systemdTPM2 unseal failed on ECC P-384 TPMs; fix zero-pads ECC point coordinatesmerged 08/2026
https://github.com/systemd/systemd/pull/43396
systemdRFE: .mokkeys module-signing key enrollment; withdrawn after review, the reasons in one commentwithdrawn 09/2026
https://github.com/systemd/systemd/pull/43638#issuecomment-5611922484
bootccomposefs fails with Docker v2s2 media typesopen
https://github.com/bootc-dev/bootc/issues/1703
bootcinstall to-disk with LUKS + TPM brokenopen
https://github.com/bootc-dev/bootc/issues/421
image-builderLUKS partition type in disk customizationsopen
https://github.com/osbuild/image-builder/issues/2609
bootc · composefschunkah re-chunking regressions, filed at backout; four of my fixes merged, two reports openfiled · 4 merged
https://github.com/bootc-dev/bootc/issues/2408 · https://github.com/composefs/composefs-rs/issues/383
the estate:https://gitlab.com/dunn.dev/cairn
the docs:https://cairn.dunn.dev
The two-box grammar and the sealing frame are borrowed with thanks from Mark Russell and Colin Walters of Red Hat, "Trust at every layer: how sealed images extend OS integrity from boot to runtime," May 2026:
https://www.redhat.com/en/blog/how-sealed-images-red-hat-enterprise-linux-extend-os-integrity-boot-runtime