Skip to content

feat(policy): add CoRIM mappings and optional servTD identity - #1037

Open
haitaohuang wants to merge 15 commits into
intel:mainfrom
haitaohuang:corim-optional-servtd-port
Open

haitaohuang wants to merge 15 commits into
intel:mainfrom
haitaohuang:corim-optional-servtd-port

Conversation

@haitaohuang

Copy link
Copy Markdown
Contributor

Summary

This is a stacked continuation of #1035 and #1032. The new commit in this PR implements the CoRIM TCB-mapping and optional servTD Identity proposals tracked in #929 and #930.

  • keep JSON TCB mappings as the default while adding feature-gated signed CoRIM mappings;
  • verify CoRIM COSE_Sign1 ES384/ESP384 signatures and RFC 9360 x5chain, reject unsupported time claims, and bind the signer to the RTMR1 root-certificate plus leaf-subject anchor from feat(policy): add stable RTMR1 signer anchor and revocation #1035;
  • support direct 48-byte signer-anchor and signed-CoRIM CFV enrollment;
  • apply the locally authoritative servTD CRL to JSON and CoRIM signer chains;
  • transport and authenticate each peer's CoRIM so source initial/current hashes are resolved through the source endorsement, with no JSON fallback after a CoRIM miss;
  • make the simplified JSON servTD Identity optional: SVN-only policies work without it, while date/status rules fail closed;
  • keep optional identity material measured in RTMR2 while leaving independently signed mapping content updateable;
  • preserve compatibility with existing JSON policies whose mapping is signed by the CFV policy issuer, while allowing an explicit mapping signer chain.

No documentation, test-fixture, workflow, or integration-script changes are included.

Validation

  • formatting, cargo check, clippy, cargo-deny, library build, and library tests;
  • policy tests with servtd_corim enabled;
  • all 32 firmware build combinations and all six standalone tools;
  • a policy-v2 CoRIM image build;
  • all 14 emulation workflow scenarios;
  • policy-v2 IGVM build and offline hash generation.

Follow-up

The remaining future work is the release-tooling and coverage work described in #1032: independent policy/mapping/identity signer-rotation coverage and stronger two-phase measurement-generation/hash-stability checks.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

One or more issues must be addressed before approval.

Once you've addressed the issues Copilot identified, you can request another Copilot review.

Pull request overview

Adds feature-gated CoRIM TCB mappings, optional servTD identity, signer-anchor enrollment, CRL handling, and peer endorsement transport.

Changes:

  • Adds COSE/x5chain CoRIM verification and RTMR1 binding.
  • Updates policy and collateral generators for optional identity, CRLs, and CoRIM-only policies.
  • Extends measurement, migration transport, and cumulative mapping tooling.
File summaries
File Description
xtask/src/build.rs Updated as part of this pull request.
tools/servtd-collateral-generator/src/main.rs Updated as part of this pull request.
tools/servtd-collateral-generator/src/build.rs Updated as part of this pull request.
tools/servtd-collateral-generator/readme.md Updated as part of this pull request.
tools/migtd-policy-generator/src/policy_v2.rs Updated as part of this pull request.
tools/migtd-policy-generator/src/main.rs Updated as part of this pull request.
tools/migtd-hash/src/main.rs Updated as part of this pull request.
tools/migtd-hash/src/lib.rs Updated as part of this pull request.
tools/migtd-hash/Cargo.toml Updated as part of this pull request.
src/policy/test/policy_v2/tcb_mapping.json Updated as part of this pull request.
src/policy/test/policy_v2/servtd_collateral.json Updated as part of this pull request.
src/policy/test/policy_v2/cert_chain/policy_issuer_chain.pem Updated as part of this pull request.
src/policy/src/v2/servtd_corim.rs Updated as part of this pull request.
src/policy/src/v2/servtd_collateral.rs Updated as part of this pull request.
src/policy/src/v2/mod.rs Updated as part of this pull request.
src/policy/src/v2/measurement.rs Updated as part of this pull request.
src/policy/src/lib.rs Updated as part of this pull request.
src/policy/Cargo.toml Updated as part of this pull request.
src/migtd/src/spdm/spdm_rsp.rs Updated as part of this pull request.
src/migtd/src/ratls/server_client.rs Updated as part of this pull request.
src/migtd/src/migration/session.rs Updated as part of this pull request.
src/migtd/src/migration/rebinding.rs Updated as part of this pull request.
src/migtd/src/migration/pre_session_data.rs Updated as part of this pull request.
src/migtd/src/migration/mod.rs Updated as part of this pull request.
src/migtd/src/lib.rs Updated as part of this pull request.
src/migtd/src/event_log.rs Updated as part of this pull request.
src/migtd/src/config.rs Updated as part of this pull request.
src/migtd/src/bin/migtd/main.rs Updated as part of this pull request.
src/migtd/Cargo.toml Updated as part of this pull request.
src/crypto/src/lib.rs Updated as part of this pull request.
src/crypto/src/crl.rs Updated as part of this pull request.
sh_script/build_policy_v2.sh Updated as part of this pull request.
sh_script/build_AzCVMEmu_policy_and_test.sh Updated as part of this pull request.
sh_script/Azure/build_azure_mock_test.sh Updated as part of this pull request.
deps/td-shim-AzCVMEmu/tdx-tdcall/src/tdx_emu.rs Updated as part of this pull request.
config/templates/td_identity.json Updated as part of this pull request.
config/templates/td_identity_signed.json Updated as part of this pull request.
config/templates/tcb_mapping.json Updated as part of this pull request.
config/templates/tcb_mapping_signed.json Updated as part of this pull request.
config/templates/servtd_collateral.json Updated as part of this pull request.
config/templates/policy_issuer_chain.pem Updated as part of this pull request.
config/AzCVMEmu/tcb_mapping.json Updated as part of this pull request.
Cargo.lock Updated as part of this pull request.
Review details

Suppressed comments (8)

sh_script/build_policy_v2.sh:25

  • This new command invocation now requires a second positional input, but the existing documented command bash sh_script/build_policy_v2.sh [preprod/prod] supplies only the environment (doc/policy_v2.md:126), so it exits before generating a policy. Either preserve a default cumulative mapping path or update the documented/release invocation in the same change.
if [[ -z "$tcb_mapping_file" ]]; then
  echo "Usage: $0 <pre-production|production> <cumulative-tcb-mapping.json>" >&2
  exit 1

src/migtd/src/config.rs:126

  • The new anchor/CoRIM accessors read GUIDs that the AzCVMEmu firmware-volume implementation does not recognize: its get_file_from_fv only handles policy, root-CA, and legacy policy-issuer-chain GUIDs, and its file-based initialization has no anchor or CoRIM loaders. Consequently a servtd_corim/direct-anchor build cannot initialize under the existing emulation feature even though config now selects these paths. Add emulation support for these enrolled files or reject this configuration explicitly.
/// Read the signed ServTD TCB-mapping CoRIM (`COSE_Sign1`) from the CFV, if
/// enrolled. Returns `None` when no CoRIM was enrolled (the policy then falls
/// back to the JSON `servtdCollateral` mapping). This file is deliberately not
/// measured; see [`MIGTD_SERVTD_CORIM_FFS_GUID`].
#[cfg(feature = "servtd_corim")]
pub fn get_servtd_corim() -> Option<&'static [u8]> {
    let cfv = get_config_volume();
    fv::get_file_from_fv(cfv, pi::fv::FV_FILETYPE_RAW, MIGTD_SERVTD_CORIM_FFS_GUID)

src/migtd/src/mig_policy.rs:483

  • Because TD Identity is optional, a peer that only needs SVN evaluation may legitimately omit servtdIdentity even when the local policy includes it. This one-sided-chain branch rejects that valid SVN-only pairing before policy evaluation; date/status rules already fail closed later when peer identity data is absent. Only cross-check the identity signer chains when both artifacts are present.
        match (
            local_policy.servtd_identity_issuer_chain.as_deref(),
            verified_policy.servtd_identity_issuer_chain.as_deref(),
        ) {
            (Some(local_identity_chain), Some(peer_identity_chain)) => {
                crypto::validate_peer_cert_chain(

src/policy/src/v2/policy.rs:399

  • When servtdTcbMappingIssuerChain is omitted, the new collateral-generator CLI documents that the identity chain is the compatibility fallback, and the collateral type likewise describes older policies using the identity chain for both artifacts. This branch instead parses the CFV issuer input; a mapping signed by the identity chain fails whenever those chains differ. Prefer servtd_identity_issuer_chain before falling back to the outer CFV chain.
    src/policy/src/v2/servtd_corim.rs:264
  • This only accepts the untagged Bytes instance, but the CoRIM contract documented above is #6.560("migration-td"). A standard producer encoding the required tagged instance will be rejected here, so its signed mapping can never be used. Match the corim crate's representation of tag 560 (and make the test fixture emit that wire form) instead of accepting only a raw bstr.
    tools/migtd-hash/src/lib.rs:266
  • Measurements explicitly accepts both the canonical tdinfo_hash and legacy tdinfoHash spellings, but this release-tool updater only reads tdinfo_hash. Running the new cumulative-update flow on a legacy camelCase mapping—which the runtime still supports—fails with a missing-field error instead of preserving/updating the history. Read the alias here as well.
    xtask/src/build.rs:226
  • This relaxed validation permits --signer-anchor without --policy-issuer-chain or --servtd-corim, but the enrollment branch then passes the raw 48-byte anchor to RawPolicyData::verify. A JSON policy whose mapping has no explicit servtdTcbMappingIssuerChain falls back to that raw anchor as PEM and fails during startup, so the CLI can produce an unusable image. Reject this combination or retain a PEM source for JSON collateral verification.
    xtask/src/build.rs:230
  • --signer-anchor is silently accepted in legacy mode, but enroll only consumes it inside the self.policy_v2 branch. A caller who supplies the new option without --policy-v2 therefore gets a legacy image with no enrolled anchor and no diagnostic. Reject this option alongside --servtd-corim when policy v2 is disabled.
  • Files reviewed: 44/49 changed files
  • Comments generated: 5
  • Review effort level: Lite

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/policy/src/v2/servtd_corim.rs Outdated
Comment thread tools/migtd-hash/src/lib.rs
Comment thread tools/migtd-hash/src/main.rs Outdated
Comment thread tools/migtd-policy-generator/src/policy_v2.rs Outdated
Comment thread tools/servtd-collateral-generator/src/build.rs Outdated

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🟡 Changes recommended

Unresolved critical and moderate findings must be addressed before approval.

Get a fresh assessment by requesting another Copilot review.

Review details

Suppressed comments (14)

sh_script/build_policy_v2.sh:25

  • This new guard makes the existing documented invocation bash sh_script/build_policy_v2.sh [preprod/prod] fail whenever the second argument is omitted, while doc/policy_v2.md still instructs that command. Either preserve a default mapping source or update the documented command and all callers to pass the required cumulative mapping.
if [[ -z "$tcb_mapping_file" ]]; then
  echo "Usage: $0 <pre-production|production> <cumulative-tcb-mapping.json>" >&2
  exit 1

src/migtd/src/mig_policy.rs:463

  • This one-sided check rejects JSON↔CoRIM peers before the peer CoRIM is attached: a JSON policy has a mapping issuer chain, while a CoRIM-only policy necessarily has none. The signer-anchor comparison above already binds both policies to the same measured root/subject, so this prevents the advertised interchangeable formats from migrating together; compare JSON chains only when both peers use that format.
        // Cross-check the JSON mapping issuer chains when both sides ship one
        // (defense-in-depth; the signer_anchor equality above already binds the
        // signer). Absent on both sides (CoRIM-only) is fine; one-sided fails.
        match (
            local_policy.servtd_tcb_mapping_issuer_chain.as_deref(),

src/policy/src/v2/policy.rs:399

  • When --signer-anchor is used with JSON servtdCollateral that omits servtdTcbMappingIssuerChain, RawPolicyData::verify receives the raw 48-byte anchor as issuer_chain and the fallback at line 397 fails from_utf8 before the mapping can be verified. The image build succeeds but policy initialization fails; reject this combination or require/propagate an explicit mapping PEM for direct-anchor builds.
    src/policy/src/v2/servtd_corim.rs:264
  • The accepted environment does not match the wire form documented above (instance = #6.560("migration-td")): this branch accepts only InstanceIdChoice::Bytes. A CoRIM carrying the tagged text instance from the proposal will therefore decode successfully but every CES lookup will be ignored, causing an UnqualifiedMigTdInfo failure. Handle the text choice (or use the exact producer encoding) and add a fixture test with encoded CoRIM bytes.
    src/policy/src/v2/servtd_corim.rs:155
  • svn_for_hash returns the first matching CES record, so a signed CoRIM containing duplicate entries for one SERVTD_INFO_HASH with different SVNs is accepted and the result depends on CBOR/order. The mapping contract is one hash to one SVN (and the JSON updater already rejects conflicting duplicates); reject conflicting matches during decode/lookup instead of silently selecting one.
    src/policy/src/v2/servtd_corim.rs:155
  • The required reference-triple is never consulted: lookup walks only conditional_endorsement_series, so a signed CoRIM containing a CES for a hash but no corresponding reference digest is accepted even though the documented mapping consists of both triples. Validate the reference/CES relationship (or reject missing reference triples) during CoRIM decoding so malformed mapping documents cannot be treated as valid endorsements.
    tools/migtd-hash/src/lib.rs:264
  • This updater only reads tdinfo_hash, although the runtime Measurements type explicitly accepts tdinfoHash as a legacy alias. Updating an older v2 mapping that still uses the camelCase spelling therefore fails instead of preserving its history; accept both spellings here (or deserialize through the shared type).
    tools/migtd-hash/src/lib.rs:299
  • This current-entry insertion silently overwrites an existing mapping for the same tdinfo_hash when the new SVN differs. That can rewrite a historical release's SVN in the cumulative authority file and undermine the intended immutable hash-to-SVN history; reject a conflicting current entry instead of replacing it.
    tools/migtd-hash/src/main.rs:201
  • tdinfo_hash_v2 is None unless --policy-v2 is set, but main unconditionally reaches the expect below when this flag is used in v1 mode, so an invalid CLI combination panics instead of producing a controlled argument error. Add requires = "policy_v2" to this option (or validate it before the calculation).
    tools/migtd-policy-generator/src/policy_v2.rs:35
  • The documented CoRIM-only mode says omitting --servtd-collateral produces no servtdCollateral, but this branch leaves any pre-existing field from the base policy untouched. A reused/template policy can therefore retain stale JSON mapping/identity data, changing the measured schema and potentially causing initialization or peer-format failures. Remove the field explicitly in the else branch.
    tools/servtd-collateral-generator/readme.md:22
  • Removing --mapping-chain changes the generated collateral from explicitly carrying the chain that verifies the mapping to relying on the later CFV policy issuer chain. With the example's separate identity_issuer_chain.pem (or any independently signed mapping), the resulting policy will fail mapping verification. Keep the explicit mapping-chain argument here, or update the example to show that the mapping must be signed by the CFV policy issuer.
    tools/servtd-collateral-generator/src/build.rs:39
  • When --mapping-chain is omitted, the CLI help and the updated README say the identity chain is reused, but this expression only reads the explicitly supplied mapping chain. With the documented command, servtdTcbMappingIssuerChain is omitted and runtime falls back to the CFV policy issuer chain; if the mapping was signed by the identity chain (or another explicit mapping signer), the generated collateral cannot be verified. Fall back to identity_chain_path here, or require --mapping-chain when no identity chain is available.
    tools/servtd-collateral-generator/src/main.rs:34
  • This option description says the identity chain is used when --mapping-chain is omitted, but the implementation leaves servtdTcbMappingIssuerChain absent; runtime then falls back to the CFV policy issuer chain, not identity_chain_path. A caller that signs the mapping with the identity chain will therefore produce collateral that fails verification unless the chains happen to match. Describe the actual policy-chain fallback (or implement the documented identity-chain fallback).
    xtask/src/build.rs:230
  • --signer-anchor is silently ignored when --policy-v2 is not set: the non-v2 build path never enrolls this file, while check_arguments rejects only --servtd-corim. This makes a successful build differ from the requested CFV contents; reject the anchor option in the same branch as the CoRIM option.
  • Files reviewed: 44/49 changed files
  • Comments generated: 1
  • Review effort level: Lite

Comment thread src/policy/src/v2/policy.rs
@haitaohuang
haitaohuang force-pushed the corim-optional-servtd-port branch 2 times, most recently from 7ca8908 to a9846da Compare September 12, 2026 17:58
@jyao1

jyao1 commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Comment from Claude:

  1. verify_own_tdinfo() is deleted with no replacement, undocumented.
    src/migtd/src/mig_policy.rs previously verified the TD's own TDINFO.MROWNER == SHA384(policy signer public key) and TDINFO.MROWNERCONFIG == policy_svn ("Per GHCI 1.5" in the removed comment), called from
    get_policy_and_measure in src/migtd/src/bin/migtd/main.rs. Both the function and its call site are
    gone; crypto::get_policy_signer_key_hash is now an orphaned function with zero callers (confirmed by
    grep across all three commits — every match is a - line). This removes a binding between the running
    TD's measured identity fields and the enrolled policy signer/SVN, for all policy_v2 builds, not just the
    new anchor-only path where the full PEM chain needed for the old check is unavailable. Nothing in the PR
    body, issue Proposal: Use CoRIM as the MigTD endorsement format #929, issue Proposal: Make the TD Identity artifact optional #930, or doc/policy_v2.md mentions this. This needs an explicit call: either it's
    intentionally superseded by the signer-anchor binding (RTMR1) and should say so in doc/policy_v2.md, or
    it's an accidental regression that needs to come back (adapted to work against a signer anchor instead of
    a full chain).

@jyao1

jyao1 commented Sep 14, 2026

Copy link
Copy Markdown
Contributor

Comment from Claude:

  1. TdTcbMapping::validate() removed with no replacement for the JSON mapping path.
    src/policy/src/v2/servtd_collateral.rs: RawServtdTcbMapping::verify_signature used to call
    mapping.validate(), which rejected malformed hash lengths and conflicting SVNs for the same
    tdinfo_hash within a JSON mapping. That call is now removed outright (not moved elsewhere — grep
    confirms no .validate() call site remains, and the corresponding test
    test_get_engine_svn had its engine.validate().unwrap() line deleted rather than replaced). The
    CoRIM path grew equivalent-and-tested validation (validated_svn_mappings), but the legacy JSON path
    did not get an equivalent. Impact is lower than finding 1 (a malformed/duplicate JSON mapping is
    producer-controlled, not attacker-controlled at runtime), but it's an asymmetry worth a conscious
    decision — either restore equivalent validation for JSON mappings or note in the PR/doc that JSON
    mappings are considered a fully-trusted, pre-validated artifact going forward.

@haitaohuang
haitaohuang force-pushed the corim-optional-servtd-port branch from a9846da to ca7ba83 Compare September 14, 2026 22:41
haitaohuang added a commit to haitaohuang/MigTD that referenced this pull request Sep 15, 2026
Require --mapping-chain even when an identity chain is supplied, and
always embed servtdTcbMappingIssuerChain in generated collateral.
This avoids the ambiguous omission that selected the CFV policy chain
at runtime rather than the independently supplied identity chain.

Pass the actual mapping signer's chain from each policy-generation
caller, including independent signer-rotation variants, and document
the explicit input contract.

Keep identity optional with its separate chain and preserve existing
runtime verification, enrollment modes, and legacy policy compatibility.

Link: intel#1037 (comment)
Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:gpt-6-astra
@haitaohuang

Copy link
Copy Markdown
Contributor Author

cargo deny was new dep vul.

@jyao1

jyao1 commented Sep 17, 2026

Copy link
Copy Markdown
Contributor

cargo deny was new dep vul.

Yes. Will look into that.

Please focus on review feedback first.

BTW: I still did not see anyone from MSFT to review and approve...

@jyao1 jyao1 closed this Sep 21, 2026
@jyao1 jyao1 reopened this Sep 21, 2026
Use SHA-384 over the complete unmasked TDINFO as the Policy v2 mapping key.
Canonicalize policyData once with only the circular mapping removed so
runtime verification and offline tooling extend identical RTMR2 bytes.

Verify the signed mapping with the RTMR1-bound policy issuer chain, remove
the separate mapping chain and obsolete mapping identity fields, and ignore
the legacy outer policy signature as required by the proposal.

Resolve the initial SVN through the source's authenticated JSON mapping
and take its current SVN from the authenticated quote or TDREPORT
evaluation. This allows an older destination to accept a newer source
release without predicting its hash. Fail closed on missing authenticated
SVN evidence and prevent the SERVTD_EXT current hash from overriding it.

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:GPT-5.6 Sol
Assisted-by: GitHub Copilot CLI:gpt-6-astra
Carry authenticated SERVTD_EXT continuity evidence through migration and
rebinding. Bind the peer policy issuer chain to attested RTMR1, reject
lookup misses or SVN rollback, and fail closed when SERVTD_ATTR masking
makes the endorsed unmasked hashes inapplicable.

Match policy-v2 migration and rebinding request headers to their four
encoded elements while retaining the five-element policy-v1 migration
format.

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:GPT-5.6 Sol
Assisted-by: GitHub Copilot CLI:gpt-6-astra
Retain authority-maintained hash history when adding a release, allow
multiple hashes at one SVN, and reject conflicting duplicate assignments.
Emit deterministic mapping bytes and validate signed mappings before use.

Update the policy-v2 guide and mapping-update example for the cumulative
workflow, including the required --mapping-isvsvn argument. Document
mapping signer authority, trust assumptions, and the distinction between
release-SVN continuity and independent policy-SVN ordering.

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:GPT-5.6 Sol
Assisted-by: GitHub Copilot CLI:gpt-6-astra
Consume the signed identity used to build the measured release instead of re-signing it after recording tdinfo_hash. Reject any non-mapping policy change before replacing the final policy outputs, including identity, issuer-chain, and platform collateral changes.

Document preparation before measurement, immutable release inputs, and a final image hash comparison against the recorded endorsement.

Assisted-by: GitHub Copilot CLI:gpt-6-astra
Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Remove check_engine_not_older and its dedicated test because runtime continuity uses the MigTD helper instead. Preserve the equal-SVN assertion in the live continuity tests alongside the existing upgrade, downgrade, and lookup-failure coverage.

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:gpt-6-astra
Measure the policy signer as a stable root-certificate plus leaf-subject anchor in both runtime and offline hashing. Require authenticated, numbered servTD CRLs so omission cannot bypass signer-chain enforcement at initialization or peer validation, and support a monotonic servtd CRL policy floor.\n\nPort only the proposal-specific implementation from ms/integration while retaining tcbmapping's existing JSON mapping and identity model.

Assisted-by: GitHub Copilot CLI:GPT-5.6 Sol
Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:gpt-6-astra
Exercise signed empty CRLs, revoked leaf and intermediate certificates, issuer mismatches, invalid signatures, and CA constraints. Cover policy rejection and peer checks against verifier-owned revocation state, including a rotated local policy signer.

Use public fixtures without retaining private keys. Extract the existing peer revocation block without changing its ordering or logging so tests can use independently verified policies without global state. Add serde_json only as a dev dependency for test policy construction.

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:gpt-6-astra
haitaohuang and others added 8 commits September 30, 2026 21:46
Accept only complete, direct, issuer-wide CRLs signed by the signing leaf\x27s immediate non-root CA with explicit cRLSign permission. Scope serial lookups to the signing leaf, authenticate peer CRL metadata under the same issuer as the local authoritative CRL, and keep peer revocation entries out of local decisions.

Reject delta, partitioned, indirect, reason-scoped, malformed and unsupported critical inputs while retaining non-critical Microsoft metadata. Leave Intel platform CRL parsing unrestricted. Cover signed negative fixtures and update mock issuers and the supported-profile documentation.

Assisted-by: GitHub Copilot CLI:gpt-6-astra
Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Add feature-gated signed CoRIM TCB mappings, authenticated peer transport, and direct signer-anchor enrollment. Keep JSON mappings as the default, support optional simplified servTD identity, and fail closed for date or status rules when identity data is unavailable.

Co-authored-by: Haitao Huang <haitaohuang@microsoft.com>
Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:GPT-5.6 Sol
Assisted-by: GitHub Copilot CLI:gpt-6-astra
Check the actual policy before building an anchor-only configuration. Require an embedded mapping chain for retained JSON collateral, or a CoRIM artifact when JSON collateral is absent, and retain the mandatory signer CRL.

Reject invalid anchor sizes and missing or empty CoRIM files early. Document anchor precedence without imposing a CoRIM requirement on valid JSON-only configurations.

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:gpt-6-astra
Expose signer anchors and signed CoRIM under their firmware GUIDs in AzCVMEmu. Load direct anchors as a PEM alternative and route shared or per-peer artifacts through the launcher while preserving JSON mode and rejecting unsupported or invalid inputs explicitly.

Add public signed fixtures and regressions for artifact routing, signer binding, local revocation, and TLS/SPDM CoRIM emulation with optional JSON identity. Exercise startup errors before VMM logging is available.

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:gpt-6-astra
The full, unmasked tdinfo_hash includes MROWNER and MROWNERCONFIG.
Authentication requires a matching hash in an authenticated JSON or
CoRIM TCB mapping whose signer is bound to the RTMR1-measured trust
anchor. That endorsement already authorizes the exact owner-field
values together with the rest of TDINFO.

Under this endorsement model, rechecking MROWNER against the policy
signer's leaf-key hash and MROWNERCONFIG against an encoding of
policySvn adds no further authorization. It only imposes legacy
encodings on already-endorsed fields. Changing either field changes
the hash that must be endorsed; no owner-field coverage is lost.

Document this rationale for retiring verify_own_tdinfo, rather than
treating RTMR measurements as an assertion of the old equalities.
Explain that RTMR1 binds signer identity, RTMR2 measures canonical
policy data including policySvn, and the authenticated mapping supplies
the distinct release isvsvn. Apply the model to PEM and direct-anchor
enrollment without forcing leaf-key rotation into TD-creation fields.

Remove get_policy_signer_key_hash, which has no remaining callers.
Retain the public-key extraction used by certificate and signature
verification.

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:gpt-6-astra
RawServtdTcbMapping::verify_signature stopped validating the deserialized
mapping, so a valid signature could authenticate malformed TDINFO hashes
or conflicting SVNs for the same hash. Signature authenticity does not
establish that the endorsed mapping is structurally valid or unambiguous.

Restore TdTcbMapping::validate and call it after signature verification
and deserialization. Reject invalid hex, hashes other than 48 bytes, and
case-insensitive duplicate hashes with different SVNs. Preserve the
previous acceptance of identical hash/SVN duplicates.

Cover malformed encodings and lengths, conflicting and identical
duplicates, and a correctly signed conflicting mapping whose signature
is independently verified by the regression. Retain only the public
fixture chain and signed payload; its temporary signing keys are not
included. Document the restored JSON mapping requirements.

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:gpt-6-astra
Require --mapping-chain even when an identity chain is supplied, and
always embed servtdTcbMappingIssuerChain in generated collateral.
This avoids the ambiguous omission that selected the CFV policy chain
at runtime rather than the independently supplied identity chain.

Pass the actual mapping signer's chain from each policy-generation
caller, including independent signer-rotation variants, and document
the explicit input contract.

Keep identity optional with its separate chain and preserve existing
runtime verification, enrollment modes, and legacy policy compatibility.

Link: intel#1037 (comment)
Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:gpt-6-astra
Regenerate signed CoRIM and optional JSON fixtures with a leaf/intermediate/root chain and intermediate-issued complete CRLs. Preserve the endorsed TDINFO hash and SVN and verify peer CRL metadata only after the authenticated COSE signer chain is attached.

Keep local revocations authoritative even when a delivered peer CRL revokes its own signer, reject unauthenticated peer CRL metadata, and document the mapping-chain measurement exclusion used by finalization.

Assisted-by: GitHub Copilot CLI:gpt-6-astra
Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
@haitaohuang
haitaohuang force-pushed the corim-optional-servtd-port branch from 48e8c9e to 2a52dc2 Compare October 1, 2026 00:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants