- ************* Preparing the environment for Debugger Extensions Gallery repositories **************
- ExtensionRepository : Implicit
- UseExperimentalFeatureForNugetShare : true
- AllowNugetExeUpdate : true
- NonInteractiveNuget : true
- AllowNugetMSCredentialProviderInstall : true
- AllowParallelInitializationOfLocalRepositories : true
- EnableRedirectToV8JsProvider : false
- -- Configuring repositories
- ----> Repository : LocalInstalled, Enabled: true
- ----> Repository : UserExtensions, Enabled: true
- >>>>>>>>>>>>> Preparing the environment for Debugger Extensions Gallery repositories completed, duration 0.015 seconds
- ************* Waiting for Debugger Extensions Gallery to Initialize **************
- >>>>>>>>>>>>> Waiting for Debugger Extensions Gallery to Initialize completed, duration 0.406 seconds
- ----> Repository : UserExtensions, Enabled: true, Packages count: 0
- ----> Repository : LocalInstalled, Enabled: true, Packages count: 41
- Microsoft (R) Windows Debugger Version 10.0.27553.1004 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [C:\Windows\MEMORY.DMP]
- Kernel Bitmap Dump File: Kernel address space is available, User address space may not be available.
- ************* Path validation summary **************
- Response Time (ms) Location
- Deferred srv*
- Symbol search path is: srv*
- Executable search path is:
- Windows 10 Kernel Version 19041 MP (8 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Edition build lab: 19041.1.amd64fre.vb_release.191206-1406
- Kernel base = 0xfffff803`35c00000 PsLoadedModuleList = 0xfffff803`3682a2c0
- Debug session time: Wed May 8 08:35:05.612 2024 (UTC + 2:00)
- System Uptime: 0 days 14:44:35.538
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ................................................................
- ......
- Loading User Symbols
- Loading unloaded module list
- .......
- For analysis of this file, run !analyze -v
- nt!KeBugCheckEx:
- fffff803`35ffdaf0 48894c2408 mov qword ptr [rsp+8],rcx ss:0018:fffffe8a`4cca7a70=0000000000000018
- 2: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- REFERENCE_BY_POINTER (18)
- Arguments:
- Arg1: 0000000000000000, Object type of the object whose reference count is being lowered
- Arg2: ffffad0e479e9710, Object whose reference count is being lowered
- Arg3: 0000000000000010, Reserved
- Arg4: ffffdb838684a669, Reserved
- The reference count of an object is illegal for the current state of the object.
- Each time a driver uses a pointer to an object the driver calls a kernel routine
- to increment the reference count of the object. When the driver is done with the
- pointer the driver calls another kernel routine to decrement the reference count.
- Drivers must match calls to the increment and decrement routines. This BugCheck
- can occur because an object's reference count goes to zero while there are still
- open handles to the object, in which case the fourth parameter indicates the number
- of opened handles. It may also occur when the object's reference count drops below zero
- whether or not there are open handles to the object, and in that case the fourth parameter
- contains the actual value of the pointer references count.
- Debugging Details:
- ------------------
- KEY_VALUES_STRING: 1
- Key : Analysis.CPU.mSec
- Value: 4592
- Key : Analysis.Elapsed.mSec
- Value: 4687
- Key : Analysis.IO.Other.Mb
- Value: 0
- Key : Analysis.IO.Read.Mb
- Value: 2
- Key : Analysis.IO.Write.Mb
- Value: 1
- Key : Analysis.Init.CPU.mSec
- Value: 1108
- Key : Analysis.Init.Elapsed.mSec
- Value: 14525
- Key : Analysis.Memory.CommitPeak.Mb
- Value: 98
- Key : Bugcheck.Code.KiBugCheckData
- Value: 0x18
- Key : Bugcheck.Code.LegacyAPI
- Value: 0x18
- Key : Bugcheck.Code.TargetModel
- Value: 0x18
- Key : Failure.Bucket
- Value: 0x18_nfs41_driver!nfs41_UpcallCreate
- Key : Failure.Hash
- Value: {13fc455a-d437-8a05-650f-dce234632809}
- Key : Hypervisor.Enlightenments.Value
- Value: 12576
- Key : Hypervisor.Enlightenments.ValueHex
- Value: 3120
- Key : Hypervisor.Flags.AnyHypervisorPresent
- Value: 1
- Key : Hypervisor.Flags.ApicEnlightened
- Value: 0
- Key : Hypervisor.Flags.ApicVirtualizationAvailable
- Value: 0
- Key : Hypervisor.Flags.AsyncMemoryHint
- Value: 0
- Key : Hypervisor.Flags.CoreSchedulerRequested
- Value: 0
- Key : Hypervisor.Flags.CpuManager
- Value: 0
- Key : Hypervisor.Flags.DeprecateAutoEoi
- Value: 1
- Key : Hypervisor.Flags.DynamicCpuDisabled
- Value: 0
- Key : Hypervisor.Flags.Epf
- Value: 0
- Key : Hypervisor.Flags.ExtendedProcessorMasks
- Value: 0
- Key : Hypervisor.Flags.HardwareMbecAvailable
- Value: 0
- Key : Hypervisor.Flags.MaxBankNumber
- Value: 0
- Key : Hypervisor.Flags.MemoryZeroingControl
- Value: 0
- Key : Hypervisor.Flags.NoExtendedRangeFlush
- Value: 1
- Key : Hypervisor.Flags.NoNonArchCoreSharing
- Value: 0
- Key : Hypervisor.Flags.Phase0InitDone
- Value: 1
- Key : Hypervisor.Flags.PowerSchedulerQos
- Value: 0
- Key : Hypervisor.Flags.RootScheduler
- Value: 0
- Key : Hypervisor.Flags.SynicAvailable
- Value: 1
- Key : Hypervisor.Flags.UseQpcBias
- Value: 0
- Key : Hypervisor.Flags.Value
- Value: 536632
- Key : Hypervisor.Flags.ValueHex
- Value: 83038
- Key : Hypervisor.Flags.VpAssistPage
- Value: 1
- Key : Hypervisor.Flags.VsmAvailable
- Value: 0
- Key : Hypervisor.RootFlags.AccessStats
- Value: 0
- Key : Hypervisor.RootFlags.CrashdumpEnlightened
- Value: 0
- Key : Hypervisor.RootFlags.CreateVirtualProcessor
- Value: 0
- Key : Hypervisor.RootFlags.DisableHyperthreading
- Value: 0
- Key : Hypervisor.RootFlags.HostTimelineSync
- Value: 0
- Key : Hypervisor.RootFlags.HypervisorDebuggingEnabled
- Value: 0
- Key : Hypervisor.RootFlags.IsHyperV
- Value: 0
- Key : Hypervisor.RootFlags.LivedumpEnlightened
- Value: 0
- Key : Hypervisor.RootFlags.MapDeviceInterrupt
- Value: 0
- Key : Hypervisor.RootFlags.MceEnlightened
- Value: 0
- Key : Hypervisor.RootFlags.Nested
- Value: 0
- Key : Hypervisor.RootFlags.StartLogicalProcessor
- Value: 0
- Key : Hypervisor.RootFlags.Value
- Value: 0
- Key : Hypervisor.RootFlags.ValueHex
- Value: 0
- Key : SecureKernel.HalpHvciEnabled
