fix(enclave): verify email and data owners from the Confidential Space token - #9548
Open
rasswanth-s wants to merge 1 commit into
Open
rasswanth-s wants to merge 1 commit into
rasswanth-s wants to merge 1 commit into
Conversation
pjwerneck
approved these changes
Oct 2, 2026
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
On Confidential Space,
attest_peerchecked the enclave's email and data owners against theclaims document the enclave publishes itself. The token only bound that document by a sha256 in
eat_nonce. Any code running in the container, including a job, can call the launcher socketand get a valid Google-signed token over a document naming different data owners. Image digest,
signature and every other check still pass, so a malicious job could change who approves jobs
without failing attestation.
Fix
The launcher already records the operator's
tee-env-*values in the token, undersubmods.container.env_override, before the container starts. No deployment change is needed:terraform and the Justfile already set both variables, and the Dockerfile allows them.
env_overrideand comparedwith the policy through the shared
check_expected().envisn't used, because it also holdsimage
ENVdefaults.fall back to the enclave's own word.
key_bundle, which only exists atruntime. It must now also agree with
env_override; if it doesn't,claims_bindingfails andthe key isn't adopted.
structure_claims()showsenv_override.Asana
https://app.asana.com/1/1185126988600652/project/1210542925864934/task/1218794314078561