Skip to content

Commit b7f9e68

Browse files
committed
docs: add v0.6.0 release test plan and results
1 parent 46bc8d5 commit b7f9e68

15 files changed

Lines changed: 2461 additions & 0 deletions
Lines changed: 45 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,45 @@
1+
# dstack v0.6.0 preview 测试执行摘要
2+
3+
> 冻结版本:`dc3b95117f518a752c0726ecd44ba7888a25cc49`(2026-07-22)
4+
> 对比基线:meta-dstack `v0.5.11`
5+
> 状态:**测试已执行;发布门禁尚未通过**
6+
7+
## 结论
8+
9+
当前自动化、模拟集成与合约测试未发现确定的产品功能失败。此前阻塞真实硬件测试的 Local-Key-Provider error 44 已定位为公共 PCCS 缺少本机 PCK certificate;使用已 provision 本机的 PCCS 后,production SGX Local-Key-Provider、真实 TDX KMS onboarding、v0.5.11/current 混合 guest 及双 Gateway rolling upgrade 均已走通。
10+
11+
发布预览版前仍必须关闭以下 P0 门禁:
12+
13+
1. 完成 COMP-02 的 VMM 原地升级、COMP-08/09 的 guest image upgrade/rollback,以及 COMP-10 的物理 host reboot;
14+
2. 若发布门禁坚持要求 v0.5.11 KMS/Gateway/VMM,需先提供 release 未包含的可追溯 service artifacts;当前已完成的是确切 v0.5.11 guest 与 0.5.8→current service rolling upgrade;
15+
3. 对真实 NVIDIA、GCP TDX、AWS NitroTPM、AMD SEV-SNP 环境完成硬件证明负向测试;
16+
4. 处理或接受构建与依赖风险清单中的发布风险。
17+
18+
## 已执行套件
19+
20+
| 范围 | 结果 | 关键数字/说明 |
21+
|---|---|---|
22+
| Release Rust binaries | PASS | 11 个目标成功构建 |
23+
| `make core-test` | PASS | workspace tests 与 doc tests 全部通过 |
24+
| `make sdk-test` | PASS | Rust/Go/Python/JS;Python 119、JS 99 个测试通过 |
25+
| Attestation Docker E2E | PASS (SIMULATED) | 6/6 平台,四个 verifier 判据均为 true |
26+
| Gateway 三节点 E2E | PASS (SIMULATED) | 27 PASS / 0 FAIL;debug attestation |
27+
| KMS JS auth | PASS | 12 + 16 + 14 + 4 个测试通过 |
28+
| Foundry | PASS | 3 suites,54 PASS / 0 FAIL |
29+
| VMM UI build | PASS | 构建成功,但有依赖与 CDN fallback 风险 |
30+
| `prek run --all-files` | PASS | 所有 hook 通过 |
31+
| REUSE | TEST-HARNESS ISSUE | 仅本地生成的 9 个短期证书缺少 SPDX 信息 |
32+
| Yocto production image | FAIL / patched artifact built | 原样因 kernel-module-fuse packaging 失败;最小测试补丁后产物校验通过 |
33+
| TDX mixed guest / rolling upgrade | PASS(限定范围) | production SGX Local-Key-Provider;v0.5.11/current guest;0.5.8→current KMS/Gateway;key/SPKI/state/HA 连续性通过;完整 COMP-01..10 尚未全覆盖 |
34+
| no-TEE + swtpm | FAIL (SIMULATED) | TPM/swtpm host 装配成功;dev guest 在进入 `/init` 前停止推进 |
35+
36+
## 结果解释
37+
38+
- **PASS**:执行步骤和断言完整满足用例。
39+
- **PASS (SIMULATED)**:模拟证据通过,不代表真实平台通过。
40+
- **PARTIAL**:只覆盖了用例的一部分断言。
41+
- **FAIL**:已执行且产品断言失败。
42+
- **BLOCKED**:当前本机缺少对应外部平台、硬件或确切旧版资料。
43+
- **NOT RUN**:尚未执行,不能由相邻套件结果推断。
44+
45+
逐用例状态见 `07-test-case-matrix.md`;问题与发布建议见 `08-findings-and-risks.md`;模拟替代的完整边界见 `09-no-tee-swtpm-simulation-report.md`
Lines changed: 60 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,60 @@
1+
# 环境与测试资料
2+
3+
## 版本冻结
4+
5+
| 项目 ||
6+
|---|---|
7+
| 测试提交 | `dc3b95117f518a752c0726ecd44ba7888a25cc49` |
8+
| 版本 | `0.6.0` |
9+
| 基线 release | `https://github.com/Dstack-TEE/meta-dstack/releases/tag/v0.5.11` |
10+
| 隔离 worktree | `/home/kvin/src/dstack-v060-test` |
11+
| 外部原始日志 | `/home/kvin/src/dstack-v060-artifacts/logs/` |
12+
13+
测试在 detached worktree 中执行,避免覆盖原分支的 `docs/security/advisories/``docs/test-plans/`。Gateway 的本地证书、端口和 debug-attestation 修改仅为 test-harness 适配,未作为产品修改提交。
14+
15+
## 主机能力
16+
17+
- 64 logical CPU、约 125 GiB RAM;
18+
- Docker 29.5.3、Docker Compose 5.1.4;
19+
- `/dev/kvm``/dev/vhost-vsock` 可用;
20+
- CPU/内核报告 TDX host 与 SGX 可用,`kvm_intel.tdx=Y`
21+
- `/dev/sgx_enclave``/dev/sgx_provision` 可用;
22+
- 宿主机 PCCS 运行于 `https://localhost:8081/sgx/certification/v4/`
23+
`/etc/sgx_default_qcnl.conf` 指向该服务;测试通过
24+
`DSTACK_E2E_QCNL_CONF=/etc/sgx_default_qcnl.conf` 只读挂载给 AESMD;
25+
- 模拟所需 `tpm_vtpm_proxy``cuse``wireguard``kvm_intel` 可用。
26+
27+
这只能证明主机具备运行条件;只有 CVM 实际启动、quote 验证和升级断言通过后,才记为真实 TDX PASS。
28+
29+
## 已构建二进制
30+
31+
release 构建成功的目标:
32+
33+
`dstack-cli``dstack-auth``dstack-vmm``supervisor``dstack-kms``dstack-gateway``dstack-verifier``local-key-provider``dstack-guest-agent``dstack-guest-agent-simulator``dstack-tee-simulator`
34+
35+
## 证据位置
36+
37+
原始日志保存在 worktree 外,避免清理测试状态时丢失。报告中的统计均应能追溯到:
38+
39+
```text
40+
/home/kvin/src/dstack-v060-artifacts/logs/
41+
```
42+
43+
日志清单包括 `release-materials-build.log``core-test.log``sdk-test.log``attestation-e2e.log``gateway-e2e-simulated-fixed-harness.log``kms-auth-js-tests.log``foundry-tests.log``vmm-ui-build.log``prek-all-files.log``reuse-lint.log``yocto-os-image-build.log`
44+
45+
## 真实硬件兼容测试资料
46+
47+
| 资料 | 标识 |
48+
|---|---|
49+
| meta-dstack v0.5.11 archive | `dstack-0.5.11.tar.gz`; SHA-256 `6f95a2a0b59975780e6f5d8bfbf016d50148092889554e4f8272c401ee549e42` |
50+
| v0.5.11 guest image | `dstack-0.5.11`; measurement/digest `c2aa0186182fe8a404f16d5f3facb334d89be32703b3571c401b114a8b6e700d` |
51+
| v0.5.11 source revision | `ce04e924e17e3cb9d38d258338cbe71e8c08d575` |
52+
| current guest image | `dstack-0.6.0`; measurement/digest `91bc72e3ca6f283cc0549d761ee436d381d1e8c4ddc4c23354e05c9bbccfdec1` |
53+
| old KMS container | `dstacktee/dstack-kms:0.5.8@sha256:9650dcb47dad0065470f432f00e78e012912214ef1a5b1d7272918817e61a26d` |
54+
| old Gateway container | `dstacktee/dstack-gateway:0.5.8@sha256:6eb1dc1a5000f37cc5b0322d3fdb71e7f2e31859b5e3a611634919278cee2411` |
55+
| harness fixes | PR #819(PCCS mount,已合并)与 PR #820(混合镜像/升级审计) |
56+
57+
公共 `pccs.phala.network` 未缓存本物理平台的 PCK certificate,AESMD 因而返回
58+
`AESM_NO_PLATFORM_CERT_DATA`(error 44)。改用已为本机完成 provisioning 的本地
59+
PCCS 后,同一 production SGX enclave 稳定健康。该变化是测试基础设施修复,不是
60+
关闭证明校验或使用 mock Local-Key-Provider。
Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
# 构建与镜像产物报告
2+
3+
## Release 资料
4+
5+
11 个 Rust release 目标、VMM UI、KMS auth 依赖和合约测试资料均已构建。`prek run --all-files` 通过。
6+
7+
## Yocto production image
8+
9+
冻结点原样 clean build 的最终结果:**FAIL(发布阻断)**
10+
11+
Rootfs 组装时 DNF 无法找到 `kernel-module-fuse`
12+
13+
```text
14+
No match for argument: kernel-module-fuse
15+
kernel-module-fuse is neither a recipe nor a generated package.
16+
```
17+
18+
最终 kernel `.config``CONFIG_FUSE_FS=y`,即 FUSE 编入内核而不是 module,因此不会生成 `kernel-module-fuse` RPM;但 `dstack-rootfs-base.inc` 仍强制安装该包。这是冻结提交可重复触发的产品 packaging 错误,不是网络问题。
19+
20+
为继续后续测试,仅在隔离 worktree 删除这一个不可能存在的 package dependency。使用该**测试补丁**后 production image 构建成功。它不能作为“冻结提交原样构建 PASS”。
21+
22+
构建过程中还发生一次 `proxy.golang.org` wget exit 4;保留下载缓存重试后成功,判定为暂态网络故障。首次使用默认 64×64 并发造成主机 swap thrash;中止后清理全部 active recipes,并以 `BB_NUMBER_THREADS=12``PARALLEL_MAKE=-j12` 恢复。强制中止遗留的 partial outputs 已显式 `do_clean` 后重建。
23+
24+
## 测试补丁产物
25+
26+
| 产物 | SHA-256 | 大小 |
27+
|---|---|---:|
28+
| `dstack-0.6.0.tar.gz` | `f1582390165f5057fe87a7ce43145acc678d5aab76d9cad1eaf6c96da9fb5ec9` | 582 MiB |
29+
| `dstack-0.6.0-uki.tar.gz` | `10eb3591cf70800a79fccbc3cded24abc0c78654891270caf7ff5631f8155395` | 581 MiB |
30+
31+
Bare tar 解包后,`sha256sum -c sha256sum.txt` 对 OVMF、kernel、initramfs、metadata 和四种 measurement CBOR 全部通过。Rootfs verity image、`ovmf-sev.fd``digest.txt` 均存在。Metadata 核对结果:
32+
33+
- version `0.6.0`
34+
- git revision `dc3b95117f518a752c0726ecd44ba7888a25cc49`
35+
- production (`is_dev=false`);
36+
- unified TDX/SEV firmware metadata;
37+
- OS digest `91bc72e3ca6f283cc0549d761ee436d381d1e8c4ddc4c23354e05c9bbccfdec1`
38+
39+
## Warnings
40+
41+
成功的测试补丁构建报告 59 个 warning。除 OVMF 三处 assignment whitespace 外,kernel configcheck 包含大量 requested/not-found symbol;详见 `08-findings-and-risks.md`。必须以最终 `.config`/运行态而不是 warning 文本本身判断安全影响。
Lines changed: 41 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,41 @@
1+
# Core、SDK 与合约测试报告
2+
3+
## Rust core
4+
5+
命令:`make core-test`
6+
结果:**PASS**(约 2m06s)
7+
8+
Workspace 与 doc tests 全部通过。与本版本高风险变化直接相关的覆盖包括 Event Log v1/v2、canonical JSON、混合格式 replay、API auth,以及 KMS/Gateway/VMM/attestation/key-provider 单元和集成测试。
9+
10+
## SDK
11+
12+
命令:`make sdk-test`
13+
结果:**PASS**
14+
15+
| SDK | 结果 |
16+
|---|---|
17+
| Rust | 13 + 1 + 9 tests 通过,并完成 `no_std` 检查 |
18+
| Go | `dstack``tappd` package 全部通过 |
19+
| Python | 119 passed;1 个 deprecation warning |
20+
| JavaScript | 99 passed |
21+
| Simulator API | Rust/JS/Python/Go 均成功交互 |
22+
23+
注意:这是 SDK 自身和 simulator API 覆盖,不等同于“旧 SDK × 新真实 guest/control plane”兼容性测试。JS 依赖审计报告 1 low、3 moderate。
24+
25+
## KMS auth JavaScript
26+
27+
| 项目 | 结果 |
28+
|---|---|
29+
| `auth-mock` | 12 PASS |
30+
| `auth-simple` | 16 PASS |
31+
| `auth-eth-bun` | 14 PASS |
32+
| `auth-eth` | 4 PASS |
33+
34+
三个 Bun 项目的 `bun install --frozen-lockfile` 在 Bun 1.2.18/1.3.14 下失败,改用非 frozen install 后测试通过。因此功能断言通过,但可重复安装门禁失败。`auth-eth` 的 npm audit 为 2 low、1 moderate、3 high。
35+
36+
## Solidity / Foundry
37+
38+
命令:`forge test --ffi`
39+
结果:**PASS**,3 suites、54 tests、0 failures。
40+
41+
覆盖 two-step ownership transfer、proxy upgrade、storage/initialization compatibility、TCB policy 与 owner authorization。该结果完整支持 GKW-06 的合约层 rehearsal,但不代表所有部署链已执行链上升级。
Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,30 @@
1+
# Attestation 模拟 E2E 报告
2+
3+
命令:
4+
5+
```bash
6+
cd dstack
7+
./tests/e2e/attestation/run.sh
8+
```
9+
10+
结果:**PASS (SIMULATED)**,6/6 平台通过:
11+
12+
- dstack TDX legacy;
13+
- dstack TDX lite;
14+
- GCP TDX;
15+
- AMD SEV-SNP;
16+
- AWS Nitro Enclave;
17+
- AWS NitroTPM。
18+
19+
每个平台均满足:
20+
21+
```text
22+
is_valid=true
23+
quote_verified=true
24+
event_log_verified=true
25+
os_image_hash_verified=true
26+
```
27+
28+
## 结论边界
29+
30+
该套件证明解析、证据分派、event-log replay 和 verifier 组合路径对六种格式有效。它没有连接云厂商或真实 GPU/TEE,因此 PLAT-01、PLAT-03、PLAT-05、PLAT-06 的真实性、freshness、证书链、KDS/OCSP 故障恢复等硬件断言仍为 BLOCKED/PARTIAL,不能标为真实平台 PASS。
Lines changed: 22 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,22 @@
1+
# Gateway 本地三节点集成报告
2+
3+
## 最终结果
4+
5+
结果:**PASS (SIMULATED)**,27 PASS / 0 FAIL。
6+
7+
覆盖:三节点 health、管理 token(missing 401、wrong 401、correct 200)、DNS credential、ZT domains、Pebble ACME 签发、WaveKV 证书同步、节点间证书一致性、SNI 证书选择和 TLS proxy health。
8+
9+
## 测试环境适配
10+
11+
仓库原始入口直接执行时暴露四个 harness 问题:
12+
13+
1. 固定默认端口已被占用;
14+
2. 配置依赖不可达的远程 TDX guest-agent;
15+
3. `kvin/mock-cf-dns-api:latest` 不支持代码所需 `/client/v4/zones` API;
16+
4. `test_admin_auth()``log_info` stdout 混入 command substitution,导致真实 HTTP 状态为 401/401/200 时仍误判。
17+
18+
在隔离 worktree 中采用高位端口、本地短期 CA/RPC 证书、仓库内 `test-suites/full-stack-compose/mock-cf-dns`,并设置 `rpc_domain=""``insecure_skip_attestation=true`;同时仅将 auth 测试诊断输出重定向至 stderr。修正后的最终日志为 `gateway-e2e-simulated-fixed-harness.log`
19+
20+
## 结论边界
21+
22+
最终 PASS 证明 Gateway 数据面、证书与集群同步逻辑在本地 debug attestation 下可工作。它不证明生产 TDX quote、真实 guest-agent 或 O/N 滚动升级兼容性。原始失败日志均保留,以便修复正式测试入口。
Lines changed: 86 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,86 @@
1+
# TDX rolling-upgrade 与旧版兼容性报告
2+
3+
## 执行入口与环境
4+
5+
```bash
6+
DSTACK_E2E_QCNL_CONF=/etc/sgx_default_qcnl.conf \
7+
DSTACK_E2E_SKIP_CURRENT_BUILD=true \
8+
./test-suites/full-stack-compose/run-upgrade-e2e.sh
9+
```
10+
11+
测试运行在具备真实 SGX 与 TDX 的主机上。AESMD 使用已为本机完成
12+
provisioning 的本地 PCCS;Local-Key-Provider 运行 production SGX enclave,未使用
13+
mock、debug enclave 或 `insecure_skip_attestation`。公共 PCCS 未包含本机 PCK
14+
certificate,原 error 44 是 PCCS provisioning 问题,修复见 PR #819
15+
16+
## 参与版本
17+
18+
- VMM、第二阶段 KMS/Gateway:冻结提交
19+
`dc3b95117f518a752c0726ecd44ba7888a25cc49`
20+
- 初始 KMS:digest-pinned `dstack-kms 0.5.8`
21+
- 初始 Gateway:digest-pinned `dstack-gateway 0.5.8`
22+
- 旧 guest:meta-dstack v0.5.11 release artifact,image digest
23+
`c2aa0186182fe8a404f16d5f3facb334d89be32703b3571c401b114a8b6e700d`
24+
- 新 guest:本次 v0.6.0 candidate,image digest
25+
`91bc72e3ca6f283cc0549d761ee436d381d1e8c4ddc4c23354e05c9bbccfdec1`
26+
27+
meta-dstack v0.5.11 release 只提供 guest artifact,并不提供标记为 v0.5.11 的
28+
KMS/Gateway release containers。因此本报告把 **guest image compatibility**
29+
**0.5.8→current service rolling upgrade** 分开表述,不将后者伪称为 v0.5.11
30+
KMS/Gateway 兼容测试。
31+
32+
## 已验证的真实硬件路径
33+
34+
第一次完整执行已到达最终 audit,并证明全部 runtime 阶段成功;其唯一失败是 harness
35+
错误地假设 onboarding 后的两个 KMS 必须各自产生一次 archive HTTP GET。保存状态的
36+
复核结果为 current GET=1、v0.5.11 GET=2;onboarding 会复制 durable state/cache,
37+
所以“每 KMS 一次 GET”不是产品不变量。PR #820 修正该审计;随后从 clean state
38+
完整复跑并明确输出 `production-compatible ... success``upgrade E2E success`
39+
40+
已取得的运行态证据如下:
41+
42+
