It seems kind of pointless to continue the Libreboot project if they're not going to work on any modern hardware for the foreseeable future. Their recommended systems are all old and out of production. Fastest recommended laptop seems to be roughly a Core2Duo at 2.0Ghz.
"Any program in your computer, that someone else is allowed to change but you're not, is an instrument of unjust power over you"
The best security design for software-in-hardware always starts with the software being burned into ROM. Then you can pick from one of two ways to do updates.
The first is the updates are received from the operating system during every boot, so removing power is a reset to factory. So if you throw the system disk in the trash and replace it with a clean one you know you have a clean system. This is in nearly every sense the best way to do it, except that you can't fix a firmware bug that exhibits before the OS boots.
The second is to have some flash memory on the hardware that can be used to install firmware updates, but have a jumper that determines if the system will look there or in ROM during boot. Then if you want clean updated firmware you set the jumper to ROM, boot and install the clean firmware to the flash and then set it back the other way.
The best solution is to support both and then ship the system with the jumper set to ROM. Then you can do 99% of updates automatically through the OS and in the event of a pre-boot firmware bug the affected user can still install the update manually if necessary.
The X200, when run without CPU microcode updates in coreboot,
currently kernel panics if running QEMU with vt-x enabled on 2 cores for the guest.
Oops.For desktops, it simply needs to get into the fast enough territory.
https://libreboot.org/docs/hcl/index.html
So I guess their solution is to hoard 2013-vintage hardware for the rest of all time?