Doctor and troubleshooting

Read environment readiness, distinguish retained history from recoverable residue, and review exact remediation.

Published baseline: v0.10.2.

Read first, repair separately

fragcap doctor
fragcap doctor --json

Doctor checks without starting Capture, a proxy, a target, or trust changes. Capture and Deep Capture readiness are separate verdicts. Missing elevation, Npcap, required backend features, or usable interfaces can block packet recording without proving that the native proxy is unavailable. Indeterminate means the check could not establish the fact; it is not a green result. Target compatibility is separate from environment readiness.

Native resource rows expose session/resource identity, kind, state, health, ownership authority, and recovery eligibility. Human output wraps full identities and adapts to narrow terminals. JSON preserves machine names and adds native_resource; do not scrape column spacing as a stable API.

Recovery is exact ownership, not a sweep

Completed bundles and retained sensitive artifacts can be healthy history. Their existence alone does not authorize deletion. Durable journals distinguish acquired, pending, reconciled, missing, ambiguous, and unprovable resources. Recovery decisions are shared with session preparation: pending prior-session recovery can refuse a new session before its plan appears.

fragcap doctor --fix

Review each named action and exact identity before its individual confirmation. CurrentUser trust removal requires the exact recorded owned CA; another user's trust, an unrelated certificate, a process with only a matching image name, or an unprovable listener is not owned. Failed recovery retains evidence. Re-run plain Doctor and retain unresolved journals and manifests rather than deleting the authority needed to recover.

Published builds offer the official Npcap acquisition page after confirmation. Optional source-build net support may fetch and launch the vendor's signed installer after confirmation. Neither path silently installs or redistributes the driver. Wireshark/extcap remediation is optional for command-line Capture.

A stalled check

Historical v0.10.0 has coarse progress and a hidden fragcap doctor --timings switch that adds completion durations; it cannot update while a probe is blocked. v0.10.1 and later ship the S151 diagnostics below and are available for optional operator-owned installed observation. The historical stall cause was not measured on the affected host. If a current release stalls despite the elapsed and nested progress, file a defect naming the release, privilege state, visible phase, elapsed time and scrubbed reproduction details.

In published v0.10.1 and later, normal Doctor help exposes --timings. Interactive normal human read-only runs identify nested residue inventory, manifest/artifact scanning, manifest CA identities, separate root certificate stores and IPv4/IPv6 readiness. After one second of pending work, stderr reports the active operation and elapsed milliseconds, repeating no faster than once per second. Slow completions include actual durations automatically; --timings includes fast completions too. Residue inventory and ETW session availability remain aggregate boundaries, not individual API attribution. Pending does not mean unavailable, and there is no new probe timeout or cancellation guarantee. JSON, redirected human, quiet, silent, fix behavior and final reports remain unchanged.

The operator owns installed reproduction on published bytes; agents do not run the installed sensitive product or change real host trust to manufacture evidence. Report version, privilege, first-run versus repeat, named phase/sub-operation, elapsed time and sanitized diagnostic evidence. Exclude account names, private paths, target inventory, endpoints, credentials and bundle contents. A stalled or interrupted check does not establish readiness or authorize repair.

For bundle authority and explicit sharing, see Output formats and Security and privacy.