PureBoot is Purism’s solution for high security boot firmware that gives you complete control.

While we design PureBoot’s defaults to meet most people’s needs, you can also create your own version with custom features, pre-approved USB keys, and all with little risk to your Librem 14 laptop.

Of course, you can always flash your custom PureBoot using the built-in menu, but with development comes bugs, and flashing via the menu may not be an option if your custom build has an issue. Fortunately, you can recover from bugs that stop the boot firmware from loading on your Librem 14 by hardware flashing the BIOS with a chip flasher.

Hardware Flashing PureBoot

Keep in mind this process will delete your onboard serial number; however, you can use a tool like cbfstool to inject it into your PureBoot rom.

To get going, you’ll need:

  • CH341A spi chip programmer (Supplying 3.3v)
  • SOIC8 clip (Often sold together with the programmer.)
  • Screwdriver (To open the Librem 14)
  • Separate PureOS or Debian computer (As your Librem 14 will be offline for the upgrade)

Remove any external power.

Unscrew and remove the backplate.Unplug the battery from the motherboard.Assemble a CH341a programmer. Attach your chip clip, making sure to line up pin 1 with the red stripe.Locate your BIOS flash chip U49, between the CPU and the nearest fan.Locate the depression on the BIOS chip; this indicates where pin 1 is.Attach the chip clip making sure to align the red stripe again.Attach to the programmer to a PureOS computer, like a laptop or even Librem 5. If you have not done so already, Download or build your PureBoot rom.

From the terminal, install flashrom.

sudo apt install flashrom

You can also use your Librem 5 as your second computer to flash your laptop. If you’re flashing from a Librem 5, build flashrom using these commands:

sudo apt install git make gcc libusb-1.0-0-dev libudev-dev
git clone https://github.com/flashrom/flashrom.git
cd flashrom/
make
sudo make install

This command will check everything is connected correctly.
sudo flashrom -p ch341a_spi

Flashrom may detect two possible chips; if so add -c <chip> to all the remaining commands, pointing at the first chip found.To begin the flash, run this command, pointing at the file PureBoot rom file

sudo flashrom -p ch341a_spi -w /home/purism/Downloads/pureboot-librem_14-Release-23.rom -c GD25B128B/GD25Q128B

Make sure to replace GD25B128B/GD25Q128B with your chip ID.

This will take several minutes to complete.After a successful flash, unplug the chip programmer.

Once unplugged from the computer, remove the clip from the chip.

To boot your Librem 14, attach the battery and screw the backplate back on.

Summery

It’s always good to have multiple options to get yourself out of a jam, and this hardware method for flashing PureBoot is an excellent tool for anyone wanting to tinker with or improve their BIOS.

Purism Products and Availability Chart

 ModelStatusLead Time 
Most Secure PC Purism Librem Mini
Librem MiniIn Stock10 days
Most Secure Server Purism Librem ServersLibrem ServersOut of Stock--
USB Security Token Purism Librem KeyLibrem KeyIn Stock10 days
Most Secure Laptop Purism Librem 14Librem 14In Stock10 days
Made in USA Phone Purism Librem 5 USALibrem 5 USAIn Stock10 days
Librem 5Currently shipping backlogs52 weeks
The current product and shipping chart of Purism Librem products, updated on September 2, 2022

Recent Posts

Related Content

Tags