Meziantou.Framework.Diagnostics.MemoryDump 1.0.0

Prefix Reserved
dotnet add package Meziantou.Framework.Diagnostics.MemoryDump --version 1.0.0
                    
NuGet\Install-Package Meziantou.Framework.Diagnostics.MemoryDump -Version 1.0.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="Meziantou.Framework.Diagnostics.MemoryDump" Version="1.0.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="Meziantou.Framework.Diagnostics.MemoryDump" Version="1.0.0" />
                    
Directory.Packages.props
<PackageReference Include="Meziantou.Framework.Diagnostics.MemoryDump" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add Meziantou.Framework.Diagnostics.MemoryDump --version 1.0.0
                    
#r "nuget: Meziantou.Framework.Diagnostics.MemoryDump, 1.0.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package Meziantou.Framework.Diagnostics.MemoryDump@1.0.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=Meziantou.Framework.Diagnostics.MemoryDump&version=1.0.0
                    
Install as a Cake Addin
#tool nuget:?package=Meziantou.Framework.Diagnostics.MemoryDump&version=1.0.0
                    
Install as a Cake Tool

Meziantou.Framework.Diagnostics.MemoryDump

Create a memory dump of the current process on Windows, Linux, and macOS, without installing dotnet-dump or any other tool.

Usage

using Meziantou.Framework.Diagnostics;

// Full dump (default)
MemoryDump.Write("app.dmp");

// Smaller dump containing the managed heap
await MemoryDump.WriteAsync("app.dmp", MemoryDumpType.WithHeap, cancellationToken);

You can open the dump with Visual Studio, WinDbg, dotnet-dump analyze, or lldb with the SOS extension.

A typical use is to dump the process when it detects a problem it cannot explain, such as thread pool starvation or a request that never completes:

if (queueDelay > TimeSpan.FromSeconds(5))
{
    MemoryDump.Write(Path.Combine(dumpDirectory, $"starvation-{DateTime.UtcNow:yyyyMMddHHmmss}.dmp"));
}

Dump types

MemoryDumpType Content
Normal Module and thread lists, all stacks, and exception information
WithHeap Same as Normal, plus handle information and all memory except mapped images. Enough to inspect the managed heap
Triage Same as Normal, with personally identifiable information such as paths and passwords removed
Full All the memory of the process, including module images

The types match the DumpType enum of Microsoft.Diagnostics.NETCore.Client and the --normal, --withheap, --triage, and --full options of createdump.

How it works

  • Windows: captures a snapshot of the process with PssCaptureSnapshot, then writes it with MiniDumpWriteDump from dbghelp.dll, as Windows Error Reporting does. A process cannot suspend itself, so dumping the live process directly can fail when its memory changes while it is read.
  • Linux and macOS: runs the createdump tool shipped with the .NET runtime, looked up in the runtime directory, then in the application directory (self-contained and single-file apps).

Calls are serialized: when several threads request a dump at the same time, the dumps are written one after the other.

Remarks

  • A memory dump may contain sensitive data such as credentials, tokens, or connection strings. Store and share it accordingly.

  • A full dump is as large as the memory used by the process, often hundreds of megabytes.

  • The process is suspended while the dump is written.

  • A process in a bad state (e.g. out of memory) may not be able to dump itself.

  • On Linux, when Yama restricts ptrace (kernel.yama.ptrace_scope = 1, the default on Ubuntu), createdump is not allowed to attach to its parent process. MemoryDump calls prctl(PR_SET_PTRACER, PR_SET_PTRACER_ANY) before starting createdump and resets it with prctl(PR_SET_PTRACER, 0) afterward. This overrides any value set by the application. With ptrace_scope = 2, the process needs the CAP_SYS_PTRACE capability, and with ptrace_scope = 3, no dump can be created.

  • In a container, ptrace may be blocked by the seccomp profile or require the SYS_PTRACE capability.

  • On macOS, createdump can only attach to a process signed with the com.apple.security.get-task-allow entitlement. The dotnet host has it, so dotnet app.dll works. The app host generated by the SDK (./app) is signed without entitlements. Re-sign it to allow dumps:

    
    <plist version="1.0">
    <dict>
        <key>com.apple.security.get-task-allow</key>
        <true/>
    </dict>
    </plist>
    
    codesign --force --sign - --entitlements entitlements.plist ./app
    
Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed.  net11.0 is compatible. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • net10.0

    • No dependencies.
  • net11.0

    • No dependencies.

NuGet packages

This package is not used by any NuGet packages.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.0.0 84 9/23/2026