Skip to content

SPECTRE v0.4.7 — Operation SPECTER (Phase 4 Complete)

Choose a tag to compare

@doublegate doublegate released this 06 Feb 01:23
· 34 commits to main since this release

Highlights

Phase 4 (Operation SPECTER) is now complete with the final CyberChef-MCP v1.9.0 integration, CI/CD pipeline hardening, and dependency security remediations.

CyberChef-MCP v1.9.0 Integration

  • Submodule updated from v1.8.0 to v1.9.0 (CyberChef v10.20.0 upstream sync)
  • New ChefClient::worker_stats() trait method for querying worker thread pool statistics
  • WorkerStats type: enabled, threads, completed, waiting, utilization
  • McpChefClient::connect() passes ENABLE_WORKERS, WORKER_MAX_THREADS, ENABLE_STREAMING env vars to Docker container
  • New spectre chef worker-stats CLI subcommand
  • 689 CyberChef-MCP tests (was 563)

CI/CD Hardening

  • Fixed recursive submodule checkout failure caused by orphaned nested submodule in CyberChef-MCP v1.9.0 (ref-proj/CyberChef gitlink with no .gitmodules entry)
  • Replaced submodules: recursive with explicit git submodule update --init --depth 1 across all 6 CI jobs + release workflow
  • Modernized release workflow: replaced deprecated actions/create-release@v1 and actions/upload-release-asset@v1 with softprops/action-gh-release@v2
  • All 9 CI jobs passing

Release Build Fixes (3 Platform Failures Resolved)

  • musl (x86_64-unknown-linux-musl): Added vendored-openssl feature to compile OpenSSL from source — musl targets lack system OpenSSL headers
  • aarch64 cross-compilation (aarch64-unknown-linux-gnu): Added vendored-openssl feature — cross Docker container lacks target OpenSSL dev packages
  • Windows (x86_64-pc-windows-msvc): Added LIB env var pointing to Npcap SDK Lib\x64 directory — linker couldn't find Packet.lib
  • Feature chain: spectre-cli/vendored-openssl → spectre-core/vendored-openssl → prtip-scanner/vendored-openssl → native-tls/vendored
  • Conditional --features vendored-openssl in build commands via matrix expression
  • Conditional LICENSE packaging (Unix and Windows) for defensive robustness

Dependency & Security Remediations

  • MSRV bumped from 1.88 to 1.92 (Cargo.toml, clippy.toml, CI workflow, README)
  • time crate: 0.3.46 → 0.3.47 (fixes stack exhaustion DoS vulnerability in RFC 2822 parsing)
  • codecov/codecov-action: v4 → v5

Release Artifacts

Platform Target Archive
Linux x86_64 x86_64-unknown-linux-gnu spectre-linux-x86_64.tar.gz
Linux x86_64 (static) x86_64-unknown-linux-musl spectre-linux-x86_64-musl.tar.gz
Linux aarch64 aarch64-unknown-linux-gnu spectre-linux-aarch64.tar.gz
macOS x86_64 x86_64-apple-darwin spectre-macos-x86_64.tar.gz
macOS Apple Silicon aarch64-apple-darwin spectre-macos-aarch64.tar.gz
Windows x86_64 x86_64-pc-windows-msvc spectre-windows-x86_64.zip

Test Summary

Component Tests
SPECTRE 980 (44 CLI + 618 core + 268 TUI + 5 doc + 45 integration)
ProRT-IP 2,557
CyberChef-MCP 689
WRAITH-Protocol 2,957
Combined 7,183

Codebase Metrics

  • 122 Rust source files across 5 crates (~35,000 lines)
  • Zero clippy warnings (standard + pedantic + nursery)
  • Zero doc warnings (RUSTDOCFLAGS="-D warnings")
  • MSRV: Rust 1.92

Component Versions

Component Version Capability
ProRT-IP v1.0.0 10M+ pps network reconnaissance
CyberChef-MCP v1.9.0 463 operations via MCP protocol
WRAITH-Protocol v2.3.7 10+ Gbps E2E encrypted comms

Architecture

All three components use a 3-layer adapter pattern:

  1. Trait (public interface): Scanner, ChefClient, CommsClient
  2. Real adapter: PrtipScanner, McpChefClient, WraithNode
  3. Stub for testing: StubScanner, McpClient, StubCommsClient

What's Next

  • Phase 5: Operation SHADOW (v0.5.x) — GUI application (Tauri 2.0)
  • Phase 6: Operation WRAITH (v0.6.x) — MCP server implementation
  • Phase 7: Operation GENESIS (v1.0.0) — Production release

Full Changelog: https://github.com/doublegate/SPECTRE/blob/v0.4.7/CHANGELOG.md