| Previous | Next |
| hrFLDTooManySegments | hrNoBackupDirectory |
hrLogFileCorrupt
What this return value changes
For hrLogFileCorrupt, this result identifies a specific state transition rather than a generic “database failure.” The decisive boundary is ESE detected structural or checksum corruption while reading a transaction log.
The stored Value is 0xC80001F5 (negative JET error -501; -501). The HRESULT carries failure severity, so output state must be treated according to the individual API contract. Current ESE documentation uses JET_errLogFileCorrupt for the corresponding published JET condition.
The first useful distinction is that a bad signature identifies lineage/header mismatch; log corruption can also occur inside an otherwise correctly named file. Start by preserve the exact generation, file hash, offset or sector, log header, storage events, and whether the file came from live storage or backup. That separates a reproducible incident from a later generic cleanup or service error.
Objects and state involved
| Diagnostic layer | transaction-log format, checksum, version, and sequence identity |
|---|---|
| Relevant API surface | JetInit soft recovery, hard recovery, log backup, and log replay |
| Code-specific boundary | ESE detected structural or checksum corruption while reading a transaction log |
| Narrow corrective direction | stop modifying the set, obtain a verified copy from the same lineage, and rerun recovery from a clean restore copy |
ESE uses write-ahead logs to reconstruct a transaction-consistent database after an unclean shutdown., a log filename is not enough; header signature, generation, version, and contents must agree.
Evidence worth preserving
Preserve the first result before retries, cleanup, service restart, or file replacement changes the evidence. The diagnostic record should identify the exact API phase and the owner of every handle or artifact involved.
- Code-specific observation: preserve the exact generation, file hash, offset or sector, log header, storage events, and whether the file came from live storage or backup.
- Log generation and header: record it together with this result and the timestamp of the first occurrence.
- Hash and failing offset: record it together with this result and the timestamp of the first occurrence.
- Engine version: record it together with this result and the timestamp of the first occurrence.
- Database and checkpoint signatures: record it together with it and the timestamp of the first occurrence.
Use hashes, lengths, IDs, generation numbers, and redacted samples instead of copying directory contents or sensitive database values into routine logs. For this it investigation, a complete provenance chain is often more useful than a second automatic retry.
How to distinguish nearby results
It specifically means that a bad signature identifies lineage/header mismatch; log corruption can also occur inside an otherwise correctly named file. Related values below can appear in the same workflow but require a different response:
hrLogBufferTooSmall | the available recovery log buffer cannot hold the log record or sector data required for replay |
|---|---|
hrBadLogVersion | the transaction log format is incompatible with the ESE version attempting to read it |
hrInvalidBackup | an incremental external backup was requested while circular logging prevents preservation of the required historical log range |
Keep the original constant and hexadecimal value in telemetry. Replacing it with “backup failed” or “database warning” removes the state information needed to select the next legal API call.
A safe response sequence
- Record it,
0xC80001F5, the API name, the current phase, and all live context or file owners. - Verify the decisive condition by preserve the exact generation, file hash, offset or sector, log header, storage events, and whether the file came from live storage or backup.
- Apply only the narrow correction: stop modifying the set, obtain a verified copy from the same lineage, and rerun recovery from a clean restore copy.
- After it, recreate any context invalidated by the failure; do not carry stale HBC, cursor, file, or restore-map state into the retry.
- repeat the smallest non-destructive test that reaches the same boundary, then verify both the return value and the resulting file, cursor, backup, or database state.
Actions that can make diagnosis worse
- do not edit or rename logs to force acceptance.
- do not run destructive repair before preserving the original set.
- do not discard the first lower-level Win32, RPC, or JET result merely because a later cleanup call returned a more familiar error.
Acceptance criteria for a fix
A useful regression test for this HRESULT should force the condition “ESE detected structural or checksum corruption while reading a transaction log”, call one documented API transition, and assert the exact HRESULT. The corrected the case should change only the decisive precondition and should verify cleanup as well as the primary output. For the result backup or restore path, also prove that the resulting set can be enumerated and that no file handle or context remains active after finalization.
Technical references
- ESE files and recovery — API ordering, file semantics, warning/error interpretation, or recovery behavior relevant to it.
- JetInit recovery behavior
- ESE error-code table
- Microsoft JET_ERR enumeration
Looking for a different code? Search another status or error code.