I'm looking into creating dump files for a managed process.
I know that I can use windbg to create a dump file, but I'm wondering if their are any special flags that I should pass to the ".dump" command, given that it's a managed application in开发者_如何学Gostead of a native one.
a related side question: I've heard of a tool called mscordmp.exe (if you google it, you can find mention of it online). Is mscordmp still relevant? I can't find a download point for it anywhere, but I thought it might be better suited for dumping managed memory than windbg.
You should use /ma to create full memory dump. Otherwise sos will complain that managed analysis will be very limited.
No, there's no any special flags related to managed application, windbg just creates memory dump, it's raw data. It is the purpose of your analysis tool to know whether your dump was created for managed application or unmanaged.
If speaking about analysing managed application, you there can be the following steps:
- attach windbgto process running managed application
- run .dump /ma <outputfilename.dmp>. It creates dump file, this operation can take about several minutes depending on memory consumed by process. The/maflag orders to create full memory dump of attached process with all options enabled (it is not full system dump, only attached process).
- detach from process, it can continue to run, while you can load dump file into windbgand analyse it.
- sos.dll is the common windbgextension for analysing managed applications.
p.s. There can be problem enabling sos.dll with .load sos.dll, in that case you can try .loadby sos mscorwks.
 
         
                                         
                                         
                                         
                                        ![Interactive visualization of a graph in python [closed]](https://www.devze.com/res/2023/04-10/09/92d32fe8c0d22fb96bd6f6e8b7d1f457.gif) 
                                         
                                         
                                         
                                         加载中,请稍侯......
 加载中,请稍侯......
      
精彩评论