As the command uses relatively quick-running heuristics to determine file type, it can report misleading information. The command can be fooled, for example, by including a magic number in the content even if the rest of the content does not match what the magic number indicates. The command report cannot be taken as completely trustworthy.
An initial part of file is considered and the command is to use position-sensitive tests
The entire file is considered and the command is to use context-sensitive tests
Otherwise, the file is reported as a data file
Position-sensitive tests are normally implemented by matching various locations within the file against a textual database of magic numbers (see the Usage section). This differs from other simpler methods such as file extensions and schemes like MIME.
In the System V implementation, the Ian Darwin implementation, and the OpenBSD implementation, the command uses a database to drive the probing of the lead bytes. That database is stored as a file that is located in /etc/magic, /usr/share/file/magic or similar.
History
The file command originated in Unix Research Version 4[2] in 1973. System V brought a major update with several important changes, most notably moving the file type information into an external text file rather than compiling it into the binary itself.
Most major BSD and Linux distributions include a free, open-source implementation that was written from scratch by Ian Darwin in 1986–87.[3] It keeps file type information in a text file with a format based on that of the System V version. It was expanded by Geoff Collyer in 1989 and since then has had input from many others, including Guy Harris, Chris Lowth and Eric Fischer. From late 1993 onward, its maintenance has been organized by Christos Zoulas. The OpenBSD system has its own subset implementation written from scratch, but still uses the Darwin/Zoulas collection of magic file formatted information.
The file command was ported to the IBM i operating system.[4]
As of version 4.00 of the Ian Darwin/Christos Zoulas implementation of file, the functionality of the command is implemented in and exposed by a libmagiclibrary that is accessible to consuming code via C (and compatible) linking.[5][6][7][8]
Usage
The SUS[9] mandates the following command-line options:
-M file, prevents the default position-sensitive and context-sensitive tests in favor of the tests specified in a specially formatted file
-m file, same as for -M, but with tests in addition to the default
-d, selects default position-sensitive and context-sensitive tests; this is the default behavior unless -M or -m are specified
-h, do not dereference symbolic links that point to an existing file or directory
-L, dereference the symbolic link that points to an existing file or directory
-i, do not classify the file further than to report as: nonexistent, a block special file, a character special file, a directory, a FIFO, a socket, a symbolic link, or a regular file; the Ian Darwin and OpenBSD versions behave differently with this option and instead output an Internet media type ("MIME type") identifying the recognized file format
Implementations may add extra options. Ian Darwin's implementation adds -s 'special files', -k 'keep-going' or -r 'raw', among many others.[10]
By default, file does not try to read a device file due to potential undesirable effects. But using the non-standard option -s (available in the Ian Darwin branch), which requests to read device files to identify content, file -s /dev/hda1 reports details such as:
Via Ian Darwin's non-standard option -k, the command does not stop after the first hit found, but looks for other matching patterns. The -r option, which is available in some versions, causes the new line character to be displayed in its raw form rather than in its octal representation. On Linux, file -k -r libmagic-dev_5.35-4_armhf.deb reports information like:
libmagic-dev_5.35-4_armhf.deb: Debian binary package (format 2.0)
- current ar archive
- data
For a compressed file, file compressed.gz reports information like:
compressed.gz: gzipcompressed data, deflated, original filename, `compressed', last
modified: Thu Jan 26 14:08:23 2006, os: Unix
For a compressed file, file -i compressed.gz reports information like:
^The early history of this program is recorded in its private CVS repository; see [1]Archived 2017-04-01 at the Wayback Machine the log of the main program
^Zoulas, Christos (February 27, 2003). "file-3.41 is now available". File (Mailing list). Archived from the original on March 4, 2016. Retrieved January 1, 2013.
^Zoulas, Christos (March 24, 2003). "file-4.00 is now available". File (Mailing list). Archived from the original on December 28, 2016. Retrieved January 1, 2013.