pastebin - collaborative debugging tool
nrubsig.kpaste.net RSS


crash because fobx deallocator was called, and then using the fobx data
Posted by Anonymous on Wed 26th Nov 2025 19:40
raw | new post

  1. 3: kd> !analyze -v
  2. *******************************************************************************
  3. *                                                                             *
  4. *                        Bugcheck Analysis                                    *
  5. *                                                                             *
  6. *******************************************************************************
  7.  
  8. PAGE_FAULT_IN_NONPAGED_AREA (50)
  9. Invalid system memory was referenced.  This cannot be protected by try-except.
  10. Typically the address is just plain bad or it is pointing at freed memory.
  11. Arguments:
  12. Arg1: ffffffffffffffd0, memory referenced.
  13. Arg2: 0000000000000002, value 0 = read operation, 1 = write operation.
  14. Arg3: fffff80007ecb964, If non-zero, the instruction address which referenced the bad memory
  15.         address.
  16. Arg4: 0000000000000002, (reserved)
  17.  
  18. Debugging Details:
  19. ------------------
  20.  
  21.  
  22. KEY_VALUES_STRING: 1
  23.  
  24.     Key  : Analysis.CPU.Sec
  25.     Value: 5
  26.  
  27.     Key  : Analysis.DebugAnalysisProvider.CPP
  28.     Value: Create: 8007007e on WINGRENDEL02
  29.  
  30.     Key  : Analysis.DebugData
  31.     Value: CreateObject
  32.  
  33.     Key  : Analysis.DebugModel
  34.     Value: CreateObject
  35.  
  36.     Key  : Analysis.Elapsed.Sec
  37.     Value: 7
  38.  
  39.     Key  : Analysis.Memory.CommitPeak.Mb
  40.     Value: 89
  41.  
  42.     Key  : Analysis.System
  43.     Value: CreateObject
  44.  
  45.  
  46. BUGCHECK_CODE:  50
  47.  
  48. BUGCHECK_P1: ffffffffffffffd0
  49.  
  50. BUGCHECK_P2: 2
  51.  
  52. BUGCHECK_P3: fffff80007ecb964
  53.  
  54. BUGCHECK_P4: 2
  55.  
  56. READ_ADDRESS:  ffffffffffffffd0
  57.  
  58. MM_INTERNAL_CODE:  2
  59.  
  60. BLACKBOXBSD: 1 (!blackboxbsd)
  61.  
  62.  
  63. BLACKBOXNTFS: 1 (!blackboxntfs)
  64.  
  65.  
  66. BLACKBOXPNP: 1 (!blackboxpnp)
  67.  
  68.  
  69. BLACKBOXWINLOGON: 1
  70.  
  71. PROCESS_NAME:  as.exe
  72.  
  73. TRAP_FRAME:  fffff48e8ef4ef20 -- (.trap 0xfffff48e8ef4ef20)
  74. NOTE: The trap frame does not contain all registers.
  75. Some register values may be zeroed or incorrect.
  76. rax=ffffd3034abae610 rbx=0000000000000000 rcx=0000000000000000
  77. rdx=0000000000000001 rsi=0000000000000000 rdi=0000000000000000
  78. rip=fffff80007ecb964 rsp=fffff48e8ef4f0b0 rbp=fffff48e8ef4f279
  79.  r8=0000000000000000  r9=000001f1c564d370 r10=fffff8000e413580
  80. r11=0000000000000001 r12=0000000000000000 r13=0000000000000000
  81. r14=0000000000000000 r15=0000000000000000
  82. iopl=0         nv up ei pl zr na po nc
  83. nt!ObfReferenceObject+0x24:
  84. fffff800`07ecb964 f0480fc15ed0    lock xadd qword ptr [rsi-30h],rbx ds:ffffffff`ffffffd0=????????????????
  85. Resetting default scope
  86.  
  87. STACK_TEXT:  
  88. fffff48e`8ef4ec78 fffff800`08048b23 : 00000000`00000050 ffffffff`ffffffd0 00000000`00000002 fffff48e`8ef4ef20 : nt!KeBugCheckEx
  89. fffff48e`8ef4ec80 fffff800`07e0d450 : 00000000`00000190 00000000`00000002 fffff48e`8ef4efa0 00000000`00000000 : nt!MiSystemFault+0x1b70a3
  90. fffff48e`8ef4ed80 fffff800`0800d66d : 00000000`00000000 fffff800`07ec281d ffff8682`45400000 fffff800`0823ddd4 : nt!MmAccessFault+0x400
  91. fffff48e`8ef4ef20 fffff800`07ecb964 : fffff800`0e413580 fffff800`0e3e738e ffffd303`4abae630 00000000`00000001 : nt!KiPageFault+0x36d
  92. fffff48e`8ef4f0b0 fffff800`0e3fba98 : ffffd303`46c4fa20 00000000`c0000016 ffffd303`4a796940 00000000`00000000 : nt!ObfReferenceObject+0x24
  93. fffff48e`8ef4f0f0 fffff800`0e3f603d : 00000000`00000004 ffff8682`4b4dbc50 000001f1`c5c23080 000001f1`c564d370 : nfs41_driver!nfs41_UpcallCreate+0x268 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_updowncall.c @ 427]
  94. fffff48e`8ef4f170 fffff800`0e4263be : ffffd303`46c4fa20 00000000`c0000016 00000000`c0000016 ffff8682`4b4db6a0 : nfs41_driver!nfs41_CloseSrvOpen+0x1ed [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_openclose.c @ 1476]
  95. fffff48e`8ef4f230 fffff800`0e41ae18 : 00000000`00000000 ffff8682`4b4dbb50 ffffd303`c0000016 ffff8682`4b4dba08 : nfs41_driver!RxCloseAssociatedSrvOpen+0x23e [base\fs\rdr2\rdbss\close.c @ 515]
  96. fffff48e`8ef4f2e0 fffff800`0e41a6b9 : ffff8682`4b4dbb50 ffff8682`4b4dbb50 ffffd303`41a47d00 ffffd303`00000000 : nfs41_driver!RxFinalizeNetFobx+0x138 [base\fs\rdr2\rxce\fcbstruc.c @ 4339]
  97. fffff48e`8ef4f360 fffff800`0e41ea36 : 00000000`00000000 fffff48e`8ef4f410 ffff8682`4b4dbb50 ffff8682`4b4dbbc0 : nfs41_driver!RxDereference+0x119 [base\fs\rdr2\rxce\fcbstruc.c @ 411]
  98. fffff48e`8ef4f3a0 fffff800`0e421577 : ffffd303`48cec860 ffffd303`442d7670 ffffd303`44476001 ffff8682`4c0a3010 : nfs41_driver!RxPurgeRelatedFobxs+0x3f6 [base\fs\rdr2\rxce\scavengr.c @ 755]
  99. fffff48e`8ef4f450 fffff800`0e401f02 : ffffd303`442d7670 ffffd303`48cec860 ffff8682`4c0a3010 ffff8682`4c0a34c0 : nfs41_driver!RxCommonSetInformation+0x2a7 [base\fs\rdr2\rdbss\fileinfo.c @ 684]
  100. fffff48e`8ef4f500 fffff800`0e42098d : fffff800`0e413160 fffff800`07ecad00 ffffd303`44476080 ffffd303`41a477d0 : nfs41_driver!RxFsdCommonDispatch+0x442 [base\fs\rdr2\rdbss\ntfsd.c @ 848]
  101. fffff48e`8ef4f600 fffff800`0e3e9197 : ffffd303`469cbbc0 ffffd303`44049bc0 ffffd303`418fe180 fffff48e`8ef4f719 : nfs41_driver!RxFsdDispatch+0xfd [base\fs\rdr2\rdbss\ntfsd.c @ 442]
  102. fffff48e`8ef4f630 fffff800`07ed21c5 : ffffd303`41a477d0 ffffd303`49591a20 ffffd303`444766d0 fffff800`07ecb32b : nfs41_driver!nfs41_FsdDispatch+0x67 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_driver.c @ 1142]
  103. fffff48e`8ef4f670 fffff800`0c1ff558 : 00000000`00000000 00000000`00000000 ffffd303`440488f0 ffffd303`480adde8 : nt!IofCallDriver+0x55
  104. fffff48e`8ef4f6b0 fffff800`0c1ff0a9 : ffff8682`460bd8c0 fffff800`0c1f8000 fffff800`0c1f8000 ffffd303`49591a20 : mup!MupiCallUncProvider+0xb8
  105. fffff48e`8ef4f720 fffff800`0c208601 : 00000000`00000000 ffffd303`480adde0 ffffd303`4ba32730 ffffd303`49591a20 : mup!MupStateMachine+0x59
  106. fffff48e`8ef4f750 fffff800`07ed21c5 : ffffd303`4ab43010 00000000`00000000 ffffd303`469cbbc0 fffff800`0ab25021 : mup!MupSetInformationFile+0x201
  107. fffff48e`8ef4f7b0 fffff800`0ab2710f : 00000000`00000008 00000000`00000000 ffffd303`4ba32780 00000000`00000208 : nt!IofCallDriver+0x55
  108. fffff48e`8ef4f7f0 fffff800`0ab24a43 : fffff48e`8ef4f880 00000000`00000001 ffffd303`4815a340 fffff800`085b418e : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x28f
  109. fffff48e`8ef4f860 fffff800`07ed21c5 : ffffd303`49591bc8 fffff800`07ed23a2 00000000`00000001 fffff800`0823e30e : FLTMGR!FltpDispatch+0xa3
  110. fffff48e`8ef4f8c0 fffff800`07e2b740 : ffffd303`4ba32780 ffffd303`49591a20 00000000`0000000d ffffd303`4ba32730 : nt!IofCallDriver+0x55
  111. fffff48e`8ef4f900 fffff800`07ed35ce : fffff48e`8ef4fb80 ffffd303`49591bc8 ffffd303`49591a20 00000000`00000000 : nt!IopCallDriverReference+0xd0
  112. fffff48e`8ef4f970 fffff800`08011505 : 00000000`00000188 00000007`ffffc530 00000007`ffffc513 00000000`00000001 : nt!NtSetInformationFile+0xbae
  113. fffff48e`8ef4fa90 00007ffb`6080da84 : 00007ffb`3489a432 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x25
  114. 00000007`ffffc478 00007ffb`3489a432 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!NtSetInformationFile+0x14
  115. 00000007`ffffc480 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`0000000d : cygwin1!strtosigno+0x36ea
  116.  
  117.  
  118. FAULTING_SOURCE_LINE:  C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_updowncall.c
  119.  
  120. FAULTING_SOURCE_FILE:  C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_updowncall.c
  121.  
  122. FAULTING_SOURCE_LINE_NUMBER:  427
  123.  
  124. FAULTING_SOURCE_CODE:  
  125.    423:         entry->psec_ctx_clienttoken = entry->psec_ctx->ClientToken;
  126.    424:         ObReferenceObject(entry->psec_ctx_clienttoken);
  127.    425:     }
  128.    426:
  129. >  427:     if (entry) {
  130.    428:         /* Clear fields used for memory mappings */
  131.    429:         switch(entry->opcode) {
  132.    430:             case NFS41_SYSOP_WRITE:
  133.    431:             case NFS41_SYSOP_READ:
  134.    432:                 entry->u.ReadWrite.buf = NULL;
  135.  
  136.  
  137. SYMBOL_NAME:  nfs41_driver!nfs41_UpcallCreate+268
  138.  
  139. MODULE_NAME: nfs41_driver
  140.  
  141. IMAGE_NAME:  nfs41_driver.sys
  142.  
  143. STACK_COMMAND:  .thread ; .cxr ; kb
  144.  
  145. BUCKET_ID_FUNC_OFFSET:  268
  146.  
  147. FAILURE_BUCKET_ID:  AV_INVALID_nfs41_driver!nfs41_UpcallCreate
  148.  
  149. OS_VERSION:  10.0.19041.1
  150.  
  151. BUILDLAB_STR:  vb_release
  152.  
  153. OSPLATFORM_TYPE:  x64
  154.  
  155. OSNAME:  Windows 10
  156.  
  157. FAILURE_ID_HASH:  {1e84f035-5ad6-3548-679b-109c80208655}
  158.  
  159. Followup:     MachineOwner
  160. ---------
  161.  
  162. 3: kd>

Submit a correction or amendment below (click here to make a fresh posting)
After submitting an amendment, you'll be able to view the differences between the old and new posts easily.

Syntax highlighting:

To highlight particular lines, prefix each line with {%HIGHLIGHT}




All content is user-submitted.
The administrators of this site (kpaste.net) are not responsible for their content.
Abuse reports should be emailed to us at