"What gives you that impression? What PCR do you see being extended by GRUB with a hash of the initramfs when loaded?"
I found if I update initramfs on Ubuntu 22.04 then PCR9 changes.
I only tested this as below lead me to believe this was an intended behaviour:
https://uapi-group.org/specifications/specs/linux_tpm_pcr_registry/ https://wiki.archlinux.org/title/Trusted_Platform_Module#Accessing_PCR_registers https://www.gnu.org/software/grub/manual/grub/html_node/Measured-Boot.html https://github.com/rhboot/shim/blob/main/README.tpm
Hence when I read your original comment it left me wondering whether I'm misunderstanding something.
"What gives you that impression? What PCR do you see being extended by GRUB
with a hash of the initramfs when loaded?"
I found if I update initramfs on Ubuntu 22.04 then PCR9 changes.
I only tested this as below lead me to believe this was an intended behaviour:
https:/ /uapi-group. org/specificati ons/specs/ linux_tpm_ pcr_registry/ /wiki.archlinux .org/title/ Trusted_ Platform_ Module# Accessing_ PCR_registers /www.gnu. org/software/ grub/manual/ grub/html_ node/Measured- Boot.html /github. com/rhboot/ shim/blob/ main/README. tpm
https:/
https:/
https:/
Hence when I read your original comment it left me wondering whether I'm misunderstanding something.