v1.2.2 — live port monitor + hold-open in orchestrator
Highlights
PortClosedDetectedevent — additive to the frozen v1 schema. The bus now carries both halves of every open↔closed transition.- Shared
PortStateTracker— single source of truth for per-(ip, port)state, used by all three engines (connect, raw userspace fallback, raw SYN race). Open emitted on first observation; close confirmed on one explicitClosedor two consecutive transient timeouts (no flap spam). - TUI Port Status panel — top half of the screen now shows live OPEN / FLAPPING / CLOSED state per
(target, port)with a flip counter, age, last-known protocol/confidence, and the bound hold-open tunnel port. - Hold-open tunnel wired into live orchestrator —
spawn_hold_open_managersubscribes toPortOpenDetectedand stands up aDumbTunnelper catch on a loopback port (deduped by(ip, port)). Best-effort: a missing CA logs a warning and disables hold-open without failing the engagement.
Schema
portsnatcher/v1 event schema is still frozen — PortClosedDetected is additive.
Compatibility
No breaking changes from v1.2.1. CLI surface, scope file format, and bus event names unchanged. The only consumer-visible change is the new PortClosedDetected variant on the bus + JSONL artifact.
Install
Prebuilt binaries for Linux (x86_64-unknown-linux-gnu, x86_64-unknown-linux-musl), macOS (aarch64-apple-darwin), and Windows (x86_64-pc-windows-msvc) are attached below by the release workflow.
cargo install --git https://github.com/IntegSec/PortSnatcher --tag v1.2.2 --bin portsnatcherFull changelog
https://github.com/IntegSec/PortSnatcher/blob/v1.2.2/CHANGELOG.md