[Tool] zedk - UEFI BIOS Editor/Unlocker

Hi all!

I’ve reimplemented the unlocking logic of UniversalAMDFormBrowser as described by @AARCH64_EL3, and just released an open-source tool called “zedk”, which builds a Setup loader from scratch, using the most recent EDK II and setup_var.efi sources.

Among other things, “zedk” allows to unlock/edit the hidden UEFI Setup/BIOS settings on Lenovo Tiny m920q/m920x/p330, m625q (and probably many others using AmiSetupFormSetVar-gated access control), just by booting to a USB flash drive — no hardware modifications required.

Many thanks to @AARCH64_EL3 for not only providing the original UniversalAMDFormBrowser tool but also explaining it how it works under the hood. This was critical to putting everything back together. Indeed, getting the build toolchain right was difficult.

Have a lot of fun!

Edit by Fernando: Thread title shortened

6 Likes

Great work! Just curious if this tool can handle modern ThinkPad BIOS settings unlock?

@kohlschuetter
Welcome to the Forum and a big thankyou for having developed and presented this new UEFI BIOS modding tool here.
Since you have explicitly mentioned within your initial post, that your work was inspired by @AARCH64_EL3 and his “UniversalAMDFormBrowser”, I have removed the related part from the thread title and hope, that this is ok for you. If you don’t agree with my action, feel free to recover your chosen original title.
Enjoy the Forum and the feedback you will get from the users!

Hey, just tried this out.

So far what I’ve observed is, this tool seems a bit more stable than umaf. Unlike umaf, it doesn’t inconsistently swap between full screen mode and a small square in the middle of the screen so thats one thing I noticed.

I would prefer automatically entering the form browser than having to enter the two commands myself, the reason being the keyboard utilizes as far as i can tell the US-EN layout, and it can be problematic to figure out how you would write what you need to with a different layout like my german keyboard layout. I had to randomly press things until i found the dash key.

So far this is simply a alternative umaf, which is of course fine since this tool just came out. But as is this tool doesnt seem to do anything much differently other than the two things I listed (correct me if I am wrong). I look forward to the development of this tool and how it will improve.

Thanks for testing, @brick2928!

zedk is more than just UniversalAMDFormBrowser, it is:

  • A toolchain to build an up-to-date^* version of edk2 UEFI-Shell (as well as UIApp, drivers for a serial console, etc.), and setup_var.efi, from source
  • An open-source implementation of @AARCH64_EL3’s idea to unload four drivers by UUID, such that edk2 UIApp can be launched (this is, as far as I understand, what UniversalAMDFormBrowser does)
  • applying a previously unknown^** trick to temporarily unlock advanced BIOS settings in Lenovo Tiny BIOSes (at least Tiny 5 series, Intel and AMD), by setting the EFI variable AmiSetupFormSetVar before launching UiApp

remarks:
^* up-to-date: Combining the latest with some older display driver; there’s a regression in edk2 between 20251105 and 20251108 releases, which zedk works around as well.
^** unknown as in: there’s a single chinese project, Lenovo-7000k-Unlock BIOS, that apparently sets AmiSetupFormSetVar to 1 to permanently enable admin-level features on Lenovo 7000k. This didn’t work on Lenovo Tiny5, as that variable is reset to 0 upon reboot. Only in combination with being able to enter UEFI-Setup after boot (via UIApp) it is possible to leverage this on Tiny5, and possibly many other AMI-based systems. This is new to zedk / not part of UniversalAMDFormBrowser either.

Regarding launching directly into UIApp: I tried doing so via the startup.nsh script, but it didn’t work for me (ended up with a black screen), so I ended up launching into the shell. Since zedk is supposed to get more features over time (for now, serial console redirection), I think it’s a good compromise.

You can try and see if it works for you by adding the following two lines to startup.nsh:

prepare-setup.nsh
UiApp.efi

… and if it does, then you have an automatic solution. But keep in mind that for UIApp, you’ll need a working keyboard, too. In any case, there are no 'Z’s or 'Y’s to mix up, and you can always autocomplete with [TAB], so a QWERTZ keyboard should be no trouble.

The black screen bug may be dependent on a specific system/firmware, or it’s a bug in edk2, all which can be fixed or worked around thanks to now having an open-source solution.

Contributions are very welcome!

Please try it out and let us know, there should be no harm doing so.

If it doesn’t unlock new features, it should at least allow you to enter BIOS settings from shell, which can be useful by itself.

If you either have an ifr dump of your BIOS settings (via uefiextract/ifrextractor) or check the EFI variables (e.g., under /sys/firmware/efi/efivars in Linux, or Config->UEFI Variable in ru.efi), and see a reference to AmiSetupFormSetVar, there’s a high chance that it will work.

Thanks for explaining the difference between zedk and UMAF @kohlschuetter, that helps me better understand how zedk improves over UMAF.

I tried adding

prepare-setup.nsh
UiApp.efi

into startup.nsh and it worked. I did not have to fiddle with uefi shell which makes me very happy.

I’ve come across a few issues already.

  1. Pressing “continue” puts the machine in a shell dialogue which one cannot exit unless they turn off the machine by pressing the power button and restart it.
    To compare with UMAF: In UMAF upon pressing continue, the machine will boot straight into windows, or I assume whatever is next in the boot order.

    1. In boot manager, it appears if zedk is the first in boot order no matter what one chooses in boot order the machine will just reboot back into zedk instead of booting into the target machine. Its a hassle to bring up the boot options menu on my device, thats why I set zedk as the first boot device in boot order.

Perhaps I am stuck in shell after pressing continue because zedk is the first boot device in boot order.. Can’t test this theory right now.
If you wish I can open github issues about these problems, in case that would help you keep better track of them.

I do not have any programming knowledge, so I will sadly not be able to contribute any kind of code to this project.

Does this software support intel machines and Insyde BIOS? Seems like it was developed heavily according to AMI and AMD machines. I look forward to your answer.

add the following line to the bottom of the script, and booting should continue as you expect it:

exit

The script does indeed work on Intel and AMD systems. I tried several Lenovo Tiny’s.

It should work on Insyde BIOS, but I haven’t tested it. It may also not unlock everything. It would be useful to try it and report back.

Hey @kohlschuetter, very quick question. Does ZEDK automatically change suppress if conditions to false to unsuppress to expose more options? I mean does this happen permanently to the bios image like what happens with UMAF upon booting it? It depends on this if I can recommend this software to other people or not.

Setting AmiSetupFormSetVar is temporary on the systems I tested on, which is Lenovo M920/P330 Tiny and M625q. I also tested it on M910 (where it doesn’t work but also doesn’t do any harm – there’s another, permanent way to unlock the hidden items).

The change may be permanent on other systems. This is hypothetical until we find such a system. Since we refer to AmiSetupFormSetVar by name, not by number, changing unrelated NVRAM bits on an unsupported is unlikely.

If you keep seeing hidden features in the regular BIOS setup after rebooting, launch the zedk shell and type

setup_var.efi AmiSetupFormSetVar:0x00=0

to manually revert the change.