Learning bite
Mounts, space, and inodes
Identify which filesystem is constrained before proposing cleanup.
On this page
A path belongs to a mounted filesystem
An application writes through a path, but capacity and mount options belong to the filesystem underneath it. A full data filesystem can fail while the root filesystem still has space. Inspect the path the application actually uses.
Inside Linux, these are read-only inspections:
findmnt --target /var -o SOURCE,TARGET,FSTYPE,OPTIONS
df -h /var
df -i /var
du -sh "$HOME"
df -h reports filesystem block usage. df -i reports inode usage where applicable. Many tiny files can exhaust inodes even when bytes remain. du walks reachable files and measures their allocation; it does not use the same accounting as df.
Read the columns before deciding what is full
A mount point attaches a filesystem to a directory in the visible tree. /var may be a directory on /, or it may be the entry point to another filesystem. findmnt --target /var asks which mounted filesystem contains that path; it does not assume /var is a separate mount.
Here is illustrative output from df -h /var, not a measurement of your machine:
Filesystem Size Used Avail Use% Mounted on
/dev/vda2 20G 15G 4.0G 79% /
The target path is /var, but its containing mount is /. Size is filesystem capacity, Used allocated usage, and Avail the space reported as available to ordinary users. These columns may not add up as a simple subtraction because of filesystem accounting and reserved space. -h uses human-readable units; preserve the units in any note.
An inode stores a file's metadata and references to its data, not its directory-entry name. Some filesystems have a fixed pool of inodes. In a corresponding df -i result, IFree close to zero would warrant investigating file counts even if byte capacity remains. Other filesystems allocate inodes differently, so interpret the actual filesystem type.
Practice in your Linux home without adding load:
findmnt --target "$HOME" -o SOURCE,TARGET,FSTYPE,OPTIONS
df -h "$HOME"
df -i "$HOME"
du -sh "$HOME"
Compare the mount source and target with /var above. If both point to /, they share that filesystem's capacity. du -sh reports allocation reachable under the chosen directory; it does not report all users' space on the whole filesystem. It can also report read errors for inaccessible entries. A scan of a small known directory is easier to interpret than a whole-machine scan.
Explain disagreement
A deleted file can retain allocated space while a process still has it open. This is one reason df can report more usage than a directory walk. Permissions, reserved space, snapshots, and other mounts also affect the comparison. If available, an administrator can use lsof +L1 to investigate open unlinked files. Do not truncate a process's file descriptor as a routine remedy.
If the mount is read-only, deleting files is not the answer to the application's write failure. If quota is the limit, total filesystem free space may look healthy. Connect the exact error to the account, mount, and relevant constraint.
Practice without exhausting the host
Record the mount source, type, free bytes, and inode usage for your home directory and /var. Explain whether they share a filesystem. Do not generate millions of files or fill the VM disk; use the module's small fixture to learn the inspection sequence.
Match the symptom to the next check
Suppose a site cannot create an upload, / has space, and findmnt shows uploads are on a separate full mount. Cleaning a cache on / cannot free that other mount. First identify what owns the data on the upload filesystem, then choose an application-aware retention or expansion plan.
If the exact error is “Read-only file system,” inspect mount options and relevant system messages. If it is “Disk quota exceeded,” inspect that account's applicable quota. If it is “No space left on device,” inspect the actual mount's block and inode accounting. A successful write of one small fixture does not demonstrate enough capacity for an entire workload.
The storage lab creates two tiny files so you can compare byte length with allocated blocks. It deliberately does not reproduce exhaustion: understanding the counters does not require filling your host.
Check and revise
“The disk has 20 GB free, so ENOSPC is impossible.” What is missing? Inode and filesystem-specific accounting, the exact target mount, and possibly quotas. The percentage alone is not a diagnosis.
Revision: path → mount → bytes and inodes → owning workload → scoped remedy. Log retention, cache policies, and capacity expansion solve different causes.
Sources
Your notes and evidence
Record observations, questions, or links to your work. Keep credentials out of your notes.
Back up or restore this path
Progress and notes stay in this browser. A backup contains only this learning path.