diff --git a/CHANGELOG.md b/CHANGELOG.md
index fac762f..f378b7f 100644
--- a/CHANGELOG.md
+++ b/CHANGELOG.md
@@ -5,8 +5,16 @@ The format follows [Keep a Changelog](https://keepachangelog.com/); versions fol
## [Unreleased]
+## [0.7.0] - 2026-09-25
+
### Added
+- **A Tools tab, with a filter tester.** Pick a field from the Control page, type an
+ expression and a value, and see at once whether they match - and which part of the
+ expression decided it, for example the `!10.0.5.0/24` that excluded `10.0.5.7`. A value
+ that is not an address, a port or a PID is reported as that, not as "does not match".
+ "Use in the Control field" puts the expression into that field.
+
- **Sockets, on the Tools tab.** Every TCP and UDP socket on this computer, like
`netstat -ano`, with no session needed: what is listening, what is connected, its state
and the program that owns it. See which port your application listens on before you
@@ -20,12 +28,6 @@ The format follows [Keep a Changelog](https://keepachangelog.com/); versions fol
on a port nothing seems to use is often in a range Windows set aside, and this shows it
at once. Nothing is sent over the network. It is the second tab of the Tools page.
-- **A Tools tab, with a filter tester.** Pick a field from the Control page, type an
- expression and a value, and see at once whether they match - and which part of the
- expression decided it, for example the `!10.0.5.0/24` that excluded `10.0.5.7`. A value
- that is not an address, a port or a PID is reported as that, not as "does not match".
- "Use in the Control field" puts the expression into that field.
-
- **Diagnostics, on the Tools tab.** When START will not work, this shows why without a
console: the same checks as `--doctor`, each marked OK, Warning or Problem, with a "?"
that explains them in plain words. "Clean up the driver" unloads a WinDivert driver that
@@ -70,7 +72,7 @@ The format follows [Keep a Changelog](https://keepachangelog.com/); versions fol
The run now says it once, and still runs, because impairing one direction on purpose is a
perfectly good thing to ask for.
-- **Some command-line shortcuts stopped working, and the full flags did not.** Adding the
+- **Some shortened command-line options no longer work. The full ones still do.** Adding the
upload flags means `--latency` is no longer the only option starting with "latency", so
short forms like `--lat`, `--jit`, `--j`, `--cor` and `--spike-p` are now ambiguous and are
refused. Every full flag still works, so saved reproduction commands and every example in
@@ -92,16 +94,25 @@ The format follows [Keep a Changelog](https://keepachangelog.com/); versions fol
### Docs
-- **The README now points at the website.** One link under the badges, and a second after the
- quick start for anyone who wants a walkthrough of a single task instead of the full manual.
- The guides there cover packet loss, latency, speed limits, aiming at one app and testing with
- no internet, each with the numbers worth trying and the command that does it.
+- **The README now points at the website.** A link after the quick start leads to the guides,
+ for anyone who wants a walkthrough of a single task instead of the full manual. They cover
+ packet loss, latency, speed limits, aiming at a single app and testing with no internet, each
+ with the numbers worth trying and the command that does it.
- **The website's front page now shows the command it was talking about.** It said one command is
enough to check that a service survives 10 percent packet loss, and then did not print one,
which every other page on the site does. It now shows the command, says that the run stops
itself when the time is up, and points at the rehearsal switch that changes no real traffic.
+- **The website's download page describes the release as it is.** It mentions the installer
+ next to the zip and lists every file a release carries. The command it gave for checking a
+ download failed for everyone. It is now the same command as in the README, which is run
+ against every published release.
+
+- **The website no longer says the program is unsigned.** It has been signed since 0.5.0. The
+ download and questions pages now say so, and explain that Windows can still warn for a while
+ because the certificate is new.
+
## [0.6.0] - 2026-09-04
### Added
diff --git a/VERSION.txt b/VERSION.txt
index a918a2a..faef31a 100644
--- a/VERSION.txt
+++ b/VERSION.txt
@@ -1 +1 @@
-0.6.0
+0.7.0
diff --git a/site/pages/download/en.html b/site/pages/download/en.html
index 1ea701b..4684db1 100644
--- a/site/pages/download/en.html
+++ b/site/pages/download/en.html
@@ -1,7 +1,7 @@
One archive, no installer. Unpack it, run the executable, and it asks for
- administrator rights itself. A zip that runs without installing anything, or an installer for everyone on
+ the computer. Either way, the program asks for administrator rights itself. Every release publishes three files, and the two beside the archive are there so you do not
- have to take the download on trust: A release publishes five files. Two are the program, and the other three are there so you
+ do not have to take the download on trust: The checksum answers "did this arrive unchanged". In PowerShell, compare the output with the
- line in Download Bean Network Tester
- The facts, in one place
.msi installer, which adds a Start Menu entry and puts the program on
+ PATH (it needs administrator rights).The facts, in one place
What is in the release
-
Checking that you got what we built
SHA256SUMS.txt:SHA256SUMS.txt (for the installer, put .msi in place of
+ .zip):
Get-FileHash .\BeanNetworkTester-*.zip -Algorithm SHA256
The signature answers a different question - "did this come out of that repository" - and needs the GitHub command-line tool:
-gh attestation verify .\BeanNetworkTester-*.zip --repo donislawdev/BeanNetworkTester
+gh attestation verify BeanNetworkTester-vX.Y.Z-windows-x64.zip --repo donislawdev/BeanNetworkTester --predicate-type https://spdx.dev/Document/v2.3
+ Type the name of the zip you downloaded as the first part - gh does not accept a
+ * there. Keep --predicate-type: without it gh looks for a
+ different kind of statement and reports that it found none.
