fix(networkstream): address code review (SUB-7786)
Derive the wire copy BEFORE handing the snapshot to the notification channel. Both were already outside the lock and buildWireStream is read-only, so this was not live -- but the ordering made the producer re-read maps the consumer already owned, resting on an out-of-repo guarantee that the consumer never writes to what it receives. Reversing the two lines removes the dependency entirely. capTreeCopy now copies the ProcessTree wrapper wholesale instead of field-listing it, so a field added to the wrapper later cannot be silently dropped -- the exact trap the three existing process copiers fell into. It also no longer assumes the inner copy is non-nil. Tests: two of the claims were not actually pinned. TestNoTickScaling asserted only that buildWireStream does not rewrite an already-correct literal, so it passed with a /10_000_000 injected into processRefFor, where such a bug would live; it now runs the whole producer path. The shutdown-honouring select added in ad55206c was covered by nothing -- every channel test buffers so the producer never blocks -- so a plain blocking send passed the suite; TestFlush_BlockedChannelSendHonoursShutdown enters the blocked path and fails against that mutation. Also replaced a fixed sleep with a poll on an observable signal, and covered the unattributed DNS key and the nil-manager branch. Docs: the key-collision claim was categorical but holds only for the structured IP form, not for unstructured DNS names; and the lock-discipline table described the flush while omitting that handleNetworkEvent holds the same mutex across an unbounded net.LookupAddr (pre-existing, untouched here). Dropped the two stale armoapi-go v0.0.696 go.sum lines. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Signed-off-by: Alon <alon@armosec.io>
A
Alon committed
dee5d909c57f0a6b7f06206ae95c11b665744a12
Parent: 0b30903