GbE-region MAC randomisation - #2171
Conversation
|
Confused on how ifdtool is built here vs #1195 (which was unclean still, required coreboot's built ifdtool that is needed to build coreboot (see modules/coreboot there) to add Makefile hacks to pack ifdtool as cbmem is packed to be used inside of Heads. ifdtool needs to be built with musl-cross-make to depend on musl's libc; so unclear how building it with coreboot's buildstack produces an actual working ifdtool to be used inside of heads? You tested this pr @FckBigTch ? |
Yes, I've tested several times, and flashed the resulting ROMs on t480s, t480 and x230. Ifdtool is usable inside of heads. Confirmed it's actually musl: Interpreter is /lib/ld-musl-x86_64.so.1 |
- nvmutil from libreboot added as a module - ifdtool from coreboot is included as a part of the Makefile Signed-off-by: Rene <chaotic@disroot.org>
- Ethernet MAC address randomization - menu option is displayed only if $CONFIG_NVMUTIL=y and $CONFIG_IFDTOOL=y are set in the config file - add mac_randomization_options_menu() - to select a completely random mac, an intel pattern or to show the current mac - add show_mac() - add change_mac() - add clean_up_mac(), remove temporary files Signed-off-by: Rene <chaotic@disroot.org>
- add $CONFIG_NVMUTIL - add $CONFIG_IFDTOOL - added only to tested boards: x230, t480, t480s - novacustom v54 and v56, tools are set to no, see linuxboot#1871 (comment) Signed-off-by: Rene <chaotic@disroot.org>
b04ba37 to
931e455
Compare
|
Some notes from deeper review
Will think about that a bit more. If you have ideas let me know @FckBigTch |
The reason I thought the Novacustom models should be excluded is that the config explicitly states: That means it's not possible to generate a random MAC address, right? But I understand that overwriting the GBE region should be avoided during an update. I hadn't even thought of the idea with the dynamic menu. I'll follow your advice and try to implement it. |
Misunderstanding. This means those boards pack a GBE (see coreboot configs) but don't ever flash it per initial flashing instructions or internal flashing. If someone misread initial flashing (which is done by OEM not end users in the case of these boards), then MAC address would become generic as per packed in rom GBE.
|
Also see linuxboot/heads-wiki#209 (needed) |
Follow-up to the PoC in #1195. This PR builds on that work and it is a feature to view and randomize the Ethernet MAC address stored in the GbE region of the flash.
Module
Makefile
initrd/bin/gui-init.sh
GUI
New submenu under the main menu, shown only when both CONFIG_NVMUTIL and CONFIG_IFDTOOL are set to yes for the board:
Tested boards
Known limitation / open question
Fbwhiptail doesn't support conditionally hiding a single menu entry, so gui-init.sh's show_options_menu is currently duplicated (one version with the MAC randomization entry, one without) selected based on whether the board has the feature enabled.
This works, but duplicating a whole menu function to add one conditional entry doesn't scale well if more optional, board-gated features are added later. An alternative I considered: always show the entry, and if CONFIG_NVMUTIL/CONFIG_IFDTOOL are no on that board, show a message like "This feature is not available on your board" instead of duplicating the menu. That avoids the duplication but surfaces a dead-end option to boards that can never use it. What do you think?
If there are anything changes you'd like me to make, just let me know.