| 0x1001000 | 1011 | Verifier Flags: 0x%1!08x! |
| 0x1001001 | 1011 | Verifier Volatile Flags: 0x%1!08x! |
| 0x1001002 | 1011 | Standard Flags: |
| 0x1001003 | 1011 | Additional Flags: |
| 0x1001004 | 1011 | Internal Flags: |
| 0x1001005 | 1011 | Boot Mode: |
| 0x1001006 | 1011 | Rules: |
| 0x1001007 | 1011 | Extensions: |
| 0x1001008 | 1011 | Verified Drivers: |
| 0x1001009 | 1011 | Excluded Drivers: |
| 0x100100a | 1011 | Advanced Options: |
| 0x100100b | 1011 | Randomized Low Resources Simulation Parameters: |
| 0x100100c | 1011 | Verifier Statistics Summary |
| 0x100100d | 1011 | Driver Verification List |
| 0x100100e | 1011 | MODULE: %1 (load: %2!d! / unload: %3!d!) |
| 0x100100f | 1011 | Pool Allocation Statistics: ( NonPaged / Paged ) |
| 0x1001010 | 1011 | Code Integrity Statistics: |
| 0x1001011 | 1011 | Time Stamp: %1 |
| 0x1001012 | 1011 | Volatile Flags: |
| 0x1001013 | 1011 | Added Drivers: |
| 0x1001014 | 1011 | Removed Drivers: |
| 0x1001015 | 1011 | [X] Indicates flag is enabled. |
| 0x1001016 | 1011 | All Drivers |
| 0x1001017 | 1011 | All rules are using default settings |
| 0x1001018 | 1011 | All other rules are using default settings |
| 0x1001019 | 1011 | Disabled: %1 (%2) |
| 0x100101a | 1011 | All rules are explicitly disabled. |
| 0x100101b | 1011 | None |
| 0x100101c | 1011 | The requested operation is successful. Changes will not be effective until the system is rebooted. |
| 0x1002000 | 1011 | %1 |
| 0x1002001 | 1011 | %1: %2 |
| 0x1002002 | 1011 | %1: %2!d! |
| 0x1002003 | 1011 | %1: %2!I64d! |
| 0x1002004 | 1011 | [%1] 0x%2!08x! Special pool. |
| 0x1002005 | 1011 | [%1] 0x%2!08x! Force IRQL checking. |
| 0x1002006 | 1011 | [%1] 0x%2!08x! Randomized low resources simulation. |
| 0x1002007 | 1011 | [%1] 0x%2!08x! Pool tracking. |
| 0x1002008 | 1011 | [%1] 0x%2!08x! I/O verification. |
| 0x1002009 | 1011 | [%1] 0x%2!08x! Deadlock detection. |
| 0x100200a | 1011 | [%1] 0x%2!08x! Enhanced I/O checking. |
| 0x100200b | 1011 | [%1] 0x%2!08x! DMA checking. |
| 0x100200c | 1011 | [%1] 0x%2!08x! Security checks. |
| 0x100200d | 1011 | [%1] 0x%2!08x! Force pending I/O requests. |
| 0x100200e | 1011 | [%1] 0x%2!08x! IRP logging. |
| 0x100200f | 1011 | [%1] 0x%2!08x! Miscellaneous checks. |
| 0x1002010 | 1011 | [%1] 0x%2!08x! Additional debug information. |
| 0x1002011 | 1011 | [%1] 0x%2!08x! Invariant MDL checking for stack. |
| 0x1002012 | 1011 | [%1] 0x%2!08x! Invariant MDL checking for driver. |
| 0x1002013 | 1011 | [%1] 0x%2!08x! Power framework delay fuzzing. |
| 0x1002014 | 1011 | [%1] 0x%2!08x! Port/miniport interface checking. |
| 0x1002015 | 1011 | [%1] 0x%2!08x! DDI compliance checking. |
| 0x1002016 | 1011 | [%1] 0x%2!08x! Systematic low resources simulation. |
| 0x1002017 | 1011 | [%1] 0x%2!08x! DDI compliance checking (additional). |
| 0x1002018 | 1011 | [%1] 0x%2!08x! Extended Verifier flags (internal). |
| 0x1002019 | 1011 | [%1] 0x%2!08x! NDIS/WIFI verification. |
| 0x100201a | 1011 | [%1] 0x%2!08x! Driver logging. |
| 0x100201b | 1011 | [%1] 0x%2!08x! Kernel synchronization delay fuzzing. |
| 0x100201c | 1011 | [%1] 0x%2!08x! VM switch verification. |
| 0x100201d | 1011 | [%1] 0x%2!08x! Code integrity checks. |
| 0x100201e | 1011 | Raise IRQLs: %1!10d! |
| 0x100201f | 1011 | Acquire Spin Locks: %1!10d! |
| 0x1002020 | 1011 | Synchronize Executions: %1!10d! |
| 0x1002021 | 1011 | Trims: %1!10d! |
| 0x1002022 | 1011 | Pool Allocations Attempted: %1!10d! |
| 0x1002023 | 1011 | Pool Allocations Succeeded: %1!10d! |
| 0x1002024 | 1011 | Pool Allocations Succeeded SpecialPool: %1!10d! |
| 0x1002025 | 1011 | Pool Allocations With No Tag: %1!10d! |
| 0x1002026 | 1011 | Pool Allocations Not Tracked: %1!10d! |
| 0x1002027 | 1011 | Pool Allocations Failed: %1!10d! |
| 0x1002028 | 1011 | Pool Allocations Failed Deliberately: %1!10d! |
| 0x1002029 | 1011 | Current Pool Allocations: ( %1!8d! / %2!8d! ) |
| 0x100202a | 1011 | Current Pool Bytes: ( %1!8d! / %2!8d! ) |
| 0x100202b | 1011 | Peak Pool Allocations: ( %1!8d! / %2!8d! ) |
| 0x100202c | 1011 | Peak Pool Bytes: ( %1!8d! / %2!8d! ) |
| 0x100202d | 1011 | Contiguous Memory Bytes: %1!8d! |
| 0x100202e | 1011 | Peak Contiguous Memory Bytes: %1!8d! |
| 0x100202f | 1011 | Execute Pool Type Count: %1!10d! |
| 0x1002030 | 1011 | Execute Page Protection Count: %1!10d! |
| 0x1002031 | 1011 | Execute Page Mapping Count: %1!10d! |
| 0x1002032 | 1011 | Execute-Write Section Count: %1!10d! |
| 0x1002033 | 1011 | Section Alignment Failures: %1!10d! |
| 0x1002034 | 1011 | Options: %1 |
| 0x1002035 | 1011 | Rule 0x%1!08x! disabled. |
| 0x1002036 | 1011 | Rule 0x%1!08x! set to use default setting. |
| 0x1002037 | 1011 | The system reboot is required for the changes to take effect. |
| 0x1002038 | 1011 | No settings were changed. |
| 0x1002039 | 1011 | The new settings are in effect until the system
is restarted or the settings are changed again. |
| 0x1002040 | 1011 | IAT in Executable Section Count: %1!10d! |
| 0x1002041 | 1011 | Verifier settings will persist and be active through system upgrade. |
| 0xc1008001 | 1011 | An unsupported command line parameter was specified.
Run "verifier /?" for command line assistance. |
| 0xc1008002 | 1011 | The specified command line parameter '/%1' is unexpected.
Run "verifier /?" for command line assistance. |
| 0xc1008003 | 1011 | The specified command line parameter '/%1' doesn't follow required format.
Run "verifier /?" for command line assistance. |
| 0xc1008004 | 1011 | The specified command line parameter '/%1' does not support option '%2'.
Run "verifier /?" for command line assistance. |
| 0xc1008005 | 1011 | The specified command line parameter '/%1' option values are not valid.
Run "verifier /?" for command line assistance. |
| 0xc1008006 | 1011 | The specified command line parameter '/%1' option '%2' doesn't follow required format.
Run "verifier /?" for command line assistance. |
| 0xc1008007 | 1011 | The specified flags 0x%1!08x! are not supported.
Run "verifier /?" for command line assistance. |
| 0xc1008008 | 10 | The specified flags 0x%1!08x! are not supported in volatile mode.
Run "verifier /?" for command line assistance. |
| 0xc1008009 | 1011 | Failed to start the verification for '%1' driver. |
| 0xc100800a | 1011 | Failed to stop the verification for '%1' driver. |
| 0xc100800b | 1011 | Rule code 0x%1!08x! not mapped to existing rule. |
| 0xc100800c | 1011 | Rule 0x%1!08x! already disabled. |
| 0xc100800d | 1011 | Rule 0x%1!08x! already using default setting. |
| 0xc100800e | 1011 | The verifier registry settings contain invalid values.
Run "verifier /reset" to clean the registry settings. |
| 0xc100800f | 1011 | Failed to query verifier registry settings. |
| 0xc1008010 | 1011 | The current operation requires admin privilege. |
| 0xc1008011 | 1011 | Failed to query volatile verifier settings. |
| 0xc1008012 | 1011 | Failed to set volatile verifier settings. |
| 0xc1008013 | 1011 | The current system environment supports only command line interface.
Run "verifier /?" for command line assistance. |
| 0xc1008014 | 1011 | The maximum number of 10 selected Core Driver Verifier rules has been reached. |
| 0xc1008015 | 1011 | Failed to obtain the list of currently loaded kernel modules. |
| 0xc1008016 | 1011 | Failed to obtain the global memory status. |
| 0xc1008017 | 1011 | There are no remaining drivers to verify. Reduce the number of excluded drivers.
Run "verifier /?" for command line assistance. |
| 0xc100f001 | 10 | Copyright (c) Microsoft Corporation. All rights reserved.
SYNTAX:
verifier {/? | /help}
verifier /standard /all
verifier /standard /driver [ ...]
verifier {/ruleclasses | /rc} [ ...] /all
verifier /flags [ ...] /all
verifier /flags [ ...] /driver [ ...]
verifier /rules {query | reset | default | disable }
verifier /query
verifier /querysettings
verifier /bootmode {persistent | resetonbootfail | oneboot | resetonunusualshutdown}
verifier /persistthroughupgrade
verifier /reset
verifier /faults [probability [pool_tags [applications [delay_minutes]]]]
verifier /faultssystematic [ ...]
verifier /log [/interval ]
verifier /volatile /flags [ ...]
verifier /volatile /adddriver [ ...]
verifier /volatile /removedriver [ ...]
verifier /volatile /faults [probability [pool_tags [applications
[delay_minutes]]]]
verifier /domain {wdm | ndis | ks | audio} [rules.all | rules.default ]
/driver ... [/logging | /livedump]
verifier /logging
verifier /livedump
PARAMETERS:
/? or /help
Displays this help message.
/standard
Specifies standard Driver Verifier flags.
/all
Specifies that all installed drivers will be verified after the next
boot.
/driver [ ...]
Specifies one or more drivers (image names) that will be verified.
Wildcard values (e.g. n*.sys) are not supported.
/driver.exclude [ ...]
Specifies one or more drivers (image names) that will be excluded
from verification. This parameter is applicable only if all drivers
are selected for verification. Wildcard values (e.g. n*.sys) are not
supported.
/flags [ ...]
Specifies one or more options that should be enabled for verification.
Flags are applied to all drivers being checked by Driver Verifier. The
provided options values must be either in decimal, hexadecimal ("0x"
prefix), octal ("0o" prefix) or binary ("0b" prefix) format.
Standard Flags:
Standard Driver Verifier options can be specified using '/standard'.
WDF verification is included in /standard but is not shown here.
0x00000001 (bit 0) - Special pool
0x00000002 (bit 1) - Force IRQL checking
0x00000008 (bit 3) - Pool tracking
0x00000010 (bit 4) - I/O verification
0x00000020 (bit 5) - Deadlock detection
0x00000080 (bit 7) - DMA checking
0x00000100 (bit 8) - Security checks
0x00000800 (bit 11) - Miscellaneous checks
0x00020000 (bit 17) - DDI compliance checking
Additional Flags:
These flags are intended for specific scenario testing. Flags marked
with (*) require I/O Verification (bit 4) that will be automatically
enabled. Flags marked with (**) support disabling of individual
rules.
0x00000004 (bit 2) - Randomized low resources simulation
0x00000200 (bit 9) - Force pending I/O requests (*)
0x00000400 (bit 10) - IRP logging (*)
0x00002000 (bit 13) - Invariant MDL checking for stack (*)
0x00004000 (bit 14) - Invariant MDL checking for driver (*)
0x00008000 (bit 15) - Power framework delay fuzzing
0x00010000 (bit 16) - Port/miniport interface checking
0x00040000 (bit 18) - Systematic low resources simulation
0x00080000 (bit 19) - DDI compliance checking (additional)
0x00200000 (bit 21) - NDIS/WIFI verification (**)
0x00800000 (bit 23) - Kernel synchronization delay fuzzing
0x01000000 (bit 24) - VM switch verification
0x02000000 (bit 25) - Code integrity checks
/ruleclasses or /rc [ ... ]
This parameter is larger set of '/flags' above. While '/flags' is
limited to 32 bit bitmap expression, this can include more than 32
verification classes. Each positive decimal integer represents a
verification class. Multiple classes can be expressed by separating
each class id with space character. Following rule classes IDs are
available and leading 0's can be omitted.
Standard Rule Classes:
1 - Special pool
2 - Force IRQL checking
4 - Pool tracking
5 - I/O verification
6 - Deadlock detection
8 - DMA checking
9 - Security checks
12 - Miscellaneous checks
18 - DDI compliance checking
34 - WDF Verification
Additional Rule Classes:
These rule classes are intended for specific scenario testing. Rule
classes are marked with (*) require I/O Verification (5) that will
be automatically enabled. Flags marked with (**) support disabling
of individual rules.
3 - Randomized low resources simulation
10 - Force pending I/O requests (*)
11 - IRP logging (*)
14 - Invariant MDL checking for stack (*)
15 - Invariant MDL checking for driver (*)
16 - Power framework delay fuzzing
17 - Port/miniport interface checking
19 - Systematic low resources simulation
20 - DDI compliance checking (additional)
22 - NDIS/WIFI verification (**)
24 - Kernel synchronization delay fuzzing
25 - VM switch verification
26 - Code integrity checks
/log.code_integrity
This option suppresses Code Integrity violation breaks and collects
only statistics for verified drivers. Statistics could be extracted
via /log option or kernel debugger. This parameter is applicable only
if Code Integrity checks are enabled.
/rules {query | reset | default | disable }
Specifies rules level control (advanced).
query Shows current status of controllable rules.
reset Resets all rules to their default state.
default Sets rule ID to its default state.
disable Disables specified rule ID.
/query
Display runtime Driver Verifier statistics and settings.
/querysettings
Displays a summary of the options and drivers that are currently
enabled, or options and drivers that will be verified after the
next boot. The display does not include drivers and options added
using /volatile.
/bootmode
Specifies the Driver Verifier boot mode. This option requires system
reboot to take effect.
persistent Ensures that Driver Verifier settings are
persistent across reboots. This is the default
value.
resetonbootfail Disables Driver Verifier for subsequent reboots
if the system failed to start.
resetonunusualshutdown
Driver Verifier persists until unusual shutdown
happens. Its abbrevation, 'rous', can be used.
oneboot Enables Driver Verifier only for the next boot.
/persistthroughupgrade
Makes the Driver Verifier settings persist through upgrade. Driver
Verifier will be active during system upgrade.
/reset
Clears Driver Verifier flags and driver settings. This option requires
system reboot to take effect. |
| 0xc100f002 | 10 | /faults [probability [pool_tags [applications [delay_minutes]]]]
Enable the Randomized low resources simulation feature and optionally
control parameters for the Randomized low resources simulation.
Probability Specifies the probability that Driver Verifier will
fail a given allocation. The value represents the
number of chances in 10,000 that Driver Verifier will
fail the allocation. The default value 600, means
600/10000 or 6.
Pool Tags: Specifies a space separated list of the pool tags to
be injected with faults. By default, any pool
allocation can be injected with faults.
Applications Specifies a space separated list of image file names
(an executable) that will be injected with faults. By
default, any pool allocation can be injected with
faults.
DelayMinutes Specifies the number of minutes after booting during
which Driver Verifier does not intentionally fail any
allocations. This delay allows the drivers to load
and the system to stabilize before the test begins.
The default value is 8 minutes.
/faultssystematic [ ...]
Controls the Systematic low resources simulation parameters.
enableboottime Enables fault injections across reboots.
disableboottime Disables fault injections across reboots.
This is the default value.
recordboottime Enables fault injections in 'what if' mode
across reboots.
resetboottime Disables fault injections across reboots and
clears the stack exclusion list.
enableruntime Dynamically enables fault injections.
disableruntime Dynamically disables fault injections.
recordruntime Dynamically enables fault injections in
'what if' mode.
resetruntime Dynamically disables fault injections and
clears the previously faulted stack list.
querystatistics Shows the current fault injection statistics.
incrementcounter Increments the test pass counter used to
identify when a fault was injected.
getstackid Retrieves the indicated injected stack id.
excludestack Excludes the stack from fault injection.
/log [/interval ]
Creates a log file with the specified name and periodically writes the
runtime statistics to this file. The interval between log file updates
is controlled by the '/interval' parameter. The default value is 30
seconds. Use CTRL+C to close the log and return.
/volatile
Changes Driver Verifier settings without rebooting the computer.
Volatile settings take effect immediately and are in effect until the
next system reboot.
/volatile /adddriver [ ...]
Starts the verification for the specified driver or drivers.
/volatile /removedriver [ ...]
Stops the verification for the specified driver or drivers.
/domain {wdm | ndis | ks | audio} [rules.all | rules.default] /driver ...
[/logging | /livedump]
Controls the verifier extension settings. The following verifier
extension types are supported:
wdm Enabled verifier extension for WDM drivers.
ndis Enabled verifier extension for networking drivers.
ks Enabled verifier extension for kernel mode
streaming drivers.
audio Enabled verifier extension for audio drivers.
The following extension options are supported:
rules.default Enables default validation rules for the selected
verifier extension.
rules.all Enables all validation rules for the selected
verifier extension.
/logging
Enables logging for violated rules detected by the selected verifier
extensions.
/livedump
Enables live memory dump collection for violated rules detected by
the selected verifier extensions. |
| 0x100101d | 11 | Active Rule Classes: |
| 0x1002042 | 11 | "StatusCode": 0x%1!08x! |
| 0x1002043 | 11 | "CurrentlyEnabled": %1 |
| 0x1002044 | 11 | "RebootRequired": %1 |
| 0x1002045 | 11 | "IsVolatile": %1 |
| 0x1002046 | 11 | "DeploymentTag": 0x%1!08x! |
| 0x1002047 | 11 | "RuleClasses": 0x%1!08x! 0x%2!08x! |
| 0x1002048 | 11 | "Drivers": %1 |
| 0x1002049 | 11 | "FailedDrivers": %1 |
| 0x100204a | 11 | "RemovedDrivers": %1 |
| 0x100204b | 11 | "FailedRemovedDrivers": %1 |
| 0x100204c | 11 | "XdvVerifierOptions": 0x%1!08x! |
| 0x100204d | 11 | "VerifierOptions": 0x%1!08x! |
| 0x100204e | 11 | Yes |
| 0x100204f | 11 | No |
| 0x1002050 | 11 | "Drivers": |
| 0x1002051 | 11 | "FailedDrivers": |
| 0x1002052 | 11 | "RemovedDrivers": |
| 0x1002053 | 11 | "FailedRemovedDrivers": |
| 0x1003000 | 11 | %1!d! - Reserved (internal). |
| 0x1003001 | 11 | %1!d! - Special pool. |
| 0x1003002 | 11 | %1!d! - Force IRQL checking. |
| 0x1003003 | 11 | %1!d! - Randomized low resources simulation. |
| 0x1003004 | 11 | %1!d! - Pool tracking. |
| 0x1003005 | 11 | %1!d! - I/O verification. |
| 0x1003006 | 11 | %1!d! - Deadlock detection. |
| 0x1003007 | 11 | %1!d! - Enhanced I/O checking (internal). |
| 0x1003008 | 11 | %1!d! - DMA checking. |
| 0x1003009 | 11 | %1!d! - Security checks. |
| 0x100300a | 11 | %1!d! - Force pending I/O requests. |
| 0x100300b | 11 | %1!d! - IRP logging. |
| 0x100300c | 11 | %1!d! - Miscellaneous checks. |
| 0x100300d | 11 | %1!d! - Additional debug information (internal). |
| 0x100300e | 11 | %1!d! - Invariant MDL checking for stack. |
| 0x100300f | 11 | %1!d! - Invariant MDL checking for driver. |
| 0x1003010 | 11 | %1!d! - Power framework delay fuzzing. |
| 0x1003011 | 11 | %1!d! - Port/miniport interface checking. |
| 0x1003012 | 11 | %1!d! - DDI compliance checking. |
| 0x1003013 | 11 | %1!d! - Systematic low resources simulation. |
| 0x1003014 | 11 | %1!d! - Additional DDI compliance checking. |
| 0x1003015 | 11 | %1!d! - Extended Verifier flags (internal). |
| 0x1003016 | 11 | %1!d! - NDIS/WIFI verification. |
| 0x1003017 | 11 | %1!d! - Driver logging (internal). |
| 0x1003018 | 11 | %1!d! - Kernel synchronization delay fuzzing. |
| 0x1003019 | 11 | %1!d! - VM switch verification. |
| 0x100301a | 11 | %1!d! - Code integrity checks. |
| 0x100301b | 11 | %1!d! - Low allocation checking < 4GB (internal). |
| 0x100301c | 11 | %1!d! - Processor branch tracing (internal). |
| 0x100301d | 11 | %1!d! - Advanced memory map checking (internal). |
| 0x100301e | 11 | %1!d! - Extended XDV time limit (internal). |
| 0x100301f | 11 | %1!d! - System BIOS checking (internal). |
| 0x1003020 | 11 | %1!d! - Hardware verification (internal). |
| 0x1003021 | 11 | %1!d! - Driver isolation checking. |
| 0x1003022 | 11 | %1!d! - WDF verfication. |
| 0x1003023 | 11 | %1!d! - Advanced DDI IRQL checking (internal). |
| 0x1003024 | 11 | %1!d! - Driver Interception Framework mode. |
| 0x1003025 | 11 | %1!d! - File system filter verification. |
| 0x1003026 | 11 | %1!d! - Driver Interception Framework test (internal). |
| 0x1003027 | 11 | %1!d! - Info disclosure IRP checking (internal). |
| 0x1003028 | 11 | %1!d! - Light weight special pool checking (internal). |
| 0x1003029 | 11 | %1!d! - AVX corruption checking (internal). |
| 0x100302a | 11 | %1!d! - Access mode mismatch checking (internal). |
| 0x100302b | 11 | %1!d! - SCSI port verification and checking. |
| 0x100302c | 11 | %1!d! - Storport verification. |
| 0x100302d | 11 | %1!d! - Win32 verification. |
| 0x100302e | 11 | %1!d! - EX Resource and Fast Resource verification. |
| 0x100302f | 11 | %1!d! - Windows Filtering Platform (WFP) verification. |
| 0x1003030 | 11 | %1!d! - Object tracking demo plugin. |
| 0xc1008008 | 11 | The specified flags 0x%1!08x! are not supported in volatile mode.
Run "verifier /?" for command line assistance. See the "/dif /now" syntax for
enabling most flags without rebooting. |
| 0xc1008018 | 11 | Failed to start the verification for '%1' driver with NSTATUS code 0x%2!08x!. |
| 0xc1008019 | 11 | Failed to stop the verification for '%1' driver with NSTATUS code 0x%2!08x!. |
| 0xc1008020 | 11 | Chosen rule classes have missing pre-requisite. |
| 0xc1008021 | 11 | Exactly one plugin/rule-class ID should be associated with /action. |
| 0xc100f001 | 11 | Copyright (c) Microsoft Corporation. All rights reserved.
SYNTAX:
verifier {/? | /help}
verifier /standard /all
verifier /standard /driver [ ...]
verifier {/ruleclasses | /rc} [ ...] /all
verifier /flags [ ...] /all
verifier /flags [ ...] /driver [ ...]
verifier /rules {query | reset | default | disable }
verifier /query
verifier /querysettings
verifier /bootmode {persistent | resetonbootfail | oneboot | resetonunusualshutdown}
verifier /persistthroughupgrade
verifier /reset
verifier /faults [probability [pool_tags [applications [delay_minutes]]]]
verifier /faultssystematic [ ...]
verifier /log [/interval ]
verifier /volatile /flags [ ...]
verifier /volatile /adddriver [ ...]
verifier /volatile /removedriver [ ...]
verifier /volatile /faults [probability [pool_tags [applications
[delay_minutes]]]]
verifier /domain {wdm | ndis | ks | audio} [rules.all | rules.default ]
/driver ... [/logging | /livedump]
verifier /logging
verifier /livedump
PARAMETERS:
/? or /help
Displays this help message.
/standard
Specifies standard Driver Verifier flags.
/all
Specifies that all installed drivers will be verified after the next
boot.
/driver [ ...]
Specifies one or more drivers (image names) that will be verified.
Wildcard values (e.g. n*.sys) are not supported.
/driver.exclude [ ...]
Specifies one or more drivers (image names) that will be excluded
from verification. This parameter is applicable only if all drivers
are selected for verification. Wildcard values (e.g. n*.sys) are not
supported.
/flags [ ...]
Specifies one or more options that should be enabled for verification.
Flags are applied to all drivers being checked by Driver Verifier. The
provided options values must be either in decimal, hexadecimal ("0x"
prefix), octal ("0o" prefix) or binary ("0b" prefix) format.
Standard Flags:
Standard Driver Verifier options can be specified using '/standard'.
WDF verification is included in /standard but is not shown here.
0x00000001 (bit 0) - Special pool
0x00000002 (bit 1) - Force IRQL checking
0x00000008 (bit 3) - Pool tracking
0x00000010 (bit 4) - I/O verification
0x00000020 (bit 5) - Deadlock detection
0x00000080 (bit 7) - DMA checking
0x00000100 (bit 8) - Security checks
0x00000800 (bit 11) - Miscellaneous checks
0x00020000 (bit 17) - DDI compliance checking
Additional Flags:
These flags are intended for specific scenario testing. Flags marked
with (*) require I/O Verification (bit 4) that will be automatically
enabled. Flags marked with (**) support disabling of individual
rules.
0x00000004 (bit 2) - Randomized low resources simulation
0x00000200 (bit 9) - Force pending I/O requests (*)
0x00000400 (bit 10) - IRP logging (*)
0x00002000 (bit 13) - Invariant MDL checking for stack (*)
0x00004000 (bit 14) - Invariant MDL checking for driver (*)
0x00008000 (bit 15) - Power framework delay fuzzing
0x00010000 (bit 16) - Port/miniport interface checking
0x00040000 (bit 18) - Systematic low resources simulation
0x00080000 (bit 19) - DDI compliance checking (additional)
0x00200000 (bit 21) - NDIS/WIFI verification (**)
0x00800000 (bit 23) - Kernel synchronization delay fuzzing
0x01000000 (bit 24) - VM switch verification
0x02000000 (bit 25) - Code integrity checks
/ruleclasses or /rc or /dif [ ... ]
This parameter is larger set of '/flags' above. While '/flags' is
limited to 32 bit bitmap expression, this can include more than 32
verification classes. Each positive decimal integer represents a
verification class. Multiple classes can be expressed by separating
each class id with space character.
The '/dif' command automatically includes rule class 36, DIF mode, but
/ruleclasses and /rc do not. Rule classes marked with (RuleClassId)
requires users to pass dependent rule class. Flags marked with (^) can
be enabled without reboot using the
'/dif [ ] /now' command.
Rule classes marked with (**) support disabling of individual rules.
Rule classes marked with (***) are in logging mode by default and
require /onecheck in order to crash upon violation.
The following rule class IDs are available (no leading 0's required):
Standard Rule Classes:
1 - Special pool (^)
2 - Force IRQL checking (^)
4 - Pool tracking (^)
5 - I/O verification (^)
6 - Deadlock detection (^)
8 - DMA checking (^)
9 - Security checks (^)
12 - Miscellaneous checks (^)
18 - DDI compliance checking (^)
34 - WDF Verification
37 - File System Filter verification (5)
Additional Rule Classes:
These rule classes are intended for specific scenario testing.
3 - Randomized low resources simulation
10 - Force pending I/O requests (5)
11 - IRP logging (5)
14 - Invariant MDL checking for stack (5)
15 - Invariant MDL checking for driver (5)
16 - Power framework delay fuzzing
17 - Port/miniport interface checking
19 - Systematic low resources simulation (36, ^)
20 - DDI compliance checking (additional) (^)
22 - NDIS/WIFI verification (**)
24 - Kernel synchronization delay fuzzing
25 - VM switch verification
26 - Code integrity checks
33 - Driver isolation checks (***, 36)
36 - Driver Interception Framework (DIF) mode
43 - SCSI Port verification
44 - Storport verification
45 - Win32 verification (3)
/dif [ ] /now
Enables the rule classes immediately without needing reboot. This option
is only valid if no rule classes are already running. See the rule class
descriptions for the rule classes capable of immediate activation.
/action [1 ... k]
This switch is generally used for communicating with plugins and is
dependent on '/dif' switch. A positive number is plugin specific
communication action ID. Plugins optionally show further usaga via
'verifier /dif {PluginId} /?'.
/stop
Disables rule classes enabled via '/dif /now' to halt verification.
/log.code_integrity
This option suppresses Code Integrity violation breaks and collects
only statistics for verified drivers. Statistics could be extracted
via /log option or kernel debugger. This parameter is applicable only
if Code Integrity checks are enabled.
/rules {query | reset | default | disable }
Specifies rules level control (advanced).
query Shows current status of controllable rules.
reset Resets all rules to their default state.
default Sets rule ID to its default state.
disable Disables specified rule ID.
/query
Display runtime Driver Verifier statistics and settings.
/querysettings
Displays a summary of the options and drivers that are currently
enabled, or options and drivers that will be verified after the
next boot. The display does not include drivers and options added
using /volatile.
/bootmode
Specifies the Driver Verifier boot mode. This option requires system
reboot to take effect.
persistent Ensures that Driver Verifier settings are
persistent across reboots. This is the default
value.
resetonbootfail Disables Driver Verifier for subsequent reboots
if the system failed to start.
resetonunusualshutdown
Driver Verifier persists until unusual shutdown
happens. Its abbrevation, 'rous', can be used.
oneboot Enables Driver Verifier only for the next boot. |
| 0xc100f002 | 11 | /bc
Sets the number of reboots for which verification should be active.
This option automatically sets the ResetOnUnusualShutdown boot mode.
/persistthroughupgrade
Makes the Driver Verifier settings persist through upgrade. Driver
Verifier will be active during system upgrade.
/reset
Clears Driver Verifier flags and driver settings. This option requires
system reboot to take effect.
/faults [probability [pool_tags [applications [delay_minutes]]]]
Enable the Randomized low resources simulation feature and optionally
control parameters for the Randomized low resources simulation.
Probability Specifies the probability that Driver Verifier will
fail a given allocation. The value represents the
number of chances in 10,000 that Driver Verifier will
fail the allocation. The default value 600, means
600/10000 or 6.
Pool Tags: Specifies a space separated list of the pool tags to
be injected with faults. By default, any pool
allocation can be injected with faults.
Applications Specifies a space separated list of image file names
(an executable) that will be injected with faults. By
default, any pool allocation can be injected with
faults.
DelayMinutes Specifies the number of minutes after booting during
which Driver Verifier does not intentionally fail any
allocations. This delay allows the drivers to load
and the system to stabilize before the test begins.
The default value is 8 minutes.
/faultssystematic [ ...]
Controls the Systematic low resources simulation parameters.
enableboottime Enables fault injections across reboots.
disableboottime Disables fault injections across reboots.
This is the default value.
recordboottime Enables fault injections in 'what if' mode
across reboots.
resetboottime Disables fault injections across reboots and
clears the stack exclusion list.
enableruntime Dynamically enables fault injections.
disableruntime Dynamically disables fault injections.
recordruntime Dynamically enables fault injections in
'what if' mode.
resetruntime Dynamically disables fault injections and
clears the previously faulted stack list.
querystatistics Shows the current fault injection statistics.
incrementcounter Increments the test pass counter used to
identify when a fault was injected.
getstackid Retrieves the indicated injected stack id.
excludestack Excludes the stack from fault injection.
/log [/interval ]
Creates a log file with the specified name and periodically writes the
runtime statistics to this file. The interval between log file updates
is controlled by the '/interval' parameter. The default value is 30
seconds. Use CTRL+C to close the log and return.
/volatile
Changes Driver Verifier settings without rebooting the computer.
Volatile settings take effect immediately and are in effect until the
next system reboot.
This option is deprecated. For most cases, '/dif /now'
should be used instead.
/volatile /adddriver [ ...]
Starts the verification for the specified driver or drivers.
/volatile /removedriver [ ...]
Stops the verification for the specified driver or drivers.
/volatile /flags
Specifies the Driver Verifier options that are changed immediately
without rebooting. Only the following flags can be used with volatile:
0x00000004 (bit 2) - Randomized low resources simulation
0x00000200 (bit 9) - Force pending I/O requests (*)
0x00000400 (bit 10) - IRP logging (*)
/domain {wdm | ndis | ks | audio} [rules.all | rules.default] /driver ...
[/logging | /livedump]
Controls the verifier extension settings. The following verifier
extension types are supported:
wdm Enabled verifier extension for WDM drivers.
ndis Enabled verifier extension for networking drivers.
ks Enabled verifier extension for kernel mode
streaming drivers.
audio Enabled verifier extension for audio drivers.
The following extension options are supported:
rules.default Enables default validation rules for the selected
verifier extension.
rules.all Enables all validation rules for the selected
verifier extension.
/logging
Enables logging for violated rules detected by the selected verifier
extensions.
/livedump
Enables live memory dump collection for violated rules detected by
the selected verifier extensions. |