Storage, filesystems, and inodes
Why a disk can be full while the files you can see are small, and the three distinct things "full" can mean.
Devices, filesystems, mounts
A disk (or a cloud volume) appears as a block device such as /dev/nvme0n1. It is divided into partitions or logical volumes. A filesystem such as ext4 or XFS is created on one of them, and it is mounted at a directory. From then on, everything under that directory lives on that filesystem. findmnt and lsblk show the tree. The operational consequence is that "the disk is full" really means "the filesystem holding this path is full". df -h /var/lib/waybill answers for the exact path you care about.
Names, inodes, and blocks
A traditional Unix filesystem separates three things:
- Directory entries map a name to an inode number.
- Inodes store metadata such as owner, mode, size, and timestamps, plus pointers to data.
- Data blocks hold the contents.
A file is deleted when its link count (the number of names) reaches zero and no process has it open. The second condition is the source of a famous incident.
Three different kinds of "full"
1. Bytes really are full. df -h and du -sh broadly agree. Find the consumer by walking down with du -xh --max-depth=1 /var | sort -h. The -x keeps you on one filesystem.
2. Deleted but open. Someone removed a 30 GB log, but the service still has it open and keeps writing. du no longer sees a name, while df still counts the blocks. lsof +L1 lists open files with zero links. The fix is to make the holder close the descriptor: reload or restart the service, or truncate through /proc/<pid>/fd/<n> if a restart is unacceptable. Deleting it "again" does nothing.
3. Inodes are full. Each file needs one inode, and on ext4 the number of inodes is fixed when the filesystem is created. A spool directory with millions of tiny files can use every inode while gigabytes of bytes remain free. df -i shows it. Creating files fails with the same "No space left on device" message, which is why this one gets misdiagnosed. Find the directory with the most entries, not the most bytes.
There is also a misleading kind of full. ext filesystems reserve about 5% of blocks for root, so ordinary users see 100% while root can still write.
Freeing space without making things worse
Space incidents tempt people into broad deletes. A safer order:
- Identify which filesystem is full and which kind of full it is.
- Find the consumer: a path from
du, a process fromlsof, or a directory with too many entries. - Check whether the data is evidence or state before removing it. Old logs may explain this incident, and a queue directory may hold undelivered work.
- Remove or compress named items and verify
dfmoved. - Fix the cause: rotation without a reopen, a job that never cleans up, a retention policy nobody set.
Growing a filesystem
When the data is legitimate, the fix is capacity. With LVM or cloud volumes you can usually grow the underlying device and then the filesystem online: lvextend, then resize2fs for ext4 or xfs_growfs for XFS. Shrinking is harder (XFS cannot shrink at all), so grow in modest steps and keep the reason in the change record.
Key terms
- Mount point
- A directory where a filesystem is attached to the tree. Everything below it lives on that filesystem until another mount takes over.
- Inode
- The on-disk record for a file, holding its metadata and the locations of its blocks. Filenames live in directories, not inodes.
- Link count
- How many directory entries name an inode. Space is freed when this reaches zero and no process holds the file open.
- Reserved blocks
- Space ext filesystems hold back for root (5% by default), so
dfcan show 100% for ordinary users while root can still write.
Read further
- How Linux Works, 3rd edition, Ch. 4, "Disks and Filesystems" (Purchase)
Partitions, filesystem creation, mounting,/etc/fstab, and the section on inodes and the structure of a traditional filesystem. Note what a directory entry stores and what an inode stores. - UNIX and Linux System Administration Handbook, 5th edition, Ch. 5, "The Filesystem" (Purchase)
The file tree, file types, link counts, and the discussion of removing a file that is still open. - UNIX and Linux System Administration Handbook, 5th edition, Ch. 20, "Storage" (Purchase)
The overview of the storage stack and the parts on logical volume management and filesystem resizing. Skim the hardware sections.