- 04-02-SUMMARY.md: --filter and --read flags wired, pcap mode, deriveOutputPath - STATE.md: advanced to plan 2/2, updated decisions, session record - ROADMAP.md: phase 4 marked Complete (2/2 plans)
6.0 KiB
Roadmap: NetSynth
Overview
NetSynth is built in four phases ordered by technical risk. Phase 1 validates the hardest foundation: live packet capture and protocol classification without any audio code. Phase 2 builds the synthesis and encoding engine in isolation against synthetic inputs, resolving audio-specific pitfalls before integration. Phase 3 wires the two pipelines together with coordinated Ctrl+C shutdown and auto-clustering, delivering the complete v1 MVP. Phase 4 adds power-user features (BPF filter, offline pcap input) that extend the core without blocking it.
Phases
Phase Numbering:
- Integer phases (1, 2, 3): Planned milestone work
- Decimal phases (2.1, 2.2): Urgent insertions (marked with INSERTED)
Decimal phases appear between their surrounding integers in numeric order.
- Phase 1: Capture and Classification - Live packet capture, protocol identification, and CLI scaffolding — no audio yet (completed 2026-03-25)
- Phase 2: Audio Synthesis Engine - Oscillators, EMA amplitude smoothing, mixing, and MP3 encoding against synthetic inputs (completed 2026-03-26)
- Phase 3: Pipeline Integration and MVP - Wire capture into synthesis, Ctrl+C with valid MP3 output, auto-clustering of unknown traffic (completed 2026-03-26)
- Phase 4: Power User Features - BPF capture filter, offline pcap file input (completed 2026-03-26)
Phase Details
Phase 1: Capture and Classification
Goal: Users can run the CLI against a live interface and see a live protocol classification summary — the full capture-to-classify pipeline validated without audio Depends on: Nothing (first phase) Requirements: CAPT-01, CAPT-02, CAPT-04, CLAS-01, CLAS-03, CLAS-04 Success Criteria (what must be TRUE):
- User can run
netsynth -i eth0and see packets being classified live to stderr - User can run
netsynth --list-interfacesand see all available network interfaces listed - User running without root/CAP_NET_RAW sees a clear error message with a
sudohint — not a panic or silent failure - On exit, user sees a per-protocol packet count summary printed to stderr
- User can pass
--verboseand see per-window protocol activity lines on stderr Plans: 4/4 plans complete
Plans:
- 01-01-PLAN.md — Go 1.24 setup, module init, shared types, config-driven classifier with tests
- 01-02-PLAN.md — Capture package: OpenCapture, ListInterfaces, privilege error handling
- 01-03-PLAN.md — Aggregation: time-windowed accumulator, exit summary, verbose output
- 01-04-PLAN.md — CLI wiring: Cobra commands, signal handling, pipeline assembly, smoke test
Phase 2: Audio Synthesis Engine
Goal: The synthesis and encoding stack produces a valid MP3 from synthetic WindowSnapshot inputs — audio pipeline fully validated before any real traffic flows through it Depends on: Phase 1 Requirements: SYNTH-01, SYNTH-02, SYNTH-03, OUT-01, OUT-02, OUT-03 Success Criteria (what must be TRUE):
- Given synthetic traffic snapshots, the tool produces an MP3 file that passes
ffprobevalidation - Each traffic class (ICMP, DNS, TCP/443, TCP/other, UDP, SSH) produces a perceptually distinct drone tone
- Drone layer amplitude rises and falls with traffic volume over time — sustained traffic sounds louder, quiet periods fade
- User can specify output path via
-oflag; it defaults tonetsynth-<timestamp>.mp3when omitted - An empty (zero-packet) input produces a clear error message instead of a corrupt or zero-byte MP3 Plans: 3/3 plans complete
Plans:
- 02-01-PLAN.md — Environment setup (gcc, ffprobe, go-lame), synth config table, oscillator, EMA layer with tests
- 02-02-PLAN.md — Stereo mixer (constant-power panning), OscillatorBank multi-layer rendering with tests
- 02-03-PLAN.md — MP3 encoder package, zero-packet guard, -o CLI flag, ffprobe integration test
Phase 3: Pipeline Integration and MVP
Goal: Live capture flows end-to-end into audio synthesis — the complete v1 MVP: run, capture, Ctrl+C, get an MP3 Depends on: Phase 2 Requirements: CAPT-03, CLAS-02 Success Criteria (what must be TRUE):
- User runs
netsynth -i eth0 -o out.mp3, generates traffic, presses Ctrl+C, and receives a valid playable MP3 atout.mp3 - Unrecognized traffic patterns are automatically assigned distinct drone tones — unknown traffic is not silent or merged into a single undifferentiated layer
- The MP3 audio reflects the actual traffic mix — a session with mostly DNS sounds different from one with mostly HTTPS Plans: 2/2 plans complete
Plans:
- 03-01-PLAN.md — Extend TrafficClass to 14 classes (hash-bucketed unknown-1 through unknown-4), update synth config with dissonant tones
- 03-02-PLAN.md — Wire capture pipeline into RunSynthesis, encoding feedback messages, end-to-end MVP verification
Phase 4: Power User Features
Goal: Users can scope capture with BPF expressions and sonify historical pcap files Depends on: Phase 3 Requirements: CAPT-05, CAPT-06 Success Criteria (what must be TRUE):
- User can run
netsynth -i eth0 --filter "port 53"and only DNS traffic is captured and sonified - User can run
netsynth --read capture.pcap -o out.mp3against an existing pcap file and receive a valid MP3 - An invalid BPF filter expression produces a clear error message before any capture begins Plans: 2/2 plans complete
Plans:
- 04-01-PLAN.md — BPF validation, pcap file reading, timestamp-based aggregation (core library functions)
- 04-02-PLAN.md — Wire --filter and --read flags into CLI with branching run logic
Progress
Execution Order: Phases execute in numeric order: 1 -> 2 -> 3 -> 4
| Phase | Plans Complete | Status | Completed |
|---|---|---|---|
| 1. Capture and Classification | 4/4 | Complete | 2026-03-25 |
| 2. Audio Synthesis Engine | 3/3 | Complete | 2026-03-26 |
| 3. Pipeline Integration and MVP | 2/2 | Complete | 2026-03-26 |
| 4. Power User Features | 2/2 | Complete | 2026-03-26 |