throughout boot, a PCR in the vTPM is extended Along with the root of this Merkle tree, and later on confirmed because of the KMS right before releasing the HPKE private key. All subsequent reads from the root partition are checked from the Merkle tree. This makes sure that the entire contents of the basis partition are attested and any make an eff