Skip to content

Release 0.9.0: the verdict reads the boot output, not just the environment - #22

Merged
Zenofex merged 1 commit into
mainfrom
release/0.9.0
Sep 28, 2026
Merged

Zenofex merged 1 commit into
mainfrom
release/0.9.0

Conversation

@Zenofex

@Zenofex Zenofex commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Version bump, lockfile, changelog. No code changes: everything shipping here is already on main and was reviewed in #21.

What ships

The boot-chain verdict stops hedging when the capture answers the question itself. A log containing Verifying Checksum ... OK no longer gets "bootcmd boots an image without a visible verification step" while the visible step sits twenty lines away. New Secure boot anchor entry for an unblown i.MX HAB fuse, emitted without needing a printenv since the fact doesn't depend on one.

What it still won't do is call a checksum a signature: a passing CRC is confirmed, never hardened.

Both implementations now reproduce expect.txt byte for byte across five fixtures, two of them real corpus captures.

Why MINOR

Either reason alone is enough:

  • New verdict behaviour.
  • Breaking library API: boot_chain::assess returns an Assessment { session, integrity, verdicts } instead of a (UbootSession, Vec<Verdict>) tuple, and verdict takes the integrity alongside the session.

The policy at the top of CHANGELOG.md puts a pre-1.0 breaking change on the minor. No CLI flag, output or exit code changed, so nothing changes for anyone using the binary.

The step that used to get missed

crates/cli/Cargo.toml pins bootintel-detectors by exact version and cargo does not derive it. Both bumps landed first try because docs/releasing.md step 1 now names it — added in #19 after it bit the 0.8.0 cut.

Verification

  • cargo test --workspace: 355 passed, 0 failed
  • clippy --workspace --all-targets -- -D warnings and fmt --all --check: clean
  • cargo build --release then bootintel --version reports bootintel 0.9.0
  • Ran the release binary against the new fixtures

After merge: dispatch cli-release for 0.9.0 with publish_crates, verify the draft against SHA256SUMS, publish and mark latest, then move the tap (step 7) and sync the in-repo reference copy.

🤖 Generated with Claude Code

…nment

Ships #21. The engine and the CLI now reproduce one committed expectation byte
for byte across five fixtures, two of them real corpus captures rather than
synthetic, so the offline verdict and the dashboard cannot disagree about a
device without a test going red in one of the two repos.

MINOR rather than PATCH for two reasons, either sufficient: new verdict
behaviour, and a breaking change to the library API (`boot_chain::assess` returns
an `Assessment` struct instead of a tuple). The policy at the top of
CHANGELOG.md puts a pre-1.0 breaking change on the minor. No CLI flag, output or
exit code changed.

Both version bumps landed first try this time, which is what step 1 of
docs/releasing.md now exists for: the `bootintel-detectors` pin in
crates/cli/Cargo.toml is not derived by cargo and was the step that got missed.

355 tests pass, clippy clean under -D warnings, rustfmt clean, release binary
reports 0.9.0.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Zenofex
Zenofex merged commit 3caebef into main Sep 28, 2026
11 checks passed
@Zenofex
Zenofex deleted the release/0.9.0 branch September 28, 2026 10:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant