12 ms·
Memzoom – view/monitor the raw memory of processes/files in your UTF-8 terminal
- atorodius 4y agoLooks pretty sweet. Not sure what I'd use it for but I love live updating stuff
- T3OU-736 4y agoHrm. As a half-bakes thought - if code handles sensitive data, making sure it is correctly obfuscated in memory?
- csdvrx 4y agoThis. I'd be nice to have a list of strings to monitor (ex: half of the ssh private key) and warn when they are found somewhere, to detect data exfiltration.
- fortyseven 4y agoReverse engineering; getting an idea of what an unknown app might be doing, and where, so you can trace it back in the code. And so on.
- Loocid 4y agoSurely whatever RE tool you're using already has a memory viewer built in.
- deleted 4y ago[deleted]
- ape4 4y agoThe one executable supports PE+ELF+MachO+ZIP+SH
- makeworld 4y agoCan anyone provide an example use case for this? Especially those different curves.
- zamadatix 4y agoThe different curves do a good job of preserving locality when mapping to 2d space.
- anitil 4y agoI can think of two where this tool could be a first step - 1. Do you ever have a program that kind of just sucks? A bit slower than you expect, laggy but not in any specific way? The fundamental cause could be many things, but it could be, for example, thrashing memory pointlessly. I've seen processes memset/bzero then write, then memset/bzero for seemingly no reason and the source is difficult to follow. 2. How does struct alignment and malloc alignment impact your program? Maybe you could reduce your working set by using packed structs or changing the order of elements. Maybe you could choose a different allocator. But this tool could show you if you've got a bunch of loose space floating around
- jart 4y agoThis is good information. On one of my other blog posts, I talk about what different types of memory look like under this viewer. https://justine.lol/sizetricks/#look https://justine.lol/sizetricks/#look It should give you the basic idea of how to interpret what you see under this intuitive display. It also goes more in depth into how size optimization tricks like struct alignment can be done.
- anitil 4y agoAh thanks for that I remember that page now, time for a reread!
- DonHopkins 4y agoOh cool! That would make a great screen saver, too. ;)
- PenguinRevolver 4y agosomeone's gonna recreate bad apple on this.
- marcodiego 4y agoThe code is interesting: https://github.com/jart/cosmopolitan/blob/master/tool/viz/memzoom.c https://github.com/jart/cosmopolitan/blob/master/tool/viz/me... Feels really old school. Looks like something from people used to write DOS programs.
- mcdonje 4y agoReally digging the retro vibe of the code, man.
- naikrovek 4y agoif you mean the straight-forward nature of the code, I agree. I think we over-complicate code today because we are promised ease of maintenance, or high-level declaration, or something else, and I don't think those promises have ever come true, except in very small textbook-type examples.
- chris1993 4y agoIt's a work of beautiful clarity
- eatonphil 4y agoFirst off, Justine is a better programmer than I. But, and I don't mean this as a humblebrag, the use of all global variables for state makes me uncomfortable. If this is good C code (not saying it isn't) then maybe that's why I'm not a C programmer. Whatever the case, Justine is great.
- jart 4y agoThat's a good instinct to have. 99% of the time we're writing something like an object library that's part of a much larger program. To use global variables in such code would impose difficulties on the application as a whole, with regard to things like threading, pollution of the linker symbol table, etc. But when you're writing small main.c programs like this one which don't use threads, globals can be a real advantage. In gdb, you can easy inspect their values. You can look at the linker output manifest listing to see how they're being arranged in your binary. If you look at a lot of the old original UNIX programs that were written back in the day, a lot of them looked very similar to this. So it's a great style. It's just not one that scales to large monolithic programs that most companies prefer to create. So over the years a cultural aversion to it was developed in many style guides.
- jart 4y agoI'm loving how half the comments are, "I don't know why I'd ever need to look at my program's memory?" And folks wonder why things are so bloated!
