Skip to content

feat(bls): XBOOTLDR, devicetree, multi-profile UKIs and reboot-on-error - #113

Merged
azenla merged 9 commits into
mainfrom
azenla/fix/enhanced-bls-support
Oct 4, 2026
Merged

azenla merged 9 commits into
mainfrom
azenla/fix/enhanced-bls-support

Conversation

@azenla

@azenla azenla commented Oct 4, 2026

Copy link
Copy Markdown
Member

Adds the next set of BLS features and brings the README up to date.

The BLS generator has a new xbootldr option that also reads the Extended Boot Loader Partition on the same disk, found by its GPT type, and sorts its entries and unified kernel images with the others. Every entry gets an entry-root value to build paths on its own partition, and the option is off by default because existing actions would look for those files on the wrong partition. The devicetree key of an entry is now installed as the EFI devicetree table for the image, patched by the fixup protocol when the firmware has one, and the firmware's table is put back when the image returns. It is ignored under Secure Boot, and a devicetree file that is missing or invalid now fails the entry, as it does in systemd-boot, where the key used to be ignored. A unified kernel image with several profiles is now one entry per profile, with ids like fedora.efi@rescue, a title that names the profile, and @N as the load options. The reboot-on-error setting of loader.conf resets the machine when an entry fails to start after a boot counter try was used up and tries were left, so a failed entry can't be retried forever.

The README now lists what is implemented, documents the BLS options, boot counting, loader.conf and the bootloader interface, and adds the command line options that were missing.

I tested these with QEMU/OVMF, using a real two-partition GPT disk for XBOOTLDR, aarch64 for the devicetree, and fake images for the profiles. I could not test Secure Boot, U-Boot's fixup protocol, signed unified kernel images, or bootctl from a running system.

azenla added 9 commits October 3, 2026 19:50
Add the reboot-on-error loader.conf setting. With auto, which is the
default, the machine resets after a failed start only if a boot counter
try was just used up and there were tries left, so the entry eventually
runs out of tries and the next boot picks another one. yes always resets
and no never does.
… a partition

Look for a filesystem on the same disk whose GPT partition type is the
XBOOTLDR type, using the partition info protocol. open_shared moves to
the handle module so the graphical menu and the discovery share it.
Add a devicetree option to the chainload action, set from the devicetree
key of a BLS entry. The file is installed as the EFI devicetree table
with the memory type that a devicetree has to be in, patched by the
fixup protocol when the firmware has one, and the table of the firmware
is put back when the image returns or fails to start. It is ignored when
Secure Boot is enabled, as it can't be verified, and the DeviceTree
loader feature is advertised.
A unified kernel image can have several profiles, each started by a
.profile section and made of the sections after it on top of the base.
Every profile is an entry. The first has the id of the file, and the
others add @ and the identifier or the number of the profile, with a
title that names the profile and the profile number as the load options.
The profiles share the boot counter of the file, sort in the order they
are in the image, and a profile after the first is not picked as the
default entry when no default was asked for.

The PE reader keeps every section in order, so repeated names and the
sections that a profile removes can be told apart, and reads images with
more than 96 sections.
Add an xbootldr option to the BLS generator. When it is enabled, the
partition with the XBOOTLDR type on the same disk as Sprout's partition
is read as well, and its entries and unified kernel images are sorted
with the others. As their files are on that partition, every entry has
an entry-root value, which is the device of the partition or nothing for
Sprout's own, to use in a path like $entry-root\$chainload. It is off
by default, as existing actions would look for the files on the wrong
partition.
Update the feature list for what is implemented now, including the
graphical menu and the generators, add the command line options that
were missing, and document the BLS generator options, boot counting,
loader.conf, and the bootloader interface.
Only warn about a devicetree under Secure Boot when the entry has one,
skip the fixup if its protocol can't be opened, and reject a devicetree
whose size is smaller than its header. Announce a reboot before the
delay, advertise the multi-profile UKI feature, and treat a Type 1 entry
with a profile after the first as an extra profile that is not picked as
the fallback default. A failure to read Sprout's own partition no longer
drops the entries of the XBOOTLDR partition, and the README lists every
initrd slot and describes the reboot behaviour more exactly.
@azenla
azenla merged commit 4e10d57 into main Oct 4, 2026
12 checks passed
@azenla
azenla deleted the azenla/fix/enhanced-bls-support branch October 4, 2026 03:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant