Skip to content

Implement rebind for AzCVMEmu#734

Open
haitaohuang wants to merge 4 commits intointel:mainfrom
haitaohuang:rebind2
Open

Implement rebind for AzCVMEmu#734
haitaohuang wants to merge 4 commits intointel:mainfrom
haitaohuang:rebind2

Conversation

@haitaohuang
Copy link
Contributor

No description provided.

@haitaohuang haitaohuang requested a review from jyao1 as a code owner March 2, 2026 18:59
@jyao1
Copy link
Contributor

jyao1 commented Mar 4, 2026

could someone from MSFT to review AzCVMEmu?

@haitaohuang haitaohuang force-pushed the rebind2 branch 2 times, most recently from 4c53a30 to aa35f45 Compare March 4, 2026 23:08
haitaohuang and others added 4 commits March 5, 2026 11:09
- Remove MIGTD_ROOT_CA_FILE for policy_v2 (root CA not needed policy v2)
- Extract quote data into reusable tdx-mock-data crate
- Generate the mock report from the quote data, remove hard coded report
- Compute SHA384 hashes at runtime for report_mac integrity

Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Populate emulated ServTD extension fields (init_servtd_info_hash,
init_attr, cpusvn, tee_tcb_svn) from TD report data when
setting up rebinding emulation. Previously these fields were all
zeros, causing verify_servtd_hash to fail with InvalidTdReport
during TLS handshake.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
Add two new test matrix entries for rebinding:
- Rebind Prepare (Skip RA): builds with policy_v2 + skip-RA features
- Rebind Prepare (Mock Report): builds with mock report, generates
  policy from mock data before running rebind test

Also update log checking to handle rebind-specific log files.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Signed-off-by: Haitao Huang <haitaohuang@microsoft.com>
@haitaohuang
Copy link
Contributor Author

could someone from MSFT to review AzCVMEmu?

@jyao1 MSFT review done.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants