Linux lsof Command

Linux 命令大全Linux Command Encyclopedia


A powerful command-line tool used to list all open files and related process information on the current system. In Linux, the "everything is a file" philosophy means lsof can display not only regular files, but also network connections, device files, pipes, sockets, and more.


lsof Basic Syntax

lsof [选项] [文件名或目录]

Common Option Parameter Descriptions

Option Description
-a Use AND logic to combine multiple conditions
-c <进程名> Display files opened by the specified process
-d <文件描述符> Display files with the specified file descriptor
-i Display network connection related information
-n Do not resolve hostnames (display IP addresses)
-P Do not resolve port names (display port numbers)
-p <PID> Display files opened by the specified process ID
-u <用户名> Display files opened by the specified user
+D <目录> Recursively display files opened under the directory
-t Output only process IDs (suitable for scripting)

Common Operation Examples

1. View all open files

lsof

This lists all files opened in the system, including regular files, directories, library files, devices, network connections, and so on.

2. View files opened by a specified process

Example

lsof -p 1234  # View files opened by the process with PID 1234
lsof -c nginx # View files opened by all nginx processes

3. View network connections

Example

lsof -i      # View all network connections
lsof -i :80  # View all connections using port 80
lsof -i TCP  # View all TCP connections

4. View files opened by a user

lsof -u root  # 查看 root 用户打开的文件

5. Find files that are deleted but still occupied by processes

lsof | grep deleted

This situation commonly occurs when log files are deleted but the service is still running, causing disk space to not be released.

6. View files opened under a specified directory

lsof +D /var/log  # 查看 /var/log 目录下被打开的文件

Output Field Explanation

The typical columns in the lsof command output are as follows:

COMMAND    PID   USER   FD      TYPE     DEVICE  SIZE/OFF    NODE NAME
  • COMMAND: Process name
  • PID: Process ID
  • USER: User running the process
  • FD: File descriptor
    • cwd: Current working directory
    • txt: Program code file
    • mem: Memory-mapped file
    • 0u、1u、2u: Standard input, output, error
  • TYPE: File type (REG regular file, DIR directory, CHR character device, etc.)
  • DEVICE: Device number
  • SIZE/OFF: File size or offset
  • NODE: File inode number
  • NAME: File name or mount point

Advanced Use Cases

1. Find processes occupying a port

lsof -i :8080

When you want to start a service but the port is already occupied, this command can quickly find the process occupying the port.

2. Recover deleted files

When a file is deleted but still in use by a process, it can be recovered through the /proc file system:

Example

lsof | grep deleted  # Find the deleted file and process
ls -l /proc//fd  # View the file descriptors of the process
cp /proc//fd/ /path/to/recovery  # Recover the file

3. Monitor file access

watch -n 1 'lsof /path/to/file'

This can monitor in real time which processes are accessing a certain file.


Common Problem Solutions

1. Insufficient disk space but cannot find large files

lsof | grep deleted

Find files that are deleted but still occupied by processes, then restart the related processes to release space.

2. Unable to unmount device

lsof /mount/point

Find which processes are using the mount point, close those processes, and then unmount.

3. Troubleshooting network connection problems

lsof -i -n -P

View all network connections to help troubleshoot port conflicts or connection issues.


Performance Considerations

Although lsof is powerful, you need to be careful when using it in a busy production environment:

  1. Running directlylsofwill scan the entire system and may consume a lot of resources
  2. Try to use precise filter conditions (such as-p、-u、-ietc.) to narrow down the query scope
  3. When using in scripts,-tthe option outputs only PID, reducing parsing overhead.

Alternative Tools

Although lsof is the most commonly used tool, some alternatives can be considered in certain scenarios:

  1. fuser: Quickly view which processes are using a specific file or socket
  2. ss/netstat: Specifically for network connection information
  3. ps: combined with/procthe file system can also obtain some information.

Summary

lsof is the Swiss Army knife for Linux system administrators and developers. Mastering it can help you:

  1. Quickly locate resource occupation problems
  2. Troubleshoot file and network related issues
  3. Understand system running status
  4. Solve various "file in use" problems

It is recommended to practice more in daily work, flexibly use various option parameters according to specific scenarios, and gradually master the full potential of this powerful tool.


Linux 命令大全Linux Command Encyclopedia

Other Extensions