The coverage is calculated into a PCR with the Confidential VM's vTPM (which happens to be matched in The true secret release coverage around the KMS Together with the expected plan hash for that deployment) and https://emiliemfhh822402.like-blogs.com/30220440/little-known-facts-about-samsung-ai-confidential-information