You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Scope verbose diagnostics to Learning Mode events - #1396
Retains sanitized verbose diagnostics for all resource types within known Learning Mode events. Filters by provider and event ID, records decoding failures, and caches unavailable manifest schemas within the existing limit.
Tests
Ran 224 Windows decoder tests and Clippy locally; all passed. Replayed 48 native and controlled traces, verifying unchanged actionable JSON and preservation of selected event properties and counts.
The reason will be displayed to describe this comment to others. Learn more.
Warning
Copilot couldn't run its full agentic review because it didn't start before the timeout. Make sure your repository has a runner available, or add a copilot-code-review.yml file specifying one with the runs-on attribute. See the docs for more details.
This PR updates Learning Mode verbose logging so unfamiliar ETW providers/event IDs are retained as bounded, sanitized diagnostics (with explicit failure reasons), and adjusts guarded relogging + telemetry projection accordingly.
Changes:
Preserve unknown providers/events in verbose logs (including schema event names when available) and record closed diagnostic reasons on decode failures instead of aborting analysis.
Update guarded relogging + analysis to handle relogger transport headers and keep all in-scope provider events.
Bump verbose logging document schema to v3 and update tests/docs to match.
Records diagnostics for unknown/malformed events, adds relogged-trace analysis path, and treats schema failures as non-fatal (with incompleteness marking).
Sanitizing the schema name in isolation loses the payload's identity-redaction context. For a TraceLogging event named jsmith with UserName=jsmith, the payload username is redacted but signature.eventName retains it; username components in named-object schema names have the same problem. Sanitize successful schema names using the raw payload's identity candidates before bounding or hashing, while keeping schema metadata separate from any payload field named EventName. Add regression tests for both forms.
Require an allowlisted, process-scoped Learning Mode event at each
selected relog ordinal, and keep a missing NetworkDecisionV1 schema from
marking actionable results incomplete.
Copilot-Session: ca558f28-d3df-4b85-9e44-b9fddef77c62
The reason will be displayed to describe this comment to others. Learn more.
Summary
Reviewed PR #1396 at ca4e222 against 43c5da4 (13 files, +1399/-329). I request changes primarily because the changed guarded relog ordinal invariant has no committed nonempty-selection regression test, and because the new negative schema cache retains TDH failures that need not mean a manifest is unavailable. The other comments identify conditional performance, documentation, and test-design issues; Low items are non-blocking. No ordinal mismatch or transient TDH failure was reproduced.
Verified clean, with receipts:is_learning_mode_event accepts only the explicit provider/event-ID pairs (extractors.rs:218-235); verbose telemetry clears eventName and properties before emission (verbose_telemetry.rs:148-156); relogging rejects count and selected-PID mismatches (etl_filter.rs:93-112,323-333). The new private-session round trip emits only an unrelated provider, so its selected set is empty (etl_filter.rs:371-527); the guarded telemetry e2e is #[ignore] (wxc_e2e_tests_e2e_telemetry_etw.rs:441-443). Existing isolated selection tests do not replace a nonempty round trip.
Findings outside the diff
Low — telemetry projection documentation:docs/development/architecture/telemetry.md:204-206 is byte-identical between base and head. The new eventName removal and group merge in the changed verbose_telemetry.rs:148-163 newly expose the incomplete description. This is anchored on the added projection line and is not a pre-existing defect being charged to the PR.
Verified pre-existing — not attributed to this PR
No unchanged, unrelated defect is filed. The 4,096-entry cache limit and one-million-event global processing bound already existed; comments concern only the PR's newly stored negative entries. A provisional finding that an unscoped capability schema error can set truncated before identifying a PID was withdrawn: unknown PID deliberately fails closed. Another provisional suggestion to exempt NetworkDecision events from the global processing bound was withdrawn because that bound is intentional and no safe exception was established.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Needs-AttentionRequires attention or a decision from the MXC maintainers.Needs-Author-FeedbackWaiting for additional information or action from the issue or pull-request author.
4 participants
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Retains sanitized verbose diagnostics for all resource types within known Learning Mode events. Filters by provider and event ID, records decoding failures, and caches unavailable manifest schemas within the existing limit.
Tests
Ran 224 Windows decoder tests and Clippy locally; all passed. Replayed 48 native and controlled traces, verifying unchanged actionable JSON and preservation of selected event properties and counts.
Microsoft Reviewers: Open in CodeFlow