2021-12-05 14:40:38 +00:00
# Configuration for a T530 running Qubes and other Linux Based OSes (through kexec)
#
# Includes
# - Deactivated+neutered ME and expanded consequent IFD BIOS regions
# - Forged 00:DE:AD:C0:FF:EE MAC address (if not extracting gbe.bin from backup with blobs/xx30/extract.sh)
# - Note that this MAC address can be modified under build/coreboot-VER/util/bincfg/gbe-82579LM.set
#
# - Includes Nitrokey/Librem Key HOTP Security dongle remote attestation (in addition to TOTP remote attestation through Qr Code)
2021-12-19 21:13:47 +00:00
# This board is designed for a t530 without a dGPU. It will work just fine for a board with a dGPU, except you will not be able to use an external monitor via the mini-displayport or the dock's displayport, though external monitors will work via VGA ports. To initialize the dGPU please use one of the dgpu boards.
2021-12-05 14:40:38 +00:00
export CONFIG_COREBOOT = y
2023-02-15 16:47:30 +00:00
export CONFIG_COREBOOT_VERSION = 4.19
2023-05-23 14:29:11 +00:00
export CONFIG_LINUX_VERSION = 5.10.5
2021-12-05 14:40:38 +00:00
2023-01-31 15:49:16 +00:00
CONFIG_COREBOOT_CONFIG = config/coreboot-t530-maximized.config
2022-06-10 13:52:07 +00:00
CONFIG_LINUX_CONFIG = config/linux-x230-maximized.config
2021-12-05 14:40:38 +00:00
#Additional hardware support
CONFIG_LINUX_USB = y
CONFIG_LINUX_E1000E = y
2022-09-16 16:51:38 +00:00
CONFIG_CRYPTSETUP2 = y
2021-12-05 14:40:38 +00:00
CONFIG_FLASHROM = y
CONFIG_FLASHTOOLS = y
CONFIG_GPG2 = y
CONFIG_KEXEC = y
CONFIG_UTIL_LINUX = y
CONFIG_LVM2 = y
CONFIG_MBEDTLS = y
CONFIG_PCIUTILS = y
2023-04-12 19:08:49 +00:00
#platform locking finalization (PR0)
CONFIG_IO386 = y
export CONFIG_FINALIZE_PLATFORM_LOCKING_PRESKYLAKE = y
2021-12-05 14:40:38 +00:00
#Remote attestation support
#TPM based requirements
export CONFIG_TPM = y
CONFIG_POPT = y
CONFIG_QRENCODE = y
CONFIG_TPMTOTP = y
#HOTP based remote attestation for supported USB Security dongle
#With/Without TPM support
CONFIG_HOTPKEY = y
#Nitrokey Storage admin tool
2021-12-05 14:44:10 +00:00
CONFIG_NKSTORECLI = n
2021-12-05 14:40:38 +00:00
#GUI Support
#Console based Whiptail support(Console based, no FB):
#CONFIG_SLANG=y
#CONFIG_NEWT=y
#FBWhiptail based (Graphical):
CONFIG_CAIRO = y
CONFIG_FBWHIPTAIL = y
#Additional tools:
#SSH server (requires ethernet drivers, eg: CONFIG_LINUX_E1000E)
CONFIG_DROPBEAR = y
export CONFIG_BOOTSCRIPT = /bin/gui-init
export CONFIG_BOOT_REQ_HASH = n
export CONFIG_BOOT_REQ_ROLLBACK = n
2023-11-08 16:47:18 +00:00
export CONFIG_BOOT_KERNEL_ADD = ""
export CONFIG_BOOT_KERNEL_REMOVE = "intel_iommu=on intel_iommu=igfx_off"
2021-12-05 14:40:38 +00:00
export CONFIG_BOOT_DEV = "/dev/sda1"
export CONFIG_BOARD_NAME = "Thinkpad T530-hotp-maximized"
export CONFIG_FLASHROM_OPTIONS = "--force --noverify-all -p internal"
# xx30-*-maximized boards require of you initially call one of the
# following to have gbe.bin ifd.bin and me.bin
# - blobs/xx30/download_clean_me.sh
# To download Lenovo original ME binary, neuter+deactivate ME, produce
# reduced IFD ME region and expanded BIOS IFD region.
# - blobs/xx30/extract.sh
# To extract from backuped 8M (bottom SPI) ME binary, GBE and IFD blobs.
2023-11-10 19:48:06 +00:00
# Make the Coreboot build depend on the following 3rd party blobs:
$(build)/coreboot-$(CONFIG_COREBOOT_VERSION)/$(BOARD)/.build : \
$( pwd ) /blobs/xx30/me.bin
$(pwd)/blobs/xx30/me.bin :
COREBOOT_DIR = " $( build) / $( coreboot_base_dir) " \
$( pwd ) /blobs/xx30/download_clean_me.sh $( pwd ) /blobs/xx30
2023-12-18 21:44:00 +00:00
# Generate split 4MB top / 8MB bottom ROMs
BOARD_TARGETS := split_8mb4mb