Some more info on the affected system:
************************************************************************
WARNING: Dump file has inconsistent set-bit count. Data may be missing.
************************************************************************
Windows 2000 Kernel Version 2195 (Service Pack 4) MP (4 procs) Free x86 compatible
Product: Server, suite: TerminalServer SingleUserTS
Kernel base = 0xdd400000 PsLoadedModuleList = 0xdd488fa0
----- Forwarded Message ----
From: J Sukh
To: xxxxx@lists.osr.com
Sent: Friday, December 21, 2007 2:16:07 PM
Subject: crash in CcUninitializeCacheMap with IRQL_NOT_LESS_OR_EQUAL
We have an NTFS-like file system.
Recently one of our customers have been running into a crash on one of their systems. From the dump it looks that the system was in the process of purging the entire file from the cache.
This looks like some kind of a corruption.
Any ideas would be appreciated.
2: kd> !analyze
-v
Bugcheck Analysis
IRQL_NOT_LESS_OR_EQUAL (a)
An attempt was made to access a pageable (or completely invalid) address at an
interrupt request level (IRQL) that is too high. This is usually
caused by drivers using improper addresses.
If a kernel debugger is available get the stack backtrace.
Arguments:
Arg1: c9330004, memory referenced
Arg2: 00000002, IRQL
Arg3: 00000000, bitfield
:
bit 0 : value 0 = read operation, 1 = write operation
bit 3 : value 0 = not an execute operation, 1 = execute operation (only on chips which support this level of status)
Arg4: dd410be7, address which referenced memory
Debugging Details:
------------------
READ_ADDRESS: c9330004
CURRENT_IRQL: 2
FAULTING_IP:
nt!CcUninitializeCacheMap+b9
dd410be7 395e04 cmp dword ptr [esi+4],ebx
DEFAULT_BUCKET_ID: INTEL_CPU_MICROCODE_ZERO
BUGCHECK_STR: 0xA
PROCESS_NAME: CMD.EXE
TRAP_FRAME: f2cbff9c – (.trap 0xfffffffff2cbff9c)
ErrCode = 00000000
eax=dd432abc ebx=00000000 ecx=00000000 edx=00000000 esi=c9330000 edi=fbf89ce8
eip=dd410be7 esp=f2cc0010 ebp=f2cc006c iopl=0 nv up ei pl zr na pe
nc
cs=0008 ss=0010 ds=0023 es=0023 fs=0030 gs=0000 efl=00010246
nt!CcUninitializeCacheMap+0xb9:
dd410be7 395e04 cmp dword ptr [esi+4],ebx ds:0023:c9330004=???
Resetting default scope
LAST_CONTROL_TRANSFER: from dd410be7 to dd46e15c
STACK_TEXT:
f2cbff9c dd410be7 fc0b7c48 f4ad2144 f2cc0c54 nt!KiTrap0E+0x210
f2cc006c dd411639 fbf89ce8 00000000 00000000 nt!CcUninitializeCacheMap+0xb9
f2cc00d0 f4ac234b faf5f8a8 00000000 00000000 nt!CcPurgeCacheSection+0xc5
f2cc036c f4ab4120 fafe05a8 fca666c8 fa2dc008 iwfsd!NTCSFsdOpenTargetObject+0x3c0b [d:\outroot\build\nti86.dev\src\ifs_ntcs\basedir\src\create.c @ 3148]
f2cc07f4 f4aa95df fd16b710 fafe05a8 fd16b710 iwfsd!NTCSFsdCommonCreate+0xa0d0
[d:\outroot\build\nti86.dev\src\ifs_ntcs\basedir\src\create.c @ 1492]
f2cc08b4 dd41ef05 fd16b710 fa2dc008 fa2dc018 iwfsd!NTCSFsdCreate+0x87f [d:\outroot\build\nti86.dev\src\ifs_ntcs\basedir\src\create.c @ 159]
f2cc08c8 dd4c7b18 dd489fc0 dd4c7060 f2cc0bc4 nt!IopfCallDriver+0x35
f2cc0a50 dd45655a fd16b710 00000000 f2cc0b08 nt!IopParseDevice+0xab8
f2cc0ac8 dd4de262 00000000 fd590c00 00000040 nt!ObpLookupObjectName+0x504
f2cc0bd8 dd4a9221 00000000 00000000 f2cc0d01 nt!ObOpenObjectByName+0xc8
f2cc0d54 dd46b339 0012f5c4 0012f59c 00000000 nt!NtQueryAttributesFile+0xe3
f2cc0d54 77f88817 0012f5c4 0012f59c 00000000 nt!KiSystemService+0xc9
0012f580 7c5874d9 0012f5c4 0012f59c 00000000 ntdll!ZwQueryAttributesFile+0xb
0012f5f0 4ad11a8c 0012fa18 00134bf0 00000001 KERNEL32!GetFileAttributesW+0x71
0012fc78 4ad10dd6 00000003 00136f98 001347b8 cmd!do_normal_copy+0xb29
0012fc98 4ad08a96 00136f00 4ad0cf93 001347b8 cmd!copy+0xab
0012fca0
4ad0cf93 001347b8 001347b8 001347b8 cmd!eCopy+0xc
0012fec8 4ad0c949 00130001 001347b8 7c5b11ac cmd!FindFixAndRun+0x1cd
0012ff0c 4ad0c617 00000000 00000001 77f81650 cmd!Dispatch+0x135
0012ff70 4ad1a70f 00000003 004c3930 004c2e08 cmd!main+0x16f
0012ffc0 7c5989d5 77f81650 ffffffff 7ffff000 cmd!mainCRTStartup+0xff
0012fff0 00000000 4ad1a610 00000000 000000c8 KERNEL32!BaseProcessStart+0x3d
STACK_COMMAND: kb
FOLLOWUP_IP:
iwfsd!NTCSFsdOpenTargetObject+3c0b [d:\outroot\build\nti86.dev\src\ifs_ntcs\basedir\src\create.c @ 3148]
f4ac234b 8d9520ffffff lea edx,[ebp-0E0h]
SYMBOL_STACK_INDEX: 3
SYMBOL_NAME: iwfsd!NTCSFsdOpenTargetObject+3c0b
FOLLOWUP_NAME: MachineOwner
MODULE_NAME: iwfsd
IMAGE_NAME: iwfsd.sys
DEBUG_FLR_IMAGE_TIMESTAMP: 47547fd6
FAILURE_BUCKET_ID:
0xA_iwfsd!NTCSFsdOpenTargetObject+3c0b
BUCKET_ID: 0xA_iwfsd!NTCSFsdOpenTargetObject+3c0b
Followup: MachineOwner
---------
Be a better friend, newshound, and
know-it-all with Yahoo! Mobile. Try it now.
____________________________________________________________________________________
Looking for last minute shopping deals?
Find them fast with Yahoo! Search. http://tools.search.yahoo.com/newsearch/category.php?category=shopping