{"id":13434693,"url":"https://github.com/jimdigriz/debian-mssp4","last_synced_at":"2025-03-18T01:31:54.431Z","repository":{"id":151384744,"uuid":"48918667","full_name":"jimdigriz/debian-mssp4","owner":"jimdigriz","description":"Installing Debian on the Microsoft Surface Pro 4","archived":true,"fork":false,"pushed_at":"2017-07-03T15:58:48.000Z","size":220,"stargazers_count":182,"open_issues_count":5,"forks_count":23,"subscribers_count":39,"default_branch":"master","last_synced_at":"2024-10-27T17:23:58.136Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Shell","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":null,"status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jimdigriz.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":null,"code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null}},"created_at":"2016-01-02T17:57:43.000Z","updated_at":"2024-08-16T17:07:21.000Z","dependencies_parsed_at":null,"dependency_job_id":"93da85c9-eca3-4086-ab2b-ea379acf93f0","html_url":"https://github.com/jimdigriz/debian-mssp4","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jimdigriz%2Fdebian-mssp4","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jimdigriz%2Fdebian-mssp4/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jimdigriz%2Fdebian-mssp4/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jimdigriz%2Fdebian-mssp4/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jimdigriz","download_url":"https://codeload.github.com/jimdigriz/debian-mssp4/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":244139293,"owners_count":20404489,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-07-31T03:00:20.684Z","updated_at":"2025-03-18T01:31:54.180Z","avatar_url":"https://github.com/jimdigriz.png","language":"Shell","funding_links":[],"categories":["Device"],"sub_categories":["Surface"],"readme":"These instructions cover how to install [Debian 'jessie' 8.x](https://www.debian.org/) onto a [Microsoft Surface Pro 4](https://www.microsoft.com/surface/devices/surface-pro-4).\n\nThe instructions assume you are not new to Debian, though you may have no experience of UEFI and SecureBoot (I did not until now!).\n\n## What is Working\n\n * dual booting\n * SecureBoot\n * Touchscreen and Pen\n * typing cover keyboard\n     * multitouch touchpad (two finger scrolling, etc)\n     * special keys\n * 2D and 3D (OpenGL) acceleration\n     * hardware video decoding\n * power and volume buttons on the screen\n * audio (including the microphone)\n * sensors - `dev_rotation` though gives nothing but zeros\n * wireless (is a 88W8897, a wireless/bluetooth combo module)\n     * bluetooth - this only appears once you use the wireless card firmware from [firmware-libertas (20151207-1~bpo8+1) [pcie8897_uapsta.bin version 15.68.4.p112]](https://packages.debian.org/jessie-backports/firmware-libertas)\n * microSD reader - presented as a USB reader appearing when you insert a card\n * suspend (rather freeze), hibernate and resume works\n\n## Outstanding Issues\n\n * camera\n     * is on an I2C bus on accessible via the graphics card\n     * from the ACPI DSDT you can get information on what the *three* cameras are\n     * front camera (`CAMF`) is a [`OV5693 (INT33BE)`](http://www.ovt.com/products/sensor.php?id=185), there is an [Android driver](https://github.com/sayeed99/test/blob/eadd15672fd628eab9ad5bfcaf00d1b7fbafee3f/drivers/external_drivers/camera/drivers/media/i2c/ov5693/ov5693.c)\n     * rear camera (`CAMR`) is a [`OV8865 (INT347A)`](http://www.ovt.com/products/sensor.php?id=134), there is an [Android driver](https://github.com/lenovo-yt2-dev/android_kernel_lenovo_baytrail/blob/357b3bc165c76b9cf1f0d2c08e458576018164a3/drivers/external_drivers/camera/drivers/media/i2c/ov8865.c)\n     * third camera (`CAM3`) is an IR [`OV7251 (INT347E)`](http://www.ovt.com/products/sensor.php?id=146), there is an [Android driver](https://github.com/ADVANSEE/0066_linux/blob/ba2479578aa7f35be22f6749f7504ba3a68414dc/drivers/media/video/mxc/capture/ov7251_mipi.c)\n * opening the typing cover (or pressing keys) does not not automatically resume\n * [AC adaptor events](https://bugzilla.kernel.org/show_bug.cgi?id=109891)\n     * [DSDT changes required to fix this](https://www.reddit.com/r/SurfaceLinux/comments/46o3mh/fix_udev_power_adapter_event_by_patching_acpi/)\n     * once done, we can turn turbo boost off on battery via `/sys/devices/system/cpu/intel_pstate/no_turbo`\n * there is an ACPI `INT3420` entry for 'Intel Bluetooth RF Kill' which would be nice to have\n * enable the other I2C (`INT344[2-5]`) and SPI (`INT344[01]`) busses via `drivers/mfd/intel-lpss-acpi.c` maybe?\n * there are a number of hardware sensors via a MAX34407 on the I2C bus\n * there is no [S3 'suspend to RAM'](http://acpi.sourceforge.net/documentation/sleep.html) available as since the Surface Pro 3, [connected standby](https://lwn.net/Articles/580451/) (ACPI state [S0ix](http://www.anandtech.com/show/6355/intels-haswell-architecture/3)) replaces it; [although supported by Linux fundamentally by Linux, some practical work is still needed](http://mjg59.dreamwidth.org/34542.html?thread=1378798#cmt1378798)\n     * this means that S3 'suspend to RAM' (`echo mem \u003e /sys/power/state`) is replaced with S1 'power on suspend' (`echo freeze \u003e /sys/power/state`) which uses a lot more juice; 100% charge lasts about 12 hours\n     * amending the DSDT manually to remove the conditional that masks out S3 results in `echo mem \u003e /sys/power/state` making the laptop power up as if power cycled.  Probably works better with [`acpi_rev_override` (`_REV=2`)](https://mjg59.dreamwidth.org/34542.html) and `acpi_os_name=\"Windows 2012\"` (or earlier)\n * [Caps Lock key light](https://patchwork.kernel.org/patch/7844371/) - 'fixed' by running `sudo kbd_mode -u`\n     * this is not a problem with the `hid-microsoft` driver which if you want to use make sure you are using `xserver-xorg-input-evdev \u003e=2.10` as well as `Option \"IgnoreAbsoluteAxes\" \"on\"`\n     * we use the `hid-multitouch` driver as it presents separate keyboard and touchpad devices, which means the xorg `evdev` driver does not handle the touchpad and `mtrack` sees it as a touchpad and can handle it\n * Wireless\n     * [power saving needs to be turned off](./root/etc/network/interfaces.d/mlan0) otherwise after about a minute of idling, you start seeing 100ms+ first hop latencies\n     * `modprobe -r mwifiex_pcie; modprobe mwifiex_pcie` results in a lockup; you need to reset the card inbeteen the unload/load with `echo 1 \u003e /sys/bus/pci/devices/0000\\:02\\:00.0/reset`\n     * on kernel 4.5.x (and I guess 4.6.x too) the [driver is pretty flakey](https://github.com/jimdigriz/debian-mssp4/issues/4) though there is a patch on the linked bugzilla\n * the GRUB with SecureBoot needs some more work, the fonts are bust, plus I need to find the problematic module so we can just load the lot in making the process simpler\n * `gparted` lockup investigation\n * move to using [`triggerhappy`](https://github.com/wertarbyte/triggerhappy) rather than `xbindkeys` so that the [multimedia keys can still work with the screen locked](https://github.com/i3/i3lock/issues/52)\n * reading sensors (such as the ALS) occasionally takes a long time, [which might be related to bad timings](https://github.com/torvalds/linux/commit/56d4b8a24cef5d66f0d10ac778a520d3c2c68a48):\n\n        [10805.080581] i2c_hid i2c-MSHW0030:00: failed to change power setting.\n        [10805.080969] i2c_hid i2c-MSHW0030:00: failed to retrieve report from device.\n        [10805.081317] i2c_hid i2c-MSHW0030:00: failed to set a report to device.\n        [10805.081609] i2c_hid i2c-MSHW0030:00: failed to set a report to device.\n        [10805.081887] i2c_hid i2c-MSHW0030:00: failed to retrieve report from device.\n        [10805.484550] i2c_hid i2c-MSHW0030:00: failed to retrieve report from device.\n        [10810.588300] i2c_hid i2c-MSHW0030:00: failed to retrieve report from device.\n        [10815.691993] i2c_hid i2c-MSHW0030:00: failed to retrieve report from device.\n        [10820.795814] i2c_hid i2c-MSHW0030:00: failed to retrieve report from device.\n        [10825.899475] i2c_hid i2c-MSHW0030:00: failed to retrieve report from device.\n        [10831.003440] i2c_hid i2c-MSHW0030:00: failed to retrieve report from device.\n        [10836.107134] i2c_hid i2c-MSHW0030:00: failed to retrieve report from device.\n        [10841.210879] i2c_hid i2c-MSHW0030:00: failed to retrieve report from device.\n        [10849.482535] i2c_hid i2c-MSHW0030:00: failed to set a report to device.\n        [10849.482955] i2c_hid i2c-MSHW0030:00: failed to change power setting.\n        [10849.483393] i2c_hid i2c-MSHW0030:00: failed to set a report to device.\n        [10849.483781] i2c_hid i2c-MSHW0030:00: failed to retrieve report from device.\n\n## Related Links\n\n * because of the high resolution screen it is worth reading through some [HiDPI related materials](https://wiki.archlinux.org/index.php/HiDPI) otherwise you will very quickly go short sighted\n * wishing for a matte screen, I got the [iLLumiShield](http://www.amazon.co.uk/gp/product/B0169CKLBK) and find it does the job great\n * for a nice cheap case, I got the blue map motif [MoKo Ultra Slim Lightweight Smart-shell Stand Cover Case (Map F)](https://www.amazon.co.uk/Microsoft-Surface-Pro-Case-Lightweight/dp/B014P2NOLU/)\n * patches based on\n      * [IPTS Linux](https://github.com/ipts-linux-org/ipts-linux-new/wiki) driver\n      * [[PATCH 1/2] HID: Use multitouch driver for Type Covers](http://lkml.iu.edu/hypermail/linux/kernel/1512.1/05130.html)\n      * [[1/2] HID: input: rework HID_QUIRK_MULTI_INPUT](https://patchwork.kernel.org/patch/9081731/)\n      * [[2/2] HID: multitouch: enable the Surface 3 Type Cover to report multitouch data](https://patchwork.kernel.org/patch/9081761/)\n * [iio-sensor-proxy](https://github.com/hadess/iio-sensor-proxy) - `systemctl enable iio-sensor-proxy.service`\n * Hibernation\n      * [Ubuntu Hibernation](https://help.ubuntu.com/community/PowerManagement/Hibernate)\n * [reverse scrolling](https://n00bsys0p.wordpress.com/2011/07/26/reverse-xorg-scrolling-in-linux-natural-scrolling/)\n * [reddit - Surface Linux: Penguins like nice things too](https://www.reddit.com/r/surfacelinux)\n * [Microsoft Surface Pro 4 update history](https://www.microsoft.com/surface/en-gb/support/install-update-activate/surface-pro-4-update-history)\n * SecureBoot\n      * [Using the Linux Foundation's PreLoader](http://www.rodsbooks.com/efi-bootloaders/secureboot.html#preloader)\n      * [Accessing UEFI Variables from Linux](http://firmware.intel.com/blog/accessing-uefi-variables-linux)\n      * [ArchLinux: Surface Pro 3 - Booting with Secure Boot Enabled](https://wiki.archlinux.org/index.php/Microsoft_Surface_Pro_3#Booting_with_Secure_Boot_Enabled)\n\n# Preflight\n\nYou will require:\n\n * an external USB keyboard, as the typing cover is not supported by Debian's kernel\n * a USB hub as there is only one USB port\n * a USB key `dd`'ed with the amd64 live ISO for [gparted](http://gparted.sourceforge.net/)\n      * **WARNING:** `gparted-live-0.24.0-2-amd64.iso` locked up after a few minutes of running, you of course do *not* want this midway through the resize.  All I can recommend if you use this version, is to be quick\n      * I have tried to boot `0.25.0-1` but it fails for various reasons whilst `0.25.0-3` the {md5,sha1}sums for the ISOs mis-match which explains why they do not work\n * a USB key `dd`'ed with the [non-free amd64 Debian network installer](http://cdimage.debian.org/cdimage/unofficial/non-free/cd-including-firmware/current/amd64/iso-cd/); I used `firmware-8.2.0-amd64-netinst.iso`\n * an (open, WEP or WPA PSK) wireless network you can connect to (or an USB Ethernet adaptor)\n\n## Prepping Windows 10\n\nThe aim here is to shrink down the Windows partition to make room for Debian.\n\nI wanted to keep Windows as Microsoft are constantly [releasing updated firmwares which will only apply from under Windows](https://www.microsoft.com/surface/en-gb/support/install-update-activate/surface-pro-4-update-history).  Of course if you plan not on dual booting you could skip all this, though I would not recommend to have something to apply those firmware updates with.\n\nLet's start by disabling Bitlocker so that gparted can resize the partition later.  This is done by clicking on Start, and clicking on 'File Manager'.  From here you will be able to go to where drive `C:` is located, and right-clicking on it will give you an option to 'Manage Bitlocker'.  From there you will be able to click on 'Disable Bitlocker'.\n\n**N.B.** if there is an exclamation mark on the drive `C:` icon, you will need to firstly enable Bitlocker before you can fully disable it\n\nNow we need to disable SecureBoot to let us boot Linux later on.\n\n - Either:\n      * from Windows, click on Start -\u003e Power -\u003e (hold down shift) -\u003e click on 'Restart'\n           - go to 'Troubleshoot'\n           - go to 'Advanced options'\n           - select 'UEFI Firmware Settings'\n      * whilst powered off, hold down the '+' volume button and turn on the laptop\n - you will be dropped into the Surface UEFI system\n - go to 'Security'\n - under 'Secure Boot', click on 'Change configuration'\n - select 'None' from the menu and click on OK\n\nBefore we go and shrink the Windows partition, lets start off by getting the latest updates (including firmwares) installed (I did this on 2015-12-31), so prepare yourself for a long and tediously slow process (hours) of watching progress bars and lots of reboot cycles as Windows 'does its thing'.\n\nWe now need to free up a space on drive `C:` and get ready for shrinking by:\n\n - [turning off the hibernation file](https://support.microsoft.com/kb/920730)\n - [turning off the paging file](http://windows.microsoft.com/en-us/windows/change-virtual-memory-size)\n - [run disk cleanup (including on the system files)](http://windows.microsoft.com/en-us/windows-10/disk-cleanup-in-windows-10) - here you can delete any old versions of Windows which can take up ~25GB\n - run *twice* `CHKDSK` on drive `C:`, this is done by opening a command prompt as administrator and typing `chkdsk /f c:`, you will need to reboot for the chkdsk to work; remember to do it a second time too!\n\n## Shrinking the Windows Partition\n\nInsert the gparted USB key and boot it by either:\n\n * from Windows, click on Start -\u003e Power -\u003e (hold down shift) -\u003e click on 'Restart'\n      - go to 'Use a device'\n      - select 'USB Storage'\n * go to the Surface UEFI system by powering on whilst holding down the '+' volume button\n      - go to the 'Boot configuration' section\n      - left swipe on 'USB Storage' to boot off your USB key\n\nYou should be able to boot into gparted now, and get something that lets you reduce the size of the NTFS partition; for me Windows took up 22GB of space so I left it in a 60GB partition to leave it enough room for Windows Update.\n\nOnce shrunk, you should test that you can still boot into Windows, and if you can, we are ready to move on (though you may wish to first go back into Window and re-enable hibernation, the paging file and Bitlocker).  If not, you will have to figure out what is wrong.\n\nFor reference, my partition table looks like:\n\n    alex@quatermain:~$ sudo fdisk -l /dev/nvme0n1\n    Disk /dev/nvme0n1: 238.5 GiB, 256060514304 bytes, 500118192 sectors\n    Units: sectors of 1 * 512 = 512 bytes\n    Sector size (logical/physical): 512 bytes / 512 bytes\n    I/O size (minimum/optimal): 512 bytes / 512 bytes\n    Disklabel type: gpt\n    Disk identifier: B9B03E80-67C3-41C1-AF4F-367C32AF2CE5\n    \n    Device             Start       End   Sectors   Size Type\n    /dev/nvme0n1p1      2048    534527    532480   260M EFI System\n    /dev/nvme0n1p2    534528    796671    262144   128M Microsoft reserved\n    /dev/nvme0n1p3    796672 130377727 129581056  61.8G Microsoft basic data\n    /dev/nvme0n1p4 494813184 500117503   5304320   2.5G Windows recovery environment\n    /dev/nvme0n1p5 130377728 493658111 363280384 173.2G Linux LVM\n    /dev/nvme0n1p6 493658112 494813183   1155072   564M Linux filesystem\n    \n    Partition table entries are not in disk order.\n\n**N.B.** you should set your swap space to about 1.5x the amount of memory you have to make sure you have space to hibernate\n\n# Installing Debian\n\nBoot off your Debian installer USB key and work through it.  Early on though you will be prompted on which Ethernet card you have, select \"no Ethernet interface\", then the next page you will be prompted to supply details on how to connect to your wireless network then the installation will continue as expected.\n\n**N.B.** I would recommend keeping the ~2.5GB recovery partition so if you ever need to return the laptop, you will find the process dead easy; though it seems you could [move the partition to external media](https://www.microsoft.com/surface/en-ca/support/storage-files-and-folders/create-a-recovery-drive?os=windows-10) or [download it from the Microsoft website](https://www.microsoft.com/surface/en-ca/support/warranty-service-and-recovery/downloadablerecoveryimage)\n\nFor your information, I went for a `/boot` partition and put everything else on LVM.\n\nWhen the installer gets to the point of installing GRUB as your boot loader, it will fail.  To resolve this you will need to 'Execute a shell' and type the following:\n\n    mount --bind /sys /target/sys\n    chroot /target /bin/bash\n    apt-get install grub-efi\n    update-grub\n    grub-install /dev/nvme0n1\n    exit\n    umount /target/sys\n    exit\n\nNow click on 'Continue without a bootloader'.\n\nYou laptop should reboot and you will see the GRUB bootloader and Debian should boot.\n\n**N.B.** until you install a newer (backports) kernel GRUB will not detect and boot Windows\n\n# Configuring\n\n## Add Additional Repositories\n\nYou need to add [Debian backports](http://backports.debian.org/), stretch, sid, as well as some suitable pinning.  So copy into place the required files under [`/etc/apt/`](root/etc/apt/).  Now run:\n\n    sudo apt-get update\n\n## Networking\n\nAll you need to do is copy the contents of [`interfaces.d`](root/etc/network/interfaces.d) into `/etc/network/interfaces.d/`; plus create a suitable `/etc/wpa_supplicant/wpa_supplicant.conf` file (if you are not using any network management tool).\n\n## Kernel\n\nFirst you need to set some kernel boot arguments which are set in [`/etc/default/grub`](root/etc/default/grub):\n\n    resume=/dev/mapper/lvm--quatermain-swap\n\n**N.B.** you must adjust the `resume` argument to match where your swap space is, or if you plan not to use hibernation, replace it with `noresume`\n\n**N.B.** if you are running a kernel earlier than 4.4, you will also need to add `intel_idle.max_cstate=2` otherwise the GPU whilst modeset'ing will black out the screen and crash the system\n\nAlso, so that your keyboard works before the root filesystem is mounted, edit your [`/etc/initramfs-tools/modules`](root/etc/initramfs-tools/modules) file to include `hid_multitouch`.\n\nRun the following to get your system ready to compile a kernel:\n\n    sudo apt-get install build-essential git fakeroot kernel-package\n    sudo apt-get install firmware-libertas/jessie-backports firmware-misc-nonfree intel-microcode\n    wget -P /usr/src http://http.debian.net/debian/pool/main/l/linux/linux-source-4.8_4.8.7-1_all.deb\n    \n    git clone https://gitlab.com/jimdigriz/linux.git /usr/src/linux\n    cd /usr/src/linux\n    git checkout mssp4\n    ar p /usr/src/linux-source-4.8_4.8.7-1_all.deb data.tar.gz | gunzip -c | tar xO ./usr/src/linux-config-4.8/config.amd64_none_amd64.xz | xzcat \u003e .config\n    \n    cat \u003c\u003c'EOF' \u003e\u003e .config\n    CONFIG_INTEL_IPTS=m\n    CONFIG_BLK_DEV_NVME=y\n    CONFIG_MODULE_SIG=n\n    CONFIG_SYSTEM_TRUSTED_KEYRING=n\n    EOF\n\nNow run `make oldconfig` (accept the defaults to all the prompting) so our `.config` changes are incorporated (we make `nvme` built in so hibernation works).\n\nTime to compile the kernel (this will take about 40 minutes):\n\n    CONCURRENCY_LEVEL=`getconf _NPROCESSORS_ONLN` fakeroot make-kpkg --initrd --append-to-version=-mssp4 kernel_image\n\n**N.B.** you can append `kernel_headers` to also build the `linux-headers` package too\n\nOnce compiled (roughly 40 minutes), you now need to install your new kernel:\n\n    sudo dpkg -i /usr/src/linux-image-4.9.0-mssp4+_4.9.0-mssp4+-10.00.Custom_amd64.deb\n\nNow reboot into your new kernel.\n\n## Power\n\nInstall the needed packages:\n\n    sudo apt-get install sleepd\n\nCopy in the [`/lib/systemd/system-sleep`](root/lib/systemd/system-sleep) helper files, [`/etc/systemd/sleep.conf`](root/etc/systemd/sleep.conf) and also [`/etc/default/sleepd`](root/etc/default/sleepd).\n\nYou should be able to suspend (`echo freeze | sudo tee /sys/power/state`, or close the typing cover), hibernate (`echo disk | sudo tee /sys/power/state`) and resume (hold the power button for roughly five seconds).\n\nIf you have problems, such as stalls at boot time, there probably is a problem with your `resume` kernel parameter (did you compile the kernel with `nvme` built in?), so to break out of the stall add `noresume` to your kernel parameters.\n\n### Screen Locking\n\nTo lock your X11 console, you will need a few packages:\n\n    sudo apt-get install xautolock xss-lock\n\nThen set your [`~/.xsession`](root/home/USER/.xsession) accordingly to run these.\n\n### PowerTOP\n\nA number of [PowerTOP](https://01.org/powertop/) suggestions are applied with:\n\n * [`/etc/sysctl.d/local.conf`](root/etc/sysctl.d/local.conf)\n * [`/etc/modprobe.d/local.conf`](root/etc/modprobe.d/local.conf)\n * [`/etc/udev/rules.d/90-local.rules`](root/etc/udev/rules.d/90-local.rules)\n\n## Graphics\n\n### Console\n\nAll you need to do is so run:\n\n    sudo dpkg-reconfigure console-setup\n\nThen select the 'Terminus' font, and the 16x32 sizing.\n\n**N.B.** you can set the keyboard mapping for the console (and Xorg) with `localectl ...`\n\nUnfortunately there is an outstanding bug ([console-setup w/ systemd forgets font setting](https://bugs.debian.org/759657)) which means you have to slip in [`/etc/udev/rules.d/90-setupcon.rules`](root/etc/udev/rules.d/90-setupcon.rules) to stop them being shrunk again (and the keyboard mapping being forced back to US)\n\n### Xorg\n\nStart off by installing Xorg:\n\n    sudo apt-get install xserver-xorg xserver-xorg-input-mtrack xserver-xorg-video-intel libgl1-mesa-dri libgl1-mesa-glx big-cursor\n\nNow populate [`/etc/X11/xorg.conf.d`](root/etc/X11/xorg.conf.d) and then you should be able to start Xorg (I recommend installing the [lightdm](http://freedesktop.org/wiki/Software/LightDM/) package) and it will have 2D and 3D acceleration enabled.  You can check this by running:\n\n    alex@quatermain:~$ grep AIGLX /var/log/Xorg.0.log\n    [     5.124] (==) AIGLX enabled\n    [     5.183] (II) AIGLX: enabled GLX_MESA_copy_sub_buffer\n    [     5.183] (II) AIGLX: enabled GLX_ARB_create_context\n    [     5.183] (II) AIGLX: enabled GLX_ARB_create_context_profile\n    [     5.183] (II) AIGLX: enabled GLX_EXT_create_context_es2_profile\n    [     5.183] (II) AIGLX: enabled GLX_INTEL_swap_event\n    [     5.183] (II) AIGLX: enabled GLX_SGI_swap_control and GLX_MESA_swap_control\n    [     5.183] (II) AIGLX: enabled GLX_EXT_framebuffer_sRGB\n    [     5.183] (II) AIGLX: enabled GLX_ARB_fbconfig_float\n    [     5.183] (II) AIGLX: GLX_EXT_texture_from_pixmap backed by buffer objects\n    [     5.183] (II) AIGLX: enabled GLX_ARB_create_context_robustness\n    [     5.183] (II) AIGLX: Loaded and initialized i965\n\nIf this does not work then you should check that the apt pinning brought in `libdrm-intel1`, `libgl1-mesa-{dri,glx}` and `xserver-xorg-video-intel` from jessie-backports.\n\nThen from within X you should see something like:\n\n    alex@quatermain:~$ xdriinfo \n    Screen 0: i965\n    \n    alex@quatermain:~$ glxinfo | head\n    name of display: :0\n    display: :0  screen: 0\n    direct rendering: Yes\n    server glx vendor string: SGI\n    server glx version string: 1.4\n    server glx extensions:\n        GLX_ARB_create_context, GLX_ARB_create_context_profile, \n        GLX_ARB_create_context_robustness, GLX_ARB_fbconfig_float, \n        GLX_ARB_framebuffer_sRGB, GLX_ARB_multisample, \n        GLX_EXT_create_context_es2_profile, GLX_EXT_framebuffer_sRGB, \n\n#### Backlight\n\nYou can use (range from 0 to 937):\n\n    xrandr --output eDP1 --set Backlight 400\n\nIf you prefer, you might want to use:\n\n    sudo apt-get install xbacklight\n\nAlternatively, look at `/sys/class/backlight/intel_backlight/{brightness,max_brightness}`.\n\n#### Multimedia Keys\n\nThis depends on your environment, though I am using [xbindkeys](http://www.nongnu.org/xbindkeys/xbindkeys.html) which should be pretty usable on all desktop environments.\n\n    sudo apt-get install xbindkeys libnotify-bin\n\nCopy in a [`~/.xbindkeysrc`](root/home/USER/.xbindkeysrc) file and also the screen brightness setting script [`/usr/local/bin/mssp4-backlight`](root/usr/local/bin/mssp4-backlight).\n\nRestart X11 (to pick up the load in your `~/.xsession` file), or run 'xbindkeys' in a terminal.\n\n#### Hardware Video Decoding\n\nLets install the drivers and a video player:\n\n    sudo apt-get install mpv/jessie-backports libva1 i965-va-driver vainfo\n\nTest if you have VA-API acceleration available with:\n\n    vainfo\n\nIf so, now configure `mpv` to use the API.\n\n    mkdir ~/.config/mpv\n    echo hwdec=vaapi \u003e ~/.config/mpv/mpv.conf\n\nWhen you play videos, you should find the CPU utilisation drops substantially; I saw a 3.5x improvement!\n\nIf this does not work (you see `Using software decoding.` in the output of `mpv`) it may be because this only works for videos encoded with a codec where VA-API accelerated decoding is available (you will see `Using hardware decoding.` when it works).  For hints, example the output of `vainfo` and compare it to what `mpv` says the video codec is (for example `h264`).\n\n##### Chromium (and Opera)\n\nLets install Chromium:\n\n    sudo apt-get install chromium\n\nOpen a tab to [chrome://gpu](chrome://gpu) and should see [hardware acceleration is off for a number of things](https://bugs.chromium.org/p/chromium/issues/detail?id=137247).  To fix this, go to in another tab [chrome://flags/#ignore-gpu-blacklist](chrome://flags/#ignore-gpu-blacklist) and enable 'Override software rendering list'.  When you click on 'Relauch now' you should see 'Video Decode' is now enable in the [chrome://gpu](chrome://gpu) tab.\n\nNow install the [h264ify](https://chrome.google.com/webstore/detail/h264ify/aleakchihdccplidncghkekgioiakgal) extension and then test by watching [COSTA RICA IN 4K 60fps (ULTRA HD) w/ Freefly Movi](https://youtu.be/iNJdPyoqt8U) and cranking it up to 2160p.  Under the menu option 'stats for nerds' you should see pretty much zero frame drops and your CPU only going to 100%ish, rather than the 250%+ without and the stuttering that goes with software rendering at this resolution.\n\n##### Vivaldi\n\nSimilar to the Chromium/Opera instructions (override the software rendering list and install h264ify), you will also need to fetch [vivaldi-snapshot](https://vivaldi.net/en-US/teamblog/132-snapshot-1-3-537-5-improved-proprietary-media-support-on-linux) from the [Vivaldi website](https://vivaldi.com) (it will auto-update afterwards).  Now go and fetch [chromium-codecs-ffmpeg-extra](http://packages.ubuntu.com/wily-updates/chromium-codecs-ffmpeg-extra) from Ubuntu and install it.\n\n    sudo dpkg -i chromium-codecs-ffmpeg-extra_51.0.2704.79-0ubuntu0.15.10.1.1232_amd64.deb\n\nNow install:\n\n    sudo apt-get install libvdpau-va-gl1 vdpauinfo\n\nNow run vivaldi with:\n\n    VDPAU_DRIVER=va_gl vivaldi\n\n##### Firefox\n\nFor Firefox, [which does not support any HTML5 video hardware decoding](https://bugzilla.mozilla.org/show_bug.cgi?id=563206), you can persuade the ([non-pepper](https://wiki.debian.org/PepperFlashPlayer)) `flashplugin-nonfree` package to use [hardware acceleration](http://www.webupd8.org/2013/09/adobe-flash-player-hardware.html):\n\n    sudo apt-get install libvdpau-va-gl1 vdpauinfo\n    sudo mkdir /etc/adobe\n    echo -e \"EnableLinuxHWVideoDecode = 1\\nOverrideGPUValidation = 1\" | sudo tee /etc/adobe/mms.cfg\n    sudo sed -i '/va_gl/ s/^# //' /etc/X11/Xsession.d/20vdpau-va-gl\n\nYou will now need to logout and back in to get the `VDPAU_DRIVER` environment variable set, or you can quickly test things with:\n\n    VDPAU_DRIVER=va_gl firefox\n\nFor me, I get about 20% CPU usage for Flash at 1080p, whilst with HTML5 I get 170%.  It is worth installing one of the many Firefox extensions that force YouTube (and other sites) to use the Flash player to lower battery (and fan!) usage.\n\n**N.B.** it seems that if you go above 1080p, the acceleration is no longer used and there is a significant uptick in CPU utilisation\n\n## Touchscreen and Pen\n\nThe driver (`intel-ipts`) is already in the compiled kernel (from the above instructions) so after copying the various binaries described below into place, you should be able to reboot and start using your touchscreen and pen.\n\n**N.B.** you will of course need to pair your the (bluetooth) pen to your laptop\n\n### OpenCL\n\nYou will need the OpenCL kernel binaries that are located in your Windows partition at `%WINDIR%\\INF\\PreciseTouch` and you need to copy the contents of it all to `/lib/firmware/intel/ipts` and add the following symbolic links:\n\n    sudo mkdir -p /lib/firmware/intel/ipts\n    mkdir windows\n    mount mount -o ro /dev/nvme0n1p3 windows\n    sudo cp windows/Windows/INF/PreciseTouch/Intel/SurfaceTouchServicingKernelSKLMSHW0078.bin /lib/firmware/intel/ipts\n    sudo cp windows/Windows/INF/PreciseTouch/Intel/SurfaceTouchServicingDescriptorSKLMSHW0078.bin /lib/firmware/intel/ipts\n    sudo cp windows/Windows/INF/PreciseTouch/Intel/SurfaceTouchServicingSFTConfigSKLMSHW0078.bin /lib/firmware/intel/ipts\n    umount windows\n    rmdir windows\n\n    sudo cp /usr/src/linux/firmware/intel/ipts/ipts_fw_config.bin /lib/firmware/intel/ipts\n    sudo ln -s iaPreciseTouchDescriptor.bin /lib/firmware/intel/ipts/intel_desc.bin\n    sudo ln -s SurfaceTouchServicingDescriptorMSHW0078.bin /lib/firmware/intel/ipts/vendor_desc.bin\n    sudo ln -s SurfaceTouchServicingKernelSKLMSHW0078.bin /lib/firmware/intel/ipts/vendor_kernel.bin\n    sudo ln -s SurfaceTouchServicingSFTConfigMSHW0078.bin /lib/firmware/intel/ipts/config.bin\n\nOnce done, the directory structure should look like:\n\n    $ tree /lib/firmware/intel/ipts\n    /lib/firmware/intel/ipts\n    +-- config.bin -\u003e SurfaceTouchServicingSFTConfigMSHW0078.bin\n    +-- iaPreciseTouchDescriptor.bin\n    +-- intel_desc.bin -\u003e iaPreciseTouchDescriptor.bin\n    +-- ipts_fw_config.bin\n    +-- SurfaceTouchServicingDescriptorMSHW0078.bin\n    +-- SurfaceTouchServicingKernelSKLMSHW0078.bin\n    +-- SurfaceTouchServicingSFTConfigMSHW0078.bin\n    +-- vendor_desc.bin -\u003e SurfaceTouchServicingDescriptorMSHW0078.bin\n    \\-- vendor_kernel.bin -\u003e SurfaceTouchServicingKernelSKLMSHW0078.bin\n\n### GuC Firmware\n\nSince kernel 4.7, the [GuC firmware version has been bumped from 4.3 to 6.1](https://git.kernel.org/cgit/linux/kernel/git/stable/linux-stable.git/commit/?id=ab65cce821cc46ccdc0b62f99bb79f75c1c7412c).  Debian jessie does not have this version so you need to [downlownload it](https://01.org/linuxgraphics/downloads/skylake-guc-6.1):\n\n    curl -s -f https://01.org/sites/default/files/downloads/intelr-graphics-linux/sklgucver61.tar.bz2 \\\n        | tar jxO skl_guc_ver6_1/skl_guc_ver6_1.bin \\\n        | sudo tee /lib/firmware/i915/skl_guc_ver6_1.bin \u003e/dev/null\n    sudo ln -s -f -T skl_guc_ver6_1.bin /lib/firmware/i915/skl_guc_ver6.bin\n\nThe MD5 checksum of `/lib/firmware/i915/skl_guc_ver6_1.bin` should be:\n\n    md5sum /lib/firmware/i915/skl_guc_ver6_1.bin\n    07fa52bd5b7401868cf17105db7dc3ab  /lib/firmware/i915/skl_guc_ver6_1.bin\n\n## Sensors\n\n### `dev_rotation`\n\nThis sensor seems not to do anything for now which means `xrandr` auto-rotation is not available:\n\n    watch -n1 cat /sys/bus/iio/devices/iio\\:device*/in_rot_quaternion_raw\n\n**N.B.** of interest though, is that when you rotate the laptop onto its side, if you have the typing cover still plugged in it gets disabled\n\n### `als`\n\nYou can check the light level by running the following:\n\n    watch -n1 cat /sys/bus/iio/devices/iio\\:device*/in_intensity_both_raw\n\nInteract with the sensor by covering and uncovering sensor located the farthest on the right at the top of the screen.\n\n### `accel_3d`\n\nMove the laptop about whilst running in a terminal:\n\n     watch -n1 cat /sys/bus/iio/devices/iio:device*/in_accel_[xyz]_raw\n\n### `gyro_3d`\n\nMove the laptop about whilst running in a terminal:\n\n     watch -n1 cat /sys/bus/iio/devices/iio:device*/in_anglvel_[xyz]_raw\n\n## SecureBoot\n\nIt is possible to get Debian booting with SecureBoot.  However, as well as having the listed restrictions below, it is a bit of a pain to set up, plus to be frank it is a lot of effort and hassle just to avoid seeing a red padlock on boot.  Indeed there is some slight benefit of security, but if you insist on running untrusted code as root under Linux or administrator under Windows, then it hardly is going to save you ;)\n\nAnyway, if you do want to do this, you should be aware of the following constraints:\n\n * you use the [Linux Foundation Secure Boot System, `PreLoader.efi`](http://blog.hansenpartnership.com/linux-foundation-secure-boot-system-released/)\n * GRUB [cannot load modules](http://askubuntu.com/questions/642653/loopback-module-for-grub-with-secure-boot), so you need to generate a GRUB image with the modules you need built it\n     * the solution below needs you to understand how to get GRUB to the point of being able to load `/boot/grub/grub.cfg`; my example below involves just a dedicated unencrypted non-LVM `/boot` mount point, you might need to adapt the `/tmp/grub.cfg` file accordingly for your own setup\n     * `grub-mkstandalone` simply puts all the modules in a memdisk, so you still get the same problem\n     * building in *all* modules does not work as there is a module (no idea which, let me know if you work it out!) that stops GRUB detecting anything except for procfs\n     * it is really difficult to get a definitive list of what modules you need, it is a bit trial and error, plus you may want extras like `cat`, `lspci`, etc\n     * every time the grub package updates, you *should* rebuild the image and re-enroll it\n\nStart off by going into GRUB, and before Linux boots, go to the command line (pressing 'c').  On the command line, type `lsmod` and note down the modules loaded, now go back to booting into Linux.\n\n**N.B.** for reference, my list is: `fshelp` `ext2` `part_gpt` `boot` `extcmd` `crypto` `terminal` `gettext` `gzio` `normal` `test` `disk` `loadenv` `video` `bufio` `font` `video_fb` `gfxterm` `efi_gop` `efi_uga` `video_bochs` `video_cirrus` `all_video` `gfxterm` `minicmd`\n\nOnce booted, run:\n\n    sudo apt-get install efibootmgr\n    \n    sudo mkdir -p /boot/efi/EFI/PreLoader\n    sudo curl -L -o /boot/efi/EFI/PreLoader/PreLoader.efi http://blog.hansenpartnership.com/wp-uploads/2013/PreLoader.efi\n    sudo curl -L -o /boot/efi/EFI/PreLoader/HashTool.efi  http://blog.hansenpartnership.com/wp-uploads/2013/HashTool.efi\n    \n    sudo efibootmgr -c -d /dev/nvme0n1 -p 1 -L Preloader -l /EFI/PreLoader/PreLoader.efi\n\nNow we generate a suitable GRUB image with built-in configuration we generate and a few extras needed modules:\n\n    cat \u003c\u003cEOF \u003e /tmp/grub.cfg\n    search --no-floppy --fs-uuid --set=prefix $(blkid -o udev $(df /boot/grub/grub.cfg | sed '1d; s/ .*//') | awk -F= '/ID_FS_UUID=/ { print $2 }')\n    configfile (\\$prefix)/grub/grub.cfg\n    EOF\n    \n    sudo grub-mkimage -O x86_64-efi -o /boot/efi/EFI/PreLoader/loader.efi -c /tmp/grub.cfg \\\n        [list of modules from the GRUB `lsmod` run earlier] \\\n        configfile search_fs_uuid search ls reboot halt \\\n        password password_pbkdf2 echo linux linuxefi chain fat efifwsetup\n\nThen reboot into the UEFI GUI interface to configure the boot order to be 'debian' *followed* by 'PreLoader', then under Security, set SecureBoot to 'Microsoft \u0026 3rd party CA'.\n\n**N.B.** we make `debian` the first boot option, so that when you run with SecureBoot disabled, it will boot automatically, whilst with SecureBoot enabled `debian` will be silently skipped and `PreLoader` will be automatically run\n\nNow, when you boot for the first time, you will be asked to enroll `loader.efi`, once done, your laptop will now boot with SecureBoot enabled.\n\n### Troubleshooting\n\nIf you get the following when running `efibootmgr`:\n\n    efibootmgr: Could not set variable Boot0006: No such file or directory\n    efibootmgr: Could not prepare boot variable: No such file or directory\n\nYou will find that if you were to run [`strace`](https://en.wikipedia.org/wiki/Strace) you would find out EFI has run out of space and is coming back with `ENOSPC`.\n\nTo clear up some space, use:\n\n    mkdir /tmp/efivars\n    mount -t efivarfs none /tmp/efivars\n    rm /tmp/efivars/dump-type0-*\n    umount /tmp/efivars\n    \n    rm /sys/fs/pstore/dmesg-efi-*\n\nNow reboot so the EFI firmware can garbage collect and free up the space, then you should be able to continue where you left off.\n\n\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjimdigriz%2Fdebian-mssp4","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjimdigriz%2Fdebian-mssp4","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjimdigriz%2Fdebian-mssp4/lists"}