refactor(networkstream): independent flush snapshot; channel keeps trees, sleep removed (SUB-7786)
The flush handed the notification channel the LIVE storage struct, then -- still holding eventsStorageMutex -- slept 100 ms and stripped every process tree from the maps the consumer was reading. private-node-agent's host network sensor reads outbound.ProcessTree off that channel, so the sleep was the only thing standing between it and having its data erased mid-read. A test proved worse: an event recorded 300 ms AFTER the flush appeared in the already-delivered snapshot, because the clear loop and the consumer shared the same maps. snapshotNetworkStream now allocates its own event maps, so the consumer's view is immune to everything the producer does next. Trees are shared by pointer, not walked: a tree is immutable once attached, which keeps the lock body to O(entities + connections) struct copies. Both sends move outside the lock, and the 100 ms sleep is deleted rather than shortened -- there is no shared state left to race on. removeProcessTreeFromEvents goes with it; the wire copy is where trees leave the payload from here. Adds docs/features/network-stream-process-attribution.md, covering the emitted schema, the batch key, the channel contract and the lock discipline. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Alon <alon@armosec.io>
A
Alon committed
6f5c8dd44d2c0d52889226d2e6281491b7a039a1
Parent: 8631fa1