Prepare a controlled observation
The laboratory creates an exclusive temporary directory, uses small files, and removes only its own artifacts on completion. Evidence records CPython 3.13.1 and Darwin 27.0.0 arm64. No Linux machine, NFS share, or production volume was used. This distinction allows learning from executed results without claiming equivalence across platforms. Before each group, predict the visible name, the open object, and where subsequent bytes should appear. Then compare the prediction with JSON output. At work, start by identifying the filesystem and application access contract. An identical textual path can resolve to another target or coexist with descriptors still attached to an earlier object.
Removing the name does not change the descriptor
In the first group, active.log contains OLD and remains open. We remove its name, observe zero links, and create another active.log containing NEW. Writing through the old descriptor produces OLD-MORE in the previous object; reading the new path returns NEW. This observation neither measures global free space nor establishes when a device reclaims blocks. It demonstrates the association retained by the descriptor. During a logging incident, deleting and recreating the path can leave the writer on the wrong object. Identify the process and supported destination-reopening procedure, retain necessary evidence, and validate new entries reaching the expected object. Avoid indiscriminate intervention across all processes.
Two reference forms, different risks
The second group creates linked-a and hard link linked-b. Both refer to the same object. Changing the first byte through linked-b also changes reads through linked-a. Removing linked-a leaves linked-b usable with modified content. This behavior prevents treating the second name as an independent copy. The third group creates a symlink and removes its target; the link remains present but no longer permits reading content. Compare the mechanisms instead of using the generic phrase we have another link as a protection guarantee. For migration, inventory references and consumers. A link can retain shared access or merely provide a path to resolve; neither observation replaces a validated recovery strategy.
Length and allocation answer different questions
The fourth group extends a file to 1048576 bytes without writing that volume of data. On the recorded host, st_blocks is zero and a read from the unwritten region returns zeros. The result shows a sparse file with logical length exceeding accounted allocation. It promises neither zero blocks on another implementation nor absence of metadata. When estimating a copy, identify whether the tool and destination preserve that representation or materialize the bytes. Summed apparent sizes, filesystem allocation, and physical pool usage can diverge. In a capacity report, always state units, layer, and relevant mechanism before converting a file listing into a space requirement.
Visible replacement and durability
In the fifth group, a reader opens VERSION-A and the path is replaced by a prepared VERSION-B file in the same directory. The old reader continues reading A; a new open reads B. There is no power-loss test. Linux documentation distinguishes persistence of content from persistence of the directory entry: synchronizing the file does not automatically cover that entry. Errors must also be handled and the procedure validated on the target. If data and manifest are two separately replaced files, a consumer can observe different generations. The one-rename exercise does not demonstrate a joint transaction. Define a publication and read protocol preserving coherence and include relevant failures in authorized tests.
Workshop: explain state to support
Draw a table containing name, open object, writer, observed content, and proposed action for the active.log case. Explain why the new name alone does not resolve rotation. Next compare the hard-link and symlink cases and identify which survives removal of the other name and under which conditions. Finally propose criteria for publishing data and manifest without accepting mixed generations. The workshop deliverable is a justified decision and a list of what still needs testing in the relevant environment. No human sessions or network-share tests were performed. The operational summary is simple: observe identity and references before acting on names. Relate the findings to retention and service ownership.
python3 content/labs/storage-evidence/run.py
# Open old object -> unlink name -> recreate name -> write through old handle
# Old handle: OLD-MORE; current path: NEW
# Replace published file: old reader sees A; new reader sees B
# Actual temporary-file exercises on recorded Darwin host; not a Linux VM.A fictional batch keeps writing to an unnamed log after the team removes it and creates another file at the same path.
Common pitfalls
Treating a name as permanent identity, a hard link as backup, logical size as allocation, and rename as a multi-file transaction.
Related topics: Linux Administration · NAS · Disaster Recovery
Confirm the object used by the application and what each operation changes before removing, replacing, or declaring recovered space.
Reference: os: operating system interfaces · BigSavant Storage 2026-09; selected Linux and AWS storage behavior