R15B: add Windows TPM TBS backend with fail-closed custody recovery - #202
Merged
bitmaster162 merged 5 commits intoSep 19, 2026
Merged
Conversation
…tbs-backend-dpapi-primer-r1
bitmaster162
marked this pull request as ready for review
September 19, 2026 15:28
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
R15B — Windows TPM TBS backend + DPAPI custody + crash-resumable provisioning
Base:
57c90dd4c7f8ec2a47a9d8b8a48e7d9fb1a11eaaHead:
d465e7520fb047aa4a83fa0dfc524f59263984b2Tree:
dfb7a0486823973d40c101b955c232e3ada11819PR patch SHA-256:
5253EB03A1AE39FABBA376DBBECBCAAEAFB456ADFD13DD24E27C9492B600105BPatch bytes: 78460
Changed files: 5
Additions/deletions: +2047 / -0
What R15B adds
Clear/deletion fail-closed remediation
A semantic review found that stale DPAPI custody plus an absent NV handle after an external TPM Clear/deletion could previously be classified as
CUSTODY_ONLYand auto-resume Define.That blocker is closed:
CUSTODY_ONLYis now a hard HOLDEMPTYmay create custody and attempt Define only within the same explicitly authorized invocationFocused exact-head remediation review on
3737b04e4b632b8cc7a2c6b869c1497ee31f0fda:Current-master synchronization
Current
origin/masterwas merged into the feature branch using a normal merge commit:d465e7520fb047aa4a83fa0dfc524f59263984b23737b04e4b632b8cc7a2c6b869c1497ee31f0fda57c90dd4c7f8ec2a47a9d8b8a48e7d9fb1a11eaaPost-sync equivalence proof:
5253EB03A1AE39FABBA376DBBECBCAAEAFB456ADFD13DD24E27C9492B600105B5253EB03A1AE39FABBA376DBBECBCAAEAFB456ADFD13DD24E27C9492B600105BPost-sync reviewer attempts that failed because of external model/provider limits are not counted as evidence.
Exact post-merge validation
On
d465e7520fb047aa4a83fa0dfc524f59263984b2:Provider CI
Natural exact-head checks on
d465e7520fb047aa4a83fa0dfc524f59263984b2:Review state
Hardware / qualification boundary
No TPM/PPI/NV mutation was performed by remediation, master-sync, CI, or this PR metadata gate.
This PR does not authorize or perform:
bind_genesisAuthority boundary
can_trade=falsecapital_permission=DENYdeploy_permission=DENYMarking this PR Ready does not authorize merge.
Actual merge to master requires a new exact Human merge authorization token tied to the frozen base/head/tree/check state.