During boot, a PCR of the vTPM is extended with the root of the Merkle tree, and later verified via the KMS right before releasing the HPKE private crucial. All subsequent reads from the root partition are checked in https://victorxtrc272472.yourkwikimage.com/user