• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

wrouesnel / netboot / 37203770096
45%
main: 45%

Build:
Build:
LAST BUILD BRANCH: wrouesnel/secure-boot-features
DEFAULT BRANCH: main
Ran 05 Oct 2026 04:08AM UTC
Jobs 1
Files 50
Run time 1min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

30 Sep 2026 06:36AM UTC coverage: 41.902% (+7.3%) from 34.596%
37203770096

push

github

wrouesnel
pixiecore: Secure Boot signing, HTTP proxy, DNS forwarder, API headers

Secure Boot:
- Sign the UEFI iPXE binaries at startup, and kernels as they're
  served, for UEFI Secure Boot (--secureboot-key/--secureboot-cert, or
  a TPM-held RSA key with --tpm-enabled --secureboot-tpm). Existing
  signatures are kept. Kernel URLs carry an HMAC token so only boot
  spec kernels are signed. Adds the uefisign package, using go-uefi.
- Add "pixiecore secureboot-cert" to create the TPM key and a
  self-signed certificate or CSR.
- Separate --api-client-tpm from --tpm-enabled, so the TPM can hold the
  Secure Boot key without being used for the API client certificate.

API mode:
- Send X-Pixiecore-Http-Port and X-Pixiecore-Https-Port for the ports
  Pixiecore listens on.
- Replace --api-proxy with --http-proxy/--http-proxy-port (default
  3128): a forward HTTP proxy that tunnels CONNECT without intercepting
  TLS, sending X-Pixiecore-Proxy-Port to the API.
- Add --dns: a DNS forwarder on --dns-port (default 53) with
  --dns-upstream servers (plain or DNS-over-HTTPS) and --dns-override
  names that resolve to Pixiecore or a given address, sending
  X-Pixiecore-Dns (ip:port) to the API. Adds the dnsforward package,
  using miekg/dns.
- Add --api-header "Name: value" for extra headers to the API server,
  e.g. bearer tokens.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>

480 of 731 new or added lines in 14 files covered. (65.66%)

173 existing lines in 7 files now uncovered.

1886 of 4501 relevant lines covered (41.9%)

3.76 hits per line

Uncovered Changes

Lines Coverage ∆ File
66
5.52
-6.64% pixiecore/pixiecore.go
64
44.83
pixiecore/cli/secureboot.go
24
69.3
14.3% pixiecore/cli/apiclient.go
20
64.91
pixiecore/cli/dns.go
19
87.16
pixiecore/dnsforward/dnsforward.go
15
53.13
pixiecore/secureboot.go
12
80.0
pixiecore/uefisign/uefisign.go
9
86.96
pixiecore/httpproxy.go
7
25.93
2.4% pixiecore/cli/apicmd.go
6
69.94
3.03% pixiecore/tpmkey/tpmkey.go
5
9.21
-0.93% pixiecore/cli/tpmcertcmd.go
2
13.91
0.8% pixiecore/cli/cli.go
1
71.05
pixiecore/cli/httptls.go
1
67.02
10.77% pixiecore/http.go

Coverage Regressions

Lines Coverage ∆ File
49
5.52
-6.64% pixiecore/pixiecore.go
35
69.3
14.3% pixiecore/cli/apiclient.go
32
67.02
10.77% pixiecore/http.go
22
0.0
0.0% pixiecore/pixicorev6.go
13
13.91
0.8% pixiecore/cli/cli.go
12
81.25
-4.8% pixiecore/apiclient.go
10
9.21
-0.93% pixiecore/cli/tpmcertcmd.go
Jobs
ID Job ID Ran Files Coverage
1 37203770096.1 05 Oct 2026 04:08AM UTC 50
41.9
GitHub Action Run
Source Files on build 37203770096
  • Tree
  • List 50
  • Changed 10
  • Source Changed 0
  • Coverage Changed 10
Coverage ∆ File Lines Relevant Covered Missed Hits/Line
  • Back to Repo
  • 1141d2e5 on github
  • Prev Build on wrouesnel/secure-boot-features (#36373570632)
  • Next Build on wrouesnel/secure-boot-features (#37394099508)
  • Delete
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc