Context
PR #68 initializes Rust KCC telemetry once from cmd/agent, selecting the WSD or KPS wrapper from the process role.
In KEY_PROTECTION_VM_EMULATED mode, the WSD process invokes both the WSD and KPS Rust static libraries. Current Linux/amd64 linkage has been tested and a WSD-side initialization correctly configures KPS-KCC failure events with service.name=workload_service. However, this behavior depends on the two linked static libraries sharing the relevant km_common telemetry globals and symbols.
The latest PR changes also remove telemetry initialization from the public WSD/KPS server constructors. Direct package users and standalone tests must therefore remember to call InitTelemetry before any KCC operation; otherwise failure telemetry is silently absent.
This follow-up tracks making that lifecycle and linkage contract explicit without expanding PR #68.
Acceptance criteria
- Document which layer owns Rust telemetry initialization for:
- the agent KPS process;
- the agent WSD process;
- emulated WSD using both KCCs;
- standalone server/package consumers and tests.
- Ensure emulated mode does not rely on accidental static-archive symbol resolution for shared telemetry state.
- Add committed Linux/amd64 child-process coverage for:
- WSD initialization followed by a WSD-KCC failure;
- WSD initialization followed by a KPS-KCC failure;
- KPS initialization followed by a KPS-KCC failure.
- Make conflicting or repeated initialization observable instead of silently ignoring a different service name.
- Verify no change to FFI status propagation, key custody, or the WSD/KPS cryptographic flows.
Related: #68
Context
PR #68 initializes Rust KCC telemetry once from
cmd/agent, selecting the WSD or KPS wrapper from the process role.In
KEY_PROTECTION_VM_EMULATEDmode, the WSD process invokes both the WSD and KPS Rust static libraries. Current Linux/amd64 linkage has been tested and a WSD-side initialization correctly configures KPS-KCC failure events withservice.name=workload_service. However, this behavior depends on the two linked static libraries sharing the relevantkm_commontelemetry globals and symbols.The latest PR changes also remove telemetry initialization from the public WSD/KPS server constructors. Direct package users and standalone tests must therefore remember to call
InitTelemetrybefore any KCC operation; otherwise failure telemetry is silently absent.This follow-up tracks making that lifecycle and linkage contract explicit without expanding PR #68.
Acceptance criteria
Related: #68