switching to user stack in kernel dumps

user3279954

Is there a way to switch to user mode of a particular process in a kernel dump while doing postmortem debugging ?

I remember doing this while live debugging using the .process command.

Thomas Weller

.process also works in kernel dumps. First, you can find your process using

!process 0 0 myprocess.exe

and then switch to that process using

.process <address>

where <address> is the hex number after PROCESS.

Note that you are still kernel debugging and you have only the physical memory of that process available (a.k.a. Working Set). The majority of virtual address space is probably swapped to disk and you cannot analyze that process as you would in user mode (especially for .NET programs, where you need the complete .NET heap).

Collected from the Internet

Please contact [email protected] to delete if infringement.

edited at
0

Comments

0 comments
Login to comment

Related

From Dev

Switching from user mode to kernel mode

From Dev

Switching from user mode to kernel mode

From Dev

How to know the address range of kernel stack in user process and kernel thread?

From Dev

Is mode switch occur switching from user thread to kernel thread?

From Dev

Kernel Panic dumps no log files

From Dev

How to generate kernel crash dumps?

From Dev

How to examine user thread call stack from windbg kernel debugger?

From Dev

Switching Kernel Versions on Ubuntu

From Dev

How does linux kernel switch between user-mode and kernel-mode stack?

From Dev

Dumping only stack trace in linux core dumps

From Dev

What is a kernel stack used for?

From Dev

Windows Server debugging: view User Mode Stack in WDM Kernel Mode Driver Breakpoint

From Dev

Locking workstation or user switching

From Dev

Analyzing Mac OS X kernel core dumps part 2

From Dev

Switching user in Fabric using with settings(user='user')

From Dev

Switching back from development to default kernel

From Dev

How to enable crash reports/core dumps/stack trace logging globally?

From Dev

Switching from OVH kernel to default kernel without reinstalling Ubuntu

From Dev

Stack memory inside the Linux kernel

From Dev

Debug stack overruns in kernel modules

From Dev

Zigbee stack on Linux (mainline kernel)?

From Dev

Where to place the stack and load the kernel

From Dev

Debug stack overruns in kernel modules

From Dev

Recompile Kernel to Change Stack Size

From Dev

Zigbee stack on Linux (mainline kernel)?

From Java

TabView resets navigation stack when switching tabs

From Dev

How to perform fast user switching

From Dev

Show Windows' user switching screen

From Dev

Show Windows' user switching screen

Related Related

HotTag

Archive