Skip to content
DnsLister Forum

Where domain hunters compare notes

The “NAND Bootstrapping Terminal” (NBT)

This concept replaces the traditional BIOS ROM with a larger, high-reliability NAND flash chip. This chip contains two distinct, protected partitions:

  1. The Firmware Core (Secure BIOS/UEFI): Responsible for hardware initialization (POST), secure boot verification, and hardware abstraction.
  2. The NBT Environment (Recovery Linux): A highly stripped-down, read-only Linux micro-kernel and initramfs image. Its only function is to provide a command-line interface (CLI) and network stack.

Operational Logic: Upon power-on, the Firmware Core initializes the hardware (CPU, RAM, NVMe drives, Network Interface Card). It then checks the boot drive (e.g., SSD) for a valid OS bootloader.

  • If a valid OS is found: The NBT partition is ignored, and control passes to the main OS bootloader.
  • If NO valid OS is found (Blank PC): The Firmware Core automatically boots the NBT Environment from the NAND.

The NBT User Experience: The user is presented with a clean, minimalist, black terminal screen (tty1). The system automatically acquires an IP address via DHCP and attempts to connect to a pre-configured, secure manifest server.

The Command Set (Examples): The NBT terminal provides a restricted, domain-specific language (DSL) shell.

  • netinfo: Displays the current network configuration (IP, Gateway, DNS).
  • list-distros: Queries the manifest server and displays a secure, verified list of available OS images (e.g., Ubuntu Server, Fedora, Debian, and even a pre-authorized Windows installer stub).
  • install [distro-name] [target-drive] (e.g., install ubuntu-server /dev/nvme0n1): This command is the core of the concept. It triggers a secure process:
    1. Downloads the installer ISO/image directly from the official, verified repository (not a third-party mirror).
    2. Validates the image using GPG signatures (or similar cryptographic verification).
    3. Partitions the target drive.
    4. Streams the installation to the drive.
    5. Installs the bootloader (GRUB).
    6. Reboots the machine into the newly installed OS.

Key Advantages of This Concept:

  • Zero-Day OS Installation: A new PC is functional for OS installation immediately, requiring no other hardware (no USB drive, no other PC to create the USB).
  • Security & Verification: The system only allows installation from a cryptographically signed "white-list" of official OS repositories, preventing malware injection.
  • Simplified Hardware: This design unifies the BIOS and the boot-recovery environment onto one chip, reducing complexity compared to separating them onto different physical chips.

https://i.redd.it/pc357e2imwnh1.jpeg

Source: r/coreboot · by /u/wanderlycan

Leave a Reply

Your email address will not be published. Required fields are marked *