Skip to content

Release 0.10.0: the kernel's own hardening report - #25

Merged
Zenofex merged 1 commit into
mainfrom
release/0.10.0
Sep 28, 2026
Merged

Zenofex merged 1 commit into
mainfrom
release/0.10.0

Conversation

@Zenofex

@Zenofex Zenofex commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Version bump, lockfile, changelog. No code changes: everything here is already on main and was reviewed in #24.

What ships

bootintel verdict answers for captures that never reach a U-Boot prompt:

no U-Boot session in boot.log
  kernel hardening
    memory init  stack:off  heap alloc:off  heap free:off
    KASLR        disabled (lack of seed)
    LSM          capability, integrity  (none provide mandatory access control)

Mandatory access control, memory initialisation and kernel address randomisation, read from what the kernel itself announced. Ported from the engine and pinned against it by three kernel-stage fixtures.

Why MINOR

Either reason alone is enough:

  • New behaviour.
  • Changed contract. verdict used to exit 3 whenever there was no U-Boot session; it now exits 3 only when a capture yields neither a session nor a hardening posture. The old behaviour became wrong the moment a plain boot log could produce a real answer — a CI job keyed on that code would have treated an answer as a failure to answer. A capture with neither still exits 3, and that case is tested.

Verification

  • cargo test --workspace: 364 passed, 0 failed
  • clippy --workspace --all-targets -- -D warnings and fmt --all --check: clean
  • cargo build --release then bootintel --version reports bootintel 0.10.0
  • Both implementations reproduce the shared expectation byte for byte across eight fixtures, five of them real captures

Both version bumps landed first try — third release running for docs/releasing.md step 1, which exists because the bootintel-detectors pin is not derived by cargo.

After merge: dispatch cli-release for 0.10.0 with publish_crates, verify the draft against SHA256SUMS, publish and mark latest, then move the tap (step 7) and sync the in-repo reference copy.

🤖 Generated with Claude Code

Ships #24. `bootintel verdict` now answers for captures that never reach a
U-Boot prompt: a plain boot log states which protections the kernel enforces,
and reporting "nothing was assessed" about one of those was false.

MINOR for two reasons, either sufficient. New behaviour, and a changed contract:
`verdict` used to exit 3 whenever there was no U-Boot session and now exits 3
only when the capture yields neither a session nor a hardening posture. A CI job
keyed on that code would previously have treated a real answer as a failure to
answer. A capture with neither still exits 3, and that case is tested.

Both implementations reproduce the shared expectation byte for byte across eight
fixtures, five of them real corpus captures rather than synthetic.

364 tests pass, clippy clean under -D warnings, rustfmt clean, release binary
reports 0.10.0. Both version bumps landed first try, which is the third release
running for docs/releasing.md step 1.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Zenofex
Zenofex merged commit cc7aab3 into main Sep 28, 2026
11 checks passed
@Zenofex
Zenofex deleted the release/0.10.0 branch September 28, 2026 21:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant