Add support for android boot - #399
Conversation
This is the branch used in the pr: composefs/composefs-rs#399 This change is temporary, and we should replace it with a released version.
cbf4e98 to
d879e41
Compare
This is the branch used in the pr: composefs/composefs-rs#399 This change is temporary, and we should replace it with a released version. Signed-off-by: Alexander Larsson <alexl@redhat.com>
d879e41 to
62e7cb8
Compare
This is the branch used in the pr: composefs/composefs-rs#399 This change is temporary, and we should replace it with a released version. Signed-off-by: Alexander Larsson <alexl@redhat.com>
This is the branch used in the pr: composefs/composefs-rs#399 This change is temporary, and we should replace it with a released version. Signed-off-by: Alexander Larsson <alexl@redhat.com>
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Untrusted component sizes can cause excessive allocation, and module-directory discovery lacks tests.
Get a fresh assessment by requesting another Copilot review.
Review effort: Balanced
Findings: 1
Open (3)
What changed in this PR
Adds preparatory Android boot v2 parsing and aboot artifact discovery.
Changes:
- Parses Android boot v2 headers, components, and command lines.
- Discovers Android/UKI aboot payloads and matching vbmeta files.
- Adds
BootEntry::Aboot, while explicitly rejecting unsupported writes.
| File | Description |
|---|---|
android_boot.rs |
Implements Android boot v2 parsing and tests. |
bootloader.rs |
Discovers and validates aboot artifacts. |
lib.rs |
Exposes the Android boot module. |
uki.rs |
Adds a shared UKI test fixture. |
write_boot.rs |
Rejects unsupported aboot writing. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
62e7cb8 to
9d0af7d
Compare
We'll need this later to parse aboot boot data. Signed-off-by: Alexander Larsson <alexl@redhat.com>
This looks for aboot.img and optional vbmeta.img for android boot support. Signed-off-by: Alexander Larsson <alexl@redhat.com>
9d0af7d to
fdc9e10
Compare
|
@cgwalters This changes the API a bit, so it kinda naturally breaks the reverse dependency. How do we handle this? |
|
The reverse dependency CI is intentionally not a gating test, but yes SOP is currently to do one of
And we need some kind of automatic reminder on this |
|
@cgwalters lemme disable it for now then |
This changes some APIs, and we need the corresponding changes in bootc from: bootc-dev/bootc#2490 We'll re-enable this once that is merged. Signed-off-by: Alexander Larsson <alexl@redhat.com>
| jobs: | ||
| bootc-test: | ||
| name: Build and test bootc with local composefs-rs | ||
| if: never() |
There was a problem hiding this comment.
For followup This should really have a TODO comment... I guess what we really need is like a cargo xtask style script that handles this, then we could even have a CI check there that causes a nonblocking CI failure e.g. a month later to ensure we don't forget to re-enable it
| // Layout from Android's boot image specification: | ||
| // https://android.googlesource.com/platform/system/tools/mkbootimg/+/refs/heads/main/include/bootimg/bootimg.h | ||
| #[derive(Debug, FromBytes, Immutable, KnownLayout)] | ||
| #[cfg_attr(test, derive(zerocopy::IntoBytes))] |
There was a problem hiding this comment.
So much nicer w/zerocopy right?
| let end = nul_terminated_len(&self.cmdline); | ||
| Ok(std::str::from_utf8(&self.cmdline[..end])?) |
There was a problem hiding this comment.
I think this would be a lot cleaner using
https://doc.rust-lang.org/stable/std/ffi/struct.CStr.html#method.from_bytes_with_nul + str::from_utf8 on the bytes from that CStr
There was a problem hiding this comment.
In fact standing rule we should have in our Rust style guide:
- In Rust, most cases of array indexing can be replaced with methods that have better runtime safety and avoid implicit panics; this is one. Using
str::split_onceis another great example
This is the branch used in the pr: composefs/composefs-rs#399 This change is temporary, and we should replace it with a released version. Signed-off-by: Alexander Larsson <alexl@redhat.com>


This is some preparatory work for bootc support for android boot. It has two parts: