Monday, August 31, 2015

diffrence between zombie and orphan process


Zombie Process :
---------------------

If the child process is dead but its parent process is alive, the child process is declared zombie, means if you run ps aux, you will see that the just died child process is having a Z in the STAT column.

>> It does not use resources and it cannot be scheduled for execution. 

Sometimes the parent process keeps the child in the zombie state to ensure that the future children processes will not receive the same PID

$ ps aux | grep Z

Orphan Process :
---------------------

If parent process is dead but its child process is alive, the child process is declared orphan, means it is now adopted by its new parent .. the init process.

An Orphan Process is a process whose parent is dead (terminated). A process with dead parents is adopted by the init process.
When does a process become an orphan process?
Sometimes, when a process crashes, it leaves the children processes alive, transforming them into orphan processes. A user can also create a orphan process, by detaching it from the terminal.
How to find orphaned processes:
This command will not display only the orphaned processes, but all the processes having the PPID 1 (having the init process as it’s parent).
ps -elf | head -1; ps -elf | awk '{if ($5 == 1) {print $0}}'
The command snapshots all the processes with PPID 1. Keep that result. Thereafter, you may periodically run the command to compare the result of the time with snapshot taken earlier. Any differences found in the new snapshot might be potentially being orphan processes.
Note, the differences found are only suggest that they’re potential (not confirm) orphan processes in Linux system. You have to get more info to confirm them before terminating those processes. For example, how STIME figure, CPU utilization, understanding its purpose of executing, etc.
Once you have confirm them, you should not hesitate to terminate them as soon as possible, by the kill -9 command, as orphan processes will drain out your Linux system resources over the time.
>> Orphan processes use a lot of resources, so they can be easily found with top or htop. 
To kill an orphaned process, use kill -9 PID.

How to Kill a Process

How to Kill a Process
You may want to stop a process while it is running. For instance, you may be running a program that contains an endless loop, so that the process you created will never stop. Or you may decide not to complete a process you started, either because it is hogging system resources or because it is doing something unintended. If your process is actively running, just hit the BREAK or DELETE key However, you cannot terminate a background process or one attached to a different terminal this way, unless you bring it back to the foreground.
You should observe some cautions when using kill to end processes. Before you attempt to kill a process, you should ensure that you have correctly identified the process ID (PID) you wish to kill. In this “family” relationship that is built as processes spawn others, you can inadvertently kill a process that is the parent of the one you want to kill, and leave an orphan, or—in the worst case—a zombie (a process that still appears in the process table as though it were active, but either has been killed or has completed and is consuming no resources).
You may also transpose numbers in the PID and kill a process that is being used for a different purpose, even a system-level process. The results can be disastrous, especially if you use what is known as a “sure (or unconditional) kill.” This type of kill is discussed in the next section.
To terminate such a process, or kill it, use the kill command, giving the process ID as an argument. For instance, to kill the process with PID 2312 (as revealed by ps), type
$  kill  2312
This command sends a signal to the process. In particular, when used with no arguments, the kill command sends the signal 15 to the process. (Over 30 different signals can be sent on UNIX systems. See Table 11–1, in the section “Signals and Semaphores,” for a list.) Signal 15 is the software termination signal (SIGTERM) that is used to stop processes.
Table 11–1: The Thirty Most Common UNIX Signals
Signal
Abbreviation
Meaning
1)
HUP
Hangup
2)
INT
Interrupt
3)
QUIT
Quit
4)
ILL
Illegal instruction
5)
TRAP
Trace/breakpoint trap
6)
ABRT
Abort
7)
EMT
Emulation trap
8)
FPE
Floating point exception
9)
KILL
Kill
10)
BUS
Bus error
11)
SEGV
Segmentation fault
12)
SIGSYS
Bad system call
13)
PIPE
Broken pipe
14)
ALRM
Alarm clock
15)
TERM
Terminated
16)
USR1
User signal 1
17)
USR2
User signal 2
18)
CLD
Child status changed
19)
PWR
Power failure
20)
WINCH
Window size change
21)
URG
Urgent socket condition
22)
POLL
Pollable event
23)
STOP
Stopped
24)
STP
Stopped (user)
25)
CONT
Continued
26)
TTIN
Stopped terminal input
27)
TTOU
Stopped terminal output
28)
VTALRM
Virtual timer expired
29)
PROF
Profiling timer expired
30)
XCPU
CPU time exceeded
Some processes, such as the shell, do not die when they receive this signal. You can kill processes that ignore signal 15 by supplying the kill command with the −9 flag. This sends the signal 9, which is the unconditional kill signal, to the process. For instance, to kill a shell process with PID 517, type
$ kill −9 517
You may want to use kill −9 to terminate sessions. For instance, you may have forgotten to log off at work. When you log in remotely from home and use the ps command, you will see that you are logged in from two terminals. You can kill the session you have at work by using the kill −9 command.
To do this, first issue the ps command to see your running processes:
$ ps
 PID     TTY        TIME    COMD
 3211    term/41    0:05    ksh
12326    term/41    0:01    ps
12233    term/15    0:20    ksh
You can see that there are two kshs running: one attached to terminal 41, one, to terminal 15. The ps command just issued is also associated with terminal 41. Thus, the ksh associated with term/15, with process number (PID) 12233, is the login at work. To kill that login shell, use the command
$  kill  −9  12233
You can also kill all the processes that you created during your current terminal login session. A process group is a set of related processes, for example, all those with a common ancestor that is a login shell. Use the command
$  kill  0
to terminate all processes in the process group.
If you program in Shell (see Chapter 20), you may want to know if a particular process is running prior to executing a command. The −0 (zero) option of kill allows you to do this. Putting the string
kill  −0  pid
into your shell script will return a value indicating whether or not the indicated process (pid) is alive.

Parent and Child Processes

When you type a command line on your UNIX system, the shell handles its execution. If the command is a built-in command known by the shell (echo, break, exit, test, and so forth), it is executed internally without creating a new process. If the command is not a built-in, the shell treats it as an executable file. The current shell uses the system call fork and creates a child process, which executes the command. The parent process, the shell, waits until the child either completes execution or dies, and then it returns to read the next command.
Normally when the shell creates the child process, it executes a wait system call. This suspends operation of the parent shell until it receives a signal from the kernel indicating the death of a child. At that point, the parent process wakes up and looks for a new command.
When you issue a command that takes a long time to run (e.g., a troff command to format a long article), you usually need to wait until the command terminates. When the troff job finishes, a signal is sent to the parent shell, and the shell begins paying attention to your input once again. You can run multiple processes at the same time by putting jobs into the background. If you end a command line with the ampersand (&) symbol, you tell the shell to run this command in the background. The command string
$ cat * troff -mm lp 2> /dev/null &
causes all the files in the current directory to be formatted and sent to the printer. Because this command would take several minutes to run, it is placed in the background with the & symbol.
When the shell sees the & at the end of the command, it forks off a child shell to execute the command, but it does not execute the wait system call. Instead of suspending operation until the child dies, the parent shell resumes processing commands immediately If anything goes wrong with the process, the output of the lp command is redirected to the device /dev/ null(discarded) to avoid a lengthy printout of garbage.
The shell provides programming control of the commands and shell scripts you execute. The command format
$ (command; command; command) &
instructs the shell to create a child or subshell to run the sequence of commands, and to place this subshell in the background.

Wednesday, July 29, 2015

Basic capabilities of BASH History:



Basic capabilities of BASH History:1.To see all the commands what we executed previously
#history

2.To check the history size of your system
#echo $HISTSIZE

3.To check where is your history file, which stores all your previous commands
#echo $HISTFILE

4.To browse history.Just press up/down arrow to browse history
5.To see all the commands which have particular word#history  | grep string
Example:#history | grep cd
Medium capabilities of Bash history:6.Some times browsing history is very tedious job and some times we are executing some big big commands so there is a capability in Bash to over come this ie search-i-reverse. For doing this press ctrl+r and type a string in previous command which you want to execute. 

Lets see it with an exampleroot@krishna-laptop:~#(reverse-i-search)`se': service winbind restart
if you see above I just pressed ctrl+r and then started to type se, it is showingservice winbind restart command, so I no need to type entire command and I have to justent press enter 

root@krishna-laptop:~# service winbind restart 
* Stopping the Winbind daemon winbind [ OK ] 
* Starting the Winbind daemon winbind [ OK ]
root@krishna-laptop:~#
7.Changing the size of history. Most of the Linux machines by default it can store up to 500 previously executed commands. Some people likes to change it to some value, here i want to keep my previously executed 3000 commands. 
#HISTSIZE=3000


8.to execute previous command#!!
or
!-1

9.To execute 25 command in bash history
#!25 


10.To execute a recent command which start with a string 
#!string

11.To clear all the history#HISTSIZE=0
or 
#history –c
12.In Linux when we execute some command there will be no output of the command, for example useradd or mount -a commands will not give you output saying that command is executed successfully or not at that time we can used the below command to see whether the previous command is executed successfully or not#echo $?If the out put of the above command is “0”, that indicates previous command executed successfully, for any other values the command is not executed successfully(total there are 256 values, 0-255).

Tuesday, July 28, 2015

Linux find command AND Operator !!

Linux find command AND Operator

By default find command will use AND option between two options. No need of mentioning any option. For example see below examples.
Example: find all the files which are more than 100MB and less than 1GB in size.
find / -size +100M -size -1G
or
find / -size +100M -a -size -1G
Like above we can combine many options and your find command use AND operator by default no need of mentioning -a option.

Search for files and execute commands on Found files

find a file with passwd.txt in /var folder and long list this file for checking file properties.
find /var -iname passwd.txt -exec ls -l {} ;
Let me explain above command. Up to find /var -iname passwd.txt, this command you are aware. This command will search for passwd.txt file in /var folder and give the paths and file names where this file is located.
-exec: with this option we are saying to find command to execute a command(here its ls -l) followed by this option
{} -This is used as input to the command which we get as files/folders from find command output.
; –This indicates that find command is completed.
Actually ; is a command chaining capability and it’s a special character. In order to negate this special character we are using before;.
Example35: Find all the files with name test.txt in /mnt and change the ownership of the files from Surendra to Narendra
find /mnt -user surendra -name test.txt -exec chown narendra: {} ;
-exec command {} ; –for executing a command on find files -inum -For finding a file with inode number
Example36:Find all the files with name test.sh in /abc folder and then grep if for word is there in that file or not
find /abc -name test.sh -exec grep ‘for’ {} ;
chmod, grep, ls, rm, mv, cp,md5sum
Example37: Find all the files with name xyz.txt owned by Surendra in /var/ftp/pub and change the permissions to 775 to them.
find /var/ftp -user surendra -name xyz.txt -exec chmod 775 {} ;
Example 38:Find all the files with name temp.txt in /xyz folder and backup then compress them to send it for saving
Find /xyz -name xyz.txt -exec tar cvfz temp.tar.gz {} ;
Example39:Find files with name abc.txt in /home directory and take backup of each file before modifying it.
find /home -name abc.txt -exec cp {} {}.bkf ;
This above command will create files with .bkf extension whenever it finds abc.txt file.
Example40:Find files which are more than 1GB and not accessed for the past 6 months and delete them.
find / -size +1G -mtime +180 -exec rm -rf {} ;
Example41:Find all the files with executable permissions and display their checksum value
find / -perm /a=x -exec md5sum {} ;
Example42:find all the files with name abc.txt and owner as surendra then move them to /opt folder
find / -user surendra -name abc.txt -exec mv {} /opt/ ;
There are many other commands you can try your own. Some other commands which can work with -exec option is mv, md5sum etc.

Find command with multiple -exec option

Find command is capable of using multiple times using the same option(We seen it for finding files which are more than 200M and less then 1GB). In our previous examples we used -size to mention the size between two sizes. Similarly we can use -exec command multiple times.
Example43:Find files with abc.txt name in /opt directory change the owner permissions from Surendra to Narendra and change the permissions to 775
find /opt -user Surendra -name abc.txt -exec chown Narendra: {} ; -exec chmod 775 {} ;
Note: We can use this multiple -exec option more than two times.

Search for multiple files

Till this point if you observe we just search for single file. But sometimes there is a requirement to search for multiple files with single find command to save some valuable time. The following two examples we will see how to do that.Example44: Find all the commands which ends with .sh file extension in /opt folder

Linux Bash Shell short cuts !!



Frequently used shortcut keys

Ctrl+a – Bring back the courser to start of the bash prompt
Ctrl+c – Cancel the command before executing it
Ctrl+d – Logout from the Shell
Ctrl+e – Move the courser to end of the command
Ctrl+l – Clear the screen
Ctrl+r – Search the history reverse order
Ctrl+p – go to previous command in history
Ctrl+n – Go to next command in history
Ctrl+s – Suspend terminal output(Useful for long out commands )
Ctrl+z – suspend the command/send command running to background

 Less frequently used shortcut keys

Alt+. – To paste last used word from previous command
Ctrl + b – move backward one character
Alt + c – capitalize to end of word starting at cursor
Alt + d – delete to end of word starting at cursor
Ctrl + f – move forward one character
Ctrl + h – delete character before the cursor
Ctrl + k – delete all characters from cursor to the end of the command line
Alt + l – make lowercase from cursor to end of word
Ctrl + q – contunue the output after pressing ctrl+s
Ctrl + s – stops the output to the screen (for long running verbose command)
Alt + u – make uppercase from cursor to end of word
Ctrl + u – delete all characters from cursor to the start of the command line
Ctrl + w – delete from cursor to start of word, for each press this will delete one word at a time 
Ctrl + y – paste the word(s) which are cut by using ctrl+k or u or w
Ctrl + xx – move to and fro from cursor to start and vice-versa.

Auto completion

When we are at prompt we can press press TAB key to auto-complete commands, directories, removing files/directories etc. We will see these as examples below for better understanding.
Example1: Execute lsdiff command to see if any files are modified by using auto complete without executing entire command.
ls
Below commands are displayed to see which commands starts with ls
ls           lsb_release  lshw         lsof         lspgpot      
lsattr       lscpu        lsinitramfs  lspci        lss16toppm   
lsblk        lsdiff       lsmod        lspcmcia     lsusb   
Now if you type d then press  it will complete the lsdiff command as shown below because there is no other command which start with lsd name.
lsdiff
Example2: Directory structure autocompletion. Suppose I want to open smb.conf which is located in /etc/samba folder we can open this by just typing /et/sa/sm to open /etc/samba/smb.conf file.
vi /et
vi /etc/sa
vi /etc/samba/sm
vi /etc/samba/smb.conf

Wildcards


Example3: Bash support wildcards. Delete all the files which are .sh file extension by using *.
rm -rf *.sh
Example4: I want to list all the files which starts with file and ends with .txt and having one character in between them.
ls -l file?.txt
This command will list all the files such as file1.txt, filea.txt, filez.txt etc.
Example5: List all the files which ends with a or b or c and start with file.
ls -l file[abc]
This will list filea, fileb and filec
Example6: List all the files which end with a to z, how can I do that?
ls -l file[a-z]
lists the files from filea, fileb to filez.
Example7: Move all the files expect .sh file extention files from present directory to /opt.
mv !(*.sh) /opt
Please share your thoughts on this.

 History

!! – To execute previous executed command
!n – To execute nth previous executed command
!-n – To execute nth command from latest executed command
!char – To execute command which start with char

How to debug a Shell script in Linux !!!

source

Debugging a shell script is very essential to check your script for any errors before moving it into production. In this post we will see different debugging options useful for running your scripts without a flaw. When executing a shell script use sh command with below options to debug a shell script in effective way.  

Option -x: If you set this option, it will show you each line before it executes it. Make a note that comments will not be reported.
sh -x scriptname
Option -v: Echo’s each line as it is read. It’s a kind of verbose and even echo back commented lines as well.
sh -v scriptname
Note: A small difference between -x and -v is that -v echo’s the line as it is read (So it will even display comments too.), whereas -x flag causes each command to be echoed as it is executed.
sh -xv scriptname
Option -u: At times you use a variable without setting some value to it. If you use this flag it will give you the error saying "so and so" variable is not set before executing the script.
sh -u scriptname
Option -e: Exit the shell script if any error occurs. This option will stop the script to run further once the script encounters an error. Use full for debugging the first error itself when running big scripts…
sh -e scriptname
Option -n: Check for syntax errors. This option is verymuch usefull for new commers to check for if, for, while, case etc statements
sh -n scriptname
Note: This options will not give any error if the command you are running is not present in your machine.
Controlled debugging:
We can use set -x at start of your code in your shell script to enable debugging and use set +x to disable debugging.
 
Tips: 1) Always use vim editor to get the syntax error at the time of editing the script itself.
      2) Place brackets in a meaning full way using tabs.
      3) Try to read and understand the script before running a script. 4) Try to give as many comments as possible for better understanding of the script.
Debugging a shell script is very essential to check your script for any errors before moving it into production. In this post we will see different debugging options useful for running your scripts without a flaw. When executing a shell script use sh command with below options to debug a shell script in effective way.    
Option -x: If you set this option, it will show you each line before it executes it. Make a note that comments will not be reported.
sh -x scriptname
Option -v: Echo’s each line as it is read. It’s a kind of verbose and even echo back commented lines as well.
sh -v scriptname
Note: A small difference between -x and -v is that -v echo’s the line as it is read (So it will even display comments too.), whereas -x flag causes each command to be echoed as it is executed.
sh -xv scriptname
Option -u: At times you use a variable without setting some value to it. If you use this flag it will give you the error saying "so and so" variable is not set before executing the script.
sh -u scriptname
Option -e: Exit the shell script if any error occurs. This option will stop the script to run further once the script encounters an error. Use full for debugging the first error itself when running big scripts…
sh -e scriptname
Option -n: Check for syntax errors. This option is verymuch usefull for new commers to check for if, for, while, case etc statements
sh -n scriptname
Note: This options will not give any error if the command you are running is not present in your machine.
Controlled debugging:
We can use set -x at start of your code in your shell script to enable debugging and use set +x to disable debugging.
 
Tips: 1) Always use vim editor to get the syntax error at the time of editing the script itself.
      2) Place brackets in a meaning full way using tabs.
      3) Try to read and understand the script before running a script. 4) Try to give as many comments as possible for better understanding of the script.