Skip to content

Diagnostics and Privacy

Alexander Phillips edited this page Sep 20, 2026 · 1 revision

Diagnostics and Privacy

Export

Reproduce the issue, then open Tools → Download diagnostics. Keep the downloaded JSON intact when reporting a problem. A fresh export after the failing action is more useful than an old bundle.

The reviewed export schema is 5. It combines available server evidence with browser state. If the server collection times out after approximately 30 seconds, a partial browser report can still be downloaded.

What the bundle explains

  • Installed/server and loaded/browser versions.
  • Environment and selected runtime capabilities.
  • Scan timing, candidate-filter counts and Docker/Compose ownership verification.
  • Snapshot validity, issue/expiry times and browser/server scan correlation.
  • Structured row decisions and blocking versus informational mount evidence.
  • Redacted settings, quarantine summaries, audit excerpts and collector status.
  • UI locale, direction, viewport and internationalization support.
  • Up to the last 20 classified plugin-request/JavaScript failures since page load.

Browser failure records intentionally omit raw error messages, response bodies, URLs and stacks. Exports describe recorded telemetry; they do not silently rescan ownership or perform cleanup.

Completeness and limits

Sections distinguish complete, partial, unavailable or failed collection. “Partial” can mean bounded history, unavailable optional evidence or a real collector failure; inspect the reason.

Collection is deliberately bounded. Reviewed limits include three log sources, up to 100 matching lines per source, a 5,000-line/2 MiB scan budget per source, and bounded audit/state lists. Mount evidence is also capped. The bundle's own collection metadata is the authority for the version that produced it.

Dev 2026.09.19.13+: expected truncation and missing optional logs are informational; actual failed collectors or missing required evidence remain warnings. Stable .12 can classify these normal limits more prominently.

Privacy

Exports use allowlists, export-scoped aliases and final recursive scrubbing of keys and values. Private paths, app/container/template names and identifiers are redacted; credentials and raw Docker/template payloads are not intended for export. Aliases allow correlation inside a bundle without stable public identifiers across exports.

Local state files, raw logs, template backups, screenshots and copied audit text do not have the same privacy contract. Review attachments before public posting. Diagnostics are troubleshooting evidence, not a configuration or appdata backup.

Reading common signals

Signal Meaning / next step
Browser/server version mismatch Hard-refresh and reopen the plugin
Browser/server scan mismatch Rescan, reproduce and export again
Unknown scan match Necessary comparison telemetry was unavailable; not proof of a mismatch
Expired snapshot Rescan before retrying an action
request_failed Docker inventory request failed
invalid_json / invalid_list Inventory response was not usable
incomplete_inventory Some records could not be verified
not_checked No applicable recorded scan evidence yet

Use Troubleshooting for corrective steps and Support and Contributing for reports.

Clone this wiki locally