Skip to content

release: promote capture and investigation workflows to main - #64

Merged
LocNguyenHuu merged 31 commits into
mainfrom
develop
Sep 20, 2026
Merged

LocNguyenHuu merged 31 commits into
mainfrom
develop

Conversation

@LocNguyenHuu

@LocNguyenHuu LocNguyenHuu commented Sep 20, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Promote the reviewed Tracexy changes from develop to main:

  • Add a local selected-session Assistant and a bounded, read-only History MCP service with explicit Project grants.
  • Rebuild Overview around capture-time traffic, scoped charts, rankings, and links back to investigation surfaces.
  • Harden packet bounds, fragments, VLAN handling, session orientation, TCP observations, helper read-failure settling, and native capture flows.
  • Complete PCAP/PCAPNG file workflows: open in place or import, recent and file-set navigation, Get Info, frame navigation/export, Quick Look, and Spotlight.

Validation

  • Signed Debug full scheme on macOS 27.0: 1,644 passed, 0 failed, 0 skipped (build/PostCompactFullTests.xcresult in the local checkout).
  • Unsigned Release build passed with Xcode 26.6 / macOS SDK 26.5. SwiftFormat, strict SwiftLint, project validation, and the source-content safety scan passed locally.
  • Native macOS 27 replay opened a PCAPNG in place, verified Overview totals, two file interfaces in Get Info, and exact selected-frame navigation from the Frames facet.
  • Direct libpcap capture on macOS 27 started on en0, populated 108 sessions and 1.9 MB of traffic, and stopped cleanly.
  • The develop CI Test job passed on the merged source tree.
  • The develop commit tree matches the reviewed PR feat(file): complete capture file workflow #63 head.

Known validation limits

  • The CI history gate flags metadata on three GitHub-generated merge commits. The source-content scan found no private material; this history issue was reviewed separately and does not change the tested app tree.
  • The development privileged helper was not installed during this replay; its installed capture path needs a separate macOS approval and exact-runtime check.
  • This host has macOS 27 but Xcode 26.6 and SDK 26.5. An SDK 27 build has not been run.
  • The earlier local macOS 26.6.2 inspector constraint crash path was addressed; user-reported macOS 27 crash reports have not been matched to a supplied diagnostic report.

LocNguyenHuu and others added 30 commits September 14, 2026 20:49
- Clamp the transport payload to the IPv4 total length / IPv6 payload
  length so Ethernet padding and trailers are never counted as TCP
  sequence space (false overlap/retransmission findings, padding leaking
  into Follow Stream). A zero length (segmentation offload) or one beyond
  the captured bytes keeps the captured payload.
- Stop at the IP layer for non-first IPv4/IPv6 fragments and for an IPv4
  header shorter than 20 bytes instead of reading ports out of payload.
- Walk 802.1Q / 802.1ad tags (up to two) to the encapsulated EtherType so
  trunk- and mirror-port captures form sessions.
- Mask the classic pcap link-type word to its low 16 bits so libpcap's
  FCS-length hint does not hide the link type.
…d orientation

- A reset arriving after an orderly close (or after the connection was
  published) is recorded as a reset observation, so a session shown as an
  error carries the matching finding and evidence.
- A one-byte probe one behind the expected sequence is a keep-alive, not
  a retransmission.
- DNS latency is measured from the header's QR bit, so an answerless
  response (NXDOMAIN, NODATA) still ends the exchange.
- A session captured mid-stream is oriented by the SYN sender, or toward
  the service port when no SYN was seen, so the remote host rather than
  this Mac's ephemeral socket reads as the destination.
…rd XPC teardown

- When libpcap reports a read error (the interface went away or was
  reconfigured) the helper carries the reason with its final frames and
  the app settles the capture like an explicit Stop instead of showing it
  as still capturing. The direct libpcap path reports the same way. The
  new batch field is optional, so an older helper stays compatible.
- Session export streams the capture file record by record and keeps only
  the selected session's frames, instead of loading the whole capture
  into memory.
- A replaced helper XPC connection is no longer discarded by the previous
  connection's late invalidation handler.
- The coordinator keeps the app-wide settings store for launch-time
  preferences.
…ation

- Register PCAP/PCAPNG document types (alternate viewer) so Open With,
  a Dock drop, or a file dropped on the main window imports through the
  same Library path as ⌘O; a file opened before Projects hydrate is
  imported once loading completes.
- Exclude every scene from AppKit state restoration and reopen the
  workspace after launch when no window is visible: a force-quit relaunch
  previously showed two identical main windows, and a restored auxiliary
  window could leave the app running with no window at all.
- Ask before quitting while a live capture runs, as the General setting
  promised, and honor "Restore last workspace on launch" when it is off.
… expose tap-only rows

- Click a column header to sort the flat Sessions table; the default
  remains the stable capture order.
- Every byte figure goes through the General → Units setting.
- Saved-capture rows, Focus Set rows, Flow Map regions and inspector
  layer/field rows are activatable for VoiceOver and UI automation.
- Sidebar and Overview read protocol counts from one pass over the
  visible sessions instead of re-filtering once per protocol.
Fold a bounded, direction-aware traffic timeline once per accepted frame in
the common session fold and project it through the investigation snapshot so
live, saved and batch paths share it without new coordinator state.

- TrafficTimeline: absolute-time buckets that double in width past a cap,
  exact totals split by session direction, untimed frames counted not drawn,
  deterministic rendering to a bounded column count
- Overview: headline figures, a hero traffic-over-time chart with exact hover
  readouts and scoped findings pinned at their first cited frame, compact
  Protocols / Sessions started / Findings charts, native Top hosts and Top
  apps tables with in-row share bars that drill into the session list, and
  Sources and Capture health panels
- Report shelf on Liquid Glass in the safe area, matching the Sessions and
  History chrome; cards and tables stay opaque content surfaces
- Compute every scoped rollup once per render and project finding membership
  only when a filter reads it, removing the per-panel re-filtering that made
  the live surface lag
- Aggregate drill-in for attributed processes, protocol byte share partition,
  and ranking entries with session counts
- Tests for the accumulator bounds, ordering, determinism, batch/live
  equivalence, chart hit-testing, and scoped rollups
…erences, recents

- CaptureFileProperties: bounded pcapng section/interface/option/ISB/DSB/NRB/custom
  inventory and classic pcap header facts folded in the single streaming pass
- PcapngStreamReader parses SHB/IDB/ISB/EPB options within block bounds; DSB and
  unknown blocks are counted, never read
- CaptureReference sidecars (.tracexyref) let File > Open… open a capture where it
  is; Library lists referenced items with missing/changed availability, Locate…,
  Copy into Library and Remove
- File menu: Open… ⌘O, Open Recent, Import into Library… ⌥⌘O, Close Capture ⇧⌘W,
  Reload ⌘R; Finder/drop route through the Project's open preference
- Open panel preview accessory (format · size · records · start/elapsed) with a
  bounded scan; capinfos/tshark oracle tests; opt-in large-capture benchmark
…-session capture interfaces

- Get Info (⌘I) is a regular auxiliary window bound to the open capture: General,
  Time, Section, Interfaces (sortable Table), Statistics, Other Blocks, Coverage
- SHA-256/SHA-1 computed on demand with progress/cancel; refused if the file changed
- Copy toolbar action renders a plain-text report
- Sessions fold the bounded set of pcapng interfaces their frames came from; the
  Context dock shows 'Captured on' with the file's interface names
…ames

- SessionFrameScanner rescans the stable source (saved file or stopped-live spool
  copy), matches by the fold's session identity for any protocol, and retains at
  most 10,000 bounded references with capture-order, direction, TCP flags,
  interface and comment presence
- Frames tab in the bottom evidence inspector: native Table with sortable headers
  and alternating rows; selecting a row loads that exact frame into Layers/Hex
  through the guarded cited-frame path; footer states bounded prefixes and
  truncated tails
…and gzip options

- CaptureFrameExporter streams whole capture / sessions / time-range scopes from
  the stable source into PCAPNG or classic PCAP, re-emitting section and
  interface metadata and copying same-byte-order frame options verbatim; gzip
  output through zlib; temp-then-rename so cancel/failure leaves no partial file
- Save panel uses the system Format pop-up on macOS 15+ (accessory pop-up on 14),
  with Scope, time-range pickers, Preserve metadata, Compress with gzip and a
  live estimate; PCAP is offered but disabled with the reason when unrepresentable
- Routes: File menu, toolbar Export menu, session row and Library row; progress
  notice with Cancel; raw-export acknowledgement shared with session export
…cap/pcapng

- Move the format readers, container properties, preview scan and PacketBuffer
  into a shared CaptureFormat/ layer compiled by the app and both extensions
- TracexyQuickLook (com.apple.quicklook.preview) renders format, size, records,
  start/elapsed, application, comment and declared interfaces; sandboxed
- TracexySpotlight (com.apple.spotlight.import) indexes format, record count,
  dates, duration, interface names and application only; sandboxed
- Import the canonical com.tcpdump.pcap / org.tcpdump.pcapng identifiers
- Extensions are embedded via Embed Foundation Extensions; CI's unsigned Release
  build and the ad-hoc test build both succeed; extension logic is unit-tested
  in the test host (rendered preview image checked)
…rames interface column, Library file-set menu

- Overview's saved-file card reads CaptureFileProperties: container by
  content, declared interface names, and fidelity/drop counters from the
  Interface Statistics Blocks (received / dropped + OS dropped), reading
  'Not recorded' when a file carries none; adds a Get Info action.
- Frames facet shows an Interface column when a pcapng declares more than
  one interface.
- Library rows of rotation-set members offer a File Set menu (Next, Previous,
  and the member list with the open file checked); every member opens in place.
- Release script verifies both app extensions carry Developer ID signatures
  and hardened runtime.
- Extension sources import the app only under TRACEXY_TEST_HOST (set on the
  TracexyTests target); canImport(Tracexy) turned into a Tracexy <-> appex
  dependency cycle once a built module sat in the products directory.
feat(assistant): add free MCP and local model workflows
Rebuild Overview as a chart-led capture report
Harden decode, session evidence and capture flows against Wireshark ground truth
@LocNguyenHuu
LocNguyenHuu merged commit 578c6d5 into main Sep 20, 2026
5 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant