Skip to content

test(kms): pin the deliberate TCB policy divergence between auth-simple and the contracts - #1345

Merged
kvinwang merged 1 commit into
nextfrom
test/kms-tcb-policy-divergence
Sep 24, 2026
Merged

kvinwang merged 1 commit into
nextfrom
test/kms-tcb-policy-divergence

Conversation

@kvinwang

@kvinwang kvinwang commented Sep 24, 2026 •

Copy link
Copy Markdown
Collaborator

Split out of #1247. Tests only — they pass on unmodified code.

auth-simple and DstackApp intentionally disagree on TCB policy:

input auth-simple DstackApp (legacy 5-arg init) DstackApp (requireTcbUpToDate = true)
tcbStatus: OutOfDate deny allow deny
advisoryIds: [INTEL-SA-00614] deny allow (never read) allow (never read)

The legacy default is the backward-compatibility behavior from specification.md §3.4/§3.8. auth-simple has no per-app owner who could opt in, so it stays strict. Existing tests checked the flag, not the resulting decision. This PR adds that assertion on both sides, with each test referencing the other.

…le and DstackApp

A legacy (5-arg) DstackApp leaves requireTcbUpToDate false and so authorizes
an out-of-date TCB with advisory IDs, while auth-simple rejects both by
default. Both behaviors are intended (spec §3.4/§3.8 backward compatibility
vs. fail-closed config-file policy) but the decision itself was unpinned.
Assert it on both sides so neither default can flip silently.
@kvinwang
kvinwang force-pushed the test/kms-tcb-policy-divergence branch from 596ba82 to 1393f46 Compare September 24, 2026 04:13
@kvinwang
kvinwang merged commit 8c344d4 into next Sep 24, 2026
13 checks passed
@kvinwang
kvinwang deleted the test/kms-tcb-policy-divergence branch September 24, 2026 04:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant