From 759d1ad5c0a9e450eda44f477623183b3e978d29 Mon Sep 17 00:00:00 2001 From: Philipp Winter Date: Sun, 31 May 2026 08:16:27 -0500 Subject: [PATCH] Return error if attestation fails. So far, we would log but not return an error if we failed to attest an enclave. That can be a problem if veil-verify is used inside a script: the exit code must be non-zero if attestation failed, which is what this PR does. --- cmd/veil-verify/attestation.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/cmd/veil-verify/attestation.go b/cmd/veil-verify/attestation.go index 06b619b..c2067c6 100644 --- a/cmd/veil-verify/attestation.go +++ b/cmd/veil-verify/attestation.go @@ -100,11 +100,11 @@ func attestEnclave( if !pcrs.Equal(doc.PCRs) { log.Printf("Expected PCRs:\n%sbut got PCRs:\n%s", pcrs, doc.PCRs) color.Red("Enclave's code DOES NOT match local code!") + return errors.New("enclave code does not match local code") } else { color.Green("Enclave's code matches local code!") + return nil } - - return nil } func buildReq(