BOOSTER(1) General Commands Manual BOOSTER(1) (NAME) booster - initramfs (DESCRIPTION) Booster initramfs . Booster . Booster: o (). o LUKS. o Clevis. TPM2 . TPM2 . o systemd-cryptenroll ( fido2 tpm2). o . o . . (CONFIG FILE) booster /etc/booster.yaml . : network: interfaces: enp0s31f2,2e:1d:61:30:a3:63 dhcp: on # either dhcp above or static configuration below can be used ip: 10.0.2.15/24 gateway: 10.0.2.255 dns_servers: 192.168.1.1,8.8.8.8 ssh_host_key: /etc/booster/ssh_host_ed25519_key ssh_authorized_keys: /etc/booster/authorized_keys ssh_listen: :22 universal: false modules: -*,hid_apple,kernel/sound/usb/,kernel/fs/btrfs/btrfs.ko,kernel/lib/crc4.ko.xz compression: zstd mount_timeout: 5m6s strip: true extra_files: vim,/usr/share/vim/vim82/,fsck,fsck.ext4 vconsole: true enable_lvm: true enable_mdraid: true token_timeout: 30s pin_delay: 5s serialize_tokens: enabled: true clevis_timeout: 45s o network . (mount) ( Tang). DHCPv4 . dhcp on . : ip - IP gateway - dns_servers - DNS. network interfaces - ( MAC) . enp0s31f6 MAC init . interfaces . network ssh_host_key ssh_authorized_keys ssh_listen LUKS SSH . ssh_host_key SSH OpenSSH PEM ssh_authorized_keys authorized_keys ssh_listen ( :22). ssh_host_key ssh_authorized_keys SSH dhcp: true ip . (REMOTE UNLOCK) . o universal booster () . booster . TPM2 tpm . . o modules . (/usr/lib/modules/$KERNEL_VERSION) . ( ".xz" ".gz") . (-) " " . (/) . * () . . Booster . o modules_force_load . modules . o append_all_modaliases booster booster . (timeout) . true . o compression initramfs . "zstd" "gzip" "xz" "lz4" "none". "zstd" . o mount_timeout . . "s" () "m" () "h" (). ( ) . "0s" . o strip ( strip ) ELF . ELF strip . . booster: finit(crc32,generic): key was rejected by service strip false . o extra_files . ("/") /usr/bin . . : o busybox (panic) . o fsck . fsck.$rootfstype . . o vconsole . true booster /etc/vconsole.conf /etc/locale.conf (keymap) . : KEYMAP KEYMAP_TOGGLE FONT FONT_MAP FONT_UNIMAP. vconsole.conf https://man.archlinux.org/man/vconsole.conf.5.en . o enable_lvm LVM . . o enable_mdraid MdRaid . . o enable_zfs ZFS . . ZFS root= zfs= . o crypttab_path crypttab . /etc/crypttab . --crypttab . . o enable_plymouth (boot splash) (Plymouth) . booster Plymouth initramfs . (GPU) modules_force_load . quiet splash . booster.log=console Plymouth Plymouth (details - ) . o enable_fido2 FIDO2 . o serialize_tokens booster LUKS ( ). ( TPM2 PCR FIDO2 clevis) PIN PIN . booster . PIN ( Enter ). : o serialize_tokens.enabled -- false. o serialize_tokens.clevis_timeout / serialize_tokens.tpm2_timeout / serialize_tokens.fido2_timeout -- clevis systemd-tpm2 PIN systemd-fido2 PIN. Go. 45s / 15s / 30s. serialize_tokens.enabled . o token_timeout ( ) booster . ( LUKS (LUKS unlock concurrency and prompt order) ). token-timeout= crypttab/rd.luks.options booster ( rd.luks.options (BOOT TIME KERNEL PARAMETERS) ). Go. : 1. token-timeout= -- (rd.luks.options) crypttab . 2. token_timeout. 3. (serialize) ( ). 4. 30s. token_timeout : . o pin_delay serialize_tokens : PIN ( TPM2-PIN FIDO2-PIN) -- ( ). Go () . PIN ( PIN ) . -- TPM2/FIDO2 clevis /DHCP -- token_timeout . TPM2 PCR clevis . booster /boot /usr/lib/booster/regenerate_images . booster . (COMMAND-LINE FLAGS) (Application Options) o -v, --verbose (SUBCOMMANDS) (build) initrd. : booster [OPTIONS] build [build-OPTIONS] output o -f, --force initrd . o --init-binary <: /usr/lib/booster/init> 'init' Booster. o --compression <: zstd> . : zstd gzip xz lz4 none. o --kernel-version initramfs. o --config <: /etc/booster.yaml> . o --universal / . o --strip ELF ( ) . o --crypttab <: /etc/crypttab> crypttab . crypttab_path . booster /etc/crypttab . . (cat) . : booster [OPTIONS] cat image file-in-image (ls) . : booster [OPTIONS] ls image (unpack) . : booster [OPTIONS] unpack image output-dir (BOOT TIME KERNEL PARAMETERS) booster . (bootloader) . Booster : o root=$deviceref (root). " (Device Reference)" (NOTES) " (ROOT PARTITION DISCOVERY)" LUKS booster . o rootfstype=$TYPE ( rootfstype=ext4). booster . . . o rootflags=$OPTIONS (mount) rootflags=user_xattr,nobarrier. GPT ( "") . o rd.luks.uuid=$UUID (UUID) LUKS . booster LUKS . o rd.luks.name=$UUID=$NAME rd.luks.uuid LUKS . o rd.luks.key=$UUID=$PATH (keyfile) initrd/initramfs UUID . o rd.luks.header=$UUID=$PATH (header) LUKS $UUID . $PATH : o Initramfs -- ( /etc/luks/root.hdr) extra_files initramfs . o (Raw block device) -- ( /dev/sdb) LUKS . Booster cryptsetup . o -- $path:$deviceref $deviceref UUID=... LABEL=... PARTUUID=... PARTLABEL=... . Booster (unmount) . o rd.luks.options=opt1,opt2 LUKS. discard same-cpu-crypt submit-from-crypt-cpus no-read-workqueue no-write-workqueue. token-timeout= (FIDO2 TPM2) . (s m h) . (30 s) . booster LUKS v2 . . o rd.modules_force_load . o resume=$deviceref (suspend-to-disk / ). o zfs=$pool/$dataset ZFS . ZFS . ZFS root= . o booster.log init booster. : ( ) - debug info warning error null. null . info . console - init . (debug) kmsg dmesg journalctl -b . debug kmsg . o booster.debug booster.log=debug,console . o quiet init . booster.debug booster.log . o init=$PATH init . /sbin/init . (ROOT PARTITION DISCOVERY) Booster (kernel cmdline) LUKS . . (Unencrypted root) root=UUID= PARTUUID= LABEL= /dev/... . (LUKS) (Encrypted (LUKS) root) . . cmdline. rd.luks.name== root=/dev/mapper/ rd.luks.name rd.luks.uuid " (BOOT TIME KERNEL PARAMETERS)" . /etc/crypttab. x-initrd.attach (mapper name) . root=/dev/mapper/ cmdline . (CRYPTTAB) . (Auto-named). rd.luks.* crypttab root= LUKS : root=UUID= Booster /dev/mapper/root . PARTUUID= LABEL= /dev/... . (Zero kernel parameters). GUID booster root= . " GPT" . GPT ( cmdline) (GPT autodiscovery (no cmdline at all)) GPT ( gdisk sgdisk fdisk cfdisk parted ...) "Linux root" . x86-64 gdisk 8304 . . GUID (Discoverable Partitions Specification) https://uapi-group.org/specifications/specs/discoverable_partitions_specification/ . GUID LUKS -- booster . Booster EFI (ESP) . . (When boot stalls) root=/dev/mapper/ booster : root=/dev/mapper/ but no LUKS unlock spec was found for "" . . (CRYPTTAB) Booster LUKS /etc/crypttab ( crypttab(5) https://man7.org/linux/man-pages/man5/crypttab.5.html ). x-initrd.attach initramfs . -- (root) --crypttab . rd.luks.* crypttab ( keyfile header tries token-timeout ) crypttab . crypttab rd.luks.* . Booster : o keyfile /path:UUID=xxx ( LABEL= PARTUUID= PARTLABEL=) -- . Booster . initramfs . o header= -- initramfs . /path:deviceref /dev/... . o fido2-device= -- crypttab fido2plugin.so enable_fido2: true . fido2-device= tpm2-device= booster LUKS2 crypttab. o keyfile-timeout= / token-timeout= -- ( ) time.ParseDuration Go ( 30s 2m) . (REMOTE UNLOCK) Booster LUKS SSH . SSH ( DHCP ip ) LUKS . LUKS . dropbear-initramfs booster -- dropbear golang.org/x/crypto/ssh Go . ( ): $ ssh-keygen -t ed25519 -f /etc/booster/ssh_host_ed25519_key -N '' authorized_keys : ssh-ed25519 AAAAC3Nz...user1@laptop ssh-ed25519 AAAAC3Nz...user2@phone /etc/booster.yaml: network: dhcp: on ssh_host_key: /etc/booster/ssh_host_ed25519_key ssh_authorized_keys: /etc/booster/authorized_keys ssh_listen: :22 ssh_host_key ssh_authorized_keys initramfs . SSH network.dhcp: true network.ip . root : $ ssh -p 22 root@ : o (Pubkey) . SSH ( slow-loris). o authorized_keys initramfs . /boot ( ) . /boot . o (fingerprint) ( ) known_hosts . o SSH authorized_keys LUKS . . (brute force) -- SSH LUKS . o ssh_listen: :22 IPv4 IPv6 -- - IPv6 (fe80::...) DHCP . ssh_listen ( 10.0.0.5:22) . o -- PAM PTY. (Device Reference) . $deviceref . : o /dev/XXX / /dev/sda1 /dev/nvme0n1 dm-mapper /dev/mapper/root /dev/vg_mesos/lv_mesos_containers . o UUID=$UUID /dev/disk/by-uuid/$UUID UUID /LUKS . UUID . o LABEL=$LABEL /dev/disk/by-label/$LABEL /LUKS . o PARTUUID=$UUID /dev/disk/by-partuuid/$UUID UUID GPT . o PARTUUID=$UUID/PARTNROFF=$OFFSET $OFFSET GPT $UUID PARTUUID=fd59d06d-ffa8-473b-94f0-6584cb2b6665/PARTNROFF=2. o PARTLABEL=$LABEL /dev/disk/by-partlabel/$LABEL GPT . o HWPATH=$PATH /dev/disk/by-path/$PATH pci-0000:02:00.0-nvme-1-part2. o WWID=$ID /dev/disk/by-id/$ID wwid nvme-KXG6AZNV256G_TOSHIBA_40SA13GZF6B1-part3 UUID (UUID parameters) root=UUID=$UUID rd.luks.uuid=$UUID UUID . UUID xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx x . UUID " . : root=UUID=ac8299a8-91ce-4bf6-a524-55a62844b787 root=UUID="ac8299a8-91ce-4bf6-a524-55a62844b787" ( ) rd.luks.uuid=ac8299a8-91ce-4bf6-a524-55a62844b787 rd.luks.uuid="ac8299a8-91ce-4bf6-a524-55a62844b787" ( ). (Password entry) : o Ctrl+W -- . o Ctrl+U -- . o Tab -- ( <-> ). LUKS (LUKS unlock concurrency and prompt order) Booster LUKS -- . --- (cancel-on-win) . PIN-token serialization. (TPM2-PIN FIDO2-PIN) LUKS2 -- . ( TPM2 PCR FIDO2 ) . cryptsetup luksDump . FIDO2 credential pre-flight. FIDO2 LUKS ( ) . CTAP2 up=false hidraw FIDO2 -- FIDO2 ( ) . fido2-uv-required=true ( CTAP 2.1
7.4) . Cancel-on-win. -- FIDO2-PIN TPM2-PIN -- ( ) . Plymouth . Plymouth Plymouth MR !393 Plymouth . PIN attempt caps. ( Enter) . (Modules selection) booster . booster defaultModulesList - generator.go. - tpm usb. universal false ( ) (host mode) . booster /sys/module/ defaultModulesList . booster modules . . . - . / . hid-apple.ko.gz hid_apple . /usr/lib/modules/$KERNEL_VERSION / . . / /usr/lib/modules/$KERNEL_VERSION . Booster / . . * << >> . booster modules_force_load . . booster . ext4 ext mbcache jbd2 mbcache jbd2 . (Unified Kernel Image) https://uapi-group.org/specifications/specs/unified_kernel_image/ ( UKI) PE ( initrd UEFI) . (UEFI) (Secure Boot) . UKI Booster UKI systemd systemd-ukify /usr/lib/booster/regenerate_uki . booster UKI systemd ( ukify) . initrd os-release . UKI /etc/booster.yaml . UKI () . (DEBUGGING) booster . booster.log=debug,console booster . TFTP (Use TFTP to download logs for unbootable device) busybox . tftp ( ) / pacman -S atftp; systemctl start atftpd. /etc/booster.yaml network support busybox (extra_files: busybox) . initramfs . busybox tftp : $ dmesg >boot.log $ lsmod >mods.log $ tftp -pl boot.log $ tftp -pl mods.log /srv/atftp . (Boot timeout) booster: Timeout waiting for root filesystem append_all_modaliases . booster . . (EXAMPLES) initramfs / . booster.img : $ booster build booster.img ( SATA/TPM/NVME/...): $ booster build --universal booster.img initramfs 5.4.91-1-lts /boot/booster-lts.img: $ booster build --kernel-version 5.4.91-1-lts /boot/booster-lts.img systemd-boot /boot/loader/entries/booster.conf . e122d09e-87a9-4b35-83f7-2592ef40cefa UUID LUKS 08684949-bcbb-47bb-1c17-089aaa59e17e UUID ( ext4) . . title Linux with Booster linux /vmlinuz-linux initrd /booster-linux.img options rd.luks.uuid=e122d09e-87a9-4b35-83f7-2592ef40cefa root=UUID=08684949-bcbb-47bb-1c17-089aaa59e17e rw FIDO2 LUKS systemd-cryptenroll : $ systemd-cryptenroll --fido2-device=auto /dev/sda2 /etc/crypttab . Booster (mapper) fido2-device= fido2plugin.so . token-timeout= booster FIDO2 ( 0 ): cryptroot UUID=e122d09e-87a9-4b35-83f7-2592ef40cefa none fido2-device=auto,token-timeout=60s,x-initrd.attach root= : title Linux with Booster linux /vmlinuz-linux initrd /booster-linux.img options root=/dev/mapper/cryptroot rw root= GPT. GUID -- x86-64 4f68bce3-e8cd-4db1-96e7-fbcaf984b709 : $ sgdisk --typecode=2:4f68bce3-e8cd-4db1-96e7-fbcaf984b709 /dev/sda LUKS /etc/crypttab ( booster /dev/mapper/root ): cryptroot UUID=e122d09e-87a9-4b35-83f7-2592ef40cefa none x-initrd.attach : title Linux with Booster linux /vmlinuz-linux initrd /booster-linux.img options rw Btrfs rootflags /etc/fstab . 69bc4dd2-7f6c-4821-aa6b-d80d9c97d470 UUID Btrfs root /etc/fstab : UUID=69bc4dd2-7f6c-4821-aa6b-d80d9c97d470 / btrfs rw,relatime,autodefrag,compress=zstd:2,space_cache,subvol=root 0 0 /boot/loader/entries/booster.conf : title Linux with Booster linux /vmlinuz-linux initrd /booster-linux.img options root=UUID=69bc4dd2-7f6c-4821-aa6b-d80d9c97d470 rw rootflags=relatime,autodefrag,compress=zstd:2,space_cache,subvol=root Booster Btrfs . subvol= ( subvolid=) -- btrfs subvolume set-default -- ( ) . @ ( ) root ( ) @/.snapshots/N/snapshot ( openSUSE) subvol=NAME subvolid=ID . /boot/EFI/Linux: $ /usr/lib/booster/regenerate_uki build /boot/EFI/Linux (COPYRIGHT) Booster Anatol Pomazau (C) 2020 http://github.com/anatol (SEE ALSO) https://github.com/anatol/booster June 2026 BOOSTER(1)