bootintel-detectors 0.13.0

Client-side boot-log detectors for BootIntel — bootloader / kernel / SoC / exposure identification. Pure regex library, no I/O.
Documentation
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
484
485
486
487
488
489
490
491
492
493
494
495
496
497
498
499
500
501
502
503
504
505
506
507
508
509
510
511
512
513
514
515
516
517
518
519
520
521
522
523
524
525
526
527
528
529
530
531
532
533
534
535
536
537
538
539
540
541
542
543
544
545
546
547
548
549
550
551
552
553
554
555
556
557
//! Per-detector unit tests. Each entry in `bootintel_detectors::analyze`
//! must have at least one positive test (a log fragment that matches)
//! and at least one negative test (a fragment that doesn't).
//!
//! Test fixtures live inline as `&str` literals rather than in files
//! so the tests are self-contained and don't drift from the code.
//! Real-corpus fixtures are exercised in the workspace-level
//! `tests/corpus_smoke.rs` (uses the samples in `samples/`).

use bootintel_detectors::{analyze, Finding, SAMPLE};

fn find(log: &str, label: &str) -> Option<Finding> {
    analyze(log).into_iter().find(|f| f.label == label)
}

// ── SAMPLE (baseline: MIPS OpenWrt on TP-Link Archer C7 v5) ──────────

#[test]
fn sample_matches_expected_8_labels() {
    // SAMPLE trips 8 detectors — Telnet is the only critical detector
    // not in the fixture (it's negative-tested in
    // telnet_absent_on_clean_log). If this count changes, either SAMPLE
    // was edited or a detector regressed.
    let findings = analyze(SAMPLE);
    let labels: Vec<&str> = findings.iter().map(|f| f.label.as_str()).collect();
    assert_eq!(
        labels,
        vec![
            "Bootloader",
            "Kernel",
            "CPU / Arch",
            "Init system",
            "Device family",
            "Network",
            "Web admin",
            "Autoboot interruptable",
        ],
        "SAMPLE should trip exactly these 8 detectors (Telnet is not in SAMPLE)"
    );
}

#[test]
fn sample_bootloader_is_uboot_2020_10() {
    let f = find(SAMPLE, "Bootloader").expect("SAMPLE must trip Bootloader");
    assert_eq!(f.value, "U-Boot 2020.10");
    assert!(f.source.as_ref().unwrap().contains("U-Boot 2020.10"));
}

// ── 1. Bootloader ────────────────────────────────────────────────────

#[test]
fn bootloader_uboot() {
    let log = "U-Boot 2016.01 (Jul 25 2022 - 17:08:05 +0800)\n";
    let f = find(log, "Bootloader").unwrap();
    assert_eq!(f.value, "U-Boot 2016.01");
    assert_eq!(f.detail.unwrap(), "Jul 25 2022 - 17:08:05 +0800");
}

#[test]
fn bootloader_coreboot() {
    let log = "coreboot-4.15\nBooting…\n";
    let f = find(log, "Bootloader").unwrap();
    assert_eq!(f.value, "coreboot 4.15");
}

#[test]
fn bootloader_esp_rom() {
    let log = "rst:0x1 (POWERON_RESET),boot:0x13 (SPI_FAST_FLASH_BOOT)\n";
    let f = find(log, "Bootloader").unwrap();
    assert_eq!(f.value, "Espressif ROM bootloader");
    assert_eq!(f.detail.unwrap(), "ESP8266/ESP32");
}

#[test]
fn bootloader_none_on_gibberish() {
    let log = "some random log content with no bootloader banner\n";
    assert!(find(log, "Bootloader").is_none());
}

// ── 2. Runtime firmware ──────────────────────────────────────────────

#[test]
fn runtime_firmware_opensbi() {
    let log = "OpenSBI v1.4\nBoot HART ID              : 1\n";
    let f = find(log, "Runtime firmware").unwrap();
    assert_eq!(f.value, "OpenSBI 1.4");
    // OpenSBI is a runtime, not a bootloader. It used to be reported
    // under `Bootloader`, which disagreed with the browser tool on the
    // same input.
    assert!(find(log, "Bootloader").is_none());
}

#[test]
fn runtime_firmware_and_bootloader_coexist() {
    // A RISC-V board hands off OpenSBI → U-Boot → Linux, and reports
    // both. Folding them into one detector hid whichever lost.
    let log = "OpenSBI v1.0\nU-Boot 2021.10 (Nov 10 2022 - 13:29:36 +0800)\n";
    assert_eq!(find(log, "Runtime firmware").unwrap().value, "OpenSBI 1.0");
    assert_eq!(find(log, "Bootloader").unwrap().value, "U-Boot 2021.10");
}

#[test]
fn runtime_firmware_needs_a_dotted_version() {
    // `\d+(?:\.\d+)+` — a bare major refuses rather than reporting
    // "OpenSBI 1".
    assert!(find("OpenSBI v1\n", "Runtime firmware").is_none());
}

// ── 3. ROM identifier ────────────────────────────────────────────────

#[test]
fn rom_identifier_esp_rom() {
    let log = "ESP-ROM:esp32s3-20210327\nBuild:Mar 27 2021\n";
    let f = find(log, "ROM identifier").unwrap();
    assert_eq!(f.value, "Espressif ROM esp32s3-20210327");
}

#[test]
fn rom_identifier_absent_on_non_esp_log() {
    assert!(find("U-Boot 2020.10 (Sep 17 2023)\n", "ROM identifier").is_none());
}

// ── 4. Firmware SDK ──────────────────────────────────────────────────

#[test]
fn firmware_sdk_esp_idf() {
    let log = "I (27) boot: ESP-IDF v5.1.2 2nd stage bootloader\n";
    let f = find(log, "Firmware SDK").unwrap();
    assert_eq!(f.value, "ESP-IDF v5.1.2");
}

#[test]
fn firmware_sdk_absent_without_the_bootloader_banner() {
    // The version has to come off the 2nd-stage bootloader line; a
    // passing mention of ESP-IDF is not a version claim.
    assert!(find("built with ESP-IDF v5.1.2\n", "Firmware SDK").is_none());
}

// ── 5. Kernel ────────────────────────────────────────────────────────

#[test]
fn kernel_linux() {
    let log = "[    0.000000] Linux version 5.15.137 (builder@host) (gcc-11.2.0) #0 SMP Tue Nov 14 19:23:42 2023\n";
    let f = find(log, "Kernel").unwrap();
    assert_eq!(f.value, "Linux 5.15.137");
    assert!(f.detail.unwrap().starts_with("gcc-11.2.0"));
}

#[test]
fn kernel_linux_without_build_metadata() {
    // Plenty of vendor kernels print the version and stop. The build
    // parentheses are optional, and `detail` is then absent.
    let log = "Linux version 3.0.15-ts-armv7l\n";
    let f = find(log, "Kernel").unwrap();
    assert_eq!(f.value, "Linux 3.0.15-ts-armv7l");
    assert_eq!(f.detail, None);
}

#[test]
fn kernel_freertos() {
    let log = "FreeRTOS Kernel V10.4.3 starting on core 0\n";
    let f = find(log, "Kernel").unwrap();
    assert_eq!(f.value, "FreeRTOS 10.4.3");
}

#[test]
fn kernel_zephyr() {
    let log = "*** Booting Zephyr OS build v3.5.0-2547-g1234567 ***\n";
    let f = find(log, "Kernel").unwrap();
    assert_eq!(f.value, "Zephyr v3.5.0-2547-g1234567");
}

// ── 6. CPU / Arch ────────────────────────────────────────────────────

#[test]
fn cpu_mips() {
    let log = "CPU0 revision is: 00019374 (MIPS 74Kc)\n";
    let f = find(log, "CPU / Arch").unwrap();
    assert_eq!(f.value, "MIPS 74Kc");
}

#[test]
fn cpu_arm64() {
    let log = "Booting Linux on physical CPU 0x0000000000 aarch64\n";
    let f = find(log, "CPU / Arch").unwrap();
    assert_eq!(f.value, "ARM64 (aarch64)");
}

#[test]
fn cpu_riscv_from_hart() {
    let log = "hart 1: running\n";
    let f = find(log, "CPU / Arch").unwrap();
    assert_eq!(f.value, "RISC-V");
}

#[test]
fn cpu_xtensa_needs_the_arch_name() {
    // `esp32` alone is a device family, not a CPU — it is reported by
    // `Device family`. Claiming an arch from it disagreed with the
    // browser tool.
    assert_eq!(
        find("xtensa: booting\n", "CPU / Arch").unwrap().value,
        "Xtensa (ESP)"
    );
    assert!(find("esp_image: segment 0\n", "CPU / Arch").is_none());
}

// ── 7. Userland ──────────────────────────────────────────────────────

#[test]
fn userland_busybox() {
    let log = "BusyBox v1.35.0 (2022-03-01) built-in shell (ash)\n";
    let f = find(log, "Userland").unwrap();
    assert_eq!(f.value, "BusyBox 1.35.0");
}

#[test]
fn userland_busybox_is_not_an_init_claim() {
    // A BusyBox banner says what the userland is, not what PID 1 is.
    // This crate used to report "BusyBox init" for it, which the
    // browser tool never did.
    let log = "BusyBox v1.35.0 (2022-03-01) built-in shell (ash)\n";
    assert!(find(log, "Init system").is_none());
}

#[test]
fn userland_absent_without_a_version() {
    assert!(find("starting busybox applets\n", "Userland").is_none());
}

// ── 8. Flash layout ──────────────────────────────────────────────────

const MTD_TABLE: &str = concat!(
    "0x000000000000-0x000000020000 : \"u-boot\"\n",
    "0x000000020000-0x000000030000 : \"u-boot-env\"\n",
    "0x000000030000-0x000000200000 : \"kernel\"\n",
);

#[test]
fn flash_layout_lists_partitions_with_sizes() {
    let f = find(MTD_TABLE, "Flash layout").unwrap();
    assert_eq!(f.value, "3 partitions");
    assert_eq!(
        f.detail.unwrap(),
        "u-boot (128K), u-boot-env (64K), kernel (1.8M)"
    );
}

#[test]
fn flash_layout_is_an_aggregate_so_it_has_no_single_line_evidence() {
    // The value counts partitions across many lines, so no single line
    // reproduces it and the evidence fields stay empty. Pointing at one
    // arbitrary MTD line would be a lie about where the value came from.
    let f = find(MTD_TABLE, "Flash layout").unwrap();
    assert_eq!(f.source, None);
    assert_eq!(f.line_number, None);
}

#[test]
fn flash_layout_deduplicates_a_repeated_table() {
    // A reset loop (or two flash devices registering) prints the table
    // twice. The same offsets must be listed once.
    let log = format!("{MTD_TABLE}reset\n{MTD_TABLE}");
    let f = find(&log, "Flash layout").unwrap();
    assert_eq!(f.value, "3 partitions");
    let names: Vec<&str> = f.detail.as_deref().unwrap().split(", ").collect();
    let unique: std::collections::HashSet<&&str> = names.iter().collect();
    assert_eq!(
        unique.len(),
        names.len(),
        "no partition may be listed twice"
    );
}

#[test]
fn flash_layout_whole_megabytes_drop_the_decimal() {
    let log = "0x000000000000-0x000000100000 : \"one\"\n0x000000100000-0x000000280000 : \"onepointfive\"\n";
    let f = find(log, "Flash layout").unwrap();
    assert_eq!(f.detail.unwrap(), "one (1M), onepointfive (1.5M)");
}

#[test]
fn flash_layout_singular_for_one_partition() {
    let log = "0x000000000000-0x000000020000 : \"u-boot\"\n";
    assert_eq!(find(log, "Flash layout").unwrap().value, "1 partition");
}

#[test]
fn flash_layout_absent_without_a_partition_map() {
    assert!(find("mtd: device 0 (boot)\n", "Flash layout").is_none());
}

// ── 9. Init system ───────────────────────────────────────────────────

#[test]
fn init_procd() {
    let log = "[    3.789012] procd: - init -\n";
    let f = find(log, "Init system").unwrap();
    assert_eq!(f.value, "procd");
    assert_eq!(f.detail.unwrap(), "OpenWrt-family");
}

#[test]
fn init_systemd() {
    let log = "systemd[1]: Starting some.service\n";
    let f = find(log, "Init system").unwrap();
    assert_eq!(f.value, "systemd");
}

// ── 10. Device family ─────────────────────────────────────────────────

#[test]
fn family_openwrt() {
    let log = "OpenWrt 22.03.5, r20134-5f15225c1e (2023-01-01)\n";
    let f = find(log, "Device family").unwrap();
    assert_eq!(f.value, "OpenWrt");
}

#[test]
fn family_raspberry_pi() {
    let log = "bcm2711 Raspberry Pi 4 Model B Rev 1.4\n";
    let f = find(log, "Device family").unwrap();
    assert_eq!(f.value, "Raspberry Pi family");
}

#[test]
fn family_qualcomm() {
    let log = "IPQ8074 SoC init\n";
    let f = find(log, "Device family").unwrap();
    assert_eq!(f.value, "Qualcomm IPQ");
}

// ── 11. Network ───────────────────────────────────────────────────────

#[test]
fn network_dhcp() {
    let log = "[    5.012345] DHCP client bound to address 192.168.1.42\n";
    let f = find(log, "Network").unwrap();
    assert_eq!(f.value, "DHCP client active");
    assert_eq!(f.detail.unwrap(), "Lease: 192.168.1.42");
}

#[test]
fn network_dnsmasq() {
    let log = "[    4.456789] dnsmasq[1236]: started, version 2.86 cachesize 150\n";
    let f = find(log, "Network").unwrap();
    assert_eq!(f.value, "dnsmasq 2.86 active");
}

// ── 12. Web admin ─────────────────────────────────────────────────────

#[test]
fn web_uhttpd() {
    let log = "[    4.345678] uhttpd[1235]: Listening on 0.0.0.0:80 0.0.0.0:443\n";
    let f = find(log, "Web admin").unwrap();
    assert_eq!(f.value, "uhttpd active");
    assert!(f.detail.unwrap().starts_with("Listen: 0.0.0.0:80"));
}

#[test]
fn web_nginx() {
    let log = "Server: nginx/1.20.1\n";
    let f = find(log, "Web admin").unwrap();
    assert_eq!(f.value, "nginx 1.20.1");
}

// ── 13. Telnet exposure ───────────────────────────────────────────────

#[test]
fn telnet_started() {
    let log = "telnetd[123]: listening on port 23\n";
    let f = find(log, "Telnet exposure").unwrap();
    assert_eq!(f.value, "Telnet service started");
    assert_eq!(f.detail.unwrap(), "Clear-text, review immediately");
}

#[test]
fn telnet_absent_on_clean_log() {
    let log = "just some kernel messages\nDHCP client bound to address 10.0.0.1\n";
    assert!(find(log, "Telnet exposure").is_none());
}

// ── 14. Autoboot interruptable ────────────────────────────────────────

#[test]
fn autoboot_3_second_countdown() {
    let log = "Hit any key to stop autoboot:  3\n";
    let f = find(log, "Autoboot interruptable").unwrap();
    assert_eq!(f.value, "Yes");
    assert!(f.source.unwrap().contains("Hit any key"));
}

#[test]
fn autoboot_0_second_not_flagged() {
    // Countdown reached zero — not interruptable in the exposure sense.
    let log = "Hit any key to stop autoboot:  0\n";
    assert!(find(log, "Autoboot interruptable").is_none());
}

// ── Labels stability check ──────────────────────────────────────────

#[test]
fn detector_labels_stable() {
    // Guards against renames or reorderings that would break the
    // TS/Rust sync-check script.
    let labels = bootintel_detectors::detector_labels();
    assert_eq!(
        labels,
        vec![
            "Bootloader",
            "Runtime firmware",
            "ROM identifier",
            "Firmware SDK",
            "Kernel",
            "CPU / Arch",
            "Userland",
            "Flash layout",
            "Init system",
            "Device family",
            "Network",
            "Web admin",
            "Telnet exposure",
            "Autoboot interruptable",
        ],
        "order and labels must match the browser detector library exactly"
    );
}

// ── Line-prefix normalization (regression) ───────────────────────────
//
// The line-anchored detectors (`(?m)^U-Boot`, `(?m)^coreboot-`,
// `(?m)^GRUB`, `(?m)^procd:`) used to be defeated by anything at all in
// front of the anchor. A plain `U-Boot 2020.10` line was detected; the
// same line behind a terminal timestamp, an ISO-8601 timestamp, or an
// ANSI colour escape produced NO findings and exit 0, while the Kernel,
// CPU and Autoboot detectors — which are not anchored — handled all
// four.
//
// The ISO-8601 case is self-inflicted: `bootintel analyze
// --log-timestamps` prefixes every line with exactly that, so the
// tool's own capture mode broke its own `scan`.
//
// One fixture per prefix shape, all four asserted to produce the same
// finding as the bare line.

/// The bare line every prefixed variant below must still match.
const UBOOT_LINE: &str = "U-Boot 2020.10 (Sep 17 2023 - 11:38:21 +0000)";

fn uboot_value(log: &str) -> Option<String> {
    find(log, "Bootloader").map(|f| f.value)
}

#[test]
fn bootloader_matches_bare_line() {
    assert_eq!(uboot_value(UBOOT_LINE).as_deref(), Some("U-Boot 2020.10"));
}

#[test]
fn bootloader_survives_bracketed_clock_prefix() {
    let log = format!("[12:34:56.789] {UBOOT_LINE}");
    assert_eq!(uboot_value(&log).as_deref(), Some("U-Boot 2020.10"));
}

#[test]
fn bootloader_survives_iso8601_prefix() {
    // Exactly what `bootintel analyze --log-timestamps` writes.
    let log = format!("[2026-09-23T10:00:00.000Z] {UBOOT_LINE}");
    assert_eq!(uboot_value(&log).as_deref(), Some("U-Boot 2020.10"));
}

#[test]
fn bootloader_survives_ansi_colour_prefix() {
    let log = format!("\x1b[32m{UBOOT_LINE}\x1b[0m");
    assert_eq!(uboot_value(&log).as_deref(), Some("U-Boot 2020.10"));
}

#[test]
fn bootloader_survives_kernel_printk_prefix() {
    let log = format!("[    0.000000] {UBOOT_LINE}");
    assert_eq!(uboot_value(&log).as_deref(), Some("U-Boot 2020.10"));
}

#[test]
fn bootloader_survives_stacked_prefixes() {
    // `--log-timestamps` over a Linux console stacks two prefixes.
    let log = format!("[2026-09-23T10:00:00.000Z] [    0.000000] {UBOOT_LINE}");
    assert_eq!(uboot_value(&log).as_deref(), Some("U-Boot 2020.10"));
}

#[test]
fn bootloader_survives_ansi_and_timestamp_together() {
    let log = format!("\x1b[1;33m[12:34:56] \x1b[0m{UBOOT_LINE}");
    assert_eq!(uboot_value(&log).as_deref(), Some("U-Boot 2020.10"));
}

#[test]
fn evidence_keeps_the_original_prefixed_line() {
    // Normalization is for matching only. What we show back to the
    // user must be what their capture actually contained, otherwise
    // they cannot find it again in the log.
    let log = format!("noise\n[2026-09-23T10:00:00.000Z] {UBOOT_LINE}\nmore noise");
    let f = find(&log, "Bootloader").expect("Bootloader should fire");
    assert_eq!(
        f.source.as_deref(),
        Some(format!("[2026-09-23T10:00:00.000Z] {UBOOT_LINE}").as_str())
    );
    assert_eq!(f.line_number, Some(2), "line number must be 1-based");
}

#[test]
fn coreboot_and_grub_anchors_also_normalized() {
    let coreboot = find("[12:34:56] coreboot-4.19 Tue Jan 1", "Bootloader");
    assert_eq!(coreboot.map(|f| f.value).as_deref(), Some("coreboot 4.19"));

    let grub = find("[2026-09-23T10:00:00.000Z] GRUB version 2.06", "Bootloader");
    assert_eq!(grub.map(|f| f.value).as_deref(), Some("GRUB 2.06"));
}

#[test]
fn init_system_anchor_also_normalized() {
    // `(?m)^procd:` is anchored too.
    let f = find("[    3.123456] procd: - early -", "Init system");
    assert!(
        f.is_some(),
        "procd should be detected behind a printk prefix"
    );
}

#[test]
fn unanchored_detectors_are_unaffected_by_normalization() {
    // Regression guard the other way: the detectors that already
    // handled prefixes must keep working, and must not start matching
    // things they shouldn't because of the stripping.
    let log = "[    0.000000] Linux version 5.15.137 (builder@buildhost) (gcc 11.2.0) #0 SMP";
    assert!(find(log, "Kernel").is_some());
}

#[test]
fn a_bracketed_non_timestamp_is_not_stripped() {
    // Only timestamp-shaped brackets come off. A line that genuinely
    // begins with some other bracketed tag keeps it, so evidence and
    // matching stay honest.
    let log = "[vendor-tag] U-Boot 2020.10 (Sep 17 2023 - 11:38:21 +0000)";
    assert!(
        uboot_value(log).is_none(),
        "a non-timestamp bracket must not be stripped by the timestamp rule"
    );
}

#[test]
fn bare_cr_line_endings_are_split() {
    // Some bootloaders emit CR-only line endings. `str::lines()` does
    // not split on those, which would leave the whole capture as one
    // line and defeat every anchored detector.
    let log = format!("boot start\r{UBOOT_LINE}\rdone");
    assert_eq!(uboot_value(&log).as_deref(), Some("U-Boot 2020.10"));
}