Skip to content

boot-success forgets the firmware entries before it removes or sets aside the trial record - #262

Merged
DevomB merged 5 commits into
mainfrom
forget-before-record
Oct 9, 2026
Merged

DevomB merged 5 commits into
mainfrom
forget-before-record

Conversation

@DevomB

@DevomB DevomB commented Oct 9, 2026 •

Copy link
Copy Markdown
Owner

Built on #261 (kernel-copy-compared, itself on #258). Until those land, the diff against main includes their commits. This PR's own change is the top commit, a9758aa.

What was wrong (an INFO from the update-chain re-read). kryptik-update apply arms nothing while a trial record stands, but boot-success dropped the record before it forgot the firmware entries, in all four places:

  • the commit and an interrupted arming removed the record first,
  • a trial that did not boot, or came up unhealthy, moved it to trial.failed first.

So an apply finishing in the seconds between could have its BootNext cleared and its trial reported as failed at the next boot. An apply hashes and writes gigabytes first, so this could not happen in practice, but the order made it possible.

What changed. build/service-scripts/boot-success.sh forgets the entries first in all four places, and the comment on forget_entries says why. The unhealthy path keeps forget_entries's result for its reboot decision, which is unchanged.

How the run proves it. tools/tests/boot-success.sh's kryptik-efiboot stand-in records whether the trial record stood at each forget. The commit, unhealthy, did-not-boot and interrupted cases expect it did. Distro run 37883972227 boots trials and commits in the update suite.

Merge with main: comments only in boot-success.sh. 31849d1 merges main 6e06d94, whose shorter comments (#241) met this branch's two changed comment blocks. forget_entries's comment is main's plus this branch's line on running before the trial record goes. The code is identical to the pre-merge head 3f3bd5f, whose Distro run is 37883972227.

DevomB added 5 commits October 8, 2026 21:21
…s its source: boot-success's commit and kryptik-recover's commit and restore now compare, as the installer and kryptik-update already did

boot-success copied the trial slot's kernel to BOOTX64.EFI.new, fsynced and
renamed it without looking at what landed, and kryptik-recover did the same for
the boot file and for the medium's kernel. A copy that read back wrong became
a boot file Secure Boot refuses. Now the copy is compared with its source
before the rename: a failed compare fails the commit and the trial stays, as a
failed write already does, and recover stops before anything is committed. The
installer compares BOOTX64.EFI and kryptik-update hashes its staged kernel.
The boot-success fixture makes the copy read back wrong and expects the old
boot file and record and the trial kept.
…side the trial record, so no BootNext an apply has just set is forgotten

kryptik-update arms nothing while a trial record stands. boot-success removed
the record (commit, interrupted arming) or moved it to trial.failed (a trial
that did not boot, or came up unhealthy) and only then forgot the entries:
an apply finishing in between would have its BootNext cleared and its trial
recorded as failed at the next boot. Now the entries go first. The fixture
records whether the trial record stood at each forget.
…ped from the page cache after its fsync, so the compare reads the ESP and not the copy still in memory

From a non-author read: cmp right after sync -f read the cached pages, which
says little more than cp's own status. dd iflag=nocache count=0 drops a file's
clean pages, best effort; boot-success's and kryptik-recover's compares and
kryptik-update's hash of its staged kernel now read what the ESP holds.
…-success.sh, where main's shorter comments meet this branch's; forget_entries's comment keeps its line on running before the trial record goes
@DevomB
DevomB merged commit b6e1f89 into main Oct 9, 2026
11 checks passed
@DevomB
DevomB deleted the forget-before-record branch October 9, 2026 07:07
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant