【发布时间】:2017-05-06 13:57:10
【问题描述】:
我有一个在生产环境 (WINDOWS XP + .NET 3.5 SP1) 中运行的 .NET 应用程序,其句柄数稳定在 2000 左右,但在某些未知情况下,它的句柄数会以极快的速度增加并最终自行崩溃(超过 10,000由 PerfMon 工具监控)。
我在增加期间从那里进行了内存转储(尚未崩溃)并导入到WinDbg,可以看到整体句柄摘要:
0:000> !handle 0 0
7229 Handles
Type Count
None 19
Event 504
Section 6108
File 262
Port 15
Directory 3
Mutant 56
WindowStation 2
Semaphore 70
Key 97
Token 2
Process 3
Thread 75
Desktop 1
IoCompletion 9
Timer 2
KeyedEvent 1
所以不足为奇,泄漏类型是 Section,请继续挖掘:
0:000> !handle 0 ff Section
Handle 00007114
Type Section
Attributes 0
GrantedAccess 0xf0007:
Delete,ReadControl,WriteDac,WriteOwner
Query,MapWrite,MapRead
HandleCount 2
PointerCount 4
Name \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IBC.AKCHAC.CGOOBGKD
No object specific information available
Handle 00007134
Type Section
Attributes 0
GrantedAccess 0xf0007:
Delete,ReadControl,WriteDac,WriteOwner
Query,MapWrite,MapRead
HandleCount 2
PointerCount 4
Name \BaseNamedObjects\MSCTF.MarshalInterface.FileMap.IBC.GKCHAC.KCLBDGKD
No object specific information available
...
...
...
...
6108 handles of type Section
可以看到BaseNamedObjects'的命名约定都是MSCTF.MarshalInterface.FileMap.IBC.***.*****。
基本上我被拦在了这里,无法进一步将信息链接到我的应用程序。
有人可以帮忙吗?
[编辑0]
尝试了GFlags 命令的几种组合(+ust 或通过 UI),但没有成功,使用 WinDbg 打开的转储总是通过!htrace 看不到任何内容,因此必须使用 附加进程最后我得到了上面泄漏句柄的堆栈:
0:033> !htrace 1758
--------------------------------------
Handle = 0x00001758 - OPEN
Thread ID = 0x00000768, Process ID = 0x00001784
0x7c809543: KERNEL32!CreateFileMappingA+0x0000006e
0x74723917: MSCTF!CCicFileMappingStatic::Create+0x00000022
0x7473fc0f: MSCTF!CicCoMarshalInterface+0x000000f8
0x747408e9: MSCTF!CStub::stub_OutParam+0x00000110
0x74742b05: MSCTF!CStubIUnknown::stub_QueryInterface+0x0000009e
0x74743e75: MSCTF!CStubITfLangBarItem::Invoke+0x00000014
0x7473fdb9: MSCTF!HandleSendReceiveMsg+0x00000171
0x7474037f: MSCTF!CicMarshalWndProc+0x00000161
*** ERROR: Symbol file could not be found. Defaulted to export symbols for C:\Windows\system32\USER32.dll -
0x7e418734: USER32!GetDC+0x0000006d
0x7e418816: USER32!GetDC+0x0000014f
0x7e4189cd: USER32!GetWindowLongW+0x00000127
--------------------------------------
然后我又卡住了,堆栈似乎没有包含我们的任何用户代码,有什么建议可以继续前进?
【问题讨论】:
-
使用 WPR/Perfview 捕获句柄使用情况并使用 WPA/Perfview 进行分析:geekswithblogs.net/akraus1/archive/2016/03/14/173308.aspx
-
如果应用程序在达到 10000 个句柄限制时崩溃,那么您可能正在泄漏 GDI/用户句柄而不是内核模式句柄。
标签: windows performance memory-leaks windbg