fix(wcm-nvidia-nras): report confidential-compute mode as unknown - #224
Merged
Merged
Conversation
The adapter set cc_mode=True unconditionally, so WCM's gate read a constant rather than evidence and could not deny on this path. Nothing the adapter receives states the mode (WCM #159), so it now returns None, which WCM 0.28.4 denies unless the signed manifest waives it. Raises the floor, tested_against and the CI pin to 0.28.4: earlier releases type cc_mode as a required bool and reject None. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Follows agentrust-io/weight-custody-manifest#161, which made WCM's own NVAT adapter stop asserting confidential-compute mode. This adapter had the same line:
cc_mode=True, unconditionally.adapt()now returnscc_mode=None. Nothing it receives states the mode. No NRAS v4 appraisal claim names it, and on two H100s no field of the signed report moved when the mode changed (WCMpython/tests/fixtures/nvidia/cc-mode, WCM #159).Behaviour change. WCM 0.28.4 denies an unstated mode (
WCM-L2-0018), so a release through this adapter now fails closed. The existing waiver isrequired_gpu_measurement.require_cc_mode: falsein the signed manifest. The adapter never sets it.Floor moves to 0.28.4. Before that,
GpuReport.cc_modeis a requiredbooland rejectsNone. Checked: on 0.27.0 the suite fails with a pydanticValidationError. Sorequirements.txt,tested_againstand the CI pin inwcm-integrations-tests.ymlmove to 0.28.4.compatibility.yamlkeeps 0.27.0 as the repo minimum, since the other WCM integrations still work there.Tests. Two new ones carry the adapter's report through the published SDK's
KeyBrokerService: refused as unstated, released only under the waiver. The manifest pins the adapter's own measurement, so the refusal is about the mode and not an earlier mismatch. Withcc_mode=Truerestored, the gate releases the key and the test fails.Run locally on 0.28.4:
wcm-*: 373 passed. The 6 failures arecbor2DLL loads blocked by Windows Application Control on this machine, and they fail the same way onmain.gpu_h100_attestation.json, passed through the fixed adapter:wcm verify-quote --kind gpugivesverified: True, andFalsewith a wrong noncevalidate_integrations,validate_compatibility, index and catalog--check, ruff: cleanNot in this PR: dropping
cc_modeand letting a release policy require cryptographic GPU verification. That stays with WCM #159.Generated with Claude Code