| Previous | Next |
| OSS_MORE_BUF | OSS_PDU_RANGE |
OSS_NEGATIVE_UINTEGER
OSS_NEGATIVE_UINTEGER (0x80093002) is an OSS ASN.1 runtime result for negative value in a nonnegative INTEGER domain. A value represented by the generated API as an unsigned or nonnegative ASN.1 INTEGER is negative when the encoder evaluates it. Because the ASN.1 lower bound and generated member type is central to this condition, Microsoft’s HRESULT range and the OSS Nokalva return-code documentation should be read together. Start the investigation by recording the value before conversion or sign extension, then separate the encoded value from generated artifacts, call arguments, and the runtime package actually loaded by the process.
What the return code narrows down
At the negative value in a nonnegative INTEGER domain boundary, capture the first OSS function returning the value and note whether the operation was encode, decode, copy, compare, constraint validation, or trace setup. Preserve the selected PDU, encoding rules, and the source field and any sentinel convention; otherwise an outer certificate or security wrapper may hide the useful codec result behind a generic failure.
Test one variable at a time
- encode the smallest legal boundary value
- trace signed-to-unsigned casts at the producer
- compare the value with the schema used to generate this build
Build a useful capture
| Record | Diagnostic value |
|---|---|
| the ASN.1 lower bound and generated member type | Locates the concrete message, allocation, module, or API boundary |
| the value before conversion or sign extension | Separates payload-dependent behavior from build and process state |
| the source field and any sentinel convention | Makes the comparison reproducible without rewriting the original artifact |
Neighboring statuses: the result
This is a value-domain failure, not malformed BER received from the network and not an integer too large for an implementation limit.
Keep the original bytes or object graph unchanged while testing encode the smallest legal boundary value. A change in the value before conversion or sign extension after reload, plugin replacement, restart, or schema deployment is evidence about runtime state, not permission to discard the reproducer. When the source field and any sentinel convention points to one message, retain a cryptographic hash and the smallest safe sample instead of logging certificate, subscriber, credential, or private-key material.
Instrumentation
Record the full 32-bit HRESULT and lower OSS return number together with operation direction, symbolic PDU, encoding rule, byte count, and generated-table identifier. Where the ASN.1 lower bound and generated member type can expose sensitive content, a hash plus a bounded structural excerpt is safer than the complete payload. Use the value before conversion or sign extension together with OSS module paths and versions logged once per process so packaging differences can be correlated without flooding normal diagnostics.
Decision matrix
| Controlled observation | Conclusion it supports |
|---|---|
| encode the smallest legal boundary value | A changed outcome isolates the first proposed control instead of a blind retry |
| the ASN.1 lower bound and generated member type differs between success and failure | The difference localizes the negative value in a nonnegative INTEGER domain boundary before unrelated settings are changed |
| An independent decoder accepts the same artifact | Inspect generated schema, selected rules, ABI, and optional OSS modules before declaring the bytes invalid |
| A fresh control object changes the outcome | Investigate initialization, lifecycle, allocator ownership, configuration mutation, and concurrent access |
Verify the repair: the result
Correct the producer or schema mapping and retain negative and zero boundary tests. A recovery test built around encode the smallest legal boundary value should replay the same operation under the same schema and encoding rule, retain one deliberately invalid control, and verify ownership and cleanup after both outcomes. Success after an unexamined retry is not proof that the ASN.1 lower bound and generated member type now satisfies the codec contract.
Technical references
- Microsoft: OSS ASN.1 HRESULT definitions
- OSS Nokalva: encoder/decoder return codes
- OSS Nokalva: runtime functions and control initialization
- Relevant ASN.1 specification or runtime detail
Looking for a different code? Search another status or error code.