Hello Michael,
Before doing any programming, I have here couple suggestions to you. You should investigate.
Since I am not sure that T420 UEFI BIOS is the same structure as legacy BIOS T400 has (since I remember that T420 is UEFI, legacy/CSM was on - I had one at work since 2011 till 2014). But it is worth trying, nothing to lose.
Knowing that T420 BIOS structure looks like (and I bet it is stored in only one 8MB flash, as my best bet):
You should read your T400 Coreboot flash content, and try to see if it complies with the given above structure. If it does, you are All Cool. Namely, you should try to read GbE region, and see where the MAC address (which you find using Linux command: ifconfig -a). If you appear to find the spot, you are 100% sure you are All Good, since then you'll read another BIOS content, and after you will have lot of possibilities for experiments:
[1] You can reprogram the BIOS from original BIOS to your Coreboot flash rewriting last 0x300000 bytes;
[2] You can rewrite original MAC address to another BIOS, and try to boot;
[3] You can compare/combine regions, and see what'll happen?!
[4] You name it!
I have no idea if you tampered with ME... And no idea if ME for each LENOVO specimen keeps some unique data from/for the platform.
But I am eager to hear/read what did you find investigating about T400 structure, does it looks the same as T420, and et cetera. :-)
You can also read descriptor region, and post it somewhere, so we can peek into it (I remember, I have somewhere some explanations about some of these descriptor region data).
Thank you,
Zoran