Linux strace command

Linux 命令大全Complete Collection of Linux Commands


What is strace

strace is a powerful diagnostic and debugging tool in Linux systems, used to trace system calls and received signals during program execution. System calls are the interfaces through which applications interact with the operating system kernel. With strace, we can gain a deep understanding of the underlying behavior of programs.

Analogy: We can think of strace as a "translator" that translates the "conversation" (system calls) between programs and the operating system into human language we can understand.


Why do you need strace

strace is especially useful in the following scenarios:

  • Debugging abnormal program behavior
  • Analyzing program performance bottlenecks
  • Understanding how programs interact with the operating system
  • Diagnosing permission-related issues
  • Troubleshooting file/network access issues

Basic Syntax

strace [选项] 命令 [命令参数]

Or attach to a running process:

strace -p PID

Common Options and Parameters

Option Description
-c Count system calls and time
-f Trace child processes
-e trace=系统调用 Trace only specific system calls
-o 文件 Write output to a file
-p PID Attach to a running process
-t Show timestamps
-T Show time spent in system calls
-s 大小 Set the maximum display length of strings (default 32)
-v Show more detailed information

Usage Examples

Example 1: Basic Tracing

Tracelsthe execution of the command:

strace ls

The output will displaylsall system calls during the execution of the command, such as opening directories, reading file information, etc.

Example 2: Counting System Calls

Countls -lthe system calls of:

strace -c ls -l

Sample output:

% time     seconds  usecs/call     calls    errors syscall
------ ----------- ----------- --------- --------- ----------------
 45.21    0.000123           5        25        12 openat
 32.35    0.000088           4        21           mmap
 12.50    0.000034           3        11           read
...

Example 3: Tracing Specific System Calls

Trace only file-related system calls:

strace -e trace=open,read,write ls

Example 4: Tracing Network Connections

Tracecurlnetwork-related system calls of:

strace -e trace=network curl http://example.com

Example 5: Attaching to a Running Process

First find the process ID:

ps aux | grep 进程名

Then attach and trace:

strace -p 进程ID

Interpreting the Output

A typical line of strace output is as follows:

openat(AT_FDCWD, "/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3

Meaning of each part:

  • openat: system call name
  • AT_FDCWD, "/etc/ld.so.cache", O_RDONLY|O_CLOEXEC: call arguments
  • = 3: return value (here it is a file descriptor)

Advanced Tips

1. Use grep to filter output

strace ls 2>&1 | grep open

2. Trace a process and all its child processes

strace -f 命令

3. Show time spent in system calls

strace -T 命令

4. Save output to a file

strace -o trace.log 命令

Troubleshooting Common Issues

1. File not found errors

Look in the output forENOENTerror:

open("/nonexistent/file", O_RDONLY) = -1 ENOENT (No such file or directory)

2. Permission issues

Look forEPERMorEACCESerror:

open("/root/file", O_RDONLY) = -1 EACCES (Permission denied)

3. Performance bottlenecks

Use-coption to count the system calls that take the longest time.


Notes

  1. strace significantly slows down program execution and is not suitable for long-term use in production environments.
  2. Some system calls may not be traceable due to security restrictions.
  3. The output can be very verbose; it is recommended to use-eoption or redirect to a file.
  4. A certain amount of system programming knowledge is required to fully understand the output.

With the powerful tool strace, you can gain an in-depth understanding of how Linux programs work and quickly locate various system-level problems.


Linux 命令大全Complete Collection of Linux Commands

Other Extensions