Post-launch research / implementation item. See ADR-010 (DPS over /etc/fstab).
Run chipsec at first boot to detect Absolute Persistence (Computrace) in the PCR event log and other firmware-level anomalies. Package as a DPS-compliant portable service (RootImage=, Verity+PKCS#7 signed GPT image) so it doesn't touch the immutable /usr.
Actions:
ADR: ADR-010
Post-launch research / implementation item. See ADR-010 (DPS over /etc/fstab).
Run
chipsecat first boot to detect Absolute Persistence (Computrace) in the PCR event log and other firmware-level anomalies. Package as a DPS-compliant portable service (RootImage=, Verity+PKCS#7 signed GPT image) so it doesn't touch the immutable /usr.Actions:
yubiOS-enroll.serviceon clean chipsec result (or warn)ADR: ADR-010