You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何访问gflags.exe创建的用户模式堆栈跟踪数据库(ust)及相关API?

回答

Great question! I've dug into this exact scenario before when building custom memory profiling tools, so let me break down what you need to know:

Can you query the UST database like a SQL store?

Short answer: No, there's no official SQL-style interface for the User Mode Stack Trace (UST) database. It's an internal Windows debugging structure designed to support tools like UMDH and LeakDiag, not a general-purpose queryable store. But that doesn't mean you can't access and analyze its data directly.

How to access UST data programmatically

The UST subsystem exposes undocumented but functional APIs in ntdll.dll that you can leverage to enumerate and parse stack traces. Here's the high-level workflow:

  • First, get a handle to the UST database associated with your target process. Use NtQueryInformationProcess with the ProcessUserModeStackTraceInformation class (you'll need to define the constant value yourself, as it's not publicly exposed) to retrieve a pointer to the UST root structure.
  • Next, use the RtlEnumerateUserStackTraces function to iterate through every recorded stack trace entry linked to memory allocations. This function will yield each allocation's stack frame addresses one by one.
  • To make sense of the raw addresses, use RtlLookupFunctionEntry to resolve each frame to a function name and offset. You can then aggregate these stack traces to count allocations and total memory per callstack, just like UMDH does.

Heads up: These APIs are undocumented, so their signatures or behavior might change across Windows versions. Always test against your target OS and be prepared to adjust for updates.

Easier alternatives for your learning goal

If you don't want to dive into undocumented APIs, there are simpler paths to get the same stack-based allocation stats:

  • Parse UMDH output: Run umdh.exe -p:<PID> -f:snapshot1.txt to generate a raw allocation snapshot, then write a script (PowerShell, Python, etc.) to parse the text output. Group entries by their stack trace strings, sum up allocation counts and sizes, and you'll have your custom stats. This is a low-effort way to learn how stack-based aggregation works without touching low-level APIs.
  • Use WinDbg scripts: In WinDbg, commands like !heap -p -a <heap_addr> will show UST-linked allocations. You can write a JavaScript or NatVis script to automate traversing all heap allocations, capturing their stacks, and aggregating the data into stats. This is great for learning how the debugger interacts with UST under the hood.

Where to find UST documentation

Microsoft doesn't publish official docs for the UST database structure or APIs—since it's part of Windows' internal debugging infrastructure. But you can find reverse-engineered details:

  • Check out community debugging resources: Senior Windows debugging experts often write about UST in blogs or books, breaking down its structure and how tools like UMDH use it.
  • Look at open-source implementations: Projects like ReactOS have recreated UST-related functions to mimic Windows' behavior; studying their code can give you a clear picture of how UST works under the hood.

内容的提问来源于stack exchange,提问作者RammerChoi

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.22 09:34:09