Skip to content

Bump dcap-qvl to 0.6.3 and common dependencies to match - #99

Open
ameba23 wants to merge 1 commit into
mainfrom
peg/bump-dcapqvl-6.3
Open

ameba23 wants to merge 1 commit into
mainfrom
peg/bump-dcapqvl-6.3

Conversation

@ameba23

@ameba23 ameba23 commented Oct 1, 2026 •

Copy link
Copy Markdown
Collaborator

This bumps to a newer version of dcap-qvl, and also bumps some common dependencies to match versions. dcap-qvl 0.6.3 does not have breaking changes which effect us, but it does have some new APIs we could benefit from in follow ups.

Benefits we get now from the update:

  • Correct TDX PERFMON parsing. Quotes with that flag are no longer incorrectly treated as having reserved bits set.
  • Corrected TDX module-status combination. Platform and module TCB statuses are combined according to Intel’s out-of-date/configuration rules.
  • Updated crypto and X.509 dependencies.

Things we could possibly do in follow-ups using the new goodies:

  • Expose detailed verified claims. We could return platform/QE statuses, advisories, evaluation-data numbers, platform flags, and collateral validity in attestation verifier.
  • We could add opt-in TCB policy controls. Let callers require acceptable statuses, reject specific advisories, or configure bounded TCB grace periods. Not sure if we want these now but worth considering.
  • Possibly add early-warning monitoring. Fetch Intel’s 'early' collateral separately, evaluate the same quote, and warn when its status worsens relative to standard collateral.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant