v1.5.0

miraymen/pix2surfv1.5.0Jul 21, 2026by github-actions[bot]

AI Summary

This release introduces Kubernetes awareness to RustNet, allowing connections to be attributed to their owning pods and containers, and adds a native PCAPNG export with process and GeoIP metadata. It also enhances the UI with gradient braille graphs, improves Windows process attribution via ETW, and drops root privileges for security.

Key Highlights

  • Kubernetes Pod/Container Attribution
  • Native Annotated PCAPNG Export
  • Process Activity View
  • Gradient Braille Graphs and Adaptive Rendering
  • Drop Root Privileges After Initialization

New Features

  • Kubernetes Pod/Container Attribution
  • Native Annotated PCAPNG Export
  • Process Activity View
  • Gradient Braille Graphs
  • Pane Scrolling and Filled Traffic Chart
  • Event-driven Windows Process Attribution
  • Hardened File Writes
  • Dynamic local-address detection
  • QUIC DPI improvements

Full Release Notes


This release makes RustNet Kubernetes-aware: connections can be attributed to their
owning pod and container, and the new native PCAPNG export writes Wireshark-ready
captures with process, DPI, GeoIP, and pod annotations. A new Activity view ranks
processes by traffic, the graphs got a gradient braille overhaul, Windows process
attribution went event-driven with ETW, and rustnet now drops root privileges after
initialization on Linux, macOS, and FreeBSD.

### Added
- **Kubernetes Pod/Container Attribution**: New optional `kubernetes` feature
  (off by default, no extra dependencies) that attributes connections to their
  owning pod and container on a node, including `hostNetwork` pods. Pod, namespace,
  and container appear in the Details pane, JSONL/PCAPNG exports, and the new
  `pod:`, `ns:`, and `container:` filter keywords. The container image enables the
  feature by default (#299, #450)
- **Native Annotated PCAPNG Export**: New `--pcapng-export FILE` writes a
  Wireshark-ready PCAPNG file whose packet comments carry best-effort process, PID,
  direction, DPI/SNI, and GeoIP metadata, preserving libpcap timestamps and original
  packet lengths. The Overview panel reports export progress and annotation stats (#432)
- **Process Activity View**: The Interfaces tab is now a process-focused Activity
  view (key `3`) ranking egress and ingress traffic with 60-second share bars,
  retained totals, connection counts, and top remote peers; `d` flips direction,
  `s` changes the sort metric, and `i` opens the detailed interface table (#465)
- **Gradient Braille Graphs and Adaptive Rendering**: Flow-inspired braille area
  graphs with gradient ramps across the Graph tab, Overview mini graphs, and
  per-connection Details waves, plus a draw-on-demand main loop with event
  coalescing that roughly halves terminal-emulator CPU (#459)
- **Pane Scrolling and Filled Traffic Chart**: Details, Help, and Interfaces tabs
  scroll with mouse wheel and vim keys instead of silently clipping, and the
  traffic chart renders RX/TX as filled areas (#452)
- **Event-driven Windows Process Attribution**: Use kernel network and process ETW
  events to retain connection ownership for short-lived processes, with IP Helper
  polling as reconciliation and fallback. IPv6 UDP ownership is now included (#474)

### Security
- **Drop Root Privileges After Initialization**: Under sudo, rustnet now drops to
  `SUDO_UID`/`SUDO_GID` (or `nobody` for plain root) once capture and eBPF are
  initialized on Linux, macOS, and FreeBSD, so a DPI compromise no longer runs as
  root. Opt out with the new `--no-uid-drop` flag; `--sandbox-strict` fails hard if
  the drop fails. Trade-offs are documented in SECURITY.md (#456, #457, #458)
- **No More `CAP_SYS_ADMIN` Auto-Grant**: DEB/RPM installs no longer grant the
  broad `cap_sys_admin` eBPF fallback capability; on pre-5.8 kernels process
  detection degrades to procfs instead (#431)
- **Hardened File Writes**: Log and capture files are created atomically with
  `O_NOFOLLOW` and mode `0600`, and `lsof`/`sockstat` are invoked by absolute path
  to prevent symlink and `$PATH` attacks (#430)

### Fixed
- **Dynamic local-address detection**: Refresh endpoint-orientation addresses after
  network changes and retry ambiguous unicast packets once. On Windows, supplement
  the IPv4-only adapter data with `GetAdaptersAddresses()` so IPv6 traffic is not
  shown with reversed local and remote endpoints (#475)
- **Transport Payload Length**: Trim the transport slice to the IP datagram length,
  so Ethernet frame padding no longer produces phantom 6-byte payloads, false
  retransmission counts, resurrected closed connections, or DPI misclassification
  from trailing bytes (#479, thanks @0xghost42)
- **Connection Lifecycle**: Reused connection tuples no longer inherit their
  predecessor's process/DPI metadata in PCAPNG annotations or rate history in
  Details; immutable history is preserved across tuple reuse; UI-side expiry no
  longer hides tracked connections; rows stay yellow through the whole warning
  window; and the recently-closed tombstone table keeps a capacity floor for tiny
  archive configs (#469, #470, #473)
- **Grouped Overview Navigation**: Space collapses or expands a process group from
  a child row, and `g`/`G` jump to the first and last visible rows in grouped
  mode (#471)
- **Live Graph Rendering**: Graphs sample and redraw more frequently with stable
  scaling, so waves no longer wobble or flatten after spikes, and the connection
  count graph now shows opened/closed lifecycle activity (#472)
- **Overview Status Polish**: Clarified filtered result counts, kept Statistics
  totals unfiltered with process counts, and added an expiry color gradient with a
  matching Help legend (#466)
- **Stable Details Layout**: The Details tab uses fixed Connection, Network
  Context, Application, and Transport Health cards with placeholder rows, so
  sections no longer shift while navigating (#462)
- **Help Scrollbar**: Restored the inset Help scrollbar and the `Help · ↑/↓ scroll`
  title hint (#460)
- **QUIC DPI**: Parse Retry and Version Negotiation packets correctly, merge CRYPTO
  fragments across coalesced Initial packets (restoring SNI for large ClientHellos),
  and use the right Initial salts for draft/mvfst versions (#453)
- **Protocol Detection Switches**: Correct DPI misclassifications (SIP/RTSP as
  HTTP, SMTP as FTP, WireGuard as BitTorrent uTP), add MQTT QoS 2/AUTH types and
  structural SNMPv3 parsing, fix NetBIOS datagram offsets, and drop non-first IP
  fragments at the parser (#454)
- **DNS Label Parsing**: Reject RFC 1035 reserved label top-bits in
  `parse_question`, matching `skip_dns_name` (#434, thanks @0xghost42)
- **SSH State Detection**: Inspect the final 6-byte packet window, so signatures at
  the end of the payload are no longer missed (#406, thanks @0xghost42)
- **TLS Cipher Names**: Correct six mislabeled ARIA and Camellia cipher-suite
  names (#404, thanks @0xghost42)
- **macOS PKTAP PIDs**: Accept PIDs up to Darwin's 99999 ceiling instead of
  dropping attribution for PIDs at or above 65535 (#415, thanks @0xghost42)
- **eBPF Map Cleanup**: Compare map timestamps against `CLOCK_MONOTONIC` instead of
  wall-clock time, so cleanup no longer flushes the entire map and attribution no
  longer silently falls back to procfs (#451)

### Performance
- **Ratatui Hot Paths**: Cache selected row positions, aggregate Graph tab metrics
  in one borrowed pass, and select only the top process rows instead of sorting
  every process (#461)
- **HTTP Parser**: Drop the per-packet `Vec` allocation in the HTTP start-line
  parser (#402, thanks @0xghost42)

### Internal
- **Library Crates 0.4.0**: `rustnet-core`, `rustnet-capture`, and `rustnet-host`
  are released as 0.4.0 with the new Kubernetes, PCAPNG, and parser APIs
- **CI Auditing**: Replaced cargo-deny with RustSec cargo-audit for CI and
  scheduled supply-chain checks (#464)
- **OUI Database**: Monthly vendor database refresh (#439)
- **Dependencies**: Routine dependency and GitHub Actions updates across the cycle
  (Dependabot)

### Contributors

Special thanks to the contributors in this release:
- [@0xghost42](https://github.com/0xghost42): the transport payload-length fix,
  TLS cipher-suite corrections, SSH and DNS DPI fixes, the PKTAP PID ceiling fix,
  and HTTP parser performance (#402, #404, #406, #415, #434, #479)