Skip to content

fix(enclave): verify email and data owners from the Confidential Space token - #9548

Merged
rasswanth-s merged 2 commits into
devfrom
rasswanth/verify-env-params
Oct 7, 2026
Merged

rasswanth-s merged 2 commits into
devfrom
rasswanth/verify-env-params

Conversation

@rasswanth-s

@rasswanth-s rasswanth-s commented Oct 2, 2026 •

Copy link
Copy Markdown
Collaborator

Problem

On Confidential Space, attest_peer checked the enclave's email and data owners against the
claims document the enclave publishes itself. The token only bound that document by a sha256 in
eat_nonce. Any code running in the container, including a job, can call the launcher socket
and get a valid Google-signed token over a document naming different data owners. Image digest,
signature and every other check still pass, so a malicious job could change who approves jobs
without failing attestation.

Fix

The launcher already records the operator's tee-env-* values in the token, under
submods.container.env_override, before the container starts. No deployment change is needed:
terraform and the Justfile already set both variables, and the Dockerfile allows them.

  • Email and data owners come from the token. They're read from env_override and compared
    with the policy through the shared check_expected(). env isn't used, because it also holds
    image ENV defaults.
  • Missing values fail. A pinned value the token doesn't record fails the check, so it can't
    fall back to the enclave's own word.
  • The claims document stays, for the key. It still binds key_bundle, which only exists at
    runtime. It must now also agree with env_override; if it doesn't, claims_binding fails and
    the key isn't adopted.
  • Display: structure_claims() shows env_override.

Asana

https://app.asana.com/1/1185126988600652/project/1210542925864934/task/1218794314078561

@rasswanth-s
rasswanth-s enabled auto-merge October 7, 2026 09:22
@rasswanth-s
rasswanth-s disabled auto-merge October 7, 2026 09:23
@rasswanth-s
rasswanth-s merged commit 5673708 into dev Oct 7, 2026
20 checks passed
@rasswanth-s
rasswanth-s deleted the rasswanth/verify-env-params branch October 7, 2026 09:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants