From: Christian Ludwig <christian_ludwig@genua.de>
To: <pve-devel@lists.proxmox.com>
Subject: [PATCH v2 pve-manager 14/16] ui: qemu: allow selecting a custom EFI firmware image
Date: Mon, 28 Sep 2026 07:48:18 +0200 [thread overview]
Message-ID: <a5cb17c8822124a5dd3e4ccd2633a665659580a2.1790337878.git@genua.de> (raw)
In-Reply-To: <cover.1790337423.git@genua.de>
Offer a custom EFI firmware image in the BIOS editor, as it modifies
the 'bios' setting rather than being a device of its own. The BIOS
selector gains an 'ovmf-custom' pseudo value, which maps to 'bios=ovmf'
plus an 'efi-firmware' volume and reveals a storage and image selector.
Choosing plain OVMF again deletes the option. The 'bios' hardware row
reflects both keys, so a custom image shows up as 'OVMF (custom)' and
can be reverted while pending.
The image replaces the OVMF code image without touching the EFI vars
store, so only offer it for guests that load the firmware read-only
via '-bios' and have no vars store, i.e. confidential VMs. The API
stays general, so an image that is already set is always shown and can
be cleared, with a hint about the vars store when an EFI disk exists.
Signed-off-by: Christian Ludwig <christian_ludwig@genua.de>
---
www/manager6/Utils.js | 2 +
www/manager6/form/QemuBiosSelector.js | 22 +++-
www/manager6/qemu/Architecture.js | 4 +-
www/manager6/qemu/HardwareView.js | 35 ++++++-
www/manager6/qemu/QemuBiosEdit.js | 140 ++++++++++++++++++++------
5 files changed, 164 insertions(+), 39 deletions(-)
diff --git a/www/manager6/Utils.js b/www/manager6/Utils.js
index 1f1be06b..a4a5ab4b 100644
--- a/www/manager6/Utils.js
+++ b/www/manager6/Utils.js
@@ -552,6 +552,8 @@ Ext.define('PVE.Utils', {
return 'SeaBIOS';
} else if (value === 'ovmf') {
return 'OVMF (UEFI)';
+ } else if (value === 'ovmf-custom') {
+ return gettext('OVMF (custom)');
} else {
return value;
}
diff --git a/www/manager6/form/QemuBiosSelector.js b/www/manager6/form/QemuBiosSelector.js
index 40abb589..62f67e32 100644
--- a/www/manager6/form/QemuBiosSelector.js
+++ b/www/manager6/form/QemuBiosSelector.js
@@ -2,13 +2,25 @@ Ext.define('PVE.form.QemuBiosSelector', {
extend: 'PVE.form.FilteredKVComboBox',
alias: ['widget.pveQemuBiosSelector'],
- comboItems: [
- ['__default__', PVE.Utils.render_qemu_bios('')],
- ['seabios', PVE.Utils.render_qemu_bios('seabios')],
- ['ovmf', PVE.Utils.render_qemu_bios('ovmf')],
- ],
+ withCustomFirmware: false,
allowedValuesPerCategory: PVE.qemu.Architecture.allowedFirmware,
setDefaultDisplay: (arch) => PVE.Utils.render_qemu_bios('', arch),
+
+ initComponent: function () {
+ let me = this;
+
+ me.comboItems = [
+ ['__default__', PVE.Utils.render_qemu_bios('')],
+ ['seabios', PVE.Utils.render_qemu_bios('seabios')],
+ ['ovmf', PVE.Utils.render_qemu_bios('ovmf')],
+ ];
+
+ if (me.withCustomFirmware) {
+ me.comboItems.push(['ovmf-custom', PVE.Utils.render_qemu_bios('ovmf-custom')]);
+ }
+
+ me.callParent();
+ },
});
diff --git a/www/manager6/qemu/Architecture.js b/www/manager6/qemu/Architecture.js
index 7b6ef402..6db8f02e 100644
--- a/www/manager6/qemu/Architecture.js
+++ b/www/manager6/qemu/Architecture.js
@@ -63,8 +63,8 @@ Ext.define('PVE.qemu.Architecture', {
},
allowedFirmware: {
- x86_64: ['__default__', 'seabios', 'ovmf'], // default is seabios
- aarch64: ['ovmf'],
+ x86_64: ['__default__', 'seabios', 'ovmf', 'ovmf-custom'], // default is seabios
+ aarch64: ['ovmf', 'ovmf-custom'],
},
render_vcpu_architecture: function (value) {
diff --git a/www/manager6/qemu/HardwareView.js b/www/manager6/qemu/HardwareView.js
index e6c02299..90dd1c72 100644
--- a/www/manager6/qemu/HardwareView.js
+++ b/www/manager6/qemu/HardwareView.js
@@ -173,7 +173,18 @@ Ext.define('PVE.qemu.HardwareView', {
editor: caps.vms['VM.Config.Options'] ? 'PVE.qemu.BiosEdit' : undefined,
defaultValue: '',
iconCls: 'microchip',
- renderer: PVE.Utils.render_qemu_bios,
+ multiKey: ['bios', 'efi-firmware'],
+ renderer: function (value, metaData, record, ri, ci, store, pending) {
+ let firmware = me.getObjectValue('efi-firmware', undefined, pending);
+ if (firmware && value === 'ovmf') {
+ return Ext.String.format(
+ '{0} ({1})',
+ PVE.Utils.render_qemu_bios('ovmf-custom'),
+ Ext.htmlEncode(firmware),
+ );
+ }
+ return PVE.Utils.render_qemu_bios(value);
+ },
},
vga: {
header: gettext('Display'),
@@ -257,6 +268,15 @@ Ext.define('PVE.qemu.HardwareView', {
affinity: {
visible: false,
},
+ 'efi-firmware': {
+ visible: false,
+ },
+ 'amd-sev': {
+ visible: false,
+ },
+ 'intel-tdx': {
+ visible: false,
+ },
};
PVE.Utils.forEachBus(undefined, function (type, id) {
@@ -438,6 +458,19 @@ Ext.define('PVE.qemu.HardwareView', {
},
};
+ if (rec.data.key === 'bios') {
+ // A custom EFI firmware image replaces the OVMF code image without touching
+ // the EFI vars store. Only offer when EFI vars are not necessary, i.e. for
+ // confidential VMs. Also offer when one is set already.
+ let value = (key) => me.getObjectValue(key, undefined, true);
+ let cvmType =
+ PVE.Parser.parsePropertyString(value('amd-sev'), 'type')?.type ??
+ PVE.Parser.parsePropertyString(value('intel-tdx'), 'type')?.type;
+
+ commonOpts.withCustomFirmware =
+ ['snp', 'tdx'].includes(cvmType) || !!value('efi-firmware');
+ }
+
if (Ext.isString(editor)) {
Ext.create(editor, commonOpts);
} else {
diff --git a/www/manager6/qemu/QemuBiosEdit.js b/www/manager6/qemu/QemuBiosEdit.js
index a637ed25..cd11f45b 100644
--- a/www/manager6/qemu/QemuBiosEdit.js
+++ b/www/manager6/qemu/QemuBiosEdit.js
@@ -1,9 +1,13 @@
-Ext.define('PVE.qemu.BiosEdit', {
- extend: 'Proxmox.window.Edit',
- alias: 'widget.pveQemuBiosEdit',
+Ext.define('PVE.qemu.BiosInputPanel', {
+ extend: 'Proxmox.panel.InputPanel',
+ xtype: 'pveQemuBiosInputPanel',
onlineHelp: 'qm_bios_and_uefi',
- subject: 'BIOS',
+
+ nodename: undefined,
+
+ withCustomFirmware: false,
+ hadCustomFirmware: false,
viewModel: {
data: {
@@ -12,38 +16,100 @@ Ext.define('PVE.qemu.BiosEdit', {
},
formulas: {
showEFIDiskHint: (get) => get('bios') === 'ovmf' && !get('efidisk0'),
+ customFirmware: (get) => get('bios') === 'ovmf-custom',
+ // the vars store of an existing EFI disk is kept as it is, so it can go out of sync
+ showVarStoreHint: (get) => get('bios') === 'ovmf-custom' && !!get('efidisk0'),
},
},
- items: [
- {
- xtype: 'pveQemuBiosSelector',
- onlineHelp: 'qm_bios_and_uefi',
- name: 'bios',
- value: '__default__',
- bind: {
- value: '{bios}',
- category: '{arch}',
+ onGetValues: function (values) {
+ let me = this;
+
+ if (values.bios === 'ovmf-custom') {
+ values.bios = 'ovmf';
+ return values;
+ }
+
+ // Remove custom firmware configuration
+ delete values['efi-firmware'];
+ if (me.hadCustomFirmware) {
+ let deleted = values.delete ? [].concat(values.delete) : [];
+ deleted.push('efi-firmware');
+ values.delete = deleted.join(',');
+ }
+
+ return values;
+ },
+
+ initComponent: function () {
+ let me = this;
+
+ me.items = [
+ {
+ xtype: 'pveQemuBiosSelector',
+ onlineHelp: 'qm_bios_and_uefi',
+ name: 'bios',
+ value: '__default__',
+ withCustomFirmware: me.withCustomFirmware,
+ bind: {
+ value: '{bios}',
+ category: '{arch}',
+ },
+ fieldLabel: 'BIOS',
},
- fieldLabel: 'BIOS',
- },
- {
- xtype: 'displayfield',
- name: 'efidisk0',
- bind: '{efidisk0}',
- hidden: true,
- },
- {
- xtype: 'displayfield',
- userCls: 'pmx-hint',
- value: gettext(
- 'You need to add an EFI disk for storing the EFI settings. See the online help for details.',
- ),
- bind: {
- hidden: '{!showEFIDiskHint}',
+ {
+ xtype: 'displayfield',
+ name: 'efidisk0',
+ bind: '{efidisk0}',
+ hidden: true,
},
- },
- ],
+ {
+ xtype: 'displayfield',
+ userCls: 'pmx-hint',
+ value: gettext(
+ 'You need to add an EFI disk for storing the EFI settings. See the online help for details.',
+ ),
+ bind: {
+ hidden: '{!showEFIDiskHint}',
+ },
+ },
+ {
+ xtype: 'pveIsoSelector',
+ name: 'efi-firmware',
+ storageContent: 'efi-firmware',
+ fileLabel: gettext('Firmware Image'),
+ nodename: me.nodename,
+ hidden: true,
+ disabled: true,
+ bind: {
+ hidden: '{!customFirmware}',
+ disabled: '{!customFirmware}',
+ },
+ },
+ {
+ xtype: 'displayfield',
+ userCls: 'pmx-hint',
+ value: gettext(
+ 'Note: The EFI disk keeps its vars store, which needs to match the custom firmware, otherwise the guest might not boot.',
+ ),
+ bind: {
+ hidden: '{!showVarStoreHint}',
+ },
+ },
+ ];
+
+ me.callParent();
+ },
+});
+
+Ext.define('PVE.qemu.BiosEdit', {
+ extend: 'Proxmox.window.Edit',
+ alias: 'widget.pveQemuBiosEdit',
+
+ onlineHelp: 'qm_bios_and_uefi',
+ subject: 'BIOS',
+
+ withCustomFirmware: false,
initComponent: function () {
let me = this;
@@ -54,6 +120,14 @@ Ext.define('PVE.qemu.BiosEdit', {
throw 'no nodename given';
}
+ me.items = [
+ {
+ xtype: 'pveQemuBiosInputPanel',
+ nodename: me.nodename,
+ withCustomFirmware: me.withCustomFirmware,
+ },
+ ];
+
me.callParent();
if (!me.isCreate) {
@@ -61,6 +135,10 @@ Ext.define('PVE.qemu.BiosEdit', {
success: function ({ result }) {
let values = result.data;
let arch = PVE.qemu.Architecture.getGuestArchitecture(values.arch, me.nodename);
+ if (values['efi-firmware'] && values.bios === 'ovmf') {
+ values.bios = 'ovmf-custom';
+ me.down('pveQemuBiosInputPanel').hadCustomFirmware = true;
+ }
me.setValues(values);
me.down('pveQemuBiosSelector').setCategory(arch);
},
--
2.34.1
next prev parent reply other threads:[~2026-09-28 5:50 UTC|newest]
Thread overview: 17+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 5:47 [PATCH v2 0/16] Support for custom EFI firmware Christian Ludwig
2026-09-28 5:47 ` [PATCH v2 pve-storage 1/16] plugin: add efi-firmware content type Christian Ludwig
2026-09-28 5:47 ` [PATCH v2 pve-storage 2/16] test: get_subdir: cover the " Christian Ludwig
2026-09-28 5:48 ` [PATCH v2 pve-storage 3/16] plugins: allow the efi-firmware content type on file based storages Christian Ludwig
2026-09-28 5:48 ` [PATCH v2 pve-storage 4/16] api: status: support efi-firmware in upload and download-url Christian Ludwig
2026-09-28 5:48 ` [PATCH v2 pve-storage 5/16] test: volume access: cover efi-firmware volumes Christian Ludwig
2026-09-28 5:48 ` [PATCH v2 pve-storage 6/16] test: list volumes: " Christian Ludwig
2026-09-28 5:48 ` [PATCH v2 qemu-server 07/16] config: add the efi-firmware option Christian Ludwig
2026-09-28 5:48 ` [PATCH v2 qemu-server 08/16] api: allow setting " Christian Ludwig
2026-09-28 5:48 ` [PATCH v2 qemu-server 09/16] ovmf: use a custom firmware image if configured Christian Ludwig
2026-09-28 5:48 ` [PATCH v2 qemu-server 10/16] test: efi-firmware key in VM config Christian Ludwig
2026-09-28 5:48 ` [PATCH v2 qemu-server 11/16] test: efi-firmware volumes replication Christian Ludwig
2026-09-28 5:48 ` [PATCH v2 pve-manager 12/16] ui: storage: add efi-firmware content type support Christian Ludwig
2026-09-28 5:48 ` [PATCH v2 pve-manager 13/16] ui: form: support other content types in the ISO selector Christian Ludwig
2026-09-28 5:48 ` Christian Ludwig [this message]
2026-09-28 5:48 ` [PATCH v2 pve-docs 15/16] pvesm: document the efi-firmware content type Christian Ludwig
2026-09-28 5:48 ` [PATCH v2 pve-docs 16/16] qm: document the efi-firmware VM option Christian Ludwig
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=a5cb17c8822124a5dd3e4ccd2633a665659580a2.1790337878.git@genua.de \
--to=christian_ludwig@genua.de \
--cc=pve-devel@lists.proxmox.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox