You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SessionStateItemCollection索引越界致应用池崩溃,求排查解决方法

异常成因分析与排查调试方案

异常核心信息

发生未处理异常,进程已终止。
Application ID: /LM/W3SVC/1/ROOT/MyApp
Process ID: 15744
Exception: System.ArgumentOutOfRangeException
Message: Index was out of range. Must be non-negative and less than the size of the collection.
Parameter name: index
StackTrace:

at System.Collections.ArrayList.get_Item(Int32 index)
at System.Web.SessionState.SessionStateItemCollection.get_Item(Int32 index)
at System.Web.Util.AspCompatApplicationStep.AnyStaObjectsInSessionState(HttpSessionState session)
at System.Web.HttpApplicationFactory.FireSessionOnEnd(HttpSessionState session, Object eventSource, EventArgs eventArgs)
at System.Web.SessionState.SessionOnEndTargetWorkItem.RaiseOnEndCallback()
at System.Web.Util.WorkItem.CallCallbackWithAssert(WorkItemCallback callback)
at System.Web.Util.WorkItem.OnQueueUserWorkItemCompletion(Object state)
at System.Threading.ExecutionContext.RunInternal(ExecutionContext executionContext, ContextCallback callback, Object state, Boolean preserveSyncCtx)
at System.Threading.ExecutionContext.Run(ExecutionContext executionContext, ContextCallback callback, Object state, Boolean preserveSyncCtx)
at System.Threading.QueueUserWorkItemCallback.System.Threading.IThreadPoolWorkItem.ExecuteWorkItem()
at System.Threading.ThreadPoolWorkQueue.Dispatch()

成因分析

从堆栈跟踪可明确,异常发生在Session过期触发Session_OnEnd事件的内部处理流程中:ASP.NET框架在检查Session中是否包含STA对象(AspCompat相关逻辑)时,遍历SessionStateItemCollection的内部ArrayList出现索引越界。可能的触发原因包括:

  • Session集合被非法修改:尽管Session_OnEnd理论上是单线程执行,但如果自定义的Session_OnEnd处理代码中存在通过反射等非常规手段修改Session集合的操作,会导致内部ArrayList的索引与元素数量不匹配。
  • 自定义Session存储提供器存在缺陷:若使用了非默认的SessionStateProvider,其实现存在线程安全问题(比如Session过期清理时未正确同步集合操作),会导致SessionStateItemCollection的内部状态损坏。
  • .NET Framework框架bug:特定旧版本的.NET Framework在AspCompat模式下处理Session_OnEnd的STA对象检查逻辑存在漏洞,引发遍历集合时的索引越界。

排查调试方法

  • 检查自定义Session_OnEnd代码:确认是否在该事件处理逻辑中修改了Session集合(包括直接修改、反射操作或间接触发集合变更的代码),如有则移除或调整。
  • 验证自定义SessionStateProvider:若使用了自定义存储提供器,检查其Session过期清理、集合遍历相关的线程安全实现,确保对SessionStateItemCollection的操作全程同步。
  • 升级.NET Framework补丁:将应用使用的.NET Framework版本升级到对应分支的最新补丁版本,排查是否存在微软已修复的框架级bug。
  • 启用详细日志跟踪:在web.config中配置以下节点,捕获更多上下文信息:
    <system.web>
      <trace enabled="true" pageOutput="false" requestLimit="1000" traceMode="SortByTime"/>
      <customErrors mode="Off"/>
      <compilation debug="true"/>
    </system.web>
    
  • 捕获dump文件分析:使用WinDbg附加到崩溃的应用程序池进程,在异常发生时生成dump文件,通过调试命令查看SessionStateItemCollection内部ArrayList的Count属性和当前访问的index值,定位集合状态异常的具体原因。

内容的提问来源于stack exchange,提问作者Vishal Anand

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.08.13 00:30:41