Stat (system call)

stat is a Unix system call that returns file attributes about an inode. The semantics of stat vary between operating systems. As an example, Unix command ls uses this system call to retrieve information on files that includes:
 * atime: time of last access (ls -lu)
 * mtime: time of last modification (ls -l)
 * ctime: time of last status change (ls -lc)

appeared in Version 1 Unix. It is among the few original Unix system calls to change, with Version 4's addition of group permissions and larger file size.

stat functions
The C POSIX library header sys/stat.h, found on POSIX and other Unix-like operating systems, declares the  functions, as well as related functions called   and. The functions take a pointer to a  buffer argument, which is used to return the file attributes. On success, the functions return zero, and on error, −1 is returned and errno is set appropriately.

The  and   functions take a filename argument. If the file is a symbolic link,  returns attributes of the eventual target of the link, while   returns attributes of the link itself. The  function takes a file descriptor argument instead, and returns attributes of the file that it identifies.

The family of functions was extended to implement large file support. Functions named,   and   return attributes in a   structure, which represents file sizes with a 64-bit type, allowing the functions to work on files 2 GiB and larger (up to 8 EiB). When the  macro is defined to 64, these 64-bit functions are available under the original names.

The functions are defined as:

stat structure
This structure is defined in sys/stat.h header file as follows, although implementations are free to define additional fields:

POSIX.1 does not require,   and   members; these fields are defined as part of XSI option in the Single Unix Specification.

In older versions of POSIX.1 standard, the time-related fields were defined as,   and  , and were of type. Since the 2008 version of the standard, these fields were renamed to,   and  , respectively, of type struct  , since this structure provides a higher resolution time unit. For the sake of compatibility, implementations can define the old names in terms of the  member of. For example,  can be defined as.

The  structure includes at least the following members:


 * – identifier of device containing file
 * – inode number
 * – protection mode; see also Unix permissions
 * – reference count of hard links
 * – user identifier of owner
 * – group identifier of owner
 * – device identifier (if special file)
 * – total file size, in bytes
 * – time of last access
 * – time of last modification
 * – time of last status change
 * – preferred block size for file system I/O, which can depend upon both the system and the type of file system
 * – number of blocks allocated in multiples of   (usually 512 bytes).

The  field is a bit field. It combines the file access modes and also indicates any special file type. There are many macros to work with the different mode flags and file types.

Criticism of atime
Reading a file changes its atime eventually requiring a disk write, which has been criticized as it is inconsistent with a read only file system. File system cache may significantly reduce this activity to one disk write per cache flush.

Linux kernel developer Ingo Molnár publicly criticized the concept and performance impact of atime in 2007, and in 2009, the relatime mount option had become the default, which addresses this criticism. The behavior behind the relatime mount option offers sufficient performance for most purposes and should not break any significant applications, as it has been extensively discussed. Initially, relatime only updated atime if atime < mtime or atime < ctime; that was subsequently modified to update atimes that were 24 hours old or older, so that tmpwatch and Debian's popularity counter (popcon) would behave properly.

Current versions of the Linux kernel support four mount options, which can be specified in fstab:
 * strictatime (formerly atime, and formerly the default; strictatime as of 2.6.30) – always update atime, which conforms to the behavior defined by POSIX
 * relatime ("relative atime", introduced in 2.6.20 and the default as of 2.6.30) – only update atime under certain circumstances: if the previous atime is older than the mtime or ctime, or the previous atime is over 24 hours in the past
 * nodiratime – never update atime of directories, but do update atime of other files
 * noatime – never update atime of any file or directory; implies nodiratime; highest performance, but least compatible
 * lazytime – update atime according to specific circumstances laid out below

Current versions of Linux, macOS, Solaris, FreeBSD, and NetBSD support a noatime mount option in /etc/fstab, which causes the atime field never to be updated. Turning off atime updating breaks POSIX compliance, and some applications, such as mbox-driven "new mail" notifications, and some file usage watching utilities, notably tmpwatch.

The noatime option on OpenBSD behaves more like Linux relatime.

Version 4.0 of the Linux kernel mainline, which was released on April 12, 2015, introduced the new mount option lazytime. It allows POSIX-style atime updates to be performed in-memory and flushed to disk together with some non-time-related I/O operations on the same file; atime updates are also flushed to disk when some of the sync system calls are executed, or before the file's in-memory inode is evicted from the filesystem cache. Additionally, it is possible to configure for how long atime modifications can remain unflushed. That way, lazytime retains POSIX compatibility while offering performance improvements.

ctime
It is tempting to believe that ctime originally meant creation time; however, while early Unix did have modification and creation times, the latter was changed to be access time before there was any C structure in which to call anything ctime. The file systems retained just the access time (atime) and modification time (mtime) through 6th edition Unix. The ctime timestamp was added in the file system restructuring that occurred with Version 7 Unix, and has always referred to inode change time. It is updated any time file metadata stored in the inode changes, such as file permissions, file ownership, and creation and deletion of hard links. POSIX also mandates ctime (last status change) update with nonzero write (file modification). In some implementations, ctime is affected by renaming a file, despite filenames not being stored in inodes: Both original Unix, which implemented a renaming by making a link (updating ctime) and then unlinking the old name (updating ctime again) and modern Linux tend to do this.

Unlike atime and mtime, ctime cannot be set to an arbitrary value with utime, as used by the touch utility, for example. Instead, when utime is used, or for any other change to the inode other than an update to atime caused by accessing the file, the ctime value is set to the current time.

Time granularity

 * time_t provides times accurate to one second.
 * Some filesystems provide finer granularity. Solaris 2.1 introduced a microsecond resolution with UFS in 1992 and a nanosecond resolution with ZFS.
 * In Linux kernels 2.5.48 and above, the stat structure supports nanosecond resolution for the three file timestamp fields. These are exposed as additional fields in the stat structure.
 * The resolution of create time on FAT filesystem is 10 milliseconds, while resolution of its write time is two seconds, and access time has a resolution of one day thus it acts as the access date.