Repository navigation
Releases: techlogist1/ulpf
Release list
ULPF v0.1.0-rc3
First tagged build of ULPF, and a release candidate rather than a final: the engine
and the CLI are what they will be at v0.1.0; the desktop app is the newest part of the
tree and has had the least hand-testing.
What it is
One static binary that takes perimeter-device logs in any vendor format — firewalls,
IDS/IPS, proxies, VPN concentrators, edge routers — stores every original byte before
it tries to understand any of them, parses each event in the device's own vocabulary,
normalizes it into a pragmatic OCSF (or ECS) subset, and writes JSON Lines. Every
output line points back to the exact bytes it came from, and those bytes are
digest-chained so a stranger can re-verify them offline. A format no parser claims is
not dropped: it is clustered into a candidate parser definition a human reviews in the
embedded UI, and approval activates it without a restart.
The CLI — one file, nothing to install
| platform | asset |
|---|---|
| Linux x86-64 | ulpf-v0.1.0-rc3-x86_64-unknown-linux-musl — static-pie, no loader and no libc needed on the host |
| macOS Apple Silicon | ulpf-v0.1.0-rc3-aarch64-apple-darwin |
| Windows x86-64 | ulpf-v0.1.0-rc3-x86_64-pc-windows-msvc.exe |
SHA256SUMS covers all three. Verify before you run it:
sha256sum -c SHA256SUMS
The desktop app
ULPF_0.1.0_aarch64.dmg and ULPF_0.1.0_aarch64.app.tar.gz for macOS Apple Silicon;
ULPF_0.1.0_x64-setup.exe and ULPF_0.1.0_x64_en-US.msi for Windows.
The two Windows installers are about 267 MB, and that is deliberate rather than a
packaging fault. They carry the WebView2 runtime instead of fetching it during
install, so the app installs on a machine that has neither WebView2 nor a network
connection. The application itself is a few megabytes; the runtime is the rest.
Nothing here is signed or notarized. Gatekeeper will object on macOS
(xattr -dr com.apple.quarantine clears the download quarantine) and SmartScreen will
object on Windows (More info → Run anyway).
What ships at this tag
Fifteen device families in parsers/ — Cisco ASA, Cisco IOS, FortiGate, OpenVPN,
PAN-OS, pfSense filterlog, Check Point, Juniper SRX, SonicWall, Sophos SFOS, Squid,
Suricata EVE, ArcSight CEF, IBM LEEF, AWS CloudTrail. Every definition was written
from the vendor's own log reference, never from memory. Two output schemas in
mappings/: ocsf.toml and ecs.toml.
A parser never names a schema field and a mapping never names a vendor. That wall is
structural, and it is why adding a device does not touch the normalizer.
Numbers
The throughput figure to quote is 258,411 events/s end to end — ingest through
JSON Lines on disk — on an Apple M1 Pro at seven worker threads, with 264/264 fixture
events correct, raw store with SHA-256 and the integrity chain included. It is the
median of three runs over a 5,000,000-event, 1,526 MB mixed file, produced by the
neutral harness rather than a hand-timed loop, with the scorecard committed at
eval/results/ulpf-20260905T140426Z-33371/scorecard.md.
A later, quieter measurement on the same input and harness gave a median of 295,928
events/s. It is recorded in the README and deliberately not promoted, because no
committed scorecard pins it yet. Read 258,411 as a floor.
docs/evaluation.md has the procedure, including what machine state has to hold for a
number to mean anything.
Known issues
- Windows,
--output NUL. A run whose output path is the null device still writes
aNUL.v1.meta.jsonbeside it with aneventscount of 0. Give--outputa real
path under$env:TEMPinstead. The fix is onlane-8-windows. scripts/isolation.shandscripts/coverage.shneed Git Bash on Windows. The
demo runner does not — it is a subcommand, so runulpf.exe demodirectly.- Nothing is code-signed on any platform.
Quick start
ulpf check
ulpf run samples/*.log --store /tmp/s --output /tmp/out.jsonl --pivot on
ulpf verify --store /tmp/s
ulpf attest --store /tmp/s --out /tmp/attest.json
ulpf raw 3 --store /tmp/s
Then the UI:
mkdir -p demo/watch && ulpf serve demo/watch --store demo/store --output demo/out.jsonl
http://127.0.0.1:7878 — 0 for Flow, 1–7 for the screens behind it, ? for the map.
Copy a log file into demo/watch and the screens move within 500 ms.