v0.7.0
What's new
A big one. 0.7.0 is about PCs with more than one thing wrong, and about saying what kind of problem a stall is before blaming anything.
The whole PC stopping is now its own finding
When every processor stops at the same instant (cursor and audio freeze together), that is one event, not a pile of separate stalls blamed on whatever happened to be running. The report says how often it happens and how long it lasts, which device interrupts went quiet and which kept arriving, and what it could not explain.
Before it blames a driver or says "the CPU was held", it now checks whether ordinary interrupt work kept flowing during the stall. If it did, nothing was holding the processor, and the report says the thread simply was not woken instead of accusing a bystander.
A report you can act on when there are layers of problems
Findings are grouped by symptom (the whole PC stops, short interruptions, one program waits, worth knowing), with a short plan and an order of attack: change one thing, run again. Severity follows how often something happens, not just how bad the worst one was. A clean PC with a few background notes now simply says nothing needs fixing.
Before and after
Every run is compared with your previous one automatically: better, worse, new, gone, or about the same, with the numbers. Runs of different lengths are compared per minute. A problem that did not show up is never called "fixed", and findings that look back over a week of event logs say that a fix cannot show there yet.
More of the "why"
- Which thread was kept waiting, and by what. Every thread switch is traced, so the report can tell "nothing woke it" (timer, firmware, power management) from "it was woken and then not given a processor", and can say which thread a starved program was stuck behind. (
--no-switchesturns it off.) - The picture stopped updating. A second, small trace listens to the graphics kernel: at a stall or a moment you flag, the report says how long no new frame reached the screen, which program's frames stopped, and whether Windows was asking for video memory to be freed. (
--no-gpu-trace) - File names for slow disk requests and hard page faults. Program and system files are named; personal files are shown only as "(a .pdf file)", because reports get pasted into forums.
- A late wake-up with idle CPUs is not "CPU starvation". When a disk request or a page fault covers the delay, the report says the thread was blocked on that drive, and it counts as a finding instead of "a one-off, ignore it".
- Hardware-access tools: RGB, fan, monitoring and tuning utilities that talk to the hardware directly are listed with the program behind each driver. Common and not a problem by itself, so it is only raised when it could explain something else in the report.
- Third-party network filters (VPNs, security suites) are named with their author.
- Devices on legacy line-based interrupts where message-signaled interrupts are available, with careful advice: forcing it through the registry can stop a device or the PC from starting.
- Drivers that fire on a timer below the stall threshold are detected as periodic.
Kinder to the PC it measures
- The report shows what the tool itself cost (processor time of both of its processes, events processed and lost).
- Light mode for small PCs: on by itself with 4 logical CPUs or fewer, or on battery (
--light/--no-light). - More than 64 logical CPUs (all processor groups) and P-core / E-core labels.
Less noise
Repeated slow events from the same disk, driver or program fold into roll-up lines in the event log, so a long download to a hard drive no longer produces endless "slow disk write" lines. An outlier still gets its own line. (Thanks for the report.)
Fixes
- A comparison between runs of different lengths could read "about the same" when the rate had dropped twelvefold.
- An NVMe drive was called "busy" at 30 MB/s, which blamed programs for a drive that was slow with almost nothing asked of it. The threshold now depends on the kind of drive.
- "spare 0%" for drives (often behind USB bridges) that do not report it now reads "spare not reported".
- Personal file names could leak through alternate path forms; several smaller fixes from a bug pass.
Known limits
The whole-PC freeze logic and the "picture stopped" finding are tested against recorded and synthetic data; neither has been confirmed on many real machines yet. If a report looks wrong, please open an issue and attach it. What did not make this release is tracked in #19.
Verifying this download
gh attestation verify WTFIsStalling.exe --repo Tyberious/WTFIsStalling proves the file was built by this repository's release workflow from the tagged commit; sha256sum -c SHA256SUMS.txt checks the files. The executables are not code-signed yet, so SmartScreen may warn: More info -> Run anyway. If an antivirus blocks the download, please open an issue with the detection name.
Download
WTFIsStalling.exe is the app. wtfis-cli.exe is the same engine for the console.