On 04/13/2011 05:46 PM, Scott Edwards wrote:
Sound messy, because a live /dev/mem is a moving target. Similar to
taking an
action photo with the shutter open too long. Just keeo this in mind.
Scott.
Think the OP is talking about applications where the crashed kernel is dead and
gone but some embedded hardware support still permits an external debugger
(serial, JTAG or similar I guess?) to read out the content of physical memory.
The result of that is a file that's the equivalent of a dd image of /dev/mem
although it's not taken from the live system by reading /dev/mem from userspace.
Regards,
Bryn.