NFR-OPS-2 — crash reporting. A log::error! panic hook on Android, and nothing at all on desktop.
Absent
No local crash record.
No backtrace capture.
No upload path — and therefore no opt-in gate to guard it.
The last point is the one that makes this awkward to defer: an opt-in gate is cheap to design in and expensive to retrofit onto a reporting path that already exists, and NFR-SEC-4's no-telemetry stance means the gate is not optional.
Acceptance
A panic writes a local crash record with a backtrace, on both platforms.
Nothing leaves the device without explicit consent, per instance rather than once.
Credentials and paths redacted before anything is written, let alone sent.
Related
#32 — NFR-OPS-1's rotating log and consented bundle are the same machinery.
See docs/outstanding.md §5.
**NFR-OPS-2 — crash reporting.** A `log::error!` panic hook on Android, and nothing at all on desktop.
## Absent
- No local crash record.
- No backtrace capture.
- No upload path — and therefore no opt-in gate to guard it.
The last point is the one that makes this awkward to defer: an opt-in gate is cheap to design in and expensive to retrofit onto a reporting path that already exists, and NFR-SEC-4's no-telemetry stance means the gate is not optional.
## Acceptance
- [ ] A panic writes a local crash record with a backtrace, on both platforms.
- [ ] Nothing leaves the device without explicit consent, per instance rather than once.
- [ ] Credentials and paths redacted before anything is written, let alone sent.
## Related
#32 — NFR-OPS-1's rotating log and consented bundle are the same machinery.
See `docs/outstanding.md` §5.
Already met by platform/dr-plat/src/crash.rs (35954df, 2026-08-30), which predates this issue — it was written from a stale outstanding.md entry. A panic writes a local record with a redacted message and backtrace on both platforms; there is deliberately no upload path, so nothing leaves the device. The consent gate belongs with NFR-OPS-1's bundle (#32), which stays open.
Already met by platform/dr-plat/src/crash.rs (35954df, 2026-08-30), which predates this issue — it was written from a stale outstanding.md entry. A panic writes a local record with a redacted message and backtrace on both platforms; there is deliberately no upload path, so nothing leaves the device. The consent gate belongs with NFR-OPS-1's bundle (#32), which stays open.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
NFR-OPS-2 — crash reporting. A
log::error!panic hook on Android, and nothing at all on desktop.Absent
The last point is the one that makes this awkward to defer: an opt-in gate is cheap to design in and expensive to retrofit onto a reporting path that already exists, and NFR-SEC-4's no-telemetry stance means the gate is not optional.
Acceptance
Related
#32 — NFR-OPS-1's rotating log and consented bundle are the same machinery.
See
docs/outstanding.md§5.Same machinery as #32.
Already met by platform/dr-plat/src/crash.rs (
35954df, 2026-08-30), which predates this issue — it was written from a stale outstanding.md entry. A panic writes a local record with a redacted message and backtrace on both platforms; there is deliberately no upload path, so nothing leaves the device. The consent gate belongs with NFR-OPS-1's bundle (#32), which stays open.