Signals and kill
Signals are the kernel's way of tapping a process on the shoulder; learn the ones that matter, TERM, KILL, HUP, INT, STOP and CONT, and how to send them with kill.
What you will learn
- Explain what a signal is and why TERM should be tried before KILL.
- Send signals by name or number with `kill` and list them with `kill -l`.
- Pause and resume a process with STOP and CONT, and recognise what Ctrl-C and Ctrl-Z send.
A signal is a one-word message
Processes do not share memory, so the kernel offers a tiny messaging system: a signal is a number delivered to a process, carrying no data, only its meaning. Each signal has a default action (terminate, terminate with a core dump, stop, continue, or ignore), and most can be caught by the program so it can react, for example by saving its work before exiting. Two cannot be caught, blocked or ignored by anyone: KILL and STOP. The kernel handles them itself.
| Signal | Number | Default | Typical use |
|---|---|---|---|
HUP | 1 | Terminate | Sent when the terminal closes; daemons reread their config on it |
INT | 2 | Terminate | What Ctrl-C sends to the foreground job |
QUIT | 3 | Terminate + core dump | Ctrl-\ ; a debugging exit |
KILL | 9 | Terminate, uncatchable | Last resort; the process gets no chance to clean up |
TERM | 15 | Terminate | The polite request to exit; kill's default |
STOP | 19 | Stop, uncatchable | Freeze a process without killing it |
TSTP | 20 | Stop | What Ctrl-Z sends; programs may catch it |
CONT | 18 | Continue | Wake a stopped process; what fg and bg use |
USR1, USR2 | 10, 12 | Terminate | Free for programs to define (reopen logs, print stats…) |
kill: badly named, widely used
~% kill -l | head -4
1) HUP
2) INT
3) QUIT
4) ILL
~% sleep 3000 &
[1] 1030
~% kill 1030
~% kill -9 1030
sh: can't kill pid 1030: No such process
~% sleep 3000 &
[1] 1033
~% kill -STOP 1033
~% ps -o pid,stat,args | grep '[s]leep'
1033 T sleep 3000
~% kill -CONT 1033
~% kill -s TERM 1033
kill does not kill: it sends a signal, and only the signal's effect decides what happens. With no option it sends TERM, the standard way of asking a program to finish: well-written programs catch it, flush their files, remove their lock files and exit. The signal can be given by name (-TERM, -HUP, -s TERM, and BusyBox also accepts -SIGTERM) or by number (-15, -9). kill -l lists every name with its number. The target is one or more PIDs, or %N for one of your shell's jobs. The first kill 1030 above worked silently; the second failed because the process was already gone.
kill -9 is the sledgehammer. KILL cannot be caught, so the process dies instantly, without saving anything, leaving temporary files, half-written output and locks behind; its children survive, orphaned. Use the sequence kill PID, wait a few seconds, check with ps, and only then kill -9 PID. A process in state D (uninterruptible I/O) will not even die to KILL until the kernel call it is stuck in returns, and a zombie Z is already dead, so neither can be helped by kill.
Where to get the PID
kill wants numbers, so the question is always *which PID*. Read it from ps -o pid,args, from the [1] 1030 line the shell printed when you started the job, from $!, or let the shell substitute it: kill $(pidof sleep) sends TERM to every process named sleep. pidof and killall, which do the lookup for you, are the subject of lesson 56. Signals are also permission-checked: a normal user can only signal their own processes, root can signal anything except PID 1, which ignores signals it has not asked for.
Commands in this lesson
| Command | What it does |
|---|---|
kill -l | List signal names and numbers. |
kill PID | Send TERM: ask the process to exit cleanly. |
kill -9 PID | Send KILL: end it now, no cleanup (last resort). |
kill -HUP PID | Send HUP, by name. |
kill -s TERM PID | Same signal, `-s NAME` syntax. |
kill -STOP PID / kill -CONT PID | Freeze a process / wake it again. |
kill -0 PID | Check that the process exists without signalling it. |
Quiz
What does plain `kill 1234` send?
- SIGKILL (9)
- SIGTERM (15)
- SIGHUP (1)
Why is `kill -9` a last resort?
- It is slower than TERM
- The process cannot catch it, so it dies without saving or cleaning up
- It also kills the parent shell
Which two signals can never be caught or ignored?
- TERM and INT
- KILL and STOP
- HUP and CONT
What signal does Ctrl-C send to the foreground job?
- INT
- TSTP
- KILL
A process has been paused with `kill -STOP`. How do you resume it?
- `kill -START PID`
- `kill -CONT PID`
- Run the command again
Practice
A `sleep 3000` is running. Find its PID (with `ps -o pid,args` or `pidof sleep`) and end it with the default signal.
A `sleep 3000` is running. Terminate it with the signal that cannot be caught or ignored.
A `sleep 3000` is running. Pause it without killing it, so that `ps` shows it in state `T`.
Open this lesson in the app to do the tasks in a real Linux machine and have them checked.