If I have a need to analyze memory leaks in a dump from a remote machine and I have enabled the user mode stack trace database as detailed here are those stack traces going to be a part of the dump file or I need to transfer something else from the remote machine except for the dump file? Or can I only see those stacks when running WinDBG on the same machine the dump was taken on? So far, all the resources I've seen regarding this topic, do not elaborate on what is the actual storage place for these stacks.
remote dump analysis - is the "user mode stack trace database" par to the dump file?
248 Views Asked by Rudolfs Bundulis At
1
There are 1 best solutions below
Related Questions in DEBUGGING
- How to pass the value of a function of one class to a function of another with the @property decorator
- Visual Studio C++, breakpoints not stopping debugging DLL (GODOT GDExtention)
- Playwright JS: Getting an error when debugging using line numbers
- C++ skips line when promting for user to enter name of person being added to a string array
- Xcode: Can't Attach to process
- unity navmeshsurface prefab not found or whatever
- It seems to be a bug about "base::trace()" or "methods:::.TraceWithMethods()"?
- How to check reference counting issues when doing direct manipulations of CPython objects?
- How to scroll to the bottom of console window in PyCharm2019 automatically?
- need help debugging prolog
- Is there a way to deactivate (but not delete) conditional breakpoints when debugging?
- How can i debug a python exe which is created by using pyinstaller?
- Increment or Decrement volume programmatically on Xiaomi device adjusts it by 10 steps instead of one step
- Checking request JSON with image data
- Why cannot I set font of `xlabel` in `plotmf` in MATLAB?
Related Questions in WINDBG
- WinDbg of .Net application shows 2 threads with locks, but empty !locks and !syncblk
- using WinApi 32 in Windbg Breakpoints based actions
- Windows kernel debugging with windbg through network: is there an alternative to ".kdfiles"?
- WinDbg session does not connect
- TEB representation for ARM64, xpr register
- How to pull .natvis data out of a PDB?
- Exception code c0020001 on shutdown - how to determine which managed code function didn't run?
- How Windows Handle to associate corresponding object type?
- Is there any way to debugging Windows XP/2000 BSOD during installation?
- Viewing the named security attributes for token in windbg (kernel mode)
- DLL not found when Debugg using Windbg for Windows7
- Understanding the Dump for w3p app with WinDbg
- find driverObject from module address using windbg kernel mode debugging
- core dump files batch processing (Windows)
- Invalid Pointer Read (Access Violation) from undocumented KERNELBASE methods crashing Windows Services
Related Questions in GFLAGS
- Setting variable in port overlay not taking effect in vcpkg
- Using gflags "Show loader snaps" with Visual Studio
- How do I get glog to use gflags when I'm using them as http_archives?
- How To enable standard page heap verification for all processes in 'WinDbg Preview'
- How does DelayFreeSizeMB change the behavior of my application?
- remote dump analysis - is the "user mode stack trace database" par to the dump file?
- Unable to specify gflag in GCP
- Access violation in RtlDebugCreateHeap api on enabling gflags
- Module opencv_sfm disabled because the following dependencies are not found: Glog/Gflags - both are detected
- Why gflags "Enable heap tail checking" is not working alone on Windows?
- Cannot find 'gflags/gflags.h' while building library OSX
- How to pass google command line flags as an argument to GDB
- ExternalProject_Add for gflags, but build many times
- Is there a way to pass an array of ints with a command line parameter in GFlags?
- Passing shell variables containing whitespace as argument
Trending Questions
- UIImageView Frame Doesn't Reflect Constraints
- Is it possible to use adb commands to click on a view by finding its ID?
- How to create a new web character symbol recognizable by html/javascript?
- Why isn't my CSS3 animation smooth in Google Chrome (but very smooth on other browsers)?
- Heap Gives Page Fault
- Connect ffmpeg to Visual Studio 2008
- Both Object- and ValueAnimator jumps when Duration is set above API LvL 24
- How to avoid default initialization of objects in std::vector?
- second argument of the command line arguments in a format other than char** argv or char* argv[]
- How to improve efficiency of algorithm which generates next lexicographic permutation?
- Navigating to the another actvity app getting crash in android
- How to read the particular message format in android and store in sqlite database?
- Resetting inventory status after order is cancelled
- Efficiently compute powers of X in SSE/AVX
- Insert into an external database using ajax and php : POST 500 (Internal Server Error)
Popular Questions
- How do I undo the most recent local commits in Git?
- How can I remove a specific item from an array in JavaScript?
- How do I delete a Git branch locally and remotely?
- Find all files containing a specific text (string) on Linux?
- How do I revert a Git repository to a previous commit?
- How do I create an HTML button that acts like a link?
- How do I check out a remote Git branch?
- How do I force "git pull" to overwrite local files?
- How do I list all files of a directory?
- How to check whether a string contains a substring in JavaScript?
- How do I redirect to another webpage?
- How can I iterate over rows in a Pandas DataFrame?
- How do I convert a String to an int in Java?
- Does Python have a string 'contains' substring method?
- How do I check if a string contains a specific word?
the data base should be in dump
take a look here for a sample to follow
compile , run in one command prompt gflags /i dbstk.exe +ust +hpa & dbstk
will be waiting for keypress
open another command prompt and attach to the running exe
cdb -pn dbstk.exe
and create a dump
.dump /ma d:\blah.dmp
open the dump and look at stack tracedatabase
cdb -z d:\blah.dmp
!heap -p
you should get some thing like this indicating the address in the dump
but the !heap extension has been rendered mostly useless due to several
modifications in heap structures in the name of security
and the extension has been lagging behind
so you may be forced to grope in bits and bytes
on x64 i think you should start groping from here onwards (may be wrong take it with a pinch of salt haven't touched x64 heap in a long time)