Linux memory map between smaps and gcore process dump

Viewed 112

I was inspecting high memory usage by a process. I got the process address consuming high memory with -

sudo less /proc/12345/smaps

I got this segment which had high memory utilization -

5555573e8000-555cba243000 rw-p 00000000 00:00 0                          [heap]
Size:           30980460 kB
KernelPageSize:        4 kB
MMUPageSize:           4 kB
Rss:            30980412 kB
Pss:            30964728 kB
Shared_Clean:          0 kB
Shared_Dirty:      31368 kB
Private_Clean:         0 kB
Private_Dirty:  30949044 kB
Referenced:     30980412 kB
Anonymous:      30980412 kB
LazyFree:              0 kB
AnonHugePages:         0 kB
ShmemPmdMapped:        0 kB
Shared_Hugetlb:        0 kB
Private_Hugetlb:       0 kB
Swap:                  0 kB
SwapPss:               0 kB
Locked:                0 kB

Next I wanted to see whats at the memory locations 5555573e8000-555cba243000

I took the core dump with

gcore -o /tmp/dump 12345

I want to know how do the addresses 5555573e8000-555cba243000 map to address in core dump? In core dump I don't see address 5555573e8000. The address in core dump have lesser digits and are like

5555573e0: 0000 0000 0000 0000 0000 0000 0000 0000  ................
1 Answers

I want to know how do the addresses 5555573e8000-555cba243000 map to address in core dump?

You want to look at the output from readelf -Wl /tmp/dump, which should look similar to:

Program Headers:
  Type           Offset   VirtAddr           PhysAddr           FileSiz  MemSiz   Flg Align
  NOTE           0x000510 0x0000000000000000 0x0000000000000000 0x001448 0x000000     0
  LOAD           0x002000 0x0000561f0fa7e000 0x0000000000000000 0x001000 0x001000 R   0x1000
  LOAD           0x003000 0x0000561f0fa7f000 0x0000000000000000 0x000000 0x001000 R E 0x1000
  LOAD           0x003000 0x0000561f0fa80000 0x0000000000000000 0x000000 0x001000 R   0x1000
  LOAD           0x003000 0x0000561f0fa81000 0x0000000000000000 0x001000 0x001000 R   0x1000
...

From there find the LOAD segment which covers 5555573e8000 virtual address, and you will have its file offset.

Related