Skip to content

fix(verifier): a DebugSwap guest verifies, and four more ways host bytes reach a measurement unchecked - #1275

Merged
kvinwang merged 9 commits into
nextfrom
fix/verifier-input-canonicalization
Sep 22, 2026
Merged

kvinwang merged 9 commits into
nextfrom
fix/verifier-input-canonicalization

Conversation

@kvinwang

@kvinwang kvinwang commented Sep 20, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

Hardens verifier and measurement inputs that are controlled by the host. The main security fix prevents a consistently measured SEV-SNP guest with unsupported SEV_FEATURES (for example DebugSwap) from passing verification and receiving keys.

Changes

  1. Restrict SEV-SNP guest features

    • Require SNPActive and reject every other SEV_FEATURES bit.
    • dstack's only launch path emits guest_features = 1; existing SEV measurement vectors are unchanged.
  2. Validate quoted TPM PCR values

    • Require every PCR to be labelled sha256 and contain exactly 32 bytes.
    • Prevents re-splitting the concatenated PCR preimage into values the TPM never held while preserving the signed digest.
  3. Reject trailing CBOR bytes

    • Measurement decoders now require the input to contain exactly one CBOR document.
  4. Require MrConfigV3.version

    • A document without version no longer silently defaults to version 3.
  5. Reject duplicate dstack.rootfs_hash parameters

    • Avoids disagreement between the measurement parser (previously first value) and initramfs (last value).
  6. Version the AWS measurement document

    • Adds version: 1 and rejects unsupported versions, matching the TDX, SEV, and GCP document formats.
  7. Remove an unused lossy accessor

    • Deletes sev_snp_mr_config(), which converted malformed input to None and had no callers.
  8. Make unverified SNP parsing explicit

    • Renames parse_amd_snp_report to parse_unverified_amd_snp_report and documents that it does not verify signatures or the AMD certificate chain.

Compatibility

The SEV, TDX, and GCP measurement encodings do not change.

Adding the AWS version field changes measurement.aws.cbor, its sha256sum.txt entry, and therefore the AWS os_image_hash. AWS NitroTPM UKI images must be rebuilt and their image hashes re-pinned. The repository has no AWS fixture or pinned AWS image hash, and image assembly regenerates this document on every build.

Verification

cargo test -p dstack-mr -p dstack-types -p tpm-qvl -p dstack-attest -p sev-snp-qvl -p dstack-verifier
cargo test --workspace
cargo clippy -- -D warnings --allow unused_variables
cargo fmt --check

Each behavioral fix has a regression test that failed on next before the fix.

@kvinwang kvinwang added the P0 Highest priority: review or decide before anything else in the audit batch label Sep 21, 2026
@kvinwang
kvinwang force-pushed the fix/verifier-input-canonicalization branch from 5a66157 to 27b106f Compare September 22, 2026 01:56
@kvinwang
kvinwang merged commit 0a835f2 into next Sep 22, 2026
11 checks passed
@kvinwang
kvinwang deleted the fix/verifier-input-canonicalization branch September 22, 2026 04:07
kvinwang added a commit that referenced this pull request Sep 25, 2026
… parser bounds

#1387 requires PCI hotplug off for GPU passthrough, so the matrix GPU row
failed; measure it with hotplug off and assert the named rejection without.
#1229 reads XLF bit 1, not bit 6, for the initrd ceiling: fix the harness
oracle and add a row with a 5-level-only kernel. #1367 made diagnose honour
num_nics, num_verity_volumes and swtpm; compare it with measure. Run the
new dstack-mr and dstack-types bound vectors from #1229, #1231, #1236 and

Signed-off-by: Kevin Wang <wy721@qq.com>
#1275 by exact name.
kvinwang added a commit that referenced this pull request Sep 25, 2026
Extend the SEV-SNP case with the certificate-table, empty-report, guest
feature, rootfs-hash and page-budget tests (#1248, #1279, #1275, #1252),
and the cloud TPM case with the PCR bank, duplicate index, quoted event
log, collateral budget and host allowlist tests (#1275, #1267, #1338,

Signed-off-by: Kevin Wang <wy721@qq.com>
#1238, #1404).
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

P0 Highest priority: review or decide before anything else in the audit batch

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant