Home / Alt manpages / fuser(1)

  • fuser(1)
  • User command
  • linux

Find Which Processes Hold a File, Mount or Port with fuser

You will use the installed fuser command to answer the common question "what is using this?" for a file, mounted file system, TCP port or UDP port. Allow about ten minutes. The examples use PSmisc 23.7, installed here as Debian package version 23.7-1build1; output and process names will differ on your machine.

Most checks are ordinary, read-only commands. Looking at another user's processes may produce partial results without elevated privileges. Killing a process is disruptive and needs deliberate confirmation.

1. Check the installed command

Start by confirming which executable is in your path and recording its version. Neither command changes state:

$ command -v fuser
/usr/bin/fuser
$ fuser --version
fuser (PSmisc) 23.7
Copyright (C) 1993-2024 Werner Almesberger and Craig Small

The local manual is the authority for this guide. fuser writes process IDs to standard output, while headings, details and diagnostics go to standard error. That split matters when you put the command in a script.

2. Find processes using an ordinary file

Pass a path in the default file namespace. A file that nobody currently has open produces no process listing and a non-zero status:

$ fuser /path/to/application.sock
$ printf 'status: %s\n' "$?"
status: 1

Replace the placeholder with a real path. If a process is using it, the output includes its PID. Use verbose mode when you need the owner, command and access type:

$ fuser -v /path/to/application.sock
                     USER        PID ACCESS COMMAND
/path/to/application.sock:
                     alice      3142 ...   app

The sample values are illustrative; the installed command will show your host's users and PIDs. In verbose output, access letters include c for current directory, e for executable, f for an open file, r for root directory and m for a mapped file or shared library. Plain output omits some letters, including the ordinary open-file marker.

Checkpoint: if the result is empty but you expect a match, rerun with sudo fuser -v PATH only when your account is authorised to inspect the other processes. The manual warns that an unprivileged lookup can miss file descriptors or classify an executable only as mapped.

3. Check a mounted file system carefully

Use -m to list every process accessing the file system containing a path or mounted block device:

$ sudo fuser -vm /var
                     USER        PID ACCESS COMMAND
/var:                root       1021 ...   systemd-journald

This is broader than checking one file. A directory argument is changed to its trailing slash so a file system mounted there can be found. Read the target twice before using the result.

Do not combine -m and -k casually. That can target every process using the file system. If you mean only the mount point itself, add -M, the mount-point safety check:

$ sudo fuser -v -M /var
$ printf 'status: %s\n' "$?"
status: 1

A status of 1 here means no matching process was reported, or the path was not accepted as the required mount point. The -M guard is especially useful in scripts where a mistyped path might otherwise make -m match a whole device.

4. Identify a process listening on a port

Select the TCP or UDP namespace with -n. The shortcut PORT/tcp is also supported:

$ sudo fuser -v -n tcp 8080
                     USER        PID ACCESS COMMAND
8080/tcp:            andy       4287 F....  python3
$ sudo fuser -v 8080/tcp

The port may be numeric or a service name. If nothing owns the port, expect no PID and a non-zero status. The default search covers both IPv4 and IPv6; use -4 or -6 when you need one address family. These options only affect TCP and UDP searches and cannot be used together.

Use the same pattern for UDP:

$ sudo fuser -v -n udp 5353
                     USER        PID ACCESS COMMAND
5353/udp:            alice      2201 F....  avahi-daemon

Port ownership is a useful first check before restarting a service. It does not tell you whether the process is healthy or whether a firewall allows traffic.

5. Use exit status for a yes-or-no check

Use silent mode when you only need to branch on whether something is in use. It suppresses normal output; the command returns zero when at least one access is found and non-zero when none is found or a fatal error occurs:

$ if fuser -s /var/lib/my-service/state.db; then
>     printf '%s\n' 'state.db is in use'
> else
>     printf '%s\n' 'state.db is not reported as in use'
> fi
state.db is in use

Do not add -a to this form. The manual says -a and -s must not be used together. Also remember that a non-zero result can mean an access was hidden by permissions, not necessarily that the path is genuinely unused.

6. Stop only the intended process

-k sends a signal to processes using the target. Its default is SIGKILL, which gives the process no opportunity to clean up. Treat it as a last resort, and inspect the verbose result first:

$ sudo fuser -v -n tcp 8080
$ sudo fuser -v -k -i -n tcp 8080
                     USER        PID ACCESS COMMAND
8080/tcp:            andy       4287 F....  python3
Kill process 4287? (y/N)

The -i prompt is ignored unless -k is present. Prefer a gentler, explicit signal when the program supports a clean shutdown:

$ sudo fuser -v -k -i -TERM -n tcp 8080

Signals can be named, such as -TERM, or numbered, such as -15. Never paste a broad mount path into a kill command without checking it. To recover, restart the affected service through its normal service manager, for example sudo systemctl restart SERVICE_NAME, if that is how the service is managed. A killed process may lose unsaved work; fuser cannot undo that.

Common traps

  • Run with sudo when the result is incomplete, but treat the permission boundary as a diagnostic clue rather than a reason to use root automatically.
  • Do not confuse -m with a single-file lookup. It means the whole file system on the device, while -M restricts the request to an actual mount point.
  • Do not expect kernel accesses to appear in normal output. The manual says they are shown only with -v.
  • Processes in another mount namespace, and some network-mounted or mapped-file cases, may not match. Check the service's namespace and use a suitable namespace-aware diagnostic when fuser's view is incomplete.
  • Repeated access of the same kind is reported once. A PID list is not a count of open descriptors.

Done means

  • You confirmed the installed PSmisc version and selected the correct namespace.
  • You used -v to inspect the owner and command before taking action.
  • You used -M when a mount-point-only check was intended.
  • You treated empty or non-zero output as possibly permission-limited.
  • You reserved -k for a reviewed target, used -i where practical, and know how the service will be recovered.