| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
feat: add plugin-driven file security alerts - persist plugin alerts asynchronously and evaluate file leakage after trace completion - expose plugin lifecycle, commands, grants, and schema-backed configuration through daemon and web APIs - enforce dynamic file policies and report denied file access with low-overhead audit integration - add live alert views and responsive plugin management interfaces - package file security plugins and document end-to-end build, deployment, and verification | 10 天前 | |
feat: add plugin-driven file security alerts - persist plugin alerts asynchronously and evaluate file leakage after trace completion - expose plugin lifecycle, commands, grants, and schema-backed configuration through daemon and web APIs - enforce dynamic file policies and report denied file access with low-overhead audit integration - add live alert views and responsive plugin management interfaces - package file security plugins and document end-to-end build, deployment, and verification | 10 天前 | |
feat(file-io): export bounded terminal actions with observable delivery Co-Authored-By: gpt-5.6-sol | 3 天前 | |
Capture live OTEL spans and TLS payloads Add AcTrail runtime, storage, viewer, and example workflows for live observation. Document operation paths and clean up obsolete fork tracepoints. | 2 个月前 | |
Fix launch compatibility and TLS sync layering - Treat legacy open and creat tracepoints as platform-optional so kernels without those syscall tracepoint ids can still launch while keeping openat required for filesystem access observation. - Keep LD_AUDIT as the default dynamic-link TLS collection path and isolate audit namespace initialization from executable inline hook installation. Allow dynamic library binding and supplemental executable hooks to coexist while skipping duplicate AcTrail inline patches across SSL and rustls paths. - Remove default agent prewarm hints to avoid launch-time binary scans. Report per-artifact and total freed sizes from actrailctl clean. - Fix fork tracepoint child pid offset Co-Authored-By: GPT-5.5 | 1 个月前 | |
Unify process identity and harden launch readiness - Unify logical process identity across collector ingestion, trace membership, storage, export, semantic lineage, and process-tree reconciliation. - Keep lifecycle collection free of exec-time procfs enrichment and preserve namespace-native TLS identity observations. - Refactor process and real-agent E2E helpers around logical identities, action snapshots, and concurrent launch sessions. - Add a daemon control-plane TLS launch-plan query and cache, with ctl diagnostics and timing, so repeated launches avoid local rescans. - Add per-profile daemon startup host-eBPF load preflight and use verified readiness for launch permission selection. - Bound direct socket payload capture for verifier-safe eBPF loading and retain staged preflight verification. Co-Authored-By: GPT-5.5 | 20 天前 | |
Capture live OTEL spans and TLS payloads Add AcTrail runtime, storage, viewer, and example workflows for live observation. Document operation paths and clean up obsolete fork tracepoints. | 2 个月前 | |
Capture live OTEL spans and TLS payloads Add AcTrail runtime, storage, viewer, and example workflows for live observation. Document operation paths and clean up obsolete fork tracepoints. | 2 个月前 | |
Fix launch compatibility and TLS sync layering - Treat legacy open and creat tracepoints as platform-optional so kernels without those syscall tracepoint ids can still launch while keeping openat required for filesystem access observation. - Keep LD_AUDIT as the default dynamic-link TLS collection path and isolate audit namespace initialization from executable inline hook installation. Allow dynamic library binding and supplemental executable hooks to coexist while skipping duplicate AcTrail inline patches across SSL and rustls paths. - Remove default agent prewarm hints to avoid launch-time binary scans. Report per-artifact and total freed sizes from actrailctl clean. - Fix fork tracepoint child pid offset Co-Authored-By: GPT-5.5 | 1 个月前 | |
Unify process identity and harden launch readiness - Unify logical process identity across collector ingestion, trace membership, storage, export, semantic lineage, and process-tree reconciliation. - Keep lifecycle collection free of exec-time procfs enrichment and preserve namespace-native TLS identity observations. - Refactor process and real-agent E2E helpers around logical identities, action snapshots, and concurrent launch sessions. - Add a daemon control-plane TLS launch-plan query and cache, with ctl diagnostics and timing, so repeated launches avoid local rescans. - Add per-profile daemon startup host-eBPF load preflight and use verified readiness for launch permission selection. - Bound direct socket payload capture for verifier-safe eBPF loading and retain staged preflight verification. Co-Authored-By: GPT-5.5 | 20 天前 | |
feat(otel-jsonl): add plugin-owned action filtering - move OTEL JSONL export lifecycle behind the dynamically loaded builtin plugin - require schema-backed action kind selection and filter before route publication - preserve upstream TTY exclusion while exposing supported kinds as Web checkboxes - align deployment assets, examples, operator configs, and lifecycle documentation - add real-agent filtering regressions and consolidate the v2 regression layout - capture distinct OpenSSL read entries Co-Authored-By: gpt-5.6-sol | 4 天前 | |
Capture live OTEL spans and TLS payloads Add AcTrail runtime, storage, viewer, and example workflows for live observation. Document operation paths and clean up obsolete fork tracepoints. | 2 个月前 |
| 文件 | 最后提交记录 | 最后更新时间 |
|---|---|---|
| 10 天前 | ||
| 10 天前 | ||
| 3 天前 | ||
| 2 个月前 | ||
| 1 个月前 | ||
| 20 天前 | ||
| 2 个月前 | ||
| 2 个月前 | ||
| 1 个月前 | ||
| 20 天前 | ||
| 4 天前 | ||
| 2 个月前 |