| Previous | Next |
| hrTooManyIO | hrPMRecDeleted |
hrBFInUse
Where the workflow stopped
For hrBFInUse, treat the value as part of a state machine: it says what remained valid and what did not. The decisive boundary is the caller attempted to abandon or repurpose a buffer page that still has an active owner or dependency.
The stored Value is 0xC80000CA (negative JET error -202; -202). The HRESULT carries failure severity, so output state must be treated according to the individual API contract. The legacy this result name comes from the Windows Directory Service backup/restore message header.
The first useful distinction is that this is an ownership conflict, not the cache-miss warning hrBFPageNotFound. Start by record page identity, latch/reference counts, cursor and transaction owners, dirty state, and the operation requesting abandonment. That separates a reproducible incident from a later generic cleanup or service error.
Similar-looking outcomes
This result specifically means that this is an ownership conflict, not the cache-miss warning hrBFPageNotFound. Related values below can appear in the same workflow but require a different response:
hrDeleteBackupFileFail | backup cleanup could not delete an artifact it was responsible for removing |
|---|---|
hrLogBufferTooSmall | the available recovery log buffer cannot hold the log record or sector data required for replay |
hrRestoreMapExists | a restore map is already registered for the component while the caller attempts to add another mapping |
Keep the original constant and hexadecimal value in telemetry. Replacing this result with “backup failed” or “database warning” removes the state information needed to select the next legal API call.
Objects and state involved
| Diagnostic layer | buffer-page ownership, dependencies, dirty state, and safe release |
|---|---|
| Relevant API surface | internal ESE buffer-manager work beneath cursor and transaction operations |
| Code-specific boundary | the caller attempted to abandon or repurpose a buffer page that still has an active owner or dependency |
| Narrow corrective direction | release the legitimate owner through normal cursor or transaction cleanup before attempting buffer disposal |
A buffer can be in use because of a legitimate cursor, transaction, latch, or I/O dependency., forcing release around the engine breaks ownership invariants.
Minimum useful trace
Preserve the first result before retries, cleanup, service restart, or file replacement changes the evidence. The diagnostic record should identify the exact API phase and the owner of every handle or artifact involved.
- Code-specific observation: record page identity, latch/reference counts, cursor and transaction owners, dirty state, and the operation requesting abandonment.
- Page and database identity: record it together with this result and the timestamp of the first occurrence.
- Owner/reference state: record it together with it and the timestamp of the first occurrence.
- Dirty and I/O status: record it together with it and the timestamp of the first occurrence.
- Cursor/transaction lifetime: record it together with it and the timestamp of the first occurrence.
Use hashes, lengths, IDs, generation numbers, and redacted samples instead of copying directory contents or sensitive database values into routine logs. For this it investigation, a complete provenance chain is often more useful than a second automatic retry.
Steps to resolve it
- Record it,
0xC80000CA, the API name, the current phase, and all live context or file owners. - Verify the decisive condition by record page identity, latch/reference counts, cursor and transaction owners, dirty state, and the operation requesting abandonment.
- Apply only the narrow correction: release the legitimate owner through normal cursor or transaction cleanup before attempting buffer disposal.
- After it, recreate any context invalidated by the failure; do not carry stale HBC, cursor, file, or restore-map state into the retry.
- repeat the smallest non-destructive test that reaches the same boundary, then verify both the return value and the resulting file, cursor, backup, or database state.
Actions that can make diagnosis worse
- do not force-close the underlying database file to release one buffer.
- do not treat ownership as physical page corruption.
- do not discard the first lower-level Win32, RPC, or JET result merely because a later cleanup call returned a more familiar error.
Acceptance criteria for a fix
A useful regression test for this HRESULT should force the condition “the caller attempted to abandon or repurpose a buffer page that still has an active owner or dependency”, call one documented API transition, and assert the exact HRESULT. The corrected the case should change only the decisive precondition and should verify cleanup as well as the primary output. For the result backup or restore path, also prove that the resulting set can be enumerated and that no file handle or context remains active after finalization.
Technical references
- ESE error-code table — API ordering, file semantics, warning/error interpretation, or recovery behavior relevant to it.
- JET_ERR enumeration
- Open-source ESE implementation
Looking for a different code? Search another status or error code.