summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorLeah Rowe <leah@libreboot.org>2026-09-22 08:29:15 +0100
committerLeah Rowe <leah@libreboot.org>2026-09-22 09:45:24 +0100
commit8f6b42dfbaada38618deb888a20bb42689704ea2 (patch)
treeea74b00b540e76ed08a1797c557262a3701763bc
parent8fab3275190e9dbd8e66528ce1ec8c92becdc3c7 (diff)
experimental edk2 support
Signed-off-by: Leah Rowe <leah@libreboot.org>
-rw-r--r--config/data/edk2/build.list2
-rw-r--r--config/data/edk2/mkhelper.cfg5
-rw-r--r--config/module/edk2/default/nuke.list18
-rw-r--r--config/module/edk2/default/patches/0001-Remove-warning-for-coreboot-images-built-without-a-p.patch39
-rw-r--r--config/module/edk2/default/patches/0002-tests-Makefile.mk-use-3rdparty-cmocka-by-default.patch30
-rw-r--r--config/module/edk2/default/patches/0003-remove-Werror-tree-wide.patch718
-rw-r--r--config/module/edk2/default/patches/0004-Remove-KCONFIG_WERROR.patch94
-rw-r--r--config/module/edk2/default/patches/0006-don-t-delete-edk2.patch28
-rw-r--r--config/module/edk2/default/patches/0007-don-t-delete-build.patch38
-rw-r--r--config/module/edk2/default/patches/0008-copy-edk2-don-t-move-it.patch34
-rw-r--r--config/module/edk2/default/patches/0009-move-crossgcc-to-crossgcc_orig-and-symlink.patch215
-rw-r--r--config/module/edk2/default/patches/0053-use-std-gnu2x.patch156
-rw-r--r--config/module/edk2/default/target.cfg43
-rw-r--r--config/module/edk2/mrchromebox/config/libgfxinit_corebootfb13
-rw-r--r--config/module/edk2/mrchromebox/target.cfg6
-rw-r--r--config/submodule/edk2/default/arm-trusted-firmware/module.cfg5
-rw-r--r--config/submodule/edk2/default/cmocka/module.cfg5
-rw-r--r--config/submodule/edk2/default/cmocka/patches/0001-disable-Werror.patch74
-rw-r--r--config/submodule/edk2/default/fsp/module.cfg5
-rw-r--r--config/submodule/edk2/default/intel-microcode/module.cfg5
-rw-r--r--config/submodule/edk2/default/libgfxinit/module.cfg5
-rw-r--r--config/submodule/edk2/default/libgfxinit/patches/0001-g45-hw-gfx-gma-plls.adb-Make-reference-clock-frequen.patch42
-rw-r--r--config/submodule/edk2/default/libgfxinit/patches/0002-re-try-EDID-reading-when-it-fails.patch38
-rw-r--r--config/submodule/edk2/default/libhwbase/0001-remove-Werror.patch26
-rw-r--r--config/submodule/edk2/default/libhwbase/module.cfg5
-rw-r--r--config/submodule/edk2/default/module.list7
-rw-r--r--config/submodule/edk2/default/vboot/module.cfg5
-rw-r--r--config/submodule/edk2/default/vboot/patches/0001-extract_vmlinuz.c-Fix-the-bounds-check-on-vmlinuz_he.patch178
-rw-r--r--config/submodule/edk2/default/vboot/patches/0002-lib-cbfstool-fix-build-error-on-newer-hostcc.patch28
-rw-r--r--config/submodule/edk2/default/vboot/patches/0003-remove-Werror.patch58
30 files changed, 1925 insertions, 0 deletions
diff --git a/config/data/edk2/build.list b/config/data/edk2/build.list
new file mode 100644
index 00000000..55c2ee44
--- /dev/null
+++ b/config/data/edk2/build.list
@@ -0,0 +1,2 @@
+build/coreboot.rom
+payloads/external/edk2/workspace/Build/UefiPayloadPkgX64/RELEASE_GCC/FV/UEFIPAYLOAD.fd
diff --git a/config/data/edk2/mkhelper.cfg b/config/data/edk2/mkhelper.cfg
new file mode 100644
index 00000000..26f3180a
--- /dev/null
+++ b/config/data/edk2/mkhelper.cfg
@@ -0,0 +1,5 @@
+# SPDX-License-Identifier: GPL-3.0-or-later
+
+premake="echo TEST"
+mkhelper="echo TEST"
+postmake="echo TEST"
diff --git a/config/module/edk2/default/nuke.list b/config/module/edk2/default/nuke.list
new file mode 100644
index 00000000..e6c247d2
--- /dev/null
+++ b/config/module/edk2/default/nuke.list
@@ -0,0 +1,18 @@
+3rdparty/fsp/EagleStreamFspBinPkg
+3rdparty/fsp/MeteorLakeFspBinPkg
+3rdparty/fsp/IceLakeFspBinPkg
+3rdparty/fsp/AmberLakeFspBinPkg
+3rdparty/fsp/DenvertonNSFspBinPkg
+3rdparty/fsp/TigerLakeFspBinPkg
+3rdparty/fsp/CedarIslandFspBinPkg
+3rdparty/fsp/ElkhartLakeFspBinPkg
+3rdparty/fsp/CometLakeFspBinPkg
+3rdparty/fsp/WhitleyFspBinPkg
+3rdparty/fsp/ArrowLakeFspBinPkg
+3rdparty/fsp/IdavilleFspBinPkg
+3rdparty/fsp/BraswellFspBinPkg
+3rdparty/fsp/CoffeeLakeFspBinPkg
+3rdparty/fsp/RaptorLakeFspBinPkg
+3rdparty/fsp/ApolloLakeFspBinPkg
+3rdparty/fsp/SkylakeFspBinPkg
+3rdparty/vboot/tests
diff --git a/config/module/edk2/default/patches/0001-Remove-warning-for-coreboot-images-built-without-a-p.patch b/config/module/edk2/default/patches/0001-Remove-warning-for-coreboot-images-built-without-a-p.patch
new file mode 100644
index 00000000..8c922522
--- /dev/null
+++ b/config/module/edk2/default/patches/0001-Remove-warning-for-coreboot-images-built-without-a-p.patch
@@ -0,0 +1,39 @@
+From c7797c30efd80203bf4c99da293921f658f6b677 Mon Sep 17 00:00:00 2001
+From: Nicholas Chin <nic.c3.14@gmail.com>
+Date: Fri, 12 May 2023 19:55:15 -0600
+Subject: [PATCH 1/9] Remove warning for coreboot images built without a
+ payload
+
+I added this in upstream to prevent people from accidentally flashing
+roms without a payload resulting in a no boot situation, but in
+libreboot lbmk handles the payload and thus this warning always comes
+up. This has caused confusion and concern so just patch it out.
+---
+ payloads/Makefile.mk | 13 +------------
+ 1 file changed, 1 insertion(+), 12 deletions(-)
+
+diff --git a/payloads/Makefile.mk b/payloads/Makefile.mk
+index 5f988dac1b..516133880f 100644
+--- a/payloads/Makefile.mk
++++ b/payloads/Makefile.mk
+@@ -50,16 +50,5 @@ distclean-payloads:
+ print-repo-info-payloads:
+ -$(foreach payload, $(PAYLOADS_LIST), $(MAKE) -C $(payload) print-repo-info 2>/dev/null; )
+
+-ifeq ($(CONFIG_PAYLOAD_NONE),y)
+-show_notices:: warn_no_payload
+-endif
+-
+-warn_no_payload:
+- printf "\n\t** WARNING **\n"
+- printf "coreboot has been built without a payload. Writing\n"
+- printf "a coreboot image without a payload to your board's\n"
+- printf "flash chip will result in a non-booting system. You\n"
+- printf "can use cbfstool to add a payload to the image.\n\n"
+-
+ .PHONY: force-payload coreinfo nvramcui
+-.PHONY: clean-payloads distclean-payloads print-repo-info-payloads warn_no_payload
++.PHONY: clean-payloads distclean-payloads print-repo-info-payloads
+--
+2.47.3
+
diff --git a/config/module/edk2/default/patches/0002-tests-Makefile.mk-use-3rdparty-cmocka-by-default.patch b/config/module/edk2/default/patches/0002-tests-Makefile.mk-use-3rdparty-cmocka-by-default.patch
new file mode 100644
index 00000000..4d379ea7
--- /dev/null
+++ b/config/module/edk2/default/patches/0002-tests-Makefile.mk-use-3rdparty-cmocka-by-default.patch
@@ -0,0 +1,30 @@
+From ff67d8671b451ed391523dc139680b07594fb8c0 Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Sat, 20 Dec 2025 22:36:18 +0100
+Subject: [PATCH 2/9] tests/Makefile.mk: use 3rdparty/cmocka by default
+
+(tests)
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ tests/Makefile.mk | 4 +++-
+ 1 file changed, 3 insertions(+), 1 deletion(-)
+
+diff --git a/tests/Makefile.mk b/tests/Makefile.mk
+index ab302634ec..7e6f260b27 100644
+--- a/tests/Makefile.mk
++++ b/tests/Makefile.mk
+@@ -25,7 +25,9 @@ TEST_LDFLAGS += --coverage
+ endif
+
+ # Use system cmoka in default, or build from 3rdparty source code if requested
+-USE_SYSTEM_CMOCKA ?= 1
++# PATCH NOTE: lbmk sets it to 0 by default. You can still override it to 1
++# if you wish; upstream sets this to 1 by default, but we do 0
++USE_SYSTEM_CMOCKA ?= 0
+ ifeq ($(USE_SYSTEM_CMOCKA),1)
+ # Only probe for Cmocka (and possibly warn that it will be built from 3rdparty)
+ # when the requested goals actually build or run unit tests. Otherwise every
+--
+2.47.3
+
diff --git a/config/module/edk2/default/patches/0003-remove-Werror-tree-wide.patch b/config/module/edk2/default/patches/0003-remove-Werror-tree-wide.patch
new file mode 100644
index 00000000..bf37dd58
--- /dev/null
+++ b/config/module/edk2/default/patches/0003-remove-Werror-tree-wide.patch
@@ -0,0 +1,718 @@
+From 193253bf2437ba3d5d2ea4378157eb94b2f66bda Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Mon, 21 Sep 2026 10:46:07 +0100
+Subject: [PATCH 3/9] remove -Werror tree-wide
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ Makefile.mk | 2 -
+ .../external/tint/tint-0.07_libpayload.patch | 70 +++++++++----------
+ payloads/libpayload/Makefile.mk | 2 +-
+ payloads/libpayload/Makefile.payload | 2 +-
+ payloads/libpayload/sample/Makefile | 2 +-
+ payloads/libpayload/sample/arch_mock/Makefile | 2 +-
+ payloads/libpayload/tests/Makefile.mk | 2 +-
+ payloads/linuxcheck/Makefile | 2 +-
+ src/commonlib/gnat/Makefile.mk | 1 -
+ tests/Makefile.common | 2 +-
+ util/amdfwtool/Makefile.mk | 2 +-
+ util/archive/Makefile | 2 +-
+ util/bincfg/Makefile | 2 +-
+ util/bucts/Makefile | 2 +-
+ util/cbfstool/Makefile.mk | 2 +-
+ util/cbfstool/lz4/Makefile | 8 +--
+ util/cbmem/Makefile | 2 +-
+ util/crossgcc/patches/gcc-15.2.0_libcpp.patch | 2 +-
+ util/ectool/Makefile | 2 +-
+ util/futility/Makefile.mk | 2 +-
+ util/ifdtool/Makefile.mk | 2 +-
+ util/intelvbttool/Makefile | 2 +-
+ ...fdata.c-fix-Werror-discarded-qualifi.patch | 4 +-
+ util/kconfig/patches/series | 2 +-
+ util/msrtool/configure | 2 +-
+ util/pmh7tool/Makefile | 2 +-
+ util/superiotool/Makefile | 6 +-
+ util/uio_usbdebug/Makefile | 2 +-
+ util/xcompile/xcompile | 2 +-
+ 29 files changed, 67 insertions(+), 70 deletions(-)
+
+diff --git a/Makefile.mk b/Makefile.mk
+index 7a208d041d..f3480b1a28 100644
+--- a/Makefile.mk
++++ b/Makefile.mk
+@@ -555,7 +555,6 @@ CFLAGS_common += -ffunction-sections
+ CFLAGS_common += -fdata-sections
+ CFLAGS_common += -fno-pie
+ CFLAGS_common += -Wstring-compare
+-CFLAGS_common += -Werror
+ ifeq ($(CONFIG_COMPILER_GCC),y)
+ CFLAGS_common += -Wold-style-declaration
+ CFLAGS_common += -Wcast-function-type
+@@ -581,7 +580,6 @@ endif
+ ADAFLAGS_common += -gnatp
+ ADAFLAGS_common += -Wuninitialized
+ ADAFLAGS_common += -Wall
+-ADAFLAGS_common += -Werror
+ ADAFLAGS_common += -pipe
+ ADAFLAGS_common += -g
+ ADAFLAGS_common += -nostdinc
+diff --git a/payloads/external/tint/tint-0.07_libpayload.patch b/payloads/external/tint/tint-0.07_libpayload.patch
+index 6c9594a369..3d70539ffb 100644
+--- a/payloads/external/tint/tint-0.07_libpayload.patch
++++ b/payloads/external/tint/tint-0.07_libpayload.patch
+@@ -4,7 +4,7 @@ diff -rupN tint-0.05/config.h tint/config.h
+ @@ -29,7 +29,15 @@
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+-
++
+ +#include <libpayload.h>
+ +#include <curses.h>
+ +
+@@ -15,7 +15,7 @@ diff -rupN tint-0.05/config.h tint/config.h
+ +#if 0
+ const char scorefile[] = SCOREFILE;
+ +#endif
+-
++
+ #endif /* #ifndef CONFIG_H */
+ diff -rupN tint-0.05/engine.c tint/engine.c
+ --- tint-0.05/engine.c 2005-07-17 13:26:22.000000000 +0200
+@@ -23,14 +23,14 @@ diff -rupN tint-0.05/engine.c tint/engine.c
+ @@ -27,10 +27,13 @@
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+-
++
+ +#include "config.h"
+ +
+ +#if 0
+ #include <stdlib.h>
+ #include <string.h>
+ +#endif
+-
++
+ -#include "typedefs.h"
+ #include "utils.h"
+ #include "io.h"
+@@ -41,10 +41,10 @@ diff -rupN tint-0.05/engine.h tint/engine.h
+ @@ -29,7 +29,7 @@
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+-
++
+ -#include "typedefs.h" /* bool */
+ +#include "curses.h" /* bool */
+-
++
+ /*
+ * Macros
+ diff -rupN tint-0.05/io.c tint/io.c
+@@ -53,7 +53,7 @@ diff -rupN tint-0.05/io.c tint/io.c
+ @@ -27,9 +27,13 @@
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+-
++
+ +#include "config.h"
+ +
+ +#if 0
+@@ -61,9 +61,9 @@ diff -rupN tint-0.05/io.c tint/io.c
+ #include <sys/time.h> /* gettimeofday() */
+ #include <unistd.h> /* gettimeofday() */
+ +#endif
+-
++
+ #include "io.h"
+-
++
+ @@ -68,7 +72,11 @@ static int in_timeleft;
+ /* Initialize screen */
+ void io_init ()
+@@ -101,16 +101,16 @@ diff -rupN tint-0.05/io.c tint/io.c
+ +#endif
+ return ch;
+ }
+-
++
+ diff -rupN tint-0.05/io.h tint/io.h
+ --- tint-0.05/io.h 2010-06-23 14:55:03.000000000 +0100
+ +++ tint/io.h 2021-02-09 08:00:00.000000000 +0200
+ @@ -30,7 +30,6 @@
+ */
+-
++
+ #include <curses.h>
+ -#include <wchar.h>
+-
++
+ /*
+ * Colors
+ diff -rupN tint-0.05/Makefile tint/Makefile
+@@ -166,7 +166,7 @@ diff -rupN tint-0.05/Makefile tint/Makefile
+ +HAVE_LIBPAYLOAD := $(wildcard $(LIBPAYLOAD_DIR)/lib/libpayload.a)
+ +LIB_CONFIG ?= configs/defconfig-tinycurses
+ +
+-+# CFLAGS := -Wall -Werror -Os
+++# CFLAGS := -Wall -Os
+ +CFLAGS := -Wall -g -Os
+ +TARGET := tint
+ +OBJS := $(TARGET).o engine.o io.o utils.o
+@@ -234,7 +234,7 @@ diff -rupN tint-0.05/tint.c tint/tint.c
+ @@ -27,6 +26,7 @@
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+-
++
+ +#if 0
+ #include <stdlib.h>
+ #include <stdio.h>
+@@ -244,24 +244,24 @@ diff -rupN tint-0.05/tint.c tint/tint.c
+ #include <sys/types.h>
+ #include <unistd.h>
+ +#endif
+-
++
+ -#include "typedefs.h"
+ #include "utils.h"
+ #include "io.h"
+ #include "config.h"
+ @@ -304,7 +304,7 @@ static void showstatus (engine_t *engine
+ /***************************************************************************/
+-
++
+ /* Header for scorefile */
+ -#define SCORE_HEADER "Tint 0.02b (c) Abraham vd Merwe - Scores"
+ +#define SCORE_HEADER "Tint 0.05 (c) Abraham vd Merwe - Scores"
+-
++
+ /* Header for score title */
+ static const char scoretitle[] = "\n\t TINT HIGH SCORES\n\n\tRank Score Name\n\n";
+ @@ -322,6 +322,7 @@ typedef struct
+ time_t timestamp;
+ } score_t;
+-
++
+ +#if 0
+ static void getname (char *name)
+ {
+@@ -271,7 +271,7 @@ diff -rupN tint-0.05/tint.c tint/tint.c
+ }
+ }
+ +#endif
+-
++
+ +#if 0
+ static void err1 ()
+ {
+@@ -281,7 +281,7 @@ diff -rupN tint-0.05/tint.c tint/tint.c
+ exit (EXIT_FAILURE);
+ }
+ +#endif
+-
++
+ void showplayerstats (engine_t *engine)
+ {
+ - fprintf (stderr,
+@@ -292,7 +292,7 @@ diff -rupN tint-0.05/tint.c tint/tint.c
+ @@ -361,6 +365,7 @@ void showplayerstats (engine_t *engine)
+ GETSCORE (engine->score),engine->status.efficiency,GETSCORE (engine->score) / getsum ());
+ }
+-
++
+ +#if 0
+ static void createscores (int score)
+ {
+@@ -302,7 +302,7 @@ diff -rupN tint-0.05/tint.c tint/tint.c
+ fprintf (stderr,"\t 1* %7d %s\n\n",score,scores[0].name);
+ }
+ +#endif
+-
++
+ +#if 0
+ static int cmpscores (const void *a,const void *b)
+ {
+@@ -312,7 +312,7 @@ diff -rupN tint-0.05/tint.c tint/tint.c
+ return 0;
+ }
+ +#endif
+-
++
+ +#if 0
+ static void savescores (int score)
+ {
+@@ -322,11 +322,11 @@ diff -rupN tint-0.05/tint.c tint/tint.c
+ fprintf (stderr,"\n");
+ }
+ +#endif
+-
++
+ /***************************************************************************/
+ /***************************************************************************/
+ /***************************************************************************/
+-
++
+ +#if 0
+ static void showhelp ()
+ {
+@@ -336,7 +336,7 @@ diff -rupN tint-0.05/tint.c tint/tint.c
+ exit (EXIT_FAILURE);
+ }
+ +#endif
+-
++
+ static void parse_options (int argc,char *argv[])
+ {
+ +#if 0
+@@ -349,12 +349,12 @@ diff -rupN tint-0.05/tint.c tint/tint.c
+ }
+ +#endif
+ }
+-
++
+ static void choose_level ()
+ {
+ +#if 0
+ char buf[NAMELEN];
+-
++
+ do
+ @@ -557,6 +572,8 @@ static void choose_level ()
+ buf[strlen (buf) - 1] = '\0';
+@@ -363,7 +363,7 @@ diff -rupN tint-0.05/tint.c tint/tint.c
+ +#endif
+ + level = 1;
+ }
+-
++
+ /***************************************************************************/
+ @@ -569,6 +586,8 @@ int main (int argc,char *argv[])
+ int ch;
+@@ -423,14 +423,14 @@ diff -rupN tint-0.05/tint.c tint/tint.c
+ exit (EXIT_SUCCESS);
+ +#endif
+ }
+-
++
+ diff -rupN tint-0.05/utils.c tint/utils.c
+ --- tint-0.05/utils.c 2001-12-07 16:49:19.000000000 +0100
+ +++ tint/utils.c 2021-02-09 08:00:00.000000000 +0200
+ @@ -27,11 +27,13 @@
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+-
++
+ +#include "config.h"
+ +
+ +#if 0
+@@ -440,7 +440,7 @@ diff -rupN tint-0.05/utils.c tint/utils.c
+ -
+ -#include "typedefs.h"
+ +#endif
+-
++
+ /*
+ * Initialize random number generator
+ @@ -61,6 +63,7 @@ int rand_value (int range)
+@@ -454,7 +454,7 @@ diff -rupN tint-0.05/utils.c tint/utils.c
+ @@ -69,3 +72,4 @@ bool str2int (int *i,const char *str)
+ return TRUE;
+ }
+-
++
+ +#endif
+ diff -rupN tint-0.05/utils.h tint/utils.h
+ --- tint-0.05/utils.h 2001-12-07 16:49:35.000000000 +0100
+@@ -462,9 +462,9 @@ diff -rupN tint-0.05/utils.h tint/utils.h
+ @@ -29,7 +29,7 @@
+ * OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
+ */
+-
++
+ -#include "typedefs.h"
+ +#include <curses.h>
+-
++
+ /*
+ * Initialize random number generator
+diff --git a/payloads/libpayload/Makefile.mk b/payloads/libpayload/Makefile.mk
+index 0f5d1a0e11..45c2c5ad74 100644
+--- a/payloads/libpayload/Makefile.mk
++++ b/payloads/libpayload/Makefile.mk
+@@ -80,7 +80,7 @@ CFLAGS += -nostdlib -fno-builtin -ffreestanding -fomit-frame-pointer
+ CFLAGS += -ffunction-sections -fdata-sections
+ CFLAGS += -Wall -Wundef -Wstrict-prototypes -Wmissing-prototypes -Wvla
+ CFLAGS += -Wwrite-strings -Wredundant-decls -Wimplicit-fallthrough
+-CFLAGS += -Wstrict-aliasing -Wshadow -Wno-address-of-packed-member -Werror
++CFLAGS += -Wstrict-aliasing -Wshadow -Wno-address-of-packed-member
+
+ ifeq ($(CONFIG_LP_LTO),y)
+ CFLAGS += -flto
+diff --git a/payloads/libpayload/Makefile.payload b/payloads/libpayload/Makefile.payload
+index 2eafd4bec3..c74704c58d 100644
+--- a/payloads/libpayload/Makefile.payload
++++ b/payloads/libpayload/Makefile.payload
+@@ -84,7 +84,7 @@ endif
+
+ CFLAGS = $(CFLAGS_$(ARCH))
+ CFLAGS += -Os -ffreestanding
+-CFLAGS += -Wall -Wextra -Wmissing-prototypes -Wvla -Werror
++CFLAGS += -Wall -Wextra -Wmissing-prototypes -Wvla
+ ifeq ($(CONFIG_LP_LTO),y)
+ CFLAGS += -flto
+ endif
+diff --git a/payloads/libpayload/sample/Makefile b/payloads/libpayload/sample/Makefile
+index 1249e9a017..269511d7df 100644
+--- a/payloads/libpayload/sample/Makefile
++++ b/payloads/libpayload/sample/Makefile
+@@ -44,7 +44,7 @@ AS := $(AS_$(ARCH-y))
+ LIBPAYLOAD_DIR := ../install/libpayload
+ XCC := CC="$(CC)" $(LIBPAYLOAD_DIR)/bin/lpgcc
+ XAS := AS="$(AS)" $(LIBPAYLOAD_DIR)/bin/lpas
+-CFLAGS := -fno-builtin -Wall -Werror -Os
++CFLAGS := -fno-builtin -Wall -Os
+ TARGET := hello
+ OBJS := $(TARGET).o
+
+diff --git a/payloads/libpayload/sample/arch_mock/Makefile b/payloads/libpayload/sample/arch_mock/Makefile
+index a1e748111e..a146c2b3be 100644
+--- a/payloads/libpayload/sample/arch_mock/Makefile
++++ b/payloads/libpayload/sample/arch_mock/Makefile
+@@ -12,7 +12,7 @@ CC := gcc
+ AS := as
+ OBJCOPY := objcopy
+ LIBPAYLOAD_DIR := ../../install/libpayload
+-CFLAGS := -fno-builtin -Wall -Werror -Os \
++CFLAGS := -fno-builtin -Wall -Os \
+ -include $(LIBPAYLOAD_DIR)/include/kconfig.h \
+ -include $(LIBPAYLOAD_DIR)/include/compiler.h \
+ -I $(LIBPAYLOAD_DIR)/include \
+diff --git a/payloads/libpayload/tests/Makefile.mk b/payloads/libpayload/tests/Makefile.mk
+index 6b6c78d835..b2e7433b65 100644
+--- a/payloads/libpayload/tests/Makefile.mk
++++ b/payloads/libpayload/tests/Makefile.mk
+@@ -45,7 +45,7 @@ TEST_CFLAGS += -I$(cmockasrc)/include
+ # Minimal subset of warnings and errors. Tests can be less strict than actual build.
+ TEST_CFLAGS += -Wall -Wundef -Wstrict-prototypes -Wvla
+ TEST_CFLAGS += -Wwrite-strings -Wno-address-of-packed-member -Wimplicit-fallthrough
+-TEST_CFLAGS += -Wstrict-aliasing -Wshadow -Werror
++TEST_CFLAGS += -Wstrict-aliasing -Wshadow
+ TEST_CFLAGS += -Wno-unknown-warning-option -Wno-source-mgr -Wno-main-return-type
+
+ TEST_CFLAGS += -std=gnu11 -ffunction-sections -fdata-sections -fno-builtin
+diff --git a/payloads/linuxcheck/Makefile b/payloads/linuxcheck/Makefile
+index 838c90df0c..a9d016db36 100644
+--- a/payloads/linuxcheck/Makefile
++++ b/payloads/linuxcheck/Makefile
+@@ -3,7 +3,7 @@ XCOMPILE=$(LIBPAYLOAD_DIR)/libpayload.xcompile
+ # build libpayload and put .config file in $(CURDIR) instead of ../libpayload
+ # to avoid pollute the libpayload source directory and possible conflicts
+ LPOPTS=obj="$(CURDIR)/build" DESTDIR="$(CURDIR)" DOTCONFIG="$(CURDIR)/.config"
+-CFLAGS += -Wall -Wvla -Werror -Os -ffreestanding -nostdinc -nostdlib
++CFLAGS += -Wall -Wvla -Os -ffreestanding -nostdinc -nostdlib
+ ifeq ($(CONFIG_ARCH_X86),y)
+ TARGETARCH = i386
+ endif
+diff --git a/src/commonlib/gnat/Makefile.mk b/src/commonlib/gnat/Makefile.mk
+index 773615c2cc..26891690cc 100644
+--- a/src/commonlib/gnat/Makefile.mk
++++ b/src/commonlib/gnat/Makefile.mk
+@@ -12,7 +12,6 @@ ADAFLAGS_libgnat-$(1) := \
+ -gnatpg \
+ -I$(dir) \
+ $$(GCC_ADAFLAGS_$(1)) \
+- -Werror \
+ -fno-pie \
+
+ libgnat-$(1)-y += a-unccon.ads
+diff --git a/tests/Makefile.common b/tests/Makefile.common
+index 14cacaeca7..c35e312a79 100644
+--- a/tests/Makefile.common
++++ b/tests/Makefile.common
+@@ -46,7 +46,7 @@ TEST_INCLUDES += -I$(dir $(TEST_KCONFIG_AUTOHEADER))
+ # -Wmissing-prototypes just make working with the test framework cumbersome.
+ # Only put conservative warnings here that really detect code that's obviously
+ # unintentional.
+-TEST_CFLAGS += -Wall -Werror -Wundef -Wstrict-prototypes -Wno-inline-asm
++TEST_CFLAGS += -Wall -Wundef -Wstrict-prototypes -Wno-inline-asm
+ TEST_CFLAGS += -Wno-unknown-warning-option -Wno-source-mgr -Wno-main-return-type
+ TEST_CFLAGS += -Wno-array-compare -Wno-trigraphs
+ TEST_CFLAGS += -Wno-unused-but-set-variables
+diff --git a/util/amdfwtool/Makefile.mk b/util/amdfwtool/Makefile.mk
+index 1f819d918f..f7dce01b71 100644
+--- a/util/amdfwtool/Makefile.mk
++++ b/util/amdfwtool/Makefile.mk
+@@ -6,7 +6,7 @@ amdfwtoolobj = amdfwtool.o data_parse.o signed_psp.o handle_file.o opts.o soc.o
+ amdfwreadobj = amdfwread.o
+ amdfwheader = amdfwtool.h
+
+-WERROR ?= -Werror
++WERROR =
+ AMDFWTOOLCFLAGS :=-O2 -Wall -Wextra -Wshadow $(WERROR)
+ AMDFWTOOLCFLAGS += -I $(top)/src/commonlib/bsd/include
+ AMDFWTOOLCFLAGS += -I $(top)/src/
+diff --git a/util/archive/Makefile b/util/archive/Makefile
+index 2de6a6294a..d301017253 100644
+--- a/util/archive/Makefile
++++ b/util/archive/Makefile
+@@ -1,7 +1,7 @@
+ ## SPDX-License-Identifier: GPL-2.0-only
+ PROGRAM = archive
+ HOSTCC ?= gcc
+-WERROR=-Werror
++WERROR=
+ CFLAGS=-O2 -Wall -Wextra -Wshadow ${WERROR}
+
+ SRCS = $(PROGRAM).c
+diff --git a/util/bincfg/Makefile b/util/bincfg/Makefile
+index dbcbc7711c..5f97f60f34 100644
+--- a/util/bincfg/Makefile
++++ b/util/bincfg/Makefile
+@@ -3,7 +3,7 @@ CC = gcc
+ YACC = bison
+ LEX = flex
+ TARGET=bincfg
+-WERROR=-Werror
++WERROR=
+ CFLAGS=-O2 -Wall -Wextra -Wshadow ${WERROR}
+ CFLAGS+=-Wno-unused-function
+ LDFLAGS= -lfl
+diff --git a/util/bucts/Makefile b/util/bucts/Makefile
+index d32258d1ec..50da491a8a 100644
+--- a/util/bucts/Makefile
++++ b/util/bucts/Makefile
+@@ -3,7 +3,7 @@ CC:=gcc
+ OBJ:=bucts.o
+ TARGET=bucts
+ VERSION:=$(shell git describe)
+-WERROR=-Werror
++WERROR=
+ CFLAGS=-O2 -Wall -Wextra -Wshadow ${WERROR}
+
+ ifeq ($(shell uname), FreeBSD)
+diff --git a/util/cbfstool/Makefile.mk b/util/cbfstool/Makefile.mk
+index 315a9a751a..d195e4713a 100644
+--- a/util/cbfstool/Makefile.mk
++++ b/util/cbfstool/Makefile.mk
+@@ -146,7 +146,7 @@ test_obj += fmap.o
+ test_obj += kv_pair.o
+ test_obj += valstr.o
+
+-TOOLCFLAGS ?= -Werror -Wall -Wextra -Wshadow
++TOOLCFLAGS ?= -Wall -Wextra -Wshadow
+ TOOLCFLAGS += -Wcast-qual -Wmissing-prototypes -Wredundant-decls -Wshadow
+ TOOLCFLAGS += -Wstrict-prototypes -Wwrite-strings
+ TOOLCFLAGS += -O2
+diff --git a/util/cbfstool/lz4/Makefile b/util/cbfstool/lz4/Makefile
+index d624e84703..be484c805f 100644
+--- a/util/cbfstool/lz4/Makefile
++++ b/util/cbfstool/lz4/Makefile
+@@ -72,10 +72,10 @@ cmake:
+ @cd cmake_unofficial; cmake CMakeLists.txt; $(MAKE)
+
+ gpptest: clean
+- $(MAKE) all CC=g++ CFLAGS="-O3 -I../lib -Wall -Wextra -Wundef -Wshadow -Wcast-align -Werror"
++ $(MAKE) all CC=g++ CFLAGS="-O3 -I../lib -Wall -Wextra -Wundef -Wshadow -Wcast-align"
+
+ clangtest: clean
+- CFLAGS="-O3 -Werror -Wconversion -Wno-sign-conversion" $(MAKE) all CC=clang
++ CFLAGS="-O3 -Wconversion -Wno-sign-conversion" $(MAKE) all CC=clang
+
+ sanitize: clean
+ CFLAGS="-O3 -g -fsanitize=undefined" $(MAKE) test CC=clang FUZZER_TIME="-T1mn" NB_LOOPS=-i1
+@@ -84,8 +84,8 @@ staticAnalyze: clean
+ CFLAGS=-g clang-tidy $(CLANG_TIDY_CHECKS) $(CLANG_TIDY_ARGS) $(SRCS)
+
+ armtest: clean
+- CFLAGS="-O3 -Werror" $(MAKE) -C $(LZ4DIR) all CC=arm-linux-gnueabi-gcc
+- CFLAGS="-O3 -Werror" $(MAKE) -C $(PRGDIR) bins CC=arm-linux-gnueabi-gcc
++ CFLAGS="-O3" $(MAKE) -C $(LZ4DIR) all CC=arm-linux-gnueabi-gcc
++ CFLAGS="-O3" $(MAKE) -C $(PRGDIR) bins CC=arm-linux-gnueabi-gcc
+
+ versionsTest: clean
+ $(MAKE) -C versionsTest
+diff --git a/util/cbmem/Makefile b/util/cbmem/Makefile
+index c0dfcbdc52..fe2891be6d 100644
+--- a/util/cbmem/Makefile
++++ b/util/cbmem/Makefile
+@@ -9,7 +9,7 @@ CC ?= $(CROSS_COMPILE)gcc
+ INSTALL ?= /usr/bin/env install
+ PREFIX ?= /usr/local
+ CFLAGS ?= -O2
+-WERROR=-Werror
++WERROR=
+ CFLAGS += -Wall -Wextra -Wmissing-prototypes -Wshadow $(WERROR)
+ CFLAGS += -std=gnu23
+ CPPFLAGS += -I . -I $(ROOT)/commonlib/include -I $(ROOT)/commonlib/bsd/include
+diff --git a/util/crossgcc/patches/gcc-15.2.0_libcpp.patch b/util/crossgcc/patches/gcc-15.2.0_libcpp.patch
+index ba60732f72..f1dc6aa2d6 100644
+--- a/util/crossgcc/patches/gcc-15.2.0_libcpp.patch
++++ b/util/crossgcc/patches/gcc-15.2.0_libcpp.patch
+@@ -1,4 +1,4 @@
+-GCC with `-Wformat-security -Werror=format-security` hardening options enabled
++GCC with `-Wformat-security =format-security` hardening options enabled
+ by default rejects some codes in libcpp. This patch fixes them.
+
+ --- gcc-15-20250112/libcpp/expr.cc.bak
+diff --git a/util/ectool/Makefile b/util/ectool/Makefile
+index a90773e5c6..5724ac6009 100644
+--- a/util/ectool/Makefile
++++ b/util/ectool/Makefile
+@@ -1,7 +1,7 @@
+ ## SPDX-License-Identifier: GPL-2.0-only
+
+ CC ?= gcc
+-WERROR=-Werror
++WERROR=
+ CFLAGS = -O2 -Wall -Wextra -Wshadow $(WERROR)
+ PROGRAM = ectool
+ INSTALL ?= /usr/bin/env install
+diff --git a/util/futility/Makefile.mk b/util/futility/Makefile.mk
+index a7bcee50d3..ba930a046b 100644
+--- a/util/futility/Makefile.mk
++++ b/util/futility/Makefile.mk
+@@ -10,7 +10,7 @@ $(VBOOT_FUTILITY): | check-openssl-presence
+ unset CFLAGS LDFLAGS; $(MAKE) -C $(VBOOT_SOURCE) \
+ BUILD=$(VBOOT_HOST_BUILD) \
+ CC="$(HOSTCC)" \
+- WERROR="-Werror -Wno-deprecated-declarations" \
++ WERROR=" -Wno-deprecated-declarations" \
+ PKG_CONFIG="$(HOSTPKGCONFIG)" \
+ V=$(V) \
+ USE_FLASHROM=0 \
+diff --git a/util/ifdtool/Makefile.mk b/util/ifdtool/Makefile.mk
+index 53506469d3..57d192ccb8 100644
+--- a/util/ifdtool/Makefile.mk
++++ b/util/ifdtool/Makefile.mk
+@@ -2,7 +2,7 @@
+
+ ifdtoolobj = ifdtool.o fmap.o kv_pair.o valstr.o
+
+-IFDTOOLCFLAGS = -O2 -g -Wall -Wextra -Wmissing-prototypes -Werror
++IFDTOOLCFLAGS = -O2 -g -Wall -Wextra -Wmissing-prototypes
+ IFDTOOLCFLAGS += -I$(top)/src/commonlib/include -I$(top)/src/commonlib/bsd/include
+ IFDTOOLCFLAGS += -I$(top)/util/cbfstool/flashmap
+ IFDTOOLCFLAGS += -include $(top)/src/commonlib/bsd/include/commonlib/bsd/compiler.h
+diff --git a/util/intelvbttool/Makefile b/util/intelvbttool/Makefile
+index 5c770dec9e..8963263354 100644
+--- a/util/intelvbttool/Makefile
++++ b/util/intelvbttool/Makefile
+@@ -6,7 +6,7 @@ CC ?= gcc
+ INSTALL ?= /usr/bin/env install
+ PREFIX ?= /usr/local
+ CFLAGS ?= -O2 -g
+-CFLAGS += -Wall -Werror
++CFLAGS += -Wall
+ CFLAGS += -I../../src/commonlib/include -I ../../src/commonlib/bsd/include
+
+ all: $(PROGRAM)
+diff --git a/util/kconfig/patches/0016-util-kconfig-confdata.c-fix-Werror-discarded-qualifi.patch b/util/kconfig/patches/0016-util-kconfig-confdata.c-fix-Werror-discarded-qualifi.patch
+index a367256102..401061d6c5 100644
+--- a/util/kconfig/patches/0016-util-kconfig-confdata.c-fix-Werror-discarded-qualifi.patch
++++ b/util/kconfig/patches/0016-util-kconfig-confdata.c-fix-Werror-discarded-qualifi.patch
+@@ -1,7 +1,7 @@
+ From 2a1a1d1b305ab276279234f70410bb6486a2049f Mon Sep 17 00:00:00 2001
+ From: Mike Banon <mikebdp2@gmail.com>
+ Date: Tue, 10 Mar 2026 00:14:58 +0100
+-Subject: [PATCH] util/kconfig/confdata.c: fix -Werror=discarded-qualifiers
++Subject: [PATCH] util/kconfig/confdata.c: fix =discarded-qualifiers
+
+ In conf_read_simple(), strchr() is called on 'sym_name', which is
+ declared const char. The function returns a char that discards the
+@@ -36,6 +36,6 @@ index 0105917..ae6ae2b 100644
+ int i, def_flags;
+ - const char *warn_unknown, *sym_name;
+ + const char *warn_unknown;
+-
++
+ warn_unknown = getenv("KCONFIG_WARN_UNKNOWN_SYMBOLS");
+ if (name) {
+diff --git a/util/kconfig/patches/series b/util/kconfig/patches/series
+index 31d446ef81..739bee9279 100644
+--- a/util/kconfig/patches/series
++++ b/util/kconfig/patches/series
+@@ -8,4 +8,4 @@
+ 0013-util-kconfig-detect-ncurses-on-FreeBSD.patch
+ 0014-util-kconfig-Move-Kconfig-deps-back-into-build-confi.patch
+ 0015-fix-incorrect-spdx-strings.patch
+-0016-util-kconfig-confdata.c-fix-Werror-discarded-qualifi.patch
++0016-util-kconfig-confdata.c-fix-discarded-qualifi.patch
+diff --git a/util/msrtool/configure b/util/msrtool/configure
+index 659cbcd66b..0415e4d9c9 100755
+--- a/util/msrtool/configure
++++ b/util/msrtool/configure
+@@ -133,7 +133,7 @@ CC=`findprog "compiler" "${CC}" clang gcc cc icc` || exit
+ INSTALL=`findprog "install" "${INSTALL}" install ginstall` || exit
+
+ test -n "$DEBUG" && myCFLAGS="-O2 -g" || myCFLAGS="-Os"
+-CFLAGS="${CFLAGS} ${myCFLAGS} -Wall -Werror"
++CFLAGS="${CFLAGS} ${myCFLAGS} -Wall "
+
+ cat > .config.c << EOF
+ #include <pci/pci.h>
+diff --git a/util/pmh7tool/Makefile b/util/pmh7tool/Makefile
+index 0a2ebbe147..c04d7e9bf9 100644
+--- a/util/pmh7tool/Makefile
++++ b/util/pmh7tool/Makefile
+@@ -1,7 +1,7 @@
+ ## SPDX-License-Identifier: GPL-2.0-only
+
+ CC = gcc
+-CFLAGS = -O2 -Wall -Wextra -Werror
++CFLAGS = -O2 -Wall -Wextra
+ PROGRAM = pmh7tool
+ INSTALL = /usr/bin/env install
+ PREFIX = /usr/local
+diff --git a/util/superiotool/Makefile b/util/superiotool/Makefile
+index 2dcfc9e929..2aad3b92e5 100644
+--- a/util/superiotool/Makefile
++++ b/util/superiotool/Makefile
+@@ -12,7 +12,7 @@ PREFIX ?= /usr/local
+ VERSION := -D'SUPERIOTOOL_VERSION="$(shell git describe 2>/dev/null)"'
+
+ CFLAGS += -O2 -Wall -Wstrict-prototypes -Wundef -Wstrict-aliasing \
+- -Werror-implicit-function-declaration -std=c11 -pedantic $(VERSION) \
++ -implicit-function-declaration -std=c11 -pedantic $(VERSION) \
+ -Wno-variadic-macros -I $(TOP)/src/commonlib/bsd/include
+ LDFLAGS += -lz
+
+@@ -24,8 +24,8 @@ ifeq ($(OS_ARCH), Darwin)
+ LIBS = -framework IOKit -framework DirectHW -lpci -lz
+ endif
+ ifeq ($(OS_ARCH), FreeBSD)
+-CFLAGS = -O2 -Wall -Werror -Wstrict-prototypes -Wundef -Wstrict-aliasing \
+- -Werror-implicit-function-declaration -std=c11 $(VERSION) \
++CFLAGS = -O2 -Wall -Wstrict-prototypes -Wundef -Wstrict-aliasing \
++ -implicit-function-declaration -std=c11 $(VERSION) \
+ -I/usr/local/include
+ LDFLAGS += -L/usr/local/lib
+ LIBS = -lz
+diff --git a/util/uio_usbdebug/Makefile b/util/uio_usbdebug/Makefile
+index af1cc8e1ec..8a3603c41d 100644
+--- a/util/uio_usbdebug/Makefile
++++ b/util/uio_usbdebug/Makefile
+@@ -30,7 +30,7 @@ KCONFIG_H := ../../src/include/kconfig.h
+
+ CFLAGS += \
+ -m32 -g \
+- -Wall -Wextra -Werror \
++ -Wall -Wextra \
+ -Wno-unused-parameter -Wno-error=sign-compare
+ CPPFLAGS += \
+ -Iinclude/ \
+diff --git a/util/xcompile/xcompile b/util/xcompile/xcompile
+index f88da69306..02d134c8e8 100755
+--- a/util/xcompile/xcompile
++++ b/util/xcompile/xcompile
+@@ -124,7 +124,7 @@ testcc() {
+ local tmp_o="$TMPFILE.o"
+ rm -f "$tmp_c" "$tmp_o"
+ echo "void _start(void) {}" >"$tmp_c"
+- "$cc" -nostdlib -Werror $cflags -c "$tmp_c" -o "$tmp_o" >/dev/null 2>&1
++ "$cc" -nostdlib $cflags -c "$tmp_c" -o "$tmp_o" >/dev/null 2>&1
+ }
+
+ testld() {
+--
+2.47.3
+
diff --git a/config/module/edk2/default/patches/0004-Remove-KCONFIG_WERROR.patch b/config/module/edk2/default/patches/0004-Remove-KCONFIG_WERROR.patch
new file mode 100644
index 00000000..04038189
--- /dev/null
+++ b/config/module/edk2/default/patches/0004-Remove-KCONFIG_WERROR.patch
@@ -0,0 +1,94 @@
+From 2676e5c95bb583db83cadb932a82977c8cdb2c20 Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Mon, 21 Sep 2026 11:20:54 +0100
+Subject: [PATCH 4/9] Remove KCONFIG_WERROR
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ Documentation/getting_started/kconfig.md | 3 ---
+ Makefile | 4 ----
+ util/kconfig/Makefile | 4 ----
+ util/kconfig/confdata.c | 2 --
+ util/kconfig/symbol.c | 2 --
+ 5 files changed, 15 deletions(-)
+
+diff --git a/Documentation/getting_started/kconfig.md b/Documentation/getting_started/kconfig.md
+index 2917c53aae..6c4102ba17 100644
+--- a/Documentation/getting_started/kconfig.md
++++ b/Documentation/getting_started/kconfig.md
+@@ -99,9 +99,6 @@ included in the Linux version.
+ - KCONFIG_SPLITCONFIG=”directory name for individual SYMBOL.h files”.
+ coreboot sets this to $(obj)/config.
+
+-- KCONFIG_WERROR=value. Define to enable warnings as errors. This is enabled
+- in coreboot, and should not be changed.
+-
+ #### Used only for ‘make menuconfig’
+ - MENUCONFIG_MODE=single_menu. Set to "single_menu" to enable. All other
+ values disable the option. This makes submenus appear below the menu option
+diff --git a/Makefile b/Makefile
+index 6a36b5968f..35576f3734 100644
+--- a/Makefile
++++ b/Makefile
+@@ -31,7 +31,6 @@ KCONFIG_DEPENDENCIES := $(obj)/auto.conf.cmd
+ KCONFIG_SPLITCONFIG := $(obj)/config/
+ KCONFIG_TRISTATE := $(obj)/tristate.conf
+ KCONFIG_NEGATIVES := 1
+-KCONFIG_WERROR := 1
+ KCONFIG_WARN_UNKNOWN_SYMBOLS := 1
+ KCONFIG_PACKAGE := CB.Config
+ KCONFIG_MAKEFILE_REAL ?= $(objk)/Makefile.real
+@@ -39,9 +38,6 @@ KCONFIG_MAKEFILE_REAL ?= $(objk)/Makefile.real
+ COREBOOT_EXPORTS += KCONFIG_CONFIG KCONFIG_AUTOHEADER KCONFIG_AUTOCONFIG
+ COREBOOT_EXPORTS += KCONFIG_DEPENDENCIES KCONFIG_SPLITCONFIG KCONFIG_TRISTATE
+ COREBOOT_EXPORTS += KCONFIG_NEGATIVES
+-ifeq ($(filter %config,$(MAKECMDGOALS)),)
+-COREBOOT_EXPORTS += KCONFIG_WERROR
+-endif
+ COREBOOT_EXPORTS += KCONFIG_WARN_UNKNOWN_SYMBOLS
+ COREBOOT_EXPORTS += KCONFIG_AUTOADS KCONFIG_PACKAGE
+ COREBOOT_EXPORTS += KCONFIG_RUSTCCFG
+diff --git a/util/kconfig/Makefile b/util/kconfig/Makefile
+index 76cc2c5e2c..45366936fc 100644
+--- a/util/kconfig/Makefile
++++ b/util/kconfig/Makefile
+@@ -31,10 +31,6 @@ ifneq ($(findstring c, $(KBUILD_EXTRA_WARN)),)
+ export KCONFIG_WARN_UNKNOWN_SYMBOLS=1
+ endif
+
+-ifneq ($(findstring e, $(KBUILD_EXTRA_WARN)),)
+-export KCONFIG_WERROR=1
+-endif
+-
+ # We need this, in case the user has it in its environment
+ unexport CONFIG_
+
+diff --git a/util/kconfig/confdata.c b/util/kconfig/confdata.c
+index ae6ae2b3d3..fa09647f44 100644
+--- a/util/kconfig/confdata.c
++++ b/util/kconfig/confdata.c
+@@ -157,8 +157,6 @@ static int conf_lineno, conf_warnings;
+
+ bool conf_errors(void)
+ {
+- if (conf_warnings)
+- return getenv("KCONFIG_WERROR");
+ return false;
+ }
+
+diff --git a/util/kconfig/symbol.c b/util/kconfig/symbol.c
+index 3afe5be2d4..1a24d458cb 100644
+--- a/util/kconfig/symbol.c
++++ b/util/kconfig/symbol.c
+@@ -317,8 +317,6 @@ static void sym_warn_unmet_dep(struct symbol *sym)
+
+ bool sym_dep_errors(void)
+ {
+- if (sym_warnings)
+- return getenv("KCONFIG_WERROR");
+ return false;
+ }
+
+--
+2.47.3
+
diff --git a/config/module/edk2/default/patches/0006-don-t-delete-edk2.patch b/config/module/edk2/default/patches/0006-don-t-delete-edk2.patch
new file mode 100644
index 00000000..74272902
--- /dev/null
+++ b/config/module/edk2/default/patches/0006-don-t-delete-edk2.patch
@@ -0,0 +1,28 @@
+From d952ebf5ff9ef68424cc1c85b4e2adfabebdb24e Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Tue, 22 Sep 2026 08:01:01 +0100
+Subject: [PATCH 6/9] don't delete edk2
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ payloads/external/edk2/Makefile | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/payloads/external/edk2/Makefile b/payloads/external/edk2/Makefile
+index 75b7f7983d..05df683fed 100644
+--- a/payloads/external/edk2/Makefile
++++ b/payloads/external/edk2/Makefile
+@@ -424,8 +424,8 @@ UniversalPayload: $(WORKSPACE)/Build/UefiPayloadPkgIA32/UniversalPayload.fit
+ clean:
+ test -d $(WORKSPACE) && (cd $(WORKSPACE); rm -rf Build; rm -f Conf/tools_def.txt Conf/CapsuleFmpPkcs7Pcd.inc) || exit 0
+
+-distclean:
+- rm -rf $(WORKSPACE)
++distclean: clean
++ :
+
+ .PHONY: $(EDK2_PATH) checktools logo UefiPayloadPkg UniversalPayload clean distclean
+
+--
+2.47.3
+
diff --git a/config/module/edk2/default/patches/0007-don-t-delete-build.patch b/config/module/edk2/default/patches/0007-don-t-delete-build.patch
new file mode 100644
index 00000000..fa320332
--- /dev/null
+++ b/config/module/edk2/default/patches/0007-don-t-delete-build.patch
@@ -0,0 +1,38 @@
+From 8227a6b08675fbd31bcee9b9143a73dd75be813e Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Tue, 22 Sep 2026 08:56:32 +0100
+Subject: [PATCH 7/9] don't delete build
+
+lbmk build.list needs to be able to copy this
+
+it also means that we will then have the ability
+to quickly re-use old build artifacts on re-build.
+
+this is a highly experimental edk2 integration in
+lbmk. when i implement it properly, lbmk will have
+its own logic for everything, without relying on
+the coreboot build system. i'm only doing it this
+way for now as a proof of concept, to show that
+edk2 can work in libreboot.
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ payloads/external/edk2/Makefile | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/payloads/external/edk2/Makefile b/payloads/external/edk2/Makefile
+index 05df683fed..948169d74a 100644
+--- a/payloads/external/edk2/Makefile
++++ b/payloads/external/edk2/Makefile
+@@ -422,7 +422,7 @@ UniversalPayload: $(WORKSPACE)/Build/UefiPayloadPkgIA32/UniversalPayload.fit
+ $(EDK2_UNIVERSAL_PAYLOAD_OUT)
+
+ clean:
+- test -d $(WORKSPACE) && (cd $(WORKSPACE); rm -rf Build; rm -f Conf/tools_def.txt Conf/CapsuleFmpPkcs7Pcd.inc) || exit 0
++ test -d $(WORKSPACE) && (cd $(WORKSPACE); rm -f Conf/tools_def.txt Conf/CapsuleFmpPkcs7Pcd.inc) || exit 0
+
+ distclean: clean
+ :
+--
+2.47.3
+
diff --git a/config/module/edk2/default/patches/0008-copy-edk2-don-t-move-it.patch b/config/module/edk2/default/patches/0008-copy-edk2-don-t-move-it.patch
new file mode 100644
index 00000000..6a5e9afa
--- /dev/null
+++ b/config/module/edk2/default/patches/0008-copy-edk2-don-t-move-it.patch
@@ -0,0 +1,34 @@
+From da0ea93d3ba5e749380ea27f7c015ec8e4c32479 Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Tue, 22 Sep 2026 09:15:38 +0100
+Subject: [PATCH 8/9] copy edk2, don't move it
+
+then we will have it in build.list for lbmk
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ payloads/external/edk2/Makefile | 4 ++--
+ 1 file changed, 2 insertions(+), 2 deletions(-)
+
+diff --git a/payloads/external/edk2/Makefile b/payloads/external/edk2/Makefile
+index 948169d74a..d6f3d98001 100644
+--- a/payloads/external/edk2/Makefile
++++ b/payloads/external/edk2/Makefile
+@@ -413,12 +413,12 @@ $(WORKSPACE)/Build/UefiPayloadPkgIA32/UniversalPayload.fit: \
+
+ UefiPayloadPkg: $(WORKSPACE)/Build/UefiPayloadPkgX64/$(RELEASE_STR)_GCC/FV/UEFIPAYLOAD.fd
+ mkdir -p $(dir $(EDK2_UEFIPAYLOAD_OUT))
+- mv $(WORKSPACE)/Build/UefiPayloadPkgX64/$(RELEASE_STR)_GCC/FV/UEFIPAYLOAD.fd \
++ cp $(WORKSPACE)/Build/UefiPayloadPkgX64/$(RELEASE_STR)_GCC/FV/UEFIPAYLOAD.fd \
+ $(EDK2_UEFIPAYLOAD_OUT)
+
+ UniversalPayload: $(WORKSPACE)/Build/UefiPayloadPkgIA32/UniversalPayload.fit
+ mkdir -p $(dir $(EDK2_UNIVERSAL_PAYLOAD_OUT))
+- mv $(WORKSPACE)/Build/UefiPayloadPkgIA32/UniversalPayload.fit \
++ cp $(WORKSPACE)/Build/UefiPayloadPkgIA32/UniversalPayload.fit \
+ $(EDK2_UNIVERSAL_PAYLOAD_OUT)
+
+ clean:
+--
+2.47.3
+
diff --git a/config/module/edk2/default/patches/0009-move-crossgcc-to-crossgcc_orig-and-symlink.patch b/config/module/edk2/default/patches/0009-move-crossgcc-to-crossgcc_orig-and-symlink.patch
new file mode 100644
index 00000000..ba744512
--- /dev/null
+++ b/config/module/edk2/default/patches/0009-move-crossgcc-to-crossgcc_orig-and-symlink.patch
@@ -0,0 +1,215 @@
+From b346f014103c88b9f2cf2a439c6156a4b0e699f1 Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Tue, 22 Sep 2026 09:17:41 +0100
+Subject: [PATCH 9/9] move crossgcc to crossgcc_orig, and symlink
+
+make a symlink for crossgcc/ for us to re-use
+from libreboot.
+
+this patch will have to be maintained according
+to whatever xarch is set to in edk2 lbmk, but
+it will probably always be default, and thus
+this patch will always be correct.
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ util/crossgcc | 1 +
+ util/crossgcc/tarballs/.empty | 0
+ util/{crossgcc => crossgcc_orig}/.gitignore | 0
+ util/{crossgcc => crossgcc_orig}/Makefile | 0
+ util/{crossgcc => crossgcc_orig}/Makefile.mk | 0
+ util/{crossgcc => crossgcc_orig}/README | 0
+ util/{crossgcc => crossgcc_orig}/buildgcc | 0
+ util/{crossgcc => crossgcc_orig}/description.md | 0
+ util/{crossgcc => crossgcc_orig}/edk2tools.txt | 0
+ util/{crossgcc => crossgcc_orig}/getopt.c | 0
+ .../patches/acpica-unix-20251212_iasl.patch | 0
+ .../patches/binutils-2.46.1_as-ipxe.patch | 0
+ .../patches/binutils-2.46.1_no-makeinfo.patch | 0
+ .../patches/gcc-15.2.0_asan_shadow_offset_callback.patch | 0
+ util/{crossgcc => crossgcc_orig}/patches/gcc-15.2.0_gnat.patch | 0
+ .../{crossgcc => crossgcc_orig}/patches/gcc-15.2.0_libcody.patch | 0
+ util/{crossgcc => crossgcc_orig}/patches/gcc-15.2.0_libcpp.patch | 0
+ util/{crossgcc => crossgcc_orig}/patches/gcc-15.2.0_libgcc.patch | 0
+ .../patches/gcc-15.2.0_musl_poisoned_calloc.patch | 0
+ .../patches/gcc-15.2.0_rv32iafc.patch | 0
+ .../patches/gmp-6.3.0_fix-c23-prototypes.patch | 0
+ .../patches/gmp-6.3.0_generic-build.patch | 0
+ ...rc_clang-add-x86_64-baremetal-triple-include-search-pat.patch | 0
+ .../sum/acpica-unix-20251212.tar.gz.cksum | 0
+ .../{crossgcc => crossgcc_orig}/sum/binutils-2.46.1.tar.xz.cksum | 0
+ util/{crossgcc => crossgcc_orig}/sum/cmake-4.3.4.tar.gz.cksum | 0
+ util/{crossgcc => crossgcc_orig}/sum/gcc-15.2.0.tar.xz.cksum | 0
+ util/{crossgcc => crossgcc_orig}/sum/gmp-6.3.0.tar.xz.cksum | 0
+ .../sum/llvm-project-22.1.8.src.tar.xz.cksum | 0
+ util/{crossgcc => crossgcc_orig}/sum/mpc-1.4.1.tar.xz.cksum | 0
+ util/{crossgcc => crossgcc_orig}/sum/mpfr-4.2.2.tar.xz.cksum | 0
+ util/{crossgcc => crossgcc_orig}/sum/nasm-3.02.tar.bz2.cksum | 0
+ 32 files changed, 1 insertion(+)
+ create mode 120000 util/crossgcc
+ delete mode 100644 util/crossgcc/tarballs/.empty
+ rename util/{crossgcc => crossgcc_orig}/.gitignore (100%)
+ rename util/{crossgcc => crossgcc_orig}/Makefile (100%)
+ rename util/{crossgcc => crossgcc_orig}/Makefile.mk (100%)
+ rename util/{crossgcc => crossgcc_orig}/README (100%)
+ rename util/{crossgcc => crossgcc_orig}/buildgcc (100%)
+ rename util/{crossgcc => crossgcc_orig}/description.md (100%)
+ rename util/{crossgcc => crossgcc_orig}/edk2tools.txt (100%)
+ rename util/{crossgcc => crossgcc_orig}/getopt.c (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/acpica-unix-20251212_iasl.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/binutils-2.46.1_as-ipxe.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/binutils-2.46.1_no-makeinfo.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/gcc-15.2.0_asan_shadow_offset_callback.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/gcc-15.2.0_gnat.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/gcc-15.2.0_libcody.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/gcc-15.2.0_libcpp.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/gcc-15.2.0_libgcc.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/gcc-15.2.0_musl_poisoned_calloc.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/gcc-15.2.0_rv32iafc.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/gmp-6.3.0_fix-c23-prototypes.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/gmp-6.3.0_generic-build.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/patches/llvm-project-22.1.8.src_clang-add-x86_64-baremetal-triple-include-search-pat.patch (100%)
+ rename util/{crossgcc => crossgcc_orig}/sum/acpica-unix-20251212.tar.gz.cksum (100%)
+ rename util/{crossgcc => crossgcc_orig}/sum/binutils-2.46.1.tar.xz.cksum (100%)
+ rename util/{crossgcc => crossgcc_orig}/sum/cmake-4.3.4.tar.gz.cksum (100%)
+ rename util/{crossgcc => crossgcc_orig}/sum/gcc-15.2.0.tar.xz.cksum (100%)
+ rename util/{crossgcc => crossgcc_orig}/sum/gmp-6.3.0.tar.xz.cksum (100%)
+ rename util/{crossgcc => crossgcc_orig}/sum/llvm-project-22.1.8.src.tar.xz.cksum (100%)
+ rename util/{crossgcc => crossgcc_orig}/sum/mpc-1.4.1.tar.xz.cksum (100%)
+ rename util/{crossgcc => crossgcc_orig}/sum/mpfr-4.2.2.tar.xz.cksum (100%)
+ rename util/{crossgcc => crossgcc_orig}/sum/nasm-3.02.tar.bz2.cksum (100%)
+
+diff --git a/util/crossgcc b/util/crossgcc
+new file mode 120000
+index 0000000000..9a648d35f7
+--- /dev/null
++++ b/util/crossgcc
+@@ -0,0 +1 @@
++../../../coreboot/default/util/crossgcc/
+\ No newline at end of file
+diff --git a/util/crossgcc/tarballs/.empty b/util/crossgcc/tarballs/.empty
+deleted file mode 100644
+index e69de29bb2..0000000000
+diff --git a/util/crossgcc/.gitignore b/util/crossgcc_orig/.gitignore
+similarity index 100%
+rename from util/crossgcc/.gitignore
+rename to util/crossgcc_orig/.gitignore
+diff --git a/util/crossgcc/Makefile b/util/crossgcc_orig/Makefile
+similarity index 100%
+rename from util/crossgcc/Makefile
+rename to util/crossgcc_orig/Makefile
+diff --git a/util/crossgcc/Makefile.mk b/util/crossgcc_orig/Makefile.mk
+similarity index 100%
+rename from util/crossgcc/Makefile.mk
+rename to util/crossgcc_orig/Makefile.mk
+diff --git a/util/crossgcc/README b/util/crossgcc_orig/README
+similarity index 100%
+rename from util/crossgcc/README
+rename to util/crossgcc_orig/README
+diff --git a/util/crossgcc/buildgcc b/util/crossgcc_orig/buildgcc
+similarity index 100%
+rename from util/crossgcc/buildgcc
+rename to util/crossgcc_orig/buildgcc
+diff --git a/util/crossgcc/description.md b/util/crossgcc_orig/description.md
+similarity index 100%
+rename from util/crossgcc/description.md
+rename to util/crossgcc_orig/description.md
+diff --git a/util/crossgcc/edk2tools.txt b/util/crossgcc_orig/edk2tools.txt
+similarity index 100%
+rename from util/crossgcc/edk2tools.txt
+rename to util/crossgcc_orig/edk2tools.txt
+diff --git a/util/crossgcc/getopt.c b/util/crossgcc_orig/getopt.c
+similarity index 100%
+rename from util/crossgcc/getopt.c
+rename to util/crossgcc_orig/getopt.c
+diff --git a/util/crossgcc/patches/acpica-unix-20251212_iasl.patch b/util/crossgcc_orig/patches/acpica-unix-20251212_iasl.patch
+similarity index 100%
+rename from util/crossgcc/patches/acpica-unix-20251212_iasl.patch
+rename to util/crossgcc_orig/patches/acpica-unix-20251212_iasl.patch
+diff --git a/util/crossgcc/patches/binutils-2.46.1_as-ipxe.patch b/util/crossgcc_orig/patches/binutils-2.46.1_as-ipxe.patch
+similarity index 100%
+rename from util/crossgcc/patches/binutils-2.46.1_as-ipxe.patch
+rename to util/crossgcc_orig/patches/binutils-2.46.1_as-ipxe.patch
+diff --git a/util/crossgcc/patches/binutils-2.46.1_no-makeinfo.patch b/util/crossgcc_orig/patches/binutils-2.46.1_no-makeinfo.patch
+similarity index 100%
+rename from util/crossgcc/patches/binutils-2.46.1_no-makeinfo.patch
+rename to util/crossgcc_orig/patches/binutils-2.46.1_no-makeinfo.patch
+diff --git a/util/crossgcc/patches/gcc-15.2.0_asan_shadow_offset_callback.patch b/util/crossgcc_orig/patches/gcc-15.2.0_asan_shadow_offset_callback.patch
+similarity index 100%
+rename from util/crossgcc/patches/gcc-15.2.0_asan_shadow_offset_callback.patch
+rename to util/crossgcc_orig/patches/gcc-15.2.0_asan_shadow_offset_callback.patch
+diff --git a/util/crossgcc/patches/gcc-15.2.0_gnat.patch b/util/crossgcc_orig/patches/gcc-15.2.0_gnat.patch
+similarity index 100%
+rename from util/crossgcc/patches/gcc-15.2.0_gnat.patch
+rename to util/crossgcc_orig/patches/gcc-15.2.0_gnat.patch
+diff --git a/util/crossgcc/patches/gcc-15.2.0_libcody.patch b/util/crossgcc_orig/patches/gcc-15.2.0_libcody.patch
+similarity index 100%
+rename from util/crossgcc/patches/gcc-15.2.0_libcody.patch
+rename to util/crossgcc_orig/patches/gcc-15.2.0_libcody.patch
+diff --git a/util/crossgcc/patches/gcc-15.2.0_libcpp.patch b/util/crossgcc_orig/patches/gcc-15.2.0_libcpp.patch
+similarity index 100%
+rename from util/crossgcc/patches/gcc-15.2.0_libcpp.patch
+rename to util/crossgcc_orig/patches/gcc-15.2.0_libcpp.patch
+diff --git a/util/crossgcc/patches/gcc-15.2.0_libgcc.patch b/util/crossgcc_orig/patches/gcc-15.2.0_libgcc.patch
+similarity index 100%
+rename from util/crossgcc/patches/gcc-15.2.0_libgcc.patch
+rename to util/crossgcc_orig/patches/gcc-15.2.0_libgcc.patch
+diff --git a/util/crossgcc/patches/gcc-15.2.0_musl_poisoned_calloc.patch b/util/crossgcc_orig/patches/gcc-15.2.0_musl_poisoned_calloc.patch
+similarity index 100%
+rename from util/crossgcc/patches/gcc-15.2.0_musl_poisoned_calloc.patch
+rename to util/crossgcc_orig/patches/gcc-15.2.0_musl_poisoned_calloc.patch
+diff --git a/util/crossgcc/patches/gcc-15.2.0_rv32iafc.patch b/util/crossgcc_orig/patches/gcc-15.2.0_rv32iafc.patch
+similarity index 100%
+rename from util/crossgcc/patches/gcc-15.2.0_rv32iafc.patch
+rename to util/crossgcc_orig/patches/gcc-15.2.0_rv32iafc.patch
+diff --git a/util/crossgcc/patches/gmp-6.3.0_fix-c23-prototypes.patch b/util/crossgcc_orig/patches/gmp-6.3.0_fix-c23-prototypes.patch
+similarity index 100%
+rename from util/crossgcc/patches/gmp-6.3.0_fix-c23-prototypes.patch
+rename to util/crossgcc_orig/patches/gmp-6.3.0_fix-c23-prototypes.patch
+diff --git a/util/crossgcc/patches/gmp-6.3.0_generic-build.patch b/util/crossgcc_orig/patches/gmp-6.3.0_generic-build.patch
+similarity index 100%
+rename from util/crossgcc/patches/gmp-6.3.0_generic-build.patch
+rename to util/crossgcc_orig/patches/gmp-6.3.0_generic-build.patch
+diff --git a/util/crossgcc/patches/llvm-project-22.1.8.src_clang-add-x86_64-baremetal-triple-include-search-pat.patch b/util/crossgcc_orig/patches/llvm-project-22.1.8.src_clang-add-x86_64-baremetal-triple-include-search-pat.patch
+similarity index 100%
+rename from util/crossgcc/patches/llvm-project-22.1.8.src_clang-add-x86_64-baremetal-triple-include-search-pat.patch
+rename to util/crossgcc_orig/patches/llvm-project-22.1.8.src_clang-add-x86_64-baremetal-triple-include-search-pat.patch
+diff --git a/util/crossgcc/sum/acpica-unix-20251212.tar.gz.cksum b/util/crossgcc_orig/sum/acpica-unix-20251212.tar.gz.cksum
+similarity index 100%
+rename from util/crossgcc/sum/acpica-unix-20251212.tar.gz.cksum
+rename to util/crossgcc_orig/sum/acpica-unix-20251212.tar.gz.cksum
+diff --git a/util/crossgcc/sum/binutils-2.46.1.tar.xz.cksum b/util/crossgcc_orig/sum/binutils-2.46.1.tar.xz.cksum
+similarity index 100%
+rename from util/crossgcc/sum/binutils-2.46.1.tar.xz.cksum
+rename to util/crossgcc_orig/sum/binutils-2.46.1.tar.xz.cksum
+diff --git a/util/crossgcc/sum/cmake-4.3.4.tar.gz.cksum b/util/crossgcc_orig/sum/cmake-4.3.4.tar.gz.cksum
+similarity index 100%
+rename from util/crossgcc/sum/cmake-4.3.4.tar.gz.cksum
+rename to util/crossgcc_orig/sum/cmake-4.3.4.tar.gz.cksum
+diff --git a/util/crossgcc/sum/gcc-15.2.0.tar.xz.cksum b/util/crossgcc_orig/sum/gcc-15.2.0.tar.xz.cksum
+similarity index 100%
+rename from util/crossgcc/sum/gcc-15.2.0.tar.xz.cksum
+rename to util/crossgcc_orig/sum/gcc-15.2.0.tar.xz.cksum
+diff --git a/util/crossgcc/sum/gmp-6.3.0.tar.xz.cksum b/util/crossgcc_orig/sum/gmp-6.3.0.tar.xz.cksum
+similarity index 100%
+rename from util/crossgcc/sum/gmp-6.3.0.tar.xz.cksum
+rename to util/crossgcc_orig/sum/gmp-6.3.0.tar.xz.cksum
+diff --git a/util/crossgcc/sum/llvm-project-22.1.8.src.tar.xz.cksum b/util/crossgcc_orig/sum/llvm-project-22.1.8.src.tar.xz.cksum
+similarity index 100%
+rename from util/crossgcc/sum/llvm-project-22.1.8.src.tar.xz.cksum
+rename to util/crossgcc_orig/sum/llvm-project-22.1.8.src.tar.xz.cksum
+diff --git a/util/crossgcc/sum/mpc-1.4.1.tar.xz.cksum b/util/crossgcc_orig/sum/mpc-1.4.1.tar.xz.cksum
+similarity index 100%
+rename from util/crossgcc/sum/mpc-1.4.1.tar.xz.cksum
+rename to util/crossgcc_orig/sum/mpc-1.4.1.tar.xz.cksum
+diff --git a/util/crossgcc/sum/mpfr-4.2.2.tar.xz.cksum b/util/crossgcc_orig/sum/mpfr-4.2.2.tar.xz.cksum
+similarity index 100%
+rename from util/crossgcc/sum/mpfr-4.2.2.tar.xz.cksum
+rename to util/crossgcc_orig/sum/mpfr-4.2.2.tar.xz.cksum
+diff --git a/util/crossgcc/sum/nasm-3.02.tar.bz2.cksum b/util/crossgcc_orig/sum/nasm-3.02.tar.bz2.cksum
+similarity index 100%
+rename from util/crossgcc/sum/nasm-3.02.tar.bz2.cksum
+rename to util/crossgcc_orig/sum/nasm-3.02.tar.bz2.cksum
+--
+2.47.3
+
diff --git a/config/module/edk2/default/patches/0053-use-std-gnu2x.patch b/config/module/edk2/default/patches/0053-use-std-gnu2x.patch
new file mode 100644
index 00000000..a1e437b8
--- /dev/null
+++ b/config/module/edk2/default/patches/0053-use-std-gnu2x.patch
@@ -0,0 +1,156 @@
+From 47a2305433ea6b123ef6baf65f496b4583e198da Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Mon, 21 Sep 2026 13:00:09 +0100
+Subject: [PATCH 53/56] use -std=gnu2x
+MIME-Version: 1.0
+Content-Type: text/plain; charset=UTF-8
+Content-Transfer-Encoding: 8bit
+
+equiv to gnu23 in practise, and fixes a build error
+for a user who reported:
+
+cc: error: unrecognized command-line option ‘-std=gnu23’; did you mean ‘-std=gnu2x’?
+
+when building coreboot utils
+
+gnu2x is gnu23 in practise, on both gcc and clang.
+we can just use this, and it won't break systems
+that worked.
+
+the user did not say what compiler and compiler version
+they were using (cbutils are built using hostcc in lbmk)
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ Makefile.mk | 2 +-
+ payloads/libpayload/Makefile | 2 +-
+ tests/Makefile.common | 2 +-
+ util/amdfwtool/Makefile.mk | 2 +-
+ util/cbfstool/Makefile.mk | 2 +-
+ util/cbmem/Makefile | 2 +-
+ util/ifdtool/Makefile.mk | 2 +-
+ util/sconfig/Makefile.mk | 2 +-
+ util/supermicro/Makefile.mk | 2 +-
+ 13 files changed, 599 insertions(+), 9 deletions(-)
+
+diff --git a/Makefile.mk b/Makefile.mk
+index 2c39d3d632..12e2368a8f 100644
+--- a/Makefile.mk
++++ b/Makefile.mk
+@@ -530,7 +530,7 @@ endif
+ CFLAGS_common += -pipe
+ CFLAGS_common += -g
+ CFLAGS_common += -nostdinc
+-CFLAGS_common += -std=gnu23
++CFLAGS_common += -std=gnu2x
+ CFLAGS_common += -nostdlib
+ CFLAGS_common += -Wall
+ CFLAGS_common += -Wundef
+diff --git a/payloads/libpayload/Makefile b/payloads/libpayload/Makefile
+index 29c3fb199f..bb7c6f600f 100644
+--- a/payloads/libpayload/Makefile
++++ b/payloads/libpayload/Makefile
+@@ -218,7 +218,7 @@ STRIP := $(STRIP_$(ARCH-y))
+ AR := $(AR_$(ARCH-y))
+ endif
+
+-CFLAGS += -std=gnu23 $(CFLAGS_$(ARCH-y))
++CFLAGS += -std=gnu2x $(CFLAGS_$(ARCH-y))
+
+ ifeq ($(CONFIG_LP_COMPILER_LLVM_CLANG),y)
+ CC:=clang
+diff --git a/tests/Makefile.common b/tests/Makefile.common
+index c35e312a79..5c6f8ff798 100644
+--- a/tests/Makefile.common
++++ b/tests/Makefile.common
+@@ -51,7 +51,7 @@ TEST_CFLAGS += -Wno-unknown-warning-option -Wno-source-mgr -Wno-main-return-type
+ TEST_CFLAGS += -Wno-array-compare -Wno-trigraphs
+ TEST_CFLAGS += -Wno-unused-but-set-variables
+
+-TEST_CFLAGS += -std=gnu23 -ffunction-sections -fdata-sections -fno-builtin
++TEST_CFLAGS += -std=gnu2x -ffunction-sections -fdata-sections -fno-builtin
+
+ ifneq ($(filter-out 0,$(DEBUG)),)
+ TEST_CFLAGS += -Og -ggdb3
+diff --git a/util/amdfwtool/Makefile.mk b/util/amdfwtool/Makefile.mk
+index f7dce01b71..ac09d083cf 100644
+--- a/util/amdfwtool/Makefile.mk
++++ b/util/amdfwtool/Makefile.mk
+@@ -11,7 +11,7 @@ AMDFWTOOLCFLAGS :=-O2 -Wall -Wextra -Wshadow $(WERROR)
+ AMDFWTOOLCFLAGS += -I $(top)/src/commonlib/bsd/include
+ AMDFWTOOLCFLAGS += -I $(top)/src/
+ AMDFWTOOLCFLAGS += -D_GNU_SOURCE # memmem() from string.h
+-AMDFWTOOLCFLAGS += -std=gnu23
++AMDFWTOOLCFLAGS += -std=gnu2x
+ AMDFWTOOLCFLAGS += -ffunction-sections -fdata-sections
+
+ ifneq ($(PKG_CONFIG),)
+diff --git a/util/cbfstool/Makefile.mk b/util/cbfstool/Makefile.mk
+index d195e4713a..75e8f1797f 100644
+--- a/util/cbfstool/Makefile.mk
++++ b/util/cbfstool/Makefile.mk
+@@ -175,7 +175,7 @@ HOSTCFLAGS += -fms-extensions
+ TOOLCFLAGS += -mno-ms-bitfields
+ endif
+ ifeq ($(shell uname -o 2>/dev/null), Cygwin)
+-TOOLCFLAGS+=-std=gnu23
++TOOLCFLAGS+=-std=gnu2x
+ TOOLCPPFLAGS+=-D_GNU_SOURCE
+ else
+ TOOLCFLAGS+=-std=c11
+diff --git a/util/cbmem/Makefile b/util/cbmem/Makefile
+index fe2891be6d..bb305cee77 100644
+--- a/util/cbmem/Makefile
++++ b/util/cbmem/Makefile
+@@ -11,7 +11,7 @@ PREFIX ?= /usr/local
+ CFLAGS ?= -O2
+ WERROR=
+ CFLAGS += -Wall -Wextra -Wmissing-prototypes -Wshadow $(WERROR)
+-CFLAGS += -std=gnu23
++CFLAGS += -std=gnu2x
+ CPPFLAGS += -I . -I $(ROOT)/commonlib/include -I $(ROOT)/commonlib/bsd/include
+ CPPFLAGS += -include $(ROOT)/commonlib/bsd/include/commonlib/bsd/compiler.h
+
+diff --git a/util/ifdtool/Makefile.mk b/util/ifdtool/Makefile.mk
+index 57d192ccb8..58bec4739c 100644
+--- a/util/ifdtool/Makefile.mk
++++ b/util/ifdtool/Makefile.mk
+@@ -7,7 +7,7 @@ IFDTOOLCFLAGS += -I$(top)/src/commonlib/include -I$(top)/src/commonlib/bsd/inclu
+ IFDTOOLCFLAGS += -I$(top)/util/cbfstool/flashmap
+ IFDTOOLCFLAGS += -include $(top)/src/commonlib/bsd/include/commonlib/bsd/compiler.h
+ IFDTOOLCFLAGS += -D_DEFAULT_SOURCE # for endianness converting functions
+-IFDTOOLCFLAGS += -std=gnu23
++IFDTOOLCFLAGS += -std=gnu2x
+
+ $(objutil)/ifdtool/%.o: $(top)/util/ifdtool/%.c
+ $(HOSTCC) $(IFDTOOLCFLAGS) $(HOSTCFLAGS) -c -o $@ $<
+diff --git a/util/sconfig/Makefile.mk b/util/sconfig/Makefile.mk
+index 9dcf5b5c71..cda1d81223 100644
+--- a/util/sconfig/Makefile.mk
++++ b/util/sconfig/Makefile.mk
+@@ -6,7 +6,7 @@ sconfigobj += main.o
+
+ SCONFIGFLAGS += -I$(top)/util/sconfig -I$(objutil)/sconfig
+ SCONFIGFLAGS += -I$(top)/src/commonlib/include -I$(top)/src/commonlib/bsd/include
+-SCONFIGFLAGS += -std=gnu23
++SCONFIGFLAGS += -std=gnu2x
+
+ $(objutil)/sconfig:
+ mkdir -p $@
+diff --git a/util/supermicro/Makefile.mk b/util/supermicro/Makefile.mk
+index f627b854bd..f5e0d7012c 100644
+--- a/util/supermicro/Makefile.mk
++++ b/util/supermicro/Makefile.mk
+@@ -6,7 +6,7 @@ SMCBIOSINFOTOOL:= $(objutil)/supermicro/smcbiosinfo
+ $(SMCBIOSINFOTOOL): $(dir)/smcbiosinfo/smcbiosinfo.c
+ printf " HOSTCC Creating SMCBIOSINFO tool\n"
+ mkdir -p $(objutil)/supermicro
+- $(HOSTCC) -std=gnu23 $(TOOLCPPFLAGS) $< -o $@
++ $(HOSTCC) -std=gnu2x $(TOOLCPPFLAGS) $< -o $@
+
+ ifeq ($(CONFIG_VENDOR_SUPERMICRO),y)
+ ifneq ($(call strip_quotes, $(CONFIG_SUPERMICRO_BOARDID)),)
+
+--
+2.47.3
+
diff --git a/config/module/edk2/default/target.cfg b/config/module/edk2/default/target.cfg
new file mode 100644
index 00000000..0fcde42a
--- /dev/null
+++ b/config/module/edk2/default/target.cfg
@@ -0,0 +1,43 @@
+# SPDX-License-Identifier: GPL-3.0-or-later
+
+# can be overridden per-tree e.g. use mrchromebox
+url="https://github.com/coreboot/coreboot.git"
+bkup_url="https://review.coreboot.org/coreboot"
+
+makeargs="UPDATED_SUBMODULES=1 CPUS=$XBMK_THREADS"
+
+rev="8ce4c91c41da3f042979f92095149a85bc93227d"
+
+# edk2 in lbmk is actually coreboot, but with a fake board config
+# that turns on edk2. coreboot is patched to never delete tianocore
+# source code.
+
+# however, it is also patched not to download tianocore. we download
+# it, using libreboot's submodules feature! for redundancy, and patching
+
+# this is a lazy way to do edk2 without integrating it into lbmk, which
+# would bloat lbmk. coreboot already does all the magic, and matt maintains
+# it. why reinvent matt's perfect wheel?
+
+# it costs about half a minute extra, to build one coreboot target,
+# and then the build is used in bulk across boards. this is the leah
+# way to do tianocore in your coreboot distribution.
+
+# yes.
+
+xarch="i386-elf" # hack. for building the fake coreboot target
+# not a performance hurdle on releases, since we will also use
+# that coreboot target, and thus we will use crossgcc there
+
+tree="default"
+
+# we will build crossgcc in here,
+# with ours symlinking to it
+fetch_depend="coreboot/default"
+
+# not stable yet for lbmk releases.
+# tianocore payloads will be disabled
+# in coreboot targets that use them,
+# and coreboot targets that only use
+# edk2 will have release=n as well
+release="n"
diff --git a/config/module/edk2/mrchromebox/config/libgfxinit_corebootfb b/config/module/edk2/mrchromebox/config/libgfxinit_corebootfb
new file mode 100644
index 00000000..5991c06c
--- /dev/null
+++ b/config/module/edk2/mrchromebox/config/libgfxinit_corebootfb
@@ -0,0 +1,13 @@
+CONFIG_USE_CBFS_FILE_OPTION_BACKEND=y
+CONFIG_VENDOR_LENOVO=y
+# CONFIG_NO_POST is not set
+CONFIG_CBFS_SIZE=0xEEC000
+CONFIG_CONSOLE_SERIAL=y
+CONFIG_USE_LEGACY_8254_TIMER=y
+CONFIG_BOARD_LENOVO_T480=y
+# CONFIG_FSP_HYPERTHREADING is not set
+CONFIG_MEC1653_ENABLE_UART=y
+# CONFIG_SMMSTORE is not set
+# CONFIG_FSP_USE_REPO is not set
+# CONFIG_TPM2 is not set
+CONFIG_PAYLOAD_EDK2=y
diff --git a/config/module/edk2/mrchromebox/target.cfg b/config/module/edk2/mrchromebox/target.cfg
new file mode 100644
index 00000000..90b914d9
--- /dev/null
+++ b/config/module/edk2/mrchromebox/target.cfg
@@ -0,0 +1,6 @@
+# SPDX-License-Identifier: GPL-3.0-or-later
+
+# look inside default/
+# all the logic for this hack is in there!
+
+tree="default"
diff --git a/config/submodule/edk2/default/arm-trusted-firmware/module.cfg b/config/submodule/edk2/default/arm-trusted-firmware/module.cfg
new file mode 100644
index 00000000..08331cf5
--- /dev/null
+++ b/config/submodule/edk2/default/arm-trusted-firmware/module.cfg
@@ -0,0 +1,5 @@
+# SPDX-License-Identifier: GPL-3.0-or-later
+
+subgit="https://review.coreboot.org/arm-trusted-firmware.git"
+subgit_bkup="https://github.com/coreboot/arm-trusted-firmware"
+subhash="b5eaba47efc5e4e3029086d5c25eee0e8dbb0129"
diff --git a/config/submodule/edk2/default/cmocka/module.cfg b/config/submodule/edk2/default/cmocka/module.cfg
new file mode 100644
index 00000000..32a43066
--- /dev/null
+++ b/config/submodule/edk2/default/cmocka/module.cfg
@@ -0,0 +1,5 @@
+# SPDX-License-Identifier: GPL-3.0-or-later
+
+subgit="https://review.coreboot.org/cmocka.git"
+subgit_bkup="https://github.com/coreboot/cmocka"
+subhash="8be37372097d1aa5e03b565936db7891b6180e73"
diff --git a/config/submodule/edk2/default/cmocka/patches/0001-disable-Werror.patch b/config/submodule/edk2/default/cmocka/patches/0001-disable-Werror.patch
new file mode 100644
index 00000000..8bf8bf10
--- /dev/null
+++ b/config/submodule/edk2/default/cmocka/patches/0001-disable-Werror.patch
@@ -0,0 +1,74 @@
+From 0762c4d3ad28239550f39793946c00a4866a797f Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Mon, 21 Sep 2026 10:49:57 +0100
+Subject: [PATCH 1/1] disable -Werror
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ .ycm_extra_conf.py | 1 -
+ CompilerChecks.cmake | 17 -----------------
+ 2 files changed, 18 deletions(-)
+
+diff --git a/.ycm_extra_conf.py b/.ycm_extra_conf.py
+index 8305a8b..538bc2b 100644
+--- a/.ycm_extra_conf.py
++++ b/.ycm_extra_conf.py
+@@ -4,7 +4,6 @@ import ycm_core
+ flags = [
+ '-Wall',
+ '-Wextra',
+-'-Werror',
+ '-x', 'c',
+ '-Iinclude',
+ ]
+diff --git a/CompilerChecks.cmake b/CompilerChecks.cmake
+index e39cc1d..9ee5462 100644
+--- a/CompilerChecks.cmake
++++ b/CompilerChecks.cmake
+@@ -7,14 +7,6 @@ if (UNIX)
+ #
+ # This will prevent that compiler flags are detected incorrectly.
+ #
+- check_c_compiler_flag("-Werror" REQUIRED_FLAGS_WERROR)
+- if (REQUIRED_FLAGS_WERROR)
+- set(CMAKE_REQUIRED_FLAGS "-Werror")
+-
+- if (PICKY_DEVELOPER)
+- list(APPEND SUPPORTED_COMPILER_FLAGS "-Werror")
+- endif()
+- endif()
+
+ add_c_compiler_flag("-std=gnu99" SUPPORTED_COMPILER_FLAGS)
+ add_c_compiler_flag("-Wpedantic" SUPPORTED_COMPILER_FLAGS)
+@@ -23,20 +15,12 @@ if (UNIX)
+ add_c_compiler_flag("-Wmissing-prototypes" SUPPORTED_COMPILER_FLAGS)
+ add_c_compiler_flag("-Wcast-align" SUPPORTED_COMPILER_FLAGS)
+ #add_c_compiler_flag("-Wcast-qual" SUPPORTED_COMPILER_FLAGS)
+- add_c_compiler_flag("-Werror=address" SUPPORTED_COMPILER_FLAGS)
+ add_c_compiler_flag("-Wstrict-prototypes" SUPPORTED_COMPILER_FLAGS)
+- add_c_compiler_flag("-Werror=strict-prototypes" SUPPORTED_COMPILER_FLAGS)
+ add_c_compiler_flag("-Wwrite-strings" SUPPORTED_COMPILER_FLAGS)
+- add_c_compiler_flag("-Werror=write-strings" SUPPORTED_COMPILER_FLAGS)
+- add_c_compiler_flag("-Werror-implicit-function-declaration" SUPPORTED_COMPILER_FLAGS)
+ add_c_compiler_flag("-Wpointer-arith" SUPPORTED_COMPILER_FLAGS)
+- add_c_compiler_flag("-Werror=pointer-arith" SUPPORTED_COMPILER_FLAGS)
+ add_c_compiler_flag("-Wreturn-type" SUPPORTED_COMPILER_FLAGS)
+- add_c_compiler_flag("-Werror=return-type" SUPPORTED_COMPILER_FLAGS)
+ add_c_compiler_flag("-Wuninitialized" SUPPORTED_COMPILER_FLAGS)
+- add_c_compiler_flag("-Werror=uninitialized" SUPPORTED_COMPILER_FLAGS)
+ add_c_compiler_flag("-Wimplicit-fallthrough" SUPPORTED_COMPILER_FLAGS)
+- add_c_compiler_flag("-Werror=strict-overflow" SUPPORTED_COMPILER_FLAGS)
+ add_c_compiler_flag("-Wstrict-overflow=2" SUPPORTED_COMPILER_FLAGS)
+ add_c_compiler_flag("-Wno-format-zero-length" SUPPORTED_COMPILER_FLAGS)
+ add_c_compiler_flag("-Wmissing-field-initializers" SUPPORTED_COMPILER_FLAGS)
+@@ -47,7 +31,6 @@ if (UNIX)
+ set(CMAKE_REQUIRED_FLAGS "${CMAKE_REQUIRED_FLAGS} -Wformat")
+ endif()
+ add_c_compiler_flag("-Wformat-security" SUPPORTED_COMPILER_FLAGS)
+- add_c_compiler_flag("-Werror=format-security" SUPPORTED_COMPILER_FLAGS)
+
+ # Allow zero for a variadic macro argument
+ string(TOLOWER "${CMAKE_C_COMPILER_ID}" _C_COMPILER_ID)
+--
+2.47.3
+
diff --git a/config/submodule/edk2/default/fsp/module.cfg b/config/submodule/edk2/default/fsp/module.cfg
new file mode 100644
index 00000000..fc238774
--- /dev/null
+++ b/config/submodule/edk2/default/fsp/module.cfg
@@ -0,0 +1,5 @@
+# SPDX-License-Identifier: GPL-3.0-or-later
+
+subgit="https://review.coreboot.org/fsp.git"
+subgit_bkup="https://github.com/coreboot/fsp"
+subhash="98426bfd958eb7397c474ff5d440dc9a1d146215"
diff --git a/config/submodule/edk2/default/intel-microcode/module.cfg b/config/submodule/edk2/default/intel-microcode/module.cfg
new file mode 100644
index 00000000..b5b452c4
--- /dev/null
+++ b/config/submodule/edk2/default/intel-microcode/module.cfg
@@ -0,0 +1,5 @@
+# SPDX-License-Identifier: GPL-3.0-or-later
+
+subgit="https://review.coreboot.org/intel-microcode.git"
+subgit_bkup="https://github.com/coreboot/intel-microcode"
+subhash="927e65c8d5a6e4ec05cc74b1778283ab2284d0c1"
diff --git a/config/submodule/edk2/default/libgfxinit/module.cfg b/config/submodule/edk2/default/libgfxinit/module.cfg
new file mode 100644
index 00000000..480ba0f1
--- /dev/null
+++ b/config/submodule/edk2/default/libgfxinit/module.cfg
@@ -0,0 +1,5 @@
+# SPDX-License-Identifier: GPL-3.0-or-later
+
+subgit="https://review.coreboot.org/libgfxinit.git"
+subgit_bkup="https://github.com/coreboot/libgfxinit"
+subhash="6e74c703132a8b4af4354a5158f286dc8f2407ab"
diff --git a/config/submodule/edk2/default/libgfxinit/patches/0001-g45-hw-gfx-gma-plls.adb-Make-reference-clock-frequen.patch b/config/submodule/edk2/default/libgfxinit/patches/0001-g45-hw-gfx-gma-plls.adb-Make-reference-clock-frequen.patch
new file mode 100644
index 00000000..71c34e5a
--- /dev/null
+++ b/config/submodule/edk2/default/libgfxinit/patches/0001-g45-hw-gfx-gma-plls.adb-Make-reference-clock-frequen.patch
@@ -0,0 +1,42 @@
+From 9be431356fce5b70875b938c3fbd6f6927031f23 Mon Sep 17 00:00:00 2001
+From: Nicholas Chin <nic.c3.14@gmail.com>
+Date: Mon, 20 May 2024 10:10:03 -0600
+Subject: [PATCH 1/2] g45/hw-gfx-gma-plls.adb: Make reference clock frequency
+ configurable
+
+Instead of assuming a 96 MHz reference clock frequency, use the value
+specified by the new INTEL_GMA_DPLL_REF_FREQ Kconfig. This defaults to
+96 MHz to preserve the existing behavior. An example of where this is
+needed is the DPLL_REF_SSCLK input, which will typically be 100 MHz
+to support LVDS spread spectrum clocking.
+
+Signed-off-by: Nicholas Chin <nic.c3.14@gmail.com>
+---
+ common/g45/hw-gfx-gma-plls.adb | 4 +++-
+ 1 file changed, 3 insertions(+), 1 deletion(-)
+
+diff --git a/common/g45/hw-gfx-gma-plls.adb b/common/g45/hw-gfx-gma-plls.adb
+index 2b93444..38d6dec 100644
+--- a/common/g45/hw-gfx-gma-plls.adb
++++ b/common/g45/hw-gfx-gma-plls.adb
+@@ -12,6 +12,8 @@
+ -- GNU General Public License for more details.
+ --
+
++with CB.Config;
++
+ with HW.Time;
+ with HW.GFX.GMA.Config;
+ with HW.GFX.GMA.Registers;
+@@ -490,7 +492,7 @@ is
+ Calculate_Clock_Parameters
+ (Target_Dotclock => Target_Clock,
+ -- should be, but doesn't has to be always the same:
+- Reference_Clock => 96_000_000,
++ Reference_Clock => CB.Config.INTEL_GMA_DPLL_REF_FREQ,
+ Limits => Select_Limits (Port_Cfg.Display, Target_Clock),
+ Best_Clock => Clk,
+ Valid => Success);
+--
+2.47.3
+
diff --git a/config/submodule/edk2/default/libgfxinit/patches/0002-re-try-EDID-reading-when-it-fails.patch b/config/submodule/edk2/default/libgfxinit/patches/0002-re-try-EDID-reading-when-it-fails.patch
new file mode 100644
index 00000000..2cc3c0b4
--- /dev/null
+++ b/config/submodule/edk2/default/libgfxinit/patches/0002-re-try-EDID-reading-when-it-fails.patch
@@ -0,0 +1,38 @@
+From 82f4346eba8fdfb0c11f19a4a0f26bd391c259b4 Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Sun, 13 Jul 2025 15:18:53 +0100
+Subject: [PATCH 2/2] re-try EDID reading when it fails
+
+some video converters are a bit buggy and have to be
+probed twice; linux works fine, but in these cases,
+coreboot won't set up the display.
+
+try it twice, to mitigate, when probing the EDID
+
+This entire function should probably be rewritten, since
+it's buggy in general.
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ common/hw-gfx-gma-display_probing.adb | 5 +++++
+ 1 file changed, 5 insertions(+)
+
+diff --git a/common/hw-gfx-gma-display_probing.adb b/common/hw-gfx-gma-display_probing.adb
+index 6908055..abaa2b6 100644
+--- a/common/hw-gfx-gma-display_probing.adb
++++ b/common/hw-gfx-gma-display_probing.adb
+@@ -140,6 +140,11 @@ is
+ Read_EDID (Raw_EDID, Port, Success);
+ end if;
+
++ if not Success then
++ Panel.Wait_On (Config_Helpers.To_Panel (Port));
++ Read_EDID (Raw_EDID, Port, Success);
++ end if;
++
+ if Success and then
+ ((not Is_DVI_I (Port) or EDID.Compatible_Display
+ (Raw_EDID, Config_Helpers.To_Display_Type (Port))) and
+--
+2.47.3
+
diff --git a/config/submodule/edk2/default/libhwbase/0001-remove-Werror.patch b/config/submodule/edk2/default/libhwbase/0001-remove-Werror.patch
new file mode 100644
index 00000000..8f0eba58
--- /dev/null
+++ b/config/submodule/edk2/default/libhwbase/0001-remove-Werror.patch
@@ -0,0 +1,26 @@
+From 5453dc70cdf327e5b4228fbce34b03107936628f Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Mon, 21 Sep 2026 10:58:18 +0100
+Subject: [PATCH 1/1] remove -Werror
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ Makefile | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/Makefile b/Makefile
+index e8d864e..9c10fb6 100644
+--- a/Makefile
++++ b/Makefile
+@@ -43,7 +43,7 @@ endif
+ CC = $(CROSS_COMPILE)gcc
+ GNATBIND = $(CROSS_COMPILE)gnatbind
+
+-CFLAGS += -Wuninitialized -Wall -Werror
++CFLAGS += -Wuninitialized -Wall
+ CFLAGS += -pipe -g
+ CFLAGS += -Wstrict-aliasing -Wshadow
+ CFLAGS += -fno-common -fomit-frame-pointer
+--
+2.47.3
+
diff --git a/config/submodule/edk2/default/libhwbase/module.cfg b/config/submodule/edk2/default/libhwbase/module.cfg
new file mode 100644
index 00000000..bb12f0f0
--- /dev/null
+++ b/config/submodule/edk2/default/libhwbase/module.cfg
@@ -0,0 +1,5 @@
+# SPDX-License-Identifier: GPL-3.0-or-later
+
+subgit="https://review.coreboot.org/libhwbase.git"
+subgit_bkup="https://github.com/coreboot/libhwbase"
+subhash="61f7287f18b249408a79bf9ab5e72568965cca2c"
diff --git a/config/submodule/edk2/default/module.list b/config/submodule/edk2/default/module.list
new file mode 100644
index 00000000..c5a2f880
--- /dev/null
+++ b/config/submodule/edk2/default/module.list
@@ -0,0 +1,7 @@
+3rdparty/arm-trusted-firmware
+3rdparty/fsp
+3rdparty/intel-microcode
+3rdparty/libgfxinit
+3rdparty/libhwbase
+3rdparty/vboot
+3rdparty/cmocka
diff --git a/config/submodule/edk2/default/vboot/module.cfg b/config/submodule/edk2/default/vboot/module.cfg
new file mode 100644
index 00000000..c47b5778
--- /dev/null
+++ b/config/submodule/edk2/default/vboot/module.cfg
@@ -0,0 +1,5 @@
+# SPDX-License-Identifier: GPL-3.0-or-later
+
+subgit="https://review.coreboot.org/vboot.git"
+subgit_bkup="https://github.com/coreboot/vboot"
+subhash="5c360ef458b0a013d8a6d47724bb0fffb5accbcf"
diff --git a/config/submodule/edk2/default/vboot/patches/0001-extract_vmlinuz.c-Fix-the-bounds-check-on-vmlinuz_he.patch b/config/submodule/edk2/default/vboot/patches/0001-extract_vmlinuz.c-Fix-the-bounds-check-on-vmlinuz_he.patch
new file mode 100644
index 00000000..1ac41de6
--- /dev/null
+++ b/config/submodule/edk2/default/vboot/patches/0001-extract_vmlinuz.c-Fix-the-bounds-check-on-vmlinuz_he.patch
@@ -0,0 +1,178 @@
+From 195f61375aeec9eec16604ec59f6eda2e6058cc1 Mon Sep 17 00:00:00 2001
+From: "Luke T. Shumaker" <lukeshu@lukeshu.com>
+Date: Thu, 30 May 2024 14:08:33 -0600
+Subject: [PATCH 1/1] extract_vmlinuz.c: Fix the bounds check on
+ vmlinuz_header_{offset,size}
+
+The check on vmlinuz_header_offset and vmlinuz_header_size is obviously
+wrong:
+
+ if (!vmlinuz_header_size ||
+ kpart_data + vmlinuz_header_offset + vmlinuz_header_size >
+ kpart_data) {
+ return 1;
+ }
+
+`kpart_data + some_unsigned_values` can obviously never be `> kpart_data`,
+unless something has overflowed! And `vmlinuz_header_offset` hasn't even
+been set yet (besides being initialized to zero)!
+
+GCC will deduce that if the check didn't cause the function to bail, then
+vmlinuz_header_size (a uint32_t) must be "negative"; that is: in the range
+[2GiB,4GiB).
+
+On platforms where size_t is 32-bits, this is *especially* broken.
+memcpy's size argument must be in the range [0,2GiB). Because GCC has
+proved that vmlinuz_header_size is higher than that, it will fail to
+compile:
+
+ host/lib/extract_vmlinuz.c:67:9: error: 'memcpy' specified bound between 2147483648 and 4294967295 exceeds maximum object size 2147483647 [-Werror=stringop-overflow=]
+
+So, fix the check.
+
+I can now say that what I suspect the original author meant to write would
+be the following patch, if `vmlinuz_header_offset` were already set:
+
+ -kpart_data + vmlinuz_header_offset + vmlinuz_header_size > kpart_data
+ +now + vmlinuz_header_offset + vmlinuz_header_size > kpart_size
+
+This hypothesis is supported by `now` not getting incremented by
+`kblob_size` the way it is for the keyblock and preamble sizes.
+
+However, we can also see that even this "corrected" bounds check is
+insufficient: it does not detect the vmlinuz_header overflowing into
+kblob_data.
+
+OK, so let's describe the fix:
+
+Have a `*vmlinuz_header` pointer instead of a
+`uint64_t vmlinuz_header_offset`, to be more similar to all the other
+regions. With this change, the correct check becomes a simple
+
+ vmlinuz_header + vmlinuz_header_size > kblob_data
+
+While we're at it, make some changes that could have helped avoid this in
+the first place:
+
+ - Add comments.
+ - Calculate the vmlinuz_header offset right away, instead of waiting.
+ - Go ahead and increment `now` by `kblob_size`, to increase regularity.
+
+Change-Id: I5c03e49070b6dd2e04459566ef7dd129d27736e4
+---
+ host/lib/extract_vmlinuz.c | 72 +++++++++++++++++++++++++++-----------
+ 1 file changed, 51 insertions(+), 21 deletions(-)
+
+diff --git a/host/lib/extract_vmlinuz.c b/host/lib/extract_vmlinuz.c
+index 4ccfcf33..d2c09443 100644
+--- a/host/lib/extract_vmlinuz.c
++++ b/host/lib/extract_vmlinuz.c
+@@ -15,16 +15,44 @@
+
+ int ExtractVmlinuz(void *kpart_data, size_t kpart_size,
+ void **vmlinuz_out, size_t *vmlinuz_size) {
++ // We're going to be extracting `vmlinuz_header` and
++ // `kblob_data`, and returning the concatenation of them.
++ //
++ // kpart_data = +-[kpart_size]------------------------------------+
++ // | |
++ // keyblock = | +-[keyblock->keyblock_size]-------------------+ |
++ // | | struct vb2_keyblock keyblock | |
++ // | | char [] ...data... | |
++ // | +---------------------------------------------+ |
++ // | |
++ // preamble = | +-[preamble->preamble_size]-------------------+ |
++ // | | struct vb2_kernel_preamble preamble | |
++ // | | char [] ...data... | |
++ // | | char [] vmlinuz_header | |
++ // | | char [] ...data... | |
++ // | +---------------------------------------------+ |
++ // | |
++ // kblob_data= | +-[preamble->body_signature.data_size]--------+ |
++ // | | char [] ...data... | |
++ // | +---------------------------------------------+ |
++ // | |
++ // +-------------------------------------------------+
++
+ size_t now = 0;
++ // The 3 sections of kpart_data.
++ struct vb2_keyblock *keyblock = NULL;
+ struct vb2_kernel_preamble *preamble = NULL;
+ uint8_t *kblob_data = NULL;
+ uint32_t kblob_size = 0;
++ // vmlinuz_header
++ uint8_t *vmlinuz_header = NULL;
+ uint32_t vmlinuz_header_size = 0;
+- uint64_t vmlinuz_header_address = 0;
+- uint64_t vmlinuz_header_offset = 0;
++ // The concatenated result.
+ void *vmlinuz = NULL;
+
+- struct vb2_keyblock *keyblock = (struct vb2_keyblock *)kpart_data;
++ // Isolate the 3 sections of kpart_data.
++
++ keyblock = (struct vb2_keyblock *)kpart_data;
+ now += keyblock->keyblock_size;
+ if (now > kpart_size)
+ return 1;
+@@ -36,37 +64,39 @@ int ExtractVmlinuz(void *kpart_data, size_t kpart_size,
+
+ kblob_data = kpart_data + now;
+ kblob_size = preamble->body_signature.data_size;
+-
+- if (!kblob_data || (now + kblob_size) > kpart_size)
++ now += kblob_size;
++ if (now > kpart_size)
+ return 1;
+
++ // Find `vmlinuz_header` within `preamble`.
++
+ if (preamble->header_version_minor > 0) {
+- vmlinuz_header_address = preamble->vmlinuz_header_address;
++ // calculate the vmlinuz_header offset from
++ // the beginning of the kpart_data. The kblob doesn't
++ // include the body_load_offset, but does include
++ // the keyblock and preamble sections.
++ size_t vmlinuz_header_offset =
++ preamble->vmlinuz_header_address -
++ preamble->body_load_address +
++ keyblock->keyblock_size +
++ preamble->preamble_size;
++
++ vmlinuz_header = kpart_data + vmlinuz_header_offset;
+ vmlinuz_header_size = preamble->vmlinuz_header_size;
+ }
+
+- if (!vmlinuz_header_size ||
+- kpart_data + vmlinuz_header_offset + vmlinuz_header_size >
+- kpart_data) {
++ if (!vmlinuz_header ||
++ !vmlinuz_header_size ||
++ vmlinuz_header + vmlinuz_header_size > kblob_data) {
+ return 1;
+ }
+
+- // calculate the vmlinuz_header offset from
+- // the beginning of the kpart_data. The kblob doesn't
+- // include the body_load_offset, but does include
+- // the keyblock and preamble sections.
+- vmlinuz_header_offset = vmlinuz_header_address -
+- preamble->body_load_address +
+- keyblock->keyblock_size +
+- preamble->preamble_size;
++ // Concatenate and return.
+
+ vmlinuz = malloc(vmlinuz_header_size + kblob_size);
+ if (vmlinuz == NULL)
+ return 1;
+-
+- memcpy(vmlinuz, kpart_data + vmlinuz_header_offset,
+- vmlinuz_header_size);
+-
++ memcpy(vmlinuz, vmlinuz_header, vmlinuz_header_size);
+ memcpy(vmlinuz + vmlinuz_header_size, kblob_data, kblob_size);
+
+ *vmlinuz_out = vmlinuz;
+--
+2.45.1
+
diff --git a/config/submodule/edk2/default/vboot/patches/0002-lib-cbfstool-fix-build-error-on-newer-hostcc.patch b/config/submodule/edk2/default/vboot/patches/0002-lib-cbfstool-fix-build-error-on-newer-hostcc.patch
new file mode 100644
index 00000000..6d5ba873
--- /dev/null
+++ b/config/submodule/edk2/default/vboot/patches/0002-lib-cbfstool-fix-build-error-on-newer-hostcc.patch
@@ -0,0 +1,28 @@
+From efeac4de14e3ac46e9146bc6a2d2e03ca04757f1 Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Wed, 1 Apr 2026 08:10:09 +0100
+Subject: [PATCH] lib/cbfstool: fix build error on newer hostcc
+
+const char being discarded. classic rookie mistake.
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ host/lib/cbfstool.c | 2 +-
+ 1 file changed, 1 insertion(+), 1 deletion(-)
+
+diff --git a/host/lib/cbfstool.c b/host/lib/cbfstool.c
+index 9b4de49e..2a2578c0 100644
+--- a/host/lib/cbfstool.c
++++ b/host/lib/cbfstool.c
+@@ -259,7 +259,7 @@ static char *extract_config_value(const char *buf, const char *config_field)
+ free(to_find);
+
+ if (start) {
+- char *end = strchr(start, '\n');
++ const char *end = strchr(start, '\n');
+ if (end)
+ return strndup(start, end - start);
+ }
+--
+2.47.3
+
diff --git a/config/submodule/edk2/default/vboot/patches/0003-remove-Werror.patch b/config/submodule/edk2/default/vboot/patches/0003-remove-Werror.patch
new file mode 100644
index 00000000..fbc60940
--- /dev/null
+++ b/config/submodule/edk2/default/vboot/patches/0003-remove-Werror.patch
@@ -0,0 +1,58 @@
+From f71d1e0981fa3a9ea8201cac97631486a90d5ce4 Mon Sep 17 00:00:00 2001
+From: Leah Rowe <leah@libreboot.org>
+Date: Mon, 21 Sep 2026 11:01:00 +0100
+Subject: [PATCH 1/1] remove -Werror
+
+Signed-off-by: Leah Rowe <leah@libreboot.org>
+---
+ Android.bp | 1 -
+ Makefile | 6 ++----
+ 2 files changed, 2 insertions(+), 5 deletions(-)
+
+diff --git a/Android.bp b/Android.bp
+index dec72cc8..1974a1a2 100644
+--- a/Android.bp
++++ b/Android.bp
+@@ -9,7 +9,6 @@ cc_defaults {
+
+ cflags: [
+ "-Wall",
+- "-Werror",
+ "-Wstrict-prototypes",
+ "-Wtype-limits",
+ "-Wundef",
+diff --git a/Makefile b/Makefile
+index 67af60d4..4243a03a 100644
+--- a/Makefile
++++ b/Makefile
+@@ -113,9 +113,8 @@ endif
+ # Provide default CC and CFLAGS for firmware builds; if you have any -D flags,
+ # please add them after this point (e.g., -DVBOOT_DEBUG).
+ DEBUG_FLAGS := $(if $(filter-out 0,${DEBUG}),-g -Og,-g -Os)
+-WERROR := -Werror
+ FIRMWARE_FLAGS := -nostdinc -ffreestanding -fno-builtin -fno-stack-protector
+-COMMON_FLAGS := -pipe ${WERROR} -Wall -Wstrict-prototypes -Wtype-limits \
++COMMON_FLAGS := -pipe -Wall -Wstrict-prototypes -Wtype-limits \
+ -Wundef -Wmissing-prototypes -Wno-trigraphs -Wredundant-decls -Wshadow \
+ -Wwrite-strings -Wstrict-aliasing -Wdate-time \
+ -Wint-conversion -ffunction-sections -fdata-sections \
+@@ -127,7 +126,7 @@ COMMON_FLAGS := -pipe ${WERROR} -Wall -Wstrict-prototypes -Wtype-limits \
+ # returns: $(1) if compiler was successful, empty string otherwise
+ test_ccflag = $(shell \
+ printf "$(2)\nvoid _start(void) {}\n" | \
+- $(CC) -nostdlib -Werror $(1) -xc -c - -o /dev/null \
++ $(CC) -nostdlib $(1) -xc -c - -o /dev/null \
+ >/dev/null 2>&1 && echo "$(1)")
+
+ COMMON_FLAGS += $(call test_ccflag,-Wimplicit-fallthrough)
+@@ -499,7 +498,6 @@ UTILLIB = ${BUILD}/libvboot_util.a
+ # Avoid build failures outside the chroot on Ubuntu 2022.04
+ # e.g.:
+ # host/lib/host_key2.c:103:17: error: ‘RSA_free’ is deprecated: Since OpenSSL 3.0
+-# [-Werror=deprecated-declarations]
+ ifeq ($(OPENSSL_VERSION),3)
+ ${UTILLIB}: CFLAGS += -Wno-error=deprecated-declarations
+ endif
+--
+2.47.3
+