Computing and the Command Line

What a Process Is

A process is a running program. The kernel starts systemd as process 1, which starts the background services (daemons), and every program you run is a child of your shell. See them with ps (ps, ps x, ps aux and its columns and states), watch them live with top or htop, draw the family tree with pstree, and read load average, memory, and CPU numbers without fooling yourself.

  • 6 min
  • 6 steps
  • 3 questions
  • Lesson 16 of 80

In this lesson

  1. Programs that are running
  2. ps
  3. top
  4. pstree and friends
  5. Your turn
  6. So

Programs that are running

A process is a program that’s running. Linux runs many at once by switching between them very quickly, so it seems they all run together 1.

At boot, the kernel starts a program called init, which on nearly every distribution today is systemd. It’s always process ID 1, and it starts all the system’s services 1. Many of those services are daemons: programs that sit in the background with no window or terminal, like the SSH server, the scheduler cron, and the network manager. So even with nobody logged in, the system is quietly busy 1.

Any process can start others. The starter is the parent, the new one its child: your login session starts bash, and bash starts every command you type 1. A child inherits its parent’s user and environment, which is why export works the way it does.

The kernel keeps track of each process: a process ID (PID), its owner, the memory it uses, and whether it’s ready to run 1. Processes have owners just like files do.

A process tree: systemd, PID 1, started by the kernel; under it daemons sshd (PID 812), cron (640), and NetworkManager (701), labeled background services with no terminal; and a login session (PID 1990), under which is bash (you) (PID 2210), under which are rsync & (PID 2381) in the background and ps (PID 2390) in the foreground. Children inherit the parent's user and environment. Right, ps aux columns: USER owner, PID process ID, %CPU %MEM share of CPU and memory, RSS memory in use in KB, STAT state, START when it started, TIME CPU time used, COMMAND what it is. States: R running, S sleeping or waiting, D waiting on disk, T stopped, Z zombie.
Everything running descends from systemd, process 1. Credit: StudyCorner diagram · CC BY 4.0 · Source

Quick check

Which process always has process ID 1 on a modern Linux system?

ps

ps takes a snapshot of processes 1:

me@linuxbox:~$ ps
    PID TTY          TIME CMD
   2210 pts/0    00:00:00 bash
   2390 pts/0    00:00:00 ps

Plain ps shows only this terminal’s processes. Two option sets cover most needs 1:

me@linuxbox:~$ ps x          # all your processes, terminal or not
me@linuxbox:~$ ps aux        # everyone's processes, with details

(They’re written without a dash, in the older BSD style; ps -ef is the equivalent you’ll see in other guides.)

The ps aux columns 1:

Column Means
USER who owns it
PID process ID
%CPU, %MEM share of processor and memory
RSS physical memory in use, in kilobytes
TTY its terminal; ? means none (a daemon)
STAT state
START, TIME when it started; CPU time used so far
COMMAND the command line

The state letters 1:

State Means
R running, or ready to run
S sleeping: waiting for something, like input or a timer
D waiting on the disk, can’t be interrupted
T stopped (paused)
Z zombie: finished, but its parent hasn’t collected it yet

Extra letters after it mean higher (<) or lower (N) priority, among other things. Mostly you’ll see S: most processes spend their lives waiting.

ps aux is long, so pipe it: ps aux | less, ps aux | grep firefox, or sort by memory with ps aux --sort=-rss | head.

Quick check

In ps aux, most processes show state S. Is the system stuck?

top

top shows processes live, refreshing every few seconds, busiest first 1:

me@linuxbox:~$ top
top - 09:52:01 up 3 days,  2:11,  1 user,  load average: 0.42, 0.37, 0.30
Tasks: 213 total,   1 running, 212 sleeping,   0 stopped,   0 zombie
%Cpu(s):  3.1 us,  1.0 sy,  0.0 ni, 95.6 id,  0.2 wa, ...
MiB Mem :  15899.6 total,   6412.3 free,   4214.0 used,   5273.3 buff/cache

The header 1:

  • Load average: how many processes were running or waiting to run, averaged over the last 1, 5, and 15 minutes. Compare it with your number of CPU cores (nproc): below that, the machine is keeping up; well above it, work is queueing.
  • %Cpu: us is your programs, sy the kernel, id idle, wa waiting on the disk.
  • Mem: buff/cache is memory Linux borrows to cache files; it gives it back the moment a program needs it, so “free” looking small isn’t a problem. available is the number to watch.

Keys inside top: M sorts by memory, P by CPU, k kills a process by PID, 1 shows each core, h for help, q to quit.

htop (sudo apt install htop) is a friendlier version with colors, scrolling, and mouse support. It’s what most people use day to day.

Quick check

Your 4-core machine shows a load average of 3.8. What does that suggest?

pstree and friends

pstree draws the parent-child tree 1:

me@linuxbox:~$ pstree -p | less
systemd(1)─┬─cron(640)
           ├─sshd(812)
           ...

Other quick checks: uptime for load, free -h for memory, vmstat 5 for a running summary every five seconds (Ctrl-C to stop) 1, and pgrep firefox to get a program’s PIDs by name.

Your turn

Exercises

  1. Run ps and ps x. Why is the second list so much longer?
  2. Find PID 1 with ps -p 1. What’s its name?
  3. Show the five processes using the most memory.
  4. Open top. What’s your load average, and how does it compare with nproc? Press M, then q.
  5. Start sleep 300 in one terminal tab. In another, find its PID with pgrep sleep and see its parent with ps -o ppid= -p <PID>. What is the parent?
Answers
  1. ps shows only this terminal’s processes; ps x shows all of yours, including ones with no terminal (?).
  2. systemd (some systems show init, a link to systemd). Under WSL you may see init instead: WSL’s own small startup program, used when systemd isn’t enabled for the distribution.
  3. ps aux --sort=-rss | head -6 (one header line plus five).
  4. On an idle machine, well below the number of cores.
  5. The PID of the bash running in the first tab: ps -p <that PID> shows bash.

So

Every running program is a process with an ID, an owner, and a parent, all descending from systemd, PID 1. ps aux takes a snapshot, top or htop watches live, and pstree shows the family tree. Read load average against your core count, and watch available memory, not free.

Lesson complete

Nice work.

1day streak
0/1today's goal
–correct

Up next · 6 min

Jobs and Signals

Next lesson
Sources for this lesson
  1. 1
    William Shotts. The Linux Command Line, Seventh Internet Edition (25.12A). LinuxCommand.org (print edition by No Starch Press). 2026. verifiedFree CC BY-NC-ND 3.0 book, release 25.12A of July 18, 2026. Part 1, Learning the Shell: the shell and terminal emulators, prompts ($ vs. # for the superuser), command history (most distributions keep the last 1,000 commands), Shift-Ctrl-C/V for copy and paste; navigation and the directory tree; exploring the system (ls options and the long listing, file, less, the guided tour of /, symbolic links); manipulating files (wildcards and character classes, mkdir, cp, mv, rm, ln; no undelete, test wildcards with ls first); working with commands (four kinds of commands, type, which, help, --help, man and its sections, apropos, whatis, info, alias); redirection; expansion and quoting; Readline keyboard tricks, completion, history search; permissions; processes. Later parts cover the environment, vi, packages, storage, networking, find, archiving, regular expressions, text processing, and shell scripting.