Skip to content

Update µcode 2026-08-07 - #953

Open
github-actions[bot] wants to merge 1234 commits into
dasharofrom
update_ucode_2026-08-07
Open

Update µcode 2026-08-07#953
github-actions[bot] wants to merge 1234 commits into
dasharofrom
update_ucode_2026-08-07

Conversation

@github-actions

Copy link
Copy Markdown

Automated changes by create-pull-request GitHub action

mkopec and others added 30 commits October 31, 2025 16:43
…r_error_type

Needed to fix compilation error if CBnT is enabled and TXT is disabled.

Upstream-Status: Pending
Change-Id: I1e267cdc21e8e397d5021f3e5edfc6ddcd374016
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Change-Id: I3f8eb4a19cb6b5f5bd87a850d1faf865959040a7
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Change-Id: I31dd961a7eac92fea3d54226e5331bdba1bce9b7
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Gołaś <filip.golas@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Gołaś <filip.golas@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Mateusz Maciejewski <mateusz.maciejewski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Mateusz Maciejewski <mateusz.maciejewski@3mdeb.com>
This reverts commit f3dbe79.

Signed-off-by: Thomas Clarke <tonux@riseup.net>
Signed-off-by: Thomas Clarke <tonux@riseup.net>
…etection feature

Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Mateusz Maciejewski <mateusz.maciejewski@3mdeb.com>
…M on i226

ASPM has been reported to cause reduced performance when running iperf3
between two VP2440 DUTs. Disable ASPM to ensure full performance is
available.

Upstream-Status: Pending
Change-Id: I6ef31a47aac64c871568a653f1cefb773f27f44a
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Change-Id: I51d677dbec0b19b6a436d45c674848fcd2ebb521
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
…, L1 for SSD

Upstream-Status: Pending
Change-Id: I1a04d4bc36b10df2fd3ea7687674142c8150d166
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Change-Id: If0d9c2689165047e6811d442f73648a81fa40ee6
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]

Change-Id: I3b7b630bcc817f290c6cb03e39e696525f407f04
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Change-Id: Ia52318806620413ad07dd52d6d6fbc29468dd0e6
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
3rdparty/dasharo-blobs updated to 16.1.40 for ADL-P

Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Mateusz Maciejewski <mateusz.maciejewski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Mateusz Maciejewski <mateusz.maciejewski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Upstream-Status: Pending
Change-Id: I2218725ecf7a8787a70816660de237bed77b2b8f
Signed-off-by: Michał Żygowski <michal.zygowski@3mdeb.com>
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Upstream-Status: Pending
Change-Id: Id9375d1a883d485b14132f76dfa36aa3ae150b72
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Change-Id: If0d50df52e8eca52816d66d6d80bcdc2a617ef59
Signed-off-by: Michał Kopeć <michal.kopec@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Wiktor Mowinski <wiktor.mowinski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Wiktor Mowinski <wiktor.mowinski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Wiktor Mowinski <wiktor.mowinski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Wiktor Mowinski <wiktor.mowinski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Wiktor Mowinski <wiktor.mowinski@3mdeb.com>
This deduplicates and simplifies bodies of several functions.

Upstream-Status: Inappropriate [Dasharo downstream]
Change-Id: I64beb41f8e103f7c7c7accf497e3cb36f0a914c9
Signed-off-by: Sergii Dmytruk <sergii.dmytruk@3mdeb.com>
SergiiDmytruk and others added 29 commits June 24, 2026 20:44
It's necessary to make builds reproducible.

Change-Id: I29758c256c8c6f6852ca2ca16eebc0e87571d3a6
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Sergii Dmytruk <sergii.dmytruk@3mdeb.com>
This tells EDK the real workspace directory, which can be taken into
account to make the build insensitive to absolute build paths.

Change-Id: Ifae696b8c196be34ac526ec32f2b90511df8cfaa
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Sergii Dmytruk <sergii.dmytruk@3mdeb.com>
Set ME to HAP disable, as per Protectli requirements. Update config
version to RC2

Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Mostly to obtain 2026.3 IoT FSP for Arrow/Meteor Lake

Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
The ArrowLakeUH Edge/IoT FSP defaults I2cPostCodeEnable to 1, routing
all internal FSP postcodes over I2C instead of the legacy Port80 path.
On the NUC BOX this made FspMemoryInit/FspSiliconInit/
FspMultiPhaseSiInit uniformly ~10-125x slower (~20s total boot vs a
~2s boot with it disabled), and suppressed the board's postcode
display, which only showed codes once Port80 routing was restored.

Upstream-Status: Pending
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Add a Kconfig to direct FSP to skip sending the TBT Connect Topology
(CNTP) command, which is not needed when using software connection
manager (as opposed to firmware connection manager). There are also
situations where boards using FW CM may wish to skip sending the
command.

When selected, the FSP UPD ITbtConnectTopologyTimeoutInMs will be set
to zero, which tells FSP to skip sending the command.

Previous SoCs always set this UPD to zero, but upon discussion it was
determined that this is not universally desirable, so guard it with a
Kconfig.

Change-Id: I634dfb9969410b57e8415ac659fa3e8d6943d52c
Upstream-Status: Backport [CB:87569]
Signed-off-by: Sean Rhodes <sean@starlabs.systems>
Signed-off-by: Matt DeVillier <matt.devillier@gmail.com>
Reviewed-on: https://review.coreboot.org/c/coreboot/+/86989
Tested-by: build bot (Jenkins) <no-reply@coreboot.org>
Reviewed-by: Jérémy Compostella <jeremy.compostella@intel.com>
Reviewed-by: Subrata Banik <subratabanik@google.com>
Reviewed-by: Angel Pons <th3fanbus@gmail.com>
Enable the option to potentially save a couple seconds of boot time,
removing an unnecessary timeout

Upstream-Status: Pending
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
edk2-platforms is a separate git repository compiled into the edk2 UEFI
payload, but it was previously absent from the embedded SBOM. Add a new
SBOM_EDK2_PLATFORMS component following the existing per-component
pattern (SBOM_<X> / _GENERATE / _PATH + CoSWID template + Makefile rule).

GENERATE mode records the commit hash (software-version) and tree hash
(colloquial-version) of the checkout at
payloads/external/edk2/workspace/edk2-platforms, mirroring the iPXE and
edk2 payload git-backed component rules. The _PATH option lets a vendor
supply a full external SBOM JSON instead. The option defaults to n, so
existing boards' SBOMs are unchanged.

Upstream-Status: Pending
Change-Id: I9f3f7bc8248da2d780764bca7d7eee2e8e4c7dea
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Add edk2-platforms to SBOM as well.

Upstream-Status: Inappropriate [Dasharo downstream]
Change-Id: I5fd189ad457b9766a7e5e25c09d89f8e71dbee8e
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Pulls the goswid change that records a SHA-256 file hash in the CoSWID
payload, used by the src/sbom rules below to carry per-component
integrity data. Changes .gitmodules to point to Dasharo fork containing
the patch.

Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
An EU CRA check (sbom-tools --standard cra) on the embedded SBOM flagged
two gaps: no component carried a cryptographic hash (Annex I integrity /
vendor hash carry-through, an error), and only coreboot declared a
license while the other components did not (Art. 13(5)).

For every component whose binary is known at build time (Intel ME, IFD,
FSP-S/M/T, microcode and the payload) sha256sum the blob and pass it to
`goswid add-payload-file --sha256`, which stores it as the CoSWID payload
file hash. Add a license link to the remaining tag templates: an SPDX id
for the open-source components (edk2, iPXE, vboot) and the upstream
license file for the proprietary Intel/Dasharo blobs.

Upstream-Status: Pending
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Identify NovaCustom as the manufacturer of the NUC BOX — the entity that
places the finished product on the market under its trademark, which is
the manufacturer for CRA purposes (Art. 13(15)).

Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Upstream-Status: Pending
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Extend the embedded SBOM to cover firmware components that were missing
or underspecified, reusing the existing per-component pattern
(SBOM_<X> / SBOM_<X>_GENERATE / SBOM_<X>_PATH + CoSWID template +
Makefile rule). The _PATH option lets a vendor supply a full external
SBOM JSON per blob; GENERATE emits a minimal hashed fallback.

New components:
- SBOM_VGA_BIOS / _SECOND / _DGPU: the VGA BIOS OptionROMs
  (VGA_BIOS_FILE and friends). GENERATE records the blob sha256 and the
  target PCI vendor:device ID from VGA_BIOS_ID.
- SBOM_EDK2_GOP: the external Intel GOP driver (EDK2_GOP_FILE) compiled
  into the edk2 payload.
- SBOM_EDK2_LAN_ROM: the external LAN Option ROM driver
  (EDK2_LAN_ROM_DRIVER) compiled into the edk2 payload.
- SBOM_EDK2_PLATFORMS: the edk2-platforms source tree, previously
  absent from the SBOM. Records the commit and tree hash of the
  checkout at payloads/external/edk2/workspace/edk2-platforms.

Intel FSP enrichment:
- Capture the FSP release version, the BIOS build number
  ((NNNN_NN) -> colloquial-version) and the target (Edge/IoT/Client,
  derived from the FD path -> edition), plus the SoC package
  (-> product-family), instead of a single opaque version token.

New CoSWID templates are added under src/sbom/ and the new options are
documented in Documentation/sbom/sbom.md. All new options default to n,
so existing boards' SBOMs are unchanged.

Change tested with 'make sbom' on novacustom_nuc_box: FSP now reports
edition=IoT, product-family=ArrowLake; edk2-platforms and a VGA BIOS
entry (with matching sha256) merge into a valid uSWID when enabled.

Upstream-Status: Pending
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Extract ME/TXE version from the firmware binary. Some versions
store it as an ASCII string like: "ME16.1.40.2765".
When the string is missing, try to extract it from the CSE Main program
(NFTP) partition manifest: the version is 4x2 byte LE fields, 8 bytes after
the $MN2 magic string.
How NFTP is located depends on the image layout:
1. When NEED_IFWI & CONFIG_IFWI_FILE_NAME,
   => located in the IFWI image, extract NFTP from CONFIG_IFWI_FILE_NAME with
      ifwitool
2. CONFIG_SOC_INTEL_CSE_HAVE_SPEC_SUPPORT=y, image has BPDT, ME_SPEC versioned
   => placed at the last non-empty BPDT partition, extract with cse_serger
   1. CONFIG_ME_SPEC >= 15 => version is 1.7
   2. 15 > CONFIG_ME_SPEC >= 12 => version is 1.6
   3. 12 > CONFIG_ME_SPEC => not possible in such case
      CONFIG_SOC_INTEL_CSE_HAVE_SPEC_SUPPORT must be "=n"
3. CONFIG_SOC_INTEL_CSE_HAVE_SPEC_SUPPORT=n
   => ME_SPEC <= 11, no BPDT, use cse_fpt to extract NFTP

Upstream-Status: Pending
Co-authored-by: Michał Żygowski <michal.zygowski@3mdeb.com>
Signed-off-by: Filip Gołaś <filip.golas@3mdeb.com>
Open source deps that would otherwise only have a commit hash
and tree hash will now instead use `<date>_<hash>`
as software-version so that this field is in any way
human readable. It will at least give a general idea
of how old/new a revision is.

coloquial-version is supposed to be used as a string-only
release name that groups multiple versions under common
major version. Using the latest tag of the dependencies
is a valid use and will inform about what upstream
release the components base on. It will be the
most important field for human readers.

Decisions based on the RFC: https://datatracker.ietf.org/doc/rfc9393/

Upstream-Status: Pending
Signed-off-by: Filip Gołaś <filip.golas@3mdeb.com>
…as edition

Extracting FSP image revision from the binary is the only
reliable source of the version number. The Bios version
can only be received from commit messages. The SKU type
can be extracted from a commit message or directory name,
the latter being the more robust method as the commit
messages are not guaranteed to contain anything.

A well known GUID and offests from the spec are used to detect
the FSP info header and extract the version number
components.

Header spec versions >=6 support extended image revisions
and require appending some more bytes to minor and
major version revision parts.

Upstream-Status: Pending
Signed-off-by: Filip Gołaś <filip.golas@3mdeb.com>
…s to them

The two binaries were merged together because all microcode binaries
used the same tag-id hardcoded in the json.
By using goswid to generate the tag-id fields from filename
we get deterministic ids for every ucode binary in a firmare.
It won't change as cpuid doesn't change.

cpuid output, revision and date of the ucode binary are added to
oswid sbom for more details.

Upstream-Status: Pending
Signed-off-by: Filip Gołaś <filip.golas@3mdeb.com>
Pull the SHA hashing and early exit error fix

Upstream-Status: Pending
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Set it to the author of the firmware covered by the SBOM, not the
hardware distributor.

Upstream-Status: Pending
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Guard parsing the revision with the SBOM_EDK2_PLATFORMS_GENERATE config
switch.

Upstream-Status: Pending
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
It now correctly resolves to BIOS_VENDOR, i.e. 3mdeb

Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Upstream-Status: Pending
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
SATA port 1 shares PCH PCIe lane 12 with lane 0 of the M.2 M-key slot.
The lane owner is picked at runtime from SATAPCIE1_DET (GPP_A12 as
SATAXPCIE1); the flash descriptor already has combo port 1 set to
"GPIO Polarity PCIe", so no descriptor change is needed.

Since the lane is not assigned to the SATA controller at reset, the port
must be marked hot-pluggable to be probed once it is. Add
sata_ports_hotplug[1] and sata_salp_support, matching what
hardkernel/odroid-h4 uses for the same PCH lane.

Upstream-Status: Pending
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Upstream-Status: Inappropriate [Dasharo downstream]
Signed-off-by: Filip Lewiński <filip.lewinski@3mdeb.com>
Upstream-Status: Inappropriate (Dasharo automation)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

10 participants