From nobody Sat Sep 26 06:44:55 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hsJ3D0LsYz6tPf6 for ; Sat, 26 Sep 2026 06:44:56 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hsJ3C5yHsz3Nc1 for ; Sat, 26 Sep 2026 06:44:55 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790405095; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=sHMrfcfdosKyhiGSeCvowlmnhO/1r9qeRADhudMrEL4=; b=RcxA3a7plLTMlE04qK6zkktr2vySzENsTSMqrB5YIEs2+p0hhjgxYdVNVpxCttEUzOl602 cG2hZhw2NiLMHgIUAwt2fj8LFbn2b5C7SgVBJUxRgVAMsLVk2lRYW4ayiSfwimZPQYyCIz 593yDcn086vp5/vYexDGJJ1xOuSm0waVP8HOrN1hJfZ/2jTsHkLL5ldGacDenP9S9dNt41 UVK0iIUqCd1WHQPZwjMZn7gZnu3NTzn6R1yWQelRXUpbAOaDbYwKE1CLOnmThJy25g8NJ6 RHtUfabtOjSBeuPhpgw2CWKFUAmfjvXGBXjotrGCWCDIV9Qr3TjIv/XS7Oa5cA== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1790405095; b=urJROE0vkzPyVdoeprl5XDoOnn8hCSAkUXqDnvrpEjOU//QP1KZT4sgwHQJ75JHznMBHOt 3I2mDyYNkKeixHWBRh0K+vTCh0OrINTfnj/5iVFRDewc3JQn6GjlrQSQyZFR3JnyQxzjBT cZX6fB6Y9ZvxDDKMiY5S32HGxQFySizMbvXdwQunW8aMMXKgLtkC+xUc7HEBrqRMBlSCU3 lKg3qq0AcZVm9efUDV9bqIZXVCyZMQu/O3Jowgwp9VFjPk0bpZFon70rjvFrJ82lww8bE/ xBGcz1pPlGavkd0z+Iu4JCYiLWii7p8lVy7kaiomVY18+Sx7zuMJA/FhEK77fA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1790405095; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=sHMrfcfdosKyhiGSeCvowlmnhO/1r9qeRADhudMrEL4=; b=ucRCExz4rekdD49eeeI4SP/YCaGjTDFhLOoWMWoSAC0u00V3FK2SUpoREFfuawbQ70ALdq WTXkOXTxh4qm6oBzZVXiFY8V03w2Kn6/6/onONr9Yi2w/pO7YsEuOZnRAAXFzq3UA3WBB2 424wN3ntwKpgYInARYmkucgiXpViaXgapQTUTjYsiTjHFiT32VzhaFln1mD9qC8fjchIh/ clPiZ7wunRQWe1lcZW6wrqgSZKbzN/4zj2m/a/iQEydv6M/Gr55+EJIJz3svTafwyPSEYs OlE+TuQuHN9M9gSJnoQy6U5FX/7TLmTZg5U6AaqxnkIVrlvbOFauLjiiNjAPfA== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hsJ3C4WYHzlvt for ; Sat, 26 Sep 2026 06:44:55 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 35df8 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sat, 26 Sep 2026 06:44:55 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Warner Losh Subject: git: 9ecc2493ca5f - main - Restore booting the partition the EFI boot image was loaded from. List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: imp X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 9ecc2493ca5fbba852e175674b5cb8975b99af84 Auto-Submitted: auto-generated Date: Sat, 26 Sep 2026 06:44:55 +0000 Message-Id: <6ab769e7.35df8.13088346@gitrepo.freebsd.org> The branch main has been updated by imp: URL: https://cgit.FreeBSD.org/src/commit/?id=9ecc2493ca5fbba852e175674b5cb8975b99af84 commit 9ecc2493ca5fbba852e175674b5cb8975b99af84 Author: Warner Losh AuthorDate: 2026-09-26 06:35:41 +0000 Commit: Warner Losh CommitDate: 2026-09-26 06:44:20 +0000 Restore booting the partition the EFI boot image was loaded from. BSDRP images are built with "poudriere image -t firmware", which puts gptboot.efi on the ESP instead of loader.efi. gptboot.efi reads the GPT bootme attribute, picks the active system partition (BSDRP1 or BSDRP2), chainloads /boot/loader.efi from it and hands loader.efi that partition in LoadedImage->DeviceHandle (stand/efi/boot1/boot1.c:try_boot). Since ce9bfd78167 ("loader.efi: Refactor try_boot_device_partitions"), find_currdev() no longer tries that device: try_boot_device_partitions() walks the parent disk while explicitly skipping dp->pd_handle, on the assumption that the boot image always comes from an ESP holding no root filesystem. When chainloaded, the partition gptboot.efi selected is therefore the one partition never considered, and loader.efi falls through to the first other UFS partition on the disk - the previous system. Every A/B upgrade silently boots the old slice. Commit 1c85c5eea09, which introduced try_boot_device_partitions(), did try dp itself before its siblings; the refactor dropped it. Restore it, keeping the sibling walk as the fallback for the normal ESP case. Fixes: ce9bfd78167 Assisted-by: Claude Code (Fable 5, Opus 5) Sponsored by: Netflix --- stand/efi/loader/main.c | 17 ++++++++++++++--- 1 file changed, 14 insertions(+), 3 deletions(-) diff --git a/stand/efi/loader/main.c b/stand/efi/loader/main.c index 488e3eb1100b..fa4647101d62 100644 --- a/stand/efi/loader/main.c +++ b/stand/efi/loader/main.c @@ -399,9 +399,10 @@ try_disk_and_partitions(pdinfo_t *disk, EFI_HANDLE skip_handle) } /* - * Search the boot device first (i.e. the ESP and any sibling partitions). - * Per the UEFI specification, filesystems on other devices must not be - * preferred until the boot device has been fully exhausted. + * Search the boot device first (i.e. the device we were loaded from and any + * sibling partitions). Per the UEFI specification, filesystems on other + * devices must not be preferred until the boot device has been fully + * exhausted. */ static int try_boot_device_partitions(void) @@ -419,6 +420,16 @@ try_boot_device_partitions(void) efi_free_devpath_name(text); } + /* + * Usually this is the ESP, which holds no root filesystem, and the + * sibling walk below is what finds the root. But when we have been + * chainloaded (gptboot.efi hands us the partition it selected with + * the GPT bootme attribute), this is the partition we are meant to + * boot from, so it must be tried before its siblings. + */ + if (try_as_currdev(dp, false)) + return (0); + return (try_disk_and_partitions(dp->pd_parent, dp->pd_handle)); }