strace / ltrace
Purpose
Guide agents through tracing system calls with strace and library calls with ltrace — the most effective tools for diagnosing incorrect binary behaviour without a crash or debugger.
Triggers
- "My program behaves incorrectly — how do I trace what it's doing?"
- "How do I find what files a binary is opening?"
- "strace shows ENOENT — how do I interpret it?"
- "How do I trace network calls with strace?"
- "What is ltrace and how does it differ from strace?"
- "How do I trace a running process?"
Workflow
1. Basic strace usage
# Trace all syscalls of a command
strace ./myapp arg1 arg2
# Attach to running process
strace -p 12345
# Trace child processes too (-f = follow fork)
strace -f ./myapp
# Save to file (raw output — not stdout)
strace ./myapp 2> trace.txt
# Most useful: timestamps + summary
strace -t -f ./myapp 2>&1 | head -100
2. Filter by syscall category
# Trace file operations only
strace -e trace=file ./myapp
# Trace network syscalls
strace -e trace=network ./myapp
# Trace specific syscalls
strace -e trace=open,openat,read,write ./myapp
# Trace process management
strace -e trace=process ./myapp
# Trace memory operations
strace -e trace=memory ./myapp
# Trace signals
strace -e trace=signal ./myapp
# Multiple categories
strace -e trace=file,network ./myapp
| Category |
Syscalls included |
file |
open, openat, stat, access, unlink, rename, ... |
network |
socket, connect, bind, accept, send, recv, ... |
process |
fork, exec, wait, clone, exit, ... |
memory |
mmap, munmap, mprotect, brk, ... |
signal |
kill, sigaction, sigprocmask, ... |
ipc |
pipe, socket pair, shmget, ... |
desc |
close, dup, poll, select, epoll, ... |
3. Interpreting common errors
# See return values and errors
strace -e trace=file ./myapp 2>&1 | grep -E "ENOENT|EPERM|EACCES|ENOTSUP"
| Error |
Meaning |
Common cause |
ENOENT |
No such file or directory |
Config file missing, wrong path |
EACCES |
Permission denied |
File permissions, SELinux |
EPERM |
Operation not permitted |
Missing capability, suid needed |
EADDRINUSE |
Address already in use |
Port already bound |
ETIMEDOUT |
Connection timed out |
Network unreachable, firewall |
ECONNREFUSED |
Connection refused |
Server not listening |
EAGAIN |
Resource temporarily unavailable |
Non-blocking I/O, try again |
ENOMEM |
Out of memory |
Allocation failed |
EBADF |
Bad file descriptor |
Using closed/invalid fd |
ENOEXEC |
Exec format error |
Wrong binary format for arch |
# Find what file is not found
strace ./myapp 2>&1 | grep 'ENOENT'
# Example output:
# openat(AT_FDCWD, "/etc/myapp.conf", O_RDONLY) = -1 ENOENT (No such file or directory)
# → Config file expected at /etc/myapp.conf
4. Useful strace flags
# Show strings fully (default truncates at 32 chars)
strace -s 256 ./myapp
# Timestamps
strace -t ./myapp # wall clock time
strace -T ./myapp # time spent in each syscall
strace -r ./myapp # relative timestamps
# System call count summary
strace -c ./myapp
# Shows count, time, errors per syscall — great for profiling
# Trace with PIDs in output (for -f)
strace -f -p ./myapp
# Output: [pid 12346] open("/etc/passwd", O_RDONLY) = 3
# Decode numerical arguments
strace -e verbose=all ./myapp
# Print instruction pointer at each syscall
strace -i ./myapp
5. ltrace — library call tracing
# Trace all library calls
ltrace ./myapp
# Trace specific library function
ltrace -e malloc,free,fopen ./myapp
# Trace nested calls (lib → lib)
ltrace -n 2 ./myapp # indent nested calls
# Trace with syscalls too
ltrace -S ./myapp
# Attach to running process
ltrace -p 12345
# Summary statistics
ltrace -c ./myapp
Typical ltrace output:
malloc(1024) = 0x55a1b2c3d000
fopen("/etc/myapp.conf", "r") = 0
free(0x55a1b2c3d000) = <void>
strace vs ltrace:
|
strace |
ltrace |
| Traces |
Kernel syscalls |
User-space library calls |
| Overhead |
Lower |
Higher (PLT hooking) |
| Shows |
open(), read(), write() |
fopen(), malloc(), printf() |
| Use when |
Binary interacts with OS/files/network |
Binary calls library functions you can't see |
6. Practical diagnosis workflows
# Find missing config file
strace -e trace=openat,open ./myapp 2>&1 | grep ENOENT
# Find what network connections are made
strace -e trace=network -f ./myapp 2>&1 | grep connect
# Debug dynamic library loading failures
strace -e trace=openat ./myapp 2>&1 | grep "\.so"
# Find permission issues
strace -e trace=file ./myapp 2>&1 | grep -E "EACCES|EPERM"
# Debug slow startup (find where time is spent)
strace -c ./myapp 2>&1
# Look for high % time in unexpected syscalls
# Watch IPC/shared memory
strace -e trace=ipc,shm ./myapp
# Find what the binary exec's
strace -e trace=execve -f ./myapp
7. seccomp filter debugging
If a program is killed by a seccomp policy, strace reveals which syscall triggered it:
strace -e trace=all ./myapp 2>&1 | tail -5
# Often shows the last syscall before SIGSYS
For strace output patterns and ltrace filtering examples, see references/strace-patterns.md.
Related skills
- Use
skills/debuggers/gdb when strace shows the failing location and you need to inspect internals
- Use
skills/binaries/elf-inspection to understand what libraries and symbols a binary uses
- Use
skills/binaries/dynamic-linking for diagnosing LD_* and library loading issues
- Use
skills/profilers/linux-perf for performance profiling (strace overhead is too high for perf)
1---2name: strace-ltrace3description: strace and ltrace skill for system call and library call tracing. Use when a binary behaves incorrectly without crashing, diagnosing file-not-found errors, permission failures, network issues, or unexpected library calls by tracing syscalls and library function calls. Activates on queries about strace, ltrace, syscall tracing, library interception, ENOENT, EPERM, strace -e, or diagnosing binary behaviour without a debugger.4---5
6# strace / ltrace
7
8## Purpose
9
10Guide agents through tracing system calls with `strace` and library calls with `ltrace` — the most effective tools for diagnosing incorrect binary behaviour without a crash or debugger.
11
12## Triggers
13
14- "My program behaves incorrectly — how do I trace what it's doing?"
15- "How do I find what files a binary is opening?"
16- "strace shows ENOENT — how do I interpret it?"
17- "How do I trace network calls with strace?"
18- "What is ltrace and how does it differ from strace?"
19- "How do I trace a running process?"
20
21## Workflow
22
23### 1. Basic strace usage
24
25```bash
26# Trace all syscalls of a command
27strace ./myapp arg1 arg2
28
29# Attach to running process
30strace -p 12345
31
32# Trace child processes too (-f = follow fork)
33strace -f ./myapp
34
35# Save to file (raw output — not stdout)
36strace ./myapp 2> trace.txt
37
38# Most useful: timestamps + summary
39strace -t -f ./myapp 2>&1 | head -100
40```
41
42### 2. Filter by syscall category
43
44```bash
45# Trace file operations only
46strace -e trace=file ./myapp
47
48# Trace network syscalls
49strace -e trace=network ./myapp
50
51# Trace specific syscalls
52strace -e trace=open,openat,read,write ./myapp
53
54# Trace process management
55strace -e trace=process ./myapp
56
57# Trace memory operations
58strace -e trace=memory ./myapp
59
60# Trace signals
61strace -e trace=signal ./myapp
62
63# Multiple categories
64strace -e trace=file,network ./myapp
65```
66
67| Category | Syscalls included |
68|----------|------------------|
69| `file` | open, openat, stat, access, unlink, rename, ... |
70| `network` | socket, connect, bind, accept, send, recv, ... |
71| `process` | fork, exec, wait, clone, exit, ... |
72| `memory` | mmap, munmap, mprotect, brk, ... |
73| `signal` | kill, sigaction, sigprocmask, ... |
74| `ipc` | pipe, socket pair, shmget, ... |
75| `desc` | close, dup, poll, select, epoll, ... |
76
77### 3. Interpreting common errors
78
79```bash
80# See return values and errors
81strace -e trace=file ./myapp 2>&1 | grep -E "ENOENT|EPERM|EACCES|ENOTSUP"
82```
83
84| Error | Meaning | Common cause |
85|-------|---------|-------------|
86| `ENOENT` | No such file or directory | Config file missing, wrong path |
87| `EACCES` | Permission denied | File permissions, SELinux |
88| `EPERM` | Operation not permitted | Missing capability, suid needed |
89| `EADDRINUSE` | Address already in use | Port already bound |
90| `ETIMEDOUT` | Connection timed out | Network unreachable, firewall |
91| `ECONNREFUSED` | Connection refused | Server not listening |
92| `EAGAIN` | Resource temporarily unavailable | Non-blocking I/O, try again |
93| `ENOMEM` | Out of memory | Allocation failed |
