Replacing Chrome OS with Debian Linux was awkward
Lenovo Thinkpads have historically been the ideal hardware for running Linux, so I was initially optimistic about replacing Chrome OS on a sightly older (but relatively decent spec) laptop. Unfortunately it turned out the laptop was a Chromebook, and the vendor (Google, I’m guessing) really didn’t want anyone replacing the operating system. I spent a few hours looking for ways around that.
The operating system I installed was Debian 13.2.0 (Cinnamon edition), and the installation media was prepared by using Rufus to flash the debian-live-13.2.0-amd64-cinnamon.iso file to a SanDisk USB drive.
The laptop’s firmware
I was ready to modify some BIOS/UEFI configuration to enable legacy mode and disable Secure Boot, then to get straight into running the installer. Instead, I discovered the BIOS/UEFI thingy had been replaced with Google’s firmware, which obstinately refused to run anything that’s not a verified Chrome OS image. The vendor had also removed or concealed the hidden Lenovo UEFI button.
The first thing was to put the Chromebook into Developer Mode, which, if I recall is done by pressing Ctrl+D. This will completely wipe the device, by the way. After 10 or 15 minutes of waiting for the laptop to transition to Developer Mode, follow the Chrome OS setup screens until the one for authenticating the laptop with a WiFi router is displayed - an Internet connection is required for the next steps.
At that point, it should be possible to switch to a Linux terminal. Normally we’d do this with Ctrl+Alt+F2 on a working Linux system. There aren’t any function keys on the Chromebook, per se, but I pressed the second key to the right of ‘Esc’ in place of ‘F2’, and that worked.
Setting up the firmware in the command line
In the terminal, login as ‘chronos’. There shouldn’t be a password for this account. If there is, it would be a default one available somewhere on the Web. A few system parameters need to be set, with the following commands, to allow leacy boot from a USB device:
sudo crossystem dev_boot_usb=1
sudo crossystem dev_boot_legacy=1
sudo crossystem dev_boot_altfw=1
Although one of the parameters enables alternative firmware, it’s likely there won’t be any installed on the laptop (but it’s worth checking anyway, in the initial bootloader screen). For this, I ran a firmware utility developed by MrChromebox. There are other ways of doing it, but this one is the quickest.
In the command line, run the following:
cd; curl -LOf https://mrchromebox.tech/firmware-util.sh && sudo bash firmware-util.sh
Having quickly looked through the script, I should caution it was developed on the assumption that Chromebooks use known partitions for their bootloader and firmware, so there’s a non-zero chance the script will brick a more recent device with write protection disabled.
As I understand it, the Mr Chrome box utility was intended for two use cases:
- The user opens the laptop and disconnects a chip to disable write protection, enabling the script to overwrite Google’s firmware.
- The MrChromebox script writes another bootloader to the firmware partition for a dual boot setup, so both bootloader are picked up when the laptop is started.
I wasn’t inclined to do either, so I allowed the script to add the alternative firmware alongside the default one. After the MrChromebox script does it’s thing, restart the laptop.
First attempt at booting into Linux
The laptop will run the default firmware, and there should be an option to switch to the alternate bootloader. This time, edk2 should be available.
The first time around, I ran into another problem, with the firmware telling me to ‘Verify it contains/points to a valid 64-bit UEFI OS’. A look at the Boot Manager’s file list (press ‘Esc’ at the edk2 splash screen) indicated that I’d stupidy formatted the USB drive with the wrong filesystem, which should be FAT32.
Linux will boot from the hard drive, but…
After reformatting the USB drive and flashing the .iso file to it again, I eventually did get Debian 13.2.0 installed on the Chromebook’s hard drive. If the option to completely erase the hard drive was selected during the installation, edk2 should launch GRUB when it’s selected as the alternate bootloader.
If, on the other hand, Debian was simply installed to partition where Chrome OS was, the GRUB file must be manually selected in the edk2 Boot Manager. To do this, press the ‘Esc’ key at the edk2 splash screen to enter the boot options. Select ‘Boot Manager’, then ‘Boot From File’, and then select the ‘EFI-SYSTEM’ entry from the list. In that filesystem, we want to boot from /efi/Debian/grub64.efi. Assuming that loads, the old familiar GRUB screen is displayed, and the bootloader should launch Linux as normal.
The Caps Lock issue
One other thing: Chromebooks have a search button in place of what should be the Caps Lock key, and this brings up the start menu in the Linux desktop. This was a minor annoyance, as I prefer to use Caps Lock instead of Shift.
To make the key function as Caps Lock again, open the command line, use the ‘xev’ command and press the key to find its keycode. On my laptop, it’s 133.Run the following command to remap the key:
xmodmap -e 'keycode 133 = Caps_Lock'
This command needs to be run every time the laptop is powered up, but we can do this by adding the command to the Startup Applications in the Cinnamon desktop.