Plan for next LUG meeting:

Go over:

  Intercept syscalls, demangles symbols, and shows return code.
  Advantages: Source code not needed to debug/no debugging 
              symbols need to be present. Very good bug 
              tracking tool.

  Can profile syscalls, find time spent in each call.

  Can trace by filtering: -e trace=callname, or 
  Show a simple program.
  No homepage.
  Author: Juan Cespedes <>
  Similar to strace allows dynamic library calls to be traced as well.
  ltrace -S to disp syscalls, kernels syscalls, not lib ones.
  strace more readable, as it symbolically displays things,
   but -C option allows similar things.

  Debugger, allows tracing of processes.
  If debugging symbols present, allows user to view source
  as it runs, alter variables, change execution, examine
  variables, and dump assembler. Set breakpoints&watchpoints.
  One of the most powerful debugging tools if source is available.
  Lacks memory search capability :(


  Part of binutils.
  objdump -d, useful to disassemble.


  Part of binutils.
  List symbols from object files, such as libraries.
  Can list functions, code snippets, etc as well.


  Allows view in: text,binary,hex,dissasm modes.
  Allows dissassembly mode, virtual/file addresses.
  ctrl-f1 fr instr sets


  Similar to biew, allows viewing in text, binary, hex, oct.
  Useful as a quick way to hex edit things.
  Character table, similar to dos/win.
  Hex/dec/octal convertor.
  No disasm :(

  Front end to gdb, very cool.
  Graphical display of data structures.
  Ability to graphically see execution of program.

Things in procfs, /proc/pid
  <man proc>
  cmdline: command line name used to call prog
  cwd: current working dir
  environ: current environment variables
  exe: symlink to binary executable
  fd: open file descriptors, and links to them
  maps: descriptions memory mapped regions, and perms.
  mem: memory used by process, not mmap()-able yet
  root: current root dir of proc, chroot() to change
  stat: info about process, reported by ps
  status: current status

  #include <sys/ptrace.h>
  Set of tools to trace processes.
  Used by debuggers and tracers, mostly.