auto
     Q�Ð¾Ù      QFile not found.
     S�Ð¾Ù      SFile not found.
  #   Uˆl–ßi~”Ò~ê�~àpAS�ÿÜ„eÐ:ç¿Ú ?÷     U
			A Quick Start for Lsof

1.  Introduction
================

  Agreed, the lsof man page is dense and lsof has a plethora of
  options.  There are examples, but the manual page format buries
  them at the end.  How does one get started with lsof?

  This file is an attempt to answer that question.  It plunges
  immediately into examples of lsof use to solve problems that
  involve looking at the open files of Unix processes.


			    Contents

	    1.  Introduction
	    2.  Finding Uses of a Specific Open File
	    3.  Finding Open Files Filling a File System
		a.  Finding an Unlinked Open File
	    4.  Finding Processes Blocking Umount
	    5.  Finding Listening Sockets
	    6.  Finding a Particular Network Connection
	    7.  Identifying a Netstat Connection
	    8.  Finding Files Open to a Named Command
	    9.  Deciphering the Remote Login Trail
		a.  The Fundamentals
		b.  The idrlogin.perl[5] Scripts
	    10. Watching an Ftp or Rcp Transfer
	    11. Listing Open NFS Files
	    12. Listing Files Open by a Specific Login
		a.  Ignoring a Specific Login
	    13. Listing Files Open to a Specific Process Group
	    14. When Lsof Seems to Hang
		a.  Kernel lstat(), readlink(), and stat() Blockages
		b.  Problems with /dev or /devices
		c.  Host and Service Name Lookup Hangs
		d.  UID to Login Name Conversion Delays
	    15. Output for Other Programs
	    16. The Lsof Exit Code and Shell Scripts
	    17. Strange messages in the NAME column

			Options

	    A.  Selection Options
	    B.  Output Options
	    C.  Precautionary Options
	    D.  Miscellaneous Lsof Options


2.  Finding Uses of a Specific Open File
========================================

  Often you're interested in knowing who is using a specific file.
  You know the path to it and you want lsof to tell you the processes
  that have open references to it.

  Simple -- execute lsof and give it the path name of the file of
  interest -- e.g.,

  $ lsof /etc/passwd

  Caveat: this only works if lsof has permission to get the status
  (via stat(2)) of the file at the named path.  Unless the lsof
  process has enough authority  -- e.g., it is being run with a
  real User ID (UID) of root -- this AIX example won't work:

  Further caveat: this use of lsof will fail if the stat(2) kernel
  syscall returns different file parameters -- particularly device
  and inode numbers -- than lsof finds in kernel node structures.
  This condition is rare and is usually documented in the 00FAQ
  file of the lsof distribution.

  $ lsof /etc/security/passwd
  lsof: status error on /etc/security/passwd: Permission denied


3.  Finding Open Files Filling a File System
============================================

  Oh! Oh!  /tmp is filling and ls doesn't show that any large files
  are being created.  Can lsof help?

  Maybe.  If there's a process that is writing to a file that has
  been unlinked, lsof may be able to discover the process for you.
  You ask it to list all open files on the file system where /tmp
  is located.

  Sometimes /tmp is a file system by itself.  In that case,

  $ lsof /tmp

  is the appropriate command.  If, however, /tmp is part of another
  file system, typically /, then you may have to ask lsof to list
  all files open on the containing file system and locate the
  offending file and its process by inspection -- e.g.,

    $ lsof / | more
  or
    $ lsof / | grep ...

  Caveat: there must be a file open to a for the lsof search to
  succeed.  Sometimes the kernel may cause a file reference to
  persist, even where there's no file open to a process.  (Can you
  say kernel bug?  Maybe.)  In any event, lsof won't be able to
  help in this case.

  a.  Finding an Unlinked Open File
  =================================

  A pesky variant of a file that is filling a file system is an
  unlinked file to which some process is still writing.  When a
  process opens a file and then unlinks it, the file's resources
  remain in 