Install GRUB Safely on BIOS and UEFI Linux Systems
You will install the locally packaged GRUB bootloader to the intended system disk or EFI System Partition, then check the files and firmware entry before rebooting. Allow 15 to 30 minutes, plus time for a recovery boot if the machine is remote or its disk layout is unfamiliar. This guide describes the installed Ubuntu 24.04 command, GRUB 2.12-1ubuntu7.3 from grub2-common.
The route
Jump straight to the step you need, or tick off Done means at the end.
Warning
grub-install changes boot files and, on BIOS systems, can write boot code to a disk. A wrong device can make another disk bootable or leave the machine unable to start. Confirm every device name before using sudo. Keep a working live USB or console and a backup of important data available.
1. Confirm the command and boot mode
Start with read-only checks. The command must be run as root for an installation, but version and layout checks normally do not need elevated privileges:
$ command -v grub-install
/usr/sbin/grub-install
$ grub-install --version
grub-install (GRUB) 2.12-1ubuntu7.3
$ dpkg-query -W -f='${Package} ${Version}\n' grub2-common
grub2-common 2.12-1ubuntu7.3
$ test -d /sys/firmware/efi && echo UEFI || echo BIOS
The last check reports the firmware mode of the currently running Linux system. It does not tell you which disk contains your installed system. A UEFI installation normally uses target x86_64-efi on a 64-bit PC and an EFI System Partition mounted at a directory such as /boot/efi. A legacy BIOS installation normally uses target i386-pc and names the whole disk, such as /dev/sda, rather than a partition.
Checkpoint
Stop if the running mode does not match the mode you intend to repair. Boot the installed system in the required mode, or use a correctly booted rescue environment. Installing an EFI loader while booted in legacy mode can fail or produce a result that firmware cannot use.
2. Map the system layout before changing it
Use lsblk and findmnt to identify the root filesystem, the separate boot filesystem if present, and the EFI System Partition. These commands only inspect the current layout:
$ lsblk -o NAME,PATH,SIZE,FSTYPE,FSVER,LABEL,UUID,MOUNTPOINTS
$ findmnt -no SOURCE,FSTYPE,TARGET /
$ findmnt -no SOURCE,FSTYPE,TARGET /boot 2>/dev/null || true
$ findmnt -no SOURCE,FSTYPE,TARGET /boot/efi 2>/dev/null || true
For UEFI, the mounted target should be a small FAT filesystem at the EFI directory you will pass to --efi-directory. Use the exact mount point shown by findmnt, not a guessed path. For BIOS, identify the disk that the firmware is meant to start. /dev/sda and /dev/nvme0n1 are whole disks; /dev/sda2 and /dev/nvme0n1p2 are partitions. Do not replace a whole-disk placeholder with a partition unless you have a specific, verified reason.
Do not use --force to silence uncertainty. The manual says it installs even when problems are detected, which makes a mistaken device or unsupported layout more dangerous.
3. Install for UEFI
Use this form when the check in step 1 reported UEFI and the EFI System Partition is mounted at /boot/efi. Replace BOOT_ID with the name you want visible in firmware, or retain the existing distribution name if you are repairing it:
$ sudo grub-install \
--target=x86_64-efi \
--efi-directory=/boot/efi \
--bootloader-id=BOOT_ID \
--recheck
--target selects the platform, --efi-directory identifies the EFI System Partition root, and --bootloader-id supplies the EFI bootloader directory and entry name. --recheck asks GRUB to remove an existing device map before checking devices again; it is most relevant when disks have changed. The command copies GRUB files and can update UEFI NVRAM. It does not create a new operating-system menu by itself. Generate or inspect the GRUB configuration separately with the tools provided by your distribution.
On this machine, successful output is usually brief or empty and the exit status is the useful result:
$ printf 'grub-install status: %s\n' "$?"
grub-install status: 0
$ find /boot/efi/EFI/BOOT_ID -maxdepth 2 -type f -print 2>/dev/null
/boot/efi/EFI/BOOT_ID/grubx64.efi
The exact EFI filename and directory contents can vary with package details and options. A zero status proves that this invocation completed; it does not prove that firmware will choose the new entry.
4. Install for legacy BIOS
Use this form only when the machine is intended to boot through legacy BIOS and you have identified the correct whole disk. Replace /dev/sdX with that verified device:
$ sudo grub-install \
--target=i386-pc \
--recheck \
/dev/sdX
The final argument is INSTALL_DEVICE, the system device filename. With the default boot directory, GRUB images are copied below /boot/grub, and BIOS boot code may also be installed in the device's boot area. This is why a BIOS command names a disk rather than the partition containing /boot.
Destructive-action checkpoint: before pressing Enter, compare the placeholder with lsblk output and confirm the disk serial or model if more than one disk is attached. A failed installation can be retried, but a write to the wrong disk is not an undoable configuration change. If the machine is remote, use a provider console or maintenance window and ensure you can boot rescue media.
Verify the files without assuming the boot itself has been fixed:
$ grub-install --version
grub-install (GRUB) 2.12-1ubuntu7.3
$ find /boot/grub -maxdepth 1 -type f -o -type d | sort | head
A BIOS installation can complete while another problem remains in the menu configuration, filesystem, firmware boot order or disk selection. Test the next boot only after checking those separately.
5. Handle an EFI system without NVRAM changes
Some repairs need files placed on the EFI System Partition but must not alter firmware variables. On EFI targets, add --no-nvram:
$ sudo grub-install \
--target=x86_64-efi \
--efi-directory=/boot/efi \
--bootloader-id=BOOT_ID \
--no-nvram
This prevents updates to the EFI Boot* and boot-device variables. It does not make the files bootable if firmware has no suitable entry or removable-media fallback. Use it when you have a deliberate firmware-entry plan, not as a general way to avoid investigating an error.
--removable is another EFI-only option. It marks the installation device as removable and changes where the loader is installed. Do not combine it casually with a normal internal-disk repair: removable-media behaviour is a different boot path. The installed manpage also provides --no-extra-removable to suppress removable-media code, but neither option is needed for the ordinary mounted-ESP command above.
6. Recover from a failed or unwanted installation
If the command fails, preserve the complete error and check the firmware mode, target, mount point and device again. Do not add --force until you understand the reported problem. Common causes include an unmounted or wrong EFI directory, missing target modules, booting the rescue system in the wrong mode, and selecting a partition where a BIOS disk is required.
If you installed into the wrong EFI directory but have not rebooted, unmounting it does not undo the copied files. Remove only the bootloader directory you explicitly created, after checking the path and name:
$ find /boot/efi/EFI/BOOT_ID -maxdepth 2 -type f -print
$ sudo rm -r --one-file-system /boot/efi/EFI/BOOT_ID
This removal is irreversible and can destroy a working entry if BOOT_ID is not exactly the directory you created. For NVRAM entries, inspect them with efibootmgr -v if that utility is installed. Removing a firmware entry is platform-specific; do not delete one merely because its display label is unfamiliar. If the wrong BIOS disk was written, leave the original disk contents alone and boot from rescue media or a provider console, then reinstall to the verified disk.
After any repair, regenerate the distribution's GRUB configuration only if required by your system, check the resulting file, and reboot during a maintenance window. Keep the rescue path open until the machine has completed a full boot.
Done means
- The installed
grub-installversion and package are recorded. - The running firmware mode matches the selected GRUB target.
- The EFI System Partition or BIOS disk was identified from read-only commands.
- The installation returned status 0 and the expected GRUB files are present.
- You know whether UEFI NVRAM was changed, and you have a rescue path before rebooting.
- No command used
--forceto hide an unresolved layout or device error.