Repository navigation
docs: describe WFP denial capture - #1420
Richie Gomez (richiemsft) wants to merge 10 commits into
Conversation
|
Azure Pipelines: There may be pipelines that require an authorized user to comment /azp run to run. |
33bf935 to
731c328
Compare
2c92515 to
070db2c
Compare
Gudge (MGudgin)
left a comment
There was a problem hiding this comment.
Verified review notes
The updated guide correctly distinguishes options-capable native capture from legacy access-only capture and explains why guarded WPR excludes brokered WFP network records. The two inline comments identify a newly incorrect .NET API reference and the undocumented PSEC capture-mode capability exception. This is a comment-only review.
Finding outside the diff
Low (documentation consistency) — Update the README's native/fallback shorthand. README.md:265 — Attribution: newly_exposed_by_change. The README is byte-identical between this PR's base and head, so the earlier wording is not presented as code changed here. This PR's new host-selection guide recognizes compatible legacy-start PSEC hosts as native access-only captures; the README still describes 'complete PSEC/V2' native hosts versus 'older' guarded-WPR tiers, leaving readers of the two linked documents with conflicting classifications. Fix: Align the README's audit-mode summary with the new compatible-export rule and distinguish legacy native capture from guarded WPR.
Verified pre-existing — not attributed to this PR
README.md and docs/process-container/networking.md are both byte-identical from base to head. Their old wording is relevant only insofar as the new guide introduces a conflicting host-selection description or newly documents capture behavior without qualifying the existing capability matrix. No unrelated pre-existing issue is attributed to this documentation PR.
731c328 to
cd9e80a
Compare
070db2c to
249d91b
Compare
cd9e80a to
348dcc1
Compare
249d91b to
131e258
Compare
348dcc1 to
cdbd9d6
Compare
131e258 to
6c29917
Compare
cdbd9d6 to
82dce5d
Compare
6c29917 to
fb62dab
Compare
82dce5d to
72c85b5
Compare
fb62dab to
6707972
Compare
72c85b5 to
67e25e8
Compare
f0432aa to
92693ee
Compare
|
Gudge (@MGudgin) The documentation findings are fixed in 92693ee: the V1 .NET type names are restored, and both the denial-capture guide and ProcessContainer networking matrix explain the narrowly scoped native PSEC capture capability exception. The docs are restacked on the implementation fix. Please re-review the updated tip. |
a01d125 to
7f147b9
Compare
92693ee to
0ef5d02
Compare
There was a problem hiding this comment.
🟡 Changes recommended
Several documented compatibility, artifact-version, and incomplete-endpoint behaviors conflict with the implementation.
3 open findings
What changed in this PR
Documents WFP network-denial capture and its compatibility, output, and telemetry contracts.
Changes:
- Describes option-aware versus legacy capture.
- Documents network-denial records and verbose v5 diagnostics.
- Records ProcessContainer networking and OS compatibility behavior.
| File | Description |
|---|---|
docs/logging-access-denied.md |
Expands denial-capture and artifact contracts. |
docs/development/architecture/telemetry.md |
Documents verbose telemetry projection. |
docs/backends/process-container/os-version-support.md |
Adds runtime compatibility guidance. |
docs/backends/process-container/networking.md |
Explains capture-only internetClient. |
🧠 Review effort: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
0ef5d02 to
0613f58
Compare
7f147b9 to
6150aa6
Compare
6150aa6 to
7bc39c7
Compare
3ed4fdc to
60e59cb
Compare
7bc39c7 to
4ce4047
Compare
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Document the source-compatible actionable record, first-observation deduplication, and redacted verbose-only WFP attribution. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Document verbose schema version 3 and require consumers to reject unsupported provider/reason vocabularies. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f
60e59cb to
9354f7e
Compare
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: e408b60b-e267-416c-806d-0a7e119fe53f

📖 Description
Documents WFP denial capture, runtime compatibility probing, and the caller-facing network denial contract.
filterIdrepresentation.This is PR 4 of 4 in the WFP Learning Mode stack. Its base is the integration-layer branch.
🔗 References
Related to #1286.
Depends on the preceding integration PR in this stack.
🔍 Validation
git diff --checkacross the complete stack — passed.✅ Checklist
Cargo.lock, thedependency-feed-checkcheck passes (not applicable)📋 Issue Type
🧱 Stack
Review and merge in this order.
Microsoft Reviewers: Open in CodeFlow