Repository navigation
Release 0.5.0: detector parity, and terminal login - #9
Merged
Merged
Conversation
Two things, and one of them changes output for existing consumers. Detector parity. This crate shipped 9 of the browser library's 14 detectors and folded two others into the wrong label, so the same log produced different JSON depending on which implementation read it. The parity test that now compares all 31 corpus logs also caught four further divergences nobody had asked about. The policy at the top of CHANGELOG.md calls an output-schema change MAJOR, and the crate is pre-1.0, so that is 0.5.0: anything parsing .findings[] by label should look before upgrading. The notable one is OpenSBI, which moves from Bootloader to Runtime firmware and previously lost to U-Boot in the precedence chain, so on a RISC-V log the version never reached output at all. `bootintel login`. Replaces pasting BOOTINTEL_API_KEY by hand, which the README had to teach `read -s` to do safely. The real reason it exists is that the server gates x-api-key at Pro, because "API access" there means CI and scripting, and applying that to interactive terminal use would have put the applicability lookup, the one path usable on a client device under an NDA, out of reach of the entry paid tier. The bic_ token resolves ahead of that gate server-side, so programmatic access stays Pro while a terminal login starts at Researcher. Verified against the running server rather than only in tests: the flow printed the link and code, polled, was approved from a browser session, and collected a bic_ token, which then returned 67 applicability findings with log_received false. Probe accounts and all test authorizations were removed from the database afterwards. Two things that live run changed. It survived a connection reset mid-poll, proving the retry, but printed a warning that was the only thing about a successful login that looked wrong; transient retries are now quiet, bounded at 20, and visible under -v. And clippy rejected a runtime assertion on a constant, correctly, so the poll-interval floor is a const assertion and the test exercises the actual computation instead of a tautology. Verified: 299 tests pass, clippy clean under -D warnings, rustfmt clean, cargo deny reports advisories, bans, licenses and sources all ok. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Two things, one of which changes output for existing consumers.
bootintel login. Browser-approved terminal sign-in, RFC 8628 shape. Replaces pastingBOOTINTEL_API_KEYby hand, which the README had to teachread -sto do safely.The real reason it exists: the server gates
x-api-keyat Pro, because "API access" there means CI and scripting. Applying that to interactive terminal use would have put the applicability lookup, the only path usable on a client device under an NDA, out of reach of the entry paid tier. Thebic_token resolves ahead of that gate server-side, so programmatic access stays Pro while a terminal login starts at Researcher.0.5.0, not 0.4.3. The detector parity work already on
mainchanges output labels, which the policy at the top of CHANGELOG.md calls MAJOR; pre-1.0 that moves the minor. Anything parsing.findings[]by label should look before upgrading. Notably OpenSBI moves fromBootloadertoRuntime firmware, and previously lost to U-Boot in the precedence chain, so on a RISC-V log its version never reached output at all.Verified against the running server, not just in tests. The flow printed the link and code, polled, was approved from a browser session, and collected a
bic_token, which then returned 67 applicability findings withlog_received: false. Probe accounts and all test authorizations were removed from the database afterwards.Two things that live run changed:
-v.constassertion and the test exercises the real computation rather than a tautology.299 tests pass, clippy clean under
-D warnings, rustfmt clean,cargo deny checkall ok.