GRUB2 & the Boot Process

GRUB2

You met the general boot chain in the System Architecture module (Firmware → GRUB2 → kernel+initramfs → systemd). This section zooms into the second link: GRUB2, the bootloader almost every Linux distro uses by default. Its job is simple to state - load the kernel and its initramfs into memory and hand them control, optionally passing along kernel parameters that change how the kernel behaves on this particular boot.

File / commandPurpose
/etc/default/grubMain GRUB config (edit this)
/boot/grub2/grub.cfgGenerated config - do not edit by hand
grub2-mkconfig -o /boot/grub2/grub.cfgRegenerate config (RHEL)
update-grubRegenerate config (Debian)

This two-file split trips people up until they understand why it exists: /etc/default/grub is the file humans edit - a short list of preferences like default timeout or extra kernel parameters. grub.cfg is a much longer, auto-generated file GRUB actually reads at boot time, built by scanning /etc/default/grub plus every installed kernel and other bootable OS it can find. Editing grub.cfg directly is pointless (and dangerous) because the next update-grub/grub2-mkconfig run will simply overwrite your changes.

Kernel parameters (things like which disk holds root, or debug flags) are set via the GRUB_CMDLINE_LINUX line in /etc/default/grub, then baked into grub.cfg on regeneration. You can also override them for a single boot only, without touching any file, by pressing e at the GRUB menu to edit the boot entry live before it runs.

Tip: This live-edit trick is exactly how you recover a lost root password: at the GRUB prompt, press e, append rd.break (RHEL/Fedora) or init=/bin/bash (Debian/Ubuntu) to the kernel line, and boot. This skips the normal login and drops you straight into a root shell - the kernel parameter tells it to run a bash shell instead of the normal init system, bypassing the password check entirely. It's a real security consideration: physical or firmware-level access to a machine's GRUB menu is effectively root access, which is why production servers often password-protect the GRUB menu itself.