[Request] Mod for Lenovo ThinkStation P3 Ultra

Hello,

I recently purchased a Lenovo ThinkStation P3 Ultra and would like to activate some additional menus (e.g. Overclocking or Memory) in the BIOS. I have read many guides and articles, but I am not sure if a mod is possible with my system.

I have already created a backup with FDT and adjusted it accordingly in AMIBCP, but I cannot flash the modified BIOS with either FDT or AFU. The error “Error 167: Protected Range Registers are currently set by BIOS, preventing flash access” is always displayed. I have already tried to disable the BIOS lock (0x1C @ 0x7) using RU, but the adjustment is reset the next time the system is restarted. I suspect that this is triggered by Boot Guard and, as far as I have read, this protection can only be removed by replacing the PCH.

What surprises me is that a full backup with FPT (without the “-bios” parameter) is also possible, as I have read that this should not be possible if locks are present.

Can anyone tell me if it is generally possible to modify the BIOS of the Lenovo ThinkStation P3 Ultra? I also have a USB-Programmer (XGecu T48 / TL866II Plus) available.

Below you will find a backup of FPT, the latest bios update and the output of MEInfoWin64: Content not found | LimeWire

Password: ThinkStationP3Ultra

Thank you for your help!

AMIBCP “Leaked” ones available are not for modern Aptio V Core bios, only works in a small initial V.
This should be used.

Flash… besides an optional SPI programmer and even so…

Thanks for your quick response!

Based on the files from my link, can you tell me whether the system will still boot after flashing a modified BIOS? I have read in other posts that the Boot Guard cannot be bypassed, and I want to avoid the system no longer being able to start.

What surprises me, however, is that no colored markings (e.g. yellow or red) are displayed in UEFITool NE for the regions and that a full backup with FPT (green message: Operation Successful) is possible.

I will definitely make a backup with the USB-Programmer before attempting anything else.

I still have to read the other post ([Problem] Lenovo ThinkStation P3 Ultra Type 30HB - BIOS Update Failure - #76 by earthoo7) in full, but as far as I understand, the flash did not work here either.

Sorry…cant lose my time with, same was doing the mod itself…

Sir…usually it cant, i do not know any “sucessful” and safe methods
…and every mod is a risk situation that any user should have in mind, asset priority etc…
Multiples backups are ALWAYS advisable (FPT and most assured one, the SPI reading of all ICs)

and FPT reading acess to regions is one thing, permisson to write that’s another story, this is where the ME_DIS jumper (ME_Disable/Service_Mode) can be the trigger for regions acess and operations.

That’s all from me, good luck.

You may need AMI SCEWIN, modifying NVRAM variables is safe and will not trigger Intel boot guard,The premise is that the BIOS follows the hii framework
https://zhuanlan.zhihu.com/p/17637013921

Blockquote
You may need AMI SCEWIN, modifying NVRAM variables is safe and will not trigger Intel boot guard,The premise is that the BIOS follows the hii framework
https://zhuanlan.zhihu.com/p/17637013921

Unfortunately, even with SCEWIN, I can’t permanently disable BIOS Lock and FPRR. Importing the modified NVRAM-File works without any problems, but the modifications are reset the next time the system is restarted. The Startup-Logo (Lenovo) is briefly displayed, and then the system restarts.

Does anyone else have any ideas on how I can modify the BIOS of the Lenovo P3 Ultra? I just want to activate the overclocking menu. I assume that the locks are identical on all current systems from Lenovo.

Hello.

I have one. Post bios setup picture, please. Googleing didn’t work for me.

What exactly do you mean? Do you need a photo of every page in the BIOS? Of every main page or every subpage too? Or should I send you the structure as text?

Any page would do. A single photo in total.

Aight, this one is new, untested with the patcher program. I’m going to prepare two archives. Will keep you updated.

UPD:
Here Model 30HA005GGE.

  1. Disable secure boot. 2. Unpack the archive to a flash drive and boot from it.
  2. Efi shell will try to add SREP to “boot order”.
  3. Check if status message indicates that a new driver entry added successfully.
  4. If everything up to this step went well, try rebooting your pc and entering bios. Now it shouldn’t enter instantly. Expect SREP running first. After this, Advanced should become available. If not, I’ll upload the second archive.
  5. Unplug the usb and delete the entry (optional).

Thank you very much for your support and your valuable time!

1: Check
2: Check
3: Check (Message: Added a new entry to DriveOrder, you may reboot the PC)
4: Smokeless Runtine EFI Patcher was executed during restart, but there are no new menus in the BIOS.
5: I don’t know how to delete the entry.

Then it patched the wrong Dxe driver, EsaFull. Could be that. Here’s a new cfg, which patches both AMITSE and EsaFull.
When booted, please check what “USB Setup” item does. It’s under Devices tab. Let me know if anything changes. If not, please attach the log file created on the usb drive.

“bcfg driver rm 0” is the complete command to delete the entry. Use it after the message appears and cmd line becomes available.

Thank you again for your support and your valuable time!

With the second CFG, a few things have changed:

1: The “Main” menu is now “Chipset” (see first photo)
2: The “Devices - USB Setup” menu now contains a lot of entries (see second photo)
3: The “Advanced” menu appears to contain the same content as “Devices > USB Setup” (see second photo)

Is the arrangement of the menus intentional?

I have also attached the logs from both configurations.

SREP - LOG.zip (1.9 KB)

If I understand how SREP works correctly, then SREP adjusts the EFI modules in RAM during POST. Would that mean that SREP does not make any permanent changes in the SPI (e.g. BIOS-Region or NVRAM)? Does that mean that the USB stick with the SREP configuration must always remain plugged in? If I make changes in the BIOS, these are stored persistently in the NVRAM independently of SREP, so it shouldn’t matter whether the USB stick with SREP is still plugged in after I have made the changes, right?

The order depends on Form Id value. You can’t see it from bios setup, but can in IFRE output.

Thanks for the detailed response.
I did patch USB Setup in case the other changes are non effective.

The patcher doesn’t write anything to spi chip. It adjusts RAM contents only. usb stick must be plugged when you want to access advanced bios, but you don’t have to leave it plugged in after configuring bios. Changes are stored persistently.

Hi,

I am looking to undervolt my Lenovo P3 Gen 2 Tiny. Unfortunately, the cpu voltage control is locked by default.

Could SREP be used to unhide the BIOS menus in P3 Gen 2 Tiny as well? Any help would be highly appreciated @Sweet_Kitten

Likely, yes. How can I help?

Thank you for your swift reply!

I just migrated from m920q to P3 Gen 2 Tiny and was bummed to find out you cannot unlock voltage control anymore by editing UEFI variables using RU.efi. My previous project was documented in a Reddit post.

If it is not too much to ask, a turnkey solution (that is, the contents of the SREP usb stick) would of course be greatest option. Just let me know what kind of further info you need from my side, provided that this is something you would be willing to do.

Thank you in advance!

Provided that I find uefi image on the support page, I’ll upload a solution soon.

Uploaded and tested on June 5th

M5PJY34USA.zip (491.1 KB)

1 Like

Hi, I’m looking to undervolt a gen 1 P3 tiny, is it possible to use the gen 2 file? or a separated one is needed, any suggestion would be highly appreciated @Sweet_Kitten . Thanks