Skip to content

docs(policy): align one-hash measurement contract - #219

Open
Haitao Huang (haitaohuang) wants to merge 3 commits into
microsoft:one_hashfrom
haitaohuang:user/hhuang/issue-204-align-one-hash-docs
Open

Haitao Huang (haitaohuang) wants to merge 3 commits into
microsoft:one_hashfrom
haitaohuang:user/hhuang/issue-204-align-one-hash-docs

Conversation

@haitaohuang

Copy link
Copy Markdown
Collaborator

Summary

  • document all JSON RTMR2 redactions and the CoRIM-only measured shape
  • clarify direct signer-anchor precedence and the RTMR1 contract
  • document monotonic generation freshness for a firmware environment without a trusted wall clock
  • remove references to a nonexistent CoRIM design document

Dependency

Depends on #208. This branch includes the two #208 commits so the documentation remains aligned; its diff will shrink after #208 merges.

Closes #204

Treat signed JSON version fields and CoMID tag-version as monotonic generations. Require local artifacts to meet the measured policySvn/MROWNERCONFIG floor without using wall-clock time.

Compare peer JSON mapping and identity versions only against like-for-like local JSON baselines; CoRIM tag-version remains an independent namespace used only for its local floor. Update generation tooling while preserving newer artifacts and signer rotation.

Fixes microsoft#198

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: GitHub Copilot CLI:gpt-5.6-sol [migtd-review]
The proposal now distinguishes routine cumulative collateral releases from
security-driven policySvn floor increases. It also documents that removing a
historical MigTD hash prevents resolving init_servtd_info_hash, which can
strand tenants from migration or rebinding.

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Assisted-by: Dallas:gpt-5.6-sol [GitHub Copilot CLI]
Document all JSON RTMR2 redactions, the CoRIM-only measured shape, direct signer-anchor enrollment, and the monotonic freshness model. Remove references to the nonexistent CoRIM design document.

Assisted-by: GitHub Copilot CLI:GPT-5.6 Sol [migtd-review]
Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant