The problem you're addressing (if any)
It's hard to reason through every possible case why an update may work or not work. Example:
DTS allows an update of a fused laptop with one set of keys to a version signed with another keys if the following are met:
- Descriptor is unlocked (via external programmer)
- ME is in HAP mode (impossible with locked descriptor)
Update from one version with one set of keys to another with another set of keys on a fused device should never be allowed
It's hard to describe every possible path, so a chart could help.
Describe the solution you'd like
A chart
Where is the value to a user, and who might that user be?
Not for users, but for developers working on the update processes
Describe alternatives you've considered
No response
Additional context
No response