corna / me_cleaner

Tool for partial deblobbing of Intel ME/TXE firmware images
GNU General Public License v3.0
4.51k stars 279 forks source link

Once removed, always removed? #330

Open nariox opened 4 years ago

nariox commented 4 years ago

Hello all, I have a question regarding BIOS/ME updates' effect on me_cleaned machines. I have looked at other issues and the FAQ and wasn't able to find this. Sorry if it has been answered before.

While I understand that most BIOSes block the ME region from being written to, during a BIOS upgrade or a ME firmware upgrade these regions, do these regions unlock themselves? If so, would ME be restored after flashing a new BIOS or will it permanently disabled (unless externally flashed with the original dump)?

Stitch626 commented 4 years ago

Depends. You have the option to unlock/lock the ME region with the script. Then it depends. Some bios updates will update/fix the me region while others don't. On Gigabyte's Sandybridge/Ivybridge uefi boards the ME gets usually updated/fixed (while bios based ones don't touch it at all). Other brands even differ within their lineup. ME updates are a bit interesting. But the answer is basically the same. Some Lenovo "own" updates fix the ME region while official Intel ones MAY skip the update due to missing communication with the ME itself.