Skip to content

efivarfs out of space #235

Description

@non-bin

I have a Framework Laptop 16 7040, with BIOS 4.04, running NixOS.

Similar to #90, running fwupdmgr refresh --force && fwupdmgr get-updates && fwupdmgr update gives the error Not enough efivarfs space, requested 30.7 kB and got 12.5 kB

Sorry for duplicating, but the original is closed and wasn't getting any attention

$ fwupdmgr refresh --force && fwupdmgr get-updates && fwupdmgr update
Authenticating…          ▕ ⣾                                     ▏
Updating lvfs
Authenticating…          ▕⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿▏ Less than one minute remaining…
Successfully downloaded new metadata:
 • 14 devices are updatable
 • 7 devices are supported in the enabled remotes (an update has been published)
Authenticating…          ▕⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿⣿▏
Authenticating…          ▕ ⣾                                     ▏
Devices with no available firmware updates:
 • Windows Production PCA
 • HDMI Expansion Card
 • Hub
 • KEK CA
 • Laptop DB
 • Laptop KEK
 • Option ROM UEFI CA
 • Touchpad
 • WD BLACK SN770 500GB
Devices with the latest available firmware version:
 • Fingerprint Sensor
 • Framework Laptop 16 Keyboard Module
 • Laptop 16 Numpad Module
 • System Firmware
 • UEFI CA
 • Unifying Receiver
Authenticating…          ▕    ⣻                                  ▏
Framework Laptop 16 (AMD Ryzen 7040 Series)

└─UEFI dbx:
  │   Device ID:          362301da643102b9f38477387e2193e57abaa590
  │   Summary:            UEFI revocation database
  │   Current version:    20250902
  │   Minimum Version:    20250902
  │   Vendor:             Microsoft (UEFI:Microsoft)
  │   URL:                https://uefi.org/revocationlistfile
  │   Install Duration:   1 second
  │   Update Error:       Not enough efivarfs space, requested 30.7 kB and got 21.7 kB
  │   GUIDs:              f8ba2887-9411-5c36-9cee-88995bb39731 ← UEFI\CRT_A1117F516A32CEFCBA3F2D1ACE10A87972FD6BBE8FE0D0B996E09E65D802A503&ARCH_X64
  │                       115f7cac-f705-5d34-9a47-37177c3e8514 ← UEFI\CRT_B38FAD316F525F27B27A21B486456C3E4279748BF16893827BF16FE659C0F75E&ARCH_X64
  │   Device Flags:       • Internal device
  │                       • Supported on remote server
  │                       • Needs a reboot after installation
  │                       • Device is usable for the duration of the update
  │                       • Updatable
  │                       • Only version upgrades are allowed
  │                       • Signed Payload
  │                       • Can tag for emulation

  └─Secure Boot dbx Configuration Update:
        New version:      20260402
        Remote ID:        lvfs
        Release ID:       143971
        Summary:          UEFI Secure Boot Forbidden Signature Database
        Variant:          x64
        License:          Proprietary
        Size:             24.6 kB
        Created:          2025-09-02 00:00:00
        Urgency:          High
        Vendor:           Linux Foundation
        Duration:         1 second
        Release Flags:    • Trusted metadata
                          • Is upgrade
        Description:
        This updates the list of forbidden signatures (the "dbx") to the latest release from Microsoft.

        Some insecure bootloaders were added, due to security vulnerabilities that allowed an attacker to bypass UEFI Secure Boot. The additional entries were from:

        • Baramanudi Management Suite
        • EAZ EasyFix
        • Finland Matriculation Examination Board
        • NTC IT ROSA Linux
        • PC-Doctor
        • Spyrus WTGCreator
        • WhiteCanyon blancco
        • Some ancient shim releases for OpenSUSE, Oracle and Red Hat
        Issues:           616257
                          CVE-2026-8863
        Checksum:         9edea8bc287bf9bf4659856b28cf421f330eb2f658c163eab0a03512a98c0e78

UEFI dbx is not currently updatable:
 • Not enough efivarfs space, requested 30.7 kB and got 21.7 kB
Devices with the latest available firmware version:
 • Fingerprint Sensor
 • Framework Laptop 16 Keyboard Module
 • Laptop 16 Numpad Module
 • System Firmware
 • UEFI CA
 • Unifying Receiver
Devices with no available firmware updates:
 • Windows Production PCA
 • HDMI Expansion Card
 • Hub
 • KEK CA
 • Laptop DB
 • Laptop KEK
 • Option ROM UEFI CA
 • Touchpad
 • WD BLACK SN770 500GB

$ df -h /sys/firmware/efi/efivars
Filesystem      Size  Used Avail Use% Mounted on
efivarfs        148K  127K   17K  89% /sys/firmware/efi/efivars

$ efibootmgr
BootCurrent: 0000
Timeout: 0 seconds
BootOrder: 0000,2001,2002,2003
Boot0000* NixOS-boot    HD(1,GPT,bada045f-6779-44d8-92f7-e193d703d588,0x800,0x100000)/\EFI\NixOS-boot\grubx64.efi
Boot0002* EFI PXE 0 for IPv4 (0C-37-96-80-1B-33)        PciRoot(0x0)/Pci(0x8,0x1)/Pci(0x0,0x3)/USB(6,0)/USB(2,0)/MAC(0c3796801b33,0)/IPv4(0.0.0.0,0,DHCP,0.0.0.0,0.0.0.0,0.0.0.0)RC
Boot2001* EFI USB Device        RC
Boot2002* EFI DVD/CDROM RC
Boot2003* EFI Network   RC

