Chapters & navigation

START HERE

Feed diagnostics

Distinguish real feed download and verification failures from the removed homepage mirror probe.

v4.10.4Updated October 10, 20263 min read
On this page

Published with v4.10.4 on 10 October 2026. See the publication record for exact identities and IVV limits.

A provider homepage and a threat-intelligence feed are different resources. A homepage result does not establish whether a feed can be downloaded, validated and applied.

The older GitHub mirror warning#

Older installers sent an HTTP HEAD request to a provider's root URL before downloading network intelligence. The GitHub raw-content root redirects to the main GitHub website. The probe refused redirects and required HTTP 200, so it could report Connecting to GitHub... FAIL even when the actual raw feed URL returned HTTP 200.

Installation already ignored that benchmark's selected-mirror result. The v4.10.4 correction removes this unused probe. The downloader still evaluates its configured sources, validates the content and enforces its integrity rules.

Read the downloader result#

Message or outcomeMeaning
An older homepage benchmark prints FAILThat probe failed. The message alone says nothing conclusive about the actual feed.
The downloader verifies independent-source quorum and provenanceThe downloader has established the required source agreement and content identity for that feed.
Installation reports that an optional Data-Shield feed was skippedThe required quorum was unavailable. Installation may preserve a validated last-known-good snapshot, or explicitly omit the optional feed when no valid snapshot exists. The warning identifies which happened.
A refresh reports degraded operation or returns an errorInspect the exact downloader and policy-application results. Do not report the feed as freshly updated.
An offline path attests existing feedsExisting material was checked without network access. This is not evidence of a new download.

Optional-feed handling is an existing installation policy, separate from removal of the homepage probe. It does not permit unverified content or silently turn a failed download into a current snapshot. Custom feeds retain their configured hash and transport requirements.

Separate refresh from product update#

syswarden update updates the product. syswarden update-feeds refreshes configured intelligence and reapplies firewall policy. The latter changes system state; it is not a read-only connectivity check.

A feed-refresh failure and firewall-policy application are reported separately. The explicit refresh command reapplies configured policy before returning a download failure. An error therefore does not mean that no operation was attempted.

Investigate a real download failure#

Keep the exact error, release version and time of the attempt in private diagnostic records. Distinguish DNS, TLS and HTTP failures from insufficient source agreement, invalid content, failed provenance or a policy-application error. For public support, share only a minimal redacted reproduction and never include credentials, private network details or raw operational evidence.

Do not disable certificate validation, follow otherwise prohibited redirects, remove integrity checks or reduce source agreement to make a download appear successful. A successful manual fetch is useful diagnostic evidence, but it does not replace the product's verification.

For package and release verification, start with Getting Started. For release assurance and the actual tested scope, read IVV and IVVQ.

Search pages and sections. Nothing leaves your browser.

Tab to a result, Enter to open. Escape to close.