0.1.1 - Add libpcap/Npcap backend and robust live capture

Introduce a cross-platform libpcap/Npcap capture backend with a Windows raw-socket fallback and plumbing to select backends via --capture-backend. Add ctypes-based libpcap wrapper (open_libpcap_capture, CaptureStats, LibpcapUnavailable) and a backend factory; refactor live capture runner to use the new backend, StopKeyMonitor, and improved clipboard handling. Make session and protocol decoders resilient to pipelined/multi-page responses and non-byte-aligned streams (alignment iterator, alignment-aware decoding, embedded-record trimming, slice support). Update mitmproxy flows adapter to reuse LiveHistorySession. Expand console messages and docs/README to explain cross-platform requirements, usage, and capture diagnostics. Minor: update package description in pyproject and adjust ARC/response handling and row bookkeeping to record row indices.
This commit is contained in:
Golumpa 2026-06-12 12:58:15 +01:00
parent 1144e33a57
commit 0e78906e3a
20 changed files with 1234 additions and 147 deletions

View file

@ -5,12 +5,20 @@ This prototype supports separate Monopoly and Arc/Gashapon history decoders.
## Monopoly
- History is fetched over the UDP game connection.
- Client history-page requests are 45 bytes.
- A client history-page request has a 45-byte request prefix. UDP payloads may
contain additional coalesced transport data after that prefix.
- History request constant: `4220` / `0x107c`.
- Request selector `4`: `Lottery_Permanent`.
- Request selector `8`: `Lottery_LimitedCharacter`.
- Request page cursor: `page_number * 4`.
- Normal server responses contain 5 history records.
- The client can pipeline several page requests before responses arrive.
- Under load, one server response can contain multiple consecutive pages. The
observed format contained 10 records representing two five-record pages,
with an internal response header before the second page's first record.
- Some batched responses begin at a non-byte-aligned position in the UDP
payload. The decoder tests all LSB bit offsets; captures have been observed
where the record stream begins five bits into the byte stream.
- The final page may contain fewer than 5 records.
Decoded fields:
@ -40,7 +48,8 @@ Pages are anchored to the continuous run starting at page 1 (history always load
## Arc / Gashapon
- Arc history uses a separate 34-byte request.
- Arc history uses a separate 34-byte request prefix and may likewise have
coalesced transport data after it.
- Request constant: `2060` / `0x080c`.
- Cursor step: `2`.
- Pool: `Arc_MiracleBox`.