Skip to content

Releases: h8rt3rmin8r/fragcap

fragcap v0.10.2

Choose a tag to compare

@github-actions github-actions released this 21 Sep 03:46
13c9230

Highlights

  • Windows Deep Capture startup and terminal observation handling are deterministic under scheduler pressure while retaining bounded queues, exact loss accounting, finite deadlines and cleanup authority.
  • Published-package certification now uses structured proxy-start and reached-client evidence for positive success, while firewall containment, process ownership, non-loopback rejection and cleanup remain strict.
  • Native product documentation and independent-review intake now have complete machine-checked contracts. This release does not claim that the external security review or final Deep Capture gate is complete.

For the complete change history, implementation details, and issue references, see the full v0.10.2 changelog.

fragcap v0.10.1

Choose a tag to compare

@github-actions github-actions released this 15 Sep 23:08
a7d2496

Highlights

  • Doctor makes slow readiness work visible with nested probe names, elapsed progress, discoverable timings and automatic slow-completion durations, while preserving final reports and repair authority.
  • Registry publication normally waits for owner review, with administrator bypass explicitly retained. Fresh checks refuse missing reviewer/tag protection or unverifiable policy before release creation and publication; checking configuration never approves a deployment.
  • Published-state checks keep candidate versions separate from actual release identity. Controlled CI and package certification do not claim field measurements, independent security approval or final Deep Capture completion.

For the complete change history, implementation details, and issue references, see the full v0.10.1 changelog.

fragcap v0.10.0

Choose a tag to compare

@github-actions github-actions released this 15 Sep 15:55
787739e

Highlights

  • Guided calibration now handles target registration, executable setup, stable candidate choices, and resumable operator pauses with fresh, separate authorization for every effect.
  • A stable version-one library API exposes the same lifecycle, adapters, typed outcomes, and cooperative cancellation without a CLI dependency.
  • Current native documentation explains packet/application authority, sensitive bundles, exact recovery, migration, and final-package certification. An independent-review handoff is ready; the audit and Deep Capture completion gate remain open.
  • Native TLS security maintenance and bounded evidence-writer batching land without weakening trust, observation, or performance limits. Operator validation uses newly published bytes, not agent-run games or installed sensitive software.

For the complete change history, implementation details, and issue references, see the full v0.10.0 changelog.

fragcap v0.9.0

Choose a tag to compare

@github-actions github-actions released this 05 Sep 05:58
ee06782

Highlights

fragcap v0.9.0 replaces Deep Capture's external proxy dependency with a native Rust implementation and completes a guarded application-inspection path for known-compatible stored targets.

  • Inspect HTTP/1.1, HTTP/2, HTTP/3, TLS, WebSocket, Server-Sent Events, gRPC, SOCKS5 TCP and UDP, and generic TCP and UDP traffic across scoped IPv4 and IPv6 routes.
  • Launch direct executables, Steam titles, and publisher-managed games under target-specific routing, with explicit compatibility calibration and proxy-bypass policy.
  • Correlate packet, process, protocol, application, loss, and cleanup evidence in bounded session artifacts, including HAR, JSON Lines, manifests, and optional client-facing TLS key logs.
  • Recover exact session-owned resources, diagnose Capture and Deep Capture independently, and validate the native path through conformance, fuzz, performance, Windows integration, packaging, and release gates.

For the complete change history, implementation details, and issue references, see the full v0.9.0 changelog.

fragcap v0.8.0

Choose a tag to compare

@github-actions github-actions released this 30 Aug 11:00
7e81f8a

Added

  • Deep Capture can now calibrate an unknown stored target in separate reachability and TLS phases, displaying and confirming every bounded effect before it starts and preserving observed facts, local bundle evidence, and cleanup outcomes.
  • Deep Capture now has a public library-first session API with side-effect-free preparation, exact-plan authorization, typed lifecycle events and reports, injectable effect adapters, bounded cleanup, and direct controlled verification; the command delegates lifecycle policy to that coordinator.
  • Capture and Deep Capture can now start an eligible stored direct executable from one prevalidated path, working directory, and argument vector. Deep Capture applies proxy variables only to that child, while warm direct targets and unsafe or stale paths remain side-effect-free refusals.

Fixed

  • Corrected the repository and documentation entry points to describe v0.7.0 accurately: Capture and Deep Capture are shipped first-class modes, contributor guidance reflects the current workspace, and issue forms use current commands, Npcap requirements, security boundaries, and planning pointers.
  • The getting-started guide now provides verified v0.7.0 paths for a first Capture and a known-compatible Deep Capture session, including current readiness output, honest compatibility refusals, bundle states, sensitive artifacts, and cleanup.
  • The public command-line reference now covers the complete v0.7.0 command, option, sink, default, and output-routing surface, with a hermetic documentation gate that catches future drift against the runtime parser.
  • The architecture guide now separates passive Capture from explicit Deep Capture, documents the shipped execution and trust boundaries, distinguishes packet truth from proxy-owned evidence, and matches current Npcap acquisition behavior.
  • The output reference now distinguishes ordinary Capture streams from the Deep Capture session bundle and documents every shipped artifact's authority, sensitivity, lifetime, omission conditions, and correlation limits.
  • Audited every production documentation route across desktop and narrow layouts, recorded accessibility and navigation evidence, and filed each material correction as a narrow follow-up issue.
  • fragcap doctor now reads manifest-backed Deep Capture CA trust from Windows current-user and local-machine Root stores, reports exact observed thumbprints and mismatches, and offers cleanup only for an exact owned trust entry.
  • Deep Capture no longer reports proxy environment propagation as confirmed merely because traffic reached the final client. Routing and propagation remain separate observations, ordinary eligibility uses current final-client routing evidence, TLS acceptance requires a correlated final-client flow, and silence remains inconclusive.
  • Corrected production documentation landmarks, keyboard bypass, generated heading hierarchy, light-theme text contrast, and architecture diagram names.
  • Corrected documentation search so retired fragcap run and fragcap tap queries lead to current command guidance while preserving release history, and added an accessible branded recovery page for missing URLs that retains HTTP status 404.

fragcap v0.7.0

Choose a tag to compare

@github-actions github-actions released this 28 Aug 03:22
d9aaec3
  • Deep Capture has a real first path. The release adds scoped proxy-inspection architecture, compatibility fact storage, doctor readiness and cleanup checks, session bundles, and the first guarded fragcap deep-capture command path.
  • Target discovery is easier to trust. Steam non-game entries are filtered, known-root discovery handles multi-engine containers, detection marks heuristic findings as unverified, warnings go to the right stream, and discovery output now renders as a readable listing.
  • Release and wrapper gates are tighter. The Bash wrapper gate delegates to the vendored standard checker, requires ShellCheck to actually run in CI, and keeps release notes focused on highlights with the full changelog as the exhaustive record.

Full changelog: https://github.com/h8rt3rmin8r/fragcap/blob/v0.7.0/CHANGELOG.md

fragcap v0.6.0

Choose a tag to compare

@github-actions github-actions released this 22 Aug 13:01
d18a456

v0.6.0 is what the first real capture found. On 2026-08-20 fragcap ran against a
Steam title for sixteen minutes and captured 18,234 packets, and that single run
produced most of this release: the capture went silent for its whole duration,
91 percent of the file turned out to belong to an unrelated background process,
and the summary reported none of it. Nearly every change below exists because
something was observed to be wrong, not because it was imagined.

  • Capture tells you what it is doing. A status block redraws in place at
    least once a second, showing elapsed time, the bound process, packets and
    bytes against any configured bound, the filter's narrowing state, every
    discard counter, and the top per-process contributors to the file so far. A
    redirected run gets a plain heartbeat instead of silence, and --json gains an
    optional capture.progress event. The sixteen-minute run whose last visible
    line was filter narrowed to 0 endpoint(s) is no longer possible.
  • A capture contains the target's traffic. It did not reliably before. Output
    is now scoped to the target, what is excluded is counted rather than dropped
    quietly, and the completion summary reports what was written per process, so a
    capture dominated by something you did not ask for is visible in the file's own
    accounting rather than only under later analysis.
  • Detection reports what it found, not what it guessed. Titles carrying no
    DRM stop being labelled "Steam DRM"; titles that genuinely ship Easy Anti-Cheat
    are now reported, which they were not, because the signatures only matched
    runtime files those titles never ship. Anti-cheat installed machine-wide as a
    Windows service is reported separately from any title's own evidence, never
    merged into it, since presence on the machine does not say which title put it
    there. A blank column now says which kind of blank it is, and a scan names what
    it did not cover. Nothing asserts a completed scan the tool cannot vouch for.
  • A Steam title keeps all three of its names. The storefront name, the
    installed folder name, and the observed launch executable, none reconstructed
    from another, and any of the three resolves the title. On a sampled library 11
    of 34 titles had a folder name that diverged from their storefront title.
    fragcap steam list also honors --json and prints column headers.
  • --help stopped lying. Every flag that has a default states it, --sink
    names every scheme it actually accepts, the documented grammar matches the
    shipped one, and four new checks in the test suite keep it that way.

Breaking: fragcap catalog update is removed. It could not run in any
released binary, and what it fetched was a third-party title list rather than any
fragcap artifact. The three catalog seed verbs collapse into one catalog seed
taking a repeatable --tier. Store paths are now overrides everywhere rather
than requirements: seven subcommands that refused to run without an explicit path
to a store fragcap already knows how to find now resolve it themselves, and every
success line names the store it touched.

Full changelog: https://github.com/h8rt3rmin8r/fragcap/blob/v0.6.0/CHANGELOG.md

fragcap v0.5.1

Choose a tag to compare

@github-actions github-actions released this 19 Aug 05:24
e2d655d

Fixed

fragcap targets (and a bare fragcap) now seed the per-user catalog from the
catalog store shipped beside the executable on first run, so a fresh install
discovers and classifies your games immediately instead of listing nothing until
a capture happened to seed it. The first-run copy of the shipped catalog lived
only on the capture path, so the documented first command every new user runs
saw no catalog in the per-user location, skipped discovery, and showed an empty
list until the store was seeded by hand; both discovery entry points now resolve
and seed the catalog through one shared step so they cannot drift again.

fragcap v0.5.0

Choose a tag to compare

@github-actions github-actions released this 18 Aug 23:43
8519653

v0.5.0 is the targeting release. fragcap now finds your installed games itself, so you no longer hand-write a profile file to capture one. Run fragcap targets to see what is on your machine, then fragcap capture <n> to capture it.

  • fragcap targets is the hero command. A bare fragcap (or fragcap targets) runs discovery, registers what it finds, and prints your titles as a numbered table with a CAPTURE column telling you which are ready to capture and a neutral KNOWN column naming the engine, anti-cheat, and DRM detected for each. The listing ends by naming the next command. An empty result prints the commands that populate it rather than an empty table.
  • Games are discovered, not described. Discovery walks Steam, and on Windows the known game-install roots across every eligible fixed volume, not just the system drive; fragcap targets scan <dir> points it at one folder. Every origin of a target sits behind one seam, so adding Epic, GOG, Xbox, or Battle.net later is a new implementor rather than a new code path. The cross-volume walk is governed by a persistent volume allowlist keyed on stable volume identity, and every listing surfaces a conserved account, so an excluded volume or an unparsable title is counted and shown rather than dropped silently.
  • Technology detection is data, not code. The engine, anti-cheat, and DRM signatures that identify a game from its install directory now live in a table in the shipped catalog database, evaluated by one generic matcher. Adding a signature of an implemented kind is honored on the next scan with no code change and no release. The bundled set covers the engines Unity, Unreal, Source, Godot, CryEngine, and RE Engine; the anti-cheat products Easy Anti-Cheat, BattlEye, Vanguard, mhyprot, nProtect GameGuard, and Xigncode3; and the DRM products Denuvo, Steam DRM, Arxan, and VMProtect. A detected product is neutral evidence, never a gate: nothing in any output frames a title as off limits or discouraged.
  • Two stores: one shipped, one yours. hint.db splits into a disposable catalog.db (shipped, replaced wholesale by a catalog refresh) and a user-owned local.db (where your targets and learned launch data accumulate). A catalog refresh never touches local.db. Resolution is fidelity-ordered, so a target you authored or that was verified on disk outranks the shipped catalog's heuristic hint for the same title.
  • One capture verb. run, tap, and watch collapse into capture, which takes exactly one of --target <selector> or --process <image>, with every other flag orthogonal. Five previously inexpressible captures (a named process into a ring buffer, a named process waited for, a registered title launched under capture, and so on) are now expressible. --help groups the surface under four headings that hide nothing.
  • fragcap doctor --fix. doctor itself is unchanged, still a read-only classifier that names a remediation for every blocking failure. --fix adds an action layer above it that offers to perform those remediations one at a time under your confirmation, and only ones the report already printed.
  • Launch and observe. A target whose launch chain is unresolved can now be captured: fragcap builds a two-stage profile from the executable you did record, captures normally, and promotes the stored target to the client image that actually held the sockets.
  • The documentation describes the tool that shipped. The landing page and getting-started guide are rewritten around fragcap targets and fragcap capture <n>, ending at a capture file on disk. The specification gains an Applies-To field bound to the workspace version, and a continuous-integration gate now refuses to assemble a release whose changelog fragment claims a specification change the release diff does not contain.

Upgrading from v0.4.0

Below 1.0.0 a minor release may carry breaking changes, and this one does. There are no aliases and no deprecation shims:

v0.4.0 v0.5.0
fragcap run / tap / watch fragcap capture
--profile <file> capture selector --target <selector> or --process <image>
fragcap profile ... fragcap targets ... (schema validate still validates a JSON artifact)
fragcap steam profile <app_id> fragcap targets add --steam <app_id>
fragcap targets seed-signatures fragcap catalog seed-signatures
--hint-db / FRAGCAP_HINT_DB --catalog-db / --local-db (FRAGCAP_CATALOG_DB / FRAGCAP_LOCAL_DB)
hint.db catalog.db (shipped) plus local.db (yours)

The Wireshark extcap integration still advertises a --profile analyzer-config option; migrating it to the stored-target model is follow-up work in its own slice, because it changes the analyzer dialog contract.

Installing on Windows

  1. Download fragcap-0.5.0-x86_64.msi and its .sha256 from the assets below.
  2. Verify it: Get-FileHash fragcap-0.5.0-x86_64.msi -Algorithm SHA256 should match the value in the .sha256 file. The installer is unsigned, so Windows shows a SmartScreen "Windows protected your PC" warning with an "Unknown Publisher" note; this is expected. Choose More info, then Run anyway.
  3. Run the installer. It installs to Program Files, adds fragcap to the system PATH, and installs the catalog database. It can optionally register fragcap as a Wireshark extcap source; both registration choices are off by default.
  4. Open a new terminal (so the PATH change takes effect) and run fragcap doctor to check your setup, then fragcap targets to see your games.
  5. Live capture also needs the npcap driver, which the installer cannot bundle. Install it from https://npcap.com with WinPcap API-compatible mode enabled, which is not the default; fragcap doctor names it if it is missing, and fragcap doctor --fix offers to fetch and launch the vendor's own installer for you. Current npcap installs loopback capture support automatically, so there is no separate loopback option to enable.

Prefer no installer? Download the portable fragcap-0.5.0-x86_64-pc-windows-msvc.zip instead and run fragcap.exe from the unzipped folder; it carries the catalog database beside the binary.

Full changelog: https://github.com/h8rt3rmin8r/fragcap/blob/v0.5.0/CHANGELOG.md

fragcap v0.4.0

Choose a tag to compare

@github-actions github-actions released this 14 Aug 23:37
2425560

v0.4.0 makes fragcap a first-class Wireshark capture source and makes fragcap doctor tell the truth about your setup, on top of a documentation, schema, and
brand pass.

  • Wireshark extcap integration. fragcap can register itself as a Wireshark
    extcap capture source, so it shows up as a capture interface inside Wireshark.
    Register it from the CLI with fragcap extcap install / fragcap extcap uninstall (with --user or --system scope), or let the Windows installer
    do it as an optional, off-by-default step (per user, or machine wide for
    administrators when Wireshark is detected).
  • fragcap doctor tells the truth and reads clearly. doctor now lists your
    real capture-capable interfaces and actual loopback support instead of
    placeholders. It identifies itself (its version and the binary, profile, and
    hint database paths it is using), colorizes status, and wraps to the terminal
    width. When the extcap integration is not registered, it names the Wireshark
    download page (which also provides the required npcap driver) alongside
    fragcap extcap install. Output stays plain under redirection, NO_COLOR, or
    --json, and recognizes a machine-wide registration, not only a per-user one.
  • Documentation you can follow. The documentation site renders theme-aware
    Mermaid diagrams from the same fenced source that renders on GitHub, the
    Getting Started guide gains an annotated install walkthrough built from real
    installer screenshots, and the external-dependency model (npcap required,
    Wireshark recommended, the extcap integration optional) is single-sourced so
    the tool and the docs cannot drift.
  • Schema, brand, and housekeeping. The master profile schema's identifier is
    corrected to the project's real domain, the vendored brand kit moves to v1.1.0
    (a semantic token layer, components, and guidelines, with every brand
    immutable unchanged), and the Windows executable now carries a proper
    FileVersion resource.

Installing on Windows

  1. Download fragcap-0.4.0-x86_64.msi and its .sha256 from the assets below.
  2. Verify it: Get-FileHash fragcap-0.4.0-x86_64.msi -Algorithm SHA256 should
    match the value in the .sha256 file. The installer is unsigned, so Windows
    shows a SmartScreen "Windows protected your PC" warning with an "Unknown
    Publisher" note; this is expected. Choose More info, then Run anyway.
  3. Run the installer. It installs to Program Files, adds fragcap to the system
    PATH, and installs the hint database. It can optionally register fragcap as a
    Wireshark extcap source; both registration choices are off by default.
  4. Open a new terminal (so the PATH change takes effect) and run
    fragcap doctor to check your setup.
  5. Live capture also needs the npcap driver, which the installer cannot
    bundle. Install it from https://npcap.com (the installer links it on
    completion) with WinPcap API-compatible mode enabled, which is not the
    default; fragcap doctor names it if it is missing. Current npcap installs
    loopback capture support automatically, so there is no separate loopback
    option to enable.

Prefer no installer? Download the portable
fragcap-0.4.0-x86_64-pc-windows-msvc.zip instead and run fragcap.exe from the
unzipped folder; it carries the hint database beside the binary.

Full changelog: https://github.com/h8rt3rmin8r/fragcap/blob/v0.4.0/CHANGELOG.md