diff --git a/docs/variants/protectli_vp2420/openness-score.md b/docs/variants/protectli_vp2420/openness-score.md new file mode 100644 index 00000000..5c6615e5 --- /dev/null +++ b/docs/variants/protectli_vp2420/openness-score.md @@ -0,0 +1,129 @@ +# Dasharo Openness Score + +This page contains the [Dasharo Openness +Score](../../glossary.md#dasharo-openness-score) for Protectli VP2420 Dasharo +releases. The content of the page is generated with [Dasharo Openness Score +utility](https://github.com/Dasharo/Openness-Score). + +## v1.2.0 + +Openness Score for protectli_vp2420_v1.2.0.rom + +Open-source code percentage: **35.3%** +Closed-source code percentage: **64.7%** + +* Image size: 16777216 (0x1000000) +* Number of regions: 26 +* Number of CBFSes: 3 +* Total open-source code size: 4804606 (0x494ffe) +* Total closed-source code size: 8800924 (0x864a9c) +* Total data size: 627958 (0x994f6) +* Total empty size: 2543728 (0x26d070) + +![](protectli_vp2420_v1.2.0.rom_openness_chart.png) + +![](protectli_vp2420_v1.2.0.rom_openness_chart_full_image.png) + +> Numbers given above already include the calculations from CBFS regions +> presented below + +### FMAP regions + +| FMAP region | Offset | Size | Category | +| ----------- | ------ | ---- | -------- | +| SI_ME | 0x1000 | 0x6ff000 | closed-source | +| SI_DESC | 0x0 | 0x1000 | data | +| RECOVERY_MRC_CACHE | 0x700000 | 0x10000 | data | +| RW_MRC_CACHE | 0x710000 | 0x10000 | data | +| SMMSTORE | 0x720000 | 0x40000 | data | +| SHARED_DATA | 0x760000 | 0x2000 | data | +| VBLOCK_DEV | 0x762000 | 0x2000 | data | +| RW_NVRAM | 0x764000 | 0x6000 | data | +| CONSOLE | 0x76a000 | 0x20000 | data | +| VBLOCK_A | 0x88a000 | 0x2000 | data | +| RW_FWID_A | 0xbfff00 | 0x100 | data | +| RO_VPD | 0xc00000 | 0x4000 | data | +| FMAP | 0xc04000 | 0x800 | data | +| RO_FRID | 0xc04800 | 0x100 | data | +| RO_FRID_PAD | 0xc04900 | 0x700 | data | +| GBB | 0xc05000 | 0x3000 | data | + +### CBFS BOOTSPLASH + +* CBFS size: 1048576 +* Number of files: 1 +* Open-source files size: 0 (0x0) +* Closed-source files size: 0 (0x0) +* Data size: 28 (0x1c) +* Empty size: 1048548 (0xfffe4) + +> Numbers given above are already normalized (i.e. they already include size +> of metadata and possible closed-source LAN drivers included in the payload + > which are not visible in the table below) + +| CBFS filename | CBFS filetype | Size | Compression | Category | +| ------------- | ------------- | ---- | ----------- | -------- | +| (empty) | null | 1048548 | none | empty | + +### CBFS FW_MAIN_A + +* CBFS size: 3620608 +* Number of files: 14 +* Open-source files size: 2364319 (0x24139f) +* Closed-source files size: 732494 (0xb2d4e) +* Data size: 8527 (0x214f) +* Empty size: 515268 (0x7dcc4) + +> Numbers given above are already normalized (i.e. they already include size +> of metadata and possible closed-source LAN drivers included in the payload + > which are not visible in the table below) + +| CBFS filename | CBFS filetype | Size | Compression | Category | +| ------------- | ------------- | ---- | ----------- | -------- | +| fallback/romstage | stage | 85648 | none | open-source | +| fallback/ramstage | stage | 129196 | LZMA | open-source | +| fallback/dsdt.aml | raw | 9759 | none | open-source | +| fallback/postcar | stage | 59620 | none | open-source | +| fallback/payload | simple elf | 2080096 | none | open-source | +| cpu_microcode_blob.bin | microcode | 20480 | none | closed-source | +| fspm.bin | fsp | 495616 | none | closed-source | +| fsps.bin | fsp | 216398 | LZ4 | closed-source | +| config | raw | 4806 | LZMA | data | +| revision | raw | 859 | none | data | +| build_info | raw | 103 | none | data | +| vbt.bin | raw | 1200 | LZMA | data | +| (empty) | null | 740 | none | empty | +| (empty) | null | 514528 | none | empty | + +### CBFS COREBOOT + +* CBFS size: 4161536 +* Number of files: 17 +* Open-source files size: 2440287 (0x253c5f) +* Closed-source files size: 732494 (0xb2d4e) +* Data size: 8843 (0x228b) +* Empty size: 979912 (0xef3c8) + +> Numbers given above are already normalized (i.e. they already include size +> of metadata and possible closed-source LAN drivers included in the payload + > which are not visible in the table below) + +| CBFS filename | CBFS filetype | Size | Compression | Category | +| ------------- | ------------- | ---- | ----------- | -------- | +| fallback/romstage | stage | 85648 | none | open-source | +| fallback/ramstage | stage | 129196 | LZMA | open-source | +| fallback/dsdt.aml | raw | 9759 | none | open-source | +| fallback/postcar | stage | 59620 | none | open-source | +| fallback/payload | simple elf | 2080096 | none | open-source | +| bootblock | bootblock | 75968 | none | open-source | +| cpu_microcode_blob.bin | microcode | 20480 | none | closed-source | +| fspm.bin | fsp | 495616 | none | closed-source | +| fsps.bin | fsp | 216398 | LZ4 | closed-source | +| cbfs_master_header | cbfs header | 28 | none | data | +| intel_fit | intel_fit | 80 | none | data | +| config | raw | 4806 | LZMA | data | +| revision | raw | 859 | none | data | +| build_info | raw | 103 | none | data | +| vbt.bin | raw | 1200 | LZMA | data | +| (empty) | null | 484 | none | empty | +| (empty) | null | 979428 | none | empty | diff --git a/docs/variants/protectli_vp2420/protectli_vp2420_v1.2.0.rom_openness_chart.png b/docs/variants/protectli_vp2420/protectli_vp2420_v1.2.0.rom_openness_chart.png new file mode 100644 index 00000000..75efd3dd Binary files /dev/null and b/docs/variants/protectli_vp2420/protectli_vp2420_v1.2.0.rom_openness_chart.png differ diff --git a/docs/variants/protectli_vp2420/protectli_vp2420_v1.2.0.rom_openness_chart_full_image.png b/docs/variants/protectli_vp2420/protectli_vp2420_v1.2.0.rom_openness_chart_full_image.png new file mode 100644 index 00000000..dd8fe68e Binary files /dev/null and b/docs/variants/protectli_vp2420/protectli_vp2420_v1.2.0.rom_openness_chart_full_image.png differ diff --git a/docs/variants/protectli_vp2420/releases.md b/docs/variants/protectli_vp2420/releases.md index 39f9c408..d9cd4d56 100644 --- a/docs/variants/protectli_vp2420/releases.md +++ b/docs/variants/protectli_vp2420/releases.md @@ -14,6 +14,66 @@ For details about our release process please read Test results for this platform can be found [here](https://docs.google.com/spreadsheets/d/1wI0qBSLdaluayYsm_lIa9iJ9LnPnCOZ9eNOyrKSc-j4/edit#gid=579117128). +## v1.2.0 - 2024-03-14 + +### Added + +- [Setup menu password configuration](https://docs.dasharo.com/dasharo-menu-docs/overview/#dasharo-menu-guides) +- [Serial port console redirection option in setup menu](https://docs.dasharo.com/dasharo-menu-docs/dasharo-system-features/#serial-port-configuration) +- [Customizable Serial Number and UUID via CBFS support](https://github.com/Dasharo/dcu) +- [Customizable boot logo support](https://github.com/Dasharo/dcu) +- [Support for taking screenshots in the firmware](https://docs.dasharo.com/dev-proc/screenshots/#taking-screenshots) +- [ESP partition scanning in look for grubx64.efi or shimx64.efi or Windows bootmgr](https://github.com/Dasharo/dasharo-issues/issues/94) +- Microsoft and Windows 2023 UEFI Secure Boot certificates +- UEFI 2.8 errata C compliance in EDKII fork + +### Changed + +- Rebased to coreboot 4.21 +- Enroll default UEFI Secure Boot keys on the first boot +- [Improved UEFI Secure Boot menu user experience](https://docs.dasharo.com/dasharo-menu-docs/device-manager/#secure-boot-configuration) +- Scope of reset to defaults hotkey to global in firmware setup +- Updated microcode to the newer version; refer to SBOM section below +- Updated ME to the newer version; refer to SBOM section below + +### Fixed + +- [Auto Boot Time-out is reset to 0 when F9 is pressed](https://github.com/Dasharo/dasharo-issues/issues/513) +- [Reset to defaults with F9 causes the wrong settings to be restored](https://github.com/Dasharo/dasharo-issues/issues/355) +- [RTC time and date resetting to the coreboot build date on 29th February](https://review.coreboot.org/c/coreboot/+/80790) + +### Binaries + +[protectli_vp2420_v1.2.0.rom][protectli_vp2420_v1.2.0.rom_file]{.md-button} +[sha256][protectli_vp2420_v1.2.0.rom_hash]{.md-button} +[sha256.sig][protectli_vp2420_v1.2.0.rom_sig]{.md-button} + +[protectli_vp2420_v1.2.0_dev_signed.rom][protectli_vp2420_v1.2.0_dev_signed.rom_file]{.md-button} +[sha256][protectli_vp2420_v1.2.0_dev_signed.rom_hash]{.md-button} +[sha256.sig][protectli_vp2420_v1.2.0_dev_signed.rom_sig]{.md-button} + +To verify binary integrity with hash and signature please follow the +instructions in [Dasharo release signature verification](/guides/signature-verification) +using [this key](https://raw.githubusercontent.com/3mdeb/3mdeb-secpack/master/customer-keys/protectli/release-keys/dasharo-release-1.2.x-for-protectli-signing-key.asc) + +### SBOM (Software Bill of Materials) + +- [Dasharo coreboot fork based on 4.21 revision add9d720](https://github.com/Dasharo/coreboot/tree/add9d720) +- [Dasharo EDKII fork based on edk2-stable202002 revision 2a15268b](https://github.com/Dasharo/edk2/tree/2a15268b) +- [iPXE based on 2023.12 revision 838611b3](https://github.com/Dasharo/ipxe/tree/838611b3) +- [vboot based on 0c11187c75 revision 0c11187c](https://chromium.googlesource.com/chromiumos/platform/vboot_reference/+/0c11187c/) +- [Intel Management Engine based on v15.40.32.2910 revision d0b63476](https://github.com/Dasharo/dasharo-blobs/blob/d0b63476/protectli/vault_ehl/me.bin) +- [Intel Flash Descriptor based on v1.0 revision d0b63476](https://github.com/Dasharo/dasharo-blobs/blob/d0b63476/protectli/vault_ehl/descriptor.bin) +- [Intel Firmware Support Package based on Elkhart Lake MR6 revision 481ea7cf](https://github.com/intel/FSP/tree/481ea7cf/ElkhartLakeFspBinPkg/) +- [Intel microcode based on EHL B1 0x00000016 revision microcode-20230808](https://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/tree/microcode-20230808/intel-ucode/06-96-01) + +[protectli_vp2420_v1.2.0.rom_file]: https://dl.3mdeb.com/open-source-firmware/Dasharo/protectli_vault_ehl/v1.2.0/protectli_vp2420_v1.2.0.rom +[protectli_vp2420_v1.2.0.rom_hash]: https://dl.3mdeb.com/open-source-firmware/Dasharo/protectli_vault_ehl/v1.2.0/protectli_vp2420_v1.2.0.rom.sha256 +[protectli_vp2420_v1.2.0.rom_sig]: https://dl.3mdeb.com/open-source-firmware/Dasharo/protectli_vault_ehl/v1.2.0/protectli_vp2420_v1.2.0.rom.sha256.sig +[protectli_vp2420_v1.2.0_dev_signed.rom_file]: https://dl.3mdeb.com/open-source-firmware/Dasharo/protectli_vault_ehl/v1.2.0/protectli_vp2420_v1.2.0_dev_signed.rom +[protectli_vp2420_v1.2.0_dev_signed.rom_hash]: https://dl.3mdeb.com/open-source-firmware/Dasharo/protectli_vault_ehl/v1.2.0/protectli_vp2420_v1.2.0_dev_signed.rom.sha256 +[protectli_vp2420_v1.2.0_dev_signed.rom_sig]: https://dl.3mdeb.com/open-source-firmware/Dasharo/protectli_vault_ehl/v1.2.0/protectli_vp2420_v1.2.0_dev_signed.rom.sha256.sig + ## v1.1.0 - 2023-04-20 ### Added diff --git a/mkdocs.yml b/mkdocs.yml index cdf3672d..c3878096 100644 --- a/mkdocs.yml +++ b/mkdocs.yml @@ -234,6 +234,7 @@ nav: - 'Recovery': variants/protectli_vp2420/recovery.md - 'Hardware Configuration Matrix': variants/protectli_vp2420/hardware-matrix.md - 'Test matrix': variants/protectli_vp2420/test-matrix.md + - 'Openness score': variants/protectli_vp2420/openness-score.md - 'Protectli VP46xx': - 'Overview': variants/protectli_vp46xx/overview.md - 'Releases': variants/protectli_vp46xx/releases.md