Moved ESP mount and boot artifact paths to /efi.
Audit / Package Resolution (push) Successful in 4s
CI / Linting (push) Failing after 3s

This commit is contained in:
2026-06-20 20:14:46 -04:00
parent 7cf6a2ba71
commit 9ee4df0166
4 changed files with 23 additions and 13 deletions
+4 -3
View File
@@ -25,17 +25,18 @@
# Install systemd-boot bootloader
install_bootloader() {
print "Installing bootloader..."
run_visible_cmd_in_chroot bootctl --esp-path=/boot install
run_visible_cmd_in_chroot bootctl --esp-path="$EFI_MOUNT_POINT" install
}
# Configure loader.conf
configure_loader() {
run_cmd_in_chroot sh -c 'cat > /boot/loader/loader.conf <<'"'"'EOF'"'"'
run_cmd_in_chroot install -d -m 0755 "${EFI_MOUNT_POINT}/loader"
run_cmd_in_chroot sh -c "cat > ${EFI_MOUNT_POINT}/loader/loader.conf" <<'EOF'
timeout menu-hidden
#console-mode keep
editor no
EOF'
EOF
}
# Full bootloader setup
+13 -8
View File
@@ -18,12 +18,14 @@
#
# Builds a UKI-only boot path:
# - Creates file-backed sbctl keys in the target system
# - Configures mkinitcpio/ukify to emit a UKI
# - Configures mkinitcpio/ukify to emit a UKI on the ESP
# - Signs and tracks the UKI with sbctl
# - Signs other EFI binaries that systemd-boot/fwupd need
# - Leaves firmware key enrollment to the user
readonly UKI_OUTPUT_PATH="/boot/EFI/Linux/arch-linux.efi"
readonly UKI_OUTPUT_PATH="${EFI_MOUNT_POINT}/EFI/Linux/arch-linux.efi"
readonly ESP_SYSTEMD_BOOT_PATH="${EFI_MOUNT_POINT}/EFI/systemd/systemd-bootx64.efi"
readonly ESP_FALLBACK_BOOT_PATH="${EFI_MOUNT_POINT}/EFI/BOOT/BOOTX64.EFI"
readonly CMDLINE_DIR="/etc/cmdline.d"
readonly SECURITY_CMDLINE="lockdown=confidentiality intel_iommu=on amd_iommu=on iommu=force iommu.passthrough=0"
@@ -166,18 +168,21 @@ verify_signed_artifacts_in_chroot() {
for artifact_path in "$@"; do
run_cmd_in_chroot sh -c '
verify_output="$(env SYSTEMD_ESP_PATH=/boot sbctl verify "$1")" || {
esp_path="$1"
artifact_path="$2"
verify_output="$(env SYSTEMD_ESP_PATH="$esp_path" sbctl verify "$artifact_path")" || {
printf "%s\n" "$verify_output" >&2
exit 1
}
printf "%s\n" "$verify_output"
if ! printf "%s\n" "$verify_output" | grep -F -- "$1" | grep -Fq "is signed"; then
printf "Expected signed Secure Boot artifact was not reported as signed: %s\n" "$1" >&2
if ! printf "%s\n" "$verify_output" | grep -F -- "$artifact_path" | grep -Fq "is signed"; then
printf "Expected signed Secure Boot artifact was not reported as signed: %s\n" "$artifact_path" >&2
exit 1
fi
' sh "$artifact_path"
' sh "$EFI_MOUNT_POINT" "$artifact_path"
done
}
@@ -188,8 +193,8 @@ verify_secure_boot_artifacts() {
verify_signed_artifacts_in_chroot \
"$UKI_OUTPUT_PATH" \
/usr/lib/systemd/boot/efi/systemd-bootx64.efi.signed \
/boot/EFI/systemd/systemd-bootx64.efi \
/boot/EFI/BOOT/BOOTX64.EFI
"$ESP_SYSTEMD_BOOT_PATH" \
"$ESP_FALLBACK_BOOT_PATH"
if [ -f "${MOUNT_POINT}/usr/lib/fwupd/efi/fwupdx64.efi.signed" ]; then
verify_signed_artifacts_in_chroot /usr/lib/fwupd/efi/fwupdx64.efi.signed