Strace Ltrace

mohitmishra786/low-level-dev-skills/skills/profilers/strace-ltrace

作者 mohitmishra786bdc58472fa9f无许可证253 个星标收录于 2026年10月9日更新于 2026年10月9日仓库3个月前更新

strace and ltrace skill for system call and library call tracing. Use when a binary behaves incorrectly without crashing, diagnosing file-not-found errors, permission failures, network issues, or unexpected library calls by tracing syscalls and library function calls. Activates on queries about strace, ltrace, syscall tracing, library interception, ENOENT, EPERM, strace -e, or diagnosing binary behaviour without a debugger.

AI 生成的概览

指导代理使用 strace 和 ltrace 跟踪系统调用与库调用,以诊断行为异常的程序。

功能
该技能提供使用 strace 跟踪系统调用、使用 ltrace 跟踪用户空间库调用的操作指引。内容涵盖基本跟踪与附加到进程、按系统调用类别过滤、ENOENT 和 EPERM 等常见错误码、常用参数,以及针对文件缺失、权限、网络连接、库加载和 seccomp 终止的实用诊断流程。产出为命令示例与结果解读说明,而非脚本。
适用场景
适用于程序未崩溃但行为异常,或需要查明程序访问了哪些文件、网络连接或库函数的情况。也适合诊断文件未找到、权限不足和动态库加载失败等问题。
运行要求
需要在 Linux 系统上安装 strace 和 ltrace,并具备跟踪进程的权限(通常为 root 或 ptrace 能力)。该技能不附带脚本,仅引用一份模式参考文档。

strace / ltrace

Purpose

Guide agents through tracing system calls with strace and library calls with ltrace — the most effective tools for diagnosing incorrect binary behaviour without a crash or debugger.

Triggers

  • "My program behaves incorrectly — how do I trace what it's doing?"
  • "How do I find what files a binary is opening?"
  • "strace shows ENOENT — how do I interpret it?"
  • "How do I trace network calls with strace?"
  • "What is ltrace and how does it differ from strace?"
  • "How do I trace a running process?"

Workflow

1. Basic strace usage

bash
# Trace all syscalls of a commandstrace ./myapp arg1 arg2
# Attach to running processstrace -p 12345
# Trace child processes too (-f = follow fork)strace -f ./myapp
# Save to file (raw output — not stdout)strace ./myapp 2> trace.txt
# Most useful: timestamps + summarystrace -t -f ./myapp 2>&1 | head -100

2. Filter by syscall category

bash
# Trace file operations onlystrace -e trace=file ./myapp
# Trace network syscallsstrace -e trace=network ./myapp
# Trace specific syscallsstrace -e trace=open,openat,read,write ./myapp
# Trace process managementstrace -e trace=process ./myapp
# Trace memory operationsstrace -e trace=memory ./myapp
# Trace signalsstrace -e trace=signal ./myapp
# Multiple categoriesstrace -e trace=file,network ./myapp
CategorySyscalls included
fileopen, openat, stat, access, unlink, rename, ...
networksocket, connect, bind, accept, send, recv, ...
processfork, exec, wait, clone, exit, ...
memorymmap, munmap, mprotect, brk, ...
signalkill, sigaction, sigprocmask, ...
ipcpipe, socket pair, shmget, ...
descclose, dup, poll, select, epoll, ...

3. Interpreting common errors

bash
# See return values and errorsstrace -e trace=file ./myapp 2>&1 | grep -E "ENOENT|EPERM|EACCES|ENOTSUP"
ErrorMeaningCommon cause
ENOENTNo such file or directoryConfig file missing, wrong path
EACCESPermission deniedFile permissions, SELinux
EPERMOperation not permittedMissing capability, suid needed
EADDRINUSEAddress already in usePort already bound
ETIMEDOUTConnection timed outNetwork unreachable, firewall
ECONNREFUSEDConnection refusedServer not listening
EAGAINResource temporarily unavailableNon-blocking I/O, try again
ENOMEMOut of memoryAllocation failed
EBADFBad file descriptorUsing closed/invalid fd
ENOEXECExec format errorWrong binary format for arch
bash
# Find what file is not foundstrace ./myapp 2>&1 | grep 'ENOENT'# Example output:# openat(AT_FDCWD, "/etc/myapp.conf", O_RDONLY) = -1 ENOENT (No such file or directory)# → Config file expected at /etc/myapp.conf

4. Useful strace flags

bash
# Show strings fully (default truncates at 32 chars)strace -s 256 ./myapp
# Timestampsstrace -t ./myapp     # wall clock timestrace -T ./myapp     # time spent in each syscallstrace -r ./myapp     # relative timestamps
# System call count summarystrace -c ./myapp# Shows count, time, errors per syscall — great for profiling
# Trace with PIDs in output (for -f)strace -f -p ./myapp# Output: [pid 12346] open("/etc/passwd", O_RDONLY) = 3
# Decode numerical argumentsstrace -e verbose=all ./myapp
# Print instruction pointer at each syscallstrace -i ./myapp

5. ltrace — library call tracing

bash
# Trace all library callsltrace ./myapp
# Trace specific library functionltrace -e malloc,free,fopen ./myapp
# Trace nested calls (lib → lib)ltrace -n 2 ./myapp   # indent nested calls
# Trace with syscalls tooltrace -S ./myapp
# Attach to running processltrace -p 12345
# Summary statisticsltrace -c ./myapp

Typical ltrace output:

text
malloc(1024) = 0x55a1b2c3d000fopen("/etc/myapp.conf", "r") = 0free(0x55a1b2c3d000) = <void>

strace vs ltrace:

straceltrace
TracesKernel syscallsUser-space library calls
OverheadLowerHigher (PLT hooking)
Showsopen(), read(), write()fopen(), malloc(), printf()
Use whenBinary interacts with OS/files/networkBinary calls library functions you can't see

6. Practical diagnosis workflows

bash
# Find missing config filestrace -e trace=openat,open ./myapp 2>&1 | grep ENOENT
# Find what network connections are madestrace -e trace=network -f ./myapp 2>&1 | grep connect
# Debug dynamic library loading failuresstrace -e trace=openat ./myapp 2>&1 | grep "\.so"
# Find permission issuesstrace -e trace=file ./myapp 2>&1 | grep -E "EACCES|EPERM"
# Debug slow startup (find where time is spent)strace -c ./myapp 2>&1# Look for high % time in unexpected syscalls
# Watch IPC/shared memorystrace -e trace=ipc,shm ./myapp
# Find what the binary exec'sstrace -e trace=execve -f ./myapp

7. seccomp filter debugging

If a program is killed by a seccomp policy, strace reveals which syscall triggered it:

bash
strace -e trace=all ./myapp 2>&1 | tail -5# Often shows the last syscall before SIGSYS

For strace output patterns and ltrace filtering examples, see references/strace-patterns.md [blocked].

Related skills

  • Use skills/debuggers/gdb when strace shows the failing location and you need to inspect internals
  • Use skills/binaries/elf-inspection to understand what libraries and symbols a binary uses
  • Use skills/binaries/dynamic-linking for diagnosing LD_* and library loading issues
  • Use skills/profilers/linux-perf for performance profiling (strace overhead is too high for perf)

来源与署名

来源:mohitmishra786/low-level-dev-skills位于skills/profilers/strace-ltrace提交bdc5847

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架