Skip to content

Conversation

@chrisccoulson
Copy link
Collaborator

This adds a dedicated function for detecting whether the partial
mitigation against discrete TPM reset attacks should be enabled. It also
only enables it on Intel platforms, something that PR: #472 achieves by
making isTPMDiscrete lie instead.

The associated CheckResultFlags are also cleaned up, keeping backwards
compatibility with the original flags when unmarshalling.

@chrisccoulson chrisccoulson force-pushed the preinstall-cleanup-partial-reset-attack-mitigation branch from 5e58e84 to 796133c Compare December 2, 2025 10:32
This adds a dedicated function for detecting whether the partial
mitigation against discrete TPM reset attacks should be enabled. It also
only enables it on Intel platforms, something that PR: canonical#472 achieves by
making isTPMDiscrete lie instead.

The associated CheckResultFlags are also cleaned up, keeping backwards
compatibility with the original flags when unmarshalling.
@chrisccoulson chrisccoulson force-pushed the preinstall-cleanup-partial-reset-attack-mitigation branch from 796133c to 532f070 Compare December 2, 2025 19:26
@chrisccoulson chrisccoulson marked this pull request as ready for review December 2, 2025 19:26
@pedronis
Copy link
Collaborator

pedronis commented Dec 4, 2025

@chrisccoulson there are conflicts now in this one

@chrisccoulson
Copy link
Collaborator Author

@chrisccoulson there are conflicts now in this one

I've fixed that now.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants