Skip to content

feat(bls): add a strict mode and let bootctl outrank the configuration - #115

Merged
azenla merged 10 commits into
mainfrom
azenla/feat/bls-strict-mode
Oct 4, 2026
Merged

azenla merged 10 commits into
mainfrom
azenla/feat/bls-strict-mode

Conversation

@azenla

@azenla azenla commented Oct 4, 2026

Copy link
Copy Markdown
Member

The values that tools like bootctl set in the bootloader interface (LoaderEntryPreferred, LoaderEntryDefault, LoaderConfigTimeout) now outrank default-entry and menu-timeout in sprout.toml, which outrank loader.conf. --menu-timeout and the one-shot timeout still win over everything.

A new --bls-strict-mode flag, and bls-strict-mode in the options of sprout.toml, makes Sprout follow the BLS specification and systemd-boot exactly. A one-shot entry then only becomes the default, no menu timeout means a hidden menu, the default entry may be one with no boot counter tries, and the menu is shown again when a started image returns. Entries that mix linux, efi and uki, entries whose file does not exist, and unified kernel images with no name are hidden. Plain efi entries are not counted, the XBOOTLDR partition is always read, autoconfiguration reads only Sprout's partition and the XBOOTLDR of its disk as one generator, and a devicetree that can't be installed fails the entry. Without strict mode these differences stay as they were, and each one is now logged where it applies, with the full list in the README. A devicetree that can't be installed now warns and boots without it, as before devicetree support was added.

BLS entries can have up to 32 initrds, and the chainload action warns when an entry has an initrd that its chain does not list. A user who once ran bootctl set-default or set-timeout may find it now overrides their sprout.toml, which is worth a release note.

I tested these with QEMU/OVMF, using a helper app to set the EFI variables, a real two-partition GPT disk with a second disk, and aarch64 for the devicetree. I did not test the menu being shown a second time and booting another entry in strict mode, strict autoconfiguration on aarch64, a one-shot set from a real OS, or Secure Boot. After a boot-counted unified kernel image returns to the menu in strict mode, choosing the same image again uses its old file name and fails.

azenla added 10 commits October 4, 2026 10:15
The default entry and the menu timeout that bootctl sets in LoaderEntryDefault,
LoaderEntryPreferred and LoaderConfigTimeout now win over default-entry and
menu-timeout in sprout.toml, as they do over loader.conf in systemd-boot.
--menu-timeout and the one-shot timeout still win over everything.
Add --bls-strict-mode and bls-strict-mode in the options of sprout.toml.
It does nothing yet; the behaviors it controls follow.
… rules

In strict mode a one-shot entry only becomes the default, the default
entry may be one with no boot counter tries left, no menu timeout means a
hidden menu, the menu is shown again when a started image returns, and
entries that mix linux, efi and uki, entries whose file is missing, and
unified kernel images with no name are hidden. Plain EFI entries are not
counted, the XBOOTLDR partition is always read, and a devicetree that
can't be installed fails the entry.

Outside of strict mode these keep working as they did, and each one is
now logged where it applies. The initrd limit of BLS entries is 32.
A devicetree that can't be installed is skipped with a warning.
In strict mode autoconfigure reads BLS entries from the partition Sprout
was loaded from and the extended boot loader partition of its disk, with
one generator, and no longer makes entries from other disks. Other
filesystems that have BLS are still not scanned for Linux kernels.
…n about dropped initrds

An entry that is not counted in strict mode still has its tries, so it
can be bad. Strict mode adds the extended boot loader partition to the
first BLS generator only. A chainload chain that does not list an initrd
that the entry has now warns, as the kernel may not find its root
without it, and strict autoconfigure says when it can't find the
partition of Sprout.
@azenla
azenla merged commit ce8f590 into main Oct 4, 2026
12 checks passed
@azenla
azenla deleted the azenla/feat/bls-strict-mode branch October 4, 2026 17:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant