Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Frequent unwanted debugger breakins in kernel mode

48 views
Skip to first unread message

Sergey Levi

unread,
Jun 9, 2008, 7:47:49 AM6/9/08
to
Hello!
Did any of you encountered such problem and solved it in some way? We
run several Windows Server 2008 and Windows Server 2003 test
configurations (both 32 and 64 bit) with WinDbg attached in kernel-
mode. WinDbg usually runs several days between restarts (though the
debugee machines are restarted every day). We connect to WinDbg
remotely when we actually need the debugger. On frequent ocassions the
debugger breaks in during image symbol unload in DebugService2 (on
Windows 2003 the routine has a different name, which I can't recall
now). I didn't manage yet to find a common rule to tell when it does
break in and when it does not. Certainly it doesn't break in every
time a symbol is unloaded.

I've reviewed the event filters settings in WinDbg and tried to modify
them, but it didn't help.

Is there anything to do with it? I would really appreciate any help or
advice.

Thanks,
Sergey Levi.

Pavel Lebedinsky [MSFT]

unread,
Jun 11, 2008, 4:31:54 AM6/11/08
to
> On frequent ocassions the
> debugger breaks in during image symbol unload in DebugService2 (on
> Windows 2003 the routine has a different name, which I can't recall
> now). I didn't manage yet to find a common rule to tell when it does
> break in and when it does not. Certainly it doesn't break in every
> time a symbol is unloaded.

Can you post a stack trace and output from 'sx' and '!gflag'?

--
This posting is provided "AS IS" with no warranties, and confers no
rights.


Sergey Levi

unread,
Jun 11, 2008, 8:59:23 AM6/11/08
to
Hi,

On Jun 11, 12:31 pm, "Pavel Lebedinsky [MSFT]"


<pa...@online.microsoft.com> wrote:
>
> Can you post a stack trace and output from 'sx' and '!gflag'?
>

Here's the output:

nt!DebugService2+0x5:
fffff800`0104b3a5 cc int 3
0: kd> kb
RetAddr : Args to
Child : Call
Site
fffff800`010fa646 : fffffadf`67727453 00000000`00000000
00000000`00000000 00000000`ffffffff : nt!DebugService2+0x5
fffff800`012b8bb0 : 00000000`00000001 fffff800`00000012
fffffadf`e61e4700 0000007f`fffffff8 : nt!DbgUnLoadImageSymbols+0x26
fffff800`01316ffc : fffffadf`e61e4710 fffffadf`e61e4740
fffffadf`e61e4740 fffffadf`e61e4740 : nt!MmUnloadSystemImage+0x3a5
fffff800`0129040d : fffffadf`e61e46f0 fffff800`0127ee0a
fffffadf`e61e46f0 00000000`00000000 : nt!IopDeleteDriver+0x4c
fffff800`0105a92b : fffffadf`e61e4710 00000000`00000001
fffffadf`e61e4740 00000000`00000000 : nt!ObpRemoveObjectRoutine+0x144
fffff800`010bfa03 : fffffadf`e602d680 fffffadf`e602d680
fffffadf`e61e4740 00000000`00000000 : nt!ObfDereferenceObject+0x83
fffff800`01273573 : fffffadf`e5f04550 00000000`00000000
fffffadf`e5f04550 00000000`00000000 : nt!IopCompleteUnloadOrDelete
+0x567
fffff800`0129040d : fffffadf`e5f04520 fffffadf`e5f04550
fffffadf`e5f04550 00000000`00000000 : nt!IopDeleteFile+0x3f0
fffff800`0105a92b : fffffadf`e5f04520 00000000`00000548
fffffadf`e5f04550 00000000`00000000 : nt!ObpRemoveObjectRoutine+0x144
fffff800`0128d6c7 : fffffa80`01110520 fffffa80`01110520
fffffa80`00e91470 00000000`00000000 : nt!ObfDereferenceObject+0x83
fffff800`0128d5b4 : fffffadf`e784bbd0 00000000`00000548
fffffadf`e5e0f040 fffffadf`e784bbd0 : nt!ObpCloseHandleTableEntry
+0x24b
fffff800`0104fce2 : fffffadf`e784bbd0 fffffadf`e383ccf0
00000000`00000000 00000000`00000000 : nt!ObpCloseHandle+0xb0
00000000`78ef135a : 000007ff`7b2f7702 00000000`00144007
00000000`00000000 00000000`00000000 : nt!KiSystemServiceCopyEnd+0x3
000007ff`7b2f7702 : 00000000`00144007 00000000`00000000
00000000`00000000 00000000`00000001 : ntdll!ZwClose+0xa
00000000`00144007 : 00000000`00000000 00000000`00000000
00000000`00000001 00000000`00000000 : 0x7ff`7b2f7702
00000000`00000000 : 00000000`00000000 00000000`00000001
00000000`00000000 000007ff`7b2f037c : 0x144007
00000000`00000000 : 00000000`00000001 00000000`00000000
000007ff`7b2f037c 00000000`00120510 : 0x0
00000000`00000001 : 00000000`00000000 000007ff`7b2f037c
00000000`00120510 000007ff`7b2e3720 : 0x0
00000000`00000000 : 000007ff`7b2f037c 00000000`00120510
000007ff`7b2e3720 000007ff`7b2e9090 : 0x1
000007ff`7b2f037c : 00000000`00120510 000007ff`7b2e3720
000007ff`7b2e9090 00000000`00000001 : 0x0
0: kd> sx
ct - Create thread - ignore
et - Exit thread - ignore
cpr - Create process - ignore
epr - Exit process - ignore
ld - Load module - ignore
ud - Unload module - ignore
ser - System error - ignore
ibp - Initial breakpoint - ignore
iml - Initial module load - ignore
out - Debuggee output - output

av - Access violation - break - not handled
asrt - Assertion failure - break - not handled
aph - Application hang - break - not handled
bpe - Break instruction exception - break
bpec - Break instruction exception continue - handled
eh - C++ EH exception - second-chance break - not handled
clr - CLR exception - second-chance break - not handled
clrn - CLR notification exception - second-chance break - handled
cce - Control-Break exception - break
cc - Control-Break exception continue - handled
cce - Control-C exception - break
cc - Control-C exception continue - handled
dm - Data misaligned - break - not handled
dbce - Debugger command exception - ignore - handled
gp - Guard page violation - break - not handled
ii - Illegal instruction - second-chance break - not handled
ip - In-page I/O error - break - not handled
dz - Integer divide-by-zero - break - not handled
iov - Integer overflow - break - not handled
ch - Invalid handle - break
hc - Invalid handle continue - not handled
lsq - Invalid lock sequence - break - not handled
isc - Invalid system call - break - not handled
3c - Port disconnected - second-chance break - not handled
svh - Service hang - break - not handled
sse - Single step exception - break
ssec - Single step exception continue - handled
sbo - Stack buffer overflow - break - not handled
sov - Stack overflow - break - not handled
vs - Verifier stop - break - not handled
vcpp - Visual C++ exception - ignore - handled
wkd - Wake debugger - break - not handled
wob - WOW64 breakpoint - break - handled
wos - WOW64 single step exception - break - handled

* - Other exception - second-chance break - not handled
0: kd> !gflag
Current NtGlobalFlag contents: 0x00000000

--
Thanks,
Sergey.

Sergey Levi

unread,
Jul 4, 2008, 6:51:46 AM7/4/08
to

We got rid of these breakins by stopping using remote debugger
connections.

0 new messages