Skip to content

Add support for android boot - #399

Merged
alexlarsson merged 3 commits into
mainfrom
aboot-support
Sep 28, 2026
Merged

alexlarsson merged 3 commits into
mainfrom
aboot-support

Conversation

@alexlarsson

Copy link
Copy Markdown
Contributor

This is some preparatory work for bootc support for android boot. It has two parts:

  • basic parsing of android boot v2 images, comparable to the existing uki parser
  • Add BootEntry::Aboot picking up aboot boot artifacts from the image.

alexlarsson added a commit to alexlarsson/bootc that referenced this pull request Sep 23, 2026
This is the branch used in the pr:
 composefs/composefs-rs#399

This change is temporary, and we should replace it with
a released version.
alexlarsson added a commit to alexlarsson/bootc that referenced this pull request Sep 23, 2026
This is the branch used in the pr:
 composefs/composefs-rs#399

This change is temporary, and we should replace it with
a released version.

Signed-off-by: Alexander Larsson <alexl@redhat.com>
Comment thread crates/composefs-boot/src/bootloader.rs Outdated
Comment thread crates/composefs-boot/src/bootloader.rs
alexlarsson added a commit to alexlarsson/bootc that referenced this pull request Sep 24, 2026
This is the branch used in the pr:
 composefs/composefs-rs#399

This change is temporary, and we should replace it with
a released version.

Signed-off-by: Alexander Larsson <alexl@redhat.com>
alexlarsson added a commit to alexlarsson/bootc that referenced this pull request Sep 25, 2026
This is the branch used in the pr:
 composefs/composefs-rs#399

This change is temporary, and we should replace it with
a released version.

Signed-off-by: Alexander Larsson <alexl@redhat.com>
cgwalters
cgwalters previously approved these changes Sep 25, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Untrusted component sizes can cause excessive allocation, and module-directory discovery lacks tests.

Get a fresh assessment by requesting another Copilot review.

Review effort: Balanced
Findings: 1 High severity · 2 Low severity

Open (3)
What changed in this PR

Adds preparatory Android boot v2 parsing and aboot artifact discovery.

Changes:

  • Parses Android boot v2 headers, components, and command lines.
  • Discovers Android/UKI aboot payloads and matching vbmeta files.
  • Adds BootEntry::Aboot, while explicitly rejecting unsupported writes.
File Description
android_boot.rs Implements Android boot v2 parsing and tests.
bootloader.rs Discovers and validates aboot artifacts.
lib.rs Exposes the Android boot module.
uki.rs Adds a shared UKI test fixture.
write_boot.rs Rejects unsupported aboot writing.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread crates/composefs-boot/src/android_boot.rs
Comment thread crates/composefs-boot/src/android_boot.rs Outdated
Comment thread crates/composefs-boot/src/bootloader.rs
We'll need this later to parse aboot boot data.

Signed-off-by: Alexander Larsson <alexl@redhat.com>
This looks for aboot.img and optional vbmeta.img for android boot
support.

Signed-off-by: Alexander Larsson <alexl@redhat.com>
@alexlarsson

Copy link
Copy Markdown
Contributor Author

@cgwalters This changes the API a bit, so it kinda naturally breaks the reverse dependency. How do we handle this?

@cgwalters

Copy link
Copy Markdown
Collaborator

The reverse dependency CI is intentionally not a gating test, but yes SOP is currently to do one of

  • disable it and then re-enable it when an updated bootc has landed
  • point it at your fork's draft of an update for this, re-point to main once update has landed

And we need some kind of automatic reminder on this

@alexlarsson

Copy link
Copy Markdown
Contributor Author

@cgwalters lemme disable it for now then

This changes some APIs, and we need the corresponding changes in
bootc from: bootc-dev/bootc#2490

We'll re-enable this once that is merged.

Signed-off-by: Alexander Larsson <alexl@redhat.com>

@cgwalters cgwalters left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Nothing blocking

jobs:
bootc-test:
name: Build and test bootc with local composefs-rs
if: never()

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For followup This should really have a TODO comment... I guess what we really need is like a cargo xtask style script that handles this, then we could even have a CI check there that causes a nonblocking CI failure e.g. a month later to ensure we don't forget to re-enable it

// Layout from Android's boot image specification:
// https://android.googlesource.com/platform/system/tools/mkbootimg/+/refs/heads/main/include/bootimg/bootimg.h
#[derive(Debug, FromBytes, Immutable, KnownLayout)]
#[cfg_attr(test, derive(zerocopy::IntoBytes))]

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

So much nicer w/zerocopy right?

Comment on lines +182 to +183
let end = nul_terminated_len(&self.cmdline);
Ok(std::str::from_utf8(&self.cmdline[..end])?)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I think this would be a lot cleaner using

https://doc.rust-lang.org/stable/std/ffi/struct.CStr.html#method.from_bytes_with_nul + str::from_utf8 on the bytes from that CStr

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

In fact standing rule we should have in our Rust style guide:

  • In Rust, most cases of array indexing can be replaced with methods that have better runtime safety and avoid implicit panics; this is one. Using str::split_once is another great example

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is in #405

@alexlarsson
alexlarsson added this pull request to the merge queue Sep 28, 2026
Merged via the queue into main with commit b90ef51 Sep 28, 2026
29 of 31 checks passed
alexlarsson added a commit to alexlarsson/bootc that referenced this pull request Sep 29, 2026
This is the branch used in the pr:
 composefs/composefs-rs#399

This change is temporary, and we should replace it with
a released version.

Signed-off-by: Alexander Larsson <alexl@redhat.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants