Skip to content

aa: record initdata in RTMR3 when MRCONFIGID is unset - #1787

Open
david-long1 wants to merge 5 commits into
confidential-containers:mainfrom
david-long1:aa-initdata-record
Open

david-long1 wants to merge 5 commits into
confidential-containers:mainfrom
david-long1:aa-initdata-record

Conversation

@david-long1

@david-long1 david-long1 commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

On GCP C3 TDX VMs used by peer pods, MRCONFIGID reads as all zeros, so AA cannot verify initdata through the normal binding path and exits when initdata is provided. This is the AA side of confidential-containers/cloud-api-adaptor#2604.

  • The TDX attester now returns NotBound when MRCONFIGID is all zeros. If it is non-zero, it still has to match the initdata digest.
  • On NotBound, AA measures an InitData event into its eventlog, which extends RTMR3, so Trustee can replay the log and check the digest.
  • The event is recorded once per boot: the same digest is skipped, a different digest makes AA refuse to start, and a failed RTMR3 extend also fails closed.
  • This needs enable_eventlog = true; with the eventlog off, AA refuses to start rather than opening it implicitly.
  • Only --initdata-toml records; --initdata-digest and BindInitData still fail on NotBound.

Built on #1764, so the diff includes its commit until it merges (compare view). The Trustee side is confidential-containers/trustee#1632, which has to merge first.

Tested with unit tests and on a GCP C3 TDX VM, including restart and reboot.

extend_entry built each entry's target register from the default PCR while extending the one the caller passed, and the WAL did not record the PCR, so recovery re-extended the default one. Record the PCR in the WAL and use it in both places.

Signed-off-by: David Long <davidlong@berkeley.edu>
On CSPs that don't let the host set MRCONFIGID it reads as zero, so the
TDX attester's comparison always fails and AA exits. Return a new
InitDataResult::NotBound for that case instead. A non-zero MRCONFIGID
must still match.

AA still treats NotBound as an error, so behaviour is unchanged until
something records the digest.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: David Long <davidlong@berkeley.edu>
When the attester reports NotBound, extend the eventlog's default
register (RTMR3 on TDX) with a github.com/confidential-containers
InitData event whose content is the initdata digest as canonical JSON,
so Trustee can replay it. This happens whether or not the eventlog is
enabled; with it disabled the eventlog is opened only for this step,
and other runtime events still follow the flag.

AA records the digest once per boot: after WAL recovery it scans its
own eventlog, skips the extend when the same digest is already logged,
and refuses to start on a different one. Any failure to record stops
AA rather than leaving initdata unbound.

This needs the hash algorithm, so it only covers --initdata-toml;
--initdata-digest and the BindInitData RPC still fail on NotBound.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: David Long <davidlong@berkeley.edu>
Comment thread attestation-agent/attestation-agent/src/lib.rs Outdated
Comment thread attestation-agent/attestation-agent/src/lib.rs Outdated
Comment thread attestation-agent/attestation-agent/src/lib.rs Outdated
Comment thread attestation-agent/attestation-agent/src/lib.rs Outdated
Comment thread attestation-agent/attestation-agent/src/eventlog/tcg2.rs
Comment thread attestation-agent/attestation-agent/src/bin/grpc-aa/main.rs Outdated
bind_init_data now returns NotBound as-is, and callers decide what to
do with it: ttrpc-aa and grpc-aa measure the digest with
measure_init_data, and the BindInitData RPC fails. measure_init_data
needs the eventlog to be enabled instead of opening it implicitly.

Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: David Long <davidlong@berkeley.edu>
Assisted-by: Claude Code <noreply@anthropic.com>
Signed-off-by: David Long <davidlong@berkeley.edu>
@Xynnn007
Xynnn007 self-requested a review October 9, 2026 06:38

@mkulke mkulke left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, thanks for accomodating comments

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants