#1134708 grub-common: 30_uefi-firmware runs on BIOS/MBR systems producing unbootable configuration

Package:
grub-common
Source:
grub-common
Description:
GRand Unified Bootloader (common files)
Submitter:
Donald Teed
Date:
2026-04-24 18:53:02 UTC
Severity:
normal
#1134708#5
Date:
2026-04-23 13:21:19 UTC
From:
To:
Dear Maintainer,

During an in-place upgrade from Debian 12 (bookworm) to Debian 13 (trixie)
on a Hyper-V Generation 1 virtual machine (BIOS/MBR, no EFI firmware),
the system was rendered unbootable after grub-common was upgraded and
update-grub was run as part of the post-install process.

The root cause is that /etc/grub.d/30_uefi-firmware is installed executable
by grub-common and is unconditionally executed by grub-mkconfig regardless
of whether the running system has UEFI firmware. On this BIOS/MBR system,
the script generated a "UEFI Firmware Settings" entry in grub.cfg which
caused the boot process to stall after the GRUB banner, leaving the system
unbootable.

I expect this is reproducible on any BIOS/MBR system where grub-common is
installed,
including legacy-mode virtual machines and older physical hardware, whenever
update-grub is run.

The script /etc/grub.d/30_uefi-firmware contains a check for $grub_platform
being "efi", however this is a GRUB environment variable evaluated at boot
time, not at config-generation time. It therefore does not prevent the
problematic menu entry from being written into grub.cfg on BIOS systems.

The fix is straightforward — add an OS-level guard as the first line of
/etc/grub.d/30_uefi-firmware:

  [ -d /sys/firmware/efi ] || exit 0

This check is evaluated when grub-mkconfig runs, which is the correct
moment. If /sys/firmware/efi does not exist, the system is not UEFI and
the script should take no action.

Workaround applied on the affected system:

  chmod -x /etc/grub.d/30_uefi-firmware

Further to the workaround... to prevent future grub-common upgrades from
restoring the execute bit and
reintroducing the problem, the following apt hook was also added:

  echo 'DPkg::Post-Invoke {"chmod -x /etc/grub.d/30_uefi-firmware ||
true;";};' \
    > /etc/apt/apt.conf.d/99-disable-uefi-grub-entry

Note: This bug is distinct from #1058818, which concerns fwsetup
--is-supported not being recognised by older GRUB binaries on UEFI systems.
This bug concerns the script running at all on non-UEFI systems during
config generation.

#1134708#10
Date:
2026-04-23 15:05:43 UTC
From:
To:
What do you mean exactly by "stall" ? Is anything displayed after the
GRUB banner (error message, grub> prompt...) ?
Can you post the generated grub.cfg ?

No, it doe not happen on any of my physical or virtual
(virt-manager/QEMU) BIOS systems. The menu entry is skipped as expected.

This check should be false on non-EFI systems, so the 30_uefi-firmware
stanza should not have any effect.

As intended.

Many systems can boot either in EFI or legacy mode depending on
UEFI/BIOS settings or boot source selection. A portable system may be
configured to be able to boot in both modes. Or the normal system may
boot in one mode but the user may boot a rescue system from removable
media in another mode by mistake and regenerate grub.cfg from there. So
it is better to generate the same grub.cfg which behaves differently at
boot time depending on the boot mode. memtest86+ does the same.

#1134708#15
Date:
2026-04-23 16:26:55 UTC
From:
To:
Thanks for the follow up.  You're right about the dual BIOS/UEFI
systems, so my suggestion wouldn't work.  However we still have a problem
that grub setup generated a menu that results in :

GRUB loading.
Welcome to GRUB

There is no way to get a menu or anything in that context.  Required a
rescue DVD boot.
That's what was meant by stalled.

Here's the grub.cfg it generates while /etc/grub.d/30_uefi-firmware is
executable:

#
# DO NOT EDIT THIS FILE
#
# It is automatically generated by grub-mkconfig using templates
# from /etc/grub.d and settings from /etc/default/grub
#

### BEGIN /etc/grub.d/00_header ###
if [ -s $prefix/grubenv ]; then
  set have_grubenv=true
  load_env
fi
if [ "${next_entry}" ] ; then
   set default="${next_entry}"
   set next_entry=
   save_env next_entry
   set boot_once=true
else
   set default="0"
fi

if [ x"${feature_menuentry_id}" = xy ]; then
  menuentry_id_option="--id"
else
  menuentry_id_option=""
fi

export menuentry_id_option

if [ "${prev_saved_entry}" ]; then
  set saved_entry="${prev_saved_entry}"
  save_env saved_entry
  set prev_saved_entry=
  save_env prev_saved_entry
  set boot_once=true
fi

function savedefault {
  if [ -z "${boot_once}" ]; then
    saved_entry="${chosen}"
    save_env saved_entry
  fi
}
function load_video {
  if [ x$feature_all_video_module = xy ]; then
    insmod all_video
  else
    insmod efi_gop
    insmod efi_uga
    insmod ieee1275_fb
    insmod vbe
    insmod vga
    insmod video_bochs
    insmod video_cirrus
  fi
}

serial --unit=0 --speed=115200 --word=8 --parity=no --stop=1
terminal_input console serial
terminal_output console serial
if [ "${recordfail}" = 1 ] ; then
  set timeout=30
else
  if [ x$feature_timeout_style = xy ] ; then
    set timeout_style=menu
    set timeout=5
  # Fallback normal timeout code in case the timeout_style feature is
  # unavailable.
  else
    set timeout=5
  fi
fi
### END /etc/grub.d/00_header ###

### BEGIN /etc/grub.d/05_debian_theme ###
set menu_color_normal=cyan/blue
set menu_color_highlight=white/blue
### END /etc/grub.d/05_debian_theme ###

