Commit e44681d
authored
feat(contracts): TEE-attested service approval commitments (#117)
Workstream C from the Tangle Cloud app-store program plan
(docs/blueprint-app-store-program-plan.md in dapp).
Operators may now commit to a specific TEE backend + measurement +
nonce-binding at approval time. Blueprints (or off-chain provisioning
oracles) cross-check the live attestation against the committed value
before accepting the provision result.
Types (`src/libraries/Types.sol`)
- `enum TeeBackend { Phala, AwsNitro, GcpConfidential, AzureSkr, DirectTdx }`
— append-only; `DirectTdx` recognised but rejected at approval (mirror
of ai-agent-sandbox-blueprint #50 policy).
- `struct TeeAttestationCommitment { backend, expectedMeasurement, nonceBinding, expiresAt }`.
Approval entrypoint (`src/core/ServicesApprovals.sol`)
- `approveServiceWithTeeCommitments(requestId, AssetSecurityCommitment[],
blsPubkey, popSignature, TeeAttestationCommitment[])` — validates each
TEE commitment (rejects DirectTdx, rejects past expiries), stores the
per-operator array in `_requestTeeCommitments`, and emits
`TeeCommitmentRecorded`.
Activation persistence (`src/facets/tangle/TangleServicesFacet.sol`)
- `_activateService` calls `_persistTeeCommitments`, copying every
approving operator's commitment list onto `_serviceTeeCommitments[serviceId]`.
- New view `getTeeCommitment(serviceId, operator)` exposes the array
for blueprint provisioning hooks. Selector list grows 7 → 9.
Storage (`src/TangleStorage.sol`)
- Two new mappings: `_requestTeeCommitments[requestId][operator]` and
`_serviceTeeCommitments[serviceId][operator]`. `__gap` reduced 44 → 42.
Errors (`src/libraries/Errors.sol`)
- `DirectTdxNotPermitted`, `TeeCommitmentExpired(uint64,uint64)`,
`MeasurementMismatch(bytes32,bytes32)`, `TeeCommitmentLengthMismatch(uint256,uint256)`.
Interface (`src/interfaces/ITangleServices.sol`)
- New entrypoint declaration.
Tests (`test/tangle/TeeCommitmentApprovalTest.t.sol`, 9 cases)
- Happy path: Nitro commitment recorded, fetched via view.
- DirectTdx rejected at first slot and at later slot.
- Past-expiry and at-current-timestamp expiry rejected.
- Future expiry persists through activation.
- Empty TEE array passes through with no persistence.
- Multiple operators with distinct backends persisted per-operator.
- Unknown-operator view returns empty array.
Why this surface and not the existing `OperatorSecurityCommitment`:
TEE commitments have a different shape (backend enum + 32-byte
measurement + 32-byte nonce + uint64 expiry) and a different lifecycle
(expiry checked at approval; cross-check against live attestation by
blueprint). Folding into the existing AssetSecurityCommitment array
would require a discriminant tag and would muddle the per-asset vs
per-attestation storage layouts. A parallel storage slot keeps both
clean.1 parent 2d0d606 commit e44681d
8 files changed
Lines changed: 1008 additions & 11 deletions
File tree
- src
- core
- facets/tangle
- interfaces
- libraries
- test/tangle
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
369 | 369 | | |
370 | 370 | | |
371 | 371 | | |
| 372 | + | |
| 373 | + | |
| 374 | + | |
| 375 | + | |
| 376 | + | |
| 377 | + | |
| 378 | + | |
| 379 | + | |
| 380 | + | |
| 381 | + | |
| 382 | + | |
| 383 | + | |
| 384 | + | |
372 | 385 | | |
373 | 386 | | |
374 | 387 | | |
375 | 388 | | |
376 | 389 | | |
377 | 390 | | |
378 | | - | |
| 391 | + | |
379 | 392 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
25 | 34 | | |
26 | 35 | | |
27 | 36 | | |
| |||
169 | 178 | | |
170 | 179 | | |
171 | 180 | | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| 192 | + | |
| 193 | + | |
| 194 | + | |
| 195 | + | |
| 196 | + | |
| 197 | + | |
| 198 | + | |
| 199 | + | |
| 200 | + | |
| 201 | + | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
| 226 | + | |
| 227 | + | |
| 228 | + | |
| 229 | + | |
| 230 | + | |
| 231 | + | |
| 232 | + | |
| 233 | + | |
| 234 | + | |
| 235 | + | |
| 236 | + | |
| 237 | + | |
| 238 | + | |
| 239 | + | |
| 240 | + | |
| 241 | + | |
| 242 | + | |
| 243 | + | |
| 244 | + | |
| 245 | + | |
| 246 | + | |
| 247 | + | |
| 248 | + | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
| 277 | + | |
| 278 | + | |
| 279 | + | |
| 280 | + | |
| 281 | + | |
| 282 | + | |
| 283 | + | |
| 284 | + | |
| 285 | + | |
| 286 | + | |
| 287 | + | |
| 288 | + | |
| 289 | + | |
| 290 | + | |
| 291 | + | |
| 292 | + | |
| 293 | + | |
| 294 | + | |
| 295 | + | |
| 296 | + | |
| 297 | + | |
| 298 | + | |
| 299 | + | |
| 300 | + | |
| 301 | + | |
| 302 | + | |
| 303 | + | |
| 304 | + | |
| 305 | + | |
| 306 | + | |
| 307 | + | |
| 308 | + | |
| 309 | + | |
| 310 | + | |
| 311 | + | |
| 312 | + | |
| 313 | + | |
| 314 | + | |
| 315 | + | |
| 316 | + | |
| 317 | + | |
| 318 | + | |
| 319 | + | |
| 320 | + | |
| 321 | + | |
| 322 | + | |
| 323 | + | |
| 324 | + | |
| 325 | + | |
| 326 | + | |
| 327 | + | |
| 328 | + | |
| 329 | + | |
| 330 | + | |
| 331 | + | |
| 332 | + | |
| 333 | + | |
172 | 334 | | |
173 | 335 | | |
174 | 336 | | |
| |||
242 | 404 | | |
243 | 405 | | |
244 | 406 | | |
245 | | - | |
246 | | - | |
247 | | - | |
248 | | - | |
249 | | - | |
250 | | - | |
251 | | - | |
| 407 | + | |
252 | 408 | | |
253 | 409 | | |
254 | 410 | | |
| |||
258 | 414 | | |
259 | 415 | | |
260 | 416 | | |
261 | | - | |
| 417 | + | |
| 418 | + | |
| 419 | + | |
| 420 | + | |
262 | 421 | | |
263 | 422 | | |
264 | 423 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
16 | 16 | | |
17 | 17 | | |
18 | 18 | | |
19 | | - | |
| 19 | + | |
20 | 20 | | |
21 | 21 | | |
22 | 22 | | |
| |||
26 | 26 | | |
27 | 27 | | |
28 | 28 | | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
29 | 56 | | |
30 | 57 | | |
31 | 58 | | |
| |||
66 | 93 | | |
67 | 94 | | |
68 | 95 | | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
69 | 99 | | |
70 | 100 | | |
71 | 101 | | |
| |||
301 | 331 | | |
302 | 332 | | |
303 | 333 | | |
| 334 | + | |
| 335 | + | |
| 336 | + | |
| 337 | + | |
| 338 | + | |
| 339 | + | |
| 340 | + | |
| 341 | + | |
| 342 | + | |
| 343 | + | |
| 344 | + | |
| 345 | + | |
| 346 | + | |
| 347 | + | |
| 348 | + | |
304 | 349 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
131 | 131 | | |
132 | 132 | | |
133 | 133 | | |
134 | | - | |
| 134 | + | |
| 135 | + | |
135 | 136 | | |
136 | 137 | | |
137 | 138 | | |
| |||
146 | 147 | | |
147 | 148 | | |
148 | 149 | | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
149 | 182 | | |
150 | 183 | | |
151 | 184 | | |
| |||
0 commit comments