Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix Now×
Skip to content
World desk3 min

Why `kill -9` Cannot Be Trapped: Linux’s SIGKILL Path

SIGKILL has no user-space handler or ignore path. A process that remains visible after `kill -9` may instead be waiting uninterruptibly inside the Linux kernel.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

kill -9 PID sends Linux signal 9, commonly named SIGKILL. A process cannot catch, block, or ignore it, so there is no application handler that can intercept the signal and refuse to exit. If the process remains visible afterward, it may be stuck in an uninterruptible kernel wait—not trapping SIGKILL.

What does kill -9 actually do?

The command asks the kernel to send a signal to a process. On x86, ARM, and many other Linux architectures, signal number 9 is SIGKILL; signal numbers can differ on some architectures. For clearer, more portable command syntax, use the signal name: kill -KILL PID or kill -s KILL PID. The Linux signal(7) reference documents signal dispositions and numbering.

Sending the signal and seeing a process disappear from a listing are separate events. The kill(2) interface describes signal sending; process listings report process state through procfs. A successful signal request does not promise that the process will vanish instantly.

Why can’t a process catch SIGKILL?

Most signals have a disposition: the process can use the default action, ignore the signal, or install a handler that runs application code. SIGKILL is an exception. Linux fixes its action as termination, leaving the process no option to install a handler, ignore it, or block it. The Linux signal(7) documentation identifies SIGKILL and SIGSTOP as signals that cannot be caught, blocked, or ignored.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The kernel still handles signal generation, pending status, and delivery. For ordinary catchable signals, Linux checks for pending unblocked signals as execution transitions from kernel mode to user mode. SIGKILL has no user-space handler path to return from: its action is fixed by the kernel rather than chosen by the process.

Masking SIGKILL does not defer it

A signal mask normally lets a process temporarily block selected signals. SIGKILL cannot be blocked; Linux silently ignores attempts to add it to a signal mask. That rule is documented in sigprocmask(2).

Why might a process still appear after the command?

A process that remains listed has not necessarily caught SIGKILL. One possible explanation is that its task is in an uninterruptible wait inside the kernel. Linux reports this state as D in process status information. A task waiting on a kernel operation or resource may not complete the work needed to exit and disappear until that wait resolves or the kernel path can make progress. The Linux kernel documentation for /proc defines the D state as sleeping in an uninterruptible wait.

This is not a guarantee that every task in D behaves alike, nor does the state alone identify the cause or predict how long the wait will last. The delay concerns progress through a kernel wait, not a successful user-space attempt to trap the signal.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to investigate a process that stays visible

  1. Check the process state with ps or inspect /proc/PID/status, substituting the process ID for PID. Linux documents that ps obtains process information from procfs; the proc documentation explains the state fields and the meaning of D.

  2. If the task is reported in D, investigate the kernel operation, I/O, or resource on which it is waiting. The state is a clue, not a diagnosis; the underlying cause depends on the host and workload.

  3. Allow for the possibility that the task will remain visible until the wait resolves or the kernel path can make progress. The proc documentation does not establish a universal time-to-exit.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How SIGTERM differs from SIGKILL

Signal Handler or ignore available? Application cleanup opportunity Does the request guarantee immediate disappearance?
SIGTERM Yes. It is a catchable termination request. Potentially. An application can arrange a handler to perform orderly cleanup. No. Software can ignore or mishandle it, so it may not end the process.
SIGKILL No. It cannot be caught, ignored, or blocked. No user-space cleanup handler can run in response. No. A kernel wait can delay final disappearance.

The distinction is control: SIGTERM gives the application a chance to respond, while SIGKILL does not. Neither signal should be described as ensuring instant disappearance in every observed process state.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Outdated Drivers Are Slowing You DownFree scan - exact matches

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.