Skip to content

docs: describe WFP denial capture - #1420

Open
Richie Gomez (richiemsft) wants to merge 10 commits into
richiemsft/wfp-learning-mode-integrationfrom
richiemsft/wfp-learning-mode-docs
Open

Richie Gomez (richiemsft) wants to merge 10 commits into
richiemsft/wfp-learning-mode-integrationfrom
richiemsft/wfp-learning-mode-docs

Conversation

@richiemsft

@richiemsft Richie Gomez (richiemsft) commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

📖 Description

Documents WFP denial capture, runtime compatibility probing, and the caller-facing network denial contract.

  • Distinguishes option-aware native network capture from legacy access-only capture.
  • Documents the exact public source, reason, direction, endpoint, and filterId representation.
  • Clarifies that Tessera is an internal component name and is not exposed in public JSON.
  • Records validated OS build points and guarded fallback behavior.

This is PR 4 of 4 in the WFP Learning Mode stack. Its base is the integration-layer branch.

🔗 References

Related to #1286.

Depends on the preceding integration PR in this stack.

🔍 Validation

  • git diff --check across the complete stack — passed.
  • Reviewed against the final API, decoder, and integration behavior.

✅ Checklist

📋 Issue Type

  • Bug fix
  • Feature
  • Task

🧱 Stack

  1. feat: prefer option-aware Learning Mode trace startup #1417 — API startup and compatibility
  2. feat: decode WFP Learning Mode network events #1418 — WFP event decoding
  3. fix: route captured network decisions through Tessera #1419 — ProcessContainer integration
  4. docs: describe WFP denial capture #1420 — Documentation

Review and merge in this order.

Microsoft Reviewers: Open in CodeFlow

@richiemsft
Richie Gomez (richiemsft) requested a review from a team as a code owner October 6, 2026 20:38
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

@MGudgin Gudge (MGudgin) left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Verified review notes

The updated guide correctly distinguishes options-capable native capture from legacy access-only capture and explains why guarded WPR excludes brokered WFP network records. The two inline comments identify a newly incorrect .NET API reference and the undocumented PSEC capture-mode capability exception. This is a comment-only review.

Finding outside the diff

Low (documentation consistency) — Update the README's native/fallback shorthand. README.md:265 — Attribution: newly_exposed_by_change. The README is byte-identical between this PR's base and head, so the earlier wording is not presented as code changed here. This PR's new host-selection guide recognizes compatible legacy-start PSEC hosts as native access-only captures; the README still describes 'complete PSEC/V2' native hosts versus 'older' guarded-WPR tiers, leaving readers of the two linked documents with conflicting classifications. Fix: Align the README's audit-mode summary with the new compatible-export rule and distinguish legacy native capture from guarded WPR.

Verified pre-existing — not attributed to this PR

README.md and docs/process-container/networking.md are both byte-identical from base to head. Their old wording is relevant only insofar as the new guide introduces a conflicting host-selection description or newly documents capture behavior without qualifying the existing capability matrix. No unrelated pre-existing issue is attributed to this documentation PR.

Comment thread docs/logging-access-denied.md Outdated
Comment thread docs/logging-access-denied.md
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch from 731c328 to cd9e80a Compare October 7, 2026 18:37
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-docs branch from 070db2c to 249d91b Compare October 7, 2026 18:37
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch 2 times, most recently from cd9e80a to 348dcc1 Compare October 7, 2026 18:45
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-docs branch from 249d91b to 131e258 Compare October 7, 2026 18:45
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch from 348dcc1 to cdbd9d6 Compare October 7, 2026 20:27
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-docs branch from 131e258 to 6c29917 Compare October 7, 2026 20:27
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch from cdbd9d6 to 82dce5d Compare October 7, 2026 20:37
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-docs branch from 6c29917 to fb62dab Compare October 7, 2026 20:37
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch from 82dce5d to 72c85b5 Compare October 7, 2026 22:36
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-docs branch from fb62dab to 6707972 Compare October 7, 2026 22:36
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch from 72c85b5 to 67e25e8 Compare October 8, 2026 17:29
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-docs branch 2 times, most recently from f0432aa to 92693ee Compare October 8, 2026 17:36
@richiemsft

Copy link
Copy Markdown
Contributor Author

Gudge (@MGudgin) The documentation findings are fixed in 92693ee: the V1 .NET type names are restored, and both the denial-capture guide and ProcessContainer networking matrix explain the narrowly scoped native PSEC capture capability exception. The docs are restacked on the implementation fix. Please re-review the updated tip.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Several documented compatibility, artifact-version, and incomplete-endpoint behaviors conflict with the implementation.

3 open findings
What changed in this PR

Documents WFP network-denial capture and its compatibility, output, and telemetry contracts.

Changes:

  • Describes option-aware versus legacy capture.
  • Documents network-denial records and verbose v5 diagnostics.
  • Records ProcessContainer networking and OS compatibility behavior.
File Description
docs/​logging-access-denied.md Expands denial-capture and artifact contracts.
docs/​development/​architecture/​telemetry.md Documents verbose telemetry projection.
docs/​backends/​process-container/​os-version-support.md Adds runtime compatibility guidance.
docs/​backends/​process-container/​networking.md Explains capture-only internetClient.

🧠 Review effort: Balanced


💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread docs/logging-access-denied.md
Comment thread docs/logging-access-denied.md Outdated
Comment thread docs/logging-access-denied.md Outdated
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-docs branch from 0ef5d02 to 0613f58 Compare October 8, 2026 19:26
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch from 7f147b9 to 6150aa6 Compare October 8, 2026 19:26
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch from 6150aa6 to 7bc39c7 Compare October 8, 2026 19:31
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-docs branch from 3ed4fdc to 60e59cb Compare October 8, 2026 19:32
@richiemsft
Richie Gomez (richiemsft) requested a balanced review from Copilot and removed request for Copilot October 8, 2026 19:33
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-integration branch from 7bc39c7 to 4ce4047 Compare October 10, 2026 00:03
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Document the source-compatible actionable record, first-observation deduplication, and redacted verbose-only WFP attribution.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Document verbose schema version 3 and require consumers to reject unsupported provider/reason vocabularies.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
@richiemsft
Richie Gomez (richiemsft) force-pushed the richiemsft/wfp-learning-mode-docs branch from 60e59cb to 9354f7e Compare October 10, 2026 00:04
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>

Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants