diff options
Diffstat (limited to 'resources/scripts')
| -rwxr-xr-x | resources/scripts/build/boot/roms | 4 | ||||
| -rwxr-xr-x | resources/scripts/build/boot/roms_helper | 31 | ||||
| -rwxr-xr-x | resources/scripts/build/clean/bios_extract | 28 | ||||
| -rw-r--r-- | resources/scripts/build/dependencies/arch | 2 | ||||
| -rwxr-xr-x | resources/scripts/build/dependencies/debian | 2 | ||||
| -rwxr-xr-x | resources/scripts/build/dependencies/fedora38 | 2 | ||||
| -rwxr-xr-x | resources/scripts/build/dependencies/parabola | 2 | ||||
| -rwxr-xr-x | resources/scripts/build/dependencies/ubuntu2004 | 2 | ||||
| -rwxr-xr-x | resources/scripts/build/dependencies/void | 2 | ||||
| -rwxr-xr-x | resources/scripts/build/module/bios_extract | 33 | ||||
| -rwxr-xr-x | resources/scripts/build/release/roms | 84 | ||||
| -rwxr-xr-x | resources/scripts/build/release/src | 27 | ||||
| -rwxr-xr-x | resources/scripts/update/blobs/download | 469 | ||||
| -rwxr-xr-x | resources/scripts/update/blobs/extract | 150 | ||||
| -rwxr-xr-x | resources/scripts/update/blobs/inject | 389 | ||||
| -rwxr-xr-x | resources/scripts/update/module/bios_extract | 22 | ||||
| -rwxr-xr-x | resources/scripts/update/module/me_cleaner | 25 | ||||
| -rwxr-xr-x | resources/scripts/update/module/mrc | 186 | 
18 files changed, 9 insertions, 1451 deletions
| diff --git a/resources/scripts/build/boot/roms b/resources/scripts/build/boot/roms index 16ce698a..70054fd4 100755 --- a/resources/scripts/build/boot/roms +++ b/resources/scripts/build/boot/roms @@ -129,10 +129,6 @@ listboards()  buildrom() {  	board="$1" -	# Start by building blobs and placing them in the -	# coreboot tree only for boards that need them -	./blobutil download ${board} || exit 1 -  	if [ -d "resources/coreboot/${board}/" ]; then  		./build boot roms_helper ${board}${opts}  	else diff --git a/resources/scripts/build/boot/roms_helper b/resources/scripts/build/boot/roms_helper index 97178593..5ac65c61 100755 --- a/resources/scripts/build/boot/roms_helper +++ b/resources/scripts/build/boot/roms_helper @@ -31,9 +31,6 @@ set -u -e  projectname="$(cat projectname)" -blobs_required="" -microcode_required="" -  kmapdir="resources/grub/keymap"  displaymodes=""  payloads="" @@ -161,15 +158,6 @@ if [ "${payload_uboot}" = "y" ] && \  	uboot_config="default"  fi -if [ "${microcode_required}" != "n" ] \ -		&& [ "${microcode_required}" != "y" ]; then -	microcode_required="y" -fi -if [ "${blobs_required}" != "n" ] \ -		&& [ "${blobs_required}" != "y" ]; then -	blobs_required="y" -fi -  # Override all payload directives with cmdline args  if [ ! -z ${payloads} ]; then	  	echo "setting payloads $payloads" @@ -320,10 +308,6 @@ moverom() {  	newrompath="$2"  	cuttype="$3" -	if [ "${blobs_required}" = "n" ]; then -		newrompath="${newrompath%.rom}_noblobs.rom" -	fi -  	printf "\nCreating new ROM image: %s\n" "${newrompath}"  	if [ "${cuttype}" = "4MiB IFD BIOS region" ]; then @@ -363,21 +347,6 @@ moverom() {  			count=64k conv=notrunc  		rm -f top64k.bin  	fi - -	if [ "${microcode_required}" = "n" ]; then -		_newrom_b="${newrompath%.rom}_nomicrocode.rom" -		cp "${newrompath}" "${_newrom_b}" || exit 1 -		microcode_present="y" -		"${cbfstool}" "${_newrom_b}" remove -n \ -				cpu_microcode_blob.bin || microcode_present="n" -		if [ "${microcode_present}" = "n" ]; then -			rm -f "${_newrom_b}" || exit 1 -			printf "REMARK: '%s' already lacks microcode\n" \ -					${newrompath} -			printf "Renaming default ROM file instead.\n" -			mv "${newrompath}" "${_newrom_b}" || exit 1 -		fi -	fi  }  # expected: configs must not specify a payload diff --git a/resources/scripts/build/clean/bios_extract b/resources/scripts/build/clean/bios_extract deleted file mode 100755 index 65493f78..00000000 --- a/resources/scripts/build/clean/bios_extract +++ /dev/null @@ -1,28 +0,0 @@ -#!/usr/bin/env sh - -#  helper script: run make clean on bios_extract -# -#	Copyright (C) 2023 Leah Rowe <info@minifree.org> -# -#    This program is free software: you can redistribute it and/or modify -#    it under the terms of the GNU General Public License as published by -#    the Free Software Foundation, either version 3 of the License, or -#    (at your option) any later version. -# -#    This program is distributed in the hope that it will be useful, -#    but WITHOUT ANY WARRANTY; without even the implied warranty of -#    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the -#    GNU General Public License for more details. -# -#    You should have received a copy of the GNU General Public License -#    along with this program.  If not, see <http://www.gnu.org/licenses/>. -# - -[ "x${DEBUG+set}" = 'xset' ] && set -v -set -u -e - -printf "Cleaning the previous build of bios_extract\n" - -[ ! -d "bios_extract/" ] && exit 0 - -make clean -BC bios_extract || exit 1 diff --git a/resources/scripts/build/dependencies/arch b/resources/scripts/build/dependencies/arch index c20a1faf..57abb022 100644 --- a/resources/scripts/build/dependencies/arch +++ b/resources/scripts/build/dependencies/arch @@ -49,7 +49,7 @@ pacman -S --needed --noconfirm nasm perl-libwww python subversion  pacman -S --needed --noconfirm base-devel -# for running the crostool script (to get mrc.bin file for t440p) +# for running the crostool script  pacman -S --needed --noconfirm sharutils curl parted e2fsprogs unzip  # for cross-compiling ARM binaries diff --git a/resources/scripts/build/dependencies/debian b/resources/scripts/build/dependencies/debian index fb0ae248..28d83116 100755 --- a/resources/scripts/build/dependencies/debian +++ b/resources/scripts/build/dependencies/debian @@ -48,7 +48,7 @@ apt-get -y install uuid-dev nasm  apt-get -y install build-essential -# for running the crostool script (to get mrc.bin file for t440p) +# for running the crostool script  apt-get -y install sharutils curl parted e2fsprogs unzip  # to use the right software versions and links for compiling  diff --git a/resources/scripts/build/dependencies/fedora38 b/resources/scripts/build/dependencies/fedora38 index 2389b806..64c1a407 100755 --- a/resources/scripts/build/dependencies/fedora38 +++ b/resources/scripts/build/dependencies/fedora38 @@ -53,7 +53,7 @@ dnf -y install nasm perl-libwww-perl python3 subversion  dnf -y install gcc -# for running the crostool script (to get mrc.bin file for t440p) +# for running the crostool script  dnf -y install sharutils curl parted e2fsprogs unzip  # for cross-compiling ARM binaries diff --git a/resources/scripts/build/dependencies/parabola b/resources/scripts/build/dependencies/parabola index da284bed..b5562abf 100755 --- a/resources/scripts/build/dependencies/parabola +++ b/resources/scripts/build/dependencies/parabola @@ -51,7 +51,7 @@ pacman -S --needed --noconfirm nasm perl-libwww python subversion  pacman -S --needed --noconfirm base-devel -# for running the crostool script (to get mrc.bin file for t440p) +# for running the crostool script  pacman -S --needed --noconfirm sharutils curl parted e2fsprogs unzip  # for cross-compiling ARM binaries diff --git a/resources/scripts/build/dependencies/ubuntu2004 b/resources/scripts/build/dependencies/ubuntu2004 index 14a1d8c2..e7a04678 100755 --- a/resources/scripts/build/dependencies/ubuntu2004 +++ b/resources/scripts/build/dependencies/ubuntu2004 @@ -46,7 +46,7 @@ apt-get -y install uuid-dev nasm  apt-get -y install build-essential -# for running the crostool script (to get mrc.bin file for t440p) +# for running the crostool script  apt-get -y install sharutils curl parted e2fsprogs unzip  # to use the right software versions and links for compiling  diff --git a/resources/scripts/build/dependencies/void b/resources/scripts/build/dependencies/void index e46cd5ee..a13a1adc 100755 --- a/resources/scripts/build/dependencies/void +++ b/resources/scripts/build/dependencies/void @@ -46,7 +46,7 @@ xbps-install -y nasm perl-LWP python subversion  xbps-install -y base-devel -# for running the crostool script (to get mrc.bin file for t440p) +# for running the crostool script  xbps-install -y sharutils curl parted e2fsprogs unzip  # for cross-compiling ARM binaries diff --git a/resources/scripts/build/module/bios_extract b/resources/scripts/build/module/bios_extract deleted file mode 100755 index 77677fa1..00000000 --- a/resources/scripts/build/module/bios_extract +++ /dev/null @@ -1,33 +0,0 @@ -#!/usr/bin/env sh - -#  helper script: builds bios_extract source code -# -#	Copyright (C) 2023 Leah Rowe <info@minifree.org> -# -#    This program is free software: you can redistribute it and/or modify -#    it under the terms of the GNU General Public License as published by -#    the Free Software Foundation, either version 3 of the License, or -#    (at your option) any later version. -# -#    This program is distributed in the hope that it will be useful, -#    but WITHOUT ANY WARRANTY; without even the implied warranty of -#    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the -#    GNU General Public License for more details. -# -#    You should have received a copy of the GNU General Public License -#    along with this program.  If not, see <http://www.gnu.org/licenses/>. -# - -[ "x${DEBUG+set}" = 'xset' ] && set -v -set -u -e - -# Build "flashrom" (utility for flashing/dumping ROMs) -# -------------------------------------------------------------------- - -if [ ! -d "bios_extract/" ]; then -    ./download bios_extract -fi - -printf "Building bios_extract\n" - -make -BC bios_extract diff --git a/resources/scripts/build/release/roms b/resources/scripts/build/release/roms index d81ec09a..62fe91bc 100755 --- a/resources/scripts/build/release/roms +++ b/resources/scripts/build/release/roms @@ -26,9 +26,6 @@ version="version-unknown"  versiondate="version-date-unknown"  cbtree="default"  target="" -CONFIG_HAVE_MRC="" -CONFIG_HAVE_ME_BIN="" -CONFIG_KBC1126_FIRMWARE=""  ifdtool="cbutils/${cbtree}/ifdtool"  cbfstool="cbutils/${cbtree}/cbfstool" @@ -73,25 +70,6 @@ make_archive()  		continue  	fi -	CONFIG_HAVE_MRC="y" -	CONFIG_HAVE_ME_BIN="y" -	CONFIG_KBC1126_FIRMWARE="y" -	grep "CONFIG_HAVE_ME_BIN=y" \ -			"resources/coreboot/${target}/config/"* \ -			|| CONFIG_HAVE_ME_BIN="n" -	grep "CONFIG_HAVE_MRC=y" \ -			"resources/coreboot/${target}/config/"* \ -			|| CONFIG_HAVE_MRC="n" -	grep "CONFIG_KBC1126_FIRMWARE=y" \ -			"resources/coreboot/${target}/config"/* \ -			|| CONFIG_KBC1126_FIRMWARE="n" - -	# remove ME/MRC/EC firmware from ROM images -	if [ "${CONFIG_HAVE_ME_BIN}" = "y" ] \ -			|| [ "${target}" = "e6400nvidia_4mb" ]; then -		strip_archive "${romdir}" -	fi -  	printf "Generating release/%s/roms/%s-%s_%s.tar.xz\n" \  			"${version}" "${projectname}" \  			"${version}" "${target##*/}" @@ -109,68 +87,6 @@ make_archive()  	fi  } -strip_archive() -{ -	romdir=${1} - -	if [ ! -d coreboot/${cbtree} ]; then -		./download coreboot ${cbtree} || exit 1 -	fi -	./build module cbutils ${cbtree} || exit 1 - -	rm -Rf "${romdir}_tmp" # dirty hack, to reduce disk io later -	# rather than using /tmp, which might not be tmpfs -	mkdir "${romdir}_tmp" - -	# Hash the rom before removing blobs -	if [ ! -f "${romdir}/blobhashes" ]; then -		printf "ROMs must match these hashes after blob insertion:" \ -			> "${romdir}/blobhashes" -	fi -	( -	cd ${romdir} || err "subshell: cd" -	sha1sum *.rom >> blobhashes || err "subshell: sha1sum" -	) - -	for romfile in "${romdir}"/*.rom -	do -		strip_rom_image "${romfile}" -	done -} - -strip_rom_image() -{ -	romfile=${1} - -	if [ ! -f "${romfile}" ]; then -		continue -	fi - -	if [ "${CONFIG_HAVE_ME_BIN}" = "y" ]; then -		${ifdtool} --nuke me "${romfile}" || exit 1 -		mv "${romfile}" "${romdir}_tmp"/ -		mv "${romfile}.new" "${romfile}" -	fi - -	if [ "${CONFIG_HAVE_MRC}" = "y" ] -	then -		${cbfstool} "${romfile}" remove -n mrc.bin || exit 1 -		${cbfstool} "${romfile}" print -	fi - -	if [ "${CONFIG_KBC1126_FIRMWARE}" = "y" ]; then -		${cbfstool} "${romfile}" remove -n ecfw1.bin || exit 1 -		${cbfstool} "${romfile}" remove -n ecfw2.bin || exit 1 -	fi - -	# TODO: replace this board-specific hack -	if [ "${target}" = "e6400nvidia_4mb" ]; then -		${cbfstool} "${romfile}" remove \ -			-n "pci10de,06eb.rom" \ -			|| exit 1 -	fi -} -  err()  {  	printf "%s: %s\n" $0 $1 diff --git a/resources/scripts/build/release/src b/resources/scripts/build/release/src index 7a2f94d7..267b3eea 100755 --- a/resources/scripts/build/release/src +++ b/resources/scripts/build/release/src @@ -23,12 +23,11 @@ set -u -e  projectname="$(cat projectname)" -modlist="coreboot flashrom grub memtest86plus seabios me_cleaner u-boot" -modlist="${modlist} bios_extract" +modlist="coreboot flashrom grub memtest86plus seabios u-boot" -dirlist="resources util" # do not add blobs directory here. it's handled below +dirlist="resources util" -filelist="lbmk blobutil modify download build README.md COPYING Makefile update" +filelist="lbmk modify download build README.md COPYING Makefile update"  filelist="${filelist} version versiondate projectname .gitcheck gitclone"  version="version-unknown" @@ -88,8 +87,6 @@ copy_files()  		cp -R "${dir}/" "${srcdir}/"  	done -	copy_blobs -  	for i in ${filelist}; do  		if [ ! -f "${i}" ]; then  			rm -Rf "${srcdir}" @@ -99,23 +96,6 @@ copy_files()  	done  } -copy_blobs() -{ -	mkdir -p "${srcdir}"/blobs -	# do not copy intel ME etc, but do copy ifd/gbe files -	for i in t440p xx20 xx30 hp8200sff hp_ivybridge hp_sandybridge \ -			hp8300usdt; do -		for j in ifd gbe 16_ifd; do -			if [ -f "blobs/${i}/${j}.bin" ]; then -				if [ ! -e "${srcdir}/blobs/${i}" ]; then -					mkdir -p "${srcdir}/blobs/${i}" -				fi -				cp blobs/${i}/${j}.bin "${srcdir}/blobs/${i}" -			fi -		done -	done -} -  purge_files()  {  	( @@ -127,7 +107,6 @@ purge_files()  		cd "${i}/" || err "cd2"  		make distclean || err "make-distclean1"  		) -		make clean -BC default/util/kbc1126/ || err "make-clean1"  	done  	) diff --git a/resources/scripts/update/blobs/download b/resources/scripts/update/blobs/download deleted file mode 100755 index 0896ed47..00000000 --- a/resources/scripts/update/blobs/download +++ /dev/null @@ -1,469 +0,0 @@ -#!/usr/bin/env sh - -# SPDX-FileCopyrightText: 2022 Caleb La Grange <thonkpeasant@protonmail.com> -# SPDX-FileCopyrightText: 2022 Ferass El Hafidi <vitali64pmemail@protonmail.com> -# SPDX-FileCopyrightText: 2023 Leah Rowe <info@minifree.org> -# SPDX-License-Identifier: GPL-3.0-only - -ec_url="" -ec_url_bkup="" -ec_hash="" -dl_hash="" -dl_url="" -dl_url_bkup="" -dl_path="" -e6400_vga_dl_hash="" -e6400_vga_dl_url="" -e6400_vga_dl_url_bkup="" -e6400_vga_offset="" -e6400_vga_romname="" - -cbdir="coreboot/default" -cbcfgsdir="resources/coreboot" -boarddir="" -blobdir="blobs" -appdir="${blobdir}/app" -_7ztest="a" -mecleaner="$(pwd)/me_cleaner/me_cleaner.py" -e6400_unpack="$(pwd)/bios_extract/dell_inspiron_1100_unpacker.py" -me7updateparser="$(pwd)/resources/blobs/me7_update_parser.py" -kbc1126_ec_dump="$(pwd)/${cbdir}/util/kbc1126/kbc1126_ec_dump" -board="" -_b="" # board shorthand without e.g. _4mb (avoid duplication per flash size) - -CONFIG_HAVE_MRC="" -CONFIG_HAVE_IFD_BIN="" -CONFIG_HAVE_ME_BIN="" -CONFIG_HAVE_GBE_BIN="" -CONFIG_KBC1126_FIRMWARE="" -CONFIG_BOARD_DELL_E6400="" -CONFIG_VGA_BIOS_FILE="" - -main() -{ -	board="${1}" -	boarddir="${cbcfgsdir}/${board}" - -	exit_if_no_config="exit 0" -	for x in "${boarddir}"/config/*; do -		if [ -f "${x}" ]; then -			exit_if_no_config="" -		fi -	done -	eval "${exit_if_no_config}" - -	if [ ! -d "${boarddir}" ]; then -		fail "Target not defined" -	elif [ ! -f "${boarddir}/board.cfg" ]; then -		fail "Target missing board.cfg" -	fi -	 -	detect_firmware || exit 0 -	scan_sources_config - -	build_dependencies -	download_blobs -} - -detect_firmware() -{ -	set -- "${boarddir}/config/"* -	. ${1} 2>/dev/null -	. "${boarddir}/board.cfg" - -	if [ "${CONFIG_HAVE_MRC}" = "y" ]; then -		needs="${needs} MRC" -	fi -	if [ "${CONFIG_HAVE_IFD_BIN}" = "y" ]; then -		needs="${needs} IFD" -	fi -	if [ "${CONFIG_HAVE_ME_BIN}" = "y" ]; then -		needs="${needs} ME" -	fi -	if [ "${CONFIG_HAVE_GBE_BIN}" = "y" ]; then -		needs="${needs} GBE" -	fi -	if [ "${CONFIG_KBC1126_FIRMWARE}" = "y" ]; then -		needs="${needs} EC" -	fi -	if [ "${CONFIG_BOARD_DELL_E6400}" = "y" ] \ -			&& [ "${CONFIG_VGA_BIOS_FILE}" != "" ]; then -		needs="${needs} E6400VGA" -	fi -	if [ -z ${needs+x} ]; then -		printf 'No binary blobs needed for this board\n' -		return 1 -	fi -	printf "Firmware needed for board %s: %s\n" ${board} ${needs} -} - -scan_sources_config() -{ -	# Shorthand (avoid duplicating configs per flash size) -	_b=${board%%_*mb} - -	awkstr=" /\{.*${_b}.*}{/ {flag=1;next} /\}/{flag=0} flag { print }" - -	while read -r line ; do -		case ${line} in -		EC_url*) -			set ${line} -			ec_url=${2} -			;; -		EC_url_bkup*) -			set ${line} -			ec_url_bkup=${2} -			;; -		EC_hash*) -			set ${line} -			ec_hash=${2} -			;; -		DL_hash*) -			set ${line} -			dl_hash=${2} -			;; -		DL_url*) -			set ${line} -			dl_url=${2} -			;; -		DL_url_bkup*) -			set ${line} -			dl_url_bkup=${2} -			;; -		E6400_VGA_DL_hash*) -			set ${line} -			e6400_vga_dl_hash=${2} -			;; -		E6400_VGA_DL_url*) -			set ${line} -			e6400_vga_dl_url=${2} -			;; -		E6400_VGA_DL_url_bkup*) -			set ${line} -			e6400_vga_dl_url_bkup=${2} -			;; -		E6400_VGA_offset*) -			set ${line} -			e6400_vga_offset=${2} -			;; -		E6400_VGA_romname*) -			set ${line} -			e6400_vga_romname=${2} -			;; -		esac -	done << EOF -	$(eval "awk '${awkstr}' resources/blobs/sources") -EOF -} - -build_dependencies() -{ -	if [ ! -d me_cleaner ]; then -		printf "downloading me_cleaner\n" -		./download me_cleaner || fail "could not download me_cleaner" -	fi -	if [ ! -d ${cbdir} ]; then -		printf "downloading coreboot\n" -		./download coreboot default \ -				|| fail "could not download coreboot" -	fi -	if [ ! -d bios_extract ]; then -		printf "downloading bios_extract\n" -		./download bios_extract \ -				|| fail "could not download bios_extract" -	fi -	if [ ! -f ${cbdir}/util/kbc1126/kbc1126_ec_dump ]; then -		printf "Building kbc1126_ec_dump from coreboot\n" -		make -BC ${cbdir}/util/kbc1126 \ -				|| fail "could not build kbc1126_ec_dump" -	fi -	if [ ! -f "${cbdir}/util/ifdtool/ifdtool" ]; then -		printf "building ifdtool from coreboot\n" -		make -C ${cbdir}/util/ifdtool \ -				|| fail 'could not build ifdtool' -	fi -} - -download_blobs() -{ -	for need in ${needs}; do -		case ${need} in -		*ME*) -			download_blob_intel_me || _failed="${_failed} me" -			;; -		*EC*) -			download_ec || _failed="${_failed} ec" -			;; -		*E6400VGA*) -			download_e6400vga || _failed="${_failed} e6400vga" -			;; -		*MRC*) -			./download mrc || _failed="${_failed} mrc" -			;; -		esac -	done -	 -	if [ ! -z ${_failed+x} ]; then -		fail "failed to obtain ${_failed}\nTry manual extraction?" -	fi -} - -download_blob_intel_me() -{ -	printf "Downloading neutered ME for board: %s\n" ${board} - -	fetch_update me || return 1 -	extract_blob_intel_me || return 1 -} - -extract_blob_intel_me() -{ -	printf "Extracting neutered ME for ${board}\n" - -	_me_destination=${CONFIG_ME_BIN_PATH#../../} - -	if [ ! -d "${_me_destination%/*}" ]; then -		mkdir -p ${_me_destination%/*} -	fi -	if [ -d "${appdir}" ]; then -		rm -r ${appdir} -	fi -	if [ -f "${_me_destination}" ]; then -		printf 'me already downloaded\n' -		return 0 -	fi - -	printf "Extracting and stripping Intel ME firmware\n" - -	innoextract ${dl_path} -d ${blobdir} \ -	|| 7z x ${dl_path} -o${appdir} \ -		|| fail 'Could not extract vendor update'  - -	bruteforce_extract_blob_intel_me "$(pwd)/${_me_destination}" \ -			"$(pwd)/${appdir}" \ -		|| fail "Could not extract Intel ME firmware" - -	printf "Truncated and cleaned me output to ${_me_destination}\n" -} - -# cursed, carcinogenic code. TODO rewrite it better -bruteforce_extract_blob_intel_me() -{ -	_me_destination="${1}" -	cdir="${2}" # must be an absolute path, not relative - -	if [ -f "${_me_destination}" ]; then -		return 0 -	fi - -	sdir="$(mktemp -d)" -	mkdir -p "${sdir}" || return 1 - -	( -	printf "Entering %s\n" "${cdir}" -	cd "${cdir}" || exit 1 -	for i in *; do -		if [ -f "${_me_destination}" ]; then -			# me.bin found, so avoid needless further traversal -			break -		elif [ -L "${i}" ]; then -			# symlinks are a security risk, in this context -			continue -		elif [ -f "${i}" ]; then -			"${mecleaner}" -r -t -O "${sdir}/vendorfile" \ -					-M "${_me_destination}" "${i}" \ -				&& break # (we found me.bin)	 -			"${mecleaner}" -r -t -O "${_me_destination}" "${i}" \ -				&& break # (we found me.bin) -			"${me7updateparser}" -O ${_me_destination} "${i}" \ -				&& break # (we found me.bin) -			_7ztest="${_7ztest}a" -			7z x "${i}" -o${_7ztest} || continue -			bruteforce_extract_blob_intel_me "${_me_destination}" \ -					"${cdir}/${_7ztest}" -			cdir="${1}" -			cd "${cdir}" -		elif [ -d "$i" ]; then -			bruteforce_extract_blob_intel_me "${_me_destination}" \ -					"${cdir}/${i}" -			cdir="${1}" -			cd "${cdir}" -		else -			printf "SKIPPING: %s\n" "${i}" -		fi -	done -	) - -	rm -Rf "${sdir}" - -	if [ ! -f "${_me_destination}" ]; then -		printf "me.bin not found in vendor update for: %s\n" ${board} -		return 1 -	fi -} - -download_ec() -{ -	printf "Downloading KBC1126 EC firmware for HP laptop\n" - -	fetch_update ec || return 1 -	extract_ec || return 1 -} - -extract_ec() -{ -	printf "Extracting KBC1126 EC firmware for board: %s\n" ${board} - -	_ec_destination=${CONFIG_KBC1126_FW1#../../} - -	if [ ! -d "${_ec_destination%/*}" ]; then -		mkdir -p "${_ec_destination%/*}" -	fi -	if [ -d "${appdir}" ]; then -		rm -Rf "${appdir}" -	fi -	if [ -f "${_ec_destination}" ]; then -		printf "ec already downloaded\n" -		return 0 -	fi - -	unar "${dl_path}" -o "${appdir}" - -	( -	cd "${appdir}/${dl_path##*/}" - -	mv Rompaq/68*.BIN ec.bin -	if [ ! -f ec.bin ]; then -		unar -D ROM.CAB Rom.bin -		mv Rom.bin ec.bin -	fi - -	"${kbc1126_ec_dump}" ec.bin -	) - -	for i in 1 2; do -		if [ -f "${appdir}/${dl_path##*/}/ec.bin.fw${i}" ]; then -			continue -		fi -		printf "Not found: %s/%s/ec.bin.fw%s\n" \ -				${appdir} ${dl_path##*/} ${i} -		printf "Could not extract EC firmware for: %s\n" \ -				${board} -		return 1 -	done - -	cp "${appdir}/${dl_path##*/}"/ec.bin.fw* "${_ec_destination%/*}/" -} - -download_e6400vga() -{ -	printf "Downloading Nvidia VGA ROM for Dell Latitude E6400\n" - -	fetch_update e6400vga || return 1 -	extract_e6400vga || return 1 -} - -extract_e6400vga() -{ -	printf "Extracting Nvidia VGA ROM for ${board}\n" - -	_vga_destination=${CONFIG_VGA_BIOS_FILE#../../} - -	if [ -f "${_vga_destination}" ]; then -		printf 'vga rom already downloaded\n' -		return 0 -	fi -	if [ ! -d "${_vga_destination%/*}" ]; then -		mkdir -p ${_vga_destination%/*} -	fi	 -	if [ -d "${appdir}" ]; then -		rm -r ${appdir} -	fi - -	mkdir -p "${appdir}" -	mv "${dl_path}" "${appdir}" - -	if [ "${e6400_vga_offset}" = "" ]; then -		printf "E6400 VGA offset not defined\n" -		return 1 -	elif [ "${e6400_vga_romname}" = "" ]; then -		printf "E6400 VGA ROM name not defined\n" -		return 1 -	fi - -	( -	cd "${appdir}" -	tail -c +${e6400_vga_offset} "${dl_path##*/}" \ -			| gunzip > bios.bin -	if [ ! -f "bios.bin" ]; then -		fail 'Could not extract bios.bin from Dell E6400 update' -	fi -	"${e6400_unpack}" bios.bin || printf "TODO: fix dell extract util\n" -	if [ ! -f "${e6400_vga_romname}" ]; then -		fail 'Could not extract VGA ROM from Dell E6400 BIOS update' -	fi -	) - -	cp "${appdir}"/"${e6400_vga_romname}" "${_vga_destination}" - -	printf "E6400 Nvidia ROM saved to: %s\n" "${_vga_destination}" -} - -fetch_update() -{ -	printf "Fetching vendor update for board: %s\n" ${board} - -	fw_type="${1}" -	dl="" -	dl_bkup="" -	dlsum="" -	if [ "${fw_type}" = "me" ]; then -		dl=${dl_url} -		dl_bkup=${dl_url_bkup} -		dlsum=${dl_hash} -	elif [ "${fw_type}" = "ec" ]; then -		dl=${ec_url} -		dl_bkup=${ec_url_bkup} -		dlsum=${ec_hash} -	elif [ "${fw_type}" = "e6400vga" ]; then -		dl=${e6400_vga_dl_url} -		dl_bkup=${e6400_vga_dl_url_bkup} -		dlsum=${e6400_vga_dl_hash} -	else -		printf "Unsupported download type: %s\n" ${fw_type} -		return 1 -	fi - -	if [ -z "${dl_url+x}" ] && [ "${fw_type}" != "e6400vga" ]; then -		printf "No vendor update specified for board: %s\n" ${board} -		return 1 -	fi - -	dl_path=${blobdir}/cache/${dlsum} -	mkdir -p ${blobdir}/cache - -	vendor_checksum ${dlsum} || \ -		wget ${dl} -O ${dl_path} || wget ${dl_bkup} -O ${dl_path} - -	vendor_checksum ${dlsum} || fail \ -		"Cannot guarantee intergity of vendor update for: ${board}" -} - -vendor_checksum() -{ -	if [ ! -f "${dl_path}" ]; then -		printf "Vendor update not found on disk for: %s\n" ${board} -		return 1 -	elif [ "$(sha1sum ${dl_path} | awk '{print $1}')" != "${1}" ]; then -		printf "Bad checksum on vendor update for: %s\n" ${board} -		return 1 -	fi -} - -fail() -{ -	printf "\nERROR: $@\n" -	exit 1 -} - -main $@ diff --git a/resources/scripts/update/blobs/extract b/resources/scripts/update/blobs/extract deleted file mode 100755 index b32ec0ea..00000000 --- a/resources/scripts/update/blobs/extract +++ /dev/null @@ -1,150 +0,0 @@ -#!/usr/bin/env sh -# script to automate extracting blobs from an existing vendor bios - -# SPDX-FileCopyrightText: 2022 Caleb La Grange <thonkpeasant@protonmail.com> -# SPDX-FileCopyrightText: 2023 Leah Rowe <leah@libreboot.org> -# SPDX-License-Identifier: GPL-3.0-only - -sname="" -board="" -vendor_rom="" - -cbdir="coreboot/default" -cbcfgsdir="resources/coreboot" -ifdtool="${cbdir}/util/ifdtool/ifdtool" -mecleaner="me_cleaner/me_cleaner.py" -me7updateparser="resources/blobs/me7_update_parser.py" - -boarddir="" - -CONFIG_HAVE_MRC="" -CONFIG_ME_BIN_PATH="" -CONFIG_GBE_BIN_PATH="" -CONFIG_IFD_BIN_PATH="" - -_me_destination="" -_gbe_destination="" -_ifd_destination="" - -main() -{ -	sname=${0} -	if [ $# -lt 2 ]; then -		fail "Missing arguments (less than two)." -	fi - -	board="${1}" -	vendor_rom="${2}" - -	boarddir="${cbcfgsdir}/${board}" - -	check_board -	build_dependencies -	extract_blobs -} - -check_board() -{ -	if [ ! -f "${vendor_rom}" ] ; then -		fail "file does not exist: ${vendor_rom}" -	elif [ ! -d "${boarddir}" ]; then -		fail "build/roms ${board}: target not defined" -	elif [ ! -f "${boarddir}/board.cfg" ]; then -		fail "build/roms ${board}: missing board.cfg" -	fi -} - -build_dependencies() -{ -	if [ ! -d me_cleaner ]; then -		printf "downloading me_cleaner\n" -		./download me_cleaner || fail 'could not download me_cleaner' -	else -		printf "me_cleaner already downloaded. Skipping.\n" -		printf "run ./download me_cleaner to manually overwrite\n" -	fi - -	if [ ! -d ${cbdir} ]; then -		printf "downloading coreboot\n" -		./download coreboot default \ -				|| fail "could not download coreboot" -	else -		printf "coreboot already downloaded. Skipping.\n" -		printf "run ./download coreboot to manually overwrite\n" -	fi - -	if ! [ -f ${ifdtool} ]; then -		printf "building ifdtool from coreboot\n" -		make -C "${ifdtool%/ifdtool}" \ -				|| fail "could not build ifdtool" -	fi -} - -extract_blobs() -{ -	printf "extracting blobs for %s from %s\n" ${board} ${vendor_rom} - -	set -- "${boarddir}/config/"* -	. ${1} 2>/dev/null -	. "${boarddir}/board.cfg" - -	if [ "$CONFIG_HAVE_MRC" = "y" ]; then -		printf 'haswell board detected, downloading mrc\n' -		./download mrc || fail "could not download mrc" -	fi - -	_me_destination=${CONFIG_ME_BIN_PATH#../../} -	_gbe_destination=${CONFIG_GBE_BIN_PATH#../../} -	_ifd_destination=${CONFIG_IFD_BIN_PATH#../../} - -	extract_blob_intel_me -	extract_blob_intel_gbe_nvm - -	# Cleans up other files extracted with ifdtool -	rm -f flashregion*.bin 2> /dev/null - -	if [ -f ${_ifd_destination} ]; then -		printf "gbe, ifd, and me extracted to %s\n" \ -				${_me_destination%/*} -	else -		printf "WARNING: Intel firmware descriptor could not " -		printf "be extracted with modified me\n" -	fi -} - -extract_blob_intel_me() -{ -	printf "extracting clean ime and modified ifd\n" - -	${mecleaner} -D ${_ifd_destination} \ -			-M ${_me_destination} ${vendor_rom} -t -r -S \ -	|| ${me7updateparser} \ -			-O ${_me_destination} ${vendor_rom} \ -	|| fail \ -			"me_cleaner failed to extract blobs from rom" -} - -extract_blob_intel_gbe_nvm() -{ -	printf "extracting gigabit ethernet firmware" -	./${ifdtool} -x ${vendor_rom} -	mv flashregion*gbe.bin ${_gbe_destination} \ -			|| fail 'could not extract gbe' -} - -fail() -{ -	print_help - -	printf "\n%s: ERROR: %s\n" ${sname} $@ -	exit 1  -} - -print_help() -{ -	printf "Usage: ./blobutil extract {boardname} {path/to/vendor_rom}\n" -	printf "Example: ./blobutil extract x230 12mb_flash.bin\n" -	printf "\nYou need to specify exactly 2 arguments\n" -} - -main $@ diff --git a/resources/scripts/update/blobs/inject b/resources/scripts/update/blobs/inject deleted file mode 100755 index 891cb198..00000000 --- a/resources/scripts/update/blobs/inject +++ /dev/null @@ -1,389 +0,0 @@ -#!/usr/bin/env sh - -# SPDX-FileCopyrightText: 2022 Caleb La Grange <thonkpeasant@protonmail.com> -# SPDX-FileCopyrightText: 2022 Ferass El Hafidi <vitali64pmemail@protonmail.com> -# SPDX-FileCopyrightText: 2023 Leah Rowe <info@minifree.org> -# SPDX-License-Identifier: GPL-3.0-only - -sname="" -archive="" -_filetype="" -rom="" -board="" -modifygbe="" -new_mac="" -release="" -releasearchive="" - -cbdir="coreboot/default" -cbcfgsdir="resources/coreboot" -ifdtool="cbutils/default/ifdtool" -cbfstool="cbutils/default/cbfstool" -nvmutil="util/nvmutil/nvm" -boarddir="" -pciromsdir="pciroms" - -CONFIG_HAVE_MRC="" -CONFIG_HAVE_ME_BIN="" -CONFIG_ME_BIN_PATH="" -CONFIG_KBC1126_FIRMWARE="" -CONFIG_KBC1126_FW1="" -CONFIG_KBC1126_FW1_OFFSET="" -CONFIG_KBC1126_FW2="" -CONFIG_KBC1126_FW2_OFFSET="" -CONFIG_VGA_BIOS_FILE="" -CONFIG_VGA_BIOS_ID="" -CONFIG_GBE_BIN_PATH="" - -main() -{ -	sname="${0}" - -	if [ $# -lt 1 ]; then -		fail "No options specified." -	elif [ "${1}" = "listboards" ]; then -		listboards -		exit 0 -	fi - -	archive="${1}" - -	while getopts r:b:m: option -	do -	    case "${option}" -		in -		r)rom=${OPTARG};; -		b)board=${OPTARG};; -		m) -			modifygbe=true -			new_mac=${OPTARG} -			;; -	    esac -	done - -	check_board -	build_dependencies -	inject_blobs -} - -check_board() -{ -	if ! check_release ${archive} ; then -		if [ ! -f "${rom}" ]; then -			fail "${rom} is not a valid path" -		elif [ -z ${rom+x} ]; then -			fail 'no rom specified' -		elif [ -z ${board+x} ]; then -			board=$(detect_board ${rom}) \ -					|| fail 'no board specified' -		fi -	else -		release=true -		releasearchive="${archive}" -		board=$(detect_board ${archive}) \ -				|| fail 'Could not detect board type' -	fi - -	boarddir="${cbcfgsdir}/${board}" -	if [ ! -d "${boarddir}" ]; then -		fail "board ${board} not found" -	fi -} - -check_release() -{ -	if [ ! -f "${archive}" ]; then -		return 1 -	fi - -	if [ "${archive##*.}" = "xz" ]; then -		printf "%s\n" "Release archive ${archive} detected" -		return 0 -	else -		return 1 -	fi -} - -# This function tries to determine the board from the filename of the rom. -# It will only succeed if the filename is not changed from the build/download -detect_board() -{ -	path=${1} -	filename=$(basename ${path}) -	case ${filename} in -		grub_*) -		board=$(echo "${filename}" | cut -d '_' -f2-3) -		;; -		seabios_withgrub_*) -		board=$(echo "${filename}" | cut -d '_' -f3-4) -		;; -		*.tar.xz) -		_stripped_prefix=${filename#*_} -		board="${_stripped_prefix%.tar.xz}" -		;; -		*) -		return 1 -	esac	 - -	if [ -d "${boarddir}/" ]; then -		printf '%s\n' "${board}" -		return 0 -	else -		return 1 -	fi -} - -build_dependencies() -{ -	if [ ! -d ${cbdir} ]; then -		printf "downloading coreboot\n" -		./download coreboot default -	fi - -	./build module cbutils default || fail "could not build cbutils" - -	./blobutil download ${board} || \ -			fail "Could not download blobs for ${board}" -} - -inject_blobs() -{ -	if [ "${release}" = "true" ]; then -		echo 'patching release file' -		patch_release_roms -	else -		patch_rom ${rom} -	fi -} - -patch_release_roms() -{ -	_tmpdir=$(mktemp -d "/tmp/${board}_tmpXXXX") -	tar xf "${releasearchive}" -C "${_tmpdir}" || \ -	fail 'could not extract release archive' - -	for x in ${_tmpdir}/bin/*/*.rom ; do -		echo "patching rom $x" -		patch_rom ${x} || fail "could not patch ${x}" -	done - -	( -	cd ${_tmpdir}/bin/* -	sha1sum --status -c blobhashes || \ -	fail 'ROMs did not match expected hashes' -	) - -	if [ "${modifygbe}" = "true" ]; then -		for x in ${_tmpdir}/bin/*/*.rom ; do -			modify_gbe ${x} -		done -	fi - -	if ! [ -d bin/release ]; then -		mkdir -p bin/release -	fi - -	mv ${_tmpdir}/bin/* bin/release/ && \ -	printf '%s\n' 'Success! Your ROMs are in bin/release' - -	rm -r "${_tmpdir}" -} - -patch_rom() -{ -	rom="${1}" - -	set -- "${boarddir}/config/"* -	. ${1} 2>/dev/null -	. "${boarddir}/board.cfg" - -	if [ "$CONFIG_HAVE_MRC" = "y" ]; then -		inject_blob_intel_mrc "${rom}" -	fi - -	if [ "${CONFIG_HAVE_ME_BIN}" = "y" ]; then -		inject_blob_intel_me "${rom}" -	fi - -	if [ "${CONFIG_KBC1126_FIRMWARE}" = "y" ]; then -		inject_blob_hp_kbc1126_ec "${rom}" -	fi - -	if [ "${CONFIG_VGA_BIOS_FILE}" != "" ] \ -				&& [ "${CONFIG_VGA_BIOS_ID}" != "" ]; then -		inject_blob_dell_e6400_vgarom_nvidia -	fi - -	if [ "${modifygbe}" = "true" ] && ! [ "${release}" = "true" ]; then -		modify_gbe ${rom} -	fi -} - -inject_blob_intel_mrc() -{ -	rom="${1}" - -	printf 'adding mrc\n' - -	# mrc.bin must be inserted at a specific offset. the only -	# libreboot platform that needs it, at present, is haswell - -	# in cbfstool, -b values above 0x80000000 are interpreted as -	# top-aligned x86 memory locations. this is converted into an -	# absolute offset within the flash, and inserted accordingly -	# at that offset into the ROM image file - -	# coreboot's own build system hardcodes the mrc.bin offset -	# because there is only one correct location in memory, but -	# it would be useful for lbmk if it could be easily scanned -	# from Kconfig, with the option to change it where in practise -	# it is not changed - -	# the hardcoded offset below is based upon reading of the coreboot -	# source code, and it is *always* correct for haswell platform. -	# TODO: this logic should be tweaked to handle more platforms - -	${cbfstool} ${rom} add -f mrc/haswell/mrc.bin -n mrc.bin -t mrc \ -		-b 0xfffa0000 || exit 1 -} - -inject_blob_intel_me() -{ -	printf 'adding intel management engine\n' - -	rom="${1}" - -	if [ -z ${CONFIG_ME_BIN_PATH} ]; then -		fail "CONFIG_ME_BIN_PATH not set" -	fi - -	_me_location=${CONFIG_ME_BIN_PATH#../../} - -	if [ ! -f "${_me_location}" ]; then -		fail "CONFIG_ME_BIN_PATH points to missing file" -	fi - -	${ifdtool} -i me:${_me_location} ${rom} -O ${rom} || exit 1 -} - -inject_blob_hp_kbc1126_ec() -{ -	rom="${1}" - -	_ec1_location="${CONFIG_KBC1126_FW1#../../}" -	_ec1_offset="${CONFIG_KBC1126_FW1_OFFSET}" -	_ec2_location="${CONFIG_KBC1126_FW2#../../}" -	_ec2_offset="${CONFIG_KBC1126_FW2_OFFSET}" - -	printf "adding hp kbc1126 ec firmware\n" - -	if [ "${_ec1_offset}" = "" ] || [ "${_ec1_offset}" = "" ]; then -		printf "EC offsets not declared for board: %s\n" \ -				"${board}" -		exit 1 -	fi -	if [ "${_ec1_location}" = "" ] || [ "${_ec2_location}" = "" ]; then -		printf "EC firmware path not declared for board: %s\n" \ -				"${board}" -	fi -	if [ ! -f "${_ec1_location}" ] || [ ! -f "${_ec2_location}" ]; then -		printf "EC firmware not downloaded for board: %s\n" \ -				"${board}" -		exit 1 -	fi - -	${cbfstool} "${rom}" add -f ${_ec1_location} -n ecfw1.bin \ -			-b ${_ec1_offset} -t raw || exit 1 -	${cbfstool} "${rom}" add -f ${_ec2_location} -n ecfw2.bin \ -			-b ${_ec2_offset} -t raw || exit 1 -} - -inject_blob_dell_e6400_vgarom_nvidia() -{ -	rom="${1}" - -	_vga_location="${CONFIG_VGA_BIOS_FILE#../../}" -	_vga_dir="${_vga_location%/*}" -	_vga_filename="${_vga_location##*/}" - -	printf "adding pci option rom\n" - -	if [ "${_vga_dir}" != "${pciromsdir}" ]; then -		printf "Invalid PCI ROM directory: %s\n" ${_vga_dir} -		exit 1 -	fi -	if [ ! -f "${_vga_location}" ]; then -		printf "No such file exists: %s\n" ${_vga_location} -		exit 1 -	fi - -	${cbfstool} ${rom} add -f "${_vga_location}" \ -		-n "pci${CONFIG_VGA_BIOS_ID}.rom" \ -		-t optionrom || exit 1 -} - -modify_gbe() -{ -	printf "changing mac address in gbe to ${new_mac}\n" - -	rom=${1} - -	if [ -z ${CONFIG_GBE_BIN_PATH} ]; then -		fail "CONFIG_GBE_BIN_PATH not set" -	fi - -	_gbe_location=${CONFIG_GBE_BIN_PATH#../../} - -	if [ ! -f "${_gbe_location}" ]; then -		fail "CONFIG_GBE_BIN_PATH points to missing file" -	fi - -	if [ ! -f ${nvmutil} ]; then -		make -C util/nvmutil || fail 'failed to build nvmutil' -	fi - -	_gbe_tmp=$(mktemp -t gbeXXXX.bin) -	cp ${_gbe_location} ${_gbe_tmp} -	${nvmutil} "${_gbe_tmp}" setmac ${new_mac} \ -			|| fail 'failed to modify mac address' - -	${ifdtool} -i GbE:${_gbe_tmp} "${rom}" \ -			-O "${rom}" || exit 1 - -	rm -f ${_gbe_tmp} -} - -listboards() -{ -	for boarddir in ${cbcfgsdir}/*; do -		if [ ! -d "${boarddir}" ]; then continue; fi -		board="${boarddir##${cbcfgsdir}/}" -		board="${board%/}" -		printf '%s\n' "${board##*/}" -	done -} - -fail() -{ -	if [ ! -z ${@+x} ]; then -		printf "\n%s: ERROR: ${@}\n" ${sname} -	fi - -	usage -	exit 1 -} - -usage() -{ -	cat <<- EOF -	USAGE: ./blobutil inject -r [rom path] -b [boardname] -m [macaddress] -	Example: ./blobutil inject -r x230_12mb.rom -b x230_12mb - -	Adding a macadress to the gbe is optional. -	If the [-m] parameter is left blank, the gbe will not be touched. - -	Type './blobutil inject listboards' to get a list of valid boards -	EOF -} - -main $@ diff --git a/resources/scripts/update/module/bios_extract b/resources/scripts/update/module/bios_extract deleted file mode 100755 index 1688aabe..00000000 --- a/resources/scripts/update/module/bios_extract +++ /dev/null @@ -1,22 +0,0 @@ -#!/usr/bin/env sh -# -#   Copyright (C) 2023 Leah Rowe <info@minifree.org> -# -#    This program is free software: you can redistribute it and/or modify -#    it under the terms of the GNU General Public License as published by -#    the Free Software Foundation, either version 3 of the License, or -#    (at your option) any later version. -# -#    This program is distributed in the hope that it will be useful, -#    but WITHOUT ANY WARRANTY; without even the implied warranty of -#    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the -#    GNU General Public License for more details. -# -#    You should have received a copy of the GNU General Public License -#    along with this program.  If not, see <http://www.gnu.org/licenses/>. -# - -[ "x${DEBUG+set}" = 'xset' ] && set -v -set -u -e - -./gitclone bios_extract diff --git a/resources/scripts/update/module/me_cleaner b/resources/scripts/update/module/me_cleaner deleted file mode 100755 index 93173257..00000000 --- a/resources/scripts/update/module/me_cleaner +++ /dev/null @@ -1,25 +0,0 @@ -#!/usr/bin/env sh -# -#   Copyright (C) 2020 Leah Rowe <info@minifree.org> -# -#    This program is free software: you can redistribute it and/or modify -#    it under the terms of the GNU General Public License as published by -#    the Free Software Foundation, either version 3 of the License, or -#    (at your option) any later version. -# -#    This program is distributed in the hope that it will be useful, -#    but WITHOUT ANY WARRANTY; without even the implied warranty of -#    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the -#    GNU General Public License for more details. -# -#    You should have received a copy of the GNU General Public License -#    along with this program.  If not, see <http://www.gnu.org/licenses/>. -# - -# This script assumes that the working directory is the -# root of retroboot_src or retroboot git. - -[ "x${DEBUG+set}" = 'xset' ] && set -v -set -u -e - -./gitclone me_cleaner diff --git a/resources/scripts/update/module/mrc b/resources/scripts/update/module/mrc deleted file mode 100755 index d6a1c3a6..00000000 --- a/resources/scripts/update/module/mrc +++ /dev/null @@ -1,186 +0,0 @@ -#!/usr/bin/env sh - -# Download Intel MRC images -# -#    This program is free software: you can redistribute it and/or modify -#    it under the terms of the GNU General Public License as published by -#    the Free Software Foundation, version 2 of the License. -# -#    This program is distributed in the hope that it will be useful, -#    but WITHOUT ANY WARRANTY; without even the implied warranty of -#    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the -#    GNU General Public License for more details. -# -#    You should have received a copy of the GNU General Public License -#    along with this program.  If not, see <http://www.gnu.org/licenses/>. -# - -[ "x${DEBUG+set}" = 'xset' ] && set -v -set -u -e -export PATH="${PATH}:/sbin" - -# This file is forked from util/chromeos/crosfirmware.sh in coreboot cfc26ce278 -# Changes to it in *this version* are copyright 2021 and 2023 Leah Rowe, under -# the same license as above. - -# use updated manifest from wayback machine, when updating mrc.bin, -# and update the other variables below accordingly. current manifest used: -# https://web.archive.org/web/20210211071412/https://dl.google.com/dl/edgedl/chromeos/recovery/recovery.conf - -# the wayback machine is used so that we get the same manifest. google -# does not seem to version the manifest, but archives are available - -# variables taken from that manifest: - -_board="peppy" -_file="chromeos_12239.92.0_peppy_recovery_stable-channel_mp-v3.bin" -_url="https://dl.google.com/dl/edgedl/chromeos/recovery/chromeos_12239.92.0_peppy_recovery_stable-channel_mp-v3.bin.zip" -_url2="https://web.archive.org/web/20200516070928/https://dl.google.com/dl/edgedl/chromeos/recovery/chromeos_12239.92.0_peppy_recovery_stable-channel_mp-v3.bin.zip" -_sha1sum="cd5917cbe7f821ad769bf0fd87046898f9e175c8" -_mrc_complete_hash="d18de1e3d52c0815b82ea406ca07897c56c65696" -_mrc_complete="mrc/haswell/mrc.bin" - -cbdir="coreboot/default" -cbfstool="cbutils/default/cbfstool" - -sname="" - -main() -{ -	sname=${0} -	printf "Downloading Intel MRC blobs\n" - -	check_existing && exit 0 -	build_dependencies || fail "could not build dependencies" -	fetch_mrc || fail "could not fetch mrc.bin" -} - -check_existing() -{ -	if [ ! -f ${_mrc_complete} ]; then -		return 1 -	fi -	printf 'found existing mrc.bin, checking its hash\n' -	if [ "$(sha1sum ${_mrc_complete} | awk '{print $1}')" \ -			= "${_mrc_complete_hash}" ]; then -		printf 'checksums matched, skipping downloading\n' -		return 0 -	else -		printf 'hashes did not match, starting over\n' -		return 1 -	fi -} - -build_dependencies() -{ -	if [ ! -d "${cbdir}/" ]; then -	    ./download coreboot default || return 1 -	fi -	./build module cbutils default || return 1 -	return 0 -} - -fetch_mrc() -{ -	mkdir -p mrc/haswell/ || return 1 - -	( -	cd mrc/haswell/ - -	download_image ${_url} ${_file} ${_sha1sum} -	if [ ! -f ${_file} ]; then -		download_image ${_url2} ${_file} ${_sha1sum} -	fi -	if [ ! -f $_file ]; then -		fail "%{_file} not downloaded / verification failed." -	fi - -	extract_partition ROOT-A ${_file} root-a.ext2 -	extract_shellball root-a.ext2 chromeos-firmwareupdate-${_board} - -	extract_coreboot chromeos-firmwareupdate-${_board} - -	../../${cbfstool} coreboot-*.bin extract -f mrc.bin \ -			-n mrc.bin -r RO_SECTION \ -					|| fail "Could not fetch mrc.bin" -	rm -f "chromeos-firmwareupdate-${_board}" coreboot-*.bin \ -			"${_file}" "root-a.ext2" - -	printf "\n\nmrc.bin saved to ${_mrc_complete}\n\n" -	) - -	return 0 -} - -download_image() -{ -	url=${1} -	_file=${2} -	_sha1sum=${3} - -	echo "Downloading recovery image" -	curl "$url" > "$_file.zip" -	if [ "$(sha1sum ${_file}.zip | awk '{print $1}')" = "${_sha1sum}" ] -	then -		unzip -q "${_file}.zip" -		rm "${_file}.zip" -		echo "Checksum verification passed for recovery image." -		return 0 -	else -		rm "${_file}.zip" -		echo "Bad checksum. Recovery image deleted." -		return 1 -	fi -} - -extract_partition() -{ -	NAME=${1} -	FILE=${2} -	ROOTFS=${3} -	_bs=1024 - -	echo "Extracting ROOT-A partition" -	ROOTP=$( printf "unit\nB\nprint\nquit\n" | \ -		 parted ${FILE} 2>/dev/null | grep ${NAME} ) - -	START=$(( $( echo ${ROOTP} | cut -f2 -d\ | tr -d "B" ) )) -	SIZE=$(( $( echo ${ROOTP} | cut -f4 -d\ | tr -d "B" ) )) - -	dd if=${FILE} of=${ROOTFS} bs=${_bs} skip=$(( ${START} / ${_bs} )) \ -		count=$(( ${SIZE} / ${_bs} ))  > /dev/null -} - -extract_shellball() -{ -	ROOTFS=${1} -	SHELLBALL=${2} - -	echo "Extracting chromeos-firmwareupdate" -	printf "cd /usr/sbin\ndump chromeos-firmwareupdate ${SHELLBALL}\nquit" \ -		| debugfs ${ROOTFS} > /dev/null 2>&1 -} - -extract_coreboot() -{ -	_shellball=${1} -	_unpacked=$( mktemp -d ) - -	echo "Extracting coreboot image" -	sh ${_shellball} --unpack ${_unpacked} > /dev/null - -	_version=$( cat ${_unpacked}/VERSION | grep BIOS\ version: | \ -			cut -f2 -d: | tr -d \  ) - -	cp ${_unpacked}/bios.bin coreboot-${_version}.bin -	rm -r "${_unpacked}" -} - -fail() -{ -	printf "%s: ERROR: %s\n" -			${sname} ${1} -	exit 1 -} - -main $@ | 
