LINUX Unplugged

660: Boots and Breakups

Mar 29, 2026
A deep dive into Ubuntu 26.10’s plan to slim down GRUB and what boot support might vanish. They explore Secure Boot history, BootHole risks, and which filesystems and boot setups are at risk. Practical alternatives get attention, from systemd-boot to DIY kernel signing. A long-running self-hosted TV project’s final release and lively notes on Tunarr, ErsatzTV, and DIY IPTV tooling round out the conversation.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Ubuntu's Minimal GRUB For Secure Boot

  • Ubuntu plans a "minimal grub" for 26.10 to reduce Secure Boot attack surface.
  • They will ship signed GRUB builds that drop many filesystem and feature drivers (Btrfs, ZFS, LUKS on /boot, JPEG/PNG, etc.) to simplify update/mitigation complexity.
INSIGHT

BootHole Shows Why Signed Bootchains Are Hard

  • Secure Boot complexity arises from signed shim/GRUB chains and the need to coordinate key/signature rollouts after vulnerabilities.
  • Wes explains BootHole history and why fixing deployed trusted bootloaders requires coordination with Microsoft and hardware trust stores.
ADVICE

Audit Your /boot Setup Now

  • Check whether your system uses signed GRUB and where /boot lives because Ubuntu's change only affects signed builds.
  • If you rely on Btrfs, ZFS, LUKS-on-/boot, or image assets in /boot, plan migration to an unsigned GRUB or alternative boot method.
Get the Snipd Podcast app to discover more snips from this episode
Get the app