WolfStack v25.25.2
v25.25.2: a host is no longer dropped into emergency mode by a WolfStack-ordered fstab line, and the inbox now reports why the previous boot failed
Markos's Orange Pi 5 Max stopped in systemd's emergency shell on every
reboot after an update, with only console photos to go on. WolfStack now
adds the mandatory nofail to any fstab line ordered on
wolfstack-mounts.target, the mounts-wait unit can no longer fail and
take the boot with it, a new boot-health analyzer reads the previous
boot's journal and /etc/fstab and puts the failing unit, the offending
line and the corrected line in the inbox, and the installer stops
listing USB/IP modules the kernel does not have.
Reported-by: Markos
Co-Authored-By: CodeWolf paul@wolf.uk.com
Co-Authored-By: IntelligentWolf Ltd paul@wolf.uk.com
Claude-Session: https://claude.ai/code/session_01QCyHVCw4cGaTkfj1DRfCVW
Verifying this release
Each binary is signed via cosign keyless OIDC (no key distribution — signing identity is the GitHub Actions workflow itself, anchored to the Sigstore Fulcio CA and the Rekor transparency log) and ships with a SLSA build provenance attestation.
Verify the cosign signature:
cosign verify-blob \
--bundle wolfstack-x86_64.cosign.bundle \
--certificate-identity-regexp 'https://github.com/intelligentwolf/WolfStack/\.github/workflows/release\.yml@.*' \
--certificate-oidc-issuer 'https://token.actions.githubusercontent.com' \
wolfstack-x86_64
Verify the build provenance:
gh attestation verify wolfstack-x86_64 --repo intelligentwolf/WolfStack
Verify the SHA-256 checksum:
sha256sum -c SHA256SUMS
Artifacts
wolfstack-x86_64/wolfstack-aarch64/wolfstack-armv7— static musl binaries (Linux x86_64, ARM64 / Raspberry Pi 4+, and 32-bit ARM).wolfstack-<arch>.cosign.bundle— cosign signature bundle (cert + signature + Rekor entry).SHA256SUMS— checksums for both binaries.
For per-version history see CHANGELOG.md.