Share via


Why Did SQL 2016 Crash ?

Question

Tuesday, May 9, 2017 8:30 PM

Came in to work, and applications could not connect to SQL. 
SQL Service was Stopped
This is a new system, going live soon.
SQL 2016 Ver 13.0.1601.5   on a VM Windows Server 2016, at a hosted site.
4 CPUs
4 each: Processor Intel(R) Xeon(R) CPU E5-2640 v3 @ 2.60GHz, 2594 Mhz, 1 Core(s), 1 Logical Processor(s)

Installed Physical Memory (RAM)____16.0 GB
Total Physical Memory______________16.0 GB
Available Physical Memory___________1.02 GB (Does this mean 15 G used, 1G remaining?)
Total Virtual Memory_______________20.0 GB
Available Virtual Memory____________4.38 GB 

No load on the server at the time (8:40 pm), just light testing during the day.
I do see some references out on the net about Linked Servers causing problem. I do have a Linked Server to a MySQL database, that pulls in data to SQL, compares ID numbers, and inserts into MySQL if it doesn't exist there. It's a pretty light job, runs every 10 minutes, , and has been running for years on our old SQL 2005 server.

min server memory (MB) 0 2147483647 0 16

max server memory (MB) 128 2147483647 2147483647 2147483647

SQL Agent Log

5/7/2017 . . 8:40:00 PM) Message [298] SQLServer Error: 109, Shared Memory Provider: Thepipe has been ended. [SQLSTATE 08S01]

5/7/2017 . . 8:40:00 PM) [298] SQLServer Error: 109, Communication link failure [SQLSTATE08S01]

5/7/2017 . . 8:40:00 PM) [298] SQLServer Error: 16389, Communication link failure [SQLSTATE08S01]

5/7/2017 . . 8:40:00 PM) [012] The MSSQLSERVER service terminated unexpectedly

5/7/2017 . . 8:40:00 PM) [139] AutoRestart: Attempting to restart the MSSQLSERVER service(attempt #1)...

5/7/2017 . . 8:40:00 PM) [368] AutoRestart: Unable to restart the MSSQLSERVER service(reason: Access is denied)

5/7/2017 . . 8:40:00 PM) [360] SQLServerAgent initiating shutdown following MSSQLSERVERshutdown

5/7/2017 . . 8:40:00 PM) [240] 1 engine thread(s) failed to stop after 2 seconds of waiting

5/7/2017 . . 8:40:00 PM) [311] Thread 'JobInvocationEngine' (ID 2832) is still running

5/7/2017 . . 8:40:00 PM) [359] The local host server is not running

5/7/2017 . . 8:40:00 PM) [098] SQLServerAgent terminated (forcefully)

WINDOWS APPLICATION LOG

5/7/20178:40:06 PM

Log Windows NT(Application)

Source Application Error

Category (100)

Event 1000

Computer DB07

Message

Faultingapplication name: sqlservr.exe, version: 2015.130.1601.5, time stamp:0x5724ae45

Faultingmodule name: ntdll.dll, version: 10.0.14393.479, time stamp: 0x5825887f

Exceptioncode: 0xc0000374

Faultoffset: 0x00000000000f8283

Faultingprocess id: 0xacc

Faultingapplication start time: 0x01d2c0bb0eeefae5

Faultingapplication path: C:\Program Files\Microsoft SQLServer\MSSQL13.MSSQLSERVER\MSSQL\Binn\sqlservr.exe

Faultingmodule path: C:\Windows\SYSTEM32\ntdll.dll

Report Id:5af64bbe-1137-4273-8aba-c0b9427cbf11

Faultingpackage full name:

Faultingpackage-relative application ID:

**
++++++++++++++++++++++++++++++**

5/7/20178:40:10 PM

Log Windows NT(Application)

Source Windows Error Reporting

Category (0)

Event 1001

Computer DB07

Message

Fault bucket, type 0

Event Name:APPCRASH

Response:Not available

Cab Id: 0

Problemsignature:

P1:sqlservr.exe

P2:2015.130.1601.5

P3: 5724ae45

P4:StackHash_c5cd

P5:10.0.14393.479

P6: 5825887f

P7: c0000374

P8 : CH_95_FROM_ntdll+0x00000000000A6C24

P9:

P10:

Attachedfiles:

These filesmay be available here:

C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_sqlservr.exe_2e75b9c7e3ef8fc936a2686aa3e8b22c226f9eff_50240049_36d88ad8

Analysissymbol:

Recheckingfor solution: 0

Report Id:5af64bbe-1137-4273-8aba-c0b9427cbf11

ReportStatus: 4

Hashedbucket:

++++++++++++++++++++++++++++++

TheMSSQLSERVER service terminated unexpectedly.

All replies (6)

Tuesday, May 9, 2017 8:31 PM

Error Messages, Part 2

++++++++++++

++++++++++++++++++++++++++++++

5/7/20178:40:20 PM

Log Windows NT(Application)

Source Microsoft-Windows-UserProfiles Service

Category (0)

Event 1530

User NT AUTHORITY\SYSTEM

Computer DB07

Message

Windowsdetected your registry file is still in use by other applications or services.The file will be unloaded now. The applications or services that hold yourregistry file may not function properly afterwards. No user action is required.

DETAIL -

15 user registry handles leaked from\Registry\User\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003:

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\SOFTWARE\Microsoft\SystemCertificates\CA

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\SOFTWARE\Policies\Microsoft\SystemCertificates

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\SOFTWARE\Policies\Microsoft\SystemCertificates

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\SOFTWARE\Policies\Microsoft\SystemCertificates

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\SOFTWARE\Policies\Microsoft\SystemCertificates

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\SOFTWARE\Microsoft\SystemCertificates\trust

Process 1016(\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\SOFTWARE\Microsoft\SystemCertificates\Root

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key\REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\SOFTWARE\Microsoft\SystemCertificates\Disallowed

Process 688(\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-80-3880718306-3832830129-1677859214-2598158968-1052248003\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot

++++++++++++++++++++++++++++++

5/7/20178:40:24 PM

Log Windows NT(Application)

Source Windows Error Reporting

Category (0)

Event 1001

Computer DB07

Message

Fault bucket120755943884, type 4

Event Name:APPCRASH

Response:Not available

Cab Id: 0

Problemsignature:

P1:sqlservr.exe

P2:2015.130.1601.5

P3: 5724ae45

P4:StackHash_c5cd

P5:10.0.14393.479

P6: 5825887f

P7: c0000374

P8 CH_95_FROM_ntdll+0x00000000000A6C24

P9:

P10:

Attachedfiles:

These filesmay be available here:

C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_sqlservr.exe_2e75b9c7e3ef8fc936a2686aa3e8b22c226f9eff_50240049_396cc486

Analysissymbol:

Recheckingfor solution: 0

Report Id:5af64bbe-1137-4273-8aba-c0b9427cbf11

ReportStatus: 0

Hashedbucket: aee6fbdcac83b76429f13a800da86f9b

++++++++++++++++++++++++++++++

5/7/20178:40:32 PM

Log Windows NT(Application)

Source Microsoft-Windows-UserProfiles Service

Category (0)

Event 1530

User NT AUTHORITY\SYSTEM

Computer DB07

Message

Windowsdetected your registry file is still in use by other applications or services.The file will be unloaded now. The applications or services that hold yourregistry file may not function properly afterwards. No user action isrequired.

DETAIL -

1 user registry handles leaked from\Registry\User\S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430:

Process 1016(\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key\REGISTRY\USER\S-1-5-80-344959196-2060754871-2302487193-2804545603-1466107430\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall

++++++++++++++++++++++++++++++

5/8/20172:00:26 AM

Log Windows NT (Application)

Source .NET Runtime

Category (0)

Event 1026

Computer DB07

Message

Application:SQLSQM.EXE

FrameworkVersion: v4.0.30319

Description:The process was terminated due to an unhandled exception.

ExceptionInfo: System.IO.FileLoadException

at Microsoft.SqlServer.Sqm.Launcher.Main(System.String[])

++++++++++++++++++++++++++++++

5/8/20172:00:26 AM

Log Windows NT(Application)

Source Application Error

Category (100)

Event 1000

Faultingapplication name: SQLSQM.EXE, version: 13.0.1601.5, time stamp: 0x5724522b

Faultingmodule name: KERNELBASE.dll, version: 10.0.14393.1066, time stamp: 0x58d9ef32

Exceptioncode: 0xe0434352

Faultoffset: 0x0000000000033c58

Faultingprocess id: 0x43a4

Faultingapplication path: C:\Program Files\Microsoft SQL Server\130\Shared\SQLSQM.EXE

Faultingmodule path: C:\Windows\System32\KERNELBASE.dll

Report Id:4813226e-8365-45eb-b258-c3f7defc4406


Wednesday, May 10, 2017 12:12 AM

Hello Homebrew,

You will find the dump files created for the app crash at C:\ProgramData\Microsoft\Windows\WER\ReportQueue. I think you should get hold of that file or files created during the SQL crash and get in touch with MS support.

Regards;
Vivek Janakiraman
www.jbswiki.com


Wednesday, May 10, 2017 5:49 AM

You should log a case with Microsoft and allow them to have a look at the tack dump produced. Is your SQL Server 2016 patched to Sp1 ?

Cheers,

Shashank

Please mark this reply as answer if it solved your issue or vote as helpful if it helped so that other forum members can benefit from it

My TechNet Wiki Articles
MVP


Wednesday, May 10, 2017 7:25 AM

This is a new system, going live soon.
SQL 2016Ver 13.0.1601.5   on a VM Windows Server 2016, at a hosted site.
4 CPUs
4 each: Processor Intel(R) Xeon(R) CPU E5-2640 v3 @ 2.60GHz, 2594 Mhz, 1 Core(s), 1 Logical Processor(s)

You have the RTM version of SQL 2016. You need to install SP1 of SQL 2016. There was an issue with a VC++ DLL, that you needed to install separately to run SQL 2016 RTM, it appears that you have missed this one. It should be included with SP1 as I recall.


Wednesday, May 10, 2017 1:55 PM

You have the RTM version of SQL 2016. You need to install SP1 of SQL 2016. There was an issue with a VC++ DLL, that you needed to install separately to run SQL 2016 RTM, it appears that you have missed this one. It should be included with SP1 as I recall.

Thanks. Installing SP1 now.


Friday, May 19, 2017 1:16 AM

Hi Homebrew,

Any update on the issue, was the issue resolved? If the issue has been resolved, please mark the corresponding replies as answer as it would benefit others when they are reading this thread. If not, could you please provide more information so we can have a better understanding about the issue?

If you have any other questions, please let me know.

Regards,
Davy

MSDN Community Support
Please remember to click "Mark as Answer" the responses that resolved your issue, and to click "Unmark as Answer" if not. This can be beneficial to other community members reading this thread. If you have any compliments or complaints to MSDN Support, feel free to contact MSDNFSF@microsoft.com.