Post #1496960
2026-02-27 16:10 UTC
… TPM event log becomes a cryptographically protected log of every image the OS is composed of. Yay!
(Note: this measurement is done in userspace for now, we hope this can be done from kernel space eventually, and we made sure the measurement is done in a way we can eventually move this.)
Replies (1)
-
@NekkoDroid@social.treehouse.systems 2026-02-27 16:28
@pid_eins There's one type of resource that is probably the most important one to measure on a modern image-based OSes: the images the OS is composed of, as they are activated. Does this mean only things contributing to the root file namespace like base-DDI/sysext/confext or also services like portabled that are added after the fact (e.g. created by a sys admin for a specific system)?