Process Management
Reviewed & published by Brayan K
By the end of this lesson you'll be able to see every program running on your machine, find a stuck app by its PID, stop it cleanly (or force it as a last resort), and run long jobs in the background that survive after you log out.
Part of the free Command Line course at LearnCodingFast — hands-on lessons with worked examples and the output they print, plus practice exercises and a quick quiz.
What You'll Learn
- What a process and a PID are, and why every program has one
- List processes with ps aux and monitor them live with top / htop
- Stop processes with kill, kill -9, killall, and pkill
- Foreground vs background: &, jobs, fg, and bg
- Keep jobs alive after logout with nohup
- How signals work — SIGTERM (graceful) vs SIGKILL (forced)
1️⃣ Processes, PIDs & ps
A process is just a running program — your browser, a server, even the shell you're typing in. The operating system gives each one a unique PID (Process ID), a number you use to refer to it. The ps command lists processes. On its own it shows only yours in the current terminal; the classic ps aux shows every process with useful columns like %CPU and %MEM. Pipe it into grep to find one program by name.
# Every running program is a "process" with a unique number: its PID.
# ps shows you those processes. Two forms cover almost everything.
# 1) ps with no options: just YOUR processes in THIS terminal
ps
# 2) ps aux: EVERY process on the machine, with details
# a = all users u = user-readable columns x = include background ones
ps aux
# 3) Pipe into grep to find one program by name (here, node)
ps aux | grep node2️⃣ Live Monitoring with top & htop
ps gives you a single snapshot. When you want to watch what's happening — which process is eating your CPU right now — use top, a live monitor that refreshes every couple of seconds. Inside top, press P to sort by CPU, M to sort by memory, and q to quit. htop is a friendlier, colour version with scrolling and mouse support — install it once and you'll never go back.
# ps is a SNAPSHOT (one moment). top is a LIVE, updating monitor —
# like Task Manager / Activity Monitor in the terminal.
top # built-in everywhere. Press q to quit.
# Press P to sort by CPU, or M to sort by memory.
htop # friendlier, colour version (you may need to install it)
# Ubuntu/Debian: sudo apt install htop
# macOS: brew install htop🎯 Your Turn: Find a Process's PID
Fill in the blanks marked ___ using the hints, then run it. You'll start a throwaway timer and track down its PID — the exact skill you need before you can stop anything.
3️⃣ Stopping Processes: kill & Signals
To stop a process you send it a signal — a short message the kernel delivers. kill PID sends SIGTERM (signal 15): a polite "please shut down" that lets the program save its work, close files, and free up ports. Only if a process ignores that and truly hangs do you reach for kill -9 PID, which sends SIGKILL (signal 9) — the kernel destroys it instantly, with no chance to clean up. Don't know the PID? killall name targets processes by exact name, and pkill -f "pattern" matches anywhere in the command line.
# A "signal" is a message you send to a process. The two that matter most:
# SIGTERM (15) "please shut down" — polite; the program can save & clean up.
# SIGKILL (9) "stop NOW" — the kernel yanks it; no cleanup possible.
# kill sends SIGTERM by default — ALWAYS try this first.
kill 1842 # ask process 1842 to shut down gracefully
# If (and only if) it ignores SIGTERM and hangs, force it with -9 (SIGKILL):
kill -9 1842 # last resort — cannot be caught, blocked, or cleaned up
# Don't know the PID? Target the program by name instead:
killall node # send SIGTERM to EVERY process named exactly "node"
pkill -f "server.js" # match anywhere in the full command line, not just the name
# Pause and resume without killing:
kill -STOP 1842 # freeze the process (it stops using CPU)
kill -CONT 1842 # let it carry onSIGTERM vs SIGKILL — get the order right
Always try kill PID (SIGTERM) first and give it a second or two. Reaching straight for kill -9 can corrupt files, leave locks behind, or strand a database mid-write, because the program never gets to finish what it was doing. kill -9 is the emergency brake, not the parking brake.
4️⃣ Foreground, Background & nohup
When you run a command normally it runs in the foreground and holds your terminal hostage until it finishes. Add a trailing & to run it in the background so you keep working. jobs lists this shell's background and paused jobs; fg pulls one to the foreground and bg resumes a paused one in the background. Press Ctrl+Z to pause whatever's in the foreground. One catch: a plain background job dies when you close the terminal (it receives SIGHUP). Start it with nohup — "no hangup" — and it survives logout.
