public inbox for pve-devel@lists.proxmox.com
 help / color / mirror / Atom feed
From: Christian Ludwig <christian_ludwig@genua.de>
To: <pve-devel@lists.proxmox.com>
Subject: [PATCH v2 0/16] Support for custom EFI firmware
Date: Mon, 28 Sep 2026 07:47:44 +0200	[thread overview]
Message-ID: <cover.1790337423.git@genua.de> (raw)

Hi,

here is an updated patch series that brings support for custom UEFI
firmware images. You can find the v1 series at [1] for reference.

In Confidential Computing the aim is to not trust the hypervisor, yet it
runs its bundled firmware in each VM. Some VM appliances also ship their
own firmware images. This series allows to bring your own firmware for
OVMF based VMs.

Today the Proxmox-VE API allows to import a custom efidisk0 (EFIVAR)
already. EFI firmware and EFIVAR data have to match. Otherwise, the VM
might not boot anymore. Therefore, with this series you can set a custom
EFI firmware via the API, along with a custom efidisk. But these are two
steps. And there is no safety net. The GUI is missing a way to set a
custom EFIVAR. So this series only allows to set a custom firmware image
for confidential computing VMs that do not need EFIVAR storage. The
defaults do not change.

The changes in detail:

pve-storage:
 - declares the new 'efi-firmware' content type for file based storage
 - provides upload/download API. There is no limit in file names,
   besides the usual safe character class

qemu-server:
 - adds a 'efi-firmware' config key that can point to 'efi-firmware'
   storage content
 - that config key is only allowed to be set for OVMF based VMs
 - adds API plumbing

pve-manager:
 - adds UI plumbing for the 'efi-firmware' storage content type
 - extends the BIOS chooser dialog with an 'OVMF (custom)' option

pve-docs:
 - adds a custom firmware subsection in the BIOS section

Note that you choose the cutom firmware from the BIOS dialog in the GUI,
therefore the 'efi-firmware' config key has the 'VM.Config.Options'
permission. The same as the BIOS option that the dialog hosts already.

Changes from v1:
 - GUI additions
 - Move 'efi-firmware' VM config option permissions from
   'VM.Config.HWType' to 'VM.Config.Options'
 - some cleanups

Tests and feedback welcome.


 - Christian

[1] https://lore.proxmox.com/pve-devel/20260817115919.abQyMsVBJeHupthBjG6HbiJWe2o8RfIy9CmAttembto@z/



             reply	other threads:[~2026-09-28  5:48 UTC|newest]

Thread overview: 17+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-28  5:47 Christian Ludwig [this message]
2026-09-28  5:47 ` [PATCH v2 pve-storage 1/16] plugin: add efi-firmware content type Christian Ludwig
2026-09-28  5:47 ` [PATCH v2 pve-storage 2/16] test: get_subdir: cover the " Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 pve-storage 3/16] plugins: allow the efi-firmware content type on file based storages Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 pve-storage 4/16] api: status: support efi-firmware in upload and download-url Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 pve-storage 5/16] test: volume access: cover efi-firmware volumes Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 pve-storage 6/16] test: list volumes: " Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 qemu-server 07/16] config: add the efi-firmware option Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 qemu-server 08/16] api: allow setting " Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 qemu-server 09/16] ovmf: use a custom firmware image if configured Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 qemu-server 10/16] test: efi-firmware key in VM config Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 qemu-server 11/16] test: efi-firmware volumes replication Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 pve-manager 12/16] ui: storage: add efi-firmware content type support Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 pve-manager 13/16] ui: form: support other content types in the ISO selector Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 pve-manager 14/16] ui: qemu: allow selecting a custom EFI firmware image Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 pve-docs 15/16] pvesm: document the efi-firmware content type Christian Ludwig
2026-09-28  5:48 ` [PATCH v2 pve-docs 16/16] qm: document the efi-firmware VM option Christian Ludwig

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=cover.1790337423.git@genua.de \
    --to=christian_ludwig@genua.de \
    --cc=pve-devel@lists.proxmox.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
Service provided by Proxmox Server Solutions GmbH | Privacy | Legal