ZubiSniffer 2.0.0 FINAL — Evidence-Based Full IPv4/UDP Session Release
======================================================================

FINAL PROJECT RULE
------------------
ZubiSniffer only displays endpoints actually observed by the selected capture
interface. It never invents endpoints, ownership, latency, usernames, or traffic
roles. Unresolved classification remains UNKNOWN. "P2P CANDIDATE" is explicitly
a candidate signal, not proof that a real person owns or uses an IP.

CUSTOM UI / LOGIN
-----------------
- Custom ZUBI icon-only shell remains the only visible main navigation:
  Packet Cap / IP Vault / Settings / About.
- Legacy Session Sniffer menu/header/status UI remains detached from QMainWindow.
- Login is now an application-modal, frameless auth surface that covers the parent
  workspace during re-authentication and covers the active screen at startup.
- Login uses a responsive 360-520px card inside a scroll area instead of the old
  fixed 410px card / 560x760 dialog geometry.
- Password reveal, remember-username, forced-password-change, Advanced API address,
  keyboard submit flow, and existing authentication backend are preserved.
- Snow/Rain/Stars/Clouds/Neon Grid/custom media continue through the shared global
  background engine and remain click-through.

REAL FULL-SESSION IPv4/UDP VISIBILITY
-------------------------------------
- The legacy default that blocked every bundled third-party/server provider range
  has been removed for new installs.
- Existing installs still using that exact untouched legacy default are migrated
  automatically to the full-session profile. Custom provider-filter subsets are
  preserved.
- The legacy default RTCP, DTLS and Classic STUN blockers are disabled in that same
  untouched-profile migration and are disabled by default for new installs.
- The old blanket BPF exclusion of UDP ports 0-1023 was removed. Real service
  traffic such as UDP/443 can now enter the capture pipeline.
- Explicit configurable noise filters (SSDP, LLMNR, etc.), custom IP blocks,
  provider filters, custom BPF and other user-selected filters remain available.
- Scope is stated honestly in the UI: current PacketCapture parses IPv4/UDP. It
  does not pretend to capture TCP or packets that never reach the selected adapter.

TRAFFIC VIEWS / CLASSIFICATION
------------------------------
Packet Cap now has four custom views:
- ALL: every currently observed remote IPv4/UDP endpoint that survives configured
  capture filters, including unresolved endpoints.
- P2P: P2P CANDIDATE endpoints only.
- SERVER: known bundled provider-CIDR matches plus endpoints whose completed
  IP-API metadata reports hosting=true.
- HYBRID: evidence-classified SERVER/HOSTING + P2P CANDIDATE endpoints; UNKNOWN is
  intentionally hidden.

New Packet Cap columns include CLASS, PROVIDER and live RATE. Classification
evidence is exposed in tooltips and can be copied from the row context menu.
Known Sony/PlayStation CIDRs are labeled from the existing bundled provider-range
database; generic hosting metadata is never promoted into a fake Sony/relay label.

SESSION ALERTS
--------------
- Existing lifecycle join/rejoin/left events drive the popup system; alerts are not
  generated from repeated packets.
- Manually saved Vault IPs retain the exact saved-user detection/disconnection
  wording and list-specific colors/sounds.
- Unsaved infrastructure endpoints are not called "players" or "people".
- Unsaved peer candidates use P2P CANDIDATE wording; unresolved rows use ENDPOINT
  wording until evidence exists.

IP VAULT
--------
Saved IPs can be copied with:
- Copy IP toolbar button
- right-click -> Copy IP
- Ctrl+C on the selected Vault row
Manual-only saving and the five list classes remain unchanged.

SETTINGS / INTERFACE
--------------------
- One custom Settings destination remains.
- Capture Runtime now reports whether server/provider visibility is complete or
  which relevant filters make it intentionally incomplete.
- Interface switching remains transactional, preserves started/stopped state, and
  treats different IP targets on the same NIC as distinct capture targets.
- Custom interface picker and global effects are preserved.

VERIFICATION
------------
- Project version: 2.0.0
- pytest: 72 passed
- python -m compileall -q src tests tools: PASS
- tools/build/preflight.py: PASS — ZubiSniffer 2.0.0
- provider classifier cached benchmark: 4000 lookups in ~0.004s in this container

TARGET-RUNTIME NOTE
-------------------
This packaging container does not include PySide6, so it cannot truthfully perform
a real Qt/Windows render launch. The Windows source package includes BUILD_EXE.bat,
which creates the Python 3.14 x64 environment, installs declared dependencies,
runs compile/preflight checks, then builds the PyInstaller app and Inno Setup
installer on the Windows target machine.

Default Packet Cap view
-----------------------
- Packet Cap now opens in EVERYTHING mode by default. This is the ALL traffic view and shows every remote endpoint actually observed by the selected capture interface before optional view filtering.
