Skip to content

lsof: which processes listen on port and hold file

Service won’t start — port 8080 is already bound. You dig into who’s holding it, and discover the same process has your config file open while you’re trying to edit it. lsof answers both questions: which processes opened which files and sockets.

Listening Ports

The classic task — find who is listening on a specific port.

lsof -i -n -P
FlagEffect
-iShow internet sockets
-nSkip DNS resolution (show IP instead of hostname)
-PSkip port-to-service conversion (show 80 instead of http)

Without -n -P, lsof wastes time on DNS lookups and resolves ports through /etc/services. On production hosts that’s unnecessary seconds.

For a specific port:

lsof -i :8080 -n -P
Tip

To find what process is listening on port 443, lsof -i :443 -n -P is sufficient. Output shows PID, user, and socket type (IPv4/IPv6, TCP/UDP).

To filter by protocol:

lsof -i TCP:22 -n -P    # TCP only
lsof -i UDP:53 -n -P    # UDP only

Processes in a Directory

Need to see which processes are working with files inside a directory? lsof +D recursively walks the directory and lists all open files.

lsof +D /var/log/
Warning

On directories with thousands of files (for example, /tmp), this command runs slowly. It traverses the filesystem rather than querying the kernel — this is an O(n) operation.

For non-recursive search (files directly in the directory, no subdirectories), use find + xargs:

find /etc/nginx -maxdepth 1 -type f -exec lsof {}

The result shows all processes holding open files from the specified directory. Typical scenario — cannot unmount a partition because someone is working with files inside it.

Single Process Inventory

When the PID is known, list all open files:

lsof -p 1234

Output includes regular files, libraries (.so), sockets, and pipes. To grep by type:

lsof -p 1234 | grep REG      # regular files only
lsof -p 1234 | grep FIFO     # pipes
lsof -p 1234 | grep IPv      # network sockets
Note

REG — Regular file, DIR — directory, FIFO — named pipe, IPv4/IPv6 — network sockets. The TYPE in lsof output matches the type in /proc/PID/fd.

The reverse operation — find PID by file:

lsof /var/log/syslog

If the file is locked (log rotation fails, unmount does not work), this command shows the culprit.

Truncated Command Names

By default, lsof truncates command names to 9 characters. For long names (java, python) this may not be enough:

lsof +c 0 -i -n -P    # show full command name
lsof +c 20 -p 1234    # up to 20 characters
lsof +c 0 -p $(pgrep -f nginx)
Tip

+c 0 means “no limit”. Useful when working with Java processes where the command line contains dozens of characters of classpath.

Quick Reference

CommandPurpose
lsof -i :PORTWho listens on PORT
lsof -i TCPAll TCP connections
lsof -i UDPAll UDP connections
lsof -p PIDFiles opened by PID
lsof +D DIRProcesses in directory
lsof /path/to/filePID that opened file
lsof +c NLimit command name to N characters
lsof -u USERAll open files for user
lsof -c CMDFiles for processes named CMD

Common Issues

lsof not installed — minimal images require installation:

apt install lsof    # Debian/Ubuntu
yum install lsof    # RHEL/CentOS

No read access to /proc — viewing other users’ processes requires root or group membership with access. Usually means running through sudo.

lsof hangs — kernel not responding to file descriptor requests (NFS issues, stalled filesystem). Ctrl+C and restart with a timeout.


lsof is one of those tools you return to every time you troubleshoot locked resources. Three commands cover 90% of the tasks: -i :PORT for ports, +D /path for directories, -p PID for processes.