git: ff2efe65a89a - main - bhyve.8: add details on using TPM with UEFI

From: Roman Bogorodskiy <novel_at_FreeBSD.org>
Date: Sat, 03 Oct 2026 08:21:27 UTC
The branch main has been updated by novel:

URL: https://cgit.FreeBSD.org/src/commit/?id=ff2efe65a89a943beec4dd4cc956f5e075a921be

commit ff2efe65a89a943beec4dd4cc956f5e075a921be
Author:     Roman Bogorodskiy <novel@FreeBSD.org>
AuthorDate: 2026-09-30 17:56:18 +0000
Commit:     Roman Bogorodskiy <novel@FreeBSD.org>
CommitDate: 2026-10-03 08:06:57 +0000

    bhyve.8: add details on using TPM with UEFI
    
    Add a note that UEFI VMs using TPM devices should be configured
    to use a varfile. Some UEFI boot loaders, such as shim, update
    persistent boot variables and then reset the system when a TPM is
    present. Without a writable varfile, the VM may be reset repeatedly.
    
    Add a TPM device example to the examples list.
    
    While here, add a missing "\" to the "uefivm" example, and add ".Pp"
    before the vCPU pinning examples for consistency with other examples.
    
    PR:             287326
    Reviewed by:    michaelo, ziaee
    Sponsored by:   The FreeBSD Foundation
    MFC after:      3 days
    Differential Revision:  https://reviews.freebsd.org/D60181
---
 usr.sbin/bhyve/bhyve.8 | 32 ++++++++++++++++++++++++++++++--
 1 file changed, 30 insertions(+), 2 deletions(-)

diff --git a/usr.sbin/bhyve/bhyve.8 b/usr.sbin/bhyve/bhyve.8
index 606d73ac6602..14d91e0711d1 100644
--- a/usr.sbin/bhyve/bhyve.8
+++ b/usr.sbin/bhyve/bhyve.8
@@ -26,7 +26,7 @@
 .\" OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
 .\" SUCH DAMAGE.
 .\"
-.Dd August 23, 2026
+.Dd October 3, 2026
 .Dt BHYVE 8
 .Os
 .Sh NAME
@@ -831,6 +831,11 @@ The argument
 needs to point to a UNIX domain socket that a
 .Cm swtpm
 process is listening on.
+The
+.Cm swtpm
+utility can be installed from the
+.Pa sysutils/swtpm
+port.
 .El
 .Pp
 The
@@ -843,6 +848,10 @@ Defaults to
 .Cm 2.0 ,
 which is the only version currently supported.
 .El
+.Pp
+When using a TPM with UEFI firmware, the boot ROM should be configured
+with a writable
+.Ar varfile .
 .Ss Boot ROM device backends
 .Sm off
 .Bl -bullet
@@ -1357,7 +1366,7 @@ Be sure to create a per-guest copy of the template VARS file from
 bhyve -c 2 -m 4g -w -H \\
   -s 0,hostbridge \\
   -s 31,lpc -l com1,stdio \\
-  -l bootrom,/usr/local/share/uefi-firmware/BHYVE_UEFI_CODE.fd,BHYVE_UEFI_VARS.fd
+  -l bootrom,/usr/local/share/uefi-firmware/BHYVE_UEFI_CODE.fd,BHYVE_UEFI_VARS.fd \\
    uefivm
 .Ed
 .Pp
@@ -1412,16 +1421,35 @@ bhyve -c 2 -w -H \\
   -n id=0,size=4G,cpus=0-1,domain_policy=prefer:0 \\
    numavm
 .Ed
+.Pp
 To run a virtual machine with a single vCPU pinned to host CPU 12:
 .Bd -literal -offset indent
 bhyve -c 1 -s 0,hostbridge -s 1,lpc -s 2,virtio-blk,/my/image \\
   -l com1,stdio -H -P -m 1G -p 0:12 vm1
 .Ed
+.Pp
 To run a virtual machine with 4 vCPUs pinned to host CPUs 12-15:
 .Bd -literal -offset indent
 bhyve -c 4 -s 0,hostbridge -s 1,lpc -s 2,virtio-blk,/my/image \\
   -l com1,stdio -H -P -m 1G -p 0-3:12-15 vm1
 .Ed
+.Pp
+Run a UEFI virtual machine with a TPM device connected to a running
+.Cm swtpm
+instance listening on
+.Pa /var/run/swtpm/tpm .
+The
+.Pa tpmvm_VARS.fd
+file must be a per-guest copy of the firmware VARS template, as described
+in the UEFI example above:
+.Bd -literal -offset indent
+bhyve -c 2 -m 4g -w -H \\
+  -s 0,hostbridge \\
+  -s 31,lpc -l com1,stdio \\
+  -l tpm,swtpm,/var/run/swtpm/tpm \\
+  -l bootrom,/usr/local/share/uefi-firmware/BHYVE_UEFI_CODE.fd,tpmvm_VARS.fd \\
+   tpmvm
+.Ed
 .Sh SEE ALSO
 .Xr bhyve 4 ,
 .Xr netgraph 4 ,