Linux File System

Before going into the world of Linux, and how it works under the hood. We should know what linux is actually ? -for a nerd, not you don't worry. Or you should worry bro !
Imagine your computer is like a restaurant.
The hardware (screen, keyboard, processor, memory) is the building, kitchen, tables, and equipment.
The apps (browser, games, Word, Spotify) are the meals customers order.
The operating system is the manager running the whole restaurant — making sure orders go to the kitchen, staff work together, and everything happens smoothly.
Linux is one type of operating system — just like Microsoft Windows and macOS.
Basically,
Linux is software that runs a computer and tells all the parts what to do.
Linux helps your computer to start up, open programs, connect to wifi, save files, manage memory and servers, etc.
Now you know what Linux is, if not read it again SIR :) .
What is Linux File System?
Now you may wonder what is file system, something like a download folder you are using - umm.. yes but no! not exactly that.
Think of linux as a big organized house of someone who has OCD - He wants everything managed in a proper folder.
So the filesystem is the map of that house and Files are where Linux stores instructions, settings, and facts, Folders group those files by purpose.
Many things in Linux that do not look like normal files are still shown as if they are files. That is one of Linux’s most important ideas.
That means:
your users are described in files
network behavior is influenced by files
running processes are exposed through files
devices are represented like files
logs are stored in files
So when i said that “Linux works through files,” i meant it dude ;)
Some basic Ideas/Terminologies
Everything is arranged under one root, Linux does not use separate drives like
C:orD:in the main view.It starts from one top-level location:
/Everything lives under it, and they have there roles:
/etc= system settings/home= user files/var= changing data like logs/boot= boot-related files/dev= devices/proc= live process and kernel info
So Linux is like one giant tree, and
/is the trunk.A “file” in Linux is not always a normal document. Some files are normal stored data, like config files or logs.
But some “files” are special:
a device can appear as a file in
/devlive process info can appear as files in
/prockernel/system info can appear as files in
/sys
So Linux often gives you information and control through the same interface: read a file, write a file, inspect a file.
Now Let's Hunt guys ➶➴, Get ready with you weapons.
The Hunt Begins
Here are few of the interesting things, i found about the linux file system.
1. /etc/hosts is a local truth source that can override DNS.
This file is a plain text OS file that maps hostnames to IP addresses, acting as a local, manual DNS lookup table.
Example idea:
127.0.0.1 localhost
It overrides DNS, allowing users to map domains to specific IP addresses before querying network name servers. It is primarily used for local web development, testing, and blocking websites.
So basically this file is a local phonebook of your system, just as the DNS is for the whole internet.
The Problem
DNS is a network service, that means DNS depends on:
network connectivity
working DNS servers
correct routing
correct resolver behavior
But some names are too important to depend entirely on the network. Linux therefore keeps a local fallback and override mechanism.
One interesting insight
Linux also has a file called:
/etc/nsswitch.conf
It contains something like hosts: files dns, that means check local files first (/etc/hosts) and only then ask DNS.
2. How does Linux turn names into reachable destinations?
The /etc/resolv.conf file in Unix-like systems configures the DNS resolver, defining which DNS servers the system uses to turn hostnames into IP addresses. It is frequently autogenerated by tools like systemd-resolved or NetworkManager, meaning manual edits may be overwritten. Use nameserver <IP> to define DNS servers.
Let's understand the gibberish above.
So,
/etc/resolv.conf — The Small File That Decides How Linux Finds the Internet. Usually only a few lines, sometimes just one.
Example structure:
nameserver 8.8.8.8
nameserver 1.1.1.1
search company.internal
This means: ask this server for hostname answers and Linux queries these sequentially.
What this file does
It provides DNS resolver configuration.
Mainly:
DNS server addresses
search domains
timeout behavior
retry rules
Without it, Linux may know how to send packets but not how to find destinations by name.
One interesting insight
/etc/resolv.conf Is Often Not “Owned” By You. That means :
You edit it. Then later... Your changes disappear.
But Why?
That's because On modern Linux, this file may be controlled by System Networking & Container Services like DHCP client, NetworkManager, systemd-resolved, VPN software, cloud-init, WSL, etc.
This is allowed because When you move between networks such as home WiFi, office network, VPN, cloud environment, hotspot the DNS server often changes.
Linux therefore allows automated ownership of resolver config.
3. Linux Exposes Routing Decisions as a File
You might think that routing belongs to networking tools. But Linux exposes routing through a filesystem entry:
/proc/net/route
This is important because it reveals a major Linux philosophy: Even live kernel networking decisions can appear as readable files.
What this file does
This file shows the routing table. A routing table answers one question: “Which road gets me closer to destination?” Routing table is the decision map.
Every outgoing network connection depends on this decision.
Linux must decide which interface to use, which gateway to send through, and whether destination is local or remote. /proc/net/route exposes that logic.
Note that : it does not exist on disk; instead, the kernel generates its content dynamically every time you read the file.
4. Linux Separates “What Exists” From “How It Is Configured”
Linux separates "what exists" (physical/virtual hardware detection) from "how it is configured" (system settings, driver behavior, and state) to provide a modular, portable, and transparent operating system. This separation is achieved through a, virtualized file system (/sys, /proc, /dev) that acts as a bridge between the kernel and user space, allowing components to be identified, added, or removed without affecting the overall system configuration.
Beginners often imagine networking as: “The machine has internet.” but Linux does not think this way. Linux thinks in interfaces.
An interface is simply: a network attachment point
Examples:
wired Ethernet
Wi-Fi
VPN tunnel
virtual adapter
container bridge
loopback device
Linux does not connect “the system” to a network. Linux connects interfaces to networks. And the filesystem reveals how that works.
What Network Interface Configuration Means
A network interface has identity. Linux must know: what interfaces exist, their names, their addresses, whether they are active, which routes belong to them, and how they should start.
This information lives across multiple places.
Interfaces Are Treated Like Devices
Linux exposes interfaces through:
/sys/class/net
This is extremely interesting. Why?
Because networking devices are represented like filesystem objects.
You might see entries such as:
eth0
lo
wlan0
docker0
tun0
Each folder represents a real interface. This tells us something deep: Linux treats networking as part of device management.
So basically devices are discoverable through filesystem structure.
5. /var/log — Linux Keeps a Memory of What Happened
It can be said that Linux rarely “mysteriously fails.” because Most of the time, Linux leaves clues. And those clues live here :
/var/log
This directory is a historical record of system behavior.
What
/var/logDoes
This directory stores logs (a timeline of events). Linux writes records about:
services starting
authentication attempts
crashes
kernel events
package installs
network activity
errors
warnings
background jobs
/var/log/auth.log - a security goldmine. but why?
That's because it keeps the track of all the Authentication history that includes: login attempts, sudo usage, SSH authentication, failed passwords, privilege escalation etc.
Also Linux logs are usually append-only.
6. Linux stores user identity in plain filesystem records
Linux stores user identity in plain filesystem records by utilizing flat, human-readable text files within the /etc/ directory, primarily /etc/passwd and /etc/shadow. These files act as the local database for user accounts, providing essential information to the operating system for authentication and file authorization.
This is how Linux handles user identity in plain files:
/etc/passwd (User Metadata): This file stores public user information, readable by all users but modifiable only by root. It lists user accounts with one record per line, delimited by colons. Each line contains:
username:password_placeholder:UID:GID:GECOS:home_directory:login_shell- /etc/shadow (Secure Credentials): To enhance security, encrypted password hashes and password aging information are stored in
/etc/shadow. This file is strictly restricted to root-only access./etc/group (Group Identity): Similarly, user groups are defined in a plain text file,
/etc/group, which maps group names to Group IDs (GIDs) and lists their members.
Why this exist ?
Linux is multi-user by design. Even if only one person uses the machine, Linux assumes:
many users
different privilege levels
shared resources
permission boundaries
The system therefore needs a structured identity model and these files are that model.
7. Linux Exposes Running Reality As Files
The /proc directory in Linux is a virtual filesystem (often called procfs) that acts as a real-time interface to the internal data structures of the Linux kernel. It is often referred to as a "process information pseudo-filesystem," providing a window into system resources and running processes without storing actual files on the hard drive.
Why
/procExists
The kernel knows everything:
running processes
CPU state
memory usage
open files
sockets
routes
uptime
kernel parameters
But programs need access to this information. Linux could have created a special API but Instead it created:
/proc
A structured, readable interface.
Key Characteristics
Virtual Filesystem: The files within
/procdo not take up space on the hard drive. They are illusions managed by the kernel, allowing users to "read" kernel memory as if it were a file.Process Information: It is the primary source for utilities like
ps,top, andhtopto gather data on running processes. Each running process has a corresponding directory, named by its Process ID (PID), such as/proc/1234/.Kernel Interface: It allows user-space tools to interact with kernel space. You can read kernel variables and, in some cases, change them.
"Everything is a File": It adheres to the Unix philosophy that everything can be represented as a file, making system information accessible via standard file commands (
cat,ls).
Major Components
/proc/[PID]/Directories: Contain information about specific processes, such ascmdline(command line arguments),cwd(current working directory),exe(link to the executable), andstatus(process state).System Info Files: Provide global system data, including:
/proc/cpuinfo: CPU architecture and speed./proc/meminfo: Physical memory usage./proc/uptime: System uptime./proc/version: Kernel version./proc/mounts: Currently mounted filesystems.
/proc/sys/Directory: A special, often writable area that acts as a central hub for configuring kernel parameters at runtime (similar tosysctl).
Purpose and Utility
Monitoring: It enables real-time monitoring of system performance and resource usage.
Debugging: It provides insights into what the kernel is doing, which is useful for tracking down issues.
Configuration: You can modify kernel behavior by writing to files in
/proc/sys.Communication: It acts as a bridge for data exchange between the kernel and user processes.
The Strange Thing You Notice First
Inside /proc, you see numbers.
Example:
ls /proc
You may see:
1
122
883
2300
These are not random folders. They are running processes.
Where Each number = PID(Process ID)



