From nobody Sat Oct 03 08:21:27 2026 X-Original-To: dev-commits-src-all@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hxdsT3lzTz6tvtW for ; Sat, 03 Oct 2026 08:21:33 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange x25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hxdsT27ssz4dtH for ; Sat, 03 Oct 2026 08:21:33 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1791015693; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=UD+bswYSxJpRwtXM9BluNTIaZ8PbOD/2A6JCko8R8a8=; b=Cr8Cvfeed/Gue2oYwKne+Zpsc7CGvagjIm1aizLHCMjZTjuRaAGmg/EV39803xmxpG6X2q AEVFZZiiEfme5HCRIiujYqZO25RR6frikFgGCNOt1pmfXFBmRsYJkBX3l1HfDyWd5hUsta w/cF2/jbBXil0Dm6RzbnJJPdmSCAyDnGoPCaZXwyZXIz+i5VdunNOO8sIJ5y9y+AMwQBrv +daHtyfL0+l6tS+xTr/CUYhEIGinp2MfLNWr0rLcDCHJHgYziwoY07QhMVKx+XyaiTSRiz mtJvmvMrUPcVuRuHeQPdVH6H8g5St64HCQ8HiYnpSTKke/0lVJftHfnRSuBu6Q== ARC-Seal: i=1; a=rsa-sha256; d=freebsd.org; s=dkim; cv=none; t=1791015693; b=ogb3syOGoZWyAXVtYyi5ImA2gKr9+3d8q4b84KPorw5kOLbvqe7ZaFCN7dl2n9IPBjS6M5 1I+MV1sIR3u9REu80Go70toQ9pXhvsQeX3b+9rxFdwg1ih5AxyrfEOaDogKYLwAbzDp1Y8 +t7YWUDcwRn2WHKgauAt7uPr/s9BZq/aOBnpBgVxBJhDR7/4PzhYx8QDslz7OM5jakOdwY lS0KXrFXZjazLrfRF9jDbyrrmQYLmeAorKwId8CWNNIBQ8AaT7ipI+DEA1O9RYszED76wB 5GYz0WIrS0GD31Xgsuac99+LRsVe+6aDqV3W7Sdr8nv1v8xRrsmH+6Ubov7hjg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1791015693; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=UD+bswYSxJpRwtXM9BluNTIaZ8PbOD/2A6JCko8R8a8=; b=KakSjroxDihNDKb7/UmpiZYhdKV2Km45oz+0hyuF2JtsbJ3GuB1x03SHBcXF4m6OANn2PM rtoEcZfH+iyuSTKUcMDIFyuxuKGlJuO6zU2L20CSdjIsSeWjOPXEvYpyotzpoHgRVS1Agl u7NQS/5dgtglabug952nswm37NunMjdWNzds3MoL2sRN+nGh9fuk6SZK6XdQdNkQ7lcPv1 r/x0X5WZs7UQQQZMzO6cNZ//mVIgs3Wf8CFgphvjbp6nsXkSZmI3Gc5YVRxxOLOgdKDyJS bV3Nna3HQCN+4kiA6DRrp6N0oKQi7yx748G37HdzHQ6qH6R/LKCz8caXyFgpkg== ARC-Authentication-Results: i=1; mx1.freebsd.org; none Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hxdsT16ykzwXL for ; Sat, 03 Oct 2026 08:21:33 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3c107 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Sat, 03 Oct 2026 08:21:27 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Roman Bogorodskiy Subject: git: ff2efe65a89a - main - bhyve.8: add details on using TPM with UEFI List-Id: Commit messages for all branches of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-all List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-all@freebsd.org Sender: owner-dev-commits-src-all@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: novel X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: ff2efe65a89a943beec4dd4cc956f5e075a921be Auto-Submitted: auto-generated Date: Sat, 03 Oct 2026 08:21:27 +0000 Message-Id: <6ac0bb07.3c107.bfda2f2@gitrepo.freebsd.org> The branch main has been updated by novel: URL: https://cgit.FreeBSD.org/src/commit/?id=ff2efe65a89a943beec4dd4cc956f5e075a921be commit ff2efe65a89a943beec4dd4cc956f5e075a921be Author: Roman Bogorodskiy AuthorDate: 2026-09-30 17:56:18 +0000 Commit: Roman Bogorodskiy