Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
31 commits
Select commit Hold shift + click to select a range
460c1bc
feat(assistant): add mcp and local model workflows
LocNguyenHuu Sep 14, 2026
08f3599
fix(decoder): bound IP payloads, skip later fragments, decode VLAN tags
LocNguyenHuu Sep 15, 2026
322cee2
fix(session): record late resets, keep-alives, DNS response timing an…
LocNguyenHuu Sep 15, 2026
83a4742
fix(capture): report source read failures, stream session export, gua…
LocNguyenHuu Sep 15, 2026
8aa2d7f
feat(app): open captures from Finder or a drop, and fix window restor…
LocNguyenHuu Sep 15, 2026
9292c08
feat(ui): sort the Sessions table by column, apply the Units setting,…
LocNguyenHuu Sep 15, 2026
34ca8bf
docs: describe capture opening, orientation, sorting and the decoder …
LocNguyenHuu Sep 15, 2026
d3f0fbc
feat(overview): rebuild Overview as a chart-led capture report
LocNguyenHuu Sep 17, 2026
0a31608
Merge branch 'fix/wireshark-flow-hardening' into feat/capture-file-wo…
LocNguyenHuu Sep 19, 2026
7671824
feat(capture): fold container properties, open captures in place, ref…
LocNguyenHuu Sep 19, 2026
25f7736
chore: format new sources and split inspector toggles out of the coor…
LocNguyenHuu Sep 19, 2026
0f7d651
feat(info): add File > Get Info window with on-demand digests and per…
LocNguyenHuu Sep 19, 2026
11f6f1b
feat(inspector): add a Frames facet listing the selected session's fr…
LocNguyenHuu Sep 19, 2026
65d39de
chore: move session correlation out of the coordinator body
LocNguyenHuu Sep 19, 2026
752c545
feat(export): add File > Export Frames… with scope, format, metadata …
LocNguyenHuu Sep 19, 2026
127ac0d
feat(file): navigate ring-buffer file sets from the File menu
LocNguyenHuu Sep 19, 2026
ddbedf7
docs: describe open in place, Get Info, Frames and Export Frames; ali…
LocNguyenHuu Sep 19, 2026
7972fe6
fix(file): keep auxiliary windows out of external opens, re-check ref…
LocNguyenHuu Sep 19, 2026
d7490ef
feat(extensions): add Quick Look preview and Spotlight importer for p…
LocNguyenHuu Sep 19, 2026
7034f66
feat(file): read Overview loss and interfaces from file properties, F…
LocNguyenHuu Sep 19, 2026
b8c1d19
chore(build): ignore coverage profile artifacts
LocNguyenHuu Sep 20, 2026
3c978a4
fix(ui): defer inspector layout changes outside update pass
LocNguyenHuu Sep 20, 2026
0f61ad5
fix(assistant): keep fixtures and documentation public safe
LocNguyenHuu Sep 20, 2026
49bef5e
Merge pull request #58 from RockxyApp/feat/mcp-local-assistant
LocNguyenHuu Sep 20, 2026
ccd35e8
chore(overview): integrate current develop
LocNguyenHuu Sep 20, 2026
5570f4f
Merge pull request #62 from RockxyApp/feat/overview-traffic-dashboard
LocNguyenHuu Sep 20, 2026
31fc80c
chore(capture): integrate reviewed develop changes
LocNguyenHuu Sep 20, 2026
341be63
Merge pull request #59 from RockxyApp/fix/wireshark-flow-hardening
LocNguyenHuu Sep 20, 2026
285dbe3
chore(file): integrate current develop
LocNguyenHuu Sep 20, 2026
a41386d
test(assistant): keep review control reachable on compact displays
LocNguyenHuu Sep 20, 2026
36010ea
feat(file): integrate capture file workflow
LocNguyenHuu Sep 20, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 2 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -20,6 +20,8 @@ xcuserdata/
*.dSYM.zip
*.dSYM
timeline.xctimeline
*.profraw
*.profdata

# Swift Package Manager
.build/
Expand Down
3 changes: 3 additions & 0 deletions .swiftlint.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,9 @@
# Paths to include during linting
included:
- Tracexy
- CaptureFormat
- TracexyQuickLook
- TracexySpotlight

# Paths to exclude during linting
excluded:
Expand Down
39 changes: 39 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -8,10 +8,49 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/).

### Added

- Ask about the selected session with a local Assistant: connect a model running on this Mac, review the exact JSON before the first send, stream the answer, and click a citation to open its frame.
- Share bounded, read-only capture history with an MCP client through a bundled command-line tool scoped to one Project you grant and revoke in Settings.
- Overview plots accepted wire bytes on the capture clock and presents protocol, session, finding, host, and app summaries with routes into the investigation.
- **File → Open… (⌘O)** opens a PCAP/PCAPNG where it is, recording a reference in the Project Library instead of copying; the Open panel previews format, size, records and start/elapsed before opening, and offers **Copy into Library**. **Import into Library… (⌥⌘O)** keeps the managed-copy path.
- Referenced captures show their availability in the Library; a moved or replaced file offers **Locate…** and **Reload** inline instead of an error.
- **File → Open Recent**, **Close Capture (⇧⌘W)**, **Reload (⌘R)** when the open file changed on disk, and **File Set → Next / Previous File** for `dumpcap`/`tcpdump` rotation sets.
- **File → Get Info (⌘I)**: a capture information window with format and variant, time span and order, PCAPNG section and interface metadata (names, descriptions, filters, statistics counters), block inventory (name resolution, decryption secrets by type and size, custom, unknown), on-demand SHA-256/SHA-1 with cancel, and a Copy action.
- A **Frames** facet in the bottom inspector lists the selected session's frames (number, relative time, direction, length, TCP flags, summary, comment marker) from a bounded on-demand rescan; a row loads that exact frame into Layers/Hex.
- **File → Export Frames…** writes a new PCAPNG or classic PCAP from a scope (whole capture, sessions in view, selected session, time range), optionally preserving PCAPNG section, interface and per-frame metadata and compressing with gzip; PCAP is disabled with the reason when the source cannot be represented.
- The Context dock shows **Captured on** (the file's interface names) for sessions of multi-interface PCAPNG captures; the Frames facet adds an **Interface** column for such captures, and the Library row of a rotation-set member offers a **File Set** menu listing the set.
- Overview reads an opened file's format, interfaces, fidelity and drop counters from the file itself: the recognised container rather than the extension, the declared interface names, and loss from the Interface Statistics Blocks the capturing tool wrote (**Not recorded** when a file carries none), with a **Get Info** action in the storage card.
- A Quick Look preview extension (Finder Space-bar, Open panel preview) and a Spotlight importer for `.pcap`/`.pcapng`, both sandboxed and built on the same readers as the app; the format readers moved to a shared `CaptureFormat/` layer.
- Tracexy now imports the canonical `com.tcpdump.pcap` / `org.tcpdump.pcapng` type identifiers instead of app-private ones, so it interoperates with Wireshark's declarations.
- The PCAPNG reader now reads section and interface options, Interface Statistics Blocks and per-frame comment presence within block bounds, and counts decryption-secrets, name-resolution, custom and unknown blocks; secrets are never read.
- Open a `.pcap`, `.cap`, `.pcapng` or `.ntar` file from Finder (Open With, Dock icon) or by dropping it on the main window; the file follows the Project's Open preference (in place by default).
- Decode 802.1Q / 802.1ad VLAN-tagged Ethernet frames so trunk- and mirror-port captures form sessions.
- Sort the Sessions table by any column from its header; the default remains stable capture order.

### Fixed

- Keep Assistant disclosure toggles and reviewed JSON in sync, reject stale approval, mark output cutoffs as incomplete, and keep the synthetic walkthrough isolated from capture-helper setup.
- Defer bottom-inspector collapse and expansion until AppKit finishes the current layout pass, avoiding a window-constraint crash during SwiftUI updates.
- Bound the transport payload by the IP-declared length so Ethernet padding and trailers are no longer counted as TCP sequence space, which produced false overlap and retransmission findings and leaked into Follow Stream.
- Stop decoding a transport header out of non-first IP fragments and out of IPv4 headers shorter than 20 bytes; those frames no longer invent endpoints or sessions.
- Record a TCP reset that arrives after an orderly close as a reset observation, so a session shown as an error also carries the matching finding and evidence.
- Classify a TCP keep-alive probe as a keep-alive rather than a retransmission.
- Measure DNS latency for answerless responses (NXDOMAIN, NODATA) by the header's response bit.
- Read the classic pcap link type from the low 16 bits of its header word, so files written with an FCS-length hint open with their sessions.
- Open one main window, not two, when relaunching after a force-quit or crash.
- Expose saved-capture rows, Focus Set rows, Flow Map regions and inspector layer/field rows to VoiceOver and UI automation as activatable controls.
- Stop a live capture and say why when the capture source stops delivering (the interface went away or was reconfigured), instead of showing it as still capturing; the helper carries the reason with its final frames.
- Stream a session export from the capture file instead of loading the whole capture into memory.
- Ask before quitting while a live capture is running, as the General setting promised.
- Apply the General → Units setting to every byte figure, and honor "Restore last workspace on launch" when it is turned off.
- Keep the Focus Set editor, Noise Control and Settings windows from reopening on their own after a relaunch, and always open the workspace window after a force-quit relaunch.
- Keep a replaced helper XPC connection from being discarded by the previous connection's late invalidation.

### Changed

- Replace placeholder MCP and Assistant settings with scoped grants, activity, and local-model controls.
- Overview Protocols shows session-byte share by innermost protocol so its bars sum to the scope.
- Orient a session captured mid-stream toward the service port when no SYN was captured, so the remote host rather than this Mac's ephemeral socket reads as the destination.

## [0.7.0] - 2026-09-08

### Added
Expand Down
Loading
Loading