@@ -308,3 +308,37 @@ When adding a new pure helper to `convert.rs`/`supervisor.rs`, prefer a Rust
308308behavior that's actually observable through the compiled API (an exception's
309309type/message, a builder's resulting policy) rather than the helper's internals
310310directly.
311+
312+ ## ProcessKit 3.2.0 surface audit
313+
314+ The 3.2.0 crate release adds several public Rust surfaces that are intentionally
315+ not swept into the Python binding as an automatic parity exercise. Each item
316+ needs its own contract, tests, and review before it becomes a Python API:
317+
318+ - ` SupervisionSession::events() ` and ` SupervisionEvent ` are a plausible future
319+ async iterator, but the Python representation of the event enum, including
320+ the bounded-channel ` Lagged ` case, must be designed first.
321+ - ` ProcessGroup::limit_evidence() ` is useful post-run evidence, but its
322+ ` Tripped ` /` NotTripped ` /` Unknown ` result must remain explicitly tri-state; it
323+ must not be reduced to a boolean on platforms where the crate cannot prove
324+ the verdict.
325+ - ` cancel_signal ` and ` cancel_grace ` require an explicit compatibility design
326+ against the binding's current cancellation and timeout behavior. They are
327+ not safe as passive builder kwargs until the soft-cancellation ordering and
328+ platform defaults are documented and tested.
329+ - ` output_json ` is presently a likely duplicate of the binding's existing
330+ ` run_json() ` /` arun_json() ` contract. A future proposal should prove a user
331+ visible semantic gap before adding another verb.
332+ - ` report-serde ` is an opt-in crate feature and is not needed while the Python
333+ ` ShutdownReport ` exposes structured fields directly. Enabling it would be a
334+ dependency/feature decision, not a free API-parity improvement.
335+ - ` Mechanism::ProcessReaper ` is platform-specific and the crate enum is
336+ non-exhaustive. Any Python-facing representation must preserve unknown future
337+ mechanisms and document the FreeBSD-only availability.
338+ - ` wait_for_path ` and the crate's HTTP probe overlap with the binding's
339+ Python-side probes. The Python implementation remains canonical until a
340+ measured compatibility or performance gap justifies a separate migration.
341+
342+ This audit deliberately creates follow-up scope rather than adding public
343+ symbols here. A follow-up that changes ` src/*.rs ` , ` _processkit.pyi ` , or the
344+ top-level exports must carry its own API-surface tests and human-review gate.
0 commit comments