O'Reilly logo

Memory Dump Analysis Anthology, Volume 7 by Dmitry Vostokov

Stay ahead with the world's most comprehensive technology and business learning platform.

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, tutorials, and more.

Start Free Trial

No credit card required

Wait Chain (Pushlocks)

Here we provide examples of threads waiting for pushlocks18 as they are not normally seen in crash dumps:

THREAD fffffa80033b5b50  Cid 0004.0030  Teb: 0000000000000000 Win32Thread:
0000000000000000 WAIT: (WrPushLock) KernelMode Non-Alertable fffff880021d9750 SynchronizationEvent Not impersonating DeviceMap fffff8a0000088f0 Owning Process fffffa80033879e0 Image: System Attached Process fffffa800439c620 Image: AppA.exe Wait Start TickCount 30819 Ticks: 14746574 (2:15:54:08.028) Context Switch Count 2800 UserTime 00:00:00.000 KernelTime 00:00:00.374 Win32 Start Address nt!ExpWorkerThread (0xfffff8000189e530) Stack Init fffff880021d9db0 Current fffff880021d9470 Base fffff880021da000 Limit fffff880021d4000 Call 0 Priority ...

With Safari, you learn the way you learn best. Get unlimited access to videos, live online training, learning paths, books, interactive tutorials, and more.

Start Free Trial

No credit card required