- Microsoft (R) Windows Debugger Version 10.0.19041.685 AMD64
 - Copyright (c) Microsoft Corporation. All rights reserved.
 - Loading Dump File [C:\Windows\MEMORY.DMP]
 - Kernel Bitmap Dump File: Full address space is available
 - Symbol search path is: srv*
 - Executable search path is:
 - Page 200006ae6 too large to be in the dump file.
 - Page 200002d34 too large to be in the dump file.
 - Page 200002d34 too large to be in the dump file.
 - Windows 10 Kernel Version 19041 MP (8 procs) Free x64
 - Product: WinNt, suite: TerminalServer SingleUserTS
 - Built by: 19041.1.amd64fre.vb_release.191206-1406
 - Machine Name:
 - Kernel base = 0xfffff800`31412000 PsLoadedModuleList = 0xfffff800`3203c760
 - Debug session time: Sat May 10 12:47:51.874 2025 (UTC + 2:00)
 - System Uptime: 0 days 0:04:31.858
 - Loading Kernel Symbols
 - ...............................................................
 - ................................................................
 - ................................................................
 - ......................
 - Loading User Symbols
 - ..................
 - Loading unloaded module list
 - .............
 - For analysis of this file, run !analyze -v
 - 2: kd> !analyze -v
 - *******************************************************************************
 - * *
 - * Bugcheck Analysis *
 - * *
 - *******************************************************************************
 - DRIVER_VERIFIER_DETECTED_VIOLATION (c4)
 - A device driver attempting to corrupt the system has been caught. This is
 - because the driver was specified in the registry as being suspect (by the
 - administrator) and the kernel has enabled substantial checking of this driver.
 - If the driver attempts to corrupt the system, bugchecks 0xC4, 0xC1 and 0xA will
 - be among the most commonly seen crashes.
 - Arguments:
 - Arg1: 00000000000000b9, MmUnmapLockedPages called with a bad user space address.
 - Arg2: 000001ffd7440d00, Address being unmapped.
 - Arg3: ffffe68dc2f46f40, MDL address.
 - Arg4: 0000000000000000, Reserved (unused).
 - Debugging Details:
 - ------------------
 - KEY_VALUES_STRING: 1
 - Key : Analysis.CPU.Sec
 - Value: 5
 - Key : Analysis.DebugAnalysisProvider.CPP
 - Value: Create: 8007007e on WINGRENDEL02
 - Key : Analysis.DebugData
 - Value: CreateObject
 - Key : Analysis.DebugModel
 - Value: CreateObject
 - Key : Analysis.Elapsed.Sec
 - Value: 7
 - Key : Analysis.Memory.CommitPeak.Mb
 - Value: 77
 - Key : Analysis.System
 - Value: CreateObject
 - BUGCHECK_CODE: c4
 - BUGCHECK_P1: b9
 - BUGCHECK_P2: 1ffd7440d00
 - BUGCHECK_P3: ffffe68dc2f46f40
 - BUGCHECK_P4: 0
 - BLACKBOXBSD: 1 (!blackboxbsd)
 - BLACKBOXNTFS: 1 (!blackboxntfs)
 - BLACKBOXWINLOGON: 1
 - PROCESS_NAME: git.exe
 - STACK_TEXT:
 - ffffe58f`88a04f18 fffff800`31de3e44 : 00000000`000000c4 00000000`000000b9 000001ff`d7440d00 ffffe68d`c2f46f40 : nt!KeBugCheckEx
 - ffffe58f`88a04f20 fffff800`31dfa343 : ffffe68d`c2f46f40 ffffe68d`b9eaed80 00000000`00011cff 000001ff`d7440d00 : nt!VerifierBugCheckIfAppropriate+0xe0
 - ffffe58f`88a04f60 fffff803`022d8a9f : ffffe68d`c2feaa80 fffff803`022efee0 00000000`00000007 ffff8000`00000000 : nt!VerifierMmUnmapLockedPages+0x173
 - ffffe58f`88a04fd0 fffff803`022d5bd3 : ffffe68d`c2d40e30 ffff9d05`0000005a 000001ff`d6c34000 000001ff`d724c170 : nfs41_driver!nfs41_UpcallDestroy+0x9f [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_updowncall.c @ 445]
 - ffffe58f`88a05030 fffff803`022f9844 : ffffe68d`c2feaa80 ffffe68d`b9eaed80 ffffe68d`c2feaa80 00000000`00000000 : nfs41_driver!nfs41_Read+0x3d3 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_readwrite.c @ 329]
 - ffffe58f`88a050f0 fffff803`02308cd9 : ffff9d05`1b216a40 00000000`00000000 ffffe68d`b9eaed80 fffff800`31de4fe0 : nfs41_driver!RxLowIoSubmit+0x2d4 [base\fs\rdr2\rxce\lowio.c @ 805]
 - ffffe58f`88a05150 fffff803`02308a50 : ffffe68d`c2feaa80 00000000`00000024 00000000`00000001 00000000`00000001 : nfs41_driver!RxLowIoReadShell+0x99 [base\fs\rdr2\rdbss\read.c @ 1341]
 - ffffe58f`88a051a0 fffff803`022df0b2 : ffffe68d`c2feaa80 ffffe68d`b9eaed80 ffffe68d`bc599000 00000000`00000000 : nfs41_driver!RxCommonRead+0xcd0 [base\fs\rdr2\rdbss\read.c @ 949]
 - ffffe58f`88a052f0 fffff803`022fc96d : fffff803`022ef160 00000000`00000000 00000000`00000000 ffffe68d`bc599090 : nfs41_driver!RxFsdCommonDispatch+0x442 [base\fs\rdr2\rdbss\ntfsd.c @ 848]
 - ffffe58f`88a053f0 fffff803`022c8907 : ffffe68d`b9eaed80 ffffe68d`b9eaeee0 00000000`00400000 ffffe68d`b9ce7c01 : nfs41_driver!RxFsdDispatch+0xfd [base\fs\rdr2\rdbss\ntfsd.c @ 442]
 - ffffe58f`88a05420 fffff800`317819c7 : ffffe68d`bc599090 ffffe68d`b9eaed80 ffffe68d`00000000 ffffe68d`00000000 : nfs41_driver!nfs41_FsdDispatch+0x67 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_driver.c @ 981]
 - ffffe58f`88a05460 fffff800`31dd7f2a : ffffe68d`b9eaed80 ffffe68d`bc599090 ffffe68d`c3540590 fffff800`3343192f : nt!IopfCallDriver+0x53
 - ffffe58f`88a054a0 fffff800`3183839b : ffffe68d`c2b658b0 ffffe68d`b9eaed80 ffffe68d`c1051730 ffffe68d`c3892910 : nt!IovCallDriver+0x266
 - ffffe58f`88a054e0 fffff800`33fdf243 : fffff800`33fd8000 00000000`00000000 ffffe68d`b9b3ca70 ffffe68d`b9cfb138 : nt!IofCallDriver+0x20730b
 - ffffe58f`88a05520 fffff800`33fded99 : ffff9d05`1b335d80 00000000`00000000 fffff800`33fd8000 00000000`00000000 : mup!MupiCallUncProvider+0xb3
 - ffffe58f`88a05590 fffff800`33fdecce : ffffe68d`b9eaed80 ffffe68d`b9cfb130 ffffe68d`c3540590 00000000`00000000 : mup!MupStateMachine+0x59
 - ffffe58f`88a055c0 fffff800`317819c7 : 00000000`00000000 00000000`00000000 ffffe68d`c2b658b0 ffffe68d`00000000 : mup!MupFsdIrpPassThrough+0x17e
 - ffffe58f`88a05630 fffff800`31dd7f2a : ffffe68d`b9eaed80 ffffe68d`b9b3ca70 ffffe58f`88a05700 00000000`00000003 : nt!IopfCallDriver+0x53
 - ffffe58f`88a05670 fffff800`3183839b : ffffe68d`c386fa20 00000000`00000000 00000000`00000000 ffffe68d`c38a0950 : nt!IovCallDriver+0x266
 - ffffe58f`88a056b0 fffff800`3272710a : 00000000`00000006 00000000`00000000 ffffe68d`b9eaed80 ffffe68d`c3475570 : nt!IofCallDriver+0x20730b
 - ffffe58f`88a056f0 fffff800`32724a43 : ffffe58f`88a05780 ffffe68d`b9ce7cc0 00000000`00000000 00000000`00000000 : FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x28a
 - ffffe58f`88a05760 fffff800`317819c7 : ffffe68d`b9eaed80 fffff800`31de41be ffffe68d`00000001 ffffe68d`00000000 : FLTMGR!FltpDispatch+0xa3
 - ffffe58f`88a057c0 fffff800`31dd7f2a : ffffe68d`b9eaed80 ffffe68d`b9ce7cc0 ffffe68d`b9eaed80 fffff800`31df4a6f : nt!IopfCallDriver+0x53
 - ffffe58f`88a05800 fffff800`3183839b : 00000000`00000000 ffffe68d`c3540590 00000000`00000000 ffffe68d`c389a490 : nt!IovCallDriver+0x266
 - ffffe58f`88a05840 fffff800`31a18ad1 : 00000000`00000000 00000000`00000000 ffffe68d`c3540590 fffff800`31dd78c1 : nt!IofCallDriver+0x20730b
 - ffffe58f`88a05880 fffff800`319e1ae4 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopSynchronousServiceTail+0x361
 - ffffe58f`88a05920 fffff800`31a15ae6 : ffffe68d`c3540590 00000000`00000000 00000000`00000000 00000000`00000000 : nt!IopReadFile+0x7cc
 - ffffe58f`88a05a10 fffff800`31823e05 : ffffe68d`c1051080 ffffe58f`88a05b80 00000007`ffffb648 00007ff9`00000008 : nt!NtReadFile+0xa6
 - ffffe58f`88a05a90 00007ff9`57c8d5b4 : 00007ff9`2ab7617c 00000007`ffffbaf8 00007ff9`2ab9002f 00000007`00000000 : nt!KiSystemServiceCopyEnd+0x25
 - 00000007`ffffb628 00007ff9`2ab7617c : 00000007`ffffbaf8 00007ff9`2ab9002f 00000007`00000000 00000000`00000001 : ntdll!NtReadFile+0x14
 - 00000007`ffffb630 00007ff9`2ab7589c : 0000000a`00001348 00000007`ffffce00 00000007`ffffb828 00000000`00000024 : cygwin1!cuserid+0x14be1
 - 00000007`ffffb6d0 00007ff9`2ab4c7bd : 00000000`00000005 00000000`00000005 00000000`00000000 00000008`0000f980 : cygwin1!cuserid+0x14301
 - 00000007`ffffb750 00007ff9`2ac65f73 : 0000000a`00000005 0000000a`00012d00 00000000`00010000 00000000`00000000 : cygwin1!getppid+0x43f
 - 00000007`ffffb7e0 0000000a`00000005 : 0000000a`00012d00 00000000`00010000 00000000`00000000 00007ff9`2ab20c4a : cygwin1!localeconv+0x1363
 - 00000007`ffffb7e8 0000000a`00012d00 : 00000000`00010000 00000000`00000000 00007ff9`2ab20c4a 0000000a`00001348 : 0x0000000a`00000005
 - 00000007`ffffb7f0 00000000`00010000 : 00000000`00000000 00007ff9`2ab20c4a 0000000a`00001348 00000007`ffffce00 : 0x0000000a`00012d00
 - 00000007`ffffb7f8 00000000`00000000 : 00007ff9`2ab20c4a 0000000a`00001348 00000007`ffffce00 00007ff9`2ac56021 : 0x10000
 - FAULTING_SOURCE_LINE: C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_updowncall.c
 - FAULTING_SOURCE_FILE: C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_updowncall.c
 - FAULTING_SOURCE_LINE_NUMBER: 445
 - SYMBOL_NAME: nfs41_driver!nfs41_UpcallDestroy+9f
 - MODULE_NAME: nfs41_driver
 - IMAGE_NAME: nfs41_driver.sys
 - STACK_COMMAND: .thread ; .cxr ; kb
 - BUCKET_ID_FUNC_OFFSET: 9f
 - FAILURE_BUCKET_ID: 0xc4_b9_VRF_nfs41_driver!nfs41_UpcallDestroy
 - OS_VERSION: 10.0.19041.1
 - BUILDLAB_STR: vb_release
 - OSPLATFORM_TYPE: x64
 - OSNAME: Windows 10
 - FAILURE_ID_HASH: {34d4b5fc-edc9-67e4-e4a9-2e4a154cdaa8}
 - Followup: MachineOwner
 - ---------
 - 2: kd> kp
 - # Child-SP RetAddr Call Site
 - 00 ffffe58f`88a04f18 fffff800`31de3e44 nt!KeBugCheckEx
 - 01 ffffe58f`88a04f20 fffff800`31dfa343 nt!VerifierBugCheckIfAppropriate+0xe0
 - 02 ffffe58f`88a04f60 fffff803`022d8a9f nt!VerifierMmUnmapLockedPages+0x173
 - 03 ffffe58f`88a04fd0 fffff803`022d5bd3 nfs41_driver!nfs41_UpcallDestroy(struct _updowncall_entry * entry = 0xffffe68d`c2d40e30)+0x9f [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_updowncall.c @ 445]
 - 04 ffffe58f`88a05030 fffff803`022f9844 nfs41_driver!nfs41_Read(struct _RX_CONTEXT * RxContext = 0xffffe68d`c2feaa80)+0x3d3 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_readwrite.c @ 329]
 - 05 ffffe58f`88a050f0 fffff803`02308cd9 nfs41_driver!RxLowIoSubmit(struct _RX_CONTEXT * RxContext = 0xffffe68d`c2feaa80, struct _IRP * Irp = 0xffffe68d`b9eaed80, struct _FCB * Fcb = 0xffff9d05`1b216a40, <function> * CompletionRoutine = 0xffffe68d`c2f46f40)+0x2d4 [base\fs\rdr2\rxce\lowio.c @ 805]
 - 06 ffffe58f`88a05150 fffff803`02308a50 nfs41_driver!RxLowIoReadShell(struct _RX_CONTEXT * RxContext = 0xffffe68d`c2feaa80, struct _IRP * Irp = 0xffffe68d`b9eaed80, struct _FCB * Fcb = 0xffff9d05`1b216a40)+0x99 [base\fs\rdr2\rdbss\read.c @ 1341]
 - 07 ffffe58f`88a051a0 fffff803`022df0b2 nfs41_driver!RxCommonRead(struct _RX_CONTEXT * RxContext = 0xffffe68d`c2feaa80, struct _IRP * Irp = 0xffffe68d`b9eaed80)+0xcd0 [base\fs\rdr2\rdbss\read.c @ 949]
 - 08 ffffe58f`88a052f0 fffff803`022fc96d nfs41_driver!RxFsdCommonDispatch(struct _RX_FSD_DISPATCH_VECTOR * DispatchVector = 0xfffff803`022ef160, struct _IRP * Irp = 0xffffe68d`b9eaed80, struct _FILE_OBJECT * FileObject = 0x00000000`00000000, struct _RDBSS_DEVICE_OBJECT * RxDeviceObject = 0xffffe68d`bc599090)+0x442 [base\fs\rdr2\rdbss\ntfsd.c @ 848]
 - 09 ffffe58f`88a053f0 fffff803`022c8907 nfs41_driver!RxFsdDispatch(struct _RDBSS_DEVICE_OBJECT * RxDeviceObject = <Value unavailable error>, struct _IRP * Irp = <Value unavailable error>)+0xfd [base\fs\rdr2\rdbss\ntfsd.c @ 442]
 - 0a ffffe58f`88a05420 fffff800`317819c7 nfs41_driver!nfs41_FsdDispatch(struct _DEVICE_OBJECT * dev = 0xffffe68d`bc599090 Device for "\FileSystem\nfs41_driver", struct _IRP * Irp = 0xffffe68d`b9eaed80)+0x67 [C:\cygwin64\home\roland_mainz\work\msnfs41_uidmapping\ms-nfs41-client\sys\nfs41sys_driver.c @ 981]
 - 0b ffffe58f`88a05460 fffff800`31dd7f2a nt!IopfCallDriver+0x53
 - 0c ffffe58f`88a054a0 fffff800`3183839b nt!IovCallDriver+0x266
 - 0d ffffe58f`88a054e0 fffff800`33fdf243 nt!IofCallDriver+0x20730b
 - 0e ffffe58f`88a05520 fffff800`33fded99 mup!MupiCallUncProvider+0xb3
 - 0f ffffe58f`88a05590 fffff800`33fdecce mup!MupStateMachine+0x59
 - 10 ffffe58f`88a055c0 fffff800`317819c7 mup!MupFsdIrpPassThrough+0x17e
 - 11 ffffe58f`88a05630 fffff800`31dd7f2a nt!IopfCallDriver+0x53
 - 12 ffffe58f`88a05670 fffff800`3183839b nt!IovCallDriver+0x266
 - 13 ffffe58f`88a056b0 fffff800`3272710a nt!IofCallDriver+0x20730b
 - 14 ffffe58f`88a056f0 fffff800`32724a43 FLTMGR!FltpLegacyProcessingAfterPreCallbacksCompleted+0x28a
 - 15 ffffe58f`88a05760 fffff800`317819c7 FLTMGR!FltpDispatch+0xa3
 - 16 ffffe58f`88a057c0 fffff800`31dd7f2a nt!IopfCallDriver+0x53
 - 17 ffffe58f`88a05800 fffff800`3183839b nt!IovCallDriver+0x266
 - 18 ffffe58f`88a05840 fffff800`31a18ad1 nt!IofCallDriver+0x20730b
 - 19 ffffe58f`88a05880 fffff800`319e1ae4 nt!IopSynchronousServiceTail+0x361
 - 1a ffffe58f`88a05920 fffff800`31a15ae6 nt!IopReadFile+0x7cc
 - 1b ffffe58f`88a05a10 fffff800`31823e05 nt!NtReadFile+0xa6
 - 1c ffffe58f`88a05a90 00007ff9`57c8d5b4 nt!KiSystemServiceCopyEnd+0x25
 - 1d 00000007`ffffb628 00007ff9`2ab7617c ntdll!NtReadFile+0x14
 - 1e 00000007`ffffb630 00007ff9`2ab7589c cygwin1!cuserid+0x14be1
 - 1f 00000007`ffffb6d0 00007ff9`2ab4c7bd cygwin1!cuserid+0x14301
 - 20 00000007`ffffb750 00007ff9`2ac65f73 cygwin1!getppid+0x43f
 - 21 00000007`ffffb7e0 0000000a`00000005 cygwin1!localeconv+0x1363
 - 22 00000007`ffffb7e8 0000000a`00012d00 0x0000000a`00000005
 - 23 00000007`ffffb7f0 00000000`00010000 0x0000000a`00012d00
 - 24 00000007`ffffb7f8 00000000`00000000 0x10000
 - 2: kd> dx -r1 ((nfs41_driver!_updowncall_entry *)0xffffe68dc2d40e30)
 - ((nfs41_driver!_updowncall_entry *)0xffffe68dc2d40e30) : 0xffffe68dc2d40e30 [Type: _updowncall_entry *]
 - [+0x000] version : 0x23d9b [Type: unsigned long]
 - [+0x008] xid : 1557 [Type: __int64]
 - [+0x010] opcode : NFS41_SYSOP_READ (5) [Type: _nfs41_opcodes]
 - [+0x014] status : 38 [Type: long]
 - [+0x018] state : NFS41_DONE_PROCESSING (2) [Type: _nfs41_updowncall_state]
 - [+0x020] lock [Type: _FAST_MUTEX]
 - [+0x058] next [Type: _LIST_ENTRY]
 - [+0x068] cond [Type: _KEVENT]
 - [+0x080] errno : 0x0 [Type: unsigned long]
 - [+0x084] async_op : 0x0 [Type: unsigned char]
 - [+0x088] sec_ctx [Type: _SECURITY_CLIENT_CONTEXT]
 - [+0x0d0] psec_ctx : 0xffff9d051b220f90 [Type: _SECURITY_CLIENT_CONTEXT *]
 - [+0x0d8] psec_ctx_clienttoken : 0xffff9d05248b07f0 [Type: void *]
 - [+0x0e0] open_state : 0x1ffd724c170 [Type: void *]
 - [+0x0e8] session : 0x1ffd6c34000 [Type: void *]
 - [+0x0f0] filename : 0xffff9d051b216b60 : "\bigdisk\builds\bash_build1\bash\.git\config" [Type: _UNICODE_STRING *]
 - [+0x0f8] buf : 0x1ffd7440d00 [Type: void *]
 - [+0x100] buf_len : 0x10000 [Type: unsigned long]
 - [+0x108] ChangeTime : 0x0 [Type: unsigned __int64]
 - [+0x110] u [Type: <unnamed-tag>]
 - 2: kd> dx -r1 (*((nfs41_driver!_updowncall_entry *)0xffffe68dc2d40e30)).u
 - (*((nfs41_driver!_updowncall_entry *)0xffffe68dc2d40e30)).u [Type: <unnamed-tag>]
 - [+0x000] Mount [Type: <unnamed-tag>]
 - [+0x000] ReadWrite [Type: <unnamed-tag>]
 - [+0x000] Lock [Type: <unnamed-tag>]
 - [+0x000] Unlock [Type: <unnamed-tag>]
 - [+0x000] Open [Type: <unnamed-tag>]
 - [+0x000] Close [Type: <unnamed-tag>]
 - [+0x000] QueryFile [Type: <unnamed-tag>]
 - [+0x000] SetFile [Type: <unnamed-tag>]
 - [+0x000] SetEa [Type: <unnamed-tag>]
 - [+0x000] QueryEa [Type: <unnamed-tag>]
 - [+0x000] Symlink [Type: <unnamed-tag>]
 - [+0x000] Volume [Type: <unnamed-tag>]
 - [+0x000] Acl [Type: <unnamed-tag>]
 - [+0x000] QueryAllocatedRanges [Type: <unnamed-tag>]
 - [+0x000] SetZeroData [Type: <unnamed-tag>]
 - [+0x000] DuplicateData [Type: <unnamed-tag>]
 - 2: kd> dx -r1 (*((nfs41_driver!_updowncall_entry *)0xffffe68dc2d40e30)).u.ReadWrite
 - (*((nfs41_driver!_updowncall_entry *)0xffffe68dc2d40e30)).u.ReadWrite [Type: <unnamed-tag>]
 - [+0x000] MdlAddress : 0xffffe68dc2f46f40 [Type: _MDL *]
 - [+0x008] offset : 0x24 [Type: unsigned __int64]
 - [+0x010] rxcontext : 0x0 [Type: _RX_CONTEXT *]
 
VerifierMmUnmapLockedPages() crash when reading from file
Posted by Anonymous on Sat 10th May 2025 12:01
raw | new post
Submit a correction or amendment below (click here to make a fresh posting)
After submitting an amendment, you'll be able to view the differences between the old and new posts easily.
 nrubsig.kpaste.net RSS