$ sudo ls -la /sys/firmware/efi/efivars
total 0
drwxr-xr-x 2 root root     0 Jul 21 09:11 .
drwxr-xr-x 5 root root     0 Jul 21 09:11 ..
-rw-r--r-- 1 root root    12 Jul 21 09:11 AcpiGlobalVariable-c020489e-6db2-4ef2-9aa5-ca06fc11d36a
-rw-r--r-- 1 root root    32 Jul 21 09:11 ActiveVgaDev-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root    14 Jul 21 09:11 AmdAcpiVar-79941ecd-ed36-49d0-8124-e4c31ac75cd4
-rw-r--r-- 1 root root  1284 Jul 21 09:11 AMD_PBS_SETUP-a339d746-f678-49b3-9fc7-54ce0f9df226
-rw-r--r-- 1 root root    12 Jul 21 09:11 AMD_RAID-fe26a894-d199-47d4-8afa-070e3d54ba86
-rw-r--r-- 1 root root  1667 Jul 21 09:11 AmdSetupPHX-3a997502-647a-4c82-998e-52ef9486a247
-rw-r--r-- 1 root root     5 Jul 21 09:11 AmdVariableProtection-408f573d-65ee-49ed-8bc5-5a32bbeae745
-rw-r--r-- 1 root root   404 Jul 21 09:11 AodCoreInfo-5ed15dc0-edef-4161-9151-6014c4cc630c
-rw-r--r-- 1 root root   404 Jul 21 09:11 AodCoreInfoTemp-5ed15dc0-edef-4161-9151-6014c4cc630c
-rw-r--r-- 1 root root   810 Jul 21 09:11 AodSetupPhx-5ed15dc0-edef-4161-9151-6014c4cc630c
-rw-r--r-- 1 root root   138 Jul 21 09:11 Boot0000-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root   196 Jul 21 09:11 Boot0002-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    46 Jul 21 09:11 Boot2001-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    44 Jul 21 09:11 Boot2002-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    40 Jul 21 09:11 Boot2003-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root     6 Jul 21 09:11 BootCurrent-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root     8 Jul 21 09:11 BootOptionSupport-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    12 Jul 21 09:11 BootOrder-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    52 Jul 21 09:11 Capsule0000-39b68c46-f7fb-441b-b6ec-16b0f69821f3
-rw-r--r-- 1 root root    26 Jul 21 09:11 CapsuleLast-39b68c46-f7fb-441b-b6ec-16b0f69821f3
-rw-r--r-- 1 root root    96 Jul 21 09:11 certdb-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root   112 Jul 21 09:11 certdbv-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root    36 Jul 21 09:11 COMPAL-b697de83-1ab6-42c4-9dee-a806c637818b
-rw-r--r-- 1 root root    53 Jul 21 09:11 ConIn-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    53 Jul 21 09:11 ConInCandidateDev-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root   198 Jul 21 09:11 ConInDev-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    40 Jul 21 09:11 ConOut-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    40 Jul 21 09:11 ConOutCandidateDev-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root    40 Jul 21 09:11 ConOutDev-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root     5 Jul 21 09:11 CurrentPolicy-77fa9abd-0359-4d32-bd60-28f4e78f784b
-rw-r--r-- 1 root root   754 Jul 21 09:11 Custom-a04a27f4-df00-4d42-b552-39511302113d
-rw-r--r-- 1 root root    25 Jul 21 09:11 CustomBootOrder-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root    10 Jul 21 09:11 CustomPlatformLang-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root     5 Jul 21 09:11 CustomSecurity-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root  7399 Jul 21 09:11 db-d719b2cb-3d3a-4596-a3bc-dad00e67656f
-rw-r--r-- 1 root root  8897 Jul 21 09:11 dbDefault-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root 23120 Jul 21 09:11 dbx-d719b2cb-3d3a-4596-a3bc-dad00e67656f
-rw-r--r-- 1 root root 20768 Jul 21 09:11 dbxDefault-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    40 Jul 21 09:11 ErrOutDev-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root     8 Jul 21 09:11 EsrtLastAttemptStatus-6ae76af1-c002-5d64-8e18-658d205acf34
-rw-r--r-- 1 root root     8 Jul 21 09:11 EsrtLastAttemptVersion-6ae76af1-c002-5d64-8e18-658d205acf34
-rw-r--r-- 1 root root   410 Jul 21 09:11 FeData-1f2d63e1-febd-4dc7-9cc5-ba2b1cef9c5b
-rw-r--r-- 1 root root     5 Jul 21 09:11 H2OFormDialogConfig-98ae8272-ce5a-46be-9f5d-d9f9cbbb99f2
-rw-r--r-- 1 root root    12 Jul 21 09:11 IhisiParamBuffer-92e59835-5f42-4e0b-9a84-47c7810ea806
-rw-r--r-- 1 root root  1596 Jul 21 09:11 IP6_CONFIG_IFR_NVDATA-02eea107-98db-400e-9830-460a1542d799
-rw-r--r-- 1 root root  2821 Jul 21 09:11 KEK-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root  4327 Jul 21 09:11 KEKDefault-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root     8 Jul 21 09:11 Lang-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    17 Jul 21 09:11 LangCodes-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root     5 Jul 21 09:11 MemoryOverwriteRequestControl-e20939be-32d4-41be-a150-897f85d49829
-rw-r--r-- 1 root root     5 Jul 21 09:11 MemoryOverwriteRequestControlLock-bb983ccf-151d-40e1-a07b-4a17be168292
-rw-r--r-- 1 root root    12 Jul 21 09:11 MsdmAddress-fd21bf2b-f5d1-46c5-aee3-c60158339239
-rw-r--r-- 1 root root     8 Jul 21 09:11 MTC-eb704011-1402-11d3-8e77-00a0c969723b
-rw-r--r-- 1 root root     5 Jul 21 09:11 NetworkSetup-a04a27f4-df00-4d42-b552-39511302113d
-rw-r--r-- 1 root root     8 Jul 21 09:11 OfflineUniqueIDEKPubCRC-eaec226f-c9a3-477a-a826-ddc716cdc0e3
-rw-r--r-- 1 root root   260 Jul 21 09:11 OfflineUniqueIDEKPub-eaec226f-c9a3-477a-a826-ddc716cdc0e3
-rw-r--r-- 1 root root    12 Jul 21 09:11 OsIndications-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    12 Jul 21 09:11 OsIndicationsSupported-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    87 Jul 21 09:11 PasswordConfig-f72deef6-13ef-4958-b027-0e45ce7fa45e
-rw-r--r-- 1 root root   540 Jul 21 09:11 PBRDevicePath-a9b5f8d2-cb6d-42c2-bc01-b5ffaae4335e
-rw-r--r-- 1 root root     6 Jul 21 09:11 PhysicalBootOrder-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root  1369 Jul 21 09:11 PK-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root  1369 Jul 21 09:11 PKDefault-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    10 Jul 21 09:11 PlatformLang-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    34 Jul 21 09:11 PlatformLangCodes-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    20 Jul 21 09:11 PlugInVgaHandles-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root     5 Jul 21 09:11 RestoreFactoryDefault-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root     5 Jul 21 09:11 SecureBoot-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    96 Jul 21 09:11 SecureBootData-aa1305b9-01f3-4afb-920e-c9b979a852fd
-rw-r--r-- 1 root root     5 Jul 21 09:11 SecureBootEnforce-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root    18 Jul 21 09:11 SecureFlashInfo-382af2bb-ffff-abcd-aaee-cce099338877
-rw-r--r-- 1 root root     5 Jul 21 09:11 SetPcrBanks-8376bdca-5e03-4735-951a-4a74141e5886
-rw-r--r-- 1 root root   754 Jul 21 09:11 Setup-a04a27f4-df00-4d42-b552-39511302113d
-rw-r--r-- 1 root root     5 Jul 21 09:11 SetupMode-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    36 Jul 21 09:11 SignatureSupport-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    16 Jul 21 09:11 StatusCodeLog-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root    14 Jul 21 09:11 Tcg2ConfigInfo-07a66697-d400-4903-b3da-67a61d2b7058
-rw-r--r-- 1 root root    20 Jul 21 09:11 Tcg2PhysicalPresence-aeb9c5c1-94f1-4d02-bfd9-4602db2d3c54
-rw-r--r-- 1 root root     8 Jul 21 09:11 Tcg2PhysicalPresenceFlags-aeb9c5c1-94f1-4d02-bfd9-4602db2d3c54
-rw-r--r-- 1 root root     6 Jul 21 09:11 Timeout-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root    12 Jul 21 09:11 TrEEPhysicalPresence-f24643c2-c622-494e-8a0d-4632579c2d5b
-rw-r--r-- 1 root root     5 Jul 21 09:11 TrEEPhysicalPresenceFlags-f24643c2-c622-494e-8a0d-4632579c2d5b
-rw-r--r-- 1 root root     5 Jul 21 09:11 UmaCarveOutDefault-0e5ce58d-e59b-4f93-904a-6ef2b97a41d7
-rw-r--r-- 1 root root    36 Jul 21 09:11 UnlockIDCopy-eaec226f-c9a3-477a-a826-ddc716cdc0e3
-rw-r--r-- 1 root root    76 Jul 21 09:11 UserVgaSelection-59d1c24f-50f1-401a-b101-f33e0daed443
-rw-r--r-- 1 root root     5 Jul 21 09:11 VarErrorFlag-04b37fe8-f6ae-480b-bdd5-37d98c5e89aa
-rw-r--r-- 1 root root     5 Jul 21 09:11 VendorKeys-8be4df61-93ca-11d2-aa0d-00e098032b8c
-rw-r--r-- 1 root root  4659 Jul 21 09:11 WIFI_MANAGER_IFR_NVDATA-9f94d327-0b18-4245-8ff2-832e300d2cef

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions