From cd44b4f1882876fdfb4b7e80ca775a4ca8faa9ea Mon Sep 17 00:00:00 2001 From: Plopmenz Date: Mon, 28 Sep 2026 21:42:18 +0200 Subject: [PATCH] nixos/systemd/tpm2/pcrextend: add pcrosseperator Add new pcrosseperator.service introduced in systemd v261 --- nixos/modules/system/boot/systemd/tpm2.nix | 15 +++++++++++++++ 1 file changed, 15 insertions(+) diff --git a/nixos/modules/system/boot/systemd/tpm2.nix b/nixos/modules/system/boot/systemd/tpm2.nix index de0f72e5a543..09bb3dfa950d 100644 --- a/nixos/modules/system/boot/systemd/tpm2.nix +++ b/nixos/modules/system/boot/systemd/tpm2.nix @@ -29,6 +29,9 @@ boot.initrd.systemd.tpm2.pcrphases.enable = lib.mkEnableOption "systemd initrd boot phase measurements"; + + boot.initrd.systemd.tpm2.pcrosseparator.enable = + lib.mkEnableOption "systemd initrd boot phase OS userspace separator"; }; # TODO: pcrextend, pcrfs, pcrmachine @@ -101,5 +104,17 @@ boot.initrd.systemd.storePaths = [ "${cfg.package}/lib/systemd/systemd-pcrextend" ]; } ) + ( + let + cfg = config.boot.initrd.systemd; + in + lib.mkIf (cfg.enable && cfg.tpm2.enable && cfg.tpm2.pcrosseparator.enable) { + boot.initrd.systemd.additionalUpstreamUnits = [ + "systemd-pcrosseparator.service" + ]; + boot.initrd.systemd.services.systemd-pcrosseparator.wantedBy = [ "initrd.target" ]; + boot.initrd.systemd.storePaths = [ "${cfg.package}/lib/systemd/systemd-pcrextend" ]; + } + ) ]; }