Skip to content

Launch digest of igvm is different than the measurement in the attestation report #4

@dimstav23

Description

@dimstav23

Issue description

  • The Launch digest of SVSM is different than the measurement in the attestation report obtained by the monitor.
  • Potentially this is caused by the init-flags value that is used to launch the VM (related issue)
  • Currently the value they set in the official repo of svsm is 5 and enables restricted injection which stops the VM from booting our case.

Version:

  • Branch dev
  • Commit 3e1ee874649db7fc4662274a6b8af2cd7ad14eff

How to reproduce:

  1. Build svsm and preserve the dumped Launch digest
  2. Request an attestation report from the monitor and dump its 48 bytes starting from offset 90h

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions