[packages/edk2-ovmf] - new, version 202608 (OVMF: UEFI firmware images for x86_64 virtual machines)
arekm
arekm at pld-linux.org
Sun Sep 13 00:57:07 CEST 2026
commit d62150ad46011873bba75ef9785ba2c70b988add
Author: Arkadiusz Miśkiewicz <arekm at maven.pl>
Date: Sun Sep 13 00:35:48 2026 +0200
- new, version 202608 (OVMF: UEFI firmware images for x86_64 virtual machines)
30-edk2-ovmf-x64-sb-enrolled.json | 33 ++++++
40-edk2-ovmf-x64-sb.json | 32 ++++++
50-edk2-ovmf-x64-nosb.json | 33 ++++++
edk2-ovmf-basetools-no-brotli.patch | 10 ++
edk2-ovmf-uninstall-memattr-protocol.patch | 126 +++++++++++++++++++++++
edk2-ovmf.spec | 160 +++++++++++++++++++++++++++++
6 files changed, 394 insertions(+)
---
diff --git a/edk2-ovmf.spec b/edk2-ovmf.spec
new file mode 100644
index 0000000..43e6abb
--- /dev/null
+++ b/edk2-ovmf.spec
@@ -0,0 +1,160 @@
+# NOTE: the firmware itself is compiled with edk2's own toolchain flags
+# (BaseTools/Conf/tools_def.template, GCC tag); %%{rpmcflags} only reach
+# the BaseTools host utilities.
+%define edk2ver 202608
+# CryptoPkg/Library/OpensslLib/openssl submodule commit at edk2-stable%%{edk2ver} (OpenSSL 3.5.7)
+%define openssl_commit 8cf17aaeb4599f8af87fefd810b5b5fee90fe69e
+# Microsoft DBX (revocation list) release, https://github.com/microsoft/secureboot_objects
+%define sbo_ver 1.7.0
+Summary: OVMF - UEFI firmware for x86_64 virtual machines
+Summary(pl.UTF-8): OVMF - firmware UEFI dla maszyn wirtualnych x86_64
+Name: edk2-ovmf
+Version: %{edk2ver}
+Release: 1
+License: BSD+patent (firmware), Apache v2.0 (bundled OpenSSL)
+Group: Applications/System
+Source0: https://github.com/tianocore/edk2/archive/refs/tags/edk2-stable%{edk2ver}.tar.gz
+# Source0-md5: 02735bb4c949f027310c26e541f52c78
+Source1: https://github.com/openssl/openssl/archive/%{openssl_commit}/openssl-8cf17aa.tar.gz
+# Source1-md5: ed255b58a1657618d6de5c57578b59cc
+# qemu firmware descriptors (docs/interop/firmware.json), used by libvirt
+Source2: 30-edk2-ovmf-x64-sb-enrolled.json
+Source3: 40-edk2-ovmf-x64-sb.json
+Source4: 50-edk2-ovmf-x64-nosb.json
+# DBX updates signed by the Microsoft KEK 2011 and KEK 2023 CAs
+Source5: https://github.com/microsoft/secureboot_objects/releases/download/v%{sbo_ver}-signed/edk2-2011-signed-secureboot-binaries.tar.gz?/secureboot-objects-2011-signed-%{sbo_ver}.tar.gz
+# Source5-md5: be66a2576824d196ebc57f5c360f017d
+Source6: https://github.com/microsoft/secureboot_objects/releases/download/v%{sbo_ver}-signed/edk2-2023-signed-secureboot-binaries.tar.gz?/secureboot-objects-2023-signed-%{sbo_ver}.tar.gz
+# Source6-md5: 085653c88c54877598a3a8b404bbb6fb
+Patch0: %{name}-basetools-no-brotli.patch
+# from Fedora/Debian: makes PcdUninstallMemAttrProtocol (and the
+# opt/org.tianocore/UninstallMemAttrProtocol fw_cfg key) work on OvmfPkgX64
+Patch1: %{name}-uninstall-memattr-protocol.patch
+URL: https://github.com/tianocore/tianocore.github.io/wiki/OVMF
+BuildRequires: acpica
+BuildRequires: gcc-c++
+BuildRequires: libuuid-devel
+BuildRequires: nasm
+BuildRequires: python3
+BuildRequires: python3-virt-firmware
+ExclusiveArch: %{x8664}
+BuildRoot: %{tmpdir}/%{name}-%{version}-root-%(id -u -n)
+
+%define _enable_debug_packages 0
+
+%define ovmfdir %{_datadir}/OVMF
+
+%description
+OVMF (Open Virtual Machine Firmware) is a port of the EDK II UEFI
+firmware to QEMU/KVM virtual machines. This package contains the
+x86_64 4 MB flash images: firmware code with and without Secure Boot
+support, matching variable stores (including one with the Microsoft
+UEFI certificates pre-enrolled), a unified image for use with a single
+flash device, and QEMU firmware descriptors.
+
+%description -l pl.UTF-8
+OVMF (Open Virtual Machine Firmware) to port firmware'u UEFI EDK II do
+maszyn wirtualnych QEMU/KVM. Ten pakiet zawiera 4-megabajtowe obrazy
+flash dla x86_64: kod firmware'u z obsługą Secure Boot i bez niej,
+pasujące magazyny zmiennych (w tym jeden ze wstępnie zarejestrowanymi
+certyfikatami UEFI Microsoftu), obraz scalony do użycia z pojedynczym
+urządzeniem flash oraz deskryptory firmware'u dla QEMU.
+
+%prep
+%setup -q -n edk2-edk2-stable%{edk2ver} -a1
+%patch -P0 -p1
+%patch -P1 -p1
+
+rmdir CryptoPkg/Library/OpensslLib/openssl
+mv openssl-%{openssl_commit} CryptoPkg/Library/OpensslLib/openssl
+
+# OVMF and OpenSSL license files share the top-level file names
+cp -p OvmfPkg/License.txt License.OvmfPkg.txt
+cp -p CryptoPkg/Library/OpensslLib/openssl/LICENSE.txt LICENSE.openssl.txt
+
+install -d dbx-2011 dbx-2023
+tar xzf %{SOURCE5} -C dbx-2011
+tar xzf %{SOURCE6} -C dbx-2023
+
+# .dec files declare include paths inside submodules that OVMF never
+# builds; the meta-data parser only checks that the directories exist
+install -d MdePkg/Library/MipiSysTLib/mipisyst/library/include \
+ MdeModulePkg/Library/BrotliCustomDecompressLib/brotli/c/include \
+ CryptoPkg/Library/MbedTlsLib/mbedtls/include/mbedtls \
+ CryptoPkg/Library/MbedTlsLib/mbedtls/library \
+ SecurityPkg/DeviceSecurity/SpdmLib/libspdm/include
+
+%build
+export PYTHON_COMMAND=%{__python3}
+%{__make} -C BaseTools \
+ EXTRA_OPTFLAGS="%{rpmcflags}" \
+ EXTRA_LDFLAGS="%{rpmldflags}"
+
+export WORKSPACE=$(pwd)
+export EDK_TOOLS_PATH=$WORKSPACE/BaseTools
+. ./edksetup.sh BaseTools
+
+# --pcd string values get their quotes from build.py (a bare L prefix).
+# PcdUninstallMemAttrProtocol: older shim/grub crash under strict NX
+# memory protection (same workaround as Debian and Fedora)
+build_ovmf() {
+ build -a X64 -t GCC -b RELEASE -p OvmfPkg/OvmfPkgX64.dsc \
+ %{?__jobs:-n %{__jobs}} \
+ -D FD_SIZE_4MB \
+ -D TPM2_ENABLE=TRUE \
+ -D NETWORK_HTTP_BOOT_ENABLE=TRUE \
+ -D NETWORK_IP6_ENABLE=TRUE \
+ -D NETWORK_TLS_ENABLE=TRUE \
+ --pcd PcdUninstallMemAttrProtocol=TRUE \
+ --pcd 'PcdFirmwareVendor=LPLD Linux distribution of EDK II\0' \
+ --pcd 'PcdFirmwareVersionString=Ledk2-stable%{edk2ver}\0' \
+ "$@"
+}
+
+build_ovmf
+cp -p Build/OvmfX64/RELEASE_GCC/FV/OVMF_CODE.fd OVMF_CODE_4M.fd
+cp -p Build/OvmfX64/RELEASE_GCC/FV/OVMF_VARS.fd OVMF_VARS_4M.fd
+cp -p Build/OvmfX64/RELEASE_GCC/FV/OVMF.fd OVMF_4M.fd
+rm -rf Build/OvmfX64
+
+# the UEFI shell would let any guest bypass Secure Boot
+build_ovmf -D SECURE_BOOT_ENABLE=TRUE -D SMM_REQUIRE=TRUE -D BUILD_SHELL=FALSE
+cp -p Build/OvmfX64/RELEASE_GCC/FV/OVMF_CODE.fd OVMF_CODE_4M.secboot.fd
+
+# throwaway build-time certificate as PK/KEK (a PK is needed to leave
+# Setup Mode), Microsoft KEK and db certificates, Microsoft dbx revocations
+virt-fw-vars \
+ --input Build/OvmfX64/RELEASE_GCC/FV/OVMF_VARS.fd \
+ --output OVMF_VARS_4M.ms.fd \
+ --enroll-generate "PLD Linux" \
+ --set-dbx dbx-2011/dbx_x64_Legacy/dbx_x64_Legacy.efiauth2 \
+ --add-dbx dbx-2023/dbx_x64.efiauth2 \
+ --secure-boot
+
+%install
+rm -rf $RPM_BUILD_ROOT
+install -d $RPM_BUILD_ROOT{%{ovmfdir},%{_datadir}/qemu/firmware}
+
+cp -p OVMF_4M.fd OVMF_CODE_4M.fd OVMF_VARS_4M.fd OVMF_CODE_4M.secboot.fd OVMF_VARS_4M.ms.fd \
+ $RPM_BUILD_ROOT%{ovmfdir}
+ln -sf OVMF_CODE_4M.secboot.fd $RPM_BUILD_ROOT%{ovmfdir}/OVMF_CODE_4M.ms.fd
+
+cp -p %{SOURCE2} %{SOURCE3} %{SOURCE4} $RPM_BUILD_ROOT%{_datadir}/qemu/firmware
+
+%clean
+rm -rf $RPM_BUILD_ROOT
+
+%files
+%defattr(644,root,root,755)
+%doc License.txt License-History.txt License.OvmfPkg.txt LICENSE.openssl.txt OvmfPkg/README
+%dir %{ovmfdir}
+%{ovmfdir}/OVMF_4M.fd
+%{ovmfdir}/OVMF_CODE_4M.fd
+%{ovmfdir}/OVMF_CODE_4M.ms.fd
+%{ovmfdir}/OVMF_CODE_4M.secboot.fd
+%{ovmfdir}/OVMF_VARS_4M.fd
+%{ovmfdir}/OVMF_VARS_4M.ms.fd
+%dir %{_datadir}/qemu/firmware
+%{_datadir}/qemu/firmware/30-edk2-ovmf-x64-sb-enrolled.json
+%{_datadir}/qemu/firmware/40-edk2-ovmf-x64-sb.json
+%{_datadir}/qemu/firmware/50-edk2-ovmf-x64-nosb.json
diff --git a/30-edk2-ovmf-x64-sb-enrolled.json b/30-edk2-ovmf-x64-sb-enrolled.json
new file mode 100644
index 0000000..89b3420
--- /dev/null
+++ b/30-edk2-ovmf-x64-sb-enrolled.json
@@ -0,0 +1,33 @@
+{
+ "description": "OVMF with SB+SMM, SB enabled, MS certs enrolled",
+ "interface-types": [
+ "uefi"
+ ],
+ "mapping": {
+ "device": "flash",
+ "mode": "split",
+ "executable": {
+ "filename": "/usr/share/OVMF/OVMF_CODE_4M.secboot.fd",
+ "format": "raw"
+ },
+ "nvram-template": {
+ "filename": "/usr/share/OVMF/OVMF_VARS_4M.ms.fd",
+ "format": "raw"
+ }
+ },
+ "targets": [
+ {
+ "architecture": "x86_64",
+ "machines": [
+ "pc-q35-*"
+ ]
+ }
+ ],
+ "features": [
+ "acpi-s3",
+ "enrolled-keys",
+ "requires-smm",
+ "secure-boot"
+ ],
+ "tags": []
+}
diff --git a/40-edk2-ovmf-x64-sb.json b/40-edk2-ovmf-x64-sb.json
new file mode 100644
index 0000000..32252e7
--- /dev/null
+++ b/40-edk2-ovmf-x64-sb.json
@@ -0,0 +1,32 @@
+{
+ "description": "OVMF with SB+SMM, empty varstore",
+ "interface-types": [
+ "uefi"
+ ],
+ "mapping": {
+ "device": "flash",
+ "mode": "split",
+ "executable": {
+ "filename": "/usr/share/OVMF/OVMF_CODE_4M.secboot.fd",
+ "format": "raw"
+ },
+ "nvram-template": {
+ "filename": "/usr/share/OVMF/OVMF_VARS_4M.fd",
+ "format": "raw"
+ }
+ },
+ "targets": [
+ {
+ "architecture": "x86_64",
+ "machines": [
+ "pc-q35-*"
+ ]
+ }
+ ],
+ "features": [
+ "acpi-s3",
+ "requires-smm",
+ "secure-boot"
+ ],
+ "tags": []
+}
diff --git a/50-edk2-ovmf-x64-nosb.json b/50-edk2-ovmf-x64-nosb.json
new file mode 100644
index 0000000..de54931
--- /dev/null
+++ b/50-edk2-ovmf-x64-nosb.json
@@ -0,0 +1,33 @@
+{
+ "description": "OVMF without SB+SMM, empty varstore",
+ "interface-types": [
+ "uefi"
+ ],
+ "mapping": {
+ "device": "flash",
+ "mode": "split",
+ "executable": {
+ "filename": "/usr/share/OVMF/OVMF_CODE_4M.fd",
+ "format": "raw"
+ },
+ "nvram-template": {
+ "filename": "/usr/share/OVMF/OVMF_VARS_4M.fd",
+ "format": "raw"
+ }
+ },
+ "targets": [
+ {
+ "architecture": "x86_64",
+ "machines": [
+ "pc-i440fx-*",
+ "pc-q35-*"
+ ]
+ }
+ ],
+ "features": [
+ "acpi-s3",
+ "amd-sev",
+ "amd-sev-es"
+ ],
+ "tags": []
+}
diff --git a/edk2-ovmf-basetools-no-brotli.patch b/edk2-ovmf-basetools-no-brotli.patch
new file mode 100644
index 0000000..b962365
--- /dev/null
+++ b/edk2-ovmf-basetools-no-brotli.patch
@@ -0,0 +1,10 @@
+--- edk2-edk2-stable202608/BaseTools/Source/C/GNUmakefile.orig 2026-08-01 11:28:22.813753232 +0200
++++ edk2-edk2-stable202608/BaseTools/Source/C/GNUmakefile 2026-08-01 11:28:33.386789396 +0200
+@@ -23,7 +23,6 @@
+
+ LIBRARIES = Common
+ APPLICATIONS = \
+- BrotliCompress \
+ VfrCompile \
+ EfiRom \
+ GenFfs \
diff --git a/edk2-ovmf-uninstall-memattr-protocol.patch b/edk2-ovmf-uninstall-memattr-protocol.patch
new file mode 100644
index 0000000..beb545a
--- /dev/null
+++ b/edk2-ovmf-uninstall-memattr-protocol.patch
@@ -0,0 +1,126 @@
+From ce2ccbe03a528cb8039f52e22c35a94c241bc17d Mon Sep 17 00:00:00 2001
+From: Gerd Hoffmann <kraxel at redhat.com>
+Date: Thu, 16 Jan 2025 17:20:38 +0100
+Subject: [PATCH 12/16] OvmfPkg/X64: add
+ opt/org.tianocore/UninstallMemAttrProtocol support
+
+Add support for opt/org.tianocore/UninstallMemAttrProtocol, to allow
+turning off EFI_MEMORY_ATTRIBUTE_PROTOCOL, simliar to ArmVirtPkg.
+
+Signed-off-by: Gerd Hoffmann <kraxel at redhat.com>
+---
+ .../PlatformBootManagerLib.inf | 2 +
+ .../PlatformBootManagerLib/BdsPlatform.c | 63 +++++++++++++++++++
+ 2 files changed, 65 insertions(+)
+
+diff --git a/OvmfPkg/Library/PlatformBootManagerLib/PlatformBootManagerLib.inf b/OvmfPkg/Library/PlatformBootManagerLib/PlatformBootManagerLib.inf
+index 9675eb081f56..cc5959c370e5 100644
+--- a/OvmfPkg/Library/PlatformBootManagerLib/PlatformBootManagerLib.inf
++++ b/OvmfPkg/Library/PlatformBootManagerLib/PlatformBootManagerLib.inf
+@@ -64,6 +64,7 @@ [Pcd]
+ gUefiOvmfPkgTokenSpaceGuid.PcdOvmfFlashVariablesEnable
+ gUefiOvmfPkgTokenSpaceGuid.PcdOvmfHostBridgePciDevId
+ gUefiOvmfPkgTokenSpaceGuid.PcdBootRestrictToFirmware
++ gUefiOvmfPkgTokenSpaceGuid.PcdUninstallMemAttrProtocol
+ gEfiMdeModulePkgTokenSpaceGuid.PcdAcpiS3Enable
+ gEfiMdePkgTokenSpaceGuid.PcdPlatformBootTimeOut
+ gEfiMdePkgTokenSpaceGuid.PcdUartDefaultBaudRate ## CONSUMES
+@@ -82,6 +83,7 @@ [Protocols]
+ gEfiDxeSmmReadyToLockProtocolGuid # PROTOCOL SOMETIMES_PRODUCED
+ gEfiLoadedImageProtocolGuid # PROTOCOL SOMETIMES_PRODUCED
+ gEfiFirmwareVolume2ProtocolGuid # PROTOCOL SOMETIMES_CONSUMED
++ gEfiMemoryAttributeProtocolGuid
+
+ [Guids]
+ gEfiEndOfDxeEventGroupGuid
+diff --git a/OvmfPkg/Library/PlatformBootManagerLib/BdsPlatform.c b/OvmfPkg/Library/PlatformBootManagerLib/BdsPlatform.c
+index 3edb92fabcb7..35bb9d31cc67 100644
+--- a/OvmfPkg/Library/PlatformBootManagerLib/BdsPlatform.c
++++ b/OvmfPkg/Library/PlatformBootManagerLib/BdsPlatform.c
+@@ -1596,6 +1596,49 @@ SaveS3BootScript (
+ ASSERT_EFI_ERROR (Status);
+ }
+
++/**
++ Uninstall the EFI memory attribute protocol if it exists.
++**/
++STATIC
++VOID
++UninstallEfiMemoryAttributesProtocol (
++ VOID
++ )
++{
++ EFI_STATUS Status;
++ EFI_HANDLE Handle;
++ UINTN Size;
++ VOID *MemoryAttributeProtocol;
++
++ Size = sizeof (Handle);
++ Status = gBS->LocateHandle (
++ ByProtocol,
++ &gEfiMemoryAttributeProtocolGuid,
++ NULL,
++ &Size,
++ &Handle
++ );
++
++ if (EFI_ERROR (Status)) {
++ ASSERT (Status == EFI_NOT_FOUND);
++ return;
++ }
++
++ Status = gBS->HandleProtocol (
++ Handle,
++ &gEfiMemoryAttributeProtocolGuid,
++ &MemoryAttributeProtocol
++ );
++ ASSERT_EFI_ERROR (Status);
++
++ Status = gBS->UninstallProtocolInterface (
++ Handle,
++ &gEfiMemoryAttributeProtocolGuid,
++ MemoryAttributeProtocol
++ );
++ ASSERT_EFI_ERROR (Status);
++}
++
+ /**
+ Do the platform specific action after the console is ready
+
+@@ -1616,6 +1659,7 @@ PlatformBootManagerAfterConsole (
+ )
+ {
+ EFI_BOOT_MODE BootMode;
++ BOOLEAN Uninstall;
+
+ DEBUG ((DEBUG_INFO, "PlatformBootManagerAfterConsole\n"));
+
+@@ -1660,6 +1704,25 @@ PlatformBootManagerAfterConsole (
+ //
+ StoreQemuBootOrder ();
+
++ //
++ // Work around shim's terminally broken use of the EFI memory attributes
++ // protocol, by uninstalling it if requested on the QEMU command line.
++ //
++ // E.g.,
++ // -fw_cfg opt/org.tianocore/UninstallMemAttrProtocol,string=y
++ //
++ Uninstall = FixedPcdGetBool (PcdUninstallMemAttrProtocol);
++ QemuFwCfgParseBool ("opt/org.tianocore/UninstallMemAttrProtocol", &Uninstall);
++ DEBUG ((
++ DEBUG_WARN,
++ "%a: %auninstalling EFI memory protocol\n",
++ __func__,
++ Uninstall ? "" : "not "
++ ));
++ if (Uninstall) {
++ UninstallEfiMemoryAttributesProtocol ();
++ }
++
+ //
+ // Process QEMU's -kernel command line option
+ //
+--
+2.55.0
+
================================================================
---- gitweb:
http://git.pld-linux.org/gitweb.cgi/packages/edk2-ovmf.git/commitdiff/d62150ad46011873bba75ef9785ba2c70b988add
More information about the pld-cvs-commit
mailing list