Skip to content

feat(bls): loader.conf, @saved and boot assessment - #108

Merged
azenla merged 4 commits into
mainfrom
azenla/feat/loader-conf
Oct 4, 2026
Merged

azenla merged 4 commits into
mainfrom
azenla/feat/loader-conf

Conversation

@azenla

@azenla azenla commented Oct 4, 2026

Copy link
Copy Markdown
Member

Reads \loader\loader.conf from the partition Sprout was loaded from and uses its default and timeout. A missing file has no effect, and any other key logs a warning. The file is measured into the TPM like sprout.toml.

Precedence, highest first:

  • Timeout: LoaderConfigTimeoutOneShot, --menu-timeout, config menu-timeout, LoaderConfigTimeout, loader.conf.
  • Default entry: config default-entry, LoaderEntryDefault, loader.conf. A source that matches no usable entry falls through to the next one.

This changes the existing order: config values now beat bootctl set-default and bootctl set-timeout, where the EFI variables used to win. To tell an explicit menu-timeout from the built-in default, the option is now optional internally. Existing config files are unaffected.

loader.conf default is a glob matched against the entry name with or without .conf. default @saved selects the entry in LoaderEntryLastBooted and saves the booted entry there. Forced and one-shot boots are not saved.

After a boot counter try is consumed, the renamed entry file is published in LoaderBootCountPath so systemd-bless-boot can mark the boot good. The BootCounting and SavedEntry features are now advertised.

Tested with cargo test (the bls parser, path and default tests run on the host), clippy on both UEFI targets, and QEMU/OVMF boots on a FAT image covering default selection, config beating loader.conf, a bad default entry falling through, and timeout precedence. Not tested: @saved persistence across boots, the contents of LoaderBootCountPath, and aarch64 at runtime.

azenla added 4 commits October 3, 2026 17:24
Read \loader\loader.conf from the partition Sprout was loaded from and
use its default and timeout as the lowest priority source. Sprout now
picks the timeout in this order: LoaderConfigTimeoutOneShot,
--menu-timeout, the configuration, LoaderConfigTimeout, loader.conf. The
default entry order is the configuration, LoaderEntryDefault, loader.conf,
and a source that matches no entry falls through to the next one.

To tell an explicit menu-timeout from the built-in default, the
configuration option is now optional. Existing files are unaffected.

A loader.conf default of @saved selects the entry in
LoaderEntryLastBooted and saves the booted entry there on every boot.

After consuming a boot counter try, publish the renamed entry file in
LoaderBootCountPath and advertise the boot counting and saved entry
features.
@azenla
azenla merged commit 7d913b3 into main Oct 4, 2026
12 checks passed
@azenla
azenla deleted the azenla/feat/loader-conf branch October 4, 2026 00:39
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant