From: Christian Ludwig <christian_ludwig@genua.de>
To: <pve-devel@lists.proxmox.com>, <-b@genua.de>, <cludwig@genua.de>
Subject: [PATCH pve-docs 13/13] qm: Document efi-firmware VM option
Date: Mon, 17 Aug 2026 11:29:38 +0200 [thread overview]
Message-ID: <aoLUgmGa86Jedgs6@pc43.vpn.genua.de> (raw)
In-Reply-To: <e9670c8e-1101-4591-9534-09217632176b@pc43.vpn.genua.de>
[-- Attachment #1: Type: text/plain, Size: 1508 bytes --]
Signed-off-by: Christian Ludwig <christian_ludwig@genua.de>
---
qm.adoc | 33 +++++++++++++++++++++++++++++++++
1 file changed, 33 insertions(+)
diff --git a/qm.adoc b/qm.adoc
index 5b46cdc..141187b 100644
--- a/qm.adoc
+++ b/qm.adoc
@@ -1246,6 +1246,39 @@ NOTE: The markers `ms-cert=2023` and `ms-cert=2023w` may indicate partial
enrollment. The VM start task log will warn about this. You should apply the
enrollment procedure for such EFI disks too.
+[[qm_custom_efi_firmware]]
+Custom EFI Firmware
+^^^^^^^^^^^^^^^^^^^
+
+By default, {pve} uses the system-provided OVMF firmware images. If you need a
+custom or vendor-specific EFI firmware code image, you can override the default
+firmware with the `efi-firmware` VM option.
+
+The firmware image must first be uploaded to a storage that has the
+`efi-firmware` content type enabled.
+
+To configure a VM to use a custom firmware image:
+
+----
+# qm set <vmid> -efi-firmware <storage>:efi-firmware/<name>
+----
+
+For example:
+
+----
+# qm set 100 -efi-firmware local:efi-firmware/custom-ovmf-code.fd
+----
+
+NOTE: The `efi-firmware` option requires `bios` to be set to `ovmf`. The
+custom image replaces only the firmware code (pflash0); the EFI vars disk
+(`efidisk0`) is still used as normal for storing UEFI variables.
+
+To remove a custom firmware assignment and revert to the default OVMF image:
+
+----
+# qm set <vmid> -delete efi-firmware
+----
+
[[qm_tpm]]
Trusted Platform Module (TPM)
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
--
2.34.1
next prev parent reply other threads:[~2026-08-17 9:37 UTC|newest]
Thread overview: 28+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-17 9:29 [PATCH storage/qemu 0/13]: Custom UEFI firmware in PVE Christian Ludwig
2026-08-17 11:59 ` Christian Ludwig
2026-08-17 9:29 ` [PATCH pve-storage 1/13] Add efi-firmware content type Christian Ludwig
2026-08-17 9:29 ` [PATCH pve-storage 2/13] Test for " Christian Ludwig
2026-08-17 9:29 ` [PATCH pve-storage 3/13] Allow efi-firmware in file-based storage Christian Ludwig
2026-08-17 9:29 ` [PATCH pve-storage 4/13] Extend storage API endpoints for efi-firmware Christian Ludwig
2026-08-17 9:29 ` [PATCH pve-storage 5/13] Volume access check test " Christian Ludwig
2026-08-17 9:29 ` [PATCH pve-storage 6/13] efi-firmware storage path to volume conversion test Christian Ludwig
2026-08-17 9:29 ` [PATCH qemu-server 07/13] Add efi-firmware key to VM config schema Christian Ludwig
2026-08-17 9:29 ` [PATCH qemu-server 08/13] Add efi-firmware support to the API Christian Ludwig
2026-08-17 9:29 ` [PATCH qemu-server 09/13] Generate efi-firmware Qemu command line Christian Ludwig
2026-08-17 9:29 ` [PATCH qemu-server 10/13] test: efi-firmware key in VM config Christian Ludwig
2026-08-17 9:29 ` [PATCH qemu-server 11/13] test: efi-firmware volumes replication Christian Ludwig
2026-08-17 9:29 ` [PATCH pve-docs 12/13] pvesm: Document efi-firmware content type Christian Ludwig
2026-08-17 9:29 ` Christian Ludwig [this message]
2026-08-17 11:59 ` [PATCH pve-storage 1/13] Add " Christian Ludwig
2026-08-17 11:59 ` [PATCH pve-storage 2/13] Test for " Christian Ludwig
2026-08-17 11:59 ` [PATCH pve-storage 3/13] Allow efi-firmware in file-based storage Christian Ludwig
2026-08-17 11:59 ` [PATCH pve-storage 4/13] Extend storage API endpoints for efi-firmware Christian Ludwig
2026-08-17 11:59 ` [PATCH pve-storage 5/13] Volume access check test " Christian Ludwig
2026-08-17 11:59 ` [PATCH pve-storage 6/13] efi-firmware storage path to volume conversion test Christian Ludwig
2026-08-17 11:59 ` [PATCH qemu-server 07/13] Add efi-firmware key to VM config schema Christian Ludwig
2026-08-17 11:59 ` [PATCH qemu-server 08/13] Add efi-firmware support to the API Christian Ludwig
2026-08-17 11:59 ` [PATCH qemu-server 09/13] Generate efi-firmware Qemu command line Christian Ludwig
2026-08-17 11:59 ` [PATCH qemu-server 10/13] test: efi-firmware key in VM config Christian Ludwig
2026-08-17 11:59 ` [PATCH qemu-server 11/13] test: efi-firmware volumes replication Christian Ludwig
2026-08-17 11:59 ` [PATCH pve-docs 12/13] pvesm: Document efi-firmware content type Christian Ludwig
2026-08-17 11:59 ` [PATCH pve-docs 13/13] qm: Document efi-firmware VM option Christian Ludwig
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=aoLUgmGa86Jedgs6@pc43.vpn.genua.de \
--to=christian_ludwig@genua.de \
--cc=-b@genua.de \
--cc=cludwig@genua.de \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.