U-Boot: one stray serial byte parks the board at a prompt forever (CONFIG_BOOT_RETRY) #35
Labels
No labels
blocked-physical
cleanup
hardware
infra
kernel
P1-critical
P2-high
P3-normal
P4-later
reliability
security
upstream
wontfix
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
tiagoagueda/a80#35
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
A single noise byte on the serial RX line during the boot window leaves the board
sitting at a prompt indefinitely. With no remote power control that is a
brick-until-someone-visits, and the serial adapter is permanently attached.
The mechanism
common/cli_readline.c:479:The timeout is honoured only until the first character arrives. After that the
read blocks forever.
common/menu.c:216compounds it:so an unrecognised menu choice clears the timeout for every subsequent read.
Both the
bootdelaycountdown and the extlinuxEnter choice:menu(38-userspace-hardening.md) go through this path.
Why this is not hypothetical
/dev/ttyUSB0on ouranos as the black box.sending stray bytes reliably stops a boot.
characters on its own.
Change
The guard is already wired into that same code path —
bootretry_tstc_timeout()atcommon/cli_readline.c:477. It just needs enabling:Idle at any prompt for 60 s re-runs
bootcmd. This covers the bootdelay prompt, theextlinux menu, and a manual
<INTERRUPT>in one change.CONFIG_RESET_TO_RETRYisavailable if a full reset is preferred over re-running
bootcmd; start without it.Note
This is not covered by
CONFIG_WATCHDOG_AUTOSTART. U-Boot pets the watchdog fromits own idle loop, so a parked prompt reads as healthy. The two changes are
complementary.
Acceptance
boots on its own within ~60 s.
<INTERRUPT>at the prompt also resumes booting rather thanwaiting forever.
Done and verified 2026-08-28.
One correction to the plan here:
CONFIG_BOOT_RETRY=y+CONFIG_BOOT_RETRY_TIME=60alonedoes not build.
CONFIG_BOOT_RETRY_COMMANDdoes not exist anywhere in the tree - that#errorstring isstale. The symbol wanted is
CONFIG_RETRY_BOOTCMD("Run bootcmd on retry"), which is theright one anyway: re-running
bootcmdis smaller thanRESET_TO_RETRYand does not incrementthe boot counter, so serial noise cannot walk the board into #36's known-good fallback.
Verified by reproducing the fault - bytes pushed at the RX line during the autoboot window,
then the port left alone:
Reachable again 72 s after the last byte - 60 s of retry plus the boot. No SPL banner in
between, so it was the retry and not a watchdog reset.
That stale
#errorstring is a one-line upstream cleanup nobody has sent.