fix(attestation): wire real measurement policy into bootstrap_measurement_policy() - #239
Open
Sertug17 wants to merge 1 commit into
Open
Conversation
Replace dangerously_accept_any_for_testing() with a real implementation that loads the measurement-policy artifact from the node's conf directory, verifies its SHA-256 digest against the manifest's bootstrap_policy_hash, and parses it before trusting it. Fails closed on any I/O error, hash mismatch, or parse failure — the node never falls back to a permissive policy. Closes SeismicSystems#238
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #238
Problem
bootstrap_measurement_policy()returneddangerously_accept_any_for_testing(), allowing any TEE image to participate in root key bootstrap without measurement verification.Changes
NETWORK_MANIFEST_PATHto read the pinnedbootstrap_policy_hash/run/seismic/conf/measurements.jsonbootstrap_policy_hashbefore parsingSeismicMeasurementPolicy::from_json_bytes()seismic-network-manifest,sha2,hexto crate dependenciesasync + Resultreturn type to both call sitesSecurity
Fails closed on every failure path I/O error, hash mismatch, parse error. The node never falls back to a permissive policy.
Testing needed