Strace Ltrace

mohitmishra786/low-level-dev-skills/skills/profilers/strace-ltrace

作者 mohitmishra786bdc58472fa9f無授權條款253 個星標收錄於 2026年10月9日更新於 2026年10月9日儲存庫3 個月前更新

strace and ltrace skill for system call and library call tracing. Use when a binary behaves incorrectly without crashing, diagnosing file-not-found errors, permission failures, network issues, or unexpected library calls by tracing syscalls and library function calls. Activates on queries about strace, ltrace, syscall tracing, library interception, ENOENT, EPERM, strace -e, or diagnosing binary behaviour without a debugger.

AI 產生的概覽

引導代理使用 strace 與 ltrace 追蹤系統呼叫與函式庫呼叫,以診斷行為異常的程式。

功能
此技能提供使用 strace 追蹤系統呼叫、使用 ltrace 追蹤使用者空間函式庫呼叫的操作指引。內容涵蓋基本追蹤與附加至行程、依系統呼叫類別篩選、ENOENT 與 EPERM 等常見錯誤碼、常用參數,以及針對檔案缺失、權限、網路連線、函式庫載入與 seccomp 終止的實用診斷流程。產出為指令範例與結果解讀說明,而非指令碼。
適用情境
適用於程式未當掉但行為異常,或需要查明程式存取了哪些檔案、網路連線或函式庫函式的情況。也適合診斷檔案找不到、權限不足與動態函式庫載入失敗等問題。
執行需求
需要在 Linux 系統上安裝 strace 與 ltrace,並具備追蹤行程的權限(通常為 root 或 ptrace 能力)。此技能不附帶指令碼,僅引用一份模式參考文件。

strace / ltrace

Purpose

Guide agents through tracing system calls with strace and library calls with ltrace — the most effective tools for diagnosing incorrect binary behaviour without a crash or debugger.

Triggers

  • "My program behaves incorrectly — how do I trace what it's doing?"
  • "How do I find what files a binary is opening?"
  • "strace shows ENOENT — how do I interpret it?"
  • "How do I trace network calls with strace?"
  • "What is ltrace and how does it differ from strace?"
  • "How do I trace a running process?"

Workflow

1. Basic strace usage

bash
# Trace all syscalls of a commandstrace ./myapp arg1 arg2
# Attach to running processstrace -p 12345
# Trace child processes too (-f = follow fork)strace -f ./myapp
# Save to file (raw output — not stdout)strace ./myapp 2> trace.txt
# Most useful: timestamps + summarystrace -t -f ./myapp 2>&1 | head -100

2. Filter by syscall category

bash
# Trace file operations onlystrace -e trace=file ./myapp
# Trace network syscallsstrace -e trace=network ./myapp
# Trace specific syscallsstrace -e trace=open,openat,read,write ./myapp
# Trace process managementstrace -e trace=process ./myapp
# Trace memory operationsstrace -e trace=memory ./myapp
# Trace signalsstrace -e trace=signal ./myapp
# Multiple categoriesstrace -e trace=file,network ./myapp
CategorySyscalls included
fileopen, openat, stat, access, unlink, rename, ...
networksocket, connect, bind, accept, send, recv, ...
processfork, exec, wait, clone, exit, ...
memorymmap, munmap, mprotect, brk, ...
signalkill, sigaction, sigprocmask, ...
ipcpipe, socket pair, shmget, ...
descclose, dup, poll, select, epoll, ...

3. Interpreting common errors

bash
# See return values and errorsstrace -e trace=file ./myapp 2>&1 | grep -E "ENOENT|EPERM|EACCES|ENOTSUP"
ErrorMeaningCommon cause
ENOENTNo such file or directoryConfig file missing, wrong path
EACCESPermission deniedFile permissions, SELinux
EPERMOperation not permittedMissing capability, suid needed
EADDRINUSEAddress already in usePort already bound
ETIMEDOUTConnection timed outNetwork unreachable, firewall
ECONNREFUSEDConnection refusedServer not listening
EAGAINResource temporarily unavailableNon-blocking I/O, try again
ENOMEMOut of memoryAllocation failed
EBADFBad file descriptorUsing closed/invalid fd
ENOEXECExec format errorWrong binary format for arch
bash
# Find what file is not foundstrace ./myapp 2>&1 | grep 'ENOENT'# Example output:# openat(AT_FDCWD, "/etc/myapp.conf", O_RDONLY) = -1 ENOENT (No such file or directory)# → Config file expected at /etc/myapp.conf

4. Useful strace flags

bash
# Show strings fully (default truncates at 32 chars)strace -s 256 ./myapp
# Timestampsstrace -t ./myapp     # wall clock timestrace -T ./myapp     # time spent in each syscallstrace -r ./myapp     # relative timestamps
# System call count summarystrace -c ./myapp# Shows count, time, errors per syscall — great for profiling
# Trace with PIDs in output (for -f)strace -f -p ./myapp# Output: [pid 12346] open("/etc/passwd", O_RDONLY) = 3
# Decode numerical argumentsstrace -e verbose=all ./myapp
# Print instruction pointer at each syscallstrace -i ./myapp

5. ltrace — library call tracing

bash
# Trace all library callsltrace ./myapp
# Trace specific library functionltrace -e malloc,free,fopen ./myapp
# Trace nested calls (lib → lib)ltrace -n 2 ./myapp   # indent nested calls
# Trace with syscalls tooltrace -S ./myapp
# Attach to running processltrace -p 12345
# Summary statisticsltrace -c ./myapp

Typical ltrace output:

text
malloc(1024) = 0x55a1b2c3d000fopen("/etc/myapp.conf", "r") = 0free(0x55a1b2c3d000) = <void>

strace vs ltrace:

straceltrace
TracesKernel syscallsUser-space library calls
OverheadLowerHigher (PLT hooking)
Showsopen(), read(), write()fopen(), malloc(), printf()
Use whenBinary interacts with OS/files/networkBinary calls library functions you can't see

6. Practical diagnosis workflows

bash
# Find missing config filestrace -e trace=openat,open ./myapp 2>&1 | grep ENOENT
# Find what network connections are madestrace -e trace=network -f ./myapp 2>&1 | grep connect
# Debug dynamic library loading failuresstrace -e trace=openat ./myapp 2>&1 | grep "\.so"
# Find permission issuesstrace -e trace=file ./myapp 2>&1 | grep -E "EACCES|EPERM"
# Debug slow startup (find where time is spent)strace -c ./myapp 2>&1# Look for high % time in unexpected syscalls
# Watch IPC/shared memorystrace -e trace=ipc,shm ./myapp
# Find what the binary exec'sstrace -e trace=execve -f ./myapp

7. seccomp filter debugging

If a program is killed by a seccomp policy, strace reveals which syscall triggered it:

bash
strace -e trace=all ./myapp 2>&1 | tail -5# Often shows the last syscall before SIGSYS

For strace output patterns and ltrace filtering examples, see references/strace-patterns.md [blocked].

Related skills

  • Use skills/debuggers/gdb when strace shows the failing location and you need to inspect internals
  • Use skills/binaries/elf-inspection to understand what libraries and symbols a binary uses
  • Use skills/binaries/dynamic-linking for diagnosing LD_* and library loading issues
  • Use skills/profilers/linux-perf for performance profiling (strace overhead is too high for perf)

來源與署名

來源:mohitmishra786/low-level-dev-skills位於skills/profilers/strace-ltrace提交bdc5847

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架