"Random" unhandled exceptions at wpfgfx_cor3!CMILCOMBase::InternalAddRef
- Dominant language
- C#
- Stars
- 7.7k
- Forks
- 1.3k
- Avg merge
- 1d 11h
- Merged PRs (30d)
- 61
Description
### Description
We have a WPF application in .NET 7 that uses the `CompositionTarget.Rendering` event to capture a user control that renders up to 10 `MediaElement`s. At random intervals, the app will crash without triggering our global unhandled exception handler.
The crash seems to happen in unmanaged code, at `CMILCOMBase::InternalAddRef`. Looking at AvalonDebugP.h, I see there's a call to `AssertW`. In `InternalAddRef`, if the reference count is < 0, AssertW is called.
Here's the line I'm referencing:
https://github.com/dotnet/wpf/blob/28f8f455c01c4c51965d78617ec8ff66cf8f1aaf/src/Microsoft.DotNet.Wpf/src/WpfGfx/common/shared/milcom.cpp#L36C7-L36C7
Here is the output from analyzing the crash dump in WinDbg.
**We can provide a copy of the crash dump, but would prefer to do so privately.**
```
User Mini Dump File with Full Memory: Only application data is available
************* Path validation summary **************
Response Time (ms) Location
Deferred srv*
Symbol search path is: srv*
Executable search path is:
Windows 10 Version 20348 MP (16 procs) Free x64
Product: Server, suite: TerminalServer DataCenter SingleUserTS
Edition build lab: 20348.1.amd64fre.fe_release.210507-1500
Debug session time: Mon Sep 11 17:10:49.000 2023 (UTC - 4:00)
System Uptime: 0 days 5:28:31.632
Process Uptime: 0 days 0:03:23.000
................................................................
................................................................
................................................................
.........................................................
Loading unloaded module list
....
This dump file has a breakpoint exception stored in it.
The stored exception information can be accessed via .ecxr.
For analysis of this file, run !analyze -v
ntdll!DbgBreakPoint:
00007fff`e3ac3c10 cc int 3
0:008> !analyze -v
*******************************************************************************
* *
* Exception Analysis *
* *
*******************************************************************************
*** WARNING: Unable to verify checksum for Tractus.NdiMultiview.exe
KEY_VALUES_STRING: 1
Key : Analysis.CPU.mSec
Value: 3796
Key : Analysis.Elapsed.mSec
Value: 299612
Key : Analysis.IO.Other.Mb
Value: 154
Key : Analysis.IO.Read.Mb
Value: 3
Key : Analysis.IO.Write.Mb
Value: 235
Key : Analysis.Init.CPU.mSec
Value: 108
Key : Analysis.Init.Elapsed.mSec
Value: 9192
Key : Analysis.Memory.CommitPeak.Mb
Value: 327
Key : CLR.Engine
Value: CORECLR
Key : CLR.Version
Value: 7.0.222.60605
Key : Failure.Bucket
Value: BREAKPOINT_80000003_wpfgfx_cor3.dll!AssertW
Key : Failure.Hash
Value: {8235c892-b0fc-0e04-8769-4c437497ea21}
Key : Failure.Source.FileLine
Value: 615
Key : Failure.Source.FilePath
Value: D:\a\_work\1\s\src\Microsoft.DotNet.Wpf\src\WpfGfx\shared\util\UtilLib\Assert.inl
Key : Failure.Source.SourceServerCommand
Value: raw.githubusercontent.com/dotnet/wpf/df04c57b2e2bb986f0afc2384cbebb3c950447b5/src/Microsoft.DotNet.Wpf/src/WpfGfx/shared/util/UtilLib/Assert.inl
Key : Timeline.OS.Boot.DeltaSec
Value: 19711
Key : Timeline.Process.Start.DeltaSec
Value: 203
Key : WER.OS.Branch
Value: fe_release
Key : WER.OS.Version
Value: 10.0.20348.1
Key : WER.Process.Version
Value: 2023.9.2.13
FILE_IN_CAB: Tractus.NdiMultiview.exe.3252.dmp
NTGLOBALFLAG: 0
PROCESS_BAM_CURRENT_THROTTLED: 0
PROCESS_BAM_PREVIOUS_THROTTLED: 0
APPLICATION_VERIFIER_FLAGS: 0
CONTEXT: (.ecxr)
rax=0000000000000000 rbx=000000ef227fe970 rcx=ec9c3e723b680000
rdx=000000ef227fd190 rsi=000000ef227fdcd0 rdi=000000ef227fe480
rip=00007fffe3ac3c10 rsp=000000ef227ff248 rbp=00007fff91f28be8
r8=0000000000100000 r9=0000000000000001 r10=0000000000010040
r11=000000000010000b r12=00007fff91f21334 r13=00007fff91f27f00
r14=00007fff91f28b88 r15=00007fff91f27e28
iopl=0 nv up ei pl nz na po nc
cs=0033 ss=002b ds=002b es=002b fs=0053 gs=002b efl=00000204
ntdll!DbgBreakPoint:
00007fff`e3ac3c10 cc int 3
Resetting default scope
EXCEPTION_RECORD: (.exr -1)
ExceptionAddress: 00007fffe3ac3c10 (ntdll!DbgBreakPoint)
ExceptionCode: 80000003 (Break instruction exception)
ExceptionFlags: 00000001
NumberParameters: 1
Parameter[0]: 0000000000000000
PROCESS_NAME: Tractus.NdiMultiview.exe
ERROR_CODE: (NTSTATUS) 0x80000003 - {EXCEPTION} Breakpoint A breakpoint has been reached.
EXCEPTION_CODE_STR: 80000003
EXCEPTION_PARAMETER1: 0000000000000000
STACK_TEXT:
000000ef`227ff248 00007fff`91e6f7e3 : 000002e4`9f2944a0 000000ef`227ff3a0 00007fff`91f28c00 000000ef`227ff2b8 : ntdll!DbgBreakPoint
000000ef`227ff250 00007fff`91e59993 : 000002e4`e400ff02 00000000`e500ff02 e500ff02`e5ffff00 0000b952`8cd4fa07 : wpfgfx_cor3!AssertW+0x143
000000ef`227ff320 00007fff`86fcbd20 : 00000000`00000000 000002e4`a1289ac0 000002e4`a1289c68 000002e4`a1289ab8 : wpfgfx_cor3!CMILCOMBase::InternalAddRef+0x33
000000ef`227ff360 00007fff`91dd34bc : 00000000`00000000 00007fff`8702e2a1 41dd34ca`e500ff02 00000000`00000000 : evr!CMFSample::GetBufferByIndex+0x40
000000ef`227ff390 00007fff`91ded700 : 000002e4`9d72c348 000002e4`a1289c68 00000000`00000000 00000000`00000000 : wpfgfx_cor3!ConvertSampleToMediaBuffer+0x3c
000000ef`227ff3e0 00007fff`91de4b09 : 000002e4`9d72c300 00000000`00000000 00000000`00000000 00000000`00000000 : wpfgfx_cor3!SampleScheduler::GetCompositionSample+0xd0
000000ef`227ff480 00007fff`91e8d8bd : 000002a3`fcfc2eb0 00007fff`91dc392e 000002e4`9d72c300 00000000`00000000 : wpfgfx_cor3!EvrPresenter::AVSurfaceRenderer::BeginComposition+0x289
000000ef`227ff530 00007fff`91eb3706 : 000002e4`9391c1a0 00007fff`91ed1992 00000000`00000003 00000000`00000000 : wpfgfx_cor3!CMilSlaveVideo::BeginComposition+0x9d
000000ef`227ff5b0 00007fff`91eb3903 : 00000000`00000000 00000000`00000000 000000ef`227ff6b0 00000000`00000000 : wpfgfx_cor3!CComposition::BeginProcessVideo+0x56
000000ef`227ff5f0 00007fff`91eb3a7a : 000002e4`939c7330 00000000`00000000 000002e4`938a4340 00000000`00000000 : wpfgfx_cor3!CComposition::ProcessComposition+0x153
000000ef`227ff680 00007fff`91e70dde : 00000000`00000000 000002e4`938a4340 000002e4`939c8ed0 00000000`00000000 : wpfgfx_cor3!CComposition::Compose+0x4a
000000ef`227ff6b0 00007fff`91e70f5f : 00000000`00000000 000002e4`939c8ed0 000002e4`939c8ed0 000002e4`939c8ed0 : wpfgfx_cor3!CPartitionThread::RenderPartition+0x3e
000000ef`227ff6f0 00007fff`91e70c73 : 000002e4`938a4340 00000000`00000000 00000000`00000000 00000000`00000000 : wpfgfx_cor3!CPartitionThread::Run+0x6f
000000ef`227ff720 00007fff`e2b74de0 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : wpfgfx_cor3!CPartitionThread::ThreadMain+0x23
000000ef`227ff750 00007fff`e3a9ec4b : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : kernel32!BaseThreadInitThunk+0x10
000000ef`227ff780 00000000`00000000 : 00000000`00000000 00000000`00000000 00000000`00000000 00000000`00000000 : ntdll!RtlUserThreadStart+0x2b
STACK_COMMAND: ~8s; .ecxr ; kb
FAULTING_SOURCE_LINE: D:\a\_work\1\s\src\Microsoft.DotNet.Wpf\src\WpfGfx\shared\util\UtilLib\Assert.inl
FAULTING_SOURCE_FILE: D:\a\_work\1\s\src\Microsoft.DotNet.Wpf\src\WpfGfx\shared\util\UtilLib\Assert.inl
FAULTING_SOURCE_LINE_NUMBER: 615
FAULTING_SOURCE_SRV_COMMAND: https://raw.githubusercontent.com/dotnet/wpf/df04c57b2e2bb986f0afc2384cbebb3c950447b5/src/Microsoft.DotNet.Wpf/src/WpfGfx/shared/util/UtilLib/Assert.inl
FAULTING_SOURCE_CODE:
No source found for 'D:\a\_work\1\s\src\Microsoft.DotNet.Wpf\src\WpfGfx\shared\util\UtilLib\Assert.inl'
SYMBOL_NAME: wpfgfx_cor3!AssertW+143
MODULE_NAME: wpfgfx_cor3
IMAGE_NAME: wpfgfx_cor3.dll
FAILURE_BUCKET_ID: BREAKPOINT_80000003_wpfgfx_cor3.dll!AssertW
OS_VERSION: 10.0.20348.1
BUILDLAB_STR: fe_release
OSPLATFORM_TYPE: x64
OSNAME: Windows 10
IMAGE_VERSION: 7.0.222.60602
FAILURE_ID_HASH: {8235c892-b0fc-0e04-8769-4c437497ea21}
Followup: MachineOwner
---------
```
### Reproduction Steps
Unfortunately we don't have a reliable reproduction. This crash only seems to happen when we are using the `CompositionTarget.Rendering` event to capture the output of the user control.
### Expected behavior
The WPF app runs as per normal.
### Actual behavior
At "random" intervals with enough time, the WPF app will crash.
### Regression?
_No response_
### Known Workarounds
_No response_
### Impact
_No response_
### Configuration
OS: Windows Server 2022
.NET Version: 7
Architecture: x64
Amazon g4dn.4xlarge in eu-central-1a
Graphics: nVidia Tesla T4
NICE DCV is enabled
### Other information
A crash dump file is available and can be shared.
Contributor guide
Assessment
This issue has not been assessed yet.