Skip to content

Glossary

Statedump

A Unified Log record (tracev3 tag 0x6003) where a process dumps a block of state, such as a plist, a protobuf or an object.

A statedump is a snapshot a process writes into the log on demand, stored in a chunk with tag 0x6003. It has a title and a payload: a property list, a protobuf or a custom object decoded by a system library. log show shows them as stateEvent entries; the "TCC Authorization Cache" of imagent is a common example.

Statedumps can reveal configuration or permissions at a point in time. A related record, the simpledump (0x6004), carries a short message without a format string, mostly from launchd.