Windows System Software -- Consulting, Training, Development -- Unique Expertise, Guaranteed Results

Sept/Oct 2019 Issue of The NT Insider available


Download PDF here: http://insider.osr.com/2019/ntinsider_2019_01.pdf

It’s a particularly BIG issue, too: 40 pages of technical goodness, ranging from WDF to Minifilters. Check it out.
Before Posting...
Please check out the Community Guidelines in the Announcements and Administration Category.

Missing recent ntoskrnl from public symbol server

Takin_Nili-EsfahaniTakin_Nili-Esfahani Member Posts: 9
edited July 2 in WINDBG

I am hoping someone from MSFT reads this forum and can forward this to the appropriate team. These versions are not found on the public symbol server.

1: kd> vertarget
Windows 10 Kernel Version 17134 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 17134.1.amd64fre.rs4_release.180410-1804
Machine Name:
Kernel base = 0xfffff80076093000 PsLoadedModuleList = 0xfffff80076440170
Debug session time: Sun Jun 23 20:58:36.570 2019 (UTC - 7:00)
System Uptime: 0 days 21:00:56.847

SYMSRV: BYINDEX: 0x278
https://msdl.microsoft.com/download/symbols
ntkrnlmp.exe
5CF9F460954000

2: kd> vertarget
Windows 10 Kernel Version 18362 MP (4 procs) Free x64
Product: WinNt, suite: TerminalServer SingleUserTS Personal
Built by: 18362.1.amd64fre.19h1_release.190318-1202
Machine Name:
Kernel base = 0xfffff80342800000 PsLoadedModuleList = 0xfffff80342c43370
Debug session time: Mon Jun 24 00:52:59.254 2019 (UTC - 7:00)
System Uptime: 4 days 21:09:46.242

SYMSRV: BYINDEX: 0x188
https://msdl.microsoft.com/download/symbols
ntkrpamp.exe
EADCD02Bab2000

Comments

  • Scott_Noone_(OSR)Scott_Noone_(OSR) Administrator Posts: 3,159

    What does

    !sym noisy
    .reload
    

    Say?

    -scott
    OSR

  • Takin_Nili-EsfahaniTakin_Nili-Esfahani Member Posts: 9

    The problem turned out to be that ntoskrnl.exe 17134 (RS4) dated 6/6/2019 is not found on the MSFT symbol server. I was debugging a mini dump and apparently this is a show stopper. When I applied the update on a test system and pointed the debugger to the file using .exepath or "-i ImagePath" it resolves the problem. I haven't verified but I believe the same problem exists for 17763 and 18362 builds.

    I can't include the complete output of those commands because it exceeds the limit. Here is the version of ntoskrnl.exe that was giving me grief:

    0: kd> lmvm nt
    Browse full module list
    start end module name
    fffff8011baa7000 fffff8011c3fb000 nt T (no symbols)
    Loaded symbol image file: ntoskrnl.exe
    Image path: \SystemRoot\system32\ntoskrnl.exe
    Image name: ntoskrnl.exe
    Browse all global symbols functions data
    Timestamp: Thu Jun 6 22:21:36 2019 (5CF9F460)
    CheckSum: 008ACBFC
    ImageSize: 00954000
    Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
    Information from resource tables:

Sign In or Register to comment.

Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!

Upcoming OSR Seminars
Writing WDF Drivers 21 Oct 2019 OSR Seminar Space & ONLINE
Internals & Software Drivers 18 Nov 2019 Dulles, VA
Kernel Debugging 30 Mar 2020 OSR Seminar Space
Developing Minifilters 27 Apr 2020 OSR Seminar Space & ONLINE