Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
65 changes: 65 additions & 0 deletions docs/variants/asrock_turind8ud/releases.md
Original file line number Diff line number Diff line change
Expand Up @@ -138,3 +138,68 @@ artifact is in CycloneDX format and can be viewed by SBOM tools, for example
[asrock_turind8ud_v0.9.0.sbom.json_file]: https://dl.3mdeb.com/open-source-firmware/Dasharo/asrock_turind8ud/uefi/v0.9.0/asrock_turind8ud_v0.9.0.sbom.json
[asrock_turind8ud_v0.9.0.sbom.json_hash]: https://dl.3mdeb.com/open-source-firmware/Dasharo/asrock_turind8ud/uefi/v0.9.0/asrock_turind8ud_v0.9.0.sbom.json.sha256
[asrock_turind8ud_v0.9.0.sbom.json_sig]: https://dl.3mdeb.com/open-source-firmware/Dasharo/asrock_turind8ud/uefi/v0.9.0/asrock_turind8ud_v0.9.0.sbom.json.sha256.sig

### CRA compliance

CRA compliance status generated with [sbom-tools](https://github.com/sbom-tool/sbom-tools)

#### Phase 2

```text
EU CRA Phase 2 (2027)
COMPLIANT — With warnings
Security ███████████████████████░░░░░░░░░░░░░░░░░ 9 (56.2%)
Integrity ████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 3 (18.8%)
Doc Meta ████████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 3 (18.8%)
License ███░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 1 (6.2%)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

What about Phase 1? What are the issues right now? Where will those be tracked?

```

### fwupd HSI

```text
HSI-1
✔ SMM locked down: Locked
✔ BIOS firmware updates: Enabled
✔ Fused platform: Locked
✔ Supported CPU: Valid
✔ TPM empty PCRs: Valid
✔ TPM v2.0: Found
✔ UEFI bootservice variables: Locked
✔ UEFI platform key: Valid

HSI-2
✔ IOMMU: Enabled
✔ Platform debugging: Locked
✔ TPM PCR0 reconstruction: Valid
✘ Platform secure boot: Disabled
✔ SPI write protection: Enabled

HSI-3
✔ CET Platform: Supported
✔ Suspend-to-ram: Disabled
✘ SPI replay protection: Not supported
✘ Pre-boot DMA protection: Disabled
✘ Suspend-to-idle: Disabled

HSI-4
✔ Processor rollback protection: Enabled
✔ SMAP: Enabled
✘ Encrypted RAM: Not supported

Runtime Suffix -!
✔ fwupd plugins: Untainted
✔ Linux kernel: Untainted
✔ UEFI db: Valid
✘ CET OS Support: Not supported
✘ Linux kernel lockdown: Disabled
✘ Linux swap: Unencrypted
✘ UEFI secure boot: Disabled
```

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

@BeataZdunczyk, you added me to this review, but I think we should discuss this internally:

  • Is that templated so other platforms can automatically benefit and will automatically get this information?
  • Is this the best visualization form we are able to achieve?
  • Are we gathering those statistics automatically or still manually?
  • How and when will we address failures?


#### Failure reasons

- [Platform Secure Boot is currently not implemented in Dasharo firmware.](https://blog.3mdeb.com/2026/2026-07-02-msi_pro_b850p_part6/#platform-secure-boot)
- SPI Replay Protection (RPMC) is unsupported by the board's SPI BIOS chip.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

That motherboard has a socketable SPI chip, AFAIK. Why don't you buy a chip that supports RPMC?

- [Pre-boot DMA protection is currently not supported for AMD platforms in Dasharo firmware.](https://github.com/Dasharo/dasharo-issues/issues/1903)
- Suspend-to-idle isn't supported on server hardware.
- [Encrypted RAM is currently not supported in Dasharo firmware.](https://github.com/Dasharo/dasharo-issues/issues/1920)
63 changes: 63 additions & 0 deletions docs/variants/asrock_turind8ud/releases_linuxboot.md
Original file line number Diff line number Diff line change
Expand Up @@ -120,3 +120,66 @@ artifact is in CycloneDX format and can be viewed by SBOM tools, for example
[asrock_turind8ud_v0.9.0.sbom.json_file]: https://dl.3mdeb.com/open-source-firmware/Dasharo/asrock_turind8ud/linuxboot/v0.9.0/asrock_turind8ud_v0.9.0.sbom.json
[asrock_turind8ud_v0.9.0.sbom.json_hash]: https://dl.3mdeb.com/open-source-firmware/Dasharo/asrock_turind8ud/linuxboot/v0.9.0/asrock_turind8ud_v0.9.0.sbom.json.sha256
[asrock_turind8ud_v0.9.0.sbom.json_sig]: https://dl.3mdeb.com/open-source-firmware/Dasharo/asrock_turind8ud/linuxboot/v0.9.0/asrock_turind8ud_v0.9.0.sbom.json.sha256.sig

### CRA compliance

CRA compliance status generated with [sbom-tools](https://github.com/sbom-tool/sbom-tools)

#### Phase 2

```text
EU CRA Phase 2 (2027)
NON-COMPLIANT — With errors
Integrity ████████████████░░░░░░░░░░░░░░░░░░░░░░░░ 11 (40.7%)
Security █████████████░░░░░░░░░░░░░░░░░░░░░░░░░░░ 9 (33.3%)
Doc Meta ██████░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 4 (14.8%)
Component Identification ███░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 2 (7.4%)
License █░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 1 (3.7%)
```

### fwupd HSI

```text
HSI-1
✔ SMM locked down: Locked
✔ BIOS firmware updates: Enabled
✔ Fused platform: Locked
✔ Supported CPU: Valid
✔ TPM empty PCRs: Valid
✔ TPM v2.0: Found

HSI-2
✔ IOMMU: Enabled
✔ Platform debugging: Locked
✔ TPM PCR0 reconstruction: Valid
✘ Platform secure boot: Disabled
✘ SPI write protection: Disabled

HSI-3
✔ CET Platform: Supported
✔ Suspend-to-ram: Disabled
✘ SPI replay protection: Not supported
✘ Pre-boot DMA protection: Disabled
✘ Suspend-to-idle: Disabled

HSI-4
✔ Processor rollback protection: Enabled
✔ SMAP: Enabled
✘ Encrypted RAM: Not supported

Runtime Suffix -!
✔ fwupd plugins: Untainted
✔ Linux kernel: Untainted
✘ CET OS Support: Not supported
✘ Linux kernel lockdown: Disabled
✘ Linux swap: Unencrypted
```

#### Failure reasons

- [Platform Secure Boot is currently not implemented in Dasharo firmware.](https://blog.3mdeb.com/2026/2026-07-02-msi_pro_b850p_part6/#platform-secure-boot)
- SPI Write Protection cannot be enabled on LinuxBoot.
- SPI Replay Protection (RPMC) is unsupported by the board's SPI BIOS chip.
- [Pre-boot DMA protection is currently not supported for AMD platforms in Dasharo firmware.](https://github.com/Dasharo/dasharo-issues/issues/1903)
- Suspend-to-idle isn't supported on server hardware.
- [Encrypted RAM is currently not supported in Dasharo firmware.](https://github.com/Dasharo/dasharo-issues/issues/1920)
8 changes: 8 additions & 0 deletions docs/variants/overview.md
Original file line number Diff line number Diff line change
Expand Up @@ -144,3 +144,11 @@ Each metric is calculated using the formula:
| Novacustom NS5xMU | novacustom_ns5x_tgl_v1.6.0.rom | NS50_70MU_1.07.14.bin | -29.8 | 43.3 | -18.6 |
| Gigabyte MZ33-AR1 | gigabyte_mz33_ar1_v0.9.0.rom | MZ33-AR1_R21_F14/image.bin | -80.0 | 5301.8 | 227.3 |
| MSI MS-7E56 | msi_ms7e56_v0.9.0.rom | E7E56AMSI.2A92 | -79.1 | 167010300.0 | 377.3 |

## fwupd HSI compliance

The following table shows the HSI levels achieved by each Dasharo release.

| Platform | Dasharo version | Flavor | HSI | Notes |
| --- | --- | --- | --- | --- |
| ASRock Rack TURIND8UD | v0.9.0 | coreboot+UEFI | 1 | [link](../asrock_turind8ud/releases#fwupd-hsi) |
Loading