Skip to content

v0.7.2 — with-device 0.2.2: the claim becomes assertable

Latest

Choose a tag to compare

@avrabe avrabe released this 05 Sep 23:02
· 40 commits to main since this release
v0.7.2
326ea6b

with-device 0.2.2 — the claim becomes assertable

with-device now exports WITH_DEVICE_CLAIM into the wrapped command, and adds
--require-claim, so a script can assert its own precondition instead of trusting that whoever
invoked it remembered:

$ with-device --require-claim pixhawk-6xrt
with-device: NOT UNDER A CLAIM for pixhawk-6xrt.
This process is not running inside `with-device`, so nothing stops another agent from driving
the same hardware at the same time — and a collision on a tty is SILENT: both readers get a
partial stream and neither errors.
Re-run as: with-device pixhawk-6xrt --purpose '<why>' -- <your command>

Nesting unions rather than overwrites, so with-device a -- with-device b -- cmd leaves the
command able to assert either.

Why it exists: jess broke its own always-claim rule five times in one session — every one of
them mid-debugging, which is exactly when a remembered rule fails. A discipline that only holds
while you are calm is not a control.

Also in this release, from 0.2.1

Nothing else changed in the interface. 0.2.1's fix (a wrapped command containing -h, -V,
--version, --status or --self-test hijacked the invocation and the tool exited 0 without
running anything
) is carried forward and covered by tests.

Testing

40 tests — 20 unit over the pure core, 20 behavioural spawning the real binary — at 96.8%
line coverage, gated at 90 in CI on both ubuntu and macos. The two-platform matrix is not
decoration: an assertion once passed on macOS and failed on Linux because GNU echo interprets
--version while BSD echo prints it, and a second flock on one fd succeeds on BSD but blocks
on Linux.

--self-test remains the field check for machines with no source tree. It is not the suite,
and 0.2.0 is the standing reminder why: it reported 5/5 PASS on a binary that returned exit 0 for
commands it never ran.

Pin

release:pulseengine/jess@v0.7.2!with-device-0.2.2-<triple>.tar.gz!with-device

Assets are cosign-signed with SLSA build provenance and a CycloneDX SBOM; the release workflow
ends by re-downloading the published release and verifying it as a consumer would. Every target
is built and tested on a host that can execute it — including aarch64-unknown-linux-gnu on a
native arm64 runner, so nothing ships unexecuted.

Falsification statement

If this release is what it claims: the cosign signature over SHA256SUMS.txt verifies against
this workflow's identity; every asset matches that manifest; each archive's SLSA provenance
verifies; --require-claim exits 2 outside a claim and 0 inside one for the named device,
and still exits 2 when the claim is on a different device; a wrapped command containing -h or
--version still runs; and a kill -9'd holder's device is immediately claimable. All are
asserted by the release's own verify job and by cargo test.