• I never really considered using proc to solve my problems. I jump to logs and such but honestly, how have I never played with proc?

  • 2 days

    You used to be able to sudo cat /proc/kcore > /dev/dsp and listen to your ram

    • Wouldn’t that just sound like gibberish? I feel like Mike Lindell would come out of the speakers.

      • 20 hours

        it rotated in between white noise, strobing sirens, digital corruption and silence.

    • That sounds really interesting! I couldn’t find anything else on this. Is this like pre-systemd?

      • 20 hours

        It was before OSS was taken over by ALSA (and other things) for sound. OSS let you play loose and fast and was very forgiving. I just tried using pulseaudio to do it and barely got a burble of static out of it.

        • 3 days

          thanks, it’s got really hard nowdays to find quality content.

          • Zine is short for magazine, I think. Offline zines are often self-published paper booklets, produced by lone wolves or communities, with a focus on one subject. Digital zines are often PDFs. Sometimes a printable booklet version is provided so they can be printed and distributed. Here’s an example of a digital zine: https://digitalselfdefence.net/pdf/dsdc-zine.pdf

  • 3 days

    I’m surprised it doesn’t mention that /proc/self automagically points to the directory of the current process. So if you’re writing a program, you can just look there for information about itself

  • Okay, this is legitimately cool as heck. This finally helps me wrap my head around the “everything is a file” concept in Linux. Of course it can just copy the executable to memory for later reference. That’s how the system would not completely have a meltdown when you do live updates.

    Excellent share!

    • It’s a bit more interesting than that…

      Linux, unlike Windows, will let you delete a file that is actively in use. It removes the reference on the file system but the contents of the file won’t be deleted until all file pointers to it close. In fact it will still be seen as taking up disk space until it’s garbage collected (deleting a large file that’s in use can be frustrating).

      So the file is actually still available to that running process. If you replace it with a new executable and run that then you get the new version.

    • I bet this is done with inodes. Deleted files aren’t truely deleted until nothing has it open and its inode gets dropped. Like ARC for files.

      You can also do interesting things like overwrite a “file” (as in a specific filesystem path) with new contents while keeping anything that already has the file open on the old contents by unlinking the old inode to the path and writing the new contents under a new inode. I believe mv does this. The kind of lesser known feature that probably strikes a good balance between preventing super annoying silent errors/corruption and causing them.

      Relevant Kevin Fang video

      • Thanks for explaining, I was wondering about that.

        Wait, is that why renaming or moving files on android takes forever?

        • No, that’s because Android. It’s also overlaying all filesystems to enforce stupid rules, like no files named “CON” and no files named the same in a different case (like in DOS).

  • I have some of her paper zines on my desk, warmly recommended.

    Might look esoteric at first but if you think we will be using Linux at least on desktop, servers, consoles and more for decades then totally worth learning about.

  • Julia Evans has a bunch of these really handy cheatsheets. I have several saved that I reference semi-regularly.

    • If you delete a file that’s still open by the app, the link in proc will still exist and you can copy the file back out of proc.

      • Does that not make them a hard link (pointing to a filesystem node) instead of a symlink (pointing to another filename)?

        • No, you can’t have a hard link cross filesystems and proc is its own fs type.

              • These days there can be a dozen virtual filesystems doing various stuff. If you ever want to get quite baffled, install a terminal emulator on an Android phone (not Termux) and run mount.

              • Remember the old days before /dev was its own virtual filesystem?

                • It still is! If you try and boot a kernel with nothing in /dev, you won’t get most of the kernel boot messages since /dev/console doesn’t exist. You need a basic set of device nodes in /dev before udev is started.

                  If you’re going to rsync a system to new hardware and exclude /dev /proc /sys, it’s better to setup a new mount of your / to a different directory and sync off that, so you get the underlying stuff without the cruft.

    • Also known as zombie files. If you are unlucky they can take up all space on a drive, or even tmpfs (so your ram) and you can’t easily find them. At least until you end the right process or restart.
      Had that happen once and had to write my own script to trace it to the log of an open terminal emulator tab that had billions of lines.

  • 3 days

    I didn’t know any of this. Amazing. I usually just look at /proc/net/ for routes and bonding config etc.

  • Great tips! Although if i may 🤓 just a little for the top right, it works because what you deleted isn’t the binary, it’s the pointer that points to the binary’s location. The data is still exactly as it was before “deletion”; the symlink is simply a copy of the original pointer’s info; and I’m speculating that the existence of any pointer prevents the system from recycling those addressed bits.

    • 3 days

      it merely deletes the inode from the directory instead of overwriting the actual data on the disk

  • Do you know how to build portable executables?

    configure --prefix=/proc/self/pwd
    

    It even works in .so files and libtool.

      • The executable will search for .so files not inside predefined paths like /usr/lib but inside it’s current directory. You may theoretically put . as an argument to configure, but it converts that into an absolute path, snd libtool and linker fail when encountering relative paths inside shared library dependencies.

      • --prefix=$(pwd) is resolved at compile time. If you move your compiled .so files to a different directory, they stop working.

        • I see what you mean, very clever solution if a program is using the configure prefix by compiling it into the binary.

          That can’t be very common though is it? Usually the configure prefix is just used by make install to install the binaries into the prefix. If the compiled program needs to know where it is installed it can read argv[0].

          Have you seen this used somewhere?

          • I am using this myself in Android app, where you can write files only inside /data/data/your.app.id/

            So naturally, if you want to publish a different app, your.app.id will be different, so you need to recompile all your Linux tools that you bundle inside your app.

            If you are not running your Linux tools on Android, you’d probably be better off using Docker or a chroot.