Moved ESP mount and boot artifact paths to /efi.
Audit / Package Resolution (push) Successful in 4s
CI / Linting (push) Failing after 3s

This commit is contained in:
2026-06-20 20:14:46 -04:00
parent 7cf6a2ba71
commit 9ee4df0166
4 changed files with 23 additions and 13 deletions
+2
View File
@@ -31,6 +31,8 @@ CONFIG_SRC_DIR="${SCRIPT_DIR}/files/etc"
HOME_SKEL_DIR="${SCRIPT_DIR}/files/home-skel" HOME_SKEL_DIR="${SCRIPT_DIR}/files/home-skel"
HOME_SKEL_DESKTOP_DIR="${SCRIPT_DIR}/files/home-skel-desktop" HOME_SKEL_DESKTOP_DIR="${SCRIPT_DIR}/files/home-skel-desktop"
MOUNT_POINT="/mnt" MOUNT_POINT="/mnt"
EFI_MOUNT_POINT="/efi"
EFI_MOUNT_OPTIONS="nodev,nosuid,noexec,nosymfollow,fmask=0077,dmask=0077"
# Base packages to install with pacstrap # Base packages to install with pacstrap
BASE_PACKAGES=( BASE_PACKAGES=(
+4 -2
View File
@@ -21,7 +21,7 @@
# - Supports ext4, BTRFS, BTRFS with DUP, and BTRFS RAID1 # - Supports ext4, BTRFS, BTRFS with DUP, and BTRFS RAID1
# - Uses xxhash checksum for BTRFS filesystems # - Uses xxhash checksum for BTRFS filesystems
# - Mounts root with noatime and appropriate discard options # - Mounts root with noatime and appropriate discard options
# - Mounts EFI partition at /boot with restrictive permissions # - Mounts EFI partition at /efi with restrictive permissions
# Format a partition as FAT32 (for EFI) # Format a partition as FAT32 (for EFI)
# Arguments: # Arguments:
@@ -154,8 +154,10 @@ mount_root_filesystem() {
# $1 - EFI partition path # $1 - EFI partition path
mount_efi_partition() { mount_efi_partition() {
local efi_partition="$1" local efi_partition="$1"
local efi_mount_target="${MOUNT_POINT}${EFI_MOUNT_POINT}"
run_visible_cmd mount --mkdir -o "fmask=0077,dmask=0077" "$efi_partition" "${MOUNT_POINT}/boot" run_visible_cmd install -d -m 0700 "$efi_mount_target"
run_visible_cmd mount -o "$EFI_MOUNT_OPTIONS" "$efi_partition" "$efi_mount_target"
} }
# Format and mount all filesystems # Format and mount all filesystems
+4 -3
View File
@@ -25,17 +25,18 @@
# Install systemd-boot bootloader # Install systemd-boot bootloader
install_bootloader() { install_bootloader() {
print "Installing bootloader..." print "Installing bootloader..."
run_visible_cmd_in_chroot bootctl --esp-path=/boot install run_visible_cmd_in_chroot bootctl --esp-path="$EFI_MOUNT_POINT" install
} }
# Configure loader.conf # Configure loader.conf
configure_loader() { configure_loader() {
run_cmd_in_chroot sh -c 'cat > /boot/loader/loader.conf <<'"'"'EOF'"'"' run_cmd_in_chroot install -d -m 0755 "${EFI_MOUNT_POINT}/loader"
run_cmd_in_chroot sh -c "cat > ${EFI_MOUNT_POINT}/loader/loader.conf" <<'EOF'
timeout menu-hidden timeout menu-hidden
#console-mode keep #console-mode keep
editor no editor no
EOF' EOF
} }
# Full bootloader setup # Full bootloader setup
+13 -8
View File
@@ -18,12 +18,14 @@
# #
# Builds a UKI-only boot path: # Builds a UKI-only boot path:
# - Creates file-backed sbctl keys in the target system # - Creates file-backed sbctl keys in the target system
# - Configures mkinitcpio/ukify to emit a UKI # - Configures mkinitcpio/ukify to emit a UKI on the ESP
# - Signs and tracks the UKI with sbctl # - Signs and tracks the UKI with sbctl
# - Signs other EFI binaries that systemd-boot/fwupd need # - Signs other EFI binaries that systemd-boot/fwupd need
# - Leaves firmware key enrollment to the user # - Leaves firmware key enrollment to the user
readonly UKI_OUTPUT_PATH="/boot/EFI/Linux/arch-linux.efi" readonly UKI_OUTPUT_PATH="${EFI_MOUNT_POINT}/EFI/Linux/arch-linux.efi"
readonly ESP_SYSTEMD_BOOT_PATH="${EFI_MOUNT_POINT}/EFI/systemd/systemd-bootx64.efi"
readonly ESP_FALLBACK_BOOT_PATH="${EFI_MOUNT_POINT}/EFI/BOOT/BOOTX64.EFI"
readonly CMDLINE_DIR="/etc/cmdline.d" readonly CMDLINE_DIR="/etc/cmdline.d"
readonly SECURITY_CMDLINE="lockdown=confidentiality intel_iommu=on amd_iommu=on iommu=force iommu.passthrough=0" readonly SECURITY_CMDLINE="lockdown=confidentiality intel_iommu=on amd_iommu=on iommu=force iommu.passthrough=0"
@@ -166,18 +168,21 @@ verify_signed_artifacts_in_chroot() {
for artifact_path in "$@"; do for artifact_path in "$@"; do
run_cmd_in_chroot sh -c ' run_cmd_in_chroot sh -c '
verify_output="$(env SYSTEMD_ESP_PATH=/boot sbctl verify "$1")" || { esp_path="$1"
artifact_path="$2"
verify_output="$(env SYSTEMD_ESP_PATH="$esp_path" sbctl verify "$artifact_path")" || {
printf "%s\n" "$verify_output" >&2 printf "%s\n" "$verify_output" >&2
exit 1 exit 1
} }
printf "%s\n" "$verify_output" printf "%s\n" "$verify_output"
if ! printf "%s\n" "$verify_output" | grep -F -- "$1" | grep -Fq "is signed"; then if ! printf "%s\n" "$verify_output" | grep -F -- "$artifact_path" | grep -Fq "is signed"; then
printf "Expected signed Secure Boot artifact was not reported as signed: %s\n" "$1" >&2 printf "Expected signed Secure Boot artifact was not reported as signed: %s\n" "$artifact_path" >&2
exit 1 exit 1
fi fi
' sh "$artifact_path" ' sh "$EFI_MOUNT_POINT" "$artifact_path"
done done
} }
@@ -188,8 +193,8 @@ verify_secure_boot_artifacts() {
verify_signed_artifacts_in_chroot \ verify_signed_artifacts_in_chroot \
"$UKI_OUTPUT_PATH" \ "$UKI_OUTPUT_PATH" \
/usr/lib/systemd/boot/efi/systemd-bootx64.efi.signed \ /usr/lib/systemd/boot/efi/systemd-bootx64.efi.signed \
/boot/EFI/systemd/systemd-bootx64.efi \ "$ESP_SYSTEMD_BOOT_PATH" \
/boot/EFI/BOOT/BOOTX64.EFI "$ESP_FALLBACK_BOOT_PATH"
if [ -f "${MOUNT_POINT}/usr/lib/fwupd/efi/fwupdx64.efi.signed" ]; then if [ -f "${MOUNT_POINT}/usr/lib/fwupd/efi/fwupdx64.efi.signed" ]; then
verify_signed_artifacts_in_chroot /usr/lib/fwupd/efi/fwupdx64.efi.signed verify_signed_artifacts_in_chroot /usr/lib/fwupd/efi/fwupdx64.efi.signed