← Linux+: production administration and troubleshooting
06 / 7 · 24 MIN

Disk, CPU, and memory diagnosis

Read each indicator according to the resource it actually measures.

Concept and mechanism

No space left on device can occur with free blocks when inodes are exhausted. df -h and df -i observe different dimensions. Removing an open file’s name does not close the process descriptor: space can remain allocated until the last relevant reference closes. Identify the writer and use supported reopening or a coordinated restart while retaining evidence. Do not delete other files without knowing which the service needs. Confirmation should include reclaimed capacity and functional continuity.

Guided application

Linux load average includes runnable tasks and uninterruptible waits; it is not CPU percentage. Correlate states, I/O, and latency to distinguish CPU competition from waits in another subsystem. Low MemFree also does not prove a RAM shortage: MemAvailable estimates usable capacity without swapping, including reclaimable components. Look for pressure signals and application behavior before clearing caches or restarting. Each indicator guides a hypothesis; an action should confirm or mitigate it with a measured result and limited scope.

IN PRACTICE

On a filesystem with millions of small files, inspect inodes before proposing more blocks. For a removed but open log, look for the writer’s retained reference.

Common pitfalls

Confusing space with inodes; treating load as CPU; inferring a leak from MemFree alone; deleting names without closing references.

Related topics: Limits, networking, and incident evidence · System and persistent storage

Take this idea with you

Mitigation should match the identified resource and mechanism.

Create account

Reference: df(1): filesystem space · XK0-006 V8