- jeroenhd 4y agoTo be fair, memory profilers and analysers are probably much easier and more accessible than just raw memory dumps. Modern tools ranging from Valgrind to the web browser heap analyser is a lot easier to master than scrolling through megabytes of hex trying to find an area of memory that's not necessary. Even if I were to debug memory using raw hex, I'd probably take a snapshot and open that in a good hex editor instead of just watching some blocks blink.
- usmannk 4y agoI think the confusing part is the live view of utf-8 encoded memory scrolling by. As opposed to samples or profiles, which are more evidently useful to those who aren't doing systems programming regularly.
- naikrovek 4y agoI don't think one needs to view memory contents of their own program to know what what the memory contents are, roughly, or to know how to use memory efficiently. Debuggers and profilers already exist for the developers of applications to know these things. this tool seems much more useful for the reverse engineer who is watching memory of a target application visually while they step in a debugger. this wouldn't even be for reading specific values of RAM, again the debugger is usually quite good at that, but instead would be useful to see how things change as execution continues.
- josephg 4y ago> Debuggers and profilers already exist for the developers of applications to know these things. One big difference between an intermediate and an expert programmer is that an expert develops their intuition for how the program they write will compile and run. Can you guess correctly how fast, or how slow each function will be? Or what the optimizer will do a good or a bad job at optimizing? Can you tell before you've written your code when avoiding allocations is going to speed things up, and when it won't matter? Debuggers and profilers honestly aren't very good at giving you a "zoomed out" view of whats going on in your program. Each tool shows you a specific aspect of your program, and hides everything else. For profilers, thats usually what the CPU spends its time on. For debuggers, the execution path of a single function. Godbolt shows how the optimizer works. And so on. But from my perspective, having more tools which show different aspects of my code is almost always a win. I never know ahead of time which perspective will let me double my program's performance, or halve memory usage. Writing code is easy. Understanding code is much more complex. So yeah, from a software development point of view I think this is neat! I want to give it a try on some of my programs because I expect to see my mental model animated back at me, and I anticipate being surprised. This looks cool!
- teddyh 4y ago/usr/libexec/xscreensaver/memscroller
- DrBazza 4y agoReminds me of *mzap on the bbc micro 40 years ago.
- ahartmetz 4y agoI wrote a similar thing with a Qt based GUI that, I think, exposes a little more information (more of the kernel's page flags). It reaches a quite respectable update rate for what it's doing (>=40 fps or so?) and it's fun to watch, though I haven't found particularly useful, err, uses. https://github.com/KDAB/QMemstat https://github.com/KDAB/QMemstat
- jart 4y agoPlease put screenshots in your README file because I'd love to see your work! Especially if they're GIFs. Contact me if you want to know the ffmpeg commands I used for memzoom.
- anitil 4y agoThe first thing I thought of was blinkenlights, and of course it's Justine. Fantastic!
- humanistbot 4y agoShe's done so many cool things that have made it to the top of HN: https://justine.lol/index.html https://justine.lol/index.html
- CyMonk 4y agothis reminds me of the days when i was a teenager in the 80s and one of my hobbies was ripping the music from video games which basically meant identifying and isolating the code and data responsible for the audio. i remember taking a hex monitor and browsing/ scrolling through all the 64k memory of the commodore c64 and i could tell you just by looking at visual repeating data patterns in the raw hex dump where the song data was located.
- IAmLiterallyAB 4y agoI'm not sure if text is the ideal way to look at memory. Perhaps something like a color gradient. With special cases for 0x00 and 0xff. But the Hilbert curve is neat.
- Arrath 4y agoNot for the first time[1], my virus scanner (Windows Defender this time, Sophos previously) flags the downloaded executable, in this case for "Trojan:Win32/Wacatac.B!ml" Which given how it analyzes memory may make sense as a false positive. 1) Justine's blinkenlights and one other I can't remember at the moment have done so previously as well.