Skip to content

v2: preferences, Guide, localization, CLI flash, signatures, BIOS option, packaging, signing pipeline - #9

Merged
debpalash merged 63 commits into
mainfrom
feat/v2-growth
Oct 5, 2026
Merged

debpalash merged 63 commits into
mainfrom
feat/v2-growth

Conversation

@debpalash

Copy link
Copy Markdown
Owner

Summary

  • GUI + TUI: remembered preferences and recent images, selected-drive details, shared Guide/shortcuts
  • CLI: bootable flash, bootable completions, stable exit codes, --windows-boot-firmware (docs/cli.md)
  • Core: OpenPGP/minisign verification of publisher checksum manifests against pinned keys (docs/signatures.md); the signed-integrity label is kept in the download-complete status line in both UIs
  • Localization: shared message catalog (8 languages, machine-quality drafts needing native review), saved language setting, header language select (GUI) and L key (TUI); only core-produced text is translated so far (docs/localization.md)
  • Experimental legacy BIOS (CSM) boot for MBR Windows media on Linux: original boot sectors, GUI select, TUI f key, CLI flag (docs/legacy-bios.md); verified against a stub bootmgr in QEMU only
  • Packaging: winget/Scoop/Homebrew/AUR/Nix/Flatpak templates + renderer + workflow (artifact only, nothing published)
  • Release: signing-ready pipeline for macOS/Windows/cosign, gated on secrets, unsigned until configured (docs/signing.md)
  • Site: comparison, Rufus-alternative and roadmap pages; downloads and install script now point at v0.1.4

Test plan

  • cargo clippy --workspace --all-targets, cargo test --workspace (core 201, tui 46, desktop 3, helper 2), cargo fmt --check
  • npm run build in site/
  • CI green on this branch
  • Rehearse the signing steps in a fork before a real release (never run)
  • Human read of competitor claims on the new site pages and native review of translations before release
  • Legacy BIOS with a real Windows installer on real hardware (not exercised)
  • flash/write on real hardware (not exercised)

Notes: flash and completions are CLI-only. write without --confirm now exits 3 instead of 1.

Add recent images and checksum/folder preferences, selected-drive details,
and a Guide overlay with shortcuts to both the GUI and TUI.
Add one-step 'bootable flash <slug-or-image> <target>' that reuses the
download, plan, and confirmation paths of 'write'; add shell completions;
map failures to documented exit codes (0 ok, 1 error, 2 usage, 3
confirmation/refusal, 4 verification) and report JSON errors on stderr
for --json commands. Share one confirmation gate between write and flash.
# Conflicts:
#	apps/bootable-tui/src/main.rs
…ned keys

Authenticate checksum manifests with OpenPGP (clear-signed and detached) or
minisign signatures made by keys pinned in the repository. A verified manifest
yields a new top-ranked IntegrityState; unknown keys and missing signatures
degrade truthfully to checksum-only; a bad signature from a pinned key refuses
the download before any transfer.

Pins Ubuntu, Debian, Linux Mint, Kali, Fedora 42-45 and AlmaLinux 9/10 keys
with fingerprints taken from publisher pages. See docs/signatures.md.
# Conflicts:
#	crates/bootable-core/src/lib.rs
Adds Locale (parsing, negotiation, system detection, plural rules), a
compile-time-keyed Message catalog embedded from locales/*.lang with
English fallback, Preferences.language, and locale-aware help, drive
details, readiness, media status, phase, and integrity labels. English
output is unchanged. Documents the API and the app strings still to
extract in docs/localization.md.
…inux

Adds WindowsBootFirmware (WriteOptions.windows_boot_firmware), original
Apache-2.0 MBR and FAT32 boot sectors that load bootmgr, install/verify
logic with byte-level tests, plan preflight, a QEMU/SeaBIOS smoke script
using a stub bootmgr, and docs/legacy-bios.md. Not yet verified against
Microsoft's real bootmgr.
# Conflicts:
#	crates/bootable-core/src/lib.rs
The view now holds the active Locale (language override, else system).
A Select next to the Guide button shows Language: <name> or
Language: System default (<name>), persists via preferences.language and
re-renders immediately. Guide, drive details, eligibility, removable-media
status, readiness button/guidance, workspace status and step titles, and
progress phase names use the locale-aware core variants. The header wraps
instead of clipping and long labels shrink or wrap.
…Windows media (CLI flag, f key, clickable control)
…the BIOS boot sector install, then verify twice
…uctive step and always unmount the source ISO
…d confirmation through shared app strings

Unified wording per docs/localization.md. Panel headings show the step title
plus source.title/target.title in every language. The confirmation dialog
sizes its acknowledgement and consequence rows to the wrapped text so no
safety sentence is clipped. The erase phrase is untouched.
… status lines through shared app strings

Windows checkboxes pick label or short caption by cell width, every option
has its own on/off status line, scheme/firmware lines use the unified
wording, the boot firmware control and experimental hint come from the
catalog.
…wngrade; add require_signature and download_iso_with_integrity
… download-final-message flag replaces the 'Ready ·' text check
…ounds-checks before each read; reject FSInfo as backup boot sector
…/ja render tests; erase phrase invariance test

Safety sentences are pre-wrapped with the display-width wrapper so Japanese
text is never stranded or clipped, header buttons and the tools row fit the
longest caption in the active language, button captions degrade with an
ellipsis instead of being cut.
…w panels, short-terminal setup panel no longer panics, localized empty states
… terminal event in --json-progress

download and flash accept --require-signature (unsigned catalog images refused, exit 4), report the IntegrityState after fetching, and route early check_target/prepare failures through the failed event.
@debpalash
debpalash merged commit f483788 into main Oct 5, 2026
12 checks passed
@debpalash
debpalash deleted the feat/v2-growth branch October 5, 2026 02:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant