Prerequisites#
- Comfort with the shell, background basics (
command &), and reading command output - M10 helps if you use history to recall PIDs you just launched
Learning objectives#
By the end of this module you will be able to:
- Explain PID, PPID, and basic process states in plain language
- List processes with
ps, spot trees withpstree, and find PIDs withpgrep - Stop processes with
kill/pkillusing SIGTERM first and SIGKILL only when needed - Start a background job, locate it, and terminate it on purpose
What a process is#
A process is a running instance of a program. Each has:
| Field | Meaning |
|---|---|
| PID | Process ID — unique number on the system right now |
| PPID | Parent PID — who started it |
| UID/GID | Identity the process runs as |
| State | Running, sleeping, stopped, zombie, … |
When you type ls, the shell starts an ls process, waits, then shows you the output. Long-running tools (web servers, sleep, editors) stay until they exit or receive a signal.
Listing processes#
ps # your processes in this terminal (simple view)
ps -ef # full system-oriented list (many distros)
ps -o pid,ppid,user,stat,cmd # choose columns
Background demo used in this course:
sleep 90 &
SP=$!
echo "sleep pid=$SP"
ps -p "$SP" -o pid,ppid,user,stat,cmd --no-headers
Example lab output:
sleep pid=1095584
1095584 1095160 box S sleep 90
Shere means interruptible sleep (waiting).$!is the PID of the last background job — handy in scripts and labs.
pgrep finds PIDs by name:
pgrep -n -a sleep
1095584 sleep 90
(-n newest; -a show command line.)
pstree shows parent/child relationships (if installed):
pstree -p $$
$$ is the PID of the current shell. You will see your shell with children underneath.
Signals you should know#
Signals are soft interrupts. Common ones:
| Signal | Number | Typical use |
|---|---|---|
| SIGTERM | 15 | Polite “please exit” (default for kill) |
| SIGKILL | 9 | Force kill — cannot be caught or ignored |
| SIGINT | 2 | Interrupt — what Ctrl+C usually sends |
| SIGHUP | 1 | Hangup — often “reload config” for daemons |
| SIGSTOP | 19 | Pause (cannot be caught) |
| SIGCONT | 18 | Continue after stop |
Habit: try SIGTERM first. Reach for SIGKILL only when a process ignores polite requests.
kill and pkill#
kill "$SP" # same as kill -TERM — ask nicely
kill -15 "$SP" # explicit SIGTERM
kill -9 "$SP" # SIGKILL — last resort
pkill -TERM sleep # by name (careful on shared systems!)
Polite termination demo:
sleep 90 &
SP=$!
kill -TERM "$SP"
sleep 0.4
ps -p "$SP" >/dev/null 2>&1 && echo alive || echo "terminated (SIGTERM)"
terminated (SIGTERM)
Forced kill demo:
sleep 30 &
SP2=$!
kill -KILL "$SP2"
sleep 0.2
ps -p "$SP2" >/dev/null 2>&1 && echo alive || echo "killed (SIGKILL)"
killed (SIGKILL)
You may also see the shell print Killed when a background job receives SIGKILL — that is expected.
Foreground, background, and jobs (quick)#
sleep 120 & # background
jobs # list jobs in this shell
fg # bring most recent job to foreground
# Ctrl+Z # suspend foreground job (SIGTSTP)
bg # resume suspended job in background
This module’s graded skill is PID + signals. Job control is the friendly sibling — practice it when you run long compilers or top.
A calm incident workflow#
When something “won’t die” on a machine you own:
- Identify:
ps,pgrep -a name, orpstree - Ask politely:
kill PIDorpkill -TERM name - Wait a second; re-check with
ps -p PID - Only then:
kill -9 PID - Ask why it hung — kill -9 skips cleanup (temp files, locks)
Never randomly kill -9 -1 or mass-pkill on a production host. Our labs use sleep for a reason.
Common mistakes#
- SIGKILL first — skips cleanup; can leave messes. Prefer TERM.
- Killing by name too broadly —
pkill pythonmight hit more than your script. Checkpgrep -afirst. - Confusing job numbers with PIDs —
kill %1is a job spec;kill 1234is a PID. - Forgetting background jobs — close a terminal and wonder why SSH sessions linger; track with
jobs/ps. - Assuming PIDs are forever — PIDs get reused after exit. Do not kill an old number hours later without checking.
Hands-on lab#
cd /tmp/linux-lab-pushpjeet
- Start
sleep 120 &and noteecho $!. - Confirm with
ps -p $! -o pid,stat,cmdandpgrep -a sleep. - Send
kill -TERM $!(or the PID you noted). Confirm it is gone. - Start another
sleep 60 &, thenkill -9that PID. Confirm. - Run
ps -o pid,ppid,stat,cmd --forest | headand spot your shell in the tree (optional).
Verify: Both sleep processes no longer appear in ps -p.
Practice: check your understanding#
Multiple choice#
1. What is a PID?
- A. Permanent install disk
- B. Process ID number for a running program instance
- C. Permission identity document
- D. Pipe ID for
|only
Answer
B. PID identifies a living process.
2. Default signal sent by kill PID is usually:
- A. SIGKILL (9)
- B. SIGTERM (15)
- C. SIGSTOP
- D. SIGWINCH
Answer
B. Default is SIGTERM — polite termination.
3. Which signal cannot be caught or ignored?
- A. SIGTERM
- B. SIGINT
- C. SIGKILL
- D. SIGHUP
Answer
C. SIGKILL (9) is forced; the process does not get to handle it.
4. pgrep sleep returns:
- A. The text of the sleep man page
- B. PIDs of matching processes
- C. Only parent shells
- D. File permissions
Answer
B. It prints matching process IDs (add -a for command lines).
5. In ps output, PPID means:
- A. Previous PID on disk
- B. Parent process ID
- C. Priority percent ID
- D. Pipe partner ID
Answer
B. PPID is the parent’s PID.
6. Best first step for a stuck process you own:
- A.
kill -9immediately - B. Reboot without looking
- C. Identify the PID, send SIGTERM, re-check
- D.
chmod 777
Answer
C. Identify, TERM, verify — then escalate if needed.
Flashcards#
| Front | Back |
|---|---|
| PID | Process ID |
| PPID | Parent process ID |
ps -ef |
Broad process listing |
pgrep -a name |
Find PIDs + command lines |
pkill -TERM name |
Signal processes by name |
| SIGTERM (15) | Polite exit request |
| SIGKILL (9) | Force kill |
| SIGINT (2) | Ctrl+C |
sleep 60 & |
Start sleep in background |
$! |
PID of last background job |
Match the columns#
| Signal / tool | Use | ||
|---|---|---|---|
| 1 | SIGTERM | A | Force kill, last resort |
| 2 | SIGKILL | B | Polite “please exit” |
| 3 | SIGINT | C | Show process tree |
| 4 | pgrep |
D | Usually Ctrl+C |
| 5 | pstree |
E | Find PIDs by pattern |
| 6 | kill -9 |
F | Same as SIGKILL on a PID |
Answer key
1→B, 2→A, 3→D, 4→E, 5→C, 6→F
Fill in the blank#
- Background sleep:
sleep 80 & - Polite kill:
kill -TERM 1234(use a real PID) - Find sleep PIDs:
pgrep -a sleep - Force kill:
kill -9 1234
Answer key
&at endkill -TERMor plainkillpgrep -a sleepkill -9/kill -KILL
Order the steps#
Stop a background sleep safely:
- Confirm it is gone with
ps -p sleep 100 &and note$!kill -TERMthat PIDpgrep -a sleepto double-check identity
Answer key
2 → 4 → 3 → 1
(start → identify → SIGTERM → verify)
Mini terminal challenge#
Goal: Full loop — start, find, terminate, verify.
Setup
cd /tmp/linux-lab-pushpjeet
Tasks
- Start three sleeps:
sleep 200 & sleep 200 & sleep 200 & - List them with
pgrep -a sleep(or filter carefully). - Terminate only one PID with
kill -TERM. - Verify two remain, then
pkill -TERM -P $$ sleepor kill the remaining PIDs explicitly so you leave no leftovers. - Confirm with
pgrep sleep(should be empty for your sleeps; ignore other users’ if any).
Verify: No leftover sleep processes from your session.
Stretch: Run ps -o pid,ppid,stat,cmd --forest and sketch parent/child on paper for your shell and one child.
Module wrap (M7–M13)#
You can now edit with vim, lean on bash expansions, redirect and pipe data, manage variables and history, persist shell settings, reason about permissions, and control processes. That is the core CLI toolkit for the rest of Linux from Scratch (scripting, archives, packages, and more when those modules publish).