# A FOREGROUND process owns your terminal until it finishes.
# A BACKGROUND process runs while you keep using the same terminal.
# 1) Start in the background with a trailing & -> prints [job] PID
node server.js & # e.g. "[1] 4821" — job number 1, PID 4821
# 2) See this shell's jobs (+ marks the most recent)
jobs # "[1]+ Running node server.js &"
# 3) Already started something in the FOREGROUND? Pause it with Ctrl+Z,
# then push it to the background, or pull it back:
bg # resume the paused job IN the background
fg %1 # bring job number 1 back to the FOREGROUND
kill %1 # kill a job by its %job-number (not its PID)
# 4) nohup = "no hangup": keep running after you close the terminal / log out.
# Without it, closing the terminal sends SIGHUP and the job dies.
nohup node server.js & # output goes to ./nohup.out
nohup ./backup.sh > backup.log 2>&1 & # send output to your own log filePro Tip
nohup ... & is fine for a quick task, but for a real server you want it to restart on crash and start on boot. Reach for a process manager: pm2 for Node apps, or systemd services on Linux. tmux and screen are also great for keeping interactive sessions alive over SSH.
🎯 Your Turn: Background a Job, Then Reclaim It
Fill in the blanks, then run it. You'll send a timer to the background, confirm it's there with jobs, and pull it back to the foreground.
Common Errors (and the fix)
- Reaching for kill -9 first: SIGKILL gives the process no chance to save data or release ports, which can corrupt files. Always try kill PID (SIGTERM) first; use -9 only when it genuinely won't stop.
- Killing the wrong PID: PIDs get reused, and a quick glance is easy to misread. Confirm with ps -p PID or ps aux | grep name before you kill. Killing the wrong number can take down something important.
- Background job vanishes after logout: a plain command & receives SIGHUP and dies when the terminal closes. Start it with nohup command & so it keeps running.
- bash: kill: (1842) - No such process: that PID has already exited (or you mistyped it). Re-run ps aux | grep name to get the current PID.
- Operation not permitted: you're trying to kill a process owned by another user (often root). Re-run with sudo kill PID — but be doubly sure of the PID first.
📋 Quick Reference
| Command | What it does |
|---|---|
| ps aux | List every running process with details |
| ps aux | grep name | Find a process by name (read its PID) |
| top / htop | Live, updating process monitor |
| kill PID | Graceful stop (SIGTERM) — try this first |
| kill -9 PID | Force kill (SIGKILL) — last resort |
| killall name / pkill -f pat | Kill by name / by command-line pattern |
| command & | Run in the background |
| jobs / fg %1 / bg %1 | List jobs / foreground / background a job |
| nohup command & | Keep a job running after logout |
Signals you'll actually use
| Signal | Number | Meaning |
|---|---|---|
| SIGTERM | 15 | Polite "shut down" — the default for kill; allows cleanup |
| SIGKILL | 9 | Forced kill — cannot be caught or ignored; no cleanup |
| SIGHUP | 1 | "Hang up" — sent on terminal close; also "reload config" |
| SIGINT | 2 | Interrupt from the keyboard (Ctrl+C) |
| SIGSTOP | 19 | Pause a process (Ctrl+Z sends the related SIGTSTP) |
| SIGCONT | 18 | Resume a paused process |
Mini-Challenge: Launch, Inspect & Stop a Server
No blanks this time — just a brief and an outline. Write the commands yourself, run them in your terminal, and check the result against the expected note. This is the exact loop you'll run whenever a server misbehaves.
# 🎯 MINI-CHALLENGE: launch, inspect, and stop a server cleanly.
# Write the commands yourself — no blanks this time. Steps:
#
# 1. Start a long-running job in the background that survives logout,
# sending its output to "app.log". (hint: nohup ... > app.log 2>&1 &)
# 2. Find its PID by filtering ps for the program name. (hint: ps aux | grep ...)
# 3. Ask it to shut down GRACEFULLY first. (hint: kill PID)
# 4. Only if it refuses to stop, force it. (hint: kill -9 PID)
#
# ✅ Expected: step 1 prints "[1] <PID>"; after step 3, "ps -p <PID>"
# shows no row — the process has exited.
# your commands here🎉 Lesson Complete!
- ✅ Every running program is a process with a unique PID
- ✅ ps aux lists processes; top/htop watch them live
- ✅ kill PID (SIGTERM) is graceful; kill -9 (SIGKILL) is a forced last resort
- ✅ killall and pkill -f stop processes by name or pattern
- ✅ &, jobs, fg, and bg move work between foreground and background
- ✅ nohup command & keeps a job alive after you log out
Practice quiz
What is a PID?
- A file permission
- A unique number identifying a process
- A pipe operator
- A shell variable
Answer: A unique number identifying a process. A PID (Process ID) is the unique number the OS gives each process.
Which command lists every process on the machine with details?
- ps aux
- jobs
- cd
- pwd
Answer: ps aux. ps aux shows every process with columns like %CPU and %MEM.
Which signal does plain kill PID send by default?
- SIGKILL (9)
- SIGHUP (1)
- SIGTERM (15)
- SIGINT (2)
Answer: SIGTERM (15). kill sends SIGTERM (15), a polite request to shut down.
What does kill -9 PID do?
- Pauses the process
- Reloads its config
- Lists its threads
- Forcibly kills it with SIGKILL, no cleanup
Answer: Forcibly kills it with SIGKILL, no cleanup. kill -9 sends SIGKILL; the kernel destroys it instantly with no cleanup.
What does adding & to the end of a command do?
- Runs it in the background
- Deletes its output
- Runs it as root
- Repeats it
Answer: Runs it in the background. A trailing & runs the command in the background.
Which command lists the background and stopped jobs in this shell?
- ps
- jobs
- top
- kill
Answer: jobs. jobs lists this shell's background and paused jobs.
Which command keeps a job running after you close the terminal?
- bg
- fg
- nohup
- jobs
Answer: nohup. nohup (no hangup) lets a job survive logout by ignoring SIGHUP.
Which command brings job number 1 back to the foreground?
- bg %1
- kill %1
- jobs %1
- fg %1
Answer: fg %1. fg %1 pulls job number 1 to the foreground.
Why should you try kill before kill -9?
- SIGTERM lets the program save and clean up first
- kill -9 is slower
- kill -9 needs sudo
- They are the same
Answer: SIGTERM lets the program save and clean up first. SIGTERM is graceful; -9 gives no chance to save data or release ports.
Which tool gives a live, continuously updating view of processes?
- ps
- top
- cat
- echo
Answer: top. top is a live monitor that refreshes; ps is just a snapshot.
Continue this course
- Previous: Shell Scripting Basics
- Next: Permissions and Users — Understand file permissions, chmod, chown, and user/group management
- Quick reference: Command Line cheat sheet › Permissions & Jobs
Frequently asked questions
What's the difference between kill and kill -9?
Plain kill sends SIGTERM (signal 15), a polite request to shut down that lets the program save files, close connections, and release ports first. kill -9 sends SIGKILL (signal 9), which the kernel enforces immediately — the program gets no chance to clean up. Always try kill first; use kill -9 only when a process is truly stuck.
How do I find the PID of a process?
Use ps aux | grep <name> to list matching processes (the PID is the number in the second column), or pgrep <name> to print just the PIDs. For a process using a specific port, lsof -i :3000 shows which PID owns port 3000.
Why did my background process die when I closed the terminal?
Closing a terminal sends a SIGHUP ('hang up') signal to its jobs. A plain command & job receives it and exits. Start it with nohup command & (no hangup) so it ignores SIGHUP and keeps running after you log out.
What's the difference between a foreground and a background process?
A foreground process owns your terminal — you can't type another command until it finishes. A background process (started with a trailing &) runs while you keep using the same terminal. Use jobs to list them, fg to pull one to the foreground, and bg to resume a paused one in the background.
What's the difference between kill, killall, and pkill?
kill targets one process by its PID (kill 1842). killall targets every process whose name matches exactly (killall node). pkill matches a pattern, and with -f it matches anywhere in the full command line (pkill -f "server.js"), which is handy when several programs share a name.