CommitDate: 2026-10-03 08:06:57 +0000 bhyve.8: add details on using TPM with UEFI Add a note that UEFI VMs using TPM devices should be configured to use a varfile. Some UEFI boot loaders, such as shim, update persistent boot variables and then reset the system when a TPM is present. Without a writable varfile, the VM may be reset repeatedly. Add a TPM device example to the examples list. While here, add a missing "\" to the "uefivm" example, and add ".Pp" before the vCPU pinning examples for consistency with other examples. PR: 287326 Reviewed by: michaelo, ziaee Sponsored by: The FreeBSD Foundation MFC after: 3 days Differential Revision: https://reviews.freebsd.org/D60181 --- usr.sbin/bhyve/bhyve.8 | 32 ++++++++++++++++++++++++++++++-- 1 file changed, 30 insertions(+), 2 deletions(-) diff --git a/usr.sbin/bhyve/bhyve.8 b/usr.sbin/bhyve/bhyve.8 index 606d73ac6602..14d91e0711d1 100644 --- a/usr.sbin/bhyve/bhyve.8 +++ b/usr.sbin/bhyve/bhyve.8 @@ -26,7 +26,7 @@ .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF .\" SUCH DAMAGE. .\" -.Dd August 23, 2026 +.Dd October 3, 2026 .Dt BHYVE 8 .Os .Sh NAME @@ -831,6 +831,11 @@ The argument needs to point to a UNIX domain socket that a .Cm swtpm process is listening on. +The +.Cm swtpm +utility can be installed from the +.Pa sysutils/swtpm +port. .El .Pp The @@ -843,6 +848,10 @@ Defaults to .Cm 2.0 , which is the only version currently supported. .El +.Pp +When using a TPM with UEFI firmware, the boot ROM should be configured +with a writable +.Ar varfile . .Ss Boot ROM device backends .Sm off .Bl -bullet @@ -1357,7 +1366,7 @@ Be sure to create a per-guest copy of the template VARS file from bhyve -c 2 -m 4g -w -H \\ -s 0,hostbridge \\ -s 31,lpc -l com1,stdio \\ - -l bootrom,/usr/local/share/uefi-firmware/BHYVE_UEFI_CODE.fd,BHYVE_UEFI_VARS.fd + -l bootrom,/usr/local/share/uefi-firmware/BHYVE_UEFI_CODE.fd,BHYVE_UEFI_VARS.fd \\ uefivm .Ed .Pp @@ -1412,16 +1421,35 @@ bhyve -c 2 -w -H \\ -n id=0,size=4G,cpus=0-1,domain_policy=prefer:0 \\ numavm .Ed +.Pp To run a virtual machine with a single vCPU pinned to host CPU 12: .Bd -literal -offset indent bhyve -c 1 -s 0,hostbridge -s 1,lpc -s 2,virtio-blk,/my/image \\ -l com1,stdio -H -P -m 1G -p 0:12 vm1 .Ed +.Pp To run a virtual machine with 4 vCPUs pinned to host CPUs 12-15: .Bd -literal -offset indent bhyve -c 4 -s 0,hostbridge -s 1,lpc -s 2,virtio-blk,/my/image \\ -l com1,stdio -H -P -m 1G -p 0-3:12-15 vm1 .Ed +.Pp +Run a UEFI virtual machine with a TPM device connected to a running +.Cm swtpm +instance listening on +.Pa /var/run/swtpm/tpm . +The +.Pa tpmvm_VARS.fd +file must be a per-guest copy of the firmware VARS template, as described +in the UEFI example above: +.Bd -literal -offset indent +bhyve -c 2 -m 4g -w -H \\ + -s 0,hostbridge \\ + -s 31,lpc -l com1,stdio \\ + -l tpm,swtpm,/var/run/swtpm/tpm \\ + -l bootrom,/usr/local/share/uefi-firmware/BHYVE_UEFI_CODE.fd,tpmvm_VARS.fd \\ + tpmvm +.Ed .Sh SEE ALSO .Xr bhyve 4 , .Xr netgraph 4 ,