- Value: 0
- Key : WER.OS.Branch
- Value: vb_release
- Key : WER.OS.Version
- Value: 10.0.19041.1
- BUGCHECK_CODE: 18
- BUGCHECK_P1: 0
- BUGCHECK_P2: ffffad0e479e9710
- BUGCHECK_P3: 10
- BUGCHECK_P4: ffffdb838684a669
- FILE_IN_CAB: MEMORY.DMP
- BLACKBOXBSD: 1 (!blackboxbsd)
- BLACKBOXNTFS: 1 (!blackboxntfs)
- BLACKBOXWINLOGON: 1
- PROCESS_NAME: System
- STACK_TEXT:
- fffffe8a`4cca7a68 fffff803`3601e05b : 00000000`00000018 00000000`00000000 ffffad0e`479e9710 00000000`00000010 : nt!KeBugCheckEx
- fffffe8a`4cca7a70 fffff803`3b4b0d49 : ffffdb83`80e7c080 fffff803`3b4a6260 fffff803`3b4a6260 fffff803`00000000 : nt!ObfReferenceObject+0x1e08eb
- fffffe8a`4cca7ab0 fffff803`3b4a63e3 : fffff803`00000009 ffffad0e`47969eb0 00000182`772981c0 00000182`77f1bea0 : nfs41_driver!nfs41_UpcallCreate+0x279 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41_driver.c @ 1586]
- fffffe8a`4cca7b30 fffff803`35f4eb35 : 00000000`00000000 fffff803`3b4a6260 00000000`00000000 00078404`ad9b3dfe : nfs41_driver!fcbopen_main+0x183 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41_driver.c @ 7185]
- fffffe8a`4cca7c10 fffff803`36006af8 : ffffc501`06d18180 ffffdb83`80e7c080 fffff803`35f4eae0 d28b49d3`034c0000 : nt!PspSystemThreadStartup+0x55
- fffffe8a`4cca7c60 00000000`00000000 : fffffe8a`4cca8000 fffffe8a`4cca2000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x28
- FAULTING_SOURCE_LINE: C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41_driver.c
- FAULTING_SOURCE_FILE: C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41_driver.c
- FAULTING_SOURCE_LINE_NUMBER: 1586
- FAULTING_SOURCE_CODE:
- 1582: entry->psec_ctx_clienttoken = entry->psec_ctx->ClientToken;
- 1583: ObReferenceObject(entry->psec_ctx_clienttoken);
- 1584: }
- 1585:
- > 1586: *entry_out = entry;
- 1587: out:
- 1588: return status;
- 1589: }
- 1590:
- 1591: void nfs41_UpcallDestroy(nfs41_updowncall_entry *entry)
- SYMBOL_NAME: nfs41_driver!nfs41_UpcallCreate+279
- MODULE_NAME: nfs41_driver
- IMAGE_NAME: nfs41_driver.sys
- STACK_COMMAND: .cxr; .ecxr ; kb
- BUCKET_ID_FUNC_OFFSET: 279
- FAILURE_BUCKET_ID: 0x18_nfs41_driver!nfs41_UpcallCreate
- OS_VERSION: 10.0.19041.1
- BUILDLAB_STR: vb_release
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- FAILURE_ID_HASH: {13fc455a-d437-8a05-650f-dce234632809}
- Followup: MachineOwner
- ---------
- 2: kd> .frame 0x2
- 02 fffffe8a`4cca7ab0 fffff803`3b4a63e3 nfs41_driver!nfs41_UpcallCreate+0x279 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41_driver.c @ 1586]
- 2: kd> dt -r entry
- Local var @ 0xfffffe8a4cca7ad0 Type _updowncall_entry*
- 0xffffdb83`863439a0
- +0x000 version : 0x19b9f
- +0x008 xid : 0n396706234
- +0x010 opcode : 9 ( NFS41_FILE_QUERY )
- +0x014 status : 0n0
- +0x018 state : 0 ( NFS41_WAITING_FOR_UPCALL )
- +0x020 lock : _FAST_MUTEX
- +0x000 Count : 0n1
- +0x008 Owner : (null)
- +0x010 Contention : 0
- +0x018 Event : _KEVENT
- +0x000 Header : _DISPATCHER_HEADER
- +0x030 OldIrql : 0
- +0x058 next : _LIST_ENTRY [ 0x00000000`00000000 - 0x00000000`00000000 ]
- +0x000 Flink : (null)
- +0x008 Blink : (null)
- +0x068 cond : _KEVENT
- +0x000 Header : _DISPATCHER_HEADER
- +0x000 Lock : 0n393217
- +0x000 LockNV : 0n393217
- +0x000 Type : 0x1 ''
- +0x001 Signalling : 0 ''
- +0x002 Size : 0x6 ''
- +0x003 Reserved1 : 0 ''
- +0x000 TimerType : 0x1 ''
- +0x001 TimerControlFlags : 0 ''
- +0x001 Absolute : 0y0
- +0x001 Wake : 0y0
- +0x001 EncodedTolerableDelay : 0y000000 (0)
- +0x002 Hand : 0x6 ''
- +0x003 TimerMiscFlags : 0 ''
- +0x003 Index : 0y000000 (0)
- +0x003 Inserted : 0y0
- +0x003 Expired : 0y0
- +0x000 Timer2Type : 0x1 ''
- +0x001 Timer2Flags : 0 ''
- +0x001 Timer2Inserted : 0y0
- +0x001 Timer2Expiring : 0y0
- +0x001 Timer2CancelPending : 0y0
- +0x001 Timer2SetPending : 0y0
- +0x001 Timer2Running : 0y0
- +0x001 Timer2Disabled : 0y0
- +0x001 Timer2ReservedFlags : 0y00
- +0x002 Timer2ComponentId : 0x6 ''
- +0x003 Timer2RelativeId : 0 ''
- +0x000 QueueType : 0x1 ''
- +0x001 QueueControlFlags : 0 ''
- +0x001 Abandoned : 0y0
- +0x001 DisableIncrement : 0y0
- +0x001 QueueReservedControlFlags : 0y000000 (0)
- +0x002 QueueSize : 0x6 ''
- +0x003 QueueReserved : 0 ''
- +0x000 ThreadType : 0x1 ''
- +0x001 ThreadReserved : 0 ''
- +0x002 ThreadControlFlags : 0x6 ''
- +0x002 CycleProfiling : 0y0
- +0x002 CounterProfiling : 0y1
- +0x002 GroupScheduling : 0y1
- +0x002 AffinitySet : 0y0
- +0x002 Tagged : 0y0
- +0x002 EnergyProfiling : 0y0
- +0x002 SchedulerAssist : 0y0
- +0x002 ThreadReservedControlFlags : 0y0
- +0x003 DebugActive : 0 ''
- +0x003 ActiveDR7 : 0y0
- +0x003 Instrumented : 0y0
- +0x003 Minimal : 0y0
- +0x003 Reserved4 : 0y00
- +0x003 AltSyscall : 0y0
- +0x003 UmsScheduled : 0y0
- +0x003 UmsPrimary : 0y0
- +0x000 MutantType : 0x1 ''
- +0x001 MutantSize : 0 ''
- +0x002 DpcActive : 0x6 ''
- +0x003 MutantReserved : 0 ''
- +0x004 SignalState : 0n0
- +0x008 WaitListHead : _LIST_ENTRY [ 0xffffdb83`86343a10 - 0xffffdb83`86343a10 ]
- +0x080 errno : 0
- +0x084 async_op : 0 ''
- +0x088 sec_ctx : _SECURITY_CLIENT_CONTEXT
- +0x000 SecurityQos : _SECURITY_QUALITY_OF_SERVICE
- +0x000 Length : 0
- +0x004 ImpersonationLevel : 0 ( SecurityAnonymous )
- +0x008 ContextTrackingMode : 0 ''
- +0x009 EffectiveOnly : 0 ''
- +0x010 ClientToken : (null)
- +0x018 DirectlyAccessClientToken : 0 ''
- +0x019 DirectAccessEffectiveOnly : 0 ''
- +0x01a ServerIsRemote : 0 ''
- +0x01c ClientTokenControl : _TOKEN_CONTROL
- +0x000 TokenId : _LUID
- +0x008 AuthenticationId : _LUID
- +0x010 ModifiedId : _LUID
- +0x018 TokenSource : _TOKEN_SOURCE
- +0x0d0 psec_ctx : 0xffffad0e`47969eb0 _SECURITY_CLIENT_CONTEXT
- +0x000 SecurityQos : _SECURITY_QUALITY_OF_SERVICE
- +0x000 Length : 0xc
- +0x004 ImpersonationLevel : 2 ( SecurityImpersonation )
- +0x008 ContextTrackingMode : 0 ''
- +0x009 EffectiveOnly : 0 ''
- +0x010 ClientToken : 0xffffad0e`479e9710 Void
- +0x018 DirectlyAccessClientToken : 0 ''
- +0x019 DirectAccessEffectiveOnly : 0 ''
- +0x01a ServerIsRemote : 0x1 ''
- +0x01c ClientTokenControl : _TOKEN_CONTROL
- +0x000 TokenId : _LUID
- +0x008 AuthenticationId : _LUID
- +0x010 ModifiedId : _LUID
- +0x018 TokenSource : _TOKEN_SOURCE
- +0x0d8 psec_ctx_clienttoken : 0xffffad0e`479e9710 Void
- +0x0e0 open_state : 0x00000182`77f1bea0 Void
- +0x0e8 session : 0x00000182`772981c0 Void
- +0x0f0 filename : 0xfffff803`3b4bedf8 _UNICODE_STRING ""
- +0x000 Length : 0
- +0x002 MaximumLength : 2
- +0x008 Buffer : 0xfffff803`3b4bed94 ""
- +0x0f8 buf : (null)
- +0x100 buf_len : 0
- +0x108 ChangeTime : 0
- +0x110 u : <unnamed-tag>
- +0x000 Mount : <unnamed-tag>
- +0x000 srv_name : (null)
- +0x008 root : (null)
- +0x010 FsAttrs : (null)
- +0x018 sec_flavor : 0
- +0x01c rsize : 0
- +0x020 wsize : 0
- +0x024 lease_time : 0
- +0x000 ReadWrite : <unnamed-tag>
- +0x000 MdlAddress : (null)
- +0x008 offset : 0
- +0x010 rxcontext : (null)
- +0x000 Lock : <unnamed-tag>
- +0x000 offset : 0n0
- +0x008 length : 0n0
- +0x010 exclusive : 0 ''
- +0x011 blocking : 0 ''
- +0x000 Unlock : <unnamed-tag>
- +0x000 count : 0
- +0x008 locks : _LOWIO_LOCK_LIST
- +0x000 Open : <unnamed-tag>
- +0x000 binfo : _FILE_BASIC_INFORMATION
- +0x028 sinfo : _FILE_STANDARD_INFORMATION
- +0x040 symlink : _UNICODE_STRING ""
- +0x050 access_mask : 0
- +0x054 access_mode : 0
- +0x058 attrs : 0
- +0x05c copts : 0
- +0x060 disp : 0
- +0x064 cattrs : 0
- +0x068 open_owner_id : 0n0
- +0x06c mode : 0
- +0x070 owner_local_uid : 0
- +0x074 owner_group_local_gid : 0
- +0x078 srv_open : (null)
- +0x080 deleg_type : 0
- +0x084 symlink_embedded : 0 ''
- +0x088 EaMdl : (null)
- +0x090 EaBuffer : (null)
- +0x000 Close : <unnamed-tag>
- +0x000 srv_open : (null)
- +0x008 remove : 0 ''
- +0x009 renamed : 0 ''
- +0x000 QueryFile : <unnamed-tag>
- +0x000 filter : (null)
- +0x008 InfoClass : 0 (No matching name)
- +0x00c restart_scan : 0 ''
- +0x00d return_single : 0 ''
- +0x00e initial_query : 0 ''
- +0x010 mdl : (null)
- +0x018 mdl_buf : (null)
- +0x000 SetFile : <unnamed-tag>
- +0x000 InfoClass : 0 (No matching name)
- +0x000 SetEa : <unnamed-tag>
- +0x000 mode : 0
- +0x000 QueryEa : <unnamed-tag>
- +0x000 EaList : (null)
- +0x008 EaListLength : 0
- +0x00c Overflow : 0
- +0x010 EaIndex : 0
- +0x014 ReturnSingleEntry : 0 ''
- +0x015 RestartScan : 0 ''
- +0x000 Symlink : <unnamed-tag>
- +0x000 target : (null)
- +0x008 set : 0 ''
- +0x000 Volume : <unnamed-tag>
- +0x000 query : 0 (No matching name)
- +0x000 Acl : <unnamed-tag>
- +0x000 query : 0
Crash in nfs41_UpcallCreate()
Posted by Anonymous on Wed 8th May 2024 07:44
raw | new post
modification of post by Anonymous (view diff)
Submit a correction or amendment below (click here to make a fresh posting)
After submitting an amendment, you'll be able to view the differences between the old and new posts easily.