Skip to content

feat: require launch measurements for SEV-enabled subnets - #11057

Open
r-birkner wants to merge 1 commit into
masterfrom
rjb/sev-enabled-subnets-can-only-be-upgraded-with-measurement
Open

feat: require launch measurements for SEV-enabled subnets#11057
r-birkner wants to merge 1 commit into
masterfrom
rjb/sev-enabled-subnets-can-only-be-upgraded-with-measurement

Conversation

@r-birkner

Copy link
Copy Markdown
Contributor

An SEV-enabled subnet may now only run a GuestOS version that has guest_launch_measurements. This is enforced as a registry invariant, so any mutation that would leave an SEV-enabled subnet on a version without launch measurements is rejected.

Note: A CloudEngine may leave replica_version_id blank, in which case it runs the versions of the StandardEngineReplicaVersionRecord.

@github-actions github-actions Bot added the feat label Aug 6, 2026
@r-birkner

Copy link
Copy Markdown
Contributor Author

Note for Reviewer @daniel-wong-dfinity-org: There is also this PR that addresses the same issue in a different place. By adding this one, we are protected at the version election and the deployment. But we can also drop this if you think it is not needed.

@r-birkner
r-birkner marked this pull request as ready for review August 7, 2026 09:43
@r-birkner
r-birkner requested a review from a team as a code owner August 7, 2026 09:43

@github-actions github-actions Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This pull request changes code owned by the Governance team. Therefore, make sure that
you have considered the following (for Governance-owned code):

  1. Update unreleased_changelog.md (if there are behavior changes, even if they are
    non-breaking).

  2. Are there BREAKING changes?

  3. Is a data migration needed?

  4. Security review?

How to Satisfy This Automatic Review

  1. Go to the bottom of the pull request page.

  2. Look for where it says this bot is requesting changes.

  3. Click the three dots to the right.

  4. Select "Dismiss review".

  5. In the text entry box, respond to each of the numbered items in the previous
    section, declare one of the following:

  • Done.

  • $REASON_WHY_NO_NEED. E.g. for unreleased_changelog.md, "No
    canister behavior changes.", or for item 2, "Existing APIs
    behave as before.".

Brief Guide to "Externally Visible" Changes

"Externally visible behavior change" is very often due to some NEW canister API.

Changes to EXISTING APIs are more likely to be "breaking".

If these changes are breaking, make sure that clients know how to migrate, how to
maintain their continuity of operations.

If your changes are behind a feature flag, then, do NOT add entrie(s) to
unreleased_changelog.md in this PR! But rather, add entrie(s) later, in the PR
that enables these changes in production.

Reference(s)

For a more comprehensive checklist, see here.

GOVERNANCE_CHECKLIST_REMINDER_DEDUP

@zeropath-ai

zeropath-ai Bot commented Aug 7, 2026

Copy link
Copy Markdown

No security or compliance issues detected. Reviewed everything up to 70740be.

Security Overview
Detected Code Changes
Change Type Relevant files
Enhancement ► rs/registry/canister/src/common/test_helpers.rs
    Add helper to insert guest launch measurements into replica version
► rs/registry/canister/src/invariants/replica_version.rs
    Make get_all_standard_engine_replica_versions public
► rs/registry/canister/src/invariants/subnet.rs
    Update imports and integrate SEV launch measurement checks into invariants
► rs/registry/canister/src/invariants/subnet/tests.rs
    Add tests for SEV launch measurements and related scenarios
► rs/registry/canister/src/mutations/do_update_subnet.rs
    Update test helpers usage to include launch measurement helper
► rs/registry/canister/unreleased_changelog.md
    Document SEV subnet launch measurement invariant changes

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant