← Linux from ScratchCheat sheet
M13Linux from Scratch

M13 — Processes and signals

Time: about 50–80 minutes
Lab root: /tmp/linux-lab-pushpjeet (we use harmless sleep processes)

Prerequisites#

  • Comfort with the shell, background basics (command &), and reading command output
  • M10 helps if you use history to recall PIDs you just launched

Learning objectives#

By the end of this module you will be able to:

  1. Explain PID, PPID, and basic process states in plain language
  2. List processes with ps, spot trees with pstree, and find PIDs with pgrep
  3. Stop processes with kill / pkill using SIGTERM first and SIGKILL only when needed
  4. Start a background job, locate it, and terminate it on purpose

What a process is#

A process is a running instance of a program. Each has:

Field Meaning
PID Process ID — unique number on the system right now
PPID Parent PID — who started it
UID/GID Identity the process runs as
State Running, sleeping, stopped, zombie, …

When you type ls, the shell starts an ls process, waits, then shows you the output. Long-running tools (web servers, sleep, editors) stay until they exit or receive a signal.


Listing processes#

ps                # your processes in this terminal (simple view)
ps -ef            # full system-oriented list (many distros)
ps -o pid,ppid,user,stat,cmd   # choose columns

Background demo used in this course:

sleep 90 &
SP=$!
echo "sleep pid=$SP"
ps -p "$SP" -o pid,ppid,user,stat,cmd --no-headers

Example lab output:

sleep pid=1095584
1095584 1095160 box      S    sleep 90
  • S here means interruptible sleep (waiting).
  • $! is the PID of the last background job — handy in scripts and labs.

pgrep finds PIDs by name:

pgrep -n -a sleep
1095584 sleep 90

(-n newest; -a show command line.)

pstree shows parent/child relationships (if installed):

pstree -p $$

$$ is the PID of the current shell. You will see your shell with children underneath.


Signals you should know#

Signals are soft interrupts. Common ones:

Signal Number Typical use
SIGTERM 15 Polite “please exit” (default for kill)
SIGKILL 9 Force kill — cannot be caught or ignored
SIGINT 2 Interrupt — what Ctrl+C usually sends
SIGHUP 1 Hangup — often “reload config” for daemons
SIGSTOP 19 Pause (cannot be caught)
SIGCONT 18 Continue after stop

Habit: try SIGTERM first. Reach for SIGKILL only when a process ignores polite requests.


kill and pkill#

kill "$SP"           # same as kill -TERM — ask nicely
kill -15 "$SP"       # explicit SIGTERM
kill -9 "$SP"        # SIGKILL — last resort
pkill -TERM sleep    # by name (careful on shared systems!)

Polite termination demo:

sleep 90 &
SP=$!
kill -TERM "$SP"
sleep 0.4
ps -p "$SP" >/dev/null 2>&1 && echo alive || echo "terminated (SIGTERM)"
terminated (SIGTERM)

Forced kill demo:

sleep 30 &
SP2=$!
kill -KILL "$SP2"
sleep 0.2
ps -p "$SP2" >/dev/null 2>&1 && echo alive || echo "killed (SIGKILL)"
killed (SIGKILL)

You may also see the shell print Killed when a background job receives SIGKILL — that is expected.


Foreground, background, and jobs (quick)#

sleep 120 &          # background
jobs                 # list jobs in this shell
fg                   # bring most recent job to foreground
# Ctrl+Z             # suspend foreground job (SIGTSTP)
bg                   # resume suspended job in background

This module’s graded skill is PID + signals. Job control is the friendly sibling — practice it when you run long compilers or top.


A calm incident workflow#

When something “won’t die” on a machine you own:

  1. Identify: ps, pgrep -a name, or pstree
  2. Ask politely: kill PID or pkill -TERM name
  3. Wait a second; re-check with ps -p PID
  4. Only then: kill -9 PID
  5. Ask why it hung — kill -9 skips cleanup (temp files, locks)

Never randomly kill -9 -1 or mass-pkill on a production host. Our labs use sleep for a reason.


Common mistakes#

  1. SIGKILL first — skips cleanup; can leave messes. Prefer TERM.
  2. Killing by name too broadly — pkill python might hit more than your script. Check pgrep -a first.
  3. Confusing job numbers with PIDs — kill %1 is a job spec; kill 1234 is a PID.
  4. Forgetting background jobs — close a terminal and wonder why SSH sessions linger; track with jobs / ps.
  5. Assuming PIDs are forever — PIDs get reused after exit. Do not kill an old number hours later without checking.

Hands-on lab#

cd /tmp/linux-lab-pushpjeet
  1. Start sleep 120 & and note echo $!.
  2. Confirm with ps -p $! -o pid,stat,cmd and pgrep -a sleep.
  3. Send kill -TERM $! (or the PID you noted). Confirm it is gone.
  4. Start another sleep 60 &, then kill -9 that PID. Confirm.
  5. Run ps -o pid,ppid,stat,cmd --forest | head and spot your shell in the tree (optional).

Verify: Both sleep processes no longer appear in ps -p.


Practice: check your understanding#

Multiple choice#

1. What is a PID?

  • A. Permanent install disk
  • B. Process ID number for a running program instance
  • C. Permission identity document
  • D. Pipe ID for | only
Answer

B. PID identifies a living process.

2. Default signal sent by kill PID is usually:

  • A. SIGKILL (9)
  • B. SIGTERM (15)
  • C. SIGSTOP
  • D. SIGWINCH
Answer

B. Default is SIGTERM — polite termination.

3. Which signal cannot be caught or ignored?

  • A. SIGTERM
  • B. SIGINT
  • C. SIGKILL
  • D. SIGHUP
Answer

C. SIGKILL (9) is forced; the process does not get to handle it.

4. pgrep sleep returns:

  • A. The text of the sleep man page
  • B. PIDs of matching processes
  • C. Only parent shells
  • D. File permissions
Answer

B. It prints matching process IDs (add -a for command lines).

5. In ps output, PPID means:

  • A. Previous PID on disk
  • B. Parent process ID
  • C. Priority percent ID
  • D. Pipe partner ID
Answer

B. PPID is the parent’s PID.

6. Best first step for a stuck process you own:

  • A. kill -9 immediately
  • B. Reboot without looking
  • C. Identify the PID, send SIGTERM, re-check
  • D. chmod 777
Answer

C. Identify, TERM, verify — then escalate if needed.

Flashcards#

Front Back
PID Process ID
PPID Parent process ID
ps -ef Broad process listing
pgrep -a name Find PIDs + command lines
pkill -TERM name Signal processes by name
SIGTERM (15) Polite exit request
SIGKILL (9) Force kill
SIGINT (2) Ctrl+C
sleep 60 & Start sleep in background
$! PID of last background job

Match the columns#

Signal / tool Use
1 SIGTERM A Force kill, last resort
2 SIGKILL B Polite “please exit”
3 SIGINT C Show process tree
4 pgrep D Usually Ctrl+C
5 pstree E Find PIDs by pattern
6 kill -9 F Same as SIGKILL on a PID
Answer key

1→B, 2→A, 3→D, 4→E, 5→C, 6→F

Fill in the blank#

  1. Background sleep: sleep 80 &
  2. Polite kill: kill -TERM 1234 (use a real PID)
  3. Find sleep PIDs: pgrep -a sleep
  4. Force kill: kill -9 1234
Answer key
  1. & at end
  2. kill -TERM or plain kill
  3. pgrep -a sleep
  4. kill -9 / kill -KILL

Order the steps#

Stop a background sleep safely:

  1. Confirm it is gone with ps -p
  2. sleep 100 & and note $!
  3. kill -TERM that PID
  4. pgrep -a sleep to double-check identity
Answer key

2 → 4 → 3 → 1
(start → identify → SIGTERM → verify)

Mini terminal challenge#

Goal: Full loop — start, find, terminate, verify.

Setup

cd /tmp/linux-lab-pushpjeet

Tasks

  1. Start three sleeps: sleep 200 & sleep 200 & sleep 200 &
  2. List them with pgrep -a sleep (or filter carefully).
  3. Terminate only one PID with kill -TERM.
  4. Verify two remain, then pkill -TERM -P $$ sleep or kill the remaining PIDs explicitly so you leave no leftovers.
  5. Confirm with pgrep sleep (should be empty for your sleeps; ignore other users’ if any).

Verify: No leftover sleep processes from your session.

Stretch: Run ps -o pid,ppid,stat,cmd --forest and sketch parent/child on paper for your shell and one child.


Module wrap (M7–M13)#

You can now edit with vim, lean on bash expansions, redirect and pipe data, manage variables and history, persist shell settings, reason about permissions, and control processes. That is the core CLI toolkit for the rest of Linux from Scratch (scripting, archives, packages, and more when those modules publish).


Continue

← Linux from Scratch hub · Cheat sheet · All tutorials