7 ms·
LVFS – Linux Vendor Firmware Service
- nickexyz 4y agoI actually did not know this existed. Found the project after all the Samsung SSD talk. Unfortunately it doesn't seem like Samsung is uploading that much firmware. "Is uploading firmware on behalf of other vendors" according to the site.
- hughsient 4y agoMake sure you open a support ticket asking for LVFS updates -- it's easy to ignore one person, but much harder to ignore hundreds of people asking for the same thing.
- nickexyz 4y agoThat is a good point, will do! With most things I just complain a bit and then go on with my life, but this actually feels like it could work. Samsung does already release some sort of broken Linux livecd for fw updates, seems like LVFS would be easier for everyone.
- hughsient 4y agoSamsung actually upload firmware to the LVFS on behalf of a few different OEMs, so they certainly know how. It's a policy decision, not a technical or legal one.
- jmclnx 4y agoAs mentioned, I did not know this exists either, but I wonder what they consider a "Major Linux Distro" ? > This site is used by all major Linux distributions to provide metadata for clients such as fwupdmgr and GNOME Software. Based upon that statement and the fact fwupdmgr does not come with Slackware, maybe major equates to GNOME Based ? But with some extra work, looks like this could be useful for non-GNOME distros.
- johnny22 4y agofwupd has nothing to do with gnome. It's a cli program and library. That library can be integrated with guis, but it works standalone.
- hughsient 4y agoIs Slackware a major Linux distribution? There's nothing wrong with Slackware, and no reason why fwupd wouldn't work on that distro -- but it's not one that most people would considered "major" IMHO. There are no GNOME deps on fwupd, although there are a couple of GNOME frontends available -- as there is also a CLI and KDE frontend.
- CameronNemo 4y agoSlackware is the oldest active Linux distribution.
- jonathantf2 4y agoOlder doesn't mean major though.
- CameronNemo 4y agoSubjective. Debatable.
- pxc 4y agoAs someone who has never used Slackware, I think Slackware is important, whether or not it's 'major'.
- bitwize 4y ago"Major" = RHEL, Fedora, Ubuntu, Debian, perhaps also Arch. Slackware is niche, sorry.
- CameronNemo 4y agoNot niche enough, AFAICT https://slackbuilds.org/repository/15.0/system/fwupd/ https://slackbuilds.org/repository/15.0/system/fwupd/
- rmolin88 4y agoI use `fwupd`[0] all of the time. Mandatory: I use arch btw :D [0](https://wiki.archlinux.org/title/fwupd https://wiki.archlinux.org/title/fwupd)
- 2OEH8eoCRo0 4y agoOne of the cool things about Fedora or Arch is we get to see these changes in their infancy before most are aware. This, pipewire, etc. https://fedoraproject.org/wiki/Changes/SystemFirmwareUpdates https://fedoraproject.org/wiki/Changes/SystemFirmwareUpdates
- CameronNemo 4y agoI mean... any distribution is like that, no? Pipewire for example has been in Debian since two releases ago. You would probably not to run it on those releases unless you were building your own up-to-date bug-fixed packages from a custom repo, but that is not out of the question especially with CI/CD being what it is nowadays.
- vetinari 4y agoWas it? > Using as a substitute for PulseAudio/JACK/ALSA > Debian 11 > As per Simon McVittie, "This is not a supported scenario for Debian 11, and is considered experimental." (Debian Wiki, PipeWire) In Fedora, it is default since Fedora 35 (released in 2021/11).
- pxc 4y agoFedora devs often also develop those components and are among the first to integrate them. Fedora seems like a great desktop for those curious about what's coming next to the Linux desktop stack. NixOS doesn't curate a default desktop experience like Fedora does, but it's also a great place to enjoy some of this tech early, and in a very risk-free way thanks to declarative configuration and rollbacks. PipeWire has been effortless to set up (and impressively compatible, performance, and unobtrusive in its own right!) on NixOS for some time now. A rolling release or a cutting edge kind of distro, even with regular releases, can be really nice if you're into exploring this stuff, like you say.
- tcyrus 4y agoI'm trying to make custom firmware archives for hardware that I use, but the docs are a bit confusing in some places.
- zamalek 4y agoThis is honestly a gigantic ad for Dell and Lenovo. Looking at the vendor list substantially changed my opinion on Dell in a matter of minutes.
- booi 4y agoDell has a pretty good record for providing firmware updates without too much hassle. Although it does seem like they ship product with.. a lot of problems. We bought a 10gbit enabled PowerConnect switch only to learn that the “10gbit” part didn’t actually work until they released a new firmware.
- mesebrec 4y agoI just wrote in a different comment that this completely sold me on Dell. I got a Dell laptop from work with Windows on it. Installed Ubuntu and it immediately prompted me to update the firmware. What an amazing experience! I always recommend Dell to people looking for a Linux laptop. Although I hear Lenovo started to get their shit together too in the last few years.
- prmoustache 4y agoI am using both a professional Dell latitude laptop and a personal thinkpad on Fedora and both receive firmware updates. And I am pretty sure I saw the Dell USB-C docking station receiving updates through this too. Not sure this applies also to non Latitude/Thinkpad consumer models though but I tend to never recommend them anyway.
- pxc 4y agoI'm not a huge fan of the kind of laptops Dell sells with Linux on them (thin, poorly ventilated ultraportable donglebooks) or super loyal to the Dell brand or whatever. However, I will say that their Linux laptops I've used have been fine executions of their concepts, and the Linux support, including for firmware updates, has been problem-free even though I don't run the stock OS. They're a good choice for Linux laptops if thin and light ultraportables are your style.
- mixmastamyk 4y agoDon't know much about it yet, and it is undoubtedly is a useful service. However looking at that page boasting telemetry and noticing an always running fwupd process running here as root it looks like this is probably leaking information thru its comm channel. Does anyone know why this is running 24/7? I don't expect my firmware to be changing minute to minute. I need to get OpenSnitch running to keep an eye on these things, heard it was making it into Debian and hopefully derivatives soon.
- hughsient 4y ago> this is probably leaking information thru its comm channel It's really not. The fwupd process doesn't have any internet access at all -- all communication is done through a socket over DBus. All the telemetry is done with the user explicitly opting in -- we even show the JSON in the terminal that is going to be sent. > Does anyone know why this is running 24/7 We auto-quit on idle or for low memory conditions -- unless you have hardware that's expensive (either in terms of power, or time) like thunderbolt and synaptics MST. The resident RSS is tiny as we mmap all the data files which can be paged out by the kernel -- we can even run fwupd on the tiny BMC processor as well. I'd be interested in what OpenSnitch says, but the D-Bus interface is the only way in and out. Interesting, the daemon doesn't actually do any policy actions itself; all actions have to be initiated by the front end -- which includes downloading new firmware metadata.
- mixmastamyk 4y agoGood to know. Why is it a root daemon and not a command/library if other tools are directing it? If I had to guess, so the end user does not have to elevate to superuser to initiate actions?
- hughsient 4y agoYes, mostly that. Depending on local policy, it might be possible to upgrade [only] signed firmware from the correct vendor without authenticating. Downgrade always requires authentication for obvious reasons. Most firmware requires you to be root (some even CAP_SYS_ADMIN) to just enumerate the hardware and read the firmware version. The other main reasons is that some hardware is really, really slow (like 8 seconds to query a dock PD version, or 12 seconds to query a thunderbolt retimer version) and you can't really build a GUI that can do firmware update operations with potentially minutes of delay for each action. Also, cache invalidation is hard if you can't see the device uevents and usb hotplug events.
- mesebrec 4y agoAmazing project! It's incredibly well engineered, imo. It's really nice to read the author's blogposts describing how he forces hardware vendors to get their shit together and either use a standardized update mechanism or create a thoroughly tested open source plugin. I remember the first time I got a Dell laptop and put Ubuntu on it, GNOME Software immediately prompted me to install a firmware update. I was so amazed by this. It really felt like Ubuntu was finally a first-class citizen. I'm still completely sold on Dell because of this experience. Sadly they still don't upload all the firmware for all machines. I have no idea why though..
- hughsient 4y agoblush -- my blog is https://blogs.gnome.org/hughsie/ https://blogs.gnome.org/hughsie/ for the important stuff, and https://mastodon.social/@hughsie https://mastodon.social/@hughsie is for the inane stuff.
- vondur 4y agoFirmware for Dell computers are also offered via the Windows update software. It’s still cool that it works with Linux too.
- bombcar 4y agoSome firmware they may only have reduced redistribution rights to. A modern computer is a giant ball of firmware from many different vendors. Hence things like Linux firmware updaters that just download the windows firmware file (which they have rights to) and extracting the firmware blob (which they know exactly where it is) so they can avoid the question if they can distribute the blob directly.
- josteink 4y agofwupdmgr is amazing. It’s like a package-manager for system firmware. For the devices supported, it feels infinitely better than downloading random files from the various vendor-sites on the internet and running setup wizards and all kinds of bloated inconsistent nonsense. I’d argue fwupdmgr actually represents something objectively done better on Linux than Windows, and my only complaint overall is that not enough vendors are supporting it.
- kieranl 4y agoAs a hardware developer lvfs and fwupd is amazing. It has support for all kinds of standard update protocols. So if you build a product and use a standardized update mechanism, it is super easy to get updates on lvfs. The other thing that is great is the testing and validation groups allows you to setup target groups so you can fully validate your updates internally before staging rollouts. Also @hughsient is really responsive at fixing issues. We use fwupd at Framework Computer.
- phendrenad2 4y agoI just wish this existed for drivers.
- pxc 4y agoLVFS is one of those things that makes modern Linux feel so civilized. Browsing around for images (or God forbid, images distributed as Windows executables) to burn to external media for firmware updates feel downright prehistoric in comparison!
- pabs3 4y agoI wish some more of this firmware was open source with reproducible builds, built using a toolchain that is also open source with reproducible builds. https://wiki.debian.org/Firmware/Open https://wiki.debian.org/Firmware/Open
- pabs3 4y agoSome wikis for firmware updates of things not supported by LVFS: https://wiki.debian.org/Firmware/Updates https://wiki.debian.org/Firmware/Updates https://help.ubuntu.com/community/BIOSUpdate https://help.ubuntu.com/community/BIOSUpdate https://wiki.gentoo.org/wiki/BIOS_Update https://wiki.gentoo.org/wiki/BIOS_Update https://en.opensuse.org/SDB:How_update_your_bios https://en.opensuse.org/SDB:How_update_your_bios https://wiki.archlinux.org/index.php/Flashing_BIOS_from_Linux https://wiki.archlinux.org/index.php/Flashing_BIOS_from_Linu...
- nubinetwork 4y agoI looked into fwupd once... it sounds nice to be able to update through a central service, but then it devolved into a rabbit hole of turning on all the privacy bugs I had previously disabled on my laptop. Why any of that is part of a firmware updater, I don't know.
- hughsient 4y ago> it devolved into a rabbit hole of turning on all the privacy bugs What does that mean? We've got a very comprehensive privacy policy... https://lvfs.readthedocs.io/en/latest/privacy.html https://lvfs.readthedocs.io/en/latest/privacy.html
- nubinetwork 4y agoI mean all of this junk (not my screenshot - my laptop is much worse) https://blogs.gnome.org/hughsie/files/2020/10/Screenshot-from-2020-10-26-12-58-54.png https://blogs.gnome.org/hughsie/files/2020/10/Screenshot-fro...
- hughsient 4y agoYou're going to have to be more specific on why a failing HSI attribute contributes to the undoing of your privacy? You're aware the security attributes are each based on mitigating actual real-world attacks, right?
- nubinetwork 4y agoYou're aware that ME itself is considered a security hole, and that a lot of people disabled it, right? Not to mention, most of the hsi2 and 3 stuff need ME as a dependency? Edit: again, why is this any part of a firmware updater? Edit2: this doesn't even get into unsigned kernels, out of tree modules, and unencrypted swaps (or at least not encrypted in the special way fwupd wants them to be)
- 4y ago