Otherwise vmspawn will still pick up firmware with support
for secure boot.
features: list[str] = []
if firmware == Firmware.uefi_secure_boot:
features += ["secure-boot"]
features: list[str] = []
if firmware == Firmware.uefi_secure_boot:
features += ["secure-boot"]
+ elif firmware.is_uefi():
+ features += ["~secure-boot"]
if config.firmware_variables in (Path("microsoft"), Path("microsoft-mok")):
features += ["enrolled-keys"]
if config.firmware_variables in (Path("microsoft"), Path("microsoft-mok")):
features += ["enrolled-keys"]