feat: require launch measurements for SEV-enabled subnets - #11057
feat: require launch measurements for SEV-enabled subnets#11057r-birkner wants to merge 1 commit into
Conversation
…versions with launch measurements
|
Note for Reviewer @daniel-wong-dfinity-org: There is also this PR that addresses the same issue in a different place. By adding this one, we are protected at the version election and the deployment. But we can also drop this if you think it is not needed. |
There was a problem hiding this comment.
This pull request changes code owned by the Governance team. Therefore, make sure that
you have considered the following (for Governance-owned code):
-
Update
unreleased_changelog.md(if there are behavior changes, even if they are
non-breaking). -
Are there BREAKING changes?
-
Is a data migration needed?
-
Security review?
How to Satisfy This Automatic Review
-
Go to the bottom of the pull request page.
-
Look for where it says this bot is requesting changes.
-
Click the three dots to the right.
-
Select "Dismiss review".
-
In the text entry box, respond to each of the numbered items in the previous
section, declare one of the following:
-
Done.
-
$REASON_WHY_NO_NEED. E.g. for
unreleased_changelog.md, "No
canister behavior changes.", or for item 2, "Existing APIs
behave as before.".
Brief Guide to "Externally Visible" Changes
"Externally visible behavior change" is very often due to some NEW canister API.
Changes to EXISTING APIs are more likely to be "breaking".
If these changes are breaking, make sure that clients know how to migrate, how to
maintain their continuity of operations.
If your changes are behind a feature flag, then, do NOT add entrie(s) to
unreleased_changelog.md in this PR! But rather, add entrie(s) later, in the PR
that enables these changes in production.
Reference(s)
For a more comprehensive checklist, see here.
GOVERNANCE_CHECKLIST_REMINDER_DEDUP
|
✅ No security or compliance issues detected. Reviewed everything up to 70740be. Security Overview
Detected Code Changes
|
An SEV-enabled subnet may now only run a GuestOS version that has
guest_launch_measurements. This is enforced as a registry invariant, so any mutation that would leave an SEV-enabled subnet on a version without launch measurements is rejected.Note: A CloudEngine may leave
replica_version_idblank, in which case it runs the versions of theStandardEngineReplicaVersionRecord.