Fwupd 2.1.7 is the latest maintenance update for the firmware update daemon for Linux. This release introduces several new features and significant improvements, useful for system administrators, developers, and advanced users who need to manage and update the firmware of their devices efficiently and securely.

The new systemd-pcrlock plugin connected to the UEFI firmware update process represents one of the most relevant additions. This improvement is particularly useful for those working with systems that require a high level of security and stability during firmware updates.

Among the other novelties, fwupd 2.1.7 introduces new host security attributes to report the lock status of Memory Technology Device storage devices and TCG-compatible disk encryption activity. These attributes are essential for those who need to monitor and manage the security of their systems in real-time.

The release also includes support for EFI signature lists marked as externally managed, a feature that simplifies the management of security signatures for system administrators.

Another important addition is the introduction of well-known AppStream identifiers for commonly used BIOS settings. This improvement facilitates the identification and consistent presentation of firmware configuration options across hardware from different manufacturers, making the process more intuitive for users.

For Android users, fwupd 2.1.7 enables additional plugins, improving compatibility and functionality on mobile devices.

The release also includes numerous bug fixes, including the resolution of PolicyKit authorization errors affecting fwupd-refresh.service and the correction of a crash that could occur during the parsing of certain Logitech HID++ bootloader records. Additionally, issues with updating when a touchpad controller was only available in bootloader mode have been resolved.

On the security front, significant improvements have been implemented, such as preventing forced installations via D-Bus, rejecting invalid CCGX device modes before accessing firmware version data, securely reading Synaptics RMI device responses, and validating GUID-defined section offsets against EFI section sizes.

Further fixes improve the detection of Dell docks, the preparation of ModemManager firmware after a Firehose detach operation, Verified Boot Coreboot security reporting, temporary filesystem build tests, and memory usage by moving more limits per class into single class instances.

Finally, fwupd 2.1.7 adds support for the PixArt PJP360 device. For more details, you can consult the release notes.

Prerequisites

  • Operating System: Linux distribution compatible with fwupd 2.1.7
  • fwupd: Version 2.1.7
  • systemd: Version compatible with the systemd-pcrlock plugin
  • UEFI: Updated UEFI firmware
  • AppStream: Support for AppStream identifiers
  • PolicyKit: Correct configuration for authorization
  • D-Bus: Support for D-Bus communications

Procedure to Update to fwupd 2.1.7

By the end of this guide, you will have correctly updated your system to fwupd 2.1.7, benefiting from the new features and bug fixes introduced.

  • Update the system before installing fwupd 2.1.7:
    • Open a terminal.
    sudo apt update && sudo apt upgrade
  • Install fwupd 2.1.7:
    • Install the downloaded package. For example, if you have downloaded a .deb file, use:
    sudo dpkg -i fwupd_2.1.7.deb
  • Verify the installation:
    fwupdmgr --version
  • Run a signature update:
    sudo fwupdmgr refresh --force
  • Run a firmware update:
    • Check if there are available firmware updates:
    sudo fwupdmgr get-updates
    sudo fwupdmgr update

Verification and Troubleshooting

By the end of this guide, you will be able to test the correct operation of fwupd 2.1.7 and resolve any issues.

Functionality Testing

  • Version Check: Open a terminal and type the command fwupd --version. Ensure that the displayed version is 2.1.7.
  • Plugin Check: Run fwupdtool get-devices to verify that all supported devices are recognized.
  • Main Functionality Test: Use fwupdtool update to perform a test update and ensure the process completes without errors.

Troubleshooting

  • PolicyKit Authorization Errors: Resolved issues with fwupd-refresh.service.
  • Lenovo TBT5 Smart Dock 7500: Fixed problems with updating when the touchpad controller was only available in bootloader mode.
  • State Notifications: Addressed issues with state notifications.
  • Forced Installations via D-Bus: Prevented forced installations.
  • Invalid CCGX Device Modes: Rejected invalid device modes before accessing firmware version data.
  • Synaptics RMI Device Responses: Securely read device responses.
  • GUID-Defined Section Offsets: Validated offsets against EFI section sizes.

For more details, consult the release notes.

By the end of this guide, you will have a comprehensive overview of the new features introduced by fwupd 2.1.7 and know how to apply this information to best manage firmware updates on Linux systems.

Educational Summary

  • systemd-pcrlock Plugin: Connected to the UEFI firmware update process.
  • New Security Attributes: Reporting the status of Memory Technology Device and TCG-compatible disk encryption.
  • Support for EFI Signature Lists: External management of EFI signatures.
  • AppStream Identifiers: Facilitates the identification of common BIOS settings.
  • Additional Plugins for Android: Improvements specific to Android builds.
  • Bug Fixes: Resolved issues with Lenovo TBT5 Smart Dock 7500, state notifications, PolicyKit authorization errors, and more.
  • Security Improvements: Prevention of forced installations, validation of device modes, secure reading of Synaptics RMI device responses.
  • Hardware Support: Added support for the PixArt PJP360 device.

Call to Action

To delve deeper into the new features and fixes introduced in fwupd 2.1.7, consult the official release notes. Apply the new features and fixes to optimize firmware update management on your Linux systems.

Editorial Note and Disclaimer

The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.

GoYou does not constitute a journalistic publication or an editorial product under Law No. 62/2001 and does not provide real-time information.

The GoYou project does not provide professional, technical, legal, or financial advice and disclaims any liability for the misuse of the information published.

In the Crypto sector, every investment involves risks: readers are invited to always inform themselves independently before making any decisions.