  │  │  │    │       group that owns it
│ │  │  │  │    user that owns it
│ │  │  │  link count (how many names point at it)
│ │  │  what everyone else may do
│ │  what members of the group may do
│ what the owner may do
type: - file, d directory, l symlink

Column by column:

So drwxr-xr-x ... learner learner ... labs reads: "a directory called labs, owned by learner; learner may read, write and enter it; the group and everyone else may only read and enter".

Permissions as numbers (octal)

People and tools often write those nine letters as three digits. Each letter has a value - r = 4, w = 2, x = 1 - and you add them per group of three:

rwx = 4+2+1 = 7      rw- = 4+2 = 6      r-x = 4+1 = 5      r-- = 4      --- = 0
rwxr-xr-x  = 755     rw-r--r--  = 644     rw-------  = 600

This is called octal notation (each digit is 0 to 7). Chapter 4 goes deep on permissions; for now, just be able to read them.

Hidden files are a convention, not a feature

A file whose name starts with . (a dotfile) is skipped by ls. Nothing more - it is not protected or secret. ls -a (all) shows them. Your shell settings, your SSH keys and your git identity all live in dotfiles in your home directory.

Flags can be combined: ls -la is -l and -a together.

. and .. also show up in ls -a, because they are real entries in every directory. That is why a brand-new directory has a link count of 2: its name in the parent, plus its own .. Each subdirectory adds one more (its .. points back).

ls flags you will actually combine

$ ls -la ~            long format, including dotfiles
$ ls -lh /var/log     -h: human sizes - 4.0K, 2.1M instead of raw bytes
$ ls -lt              -t: sort by time, newest first
$ ls -ltr             -r: reverse it - oldest first, newest at the bottom
$ ls -lS              -S: sort by size, largest first
$ ls -ld /etc         -d: the directory ITSELF, not what is inside it
$ ls -1               -1: one name per line, nothing else

ls -ld is the one people forget. Without -d, ls -l /etc lists everything inside /etc; with it you get the line for /etc itself:

$ ls -ld /tmp /etc
drwxr-xr-x 12 root root 4096 Sep 14 17:43 /etc
drwxrwxrwt  2 root root 4096 Sep 22 20:00 /tmp

That trailing t on /tmp is a special permission (the sticky bit) - chapter 4.

The errors, and what they mean

$ cd /nope
bash: cd: /nope: No such file or directory
$ cd /etc/hostname
bash: cd: /etc/hostname: Not a directory
$ cd /root
bash: cd: /root: Permission denied
$ ls /nope
ls: cannot access '/nope': No such file or directory

The first word tells you who is complaining. bash: cd: is the shell itself, because cd is a builtin (a command built into the shell, not a separate program). ls: is the ls program. The part after the last colon is the kernel's standard error text - the same few strings everywhere: No such file or directory (nothing at that path), Permission denied (it exists, you may not), Not a directory (you treated a file as a folder), Is a directory (the reverse). Read them as facts, not noise.

What kind of file is this?

$ file /usr/bin/ls /etc/passwd /sbin/init
/usr/bin/ls: ELF 64-bit LSB pie executable, ARM aarch64, ...
/etc/passwd: ASCII text
/sbin/init: symbolic link to ../lib/systemd/systemd

file looks at what is inside a file, not its name - Linux does not care about extensions like .txt. "ELF ... executable" means a compiled program (ELF is the format Linux programs use); "ASCII text" means plain text.

stat prints every detail ls -l summarises. stat -c FORMAT prints only the fields you ask for - handy for checking one thing:

$ stat -c '%A %a %U:%G %s %n' /etc/passwd
-rw-r--r-- 644 root:root 969 /etc/passwd

(%A permissions as letters, %a as octal, %U:%G owner:group, %s size, %n name.)

What you can now do

Why it helps

Reading ls -l fluently is the first thing you do on any "Permission denied" problem: owner, group, permissions, and whether the thing is a directory or a symlink are all on that one line. Knowing ls -ld versus ls -l stops you misreading a directory's own permissions when a program cannot write into it.

The error strings pay off too. No such file or directory means nothing is at that path - often a typo or a relative path from the wrong place. Not a directory means some part of the path is a file. Permission denied means it exists but you may not. Knowing them as facts turns a vague failure into a one-line fix.

Commands in this lesson

ls cd file stat

FAQ

What is the difference between ~ and /home/learner?

For you, nothing: the shell replaces ~ with the value of $HOME, which is /home/learner. The difference shows up when someone else runs it: as root (sudo -i) ~ becomes /root. Also, only the shell replaces ~, and only when it is unquoted at the start of a word, so "~/x" in quotes is taken literally.

Why does a new empty directory have a link count of 2?

A directory's link count is the number of names pointing at it. One is its entry in the parent (labs inside oncall-lab), the other is its own . entry. Every subdirectory adds one more, because each child's .. points back to it. So a directory's link count minus 2 is its number of subdirectories. For files, the count is the number of names (hard links) a file has, which chapter 4 uses.

Is a dotfile hidden for security?

No. The leading dot only tells ls and wildcards like * to skip it by default. Anyone who can read the directory sees it with ls -a. Protection comes from permissions: ~/.ssh is safe because only you may enter it and only you may read the key, not because of the dot. Note that rm -rf * also skips dotfiles, a surprise when "cleaning" a directory.

Why does ls say "cannot access" but cd says "No such file or directory" with a different prefix?

The prefix names who is complaining. cd is a shell builtin, so bash reports it as bash: cd:. ls is a separate program, so it puts its own name first and its own wording. The text after the last colon is the kernel's standard message for what went wrong. Same problem, same final words, whichever program hit it.

Does Linux care about file extensions?

The kernel does not. Whether a file can run depends on its execute permission and its content: a compiled program, or a text script whose first line names the program that should run it. file inspects the content to tell you what it is. Some programs do only read files with a certain ending by convention (for example only *.conf files in a settings directory), so a correct file with the wrong name can be silently ignored.

In an interview Junior

Explain every field of an ls -l line.

Take drwxr-xr-x 2 learner learner 4096 Sep 14 17:43 labs:

Gotcha: ls -l /etc lists what is inside /etc; ls -ld /etc gives the line for the directory itself. stat prints every detail.

Also asked: What is the difference between an absolute and a relative path, and when does it bite you? · What does "Permission denied" tell you, compared with "No such file or directory"? · What are hidden files in Linux, and how do you see them?

Practise this lesson in the terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.