linux

Exploring Linux File System

Exploring Linux File System in detail and going over each directory of file system

This post walks through the Linux file system and its directory structure: what each top-level directory is for, and why it’s laid out the way it is.

The layout is a published standard, the FHS, so /etc, /var, and /home mean the same thing on the major distributions.

What is a file system, and how does it work?

A file system is how files are named and placed on a storage device so you can find them again. Without one, a disk would just be one large block of data with no way to tell where anything begins or ends. A file system keeps that data organized and lets the computer retrieve it quickly.

A file system has two or three layers. Sometimes they’re kept separate; sometimes their jobs are combined.

  • Logical file system: handles interaction with applications, exposing an api for functions like OPEN, CLOSE, and READ. It also holds file and directory metadata, such as name, size, and file permissions (you can see these with ls -la -h). If a program doesn’t have access to a file or directory, this layer raises the error. It’s responsible for file access, directory operations, and security.

  • VFS (Virtual File System): an optional layer that sits on top of the real file system, acting as an interface between the kernel and whatever concrete file system is underneath. It’s what lets you access files across different file systems, for example, Windows reading a Linux file system and vice versa, without caring which one it’s actually talking to.

  • Physical file system: handles how physical blocks are read and written, including memory management and buffering. It decides exactly where on the disk your files get placed and how to use space efficiently. It’s also the layer that mostly talks to the device drivers for the underlying storage, whether that’s an HDD or an SSD.

Linux file system

Linux supports close to 100 file system types, old and new, including ext3, ext4, btrfs, and more. The most common one across Linux distributions is ext4.

The directory structure

On Linux, directories are structured as a tree. This layout is defined in the FHS (File Hierarchy Standard), maintained by the Linux Foundation and followed by major distributions.

The root / is the top of the file system (it contains everything the OS needs or uses).

bash
/├── bin ->; usr/bin├── boot├── dev├── etc├── home├── lib ->; usr/lib├── lib64 ->; usr/lib├── lost+found├── mnt├── opt├── proc├── root├── run├── sbin ->; usr/bin├── snap ->; /var/lib/snapd/snap├── srv├── sys├── tmp├── usr└── var20 directories, 0 files

The root, represented by /, contains everything.

Note: you can also think of a directory as a file that holds a bunch of addresses to other files.

Here’s what each of these top-level directories holds.

bin/

Short for binaries, this directory holds programs that live on the machine. It mostly contains executables. Here’s what a bin/ directory might look like.

bash
➜  ~ tree -L 1 /bin -C | tail -n 20├── znew├── zonetab2pot.py├── zoom ->; /opt/zoom/ZoomLauncher├── zramctl├── zresample├── zretune├── zsh├── zsh-5.8├── zsoelim ->; soelim├── zstd├── zstdcat ->; zstd├── zstdgrep├── zstdless├── zstdmt ->; /usr/bin/zstd├── zvbi-atsc-cc├── zvbi-chains├── zvbid└── zvbi-ntsc-cc

boot/

This directory contains the files the kernel needs at boot time, and the bootloader also lives here.

bash
/boot├── grub├── initramfs-linux-fallback.img├── initramfs-linux.img├── initramfs-linux-lts-fallback.img├── initramfs-linux-lts.img├── intel-ucode.img├── lost+found├── vmlinuz-linux└── vmlinuz-linux-lts

Notice that grub is also present in the boot/ directory.

sbin/

This directory holds the system binaries needed for system administration.

dev/

This directory represents each device attached to the system as a file. For example, your disk might show up as dev/sda, and a partition as dev/sda1. Drivers and applications usually access this folder.

etc/

etc/ is sometimes read as edit to configure, but it was also historically read as et cetera; you can read here about the history of the name.

This is where configs for system software live. For example, package managers like pacman or apt keep their config under etc/.

bash
➜  ~ tree -L 1 /etc | grep "pacman"├── pacman.conf

lib/

Short for libraries, this directory holds the libraries the system needs to boot and the ones different applications use to do their work.

media & mnt/

Both directories hold mounted drives, such as an external HDD or SSD. Use mnt/ when mounting things manually; media/ is where the OS mounts drives automatically.

opt/

This directory holds manually installed software, usually from the vendor.

Note: some software installed from a package manager might also live here.

bash
➜  ~ tree -L 1 /opt/opt├── Simplenote├── sublime_text_3└── zoom

For example, you can see zoom and sublime text here.

proc/

This directory mostly holds files with information about the hardware and the running processes on the system. Each process gets its own directory under proc/.

For example, here’s spotifyd (the Spotify daemon) represented as a process in proc/.

bash
➜  ~ ps aux | grep "spotifyd"hackerm+   98147  0.0  0.1 365184 13324 ?        Ssl  07:15   0:00 /usr/bin/spotifyd --no-daemon
bash
➜  ~ tree -L 1 /proc | grep "98147"├── 98147

root/

This is the home/ folder for the root user, and only a user with root permission can access it.

run/

This is a fairly new folder, and different Linux distributions use it in different ways. It’s mounted as a temporary file system (tmpfs), wiped on reboot or shutdown, and holds programs needed early in the boot process.

bash
➜  ~ tree -L 1 /run/run├── credentials├── cups├── dbus├── dhcpcd├── dmeventd-client├── media├── mount├── mysqld├── named├── NetworkManager├── nscd├── openvpn-client├── user├── utmp└── wpa_supplicant

srv/

Short for service, this directory holds files that external users access through, for example, an ftp server.

sys/

Also known as the system folder, this directory holds files that interact with the kernel. It’s created when the system boots.

bash
➜  ~ tree -L 1 /sys/sys├── block├── bus├── class├── dev├── devices├── firmware├── fs├── hypervisor├── kernel├── module└── power

tmp/

Applications store files here temporarily during a session. For example, a word processor like LibreOffice might save a temporary file here in case the program crashes or the system reboots.

usr/

This directory contains shareable, read-only files, including executable binaries, libraries, man files, and other documentation.

var/

Short for variable, this directory holds files and directories expected to grow, such as logs for databases, webservers, and emailboxes.

home/

This is the storage for user files. Each user has a subdirectory under /home, which is where you’ll find application settings as hidden directories, for example, browser cache in .cache/, and where your dotfiles live.

I’ve used Linux for more than 4 years, and I’ve always been curious about how its file system and directory structure work. This post is a high-level look at that: how a file system works in general, and how Linux lays out its directories specifically. I’m not going into detail on a specific file system like ext4 here; that’s a topic for another post.

If you think I missed anything, you can always DM me on twitter or email me. I’d love to hear your thoughts.