Skip to content

Clarify Dogebox-WG ownership of NanoPC-T6 secure-boot PTA client - #14

Draft
edtubbs with Copilot wants to merge 9 commits into
mainfrom
copilot/enable-secure-boot-dogebox-os
Draft

Clarify Dogebox-WG ownership of NanoPC-T6 secure-boot PTA client#14
edtubbs with Copilot wants to merge 9 commits into
mainfrom
copilot/enable-secure-boot-dogebox-os

Conversation

Copilot AI commented Mar 6, 2026

Copy link
Copy Markdown

The issue was ambiguity around whether Dogebox OS must be the Rockchip secure-boot PTA client and, if an OS-side client is needed, which Dogebox-WG project should own it. This PR tightens the NanoPC-T6 docs to make client responsibility explicit.

  • PTA invocation model

    • Clarifies that enabling CFG_RK_SECURE_BOOT=y only exposes the OP-TEE pseudo-TA API.
    • States invocation is explicit (not automatic) and can come from either U-Boot or Linux userspace.
  • Dogebox-WG project ownership

    • Adds explicit guidance that OS-side client implementation should live in dogeboxd (or a dogeboxd root helper), aligning with dogeboxd’s host-level orchestration/privileged responsibility.
  • Documentation scope

    • Keeps changes localized to NanoPC-T6 secure-boot docs; no runtime/config behavior changes.
Within Dogebox-WG projects, that OS-side client should live in
`dogeboxd` (or a `dogeboxd` root helper), since `dogeboxd` owns host-level
system orchestration and privileged operations.

✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

Co-authored-by: edtubbs <84785904+edtubbs@users.noreply.github.com>
Copilot AI changed the title [WIP] Add secure boot support for Dogebox OS Enable Rockchip secure-boot PTA in NanoPC-T6 OP-TEE build Mar 6, 2026
Co-authored-by: edtubbs <84785904+edtubbs@users.noreply.github.com>
Copilot AI changed the title Enable Rockchip secure-boot PTA in NanoPC-T6 OP-TEE build Enable Rockchip secure-boot PTA for NanoPC-T6 and document pseudo-TA call path Mar 6, 2026
Co-authored-by: edtubbs <84785904+edtubbs@users.noreply.github.com>
Copilot AI changed the title Enable Rockchip secure-boot PTA for NanoPC-T6 and document pseudo-TA call path Clarify NanoPC-T6 secure-boot pseudo-TA client model Mar 6, 2026
Co-authored-by: edtubbs <84785904+edtubbs@users.noreply.github.com>
Copilot AI changed the title Clarify NanoPC-T6 secure-boot pseudo-TA client model Clarify Dogebox-WG ownership of NanoPC-T6 secure-boot PTA client Mar 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants