Moved ESP mount and boot artifact paths to /efi.
This commit is contained in:
@@ -31,6 +31,8 @@ CONFIG_SRC_DIR="${SCRIPT_DIR}/files/etc"
|
|||||||
HOME_SKEL_DIR="${SCRIPT_DIR}/files/home-skel"
|
HOME_SKEL_DIR="${SCRIPT_DIR}/files/home-skel"
|
||||||
HOME_SKEL_DESKTOP_DIR="${SCRIPT_DIR}/files/home-skel-desktop"
|
HOME_SKEL_DESKTOP_DIR="${SCRIPT_DIR}/files/home-skel-desktop"
|
||||||
MOUNT_POINT="/mnt"
|
MOUNT_POINT="/mnt"
|
||||||
|
EFI_MOUNT_POINT="/efi"
|
||||||
|
EFI_MOUNT_OPTIONS="nodev,nosuid,noexec,nosymfollow,fmask=0077,dmask=0077"
|
||||||
|
|
||||||
# Base packages to install with pacstrap
|
# Base packages to install with pacstrap
|
||||||
BASE_PACKAGES=(
|
BASE_PACKAGES=(
|
||||||
|
|||||||
@@ -21,7 +21,7 @@
|
|||||||
# - Supports ext4, BTRFS, BTRFS with DUP, and BTRFS RAID1
|
# - Supports ext4, BTRFS, BTRFS with DUP, and BTRFS RAID1
|
||||||
# - Uses xxhash checksum for BTRFS filesystems
|
# - Uses xxhash checksum for BTRFS filesystems
|
||||||
# - Mounts root with noatime and appropriate discard options
|
# - Mounts root with noatime and appropriate discard options
|
||||||
# - Mounts EFI partition at /boot with restrictive permissions
|
# - Mounts EFI partition at /efi with restrictive permissions
|
||||||
|
|
||||||
# Format a partition as FAT32 (for EFI)
|
# Format a partition as FAT32 (for EFI)
|
||||||
# Arguments:
|
# Arguments:
|
||||||
@@ -154,8 +154,10 @@ mount_root_filesystem() {
|
|||||||
# $1 - EFI partition path
|
# $1 - EFI partition path
|
||||||
mount_efi_partition() {
|
mount_efi_partition() {
|
||||||
local efi_partition="$1"
|
local efi_partition="$1"
|
||||||
|
local efi_mount_target="${MOUNT_POINT}${EFI_MOUNT_POINT}"
|
||||||
|
|
||||||
run_visible_cmd mount --mkdir -o "fmask=0077,dmask=0077" "$efi_partition" "${MOUNT_POINT}/boot"
|
run_visible_cmd install -d -m 0700 "$efi_mount_target"
|
||||||
|
run_visible_cmd mount -o "$EFI_MOUNT_OPTIONS" "$efi_partition" "$efi_mount_target"
|
||||||
}
|
}
|
||||||
|
|
||||||
# Format and mount all filesystems
|
# Format and mount all filesystems
|
||||||
|
|||||||
@@ -25,17 +25,18 @@
|
|||||||
# Install systemd-boot bootloader
|
# Install systemd-boot bootloader
|
||||||
install_bootloader() {
|
install_bootloader() {
|
||||||
print "Installing bootloader..."
|
print "Installing bootloader..."
|
||||||
run_visible_cmd_in_chroot bootctl --esp-path=/boot install
|
run_visible_cmd_in_chroot bootctl --esp-path="$EFI_MOUNT_POINT" install
|
||||||
}
|
}
|
||||||
|
|
||||||
# Configure loader.conf
|
# Configure loader.conf
|
||||||
configure_loader() {
|
configure_loader() {
|
||||||
run_cmd_in_chroot sh -c 'cat > /boot/loader/loader.conf <<'"'"'EOF'"'"'
|
run_cmd_in_chroot install -d -m 0755 "${EFI_MOUNT_POINT}/loader"
|
||||||
|
run_cmd_in_chroot sh -c "cat > ${EFI_MOUNT_POINT}/loader/loader.conf" <<'EOF'
|
||||||
timeout menu-hidden
|
timeout menu-hidden
|
||||||
#console-mode keep
|
#console-mode keep
|
||||||
|
|
||||||
editor no
|
editor no
|
||||||
EOF'
|
EOF
|
||||||
}
|
}
|
||||||
|
|
||||||
# Full bootloader setup
|
# Full bootloader setup
|
||||||
|
|||||||
@@ -18,12 +18,14 @@
|
|||||||
#
|
#
|
||||||
# Builds a UKI-only boot path:
|
# Builds a UKI-only boot path:
|
||||||
# - Creates file-backed sbctl keys in the target system
|
# - Creates file-backed sbctl keys in the target system
|
||||||
# - Configures mkinitcpio/ukify to emit a UKI
|
# - Configures mkinitcpio/ukify to emit a UKI on the ESP
|
||||||
# - Signs and tracks the UKI with sbctl
|
# - Signs and tracks the UKI with sbctl
|
||||||
# - Signs other EFI binaries that systemd-boot/fwupd need
|
# - Signs other EFI binaries that systemd-boot/fwupd need
|
||||||
# - Leaves firmware key enrollment to the user
|
# - Leaves firmware key enrollment to the user
|
||||||
|
|
||||||
readonly UKI_OUTPUT_PATH="/boot/EFI/Linux/arch-linux.efi"
|
readonly UKI_OUTPUT_PATH="${EFI_MOUNT_POINT}/EFI/Linux/arch-linux.efi"
|
||||||
|
readonly ESP_SYSTEMD_BOOT_PATH="${EFI_MOUNT_POINT}/EFI/systemd/systemd-bootx64.efi"
|
||||||
|
readonly ESP_FALLBACK_BOOT_PATH="${EFI_MOUNT_POINT}/EFI/BOOT/BOOTX64.EFI"
|
||||||
readonly CMDLINE_DIR="/etc/cmdline.d"
|
readonly CMDLINE_DIR="/etc/cmdline.d"
|
||||||
readonly SECURITY_CMDLINE="lockdown=confidentiality intel_iommu=on amd_iommu=on iommu=force iommu.passthrough=0"
|
readonly SECURITY_CMDLINE="lockdown=confidentiality intel_iommu=on amd_iommu=on iommu=force iommu.passthrough=0"
|
||||||
|
|
||||||
@@ -166,18 +168,21 @@ verify_signed_artifacts_in_chroot() {
|
|||||||
|
|
||||||
for artifact_path in "$@"; do
|
for artifact_path in "$@"; do
|
||||||
run_cmd_in_chroot sh -c '
|
run_cmd_in_chroot sh -c '
|
||||||
verify_output="$(env SYSTEMD_ESP_PATH=/boot sbctl verify "$1")" || {
|
esp_path="$1"
|
||||||
|
artifact_path="$2"
|
||||||
|
|
||||||
|
verify_output="$(env SYSTEMD_ESP_PATH="$esp_path" sbctl verify "$artifact_path")" || {
|
||||||
printf "%s\n" "$verify_output" >&2
|
printf "%s\n" "$verify_output" >&2
|
||||||
exit 1
|
exit 1
|
||||||
}
|
}
|
||||||
|
|
||||||
printf "%s\n" "$verify_output"
|
printf "%s\n" "$verify_output"
|
||||||
|
|
||||||
if ! printf "%s\n" "$verify_output" | grep -F -- "$1" | grep -Fq "is signed"; then
|
if ! printf "%s\n" "$verify_output" | grep -F -- "$artifact_path" | grep -Fq "is signed"; then
|
||||||
printf "Expected signed Secure Boot artifact was not reported as signed: %s\n" "$1" >&2
|
printf "Expected signed Secure Boot artifact was not reported as signed: %s\n" "$artifact_path" >&2
|
||||||
exit 1
|
exit 1
|
||||||
fi
|
fi
|
||||||
' sh "$artifact_path"
|
' sh "$EFI_MOUNT_POINT" "$artifact_path"
|
||||||
done
|
done
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -188,8 +193,8 @@ verify_secure_boot_artifacts() {
|
|||||||
verify_signed_artifacts_in_chroot \
|
verify_signed_artifacts_in_chroot \
|
||||||
"$UKI_OUTPUT_PATH" \
|
"$UKI_OUTPUT_PATH" \
|
||||||
/usr/lib/systemd/boot/efi/systemd-bootx64.efi.signed \
|
/usr/lib/systemd/boot/efi/systemd-bootx64.efi.signed \
|
||||||
/boot/EFI/systemd/systemd-bootx64.efi \
|
"$ESP_SYSTEMD_BOOT_PATH" \
|
||||||
/boot/EFI/BOOT/BOOTX64.EFI
|
"$ESP_FALLBACK_BOOT_PATH"
|
||||||
|
|
||||||
if [ -f "${MOUNT_POINT}/usr/lib/fwupd/efi/fwupdx64.efi.signed" ]; then
|
if [ -f "${MOUNT_POINT}/usr/lib/fwupd/efi/fwupdx64.efi.signed" ]; then
|
||||||
verify_signed_artifacts_in_chroot /usr/lib/fwupd/efi/fwupdx64.efi.signed
|
verify_signed_artifacts_in_chroot /usr/lib/fwupd/efi/fwupdx64.efi.signed
|
||||||
|
|||||||
Reference in New Issue
Block a user