feat: require SEV launch measurements for new GuestOS versions - #11052
feat: require SEV launch measurements for new GuestOS versions#11052r-birkner wants to merge 2 commits into
Conversation
There was a problem hiding this comment.
This pull request changes code owned by the Governance team. Therefore, make sure that
you have considered the following (for Governance-owned code):
-
Update
unreleased_changelog.md(if there are behavior changes, even if they are
non-breaking). -
Are there BREAKING changes?
-
Is a data migration needed?
-
Security review?
How to Satisfy This Automatic Review
-
Go to the bottom of the pull request page.
-
Look for where it says this bot is requesting changes.
-
Click the three dots to the right.
-
Select "Dismiss review".
-
In the text entry box, respond to each of the numbered items in the previous
section, declare one of the following:
-
Done.
-
$REASON_WHY_NO_NEED. E.g. for
unreleased_changelog.md, "No
canister behavior changes.", or for item 2, "Existing APIs
behave as before.".
Brief Guide to "Externally Visible" Changes
"Externally visible behavior change" is very often due to some NEW canister API.
Changes to EXISTING APIs are more likely to be "breaking".
If these changes are breaking, make sure that clients know how to migrate, how to
maintain their continuity of operations.
If your changes are behind a feature flag, then, do NOT add entrie(s) to
unreleased_changelog.md in this PR! But rather, add entrie(s) later, in the PR
that enables these changes in production.
Reference(s)
For a more comprehensive checklist, see here.
GOVERNANCE_CHECKLIST_REMINDER_DEDUP
|
✅ No security or compliance issues detected. Reviewed everything up to d8aae0d. Security Overview
Detected Code Changes
|
unreleased_changelog.md has been updated.
There was a problem hiding this comment.
Pull request overview
This PR tightens ReviseElectedGuestosVersions validation so that electing a new GuestOS/replica version requires SEV-SNP launch measurements, preventing versions that cannot be attested from becoming electable.
Changes:
- Treat
guest_launch_measurementsas a required “elect version” parameter (must be set/unset together with the other election parameters) and improve validation errors by listing missing parameters. - Validate provided launch measurements in
ReviseElectedGuestosVersionsPayload::validateto catch malformed data before proposal submission/execution. - Update system/integration tests and changelog to reflect the new requirement.
Reviewed changes
Copilot reviewed 5 out of 5 changed files in this pull request and generated no comments.
Show a summary per file
| File | Description |
|---|---|
| rs/tests/networking/nns_delegation_test.rs | Passes launch measurements when electing an upgrade version in the networking test flow. |
| rs/registry/canister/unreleased_changelog.md | Documents the new validation requirement and updated rejection behavior/error messaging. |
| rs/registry/canister/src/mutations/do_revise_elected_replica_versions/tests.rs | Adds unit tests covering valid/invalid/missing launch measurement scenarios for the payload. |
| rs/registry/canister/src/mutations/do_revise_elected_replica_versions.rs | Enforces “all-or-nothing” election parameters including measurements and validates measurement contents. |
| rs/nns/integration_tests/src/upgrades_handler.rs | Updates integration tests to include measurements on election and adds negative cases for missing/empty measurements. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
6b0972a to
d8aae0d
Compare
Electing a GuestOS version now requires SEV-SNP launch measurements. Without a
measurement, nodes running the version cannot be attested, so a version that
lacks one should never become electable in the first place.
Note for release tooling: a
ReviseElectedGuestosVersionsproposal submittedwithout
--guest-launch-measurements-pathwill now be rejected.