FAST_FAIL_FATAL_APP_EXIT during defapp invocation after logon #15934

Closed
opened 2026-01-31 04:52:38 +00:00 by claunia · 14 comments
Owner

Originally created by @ianjoneill on GitHub (Nov 20, 2021).

Windows Terminal version

1.11.2921.0

Windows build number

10.0.22000.318

Other Software

No response

Steps to reproduce

Unfortunately this just happened with no interaction following logon, however I don't have windows terminal set to start up on logon.

This makes me think it must have been a defapp invocation because I certainly didn't trigger it. The app appeared for a split second, then disappeared.

Expected Behavior

No response

Actual Behavior

Crash dump appeared in %LOCALAPPDATA%\CrashDumps.

Can provide the dump by email if that would be useful.

WinDbg output:

0:000> !analyze -v
*******************************************************************************
*                                                                             *
*                        Exception Analysis                                   *
*                                                                             *
*******************************************************************************


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 7249

    Key  : Analysis.DebugAnalysisManager
    Value: Create

    Key  : Analysis.Elapsed.mSec
    Value: 169477

    Key  : Analysis.Init.CPU.mSec
    Value: 608

    Key  : Analysis.Init.Elapsed.mSec
    Value: 43767

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 322

    Key  : FailFast.Name
    Value: FATAL_APP_EXIT

    Key  : FailFast.Type
    Value: 7

    Key  : Timeline.Process.Start.DeltaSec
    Value: 1

    Key  : WER.OS.Branch
    Value: co_release

    Key  : WER.OS.Timestamp
    Value: 2021-06-04T16:28:00Z

    Key  : WER.OS.Version
    Value: 10.0.22000.1

    Key  : WER.Process.Version
    Value: 1.11.2110.19001


FILE_IN_CAB:  WindowsTerminal.exe.22988.dmp

NTGLOBALFLAG:  0

PROCESS_BAM_CURRENT_THROTTLED: 0

PROCESS_BAM_PREVIOUS_THROTTLED: 0

APPLICATION_VERIFIER_FLAGS:  0

CONTEXT:  (.ecxr)
rax=0000000000000001 rbx=00000015524ff460 rcx=0000000000000007
rdx=000000000000000f rsi=00000015524fea40 rdi=00000000ffffffff
rip=00007ff83b98dd7e rsp=00000015524fe0f0 rbp=00000015524fe250
 r8=0000000000000001  r9=00000015524fe098 r10=0000000000000012
r11=0000200200000000 r12=0000000000000000 r13=00000015524fec20
r14=00000015524fe400 r15=00000015524fe430
iopl=0         nv up ei pl nz na pe nc
cs=0033  ss=002b  ds=002b  es=002b  fs=0053  gs=002b             efl=00000202
ucrtbase!abort+0x4e:
00007ff8`3b98dd7e cd29            int     29h
Resetting default scope

EXCEPTION_RECORD:  (.exr -1)
ExceptionAddress: 00007ff83b98dd7e (ucrtbase!abort+0x000000000000004e)
   ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  ExceptionFlags: 00000001
NumberParameters: 1
   Parameter[0]: 0000000000000007
Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT 

PROCESS_NAME:  WindowsTerminal.exe

ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_CODE_STR:  c0000409

EXCEPTION_PARAMETER1:  0000000000000007

STACK_TEXT:  
00000015`524fe0f0 00007ff8`3b98d499     : 00000015`00000003 00000015`00000003 00007fff`f71f62b0 00007fff`f71f6280 : ucrtbase!abort+0x4e
00000015`524fe120 00007ff8`0a101aab     : 00000015`524ff460 00000015`524fea40 00000015`524fe400 00000015`524fe400 : ucrtbase!terminate+0x29
00000015`524fe150 00007ff8`0a102317     : 00007fff`effd33a3 00007fff`efffc18c 00000015`524fe370 00007fff`f71e2519 : VCRUNTIME140_1!FindHandler<__FrameHandler4>+0x45b
00000015`524fe320 00007ff8`0a1040d9     : 00007ff7`f4090000 00000015`524ff460 00000015`524fec20 00000015`524fea40 : VCRUNTIME140_1!__InternalCxxFrameHandler<__FrameHandler4>+0x267
00000015`524fe3c0 00007ff7`f409ef84     : 00000015`524ff7b0 00007ff7`f40c3dcc 00000015`524ff460 00000015`524ff7b0 : VCRUNTIME140_1!__CxxFrameHandler4+0xa9
00000015`524fe430 00007ff8`3dc482ff     : 00000000`00000000 00000015`524fe9f0 00000015`524ff460 00000000`00000081 : WindowsTerminal+0xef84
00000015`524fe460 00007ff8`3dbd5a0a     : 00000015`524ff460 00007ff7`f4090000 00007ff7`f40969c5 00007ff7`f40cd39c : ntdll!RtlpExecuteHandlerForException+0xf
00000015`524fe490 00007ff8`3dbd2cd3     : 00000000`00000000 00000015`524ff310 00000000`00000000 00007ff8`3dbd2c3f : ntdll!RtlDispatchException+0x25a
00000015`524febe0 00007ff8`3b56466c     : 00000000`00000000 00007ff7`f40c8170 00000015`524ff5b0 00000000`00000000 : ntdll!RtlRaiseException+0x163
00000015`524ff440 00007fff`f71e6480     : 00000000`00000000 00000000`00000000 00000000`00000000 00007ff8`3dbc8db8 : KERNELBASE!RaiseException+0x6c
00000015`524ff520 00007ff7`f40a0bfb     : 00000118`baf05d30 00000000`800706be 00000000`800706be 00000118`bafa6160 : VCRUNTIME140!_CxxThrowException+0x90
00000015`524ff580 00007ff7`f40a26d6     : 00000118`bafa99d0 00000118`bafa99d0 00000118`bafa6160 00000118`bafa6148 : WindowsTerminal+0x10bfb
00000015`524ff5e0 00007ff7`f40969c5     : 00000000`00000000 00000118`bae5a258 00000015`524ffb88 00000015`524ffb70 : WindowsTerminal+0x126d6
00000015`524ff7b0 00007ff7`f409878e     : 00000000`0000000a 00000000`0000000a 00000000`00000000 00000000`00000000 : WindowsTerminal+0x69c5
00000015`524ffa80 00007ff7`f409bf72     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal+0x878e
00000015`524ffc40 00007ff8`3c8854e0     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal+0xbf72
00000015`524ffc80 00007ff8`3dba485b     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x10
00000015`524ffcb0 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x2b


SYMBOL_NAME:  ucrtbase!abort+4e

MODULE_NAME: ucrtbase

IMAGE_NAME:  ucrtbase.dll

STACK_COMMAND:  ~0s ; .ecxr ; kb

FAILURE_BUCKET_ID:  FAIL_FAST_FATAL_APP_EXIT_c0000409_ucrtbase.dll!abort

OS_VERSION:  10.0.22000.1

BUILDLAB_STR:  co_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

IMAGE_VERSION:  10.0.22000.1

FAILURE_ID_HASH:  {e31753ac-c98a-8055-3663-47e707543d20}

Followup:     MachineOwner
---------
Originally created by @ianjoneill on GitHub (Nov 20, 2021). ### Windows Terminal version 1.11.2921.0 ### Windows build number 10.0.22000.318 ### Other Software _No response_ ### Steps to reproduce Unfortunately this just happened with no interaction following logon, however I don't have windows terminal set to start up on logon. This makes me think it must have been a defapp invocation because I certainly didn't trigger it. The app appeared for a split second, then disappeared. ### Expected Behavior _No response_ ### Actual Behavior Crash dump appeared in `%LOCALAPPDATA%\CrashDumps`. Can provide the dump by email if that would be useful. WinDbg output: ``` 0:000> !analyze -v ******************************************************************************* * * * Exception Analysis * * * ******************************************************************************* KEY_VALUES_STRING: 1 Key : Analysis.CPU.mSec Value: 7249 Key : Analysis.DebugAnalysisManager Value: Create Key : Analysis.Elapsed.mSec Value: 169477 Key : Analysis.Init.CPU.mSec Value: 608 Key : Analysis.Init.Elapsed.mSec Value: 43767 Key : Analysis.Memory.CommitPeak.Mb Value: 322 Key : FailFast.Name Value: FATAL_APP_EXIT Key : FailFast.Type Value: 7 Key : Timeline.Process.Start.DeltaSec Value: 1 Key : WER.OS.Branch Value: co_release Key : WER.OS.Timestamp Value: 2021-06-04T16:28:00Z Key : WER.OS.Version Value: 10.0.22000.1 Key : WER.Process.Version Value: 1.11.2110.19001 FILE_IN_CAB: WindowsTerminal.exe.22988.dmp NTGLOBALFLAG: 0 PROCESS_BAM_CURRENT_THROTTLED: 0 PROCESS_BAM_PREVIOUS_THROTTLED: 0 APPLICATION_VERIFIER_FLAGS: 0 CONTEXT: (.ecxr) rax=0000000000000001 rbx=00000015524ff460 rcx=0000000000000007 rdx=000000000000000f rsi=00000015524fea40 rdi=00000000ffffffff rip=00007ff83b98dd7e rsp=00000015524fe0f0 rbp=00000015524fe250 r8=0000000000000001 r9=00000015524fe098 r10=0000000000000012 r11=0000200200000000 r12=0000000000000000 r13=00000015524fec20 r14=00000015524fe400 r15=00000015524fe430 iopl=0 nv up ei pl nz na pe nc cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000202 ucrtbase!abort+0x4e: 00007ff8`3b98dd7e cd29 int 29h Resetting default scope EXCEPTION_RECORD: (.exr -1) ExceptionAddress: 00007ff83b98dd7e (ucrtbase!abort+0x000000000000004e) ExceptionCode: c0000409 (Security check failure or stack buffer overrun) ExceptionFlags: 00000001 NumberParameters: 1 Parameter[0]: 0000000000000007 Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT PROCESS_NAME: WindowsTerminal.exe ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application. EXCEPTION_CODE_STR: c0000409 EXCEPTION_PARAMETER1: 0000000000000007 STACK_TEXT: 00000015`524fe0f0 00007ff8`3b98d499 : 00000015`00000003 00000015`00000003 00007fff`f71f62b0 00007fff`f71f6280 : ucrtbase!abort+0x4e 00000015`524fe120 00007ff8`0a101aab : 00000015`524ff460 00000015`524fea40 00000015`524fe400 00000015`524fe400 : ucrtbase!terminate+0x29 00000015`524fe150 00007ff8`0a102317 : 00007fff`effd33a3 00007fff`efffc18c 00000015`524fe370 00007fff`f71e2519 : VCRUNTIME140_1!FindHandler<__FrameHandler4>+0x45b 00000015`524fe320 00007ff8`0a1040d9 : 00007ff7`f4090000 00000015`524ff460 00000015`524fec20 00000015`524fea40 : VCRUNTIME140_1!__InternalCxxFrameHandler<__FrameHandler4>+0x267 00000015`524fe3c0 00007ff7`f409ef84 : 00000015`524ff7b0 00007ff7`f40c3dcc 00000015`524ff460 00000015`524ff7b0 : VCRUNTIME140_1!__CxxFrameHandler4+0xa9 00000015`524fe430 00007ff8`3dc482ff : 00000000`00000000 00000015`524fe9f0 00000015`524ff460 00000000`00000081 : WindowsTerminal+0xef84 00000015`524fe460 00007ff8`3dbd5a0a : 00000015`524ff460 00007ff7`f4090000 00007ff7`f40969c5 00007ff7`f40cd39c : ntdll!RtlpExecuteHandlerForException+0xf 00000015`524fe490 00007ff8`3dbd2cd3 : 00000000`00000000 00000015`524ff310 00000000`00000000 00007ff8`3dbd2c3f : ntdll!RtlDispatchException+0x25a 00000015`524febe0 00007ff8`3b56466c : 00000000`00000000 00007ff7`f40c8170 00000015`524ff5b0 00000000`00000000 : ntdll!RtlRaiseException+0x163 00000015`524ff440 00007fff`f71e6480 : 00000000`00000000 00000000`00000000 00000000`00000000 00007ff8`3dbc8db8 : KERNELBASE!RaiseException+0x6c 00000015`524ff520 00007ff7`f40a0bfb : 00000118`baf05d30 00000000`800706be 00000000`800706be 00000118`bafa6160 : VCRUNTIME140!_CxxThrowException+0x90 00000015`524ff580 00007ff7`f40a26d6 : 00000118`bafa99d0 00000118`bafa99d0 00000118`bafa6160 00000118`bafa6148 : WindowsTerminal+0x10bfb 00000015`524ff5e0 00007ff7`f40969c5 : 00000000`00000000 00000118`bae5a258 00000015`524ffb88 00000015`524ffb70 : WindowsTerminal+0x126d6 00000015`524ff7b0 00007ff7`f409878e : 00000000`0000000a 00000000`0000000a 00000000`00000000 00000000`00000000 : WindowsTerminal+0x69c5 00000015`524ffa80 00007ff7`f409bf72 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal+0x878e 00000015`524ffc40 00007ff8`3c8854e0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal+0xbf72 00000015`524ffc80 00007ff8`3dba485b : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x10 00000015`524ffcb0 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x2b SYMBOL_NAME: ucrtbase!abort+4e MODULE_NAME: ucrtbase IMAGE_NAME: ucrtbase.dll STACK_COMMAND: ~0s ; .ecxr ; kb FAILURE_BUCKET_ID: FAIL_FAST_FATAL_APP_EXIT_c0000409_ucrtbase.dll!abort OS_VERSION: 10.0.22000.1 BUILDLAB_STR: co_release OSPLATFORM_TYPE: x64 OSNAME: Windows 10 IMAGE_VERSION: 10.0.22000.1 FAILURE_ID_HASH: {e31753ac-c98a-8055-3663-47e707543d20} Followup: MachineOwner --------- ```
Author
Owner

@zadjii-msft commented on GitHub (Nov 22, 2021):

the dump by email if that would be useful

That definitely would be, my email is in my profile ☺️ (maybe ping me on this thread when you sent it so I can check all the various filtered folders, thanks!)

@zadjii-msft commented on GitHub (Nov 22, 2021): > the dump by email if that would be useful That definitely would be, my email is in my profile ☺️ (maybe ping me on this thread when you sent it so I can check all the various filtered folders, thanks!)
Author
Owner

@ianjoneill commented on GitHub (Nov 22, 2021):

I've sent the dump via email.

Out of curiosity, is there any reason why the debug symbols for release builds aren't pushed to the Microsoft symbol servers?

@ianjoneill commented on GitHub (Nov 22, 2021): I've sent the dump via email. Out of curiosity, is there any reason why the debug symbols for release builds aren't pushed to the Microsoft symbol servers?
Author
Owner

@ianjoneill commented on GitHub (Dec 6, 2021):

@zadjii-msft did you get the crash dump, or would you like me to resend it?

@ianjoneill commented on GitHub (Dec 6, 2021): @zadjii-msft did you get the crash dump, or would you like me to resend it?
Author
Owner

@zadjii-msft commented on GitHub (Dec 7, 2021):

Sorry yea, I did get it, just distracted with other tasks. Loading the symbols up now ☺️

@zadjii-msft commented on GitHub (Dec 7, 2021): Sorry yea, I did get it, just distracted with other tasks. Loading the symbols up now ☺️
Author
Owner

@erica647 commented on GitHub (Dec 22, 2021):

I just received what appears to be the same crash dump in Windows 11 version 22000.376 with Terminal version 1.11.3471.0... WinDBG Output:

0:000> !analyze -v


  •                                                                         *
    
  •                    Exception Analysis                                   *
    
  •                                                                         *
    

KEY_VALUES_STRING: 1

Key  : Analysis.CPU.mSec
Value: 3921

Key  : Analysis.DebugAnalysisManager
Value: Create

Key  : Analysis.Elapsed.mSec
Value: 49989

Key  : Analysis.Init.CPU.mSec
Value: 265

Key  : Analysis.Init.Elapsed.mSec
Value: 19268

Key  : Analysis.Memory.CommitPeak.Mb
Value: 333

Key  : FailFast.Name
Value: FATAL_APP_EXIT

Key  : FailFast.Type
Value: 7

Key  : Timeline.Process.Start.DeltaSec
Value: 2

Key  : WER.OS.Branch
Value: co_release

Key  : WER.OS.Timestamp
Value: 2021-06-04T16:28:00Z

Key  : WER.OS.Version
Value: 10.0.22000.1

Key  : WER.Process.Version
Value: 1.11.2112.13011

FILE_IN_CAB: WindowsTerminal.exe.8524.dmp

NTGLOBALFLAG: 0

PROCESS_BAM_CURRENT_THROTTLED: 0

PROCESS_BAM_PREVIOUS_THROTTLED: 0

APPLICATION_VERIFIER_FLAGS: 0

CONTEXT: (.ecxr)
rax=0000000000000001 rbx=000000db070ff3c0 rcx=0000000000000007
rdx=000000000000000f rsi=000000db070fe9a0 rdi=00000000ffffffff
rip=00007ff953f8dd7e rsp=000000db070fe050 rbp=000000db070fe1b0
r8=0000000000000001 r9=000000db070fdff8 r10=0000000000000012
r11=0000000000020020 r12=0000000000000000 r13=000000db070feb80
r14=000000db070fe360 r15=000000db070fe390
iopl=0 nv up ei pl nz na pe nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000202
ucrtbase!abort+0x4e:
00007ff9`53f8dd7e cd29 int 29h
Resetting default scope

EXCEPTION_RECORD: (.exr -1)
ExceptionAddress: 00007ff953f8dd7e (ucrtbase!abort+0x000000000000004e)
ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000007
Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT

PROCESS_NAME: WindowsTerminal.exe

ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_CODE_STR: c0000409

EXCEPTION_PARAMETER1: 0000000000000007

STACK_TEXT:
000000db070fe050 00007ff953f8d499 : 000000db00000003 000000db00000003 00007ff926a762b0 00007ff926a76280 : ucrtbase!abort+0x4e
000000db070fe080 00007ff947111aab : 000000db070ff3c0 000000db070fe9a0 000000db070fe360 000000db070fe360 : ucrtbase!terminate+0x29
000000db070fe0b0 00007ff947112317 : 00007ff90fa233a3 00007ff90fa4c18c 000000db070fe2d0 00007ff926a62519 : VCRUNTIME140_1!FindHandler<__FrameHandler4>+0x45b
000000db070fe280 00007ff9471140d9 : 00007ff768df0000 000000db070ff3c0 000000db070feb80 000000db070fe9a0 : VCRUNTIME140_1!__InternalCxxFrameHandler<__FrameHandler4>+0x267
000000db070fe320 00007ff768dff664 : 000000db070ff710 00007ff768e23354 000000db070ff3c0 000000db070ff710 : VCRUNTIME140_1!__CxxFrameHandler4+0xa9
000000db070fe390 00007ff9565c82ff : 0000000000000000 000000db070fe950 000000db070ff3c0 0000000000000081 : WindowsTerminal+0xf664
000000db070fe3c0 00007ff956555a0a : 000000db070ff3c0 00007ff768df0000 00007ff768df44ca 00007ff768e2d1bc : ntdll!RtlpExecuteHandlerForException+0xf
000000db070fe3f0 00007ff956552cd3 : 0000000000000000 000000db070ff270 0000000000000000 00007ff956552c3f : ntdll!RtlDispatchException+0x25a
000000db070feb40 00007ff95407478c : 0000000000000000 00007ff768e280f8 000000db070ff510 0000000000000000 : ntdll!RtlRaiseException+0x163
000000db070ff3a0 00007ff926a66480 : 0000000000000000 0000000000000000 0000000000000000 00007ff956548db8 : KERNELBASE!RaiseException+0x6c
000000db070ff480 00007ff768e02aa3 : 00000253ea6582d0 00000000800706be 00000000800706be 00000253ea6910f0 : VCRUNTIME140!_CxxThrowException+0x90
000000db070ff4e0 00007ff768e0150e : 00000253ea661580 00000253ea661580 00000253ea6910f0 00000253ea691208 : WindowsTerminal+0x12aa3
000000db070ff540 00007ff768df44ca : 0000000000000000 00000253e8d8b228 000000db070ffae8 000000db070ffad0 : WindowsTerminal+0x1150e
000000db070ff710 00007ff768df127e : 000000000000000a 000000000000000a 0000000000000000 0000000000000000 : WindowsTerminal+0x44ca
000000db070ff9e0 00007ff768dfc482 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : WindowsTerminal+0x127e
000000db070ffba0 00007ff954fe54e0 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : WindowsTerminal+0xc482
000000db070ffbe0 00007ff95652485b : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : kernel32!BaseThreadInitThunk+0x10
000000db070ffc10 0000000000000000 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : ntdll!RtlUserThreadStart+0x2b

SYMBOL_NAME: ucrtbase!abort+4e

MODULE_NAME: ucrtbase

IMAGE_NAME: ucrtbase.dll

STACK_COMMAND: ~0s ; .ecxr ; kb

FAILURE_BUCKET_ID: FAIL_FAST_FATAL_APP_EXIT_c0000409_ucrtbase.dll!abort

OS_VERSION: 10.0.22000.1

BUILDLAB_STR: co_release

OSPLATFORM_TYPE: x64

OSNAME: Windows 10

IMAGE_VERSION: 10.0.22000.1

FAILURE_ID_HASH: {e31753ac-c98a-8055-3663-47e707543d20}

Followup: MachineOwner

This also happened to me on startup and was definitely a surprise since I don't have Terminal set to run at startup.

@erica647 commented on GitHub (Dec 22, 2021): I just received what appears to be the same crash dump in Windows 11 version 22000.376 with Terminal version 1.11.3471.0... WinDBG Output: 0:000> !analyze -v ******************************************************************************* * * * Exception Analysis * * * ******************************************************************************* KEY_VALUES_STRING: 1 Key : Analysis.CPU.mSec Value: 3921 Key : Analysis.DebugAnalysisManager Value: Create Key : Analysis.Elapsed.mSec Value: 49989 Key : Analysis.Init.CPU.mSec Value: 265 Key : Analysis.Init.Elapsed.mSec Value: 19268 Key : Analysis.Memory.CommitPeak.Mb Value: 333 Key : FailFast.Name Value: FATAL_APP_EXIT Key : FailFast.Type Value: 7 Key : Timeline.Process.Start.DeltaSec Value: 2 Key : WER.OS.Branch Value: co_release Key : WER.OS.Timestamp Value: 2021-06-04T16:28:00Z Key : WER.OS.Version Value: 10.0.22000.1 Key : WER.Process.Version Value: 1.11.2112.13011 FILE_IN_CAB: WindowsTerminal.exe.8524.dmp NTGLOBALFLAG: 0 PROCESS_BAM_CURRENT_THROTTLED: 0 PROCESS_BAM_PREVIOUS_THROTTLED: 0 APPLICATION_VERIFIER_FLAGS: 0 CONTEXT: (.ecxr) rax=0000000000000001 rbx=000000db070ff3c0 rcx=0000000000000007 rdx=000000000000000f rsi=000000db070fe9a0 rdi=00000000ffffffff rip=00007ff953f8dd7e rsp=000000db070fe050 rbp=000000db070fe1b0 r8=0000000000000001 r9=000000db070fdff8 r10=0000000000000012 r11=0000000000020020 r12=0000000000000000 r13=000000db070feb80 r14=000000db070fe360 r15=000000db070fe390 iopl=0 nv up ei pl nz na pe nc cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000202 ucrtbase!abort+0x4e: 00007ff9`53f8dd7e cd29 int 29h Resetting default scope EXCEPTION_RECORD: (.exr -1) ExceptionAddress: 00007ff953f8dd7e (ucrtbase!abort+0x000000000000004e) ExceptionCode: c0000409 (Security check failure or stack buffer overrun) ExceptionFlags: 00000001 NumberParameters: 1 Parameter[0]: 0000000000000007 Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT PROCESS_NAME: WindowsTerminal.exe ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application. EXCEPTION_CODE_STR: c0000409 EXCEPTION_PARAMETER1: 0000000000000007 STACK_TEXT: 000000db`070fe050 00007ff9`53f8d499 : 000000db`00000003 000000db`00000003 00007ff9`26a762b0 00007ff9`26a76280 : ucrtbase!abort+0x4e 000000db`070fe080 00007ff9`47111aab : 000000db`070ff3c0 000000db`070fe9a0 000000db`070fe360 000000db`070fe360 : ucrtbase!terminate+0x29 000000db`070fe0b0 00007ff9`47112317 : 00007ff9`0fa233a3 00007ff9`0fa4c18c 000000db`070fe2d0 00007ff9`26a62519 : VCRUNTIME140_1!FindHandler<__FrameHandler4>+0x45b 000000db`070fe280 00007ff9`471140d9 : 00007ff7`68df0000 000000db`070ff3c0 000000db`070feb80 000000db`070fe9a0 : VCRUNTIME140_1!__InternalCxxFrameHandler<__FrameHandler4>+0x267 000000db`070fe320 00007ff7`68dff664 : 000000db`070ff710 00007ff7`68e23354 000000db`070ff3c0 000000db`070ff710 : VCRUNTIME140_1!__CxxFrameHandler4+0xa9 000000db`070fe390 00007ff9`565c82ff : 00000000`00000000 000000db`070fe950 000000db`070ff3c0 00000000`00000081 : WindowsTerminal+0xf664 000000db`070fe3c0 00007ff9`56555a0a : 000000db`070ff3c0 00007ff7`68df0000 00007ff7`68df44ca 00007ff7`68e2d1bc : ntdll!RtlpExecuteHandlerForException+0xf 000000db`070fe3f0 00007ff9`56552cd3 : 00000000`00000000 000000db`070ff270 00000000`00000000 00007ff9`56552c3f : ntdll!RtlDispatchException+0x25a 000000db`070feb40 00007ff9`5407478c : 00000000`00000000 00007ff7`68e280f8 000000db`070ff510 00000000`00000000 : ntdll!RtlRaiseException+0x163 000000db`070ff3a0 00007ff9`26a66480 : 00000000`00000000 00000000`00000000 00000000`00000000 00007ff9`56548db8 : KERNELBASE!RaiseException+0x6c 000000db`070ff480 00007ff7`68e02aa3 : 00000253`ea6582d0 00000000`800706be 00000000`800706be 00000253`ea6910f0 : VCRUNTIME140!_CxxThrowException+0x90 000000db`070ff4e0 00007ff7`68e0150e : 00000253`ea661580 00000253`ea661580 00000253`ea6910f0 00000253`ea691208 : WindowsTerminal+0x12aa3 000000db`070ff540 00007ff7`68df44ca : 00000000`00000000 00000253`e8d8b228 000000db`070ffae8 000000db`070ffad0 : WindowsTerminal+0x1150e 000000db`070ff710 00007ff7`68df127e : 00000000`0000000a 00000000`0000000a 00000000`00000000 00000000`00000000 : WindowsTerminal+0x44ca 000000db`070ff9e0 00007ff7`68dfc482 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal+0x127e 000000db`070ffba0 00007ff9`54fe54e0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal+0xc482 000000db`070ffbe0 00007ff9`5652485b : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x10 000000db`070ffc10 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x2b SYMBOL_NAME: ucrtbase!abort+4e MODULE_NAME: ucrtbase IMAGE_NAME: ucrtbase.dll STACK_COMMAND: ~0s ; .ecxr ; kb FAILURE_BUCKET_ID: FAIL_FAST_FATAL_APP_EXIT_c0000409_ucrtbase.dll!abort OS_VERSION: 10.0.22000.1 BUILDLAB_STR: co_release OSPLATFORM_TYPE: x64 OSNAME: Windows 10 IMAGE_VERSION: 10.0.22000.1 FAILURE_ID_HASH: {e31753ac-c98a-8055-3663-47e707543d20} Followup: MachineOwner --------- This also happened to me on startup and was definitely a surprise since I don't have Terminal set to run at startup.
Author
Owner

@ianjoneill commented on GitHub (May 25, 2022):

@zadjii-msft I've had another one of these crashes recently apparently - on 2022-05-19.

Now that debug symbols are available, it looks like the crash (assuming it's the same) is somewhere in WindowManager::ProposeCommandline(), which I know is your domain!

For some reason WinDbg isn't giving the the line number in ProposeCommandline() - I'm not sure why...

image

I can email over the dump if that's useful.

Output of !analyze -v:

*******************************************************************************
*                                                                             *
*                        Exception Analysis                                   *
*                                                                             *
*******************************************************************************


KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 1812

    Key  : Analysis.DebugAnalysisManager
    Value: Create

    Key  : Analysis.Elapsed.mSec
    Value: 2370

    Key  : Analysis.Init.CPU.mSec
    Value: 952

    Key  : Analysis.Init.Elapsed.mSec
    Value: 40562

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 399

    Key  : FailFast.Name
    Value: FATAL_APP_EXIT

    Key  : FailFast.Type
    Value: 7

    Key  : Timeline.Process.Start.DeltaSec
    Value: 1

    Key  : WER.OS.Branch
    Value: co_release

    Key  : WER.OS.Timestamp
    Value: 2021-06-04T16:28:00Z

    Key  : WER.OS.Version
    Value: 10.0.22000.1

    Key  : WER.Process.Version
    Value: 1.13.2204.8004


FILE_IN_CAB:  WindowsTerminal.exe.6404.dmp

NTGLOBALFLAG:  0

PROCESS_BAM_CURRENT_THROTTLED: 0

PROCESS_BAM_PREVIOUS_THROTTLED: 0

APPLICATION_VERIFIER_FLAGS:  0

CONTEXT:  000000fc9b4feed0 -- (.cxr 0xfc9b4feed0)
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=0000000000000000 rsp=0000000000000000 rbp=0000000000000000
 r8=0000000000000000  r9=0000000000000000 r10=0000000000000000
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up di pl nz na pe nc
cs=0000  ss=0000  ds=0000  es=0000  fs=0000  gs=0000             efl=00000000
00000000`00000000 ??              ???
Resetting default scope

EXCEPTION_RECORD:  (.exr -1)
ExceptionAddress: 00007ffe71dedd7e (ucrtbase!abort+0x000000000000004e)
   ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  ExceptionFlags: 00000001
NumberParameters: 1
   Parameter[0]: 0000000000000007
Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT 

PROCESS_NAME:  WindowsTerminal.exe

ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_CODE_STR:  c0000409

EXCEPTION_PARAMETER1:  0000000000000007

FAULTING_THREAD:  00003988

STACK_TEXT:  
000000fc`9b4fdcb0 00007ffe`71ded499     : 000000fc`00000003 000000fc`00000003 00007ffe`4bde62b0 00007ffe`4bde6280 : ucrtbase!abort+0x4e
000000fc`9b4fdce0 00007ffe`66551aab     : 000000fc`9b4ff020 000000fc`9b4fde10 000000fc`9b4fe600 000000fc`9b4fdfc0 : ucrtbase!terminate+0x29
000000fc`9b4fdd10 00007ffe`66552317     : 00007ffe`72378aa0 00000000`00000000 000000fc`9b4fde70 00007ffe`4bdd2529 : VCRUNTIME140_1!FindHandler<__FrameHandler4>+0x45b
000000fc`9b4fdee0 00007ffe`66554119     : 00007ff6`61d90000 000000fc`9b4ff020 000000fc`9b4fe7e0 000000fc`9b4fe600 : VCRUNTIME140_1!__InternalCxxFrameHandler<__FrameHandler4>+0x267
000000fc`9b4fdf80 00007ff6`61da35d8     : 000000fc`9b4ff510 00007ff6`61dd16c0 000000fc`9b4ff020 000000fc`9b4ff510 : VCRUNTIME140_1!__CxxFrameHandler4+0xa9
000000fc`9b4fdff0 00007ffe`74188e4f     : 00000000`00000000 000000fc`9b4fe5b0 000000fc`9b4ff020 00000000`00000081 : WindowsTerminal!__GSHandlerCheck_EH4+0x64
000000fc`9b4fe020 00007ffe`74115e9a     : 000000fc`9b4ff020 00007ff6`61d90000 00007ff6`61d9615a 00007ff6`61dde1b0 : ntdll!RtlpExecuteHandlerForException+0xf
000000fc`9b4fe050 00007ffe`74113163     : 00000000`00000000 000000fc`9b4feed0 00000000`00000000 00007ffe`741130cf : ntdll!RtlDispatchException+0x25a
000000fc`9b4fe7a0 00007ffe`7164474c     : 00000000`00000000 00007ff6`61dd7fe0 000000fc`9b4ff170 00000000`00000000 : ntdll!RtlRaiseException+0x163
000000fc`9b4ff000 00007ffe`4bdd64c0     : 00000000`00000000 00000000`00000000 000000fc`9b4ff180 00000000`00000000 : KERNELBASE!RaiseException+0x6c
000000fc`9b4ff0e0 00007ff6`61dad1e5     : 000002ee`81f9c210 00000000`80040155 00000000`80040155 000000fc`9b4ff928 : VCRUNTIME140!_CxxThrowException+0x90
000000fc`9b4ff140 00007ff6`61d95d41     : 000002ee`817926c8 000002ee`817926c8 000000fc`9b4ff928 000000fc`9b4ff928 : WindowsTerminal!winrt::throw_hresult+0x251
000000fc`9b4ff1a0 00007ff6`61d9615a     : 00000000`00000000 000002ee`817926c8 000000fc`9b4ff928 000000fc`9b4ff910 : WindowsTerminal!AppHost::_HandleCommandlineArgs+0xe71
000000fc`9b4ff510 00007ff6`61d9128e     : 00000000`0000000a 00000000`0000000a 00000000`00000000 00000000`00000000 : WindowsTerminal!AppHost::AppHost+0x37a
000000fc`9b4ff820 00007ff6`61d9c8d2     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal!wWinMain+0x11e
000000fc`9b4ffbf0 00007ffe`733354e0     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal!__scrt_common_main_seh+0x106
000000fc`9b4ffc30 00007ffe`740e485b     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x10
000000fc`9b4ffc60 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x2b


STACK_COMMAND:  ~0s ; .cxr ; kb

SYMBOL_NAME:  ucrtbase!abort+4e

MODULE_NAME: ucrtbase

IMAGE_NAME:  ucrtbase.dll

FAILURE_BUCKET_ID:  FAIL_FAST_FATAL_APP_EXIT_c0000409_ucrtbase.dll!abort

OS_VERSION:  10.0.22000.1

BUILDLAB_STR:  co_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

IMAGE_VERSION:  10.0.22000.1

FAILURE_ID_HASH:  {e31753ac-c98a-8055-3663-47e707543d20}

Followup:     MachineOwner
@ianjoneill commented on GitHub (May 25, 2022): @zadjii-msft I've had another one of these crashes recently apparently - on 2022-05-19. Now that debug symbols are available, it looks like the crash (assuming it's the same) is somewhere in `WindowManager::ProposeCommandline()`, which I know is your domain! For some reason WinDbg isn't giving the the line number in `ProposeCommandline()` - I'm not sure why... ![image](https://user-images.githubusercontent.com/5821575/170263256-79186e8e-40e3-4355-9607-2730928c1242.png) I can email over the dump if that's useful. Output of `!analyze -v`: ``` ******************************************************************************* * * * Exception Analysis * * * ******************************************************************************* KEY_VALUES_STRING: 1 Key : Analysis.CPU.mSec Value: 1812 Key : Analysis.DebugAnalysisManager Value: Create Key : Analysis.Elapsed.mSec Value: 2370 Key : Analysis.Init.CPU.mSec Value: 952 Key : Analysis.Init.Elapsed.mSec Value: 40562 Key : Analysis.Memory.CommitPeak.Mb Value: 399 Key : FailFast.Name Value: FATAL_APP_EXIT Key : FailFast.Type Value: 7 Key : Timeline.Process.Start.DeltaSec Value: 1 Key : WER.OS.Branch Value: co_release Key : WER.OS.Timestamp Value: 2021-06-04T16:28:00Z Key : WER.OS.Version Value: 10.0.22000.1 Key : WER.Process.Version Value: 1.13.2204.8004 FILE_IN_CAB: WindowsTerminal.exe.6404.dmp NTGLOBALFLAG: 0 PROCESS_BAM_CURRENT_THROTTLED: 0 PROCESS_BAM_PREVIOUS_THROTTLED: 0 APPLICATION_VERIFIER_FLAGS: 0 CONTEXT: 000000fc9b4feed0 -- (.cxr 0xfc9b4feed0) rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000 rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000 rip=0000000000000000 rsp=0000000000000000 rbp=0000000000000000 r8=0000000000000000 r9=0000000000000000 r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up di pl nz na pe nc cs=0000 ss=0000 ds=0000 es=0000 fs=0000 gs=0000 efl=00000000 00000000`00000000 ?? ??? Resetting default scope EXCEPTION_RECORD: (.exr -1) ExceptionAddress: 00007ffe71dedd7e (ucrtbase!abort+0x000000000000004e) ExceptionCode: c0000409 (Security check failure or stack buffer overrun) ExceptionFlags: 00000001 NumberParameters: 1 Parameter[0]: 0000000000000007 Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT PROCESS_NAME: WindowsTerminal.exe ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application. EXCEPTION_CODE_STR: c0000409 EXCEPTION_PARAMETER1: 0000000000000007 FAULTING_THREAD: 00003988 STACK_TEXT: 000000fc`9b4fdcb0 00007ffe`71ded499 : 000000fc`00000003 000000fc`00000003 00007ffe`4bde62b0 00007ffe`4bde6280 : ucrtbase!abort+0x4e 000000fc`9b4fdce0 00007ffe`66551aab : 000000fc`9b4ff020 000000fc`9b4fde10 000000fc`9b4fe600 000000fc`9b4fdfc0 : ucrtbase!terminate+0x29 000000fc`9b4fdd10 00007ffe`66552317 : 00007ffe`72378aa0 00000000`00000000 000000fc`9b4fde70 00007ffe`4bdd2529 : VCRUNTIME140_1!FindHandler<__FrameHandler4>+0x45b 000000fc`9b4fdee0 00007ffe`66554119 : 00007ff6`61d90000 000000fc`9b4ff020 000000fc`9b4fe7e0 000000fc`9b4fe600 : VCRUNTIME140_1!__InternalCxxFrameHandler<__FrameHandler4>+0x267 000000fc`9b4fdf80 00007ff6`61da35d8 : 000000fc`9b4ff510 00007ff6`61dd16c0 000000fc`9b4ff020 000000fc`9b4ff510 : VCRUNTIME140_1!__CxxFrameHandler4+0xa9 000000fc`9b4fdff0 00007ffe`74188e4f : 00000000`00000000 000000fc`9b4fe5b0 000000fc`9b4ff020 00000000`00000081 : WindowsTerminal!__GSHandlerCheck_EH4+0x64 000000fc`9b4fe020 00007ffe`74115e9a : 000000fc`9b4ff020 00007ff6`61d90000 00007ff6`61d9615a 00007ff6`61dde1b0 : ntdll!RtlpExecuteHandlerForException+0xf 000000fc`9b4fe050 00007ffe`74113163 : 00000000`00000000 000000fc`9b4feed0 00000000`00000000 00007ffe`741130cf : ntdll!RtlDispatchException+0x25a 000000fc`9b4fe7a0 00007ffe`7164474c : 00000000`00000000 00007ff6`61dd7fe0 000000fc`9b4ff170 00000000`00000000 : ntdll!RtlRaiseException+0x163 000000fc`9b4ff000 00007ffe`4bdd64c0 : 00000000`00000000 00000000`00000000 000000fc`9b4ff180 00000000`00000000 : KERNELBASE!RaiseException+0x6c 000000fc`9b4ff0e0 00007ff6`61dad1e5 : 000002ee`81f9c210 00000000`80040155 00000000`80040155 000000fc`9b4ff928 : VCRUNTIME140!_CxxThrowException+0x90 000000fc`9b4ff140 00007ff6`61d95d41 : 000002ee`817926c8 000002ee`817926c8 000000fc`9b4ff928 000000fc`9b4ff928 : WindowsTerminal!winrt::throw_hresult+0x251 000000fc`9b4ff1a0 00007ff6`61d9615a : 00000000`00000000 000002ee`817926c8 000000fc`9b4ff928 000000fc`9b4ff910 : WindowsTerminal!AppHost::_HandleCommandlineArgs+0xe71 000000fc`9b4ff510 00007ff6`61d9128e : 00000000`0000000a 00000000`0000000a 00000000`00000000 00000000`00000000 : WindowsTerminal!AppHost::AppHost+0x37a 000000fc`9b4ff820 00007ff6`61d9c8d2 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal!wWinMain+0x11e 000000fc`9b4ffbf0 00007ffe`733354e0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal!__scrt_common_main_seh+0x106 000000fc`9b4ffc30 00007ffe`740e485b : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x10 000000fc`9b4ffc60 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x2b STACK_COMMAND: ~0s ; .cxr ; kb SYMBOL_NAME: ucrtbase!abort+4e MODULE_NAME: ucrtbase IMAGE_NAME: ucrtbase.dll FAILURE_BUCKET_ID: FAIL_FAST_FATAL_APP_EXIT_c0000409_ucrtbase.dll!abort OS_VERSION: 10.0.22000.1 BUILDLAB_STR: co_release OSPLATFORM_TYPE: x64 OSNAME: Windows 10 IMAGE_VERSION: 10.0.22000.1 FAILURE_ID_HASH: {e31753ac-c98a-8055-3663-47e707543d20} Followup: MachineOwner ```
Author
Owner

@ianjoneill commented on GitHub (May 25, 2022):

OK so I'm not seeing a line number, because apparently there aren't any symbols for the remoting module:

0:000> lml
start             end                 module name
000002ee`ff080000 000002ee`ff086000   Microsoft_Terminal_Remoting_2eeff080000 C (no symbols)           
00007ff6`61d90000 00007ff6`61e0d000   WindowsTerminal   (private pdb symbols)  f:\symbols\WindowsTerminal.pdb\7105E125CF12495CB052960B96C6D5261\WindowsTerminal.pdb
...
@ianjoneill commented on GitHub (May 25, 2022): OK so I'm not seeing a line number, because apparently there aren't any symbols for the remoting module: ``` 0:000> lml start end module name 000002ee`ff080000 000002ee`ff086000 Microsoft_Terminal_Remoting_2eeff080000 C (no symbols) 00007ff6`61d90000 00007ff6`61e0d000 WindowsTerminal (private pdb symbols) f:\symbols\WindowsTerminal.pdb\7105E125CF12495CB052960B96C6D5261\WindowsTerminal.pdb ... ```
Author
Owner

@zadjii-msft commented on GitHub (May 25, 2022):

@ianjoneill Which Terminal version are you on? That stack looks awfully a lot like the ones that should have been fixed in {#12666, #12838, #12825}.

Failure hash {53231a3c-a7ad-15be-67fb-05120d4c1d20} (MSFT:38542548) looks like it's still active on Terminal Preview 1.13.1098*.0, but I can't find ANY dumps reported for {e31753ac-c98a-8055-3663-47e707543d20}

There's also apparently been a single hit of 6483b1ae-b101-d12c-e7e2-7fb21af6f2b4 on 1.14, which is ANOTHER hash of this same FAIL_FAST_FATAL_APP_EXIT_CPP_EXCEPTION_c0000409_WindowsTerminal.exe!AppHost::_HandleCommandlineArgs crash. So annoying. Oh, wait, this one's the ARM version of 53231a3c-a7ad-15be-67fb-05120d4c1d20 above. Ignore me.

@zadjii-msft commented on GitHub (May 25, 2022): @ianjoneill Which Terminal version are you on? That stack looks awfully a lot like the ones that should have been fixed in {#12666, #12838, #12825}. Failure hash `{53231a3c-a7ad-15be-67fb-05120d4c1d20}` (MSFT:38542548) looks like it's still active on Terminal Preview 1.13.1098*.0, but I can't find ANY dumps reported for {e31753ac-c98a-8055-3663-47e707543d20} ~There's also apparently been a single hit of `6483b1ae-b101-d12c-e7e2-7fb21af6f2b4` on 1.14, which is ANOTHER hash of this same `FAIL_FAST_FATAL_APP_EXIT_CPP_EXCEPTION_c0000409_WindowsTerminal.exe!AppHost::_HandleCommandlineArgs` crash. So annoying.~ Oh, wait, this one's the ARM version of `53231a3c-a7ad-15be-67fb-05120d4c1d20` above. Ignore me.
Author
Owner

@ianjoneill commented on GitHub (May 25, 2022):

The crash was from version 1.13.10984.0.

@ianjoneill commented on GitHub (May 25, 2022): The crash was from version 1.13.10984.0.
Author
Owner

@ianjoneill commented on GitHub (Jun 3, 2022):

Just got another one of these on 1.14.1452.0 - again during a defapp launch on login. I may have been imagining it, but I think there were 2 terminal windows opened in quick succession.

Oddly the hash bucket detailed in event viewer is different to that reported by WinDbg - maybe that's why you couldn't find it last time?

Analysis symbol: 
Rechecking for solution: 0
Report Id: 6fbc501e-e9a0-4c00-8977-e281faca86d7
Report Status: 268435456
Hashed bucket: f02670cbb02490753f72a589ea205c7b
Cab Guid: 0

There don't appear to be debug symbols for the remoting module of the terminal again, which is a little annoying if you can't find the trace on your end. Any ideas why?

`analyze -v` output
*******************************************************************************
*                                                                             *
*                        Exception Analysis                                   *
*                                                                             *
*******************************************************************************

DEBUG_FLR_EXCEPTION_CODE(80040155) and the ".exr -1" ExceptionCode(c0000409) don't match

KEY_VALUES_STRING: 1

    Key  : Analysis.CPU.mSec
    Value: 687

    Key  : Analysis.DebugAnalysisManager
    Value: Create

    Key  : Analysis.Elapsed.mSec
    Value: 835

    Key  : Analysis.Init.CPU.mSec
    Value: 733

    Key  : Analysis.Init.Elapsed.mSec
    Value: 26846

    Key  : Analysis.Memory.CommitPeak.Mb
    Value: 163

    Key  : FailFast.Name
    Value: FATAL_APP_EXIT

    Key  : FailFast.Type
    Value: 7

    Key  : Timeline.Process.Start.DeltaSec
    Value: 1

    Key  : WER.OS.Branch
    Value: co_release

    Key  : WER.OS.Timestamp
    Value: 2021-06-04T16:28:00Z

    Key  : WER.OS.Version
    Value: 10.0.22000.1

    Key  : WER.Process.Version
    Value: 1.14.2205.25002

    Key  : WinRT.Throw.HResult
    Value: 80040155


FILE_IN_CAB:  WindowsTerminal.exe.18832.dmp

NTGLOBALFLAG:  0

PROCESS_BAM_CURRENT_THROTTLED: 0

PROCESS_BAM_PREVIOUS_THROTTLED: 0

APPLICATION_VERIFIER_FLAGS:  0

CONTEXT:  0000001f218feaa0 -- (.cxr 0x1f218feaa0)
rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000
rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000
rip=0000000000000000 rsp=0000000000000000 rbp=0000000000000000
 r8=0000000000000000  r9=0000000000000000 r10=0000000000000000
r11=0000000000000000 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0         nv up di pl nz na pe nc
cs=0000  ss=0000  ds=0000  es=0000  fs=0000  gs=0000             efl=00000000
00000000`00000000 ??              ???
Resetting default scope

EXCEPTION_RECORD:  (.exr -1)
ExceptionAddress: 00007ff92d42dd7e (ucrtbase!abort+0x000000000000004e)
   ExceptionCode: c0000409 (Security check failure or stack buffer overrun)
  ExceptionFlags: 00000001
NumberParameters: 1
   Parameter[0]: 0000000000000007
Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT 

PROCESS_NAME:  WindowsTerminal.exe

ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application.

EXCEPTION_CODE_STR:  80040155

EXCEPTION_PARAMETER1:  0000000000000007

FAULTING_THREAD:  00004d30

STACK_TEXT:  
0000001f`218fd880 00007ff9`2d42d499     : 0000001f`00000003 0000001f`00000003 00007ff9`10b662b0 00007ff9`10b66280 : ucrtbase!abort+0x4e
0000001f`218fd8b0 00007ff9`21141aab     : 0000001f`218febf0 0000001f`218fd9e0 0000001f`218fe1d0 0000001f`218fdb90 : ucrtbase!terminate+0x29
0000001f`218fd8e0 00007ff9`21142317     : 0000001f`218fed50 00000000`00100000 00000000`00000001 00007ff9`10b52529 : VCRUNTIME140_1!FindHandler<__FrameHandler4>+0x45b
0000001f`218fdab0 00007ff9`21144119     : 00007ff6`78200000 0000001f`218febf0 0000001f`218fe3b0 0000001f`218fe1d0 : VCRUNTIME140_1!__InternalCxxFrameHandler<__FrameHandler4>+0x267
0000001f`218fdb50 00007ff6`78213148     : 0000001f`218ff160 00007ff6`782446b8 0000001f`218febf0 0000001f`218ff160 : VCRUNTIME140_1!__CxxFrameHandler4+0xa9
0000001f`218fdbc0 00007ff9`2f8e8e4f     : 00000000`00000000 0000001f`218fe180 0000001f`218febf0 00000000`00000081 : WindowsTerminal!__GSHandlerCheck_EH4+0x64
0000001f`218fdbf0 00007ff9`2f875e9a     : 0000001f`218febf0 00007ff6`78200000 00007ff6`782054d0 00007ff6`782510f0 : ntdll!RtlpExecuteHandlerForException+0xf
0000001f`218fdc20 00007ff9`2f873163     : 00000000`00000000 0000001f`218feaa0 00000000`00000000 00007ff9`2f8730cf : ntdll!RtlDispatchException+0x25a
0000001f`218fe370 00007ff9`2cf5474c     : 00000000`00000000 00007ff6`7824af30 0000001f`218fed40 00000000`00000000 : ntdll!RtlRaiseException+0x163
0000001f`218febd0 00007ff9`10b564c0     : 00000000`00000000 00000000`00000000 0000001f`218fed40 00000000`00000000 : KERNELBASE!RaiseException+0x6c
0000001f`218fecb0 00007ff6`7821eb05     : 0000018b`b1b51c00 00000000`80040155 00000000`80040155 0000018b`b1b76bb0 : VCRUNTIME140!_CxxThrowException+0x90
0000001f`218fed10 00007ff6`78215bc2     : 0000018b`ab29c348 0000018b`ab29c348 0000018b`b1b76bb0 0000018b`b1b76c58 : WindowsTerminal!winrt::throw_hresult+0x251
0000001f`218fed70 00007ff6`782054d0     : 00000000`00000000 0000018b`ab29c348 00000000`00000000 0000001f`218ff5a8 : WindowsTerminal!AppHost::_HandleCommandlineArgs+0x11532
0000001f`218ff160 00007ff6`782078fe     : 00000000`0000000a 00000000`0000000a 00000000`00000000 00000000`00000000 : WindowsTerminal!AppHost::AppHost+0x3a0
0000001f`218ff4a0 00007ff6`7820d3c2     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal!wWinMain+0x11e
0000001f`218ff890 00007ff9`2dd054e0     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal!__scrt_common_main_seh+0x106
0000001f`218ff8d0 00007ff9`2f84485b     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x10
0000001f`218ff900 00000000`00000000     : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x2b


STACK_COMMAND:  ~0s ; .cxr ; kb

SYMBOL_NAME:  ucrtbase!abort+4e

MODULE_NAME: ucrtbase

IMAGE_NAME:  ucrtbase.dll

FAILURE_BUCKET_ID:  FAIL_FAST_FATAL_APP_EXIT_80040155_ucrtbase.dll!abort

OS_VERSION:  10.0.22000.1

BUILDLAB_STR:  co_release

OSPLATFORM_TYPE:  x64

OSNAME:  Windows 10

IMAGE_VERSION:  10.0.22000.1

FAILURE_ID_HASH:  {99b92e88-560f-20ef-742d-c8fd513ad30b}

Followup:     MachineOwner
---------
@ianjoneill commented on GitHub (Jun 3, 2022): Just got another one of these on 1.14.1452.0 - again during a defapp launch on login. I may have been imagining it, but I _think_ there were 2 terminal windows opened in quick succession. Oddly the hash bucket detailed in event viewer is different to that reported by WinDbg - maybe that's why you couldn't find it last time? ``` Analysis symbol: Rechecking for solution: 0 Report Id: 6fbc501e-e9a0-4c00-8977-e281faca86d7 Report Status: 268435456 Hashed bucket: f02670cbb02490753f72a589ea205c7b Cab Guid: 0 ``` There don't appear to be debug symbols for the remoting module of the terminal again, which is a little annoying if you can't find the trace on your end. Any ideas why? <details> <summary>`analyze -v` output</summary> ``` ******************************************************************************* * * * Exception Analysis * * * ******************************************************************************* DEBUG_FLR_EXCEPTION_CODE(80040155) and the ".exr -1" ExceptionCode(c0000409) don't match KEY_VALUES_STRING: 1 Key : Analysis.CPU.mSec Value: 687 Key : Analysis.DebugAnalysisManager Value: Create Key : Analysis.Elapsed.mSec Value: 835 Key : Analysis.Init.CPU.mSec Value: 733 Key : Analysis.Init.Elapsed.mSec Value: 26846 Key : Analysis.Memory.CommitPeak.Mb Value: 163 Key : FailFast.Name Value: FATAL_APP_EXIT Key : FailFast.Type Value: 7 Key : Timeline.Process.Start.DeltaSec Value: 1 Key : WER.OS.Branch Value: co_release Key : WER.OS.Timestamp Value: 2021-06-04T16:28:00Z Key : WER.OS.Version Value: 10.0.22000.1 Key : WER.Process.Version Value: 1.14.2205.25002 Key : WinRT.Throw.HResult Value: 80040155 FILE_IN_CAB: WindowsTerminal.exe.18832.dmp NTGLOBALFLAG: 0 PROCESS_BAM_CURRENT_THROTTLED: 0 PROCESS_BAM_PREVIOUS_THROTTLED: 0 APPLICATION_VERIFIER_FLAGS: 0 CONTEXT: 0000001f218feaa0 -- (.cxr 0x1f218feaa0) rax=0000000000000000 rbx=0000000000000000 rcx=0000000000000000 rdx=0000000000000000 rsi=0000000000000000 rdi=0000000000000000 rip=0000000000000000 rsp=0000000000000000 rbp=0000000000000000 r8=0000000000000000 r9=0000000000000000 r10=0000000000000000 r11=0000000000000000 r12=0000000000000000 r13=0000000000000000 r14=0000000000000000 r15=0000000000000000 iopl=0 nv up di pl nz na pe nc cs=0000 ss=0000 ds=0000 es=0000 fs=0000 gs=0000 efl=00000000 00000000`00000000 ?? ??? Resetting default scope EXCEPTION_RECORD: (.exr -1) ExceptionAddress: 00007ff92d42dd7e (ucrtbase!abort+0x000000000000004e) ExceptionCode: c0000409 (Security check failure or stack buffer overrun) ExceptionFlags: 00000001 NumberParameters: 1 Parameter[0]: 0000000000000007 Subcode: 0x7 FAST_FAIL_FATAL_APP_EXIT PROCESS_NAME: WindowsTerminal.exe ERROR_CODE: (NTSTATUS) 0xc0000409 - The system detected an overrun of a stack-based buffer in this application. This overrun could potentially allow a malicious user to gain control of this application. EXCEPTION_CODE_STR: 80040155 EXCEPTION_PARAMETER1: 0000000000000007 FAULTING_THREAD: 00004d30 STACK_TEXT: 0000001f`218fd880 00007ff9`2d42d499 : 0000001f`00000003 0000001f`00000003 00007ff9`10b662b0 00007ff9`10b66280 : ucrtbase!abort+0x4e 0000001f`218fd8b0 00007ff9`21141aab : 0000001f`218febf0 0000001f`218fd9e0 0000001f`218fe1d0 0000001f`218fdb90 : ucrtbase!terminate+0x29 0000001f`218fd8e0 00007ff9`21142317 : 0000001f`218fed50 00000000`00100000 00000000`00000001 00007ff9`10b52529 : VCRUNTIME140_1!FindHandler<__FrameHandler4>+0x45b 0000001f`218fdab0 00007ff9`21144119 : 00007ff6`78200000 0000001f`218febf0 0000001f`218fe3b0 0000001f`218fe1d0 : VCRUNTIME140_1!__InternalCxxFrameHandler<__FrameHandler4>+0x267 0000001f`218fdb50 00007ff6`78213148 : 0000001f`218ff160 00007ff6`782446b8 0000001f`218febf0 0000001f`218ff160 : VCRUNTIME140_1!__CxxFrameHandler4+0xa9 0000001f`218fdbc0 00007ff9`2f8e8e4f : 00000000`00000000 0000001f`218fe180 0000001f`218febf0 00000000`00000081 : WindowsTerminal!__GSHandlerCheck_EH4+0x64 0000001f`218fdbf0 00007ff9`2f875e9a : 0000001f`218febf0 00007ff6`78200000 00007ff6`782054d0 00007ff6`782510f0 : ntdll!RtlpExecuteHandlerForException+0xf 0000001f`218fdc20 00007ff9`2f873163 : 00000000`00000000 0000001f`218feaa0 00000000`00000000 00007ff9`2f8730cf : ntdll!RtlDispatchException+0x25a 0000001f`218fe370 00007ff9`2cf5474c : 00000000`00000000 00007ff6`7824af30 0000001f`218fed40 00000000`00000000 : ntdll!RtlRaiseException+0x163 0000001f`218febd0 00007ff9`10b564c0 : 00000000`00000000 00000000`00000000 0000001f`218fed40 00000000`00000000 : KERNELBASE!RaiseException+0x6c 0000001f`218fecb0 00007ff6`7821eb05 : 0000018b`b1b51c00 00000000`80040155 00000000`80040155 0000018b`b1b76bb0 : VCRUNTIME140!_CxxThrowException+0x90 0000001f`218fed10 00007ff6`78215bc2 : 0000018b`ab29c348 0000018b`ab29c348 0000018b`b1b76bb0 0000018b`b1b76c58 : WindowsTerminal!winrt::throw_hresult+0x251 0000001f`218fed70 00007ff6`782054d0 : 00000000`00000000 0000018b`ab29c348 00000000`00000000 0000001f`218ff5a8 : WindowsTerminal!AppHost::_HandleCommandlineArgs+0x11532 0000001f`218ff160 00007ff6`782078fe : 00000000`0000000a 00000000`0000000a 00000000`00000000 00000000`00000000 : WindowsTerminal!AppHost::AppHost+0x3a0 0000001f`218ff4a0 00007ff6`7820d3c2 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal!wWinMain+0x11e 0000001f`218ff890 00007ff9`2dd054e0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : WindowsTerminal!__scrt_common_main_seh+0x106 0000001f`218ff8d0 00007ff9`2f84485b : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x10 0000001f`218ff900 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x2b STACK_COMMAND: ~0s ; .cxr ; kb SYMBOL_NAME: ucrtbase!abort+4e MODULE_NAME: ucrtbase IMAGE_NAME: ucrtbase.dll FAILURE_BUCKET_ID: FAIL_FAST_FATAL_APP_EXIT_80040155_ucrtbase.dll!abort OS_VERSION: 10.0.22000.1 BUILDLAB_STR: co_release OSPLATFORM_TYPE: x64 OSNAME: Windows 10 IMAGE_VERSION: 10.0.22000.1 FAILURE_ID_HASH: {99b92e88-560f-20ef-742d-c8fd513ad30b} Followup: MachineOwner --------- ``` </details>
Author
Owner

@zadjii-msft commented on GitHub (Jul 8, 2022):

FWIW this definitely hasn't gone away. I ultimately still don't know the root cause.

There's MSFT:38572983 that's got the same(ish) stack. Hard to be sure it's the same root cause, because basically any error in ProposeCommandline ends up in this same bucket under AppHost::_HandleCommandlineArgs.

I looked at a dump (6d7377b5-a84b-4a6b-8557-49d058063b39), for failure hash bc968a4d-8e74-054f-1bc1-9845eb660167, and in there, the crash was caused by a RPC_S_CALL_FAILED_DNE:

Return value/code Description
0x000006BF
RPC_S_CALL_FAILED_DNE
The remote procedure call failed, and execution on the server did not start. Implies the server was reachable at a certain point in time.

I bet we could just add that to the list of errors we're expecting to see.

Alternatively, we could just try the main body of code in the catch always. That body is used when we failed to ask the monarch to do something for us, at startup. Worst case scenario - there's a monarch alive that we can't communicate with, and some x-windowing stuff is wonky, but we'd probably just end up being a second monarch. IMO, that's probably safe enough. /cc @DHowett for thoughts.

ultimately, I have no idea if that crash is the same as what you're seeing, because the structure of the code here makes the diagnosis really hard. I can only hope fixing MSFT:38572983 would also fix this.

(bc968a4d-8e74-054f-1bc1-9845eb660167 represents 8.85% of our crashes in 1.14 stable so far)

@zadjii-msft commented on GitHub (Jul 8, 2022): FWIW this definitely hasn't gone away. I ultimately still don't know the root cause. There's MSFT:38572983 that's got the same(ish) stack. Hard to be sure it's the same root cause, because basically any error in `ProposeCommandline` ends up in this same bucket under `AppHost::_HandleCommandlineArgs`. I looked at a dump (`6d7377b5-a84b-4a6b-8557-49d058063b39`), for failure hash `bc968a4d-8e74-054f-1bc1-9845eb660167`, and in there, the crash was caused by a `RPC_S_CALL_FAILED_DNE`: Return value/code | Description -- | -- <a href="https://docs.microsoft.com/en-us/previous-versions/aa505946(v=msdn.10)">0x000006BF<br>RPC_S_CALL_FAILED_DNE</a> | The remote procedure call failed, and execution on the server did not start. Implies the server was reachable at a certain point in time. I bet we could just add that to the list of errors we're expecting to see. Alternatively, we could just try the main body of code in the `catch` _always_. That body is used when we failed to ask the monarch to do something for us, at startup. Worst case scenario - there's a monarch alive that we can't communicate with, and some x-windowing stuff is wonky, but we'd probably just end up being a second monarch. IMO, that's probably safe enough. /cc @DHowett for thoughts. **ultimately**, I have no idea if that crash is the same as what you're seeing, because the structure of the code here makes the diagnosis really hard. I can only hope fixing MSFT:38572983 would also fix this. _(`bc968a4d-8e74-054f-1bc1-9845eb660167` represents 8.85% of our crashes in 1.14 stable so far)_
Author
Owner

@DHowett commented on GitHub (Jul 8, 2022):

I definitely think that we should fail as gracefully as possible, and that crashing is not doing that. If we need to become an isolated monarch, or a second monarch, or whatever... as long as the terminal ends up open and usable, I prefer it over any other option. :)

@DHowett commented on GitHub (Jul 8, 2022): I definitely think that we should fail as gracefully as possible, and that crashing is _not_ doing that. If we need to become an isolated monarch, or a second monarch, or whatever... as long as the terminal ends up *open* and *usable*, I prefer it over any other option. :)
Author
Owner

@zadjii-msft commented on GitHub (Jul 29, 2022):

I suspect this was fixed in #13604, but I'm gonna leave this open till we find out for sure if this got them all.

@zadjii-msft commented on GitHub (Jul 29, 2022): I suspect this was fixed in #13604, but I'm gonna leave this open till we find out for sure if this got them all.
Author
Owner

@zadjii-msft commented on GitHub (Aug 18, 2022):

This was finally fixed in 1.15.2203 which isn't a real build number, but anything above that should have the fix ☺️

@zadjii-msft commented on GitHub (Aug 18, 2022): This _was_ finally fixed in 1.15.2203 which isn't a real build number, but anything above that should have the fix ☺️
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/terminal#15934