/* * SysDeck - Firmware Panel * Author: Jeremy Anderson (https://dcos.net) * * Uses fwupdmgr to enumerate firmware devices and tpm2_pcrread to dump * the first PCR register (boot chain proof). Both calls fail closed * with informative cards when the underlying tools are absent. * * v0.1.4 SECURITY: fwupd device metadata (Name/Vendor/Version/Flags) * comes from the device itself — a malicious peripheral controls those * strings. All interpolations are now escaped (0.3.0 audit); the * escapeHtml map is the full 5-char one the newer panels use. */ export async function mount(panel, { bridge, EventBus }) { panel.innerHTML = renderSkeleton(); const [devices, tpmPcr0] = await Promise.allSettled([ bridge.firmware.devices(), bridge.firmware.tpmInfo(), ]); const deviceList = devices.value?.Devices ?? []; panel.innerHTML = `

Firmware Control

fwupd + TPM 2.0

fwupd Devices (${deviceList.length})

${deviceList.map((d) => ` `).join('') || ''}
NameVendorVersionFlags
${escapeHtml(d.Name)} ${escapeHtml(d.Vendor ?? '—')} ${escapeHtml(d.Version ?? '—')} ${escapeHtml((d.Flags ?? []).join(', ') || '—')}
No fwupd devices.

TPM 2.0 — PCR 0 (SHA256)

${escapeHtml(tpmPcr0.value ?? 'tpm2-tools not installed')}
`; EventBus.emit('firmware.loaded', { deviceCount: deviceList.length }); } function escapeHtml(s) { return String(s == null ? '' : s) .replace(/&/g, '&') .replace(//g, '>') .replace(/"/g, '"') .replace(/'/g, '''); } function renderSkeleton() { return `
`; }