↓ Skip to main content
[snippet]

strace vs ltrace when a process hangs

strace = syscalls into the kernel. ltrace = library calls. Start with strace when the box is sick.

# App stuck after deploy — is it waiting on the kernel?
strace -p $(pgrep -n myapp) -f -e trace=network,file,desc

# Or attach from start and follow children:
strace -f -o /tmp/myapp.strace ./myapp

# Library-level (malloc, pthread, libc):
ltrace -p $(pgrep -n myapp) -e malloc+free+pthread_mutex_lock

Scenario: API latency spikes; CPU is idle. strace shows the worker blocked in poll/recvfrom on a DB socket — not a CPU bug. If strace is quiet but the process is busy, try ltrace for userspace lock contention.