### BEGIN /etc/grub.d/10_linux ###
function gfxmode {
        set gfxpayload="${1}"
}
set linux_gfx_mode=
export linux_gfx_mode
menuentry 'Debian GNU/Linux' --class debian --class gnu-linux --class gnu
--class os $menuentry_id_option
'gnulinux-simple-30b91b34-edee-4e65-948f-d991febc3252' {
        load_video
        insmod gzio
        if [ x$grub_platform = xxen ]; then insmod xzio; insmod lzopio; fi
        insmod part_msdos
        insmod ext2
        set root='hd1,msdos1'
        if [ x$feature_platform_search_hint = xy ]; then
          search --no-floppy --fs-uuid --set=root --hint-bios=hd1,msdos1
--hint-efi=hd1,msdos1 --hint-baremetal=ahci1,msdos1
 30b91b34-edee-4e65-948f-d991febc3252
        else
          search --no-floppy --fs-uuid --set=root
30b91b34-edee-4e65-948f-d991febc3252
        fi
        echo    'Loading Linux 6.12.74+deb13+1-amd64 ...'
        linux   /boot/vmlinuz-6.12.74+deb13+1-amd64
root=UUID=30b91b34-edee-4e65-948f-d991febc3252 ro  quiet
        echo    'Loading initial ramdisk ...'
        initrd  /boot/initrd.img-6.12.74+deb13+1-amd64
}
submenu 'Advanced options for Debian GNU/Linux' $menuentry_id_option
'gnulinux-advanced-30b91b34-edee-4e65-948f-d991febc3252' {
        menuentry 'Debian GNU/Linux, with Linux 6.12.74+deb13+1-amd64'
--class debian --class gnu-linux --class gnu --class os
$menuentry_id_option
'gnulinux-6.12.74+deb13+1-amd64-advanced-30b91b34-edee-4e65-948f-d991febc3252'
{
                load_video
                insmod gzio
                if [ x$grub_platform = xxen ]; then insmod xzio; insmod
lzopio; fi
                insmod part_msdos
                insmod ext2
                set root='hd1,msdos1'
                if [ x$feature_platform_search_hint = xy ]; then
                  search --no-floppy --fs-uuid --set=root
--hint-bios=hd1,msdos1 --hint-efi=hd1,msdos1 --hint-baremetal=ahci1,msdos1
 30b91b34-edee-4e65-948f-d991febc3252
                else
                  search --no-floppy --fs-uuid --set=root
30b91b34-edee-4e65-948f-d991febc3252
                fi
                echo    'Loading Linux 6.12.74+deb13+1-amd64 ...'
                linux   /boot/vmlinuz-6.12.74+deb13+1-amd64
root=UUID=30b91b34-edee-4e65-948f-d991febc3252 ro  quiet
                echo    'Loading initial ramdisk ...'
                initrd  /boot/initrd.img-6.12.74+deb13+1-amd64
        }
        menuentry 'Debian GNU/Linux, with Linux 6.12.74+deb13+1-amd64
(recovery mode)' --class debian --class gnu-linux --class gnu --class os
$menuentry_id_option
'gnulinux-6.12.74+deb13+1-amd64-recovery-30b91b34-edee-4e65-948f-d991febc3252'
{
                load_video
                insmod gzio
                if [ x$grub_platform = xxen ]; then insmod xzio; insmod
lzopio; fi
                insmod part_msdos
                insmod ext2
                set root='hd1,msdos1'
                if [ x$feature_platform_search_hint = xy ]; then
                  search --no-floppy --fs-uuid --set=root
--hint-bios=hd1,msdos1 --hint-efi=hd1,msdos1 --hint-baremetal=ahci1,msdos1
 30b91b34-edee-4e65-948f-d991febc3252
                else
                  search --no-floppy --fs-uuid --set=root
30b91b34-edee-4e65-948f-d991febc3252
                fi
                echo    'Loading Linux 6.12.74+deb13+1-amd64 ...'
                linux   /boot/vmlinuz-6.12.74+deb13+1-amd64
root=UUID=30b91b34-edee-4e65-948f-d991febc3252 ro single dis_ucode_ldr
                echo    'Loading initial ramdisk ...'
                initrd  /boot/initrd.img-6.12.74+deb13+1-amd64
        }
        menuentry 'Debian GNU/Linux, with Linux 6.1.0-38-amd64' --class
debian --class gnu-linux --class gnu --class os $menuentry_id_option
'gnulinux-6.1.0-38-amd64-advanced-30b91b34-edee-4e65-948f-d991febc3252' {
                load_video
                insmod gzio
                if [ x$grub_platform = xxen ]; then insmod xzio; insmod
lzopio; fi
                insmod part_msdos
                insmod ext2
                set root='hd1,msdos1'
                if [ x$feature_platform_search_hint = xy ]; then
                  search --no-floppy --fs-uuid --set=root
--hint-bios=hd1,msdos1 --hint-efi=hd1,msdos1 --hint-baremetal=ahci1,msdos1
 30b91b34-edee-4e65-948f-d991febc3252
                else
                  search --no-floppy --fs-uuid --set=root
30b91b34-edee-4e65-948f-d991febc3252
                fi
                echo    'Loading Linux 6.1.0-38-amd64 ...'
                linux   /boot/vmlinuz-6.1.0-38-amd64
root=UUID=30b91b34-edee-4e65-948f-d991febc3252 ro  quiet
                echo    'Loading initial ramdisk ...'
                initrd  /boot/initrd.img-6.1.0-38-amd64
        }
        menuentry 'Debian GNU/Linux, with Linux 6.1.0-38-amd64 (recovery
mode)' --class debian --class gnu-linux --class gnu --class os
$menuentry_id_option
'gnulinux-6.1.0-38-amd64-recovery-30b91b34-edee-4e65-948f-d991febc3252' {
                load_video
                insmod gzio
                if [ x$grub_platform = xxen ]; then insmod xzio; insmod
lzopio; fi
                insmod part_msdos
                insmod ext2
                set root='hd1,msdos1'
                if [ x$feature_platform_search_hint = xy ]; then
                  search --no-floppy --fs-uuid --set=root
--hint-bios=hd1,msdos1 --hint-efi=hd1,msdos1 --hint-baremetal=ahci1,msdos1
 30b91b34-edee-4e65-948f-d991febc3252
                else
                  search --no-floppy --fs-uuid --set=root
30b91b34-edee-4e65-948f-d991febc3252
                fi
                echo    'Loading Linux 6.1.0-38-amd64 ...'
                linux   /boot/vmlinuz-6.1.0-38-amd64
root=UUID=30b91b34-edee-4e65-948f-d991febc3252 ro single dis_ucode_ldr
                echo    'Loading initial ramdisk ...'
                initrd  /boot/initrd.img-6.1.0-38-amd64
        }
        menuentry 'Debian GNU/Linux, with Linux 6.1.0-37-amd64' --class
debian --class gnu-linux --class gnu --class os $menuentry_id_option
'gnulinux-6.1.0-37-amd64-advanced-30b91b34-edee-4e65-948f-d991febc3252' {
                load_video
                insmod gzio
                if [ x$grub_platform = xxen ]; then insmod xzio; insmod
lzopio; fi
                insmod part_msdos
                insmod ext2
                set root='hd1,msdos1'
                if [ x$feature_platform_search_hint = xy ]; then
                  search --no-floppy --fs-uuid --set=root
--hint-bios=hd1,msdos1 --hint-efi=hd1,msdos1 --hint-baremetal=ahci1,msdos1
 30b91b34-edee-4e65-948f-d991febc3252
                else
                  search --no-floppy --fs-uuid --set=root
30b91b34-edee-4e65-948f-d991febc3252
                fi
                echo    'Loading Linux 6.1.0-37-amd64 ...'
                linux   /boot/vmlinuz-6.1.0-37-amd64
root=UUID=30b91b34-edee-4e65-948f-d991febc3252 ro  quiet
                echo    'Loading initial ramdisk ...'
                initrd  /boot/initrd.img-6.1.0-37-amd64
        }
        menuentry 'Debian GNU/Linux, with Linux 6.1.0-37-amd64 (recovery
mode)' --class debian --class gnu-linux --class gnu --class os
$menuentry_id_option
'gnulinux-6.1.0-37-amd64-recovery-30b91b34-edee-4e65-948f-d991febc3252' {
                load_video
                insmod gzio
                if [ x$grub_platform = xxen ]; then insmod xzio; insmod
lzopio; fi
                insmod part_msdos
                insmod ext2
                set root='hd1,msdos1'
                if [ x$feature_platform_search_hint = xy ]; then
                  search --no-floppy --fs-uuid --set=root
--hint-bios=hd1,msdos1 --hint-efi=hd1,msdos1 --hint-baremetal=ahci1,msdos1
 30b91b34-edee-4e65-948f-d991febc3252
                else
                  search --no-floppy --fs-uuid --set=root
30b91b34-edee-4e65-948f-d991febc3252
                fi
                echo    'Loading Linux 6.1.0-37-amd64 ...'
                linux   /boot/vmlinuz-6.1.0-37-amd64
root=UUID=30b91b34-edee-4e65-948f-d991febc3252 ro single dis_ucode_ldr
                echo    'Loading initial ramdisk ...'
                initrd  /boot/initrd.img-6.1.0-37-amd64
        }
}

### END /etc/grub.d/10_linux ###

### BEGIN /etc/grub.d/20_linux_xen ###

### END /etc/grub.d/20_linux_xen ###

### BEGIN /etc/grub.d/25_bli ###
if [ "$grub_platform" = "efi" ]; then
  insmod bli
fi
### END /etc/grub.d/25_bli ###

### BEGIN /etc/grub.d/30_os-prober ###
### END /etc/grub.d/30_os-prober ###

### BEGIN /etc/grub.d/30_uefi-firmware ###
if [ "$grub_platform" = "efi" ]; then
        fwsetup --is-supported
        if [ "$?" = 0 ]; then
                menuentry 'UEFI Firmware Settings' $menuentry_id_option
'uefi-firmware' {
                        fwsetup
                }
        fi
fi
### END /etc/grub.d/30_uefi-firmware ###

### BEGIN /etc/grub.d/40_custom ###
# This file provides an easy way to add custom menu entries.  Simply type
the
# menu entries you want to add after this comment.  Be careful not to change
# the 'exec tail' line above.
### END /etc/grub.d/40_custom ###

### BEGIN /etc/grub.d/41_custom ###
if [ -f  ${config_directory}/custom.cfg ]; then
  source ${config_directory}/custom.cfg
elif [ -z "${config_directory}" -a -f  $prefix/custom.cfg ]; then
  source $prefix/custom.cfg
fi
### END /etc/grub.d/41_custom ###

This shows there is no EFI:

# # Confirm no EFI on this system
# ls /sys/firmware/efi 2>/dev/null && echo "EFI present" || echo "No EFI"
No EFI

#1134708#20
Date:
2026-04-24 18:51:31 UTC
From:
To:
I am unable to reproduce the issue on a QEMU+SeaBIOS VM with this
grub.cfg; GRUB 2.12 displays the menu without the UEFI firmware entry as
expected, and is functional.