News report
coreboot 26.09 Adds Framework Laptop 12 and Advances AMD Turin Support
coreboot 26.09 adds Framework Laptop 12 support, advances AMD Turin and moves firmware builds to C23 while tightening parser validation.
On this page
coreboot 26.09 broadens PC and server platform support
The coreboot project released coreboot 26.09 on October 1 after merging 1,324 commits from 120 authors during the cycle. The release adds support for a range of systems, including the Framework Laptop 12 with 13th Gen Intel Core processors, several older desktop boards, Intel NUC hardware and GIGABYTE's MZ33-AR1 EPYC server motherboard.
For PC users, the Framework Laptop 12 addition is the most recognizable new client platform. It means the board now exists in upstream coreboot's supported mainboard tree; it does not by itself mean every retail Framework Laptop 12 installation automatically switches to coreboot or that replacing factory firmware is risk-free.
| Area | What changed |
|---|---|
| Framework Laptop 12 | 13th Gen Intel Core model added to upstream supported mainboards |
| AMD Turin | PoC support matured and GIGABYTE MZ33-AR1 became the first board on this path |
| Firmware language | coreboot firmware build moved to GNU C23; host tools retain their C11 baseline |
| EFI payloads | Capsule-on-disk support added and enabled for edk2 payloads |
| Input hardening | Additional bounds and consistency validation added for EDID, FDT, BMP, CBFS, FMAP and other parsed data |
AMD Turin bring-up now includes a real EPYC motherboard
The AMD Turin proof-of-concept work progressed beyond early scaffolding in this release. coreboot added CPPC support, interrupt-routing hooks, firmware-table configuration and ACPI descriptions for CXL and MPDMA devices, alongside SEV NVRAM integration work.
GIGABYTE's MZ33-AR1 is the first motherboard added on this Turin path. Its upstream port includes PCIe slot and MCIO topology, onboard-device configuration and BMC BIOS-update packaging. This is meaningful progress for open firmware on current server hardware, but the release notes describe the Turin work as an evolving proof of concept rather than a blanket statement that all EPYC 9005 systems are production-ready with coreboot.
The firmware build moves to C23 while parsers get stricter
coreboot's firmware build now uses the GNU C23 language standard. Mainboard code was updated to use the C23 static_assert keyword, while a temporary attempt to move host tooling to the same baseline was reverted because it broke builds on older Linux distributions. Host tools therefore retain their existing C11 baseline.
The release also puts substantial emphasis on defensive parsing. Changes add stricter checks around EDID buffers and extension blocks, FDT headers, BMP dimensions and offsets, CBFS headers, FMAP regions and TPM2 response sizes. These are hardening changes rather than evidence that a specific exploitable vulnerability affected every coreboot system.
AI-assisted review gets explicit project rules
coreboot also formalized rules for AI-assisted code review. AI-generated Gerrit comments must be marked as such and manually reviewed before posting; automated AI output may not set Code-Review +2 or trigger submission. The policy also prohibits using AI-generated comments to reply to human review comments.
That policy is separate from the firmware features, but it is notable operationally: coreboot is permitting AI assistance while keeping review authority and responsibility with human contributors.
Sources
Primary and technical sources
These sources support the reporting and analysis above. Current stories are updated when later evidence materially changes the facts.
Related
Continue from here
Useful next steps selected from the same technical reference and publication system.
Compatibility & upgrades
ATX vs Micro-ATX vs Mini-ITX Motherboard Sizes
Compare ATX, Micro-ATX, and Mini-ITX motherboard dimensions, mounting and case-fit implications without confusing board size with chipset features or performance.
Tool
DDR Memory Latency Calculator
Convert DDR data rate and CAS latency cycles into CAS timing in nanoseconds.
Technical guide
Windows Page File Explained: Virtual Memory and Commit Limit
Understand what the Windows page file does, how it extends the system commit limit, how paging differs from RAM use, and why crash dumps can depend on it.
Tool
DDR Memory Bandwidth Calculator
Calculate theoretical peak DDR memory bandwidth from transfer rate, bus width per channel, and active channel count.