>_0xFORUM
Sign in

# Debugging

unread
WOW64 debugging: 32-bit stack in a 64-bit WinDbg

WOW64. I forgot to switch to the 32-bit stack and read garbage for 20 minutes. !wow64exts.sw exists. I used it afte…

nospecMEMBERstarted 24 Aug 2026, 12:25
Last ReplyheapsprayheapsprayFriday, 12:57
9posts259viewshexraysnt_xgetbvio_gske_dpc9 reading
unread
rr --stap-sdt vs regular breakpoints on a usdt probe

USDT probes in a public binary. rr could see them. Regular gdb needed the extra setup. I will start adding USDT pro…

stibpstibpMEMBERstarted 5 Aug 2026, 21:34
Last ReplymicromicroThursday, 19:03
11posts457viewsex_sysretsoftlockio_wbinvdnpaged8 reading
Sanitizer vs debugger: who goes first on a new crash

New crash in CI with ASan. I opened the report, then the debugger. The report was enough. I still opened the debugg…

saferetsaferetMEMBERstarted 25 Aug 2026, 13:03
Last Replyendbr64endbr64Wednesday, 04:21
16posts300viewscm_cr3ob_inveptcm_rdrandndis_int36 reading
hot
Deadlock in a thread pool — which wait chain tool did not lie

Windows wait chain traversal said nothing useful. WinDbg !locks plus a hang dump showed two SRW locks taken backwar…

tscskewtscskewMEMBERstarted 6 Jan 2026, 02:54
Last ReplymmiostalemmiostaleTuesday, 04:34
10posts4.1kviewsalpc_seamretwfp_syscallstor_invlpgio_sti7 reading
Watchpoints on unaligned fields — x86 vs ARM64

x86 hardware watchpoint on a 3-byte field worked by accident. ARM64 refused. I watched the 8-byte container. Docume…

avx512avx512MEMBERstarted 5 Jul 2026, 06:51
Last Replyenqcmdenqcmd23 Aug 2026, 08:09
15posts1.1kviewske_dpcrootkit_ivanint3loopetw_stac10 reading
hot
Reproducing a file-watcher race with rr --chaos

The bug only showed up on a loaded CI runner. Locally it was a heisenbug. rr record --chaos hit it in ~40 recording…

rttimsvcMEMBERstarted 27 Aug 2025, 02:49
Last Replysha256rsha256r19 Aug 2026, 11:58
28posts2.6kviewsndis_dr7alpc_wbinvdhexraysnt_xgetbv8 reading
hot
First-chance vs second-chance — people still break on every throw

C++ exceptions as first-chance will ruin your day on a UI app. Break on second-chance unless you are hunting a swal…

nminestMEMBERstarted 13 Dec 2025, 22:39
Last Replypkskey12 Aug 2026, 00:58
9posts3.7kviewsse_xgetbvse_invvpidndis_vmxonollyhold5 reading
hot
rr pack + git-lfs — we tried, we regretted

Storing recordings in git-lfs. They bitrotted, they were huge, nobody replayed them. We keep a 30-day NAS instead. …

gnuhashgnuhashMEMBERstarted 24 Apr 2026, 10:20
Last Replyrasbankrasbank8 Aug 2026, 03:36
21posts929viewsndis_vmxonollyholdex_sysret4 reading
Crash in a spawned helper that the parent waited on

Parent looked hung. Child had already crashed. People dumped the parent for two hours. If there is a helper process…

fsbasefsbaseMEMBERstarted 31 Jul 2026, 02:26
Last Replybugonbugon6 Aug 2026, 07:20
6posts460viewsse_invvpid1 reading
hot
Hang dumps vs crash dumps — which one your on-call should collect

Service hung, no exception. People collected a minidump and we learned nothing. Hang dump, full, with handle stack …

sleighjitsleighjitMEMBERstarted 15 Nov 2025, 08:07
Last Replyracehuntracehunt4 Aug 2026, 23:20
12posts2.3kviewsnpaged1 reading
dbgeng vs pykd vs javascript — 2026 lab default

I still write pykd for batch dumps. JS for interactive. Raw dbgeng for one tool that must not depend on Python. Thr…

clwbclwbMEMBERstarted 21 Jul 2026, 20:58
Last Replyracehuntracehunt4 Aug 2026, 23:20
7posts274viewsvehchainob_dr7ke_hlt4 reading
hot
gdb catch syscall plus a filter — still useful?

catch syscall write, then a condition on the fd. It worked. It was slow. strace -e would have been enough for this …

startioMEMBERstarted 6 Mar 2026, 04:08
Last Replythpsplit1 Aug 2026, 23:19
27posts1.6kviewsse_xgetbvse_invvpidndis_vmxon6 reading
Replay a TTD trace on a different machine — symbol path pain

Trace on a lab box, replay on a laptop. Symbols missing, line numbers gone, I stared at disassembly I already under…

microcodemicrocodeMEMBERstarted 15 Jun 2026, 07:10
Last Replycgroupv2cgroupv231 Jul 2026, 23:29
11posts1.4kviewsnt_inveptnt_msr2 reading
ETW while debugging — do you leave it on?

Debugging a service with ETW session still running. The session caught my debugger's own noise and I chased a ghost…

asanringMEMBERstarted 1 Jun 2026, 16:41
Last Replyyamayama29 Jul 2026, 16:39
13posts1.4kviewsio_wbinvdnpagedex_epcpagestor_fs6 reading
Hardware breakpoints that vanish under a hypervisor

DR0-DR3 worked bare metal. Under Hyper-V the guest debugger lost them on some resumes. I switched to code breakpoin…

headlessheadlessMEMBERstarted 18 Nov 2025, 03:41
Last Replypaulnoblepaulnoble29 Jul 2026, 16:10
9posts1.5kviewsalpc_wbinvdhexraysnt_xgetbvio_gs8 reading
When to stop stepping and start reading

I stepped 400 times. The bug was a comment that lied about ownership. Reading the function would have been faster. …

clacstacclacstacMEMBERstarted 16 Jul 2026, 04:32
Last Replyinitarrayinitarray27 Jul 2026, 18:16
6posts850viewsalpc_ripalpc_tss3 reading
hot
rr chaos plus ASLR — pinning the recording

Chaos mode plus ASLR made two recordings incomparable. I pin layout for the campaign, then re-enable ASLR for the f…

retsyncretsyncMEMBERstarted 4 Nov 2025, 10:51
Last Replyoutstackoutstack24 Jul 2026, 03:38
10posts1.5kviewsob_mdlvehchainob_dr7ke_hlt4 reading
hot
gdb record vs rr vs Intel PT — a boring lab comparison

I keep seeing Twitter comparisons. Here is a week of using all three on the same flaky parser. rr won for userspace…

gdbrecgdbrecMEMBERstarted 21 Sep 2025, 10:32
Last Replypassivepassive23 Jul 2026, 08:12
82posts3.8kviewske_hltob_eenterndis_eresume5 reading
hot
printk + netconsole instead of a kernel debugger, still valid?

Embedded board, no debugger transport. netconsole + a panic on WARN. It shipped a fix. Not every kernel bug needs k…

invpcidMEMBERstarted 24 Jun 2026, 16:45
Last Replyttdposttdpos25 Jun 2026, 15:43
23posts370viewsio_stips_seamretcm_cr3ob_invept7 reading
hot
Stack smash that ASan caught and WinDbg !analyze called 'heap'

Stack buffer. ASan said stack. !analyze said heap corruption because we had already returned. I believed ASan. Orde…

pstoreMEMBERstarted 11 Jun 2026, 12:16
Last Replypaveldbgpaveldbg19 Jun 2026, 13:23
34posts1.1kviewswfp_syscallstor_invlpgio_stips_seamret5 reading
hot
gdb 'finish' that never finishes because of a longjmp

finish from a frame that longjmp'd out. gdb sat there. I Ctrl-C and used the recording instead. If the code has set…

btfidMEMBERstarted 20 May 2026, 17:51
Last Replyhltspinhltspin22 May 2026, 18:59
10posts1.6kviewsstor_invlpgio_stips_seamretcm_cr39 reading
hot
Non-invasive attach to a production-shaped lab process

I needed stacks without changing timing much. Non-invasive attach, dump, detach. Good enough. Invasive attach is a …

bpflsmbpflsmMEMBERstarted 15 May 2026, 20:18
Last Replymcestackmcestack17 May 2026, 00:21
11posts1.5kviewsob_inveptcm_rdrandndis_int3idtvec8 reading
Verifier + driver verifier + our filter — boot loop

Enabled both, forgot a flag, boot loop on the lab box. Recovery from last known good. Snapshot next time. Verifier …

baikalMEMBERstarted 7 May 2026, 17:35
Last Replyxorpsexorpse8 May 2026, 00:13
7posts724viewsalpc_rip1 reading
hot
Thread names in dumps — set them, I beg you

A dump with 80 threads named 'unknown' or 'ThreadPool'. Set the name at creation. WinDbg and gdb both show it. This…

relroMEMBERstarted 17 Apr 2026, 23:19
Last Replycookiemon18 Apr 2026, 11:03
12posts1.6kviewsvolchokstor_mdl3 reading
Core dump from a container that has no gdb inside

Distroless. No gdb. I copy the core and the exact libs out, then gdb on a sibling image with debug symbols. Please …

endbr64endbr64MEMBERstarted 7 Apr 2026, 02:09
Last Replywrpkruwrpkru7 Apr 2026, 23:55
7posts1.1kviewsob_eenterndis_eresumehex_olga10 reading
hot
WinDbg preview vs classic — I still keep both

Preview for TTD and dx. Classic for a kernel connection that preview dropped once. Both stay on the tools snapshot.…

retguardMEMBERstarted 30 Mar 2026, 04:13
Last Replyramoops31 Mar 2026, 18:03
8posts1.9kviewsollyholdex_sysretsoftlock7 reading
hot
Heisenbug that vanished under a debugger and under rr

Timing bug that needed a loaded disk. Debugger and rr both slowed it enough to hide it. Logging with TSC stamps fou…

loadcfgloadcfgSENIORvendorstarted 21 Mar 2026, 23:34
Last Replyslaspecslaspec24 Mar 2026, 13:32
17posts2kviewsidtvec2 reading
hot
Minidump callback: what I include in 2026

Custom minidump callback. I include the heap? No. Indirect memory? Sometimes. Handle data? Yes for hangs. Paste you…

pushlockMEMBERstarted 16 Mar 2026, 05:13
Last Replyacpidsdtacpidsdt17 Mar 2026, 01:02
8posts1.5kviewsndis_int3idtvecalpc_rip5 reading
hot
AddressSanitizer suppressions that became the product

A 200-line suppression file. Half of it was real bugs we papered over. I deleted 80 lines and CI went red in a good…

cryptcryptGUESTstarted 28 Feb 2026, 09:12
Last Replyartemttdartemttd2 Mar 2026, 22:51
17posts1.5kviewsint3loopetw_stacob_mdlvehchain9 reading
hot
WinDbg time travel: stepping across a syscall

Stepping into NtDeviceIoControlFile in TTD does not take you to the kernel. People still try. You get the user retu…

kdnetkdnetMEMBERstarted 17 Feb 2026, 19:14
Last Replyvolchokvolchok18 Feb 2026, 10:40
16posts3.5kviewsps_seamretcm_cr3ob_inveptcm_rdrand8 reading
hot
rr vs a logging build for a 2-hour soak

Soak test, 2 hours, race in hour 1.8. rr recording was huge. A logging build with seqlocks would have been cheaper.…

cioptscioptsMEMBERstarted 9 Feb 2026, 18:35
Last Replytebselftebself11 Feb 2026, 13:46
9posts3.9kviewsio_gs1 reading
hot
Kernel dump from a VM that has no serial and no kdnet

Nested VM, no debug transport. I triggered a hang dump from the hypervisor side and pulled the vmem. It worked. It …

bootmgfwbootmgfwMEMBERstarted 29 Jan 2026, 21:21
Last Replyrttimsvcrttimsvc30 Jan 2026, 19:01
12posts1.5kviewsrootkit_ivanint3loopetw_stacob_mdl4 reading
hot
Conditional breakpoints that make the target unusable

A condition that walks a list on every hit. Target became a slideshow. I logged instead. When is a conditional brea…

spidumpspidumpMEMBERstarted 22 Jan 2026, 00:14
Last Replycetsscetss22 Jan 2026, 21:50
12posts2.9kviewsstor_mdl3 reading
sOS / managed TTD — traces that actually help

Managed service, TTD, SOS. The interesting frame was a transition and SOS shrugged until I loaded the right DAC. DA…

smbiossmbiosMEMBERstarted 12 Jan 2026, 10:17
Last Replycpuidleafcpuidleaf14 Jan 2026, 08:59
17posts1.2kviewsetw_stacob_mdlvehchainob_dr710 reading
hot
lldb on Darwin vs gdb on Linux for the same C++ test

Same test, two platforms. lldb pretty-printers saved me. gdb + rr saved me more. I will not pretend they are interc…

ud2padud2padMEMBERstarted 27 Dec 2025, 14:08
Last Replyflossstrflossstr30 Dec 2025, 23:25
18posts4.2kviewsnt_xgetbvio_gs2 reading
hot
WinDbg Javascript vs dx LINQ — what I actually keep

I wrote a JS script, then a dx one-liner that did the same thing. The one-liner survived. The script bitrotted. If …

swapgsswapgsMEMBERstarted 8 Dec 2025, 07:17
Last Replybitstreambitstream8 Dec 2025, 23:24
17posts4kviewsndis_eresumehex_olgaalpc_seamretwfp_syscall6 reading
hot
gdb reverse-continue on a recording that is 40GB

rr pack, 40GB, reverse-continue from the crash to the first write. Took minutes, not hours. Still worth it. Where d…

wowentrywowentryMEMBERstarted 1 Dec 2025, 18:31
Last Replymkstructmkstruct7 Dec 2025, 08:00
35posts1.7kviewsex_epcpagestor_fsvolchokstor_mdl9 reading
hot
TTD memory queries that actually finish

People write dx queries that scan the whole trace for a byte pattern and then complain TTD is slow. Narrow to a tim…

ghidrafidMEMBERstarted 23 Oct 2025, 12:27
Last Replybaikal25 Oct 2025, 05:57
22posts4.7kviewsnt_invept3 reading
hot
Kernel debugging over kdnet instead of serial in 2026

Serial is honest and slow. kdnet on a lab host is fine if the NIC is dedicated. I still keep a serial fallback beca…

yarahotyarahotMEMBERstarted 19 Oct 2025, 21:50
Last Replyfsgsbasefsgsbase21 Oct 2025, 17:07
9posts2.2kviewsalpc_tssse_xgetbvse_invvpid10 reading
hot
Reproducing a CI-only flake without shipping the CI machine

Flake is 1/80 on CI, never local. I cannot copy the runner. cgroups + noise got me to 1/10 locally. If your CI is o…

flossstrflossstrMEMBERstarted 12 Oct 2025, 14:12
Last Replysimdfaultsimdfault14 Oct 2025, 12:30
11posts5.8kviewsob_eenterndis_eresumehex_olgaalpc_seamret7 reading
hot
WinDbg !analyze -v lied and I believed it for an hour

Bugcheck 0xA. !analyze pointed at a third-party filter. The actual bug was our completion routine completing twice.…

zydisMEMBERstarted 30 Sep 2025, 01:05
Last Replyheavenheaven1 Oct 2025, 18:57
10posts3kviewsob_dr7ke_hlt2 reading
hot
Page heap caught a use-after-free that ASan on Windows missed

Same test, two tools. ASan silent. Full page heap on a verifier-enabled build exploded immediately. The free was in…

ttdposttdposSENIORvendorstarted 9 Sep 2025, 20:10
Last Replyalignasalignas11 Sep 2025, 22:06
10posts3.2kviewsnt_msrndis_dr7alpc_wbinvdhexrays6 reading
hot
WinDbg TTD for a service that only fails on Tuesdays

Time Travel Tracing on a Windows service that deadlocks after a weekly GPO refresh. dx @$cursession.TTD.Calls("ntdl…

x64dbgbpx64dbgbpMEMBERstarted 2 Sep 2025, 14:53
Last Replysetnzsetnz5 Sep 2025, 04:24
12posts7.3kviewsex_sysretsoftlockio_wbinvd9 reading