NFR-OPS-2 — Crash reporting #33

Closed
opened 2026-09-05 16:20:16 +00:00 by dtourolle · 2 comments
Owner

NFR-OPS-2 — crash reporting. A log::error! panic hook on Android, and nothing at all on desktop.

Absent

  • No local crash record.
  • No backtrace capture.
  • No upload path — and therefore no opt-in gate to guard it.

The last point is the one that makes this awkward to defer: an opt-in gate is cheap to design in and expensive to retrofit onto a reporting path that already exists, and NFR-SEC-4's no-telemetry stance means the gate is not optional.

Acceptance

  • A panic writes a local crash record with a backtrace, on both platforms.
  • Nothing leaves the device without explicit consent, per instance rather than once.
  • Credentials and paths redacted before anything is written, let alone sent.

Related

#32 — NFR-OPS-1's rotating log and consented bundle are the same machinery.

See docs/outstanding.md §5.

**NFR-OPS-2 — crash reporting.** A `log::error!` panic hook on Android, and nothing at all on desktop. ## Absent - No local crash record. - No backtrace capture. - No upload path — and therefore no opt-in gate to guard it. The last point is the one that makes this awkward to defer: an opt-in gate is cheap to design in and expensive to retrofit onto a reporting path that already exists, and NFR-SEC-4's no-telemetry stance means the gate is not optional. ## Acceptance - [ ] A panic writes a local crash record with a backtrace, on both platforms. - [ ] Nothing leaves the device without explicit consent, per instance rather than once. - [ ] Credentials and paths redacted before anything is written, let alone sent. ## Related #32 — NFR-OPS-1's rotating log and consented bundle are the same machinery. See `docs/outstanding.md` §5.
dtourolle added the unmet-requirementsize:Mandroid labels 2026-09-05 16:20:16 +00:00
Author
Owner

Same machinery as #32.

**Same machinery as** #32.
Author
Owner

Already met by platform/dr-plat/src/crash.rs (35954df, 2026-08-30), which predates this issue — it was written from a stale outstanding.md entry. A panic writes a local record with a redacted message and backtrace on both platforms; there is deliberately no upload path, so nothing leaves the device. The consent gate belongs with NFR-OPS-1's bundle (#32), which stays open.

Already met by platform/dr-plat/src/crash.rs (35954df, 2026-08-30), which predates this issue — it was written from a stale outstanding.md entry. A panic writes a local record with a redacted message and backtrace on both platforms; there is deliberately no upload path, so nothing leaves the device. The consent gate belongs with NFR-OPS-1's bundle (#32), which stays open.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: dtourolle/DarkRoom#33