Repository navigation
Release 0.8.0: read the boot chain on the bench, offline - #19
Merged
Merged
Conversation
Two halves of one workflow, both merged and green: take the U-Boot prompt on a board in front of you (#18), and turn what you pull off it into a verdict (#17). Everything runs on the operator's machine, which is the only version a consultancy under an NDA can use. MINOR rather than PATCH under the policy at the top of CHANGELOG.md: two new subcommands' worth of surface, no behaviour changed for anyone who does not use them. `bootintel-detectors` is pinned by exact version in crates/cli/Cargo.toml, so that bump is part of a release rather than something cargo derives. It fails `cargo update -w` loudly when missed, so it cannot reach a release quietly, but it is the step that gets forgotten; docs/releasing.md now says so in step 1. 349 tests pass, clippy clean under -D warnings, rustfmt clean. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Zenofex
added a commit
that referenced
this pull request
Sep 28, 2026
…nment (#22) Version bump, lockfile, changelog. No code changes: everything shipping here is already on `main` and was reviewed in #21. ## What ships The boot-chain verdict stops hedging when the capture answers the question itself. A log containing `Verifying Checksum ... OK` no longer gets "bootcmd boots an image without a visible verification step" while the visible step sits twenty lines away. New `Secure boot anchor` entry for an unblown i.MX HAB fuse, emitted without needing a `printenv` since the fact doesn't depend on one. What it still won't do is call a checksum a signature: a passing CRC is `confirmed`, never `hardened`. Both implementations now reproduce `expect.txt` byte for byte across five fixtures, two of them real corpus captures. ## Why MINOR Either reason alone is enough: - New verdict behaviour. - **Breaking library API**: `boot_chain::assess` returns an `Assessment { session, integrity, verdicts }` instead of a `(UbootSession, Vec<Verdict>)` tuple, and `verdict` takes the integrity alongside the session. The policy at the top of `CHANGELOG.md` puts a pre-1.0 breaking change on the minor. **No CLI flag, output or exit code changed**, so nothing changes for anyone using the binary. ## The step that used to get missed `crates/cli/Cargo.toml` pins `bootintel-detectors` by exact version and cargo does not derive it. Both bumps landed first try because `docs/releasing.md` step 1 now names it — added in #19 after it bit the 0.8.0 cut. ## Verification - `cargo test --workspace`: 355 passed, 0 failed - `clippy --workspace --all-targets -- -D warnings` and `fmt --all --check`: clean - `cargo build --release` then `bootintel --version` reports `bootintel 0.9.0` - Ran the release binary against the new fixtures After merge: dispatch `cli-release` for `0.9.0` with `publish_crates`, verify the draft against `SHA256SUMS`, publish and mark latest, then move the tap (step 7) and sync the in-repo reference copy. 🤖 Generated with [Claude Code](https://claude.com/claude-code) Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Version bump, lockfile, changelog, and one docs fix. No code changes: everything in this release is already on
mainand was reviewed in #17 and #18.What ships
bootintel verdict <capture>— assess a U-Boot session offlineanalyze --interrupt-autoboot— take the prompt and pull the environmentTogether: bench to verdict with no upload and no typing.
Why MINOR
Two new subcommands' worth of surface and no behaviour change for anyone who does not use them. The policy at the top of
CHANGELOG.mdreserves PATCH for changes with no user-visible behaviour change, and MAJOR for renamed flags, schema changes, or exit-code policy changes.The one non-mechanical change
crates/cli/Cargo.tomlpinsbootintel-detectorsby exact version, because the published binary crate has to name a version that exists on the index. That bump is part of cutting a release rather than something cargo derives, and forgetting it failscargo update -wimmediately, so it cannot reach a release quietly. It is still the step that gets missed, sodocs/releasing.mdstep 1 now names it.Verification
cargo test --workspace: 349 passed, 0 failedcargo clippy --workspace --all-targets -- -D warnings: cleancargo fmt --all --check: cleancargo build --releasethenbootintel --versionreportsbootintel 0.8.0After merge: dispatch
cli-releasefor0.8.0withpublish_crates, verify the draft againstSHA256SUMS, publish and mark latest, then move the Homebrew formula.🤖 Generated with Claude Code