GbE-region MAC randomisation - #2171
Open
FckBigTch wants to merge 3 commits into
Open
Conversation
- nvmutil from libreboot added as a module - ifdtool from coreboot is included as a part of the Makefile Signed-off-by: Rene <chaotic@disroot.org>
- Ethernet MAC address randomization - menu option is displayed only if $CONFIG_NVMUTIL=y and $CONFIG_IFDTOOL=y are set in the config file - add mac_randomization_options_menu() - to select a completely random mac, an intel pattern or to show the current mac - add show_mac() - add change_mac() - add clean_up_mac(), remove temporary files Signed-off-by: Rene <chaotic@disroot.org>
- add $CONFIG_NVMUTIL - add $CONFIG_IFDTOOL - added only to tested boards: x230, t480, t480s - novacustom v54 and v56, tools are set to no, see linuxboot#1871 (comment) Signed-off-by: Rene <chaotic@disroot.org>
This was referenced Jul 29, 2026
tlaurion
requested changes
Jul 29, 2026
|
|
||
| nvmutil_configure := | ||
| nvmutil_target := \ | ||
| $(MAKE_JOS) \ |
Collaborator
There was a problem hiding this comment.
Typo, doesn't parallelise build
Collaborator
|
Confused on how ifdtool is built here vs #1195 (which was unclean still, required coreboot's built ifdtool that is needed to build coreboot (see modules/coreboot there) to add Makefile hacks to pack ifdtool as cbmem is packed to be used inside of Heads. ifdtool needs to be built with musl-cross-make to depend on musl's libc; so unclear how building it with coreboot's buildstack produces an actual working ifdtool to be used inside of heads? You tested this pr @FckBigTch ? |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follow-up to the PoC in #1195. This PR builds on that work and it is a feature to view and randomize the Ethernet MAC address stored in the GbE region of the flash.
Module
Makefile
initrd/bin/gui-init.sh
GUI
New submenu under the main menu, shown only when both CONFIG_NVMUTIL and CONFIG_IFDTOOL are set to yes for the board:
Tested boards
Known limitation / open question
Fbwhiptail doesn't support conditionally hiding a single menu entry, so gui-init.sh's show_options_menu is currently duplicated (one version with the MAC randomization entry, one without) selected based on whether the board has the feature enabled.
This works, but duplicating a whole menu function to add one conditional entry doesn't scale well if more optional, board-gated features are added later. An alternative I considered: always show the entry, and if CONFIG_NVMUTIL/CONFIG_IFDTOOL are no on that board, show a message like "This feature is not available on your board" instead of duplicating the menu. That avoids the duplication but surfaces a dead-end option to boards that can never use it. What do you think?
If there are anything changes you'd like me to make, just let me know.