Moved ESP mount and boot artifact paths to /efi.
Audit / Package Resolution (push) Successful in 4s
CI / Linting (push) Failing after 3s

This commit is contained in:
2026-06-20 20:14:46 -04:00
parent 7cf6a2ba71
commit 9ee4df0166
4 changed files with 23 additions and 13 deletions
+2
View File
@@ -31,6 +31,8 @@ CONFIG_SRC_DIR="${SCRIPT_DIR}/files/etc"
HOME_SKEL_DIR="${SCRIPT_DIR}/files/home-skel"
HOME_SKEL_DESKTOP_DIR="${SCRIPT_DIR}/files/home-skel-desktop"
MOUNT_POINT="/mnt"
EFI_MOUNT_POINT="/efi"
EFI_MOUNT_OPTIONS="nodev,nosuid,noexec,nosymfollow,fmask=0077,dmask=0077"
# Base packages to install with pacstrap
BASE_PACKAGES=(
+4 -2
View File
@@ -21,7 +21,7 @@
# - Supports ext4, BTRFS, BTRFS with DUP, and BTRFS RAID1
# - Uses xxhash checksum for BTRFS filesystems
# - Mounts root with noatime and appropriate discard options
# - Mounts EFI partition at /boot with restrictive permissions
# - Mounts EFI partition at /efi with restrictive permissions
# Format a partition as FAT32 (for EFI)
# Arguments:
@@ -154,8 +154,10 @@ mount_root_filesystem() {
# $1 - EFI partition path
mount_efi_partition() {
local efi_partition="$1"
local efi_mount_target="${MOUNT_POINT}${EFI_MOUNT_POINT}"
run_visible_cmd mount --mkdir -o "fmask=0077,dmask=0077" "$efi_partition" "${MOUNT_POINT}/boot"
run_visible_cmd install -d -m 0700 "$efi_mount_target"
run_visible_cmd mount -o "$EFI_MOUNT_OPTIONS" "$efi_partition" "$efi_mount_target"
}
# Format and mount all filesystems
+4 -3
View File
@@ -25,17 +25,18 @@
# Install systemd-boot bootloader
install_bootloader() {
print "Installing bootloader..."
run_visible_cmd_in_chroot bootctl --esp-path=/boot install
run_visible_cmd_in_chroot bootctl --esp-path="$EFI_MOUNT_POINT" install
}
# Configure loader.conf
configure_loader() {
run_cmd_in_chroot sh -c 'cat > /boot/loader/loader.conf <<'"'"'EOF'"'"'
run_cmd_in_chroot install -d -m 0755 "${EFI_MOUNT_POINT}/loader"
run_cmd_in_chroot sh -c "cat > ${EFI_MOUNT_POINT}/loader/loader.conf" <<'EOF'
timeout menu-hidden
#console-mode keep
editor no
EOF'
EOF
}
# Full bootloader setup
+13 -8
View File
@@ -18,12 +18,14 @@
#
# Builds a UKI-only boot path:
# - Creates file-backed sbctl keys in the target system
# - Configures mkinitcpio/ukify to emit a UKI
# - Configures mkinitcpio/ukify to emit a UKI on the ESP
# - Signs and tracks the UKI with sbctl
# - Signs other EFI binaries that systemd-boot/fwupd need
# - Leaves firmware key enrollment to the user
readonly UKI_OUTPUT_PATH="/boot/EFI/Linux/arch-linux.efi"
readonly UKI_OUTPUT_PATH="${EFI_MOUNT_POINT}/EFI/Linux/arch-linux.efi"
readonly ESP_SYSTEMD_BOOT_PATH="${EFI_MOUNT_POINT}/EFI/systemd/systemd-bootx64.efi"
readonly ESP_FALLBACK_BOOT_PATH="${EFI_MOUNT_POINT}/EFI/BOOT/BOOTX64.EFI"
readonly CMDLINE_DIR="/etc/cmdline.d"
readonly SECURITY_CMDLINE="lockdown=confidentiality intel_iommu=on amd_iommu=on iommu=force iommu.passthrough=0"
@@ -166,18 +168,21 @@ verify_signed_artifacts_in_chroot() {
for artifact_path in "$@"; do
run_cmd_in_chroot sh -c '
verify_output="$(env SYSTEMD_ESP_PATH=/boot sbctl verify "$1")" || {
esp_path="$1"
artifact_path="$2"
verify_output="$(env SYSTEMD_ESP_PATH="$esp_path" sbctl verify "$artifact_path")" || {
printf "%s\n" "$verify_output" >&2
exit 1
}
printf "%s\n" "$verify_output"
if ! printf "%s\n" "$verify_output" | grep -F -- "$1" | grep -Fq "is signed"; then
printf "Expected signed Secure Boot artifact was not reported as signed: %s\n" "$1" >&2
if ! printf "%s\n" "$verify_output" | grep -F -- "$artifact_path" | grep -Fq "is signed"; then
printf "Expected signed Secure Boot artifact was not reported as signed: %s\n" "$artifact_path" >&2
exit 1
fi
' sh "$artifact_path"
' sh "$EFI_MOUNT_POINT" "$artifact_path"
done
}
@@ -188,8 +193,8 @@ verify_secure_boot_artifacts() {
verify_signed_artifacts_in_chroot \
"$UKI_OUTPUT_PATH" \
/usr/lib/systemd/boot/efi/systemd-bootx64.efi.signed \
/boot/EFI/systemd/systemd-bootx64.efi \
/boot/EFI/BOOT/BOOTX64.EFI
"$ESP_SYSTEMD_BOOT_PATH" \
"$ESP_FALLBACK_BOOT_PATH"
if [ -f "${MOUNT_POINT}/usr/lib/fwupd/efi/fwupdx64.efi.signed" ]; then
verify_signed_artifacts_in_chroot /usr/lib/fwupd/efi/fwupdx64.efi.signed