Skip to main content

Tools for ovmf / armvirt firmware volumes

This is a small collection of tools for edk2 firmware images. They support decoding and printing the content of firmware volumes. Variable stores (OVMF_VARS.fd) can be modified, for example to enroll secure boot certificates.

virt-fw-dump

Decodes and prints the content of firmware volumes.

Usage: virt-fw-dump -i <file>.

Try virt-fw-dump --help for more info, there are some options to filter output.

virt-fw-vars

Print and edit variable store volumes. Currently focused on enrolling certificates and enabling secure boot.

Print variables: virt-fw-vars -i <file> --print.

Enroll certificates:

virt-fw-vars \
    --input <template> \
    --output <vars> \
    --enroll-redhat \
    --secure-boot

Try virt-fw-vars --help for more usage information.

virt-fw-vars can handle edk2 variable stores (which are flash firmware volumes) and AWS uefi variable stores. The input format is detected automatically and the same format is used for output.

Working with edk2 variable stores requires a firmware volume as input. Typically the OVMF_VARS.fd file created when building OVMF is used for that (it is an empty variable store).

aws variable stores can also be created from scratch and written to a file with using the --output-aws option.

virt-fw-sigdb

Print and edit efi signature database files, example:

virt-fw-sigdb -i /etc/pki/ca-trust/extracted/edk2/cacerts.bin --print

Try virt-fw-sigdb --help for more usage information.

host-efi-vars

Read efi variables from linux efivarfs and decode/print them.

kernel-bootcfg

Manage efi boot configuration for UKIs (unified kernel images) when using direkt boot (without boot loader like grub or systemd-boot).

pe-dumpinfo

Information dump for pe (the format used by efi) binaries.

pe-listsigs

List signatures and certificate chain for pe binaries. Can also extract certificates & signatures.

using the python modules

There isn't much documentation yet, sorry. Best code reads to get started are probably the test cases (see tests/tests.py) and the code for the virt-fw-vars utility (see virt/firmware/vars.py).

install

Release: pip3 install virt-firmware

Snapshot: pip3 install git+https://gitlab.com/kraxel/virt-firmware.git

TODO list

  • Add more documentation.

contributing

I take MRs.

There is an AI review bot active on the repo which will comment on MRs. It is good at spell checking. Sometimes it offers useful suggestions or catches inconsistencies in the patches. Sometimes it asks for stupid stuff like careful error checking in test cases. Sometimes it suggests to check for error conditions which can not happen, but the bot is apparently not clever enough to see that. Sometimes it suggests code reorganizations where it is more a matter of taste or personal preference whenever you take the one or the other way.

So, don't take the bot too serious.

Release files for virt-firmware 26.9

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for virt-firmware 26.9
File Size Uploaded
virt_firmware-26.9.tar.gz 170.1 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for virt-firmware 26.9
File Interpreter ABI Platform
virt_firmware-26.9-py3-none-any.whl Python 3 none any Details

Total release size: 337.3 kB

Release files / virt_firmware-26.9.tar.gz

Download URL virt_firmware-26.9.tar.gz
Size 170.1 kB
Tags Source
SHA-256 checksum
How to use checksums
abdcfc74b8656173f762655a8d4d44f551342ac9574f1e7afa5cfc7bcd950e65
BLAKE2b-256 checksum
How to use checksums
f1645eaac1494de845d463c48f3f3209d84e8c309487db34b83126ad82ea1b7d
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.14.7

Release files / virt_firmware-26.9-py3-none-any.whl

Download URL virt_firmware-26.9-py3-none-any.whl
Size 167.2 kB
Tags Python 3
SHA-256 checksum
How to use checksums
64d0078e6dd0c82a1df3a97c3cc8a149340068095cf8cfb6beb02005e3194160
BLAKE2b-256 checksum
How to use checksums
12d25bb71bc268ea250d372dffbf6509d7f30f68acdcb92f79d27a47c4d02617
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.14.7

Release history Release notifications | RSS feed

This release

26.9 This release

2 release files

26.8.1

2 release files

26.8

2 release files

26.7.4

2 release files

26.7.3

2 release files

26.7.2

2 release files

26.7.1

2 release files

26.6

2 release files

26.5.4

2 release files

26.5.3

2 release files

26.5.2

2 release files

26.4

2 release files

26.2

2 release files

25.12

2 release files

25.10

2 release files

25.9

2 release files

25.7.3

2 release files

25.7.2

2 release files

25.7

2 release files

25.4.1

2 release files

25.4

2 release files

25.3

2 release files

24.11

2 release files

24.7

2 release files

24.4

2 release files

24.2

2 release files

24.1.1

2 release files

24.1

2 release files

23.11

2 release files

23.10

2 release files

23.9

2 release files

23.6

2 release files

23.5

2 release files

23.4

2 release files

1.8

2 release files

1.7

2 release files

1.6

2 release files

1.5

2 release files

1.4

2 release files

1.3

2 release files

1.2

2 release files

1.1

2 release files

1.0

2 release files

0.98

2 release files

0.97

2 release files

0.96

2 release files

0.95

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page