From 08ebf6d678445ff0765a9e86868258f3807f5f65 Mon Sep 17 00:00:00 2001 From: Daan De Meyer Date: Fri, 5 Jun 2026 09:27:56 +0000 Subject: [PATCH] vmspawn: Exclude secure-boot unless requested Otherwise vmspawn will still pick up firmware with support for secure boot. --- mkosi/vmspawn.py | 2 ++ 1 file changed, 2 insertions(+) diff --git a/mkosi/vmspawn.py b/mkosi/vmspawn.py index a5c2fa03d..8a4b364c9 100644 --- a/mkosi/vmspawn.py +++ b/mkosi/vmspawn.py @@ -64,6 +64,8 @@ def run_vmspawn(args: Args, config: Config) -> None: features: list[str] = [] if firmware == Firmware.uefi_secure_boot: features += ["secure-boot"] + elif firmware.is_uefi(): + features += ["~secure-boot"] if config.firmware_variables in (Path("microsoft"), Path("microsoft-mok")): features += ["enrolled-keys"] -- 2.47.3