DumpReader

Free Windows upgrade log reader

The upgrade rolled back.
Read the logs it left behind.

UpgradeAutopsy lists every phase, result code, error line and CompatData entry in your Panther logs, each with the file and line it came from. Setup writes thousands of lines and hides four useful ones in them.

Drop setuperr.log here
works anywhere on the page
C:\$WINDOWS.~BT\Sources\Panther · or a .zip of the folder · up to 32 MB
  • Read in your browser; your file is never uploaded
  • No account, cookies, analytics or ads
  • Free — donations only

Three hours, 71%, and a hex code

A feature update runs for hours, reaches some percentage, reboots, and puts everything back exactly as it was with an error code and no explanation. The code is almost always 0xC1900101, which on its own means “something went wrong and Setup rolled back” and nothing more.

Setup does write down what happened, in C:\$WINDOWS.~BT\Sources\Panther. Microsoft's own tool for reading it is SetupDiag.exe, a command-line rule-matcher you download separately, which frequently returns “no match found” and assumes you already know where Panther is.

This page reads those logs and lays out their contents: the phases mentioned and when, every result and extend code with its documented meaning where one exists, every Error and Fatal line verbatim, and every entry in the compatibility report.

Where the logs are

File Where When it exists
setuperr.logC:\$WINDOWS.~BT\Sources\Panther\Errors only, so it is small. Start with this one.
setupact.logC:\$WINDOWS.~BT\Sources\Panther\The full narrative, tens of MB. It carries the phase transitions.
setupact.log (rollback)C:\$WINDOWS.~BT\Sources\Rollback\Written while the machine reverts.
CompatData_*.xmlC:\$WINDOWS.~BT\Sources\Panther\The compatibility scan's findings, as structured XML.
After a rollback finishesC:\Windows\Panther\ and \Panther\NewOS\Where things end up once the old Windows is running again.

$WINDOWS.~BT is hidden and a protected operating-system folder. In File Explorer: View → Show → Hidden items, then Options → View and clear Hide protected operating system files. Windows will ask for permission when you open it.

You can drop several files at once, or zip the Panther folder and drop that. More files means more of the picture — but setuperr.log alone is usually a 200 KB upload and carries most of what is extractable.

The four phases, and what a mention of each means

Setup runs in stages, and its logs name them. Knowing which stages your logs mention narrows the reading enormously — advice written for one phase is irrelevant to the others.

Phase What is happening
DownlevelThe old Windows is still running. Files download and the compatibility scan runs.
SafeOSA recovery-like environment before the new Windows boots. WinRE work and disk work happen here.
FirstBootThe new Windows starting for the first time.
SecondBootThe new Windows starting with user settings applied. MIGRATE_DATA is the sub-phase that moves profiles and data.

The report lists which phases your logs mention and how many times, and is explicit that a phase not appearing can mean either that it never ran or that its log was not supplied. Those are different, and the tool will not pretend to know which one applies.

Result codes and extend codes

Setup errors usually appear as a pair: 0xC1900101 - 0x20017. The first half is generic. The second half — the extend code — is the part that records a phase and a stage.

Every pair in your logs is extracted with its occurrence count and first location. Codes with a documented meaning carry a note saying what they are recorded against. Codes without one are shown raw, and the report says so, rather than offering a plausible-sounding guess.

Extend code Recorded against
0x20017SafeOS phase, boot stage
0x2000CSafeOS phase, apply-image stage
0x30018Driver-install stage
0x4000DSecondBoot phase, migrate-data stage
0x40017SecondBoot phase, boot stage

The phases and codes in setuperr.log, and what each names

Setup reports its result as a pair: a status code, and the phase it was in when it stopped. The phase is the more useful half, because it eliminates most of the internet’s advice before you read a word of it. Every string below is one this reader extracts with its line number.

What you will see in the file What it records
0xC1900101SetupManager: Reporting downlevel setup result: [0xC1900101 - 0x20017]The generic “rollback” result. On its own it names nothing — the second code after the dash is the part that identifies where it stopped, and it is the one worth searching.
0xC1900208SetupManager: Reporting result: [0xC1900208 - 0x4000C]Setup recorded an incompatibility rather than a failure. The blocking application or driver is named in the compatibility XML alongside the log.
0x8007042B - 0x4000DSetupManager: Rollback from FIRST_BOOT, result [0x8007042B - 0x4000D]A process ended unexpectedly during migration. The pair is what identifies it: 0x4000D places the failure inside the first-boot phase.
0x800F0922CBS failed with 0x800F0922A servicing failure, usually reported against the system reserved partition or a component store operation.
SAFE_OS phaseCDlpActionImpl: Failure in SAFE_OS phase during MIGRATE_DATA operationThe temporary operating system Setup boots into to do the work. A failure here happened before your installed Windows was touched.
MIGRATE_DATACDlpActionImpl: Failure in SAFE_OS phase during MIGRATE_DATA operationThe operation that moves user data and settings across. It is the longest phase and the one most often recorded at the point of failure.
FIRST_BOOTSetupManager: Rollback from FIRST_BOOT, result [0x8007042B - 0x4000D]The first start into the new build. Reaching this means installation completed and the machine turned back before finishing.
SECOND_BOOTSetupPlatform: SECOND_BOOT phase not reachedThe second start, where drivers and settings are applied. Its absence is recorded as its own line, and absence is information.

CompatData: what the compatibility scan flagged

CompatData_*.xml is structured, which makes it the most precise file in the folder. It lists programs, driver packages and hardware items, each with a blocking flag.

Every entry is extracted with its flag, version, publisher and INF name where present, plus a count of which XML elements appeared — so if the file contains element types this reader does not know, you can see that rather than having them silently dropped.

The XML is parsed with the document type refused outright. That removes entity attacks as a class rather than defusing them individually, and no real CompatData file contains one.

Why this page does not tell you which thing broke it

A successful Windows upgrade writes hundreds of error lines. Picking one out of a failed run and presenting it as the reason would look authoritative and be unfounded.

So the report gives you the material instead: every error line verbatim with its timestamp, every code with its count, every phase with its time span, every flagged compatibility entry. That is the evidence a vendor's support desk asks for and cannot normally get.

Frequently asked questions

Which single file should I upload?

setuperr.log. It contains errors only, so it is small and fast, and it carries the code pairs. Add setupact.log or the whole Panther folder as a zip if you want the phase timings as well.

I have logs from three attempts.

Upload one attempt at a time. $WINDOWS.~BT is replaced on each new attempt, so mixing them produces a timeline that never happened. The report prints the timestamp range it read so you can tell which attempt you are looking at.

It says a code has no documented meaning.

That is deliberate. Where this reader has no confirmed meaning for a code it shows the raw value and says so, rather than inventing an explanation.

Is 0xC1900101 always a driver problem?

It is a generic rollback result. The extend code beside it records a phase and a stage, and that is as far as the log itself goes.

Does it upload my whole Panther folder anywhere?

Files are read inside your browser and never uploaded. Archive members are size-, ratio- and path-checked before anything is opened.

Sources