Programming and IT

Linux commands

The Linux terminal works the same way in every distribution: command name, options, arguments. Below are six tables by area of work, each with one line per command and an example you can type to see the result straight away.

Updated
In this article

How to read a command line#

Every call has three parts: the program name, options and arguments. Options come short (-l) and long (--long); short ones can be combined, so ls -l -a and ls -la are the same thing. Arguments are what you work on: paths, process names, addresses.

Two commands help when you forget an option:

ls --help          # a short summary right in the terminal
man ls             # the full manual, quit with q

One more habit saves hours: Tab completes file and command names, the up arrow brings back the previous command, Ctrl+C stops a stuck program and Ctrl+D ends input.

You do not always need superuser rights. The rule is simple: your own home directory — no sudo; system directories and services — with sudo. If a command from this cheat sheet answers Permission denied, that is your hint.

Files and directories#

Command What it does Example
pwd prints the current directory pwd
ls lists a directory's contents ls -lh /var/log
cd changes directory cd ~/projects
mkdir creates a directory mkdir -p src/api/v1
cp copies a file or a tree cp -r src backup
mv moves and renames mv notes.txt archive/
rm deletes rm -r build
touch creates an empty file touch README.md
cat prints a whole file cat /etc/hostname
less pages through a file less /var/log/syslog
head / tail first and last lines tail -n 50 app.log
tail -f follows lines as they are appended tail -f app.log

-p on mkdir creates the whole chain of directories at once and stays quiet if the directory already exists. -h on ls prints sizes in kilobytes and megabytes instead of raw bytes. rm has no undo: there is no trash can in the terminal, so before rm -r it pays to run ls on the same path.

Three path shortcuts save typing: ~ is your home directory, . the current one, .. the parent. cd - takes you back to where you were before the last change.

Permissions#

Every file has three sets of permissions — for the owner, the group and everyone else — and each set has three bits: read (4), write (2), execute (1). That is where the familiar numbers come from: 7 = 4+2+1 (everything), 6 = 4+2 (read and write), 4 — read only.

Command What it does Example
chmod changes permissions chmod 644 notes.txt
chmod +x makes a file executable chmod +x deploy.sh
chown changes owner and group sudo chown www-data:www-data site
ls -l shows permissions as a string ls -l notes.txt
id prints your uid, gid and groups id
sudo runs a command as the superuser sudo systemctl restart nginx

chmod 644 is rw-r--r--: the owner reads and writes, everyone else only reads. For a directory, the execute bit means the right to enter it, which is why directories usually get 755, not 644. You almost never need 777: if it "fixes" a problem, the real cause is the wrong owner.

Processes#

Command What it does Example
ps aux a snapshot of every process ps aux | grep nginx
top a live table of load top
kill sends a process a termination signal kill 4821
kill -9 kills a process unconditionally kill -9 4821
pkill kills by name pkill -f "python app.py"
jobs / fg / bg jobs in the current shell bg %1
systemctl status the state of a service systemctl status nginx
journalctl service logs journalctl -u nginx -n 100

A plain kill asks a process to close cleanly — finish writing a file, release a port. kill -9 gives it no such chance, so it is the last resort, not the first. To run a long program in the background, put & at the end of the line; to bring it back to the foreground, use fg.

Networking#

Command What it does Example
ip a addresses of network interfaces ip a
ping checks whether a host is reachable ping -c 4 example.com
curl makes an HTTP request from the terminal curl -i https://example.com
wget downloads a file wget https://example.com/file.zip
ss -tulpn open ports and who holds them sudo ss -tulpn
dig asks DNS about a name dig example.com
ssh logs in to a remote machine ssh user@10.0.0.5
scp copies a file over ssh scp dump.sql user@10.0.0.5:/tmp/

-c 4 on ping stops after four packets — otherwise it runs forever. ss -tulpn with sudo shows the name of the process that took a port: it is the first command to run when a service says "address already in use". What curl returns and how to read status codes is covered in what is an API.

Packages and disk space#

Command Distributions Example
apt Debian, Ubuntu sudo apt update && sudo apt install git
apt remove Debian, Ubuntu sudo apt remove git
dnf Fedora, RHEL sudo dnf install git
pacman Arch sudo pacman -S git
apt list --installed Debian, Ubuntu apt list --installed | grep python
df / du everywhere df -h and du -sh ~/Downloads

apt update refreshes the list of available packages, apt upgrade upgrades the packages themselves; mixing them up is a typical first-week mistake. df -h shows free space per partition, du -sh folder shows how much one folder takes. When the disk is full, this pair finds the culprit in two calls.

Finding files and text#

Command What it does Example
find finds files by name, size, date find . -name "*.log" -mtime -1
grep finds a string inside files grep -rn "TODO" src/
grep -i case-insensitive search grep -i error app.log
which shows the path to a program which python3
wc -l counts lines wc -l access.log
sort / uniq sorting and collapsing duplicates sort ips.txt | uniq -c

For grep, -r means "go into every subdirectory" and -n means "show line numbers". The search pattern is a regular expression, and knowing the syntax turns grep into a tool of its own: classes, quantifiers and anchors are explained in the article on regular expressions.

A special strength of the terminal is the pipe |: the output of one command becomes the input of the next. A classic chain for analysing a log looks like this:

grep "500" access.log | awk '{print $1}' | sort | uniq -c | sort -rn | head

Step by step: pick the lines with status 500, take the first field (the address) from each, group identical ones, count them, sort in descending order and show the top of the list.

Common mistakes#

A space in a path without quotes. cd My files tries to go to a directory called "My". The right way is cd "My files".

rm -rf with a variable. If the variable turns out to be empty, the path $DIR/ becomes just /. Check the value with echo before deleting.

Copying a directory without -r. cp src dst on a directory answers omitting directory; a tree needs cp -r.

Editing a system file without a backup. Before sudo nano /etc/…, run sudo cp /etc/file /etc/file.bak.

It is safer to practise commands in a throwaway container than on your working system: any mistake there is undone by a restart — see what is Docker. For a full study plan, see learn Linux from scratch.

Step-by-step plan

  1. Learn to move aroundWalk the directory tree with pwd, ls -la and cd without using a file manager.
  2. Understand permissionsCreate a file, look at ls -l, change the permissions to 600 and 755 and explain every letter in the output.
  3. Find a process and a portStart a long-running program, find it with ps aux, stop it with kill, check the port with ss -tulpn.
  4. Build a pipelinePick lines from a log with grep, count them with wc -l and group them with sort | uniq -c.
  5. Write your own cheat sheetList the twenty commands you actually used this week, with an example for each.

Start learning this in your own space

The plan goes into your repository: tick off stages, keep notes — the change history shows how far you have come.

Start the plan

Check yourself

1.Which command prints the current directory?

2.Which command shows free space on partitions in readable units?

3.In numeric permissions 644, the owner's 6 is the sum of read (4) and write (2). Which number gives the owner the full rwx set?

4.Which grep option makes it search every subdirectory?

Sources

Was this helpful?

More articles

Programming and IT Git commands Git has well over a hundred commands, but on an ordinary day you use about twenty. Here they are in the order you need them — from your first copy of a repository to undoing a bad step — with one line of explanation each. Programming and IT Markdown tables A Markdown table is built from pipes and a separator line under the header. Below is the table syntax with column alignment, plus a short cheat sheet for the rest of the markup — headings, lists, links, images, code, quotes and task lists. Programming and IT Regular expressions A regular expression is a compact description of a set of strings. The same syntax works in grep, in your code editor, in JavaScript, PHP, Java and Python, so you only need to learn it once. This page covers the pattern language itself, not the library of any particular language. Programming and IT How to learn Linux from scratch Linux runs most servers, containers and countless devices, so developers, testers, analysts and system administrators all need the command line. The easiest way to learn it is not by reading lists of commands but by working in the terminal every day and solving small practical tasks. Below is a sequence of topics for two to three months. Programming and IT Python: reading a file Working with a file takes three steps: open it, read or write, close it. You are better off not closing it by hand — that is what the `with` statement is for. And the parameter people forget most is the encoding: without it, the same code reads a file differently on different machines. Programming and IT How to undo a commit The question "how do I undo a commit" actually hides four different ones: fix the last commit, take it back and redo it, erase several, or cancel an old commit in the middle of history. The answer depends above all on one thing — whether anyone besides you has seen that commit.

More solutions