Sigil documentation
ReferenceRust referencesigil-tee-material

sigil-tee-material · sev_snp

Source declarations, signatures and documentation for sev_snp.

Source: sigil/node/sigil-tee-material/src/sev_snp.rs. SHA-256: d6114d510f4c779ad601653420b40d86a733c0f18405363a17213ea94419e892.

This reference follows declared source modules, retains conditional attributes, and includes public declarations and implementation methods. Private-module re-exports and trait resolution require the compiler; this is a source reference, not a claim that every listed item is a root import. Function bodies and constant values are omitted.

sev_snp::KDS_BASE

pub const KDS_BASE: &str;

Source line: 20.

sev_snp::ValidatedSevSnpChain

#[derive(Debug, Clone)]
pub struct ValidatedSevSnpChain {
pub ark_fingerprint_sha256: [u8; 32],
pub ask_fingerprint_sha256: [u8; 32],
pub ark_der: Vec<u8>,
pub ask_der: Vec<u8>,
pub expires_at: DateTime<Utc>
}

Source line: 23.

sev_snp::AmdProduct

#[derive(Clone, Copy, Debug)]
pub enum AmdProduct {
    Milan,
    Genoa,
}

Source line: 32.

sev_snp::AmdProduct::parse

pub fn parse(s: &str) -> Result<Self, ToolError>;

Source line: 38.

sev_snp::AmdProduct::as_str

pub fn as_str(&self) -> &'static str;

Source line: 47.

sev_snp::fetch_cert_chain_pem

#[cfg(feature = "network")]
pub fn fetch_cert_chain_pem(product: AmdProduct) -> Result<String, ToolError>;

Source line: 56.

sev_snp::fetch_vcek_der

#[cfg(feature = "network")]
pub fn fetch_vcek_der(
    product: AmdProduct,
    chip_id_hex: &str,
    bl_spl: u8,
    tee_spl: u8,
    snp_spl: u8,
    ucode_spl: u8,
) -> Result<Vec<u8>, ToolError>;

Source line: 62.

sev_snp::validate_cert_chain

Validate an AMD SEV-SNP cert chain. Accepts a KDS-style PEM chain containing the product ASK and self-signed ARK. Pins based on ARK alone are not enough for production; the tool returns both ARK and ASK fingerprints.

Compatibility wrapper for callers that only need the ARK pin. New production code should call validate_cert_chain_material and pin both ARK and ASK fingerprints.

pub fn validate_cert_chain(input: &[u8]) -> Result<([u8; 32], Vec<u8>), ToolError>;

Source line: 90.

sev_snp::validate_cert_chain_material

Validate AMD SEV-SNP ARK + ASK chain material and return both fingerprints. AMD KDS cert_chain responses carry the product ASK followed by the self-signed ARK; operators pin both in genesis.

pub fn validate_cert_chain_material(input: &[u8]) -> Result<ValidatedSevSnpChain, ToolError>;

Source line: 98.

sev_snp::base64_decode_pub

Minimal pure-Rust base64 decode (RFC 4648 standard alphabet).

pub fn base64_decode_pub(s: &str) -> Result<Vec<u8>, String>;

Source line: 264.

sev_snp::build_anchors

Build a sev_snp_trust_anchors policy-anchor JSON value from the validated ARK fingerprint + operator-supplied measurement allowlist.

pub fn build_anchors(
    ark_fpr: [u8; 32],
    ask_fpr: [u8; 32],
    _measurements: &[Vec<u8>],
    measurement_hex: &[String],
) -> serde_json::Value;

Source line: 302.

sev_snp::emit_genesis_from_files

One-shot emit-genesis from a validated ARK chain + measurement file.

pub fn emit_genesis_from_files(
    ark_chain_path: &Path,
    measurement_paths: &[&Path],
) -> Result<GenesisBundle, ToolError>;

Source line: 324.

On this page