Dell Edge Gateway 5000 to support natively flashing UEFI firmware under Linux
en.community.dell.com
en.community.dell.com
Like the difference between installing the VMWare Toolbox on a Linux guest (which builds and injects proprietary kernel modules written by VMWare), vs. using open-vm-tools, whose modules live in the kernel tree to begin with and are maintained by the kernel devs.
And it seems that this is one of the first actual hardware implementations of said method; the OS-side software implementation has so far only been tested against emulators. It's not that surprising to see bugs here.
Disclaimer: I run a medium sized dedicated server host. Hi.
http://www.dell.com/us/business/p/dell-edge-gateway-5000/pd?...
It's a ruggedized industrial-usage small-ish form factor fanless PC.
Now, having the firmware run a seldomly used code path on resume sounds scary to me: That _must_ be accompanied with some OS-level check (eg hashing) that the firmware didn't touch any memory that it didn't originally reserve.
Luckily Windows is doing that, so Linux can ride the coattail again (as is usual with Intel-originated firmware standards) - except if Windows is guaranteeing some unused memory, because then, some UEFI implementation exploit that, inadvertently breaking things on Linux (yet again).
Indeed not. But if we are going to nitpick, my first question would be what value does being able to flash new firmware from inside Linux achieve compared to what we have today: a OS-agnostic bootable update-medium?
Is this really an improvement? Is it worth it?
Anyway you can already flash the firmware, just without a standard interface: either with the uefi copy thing, or with a proprietary tool.
There's a new CLI tool and dbus api for discovering and installing firmware updates that are securely hosted by redhat. There is also native support in GNOME Software for surfacing the updates and making them available.
This means on a Dell server, you literally type: `fwupdmgr update` and all possible firmware is updated.
So literally every comment in the thread so far is missing the point. This doesn't require shelling in, putting it in the UEFI partition, orchestrating your infrastructure to reboot the servers into the EFI partition to install and then let it reboot back to Linux. You just type `fwupdmgr update`.