From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from firstgate.proxmox.com (firstgate.proxmox.com [212.224.123.68]) by lore.proxmox.com (Postfix) with ESMTPS id EB6BF1FF185 for ; Mon, 17 Nov 2025 13:59:02 +0100 (CET) Received: from firstgate.proxmox.com (localhost [127.0.0.1]) by firstgate.proxmox.com (Proxmox) with ESMTP id C46C61838D; Mon, 17 Nov 2025 13:59:04 +0100 (CET) From: Fiona Ebner To: pve-devel@lists.proxmox.com Date: Mon, 17 Nov 2025 13:58:42 +0100 Message-ID: <20251117125858.143552-1-f.ebner@proxmox.com> X-Mailer: git-send-email 2.47.3 MIME-Version: 1.0 X-Bm-Milter-Handled: 55990f41-d878-4baa-be0a-ee34c49e34d2 X-Bm-Transport-Timestamp: 1763384312234 X-SPAM-LEVEL: Spam detection results: 0 AWL -0.017 Adjusted score from AWL reputation of From: address BAYES_00 -1.9 Bayes spam probability is 0 to 1% DMARC_MISSING 0.1 Missing DMARC policy KAM_DMARC_STATUS 0.01 Test Rule for DKIM or SPF Failure with Strict Alignment RCVD_IN_VALIDITY_CERTIFIED_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. RCVD_IN_VALIDITY_RPBL_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. RCVD_IN_VALIDITY_SAFE_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to Validity was blocked. See https://knowledge.validity.com/hc/en-us/articles/20961730681243 for more information. SPF_HELO_NONE 0.001 SPF: HELO does not publish an SPF Record SPF_PASS -0.001 SPF: sender matches SPF record URIBL_BLOCKED 0.001 ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [qemuserver.pm] Subject: [pve-devel] [PATCH qemu-server] vm start: fix migration regression with Windows by only enrolling EFI certs on cold start X-BeenThere: pve-devel@lists.proxmox.com X-Mailman-Version: 2.1.29 Precedence: list List-Id: Proxmox VE development discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Reply-To: Proxmox VE development discussion Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: pve-devel-bounces@lists.proxmox.com Sender: "pve-devel" The EFI disk can only be exclusively accessed during cold start, so skip check_efi_vars() for migration and resume from hibernation. Also, check_efi_vars() might write the VM configuration, which also cannot be done in the context of migration at this stage, because the configuration does not exist on the target yet and it would result in: > close (rename) atomic file '/etc/pve/nodes/squid176/qemu-server/106.conf' failed: File exists Fixes: c5b3a314 ("fix #6985: ovmf: auto-enroll Microsoft UEFI CA 2023 for Windows") Reported-by: Friedrich Weber Suggested-by: Thomas Lamprecht Signed-off-by: Fiona Ebner --- src/PVE/QemuServer.pm | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/src/PVE/QemuServer.pm b/src/PVE/QemuServer.pm index 9946e445..b39157af 100644 --- a/src/PVE/QemuServer.pm +++ b/src/PVE/QemuServer.pm @@ -5610,7 +5610,11 @@ sub vm_start_nolock { my $storage_hints = generate_storage_hints($conf, 1); PVE::Storage::activate_volumes($storecfg, $vollist, undef, $storage_hints); - check_efi_vars($storecfg, $vmid, $conf) if $conf->{bios} && $conf->{bios} eq 'ovmf'; + # Can only exclusively access EFI disk during cold start. Also, check_efi_vars() might write + # the configuration, which must not be done at this stage of migration on the target. + if (!$statefile && !$resume && $conf->{bios} && $conf->{bios} eq 'ovmf') { + check_efi_vars($storecfg, $vmid, $conf); + } # Note that for certain cases like templates, the configuration is minimized, so need to ensure # the rest of the function here uses the same configuration that was used to build the command -- 2.47.3 _______________________________________________ pve-devel mailing list pve-devel@lists.proxmox.com https://lists.proxmox.com/cgi-bin/mailman/listinfo/pve-devel