From 9f6407d061db0222e9971834224be3acfa23ef22 Mon Sep 17 00:00:00 2001 From: Michael Prokop Date: Fri, 4 Jul 2025 08:45:14 +0200 Subject: [PATCH] MT#63155 Fix EFI detection for kernel versions >=6.3 With kernel versions >=6.3, efivarfs is loaded even when the system wasn't booted in EFI mode. But loading efivarfs fails: | root@web01a ~ # lsmod | grep efi | efivarfs 28672 0 | | root@web01a ~ # ls /sys/firmware/efi/ | ls: cannot access '/sys/firmware/efi/': No such file or directory | | root@web01a ~ # mount -t efivarfs efivarfs /sys/firmware/efi/efivars | mount: /sys/firmware/efi/efivars: fsopen() failed: Operation not supported. | dmesg(1) may have more information after failed mount system call. Adjust our EFI support detection code to what we're also doing in grml-debootstrap.git (see commit b8a6a2c90f5bffceeb7d85cdc30ac7a7e58f4c0b). Furthermore by now we have grml-debootstrap v0.121 available in our current deployment ISO, so drop the now deprecated efivars_workaround. Change-Id: I2210a7b87d0df2ae41872380e458e29e755f6886 (cherry picked from commit fd55984db114f7e2b3235b40254858a2601b8b5d) (cherry picked from commit f907bdcfba14e1c91278521981400ef82df9234f) --- templates/scripts/includes/deployment.sh | 113 ++--------------------- 1 file changed, 7 insertions(+), 106 deletions(-) diff --git a/templates/scripts/includes/deployment.sh b/templates/scripts/includes/deployment.sh index 6252349..2ff1586 100755 --- a/templates/scripts/includes/deployment.sh +++ b/templates/scripts/includes/deployment.sh @@ -345,117 +345,21 @@ wait_exit() { exit "${e_code}" } -# check for EFI support, if not present try to enable it +# check for EFI support or try to enable it efi_support() { - if lsmod | grep -q efivarfs ; then - echo "EFI support detected." - return 0 - fi + # Absence of an EFI runtime does not prevent loading efivarfs since commit + # 301de9a2055357375a4e1053d9df0f8f3467ff00 which landed in Linux v6.3. + # Unconditionally load it, in case nothing else attempted it. + modprobe efivarfs &>/dev/null || true - if modprobe efivarfs &>/dev/null ; then - echo "EFI support enabled now." + if [ -d /sys/firmware/efi ] ; then + einfo "EFI support detected." return 0 fi return 1 } -# Debian kernels >=5.10 don't provide efivars support, ensure to either: -# 1) have grml-debootstrap v0.99 or newer available (which provides according -# efivarfs workaround), or otherwise: -# 2) apply local workaround using post script within grml-debootstrap -# (to avoid having to update the grml-debootstrap package, because that's not -# available within environments relying on our approx Debian mirror, which -# doesn't provide the Grml repository) -efivars_workaround() { - if lsmod | grep -q 'efivars' ; then - echo "We do have efivars support, no need to apply workarounds" - return 0 - fi - - echo "Running with kernel without efivars support" - if check_package_version grml-debootstrap 0.99~ ; then - echo "grml-debootstrap >=0.99 available, no need to apply pre/post script workaround" - return 0 - fi - - echo "Present grml-debootstrap version is not recent enough, falling back to workarounds using local script" - - # pre script, relevant for grml-debootstrap versions <=0.96 with EFI environments - mkdir -p /etc/debootstrap/pre-scripts/ - cat > /etc/debootstrap/pre-scripts/efivarfs << "EOL" -#!/bin/bash -set -eu -p pipefail - -echo "Executing $0" - -if ! ls "${MNTPOINT}"/sys/firmware/efi/efivars/* &>/dev/null ; then - # we need to have /sys available to be able to mount /sys/firmware/efi/efivars - if ! chroot "${MNTPOINT}" test -d /sys/kernel ; then - echo "Mointing /sys" - chroot "${MNTPOINT}" mount -t sysfs none /sys - fi - - echo "Mounting efivarfs on /sys/firmware/efi/efivars" - chroot "${MNTPOINT}" mount -t efivarfs efivarfs /sys/firmware/efi/efivars -fi -echo "Finished execution of $0" -EOL - - chmod 775 /etc/debootstrap/pre-scripts/efivarfs - PRE_SCRIPTS_OPTION="--pre-scripts /etc/debootstrap/pre-scripts/" - - # post script - mkdir -p /etc/debootstrap/post-scripts/ - cat > /etc/debootstrap/post-scripts/efivarfs << "EOL" -#!/bin/bash -set -eu -p pipefail - -echo "Executing $0" - -if ! [ -e "${MNTPOINT}"/dev/mapper/ngcp-root ] ; then - echo "Mounting /dev (via bind mount)" - mount --bind /dev "${MNTPOINT}"/dev/ -fi - -if ! [ -e "${MNTPOINT}"/proc/cmdline ] ; then - echo "Mounting /proc" - chroot "${MNTPOINT}" mount -t proc none /proc -fi - -if ! ls "${MNTPOINT}"/sys/firmware/efi/efivars/* &>/dev/null ; then - # we need to have /sys available to be able to mount /sys/firmware/efi/efivars - if ! chroot "${MNTPOINT}" test -d /sys/kernel ; then - echo "Mointing /sys" - chroot "${MNTPOINT}" mount -t sysfs none /sys - fi - - echo "Mounting efivarfs on /sys/firmware/efi/efivars" - chroot "${MNTPOINT}" mount -t efivarfs efivarfs /sys/firmware/efi/efivars -fi - -if ! [ -d "${MNTPOINT}"/boot/efi/EFI ] ; then - echo "Mounting /boot/efi" - chroot "${MNTPOINT}" mount /boot/efi -fi - -echo "Invoking grub-install with proper EFI environment" -chroot "${MNTPOINT}" grub-install - -for f in /boot/efi /sys/firmware/efi/efivars /sys /proc /dev ; do - if mountpoint "${MNTPOINT}/$f" &>/dev/null ; then - echo "Unmounting $f" - umount "${MNTPOINT}/$f" - fi -done - -echo "Finished execution of $0" -EOL - - chmod 775 /etc/debootstrap/post-scripts/efivarfs - POST_SCRIPTS_OPTION="--post-scripts /etc/debootstrap/post-scripts/" -} - cdr2mask() { # From https://stackoverflow.com/questions/20762575/explanation-of-convertor-of-cidr-to-netmask-in-linux-shell-netmask2cdir-and-cdir # Number of args to shift, 255..255, first non-255 byte, zeroes @@ -2199,9 +2103,6 @@ if [[ -n "${EFI_PARTITION}" ]] ; then # ensure we force creation of a proper FAT filesystem echo "Creating FAT filesystem on EFI partition ${EFI_PARTITION}" mkfs.fat -F32 -n "EFI" "${EFI_PARTITION}" - - # this can be dropped once we have grml-debootstrap >=v0.99 available in our squashfs - efivars_workaround else echo "EFI support NOT present, not enabling EFI support within grml-debootstrap" fi