From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 0AF0F1FF09B for ; Mon, 28 Sep 2026 07:49:35 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id B8BD2217E1; Mon, 28 Sep 2026 07:48:42 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=genua.de; s=202307; t=1790574489; bh=MfVNxe+Mr+8yZ0k093w2gP97J/00xPmyfeXbEtq8NS8=; h=Date:From:To:Subject:References:In-Reply-To:From; b=UoNUx2TUq+8Rfpoim4chFP/+tXw80eAkwza7dcE5x13N9HzxyTAL9YfC9jn2vuefQ uExbEG3OTR1OKr+z6A92lVjgTSH7NzAzgvGdN+IDSbodMWo43X86zVdR6UFtdWHcpk XPdjsiG/vRvFEmsb4zvJmnJt/d5OO4hjlF7maaSu+8u720Lb26CNUita4BC3h9CFe5 1VS4mT31tkipXWsA8fOAbdYVj7E8V7ofz6eUX58jjKyjlmr40oEb/QZyk4QgviRx/G ll5wXP5i6HQF4UwcafleF2wdCvuYzPv3BiP9GWpNi/oohuCqy55Q2QFA5/D09YCPMX w3ETkhB+J+mVQ== Date: Mon, 28 Sep 2026 07:48:08 +0200 From: Christian Ludwig To: Subject: [PATCH v2 qemu-server 08/16] api: allow setting the efi-firmware option Message-ID: <112600c5d24f1a06ab9049b1b234035c989d0135.1790337726.git@genua.de> References: MIME-Version: 1.0 In-Reply-To: X-Originating-IP: [192.168.217.185] X-ClientProxiedBy: kch1-mta07.win.genua.de (10.208.16.107) To kch1-mta07.win.genua.de (10.208.16.107) Content-Type: text/plain; charset="us-ascii" Content-Disposition: inline X-SPAM-LEVEL: Spam detection results: 0 AWL 0.090 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy SPF_HELO_PASS -0.001 SPF: HELO matches SPF record SPF_PASS -0.001 SPF: sender matches SPF record UNPARSEABLE_RELAY 0.001 Informational: message has unparseable relay lines Message-ID-Hash: 6KRR6Y2QOGYZ2SCSBNAGX4GLEYDHQXDZ X-Message-ID-Hash: 6KRR6Y2QOGYZ2SCSBNAGX4GLEYDHQXDZ X-MailFrom: christian_ludwig@genua.de X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Add the option to the POST/PUT {vmid}/config endpoints. It needs VM.Config.Options permission, like the 'bios' option it modifies, and is rejected without bios=ovmf. Deleting it does not trigger volume cleanup, firmware images are shared. Signed-off-by: Christian Ludwig --- src/PVE/API2/Qemu.pm | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/src/PVE/API2/Qemu.pm b/src/PVE/API2/Qemu.pm index 71247eec..8b12bb53 100644 --- a/src/PVE/API2/Qemu.pm +++ b/src/PVE/API2/Qemu.pm @@ -277,6 +277,10 @@ my $check_storage_access = sub { "/storage/$settings->{vmstatestorage}", ['Datastore.AllocateSpace'], ) if defined($settings->{vmstatestorage}); + + PVE::Storage::check_volume_access( + $rpcenv, $authuser, $storecfg, $vmid, $settings->{'efi-firmware'}, 'efi-firmware', + ) if defined($settings->{'efi-firmware'}); }; my $check_storage_access_clone = sub { @@ -825,6 +829,7 @@ my $generaloptions = { 'autostart' => 1, 'bios' => 1, 'description' => 1, + 'efi-firmware' => 1, 'keyboard' => 1, 'localtime' => 1, 'migrate_downtime' => 1, @@ -1366,6 +1371,9 @@ __PACKAGE__->register_method({ $check_drive_param->($param, $storecfg); + raise_param_exc({ 'efi-firmware' => "requires bios=ovmf" }) + if $param->{'efi-firmware'} && ($param->{bios} // '') ne 'ovmf'; + PVE::QemuServer::Network::add_random_macs($param); } @@ -2527,6 +2535,13 @@ my $update_vm_api = sub { print "automatic pinning of machine version failed - $@" if $@; } $conf->{pending}->{$opt} = $param->{$opt}; + } elsif ($opt eq 'efi-firmware') { + PVE::Storage::check_volume_access( + $rpcenv, $authuser, $storecfg, $vmid, $param->{$opt}, 'efi-firmware', + ); + my $bios = $param->{bios} // $conf->{pending}->{bios} // $conf->{bios} // ''; + raise_param_exc({ $opt => "requires bios=ovmf" }) if $bios ne 'ovmf'; + $conf->{pending}->{$opt} = $param->{$opt}; } elsif ($opt eq 'cipassword') { if (!PVE::QemuServer::Helpers::windows_version($conf->{ostype})) { # Same logic as in cloud-init (but with the regex fixed...) -- 2.34.1