fix(bls): match systemd-boot on entry ids, preferred entries and boot assessment - #112
Merged
Merged
Conversation
Entries now have an id, the file name without the boot counter and with its .conf or .efi extension in lower case, which is what systemd-boot publishes in LoaderEntries and LoaderEntrySelected and what bootctl expects. LoaderEntryDefault, LoaderEntryOneShot and loader.conf match by id, ignoring case, with *, ? and [a-z], and no longer match titles or numbers. A type 1 and a type 2 entry with the same name no longer clash. @saved now works from LoaderEntryDefault as well, stops saving when it is not asked for, and removes a stale saved entry. LoaderEntryPreferred and the loader.conf preferred key select an entry that skips bad boot counter entries. An entry with no tries left that is booted by hand is counted too, and a read-only entry file is left alone. Type 1 entries can name an architecture, which hides them on another architecture, and a uki with an optional profile. Files that start with auto- are ignored. loader.conf is read lossily, and a failed measurement no longer stops the boot.
A menu with a zero timeout or menu-hidden now waits 100 ms for a key press before booting the default entry, which is how the boot loader interface lets a user interrupt a hidden menu. menu-disabled still skips the wait.
…mall details Do not pad the boot counter digits or cap the tries done counter, as systemd-bless-boot reads a counter with a leading zero as octal and systemd-boot never writes one. A profile only selects a profile when it is a number above zero, an unterminated bracket in a pattern matches nothing, and files that start with auto- are ignored in any case and for unified kernel images too. The saved entry is compared ignoring case, and entry settings are only expanded for sources that are looked at.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes the gaps found by checking Sprout against the Boot Loader Specification, the Boot Loader Interface and systemd-boot's source.
Entries now have the id systemd-boot gives them: the file name without the boot counter and with its
.confor.efiextension, in lower case. Sprout publishes that inLoaderEntries,LoaderEntrySelectedandLoaderEntryLastBooted, sobootctlcan find its own entries and UKIs.LoaderEntryDefault,LoaderEntryOneShotandloader.confmatch by id, ignoring case, with*,?and[a-z]. They no longer match titles or numbers, and an old name without the extension still matches.@savednow works fromLoaderEntryDefaulttoo, and a saved entry is removed when it is no longer asked for.LoaderEntryPreferredand theloader.confpreferredkey select an entry that skips boot counter entries with no tries left.A bad entry that is booted by hand is now counted, and its
LoaderBootCountPathis set. Read-only entry files are left alone. Type 1 entries can usearchitecture,ukiandprofile, files starting withauto-are ignored, andloader.confaccepts quoted values, invalid UTF-8, and a failed TPM measurement without stopping the boot. A hidden menu, from a zero timeout ormenu-hidden, waits 100 ms for a key press before booting, andmenu-disableddoes not.The advertised features now include sort keys and the preferred entry, and no longer claim drop-in drivers.
LoaderInfoincludes the Sprout version.I tested each change with QEMU/OVMF boots, including injected key presses. I could not test the EFI variables from a running OS,
@savedacross boots, or aarch64. XBOOTLDR discovery, devicetree, multi-profile UKIs and the random seed are not part of this.