Article ID: 167666
Article Last Modified on 9/22/2005
------------------------------------------------------------------
Application exception occurred:
App: exe\tn3servr.DBG
Exception number: c0000005 (access violation)
<data omitted>
Function: RtlDestroyHeap
<data omitted>
FAULT -> 77f7ebf f3ab rep stosd es:00194000=??????
*----> Stack Back Trace <----*
FramePtr Function Name
<data omitted> ntdll!RtlDestroyHeap
ntdll!RtlAllocateHeap
kernel32!LocalAlloc
tn3servr!TnAlloc
tn3servr!SMG_CB_Allocate
tn3servr!SMGScheduleSessionInitialization
tn3servr!TCPSessionTerminate
-----------------------------------------------------------------
However, when attached with the NTSD or CDB debugger, the failure may
actually occur in the following function:
Function: RtlpFindAndCommitPages
Stack Back Trace - Function Names
ntdll!RtlpFindAndCommitPages+0xde
ntdll!RtlpExtendHeap+0x52
ntdll!RtlAllocateHeapSlowly+0x894
ntdll!RtlAllocateHeap+0x67a
kernel32!LocalAlloc+0x71
tn3servr!TnAlloc+0xd
tn3servr!SMG_CB_Allocate+0xb
tn3servr!SMGScheduleSessionInitiali
tn3servr!TCPSessionTerminate+0x23d
tn3servr!TCPThreadMain+0x1d7
tn3servr!TnMain+0x79
kernel32!BaseThreadStart+0x51
Default RU Sizes:
Inbound: 2048 (Default is 1024)
Outbound: 4096 (Default is 2048)
>04/10 11:09:42.751 (+260 msecs) Event=TEV_DataFromSNAAsync
Thread = 0x000000A5 Session = 0x001F7ED8 Socket = 0x00000390
VCB address=0x001F80AC
verb_length=0x0044 verb=0x0052 (RUI) opcode=0x8003 (READ)
sid=0x00020003 correlator=0x001F7ED8 post_handle=0x000003A4
prim_rc=LUA_OK sec_rc=LUA_SEC_RC_OK
lu_exp lua_data_length=0x00000023
lua_message_type=0x31 (LUA_MESSAGE_TYPE_BIND)
TH Only efi=1 oadi=0 daf=FD oaf=01 snf=9E05
RH REQ SC fi=1 sdi=0 bci=1 eci=1 (Only)
6B 80 00 dr1=1 dr2=0 ri=0 qri=0 pi=0
bbi=0 ebi=0 cdi=0 csi=0 edi=0 pdi=0
000000 31010303 b1903080 00018889 80000280 *..........hi....*
000010 00000000 00000000 03000006 c2c3c3d7 *............BCCP*
000020 f4f800 *48. *
The BIND command data appears in the data portion of the above message,
starting at 0x31 (the BIND command, which is byte 0 of the BIND). The
maximum secondary and primary RU sizes appear at offset 10 and 11 (starting
at 0 origin) in the above trace:
M * (2**N)
0x87 = 1024
0x88 = 2048
0x89 = 4096
S E R V P A C K
Keywords: kbbug kbfix kbqfe kbnetwork kbhotfixserver KB167666