Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
85 commits
Select commit Hold shift + click to select a range
5c39896
Fix Tx Suite monitor frame progression
ceane Jul 22, 2026
4973ea6
Add I/Q capture explainer page
ceane Jul 23, 2026
d699d3c
Fixes for the Tx flow and device all around
ceane Jul 24, 2026
97af0c9
- Adding FFT/IFFT Route, updating FAQs
ceane Jul 25, 2026
a85684c
[WIP] Large refactor of device capabilities, redux and FFT Canvas on …
ceane Jul 26, 2026
7b70386
Complete spectrum state and SDR Tx refactor
ceane Jul 28, 2026
a782018
Migrating other tools into the repo
ceane Jul 30, 2026
b871a37
Remove obsolete agent notes
ceane Aug 1, 2026
baa5850
docs: add security policy
ceane Aug 1, 2026
bf3b164
test: extend live Redux harness for pause and lifecycle snapshots
ceane Aug 2, 2026
b6daa84
test: make VFO latency assertion optional without LIVE_BACKEND_URL
ceane Aug 2, 2026
f5c8b62
fix: keep Server Down off the source-handoff path
ceane Aug 2, 2026
7f728bd
fix: soft-disconnect control plane without wiping source inventory
ceane Aug 2, 2026
f86c4d0
feat: add settings page, FAQ landing, and link card components
ceane Aug 2, 2026
980150d
feat: use app logo and back button in FAQ layout
ceane Aug 2, 2026
699be3e
feat: add open/sectionId/hideHeader to Collapsible
ceane Aug 2, 2026
a9b82db
feat: wire settings and FAQ landing into app routes
ceane Aug 2, 2026
631ef4c
feat: seed spectrum sidebar and fast snapshot from settings defaults
ceane Aug 2, 2026
c0df90e
Continue multisource streaming and demodulation work
ceane Aug 4, 2026
5174304
Fix frontend and Rust test failures
ceane Aug 4, 2026
9fb4552
Merge main and keep multisource fixes
ceane Aug 4, 2026
6360110
Harden legal app archive routes
ceane Aug 5, 2026
4cf1436
Fix RTL FFI cfg gating
ceane Aug 5, 2026
57be5ec
Close legal app export path sink
ceane Aug 5, 2026
700b9df
Fix integration source lifecycle coverage
ceane Aug 5, 2026
28a8813
Migrate app to React Router 8 Framework Mode
ceane Aug 5, 2026
fb0bbb6
Add WebMCP agent coverage and CLI support
ceane Aug 5, 2026
e73eae0
Add versioned IQ demod artifacts and CLI harness
ceane Aug 5, 2026
6340bf0
Share demod DSP processors with frontend and CLI
ceane Aug 5, 2026
c7f1b61
Merge React Router 8 stack into continuing demod
ceane Aug 5, 2026
febb86b
Merge WebMCP and demod stack into continuing demod
ceane Aug 5, 2026
ffb0806
Fix parent branch typecheck errors
ceane Aug 5, 2026
dd1b348
Keep FM station tuning selection stable
ceane Aug 5, 2026
3eff673
Fix live FM demod frame continuity
ceane Aug 5, 2026
def98be
Fix post-login start page card navigation
ceane Aug 5, 2026
e8b542d
WIP: stabilize live FM demodulation
ceane Aug 6, 2026
cae6218
Clarify FM and APT demodulation paths
ceane Aug 6, 2026
a151a6c
Restore demod source playback controls
ceane Aug 6, 2026
c8f33ac
Fix encrypted capture fixture parsing
ceane Aug 7, 2026
a12fbbd
Complete demod capture flow and source lifecycle fixes
ceane Aug 7, 2026
eaa242f
docs: add RMS glossary entry
ceane Aug 7, 2026
1774546
Add signals skill and RX analysis CLI
ceane Aug 7, 2026
85f4188
Migrate learn signals route from /learn-signals to /learn
ceane Aug 7, 2026
3a7994b
refactor: reorganize frontend and backend architecture
ceane Aug 9, 2026
ed5f9f2
test: cover whole channel sample rate exit
ceane Aug 9, 2026
ee93f2c
Fix Tx channel range update loop
ceane Aug 9, 2026
8f4ff18
fix: resolve npm security vulnerabilities
ceane Aug 9, 2026
f01ad08
test: stabilize CI timezone and integration store
ceane Aug 9, 2026
3ae0c04
Remove duplicate FFT Rx IFFT Tx learn page
ceane Aug 9, 2026
3cbadbc
Add SDR++ attribution spacing
ceane Aug 9, 2026
6ed6e53
fix: remove hard-coded Redis test nonces
ceane Aug 9, 2026
88f5606
fix: declare settings attribution styles
ceane Aug 10, 2026
ceb02a2
fix: remediate Aikido security findings
ceane Aug 10, 2026
af37eb7
fix: unify mirrored spectrum presentation contract
ceane Aug 13, 2026
e6d61e6
WIP on mirror spectrum feature, fixed perf regressions
ceane Aug 13, 2026
acb10ca
Fix Waterfall node VFO and compact controls
ceane Aug 13, 2026
7539a63
Improve SDR settings controls
ceane Aug 13, 2026
73816ae
Fix failing CI checks and dependency audit
ceane Aug 13, 2026
a44c370
Complete mirror spectrum, article updates, and bug fixes
ceane Aug 16, 2026
e3f531b
Fix Rust frame-rate expectations and source resume
ceane Aug 16, 2026
43a964c
Fix release retune performance budget
ceane Aug 16, 2026
58d97f2
Add end-to-end Rx Tx performance instrumentation
ceane Aug 16, 2026
868e939
Document Rx Tx performance baseline
ceane Aug 16, 2026
3699663
Fix performance metrics test import boundary
ceane Aug 16, 2026
3c09143
Fix backend bugs and frame-rate optimization
ceane Aug 17, 2026
b0f65f5
Stabilize CI frame budget benchmark
ceane Aug 17, 2026
53626b9
Document real-time device I/O and stream UX rules
ceane Aug 17, 2026
fe0977c
Refresh authenticated navigation and onboarding surfaces
ceane Aug 17, 2026
b723a88
Stabilize mirrored spectrum and source stream presentation
ceane Aug 17, 2026
9985b0e
Harden SDR recovery and source stream ownership
ceane Aug 17, 2026
e1e3897
Add explainer graphics and article tooling
ceane Aug 18, 2026
ef0c0a4
Validate and cap logical frame-rate settings
ceane Aug 18, 2026
e3ae27f
Fix multiplexed stream subscriber lifecycle
ceane Aug 19, 2026
a2e88f7
Propagate RX device options across subscribers
ceane Aug 19, 2026
189fbcf
Sync channel selection across subscribers
ceane Aug 19, 2026
fdec545
Publish local RX tuning changes immediately
ceane Aug 19, 2026
5f375fb
Scope live lifecycle state by stream mode
ceane Aug 19, 2026
c537ce8
Ignore local stream option echoes during channel tuning
ceane Aug 19, 2026
e7a624b
Prevent reconnect pause override render loop
ceane Aug 20, 2026
b1351a2
Keep mirrored subscribers aligned with device tuning
ceane Aug 20, 2026
3ade93b
Prevent startup mirror hydration from freezing streams
ceane Aug 20, 2026
e54317a
Implement high-performance subscriber streaming
ceane Aug 20, 2026
057a2f5
Break frame arrival runtime import cycle
ceane Aug 20, 2026
1af9e8a
Bound client stream frame decode work
ceane Aug 21, 2026
a407c35
Add street sign collage to article
ceane Aug 21, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
53 changes: 47 additions & 6 deletions .agents/AGENTS.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,20 +3,39 @@
Guidance for AI coding agents working on the N-APT RF spectrum analyzer. Keep
feature notes and implementation summaries in `.agents/`.

For signal-processing, IQ-capture, FFT, demodulation, `/learn`, or signals CLI
work, load `.agents/signals/SKILL.md`. It defines the project's plain-language
terminology, current demod modes, evidence standards, and RX-only safety rules.

## Working Rules

- The user normally has the dev server running. Do not start or restart it for
ordinary changes; Vite and Rust hot reload are enabled.
- Keep changes scoped, avoid scratch files, and keep the workspace clean.
- Keep changes as device/source agnostic as possible
- Do not add unrequested design changes or features.
- Do not run `npm run build`; run `npm run build:markdown` only for markdown
article changes.
- Do not use browser automation for testing. If frontend testing is necessary,
use `http://localhost:5173`; `127.0.0.1` is blocked.
- Do not preserve backwards compatibility.
- Prefer inspecting code and focused tests over repeating broad verification.
- Use the Act MCP tool for repository searches.
- Do not add unrequested design changes or features.
- Add regression tests for bugs and run `npm run typecheck` after TypeScript
changes. Run `cargo check` after Rust changes.
- Keep changes scoped, avoid scratch files, and keep the workspace clean.

## Real-Time Device I/O

- Do not log from device I/O paths. This includes RTL-SDR/HackRF callbacks,
sample reads and writes, acquisition hot paths, reader startup/restart,
cancellation, cleanup/drop, and Tx monitor or transmission callbacks.
- Logger formatting and logger locks can delay USB/libusb work and make the
hardware unstable. Use comments to document these constraints, and use
returned errors, state, counters, or deferred control-plane diagnostics to
surface failures after the I/O operation completes.
- Keep the global Tx log disabled; do not re-enable it or add logging around
physical Tx operations without explicit authorization and device-safety
evidence.

## Mock APT SDR Rules

Expand All @@ -29,12 +48,12 @@ feature notes and implementation summaries in `.agents/`.

## I/Q Captures and Privacy

- Never add I/Q capture data to Git. This includes `.napt`, `.wav`, `.iq`, and
related extensions such as `.iq.u8` and `.c64`. Keep captures local or in
- Never add I/Q capture data to Git. This includes `.napt, .iq, .wav`, and
related extensions such as `.c64`. Keep captures local or in
external storage; version only metadata, manifests, and synthetic fixtures.
- Treat every I/Q capture as potentially sensitive: it may reveal information
about the recording environment, and some signals may contain exceptionally
sensitive or otherwise unparalleled information.
sensitive or otherwise private information.
- Treat N-APT captures as the greatest privacy risk in this project. Minimize
copying and exposure, and never share, upload, or commit them without the
user's explicit authorization.
Expand Down Expand Up @@ -87,6 +106,7 @@ build merely to validate a local edit.
### TypeScript and React

- Use strict TypeScript; prefer `unknown` over `any`.
- In tests, import `act` from `@testing-library/react`; do not use `react-dom/test-utils`.
- Use `camelCase` for variables/functions, `PascalCase` for types/components,
and `UPPER_SNAKE_CASE` for constants.
- Keep hook dependency arrays correct and use `useCallback` when passing stable
Expand All @@ -108,10 +128,31 @@ build merely to validate a local edit.
- The main app runs on port 5173. The markdown preview runs on port 5174.
- The login password is `UNSAFE_LOCAL_USER_PASSWORD` in `.env.local`; do not
print or commit secrets.
- Rust logs are in `/tmp/rust_log.txt`; Tx logs are in `/tmp/n-apt/tx_log.txt`.
- Rust logs, both output and errors, are in `/tmp/rust_log.txt`; Tx logs are in `/tmp/n-apt/tx_log.txt`.

## Repository Conventions

- Use `@n-apt/*` for scoped imports.
- When adding Vite aliases for static assets, update Jest `moduleNameMapper` so
tests resolve them through the shared file mock instead of parsing raw assets.

## Learned User Preferences

- Prefer frontend DSP for demodulation so audio/processing changes can be inspected and listened to in real time on the demod route.
- Treat `liveSourceLifecycle` and `sourcePresentationController` as the source of truth for live placeholder and stream lifecycle; FFT/waterfall canvases should only render those states. Paused Rx keeps the last live Rx frame; Tx standby accepts `request_next_frame` previews; transmitting must unfreeze and follow live Tx frames.
- When the backend is down or killed, show Server Down / unavailable — not an indefinite Loading FFT state or optimistic Loading flashes from polling.
- Do not auto-start Tx when opening a Tx device into standby; standby is announce-only until the user explicitly starts transmit.
- Keep VFO and FrequencyRangeSlider scroll/pan responsive; avoid debounce, timer coalescing, or paint gates that stall live spectrum during hardware retune.
- Keep mirror I/Q baseband behavior explicit in `test/ts/basebandMirror.test.ts`; the mirror path should stay GPU-resample focused with performance close to mirror-off.
- Keep build/hot-reload orchestration under `scripts/build`; leave in-app hot-reload notifications in the app code.

