sigil-tee-material · crate
Source declarations, signatures and documentation for crate.
Source: sigil/node/sigil-tee-material/src/lib.rs. SHA-256: 879b99876baa7a9015ee8c4db1cda1660a1752fd0f43f120748b5b7fcb0fa32c.
This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.
bundle
Operator tooling for fetching, validating, and emitting genesis trust-anchor bundles for Sigil's per-vendor TEE verifier.
See sigil/docs/operator/tee-verifier-readiness.md for the broader
context and the per-vendor checklist.
Output bundle schema
Every emit-genesis subcommand produces the same outer envelope:
{
"vendor": "amd-sev-snp" | "intel-sgx-dcap" | "intel-tdx" | "arm-cca",
"generatedAt": "<RFC 3339>",
"expiresAt": "<RFC 3339 | null>",
"materials": { ... vendor-specific raw artefacts as base64/hex ... },
"measurements": [ "<hex>", ... ],
"policyPatch": {
"compute_params": {
"<vendor>_trust_anchors": { ... drop-in shape for genesis ... }
}
}
}Operators concatenate policyPatch into their genesis JSON. The
materials block is preserved so the bundle is self-describing
(auditable: who ran the fetch, when, what the source bytes were).
All cryptography is pure Rust:
p256/p384for ECDSA (Intel / AMD-Arm respectively)sha2for SHA-256/384x509-parserfor X.509 DER parsingcoset+ciboriumfor COSE_Sign1 + CBOR (Arm CCA)- (optional)
ureq+ rustls for HTTPS fetch
No C/FFI. No vendor SDK. No proprietary blobs.
pub mod bundle;Source line: 39.
error
pub mod error;Source line: 40.
fetch
#[cfg(feature = "network")]
pub mod fetch;Source line: 42.
hex_io
pub mod hex_io;Source line: 43.
arm_cca
pub mod arm_cca;Source line: 45.
sev_snp
pub mod sev_snp;Source line: 46.
sgx_dcap
pub mod sgx_dcap;Source line: 47.
tdx
pub mod tdx;Source line: 48.
pub use bundle::{GenesisBundle, PolicyPatch};
pub use bundle::{GenesisBundle, PolicyPatch};Source line: 50.
pub use error::ToolError;
pub use error::ToolError;Source line: 51.