igneum/relay/playbooks/pc2-crash-collect.ps1

82 lines
6.7 KiB
PowerShell

# What stopped PC 2 at 10:46Z on 7 October 2026 (MF-11): every stream (app, node, miner) went quiet mid-line twelve
# minutes after the 0.3.19 update returned. Read-only collection, printed to the job report: the System and
# Application event logs from 10:00Z (boot, power, bugcheck, WHEA, display drivers first), the minidump folder and
# the latest dump's bugcheck code, the app's last two logs and OTA files, the relay agent's logs and task, the GPU
# drivers and the reliability records. Queued as a signed `run` job (packaging/ota/publish-jobs.sh); it touches
# nothing and sends nothing to the installed app.
$ErrorActionPreference = 'Continue'
$sinceUtc = '2026-10-07T10:00:00.000Z'
function Section([string]$t) { Write-Host ''; Write-Host ('== ' + $t) }
function Q([string]$log, [string]$xpath, [int]$count) {
try { & wevtutil.exe qe $log ('/q:' + $xpath) /f:text ('/c:' + $count) 2>&1 | ForEach-Object { "$_" } } catch { Write-Host ('wevtutil failed: ' + $_.Exception.Message) }
}
$time = "TimeCreated[@SystemTime>='" + $sinceUtc + "']"
Section ('now ' + (Get-Date -Format o) + ' (local), ' + [DateTime]::UtcNow.ToString('o') + ' UTC')
try { Get-CimInstance Win32_OperatingSystem | Select-Object LastBootUpTime, Caption, BuildNumber | Format-List | Out-String | Write-Host } catch {}
Section 'boot and shutdown events since 10:00Z (41 Kernel-Power, 1001 BugCheck, 6005 6006 6008 Event Log, 1074 User32, 12 13 Kernel-General)'
Q 'System' ("*[System[" + $time + " and (EventID=41 or EventID=1001 or EventID=6005 or EventID=6006 or EventID=6008 or EventID=1074 or EventID=12 or EventID=13)]]") 60
Section 'System by source: Kernel-Power, BugCheck, WHEA, nvlddmkm, amdkmdag, Display, Kernel-General'
Q 'System' ("*[System[" + $time + " and Provider[@Name='Microsoft-Windows-Kernel-Power' or @Name='Microsoft-Windows-WER-SystemErrorReporting' or @Name='Microsoft-Windows-WHEA-Logger' or @Name='nvlddmkm' or @Name='amdkmdag' or @Name='Display' or @Name='Microsoft-Windows-Kernel-General' or @Name='volmgr' or @Name='disk']]]") 200
Section 'System: every critical and error since 10:00Z'
Q 'System' ("*[System[" + $time + " and (Level=1 or Level=2)]]") 200
Section 'Application: every critical and error since 10:00Z (Application Error, WER, .NET, Igneum)'
Q 'Application' ("*[System[" + $time + " and (Level=1 or Level=2)]]") 200
Section 'Application: Igneum and PowerShell sources since 10:00Z'
Q 'Application' ("*[System[" + $time + " and Provider[@Name='Igneum Miner' or @Name='igneum-app' or @Name='PowerShell' or @Name='Windows Error Reporting']]]") 100
Section 'minidumps'
$mdDir = Join-Path $env:SystemRoot 'Minidump'
try { Get-ChildItem $mdDir -ErrorAction SilentlyContinue | Sort-Object LastWriteTime | Format-Table Name, Length, LastWriteTime -AutoSize | Out-String | Write-Host } catch {}
try { Get-Item (Join-Path $env:SystemRoot 'MEMORY.DMP') -ErrorAction SilentlyContinue | Format-Table Name, Length, LastWriteTime -AutoSize | Out-String | Write-Host } catch {}
$dump = Get-ChildItem $mdDir -ErrorAction SilentlyContinue | Sort-Object LastWriteTime -Descending | Select-Object -First 1
if ($dump) {
# the 64-bit dump header: 'PAGEDU64', the bugcheck code at 0x38 and its four parameters at 0x40, 0x48, 0x50, 0x58
try {
$fs = [IO.File]::OpenRead($dump.FullName)
$hdr = New-Object byte[] 4096
$n = $fs.Read($hdr, 0, 4096)
$fs.Close()
$sig = [Text.Encoding]::ASCII.GetString($hdr, 0, 8)
$code = [BitConverter]::ToUInt32($hdr, 0x38)
$p = @(0x40, 0x48, 0x50, 0x58) | ForEach-Object { ('0x{0:x}' -f [BitConverter]::ToUInt64($hdr, $_)) }
Write-Host ('latest dump ' + $dump.Name + ' (' + $dump.LastWriteTime.ToString('o') + '): header ' + $sig + ', bugcheck 0x' + ('{0:x}' -f $code) + ' params ' + ($p -join ' '))
} catch { Write-Host ('dump header not read: ' + $_.Exception.Message) }
} else { Write-Host 'no minidump on this PC' }
Section 'reliability records (last 40, newest first)'
try { Get-CimInstance Win32_ReliabilityRecords -ErrorAction SilentlyContinue | Sort-Object TimeGenerated -Descending | Select-Object -First 40 TimeGenerated, SourceName, EventIdentifier, ProductName, Message | Format-List | Out-String -Width 220 | Write-Host } catch { Write-Host ('no reliability records: ' + $_.Exception.Message) }
Section 'GPU drivers'
try { Get-CimInstance Win32_VideoController | Select-Object Name, DriverVersion, DriverDate, Status, VideoProcessor | Format-List | Out-String | Write-Host } catch {}
try { & nvidia-smi --query-gpu=name,driver_version,pstate,temperature.gpu --format=csv 2>&1 | ForEach-Object { "$_" } } catch {}
try { & powercfg.exe /lastwake 2>&1 | ForEach-Object { "$_" } } catch {}
try { & powercfg.exe /requests 2>&1 | ForEach-Object { "$_" } } catch {}
Section 'app logs: the last three runs (tail 80 each)'
$logs = Join-Path $env:LOCALAPPDATA 'igneum\logs'
$files = @(Get-ChildItem $logs -Filter 'app-*.log' -ErrorAction SilentlyContinue | Sort-Object LastWriteTime -Descending | Select-Object -First 3)
$files | Format-Table Name, Length, LastWriteTime -AutoSize | Out-String | Write-Host
foreach ($f in $files) { Write-Host ('--- ' + $f.Name + ' (last write ' + $f.LastWriteTime.ToString('o') + ')'); Get-Content $f.FullName -Tail 80 -ErrorAction SilentlyContinue }
Section 'OTA files in the app folder'
$app = Join-Path $env:LOCALAPPDATA 'igneum\app'
foreach ($n in @('ota-apply.log', 'ota-setup.log', 'update-pending.json', 'update-result.json', 'failed-versions.json', 'jobs-state.json')) {
$p = Join-Path $app $n
if (Test-Path $p) { Write-Host ('--- ' + $n + ' (' + (Get-Item $p).LastWriteTime.ToString('o') + ')'); Get-Content $p -Tail 40 -ErrorAction SilentlyContinue }
}
Write-Host ('start at login: ' + (Get-ItemProperty -Path 'HKCU:\Software\Microsoft\Windows\CurrentVersion\Run' -ErrorAction SilentlyContinue | Select-Object -ExpandProperty 'Igneum Miner' -ErrorAction SilentlyContinue))
Section 'relay agent: logs, scheduled task, running shells'
$rl = Join-Path $env:LOCALAPPDATA 'igneum-relay'
try { Get-ChildItem (Join-Path $rl 'logs') -ErrorAction SilentlyContinue | Sort-Object LastWriteTime -Descending | Select-Object -First 6 Name, Length, LastWriteTime | Format-Table -AutoSize | Out-String | Write-Host } catch {}
foreach ($n in @('state.json', 'machine.txt')) { $p = Join-Path $rl $n; if (Test-Path $p) { Write-Host ('--- ' + $n); Get-Content $p -ErrorAction SilentlyContinue } }
try { & schtasks.exe /Query /TN IgneumRelayAgent /V /FO LIST 2>&1 | Select-Object -First 14 | ForEach-Object { "$_" } } catch {}
try { & schtasks.exe /Query /TN IgneumRelayService /V /FO LIST 2>&1 | Select-Object -First 14 | ForEach-Object { "$_" } } catch {}
try { Get-Process -Name powershell, cmd, 'Igneum Miner', igneum-app, igneumd -ErrorAction SilentlyContinue | Select-Object Id, ProcessName, StartTime | Format-Table -AutoSize | Out-String | Write-Host } catch {}
Write-Host 'collection done'