94| `EBADF` | Bad file descriptor | Using closed/invalid fd |
95| `ENOEXEC` | Exec format error | Wrong binary format for arch |
96
97```bash
98# Find what file is not found
99strace ./myapp 2>&1 | grep 'ENOENT'
100# Example output:
101# openat(AT_FDCWD, "/etc/myapp.conf", O_RDONLY) = -1 ENOENT (No such file or directory)
102# → Config file expected at /etc/myapp.conf
103```
104
105### 4. Useful strace flags
106
107```bash
108# Show strings fully (default truncates at 32 chars)
109strace -s 256 ./myapp
110
111# Timestamps
112strace -t ./myapp # wall clock time
113strace -T ./myapp # time spent in each syscall
114strace -r ./myapp # relative timestamps
115
116# System call count summary
117strace -c ./myapp
118# Shows count, time, errors per syscall — great for profiling
119
120# Trace with PIDs in output (for -f)
121strace -f -p ./myapp
122# Output: [pid 12346] open("/etc/passwd", O_RDONLY) = 3
123
124# Decode numerical arguments
125strace -e verbose=all ./myapp
126
127# Print instruction pointer at each syscall
128strace -i ./myapp
129```
130
131### 5. ltrace — library call tracing
132
133```bash
134# Trace all library calls
135ltrace ./myapp
136
137# Trace specific library function
138ltrace -e malloc,free,fopen ./myapp
139
140# Trace nested calls (lib → lib)
141ltrace -n 2 ./myapp # indent nested calls
142
143# Trace with syscalls too
144ltrace -S ./myapp
145
146# Attach to running process
147ltrace -p 12345
148
149# Summary statistics
150ltrace -c ./myapp
151```
152
153Typical ltrace output:
154
155```text
156malloc(1024) = 0x55a1b2c3d000
157fopen("/etc/myapp.conf", "r") = 0
158free(0x55a1b2c3d000) = <void>
159```
160
161strace vs ltrace:
162
163| | strace | ltrace |
164|--|--------|--------|
165| Traces | Kernel syscalls | User-space library calls |
166| Overhead | Lower | Higher (PLT hooking) |
167| Shows | `open()`, `read()`, `write()` | `fopen()`, `malloc()`, `printf()` |
168| Use when | Binary interacts with OS/files/network | Binary calls library functions you can't see |
169
170### 6. Practical diagnosis workflows
171
172```bash
173# Find missing config file
174strace -e trace=openat,open ./myapp 2>&1 | grep ENOENT
175
176# Find what network connections are made
177strace -e trace=network -f ./myapp 2>&1 | grep connect
178
179# Debug dynamic library loading failures
180strace -e trace=openat ./myapp 2>&1 | grep "\.so"
181
182# Find permission issues
183strace -e trace=file ./myapp 2>&1 | grep -E "EACCES|EPERM"
184
185# Debug slow startup (find where time is spent)
186strace -c ./myapp 2>&1
187# Look for high % time in unexpected syscalls
188
189# Watch IPC/shared memory
190strace -e trace=ipc,shm ./myapp
191
192# Find what the binary exec's
193strace -e trace=execve -f ./myapp
194```
195
196### 7. seccomp filter debugging
197
198If a program is killed by a seccomp policy, strace reveals which syscall triggered it:
199
200```bash
201strace -e trace=all ./myapp 2>&1 | tail -5
202# Often shows the last syscall before SIGSYS
203```
204
205For strace output patterns and ltrace filtering examples, see [references/strace-patterns.md](references/strace-patterns.md).
206
207## Related skills
208
209- Use `skills/debuggers/gdb` when strace shows the failing location and you need to inspect internals
210- Use `skills/binaries/elf-inspection` to understand what libraries and symbols a binary uses
211- Use `skills/binaries/dynamic-linking` for diagnosing `LD_*` and library loading issues
212- Use `skills/profilers/linux-perf` for performance profiling (strace overhead is too high for perf)