From 5323798688975a0113c778667e47ce8194456de0 Mon Sep 17 00:00:00 2001 From: BootIntel Agent Date: Mon, 28 Sep 2026 21:24:06 +0000 Subject: [PATCH] Release 0.10.0: the kernel's own hardening report Ships #24. `bootintel verdict` now answers for captures that never reach a U-Boot prompt: a plain boot log states which protections the kernel enforces, and reporting "nothing was assessed" about one of those was false. MINOR for two reasons, either sufficient. New behaviour, and a changed contract: `verdict` used to exit 3 whenever there was no U-Boot session and now exits 3 only when the capture yields neither a session nor a hardening posture. A CI job keyed on that code would previously have treated a real answer as a failure to answer. A capture with neither still exits 3, and that case is tested. Both implementations reproduce the shared expectation byte for byte across eight fixtures, five of them real corpus captures rather than synthetic. 364 tests pass, clippy clean under -D warnings, rustfmt clean, release binary reports 0.10.0. Both version bumps landed first try, which is the third release running for docs/releasing.md step 1. Co-Authored-By: Claude Opus 5 (1M context) --- CHANGELOG.md | 9 ++++++++- Cargo.lock | 4 ++-- Cargo.toml | 2 +- crates/cli/Cargo.toml | 2 +- 4 files changed, 12 insertions(+), 5 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index ee98cdc..937f676 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -8,6 +8,12 @@ All notable changes to bootintel-cli are documented here. Format follows [Keep a ## [Unreleased] +## [0.10.0] — 2026-09-28 — the kernel's own hardening report + +`bootintel verdict` now answers for captures that never reach a U-Boot prompt. +A plain boot log states which protections the kernel enforces, and reporting +"nothing was assessed" about one of those was false. + ### Added - **`bootintel verdict` now reports the kernel hardening posture** alongside the boot chain: mandatory access control, memory initialisation, and kernel address @@ -710,7 +716,8 @@ Initial release. All six subcommands live; five branch-based milestones (M1-M5) - PDF report download subcommand — server-side endpoint exists but no client-side wrapper yet. - Windows support — the Rust code compiles for Windows and the release workflow builds it, but install.sh doesn't handle Windows yet (`.ps1` installer is a follow-up). -[Unreleased]: https://github.com/bootintel/cli/compare/cli-v0.9.0...HEAD +[Unreleased]: https://github.com/bootintel/cli/compare/cli-v0.10.0...HEAD +[0.10.0]: https://github.com/bootintel/cli/releases/tag/cli-v0.10.0 [0.9.0]: https://github.com/bootintel/cli/releases/tag/cli-v0.9.0 [0.8.0]: https://github.com/bootintel/cli/releases/tag/cli-v0.8.0 [0.7.0]: https://github.com/bootintel/cli/releases/tag/cli-v0.7.0 diff --git a/Cargo.lock b/Cargo.lock index ae2d208..bbed8aa 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -131,7 +131,7 @@ checksum = "b588b76d00fde79687d7646a9b5bdf3cc0f655e0bbd080335a95d7e96f3587da" [[package]] name = "bootintel" -version = "0.9.0" +version = "0.10.0" dependencies = [ "anyhow", "arboard", @@ -154,7 +154,7 @@ dependencies = [ [[package]] name = "bootintel-detectors" -version = "0.9.0" +version = "0.10.0" dependencies = [ "regex", ] diff --git a/Cargo.toml b/Cargo.toml index c23cdd3..ffdf716 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -19,7 +19,7 @@ members = ["crates/detectors", "crates/cli"] resolver = "2" [workspace.package] -version = "0.9.0" +version = "0.10.0" edition = "2021" rust-version = "1.90" license = "Apache-2.0" diff --git a/crates/cli/Cargo.toml b/crates/cli/Cargo.toml index 6df58af..4103bb4 100644 --- a/crates/cli/Cargo.toml +++ b/crates/cli/Cargo.toml @@ -24,7 +24,7 @@ path = "src/main.rs" # version when packaging for crates.io, which rejects a bare path dep. # This is what publish = false was working around; publishing # bootintel-detectors first makes the workaround unnecessary. -bootintel-detectors = { path = "../detectors", version = "0.9.0" } +bootintel-detectors = { path = "../detectors", version = "0.10.0" } clap = { version = "4.5", features = ["derive", "wrap_help", "env"] } # Shell-completion emitters for `bootintel completions `. Version # tracks the clap major/minor (4.5). No default features — we only use