Skip to content

cmcp v0.4.0

Choose a tag to compare

@github-actions github-actions released this 08 Aug 21:46
· 185 commits to main since this release
a2e9515

Upgrade from 0.3.0

0.3.0 reports a forged TPM quote as hardware-attested. The tpm2 branch of verify_trace_claim called only verify_tpm_measurement, which takes no signature parameter, so a TPMS_ATTEST blob with the correct magic and matching qualifying_data was accepted with no signature and no certificate chain. Everything in that blob is attacker-writable; the TPMT_SIGNATURE and the AK certificate chain are what bind a quote to a key inside a TPM, and neither was checked on the production path. The authenticated path existed in the package and had been validated against real hardware. Nothing in production called it.

Fixed here: the quote signature and the AK certificate chain now gate hardware_attestation. Material that is supplied and does not verify is fatal; material that is absent degrades the field to unverified rather than passing.

Not affected: SEV-SNP and TDX, which verify report signatures to their respective roots, and software-only deployments, which claim no hardware attestation.

Tracked as GHSA-q5qc-j6fh-5wxp (#370, fixed in #469).

Breaking for verifiers

Signed evidence now travels with the claim as gateway.attestation_evidence. It could not stay where it was: the claim model rejected it before the platform branch ran, which is precisely what kept the chain verifiers unreachable.

result
0.4.0 verifier reading an older claim fine, the fields are optional and the old location is still read as a fallback
a verifier older than 0.4.0 reading a 0.4.0 claim CLAIM_MALFORMED on gateway.attestation_evidence

Upgrade gateways and verifiers together. Claims carrying no evidence serialize byte-identically to 0.3.0, so software-only deployments are unaffected.

Five more places assurance was over-reported

Collected in the changelog's Security section rather than left scattered, because they are one story:

  • Tokenless dev mode could bind every interface. CMCP_DEV_MODE=1 skips the bearer-token requirement and the default bind is 0.0.0.0:8443, so the documented quickstart stood up an unauthenticated gateway on the host's every interface. The combination is now refused.
  • A claim was issued when the per-session TEE attestation call failed (#426). close_session fell back to the startup report, which carries no chain-root commitment, and signed anyway.
  • Unsigned PCR reads were reported as provider=tpm (#441). A read carries no signature; only a quote binds those values to a TPM.
  • SNP report_data mismatch was not fatal (#371, #390), and a claim could reach VERIFIED with an unverified VCEK chain.
  • TCG event logs were never replayed against the quoted PCR values (#443).

Known limitation

On some Azure Trusted Launch hosts the AK certificate at NV index 0x01C101D0 carries no AIA extension, so there is no chain to walk to a pinnable root. On those hosts the claim reports unverified rather than verified, which is the correct answer. This is a property of the host rather than of the verifier (#453).

Full detail in CHANGELOG.md and current status in STATUS.md.


What's Changed

  • fix(audit): bind audit-chain root into the attested report_data by @imran-siddique in #368
  • fix(ci): resolve agt CLI in release governance job by @imran-siddique in #369
  • feat(docs): SEO and AEO optimization by @imran-siddique in #373
  • docs(readme): lead with 'the secure, confidential way to run MCP' by @imran-siddique in #374
  • docs(site): 'secure version of MCP' in description + llms.txt (AEO) by @imran-siddique in #375
  • docs: reconcile documentation with the implementation by @imran-siddique in #383
  • feat(tee): raise explicit not-implemented error for the opaque provider by @imran-siddique in #385
  • test(agt): fix datetime.UTC AttributeError blocking unit CI by @imran-siddique in #388
  • fix(verify): verify SNP report signature + VCEK chain (cmcp#370) by @imran-siddique in #386
  • fix(verify): offline DCAP TDX quote verification (cmcp#370) by @imran-siddique in #387
  • fix(verify): make SNP report_data binding fatal and never report VERIFIED without a verified VCEK chain (#371) by @imran-siddique in #390
  • fix(docs): make MkDocs strict build use docs dir by @carloshvp in #376
  • docs: propose embodied action evidence profile by @carloshvp in #339
  • ci: sign published images (cosign) + attest SLSA build provenance by @imran-siddique in #391
  • docs: persist custom domain via docs/CNAME (fix cmcp.agentrust-io.com 404) by @imran-siddique in #394
  • docs: add cross-project top navigation (supernav) by @imran-siddique in #395
  • chore(deps): bump actions/attest-build-provenance from 2 to 4 by @dependabot[bot] in #393
  • feat(verify): add embodied action evidence fixtures by @carloshvp in #392
  • fix(cli): force UTF-8 CLI output so status glyphs do not crash on Windows (#396) by @imran-siddique in #397
  • docs(tee): clarify in-tree appraisal is aTLS fallback, not primary gate by @imran-siddique in #398
  • docs(quickstart): fix TRACE Claim retrieval, verify, and startup log by @katy-gordon in #399
  • chore(deps): update mkdocstrings requirement from >=1.0.4 to >=1.0.6 by @dependabot[bot] in #400
  • docs: add PRIVACY.md by @imran-siddique in #401
  • docs: disallow /cdn-cgi/ in robots.txt by @imran-siddique in #405
  • feat(tee): hardware-validated Azure CVM (vTPM-rooted SEV-SNP) attestation by @imran-siddique in #407
  • feat(tee): land Azure CVM distinct runtime.platform value (agentrust-trace 0.4) by @imran-siddique in #411
  • docs(spec): house-style cleanup (de-bold, remove dashes; no normative changes) by @imran-siddique in #410
  • fix(tee): bare-metal SEV-SNP via configfs-TSM; accept report version >=2 by @imran-siddique in #412
  • refactor(verify): delegate shared attestation crypto to agent-manifest 0.5 by @imran-siddique in #413
  • chore(deps): bump actions/setup-python from 6 to 7 by @dependabot[bot] in #402
  • chore(deps): bump pypa/gh-action-pypi-publish from 1.14.0 to 1.14.1 by @dependabot[bot] in #403
  • chore(deps): update mkdocs-material requirement from >=9.7.6 to >=9.7.7 by @dependabot[bot] in #404
  • fix(policy): resource-scoped Cedar policies never enforced + release-prep runtime fixes by @imran-siddique in #414
  • docs: cmcp verify in CLI table, correct autodetect order, policies/ naming by @imran-siddique in #416
  • docs+examples: working block-first quickstart, mock upstream, enforcing example policies by @imran-siddique in #417
  • fix(security): restrict tokenless dev mode to loopback (#408) by @imran-siddique in #418
  • fix(doc): remove duplicate content by @Qiang-Xu in #419
  • fix(deps): require agent-manifest>=0.6.1 and report unappraisable manifests clearly by @imran-siddique in #422
  • chore(deps): bump ossf/scorecard-action from 2.4.3 to 2.4.4 by @dependabot[bot] in #421
  • fix(tdx): parse the nested QE certification data; validate on real hardware by @imran-siddique in #420
  • docs: stop claiming hardware attestation unconditionally; move identifiers off agentrust.io by @imran-siddique in #423
  • feat(trace): emit the TRACE v0.2 profile URI by @imran-siddique in #424
  • docs: strip em dashes from the README by @imran-siddique in #428
  • fix(ci): repoint CODEOWNERS at the directories that exist by @imran-siddique in #438
  • docs(spec): TPM security model for non-confidential-compute devices by @imran-siddique in #439
  • fix(tee): correct PCR hex parsing that corrupted the measurement by @imran-siddique in #437
  • docs(spec): make the TPM security model vendor-neutral by @imran-siddique in #440
  • fix(tee): stop labelling unsigned PCR reads as hardware-attested by @imran-siddique in #441
  • feat(verify): replay TCG event logs against reported PCR values by @imran-siddique in #443
  • feat(aarm): record the five AARM R4 decisions and export telemetry (R8) by @imran-siddique in #442
  • feat(verify): verify the TPM quote signature, validated on real vTPM hardware by @imran-siddique in #444
  • fix(tee): quote with a real attestation key and keep the signature by @imran-siddique in #445
  • docs(testing): record the Azure vTPM certificate chain and event log findings by @imran-siddique in #446
  • feat(verify): delegate TPM signature and chain verification to agent-manifest by @imran-siddique in #448
  • feat(tee): quote with the platform attestation key and ship its certificate chain by @imran-siddique in #449
  • fix(tee): guard the empty-chain case and add the platform AK unit tests by @imran-siddique in #450
  • feat(tee): measure the gateway into a TPM NV extend index (#432) by @imran-siddique in #451
  • docs(tee): record the NV extend hardware run, and correct the Azure PKI claim by @imran-siddique in #452
  • docs(status): make the TPM row agree with the hardware-validation record by @imran-siddique in #455
  • docs(spec): record the TPM decisions, refresh the tier table, seal before event log by @imran-siddique in #458
  • feat(tee): certify the gateway measurement so it is signed evidence (#432) by @imran-siddique in #459
  • fix(tee): make TPM2_NV_Certify actually work, found on hardware (#460) by @imran-siddique in #461
  • chore(ci): pin agentrust-io/.github checkout to an immutable SHA by @imran-siddique in #463
  • refactor(tee): consume the shared TPM parsers from agent-manifest 0.8 by @imran-siddique in #464
  • refactor(tee): consume the shared SNP report layout from agent-manifest 0.10 by @imran-siddique in #466
  • fix: refuse to issue trace claim when hardware TEE session report is missing by @qubeena07 in #426
  • fix(otel): wire R8 telemetry export into the running gateway by @zohebk8s in #465
  • chore(deps): bump github/codeql-action from 4 to 4.37.4 by @dependabot[bot] in #467
  • chore(deps): bump pypa/gh-action-pypi-publish from 1.14.1 to 1.14.2 by @dependabot[bot] in #468
  • fix(verify): authenticate TPM quotes and let evidence reach the verifier (#370) by @zohebk8s in #469
  • chore: bump to 0.4.0 and make the CI security audit actually run by @imran-siddique in #470
  • chore(deps): ceiling agt-core below 5.0 so pip cannot break Cedar by @imran-siddique in #473
  • docs: pin loopback in the README config and scope the tpm row to 0.3.0 by @imran-siddique in #475
  • test(catalog): pin the sensitivity vocabulary against a fail-open regression by @imran-siddique in #478
  • fix(inspection): stage 3 content classification was dead when AGT is installed by @imran-siddique in #477
  • Repair the broken social card image, give the homepage a real title by @imran-siddique in #480
  • docs(adopters): drop the placeholder row by @imran-siddique in #481
  • chore(release): prepare 0.4.0 by @imran-siddique in #482

New Contributors

Full Changelog: v0.3.0...v0.4.0