Skip to main content

Crate execsurface_observe

Crate execsurface_observe 

Source
Expand description

Linux metadata-only observation backend.

On Linux x86_64 the reference implementation uses ptrace and reads only selected metadata pointers. It never dereferences argv or envp.

M8 introduces an internal backend boundary before adding alternative collectors. The public observation semantics remain unchanged: ptrace is still the default backend and the correctness reference.

Structs§

BackendDescriptor
Machine-readable identity and capability declaration for one backend.
BackendObservation
Internal collection result. The legacy public observer functions continue returning Observation; M8.3 uses this envelope at the backend boundary so collection health cannot be confused with absence of drift.
CommandSpec
ObserveOptions

Enums§

CollectionCompleteness
Explicit health state at the backend-to-core handoff.
ObservationCapability
Typed observation capability vocabulary introduced by M8.3.
ObserveError

Constants§

ALL_OBSERVATION_CAPABILITIES
DEFAULT_EVENT_LIMIT

Functions§

experimental_ebpf_backend_descriptor
Descriptor for the selected M8.3 libbpf-rs path before product integration.
observe_command
observe_command_with_options
reference_backend_descriptor