Skip to content

Add COM diagnostics and retain unrecognized Learning Mode events - #1386

Closed
Jacob Dereje (jacobdereje-msft) wants to merge 4 commits into
microsoft:mainfrom
jacobdereje-msft:jacob/64373507-verbose-events
Closed

Jacob Dereje (jacobdereje-msft) wants to merge 4 commits into
microsoft:mainfrom
jacobdereje-msft:jacob/64373507-verbose-events

Conversation

@jacobdereje-msft

@jacobdereje-msft Jacob Dereje (jacobdereje-msft) commented Oct 4, 2026 •

Copy link
Copy Markdown

Adds diagnostic labels for COM activation and interface calls. Retains unfamiliar providers and event IDs in verbose logs, extracting their properties where possible and recording a diagnostic reason when parsing fails.

Tests

Ran 219 decoder tests and Clippy locally; all passed. Validated native block/allow capture, COM events, deduplication, timeout, ETL retention and telemetry consent. Processing the same real traces before and after produced identical actionable JSON.

Microsoft Reviewers: Open in CodeFlow

Copilot AI balanced review requested due to automatic review settings October 4, 2026 22:27
Co-authored-by: Richie Gomez (he/him) <saulg@microsoft.com>
Copilot-Session: 7758b99e-b7a0-4060-baf9-268db306b58b

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Newly retained composite property values can expose private file paths in local verbose artifacts.

Review effort: Balanced
Findings: 1 High severity

Open (1)
What changed in this PR

Expands Learning Mode diagnostics with COM-specific outcomes and retention of unfamiliar events, while keeping actionable denial extraction limited to known schemas.

Changes:

  • Adds version-3 verbose diagnostics and nonfatal schema-failure reporting.
  • Broadens process-scoped ETL retention and deduplicates sanitized telemetry.
  • Adds decoder, relogging, and telemetry regression coverage.
File Description
src/​testing/​wxc_e2e_tests/​tests/​e2e_telemetry_etw.rs Updates fixtures and version expectations.
src/​host/​plm/​src/​elevated.rs Uses relogged-trace analysis.
src/​core/​mxc_engine/​src/​verbose_telemetry.rs Deduplicates signatures after removing sensitive properties.
src/​core/​learning_mode_platforms/​windows/​src/​tdh_decode.rs Adds schema-cache test support.
src/​core/​learning_mode_platforms/​windows/​src/​extractors.rs Classifies COM events and expands path detection.
src/​core/​learning_mode_platforms/​windows/​src/​etl_filter.rs Retains unfamiliar process-scoped events.
src/​core/​learning_mode_platforms/​windows/​src/​etl_decode.rs Records unfamiliar events and decode failures.
src/​core/​learning_mode_platforms/​windows/​Cargo.toml Adds temporary-file test dependency.
src/​core/​learning_mode_core/​src/​verbose_logging.rs Introduces version-3 providers and reasons.
src/​Cargo.lock Records the test dependency.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/core/learning_mode_platforms/windows/src/etl_decode.rs
Copilot AI balanced review requested due to automatic review settings October 4, 2026 22:31

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Command-line properties can expose private paths, and supported-schema failures can leave incomplete analysis marked complete.

Review effort: Balanced
Findings: 3 High severity

Open (3)

Comment thread src/core/learning_mode_platforms/windows/src/etl_decode.rs
Comment thread src/core/learning_mode_platforms/windows/src/extractors.rs
Copilot AI balanced review requested due to automatic review settings October 5, 2026 04:48

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Privileged trace-scoping changes need human validation, and supported-event schema failures can produce apparently complete but incomplete learned policies.

Review effort: Balanced
Findings: 2 High severity

Open (2)
Resolved since last review (2)

Comment thread src/core/learning_mode_platforms/windows/src/etl_decode.rs
Copilot AI balanced review requested due to automatic review settings October 5, 2026 05:12
Copilot-Session: 7758b99e-b7a0-4060-baf9-268db306b58b

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Brokered schema failures can silently omit capability denials while reporting complete analysis, allowing incomplete adjusted policies.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
Resolved since last review (2)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Mark brokered events incomplete when schema lookup blocks PID recovery

src/​core/​learning_mode_platforms/​windows/​src/​etl_decode.rs:991

When a supported brokered Event 28 has no resolvable schema, its payload ProcessId cannot be recovered. If the broker's header PID is outside the sandbox lifetimes, this fallback silently drops the event. Subsequent analysis cannot detect the loss and can report deniedResourcesTruncated=false, allowing an incomplete adjusted policy. Keep schema failures fatal during brokered-event scoping, without retaining unscoped host events. Update relog_selection_skips_unattributable_capability_schema_failure to expect the failure.

Comment thread src/core/learning_mode_platforms/windows/src/etl_decode.rs
Copilot AI balanced review requested due to automatic review settings October 5, 2026 05:18

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Brokered schema failures can silently omit capability denials while guarded analysis reports complete results.

Review effort: Balanced
Findings: 1 Medium severity · 1 Low severity

Open (2)
Resolved since last review (1)

Comment thread src/core/learning_mode_platforms/windows/src/etl_decode.rs
Comment thread src/core/learning_mode_core/src/verbose_logging.rs
Copilot-Session: 7758b99e-b7a0-4060-baf9-268db306b58b
Copilot AI balanced review requested due to automatic review settings October 5, 2026 05:45

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Unresolved redaction and event-identity issues need correction, and privacy-sensitive privileged trace filtering warrants final human review.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
Resolved since last review (1)
Previously missed (1)

In code that hasn't changed since last review

Medium severity Preserve TraceLogging schema names in diagnostic signatures

src/​core/​learning_mode_platforms/​windows/​src/​etl_decode.rs:1059

TraceLogging events commonly share event ID 0 and are distinguished by schema-declared names. decode_event_parts reads that name but retains it only on failure. Two successfully decoded, differently named events from the same provider and PID with identical properties therefore collapse into one signature here, losing their identities and combining their counts. Carry the schema name into successful diagnostic signatures as sanitized metadata, keeping it distinct from payload fields, and test two differently named events with identical payloads. Telemetry can continue stripping this metadata.

Comment thread src/core/learning_mode_platforms/windows/src/etl_decode.rs
Copilot-Session: 7758b99e-b7a0-4060-baf9-268db306b58b
Copilot AI balanced review requested due to automatic review settings October 5, 2026 06:48

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🔵 Needs a closer look

Broader privileged trace retention and changed decoding and privacy behavior warrant Windows-focused human review of the reported native validation.

Review effort: Balanced
Findings: None

Resolved since last review (2)

@richiemsft

Copy link
Copy Markdown
Contributor

Can you split this PR into:

  1. Add COM diagnostics
  2. retain unrecognized Learning Mode Events

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants