Releases: marcelosofficial-ctrl/CrashScope
Release list
CrashScope 1.2.0
CrashScope 1.2.0
Publication provenance
- validated private runtime commit:
3a6a3ffd9ad40943e7e5fc8be4d8faf0fc7b9912 - validated private documentation seal:
da470305ad3b5b186e7e3542f428df4fe2ceb30d - privacy-safe public tag commit:
8ce9c25dc40f6481bf7b782d3dae67deeb3e6cef - original privacy-safe public documentation commit:
097790d6c700fc4fe3e32e080bc0200b08a5bc1f - exact shared runtime Git tree:
b23d4e4e8f79598362d8d9cc9d1a405e989ee3c6 - portable SHA-256:
5cd5821800b2e5f2c4ace319a6921267414465129c704b8e50c83b1a1a932b04 - installer SHA-256:
a37c012293a1c5e5aa94c823f1898a85ef0bc896b5b3cf03d870e8191050a12e
The engineering history remains private in CrashScope-development. Public source commits preserve the exact validated Git trees while using privacy-safe public commit metadata.
CrashScope 1.2.0 release notes
CrashScope 1.2.0 adds a native Windows desktop application shell while preserving the local-first, evidence-first, least-privilege, and low-overhead Agent architecture.
CrashScope 1.2.0 is publicly released at GitHub Releases. The published installer, portable ZIP, and checksum file are the exact artifacts sealed during local release validation.
Public publication provenance
- Public runtime/tag commit:
8ce9c25dc40f6481bf7b782d3dae67deeb3e6cef - Public documentation/main commit at publication:
097790d6c700fc4fe3e32e080bc0200b08a5bc1f - Exact shared runtime Git tree:
b23d4e4e8f79598362d8d9cc9d1a405e989ee3c6 - Public
v1.2.0remains on the runtime boundary. - Publication used direct validated artifact upload; no public GitHub Actions runner jobs were required.
Native desktop shell
- WPF hosts the existing React dashboard through WebView2.
- The Agent remains the lightweight background/runtime process.
- The Desktop process exists only while the native UI is open.
- Closing the Desktop window unloads the WebView2 UI while leaving the Agent running.
- Duplicate Desktop launches signal and activate the existing window rather than creating another shell.
- Normal launch, tray Open CrashScope, and existing-instance behavior prefer the Desktop shell and retain browser fallback.
- Navigation remains restricted to CrashScope's loopback dashboard origin.
Windows integration
- CrashScope now uses a recognizable multi-resolution application icon.
- The Desktop window uses native dark caption integration.
- Portable packages contain the Desktop payload under
desktop\. - Installer shortcuts continue to target
CrashScope.exeso the Agent lifecycle remains authoritative, while the Desktop executable supplies the shortcut icon. - The installer remains per-user and non-admin for normal use.
State-safety hardening
CrashScope's installed-validation safety helper now carries the original product-data root in its durable context. Vault completion re-verifies the restored path/length/SHA-256 manifest before deleting the preservation vault. Repeated completion is accepted only after the restored state has been independently verified.
The installed-validator safety test includes a synthetic runtime proof covering protect, isolated validation state, verified restore, first completion, repeated completion, and final manifest equality.
Validation
- 266/266 .NET tests passed: Core 30, Infrastructure 37, Agent 179, Desktop 20.
- Production preview packaging, portable smoke, installer build, and installer contract passed.
- Real installed 1.1.0 -> 1.2 production-preview upgrade passed.
- Start Menu and Desktop shortcuts passed target/icon/working-directory validation.
- Native Desktop launch, true single-instance behavior, dark title bar, embedded dashboard, tray icon, and close-window-keeps-Agent behavior passed.
- Upgrade and uninstall preserved CrashScope user data.
- Upgrade/uninstall preserved unrelated startup state and removed only the exact CrashScope-owned startup value.
- Recovery consensus verified that the restored user-data tree contained no 1.2G marker, every file predated 1.2G, and the tree exactly matched the separately preserved R6 snapshot.
Hardware-validation scope
The strongest real-hardware validation remains the Ryzen 5 7500F / Radeon RX 9070 XT Windows 11 development system plus the existing Windows 10 / Intel Core i5-3210M / Intel HD Graphics 4000 second-PC validation. NVIDIA real-hardware validation remains outstanding and is not claimed.
Signing
The local 1.2.0 installer is unsigned. Windows SmartScreen reputation warnings may occur. Self-signing would not create public reputation trust, and CrashScope does not instruct users to disable SmartScreen or other Windows security controls.
Final release artifact seal
- Binary release/tag target:
3a6a3ffd9ad40943e7e5fc8be4d8faf0fc7b9912 - Portable ZIP SHA-256:
5cd5821800b2e5f2c4ace319a6921267414465129c704b8e50c83b1a1a932b04 - Installer SHA-256:
a37c012293a1c5e5aa94c823f1898a85ef0bc896b5b3cf03d870e8191050a12e - Published Agent SHA-256:
db0deb3234def23a2b4b95e34b841904a189b8625b7ef3f9a5ed6969ee522244 - Published Desktop SHA-256:
c19401015f81ea66d53e9b25e096b3bff3ce7bda5aec7ba740da8ec4fad5974e - Automated .NET tests: 266/266 PASS
The binary release boundary remains the validated private runtime commit above. Public v1.2.0 points to a privacy-safe public commit with the exact same runtime Git tree; later documentation-only commits do not move the tag or replace the published binaries.
Code signing policy
CrashScope's future trusted-signing policy is documented here:
https://github.com/marcelosofficial-ctrl/CrashScope/blob/main/docs/code-signing-policy.md
Future SignPath Foundation signing, if approved and active for a release, will remain manually approval-gated and will only sign CrashScope-owned binaries built from the declared public source workflow.
CrashScope 1.1.0
CrashScope 1.1.0
Publication provenance
- validated private engineering commit:
e51943f6b7aecaf98223ef30cbec10ef94c1eba1 - privacy-safe public tag commit:
341487a0f82c15523611a92fb2829a16cf97d2a7 - exact shared Git tree:
908cb6d12da1c360a663ce85b9a95c2469464c13 - portable SHA-256:
4ac728d03d634218add25d94e69a1a55ddd3283b6afc786dc155e1e7e15360a9 - installer SHA-256:
eb0acdab0f1da5ae5fbaeceadbd3691ee188f0d42204ddffc9527aa38f28062f
The full engineering history remains private in CrashScope-development because historical commit metadata contained personal author/committer email information. The public tag preserves the exact validated source tree without exposing that history.
CrashScope 1.1.0 release notes
CrashScope 1.1.0 extends the frozen 1.0 line with a generic external-evidence provider architecture and ConfigTrace integration while preserving the local-first, privacy-first, evidence-first, and low-overhead design.
Public publication is still intentionally deferred until the coordinated release sweep. The exact final v1.1.0 tag target is the locally frozen 1.1 release commit produced after validation; no tag or GitHub Release is created by the local release-engineering batches.
What changed from 1.0
Generic external evidence providers
CrashScope now has a generic EvidenceEvent provider boundary for process-isolated evidence sources. Provider evidence is mapped into the existing incident model as bounded chronological evidence rather than as a separate causal system.
The central rule remains:
A nearby event is correlation evidence unless stronger evidence supports a causal claim.
For example, CrashScope can say that a renderer setting changed seconds before an incident. It does not claim that the setting change caused the incident.
ConfigTrace 1.0.1 integration
CrashScope 1.1 bundles ConfigTrace as its first external sidecar provider:
- ConfigTrace is OFF by default;
- the user explicitly selects one existing absolute configuration root;
- ConfigTrace starts only while a workload is actively monitored;
- the sidecar stops with the workload;
- journals live under CrashScope-owned local application data;
- nearby semantic configuration changes are imported as
Contextevidence; - ConfigTrace failure is isolated and must not take CrashScope down;
- portable and installed layouts use the same bundled
providers\ConfigTrace\configtrace.exepath.
Bundled ConfigTrace provenance:
- version: 1.0.1
- source commit:
b629c970dfc14fca5df1e0ef2b0d1d07d0d8c56c - Windows EXE SHA-256:
fe1c470a58402e82e97ee529c6a6b02822430da70e65ffc5fc5a71359ad4e521 - license: MIT
- bundled license path:
providers\ConfigTrace\LICENSE.txt
ConfigTrace 1.0.1 includes a privacy fix discovered during CrashScope integration: sensitive-key recognition now handles camelCase/PascalCase names such as apiToken, accessToken, refreshToken, clientSecret, sessionId, and APIKey. Real JSONL watcher validation proved that sensitive values remain redacted while change fingerprints continue to work.
Settings and dashboard
CrashScope settings schema v3 adds:
configTraceEnabledconfigTraceRootPath
Existing 1.0-era settings migrate with ConfigTrace disabled and no configured root.
The dashboard adds a ConfigTrace control that:
- saves one absolute configuration root;
- prevents enabling the provider without a valid saved root;
- explains that ConfigTrace only runs during monitored workloads;
- keeps the provider disabled by default.
Manual diagnostic markers
User-requested safe diagnostic markers now use the same bounded provider-evidence mapping as live incidents. ConfigTrace evidence attached to a marker remains Context; the marker classification stays UserDiagnosticMarker.
Validation status
The 1.1 integration checkpoint passed:
- 239 .NET tests passed, 0 failed
- ConfigTrace Rust formatting/tests/build validation
- ConfigTrace 1.0.1 real watch-journal privacy smoke
- portable sidecar packaging/hash/provenance checks
- real ConfigTrace OFF/ON lifecycle validation
- real semantic config-change journal capture
- secret absent from the raw ConfigTrace journal
- secret absent from CrashScope incident JSON
- exactly one ConfigTrace evidence item observed in the end-to-end marker validation
- that evidence item mapped as
Context - bundled sidecar started with the monitored workload and stopped with it
- real user CrashScope state restored after validation
A short idle integration measurement during the pre-release A11 gate recorded approximately:
- ConfigTrace OFF: Agent average CPU 0.29%, Agent peak working set 97.63 MB
- ConfigTrace ON: Agent average CPU 0.1937%, Agent peak working set 99.74 MB
- ConfigTrace sidecar average CPU 0% in that sample, peak working set 4.95 MB
Those are targeted integration measurements, not the final 1.1 performance seal. Final release validation separately rechecks performance and cross-machine behavior.
Packaging
The self-contained 1.1 portable and installer packages include:
CrashScope.exe
wwwroot/
providers/
ConfigTrace/
configtrace.exe
LICENSE.txt
LICENSE.txt
THIRD-PARTY-NOTICES.md
BUILD-INFO.txt
The installer recursively installs the same validated portable payload. It remains per-user, non-admin for normal operation, does not create a Windows service, does not force Start with Windows, and preserves CrashScope user data.
Not included in 1.1
GapTrace/network evidence is intentionally not part of CrashScope 1.1. The generic provider boundary is designed to support future evidence sources without making them a requirement for this release.
Code signing is also not implemented in 1.1.0; unsigned-build SmartScreen reputation warnings may occur.
Final local release validation
CrashScope 1.1 local release validation is complete.
Validated release boundary:
- exact v1.1.0 release/tag target:
e51943f6b7aecaf98223ef30cbec10ef94c1eba1 - exact portable SHA-256:
4ac728d03d634218add25d94e69a1a55ddd3283b6afc786dc155e1e7e15360a9 - exact installer SHA-256:
eb0acdab0f1da5ae5fbaeceadbd3691ee188f0d42204ddffc9527aa38f28062f - automated .NET tests: 239/239 PASS
Installed upgrade validation passed for the exact 1.0.0 -> 1.1.0 path:
- settings schema v2 -> v3 migrated correctly;
- existing Auto Assist and retention settings were preserved;
- ConfigTrace was introduced disabled with a null root by default;
- a persisted 1.0 diagnostic-marker incident survived the upgrade;
- startup state survived the upgrade;
- 1.1 uninstall removed the application and owned startup value while preserving user data;
- the original pre-validation user state was restored exactly.
Final main-PC performance/cleanliness measurements:
- ConfigTrace OFF: CrashScope 0.2365% average CPU, 91.71 MB average working set, 94.58 MB peak working set, 34.76 MB average private memory;
- ConfigTrace ON with an active controlled workload: CrashScope 0.1966% average CPU, 95.36 MB average working set, 97.31 MB peak working set, 34.06 MB average private memory;
- ConfigTrace sidecar: 0% measured average CPU, 4.96 MB average working set, 4.99 MB peak working set, 0.91 MB average private memory;
- stale WebSocket frames: 0;
- stream delivery misses: 0;
- ConfigTrace journal created successfully;
- plaintext test secret in the journal: not found;
- sidecar start/stop lifecycle: PASS.
Genuine second-PC validation also passed:
- Windows 10;
- Intel Core i5-3210M;
- Intel HD Graphics 4000;
- non-elevated validation;
- exact portable SHA matched;
- automated validator exited 0;
- final manual dashboard inspection: PASS.
The branch may contain a later documentation-only commit recording these completed gates. That later documentation commit is intentionally not the v1.1.0 binary release boundary. The release/tag target remains the exact runtime commit above so source provenance matches the binaries that were actually validated.
Public release publication is complete for this version.
CrashScope 1.0.0
CrashScope 1.0.0
Publication provenance
- validated private engineering commit:
10c5769364068619f026e609a3c221d2665ede57 - privacy-safe public tag commit:
4336d5cde8b2e0fcd07e3397abe0b72826b6a49f - exact shared Git tree:
ed81a24c9f4eb49954633f21d4ac681cdd0000c2 - portable SHA-256:
3a0a61969830e824b5c8d3d828b730a0e878b81679df6b8625897840c39560bb - installer SHA-256:
8574e45f1ce649cfd78748bc42044ef5e9b79a7fa738fc862bb657d51dd52abc
The full engineering history remains private in CrashScope-development because historical commit metadata contained personal author/committer email information. The public tag preserves the exact validated source tree without exposing that history.
CrashScope 1.0.0 release notes
CrashScope 1.0.0 is the frozen first stable local release line. CrashScope 1.0.0 is published alongside CrashScope 1.1.0 as part of the coordinated release.
Frozen source
- Source commit:
10c5769364068619f026e609a3c221d2665ede57 - Version:
1.0.0 - Portable ZIP SHA-256:
3a0a61969830e824b5c8d3d828b730a0e878b81679df6b8625897840c39560bb - Installer SHA-256:
8574e45f1ce649cfd78748bc42044ef5e9b79a7fa738fc862bb657d51dd52abc - Automated .NET tests: 185 passed, 0 failed
The historical v1.0.0 tag must point to that exact source commit. The frozen commit is not amended or rewritten by 1.1 development.
Highlights
CrashScope 1.0.0 provides a local-first Windows crash-diagnostics workflow for games, GPU workloads, AI tools, and unstable PCs:
- low-overhead CPU, RAM, GPU, VRAM, temperature, clock, power, and fan telemetry when exposed by the hardware provider;
- a central 0.5 Hz background / 1 Hz active sampler and approximately 120 seconds of rolling telemetry;
- Windows Event Log, WER, watchdog/LiveKernel, display-driver, application-fault/hang, Kernel-Power, and WHEA evidence;
- evidence-first incident reports with Trigger, Corroborating, and Context roles;
- SQLite incident/session persistence and process identity protection against PID reuse;
- a React/TypeScript dashboard served only on loopback;
- safe user diagnostic markers;
- privacy-safe support-bundle export;
- per-user Start with Windows support controlled by the user;
- a self-contained Windows x64 portable package and per-user Inno Setup installer;
- normal operation without Administrator privileges, a Windows service, an account, analytics, or automatic cloud upload.
CrashScope deliberately separates observation from causation. A process disappearing is not automatically labeled a crash, Kernel-Power 41 is not presented as root-cause proof, and correlated telemetry or Windows evidence is not overstated.
Final 1.0 validation
The frozen 1.0 build passed the complete local release-validation sequence, including installer lifecycle, state restoration, localhost security, second-instance behavior, workload attach/stop, persistence, safe incident capture, and UTF-8/UI validation.
Final main-PC performance on the Ryzen 5 7500F / Radeon RX 9070 XT / Windows 11 reference system:
- average Agent CPU: 0.2327%
- average working set: 91.36 MB
- peak working set: 94.41 MB
- private memory: 34.28 MB
- stale WebSocket frames: 0
- stream delivery misses: 0
A genuine second-PC validation also passed on Windows 10 Home with an Intel Core i5-3210M, Intel HD Graphics 4000, and approximately 8 GB of RAM. That machine had neither the .NET SDK/runtime command nor Node.js installed, confirming the self-contained package path. The final second-PC visual check also confirmed clean UTF-8 rendering and clean unavailable-metric fallbacks.
Packaging and security notes
- Installer AppId remains stable across upgrades:
{08FC71E2-02C3-4A5A-B5EA-F9302EADE31A}. - Default installer location:
%LOCALAPPDATA%\Programs\CrashScope. - User data under
%LOCALAPPDATA%\CrashScopeis preserved by installer repair/uninstall semantics. - CrashScope listens only on loopback and enforces browser-origin restrictions for its local UI/API.
- The installer is unsigned; Windows SmartScreen reputation warnings may occur.
- Code signing is not implemented in 1.0.0.