Skip to content

fix(wcm-nvidia-nras): report confidential-compute mode as unknown - #224

Merged
imran-siddique merged 1 commit into
mainfrom
fix/wcm-nvidia-cc-mode-unknown
Sep 25, 2026
Merged

imran-siddique merged 1 commit into
mainfrom
fix/wcm-nvidia-cc-mode-unknown

Conversation

@imran-siddique

Copy link
Copy Markdown
Member

Follows agentrust-io/weight-custody-manifest#161, which made WCM's own NVAT adapter stop asserting confidential-compute mode. This adapter had the same line: cc_mode=True, unconditionally.

adapt() now returns cc_mode=None. Nothing it receives states the mode. No NRAS v4 appraisal claim names it, and on two H100s no field of the signed report moved when the mode changed (WCM python/tests/fixtures/nvidia/cc-mode, WCM #159).

Behaviour change. WCM 0.28.4 denies an unstated mode (WCM-L2-0018), so a release through this adapter now fails closed. The existing waiver is required_gpu_measurement.require_cc_mode: false in the signed manifest. The adapter never sets it.

Floor moves to 0.28.4. Before that, GpuReport.cc_mode is a required bool and rejects None. Checked: on 0.27.0 the suite fails with a pydantic ValidationError. So requirements.txt, tested_against and the CI pin in wcm-integrations-tests.yml move to 0.28.4. compatibility.yaml keeps 0.27.0 as the repo minimum, since the other WCM integrations still work there.

Tests. Two new ones carry the adapter's report through the published SDK's KeyBrokerService: refused as unstated, released only under the waiver. The manifest pins the adapter's own measurement, so the refusal is about the mode and not an earlier mismatch. With cc_mode=True restored, the gate releases the key and the test fails.

Run locally on 0.28.4:

  • nvidia-nras: 62 passed
  • all wcm-*: 373 passed. The 6 failures are cbor2 DLL loads blocked by Windows Application Control on this machine, and they fail the same way on main.
  • the real H100 report and chain from WCM's gpu_h100_attestation.json, passed through the fixed adapter: wcm verify-quote --kind gpu gives verified: True, and False with a wrong nonce
  • validate_integrations, validate_compatibility, index and catalog --check, ruff: clean

Not in this PR: dropping cc_mode and letting a release policy require cryptographic GPU verification. That stays with WCM #159.

Generated with Claude Code

The adapter set cc_mode=True unconditionally, so WCM's gate read a
constant rather than evidence and could not deny on this path. Nothing
the adapter receives states the mode (WCM #159), so it now returns None,
which WCM 0.28.4 denies unless the signed manifest waives it.

Raises the floor, tested_against and the CI pin to 0.28.4: earlier
releases type cc_mode as a required bool and reject None.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@imran-siddique
imran-siddique requested review from a team and carloshvp as code owners September 25, 2026 20:20
@imran-siddique
imran-siddique merged commit 310b5d5 into main Sep 25, 2026
16 checks passed
@imran-siddique
imran-siddique deleted the fix/wcm-nvidia-cc-mode-unknown branch September 25, 2026 20:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant