Coreboot, heads and USB hiding from dom0

I see several topics on USB hiding from dom0, but still don’t understand which command to run in step 5 of this:

because i don’t know if it’s using legacy or EFI.

Both paths exist in /boot

I thought coreboot replaced legacy and UEFI?

Has anyone faced this?

IIRC coreboot and heads don’t support EFI yet, i.e. it’s always legacy boot.

Thanks! I think i survived this, but how can i test that this actually did what’s needed?

Is there some pentesting USB software i can download for that?

coreboot offers UEFI support with the edk2 payload (tianocore, in
past) - just another payload.

