On Sat, Feb 20, 2021 at 01:32:48AM +0000, Matthew Garrett wrote: > +#define TPM_RESTRICTED_PCR 23 As stupid it may sound, I'd just change this to: #define TPM_PCR_23 23 It documents to the code that we are dealing with PCR 23, which just a plain number doesn't. By naming it as TPM_RESTRICED_TPM you have to unnecessarily xref to its definition. It obfuscates rather than clarifies anything important. /Jarkko