bk99.de entertain the web since 1997

Replacing error-prone firmware with Linux

Summary

Ron Minnich and colleagues show how LinuxBoot replaces large UEFI components with an auditable Linux kernel and simple user space tools. LinuxBoot grew out of Google's NERF work. The approach uses Linux as part of the firmware.

Ideas

  • LinuxBoot keeps early hardware initialisation and replaces later UEFI drivers.
  • kexec starts the actual operating system from the firmware Linux.
  • Familiar Linux drivers reduce vendor-specific firmware code.
  • A reproducible user space makes auditing and updating easier.

Insights

  • Firmware benefits from the same development and diagnostic tools as operating systems.
  • Less privileged code reduces the surface for bugs before the actual system starts.
  • Open boot chains make trust in the platform more verifiable.

Recommendations

  • Document every executable stage of the boot chain.
  • Sign firmware artefacts and test recovery after failed updates.

References

Read the original article

Search the Web Archive