Description
Future measured-boot values can be predicted before a kernel upgrade changes TPM PCR contents. The command helps users of sealed secrets, secure boot, and TPM-bound disk unlock flows plan whether a reboot will still satisfy policy. It reads boot and policy inputs, and a wrong assumption can make recovery keys necessary.