Skip to content

Release 0.5.0: detector parity, and terminal login - #9

Merged
Zenofex merged 1 commit into
mainfrom
feat/terminal-login
Sep 26, 2026
Merged

Zenofex merged 1 commit into
mainfrom
feat/terminal-login

Conversation

@Zenofex

@Zenofex Zenofex commented Sep 26, 2026

Copy link
Copy Markdown
Contributor

Two things, one of which changes output for existing consumers.

bootintel login. Browser-approved terminal sign-in, RFC 8628 shape. Replaces pasting BOOTINTEL_API_KEY by hand, which the README had to teach read -s to do safely.

The real reason it exists: the server gates x-api-key at Pro, because "API access" there means CI and scripting. Applying that to interactive terminal use would have put the applicability lookup, the only path usable on a client device under an NDA, out of reach of the entry paid tier. The bic_ token resolves ahead of that gate server-side, so programmatic access stays Pro while a terminal login starts at Researcher.

0.5.0, not 0.4.3. The detector parity work already on main changes output labels, which the policy at the top of CHANGELOG.md calls MAJOR; pre-1.0 that moves the minor. Anything parsing .findings[] by label should look before upgrading. Notably OpenSBI moves from Bootloader to Runtime firmware, and previously lost to U-Boot in the precedence chain, so on a RISC-V log its version never reached output at all.

Verified against the running server, not just in tests. The flow printed the link and code, polled, was approved from a browser session, and collected a bic_ token, which then returned 67 applicability findings with log_received: false. Probe accounts and all test authorizations were removed from the database afterwards.

Two things that live run changed:

  • It survived a connection reset mid-poll, proving the retry worked, but printed a warning that was the only thing about a successful login that looked wrong. Transient retries are now quiet, bounded at 20, and visible under -v.
  • clippy correctly rejected a runtime assertion on a constant, so the poll-interval floor is a const assertion and the test exercises the real computation rather than a tautology.

299 tests pass, clippy clean under -D warnings, rustfmt clean, cargo deny check all ok.

Two things, and one of them changes output for existing consumers.

Detector parity. This crate shipped 9 of the browser library's 14 detectors
and folded two others into the wrong label, so the same log produced
different JSON depending on which implementation read it. The parity test
that now compares all 31 corpus logs also caught four further divergences
nobody had asked about. The policy at the top of CHANGELOG.md calls an
output-schema change MAJOR, and the crate is pre-1.0, so that is 0.5.0:
anything parsing .findings[] by label should look before upgrading. The
notable one is OpenSBI, which moves from Bootloader to Runtime firmware and
previously lost to U-Boot in the precedence chain, so on a RISC-V log the
version never reached output at all.

`bootintel login`. Replaces pasting BOOTINTEL_API_KEY by hand, which the
README had to teach `read -s` to do safely. The real reason it exists is that
the server gates x-api-key at Pro, because "API access" there means CI and
scripting, and applying that to interactive terminal use would have put the
applicability lookup, the one path usable on a client device under an NDA,
out of reach of the entry paid tier. The bic_ token resolves ahead of that
gate server-side, so programmatic access stays Pro while a terminal login
starts at Researcher.

Verified against the running server rather than only in tests: the flow
printed the link and code, polled, was approved from a browser session, and
collected a bic_ token, which then returned 67 applicability findings with
log_received false. Probe accounts and all test authorizations were removed
from the database afterwards.

Two things that live run changed. It survived a connection reset mid-poll,
proving the retry, but printed a warning that was the only thing about a
successful login that looked wrong; transient retries are now quiet, bounded
at 20, and visible under -v. And clippy rejected a runtime assertion on a
constant, correctly, so the poll-interval floor is a const assertion and the
test exercises the actual computation instead of a tautology.

Verified: 299 tests pass, clippy clean under -D warnings, rustfmt clean,
cargo deny reports advisories, bans, licenses and sources all ok.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
@Zenofex
Zenofex merged commit 05ee328 into main Sep 26, 2026
11 checks passed
@Zenofex
Zenofex deleted the feat/terminal-login branch September 26, 2026 22:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant