Linux strace command
Complete Collection of Linux Commands
What is strace
strace is a powerful diagnostic and debugging tool in Linux systems, used to trace system calls and received signals during program execution. System calls are the interfaces through which applications interact with the operating system kernel. With strace, we can gain a deep understanding of the underlying behavior of programs.
Analogy: We can think of strace as a "translator" that translates the "conversation" (system calls) between programs and the operating system into human language we can understand.
Why do you need strace
strace is especially useful in the following scenarios:
- Debugging abnormal program behavior
- Analyzing program performance bottlenecks
- Understanding how programs interact with the operating system
- Diagnosing permission-related issues
- Troubleshooting file/network access issues
Basic Syntax
strace [选项] 命令 [命令参数]
Or attach to a running process:
strace -p PID
Common Options and Parameters
| Option | Description |
|---|---|
-c |
Count system calls and time |
-f |
Trace child processes |
-e trace=系统调用 |
Trace only specific system calls |
-o 文件 |
Write output to a file |
-p PID |
Attach to a running process |
-t |
Show timestamps |
-T |
Show time spent in system calls |
-s 大小 |
Set the maximum display length of strings (default 32) |
-v |
Show more detailed information |
Usage Examples
Example 1: Basic Tracing
Tracelsthe execution of the command:
strace ls
The output will displaylsall system calls during the execution of the command, such as opening directories, reading file information, etc.
Example 2: Counting System Calls
Countls -lthe system calls of:
strace -c ls -l
Sample output:
% time seconds usecs/call calls errors syscall ------ ----------- ----------- --------- --------- ---------------- 45.21 0.000123 5 25 12 openat 32.35 0.000088 4 21 mmap 12.50 0.000034 3 11 read ...
Example 3: Tracing Specific System Calls
Trace only file-related system calls:
strace -e trace=open,read,write ls
Example 4: Tracing Network Connections
Tracecurlnetwork-related system calls of:
strace -e trace=network curl http://example.com
Example 5: Attaching to a Running Process
First find the process ID:
ps aux | grep 进程名
Then attach and trace:
strace -p 进程ID
Interpreting the Output
A typical line of strace output is as follows:
openat(AT_FDCWD, "/etc/ld.so.cache", O_RDONLY|O_CLOEXEC) = 3
Meaning of each part:
openat: system call nameAT_FDCWD, "/etc/ld.so.cache", O_RDONLY|O_CLOEXEC: call arguments= 3: return value (here it is a file descriptor)
Advanced Tips
1. Use grep to filter output
strace ls 2>&1 | grep open
2. Trace a process and all its child processes
strace -f 命令
3. Show time spent in system calls
strace -T 命令
4. Save output to a file
strace -o trace.log 命令
Troubleshooting Common Issues
1. File not found errors
Look in the output forENOENTerror:
open("/nonexistent/file", O_RDONLY) = -1 ENOENT (No such file or directory)
2. Permission issues
Look forEPERMorEACCESerror:
open("/root/file", O_RDONLY) = -1 EACCES (Permission denied)
3. Performance bottlenecks
Use-coption to count the system calls that take the longest time.
Notes
- strace significantly slows down program execution and is not suitable for long-term use in production environments.
- Some system calls may not be traceable due to security restrictions.
- The output can be very verbose; it is recommended to use
-eoption or redirect to a file. - A certain amount of system programming knowledge is required to fully understand the output.
With the powerful tool strace, you can gain an in-depth understanding of how Linux programs work and quickly locate various system-level problems.
Other Extensions