<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Debugging on Lead DevOps</title><link>https://lead-devops.blackdevhub.online/en/tags/debugging/</link><description>Recent content in Debugging on Lead DevOps</description><generator>Hugo</generator><language>en-US</language><lastBuildDate>Fri, 18 Sep 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://lead-devops.blackdevhub.online/en/tags/debugging/index.xml" rel="self" type="application/rss+xml"/><item><title>coredumpctl: Finding a Binary Crash</title><link>https://lead-devops.blackdevhub.online/en/posts/coredumpctl-naiti-padenie-binarya/</link><pubDate>Fri, 18 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/coredumpctl-naiti-padenie-binarya/</guid><description>&lt;h2 id="what-is-coredumpctl-and-how-it-works"&gt;What is coredumpctl and how it works&#10;&lt;/h2&gt;&#10;&lt;p&gt;When a binary crashes with SEGV, the kernel can save a core dump — a snapshot of process memory at the moment of the crash. In systemd-based distributions, &lt;code&gt;coredumpctl&lt;/code&gt; handles collecting, storing, and searching these dumps. It&amp;rsquo;s a wrapper around &lt;code&gt;systemd-coredump&lt;/code&gt;, which stores dumps in &lt;code&gt;/var/lib/systemd/coredump/&lt;/code&gt; and indexes metadata through journald.&lt;/p&gt;&#10;&lt;div class="td-callout td-callout--note" role="note"&gt;&#10; &lt;div class="td-callout__title"&gt;&lt;i class="td-callout__icon fa-solid fa-circle-info" aria-hidden="true"&gt;&lt;/i&gt;&lt;span class="td-callout__label"&gt;Note&lt;/span&gt;&lt;/div&gt;&#10; &lt;div class="td-callout__body"&gt;&#10;&lt;p&gt;Requires &lt;code&gt;systemd-coredump&lt;/code&gt; and an active journald. In minimal containers without systemd, this tool is unavailable.&lt;/p&gt;</description></item><item><title>curl: HTTP Debugging in CLI</title><link>https://lead-devops.blackdevhub.online/en/posts/curl-http-debugging-cli/</link><pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/curl-http-debugging-cli/</guid><description>&lt;p&gt;cURL is the standard tool for debugging HTTP in the terminal. It ships out of the box on Linux and macOS and is present in most Docker images. Need to quickly check an API, inspect response headers, or trace a redirect issue — one command line is enough.&lt;/p&gt;&#10;&lt;h2 id="basic-debug-flags"&gt;Basic Debug Flags&#10;&lt;/h2&gt;&#10;&lt;p&gt;The most common scenario: get a response and see what the server returned. The &lt;code&gt;-i&lt;/code&gt; flag prints headers before the body, &lt;code&gt;-v&lt;/code&gt; enables verbose mode with connection details.&lt;/p&gt;</description></item><item><title>lsof: which processes listen on port and hold file</title><link>https://lead-devops.blackdevhub.online/en/posts/lsof-port-file-processes/</link><pubDate>Fri, 04 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/lsof-port-file-processes/</guid><description>&lt;p&gt;Service won&amp;rsquo;t start — port 8080 is already bound. You dig into who&amp;rsquo;s holding it, and discover the same process has your config file open while you&amp;rsquo;re trying to edit it. lsof answers both questions: which processes opened which files and sockets.&lt;/p&gt;&#10;&lt;h2 id="listening-ports"&gt;Listening Ports&#10;&lt;/h2&gt;&#10;&lt;p&gt;The classic task — find who is listening on a specific port.