confidential-containers / guest-components

Confidential Containers Guest Tools and Components
Apache License 2.0
81 stars 89 forks source link

attester: tdx: strip CCEL #575

Open mythi opened 3 months ago

mythi commented 3 months ago

Fixes: #569

The CCEL log is made available through an ACPI sysfs entry and is of size "log_area_minimum_length". OVMF sets it to 64k.

The current tdx-attester code reads the whole blob and it's used as is in encoding and when sent over the wire.

Test runs suggests that it could be beneficial to strip the log before processing it further:

Squeezed from 65536 to 5064 bytes

The stripping follows the same pattern as what eventlog-rs does on the receiving end (we keep the same "stop flag" in the blob to keep things compatible).