Security
- Reject Unix output files owned by unrelated users before changing or writing them, anchor opens to validated directories, and create diagnostic logs exclusively
Added
- Traffic surge visibility: automatic linear scales, preserved sampled peaks,
time labels, and two-second rate averages in Graph/Details and Activity sorting - Traffic reporting clarity: graphs follow the capture interface; label smoothed
process rates, use binary byte units, and show explicit idle rates - Retained Linux process identity: eBPF preserves bounded executable paths
and immediate-parent metadata after exit or exec, and checks task birth times
before extending ancestry through procfs (#640) - Generic container attribution (Linux): identify Docker, Podman and LXC
from socket/process cgroups without daemon sockets. Show runtime, ID and
available names in Details,container:/runtime:filters, headless JSON,
JSONL logs, PCAP sidecars and PCAPNG comments - Database DPI: identify MySQL classic greetings and TLS requests, Redis
RESP command arrays, and PostgreSQL startup messages and TLS requests.
Details shows bounded metadata without retaining credentials, SQL, Redis
keys, or values. Recognition uses complete messages within one TCP payload;
no stream reassembly or TLS decryption is added - Observed VLAN IDs: preserve captured 802.1Q IDs in connection details,
headless snapshots, JSON event logs, and PCAP sidecars, including priority
tags (VID 0). Supports Ethernet and Linux cooked capture; stripped tags
remain unknown - Headless Traffic Counters: JSON/JSONL stats include lifetime packet and
original-length byte totals from capture, independent of connection snapshots
and TUI clears, for external metrics exporters - Initial Connection View:
[view] group_by_processinconfig.toml
enables process grouping at startup and on view reset; the default stays flat. - Headless Mode:
--headlessruns without the TUI, with optional
--durationand shared--filtersyntax. Versioned snapshots stream as
JSONL by default, while--output jsonemits one final snapshot. Stdout is
reserved for machine-readable output. A bounded asynchronous writer replaces
stale queued snapshots before JSON serialization and prevents blocked
consumers from delaying shutdown, while runtime capture and critical
worker failures emit terminal error state and return a nonzero status.
Connection IDs remain stable through archival and distinguish reused
endpoints, traffic rates have explicit bytes-per-second field names, and
timed-out workers retain astoppingterminal status. Documentation clarifies
snapshot-history limits, separate PCAP collection, and full-snapshot costs - Reusable Connection Filters: the complete filter language now lives in
rustnet-core, with the existing TUI path retained as a compatibility
re-export for future headless frontends - Inline Connection Health: connection rows now show compact TCP
retransmit/out-of-order, QUIC Retry/version, and transactional UDP
retry/timeout badges, with a severity-first Health sort. The Details
Transport Health card marks the counters behind the badge with their
letters, e.g.TCP Retransmits (R)andOut-of-Order (O)(#583) - VPN Traffic Detection: identify WireGuard and OpenVPN connections through
packet signatures, including OpenVPN over UDP and TCP (#581) - Passive DNS Analytics: the Host tab now shows rolling response codes,
timeouts, matched latency, question names, and DNS health, with a compact
health line in Overview - Host Socket Inventory: the new Host tab shows TCP LISTEN sockets, UDP
BOUND endpoints, TCP state totals, observed RTT, process owners, and the
detailed interface table on Linux, macOS, FreeBSD, and Windows - State-Aware Status Bar: the Overview footer highlights active process
grouping and history modes and shows whether Space will expand or collapse
the selected process group
Changed
-
Publish the internal workspace crates as 0.6.0 for the changed library APIs.
-
Label the Overview interface error and drop counters as Interfaces.
-
Simplify Graph and Details to automatic independent RX/TX scales, with no scale,
log, or lock controls.
Current rates and peak labels retain raw measurements. Details gains taller
plots, aligned totals, and clear messages when no live history is available. -
Smooth scrolling in Overview, Graph, and Details at 20 fps, preserving the
500 ms sampling interval. Activity, DNS, and Graph bars animate value changes
over 250 ms; numeric readings update immediately and settled bars redraw slowly. -
Restore Activity's application and interface traffic-share charts on roomy
terminals, plus capture coverage bars, while keeping the table and drill-down.
Share charts use 60-second totals and live interface rates stay in fixed columns. -
Improve TUI readability with wrapped Host records on narrow terminals,
Unicode cell-aware truncation, consistent headings and gutters, and labeled
RX/TX chart scales. TCP state rows can scroll; Help shadows are opt-in
through[ui] popup_shadow = true -
Move DNS-inferred hostnames from Remote to App and their Details metadata
into the Application card, retaining the~marker and SNI / Host precedence (#638) -
Documentation accuracy: Align English, Chinese, and Japanese feature
claims, installation and profiling steps, sandbox limits, and the roadmap
with the current implementation. -
App artwork: use a cyan and green terminal signal for desktop icons,
the macOS installer, and the README logo in all three languages. -
Document Scoop installation in all three README languages and both
installation guides -
Contextual help: each tab and Host section now explains its purpose before
listing controls. Activity defines Egress (TX) and Ingress (RX) from the device's
perspective; Host DNS explains passive lookup outcomes and coverage limits. -
Compact layouts: Overview, Details, Activity, and Graph share clickable section
selectors withv/ Shift+vwhen the full layout does not fit. Overview
shows System inline with dividers; Host uses the same controls for its two views.
Section tabs share the main tabs' styling and show shortcuts in the footer.
Activity groups traffic by application name, with scrollable PID lists, stable
selection, inline details, and exact connection jumps to Overview. Application
peers are deduplicated and peaks use simultaneous rates. Overview filters do
not affect Activity totals. The newpid:filter matches exact process IDs.
Capture stays accessible at every size; interface inventory lives in Host.
Capture panels omit explanatory footnotes. -
TUI visual polish: Activity uses compact TX/RX summaries, a roomier
process ranking, and a separate capture-quality sidebar on wide terminals.
Share bars use theme-derived gradients with textured ANSI fallbacks.
The default keeps TX blue / RX green; other themes retain their own traffic
tokens. Shared section rules and table headings improve hierarchy throughout
the TUI, with responsive navigation and NO_COLOR support.
Graph's health, TCP state, and application distribution bars share Activity's
shading, fractional tips, and dotted tracks while preserving semantic colours. -
Frontend Modules: startup and the TUI loop now live in library modules;
headless orchestration, schema projection, and output handling are separate
modules. Overlapping JSON, PCAP, sidecar, PCAPNG, and regular-file stdout
destinations are rejected before RustNet truncates or writes output data -
Packet Processing: consolidate tracker lookups, reuse parsed-packet buffers,
and group up to 16 already queued batches per ordered update without waiting
to fill the group. A sole processor parses and updates each packet immediately,
without staging DPI allocations. Parallel workers keep packet cleanup outside
the ordered commit and skip notifications without waiters.
The queue remains bounded at 10,000 packets,
plus up to 1,600 in-flight packets per worker (6,400 across at most four workers).
A full queue uses a 5 ms send timeout. Linux, macOS, FreeBSD, and Windows capture
share bounded idle-wait and fallback handling, using Unix descriptor readiness
or Npcap events where supported to wake promptly for new traffic.
Overload can still cause queue or capture-backend loss -
Runtime Lifecycle Foundation: privileged capture and process attribution
are prepared synchronously before sandboxing, while all long-lived workers
start through a typed post-sandbox handoff and stop under one owned,
bounded supervisor -
Staleness Cue: idle connection rows now show a stripe at their left
edge and a removal countdown in the bandwidth column from halfway through
their timeout (previously 75%), both running yellow to red as cleanup
nears, while the rest of the row softens toward gray
instead of recoloring whole rows, so Health, RTT, and State keep their
colors and stale rows stay distinct from gray historic rows on dark
terminals -
Responsive System Sidebar: Traffic now appears before the static Security
details, which collapse to the sandbox status when terminal height is limited -
Contextual Help Overlay: Help now opens above the active tab and only
shows controls and concepts relevant to that view. The tab bar now contains
the five application views, with direct shortcuts1through5 -
Internal Deduplication: duplicated helpers, fixtures, and workflow steps
were consolidated across the workspace, removing about 2,000 lines with no
intended change in behaviour. Small visible differences: truncated names in
the connection table, Activity tab, and filter chip no longer leave a space
before the ellipsis, GeoIP lookups also skip multicast, reserved,
benchmarking, documentation, and discard addresses, hostnames stuck in a
pending DNS state are retried after 30 seconds, a connection superseded by
a new SYN is archived with its cached rates zeroed like an expired one, the
sandbox report uses one wording for a failed root uid drop on every
platform and, on builds without Landlock, for the success case as well, the
standalone aarch64 and Android static build workflows are removed since the
release workflow already produces those binaries, and dispatching the
release workflow withskip_downstreamnow also skips the crates.io,
Docker, COPR, PPA, and OBS publish jobs so a backfill cannot republish -
Release Backfills: a re-run of the release workflow no longer overwrites
assets that are already on the release unlessoverwrite_assetsis set,
since Chocolatey, Scoop, and the AUR binary package pin checksums of the
published files -
Acronym Casing: the Details header chip reads
RTTinstead ofrtt
and PCAPNG export errors spell the format in uppercase
Fixed
-
Restore FreeBSD builds with mio 1.2.4, which supports libc 0.2.190.
-
Apply Overview's PTR visibility setting to Activity totals, including retained
connections; use--show-ptr-lookupsto include reverse DNS traffic in both tabs. -
Preserve Linux Host socket owners discovered at startup across restricted procfs refreshes, including listeners and bound UDP sockets
-
Keep packet rates, connection lifecycle, and health updating when interface counters are unavailable; prevent compact RX/TX rates from losing leading digits.
-
macOS traffic graphs: use aggregate counters for default PKTAP capture, keep
Details scrolling independently, and publish complete interface-rate snapshots -
Add the missing divider between Overview traffic and interface counters.
-
Keep the filter cursor on UTF-8 character boundaries when typing, moving, or deleting non-ASCII text, avoiding TUI panics.
-
Preserve regex syntax in connection filters, including uppercase escapes such as
\Dand explicit case-sensitive groups. -
ARM DEB compatibility with Ubuntu 22.04 and Debian 12/13: use a glibc 2.35
build baseline, declare runtime dependencies, and embed ARMv7 libpcap to
avoid Debian 13's time64 ABI mismatch. Test package installation and capture. -
Traffic graph stability: remove hollow outlines and preserve the scroll position
across sample arrivals; interpolate before rasterizing to prevent contour wobble -
Keep Activity summary TX/RX labels, numbers, and units aligned as live rates change
-
QUIC handshake storage: coalesce bounded CRYPTO ranges in either arrival
order, keep assembling through ClientHello for ALPN, and release bytes after
extraction. UI/history snapshots retain metadata only. Library consumers must
adaptget_fragments()from a map reference to an(offset, slice)iterator -
32-bit parser validation: test QUIC and SNMP length boundaries in debug
and release CI; constrain SNMP nested fields to their declared containers -
Short Kubernetes flows: retain cgroup v2 pod/container identity with eBPF
socket records after process exit, match both endpoint orientations, and
evict old records when the map fills.
Track evidence export before debug-pod cleanup in the separate
kubectl-rustnet follow-up. -
Clarify unreleased features and Windows setup in all three documentation
languages; link v1.6.0 docs and add release checks for availability notes (#620) -
Connection viewport: paging, scrollbars, and mouse targets track the current
layout immediately after resizing, including filters and two-row capture errors. -
Details information pages: replace overflowing information scrollbars with
sections and numbered pages reached with v/V. Keep j/k, paging, and the wheel
for connection navigation; retain Traffic plots when they fit -
Details layout: use the terminal's full width and anchor RX/TX plots
above the footer with a proportional height capped at 18 rows -
TUI alignment: align Activity pane headings, expand Host interface columns,
and size Graph process names and rows to the available space -
Required UID Drop: abort startup before packet-processing workers when a
requested root UID/GID drop fails, including in best-effort mode -
Windows Connection History: connections that reuse a tuple with the
same capture timestamp keep distinct history entries -
Idle Capture Shutdown: nonblocking capture reads and bounded idle
polling let worker shutdown finish even after packet traffic stops -
Windows Address Discovery: collect IPv4, IPv6, and subnet broadcasts
through IP Helper without loading the Npcap capture driver -
Loss and Export Accounting: queue backpressure drops are reported
separately from libpcap and interface drops, partial batches drain during
shutdown, and classic PCAP output remains bound to its securely pre-opened
file descriptor -
32-bit eBPF Map ABI: explicitly align the shared C and Rust
ConnInfo
structures to 8 bytes, fixing compilation on i586 (#611) -
macOS Host Tab SYN_RCVD: sockets that
lsofreports asSYN_RCVDnow
show as SYN received instead of an unknown state -
Bogus "unknown" Process Group on Linux: a process that exited while
RustNet scanned/procwas recorded under the literal nameunknown, which
showed up as its own process group next to the real<unknown>bucket and,
with eBPF attribution, overrode the correct name the kernel had captured at
socket creation. Such a process is now skipped instead (#590) -
TCP Window Size Per Direction: the Details Transport Health card kept a
single window slot that every segment overwrote, so the value flipped
between the local and remote advertised windows. Both are now shown (↓
local,↑remote), in bytes only when the captured handshake proved the
window scale. Without it the scale is unknowable from the wire, so the row
readsunknown (no handshake)rather than a raw header field that stands
for anything up to 16384 times its value; the Details help and USAGE explain
it (#589) -
TCP Analytics for a Connection's First Packet: the packet that creates a
connection now reaches the TCP analytics. For a connection this host
initiates that packet is its own SYN, the only carrier of the local
window-scale option, so windows could never be reported in bytes even with
the whole handshake captured (#589) -
Duplicate ACK False Positives: a repeated ACK only counts as a duplicate
when this host has data outstanding and the advertised window is unchanged
(RFC 5681), so an idle connection's keepalives and the peer's window updates
no longer inflate the counter or report a fast retransmit on a connection
that never retransmitted. A RST no longer overwrites the last advertised
window with its meaningless zero (#589) -
Default Npcap Installations on Windows: RustNet now finds Npcap in its
standardSystem32\Npcapdirectory, so WinPcap API-compatible mode is no
longer required.--helpand--versionalso work without Npcap installed -
Attribution of Pre-Existing Connections on Linux: connections that were
already open before RustNet started keep their process name after privilege
reduction, including root services when RustNet runs with file capabilities
on Linux 5.11 and newer. A one-shot BPF task-file inventory and the
privileged procfs scan feed a validated fallback shown as the "startup
snapshot" match quality (#575) -
Keep new releases in draft until Linux, macOS and Windows installer jobs
all succeed, preventing publication with missing installer assets.
Removed
- Unused screenshots, the macOS PNG export, duplicate PPA setup notes,
obsolete manual build/debug tools, and redundant services copies in local
installers and Docker. Release archives retain services for the AUR package. - Unused internal APIs, ineffective DPI packet limits, and sandbox pathname
write exceptions. Capture outputs continue using descriptors opened before
sandboxing - Ubuntu 25.10 (Questing) PPA: the series reached end of life and
Launchpad rejects new uploads for it, so the PPA build matrix and install
docs drop it. Already-published questing packages stay in the PPA archive