- Microsoft (R) Windows Debugger Version 10.0.19041.685 AMD64
- Copyright (c) Microsoft Corporation. All rights reserved.
- Loading Dump File [C:\Windows\MEMORY.DMP]
- Kernel Bitmap Dump File: Full address space is available
- Symbol search path is: srv*
- Executable search path is:
- Page 200006ae6 too large to be in the dump file.
- Page 200002d34 too large to be in the dump file.
- Page 200002d34 too large to be in the dump file.
- Windows 10 Kernel Version 19041 MP (8 procs) Free x64
- Product: WinNt, suite: TerminalServer SingleUserTS
- Built by: 19041.1.amd64fre.vb_release.191206-1406
- Machine Name:
- Kernel base = 0xfffff800`31412000 PsLoadedModuleList = 0xfffff800`3203c760
- Debug session time: Sat May 10 12:47:51.874 2025 (UTC + 2:00)
- System Uptime: 0 days 0:04:31.858
- Loading Kernel Symbols
- ...............................................................
- ................................................................
- ................................................................
- ......................
- Loading User Symbols
- ..................
- Loading unloaded module list
- .............
- For analysis of this file, run !analyze -v
- 2: kd> !analyze -v
- *******************************************************************************
- * *
- * Bugcheck Analysis *
- * *
- *******************************************************************************
- DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
- A device driver attempting to corrupt the system has been caught. This is
- because the driver was specified in the registry as being suspect (by the
- administrator) and the kernel has enabled substantial checking of this driver.
- If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
- be among the most commonly seen crashes.
- Arguments:
- Arg1: 00000000000000b9, MmUnmapLockedPages called with a bad user space address.
- Arg2: 000001ffd7440d00, Address being unmapped.
- Arg3: ffffe68dc2f46f40, MDL address.
- Arg4: 0000000000000000, Reserved (unused).
- Debugging Details:
- ------------------
- KEY_VALUES_STRING: 1
- Key : Analysis.CPU.Sec
- Value: 5
- Key : Analysis.DebugAnalysisProvider.CPP
- Value: Create: 8007007e on WINGRENDEL02
- Key : Analysis.DebugData
- Value: CreateObject
- Key : Analysis.DebugModel
- Value: CreateObject
- Key : Analysis.Elapsed.Sec
- Value: 7
- Key : Analysis.Memory.CommitPeak.Mb
- Value: 77
- Key : Analysis.System
- Value: CreateObject
- BUGCHECK_CODE: c4
- BUGCHECK_P1: b9
- BUGCHECK_P2: 1ffd7440d00
- BUGCHECK_P3: ffffe68dc2f46f40
- BUGCHECK_P4: 0
- BLACKBOXBSD: 1 (!blackboxbsd)
- BLACKBOXNTFS: 1 (!blackboxntfs)
- BLACKBOXWINLOGON: 1
- PROCESS_NAME: git.exe
- STACK_TEXT:
- ffffe58f`88a04f18 fffff800`31de3e44 : 00000000`000000c4 00000000`000000b9 000001ff`d7440d00 ffffe68d`c2f46f40 : nt!KeBugCheckEx
- ffffe58f`88a04f20 fffff800`31dfa343 : ffffe68d`c2f46f40 ffffe68d`b9eaed80 00000000`00011cff 000001ff`d7440d00 : nt!VerifierBugCheckIfAppropriate+0xe0
- ffffe58f`88a04f60 fffff803`022d8a9f : ffffe68d`c2feaa80 fffff803`022efee0 00000000`00000007 ffff8000`00000000 : nt!VerifierMmUnmapLockedPages+0x173
- ffffe58f`88a04fd0 fffff803`022d5bd3 : ffffe68d`c2d40e30 ffff9d05`0000005a 000001ff`d6c34000 000001ff`d724c170 : nfs41_driver!nfs41_UpcallDestroy+0x9f [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_updowncall.c @ 445]
- ffffe58f`88a05030 fffff803`022f9844 : ffffe68d`c2feaa80 ffffe68d`b9eaed80 ffffe68d`c2feaa80 00000000`00000000 : nfs41_driver!nfs41_Read+0x3d3 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_readwrite.c @ 329]
- ffffe58f`88a050f0 fffff803`02308cd9 : ffff9d05`1b216a40 00000000`00000000 ffffe68d`b9eaed80 fffff800`31de4fe0 : nfs41_driver!RxLowIoSubmit+0x2d4 [base\fs\rdr2\rxce\lowio.c @ 805]
- ffffe58f`88a05150 fffff803`02308a50 : ffffe68d`c2feaa80 00000000`00000024 00000000`00000001 00000000`00000001 : nfs41_driver!RxLowIoReadShell+0x99 [base\fs\rdr2\rdbss\read.c @ 1341]
- ffffe58f`88a051a0 fffff803`022df0b2 : ffffe68d`c2feaa80 ffffe68d`b9eaed80 ffffe68d`bc599000 00000000`00000000 : nfs41_driver!RxCommonRead+0xcd0 [base\fs\rdr2\rdbss\read.c @ 949]
- ffffe58f`88a052f0 fffff803`022fc96d : fffff803`022ef160 00000000`00000000 00000000`00000000 ffffe68d`bc599090 : nfs41_driver!RxFsdCommonDispatch+0x442 [base\fs\rdr2\rdbss\ntfsd.c @ 848]
- ffffe58f`88a053f0 fffff803`022c8907 : ffffe68d`b9eaed80 ffffe68d`b9eaeee0 00000000`00400000 ffffe68d`b9ce7c01 : nfs41_driver!RxFsdDispatch+0xfd [base\fs\rdr2\rdbss\ntfsd.c @ 442]
- ffffe58f`88a05420 fffff800`317819c7 : ffffe68d`bc599090 ffffe68d`b9eaed80 ffffe68d`00000000 ffffe68d`00000000 : nfs41_driver!nfs41_FsdDispatch+0x67 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_driver.c @ 981]
- ffffe58f`88a05460 fffff800`31dd7f2a : ffffe68d`b9eaed80 ffffe68d`bc599090 ffffe68d`c3540590 fffff800`3343192f : nt!IopfCallDriver+0x53
- ffffe58f`88a054a0 fffff800`3183839b : ffffe68d`c2b658b0 ffffe68d`b9eaed80 ffffe68d`c1051730 ffffe68d`c3892910 : nt!IovCallDriver+0x266
- ffffe58f`88a054e0 fffff800`33fdf243 : fffff800`33fd8000 00000000`00000000 ffffe68d`b9b3ca70 ffffe68d`b9cfb138 : nt!IofCallDriver+0x20730b
- ffffe58f`88a05520 fffff800`33fded99 : ffff9d05`1b335d80 00000000`00000000 fffff800`33fd8000 00000000`00000000 : mup!MupiCallUncProvider+0xb3
- ffffe58f`88a05590 fffff800`33fdecce : ffffe68d`b9eaed80 ffffe68d`b9cfb130 ffffe68d`c3540590 00000000`00000000 : mup!MupStateMachine+0x59
- ffffe58f`88a055c0 fffff800`317819c7 : 00000000`00000000 00000000`00000000 ffffe68d`c2b658b0 ffffe68d`00000000 : mup!MupFsdIrpPassThrough+0x17e
- ffffe58f`88a05630 fffff800`31dd7f2a : ffffe68d`b9eaed80 ffffe68d`b9b3ca70 ffffe58f`88a05700 00000000`00000003 : nt!IopfCallDriver+0x53
- ffffe58f`88a05670 fffff800`3183839b : ffffe68d`c386fa20 00000000`00000000 00000000`00000000 ffffe68d`c38a0950 : nt!IovCallDriver+0x266
- ffffe58f`88a056b0 fffff800`3272710a : 00000000`00000006 00000000`00000000 ffffe68d`b9eaed80 ffffe68d`c3475570 : nt!IofCallDriver+0x20730b
- ffffe58f`88a056f0 fffff800`32724a43 : ffffe58f`88a05780 ffffe68d`b9ce7cc0 00000000`00000000 00000000`00000000 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x28a
- ffffe58f`88a05760 fffff800`317819c7 : ffffe68d`b9eaed80 fffff800`31de41be ffffe68d`00000001 ffffe68d`00000000 : FLTMGR!FltpDispatch+0xa3
- ffffe58f`88a057c0 fffff800`31dd7f2a : ffffe68d`b9eaed80 ffffe68d`b9ce7cc0 ffffe68d`b9eaed80 fffff800`31df4a6f : nt!IopfCallDriver+0x53
- ffffe58f`88a05800 fffff800`3183839b : 00000000`00000000 ffffe68d`c3540590 00000000`00000000 ffffe68d`c389a490 : nt!IovCallDriver+0x266
- ffffe58f`88a05840 fffff800`31a18ad1 : 00000000`00000000 00000000`00000000 ffffe68d`c3540590 fffff800`31dd78c1 : nt!IofCallDriver+0x20730b
- ffffe58f`88a05880 fffff800`319e1ae4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopSynchronousServiceTail+0x361
- ffffe58f`88a05920 fffff800`31a15ae6 : ffffe68d`c3540590 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopReadFile+0x7cc
- ffffe58f`88a05a10 fffff800`31823e05 : ffffe68d`c1051080 ffffe58f`88a05b80 00000007`ffffb648 00007ff9`00000008 : nt!NtReadFile+0xa6
- ffffe58f`88a05a90 00007ff9`57c8d5b4 : 00007ff9`2ab7617c 00000007`ffffbaf8 00007ff9`2ab9002f 00000007`00000000 : nt!KiSystemServiceCopyEnd+0x25
- 00000007`ffffb628 00007ff9`2ab7617c : 00000007`ffffbaf8 00007ff9`2ab9002f 00000007`00000000 00000000`00000001 : ntdll!NtReadFile+0x14
- 00000007`ffffb630 00007ff9`2ab7589c : 0000000a`00001348 00000007`ffffce00 00000007`ffffb828 00000000`00000024 : cygwin1!cuserid+0x14be1
- 00000007`ffffb6d0 00007ff9`2ab4c7bd : 00000000`00000005 00000000`00000005 00000000`00000000 00000008`0000f980 : cygwin1!cuserid+0x14301
- 00000007`ffffb750 00007ff9`2ac65f73 : 0000000a`00000005 0000000a`00012d00 00000000`00010000 00000000`00000000 : cygwin1!getppid+0x43f
- 00000007`ffffb7e0 0000000a`00000005 : 0000000a`00012d00 00000000`00010000 00000000`00000000 00007ff9`2ab20c4a : cygwin1!localeconv+0x1363
- 00000007`ffffb7e8 0000000a`00012d00 : 00000000`00010000 00000000`00000000 00007ff9`2ab20c4a 0000000a`00001348 : 0x0000000a`00000005
- 00000007`ffffb7f0 00000000`00010000 : 00000000`00000000 00007ff9`2ab20c4a 0000000a`00001348 00000007`ffffce00 : 0x0000000a`00012d00
- 00000007`ffffb7f8 00000000`00000000 : 00007ff9`2ab20c4a 0000000a`00001348 00000007`ffffce00 00007ff9`2ac56021 : 0x10000
- FAULTING_SOURCE_LINE: C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_updowncall.c
- FAULTING_SOURCE_FILE: C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_updowncall.c
- FAULTING_SOURCE_LINE_NUMBER: 445
- SYMBOL_NAME: nfs41_driver!nfs41_UpcallDestroy+9f
- MODULE_NAME: nfs41_driver
- IMAGE_NAME: nfs41_driver.sys
- STACK_COMMAND: .thread ; .cxr ; kb
- BUCKET_ID_FUNC_OFFSET: 9f
- FAILURE_BUCKET_ID: 0xc4_b9_VRF_nfs41_driver!nfs41_UpcallDestroy
- OS_VERSION: 10.0.19041.1
- BUILDLAB_STR: vb_release
- OSPLATFORM_TYPE: x64
- OSNAME: Windows 10
- FAILURE_ID_HASH: {34d4b5fc-edc9-67e4-e4a9-2e4a154cdaa8}
- Followup: MachineOwner
- ---------
- 2: kd> kp
- # Child-SP RetAddr Call Site
- 00 ffffe58f`88a04f18 fffff800`31de3e44 nt!KeBugCheckEx
- 01 ffffe58f`88a04f20 fffff800`31dfa343 nt!VerifierBugCheckIfAppropriate+0xe0
- 02 ffffe58f`88a04f60 fffff803`022d8a9f nt!VerifierMmUnmapLockedPages+0x173
- 03 ffffe58f`88a04fd0 fffff803`022d5bd3 nfs41_driver!nfs41_UpcallDestroy(struct _updowncall_entry * entry = 0xffffe68d`c2d40e30)+0x9f [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_updowncall.c @ 445]
- 04 ffffe58f`88a05030 fffff803`022f9844 nfs41_driver!nfs41_Read(struct _RX_CONTEXT * RxContext = 0xffffe68d`c2feaa80)+0x3d3 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_readwrite.c @ 329]
- 05 ffffe58f`88a050f0 fffff803`02308cd9 nfs41_driver!RxLowIoSubmit(struct _RX_CONTEXT * RxContext = 0xffffe68d`c2feaa80, struct _IRP * Irp = 0xffffe68d`b9eaed80, struct _FCB * Fcb = 0xffff9d05`1b216a40, <function> * CompletionRoutine = 0xffffe68d`c2f46f40)+0x2d4 [base\fs\rdr2\rxce\lowio.c @ 805]
- 06 ffffe58f`88a05150 fffff803`02308a50 nfs41_driver!RxLowIoReadShell(struct _RX_CONTEXT * RxContext = 0xffffe68d`c2feaa80, struct _IRP * Irp = 0xffffe68d`b9eaed80, struct _FCB * Fcb = 0xffff9d05`1b216a40)+0x99 [base\fs\rdr2\rdbss\read.c @ 1341]
- 07 ffffe58f`88a051a0 fffff803`022df0b2 nfs41_driver!RxCommonRead(struct _RX_CONTEXT * RxContext = 0xffffe68d`c2feaa80, struct _IRP * Irp = 0xffffe68d`b9eaed80)+0xcd0 [base\fs\rdr2\rdbss\read.c @ 949]
- 08 ffffe58f`88a052f0 fffff803`022fc96d nfs41_driver!RxFsdCommonDispatch(struct _RX_FSD_DISPATCH_VECTOR * DispatchVector = 0xfffff803`022ef160, struct _IRP * Irp = 0xffffe68d`b9eaed80, struct _FILE_OBJECT * FileObject = 0x00000000`00000000, struct _RDBSS_DEVICE_OBJECT * RxDeviceObject = 0xffffe68d`bc599090)+0x442 [base\fs\rdr2\rdbss\ntfsd.c @ 848]
- 09 ffffe58f`88a053f0 fffff803`022c8907 nfs41_driver!RxFsdDispatch(struct _RDBSS_DEVICE_OBJECT * RxDeviceObject = <Value unavailable error>, struct _IRP * Irp = <Value unavailable error>)+0xfd [base\fs\rdr2\rdbss\ntfsd.c @ 442]
- 0a ffffe58f`88a05420 fffff800`317819c7 nfs41_driver!nfs41_FsdDispatch(struct _DEVICE_OBJECT * dev = 0xffffe68d`bc599090 Device for "\FileSystem\nfs41_driver", struct _IRP * Irp = 0xffffe68d`b9eaed80)+0x67 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_driver.c @ 981]
- 0b ffffe58f`88a05460 fffff800`31dd7f2a nt!IopfCallDriver+0x53
- 0c ffffe58f`88a054a0 fffff800`3183839b nt!IovCallDriver+0x266
- 0d ffffe58f`88a054e0 fffff800`33fdf243 nt!IofCallDriver+0x20730b
- 0e ffffe58f`88a05520 fffff800`33fded99 mup!MupiCallUncProvider+0xb3
- 0f ffffe58f`88a05590 fffff800`33fdecce mup!MupStateMachine+0x59
- 10 ffffe58f`88a055c0 fffff800`317819c7 mup!MupFsdIrpPassThrough+0x17e
- 11 ffffe58f`88a05630 fffff800`31dd7f2a nt!IopfCallDriver+0x53
- 12 ffffe58f`88a05670 fffff800`3183839b nt!IovCallDriver+0x266
- 13 ffffe58f`88a056b0 fffff800`3272710a nt!IofCallDriver+0x20730b
- 14 ffffe58f`88a056f0 fffff800`32724a43 FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x28a
- 15 ffffe58f`88a05760 fffff800`317819c7 FLTMGR!FltpDispatch+0xa3
- 16 ffffe58f`88a057c0 fffff800`31dd7f2a nt!IopfCallDriver+0x53
- 17 ffffe58f`88a05800 fffff800`3183839b nt!IovCallDriver+0x266
- 18 ffffe58f`88a05840 fffff800`31a18ad1 nt!IofCallDriver+0x20730b
- 19 ffffe58f`88a05880 fffff800`319e1ae4 nt!IopSynchronousServiceTail+0x361
- 1a ffffe58f`88a05920 fffff800`31a15ae6 nt!IopReadFile+0x7cc
- 1b ffffe58f`88a05a10 fffff800`31823e05 nt!NtReadFile+0xa6
- 1c ffffe58f`88a05a90 00007ff9`57c8d5b4 nt!KiSystemServiceCopyEnd+0x25
- 1d 00000007`ffffb628 00007ff9`2ab7617c ntdll!NtReadFile+0x14
