Skip to content

fix(bls): match systemd-boot on entry ids, preferred entries and boot assessment - #112

Merged
azenla merged 8 commits into
mainfrom
azenla/fix/bls-support
Oct 4, 2026
Merged

azenla merged 8 commits into
mainfrom
azenla/fix/bls-support

Conversation

@azenla

@azenla azenla commented Oct 4, 2026

Copy link
Copy Markdown
Member

Fixes the gaps found by checking Sprout against the Boot Loader Specification, the Boot Loader Interface and systemd-boot's source.

Entries now have the id systemd-boot gives them: the file name without the boot counter and with its .conf or .efi extension, in lower case. Sprout publishes that in LoaderEntries, LoaderEntrySelected and LoaderEntryLastBooted, so bootctl can find its own entries and UKIs. LoaderEntryDefault, LoaderEntryOneShot and loader.conf match by id, ignoring case, with *, ? and [a-z]. They no longer match titles or numbers, and an old name without the extension still matches. @saved now works from LoaderEntryDefault too, and a saved entry is removed when it is no longer asked for. LoaderEntryPreferred and the loader.conf preferred key select an entry that skips boot counter entries with no tries left.

A bad entry that is booted by hand is now counted, and its LoaderBootCountPath is set. Read-only entry files are left alone. Type 1 entries can use architecture, uki and profile, files starting with auto- are ignored, and loader.conf accepts quoted values, invalid UTF-8, and a failed TPM measurement without stopping the boot. A hidden menu, from a zero timeout or menu-hidden, waits 100 ms for a key press before booting, and menu-disabled does not.

The advertised features now include sort keys and the preferred entry, and no longer claim drop-in drivers. LoaderInfo includes the Sprout version.

I tested each change with QEMU/OVMF boots, including injected key presses. I could not test the EFI variables from a running OS, @saved across boots, or aarch64. XBOOTLDR discovery, devicetree, multi-profile UKIs and the random seed are not part of this.

azenla added 8 commits October 3, 2026 19:19
Entries now have an id, the file name without the boot counter and with
its .conf or .efi extension in lower case, which is what systemd-boot
publishes in LoaderEntries and LoaderEntrySelected and what bootctl
expects. LoaderEntryDefault, LoaderEntryOneShot and loader.conf match by
id, ignoring case, with *, ? and [a-z], and no longer match titles or
numbers. A type 1 and a type 2 entry with the same name no longer clash.

@saved now works from LoaderEntryDefault as well, stops saving when it
is not asked for, and removes a stale saved entry. LoaderEntryPreferred
and the loader.conf preferred key select an entry that skips bad boot
counter entries. An entry with no tries left that is booted by hand is
counted too, and a read-only entry file is left alone.

Type 1 entries can name an architecture, which hides them on another
architecture, and a uki with an optional profile. Files that start with
auto- are ignored. loader.conf is read lossily, and a failed measurement
no longer stops the boot.
A menu with a zero timeout or menu-hidden now waits 100 ms for a key press
before booting the default entry, which is how the boot loader interface
lets a user interrupt a hidden menu. menu-disabled still skips the wait.
…mall details

Do not pad the boot counter digits or cap the tries done counter, as
systemd-bless-boot reads a counter with a leading zero as octal and
systemd-boot never writes one. A profile only selects a profile when it
is a number above zero, an unterminated bracket in a pattern matches
nothing, and files that start with auto- are ignored in any case and for
unified kernel images too. The saved entry is compared ignoring case, and
entry settings are only expanded for sources that are looked at.
@azenla
azenla merged commit 14bcfc2 into main Oct 4, 2026
12 checks passed
@azenla
azenla deleted the azenla/fix/bls-support branch October 4, 2026 02:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant