1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
|
<!DOCTYPE html>
<html>
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<style type="text/css">
@import url('../css/main.css');
</style>
<title>ASUS Chromebook C201</title>
</head>
<body>
<div class="section">
<h1 id="pagetop">ASUS Chromebook C201</h1>
<p>
This is a chromebook, using the Rockchip RK3288 SoC. It uses
an ARM CPU, and has free EC firmware (unlike some other laptops).
More RK3288-based laptops will be added to libreboot at a later date.
</p>
<p>
Paul Kocialkowski, a <a href="http://www.replicant.us/">Replicant</a> developer, ported this laptop to libreboot. Thank you, Paul!
</p>
<p>
<b>
NOTE: This board is unsupported in libreboot 20150518.
To use it in libreboot, for now, you must build for it
from source using the libreboot git repository. Note that
we recommend building for it from an x86 host, until
libreboot's build system is modified accordingly.
</b>
</p>
<p>
<b>More info will be added later, including build/installation instructions.
The board is supported in libreboot, however, and has been confirmed to work.</b>
</p>
<p>
Flashing instructions can be found at <a href="../install/index.html#flashrom">../install/index.html#flashrom</a>
</p>
<p>
<a href="index.html">Back to previous index</a>.
</p>
</div>
<div class="section">
<ul>
<li><a href="#thescrew">Flash chip write protection: the screw</a></li>
<li><a href="#googlebastards">Google is bad. We do not endorse them.</a></li>
<li><a href="#os">Replace ChromeOS immediately!</a></li>
<li><a href="#videoblobs">Caution: Video acceleration requires a blob. Do not install it. Use software rendering.</a></li>
<li><a href="#wifiblobs">Caution: WiFi acceleration requires a blob. Do not install it. Use a USB dongle.</a></li>
<li><a href="#ec">EC firmware is free software!</a></li>
<li><a href="#microcode">No microcode!</a></li>
<li><a href="#depthcharge">Depthcharge payload</a></li>
</ul>
</div>
<div class="section">
<h1 id="thescrew">Flash chip write protection: the screw</h1>
<p>
It's next to the flash chip. Unscrew it, and the flash chip is read-write. Screw it back in, and the flash chip is read-only.
It's called the screw.
</p>
<p>
<i>The screw</i> is accessible by removing other screws and gently prying off the upper shell, where the flash chip and the screw
are then directly accessible. User flashing from software is possible, without having to externally re-flash, but the flash chip
is SPI (SOIC-8 form factor) so you can also externally re-flash if you want to. In practise, you only need to externally re-flash
if you brick the laptop; read <a href="../install/bbb_setup.html">../install/bbb_setup.html</a> for an example of how to set up
an SPI programmer.
</p>
<p>
Write protection is useful, because it prevents the firmware from being re-flashed by any malicious software that
might become executed on your GNU/Linux system, as root. In other words, it can prevent a firmware-level <i>evil maid</i> attack. It's
possible to write protect on all current libreboot systems, but chromebooks make it easy. The screw is such a stupidly
simple idea, which all laptop designs should implement.
</p>
</div>
<div class="section">
<h1 id="googlebastards">Google is bad. We do not endorse them.</h1>
<p>
It's merely a coincidence that libreboot can support this hardware, with some issues (see sections below).
While Google does hire a lot of coreboot developers, it's not the case that these laptops can be used
in freedom (libreboot) because Google cares about user freedom. It's just a lucky coincidence. Nothing more.
</p>
<p>
Chromebooks are designed (from the factory) to actually coax the user into using
<a href="https://www.gnu.org/philosophy/who-does-that-server-really-serve.en.html">proprietary web services</a>
(SaaSS) that invade the user's privacy (ChromeOS is literally just the Google Chrome browser when you boot up, itself proprietary
and comes with proprietary add-ons like flash. It's only intended for SaaSS, not actual, real computing).
Google is even a member of the <i>PRISM</i> program, as outlined
by Edward Snowden. See notes about ChromeOS below. The libreboot project recommends
that the user replace the default <i>ChromeOS</i> with a distribution that can be used in freedom,
without invading the user's privacy.
</p>
<p>
We also use a similar argument for the MacBook and the ThinkPads that are supported in libreboot.
Those laptops are supported, in spite of Apple and Lenovo, companies which are actually <i>hostile</i>
to the free software movement.
</p>
<p>
<a href="#pagetop">Back to top of page</a>.
</p>
</div>
<div class="section">
<h1 id="os">Replace ChromeOS immediately!</h1>
<p>
This laptop comes preinstalled (from the factory) with Google ChromeOS. This is a GNU/Linux distribution, but it's not general purpose
and it comes with proprietary software. It's designed for <i><a href="https://www.gnu.org/philosophy/who-does-that-server-really-serve.en.html">SaaSS</a></i>. Libreboot recommends that all users of this laptop replace it with another distribution.
</p>
<h2>No FSF-endorsed distros available</h2>
<p>
The FSF has a <a href="https://www.gnu.org/distros/free-distros.html">list of distributions</a> that are 100% free software. None of these
are confirmed to work on ARM chromebooks yet. Parabola looks hopeful:
<a href="https://www.parabola.nu/news/parabola-supports-armv7/">https://www.parabola.nu/news/parabola-supports-armv7/</a>
</p>
<p>
The libreboot project would like to see all FSF-endorsed distro projects port to these laptops. This includes Trisquel, GuixSD and others.
And ProteanOS. Maybe even LibreCMC. The more the merrier. We need them, badly.
</p>
<h2>What can be done meanwhile?</h2>
<p>
There are some other distributions, which are not freedom-friendly (institutionally speaking), but can be used as such with some tweaking.
</p>
<p>
There isn't much choice, but we can recommend these distributions for the time being:
</p>
<h3>Debian GNU/Linux</h3>
<p>
The FSF briefly details the problems with Debian:
<a href="https://www.gnu.org/distros/common-distros.html#Debian">https://www.gnu.org/distros/common-distros.html#Debian</a>
</p>
<p>
You can actually run Debian without any proprietary software. The default installation comes without any proprietary software,
and although the project does have proprietary software, its only in a separate repository which isn't enabled by default.
The Debian project has a strict policy of keeping proprietary software out of the main repository, and moving it to a separate repository;
this repository is called <i>non-free</i>, with supplementary packages that require it in <i>contrib</i>, also not enabled by default.
If you install Debian and replace the kernel with <a href="http://www.fsfla.org/ikiwiki/selibre/linux-libre/">linux-libre</a>,
you can be reasonably certain not to install any proprietary software. However, make sure to exercise caution, since this isn't
endorsed at all, and mistakes can happen.
</p>
<p>
<b>Note that this does not mean Debian is ok! Far from it! Institutionally, Debian is ethically questionable because it distributes proprietary software,
even if it's optional and not included by default. At the same time, they also do amazing work on things like reproducible builds (recent example),
and it's the underpin design upon which Trisquel is ultimately based. Debian does a lot of good work, so it's a shame that they have this
silly issue, even after several years.</b>
</p>
<p>
The libreboot project calls on Debian, to outsource the hosting and documentation for <i>non-free</i> and <i>contrib</i>
to a separate, third party project (like what Fedora does, as described below).
</p>
<p>
There are linux-libre builds available for Debian, but only on x86 thus far. See:
<a href="https://jxself.org/linux-libre/">https://jxself.org/linux-libre/</a>
</p>
<h3>Fedora GNU/Linux</h3>
<p>
The FSF briefly details the problems with Fedora:
<a href="https://www.gnu.org/distros/common-distros.html#Fedora">https://www.gnu.org/distros/common-distros.html#Fedora</a>
</p>
<p>
Unlike Debian, Fedora (to the best of our knowledge) only distributes proprietary software in the form of firmware blobs for the Linux kernel.
There are repositories for Fedora that contain proprietary software, but none of those are official and have to be added. So just don't add them.
Then, delete <i>linux</i> and replace it with <a href="http://www.fsfla.org/ikiwiki/selibre/linux-libre/">linux-libre</a>.
</p>
<p>
<b>Note that this does not mean Fedora is ok! Far from it! Institutionally, Fedora is ethically questionable because it distributes proprietary software,
even if it's easy to remove.</b>
</p>
<p>
There are linux-libre builds available for Fedora, but only on x86 thus far. See:
<a href="http://www.fsfla.org/ikiwiki/selibre/linux-libre/freed-ora.en.html">http://www.fsfla.org/ikiwiki/selibre/linux-libre/freed-ora.en.html</a>
</p>
<h3>We need libre distributions to be ported.</h3>
<p>
As soon as possible, the libreboot project would like to remove mention of Fedora and Debian, which
we actually feel uncomfortable recommending to users, but saw as an acceptable (and temporary) compromise.
</p>
<p>
In both Debian and Fedora, the browsers available do not try to steer the user away from proprietary browser plugins/add-ons.
For instance, they both use upstream FireFox (Debian merely removes the Mozilla branding and renames it to IceWeasel). Make
sure to check the license of any browser plugins that you install, to ensure that the plugin is free software.
</p>
<p>
There may also be other edge cases like this, so do beware when using those distributions.
</p>
<p>
<a href="#pagetop">Back to top of page</a>.
</p>
</div>
<div class="section">
<h1 id="videoblobs">Caution: Video acceleration requires a blob. Do not install it. Use software rendering.</h1>
<p>
The lima driver source code for the onboard Mali GPU is not released. The developer withheld it for personal reasons.
Until that is released, the only way to use video (in freedom) on this laptop is to not have video acceleration, by
making sure not to install the relevant blob. Most tasks can still be performed without video acceleration, without
any noticeable performance penalty.
</p>
<p>
In practise, this means that certain things like games, blender and GNOME shell (or other fancy desktops) won't work well.
The libreboot project recommends a lightweight desktop which does not need video acceleration, such as <i>LXDE</i>.
</p>
<p>
The lima developer wrote this blog post, which sheds light on the story:
<a href="http://libv.livejournal.com/27461.html">http://libv.livejournal.com/27461.html</a>
</p>
<p>
<a href="#pagetop">Back to top of page</a>.
</p>
</div>
<div class="section">
<h1 id="wifiblobs">Caution: WiFi needs a blob. Do not install it. Use a USB dongle.</h1>
<p>
These laptops have non-removeable (soldered on) WiFi chips, which require non-free firmware in the Linux kernel
in order to work.
</p>
<p>
The libreboot project recommends that you use an external USB wifi dongle that works
with free software. See <a href="index.html#recommended_wifi">index.html#recommended_wifi</a>.
</p>
<p>
There are 2 companies (endorsed by the Free Software Foundation, under their <i>Respects your Freedom</i>
guidelines), that sell USB WiFi dongles guaranteed to work with free software (i.e. linux-libre kernel):
</p>
<ul>
<li><a href="https://www.thinkpenguin.com/gnu-linux/penguin-wireless-n-usb-adapter-gnu-linux-tpe-n150usb">ThinkPenguin sells them</a> (company based in USA)</li>
<li><a href="https://tehnoetic.com/tehnoetic-wireless-adapter-gnu-linux-libre-tet-n150">Tehnoetic sells them</a> (company based in Europe)</li>
</ul>
<p>
These wifi dongles are the Unex DNUA-93F, which uses the AR9271 (atheros) chipset, supported by
the free <i>ath9k_htc</i> driver in the Linux kernel. They work in <i>linux-libre</i> too.
</p>
<h2>Workaround?</h2>
<p>
It's possible on coreboot systems to disable hardware, by modifying the devicetree accordingly.
The devicetree is a part of the coreboot source for any system, that defines which hardware exists in the system.
There are usually other ways too.
</p>
<p>
<b>
TODO for the libreboot project: *disable* the onboard wifi chip (hardcoded in coreboot-libre), by patching coreboot-libre to render
the built-in WiFi unusable. This will lessen the temptation for users to use it.
</b>
</p>
</div>
<div class="section">
<h1 id="ec">EC firmware is free software!</h1>
<p>
It's free software. Google provides the source. Build scripts will be added later, with EC sources
provided in libreboot, and builds of the EC firmware.
</p>
<p>
This is unlike the other current libreboot laptops (Intel based). In practise, you can
(if you do without the video/wifi blobs, and replace ChromeOS with a distribution
that respects your freedom) be more free when using one of these laptops.
</p>
<p>
The libreboot FAQ briefly describes what an <i>EC</i> is:
<a href="http://libreboot.org/faq/#firmware-ec">http://libreboot.org/faq/#firmware-ec</a>
</p>
</div>
<div class="section">
<h1 id="microcode">No microcode!</h1>
<p>
Unlike x86 (e.g. Intel/AMD) CPUs, ARM CPUs do not use microcode, not even built in.
On the Intel/AMD based libreboot systems, there is still microcode in the CPU
(not considered problematic by the FSF, provided that it is reasonably trusted
to not be malicious, since it's part of the hardware and read-only), but we
exclude microcode updates (volatile updates which are uploaded at boot time by the boot firmware,
if present), which are proprietary software.
</p>
<p>
On ARM CPUs, the instruction set is implemented in circuitry, without microcode.
</p>
<p>
<a href="#pagetop">Back to top of page</a>.
</p>
</div>
<div class="section">
<h1 id="depthcharge">Depthcharge payload</h1>
<p>
These systems do not use the GRUB payload. Instead, they use a payload called depthcharge,
which is common on Chromebooks. This is free software, maintained by Google.
</p>
</div>
<div class="section">
<p>
Copyright © 2015 Francis Rowe <info@gluglug.org.uk><br/>
Permission is granted to copy, distribute and/or modify this document
under the terms of the GNU Free Documentation License, Version 1.3
or any later version published by the Free Software Foundation;
with no Invariant Sections, no Front-Cover Texts, and no Back-Cover Texts.
A copy of the license can be found at <a href="../gfdl-1.3.txt">../gfdl-1.3.txt</a>
</p>
<p>
Updated versions of the license (when available) can be found at
<a href="https://www.gnu.org/licenses/licenses.html">https://www.gnu.org/licenses/licenses.html</a>
</p>
<p>
UNLESS OTHERWISE SEPARATELY UNDERTAKEN BY THE LICENSOR, TO THE
EXTENT POSSIBLE, THE LICENSOR OFFERS THE LICENSED MATERIAL AS-IS
AND AS-AVAILABLE, AND MAKES NO REPRESENTATIONS OR WARRANTIES OF
ANY KIND CONCERNING THE LICENSED MATERIAL, WHETHER EXPRESS,
IMPLIED, STATUTORY, OR OTHER. THIS INCLUDES, WITHOUT LIMITATION,
WARRANTIES OF TITLE, MERCHANTABILITY, FITNESS FOR A PARTICULAR
PURPOSE, NON-INFRINGEMENT, ABSENCE OF LATENT OR OTHER DEFECTS,
ACCURACY, OR THE PRESENCE OR ABSENCE OF ERRORS, WHETHER OR NOT
KNOWN OR DISCOVERABLE. WHERE DISCLAIMERS OF WARRANTIES ARE NOT
ALLOWED IN FULL OR IN PART, THIS DISCLAIMER MAY NOT APPLY TO YOU.
</p>
<p>
TO THE EXTENT POSSIBLE, IN NO EVENT WILL THE LICENSOR BE LIABLE
TO YOU ON ANY LEGAL THEORY (INCLUDING, WITHOUT LIMITATION,
NEGLIGENCE) OR OTHERWISE FOR ANY DIRECT, SPECIAL, INDIRECT,
INCIDENTAL, CONSEQUENTIAL, PUNITIVE, EXEMPLARY, OR OTHER LOSSES,
COSTS, EXPENSES, OR DAMAGES ARISING OUT OF THIS PUBLIC LICENSE OR
USE OF THE LICENSED MATERIAL, EVEN IF THE LICENSOR HAS BEEN
ADVISED OF THE POSSIBILITY OF SUCH LOSSES, COSTS, EXPENSES, OR
DAMAGES. WHERE A LIMITATION OF LIABILITY IS NOT ALLOWED IN FULL OR
IN PART, THIS LIMITATION MAY NOT APPLY TO YOU.
</p>
<p>
The disclaimer of warranties and limitation of liability provided
above shall be interpreted in a manner that, to the extent
possible, most closely approximates an absolute disclaimer and
waiver of all liability.
</p>
</div>
</body>
</html>
|