Skip to content

Diagnostic Forensics

darkstar edited this page Oct 3, 2026 · 2 revisions

Diagnostic Forensics

Most error libraries answer "what went wrong right now?" diagprint can also answer "what has this exact logical diagnostic been doing over time?"

why ✓ → timeline ✓ → blame ✓ → causal graph ✓ → replay ✓

📚 Record history

diagprint scan . --static --history .diagprint/history --history-label baseline
diagprint history fingerprints .diagprint/history

History is privacy-light and hash-chained: canonical identity, lifecycle state, run labels, severity counts and cryptographic evidence, with no messages, source text, arbitrary attributes or remediation payloads.

🔎 why: the case file

diagprint why .diagprint/history 7f23a9d5c120
DIAGNOSTIC CASE FILE
schema: diagprint.forensics.case-file/v1
status: active
chain-verified: true
first-seen: run=000002 label="baseline"
last-seen: run=000011 label="regressed"
episodes: 2   reappearances: 1   severity-increases: 1

Evidence only: no guessed root cause, blame or authorship. Fingerprints can be a unique leading hex prefix.

📈 timeline

diagprint timeline .diagprint/history 7f23a9d5c120
Glyph Meaning
● first observation / active run
▲ severity increase
◆ canonical content change
○ resolution
↻ reappearance after absence
· absent or not yet seen

The glyphs are just presentation; the timeline keeps full transition counts, severity distribution, content digests, episodes and labels.

🧬 blame: Git provenance

diagprint scan . --static --history .diagprint/history --git-provenance
diagprint blame .diagprint/history 7f23a9d5c120

The worktree must be clean before and after the scan; the run is then bound to the exact commit and tree, and blame verifies them in the local object store. Older history can be backfilled with diagprint history git-bind <HISTORY> <RUN> <COMMIT>; those records are permanently marked user_asserted.

Important

blame means provenance, not causation. A commit being associated with a run never establishes that it caused the diagnostic.

🕸️ graph: relationships

diagprint graph .diagprint/history <FINGERPRINT>
diagprint graph .diagprint/history <FINGERPRINT> --evidence all     # include inferred correlations
diagprint graph .diagprint/history <FINGERPRINT> --format dot       # Graphviz

Typed relationships between canonical identities, with evidence provenance kept separate (producer-declared, source-chain, structural, trace, temporal, inferred). Traversal is cycle-safe and depth-bounded; cascades report recorded explicit causal edges only.

🔁 replay

Read-only reconstruction of remediation-bound transitions; see Remediation.

Specs: forensics · timeline · git provenance · relationship graph · replay

← 🔧 Remediation  ·  ⌨️ CLI Reference →

🩺 diagprint

⚡ Start

🧱 Build

📤 Ship

🔧 Fix

🔬 Investigate

🛠️ Project


🌐 Site · 📖 docs.rs · 📦 crates.io

Clone this wiki locally