1. production SGX Local-Key-Provider enclave healthy;真实 TDX KMS CVM 报告
43+
`KeyProviderInfo { name: "local-sgx", id: "<SGX MRENCLAVE>" }`
44+
2. old KMS quote-enabled bootstrap,按真实 quote 的 `mrAggregated` 与物理 TDX
45+
device ID 精确授权;latest KMS 以 mutual RA-TLS onboarding;
46+
3. onboarding 前后 KMS CA SPKI、root k256 public key、per-app environment public
47+
key逐字节一致;
48+
4. v0.5.11 guest 使用 legacy manifest 启动、取得 key,并在切换 latest KMS 后重启;
49+
加密数据盘重新挂载;
50+
5. current guest 以 TDX lite policy 启动并取得 key;allowlist 精确包含 old/current
51+
两个 OS hash,不存在关闭 image verification/self-authorization 的日志;
52+
6. old/current guest 同时通过两个 Gateway 可达;两个 Gateway 逐节点从 0.5.8
53+
升到 current;
54+
7. Gateway certificate、DNS credential 与 durable state 保持;升级后的两个节点均
55+
能用原 credential 强制重新签发证书;
56+
8. clean rerun 的 rolling upgrade HA probe:4350 次请求、0 failures、1921 次成功
57+
failover,持续 253195 ms。
58+
59+
原始日志:
60+
61+
```text
62+
/home/kvin/src/dstack-v060-artifacts/logs/full-stack-tdx-upgrade-e2e-v0511-mixed-final.log
63+
/home/kvin/src/dstack-v060-artifacts/logs/full-stack-tdx-upgrade-e2e-v0511-mixed-exit0.log
64+
```
65+
66+
## COMP 用例审计
67+
68+
| 用例 | 结论 | 本次覆盖与缺口 |
69+
|---|---|---|
70+
| COMP-01 | PARTIAL | 建立了 old service + v0.5.11 guest 的真实 key/TLS/storage 基线,但 VMM 不是 old,且 KMS/Gateway 基线是 0.5.8 |
71+
| COMP-02 | NOT RUN | 未执行 old→new VMM 原地升级 |
72+
| COMP-03 | PASS | v0.5.11 guest 切换 latest KMS 后重新启动、取 key;KMS identity 与 app key 保持 |
73+
| COMP-04 | PASS | v0.5.11 guest 在两个 Gateway 完成 rolling upgrade 后仍可达,DNS/TLS/WireGuard 路径恢复 |
74+
| COMP-05 | PASS | latest VMM 创建全新 v0.5.11 image CVM,legacy numeric manifest 被接受,之后可由 latest service 继续服务 |
75+
| COMP-06 | PASS | latest VMM 创建 current image,TDX lite policy、exact image allowlist、key 与 Gateway 路径通过 |
76+
| COMP-07 | PARTIAL | old/current guest 并行可达且使用独立 app ID;未执行计划要求的同 app image 双版本 identity crossover 专项断言 |
77+
| COMP-08 | NOT RUN | 未执行同一 canary 的 O→N image 原地升级及身份/存储策略检查 |
78+
| COMP-09 | NOT RUN | 未执行 N→O rollback 与 policy-deny 对照 |
79+
| COMP-10 | PARTIAL | guest/KMS/Gateway 级 stop/start 与服务恢复有覆盖;未重启物理 host |
80+
81+
## 结论与边界
82+
83+
Local-Key-Provider 阻塞已经解除;真实 TDX 证据支持 v0.5.11/current 混合 guest、
84+
Local-Key-Provider KMS onboarding、Gateway rolling upgrade 及密钥/状态连续性。它不支持
85+
把 COMP-01..10 全部写成 PASS:VMM 原地升级、app image upgrade/rollback、同 app
86+
交叉身份和物理 host reboot 仍缺专项执行。模拟报告不能替代这些项目。

0 commit comments

Comments
 (0)