GPU TEE attestation: verify GPU confidential mode and bind it to the CVM (currently unverified)
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 5/5
- Tempo estimado
- Mais de uma semana
- Facilidade para iniciantes
- 25/100
- Tipo de issue
- Funcionalidade
- Clareza
- Razoavelmente clara
- Status de atividade
- Pouca atividade
- Domínio
- infrastructure, security
Direção de pesquisa
Comece por docs/gpu-attestation-design.md e, em seguida, inspecione verifier/src/verification.rs, vmm/src/app/qemu.rs:840, dstack-attest/src/attestation.rs:176 e guest-agent/src/rpc_service.rs:327. Rastreie o limite existente de eventos medidos e os serviços de inicialização da GPU antes de escolher uma linha de trabalho. Para considerar o trabalho concluído, é necessário haver verificação e vinculação da GPU em modo fail-closed, com as alterações em verifier, KMS, RPC, service-gating e na documentação cobertas conforme aplicável.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Problem
dstack attaches NVIDIA GPUs to CVMs but never verifies them. The CPU-side stack has no GPU/NRAS logic, and the guest OS flips the GPU to "ready" unconditionally at boot, before the workload runs. Consequences:
- A non-confidential GPU (CC off in host BIOS, or a normal GPU) is exposed plaintext to the workload with no error that stops it — no attacker required.
- Even a genuine CC GPU is not bound to the CVM: nothing lets a relying party (or the KMS) trust that a specific attested CVM is backed by a genuine GPU in confidential mode.
"Dual attestation" in docs/security/security-model.md is a documented expectation, not something enforced anywhere.
Full design write-up: docs/gpu-attestation-design.md (branch gpu-tee-nras-verification).
Current gaps (evidence)
- No CPU-side GPU verification —
AttestationQuoteis CPU-TEE only;VerificationDetailshas no GPU fields (verifier/src/verification.rs). - GPU attached as plain
vfio-pci, no CC-mode/attestation (vmm/src/app/qemu.rs:840). nvidia-smi conf-compute -srs 1run unconditionally at boot, nocc_modecheck (meta-dstacknvidia-persistenced.service).app-compose.servicehas no dependency on GPU bring-up — the workload starts even if it fails.- No app-facing RPC to query/enable GPU confidentiality.
Threat model (what this closes / doesn't)
| Attack | Closed? |
|---|---|
| Forge GPU evidence (no NVIDIA key) | ✅ cert chain + RIM, verifier in measured guest |
| Non-CC / CC-off GPU silently used | ✅ fail-fast, cc_mode==ON |
| Copy attack — GPU-less instance B copies a GPU-attested value from A | ✅ only if verdict lives in append-only measured pre-app state; ❌ if in report_data (app-forgeable via guest-agent/src/rpc_service.rs:327) |
| Stale/replayed GPU evidence | ✅ fresh boot nonce |
| Live relay / cuckoo to a genuine remote CC GPU | ❌ residual — no shipping system defeats it; needs TEE-IO/TDISP hardware. Document, don't imply "GPU proven local." |
Workstreams
1. Offline local verifier (NVAT)
- Adopt NVIDIA C++ Attestation SDK (
libnvat, NVIDIA/attestation-sdk); Pythonnvtrustis EOL 2026-09-15. - Bake
libnvat+ pre-provisioned filesystem RIM store into the NVIDIA image (re-provision on driver/VBIOS upgrade). - Handle OCSP (the one online dep,
ocsp.ndis.nvidia.com): in-CVM caching/replay proxy at--ocsp-url, and/or a Rego policy toleratingx-nvidia-cert-ocsp-status.
2. Binding via measured append-only state (before the app boundary)
-
dstack-utilemits agpu-attestationevent committingH(nvat_eat‖cert_chain‖claims)beforesystem-ready. - Verifier trusts it via the existing
find_eventboundary (breaks atsystem-ready,dstack-attest/src/attestation.rs:176) → RTMR3-bound on TDX. -
report_datastays for freshness + RA-TLS key binding only — not the GPU verdict.
3. Fail-fast enforcement & app gate
-
dstack-gpu-attest.service: verify every configured GPU (num_gpus>0is measured), requirecc_mode==ON(rejectOFFandDEVTOOLS), set-srs 1only on pass. -
app-compose.serviceRequires=+After=dstack-gpu-attest.service; fail closed (nosystem-ready, no workload). - Guest-agent RPC
GetGpuAttestation()/EnsureGpuReady()so apps can confirm/enable before use.
4. KMS gating, verifier surfacing, docs
- KMS gates key release on the
gpu-attestationevent (likecompose-hash). - Verifier parses NVAT EAT/claims into
VerificationDetails. -
security-model.md: state the guarantee (measured-guest-vouches + channel-bound) and the co-location residual.
Caveats
- SEV-SNP is blocked: no runtime measurement register (
tpm_runtime_pcr()=None,has_tdx()=false);decode_app_info_sev_snpreads identity from launch-timeHOST_DATA/MrConfigV3and ignores the runtime log. SNP needs an SVSM/coconut-vTPM (PCR channel) before this works — until then SNP GPU attestation is strictly weaker than TDX. (See #713.) - DEVTOOLS CC mode enables CC APIs without memory encryption — must be rejected.
- Co-location residual stands until Blackwell TEE-IO/TDISP.
Hardware validation checklist (unconfirmed in docs)
- NVAT behavior on OCSP connection failure (fail-open vs closed); can Rego neutralize revocation?
- OCSP
nextUpdatewindow; warm-cache ride-through. - Exact
libnvatenv-var spellings; trust-root store overridability. - Does
-srs 1error or no-op on a CC-off GPU? - Does the driver expose SPDM
KEY_EXCHANGEkey (optional session-binding stretch)? - SNP SVSM vTPM feasibility in meta-dstack.
- Linguagem predominante
- Rust
- Estrelas
- 551
- Forks
- 97
- Merge médio
- 1d 8h
- PRs com merge (30d)
- 182
Guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de Dstack-TEE/dstack
-
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 35/100
Dstack-TEE/dstack#1384 ·
-
Dificuldade 5/5 Mais de uma semana Facilidade para iniciantes 30/100
Dstack-TEE/dstack#1301 ·
-
Dificuldade 3/5 1-2 dias Facilidade para iniciantes 55/100
Dstack-TEE/dstack#1300 ·
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 48/100
Dstack-TEE/dstack#1299 ·
-
Dificuldade 4/5 3-5 dias Facilidade para iniciantes 48/100
Dstack-TEE/dstack#1298 ·
Todas as issues de Dstack-TEE/dstack
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
BurntSushi/jiff#653 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
ZcashFoundation/zeeder#106 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 76/100
oxidize-rb/rb-sys#807 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 88/100
-
todo:ticket
Dificuldade 2/5 1-2 dias Facilidade para iniciantes 74/100