sigil-node · tee_verify
Source declarations, signatures and documentation for tee_verify.
Source: sigil/node/sigil-node/src/tee_verify/mod.rs. SHA-256: e8aaa931f756a68434130a608ad88f92d26d2ec19ab323ab6c1f7bf616f224f4.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
Module condition:
#[cfg(feature = "tee-verify")]tee_verify::arm_cca
#[cfg(feature = "tee-verify")]
pub mod arm_cca;Source line: 35.
tee_verify::sev_snp
#[cfg(feature = "tee-verify")]
pub mod sev_snp;Source line: 36.
tee_verify::sgx_dcap
#[cfg(feature = "tee-verify")]
pub mod sgx_dcap;Source line: 37.
tee_verify::tdx
#[cfg(feature = "tee-verify")]
pub mod tdx;Source line: 38.
tee_verify::TeeVerifyOk
Outcome of a successful vendor verification. The executor uses this to anchor the verified measurement and (optionally) an expiry epoch onto the on-chain audit trail.
#[cfg(feature = "tee-verify")]
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct TeeVerifyOk {
pub vendor: &'static str,
/// Hex-decoded measurement bytes (e.g. MRENCLAVE for SGX, MRTD for
/// TDX, measurement digest for SEV-SNP, RIM/RPM for Arm CCA).
pub measurement: Vec<u8>,
/// Optional freshness deadline (chain epoch). When set, the
/// executor will reject the receipt if `current_epoch > expiry`.
pub expiry_epoch: Option<u64>
}Source line: 44.
tee_verify::TeeVerifyError
Per-vendor failure modes. Every variant carries the failing vendor so the executor's typed error / audit trail can attribute the rejection.
#[cfg(feature = "tee-verify")]
#[derive(Debug, Clone, PartialEq, Eq, thiserror::Error)]
pub enum TeeVerifyError {
#[error("tee-verify: vendor {vendor:?} not supported")]
UnsupportedVendor { vendor: String },
#[error("tee-verify: {vendor} report malformed: {detail}")]
MalformedReport {
vendor: &'static str,
detail: String,
},
#[error("tee-verify: {vendor} signature invalid: {detail}")]
InvalidSignature {
vendor: &'static str,
detail: String,
},
#[error("tee-verify: {vendor} certificate chain invalid: {detail}")]
InvalidCertChain {
vendor: &'static str,
detail: String,
},
#[error("tee-verify: {vendor} attestation expired/stale: {detail}")]
ExpiredOrStale {
vendor: &'static str,
detail: String,
},
#[error("tee-verify: {vendor} measurement does not match policy expectation: {detail}")]
WrongMeasurement {
vendor: &'static str,
detail: String,
},
/// Production verifier could not run because the vendor reference
/// material (root certs, reference measurements, vendor SDK) has
/// not been plugged in. Production builds MUST treat this as a
/// hard rejection — under no circumstances does the executor
/// silently fall back to "accept".
#[error(
"tee-verify: {vendor} verification blocked: real vendor fixture material not yet bundled — \
do not enable T3 settlement for this vendor on mainnet until reference signing keys, \
root certificates, and reference measurements are wired"
)]
FixtureMaterialRequired { vendor: &'static str },
#[error("tee-verify: {vendor} internal: {detail}")]
Internal {
vendor: &'static str,
detail: String,
},
}Source line: 57.
tee_verify::TeeVerifier
Vendor verifier contract. One instance per vendor.
#[cfg(feature = "tee-verify")]
pub trait TeeVerifier: Send + Sync {
/// Vendor identifier as it appears on `TeeAttestation::vendor`.
fn vendor(&self) -> &'static str;
/// Verify the attestation. `now_epoch` is the chain epoch the
/// executor is operating in (used for freshness checks).
fn verify(
&self,
attestation: &TeeAttestation,
now_epoch: u64,
) -> Result<TeeVerifyOk, TeeVerifyError>;
}Source line: 104.
tee_verify::TeeVerifierRegistry
Registry of vendor verifiers, keyed by vendor string.
#[cfg(feature = "tee-verify")]
#[derive(Clone)]
pub struct TeeVerifierRegistry {
}Source line: 119.
tee_verify::TeeVerifierRegistry::new
#[cfg(feature = "tee-verify")]
pub fn new() -> Self;Source line: 130.
tee_verify::TeeVerifierRegistry::production
Production registry: real verifier per vendor. Each fails closed
with FixtureMaterialRequired until reference material is wired.
SGX DCAP, TDX, Arm CCA remain Phase 13 stubs. SEV-SNP also stays
in stub mode here because no policy is being passed; callers
that have a ComputePolicy should use
[production_with_policy] to activate the real SEV-SNP
verifier.
#[cfg(feature = "tee-verify")]
pub fn production() -> Self;Source line: 143.
tee_verify::TeeVerifierRegistry::production_with_policy
Phase 14a / 14b — production registry that pulls per-vendor trust anchors from the chain config. Each vendor's real verifier is feature-gated; when its feature is off, the vendor falls back to the Phase 13 fail-closed stub.
SGX DCAP: real when tee-verify-sgx-dcap is on **and
policy.sgx_dcap_trust_anchors is Some.
SEV-SNP: real when tee-verify-sev-snp is on **and
policy.sev_snp_trust_anchors is Some.
TDX / Arm CCA: Phase 13 stubs.
#[cfg(feature = "tee-verify")]
#[cfg(any(
feature = "tee-verify-sev-snp",
feature = "tee-verify-sgx-dcap",
feature = "tee-verify-tdx",
feature = "tee-verify-arm-cca"
))]
pub fn production_with_policy(policy: &crate::compute_state::ComputePolicy) -> Self;Source line: 168.
tee_verify::TeeVerifierRegistry::register
#[cfg(feature = "tee-verify")]
pub fn register(&mut self, verifier: Arc<dyn TeeVerifier>);Source line: 229.
tee_verify::TeeVerifierRegistry::verify
#[cfg(feature = "tee-verify")]
pub fn verify(
&self,
attestation: &TeeAttestation,
now_epoch: u64,
) -> Result<TeeVerifyOk, TeeVerifyError>;Source line: 233.
tee_verify::TeeVerifierRegistry::supports_vendor
Returns true when the vendor has a registered verifier.
#[cfg(feature = "tee-verify")]
pub fn supports_vendor(&self, vendor: &str) -> bool;Source line: 249.