Home / Alt manpages / proc_pid(5)

  • proc_pid(5)
  • File format
  • linux

Inspect a Linux Process Safely with /proc/<pid> and /proc/self

You will inspect a running process through Linux procfs, identify the difference between a numeric process directory and /proc/self, and check the access boundary before reading process data. The examples are read-only apart from starting and stopping a short-lived test process. Allow about ten minutes. No elevated privileges are needed for a process you own.

1. Check the kernel and procfs

The installed reference is proc_pid(5) from Linux man-pages 6.7. The machine used for these examples runs Linux kernel 6.8.0-139-generic. The kernel exposes one numeric directory under /proc for each running process. Check that procfs is mounted and that the current shell can read it:

$ test -d /proc && echo "procfs directory exists"
procfs directory exists
$ ls -ld /proc
dr-xr-xr-x ... /proc

The exact mode display and owner can vary. The useful result is that /proc is a directory. If this check fails, stop here: the examples cannot work until the host or container provides procfs.

2. Start a disposable process and record its PID

Use a process you own so the example does not depend on another service remaining alive. This starts sleep in the background and stores its process ID in a shell variable:

sleep 60 &
pid=$!
printf 'PID=%s\n' "$pid"
test -d "/proc/$pid" && echo "process directory is present"

You should see a numeric PID followed by process directory is present. The directory exists only while that process exists. PIDs can be reused, so treat a saved PID as a short-lived handle, not as a permanent identity.

Checkpoint

Verify that the directory still belongs to the process you started:

$ readlink "/proc/$pid/exe"
/usr/bin/sleep
$ tr '\0' ' ' < "/proc/$pid/cmdline"; printf '\n'
sleep 60

The executable path can differ on another installation, but it should identify the command you launched. If the directory has disappeared, the process has exited; do not inspect a replacement process that happens to receive the same PID.

3. Read a numeric process directory

A path such as /proc/12345/ names the process whose ID is 12345. The directory contains pseudo-files and directories supplied by the kernel rather than ordinary files stored on disk. For a process you own, inspect a compact status summary:

$ sed -n '1,12p' "/proc/$pid/status"
Name:   sleep
Umask:  0022
State:  S (sleeping)
Tgid:   12345
Ngid:   0
Pid:    12345
PPid:   12300
TracerPid:      0
Uid:    1004    1004    1004    1004
Gid:    1004    1004    1004    1004
FDSize: 64
Groups: ...

Values such as the PID, parent PID, user IDs and group IDs are machine-specific. The important check is that the Pid: value matches the directory you opened and that the command name is the expected one. Reading status does not pause, signal or reconfigure the process.

4. Understand /proc/self

/proc/self/ is a special path. It refers to the process making the access, and is equivalent to that process's numeric directory. It is not a permanent alias for your login shell and it is not necessarily the process named by the outer command line.

For example, the shell expands $$ before it starts cat, but cat is the process that opens /proc/self/status:

$ sh -c 'printf "shell pid: %s\n" "$$"; sed -n "1p" /proc/self/status'
shell pid: 12300
Name:   sed

This is a common distraction trap. In a pipeline, each program has its own /proc/self. If you need a stable target across several commands, resolve the PID once and use /proc/$pid/..., quoting the path as shown above.

To demonstrate the alias without starting another process, compare a value read through both paths in one shell. The comparison must be performed by the shell, so the two reads refer to the same shell process:

$ self_pid=$$
$ while IFS=: read -r field numeric_pid; do
>     [ "$field" = "Pid" ] && break
> done < /proc/self/status
$ numeric_pid=${numeric_pid#?}
$ printf 'shell=%s status=%s\n' "$self_pid" "$numeric_pid"
shell=12300 status=12300

5. Check the access boundary

The manpage describes an ownership change designed to protect process information. Files below a process directory are normally owned by that process's effective user and group. If the process's dumpable attribute is not 1, the files are instead owned by root in the relevant user namespace. A set-user-ID transition or an explicit prctl(2) change can affect this attribute.

Inspect the directory metadata before assuming that another process is readable:

$ stat -c 'path=%n owner=%U:%G mode=%A' "/proc/$pid/status"
path=/proc/12345/status owner=andy:dixon mode=-r--r--r--

Names and modes vary with the process and the host's procfs settings. Do not treat root ownership as a request to run everything with sudo. Privilege can expose sensitive process data, and it does not make a stale PID safe. First confirm the numeric PID, the process identity and the reason access is needed. In a container, the root user and group mentioned by procfs may be the root IDs of that user namespace rather than the host's initial namespace.

6. Clean up and recover from the test

Stop only the disposable process created in step 2, then confirm its procfs directory has gone:

kill "$pid"
wait "$pid" 2>/dev/null || true
if test -e "/proc/$pid"; then
    echo "process is still present"
else
    echo "test process has exited"
fi

This signal is directed at the PID stored by the current shell. If you lost the variable, do not guess a PID: use a new test process or leave the unrelated process alone. There is no procfs file to delete and no configuration change to undo.

Common failure modes

  • No such file or directory: the process exited, or the PID was mistyped. Recheck the process immediately before reading its directory.
  • Unexpected command name: the PID was reused after the original process exited. Treat the new contents as unrelated.
  • Permission denied: the target process is protected by its ownership, dumpable state, user namespace or the host's procfs policy. Do not bypass the boundary automatically.
  • Confusing /proc/self output: a helper such as sed, cat or awk opened the path. Use a numeric PID captured at the point you identified the process.

Done means

  • You confirmed that procfs is available and found a live numeric process directory.
  • You checked the command and PID before trusting the directory's contents.
  • You know that /proc/self names the process performing the access, including pipeline helpers.
  • You checked ownership before considering elevated access.
  • Your disposable test process has exited, and no procfs files were deleted or modified.