From: Daan De Meyer Date: Fri, 5 Jun 2026 09:27:56 +0000 (+0000) Subject: vmspawn: Exclude secure-boot unless requested X-Git-Url: http://git.ipfire.org/gitweb/index.cgi?a=commitdiff_plain;h=HEAD;p=thirdparty%2Fmkosi.git vmspawn: Exclude secure-boot unless requested Otherwise vmspawn will still pick up firmware with support for secure boot. --- diff --git a/mkosi/vmspawn.py b/mkosi/vmspawn.py index a5c2fa03d..8a4b364c9 100644 --- a/mkosi/vmspawn.py +++ b/mkosi/vmspawn.py @@ -64,6 +64,8 @@ def run_vmspawn(args: Args, config: Config) -> None: features: list[str] = [] if firmware == Firmware.uefi_secure_boot: features += ["secure-boot"] + elif firmware.is_uefi(): + features += ["~secure-boot"] if config.firmware_variables in (Path("microsoft"), Path("microsoft-mok")): features += ["enrolled-keys"]