github domcyrus/rustnet v1.7.0
Release v1.7.0

3 hours ago

Security

  • Reject Unix output files owned by unrelated users before changing or writing them, anchor opens to validated directories, and create diagnostic logs exclusively

Added

  • Traffic surge visibility: automatic linear scales, preserved sampled peaks,
    time labels, and two-second rate averages in Graph/Details and Activity sorting
  • Traffic reporting clarity: graphs follow the capture interface; label smoothed
    process rates, use binary byte units, and show explicit idle rates
  • Retained Linux process identity: eBPF preserves bounded executable paths
    and immediate-parent metadata after exit or exec, and checks task birth times
    before extending ancestry through procfs (#640)
  • Generic container attribution (Linux): identify Docker, Podman and LXC
    from socket/process cgroups without daemon sockets. Show runtime, ID and
    available names in Details, container: / runtime: filters, headless JSON,
    JSONL logs, PCAP sidecars and PCAPNG comments
  • Database DPI: identify MySQL classic greetings and TLS requests, Redis
    RESP command arrays, and PostgreSQL startup messages and TLS requests.
    Details shows bounded metadata without retaining credentials, SQL, Redis
    keys, or values. Recognition uses complete messages within one TCP payload;
    no stream reassembly or TLS decryption is added
  • Observed VLAN IDs: preserve captured 802.1Q IDs in connection details,
    headless snapshots, JSON event logs, and PCAP sidecars, including priority
    tags (VID 0). Supports Ethernet and Linux cooked capture; stripped tags
    remain unknown
  • Headless Traffic Counters: JSON/JSONL stats include lifetime packet and
    original-length byte totals from capture, independent of connection snapshots
    and TUI clears, for external metrics exporters
  • Initial Connection View: [view] group_by_process in config.toml
    enables process grouping at startup and on view reset; the default stays flat.
  • Headless Mode: --headless runs without the TUI, with optional
    --duration and shared --filter syntax. Versioned snapshots stream as
    JSONL by default, while --output json emits one final snapshot. Stdout is
    reserved for machine-readable output. A bounded asynchronous writer replaces
    stale queued snapshots before JSON serialization and prevents blocked
    consumers from delaying shutdown, while runtime capture and critical
    worker failures emit terminal error state and return a nonzero status.
    Connection IDs remain stable through archival and distinguish reused
    endpoints, traffic rates have explicit bytes-per-second field names, and
    timed-out workers retain a stopping terminal status. Documentation clarifies
    snapshot-history limits, separate PCAP collection, and full-snapshot costs
  • Reusable Connection Filters: the complete filter language now lives in
    rustnet-core, with the existing TUI path retained as a compatibility
    re-export for future headless frontends
  • Inline Connection Health: connection rows now show compact TCP
    retransmit/out-of-order, QUIC Retry/version, and transactional UDP
    retry/timeout badges, with a severity-first Health sort. The Details
    Transport Health card marks the counters behind the badge with their
    letters, e.g. TCP Retransmits (R) and Out-of-Order (O) (#583)
  • VPN Traffic Detection: identify WireGuard and OpenVPN connections through
    packet signatures, including OpenVPN over UDP and TCP (#581)
  • Passive DNS Analytics: the Host tab now shows rolling response codes,
    timeouts, matched latency, question names, and DNS health, with a compact
    health line in Overview
  • Host Socket Inventory: the new Host tab shows TCP LISTEN sockets, UDP
    BOUND endpoints, TCP state totals, observed RTT, process owners, and the
    detailed interface table on Linux, macOS, FreeBSD, and Windows
  • State-Aware Status Bar: the Overview footer highlights active process
    grouping and history modes and shows whether Space will expand or collapse
    the selected process group

Changed

  • Publish the internal workspace crates as 0.6.0 for the changed library APIs.

  • Label the Overview interface error and drop counters as Interfaces.

  • Simplify Graph and Details to automatic independent RX/TX scales, with no scale,
    log, or lock controls.
    Current rates and peak labels retain raw measurements. Details gains taller
    plots, aligned totals, and clear messages when no live history is available.

  • Smooth scrolling in Overview, Graph, and Details at 20 fps, preserving the
    500 ms sampling interval. Activity, DNS, and Graph bars animate value changes
    over 250 ms; numeric readings update immediately and settled bars redraw slowly.

  • Restore Activity's application and interface traffic-share charts on roomy
    terminals, plus capture coverage bars, while keeping the table and drill-down.
    Share charts use 60-second totals and live interface rates stay in fixed columns.

  • Improve TUI readability with wrapped Host records on narrow terminals,
    Unicode cell-aware truncation, consistent headings and gutters, and labeled
    RX/TX chart scales. TCP state rows can scroll; Help shadows are opt-in
    through [ui] popup_shadow = true

  • Move DNS-inferred hostnames from Remote to App and their Details metadata
    into the Application card, retaining the ~ marker and SNI / Host precedence (#638)

  • Documentation accuracy: Align English, Chinese, and Japanese feature
    claims, installation and profiling steps, sandbox limits, and the roadmap
    with the current implementation.

  • App artwork: use a cyan and green terminal signal for desktop icons,
    the macOS installer, and the README logo in all three languages.

  • Document Scoop installation in all three README languages and both
    installation guides

  • Contextual help: each tab and Host section now explains its purpose before
    listing controls. Activity defines Egress (TX) and Ingress (RX) from the device's
    perspective; Host DNS explains passive lookup outcomes and coverage limits.

  • Compact layouts: Overview, Details, Activity, and Graph share clickable section
    selectors with v / Shift+v when the full layout does not fit. Overview
    shows System inline with dividers; Host uses the same controls for its two views.
    Section tabs share the main tabs' styling and show shortcuts in the footer.
    Activity groups traffic by application name, with scrollable PID lists, stable
    selection, inline details, and exact connection jumps to Overview. Application
    peers are deduplicated and peaks use simultaneous rates. Overview filters do
    not affect Activity totals. The new pid: filter matches exact process IDs.
    Capture stays accessible at every size; interface inventory lives in Host.
    Capture panels omit explanatory footnotes.

  • TUI visual polish: Activity uses compact TX/RX summaries, a roomier
    process ranking, and a separate capture-quality sidebar on wide terminals.
    Share bars use theme-derived gradients with textured ANSI fallbacks.
    The default keeps TX blue / RX green; other themes retain their own traffic
    tokens. Shared section rules and table headings improve hierarchy throughout
    the TUI, with responsive navigation and NO_COLOR support.
    Graph's health, TCP state, and application distribution bars share Activity's
    shading, fractional tips, and dotted tracks while preserving semantic colours.

  • Frontend Modules: startup and the TUI loop now live in library modules;
    headless orchestration, schema projection, and output handling are separate
    modules. Overlapping JSON, PCAP, sidecar, PCAPNG, and regular-file stdout
    destinations are rejected before RustNet truncates or writes output data

  • Packet Processing: consolidate tracker lookups, reuse parsed-packet buffers,
    and group up to 16 already queued batches per ordered update without waiting
    to fill the group. A sole processor parses and updates each packet immediately,
    without staging DPI allocations. Parallel workers keep packet cleanup outside
    the ordered commit and skip notifications without waiters.
    The queue remains bounded at 10,000 packets,
    plus up to 1,600 in-flight packets per worker (6,400 across at most four workers).
    A full queue uses a 5 ms send timeout. Linux, macOS, FreeBSD, and Windows capture
    share bounded idle-wait and fallback handling, using Unix descriptor readiness
    or Npcap events where supported to wake promptly for new traffic.
    Overload can still cause queue or capture-backend loss

  • Runtime Lifecycle Foundation: privileged capture and process attribution
    are prepared synchronously before sandboxing, while all long-lived workers
    start through a typed post-sandbox handoff and stop under one owned,
    bounded supervisor

  • Staleness Cue: idle connection rows now show a stripe at their left
    edge and a removal countdown in the bandwidth column from halfway through
    their timeout (previously 75%), both running yellow to red as cleanup
    nears, while the rest of the row softens toward gray
    instead of recoloring whole rows, so Health, RTT, and State keep their
    colors and stale rows stay distinct from gray historic rows on dark
    terminals

  • Responsive System Sidebar: Traffic now appears before the static Security
    details, which collapse to the sandbox status when terminal height is limited

  • Contextual Help Overlay: Help now opens above the active tab and only
    shows controls and concepts relevant to that view. The tab bar now contains
    the five application views, with direct shortcuts 1 through 5

  • Internal Deduplication: duplicated helpers, fixtures, and workflow steps
    were consolidated across the workspace, removing about 2,000 lines with no
    intended change in behaviour. Small visible differences: truncated names in
    the connection table, Activity tab, and filter chip no longer leave a space
    before the ellipsis, GeoIP lookups also skip multicast, reserved,
    benchmarking, documentation, and discard addresses, hostnames stuck in a
    pending DNS state are retried after 30 seconds, a connection superseded by
    a new SYN is archived with its cached rates zeroed like an expired one, the
    sandbox report uses one wording for a failed root uid drop on every
    platform and, on builds without Landlock, for the success case as well, the
    standalone aarch64 and Android static build workflows are removed since the
    release workflow already produces those binaries, and dispatching the
    release workflow with skip_downstream now also skips the crates.io,
    Docker, COPR, PPA, and OBS publish jobs so a backfill cannot republish

  • Release Backfills: a re-run of the release workflow no longer overwrites
    assets that are already on the release unless overwrite_assets is set,
    since Chocolatey, Scoop, and the AUR binary package pin checksums of the
    published files

  • Acronym Casing: the Details header chip reads RTT instead of rtt
    and PCAPNG export errors spell the format in uppercase

Fixed

  • Restore FreeBSD builds with mio 1.2.4, which supports libc 0.2.190.

  • Apply Overview's PTR visibility setting to Activity totals, including retained
    connections; use --show-ptr-lookups to include reverse DNS traffic in both tabs.

  • Preserve Linux Host socket owners discovered at startup across restricted procfs refreshes, including listeners and bound UDP sockets

  • Keep packet rates, connection lifecycle, and health updating when interface counters are unavailable; prevent compact RX/TX rates from losing leading digits.

  • macOS traffic graphs: use aggregate counters for default PKTAP capture, keep
    Details scrolling independently, and publish complete interface-rate snapshots

  • Add the missing divider between Overview traffic and interface counters.

  • Keep the filter cursor on UTF-8 character boundaries when typing, moving, or deleting non-ASCII text, avoiding TUI panics.

  • Preserve regex syntax in connection filters, including uppercase escapes such as \D and explicit case-sensitive groups.

  • ARM DEB compatibility with Ubuntu 22.04 and Debian 12/13: use a glibc 2.35
    build baseline, declare runtime dependencies, and embed ARMv7 libpcap to
    avoid Debian 13's time64 ABI mismatch. Test package installation and capture.

  • Traffic graph stability: remove hollow outlines and preserve the scroll position
    across sample arrivals; interpolate before rasterizing to prevent contour wobble

  • Keep Activity summary TX/RX labels, numbers, and units aligned as live rates change

  • QUIC handshake storage: coalesce bounded CRYPTO ranges in either arrival
    order, keep assembling through ClientHello for ALPN, and release bytes after
    extraction. UI/history snapshots retain metadata only. Library consumers must
    adapt get_fragments() from a map reference to an (offset, slice) iterator

  • 32-bit parser validation: test QUIC and SNMP length boundaries in debug
    and release CI; constrain SNMP nested fields to their declared containers

  • Short Kubernetes flows: retain cgroup v2 pod/container identity with eBPF
    socket records after process exit, match both endpoint orientations, and
    evict old records when the map fills.
    Track evidence export before debug-pod cleanup in the separate
    kubectl-rustnet follow-up.

  • Clarify unreleased features and Windows setup in all three documentation
    languages; link v1.6.0 docs and add release checks for availability notes (#620)

  • Connection viewport: paging, scrollbars, and mouse targets track the current
    layout immediately after resizing, including filters and two-row capture errors.

  • Details information pages: replace overflowing information scrollbars with
    sections and numbered pages reached with v/V. Keep j/k, paging, and the wheel
    for connection navigation; retain Traffic plots when they fit

  • Details layout: use the terminal's full width and anchor RX/TX plots
    above the footer with a proportional height capped at 18 rows

  • TUI alignment: align Activity pane headings, expand Host interface columns,
    and size Graph process names and rows to the available space

  • Required UID Drop: abort startup before packet-processing workers when a
    requested root UID/GID drop fails, including in best-effort mode

  • Windows Connection History: connections that reuse a tuple with the
    same capture timestamp keep distinct history entries

  • Idle Capture Shutdown: nonblocking capture reads and bounded idle
    polling let worker shutdown finish even after packet traffic stops

  • Windows Address Discovery: collect IPv4, IPv6, and subnet broadcasts
    through IP Helper without loading the Npcap capture driver

  • Loss and Export Accounting: queue backpressure drops are reported
    separately from libpcap and interface drops, partial batches drain during
    shutdown, and classic PCAP output remains bound to its securely pre-opened
    file descriptor

  • 32-bit eBPF Map ABI: explicitly align the shared C and Rust ConnInfo
    structures to 8 bytes, fixing compilation on i586 (#611)

  • macOS Host Tab SYN_RCVD: sockets that lsof reports as SYN_RCVD now
    show as SYN received instead of an unknown state

  • Bogus "unknown" Process Group on Linux: a process that exited while
    RustNet scanned /proc was recorded under the literal name unknown, which
    showed up as its own process group next to the real <unknown> bucket and,
    with eBPF attribution, overrode the correct name the kernel had captured at
    socket creation. Such a process is now skipped instead (#590)

  • TCP Window Size Per Direction: the Details Transport Health card kept a
    single window slot that every segment overwrote, so the value flipped
    between the local and remote advertised windows. Both are now shown (↓
    local, ↑ remote), in bytes only when the captured handshake proved the
    window scale. Without it the scale is unknowable from the wire, so the row
    reads unknown (no handshake) rather than a raw header field that stands
    for anything up to 16384 times its value; the Details help and USAGE explain
    it (#589)

  • TCP Analytics for a Connection's First Packet: the packet that creates a
    connection now reaches the TCP analytics. For a connection this host
    initiates that packet is its own SYN, the only carrier of the local
    window-scale option, so windows could never be reported in bytes even with
    the whole handshake captured (#589)

  • Duplicate ACK False Positives: a repeated ACK only counts as a duplicate
    when this host has data outstanding and the advertised window is unchanged
    (RFC 5681), so an idle connection's keepalives and the peer's window updates
    no longer inflate the counter or report a fast retransmit on a connection
    that never retransmitted. A RST no longer overwrites the last advertised
    window with its meaningless zero (#589)

  • Default Npcap Installations on Windows: RustNet now finds Npcap in its
    standard System32\Npcap directory, so WinPcap API-compatible mode is no
    longer required. --help and --version also work without Npcap installed

  • Attribution of Pre-Existing Connections on Linux: connections that were
    already open before RustNet started keep their process name after privilege
    reduction, including root services when RustNet runs with file capabilities
    on Linux 5.11 and newer. A one-shot BPF task-file inventory and the
    privileged procfs scan feed a validated fallback shown as the "startup
    snapshot" match quality (#575)

  • Keep new releases in draft until Linux, macOS and Windows installer jobs
    all succeed, preventing publication with missing installer assets.

Removed

  • Unused screenshots, the macOS PNG export, duplicate PPA setup notes,
    obsolete manual build/debug tools, and redundant services copies in local
    installers and Docker. Release archives retain services for the AUR package.
  • Unused internal APIs, ineffective DPI packet limits, and sandbox pathname
    write exceptions. Capture outputs continue using descriptors opened before
    sandboxing
  • Ubuntu 25.10 (Questing) PPA: the series reached end of life and
    Launchpad rejects new uploads for it, so the PPA build matrix and install
    docs drop it. Already-published questing packages stay in the PPA archive

Don't miss a new rustnet release

NewReleases is sending notifications on new releases.