|
| 1 | +package multimeasurements |
| 2 | + |
| 3 | +import ( |
| 4 | + "encoding/hex" |
| 5 | + "os" |
| 6 | + "path/filepath" |
| 7 | + "testing" |
| 8 | + |
| 9 | + "github.com/stretchr/testify/require" |
| 10 | +) |
| 11 | + |
| 12 | +// TestMeasurements is kept simple: map[pcr]measurement |
| 13 | +type TestMeasurements map[uint32][]byte |
| 14 | + |
| 15 | +func mustBytesFromHex(hexValue string) []byte { |
| 16 | + bytes, err := hex.DecodeString(hexValue) |
| 17 | + if err != nil { |
| 18 | + panic(err) |
| 19 | + } |
| 20 | + return bytes |
| 21 | +} |
| 22 | + |
| 23 | +// Measurements V1 (legacy) JSON (from https://github.com/flashbots/cvm-reverse-proxy/blob/837588b9f87ee49d1bb6dca4712a1c2844eb1ecc/measurements.json) |
| 24 | +var measurementsV1JSON = []byte(`{"azure-tdx-example":{"11":{"expected":"efa43e0beff151b0f251c4abf48152382b1452b4414dbd737b4127de05ca31f7"},"12":{"expected":"0000000000000000000000000000000000000000000000000000000000000000"},"13":{"expected":"0000000000000000000000000000000000000000000000000000000000000000"},"15":{"expected":"0000000000000000000000000000000000000000000000000000000000000000"},"4":{"expected":"ea92ff762767eae6316794f1641c485d4846bc2b9df2eab6ba7f630ce6f4d66f"},"8":{"expected":"0000000000000000000000000000000000000000000000000000000000000000"},"9":{"expected":"c9f429296634072d1063a03fb287bed0b2d177b0a504755ad9194cffd90b2489"}},"dcap-tdx-example":{"0":{"expected":"5d56080eb9ef8ce0bbaf6bdcdadeeb06e7c5b0a4d1ec16be868a85a953babe0c5e54d01c8e050a54fe1ca078372530d2"},"1":{"expected":"4216e925f796f4e282cfa6e72d4c77a80560987afa29155a61fdc33adb80eab0d4112abd52387e5e25a60deefb8a5287"},"2":{"expected":"4274fefb79092c164000b571b64ecb432fa2357adb421fd1c77a867168d7d7f7fe82796d1eba092c7bab35cf43f5ec55"},"3":{"expected":"000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000"},"4":{"expected":"000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000"}}}`) |
| 25 | + |
| 26 | +// TestMultiMeasurementsV2 tests the v2 data schema |
| 27 | +func TestMultiMeasurementsV2(t *testing.T) { |
| 28 | + // Load expected measurements from JSON file (in V2 format) |
| 29 | + m, err := New("../measurements.json") |
| 30 | + require.NoError(t, err) |
| 31 | + require.Len(t, m.Measurements, 3) |
| 32 | + |
| 33 | + // Setup test measurements (matching cvm-image-azure-tdx.rootfs-20241107200854.wic.vhd) |
| 34 | + testMeasurements := TestMeasurements{ |
| 35 | + 4: mustBytesFromHex("1b8cd655f5ebdf50bedabfb5db6b896a0a7c56de54f318103a2de1e7cea57b6b"), |
| 36 | + 9: mustBytesFromHex("992465f922102234c196f596fdaba86ea16eaa4c264dc425ec26bc2d1c364472"), |
| 37 | + } |
| 38 | + |
| 39 | + // Ensure matching entries works, and that additional fields are ignored |
| 40 | + testMeasurements[11] = testMeasurements[4] |
| 41 | + exists, foundMeasurement := m.Contains(testMeasurements) |
| 42 | + require.True(t, exists) |
| 43 | + require.Equal(t, "cvm-image-azure-tdx.rootfs-20241107200854.wic.vhd", foundMeasurement.MeasurementID) |
| 44 | + require.Equal(t, "azure-tdx", foundMeasurement.AttestationType) |
| 45 | + |
| 46 | + // Ensure check fails with a missing required key |
| 47 | + delete(testMeasurements, 4) |
| 48 | + exists, _ = m.Contains(testMeasurements) |
| 49 | + require.False(t, exists) |
| 50 | + |
| 51 | + // Double-check it works again |
| 52 | + testMeasurements[4] = testMeasurements[11] |
| 53 | + exists, _ = m.Contains(testMeasurements) |
| 54 | + require.True(t, exists) |
| 55 | + |
| 56 | + // Any changed value should make it fail |
| 57 | + testMeasurements[4] = testMeasurements[9] |
| 58 | + exists, _ = m.Contains(testMeasurements) |
| 59 | + require.False(t, exists) |
| 60 | + |
| 61 | + // Check for another set of known measurements (dcap-tdx-example) |
| 62 | + testMeasurements = TestMeasurements{ |
| 63 | + 0: mustBytesFromHex("5d56080eb9ef8ce0bbaf6bdcdadeeb06e7c5b0a4d1ec16be868a85a953babe0c5e54d01c8e050a54fe1ca078372530d2"), |
| 64 | + 1: mustBytesFromHex("4216e925f796f4e282cfa6e72d4c77a80560987afa29155a61fdc33adb80eab0d4112abd52387e5e25a60deefb8a5287"), |
| 65 | + 2: mustBytesFromHex("4274fefb79092c164000b571b64ecb432fa2357adb421fd1c77a867168d7d7f7fe82796d1eba092c7bab35cf43f5ec55"), |
| 66 | + 3: mustBytesFromHex("000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000"), |
| 67 | + 4: mustBytesFromHex("000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000"), |
| 68 | + } |
| 69 | + exists, foundMeasurement = m.Contains(testMeasurements) |
| 70 | + require.True(t, exists) |
| 71 | + require.Equal(t, "dcap-tdx-example-02", foundMeasurement.MeasurementID) |
| 72 | +} |
| 73 | + |
| 74 | +func TestMultiMeasurementsV1(t *testing.T) { |
| 75 | + tempDir := t.TempDir() |
| 76 | + err := os.WriteFile(filepath.Join(tempDir, "measurements.json"), measurementsV1JSON, 0644) |
| 77 | + require.NoError(t, err) |
| 78 | + |
| 79 | + // Load expected measurements from JSON file |
| 80 | + m, err := New(filepath.Join(tempDir, "measurements.json")) |
| 81 | + require.NoError(t, err) |
| 82 | + require.Len(t, m.Measurements, 2) |
| 83 | + |
| 84 | + testMeasurements := TestMeasurements{ |
| 85 | + 0: mustBytesFromHex("5d56080eb9ef8ce0bbaf6bdcdadeeb06e7c5b0a4d1ec16be868a85a953babe0c5e54d01c8e050a54fe1ca078372530d2"), |
| 86 | + 1: mustBytesFromHex("4216e925f796f4e282cfa6e72d4c77a80560987afa29155a61fdc33adb80eab0d4112abd52387e5e25a60deefb8a5287"), |
| 87 | + 2: mustBytesFromHex("4274fefb79092c164000b571b64ecb432fa2357adb421fd1c77a867168d7d7f7fe82796d1eba092c7bab35cf43f5ec55"), |
| 88 | + 3: mustBytesFromHex("000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000"), |
| 89 | + 4: mustBytesFromHex("000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000"), |
| 90 | + } |
| 91 | + exists, foundMeasurement := m.Contains(testMeasurements) |
| 92 | + require.True(t, exists) |
| 93 | + require.Equal(t, "dcap-tdx-example", foundMeasurement.MeasurementID) |
| 94 | +} |
0 commit comments