Allow specifying accepted avisories for SWHardeningNeeded TCB status#733
Merged
Conversation
✅ Deploy Preview for marblerun-docs canceled.
|
01cca91 to
152c8b3
Compare
thomasten
requested changes
Sep 27, 2024
thomasten
approved these changes
Oct 1, 2024
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
77591d1 to
5035c93
Compare
Signed-off-by: Daniel Weiße <dw@edgeless.systems>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
#729 added support for reading the Security Advisories if attestation failed due to invalid TCB status.
This PR builds on that to allow users to specify just specific advisories when the reported TCB status is
SWHardeningNeededProposed changes
--accepted-advisorieswhich allows specifying a list of Intel Security Advisories to accept if the Coordinator's TCB status isSWHardeningNeeded. If not set, all advisories are acceptedPackages.AcceptedAdvisorieswhich allows specifying a list of Intel Security Advisories to accept if the package's TCB status isSWHardeningNeeded. If not set, all advisories are acceptednilerror if parsing the advisory list of a report failed