Skip to content

Create shared TCB Module #304

Description

@amd-aliem

Context

Follow-up from PR #283 - (review thread from @DGonzalezVillal on snphost_config_commit.py).

TCB parsing, comparison, and to_u64 packing are already being reimplemented independently across 3 open PRs, and will keep recurring in every future TCB-touching test. Create a common module.

Preferred long-term direction - structured output from snpguest / sev crate

In my opinion we should improve snpguest to emit consumable structured output (e.g. snpguest display report --json, and similar for TCB) backed by the sev crate, and have the harness consume that. That, or have a rust->python binding for the sev crate.

  • We currently re-define report fields the sev crate already models, so we don't exercise our own crate or the user-facing snpguest tool.
  • Every new report version has to be re-implemented here in addition to the crate/tool - double maintenance, and a place for the two to drift.
  • Parsing human-readable CLI output is brittle - raw-offset parsing (as pr#247 does) avoids that but moves the version/generation-tracking burden into the harness.

Proposal - short-term consolidation

Until structured snpguest output is available, collapse the three copies into a single shared module (e.g. sev_verify/cert_tests/common/tcb.py) rather than maintaining three.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions