Heads-threat-model: per-board TPM GPIO reset protection table, NV4x ADL-P CONFIRMED, flash guides - #224
Merged
Merged
Conversation
Thrilleratplay
suggested changes
Jul 27, 2026
Thrilleratplay
left a comment
Contributor
There was a problem hiding this comment.
I feel "read twice" is not enough of a safe guard to ensure a user has a valid backup.
Other than that, looks good to me.
tlaurion
force-pushed
the
doc/tpm-gpio-vuln
branch
2 times, most recently
from
July 29, 2026 21:03
0be854e to
8279fa0
Compare
|
lgtm. looks like a lot of work went into this. |
|
lgtm |
tlaurion
force-pushed
the
doc/tpm-gpio-vuln
branch
2 times, most recently
from
July 31, 2026 02:31
3809638 to
c35a03a
Compare
tlaurion
force-pushed
the
doc/tpm-gpio-vuln
branch
2 times, most recently
from
July 31, 2026 04:20
94585a6 to
77f5026
Compare
tlaurion
marked this pull request as draft
July 31, 2026 04:59
tlaurion
marked this pull request as ready for review
July 31, 2026 04:59
Collaborator
Author
|
@Thrilleratplay @gaspar-ilom last review before merge please, conjointly to linuxboot/heads#2165 |
Thrilleratplay
approved these changes
Jul 31, 2026
Thrilleratplay
left a comment
Contributor
There was a problem hiding this comment.
LGTM. The links add a lot of context to someone not familiar with the ecosystem.
tlaurion
force-pushed
the
doc/tpm-gpio-vuln
branch
2 times, most recently
from
July 31, 2026 20:49
548db45 to
03fe8ea
Compare
…PIO reset vulnerability - Restructure page into H2/H3 hierarchy covering the TPM GPIO reset vulnerability (coreboot bug #576), per-board protection status, threat model, countermeasures and CPU microcode mitigation status - Add per-board table with emoji status markers (✅ Protected, ❌ Not protected, ❌ CONFIRMED vulnerable,⚠️ EOL/ESU) for quick visual scanning; rows sorted alphabetically by board name - Mark NV4x ADL-P and NitroPad NS50 (PCH 0x5182) as CONFIRMED vulnerable: NF1 mode confirmed, PCRs cleared to zero via GPIO PLTRST# assertion on NV4x hardware; NS50 shares the same PCH - Document that TPM DUK with passphrase is not affected on any board Signed-off-by: Thierry Laurion <insurgo@riseup.net>
- Add consistent status headings to every board guide: microcode servicing status (✅ Active /⚠️ EOL), TPM GPIO reset status (✅ PROTECTED / 🛡️ INCONCLUSIVE / 🛡️ VULNERABLE), Safety First, Disassembly and Flashing sections - Standardize backup language: create and verify at least two full-chip backups before any write operation - Use [flasher]/[programmer] placeholders and uniform wording across all guides Signed-off-by: Thierry Laurion <insurgo@riseup.net>
… and tpm-gpio-assert tools - Document the TPM GPIO reset vulnerability (Kukri, 2024) and how the PLTRST# pin can be reprogrammed to GPIO mode on Skylake+ - Add usage for the initrd audit tools: tpm-gpio-detect (non- destructive lock status audit) and tpm-gpio-assert (destructive PLTRST# assertion), with output saved to /media for reporting - Point to the extended tpm-gpio-fail fork for per-platform status Signed-off-by: Thierry Laurion <insurgo@riseup.net>
Signed-off-by: Thierry Laurion <insurgo@riseup.net>
- Fix inconsistent 'Coreboot' capitalization to the project's canonical lowercase 'coreboot' spelling in Community.md, index.md and Prerequisites.md Signed-off-by: Thierry Laurion <insurgo@riseup.net>
tlaurion
force-pushed
the
doc/tpm-gpio-vuln
branch
from
July 31, 2026 20:55
03fe8ea to
46fe46b
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Heads Threat Model -- Per-Board Protection Table
RecoveryShell
SPI Programmer Best Practices
20 Board Flashing Guides