feat(ipe): add signed policy loading and Azure mode selection - #52
Draft
aadhar-agarwal wants to merge 12 commits into
Draft
feat(ipe): add signed policy loading and Azure mode selection#52aadhar-agarwal wants to merge 12 commits into
aadhar-agarwal wants to merge 12 commits into
Conversation
aadhar-agarwal
force-pushed
the
aadagarwal/acl-ipe-mode-toggle
branch
2 times, most recently
from
August 14, 2026 18:32
fe37a53 to
a449cd2
Compare
14 tasks
aadhar-agarwal
force-pushed
the
aadagarwal/acl-ipe-mode-toggle
branch
4 times, most recently
from
August 19, 2026 18:19
269560d to
6cbfb5e
Compare
Build signed IPE policy and /usr dm-verity assets for Secure Boot UKIs, load the policy before switch_root, and select disabled or permissive mode from Azure IMDS. Add the build, loader, Azure, CI, and documentation contracts, including custom Secure Boot trust for VHD validation and reliable external policy handoff to the SDK container. Signed-off-by: Aadhar Agarwal <aadagarwal@microsoft.com>
aadhar-agarwal
force-pushed
the
aadagarwal/acl-ipe-mode-toggle
branch
from
August 19, 2026 22:00
6cbfb5e to
0db5ca5
Compare
Expose opt-in controls so a PR run can build Mantle from aclmain and execute targeted Azure Kola validation without changing normal defaults. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d2c3f02c-40e7-4079-9a25-e82509b05333
Add SSH keepalives and force-kill reboot sessions that ignore TERM so Azure smoke validation can continue polling for the reboot. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d2c3f02c-40e7-4079-9a25-e82509b05333
Request the canonical libgomp RPM explicitly and expand catalog lists into distinct DNF arguments so bundled cloud-native libraries cannot hijack gettext dependency resolution. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d2c3f02c-40e7-4079-9a25-e82509b05333
Keep the catalog and sourced RPM helper non-executable while leaving the provider contract executable. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d2c3f02c-40e7-4079-9a25-e82509b05333
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 266c8380-b4b0-48c4-8e5b-41af575fc9d0
There was a problem hiding this comment.
Pull request overview
Adds opt-in IPE support to Azure Secure Boot UKI images, including signed policies, dm-verity signatures, and IMDS-based permissive mode.
Changes:
- Builds and loads signed IPE policies with signed
/usrroot hashes. - Adds Azure Trusted Launch certificate forwarding and runtime validation.
- Adds supporting tests, CI parameters, documentation, and package fixes.
Reviewed changes
Copilot reviewed 35 out of 35 changed files in this pull request and generated 2 comments.
Show a summary per file
| File | Description |
|---|---|
sdk_lib/sdk_entry.sh |
Forwards validated IPE settings. |
sdk_lib/sdk_container_common.sh |
Adds version-file fallback. |
run_sdk_container |
Streams external policies into containers. |
run_azure_tests.sh |
Forwards Trusted Launch settings. |
image_to_vm.sh |
Reuses IPE signing certificates. |
ci-automation/vendor-testing/azure.sh |
Configures Trusted Launch and certificates. |
build_library/rpm/uki_install.sh |
Signs and installs verity companions. |
build_library/rpm/sign_uki_ephemeral.sh |
Supports shared signing certificates. |
build_library/rpm/rpm_install.sh |
Installs signed policies and multi-RPM mappings. |
build_library/rpm/package_catalog.yaml |
Adds explicit libgomp dependencies. |
build_library/rpm/ipe_verity.sh |
Serializes validated root hashes. |
build_library/rpm/ensure_ephemeral_cert.sh |
Generates shared ephemeral certificates. |
build_library/rpm/dracut_install.sh |
Installs the IPE loader module. |
build_library/rpm/additional_files/ipe/acl-ipe-boot-policy.pol |
Defines the IPE execution policy. |
build_library/rpm/additional_files/dracut-acl-selinux-toggle/module-setup.sh |
Installs the shared profile helper. |
build_library/rpm/additional_files/dracut-acl-selinux-toggle/acl-selinux-toggle.sh |
Uses shared IMDS parsing. |
build_library/rpm/additional_files/dracut-acl-ipe-load/module-setup.sh |
Defines the IPE dracut module. |
build_library/rpm/additional_files/dracut-acl-ipe-load/acl-ipe-load.sh |
Selects and activates IPE mode. |
build_library/rpm/additional_files/dracut-acl-ipe-load/acl-ipe-load.service |
Orders early policy loading. |
build_library/rpm/additional_files/acl-node-security-profile.sh |
Fetches and caches IMDS profiles. |
build_library/build_image_util.sh |
Integrates policy installation. |
acl/validate/validate_common.sh |
Forwards host-test timeouts. |
acl/tests/test-run-sdk-container-ipe-policy.sh |
Tests policy streaming and reuse. |
acl/tests/test-rpm-provider-selection.sh |
Tests multi-package mappings. |
acl/tests/test-ipe-policy-input.sh |
Tests policy preparation and validation. |
acl/tests/test-ipe-loader-runtime.sh |
Tests runtime mode selection. |
acl/tests/test-azure-security-profile-test-common.sh |
Tests timeout contracts. |
acl/tests/run-selinux-toggle-test.sh |
Reuses shared Azure helpers. |
acl/tests/run-ipe-permissive-test.sh |
Validates permissive IPE behavior. |
acl/tests/run-ipe-mode-toggle-test.sh |
Tests reboot-based IPE selection. |
acl/tests/azure-security-profile-test-common.sh |
Shares Azure tag/reboot logic. |
acl/docs/BUILD_RPM_IMAGE_README.md |
Documents policy build inputs. |
acl/docs/architecture.md |
Documents IPE and verity architecture. |
acl/build_rpm_image.sh |
Adds IPE configuration and validation. |
.pipelines/github-pr-validation.yml |
Adds validation parameters. |
Suppressed comments (1)
acl/docs/BUILD_RPM_IMAGE_README.md:173
- The external-policy example also omits
ACL_IPE_CAPABLE=true, so the supplied artifact is validated but never installed becauserpm_install_ipe_policyreturns immediately for the default disabled capability. Update this command to opt into IPE explicitly.
./acl/build_rpm_image.sh --rebuild \
--ipe-policy-mode=external \
--ipe-policy-path=/secure/input/acl.pol.p7b
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
Comment on lines
+165
to
+168
| Production builds can consume an externally signed attached DER PKCS#7 | ||
| artifact. The artifact is mounted read-only into the SDK container, verified, | ||
| and accepted only when its extracted content exactly matches | ||
| `build_library/rpm/additional_files/ipe/acl-ipe-boot-policy.pol`: |
| default, which is intended for development and test builds: | ||
|
|
||
| ```bash | ||
| ./acl/build_rpm_image.sh --rebuild --ipe-policy-mode=ephemeral |
Replace the public capability/policy-mode split with ACL_IPE_ASSET_MODE. Record the completed producer mode in ipe-asset-mode and compare exact modes when reusing image artifacts. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 266c8380-b4b0-48c4-8e5b-41af575fc9d0
The IPE policy trusts signed dm-verity roots and never interpolates a per-image root hash, so retain only the policy rule validation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: 266c8380-b4b0-48c4-8e5b-41af575fc9d0
…-mode-toggle # Conflicts: # sdk_lib/sdk_container_common.sh
Stage a bootable policy candidate outside /usr, bind it to the signed UKI command line, and load it best-effort from systemd-stub credentials on Azure. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d2c3f02c-40e7-4079-9a25-e82509b05333
aadhar-agarwal
force-pushed
the
aadagarwal/acl-ipe-mode-toggle
branch
from
August 27, 2026 00:29
5f6bf68 to
27b83f3
Compare
The policy credential is exposed only in the initrd. Validate the loaded policy after switch-root instead of requiring the transient credential path. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d2c3f02c-40e7-4079-9a25-e82509b05333
Use one per-build ephemeral certificate for both test and production VHD conversions so the exported gallery certificate matches every signed image. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: d2c3f02c-40e7-4079-9a25-e82509b05333
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Delivers the signed IPE policy as a per-UKI credential companion while preserving a bootable build-time candidate and moving final signing to ACL Pipelines definition 5425.
The credential is stored at
EFI/Linux/<uki>.efi.extra.d/acl-ipe-policy.p7b.cred. systemd-stub exposes it in the initramfs at/.extra/credentials/acl-ipe-policy.p7b.cred, and the signed UKI command line binds it withacl.ipe.policy_sha256=<sha256-of-attached-CMS>.Change Log
ephemeralandexternalmodes.${BUILD_DIR}/acl-ipe-policy/.offorpermissivefrom Azure IMDS.Type of Change
Does this affect the image build?
Associated Issues
8c9d4f29.Mode behavior
disabled: no token, credential, or raw policy.ephemeral: the build-time candidate is final for development and tests.external: the build-time candidate keeps the VHD bootable; definition 5425 validates and replaces it.Normal production defaults remain disabled. Production activation is a follow-up.
Test Methodology
• prcheck 1193008
• acl-pipelines-prcheck 1193009
701fa3e63; PR 287548c9d4f29.• [ARM64-7-OneBranch]-Prod-BuildACL 1193017
ipeAssetMode: disabled. ARM64 QEMU Kola is a known failing baseline and is not an IPE gate.• Mantle PR 34
728686795/dc202453, including both architectures after the ARM64 retry.release/3.0• [ARM64]-Prod-BuildACL-Nightly 1193013
701fa3e63/8c9d4f29.Current-head IPE validation is in progress for PR 28754
8c9d4f29. ARM64 QEMU Kola remains a known failing baseline and is not an IPE gate.Landing Timeline
release/3.0.Merge Checklist