| Previous | Next |
| hrReadVerifyFailure | hrDiskIO |
hrOutOfFileHandles
Locate the failure in the Jet call chain
For hrOutOfFileHandles, the diagnostic value comes from the specific ESE error family and the exact operation that returned it. The decisive boundary is the engine could not obtain another operating-system file handle for database work.
This result is the legacy Directory Service backup/restore HRESULT form of the ESE condition normally written as JET_errOutOfFileHandles. Preserve the original value 0xC80003FC when a wrapper also exposes a signed JET_ERR.
The key comparison for this HRESULT is this: hrTooManyOpenDatabases counts ESE database opens, while this result reaches the OS handle layer. The first useful observation is to measure process and system handle counts and identify leaked database, log, temporary, or backup files. This it evidence identifies the exhausted pool so a leak, long transaction, concurrency spike, and hard capacity limit are not confused.
The ESE objects in play
| Diagnostic layer | bounded engine, process, and storage resources |
|---|---|
| Typical API surface | instance system parameters, sessions, cursors, temporary tables, database attachment, and file growth |
| Code-specific boundary | the engine could not obtain another operating-system file handle for database work |
| First corrective direction | close leaked handles, reduce parallel file activity, and verify handle counts fall before retrying |
A retry without closing owners or adding capacity often repeats the same failure and increases load., resource codes should be tied to the exact exhausted pool rather than treated as generic low memory.
Questions the logs must answer
A useful trace for this HRESULT should preserve the first failing operation and the state of the bounded engine, process, and storage resources.
- Code-specific observation: measure process and system handle counts and identify leaked database, log, temporary, or backup files.
- the oldest transaction, longest-held cursor, or file growth operation retaining the resource; associate it with this result rather than with a later generic exception.
- live resource counts grouped by session and request owner; associate it with this result rather than with a later generic exception.
- relevant JET_param values and process or system capacity at first failure; associate it with it rather than with a later generic exception.
Log lengths, hashes, IDs, flags, and redacted samples where appropriate.
Response and verification
- Freeze the failing request context and record it,
0xC80003FC, the Jet API name, and the current instance/session ownership. - Verify the code-specific precondition: measure process and system handle counts and identify leaked database, log, temporary, or backup files.
- Apply the narrow correction: close leaked handles, reduce parallel file activity, and verify handle counts fall before retrying.
- Before retrying it, reconcile resource counts, owner cleanup, and capacity after the correction.
- confirm both the returned HRESULT and the resulting database, cursor, or file state; then add a regression test that forces the old boundary and proves cleanup leaves no stale handles.
Developer-facing acceptance test
Build a focused test that reproduces it at the bounded engine, process, and storage resources layer. Record the precondition, execute one API call, and assert the HRESULT plus the resulting handle and transaction state. The corrected it test should change only the decisive condition—the engine could not obtain another operating-system file handle for database work—and should prove that cleanup is safe if the call still fails.
Distinguishing signals
For this HRESULT, hrTooManyOpenDatabases counts ESE database opens, while it reaches the OS handle layer. The following neighboring results belong to the same broad subsystem but mark different boundaries:
hrOutOfDatabaseSpace | the database reached an engine-imposed growth ceiling rather than merely a full volume |
|---|---|
hrOutOfMemory | ESE or its caller could not reserve memory required for the operation |
hrOutOfCursors | the process exhausted table cursor resources because cursors were opened faster than they were closed |
Keep it in the incident record; replacing it with “database error” hides whether the next step is handle renewal, schema correction, lock reconciliation, or file preservation.
Actions that can hide or worsen the problem
- do not raise limits before checking ownership and release paths.
- do not create a retry storm while the exhausted resource remains unavailable.
Technical references
- JET_param enumeration — used to verify the ESE object model, API ordering, or error family relevant to it.
- Transactions and save points
- ESE files and storage paths
- ESE source repository
- Microsoft: JET_ERR enumeration
Looking for a different code? Search another status or error code.
