From b70c9d614f131e5b8637a402764fbdfac927943a Mon Sep 17 00:00:00 2001 From: Rick Peters Date: Thu, 24 Sep 2026 10:30:24 +0200 Subject: [PATCH] fix: shellcheck in the bundle, and the docs for the BIOS checks - Rename a variable in lib/bios.sh that clashed with lib/state.sh's array in the bundle. - README, AGENTS.md and CHANGELOG.md for the greyed-out item, the device check and the aligned warning box. --- AGENTS.md | 10 ++++++++++ CHANGELOG.md | 11 ++++++++++- README.md | 11 +++++++---- lib/bios.sh | 6 +++--- 4 files changed, 30 insertions(+), 8 deletions(-) diff --git a/AGENTS.md b/AGENTS.md index be4a747..6676adb 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -135,6 +135,11 @@ gamescope and the Plasma desktop. Primary target: the Valve Steam Machine - `bios` is an *action* (`ACTIONS` in `lib/menu.sh`), not an on/off component: never preselected (not even on a first run), never re-applied by `a`, not listed in the state overview, and `bios_status` is always off. + Only selectable when Valve's version differs from the installed one + (`component_selectable`, greyed out otherwise). Download, SHA-256 and the + fwupd device check (`get-details --json`: no `UpdateError`) come before the + warnings. The warning box uses `█` for its frame: Konsole draws a long + coloured row of `#` narrower, so the right edge wouldn't line up. Keep both confirmations (y/N, then typing `UPDATE`) and the warnings; the firmware comes from the newest `holo-X.Y` repo (`.files` db names the `.cab`, `.db` gives the SHA-256), and fwupd itself refuses non-Fremont @@ -144,6 +149,11 @@ gamescope and the Plasma desktop. Primary target: the Valve Steam Machine ## Checking changes +The bundle puts every module in one file, so shellcheck sees all their +`local` variables together: don't reuse a name another module uses as an +array (e.g. `g` in `lib/state.sh`), or CI's shellcheck on the bundle fails. + + There is no test suite. At minimum: ```bash diff --git a/CHANGELOG.md b/CHANGELOG.md index b159f61..4731128 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -56,12 +56,21 @@ Machine LED driver works on every installed kernel and survives kernel updates. - When a new version is released, the `latest` tag and release move to it (bundle replaced), so the older `.../releases/download/latest/...` URL also always gives the newest version. -- **feat: Opt-in BIOS update for the Steam Machine** +- `2f9b2a5` **feat: Opt-in BIOS update for the Steam Machine** - New menu item (Steam Machine only, never ticked by default) showing the current BIOS version and the newest from Valve's `fremont-hw-support`. - Two large warnings and two confirmations (y/N, then typing `UPDATE`), checksum-verified download, installed with fwupd; the wizard then offers the restart that writes it, with a warning to keep the power on. +- `40c9ee6` **fix: BIOS update only when newer, device check first, aligned warnings** + - The item is greyed out and can't be ticked unless Valve has a newer BIOS. + - Before any warning: SHA-256 of Valve's package, then fwupd confirms the + firmware fits this machine's hardware; otherwise it stops. + - Warning box drawn with a solid red frame whose edges line up, and the + menu's "Now" column aligned. +- **fix: shellcheck in the bundle, and the docs for the BIOS checks** + - A variable name in `lib/bios.sh` clashed with `lib/state.sh` in the bundle + (CI's shellcheck would fail); README, AGENTS.md and this changelog updated. ## 0.6.2 - 2026-09-23 diff --git a/README.md b/README.md index eb1b65c..f444c32 100644 --- a/README.md +++ b/README.md @@ -286,10 +286,13 @@ journalctl --user -b | grep -i led **BIOS updates** (opt-in, never ticked by default). On a Steam Machine the menu has an **Update BIOS** item that shows the current BIOS version and the newest one Valve ships (`F7F0108.cab` in its `fremont-hw-support` package, looked up -on Valve's SteamOS mirror). Ticking it shows a large warning, asks for -confirmation, shows the warning again and only continues when you type -`UPDATE`. It then downloads the package (checksum verified) and hands the -firmware to fwupd; the BIOS is written during the next restart. +on Valve's SteamOS mirror). It can only be ticked when Valve has a newer BIOS +than the one installed; otherwise it's greyed out. Before asking anything it +downloads the package and checks it: the SHA-256 from Valve's repository +proves it's Valve's file, and fwupd confirms the firmware is for this very +machine (it compares the firmware's hardware IDs with the device). Only then +it shows a large warning and asks for confirmation, shows the warning again +and continues when you type `UPDATE`; the BIOS is written during the next restart. **At your own risk:** a failed or interrupted BIOS update can leave the machine unable to start. Keep it on mains power, and never turn off the power, unplug diff --git a/lib/bios.sh b/lib/bios.sh index 99b6fec..0fd8075 100644 --- a/lib/bios.sh +++ b/lib/bios.sh @@ -143,12 +143,12 @@ bios_enable() { fi ok "fwupd confirms BIOS $BIOS_NEWEST is firmware for this machine." - local g="$c_green$c_bold" b="$c_bold" n="$c_reset" + local yes="$c_green$c_bold" b="$c_bold" n="$c_reset" bios_disclaimer "WARNING: BIOS UPDATE - ENTIRELY AT YOUR OWN RISK" \ "Current BIOS: ${b}$current${n}" \ "New BIOS: ${b}$BIOS_NEWEST${n}" \ - "Checksum: ${g}OK${n} (Valve's package)" \ - "Compatible: ${g}yes${n} (checked by fwupd)" + "Checksum: ${yes}OK${n} (Valve's package)" \ + "Compatible: ${yes}yes${n} (checked by fwupd)" if ! ask_yn "Do you understand the risks and want to continue?" n; then info "BIOS update cancelled; nothing was changed."; rm -rf "$tmp"; return 0 fi