| Previous | Next |
| hrBadCheckpointSignature | hrDatabaseInconsistent |
hrCheckpointCorrupt
State represented by this code
For hrCheckpointCorrupt, the useful interpretation begins with the object and phase that returned the value. The decisive boundary is the checkpoint is missing, unreadable, or structurally invalid for recovery.
The stored Value is 0xC8000215 (negative JET error -533; -533). The HRESULT carries failure severity, so output state must be treated according to the individual API contract. Current ESE documentation uses JET_errCheckpointCorrupt for the corresponding published JET condition.
The first useful distinction is that the checkpoint is an optimization pointer; deleting it changes recovery scope and must not be the first unrecorded action. Start by preserve the checkpoint file, header, size, hash, system path, expected generation, and surrounding storage events. That separates a reproducible incident from a later generic cleanup or service error.
Data for a reproducible incident
Preserve the first result before retries, cleanup, service restart, or file replacement changes the evidence. The diagnostic record should identify the exact API phase and the owner of every handle or artifact involved.
- Code-specific observation: preserve the checkpoint file, header, size, hash, system path, expected generation, and surrounding storage events.
- Complete log inventory: record it together with this result and the timestamp of the first occurrence.
- Checkpoint path, size, and hash: record it together with this result and the timestamp of the first occurrence.
- Header signature and generation: record it together with this result and the timestamp of the first occurrence.
- System-path configuration: record it together with this result and the timestamp of the first occurrence.
Use hashes, lengths, IDs, generation numbers, and redacted samples instead of copying directory contents or sensitive database values into routine logs. For this it investigation, a complete provenance chain is often more useful than a second automatic retry.
Objects and state involved
| Diagnostic layer | the checkpoint file that bounds the log range needed for recovery |
|---|---|
| Relevant API surface | JetInit, system-path configuration, soft recovery, and hard recovery |
| Code-specific boundary | the checkpoint is missing, unreadable, or structurally invalid for recovery |
| Narrow corrective direction | secure the evidence and follow product-supported recovery using the complete required logs |
The checkpoint tracks the oldest log position not fully represented in database pages., recovery can require more log replay when checkpoint information is unavailable.
Actions that can make diagnosis worse
- do not infer that missing checkpoint means the database is clean.
- do not delete the checkpoint before recording it and the log set.
- do not discard the first lower-level Win32, RPC, or JET result merely because a later cleanup call returned a more familiar error.
Nearby ESE or AD backup states
It specifically means that the checkpoint is an optimization pointer; deleting it changes recovery scope and must not be the first unrecorded action. Related values below can appear in the same workflow but require a different response:
hrError | the Directory Service backup layer returned an internal failure without a more specific facility code |
|---|---|
hrInvalidRecips | the recipient information supplied to the legacy backup operation failed validation |
hrBFPageNotFound | the requested page was not present in the buffer-manager context used by the operation |
Keep the original constant and hexadecimal value in telemetry. Replacing it with “backup failed” or “database warning” removes the state information needed to select the next legal API call.
Next actions
- Record it,
0xC8000215, the API name, the current phase, and all live context or file owners. - Verify the decisive condition by preserve the checkpoint file, header, size, hash, system path, expected generation, and surrounding storage events.
- Apply only the narrow correction: secure the evidence and follow product-supported recovery using the complete required logs.
- After it, recreate any context invalidated by the failure; do not carry stale HBC, cursor, file, or restore-map state into the retry.
- repeat the smallest non-destructive test that reaches the same boundary, then verify both the return value and the resulting file, cursor, backup, or database state.
Acceptance criteria for a fix
A useful regression test for this HRESULT should force the condition “the checkpoint is missing, unreadable, or structurally invalid for recovery”, call one documented API transition, and assert the exact HRESULT. The corrected the case should change only the decisive precondition and should verify cleanup as well as the primary output. For the result backup or restore path, also prove that the resulting set can be enumerated and that no file handle or context remains active after finalization.
Technical references
- ESE checkpoint files — API ordering, file semantics, warning/error interpretation, or recovery behavior relevant to it.
- Transaction-log parameters
- JetInit recovery
- Microsoft JET_ERR enumeration
Looking for a different code? Search another status or error code.