SIGN IN SIGN UP

fix(networkstream): address code review (SUB-7786)

Derive the wire copy BEFORE handing the snapshot to the notification channel.
Both were already outside the lock and buildWireStream is read-only, so this was
not live -- but the ordering made the producer re-read maps the consumer already
owned, resting on an out-of-repo guarantee that the consumer never writes to what
it receives. Reversing the two lines removes the dependency entirely.

capTreeCopy now copies the ProcessTree wrapper wholesale instead of field-listing
it, so a field added to the wrapper later cannot be silently dropped -- the exact
trap the three existing process copiers fell into. It also no longer assumes the
inner copy is non-nil.

Tests: two of the claims were not actually pinned. TestNoTickScaling asserted only
that buildWireStream does not rewrite an already-correct literal, so it passed
with a /10_000_000 injected into processRefFor, where such a bug would live; it
now runs the whole producer path. The shutdown-honouring select added in ad55206c
was covered by nothing -- every channel test buffers so the producer never blocks
-- so a plain blocking send passed the suite; TestFlush_BlockedChannelSendHonoursShutdown enters the blocked path and fails against that mutation. Also replaced a
fixed sleep with a poll on an observable signal, and covered the unattributed DNS
key and the nil-manager branch.

Docs: the key-collision claim was categorical but holds only for the structured
IP form, not for unstructured DNS names; and the lock-discipline table described
the flush while omitting that handleNetworkEvent holds the same mutex across an
unbounded net.LookupAddr (pre-existing, untouched here).

Dropped the two stale armoapi-go v0.0.696 go.sum lines.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Alon <alon@armosec.io>
A
Alon committed
dee5d909c57f0a6b7f06206ae95c11b665744a12
Parent: 0b30903