所以发生的事情是 procdump 挂起工作进程,这会阻止它响应内部 ping,即使使用 -r reflect/clone 选项也是如此。如果将内存写入转储文件的时间超过 90 秒,则 IIS 将回收工作程序,导致旧进程终止。Procdump 然后返回“拒绝访问”或“仅完成部分 ReadProcessMemory 或 WriteProcessMemory 请求”错误消息,因为它试图读取的内存不再分配并且进程不再存在。
要解决此问题,您可以使用Resource Monitor、Process Explorer或PsSuspend来暂停svchost.exe -k iissvcs
进程,使其不会中断 procdump 进程。可以在管理控制台中运行以下 PowerShell 脚本,以创建具有最大工作集的 w3wp 进程的内存转储:
#Prevent IIS from recycling the process during procdump and causing an Access Denied error message
$iispid = Get-Process svchost | ?{$_.modules.ModuleName -eq "iisw3adm.dll"} | Select -First 1 -ExpandProperty Id
$workerpid = Get-Process w3wp | Sort ws -Descending | Select -First 1 -ExpandProperty Id
cd ~\Downloads #move to location where you want to save the dump files
#Add -accepteula to the sysinternals calls if you want to bypass the initial EULA prompt on new servers
& "c:\sysinternals\pssuspend.exe" $iispid
Write-Output "Creating memory dump for w3wp PID $workerpid"
& "c:\sysinternals\procdump.exe" -ma $workerpid
& "c:\sysinternals\pssuspend.exe" $iispid -r
输出应如下所示:
PS> & "\\dfshare\sysinternals\pssuspend.exe" $iispid
PsSuspend v1.06 - Process Suspender
Copyright ⌐ 2001-2003 Mark Russinovich
Sysinternals
Process 49836 suspended.
PS> & "\\dfshare\sysinternals\procdump.exe" -ma 98340
ProcDump v8.2 - Sysinternals process dump utility
Copyright (C) 2009-2016 Mark Russinovich and Andrew Richards
Sysinternals - www.sysinternals.com
[01:03:24] Dump 1 initiated: C:\Users\gbray\Downloads\w3wp.exe_161230_010324.dmp
[01:03:29] Dump 1 writing: Estimated dump file size is 19347 MB.
[01:05:14] Dump 1 complete: 19350 MB written in 109.8 seconds
[01:05:14] Dump count reached.
PS> & "\\dfshare\sysinternals\pssuspend.exe" $iispid -r
PsSuspend v1.06 - Process Suspender
Copyright ⌐ 2001-2003 Mark Russinovich
Sysinternals
Process 49836 resumed.
我不知道暂停 iissvcs 进程可能会产生什么其他问题,因此最好在iisreset
创建内存转储后运行。