Release 0.10.0: the kernel's own hardening report - #25
Merged
Merged
Conversation
Ships #24. `bootintel verdict` now answers for captures that never reach a U-Boot prompt: a plain boot log states which protections the kernel enforces, and reporting "nothing was assessed" about one of those was false. MINOR for two reasons, either sufficient. New behaviour, and a changed contract: `verdict` used to exit 3 whenever there was no U-Boot session and now exits 3 only when the capture yields neither a session nor a hardening posture. A CI job keyed on that code would previously have treated a real answer as a failure to answer. A capture with neither still exits 3, and that case is tested. Both implementations reproduce the shared expectation byte for byte across eight fixtures, five of them real corpus captures rather than synthetic. 364 tests pass, clippy clean under -D warnings, rustfmt clean, release binary reports 0.10.0. Both version bumps landed first try, which is the third release running for docs/releasing.md step 1. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Version bump, lockfile, changelog. No code changes: everything here is already on
mainand was reviewed in #24.What ships
bootintel verdictanswers for captures that never reach a U-Boot prompt:Mandatory access control, memory initialisation and kernel address randomisation, read from what the kernel itself announced. Ported from the engine and pinned against it by three kernel-stage fixtures.
Why MINOR
Either reason alone is enough:
verdictused to exit 3 whenever there was no U-Boot session; it now exits 3 only when a capture yields neither a session nor a hardening posture. The old behaviour became wrong the moment a plain boot log could produce a real answer — a CI job keyed on that code would have treated an answer as a failure to answer. A capture with neither still exits 3, and that case is tested.Verification
cargo test --workspace: 364 passed, 0 failedclippy --workspace --all-targets -- -D warningsandfmt --all --check: cleancargo build --releasethenbootintel --versionreportsbootintel 0.10.0Both version bumps landed first try — third release running for
docs/releasing.mdstep 1, which exists because thebootintel-detectorspin is not derived by cargo.After merge: dispatch
cli-releasefor0.10.0withpublish_crates, verify the draft againstSHA256SUMS, publish and mark latest, then move the tap (step 7) and sync the in-repo reference copy.🤖 Generated with Claude Code