Core Dump
A snapshot of a crashed process's memory for later analysis.
Also known as: core dump, coredump, crash dump
A core dump is a file containing a snapshot of a process’s memory and CPU state at the moment it crashed. When a program dies from a fatal fault — a segmentation fault, an abort — the operating system can write this snapshot so you can inspect it after the fact, in a debugger, instead of trying to catch the crash live. It’s especially valuable for failures that are hard to reproduce.
ulimit -c unlimited # allow core dumps for this shell
# ... program crashes, producing a core file ...
gdb ./program core # load the dump and inspect
(gdb) bt # backtrace: where it crashed
In the debugger, bt (backtrace) is usually the first thing you run: it shows the stack trace at the point of failure — the chain of function calls that led there, and the exact line that faulted if symbols are available.
The classic mistakes:
- Core dumps are disabled. Many systems set the core size limit to zero by default, so a crash produces nothing to analyse. If you need dumps, raise the limit (or set the kernel’s core pattern to a managed location) before the crash.
- Stripped binaries. A dump is useless without symbols that map addresses to function names and lines. Ship debug symbols (or keep the exact build) alongside any binary you expect to debug.
- Huge files. A core dump can be as large as the process’s memory. On a big service that’s gigabytes; configure where they go, how many to keep, and clean them up.
- Secrets in the dump. The snapshot is raw memory and can contain passwords, tokens and personal data. Treat core dumps as sensitive; restrict access and delete them when done.
- Expecting it to explain a logic bug. A core dump shows where it crashed, not why the program did the wrong thing. For a
nulldereference it’s gold; for a wrong result, you need other tools.
Core dumps are a post-mortem tool: capture the crash once, then analyse at leisure. On systems where enabling them everywhere is impractical, a crash-reporting service does the same job by collecting the dump centrally — the same idea applied at fleet scale. See signals for what kills a process and ulimit for the limits that govern dumps.