feat(bls): loader.conf, @saved and boot assessment - #108
Merged
Merged
Conversation
Read \loader\loader.conf from the partition Sprout was loaded from and use its default and timeout as the lowest priority source. Sprout now picks the timeout in this order: LoaderConfigTimeoutOneShot, --menu-timeout, the configuration, LoaderConfigTimeout, loader.conf. The default entry order is the configuration, LoaderEntryDefault, loader.conf, and a source that matches no entry falls through to the next one. To tell an explicit menu-timeout from the built-in default, the configuration option is now optional. Existing files are unaffected. A loader.conf default of @saved selects the entry in LoaderEntryLastBooted and saves the booted entry there on every boot. After consuming a boot counter try, publish the renamed entry file in LoaderBootCountPath and advertise the boot counting and saved entry features.
…ve forced boots for @saved
…he boot count path
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Reads
\loader\loader.conffrom the partition Sprout was loaded from and uses itsdefaultandtimeout. A missing file has no effect, and any other key logs a warning. The file is measured into the TPM likesprout.toml.Precedence, highest first:
LoaderConfigTimeoutOneShot,--menu-timeout, configmenu-timeout,LoaderConfigTimeout,loader.conf.default-entry,LoaderEntryDefault,loader.conf. A source that matches no usable entry falls through to the next one.This changes the existing order: config values now beat
bootctl set-defaultandbootctl set-timeout, where the EFI variables used to win. To tell an explicitmenu-timeoutfrom the built-in default, the option is now optional internally. Existing config files are unaffected.loader.confdefaultis a glob matched against the entry name with or without.conf.default @savedselects the entry inLoaderEntryLastBootedand saves the booted entry there. Forced and one-shot boots are not saved.After a boot counter try is consumed, the renamed entry file is published in
LoaderBootCountPathsosystemd-bless-bootcan mark the boot good. TheBootCountingandSavedEntryfeatures are now advertised.Tested with
cargo test(the bls parser, path and default tests run on the host), clippy on both UEFI targets, and QEMU/OVMF boots on a FAT image covering default selection, config beatingloader.conf, a bad default entry falling through, and timeout precedence. Not tested:@savedpersistence across boots, the contents ofLoaderBootCountPath, and aarch64 at runtime.