Repository navigation
feat(bls): XBOOTLDR, devicetree, multi-profile UKIs and reboot-on-error - #113
Merged
Merged
Conversation
Add the reboot-on-error loader.conf setting. With auto, which is the default, the machine resets after a failed start only if a boot counter try was just used up and there were tries left, so the entry eventually runs out of tries and the next boot picks another one. yes always resets and no never does.
… a partition Look for a filesystem on the same disk whose GPT partition type is the XBOOTLDR type, using the partition info protocol. open_shared moves to the handle module so the graphical menu and the discovery share it.
Add a devicetree option to the chainload action, set from the devicetree key of a BLS entry. The file is installed as the EFI devicetree table with the memory type that a devicetree has to be in, patched by the fixup protocol when the firmware has one, and the table of the firmware is put back when the image returns or fails to start. It is ignored when Secure Boot is enabled, as it can't be verified, and the DeviceTree loader feature is advertised.
A unified kernel image can have several profiles, each started by a .profile section and made of the sections after it on top of the base. Every profile is an entry. The first has the id of the file, and the others add @ and the identifier or the number of the profile, with a title that names the profile and the profile number as the load options. The profiles share the boot counter of the file, sort in the order they are in the image, and a profile after the first is not picked as the default entry when no default was asked for. The PE reader keeps every section in order, so repeated names and the sections that a profile removes can be told apart, and reads images with more than 96 sections.
Add an xbootldr option to the BLS generator. When it is enabled, the partition with the XBOOTLDR type on the same disk as Sprout's partition is read as well, and its entries and unified kernel images are sorted with the others. As their files are on that partition, every entry has an entry-root value, which is the device of the partition or nothing for Sprout's own, to use in a path like $entry-root\$chainload. It is off by default, as existing actions would look for the files on the wrong partition.
Update the feature list for what is implemented now, including the graphical menu and the generators, add the command line options that were missing, and document the BLS generator options, boot counting, loader.conf, and the bootloader interface.
Only warn about a devicetree under Secure Boot when the entry has one, skip the fixup if its protocol can't be opened, and reject a devicetree whose size is smaller than its header. Announce a reboot before the delay, advertise the multi-profile UKI feature, and treat a Type 1 entry with a profile after the first as an extra profile that is not picked as the fallback default. A failure to read Sprout's own partition no longer drops the entries of the XBOOTLDR partition, and the README lists every initrd slot and describes the reboot behaviour more exactly.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds the next set of BLS features and brings the README up to date.
The BLS generator has a new
xbootldroption that also reads the Extended Boot Loader Partition on the same disk, found by its GPT type, and sorts its entries and unified kernel images with the others. Every entry gets anentry-rootvalue to build paths on its own partition, and the option is off by default because existing actions would look for those files on the wrong partition. Thedevicetreekey of an entry is now installed as the EFI devicetree table for the image, patched by the fixup protocol when the firmware has one, and the firmware's table is put back when the image returns. It is ignored under Secure Boot, and a devicetree file that is missing or invalid now fails the entry, as it does in systemd-boot, where the key used to be ignored. A unified kernel image with several profiles is now one entry per profile, with ids likefedora.efi@rescue, a title that names the profile, and@Nas the load options. Thereboot-on-errorsetting ofloader.confresets the machine when an entry fails to start after a boot counter try was used up and tries were left, so a failed entry can't be retried forever.The README now lists what is implemented, documents the BLS options, boot counting,
loader.confand the bootloader interface, and adds the command line options that were missing.I tested these with QEMU/OVMF, using a real two-partition GPT disk for XBOOTLDR, aarch64 for the devicetree, and fake images for the profiles. I could not test Secure Boot, U-Boot's fixup protocol, signed unified kernel images, or
bootctlfrom a running system.