Live data from Hacker News

Fedora considers deprecating legacy BIOS

lwn.net

221–230 of 233 posts

Re: Fedora considers deprecating legacy BIOS

#221
post #217

Earlier quoted context omitted.

And its something you want to do for security reasons anyway, since linux by default isn't encrypting swap partitions. Putting swap on an LUKs encrypted partition is a bit of a PITA but allows one to hibernate/resume without fear that ones private keys end up in plaintext stored on a disk.

And relevant to OP, you cannot hibernate on Linux with secure boot enabled, I think precisely because Linux doesn't know how to sign/encrypt the RAM dump (no idea how it's actually called)

Well, its an artificial limitation on secure boot in the Linux kernel pending some cleaups, and is fairly trivial to work around if your willing to comment out the line in question build your own kernel and sign it with a key of your own creation you have enrolled in the firmware.

The problem is less about linux being capable of encrypting/protecting the swap file and more around being able to assure that is true. So like many Linux kernel issues recently its less technical, more political.

So, as I mentioned previously its entirely possible with off the shelf distro's to enable encrypted swap, the average user just has to choose between hibernate, assuring the swap is secure, and secure boot. Its a bit irritating, but seems to be low priority as the focus seems to be on suspend or hibernate without secure boot.

Re: Fedora considers deprecating legacy BIOS

#222

This is a bit of a tone deaf idea to explore right now. If anything, the environment and chip shortage issues should be pushing people to promise extending support for older systems for another decade. That said, while there are loads of systems out there that could still use BIOS, I like to look at the second hand market. There are a lot of Dell R710s for sale on eBay still (700+ listings). These are commonly sugges…

Side note: Red Hat disabled the kernel code for the Perc 6/I raid card which is standard in the basic R710 chassis starting with RHEL8.

Unless you have the higher end H710 raid controller or whatever else, Red Hat rendered this chassis controller inoperable with their custom in-house kernel patching process.

Re: Fedora considers deprecating legacy BIOS

#223
post #4

> UEFI is defined by a versioned standard that can be tested and certified against. By contrast, every legacy BIOS is unique. The "standard" for BIOSes was at first the IBM PC ROS's Reference Manual, and later the PS/2 Reference. Naturally, many vendors failed to implement it correctly. But the problem with EFI is the same. Still hoping that someday, EFI netboot support will be something usable. I once considered usi…

> - EFI system partition is the FAT file system, which is an FS that is even older than the legacy BIOS. Many gory details. Legacy from Microsoft.

I've always wondered why it was required that my EFI partition be FAT. I've had systems where that partition has gotten messed up and required an fsck from a recovery boot, and it seemed like it should be possible to either do that automatically in some way, but being able to use a filesystem that self-corrects would be nice too (although maybe overkill for the 1 GB or whatever I give it). I guess maybe it would only be possible to perform the fsck if I booted from a different partition, which then could develop the same issue. This does make me wonder how silly it would be to have a duplicate boot partition on each of my machines that I only mount to sync over changes to the real one so I could avoid needing to grab my flash drive when stuff like this happens...

Re: Fedora considers deprecating legacy BIOS

#224
post #72

Earlier quoted context omitted.

Seems there are two such projects for that: https://github.com/stefanberger/swtpm http://sourceforge.net/projects/ibmtpm20tss/

I mean "in a way that would allow you to boot Windows on top of it".

Perhaps via a virtual machine?

Re: Fedora considers deprecating legacy BIOS

#225

According to Wikipedia, Intel’s 945 chipset for Core 2 processors ships with UEFI. This was originally released in 2006. Note that Google Chrome which is the web browser with the highest adoption rate requires a CPU with SSE3 support which was introduced in 2004. Which platform older than a Core 2 can even run the latest operating systems? The very latest Pentium 4 range (2004-2006)? So we would just be dropping supp…

OpenBSD 7.1 was just released and supports my G5 Mac. It also supports i386, UltraSparc, and Digital Alpha. NetBSD supports i386, Alpha, Amiga, 32-bit Sparc, 32-bit MIPS, ARMv6, StrongARM, sun2, sun3... LinuxMint still supports i686. Debian supports i386, i686, armel, armhf, s390, and MIPS. Slackware supports i586 and s390. Kali supports i686. Void Linux supports i686, ARMv6, ARV7. FreeBSD supports arm, armel, i386,…

According to discussions on the Gentoo [1] and Fedora [2] forums, i686 without SSE2 could be broken in some packages in subtle ways. One is that the stack alignment changed from 4 bytes to 16 bytes, another is long NOPs, another is that some software seems to require SSE2 on i686 like rustc or qt.

Even those platforms that claim to build for i686, I’m not sure if everything works correctly on pre-SSE2 (Pentium Pro, Pentium III, older Pentium 4) CPUs. And I don’t think any of the Linux distributions will actually run on a i386, i486 or i586 as i686 is almost required to have multithreading without busy waits.

The BSDs I don’t know about, but it’s a fair number of distributions that seem to support older x86 CPUs you posted. I didn’t know there would be so many. I couldn’t find Linux Mint though.

[1]: https://forums.gentoo.org/viewtopic-t-1087434.html?sid=4b682... [2]: https://lists.fedoraproject.org/archives/list/devel@lists.fe...

Re: Fedora considers deprecating legacy BIOS

#226
post #188

Earlier quoted context omitted.

>Perhaps you are thinking of Secure Boot. Nope. I think there must be a miscommunication here so I'll be more explicit. If you have CSM/BIOS mode on your UEFI default motherboard and you set it to CMB/BIOS mode of course you can run BIOS based video cards. But if you switch your mobo to UEFI boot (say, because you want to run future Fedora, or maybe boot off an nvme storage device) you can't use your BIOS firmware vi…

A lot of firmware supports using CSM to do GPU init and then providing UEFI interfaces on top of that. Of course, this is incompatible with Secure Boot.

In fact, you can't really run any other legacy option ROMs without legacy VGA support. You can run legacy SAS option ROMs for example and still do UEFI boot because of similar support for Int13, but to even run them require VGA text mode to be working.

Re: Fedora considers deprecating legacy BIOS

#228
post #32

UEFI emulation is a thing. For people with legacy-only firmware systems, you too can run UEFI on lazy cloud providers and legacy hardware. I do this on my 14 year old dell laptop just so that all my x86_64 systems have the same boot efistub linux kernel images. All you need is to use one of the EDK DUET bootloader builds such as BootDuet¹, or for an easier user experience CloverBootloader². Only complaint is securebo…

Interesting... I'll check if it can emulate 64 bits UEFI on a 32 bits one (yet 64 bits cpu): Finding anything to boot on my old tablet PC is becoming a pain.

GRUB does this relatively easily (without needing emulation) as I too have done it before on an old tablet. I am not sure what OS you are using but it should work fine for Linux and Windows although only the prior is easy and just works. On Debian and it's derivatives you just need the grub-efi-ia32 package, and then regular GRUB install process and 64bit loads fine without anything special.

Re: Fedora considers deprecating legacy BIOS

#229
post #228

Earlier quoted context omitted.

Interesting... I'll check if it can emulate 64 bits UEFI on a 32 bits one (yet 64 bits cpu): Finding anything to boot on my old tablet PC is becoming a pain.

GRUB does this relatively easily (without needing emulation) as I too have done it before on an old tablet. I am not sure what OS you are using but it should work fine for Linux and Windows although only the prior is easy and just works. On Debian and it's derivatives you just need the grub-efi-ia32 package, and then regular GRUB install process and 64bit loads fine without anything special.

The problem is less booting the OS once installed, but finding an iso I don't have to mess with too much to install it. Most of them assume 64 bits CPU means 64 bits UEFI...

Re: Fedora considers deprecating legacy BIOS

#230
post #218

Earlier quoted context omitted.

I tired using celluloid which is a gnome wrapper around mpv, but it stopped working. Running it on the command line, I'm prompted with an exception and admonished that wayland support is 'experimental' and known to be unstable.

I use celluloid on Wayland. Never crashed. It'd be helpful to know what distro you are using. Fedora has the best Wayland experience of them all, others not so much. You wouldn't have a nice Wayland experience on Ubuntu 20.04 LTS for example.

>You wouldn't have a nice Wayland experience on Ubuntu 20.04 LTS for example.

That's a bingo! :^(

Looking to move to an arch flavor, but need to figure out how to backup ~ 500GB of stuff I don't want to lose.

Post reply on HN