Skip to content

Release 0.8.0: read the boot chain on the bench, offline - #19

Merged
Zenofex merged 1 commit into
mainfrom
release/0.8.0
Sep 28, 2026
Merged

Zenofex merged 1 commit into
mainfrom
release/0.8.0

Conversation

@Zenofex

@Zenofex Zenofex commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Version bump, lockfile, changelog, and one docs fix. No code changes: everything in this release is already on main and was reviewed in #17 and #18.

What ships

#17 bootintel verdict <capture> — assess a U-Boot session offline
#18 analyze --interrupt-autoboot — take the prompt and pull the environment

Together: bench to verdict with no upload and no typing.

Why MINOR

Two new subcommands' worth of surface and no behaviour change for anyone who does not use them. The policy at the top of CHANGELOG.md reserves PATCH for changes with no user-visible behaviour change, and MAJOR for renamed flags, schema changes, or exit-code policy changes.

The one non-mechanical change

crates/cli/Cargo.toml pins bootintel-detectors by exact version, because the published binary crate has to name a version that exists on the index. That bump is part of cutting a release rather than something cargo derives, and forgetting it fails cargo update -w immediately, so it cannot reach a release quietly. It is still the step that gets missed, so docs/releasing.md step 1 now names it.

Verification

  • cargo test --workspace: 349 passed, 0 failed
  • cargo clippy --workspace --all-targets -- -D warnings: clean
  • cargo fmt --all --check: clean
  • cargo build --release then bootintel --version reports bootintel 0.8.0

After merge: dispatch cli-release for 0.8.0 with publish_crates, verify the draft against SHA256SUMS, publish and mark latest, then move the Homebrew formula.

🤖 Generated with Claude Code

Two halves of one workflow, both merged and green: take the U-Boot prompt on a
board in front of you (#18), and turn what you pull off it into a verdict
(#17). Everything runs on the operator's machine, which is the only version a
consultancy under an NDA can use.

MINOR rather than PATCH under the policy at the top of CHANGELOG.md: two new
subcommands' worth of surface, no behaviour changed for anyone who does not use
them.

`bootintel-detectors` is pinned by exact version in crates/cli/Cargo.toml, so
that bump is part of a release rather than something cargo derives. It fails
`cargo update -w` loudly when missed, so it cannot reach a release quietly, but
it is the step that gets forgotten; docs/releasing.md now says so in step 1.

349 tests pass, clippy clean under -D warnings, rustfmt clean.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Zenofex
Zenofex merged commit ca30403 into main Sep 28, 2026
11 checks passed
@Zenofex
Zenofex deleted the release/0.8.0 branch September 28, 2026 06:40
Zenofex added a commit that referenced this pull request Sep 28, 2026
…nment (#22)

Version bump, lockfile, changelog. No code changes: everything shipping
here is already on `main` and was reviewed in #21.

## What ships

The boot-chain verdict stops hedging when the capture answers the
question itself. A log containing `Verifying Checksum ... OK` no longer
gets "bootcmd boots an image without a visible verification step" while
the visible step sits twenty lines away. New `Secure boot anchor` entry
for an unblown i.MX HAB fuse, emitted without needing a `printenv` since
the fact doesn't depend on one.

What it still won't do is call a checksum a signature: a passing CRC is
`confirmed`, never `hardened`.

Both implementations now reproduce `expect.txt` byte for byte across
five fixtures, two of them real corpus captures.

## Why MINOR

Either reason alone is enough:

- New verdict behaviour.
- **Breaking library API**: `boot_chain::assess` returns an `Assessment
{ session, integrity, verdicts }` instead of a `(UbootSession,
Vec<Verdict>)` tuple, and `verdict` takes the integrity alongside the
session.

The policy at the top of `CHANGELOG.md` puts a pre-1.0 breaking change
on the minor. **No CLI flag, output or exit code changed**, so nothing
changes for anyone using the binary.

## The step that used to get missed

`crates/cli/Cargo.toml` pins `bootintel-detectors` by exact version and
cargo does not derive it. Both bumps landed first try because
`docs/releasing.md` step 1 now names it — added in #19 after it bit the
0.8.0 cut.

## Verification

- `cargo test --workspace`: 355 passed, 0 failed
- `clippy --workspace --all-targets -- -D warnings` and `fmt --all
--check`: clean
- `cargo build --release` then `bootintel --version` reports `bootintel
0.9.0`
- Ran the release binary against the new fixtures

After merge: dispatch `cli-release` for `0.9.0` with `publish_crates`,
verify the draft against `SHA256SUMS`, publish and mark latest, then
move the tap (step 7) and sync the in-repo reference copy.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant