Skip to content

content: update WinBoat page for v0.9.2 - #112

Merged
Stensel8 merged 2 commits into
mainfrom
claude/winboat-v092-update
Aug 31, 2026
Merged

content: update WinBoat page for v0.9.2#112
Stensel8 merged 2 commits into
mainfrom
claude/winboat-v092-update

Conversation

@Stensel8

@Stensel8 Stensel8 commented Aug 31, 2026

Copy link
Copy Markdown
Member

Summary

The WinBoat page judged v0.9.0 and that verdict no longer holds. Retested on v0.9.2, which is noticeably steadier, and added the security fixes from v0.9.1/v0.9.2 that anyone still on v0.9.0 needs to know about.

Type of change

  • content — update or improve existing content

Details

Status

The page opened with "Tested on v0.9.0. Bugs are expected." That version was rough and the page reflected it. v0.9.2 moves it from "interesting but unusable" to "actually worth trying" — still not something to hand to someone who just needs Windows working today, but the direction is right.

The startup-loop findings stay, now explicitly marked as v0.9.0. They describe what the project is working through, and deleting them would erase the history rather than update it.

Security note added

More important than the impression: v0.9.1 and v0.9.2 patch a vulnerability that allowed arbitrary PowerShell execution inside the VM through the get-icon call, plus restricted UNC path access, control character injection, a Slowloris-style attack, and passwords being written to the compose and FreeRDP logs. The project credits @AndreaBonn and shipped a fix within four hours of disclosure.

That is now a warning callout at the top: if you are on v0.9.0, update.

One hedged observation

v0.9.2 also bumps dockur/windows from 5.14 to 6.05 — a major jump in the image that actually runs Windows, and a plausible explanation for the improved startup behaviour. Written as a possibility, not a finding, since no direct link was measured.

known-issues was updated in step so it no longer reports the startup loop as unchanged and open.

Checklist

  • PR title follows the commit convention
  • Both EN and NL versions updated
  • Media is in AVIF format (not PNG/JPG)
  • No broken image references — all six /images/winboat-*.avif and cachyos-hello-winboat.avif verified present
  • Tested locally with hugo server — content-only change, no new shortcodes or images

De pagina oordeelde over v0.9.0 en dat was niet meer eerlijk. Opnieuw
getest op v0.9.2 en het draait merkbaar rustiger. Nog niet af, maar het
verschil tussen 'interessant maar onbruikbaar' en 'het proberen waard'.

De bevindingen over de startup loop blijven staan, nu expliciet gemerkt
als v0.9.0. Ze beschrijven waar het project doorheen werkt, en ze
weggooien zou de geschiedenis wissen.

Belangrijker dan mijn indruk: v0.9.1 en v0.9.2 dichten een kwetsbaarheid
waarmee via get-icon willekeurige PowerShell in de VM kon draaien, plus
UNC-padtoegang, injectie van stuurtekens, een Slowloris-achtige aanval,
en wachtwoorden in de compose- en FreeRDP-logs. Dat staat nu als
waarschuwing bovenaan: wie op v0.9.0 zit moet updaten.

Ook genoteerd dat v0.9.2 dockur/windows van 5.14 naar 6.05 tilt. Dat is
de image die Windows daadwerkelijk draait, dus het is een plausibele
verklaring voor het betere opstartgedrag - als mogelijkheid opgeschreven,
niet als vaststelling, want ik heb dat verband niet gemeten.

known-issues meegetrokken zodat die niet blijft zeggen dat het probleem
onveranderd open staat.
Copilot AI lite review requested due to automatic review settings August 31, 2026 18:13

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@Stensel8 Stensel8 self-assigned this Aug 31, 2026
De Nederlandse pagina miste de statusregel, de beveiligingswaarschuwing
en de dockur/windows-notitie. Bij het schrijven brak een script halverwege
af waardoor het NL-bestand niet werd weggeschreven, en in de herstelronde
zijn alleen de Bugs- en slotsectie opnieuw gedaan.

Daardoor stond er nog 'Getest op v0.9.0' zonder enige verwijzing naar de
kwetsbaarheid die in v0.9.1 en v0.9.2 gedicht is. Dat is precies het deel
dat Nederlandse lezers moesten zien.

Verder em-dashes vervangen door gewone leestekens. De winboat-pagina
gebruikte er nul, dus die waren niet van deze pagina.
@Stensel8
Stensel8 merged commit bccc55f into main Aug 31, 2026
7 checks passed
@Stensel8
Stensel8 deleted the claude/winboat-v092-update branch August 31, 2026 18:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants