20131 20131
中文

Three platforms, one release rhythm — with honest gaps

Capability levels: FULL / LIMITED / UNAVAILABLE per platform capability, as verified by current research and engineering tests — not marketing tables.

CapabilityWindowsmacOSLinux
Agent-layer hooks (Claude Code, OpenClaw, MCP proxy)FULLFULLFULL
Process & lineage observationFULL (user-mode; ETW kernel session optional, admin)FULL (libproc polling, zero-privilege; real-time events need Apple EndpointSecurity entitlement — approval-gated, pending)FULL (procfs, zero-privilege)
File action visibilityFULL user-mode; kernel-level pre-action PLANNEDLIMITED (polling cadence; real-time via entitlement, pending)FULL visibility; enforcement via eBPF PLANNED (Phase 2)
Network observationFULL with admin ETW session; LIMITED user-modeLIMITED (polling)FULL/LIMITED (procfs + auditd for kernel events)
Native enforcement (blocking)PLANNED per phasePLANNEDPLANNED (eBPF)
Recovery / undoPLANNED (snapshot backends per OS)PLANNEDPLANNED (btrfs + eBPF, Phase 2)

What that means in practice

Every OS update runs compatibility contract tests (API, enforcement, performance, recovery) — an OS update must never force a core rewrite.