Repository navigation
feat(bls): add a strict mode and let bootctl outrank the configuration - #115
Merged
Merged
Conversation
The default entry and the menu timeout that bootctl sets in LoaderEntryDefault, LoaderEntryPreferred and LoaderConfigTimeout now win over default-entry and menu-timeout in sprout.toml, as they do over loader.conf in systemd-boot. --menu-timeout and the one-shot timeout still win over everything.
Add --bls-strict-mode and bls-strict-mode in the options of sprout.toml. It does nothing yet; the behaviors it controls follow.
… rules In strict mode a one-shot entry only becomes the default, the default entry may be one with no boot counter tries left, no menu timeout means a hidden menu, the menu is shown again when a started image returns, and entries that mix linux, efi and uki, entries whose file is missing, and unified kernel images with no name are hidden. Plain EFI entries are not counted, the XBOOTLDR partition is always read, and a devicetree that can't be installed fails the entry. Outside of strict mode these keep working as they did, and each one is now logged where it applies. The initrd limit of BLS entries is 32. A devicetree that can't be installed is skipped with a warning.
In strict mode autoconfigure reads BLS entries from the partition Sprout was loaded from and the extended boot loader partition of its disk, with one generator, and no longer makes entries from other disks. Other filesystems that have BLS are still not scanned for Linux kernels.
…n about dropped initrds An entry that is not counted in strict mode still has its tries, so it can be bad. Strict mode adds the extended boot loader partition to the first BLS generator only. A chainload chain that does not list an initrd that the entry has now warns, as the kernel may not find its root without it, and strict autoconfigure says when it can't find the partition of Sprout.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The values that tools like
bootctlset in the bootloader interface (LoaderEntryPreferred,LoaderEntryDefault,LoaderConfigTimeout) now outrankdefault-entryandmenu-timeoutinsprout.toml, which outrankloader.conf.--menu-timeoutand the one-shot timeout still win over everything.A new
--bls-strict-modeflag, andbls-strict-modein the options ofsprout.toml, makes Sprout follow the BLS specification and systemd-boot exactly. A one-shot entry then only becomes the default, no menu timeout means a hidden menu, the default entry may be one with no boot counter tries, and the menu is shown again when a started image returns. Entries that mixlinux,efianduki, entries whose file does not exist, and unified kernel images with no name are hidden. Plainefientries are not counted, the XBOOTLDR partition is always read, autoconfiguration reads only Sprout's partition and the XBOOTLDR of its disk as one generator, and a devicetree that can't be installed fails the entry. Without strict mode these differences stay as they were, and each one is now logged where it applies, with the full list in the README. A devicetree that can't be installed now warns and boots without it, as before devicetree support was added.BLS entries can have up to 32 initrds, and the chainload action warns when an entry has an initrd that its chain does not list. A user who once ran
bootctl set-defaultorset-timeoutmay find it now overrides theirsprout.toml, which is worth a release note.I tested these with QEMU/OVMF, using a helper app to set the EFI variables, a real two-partition GPT disk with a second disk, and aarch64 for the devicetree. I did not test the menu being shown a second time and booting another entry in strict mode, strict autoconfiguration on aarch64, a one-shot set from a real OS, or Secure Boot. After a boot-counted unified kernel image returns to the menu in strict mode, choosing the same image again uses its old file name and fails.