Q: You are investigating an application crash, but no core dump was generated. How do you ensure core dumps are created for future crashes?
By default, core dumps are often disabled in production environments due to disk space and security concerns. To enable them:
#Linux #Linux / SRE — Scenario-Based Interview Questions #L3 #SRE #Systems #Troubleshooting
🎙️ Candidate Opening & Architectural Context
""We encountered this OS-level bottleneck during peak traffic and diagnosed it down to kernel and filesystem metrics. The interviewer is testing: Core dump mechanisms, ulimits, systemd.. I structure my answer around systematic triage first, root cause analysis second, and permanent remediation third.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
By default, core dumps are often disabled in production environments due to disk space and security concerns. To enable them:
- ulimit: Check and set the soft/hard limits for core file size.
ulimit -S -c unlimitedin the script starting the app, or edit/etc/security/limits.confto set* soft core unlimited. - Kernel Pattern: Check where dumps are written via
sysctl kernel.core_pattern. It should point to a valid directory or a handler like systemd-coredump (e.g.,|/usr/lib/systemd/systemd-coredump %P %u %g %s %t %c %h). - Systemd: If run as a systemd service, the unit file must have
LimitCORE=infinityin the[Service]section.
2️⃣
Remediation & Permanent Safeguards
- App configuration: Ensure the application itself doesn't catch the SEGV signal without re-raising it, or hasn't called
prctlto disable dumpability (e.g.,PR_SET_DUMPABLE).
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: ulimit: Check and set the soft/hard limits for core file size. ulimit -S -c unlimited in the script starting the app, or edit /etc."
⚡ 60-Second Elevator Pitch Talking Points
- ulimit: Check and set the soft/hard limits for core file size. ulimit -S -c unlimited in the scri...
- Kernel Pattern: Check where dumps are written via sysctl kernel.core_pattern. It should point to ...
- Systemd: If run as a systemd service, the unit file must have LimitCORE=infinity in the [Service]...
Advertisement