Re: 求助一个Crash Dump的INVALID_POINTER_READ问题

C/C++本地代码调试

求助一个Crash Dump的INVALID_POINTER_READ问题


saviola 2016-06-02, 19:33 下午
各位高手和老师们好!

近期遇到个无法解释的问题,程序Crash了,windbg了一下Dump,用.ecxr得到了exception状态时的指令。但是,它执行的指令不该触发异常啊,请看下这怎么解释?


0:005> !analyze -v

FAULTING_IP:
ProgramName!FAsyncTask<FSceneRenderer::FAsyncVisibilityCull>::FinishThreadedWork+3
0199ac63 83bfb003000000  cmp     dword ptr [edi+3B0h],0

EXCEPTION_RECORD:  ffffffff -- (.exr 0xffffffffffffffff)
ExceptionAddress: 0199ac63 (ProgramName!FAsyncTask<FSceneRenderer::FAsyncVisibilityCull>::FinishThreadedWork+0x00000003)
   ExceptionCode: c0000005 (Access violation)

  ExceptionFlags: 00000000
NumberParameters: 2
   Parameter[0]: 00000000
   Parameter[1]: abe904dc
Attempt to read from address abe904dc

DEFAULT_BUCKET_ID:  INVALID_POINTER_READ


0:005> .ecxr
eax=00000000 ebx=0007781f ecx=abe9012c edx=00000002 esi=007cfd20 edi=abe9012c
eip=0199ac63 esp=077efcc4 ebp=077efce8 iopl=0         nv up ei pl zr na pe cy
cs=0023  ss=002b  ds=002b  es=002b  fs=0053  gs=002b             efl=00010247
ProgramName!FAsyncTask<FSceneRenderer::FAsyncVisibilityCull>::FinishThreadedWork+0x3:
0199ac63 83bfb003000000  cmp     dword ptr [edi+3B0h],0 ds:002b:abe904dc=00000000

0:005> !address abe904dc
 ProcessParametrs 00bd13e8 in range 00bd0000 00cd0000
 Environment 00bd07f0 in range 00bd0000 00cd0000
    abe90000 : abe90000 - 0001e000
                    Type     00020000 MEM_PRIVATE
                    Protect  00000004 PAGE_READWRITE
                    State    00001000 MEM_COMMIT
                    Usage    RegionUsageIsVAD

0:005> dd abe904dc-20h L10
abe904bc  00000000 00000001 00000001 00000028
abe904cc  00000000 00000000 00000000 00000000
abe904dc  00000000 00000000 02b041c4 abe90058
abe904ec  7f7fffff 00000025 00000008 55804600

这块内存完全是可以被读到内容的呀,是个正常的READWRITE Page,哪怕是指针指坏了不该读那儿,但不管怎样是能读到的呀!为什么异常了?

背景:这是个32位程序,跑在64位Windows上时偶发Crash时的Dump

好迷茫,求指教。万分感谢!

Re: 求助一个Crash Dump的INVALID_POINTER_READ问题


HiJack 2016-08-14, 16:03 下午
你确认这个地址可读?edi+3B0h

Re: 求助一个Crash Dump的INVALID_POINTER_READ问题


格蠹老雷 2016-08-22, 10:52 上午
那个地址已经超出了32位进程的2GB用户态空间的边界了


Re: 求助一个Crash Dump的INVALID_POINTER_READ问题


saviola 2016-09-14, 12:46 下午
感谢老大回复!

但这个程序是启用了Large Address Aware的,并且是运行在64位Win7上。虽为32bit app,应能访问3GB内地址的。所以应该不是>2GB地址不可读写的问题。

Re: 求助一个Crash Dump的INVALID_POINTER_READ问题


saviola 2016-09-14, 12:50 下午
 lhwqqq wrote:
你确认这个地址可读?edi+3B0h


是的,!address已经告诉大家了。。。后面我dd也显示了data

edi=abe9012c

edi+3B0 = abe904dc

0:005> !address abe904dc
 ProcessParametrs 00bd13e8 in range 00bd0000 00cd0000
 Environment 00bd07f0 in range 00bd0000 00cd0000
    abe90000 : abe90000 - 0001e000
                    Type     00020000 MEM_PRIVATE
                    Protect  00000004 PAGE_READWRITE
                    State    00001000 MEM_COMMIT
                    Usage    RegionUsageIsVAD


Powered by Community Server Powered by CnForums.Net