Announcement

Collapse
No announcement yet.

Help Disabling Flash Protection Range Registers on Lenovo P360 Tiny BIOS

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Help Disabling Flash Protection Range Registers on Lenovo P360 Tiny BIOS

    Hey guys,

    Hope you all are doing well. I come here from Win-Raid because I am having issues disabling Flash Protection Range Registers so I can flash my BIOS from within Windows using Intel's IFW tool/using flashrom within Linux, however I cannot due to the above mentioned error.

    Here is my thread on Win-Raid detailing the whole process I went through: https://winraid.level1techs.com/t/re...h-gen/95478/27

    Essentially I managed to boot into Windows while shorting PINs 1+5 of my audio chip to disable the HAP bit so that flash descriptors are unlocked until reboot, and then flashed a modified flash descriptor with the HAP bit disabled so that it will persist over reboot and disable Intel Management Engine.

    I thought that this would also enable write access for the BIOS region of my SPI, however it did not. After some heavy research, I found out that my BIOS has a Flash Protection Range Register option (hidden from the menu) so I booted into a UEFI shell and Disabled that option as well as the BIOS lock using datasone's setup_var.efi package here: https://github.com/datasone/setup_var.efi.

    However it does not persist after a reboot. I noticed that whenever I modify the BIOS lock or even just the FPRR option and reboot, I get to the Lenovo BIOS screen and the screen goes black then reboots again, where it again goes to the Lenovo BIOS screen and ultimately will continue booting the OS. It seems like when this BIOS screen goes black and reboots, the modified setup_var's get reset to default.

    Can anyone here assist me in disabling this Flash Protection Range Register setup_var? My chip is an XMC WSON8 chip and I would rather not have to desolder it from the board just to read/write to it if at all possible, I would like to keep this completely software-based.

    I know its possible as the option is there in the BIOS, I just can't figure out why the OS won't boot if those options are modified and the BIOS will ultimately reset the values on its own. I do have Secure Boot disabled.

    May I post my BIOS here for assistance? If so, would you need a full SPI dump (including DESC, ME, GbE, etc regions) or just the BIOS region?

    Thanks in advance for any assistance!
    Last edited by abhorsen; 07-06-2023, 10:34 AM.

    #2
    Re: Help Disabling Flash Protection Range Registers on Lenovo P360 Tiny BIOS

    Anyone that has any input on this or can help?

    Comment


      #3
      Re: Help Disabling Flash Protection Range Registers on Lenovo P360 Tiny BIOS

      Bump on this again? Really struggling to flash a BIOS to my chip; Tried using AMI's flash utilities as an alternative and got the below error:

      127 - Error: Failed to load image into memory.
      BIOS Guard is enabled, This feature may not be supported.

      Any input from anyone at all would be very much appreciated.

      Comment

      Working...
      X