| Unify process identity and harden launch readiness - Unify logical process identity across collector ingestion, trace membership, storage, export, semantic lineage, and process-tree reconciliation. - Keep lifecycle collection free of exec-time procfs enrichment and preserve namespace-native TLS identity observations. - Refactor process and real-agent E2E helpers around logical identities, action snapshots, and concurrent launch sessions. - Add a daemon control-plane TLS launch-plan query and cache, with ctl diagnostics and timing, so repeated launches avoid local rescans. - Add per-profile daemon startup host-eBPF load preflight and use verified readiness for launch permission selection. - Bound direct socket payload capture for verifier-safe eBPF loading and retain staged preflight verification. Co-Authored-By: GPT-5.5 | 8 天前 |
| Improve LLM payload capture and onboarding - Preserve request tool-call content and complete Anthropic SSE responses when stop_reason arrives. - Centralize the TLS unknown-stream default, lower it to 1MiB, and let tests inherit the product default. - Rewrite README and quickstart around init/start/launch/web, add a release install helper, and collapse duplicated default config in docs and examples. Co-Authored-By: GPT-5.5 | 14 天前 |
| Improve TLS capture runtime and LLM codec plugins - Add WASM LLM codec ABI/runtime support, Qoder/noop plugin fixtures, and Chinese operator docs. - Harden TLS payload sync across launch dependency resolution, mount namespaces, wrapped musl targets, and AArch64 trampoline relocation. - Refactor probe runtime flow control for HTTP/1, HTTP/2, text payload bounds, loader execution, and unwind stubs. - Tighten LLM projection parsing for codec overrides, reasoning token details, and bounded request/response body summaries. - Expand E2E coverage for multi-libc wrappers, namespaced TLS lookup, polluted env wrappers, TLS flow reset, and xiaoo scenarios. - Update install/build scripts, runtime dependency checks, web insight limits, and README/docs references. Co-Authored-By: GPT-5.5 | 11 天前 |
| Unify process identity and harden launch readiness - Unify logical process identity across collector ingestion, trace membership, storage, export, semantic lineage, and process-tree reconciliation. - Keep lifecycle collection free of exec-time procfs enrichment and preserve namespace-native TLS identity observations. - Refactor process and real-agent E2E helpers around logical identities, action snapshots, and concurrent launch sessions. - Add a daemon control-plane TLS launch-plan query and cache, with ctl diagnostics and timing, so repeated launches avoid local rescans. - Add per-profile daemon startup host-eBPF load preflight and use verified readiness for launch permission selection. - Bound direct socket payload capture for verifier-safe eBPF loading and retain staged preflight verification. Co-Authored-By: GPT-5.5 | 8 天前 |
| Improve TLS capture runtime and LLM codec plugins - Add WASM LLM codec ABI/runtime support, Qoder/noop plugin fixtures, and Chinese operator docs. - Harden TLS payload sync across launch dependency resolution, mount namespaces, wrapped musl targets, and AArch64 trampoline relocation. - Refactor probe runtime flow control for HTTP/1, HTTP/2, text payload bounds, loader execution, and unwind stubs. - Tighten LLM projection parsing for codec overrides, reasoning token details, and bounded request/response body summaries. - Expand E2E coverage for multi-libc wrappers, namespaced TLS lookup, polluted env wrappers, TLS flow reset, and xiaoo scenarios. - Update install/build scripts, runtime dependency checks, web insight limits, and README/docs references. Co-Authored-By: GPT-5.5 | 11 天前 |
| feat: container permission auto-selection (host-eBPF × seccomp-notify) Introduce independent --host-ebpf and --seccomp-notify policies, each supporting auto|required|disabled. - Let actrailctl probe the container seccomp-notify path and let the daemon combine that result with host collector state and operator configuration to return the selected immutable profile and effective launch switches. - Keep automatic degradation explicit, with required permissions failing loud and disabled permissions never binding. - Bind the kernel-authenticated peer principal to trace ownership for control operations and TLS-sync ingestion. - Add the self-contained deploy/container-auto Docker bundle, custom seccomp profile, permission-matrix E2E, and cross-container isolation coverage without replacing the master deployment layout. - Replace the unreleased legacy launch flags, preserve existing track-add protocol compatibility, clarify deployment documentation, and bump the workspace version to 0.6.3. Validated with targeted unit tests, a release build, and the full 2x2 permission matrix plus cross-container isolation E2E on x86_64 and ARM64. Co-Authored-By: Claude Fable 5 | 18 天前 |
| fix: harden perf decoding and daemon startup Co-Authored-By: gpt-5.6-sol | 6 天前 |
| Add perf buffer eBPF event transport and auto-select event transport | 20 天前 |
| Prepare AcTrail 0.5.0 - Bump workspace version to 0.5.0 - Add containerized launch and bounded concurrent process support - Compress file scan and LLM request recording storage - Improve semantic action projection and action-tree visualization - Harden TLS payload capture, cleanup guards, and CLI/web flows Co-Authored-By: GPT-5.5 | 28 天前 |
| Unify process identity and harden launch readiness - Unify logical process identity across collector ingestion, trace membership, storage, export, semantic lineage, and process-tree reconciliation. - Keep lifecycle collection free of exec-time procfs enrichment and preserve namespace-native TLS identity observations. - Refactor process and real-agent E2E helpers around logical identities, action snapshots, and concurrent launch sessions. - Add a daemon control-plane TLS launch-plan query and cache, with ctl diagnostics and timing, so repeated launches avoid local rescans. - Add per-profile daemon startup host-eBPF load preflight and use verified readiness for launch permission selection. - Bound direct socket payload capture for verifier-safe eBPF loading and retain staged preflight verification. Co-Authored-By: GPT-5.5 | 8 天前 |
| Capture live OTEL spans and TLS payloads Add AcTrail runtime, storage, viewer, and example workflows for live observation. Document operation paths and clean up obsolete fork tracepoints. | 1 个月前 |
| Fix launch compatibility and TLS sync layering - Treat legacy open and creat tracepoints as platform-optional so kernels without those syscall tracepoint ids can still launch while keeping openat required for filesystem access observation. - Keep LD_AUDIT as the default dynamic-link TLS collection path and isolate audit namespace initialization from executable inline hook installation. Allow dynamic library binding and supplemental executable hooks to coexist while skipping duplicate AcTrail inline patches across SSL and rustls paths. - Remove default agent prewarm hints to avoid launch-time binary scans. Report per-artifact and total freed sizes from actrailctl clean. - Fix fork tracepoint child pid offset Co-Authored-By: GPT-5.5 | 1 个月前 |
| fix: harden perf decoding and daemon startup Co-Authored-By: gpt-5.6-sol | 6 天前 |
| Prepare AcTrail 0.5.0 - Bump workspace version to 0.5.0 - Add containerized launch and bounded concurrent process support - Compress file scan and LLM request recording storage - Improve semantic action projection and action-tree visualization - Harden TLS payload capture, cleanup guards, and CLI/web flows Co-Authored-By: GPT-5.5 | 28 天前 |