Strace Ltrace

mohitmishra786/low-level-dev-skills/skills/profilers/strace-ltrace

by mohitmishra786bdc58472fa9fNo license253 starsListed Oct 9, 2026Updated Oct 9, 2026Repository updated 3 months ago

strace and ltrace skill for system call and library call tracing. Use when a binary behaves incorrectly without crashing, diagnosing file-not-found errors, permission failures, network issues, or unexpected library calls by tracing syscalls and library function calls. Activates on queries about strace, ltrace, syscall tracing, library interception, ENOENT, EPERM, strace -e, or diagnosing binary behaviour without a debugger.

Instructions onlySoftware Development
AI-generated overview

Guides agents through strace and ltrace to trace syscalls and library calls when diagnosing misbehaving binaries.

What it does
This skill provides instructions for using strace to trace system calls and ltrace to trace user-space library calls. It covers basic and attached tracing, syscall category filters, common error codes such as ENOENT and EPERM, useful flags, and practical diagnosis workflows for missing files, permissions, network connections, library loading, and seccomp kills. It produces command examples and interpretation guidance rather than scripts.
When to use it
Use it when a binary behaves incorrectly without crashing, or when you need to find which files, network connections, or library functions a program uses. It also fits diagnosing file-not-found, permission, and dynamic library loading failures.
Requirements
Requires strace and ltrace to be installed on a Linux system, plus permission to trace processes (often root or ptrace capability). No scripts ship with the skill; it references a patterns document.

strace / ltrace

Purpose

Guide agents through tracing system calls with strace and library calls with ltrace — the most effective tools for diagnosing incorrect binary behaviour without a crash or debugger.

Triggers

  • "My program behaves incorrectly — how do I trace what it's doing?"
  • "How do I find what files a binary is opening?"
  • "strace shows ENOENT — how do I interpret it?"
  • "How do I trace network calls with strace?"
  • "What is ltrace and how does it differ from strace?"
  • "How do I trace a running process?"

Workflow

1. Basic strace usage

bash
# Trace all syscalls of a commandstrace ./myapp arg1 arg2
# Attach to running processstrace -p 12345
# Trace child processes too (-f = follow fork)strace -f ./myapp
# Save to file (raw output — not stdout)strace ./myapp 2> trace.txt
# Most useful: timestamps + summarystrace -t -f ./myapp 2>&1 | head -100

2. Filter by syscall category

bash
# Trace file operations onlystrace -e trace=file ./myapp
# Trace network syscallsstrace -e trace=network ./myapp
# Trace specific syscallsstrace -e trace=open,openat,read,write ./myapp
# Trace process managementstrace -e trace=process ./myapp
# Trace memory operationsstrace -e trace=memory ./myapp
# Trace signalsstrace -e trace=signal ./myapp
# Multiple categoriesstrace -e trace=file,network ./myapp
CategorySyscalls included
fileopen, openat, stat, access, unlink, rename, ...
networksocket, connect, bind, accept, send, recv, ...
processfork, exec, wait, clone, exit, ...
memorymmap, munmap, mprotect, brk, ...
signalkill, sigaction, sigprocmask, ...
ipcpipe, socket pair, shmget, ...
descclose, dup, poll, select, epoll, ...

3. Interpreting common errors

bash
# See return values and errorsstrace -e trace=file ./myapp 2>&1 | grep -E "ENOENT|EPERM|EACCES|ENOTSUP"
ErrorMeaningCommon cause
ENOENTNo such file or directoryConfig file missing, wrong path
EACCESPermission deniedFile permissions, SELinux
EPERMOperation not permittedMissing capability, suid needed
EADDRINUSEAddress already in usePort already bound
ETIMEDOUTConnection timed outNetwork unreachable, firewall
ECONNREFUSEDConnection refusedServer not listening
EAGAINResource temporarily unavailableNon-blocking I/O, try again
ENOMEMOut of memoryAllocation failed
EBADFBad file descriptorUsing closed/invalid fd
ENOEXECExec format errorWrong binary format for arch
bash
# Find what file is not foundstrace ./myapp 2>&1 | grep 'ENOENT'# Example output:# openat(AT_FDCWD, "/etc/myapp.conf", O_RDONLY) = -1 ENOENT (No such file or directory)# → Config file expected at /etc/myapp.conf

4. Useful strace flags

bash
# Show strings fully (default truncates at 32 chars)strace -s 256 ./myapp
# Timestampsstrace -t ./myapp     # wall clock timestrace -T ./myapp     # time spent in each syscallstrace -r ./myapp     # relative timestamps
# System call count summarystrace -c ./myapp# Shows count, time, errors per syscall — great for profiling
# Trace with PIDs in output (for -f)strace -f -p ./myapp# Output: [pid 12346] open("/etc/passwd", O_RDONLY) = 3
# Decode numerical argumentsstrace -e verbose=all ./myapp
# Print instruction pointer at each syscallstrace -i ./myapp

5. ltrace — library call tracing

bash
# Trace all library callsltrace ./myapp
# Trace specific library functionltrace -e malloc,free,fopen ./myapp
# Trace nested calls (lib → lib)ltrace -n 2 ./myapp   # indent nested calls
# Trace with syscalls tooltrace -S ./myapp
# Attach to running processltrace -p 12345
# Summary statisticsltrace -c ./myapp

Typical ltrace output:

text
malloc(1024) = 0x55a1b2c3d000fopen("/etc/myapp.conf", "r") = 0free(0x55a1b2c3d000) = <void>

strace vs ltrace:

straceltrace
TracesKernel syscallsUser-space library calls
OverheadLowerHigher (PLT hooking)
Showsopen(), read(), write()fopen(), malloc(), printf()
Use whenBinary interacts with OS/files/networkBinary calls library functions you can't see

6. Practical diagnosis workflows

bash
# Find missing config filestrace -e trace=openat,open ./myapp 2>&1 | grep ENOENT
# Find what network connections are madestrace -e trace=network -f ./myapp 2>&1 | grep connect
# Debug dynamic library loading failuresstrace -e trace=openat ./myapp 2>&1 | grep "\.so"
# Find permission issuesstrace -e trace=file ./myapp 2>&1 | grep -E "EACCES|EPERM"
# Debug slow startup (find where time is spent)strace -c ./myapp 2>&1# Look for high % time in unexpected syscalls
# Watch IPC/shared memorystrace -e trace=ipc,shm ./myapp
# Find what the binary exec'sstrace -e trace=execve -f ./myapp

7. seccomp filter debugging

If a program is killed by a seccomp policy, strace reveals which syscall triggered it:

bash
strace -e trace=all ./myapp 2>&1 | tail -5# Often shows the last syscall before SIGSYS

For strace output patterns and ltrace filtering examples, see references/strace-patterns.md [blocked].

Related skills

  • Use skills/debuggers/gdb when strace shows the failing location and you need to inspect internals
  • Use skills/binaries/elf-inspection to understand what libraries and symbols a binary uses
  • Use skills/binaries/dynamic-linking for diagnosing LD_* and library loading issues
  • Use skills/profilers/linux-perf for performance profiling (strace overhead is too high for perf)

Source and attribution

Source:mohitmishra786/low-level-dev-skillsinskills/profilers/strace-ltraceat commitbdc5847

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal