fix: resolve grub-pc / grub-efi-amd64 "held broken packages" conflict

The edition package lists installed BOTH grub-pc and grub-efi-amd64
(+ shim-signed). Those provide the same bootloader role and conflict in
apt, so every rootfs build failed with "unable to correct problems, you
have held broken packages".

A rootfs now carries exactly ONE bootloader, chosen by the BOOT variable
(mirroring the existing --boot bios|efi deploy option):

- versions.mk / common.sh: BOOT := bios (bios -> grub-pc,
  efi -> grub-efi-amd64 + shim-signed + mokutil), exported via the
  Makefile.
- build-rootfs.sh validates BOOT early and injects the matching boot
  packages into the apt install; the static package lists no longer
  contain any grub package.
- deploy-disk.sh / build-image.sh / install.sh default --boot from the
  same BOOT variable, so a rootfs and the artifact deployed from it can
  never disagree (BOOT=efi make image-cloud produces a UEFI image).
- mokutil is now installed explicitly in the efi flavour (it was not
  pulled in because we install with --no-install-recommends).
- docs updated (building.md knob + rationale, secureboot.md note).
This commit is contained in:
Blake Ridgway
2026-08-21 14:15:10 -05:00
parent bb031ca92f
commit 0361c12c07
12 changed files with 47 additions and 19 deletions

View File

@@ -81,6 +81,13 @@ Set these as environment variables or edit `versions.mk`:
| `ARCLINE_EXTRA_REPOS` | fetch grafana/loki upstream repos | `0` |
| `ARCLINE_TOOLCHAIN` | toolchain in image builds | `auto` |
| `ARCLINE_SIGN` | sign boot chain with the MOK (secure boot) | `0` |
| `BOOT` | bootloader in the image: `bios` → grub-pc, `efi` → grub-efi-amd64 + shim-signed | `bios` |
> **Why one bootloader?** `grub-pc` and `grub-efi-amd64` conflict, so apt fails
> with *"held broken packages"* if both are in a package list. Arcline ships
> exactly the one matching `BOOT` (injected by `build-rootfs.sh`). For a UEFI +
> secure-boot build: `BOOT=efi make iso-server` (or `make image-cloud` with
> `BOOT=efi`). The deployed image/install uses the same variable by default.
## Building without the Arcline toolchain