Skip to main content

Mount

Mounting in Linux attaches a filesystem (on a disk partition, network share, or virtual source) to a directory in the filesystem tree. After mounting, files on the device appear at that directory path and are accessible through normal file operations.

What Is a Mount in Simple Terms

Linux has one directory tree starting at /. Everything is in that tree. But storage devices (hard disks, USB drives, network shares) are physically separate. Mounting is the act of attaching a storage device to a point in the tree so its files become accessible.

Think of it like plugging a filing cabinet into a specific drawer slot in a large cabinet system. Once plugged in, you can reach the files inside by opening that drawer — the files are still physically in the plugged-in cabinet, but accessible through the drawer slot.

How It Works

Before mounting, a storage device exists but its files are not accessible through the directory tree. After mounting at a mount point (any directory), the device's filesystem root appears at that directory.

◈ DIAGRAM
Before mounting /dev/sdb1:
/
+-- etc/
+-- var/
+-- mnt/
+-- data/ <- empty directory
After: mount /dev/sdb1 /mnt/data
/
+-- etc/
+-- var/
+-- mnt/
+-- data/ <- now shows contents of /dev/sdb1
+-- backups/
+-- archives/
+-- database.dump

Common mount points:

TEXT
/ Root filesystem -- always mounted
/boot Boot partition (kernel, initrd)
/home User home directories (often separate disk)
/var Variable data -- often separate to prevent root fill
/tmp Temporary storage (often tmpfs)
/mnt Manual temporary mount point
/media Auto-mounted removable media
/data Common convention for additional data disks

Practical Commands

Bash
## Show all currently mounted filesystems
mount
## Or more readable:
df -h
## Show type of each filesystem
df -Th
## Filesystem Type Size Used Avail Use% Mounted on
## /dev/xvda1 ext4 20G 12G 7.5G 62% /
## tmpfs tmpfs 1.9G 0 1.9G 0% /dev/shm
## Mount a device manually
sudo mount /dev/sdb1 /mnt/data
## Mount with specific options
sudo mount -o ro /dev/sdb1 /mnt/data ## read-only
sudo mount -o noexec,nosuid /dev/sdb1 /mnt ## security options
sudo mount -t xfs /dev/sdc1 /mnt/data ## specify filesystem type
## Unmount
sudo umount /mnt/data
## or by device:
sudo umount /dev/sdb1
## Force unmount when busy
sudo umount -l /mnt/data ## lazy unmount -- waits for processes to finish
## Find what is using a busy mount point
lsof /mnt/data ## list open files on that mount
fuser -v /mnt/data ## list processes using it
## Persistent mounts -- edit /etc/fstab
cat /etc/fstab
## UUID=abc123 /data xfs defaults,noatime 0 2
## Test fstab without rebooting
sudo mount -a ## mounts everything in fstab not already mounted
## Mount a network filesystem (NFS)
sudo mount -t nfs 10.0.1.5:/exports/data /mnt/nfs
## Mount a tmpfs (RAM filesystem)
sudo mount -t tmpfs -o size=2G tmpfs /tmp

Security mount options:

TEXT
ro Read-only -- cannot write to this filesystem
noexec Cannot execute binaries from this filesystem
nosuid Setuid binaries have no effect
nodev No device files on this filesystem
Production pattern for /tmp:
mount -o defaults,noexec,nosuid,nodev tmpfs /tmp
This prevents attackers from uploading and running binaries via /tmp.

Common /etc/fstab example:

TEXT
## device/UUID mountpoint fstype options dump pass
UUID=abc123-... / ext4 defaults 0 1
UUID=def456-... /boot ext4 defaults 0 2
UUID=ghi789-... /data xfs defaults,noatime 0 2
tmpfs /tmp tmpfs nosuid,nodev,noexec 0 0

Troubleshooting

Symptom Command What to Look For
Mount fails `dmesg tail -20`
Cannot unmount, device busy lsof /mountpoint Processes with open files
Mount does not persist after reboot cat /etc/fstab Entry missing or wrong UUID
Disk full but df shows space df -i /mountpoint Inode exhaustion
Tip

Use UUIDs instead of device names (/dev/sdb1) in /etc/fstab. Device names can change when disks are added or removed. UUIDs are stable. Get the UUID with: blkid /dev/sdb1.

Security

Mount /tmp with noexec,nosuid,nodev on production servers. Many attacks work by uploading a binary to /tmp and executing it. The noexec option prevents binaries from running from /tmp, blocking this common attack vector.

Frequently Asked Questions

What actually happens under the hood when you mount a filesystem in Linux?

The kernel attaches the filesystem's superblock to a directory (the mount point) in the existing directory tree, making that directory's prior contents temporarily inaccessible and replacing them with the mounted filesystem's root. This is how Linux presents disks, network shares (NFS, CIFS), and even virtual sources like `/proc` or `tmpfs` as ordinary directories — there's no drive-letter concept like Windows; everything hangs off a single tree rooted at `/`.

What's a common mistake people make with mounts that causes data 'loss' after a reboot?

Running `mount` manually only affects the current session — after a reboot, the mount is gone unless it's also added to `/etc/fstab`, which is the config the OS reads at boot to remount everything automatically. A related gotcha: writing to a mount point directory before something is mounted there hides those files, not deletes them, but forgetting this has led to accidental 'lost data' reports when in fact the files are still on the underlying disk, just obscured by the later mount.