cmcp v0.4.0
Upgrade from 0.3.0
0.3.0 reports a forged TPM quote as hardware-attested. The tpm2 branch of verify_trace_claim called only verify_tpm_measurement, which takes no signature parameter, so a TPMS_ATTEST blob with the correct magic and matching qualifying_data was accepted with no signature and no certificate chain. Everything in that blob is attacker-writable; the TPMT_SIGNATURE and the AK certificate chain are what bind a quote to a key inside a TPM, and neither was checked on the production path. The authenticated path existed in the package and had been validated against real hardware. Nothing in production called it.
Fixed here: the quote signature and the AK certificate chain now gate hardware_attestation. Material that is supplied and does not verify is fatal; material that is absent degrades the field to unverified rather than passing.
Not affected: SEV-SNP and TDX, which verify report signatures to their respective roots, and software-only deployments, which claim no hardware attestation.
Tracked as GHSA-q5qc-j6fh-5wxp (#370, fixed in #469).
Breaking for verifiers
Signed evidence now travels with the claim as gateway.attestation_evidence. It could not stay where it was: the claim model rejected it before the platform branch ran, which is precisely what kept the chain verifiers unreachable.
| result | |
|---|---|
| 0.4.0 verifier reading an older claim | fine, the fields are optional and the old location is still read as a fallback |
| a verifier older than 0.4.0 reading a 0.4.0 claim | CLAIM_MALFORMED on gateway.attestation_evidence |
Upgrade gateways and verifiers together. Claims carrying no evidence serialize byte-identically to 0.3.0, so software-only deployments are unaffected.
Five more places assurance was over-reported
Collected in the changelog's Security section rather than left scattered, because they are one story:
- Tokenless dev mode could bind every interface.
CMCP_DEV_MODE=1skips the bearer-token requirement and the default bind is0.0.0.0:8443, so the documented quickstart stood up an unauthenticated gateway on the host's every interface. The combination is now refused. - A claim was issued when the per-session TEE attestation call failed (#426).
close_sessionfell back to the startup report, which carries no chain-root commitment, and signed anyway. - Unsigned PCR reads were reported as
provider=tpm(#441). A read carries no signature; only a quote binds those values to a TPM. - SNP
report_datamismatch was not fatal (#371, #390), and a claim could reachVERIFIEDwith an unverified VCEK chain. - TCG event logs were never replayed against the quoted PCR values (#443).
Known limitation
On some Azure Trusted Launch hosts the AK certificate at NV index 0x01C101D0 carries no AIA extension, so there is no chain to walk to a pinnable root. On those hosts the claim reports unverified rather than verified, which is the correct answer. This is a property of the host rather than of the verifier (#453).
Full detail in CHANGELOG.md and current status in STATUS.md.
What's Changed
- fix(audit): bind audit-chain root into the attested report_data by @imran-siddique in #368
- fix(ci): resolve agt CLI in release governance job by @imran-siddique in #369
- feat(docs): SEO and AEO optimization by @imran-siddique in #373
- docs(readme): lead with 'the secure, confidential way to run MCP' by @imran-siddique in #374
- docs(site): 'secure version of MCP' in description + llms.txt (AEO) by @imran-siddique in #375
- docs: reconcile documentation with the implementation by @imran-siddique in #383
- feat(tee): raise explicit not-implemented error for the opaque provider by @imran-siddique in #385
- test(agt): fix datetime.UTC AttributeError blocking unit CI by @imran-siddique in #388
- fix(verify): verify SNP report signature + VCEK chain (cmcp#370) by @imran-siddique in #386
- fix(verify): offline DCAP TDX quote verification (cmcp#370) by @imran-siddique in #387
- fix(verify): make SNP report_data binding fatal and never report VERIFIED without a verified VCEK chain (#371) by @imran-siddique in #390
- fix(docs): make MkDocs strict build use docs dir by @carloshvp in #376
- docs: propose embodied action evidence profile by @carloshvp in #339
- ci: sign published images (cosign) + attest SLSA build provenance by @imran-siddique in #391
- docs: persist custom domain via docs/CNAME (fix cmcp.agentrust-io.com 404) by @imran-siddique in #394
- docs: add cross-project top navigation (supernav) by @imran-siddique in #395
- chore(deps): bump actions/attest-build-provenance from 2 to 4 by @dependabot[bot] in #393
- feat(verify): add embodied action evidence fixtures by @carloshvp in #392
- fix(cli): force UTF-8 CLI output so status glyphs do not crash on Windows (#396) by @imran-siddique in #397
- docs(tee): clarify in-tree appraisal is aTLS fallback, not primary gate by @imran-siddique in #398
- docs(quickstart): fix TRACE Claim retrieval, verify, and startup log by @katy-gordon in #399
- chore(deps): update mkdocstrings requirement from >=1.0.4 to >=1.0.6 by @dependabot[bot] in #400
- docs: add PRIVACY.md by @imran-siddique in #401
- docs: disallow /cdn-cgi/ in robots.txt by @imran-siddique in #405
- feat(tee): hardware-validated Azure CVM (vTPM-rooted SEV-SNP) attestation by @imran-siddique in #407
- feat(tee): land Azure CVM distinct runtime.platform value (agentrust-trace 0.4) by @imran-siddique in #411
- docs(spec): house-style cleanup (de-bold, remove dashes; no normative changes) by @imran-siddique in #410
- fix(tee): bare-metal SEV-SNP via configfs-TSM; accept report version >=2 by @imran-siddique in #412
- refactor(verify): delegate shared attestation crypto to agent-manifest 0.5 by @imran-siddique in #413
- chore(deps): bump actions/setup-python from 6 to 7 by @dependabot[bot] in #402
- chore(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 by @dependabot[bot] in #403
- chore(deps): update mkdocs-material requirement from >=9.7.6 to >=9.7.7 by @dependabot[bot] in #404
- fix(policy): resource-scoped Cedar policies never enforced + release-prep runtime fixes by @imran-siddique in #414
- docs: cmcp verify in CLI table, correct autodetect order, policies/ naming by @imran-siddique in #416
- docs+examples: working block-first quickstart, mock upstream, enforcing example policies by @imran-siddique in #417
- fix(security): restrict tokenless dev mode to loopback (#408) by @imran-siddique in #418
- fix(doc): remove duplicate content by @Qiang-Xu in #419
- fix(deps): require agent-manifest>=0.6.1 and report unappraisable manifests clearly by @imran-siddique in #422
- chore(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 by @dependabot[bot] in #421
- fix(tdx): parse the nested QE certification data; validate on real hardware by @imran-siddique in #420
- docs: stop claiming hardware attestation unconditionally; move identifiers off agentrust.io by @imran-siddique in #423
- feat(trace): emit the TRACE v0.2 profile URI by @imran-siddique in #424
- docs: strip em dashes from the README by @imran-siddique in #428
- fix(ci): repoint CODEOWNERS at the directories that exist by @imran-siddique in #438
- docs(spec): TPM security model for non-confidential-compute devices by @imran-siddique in #439
- fix(tee): correct PCR hex parsing that corrupted the measurement by @imran-siddique in #437
- docs(spec): make the TPM security model vendor-neutral by @imran-siddique in #440
- fix(tee): stop labelling unsigned PCR reads as hardware-attested by @imran-siddique in #441
- feat(verify): replay TCG event logs against reported PCR values by @imran-siddique in #443
- feat(aarm): record the five AARM R4 decisions and export telemetry (R8) by @imran-siddique in #442
- feat(verify): verify the TPM quote signature, validated on real vTPM hardware by @imran-siddique in #444
- fix(tee): quote with a real attestation key and keep the signature by @imran-siddique in #445
- docs(testing): record the Azure vTPM certificate chain and event log findings by @imran-siddique in #446
- feat(verify): delegate TPM signature and chain verification to agent-manifest by @imran-siddique in #448
- feat(tee): quote with the platform attestation key and ship its certificate chain by @imran-siddique in #449
- fix(tee): guard the empty-chain case and add the platform AK unit tests by @imran-siddique in #450
- feat(tee): measure the gateway into a TPM NV extend index (#432) by @imran-siddique in #451
- docs(tee): record the NV extend hardware run, and correct the Azure PKI claim by @imran-siddique in #452
- docs(status): make the TPM row agree with the hardware-validation record by @imran-siddique in #455
- docs(spec): record the TPM decisions, refresh the tier table, seal before event log by @imran-siddique in #458
- feat(tee): certify the gateway measurement so it is signed evidence (#432) by @imran-siddique in #459
- fix(tee): make TPM2_NV_Certify actually work, found on hardware (#460) by @imran-siddique in #461
- chore(ci): pin agentrust-io/.github checkout to an immutable SHA by @imran-siddique in #463
- refactor(tee): consume the shared TPM parsers from agent-manifest 0.8 by @imran-siddique in #464
- refactor(tee): consume the shared SNP report layout from agent-manifest 0.10 by @imran-siddique in #466
- fix: refuse to issue trace claim when hardware TEE session report is missing by @qubeena07 in #426
- fix(otel): wire R8 telemetry export into the running gateway by @zohebk8s in #465
- chore(deps): bump github/codeql-action from 4 to 4.37.4 by @dependabot[bot] in #467
- chore(deps): bump pypa/gh-action-pypi-publish from 1.14.1 to 1.14.2 by @dependabot[bot] in #468
- fix(verify): authenticate TPM quotes and let evidence reach the verifier (#370) by @zohebk8s in #469
- chore: bump to 0.4.0 and make the CI security audit actually run by @imran-siddique in #470
- chore(deps): ceiling agt-core below 5.0 so pip cannot break Cedar by @imran-siddique in #473
- docs: pin loopback in the README config and scope the tpm row to 0.3.0 by @imran-siddique in #475
- test(catalog): pin the sensitivity vocabulary against a fail-open regression by @imran-siddique in #478
- fix(inspection): stage 3 content classification was dead when AGT is installed by @imran-siddique in #477
- Repair the broken social card image, give the homepage a real title by @imran-siddique in #480
- docs(adopters): drop the placeholder row by @imran-siddique in #481
- chore(release): prepare 0.4.0 by @imran-siddique in #482
New Contributors
- @carloshvp made their first contribution in #376
- @katy-gordon made their first contribution in #399
- @Qiang-Xu made their first contribution in #419
- @qubeena07 made their first contribution in #426
- @zohebk8s made their first contribution in #465
Full Changelog: v0.3.0...v0.4.0