Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 8 additions & 2 deletions dstack/kms/src/main_service.rs
Original file line number Diff line number Diff line change
Expand Up @@ -1101,7 +1101,10 @@ mod tests {

assert_eq!(boot_info.tee_variant, TeeVariant::DstackAmdSevSnp);
assert_eq!(boot_info.mr_aggregated.len(), 32);
assert_eq!(boot_info.device_id, vec![0xab; 64]);
assert_eq!(
boot_info.device_id,
sha2::Sha256::digest([0xab; 64]).to_vec()
);
assert_eq!(boot_info.app_id, vec![0x11; 20]);
}

Expand Down Expand Up @@ -1137,7 +1140,10 @@ mod tests {
let boot_info = build_boot_info_for_attestation(&attestation, false, &vm_config)
.expect("self-contained SNP vm_config should not require KMS-local sev_snp config");
assert_eq!(boot_info.tee_variant, TeeVariant::DstackAmdSevSnp);
assert_eq!(boot_info.device_id, vec![0xab; 64]);
assert_eq!(
boot_info.device_id,
sha2::Sha256::digest([0xab; 64]).to_vec()
);
}

fn snp_boot_info() -> BootInfo {
Expand Down
21 changes: 13 additions & 8 deletions dstack/kms/src/main_service/amd_attest.rs
Original file line number Diff line number Diff line change
Expand Up @@ -60,8 +60,10 @@ pub(crate) fn validate_amd_snp_measurement_binding(
///
/// This helper first recomputes and validates the QEMU SNP launch measurement.
/// `mr_system` is `sha256(MEASUREMENT)`, `mr_aggregated` is
/// `sha256(MEASUREMENT || HOST_DATA)`, and `device_id` is the
/// hardware-verified 64-byte SNP `chip_id`. `app_id`, `compose_hash`,
/// `sha256(MEASUREMENT || HOST_DATA)`, and `device_id` is
/// `sha256(chip_id)` over the hardware-verified 64-byte SNP `chip_id` — the
/// same 32-byte form `GetAttestationInfo` reports and operators register, so
/// device allowlists compare equal. `app_id`, `compose_hash`,
/// `instance_id`, and key provider identity come from the MrConfigV3 document
/// bound by HOST_DATA.
///
Expand Down Expand Up @@ -116,7 +118,7 @@ fn build_amd_snp_boot_info_with_tcb_status(
app_id: mr_config.app_id.clone().unwrap_or_default(),
compose_hash: mr_config.compose_hash.clone(),
instance_id: mr_config.instance_id.clone().unwrap_or_default(),
device_id: verified_chip_id.to_vec(),
device_id: Sha256::digest(verified_chip_id).to_vec(),
key_provider_info,
tcb_status: tcb_status.to_string(),
advisory_ids: advisory_ids.to_vec(),
Expand Down Expand Up @@ -368,7 +370,7 @@ mod tests {
.expect("matching measurement should build snp boot info");
assert_eq!(boot_info.tee_variant, TeeVariant::DstackAmdSevSnp);
assert_eq!(boot_info.mr_aggregated.len(), 32);
assert_eq!(boot_info.device_id, chip_id.to_vec());
assert_eq!(boot_info.device_id, Sha256::digest(chip_id).to_vec());
assert_eq!(boot_info.app_id, vec![0x11; 20]);
assert_eq!(boot_info.compose_hash, vec![0x22; 32]);
assert_eq!(boot_info.os_image_hash, test_os_image_hash(&input).unwrap());
Expand Down Expand Up @@ -404,7 +406,7 @@ mod tests {
.expect("verified snp attestation should feed boot info helper");

assert_eq!(boot_info.mr_aggregated.len(), 32);
assert_eq!(boot_info.device_id, chip_id.to_vec());
assert_eq!(boot_info.device_id, Sha256::digest(chip_id).to_vec());
assert_eq!(boot_info.app_id, vec![0x11; 20]);
assert_eq!(boot_info.tcb_status, "UpToDate");
Ok(())
Expand Down Expand Up @@ -486,7 +488,7 @@ mod tests {
.expect("vm_config-carried snp measurement inputs should build boot info");

assert_eq!(boot_info.mr_aggregated.len(), 32);
assert_eq!(boot_info.device_id, chip_id.to_vec());
assert_eq!(boot_info.device_id, Sha256::digest(chip_id).to_vec());
assert_eq!(boot_info.app_id, vec![0x11; 20]);
Ok(())
}
Expand Down Expand Up @@ -715,8 +717,11 @@ mod tests {
let boot_info = build_amd_snp_boot_info(&verified, &[0x01; 64], &input).unwrap();
let changed_boot_info = build_amd_snp_boot_info(&verified, &[0x02; 64], &input).unwrap();

assert_eq!(boot_info.device_id, vec![0x01; 64]);
assert_eq!(changed_boot_info.device_id, vec![0x02; 64]);
assert_eq!(boot_info.device_id, Sha256::digest([0x01; 64]).to_vec());
assert_eq!(
changed_boot_info.device_id,
Sha256::digest([0x02; 64]).to_vec()
);
assert_ne!(boot_info.device_id, changed_boot_info.device_id);
assert_eq!(boot_info.instance_id, changed_boot_info.instance_id);
assert_eq!(
Expand Down
6 changes: 2 additions & 4 deletions dstack/kms/src/onboard_service.rs
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,6 @@ use ra_tls::{
rcgen::{Certificate, KeyPair, PKCS_ECDSA_P256_SHA256},
};
use safe_write::{safe_write, safe_write_with_mode};
use sha2::Digest;
use tokio::sync::Mutex as AsyncMutex;
use tracing::info;

Expand Down Expand Up @@ -238,16 +237,15 @@ fn build_attestation_info_response(
) -> Result<AttestationInfoResponse> {
let boot_info = build_boot_info_for_attestation(verified, false, vm_config)
.context("Failed to decode app info")?;
let raw_device_id = verified.report.get_devide_id();
Ok(AttestationInfoResponse {
device_id: sha2::Sha256::digest(&raw_device_id).to_vec(),
device_id: boot_info.device_id,
mr_aggregated: boot_info.mr_aggregated,
os_image_hash: boot_info.os_image_hash,
tee_variant,
site_name,
eth_rpc_url,
kms_contract_address,
ppid: raw_device_id,
ppid: verified.report.get_devide_id(),
})
}

Expand Down
Loading