Linux Basics · Lesson 9 · 20 min

Finding files & links

“I saved it somewhere…” Every computer user has said it. On Linux you don't click through folders hoping to get lucky. You ask the computer to search. Then you'll learn to make shortcuts, which Linux calls links.

You will learn

  • find: search by name, type, size and age, and act on what you find
  • locate and updatedb: instant search, and why it can miss new files
  • which, whereis and type: where does a command live?
  • ln -s (shortcuts), hard links, and readlink

find: the search engine

find walks through every folder under a starting point and prints what matches. The pattern is always where to look, then what to match:

Same on both
find ~ -name "notes.txt"          # exact name, anywhere in my home
find ~ -name "*.txt"              # * = anything. Keep the quotes!
find ~ -iname "*project*"         # -iname ignores UPPER/lower case
find ~ -type d -name "game*"      # only folders (d). Files are -type f
find ~ -size +100M                # bigger than 100 MB (k, M, G)
find ~ -mtime -1                  # changed in the last day
find /etc -name "*.conf" 2>/dev/null   # hide "Permission denied" noise
Why the quotes?

Without quotes, bash expands *.txt before find even runs. If your current folder has a.txt, find receives -name a.txt and only looks for that one name. Quoting passes the pattern to find untouched.

Doing something with the results

Same on both
find ~ -name "*.bak" -exec ls -l {} \;     # run a command on each result ({} = the file)
find ~/projects -type f -exec wc -l {} +   # + = one command with all the files
find ~ -name "*.bak"                       # ALWAYS look first…
find ~ -name "*.bak" -delete               # …then delete
Look before you delete

-delete doesn't ask questions and there's no trash can. Run the same find without -delete first, read the list, and only then add it. And -delete must go last: find ~ -delete -name "*.bak" deletes everything, because find does the steps in order.

locate: instant, but a little behind

find searches live, so on a big disk it can take a while. locate searches a database of every file name instead, so it answers instantly. The catch: the database is a snapshot, rebuilt once a day by a timer. Files created since then don't show up until you run sudo updatedb.

Rocky / RHEL
sudo dnf install mlocate
sudo updatedb           # build the database first!
locate final-project

Rocky 9 uses mlocate. Installing it doesn't build the database, so locate complains until you run updatedb once.

Ubuntu / Debian
sudo apt install plocate
locate final-project
sudo updatedb           # refresh after new files

Ubuntu uses the newer, faster plocate. It builds its database right after installing.

Where does a command live?

Commands are just program files. When you type ls, bash looks through the folders listed in $PATH until it finds a file called ls.

Same on both
which python3      # the file that runs when you type python3
whereis ssh        # program + config + manual page locations
type cd            # cd is a shell builtin: part of bash, no file at all
type ll            # ll is an alias (a nickname for another command)
echo $PATH         # the folders bash searches, in order
/usr/bin/python3
ssh: /usr/bin/ssh /etc/ssh /usr/share/man/man1/ssh.1.gz
cd is a shell builtin
Spot the difference

ll exists on both, but it's a different alias. Rocky makes it ls -l, Ubuntu makes it ls -alF, which also shows hidden files. type ll tells you which one you've got.

A symbolic link (symlink, or soft link) is a tiny file that just says “the real thing is over there.” It's like a desktop shortcut on Windows.

Same on both
ln -s ~/projects/game-2026-final-v3 game   # ln -s TARGET LINKNAME
ls -l game
cd game          # works like the real folder
pwd -P           # -P shows the real path behind the link
readlink game    # just print where a link points
lrwxrwxrwx 1 student student 41 Sep 27 10:02 game -> /home/student/projects/game-2026-final-v3

The l at the start and the arrow tell you it's a link. Order matters: target first, then the new name, the same order as cp. If the target is deleted or moved, the link breaks (it “dangles”). find ~ -xtype l finds broken links.

Hard links

Without -s, ln makes a hard link: a second name for the same data on disk. Every file has an ID number called an inode; ls -i shows it. Two hard links share the same inode, so they're not a copy and not a shortcut. They're the same file with two names.

Same on both
ln Documents/notes.txt notes-hard.txt
ls -li Documents/notes.txt notes-hard.txt   # same inode, link count 2
rm Documents/notes.txt
cat notes-hard.txt                          # still there!
Symlink (ln -s)Hard link (ln)
What it isA pointer to a pathA second name for the same data
Original deleted?Link breaksData survives until the last name is gone
Folders?YesNo (files only)
Other disks?YesNo (same filesystem only)
You'll use itAll the timeRarely, but it explains the “link count” in ls -l

The system is full of symlinks. On both families /bin is a link to /usr/bin, and systemd's enable works by creating symlinks (lesson 15). Ubuntu's Apache turns sites on and off with links from sites-enabled to sites-available.

Try it: the lost project 🔎

Your final project is saved somewhere in your home folder, but you can't remember where.

Quick check

1. You created report.txt five minutes ago, but locate report.txt finds nothing. Why?

2. Which command makes a shortcut called web that points to /var/www/html?

3. You want to delete every .tmp file under ~/projects. What's the safe way?

4. which cd finds nothing, but cd works fine. Why?

Finished the missions and the quiz? Mark it done to track your progress.