- 1e 00000007`ffffb630 00007ff9`2ab7589c cygwin1!cuserid+0x14be1
- 1f 00000007`ffffb6d0 00007ff9`2ab4c7bd cygwin1!cuserid+0x14301
- 20 00000007`ffffb750 00007ff9`2ac65f73 cygwin1!getppid+0x43f
- 21 00000007`ffffb7e0 0000000a`00000005 cygwin1!localeconv+0x1363
- 22 00000007`ffffb7e8 0000000a`00012d00 0x0000000a`00000005
- 23 00000007`ffffb7f0 00000000`00010000 0x0000000a`00012d00
- 24 00000007`ffffb7f8 00000000`00000000 0x10000
- 2: kd> dx -r1 ((nfs41_driver!_updowncall_entry *)0xffffe68dc2d40e30)
- ((nfs41_driver!_updowncall_entry *)0xffffe68dc2d40e30) : 0xffffe68dc2d40e30 [Type: _updowncall_entry *]
- [+0x000] version : 0x23d9b [Type: unsigned long]
- [+0x008] xid : 1557 [Type: __int64]
- [+0x010] opcode : NFS41_SYSOP_READ (5) [Type: _nfs41_opcodes]
- [+0x014] status : 38 [Type: long]
- [+0x018] state : NFS41_DONE_PROCESSING (2) [Type: _nfs41_updowncall_state]
- [+0x020] lock [Type: _FAST_MUTEX]
- [+0x058] next [Type: _LIST_ENTRY]
- [+0x068] cond [Type: _KEVENT]
- [+0x080] errno : 0x0 [Type: unsigned long]
- [+0x084] async_op : 0x0 [Type: unsigned char]
- [+0x088] sec_ctx [Type: _SECURITY_CLIENT_CONTEXT]
- [+0x0d0] psec_ctx : 0xffff9d051b220f90 [Type: _SECURITY_CLIENT_CONTEXT *]
- [+0x0d8] psec_ctx_clienttoken : 0xffff9d05248b07f0 [Type: void *]
- [+0x0e0] open_state : 0x1ffd724c170 [Type: void *]
- [+0x0e8] session : 0x1ffd6c34000 [Type: void *]
- [+0x0f0] filename : 0xffff9d051b216b60 : "\bigdisk\builds\bash_build1\bash\.git\config" [Type: _UNICODE_STRING *]
- [+0x0f8] buf : 0x1ffd7440d00 [Type: void *]
- [+0x100] buf_len : 0x10000 [Type: unsigned long]
- [+0x108] ChangeTime : 0x0 [Type: unsigned __int64]
- [+0x110] u [Type: <unnamed-tag>]
- 2: kd> dx -r1 (*((nfs41_driver!_updowncall_entry *)0xffffe68dc2d40e30)).u
- (*((nfs41_driver!_updowncall_entry *)0xffffe68dc2d40e30)).u [Type: <unnamed-tag>]
- [+0x000] Mount [Type: <unnamed-tag>]
- [+0x000] ReadWrite [Type: <unnamed-tag>]
- [+0x000] Lock [Type: <unnamed-tag>]
- [+0x000] Unlock [Type: <unnamed-tag>]
- [+0x000] Open [Type: <unnamed-tag>]
- [+0x000] Close [Type: <unnamed-tag>]
- [+0x000] QueryFile [Type: <unnamed-tag>]
- [+0x000] SetFile [Type: <unnamed-tag>]
- [+0x000] SetEa [Type: <unnamed-tag>]
- [+0x000] QueryEa [Type: <unnamed-tag>]
- [+0x000] Symlink [Type: <unnamed-tag>]
- [+0x000] Volume [Type: <unnamed-tag>]
- [+0x000] Acl [Type: <unnamed-tag>]
- [+0x000] QueryAllocatedRanges [Type: <unnamed-tag>]
- [+0x000] SetZeroData [Type: <unnamed-tag>]
- [+0x000] DuplicateData [Type: <unnamed-tag>]
- 2: kd> dx -r1 (*((nfs41_driver!_updowncall_entry *)0xffffe68dc2d40e30)).u.ReadWrite
- (*((nfs41_driver!_updowncall_entry *)0xffffe68dc2d40e30)).u.ReadWrite [Type: <unnamed-tag>]
- [+0x000] MdlAddress : 0xffffe68dc2f46f40 [Type: _MDL *]
- [+0x008] offset : 0x24 [Type: unsigned __int64]
- [+0x010] rxcontext : 0x0 [Type: _RX_CONTEXT *]
VerifierMmUnmapLockedPages() crash when reading from file
Posted by Anonymous on Sat 10th May 2025 12:01
raw | new post
Submit a correction or amendment below (click here to make a fresh posting)
After submitting an amendment, you'll be able to view the differences between the old and new posts easily.