Skip to content

Land the live Linux eBPF capture daemon + emit the observability-gap metric #39

Description

@gnanirahulnutakki

eBPF capture is currently scaffold for live enforcement (privileged daemon Executed=false; real C + correlator + smoke tests; cross-compiles for linux but cannot attach on macOS).

Action: implement the live Linux daemon path and emit a measured observability-gap metric (fraction of effects below the tool-call boundary).

BRIDGE: this is also the instrument for the lead research paper — cross-link ardur-vault paper-track/P2.

Acceptance: daemon attaches on Linux CI and emits the metric on a real workload.

Size: L


From the Ardur dual-track Master Plan (Track A). Verified locally 2026-06-23.

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions