From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from gate001.proxmox.com (gate001.proxmox.com [IPv6:2a0f:8001:1:32::40]) by lore.proxmox.com (Postfix) with ESMTPS id 8AD6C1FF09B for ; Mon, 28 Sep 2026 07:50:40 +0200 (CEST) Received: from gate001.proxmox.com (localhost.localdomain [127.0.0.1]) by gate001.proxmox.com (Proxmox) with ESMTP id BF95921914; Mon, 28 Sep 2026 07:48:45 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=genua.de; s=202307; t=1790574499; bh=T9lYVa/Rs75TXlBPiYRXXe2ZE9nFPj/5WtBKsLIhu64=; h=Date:From:To:Subject:References:In-Reply-To:From; b=ScgTKbIJR3O+ZNDRNFmQD4EOr9avzgFvVvhd45JT6TO77s8K1MWyLyV4ZP/gbEa5r ErpYVlQYigaloW4aAw+o7XfB7AfsU3udjYSjeB6/0R8UdTadQI7wwvdKaRUp51o0RN E4M5nMkYk0nJlr3ThQYUImb/gwPMSR0YFfR1jXfJ6TxhtSdqtO7pHJpzIqOl6dWwHt 0fkMHSCThpun/teDPagFewfSaasN8YAtJF59CGcBnGe95+BMsk4pZCcOUDRv1daVjr K4j6H7cu/JJ5qvyDBe1PCxj6/saomIz0/UT0DozaapmAtORNfWijIVBL7c6Tynhplc uprqttWEeBORQ== Date: Mon, 28 Sep 2026 07:48:18 +0200 From: Christian Ludwig To: Subject: [PATCH v2 pve-manager 14/16] ui: qemu: allow selecting a custom EFI firmware image Message-ID: References: MIME-Version: 1.0 In-Reply-To: X-Originating-IP: [192.168.217.185] X-ClientProxiedBy: kch1-mta08.win.genua.de (10.208.16.108) To kch1-mta07.win.genua.de (10.208.16.107) Content-Type: text/plain; charset="us-ascii" Content-Disposition: inline X-SPAM-LEVEL: Spam detection results: 0 AWL 0.077 Adjusted score from AWL reputation of From: address DKIM_SIGNED 0.1 Message has a DKIM or DK signature, not necessarily valid DKIM_VALID -0.1 Message has at least one valid DKIM or DK signature DKIM_VALID_AU -0.1 Message has a valid DKIM or DK signature from author's domain DKIM_VALID_EF -0.1 Message has a valid DKIM or DK signature from envelope-from domain DMARC_PASS -0.1 DMARC pass policy SPF_HELO_PASS -0.001 SPF: HELO matches SPF record SPF_PASS -0.001 SPF: sender matches SPF record UNPARSEABLE_RELAY 0.001 Informational: message has unparseable relay lines Message-ID-Hash: XQ73O5L4U5UHS4UFOE2LULMQSIRLRZX7 X-Message-ID-Hash: XQ73O5L4U5UHS4UFOE2LULMQSIRLRZX7 X-MailFrom: christian_ludwig@genua.de X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header X-Mailman-Version: 3.3.10 Precedence: list List-Id: Proxmox VE development discussion List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: Offer a custom EFI firmware image in the BIOS editor, as it modifies the 'bios' setting rather than being a device of its own. The BIOS selector gains an 'ovmf-custom' pseudo value, which maps to 'bios=ovmf' plus an 'efi-firmware' volume and reveals a storage and image selector. Choosing plain OVMF again deletes the option. The 'bios' hardware row reflects both keys, so a custom image shows up as 'OVMF (custom)' and can be reverted while pending. The image replaces the OVMF code image without touching the EFI vars store, so only offer it for guests that load the firmware read-only via '-bios' and have no vars store, i.e. confidential VMs. The API stays general, so an image that is already set is always shown and can be cleared, with a hint about the vars store when an EFI disk exists. Signed-off-by: Christian Ludwig --- www/manager6/Utils.js | 2 + www/manager6/form/QemuBiosSelector.js | 22 +++- www/manager6/qemu/Architecture.js | 4 +- www/manager6/qemu/HardwareView.js | 35 ++++++- www/manager6/qemu/QemuBiosEdit.js | 140 ++++++++++++++++++++------ 5 files changed, 164 insertions(+), 39 deletions(-) diff --git a/www/manager6/Utils.js b/www/manager6/Utils.js index 1f1be06b..a4a5ab4b 100644 --- a/www/manager6/Utils.js +++ b/www/manager6/Utils.js @@ -552,6 +552,8 @@ Ext.define('PVE.Utils', { return 'SeaBIOS'; } else if (value === 'ovmf') { return 'OVMF (UEFI)'; + } else if (value === 'ovmf-custom') { + return gettext('OVMF (custom)'); } else { return value; } diff --git a/www/manager6/form/QemuBiosSelector.js b/www/manager6/form/QemuBiosSelector.js index 40abb589..62f67e32 100644 --- a/www/manager6/form/QemuBiosSelector.js +++ b/www/manager6/form/QemuBiosSelector.js @@ -2,13 +2,25 @@ Ext.define('PVE.form.QemuBiosSelector', { extend: 'PVE.form.FilteredKVComboBox', alias: ['widget.pveQemuBiosSelector'], - comboItems: [ - ['__default__', PVE.Utils.render_qemu_bios('')], - ['seabios', PVE.Utils.render_qemu_bios('seabios')], - ['ovmf', PVE.Utils.render_qemu_bios('ovmf')], - ], + withCustomFirmware: false, allowedValuesPerCategory: PVE.qemu.Architecture.allowedFirmware, setDefaultDisplay: (arch) => PVE.Utils.render_qemu_bios('', arch), + + initComponent: function () { + let me = this; + + me.comboItems = [ + ['__default__', PVE.Utils.render_qemu_bios('')], + ['seabios', PVE.Utils.render_qemu_bios('seabios')], + ['ovmf', PVE.Utils.render_qemu_bios('ovmf')], + ]; + + if (me.withCustomFirmware) { + me.comboItems.push(['ovmf-custom', PVE.Utils.render_qemu_bios('ovmf-custom')]); + } + + me.callParent(); + }, }); diff --git a/www/manager6/qemu/Architecture.js b/www/manager6/qemu/Architecture.js index 7b6ef402..6db8f02e 100644 --- a/www/manager6/qemu/Architecture.js +++ b/www/manager6/qemu/Architecture.js @@ -63,8 +63,8 @@ Ext.define('PVE.qemu.Architecture', { }, allowedFirmware: { - x86_64: ['__default__', 'seabios', 'ovmf'], // default is seabios - aarch64: ['ovmf'], + x86_64: ['__default__', 'seabios', 'ovmf', 'ovmf-custom'], // default is seabios + aarch64: ['ovmf', 'ovmf-custom'], }, render_vcpu_architecture: function (value) { diff --git a/www/manager6/qemu/HardwareView.js b/www/manager6/qemu/HardwareView.js index e6c02299..90dd1c72 100644 --- a/www/manager6/qemu/HardwareView.js +++ b/www/manager6/qemu/HardwareView.js @@ -173,7 +173,18 @@ Ext.define('PVE.qemu.HardwareView', { editor: caps.vms['VM.Config.Options'] ? 'PVE.qemu.BiosEdit' : undefined, defaultValue: '', iconCls: 'microchip', - renderer: PVE.Utils.render_qemu_bios, + multiKey: ['bios', 'efi-firmware'], + renderer: function (value, metaData, record, ri, ci, store, pending) { + let firmware = me.getObjectValue('efi-firmware', undefined, pending); + if (firmware && value === 'ovmf') { + return Ext.String.format( + '{0} ({1})', + PVE.Utils.render_qemu_bios('ovmf-custom'), + Ext.htmlEncode(firmware), + ); + } + return PVE.Utils.render_qemu_bios(value); + }, }, vga: { header: gettext('Display'), @@ -257,6 +268,15 @@ Ext.define('PVE.qemu.HardwareView', { affinity: { visible: false, }, + 'efi-firmware': { + visible: false, + }, + 'amd-sev': { + visible: false, + }, + 'intel-tdx': { + visible: false, + }, }; PVE.Utils.forEachBus(undefined, function (type, id) { @@ -438,6 +458,19 @@ Ext.define('PVE.qemu.HardwareView', { }, }; + if (rec.data.key === 'bios') { + // A custom EFI firmware image replaces the OVMF code image without touching + // the EFI vars store. Only offer when EFI vars are not necessary, i.e. for + // confidential VMs. Also offer when one is set already. + let value = (key) => me.getObjectValue(key, undefined, true); + let cvmType = + PVE.Parser.parsePropertyString(value('amd-sev'), 'type')?.type ?? + PVE.Parser.parsePropertyString(value('intel-tdx'), 'type')?.type; + + commonOpts.withCustomFirmware = + ['snp', 'tdx'].includes(cvmType) || !!value('efi-firmware'); + } + if (Ext.isString(editor)) { Ext.create(editor, commonOpts); } else { diff --git a/www/manager6/qemu/QemuBiosEdit.js b/www/manager6/qemu/QemuBiosEdit.js index a637ed25..cd11f45b 100644 --- a/www/manager6/qemu/QemuBiosEdit.js +++ b/www/manager6/qemu/QemuBiosEdit.js @@ -1,9 +1,13 @@ -Ext.define('PVE.qemu.BiosEdit', { - extend: 'Proxmox.window.Edit', - alias: 'widget.pveQemuBiosEdit', +Ext.define('PVE.qemu.BiosInputPanel', { + extend: 'Proxmox.panel.InputPanel', + xtype: 'pveQemuBiosInputPanel', onlineHelp: 'qm_bios_and_uefi', - subject: 'BIOS', + + nodename: undefined, + + withCustomFirmware: false, + hadCustomFirmware: false, viewModel: { data: { @@ -12,38 +16,100 @@ Ext.define('PVE.qemu.BiosEdit', { }, formulas: { showEFIDiskHint: (get) => get('bios') === 'ovmf' && !get('efidisk0'), + customFirmware: (get) => get('bios') === 'ovmf-custom', + // the vars store of an existing EFI disk is kept as it is, so it can go out of sync + showVarStoreHint: (get) => get('bios') === 'ovmf-custom' && !!get('efidisk0'), }, }, - items: [ - { - xtype: 'pveQemuBiosSelector', - onlineHelp: 'qm_bios_and_uefi', - name: 'bios', - value: '__default__', - bind: { - value: '{bios}', - category: '{arch}', + onGetValues: function (values) { + let me = this; + + if (values.bios === 'ovmf-custom') { + values.bios = 'ovmf'; + return values; + } + + // Remove custom firmware configuration + delete values['efi-firmware']; + if (me.hadCustomFirmware) { + let deleted = values.delete ? [].concat(values.delete) : []; + deleted.push('efi-firmware'); + values.delete = deleted.join(','); + } + + return values; + }, + + initComponent: function () { + let me = this; + + me.items = [ + { + xtype: 'pveQemuBiosSelector', + onlineHelp: 'qm_bios_and_uefi', + name: 'bios', + value: '__default__', + withCustomFirmware: me.withCustomFirmware, + bind: { + value: '{bios}', + category: '{arch}', + }, + fieldLabel: 'BIOS', }, - fieldLabel: 'BIOS', - }, - { - xtype: 'displayfield', - name: 'efidisk0', - bind: '{efidisk0}', - hidden: true, - }, - { - xtype: 'displayfield', - userCls: 'pmx-hint', - value: gettext( - 'You need to add an EFI disk for storing the EFI settings. See the online help for details.', - ), - bind: { - hidden: '{!showEFIDiskHint}', + { + xtype: 'displayfield', + name: 'efidisk0', + bind: '{efidisk0}', + hidden: true, }, - }, - ], + { + xtype: 'displayfield', + userCls: 'pmx-hint', + value: gettext( + 'You need to add an EFI disk for storing the EFI settings. See the online help for details.', + ), + bind: { + hidden: '{!showEFIDiskHint}', + }, + }, + { + xtype: 'pveIsoSelector', + name: 'efi-firmware', + storageContent: 'efi-firmware', + fileLabel: gettext('Firmware Image'), + nodename: me.nodename, + hidden: true, + disabled: true, + bind: { + hidden: '{!customFirmware}', + disabled: '{!customFirmware}', + }, + }, + { + xtype: 'displayfield', + userCls: 'pmx-hint', + value: gettext( + 'Note: The EFI disk keeps its vars store, which needs to match the custom firmware, otherwise the guest might not boot.', + ), + bind: { + hidden: '{!showVarStoreHint}', + }, + }, + ]; + + me.callParent(); + }, +}); + +Ext.define('PVE.qemu.BiosEdit', { + extend: 'Proxmox.window.Edit', + alias: 'widget.pveQemuBiosEdit', + + onlineHelp: 'qm_bios_and_uefi', + subject: 'BIOS', + + withCustomFirmware: false, initComponent: function () { let me = this; @@ -54,6 +120,14 @@ Ext.define('PVE.qemu.BiosEdit', { throw 'no nodename given'; } + me.items = [ + { + xtype: 'pveQemuBiosInputPanel', + nodename: me.nodename, + withCustomFirmware: me.withCustomFirmware, + }, + ]; + me.callParent(); if (!me.isCreate) { @@ -61,6 +135,10 @@ Ext.define('PVE.qemu.BiosEdit', { success: function ({ result }) { let values = result.data; let arch = PVE.qemu.Architecture.getGuestArchitecture(values.arch, me.nodename); + if (values['efi-firmware'] && values.bios === 'ovmf') { + values.bios = 'ovmf-custom'; + me.down('pveQemuBiosInputPanel').hadCustomFirmware = true; + } me.setValues(values); me.down('pveQemuBiosSelector').setCategory(arch); }, -- 2.34.1