#LinuxBoot

2025-11-14

I managed to get the HEADS firmware to boot my existing fedora install, but only after I reinstalled GRUB2 on that. GRUB2 has nothing to do with the boot process (HEADS uses kexec to directly run a kernel), but apparently HEADS requires its configuration to be present on /boot. Even if I manually set up the kexec_*.txt files on there, it claims that no bootable configuration could be found. Very odd. #linuxboot #firmware

Kevin Karhan :verified:kkarhan@infosec.space
2025-11-12

@OhMyGod @bsi @BNetzA @BMWK @EUCommission @digitalcourage ja, weil under #ARM64-Mobilgeräten kein standarditisierter Hartdwaretree vorliegt und alle #Integratoren und #SoC-Vendoren irgendwelche shice zusammenkoksen!

Ich bin ja für #RightToRepair, #RightToAPI, Verbot.von #Digitalzwang und #Supportpflicht für Hersteller samt Zwangs-#OpenSource-Lizensierung nach #Supportende!

Kevin Karhan :verified:kkarhan@infosec.space
2025-11-12

@OhMyGod Ja, das ist aber seitens #Google so gewollt denn die wollen es zu #iOS enshittifyen mit Zwangs-#Doxxing aller Entwickler!

Wenns nach mir ginge wäre #ARM64-#UEFI (oder besser #LinuxBoot auf allen Plattformen) bei #Smartphones vorgeschrieben um diese #Elektroschrott-Produktion zu stoppen!

#Enshittification

Kevin Karhan :verified:kkarhan@infosec.space
2025-11-11

@adingbatponder yes as in the #remite part of it is offline so no #AMT functionality.

This is called a "#neutered #ManagmentEngine" and "permanently disable" is also an option on commercial #UEFI|s like #ThinkPad.

Kevin Karhan :verified:kkarhan@infosec.space
2025-11-05

@LunaDragofelis @dborch Ja, und ich bin der Ansicht dass dies durch #Standardisierung gefixt werden kann.

#ARM - insbesondere #ARM64 - unterstützt das und es wäre daher trivial entsprechend dies zu verlangen.

Daniel 黄法官 CyReVolt 🐢CyReVolt
2025-10-31

My proposal " for the " was rejected by @nlnet.
Quite unfortunate, but I got a job again anyway, so I don't depend on it and would have had to pass it on.

If anyone is interested in the idea, please do reach out to me though - there is always another chance to apply, plus @sovtechfund and possibly others.

Daniel 黄法官 CyReVolt 🐢CyReVolt
2025-08-25

Het tuig aanpakken!

I just did a full from our graphical menu. :D

youtube.com/watch?v=gpOJrqOjBHI

Daniel 黄法官 CyReVolt 🐢CyReVolt
2025-08-25

I just successfully did a `kexec` on the TP-Link M7350 v3 router via `cpu`, using kexec-tools:

cpu-tpl $KEXEC -cf arch/arm/boot/zImage

I.e., we can now !
Well, we still need to gain NAND flash support and get the kernel to boot without lk2nd directly, but the PoC is done. :)

cpu-tpl is my script wrapping cpu to set up a namespace and use the fixed IP address. $KEXEC is just the full path to my Arm 32 build of kexec.

Daniel 黄法官 CyReVolt 🐢CyReVolt
2025-08-03

If I get any of the grants I applied for, I will do streams again for the . ✨👩‍💻✨

Thus far, I asked:
- NLnet to fund integration with U-Boot XPL
- OSFF to fund further development of ME tooling

The former will be much more work.
And the latter would be integrated in fiedka.app and @coreboot.

Daniel 黄法官 CyReVolt 🐢CyReVolt
2025-07-22

Today, we met with a small group of people working on and . Starting at Hackerbrücke, we went by the Google Arnulfpost campus that is still being worked on, then got some lunch nearby.
realestate.withgoogle.com/arnu

We continued walking around in the sunshine ☀️ and made up some bogus historical non-facts, chatting around and passing by Lenbachhaus where we stopped for a while to enjoy its garden. Finally, we went toward Marienplatz where we split again to get back home. A fun day! 🥳

Kevin Karhan :verified:kkarhan@infosec.space
2025-06-24

@tauon #Microsoft did!

IMHO #USEFI is an irredeemabke #Bloatware and needs to be replaced with #LinuxBoot aka. #NERF!

en.wikipedia.org/wiki/LinuxBoot

nickbeardednickbearded
2025-05-08

Currently debugging : it boots into CLI on TTY1 as intended, but startx errors pop up due to .Xauthority issues, hostname not found, or X server already running.

Switching to TTY2 and running sudo startx works, LXDE starts fine.

Goal: make TTY1 stay clean CLI-only, no automatic X attempts, no startup errors. Working on suppressing X server noise and managing session permissions.

Kevin Karhan :verified:kkarhan@infosec.space
2025-05-07

@wolf480pl @cas I just assume they don't want to have to deal with a gazillion of undocumented SBCs that may only get 1 person to once push code that gets accepted, but then "orphaned" and break over time as they may not be willing to build & test every new kernel before release just to enshure it ain't broken!

It's absolute chaos and one of the reasons I didn't even try to build @OS1337 for the #Pi0W as of today...

Daniel 黄法官 CyReVolt 🐢CyReVolt
2025-05-06

Oh nice, the kexec patches for RISC-V in github.com/horms/kexec-tools have just been merged 2 weeks ago! 🥳

that added support for loading Image files and kexec_file_load

yay !

Daniel 黄法官 CyReVolt 🐢CyReVolt
2025-04-18

Here is one:
book.linuxboot.org/use-cases.h

The book keeps growing. :)

Philip Molloyphilipmolloy
2025-04-03

"Since bootloaders run before operating systems run, they mostly have UEFI-provided services as APIs to rely on. Therefore, bootloaders do not benefit from modern operating system security features"

microsoft.com/en-us/security/b

2025-03-12

Would be cool to see #linuxboot or #coreboot on the @frameworkcomputer #framework12 being worked on when it releases. Wish my eyes didn't haze over when looking at code, otherwise I'd help get it running.

2025-03-03

#dailyreport #gentoo #linux #linuxkernel #linuxboot
#installation #osinstallation #microsoft #wifi
OS Installation Memos.
For Gentoo Linux 🐧:
- wifi/bluetooth adapter trigger loading of binary
firmware blobs from installUSB, it is better to remove
it before installation. Driver may be fully opensource
or requre
firmware analspy. en.wikipedia.org/wiki/Comparis
- Ensure that SSD is supported (NVME) in kernel
- To speedup kernel building disable:
+ Network device support > Ethernet driver support and
Wireless LAN
+ HID - > devices drivers
- Firstly try Legacy BIOS. Don't disable anything in
kernel.

For MS Windows 🪟: configure firewall to block outgoin
and store backups at separate partition.
🤡

2025-02-18

@novacustom

Grateful to NovaCustom for their generous financial contribution and collaboration to integrate Heads firmware into their hardware offerings.

This partnership highlights the growing adoption of Heads as a trusted solution for secure boot verification and tamper detection.

Looking to adapt Heads to your specific needs? Explore our consultation services: osresearch.net/Consultation-Se

Want hardware preflashed with Heads? Check out our trusted vendors: osresearch.net/Vendors/

#OpenSource #FirmwareSecurity #Heads #linuxboot #firmware #cybersecurity #qubesos #linux #security #coreboot

Tommi 🤯 → 39C3tommi@pan.rent
2025-01-17

Done!

Installation was bumpy… The main issue was that I chose btrfs for /boot, which apparently needs ext4 instead.

Now I am getting this error message during boot, does anyone have any idea about how to solve this? (Please tell me I don’t need to reinstall…)

Apart from that everything seems to be working well! I will conclude the configuration tomorrow.

@debian @frameworkcomputer

#Linux #LinuxInstall #Debian #DebianInstall #DebianTrixie #Debian13 #GRUB #LinuxBoot #help #Framework #FrameworkLaptop

Error: “Linux Boot Manager boot failed.”

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst