feat(process): publish v0.3 system-evidence bridge - #3
Draft
stacknil wants to merge 5 commits into
Draft
Conversation
Owner
Author
|
Semantic contract follow-up in
Validation: |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
linux-process-observe adaptsubcommand forprocess_diff.jsonDesign decision
The adapter stays inside
linux-process-observebecause its source contract isstacknil.system-evidence.v1. It maps process changes toprocess_*events and socket-link changes tosocket_link_*events while preserving the original identity and field changes inmetadata. No code changes are made in telemetry-lab; its existing event loader/window workflow is the consumer boundary.Main risk
A process diff is saved snapshot evidence, not live telemetry. The adapter intentionally does not infer causality, reachability, compromise, or authoritative process identity from executable paths or PID context.
Compatibility impact
Existing process snapshot, socket-link, diff, and report schemas are unchanged. The new JSONL has telemetry-lab's required
timestamp,event_type,source,target, andstatusfields. Unlinked sockets use a deterministic PID fallback source when available.Rollback path
Revert the three commits or remove the
adaptsubcommand and adapter module. Existing snapshot/diff workflows remain independently usable.Validation
git diff --checkpassesRelease gate
This PR is intentionally draft because the release diff touches 11 files. After checks and bot review, perform a final diff review, keep the PR open for the required review window, then merge and tag
v0.3.0.