#!/usr/bin/env python3 """Read guest memory out of a core file, at an address the fault registers named. core-guest-stack.py answers "where did it stop"; this answers "what was actually IN the object". A garbage pointer is ambiguous on its own: a C++ object whose first word points into a loaded image is alive and merely holds a bad field, while one whose first word is a float or a small integer was never that kind of object at all. scripts/core-guest-memory.py [--words N]
[
...] Each word is printed as hex, as a signed integer, as an IEEE double, and, when it falls inside a mapped region the core describes, with the name of the file mapped there. That last column is the one that decides "real object" versus "not an object". """ import struct import sys PT_LOAD = 1 PT_NOTE = 4 NT_FILE = 0x46494C45 def _phdrs(blob): if blob[:4] != b"\x7fELF" or blob[4] != 2: raise SystemExit("not a 64-bit ELF core") e_phoff, = struct.unpack_from("> 63 else w points = _owner(files, w) note = f" -> {points}" if points else "" print(f" +{i:#05x} {w:#018x} {s:>20} {d:>24.6g}{note}") print() if __name__ == "__main__": main()