Expand description
Client-side boot-log detectors for BootIntel.
Mirrors the 14-detector browser detector library at bootintel.com/tools/fingerprint. Kept pure (no I/O, no async, no serde) so this crate can be reused in other contexts — a future WASM build for the browser tool, a plugin for third-party firmware-analysis tooling, etc.
Sync discipline: each detector below is a one-for-one port of a browser detector entry. When adding, removing, or renaming a detector, keep both sources aligned.
Regex flavor: only features supported by both JavaScript regex
and Rust regex are used (no lookaround, no backreferences). If
a future detector needs lookaround, pull in fancy-regex for
just that detector — do not switch the whole library.
Modules§
- boot_
chain - U-Boot interactive session: environment, and the boot-chain verdict.
Structs§
- Finding
- A single detector’s output.
Constants§
- CRITICAL_
LABELS - Labels that mark a finding as a critical exposure — surfaced
in scan text output, batch rollups, HTML/SARIF/JUnit rendering,
--gate-critical, and the TUI’s critical highlight. Kept as one list here so scan + batch + output + tui + analyze all agree on what “critical” means without drifting. - SAMPLE
- A canned MIPS OpenWrt boot log used by tests and by
--sampleon the CLI. Byte-for-byte identical to the SAMPLE constant in the browser detector library so browser + CLI output can be diffed against each other.
Functions§
- analyze
- Analyze a boot log against every detector; return findings in detector-registration order. Detectors that don’t match are silently dropped.
- detector_
labels - Return the labels of every registered detector, in order. Used by
the sync-check script +
bootintel version.