Installation
From PyPI
pip install sdb-debugger
From Source
Ensure you have the following dependencies:
- Python 3.10 or newer
- libkdumpfile (optional - needed for kdump-compressed crash dumps)
- drgn
Note that in order for drgn to support kdump files it needs to be compiled with libkdumpfile. Unfortunately that means that users should always install libkdumpfile first before installing drgn.
Then install sdb:
git clone https://github.com/sdimitro/sdb.git
cd sdb
pip install .
For development installation (editable mode with dev dependencies):
pip install -e ".[dev]"
Quickstart
Running sudo sdb attaches sdb to the running kernel by default.
To debug a running program, run sudo sdb -p <PID>.
For post-mortem debugging (either a kernel crash dump or a userland core dump), use sudo sdb <vmlinux path|userland binary path> <dump>.
$ sudo sdb
sdb> find_task 1 | member comm
(char [16])"systemd"
sdb> find_task 1 | stack
TASK_STRUCT STATE COUNT
==========================================
0xffff89cea441dd00 INTERRUPTIBLE 1
__schedule+0x2e5
schedule+0x33
schedule_hrtimeout_range_clock+0xfd
schedule_hrtimeout_range+0x13
ep_poll+0x40a
do_epoll_wait+0xb7
__x64_sys_epoll_wait+0x1e
do_syscall_64+0x57
entry_SYSCALL_64+0x7c
sdb> addr modules | lxlist "struct module" list | member name ! sort | head -n 3
(char [56])"aesni_intel"
(char [56])"async_memcpy"
(char [56])"async_pq"
Developer Testing
First, install the development dependencies:
pip install -e ".[dev]"
# Or using requirements file:
pip install -r requirements-dev.txt
Linting
pylint -d duplicate-code -d invalid-name sdb
pylint -d duplicate-code -d invalid-name tests
Ruff (Fast Linting and Formatting)
Ruff is a fast Python linter and formatter that combines multiple tools:
ruff check sdb tests
Type Checking
mypy --strict --show-error-codes -p sdb
mypy --strict --ignore-missing-imports --show-error-codes -p tests
Note: pytest is required for mypy to properly type-check test decorators.
Style Checks
yapf --diff --style google --recursive sdb
yapf --diff --style google --recursive tests
If yapf has suggestions you can apply them automatically by substituting
--diff with -i like this:
yapf -i --style google --recursive sdb
yapf -i --style google --recursive tests
Unit Testing
Unit tests don't require crash dumps and can be run quickly:
pytest -v --cov sdb --cov-report xml tests/unit
Integration Testing
Integration tests require crash/core dumps to test against live debugging scenarios:
.github/scripts/download-dumps-from-gdrive.sh
.github/scripts/extract-dump.sh dump.201912060006.tar.lzma
.github/scripts/extract-dump.sh dump.202303131823.tar.gz
pytest -v --cov sdb --cov-report xml tests/integration
To run all tests (unit + integration):
pytest -v --cov sdb --cov-report xml tests
If you want pytest to stop on the first failure it encounters add
-x/--exitfirst to the command.
If you've added new test commands or found mistakes in the current reference output and you want to (re)generate reference output, download all crash/core dumps (or the specific one you want to correct) and run the following:
PYTHONPATH=$(pwd) python3 tests/integration/gen_regression_output.py
Metadata
Release files for sdb-debugger 0.6.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| sdb_debugger-0.6.0.tar.gz | 790.1 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| sdb_debugger-0.6.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 942.7 kB
Release files / sdb_debugger-0.6.0.tar.gz
| Download URL | sdb_debugger-0.6.0.tar.gz |
|---|---|
| Size | 790.1 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
f56604971b7453b4c3c88ea22271c127e30d8261cfda50aab4691903d228e896
|
|
BLAKE2b-256 checksum How to use checksums |
3f931e1d02b833102bd2615939e6acc3a5d9ff2c10886cd21d66fab65a41c5f4
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 9, 2026.
Transparency logRelease files / sdb_debugger-0.6.0-py3-none-any.whl
| Download URL | sdb_debugger-0.6.0-py3-none-any.whl |
|---|---|
| Size | 152.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
fdb00ccf42cceef17d81e096ee5e9293dfef83695ba2cb1a6002f46ef8864b06
|
|
BLAKE2b-256 checksum How to use checksums |
9b2e4a065861d8e25e591ecef9382c2872aa6424289e6595c29f869794bca2d6
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 9, 2026.
Transparency log