Skip to content

go: expose process_vm_access events and statistics - #429

Draft
Aegrah wants to merge 3 commits into
process-vm-access-publicfrom
process-vm-access-go
Draft

Aegrah wants to merge 3 commits into
process-vm-access-publicfrom
process-vm-access-go

Conversation

@Aegrah

@Aegrah Aegrah commented Sep 16, 2026

Copy link
Copy Markdown

Part 3 of 3, bottom-up: private probespublic event and testsGo bindings.

Summary

Expose process_vm_access records, queue/event flags, snapshot statuses and correlation-map failure statistics in Go. Preserve signed syscall returns and validity fields so consumers can distinguish unresolved identity and incomplete snapshots.

Issue: https://github.com/elastic/endpoint-dev/issues/21204

Validation

Preflight: 20260916-pva-v2-release-final. Fleet acceptance: 20260916T172021Z-process-vm-access, accepted build endpoint-9.4.2-5564d77d41a8132d (Stack/Agent/Endpoint 9.4.2). Main integration was validated separately. Full persona-volume gate explicitly waived by the user; no production-volume claim.

Go tests pass on x64 and ARM64. Sensor validation belongs to the preceding two layers; no additional kernel hook is introduced here.

Companions: elastic/endpoint-package#800 · https://github.com/elastic/endpoint-dev/pull/22027

@Aegrah

Aegrah commented Sep 16, 2026

Copy link
Copy Markdown
Author

Merge-forward of the #428 valgrind fix-up (7a5bdd7); no change of its own.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant