<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Filesystem on Nalar</title>
    <link>https://nalar.dev/tags/filesystem/</link>
    <description>Recent content in Filesystem on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 01 Sep 2026 00:00:00 +0700</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/filesystem/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Find Hidden Linux Disk Usage with df, du, and lsof</title>
      <link>https://nalar.dev/find-hidden-disk-usage-with-df-du-and-lsof/</link>
      <pubDate>Tue, 01 Sep 2026 00:00:00 +0700</pubDate>
      <guid>https://nalar.dev/find-hidden-disk-usage-with-df-du-and-lsof/</guid>
      <description>&lt;p&gt;A Linux filesystem can report 95% usage in &lt;code&gt;df&lt;/code&gt; while &lt;code&gt;du&lt;/code&gt; appears to account for much less. The tools are not contradicting each other: they measure different things.&lt;/p&gt;&#xA;&lt;p&gt;&lt;code&gt;df&lt;/code&gt; asks the filesystem about allocated blocks. &lt;code&gt;du&lt;/code&gt; walks visible directory entries and sums blocks reachable through those paths. The gap between those views points to several useful troubleshooting cases.&lt;/p&gt;&#xA;&lt;h2 id=&#34;start-with-the-filesystem-view&#34;&gt;Start with the filesystem view&lt;/h2&gt;&#xA;&lt;p&gt;Check filesystems and their types:&lt;/p&gt;&#xA;&lt;div&#xA;  x-data=&#34;{ code: $el.querySelector(&#39;code&#39;).innerText, copied: false }&#34;&#xA;  class=&#34;code-block group relative my-6 overflow-hidden rounded-xl border border-line bg-surface-muted dark:border-night-line dark:bg-night-surface&#34;&gt;&#xA;  &lt;button&#xA;    type=&#34;button&#34;&#xA;    @click=&#34;navigator.clipboard.writeText(code); copied = true; setTimeout(() =&gt; copied = false, 1600)&#34;&#xA;    class=&#34;absolute right-3 top-3 z-10 rounded-lg border border-line-strong bg-surface px-2 py-1 font-mono text-[0.65rem] text-muted opacity-0 transition group-hover:opacity-100 hover:bg-ink hover:text-white dark:border-night-line dark:bg-night dark:text-night-muted dark:hover:bg-white dark:hover:text-ink&#34;&gt;&#xA;    &lt;span x-text=&#34;copied ? &#39;Copied&#39; : &#39;Copy&#39;&#34;&gt;&lt;/span&gt;&#xA;  &lt;/button&gt;&#xA;  &#xA;  &lt;div class=&#34;overflow-x-auto p-4 text-sm leading-6 [&amp;_pre]:!m-0 [&amp;_pre]:!bg-transparent [&amp;_pre]:!p-0 [&amp;_code]:font-mono&#34;&gt;&#xA;    &lt;div class=&#34;highlight&#34;&gt;&lt;pre tabindex=&#34;0&#34; style=&#34;background-color:#fff;-moz-tab-size:4;-o-tab-size:4;tab-size:4;&#34;&gt;&lt;code class=&#34;language-bash&#34; data-lang=&#34;bash&#34;&gt;&lt;span style=&#34;display:flex;&#34;&gt;&lt;span&gt;df -hT&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&#xA;  &lt;/div&gt;&#xA;&lt;/div&gt;&#xA;&lt;p&gt;Identify the mount that is actually full. Do not immediately scan recursively from &lt;code&gt;/&lt;/code&gt;; container mounts, network filesystems, and bind mounts can make that slow and misleading.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
