Install
$ agentstack add skill-flydev-fr-mormot2-superpowers-systematic-debugging ✓ scanned · ✓ verified — works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
About
Systematic Debugging
Overview
Random fixes waste time and create new bugs. Quick patches mask underlying issues.
Core principle: ALWAYS find root cause before attempting fixes. Symptom fixes are failure.
Violating the letter of this process is violating the spirit of debugging.
The Iron Law
NO FIXES WITHOUT ROOT CAUSE INVESTIGATION FIRST
If you haven't completed Phase 1, you cannot propose fixes.
When to Use
Use for ANY technical issue:
- Test failures
- Bugs in production
- Unexpected behavior
- Performance problems
- Build failures
- Integration issues
Use this ESPECIALLY when:
- Under time pressure (emergencies make guessing tempting)
- "Just one quick fix" seems obvious
- You've already tried multiple fixes
- Previous fix didn't work
- You don't fully understand the issue
Don't skip when:
- Issue seems simple (simple bugs have root causes too)
- You're in a hurry (rushing guarantees rework)
- Manager wants it fixed NOW (systematic is faster than thrashing)
The Four Phases
You MUST complete each phase before proceeding to the next.
Phase 1: Root Cause Investigation
BEFORE attempting ANY fix:
- Read Error Messages Carefully
- Don't skip past errors or warnings
- They often contain the exact solution
- Read stack traces completely
- Note line numbers, file paths, error codes
- Reproduce Consistently
- Can you trigger it reliably?
- What are the exact steps?
- Does it happen every time?
- If not reproducible → gather more data, don't guess
- Check Recent Changes
- What changed that could cause this?
- Git diff, recent commits
- New dependencies, config changes
- Environmental differences
- Gather Evidence in Multi-Component Systems
WHEN system has multiple components (CI → build → signing, API → service → database):
BEFORE proposing fixes, add diagnostic instrumentation: ``` For EACH component boundary:
- Log what data enters component
- Log what data exits component
- Verify environment/config propagation
- Check state at each layer
Run once to gather evidence showing WHERE it breaks THEN analyze evidence to identify failing component THEN investigate that specific component ```
Example (multi-layer system): ```bash # Layer 1: Workflow echo "=== Secrets available in workflow: ===" echo "IDENTITY: ${IDENTITY:+SET}${IDENTITY:-UNSET}"
# Layer 2: Build script echo "=== Env vars in build script: ===" env | grep IDENTITY || echo "IDENTITY not in environment"
# Layer 3: Signing script echo "=== Keychain state: ===" security list-keychains security find-identity -v
# Layer 4: Actual signing codesign --sign "$IDENTITY" --verbose=4 "$APP" ```
This reveals: Which layer fails (secrets → workflow ✓, workflow → build ✗)
- Trace Data Flow
WHEN error is deep in call stack:
See root-cause-tracing.md in this directory for the complete backward tracing technique.
Quick version:
- Where does bad value originate?
- What called this with bad value?
- Keep tracing up until you find the source
- Fix at source, not at symptom
Phase 2: Pattern Analysis
Find the pattern before fixing:
- Find Working Examples
- Locate similar working code in same codebase
- What works that's similar to what's broken?
- Compare Against References
- If implementing pattern, read reference implementation COMPLETELY
- Don't skim - read every line
- Understand the pattern fully before applying
- Identify Differences
- What's different between working and broken?
- List every difference, however small
- Don't assume "that can't matter"
- Understand Dependencies
- What other components does this need?
- What settings, config, environment?
- What assumptions does it make?
Phase 3: Hypothesis and Testing
Scientific method:
- Form Single Hypothesis
- State clearly: "I think X is the root cause because Y"
- Write it down
- Be specific, not vague
- Test Minimally
- Make the SMALLEST possible change to test hypothesis
- One variable at a time
- Don't fix multiple things at once
- Verify Before Continuing
- Did it work? Yes → Phase 4
- Didn't work? Form NEW hypothesis
- DON'T add more fixes on top
- When You Don't Know
- Say "I don't understand X"
- Don't pretend to know
- Ask for help
- Research more
Phase 4: Implementation
Fix the root cause, not the symptom:
- Create Failing Test Case
- Simplest possible reproduction
- Automated test if possible
- One-off test script if no framework
- MUST have before fixing
- Use the
superpowers:test-driven-developmentskill for writing proper failing tests
- Implement Single Fix
- Address the root cause identified
- ONE change at a time
- No "while I'm here" improvements
- No bundled refactoring
- Verify Fix
- Test passes now?
- No other tests broken?
- Issue actually resolved?
- If Fix Doesn't Work
- STOP
- Count: How many fixes have you tried?
- If When this section applies: the session is operating on a Pascal project (the
> PASCAL_PROJECT=1 env was exported by the mormot2-superpowers session-start hook). > If PASCAL_PROJECT is unset, ignore this section.
The 4-phase root-cause method applies as-is. Pascal-specific signals to use during Phase 1 (reproduce + observe):
TSynLog as a structured observation log
TSynLog writes one entry per significant event with millisecond timestamps and (when configured) a stack trace per error. To enable on a target session, before reproducing the bug:
with TSynLog.Family do begin
Level := LOG_VERBOSE; // sllInfo + sllDebug + sllTrace + sllError + ...
PerThreadLog := ptIdentifiedInOneFile;
HighResolutionTimestamp := true;
AutoFlushTimeOut := 5;
end;
Logs land under the project's working directory, named after the executable. Read them before forming a hypothesis. Don't speculate without the log line that triggered the bug.
FastMM4 leak reports (Delphi)
When a unit-test or shutdown reports a leak, the FastMM4 report identifies the allocation site by call stack. Match the stack against .map/DWARF (cross-link pascal-debugging-logging) to land on the source line. Common false positives: dynamic packages, RTL caches kept across processes.
EAccessViolation, EAssertionFailed
Always read the address. If the project ships with .map (Delphi -GD) or DWARF symbols (FPC -gw3 -gl), TSynLog resolves the address to a source line in the log. Without symbols, use addr2line (FPC) or the .map+mORMot2-MapDownload flow (Delphi) before guessing.
Pitfalls
- "It only happens in Release builds" usually means uninitialized stack (build with
-Oron FPC to catch it) or RTL patches disabled (NOPATCHRTLset unintentionally). - "It only happens with the SQLite static lib" - see
mormot2-deployfor static-lib link flags. - Never debug threading bugs without
PerThreadLog := ptIdentifiedInOneFile.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: flydev-fr
- Source: flydev-fr/mormot2-superpowers
- License: MIT
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet — be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.