## Learned Workspace Facts

- Never lower the hardware sample rate below 3.2 MHz (N-APT Nyquist needs that width); narrower modes such as FM use a bandwidth slice/window inside that sample rate.
- Span bandwidth is a selected slice within the sample-rate window, not the same thing as sample rate.
- The available spectrum display range is 0 Hz to 30 GHz; center/span padding and clamps must respect those bounds (including sample_rate/2 from center). With "Mirror I/Q baseband below 0 Hz" enabled, negative-frequency presentation is allowed without changing what the radio is tuned to.
- Mirror I/Q below 0 Hz is presentation-only: reflect acquired positive baseband across DC via `basebandMirror.ts` and the WebGPU resample path; it must not retune hardware on every pan tick.
- During VFO/slider retune, paint live IQ on each frame's acquisition axis (`center_frequency_hz ± sample_rate/2`) when the requested viewport and frame center diverge; mapping bins onto the scrolled Redux viewport causes channel-island flatlining.
- Agent guidance and related docs live under `.agents/` (including `.agents/AGENTS.md`).
- HackRF One needs LNA/VGA/AMP gain plus baseband bandwidth-filter control, with persistence/control parity similar to other radio gain settings.
- Avoid eagerly loading heavy `/transformers` / transformers.js paths on app startup; they can hang localhost load and should stay excluded or lazy-loaded.
20 changes: 0 additions & 20 deletions .agents/FEATURE_COMPLETION_SUMMARY.md

This file was deleted.

22 changes: 0 additions & 22 deletions .agents/FRAME_RATE_AND_SYNC_FIX.md

This file was deleted.

30 changes: 0 additions & 30 deletions .agents/NON_TTY_BUILD_NOTIFICATIONS.md

This file was deleted.

13 changes: 0 additions & 13 deletions .agents/RUST_HOTLOAD_AND_BUILD_PRUNING.md

This file was deleted.

79 changes: 79 additions & 0 deletions .agents/SECURITY.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,79 @@
# Security Policy

## Scope

This policy covers the n-apt source repository, its Rust backend, TypeScript
frontend, WebSocket endpoints, WASM modules, build scripts, and published
packages or binaries maintained from this repository.

I/Q captures and related recordings are especially sensitive. Do not include
captures, credentials, private keys, or other personal data in a report or
pull request. Share the smallest reproducible artifact possible, preferably a
synthetic fixture or a redacted log.

Never upload captures or derived artifacts to AI tools, security scanners,
issue trackers, or other cloud services. Avoid exposing capture filenames,
metadata, filesystem paths, logs, screenshots, recordings, or crash dumps when
they could identify a person, place, device, or recording environment.

Do not decrypt, copy, transform, or export captures unless necessary for the
requested task. Keep temporary derivatives outside the repository and remove
them after use when they are no longer needed. Use synthetic fixtures or
redacted excerpts for tests, bug reports, and reproductions whenever possible.

## Supported versions

Security fixes are generally made against the default branch and the most
recent release. Older versions may not receive backports.

## Reporting a vulnerability

Please report suspected vulnerabilities privately through GitHub's repository
security advisory / private vulnerability reporting flow for
[ceane/n-apt](https://github.com/ceane/n-apt/security/advisories).

If that flow is unavailable, contact the maintainer through the contact method
listed on the [repository owner profile](https://github.com/ceane) and request
a private security channel. Do not open a public issue for an undisclosed
vulnerability.

Include, when safe to share:

- the affected version, commit, or deployment;
- the component and vulnerability type;
- clear reproduction steps or a minimal proof of concept;
- the security impact and any prerequisites; and
- suggested mitigation, if known.

Please allow time for confirmation, remediation, and coordinated disclosure.
We will acknowledge valid reports, keep the reporter informed when practical,
and credit reporters who want attribution.

## Automated findings and triage

CodeQL alerts and Aikido findings are treated as security signals, not as
automatic proof of exploitability. Maintainers should reproduce or otherwise
validate each finding, identify the affected data flow and reachable
deployment, and record the decision to fix, mitigate, defer, or dismiss.

- **CodeQL:** review alerts in the repository's GitHub Security tab, prioritize
reachable high-impact flows, and retain the alert reference in the change or
triage record.
- **Aikido:** review the trial workspace findings for dependency, secret,
SAST, and infrastructure exposure; verify that the finding maps to this
repository and is not a duplicate of a CodeQL alert.
- **Dependencies and secrets:** rotate exposed credentials immediately, avoid
committing secrets while reproducing a finding, and use lockfile-aware
updates for dependency fixes.

Automated scanners do not replace review of authentication, authorization,
WebSocket input validation, file/capture handling, cryptography, or native
device boundaries.

## Disclosure

Please keep vulnerability details private until a fix or mitigation is
available and a disclosure date has been agreed with the maintainer. Public
security advisories should include affected versions, fixed versions or
mitigations, and upgrade guidance without exposing sensitive captures or
credentials.
Loading
Loading