Skip to content

Zombie process

A terminated Unix child process whose process-table record and exit status remain until its parent waits and the kernel reaps it.

Version
v1 · 2026-09-28 · History
Domain-specific #
12960
Domain group
Applied Sciences & Engineering
Origin domain
Computer Science & Software Engineering
Subdomains
Operating Systems, Unix Process Management → Computer Science & Software Engineering
Aliases
Defunct process

Core Idea

A Unix child does not disappear at the instant it exits. The kernel releases its execution resources but retains a minimal process-table entry containing identity and exit status so the parent can learn how it finished. During this interval the child is a zombie or defunct process.

When the parent calls wait, the status is delivered and the kernel reaps the entry, freeing the PID for reuse. A zombie cannot be killed because it is already dead; the repair belongs to the parent–reaper relationship. This differs from an orphan, which is still executing after its parent has died and can be adopted by a designated reaper.

Structural Signature

Sig role-phrases:

  • terminated child — has finished execution and can no longer run code It is essential. Counterfactual: A live process cannot be a zombie.
  • exit status — provides completion information still owed to the parent It is essential. Counterfactual: Without pending status there is no reason to retain the child record.
  • process-table entry — holds PID and termination metadata after resource release It is essential. Counterfactual: Once removed, the zombie no longer exists as a process state.
  • parent process — owns the responsibility and opportunity to collect child status It is essential. Counterfactual: Zombie state is relational to parent–child lifecycle.
  • wait operation — collects status and permits reaping It is essential. Counterfactual: Failure to wait is what makes the record persist.
  • kernel reaping — removes the residual record and permits PID reuse It is essential. Counterfactual: A user-space signal cannot terminate something already dead.

What It Is Not

  • It is not a running process that is merely hung.
  • It is not an orphan process.
  • It is not consuming its former full address space and CPU.
  • It is not removable by sending a normal termination signal to the zombie itself.
  • Closest near-miss. An orphan is alive after losing its parent; adoption by a reaper prevents its eventual exit status from remaining indefinitely.

Scope of Application

  • Unix process control. Parent–child exit status is transmitted through wait.
  • Server debugging. Persistent zombies reveal missing reaping logic.
  • Resource management. Accumulation consumes process-table and PID capacity.
  • Operating-system teaching. The state separates execution lifetime from accounting lifetime.

Clarity

Report process state, PID, parent PID, duration, count, and whether the parent is live and waiting. Distinguish transient normal zombies from persistent accumulation. File or buffer retention can involve related process or descriptor behavior and should not be attributed without verification.

Manages Complexity

The state is a deliberately tiny remnant that makes asynchronous child completion reliable. Its morbid metaphor obscures the protocol: the kernel preserves information rather than code. Problems arise from unbounded accumulation, not from a brief record.

Abstract Reasoning

  1. Confirm the process has terminated rather than merely stopped or slept.
  2. Inspect whether a defunct process-table entry remains.
  3. Identify the parent and the uncollected exit status relationship.
  4. Determine whether the state is transient or accumulating.
  5. Check parent handling of child-exit notification and wait calls.
  6. Allow the appropriate parent or reaper to collect status.
  7. Verify entry removal and prevent recurrence in process-control logic.

Knowledge Transfer

The general pattern—completed task retained until acknowledgment—transfers to queues and distributed systems. The Unix zombie identity stops at process-table semantics and parent wait protocol. A stale record elsewhere may be analogous but is not a zombie process.

Examples

Applied / In Practice

A child exits and appears briefly as defunct before its parent immediately calls wait.

Mapped back: status handoff → The zombie preserves the completion result only until collection..

Applied / In Practice

A long-running parent repeatedly spawns children but never waits, filling process-table slots with defunct entries.

Mapped back: accumulation → Each dead child retains a small kernel record..

Applied / In Practice

A running child continues after its parent exits and is adopted by a system reaper.

Mapped back: boundary → It is an orphan, not a zombie..

Structural Tensions

T1 — Completion versus Accounting Persistence. Execution has ended, yet parent–child protocol requires a remaining identity and status.

Diagnostic: Distinguish liveness from existence of a process-table record.

T2 — Small Per-Record Cost versus Systemic Accumulation. One zombie uses little space, while many can exhaust PID or table capacity and signal a faulty parent.

Diagnostic: Measure count and parent ownership rather than treating one transient zombie as a crisis.

Structural–Framed Character

Termination, status, and reaping are structural kernel states; whether persistence is erroneous is operationally framed by duration and workload. A state designed for correctness becomes a leak only when the consumer fails.

Structural Core vs. Domain Accent

The skeleton is completed work whose acknowledgment record remains. Unix supplies PIDs, parent–child relation, exit status, wait, signals, and process tables. Those mechanisms define the zombie.

This entry is a kind of Process state.

  • Approved root. Frozen DAG placement is unparented.

  • Related — orphan process and wait system call. They provide the contrasting live state and the reaping mechanism.

Relationships to Other Abstractions

Local relationship map for Zombie processParents appear above the current abstraction, mutual partners to the right, and children below. Node labels state whether each abstraction is prime or domain-specific; colors identify relation types.Zombie processDOMAINDomain-specific abstraction: Process state — is a kind ofProcess stateDOMAIN

Current abstraction Zombie process Domain-specific

Parents (1) — more general patterns this builds on

  • Zombie process is a kind of Process state Domain-specific

    Zombie process is a domain-specific instance of process state under its frozen identity. The complete catalog already supplies this broader identity.

Hierarchy path (1) — routes to 1 parentless root

Neighborhood in Abstraction Space

Zombie process sits in a moderately populated region (53rd percentile for distinctiveness): it has near-neighbors but no dense thicket of look-alikes.

Family — Program Scope & Nesting Disciplines (10 abstractions)

Nearest neighbors

Computed from structural-signature embeddings · 2026-10-08

Not to Be Confused With

  • Orphan process. Tell: Remains alive after its parent terminates.
  • Hung process. Tell: Still exists as executing or blocked code.
  • Stopped process. Tell: Is suspended but can resume.
  • Daemon. Tell: A long-lived background process, not a terminated child record.

References

  • Frozen Wikipedia discovery revision: https://en.wikipedia.org/wiki/Zombie_process (revision 1363503125).
  • Preserved source candidate: https://www.mankier.com/2/wait#Notes
  • Preserved source candidate: http://www-cdf.fnal.gov/offline/UNIX_Concepts/concepts.zombies.txt
  • Preserved source candidate: https://stackoverflow.com/questions/42627411/can-someone-please-explain-how-this-worksfork-sleep
  • Preserved source candidate: http://unixhelp.ed.ac.uk/CGI/man-cgi?ps
  • Preserved source candidate: https://web.archive.org/web/20130308114410/http://unixhelp.ed.ac.uk/CGI/man-cgi?ps
  • Preserved source candidate: https://yarchive.net/comp/zombie_process.html
  • Preserved source candidate: http://www.faqs.org/faqs/unix-faq/faq/part3/section-13.html

The frozen Wikipedia revision is discovery provenance. The retained source set was reviewed for identity, formal or operational relation, and scope. The encyclopedia's structural synthesis is bounded to those claims; a thin authority surface is recorded as a nonblocking source-strengthening repair rather than concealed.