Sprout is a programmable UEFI bootloader written in Rust.
It is in use at Edera today in development environments and is intended to ship to production soon.
The name "Sprout" is derived from our company name "Edera" which means "ivy." Given that Sprout is the first thing intended to start on an Edera system, the name was apt.
It supports x86_64 and ARM64 EFI-capable systems. It is designed to require UEFI and can be chainloaded from an
existing UEFI bootloader or booted by the hardware directly.
Sprout is licensed under Apache 2.0 and is open to modifications and contributions.
NOTE: Sprout is still in beta. Some features may not work as expected. Please report any bugs you find.
At Edera we make compute isolation technology for a wide variety of environments, often ones we do not fully control. Our technology uses a hypervisor to boot the host system to provide a new isolation mechanism that works with or without hardware virtualization support. To do this, we need to inject our hypervisor at boot time.
Unfortunately, GRUB, the most common bootloader on Linux systems today, uses a shell-script like configuration system. Both the code that runs to generate a GRUB config and the GRUB config itself is fully turing complete. This makes modifying boot configuration difficult and error-prone.
Sprout was designed to take in a machine-readable, writable, and modifiable configuration that treats boot information like data plus configuration, and can be chained from both UEFI firmware and GRUB alike.
Sprout aims to be flexible, secure, and modern. Written in Rust, it handles data safely and uses unsafe code as little as possible. It also critically must be easy to install into all common distributions, relying on simple principles to simplify installation and usage.
Some guides support Secure Boot and some do not. We recommend running Sprout without Secure Boot for development, and with Secure Boot for production.
| Operating System | Secure Boot Enabled | Link |
|---|---|---|
| Fedora | ✅ | Setup Guide |
| Debian | ✅ | Setup Guide |
| Ubuntu | ✅ | Setup Guide |
| openSUSE | ✅ | Setup Guide |
| Fedora | ❌ | Setup Guide |
| Alpine Edge | ❌ | Setup Guide |
| Generic Linux | ❌ | Setup Guide |
| Windows | ❌ | Setup Guide |
- Configuration Reference
- Development Guide
- Contributing Guide
- Sprout License
- Code of Conduct
- Security Policy
- Loadable driver support
- Bootloader specification (BLS) support: Type #1 entries, Type #2 unified kernel images, and the extended boot loader partition
- UKI support: including images with multiple profiles
- Boot counting, so
systemd-bless-bootcan assess a boot -
loader.confsupport - Chainload support
- Linux boot support via EFI stub
- Windows boot support via chainload
- Load Linux initrd from disk
- Devicetree support
- Basic, simple, and graphical boot menus
- A strict mode that follows the BLS specification and systemd-boot exactly
- Generators for BLS entries, lists, and matrices, with variants
- BLS autoconfiguration support
- Secure Boot support
- Bootloader interface support
- BLS specification conformance
- Full-featured boot menu
- Network boot of unified kernel images (
uki-url) and devicetree overlays - A random seed for the Linux kernel
- multiboot2 support
- Linux boot protocol (boot without EFI stub)
- drivers: loadable EFI modules that can add functionality to the EFI system.
- autoconfiguration: code that can automatically generate sprout.toml based on the EFI environment.
- actions: executable code with a configuration that can be run by various other sprout concepts.
- generators: code that can generate boot entries based on inputs or runtime code.
- extractors: code that can extract values from the EFI environment.
- values: key-value pairs that can be specified in the configuration or provided by extractors or generators.
- entries: boot entries that will be displayed to the user.
- phases: stages of the bootloader that can be hooked to run actions at specific points.
Sprout is provided as a single EFI binary called sprout.efi.
It can be chainloaded from GRUB or other UEFI bootloaders or booted into directly.
Sprout reads its configuration from \sprout.toml in the root of the EFI partition it was loaded from.
This is a configuration that boots a Linux kernel from the EFI partition:
# sprout configuration: version 1
version = 1
# add a boot entry for booting linux
# which will run the boot-linux action.
[entries.boot-linux]
title = "Boot Linux"
actions = ["boot-linux"]
# use the chainload action to boot linux via the efi stub.
# the options below are passed to the efi stub as the
# kernel command line. the initrd is loaded using the efi stub
# initrd loader mechanism.
[actions.boot-linux]
chainload.path = "\\vmlinuz"
chainload.options = ["root=/dev/sda1"]
chainload.linux-initrd = "\\initrd"On a system that follows the Boot Loader Specification, you may not need to write one. With an ext4 driver loaded, autoconfiguration finds the entries on its own:
version = 1
[drivers.ext4]
path = "\\sprout\\drivers\\ext4.efi"
[options]
autoconfigure = trueThe full list of settings, the command line options, generators, and how Sprout treats BLS entries,
loader.conf and strict mode are in the configuration reference.
