fix: resolve grub-pc / grub-efi-amd64 "held broken packages" conflict
The edition package lists installed BOTH grub-pc and grub-efi-amd64 (+ shim-signed). Those provide the same bootloader role and conflict in apt, so every rootfs build failed with "unable to correct problems, you have held broken packages". A rootfs now carries exactly ONE bootloader, chosen by the BOOT variable (mirroring the existing --boot bios|efi deploy option): - versions.mk / common.sh: BOOT := bios (bios -> grub-pc, efi -> grub-efi-amd64 + shim-signed + mokutil), exported via the Makefile. - build-rootfs.sh validates BOOT early and injects the matching boot packages into the apt install; the static package lists no longer contain any grub package. - deploy-disk.sh / build-image.sh / install.sh default --boot from the same BOOT variable, so a rootfs and the artifact deployed from it can never disagree (BOOT=efi make image-cloud produces a UEFI image). - mokutil is now installed explicitly in the efi flavour (it was not pulled in because we install with --no-install-recommends). - docs updated (building.md knob + rationale, secureboot.md note).
This commit is contained in:
@@ -53,9 +53,10 @@ against your MOK.
|
||||
|
||||
## Notes
|
||||
|
||||
- Requires `sbsigntool` on the build host and `mokutil` in the image
|
||||
(`mokutil` is pulled in by the `shim-signed` package already in the package
|
||||
lists).
|
||||
- Requires `sbsigntool` on the build host. `mokutil` (for enrollment) is
|
||||
installed in the image as part of the EFI boot flavour:
|
||||
`BOOT=efi make iso-server` (the `efi` flavour adds `grub-efi-amd64
|
||||
shim-signed mokutil`).
|
||||
- Losing `MOK.priv` means you cannot sign future updates — back it up.
|
||||
- Full vendor CA / Microsoft KEK signing is intentionally not used; revisit
|
||||
only if a commercial distribution is ever pursued.
|
||||
|
||||
Reference in New Issue
Block a user