Expand description
Linux metadata-only observation backend.
On Linux x86_64 the reference implementation uses ptrace and reads only selected metadata pointers. It never dereferences argv or envp.
M8 introduces an internal backend boundary before adding alternative collectors. The public observation semantics remain unchanged: ptrace is still the default backend and the correctness reference.
Structs§
- Backend
Descriptor - Machine-readable identity and capability declaration for one backend.
- Backend
Observation - Internal collection result. The legacy public observer functions continue
returning
Observation; M8.3 uses this envelope at the backend boundary so collection health cannot be confused with absence of drift. - Command
Spec - Observe
Options
Enums§
- Collection
Completeness - Explicit health state at the backend-to-core handoff.
- Observation
Capability - Typed observation capability vocabulary introduced by M8.3.
- Observe
Error
Constants§
Functions§
- experimental_
ebpf_ backend_ descriptor - Descriptor for the selected M8.3 libbpf-rs path before product integration.
- observe_
command - observe_
command_ with_ options - reference_
backend_ descriptor