Skip to content

Releases: techlogist1/ulpf

Release list

ULPF v0.1.0-rc3

ULPF v0.1.0-rc3 Pre-release
Pre-release

Choose a tag to compare

@github-actions github-actions released this 07 Sep 17:38

First tagged build of ULPF, and a release candidate rather than a final: the engine
and the CLI are what they will be at v0.1.0; the desktop app is the newest part of the
tree and has had the least hand-testing.

What it is

One static binary that takes perimeter-device logs in any vendor format — firewalls,
IDS/IPS, proxies, VPN concentrators, edge routers — stores every original byte before
it tries to understand any of them, parses each event in the device's own vocabulary,
normalizes it into a pragmatic OCSF (or ECS) subset, and writes JSON Lines. Every
output line points back to the exact bytes it came from, and those bytes are
digest-chained so a stranger can re-verify them offline. A format no parser claims is
not dropped: it is clustered into a candidate parser definition a human reviews in the
embedded UI, and approval activates it without a restart.

The CLI — one file, nothing to install

platform asset
Linux x86-64 ulpf-v0.1.0-rc3-x86_64-unknown-linux-musl — static-pie, no loader and no libc needed on the host
macOS Apple Silicon ulpf-v0.1.0-rc3-aarch64-apple-darwin
Windows x86-64 ulpf-v0.1.0-rc3-x86_64-pc-windows-msvc.exe

SHA256SUMS covers all three. Verify before you run it:

sha256sum -c SHA256SUMS

The desktop app

ULPF_0.1.0_aarch64.dmg and ULPF_0.1.0_aarch64.app.tar.gz for macOS Apple Silicon;
ULPF_0.1.0_x64-setup.exe and ULPF_0.1.0_x64_en-US.msi for Windows.

The two Windows installers are about 267 MB, and that is deliberate rather than a
packaging fault.
They carry the WebView2 runtime instead of fetching it during
install, so the app installs on a machine that has neither WebView2 nor a network
connection. The application itself is a few megabytes; the runtime is the rest.

Nothing here is signed or notarized. Gatekeeper will object on macOS
(xattr -dr com.apple.quarantine clears the download quarantine) and SmartScreen will
object on Windows (More info → Run anyway).

What ships at this tag

Fifteen device families in parsers/ — Cisco ASA, Cisco IOS, FortiGate, OpenVPN,
PAN-OS, pfSense filterlog, Check Point, Juniper SRX, SonicWall, Sophos SFOS, Squid,
Suricata EVE, ArcSight CEF, IBM LEEF, AWS CloudTrail. Every definition was written
from the vendor's own log reference, never from memory. Two output schemas in
mappings/: ocsf.toml and ecs.toml.

A parser never names a schema field and a mapping never names a vendor. That wall is
structural, and it is why adding a device does not touch the normalizer.

Numbers

The throughput figure to quote is 258,411 events/s end to end — ingest through
JSON Lines on disk — on an Apple M1 Pro at seven worker threads, with 264/264 fixture
events correct, raw store with SHA-256 and the integrity chain included. It is the
median of three runs over a 5,000,000-event, 1,526 MB mixed file, produced by the
neutral harness rather than a hand-timed loop, with the scorecard committed at
eval/results/ulpf-20260905T140426Z-33371/scorecard.md.

A later, quieter measurement on the same input and harness gave a median of 295,928
events/s. It is recorded in the README and deliberately not promoted, because no
committed scorecard pins it yet. Read 258,411 as a floor.

docs/evaluation.md has the procedure, including what machine state has to hold for a
number to mean anything.

Known issues

  • Windows, --output NUL. A run whose output path is the null device still writes
    a NUL.v1.meta.json beside it with an events count of 0. Give --output a real
    path under $env:TEMP instead. The fix is on lane-8-windows.
  • scripts/isolation.sh and scripts/coverage.sh need Git Bash on Windows. The
    demo runner does not — it is a subcommand, so run ulpf.exe demo directly.
  • Nothing is code-signed on any platform.

Quick start

ulpf check
ulpf run samples/*.log --store /tmp/s --output /tmp/out.jsonl --pivot on
ulpf verify --store /tmp/s
ulpf attest --store /tmp/s --out /tmp/attest.json
ulpf raw 3 --store /tmp/s

Then the UI:

mkdir -p demo/watch && ulpf serve demo/watch --store demo/store --output demo/out.jsonl

http://127.0.0.1:7878 — 0 for Flow, 1–7 for the screens behind it, ? for the map.
Copy a log file into demo/watch and the screens move within 500 ms.