Merge remote-tracking branch 'origin/github/pr/68'
[grml-live.git] / grml-live
index 27e8e6a..f4d1f2e 100755 (executable)
--- a/grml-live
+++ b/grml-live
@@ -12,6 +12,9 @@
 export LANG=C
 export LC_ALL=C
 
+# avoid leaking into chroots
+unset TMPDIR
+
 # define function getfilesize before "set -e"
 if stat --help >/dev/null 2>&1; then
   getfilesize='stat -c %s'  # GNU stat
@@ -23,8 +26,10 @@ fi
 # disable for now since it seems to cause some problems
 # set -e
 
+# The line following this line is patched by debian/rules.
+GRML_LIVE_VERSION='***UNRELEASED***'
+
 # global variables
-GRML_LIVE_VERSION='0.17.0'
 PN="$(basename $0)"
 CMDLINE="$0 $@"
 ADDONS_LIST_FILE='/boot/isolinux/addons_list.cfg'
@@ -39,13 +44,14 @@ $PN - build process script for generating a (grml based) Linux Live-ISO
 Usage: $PN [options, see as follows]
 
    -a <architecture>       architecture; available values: i386 and amd64
-   -A                      ensure clean build and pack artifacts
+   -A                      clean build directories before and after running
    -b                      build the ISO without updating the chroot via FAI
    -B                      build the ISO without touching the chroot (skips cleanup)
    -c <classe[s]>          classes to be used for building the ISO via FAI
    -C <configfile>         configuration file for grml-live
    -d <date>               use specified date instead of build time as date of release
    -D <configdir>          use specified configuration directory instead of /etc/grml/fai
+   -e <iso_name>           extract ISO and squashfs contents from iso_name
    -F                      force execution without prompting
    -g <grml_name>          set the grml flavour name
    -h                      display short usage information and exit
@@ -58,13 +64,15 @@ Usage: $PN [options, see as follows]
    -q                      skip mksquashfs
    -Q                      skip netboot package build
    -r <release_name>       release name
-   -s <suite>              Debian suite; values: etch, lenny, squeeze, sid
+   -s <suite>              Debian suite/release, like: stable, testing, unstable
+   -S <script_directory>   place of scripts (defaults to /usr/share/grml-live/scripts)
    -t <template_directory> place of the templates
-   -T <tar_name>           unpack chroot tar archive before starting
    -u                      update existing chroot instead of rebuilding it from scratch
    -U <username>           arrange output to be owned by specified username
    -v <version_number>     specify version number of the release
    -V                      increase verbosity in the build process
+   -w <date>               wayback machine, build system using Debian archives
+                           from specified date
    -z                      use ZLIB instead of LZMA/XZ compression
 
 Usage examples:
@@ -72,20 +80,20 @@ Usage examples:
     $PN
     $PN -c GRMLBASE,GRML_FULL,AMD64 -o /dev/shm/grml
     $PN -c GRMLBASE,GRML_FULL,AMD64 -i grml_0.0-1.iso -v 0.0-1
-    $PN -c GRMLBASE,GRML_FULL,AMD64 -s sid -V -r 'grml-live rocks'
+    $PN -c GRMLBASE,GRML_FULL,AMD64 -s stable -V -r 'grml-ftw'
 
 More details: man grml-live + /usr/share/doc/grml-live/grml-live.html
               http://grml.org/grml-live/
 
 Please send your bug reports and feedback to the grml-team: http://grml.org/bugs/
 "
+   [ "$(id -u 2>/dev/null)" != 0 ] && echo "Please notice that this script requires root permissions."
 }
 
 # make sure it's possible to get usage information without being
 # root or actually executing the script
 if [ "$1" = '-h' -o "$1" = '--help' ] ; then
    usage
-   [ "$(id -u 2>/dev/null)" != 0 ] && echo "Please notice that this script requires root permissions."
    exit 0
 fi
 # }}}
@@ -120,6 +128,8 @@ BUILD_ONLY=''
 BUILD_DIRTY=''
 BOOTSTRAP_ONLY=''
 HOSTNAME=''
+USERNAME=''
+CONFIGDUMP=''
 
 # don't use colors/escape sequences
 if [ -r /lib/lsb/init-functions ] ; then
@@ -139,18 +149,30 @@ else
 fi
 
 # source main configuration file:
-LIVE_CONF=/etc/grml/grml-live.conf
-. $LIVE_CONF
+[ -z "$LIVE_CONF" ] && LIVE_CONF='/etc/grml/grml-live.conf'
+if ! [ -r "$LIVE_CONF" ] ; then
+  ewarn "Configuration file $LIVE_CONF can not be read, ignoring"
+else
+  einfo "Sourcing configuration file $LIVE_CONF"
+  . $LIVE_CONF
+  eend $?
+fi
 # }}}
 
 # umount all directories {{{
 umount_all() {
    # make sure we don't leave any mounts - FAI doesn't remove them always
+   umount $CHROOT_OUTPUT/proc/sys/fs/binfmt_misc 2>/dev/null || /bin/true
    umount $CHROOT_OUTPUT/proc 2>/dev/null || /bin/true
+   umount $CHROOT_OUTPUT/run  2>/dev/null || /bin/true
    umount $CHROOT_OUTPUT/sys  2>/dev/null || /bin/true
    umount $CHROOT_OUTPUT/dev/pts 2>/dev/null || /bin/true
    umount $CHROOT_OUTPUT/dev 2>/dev/null || /bin/true
 
+   if [ -n "$EXTRACT_ISO_NAME" ] ; then
+     umount "$EXTRACT_ISO_NAME" 2>/dev/null || /bin/true
+   fi
+
    # certain FAI versions sadly leave a ramdisk behind, so better safe than sorry
    if [ -x /usr/lib/fai/mkramdisk ] ; then
      /usr/lib/fai/mkramdisk -u "$(readlink -f ${CHROOT_OUTPUT}/var/lib/dpkg)" >/dev/null 2>&1 || /bin/true
@@ -165,17 +187,23 @@ umount_all() {
 bailout() {
   rm -f /var/run/fai/fai_softupdate_is_running \
         /var/run/fai/FAI_INSTALLATION_IN_PROGRESS
+  [ -n "$CONFIGDUMP"      ]  && rm -f  "$CONFIGDUMP"
   [ -n "$SQUASHFS_STDERR" ]  && rm -rf "$SQUASHFS_STDERR"
   umount_all
   [ -n "$1" ] && EXIT="$1" || EXIT="1"
   [ -n "$2" ] && eerror "$2">&2
-  if [ -n "$PACK_ARTIFACTS" ]; then
+  if [ -n "$CLEAN_ARTIFACTS" ]; then
     log "Cleaning up"
     einfo "Cleaning up"
     [ -n "${BUILD_OUTPUT}"  -a -d "${BUILD_OUTPUT}"  ] && rm -r "${BUILD_OUTPUT}"
     [ -n "${CHROOT_OUTPUT}" -a -d "${CHROOT_OUTPUT}" ] && rm -r "${CHROOT_OUTPUT}"
     eend 0
   fi
+
+  # get rid of automatically generated conffiles
+  rm -f ${GRML_FAI_CONFIG}/nfsroot.conf
+  rm -f ${GRML_FAI_CONFIG}/make-fai-nfsroot.conf
+
   if [ -n "$CHOWN_USER" ]; then
     log "Setting ownership"
     einfo "Setting ownership"
@@ -185,7 +213,6 @@ bailout() {
     [ -n "${ISO_OUTPUT}"     -a -d "${ISO_OUTPUT}"     ] && chown -R "${CHOWN_USER}:" "${ISO_OUTPUT}"
     [ -n "${LOG_OUTPUT}"     -a -d "${LOG_OUTPUT}"     ] && chown -R "${CHOWN_USER}:" "${LOG_OUTPUT}"
     [ -n "${NETBOOT}"        -a -d "${NETBOOT}"        ] && chown -R "${CHOWN_USER}:" "${NETBOOT}"
-    [ -n "${CHROOT_ARCHIVE}" -a -f "${CHROOT_ARCHIVE}" ] && chown -R "${CHOWN_USER}:" "${CHROOT_ARCHIVE}"
     eend 0
   fi
   log "------------------------------------------------------------------------------"
@@ -252,12 +279,12 @@ extend_string_end() {
 # This is because:
 #   * We assume that the chroot always has a "good" version of
 #     the file. Also it makes sources handling easier.
-#   * On unstable, we Recommend the Debian packages containing
+#   * On unstable, we recommend the Debian packages containing
 #     these files. The user can override them by putting his
 #     "better" version into the chroot.
-#   * On stable, the Debian packages are probably not available,
-#     or outdated, so we look in TEMPLATE_DIRECTORY/compat first, where
-#     our grml-live-compat package installs current file versions.
+#   * With older releases the Debian packages are probably
+#     not available, so we look in TEMPLATE_DIRECTORY/compat,
+#     where a (custom) package might install current file versions.
 copy_addon_file() {
   DEST="${BUILD_OUTPUT}/boot/$3"
   if [ ! -d "${DEST}/" ]; then
@@ -269,7 +296,7 @@ copy_addon_file() {
     return $?
   fi
   if [ -e "${TEMPLATE_DIRECTORY}/compat/$3/$1" ]; then
-    log   "Copying $1 from grml-live-compat"
+    log   "Copying $1 from ${TEMPLATE_DIRECTORY}/compat"
     cp "${TEMPLATE_DIRECTORY}/compat/$3/$1" "${DEST}/"
     return $?
   fi
@@ -283,20 +310,56 @@ copy_addon_file() {
   ewarn "$msg" ; eend 1
   log "copy_addon_file: $msg"
 }
+
+# replace placeholders in template files with actual information
+adjust_boot_files() {
+  if [ -z "$1" ] ; then
+    echo "Usage: adjust_boot_files <template_file>" >&2
+    exit 1
+  fi
+
+  for file in "$@" ; do
+    if [ -r "${file}" ] && [ -f "${file}" ] ; then
+      sed -i "s/%ARCH%/$ARCH/g"                    "${file}"
+      sed -i "s/%DATE%/$DATE/g"                    "${file}"
+      sed -i "s/%DISTRI_INFO%/$DISTRI_INFO/g"      "${file}"
+      sed -i "s/%DISTRI_NAME%/$DISTRI_NAME/g"      "${file}"
+      sed -i "s/%DISTRI_SPLASH%/$DISTRI_SPLASH/g"  "${file}"
+      sed -i "s/%GRML_NAME%/$GRML_NAME/g"          "${file}"
+      sed -i "s/%SQUASHFS_NAME%/$SQUASHFS_NAME/g"  "${file}"
+      sed -i "s/%RELEASE_INFO%/$RELEASE_INFO/g"    "${file}"
+      sed -i "s/%SHORT_NAME%/$SHORT_NAME/g"        "${file}"
+      sed -i "s/%VERSION%/$VERSION/g"              "${file}"
+      if [ -n "${BOOT_FILE}" ] ; then
+        sed -i "s;%BOOT_FILE%;$BOOT_FILE;g"        "${file}"
+      fi
+
+      [ -n "$DEFAULT_BOOTOPTIONS" ] && sed -i "s; boot=live; boot=live $DEFAULT_BOOTOPTIONS;"  "${file}"
+
+      if [ -n "$NO_BOOTID" ] ; then
+        sed -i "s/ bootid=%BOOTID%//g" "${file}" # drop bootid bootoption
+      else
+        sed -i "s/%BOOTID%/$BOOTID/g" "${file}" # adjust bootid=... argument
+      fi
+    fi
+  done
+}
 # }}}
 
 # command line parsing {{{
-while getopts "a:C:c:d:D:g:i:I:o:r:s:t:T:U:v:AbBFnNqQuVz" opt; do
+while getopts "a:C:c:d:D:e:g:i:I:o:r:s:S:t:U:v:w:AbBFhnNqQuVz" opt; do
   case "$opt" in
     a) ARCH="$OPTARG" ;;
-    A) PACK_ARTIFACTS=1 ;;
+    A) CLEAN_ARTIFACTS=1 ;;
     b) BUILD_ONLY=1 ;;
     B) BUILD_DIRTY=1 ;;
     c) CLASSES="$OPTARG" ;;
     C) LOCAL_CONFIG="$(readlink -f $OPTARG)" ;;
     d) DATE="$OPTARG" ;;
     D) GRML_FAI_CONFIG="$(readlink -f $OPTARG)" ;;
+    e) EXTRACT_ISO_NAME="$(readlink -f $OPTARG)" ;;
     g) GRML_NAME="$OPTARG" ;;
+    h) usage ; bailout 0 ;;
     i) ISO_NAME="$OPTARG" ;;
     I) CHROOT_INSTALL="$OPTARG" ;;
     n) SKIP_MKISOFS=1 ;;
@@ -306,18 +369,24 @@ while getopts "a:C:c:d:D:g:i:I:o:r:s:t:T:U:v:AbBFnNqQuVz" opt; do
     Q) SKIP_NETBOOT=1 ;;
     r) RELEASENAME="$OPTARG" ;;
     s) SUITE="$OPTARG" ;;
+    S) SCRIPTS_DIRECTORY="$OPTARG";;
     t) TEMPLATE_DIRECTORY="$OPTARG";;
-    T) UNPACK_CHROOT="$(readlink -f $OPTARG)" ;;
     v) VERSION="$OPTARG" ;;
     F) FORCE=1 ;;
     u) UPDATE=1 ;;
     U) CHOWN_USER="$OPTARG" ;;
     V) VERBOSE="-v" ;;
+    w) export WAYBACK_DATE="$OPTARG" ;;
     z) SQUASHFS_ZLIB=1 ;;
-    ?) echo "invalid option -$OPTARG" >&2; bailout 1 ;;
+    ?) echo "invalid option -$OPTARG" >&2; usage; bailout 1 ;;
   esac
 done
 shift $(($OPTIND - 1))  # set ARGV to the first not parsed commandline parameter
+
+if [ -n "$1" ] ; then
+  echo "Error: unknown argument '$1' in options. Exiting to avoid possible data loss." >&2
+  bailout 1
+fi
 # }}}
 
 # read local (non-packaged) configuration {{{
@@ -350,27 +419,27 @@ fi
 [ -n "$BOOT_METHOD" ]             || BOOT_METHOD='isolinux'
 [ -n "$CLASSES" ]                 || CLASSES="GRMLBASE,GRML_FULL,$(echo ${ARCH} | tr 'a-z' 'A-Z')"
 [ -n "$DATE" ]                    || DATE="$(date +%Y-%m-%d)"
-[ -n "$DISTRI_INFO" ]             || DISTRI_INFO='Grml - Live Linux for system administrators   '
+[ -n "$DISTRI_INFO" ]             || DISTRI_INFO='Grml - Live Linux for system administrators'
 [ -n "$DISTRI_NAME" ]             || DISTRI_NAME="grml"
 [ -n "$DISTRI_SPLASH" ]           || DISTRI_SPLASH='grml.png'
 [ -n "$FORCE_ISO_REBUILD" ]       || FORCE_ISO_REBUILD="false"
 [ -n "$GRML_FAI_CONFIG" ]         || GRML_FAI_CONFIG='/etc/grml/fai'
 [ -n "$GRML_NAME" ]               || GRML_NAME='grml'
 [ -n "$HOSTNAME" ]                || HOSTNAME='grml'
-[ -n "$HYBRID_METHOD" ]           || HYBRID_METHOD='manifold'
-[ -n "$NFSROOT_CONF" ]            || NFSROOT_CONF="${GRML_FAI_CONFIG}/make-fai-nfsroot.conf"
+[ -n "$HYBRID_METHOD" ]           || HYBRID_METHOD='isohybrid'
 [ -n "$RELEASENAME" ]             || RELEASENAME='grml-live rocks'
+[ -n "$SECURE_BOOT" ]             || SECURE_BOOT='disable'
 [ -n "$SQUASHFS_EXCLUDES_FILE" ]  || SQUASHFS_EXCLUDES_FILE="${GRML_FAI_CONFIG}/config/grml/squashfs-excludes"
-[ -n "$SUITE" ]                   || SUITE='squeeze'
+[ -n "$SUITE" ]                   || SUITE='testing'
 [ -n "$TEMPLATE_DIRECTORY" ]      || TEMPLATE_DIRECTORY='/usr/share/grml-live/templates'
+[ -n "$SCRIPTS_DIRECTORY" ]       || SCRIPTS_DIRECTORY='/usr/share/grml-live/scripts'
 [ -n "$USERNAME" ]                || USERNAME='grml'
 [ -n "$VERSION" ]                 || VERSION='0.0.1'
 
 # output specific stuff, depends on $OUTPUT (iff not set):
-[ -n "$OUTPUT" ]           || OUTPUT='/grml/grml-live'
+[ -n "$OUTPUT" ]           || OUTPUT="$PWD/grml/"
 [ -n "$BUILD_OUTPUT" ]     || BUILD_OUTPUT="$OUTPUT/grml_cd"
 [ -n "$CHROOT_OUTPUT" ]    || CHROOT_OUTPUT="$OUTPUT/grml_chroot"
-[ -n "$CHROOT_ARCHIVE" ]   || CHROOT_ARCHIVE="$OUTPUT/$(basename $CHROOT_OUTPUT).tgz"
 [ -n "$ISO_OUTPUT" ]       || ISO_OUTPUT="$OUTPUT/grml_isos"
 [ -n "$LOG_OUTPUT" ]       || LOG_OUTPUT="$OUTPUT/grml_logs"
 [ -n "$REPORTS" ]          || REPORTS="${LOG_OUTPUT}/reports/"
@@ -411,7 +480,7 @@ if [ -z "$FORCE" ] ; then
    [ -n "$LOCAL_CONFIG" ]        && echo "  Configuration:     $LOCAL_CONFIG"
    [ -n "$GRML_FAI_CONFIG" ]     && echo "  Config directory:  $GRML_FAI_CONFIG"
    echo "  main directory:    $OUTPUT"
-   [ -n "$UNPACK_CHROOT" ]       && echo "  Chroot from:       $UNPACK_CHROOT"
+   [ -n "$EXTRACT_ISO_NAME" ]    && echo "  Extract ISO:       $EXTRACT_ISO_NAME"
    [ -n "$CHROOT_OUTPUT" ]       && echo "  Chroot target:     $CHROOT_OUTPUT"
    [ -n "$BUILD_OUTPUT" ]        && echo "  Build target:      $BUILD_OUTPUT"
    [ -n "$ISO_OUTPUT" ]          && echo "  ISO target:        $ISO_OUTPUT"
@@ -434,7 +503,7 @@ if [ -z "$FORCE" ] ; then
    [ -n "$SQUASHFS_ZLIB" ]       && echo "  Using ZLIB (instead of LZMA/XZ) compression."
    [ -n "$SQUASHFS_OPTIONS" ]    && echo "  Using SQUASHFS_OPTIONS ${SQUASHFS_OPTIONS}"
    [ -n "$VERBOSE" ]             && echo "  Using VERBOSE mode."
-   [ -n "$PACK_ARTIFACTS" ]      && echo "  Will prepare packed artifacts and ensure clean build."
+   [ -n "$CLEAN_ARTIFACTS" ]     && echo "  Will clean output before and after running."
    [ -n "$UPDATE" ]              && echo "  Executing UPDATE instead of fresh installation."
    if [ -n "$BOOTSTRAP_ONLY" ] ; then
      echo "  Bootstrapping only and not building (files for) ISO."
@@ -449,14 +518,16 @@ if [ -z "$FORCE" ] ; then
    echo -n "Is this ok for you? [y/N] "
    read a
    if ! [ "$a" = 'y' -o "$a" = 'Y' ] ; then
-      bailout 1 "Exiting as requested."
+      CLEAN_ARTIFACTS=0
+      echo "Exiting as requested."
+      exit 0
    fi
    echo
 fi
 # }}}
 
 # clean up before start {{{
-if [ -n "${PACK_ARTIFACTS}" ]; then
+if [ -n "${CLEAN_ARTIFACTS}" ]; then
   echo "Wiping old artifacts"
   [ -n "${CHROOT_OUTPUT}"  -a -d "${CHROOT_OUTPUT}"  ] && rm -r "${CHROOT_OUTPUT}"
   [ -n "${BUILD_OUTPUT}"   -a -d "${BUILD_OUTPUT}"   ] && rm -r "${BUILD_OUTPUT}"
@@ -517,31 +588,56 @@ log "$CMDLINE"
 einfo "Logging actions to logfile $LOGFILE"
 # }}}
 
-# unpack chroot {{{
-if [ -n "${UNPACK_CHROOT}" ]; then
-  log "Unpacking chroot from ${UNPACK_CHROOT}"
-  einfo "Unpacking chroot from ${UNPACK_CHROOT}"
-  [ -d "$CHROOT_OUTPUT" ] || mkdir -p "${CHROOT_OUTPUT}"
-  tar -xf "${UNPACK_CHROOT}" -C "${CHROOT_OUTPUT}/" --strip-components 1 ; RC=$?
-  if [ "$RC" != 0 ] ; then
+# dump config variables into file, for script access {{{
+CONFIGDUMP=$(mktemp)
+set | egrep \
+  '^(GRML_NAME|RELEASENAME|DATE|VERSION|SUITE|ARCH|DISTRI_NAME|USERNAME|HOSTNAME|APT_PROXY)=' \
+  > ${CONFIGDUMP}
+# }}}
+
+# unpack iso/squashfs {{{
+extract_iso() {
+if [ -n "$EXTRACT_ISO_NAME" ]; then
+  log "Unpacking ISO from ${EXTRACT_ISO_NAME}"
+  einfo "Unpacking ISO from ${EXTRACT_ISO_NAME}"
+  local mountpoint=$(mktemp -d)
+  local rc=0
+  mount -o loop "${EXTRACT_ISO_NAME}" "$mountpoint" ; rc=$?
+  if [ "$rc" != 0 ]; then
+    rmdir "$mountpoint"
+    log "mount failed"
+    eerror "mount failed"
+    eend 1
+    bailout 1
+  fi
+
+  if ls "${mountpoint}"/live/*/*.squashfs 2>/dev/null | grep -q . ; then # ISOs >=2011.12
+    log "Using ${mountpoint}/live/*/*.squashfs for unsquashfs"
+    unsquashfs -d "${CHROOT_OUTPUT}" "${mountpoint}"/live/*/*.squashfs ; rc=$?
+  elif ls "${mountpoint}"/live/*.squashfs 2>/dev/null | grep -q . ; then # ISOs before 2011.12
+    log "Using ${mountpoint}/live/*.squashfs for unsquashfs"
+    unsquashfs -d "${CHROOT_OUTPUT}" "${mountpoint}"/live/*.squashfs ; rc=$?
+  else
+    log "Error: Could not find any *.squashfs files on the ISO"
+    eerror "Error: Could not find any *.squashfs files on the ISO"
     eend 1
     bailout 1
   fi
-  eend 0
-fi
-# }}}
 
-# cleanup CHROOT_ARCHIVE now {{{
-if [ -n "${PACK_ARTIFACTS}" ]; then
-  # can't do this earlier, as UNPACK_CHROOT might point to CHROOT_ARCHIVE
-  [ -n "${CHROOT_ARCHIVE}" -a -f "${CHROOT_ARCHIVE}" ] && rm "${CHROOT_ARCHIVE}"
+  umount "$mountpoint"
+  rmdir "$mountpoint"
+  if [ "$rc" != 0 ]; then
+    log "unsquashfs failed"
+    eerror "unsquashfs failed"
+    eend 1
+    bailout 1
+  fi
 fi
+}
+extract_iso
 # }}}
 
 # on-the-fly configuration {{{
-if [ -n "$FAI_DEBOOTSTRAP" ] ; then
-  sed "s#^FAI_DEBOOTSTRAP=.*#FAI_DEBOOTSTRAP=\"$FAI_DEBOOTSTRAP\"#" "$NFSROOT_CONF" | sponge "$NFSROOT_CONF"
-fi
 
 # does this suck? YES!
 # /usr/share/debootstrap/scripts/unstable does not exist, instead use 'sid':
@@ -551,15 +647,9 @@ case $SUITE in
 esac
 export SUITE # make sure it's available in FAI scripts
 
-for file in "$LIVE_CONF" "$LOCAL_CONFIG" "$NFSROOT_CONF" ; do
-    if [ -n "$file" ] ; then
-       sed "s|^FAI_DEBOOTSTRAP=\"[a-z]* |FAI_DEBOOTSTRAP=\"$SUITE |" "$file" | sponge "$file"
-    fi
-done
-
 # validate whether the specified architecture class matches the
 # architecture (option), otherwise installation of kernel will fail
-if echo $CLASSES | grep -qi i386 ; then
+if echo $CLASSES | grep -qw I386 ; then
    if ! [[ "$ARCH" == "i386" ]] ; then
       log    "Error: You specified the I386 class but are trying to build something else (AMD64?)."
       eerror "Error: You specified the I386 class but are trying to build something else (AMD64?)."
@@ -577,11 +667,35 @@ elif echo $CLASSES | grep -qi amd64 ; then
    fi
 fi
 
-if grep -q -- 'FAI_DEBOOTSTRAP_OPTS.*--arch' "$NFSROOT_CONF" ; then
-   sed "s/--arch [a-z0-9]* /--arch $ARCH /" "$NFSROOT_CONF" | sponge "$NFSROOT_CONF"
-else
-   sed "s|^FAI_DEBOOTSTRAP_OPTS=\"\(.*\)|FAI_DEBOOTSTRAP_OPTS=\"--arch $ARCH \1|" "$NFSROOT_CONF" | sponge "$NFSROOT_CONF"
+# generate nfsroot configuration for FAI on the fly
+if [ -z "$FAI_DEBOOTSTRAP" ] ; then
+  if [ -n "$WAYBACK_DATE" ] ; then
+    FAI_DEBOOTSTRAP="$SUITE http://snapshot.debian.org/archive/debian/$WAYBACK_DATE/"
+  else
+    FAI_DEBOOTSTRAP="$SUITE http://ftp.debian.org/debian"
+  fi
+fi
+
+if [ -z "$FAI_DEBOOTSTRAP_OPTS" ] ; then
+  FAI_DEBOOTSTRAP_OPTS="--exclude=info,tasksel,tasksel-data --include=aptitude --arch $ARCH"
 fi
+
+# create backup of old (not yet automatically generated) config file
+if [ -f "${GRML_FAI_CONFIG}/make-fai-nfsroot.conf" ] ; then
+  if ! grep -q 'This is an automatically generated file by grml-live' "${GRML_FAI_CONFIG}/make-fai-nfsroot.conf" ; then
+    ewarn "Found old ${GRML_FAI_CONFIG}/make-fai-nfsroot.conf - moving to ${GRML_FAI_CONFIG}/make-fai-nfsroot.conf.outdated"
+    mv "${GRML_FAI_CONFIG}/make-fai-nfsroot.conf" "${GRML_FAI_CONFIG}/make-fai-nfsroot.conf.outdated"
+    eend $?
+  fi
+fi
+
+echo "# This is an automatically generated file by grml-live.
+# Do NOT edit this file, your changes will be lost.
+FAI_DEBOOTSTRAP=\"$FAI_DEBOOTSTRAP\"
+FAI_DEBOOTSTRAP_OPTS=\"$FAI_DEBOOTSTRAP_OPTS\"
+# EOF " > "${GRML_FAI_CONFIG}/nfsroot.conf"
+# support FAI <=3.4.8, versions >=4.0 use nfsroot.conf
+( cd ${GRML_FAI_CONFIG} && ln -sf nfsroot.conf make-fai-nfsroot.conf )
 # }}}
 
 # CHROOT_OUTPUT - execute FAI {{{
@@ -591,12 +705,6 @@ if [ -n "$BUILD_DIRTY" ]; then
 else
    [ -n "$CHROOT_OUTPUT" ] || CHROOT_OUTPUT="$OUTPUT/grml_chroot"
 
-   # provide inform fai about the ISO we build
-   [ -d "$CHROOT_OUTPUT/etc/" ] || mkdir -p "$CHROOT_OUTPUT/etc/"
-   echo '# This file has been generated by grml-live.' > "$CHROOT_OUTPUT/etc/grml_live_version"
-   [ -n "$GRML_LIVE_VERSION" ] && echo "GRML_LIVE_VERSION=$GRML_LIVE_VERSION" >> "$CHROOT_OUTPUT/etc/grml_live_version"
-   [ -n "$SUITE" ] && echo "SUITE=$SUITE" >> "$CHROOT_OUTPUT/etc/grml_live_version"
-
    if [ -n "$UPDATE" -o -n "$BUILD_ONLY" ] ; then
       FAI_ACTION=softupdate
    else
@@ -626,49 +734,36 @@ else
       mkdir -p "${OUTPUT}/grml_sources/" "${CHROOT_OUTPUT}/grml-live/sources/"
       mount --bind "${OUTPUT}/grml_sources/" "${CHROOT_OUTPUT}/grml-live/sources/"
 
-      # tell dpkg to use "unsafe io" during the build
-      [ -d "$CHROOT_OUTPUT/etc/dpkg/dpkg.cfg.d" ] || mkdir -p "$CHROOT_OUTPUT/etc/dpkg/dpkg.cfg.d"
-      echo force-unsafe-io > "$CHROOT_OUTPUT/etc/dpkg/dpkg.cfg.d/unsafe-io"
-
       log "Executed FAI command line:"
-      log "BUILD_ONLY=$BUILD_ONLY BOOTSTRAP_ONLY=$BOOTSTRAP_ONLY GRML_LIVE_LOCAL_CONFIG=$LOCAL_CONFIG fai $VERBOSE -C $GRML_FAI_CONFIG -s file:///$GRML_FAI_CONFIG/config -c$CLASSES -u $HOSTNAME $FAI_ACTION $CHROOT_OUTPUT $FAI_ARGS"
-      BUILD_ONLY="$BUILD_ONLY" BOOTSTRAP_ONLY="$BOOTSTRAP_ONLY" GRML_LIVE_LOCAL_CONFIG="$LOCAL_CONFIG" fai $VERBOSE \
+      log "BUILD_ONLY=$BUILD_ONLY BOOTSTRAP_ONLY=$BOOTSTRAP_ONLY GRML_LIVE_CONFIG=$CONFIGDUMP WAYBACK_DATE=$WAYBACK_DATE fai $VERBOSE -C $GRML_FAI_CONFIG -s file:///$GRML_FAI_CONFIG/config -c$CLASSES -u $HOSTNAME $FAI_ACTION $CHROOT_OUTPUT $FAI_ARGS"
+      BUILD_ONLY="$BUILD_ONLY" BOOTSTRAP_ONLY="$BOOTSTRAP_ONLY" GRML_LIVE_CONFIG="$CONFIGDUMP" fai $VERBOSE \
                   -C "$GRML_FAI_CONFIG" -s "file:///$GRML_FAI_CONFIG/config" -c"$CLASSES" \
                   -u "$HOSTNAME" "$FAI_ACTION" "$CHROOT_OUTPUT" $FAI_ARGS | tee -a $LOGFILE
       RC="$PIPESTATUS" # notice: bash-only
 
-      rm -f "$CHROOT_OUTPUT/etc/dpkg/dpkg.cfg.d/unsafe-io"
-
-      FORCE_ISO_REBUILD=true
-
       if [ "$RC" != 0 ] ; then
          log    "Error: critical error while executing fai [exit code ${RC}]. Exiting."
          eerror "Error: critical error while executing fai [exit code ${RC}]. Exiting." ; eend 1
          bailout 1
-      else
-         einfo "Setting /etc/grml_version to $GRML_NAME $VERSION Release Codename $RELEASENAME [$DATE]"
-         log   "Setting /etc/grml_version to $GRML_NAME $VERSION Release Codename $RELEASENAME [$DATE]"
-         echo "$GRML_NAME $VERSION Release Codename $RELEASENAME [$DATE]" > $CHROOT_OUTPUT/etc/grml_version
-         chmod 644 $CHROOT_OUTPUT/etc/grml_version
-         einfo "Rebuilding initramfs"
-         # make sure new /etc/grml_version reaches initramfs, iterate over all
-         # present kernel versions (note: we can't really handle more than one
-         # kernel version anyway right now)
-         # chroot $CHROOT_OUTPUT update-initramfs -u -t => might break when using kernel-package :(
-         for initrd in "$(basename $CHROOT_OUTPUT/boot/vmlinuz-*)" ; do
-           if ! chroot $CHROOT_OUTPUT update-initramfs -k "${initrd##vmlinuz-}" -c ; then
-             einfo "Creating fresh initrd did not work, trying update instead:"
-             log   "Creating fresh initrd did not work, trying update instead:"
-             chroot $CHROOT_OUTPUT update-initramfs -k "${initrd##vmlinuz-}" -u
-           fi
-         done
-         eend $?
       fi
 
+      # provide inform fai about the ISO we build, needs to be provided
+      # *after* FAI stage, otherwise FAI skips the debootstrap stage if
+      # there is not BASEFILE (as it checks for presence of /etc) :(
+      echo '# This file has been generated by grml-live.' > "$CHROOT_OUTPUT/etc/grml_live_version"
+      [ -n "$GRML_LIVE_VERSION" ] && echo "GRML_LIVE_VERSION=$GRML_LIVE_VERSION" >> "$CHROOT_OUTPUT/etc/grml_live_version"
+      [ -n "$SUITE" ] && echo "SUITE=$SUITE" >> "$CHROOT_OUTPUT/etc/grml_live_version"
+
+      FORCE_ISO_REBUILD=true
+
       # move fai logs into grml_logs directory
       mkdir -p "$LOG_OUTPUT"/fai/
       cp -r "$CHROOT_OUTPUT"/var/log/fai/"$HOSTNAME"/last/* "$LOG_OUTPUT"/fai/
       rm -rf "$CHROOT_OUTPUT"/var/log/fai
+
+      # store copy of autogenerated configuration file
+      cp ${GRML_FAI_CONFIG}/nfsroot.conf "$LOG_OUTPUT"/fai/
+
       # copy fai package list
       cp "$CHROOT_OUTPUT"/var/log/install_packages.list "$LOG_OUTPUT"/fai/
       # fixup owners
@@ -693,6 +788,11 @@ else
          grep 'FAILED with exit code' $CHECKLOG/shell.log >> $LOGFILE && ERROR=6
       fi
 
+      if [ -r "$CHECKLOG/fai.log" ] ; then
+        grep 'updatebase.*FAILED with exit code' "$CHECKLOG/fai.log" >> "$LOGFILE" && ERROR=7
+        grep 'instsoft.*FAILED with exit code'   "$CHECKLOG/fai.log" >> "$LOGFILE" && ERROR=8
+      fi
+
       if [ -n "$ERROR" ] ; then
          log    "Error: there was a critical error [${ERROR}] during execution of stage 'fai dirinstall' [$(date)]"
          eerror "Error: there was a critical error during execution of stage 'fai dirinstall'"
@@ -751,11 +851,12 @@ else
 <testsuite name="grml-live-missing-packages" tests="${package_count}" time="1" failures="${package_errors}" errors="${package_errors}" skipped="0" assertions="0">
 EOF
 
-  for package in $(awk '{print $5}' "${CHECKLOG}/package_errors.log" | sed 's/\.$//') ; do
+  for package in $(awk '{print $1}' "${CHECKLOG}/package_errors.log" | sed 's;/;\\/;') ; do
+    failure_reason="$(awk "/$package/ {print \$2}" "${CHECKLOG}/package_errors.log")"
     cat >> "${REPORT_MISSING_PACKAGES}" << EOF
   <testcase name="test_missing_packages_${package}" time="0" assertions="0">
-    <failure type="RuntimeError" message="Package ${package} is missing">
-Package $package is missing in chroot
+    <failure type="${failure_reason}" message="Package ${package} is missing">
+Package $package is missing in chroot (${failure_reason})
   </failure>
   </testcase>
 EOF
@@ -784,6 +885,86 @@ EOF
 fi
 # }}}
 
+# grub boot {{{
+grub_setup() {
+  BOOTX64="/boot/bootx64.efi"
+  BOOTX32="/boot/bootia32.efi"
+  EFI_IMG="/boot/efi.img"
+
+  if [[ "$ARCH" == "amd64" ]] ; then
+    # important: this depends on execution of ${GRML_FAI_CONFIG}/config/scripts/GRMLBASE/45-grub-images
+    if ! [ -r "${CHROOT_OUTPUT}/${BOOTX64}" ] ; then
+      log    "Can not access GRUB efi image ${CHROOT_OUTPUT}/${BOOTX64}, required for Secure Boot support"
+      eerror "Can not access GRUB efi image ${CHROOT_OUTPUT}/${BOOTX64}, required for Secure Boot support" ; eend 1
+      log    "Possible reason is failure to run ${GRML_FAI_CONFIG}/config/scripts/GRMLBASE/45-grub-images"
+      ewarn  "Possible reason is failure to run ${GRML_FAI_CONFIG}/config/scripts/GRMLBASE/45-grub-images"
+      bailout 50
+    fi
+
+    dd if=/dev/zero of="${CHROOT_OUTPUT}/${EFI_IMG}" bs=4M count=1 2>/dev/null || bailout 50
+    mkfs.vfat -n GRML "${CHROOT_OUTPUT}/${EFI_IMG}" >/dev/null || bailout 51
+    mmd -i "${CHROOT_OUTPUT}/${EFI_IMG}" ::EFI || bailout 52
+    mmd -i "${CHROOT_OUTPUT}/${EFI_IMG}" ::EFI/BOOT || bailout 52
+
+    if [ "${SECURE_BOOT:-}" = "disable" ] ; then
+      log   "Secure Boot is disabled."
+      einfo "Secure Boot is disabled." ; eend 0
+
+      # install "$BOOTX64" as ::EFI/BOOT/bootx64.efi inside image file "$EFI_IMG":
+      mcopy -i "${CHROOT_OUTPUT}/${EFI_IMG}" "${CHROOT_OUTPUT}/${BOOTX64}" ::EFI/BOOT/bootx64.efi >/dev/null || bailout 53
+
+      log   "Generated 64-bit EFI image $BOOTX64"
+      einfo "Generated 64-bit EFI image $BOOTX64" ; eend 0
+    else
+      log   "Secure Boot is enabled [mode: $SECURE_BOOT]"
+      einfo "Secure Boot is enabled [mode: $SECURE_BOOT]" ; eend 0
+
+      if [ "${SECURE_BOOT}" = "ubuntu" ] ; then
+        local GRUBCFG_TEMPLATE="${TEMPLATE_DIRECTORY}/secureboot/grub.cfg"
+        local GRUBCFG_TMP=$(mktemp)
+
+        if ! [ -r "${GRUBCFG_TEMPLATE}" ] ; then
+          log    "Secure Boot template for GRUB [${GRUBCFG_TEMPLATE}] not found."
+          eerror "Secure Boot template for GRUB [${GRUBCFG_TEMPLATE}] not found." ; eend 1
+          bailout 54
+        fi
+
+        cp "${GRUBCFG_TEMPLATE}" "${GRUBCFG_TMP}"
+        adjust_boot_files "${GRUBCFG_TMP}"
+
+        mmd -i "${CHROOT_OUTPUT}/${EFI_IMG}" ::EFI/ubuntu || bailout 55
+        mcopy -i "${CHROOT_OUTPUT}/${EFI_IMG}" "${GRUBCFG_TMP}" ::EFI/ubuntu/grub.cfg || bailout 56
+        rm "${GRUBCFG_TMP}"
+
+        mcopy -i "${CHROOT_OUTPUT}/${EFI_IMG}" "${TEMPLATE_DIRECTORY}"/EFI/BOOT/grubx64.efi.signed ::EFI/BOOT/grubx64.efi >/dev/null || bailout 57
+        mcopy -i "${CHROOT_OUTPUT}/${EFI_IMG}" "${TEMPLATE_DIRECTORY}"/EFI/BOOT/shimx64.efi.signed ::EFI/BOOT/bootx64.efi >/dev/null || bailout 58
+
+        log   "Generated 64-bit Secure Boot (ubuntu) EFI image ${CHROOT_OUTPUT}/${EFI_IMG}"
+        einfo "Generated 64-bit Secure Boot (ubuntu) EFI image ${CHROOT_OUTPUT}/${EFI_IMG}" ; eend 0
+      fi
+    fi
+  fi
+
+  if [[ "$ARCH" == "i386" ]] ; then
+    if ! [ -r "${CHROOT_OUTPUT}/${BOOTX32}" ] ; then
+      log    "Can not access GRUB efi image ${CHROOT_OUTPUT}/${BOOTX32}."
+      eerror "Can not access GRUB efi image ${CHROOT_OUTPUT}/${BOOTX32}." ; eend 1
+      log    "Possible reason is failure to run ${GRML_FAI_CONFIG}/config/scripts/GRMLBASE/45-grub-images"
+      ewarn "Possible reason is failure to run ${GRML_FAI_CONFIG}/config/scripts/GRMLBASE/45-grub-images"
+      bailout 50
+    fi
+
+    dd if=/dev/zero of="${CHROOT_OUTPUT}/${EFI_IMG}" bs=4M count=1 2>/dev/null || bailout 50
+    mkfs.vfat -n GRML "${CHROOT_OUTPUT}/${EFI_IMG}" >/dev/null || bailout 51
+    mmd -i "${CHROOT_OUTPUT}/${EFI_IMG}" ::EFI || bailout 52
+    mmd -i "${CHROOT_OUTPUT}/${EFI_IMG}" ::EFI/BOOT || bailout 52
+    mcopy -i "${CHROOT_OUTPUT}/${EFI_IMG}" "${CHROOT_OUTPUT}/${BOOTX32}" ::EFI/BOOT/bootia32.efi >/dev/null || bailout 53
+    log   "Generated 32-bit EFI image $BOOTX32"
+    einfo "Generated 32-bit EFI image $BOOTX32" ; eend 0
+  fi
+}
+# }}}
+
 # BUILD_OUTPUT - execute arch specific stuff and squashfs {{{
 [ -n "$BUILD_OUTPUT" ] || BUILD_OUTPUT="$OUTPUT/grml_cd"
 mkdir -p "$BUILD_OUTPUT" || bailout 6 "Problem with creating $BUILD_OUTPUT for stage ARCH"
@@ -791,265 +972,334 @@ mkdir -p "$BUILD_OUTPUT" || bailout 6 "Problem with creating $BUILD_OUTPUT for s
 # prepare ISO
 if [ "$ARCH" = i386 ] || [ "$ARCH" = amd64 ] ; then
   if [ -n "$BOOTSTRAP_ONLY" ] ; then
-     log   "Skipping stage 'boot' as building with bootstrap only."
-     ewarn "Skipping stage 'boot' as building with bootstrap only." ; eend 0
+    log   "Skipping stage 'boot' as building with bootstrap only."
+    ewarn "Skipping stage 'boot' as building with bootstrap only." ; eend 0
   else
-    if [ -d "$BUILD_OUTPUT"/boot/isolinux -a -z "$UPDATE" -a -z "$BUILD_ONLY" ] ; then
-       log   "Skipping stage 'boot' as $BUILD_OUTPUT/boot/isolinux exists already."
-       ewarn "Skipping stage 'boot' as $BUILD_OUTPUT/boot/isolinux exists already." ; eend 0
+    # booting stuff:
+    mkdir -p "$BUILD_OUTPUT"/boot/isolinux
+    mkdir -p "$BUILD_OUTPUT"/boot/"${SHORT_NAME}"
+
+    # if we don't have an initrd we a) can't boot and b) there was an error
+    # during build, so check for the file:
+    INITRD="$(ls $CHROOT_OUTPUT/boot/initrd* 2>/dev/null| grep -v '.bak$' | sort -r | head -1)"
+    if [ -n "$INITRD" ] ; then
+      cp $INITRD "$BUILD_OUTPUT"/boot/"${SHORT_NAME}"/initrd.img
+      find $CHROOT_OUTPUT/boot/ -name initrd\*.bak -exec rm {} \;
     else
-       # booting stuff:
-       [ -d "$BUILD_OUTPUT"/boot/isolinux ] || mkdir -p "$BUILD_OUTPUT"/boot/isolinux
-       [ -d "$BUILD_OUTPUT"/boot/"${SHORT_NAME}" ] || mkdir -p "$BUILD_OUTPUT"/boot/"${SHORT_NAME}"
-
-       # if we don't have an initrd we a) can't boot and b) there was an error
-       # during build, so check for the file:
-       INITRD="$(ls $CHROOT_OUTPUT/boot/initrd* 2>/dev/null| grep -v '.bak$' | sort -r | head -1)"
-       if [ -n "$INITRD" ] ; then
-          cp $INITRD "$BUILD_OUTPUT"/boot/"${SHORT_NAME}"/initrd.gz
-          find $CHROOT_OUTPUT/boot/ -name initrd\*.bak -exec rm {} \;
-       else
-          log    "Error: No initrd found inside $CHROOT_OUTPUT/boot/ - Exiting"
-          eerror "Error: No initrd found inside $CHROOT_OUTPUT/boot/ - Exiting" ; eend 1
-          bailout 10
-       fi
+      log    "Error: No initrd found inside $CHROOT_OUTPUT/boot/ - Exiting"
+      eerror "Error: No initrd found inside $CHROOT_OUTPUT/boot/ - Exiting" ; eend 1
+      bailout 10
+    fi
 
-       KERNEL_IMAGE="$(ls $CHROOT_OUTPUT/boot/vmlinuz* 2>/dev/null | sort -r | head -1)"
-       if [ -n "$KERNEL_IMAGE" ] ; then
-          cp "$KERNEL_IMAGE" "$BUILD_OUTPUT"/boot/"${SHORT_NAME}"/linux26
-       else
-          log    "Error: No kernel found inside $CHROOT_OUTPUT/boot/ - Exiting"
-          eerror "Error: No kernel found inside $CHROOT_OUTPUT/boot/ - Exiting" ; eend 1
-          bailout 11
-       fi
+    KERNEL_IMAGE="$(ls $CHROOT_OUTPUT/boot/vmlinuz* 2>/dev/null | sort -r | head -1)"
+    if [ -n "$KERNEL_IMAGE" ] ; then
+      cp "$KERNEL_IMAGE" "$BUILD_OUTPUT"/boot/"${SHORT_NAME}"/vmlinuz
+    else
+      log    "Error: No kernel found inside $CHROOT_OUTPUT/boot/ - Exiting"
+      eerror "Error: No kernel found inside $CHROOT_OUTPUT/boot/ - Exiting" ; eend 1
+      bailout 11
+    fi
 
-       [ -n "$TEMPLATE_DIRECTORY" ] || TEMPLATE_DIRECTORY='/usr/share/grml-live/templates'
-       if ! [ -d "${TEMPLATE_DIRECTORY}"/boot ] ; then
-          log    "Error: ${TEMPLATE_DIRECTORY}/boot does not exist. Exiting."
-          eerror "Error: ${TEMPLATE_DIRECTORY}/boot does not exist. Exiting." ; eend 1
-          bailout 8
-       fi
+    # we need to set "$BOOTID" before we invoke adjust_boot_files for the
+    # first time, being inside grub_setup below
+    if [ -n "$NO_BOOTID" ] ; then
+      log   'Skipping bootid feature as requested via $NO_BOOTID.'
+      einfo 'Skipping bootid feature as requested via $NO_BOOTID.'
+    else
+      [ -n "$BOOTID" ] || BOOTID="$(echo ${GRML_NAME}${VERSION} | tr -d ',./;\- ')"
+      mkdir -p "$BUILD_OUTPUT"/conf
+      einfo "Generating /conf/bootid.txt with entry ${BOOTID}."
+      log   "Generating /conf/bootid.txt with entry ${BOOTID}."
+      echo "$BOOTID" > "$BUILD_OUTPUT"/conf/bootid.txt
+      eend $?
+    fi
 
-       # copy _required_ isolinux files
-       for file in ifcpu64.c32 isolinux.bin vesamenu.c32; do
-         copy_addon_file "${file}" /usr/lib/syslinux isolinux
-       done
+    # every recent Grml ISO ships a /conf/bootid.txt, though GRUB might find
+    # the /conf/bootid.txt of a different (Grml) ISO than the one that's
+    # supposed to be running, so within scripts/GRMLBASE/45-grub-images
+    # we generate a random filename, stored inside /boot/grub/bootfile.txt,
+    # which we place on the resulting ISO here
+    if [ -r "${CHROOT_OUTPUT}"/boot/grub/bootfile.txt ] ; then
+      mkdir -p "${BUILD_OUTPUT}"/conf
+      rm -f "${BUILD_OUTPUT}"/conf/bootfile*  # ensure we don't leave any old(er) files behind
+
+      einfo "Generating "${BUILD_OUTPUT}"/conf/bootfile* files"
+      log   "Generating "${BUILD_OUTPUT}"/conf/bootfile* files"
+
+      BOOT_FILE="/conf/bootfile_$(cat "${CHROOT_OUTPUT}"/boot/grub/bootfile.txt)"
+      echo "# This file is relevant for GRUB boot with the Grml ISO." > "${BUILD_OUTPUT}/${BOOT_FILE}"
+      # save information about the random filename inside /conf/bootfile.txt
+      echo "${BOOT_FILE}" > "${BUILD_OUTPUT}"/conf/bootfile.txt
+      eend $?
+    fi
 
-       # *always* copy files to output directory so the variables
-       # get adjusted according to the build.
-       cp ${TEMPLATE_DIRECTORY}/boot/isolinux/*  "$BUILD_OUTPUT"/boot/isolinux/
+    grub_setup
+
+    # EFI boot files
+    if [ -r "${CHROOT_OUTPUT}/boot/efi.img" -a -r "${CHROOT_OUTPUT}/boot/bootx64.efi" ] ; then
+      einfo "Copying 64-bit EFI boot files into ISO path."
+      log   "Copying 64-bit EFI boot files into ISO path."
+      RC=$0
+      cp "${CHROOT_OUTPUT}/boot/efi.img" "${BUILD_OUTPUT}/boot/" || RC=$?
+      mkdir -p "${BUILD_OUTPUT}/EFI/BOOT/" || RC=$?
+      cp "${CHROOT_OUTPUT}/boot/bootx64.efi" "${BUILD_OUTPUT}/EFI/BOOT/bootx64.efi" || RC=$?
+      eend $?
+    elif [ -r "${CHROOT_OUTPUT}/boot/efi.img" -a -r "${CHROOT_OUTPUT}/boot/bootia32.efi" ] ; then
+      einfo "Copying 32-bit EFI boot files into ISO path."
+      log "Copying 32-bit EFI boot files into ISO path."
+      RC=$0
+      cp "${CHROOT_OUTPUT}/boot/efi.img" "${BUILD_OUTPUT}/boot/" || RC=$?
+      mkdir -p "${BUILD_OUTPUT}/EFI/BOOT/" || RC=$?
+      cp "${CHROOT_OUTPUT}/boot/bootia32.efi" "${BUILD_OUTPUT}/EFI/BOOT/bootia32.efi" || RC=$?
+      eend $?
+    else
+      ewarn "No EFI boot files found, skipping." ; eend 0
+    fi
 
-       if [ -n "$NO_ADDONS" ] ; then
-          log   "Skipping installation of boot addons as requested via \$NO_ADDONS."
-          einfo "Skipping installation of boot addons as requested via \$NO_ADDONS."; eend 0
-       else
-          if ! [ -d "$TEMPLATE_DIRECTORY"/boot/addons ] ; then
-            log   "Boot addons not found, skipping therefore. (Consider installing package grml-live-addons)"
-            ewarn "Boot addons not found, skipping therefore. (Consider installing package grml-live-addons)" ; eend 0
-          else
-            # copy addons from system packages or grml-live-compat
-            copy_addon_file ipxe.lkrn /usr/lib/ipxe addons
-            copy_addon_file pci.ids /usr/share/misc addons
-            copy_addon_file memtest86+.bin /boot addons
-            for file in memdisk chain.c32 hdt.c32 menu.c32; do
-              copy_addon_file "${file}" /usr/lib/syslinux addons
-            done
-
-            # make memtest filename FAT16/8.3 compatible
-            mv "${BUILD_OUTPUT}/boot/addons/memtest86+.bin" \
-              "${BUILD_OUTPUT}/boot/addons/memtest"
-
-            # copy only files so we can handle bsd4grml on its own
-            for file in ${TEMPLATE_DIRECTORY}/boot/addons/* ; do
-              test -f $file && cp $file "$BUILD_OUTPUT"/boot/addons/
-            done
-
-            if [ -n "$NO_ADDONS_BSD4GRML" ] ; then
-               log   "Skipping installation of bsd4grml as requested via \$NO_ADDONS_BSD4GRML."
-               einfo "Skipping installation of bsd4grml as requested via \$NO_ADDONS_BSD4GRML."; eend 0
-            else
-               if [ -d "$TEMPLATE_DIRECTORY"/boot/addons/bsd4grml ] ; then
-                 cp -a ${TEMPLATE_DIRECTORY}/boot/addons/bsd4grml "$BUILD_OUTPUT"/boot/addons/
-               else
-                 log   "Missing addon file: bsd4grml"
-                 ewarn "Missing addon file: bsd4grml" ; eend 0
-               fi
-            fi
-
-          fi # no "$TEMPLATE_DIRECTORY"/boot/addons
-       fi # NO_ADDONS
-
-       if ! [ -d "${BUILD_OUTPUT}/boot/grub" ] ; then
-         mkdir -p "${BUILD_OUTPUT}/boot/grub"
-       fi
-       cp ${TEMPLATE_DIRECTORY}/boot/grub/* "$BUILD_OUTPUT"/boot/grub/
-
-       # copy grub files from target
-       cp -a "${CHROOT_OUTPUT}"/usr/lib/grub/*-pc/*.mod "${BUILD_OUTPUT}"/boot/grub/
-       cp -a "${CHROOT_OUTPUT}"/usr/lib/grub/*-pc/*.o "${BUILD_OUTPUT}"/boot/grub/
-       cp -a "${CHROOT_OUTPUT}"/usr/lib/grub/*-pc/*.lst "${BUILD_OUTPUT}"/boot/grub/
-       cp -a "${CHROOT_OUTPUT}"/usr/share/grub/ascii.pf2 "${BUILD_OUTPUT}"/boot/grub/
-       cp -a "${CHROOT_OUTPUT}"/boot/grub/core.img "${BUILD_OUTPUT}"/boot/grub/
-
-       if ! [ -d "${TEMPLATE_DIRECTORY}"/GRML ] ; then
-          log    "Error: ${TEMPLATE_DIRECTORY}/GRML does not exist. Exiting."
-          eerror "Error: ${TEMPLATE_DIRECTORY}/GRML does not exist. Exiting." ; eend 1
-          bailout 9
-       fi
+    [ -n "$TEMPLATE_DIRECTORY" ] || TEMPLATE_DIRECTORY='/usr/share/grml-live/templates'
+    if ! [ -d "${TEMPLATE_DIRECTORY}"/boot ] ; then
+      log    "Error: ${TEMPLATE_DIRECTORY}/boot does not exist. Exiting."
+      eerror "Error: ${TEMPLATE_DIRECTORY}/boot does not exist. Exiting." ; eend 1
+      bailout 8
+    fi
 
-       [ -d "$BUILD_OUTPUT"/GRML ] || mkdir "$BUILD_OUTPUT"/GRML
-       cp -a ${TEMPLATE_DIRECTORY}/GRML/* "$BUILD_OUTPUT"/GRML/
+    # copy _required_ isolinux files
+    if [ -d "${CHROOT_OUTPUT}/usr/lib/ISOLINUX" ] ; then
+      copy_addon_file isolinux.bin /usr/lib/ISOLINUX isolinux
+      for file in ${CHROOT_OUTPUT}/usr/lib/syslinux/modules/bios/*.c32 ; do
+        copy_addon_file "$(basename "$file")"  /usr/lib/syslinux/modules/bios/ isolinux
+      done
+    else # syslinux versions <= 3:4.05+dfsg-6+deb8u1
+      copy_addon_file isolinux.bin /usr/lib/syslinux isolinux
+      copy_addon_file ifcpu64.c32  /usr/lib/syslinux isolinux
+      copy_addon_file vesamenu.c32 /usr/lib/syslinux isolinux
+    fi
 
-       # adjust boot splash information:
-       RELEASE_INFO="$GRML_NAME $VERSION - Release Codename $RELEASENAME"
-       RELEASE_INFO="$(cut_string 68 "$RELEASE_INFO")"
-       RELEASE_INFO="$(extend_string_end 68 "$RELEASE_INFO")"
+    # *always* copy files to output directory so the variables
+    # get adjusted according to the build.
+    cp ${TEMPLATE_DIRECTORY}/boot/isolinux/*  "$BUILD_OUTPUT"/boot/isolinux/
 
-       if [ -r "$BUILD_OUTPUT"/GRML/grml-version ] ; then
-          sed -i "s/%RELEASE_INFO%/$GRML_NAME $VERSION - $RELEASENAME/" "$BUILD_OUTPUT"/GRML/grml-version
-          sed -i "s/%DATE%/$DATE/"                                      "$BUILD_OUTPUT"/GRML/grml-version
-       fi
+    mkdir -p "${BUILD_OUTPUT}/boot/grub"
+    cp -a ${TEMPLATE_DIRECTORY}/boot/grub/* "$BUILD_OUTPUT"/boot/grub/
 
-       # make sure the squashfs filename is set accordingly:
-       SQUASHFS_NAME="$GRML_NAME.squashfs"
+    if [ -n "$NO_ADDONS" ] ; then
+      rm -f "$BUILD_OUTPUT"/boot/grub/addons.cfg
+      log   "Skipping installation of boot addons as requested via \$NO_ADDONS."
+      einfo "Skipping installation of boot addons as requested via \$NO_ADDONS."; eend 0
+    else
+      if ! [ -d "$TEMPLATE_DIRECTORY"/boot/addons ] ; then
+        log   "Boot addons not found, skipping therefore. (Consider installing package grml-live-addons)"
+        ewarn "Boot addons not found, skipping therefore. (Consider installing package grml-live-addons)" ; eend 0
+      else
+        # copy addons from system packages or grml-live-addons
+        copy_addon_file ipxe.lkrn /usr/lib/ipxe addons
+        copy_addon_file pci.ids /usr/share/misc addons
+        copy_addon_file memtest86+.bin /boot addons
+
+        # since syslinux(-common) v3:6.03~pre1+dfsg-4 the files are in a
+        # different directory :(
+        if [ -d "${CHROOT_OUTPUT}/usr/lib/syslinux/modules/bios/" ] ; then
+          syslinux_modules_dir=/usr/lib/syslinux/modules/bios/
+        else
+          syslinux_modules_dir=/usr/lib/syslinux
+        fi
+        for file in chain.c32 hdt.c32 mboot.c32 menu.c32; do
+          copy_addon_file "${file}" "${syslinux_modules_dir}" addons
+        done
+
+        copy_addon_file memdisk /usr/lib/syslinux addons
+
+        # make memtest filename FAT16/8.3 compatible
+        mv "${BUILD_OUTPUT}/boot/addons/memtest86+.bin" \
+          "${BUILD_OUTPUT}/boot/addons/memtest"
+
+        # copy only files so we can handle bsd4grml on its own
+        for file in ${TEMPLATE_DIRECTORY}/boot/addons/* ; do
+          test -f $file && cp $file "$BUILD_OUTPUT"/boot/addons/
+        done
+
+        if [ -n "$NO_ADDONS_BSD4GRML" ] ; then
+          log   "Skipping installation of bsd4grml as requested via \$NO_ADDONS_BSD4GRML."
+          einfo "Skipping installation of bsd4grml as requested via \$NO_ADDONS_BSD4GRML."; eend 0
+        else
+          if [ -d "$TEMPLATE_DIRECTORY"/boot/addons/bsd4grml ] ; then
+            cp -a ${TEMPLATE_DIRECTORY}/boot/addons/bsd4grml "$BUILD_OUTPUT"/boot/addons/
+          else
+            log   "Missing addon file: bsd4grml"
+            ewarn "Missing addon file: bsd4grml" ; eend 0
+          fi
+        fi
+
+      fi # no "$TEMPLATE_DIRECTORY"/boot/addons
+    fi # NO_ADDONS
+
+    # generate loopback.cfg config file without depending on grub's regexp module
+    # which isn't available in Debian/squeeze
+    echo "## grub2 loopback configuration" > "${BUILD_OUTPUT}"/boot/grub/loopback.cfg
+    echo "source /boot/grub/header.cfg" >> "${BUILD_OUTPUT}"/boot/grub/loopback.cfg
+    for config in "${BUILD_OUTPUT}"/boot/grub/*_default.cfg "${BUILD_OUTPUT}"/boot/grub/*_options.cfg ; do
+      [ -r "$config" ] || continue
+      echo "source ${config##$BUILD_OUTPUT}" >> "${BUILD_OUTPUT}"/boot/grub/loopback.cfg
+    done
+    if [ -z "$NO_ADDONS" ] ; then
+      echo "source /boot/grub/addons.cfg" >> "${BUILD_OUTPUT}"/boot/grub/loopback.cfg
+    fi
+    echo "source /boot/grub/footer.cfg" >> "${BUILD_OUTPUT}"/boot/grub/loopback.cfg
+
+    # copy grub files from target
+    mkdir -p "${BUILD_OUTPUT}"/boot/grub/i386-pc/
+    cp -a "${CHROOT_OUTPUT}"/usr/lib/grub/*-pc/*.mod "${BUILD_OUTPUT}"/boot/grub/i386-pc/
+    cp -a "${CHROOT_OUTPUT}"/usr/lib/grub/*-pc/*.o "${BUILD_OUTPUT}"/boot/grub/i386-pc/
+    cp -a "${CHROOT_OUTPUT}"/usr/lib/grub/*-pc/*.lst "${BUILD_OUTPUT}"/boot/grub/i386-pc/
+    cp -a "${CHROOT_OUTPUT}"/usr/share/grub/ascii.pf2 "${BUILD_OUTPUT}"/boot/grub/
+    cp -a "${CHROOT_OUTPUT}"/boot/grub/core.img "${BUILD_OUTPUT}"/boot/grub/
+    cp -a "${CHROOT_OUTPUT}"/boot/grub/grub.img "${BUILD_OUTPUT}"/boot/grub/
+
+    # copy modules for UEFI grub, 64-bit
+    mkdir -p "${BUILD_OUTPUT}"/boot/grub/x86_64-efi/
+    cp -a "${CHROOT_OUTPUT}"/usr/lib/grub/x86_64-efi/*.{mod,lst} "${BUILD_OUTPUT}"/boot/grub/x86_64-efi/
+
+    # copy modules for UEFI grub, 32-bit
+    mkdir -p "${BUILD_OUTPUT}"/boot/grub/i386-efi/
+    cp -a "${CHROOT_OUTPUT}"/usr/lib/grub/i386-efi/*.{mod,lst} "${BUILD_OUTPUT}"/boot/grub/i386-efi/
+
+    if ! [ -d "${TEMPLATE_DIRECTORY}"/GRML ] ; then
+      log    "Error: ${TEMPLATE_DIRECTORY}/GRML does not exist. Exiting."
+      eerror "Error: ${TEMPLATE_DIRECTORY}/GRML does not exist. Exiting." ; eend 1
+      bailout 9
+    fi
 
-       if [ -n "$NO_BOOTID" ] ; then
-          log   'Skipping bootid feature as requested via $NO_BOOTID.'
-          einfo 'Skipping bootid feature as requested via $NO_BOOTID.'
-       else
-          [ -n "$BOOTID" ] || BOOTID="$(echo ${GRML_NAME}${VERSION} | tr -d ',./;\- ')"
-          [ -d "$BUILD_OUTPUT"/conf ] || mkdir "$BUILD_OUTPUT"/conf
-          einfo "Generating /conf/bootid.txt with entry ${BOOTID}."
-          log   "Generating /conf/bootid.txt with entry ${BOOTID}."
-          echo "$BOOTID" > "$BUILD_OUTPUT"/conf/bootid.txt
-          eend $?
-       fi
+    mkdir -p "$BUILD_OUTPUT"/GRML/"${GRML_NAME}"/
+    cp -a ${TEMPLATE_DIRECTORY}/GRML/* "$BUILD_OUTPUT"/GRML/"${GRML_NAME}"/
 
-       # adjust all variables in the templates with the according distribution information
-       for file in "${BUILD_OUTPUT}"/boot/isolinux/*.cfg "${BUILD_OUTPUT}"/boot/isolinux/*.msg \
-                   "${BUILD_OUTPUT}"/boot/grub/* ; do
-         if [ -r "${file}" ] ; then
-           sed -i "s/%ARCH%/$ARCH/g"                    "${file}"
-           sed -i "s/%DATE%/$DATE/g"                    "${file}"
-           sed -i "s/%DISTRI_INFO%/$DISTRI_INFO/g"      "${file}"
-           sed -i "s/%DISTRI_NAME%/$DISTRI_NAME/g"      "${file}"
-           sed -i "s/%DISTRI_SPLASH%/$DISTRI_SPLASH/g"  "${file}"
-           sed -i "s/%GRML_NAME%/$GRML_NAME/g"          "${file}"
-           sed -i "s/%SQUASHFS_NAME%/$SQUASHFS_NAME/g"  "${file}"
-           sed -i "s/%RELEASE_INFO%/$RELEASE_INFO/g"    "${file}"
-           sed -i "s/%SHORT_NAME%/$SHORT_NAME/g"        "${file}"
-           sed -i "s/%VERSION%/$VERSION/g"              "${file}"
-
-           [ -n "$DEFAULT_BOOTOPTIONS" ] && sed -i "s/ boot=live/ boot=live $DEFAULT_BOOTOPTIONS/"  "${file}"
-
-           if [ -n "$NO_BOOTID" ] ; then
-              sed -i "s/ bootid=%BOOTID%//g" "${file}" # drop bootid bootoption
-           else
-              sed -i "s/%BOOTID%/$BOOTID/g" "${file}" # adjust bootid=... argument
-           fi
-         fi
-       done
-
-       # adjust bootsplash accordingly but make sure the string has the according lenght
-       SQUASHFS_NAME="$(cut_string 20 "$SQUASHFS_NAME")"
-       SQUASHFS_NAME="$(extend_string_end 20 "$SQUASHFS_NAME")"
-       for file in f4 f5 ; do
-          if [ -r "${BUILD_OUTPUT}/boot/isolinux/${file}" ] ; then
-             sed -i "s/%SQUASHFS_NAME%/$SQUASHFS_NAME/" "${BUILD_OUTPUT}/boot/isolinux/${file}"
-             sed -i "s/%SQUASHFS_NAME%/$SQUASHFS_NAME/" "${BUILD_OUTPUT}/boot/isolinux/${file}"
-          fi
-       done
-
-       # generate addon list
-       rm -f "${BUILD_OUTPUT}/${ADDONS_LIST_FILE}"
-       for name in "${BUILD_OUTPUT}"/boot/isolinux/addon_*.cfg ; do
-         include_name=$(basename "$name")
-         echo "include $include_name"  >> "${BUILD_OUTPUT}/${ADDONS_LIST_FILE}"
-       done
-
-       if ! [ -r "${BUILD_OUTPUT}/boot/isolinux/${DISTRI_NAME}.cfg" ] || [ "$DISTRI_NAME" = "grml" ] ; then
-          log "including grmlmain.cfg in ${BUILD_OUTPUT}/boot/isolinux/distri.cfg"
-          echo "include grmlmain.cfg"    >  "${BUILD_OUTPUT}/boot/isolinux/distri.cfg"
-          echo "include default.cfg"     >  "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
-          echo "include menuoptions.cfg" >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
-          echo "include grml.cfg"        >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
-
-          for f in "${BUILD_OUTPUT}"/boot/isolinux/submenu*.cfg ; do
-            echo "include $(basename $f)"     >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
-          done
-
-          echo "include options.cfg"     >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
-          if [ ! -n "$NO_ADDONS" ] ; then
-            echo "include addons.cfg"    >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
-          fi
-          echo "include isoprompt.cfg"   >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
-          echo "include hd.cfg"          >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
-          echo "include hidden.cfg"      >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
-       else # assume we are building a custom distribution:
-          log "File ${BUILD_OUTPUT}/boot/isolinux/${DISTRI_NAME}.cfg found, using it."
-          einfo "File ${BUILD_OUTPUT}/boot/isolinux/${DISTRI_NAME}.cfg found, using it."
-          if grep -q "^include ${DISTRI_NAME}.cfg" "${BUILD_OUTPUT}/boot/isolinux/distri.cfg" ; then
-            log "include for ${DISTRI_NAME}.cfg already present, nothing to do."
-            eindent
-            einfo "include for ${DISTRI_NAME}.cfg already present, nothing to do."
-            eoutdent
-            eend $?
-         else
-            log "including ${DISTRI_NAME}.cfg in ${BUILD_OUTPUT}/boot/isolinux/distri.cfg"
-            echo "include ${DISTRI_NAME}.cfg" > "${BUILD_OUTPUT}/boot/isolinux/distri.cfg"
-            [ -n "$NO_ADDONS" ] || echo "include addons.cfg" >> "${BUILD_OUTPUT}/boot/isolinux/distri.cfg"
-          fi
-       fi
+    # adjust boot splash information:
+    RELEASE_INFO="$GRML_NAME $VERSION - Release Codename $RELEASENAME"
+    RELEASE_INFO="$(cut_string 68 "$RELEASE_INFO")"
+    RELEASE_INFO="$(extend_string_end 68 "$RELEASE_INFO")"
 
-       # use old style console based isolinux method only if requested:
-       if [[ "${ISOLINUX_METHOD}" == "console" ]] ; then
-          log 'Using console based isolinux method as requested via $ISOLINUX_METHOD.'
-          einfo 'Using console based isolinux method as requested via $ISOLINUX_METHOD.'
-          if grep -q '^include console.cfg' "${BUILD_OUTPUT}/boot/isolinux/distri.cfg" ; then
-            einfo "include for console.cfg already found, nothing to do."
-            eend 0
-          else
-            log "including console.cfg in ${BUILD_OUTPUT}/boot/isolinux/isolinux.cfg"
-            einfo "including console.cfg in ${BUILD_OUTPUT}/boot/isolinux/isolinux.cfg"
-            echo "include console.cfg" >> "${BUILD_OUTPUT}/boot/isolinux/isolinux.cfg"
-            eend $?
-          fi
-       else
-          log 'Using graphical boot menu.'
-          if grep -q '^include vesamenu.cfg' "${BUILD_OUTPUT}/boot/isolinux/isolinux.cfg" ; then
-            log "include for vesamenu.cfg already found, nothing to do."
-          else
-            log "including vesamenu.cfg in ${BUILD_OUTPUT}/boot/isolinux/isolinux.cfg"
-            echo "include vesamenu.cfg" >> "${BUILD_OUTPUT}/boot/isolinux/isolinux.cfg"
-          fi
-       fi
+    if [ -r "$BUILD_OUTPUT"/GRML/"${GRML_NAME}"/grml-version ] ; then
+      sed -i "s/%RELEASE_INFO%/$GRML_NAME $VERSION - $RELEASENAME/" "$BUILD_OUTPUT"/GRML/"${GRML_NAME}"/grml-version
+      sed -i "s/%DATE%/$DATE/"                                      "$BUILD_OUTPUT"/GRML/"${GRML_NAME}"/grml-version
+    fi
 
-       if [ -e "$BUILD_OUTPUT"/boot/addons/bsd4grml/boot.6 ]; then
-          sed -i "s/%RELEASE_INFO%/$GRML_NAME $VERSION - $RELEASENAME/" "$BUILD_OUTPUT"/boot/addons/bsd4grml/boot.6
-       fi
+    # make sure the squashfs filename is set accordingly:
+    SQUASHFS_NAME="$GRML_NAME.squashfs"
+
+    # adjust all variables in the templates with the according distribution information
+    adjust_boot_files "${BUILD_OUTPUT}"/boot/isolinux/*.cfg \
+      "${BUILD_OUTPUT}"/boot/isolinux/*.msg \
+      "${BUILD_OUTPUT}"/boot/grub/* \
+      "${BUILD_OUTPUT}"/boot/ubuntu/*
+
+    for param in ARCH DATE DISTRI_INFO DISTRI_NAME DISTRI_SPLASH GRML_NAME SQUASHFS_NAME \
+      RELEASE_INFO SHORT_NAME VERSION ; do
+      for file in $(find "${BUILD_OUTPUT}" -name "*%$param%*") ; do
+        value="$(eval echo '$'"$param")"
+        mv ${file} ${file/\%${param}\%/$value}
+      done
+    done
+
+    # adjust bootsplash accordingly but make sure the string has the according length
+    SQUASHFS_NAME="$(cut_string 20 "$SQUASHFS_NAME")"
+    SQUASHFS_NAME="$(extend_string_end 20 "$SQUASHFS_NAME")"
+    for file in f4 f5 ; do
+      if [ -r "${BUILD_OUTPUT}/boot/isolinux/${file}" ] ; then
+        sed -i "s/%SQUASHFS_NAME%/$SQUASHFS_NAME/" "${BUILD_OUTPUT}/boot/isolinux/${file}"
+        sed -i "s/%SQUASHFS_NAME%/$SQUASHFS_NAME/" "${BUILD_OUTPUT}/boot/isolinux/${file}"
+      fi
+    done
+
+    # generate addon list
+    rm -f "${BUILD_OUTPUT}/${ADDONS_LIST_FILE}"
+    for name in "${BUILD_OUTPUT}"/boot/isolinux/addon_*.cfg ; do
+      include_name=$(basename "$name")
+      echo "include $include_name"  >> "${BUILD_OUTPUT}/${ADDONS_LIST_FILE}"
+    done
+
+    if ! [ -r "${BUILD_OUTPUT}/boot/isolinux/${DISTRI_NAME}.cfg" ] || [ "$DISTRI_NAME" = "grml" ] ; then
+      log "including grmlmain.cfg in ${BUILD_OUTPUT}/boot/isolinux/distri.cfg"
+      echo "include grmlmain.cfg"    >  "${BUILD_OUTPUT}/boot/isolinux/distri.cfg"
+      echo "include default.cfg"     >  "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
+      echo "include menuoptions.cfg" >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
+      echo "include grml.cfg"        >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
+
+      for f in "${BUILD_OUTPUT}"/boot/isolinux/submenu*.cfg ; do
+        echo "include $(basename $f)"     >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
+      done
+
+      echo "include options.cfg"     >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
+      if [ -z "$NO_ADDONS" ] ; then
+        echo "include addons.cfg"    >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
+      fi
+      echo "include isoprompt.cfg"   >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
+      echo "include hd.cfg"          >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
+      echo "include hidden.cfg"      >> "${BUILD_OUTPUT}/boot/isolinux/grmlmain.cfg"
+    else # assume we are building a custom distribution:
+      log "File ${BUILD_OUTPUT}/boot/isolinux/${DISTRI_NAME}.cfg found, using it."
+      einfo "File ${BUILD_OUTPUT}/boot/isolinux/${DISTRI_NAME}.cfg found, using it."
+      if grep -q "^include ${DISTRI_NAME}.cfg" "${BUILD_OUTPUT}/boot/isolinux/distri.cfg" ; then
+        log "include for ${DISTRI_NAME}.cfg already present, nothing to do."
+        eindent
+        einfo "include for ${DISTRI_NAME}.cfg already present, nothing to do."
+        eoutdent
+        eend $?
+      else
+        log "including ${DISTRI_NAME}.cfg in ${BUILD_OUTPUT}/boot/isolinux/distri.cfg"
+        echo "include ${DISTRI_NAME}.cfg" > "${BUILD_OUTPUT}/boot/isolinux/distri.cfg"
+        if [ -z "$NO_ADDONS" ] ; then
+          echo "include addons.cfg" >> "${BUILD_OUTPUT}/boot/isolinux/distri.cfg"
+        fi
+      fi
+    fi
 
-       DPKG_LIST="/var/log/fai/$HOSTNAME/last/dpkg.list" # the dpkg --list output of the chroot
-       if ! [ -r "$DPKG_LIST" ] ; then
-          ewarn "$DPKG_LIST could not be read, ignoring to store package information on ISO therefore."
-       else
-          einfo "Storing package list information as /GRML/${GRML_NAME}-packages.txt on ISO."
-          cp "$DPKG_LIST" "${BUILD_OUTPUT}/GRML/${GRML_NAME}-packages.txt"
-          eend $?
-       fi
+    # use old style console based isolinux method only if requested:
+    if [[ "${ISOLINUX_METHOD}" == "console" ]] ; then
+      log 'Using console based isolinux method as requested via $ISOLINUX_METHOD.'
+      einfo 'Using console based isolinux method as requested via $ISOLINUX_METHOD.'
+      if grep -q '^include console.cfg' "${BUILD_OUTPUT}/boot/isolinux/distri.cfg" ; then
+        einfo "include for console.cfg already found, nothing to do."
+        eend 0
+      else
+        log "including console.cfg in ${BUILD_OUTPUT}/boot/isolinux/isolinux.cfg"
+        einfo "including console.cfg in ${BUILD_OUTPUT}/boot/isolinux/isolinux.cfg"
+        echo "include console.cfg" >> "${BUILD_OUTPUT}/boot/isolinux/isolinux.cfg"
+        eend $?
+      fi
+    else
+      log 'Using graphical boot menu.'
+      if grep -q '^include vesamenu.cfg' "${BUILD_OUTPUT}/boot/isolinux/isolinux.cfg" ; then
+        log "include for vesamenu.cfg already found, nothing to do."
+      else
+        log "including vesamenu.cfg in ${BUILD_OUTPUT}/boot/isolinux/isolinux.cfg"
+        echo "include vesamenu.cfg" >> "${BUILD_OUTPUT}/boot/isolinux/isolinux.cfg"
+      fi
+    fi
 
-       # autostart for Windows:
-       if [ -d "${TEMPLATE_DIRECTORY}/windows/autostart/" ] ; then
-          cp ${TEMPLATE_DIRECTORY}/windows/autostart/* "$BUILD_OUTPUT"/
-       fi
+    if [ -e "$BUILD_OUTPUT"/boot/addons/bsd4grml/boot.6 ]; then
+      sed -i "s/%RELEASE_INFO%/$GRML_NAME $VERSION - $RELEASENAME/" "$BUILD_OUTPUT"/boot/addons/bsd4grml/boot.6
+    fi
+
+    DPKG_LIST="/var/log/fai/$HOSTNAME/last/dpkg.list" # the dpkg --list output of the chroot
+    if ! [ -r "$DPKG_LIST" ] ; then
+      ewarn "$DPKG_LIST could not be read, ignoring to store package information on ISO therefore."
+    else
+      einfo "Storing package list information as /GRML/${GRML_NAME}/packages.txt on ISO."
+      cp "$DPKG_LIST" "${BUILD_OUTPUT}"/GRML/"${GRML_NAME}"/packages.txt
+      eend $?
+    fi
+
+    # autostart for Windows:
+    if [ -d "${TEMPLATE_DIRECTORY}/windows/autostart/" ] ; then
+      cp ${TEMPLATE_DIRECTORY}/windows/autostart/* "$BUILD_OUTPUT"/
+    fi
 
     FORCE_ISO_REBUILD=true
     einfo "Finished execution of stage 'boot'" ; eend 0
-    fi
   fi # BOOTSTRAP_ONLY
 else
-   log    'Error: Unsupported ARCH, sorry. Want to support it? Contribute!'
-   eerror 'Error: Unsupported ARCH, sorry. Want to support it? Contribute!' ; eend 1
-   bailout
+  log    'Error: Unsupported ARCH, sorry. Want to support it? Contribute!'
+  eerror 'Error: Unsupported ARCH, sorry. Want to support it? Contribute!' ; eend 1
+  bailout
 fi
 
 # support installation of local files into the chroot/ISO
@@ -1074,7 +1324,7 @@ elif [ -n "$SKIP_MKSQUASHFS" ] ; then
    log   "Skipping stage 'squashfs' as requested via option -q or -N"
    ewarn "Skipping stage 'squashfs' as requested via option -q or -N" ; eend 0
 else
-   [ -d "$BUILD_OUTPUT"/live ] || mkdir "$BUILD_OUTPUT"/live
+   mkdir -p "$BUILD_OUTPUT"/live/"${GRML_NAME}"/
    # make sure we don't leave (even an empty) base.tgz:
    [ -f "$CHROOT_OUTPUT/base.tgz" ] && rm -f "$CHROOT_OUTPUT/base.tgz"
 
@@ -1123,11 +1373,11 @@ else
    [ -n "$SQUASHFS_INFO_MSG" ] && SQUASHFS_INFO_MSG="using options: $SQUASHFS_INFO_MSG"
    einfo "Squashfs build information: running binary $SQUASHFS_BINARY $SQUASHFS_INFO_MSG"
 
-   log "$SQUASHFS_BINARY $CHROOT_OUTPUT/ $BUILD_OUTPUT/live/${GRML_NAME}.squashfs -noappend $SQUASHFS_OPTIONS"
+   log "$SQUASHFS_BINARY $CHROOT_OUTPUT/ $BUILD_OUTPUT/live/${GRML_NAME}/${GRML_NAME}.squashfs -noappend $SQUASHFS_OPTIONS"
 
-   if $SQUASHFS_BINARY $CHROOT_OUTPUT/ $BUILD_OUTPUT/live/"${GRML_NAME}".squashfs \
+   if $SQUASHFS_BINARY $CHROOT_OUTPUT/ $BUILD_OUTPUT/live/"${GRML_NAME}"/"${GRML_NAME}".squashfs \
       -noappend $SQUASHFS_OPTIONS 2>"${SQUASHFS_STDERR}" ; then
-      echo "${GRML_NAME}.squashfs" > $BUILD_OUTPUT/live/filesystem.module
+      echo "${GRML_NAME}.squashfs" > $BUILD_OUTPUT/live/"${GRML_NAME}"/filesystem.module
       log "Finished execution of stage 'squashfs' [$(date)]"
       einfo "Finished execution of stage 'squashfs'" ; eend 0
    else
@@ -1144,8 +1394,8 @@ fi
 
 # create md5sum file:
 if [ -z "$BOOTSTRAP_ONLY" ] ; then
-  ( cd $BUILD_OUTPUT/GRML &&
-  find .. -type f -not -name md5sums -not -name isolinux.bin -exec md5sum {} \; > md5sums )
+  ( cd $BUILD_OUTPUT/GRML/"${GRML_NAME}" &&
+  find ../.. -type f -not -name md5sums -not -name isolinux.bin -exec md5sum {} \; > md5sums )
 fi
 # }}}
 
@@ -1155,12 +1405,14 @@ fi
 
 if [ "$BOOT_METHOD" = "isolinux" ] ; then
    BOOT_ARGS="-no-emul-boot -boot-load-size 4 -boot-info-table -b boot/isolinux/isolinux.bin -c boot/isolinux/boot.cat"
+   if [ "$HYBRID_METHOD" = "isohybrid" ] ; then
+     EFI_ARGS="-isohybrid-mbr /usr/lib/ISOLINUX/isohdpfx.bin -eltorito-alt-boot -e boot/efi.img -no-emul-boot -isohybrid-gpt-basdat"
+   fi
 elif [ "$BOOT_METHOD" = "grub2" ] ; then
    BOOT_ARGS="-no-emul-boot -boot-load-size 4 -b boot/grub/toriboot.bin"
 fi
 
-# Just until http://bts.grml.org/grml/issue945 has been resolved.
-# HYBRID_METHOD defaults to manifold, so make sure the default works OOTB.
+# Work around http://bts.grml.org/grml/issue945
 if [[ $BOOT_METHOD != isolinux && ($HYBRID_METHOD = isohybrid || $HYBRID_METHOD = manifold) ]]; then
   log   "Setting HYBRID_METHOD to grub2 as hybrid mode does not work with isohybrid yet."
   ewarn "Setting HYBRID_METHOD to grub2 as hybrid mode does not work with isohybrid yet."
@@ -1195,47 +1447,28 @@ else
       bailout
    fi
 
-   case "$ARCH" in
-     amd64)
-       # using -eltorito-alt-boot is limited to xorriso for now
-       case "$MKISOFS" in
-         xorriso*)
-           einfo "Using xorriso for ISO generation." ;  eend 0
-           eindent
-
-           if ! dpkg --compare-versions $(dpkg-query -W -f='${Version}\n' xorriso 2>/dev/null) gt-nl 1.1.6-1 ; then
-             log   "Disabling (U)EFI boot support since xorriso version is not recent enough."
-             ewarn "Disabling (U)EFI boot support since xorriso version is not recent enough." ; eend 0
-           else
-             log   "xorriso with -eltorito-alt-boot present, enabling (U)EFI boot support."
-             einfo "xorriso with -eltorito-alt-boot present, enabling (U)EFI boot support." ; eend 0
-
-             if [ -r "${CHROOT_OUTPUT}/var/lib/grml_live_efi.img" ] ; then
-               einfo "Found /var/lib/grml_live_efi.img - moving to /boot/efi.img for ISO."
-               log   "Found /var/lib/grml_live_efi.img - moving to /boot/efi.img for ISO."
-               mv "${CHROOT_OUTPUT}/var/lib/grml_live_efi.img" "${BUILD_OUTPUT}/boot/efi.img"
-               eend $?
-             fi
-
-             if [ -r "${CHROOT_OUTPUT}/var/lib/grml_live_bootx64.efi" ] ; then
-               einfo "Found /var/lib/grml_live_bootx64.efi - moving to /efi/boot/bootx64.efi for ISO"
-               log   "Found /var/lib/grml_live_bootx64.efi - moving to /efi/boot/bootx64.efi for ISO"
-               mkdir -p "${BUILD_OUTPUT}/efi/boot/"
-               mv "${CHROOT_OUTPUT}/var/lib/grml_live_bootx64.efi" "${BUILD_OUTPUT}/efi/boot/bootx64.efi"
-               eend $?
-             fi
-
-             if [ -r "${BUILD_OUTPUT}"/boot/efi.img ] ; then
-               einfo "/boot/efi.img found and amd64 architecture present, extending boot arguments."
-               log   "/boot/efi.img found and amd64 architecture present, extending boot arguments."
-               BOOT_ARGS="$BOOT_ARGS -boot-info-table -eltorito-alt-boot -e boot/efi.img -no-emul-boot"
-               eend $?
-             fi
-           fi
+   einfo "Using ${MKISOFS} to build ISO." ;  eend 0
+   case "${ARCH}-${MKISOFS}" in
+     # using -eltorito-alt-boot is limited to xorriso for now
+     amd64-xorriso*)
+       eindent
 
-           eoutdent
-           ;;
-       esac
+       if ! dpkg --compare-versions $(dpkg-query -W -f='${Version}\n' xorriso 2>/dev/null) gt-nl 1.1.6-1 ; then
+         log   "Disabling (U)EFI boot support because xorriso version is too old."
+         ewarn "Disabling (U)EFI boot support because xorriso version is too old." ; eend 0
+       else
+         if [ -r "${BUILD_OUTPUT}"/boot/efi.img ] ; then
+           einfo "Enabling (U)EFI boot."
+           log   "Enabling (U)EFI boot."
+           BOOT_ARGS="$BOOT_ARGS -boot-info-table -eltorito-alt-boot -e boot/efi.img -no-emul-boot"
+           eend $?
+         else
+           log   "Disabling (U)EFI boot support because /boot/efi.img is missing."
+           ewarn "Disabling (U)EFI boot support because /boot/efi.img is missing." ; eend 0
+         fi
+       fi
+
+       eoutdent
        ;;
    esac
 
@@ -1245,12 +1478,12 @@ else
          # make a 2048-byte bootsector for El Torito
          dd if=/dev/zero of=boot/grub/toriboot.bin bs=512 count=4 2>/dev/null
          # those are in 2048-byte sectors, so 1 16 matches 4 63 below
-         echo 1 16 | mksh /usr/share/grml-live/scripts/bootgrub.mksh -B 11 | \
+         echo 1 16 | mksh "${SCRIPTS_DIRECTORY}/bootgrub.mksh" -B 11 | \
             dd of=boot/grub/toriboot.bin conv=notrunc 2>/dev/null
       fi
-      log "$MKISOFS -V '${GRML_NAME} ${VERSION}' -publisher 'grml-live | grml.org' -l -r -J $BOOT_ARGS -o ${ISO_OUTPUT}/${ISO_NAME} ."
+      log "$MKISOFS -V '${GRML_NAME} ${VERSION}' -publisher 'grml-live | grml.org' -l -r -J $BOOT_ARGS $EFI_ARGS -no-pad -o ${ISO_OUTPUT}/${ISO_NAME} ."
       $MKISOFS -V "${GRML_NAME} ${VERSION}" -publisher 'grml-live | grml.org' \
-              -l -r -J $BOOT_ARGS -no-pad \
+              -l -r -J $BOOT_ARGS $EFI_ARGS -no-pad \
               -o "${ISO_OUTPUT}/${ISO_NAME}" . ; RC=$?
       # both of these need core.img there, so it’s easier to write it here
       if [ "$BOOT_METHOD" = "grub2" ] || [ "$HYBRID_METHOD" = "grub2" ]; then
@@ -1267,57 +1500,43 @@ else
          of="${ISO_OUTPUT}/${ISO_NAME}" 2>/dev/null
 
       # support disabling hybrid ISO image
-      if [ "$HYBRID_METHOD" = "disable" ] ; then\
-         log   "Skipping creation of hybrid ISO file as requested via HYBRID_METHOD=disable"
-         einfo "Skipping creation of hybrid ISO file as requested via HYBRID_METHOD=disable"
-         eend 0
-      elif [ "$HYBRID_METHOD" = "manifold" ] ; then
-         # isoinfo is part of both mkisofs and genisoimage so we're good
-         bootoff=$(isoinfo -l -i "${ISO_OUTPUT}/${ISO_NAME}" | \
-           sed -n '/^.*\[ *\([0-9]*\)[] ].* ISOLINUX.BIN[;1]* *$/s//\1/p')
-         if ! [ -r boot/grub/core.img ] ; then
-           ewarn "boot/grub/core.img not found, not creating manifold boot ISO file"
-         elif [ "${bootoff:-0}" -lt 1 ] ; then
-           ewarn "isolinux.bin not found on the ISO file, disabling manifold boot"
-         else
-           log "Creating hybrid ISO file with manifold method"
-           einfo "Creating hybrid ISO file with manifold method"
-           if [ "$HYBRID_METHOD" = "grub2" ] ; then
-               # 512 bytes: MBR, partition table, load GRUB 2
-               echo 4 63 | mksh /usr/share/grml-live/scripts/bootgrub.mksh -A -M 4:0x96 -g $cyls:16:32
-           else
-              # read only one but 2048-byte sized (scale: << 2) sector
-              echo $bootoff $bootoff | \
-                 mksh /usr/share/grml-live/scripts/bootilnx.mksh -A -M 4:0x96 -g $cyls:16:32 -S 2
-           fi | dd of="${ISO_OUTPUT}/${ISO_NAME}" conv=notrunc 2>/dev/null
-           eend $?
-         fi
-      # use isohybrid as default
+      if [ "$HYBRID_METHOD" = "disable" ] ; then
+        log   "Skipping creation of hybrid ISO file as requested via HYBRID_METHOD=disable"
+        einfo "Skipping creation of hybrid ISO file as requested via HYBRID_METHOD=disable"
+        eend 0
+      elif [ "$HYBRID_METHOD" = "manifold" ] || [ "$HYBRID_METHOD" = "grub2" ] ; then
+        # isoinfo is part of both mkisofs and genisoimage so we're good
+        bootoff=$(isoinfo -l -i "${ISO_OUTPUT}/${ISO_NAME}" | \
+          sed -n '/^.*\[ *\([0-9]*\)[] ].* ISOLINUX.BIN[;1]* *$/s//\1/p')
+
+        if ! [ -r boot/grub/core.img ] ; then
+          log   "boot/grub/core.img not found, not creating manifold boot ISO file"
+          ewarn "boot/grub/core.img not found, not creating manifold boot ISO file"
+        elif [ "${bootoff:-0}" -lt 1 ] ; then
+          log   "isolinux.bin not found on the ISO file, disabling manifold boot"
+          ewarn "isolinux.bin not found on the ISO file, disabling manifold boot"
+        else
+          if [ "$HYBRID_METHOD" = "grub2" ] ; then
+            log   "Creating hybrid ISO file with manifold/grub2 method"
+            einfo "Creating hybrid ISO file with manifold/grub2 method"
+            # 512 bytes: MBR, partition table, load GRUB 2
+            echo 4 63 | mksh "${SCRIPTS_DIRECTORY}/bootgrub.mksh" -A -M 4:0x96 -g $cyls:16:32
+          else
+            log   "Creating hybrid ISO file with manifold method"
+            einfo "Creating hybrid ISO file with manifold method"
+            # read only one but 2048-byte sized (scale: << 2) sector
+            echo $bootoff $bootoff | \
+              mksh ${SCRIPTS_DIRECTORY}/bootilnx.mksh -A -M 4:0x96 -g $cyls:16:32 -S 2
+          fi | dd of="${ISO_OUTPUT}/${ISO_NAME}" conv=notrunc 2>/dev/null
+          eend $?
+        fi
+      elif [ "$HYBRID_METHOD" = "isohybrid" ] ; then
+        : # nothing to do, handled via $MKISOFS $EFI_ARGS already
       else
-         if ! which isohybrid >/dev/null 2>&1 ; then
-           bailout 12 "isohybrid binary not found - please install syslinux/syslinux-common"
-         else
-           log   "Creating hybrid ISO file with isohybrid method"
-           einfo "Creating hybrid ISO file with isohybrid method"
-           # Notes for consideration:
-           # "-entry 4 -type 1c"
-           # * using 4 as the partition number is supposed to help with BIOSes
-           #   that only support USB-Zip boot
-           # * using 1c (i.e. hidden FAT32 LBA), instead of the default 0x17
-           #   (hidden NTFS, IIRC), as the partition type is sometimes needed
-           #   to get the BIOS even look at the partition created by isohybrid
-           if isohybrid --help | grep -q -- --uefi ; then
-             einfo "Detected uefi support for isohybrid, enabling."
-             ISOHYBRID_OPTIONS=--uefi
-           fi
-
-           log "isohybrid $ISOHYBRID_OPTIONS ${ISO_OUTPUT}/${ISO_NAME}"
-           isohybrid $ISOHYBRID_OPTIONS "${ISO_OUTPUT}/${ISO_NAME}"
-           eend $?
-         fi
+        bailout 12 "Unknown HYBRID_METHOD [${HYBRID_METHOD}]. Supported values: disable, isohybrid, grub2, manifold"
       fi
 
-      # generate md5sum and sha1sum of ISO if we are using class 'RELEASE':
+      # generate ISO checksums if we are using class 'RELEASE':
       case $CLASSES in *RELEASE*)
          [ "$RC" = 0 ] && \
          (
@@ -1326,6 +1545,10 @@ else
              touch -r ${ISO_NAME} ${ISO_NAME}.md5
              sha1sum ${ISO_NAME} > ${ISO_NAME}.sha1 && \
              touch -r ${ISO_NAME} ${ISO_NAME}.sha1
+             sha256sum ${ISO_NAME} > ${ISO_NAME}.sha256 && \
+             touch -r ${ISO_NAME} ${ISO_NAME}.sha256
+             sha512sum ${ISO_NAME} > ${ISO_NAME}.sha512 && \
+             touch -r ${ISO_NAME} ${ISO_NAME}.sha512
            fi
          )
          ;;
@@ -1361,10 +1584,18 @@ create_netbootpackage() {
 
   mkdir -p "$NETBOOT"
 
-  if ! [ -r "${CHROOT}/usr/lib/syslinux/pxelinux.0" ] ; then
-    ewarn "File /usr/lib/syslinux/pxelinux.0 not found in build chroot." ; eend 0
+  # since syslinux v3:6.03~pre1+dfsg-4 the pxelinux.0 has been split into a
+  # separate pxelinux package
+  if [ -d "${CHROOT_OUTPUT}/usr/lib/PXELINUX/" ] ; then
+    local pxelinux_dir=/usr/lib/PXELINUX
+  else
+    local pxelinux_dir=/usr/lib/syslinux
+  fi
+
+  if ! [ -r "${CHROOT_OUTPUT}/${pxelinux_dir}/pxelinux.0" ] ; then
+    ewarn "File ${pxelinux_dir}/pxelinux.0 not found in build chroot." ; eend 0
     eindent
-    einfo "Install syslinux[-common] package in chroot to get a netboot package."
+    einfo "Install syslinux[-common]/pxelinux package in chroot to get a netboot package."
     eoutdent
     return 0
   fi
@@ -1374,20 +1605,33 @@ create_netbootpackage() {
 
   mkdir -p "$WORKING_DIR"
 
-  cp "${CHROOT_OUTPUT}"/boot/vmlinuz-*    "$WORKING_DIR"/linux26
+  cp "${CHROOT_OUTPUT}"/boot/vmlinuz-*    "$WORKING_DIR"/vmlinuz
   cp "${CHROOT_OUTPUT}"/boot/initrd.img-* "$WORKING_DIR"/initrd.img
-  cp "${CHROOT_OUTPUT}"/usr/lib/syslinux/pxelinux.0 "${WORKING_DIR}/pxelinux.0"
+  cp "${CHROOT_OUTPUT}/${pxelinux_dir}/pxelinux.0" "${WORKING_DIR}/pxelinux.0"
 
+  if [ -r "${CHROOT_OUTPUT}"/usr/lib/syslinux/modules/bios/ldlinux.c32 ] ; then
+    cp "${CHROOT_OUTPUT}"/usr/lib/syslinux/modules/bios/ldlinux.c32 "${WORKING_DIR}"/
+  fi
+
+  mkdir -p "${WORKING_DIR}/pxelinux.cfg"
   if [ -r "${BUILD_OUTPUT}/boot/isolinux/netboot.cfg" ] ; then
-    mkdir -p "${WORKING_DIR}/pxelinux.cfg/default"
     cp "${BUILD_OUTPUT}/boot/isolinux/netboot.cfg" "${WORKING_DIR}/pxelinux.cfg/default"
   else
-    ewarn "File ${BUILD_OUTPUT}/boot/isolinux/netboot.cfg not found." ; eend 0
+    log   "File ${BUILD_OUTPUT}/boot/isolinux/netboot.cfg not found."
+    ewarn "File ${BUILD_OUTPUT}/boot/isolinux/netboot.cfg not found."
+    eindent
+    log   "Hint: Are you using custom templates which do not provide netboot.cfg?"
+    ewarn "Hint: Are you using custom templates which do not provide netboot.cfg?" ; eend 0
+    eoutdent
   fi
 
-  mkdir -p "${WORKING_DIR}/pxelinux.cfg"
-
   if tar -C "$OUTPUTDIR" -jcf "${OUTPUT_FILE}" "grml_netboot_package_${GRML_NAME}_${VERSION}" ; then
+    (
+      cd $(dirname "${OUTPUT_FILE}")
+      sha1sum $(basename "${OUTPUT_FILE}") > "${OUTPUT_FILE}.sha1"
+      sha256sum $(basename "${OUTPUT_FILE}") > "${OUTPUT_FILE}.sha256"
+      sha512sum $(basename "${OUTPUT_FILE}") > "${OUTPUT_FILE}.sha512"
+    )
     einfo "Generated netboot package ${OUTPUT_FILE}" ; eend 0
     rm -rf "${OUTPUTDIR}"
   else
@@ -1400,16 +1644,6 @@ create_netbootpackage() {
 create_netbootpackage
 # }}}
 
-# pack artifacts {{{
-if [ -n "$PACK_ARTIFACTS" ]; then
-  log "Packing artifcats"
-  einfo "Packing artifacts"
-  [ -f "${CHROOT_ARCHIVE}" ] && rm -r "${CHROOT_ARCHIVE}"
-  tar -c -a -f ${CHROOT_ARCHIVE} --preserve-permissions -C "$(dirname ${CHROOT_OUTPUT})" "$(basename ${CHROOT_OUTPUT})"
-  eend 0
-fi
-# }}}
-
 # log build information to database if grml-live-db is installed and enabled {{{
 dpkg_to_db() {
 if [ -d /usr/share/grml-live-db ] ; then