microsoft/ebpf-for-windows · Archived

debug-crash-dump

Download and analyze crash dumps from CI failures using CDB/WinDbg. Use this skill when asked to debug crashes, analyze dump files, set up WinDbg/CDB, investigate fault injection failures, or start mcp-windbg.

First seen Jul 10, 2026

Installation

$ npx skills add microsoft/ebpf-for-windows --skill debug-crash-dump

Stronger alternatives

This repository is archived — consider an actively maintained alternative.

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from microsoft/ebpf-for-windows.

npx skills add microsoft/ebpf-for-windows

Browse all from microsoft/ebpf-for-windows

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 3.6K
License LICENSE.txt
Default branch main
Open issues 270
Status Archived

Package contents

Files included with this skill beyond the listing page.

  • skill md SKILL.md 3,983 B
  • docs SUMMARY.md 233 B

History

  1. First seen on skills.sh
  2. First recorded snapshot · 2 installs

SKILL.md

Crash Dump Debugging

Download and analyze crash dumps from CI workflow failures (especially faultinjectionfull).

See [docs/CrashDumpDebugging.md](../../../docs/CrashDumpDebugging.md) for the full human-readable guide.

When to Use

  • User asks to debug a CI crash or test failure with a crash dump
  • User asks to download crash dump artifacts from a workflow run
  • User asks to set up CDB, WinDbg, or mcp-windbg
  • User asks to analyze a .dmp file
  • User asks about fault injection leak detection failures

Agent Prerequisites

  1. Windows Debugging Tools (CDB/WinDbg) — Install the Debugging Tools feature from the Windows SDK:

``powershell # Download the SDK online installer Invoke-WebRequest -Uri "https://go.microsoft.com/fwlink/?linkid=2272610"; -OutFile winsdksetup.exe # Install only the debugging tools (elevated) Start-Process -FilePath .\winsdksetup.exe -ArgumentList "/features","OptionId.WindowsDesktopDebuggers","/quiet","/norestart" -Verb RunAs -Wait ` CDB installs to: C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\cdb.exe`

  1. mcp-windbg (MCP server for AI-assisted dump analysis):

``powershell # Install Python 3.12 via NuGet (if not already available) nuget install python -Version 3.12.8 -OutputDirectory C:\Users\$env:USERNAME\tools $pyExe = (Get-ChildItem "C:\Users\$env:USERNAME\tools\python.3.12.8" -Recurse -Filter "python.exe" | Select-Object -First 1).FullName & $pyExe -m ensurepip --upgrade & $pyExe -m pip install mcp-windbg ``

Downloading Artifacts

# Download crash dumps and build artifacts (PDBs) from a CI run
gh run download <run_id> -R <owner>/ebpf-for-windows -n "Crash-Dumps-<test>-x64-<config>" -D crash-dumps
gh run download <run_id> -R <owner>/ebpf-for-windows -n "Build-x64-<config>" -D build
# Extract inner build zip for PDBs (produces build\<config>\<config>\ with PDBs)
Expand-Archive build\build-<config>.zip -DestinationPath build\<config>

Analyzing Dumps with CDB

$cdbPath = "C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\cdb.exe"
$symPath = "build\<config>\<config>;SRV*C:\Symbols*https://msdl.microsoft.com/download/symbols"

# Quick triage: exception record + stack trace
& $cdbPath -z crash-dumps\unit_tests.exe.XXXX.dmp -y $symPath -lines -c ".ecxr;kP;q"

# Full automated analysis
& $cdbPath -z crash-dumps\unit_tests.exe.XXXX.dmp -y $symPath -c "!analyze -v;q"

Running mcp-windbg Server

$pyExe = (Get-ChildItem "C:\Users\$env:USERNAME\tools\python.3.12.8" -Recurse -Filter "python.exe" | Select-Object -First 1).FullName
$cdbPath = "C:\Program Files (x86)\Windows Kits\10\Debuggers\x64\cdb.exe"
$symPath = "build\<config>\<config>;SRV*C:\Symbols*https://msdl.microsoft.com/download/symbols"

& $pyExe -m mcp_windbg --cdb-path $cdbPath --symbols-path $symPath --transport streamable-http --port 8765
# MCP endpoint: http://127.0.0.1:8765/mcp

Common Patterns

  • Fault injection crashes: Usually assert allocations.empty() in leakdetector.cpp — a memory leak detected during teardown. Check the leak detector's inmemory_log for the allocation call stack:

`` $$ Get exception context and inspect the stack to find the leakdetector frame: .ecxr kP $$ Identify the frame index where 'this' is the leakdetector instance .frame <N> dx this->inmemory_log ``

  • Crash dump artifacts: Named Crash-Dumps-<testname>-<platform>-<config> (e.g., Crash-Dumps-faultinjection_full-x64-Debug)
  • Build artifacts with PDBs: Named <buildartifact>-<config> (for the default buildartifact=Build-x64, this is Build-x64-Debug), and contain an inner zip build-<config>.zip