Home / Alt manpages / grub-glue-efi(1)

  • grub-glue-efi(1)
  • User command
  • linux

Build a Universal EFI Binary with grub-glue-efi

You will finish with one Apple-format universal EFI binary containing a 32-bit and a 64-bit GRUB EFI image. This guide uses grub-glue-efi from grub-common version 2.12-1ubuntu7.3, installed on Ubuntu here. Allow about 15 minutes if both input images already exist. Building the input images is a separate task and requires the matching GRUB platform files.

The command combines files. It does not install a bootloader, copy anything to an EFI System Partition, sign an image, or prove that either input can boot. Keep the result in a working directory until you have tested it on the firmware and boot path you actually support.

1. Confirm the command and its version

Start with the read-only checks below:

$ command -v grub-glue-efi
/usr/bin/grub-glue-efi
$ grub-glue-efi --version
grub-glue-efi (GRUB) 2.12-1ubuntu7.3
$ dpkg-query -W -f='${Package} ${Version}\n' grub-common
grub-common 2.12-1ubuntu7.3

Checkpoint: the executable and package versions should describe the same installed GRUB build. If the command is missing, stop here and install or repair the package through your normal system administration process. This guide does not need elevated privileges.

2. Gather one image for each architecture

grub-glue-efi expects an ia32 EFI image for --input32 and an amd64 EFI image for --input64. They are not two copies of the same file. Check their paths, sizes and machine types before combining them:

$ file /path/to/grub-i386.efi /path/to/grub-x86_64.efi
/path/to/grub-i386.efi:   PE32 executable (EFI application) Intel 80386
/path/to/grub-x86_64.efi: PE32+ executable (EFI application) x86-64
$ test -s /path/to/grub-i386.efi && test -s /path/to/grub-x86_64.efi
$ printf '%s\n' "$?"
0

The wording from file can vary slightly between versions, but the important distinction is PE32 versus PE32+, and 32-bit Intel versus x86-64. A zero status from test -s only says that both files are non-empty. It does not validate GRUB headers or bootability.

If you are creating the images with grub-mkimage, select i386-efi for the 32-bit image and x86_64-efi for the 64-bit image, and use the corresponding platform directory. For example:

grub-mkimage -p /boot/grub \
  -O i386-efi \
  -d /usr/lib/grub/i386-efi \
  -o /path/to/grub-i386.efi \
  boot

grub-mkimage -p /boot/grub \
  -O x86_64-efi \
  -d /usr/lib/grub/x86_64-efi \
  -o /path/to/grub-x86_64.efi \
  boot

Those platform directories and the modules available in them depend on installed packages. Do not substitute the x86-64 directory for the 32-bit one. On this machine the amd64 platform directory is present, while the 32-bit directory is not, so the first example is a template rather than a command that can succeed locally without the matching files.

3. Combine the two images into a new file

Choose an output path that is not either input path. The command overwrites an existing output file, so check it before running the write:

input32=/path/to/grub-i386.efi
input64=/path/to/grub-x86_64.efi
output=/path/to/grub-universal.efi

if test -e "$output"; then
    printf 'Refusing to overwrite existing output: %s\n' "$output" >&2
    exit 1
fi

grub-glue-efi \
  --input32="$input32" \
  --input64="$input64" \
  --output="$output"

There is no need for sudo when the files are in a directory you can write. Use elevated privileges only if your chosen path is deliberately protected, and review that path first. Writing into a mounted EFI System Partition is a separate, security-sensitive deployment action. Do not use it as the first test.

Checkpoint: a successful command normally produces no standard output when --verbose is absent. Confirm that the output exists and is non-empty:

$ test -s /path/to/grub-universal.efi
$ printf '%s\n' "$?"
0
$ file /path/to/grub-universal.efi
/path/to/grub-universal.efi: Universal EFI binary with 2 architectures, i386, x86_64

The file result is a useful format check. It does not replace boot testing. If the command fails, preserve the error text and inspect every input path. A missing file, an unreadable file or a typo in an option can look like a build problem when it is only a path problem.

4. Use verbose output when you need a trace

Add --verbose when you want a short confirmation on standard error. Keep binary output in a file by using --output:

$ grub-glue-efi --verbose \
    --input32=/path/to/grub-i386.efi \
    --input64=/path/to/grub-x86_64.efi \
    --output=/path/to/grub-universal.efi
/path/to/grub-universal.efi: Universal EFI binary with 2 architectures, i386, x86_64

The output option defaults to standard output. That is useful for a controlled pipeline, but it is easy to corrupt an EFI binary by mixing diagnostics or other text into the same stream. For routine work, always name an output file and redirect logs separately if you need to retain them.

5. Check the result before deployment

Compare the architecture report with the two inputs, then retain hashes if the file will be copied between systems:

file /path/to/grub-i386.efi \
     /path/to/grub-x86_64.efi \
     /path/to/grub-universal.efi
sha256sum /path/to/grub-universal.efi

A universal result is a container for both architectures, not a guarantee that firmware will choose the desired slice or that the embedded GRUB configuration is correct. Test it in the intended Apple or other firmware environment, and apply your normal Secure Boot signing and verification process where required. Do not assume that combining unsigned inputs creates a signed output.

If you need to undo this guide's filesystem change, remove only the generated output after checking its exact path and confirming it is not being used:

output=/path/to/grub-universal.efi
test -f "$output" && printf 'Review before removing: %s\n' "$output"
# After that review, remove the generated file with your normal change control.

The input images are not modified by grub-glue-efi. Keep them if you need to reproduce the result.

Done means

  • The installed command reports the expected GRUB version.
  • --input32 points to a non-empty ia32 EFI image and --input64 points to a non-empty x86-64 EFI image.
  • The output path was reviewed before writing and is separate from both inputs.
  • file reports a universal EFI binary containing i386 and x86_64.
  • The result has been tested, signed and deployed only through the firmware workflow appropriate to your system.