You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Unix查找24小时内创建文件命令返回旧文件问题求助

问题分析与解决建议

首先得指出你踩了一个常见的误区:find命令里的-ctime不是指文件的创建时间!它跟踪的是文件的inode更改时间——也就是文件的元数据(比如权限、所有者、链接数)或者内容被修改的时间。那些2012、2013年的旧文件之所以被匹配到,大概率是最近被修改过权限、或者被跨分区移动过(跨分区移动会改变inode,触发ctime更新),导致它们的ctime变成了接近24小时前的时间,所以被-ctime 1命中了。

如果你确实要找创建时间在24小时前的文件,得根据你的操作系统用对应的参数:

1. Linux系统(Ubuntu、CentOS等现代发行版)

现在大部分Linux的find已经支持-birth参数来筛选创建时间,或者更灵活的-newerBt参数:

  • 要找创建时间刚好在24~48小时前的文件(和你原来-ctime 1的逻辑对应),可以用:
find /users/c_t2/ws/ -maxdepth 1 ! -name 'ws' ! -name 'binaries' ! -name 'delivery' ! -name 'cause' -birth +1 -birth -2

这里+1表示超过1天(24小时),-2表示不到2天(48小时)。

  • 或者用更直观的时间字符串:
find /users/c_t2/ws/ -maxdepth 1 ! -name 'ws' ! -name 'binaries' ! -name 'delivery' ! -name 'cause' -newerBt '24 hours ago' ! -newerBt '48 hours ago'

如果你的find版本太老不支持-birth,可以用stat命令辅助筛选:

find /users/c_t2/ws/ -maxdepth 1 ! -name 'ws' ! -name 'binaries' ! -name 'delivery' ! -name 'cause' -type f -exec bash -c '
    # 获取文件创建时间的时间戳
    create_ts=$(stat -c "%W" "$1")
    now_ts=$(date +%s)
    # 计算时间差:24小时(86400秒)到48小时(172800秒)之间
    time_diff=$((now_ts - create_ts))
    if [ $time_diff -ge 86400 ] && [ $time_diff -lt 172800 ]; then
        echo "$1"
    fi
' _ {} \;

2. macOS/BSD系统

这类系统的find用-Btime参数来表示创建时间(Birth Time),用法和-ctime一致:

find /users/c_t2/ws/ -maxdepth 1 ! -name 'ws' ! -name 'binaries' ! -name 'delivery' ! -name 'cause' -Btime 1

这个命令会直接返回创建时间在24~48小时前的文件。

额外提示

如果你的需求是“找所有创建时间早于24小时前的文件”(而不是刚好24小时左右),只需要把参数改成-birth +1(Linux)或者-Btime +1(macOS/BSD)即可。

内容的提问来源于stack exchange,提问作者Hemant Chowdary

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 08:07:38