Repository navigation
Release 0.6.1: the gate survives a pipe, and history is opt-in - #15
Merged
Merged
Conversation
scan --gate-critical could report success on a capture that trips the gate. Measured on the 0.6.0 release binary, piping into head with output over the 64 KB pipe buffer: exit 1, then 0, then 0, on a log with telnet exposed. A CI job piping through head or tee would go green on a device with a critical exposure, non-deterministically, which is the worst direction for a gate to fail. Cause was ordering. The output write ran before the gate check, so a broken pipe propagated up and main.rs turned it into exit 0 before any verdict was evaluated. That handler is right that a reader closing the pipe is not an error, but it must not become a verdict. The pipe error is now swallowed at the write site only, and the gates decide on findings alone, which do not depend on whether anyone was still reading. Any other write error is still fatal, and manpage | head still exits 0 silently. Scan history is now opt in. It was on by default with an opt-out and a one-time notice, which is the wrong default for a tool whose pitch is that it uploads nothing: a record of every log path a consultant analysed should not appear on disk because nobody said no. `bootintel doctor` disclosing it on a fresh machine is what prompted this. no_history and BOOTINTEL_NO_HISTORY still mean off, so anyone who had opted out stays opted out, and an explicit off beats an explicit on so a machine-wide opt-out cannot be re-enabled by a config file. Numbered 0.6.1 by request. I flagged that a changed default is not really PATCH under the policy at the top of CHANGELOG.md, and that someone upgrading will find history silently stopped. The warning is therefore the first thing in the 0.6.1 entry rather than implied by a version digit. Two things the testing changed. My first attempt to reproduce the pipe bug used the default 361-byte output, well under the pipe buffer, so both binaries returned 1 and it looked unreproducible; inflating with --context exposed it. That is the second time today a negative result was an artefact of too small a test. And four tests failed when the history default inverted, correctly, and were updated to assert the new contract rather than weakened. Verified on the built binary: four consecutive piped gate runs all exit 1; manpage | head exits 0; no history file by default; one when BOOTINTEL_HISTORY=1; `config list` shows the new key. 310 tests pass, clippy clean under -D warnings, rustfmt clean, cargo deny all ok. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Read the second item before upgrading. It changes a default.
scan --gate-criticalcould report success on a capture that trips the gateMeasured on the 0.6.0 release binary, piping into
headwith output over the 64 KB pipe buffer, on a log with telnet exposed:A CI job piping through
headorteewould go green on a device with a critical exposure, non-deterministically.Cause was ordering: the output write ran before the gate check, so a broken pipe propagated up and
main.rsturned it into exit 0 before any verdict was evaluated. That handler is right that a reader closing the pipe is not an error, but it must not become a verdict. The pipe error is now swallowed at the write site only; the gates decide on findings alone. Any other write error is still fatal, andmanpage | headstill exits 0 silently.Scan history is now opt in
If you relied on it, it has stopped. Enable with
bootintel config set history trueorBOOTINTEL_HISTORY=1.It was on by default with an opt-out. That is the wrong default for a tool whose pitch is that it uploads nothing.
bootintel doctordisclosing it on a fresh machine is what prompted the change.no_historystill means off, and an explicit off beats an explicit on so a machine-wide opt-out cannot be re-enabled by a config file.On the version number
Numbered 0.6.1 by request. I flagged that a changed default is not really PATCH under the policy in CHANGELOG.md, and that someone upgrading will find history silently stopped. The warning is the first thing in the changelog entry rather than implied by the digit.
Testing notes
My first attempt to reproduce the pipe bug used the default 361-byte output, well under the pipe buffer, so both binaries returned 1 and it looked unreproducible. Inflating with
--contextexposed it. Four tests failed when the history default inverted, correctly, and were updated to assert the new contract rather than weakened.310 tests pass, clippy clean under
-D warnings, rustfmt clean,cargo deny checkall ok.