2021-12-05 14:40:38 +00:00
# Configuration for a T530 running Qubes and other Linux Based OSes (through kexec)
#
# Includes
# - Deactivated+neutered ME and expanded consequent IFD BIOS regions
# - Forged 00:DE:AD:C0:FF:EE MAC address (if not extracting gbe.bin from backup with blobs/xx30/extract.sh)
# - Note that this MAC address can be modified under build/coreboot-VER/util/bincfg/gbe-82579LM.set
#
# - Includes Nitrokey/Librem Key HOTP Security dongle remote attestation (in addition to TOTP remote attestation through Qr Code)
2021-12-19 21:13:47 +00:00
# This board is designed for a t530 without a dGPU. It will work just fine for a board with a dGPU, except you will not be able to use an external monitor via the mini-displayport or the dock's displayport, though external monitors will work via VGA ports. To initialize the dGPU please use one of the dgpu boards.
2021-12-05 14:40:38 +00:00
export CONFIG_COREBOOT = y
2024-02-05 16:06:11 +00:00
export CONFIG_COREBOOT_VERSION = 4.22.01
2023-05-23 14:29:11 +00:00
export CONFIG_LINUX_VERSION = 5.10.5
2021-12-05 14:40:38 +00:00
2023-01-31 15:49:16 +00:00
CONFIG_COREBOOT_CONFIG = config/coreboot-t530-maximized.config
2022-06-10 13:52:07 +00:00
CONFIG_LINUX_CONFIG = config/linux-x230-maximized.config
2021-12-05 14:40:38 +00:00
#Additional hardware support
CONFIG_LINUX_USB = y
CONFIG_LINUX_E1000E = y
2023-11-25 19:50:32 +00:00
CONFIG_MOBILE_TETHERING = y
2021-12-05 14:40:38 +00:00
2022-09-16 16:51:38 +00:00
CONFIG_CRYPTSETUP2 = y
2021-12-05 14:40:38 +00:00
CONFIG_FLASHROM = y
CONFIG_FLASHTOOLS = y
CONFIG_GPG2 = y
CONFIG_KEXEC = y
CONFIG_UTIL_LINUX = y
CONFIG_LVM2 = y
CONFIG_MBEDTLS = y
CONFIG_PCIUTILS = y
2023-04-12 19:08:49 +00:00
#platform locking finalization (PR0)
CONFIG_IO386 = y
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE = y
2021-12-05 14:40:38 +00:00
#Remote attestation support
#TPM based requirements
export CONFIG_TPM = y
CONFIG_POPT = y
CONFIG_QRENCODE = y
CONFIG_TPMTOTP = y
#HOTP based remote attestation for supported USB Security dongle
#With/Without TPM support
CONFIG_HOTPKEY = y
2024-01-09 19:33:23 +00:00
export CONFIG_AUTO_BOOT_TIMEOUT = 5
2021-12-05 14:40:38 +00:00
#Nitrokey Storage admin tool
2021-12-05 14:44:10 +00:00
CONFIG_NKSTORECLI = n
2021-12-05 14:40:38 +00:00
#GUI Support
#Console based Whiptail support(Console based, no FB):
#CONFIG_SLANG=y
#CONFIG_NEWT=y
#FBWhiptail based (Graphical):
CONFIG_CAIRO = y
CONFIG_FBWHIPTAIL = y
#Additional tools:
#SSH server (requires ethernet drivers, eg: CONFIG_LINUX_E1000E)
CONFIG_DROPBEAR = y
export CONFIG_BOOTSCRIPT = /bin/gui-init
export CONFIG_BOOT_REQ_HASH = n
export CONFIG_BOOT_REQ_ROLLBACK = n
2023-11-08 16:47:18 +00:00
export CONFIG_BOOT_KERNEL_ADD = ""
export CONFIG_BOOT_KERNEL_REMOVE = "intel_iommu=on intel_iommu=igfx_off"
2021-12-05 14:40:38 +00:00
export CONFIG_BOOT_DEV = "/dev/sda1"
export CONFIG_BOARD_NAME = "Thinkpad T530-hotp-maximized"
export CONFIG_FLASHROM_OPTIONS = "--force --noverify-all -p internal"
2024-01-04 18:48:52 +00:00
#Include bits related to ivybridge ME blob download/neutering down to BUP+ROMP
BOARD_TARGETS := xx30_me_blobs
2023-11-10 19:48:06 +00:00
2023-12-18 21:44:00 +00:00
# Generate split 4MB top / 8MB bottom ROMs
2024-01-04 18:48:52 +00:00
BOARD_TARGETS += split_8mb4mb