Repository navigation
wiki: correct Boot Guard and PCR 0 claims, fix spacing - #250
Merged
Merged
Conversation
tlaurion
force-pushed
the
wiki/fuse-and-spacing-fixes
branch
from
September 17, 2026 23:05
5cb8966 to
4409eb8
Compare
… claim NovaCustom does not always ship unfused keys: units can ship unfused, but production TrustRoot units are provisioned and only accept firmware signed for the provisioned Boot Guard profile. Remove the assertion that most client machines ship verified boot only and therefore leave PCR 0 zero. Nothing supported that sentence, so it is deleted rather than reworded into another generalization. PCR 0 is now described only as receiving an ACM measurement when the platform is provisioned with a Boot Guard profile that includes measurement. The sentence was introduced by this work as linuxboot#249 and propagated into heads doc/tpm.md by linuxboot/heads#2203. Documentation only. Signed-off-by: Thierry Laurion <insurgo@riseup.net>
Add the space after the `"generic"` code span in the PCR 4 boot path list and after the comma before "Heads boots normally" so the rendered prose reads correctly. Signed-off-by: Thierry Laurion <insurgo@riseup.net>
tlaurion
force-pushed
the
wiki/fuse-and-spacing-fixes
branch
from
September 17, 2026 23:07
4409eb8 to
b2c4585
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This corrects the Boot Guard and PCR 0 documentation across the affected pages and fixes two rendering glitches. In
About/Vendors_resellers.md, the claim that NovaCustom's Boot Guard keys are never fused was wrong: units can ship unfused, while production TrustRoot units are provisioned and only accept firmware signed for the provisioned profile. The unsupported assertion that most client machines ship verified boot only, and so leave PCR 0 zero, was removed fromAbout/Keys.mdandAbout/Heads-threat-model.md; PCR 0 is now described only as receiving an ACM measurement when the platform is provisioned with a profile that includes measurement. Two spacing breaks in the rendered prose were also fixed, inAbout/Keys.mdandAbout/FAQ.md. The unsupported claim was introduced by this work as #249 and propagated into headsdoc/tpm.mdby linuxboot/heads#2203; documentation only, no code changes.