From 53a3ad25af78d6399d9b605a037878ccd3179320 Mon Sep 17 00:00:00 2001 From: nl6720 Date: Sat, 18 Jun 2022 09:56:24 +0300 Subject: mkarchiso: add SBAT metadata to grub-mkstandalone created EFI binaries Even though archiso created ISOs do not support Secure Boot, having SBAT would allow users to more easily repack the files in the ISO to add a signed shim. Fixes #174 --- archiso/mkarchiso | 2 ++ 1 file changed, 2 insertions(+) (limited to 'archiso') diff --git a/archiso/mkarchiso b/archiso/mkarchiso index bb084f7..bb0524c 100755 --- a/archiso/mkarchiso +++ b/archiso/mkarchiso @@ -544,6 +544,7 @@ _make_bootmode_uefi-ia32.grub.esp() { --modules="part_gpt part_msdos fat iso9660" \ --locales="en@quot" \ --themes="" \ + --sbat=/usr/share/grub/sbat.csv \ -o "${work_dir}/BOOTIA32.EFI" "boot/grub/grub.cfg=${work_dir}/grub-embed.cfg" # Add GRUB to the list of files used to calculate the required FAT image size. efiboot_files+=("${work_dir}/BOOTIA32.EFI" @@ -619,6 +620,7 @@ _make_bootmode_uefi-x64.grub.esp() { --modules="part_gpt part_msdos fat iso9660" \ --locales="en@quot" \ --themes="" \ + --sbat=/usr/share/grub/sbat.csv \ -o "${work_dir}/BOOTx64.EFI" "boot/grub/grub.cfg=${work_dir}/grub-embed.cfg" # Add GRUB to the list of files used to calculate the required FAT image size. efiboot_files+=("${work_dir}/BOOTx64.EFI" -- cgit v1.2.3-70-g09d2