Repository navigation
Release 0.9.0: the verdict reads the boot output, not just the environment - #22
Merged
Merged
Conversation
…nment Ships #21. The engine and the CLI now reproduce one committed expectation byte for byte across five fixtures, two of them real corpus captures rather than synthetic, so the offline verdict and the dashboard cannot disagree about a device without a test going red in one of the two repos. MINOR rather than PATCH for two reasons, either sufficient: new verdict behaviour, and a breaking change to the library API (`boot_chain::assess` returns an `Assessment` struct instead of a tuple). The policy at the top of CHANGELOG.md puts a pre-1.0 breaking change on the minor. No CLI flag, output or exit code changed. Both version bumps landed first try this time, which is what step 1 of docs/releasing.md now exists for: the `bootintel-detectors` pin in crates/cli/Cargo.toml is not derived by cargo and was the step that got missed. 355 tests pass, clippy clean under -D warnings, rustfmt clean, release binary reports 0.9.0. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Version bump, lockfile, changelog. No code changes: everything shipping here is already on
mainand was reviewed in #21.What ships
The boot-chain verdict stops hedging when the capture answers the question itself. A log containing
Verifying Checksum ... OKno longer gets "bootcmd boots an image without a visible verification step" while the visible step sits twenty lines away. NewSecure boot anchorentry for an unblown i.MX HAB fuse, emitted without needing aprintenvsince the fact doesn't depend on one.What it still won't do is call a checksum a signature: a passing CRC is
confirmed, neverhardened.Both implementations now reproduce
expect.txtbyte for byte across five fixtures, two of them real corpus captures.Why MINOR
Either reason alone is enough:
boot_chain::assessreturns anAssessment { session, integrity, verdicts }instead of a(UbootSession, Vec<Verdict>)tuple, andverdicttakes the integrity alongside the session.The policy at the top of
CHANGELOG.mdputs a pre-1.0 breaking change on the minor. No CLI flag, output or exit code changed, so nothing changes for anyone using the binary.The step that used to get missed
crates/cli/Cargo.tomlpinsbootintel-detectorsby exact version and cargo does not derive it. Both bumps landed first try becausedocs/releasing.mdstep 1 now names it — added in #19 after it bit the 0.8.0 cut.Verification
cargo test --workspace: 355 passed, 0 failedclippy --workspace --all-targets -- -D warningsandfmt --all --check: cleancargo build --releasethenbootintel --versionreportsbootintel 0.9.0After merge: dispatch
cli-releasefor0.9.0withpublish_crates, verify the draft againstSHA256SUMS, publish and mark latest, then move the tap (step 7) and sync the in-repo reference copy.🤖 Generated with Claude Code