MULTIPLE_IRP_COMPLETE_REQUESTS (44)
A driver has requested that an IRP be completed (IoCompleteRequest()), but
the packet has already been completed. This is a tough bug to find because
the easiest case, a driver actually attempted to complete its own packet
twice, is generally not what happened. Rather, two separate drivers each
believe that they own the packet, and each attempts to complete it. The
first actually works, and the second fails. Tracking down which drivers
in the system actually did this is difficult, generally because the trails
of the first driver have been covered by the second. However, the driver
stack for the current request can be found by examining the DeviceObject
fields in each of the stack locations.
Arguments:
Arg1: ffffcc81b3e13b2e, Address of the IRP
Arg2: 000000000000121b
Arg3: 0000000000000000
Arg4: 0000000000000000
Debugging Details:
------------------
KEY_VALUES_STRING: 1
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 17134.1.amd64fre.rs4_release.180410-1804
DUMP_TYPE: 2
BUGCHECK_P1: ffffcc81b3e13b2e
BUGCHECK_P2: 121b
BUGCHECK_P3: 0
BUGCHECK_P4: 0
IRP_ADDRESS: ffffcc81b3e13b2e
FOLLOWUP_IP:
Npfs!NpFsdRead+272
fffff807`74ccda22 488d442450 lea rax,[rsp+50h]
CPU_COUNT: 4
CPU_MHZ: a22
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3a
CPU_STEPPING: 9
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: WIN8_DRIVER_FAULT
BUGCHECK_STR: 0x44
PROCESS_NAME: Adobe CEF Helper.exe
CURRENT_IRQL: 0
ANALYSIS_SESSION_HOST: DESKTOP-NG9H4F5
ANALYSIS_SESSION_TIME: 04-08-2019 20:51:05.0026
ANALYSIS_VERSION: 10.0.18317.1001 amd64fre
LAST_CONTROL_TRANSFER: from fffff802abff2bc1 to fffff802abfb60a0
STACK_TEXT:
fffffb0d`335235f8 fffff802`abff2bc1 : 00000000`00000044 ffffcc81`b3e13b2e 00000000`0000121b 00000000`00000000 : nt!KeBugCheckEx
fffffb0d`33523600 fffff802`abea75f7 : 00000000`00000000 ffffcc81`b82e6702 00000000`00000000 ffff8187`240745b8 : nt!IopfCompleteRequest+0x14b5b1
fffffb0d`33523720 fffff807`74ccda22 : 00000000`00000000 ffff8187`00000000 00000000`00000000 ffffcc81`b6a99d00 : nt!IofCompleteRequest+0x17
fffffb0d`33523750 fffff802`abea4e69 : ffffcc81`b550e730 00000000`00003330 00000000`0762cea0 ffffcc81`b82e6770 : Npfs!NpFsdRead+0x272
fffffb0d`33523800 fffff807`71cd51f2 : 00000000`00000000 ffffcc81`b46a3580 00000000`00000003 fffff802`abe67bd1 : nt!IofCallDriver+0x59
fffffb0d`33523840 fffff802`abea4e69 : ffffcc81`b82e6770 fffff802`ac307902 ffffcc81`00000001 fffff802`abea9501 : FLTMGR!FltpDispatch+0xe2
fffffb0d`335238a0 fffff802`ac308f9b : ffffcc81`b82e6770 00000000`00000000 ffffcc81`b82e6770 00000000`05fcebb8 : nt!IofCallDriver+0x59
fffffb0d`335238e0 fffff802`ac31fe52 : fffffb0d`00000000 ffffcc81`b6a99d80 00000000`060cf9c4 fffffb0d`33523b80 : nt!IopSynchronousServiceTail+0x1ab
fffffb0d`33523990 fffff802`abfc6743 : ffffcc81`b6bfd700 00000000`00000000 00000000`00000001 00000000`03d4d338 : nt!NtReadFile+0x692
fffffb0d`33523a90 00000000`77a81e4c : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x13
00000000`05fceb98 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : 0x77a81e4c
THREAD_SHA1_HASH_MOD_FUNC: cd24469ef18462b08651a36720300f381aefedd5
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 1081509641559f5e362d02794005f5865a510c58
THREAD_SHA1_HASH_MOD: 1fb12fd56247692a33c96061968e15ab0a162256
FAULT_INSTR_CODE: 24448d48
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: Npfs!NpFsdRead+272
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: Npfs
IMAGE_NAME: Npfs.SYS
DEBUG_FLR_IMAGE_TIMESTAMP: 0
IMAGE_VERSION: 10.0.17134.648
STACK_COMMAND: .thread ; .cxr ; kb
BUCKET_ID_FUNC_OFFSET: 272
FAILURE_BUCKET_ID: 0x44_Npfs!NpFsdRead
BUCKET_ID: 0x44_Npfs!NpFsdRead
PRIMARY_PROBLEM_CLASS: 0x44_Npfs!NpFsdRead
TARGET_TIME: 2019-04-08T17:06:54.000Z
OSBUILD: 17134
OSSERVICEPACK: 648
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2019-03-06 11:32:15
BUILDDATESTAMP_STR: 180410-1804
BUILDLAB_STR: rs4_release
BUILDOSVER_STR: 10.0.17134.1.amd64fre.rs4_release.180410-1804
ANALYSIS_SESSION_ELAPSED_TIME: f4d0
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:0x44_npfs!npfsdread
FAILURE_ID_HASH: {83c16d25-d942-8827-cb9a-ca6dbb843515}
Followup: MachineOwner
---------
3: kd> lmvm Npfs
start end module name
fffff807`74cc0000 fffff807`74cdb000 Npfs (pdb symbols) C:\ProgramData\Dbg\sym\npfs.pdb\B5CEC1D5B2B061D905BFC968F6DF104E1\npfs.pdb
Loaded symbol image file: Npfs.SYS
Mapped memory image file: C:\ProgramData\Dbg\sym\Npfs.SYS\F8E8282C1b000\Npfs.SYS
Image path: \SystemRoot\System32\Drivers\Npfs.SYS
Image name: Npfs.SYS
Image was built with /Brepro flag.
Timestamp: F8E8282C (This is a reproducible build file hash, not a timestamp)
CheckSum: 000211DF
ImageSize: 0001B000
File version: 10.0.17134.648
Product version: 10.0.17134.648
File flags: 0 (Mask 3F)
File OS: 40004 NT Win32
File type: 3.7 Driver
File date: 00000000.00000000
Translations: 0409.04b0
Information from resource tables:
CompanyName: Microsoft Corporation
ProductName: Microsoft® Windows® Operating System
InternalName: npfs.sys
OriginalFilename: npfs.sys
ProductVersion: 10.0.17134.648
FileVersion: 10.0.17134.648 (WinBuild.160101.0800)
FileDescription: NPFS Driver
LegalCopyright: © Microsoft Corporation. All rights reserved.
SYSTEM_THREAD_EXCEPTION_NOT_HANDLED_M (1000007e)
This is a very common bugcheck. Usually the exception address pinpoints
the driver/function that caused the problem. Always note this address
as well as the link date of the driver/image that contains this address.
Some common problems are exception code 0x80000003. This means a hard
coded breakpoint or assertion was hit, but this system was booted
/NODEBUG. This is not supposed to happen as developers should never have
hardcoded breakpoints in retail code, but ...
If this happens, make sure a debugger gets connected, and the
system is booted /DEBUG. This will let us see why this breakpoint is
happening.
Arguments:
Arg1: ffffffffc0000005, The exception code that was not handled
Arg2: fffff80256eb873e, The address that the exception occurred at
Arg3: ffffa380f16998e8, Exception Record Address
Arg4: ffffa380f1699130, Context Record Address
Debugging Details:
------------------
*** WARNING: Unable to verify timestamp for win32k.sys
KEY_VALUES_STRING: 1
Key : AV.Dereference
Value: NullPtr
Key : AV.Fault
Value: Read
PROCESSES_ANALYSIS: 1
SERVICE_ANALYSIS: 1
STACKHASH_ANALYSIS: 1
TIMELINE_ANALYSIS: 1
DUMP_CLASS: 1
DUMP_QUALIFIER: 400
BUILD_VERSION_STRING: 17134.1.amd64fre.rs4_release.180410-1804
DUMP_TYPE: 2
BUGCHECK_P1: ffffffffc0000005
BUGCHECK_P2: fffff80256eb873e
BUGCHECK_P3: ffffa380f16998e8
BUGCHECK_P4: ffffa380f1699130
EXCEPTION_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
FAULTING_IP:
nt!SMKM_STORE_MGR<SM_TRAITS>::SmCompressCtxProcessEntry+42
fffff802`56eb873e 410f1002 movups xmm0,xmmword ptr [r10]
EXCEPTION_RECORD: ffffa380f16998e8 -- (.exr 0xffffa380f16998e8)
ExceptionAddress: fffff80256eb873e (nt!SMKM_STORE_MGR<SM_TRAITS>::SmCompressCtxProcessEntry+0x0000000000000042)
ExceptionCode: c0000005 (Access violation)
ExceptionFlags: 00000000
NumberParameters: 2
Parameter[0]: 0000000000000000
Parameter[1]: 0000000000000000
Attempt to read from address 0000000000000000
CONTEXT: ffffa380f1699130 -- (.cxr 0xffffa380f1699130)
rax=ffffe70974774f4f rbx=ffffe709793d0028 rcx=0000000000000080
rdx=fffff8025730d9c0 rsi=ffffe7097477c987 rdi=fffff8025730deb0
rip=fffff80256eb873e rsp=ffffa380f1699b20 rbp=0000000000000000
r8=ffffe70974766028 r9=0000000000000020 r10=0000000000000000
r11=ffffe70974774f4f r12=fffff8025730d9c0 r13=ffffe709747defd7
r14=ffffe709793d0000 r15=fffff8025730deb0
iopl=0 nv up ei ng nz na pe nc
cs=0010 ss=0018 ds=002b es=002b fs=0053 gs=002b efl=00010282
nt!SMKM_STORE_MGR<SM_TRAITS>::SmCompressCtxProcessEntry+0x42:
fffff802`56eb873e 410f1002 movups xmm0,xmmword ptr [r10] ds:002b:00000000`00000000=????????????????????????????????
Resetting default scope
CPU_COUNT: 4
CPU_MHZ: a22
CPU_VENDOR: GenuineIntel
CPU_FAMILY: 6
CPU_MODEL: 3a
CPU_STEPPING: 9
CUSTOMER_CRASH_COUNT: 1
DEFAULT_BUCKET_ID: NULL_DEREFERENCE
PROCESS_NAME: MemCompression
CURRENT_IRQL: 0
FOLLOWUP_IP:
nt!SMKM_STORE_MGR<SM_TRAITS>::SmCompressCtxProcessEntry+42
fffff802`56eb873e 410f1002 movups xmm0,xmmword ptr [r10]
BUGCHECK_STR: AV
READ_ADDRESS: fffff802572f4388: Unable to get MiVisibleState
Unable to get NonPagedPoolStart
Unable to get NonPagedPoolEnd
Unable to get PagedPoolStart
Unable to get PagedPoolEnd
0000000000000000
ERROR_CODE: (NTSTATUS) 0xc0000005 - <Unable to get error code text>
EXCEPTION_CODE_STR: c0000005
EXCEPTION_PARAMETER1: 0000000000000000
EXCEPTION_PARAMETER2: 0000000000000000
ANALYSIS_SESSION_HOST: DESKTOP-NG9H4F5
ANALYSIS_SESSION_TIME: 04-08-2019 20:51:02.0664
ANALYSIS_VERSION: 10.0.18317.1001 amd64fre
LAST_CONTROL_TRANSFER: from fffff80256ebaf47 to fffff80256eb873e
STACK_TEXT:
ffffa380`f1699b20 fffff802`56ebaf47 : ffffe709`793cd028 ffffe709`793d0028 ffffa380`f1699be0 fffff802`5730de00 : nt!SMKM_STORE_MGR<SM_TRAITS>::SmCompressCtxProcessEntry+0x42
ffffa380`f1699b90 fffff802`56fd72d7 : ffffffff`fd050f80 ffffe709`7344e080 fffff802`56ebadf0 00000000`000273c8 : nt!SMKM_STORE_MGR<SM_TRAITS>::SmCompressCtxWorkerThread+0x157
ffffa380`f1699c10 fffff802`57058516 : ffffbc80`f278b180 ffffe709`7344e080 fffff802`56fd7290 00000000`00027ac8 : nt!PspSystemThreadStartup+0x47
ffffa380`f1699c60 00000000`00000000 : ffffa380`f169a000 ffffa380`f1694000 00000000`00000000 00000000`00000000 : nt!KiStartSystemThread+0x16
THREAD_SHA1_HASH_MOD_FUNC: 8a5bb278c59853aafd0e2c012c5df8ee105fdfad
THREAD_SHA1_HASH_MOD_FUNC_OFFSET: 241208a5246b2efad95bb7102af0d9a677ad0618
THREAD_SHA1_HASH_MOD: d084f7dfa548ce4e51810e4fd5914176ebc66791
FAULT_INSTR_CODE: 2100f41
SYMBOL_STACK_INDEX: 0
SYMBOL_NAME: nt!SMKM_STORE_MGR<SM_TRAITS>::SmCompressCtxProcessEntry+42
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: nt
IMAGE_NAME: ntkrnlmp.exe
DEBUG_FLR_IMAGE_TIMESTAMP: 5c7f858f
IMAGE_VERSION: 10.0.17134.648
STACK_COMMAND: .cxr 0xffffa380f1699130 ; kb
BUCKET_ID_FUNC_OFFSET: 42
FAILURE_BUCKET_ID: AV_nt!SMKM_STORE_MGR_SM_TRAITS_::SmCompressCtxProcessEntry
BUCKET_ID: AV_nt!SMKM_STORE_MGR_SM_TRAITS_::SmCompressCtxProcessEntry
PRIMARY_PROBLEM_CLASS: AV_nt!SMKM_STORE_MGR_SM_TRAITS_::SmCompressCtxProcessEntry
TARGET_TIME: 2019-04-08T17:21:42.000Z
OSBUILD: 17134
OSSERVICEPACK: 648
SERVICEPACK_NUMBER: 0
OS_REVISION: 0
SUITE_MASK: 272
PRODUCT_TYPE: 1
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
OSEDITION: Windows 10 WinNt TerminalServer SingleUserTS
OS_LOCALE:
USER_LCID: 0
OSBUILD_TIMESTAMP: 2019-03-06 11:32:15
BUILDDATESTAMP_STR: 180410-1804
BUILDLAB_STR: rs4_release
BUILDOSVER_STR: 10.0.17134.1.amd64fre.rs4_release.180410-1804
ANALYSIS_SESSION_ELAPSED_TIME: 7fae
ANALYSIS_SOURCE: KM
FAILURE_ID_HASH_STRING: km:av_nt!smkm_store_mgr_sm_traits_::smcompressctxprocessentry
FAILURE_ID_HASH: {2c9addae-1766-cbb9-1df5-8002dbc115c2}
Followup: MachineOwner
---------