whatis system-call
System Call (Syscall)
Also known as: syscall
The interface programs use to ask the kernel to do privileged work, such as opening files, allocating memory, or creating processes.
What Is a System Call in Linux?
User programs cannot touch hardware directly. Instead they call functions like open, read, write, mmap, and clone, which switch into kernel mode, do the work, and return.
strace shows every system call a program makes, which quickly reveals missing files, permission errors, or where a program is hanging.
Example
strace -e trace=openat ls /tmp Learn more about System Call (Syscall)
- strace and ltrace Explained When a program fails with no useful error message, strace and ltrace show exactly what system calls and library calls it is making, often revealing the real problem in seconds. This guide covers reading their output and common debugging patterns.
- io_uring Explained: Why Linux Needed a Third Async I/O Interface Two shared ring buffers replace a syscall per operation. What was wrong with epoll and AIO, how submission and completion queues work, why polled mode can do I/O with zero syscalls, and the security tradeoff that has distributions disabling it.
- eBPF and bpftrace Explained How eBPF runs sandboxed programs inside the kernel, what the verifier will and will not allow, and the bpftrace one-liners that answer production questions strace cannot.