Skip to content

fix(dstack-mr): lower the SEV-SNP metadata page budget to 65536 pages - #1252

Merged
kvinwang merged 2 commits into
nextfrom
fix/dstack-mr-sev-page-budget
Sep 24, 2026
Merged

kvinwang merged 2 commits into
nextfrom
fix/dstack-mr-sev-page-budget

Conversation

@kvinwang

@kvinwang kvinwang commented Sep 20, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

MAX_OVMF_METADATA_PAGES allowed 16 777 216 pages (64 GiB). Each page costs a SHA-384, and verify_sev_launch recomputes the whole measurement from the caller-supplied measurement.snp.cbor before comparing it with the hardware MEASUREMENT. A ~200-byte document with one section sized to the budget costs 11.3 s of one core (measured, 0.68 µs/page) on the verifier's POST /verify and the KMS key-release path, repeatable by anyone holding one valid SNP quote.

Fix

Lower the ceiling to 65 536 pages, the same bound as tdvf::MAX_MEASURED_PAGES. The shipped dstack-0.6.0 metadata is 7 sections / 31 pages, so this leaves >2000x headroom (~44 ms worst case).

Verification

  • Test: the shipped 7-section table is accepted, a 16M-page section is rejected.
  • cargo test -p dstack-mr passes; KMS SNP tests (cargo test -p dstack-kms snp, 14) pass; fmt and clippy clean.

… firmware needs

MAX_OVMF_METADATA_PAGES admitted 16777216 pages -- 64 GiB. Every page is
one SHA-384 over a PAGE_INFO, and verify_sev_launch recomputes the whole
measurement *before* comparing it with the hardware MEASUREMENT, so the
budget is spent entirely on input the requester authored. The document is
bound only to vm_config.os_image_hash, which the requester also chooses,
so no allowlist rejects it first.

Measured on an EPYC-class host: 0.68 us per page, so the ceiling is
**11.3 seconds of one core** for a measurement.snp.cbor of about 200
bytes. The path is reached from the verifier's POST /verify and from the
KMS's key-release path, both gated only by one valid SNP quote -- which a
holder can replay with an arbitrary vm_config.

The shipped dstack-0.6.0 image declares 7 sections totalling **31
pages**, so the ceiling was 541000x what a real firmware asks for. Lower
it to 65536 pages: over 2000x headroom, about 44 ms at the ceiling, and
deliberately the same number as tdvf::MAX_MEASURED_PAGES, since the two
measurement paths have the same shape and should have the same bound.
@kvinwang kvinwang changed the title fix(dstack-mr): a 200-byte SEV-SNP measurement document buys 11.3 seconds of CPU fix(dstack-mr): lower the SEV-SNP metadata page budget to 65536 pages Sep 24, 2026
@kvinwang
kvinwang merged commit ac6f449 into next Sep 24, 2026
11 checks passed
@kvinwang
kvinwang deleted the fix/dstack-mr-sev-page-budget branch September 24, 2026 14:20
kvinwang added a commit that referenced this pull request Sep 25, 2026
Extend the SEV-SNP case with the certificate-table, empty-report, guest
feature, rootfs-hash and page-budget tests (#1248, #1279, #1275, #1252),
and the cloud TPM case with the PCR bank, duplicate index, quoted event
log, collateral budget and host allowlist tests (#1275, #1267, #1338,

Signed-off-by: Kevin Wang <wy721@qq.com>
#1238, #1404).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant