Observed
A sensor recorded this kernel event inside its own bounded capture.
Experimental · local-first · missionq/0.1.0
Arc coordinates packet evidence from Linux sensors you control. It shows what each host observed, what can be correlated across hosts, and where the evidence still ends.
The governing rule
Every native traceq artifact remains authoritative for its
own host. Arc writes a separate mission record and labels every
cross-host relationship by the evidence that supports it.
Evidence vocabulary
A sensor recorded this kernel event inside its own bounded capture.
Compatible tuple, packet length, clock interval, and one-to-one assignment support the relationship.
The time and flow fit, but packet metadata differs. Arc preserves the weaker claim.
An artifact is missing or no viable observation pair exists. The gap stays visible.
One mission, bounded end to end
An outbound-only sensor reports identity, kernel release, capabilities, and clock uncertainty.
Arc issues an idempotent assignment with exact duration, event, byte, filter, and probe bounds.
The complete traceq artifact is checked before Arc indexes a single receipt.
Adjacent sensors are matched deterministically; loss and clock uncertainty stay attached.
Website request / timeout
In the seeded mission, the application host records
SKB_DROP_REASON_NETFILTER_DROP. That is direct local
evidence. The same artifact reports 14 recursion misses, so Arc
refuses to call the mission complete.
Rootless evaluation
Clone the repository, run the seeded control plane, and explore the complete sensor → assignment → artifact → correlation lifecycle without attaching BPF programs.
$ cargo run -p skbx-arc -- serve --demo
Then open http://127.0.0.1:7878
Lab boundary
Start from evidence