A checksum you copy from the same page as the download proves less than a signature. Both are published, so both are worth a moment.
The executable is not signed with a paid certificate, so SmartScreen flags it as something it - has not seen before. That is a statement about the certificate, not about the file - which is - exactly why the checksum and the signature are published. The - questions page covers this and what the driver needs.
+The program and the installer are signed, so Windows names who signed them instead of saying + "Unknown publisher". The certificate is new, so SmartScreen may still warn for a while - it has + not seen it often yet. That is about the certificate, not about the file, and the two checks + above let you verify the file yourself. The questions page covers this and + what the driver needs.
Jedno archiwum, bez instalatora. Rozpakuj, uruchom plik wykonywalny, a on sam - poprosi o prawa administratora.
+Archiwum zip, które działa bez instalowania, albo instalator dla wszystkich + użytkowników komputera. W obu przypadkach program sam poprosi o prawa administratora.
@@ -13,7 +13,9 @@.msi, który dodaje program do menu Start i do PATH
+ (wymaga praw administratora).Każde wydanie publikuje trzy pliki, a te dwa obok archiwum są po to, żebyś nie musiał brać - pobrania na wiarę:
+Wydanie publikuje pięć plików. Dwa to program, a pozostałe trzy są po to, żebyś nie musiał + brać pobrania na wiarę:
Suma kontrolna odpowiada na pytanie „czy plik dotarł niezmieniony". W PowerShellu porównaj
- wynik z linią w SHA256SUMS.txt:
SHA256SUMS.txt (dla instalatora wpisz .msi zamiast
+ .zip):
Get-FileHash .\BeanNetworkTester-*.zip -Algorithm SHA256
Podpis odpowiada na inne pytanie - „czy to wyszło z tego repozytorium" - i wymaga narzędzia linii komend GitHuba:
-gh attestation verify .\BeanNetworkTester-*.zip --repo donislawdev/BeanNetworkTester
+gh attestation verify BeanNetworkTester-vX.Y.Z-windows-x64.zip --repo donislawdev/BeanNetworkTester --predicate-type https://spdx.dev/Document/v2.3
+ Jako pierwszą część wpisz nazwę pobranego pliku zip - gh nie przyjmuje tam
+ *. Zostaw --predicate-type: bez niego gh szuka innego
+ rodzaju poświadczenia i odpowiada, że żadnego nie znalazł.
Suma kontrolna skopiowana z tej samej strony, z której pobierasz plik, dowodzi mniej niż podpis. Publikujemy oba, więc oba są warte chwili.
Plik wykonywalny nie jest podpisany płatnym certyfikatem, więc SmartScreen oznacza go jako - coś, czego wcześniej nie widział. To zdanie o certyfikacie, nie o pliku - i właśnie dlatego suma - kontrolna i podpis są opublikowane. Strona z pytaniami - opisuje to oraz czego potrzebuje sterownik.
+Program i instalator są podpisane, więc Windows pokazuje, kto je podpisał, zamiast + nieznanego wydawcy. Certyfikat jest nowy, więc SmartScreen może jeszcze przez jakiś czas + ostrzegać - rzadko go dotąd widział. To zdanie o certyfikacie, nie o pliku, a dwa sprawdzenia + powyżej pozwalają zweryfikować plik samodzielnie. + Strona z pytaniami opisuje to oraz czego potrzebuje + sterownik.
Because the executable is new and unsigned, and SmartScreen flags anything it has not seen - before. A code-signing certificate is a yearly cost, not a statement about the file. Every release - publishes a SHA-256 checksum, a list of components, and a signature tying the two to the build that - produced them, so you can verify what you downloaded instead of trusting a green tick.
+The program is signed, so the warning names who signed it instead of saying "Unknown + publisher". SmartScreen can still warn for a while, because the certificate is new and it has not + seen it often yet. Some antivirus tools may also react to a program that asks for administrator + rights and loads a network driver. Every release publishes a SHA-256 checksum and a signed list of + its components, so you can verify what you downloaded instead of trusting a green tick.
Bo plik jest nowy i niepodpisany, a SmartScreen oznacza wszystko, czego wcześniej nie widział. - Certyfikat do podpisywania kodu to koszt roczny, nie opinia o pliku. Każde wydanie publikuje sumę - kontrolną SHA-256, listę komponentów i podpis wiążący jedno z drugim z buildem, który je wytworzył - - więc możesz sprawdzić, co pobrałeś, zamiast wierzyć zielonemu znaczkowi.
+Program jest podpisany, więc ostrzeżenie pokazuje, kto go podpisał, zamiast nieznanego + wydawcy. SmartScreen może jeszcze przez jakiś czas ostrzegać, bo certyfikat jest nowy i rzadko go + dotąd widział. Niektóre antywirusy mogą też reagować na program, który prosi o prawa + administratora i ładuje sterownik sieciowy. Każde wydanie publikuje sumę kontrolną SHA-256 i + podpisaną listę komponentów, więc możesz sprawdzić, co pobrałeś, zamiast wierzyć zielonemu + znaczkowi.