| Previous | Next |
| UTC_E_INVALID_FILTER | UTC_E_ESCALATION_NOT_AUTHORIZED |
UTC_E_EXE_TERMINATED
Separate cause from final symptom: RunExeWithArgs child process
When UTC_E_EXE_TERMINATED (0x87C5101A) is returned, the producing layer is scenario action execution for this HRESULT. The first diagnostic step is to separate configuration, policy and runtime state for this HRESULT. The rejected object or state is RunExeWithArgs child process, and the specific boundary is that UTC terminated an executable action because of cancellation, timeout, shutdown or scenario transition for this HRESULT. Later service errors should not replace this first result in the incident record for this HRESULT.
Scenario actions run under service-controlled identity, timeout and cancellation rules for this HRESULT. The useful evidence is the exact action instance and its child process or script state, not a later generic service event for this HRESULT. stdout, stderr and native exit values should be retained separately from the UTC HRESULT for this HRESULT. Record the configuration package or scenario generation together with the Windows build; otherwise a repaired file can be tested against a stale in-memory graph and appear to fail for the same reason for this HRESULT.
High-value observations
| UTC diagnostic field | Value |
|---|---|
| Owning state or object | RunExeWithArgs child process |
| Producing layer | scenario action execution |
| Do not confuse with | UTC_E_CHILD_PROCESS_FAILED records a process that exited itself with a nonzero code |
| Decisive evidence | binary path/hash, command line, PID, job object, timeout, termination reason, stdout and stderr |
| Narrow comparison | run a fast no-op executable under the same action, then reproduce the blocking workload |
The AllStat message names the immediate condition as “RunExeWithArgsAction was forced to terminate a running executable” for this HRESULT. In practice, the useful extension is to ask whether the request was rejected before any side effect, after partial setup, or during cleanup for this HRESULT. Verify the existence and ownership of the expected output—session, directory, process, result object or emitted event—rather than assuming the message describes the final system state for this HRESULT.
A focused experiment
- Freeze the failing scenario package, caller inputs and UTC service lifetime that produced this result.
- Collect the high-value state: binary path/hash, command line, PID, job object, timeout, termination reason, stdout and stderr for this HRESULT.
- Use a passing control on the same Windows build, then run a fast no-op executable under the same action, then reproduce the blocking workload for this HRESULT.
- Repeat once after normal teardown to prove the result is not caused by a stale handle or leftover run state for this HRESULT.
The most informative neighbor is UTC_E_CHILD_PROCESS_FAILED. The distinction is concrete: UTC_E_CHILD_PROCESS_FAILED records a process that exited itself with a nonzero code for this HRESULT. Keeping both symbolic names in logs prevents a broad “DiagTrack error” bucket from hiding whether the failure occurred during parsing, authorization, resource acquisition, execution or teardown for this HRESULT.
Child-action accounting
Keep process creation, job assignment, timeout, cancellation, exit code and output capture as separate timestamps for this HRESULT. That sequence reveals whether the child failed itself, was terminated by UTC or never started for this HRESULT.
Recovery criteria
Make the child honor cancellation and complete within the action budget; preserve partial output for diagnosis for this HRESULT. Apply that change only to the owning boundary for this HRESULT. A successful repair must make the controlled case cross this boundary while retaining the intended policy, trace providers, destination and security context for this HRESULT.
Avoid broad registry resets or global service-policy changes until the single-owner comparison has been run for this HRESULT. They can hide the original configuration generation without proving the contract was corrected for this HRESULT.
- the same request now produces its documented success or nonfatal status without a second hidden retry
- the operational log shows one coherent request lifetime and no orphaned action, timer, process or trace session
- teardown followed by a second run does not reuse stale state or recreate RunExeWithArgs child process
- the nearby condition remains distinguishable: UTC_E_CHILD_PROCESS_FAILED records a process that exited itself with a nonzero code
Technical references
- Microsoft Open Specifications: Windows error-code registry — reference for scenario action execution while interpreting this result.
- Microsoft: Universal Telemetry Client configuration diagnosis
- Microsoft: UniversalTelemetryClient operational-log guidance
- Microsoft: About Windows Error Reporting
Looking for a different code? Search another status or error code.
