| Previous | Next |
| DB_E_COSTLIMIT | DB_E_BADLOCKMODE |
DB_E_BADBOOKMARK
Exact value and interpretation
DB_E_BADBOOKMARK has the unsigned 32-bit value 2147749390 (0x80040E0E) and the signed representation -2147217906. AllStat defines the result as “Bookmark is invalid”. In the concrete failure represented here, a bookmark-based rowset method receives bookmark bytes that are invalid for the current rowset.
The high bit is set for it, so it is a failure HRESULT rather than a success or informational status. Its facility field is 4 (FACILITY_ITF) and its low code is 3598 (0x0E0E). Those bit fields place this result in an interface-defined family, but they do not reveal the provider, object identity, method, rowset generation or command state that produced it.
Evidence to collect before changing the system
A useful this result record includes provider CLSID and version, process architecture, interface and method, COM apartment and thread, object correlation ID, transaction state, and the first preceding HRESULT. When it involves row values, bookmarks, keys and query parameters, record types, lengths, hashes or redacted identifiers instead of secrets or full business data.
- Evidence 1 for it: the bookmark byte length and a safe hash of its contents.
- Evidence 2 for it: the rowset identity and generation that produced it.
- Evidence 3 for it: bookmark persistence properties and the operation that invalidated the rowset.
OLE DB contract boundary
This result must be interpreted against this contract: OLE DB rowsets own HROW values, fetch position, granted properties and visibility rules; row handles, bookmarks, update state and navigation capabilities remain valid only under the lifetime and generation that produced them.
Start with the current rowset instance, its granted properties and the exact row or position token used by the consumer when investigating this result. Preserve it before ADO, ATL,.NET, a database abstraction layer or an application exception replaces it with a generic message; the exact interface and method matter because one OLE DB object can expose several contracts with different preconditions.
Specific conditions that produce it
- Cause 1 for it: the bookmark came from another rowset instance.
- Cause 2 for it: the bookmark buffer length is wrong or its bytes were truncated.
- Cause 3 for it: the provider invalidated bookmarks after reexecution, transaction change or row deletion.
Diagnostic sequence
- Capture it immediately at the native OLE DB return and obtain the current OLE DB error object before another COM call replaces thread error information.
- Identify the exact stage for it: a bookmark-based rowset method receives bookmark bytes that are invalid for the current rowset.
- compare the live command, rowset, accessor or schema state with the metadata and properties actually granted by the provider.
- inspect per-binding, per-property, per-row or per-record statuses whenever the method supplies them; the aggregate result may not identify the rejected element.
- reproduce the issue with the smallest command, rowset or definition operation that preserves the same contract boundary.
- apply one evidence-backed correction, then verify that the operation succeeds and does not merely change into a nearby HRESULT.
Corrective actions
- Action 1 for it: keep bookmarks scoped to the rowset generation that created them.
- Action 2 for it: store the exact bookmark length with the bytes.
- Action 3 for it: refetch a bookmark after rowset reexecution or documented invalidation.
Practical incident
A UI serializes only part of a variable-length bookmark and later calls GetRowsAt; storing the full length and bytes prevents it. The diagnostic value comes from retaining it together with the failing interface and object state, not from reducing every provider result to “database error”.
Implementation guidance
Code handling it should release OLE DB resources in ownership order, preserve every provider error record, and log granted properties rather than only requested properties. When handling it, handles such as HACCESSOR, HROW, HCHAPTER and provider-specific region tokens must never be treated as portable integers across object lifetimes.
When it crosses an abstraction boundary, attach a stable correlation ID and structured fields for the native HRESULT, provider source, interface IID, method, object generation and operation phase. Do not log passwords, access tokens, complete SQL text or unrestricted row values merely to make the event easier to search.
Retry and recovery policy
Retry rule for it: retry only with a bookmark obtained from the current rowset under its supported persistence rules. A safe it retry must use a changed input, object generation, provider capability or state transition. If the call returning it could have created, updated, deleted or copied data, determine partial completion before replaying it.
Use bounded retries and preserve cancellation. Configuration and contract failures should normally fail fast; concurrency, resource or transient state failures may justify retry only after their stated precondition changes.
Difference from related HRESULT values
DB_E_BOOKMARKSKIPPED means the bookmark form is valid but no matching row is found, while it means the bookmark itself is invalid. Keep these outcomes separate in telemetry and user-facing remediation because it requires a different next action.
Official Microsoft references
Looking for a different code? Search another status or error code.
