@sphinxc0re no coreboot yet - they have Bootguard enabled and the OEM key fuses blown, so it will require their assistance to sign a shim layer after the ACM.
(void*)