git: ff2efe65a89a - main - bhyve.8: add details on using TPM with UEFI
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Sat, 03 Oct 2026 08:21:27 UTC
The branch main has been updated by novel:
URL: https://cgit.FreeBSD.org/src/commit/?id=ff2efe65a89a943beec4dd4cc956f5e075a921be
commit ff2efe65a89a943beec4dd4cc956f5e075a921be
Author: Roman Bogorodskiy <novel@FreeBSD.org>
AuthorDate: 2026-09-30 17:56:18 +0000
Commit: Roman Bogorodskiy <novel@FreeBSD.org>
CommitDate: 2026-10-03 08:06:57 +0000
bhyve.8: add details on using TPM with UEFI
Add a note that UEFI VMs using TPM devices should be configured
to use a varfile. Some UEFI boot loaders, such as shim, update
persistent boot variables and then reset the system when a TPM is
present. Without a writable varfile, the VM may be reset repeatedly.
Add a TPM device example to the examples list.
While here, add a missing "\" to the "uefivm" example, and add ".Pp"
before the vCPU pinning examples for consistency with other examples.
PR: 287326
Reviewed by: michaelo, ziaee
Sponsored by: The FreeBSD Foundation
MFC after: 3 days
Differential Revision: https://reviews.freebsd.org/D60181
---
usr.sbin/bhyve/bhyve.8 | 32 ++++++++++++++++++++++++++++++--
1 file changed, 30 insertions(+), 2 deletions(-)
diff --git a/usr.sbin/bhyve/bhyve.8 b/usr.sbin/bhyve/bhyve.8
index 606d73ac6602..14d91e0711d1 100644
--- a/usr.sbin/bhyve/bhyve.8
+++ b/usr.sbin/bhyve/bhyve.8
@@ -26,7 +26,7 @@
.\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
.\" SUCH DAMAGE.
.\"
-.Dd August 23, 2026
+.Dd October 3, 2026
.Dt BHYVE 8
.Os
.Sh NAME
@@ -831,6 +831,11 @@ The argument
needs to point to a UNIX domain socket that a
.Cm swtpm
process is listening on.
+The
+.Cm swtpm
+utility can be installed from the
+.Pa sysutils/swtpm
+port.
.El
.Pp
The
@@ -843,6 +848,10 @@ Defaults to
.Cm 2.0 ,
which is the only version currently supported.
.El
+.Pp
+When using a TPM with UEFI firmware, the boot ROM should be configured
+with a writable
+.Ar varfile .
.Ss Boot ROM device backends
.Sm off
.Bl -bullet
@@ -1357,7 +1366,7 @@ Be sure to create a per-guest copy of the template VARS file from
bhyve -c 2 -m 4g -w -H \\
-s 0,hostbridge \\
-s 31,lpc -l com1,stdio \\
- -l bootrom,/usr/local/share/uefi-firmware/BHYVE_UEFI_CODE.fd,BHYVE_UEFI_VARS.fd
+ -l bootrom,/usr/local/share/uefi-firmware/BHYVE_UEFI_CODE.fd,BHYVE_UEFI_VARS.fd \\
uefivm
.Ed
.Pp
@@ -1412,16 +1421,35 @@ bhyve -c 2 -w -H \\
-n id=0,size=4G,cpus=0-1,domain_policy=prefer:0 \\
numavm
.Ed
+.Pp
To run a virtual machine with a single vCPU pinned to host CPU 12:
.Bd -literal -offset indent
bhyve -c 1 -s 0,hostbridge -s 1,lpc -s 2,virtio-blk,/my/image \\
-l com1,stdio -H -P -m 1G -p 0:12 vm1
.Ed
+.Pp
To run a virtual machine with 4 vCPUs pinned to host CPUs 12-15:
.Bd -literal -offset indent
bhyve -c 4 -s 0,hostbridge -s 1,lpc -s 2,virtio-blk,/my/image \\
-l com1,stdio -H -P -m 1G -p 0-3:12-15 vm1
.Ed
+.Pp
+Run a UEFI virtual machine with a TPM device connected to a running
+.Cm swtpm
+instance listening on
+.Pa /var/run/swtpm/tpm .
+The
+.Pa tpmvm_VARS.fd
+file must be a per-guest copy of the firmware VARS template, as described
+in the UEFI example above:
+.Bd -literal -offset indent
+bhyve -c 2 -m 4g -w -H \\
+ -s 0,hostbridge \\
+ -s 31,lpc -l com1,stdio \\
+ -l tpm,swtpm,/var/run/swtpm/tpm \\
+ -l bootrom,/usr/local/share/uefi-firmware/BHYVE_UEFI_CODE.fd,tpmvm_VARS.fd \\
+ tpmvm
+.Ed
.Sh SEE ALSO
.Xr bhyve 4 ,
.Xr netgraph 4 ,