Closed jakobjakobson13 closed 11 months ago
On a first glance I believe this is not possible - more or less by design. Measured boot is "measuring" the firmware (HEADS) image and verifies this very firmware image during each boot process. If some outside entity (i.e., the OS via fwup
) would update the firmware image, then for HEADS during the next boot it would look like the firmware has changed. Although in theory it might be possible to update the needed information from within the OS, too. I am not aware of any tooling which does so...
So under the line: sorry, this won't work.
The idea behind fwup and coreboot in case of heads is to drop firmware payload under /boot and have Heads pickup and verify firmware before proposing to flash an upgrade through inner flashrom
Dear developers,
if it's technically possible, could you please distribute heads updates via https://fwupd.org ?
Thanks and bye Jakob