Skip to content

v1.2.2 — live port monitor + hold-open in orchestrator

Choose a tag to compare

@BitF4rmer BitF4rmer released this 24 Apr 19:15
· 8 commits to main since this release

Highlights

  • PortClosedDetected event — additive to the frozen v1 schema. The bus now carries both halves of every open↔closed transition.
  • Shared PortStateTracker — single source of truth for per-(ip, port) state, used by all three engines (connect, raw userspace fallback, raw SYN race). Open emitted on first observation; close confirmed on one explicit Closed or two consecutive transient timeouts (no flap spam).
  • TUI Port Status panel — top half of the screen now shows live OPEN / FLAPPING / CLOSED state per (target, port) with a flip counter, age, last-known protocol/confidence, and the bound hold-open tunnel port.
  • Hold-open tunnel wired into live orchestrator — spawn_hold_open_manager subscribes to PortOpenDetected and stands up a DumbTunnel per catch on a loopback port (deduped by (ip, port)). Best-effort: a missing CA logs a warning and disables hold-open without failing the engagement.

Schema

portsnatcher/v1 event schema is still frozen — PortClosedDetected is additive.

Compatibility

No breaking changes from v1.2.1. CLI surface, scope file format, and bus event names unchanged. The only consumer-visible change is the new PortClosedDetected variant on the bus + JSONL artifact.

Install

Prebuilt binaries for Linux (x86_64-unknown-linux-gnu, x86_64-unknown-linux-musl), macOS (aarch64-apple-darwin), and Windows (x86_64-pc-windows-msvc) are attached below by the release workflow.

cargo install --git https://github.com/IntegSec/PortSnatcher --tag v1.2.2 --bin portsnatcher

Full changelog

https://github.com/IntegSec/PortSnatcher/blob/v1.2.2/CHANGELOG.md