Files
felhom.eu/documentation/audits/kernel-spike-2026-10-07/tools/spike-bootnext-setup.sh
T

23 lines
1.5 KiB
Bash

#!/bin/bash
# Candidate 1 (R-836): UEFI BootNext. A copy of the signed loader in \EFI\felhomnext\ whose grub.cfg exports the target
# entry, and a firmware entry "felhom-next" kept OUT of BootOrder. The firmware clears BootNext itself after one use.
# Usage: spike-bootnext-setup.sh <target-entry-id> (re-run to change the target). Reversible: spike-bootnext-undo.sh
set -euo pipefail
TARGET=$1
P=/boot/efi/EFI/proxmox; N=/boot/efi/EFI/felhomnext
mkdir -p $N; cp -p $P/shimx64.efi $P/grubx64.efi $P/mmx64.efi $N/
STUB=$(grep -v '^configfile' $P/grub.cfg)
printf '%s\n' "set felhom_bn=$TARGET" "export felhom_bn" "$STUB" 'configfile $prefix/grub.cfg' > $N/grub.cfg
# the main grub.cfg honours felhom_bn (set only when the felhomnext loader started GRUB)
if ! grep -q felhom_bn /etc/grub.d/01_felhom_oneshot; then
sed -i 's#^G$#if [ "${felhom_bn}" ]; then set default="${felhom_bn}"; fi\nG#' /etc/grub.d/01_felhom_oneshot
update-grub 2>&1 | tail -1
fi
ORDER=$(efibootmgr | sed -n 's/^BootOrder: //p')
if ! efibootmgr | grep -q ' felhom-next'; then
DISK=/dev/$(lsblk -no PKNAME $(findmnt -n -o SOURCE /boot/efi)); PART=$(cat /sys/class/block/$(basename $(findmnt -n -o SOURCE /boot/efi))/partition)
efibootmgr -q -c -d $DISK -p $PART -L felhom-next -l '\EFI\felhomnext\shimx64.efi'
efibootmgr -q -o "$ORDER" # -c puts the new entry first; the normal order is restored
fi
efibootmgr | grep -E 'BootOrder|felhom-next|BootNext'; cat $N/grub.cfg; grep -n felhom_bn /boot/grub/grub.cfg