)]}'
{
  "log": [
    {
      "commit": "d6354135aaa17ef9d3405a838408c5f0fc2d4366",
      "tree": "1e1eab9e980dddd159f08f72100c40660733f1ee",
      "parents": [
        "904a9aad9b72293c8108a3328056283d85b2b806",
        "f01f78f401d40757d6a66a05b0db89c70ab6d02a"
      ],
      "author": {
        "name": "android-build-automerger-merge-worker@system.gserviceaccount.com",
        "email": "android-build-automerger-merge-worker@system.gserviceaccount.com",
        "time": "Tue Jul 21 15:21:52 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Tue Jul 21 15:21:52 2026 -0700"
      },
      "message": "Merge \"Upgrade libcap-ng to v0.9.3 am: 0d4df181f5\" into main-kernel"
    },
    {
      "commit": "f01f78f401d40757d6a66a05b0db89c70ab6d02a",
      "tree": "1e1eab9e980dddd159f08f72100c40660733f1ee",
      "parents": [
        "904a9aad9b72293c8108a3328056283d85b2b806",
        "0d4df181f5e5bb457c8caa1afe3eeb7d30583d2a"
      ],
      "author": {
        "name": "Joey Scarr",
        "email": "jsca@google.com",
        "time": "Tue Jul 21 15:21:46 2026 -0700"
      },
      "committer": {
        "name": "android-build-automerger-merge-worker@system.gserviceaccount.com",
        "email": "android-build-automerger-merge-worker@system.gserviceaccount.com",
        "time": "Tue Jul 21 15:21:46 2026 -0700"
      },
      "message": "Upgrade libcap-ng to v0.9.3 am: 0d4df181f5\n\nOriginal change: https://googleplex-android-review.googlesource.com/c/platform/external/libcap-ng/+/41059823\n\nChange-Id: I15f0483b75009ef49e2ee22edf19c2648dae5203\nSigned-off-by: Automerger Merge Worker \u003candroid-build-automerger-merge-worker@system.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "0d4df181f5e5bb457c8caa1afe3eeb7d30583d2a",
      "tree": "1e1eab9e980dddd159f08f72100c40660733f1ee",
      "parents": [
        "525bd9c55e1d9dee10a495b3978b502449cc112f",
        "0ab44af5a23e8edb69a39c0dc803ce4395ff2086"
      ],
      "author": {
        "name": "Joey Scarr",
        "email": "jsca@google.com",
        "time": "Mon Jul 20 04:22:25 2026 +0000"
      },
      "committer": {
        "name": "Joey Scarr",
        "email": "jsca@google.com",
        "time": "Mon Jul 20 21:57:34 2026 +0000"
      },
      "message": "Upgrade libcap-ng to v0.9.3\n\nRan `./autogen.sh \u0026\u0026 ./configure` after external_updater.\n\nThis project was upgraded with external_updater.\nUsage: tools/external_updater/updater.sh update external/libcap-ng\nFor more info, check https://cs.android.com/android/platform/superproject/main/+/main:tools/external_updater/README.md\n\nBug: 534939361\nTest: TreeHugger\nChange-Id: Id2e1878f5bbc5be1e87acec3cf4f533eddf9bcbc\n"
    },
    {
      "commit": "904a9aad9b72293c8108a3328056283d85b2b806",
      "tree": "9556c46d76a54324871c0b16229b669052d11c3d",
      "parents": [
        "8dd5e09d5faf27a871e8654ddaa2d2af7c696578",
        "01a224348e3e408eccee4e6036937a683c6d684e"
      ],
      "author": {
        "name": "android-build-automerger-merge-worker@system.gserviceaccount.com",
        "email": "android-build-automerger-merge-worker@system.gserviceaccount.com",
        "time": "Mon Apr 20 17:46:26 2026 -0700"
      },
      "committer": {
        "name": "Gerrit Code Review",
        "email": "noreply-gerritcodereview@google.com",
        "time": "Mon Apr 20 17:46:26 2026 -0700"
      },
      "message": "Merge \"Update Android METADATA am: 525bd9c55e\" into main-kernel"
    },
    {
      "commit": "01a224348e3e408eccee4e6036937a683c6d684e",
      "tree": "9556c46d76a54324871c0b16229b669052d11c3d",
      "parents": [
        "8dd5e09d5faf27a871e8654ddaa2d2af7c696578",
        "525bd9c55e1d9dee10a495b3978b502449cc112f"
      ],
      "author": {
        "name": "Kate Ageeva",
        "email": "evageeva@google.com",
        "time": "Mon Apr 20 17:46:16 2026 -0700"
      },
      "committer": {
        "name": "android-build-automerger-merge-worker@system.gserviceaccount.com",
        "email": "android-build-automerger-merge-worker@system.gserviceaccount.com",
        "time": "Mon Apr 20 17:46:16 2026 -0700"
      },
      "message": "Update Android METADATA am: 525bd9c55e\n\nOriginal change: https://googleplex-android-review.googlesource.com/c/platform/external/libcap-ng/+/39452823\n\nChange-Id: I7ae1d91e28f16011e8170a264baa687584ae0b5d\nSigned-off-by: Automerger Merge Worker \u003candroid-build-automerger-merge-worker@system.gserviceaccount.com\u003e\n"
    },
    {
      "commit": "525bd9c55e1d9dee10a495b3978b502449cc112f",
      "tree": "9556c46d76a54324871c0b16229b669052d11c3d",
      "parents": [
        "8dd5e09d5faf27a871e8654ddaa2d2af7c696578"
      ],
      "author": {
        "name": "Kate Ageeva",
        "email": "evageeva@google.com",
        "time": "Fri Apr 17 04:31:45 2026 +0000"
      },
      "committer": {
        "name": "Kate Ageeva",
        "email": "evageeva@google.com",
        "time": "Fri Apr 17 04:31:45 2026 +0000"
      },
      "message": "Update Android METADATA\n\nBug: 502375747\nChange-Id: I3d90de233305a225b4b83ac666167de60fb25333\n"
    },
    {
      "commit": "0ab44af5a23e8edb69a39c0dc803ce4395ff2086",
      "tree": "19546789a3431d72aa1fe696cf1808f9f64bbc75",
      "parents": [
        "f5f318a511cb9bc4a3faee18f0c0e7e2fc605673"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Apr 09 12:10:09 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Apr 09 12:16:37 2026 -0400"
      },
      "message": "Finalize libcap-ng 0.9.3 release\n"
    },
    {
      "commit": "f5f318a511cb9bc4a3faee18f0c0e7e2fc605673",
      "tree": "74aad95e82616123f4eaff0109880731f37e8232",
      "parents": [
        "1bd5eb051fd7f9ca0b58b25a3153c0b79edc8ff9"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Apr 09 12:06:49 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Apr 09 12:16:27 2026 -0400"
      },
      "message": "update man page and bash completions for cap-audits -h option\n"
    },
    {
      "commit": "1bd5eb051fd7f9ca0b58b25a3153c0b79edc8ff9",
      "tree": "e75ccb9ad8c3f949b9c69bd217ec87a426573909",
      "parents": [
        "bed7b57c745a57e535f3f5eef08f7e72a3ed1bcb"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Apr 09 11:57:55 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Apr 09 12:16:15 2026 -0400"
      },
      "message": "add experimantal notice to cap-audit\n"
    },
    {
      "commit": "bed7b57c745a57e535f3f5eef08f7e72a3ed1bcb",
      "tree": "e9e42bb5db10a1ae729a547e38147493e0c12ec5",
      "parents": [
        "d3d114fe5741ed2cee4d9f00f2970a5ea1e58e43"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Apr 09 11:49:26 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Apr 09 12:16:01 2026 -0400"
      },
      "message": "update changelog\n"
    },
    {
      "commit": "d3d114fe5741ed2cee4d9f00f2970a5ea1e58e43",
      "tree": "33d545dba4abbf30af419382fc0793afb681e1fb",
      "parents": [
        "28923a208dabacad8997b468e39f39fff925f1eb"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Apr 09 11:48:54 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Apr 09 12:15:47 2026 -0400"
      },
      "message": "filecap: add path-to-fd consistency check in capability write path\n"
    },
    {
      "commit": "28923a208dabacad8997b468e39f39fff925f1eb",
      "tree": "ab5d4ecae2c7d1798f6ced3b01c497634e53bb5d",
      "parents": [
        "2a95af69f4a6e29a4b85df84185166c1916ced99"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Apr 01 22:16:53 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Apr 09 12:15:17 2026 -0400"
      },
      "message": "Limit COLUMNS to 400\n"
    },
    {
      "commit": "2a95af69f4a6e29a4b85df84185166c1916ced99",
      "tree": "b84ee932c1721cc76045ae9a0c6ee304ba5478a4",
      "parents": [
        "041dbc7c8ef8d9f6fd7c9d41841eb5b184b853f9"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 31 22:41:14 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 31 22:41:14 2026 -0400"
      },
      "message": "Limit COLUMNS to 400\n"
    },
    {
      "commit": "041dbc7c8ef8d9f6fd7c9d41841eb5b184b853f9",
      "tree": "5989359616ffcfb74546bda54ae2972a556926df",
      "parents": [
        "dc960ab5c4f97f4794ad7a21f938b7a0a0a21715"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 29 15:56:56 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 29 15:56:56 2026 -0400"
      },
      "message": "clarify CAPNG_DROP_SUPP_GRP documentation to match the code\n"
    },
    {
      "commit": "dc960ab5c4f97f4794ad7a21f938b7a0a0a21715",
      "tree": "9a30b8e98ea959f114b9596f2a4d0ed9bb28e381",
      "parents": [
        "6f7ec491e1adb83421f742f92d722376cdbc6e6d"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 29 15:53:06 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 29 15:53:06 2026 -0400"
      },
      "message": "cap-ng: track temporary helper capabilities per set in change_id\n\nTrack temporary CAP_SETPCAP, CAP_SETUID, and CAP_SETGID additions\nseparately for the effective and permitted sets in capng_change_id()\n\nThe previous helper tracking only checked whether a capability was\npresent in the effective set and later dropped it from both\neffective and permitted. That could remove a caller-requested final\npermitted capability when the helper was only added temporarily to\neffective.\n\nUse an internal bitmap to record exactly which helper bits were\nadded to which sets and only drop those bits during cleanup. Add a\nregression test covering a permitted-only CAP_SETPCAP request during\nbounding-set application.\n"
    },
    {
      "commit": "6f7ec491e1adb83421f742f92d722376cdbc6e6d",
      "tree": "8a20499f30f713fa5e254fbf5e70f1ef696f7f2c",
      "parents": [
        "e1a06f7d43149521f19c5abb90b0237603ff7678"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 29 14:36:57 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 29 14:36:57 2026 -0400"
      },
      "message": "rename capng_stage_supplementary_groups to capng_stage_additional_groups to make things more clear about what they are\n"
    },
    {
      "commit": "e1a06f7d43149521f19c5abb90b0237603ff7678",
      "tree": "aeb9f5dc99b04980ac305691e309d4f5d04b19a9",
      "parents": [
        "8b46073560ed72597c70f755caf17a2ab198f25e"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 28 23:04:11 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 28 23:04:11 2026 -0400"
      },
      "message": "capng: add explicit capng_change_id bounding apply flag\n\nKeep capng_change_id() backward compatible by ignoring prepared\nbounding-set state unless callers opt in with CAPNG_APPLY_BOUNDING.\nTrack whether the internal bounding set was explicitly prepared so the\nnew flag only consumes caller-staged changes and never reapplies\nimported process state. Reject CAPNG_APPLY_BOUNDING together with\nCAPNG_CLEAR_BOUNDING using a new -17 error code, while preserving the\nexisting ambient and helper-capability behavior.\n"
    },
    {
      "commit": "8b46073560ed72597c70f755caf17a2ab198f25e",
      "tree": "7c395a70300f89eb36225389e7f5bff87e7e89b4",
      "parents": [
        "df14f82f25efcadf2af08cc9803f525f3ddb5715"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 28 17:24:08 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 28 17:24:08 2026 -0400"
      },
      "message": "cap-ng: support staged supplementary groups in change_id\n\nAdd capng_stage_supplementary_groups() and a new\nCAPNG_APPLY_STAGED_SUPP_GRP flag so callers can stage a supplementary gid\nlist and have capng_change_id() apply it during the credential\ntransition.\n\nWhen CAPNG_INIT_SUPP_GRP and CAPNG_APPLY_STAGED_SUPP_GRP are combined,\nresolve the target account, build its natural supplementary groups, and\nmerge the staged gids without duplicates. Reject the invalid\nDROP_SUPP_GRP plus APPLY_STAGED_SUPP_GRP combination and assign unique\nreturn codes to all supplementary-group failure paths.\n\nTreat staged supplementary gids as one-shot internal state by clearing\nthem on every capng_change_id() return path and during deinit. Update\nthe public header, man pages, and tests for the new API and behavior.\n"
    },
    {
      "commit": "df14f82f25efcadf2af08cc9803f525f3ddb5715",
      "tree": "6bd9a27bf2345a7118630da07a29df89d92f3384",
      "parents": [
        "e78e92d451d9bee06765c816ec9405d8291cc724"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 22:02:35 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 22:02:35 2026 -0400"
      },
      "message": "renamed variables for clarity of purpose\n"
    },
    {
      "commit": "e78e92d451d9bee06765c816ec9405d8291cc724",
      "tree": "5ef4bb85915d0ec5671bbec5d89e1237ea5f6c98",
      "parents": [
        "c0e64871d59f6875790047580ca5d08f0d2fba61"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 17:40:06 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 17:40:06 2026 -0400"
      },
      "message": "update documentation\n"
    },
    {
      "commit": "c0e64871d59f6875790047580ca5d08f0d2fba61",
      "tree": "845458ab54e1aa43483a37b9b5bc93d91d381b9c",
      "parents": [
        "fe89b7ad0df3640297c4a46e66aacf2d9fdb7cea"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 17:34:33 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 17:34:33 2026 -0400"
      },
      "message": "capng_change_id: track addition of CAP_SETPCAP\n\ncapng_change_id was not tracking if it added CAP_SETPCAP. This means it\nalways discarded it. Now it tracks that it added it and removes it only\nif it added it. This preserves the user\u0027s intent if they declared that they\nwanted the capability.\n"
    },
    {
      "commit": "fe89b7ad0df3640297c4a46e66aacf2d9fdb7cea",
      "tree": "3fe42090bd7cf772ec35491359040988cd714970",
      "parents": [
        "68615b4e88db8d6ccf31a731ffd1b403f2706f25"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 09:44:20 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 09:44:20 2026 -0400"
      },
      "message": "update changelog\n"
    },
    {
      "commit": "68615b4e88db8d6ccf31a731ffd1b403f2706f25",
      "tree": "f318a5b16dfc3f180b5ab2149f4af9fa0a2fffaa",
      "parents": [
        "08fdecaee55688f2b91ef12e64b7ef71f6eddd5c"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 09:00:52 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 09:00:52 2026 -0400"
      },
      "message": "remove the created netcap.8 in make distcheck\n"
    },
    {
      "commit": "08fdecaee55688f2b91ef12e64b7ef71f6eddd5c",
      "tree": "34e44c52db2d67ef2ac437010a085f63804c6f1e",
      "parents": [
        "7074475af243f9bcb195497038c8c298020a5bcb"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 00:09:00 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 00:09:00 2026 -0400"
      },
      "message": "update changelog\n"
    },
    {
      "commit": "7074475af243f9bcb195497038c8c298020a5bcb",
      "tree": "739f87ff53315deae94fb4b644602f3f1ea98335",
      "parents": [
        "fd76087318aefa86456c75f9fc2c5a8707e16e74"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 00:00:45 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 27 00:00:45 2026 -0400"
      },
      "message": "netcap: add --interface option to restrict analysis to a particular interface\n"
    },
    {
      "commit": "fd76087318aefa86456c75f9fc2c5a8707e16e74",
      "tree": "b7195c00e646553b15c569d68fd43ebfbf5510ed",
      "parents": [
        "dc7c62b7f707e7b99cdc5fa45be0f3bc1ce1e59b"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 23:46:36 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 23:46:36 2026 -0400"
      },
      "message": "netcap: add --list-interfaces command line option\n"
    },
    {
      "commit": "dc7c62b7f707e7b99cdc5fa45be0f3bc1ce1e59b",
      "tree": "c717356b6fb10fff95a5ca4a3072e33f0dcd4071",
      "parents": [
        "8600999280b811fb05706d86e3375cd763e44329"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 23:08:42 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 23:08:42 2026 -0400"
      },
      "message": "move bash completion from /etc/bash_completion.d/ to %{_datadir}/bash-completion/completions/\n"
    },
    {
      "commit": "8600999280b811fb05706d86e3375cd763e44329",
      "tree": "7c8bf5af2005fe59138796434a50c6bab50e0bc1",
