[Problem] Lenovo ThinkBook 16p G5 IRX: SPI Image Creation

Hi everyone,

I’m currently working on a Lenovo ThinkBook 16p G5 IRX and I’m trying to rebuild a proper full SPI image, but I’m running into multiple issues.

:pushpin: Situation

  • I dumped my chips using a programmer:

    • 8MB chip → supposed ME region

    • 16MB chip → BIOS region

  • However:

    • My 8MB dump does NOT contain Descriptor + ME properly

    • It behaves like a partial/non-SPI image

  • When I flash:

    • :cross_mark: With current dump → fans stop spinning

    • :cross_mark: With modified BIOS → no display

    • :warning: With proper ME/FD → fans spin but still no POST

:open_file_folder: What I Have

  • Original Lenovo BIOS: WinP5CNxxWW.fd

  • Extracted regions using BIOSUtilities

  • My programmer dumps (8MB + 16MB)

:warning: Problems

  1. My dumps seem incomplete (no valid descriptor / ME in 8MB)

  2. BIOS .fd only contains BIOS region (no full SPI)

Unsure how to:

  • Properly rebuild full SPI (Descriptor + ME + BIOS)

  • Match ME config to motherboard

  • Fix boot (fan behavior vs no display)

:wrench: What I Tried

  • Extracting with:

    • BIOSUtilities

    • UEFITool

    • H2OFFT dump (-g)

  • Using FIT (CSME 16.x)

  • Flashing full chip via CH347

:red_question_mark: Questions

  1. How can I rebuild a complete SPI image correctly for this model?

  2. Where can I get:

    • Valid Descriptor

    • Correct ME configuration (FIT-ready)

  3. Why would an 8MB dump not contain FD + ME?

  4. Is this model using:

    • Split SPI layout?

    • Hidden/locked descriptor?

  5. Best method to:

    • Restore boot (fans + display)?

:brain: Goal

Create a clean, bootable full SPI image that:

  • Matches motherboard config

  • Includes proper FD + ME + BIOS

  • Boots normally (display + fans)


If anyone experienced with Insyde / Lenovo / Raptor Lake SPI layouts can guide me, I’d really appreciate it.

:paperclip: Attachments

(I will upload)

  • 8MB dump

  • 16MB dump

  • Original .fd

  • Extracted regions


Edit by Fernando: Thread title shortened

Hi, just make sure you make a good/proper backup of both your 8MB and 16MB chips.

I will assist you once you attach them.

Hi, thanks for helping.

For the backup, I used a CH341A programmer with a SOIC8 clip directly on the board (in-circuit).
Both chips (8MB and 16MB) were detected properly.

Steps I did:

  • Connected the clip to each chip

  • Detected the chip in the programmer software

  • Read the contents

  • Saved the dump files

I also made sure to read multiple times and compared the dumps to confirm they are consistent.

BACKUP FOLDER.rar (9.5 MB)

Your files are ready. Do you want me to send you the already DMI-filled version, or do you know how to fill them correctly yourself?

dmi filled ready sir..

These should work 100%

8MB(CSME).rar (1.9 MB)

16MB(DMI).rar (5.5 MB)

I’ve already tried the files you sent, but it’s still not working. They are the same as what I already have.

I just want to share what happened before my laptop stopped working.

Before it got bricked, I had unlocked the advanced BIOS settings and manually disabled JEDEC write leveling along with some RAM training options. After I restarted the laptop, it got stuck and now there’s no POST.

There’s one last thing I’d like to try — I’m thinking of adding or re-enabling the advanced settings in the BIOS and then flashing it again. However, I’m not sure how to properly enable or restore those advanced settings.

Any guidance on this would really help.

Well, what a mess. the RAM isn’t initializing, so of course it won’t POST. Have you tried disconnecting all power sources, including the CMOS battery, then holding the power button for 30–60 seconds, and after that leaving it fully disconnected for about 10–15 minutes? I know it sounds simple but try this first if you haven’t already.

Also, I don’t know the exact BIOS recovery key combination for these machine types machine, but it’s worth checking and trying that method as well (Also Fn+R ?). At this point, it seems even rewriting the SPI did not reset those settings, but you could also try a BIOS downgrade to see if it performs a low-level reset. Good Luck!

P5CN21WW_8MB.rar (1.9 MB)

P5CN21WW_16MB.rar (5.5 MB)

Hi, thanks for the suggestions.

I’ve already tried a full power drain (AC + main battery + CMOS disconnected, held power ~60 seconds, left it for ~15–20 minutes), but unfortunately still no POST.

I’m starting to think the issue might be that the bad setting isn’t actually stored in the SPI BIOS chip I rewrote, or that I only rewrote part of what controls it (e.g. NVRAM/variable store not fully cleared).

Also, on the board I found two 8-pin SPI chips:

  • Winbond 25Q16JWNIQ (16Mbit / 2MB)

  • GigaDevice 25Q80ESIG (8Mbit / 1MB)

So now I’m wondering if one of these might hold EC firmware or a separate NVRAM/variable store that wasn’t affected by rewriting the main dump.

Do you think it’s possible the memory training / JEDEC settings are stored in one of these smaller chips or managed by EC/other firmware instead of the main BIOS region?

When writing SPI chips, always do this sequence: full erase → write → verify, in that exact order. And don’t touch that 80Mb chip, it’s probably for the Thunderbolt firmware (TBT Fw), nothing to do with those low-level settings.

is this okay to use? or you have something to recommend?

Maybe try reading the rich guides I already posted earlier for another user.

Hey bro, I think the 8MB CSME you made earlier is for Raptor Lake, but my laptop is ThinkBook 16p Gen 5 IRX (Alder Lake platform).

Can you please rebuild the CSME for me using:
:backhand_index_pointing_right: Intel CSME for Alder Lake (mobile / H or HX platform)

Important:

  • It should match Alder Lake PCH (600 series)

  • Not Raptor Lake

  • Clean ME (properly initialized via FIT)

If possible, base it on:
:backhand_index_pointing_right: the stock Lenovo BIOS (P5CN series) or same-board dump

This is likely why the system has no POST right now.

Thanks :folded_hands:

Well, the files I prepared for you are intended for the machine whose backup you sent.

I extracted the serial number from your files and provided you with the exact corresponding BIOS files. Does your serial number not end with Z4D?

That would mean the files sent are not the original dumps.

Hey bro, just wanted to ask if it’s okay with you to modify my BIOS and add the advanced menu to it. I’d really appreciate the help, but only if you’re comfortable doing it . No pressure at all.