So, my OCD told me I should update my bios as it was a few months old and I keep listening to people who are supposedly in the know, telling me that “You should update your bios to get the latest security features”. I let the computer do it’s thing as it updated and then all hell broke loose. The computer took a long time to ram train, etc and then I got a pop up. Windows Boot Manager (WBM) has detected a problem and your computer needs to be repaired, in a big full blue screen that Microsoft like to use.
WTF! I don’t have Windows installed, WTH is this BS? I know on my older PC it has Windows boot Manager and UEFI boot manager, because it does and if I have WBM as the first option, it takes forever to boot into CachyOS. In any case, it looks as if Microsoft has convinced manufacturers to include this crap into the bios of new motherboards.
I went back into the bios but the only option was the Windows boot manager, more MS BS. What to do now? My only choice was to disable WBM which I did but this resulted in the dreaded secure boot violation error. Well, I know what to do here, back into the bios and disable secure boot. Needless to say, after this kerfuffle, I will no longer be updating the bios unless it’s something that cannot be ignored, but what a PITA! It’s too bad there is no Linux Bios Update, to negate all this forced stupidity from MS. Yeah I know, limited world wide Linux usage but it seems that eventually Bios updates will completely screw up people’s usage of Linux.
Well.. I don’t know if you know but maybe you don’t xd. The UEFI bios on pretty much all computers has a thing called NVRAM. It stores all sorts of things including boot entries (bootloaders).
If you do use Limine like I do.. you would quickly know that the nvram entry for limine (cachy) gets wiped every time you update the bios. (because reasons i guess).
Depending on how your disk / bootloader situation looks like.. or if that perticular disk / disks had or still has a windows efi bootloader somewhere.. then your motherboard will default to that and try to boot from it.
Updating your bios is good to do. Security is not the only thing you gain (cough cough intel cpu death issues on 13th and 14th gen cpus).
You can fix the issues mostly either by chrooting from a live cachy usb and running sudo limine install + update (to get the nvram entry back). Or you can do the same thing from cachy itself if it still boots.
Also.. flashing your bios does not mean the settings get saved. Disable secure boot. Disable CSM (aka boot in UEFI mode only because its faster) and etc.
And last thing.. you can make a fallback efi entry inside the boot partition of cachy by copying /boot/EFI/Limine/limine_x64.efi to /boot/EFI/BOOT/BOOTX64.EFI
That is basically the efi fallback that all modern UEFI motherboards will (guess what) fall back to if the efi loader is not fully supported.. can’t find it etc (like limine sometimes). Then you will permanently see the limine boot option even if you change motherboards.
If you do happen to make that fallback in the boot partition.. you can also make a pacman hook to automatically install (basically copy) the newest version of limine blah blah blah to the path i showed above so that the efi loader doesn’t get older and older as time goes by.
It’s fine, my computer tried to boot into CachyOS as soon as I disabled the MS stuff, I only had an issue with the secure boot violation because I can’t be bothered to update the Windows secure boot rules. Yes, I use Limine and again, as long as I can boot, I don’t really care, If I ever have some free time, and am bored, I’ll fix it all but as I am retired, I am rarely bored. I was holding off on updating the BIOS as it only offered stability for 9X00 AMD CPUs and as I am only using a 7600x, it was of little concern. This BIOS, however, is supposed to improve EXPOs performance, probably also not an issue, considering my RAM is over a year old and working fine with EXPO but I was temporarily bored. Yes, what breaks all modern computers the most, boredom.
Okay, I was having a rest after mowing the lawn and so I decided to see if I could reinstall limine and restore it to the BIOS. I actually used the CachyOS package manager which allowed me to update Limine which then showed up in the BIOS as selection 1. I left the Windows Boot Manager disabled and I may even remove it or not. In any case, Limine has been restored which was my goal, and all is good again. At least I was able to boot into CachyOS even without the Limine entry but this should speed things up.
The reason why windows boot manager pops up is because you still have the windows bootloader somewhere on your drive/s. Like I get the hate towards microslop (I hate them just as much) but the nvram entry for windows boot manager doesn’t just pop in magically because of microsoft force feeding motherboard manufacturers or something xd. The bios always checks for efi partitions and for preset paths. Ofc it sees windows first since the vast majority of people use that.
For example if you remove all drives from your computer and start it up.. you will notice that all windows boot manager / linux / etc boot options will dissappear. You plug them back in and poof windows boot manager is there but cachy (limine) isn’t.
Either clean up your drive and make sure there is only 1 boot partition and that boot partition doesn’t contain 423 diffrent bootloaders.. or live with it and do the efi fallback option I told you above in my previous reply.
My laptop was brand new when I got it - and I ordered it without an operating system.
Yet, the first thing I did was enter the UEFI and turn Secure Boot off. Because Microsoft do “force-feed” computer manufacturers. I haven’t got a Windows Boot Manager because there never was one on this laptop. But Microsoft still has a presence in the UEFI.
Which is why I won’t ever turn it back on - I don’t need “windows security” (sic).
Okay, so I cp’d limine_x64.efi to BOOTX64.EFI, now I need the hook to get limine to auto update. There are a number of hooks in /usr/share/libalpm/hooks, will one of those do or will I have to create a hook? I have never done this so not sure how to proceed.
As for partitions, there are two active partitions, a Fat 32 partition and a Btrfs Partition. Are you saying that I can delete the fat 32 partition? I’m thinking not as its where the boot info is however it also means that windows is hiding here.
I also went where nobody should go , into /Boot/EFI and found three entries: BOOT, Limine & Microsoft. I deleted Microsoft, rebooted and found that Microsoft had been replaced in the BIOS with UEFI, which I am fine with. Not sure when I will have to update the BIOS but if I do, I am certain that Microsoft will no longer be in there doing what MS does. I don’t hate Windows, I’m just not currently pleased with the direction Microsoft is taking it. It’s fine, to each their own, just let me wander the way I choose.
Even if the laptop is brand new, at some point during QA it could have had an OS on it to do some testing. Afterwards the disk was wiped b/c it was ordered w/o OS, but they left the bootloader on it? Maybe.
Only thing I can think of. I had an incredibly janky setup where I had Windows on an external drive as I had to update my GPU BIOS to solve an hourly crash. When I updated my proper BIOS, it defaulted to the Windows bootloader I didn’t realize got put on my system drive and not the external.
The BIOS itself typically doesn’t come with any sort of bootloader as they not only change between versions, but Windows also ships some updates that patches it. A mobo manufacturer shipping that and causing people needing to repatch or even hose booting entirely would get a LOT of bad attention. Not to mention the boot partition tends to be around 100mb or more on Windows and a BIOS is like 20mb.
True. However, the place I bought it from only sell Linux laptops and computers. They only pre-install Linux distros. Why would they test with Windows? There was no boot-loader on the system.
Secure Boot is in the UEFI. It could be useful - if you sign your own keys.
By bios do you mean the graphical application that you interact with at setup? I don’t think I’ve ever updated that directly, but I’ve used fwupd several times when Intel release a security update and it’s always pulled down that latest firmware fix.
Firmware and BIOS are two different things. Some stuff from fwupd may write things it uses (ie. revocation lists) but the BIOS can also contain lower microcode. It is literally the first screen you see on boot before the bootloader.
Definitely DO NOT delete the efi partition lol. You need that for linux. Its good that you deleted the microsoft directory. That means limine saw windows somewhere once and kept it as an entry. I can send you the pacman hook later today.
Hmmm, fwupd eh? That does sound interesting, and apparently version 2.11 has support for AMD systems. Might be worth a try, and might even fix secure boot while it’s at it. I could fix it the old way but it’s a pita and if something will do it automatically, yeah, this old guy likes that.