lsof
Overview
lsof lists open files. On Linux, “files” include sockets, devices, and pipes — so it is essential for “who holds this port?” and “what files does this process have open?”.
Syntax
lsof [options]
lsof -p PID
lsof -i :portCommon Options
| Option | Description |
|---|---|
-p PID |
Files for a process |
-i |
Internet sockets (optional address/port filter) |
-iTCP:443 -sTCP:LISTEN |
Listening TCP on 443 |
-u user |
Files for a user |
+D dir |
Recurse directory (expensive) |
-n -P |
No DNS / no port name resolution (faster) |
-c name |
Command name prefix |
Key Use Cases
- Find process listening on a port
- Debug deleted-but-open files filling disks
- See files held by a stuck process
- Audit network endpoints per process
Examples with Explanations
Who listens on port 22?
sudo lsof -nP -iTCP:22 -sTCP:LISTENClassic “what owns this port?” check (also see ss -lntp).
Open files for a PID
sudo lsof -p $(pgrep -x nginx | head -1)Configs, logs, and sockets held by that process.
Deleted files still open
sudo lsof +L1 | grep deleted
# or: sudo lsof -nP | grep '(deleted)'Process keeps space until close/restart — common disk-full mystery.
Files under a mount
sudo lsof /varSee activity before unmount (umount busy).
Network connections for a user
sudo lsof -u deploy -a -i-a ANDs the filters.
Notes & Pitfalls
- Often needs root for system-wide or other users’ processes.
- Heavy on huge systems; narrow with
-p,-i,-u.