efi/preinstall: support NVIDIA DGX Spark and RTX Spark - #568
Draft
alexclewontin wants to merge 1 commit into
Draft
alexclewontin wants to merge 1 commit into
alexclewontin wants to merge 1 commit into
Conversation
frederic-hoerni
self-requested a review
September 7, 2026 15:50
alexclewontin
force-pushed
the
alexclewontin/check-host-security-dgx-spark
branch
from
September 18, 2026 21:29
b021b67 to
3db51a0
Compare
There was a problem hiding this comment.
🟡 Changes recommended
It reports firmware integrity as verified before validating hardware-root-of-trust fuses or debugger authentication.
Get a fresh assessment by requesting another Copilot review.
Pull request overview
Adds NVIDIA DGX Spark and RTX Spark support to ARM64 preinstall checks.
Changes:
- Detects supported NVIDIA Spark platforms via SMBIOS.
- Classifies their CRB TPM as discrete.
- Adds platform-security dispatch and tests.
File summaries
| File | Description |
|---|---|
efi/preinstall/checks_fixture_test.go |
Adds a DGX Spark host fixture. |
efi/preinstall/check_tpm.go |
Dispatches NVIDIA TPM detection. |
efi/preinstall/check_tpm_nvidia.go |
Implements Spark TPM classification. |
efi/preinstall/check_tpm_nvidia_test.go |
Tests NVIDIA TPM classification. |
efi/preinstall/check_host_security.go |
Dispatches NVIDIA security checks. |
efi/preinstall/check_host_security_test.go |
Tests reset-mitigation status. |
efi/preinstall/check_host_security_nvidia.go |
Adds Spark identification and security handling. |
efi/preinstall/check_host_security_nvidia_test.go |
Tests NVIDIA host-security handling. |
Review details
- Files reviewed: 8/8 changed files
- Comments generated: 2
- Review effort level: Balanced
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
|
|
||
| // TODO: Implement proper debug authentication checks, once we have the documentation | ||
| // from NVIDIA to do so. | ||
| return platformFirmwareIntegrityVerified, nil |
Member
Author
There was a problem hiding this comment.
This is a TODO, will be addressed before the PR is merged
| // Spark platform: either the DGX Spark (exact match on "GB10") or any RTX Spark | ||
| // variant (prefix match on "NVIDIA RTX Spark"). | ||
| func isNvidiaSparkCPUVersion(cpuVersion string) bool { | ||
| return cpuVersion == nvidiaDGXSparkCPUVersion || strings.HasPrefix(cpuVersion, nvidiaRTXSparkCPUVersionPrefix) |
alexclewontin
force-pushed
the
alexclewontin/check-host-security-dgx-spark
branch
from
September 22, 2026 21:34
3db51a0 to
77fceaa
Compare
alexclewontin
force-pushed
the
alexclewontin/check-host-security-dgx-spark
branch
from
September 25, 2026 16:37
77fceaa to
012a729
Compare
alexclewontin
force-pushed
the
alexclewontin/check-host-security-dgx-spark
branch
from
September 25, 2026 16:41
012a729 to
d34e747
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
WIP - stack version of #560
NVIDIA will provide documentation on reading HW ROT and debugger fusing, which will be incorporated before this should be merged.