      "parents": [
        "05a4bb68cb91253f9dbad7df45f8e3f5d5b493a5"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 22:45:14 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 22:45:14 2026 -0400"
      },
      "message": "add missing file\n"
    },
    {
      "commit": "05a4bb68cb91253f9dbad7df45f8e3f5d5b493a5",
      "tree": "b2668bf80114faf758621af0d643ed7cd3f203d5",
      "parents": [
        "4019cdb85daf90340a732fef8a208a7ca39b81ee"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 22:41:05 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 22:41:05 2026 -0400"
      },
      "message": "configure: disable netcap --advanced when vm_sockets headers are missing\n"
    },
    {
      "commit": "4019cdb85daf90340a732fef8a208a7ca39b81ee",
      "tree": "4d89d88a06097c08a7e794823a76cb3e577ef4c3",
      "parents": [
        "578424fdd37ef4cb713116ae35ddc8ddaecaa941"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 17:57:00 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 17:57:00 2026 -0400"
      },
      "message": "Update unit test\n\nAdded test to call read_process_caps before doing bit tests to\nensure it is working before we start manipulating sets.\n"
    },
    {
      "commit": "578424fdd37ef4cb713116ae35ddc8ddaecaa941",
      "tree": "08de3f0a454b2689eba1e1c126d84aed33a155cc",
      "parents": [
        "ab4b85435d1d3e3dc30a909d952024986a38ffbd"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 17:50:44 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 17:50:44 2026 -0400"
      },
      "message": "cap-audit: split userspace tool into focused source files\n\nBreak cap_audit.c into main, event processing, analysis, JSON/YAML\noutput, and shared utility modules with a common cap_audit.h header.\n\nMove shared structs, globals, and cross-file prototypes into the\nheader, keep file-local helpers static, and update the build to compile\nand link the new sources.\n"
    },
    {
      "commit": "ab4b85435d1d3e3dc30a909d952024986a38ffbd",
      "tree": "61f5c279f085e51eab4660425673b9ea0e04fac8",
      "parents": [
        "0641b970e944e7e5653143b9dcfd6c65408c10c3"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 09:03:50 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 09:03:50 2026 -0400"
      },
      "message": "cap-audit: restore final-drain shutdown noise backstop\n\nReintroduce a narrow shutdown-only filter for the last ring-buffer\ndrain after the traced process exits.\n\nThe normal always-noise filter still handles the known exec and memory\naccounting cases during steady-state processing. This change only adds\na small safety net for late SYS_ADMIN/SETPCAP events from the initial\nPID while results are being finalized.\n"
    },
    {
      "commit": "0641b970e944e7e5653143b9dcfd6c65408c10c3",
      "tree": "9fc1cd12cfb2ba30eb208086aab00120e8c24605",
      "parents": [
        "4b8786ccb73dea8313eebe4a154226f5666d66d3"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 08:54:12 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Mar 26 08:54:12 2026 -0400"
      },
      "message": "remove shutdown patch which got combined with INSTALL\n"
    },
    {
      "commit": "4b8786ccb73dea8313eebe4a154226f5666d66d3",
      "tree": "61f5c279f085e51eab4660425673b9ea0e04fac8",
      "parents": [
        "3c68bfb054095eb5fbc7086a6170a1b9c0ca1d7c"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 25 23:23:11 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 25 23:23:11 2026 -0400"
      },
      "message": "update INSTALL\n"
    },
    {
      "commit": "3c68bfb054095eb5fbc7086a6170a1b9c0ca1d7c",
      "tree": "473eaab35824bf6f87e72238d90058a179d8cf81",
      "parents": [
        "db20a8bbe3a7e6380143feb34819a51347ac8492"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 25 23:03:46 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 25 23:03:46 2026 -0400"
      },
      "message": "update changelog\n"
    },
    {
      "commit": "db20a8bbe3a7e6380143feb34819a51347ac8492",
      "tree": "5f05c87240ed119e7bafd8c6a52133dde568e3ad",
      "parents": [
        "08acc3410f42a44c04e77e14592767e6e5af3e35"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 25 22:59:39 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 25 22:59:39 2026 -0400"
      },
      "message": "cap-audit: split capability analysis across init and runtime phases\n"
    },
    {
      "commit": "08acc3410f42a44c04e77e14592767e6e5af3e35",
      "tree": "583d3d02b7d4e14f6ffcc4bcf644b21105b30e25",
      "parents": [
        "c08ad3e20cc948468c056d76b161ce1e2d3c831c"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 25 17:44:23 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 25 17:44:23 2026 -0400"
      },
      "message": "Add .gitignore file\n"
    },
    {
      "commit": "c08ad3e20cc948468c056d76b161ce1e2d3c831c",
      "tree": "2b8abefb84b5fcf7bc54e509e3b22af2bea4c255",
      "parents": [
        "8f73eec4ff303f24f51eadb09be7e1d040e5ffdd"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 24 15:06:17 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 24 15:06:17 2026 -0400"
      },
      "message": "Open the libcap-ng 0.9.3 development cycle\n"
    },
    {
      "commit": "8f73eec4ff303f24f51eadb09be7e1d040e5ffdd",
      "tree": "9f65c7a0b51f5e6b5c916351b7ca97d4c534746d",
      "parents": [
        "8e7671f3f9355cba9ead35420c9a96ed27af3c58"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 24 14:51:07 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 24 14:51:07 2026 -0400"
      },
      "message": "Finalize libcap-ng 0.9.2 release\n"
    },
    {
      "commit": "8e7671f3f9355cba9ead35420c9a96ed27af3c58",
      "tree": "9f65c7a0b51f5e6b5c916351b7ca97d4c534746d",
      "parents": [
        "cb289860e24c02a77ff71b24dd93e098ab9ee453"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 24 14:46:32 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 24 14:46:32 2026 -0400"
      },
      "message": "cap-audit: add denied syscalls to the report\n"
    },
    {
      "commit": "cb289860e24c02a77ff71b24dd93e098ab9ee453",
      "tree": "ea4081b3552e34bb939ebed0eac962881535900e",
      "parents": [
        "f3e25610dd77e12a774b8a686daeecf6e9c4dad5"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 24 14:23:05 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 24 14:23:05 2026 -0400"
      },
      "message": "remove unused workflow\n"
    },
    {
      "commit": "f3e25610dd77e12a774b8a686daeecf6e9c4dad5",
      "tree": "f42e751c64c291f196be59396a23a516184f756e",
      "parents": [
        "778c0c6629ac32321925c836cb976811878c3015"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 24 11:16:31 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 24 11:16:31 2026 -0400"
      },
      "message": "cap-audit: guard unresolved machine type\n"
    },
    {
      "commit": "778c0c6629ac32321925c836cb976811878c3015",
      "tree": "505af8a261fe1de2ae8d138fecf06f55f64266b8",
      "parents": [
        "a00949096043c6270e55f90a71dc130e155c3b8f"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 23 15:58:19 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 23 15:58:19 2026 -0400"
      },
      "message": "cap-audit: narrow NOAUDIT filtering\n\nNarrowed is_always_noise() so CAP_OPT_NOAUDIT is no longer a blanket filter; it now suppresses only the confirmed advisory memory-overcommit pattern: CAP_SYS_ADMIN on brk, mmap, mprotect, or mremap, while preserving real enforcement checks that also use NOAUDIT to avoid audit spam.\n\nUpdated the cap_audit.c file overview and the is_always_noise() function comment to explain the two filter categories, clarify that CAP_OPT_NOAUDIT means “do not audit” rather than “advisory,” and document why the syscall+capability+flag combination is required.\n\nUpdated the BPF-side overview so cap_opts is described as correlation data for userspace to identify known advisory call sites, not as a unilateral standalone filter.\n"
    },
    {
      "commit": "a00949096043c6270e55f90a71dc130e155c3b8f",
