Skip to content

docs(verifier): say os_image_is_dev is only reported on the TDX legacy path - #1266

Merged
kvinwang merged 1 commit into
nextfrom
fix/verifier-result-contract
Sep 24, 2026
Merged

kvinwang merged 1 commit into
nextfrom
fix/verifier-result-contract

Conversation

@kvinwang

@kvinwang kvinwang commented Sep 20, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

verifier/README.md told relying parties to reject dev images via os_image_is_dev, and said it is null only on GCP TDX and Nitro Enclave. In fact the only assignment is on the TDX legacy path (the only path that downloads the image and reads metadata.json). TDX lite, SEV-SNP, GCP TDX, AWS NitroTPM and Nitro Enclave carry only the manifest digest, so the field is always null there, and a "reject if os_image_is_dev == true" policy accepts every dev image on those paths. The README also did not say that is_valid ignores tcb_status.

Fix

Docs only: state where os_image_is_dev/os_image_version are reported, tell relying parties to allowlist os_image_hash instead, and note that tcb_status is surfaced, not gated (linking the existing security-model section).

Verification

cargo test -p dstack-verifier, fmt and clippy clean (no code change beyond doc comments).

The measurement-cache bound from the original PR is #1369, and the report_data domain-tag section is #1370.

@kvinwang kvinwang changed the title feat(verifier): say which trust anchor os_image_hash_verified came from docs(verifier): say os_image_is_dev is only reported on the TDX legacy path Sep 24, 2026
@kvinwang
kvinwang force-pushed the fix/verifier-result-contract branch from ee42885 to 4adaff2 Compare September 24, 2026 09:02
@kvinwang
kvinwang merged commit bb3fbd1 into next Sep 24, 2026
12 checks passed
@kvinwang
kvinwang deleted the fix/verifier-result-contract branch September 24, 2026 14:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant