Sigil documentation
ReferenceRust referencesigil-node

sigil-node · tee_verify

Source declarations, signatures and documentation for tee_verify.

Source: sigil/node/sigil-node/src/tee_verify/mod.rs. SHA-256: e8aaa931f756a68434130a608ad88f92d26d2ec19ab323ab6c1f7bf616f224f4.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

Module condition:

#[cfg(feature = "tee-verify")]

tee_verify::arm_cca

#[cfg(feature = "tee-verify")]
pub mod arm_cca;

Source line: 35.

tee_verify::sev_snp

#[cfg(feature = "tee-verify")]
pub mod sev_snp;

Source line: 36.

tee_verify::sgx_dcap

#[cfg(feature = "tee-verify")]
pub mod sgx_dcap;

Source line: 37.

tee_verify::tdx

#[cfg(feature = "tee-verify")]
pub mod tdx;

Source line: 38.

tee_verify::TeeVerifyOk

Outcome of a successful vendor verification. The executor uses this to anchor the verified measurement and (optionally) an expiry epoch onto the on-chain audit trail.

#[cfg(feature = "tee-verify")]
#[derive(Debug, Clone, PartialEq, Eq)]
pub struct TeeVerifyOk {
pub vendor: &'static str,
/// Hex-decoded measurement bytes (e.g. MRENCLAVE for SGX, MRTD for

/// TDX, measurement digest for SEV-SNP, RIM/RPM for Arm CCA).

pub measurement: Vec<u8>,
/// Optional freshness deadline (chain epoch). When set, the

/// executor will reject the receipt if `current_epoch > expiry`.

pub expiry_epoch: Option<u64>
}

Source line: 44.

tee_verify::TeeVerifyError

Per-vendor failure modes. Every variant carries the failing vendor so the executor's typed error / audit trail can attribute the rejection.

#[cfg(feature = "tee-verify")]
#[derive(Debug, Clone, PartialEq, Eq, thiserror::Error)]
pub enum TeeVerifyError {
    #[error("tee-verify: vendor {vendor:?} not supported")]
    UnsupportedVendor { vendor: String },
    #[error("tee-verify: {vendor} report malformed: {detail}")]
    MalformedReport {
        vendor: &'static str,
        detail: String,
    },
    #[error("tee-verify: {vendor} signature invalid: {detail}")]
    InvalidSignature {
        vendor: &'static str,
        detail: String,
    },
    #[error("tee-verify: {vendor} certificate chain invalid: {detail}")]
    InvalidCertChain {
        vendor: &'static str,
        detail: String,
    },
    #[error("tee-verify: {vendor} attestation expired/stale: {detail}")]
    ExpiredOrStale {
        vendor: &'static str,
        detail: String,
    },
    #[error("tee-verify: {vendor} measurement does not match policy expectation: {detail}")]
    WrongMeasurement {
        vendor: &'static str,
        detail: String,
    },
    /// Production verifier could not run because the vendor reference
    /// material (root certs, reference measurements, vendor SDK) has
    /// not been plugged in. Production builds MUST treat this as a
    /// hard rejection — under no circumstances does the executor
    /// silently fall back to "accept".
    #[error(
        "tee-verify: {vendor} verification blocked: real vendor fixture material not yet bundled — \
         do not enable T3 settlement for this vendor on mainnet until reference signing keys, \
         root certificates, and reference measurements are wired"
    )]
    FixtureMaterialRequired { vendor: &'static str },
    #[error("tee-verify: {vendor} internal: {detail}")]
    Internal {
        vendor: &'static str,
        detail: String,
    },
}

Source line: 57.

tee_verify::TeeVerifier

Vendor verifier contract. One instance per vendor.

#[cfg(feature = "tee-verify")]
pub trait TeeVerifier: Send + Sync {
    /// Vendor identifier as it appears on `TeeAttestation::vendor`.
    fn vendor(&self) -> &'static str;

    /// Verify the attestation. `now_epoch` is the chain epoch the
    /// executor is operating in (used for freshness checks).
    fn verify(
        &self,
        attestation: &TeeAttestation,
        now_epoch: u64,
    ) -> Result<TeeVerifyOk, TeeVerifyError>;
}

Source line: 104.

tee_verify::TeeVerifierRegistry

Registry of vendor verifiers, keyed by vendor string.

#[cfg(feature = "tee-verify")]
#[derive(Clone)]
pub struct TeeVerifierRegistry {

}

Source line: 119.

tee_verify::TeeVerifierRegistry::new

#[cfg(feature = "tee-verify")]
pub fn new() -> Self;

Source line: 130.

tee_verify::TeeVerifierRegistry::production

Production registry: real verifier per vendor. Each fails closed with FixtureMaterialRequired until reference material is wired. SGX DCAP, TDX, Arm CCA remain Phase 13 stubs. SEV-SNP also stays in stub mode here because no policy is being passed; callers that have a ComputePolicy should use [production_with_policy] to activate the real SEV-SNP verifier.

#[cfg(feature = "tee-verify")]
pub fn production() -> Self;

Source line: 143.

tee_verify::TeeVerifierRegistry::production_with_policy

Phase 14a / 14b — production registry that pulls per-vendor trust anchors from the chain config. Each vendor's real verifier is feature-gated; when its feature is off, the vendor falls back to the Phase 13 fail-closed stub.

SGX DCAP: real when tee-verify-sgx-dcap is on **and policy.sgx_dcap_trust_anchors is Some. SEV-SNP: real when tee-verify-sev-snp is on **and policy.sev_snp_trust_anchors is Some. TDX / Arm CCA: Phase 13 stubs.

#[cfg(feature = "tee-verify")]
#[cfg(any(
        feature = "tee-verify-sev-snp",
        feature = "tee-verify-sgx-dcap",
        feature = "tee-verify-tdx",
        feature = "tee-verify-arm-cca"
    ))]
pub fn production_with_policy(policy: &crate::compute_state::ComputePolicy) -> Self;

Source line: 168.

tee_verify::TeeVerifierRegistry::register

#[cfg(feature = "tee-verify")]
pub fn register(&mut self, verifier: Arc<dyn TeeVerifier>);

Source line: 229.

tee_verify::TeeVerifierRegistry::verify

#[cfg(feature = "tee-verify")]
pub fn verify(
        &self,
        attestation: &TeeAttestation,
        now_epoch: u64,
    ) -> Result<TeeVerifyOk, TeeVerifyError>;

Source line: 233.

tee_verify::TeeVerifierRegistry::supports_vendor

Returns true when the vendor has a registered verifier.

#[cfg(feature = "tee-verify")]
pub fn supports_vendor(&self, vendor: &str) -> bool;

Source line: 249.

On this page