Add google kano flashing guide - #223
Conversation
| TODO: Do we need to run `gsctool` from ChromeOS? I did not have to but maybe the previous owner of my Kano | ||
| device did it? [source](https://docs.mrchromebox.tech/docs/firmware/wp/disabling.html#step-1-enabling-closed-case-debugging-ccd) | ||
|
|
||
| Now we disable software write protection: |
There was a problem hiding this comment.
@MrChromebox this is weird and we don't understand.
Even if IFD has all regions disabled per linuxboot/heads#2133 's linuxboot/heads@aece972
Found Master Section
FLMSTR1: 0xffffffff (Host CPU/BIOS)
EC Region Write Access: enabled
Platform Data Region Write Access: enabled
GbE Region Write Access: enabled
Intel ME Region Write Access: enabled
Host CPU/BIOS Region Write Access: enabled
Flash Descriptor Write Access: enabled
EC Region Read Access: enabled
Platform Data Region Read Access: enabled
GbE Region Read Access: enabled
Intel ME Region Read Access: enabled
Host CPU/BIOS Region Read Access: enabled
Flash Descriptor Read Access: enabled
FLMSTR2: 0xffffffff (Intel ME)
EC Region Write Access: enabled
Platform Data Region Write Access: enabled
GbE Region Write Access: enabled
Intel ME Region Write Access: enabled
Host CPU/BIOS Region Write Access: enabled
Flash Descriptor Write Access: enabled
EC Region Read Access: enabled
Platform Data Region Read Access: enabled
GbE Region Read Access: enabled
Intel ME Region Read Access: enabled
Host CPU/BIOS Region Read Access: enabled
Flash Descriptor Read Access: enabled
FLMSTR3: 0xffffffff (GbE)
EC Region Write Access: enabled
Platform Data Region Write Access: enabled
GbE Region Write Access: enabled
Intel ME Region Write Access: enabled
Host CPU/BIOS Region Write Access: enabled
Flash Descriptor Write Access: enabled
EC Region Read Access: enabled
Platform Data Region Read Access: enabled
GbE Region Read Access: enabled
Intel ME Region Read Access: enabled
Host CPU/BIOS Region Read Access: enabled
Flash Descriptor Read Access: enabled
FLMSTR5: 0xffffffff (EC)
EC Region Write Access: enabled
Platform Data Region Write Access: enabled
GbE Region Write Access: enabled
Intel ME Region Write Access: enabled
Host CPU/BIOS Region Write Access: enabled
Flash Descriptor Write Access: enabled
EC Region Read Access: enabled
Platform Data Region Read Access: enabled
GbE Region Read Access: enabled
Intel ME Region Read Access: enabled
Host CPU/BIOS Region Read Access: enabled
Flash Descriptor Read Access: enabled
Heads flashprog -p internal still reports:
flashprog unknown on Linux 6.6.30-Heads (x86_64)
flashprog is free software, get the source code at https://flashprog.org
Calibrating delay loop... OK.
coreboot table found at 0x76883000.
Found chipset "Intel Alder Lake-P".
Enabling flash write... GPR0: Warning: 0x00001000-0x001a6fff is read-only.
At least some flash regions are write protected. For write operations,
you should use a flash layout and include only writable regions. See
manpage for more details.
OK.
Found Programmer flash chip "Opaque flash chip" (32768 kB, Programmer-specific) on internal.
No operations were specified.
There was a problem hiding this comment.
Also Heads recovery shell cbmem --console | grep '[DEBUG] ME' returns:
[DEBUG] ME: HFSTS1 : 0x90000055
[DEBUG] ME: HFSTS2 : 0x82130116
[DEBUG] ME: HFSTS3 : 0x00000050
[DEBUG] ME: HFSTS4 : 0x00004000
[DEBUG] ME: HFSTS5 : 0x00000000
[DEBUG] ME: HFSTS6 : 0x40600006
[DEBUG] ME: Manufacturing Mode : YES
[DEBUG] ME: SPI Protection Mode Enabled : NO
[DEBUG] ME: FW Partition Table : OK
[DEBUG] ME: Bringup Loader Failure : NO
[DEBUG] ME: Firmware Init Complete : NO
[DEBUG] ME: Boot Options Present : NO
[DEBUG] ME: Update In Progress : NO
[DEBUG] ME: D0i3 Support : YES
[DEBUG] ME: Low Power State Enabled : NO
[DEBUG] ME: CPU Replaced : YES
[DEBUG] ME: CPU Replacement Valid : YES
[DEBUG] ME: Current Working State : 5
[DEBUG] ME: Current Operation State : 1
[DEBUG] ME: Current Operation Mode : 0
[DEBUG] ME: Error Code : 0
[DEBUG] ME: FPFs Committed : YES
[DEBUG] ME: Enhanced Debug Mode : NO
[DEBUG] ME: CPU Debug Disabled : YES
[DEBUG] ME: TXT Support : NO
[DEBUG] ME: Manufacturing Vars Locked : YES
[DEBUG] ME: WP for RO is enabled : YES
[DEBUG] ME: RO write protection scope - Start=0x1000, End=0x1A6FFF
So ME region still protected.
[DEBUG] ME: WP for RO is enabled : YES
[DEBUG] ME: RO write protection scope - Start=0x1000, End=0x1A6FFF
tlaurion
left a comment
There was a problem hiding this comment.
@MrChromebox we need some help figuring out what steps are needed to properly disactivate HW+SW protection so ME is not reported as locked
|
@cwiggs any updates? |
|
No updates, haven't heard anything from MrChromebox. I just made this post: https://forum.chrultrabook.com/t/better-understanding-of-firmeware-write-protection/9084 hopefully it helps gain some traction? |
|
not sure the confusion here. On a factory clean device:
same as any other device which ships with a locked IFD - I assume. I do not have a MTL Chromebook (or any MTL device). Users wishing to run my firmware just need to disable HW WP via SuzyQ and my script does the rest. I don't touch the IFD or ME. |
Was this meant to say "disable HW WP via SuzyQ? To do this would that be following the steps 1 and 2 here: https://docs.mrchromebox.tech/docs/firmware/wp/disabling.html#using-closed-case-debugging-ccd-using-a-suzyqable
2 questions:
I don't remember doing this but I could be wrong. What is the process to unlock IFD?
|
yes for a factory fresh device, yes. For the case you asked about on the chrultrabook forums where the device is already flashed, no
on a factory fresh device, yes. On a device that's already flashed, it's already been done. Doesn't hurt to verify with
Yes. Connect the SuzyQ, open a terminal to ttyUSB0, verify WP off, verify factory reset, etc.
I have no idea what has or has not been done to your device. Unlocking the IFD requires external flashing. It's not something that flashing MrChromebox firmware requires (or recommends). What exactly are you needing to do that requires the IFD/ME areas be writable from a live system? Unlocking the IFD, at a high level, is:
HEADS has documentation on doing this. it's out of scope for MrChromebox firmware. |
Would that command be?:
|
|
@cwiggs LGTM other than --enable vs --disable but again, I would check with --wp-status first, so you know what the current state is |
|
GPR0 was active in ifd, I think i fixed it under linuxboot/heads#2133 (comment) I'm not sure I still have a complete grasp of the steps needed. |
why do you need to modify the ME region? isn't Kano already using CSME-lite? |
AFAIK, those blobs could be updated in coreboot blobs repo. If blob changed/updated in the future, if Heads doesn't provide RW access to it and doesn't provide a way to update it per board config (ie --ifd -i me), then end user would be left with an old version of it flashed externally. Under Heads, we apply HAP for now to the point it will cause regression (see linuxboot/heads#1801 : Meteor Lake last platform to support S3 allegedly: still function in practice but not supported by Intel). Same for ME+IFD writeable so we can flash whole SPI internally, and rely on PR0 to apply chipset locking before kexec call. That's also why I ask coreboot dev to push for https://review.coreboot.org/c/coreboot/+/85278 which for now is applied per fork as patches under Heads (We had that debate personally in the past @MrChromebox : it was showed possible to apply to Skylake+ and should be merged upstream). TLDR:
|
updated |
Signed-off-by: Chris Wiggins <chris@cwiggs.com>
|
Updated the guide with what I think is the proper approach now that I got confirmation that we don't need to remove the battery. I think I now understand hardware vs software write protection better. @MrChromebox Can you expand on why https://forum.chrultrabook.com/t/flashrom-error-when-trying-to-unbrick-with-suzyq/8789/2?u=stonework5729 is needed for Kano? |
not really, I don't have access to Google's documentation on why that's needed for (some? all?) Brya-based devices, I just know that it is. |
Cleanup a lot of the doc and add a backup section. Signed-off-by: Chris Wiggins <chris@cwiggs.com>
Understood. Thanks for the info! I pushed some more changes cleaning up some the doc and I added a section on how to backup the rom. Marked the PR as ready for review. |
preview: https://cwiggs.github.io/heads-wiki/