Open nathandyer opened 3 months ago
Seconded on the HCL - ISTR it was discussed and we were kindof leaning towards:
Thanks both for the review and discussion! I'll table this for now and we can return to it again when the timing is right.
I just learned via @deeplow that Qubes how has fwupd integration - https://github.com/freedomofpress/securedrop-workstation/issues/1125; is that stable enough for us to recommend via docs until we build it into the updater? Otherwise I think the steps you added are fine.
If we're recommending fwupd anyways, we might as well use the integrated one, especially in the installation phase, where it's an admin fully dedicated to the thing and not a regular user just wanting to get work done. I don't think it matters much if we do the firmware update prior to the Qubes install or after.
1x Qubes-certified recco (most likely the Novacustom NV41 (coreboot/heads still undecided) 1x "mainstream" recco (most likely a Lenovo T-series known to work well with 4.2) only as a 3rd option would we mention the HCL, with limited support implications.
I think these are reasonable recommendations. However, for the novacustom one we may want to to provide some guidance. For example, some may see a 32gb dimm and choose it, where the proper choice would be 2*16GB, and then the firmware part may have too many options. In my opinion guidance here will be critical to avoid some avoidable situations.
This PR overhauls the hardware guide by making a few key changes:
fwupd
on supported systems, and to their manufacturers instructions for instances where fwupd is not supported.Fixes
Fixes #211 Fixes #210 Fixes #69
Testing