Skip to content

fix(verifier): bound the measurement cache directory - #1369

Merged
kvinwang merged 1 commit into
nextfrom
fix/verifier-measurement-cache-bound
Sep 24, 2026
Merged

kvinwang merged 1 commit into
nextfrom
fix/verifier-measurement-cache-bound

Conversation

@kvinwang

@kvinwang kvinwang commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Split out of #1266.

Problem

store_measurements_in_cache writes one file per VM shape under <image_cache_dir>/measurements/ and nothing ever removes them, including entries whose measurements then failed to match the quote. A caller with any valid quote can vary the shape and grow the directory without limit (slowly: each entry costs a full image measurement).

Fix

Cap the directory at MEASUREMENT_CACHE_MAX_ENTRIES = 1024 (~400 B each). After each store, drop the oldest .json entries by mtime; in-flight NamedTempFiles have no extension and are left alone. Pruning is best effort and never fails a verification. A cap, not a TTL: a shape always yields the same measurements.

Verification

cargo test -p dstack-verifier (36 passed, including measurement_cache_evicts_the_oldest_entries_and_spares_temporaries), fmt and clippy clean. Merges cleanly with #1337.

@kvinwang
kvinwang force-pushed the fix/verifier-measurement-cache-bound branch from 1af2881 to 0e7de76 Compare September 24, 2026 09:00
@kvinwang
kvinwang merged commit 5fd3f75 into next Sep 24, 2026
12 checks passed
@kvinwang
kvinwang deleted the fix/verifier-measurement-cache-bound branch September 24, 2026 14:22
kvinwang added a commit that referenced this pull request Sep 25, 2026
…bounds

#1251 renamed the manifest confinement test the image-download case ran by
name. Run its replacement plus the tests that pin the sha256sum grammar,
the end-to-end image binding (#1337) and the truncated-download retry
(#1388), and extend the measurement cache case with shape-only keying
(#1334) and the bounded cache directory (#1369).

Signed-off-by: Kevin Wang <wy721@qq.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant