Hardened/production builds cannot boot on real hardware as shipped, for two coupled reasons, and neither is documented.
Unsigned binary vs Secure Boot: the ISO/ESP build copies nonos_boot.efi straight to EFI/Boot/BOOTX64.EFI with no sbsign/pesign, no shim, no SBAT, no db.auth (mk/20-build.mk, mk/30-image.mk). But Hardened mode's enforce_secure_boot (security/enforce/requirements/secureboot.rs:22) denies and fatal_resets when firmware Secure Boot is OFF. So Hardened demands Secure Boot ON, yet the unsigned binary cannot pass firmware Secure Boot to start. The only path is enrolling the NONOS key into db (or a shim+MOK flow that does not exist). Ship a signing + cert-enrollment target, or document "Hardened requires key enrollment," or provide a shim+SBAT path.
TPM required but often off: Hardened's enforce_measured_boot denies when EFI_TCG2 is absent (modes/hardened.rs:31), and many consumer boards ship fTPM/PTT disabled by default. User must enable it in firmware.
Standard mode only warns on both, so the default standard-qemu image boots on real HW with Secure Boot and TPM merely warned. The real-HW blockers are concentrated entirely in the production/hardened policy. Also: the Hardened HW-RNG gate is RDRAND-only (requirements/hardware.rs:20) and should accept RDSEED too, so pre-Ivy-Bridge / some Atom CPUs are not excluded.
Hardened/production builds cannot boot on real hardware as shipped, for two coupled reasons, and neither is documented.
Unsigned binary vs Secure Boot: the ISO/ESP build copies nonos_boot.efi straight to EFI/Boot/BOOTX64.EFI with no sbsign/pesign, no shim, no SBAT, no db.auth (mk/20-build.mk, mk/30-image.mk). But Hardened mode's enforce_secure_boot (security/enforce/requirements/secureboot.rs:22) denies and fatal_resets when firmware Secure Boot is OFF. So Hardened demands Secure Boot ON, yet the unsigned binary cannot pass firmware Secure Boot to start. The only path is enrolling the NONOS key into db (or a shim+MOK flow that does not exist). Ship a signing + cert-enrollment target, or document "Hardened requires key enrollment," or provide a shim+SBAT path.
TPM required but often off: Hardened's enforce_measured_boot denies when EFI_TCG2 is absent (modes/hardened.rs:31), and many consumer boards ship fTPM/PTT disabled by default. User must enable it in firmware.
Standard mode only warns on both, so the default standard-qemu image boots on real HW with Secure Boot and TPM merely warned. The real-HW blockers are concentrated entirely in the production/hardened policy. Also: the Hardened HW-RNG gate is RDRAND-only (requirements/hardware.rs:20) and should accept RDSEED too, so pre-Ivy-Bridge / some Atom CPUs are not excluded.