Inspect and Rename Linux Process Names with /proc/pid/comm
You will read the kernel's short command name for a process, rename a disposable test process, and verify the result without changing a service or executable. Allow about ten minutes. The examples use an ordinary shell and do not require sudo.
The route
Jump straight to the step you need, or tick off Done means at the end.
This guide describes the system on which it was checked: Linux 6.8.0-139-generic with the Debian manpages package at 6.7-2. The installed manual is proc_pid_comm(5) from Linux man-pages 6.7. The interface has existed since Linux 2.6.33, but surrounding tools can display process names differently.
1. Read your shell's command name
Replace PID with a decimal process ID. The file contains the process's comm value, which is a short name associated with the process. It is not the full executable path and it is not the complete argument list.
$ PID=$$
$ printf 'pid=%s\n' "$PID"
pid=12345
$ cat "/proc/$PID/comm"
bash
The PID in the output is an example placeholder. Your shell may be called bash, zsh or something else. Checkpoint: if the file is missing, the process probably exited between discovering its PID and reading it. Obtain a fresh PID rather than retrying an old one.
2. Inspect a known process without changing it
Start a short-lived process in the background and keep its PID in a shell variable. Reading its name is unprivileged. The process below sleeps for five minutes unless you stop it sooner.
$ sleep 300 &
[1] 12346
$ PID=$!
$ printf 'pid=%s comm=' "$PID"
pid=12346 comm=$
$ cat "/proc/$PID/comm"
sleep
Use the process ID, not the job number in square brackets, in the /proc path. The shell's job number is only a local shell reference. You can also inspect the task directory:
$ printf 'tasks: '
$ printf '%s ' "/proc/$PID/task"/*
tasks: /proc/12346/task/12346
$ printf '\n'
A process with one thread normally has one task directory whose numeric name matches the process ID. Multithreaded programs can have several task IDs.
3. Rename the disposable process
Writing a line to /proc/PID/comm changes that process's command name. This is live process state, not a persistent service or executable configuration. Do not test this against a production service merely to make its display name nicer.
$ printf 'batch-check\n' > "/proc/$PID/comm"
$ IFS= read -r NAME < "/proc/$PID/comm"
$ printf 'new comm=%s\n' "$NAME"
new comm=batch-check
Writing the file can fail if the process has already exited or if the kernel's procfs permission checks do not allow the operation. Do not add sudo automatically: elevated access does not make an exited PID safe to reuse. Recheck the PID and the process owner before investigating permissions.
Checkpoint: stop the test process when you are finished. This is the recovery step for the only state change in this guide:
$ kill "$PID"
$ wait "$PID" 2>/dev/null || true
$ test ! -e "/proc/$PID" && echo 'test process stopped'
test process stopped
4. Respect the name limit
The kernel constant TASK_COMM_LEN is 16 bytes, including the terminating null byte. In ordinary ASCII text that leaves at most 15 visible characters. Longer input is silently truncated, so a successful write does not mean the complete string was stored.
$ bash -c 'printf "sixteen-character-name\n" > "/proc/$$/comm"; IFS= read -r name < "/proc/$$/comm"; printf "stored=%s\nlength=%s\n" "$name" "${#name}"'
stored=sixteen-charact
length=15
The child shell is disposable, and the shell built-in read avoids accidentally reading a different process's comm through a separate cat process. For predictable monitoring labels, choose a short ASCII name and read it back after writing.
5. Understand threads and related interfaces
Threads in one process can have different command names. The per-thread path is /proc/PID/task/TID/comm. A thread may change its own name or the name of another thread in the same thread group by writing through /proc/self/task/TID/comm, subject to the kernel's permission checks.
That distinction matters when a profiler or monitor shows a worker name rather than the main process name. Do not assume that every task under one PID shares the value returned by /proc/PID/comm. Enumerate /proc/PID/task and read each task's comm when thread-level labels matter.
The file is also the procfs counterpart of the prctl(2) PR_SET_NAME and PR_GET_NAME operations. The pthread interface uses it when renaming threads other than the caller. It is a name for diagnostics and process observation, not an access-control identity.
6. Avoid common interpretation errors
- Do not treat
commas a command line. Use/proc/PID/cmdlinewhen you need arguments, and inspect/proc/PID/exewhen you need the executable link. - Do not use a stale PID. Linux can reuse a PID after a process exits. Check the process again immediately before reading or writing its procfs files.
- Do not assume names are unique. Several unrelated processes can have the same
commvalue. Combine it with a verified PID and, where appropriate, the executable path. - Do not rely on a long label. Silent truncation can make two intended labels identical. Verify the stored value rather than trusting the input string.
The comm value is also used for the %e substitution in /proc/sys/kernel/core_pattern. If you are diagnosing core-dump filenames, record the name before changing it and remember that the value can differ between threads.
Done means
- You can read a live process name from
/proc/PID/comm. - You can rename a process you intentionally started and read the new value back.
- You expect up to 15 visible ASCII characters because the limit includes the null byte.
- You know how process names differ from command-line arguments, executable paths and thread names.
- Your disposable test process has stopped, and no service or persistent configuration was changed.