From 1d60fc20d1d19f1074c8cd09c6cf7e6053e43fb2 Mon Sep 17 00:00:00 2001 From: NobodyNo0ne Date: Fri, 28 Aug 2026 12:31:40 +0100 Subject: [PATCH 1/4] Support for X280. CircleCI seed for Coreboot 25.12. Patches for SPI locking, and 16GB models of X280 for Coreboot 25.12. TLaurion fixes for splash/display, without i915. Signed-off-by: NobodyNo0ne --- .circleci/config.yml | 19 + .gitignore | 1 + blobs/xx80/README.md | 3 +- blobs/xx80/hashes.txt | 5 + .../x280_download_clean_deguard_me_pad_tb.sh | 204 + blobs/xx80/x280_gbe.bin | Bin 0 -> 8192 bytes blobs/xx80/x280_ifd.bin | Bin 0 -> 4096 bytes .../EOL_x280-hotp-maximized.config | 94 + .../EOL_x280-maximized.config | 100 + config/coreboot-x280-maximized.config | 902 ++++ .../coreboot-x280-maximized.config_defconfig | 24 + config/linux-x280.config | 3764 +++++++++++++++++ modules/coreboot | 4 + .../0001-cbmem-include-endian.patch | 9 + ...klkbl_spd-Fix_integer_overflow_91170.patch | 38 + ...wn-Allow-locking-down-SPI-and-LPC-in.patch | 427 ++ targets/x280_me_blobs.mk | 21 + 17 files changed, 5614 insertions(+), 1 deletion(-) create mode 100755 blobs/xx80/x280_download_clean_deguard_me_pad_tb.sh create mode 100644 blobs/xx80/x280_gbe.bin create mode 100644 blobs/xx80/x280_ifd.bin create mode 100644 boards/EOL_x280-hotp-maximized/EOL_x280-hotp-maximized.config create mode 100644 boards/EOL_x280-maximized/EOL_x280-maximized.config create mode 100644 config/coreboot-x280-maximized.config create mode 100644 config/coreboot-x280-maximized.config_defconfig create mode 100644 config/linux-x280.config create mode 100644 patches/coreboot-25.12/0001-cbmem-include-endian.patch create mode 100644 patches/coreboot-25.12/0002-mb_lenovo_sklkbl_spd-Fix_integer_overflow_91170.patch create mode 100644 patches/coreboot-25.12/0003-soc-intel-lockdown-Allow-locking-down-SPI-and-LPC-in.patch create mode 100644 targets/x280_me_blobs.mk diff --git a/.circleci/config.yml b/.circleci/config.yml index 191855454..af14b1d2c 100644 --- a/.circleci/config.yml +++ b/.circleci/config.yml @@ -167,6 +167,7 @@ jobs: command: | ./blobs/xx80/t480_download_clean_deguard_me_pad_tb.sh -m $(readlink -f ./blobs/utils/me_cleaner/me_cleaner.py) ./blobs/xx80/ ./blobs/xx80/t480s_download_clean_deguard_me_pad_tb.sh -m $(readlink -f ./blobs/utils/me_cleaner/me_cleaner.py) ./blobs/xx80/ + ./blobs/xx80/x280_download_clean_deguard_me_pad_tb.sh -m $(readlink -f ./blobs/utils/me_cleaner/me_cleaner.py) ./blobs/xx80/ - run: name: Download, neuter and deguard m900 ME (keep generated GBE and extracted IFD in tree) command: | @@ -476,6 +477,15 @@ workflows: requires: - x86-musl-cross-make [cross compiler] + # 25.12 fork — builds coreboot-25.12 toolchain + - x86_coreboot: + name: EOL_x280-hotp-maximized [seed:coreboot-25.12] + target: EOL_x280-hotp-maximized + subcommand: "" + coreboot_dir: coreboot-25.12 + requires: + - x86-musl-cross-make [cross compiler] + # ── Dasharo shared toolchain ────────────────────────────────────────── # 4 forks share crossgcc (verified by sum-file diff). # novacustom-nv4x_adl is the only seed; all other Dasharo boards are @@ -527,6 +537,15 @@ workflows: requires: - x86-musl-cross-make [cross compiler] + # ── coreboot 25.12 boards X280-hotp-maximized acts as seed ─────────────────────────────── + + - build: + name: EOL_x280-maximized + target: EOL_x280-maximized + subcommand: "" + requires: + - EOL_x280-hotp-maximized [seed:coreboot-25.12] + # ── coreboot 25.09 boards (alphabetical) ─────────────────────────────── - build: name: EOL_m900_tower-hotp-maximized diff --git a/.gitignore b/.gitignore index 766b9aced..b6b236a25 100644 --- a/.gitignore +++ b/.gitignore @@ -19,6 +19,7 @@ *~ .*.sw* /.direnv +*.bin clean config/*.old crossgcc diff --git a/blobs/xx80/README.md b/blobs/xx80/README.md index 87fbac58b..76cb61be9 100644 --- a/blobs/xx80/README.md +++ b/blobs/xx80/README.md @@ -1,4 +1,4 @@ -# T480 Blobs +# xx80 Blobs The following blobs are needed: @@ -22,6 +22,7 @@ As specified in the first link, this ME can be deployed to: * T480 * T480s +* X280 ## ifd.bin and gbe.bin diff --git a/blobs/xx80/hashes.txt b/blobs/xx80/hashes.txt index e3b6df2fd..16f17eb4f 100644 --- a/blobs/xx80/hashes.txt +++ b/blobs/xx80/hashes.txt @@ -8,3 +8,8 @@ f2f6d5fb0a5e02964b494862032fd93f1f88e2febd9904b936083600645c7fdf t480_ifd.bin b53e4670327e076ef879b2abef0efd9aade20da88d0c0976921b9f32378c0119 t480s_tb.bin caf6393cd5c4ff305b677f50c258658710c42439080868c1fb8ea7584cffb204 t480s_ifd.bin 36be39ecd0d06fa3f7893ca2746f702271c46b75de52bc599467a058bab8e271 t480s_gbe.bin +#X280: +fc67c1cafd11666a2f2702232e887ca413ce146ee25ec246ca94e60ac3083313 x280_tb.bin +404e08c7c9a4fd43c3b4da82012340ae360b3fbe299f4cb6b75344054d5fc936 x280_me.bin +4f0d11e9d62fe4d22fe2108ff35764f1bf2ad9131965e85f3cd43d6a1e83bb63 x280_ifd.bin +67ca8a1e91d31bb992bf8fddc1636b1df682bbb285b2c0701cfb4565924b8103 x280_gbe.bin diff --git a/blobs/xx80/x280_download_clean_deguard_me_pad_tb.sh b/blobs/xx80/x280_download_clean_deguard_me_pad_tb.sh new file mode 100755 index 000000000..86e5ff012 --- /dev/null +++ b/blobs/xx80/x280_download_clean_deguard_me_pad_tb.sh @@ -0,0 +1,204 @@ +#!/usr/bin/env bash + +# These variables are all for the deguard tool. +# They would need to be changed if using the tool for other devices like the X280 or with a different ME version... +ME_delta="thinkpad_x280" +ME_version="11.6.0.1126" +ME_sku="2M" +ME_pch="LP" + +# Thunderbolt firmware offset in bytes to pad to 1M +TBFW_SIZE=1048575 + +# Integrity checks for the vendor provided ME blob... +# ...and the cleaned and deguarded version from that blob. +DEGUARDED_ME_BIN_HASH="404e08c7c9a4fd43c3b4da82012340ae360b3fbe299f4cb6b75344054d5fc936" +# Integrity checks for the vendor provided Thunderbolt blob... +# still not sure it'll work +TB_DOWNLOAD_HASH="dcefadd999684d13a7909ee0bac17964209a6c4e6ebf5609ba72f9dab5e1d5b5" +# ...and the padded and flashable version from that blob. +# still not sure it'll work +TB_BIN_HASH="fc67c1cafd11666a2f2702232e887ca413ce146ee25ec246ca94e60ac3083313" + +function usage() { + echo -n \ + "Usage: $(basename "$0") -m (optional) path_to_output_directory +Download Intel ME firmware from Dell, neutralize and shrink keeping the MFS. +Download Thunderbolt firmware from Lenovo and pad it for flashing externally. +" +} + +function chk_sha256sum() { + sha256_hash="$1" + filename="$2" + echo "$sha256_hash" "$filename" "$(pwd)" + sha256sum "$filename" + if ! echo "${sha256_hash} ${filename}" | sha256sum --check; then + echo "ERROR: SHA256 checksum for ${filename} doesn't match." + + fi +} + +function chk_exists_and_matches() { + if [[ -f "$1" ]]; then + if echo "${2} ${1}" | sha256sum --check; then + echo "SKIPPING: SHA256 checksum for $1 matches." + [[ "$3" = ME ]] && me_exists="y" + [[ "$3" = TB ]] && tb_exists="y" + fi + echo "$1 exists but checksum doesn't match. Continuing..." + fi +} + +function download_and_clean() { + me_cleaner="$(realpath "${1}")" + me_output="$(realpath "${2}")" + + # Download and unpack the Dell installer into a temporary directory and + # extract the deguardable Intel ME blob. + pushd "$(mktemp -d)" || exit + + # Download the installer that contains the ME blob + me_installer_filename="Inspiron_5468_1.3.0.exe" + user_agent="Mozilla/5.0 (Windows NT 10.0; rv:91.0) Gecko/20100101 Firefox/91.0" + curl -A "$user_agent" -s -O "https://dl.dell.com/FOLDER04573471M/1/${me_installer_filename}" + chk_sha256sum "$ME_DOWNLOAD_HASH" "$me_installer_filename" + + # Download the tool to unpack Dell's installer and unpack the ME blob. + git clone https://github.com/platomav/BIOSUtilities + git -C BIOSUtilities checkout ef50b75ae115ae8162fa8b0a7b8c42b1d2db894b + + python "BIOSUtilities/Dell_PFS_Extract.py" "${me_installer_filename}" -e || exit + + extracted_me_filename="1 Inspiron_5468_1.3.0 -- 3 Intel Management Engine (Non-VPro) Update v${ME_version}.bin" + + # Deactivate, partially neuter and shrink Intel ME. Note that this doesn't include + # --soft-disable to set the "ME Disable" or "ME Disable B" (e.g., + # High Assurance Program) bits, as they are defined within the Flash + # Descriptor. + # However, the HAP bit must be enabled to make the deguarded ME work. We only clean the ME in this function. + # For ME 11.x this means we must keep the rbe, bup, kernel and syslib modules. + # https://github.com/corna/me_cleaner/wiki/How-does-it-work%3F#me-versions-from-11x-skylake-1 + # Furthermore, deguard requires keeping the MFS, the HAP bit set, and we cannot relocate the FTPR partition. + # Some more general info on shrinking: + # https://github.com/corna/me_cleaner/wiki/External-flashing#neutralize-and-shrink-intel-me-useful-only-for-coreboot + + # MFS is needed for deguard so we whitelist it here and also do not relocate the FTPR partition + python "$me_cleaner" --whitelist MFS -t -O "$me_output" "${me_installer_filename}_extracted/Firmware/${extracted_me_filename}" + rm -rf ./* + popd || exit +} + +function deguard() { + me_input="$(realpath "${1}")" + me_output="$(realpath "${2}")" + + # Download the deguard tool into a temporary directory and apply the patch to the cleaned ME blob. + pushd "$(mktemp -d)" || exit + git clone https://github.com/coreboot/deguard + pushd deguard || exit + git checkout 4944584c7cc0201adcc89a0465ab60f7f9f50ac6 + + python ./finalimage.py \ + --delta "data/delta/$ME_delta" \ + --version "$ME_version" \ + --pch "$ME_pch" \ + --sku "$ME_sku" \ + --fake-fpfs data/fpfs/zero \ + --input "$me_input" \ + --output "$me_output" + + popd || exit + #Cleanup + rm -rf ./* + popd || exit +} + +function download_and_pad_tb() { + tb_output="$(realpath "${1}")" + + # Download and unpack the Lenovo installer into a temporary directory and + # extract the TB blob. + pushd "$(mktemp -d)" || exit + + # Download the installer that contains the TB blob + tb_installer_filename=""n20th12w.exe"" + user_agent="Mozilla/5.0 (Windows NT 10.0; rv:91.0) Gecko/20100101 Firefox/91.0" + curl -A "$user_agent" -s -O "https://download.lenovo.com/pccbbs/mobiles/${tb_installer_filename}" + chk_sha256sum "$TB_DOWNLOAD_HASH" "$tb_installer_filename" + + # https://www.reddit.com/r/thinkpad/comments/9rnimi/ladies_and_gentlemen_i_present_to_you_the/ + innoextract n20th12w.exe -d . + mv ./code\$GetExtractPath\$/TBT.bin tb.bin + # pad with zeros + dd if=/dev/zero of=tb.bin bs=1 seek="$TBFW_SIZE" count=1 + mv "tb.bin" "$tb_output" + + rm -rf ./* + popd || exit +} + +function usage_err() { + echo "$1" + usage + exit 1 +} + +function parse_params() { + while getopts ":m:" opt; do + case $opt in + m) + if [[ -x "$OPTARG" ]]; then + me_cleaner="$OPTARG" + fi + ;; + ?) + usage_err "Invalid Option: -$OPTARG" + ;; + esac + done + + if [[ -z "${me_cleaner}" ]]; then + if [[ -z "${COREBOOT_DIR}" ]]; then + usage_err "ERROR: me_cleaner.py not found. Set path with -m parameter or define the COREBOOT_DIR variable." + else + me_cleaner="${COREBOOT_DIR}/util/me_cleaner/me_cleaner.py" + fi + fi + echo "Using me_cleaner from ${me_cleaner}" + + shift $(($OPTIND - 1)) + output_dir="$(realpath "${1:-./}")" + if [[ ! -d "${output_dir}" ]]; then + usage_err "No valid output dir found" + fi + me_cleaned="${output_dir}/me_cleaned.bin" + me_deguarded="${output_dir}/x280_me.bin" + tb_flashable="${output_dir}/x280_tb.bin" + echo "Writing cleaned and deguarded ME to ${me_deguarded}" + echo "Writing flashable TB to ${tb_flashable}" +} + +if [[ "${BASH_SOURCE[0]}" == "$0" ]]; then + if [[ "${1:-}" == "--help" ]]; then + usage + exit 0 + fi + + parse_params "$@" + chk_exists_and_matches "$me_deguarded" "$DEGUARDED_ME_BIN_HASH" ME + chk_exists_and_matches "$tb_flashable" "$TB_BIN_HASH" TB + + if [[ -z "$me_exists" ]]; then + download_and_clean "$me_cleaner" "$me_cleaned" + deguard "$me_cleaned" "$me_deguarded" + rm -f "$me_cleaned" + fi + + if [[ -z "$tb_exists" ]]; then + download_and_pad_tb "$tb_flashable" + fi + + chk_sha256sum "$DEGUARDED_ME_BIN_HASH" "$me_deguarded" + chk_sha256sum "$TB_BIN_HASH" "$tb_flashable" +fi diff --git a/blobs/xx80/x280_gbe.bin b/blobs/xx80/x280_gbe.bin new file mode 100644 index 0000000000000000000000000000000000000000..0124ba42d7cd342033f62c92115df28624482392 GIT binary patch literal 8192 zcmbR7Yqr4Gos1m+|BEo3XJBYx5cvQ9ut1p7D)H;03^35Z%AjMwAO_^}Bxx~mIdcdz zUKd@v>$>O-FbQG-wKg#LwQ+#7urn|yD1aDzK+MSCpdrNW@E-#(F#Z2Oj~Ap26Ce~% z*}%ZT#lSLQgS&&up@WLQ8xrIh7(4_R9Dp>-ML`B;E+L?HAbX1egA9Wq0~?U$1k&t4 zS^!9M0ci;!%>$)*p)})P0|uQrh73O23>a8}@(3G8S)(B^azY?8xP_S!GXsu_poIXl zEt&w3yN3r;Y*b`41V{~mkyF}?`gAk|MnhmU1V%$(Gz3ON02Bg#Mg~Ey2BzUYzJC7k zK8}9$4i$!bYY+T?N3j3DoHqS`DOc=mB}6EU_Wu!KG0GYZ0cwZ9X#XF334|^>+W$un lkx@RiLV((Ndepqp5Eu=C(GVC7fzc2c4S~TO0t4Ou2LPVHS;7DS literal 0 HcmV?d00001 diff --git a/blobs/xx80/x280_ifd.bin b/blobs/xx80/x280_ifd.bin new file mode 100644 index 0000000000000000000000000000000000000000..b9c7f858e5946549201d3233af9b23f01de9c358 GIT binary patch literal 4096 zcmeHKu}T9$6r8=yVG_igB*g_HuEn(y^#crn!zPWzHKL&42c)$!mA#c;U}-H{ir{DX z38skH9IW&14#^o!l|teU%v*Ne+xK?osuINsgrpWfX+ zJikZ|L`zwoX(|N|_7Xqyd!u461HLHDik`oeFI)x=0VRW{L19MI)NTglL|!zcs6F7k zXwlvVod8xzL-xoG67aLQ#waHT6csh86`VxC^|)?7(lpJ4Y8HV`u}VYYfb5d{I>3l) zljQWg&E%}s=I$a%l1&cLE2=I7YG^Rp>;~~wb^t~$LQM85Gv9gPM*q=<2>7i=>j=ah z2j_ruz&YR?a1J;JoCD4Q=fILV@MJ>7CN^)q5Rr+Dc?{tj-*krgx@6Ct` + /* SPDX-License-Identifier: GPL-2.0-only */ + + #include diff --git a/patches/coreboot-25.12/0002-mb_lenovo_sklkbl_spd-Fix_integer_overflow_91170.patch b/patches/coreboot-25.12/0002-mb_lenovo_sklkbl_spd-Fix_integer_overflow_91170.patch new file mode 100644 index 000000000..b7198911a --- /dev/null +++ b/patches/coreboot-25.12/0002-mb_lenovo_sklkbl_spd-Fix_integer_overflow_91170.patch @@ -0,0 +1,38 @@ +From 3b9fae176d9ef65be7f3baeec1f4ffda3b5a1bbb Mon Sep 17 00:00:00 2001 +From: "Johann C. Rode" +Date: Wed, 11 Feb 2026 20:07:01 -0800 +Subject: [PATCH] mb/lenovo/sklkbl/spd: Fix integer overflow + +This fixes an integer overflow in the calculation of the offset within +the SPD binary that has caused memory detection failures on some +machines (e.g. this resolves https://ticket.coreboot.org/issues/627 ). +In a nutshell, spd_index (uint8_t) receives an assigned multiplication +by 512 (SPD_SIZE_MAX_DDR4) which will always truncate the result. + +Change-Id: I048a73c18c9a3d1b20e2a4276e1714e59550eaf5 +Signed-off-by: Johann C. Rode +Reviewed-on: https://review.coreboot.org/c/coreboot/+/91170 +Reviewed-by: Patrick Rudolph +Reviewed-by: Angel Pons +Tested-by: build bot (Jenkins) +--- + src/mainboard/lenovo/sklkbl_thinkpad/spd/spd.c | 3 +-- + 1 file changed, 1 insertion(+), 2 deletions(-) + +diff --git a/src/mainboard/lenovo/sklkbl_thinkpad/spd/spd.c b/src/mainboard/lenovo/sklkbl_thinkpad/spd/spd.c +index 6ce18e5167..eaff251cc7 100644 +--- a/src/mainboard/lenovo/sklkbl_thinkpad/spd/spd.c ++++ b/src/mainboard/lenovo/sklkbl_thinkpad/spd/spd.c +@@ -28,8 +28,7 @@ uint8_t *mainboard_find_spd_data(uint8_t spd_index) + die("Missing SPD data (spd.bin size %zu smaller than SPD size %u).", spd_file_len, SPD_SIZE_MAX_DDR4); + + /* Assume same memory in both channels */ +- spd_index *= SPD_SIZE_MAX_DDR4; +- spd_data = (uint8_t *)(spd_file + spd_index); ++ spd_data = (uint8_t *)(spd_file + spd_index * SPD_SIZE_MAX_DDR4); + + /* Make sure a valid SPD was found */ + if (spd_data[0] == 0) +-- +2.55.0 + diff --git a/patches/coreboot-25.12/0003-soc-intel-lockdown-Allow-locking-down-SPI-and-LPC-in.patch b/patches/coreboot-25.12/0003-soc-intel-lockdown-Allow-locking-down-SPI-and-LPC-in.patch new file mode 100644 index 000000000..b5f7aa404 --- /dev/null +++ b/patches/coreboot-25.12/0003-soc-intel-lockdown-Allow-locking-down-SPI-and-LPC-in.patch @@ -0,0 +1,427 @@ +From d8ee9def7fe87b647cdeb951485efc679d119d86 Mon Sep 17 00:00:00 2001 +From: =?UTF-8?q?Micha=C5=82=20=C5=BBygowski?= +Date: Sat, 23 Nov 2024 22:43:10 +0100 +Subject: [PATCH 3/5] soc/intel/lockdown: Allow locking down SPI and LPC in SMM +MIME-Version: 1.0 +Content-Type: text/plain; charset=UTF-8 +Content-Transfer-Encoding: 8bit + +Heads payload uses APM_CNT_FINALIZE SMI to set and lock down the SPI +controller with PR0 flash protection for pre-Skylake platforms. + +Add new option to skip LPC and FAST SPI lock down in coreboot and move +it to APM_CNT_FINALIZE SMI handler. Reuse the INTEL_CHIPSET_LOCKDOWN +option to prevent issuing APM_CNT_FINALIZE SMI on normal boot path, +like it was done on pre-Skylake platforms. As the locking on modern +SOCs became more complicated, separate the SPI and LPC locking into +new modules to make linking to SMM easier. + +The expected configuration to leverage the feautre is to unselect +INTEL_CHIPSET_LOCKDOWN and select SOC_INTEL_COMMON_SPI_LOCKDOWN_SMM. + +Testing various microarchitectures happens on heads repository: +https://github.com/linuxboot/heads/pull/1818 + +TEST=Lock the SPI flash using APM_CNT_FINALIZE in heads on Alder Lake +(Protectli VP66xx) and Comet Lake (Protectli VP46xx) platforms. Check +if flash is unlocked in the heads recovery console. Check if flash is +locked in the kexec'ed OS. + +Change-Id: Icbcc6fcde90e5b0a999aacb720e2e3dc2748c838 +Signed-off-by: Michał Żygowski +--- + src/soc/intel/alderlake/finalize.c | 4 +- + src/soc/intel/cannonlake/finalize.c | 4 +- + src/soc/intel/common/block/lpc/Makefile.mk | 4 ++ + src/soc/intel/common/block/smm/smihandler.c | 10 ++++ + .../common/pch/include/intelpch/lockdown.h | 3 ++ + src/soc/intel/common/pch/lockdown/Kconfig | 15 ++++++ + src/soc/intel/common/pch/lockdown/Makefile.mk | 5 ++ + src/soc/intel/common/pch/lockdown/lockdown.c | 48 ++----------------- + .../intel/common/pch/lockdown/lockdown_lpc.c | 23 +++++++++ + .../intel/common/pch/lockdown/lockdown_spi.c | 32 +++++++++++++ + src/soc/intel/denverton_ns/lpc.c | 3 +- + src/soc/intel/elkhartlake/finalize.c | 4 +- + src/soc/intel/jasperlake/finalize.c | 3 +- + src/soc/intel/meteorlake/finalize.c | 4 +- + src/soc/intel/pantherlake/finalize.c | 4 +- + src/soc/intel/skylake/finalize.c | 3 +- + src/soc/intel/tigerlake/finalize.c | 4 +- + 17 files changed, 121 insertions(+), 52 deletions(-) + create mode 100644 src/soc/intel/common/pch/lockdown/lockdown_lpc.c + create mode 100644 src/soc/intel/common/pch/lockdown/lockdown_spi.c + +diff --git a/src/soc/intel/alderlake/finalize.c b/src/soc/intel/alderlake/finalize.c +index 700fde977b..615729d3dd 100644 +--- a/src/soc/intel/alderlake/finalize.c ++++ b/src/soc/intel/alderlake/finalize.c +@@ -85,7 +85,9 @@ static void soc_finalize(void *unused) + printk(BIOS_DEBUG, "Finalizing chipset.\n"); + + pch_finalize(); +- apm_control(APM_CNT_FINALIZE); ++ if (CONFIG(INTEL_CHIPSET_LOCKDOWN) || acpi_is_wakeup_s3()) ++ apm_control(APM_CNT_FINALIZE); ++ + tbt_finalize(); + if (CONFIG(USE_FSP_NOTIFY_PHASE_READY_TO_BOOT) && + CONFIG(USE_FSP_NOTIFY_PHASE_END_OF_FIRMWARE)) +diff --git a/src/soc/intel/cannonlake/finalize.c b/src/soc/intel/cannonlake/finalize.c +index 974794bd97..461ba3a884 100644 +--- a/src/soc/intel/cannonlake/finalize.c ++++ b/src/soc/intel/cannonlake/finalize.c +@@ -87,7 +87,9 @@ static void soc_finalize(void *unused) + printk(BIOS_DEBUG, "Finalizing chipset.\n"); + + pch_finalize(); +- apm_control(APM_CNT_FINALIZE); ++ if (CONFIG(INTEL_CHIPSET_LOCKDOWN) || acpi_is_wakeup_s3()) ++ apm_control(APM_CNT_FINALIZE); ++ + if (CONFIG(DISABLE_HECI1_AT_PRE_BOOT) && + CONFIG(SOC_INTEL_COMMON_BLOCK_HECI1_DISABLE_USING_PMC_IPC)) + heci1_disable(); +diff --git a/src/soc/intel/common/block/lpc/Makefile.mk b/src/soc/intel/common/block/lpc/Makefile.mk +index b510cd0ec3..60792654b5 100644 +--- a/src/soc/intel/common/block/lpc/Makefile.mk ++++ b/src/soc/intel/common/block/lpc/Makefile.mk +@@ -5,3 +5,7 @@ romstage-$(CONFIG_SOC_INTEL_COMMON_BLOCK_LPC) += lpc_lib.c + + ramstage-$(CONFIG_SOC_INTEL_COMMON_BLOCK_LPC) += lpc_lib.c + ramstage-$(CONFIG_SOC_INTEL_COMMON_BLOCK_LPC) += lpc.c ++ ++ifeq ($(CONFIG_SOC_INTEL_COMMON_SPI_LOCKDOWN_SMM),y) ++smm-$(CONFIG_SOC_INTEL_COMMON_BLOCK_LPC) += lpc_lib.c ++endif +diff --git a/src/soc/intel/common/block/smm/smihandler.c b/src/soc/intel/common/block/smm/smihandler.c +index 59489a4f03..2a1f26d2eb 100644 +--- a/src/soc/intel/common/block/smm/smihandler.c ++++ b/src/soc/intel/common/block/smm/smihandler.c +@@ -14,12 +14,14 @@ + #include + #include + #include ++#include + #include + #include + #include + #include + #include + #include ++#include + #include + #include + #include +@@ -345,6 +347,14 @@ static void finalize(void) + } + finalize_done = 1; + ++ if (CONFIG(SOC_INTEL_COMMON_SPI_LOCKDOWN_SMM)) { ++ /* SPI lock down configuration */ ++ fast_spi_lockdown_bios(CHIPSET_LOCKDOWN_COREBOOT); ++ ++ /* LPC/eSPI lock down configuration */ ++ lpc_lockdown_config(CHIPSET_LOCKDOWN_COREBOOT); ++ } ++ + if (CONFIG(SPI_FLASH_SMM)) + /* Re-init SPI driver to handle locked BAR */ + fast_spi_init(); +diff --git a/src/soc/intel/common/pch/include/intelpch/lockdown.h b/src/soc/intel/common/pch/include/intelpch/lockdown.h +index b5aba06fe0..1b96f41a2a 100644 +--- a/src/soc/intel/common/pch/include/intelpch/lockdown.h ++++ b/src/soc/intel/common/pch/include/intelpch/lockdown.h +@@ -22,4 +22,7 @@ int get_lockdown_config(void); + */ + void soc_lockdown_config(int chipset_lockdown); + ++void fast_spi_lockdown_bios(int chipset_lockdown); ++void lpc_lockdown_config(int chipset_lockdown); ++ + #endif /* SOC_INTEL_COMMON_PCH_LOCKDOWN_H */ +diff --git a/src/soc/intel/common/pch/lockdown/Kconfig b/src/soc/intel/common/pch/lockdown/Kconfig +index 38f60d2056..545185c52f 100644 +--- a/src/soc/intel/common/pch/lockdown/Kconfig ++++ b/src/soc/intel/common/pch/lockdown/Kconfig +@@ -3,7 +3,22 @@ + config SOC_INTEL_COMMON_PCH_LOCKDOWN + bool + default n ++ select HAVE_INTEL_CHIPSET_LOCKDOWN + help + This option allows to have chipset lockdown for DMI, FAST_SPI and + soc_lockdown_config() to implement any additional lockdown as PMC, + LPC for supported PCH. ++ ++config SOC_INTEL_COMMON_SPI_LOCKDOWN_SMM ++ bool "Lock down SPI controller in SMM" ++ default n ++ depends on HAVE_SMI_HANDLER && !INTEL_CHIPSET_LOCKDOWN ++ select SPI_FLASH_SMM ++ help ++ This option allows to have chipset lockdown for FAST_SPI and LPC for ++ supported PCH. If selected, coreboot will skip locking down the SPI ++ and LPC controller. The payload or OS is responsible for locking it ++ using APM_CNT_FINALIZE SMI. Used by heads to set and lock PR0 flash ++ protection. ++ ++ If unsure, say N. +diff --git a/src/soc/intel/common/pch/lockdown/Makefile.mk b/src/soc/intel/common/pch/lockdown/Makefile.mk +index 71466f8edd..64aad562ac 100644 +--- a/src/soc/intel/common/pch/lockdown/Makefile.mk ++++ b/src/soc/intel/common/pch/lockdown/Makefile.mk +@@ -1,2 +1,7 @@ + ## SPDX-License-Identifier: GPL-2.0-only + ramstage-$(CONFIG_SOC_INTEL_COMMON_PCH_LOCKDOWN) += lockdown.c ++ramstage-$(CONFIG_SOC_INTEL_COMMON_PCH_LOCKDOWN) += lockdown_lpc.c ++ramstage-$(CONFIG_SOC_INTEL_COMMON_PCH_LOCKDOWN) += lockdown_spi.c ++ ++smm-$(CONFIG_SOC_INTEL_COMMON_SPI_LOCKDOWN_SMM) += lockdown_lpc.c ++smm-$(CONFIG_SOC_INTEL_COMMON_SPI_LOCKDOWN_SMM) += lockdown_spi.c +diff --git a/src/soc/intel/common/pch/lockdown/lockdown.c b/src/soc/intel/common/pch/lockdown/lockdown.c +index eec3beb01b..2d229e1a90 100644 +--- a/src/soc/intel/common/pch/lockdown/lockdown.c ++++ b/src/soc/intel/common/pch/lockdown/lockdown.c +@@ -60,56 +60,17 @@ static void fast_spi_lockdown_cfg(int chipset_lockdown) + /* Set FAST_SPI opcode menu */ + fast_spi_set_opcode_menu(); + +- /* Discrete Lock Flash PR registers */ +- fast_spi_pr_dlock(); +- + /* Check if SPI transaction is pending */ + fast_spi_cycle_in_progress(); + + /* Clear any outstanding status bits like AEL, FCERR, FDONE, SAF etc. */ + fast_spi_clear_outstanding_status(); + +- /* Lock FAST_SPIBAR */ +- fast_spi_lock_bar(); +- + /* Set Vendor Component Lock (VCL) */ + fast_spi_vscc0_lock(); + +- /* Set BIOS Interface Lock, BIOS Lock */ +- if (chipset_lockdown == CHIPSET_LOCKDOWN_COREBOOT) { +- /* BIOS Interface Lock */ +- fast_spi_set_bios_interface_lock_down(); +- +- /* Only allow writes in SMM */ +- if (CONFIG(BOOTMEDIA_SMM_BWP)) { +- fast_spi_set_eiss(); +- fast_spi_enable_wp(); +- } +- +- /* BIOS Lock */ +- fast_spi_set_lock_enable(); +- +- /* EXT BIOS Lock */ +- fast_spi_set_ext_bios_lock_enable(); +- } +-} +- +-static void lpc_lockdown_config(int chipset_lockdown) +-{ +- /* Set BIOS Interface Lock, BIOS Lock */ +- if (chipset_lockdown == CHIPSET_LOCKDOWN_COREBOOT) { +- /* BIOS Interface Lock */ +- lpc_set_bios_interface_lock_down(); +- +- /* Only allow writes in SMM */ +- if (CONFIG(BOOTMEDIA_SMM_BWP)) { +- lpc_set_eiss(); +- lpc_enable_wp(); +- } +- +- /* BIOS Lock */ +- lpc_set_lock_enable(); +- } ++ if (!CONFIG(SOC_INTEL_COMMON_SPI_LOCKDOWN_SMM)) ++ fast_spi_lockdown_bios(chipset_lockdown); + } + + static void sa_lockdown_config(int chipset_lockdown) +@@ -135,8 +96,9 @@ static void platform_lockdown_config(void *unused) + /* SPI lock down configuration */ + fast_spi_lockdown_cfg(chipset_lockdown); + +- /* LPC/eSPI lock down configuration */ +- lpc_lockdown_config(chipset_lockdown); ++ if (!CONFIG(SOC_INTEL_COMMON_SPI_LOCKDOWN_SMM)) ++ /* LPC/eSPI lock down configuration */ ++ lpc_lockdown_config(chipset_lockdown); + + /* GPMR lock down configuration */ + gpmr_lockdown_cfg(); +diff --git a/src/soc/intel/common/pch/lockdown/lockdown_lpc.c b/src/soc/intel/common/pch/lockdown/lockdown_lpc.c +new file mode 100644 +index 0000000000..69278ea343 +--- /dev/null ++++ b/src/soc/intel/common/pch/lockdown/lockdown_lpc.c +@@ -0,0 +1,23 @@ ++/* SPDX-License-Identifier: GPL-2.0-only */ ++ ++#include ++#include ++#include ++ ++void lpc_lockdown_config(int chipset_lockdown) ++{ ++ /* Set BIOS Interface Lock, BIOS Lock */ ++ if (chipset_lockdown == CHIPSET_LOCKDOWN_COREBOOT) { ++ /* BIOS Interface Lock */ ++ lpc_set_bios_interface_lock_down(); ++ ++ /* Only allow writes in SMM */ ++ if (CONFIG(BOOTMEDIA_SMM_BWP)) { ++ lpc_set_eiss(); ++ lpc_enable_wp(); ++ } ++ ++ /* BIOS Lock */ ++ lpc_set_lock_enable(); ++ } ++} +diff --git a/src/soc/intel/common/pch/lockdown/lockdown_spi.c b/src/soc/intel/common/pch/lockdown/lockdown_spi.c +new file mode 100644 +index 0000000000..8dbe93013e +--- /dev/null ++++ b/src/soc/intel/common/pch/lockdown/lockdown_spi.c +@@ -0,0 +1,32 @@ ++/* SPDX-License-Identifier: GPL-2.0-only */ ++ ++#include ++#include ++#include ++ ++void fast_spi_lockdown_bios(int chipset_lockdown) ++{ ++ /* Discrete Lock Flash PR registers */ ++ fast_spi_pr_dlock(); ++ ++ /* Lock FAST_SPIBAR */ ++ fast_spi_lock_bar(); ++ ++ /* Set BIOS Interface Lock, BIOS Lock */ ++ if (chipset_lockdown == CHIPSET_LOCKDOWN_COREBOOT) { ++ /* BIOS Interface Lock */ ++ fast_spi_set_bios_interface_lock_down(); ++ ++ /* Only allow writes in SMM */ ++ if (CONFIG(BOOTMEDIA_SMM_BWP)) { ++ fast_spi_set_eiss(); ++ fast_spi_enable_wp(); ++ } ++ ++ /* BIOS Lock */ ++ fast_spi_set_lock_enable(); ++ ++ /* EXT BIOS Lock */ ++ fast_spi_set_ext_bios_lock_enable(); ++ } ++} +diff --git a/src/soc/intel/denverton_ns/lpc.c b/src/soc/intel/denverton_ns/lpc.c +index 7dc971ea92..c4f7681c62 100644 +--- a/src/soc/intel/denverton_ns/lpc.c ++++ b/src/soc/intel/denverton_ns/lpc.c +@@ -536,7 +536,8 @@ static const struct pci_driver lpc_driver __pci_driver = { + + static void finalize_chipset(void *unused) + { +- apm_control(APM_CNT_FINALIZE); ++ if (CONFIG(INTEL_CHIPSET_LOCKDOWN) || acpi_is_wakeup_s3()) ++ apm_control(APM_CNT_FINALIZE); + } + + BOOT_STATE_INIT_ENTRY(BS_OS_RESUME, BS_ON_ENTRY, finalize_chipset, NULL); +diff --git a/src/soc/intel/elkhartlake/finalize.c b/src/soc/intel/elkhartlake/finalize.c +index 275413b4ef..fc54710303 100644 +--- a/src/soc/intel/elkhartlake/finalize.c ++++ b/src/soc/intel/elkhartlake/finalize.c +@@ -43,7 +43,9 @@ static void soc_finalize(void *unused) + printk(BIOS_DEBUG, "Finalizing chipset.\n"); + + pch_finalize(); +- apm_control(APM_CNT_FINALIZE); ++ if (CONFIG(INTEL_CHIPSET_LOCKDOWN) || acpi_is_wakeup_s3()) ++ apm_control(APM_CNT_FINALIZE); ++ + if (CONFIG(USE_FSP_NOTIFY_PHASE_READY_TO_BOOT) && + CONFIG(USE_FSP_NOTIFY_PHASE_END_OF_FIRMWARE)) + heci_finalize(); +diff --git a/src/soc/intel/jasperlake/finalize.c b/src/soc/intel/jasperlake/finalize.c +index 8788db155d..4840c0c04c 100644 +--- a/src/soc/intel/jasperlake/finalize.c ++++ b/src/soc/intel/jasperlake/finalize.c +@@ -76,7 +76,8 @@ static void soc_finalize(void *unused) + printk(BIOS_DEBUG, "Finalizing chipset.\n"); + + pch_finalize(); +- apm_control(APM_CNT_FINALIZE); ++ if (CONFIG(INTEL_CHIPSET_LOCKDOWN) || acpi_is_wakeup_s3()) ++ apm_control(APM_CNT_FINALIZE); + + /* Indicate finalize step with post code */ + post_code(POSTCODE_OS_BOOT); +diff --git a/src/soc/intel/meteorlake/finalize.c b/src/soc/intel/meteorlake/finalize.c +index 1fd1d98fb5..80802db285 100644 +--- a/src/soc/intel/meteorlake/finalize.c ++++ b/src/soc/intel/meteorlake/finalize.c +@@ -64,7 +64,9 @@ static void soc_finalize(void *unused) + printk(BIOS_DEBUG, "Finalizing chipset.\n"); + + pch_finalize(); +- apm_control(APM_CNT_FINALIZE); ++ if (CONFIG(INTEL_CHIPSET_LOCKDOWN) || acpi_is_wakeup_s3()) ++ apm_control(APM_CNT_FINALIZE); ++ + tbt_finalize(); + sa_finalize(); + if (CONFIG(USE_FSP_NOTIFY_PHASE_READY_TO_BOOT) && +diff --git a/src/soc/intel/pantherlake/finalize.c b/src/soc/intel/pantherlake/finalize.c +index 05ec3eaaca..1d47dd7a0b 100644 +--- a/src/soc/intel/pantherlake/finalize.c ++++ b/src/soc/intel/pantherlake/finalize.c +@@ -63,7 +63,9 @@ static void soc_finalize(void *unused) + printk(BIOS_DEBUG, "Finalizing chipset.\n"); + + pch_finalize(); +- apm_control(APM_CNT_FINALIZE); ++ if (CONFIG(INTEL_CHIPSET_LOCKDOWN) || acpi_is_wakeup_s3()) ++ apm_control(APM_CNT_FINALIZE); ++ + tbt_finalize(); + sa_finalize(); + if (CONFIG(USE_FSP_NOTIFY_PHASE_READY_TO_BOOT) && +diff --git a/src/soc/intel/skylake/finalize.c b/src/soc/intel/skylake/finalize.c +index fd80aeac1a..a147b62e46 100644 +--- a/src/soc/intel/skylake/finalize.c ++++ b/src/soc/intel/skylake/finalize.c +@@ -106,7 +106,8 @@ static void soc_finalize(void *unused) + pch_finalize_script(dev); + + soc_lockdown(dev); +- apm_control(APM_CNT_FINALIZE); ++ if (CONFIG(INTEL_CHIPSET_LOCKDOWN) || acpi_is_wakeup_s3()) ++ apm_control(APM_CNT_FINALIZE); + + /* Indicate finalize step with post code */ + post_code(POSTCODE_OS_BOOT); +diff --git a/src/soc/intel/tigerlake/finalize.c b/src/soc/intel/tigerlake/finalize.c +index cd02745a9e..158b2fb691 100644 +--- a/src/soc/intel/tigerlake/finalize.c ++++ b/src/soc/intel/tigerlake/finalize.c +@@ -55,7 +55,9 @@ static void soc_finalize(void *unused) + printk(BIOS_DEBUG, "Finalizing chipset.\n"); + + pch_finalize(); +- apm_control(APM_CNT_FINALIZE); ++ if (CONFIG(INTEL_CHIPSET_LOCKDOWN) || acpi_is_wakeup_s3()) ++ apm_control(APM_CNT_FINALIZE); ++ + tbt_finalize(); + if (CONFIG(DISABLE_HECI1_AT_PRE_BOOT)) + heci1_disable(); +-- +2.39.5 + diff --git a/targets/x280_me_blobs.mk b/targets/x280_me_blobs.mk new file mode 100644 index 000000000..589a4f58b --- /dev/null +++ b/targets/x280_me_blobs.mk @@ -0,0 +1,21 @@ +# Targets for downloading xx80 ME blob, neutering it and deactivating ME. +# This also uses the deguard tool to bypass Intel Boot Guard exploiting CVE-2017-5705. +# See https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00086.html + +# xx80-*-maximized boards require of you initially call one of the +# following to have gbe.bin ifd.bin and me.bin +# - blobs/xx80/download_clean_me_and_deguard.sh +# To download Lenovo original ME binary, neuter+deactivate ME, produce +# reduced IFD ME region and expanded BIOS IFD region. +# Also creates the tb.bin blob to flash the Thunderbolt SPI. + +# Make the Coreboot build depend on the following 3rd party blobs: +$(build)/coreboot-$(CONFIG_COREBOOT_VERSION)/$(BOARD)/.build: \ + $(pwd)/blobs/xx80/x280_me.bin $(pwd)/blobs/xx80/x280_tb.bin $(build)/$(BOARD)/x280_tb.bin + +$(pwd)/blobs/xx80/x280_me.bin $(pwd)/blobs/xx80/x280_tb.bin &: + $(pwd)/blobs/xx80/x280_download_clean_deguard_me_pad_tb.sh \ + -m $(pwd)/blobs/utils/me_cleaner/me_cleaner.py $(pwd)/blobs/xx80 + +$(build)/$(BOARD)/x280_tb.bin: $(pwd)/blobs/xx80/x280_tb.bin + cp $(pwd)/blobs/xx80/x280_tb.bin $(build)/$(BOARD) From 10f209345b7a6029497d6bca80e7562f44e6390c Mon Sep 17 00:00:00 2001 From: NobodyNo0ne Date: Fri, 28 Aug 2026 18:25:03 +0100 Subject: [PATCH 2/4] Went through the reviewed changes and did some of them. Signed-off-by: NobodyNo0ne --- boards/EOL_x280-hotp-maximized/EOL_x280-hotp-maximized.config | 2 +- boards/EOL_x280-maximized/EOL_x280-maximized.config | 2 +- patches/coreboot-25.12/0001-cbmem-include-endian.patch | 3 +-- 3 files changed, 3 insertions(+), 4 deletions(-) diff --git a/boards/EOL_x280-hotp-maximized/EOL_x280-hotp-maximized.config b/boards/EOL_x280-hotp-maximized/EOL_x280-hotp-maximized.config index 0c132939b..aac9bec21 100644 --- a/boards/EOL_x280-hotp-maximized/EOL_x280-hotp-maximized.config +++ b/boards/EOL_x280-hotp-maximized/EOL_x280-hotp-maximized.config @@ -1,4 +1,4 @@ -# WARNING: This system remains perpetually vulnerable to Spectre v2 (CVE-2017-5715). Mitigations and microcode updates previously applied are now known to be ineffective due to QSB-107 and related CVEs. If Spectre v2 is a concern in your threat model, consider migrating to a platform with ongoing microcode support. Proper OPSEC for Memory Use MUST be followed:https://www.anarsec.guide/posts/qubes/#appendix-opsec-for-memory-use +# WARNING: This system remains perpetually vulnerable to Spectre v2 (CVE-2017-5715). Mitigations and microcode updates previously applied are now known to be ineffective due to QSB-107 and related CVEs. If Spectre v2 is a concern in your threat model, consider migrating to a platform with ongoing microcode support. Proper OPSEC for Memory Use MUST be followed: https://www.anarsec.guide/posts/qubes/#appendix-opsec-for-memory-use # Configuration for a T480 running Qubes 4.2.3 and other Linux Based OSes (through kexec) # # CAVEATS: TPM_GPIO_RESET=VULNERABLE -- TOTP/HOTP secret extractable, DUK with passphrase safe diff --git a/boards/EOL_x280-maximized/EOL_x280-maximized.config b/boards/EOL_x280-maximized/EOL_x280-maximized.config index 8986b6ffd..a19e52b3f 100644 --- a/boards/EOL_x280-maximized/EOL_x280-maximized.config +++ b/boards/EOL_x280-maximized/EOL_x280-maximized.config @@ -1,4 +1,4 @@ -# WARNING: This system remains perpetually vulnerable to Spectre v2 (CVE-2017-5715). Mitigations and microcode updates previously applied are now known to be ineffective due to QSB-107 and related CVEs. If Spectre v2 is a concern in your threat model, consider migrating to a platform with ongoing microcode support. Proper OPSEC for Memory Use MUST be followed:https://www.anarsec.guide/posts/qubes/#appendix-opsec-for-memory-use +# WARNING: This system remains perpetually vulnerable to Spectre v2 (CVE-2017-5715). Mitigations and microcode updates previously applied are now known to be ineffective due to QSB-107 and related CVEs. If Spectre v2 is a concern in your threat model, consider migrating to a platform with ongoing microcode support. Proper OPSEC for Memory Use MUST be followed: https://www.anarsec.guide/posts/qubes/#appendix-opsec-for-memory-use # Configuration for a T480 running Qubes 4.2.3 and other Linux Based OSes (through kexec) # # CAVEATS: diff --git a/patches/coreboot-25.12/0001-cbmem-include-endian.patch b/patches/coreboot-25.12/0001-cbmem-include-endian.patch index 75f8c9b49..c49aa0b5f 100644 --- a/patches/coreboot-25.12/0001-cbmem-include-endian.patch +++ b/patches/coreboot-25.12/0001-cbmem-include-endian.patch @@ -3,7 +3,6 @@ index 018ea871f9..8217b9e8a3 100644 --- a/util/cbmem/cbmem.c +++ b/util/cbmem/cbmem.c @@ -1,3 +1,4 @@ -+#include /* SPDX-License-Identifier: GPL-2.0-only */ - + +#include #include From 75762217dd92ae57eac6783c0ee5505743acbf54 Mon Sep 17 00:00:00 2001 From: NobodyNo0ne Date: Fri, 28 Aug 2026 18:55:01 +0100 Subject: [PATCH 3/4] I hope this was the issue. CircleCI logs suggest it is not but I changed nothing in modules/coreboot for it to fail finding 3rdparty Signed-off-by: NobodyNo0ne --- patches/coreboot-25.12/0001-cbmem-include-endian.patch | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/patches/coreboot-25.12/0001-cbmem-include-endian.patch b/patches/coreboot-25.12/0001-cbmem-include-endian.patch index c49aa0b5f..ffc5a4d3d 100644 --- a/patches/coreboot-25.12/0001-cbmem-include-endian.patch +++ b/patches/coreboot-25.12/0001-cbmem-include-endian.patch @@ -4,5 +4,6 @@ index 018ea871f9..8217b9e8a3 100644 +++ b/util/cbmem/cbmem.c @@ -1,3 +1,4 @@ /* SPDX-License-Identifier: GPL-2.0-only */ - +#include ++#include + #include From 32a0c6beeb5fdeff108ff4312e8392a48b1cff7c Mon Sep 17 00:00:00 2001 From: NobodyNo0ne Date: Fri, 28 Aug 2026 23:57:58 +0100 Subject: [PATCH 4/4] Final changes to comments, and added myself and @AlguienSasaki to BOARDS_AND_TESTERS.md Signed-off-by: NobodyNo0ne --- boards/EOL_x280-hotp-maximized/EOL_x280-hotp-maximized.config | 2 +- boards/EOL_x280-maximized/EOL_x280-maximized.config | 2 +- doc/BOARDS_AND_TESTERS.md | 2 ++ 3 files changed, 4 insertions(+), 2 deletions(-) diff --git a/boards/EOL_x280-hotp-maximized/EOL_x280-hotp-maximized.config b/boards/EOL_x280-hotp-maximized/EOL_x280-hotp-maximized.config index aac9bec21..c044a8b5f 100644 --- a/boards/EOL_x280-hotp-maximized/EOL_x280-hotp-maximized.config +++ b/boards/EOL_x280-hotp-maximized/EOL_x280-hotp-maximized.config @@ -1,5 +1,5 @@ # WARNING: This system remains perpetually vulnerable to Spectre v2 (CVE-2017-5715). Mitigations and microcode updates previously applied are now known to be ineffective due to QSB-107 and related CVEs. If Spectre v2 is a concern in your threat model, consider migrating to a platform with ongoing microcode support. Proper OPSEC for Memory Use MUST be followed: https://www.anarsec.guide/posts/qubes/#appendix-opsec-for-memory-use -# Configuration for a T480 running Qubes 4.2.3 and other Linux Based OSes (through kexec) +# Configuration for a X280 running Qubes 4.2.3 and other Linux Based OSes (through kexec) # # CAVEATS: TPM_GPIO_RESET=VULNERABLE -- TOTP/HOTP secret extractable, DUK with passphrase safe # See doc/TPM_GPIO_Reset_Vulnerability.md for details. diff --git a/boards/EOL_x280-maximized/EOL_x280-maximized.config b/boards/EOL_x280-maximized/EOL_x280-maximized.config index a19e52b3f..87e04b4ab 100644 --- a/boards/EOL_x280-maximized/EOL_x280-maximized.config +++ b/boards/EOL_x280-maximized/EOL_x280-maximized.config @@ -1,5 +1,5 @@ # WARNING: This system remains perpetually vulnerable to Spectre v2 (CVE-2017-5715). Mitigations and microcode updates previously applied are now known to be ineffective due to QSB-107 and related CVEs. If Spectre v2 is a concern in your threat model, consider migrating to a platform with ongoing microcode support. Proper OPSEC for Memory Use MUST be followed: https://www.anarsec.guide/posts/qubes/#appendix-opsec-for-memory-use -# Configuration for a T480 running Qubes 4.2.3 and other Linux Based OSes (through kexec) +# Configuration for a X280 running Qubes 4.2.3 and other Linux Based OSes (through kexec) # # CAVEATS: # This board is vulnerable to a TPM reset attack, i.e. the PCRs are reset while the system is running. diff --git a/doc/BOARDS_AND_TESTERS.md b/doc/BOARDS_AND_TESTERS.md index 27d447198..88e1a3019 100644 --- a/doc/BOARDS_AND_TESTERS.md +++ b/doc/BOARDS_AND_TESTERS.md @@ -40,6 +40,7 @@ Dates below are as of the document's last update and may be stale. | `EOL_librem_15v4` | 7th | Kaby Lake | Mar 31, 2024 | 2024-03 | | `EOL_t480` | 8th | Kaby Lake-R | Mar 31, 2026 ¹ | 2024-03 | | `EOL_t480s` | 8th | Kaby Lake-R | Mar 31, 2026 ¹ | 2024-03 | +| `EOL_x280` | 8th | Kaby Lake-R | Mar 31, 2026 ¹ | 2024-03 | ¹ KBL-R falls under Whiskey Lake ESU (Mar 31, 2026); also classified under Coffee Lake ESU (Jun 30, 2025). Both dates have passed. @@ -153,6 +154,7 @@ xx8x (Kaby Lake Refresh, 8th Gen Mobile -- EOL) === - [ ] t480: @gaspar-ilom @doritos4mlady @MattClifton76 @notgivenby @akunterkontrolle @nestire (Nitrokey) - [ ] t480s: @thickfont @kjkent @HarleyGodfrey @nestire (Nitrokey) +- [ ] x280: @NobodyNo0ne @AlguienSasaki Librem ===