Home / Alt manpages / proc_pid_comm(5)

  • proc_pid_comm(5)
  • File format
  • linux

Inspect and Rename Linux Process Names with /proc/pid/comm

You will read the kernel's short command name for a process, rename a disposable test process, and verify the result without changing a service or executable. Allow about ten minutes. The examples use an ordinary shell and do not require sudo.

This guide describes the system on which it was checked: Linux 6.8.0-139-generic with the Debian manpages package at 6.7-2. The installed manual is proc_pid_comm(5) from Linux man-pages 6.7. The interface has existed since Linux 2.6.33, but surrounding tools can display process names differently.

1. Read your shell's command name

Replace PID with a decimal process ID. The file contains the process's comm value, which is a short name associated with the process. It is not the full executable path and it is not the complete argument list.

$ PID=$$
$ printf 'pid=%s\n' "$PID"
pid=12345
$ cat "/proc/$PID/comm"
bash

The PID in the output is an example placeholder. Your shell may be called bash, zsh or something else. Checkpoint: if the file is missing, the process probably exited between discovering its PID and reading it. Obtain a fresh PID rather than retrying an old one.

2. Inspect a known process without changing it

Start a short-lived process in the background and keep its PID in a shell variable. Reading its name is unprivileged. The process below sleeps for five minutes unless you stop it sooner.

$ sleep 300 &
[1] 12346
$ PID=$!
$ printf 'pid=%s comm=' "$PID"
pid=12346 comm=$
$ cat "/proc/$PID/comm"
sleep

Use the process ID, not the job number in square brackets, in the /proc path. The shell's job number is only a local shell reference. You can also inspect the task directory:

$ printf 'tasks: '
$ printf '%s ' "/proc/$PID/task"/*
tasks: /proc/12346/task/12346
$ printf '\n'

A process with one thread normally has one task directory whose numeric name matches the process ID. Multithreaded programs can have several task IDs.

3. Rename the disposable process

Writing a line to /proc/PID/comm changes that process's command name. This is live process state, not a persistent service or executable configuration. Do not test this against a production service merely to make its display name nicer.

$ printf 'batch-check\n' > "/proc/$PID/comm"
$ IFS= read -r NAME < "/proc/$PID/comm"
$ printf 'new comm=%s\n' "$NAME"
new comm=batch-check

Writing the file can fail if the process has already exited or if the kernel's procfs permission checks do not allow the operation. Do not add sudo automatically: elevated access does not make an exited PID safe to reuse. Recheck the PID and the process owner before investigating permissions.

Checkpoint: stop the test process when you are finished. This is the recovery step for the only state change in this guide:

$ kill "$PID"
$ wait "$PID" 2>/dev/null || true
$ test ! -e "/proc/$PID" && echo 'test process stopped'
test process stopped

4. Respect the name limit

The kernel constant TASK_COMM_LEN is 16 bytes, including the terminating null byte. In ordinary ASCII text that leaves at most 15 visible characters. Longer input is silently truncated, so a successful write does not mean the complete string was stored.

$ bash -c 'printf "sixteen-character-name\n" > "/proc/$$/comm"; IFS= read -r name < "/proc/$$/comm"; printf "stored=%s\nlength=%s\n" "$name" "${#name}"'
stored=sixteen-charact
length=15

The child shell is disposable, and the shell built-in read avoids accidentally reading a different process's comm through a separate cat process. For predictable monitoring labels, choose a short ASCII name and read it back after writing.

Threads in one process can have different command names. The per-thread path is /proc/PID/task/TID/comm. A thread may change its own name or the name of another thread in the same thread group by writing through /proc/self/task/TID/comm, subject to the kernel's permission checks.

That distinction matters when a profiler or monitor shows a worker name rather than the main process name. Do not assume that every task under one PID shares the value returned by /proc/PID/comm. Enumerate /proc/PID/task and read each task's comm when thread-level labels matter.

The file is also the procfs counterpart of the prctl(2) PR_SET_NAME and PR_GET_NAME operations. The pthread interface uses it when renaming threads other than the caller. It is a name for diagnostics and process observation, not an access-control identity.

6. Avoid common interpretation errors

  • Do not treat comm as a command line. Use /proc/PID/cmdline when you need arguments, and inspect /proc/PID/exe when you need the executable link.
  • Do not use a stale PID. Linux can reuse a PID after a process exits. Check the process again immediately before reading or writing its procfs files.
  • Do not assume names are unique. Several unrelated processes can have the same comm value. Combine it with a verified PID and, where appropriate, the executable path.
  • Do not rely on a long label. Silent truncation can make two intended labels identical. Verify the stored value rather than trusting the input string.

The comm value is also used for the %e substitution in /proc/sys/kernel/core_pattern. If you are diagnosing core-dump filenames, record the name before changing it and remember that the value can differ between threads.

Done means

  • You can read a live process name from /proc/PID/comm.
  • You can rename a process you intentionally started and read the new value back.
  • You expect up to 15 visible ASCII characters because the limit includes the null byte.
  • You know how process names differ from command-line arguments, executable paths and thread names.
  • Your disposable test process has stopped, and no service or persistent configuration was changed.