SIGN IN SIGN UP

refactor(networkstream): independent flush snapshot; channel keeps trees, sleep removed (SUB-7786)

The flush handed the notification channel the LIVE storage struct, then -- still
holding eventsStorageMutex -- slept 100 ms and stripped every process tree from
the maps the consumer was reading. private-node-agent's host network sensor
reads outbound.ProcessTree off that channel, so the sleep was the only thing
standing between it and having its data erased mid-read. A test proved worse: an
event recorded 300 ms AFTER the flush appeared in the already-delivered
snapshot, because the clear loop and the consumer shared the same maps.

snapshotNetworkStream now allocates its own event maps, so the consumer's view
is immune to everything the producer does next. Trees are shared by pointer, not
walked: a tree is immutable once attached, which keeps the lock body to
O(entities + connections) struct copies. Both sends move outside the lock, and
the 100 ms sleep is deleted rather than shortened -- there is no shared state
left to race on. removeProcessTreeFromEvents goes with it; the wire copy is
where trees leave the payload from here.

Adds docs/features/network-stream-process-attribution.md, covering the emitted
schema, the batch key, the channel contract and the lock discipline.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Alon <alon@armosec.io>
A
Alon committed
6f5c8dd44d2c0d52889226d2e6281491b7a039a1
Parent: 8631fa1