Note: This bug is displayed in read-only format because the product is no longer active in Red Hat Bugzilla.

Bug 1336138

Summary: System Administrator guide: Documentation of grubby commands must be run as root
Product: [Retired] Fedora Documentation Reporter: Fabash <fh.fedora>
Component: system-administrator's-guideAssignee: Stephen Wadeley <swadeley>
Status: CLOSED CURRENTRELEASE QA Contact: Fedora Docs QA <docs-qa>
Severity: low Docs Contact:
Priority: unspecified    
Version: develCC: swadeley
Target Milestone: ---   
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2016-07-14 18:41:55 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description Fabash 2016-05-14 16:53:26 UTC
Description of problem:

In chapter: 21.4. Configuring GRUB 2 Using the grubby Tool

The following commands should be mentioned to be executed also as root, like the other ones, using a sharp caracter at begining of each command;

~]$ grubby --info=ALL

~]$ grubby --info /boot/vmlinuz-4.2.0-1.fc23.x86_64

grubby --remove-args="argX argY" --args="argA argB" --update-kernel /boot/kernel

~]$ grubby --info /boot/vmlinuz-4.2.0-1.fc23.x86_64

Otherwise, this error is displayed in the console:

Unable to access bootloader configuration file "/etc/grub2-efi.cfg": Permission denied

Version-Release number of selected component (if applicable):

Fedora 23 - System Administrator Guide

How reproducible:

Run command 'grubby --info /boot/vmlinuz-X.Y.Z-r.fc23.x86_64' as user

Steps to Reproduce:
1.
2.
3.

Actual results:
Error:
Unable to access bootloader configuration file "/etc/grub2-efi.cfg": Permission denied


Expected results:
Command is executed without error

Additional info:

Comment 1 Stephen Wadeley 2016-05-19 18:23:55 UTC
Hello

Thank you for raising this bug


I tested again on Fed24 test VM and it works for me, but I do not have secure boot:

test@localhost ~]$ grubby --info=ALL
index=0
kernel=/boot/vmlinuz-4.5.4-300.fc24.x86_64
args="ro rd.lvm.lv=fedora/root rd.lvm.lv=fedora/swap rhgb quiet LANG=en_US.UTF-8"
root=/dev/mapper/fedora-root
initrd=/boot/initramfs-4.5.4-300.fc24.x86_64.img
title=Fedora (4.5.4-300.fc24.x86_64) 24 (Workstation Edition)

others confirm your test, so it seems this is related to UEFI.

The grubby --info command occurs three times in the guide. I remember when I tested these commands when writing the chapter, that I thought it would be useful to know you could get this info from some remote user without asking them to become root.

I will therefore just make a note below the first occurrence of the command, but I will change the third one as that is after you already had to become root to update the ARGS

Comment 2 Stephen Wadeley 2016-05-19 19:26:56 UTC
commit 5416f33672175f46c37c100591657daf6b54b55d
Author: Stephen Wadeley <swadeley>
Date:   Thu May 19 20:35:16 2016 +0200

    On UEFI systems, all grubby commands must be as root
    
    Bug 1336138 - System Administrator guide: Documentation of grubby
    commands must be run as root