Recover Deleted Linux Files With lsof

本文介绍如何利用Linux下的lsof命令恢复刚刚被误删的文件。通过跟踪仍然打开该文件的进程,可以找到文件的inode,并从/proc目录中复制回文件内容。

摘要生成于 C知道 ,由 DeepSeek-R1 满血版支持, 前往体验 >

One of the more neat things you can do with the versatile utility lsof is useit to recover a file you've just accidentally deleted.


A file in Linux is a pointer to an inode, which contains the filedata (permissions, owner and where its actual content lives on the disk). Deleting thefile removes the link, but not the inode itself - if another process has it open, theinode isn't released for writing until that process is done with it.

To try this out, create a test text file, save it and then type lesstest.txt. Open another terminal window, and type rm testing.txt. If youtry ls testing.txt you'll get an error message. But! less still has areference to the file. So:

> lsof | grep testing.txt
less	4607	juliet  4r  REG 254,4   21  
           8880214 /home/juliet/testing.txt (deleted)

The important columns are the second one, which gives you the PID of the process that has thefile open (4607), and the fourth one, which gives you the file descriptor (4). Now, we golook in /proc, where there will still be a reference to the inode, from whichyou can copy the file back out:

> ls -l /proc/4607/fd/4
lr-x------ 1 juliet juliet 64 Apr  7 03:19 
             /proc/4607/fd/4 -> /home/juliet/testing.txt (deleted)
> cp /proc/4607/fd/4 testing.txt.bk

Note: don't use the -a flag with cp, as this willcopy the (broken) symbolic link, rather than the actual file contents.

Now check the file to make sure you've got what you think you have, and you'redone!


FROM: http://www.linuxplanet.com/linuxplanet/tips/6767/1/


REF: 

1. Finding open files with lsof

http://www.ibm.com/developerworks/aix/library/au-lsof.html


2. lsof – The most powerful, versitile, and underused Unix command

http://www.benharold.com/?p=14


3. 15 Linux lsof Command Examples (Identify Open Files)

http://www.thegeekstuff.com/2012/08/lsof-command-examples/



评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值