{
    "mode": "man",
    "parameter": "systemd-pcrextend",
    "section": "8",
    "url": "https://www.chedong.com/phpMan.php/man/systemd-pcrextend/8/json",
    "generated": "2026-10-04T19:58:37Z",
    "synopsis": "systemd-pcrphase.service\nsystemd-pcrphase-sysinit.service\nsystemd-pcrphase-initrd.service\nsystemd-pcrmachine.service\nsystemd-pcrfs-root.service\nsystemd-pcrfs@.service\n/usr/lib/systemd/systemd-pcrextend [STRING]",
    "sections": {
        "NAME": {
            "content": "systemd-pcrphase.service, systemd-pcrphase-sysinit.service, systemd-pcrphase-initrd.service,\nsystemd-pcrmachine.service, systemd-pcrfs-root.service, systemd-pcrfs@.service, systemd-\npcrextend - Measure boot phase into TPM2 PCR 11, machine ID and file system identity into PCR\n15\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "systemd-pcrphase.service\n\nsystemd-pcrphase-sysinit.service\n\nsystemd-pcrphase-initrd.service\n\nsystemd-pcrmachine.service\n\nsystemd-pcrfs-root.service\n\nsystemd-pcrfs@.service\n\n/usr/lib/systemd/systemd-pcrextend [STRING]\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "systemd-pcrphase.service, systemd-pcrphase-sysinit.service, and\nsystemd-pcrphase-initrd.service are system services that measure specific strings into TPM2\nPCR 11 during boot at various milestones of the boot process.\n\nsystemd-pcrmachine.service is a system service that measures the machine ID (see machine-\nid(5)) into PCR 15.\n\nsystemd-pcrfs-root.service and systemd-pcrfs@.service are services that measure file system\nidentity information (i.e. mount point, file system type, label and UUID, partition label and\nUUID) into PCR 15.  systemd-pcrfs-root.service does so for the root file system,\nsystemd-pcrfs@.service is a template unit that measures the file system indicated by its\ninstance identifier instead.\n\nThese services require systemd-stub(7) to be used in a unified kernel image (UKI). They\nexecute no operation when the stub has not been used to invoke the kernel. The stub will\nmeasure the invoked kernel and associated vendor resources into PCR 11 before handing control\nto it; once userspace is invoked these services then will extend TPM2 PCR 11 with certain\nliteral strings indicating phases of the boot process. During a regular boot process PCR 11\nis extended with the following strings:\n\n1. \"enter-initrd\" — early when the initrd initializes, before activating system extension\nimages for the initrd. It acts as a barrier between the time where the kernel initializes\nand where the initrd starts operating and enables system extension images, i.e. code\nshipped outside of the UKI. (This extension happens when the systemd-pcrphase-\ninitrd.service(8) service is started.)\n\n2. \"leave-initrd\" — when the initrd is about to transition into the host file system. It\nacts as barrier between initrd code and host OS code. (This extension happens when the\nsystemd-pcrphase-initrd.service service is stopped.)\n\n3. \"sysinit\" — when basic system initialization is complete (which includes local file\nsystems having been mounted), and the system begins starting regular system services.\n(This extension happens when the systemd-pcrphase-sysinit.service(8) service is started.)\n\n4. \"ready\" — during later boot-up, after remote file systems have been activated (i.e. after\nremote-fs.target), but before users are permitted to log in (i.e. before\nsystemd-user-sessions.service). It acts as barrier between the time where unprivileged\nregular users are still prohibited to log in and where they are allowed to log in. (This\nextension happens when the systemd-pcrphase.service service is started.)\n\n5. \"shutdown\" — when the system shutdown begins. It acts as barrier between the time the\nsystem is fully up and running and where it is about to shut down. (This extension\nhappens when the systemd-pcrphase.service service is stopped.)\n\n6. \"final\" — at the end of system shutdown. It acts as barrier between the time the service\nmanager still runs and when it transitions into the final shutdown phase where service\nmanagement is not available anymore. (This extension happens when the systemd-pcrphase-\nsysinit.service(8) service is stopped.)\n\nDuring a regular system lifecycle, PCR 11 is extended with the strings \"enter-initrd\",\n\"leave-initrd\", \"sysinit\", \"ready\", \"shutdown\", and \"final\".\n\nSpecific phases of the boot process may be referenced via the series of strings measured,\nseparated by colons (the \"phase path\"). For example, the phase path for the regular system\nruntime is \"enter-initrd:leave-initrd:sysinit:ready\", while the one for the initrd is just\n\"enter-initrd\". The phase path for the boot phase before the initrd is an empty string;\nbecause that's hard to pass around a single colon (\":\") may be used instead. Note that the\naforementioned six strings are just the default strings and individual systems might measure\nother strings at other times, and thus implement different and more fine-grained boot phases\nto bind policy to.\n\nBy binding policy of TPM2 objects to a specific phase path it is possible to restrict access\nto them to specific phases of the boot process, for example making it impossible to access\nthe root file system's encryption key after the system transitioned from the initrd into the\nhost root file system.\n\nUse systemd-measure(1) to pre-calculate expected PCR 11 values for specific boot phases (via\nthe --phase= switch).\n\nsystemd-pcrfs-root.service and systemd-pcrfs@.service are automatically pulled into the\ninitial transaction by systemd-gpt-auto-generator(8) for the root and /var/ file systems.\nsystemd-fstab-generator(8) will do this for all mounts with the x-systemd.pcrfs mount option\nin /etc/fstab.\n",
            "subsections": []
        },
        "OPTIONS": {
            "content": "The /usr/lib/systemd/system-pcrextend executable may also be invoked from the command line,\nwhere it expects the word to extend into PCR 11, as well as the following switches:\n",
            "subsections": [
                {
                    "name": "--bank=",
                    "content": "Takes the PCR banks to extend the specified word into. If not specified the tool\nautomatically determines all enabled PCR banks and measures the word into all of them.\n\nAdded in version 252.\n"
                },
                {
                    "name": "--pcr=",
                    "content": "Takes the index of the PCR to extend. If --machine-id or --file-system= are specified\ndefaults to 15, otherwise defaults to 11.\n\nAdded in version 255.\n\n--tpm2-device=PATH\nControls which TPM2 device to use. Expects a device node path referring to the TPM2 chip\n(e.g.  /dev/tpmrm0). Alternatively the special value \"auto\" may be specified, in order to\nautomatically determine the device node of a suitable TPM2 device (of which there must be\nexactly one). The special value \"list\" may be used to enumerate all suitable TPM2 devices\ncurrently discovered.\n\nAdded in version 252.\n"
                },
                {
                    "name": "--graceful",
                    "content": "If no TPM2 firmware, kernel subsystem, kernel driver or device support is found, exit\nwith exit status 0 (i.e. indicate success). If this is not specified any attempt to\nmeasure without a TPM2 device will cause the invocation to fail.\n\nAdded in version 253.\n",
                    "long": "--graceful"
                },
                {
                    "name": "--machine-id",
                    "content": "Instead of measuring a word specified on the command line into PCR 11, measure the host's\nmachine ID into PCR 15.\n\nAdded in version 253.\n",
                    "long": "--machine-id"
                },
                {
                    "name": "--file-system=",
                    "content": "Instead of measuring a word specified on the command line into PCR 11, measure identity\ninformation of the specified file system into PCR 15. The parameter must be the path to\nthe established mount point of the file system to measure.\n\nAdded in version 253.\n"
                },
                {
                    "name": "-h --help",
                    "content": "Print a short help text and exit.\n",
                    "flag": "-h",
                    "long": "--help"
                },
                {
                    "name": "--version",
                    "content": "Print a short version string and exit.\n",
                    "long": "--version"
                }
            ]
        },
        "FILES": {
            "content": "/run/log/systemd/tpm2-measure.log\nMeasurements are logged into an event log file maintained in\n/run/log/systemd/tpm2-measure.log, which contains a JSON-SEQ[1] series of objects that\nfollow the general structure of the TCG Common Event Log Format (CEL-JSON)[2] event\nobjects (but lack the \"recnum\" field).\n\nA LOCKEX BSD file lock (flock(2)) on the log file is acquired while the measurement is\nmade and the file is updated. Thus, applications that intend to acquire a consistent\nquote from the TPM with the associated snapshot of the event log should acquire a LOCKSH\nlock while doing so.\n\nAdded in version 252.\n",
            "subsections": []
        },
        "SEE ALSO": {
            "content": "systemd(1), systemd-stub(7), systemd-measure(1), systemd-gpt-auto-generator(8), systemd-\nfstab-generator(8), TPM2 PCR Measurements Made by systemd[3]\n",
            "subsections": []
        },
        "NOTES": {
            "content": "1. JSON-SEQ\nhttps://www.rfc-editor.org/rfc/rfc7464.html\n\n2. TCG Common Event Log Format (CEL-JSON)\nhttps://trustedcomputinggroup.org/resource/canonical-event-log-format/\n\n3. TPM2 PCR Measurements Made by systemd\nhttps://systemd.io/TPM2PCRMEASUREMENTS\n\nsystemd 255                                                              SYSTEMD-PCRPHASE.SERVICE(8)",
            "subsections": []
        }
    },
    "summary": "systemd-pcrphase.service, systemd-pcrphase-sysinit.service, systemd-pcrphase-initrd.service, systemd-pcrmachine.service, systemd-pcrfs-root.service, systemd-pcrfs@.service, systemd- pcrextend - Measure boot phase into TPM2 PCR 11, machine ID and file system identity into PCR 15",
    "flags": [
        {
            "flag": "",
            "long": null,
            "arg": null,
            "description": "Takes the PCR banks to extend the specified word into. If not specified the tool automatically determines all enabled PCR banks and measures the word into all of them. Added in version 252."
        },
        {
            "flag": "",
            "long": null,
            "arg": null,
            "description": "Takes the index of the PCR to extend. If --machine-id or --file-system= are specified defaults to 15, otherwise defaults to 11. Added in version 255. --tpm2-device=PATH Controls which TPM2 device to use. Expects a device node path referring to the TPM2 chip (e.g. /dev/tpmrm0). Alternatively the special value \"auto\" may be specified, in order to automatically determine the device node of a suitable TPM2 device (of which there must be exactly one). The special value \"list\" may be used to enumerate all suitable TPM2 devices currently discovered. Added in version 252."
        },
        {
            "flag": "",
            "long": "--graceful",
            "arg": null,
            "description": "If no TPM2 firmware, kernel subsystem, kernel driver or device support is found, exit with exit status 0 (i.e. indicate success). If this is not specified any attempt to measure without a TPM2 device will cause the invocation to fail. Added in version 253."
        },
        {
            "flag": "",
            "long": "--machine-id",
            "arg": null,
            "description": "Instead of measuring a word specified on the command line into PCR 11, measure the host's machine ID into PCR 15. Added in version 253."
        },
        {
            "flag": "",
            "long": null,
            "arg": null,
            "description": "Instead of measuring a word specified on the command line into PCR 11, measure identity information of the specified file system into PCR 15. The parameter must be the path to the established mount point of the file system to measure. Added in version 253."
        },
        {
            "flag": "-h",
            "long": "--help",
            "arg": null,
            "description": "Print a short help text and exit."
        },
        {
            "flag": "",
            "long": "--version",
            "arg": null,
            "description": "Print a short version string and exit."
        }
    ],
    "examples": [],
    "see_also": [
        {
            "name": "systemd",
            "section": "1",
            "url": "https://www.chedong.com/phpMan.php/man/systemd/1/json"
        },
        {
            "name": "systemd-stub",
            "section": "7",
            "url": "https://www.chedong.com/phpMan.php/man/systemd-stub/7/json"
        },
        {
            "name": "systemd-measure",
            "section": "1",
            "url": "https://www.chedong.com/phpMan.php/man/systemd-measure/1/json"
        },
        {
            "name": "systemd-gpt-auto-generator",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/systemd-gpt-auto-generator/8/json"
        },
        {
            "name": "fstab-generator",
            "section": "8",
            "url": "https://www.chedong.com/phpMan.php/man/fstab-generator/8/json"
        }
    ]
}