Repository navigation
v2: preferences, Guide, localization, CLI flash, signatures, BIOS option, packaging, signing pipeline - #9
Merged
Merged
Conversation
Add recent images and checksum/folder preferences, selected-drive details, and a Guide overlay with shortcuts to both the GUI and TUI.
Add one-step 'bootable flash <slug-or-image> <target>' that reuses the download, plan, and confirmation paths of 'write'; add shell completions; map failures to documented exit codes (0 ok, 1 error, 2 usage, 3 confirmation/refusal, 4 verification) and report JSON errors on stderr for --json commands. Share one confirmation gate between write and flash.
# Conflicts: # apps/bootable-tui/src/main.rs
…ned keys Authenticate checksum manifests with OpenPGP (clear-signed and detached) or minisign signatures made by keys pinned in the repository. A verified manifest yields a new top-ranked IntegrityState; unknown keys and missing signatures degrade truthfully to checksum-only; a bad signature from a pinned key refuses the download before any transfer. Pins Ubuntu, Debian, Linux Mint, Kali, Fedora 42-45 and AlmaLinux 9/10 keys with fingerprints taken from publisher pages. See docs/signatures.md.
# Conflicts: # crates/bootable-core/src/lib.rs
… line (GUI and TUI)
Adds Locale (parsing, negotiation, system detection, plural rules), a compile-time-keyed Message catalog embedded from locales/*.lang with English fallback, Preferences.language, and locale-aware help, drive details, readiness, media status, phase, and integrity labels. English output is unchanged. Documents the API and the app strings still to extract in docs/localization.md.
…inux Adds WindowsBootFirmware (WriteOptions.windows_boot_firmware), original Apache-2.0 MBR and FAT32 boot sectors that load bootmgr, install/verify logic with byte-level tests, plan preflight, a QEMU/SeaBIOS smoke script using a stub bootmgr, and docs/legacy-bios.md. Not yet verified against Microsoft's real bootmgr.
# Conflicts: # crates/bootable-core/src/lib.rs
The view now holds the active Locale (language override, else system). A Select next to the Guide button shows Language: <name> or Language: System default (<name>), persists via preferences.language and re-renders immediately. Guide, drive details, eligibility, removable-media status, readiness button/guidance, workspace status and step titles, and progress phase names use the locale-aware core variants. The header wraps instead of clipping and long labels shrink or wrap.
…ore strings, wide-character layout)
…Windows media (CLI flag, f key, clickable control)
…tion for Windows media
…ion and BIOS option
…ips; Strings helper
…al matches several drives
…nd their status lines
…the BIOS boot sector install, then verify twice
…keep the erase phrase out of the catalog
…uctive step and always unmount the source ISO
…d confirmation through shared app strings Unified wording per docs/localization.md. Panel headings show the step title plus source.title/target.title in every language. The confirmation dialog sizes its acknowledgement and consequence rows to the wrapped text so no safety sentence is clipped. The erase phrase is untouched.
… status lines through shared app strings Windows checkboxes pick label or short caption by cell width, every option has its own on/off status line, scheme/firmware lines use the unified wording, the boot firmware control and experimental hint come from the catalog.
…ksum-only, not 'Signature verified'
…l through shared app strings
…with a state flag
…e and status helpers
…wngrade; add require_signature and download_iso_with_integrity
… download-final-message flag replaces the 'Ready ·' text check
…ounds-checks before each read; reject FSInfo as backup boot sector
…/ja render tests; erase phrase invariance test Safety sentences are pre-wrapped with the display-width wrapper so Japanese text is never stranded or clipped, header buttons and the tools row fit the longest caption in the active language, button captions degrade with an ellipsis instead of being cut.
…w panels, short-terminal setup panel no longer panics, localized empty states
… terminal event in --json-progress download and flash accept --require-signature (unsigned catalog images refused, exit 4), report the IntegrityState after fetching, and route early check_target/prepare failures through the failed event.
…utput, and the terminal-event guarantee
…es on Windows checkouts
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
bootable flash,bootable completions, stable exit codes,--windows-boot-firmware(docs/cli.md)docs/signatures.md); the signed-integrity label is kept in the download-complete status line in both UIsLkey (TUI); only core-produced text is translated so far (docs/localization.md)fkey, CLI flag (docs/legacy-bios.md); verified against a stubbootmgrin QEMU onlydocs/signing.md)Test plan
cargo clippy --workspace --all-targets,cargo test --workspace(core 201, tui 46, desktop 3, helper 2),cargo fmt --checknpm run buildinsite/flash/writeon real hardware (not exercised)Notes:
flashandcompletionsare CLI-only.writewithout--confirmnow exits 3 instead of 1.