Changelog0.9.0

Fixed

Fixed in fragcap 0.9.0.

  • Keeps the scoped HTTP/3 integration shuttle alive through association cleanup so terminal QUIC accounting cannot race an otherwise complete exchange.

  • The production accessibility audit now follows the generated v0.9.0 route count and distinguishes real skip-link navigation from unrelated framework prefetch requests.

  • Release validation now preserves the exact measured version and binary identity of historical Windows physical evidence while keeping explicit current-release validation strict.

  • Session bundle directory creation is now an explicit artifact-owner operation instead of an accidental side effect of starting the former external proxy.

  • Steam protocol launches are refused before effects while native child-scoped routing cannot be guaranteed; issue #308 owns the platform-client routing strategy.

  • Native observations again join the packet-side flow registry for real targets, while controlled observations carry the exact spawned child process identifier rather than the parent CLI identifier.

  • HTTP/1.1 clients using Expect: 100-continue no longer deadlock behind a withheld request body, and every parsed request retains metadata evidence when later forwarding or response handling fails.

  • Native Deep Capture now proxies multiplexed HTTP/2 over the separately verified TLS boundaries with distinct connection and stream identity, bounded flow control, and stream-local terminal evidence.

  • HTTP observations now retain protocol-faithful metadata. HTTP/1.1 keeps wire order and casing; HTTP/2 keeps typed pseudo-fields, binary-safe values, and the duplicate ordering exposed after decompression while naming unavailable HPACK representation explicitly.

  • Request and response bodies now produce bounded incremental raw evidence independently from forwarding capacity, with separate bounded gzip, zlib-deflate, and Brotli transformation records.

  • application.jsonl version 2 is appended and flushed during the session, remains prefix-readable after interruption, and uses exactly one reconciling trailer to mark orderly writer completion.

  • HTTP/2 connection-driver tasks abort with their owning connection rather than detaching during forced shutdown.

  • CONNECT tunnels negotiate the client protocol first and offer exactly that ALPN to the verified origin, preserving HTTP/1.1-only clients against dual-protocol origins.

  • Tunneled HTTP/2 requests cannot address an authority other than the authenticated CONNECT destination.

  • Active HTTP/2 streams prevent the new-stream accept timer from terminating their connection, while each stream retains its own progress timeout.

  • HTTP/1.1 body failures now emit partial body evidence and an error-specific stream terminal.

  • Body retention and decoder limits are shared across the entire session, including HTTP/1.1, and queue-dropped body evidence retains byte and stream-level loss accounting.

  • Added bounded native WebSocket inspection over verified HTTP/1.1 upgrades and HTTP/2 extended CONNECT, including raw frames, masking, fragmentation, derived messages, UTF-8 validation, and per-message DEFLATE outcomes.

  • Added incremental Server-Sent Events fields, comments, event dispatch, last-event identifiers, and retry metadata without buffering an indefinite response.

  • Added schema-free gRPC call, opaque message-envelope, compression-flag, and terminal-status observations over HTTP/2.

  • Added explicit native client-facing TLS 1.2 and TLS 1.3 key logs at the protected final bundle path, with live flushing and exact session status.

  • Added operator-supplied upstream mutual-TLS identities and evidence-backed refusal categories without target key discovery or certificate-pinning bypass.

  • Added protected bundle preparation, bounded sensitive-action recovery, confirmed exact cleanup, and atomic share-on-copy with a transformation manifest.

  • Added fragcap bundle cleanup and fragcap bundle export for completed Deep Capture evidence.

Native Deep Capture now reconciles accepted proxy connections with timestamped packet and process evidence, projects bounded truthful HAR 1.2 from finalized application records, and publishes a validated version 2 bundle manifest with explicit artifact authority, completeness, loss, correlation, and omissions.

Deep Capture now authorizes an explicit target-scoped routing plan, synchronizes resource ownership before external effects, recovers only exactly owned residue, and publishes complete proxy and cleanup lifecycle streams with a derived cleanup summary.

Native Deep Capture now carries a closed HTTP and TLS conformance matrix with independent client and origin lineages, exact expected and observed results, zero skipped required rows, complete artifact reconciliation, committed synthetic evidence, and required unmodified TShark consumption.

Capture and Deep Capture now prepare one exact stored publisher-launcher chain, start only its cold root with child-scoped routing, bind declared intermediate ancestry by canonical executable path, refuse competing stage matches, and keep a finite launch deadline active until the sole terminal client binds.

Deep Capture now owns a proven-cold Steam client before dispatching a stored title: it starts the exact platform root with child-scoped routing, observes that created process, dispatches the title once, and grants terminal ownership only to the declared client beneath the owned platform ancestry.

  • Add an explicit deep-capture --restart-warm workflow that waits while the operator closes a warm direct, Steam, or publisher application normally, then re-prepares and separately authorizes the corresponding cold session.

  • Add session-authenticated SOCKS5 TCP CONNECT for IPv4, IPv6, and proxy-resolved domain destinations on the shared native Deep Capture listener, with bounded byte-transparent relay, half-close, cancellation, typed evidence, and child-scoped socks5h routing.

  • Add authenticated SOCKS5 UDP ASSOCIATE with control-owned lifetime, IPv4, IPv6, and proxy-resolved domain forwarding, immutable client pinning, and bounded exact peer mappings (#311).

  • Add bounded directional generic TCP and non-HTTP TLS evidence with explicit plaintext, opaque encrypted, or intercepted decrypted provenance (#312).

  • Add bounded, boundary-faithful generic UDP payload evidence for authenticated SOCKS5 associations, including exact direction, sequence, endpoints, timing, retention outcomes, and loss accounting while preserving complete forwarding (#313).

  • Added scoped native QUIC and HTTP/3 inspection with immutable connection pairs, bounded stream and datagram evidence, and explicit unsafe-case refusals (#314).

  • Add explicit IPv4 or IPv6 Deep Capture loopback selection, exact family-bearing routes and lifecycle evidence, scoped IPv6 literal support, canonical mapped-address ownership, and independent Doctor readiness (#315).

  • Add schema-versioned protocol classification across every shipped Deep Capture traffic family, with separately reconciled detection, inspectability, stable reasons, and typed artifact omissions (#316).

Complete native Deep Capture compatibility calibration across exact launch, routing, IPv4 or IPv6 loopback, and shipped protocol cases. Calibration plans, events, stored facts, target detail, compatibility artifacts, and manifests now carry the selected case dimensions.

Add explicit target-scoped proxy bypass policy for DNS domains, IP addresses, CIDRs, ports, and IPv6. Bare and leading-dot domains both include descendants so the reviewed policy matches conventional NO_PROXY behavior. Plans and bundles expose canonical operator rules, exact listener infrastructure, complete child environment ownership, DNS decision boundaries, and routing-decision accounting.

Add a bounded, versioned process lifecycle stream for managed Deep Capture sessions. Launch receipts, relevant process starts and exits, query-only snapshots, stage transitions, packet-derived socket-owner intervals, and the terminal outcome now reconcile through stable process-instance and flow anchors. The final trailer drives compatibility and manifest truth.

Add independent Capture and Deep Capture Doctor verdicts plus one bounded native runtime inventory. Resource journals and session-owner records now distinguish healthy history, active work, stale obligations, cleanup failures, unknown evidence, and unsupported runtime state without turning a scan limit into a clean result.

  • Added a versioned native Deep Capture threat registry and cargo xtask threat-model gate that bind every high-risk abuse case to owned controls, evidence, and exact executable negative tests.

  • Added automatic review-drift checks for the exhaustive shipped protocol families and every direct normal or Windows-target fragcap-proxy dependency.

  • Added six coverage-guided targets and deterministic stable replay for twenty fragcap-owned native protocol, state-machine, and artifact parser surfaces.

  • Added a versioned surface registry, minimized synthetic corpora, an exact-pinned bounded CI matrix, and cargo xtask fuzz drift and corpus checks.

  • Added a versioned, executable native failure registry with thirty generated scenarios spanning both sides of seven journaled effects and eight lifecycle transitions.

  • Added cargo xtask failure-matrix to validate ten controlled failure families, seven independently asserted outcome authorities, production effect and lifecycle-edge drift, and exact executable test evidence in ordinary CI.

  • Early session failure after native proxy acquisition now performs the bounded listener stop exactly once before runtime cleanup, preserving the journaled cleanup and recovery contract.

  • Terminal reports now retain the exact ordered lifecycle edge trace used by the generated matrix, and boundary failures cannot leave a complete outcome.

  • Add a reviewed fourteen-row native Deep Capture performance registry, release campaign harness, Windows and Ubuntu short gate, genuine Windows two-hour soak profile, and bounded runtime failure, connection-task, leaf-cache, and application-queue accounting. (#326)

  • Add a closed native Windows integration matrix with finite hosted and explicitly authorized physical rows, staged official-feature binary validation, exact effect cleanup, and sanitized release evidence. (#327)

Keeps native proxy task ownership finite under sustained loopback traffic and makes stop return within its caller-provided budget while retaining timed-out owner threads for a later cleanup retry.

Keeps the packet-sink test helpers clean under the pinned Rust 1.96 Clippy rules by using the standard integer divisibility operation.

Native application-stream validation now waits for accepted records to become readable instead of assuming the asynchronous writer flushes within 20 milliseconds, preventing intermittent Windows CI failures.

Native controlled-proxy validation now waits for connection workers to finish before checking their final HTTP and HTTPS observations, preventing intermittent Windows CI failures.