You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Adds diagnostic labels for COM activation and interface calls, retaining the CLSID/IID in verbose logs. ## Tests Ran 214 decoder tests and Clippy locally; all passed. Replayed real VM COM traces and verified activation and interface-call diagnostics. Processing the same traces before and after produced identical actionable JSON. ###### Microsoft Reviewers: Open in CodeFlow
The reason will be displayed to describe this comment to others. Learn more.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
Adds COM-specific verbose diagnostics to Windows Learning Mode decoding and telemetry projection, including distinct outcome reasons for COM activation and COM interface calls, while bumping the verbose document schema version.
Changes:
Introduces ComActivation / ComInterfaceCall verbose outcome reasons and bumps verbose schema version to 3.
Recognizes COM access-check object types as verbose-only outcomes and validates CLSID/IID is GUID-shaped.
Updates tests and documentation to cover COM diagnostics and the version bump.
The access-check documentation above this function is now inaccurate: it says all other object types are dropped until their access-mask vocabulary is understood, but these COM object types are retained as verbose-only outcomes and intentionally have no access classification. Please document the COM exception and its ComActivation/ComInterfaceCall outcomes so the extractor contract matches this branch.
The reason will be displayed to describe this comment to others. Learn more.
Summary
Reviewed PR #1395 at 559fdc5 against its PR base 63b71a3 (6 changed files, +307/-6). I request changes primarily to make the new COM diagnostic reason contract unambiguous and to exercise the privacy-provider path that the new "both modes" test does not cover. The mixed-version guardian issue is conditional: please confirm the supported deployment/update model and either handle v2 artifacts or enforce/document matched binaries. The documentation's "denied" wording is a claim mismatch, not a merge condition by itself. Low-priority test and API-documentation suggestions below are non-blocking.
Verified clean: Valid COM access checks still return non-actionable outcomes rather than actionable policy denials; telemetry projection removes signature properties before emission, including CLSID/IID values. The decoder test count increases from 48 to 50; the new COM integration tests use kernel_event rather than the existing permissive_event helper.
Findings outside the diff / claim-only findings
No finding requires an out-of-diff anchor. The misleading "denied" claim is on the newly added documentation line and is commented there as claim_mismatch; it is not independently blocking.
Verified pre-existing — not attributed to this PR
No pre-existing issue is being charged to this PR. guarded_capture.rs is byte-identical between base and head; the telemetry reader's exact-version check also predates the PR. Both are cited only because the new v2-to-v3 version change makes their combination relevant to a possible mixed-version deployment.
Malformed COM identifiers are still passed through the generic property sanitizer when this error is recorded. That sanitizer only redacts recognized paths/usernames, so an invalid ObjectName such as an arbitrary token or email address is persisted verbatim even though only a validated CLSID/IID is safe to retain. Please drop or redact ObjectName for this malformed-COM path before recording the verbose signature.
Correction to my Changes Requested review (5446248759): I withdraw the Medium finding about a v2 verbose artifact from an older co-located guardian (comment 4210188524). This was my incorrect assumption about artifact ownership.
In guarded capture, plm/elevated.rs:2154-2168 sends an AnalysisResult over the pipe, not a verbose document. The SDK's capture_output.rs:70-79 builds and writes the actionable and verbose siblings from that result using its own VerboseLoggingDocument::VERSION; the telemetry reader runs in that same SDK. An older signed guardian therefore cannot produce the alleged v2 artifact for a newer SDK reader through this path. Please disregard this finding as a merge condition.
This correction applies only to the version-compatibility finding. I am verifying the disposition of the other six comments against the updated head.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds diagnostic labels for COM activation and interface calls, retaining the CLSID/IID in verbose logs. ## Tests Ran 214 decoder tests and Clippy locally; all passed. Replayed real VM COM traces and verified activation and interface-call diagnostics. Processing the same traces before and after produced identical actionable JSON. ###### Microsoft Reviewers: Open in CodeFlow