strace / ltrace
Purpose
Guide agents through tracing system calls with strace and library calls with ltrace — the most effective tools for diagnosing incorrect binary behaviour without a crash or debugger.
Triggers
- "My program behaves incorrectly — how do I trace what it's doing?"
- "How do I find what files a binary is opening?"
- "strace shows ENOENT — how do I interpret it?"
- "How do I trace network calls with strace?"
- "What is ltrace and how does it differ from strace?"
- "How do I trace a running process?"
Workflow
1. Basic strace usage
2. Filter by syscall category
3. Interpreting common errors
4. Useful strace flags
5. ltrace — library call tracing
Typical ltrace output:
strace vs ltrace:
6. Practical diagnosis workflows
7. seccomp filter debugging
If a program is killed by a seccomp policy, strace reveals which syscall triggered it:
For strace output patterns and ltrace filtering examples, see references/strace-patterns.md [blocked].
Related skills
- Use
skills/debuggers/gdbwhen strace shows the failing location and you need to inspect internals - Use
skills/binaries/elf-inspectionto understand what libraries and symbols a binary uses - Use
skills/binaries/dynamic-linkingfor diagnosingLD_*and library loading issues - Use
skills/profilers/linux-perffor performance profiling (strace overhead is too high for perf)