      "tree": "c5ac65f44684a1ce9223da3aa67a111fa2232020",
      "parents": [
        "427310b390d71fba9357d62b429a79da8cde91f1"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 17:06:25 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 17:06:25 2026 -0400"
      },
      "message": "Replace syscall-based filter with CAP_OPT_NOAUDIT\n\nUpdated the userspace cap-audit overview and event layout to carry cap_opts, define CAP_OPT_NOAUDIT, and explain that advisory capability probes are now filtered by the kernel’s CAP_OPT_NOAUDIT signal instead of by guessing from syscall numbers.\n\nReplaced the old syscall-number-based is_always_noise() memory-accounting heuristic with a cap_opts \u0026 CAP_OPT_NOAUDIT check, while keeping the explicit execve credential-transition filter and updating verbose logging to distinguish exec noise from advisory checks.\n\nRemoved the unused mremap_nr bookkeeping from userspace initialization, since the always-noise filter no longer depends on syscall-number matching for memory-accounting paths.\n\nUpdated the BPF-side overview and cap_event structure to include cap_opts, added a fallback CAP_OPT_NOAUDIT definition, threaded the kernel opts argument through handle_capable(), and passed safe default 0 values from the non-cap_capable() probes.\n"
    },
    {
      "commit": "427310b390d71fba9357d62b429a79da8cde91f1",
      "tree": "52ad576be8d603d28051b8722de6fd78c9f806c4",
      "parents": [
        "2f43777da2b98762bba388c2c2cfd17bd791c847"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 15:09:04 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 15:09:04 2026 -0400"
      },
      "message": "Update changelog\n"
    },
    {
      "commit": "2f43777da2b98762bba388c2c2cfd17bd791c847",
      "tree": "7100eb42ab891574046518abfb37b94d6dd846a9",
      "parents": [
        "252c2e7b757d668118a28e1946e9fd0328807d15"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 14:22:10 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 14:22:10 2026 -0400"
      },
      "message": "Update documentation and fix API issue\n\nFixed a small library/API issue in capng_set_rootid() so callers can pass CAPNG_UNSET_ROOTID to clear a previously selected namespace root id and return to writing regular V2 file capabilities, instead of being forced to keep V3 mode once set.\n\nUpdated API man pages to match current behavior and symbols.\n\nFixed man-page formatting/clarity issues in the utility docs.\n"
    },
    {
      "commit": "252c2e7b757d668118a28e1946e9fd0328807d15",
      "tree": "376f4c07abfb4935eb7ab45fdacbc2809f5c447c",
      "parents": [
        "961ce75eda0399d0d6f618e559f136b2cbdf8857"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 14:09:53 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 14:09:53 2026 -0400"
      },
      "message": "Code cleanups\n\nUpdated permitted-capability evaluation to avoid dead stores while preserving the empty/full/partial result handling in capng_have_permitted_capabilities(), and hardened buffered capability text rendering so the scan-build null/leak findings in capng_print_caps_text() are eliminated.\n\nGuarded the pscap process-tree sort so qsort() is only called when there is more than one entry, which removes the empty-array nonnull warning from scan-build.\n\nCleaned up netcap --advanced reporting code by removing dead assignments and guarding endpoint sorting in both tree and JSON render paths when the endpoint array can be empty.\n"
    },
    {
      "commit": "961ce75eda0399d0d6f618e559f136b2cbdf8857",
      "tree": "75f22484b4d68ce9a19ba15091f2e83678f71387",
      "parents": [
        "02b95e3375e2ac4b5ffa788c52f178a92f9bc131"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 11:58:51 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 11:58:51 2026 -0400"
      },
      "message": "invert math\n"
    },
    {
      "commit": "02b95e3375e2ac4b5ffa788c52f178a92f9bc131",
      "tree": "cbb5ea7d3b15b2e32afae874f282c79bb8276a7d",
      "parents": [
        "d2326d4ec91ed37a6dc605ea3c8354aff34032dd"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 11:56:20 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 11:56:20 2026 -0400"
      },
      "message": "capng_lock: use math operator to combine return codes\n"
    },
    {
      "commit": "d2326d4ec91ed37a6dc605ea3c8354aff34032dd",
      "tree": "ef7b81582a2c037b10f611dbd725ec016d1739aa",
      "parents": [
        "5b0b7a678791b53840d2415d165ef5bd0e4c3bdf"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 11:43:07 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 11:43:07 2026 -0400"
      },
      "message": "update capng_lock man page\n"
    },
    {
      "commit": "5b0b7a678791b53840d2415d165ef5bd0e4c3bdf",
      "tree": "ab8d5ca1fe8756ebf9309251c0528d936e9a2007",
      "parents": [
        "e59017c876be64a7bbb67ce929c1e19b958b3961"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 11:26:28 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 22 11:26:28 2026 -0400"
      },
      "message": "revise capng_lock to call both and bitmap the results\n"
    },
    {
      "commit": "e59017c876be64a7bbb67ce929c1e19b958b3961",
      "tree": "5f37dbf66b21e5d8d48f0ea159c31d937eabb442",
      "parents": [
        "f72bc03f176d0303eae05f083f0644d71ac361b2"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 18:57:20 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 18:57:20 2026 -0400"
      },
      "message": "Bye bye securebits\n"
    },
    {
      "commit": "f72bc03f176d0303eae05f083f0644d71ac361b2",
      "tree": "6837d9be6d771f91e4a1b05d69e27ededeaf1828",
      "parents": [
        "7d6508baecbf3a48cc00ea9552f473033c4846bb"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 15:19:02 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 15:19:02 2026 -0400"
      },
      "message": "Promote mmap mprotect mremap to always-noise filter\n\nUpdated the cap-audit file-level overview to describe the simplified two-layer filter architecture: the existing BPF pre-exec gate plus a userspace always-noise filter for exec credential transitions and memory overcommit accounting checks.\n\nExtended struct app_caps with mremap_nr, removed the now-unused recording_ready/shutting_down state, and promoted mmap, mprotect, and mremap into is_always_noise() alongside brk for unconditional CAP_SYS_ADMIN filtering on the overcommit-accounting path.\n\nSimplified handle_cap_event() so it only applies the always-noise filter, and split verbose logging between exec noise and memory-accounting noise as requested.\n\nInitialized the new mremap syscall number in main() with the other tracked syscall numbers.\n"
    },
    {
      "commit": "7d6508baecbf3a48cc00ea9552f473033c4846bb",
      "tree": "8ab9f9326c824b12b340cd08d7618f36740a63ba",
      "parents": [
        "df18eed927eff25db2a312a7a0b6ece03b1d11ca"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 14:24:47 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 14:24:47 2026 -0400"
      },
      "message": "Correct return code checking of prctl\n"
    },
    {
      "commit": "df18eed927eff25db2a312a7a0b6ece03b1d11ca",
      "tree": "867b573bec78be468e0761960426d9ee88496dab",
      "parents": [
        "5541dbe7a428b42e0bb5985459eaca39476ca44c"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 14:21:24 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 14:21:24 2026 -0400"
      },
      "message": "Untangle PR_SET_SECUREBITS and PR_SET_NO_NEW_PRIVS\n"
    },
    {
      "commit": "5541dbe7a428b42e0bb5985459eaca39476ca44c",
      "tree": "328328ff1d4df54be053cd2857f81662feea4bde",
      "parents": [
        "0eeaa5d97894bb9fe4c666df8fb1486fabe03fa1"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 14:14:28 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 14:14:28 2026 -0400"
      },
      "message": "Remove setting m.state since cap_apply did that\n"
    },
    {
      "commit": "0eeaa5d97894bb9fe4c666df8fb1486fabe03fa1",
      "tree": "d84c0f66c72eca1c2d76f871e1a83d3af4e04c22",
      "parents": [
        "120528675bf583084bc5c5f9cd6e9e8fc1a3ca59"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 14:10:50 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 14:10:50 2026 -0400"
      },
      "message": "Move state change to after get_bounding_set in case of error\n"
    },
    {
      "commit": "120528675bf583084bc5c5f9cd6e9e8fc1a3ca59",
      "tree": "22223cd3a8d86a86db9df8385d4d11b71bd0892f",
      "parents": [
        "d6160c6cf267c8d7eeace4f49508d99ed6574ca8"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 14:07:28 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 14:07:28 2026 -0400"
      },
      "message": "capng: verify correct number of args was parsed in get_bounding_set and get_ambient_set\n"
    },
    {
      "commit": "d6160c6cf267c8d7eeace4f49508d99ed6574ca8",
      "tree": "30688e55cc6014c560e58ee39cca873db3561a13",
      "parents": [
        "e2526de6913f27446e67cde3558ad4740495019b"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 14:02:27 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 14:02:27 2026 -0400"
      },
      "message": "capng: fix capability feature detection and have_capabilities reporting\n\nThe runtime prctl probes in init_lib used !errno to detect feature\nsupport, which incorrectly treats EPERM (e.g. from seccomp or LSM\npolicy) the same as EINVAL (kernel lacks the feature). Change the\nprobes to test errno !\u003d EINVAL so that access restrictions don\u0027t\nsuppress feature flags.\n\nIn capng_have_capabilities(), the else branches for the bounding and\nambient set blocks set empty\u003d1 unconditionally when a feature is\nabsent, regardless of whether the caller requested those sets. Add\nthe missing set \u0026 CAPNG_SELECT_BOUNDS and set \u0026 CAPNG_SELECT_AMBIENT\nguards so that the unsupported-feature path mirrors the supported one.\n"
    },
    {
      "commit": "e2526de6913f27446e67cde3558ad4740495019b",
      "tree": "8ee0b777741b4acc1c6d24a84e47e9033f23fbb2",
      "parents": [
        "bdbcbea95e1b43aac79250a6378141faa78f443c"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 13:27:26 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sat Mar 21 13:27:26 2026 -0400"
      },
      "message": "Improve securebits and no_new_privs handling\n\ncapng_lock now correctly returns -1 if PR_SET_SECUREBITS is unavailable at runtime, restoring fail-closed behavior. By now all kernels should have this enabled.\n"
    },
    {
      "commit": "bdbcbea95e1b43aac79250a6378141faa78f443c",
      "tree": "268a552c5d900e209de08a1142342e357a857647",
      "parents": [
        "20ae739c217eaa69a6c4b1aa3e4bca6fe705cae9"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 20 14:41:52 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Fri Mar 20 14:41:52 2026 -0400"
      },
      "message": "Cleanup proc output\n\nMoved output sanitization helper into utils/proc-sanitize.c and utils/proc-sanitize.h so the control-byte escaping logic lives in one place and can be reused across the utilities.\n\nUpdated pscap to sanitize comm values and netcap to sanitize comm and network interface before outputting them.\n"
    },
    {
      "commit": "20ae739c217eaa69a6c4b1aa3e4bca6fe705cae9",
      "tree": "c474648ad69e8f8ed1060d7b207a63349f913201",
      "parents": [
        "722144478cbbbac86e63008e384689f9768bb850"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 11 14:15:40 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 11 14:15:40 2026 -0400"
      },
      "message": "When (full) is given, mark privileged-caps orange\n"
    },
    {
      "commit": "722144478cbbbac86e63008e384689f9768bb850",
      "tree": "dbf5b249ac879ae60b88608cf3028673d2b849b9",
      "parents": [
        "a6c6a2cd0ccae7dd1184c184766b687530a7edf5"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 11 13:54:46 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 11 13:54:46 2026 -0400"
      },
      "message": "Keep cap_last_cap validation within 64 bits\n\nAdded MAX_CAP_BITS and redefined MAX_CAP_VALUE as the highest valid capability index, making the storage limit explicit and unambiguous for validation logic.\n\nClamped runtime last_cap after parsing /proc so any oversized value is reduced to MAX_CAP_VALUE before capability validation/iteration code can consume it; this preserves behavior while preventing indices beyond fixed storage (VFS_CAP_U32 \u003d\u003d 2).\n"
    },
    {
      "commit": "a6c6a2cd0ccae7dd1184c184766b687530a7edf5",
      "tree": "8e05fc67d6ed0ab3491c62c6f9bd4f413d94db84",
      "parents": [
        "0fade0b7acbced772bf9b8d61359620909791e29"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 11 12:55:13 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 11 12:55:13 2026 -0400"
      },
      "message": "Fix buffer termination issue in caps_summary_for_pid\n\nIn caps_summary_for_pid, the previous logic could append \", \" and then break if the capability name did not fit, leaving a partial token write path. The loop was patched to check space for both separator and name (sep + n) before writing either piece. This ensures the output string is never advanced into a separator-only state.\n\nApplied the same fix pattern to ambient capability formatting in the same function, so both capability list builders now use the same atomic “separator+name fits” check.\n"
    },
    {
      "commit": "0fade0b7acbced772bf9b8d61359620909791e29",
      "tree": "bcefcfe07fcdb2e4718044986a8f92e4ad0701d0",
      "parents": [
        "7c68df21b8e57d8eec270e90c3e1a0767a27afbc"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 11 12:30:40 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 11 12:30:40 2026 -0400"
      },
      "message": "Restore -z nodelete linker flag\n\nRestore the -z nodelete linker flag which previously prevented libcap-ng.so from being unloaded.\n"
    },
    {
      "commit": "7c68df21b8e57d8eec270e90c3e1a0767a27afbc",
      "tree": "82d8605ec881d22359fdacf006c18a1f7dad0e59",
      "parents": [
        "e36f3fefd5963d668c60b289415aa6e7bd65a3a0"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 10 01:08:26 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 10 01:08:26 2026 -0400"
      },
      "message": "update changelog\n"
    },
    {
      "commit": "e36f3fefd5963d668c60b289415aa6e7bd65a3a0",
      "tree": "8a7ace0bb67bf6305ffda35a83743f9ea9b64fd0",
      "parents": [
        "dbc88f0ee09c15e8316e4558d3ef512fac59f4ce"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 10 00:59:44 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 10 00:59:44 2026 -0400"
      },
      "message": "capng_apply returns success when no capability set selected\n\nAdded a minimal guard in capng_apply to reject an empty selection mask (set \u003d\u003d 0) by returning -1 and setting errno \u003d EINVAL, preserving the expected failure behavior for invalid masks.\n\nAdded a regression test in src/test/lib_test.c that initializes state, calls capng_apply(0), and asserts it fails with errno \u003d\u003d EINVAL.\n"
    },
    {
      "commit": "dbc88f0ee09c15e8316e4558d3ef512fac59f4ce",
      "tree": "58c7282acae7a0c0f516593e3383bcf812ca5eb6",
      "parents": [
        "2c232453c4b2583ecf0f21dc1f8fcfec16517dc1"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 10 00:43:17 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 10 00:43:17 2026 -0400"
      },
      "message": "pscap caches stale username when getpwuid() fails\n\nThis is highly unlikely, but that said, in the euid !\u003d uid path, the code looked up getpwuid(euid) and only updated name on success; on failure it previously left name unchanged, which could cause the previous username to be reused for a different UID in output. The fallback print path uses numeric UID only when name \u003d\u003d NULL, so stale name could mislabel rows.\n\nThis is fixed this by explicitly resetting name \u003d NULL when getpwuid fails, so unmapped UIDs are now printed numerically instead of inheriting a stale username.\n"
    },
    {
      "commit": "2c232453c4b2583ecf0f21dc1f8fcfec16517dc1",
      "tree": "ab217733ffbb96649b6c96458566f8833e3fe520",
      "parents": [
        "e5bfe76f7de6fcd1d164238c680782bf8e5750f0"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 10 00:24:43 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 10 00:24:43 2026 -0400"
      },
      "message": "Python capng_updatev varargs is wrong\n\nUpdated the Python SWIG varargs declaration for capng_updatev to use -1 as the default optional value and increased the optional varargs expansion limit from 16 to 64. This ensures omitted Python arguments become the required sentinel for the C varargs consumer and removes the old low ceiling.\n"
    },
    {
      "commit": "e5bfe76f7de6fcd1d164238c680782bf8e5750f0",
      "tree": "9c69cead489866d8f9b4f44f4b2c2f391ac1ea6d",
      "parents": [
        "1fd9ed02e0af0f8efaace294b0c95c723fbdebaa"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 10 00:06:17 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 10 00:06:17 2026 -0400"
      },
      "message": "Improve bookkeeping for capng_print_caps_text buffer\n\nChanged capng_print_caps_text() to do a first pass that computes the exact required size (all selected names + \", \" separators + NUL), allocates once, and then writes safely with bounded bookkeeping. This removes the supposedly fragile fixed-size heuristic entirely.\n"
    },
    {
      "commit": "1fd9ed02e0af0f8efaace294b0c95c723fbdebaa",
      "tree": "04fe2c2d22c1c375fa2cc1f05374ffc237617e78",
      "parents": [
        "08cdad42294ee4955b5ea83f4482d7fbff7627de"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 09 23:29:54 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 09 23:29:54 2026 -0400"
      },
      "message": "Sanitize input from /proc\n\nAdded sanitize_untrusted_field() and sanitize_untrusted_owned() to escape control bytes (0x00-0x1f, 0x7f) in untrusted proc/cgroup-derived strings while keeping normal printable content unchanged. This applies sanitization at ingestion rather than at render time to preserve existing wrapping/color behavior.\n\nSanitized lsm_label immediately after reading /proc/\u003cpid\u003e/attr/current, with graceful fallback to NULL on allocation failure.\n\nSanitized process metadata fields (comm, exe, and unit) during add_process() collection so tree rendering continues to use existing ANSI-aware formatting logic unchanged.\n"
    },
    {
      "commit": "08cdad42294ee4955b5ea83f4482d7fbff7627de",
      "tree": "48d2a6c3c53fb263ed1a3148436a3ff25d676d94",
      "parents": [
        "ba2e9e03199541b1c07f3e925ffc5b23774bd18f"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 09 23:00:57 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 09 23:00:57 2026 -0400"
      },
      "message": "Verify kernel answers netlink query\n\nIn read_diag_messages() / read_vsock_diag_messages() make sure the kernel sent the reply before using it.\n"
    },
    {
      "commit": "ba2e9e03199541b1c07f3e925ffc5b23774bd18f",
      "tree": "b2914ba4ea5b672d7d027a7298f6a0f64121c540",
      "parents": [
        "febd0dda0d507e47fa234c13ba3d43458d29ad58"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 09 22:40:18 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 09 22:40:18 2026 -0400"
      },
      "message": "Fix race in init_lib\n\nImplemented a fix by replacing the unsynchronized one-bit guard with an atomic 3-state guard:\n\n* fast-return when state is fully initialized (2),\n* single-thread initialization transition (0 -\u003e 1) via CAS,\n* wait for completion when another thread is initializing,\n* release-store final state (2) only after initialization work is done.\n"
    },
    {
      "commit": "febd0dda0d507e47fa234c13ba3d43458d29ad58",
      "tree": "ad9732df4187b80aa4cc0eba49024dc2ea4605bc",
      "parents": [
        "eedb68e9af5dd18ad2486428f8bf804cdc6d1c3b"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 08 23:36:21 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 08 23:36:21 2026 -0400"
      },
      "message": "Update changelog\n"
    },
    {
      "commit": "eedb68e9af5dd18ad2486428f8bf804cdc6d1c3b",
      "tree": "e2714d677e6f7e00d0f6fc1f11de72d5105edda6",
      "parents": [
        "d2d688caeb147843bc9c47f9e2a5e784c4bda6b4"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 08 23:30:46 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 08 23:30:46 2026 -0400"
      },
      "message": "Merge securebits_locked into securebits line\n\nUpdated render_tree_process_details to emit a single combined securebits defenses line in tree output, appending lock state as (locked: ...) and incrementing def_n only once (removed the separate securebits_locked tree node).\n\nImplemented complete securebits value colorization on the combined line:\n\n*    keep_caps\u003dyes → yellow, keep_caps\u003dno → neutral\n*    no_setuid_fixup\u003dyes → yellow, no_setuid_fixup\u003dno → neutral\n*    noroot\u003dyes → green, noroot\u003dno → yellow\n*    locked: yes → green, locked: no → yellow.\n\nLeft JSON structure unchanged (still separate securebits and securebits_locked fields); only tree presentation changed.\n\nUpdated netcap(8) advanced-mode defenses description to document the combined tree format and explicitly note JSON retains separate securebits / securebits_locked fields.\n\nUpdated the INTERPRETATION section with the full securebits color semantics for the combined format (noroot and locked good/gap states, cautionary keep_caps\u003dyes and no_setuid_fixup\u003dyes, neutral no values for those two).\n"
    },
    {
      "commit": "d2d688caeb147843bc9c47f9e2a5e784c4bda6b4",
      "tree": "49c1b76f63fcc82f19665d1109cc2a95108b5370",
      "parents": [
        "63e7654806b3486dffe867189250b52a41d6a524"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 08 23:13:34 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 08 23:13:34 2026 -0400"
      },
      "message": "Improve documentation and reduce argument counts\n\nUpdated the top-level overview comment in netcap-advanced.c to document colorized severity output with --no-color, pidfd-based SO_REUSEPORT probing, ambient-capability detail, system.slice-restricted unit extraction, and ANSI-aware wrapping behavior for safe colored tree rendering.\n\nAdded missing kernel-style function headers for the requested helper set, including capability severity/color helpers, hash/set helpers, bind formatting/sorting, tree/json process render helpers, and ANSI escape/color-state scanners.\n\nAdded inline documentation in render_tree for each hierarchy level (plane/interface/protocol/bind/port/process), for protocol highlighting intent, and for pidset-based deduplication of processes shared across grouped endpoints/ports.\n\nAdded inline rationale comments at the reuseport probe site in collect_proc_inodes and at sort ordering in endpoint_cmp to explain data-flow and grouping stability decisions.\n\nReduced parse_status_defenses argument count by introducing struct status_fields, populating it in add_process, and passing a single pointer into the parser path.\n\nReduced add_endpoint argument count by introducing struct endpoint_attrs, then updated endpoint_to_ifaces and parse_packet_file to build/pass attrs locally instead of separate wildcard/reuseport arguments.\n"
    },
    {
      "commit": "63e7654806b3486dffe867189250b52a41d6a524",
      "tree": "59829f696a371dc6f4a527c8dcea2d5f5f3d8814",
      "parents": [
        "4002fc1d45f20e4e7e4b3001a7667f238c7d89af"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 08 22:37:34 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 08 22:37:34 2026 -0400"
      },
      "message": "Fix remaining issues in netcap-advanced.c and netcap.8\n\nUpdated securebits colorization in render_tree_process_details() to keep noroot\u003dyes green and additionally color keep_caps\u003dyes and no_setuid_fixup\u003dyes yellow using the same strstr + reconstruct pattern when use_color is enabled.\n\nChanged the local planes array declaration in render_tree() from a fixed size to PLANE_COUNT for enum-consistent sizing.\n\nReplaced the garbled INTERPRETATION markup in the man page with proper troff bold escapes (\\fB...\\fP), so keywords render correctly in formatted output.\n"
    },
    {
      "commit": "4002fc1d45f20e4e7e4b3001a7667f238c7d89af",
      "tree": "e28850ba36c645603f0de1ac8f0c552fddff2f08",
      "parents": [
        "da8661a5d42b795d7a20c7bf4f0cb385afe2c957"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 08 22:02:22 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 08 22:02:22 2026 -0400"
      },
      "message": "Add colorized output to netcap --advanced\n\nAdded color infrastructure and severity classification in advanced tree rendering, including ANSI color constants, capability tier lists, and severity helpers used for per-capability and flag coloring.\n\nUpdated tree rendering to colorize key capability and defense values (including caps, ambient, no_new_privs, seccomp, runs_as_nonroot, LSM label, securebits fields) and made privileged-caps follow worst-capability severity in process capabilities.\n\nAdded protocol-node highlighting for raw, raw6, and packet in tree output, and ensured colorization is disabled for JSON output while enabling color only on TTY by default unless --no-color is set.\n\nUpdated netcap.8 with --no-color in OPTIONS and added a new INTERPRETATION section describing color semantics, capabilities tiers, ambient/bounding implications, defense fields, flags, and raw/packet risk interpretation.\n"
    },
    {
      "commit": "da8661a5d42b795d7a20c7bf4f0cb385afe2c957",
      "tree": "1ed30abda7c2e3fe3ae3b0c4c28c286e38281111",
      "parents": [
        "78c5d01581b4428cfe02f72f55c856ca594b302c"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 08 12:40:24 2026 -0400"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 08 12:40:24 2026 -0400"
      },
      "message": "add acct name to pscap --tree output\n"
    },
    {
      "commit": "78c5d01581b4428cfe02f72f55c856ca594b302c",
      "tree": "f63fd3c4146a2d1df2e4cc36787ae636b6ce5070",
      "parents": [
        "7228b4d544cb0621b91126235ea9103e8171c8aa"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 04 22:13:32 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Wed Mar 04 22:13:32 2026 -0500"
      },
      "message": "Add brk filtering to always-noise cap_audit\n\nUpdated the cap-audit overview comment to describe memory overcommit accounting (brk → CAP_SYS_ADMIN) as an additional kernel-internal noise category, alongside pre-exec, startup, and shutdown noise handling.\n\nChanged is_always_noise() to unconditionally filter CAP_SYS_ADMIN events coming from brk, and expanded its comment to document both always-noise classes: exec credential transitions and memory accounting checks.\n\nUpdated is_startup_noise() so it no longer filters brk; it now only filters mmap/mprotect CAP_SYS_ADMIN startup noise.\n\nAdjusted handle_cap_event() always-noise verbose output so brk events are labeled as Filtered memory accounting noise, while exec-related events retain Filtered exec noise. Also updated nearby filter-block comments to match the new behavior.\n"
    },
    {
      "commit": "7228b4d544cb0621b91126235ea9103e8171c8aa",
      "tree": "ec909bc4b992b51b5f3ef4d260581a10f8b1448b",
      "parents": [
        "b418825044aa066ea9510628c6f40305b712a9ff"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 03 14:06:07 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 03 14:06:07 2026 -0500"
      },
      "message": "bindings: add check-local for python module underlinkage\n\nAdd check-local targets for python3 bindings that rebuild with\n-Wl,--no-undefined using python3-config --embed --libs.\nThis makes make check catch unresolved Py* symbols in module link steps.\n"
    },
    {
      "commit": "b418825044aa066ea9510628c6f40305b712a9ff",
      "tree": "8c1bef160a18f22725cf86c13030817b51cae426",
      "parents": [
        "d5ce7e2bb11bcbafcac65e7948fa18a1e84aa102"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 03 13:41:59 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 03 13:41:59 2026 -0500"
      },
      "message": "Remove loopback-only flag from netcap\n"
    },
    {
      "commit": "d5ce7e2bb11bcbafcac65e7948fa18a1e84aa102",
      "tree": "7222628f8b65c4135fcb9e3c85c8ec42b521abf0",
      "parents": [
        "db449f49dca48acd8a82b8efdda436590a4c7547"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 03 12:08:06 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Mar 03 12:08:06 2026 -0500"
      },
      "message": "Enumerate ambient capabilities\n\nAdded a new ambient_caps field to struct process_info so each process can carry a detailed ambient capability list in parallel with the existing caps summary and ambient_present boolean.\n"
    },
    {
      "commit": "db449f49dca48acd8a82b8efdda436590a4c7547",
      "tree": "8452cf3da8dd690ca488a0ab8483a188010e0c49",
      "parents": [
        "f037ac4cc08ce4960e7db07ba6426f14a13c66c8"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 02 22:58:23 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 02 22:58:23 2026 -0500"
      },
      "message": "Modify extract_unit_from_cgroup filtering logic\n\nUpdated extract_unit_from_cgroup to skip .service/.scope matches unless the same cgroup line also contains system.slice, ensuring only system daemon units are reported. The existing unit extraction/trimming logic remains unchanged, and the function still returns NULL when no qualifying line is found.\n"
    },
    {
      "commit": "f037ac4cc08ce4960e7db07ba6426f14a13c66c8",
      "tree": "79374710320c3f9bb65cb0e21dc8709a62ec10d5",
      "parents": [
        "4fefc81147aab9307ea6cd2e595981b82e929df1"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 02 22:44:19 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 02 22:44:19 2026 -0500"
      },
      "message": "Filter VSOCK seqpacket sockets properly\n\nUpdated VSOCK /proc/net/vsock fallback parsing to handle SOCK_SEQPACKET explicitly, filtering it like stream sockets (state \u003d\u003d 0x0A) and labeling it as seqpacket.\n\nUpdated VSOCK sock_diag filtering so both SOCK_STREAM and SOCK_SEQPACKET require TCP_LISTEN, while SOCK_DGRAM alone keeps the nonzero-source-port filter.\n"
    },
    {
      "commit": "4fefc81147aab9307ea6cd2e595981b82e929df1",
      "tree": "1b2ed902171f943e981ad4439a4d3174250159d4",
      "parents": [
        "427cd10381edb4968b1f967a3c902c50633bc783"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 02 11:41:18 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Mon Mar 02 11:41:18 2026 -0500"
      },
      "message": "Add SO_REUSEPORT detection for INET sockets\n\nImplemented best-effort SO_REUSEPORT probing for INET sockets using pidfd_open + pidfd_getfd + getsockopt(SO_REUSEPORT), with syscall-number guards and a one-time diag_dbg message when kernel support is unavailable (ENOSYS).\n\nExtended socket/inode and endpoint data models with a reuseport field, and added the necessary syscall include/prototype wiring used by the new probe path.\n\nUpdated /proc/\u003cpid\u003e/fd inode collection to probe each discovered socket FD and OR-stick reuseport on the inode entry when any FD for that inode reports enabled reuseport.\n"
    },
    {
      "commit": "427cd10381edb4968b1f967a3c902c50633bc783",
      "tree": "9957aa2bf134d543b9bbe26dd96e5b8e88d49327",
      "parents": [
        "b512d97eee027b3665e1f81357d03746eda00c36"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 23:25:00 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 23:25:00 2026 -0500"
      },
      "message": "Add bash completions for libcap-ng-utils\n"
    },
    {
      "commit": "b512d97eee027b3665e1f81357d03746eda00c36",
      "tree": "d48f1dddcb5694906a221823bb1455ca697ad409",
      "parents": [
        "732da9bc8057ad78e7d63cbb2047dbe447f1933e",
        "169c4c52c6b6424e71d56a3f36064c3174134073"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 22:40:27 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 22:40:27 2026 -0500"
      },
      "message": "Merge origin/master into advanced\n"
    },
    {
      "commit": "732da9bc8057ad78e7d63cbb2047dbe447f1933e",
      "tree": "a187102cae9b8cad93f0defcaf6617955d7aff8d",
      "parents": [
        "4b431771d21d64cf3138ec41e40c15bc9432fc3d"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 21:28:50 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 21:28:50 2026 -0500"
      },
      "message": "Add bash completions for libcap-ng-utils\n\nAdded bash completion scripts for pscap, netcap, and filecap with option-aware completions and basic argument handling (-p PID completion for pscap, path completion for filecap).\n"
    },
    {
      "commit": "4b431771d21d64cf3138ec41e40c15bc9432fc3d",
      "tree": "f7f2ec35451cb60008bb66eb94dc231b99d6d738",
      "parents": [
        "a8e10ed89cb586904a716ecfe0ed84ef902e59ee"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 21:13:25 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 21:13:25 2026 -0500"
      },
      "message": "Update netcap.8 man page for new fields\n\nUpdated the tree output documentation to add the optional exe field for each process line, including when it is omitted and why it complements truncated comm (Name: limited to 15 chars).\n\nUpdated JSON endpoint documentation to distinguish INET/LINK-LAYER endpoint shape from VSOCK endpoint shape (vsock_type, cid, no proto/bind for VSOCK).\n\nUpdated JSON process object documentation to include optional exe plus always-present ambient_present and open_ended_bounding, and documented their relationship to the bracketed caps annotations.\n"
    },
    {
      "commit": "a8e10ed89cb586904a716ecfe0ed84ef902e59ee",
      "tree": "4bb455a4179d94a9211715eaba597c16e0cf7686",
      "parents": [
        "27ebad597c9e70a172e0af92caa435c155638b58"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 20:57:45 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 20:57:45 2026 -0500"
      },
      "message": "add left \u003e 1 guard for symmetry with ambient capabilities\n"
    },
    {
      "commit": "27ebad597c9e70a172e0af92caa435c155638b58",
      "tree": "4287c56881373eacf83fa8751fb070bff8cf0016",
      "parents": [
        "ec7c1d6458390622aa23479ffcb1f97d2f9ee2ff"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 20:49:45 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 20:49:45 2026 -0500"
      },
      "message": "Update netcap.8 man page documentation\n\nUpdated the NAME section wording to describe netcap as a posture-review tool rather than a legacy capability viewer.\n\nExpanded permission guidance in DESCRIPTION to document full-output requirements (root or CAP_DAC_READ_SEARCH + CAP_NET_ADMIN) and clarified that missing sock_diag-derived protocol data is silent when permissions are insufficient.\n\nEnhanced ADVANCED MODE docs with:\n\n  * VSOCK-specific tree layout exception (Planes -\u003e endpoint -\u003e process -\u003e caps/defenses/flags).\n\n  * Wildcard bind expansion semantics across non-loopback interfaces.\n\n  * multicast/group synthetic interface behavior for unresolved multicast-bound endpoints.\n\n  * Optional per-process unit field sourced from cgroup/systemd metadata.\n\n  * SCTP/DCCP discovery dependency on NETLINK_SOCK_DIAG and CAP_NET_ADMIN.\n\n  * privileged-caps trigger list (CAP_SYS_ADMIN, CAP_SYS_PTRACE, CAP_DAC_READ_SEARCH, CAP_NET_ADMIN, CAP_NET_RAW).\n\n  * caps annotations for [ambient-present] and [open-ended-bounding].\n\nReworked the JSON OUTPUT section to include a concrete structural outline: top-level keys, plane fields, ifaces/endpoints branches, endpoint fields, and process fields including optional unit.\n\nClarified runs_as_nonroot semantics as based on the real UID (Uid: first field), including the setuid/effective-UID caveat\n"
    },
    {
      "commit": "ec7c1d6458390622aa23479ffcb1f97d2f9ee2ff",
      "tree": "b4c9cce004b56844039842f1e4055971bf388533",
      "parents": [
        "c31c62e7904836af57a92fd4a18d95cd4de54b3e"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 14:46:06 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 14:46:06 2026 -0500"
      },
      "message": "Add full executable path to process model\n\nAdded a full executable path field (char *exe) to the process model, while keeping comm unchanged for backward compatibility.\n\nUpdated add_process to read /proc/\u003cpid\u003e/exe via readlink, store it with xstrdup when available, tolerate failures by leaving p-\u003eexe as NULL, and strip a trailing (deleted) suffix before storing.\n\nUpdated tree rendering to include exe\u003d\u003cpath\u003e only when p-\u003eexe is present, otherwise preserving the prior output shape without an exe fragment.\n\nUpdated JSON rendering to emit \"exe\": ... immediately after \"comm\": ... when p-\u003eexe is non-NULL.\n"
    },
    {
      "commit": "c31c62e7904836af57a92fd4a18d95cd4de54b3e",
      "tree": "72978eccdbce249a2024ed1c3d1a69947602416f",
      "parents": [
        "6e1102c3ffa6daa49cf62d0c13af51a91242f459"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 12:28:05 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Sun Mar 01 12:28:05 2026 -0500"
      },
      "message": "Refactor duplicate code\n\nRefactored duplicated tree-rendering logic for per-process details into a new helper, render_tree_process_details.\n\nRefactored duplicated JSON process rendering into render_json_process.\n"
    },
    {
      "commit": "169c4c52c6b6424e71d56a3f36064c3174134073",
      "tree": "0895a74275285f54e103031b52e4223e0aa3c745",
      "parents": [
        "16979da543a7e77d4f6a9c07a5685ed8685830a9"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Feb 19 16:49:22 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Feb 19 16:49:22 2026 -0500"
      },
      "message": "Remove  syscall numbers\n"
    },
    {
      "commit": "16979da543a7e77d4f6a9c07a5685ed8685830a9",
      "tree": "329c44a0af54c260eafd526b20d37d0359d3c20f",
      "parents": [
        "5414a4aad7c1f96a2063a3243975043fccbfc709"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Feb 19 16:40:40 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Thu Feb 19 16:40:40 2026 -0500"
      },
      "message": "Add a --help option\n"
    },
    {
      "commit": "5414a4aad7c1f96a2063a3243975043fccbfc709",
      "tree": "cd8062d1b5221782251ed26b9daf7edd05fc445f",
      "parents": [
        "427ed6d2c2b16e9b48f12953e55febfead3ef2e2"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Feb 17 16:49:22 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Feb 17 16:49:22 2026 -0500"
      },
      "message": "Open the 0.9.2 development cycle\n"
    },
    {
      "commit": "427ed6d2c2b16e9b48f12953e55febfead3ef2e2",
      "tree": "637c9249914cc822b090823a78a27b8aa626ac3e",
      "parents": [
        "2b076af75d7e5f2f5a40aff04a1daf5b870e4196"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Feb 17 16:35:34 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Feb 17 16:35:34 2026 -0500"
      },
      "message": "Finalize 0.9.1 release\n"
    },
    {
      "commit": "2b076af75d7e5f2f5a40aff04a1daf5b870e4196",
      "tree": "637c9249914cc822b090823a78a27b8aa626ac3e",
      "parents": [
        "863ccefce266d3972d043ab316b4da67fb31949e"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Feb 17 16:26:44 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Feb 17 16:26:44 2026 -0500"
      },
      "message": "Adjust capng_print_caps_text and capng_print_caps_numeric\n\nThey can conditionally malloc a buffer. The current attribute made\nit look like they unconditionally create a memory allocation. Remove\nthat and add a reminder to the man page.\n"
    },
    {
      "commit": "863ccefce266d3972d043ab316b4da67fb31949e",
      "tree": "0ebd4387c69bc6d4aa56423cc12979991af44ae7",
      "parents": [
        "b24bf6f41793a526720c7bac655a255ad7df4f6c"
      ],
      "author": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Feb 17 16:22:23 2026 -0500"
      },
      "committer": {
        "name": "Steve Grubb",
        "email": "ausearch.1@gmail.com",
        "time": "Tue Feb 17 16:22:23 2026 -0500"
      },
      "message": "Fix dead code warning and add a unit test for regressions\n"
    }
  ],
  "next": "b24bf6f41793a526720c7bac655a255ad7df4f6c"
}
