fix(dstack-mr): lower the SEV-SNP metadata page budget to 65536 pages - #1252
Merged
Merged
Conversation
… firmware needs MAX_OVMF_METADATA_PAGES admitted 16777216 pages -- 64 GiB. Every page is one SHA-384 over a PAGE_INFO, and verify_sev_launch recomputes the whole measurement *before* comparing it with the hardware MEASUREMENT, so the budget is spent entirely on input the requester authored. The document is bound only to vm_config.os_image_hash, which the requester also chooses, so no allowlist rejects it first. Measured on an EPYC-class host: 0.68 us per page, so the ceiling is **11.3 seconds of one core** for a measurement.snp.cbor of about 200 bytes. The path is reached from the verifier's POST /verify and from the KMS's key-release path, both gated only by one valid SNP quote -- which a holder can replay with an arbitrary vm_config. The shipped dstack-0.6.0 image declares 7 sections totalling **31 pages**, so the ceiling was 541000x what a real firmware asks for. Lower it to 65536 pages: over 2000x headroom, about 44 ms at the ceiling, and deliberately the same number as tdvf::MAX_MEASURED_PAGES, since the two measurement paths have the same shape and should have the same bound.
This was referenced Sep 20, 2026
kvinwang
added a commit
that referenced
this pull request
Sep 25, 2026
Extend the SEV-SNP case with the certificate-table, empty-report, guest feature, rootfs-hash and page-budget tests (#1248, #1279, #1275, #1252), and the cloud TPM case with the PCR bank, duplicate index, quoted event log, collateral budget and host allowlist tests (#1275, #1267, #1338, Signed-off-by: Kevin Wang <wy721@qq.com> #1238, #1404).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
MAX_OVMF_METADATA_PAGESallowed 16 777 216 pages (64 GiB). Each page costs a SHA-384, andverify_sev_launchrecomputes the whole measurement from the caller-suppliedmeasurement.snp.cborbefore comparing it with the hardwareMEASUREMENT. A ~200-byte document with one section sized to the budget costs 11.3 s of one core (measured, 0.68 µs/page) on the verifier'sPOST /verifyand the KMS key-release path, repeatable by anyone holding one valid SNP quote.Fix
Lower the ceiling to 65 536 pages, the same bound as
tdvf::MAX_MEASURED_PAGES. The shippeddstack-0.6.0metadata is 7 sections / 31 pages, so this leaves >2000x headroom (~44 ms worst case).Verification
cargo test -p dstack-mrpasses; KMS SNP tests (cargo test -p dstack-kms snp, 14) pass; fmt and clippy clean.