is rpcexts! broken in windbg or is it more likely that im broken

is rpcexts! broken in windbg or is it more likely that im broken

i was trying to muck around with rpcexts! extension in latest windbg
but windbg is giving me errors

and there is only one google hit for the error in google groups and it
seems that query is unresolved

os = xp sp2
windbg version = latest

0:000> !version
Free RPC Extension dll for Build 6526

0:000> version
Windows XP Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: SingleUserTS
kernel32.dll version: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Debug session time: Thu Sep 18 03:41:13.224 2008 (GMT+5)

Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
Copyright (c) Microsoft Corporation. All rights reserved.

errors as follows

0:000> !rpcexts.getcallinfo
Searching for call info …
OpenRPCDebugCallInfoEnumeration failed: 1734
0:000> !rpcexts.getclientcallinfo
Searching for call info …
OpenRPCDebugClientCallInfoEnumeration failed: 1734
0:000> |
. 0 id: 910 exited name: DoRPC_Client.exe
0:000> !rpcexts.getthreadinfo 1734
Searching for thread info …
OpenRPCDebugThreadInfoEnumeration failed: 1
0:000> !rpcexts.rpctime
Current time is: 015871.890 (0x003dff.37a)
0:000> !rpcexts.thread
Error: Failure to get address
0:000> !teb
TEB at 7ffdf000
ExceptionList: 0012ff40
StackBase: 00130000
StackLimit: 0012d000
SubSystemTib: 00000000
FiberData: 00001e00
ArbitraryUserPointer: 00000000
Self: 7ffdf000
EnvironmentPointer: 00000000
ClientId: 00000910 . 00000cec
RpcHandle: 00000000
Tls Storage: 00000000
PEB Address: 7ffd7000
LastErrorValue: 10061
LastStatusValue: c0000236
Count Owned Locks: 0
HardErrorMode: 0
0:000> !rpcexts.thread @teb
Error: Failure to get address
0:000> !rpcexts.thread @$teb
Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
0:000> !rpcexts.thread 7ffdf000
Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
0:000> !rpcexts.checkrpcsym
rpcexts has no checkrpcsym export
0:000> !rpcexts.eeinfo
Error: Failure to get address
0:000> !rpcexts.getendpointinfo
Searching for endpoint info …
OpenRPCDebugEndpointInfoEnumeration failed: 1734

here is a wt -l4 -or -oR -oa dump

24 45 [3] WS2_32!getaddrinfo eax = 0

> No match on ret
24 45 [3] WS2_32!getaddrinfo
39 0 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
call at 77e91501
5 0 [4] RPCRT4!__security_check_cookie eax = 0
44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress eax = 0
> No match on ret
44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
18 0 [3] RPCRT4!TCPOrHTTP_Open
call at 77eec1d6
ModLoad: 662b0000 66308000 C:\WINDOWS\system32\hnetcfg.dll
ModLoad: 77f10000 77f56000 C:\WINDOWS\system32\GDI32.dll
ModLoad: 77d40000 77dd0000 C:\WINDOWS\system32\USER32.dll
ModLoad: 71a90000 71a98000 C:\WINDOWS\System32\wshtcpip.dll
279 0 [4] RPCRT4!WS_Open eax = 6ba
25 279 [3] RPCRT4!TCPOrHTTP_Open
call at 77eec217
7 0 [4]
RPCRT4!IP_ADDRESS_RESOLVER::~IP_ADDRESS_RESOLVER eax = 1
29 286 [3] RPCRT4!TCPOrHTTP_Open
call at 77eec227
5 0 [4] RPCRT4!__security_check_cookie eax = 6ba
34 291 [3] RPCRT4!TCPOrHTTP_Open eax = 6ba
> No match on ret
34 291 [3] RPCRT4!TCPOrHTTP_Open
4 0 [3] RPCRT4!TCP_Open eax = 6ba
> No match on ret
4 0 [3] RPCRT4!TCP_Open
11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen eax = 6ba
> No match on ret
11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen
15 0 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
call at 77ea3e06
51 0 [4] RPCRT4!OSF_CASSOCIATION::ShutdownRequested eax = 0
23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind eax = 6ba
> No match on ret
23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
14 0 [3] RPCRT4!OSF_CCALL::BindToServer
call at 77ea3d56
14 0 [4] RPCRT4!OSF_CCALL::GetStatusForTimeout eax = 6ba
22 14 [3] RPCRT4!OSF_CCALL::BindToServer
call at 77e84e2a
10 0 [4] RPCRT4!REFERENCED_OBJECT::RemoveReference eax = 1
30 24 [3] RPCRT4!OSF_CCALL::BindToServer eax = 6ba
> No match on ret
30 24 [3] RPCRT4!OSF_CCALL::BindToServer
8 0 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
call at 77e84d76
54 0 [4] RPCRT4!OSF_CCALL::FreeCCall eax = 0
11 54 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
call at 77e8019a
13 0 [4] RPCRT4!CLIENT_AUTH_INFO::~CLIENT_AUTH_INFO
eax = 12fc01
17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall eax = 6ba
> No match on ret
17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
25 0 [3]
RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax eax = 6ba
> No match on ret
25 0 [3] RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax
7 0 [3] RPCRT4!I_RpcGetBufferWithObject eax = 6ba
> No match on ret
7 0 [3] RPCRT4!I_RpcGetBufferWithObject
2 0 [3] RPCRT4!I_RpcGetBuffer eax = 6ba
> No match on ret
2 0 [3] RPCRT4!I_RpcGetBuffer
7 0 [3] RPCRT4!NdrGetBuffer
call at 77ea3bc1
11 0 [4] RPCRT4!RpcRaiseException
(910.cec): Unknown exception - code 000006ba (first chance)
eax=77c3b8c1 ebx=00000000 ecx=003423d8 edx=77c61ae8 esi=7c90e88e edi=00000000
eip=7c90eb94 esp=0012fe54 ebp=0012ff50 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:

any pointers to resolve this issue are welcome

ps

yes i checked dbgrpc too that is also giving errors

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -c
Searching for call info …
OpenRPCDebugCallInfoEnumeration failed: 1734

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -a
Searching for call info …
OpenRPCDebugClientCallInfoEnumeration failed: 1734

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -e
Searching for endpoint info …
OpenRPCDebugEndpointInfoEnumeration failed: 1734

C:\Program Files\Debugging Tools for Windows (x86)>

regards

raj_r

is rpcexts! broken in windbg or is it more likely that im broken

i was trying to muck around with rpcexts! extension in latest windbg
but windbg is giving me errors

and there is only one google hit for the error in google groups and it
seems that query is unresolved

http://groups.google.co.mz/group/microsoft.public.windbg/browse_thread/thread/f0a50fac946cff9d

os = xp sp2
windbg version = latest

0:000> !version
Free RPC Extension dll for Build 6526

0:000> version
Windows XP Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: SingleUserTS
kernel32.dll version: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Debug session time: Thu Sep 18 03:41:13.224 2008 (GMT+5)

Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
Copyright (c) Microsoft Corporation. All rights reserved.

errors as follows

0:000> !rpcexts.getcallinfo
Searching for call info …
OpenRPCDebugCallInfoEnumeration failed: 1734
0:000> !rpcexts.getclientcallinfo
Searching for call info …
OpenRPCDebugClientCallInfoEnumeration failed: 1734
0:000> |
. 0 id: 910 exited name: DoRPC_Client.exe
0:000> !rpcexts.getthreadinfo 1734
Searching for thread info …
OpenRPCDebugThreadInfoEnumeration failed: 1
0:000> !rpcexts.rpctime
Current time is: 015871.890 (0x003dff.37a)
0:000> !rpcexts.thread
Error: Failure to get address
0:000> !teb
TEB at 7ffdf000
ExceptionList: 0012ff40
StackBase: 00130000
StackLimit: 0012d000
SubSystemTib: 00000000
FiberData: 00001e00
ArbitraryUserPointer: 00000000
Self: 7ffdf000
EnvironmentPointer: 00000000
ClientId: 00000910 . 00000cec
RpcHandle: 00000000
Tls Storage: 00000000
PEB Address: 7ffd7000
LastErrorValue: 10061
LastStatusValue: c0000236
Count Owned Locks: 0
HardErrorMode: 0
0:000> !rpcexts.thread @teb
Error: Failure to get address
0:000> !rpcexts.thread @$teb
Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
0:000> !rpcexts.thread 7ffdf000
Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
0:000> !rpcexts.checkrpcsym
rpcexts has no checkrpcsym export
0:000> !rpcexts.eeinfo
Error: Failure to get address
0:000> !rpcexts.getendpointinfo
Searching for endpoint info …
OpenRPCDebugEndpointInfoEnumeration failed: 1734

here is a wt -l4 -or -oR -oa dump

24 45 [3] WS2_32!getaddrinfo eax = 0

> No match on ret
24 45 [3] WS2_32!getaddrinfo
39 0 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
call at 77e91501
5 0 [4] RPCRT4!__security_check_cookie eax = 0
44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress eax = 0
> No match on ret
44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
18 0 [3] RPCRT4!TCPOrHTTP_Open
call at 77eec1d6
ModLoad: 662b0000 66308000 C:\WINDOWS\system32\hnetcfg.dll
ModLoad: 77f10000 77f56000 C:\WINDOWS\system32\GDI32.dll
ModLoad: 77d40000 77dd0000 C:\WINDOWS\system32\USER32.dll
ModLoad: 71a90000 71a98000 C:\WINDOWS\System32\wshtcpip.dll
279 0 [4] RPCRT4!WS_Open eax = 6ba
25 279 [3] RPCRT4!TCPOrHTTP_Open
call at 77eec217
7 0 [4]
RPCRT4!IP_ADDRESS_RESOLVER::~IP_ADDRESS_RESOLVER eax = 1
29 286 [3] RPCRT4!TCPOrHTTP_Open
call at 77eec227
5 0 [4] RPCRT4!__security_check_cookie eax = 6ba
34 291 [3] RPCRT4!TCPOrHTTP_Open eax = 6ba
> No match on ret
34 291 [3] RPCRT4!TCPOrHTTP_Open
4 0 [3] RPCRT4!TCP_Open eax = 6ba
> No match on ret
4 0 [3] RPCRT4!TCP_Open
11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen eax = 6ba
> No match on ret
11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen
15 0 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
call at 77ea3e06
51 0 [4] RPCRT4!OSF_CASSOCIATION::ShutdownRequested eax = 0
23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind eax = 6ba
> No match on ret
23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
14 0 [3] RPCRT4!OSF_CCALL::BindToServer
call at 77ea3d56
14 0 [4] RPCRT4!OSF_CCALL::GetStatusForTimeout eax = 6ba
22 14 [3] RPCRT4!OSF_CCALL::BindToServer
call at 77e84e2a
10 0 [4] RPCRT4!REFERENCED_OBJECT::RemoveReference eax = 1
30 24 [3] RPCRT4!OSF_CCALL::BindToServer eax = 6ba
> No match on ret
30 24 [3] RPCRT4!OSF_CCALL::BindToServer
8 0 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
call at 77e84d76
54 0 [4] RPCRT4!OSF_CCALL::FreeCCall eax = 0
11 54 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
call at 77e8019a
13 0 [4] RPCRT4!CLIENT_AUTH_INFO::~CLIENT_AUTH_INFO
eax = 12fc01
17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall eax = 6ba
> No match on ret
17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
25 0 [3]
RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax eax = 6ba
> No match on ret
25 0 [3] RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax
7 0 [3] RPCRT4!I_RpcGetBufferWithObject eax = 6ba
> No match on ret
7 0 [3] RPCRT4!I_RpcGetBufferWithObject
2 0 [3] RPCRT4!I_RpcGetBuffer eax = 6ba
> No match on ret
2 0 [3] RPCRT4!I_RpcGetBuffer
7 0 [3] RPCRT4!NdrGetBuffer
call at 77ea3bc1
11 0 [4] RPCRT4!RpcRaiseException
(910.cec): Unknown exception - code 000006ba (first chance)
eax=77c3b8c1 ebx=00000000 ecx=003423d8 edx=77c61ae8 esi=7c90e88e edi=00000000
eip=7c90eb94 esp=0012fe54 ebp=0012ff50 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:

any pointers to resolve this issue are welcome

ps

yes i checked dbgrpc too that is also giving errors

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -c
Searching for call info …
OpenRPCDebugCallInfoEnumeration failed: 1734

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -a
Searching for call info …
OpenRPCDebugClientCallInfoEnumeration failed: 1734

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -e
Searching for endpoint info …
OpenRPCDebugEndpointInfoEnumeration failed: 1734

C:\Program Files\Debugging Tools for Windows (x86)>

regards

raj_r

Just to rule out the obvious, have you configured RPC to preserve/enable state information? Given your very knowledge of the ways
of the debugger, I imagine that you already know this, but in case note, I recall that running dbgrpc -e without setting the group
policy for the target (and rebooting, or maybe just waiting a while will do it - not sure) will produce error 1734.

In GPEDIT.MSC:

Computer Configuration/Administrative Templates/System/Remote Procedure Call/RPC Troubleshooting State Information: Full

I haven’t done this in a while, and I know that ‘Full’ isn’t required, but I just set it to that because it works.

Good luck,

mm

raj_r wrote:

is rpcexts! broken in windbg or is it more likely that im broken

i was trying to muck around with rpcexts! extension in latest windbg
but windbg is giving me errors

and there is only one google hit for the error in google groups and it
seems that query is unresolved

http://groups.google.co.mz/group/microsoft.public.windbg/browse_thread/thread/f0a50fac946cff9d

os = xp sp2
windbg version = latest

0:000> !version
Free RPC Extension dll for Build 6526

0:000> version
Windows XP Version 2600 (Service Pack 2) UP Free x86 compatible
Product: WinNt, suite: SingleUserTS
kernel32.dll version: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
Debug session time: Thu Sep 18 03:41:13.224 2008 (GMT+5)

Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
Copyright (c) Microsoft Corporation. All rights reserved.

errors as follows

0:000> !rpcexts.getcallinfo
Searching for call info …
OpenRPCDebugCallInfoEnumeration failed: 1734
0:000> !rpcexts.getclientcallinfo
Searching for call info …
OpenRPCDebugClientCallInfoEnumeration failed: 1734
0:000> |
… 0 id: 910 exited name: DoRPC_Client.exe
0:000> !rpcexts.getthreadinfo 1734
Searching for thread info …
OpenRPCDebugThreadInfoEnumeration failed: 1
0:000> !rpcexts.rpctime
Current time is: 015871.890 (0x003dff.37a)
0:000> !rpcexts.thread
Error: Failure to get address
0:000> !teb
TEB at 7ffdf000
ExceptionList: 0012ff40
StackBase: 00130000
StackLimit: 0012d000
SubSystemTib: 00000000
FiberData: 00001e00
ArbitraryUserPointer: 00000000
Self: 7ffdf000
EnvironmentPointer: 00000000
ClientId: 00000910 . 00000cec
RpcHandle: 00000000
Tls Storage: 00000000
PEB Address: 7ffd7000
LastErrorValue: 10061
LastStatusValue: c0000236
Count Owned Locks: 0
HardErrorMode: 0
0:000> !rpcexts.thread @teb
Error: Failure to get address
0:000> !rpcexts.thread @$teb
Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
0:000> !rpcexts.thread 7ffdf000
Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
0:000> !rpcexts.checkrpcsym
rpcexts has no checkrpcsym export
0:000> !rpcexts.eeinfo
Error: Failure to get address
0:000> !rpcexts.getendpointinfo
Searching for endpoint info …
OpenRPCDebugEndpointInfoEnumeration failed: 1734

here is a wt -l4 -or -oR -oa dump

24 45 [3] WS2_32!getaddrinfo eax = 0
>> No match on ret
24 45 [3] WS2_32!getaddrinfo
39 0 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
call at 77e91501
5 0 [4] RPCRT4!__security_check_cookie eax = 0
44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress eax = 0
>> No match on ret
44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
18 0 [3] RPCRT4!TCPOrHTTP_Open
call at 77eec1d6
ModLoad: 662b0000 66308000 C:\WINDOWS\system32\hnetcfg.dll
ModLoad: 77f10000 77f56000 C:\WINDOWS\system32\GDI32.dll
ModLoad: 77d40000 77dd0000 C:\WINDOWS\system32\USER32.dll
ModLoad: 71a90000 71a98000 C:\WINDOWS\System32\wshtcpip.dll
279 0 [4] RPCRT4!WS_Open eax = 6ba
25 279 [3] RPCRT4!TCPOrHTTP_Open
call at 77eec217
7 0 [4]
RPCRT4!IP_ADDRESS_RESOLVER::~IP_ADDRESS_RESOLVER eax = 1
29 286 [3] RPCRT4!TCPOrHTTP_Open
call at 77eec227
5 0 [4] RPCRT4!__security_check_cookie eax = 6ba
34 291 [3] RPCRT4!TCPOrHTTP_Open eax = 6ba
>> No match on ret
34 291 [3] RPCRT4!TCPOrHTTP_Open
4 0 [3] RPCRT4!TCP_Open eax = 6ba
>> No match on ret
4 0 [3] RPCRT4!TCP_Open
11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen eax = 6ba
>> No match on ret
11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen
15 0 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
call at 77ea3e06
51 0 [4] RPCRT4!OSF_CASSOCIATION::ShutdownRequested eax = 0
23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind eax = 6ba
>> No match on ret
23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
14 0 [3] RPCRT4!OSF_CCALL::BindToServer
call at 77ea3d56
14 0 [4] RPCRT4!OSF_CCALL::GetStatusForTimeout eax = 6ba
22 14 [3] RPCRT4!OSF_CCALL::BindToServer
call at 77e84e2a
10 0 [4] RPCRT4!REFERENCED_OBJECT::RemoveReference eax = 1
30 24 [3] RPCRT4!OSF_CCALL::BindToServer eax = 6ba
>> No match on ret
30 24 [3] RPCRT4!OSF_CCALL::BindToServer
8 0 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
call at 77e84d76
54 0 [4] RPCRT4!OSF_CCALL::FreeCCall eax = 0
11 54 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
call at 77e8019a
13 0 [4] RPCRT4!CLIENT_AUTH_INFO::~CLIENT_AUTH_INFO
eax = 12fc01
17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall eax = 6ba
>> No match on ret
17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
25 0 [3]
RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax eax = 6ba
>> No match on ret
25 0 [3] RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax
7 0 [3] RPCRT4!I_RpcGetBufferWithObject eax = 6ba
>> No match on ret
7 0 [3] RPCRT4!I_RpcGetBufferWithObject
2 0 [3] RPCRT4!I_RpcGetBuffer eax = 6ba
>> No match on ret
2 0 [3] RPCRT4!I_RpcGetBuffer
7 0 [3] RPCRT4!NdrGetBuffer
call at 77ea3bc1
11 0 [4] RPCRT4!RpcRaiseException
(910.cec): Unknown exception - code 000006ba (first chance)
eax=77c3b8c1 ebx=00000000 ecx=003423d8 edx=77c61ae8 esi=7c90e88e edi=00000000
eip=7c90eb94 esp=0012fe54 ebp=0012ff50 iopl=0 nv up ei pl zr na pe nc
cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000 efl=00000246
ntdll!KiFastSystemCallRet:

any pointers to resolve this issue are welcome

ps

yes i checked dbgrpc too that is also giving errors

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -c
Searching for call info …
OpenRPCDebugCallInfoEnumeration failed: 1734

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -a
Searching for call info …
OpenRPCDebugClientCallInfoEnumeration failed: 1734

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -e
Searching for endpoint info …
OpenRPCDebugEndpointInfoEnumeration failed: 1734

C:\Program Files\Debugging Tools for Windows (x86)>

regards

raj_r

yes martin i have it as full already :slight_smile: thanks for pointing it out
though as obviously i should have included that information in my
query
and please dont stop pointing out the obvious if it isnt explicitly stated :slight_smile:

and rebooting, or maybe just waiting a while will do it - not sure) will produce error 1734.

im hoping that is the case and hope it appears magically when i re try
it later today

but a clear cut reboot requirement in docs would have been great :frowning:

C:\>gpresult.exe /scope computer /z | “c:\Program Files\GnuWin32\bin\grep.exe”
-A 4 “Administrative”
Administrative Templates

GPO: Local Group Policy
Setting: Software\Policies\Microsoft\Windows NT\Rpc
State: Enabled

C:\>reg query “hklm\software\policies\microsoft\windows nt\Rpc”

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\software\policies\microsoft\windows nt\Rpc
StateInformation REG_DWORD 0x4

C:\>

regards

raj_r

On 9/18/08, Martin O’Brien wrote:
> Just to rule out the obvious, have you configured RPC to preserve/enable
> state information? Given your very knowledge of the ways
> of the debugger, I imagine that you already know this, but in case note, I
> recall that running dbgrpc -e without setting the group
> policy for the target (and rebooting, or maybe just waiting a while will do
> it - not sure) will produce error 1734.
>
> In GPEDIT.MSC:
>
> Computer Configuration/Administrative Templates/System/Remote Procedure
> Call/RPC Troubleshooting State Information: Full
>
> I haven’t done this in a while, and I know that ‘Full’ isn’t required, but I
> just set it to that because it works.
>
>
> Good luck,
>
> mm
>
>
>
>
>
>
> raj_r wrote:
>> is rpcexts! broken in windbg or is it more likely that im broken
>>
>> i was trying to muck around with rpcexts! extension in latest windbg
>> but windbg is giving me errors
>>
>> and there is only one google hit for the error in google groups and it
>> seems that query is unresolved
>>
>> http://groups.google.co.mz/group/microsoft.public.windbg/browse_thread/thread/f0a50fac946cff9d
>>
>> os = xp sp2
>> windbg version = latest
>>
>> 0:000> !version
>> Free RPC Extension dll for Build 6526
>>
>>
>> 0:000> version
>> Windows XP Version 2600 (Service Pack 2) UP Free x86 compatible
>> Product: WinNt, suite: SingleUserTS
>> kernel32.dll version: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
>> Debug session time: Thu Sep 18 03:41:13.224 2008 (GMT+5)
>>
>> Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
>> Copyright (c) Microsoft Corporation. All rights reserved.
>>
>>
>> errors as follows
>>
>>
>> 0:000> !rpcexts.getcallinfo
>> Searching for call info …
>> OpenRPCDebugCallInfoEnumeration failed: 1734
>> 0:000> !rpcexts.getclientcallinfo
>> Searching for call info …
>> OpenRPCDebugClientCallInfoEnumeration failed: 1734
>> 0:000> |
>> … 0 id: 910 exited name: DoRPC_Client.exe
>> 0:000> !rpcexts.getthreadinfo 1734
>> Searching for thread info …
>> OpenRPCDebugThreadInfoEnumeration failed: 1
>> 0:000> !rpcexts.rpctime
>> Current time is: 015871.890 (0x003dff.37a)
>> 0:000> !rpcexts.thread
>> Error: Failure to get address
>> 0:000> !teb
>> TEB at 7ffdf000
>> ExceptionList: 0012ff40
>> StackBase: 00130000
>> StackLimit: 0012d000
>> SubSystemTib: 00000000
>> FiberData: 00001e00
>> ArbitraryUserPointer: 00000000
>> Self: 7ffdf000
>> EnvironmentPointer: 00000000
>> ClientId: 00000910 . 00000cec
>> RpcHandle: 00000000
>> Tls Storage: 00000000
>> PEB Address: 7ffd7000
>> LastErrorValue: 10061
>> LastStatusValue: c0000236
>> Count Owned Locks: 0
>> HardErrorMode: 0
>> 0:000> !rpcexts.thread @teb
>> Error: Failure to get address
>> 0:000> !rpcexts.thread @$teb
>> Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
>> 0:000> !rpcexts.thread 7ffdf000
>> Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
>> 0:000> !rpcexts.checkrpcsym
>> rpcexts has no checkrpcsym export
>> 0:000> !rpcexts.eeinfo
>> Error: Failure to get address
>> 0:000> !rpcexts.getendpointinfo
>> Searching for endpoint info …
>> OpenRPCDebugEndpointInfoEnumeration failed: 1734
>>
>>
>>
>> here is a wt -l4 -or -oR -oa dump
>>
>> 24 45 [3] WS2_32!getaddrinfo eax = 0
>>>> No match on ret
>> 24 45 [3] WS2_32!getaddrinfo
>> 39 0 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
>> call at 77e91501
>> 5 0 [4] RPCRT4!__security_check_cookie eax = 0
>> 44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress eax = 0
>>>> No match on ret
>> 44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
>> 18 0 [3] RPCRT4!TCPOrHTTP_Open
>> call at 77eec1d6
>> ModLoad: 662b0000 66308000 C:\WINDOWS\system32\hnetcfg.dll
>> ModLoad: 77f10000 77f56000 C:\WINDOWS\system32\GDI32.dll
>> ModLoad: 77d40000 77dd0000 C:\WINDOWS\system32\USER32.dll
>> ModLoad: 71a90000 71a98000 C:\WINDOWS\System32\wshtcpip.dll
>> 279 0 [4] RPCRT4!WS_Open eax = 6ba
>> 25 279 [3] RPCRT4!TCPOrHTTP_Open
>> call at 77eec217
>> 7 0 [4]
>> RPCRT4!IP_ADDRESS_RESOLVER::~IP_ADDRESS_RESOLVER eax = 1
>> 29 286 [3] RPCRT4!TCPOrHTTP_Open
>> call at 77eec227
>> 5 0 [4] RPCRT4!__security_check_cookie eax = 6ba
>> 34 291 [3] RPCRT4!TCPOrHTTP_Open eax = 6ba
>>>> No match on ret
>> 34 291 [3] RPCRT4!TCPOrHTTP_Open
>> 4 0 [3] RPCRT4!TCP_Open eax = 6ba
>>>> No match on ret
>> 4 0 [3] RPCRT4!TCP_Open
>> 11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen eax = 6ba
>>>> No match on ret
>> 11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen
>> 15 0 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
>> call at 77ea3e06
>> 51 0 [4] RPCRT4!OSF_CASSOCIATION::ShutdownRequested eax =
>> 0
>> 23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind eax
>> = 6ba
>>>> No match on ret
>> 23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
>> 14 0 [3] RPCRT4!OSF_CCALL::BindToServer
>> call at 77ea3d56
>> 14 0 [4] RPCRT4!OSF_CCALL::GetStatusForTimeout eax = 6ba
>> 22 14 [3] RPCRT4!OSF_CCALL::BindToServer
>> call at 77e84e2a
>> 10 0 [4] RPCRT4!REFERENCED_OBJECT::RemoveReference eax =
>> 1
>> 30 24 [3] RPCRT4!OSF_CCALL::BindToServer eax = 6ba
>>>> No match on ret
>> 30 24 [3] RPCRT4!OSF_CCALL::BindToServer
>> 8 0 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
>> call at 77e84d76
>> 54 0 [4] RPCRT4!OSF_CCALL::FreeCCall eax = 0
>> 11 54 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
>> call at 77e8019a
>> 13 0 [4] RPCRT4!CLIENT_AUTH_INFO::~CLIENT_AUTH_INFO
>> eax = 12fc01
>> 17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall eax = 6ba
>>>> No match on ret
>> 17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
>> 25 0 [3]
>> RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax eax = 6ba
>>>> No match on ret
>> 25 0 [3] RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax
>> 7 0 [3] RPCRT4!I_RpcGetBufferWithObject eax = 6ba
>>>> No match on ret
>> 7 0 [3] RPCRT4!I_RpcGetBufferWithObject
>> 2 0 [3] RPCRT4!I_RpcGetBuffer eax = 6ba
>>>> No match on ret
>> 2 0 [3] RPCRT4!I_RpcGetBuffer
>> 7 0 [3] RPCRT4!NdrGetBuffer
>> call at 77ea3bc1
>> 11 0 [4] RPCRT4!RpcRaiseException
>> (910.cec): Unknown exception - code 000006ba (first chance)
>> eax=77c3b8c1 ebx=00000000 ecx=003423d8 edx=77c61ae8 esi=7c90e88e
>> edi=00000000
>> eip=7c90eb94 esp=0012fe54 ebp=0012ff50 iopl=0 nv up ei pl zr na pe
>> nc
>> cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
>> efl=00000246
>> ntdll!KiFastSystemCallRet:
>>
>>
>> any pointers to resolve this issue are welcome
>>
>> ps
>>
>> yes i checked dbgrpc too that is also giving errors
>>
>>
>> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -c
>> Searching for call info …
>> OpenRPCDebugCallInfoEnumeration failed: 1734
>>
>> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -a
>> Searching for call info …
>> OpenRPCDebugClientCallInfoEnumeration failed: 1734
>>
>> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -e
>> Searching for endpoint info …
>> OpenRPCDebugEndpointInfoEnumeration failed: 1734
>>
>> C:\Program Files\Debugging Tools for Windows (x86)>
>>
>> regards
>>
>> raj_r
>>
>
> —
> You are currently subscribed to windbg as: xxxxx@gmail.com
> To unsubscribe send a blank email to xxxxx@lists.osr.com
>

I figured you already knew about this, but you never know.

What about the setting for ‘Propagate Extended Error Information==On?’

The only other thing I can think of to suggest is, in a nutshell, weakening everything related to security. I don’t remember what
version of the os your target is, but MSFT has broken various aspects of RPC over time, and on Vista pretty much nothing I used to
us works without doing some pretty catastrophic things to security, because I don’t know exactly what to change, and naturally MSFT
is of course not saying, because that would be ‘insecure.’ Sure, but it has to be better than what I’m doing. In any case, I think
your using XP SP2, and I know that I had to change something else in GP to fix the remote debugging stuff I wrote that uses RPC, but
it’s been too long for me to remember what it was exactly.

Sorry,

mm

raj_r wrote:

yes martin i have it as full already :slight_smile: thanks for pointing it out
though as obviously i should have included that information in my
query
and please dont stop pointing out the obvious if it isnt explicitly stated :slight_smile:

> and rebooting, or maybe just waiting a while will do it - not sure) will produce error 1734.

im hoping that is the case and hope it appears magically when i re try
it later today

but a clear cut reboot requirement in docs would have been great :frowning:

C:\>gpresult.exe /scope computer /z | “c:\Program Files\GnuWin32\bin\grep.exe”
-A 4 “Administrative”
Administrative Templates

GPO: Local Group Policy
Setting: Software\Policies\Microsoft\Windows NT\Rpc
State: Enabled

C:\>reg query “hklm\software\policies\microsoft\windows nt\Rpc”

! REG.EXE VERSION 3.0

HKEY_LOCAL_MACHINE\software\policies\microsoft\windows nt\Rpc
StateInformation REG_DWORD 0x4

C:\>

regards

raj_r

On 9/18/08, Martin O’Brien wrote:
>> Just to rule out the obvious, have you configured RPC to preserve/enable
>> state information? Given your very knowledge of the ways
>> of the debugger, I imagine that you already know this, but in case note, I
>> recall that running dbgrpc -e without setting the group
>> policy for the target (and rebooting, or maybe just waiting a while will do
>> it - not sure) will produce error 1734.
>>
>> In GPEDIT.MSC:
>>
>> Computer Configuration/Administrative Templates/System/Remote Procedure
>> Call/RPC Troubleshooting State Information: Full
>>
>> I haven’t done this in a while, and I know that ‘Full’ isn’t required, but I
>> just set it to that because it works.
>>
>>
>> Good luck,
>>
>> mm
>>
>>
>>
>>
>>
>>
>> raj_r wrote:
>>> is rpcexts! broken in windbg or is it more likely that im broken
>>>
>>> i was trying to muck around with rpcexts! extension in latest windbg
>>> but windbg is giving me errors
>>>
>>> and there is only one google hit for the error in google groups and it
>>> seems that query is unresolved
>>>
>>> http://groups.google.co.mz/group/microsoft.public.windbg/browse_thread/thread/f0a50fac946cff9d
>>>
>>> os = xp sp2
>>> windbg version = latest
>>>
>>> 0:000> !version
>>> Free RPC Extension dll for Build 6526
>>>
>>>
>>> 0:000> version
>>> Windows XP Version 2600 (Service Pack 2) UP Free x86 compatible
>>> Product: WinNt, suite: SingleUserTS
>>> kernel32.dll version: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
>>> Debug session time: Thu Sep 18 03:41:13.224 2008 (GMT+5)
>>>
>>> Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
>>> Copyright (c) Microsoft Corporation. All rights reserved.
>>>
>>>
>>> errors as follows
>>>
>>>
>>> 0:000> !rpcexts.getcallinfo
>>> Searching for call info …
>>> OpenRPCDebugCallInfoEnumeration failed: 1734
>>> 0:000> !rpcexts.getclientcallinfo
>>> Searching for call info …
>>> OpenRPCDebugClientCallInfoEnumeration failed: 1734
>>> 0:000> |
>>> … 0 id: 910 exited name: DoRPC_Client.exe
>>> 0:000> !rpcexts.getthreadinfo 1734
>>> Searching for thread info …
>>> OpenRPCDebugThreadInfoEnumeration failed: 1
>>> 0:000> !rpcexts.rpctime
>>> Current time is: 015871.890 (0x003dff.37a)
>>> 0:000> !rpcexts.thread
>>> Error: Failure to get address
>>> 0:000> !teb
>>> TEB at 7ffdf000
>>> ExceptionList: 0012ff40
>>> StackBase: 00130000
>>> StackLimit: 0012d000
>>> SubSystemTib: 00000000
>>> FiberData: 00001e00
>>> ArbitraryUserPointer: 00000000
>>> Self: 7ffdf000
>>> EnvironmentPointer: 00000000
>>> ClientId: 00000910 . 00000cec
>>> RpcHandle: 00000000
>>> Tls Storage: 00000000
>>> PEB Address: 7ffd7000
>>> LastErrorValue: 10061
>>> LastStatusValue: c0000236
>>> Count Owned Locks: 0
>>> HardErrorMode: 0
>>> 0:000> !rpcexts.thread @teb
>>> Error: Failure to get address
>>> 0:000> !rpcexts.thread @$teb
>>> Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
>>> 0:000> !rpcexts.thread 7ffdf000
>>> Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
>>> 0:000> !rpcexts.checkrpcsym
>>> rpcexts has no checkrpcsym export
>>> 0:000> !rpcexts.eeinfo
>>> Error: Failure to get address
>>> 0:000> !rpcexts.getendpointinfo
>>> Searching for endpoint info …
>>> OpenRPCDebugEndpointInfoEnumeration failed: 1734
>>>
>>>
>>>
>>> here is a wt -l4 -or -oR -oa dump
>>>
>>> 24 45 [3] WS2_32!getaddrinfo eax = 0
>>>>> No match on ret
>>> 24 45 [3] WS2_32!getaddrinfo
>>> 39 0 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
>>> call at 77e91501
>>> 5 0 [4] RPCRT4!__security_check_cookie eax = 0
>>> 44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress eax = 0
>>>>> No match on ret
>>> 44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
>>> 18 0 [3] RPCRT4!TCPOrHTTP_Open
>>> call at 77eec1d6
>>> ModLoad: 662b0000 66308000 C:\WINDOWS\system32\hnetcfg.dll
>>> ModLoad: 77f10000 77f56000 C:\WINDOWS\system32\GDI32.dll
>>> ModLoad: 77d40000 77dd0000 C:\WINDOWS\system32\USER32.dll
>>> ModLoad: 71a90000 71a98000 C:\WINDOWS\System32\wshtcpip.dll
>>> 279 0 [4] RPCRT4!WS_Open eax = 6ba
>>> 25 279 [3] RPCRT4!TCPOrHTTP_Open
>>> call at 77eec217
>>> 7 0 [4]
>>> RPCRT4!IP_ADDRESS_RESOLVER::~IP_ADDRESS_RESOLVER eax = 1
>>> 29 286 [3] RPCRT4!TCPOrHTTP_Open
>>> call at 77eec227
>>> 5 0 [4] RPCRT4!__security_check_cookie eax = 6ba
>>> 34 291 [3] RPCRT4!TCPOrHTTP_Open eax = 6ba
>>>>> No match on ret
>>> 34 291 [3] RPCRT4!TCPOrHTTP_Open
>>> 4 0 [3] RPCRT4!TCP_Open eax = 6ba
>>>>> No match on ret
>>> 4 0 [3] RPCRT4!TCP_Open
>>> 11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen eax = 6ba
>>>>> No match on ret
>>> 11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen
>>> 15 0 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
>>> call at 77ea3e06
>>> 51 0 [4] RPCRT4!OSF_CASSOCIATION::ShutdownRequested eax =
>>> 0
>>> 23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind eax
>>> = 6ba
>>>>> No match on ret
>>> 23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
>>> 14 0 [3] RPCRT4!OSF_CCALL::BindToServer
>>> call at 77ea3d56
>>> 14 0 [4] RPCRT4!OSF_CCALL::GetStatusForTimeout eax = 6ba
>>> 22 14 [3] RPCRT4!OSF_CCALL::BindToServer
>>> call at 77e84e2a
>>> 10 0 [4] RPCRT4!REFERENCED_OBJECT::RemoveReference eax =
>>> 1
>>> 30 24 [3] RPCRT4!OSF_CCALL::BindToServer eax = 6ba
>>>>> No match on ret
>>> 30 24 [3] RPCRT4!OSF_CCALL::BindToServer
>>> 8 0 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
>>> call at 77e84d76
>>> 54 0 [4] RPCRT4!OSF_CCALL::FreeCCall eax = 0
>>> 11 54 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
>>> call at 77e8019a
>>> 13 0 [4] RPCRT4!CLIENT_AUTH_INFO::~CLIENT_AUTH_INFO
>>> eax = 12fc01
>>> 17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall eax = 6ba
>>>>> No match on ret
>>> 17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
>>> 25 0 [3]
>>> RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax eax = 6ba
>>>>> No match on ret
>>> 25 0 [3] RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax
>>> 7 0 [3] RPCRT4!I_RpcGetBufferWithObject eax = 6ba
>>>>> No match on ret
>>> 7 0 [3] RPCRT4!I_RpcGetBufferWithObject
>>> 2 0 [3] RPCRT4!I_RpcGetBuffer eax = 6ba
>>>>> No match on ret
>>> 2 0 [3] RPCRT4!I_RpcGetBuffer
>>> 7 0 [3] RPCRT4!NdrGetBuffer
>>> call at 77ea3bc1
>>> 11 0 [4] RPCRT4!RpcRaiseException
>>> (910.cec): Unknown exception - code 000006ba (first chance)
>>> eax=77c3b8c1 ebx=00000000 ecx=003423d8 edx=77c61ae8 esi=7c90e88e
>>> edi=00000000
>>> eip=7c90eb94 esp=0012fe54 ebp=0012ff50 iopl=0 nv up ei pl zr na pe
>>> nc
>>> cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
>>> efl=00000246
>>> ntdll!KiFastSystemCallRet:
>>>
>>>
>>> any pointers to resolve this issue are welcome
>>>
>>> ps
>>>
>>> yes i checked dbgrpc too that is also giving errors
>>>
>>>
>>> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -c
>>> Searching for call info …
>>> OpenRPCDebugCallInfoEnumeration failed: 1734
>>>
>>> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -a
>>> Searching for call info …
>>> OpenRPCDebugClientCallInfoEnumeration failed: 1734
>>>
>>> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -e
>>> Searching for endpoint info …
>>> OpenRPCDebugEndpointInfoEnumeration failed: 1734
>>>
>>> C:\Program Files\Debugging Tools for Windows (x86)>
>>>
>>> regards
>>>
>>> raj_r
>>>
>> —
>> You are currently subscribed to windbg as: xxxxx@gmail.com
>> To unsubscribe send a blank email to xxxxx@lists.osr.com
>>
>

thanks martin

it seems it REQUIRES a reboot
using gpudate which claimed it has refreshed local policies several
times never made it appear
which reboot seems to have achieved

0844 0000.0001 01 LRPC OLE77E9E65BA4754020AB913B9BC
0bc8 0000.0001 01 TCP 9191

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc -l -P 0bc8 -L 0.1
Getting cell info …
Endpoint
Status: Active
Protocol Sequence: TCP
Endpoint name: 9191

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc -t -P 0bc8
Searching for thread info …
PID CELL ID ST TID ENDPOINT LASTTIME

0bc8 0000.0002 03 00000b6c 00113fb5

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc -l -P 0bc8 -L 0.2
Getting cell info …
Thread
Status: Idle
Thread ID: 0xB6C (2924)
Thread is an IO completion thread
Last update time (in seconds since boot):1130.421 (0x46A.1A5)

oh yeah i enabled all the five or six policies that were there in that
template some of which were warning (oops sorry explaining) of dire
consequences if i went ahead with enabling them

and also performed gpuupdate several times before posting my query

and default is auto2 which claimed that it maintains basic rpc info

but basic probably is something like this

rpcinfo basic;
ZeroMemory(&basic,sizeof(basic));

thanks again and why sorry ?

