Filesystem Hierarchy

Filesystem Hierarchy

Concepts

The Filesystem Hierarchy Standard (FHS)

Linux follows the Filesystem Hierarchy Standard — a convention that defines where files should go. Every Linux distribution (including Ubuntu and Debian) follows this structure. Once you know it, you can find your way around any Linux system.

Top-Level Directories

/
├── bin       → essential user commands
├── boot      → bootloader and kernel
├── dev       → device files
├── etc       → system configuration
├── home      → user home directories
├── lib       → shared libraries
├── media     → removable media mount points
├── mnt       → temporary mount points
├── opt       → optional/third-party software
├── proc      → process information (virtual)
├── root      → root user's home directory
├── run       → runtime data (virtual)
├── sbin      → essential system commands
├── srv       → service data
├── sys       → kernel/hardware information (virtual)
├── tmp       → temporary files
├── usr       → user programs and data
└── var       → variable data (logs, caches, mail)

Directory-by-Directory Breakdown

/ — The Root

The top of the tree. Everything is under /. Do not confuse it with /root (the root user’s home directory).

[Read more]

Filesystems and Mounting

Filesystems and Mounting

Concepts

What Is a Filesystem?

A filesystem organizes data on a partition — it defines how files are stored, named, and retrieved. Without a filesystem, a partition is just raw bytes.

Filesystem Description Default On
ext4 Standard Linux filesystem. Reliable, mature, well-supported. Ubuntu, Debian
xfs High-performance, good for large files. RHEL, CentOS
btrfs Modern, supports snapshots, compression, RAID. openSUSE, Fedora (optional)
vfat/FAT32 Simple, cross-platform. Max file size 4GB. USB drives, EFI partitions
ntfs Windows filesystem. Linux has read/write support. Windows drives
tmpfs Lives in RAM, not on disk. Fast, cleared on reboot. /tmp, /run

Creating a Filesystem

sudo mkfs.ext4 /dev/sdb1          # ext4
sudo mkfs.xfs /dev/sdb1           # XFS
sudo mkfs.vfat /dev/sdb1          # FAT32
sudo mkfs.btrfs /dev/sdb1         # Btrfs

# With a label
sudo mkfs.ext4 -L "mydata" /dev/sdb1

Warning: mkfs erases all data on the partition.

[Read more]

find, locate, and xargs

find, locate, and xargs

Concepts

find — Search for Files by Criteria

find walks the directory tree and tests each file against your criteria. It is powerful, flexible, and available everywhere.

find [starting-path] [tests] [actions]

Search by Name

# Find by exact name
find /etc -name "hosts"

# Case-insensitive
find /home -iname "readme*"

# Wildcards (must be quoted to prevent shell expansion)
find . -name "*.log"
find . -name "*.txt" -o -name "*.md"     # -o = OR

Search by Type

find /var -type f          # regular files
find /var -type d          # directories
find /var -type l          # symbolic links

Search by Size

find /var/log -size +10M        # larger than 10 MB
find . -size -1k                # smaller than 1 KB
find . -size +100M -size -1G    # between 100 MB and 1 GB
# Units: c=bytes, k=KB, M=MB, G=GB

Search by Time

# Modified time (days)
find /tmp -mtime -1       # modified in the last 24 hours
find /tmp -mtime +30      # modified more than 30 days ago

# Accessed time
find . -atime -7          # accessed in the last 7 days

# Modified time (minutes)
find . -mmin -60          # modified in the last 60 minutes

# Newer than a file
find . -newer reference.txt

Search by Permissions and Ownership

# Exact permission
find /usr -perm 755

# At least these permissions set
find . -perm -644

# Owned by user
find / -user kmiguel 2>/dev/null

# Owned by group
find / -group www-data 2>/dev/null

# Files with no owner (orphaned)
find / -nouser 2>/dev/null

Search by Depth

find . -maxdepth 1 -name "*.txt"    # current directory only
find . -maxdepth 2 -type d          # at most 2 levels deep
find . -mindepth 2 -name "*.conf"   # skip the first level

Combining Tests

# AND (default) — both must be true
find . -name "*.log" -size +1M

# OR
find . -name "*.jpg" -o -name "*.png"

# NOT
find . ! -name "*.tmp"
find . -not -user root

# Grouping with parentheses (must be escaped)
find . \( -name "*.log" -o -name "*.tmp" \) -mtime +30

Actions

# Default action: -print (show the path)
find . -name "*.txt"

# Delete matching files
find /tmp -name "*.tmp" -delete

# Execute a command on each result
find . -name "*.log" -exec ls -lh {} \;
# {} is replaced by the filename. \; ends the command.

# Execute with confirmation
find . -name "*.bak" -ok rm {} \;

# More efficient: pass multiple files at once (like xargs)
find . -name "*.txt" -exec grep -l "TODO" {} +
# {} + passes as many files as possible in one command invocation

locate searches a pre-built database, making it much faster than find — but the database may be stale.

[Read more]

Firewall Deep Dive

Firewall Deep Dive

Prerequisite — Packet Filtering Refresher: A firewall examines network packets and decides whether to accept, drop (silently ignore), or reject (refuse with a response) each one. Linux’s built-in firewall lives in the kernel (netfilter). Tools like ufw, iptables, and nftables are user-space interfaces for configuring it. This lesson builds on the firewall introduction in Module 09.

Concepts

ufw — Uncomplicated Firewall

ufw is the default firewall frontend on Ubuntu (also available on Debian). It provides a simple command-line interface over iptables/nftables.

[Read more]

Firewalls

Firewalls

Prerequisite: A firewall filters network traffic based on rules. It decides which incoming and outgoing connections to allow or block. Think of it as a bouncer for your network ports.

Concepts

Linux Firewalls — The Stack

Linux has a built-in firewall in the kernel. The tools to manage it form a stack:

User-friendly  →  ufw (Ubuntu)
                    ↓
Mid-level       →  nftables (modern) / iptables (legacy)
                    ↓
Kernel          →  netfilter (the actual firewall engine)
  • netfilter — the kernel framework that does the actual filtering
  • nftables — the modern userspace tool to configure netfilter (replaces iptables)
  • iptables — the legacy tool (still works, uses nftables backend on modern systems)
  • ufw — “Uncomplicated Firewall” — a simple frontend for iptables/nftables

Ubuntu: Ships with ufw (disabled by default). Simple and recommended for most users. Debian: Ships with nftables. No high-level frontend by default. You can install ufw.

[Read more]