---
tags:
- linux
- l1
- flashcard-deck
- strace
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [strace](../../../../library/portal/topics.md) | **Domain:** Linux
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
strace/a1f2b3c4d5e6	strace	easy	strace,syscalls,basics	What does strace show?	System calls made by a process, their arguments, and return values. Every interaction between a program and the kernel (file opens, network connects, memory allocation) goes through syscalls — strace intercepts and logs them. Even a simple ls makes dozens of syscalls. Start with strace -e trace=file ls to see just the file-related ones.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/b2a3c4d5e6f7	strace	easy	strace,language-agnostic,kernel	Why can strace work without source code or knowledge of the programming language?	Because it observes the kernel system call interface, which all programs must use regardless of language. Whether the code is Python, Go, or a static C binary, it must ask the kernel to open files, send network packets, and allocate memory. strace hooks at this universal boundary, making it language-agnostic.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/c3b4d5e6f7a8	strace	easy	strace,flags,children	What does the -f flag do in strace?	Follows child processes created by fork/clone, tracing them along with the parent. Without -f, you only see the parent's syscalls and miss what child processes do. Essential for debugging multi-process programs like web servers (Apache/Nginx), shell pipelines, or anything that spawns subprocesses.\n\nRemember: "strace -p PID = attach to running process." Ctrl+C to detach. Add -f to follow child processes.\n\nGotcha: strace adds significant overhead — don't use on production for extended periods.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/d4c5e6f7a8b9	strace	medium	strace,flags,filtering	What does -e trace=file do in strace?	Restricts output to only file-related syscalls (open, stat, access, unlink, etc.), filtering out everything else. This dramatically reduces noise when debugging "file not found" or permission problems. Other useful filters: trace=network for socket issues, trace=process for fork/exec debugging.\n\nRemember: "-e trace=network shows socket syscalls (connect, accept, send, recv). -e trace=file shows file operations (open, read, write, stat)."	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/e5d6f7a8b9c0	strace	easy	strace,attach,pid	How do you attach strace to an already-running process?	Use strace -p <pid>. This attaches to the process without restarting it — ideal for debugging a hung service in production. You will need root or matching UID. Combine with -f to also trace child processes. Detach cleanly with Ctrl+C; the process continues running normally after you detach.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/f6e7a8b9c0d1	strace	medium	strace,errors,debugging	What are two very useful error codes to grep for in strace output?	ENOENT (file not found) and EACCES (permission denied). Run strace -o trace.log <cmd> then grep -E 'ENOENT|EACCES' trace.log. ENOENT reveals missing config files, libraries, or certificates. EACCES exposes permission problems on files, directories, or sockets. These two errors explain the majority of "it works on my machine" issues.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/a7f8b9c0d1e2	strace	medium	strace,network,debugging	What does "connect(...) = -1 ECONNREFUSED" in strace output indicate?	The process tried to establish a network connection but the target host/port refused it — typically meaning nothing is listening on that port. Check: is the target service running? Is the port correct? Is a firewall blocking? This single strace line often pinpoints connectivity issues faster than reading application logs.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/b8a9c0d1e2f3	strace	medium	strace,stalls,debugging	How can you identify what a stalled process is waiting on using strace?	Attach with strace -p <pid> and look for repeated calls to futex, poll, epoll_wait, read, or recvfrom. These indicate the process is blocked waiting for a lock, I/O, or network data. Add -T to see time spent in each call — a 30-second read() on a socket tells you the remote end is slow. This is often faster than log analysis.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/c9b0d1e2f3a4	strace	medium	strace,timing,flags	How do you add timestamps and per-call duration to strace output?	Use -tt for microsecond wall-clock timestamps and -T for time spent in each syscall (shown at line end). \nExample: strace -tt -T -o trace.log <command>. The -T output reveals which syscalls are slow — a connect() taking 5 seconds points to DNS or network issues. Combine with grep to find the slowest calls.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/d0c1e2f3a4b5	strace	easy	strace,output,logging	How do you save strace output to a file?	Use -o flag: strace -o trace.log <command>. This separates strace output from the program's own stderr, making both easier to read. For multi-process traces, add -ff to create one file per PID: strace -ff -o trace <command> produces trace.1234, trace.1235, etc.\n\nRemember: "strace -c = syscall summary." It counts calls, errors, and time per syscall. Great for finding which syscall dominates.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/e1d2f3a4b5c6	strace	medium	strace,filter,categories	What are the main trace filter categories in strace?	trace=file (open, stat, chmod — file operations), trace=network (socket, connect, sendto — network calls), trace=process (fork, exec, exit — process lifecycle), trace=signal (signal delivery), trace=memory (mmap, brk — memory allocation). These let you focus on specific problem domains and cut through noise.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/f2e3a4b5c6d7	strace	hard	strace,limitations,overhead	What are the main limitations of strace?	Output can be huge and noisy for high-volume workloads. It only shows kernel boundary crossings — not language-level variables, function calls, or application logic. Tracing adds significant overhead (10-100x slowdown) via ptrace, which can perturb timing-sensitive programs and mask race conditions. For lower overhead, consider eBPF-based tools like bpftrace.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/a3f4b5c6d7e8	strace	medium	strace,execve,process	What does the execve syscall tell you in strace output?	It shows which program was executed, with what arguments and environment variables. \nExample: execve("/usr/bin/python3", ["python3", "app.py"], [...]) reveals the exact binary and arguments. This is invaluable for debugging shell scripts, cron jobs, or systemd services that launch child programs with unexpected arguments or wrong paths.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes
strace/b4a5c6d7e8f9	strace	hard	strace,workflow,debugging	What is a practical strace debugging workflow?	1. Start narrow — filter to file or network calls (-e trace=file). \n2. Log to a file with -o to separate from program output. \n3. Grep for ENOENT, EACCES, ECONNREFUSED — the most common culprits. \n4. Correlate with timestamps using -tt -T to find slow calls. \n5. Widen the filter only if the narrow trace was inconclusive. Avoid unfiltered strace on busy processes — the output is overwhelming.	zines/spying.on.your.programs.with.strace.zine.v3.cleaned.notes

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [strace](../../../../library/topics/strace/index.md) (Topic Pack, L1) — strace

<!-- wiki:related:end -->
