From sacadmin Fri Apr  2 16:33:56 2010
Received: from tethys.sfbay.sun.com (tethys.SFBay.Sun.COM [129.146.226.92])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o32NXt88015903;
	Fri, 2 Apr 2010 16:33:55 -0700 (PDT)
Received: from tethys.sfbay.sun.com (localhost [127.0.0.1])
	by tethys.sfbay.sun.com (8.14.4+Sun/8.14.4) with ESMTP id o32NLIMa007320;
	Fri, 2 Apr 2010 16:21:18 -0700 (PDT)
Received: (from jg@localhost)
	by tethys.sfbay.sun.com (8.14.4+Sun/8.14.4/Submit) id o32NLIQb007317;
	Fri, 2 Apr 2010 16:21:18 -0700 (PDT)
Date: Fri, 2 Apr 2010 16:21:18 -0700 (PDT)
From: Jerry Gilliam <jg@tethys.sfbay.sun.com>
Message-Id: <201004022321.o32NLIQb007317@tethys.sfbay.sun.com>
To: PSARC-record@sac.sfbay.sun.com
Subject: Boot Block Downgrade Avoidance [PSARC/2010/113 Self Review]
Status: RO
Content-Length: 607


Template Version: @(#)sac_nextcase 1.70 03/30/10 SMI
This information is Copyright (c) 2010, Oracle and/or its affiliates. All rights reserved.
1. Introduction
    1.1. Project/Component Working Name:
	 Boot Block Downgrade Avoidance
    1.2. Name of Document Author/Supplier:
	 Author:  Jan Setje-Eilers
    1.3  Date of This Document:
	02 April, 2010
4. Technical Description
    See the case directory for more detail

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		ON
    6.5. ARC review type: Automatic
    6.6. ARC Exposure: open


From jerry.gilliam@oracle.com Fri Apr  2 16:44:05 2010
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id o32Ni5xO015985
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 2 Apr 2010 16:44:05 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.4) with ESMTP id o32Ni337031083;
	Fri, 2 Apr 2010 17:44:04 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0L0900A0VWLFBC00@nwk-avmta-2.sfbay.sun.com>; Fri,
 02 Apr 2010 16:44:03 -0700 (PDT)
Received: from sca-ea-mail-2.sun.com ([192.18.43.25])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0L0900G83WLEQGB0@nwk-avmta-2.sfbay.sun.com>; Fri,
 02 Apr 2010 16:44:02 -0700 (PDT)
Received: from acsinet15.oracle.com (acsinet15.oracle.com [141.146.126.227])
	by sca-ea-mail-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id o32Ni242010414;
 Fri, 02 Apr 2010 23:44:02 +0000 (GMT)
Received: from acsmt353.oracle.com (acsmt353.oracle.com [141.146.40.153])
	by acsinet15.oracle.com (Switch-3.4.2/Switch-3.4.1)
 with ESMTP id o32GXh3V022908; Fri, 02 Apr 2010 23:44:01 +0000 (GMT)
Received: from abhmt012.oracle.com by acsmt353.oracle.com	with ESMTP id
 134334511270251822; Fri, 02 Apr 2010 16:43:42 -0700
Received: from [129.146.226.92] (/129.146.226.92)
	by default (Oracle Beehive Gateway v4.0)	with ESMTP ; Fri,
 02 Apr 2010 16:43:42 -0700
Date: Fri, 02 Apr 2010 16:31:03 -0700
From: Jerry Gilliam <jerry.gilliam@oracle.com>
Subject: Boot Block Downgrade Avoidance [PSARC/2010/113 Self Review]
To: PSARC-ext@sun.com
Cc: bart.smaalders@sun.com, Dave.Miner@sun.com, david.comay@sun.com,
        enrico.perla@oracle.com, Eric.Ray@sun.com, ethan.quach@oracle.com,
        evan.layton@oracle.com, Jan.SetjeEilers@oracle.com,
        Jerry.Gilliam@sun.com, Liane.Praza@sun.com, Mark.J.Nelson@oracle.com,
        Sanjay.Nadkarni@sun.com, Sarah.Jelinek@sun.com,
        seth.goldberg@oracle.com
Message-id: <4BB67E37.4020106@oracle.com>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Source-IP: acsmt353.oracle.com [141.146.40.153]
X-Auth-Type: Internal IP
X-CT-RefId: str=0001.0A090206.4BB68142.0019:SCFMA4539814,ss=1,fgs=0
User-Agent: Mozilla/5.0 (X11; U; SunOS i86pc; en-US; rv:1.9.1.8) Gecko/20100302
 Lightning/1.0b1 Thunderbird/3.0.2
Status: RO
Content-Length: 4745


I'm submitting the following fast-track on behalf of Jan Setje-Eilers.

The project believes this qualifies for automatic approval and I've
filed it as such, but can promote to a full fast-track if anyone
prefers.

The proposal is to add a command-line -u option to installboot and
installgrub with Consolidation Private commitment and minor release
binding.

----


1) Summary

	Updating the boot block on a pool with multiple zfs boot
	environments during upgrades should involve a check to avoid
	potentially downgrading the boot block.

2) Technical Details

   2.0) Background

	With the advent of zfs boot, multiple versions of the OS
	can reside in a single area of a device (entire device, partition
	or slice). This forces them to share a single boot loader which
	imposes the following issues:

		a) Newer boot loaders must be able to load older versions
		   of the OS.

			This is ultimately an implementation issue and
			is not part of this case.

		b) During upgrade care must be taken to avoid replacing
		   what might be a newer copy of a boot loader with an
		   older one.

			This issue can arise if a BE is cloned and
			updated to a newer version and is subsequently
			fallen back to and then again cloned and updated
			to an intermediate version.

   2.1) Current state

	2.1.1) SPARC

		In order to avoid potentially downgrading the loader on SPARC
		it is simply never updated. This is poor.

	2.1.2) x86

		On x86 the private concept of a capability file was
		introduced to attempt to capture both a version and
		features a specific copy of GRUB might supply. This
		relied on being able to see all the capability files
		of available BEs. It also required manual updates of
		the file.

   2.2 Proposed Solution

	2.2.1) Mechanism

		A version string is embedded into the installed boot block
		when it is installed. That string can then be parsed and
		compared against a potentially newer string on subsequent
		installs.

	2.2.2) Implementation details

		The string is supplied by the packaging information and is
		ultimately a consolidation private bit of information that
		is generated in the same place that the tools to parse and
		compare it are built.

		For the sake of the current bits this will be the package
		fmri which will gain minor and micro version numbers
		to allow some manual control in addition to the release
		and build numbers as well as time-stamps.

		However the SVR4 package version could have been used
		just as well, and the tool could explicitly handle a
		transition to a new type of string if the need were to
		arise.

		For the sake of this case package fmris are treated
		as external and may evolve.

		However at the moment an fmri might look like this:

  pkg://opensolaris.org/system/boot/grub@0.97.123.456,5.11-0.136:20100316T170914Z

		In this example each of the following are tested to
		be greater, equal or lower. A result of greater (newer) will
		force an install (update). A result of equal will move on to
		the next check (or in the final case result in no install).
		A result of lower will block an install.

		0.97	external version
		123	minor version (Solaris specific features)
		456	micro version (Solaris specific changes/fixes)
		5	major OS version
		11	minor OS version
		0	release number
		136	build number
		20100316T170914Z	time stamp

		The publisher is ignored when computing newerness, but
		is written to the installed boot block.

		Lack of an embedded version (or complete lack of a booter)
		is treated as an event worthy of getting the booter onto
		a more supportable train and loader is installed and the
		version string is written. This covers situations such
		as a developer modification (bfu, manual installboot
		invocation) of one BE followed by falling back to another
		and then updating from there.

		The version string is validated to be parsable and comparable
		and the entire operation returns failure if the string
		can not be worked with. This is done to avoid creating
		a situation where installed bits can not be updated from.

3) Consolidation Private Interfaces

	This interface is being developed for libbe which is bound for
	the OS/Net consolidation, so the commitment level is consolidation
	private.

	Both installboot and installgrub gain a -u option that
	takes the version string.

	3.1) installboot

		installboot [-F fstype] [-u<version>] bootblk raw-device

	3.2) installgrub

		installgrub [-fm] [-u<version>] stage1 stage2 raw-device

	Both check the version against a version supplied by a previously
	installed boot block and will only update the boot block if the
	install is deemed to be an upgrade.

	Lack of an embedded version (or complete lack of a booter) will
	result in an install.