regards

raj_r

On 9/20/08, Martin O’Brien wrote:
> I figured you already knew about this, but you never know.
>
>
> What about the setting for ‘Propagate Extended Error Information==On?’
>
> The only other thing I can think of to suggest is, in a nutshell, weakening
> everything related to security. I don’t remember what
> version of the os your target is, but MSFT has broken various aspects of RPC
> over time, and on Vista pretty much nothing I used to
> us works without doing some pretty catastrophic things to security, because
> I don’t know exactly what to change, and naturally MSFT
> is of course not saying, because that would be ‘insecure.’ Sure, but it has
> to be better than what I’m doing. In any case, I think
> your using XP SP2, and I know that I had to change something else in GP to
> fix the remote debugging stuff I wrote that uses RPC, but
> it’s been too long for me to remember what it was exactly.
>
>
> Sorry,
>
> mm
>
>
>
>
>
>
>
>
>
> raj_r wrote:
>> yes martin i have it as full already :slight_smile: thanks for pointing it out
>> though as obviously i should have included that information in my
>> query
>> and please dont stop pointing out the obvious if it isnt explicitly stated
>> :slight_smile:
>>
>>
>>> and rebooting, or maybe just waiting a while will do it - not sure) will
>>> produce error 1734.
>>
>> im hoping that is the case and hope it appears magically when i re try
>> it later today
>>
>> but a clear cut reboot requirement in docs would have been great :frowning:
>>
>> C:>gpresult.exe /scope computer /z | “c:\Program
>> Files\GnuWin32\bin\grep.exe”
>> -A 4 “Administrative”
>> Administrative Templates
>> ------------------------
>> GPO: Local Group Policy
>> Setting: Software\Policies\Microsoft\Windows NT\Rpc
>> State: Enabled
>>
>> C:>reg query “hklm\software\policies\microsoft\windows nt\Rpc”
>>
>> ! REG.EXE VERSION 3.0
>>
>> HKEY_LOCAL_MACHINE\software\policies\microsoft\windows nt\Rpc
>> StateInformation REG_DWORD 0x4
>>
>> C:>
>>
>> regards
>>
>> raj_r
>>
>> On 9/18/08, Martin O’Brien wrote:
>>> Just to rule out the obvious, have you configured RPC to preserve/enable
>>> state information? Given your very knowledge of the ways
>>> of the debugger, I imagine that you already know this, but in case note,
>>> I
>>> recall that running dbgrpc -e without setting the group
>>> policy for the target (and rebooting, or maybe just waiting a while will
>>> do
>>> it - not sure) will produce error 1734.
>>>
>>> In GPEDIT.MSC:
>>>
>>> Computer Configuration/Administrative Templates/System/Remote Procedure
>>> Call/RPC Troubleshooting State Information: Full
>>>
>>> I haven’t done this in a while, and I know that ‘Full’ isn’t required,
>>> but I
>>> just set it to that because it works.
>>>
>>>
>>> Good luck,
>>>
>>> mm
>>>
>>>
>>>
>>>
>>>
>>>
>>> raj_r wrote:
>>>> is rpcexts! broken in windbg or is it more likely that im broken
>>>>
>>>> i was trying to muck around with rpcexts! extension in latest windbg
>>>> but windbg is giving me errors
>>>>
>>>> and there is only one google hit for the error in google groups and it
>>>> seems that query is unresolved
>>>>
>>>> http://groups.google.co.mz/group/microsoft.public.windbg/browse_thread/thread/f0a50fac946cff9d
>>>>
>>>> os = xp sp2
>>>> windbg version = latest
>>>>
>>>> 0:000> !version
>>>> Free RPC Extension dll for Build 6526
>>>>
>>>>
>>>> 0:000> version
>>>> Windows XP Version 2600 (Service Pack 2) UP Free x86 compatible
>>>> Product: WinNt, suite: SingleUserTS
>>>> kernel32.dll version: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
>>>> Debug session time: Thu Sep 18 03:41:13.224 2008 (GMT+5)
>>>>
>>>> Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
>>>> Copyright (c) Microsoft Corporation. All rights reserved.
>>>>
>>>>
>>>> errors as follows
>>>>
>>>>
>>>> 0:000> !rpcexts.getcallinfo
>>>> Searching for call info …
>>>> OpenRPCDebugCallInfoEnumeration failed: 1734
>>>> 0:000> !rpcexts.getclientcallinfo
>>>> Searching for call info …
>>>> OpenRPCDebugClientCallInfoEnumeration failed: 1734
>>>> 0:000> |
>>>> … 0 id: 910 exited name: DoRPC_Client.exe
>>>> 0:000> !rpcexts.getthreadinfo 1734
>>>> Searching for thread info …
>>>> OpenRPCDebugThreadInfoEnumeration failed: 1
>>>> 0:000> !rpcexts.rpctime
>>>> Current time is: 015871.890 (0x003dff.37a)
>>>> 0:000> !rpcexts.thread
>>>> Error: Failure to get address
>>>> 0:000> !teb
>>>> TEB at 7ffdf000
>>>> ExceptionList: 0012ff40
>>>> StackBase: 00130000
>>>> StackLimit: 0012d000
>>>> SubSystemTib: 00000000
>>>> FiberData: 00001e00
>>>> ArbitraryUserPointer: 00000000
>>>> Self: 7ffdf000
>>>> EnvironmentPointer: 00000000
>>>> ClientId: 00000910 . 00000cec
>>>> RpcHandle: 00000000
>>>> Tls Storage: 00000000
>>>> PEB Address: 7ffd7000
>>>> LastErrorValue: 10061
>>>> LastStatusValue: c0000236
>>>> Count Owned Locks: 0
>>>> HardErrorMode: 0
>>>> 0:000> !rpcexts.thread @teb
>>>> Error: Failure to get address
>>>> 0:000> !rpcexts.thread @$teb
>>>> Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
>>>> 0:000> !rpcexts.thread 7ffdf000
>>>> Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
>>>> 0:000> !rpcexts.checkrpcsym
>>>> rpcexts has no checkrpcsym export
>>>> 0:000> !rpcexts.eeinfo
>>>> Error: Failure to get address
>>>> 0:000> !rpcexts.getendpointinfo
>>>> Searching for endpoint info …
>>>> OpenRPCDebugEndpointInfoEnumeration failed: 1734
>>>>
>>>>
>>>>
>>>> here is a wt -l4 -or -oR -oa dump
>>>>
>>>> 24 45 [3] WS2_32!getaddrinfo eax = 0
>>>>>> No match on ret
>>>> 24 45 [3] WS2_32!getaddrinfo
>>>> 39 0 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
>>>> call at 77e91501
>>>> 5 0 [4] RPCRT4!__security_check_cookie eax = 0
>>>> 44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress eax = 0
>>>>>> No match on ret
>>>> 44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
>>>> 18 0 [3] RPCRT4!TCPOrHTTP_Open
>>>> call at 77eec1d6
>>>> ModLoad: 662b0000 66308000 C:\WINDOWS\system32\hnetcfg.dll
>>>> ModLoad: 77f10000 77f56000 C:\WINDOWS\system32\GDI32.dll
>>>> ModLoad: 77d40000 77dd0000 C:\WINDOWS\system32\USER32.dll
>>>> ModLoad: 71a90000 71a98000 C:\WINDOWS\System32\wshtcpip.dll
>>>> 279 0 [4] RPCRT4!WS_Open eax = 6ba
>>>> 25 279 [3] RPCRT4!TCPOrHTTP_Open
>>>> call at 77eec217
>>>> 7 0 [4]
>>>> RPCRT4!IP_ADDRESS_RESOLVER::~IP_ADDRESS_RESOLVER eax = 1
>>>> 29 286 [3] RPCRT4!TCPOrHTTP_Open
>>>> call at 77eec227
>>>> 5 0 [4] RPCRT4!__security_check_cookie eax = 6ba
>>>> 34 291 [3] RPCRT4!TCPOrHTTP_Open eax = 6ba
>>>>>> No match on ret
>>>> 34 291 [3] RPCRT4!TCPOrHTTP_Open
>>>> 4 0 [3] RPCRT4!TCP_Open eax = 6ba
>>>>>> No match on ret
>>>> 4 0 [3] RPCRT4!TCP_Open
>>>> 11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen eax = 6ba
>>>>>> No match on ret
>>>> 11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen
>>>> 15 0 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
>>>> call at 77ea3e06
>>>> 51 0 [4] RPCRT4!OSF_CASSOCIATION::ShutdownRequested eax
>>>> =
>>>> 0
>>>> 23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
>>>> eax
>>>> = 6ba
>>>>>> No match on ret
>>>> 23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
>>>> 14 0 [3] RPCRT4!OSF_CCALL::BindToServer
>>>> call at 77ea3d56
>>>> 14 0 [4] RPCRT4!OSF_CCALL::GetStatusForTimeout eax =
>>>> 6ba
>>>> 22 14 [3] RPCRT4!OSF_CCALL::BindToServer
>>>> call at 77e84e2a
>>>> 10 0 [4] RPCRT4!REFERENCED_OBJECT::RemoveReference eax
>>>> =
>>>> 1
>>>> 30 24 [3] RPCRT4!OSF_CCALL::BindToServer eax = 6ba
>>>>>> No match on ret
>>>> 30 24 [3] RPCRT4!OSF_CCALL::BindToServer
>>>> 8 0 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
>>>> call at 77e84d76
>>>> 54 0 [4] RPCRT4!OSF_CCALL::FreeCCall eax = 0
>>>> 11 54 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
>>>> call at 77e8019a
>>>> 13 0 [4] RPCRT4!CLIENT_AUTH_INFO::~CLIENT_AUTH_INFO
>>>> eax = 12fc01
>>>> 17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall eax =
>>>> 6ba
>>>>>> No match on ret
>>>> 17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
>>>> 25 0 [3]
>>>> RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax eax = 6ba
>>>>>> No match on ret
>>>> 25 0 [3]
>>>> RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax
>>>> 7 0 [3] RPCRT4!I_RpcGetBufferWithObject eax = 6ba
>>>>>> No match on ret
>>>> 7 0 [3] RPCRT4!I_RpcGetBufferWithObject
>>>> 2 0 [3] RPCRT4!I_RpcGetBuffer eax = 6ba
>>>>>> No match on ret
>>>> 2 0 [3] RPCRT4!I_RpcGetBuffer
>>>> 7 0 [3] RPCRT4!NdrGetBuffer
>>>> call at 77ea3bc1
>>>> 11 0 [4] RPCRT4!RpcRaiseException
>>>> (910.cec): Unknown exception - code 000006ba (first chance)
>>>> eax=77c3b8c1 ebx=00000000 ecx=003423d8 edx=77c61ae8 esi=7c90e88e
>>>> edi=00000000
>>>> eip=7c90eb94 esp=0012fe54 ebp=0012ff50 iopl=0 nv up ei pl zr na
>>>> pe
>>>> nc
>>>> cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
>>>> efl=00000246
>>>> ntdll!KiFastSystemCallRet:
>>>>
>>>>
>>>> any pointers to resolve this issue are welcome
>>>>
>>>> ps
>>>>
>>>> yes i checked dbgrpc too that is also giving errors
>>>>
>>>>
>>>> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -c
>>>> Searching for call info …
>>>> OpenRPCDebugCallInfoEnumeration failed: 1734
>>>>
>>>> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -a
>>>> Searching for call info …
>>>> OpenRPCDebugClientCallInfoEnumeration failed: 1734
>>>>
>>>> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -e
>>>> Searching for endpoint info …
>>>> OpenRPCDebugEndpointInfoEnumeration failed: 1734
>>>>
>>>> C:\Program Files\Debugging Tools for Windows (x86)>
>>>>
>>>> regards
>>>>
>>>> raj_r
>>>>
>>> —
>>> You are currently subscribed to windbg as: xxxxx@gmail.com
>>> To unsubscribe send a blank email to xxxxx@lists.osr.com
>>>
>>
>
> —
> You are currently subscribed to windbg as: xxxxx@gmail.com
> To unsubscribe send a blank email to xxxxx@lists.osr.com
>

No problem.

Sorry because I didn’t realize that the reboot hadn’t been performed, so I thought that I was out of ideas.

Glad it works,

mm

raj_r wrote:

thanks martin

it seems it REQUIRES a reboot
using gpudate which claimed it has refreshed local policies several
times never made it appear
which reboot seems to have achieved

0844 0000.0001 01 LRPC OLE77E9E65BA4754020AB913B9BC
0bc8 0000.0001 01 TCP 9191

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc -l -P 0bc8 -L 0.1
Getting cell info …
Endpoint
Status: Active
Protocol Sequence: TCP
Endpoint name: 9191

C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc -t -P 0bc8
Searching for thread info …
PID CELL ID ST TID ENDPOINT LASTTIME

0bc8 0000.0002 03 00000b6c 00113fb5
>
> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc -l -P 0bc8 -L 0.2
> Getting cell info …
> Thread
> Status: Idle
> Thread ID: 0xB6C (2924)
> Thread is an IO completion thread
> Last update time (in seconds since boot):1130.421 (0x46A.1A5)
>
>
>
>
> oh yeah i enabled all the five or six policies that were there in that
> template some of which were warning (oops sorry explaining) of dire
> consequences if i went ahead with enabling them
>
> and also performed gpuupdate several times before posting my query
>
> and default is auto2 which claimed that it maintains basic rpc info
>
> but basic probably is something like this
>
> rpcinfo basic;
> ZeroMemory(&basic,sizeof(basic));
>
> thanks again and why sorry ?
>
> regards
>
> raj_r
>
> On 9/20/08, Martin O’Brien wrote:
>> I figured you already knew about this, but you never know.
>>
>>
>> What about the setting for ‘Propagate Extended Error Information==On?’
>>
>> The only other thing I can think of to suggest is, in a nutshell, weakening
>> everything related to security. I don’t remember what
>> version of the os your target is, but MSFT has broken various aspects of RPC
>> over time, and on Vista pretty much nothing I used to
>> us works without doing some pretty catastrophic things to security, because
>> I don’t know exactly what to change, and naturally MSFT
>> is of course not saying, because that would be ‘insecure.’ Sure, but it has
>> to be better than what I’m doing. In any case, I think
>> your using XP SP2, and I know that I had to change something else in GP to
>> fix the remote debugging stuff I wrote that uses RPC, but
>> it’s been too long for me to remember what it was exactly.
>>
>>
>> Sorry,
>>
>> mm
>>
>>
>>
>>
>>
>>
>>
>>
>>
>> raj_r wrote:
>>> yes martin i have it as full already :slight_smile: thanks for pointing it out
>>> though as obviously i should have included that information in my
>>> query
>>> and please dont stop pointing out the obvious if it isnt explicitly stated
>>> :slight_smile:
>>>
>>>
>>>> and rebooting, or maybe just waiting a while will do it - not sure) will
>>>> produce error 1734.
>>> im hoping that is the case and hope it appears magically when i re try
>>> it later today
>>>
>>> but a clear cut reboot requirement in docs would have been great :frowning:
>>>
>>> C:>gpresult.exe /scope computer /z | “c:\Program
>>> Files\GnuWin32\bin\grep.exe”
>>> -A 4 “Administrative”
>>> Administrative Templates
>>> ------------------------
>>> GPO: Local Group Policy
>>> Setting: Software\Policies\Microsoft\Windows NT\Rpc
>>> State: Enabled
>>>
>>> C:>reg query “hklm\software\policies\microsoft\windows nt\Rpc”
>>>
>>> ! REG.EXE VERSION 3.0
>>>
>>> HKEY_LOCAL_MACHINE\software\policies\microsoft\windows nt\Rpc
>>> StateInformation REG_DWORD 0x4
>>>
>>> C:>
>>>
>>> regards
>>>
>>> raj_r
>>>
>>> On 9/18/08, Martin O’Brien wrote:
>>>> Just to rule out the obvious, have you configured RPC to preserve/enable
>>>> state information? Given your very knowledge of the ways
>>>> of the debugger, I imagine that you already know this, but in case note,
>>>> I
>>>> recall that running dbgrpc -e without setting the group
>>>> policy for the target (and rebooting, or maybe just waiting a while will
>>>> do
>>>> it - not sure) will produce error 1734.
>>>>
>>>> In GPEDIT.MSC:
>>>>
>>>> Computer Configuration/Administrative Templates/System/Remote Procedure
>>>> Call/RPC Troubleshooting State Information: Full
>>>>
>>>> I haven’t done this in a while, and I know that ‘Full’ isn’t required,
>>>> but I
>>>> just set it to that because it works.
>>>>
>>>>
>>>> Good luck,
>>>>
>>>> mm
>>>>
>>>>
>>>>
>>>>
>>>>
>>>>
>>>> raj_r wrote:
>>>>> is rpcexts! broken in windbg or is it more likely that im broken
>>>>>
>>>>> i was trying to muck around with rpcexts! extension in latest windbg
>>>>> but windbg is giving me errors
>>>>>
>>>>> and there is only one google hit for the error in google groups and it
>>>>> seems that query is unresolved
>>>>>
>>>>> http://groups.google.co.mz/group/microsoft.public.windbg/browse_thread/thread/f0a50fac946cff9d
>>>>>
>>>>> os = xp sp2
>>>>> windbg version = latest
>>>>>
>>>>> 0:000> !version
>>>>> Free RPC Extension dll for Build 6526
>>>>>
>>>>>
>>>>> 0:000> version
>>>>> Windows XP Version 2600 (Service Pack 2) UP Free x86 compatible
>>>>> Product: WinNt, suite: SingleUserTS
>>>>> kernel32.dll version: 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
>>>>> Debug session time: Thu Sep 18 03:41:13.224 2008 (GMT+5)
>>>>>
>>>>> Microsoft (R) Windows Debugger Version 6.9.0003.113 X86
>>>>> Copyright (c) Microsoft Corporation. All rights reserved.
>>>>>
>>>>>
>>>>> errors as follows
>>>>>
>>>>>
>>>>> 0:000> !rpcexts.getcallinfo
>>>>> Searching for call info …
>>>>> OpenRPCDebugCallInfoEnumeration failed: 1734
>>>>> 0:000> !rpcexts.getclientcallinfo
>>>>> Searching for call info …
>>>>> OpenRPCDebugClientCallInfoEnumeration failed: 1734
>>>>> 0:000> |
>>>>> … 0 id: 910 exited name: DoRPC_Client.exe
>>>>> 0:000> !rpcexts.getthreadinfo 1734
>>>>> Searching for thread info …
>>>>> OpenRPCDebugThreadInfoEnumeration failed: 1
>>>>> 0:000> !rpcexts.rpctime
>>>>> Current time is: 015871.890 (0x003dff.37a)
>>>>> 0:000> !rpcexts.thread
>>>>> Error: Failure to get address
>>>>> 0:000> !teb
>>>>> TEB at 7ffdf000
>>>>> ExceptionList: 0012ff40
>>>>> StackBase: 00130000
>>>>> StackLimit: 0012d000
>>>>> SubSystemTib: 00000000
>>>>> FiberData: 00001e00
>>>>> ArbitraryUserPointer: 00000000
>>>>> Self: 7ffdf000
>>>>> EnvironmentPointer: 00000000
>>>>> ClientId: 00000910 . 00000cec
>>>>> RpcHandle: 00000000
>>>>> Tls Storage: 00000000
>>>>> PEB Address: 7ffd7000
>>>>> LastErrorValue: 10061
>>>>> LastStatusValue: c0000236
>>>>> Count Owned Locks: 0
>>>>> HardErrorMode: 0
>>>>> 0:000> !rpcexts.thread @teb
>>>>> Error: Failure to get address
>>>>> 0:000> !rpcexts.thread @$teb
>>>>> Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
>>>>> 0:000> !rpcexts.thread 7ffdf000
>>>>> Unable to get field ReservedForNtRpc of type TEB at 0x7ffdf000
>>>>> 0:000> !rpcexts.checkrpcsym
>>>>> rpcexts has no checkrpcsym export
>>>>> 0:000> !rpcexts.eeinfo
>>>>> Error: Failure to get address
>>>>> 0:000> !rpcexts.getendpointinfo
>>>>> Searching for endpoint info …
>>>>> OpenRPCDebugEndpointInfoEnumeration failed: 1734
>>>>>
>>>>>
>>>>>
>>>>> here is a wt -l4 -or -oR -oa dump
>>>>>
>>>>> 24 45 [3] WS2_32!getaddrinfo eax = 0
>>>>>>> No match on ret
>>>>> 24 45 [3] WS2_32!getaddrinfo
>>>>> 39 0 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
>>>>> call at 77e91501
>>>>> 5 0 [4] RPCRT4!__security_check_cookie eax = 0
>>>>> 44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress eax = 0
>>>>>>> No match on ret
>>>>> 44 5 [3] RPCRT4!IP_ADDRESS_RESOLVER::NextAddress
>>>>> 18 0 [3] RPCRT4!TCPOrHTTP_Open
>>>>> call at 77eec1d6
>>>>> ModLoad: 662b0000 66308000 C:\WINDOWS\system32\hnetcfg.dll
>>>>> ModLoad: 77f10000 77f56000 C:\WINDOWS\system32\GDI32.dll
>>>>> ModLoad: 77d40000 77dd0000 C:\WINDOWS\system32\USER32.dll
>>>>> ModLoad: 71a90000 71a98000 C:\WINDOWS\System32\wshtcpip.dll
>>>>> 279 0 [4] RPCRT4!WS_Open eax = 6ba
>>>>> 25 279 [3] RPCRT4!TCPOrHTTP_Open
>>>>> call at 77eec217
>>>>> 7 0 [4]
>>>>> RPCRT4!IP_ADDRESS_RESOLVER::~IP_ADDRESS_RESOLVER eax = 1
>>>>> 29 286 [3] RPCRT4!TCPOrHTTP_Open
>>>>> call at 77eec227
>>>>> 5 0 [4] RPCRT4!__security_check_cookie eax = 6ba
>>>>> 34 291 [3] RPCRT4!TCPOrHTTP_Open eax = 6ba
>>>>>>> No match on ret
>>>>> 34 291 [3] RPCRT4!TCPOrHTTP_Open
>>>>> 4 0 [3] RPCRT4!TCP_Open eax = 6ba
>>>>>>> No match on ret
>>>>> 4 0 [3] RPCRT4!TCP_Open
>>>>> 11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen eax = 6ba
>>>>>>> No match on ret
>>>>> 11 0 [3] RPCRT4!OSF_CCONNECTION::TransOpen
>>>>> 15 0 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
>>>>> call at 77ea3e06
>>>>> 51 0 [4] RPCRT4!OSF_CASSOCIATION::ShutdownRequested eax
>>>>> =
>>>>> 0
>>>>> 23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
>>>>> eax
>>>>> = 6ba
>>>>>>> No match on ret
>>>>> 23 51 [3] RPCRT4!OSF_CCONNECTION::OpenConnectionAndBind
>>>>> 14 0 [3] RPCRT4!OSF_CCALL::BindToServer
>>>>> call at 77ea3d56
>>>>> 14 0 [4] RPCRT4!OSF_CCALL::GetStatusForTimeout eax =
>>>>> 6ba
>>>>> 22 14 [3] RPCRT4!OSF_CCALL::BindToServer
>>>>> call at 77e84e2a
>>>>> 10 0 [4] RPCRT4!REFERENCED_OBJECT::RemoveReference eax
>>>>> =
>>>>> 1
>>>>> 30 24 [3] RPCRT4!OSF_CCALL::BindToServer eax = 6ba
>>>>>>> No match on ret
>>>>> 30 24 [3] RPCRT4!OSF_CCALL::BindToServer
>>>>> 8 0 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
>>>>> call at 77e84d76
>>>>> 54 0 [4] RPCRT4!OSF_CCALL::FreeCCall eax = 0
>>>>> 11 54 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
>>>>> call at 77e8019a
>>>>> 13 0 [4] RPCRT4!CLIENT_AUTH_INFO::~CLIENT_AUTH_INFO
>>>>> eax = 12fc01
>>>>> 17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall eax =
>>>>> 6ba
>>>>>>> No match on ret
>>>>> 17 67 [3] RPCRT4!OSF_BINDING_HANDLE::AllocateCCall
>>>>> 25 0 [3]
>>>>> RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax eax = 6ba
>>>>>>> No match on ret
>>>>> 25 0 [3]
>>>>> RPCRT4!OSF_BINDING_HANDLE::NegotiateTransferSyntax
>>>>> 7 0 [3] RPCRT4!I_RpcGetBufferWithObject eax = 6ba
>>>>>>> No match on ret
>>>>> 7 0 [3] RPCRT4!I_RpcGetBufferWithObject
>>>>> 2 0 [3] RPCRT4!I_RpcGetBuffer eax = 6ba
>>>>>>> No match on ret
>>>>> 2 0 [3] RPCRT4!I_RpcGetBuffer
>>>>> 7 0 [3] RPCRT4!NdrGetBuffer
>>>>> call at 77ea3bc1
>>>>> 11 0 [4] RPCRT4!RpcRaiseException
>>>>> (910.cec): Unknown exception - code 000006ba (first chance)
>>>>> eax=77c3b8c1 ebx=00000000 ecx=003423d8 edx=77c61ae8 esi=7c90e88e
>>>>> edi=00000000
>>>>> eip=7c90eb94 esp=0012fe54 ebp=0012ff50 iopl=0 nv up ei pl zr na
>>>>> pe
>>>>> nc
>>>>> cs=001b ss=0023 ds=0023 es=0023 fs=003b gs=0000
>>>>> efl=00000246
>>>>> ntdll!KiFastSystemCallRet:
>>>>>
>>>>>
>>>>> any pointers to resolve this issue are welcome
>>>>>
>>>>> ps
>>>>>
>>>>> yes i checked dbgrpc too that is also giving errors
>>>>>
>>>>>
>>>>> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -c
>>>>> Searching for call info …
>>>>> OpenRPCDebugCallInfoEnumeration failed: 1734
>>>>>
>>>>> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -a
>>>>> Searching for call info …
>>>>> OpenRPCDebugClientCallInfoEnumeration failed: 1734
>>>>>
>>>>> C:\Program Files\Debugging Tools for Windows (x86)>dbgrpc.exe -e
>>>>> Searching for endpoint info …
>>>>> OpenRPCDebugEndpointInfoEnumeration failed: 1734
>>>>>
>>>>> C:\Program Files\Debugging Tools for Windows (x86)>
>>>>>
>>>>> regards
>>>>>
>>>>> raj_r
>>>>>
>>>> —
>>>> You are currently subscribed to windbg as: xxxxx@gmail.com
>>>> To unsubscribe send a blank email to xxxxx@lists.osr.com
>>>>
>> —
>> You are currently subscribed to windbg as: xxxxx@gmail.com
>> To unsubscribe send a blank email to xxxxx@lists.osr.com
>>
>