执行dump命令提取进程内存至文件时遭遇‘illegal number of blocks per write -- memory’错误的解决方案求助
dump Command Error When Extracting Process Memory Hey there, let's break down what's going wrong here and get your process memory extracted properly.
Why You're Seeing That Error
The dump command you're using is actually designed for filesystem backups, not reading process memory from /proc/$pid/mem. Its syntax expects parameters related to backup volumes and block counts, so when you pass memory as an argument, it misinterprets it as an invalid "blocks per write" value—hence the error dump: illegal number of blocks per write -- memory.
Correct Ways to Extract Process Memory
Here are two reliable methods to get the job done:
1. Use gcore (Simplest Approach)
gcore is a dedicated tool for generating core dumps of running processes, which contain the full memory state of the process. Run this command:
sudo gcore -o result $pid
This will create a file named result.$pid (replace $pid with your target process ID) that holds all the process's memory. You can then analyze or extract data from this core file as needed.
2. Use dd with /proc/$pid/mem (Targeted Extraction)
If you only need specific memory regions (not the entire process memory), you can use dd along with /proc/$pid/maps to locate valid memory segments:
- First, list the process's memory regions to find the address range you want:
Look for lines like this (example of a writable heap segment):cat /proc/$pid/maps55f8b7a3a000-55f8b7a5b000 rw-p 00000000 08:01 131073 /usr/bin/your-program
- Calculate the length of the segment: subtract the start address from the end address (convert hex to decimal if needed). For the example above,
0x55f8b7a5b000 - 0x55f8b7a3a000 = 0x21000(135168 in decimal). - Use
ddto read only that valid segment:
Replace thesudo dd if=/proc/$pid/mem of=result.bin bs=1 skip=$((0x55f8b7a3a000)) count=$((0x21000))skipandcountvalues with your actual start address and segment length.
Important Notes
- You need root (
sudo) access to read/proc/$pid/memand generate core dumps. - The target process must be running when you execute these commands—if it exits,
/proc/$pidwill be removed immediately. - Avoid trying to read the entire
/proc/$pid/memdirectly; it contains large chunks of invalid/unmapped memory that will cause errors or produce useless data.
内容的提问来源于stack exchange,提问作者Pedro

