for the duration of boot, a PCR in the vTPM is extended Along with the root of this Merkle tree, and later on verified because of the KMS right before releasing the HPKE private vital. All subsequent reads from the root partition are checked against the Merkle tree. This ensures that your entire contents of the basis partition are attested and any