Repository navigation
aa: record initdata in RTMR3 when MRCONFIGID is unset - #1787
Open
david-long1 wants to merge 5 commits into
Open
david-long1 wants to merge 5 commits into
david-long1 wants to merge 5 commits into
Conversation
extend_entry built each entry's target register from the default PCR while extending the one the caller passed, and the WAL did not record the PCR, so recovery re-extended the default one. Record the PCR in the WAL and use it in both places. Signed-off-by: David Long <davidlong@berkeley.edu>
On CSPs that don't let the host set MRCONFIGID it reads as zero, so the TDX attester's comparison always fails and AA exits. Return a new InitDataResult::NotBound for that case instead. A non-zero MRCONFIGID must still match. AA still treats NotBound as an error, so behaviour is unchanged until something records the digest. Assisted-by: Claude Code <noreply@anthropic.com> Signed-off-by: David Long <davidlong@berkeley.edu>
When the attester reports NotBound, extend the eventlog's default register (RTMR3 on TDX) with a github.com/confidential-containers InitData event whose content is the initdata digest as canonical JSON, so Trustee can replay it. This happens whether or not the eventlog is enabled; with it disabled the eventlog is opened only for this step, and other runtime events still follow the flag. AA records the digest once per boot: after WAL recovery it scans its own eventlog, skips the extend when the same digest is already logged, and refuses to start on a different one. Any failure to record stops AA rather than leaving initdata unbound. This needs the hash algorithm, so it only covers --initdata-toml; --initdata-digest and the BindInitData RPC still fail on NotBound. Assisted-by: Claude Code <noreply@anthropic.com> Signed-off-by: David Long <davidlong@berkeley.edu>
david-long1
force-pushed
the
aa-initdata-record
branch
from
October 5, 2026 23:27
53b4d4b to
33b1be5
Compare
david-long1
marked this pull request as ready for review
October 8, 2026 05:02
mkulke
reviewed
Oct 8, 2026
bind_init_data now returns NotBound as-is, and callers decide what to do with it: ttrpc-aa and grpc-aa measure the digest with measure_init_data, and the BindInitData RPC fails. measure_init_data needs the eventlog to be enabled instead of opening it implicitly. Assisted-by: Claude Code <noreply@anthropic.com> Signed-off-by: David Long <davidlong@berkeley.edu>
Assisted-by: Claude Code <noreply@anthropic.com> Signed-off-by: David Long <davidlong@berkeley.edu>
Xynnn007
self-requested a review
October 9, 2026 06:38
mkulke
approved these changes
Oct 9, 2026
mkulke
left a comment
Contributor
There was a problem hiding this comment.
lgtm, thanks for accomodating comments
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
On GCP C3 TDX VMs used by peer pods, MRCONFIGID reads as all zeros, so AA cannot verify initdata through the normal binding path and exits when initdata is provided. This is the AA side of confidential-containers/cloud-api-adaptor#2604.
NotBoundwhen MRCONFIGID is all zeros. If it is non-zero, it still has to match the initdata digest.NotBound, AA measures anInitDataevent into its eventlog, which extends RTMR3, so Trustee can replay the log and check the digest.enable_eventlog = true; with the eventlog off, AA refuses to start rather than opening it implicitly.--initdata-tomlrecords;--initdata-digestandBindInitDatastill fail onNotBound.Built on #1764, so the diff includes its commit until it merges (compare view). The Trustee side is confidential-containers/trustee#1632, which has to merge first.
Tested with unit tests and on a GCP C3 TDX VM, including restart and reboot.