> It occurs to me that we are actually over-thinking things, by making it
> possible to list a choice of vars files per firmware. We could remove this
> special case by just having separate tpo level firmware entries and a main
> feature flag to say if it is enrolled or not - see below example

That would also make it easier to implement something like ...

    qemu -firmware json=/path/to/firmware/spec.json

... because you simply have two files for the enrolled/non-enrolled


