mirror of
https://github.com/NVIDIA/OpenShell.git
synced 2026-10-04 00:23:53 +08:00
Previously, Network Activity could be constructed without a source or destination endpoint, allowing connection, accept, relay, and configuration events to violate the OCSF 1.8 endpoint constraint. Now, NetworkActivityBuilder requires a source or destination endpoint at compile time. Connection failures identify the workload peer or genuine transparent destination, listener failures identify the listening endpoint, and mediation-lane failures use Application Lifecycle rather than fabricated network endpoints. Malformed forward requests use HTTP Activity with a method-only request, generated 400 response, and workload peer. Additionally, Unix relay-channel events use Base Event, policy-validation warnings use Config State Change, and the unused bypass monitor is removed because the current isolation architecture no longer uses it. Signed-off-by: Kris Hicks <khicks@nvidia.com>