windows11bugs
4 Topics[GSOD]SYSTEM_SERVICE_EXCEPTION in win32kfull!SetMagnificationInputTransform when a process exits
问题概述 Windows 11 Insider Experimental 26H2 Build 26340.9233 连续发生两次绿屏崩溃。 两份 minidump 经 WinDbg 分析后指向完全相同的故障函数、调用栈、触发进程及故障哈希。崩溃发生在 Windows 销毁进程关联的桌面对象,并清理屏幕放大输入变换状态时。 系统环境 操作系统:Windows 11 Pro for Workstations Insider 通道:Experimental 显示版本:26H2 完整系统版本:26340.9233 BuildLabEx:26100.6.amd64fre.ge_release_flt.260716-1700 系统架构:x64 win32kfull.sys 版本:10.0.26100.9233 BIOS Revision:1.42.0.0 Hyper-V:已启用 故障现象 系统显示绿色停止错误画面并自动重启: Stop code:SYSTEM_SERVICE_EXCEPTION Bugcheck:0x0000003B Exception code:0xC0000005 What failed:win32kfull.sys 该问题在同一天连续发生两次,并分别生成以下转储: 082226-21906-01.dmp 082226-21734-01.dmp WinDbg 分析结果 两份转储的分析结果一致: BUGCHECK_CODE: 3b BUGCHECK_P1: c0000005 PROCESS_NAME: codex-command-runner-0.149.0-alpha.4.1.exe FAILURE_BUCKET_ID: AV_win32kfull!SetMagnificationInputTransform FAILURE_ID_HASH: {527223d9-4b8b-e502-e7e6-16fc4649fd38} SYMBOL_NAME: win32kfull!SetMagnificationInputTransform+39 IMAGE_NAME: win32kfull.sys IMAGE_VERSION: 10.0.26100.9233 故障指令: win32kfull!SetMagnificationInputTransform+0x39: mov rbx, qword ptr [rax+1F0h] RAX = 0000000000000000 这表明内核代码尝试通过空指针读取内存,从而触发 0xC0000005 访问冲突。 关键调用栈 nt!NtTerminateProcess nt!PspExitThread nt!PspExitLastThread nt!PspRundownSingleProcess nt!ObKillProcess nt!ExSweepHandleTable nt!ExpWin32CloseProcedure win32k!W32CalloutDispatchThunk win32kbase!W32CalloutDispatch win32kfull!UnmapDesktop win32kfull!DestroyDesktop win32kfull!zzzDecomposeDesktop win32kfull!MagpDecomposeDesktop win32kfull!MagpRevokeInputTransfrom win32kfull!CancelMagnificationInputTransform win32kfull!SetMagnificationInputTransform+0x39 从调用栈判断,崩溃发生在以下过程中: codex-command-runner 进程退出; Windows 清理该进程及其桌面对象; win32kfull.sys 撤销 Magnification Input Transform; SetMagnificationInputTransform 解引用空指针; 系统触发 SYSTEM_SERVICE_EXCEPTION。 重复性 两次崩溃均具有以下共同点: 相同停止代码和异常类型; 相同故障函数及函数偏移; 相同的空指针访问方式; 相同触发进程及版本; 相同桌面销毁和放大输入变换清理调用栈; 相同 Failure ID Hash。 因此,该问题具有较强的可重复性,不像随机硬件错误。 目前尚未完全确定具体的用户操作序列,但两次均发生在 Codex 桌面应用的本地命令运行器退出期间。该进程看起来是触发场景;实际非法访问发生在 Windows 内核的 win32kfull.sys 中。 预期行为 任何普通用户态进程退出或其桌面对象被销毁时,Windows 都应安全清理 Magnification Input Transform 状态。即使相关状态不存在、已经释放或不完整,也不应发生内核空指针访问或导致整个系统崩溃。 实际行为 win32kfull!SetMagnificationInputTransform 在桌面销毁路径中收到或获取了空对象,但没有在访问对象偏移 0x1F0 前进行有效性检查,最终导致系统级崩溃。 希望微软协助调查 请重点检查 Build 26340.9233 中以下方面: SetMagnificationInputTransform 的对象生命周期和空指针检查; CancelMagnificationInputTransform 与 MagpRevokeInputTransfrom 的重复撤销或竞态条件; 临时桌面、隔离桌面或进程退出时的 DestroyDesktop 清理路径; Experimental 26340 系列中 Magnifier 相关改动是否影响输入变换状态; 短时间内创建并销毁桌面的应用是否能够稳定触发该问题。 English engineering summary Two independent minidumps from Windows 11 Insider Experimental Build 26340.9233 show an identical SYSTEM_SERVICE_EXCEPTION (0x3B) with 0xC0000005. The crash occurs at: win32kfull!SetMagnificationInputTransform+0x39 mov rbx, qword ptr [rax+1F0h] RAX = 0 Both dumps have the same process, stack, failure bucket and failure hash: PROCESS_NAME: codex-command-runner-0.149.0-alpha.4.1.exe FAILURE_BUCKET_ID: AV_win32kfull!SetMagnificationInputTransform FAILURE_ID_HASH: {527223d9-4b8b-e502-e7e6-16fc4649fd38} The process is terminating, Windows destroys its associated desktop, and the kernel crashes while revoking the Magnification Input Transform: NtTerminateProcess → PspRundownSingleProcess → ExpWin32CloseProcedure → UnmapDesktop → DestroyDesktop → MagpDecomposeDesktop → MagpRevokeInputTransfrom → CancelMagnificationInputTransform → SetMagnificationInputTransform → NULL pointer dereference Please investigate the object lifetime, synchronization and null validation in the Magnification Input Transform cleanup path when a temporary or isolated desktop is destroyed.220Views4likes3CommentsBitLocker Loop / Soft-Brick After Secure Boot 2023 Certificate Update (ASUS ROG G713QE)
Hello, following the June 2026 Windows Update regarding the transition to "Microsoft UEFI CA 2023" Secure Boot keys, my machine (ASUS ROG Strix G713QE, AMD Ryzen CPU with fTPM) experienced a critical failure cascade leading to an infinite BitLocker recovery loop. Exact Step-by-Step Failure Chronology: Initial Post-Update Boot: The machine booted directly into the blue BitLocker Recovery screen, prompting for the 48-digit recovery key. First Unlock & WinRE Access: Entering the correct 48-digit key successfully decrypted the drive and allowed access to the Windows Recovery Environment (WinRE). Standard Recovery Failures: All default automated repair methods (Startup Repair, etc.) failed, systematically looping back to the WinRE menu. Failed Update Uninstall: Attempting to use the "Uninstall latest quality/feature update" option threw an error stating that Windows could not uninstall the update due to an update currently in progress. (Note: This strongly suggests that pending transaction flags or file-lock attributes in the Component-Based Servicing store were never cleared due to the unfinalized update state). System Restore Attempt: A System Restore point was selected. The progress bar completed successfully, and the validation/success pop-up appeared. A reboot was then triggered. The Hard Loop: Upon this post-restore reboot, the system fell into an infinite BitLocker loop. Entering the 48-digit key now causes an immediate crash/reset, completely locking out any further access to the Windows Recovery Environment (WinRE). Current Root Cause Analysis: The only way to regain temporary access to the OS was to perform a full UEFI BIOS reflash, which allowed exactly one functional boot (rebooting at this state threw us back to the BitLocker hard loop). Once inside, the loop was permanently stabilized by executing the following command in an elevated prompt to purge the stuck transaction: DISM /Online /Cleanup-Image /RevertPendingActions BitLocker protection has also been suspended (manage-bde -protectors -disable C:) to prevent the TPM from locking up the system again. There is a major structural conflict on this motherboard generation between the new Microsoft CA 2023 certificate write-orders in the NVRAM, the CBS transaction state, and the ASUS fTPM firmware validation. Please deploy a BIOS fix or implement a compatibility safeguard hold on Windows Update for this hardware profile.190Views0likes0CommentsFacing Issues with Insider Preview (27808.1000)
Hello, I’m facing an issue where my graphics application (Autodesk Fusion 360) only works when I disable my NVIDIA graphics driver. However, as soon as I enable the driver, the application stops working. System Details: GPU Model: NVIDIA 1650 Operating System: Windows 11 Insider Preview 27808.1000 (rs_prerelease) Driver Version: NVIDIA Driver Version 572.70 Application Affected: Autodesk Fusion 360, OpenSCAD Troubleshooting Steps I’ve Tried: Reinstalled the NVIDIA Driver (Used a clean installation from the official NVIDIA website). Tried Rolling Back the Driver (If a newer update caused the issue). Checked NVIDIA Control Panel Settings (Set preferred GPU to NVIDIA, power management to maximum performance). Verified Windows Updates (Ensured my OS is up to date). Checked for Application-Specific Compatibility Issues.191Views0likes2Comments