&lt;/p&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-9cff1145-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="1"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-9cff1145-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;lsof -i -n -P&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;div class="td-table-scroll td-table-scroll--static"&gt;&#10;&lt;table&gt;&#10; &lt;thead&gt;&#10; &lt;tr&gt;&#10; &lt;th scope="col"&gt;Flag&lt;/th&gt;&#10; &lt;th scope="col"&gt;Effect&lt;/th&gt;&#10; &lt;/tr&gt;&#10; &lt;/thead&gt;&#10; &lt;tbody&gt;&#10; &lt;tr&gt;&#10; &lt;td&gt;&lt;code&gt;-i&lt;/code&gt;&lt;/td&gt;&#10; &lt;td&gt;Show internet sockets&lt;/td&gt;&#10; &lt;/tr&gt;&#10; &lt;tr&gt;&#10; &lt;td&gt;&lt;code&gt;-n&lt;/code&gt;&lt;/td&gt;&#10; &lt;td&gt;Skip DNS resolution (show IP instead of hostname)&lt;/td&gt;&#10; &lt;/tr&gt;&#10; &lt;tr&gt;&#10; &lt;td&gt;&lt;code&gt;-P&lt;/code&gt;&lt;/td&gt;&#10; &lt;td&gt;Skip port-to-service conversion (show 80 instead of http)&lt;/td&gt;&#10; &lt;/tr&gt;&#10; &lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;/div&gt;&#10;&#10;&lt;p&gt;Without &lt;code&gt;-n -P&lt;/code&gt;, lsof wastes time on DNS lookups and resolves ports through /etc/services. On production hosts that&amp;rsquo;s unnecessary seconds.&lt;/p&gt;</description></item><item><title>strace: System Call Tracing for Diagnosing Hangs and Leaks</title><link>https://lead-devops.blackdevhub.online/en/posts/strace-syscall-troubleshooting/</link><pubDate>Thu, 03 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/strace-syscall-troubleshooting/</guid><description>&lt;p&gt;When a service hangs, standard tools like top, htop, and ps show the state but not the cause. If a process is in state D (uninterruptible sleep), it&amp;rsquo;s waiting on a syscall. strace attaches to a live process and outputs every system call in real time. This turns a mysterious hang into a specific syscall, its arguments, and return code.&lt;/p&gt;&#10;&lt;div class="td-callout td-callout--note" role="note"&gt;&#10; &lt;div class="td-callout__title"&gt;&lt;i class="td-callout__icon fa-solid fa-circle-info" aria-hidden="true"&gt;&lt;/i&gt;&lt;span class="td-callout__label"&gt;Note&lt;/span&gt;&lt;/div&gt;&#10; &lt;div class="td-callout__body"&gt;&#10;&lt;p&gt;strace uses ptrace, the kernel&amp;rsquo;s debugging mechanism. On production, tracing slows a process by 2–10x. Use it sparingly, targeting a single PID.&lt;/p&gt;</description></item><item><title>ngrep: grep for Network Packets in Real Time</title><link>https://lead-devops.blackdevhub.online/en/posts/ngrep-setevoy-grep/</link><pubDate>Wed, 02 Sep 2026 00:00:00 +0000</pubDate><guid>https://lead-devops.blackdevhub.online/en/posts/ngrep-setevoy-grep/</guid><description>&lt;p&gt;Ngrep applies grep-style pattern matching to network packets. When you need to see exactly what two services are exchanging over the wire and tcpdump drowns you in noise, ngrep isolates the payload content you care about.&lt;/p&gt;&#10;&lt;h2 id="installation"&gt;Installation&#10;&lt;/h2&gt;&#10;&lt;p&gt;Ngrep ships in the standard repositories of most distributions.&lt;/p&gt;&#10;&lt;div class="td-code td-code--untitled" id="td-code-b19d843d-fence-0" data-td-code data-td-code-auto-id&#10; data-td-language="bash" data-td-line-count="8"&gt;&#10; &lt;div class="td-code__viewport" id="td-code-b19d843d-fence-0-viewport" data-td-code-viewport&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# Debian/Ubuntu&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;apt install ngrep&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# RHEL/CentOS/Alma&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;yum install ngrep&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="c1"&gt;# macOS&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;brew install ngrep&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;&#10;&lt;/div&gt;&#10;&lt;p&gt;Running ngrep requires root privileges or the &lt;code&gt;CAP_NET_RAW&lt;/code&gt; and &lt;code&gt;CAP_NET_ADMIN&lt;/code&gt; capabilities.&lt;/p&gt;</description></item></channel></rss>