Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
47 commits
Select commit Hold shift + click to select a range
90e511d
Add support for MrChromeBox coreboot fork.
mdrobnak May 27, 2024
6814d31
Add Support for Linux 6.6.30 (same patches a 4.9.80).
mdrobnak May 27, 2024
207478c
add kano boards.config
cwiggs Jun 24, 2026
065ac5e
kano: put board in debug mode, remove CR50 notes
tlaurion Jun 24, 2026
5aa50d9
kano: config/*kano* use mdrobnak:google_omnigul as base, then coreboo…
tlaurion Jun 24, 2026
1b704f2
patches/coreboot-mrchromebox/0001-util-cbmem-Add-endian.h-include-for…
tlaurion Jun 24, 2026
b0cf868
kano: ./docker_repro.sh make BOARD=kano coreboot.modify_defconfig_in_…
tlaurion Jun 24, 2026
541511c
kano: config/coreboot-kano.config; remove irrelevant omnigul things
tlaurion Jun 24, 2026
4cc238e
kano: ./docker_repro.sh make BOARD=kano coreboot.modify_and_save_oldc…
tlaurion Jun 24, 2026
de92d80
config/coreboot-kano.config: fix blob paths for MrChromebox repo layout
tlaurion Jun 25, 2026
6ad3213
modules/coreboot: init 3rdparty/blobs submodule for mrchromebox fork
tlaurion Jun 25, 2026
c095bde
kano: add CI seed for MrChromebox fork
tlaurion Jun 25, 2026
cc6199d
kano: add PR0 lockdown support via SMM SPI/LPC lockdown
tlaurion Jun 25, 2026
9a1d9af
doc/variation-to-defconfig.md: cross-board analysis from 38 defconfigs
tlaurion Jun 25, 2026
3c7876e
config/coreboot-kano.config: expand blob paths to real paths
tlaurion Jun 25, 2026
7ddffd6
kano: fix CBFS size and IFD validation
tlaurion Jun 25, 2026
566530a
boards/kano/kano.config: note ME disable options unavailable in mrchr…
tlaurion Jun 25, 2026
eaa8983
patches/coreboot-mrchromebox/0001-util-cbmem-Add-endian.h-include-for…
tlaurion Jun 26, 2026
bf9b355
README: document full clone history needed for version identifiers
tlaurion Jun 26, 2026
8ec1182
update kano.config
cwiggs Jun 25, 2026
1f519aa
CONFIG_BOOTSCRIPT should be /bin/gui-init.sh (missing .sh)
cwiggs Jul 6, 2026
4d74a0c
Skip ClearControl when TPM does not support
cwiggs Jul 8, 2026
b37ea9a
Update comment about which SPI to use
cwiggs Jul 8, 2026
88e1312
Enable serial console output
cwiggs Jul 8, 2026
43708ee
Revert "Enable serial console output"
cwiggs Jul 8, 2026
98d8d35
add tpm doc explaining CR50 features that are missing
cwiggs Jul 8, 2026
56dc241
add tlaurion patch to tpmr.sh
cwiggs Jul 8, 2026
24c31f4
Enable Heads to detect wrong date and update it
cwiggs Jul 9, 2026
08d2b57
build: apply HAP bit via ifdtool post-build to disable ME at runtime
tlaurion Jul 9, 2026
6c2ec4f
config/coreboot-kano.config: normalize USE_PC_CMOS_ALTCENTURY via sav…
tlaurion Jul 9, 2026
92ed81f
boards/kano: disable CONFIG_DROPBEAR
tlaurion Jul 10, 2026
7be20d4
adding KANO laptop to boards and testers doc
cwiggs Jul 22, 2026
8416361
fix merge conflict
cwiggs Sep 1, 2026
849bef1
modules/coreboot: apply GPR0 disable independently of HAP in post-bui…
tlaurion Sep 2, 2026
fc0312e
boards/kano: version the MrChromebox coreboot fork name
tlaurion Sep 2, 2026
5372f62
boards/kano: note TPM GPIO Reset NOT_VULNERABLE (CR50 on I2C)
tlaurion Sep 3, 2026
9b22a41
boards/kano: switch from MrChromebox coreboot fork to upstream 26.03
tlaurion Sep 3, 2026
98574da
boards/kano: record upstream-26.03 config normalization and blob blocker
tlaurion Sep 3, 2026
d5e891e
boards/kano: switch kano back to the MrChromebox coreboot fork
tlaurion Sep 3, 2026
d95ae39
boards/kano: recheck fork coreboot config via make save helpers; rest…
tlaurion Sep 3, 2026
5403092
tpm-gpio-reset: point module at 3e3a695 (platform support + cleanup f…
tlaurion Sep 3, 2026
bdd9c08
tpm-gpio-reset: attribute Kondix10 (Konrad Dadasiewicz) platform work
tlaurion Sep 3, 2026
d177677
doc/wp-notes.md: include kano in PR0 chipset-locking coverage
tlaurion Sep 3, 2026
1401726
gitignore: ignore .code-graph/ workspace
tlaurion Sep 3, 2026
cec089e
boards: add kano-hotp variant (unified with kano)
tlaurion Sep 3, 2026
b184149
gitignore: ignore backup/scratch artifacts to prevent accidental trac…
tlaurion Sep 3, 2026
10fb2c9
Merge branch 'master' into google_kano
tlaurion Sep 3, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
20 changes: 19 additions & 1 deletion .circleci/config.yml
Original file line number Diff line number Diff line change
Expand Up @@ -263,7 +263,7 @@ jobs:
# See doc/circleci.md for full documentation.
# Workspace chain: create_hashes -> x86_blobs -> x86_musl_cross_make -> x86_coreboot
# Seeds (one per unique toolchain): coreboot-4.11, coreboot-25.09,
# coreboot-dasharo_nv4x, coreboot-purism
# coreboot-dasharo_nv4x, coreboot-mrchromebox-26.03, coreboot-purism
# Dasharo v56/msi_z690/msi_z790 are build jobs, not x86_coreboot.
x86_coreboot:
executor: heads-docker
Expand Down Expand Up @@ -546,6 +546,24 @@ workflows:
requires:
- EOL_x280-hotp-maximized [seed:coreboot-25.12]

# mrchromebox fork (coreboot 26.03 based) -- builds coreboot-mrchromebox-26.03 toolchain
# Downstream boards: kano, kano-hotp
- x86_coreboot:
name: kano [seed:coreboot-mrchromebox-26.03]
target: kano
subcommand: ""
coreboot_dir: coreboot-mrchromebox-26.03
requires:
- x86-musl-cross-make [cross compiler]

# kano-hotp (seeded by kano)
- build:
name: kano-hotp
target: kano-hotp
subcommand: ""
requires:
- kano [seed:coreboot-mrchromebox-26.03]

# ── coreboot 25.09 boards (alphabetical) ───────────────────────────────
- build:
name: EOL_m900_tower-hotp-maximized
Expand Down
9 changes: 9 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -18,6 +18,14 @@
*.xz
*~
.*.sw*
*.bak
*.bck
*.orig
*.rej
*.save
*.tmp
-patch
.md-patch
/.direnv
*.bin
clean
Expand All @@ -27,3 +35,4 @@ typescript*
result
.claude/
tmpDir/
.code-graph/
18 changes: 18 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -57,6 +57,24 @@ We welcome contributions to the Heads project! Before contributing, please read
Heads builds inside a versioned Docker image. The supported and tested workflow uses the
provided Docker wrappers — no host-side QEMU or swtpm installation is needed.

### Clone the Repository

Clone with full history to ensure version tags are available for
`git describe --tags` (used at build time for artifact filenames):

```bash
git clone https://github.com/linuxboot/heads.git
cd heads
```

To repair an existing shallow clone (`--depth 1` was used) or if
artifact filenames show a trailing `_-` (missing git abbreviation):

```bash
git fetch --unshallow origin
git fetch --tags origin
```

**Quick start** (requires [Docker CE](https://docs.docker.com/engine/install/)):

```bash
Expand Down
3 changes: 2 additions & 1 deletion bin/validate_cbfs_ifd_fit.sh
Original file line number Diff line number Diff line change
Expand Up @@ -274,7 +274,8 @@ if [ -z "$IFD_VALIDATION_SKIPPED" ] && [ -f "$IFD_PATH" ] && [ -n "$IFDTOOL" ];
MAX_CBFS_SIZE=0x1000000 # 16 MiB - Intel SPI decode window limit

# Calculate safe expansion target: min(IFD BIOS size, 16 MiB limit)
if [ $BIOS_SIZE -gt $MAX_CBFS_SIZE ]; then
MAX_CBFS_SIZE_DEC=$((MAX_CBFS_SIZE))
if [ $BIOS_SIZE -gt $MAX_CBFS_SIZE_DEC ]; then
TARGET_SIZE=$MAX_CBFS_SIZE
TARGET_SIZE_KB=$((TARGET_SIZE / 1024))
BIOS_SIZE_MB=$((BIOS_SIZE / 1024 / 1024))
Expand Down
86 changes: 86 additions & 0 deletions boards/kano-hotp/kano-hotp.config
Original file line number Diff line number Diff line change
@@ -0,0 +1,86 @@
# Configuration for a Acer Chromebook Spin 714 (CP714-1WN/2WN/KANO)
# HOTP variant: requires a supported HOTP Security dongle (Nitrokey Pro/Storage or Librem Key)
# for HOTP-based remote attestation alongside the TPM.
# Intel iGPU "UHD Graphics", 12th Gen Intel Core i5-1235U, 8GB RAM
# CAVEATS: TPM_GPIO_RESET=NOT_VULNERABLE -- Google CR50 on I2C (bus 0x1, addr 0x50) is a separate MCU not driven by the PCH PLTRST# multifunction GPIO pad; the discrete-TPM PLTRST# reprogramming attack cannot reset the CR50
# See doc/TPM_GPIO_Reset_Vulnerability.md for details.
# 256GB NVMe Storage, Intel AX211 Wi-FI 6E,

# 32MB Winbond Chip W25Q256JV_M - SuzyQ cable used to flash with ccd.

export CONFIG_COREBOOT=y
export CONFIG_COREBOOT_VERSION=mrchromebox-26.03
# Post-build ifdtool (modules/coreboot) applies these IFD toggles:
CONFIG_COREBOOT_APPLY_HAP=y # disable ME at runtime (fork lacks HAP Kconfigs)
CONFIG_COREBOOT_GPR0_DISABLE=y # ME region stays RO even with FLMSTR unlocked without this
export CONFIG_LINUX_VERSION=6.6.30

CONFIG_COREBOOT_CONFIG=config/coreboot-kano.config
CONFIG_LINUX_CONFIG=config/linux-kano.config

#Enable DEBUG output
export CONFIG_DEBUG_OUTPUT=y
export CONFIG_ENABLE_FUNCTION_TRACING_OUTPUT=y
#Enable TPM2 pcap output under /tmp
export CONFIG_TPM2_CAPTURE_PCAP=y

#On-demand hardware support (modules.cpio)
CONFIG_LINUX_USB=y
CONFIG_LINUX_E1000=n
CONFIG_MOBILE_TETHERING=y

#Modules packed into tools.cpio
CONFIG_IO386=y
CONFIG_CRYPTSETUP2=y
CONFIG_FLASHPROG=y
CONFIG_FLASHTOOLS=y
CONFIG_GPG2=y
CONFIG_KEXEC=y
CONFIG_UTIL_LINUX=y
CONFIG_LVM2=y
CONFIG_MBEDTLS=y
CONFIG_PCIUTILS=y
#Runtime tools to write to EC/MSR
CONFIG_IOTOOLS=n
CONFIG_MSRTOOLS=n
#Remote attestation support
# TPM2 requirements
CONFIG_TPM2_TSS=y
CONFIG_OPENSSL=y
#Remote Attestation common tools
CONFIG_POPT=y
CONFIG_QRENCODE=y
CONFIG_TPMTOTP=y
#HOTP based remote attestation for supported USB Security dongle
#With/Without TPM support
CONFIG_HOTPKEY=y
#Nitrokey Storage admin tool (deprecated)
#CONFIG_NKSTORECLI=n
#GUI Support
#Console based Whiptail support(Console based, no FB):
#CONFIG_SLANG=y
#CONFIG_NEWT=y
#FBWhiptail based (Graphical):
CONFIG_CAIRO=y
CONFIG_FBWHIPTAIL=y
#Additional tools (tools.cpio):
#SSH server (requires ethernet drivers, eg: CONFIG_LINUX_E1000E)
#CONFIG_DROPBEAR=y

#Runtime configuration
#Automatically boot if HOTP is valid
export CONFIG_AUTO_BOOT_TIMEOUT=5
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
#TPM2 requirements
export CONFIG_TPM2_TOOLS=y
export CONFIG_PRIMARY_KEY_TYPE=ecc
#TPM1 requirements
#export CONFIG_TPM=y
export CONFIG_BOOTSCRIPT=/bin/gui-init.sh
export CONFIG_BOOT_REQ_HASH=n
export CONFIG_BOOT_REQ_ROLLBACK=n
export CONFIG_BOOT_KERNEL_ADD=""
export CONFIG_BOOT_KERNEL_REMOVE=""
export CONFIG_BOOT_DEV="/dev/nvme0n1"
export CONFIG_BOARD_NAME="Google Kano HOTP"
export CONFIG_FLASH_OPTIONS="flashprog --progress --programmer internal --ifd -i bios -i fd"
84 changes: 84 additions & 0 deletions boards/kano/kano.config
Original file line number Diff line number Diff line change
@@ -0,0 +1,84 @@
# Configuration for a Acer Chromebook Spin 714 (CP714-1WN/2WN/KANO)
# Intel iGPU "UHD Graphics", 12th Gen Intel Core i5-1235U, 8GB RAM
# CAVEATS: TPM_GPIO_RESET=NOT_VULNERABLE -- Google CR50 on I2C (bus 0x1, addr 0x50) is a separate MCU not driven by the PCH PLTRST# multifunction GPIO pad; the discrete-TPM PLTRST# reprogramming attack cannot reset the CR50
# See doc/TPM_GPIO_Reset_Vulnerability.md for details.
# 256GB NVMe Storage, Intel AX211 Wi-FI 6E,

# 32MB Winbond Chip W25Q256JV_M - SuzyQ cable used to flash with ccd.

export CONFIG_COREBOOT=y
export CONFIG_COREBOOT_VERSION=mrchromebox-26.03
# Post-build ifdtool (modules/coreboot) applies these IFD toggles:
CONFIG_COREBOOT_APPLY_HAP=y # disable ME at runtime (fork lacks HAP Kconfigs)
CONFIG_COREBOOT_GPR0_DISABLE=y # ME region stays RO even with FLMSTR unlocked without this
export CONFIG_LINUX_VERSION=6.6.30

CONFIG_COREBOOT_CONFIG=config/coreboot-kano.config
CONFIG_LINUX_CONFIG=config/linux-kano.config

#Enable DEBUG output
export CONFIG_DEBUG_OUTPUT=y
export CONFIG_ENABLE_FUNCTION_TRACING_OUTPUT=y
#Enable TPM2 pcap output under /tmp
export CONFIG_TPM2_CAPTURE_PCAP=y

#On-demand hardware support (modules.cpio)
CONFIG_LINUX_USB=y
CONFIG_LINUX_E1000=n
CONFIG_MOBILE_TETHERING=y

#Modules packed into tools.cpio
CONFIG_IO386=y
CONFIG_CRYPTSETUP2=y
CONFIG_FLASHPROG=y
CONFIG_FLASHTOOLS=y
CONFIG_GPG2=y
CONFIG_KEXEC=y
CONFIG_UTIL_LINUX=y
CONFIG_LVM2=y
CONFIG_MBEDTLS=y
CONFIG_PCIUTILS=y
#Runtime tools to write to EC/MSR
CONFIG_IOTOOLS=n
CONFIG_MSRTOOLS=n
#Remote attestation support
# TPM2 requirements
CONFIG_TPM2_TSS=y
CONFIG_OPENSSL=y
#Remote Attestation common tools
CONFIG_POPT=y
CONFIG_QRENCODE=y
CONFIG_TPMTOTP=y
#HOTP based remote attestation for supported USB Security dongle
#With/Without TPM support
CONFIG_HOTPKEY=n
#Nitrokey Storage admin tool (deprecated)
#CONFIG_NKSTORECLI=n
#GUI Support
#Console based Whiptail support(Console based, no FB):
#CONFIG_SLANG=y
#CONFIG_NEWT=y
#FBWhiptail based (Graphical):
CONFIG_CAIRO=y
CONFIG_FBWHIPTAIL=y
#Additional tools (tools.cpio):
#SSH server (requires ethernet drivers, eg: CONFIG_LINUX_E1000E)
#CONFIG_DROPBEAR=y

#Runtime configuration
#Automatically boot if HOTP is valid
export CONFIG_AUTO_BOOT_TIMEOUT=5
export CONFIG_FINALIZE_PLATFORM_LOCKING=y
#TPM2 requirements
export CONFIG_TPM2_TOOLS=y
export CONFIG_PRIMARY_KEY_TYPE=ecc
#TPM1 requirements
#export CONFIG_TPM=y
export CONFIG_BOOTSCRIPT=/bin/gui-init.sh
export CONFIG_BOOT_REQ_HASH=n
export CONFIG_BOOT_REQ_ROLLBACK=n
export CONFIG_BOOT_KERNEL_ADD=""
export CONFIG_BOOT_KERNEL_REMOVE=""
export CONFIG_BOOT_DEV="/dev/nvme0n1"
export CONFIG_BOARD_NAME="Google Kano"
export CONFIG_FLASH_OPTIONS="flashprog --progress --programmer internal --ifd -i bios -i fd"
Loading