When running lsof, you may see two processes in your process list: the original lsof process and a child process. The child process is used to isolate the parent from kernel functions that can block (e.g., readlink(), stat(), or reading from /dev devices).
Information is exchanged via pipes. If the parent detects the child has become blocked, it attempts to kill the child to prevent the parent from hanging.
To avoid these blocks, you can use specific lsof options, but use caution as this may be risky for system stability. Refer to the BLOCKS AND TIMEOUTS and AVOIDING KERNEL BLOCKS sections of the lsof man page for details.
COMMAND PID USER FD TYPE DEVICE ...
...
lsof 29450 abe 7w PIPE 0x48732408 ...
lsof 29450 abe 8r PIPE 0x48970808 ...
...
lsof 29451 abe 6r PIPE 0x48732408 ...
lsof 29451 abe 9w PIPE 0x48970808 ...