SIGN IN SIGN UP

docs(networkstream): correct the saturated-tree breach threshold to ~3,600 (SUB-7786)

The previous commit corrected the saturated-tree figure from 2.27 to 1.91 MiB but left
the threshold that had been derived from the old figure at ~3,000, so the paragraph
contradicted its own arithmetic: 3.75 - 1.91 leaves 1.84 MiB, which is ~3,640 entries,
not ~2,900. The ~2,900 only followed from the retired 2.27 MiB.

Measured directly this time rather than derived from another derived number: a
saturated tree map marshals to 1,978,505 B (1.89 MiB), leaving 3,932,160 - 1,978,505 =
1,953,655 B (1.86 MiB), so ~3,690 entries at 530 B. Two independent measurements put it
at ~3,580 and ~3,600, so the doc states ~3,600 -- rounding low is the right direction
for a breach threshold. Corrected in all three places: the table caption, the residual
table row and the derivation.

Added the rule that produced both of the errors in this chain, so the next person does
not repeat it: derive the threshold from the measured tree total, never from a payload
figure that already contains entries.

Unaffected: entries alone still breach at 3,932,160 / 530 = ~7,400, and the operator
conclusion -- that maxProcessTreeBytes is a real lever because trees are roughly half
the payload in that regime -- holds unchanged at ~3,600.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Signed-off-by: Alon <alon@armosec.io>
A
Alon committed
8bc4f41e1b38eddb1b778aa5570b4825ff68620a
Parent: 892df8b