Skip to content

wiki: correct Boot Guard and PCR 0 claims, fix spacing - #250

Merged
tlaurion merged 2 commits into
linuxboot:masterfrom
tlaurion:wiki/fuse-and-spacing-fixes
Sep 17, 2026
Merged

tlaurion merged 2 commits into
linuxboot:masterfrom
tlaurion:wiki/fuse-and-spacing-fixes

Conversation

@tlaurion

@tlaurion tlaurion commented Sep 17, 2026 •

Copy link
Copy Markdown
Collaborator

This corrects the Boot Guard and PCR 0 documentation across the affected pages and fixes two rendering glitches. In About/Vendors_resellers.md, the claim that NovaCustom's Boot Guard keys are never fused was wrong: units can ship unfused, while production TrustRoot units are provisioned and only accept firmware signed for the provisioned profile. The unsupported assertion that most client machines ship verified boot only, and so leave PCR 0 zero, was removed from About/Keys.md and About/Heads-threat-model.md; PCR 0 is now described only as receiving an ACM measurement when the platform is provisioned with a profile that includes measurement. Two spacing breaks in the rendered prose were also fixed, in About/Keys.md and About/FAQ.md. The unsupported claim was introduced by this work as #249 and propagated into heads doc/tpm.md by linuxboot/heads#2203; documentation only, no code changes.

Copilot AI lite review requested due to automatic review settings September 17, 2026 22:56

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@tlaurion
tlaurion force-pushed the wiki/fuse-and-spacing-fixes branch from 5cb8966 to 4409eb8 Compare September 17, 2026 23:05
… claim

NovaCustom does not always ship unfused keys: units can ship unfused, but
production TrustRoot units are provisioned and only accept firmware signed
for the provisioned Boot Guard profile.

Remove the assertion that most client machines ship verified boot only and
therefore leave PCR 0 zero. Nothing supported that sentence, so it is deleted
rather than reworded into another generalization. PCR 0 is now described only
as receiving an ACM measurement when the platform is provisioned with a Boot
Guard profile that includes measurement. The sentence was introduced by this
work as linuxboot#249 and propagated into heads doc/tpm.md by
linuxboot/heads#2203. Documentation only.

Signed-off-by: Thierry Laurion <insurgo@riseup.net>
Add the space after the `"generic"` code span in the PCR 4 boot path list and after the comma before "Heads boots normally" so the rendered prose reads correctly.

Signed-off-by: Thierry Laurion <insurgo@riseup.net>
@tlaurion
tlaurion force-pushed the wiki/fuse-and-spacing-fixes branch from 4409eb8 to b2c4585 Compare September 17, 2026 23:07
@tlaurion tlaurion changed the title wiki: correct NovaCustom Boot Guard fuse claim and spacing wiki: correct Boot Guard and PCR 0 claims, fix spacing Sep 17, 2026
@tlaurion
tlaurion merged commit 8f76fd8 into linuxboot:master Sep 17, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants