Skip to content

efi/preinstall: support NVIDIA DGX Spark and RTX Spark - #568

Draft
alexclewontin wants to merge 1 commit into
alexclewontin/check-host-security-arm64from
alexclewontin/check-host-security-dgx-spark
Draft

alexclewontin wants to merge 1 commit into
alexclewontin/check-host-security-arm64from
alexclewontin/check-host-security-dgx-spark

Conversation

@alexclewontin

Copy link
Copy Markdown
Member

WIP - stack version of #560

NVIDIA will provide documentation on reading HW ROT and debugger fusing, which will be incorporated before this should be merged.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

It reports firmware integrity as verified before validating hardware-root-of-trust fuses or debugger authentication.

Get a fresh assessment by requesting another Copilot review.

Pull request overview

Adds NVIDIA DGX Spark and RTX Spark support to ARM64 preinstall checks.

Changes:

  • Detects supported NVIDIA Spark platforms via SMBIOS.
  • Classifies their CRB TPM as discrete.
  • Adds platform-security dispatch and tests.
File summaries
File Description
efi/preinstall/checks_fixture_test.go Adds a DGX Spark host fixture.
efi/preinstall/check_tpm.go Dispatches NVIDIA TPM detection.
efi/preinstall/check_tpm_nvidia.go Implements Spark TPM classification.
efi/preinstall/check_tpm_nvidia_test.go Tests NVIDIA TPM classification.
efi/preinstall/check_host_security.go Dispatches NVIDIA security checks.
efi/preinstall/check_host_security_test.go Tests reset-mitigation status.
efi/preinstall/check_host_security_nvidia.go Adds Spark identification and security handling.
efi/preinstall/check_host_security_nvidia_test.go Tests NVIDIA host-security handling.
Review details
  • Files reviewed: 8/8 changed files
  • Comments generated: 2
  • Review effort level: Balanced

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.


// TODO: Implement proper debug authentication checks, once we have the documentation
// from NVIDIA to do so.
return platformFirmwareIntegrityVerified, nil

@alexclewontin alexclewontin Sep 18, 2026 •

Copy link
Copy Markdown
Member Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a TODO, will be addressed before the PR is merged

// Spark platform: either the DGX Spark (exact match on "GB10") or any RTX Spark
// variant (prefix match on "NVIDIA RTX Spark").
func isNvidiaSparkCPUVersion(cpuVersion string) bool {
return cpuVersion == nvidiaDGXSparkCPUVersion || strings.HasPrefix(cpuVersion, nvidiaRTXSparkCPUVersionPrefix)
@alexclewontin
alexclewontin force-pushed the alexclewontin/check-host-security-dgx-spark branch from 3db51a0 to 77fceaa Compare September 22, 2026 21:34
@alexclewontin
alexclewontin force-pushed the alexclewontin/check-host-security-dgx-spark branch from 77fceaa to 012a729 Compare September 25, 2026 16:37
@alexclewontin
alexclewontin force-pushed the alexclewontin/check-host-security-dgx-spark branch from 012a729 to d34e747 Compare September 25, 2026 16:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants