A daemon needs a directory for its PID file and its control socket. The data must be writable very early in boot, and it must not survive a reboot. Which directory does current FHS practice designate for it?
LPIC-1 Exam 101-500, objective 104. Devices, Linux filesystems, filesystem hierarchy standard medium
Machine-checked — no person has signed for it. This question was read against the source cited below by an automated pass, which found no contradiction. That is a weaker claim than it sounds: the same kind of process wrote the question, so it can confirm its own mistake.
Treat it as a good draft rather than as settled fact, and read the source below before you rely on it. It is not used in mock exams here — only questions a person has signed for are.
How these questions are written — where each question comes from, what the verification ledger records, and what happens when one is found wrong.
The options
Correct /run
Correct. /run holds volatile runtime data for processes since boot. Distributions mount a tmpfs there, so it is writable before other filesystems appear and is empty again after a reboot.
Not correct /var/run
Wrong as the designated location today. It was the historical home for this data and is now a compatibility symlink to /run on most distributions, but /var may itself be a late-mounted filesystem.
Not correct /tmp
Wrong. /tmp is world-writable scratch space for any user's temporary files, so a system daemon's control socket there is both misfiled and exposed to a name-collision attack.
Not correct /var/lib
Wrong in the opposite direction. /var/lib is for state that an application must keep across reboots, such as databases and package manager records.
Why
Under /var, the subdirectory encodes the lifetime and purpose of the data: /var/log for logs, /var/spool for queued work awaiting processing, /var/cache for regenerable cached data, and /var/lib for persistent application state. Runtime data that describes the system only since it was booted was moved out of /var/run to the top-level /run precisely because /var can be a separate filesystem mounted too late for early boot. /run is a tmpfs, so nothing in it survives a restart.
Where this comes from
- Cited
- manual page hier(7)
Practise this
Reading one question is not practice. The trainer will draw a short set from objective 104 and space the ones you get wrong.
More questions on this objective
- A new disk /dev/sdb has no partition table at all. Which command writes an empty GPT partition table onto it without dropping you into an interactive editor? machine-checked
- You need the partition /dev/sdc1 on a USB stick to carry a FAT32 filesystem so that Windows machines can read and write it. Which command creates it? machine-checked
- You have just run `mkswap /dev/sdb2`. Which command makes the kernel start using that swap area immediately, without a reboot? machine-checked
- Why is it dangerous to run e2fsck against an ext4 filesystem that is currently mounted read-write? machine-checked
- On an ext4 filesystem at /dev/sda1 you want an automatic check to be forced after every 30 mounts. Which command sets that? machine-checked
- `df -h /var` reports the filesystem 100% full, but `du -sh /var` accounts for only about half that space. Nothing is hidden under a mount point. What is the most likely explanation? machine-checked
All questions on Devices, Linux filesystems, filesystem hierarchy standard