Skip to content

Log EC console to the Windows Event Log - #2

Draft
JohnAZoidberg wants to merge 7 commits into
framework-masterfrom
ec-console-log
Draft

JohnAZoidberg wants to merge 7 commits into
framework-masterfrom
ec-console-log

Conversation

@JohnAZoidberg

Copy link
Copy Markdown
Member

No description provided.

JohnAZoidberg and others added 7 commits September 23, 2026 18:44
Poll the EC console buffer and write each line to the
Framework-CrosEcBus/Console event log channel, so it persists across
boots. The Event Log service caps it at 10 MB.
Newer WDKs only ship x64 InfVerif.dll, which 32-bit MSBuild can't load

> INF verification exception: Unable to load DLL 'x86\InfVerif.dll':
> The specified module could not be found

Signed-off-by: Daniel Schaefer <dhs@frame.work>
Signed-off-by: Daniel Schaefer <dhs@frame.work>
The channel defaulted to Application isolation, which is served by the
EventLog-Application session. That session never received events from
the kernel-mode provider, so the driver saw the provider as disabled,
never read the EC console, and the log stayed empty.

Kernel-mode providers need System isolation (EventLog-System session),
like the in-box kernel driver channels.

Signed-off-by: Daniel Schaefer <dhs@frame.work>
Document how to check that the right driver build is installed, that
the event provider and channel are registered and enabled, and that the
Event Log service is listening. Also how to capture and decode the WPP
trace (with or without the WDK), and how to record the provider's events
in a private session to rule out the channel configuration.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Signed-off-by: Daniel Schaefer <dhs@frame.work>
Signed-off-by: Daniel Schaefer <dhs@frame.work>
Signed-off-by: Daniel Schaefer <dhs@frame.work>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant