GPU TEE attestation: verify GPU confidential mode and bind it to the CVM (currently unverified)
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Accessibilité débutants
- 25/100
- Type d'issue
- Fonctionnalité
- Clarté
- Plutôt claire
- Activité
- Calme
- Domaine
- infrastructure, security
Piste de recherche
Commencez par docs/gpu-attestation-design.md, puis examinez verifier/src/verification.rs, vmm/src/app/qemu.rs:840, dstack-attest/src/attestation.rs:176 et guest-agent/src/rpc_service.rs:327. Suivez la limite existante des événements mesurés et les services de démarrage du GPU avant de choisir un axe de travail. Pour considérer le travail comme terminé, il faut une vérification et une liaison du GPU en mode fail-closed, avec les changements concernant verifier, KMS, RPC, service-gating et la documentation couverts le cas échéant.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
Problem
dstack attaches NVIDIA GPUs to CVMs but never verifies them. The CPU-side stack has no GPU/NRAS logic, and the guest OS flips the GPU to "ready" unconditionally at boot, before the workload runs. Consequences:
- A non-confidential GPU (CC off in host BIOS, or a normal GPU) is exposed plaintext to the workload with no error that stops it — no attacker required.
- Even a genuine CC GPU is not bound to the CVM: nothing lets a relying party (or the KMS) trust that a specific attested CVM is backed by a genuine GPU in confidential mode.
"Dual attestation" in docs/security/security-model.md is a documented expectation, not something enforced anywhere.
Full design write-up: docs/gpu-attestation-design.md (branch gpu-tee-nras-verification).
Current gaps (evidence)
- No CPU-side GPU verification —
AttestationQuoteis CPU-TEE only;VerificationDetailshas no GPU fields (verifier/src/verification.rs). - GPU attached as plain
vfio-pci, no CC-mode/attestation (vmm/src/app/qemu.rs:840). nvidia-smi conf-compute -srs 1run unconditionally at boot, nocc_modecheck (meta-dstacknvidia-persistenced.service).app-compose.servicehas no dependency on GPU bring-up — the workload starts even if it fails.- No app-facing RPC to query/enable GPU confidentiality.
Threat model (what this closes / doesn't)
| Attack | Closed? |
|---|---|
| Forge GPU evidence (no NVIDIA key) | ✅ cert chain + RIM, verifier in measured guest |
| Non-CC / CC-off GPU silently used | ✅ fail-fast, cc_mode==ON |
| Copy attack — GPU-less instance B copies a GPU-attested value from A | ✅ only if verdict lives in append-only measured pre-app state; ❌ if in report_data (app-forgeable via guest-agent/src/rpc_service.rs:327) |
| Stale/replayed GPU evidence | ✅ fresh boot nonce |
| Live relay / cuckoo to a genuine remote CC GPU | ❌ residual — no shipping system defeats it; needs TEE-IO/TDISP hardware. Document, don't imply "GPU proven local." |
Workstreams
1. Offline local verifier (NVAT)
- Adopt NVIDIA C++ Attestation SDK (
libnvat, NVIDIA/attestation-sdk); Pythonnvtrustis EOL 2026-09-15. - Bake
libnvat+ pre-provisioned filesystem RIM store into the NVIDIA image (re-provision on driver/VBIOS upgrade). - Handle OCSP (the one online dep,
ocsp.ndis.nvidia.com): in-CVM caching/replay proxy at--ocsp-url, and/or a Rego policy toleratingx-nvidia-cert-ocsp-status.
2. Binding via measured append-only state (before the app boundary)
-
dstack-utilemits agpu-attestationevent committingH(nvat_eat‖cert_chain‖claims)beforesystem-ready. - Verifier trusts it via the existing
find_eventboundary (breaks atsystem-ready,dstack-attest/src/attestation.rs:176) → RTMR3-bound on TDX. -
report_datastays for freshness + RA-TLS key binding only — not the GPU verdict.
3. Fail-fast enforcement & app gate
-
dstack-gpu-attest.service: verify every configured GPU (num_gpus>0is measured), requirecc_mode==ON(rejectOFFandDEVTOOLS), set-srs 1only on pass. -
app-compose.serviceRequires=+After=dstack-gpu-attest.service; fail closed (nosystem-ready, no workload). - Guest-agent RPC
GetGpuAttestation()/EnsureGpuReady()so apps can confirm/enable before use.
4. KMS gating, verifier surfacing, docs
- KMS gates key release on the
gpu-attestationevent (likecompose-hash). - Verifier parses NVAT EAT/claims into
VerificationDetails. -
security-model.md: state the guarantee (measured-guest-vouches + channel-bound) and the co-location residual.
Caveats
- SEV-SNP is blocked: no runtime measurement register (
tpm_runtime_pcr()=None,has_tdx()=false);decode_app_info_sev_snpreads identity from launch-timeHOST_DATA/MrConfigV3and ignores the runtime log. SNP needs an SVSM/coconut-vTPM (PCR channel) before this works — until then SNP GPU attestation is strictly weaker than TDX. (See #713.) - DEVTOOLS CC mode enables CC APIs without memory encryption — must be rejected.
- Co-location residual stands until Blackwell TEE-IO/TDISP.
Hardware validation checklist (unconfirmed in docs)
- NVAT behavior on OCSP connection failure (fail-open vs closed); can Rego neutralize revocation?
- OCSP
nextUpdatewindow; warm-cache ride-through. - Exact
libnvatenv-var spellings; trust-root store overridability. - Does
-srs 1error or no-op on a CC-off GPU? - Does the driver expose SPDM
KEY_EXCHANGEkey (optional session-binding stretch)? - SNP SVSM vTPM feasibility in meta-dstack.
- Langage dominant
- Rust
- Étoiles
- 551
- Forks
- 97
- Merge moyen
- 19 h 22 min
- PR mergées (30 j)
- 109
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de Dstack-TEE/dstack
-
Difficulté 5/5 Plus d'une semaine Accessibilité débutants 30/100
Dstack-TEE/dstack#1301 ·
-
Difficulté 3/5 1-2 jours Accessibilité débutants 55/100
Dstack-TEE/dstack#1300 ·
-
Difficulté 4/5 3-5 jours Accessibilité débutants 48/100
Dstack-TEE/dstack#1299 ·
-
Difficulté 4/5 3-5 jours Accessibilité débutants 48/100
Dstack-TEE/dstack#1298 ·
-
P0
Difficulté 5/5 Plus d'une semaine Accessibilité débutants 25/100
Dstack-TEE/dstack#1297 ·
Toutes les issues de Dstack-TEE/dstack
Issues similaires
-
Replayed reasoning items send "content": null, which the Responses API schema does not permit Ouvertebug CLI custom-model
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
-
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
rust-bitcoin/rust-bitcoin#6930 · 1 commentaire ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
-
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100
fulcrumgenomics/ferro-hgvs#2251 ·
-
Missing examples for `Allocator` OuverteA-allocators A-docs C-enhancement T-libs
Difficulté 2/5 1-3 heures Accessibilité débutants 75/100