SUPPORTING RESEARCH · Updated
NetWatch evidence notes
These notes support the NetWatch examples in the engineering publication series. They distinguish release-history statements, implementation details and design proposals. They do not establish adoption growth, productivity gains or authorship of individual code changes.
The implementation references are pinned to NetWatch commit 9b4597e, reviewed on 10 September 2026. Earlier design notes supplied by the author are dated 3 September 2026 and concern version 0.29.2; their hypotheses are not statements about the current implementation.
Shared panels
The 0.30.0 release history describes replacing 48 separately built UI blocks across 15 files with a shared panel component. The component introduction and implementation describe inconsistent title colours and corner styles, and provide shared construction methods for titles, metadata, focus and badges.
This illustrates moving repeated presentation choices into a common implementation. The count is the project's historical account, corroborated by the component comment, not an independent reconstruction of the old revision. No measured reduction in review time or organisational escalation is established.
Windows installation
The 0.29.2 release history, dated 16 August 2026, describes a Windows loader failure involving wpcap.dll: Npcap's normal installation directory was outside the executable's library search path. The recorded correction introduced delayed loading and explicit discovery, and made help and version output available without Npcap.
Issue #47, opened 12 August, separately records a user encountering a loader error on version 0.29.0 without the additional capture software installed. That report and the changelog's default-installed-Npcap failure are related, but not identical reproductions.
The case illustrates how dependency handling affects access to a product, and demonstrates that failed starts can generate user reports. It is based on release history and the report, not a Windows installation executed for this review. It supplies no conversion-rate or retained-user measurement.
Attribution diagnosis
The author's earlier design review observed substantial traffic under pid:0 and proposed testing whether Landlock restrictions prevented reading process information. The accompanying handover explicitly treated this as a hypothesis.
The later 0.30.0 release history records a different finding: absent attribution had been displayed as PID zero. The correction labelled unattributed traffic as such, while retaining a known PID when its name was unavailable.
A visible symptom justified investigation but did not establish the proposed cause. The display correction does not prove that every attribution issue was solved, or that AI authored the defect, hypothesis or correction. The essay uses this as reasoning discipline applicable to AI-assisted work, not as a documented AI failure.
Graph semantics
The 0.30.1 release history, dated 7 September 2026, records incorrectly aligned per-interface throughput histories. Their oldest samples were aligned even though each history ended at the present, allowing a newer interface's traffic to appear before the interface existed.
The same release records a mirrored plot independently drawing two zero baselines. These cases illustrate how a chart can render successfully while misrepresenting its data. Verification needs a known temporal or geometric expectation. No measured user impact, time saving or AI authorship is established.
Controlled demo
The demo implementation constructs a fixed clock and a real diagnosis engine. Its tick advances time and supplies scenario observations. Demo remediation changes scenario state rather than the host's resolver configuration; the module describes a persistent demo banner and verification through the normal rule condition.
The fixture seeds baselines and constructs observations. These are controlled scenario data, not an established capture of a production incident, even where comments use the word “recorded.” The author's handover also identifies the mockup numbers as synthetic.
This exercises decision logic with controlled inputs and time. It does not establish live-collector accuracy, validate every diagnostic cause or demonstrate safe remediation on every supported host.
An earlier mockup described 40 ms against a 1.2 ms baseline as 100×; the ratio is approximately 33.3×. The fixture comment identifies that inconsistency and the move toward producing screen and report values from engine evidence. However, the report test named every_metric_in_the_report_comes_from_evidence checks a narrower property: selected lines contain at least one allowed evidence string. It is not proof that every number in every report is valid.
Packaging participation
The README's acknowledgements credit downstream maintainers for AUR packages, a nixpkgs package, a Scoop entry and Homebrew integration. This is documentary evidence of distribution work beyond the author.
The current availability of each downstream package was not independently audited. The credits do not establish motivations, recruitment methods or resulting adoption growth. The essays reference the acknowledgements, not current installation advice.
Design handover
The author's 3 September design handover links a review, HTML mockups, rendered images and a diagnosis specification. It distinguishes its synthetic scenario from real captures, proposes a work sequence and describes constraints for reversible remediations and evidence-based reporting. The underlying design bundle is author-supplied material, not a public implementation reference.
It illustrates how a concrete artefact can expose intended behaviour, unresolved hypotheses and acceptance conditions. It does not demonstrate measured productivity improvement, a personal leadership transition, successful human delegation or a controlled comparison of development methods.
Attribution boundary
These notes support the NetWatch cases in the leadership, distribution and AI-assisted engineering essays. The deterministic trading discussion instead references TickTape, with commit-pinned implementation citations in that paper. The pricing calculation, executive investment proposal and release-delegation scenario are illustrative. No employer incident, financial loss, personal recollection, growth statistic or AI speedup is supplied by these sources.