fix: resolve grub-pc / grub-efi-amd64 "held broken packages" conflict

The edition package lists installed BOTH grub-pc and grub-efi-amd64
(+ shim-signed). Those provide the same bootloader role and conflict in
apt, so every rootfs build failed with "unable to correct problems, you
have held broken packages".

A rootfs now carries exactly ONE bootloader, chosen by the BOOT variable
(mirroring the existing --boot bios|efi deploy option):

- versions.mk / common.sh: BOOT := bios (bios -> grub-pc,
  efi -> grub-efi-amd64 + shim-signed + mokutil), exported via the
  Makefile.
- build-rootfs.sh validates BOOT early and injects the matching boot
  packages into the apt install; the static package lists no longer
  contain any grub package.
- deploy-disk.sh / build-image.sh / install.sh default --boot from the
  same BOOT variable, so a rootfs and the artifact deployed from it can
  never disagree (BOOT=efi make image-cloud produces a UEFI image).
- mokutil is now installed explicitly in the efi flavour (it was not
  pulled in because we install with --no-install-recommends).
- docs updated (building.md knob + rationale, secureboot.md note).
This commit is contained in:
Blake Ridgway
2026-08-21 14:15:10 -05:00
parent bb031ca92f
commit 0361c12c07
12 changed files with 47 additions and 19 deletions

View File

@@ -21,7 +21,7 @@ source "$(dirname "${BASH_SOURCE[0]}")/common.sh"
EDITION="${1:?usage: build-image.sh <edition> [--format qcow2|raw] [--size 4G] [--boot bios|efi]}"
FORMAT="qcow2"
SIZE="4G"
BOOT="bios"
BOOT="${BOOT:-bios}" # default from the BOOT build variable (see versions.mk)
shift || true
while [[ $# -gt 0 ]]; do

View File

@@ -29,6 +29,14 @@ case "$ARCLINE_TOOLCHAIN" in
*) die "ARCLINE_TOOLCHAIN must be auto|skip|require (got '$ARCLINE_TOOLCHAIN')" ;;
esac
# Fail fast on a bad boot flavour. grub-pc and grub-efi-amd64 conflict, so we
# install exactly the one matching BOOT (never both).
case "$BOOT" in
bios) BOOT_PKGS="grub-pc" ;;
efi) BOOT_PKGS="grub-efi-amd64 shim-signed mokutil" ;;
*) die "BOOT must be bios|efi (got '$BOOT')" ;;
esac
EDIR="$(edition_dir "$EDITION")"
ROOTFS="$ROOTFS_DIR/$EDITION"
ARTIFACT="$ARTIFACT_DIR/arcline-$EDITION-$VERSION-$ARCH.tar.xz"
@@ -73,8 +81,8 @@ trap 'unmount_pseudo' EXIT
chroot_run() { chroot "$ROOTFS" /bin/bash -c "$*"; }
# ── 3. install edition packages ─────────────────────────────────────────────
log "[3/6] installing edition packages (${EDITION})"
PKGS="$(grep -vE '^\s*(#|$)' "$EDIR/packages.list" | tr '\n' ' ')"
log "[3/6] installing edition packages (${EDITION}, boot: $BOOT)"
PKGS="$(grep -vE '^\s*(#|$)' "$EDIR/packages.list" | tr '\n' ' ')$BOOT_PKGS"
mount_pseudo
chroot_run "export DEBIAN_FRONTEND=noninteractive; apt-get update -qq && apt-get install -y --no-install-recommends $PKGS" \
| tee "$LOG_DIR/packages-$EDITION.log"

View File

@@ -20,6 +20,9 @@ set -euo pipefail
: "${KERNEL_PACKAGE:=linux-image-amd64}"
: "${KERNEL_VERSION:=6.12}"
# Boot flavour (mirrors versions.mk): bios → grub-pc, efi → grub-efi-amd64.
: "${BOOT:=bios}"
# Toolchain policy for image builds:
# auto (default) install the Arcline tools if build/debs/*.deb exist,
# otherwise build without them (with a warning)

View File

@@ -25,7 +25,7 @@ source "$(dirname "${BASH_SOURCE[0]}")/common.sh"
DEV="${1:?usage: deploy-disk.sh <device> <rootfs> <edition> [--boot bios|efi]}"
ROOTFS="${2:?usage: deploy-disk.sh <device> <rootfs> <edition> [--boot bios|efi]}"
EDITION="${3:?usage: deploy-disk.sh <device> <rootfs> <edition> [--boot bios|efi]}"
BOOT="${4:-bios}"
BOOT="${4:-$BOOT}" # default from the BOOT build variable (see versions.mk)
require_root "$0" "$@"
validate_edition "$EDITION"

View File

@@ -18,7 +18,7 @@ source "$(dirname "${BASH_SOURCE[0]}")/common.sh"
DEV="${1:?usage: install.sh <device> [--edition server] [--boot bios|efi] [--rootfs <dir>|--image <tar.xz>]}"
EDITION="server"
BOOT="bios"
BOOT="${BOOT:-bios}" # default from the BOOT build variable (see versions.mk)
ROOTFS_SRC=""
shift || true