Hi all,
I've been following Genode/Sculpt OS and the recent discussions around Secure Boot. I saw Johannes Lötzsch's post on the 2026 roadmap thread back in January where he described his partial setup (TrustedGRUB/Lanzaboote for the kernel, but the Sculpt image and GENODE* configs unsigned), and Norman's reply that the topic "screams to be addressed in 2026."
Now that we're halfway through 2026 and Sculpt 26.04 has shipped, I wanted to ask:
Is there any progress on a full verified boot chain? Even a rough plan or list of blockers would be interesting to hear.
Johannes mentioned using Lanzaboote with custom keys — is that still the best community approach today, or has anyone managed to go further (signed system image, measured GENODE* partition, TPM integration)?
For someone who wants to contribute here — what's the smallest useful piece that could move this forward? Is it documentation of the existing hack, build-system work, a design discussion on how to handle the dynamic depot model, something else?
I think Sculpt's runtime security architecture is genuinely unmatched, but telling users to disable Secure Boot to run it is a hard sell. I'd love to see this gap closed.
Thanks
Alex