0x00007ffa2a593f92 <+146>: movups (%rcx,%rdx,1),%xmm00x00007ffa2a593f96 <+150>: add $0x10,%rcx
Do we have readers here?
PssCaptureSnapshot() with (PSS_CAPTURE_HANDLES | PSS_CAPTURE_THREADS) or PSS_CAPTURE_HANDLES allone on the calling process, GetCurrentProcess().
https://learn.microsoft.com/en-us/windows/win32/api/processsnapshot/nf-processsnapshot-psscapturesnapshot
On average, every second call results in EXCEPTION_ACCESS_VIOLATION at
#0 0x7FFA2A590F8D: <KiUserExceptionDispatcher()>+45
#1 0x7FFA2A593F25: <memcpy()>+37
#2 0x7FFA2A606120: <PssNtWalkSnapshot()>+6160
#3 0x7FFA2A606441: <PssNtWalkSnapshot()>+6961
#4 0x7FFA2A605CAB: <PssNtWalkSnapshot()>+5019
#5 0x7FFA2A603F22: <PssNtCaptureSnapshot()>+882
#6 0x7FFA280F00DD: <PssCaptureSnapshot()>+29
(my own inexact backtrace)
Within Debugger it runs 99,9% as wanted. Same results as Admin and OpenProcess() on self.
Does someone has a pointer? I suspect not an access violation but a read or write out of allocated memory.
Ah, GDB says SIGSEGV:
#0 0x00007ffa2a593f92 in ntdll!memmove () from C:\WINDOWS\SYSTEM32\ntdll.dll #1 0x00007ffa2a606121 in ntdll!PssNtWalkSnapshot () from C:\WINDOWS\SYSTEM32\ntdll.dll
#2 0x00007ffa2a606442 in ntdll!PssNtWalkSnapshot () from C:\WINDOWS\SYSTEM32\ntdll.dll
#3 0x00007ffa2a605cac in ntdll!PssNtWalkSnapshot () from C:\WINDOWS\SYSTEM32\ntdll.dll
#4 0x00007ffa2a603f23 in ntdll!PssNtCaptureSnapshot () from C:\WINDOWS\SYSTEM32\ntdll.dll
#5 0x00007ffa280f00de in PssCaptureSnapshot () from C:\WINDOWS\System32\KernelBase.dll
0x00007ffa2a593f89 <+137>: cmp %rcx,%r11
0x00007ffa2a593f8c <+140>: ja 0x7ffa2a594100 <ntdll!memmove+512>
0x00007ffa2a593f92 <+146>: movups (%rcx,%rdx,1),%xmm00x00007ffa2a593f96 <+150>: add $0x10,%rcx
0x00007ffa2a593f9a <+154>: test $0xf,%cl
0x00007ffa2a593f9d <+157>: je 0x7ffa2a593fb1 <ntdll!memmove+177>
Common mistake is miscalculation of data size or address of data
Sysop: | Keyop |
---|---|
Location: | Huddersfield, West Yorkshire, UK |
Users: | 379 |
Nodes: | 16 (2 / 14) |
Uptime: | 42:17:34 |
Calls: | 8,141 |
Calls today: | 4 |
Files: | 13,085 |
Messages: | 5,857,793 |