Capacity has more than one measure
df reports filesystem-level usage; du walks accessible files and totals observed usage. Confirm both refer to the same mount and avoid crossing other filesystems unintentionally. Block space and inode availability are different dimensions. A filesystem may have free blocks yet be unable to create new files because inodes are exhausted.
Why df and du may differ
A process can keep a file open after its directory entry is removed. The name disappears from normal searches, but blocks may remain allocated until the last descriptor closes. Permissions, files hidden beneath mounts, and filesystem characteristics may also affect comparisons. Treat the discrepancy as a hypothesis, not automatic proof of one particular issue.
Recover capacity responsibly
Identify the owner and retention requirements of each data type. Logs, queues, and temporary files may have different application meanings. Use supported rotation or cleanup and verify that the application can still write. Do not indiscriminately delete database files or change volumes during an incident without understanding recovery. After intervention, check capacity, growth rate, and the cause of exhaustion.
Workplace application
On a shared filesystem, do not choose files solely by size. Distinguish logs disposable under approved retention, unconsumed queues, and business data. Compare df and du over the same scope; differences can have several causes. If deleted files remain open, coordinate a supported mechanism for closing references. Confirm reclaimed space and new application writes before reporting recovery.
Logical size and allocated space
A sparse file may have an apparent size greater than its allocated blocks. Comparing 20 GiB logical size with 2 GiB usage proves neither truncation nor lost data. Identify which measure the tool reports and consider whether copying or restoration preserves sparse regions. For capacity planning, exercise actual behavior at the destination and include headroom for metadata and other consumers. Do not confuse this difference with a deleted file that remains open.
df -h /var
df -i /var
findmnt /var
du -x -h --max-depth=1 /var/log
# lsof +L1 can identify open files with no directory links when available.The service cannot create files even though df -h shows 20 GB free. df -i reports 100% inode use. Investigate the large number of small files and retention policy; merely increasing a log size limit does not address the problem.
Common pitfalls
Deleting active data, comparing different scopes, or overlooking deleted files still open.
Related topics: Interpret CPU, memory, and I/O waiting · Separate DNS, connections, TLS, and the application
Confirm mount, blocks, inodes, and open files before choosing cleanup.
Reference: df(1): filesystem space · DR Linux 2026.4; networking and Bash manuals reviewed 2026-10-01; cgroup v2 and upstream systemd manuals reviewed 2026-10-01; RHEL 10 examples; Linux man-pages 6.19; OpenSSL 3.5