<component type="console-application">
<id>org.freedesktop.fwupd</id>
<name>fwupd</name>
<summary>Update device firmware on Linux</summary>
<project_license>LGPL-2.0+</project_license>
<developer_name>The fwupd authors</developer_name>
<description>
<p>
This project aims to make updating firmware on Linux automatic, safe and
reliable.
You can either use a GUI software manager like GNOME Software to view and
apply updates, the command-line tool or the D-Bus interface directly.
</p>
<p>
The fwupd process is a system daemon to allow session software to update
device firmware on your local machine.
It is designed for desktops, but this project is also usable on phones,
tablets and on headless servers.
</p>
</description>
<pkgname>fwupd</pkgname>
<url type="homepage">https://fwupd.org/</url>
<url type="bugtracker">https://github.com/fwupd/fwupd/issues</url>
<url type="translate">https://hosted.weblate.org/projects/fwupd/fwupd/</url>
<url type="vcs-browser">https://github.com/fwupd/fwupd</url>
<provides>
<binary>fwupdmgr</binary>
<binary>fwupdtool</binary>
</provides>
<languages>
<lang percentage="95">ar</lang>
<lang percentage="84">bg</lang>
<lang percentage="87">ca</lang>
<lang percentage="97">cs</lang>
<lang percentage="48">da</lang>
<lang percentage="97">de</lang>
<lang percentage="97">en_GB</lang>
<lang percentage="100">en_US</lang>
<lang percentage="97">es</lang>
<lang percentage="59">et</lang>
<lang percentage="96">fi</lang>
<lang percentage="34">fr</lang>
<lang percentage="43">fur</lang>
<lang percentage="42">he</lang>
<lang percentage="78">hi</lang>
<lang percentage="83">hr</lang>
<lang percentage="74">hu</lang>
<lang percentage="97">id</lang>
<lang percentage="67">it</lang>
<lang percentage="91">ja</lang>
<lang percentage="35">ka</lang>
<lang percentage="100">kk</lang>
<lang percentage="75">ko</lang>
<lang percentage="42">lt</lang>
<lang percentage="40">nl</lang>
<lang percentage="97">pl</lang>
<lang percentage="100">pt</lang>
<lang percentage="97">pt_BR</lang>
<lang percentage="97">ro</lang>
<lang percentage="100">ru</lang>
<lang percentage="54">si</lang>
<lang percentage="97">sl</lang>
<lang percentage="91">sq</lang>
<lang percentage="91">sr</lang>
<lang percentage="100">sv</lang>
<lang percentage="47">tr</lang>
<lang percentage="100">uk</lang>
<lang percentage="99">zh_CN</lang>
<lang percentage="56">zh_TW</lang>
</languages>
<releases>
<release type="stable" version="2.1.8" timestamp="1790121600">
<description>
<p>
This release adds the following features:
</p>
<ul>
<li>Add a new plugin to poke bootupd when the ESP changes</li>
<li>Add RSA-3072 signature verification support for Lenovo accessories</li>
</ul>
<p>This release fixes the following bugs:</p>
<ul>
<li>Add a workaround for the systemd-pcrosseparator.service PCR0 extension</li>
<li>Add hashes for the latest DBX for offline machines</li>
<li>Add user aware message to complete the dell-dock update</li>
<li>Allow enumeration BIOS settings to take either string or integer</li>
<li>Allow redfish firmware blobs up to 512MiB</li>
<li>Always use base-16 when parsing the UEFI capsule index</li>
<li>Do not allow a DFU altname or STM32 sector size of zero</li>
<li>Fix a buffer overwrite when parsing Synaptics CAPE HID reports</li>
<li>Fix a dell-dock crash via malformed EC_CMD_GET_DOCK_INFO response</li>
<li>Fix a file descriptor leak when getting firmware details</li>
<li>Fix a memory leak when parsing an invalid TPM eventlog</li>
<li>Fix a NULL deref when enumerating a broken synaptics-rmi device</li>
<li>Fix a snapd error when installing the latest dbx</li>
<li>Fix an integer underflow in Focal FP HID CRC parser</li>
<li>Fix eMMC error recovery command when setting install mode fails</li>
<li>Fix firmware recovery of Logitech Unifying devices</li>
<li>Increase the Huddly USB bulk write timeout to 30s</li>
<li>Invalidate the Wacom descriptor cache when the block count changes</li>
<li>Limit decompressing LZMA streams to 2GiB</li>
<li>Update PCB version checking logic in usi-dock</li>
<li>Use the stricter PolicyKit action ID when the device has gone</li>
<li>Verify the jcat item IDs before using them as filenames</li>
</ul>
<p>This release adds support for the following hardware:</p>
<ul>
<li>ASUS GX5407</li>
<li>Elan PID 0CB6</li>
<li>FocalTech MOC fingerprint sensors</li>
<li>Lenovo ThinkPad Thunderbolt 4 Dock Gen 2 7000</li>
<li>MaxLinear MxL862xx</li>
<li>MediaTek MT9700 FCTE and MT9701 KSMU</li>
<li>Pixart PID 4F01, 4F02, 4F0D and 4F0E</li>
<li>Rolling RW101</li>
</ul>
</description>
</release>
<release type="stable" version="2.1.7" timestamp="1785110400">
<description>
<p>
This release adds the following features:
</p>
<ul>
<li>Add "well known" AppStream IDs for common BIOS settings</li>
<li>Add MTD lock security attribute</li>
<li>Add support for "externally managed" EFI signature lists</li>
<li>Add systemd-pcrlock plugin and hook up to UEFI updates</li>
<li>Add TCG disk encryption security attribute</li>
<li>Enable more plugins when compiling for Android</li>
</ul>
<p>This release fixes the following bugs:</p>
<ul>
<li>Add wrappers for input streams for future Rust implementations</li>
<li>Allow overriding some methods in FwupdClient for a future refactor</li>
<li>Allow plain string versions for some AMD GPUs</li>
<li>Allow suspend-to-ram with encrypted RAM</li>
<li>Always test Dell dock type when connected</li>
<li>Avoid possible out-of-bounds read in when parsing the DFU sector</li>
<li>Do not abort when udisks cannot resolve a device</li>
<li>Do not allow force installs over D-Bus</li>
<li>Do not fail to start when a pre-group comment has no keys set</li>
<li>Fall back to copying the file descriptor contents when not sealed</li>
<li>Fix dropped status updates during updates</li>
<li>Fix FW update for Lenovo TBT5 Smart Dock 7500</li>
<li>Fix fwupd-refresh.service polkit auth errors</li>
<li>Fix segfault parsing some logitech-hidpp bootloader records</li>
<li>Fix the seal self tests when building on a tmpfs</li>
<li>Fix update failure when the TP IC is in bootloader-only mode</li>
<li>Mark Coreboot VBOOT as obsoleting BootGuard verified</li>
<li>Move more per-class limits to the class instances to reduce RSS</li>
<li>Prepare modem-manager firmware after firehose detach</li>
<li>Reject out-of-range CCGX device mode before indexing versions</li>
<li>Require trusted metadata for device updates</li>
<li>Require trusted metadata when using OnlyTrusted</li>
<li>Skip modem-manager secboot status when unsupported</li>
<li>Use safe reads for synaptics-rmi device responses</li>
<li>Validate GUID-defined section offset against EFI section size</li>
</ul>
<p>This release adds support for the following hardware:</p>
<ul>
<li>PixArt PJP360 device</li>
</ul>
</description>
</release>
<release type="stable" version="2.1.6" timestamp="1782864000">
<description>
<p>
This release adds the following features:
</p>
<ul>
<li>Add --filter-protocol to fwupdmgr and fwupdtool</li>
<li>Add a new HSI attribute for coreboot verified boot</li>
<li>Add hashes for the latest DBX for offline machines</li>
<li>Allow parsing Hayden Bridge Thunderbolt firmware</li>
<li>Handle HPE Redfish reset-required updates</li>
<li>Ignore efivar free space on VMWare, GCE and EC2 VMs</li>
<li>Prevent FwupdClient from downloading the same file multiple times</li>
<li>Split UEFI Memory Protection HSI from NX Compat</li>
</ul>
<p>This release fixes the following bugs:</p>
<ul>
<li>Avoid an integer overflow in the ifwi-cpd manifest length check</li>
<li>Avoid truncating the AMD Kria FRU board area offset</li>
<li>Block dbx updates on ASUSTeK GL553VD</li>
<li>Check SMEE hardware bit directly for AMD SME detection</li>
<li>Create the ESP OS directory if not found</li>
<li>Detect the BCR device on Celeron LPC SPI controllers</li>
<li>Fall back to a binary firmware when no specific MTD image type is set</li>
<li>Fix AI table clear behavior of the elantp boot code.</li>
<li>Fix errors with fwupd-refresh service not working properly</li>
<li>Fix Genesys GL32xx device locker crash due to argument mismatch</li>
<li>Fix installing KEK updates when using snapd by sending the correct blob</li>
<li>Fix integer underflow when Elan firmware is smaller than one page</li>
<li>Fix possible NULL pointer dereference when updating SteelSeries firmware</li>
<li>Fix the display of the HP UEFI db certificate</li>
<li>Improved usi-dock progress reporting behavior</li>
<li>Increase the parser item limit from 100 to 1000 for large KEKs</li>
<li>Log out of the Redfish session when required on HPE hardware</li>
<li>Only show 'authenticating' after a short delay</li>
<li>Re-process the device metadata when required after all devices are added</li>
<li>Require sealed memfd input to prevent possible TOCTOU attacks</li>
<li>Sanitize the Jabra GNP device version in a more secure way</li>
<li>Validate raydium-tp buffer size before direct index access</li>
<li>Validate that Lenovo dock device-reported program sizes are valid</li>
</ul>
<p>This release adds support for the following hardware:</p>
<ul>
<li>Lenovo dual-bank accessory dongle and paired peripherals</li>
</ul>
</description>
</release>
<release type="stable" version="2.1.5" timestamp="1780963200">
<description>
<p>
This release adds the following features:
</p>
<ul>
<li>Allow overriding the detected CPU vendor to allow more self tests</li>
<li>Allow updating the Windows-specific UEFI CA on dual boot machines</li>
<li>Install the db updates on broken hardware with new firmware</li>
</ul>
<p>This release fixes the following bugs:</p>
<ul>
<li>Add tests for the vbe, upower, uefi-sbat, pci-bcr, mtd, gpio and msr plugins</li>
<li>Check the array index in some runtime-generated code</li>
<li>Claim the udev netlink backend before old libusb versions</li>
<li>Expand the netlink socket buffer to prevent packet loss during event floods</li>
<li>Fix a msgpack regression when updating some Huddly cameras</li>
<li>Fix HID feature read buffer size in goodix-tp device probe</li>
<li>Fix reproducible builds</li>
<li>Fix the check-reboot-needed command</li>
<li>Increase the i2c-hid re-bind delay for synaptics-rmi PID 0x96e7</li>
<li>Parse the dell-dock marketing name in a more safe way</li>
<li>Set a firmware size limit on intel-gsc aux and oprom firmware types</li>
<li>Simplify the engine by only loading the config object once</li>
<li>Use a cryptographically secure RNG when building the idle and inhibit IDs</li>
<li>Use a more appropriate firmware maximum size for Huddly cameras</li>
</ul>
<p>This release adds support for the following hardware:</p>
<ul>
<li>Elan touchscreens</li>
</ul>
</description>
</release>
</releases>
<content_rating type="oars-1.1">
<content_attribute id="social-info">moderate</content_attribute>
</content_rating>
</component>