lsof 4.99.5
Lists open files across every process, which on Linux means sockets, pipes, devices, and directories too. One tool answers what is using this port and why can I not unmount this disk.
Download TAR.GZ Project website ↗Download Mirrors
Linux represents almost everything as a file, which is why one tool answers an unrelated-looking set of questions.
The commands worth knowing
sudo lsof -i :8080 # what is on this port
sudo lsof -i -P -n # every network connection, no name lookups
sudo lsof +L1 # deleted files still held open
sudo lsof +D /mnt/backup # what is using this mount point
sudo lsof -p 1234 # one process
sudo lsof -c nginx # by command name
Use sudo. Without it you only see your own processes, and that is the most common reason people conclude nothing is holding a file when something is.
Use -n -P for anything network related. Name resolution turns a fast command into one that stalls on a slow resolver.
Why the disk is still full
The trick that makes lsof worth learning. You deleted a 40GB log and df reports no change.
Deleting a file removes the directory entry. The inode and its blocks survive until the last descriptor referring to them is closed, and a running process that had it open still has it open.
sudo lsof +L1
+L1 lists files with a link count below one. The NAME column shows the original path with (deleted) appended. Restart the process, or send SIGHUP if it reopens its logs, which is exactly what logrotate relies on.
Why umount says busy
sudo lsof +D /mnt/backup
Very often the answer is a shell whose working directory is inside the mount, including your own in another tab. That shows as an FD of cwd, and closing files does not fix it because the process is standing in the directory rather than holding a file.
Finding descriptor leaks
sudo lsof -p 1234 -r 2 # repeat every 2 seconds
ls /proc/1234/fd | wc -l # current count
cat /proc/1234/limits | grep 'open files'
A count that only grows is a leak, and it is why a service runs fine for days then starts failing with “too many open files.” Our ulimit guide covers the limits side.
fuser, for when you just want it gone
fuser -v /mnt/backup
sudo fuser -km /mnt/backup # kill everything using the mount
Use lsof to understand and fuser to act. Our lsof guide covers both.
Verify Your Download
Most people install from their distribution repository. Source releases are on GitHub.