diff --git a/live-build/ubuntu-cpc/hooks/033-disk-image-uefi.binary b/live-build/ubuntu-cpc/hooks/033-disk-image-uefi.binary index 638c020c..33a19316 100755 --- a/live-build/ubuntu-cpc/hooks/033-disk-image-uefi.binary +++ b/live-build/ubuntu-cpc/hooks/033-disk-image-uefi.binary @@ -62,30 +62,21 @@ install_grub() { efi_boot_dir="/boot/efi/EFI/BOOT" chroot mountpoint mkdir -p "${efi_boot_dir}" - # The modules below only make sense on non-Secure Boot UEFI systems. - # Otherwise, with Secure Boot enabled GRUB will refuse to load them. - # Any modules already in debian/build-efi-images do not need to be listed. - # Furthermore, other modules such as terminal, video_* and efi_* are all - # already available. + # UEFI GRUB modules are meant to be used equally by Secure Boot and + # non-Secure Boot systems. If you need an extra module not already + # provided or run into "Secure Boot policy forbids loading X" problems, + # please file a bug against grub2 to include the affected module. case $ARCH in arm64) chroot mountpoint apt-get -qqy install --no-install-recommends grub-efi-arm64 grub-efi-arm64-bin - grub_modules="serial" efi_target=arm64-efi ;; amd64) chroot mountpoint apt-get install -qqy grub-efi-amd64-signed grub-efi-amd64 shim-signed - grub_modules="multiboot serial usb usb_keyboard" efi_target=x86_64-efi ;; esac - cat << EOF >> mountpoint/etc/default/grub.d/50-cloudimg-settings.cfg -${IMAGE_STR} -# For Cloud Image compatability -GRUB_PRELOAD_MODULES="${GRUB_PRELOAD_MODULES:-$grub_modules}" -EOF - chroot mountpoint grub-install "${loop_device}" \ --boot-directory=/boot \ --efi-directory=/boot/efi \