Finding files & links
“I saved it somewhere…” Every computer user has said it. On Linux you don't click through folders hoping to get lucky. You ask the computer to search. Then you'll learn to make shortcuts, which Linux calls links.
You will learn
find: search by name, type, size and age, and act on what you findlocateandupdatedb: instant search, and why it can miss new fileswhich,whereisandtype: where does a command live?ln -s(shortcuts), hard links, andreadlink
find: the search engine
find walks through every folder under a starting point and prints what matches. The pattern is always where to look, then what to match:
find ~ -name "notes.txt" # exact name, anywhere in my home find ~ -name "*.txt" # * = anything. Keep the quotes! find ~ -iname "*project*" # -iname ignores UPPER/lower case find ~ -type d -name "game*" # only folders (d). Files are -type f find ~ -size +100M # bigger than 100 MB (k, M, G) find ~ -mtime -1 # changed in the last day find /etc -name "*.conf" 2>/dev/null # hide "Permission denied" noise
Without quotes, bash expands *.txt before find even runs. If your current folder has a.txt, find receives -name a.txt and only looks for that one name. Quoting passes the pattern to find untouched.
Doing something with the results
find ~ -name "*.bak" -exec ls -l {} \; # run a command on each result ({} = the file)
find ~/projects -type f -exec wc -l {} + # + = one command with all the files
find ~ -name "*.bak" # ALWAYS look first…
find ~ -name "*.bak" -delete # …then delete-delete doesn't ask questions and there's no trash can. Run the same find without -delete first, read the list, and only then add it. And -delete must go last: find ~ -delete -name "*.bak" deletes everything, because find does the steps in order.
locate: instant, but a little behind
find searches live, so on a big disk it can take a while. locate searches a database of every file name instead, so it answers instantly. The catch: the database is a snapshot, rebuilt once a day by a timer. Files created since then don't show up until you run sudo updatedb.
sudo dnf install mlocate
sudo updatedb # build the database first!
locate final-project
Rocky 9 uses mlocate. Installing it doesn't build the database, so locate complains until you run updatedb once.
sudo apt install plocate
locate final-project
sudo updatedb # refresh after new files
Ubuntu uses the newer, faster plocate. It builds its database right after installing.
Where does a command live?
Commands are just program files. When you type ls, bash looks through the folders listed in $PATH until it finds a file called ls.
which python3 # the file that runs when you type python3 whereis ssh # program + config + manual page locations type cd # cd is a shell builtin: part of bash, no file at all type ll # ll is an alias (a nickname for another command) echo $PATH # the folders bash searches, in order
/usr/bin/python3 ssh: /usr/bin/ssh /etc/ssh /usr/share/man/man1/ssh.1.gz cd is a shell builtin
ll exists on both, but it's a different alias. Rocky makes it ls -l, Ubuntu makes it ls -alF, which also shows hidden files. type ll tells you which one you've got.
Links: Linux shortcuts
A symbolic link (symlink, or soft link) is a tiny file that just says “the real thing is over there.” It's like a desktop shortcut on Windows.
ln -s ~/projects/game-2026-final-v3 game # ln -s TARGET LINKNAME ls -l game cd game # works like the real folder pwd -P # -P shows the real path behind the link readlink game # just print where a link points
lrwxrwxrwx 1 student student 41 Sep 27 10:02 game -> /home/student/projects/game-2026-final-v3
The l at the start and the arrow tell you it's a link. Order matters: target first, then the new name, the same order as cp. If the target is deleted or moved, the link breaks (it “dangles”). find ~ -xtype l finds broken links.
Hard links
Without -s, ln makes a hard link: a second name for the same data on disk. Every file has an ID number called an inode; ls -i shows it. Two hard links share the same inode, so they're not a copy and not a shortcut. They're the same file with two names.
ln Documents/notes.txt notes-hard.txt ls -li Documents/notes.txt notes-hard.txt # same inode, link count 2 rm Documents/notes.txt cat notes-hard.txt # still there!
Symlink (ln -s) | Hard link (ln) | |
|---|---|---|
| What it is | A pointer to a path | A second name for the same data |
| Original deleted? | Link breaks | Data survives until the last name is gone |
| Folders? | Yes | No (files only) |
| Other disks? | Yes | No (same filesystem only) |
| You'll use it | All the time | Rarely, but it explains the “link count” in ls -l |
The system is full of symlinks. On both families /bin is a link to /usr/bin, and systemd's enable works by creating symlinks (lesson 15). Ubuntu's Apache turns sites on and off with links from sites-enabled to sites-available.
Try it: the lost project 🔎
Your final project is saved somewhere in your home folder, but you can't remember where.
Quick check
1. You created report.txt five minutes ago, but locate report.txt finds nothing. Why?
✓ locate searches a snapshot. find always searches live.
2. Which command makes a shortcut called web that points to /var/www/html?
✓ Target first, then the link name, just like cp SOURCE DEST.
3. You want to delete every .tmp file under ~/projects. What's the safe way?
✓ Look first, delete second, and -delete goes last. Option b deletes everything, because find runs its steps left to right.
4. which cd finds nothing, but cd works fine. Why?
✓ A program can't change your shell's folder, so cd has to be built into bash.