|
| 1 | +# SOW-0027 - Netdata Vendor Memory-Safety Update |
| 2 | + |
| 3 | +## Status |
| 4 | + |
| 5 | +Status: open |
| 6 | + |
| 7 | +Sub-state: not started; tracks propagation of SOW-0026 source fixes to the Netdata vendored copy. |
| 8 | + |
| 9 | +## Requirements |
| 10 | + |
| 11 | +### Purpose |
| 12 | + |
| 13 | +Keep NetIPC memory-safety fixes source-owned in `plugin-ipc` while ensuring the Netdata vendored copy receives those fixes through the normal vendor/update path. |
| 14 | + |
| 15 | +### User Request |
| 16 | + |
| 17 | +The user asked to fix NetIPC library issues in `plugin-ipc`, not directly in the Netdata PR, because this repository is the source of truth. |
| 18 | + |
| 19 | +### Assistant Understanding |
| 20 | + |
| 21 | +Facts: |
| 22 | + |
| 23 | +- SOW-0026 implements source fixes for NetIPC memory-safety scout findings in `plugin-ipc`. |
| 24 | +- Netdata consumes NetIPC through a vendored copy. |
| 25 | +- Directly patching Netdata's vendored NetIPC copy would create source-of-truth drift. |
| 26 | + |
| 27 | +Inferences: |
| 28 | + |
| 29 | +- After SOW-0026 lands, the next safe step is a focused vendor/update pass against the relevant Netdata checkout. |
| 30 | + |
| 31 | +Unknowns: |
| 32 | + |
| 33 | +- The exact Netdata checkout, branch, and PR target for propagation must be confirmed before implementation starts. |
| 34 | + |
| 35 | +### Acceptance Criteria |
| 36 | + |
| 37 | +- The selected Netdata checkout is confirmed before implementation. |
| 38 | +- The vendored NetIPC copy is updated from `plugin-ipc` rather than manually patched. |
| 39 | +- The project-local vendor diff/checker is run and its result is recorded. |
| 40 | +- Netdata build or targeted tests covering the touched NetIPC integration paths are run or a blocker is recorded with evidence. |
| 41 | +- No unrelated Netdata changes are included. |
| 42 | + |
| 43 | +## Analysis |
| 44 | + |
| 45 | +Sources checked: |
| 46 | + |
| 47 | +- SOW-0026 source-ownership decision. |
| 48 | +- `docs/netipc-integrator-skill.md` source-of-truth guidance. |
| 49 | +- Prior vendor synchronization SOWs in `.agents/sow/done/`. |
| 50 | + |
| 51 | +Current state: |
| 52 | + |
| 53 | +- Source fixes are expected to land in `plugin-ipc` through SOW-0026 first. |
| 54 | +- No Netdata checkout has been selected for this SOW yet. |
| 55 | + |
| 56 | +Risks: |
| 57 | + |
| 58 | +- Copying files manually can introduce import-path or layout mistakes. |
| 59 | +- Updating the wrong Netdata checkout can create unrelated branch drift. |
| 60 | +- Skipping the vendor diff can hide missing language-specific updates. |
| 61 | + |
| 62 | +## Pre-Implementation Gate |
| 63 | + |
| 64 | +Status: needs-user-decision |
| 65 | + |
| 66 | +Problem / root-cause model: |
| 67 | + |
| 68 | +- NetIPC fixes must be propagated to the downstream Netdata vendored copy, but that work belongs in a separate focused pass after the source repository is committed and pushed. |
| 69 | + |
| 70 | +Evidence reviewed: |
| 71 | + |
| 72 | +- SOW-0026 records that NetIPC source ownership belongs to `plugin-ipc`. |
| 73 | +- Historical vendor-sync SOWs use the project-local `diff-netdata-vendor.sh` checker. |
| 74 | + |
| 75 | +Affected contracts and surfaces: |
| 76 | + |
| 77 | +- Netdata vendored C, Rust, and Go NetIPC sources. |
| 78 | +- Netdata build/test paths that consume NetIPC. |
| 79 | +- Vendor synchronization evidence in this SOW. |
| 80 | + |
| 81 | +Existing patterns to reuse: |
| 82 | + |
| 83 | +- `diff-netdata-vendor.sh` |
| 84 | +- Prior SOW-0003 and SOW-0008 vendor synchronization flow. |
| 85 | + |
| 86 | +Risk and blast radius: |
| 87 | + |
| 88 | +- Medium: changes land in a consumer repository and may affect Netdata build/test behavior. |
| 89 | +- Keep scope limited to NetIPC vendor propagation and required validation. |
| 90 | + |
| 91 | +Sensitive data handling plan: |
| 92 | + |
| 93 | +- No secrets, customer data, credentials, production logs, or private endpoints are required. |
| 94 | +- Evidence will use source paths, commands, commit hashes, and sanitized summaries only. |
| 95 | + |
| 96 | +Implementation plan: |
| 97 | + |
| 98 | +1. Confirm the target Netdata checkout and branch. |
| 99 | +2. Propagate the committed `plugin-ipc` source changes through the normal vendor/update path. |
| 100 | +3. Run the vendor diff/checker and targeted Netdata validation. |
| 101 | +4. Commit only the vendor update and required tracking artifacts. |
| 102 | + |
| 103 | +Validation plan: |
| 104 | + |
| 105 | +- Run the vendor diff/checker against the selected Netdata checkout. |
| 106 | +- Run targeted Netdata build/tests for touched C/Rust/Go NetIPC integration paths. |
| 107 | +- Run same-failure searches for the SOW-0026 finding classes in the Netdata vendored copy. |
| 108 | + |
| 109 | +Artifact impact plan: |
| 110 | + |
| 111 | +- AGENTS.md: no expected update. |
| 112 | +- Runtime project skills: no expected update. |
| 113 | +- Specs: no expected update unless propagation exposes source/doc drift. |
| 114 | +- End-user/operator docs: no expected update. |
| 115 | +- End-user/operator skills: no expected update. |
| 116 | +- SOW lifecycle: this SOW remains open until the user selects the Netdata checkout. |
| 117 | + |
| 118 | +Open-source reference evidence: |
| 119 | + |
| 120 | +- None checked yet; this SOW is a local vendor propagation task. |
| 121 | + |
| 122 | +Open decisions: |
| 123 | + |
| 124 | +1. Select the target Netdata checkout, branch, and PR context before implementation. |
| 125 | + |
| 126 | +## Implications And Decisions |
| 127 | + |
| 128 | +- No implementation decisions have been made yet. |
| 129 | + |
| 130 | +## Plan |
| 131 | + |
| 132 | +1. Confirm target checkout and branch. |
| 133 | +2. Run vendor propagation. |
| 134 | +3. Validate vendor parity and targeted Netdata behavior. |
| 135 | +4. Commit and push when validated. |
| 136 | + |
| 137 | +## Execution Log |
| 138 | + |
| 139 | +### 2026-06-29 |
| 140 | + |
| 141 | +- Created as the tracked follow-up for SOW-0026 vendor propagation. |
| 142 | +- No implementation started. |
| 143 | + |
| 144 | +## Validation |
| 145 | + |
| 146 | +Acceptance criteria evidence: |
| 147 | + |
| 148 | +- Not started. |
| 149 | + |
| 150 | +Tests or equivalent validation: |
| 151 | + |
| 152 | +- Not started. |
| 153 | + |
| 154 | +Real-use evidence: |
| 155 | + |
| 156 | +- Not started. |
| 157 | + |
| 158 | +Reviewer findings: |
| 159 | + |
| 160 | +- Not started. |
| 161 | + |
| 162 | +Same-failure scan: |
| 163 | + |
| 164 | +- Not started. |
| 165 | + |
| 166 | +Sensitive data gate: |
| 167 | + |
| 168 | +- The SOW contains only source paths and workflow descriptions. No secrets or customer data are included. |
| 169 | + |
| 170 | +Artifact maintenance gate: |
| 171 | + |
| 172 | +- AGENTS.md: no update needed for this tracking SOW. |
| 173 | +- Runtime project skills: none exist. |
| 174 | +- Specs: no update needed until implementation changes behavior. |
| 175 | +- End-user/operator docs: no update needed until implementation changes behavior. |
| 176 | +- End-user/operator skills: no update needed until implementation changes behavior. |
| 177 | +- SOW lifecycle: created as open in `.agents/sow/pending/`. |
| 178 | + |
| 179 | +Specs update: |
| 180 | + |
| 181 | +- Not started. |
| 182 | + |
| 183 | +Project skills update: |
| 184 | + |
| 185 | +- Not started. |
| 186 | + |
| 187 | +End-user/operator docs update: |
| 188 | + |
| 189 | +- Not started. |
| 190 | + |
| 191 | +End-user/operator skills update: |
| 192 | + |
| 193 | +- Not started. |
| 194 | + |
| 195 | +Lessons: |
| 196 | + |
| 197 | +- None yet. |
| 198 | + |
| 199 | +Follow-up mapping: |
| 200 | + |
| 201 | +- This SOW tracks the SOW-0026 Netdata vendor propagation item. |
| 202 | + |
| 203 | +## Outcome |
| 204 | + |
| 205 | +Pending. |
| 206 | + |
| 207 | +## Lessons Extracted |
| 208 | + |
| 209 | +Pending. |
| 210 | + |
| 211 | +## Followup |
| 212 | + |
| 213 | +None yet. |
| 214 | + |
| 215 | +## Regression Log |
| 216 | + |
| 217 | +None yet. |
0 commit comments