Skip to content

feat: require SEV launch measurements for new GuestOS versions - #11052

Open
r-birkner wants to merge 2 commits into
masterfrom
rjb/require-launch-measurement
Open

feat: require SEV launch measurements for new GuestOS versions#11052
r-birkner wants to merge 2 commits into
masterfrom
rjb/require-launch-measurement

Conversation

@r-birkner

@r-birkner r-birkner commented Aug 6, 2026

Copy link
Copy Markdown
Contributor

Electing a GuestOS version now requires SEV-SNP launch measurements. Without a
measurement, nodes running the version cannot be attested, so a version that
lacks one should never become electable in the first place.

Note for release tooling: a ReviseElectedGuestosVersions proposal submitted
without --guest-launch-measurements-path will now be rejected.

@github-actions github-actions Bot added the chore label Aug 6, 2026
@r-birkner r-birkner changed the title chore: require SEV launch measurements for new GuestOS versions feat: require SEV launch measurements for new GuestOS versions Aug 6, 2026
@github-actions github-actions Bot added feat and removed chore labels Aug 6, 2026
@r-birkner
r-birkner marked this pull request as ready for review August 6, 2026 14:47
@r-birkner
r-birkner requested review from a team as code owners August 6, 2026 14:47

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request changes code owned by the Governance team. Therefore, make sure that
you have considered the following (for Governance-owned code):

  1. Update unreleased_changelog.md (if there are behavior changes, even if they are
    non-breaking).

  2. Are there BREAKING changes?

  3. Is a data migration needed?

  4. Security review?

How to Satisfy This Automatic Review

  1. Go to the bottom of the pull request page.

  2. Look for where it says this bot is requesting changes.

  3. Click the three dots to the right.

  4. Select "Dismiss review".

  5. In the text entry box, respond to each of the numbered items in the previous
    section, declare one of the following:

  • Done.

  • $REASON_WHY_NO_NEED. E.g. for unreleased_changelog.md, "No
    canister behavior changes.", or for item 2, "Existing APIs
    behave as before.".

Brief Guide to "Externally Visible" Changes

"Externally visible behavior change" is very often due to some NEW canister API.

Changes to EXISTING APIs are more likely to be "breaking".

If these changes are breaking, make sure that clients know how to migrate, how to
maintain their continuity of operations.

If your changes are behind a feature flag, then, do NOT add entrie(s) to
unreleased_changelog.md in this PR! But rather, add entrie(s) later, in the PR
that enables these changes in production.

Reference(s)

For a more comprehensive checklist, see here.

GOVERNANCE_CHECKLIST_REMINDER_DEDUP

@zeropath-ai

zeropath-ai Bot commented Aug 6, 2026

Copy link
Copy Markdown

No security or compliance issues detected. Reviewed everything up to d8aae0d.

Security Overview
Detected Code Changes
Change Type Relevant files
Enhancement ► rs/nns/integration_tests/src/upgrades_handler.rs
    Implement guest launch measurements handling and validation for elected replica versions
► rs/registry/canister/src/mutations/do_revise_elected_replica_versions.rs
    Require and validate guest_launch_measurements when electing a version; improve validation error messaging and parameter checks
► rs/registry/canister/tests/update_subnet_and_elect_replica_version.rs
    Adapt tests to use lazy_static for guest launch measurements and updated payload construction
► rs/registry/canister/tests/update_subnet_and_elect_replica_version.rs
    Update tests to reflect new guest_launch_measurements usage
► rs/registry/canister/unreleased_changelog.md
    Add changelog entry: guest launch measurements is now required (when electing a new Guestos version)
Bug Fix ► rs/nns/integration_tests/src/upgrades_handler.rs
    Import updated GuestLaunchMeasurement related types and add test helper for measurements
► rs/tests/networking/nns_delegation_test.rs
    Adjust upgrade path to pass guest_launch_measurements during upgrade on non-NNS subnets

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR tightens ReviseElectedGuestosVersions validation so that electing a new GuestOS/replica version requires SEV-SNP launch measurements, preventing versions that cannot be attested from becoming electable.

Changes:

  • Treat guest_launch_measurements as a required “elect version” parameter (must be set/unset together with the other election parameters) and improve validation errors by listing missing parameters.
  • Validate provided launch measurements in ReviseElectedGuestosVersionsPayload::validate to catch malformed data before proposal submission/execution.
  • Update system/integration tests and changelog to reflect the new requirement.

Reviewed changes

Copilot reviewed 5 out of 5 changed files in this pull request and generated no comments.

Show a summary per file
File Description
rs/tests/networking/nns_delegation_test.rs Passes launch measurements when electing an upgrade version in the networking test flow.
rs/registry/canister/unreleased_changelog.md Documents the new validation requirement and updated rejection behavior/error messaging.
rs/registry/canister/src/mutations/do_revise_elected_replica_versions/tests.rs Adds unit tests covering valid/invalid/missing launch measurement scenarios for the payload.
rs/registry/canister/src/mutations/do_revise_elected_replica_versions.rs Enforces “all-or-nothing” election parameters including measurements and validates measurement contents.
rs/nns/integration_tests/src/upgrades_handler.rs Updates integration tests to include measurements on election and adds negative cases for missing/empty measurements.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread rs/nns/integration_tests/src/upgrades_handler.rs
Comment thread rs/nns/integration_tests/src/upgrades_handler.rs
Comment thread rs/nns/integration_tests/src/upgrades_handler.rs Outdated
Comment thread rs/nns/integration_tests/src/upgrades_handler.rs
Comment thread rs/registry/canister/src/mutations/do_revise_elected_replica_versions/tests.rs Outdated
Comment thread rs/registry/canister/src/mutations/do_revise_elected_replica_versions/tests.rs Outdated
Comment thread rs/registry/canister/src/mutations/do_revise_elected_replica_versions.rs Outdated
Comment thread rs/registry/canister/unreleased_changelog.md
@r-birkner
r-birkner force-pushed the rjb/require-launch-measurement branch from 6b0972a to d8aae0d Compare August 10, 2026 17:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants