Skip to content

Conversation

@Jakob-Naucke
Copy link
Member

Add --initdata flag to trustee-attester, taking initdata as a string.

Preliminary change: some manpage fixes

cc @uril

- Do not use the RB formatter, which drops spaces and alternates
  bold/non-bold formatting which was probably unintended.
- Indent get-resource subcommand and move below options.

Signed-off-by: Jakob Naucke <[email protected]>
@Jakob-Naucke Jakob-Naucke requested a review from a team as a code owner October 31, 2025 16:04
@Jakob-Naucke Jakob-Naucke force-pushed the trustee-attester-initdata branch from d0dd922 to f18b308 Compare October 31, 2025 16:11
Copy link
Member

@fitzthum fitzthum left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

It might be good to note somewhere that this is the plaintext init-data and that Trustee will expect the hash of the init-data to have been already measured somehow.

Add `--initdata` flag to trustee-attester, taking initdata as a string.

Signed-off-by: Jakob Naucke <[email protected]>
@Jakob-Naucke Jakob-Naucke force-pushed the trustee-attester-initdata branch from f18b308 to 15269b0 Compare October 31, 2025 16:42
@Jakob-Naucke
Copy link
Member Author

Thanks for the fast review. Have added a remark on initdata measurement in the man page.

@Xynnn007 Xynnn007 merged commit fb0ebbf into confidential-containers:main Nov 1, 2025
14 checks passed
@Jakob-Naucke Jakob-Naucke deleted the trustee-attester-initdata branch November 3, 2025 13:32
Jakob-Naucke added a commit to Jakob-Naucke/trusted-cluster-investigations that referenced this pull request Nov 12, 2025
Requires initdata-compatible trustee-attester [1] and
clevis-pin-trustee [2]. Uses a Trustee that does not verify initdata
for now [3].

[1] confidential-containers/guest-components#1163
[2] latchset/clevis-pin-trustee#12
[3] https://github.com/confidential-clusters/trustee/tree/skip-verify-initdata

Signed-off-by: Jakob Naucke <[email protected]>
Jakob-Naucke added a commit to Jakob-Naucke/trusted-cluster-investigations that referenced this pull request Nov 12, 2025
Requires initdata-compatible trustee-attester [1] and
clevis-pin-trustee [2]. Uses a Trustee that does not verify initdata
for now [3].

[1] confidential-containers/guest-components#1163
[2] latchset/clevis-pin-trustee#12
[3] https://github.com/confidential-clusters/trustee/tree/skip-verify-initdata

Signed-off-by: Jakob Naucke <[email protected]>
Jakob-Naucke added a commit to Jakob-Naucke/trusted-cluster-investigations that referenced this pull request Nov 19, 2025
Requires initdata-compatible trustee-attester [1] and
clevis-pin-trustee [2]. Uses a Trustee that does not verify initdata
for now [3].

[1] confidential-containers/guest-components#1163
[2] latchset/clevis-pin-trustee#12
[3] https://github.com/confidential-clusters/trustee/tree/skip-verify-initdata

Signed-off-by: Jakob Naucke <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants