Skip to content

Conversation

@slomp
Copy link
Contributor

@slomp slomp commented Dec 17, 2025

These changes make the shared/singleton "NT Kernel Logger" session (EnableFlags) operate more similarly to a private kernel session (EnableTraceEx2()).

(We could also consider adding UI toggles to enable/disable system trace features on-the-fly.)

@slomp slomp force-pushed the slomp/etw-refactor-2 branch from f74950b to b6da093 Compare December 17, 2025 19:19
@slomp slomp force-pushed the slomp/etw-refactor-2 branch from b6da093 to 06b745d Compare January 2, 2026 19:23
@slomp slomp marked this pull request as ready for review January 2, 2026 19:23
@slomp slomp changed the title RFC : Toggling EnableFlags _after_ the "NT Kernel Logger" session has started RFC : Toggling EnableFlags after the "NT Kernel Logger" session has started Jan 2, 2026
@slomp slomp changed the title RFC : Toggling EnableFlags after the "NT Kernel Logger" session has started Toggling EnableFlags after the "NT Kernel Logger" session has started Jan 2, 2026
@slomp slomp force-pushed the slomp/etw-refactor-2 branch from 06b745d to 44696c4 Compare January 15, 2026 19:28
@slomp
Copy link
Contributor Author

slomp commented Jan 15, 2026

I think it's ready to merge now.

@wolfpld wolfpld merged commit ba677b7 into wolfpld:master Jan 15, 2026
5 of 6 checks passed
@slomp slomp deleted the slomp/etw-refactor-2 branch January 16, 2026 18:22
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants