Processes, PIDs, and process states
ps, top, and understanding what a process actually is. · 9 min
A process is a running instance of a program, and every process has a unique Process ID (PID) assigned by the kernel, plus a Parent Process ID (PPID) identifying which process started it. PID 1 is always the first process the kernel starts at boot — on virtually all modern distributions, that's `systemd`, which then starts every other process, directly or indirectly, making every process on the system a descendant of PID 1.
A process moves through states over its lifetime: Running (actively executing or ready to), Sleeping (waiting for something — input, a timer, a lock — the most common state for an idle process), Stopped (paused, typically by a signal, resumable), and Zombie (the process has finished executing but its parent hasn't yet collected its exit status — a genuine zombie is harmless in small numbers but indicates the parent process has a bug if they accumulate). An orphan process is one whose parent exited first; it gets automatically re-parented to PID 1 (or a subreaper) so it isn't left dangling.
`ps` gives a snapshot of processes at the moment you run it; `top` (or the friendlier `htop`, often installed separately) gives a live, continuously updating view sorted by resource usage — your default tool for "what is actually using CPU/memory right now on this box".
| Command | Purpose | Example |
|---|---|---|
| ps aux | List all running processes with detailed info (user, CPU%, memory%, command) | — |
| ps -ef | Alternative process listing format, showing PPID clearly | — |
| top | Live, continuously updating process viewer sorted by CPU usage by default | — |
| htop | A more user-friendly, colorized live process viewer (often needs installing separately) | — |
| pgrep | Find PIDs by process name | pgrep nginx |
| pidof | Find the PID(s) of a running program by exact name | pidof sshd |
Takeaway: Every process on the system is a descendant of PID 1 (systemd on modern distros) — `ps -ef` showing PPID is how you trace that ancestry when you need to understand what actually launched a misbehaving process.