Skip to content

Track confidentiality guarantees across model execution, tools and agent delegation #41

Description

@imran-siddique

Current execution (September 19): existing WCM PR #150 at f168aa8 now composes an adversarial confined agent with the software workflow. Hosted run 35469947313 passes 36 tests: 32 portable (16 named scenario mutations) and four native agent cases (positive plus network/filesystem/logging weakenings). No named portable scenario lacks a mutation target. Released-package packaging and controlled-host/independent-operator hardware milestones remain open. No merge performed.

Objective

Establish when a confidentiality policy survives model execution, tool use and agent delegation. Track reusable contracts, enforcement and evidence across repositories. Keep model-, vendor- and cloud-specific mechanisms in explicit adapters; unsupported properties must remain visible.

Work queue

Work one bounded slice at a time. Begin with response requirements, then implement and validate before advancing that issue's status. Hardware work has separate prerequisites and is not authorized merely by this tracker.

  • 1. Define and implement authenticated responses bound to an attested request: Define and implement authenticated responses bound to an attested request ca2a#188 — implementation merged in Authenticate live handoff responses and preserve timeout diagnostics ca2a#187 on September 18. 57 focused tests, 691 full-suite tests and hosted CI passed. The child issue remains open for acceptance-status reconciliation; output encryption and new hardware evidence are outside this response-authentication result.
  • 2. Validate configured agent release controls: Validate that agent egress cannot bypass configured release controls cmcp#659 — reference #662 merged; follow-up #663 at bad751becca0 requires bounded watchdog acknowledgments after review reproduced an unresponsive-watcher gap. Hosted native Linux run 35445862949 passed 61 tests, including paused-watcher and write-only mutation controls. Trusted host/daemon and tested sink limits remain; acceptance review is pending.
  • 3. Bind deployed broker code and effective configuration to appraised workload identity: Bind deployed broker code and effective configuration to appraised workload identity weight-custody-manifest#144 — #143 and #147 merged; active Validate SNP firmware, provisioning lifecycle and composed software handoffs weight-custody-manifest#148 adds restricted firmware and 11 complete-image TCG controls. Follow-up af5468e adds real Azure SNP/vTPM evidence: seven attestation controls verified on guest and owner, plus a reproduced stale caller-digest counterexample. GCP follow-up dc5dd52 verifies two fresh native reports and five rejection controls on the owner machine, plus the native collector binding. A changed probe file retains the launch measurement. Both clouds' test resources are deleted. Follow-up 0500021 adds actual built-artifact prediction and seven digest-sensitivity controls; 989 local tests pass. Matching controlled-host hardware remains unavailable. Exact production-image enforcement, matching native-SNP report and live lifecycle acceptance remain open.
  • 4. Validate provisioning lifecycle: Validate provisioning lifecycle under restart, rollback and interrupted outcomes weight-custody-manifest#145 — PR #150 at db8f10638bb9 adds the contract and 18 software controls. 136 focused / 995 full tests passed; four deliberate weakenings failed as intended; hosted checks passed. Unknown installation, storage rollback assumptions and fake-worker stop behavior are explicit. Hardware lifecycle, trusted time and erasure remain unestablished.
  • 5. Demonstrate protected provisioning/loading/execution: Demonstrate protected model provisioning, loading and execution weight-custody-manifest#146 — execution evidence contract and paired acceptance matrix drafted in the local September 19 paper. No protected model execution result. Requires #144, #145 and controlled-host #149; CPU-only acceptance must not imply GPU protection.
  • 6. Explicit disclosure authorization: Define explicit authorization for releasing confidential data and derived outputs cmcp#660 — PR #672 merged at 2cdb168ce520. Exact-output scoped owner approvals, durable pre-delivery consumption and unknown delivery semantics; 77 focused / 2046 full tests and six mutation controls passed. This is an opt-in library, not a gateway bypass or source classifier. Composition acceptance remains separate.
  • 7. Composed acceptance harness: Build a reproducible acceptance harness for confidential workflows across components integrations#199 — core development in existing WCM #150 at f168aa8 now joins provisioning/key opening, affine model computation, an adversarial Docker agent at the tool boundary, cMCP/Cedar subprocess, cA2A sealed HTTP delegation/response MAC and exact-output disclosure. Hosted run 35469947313 passes 36 tests. Sixteen portable mutations cover every named scenario; three native isolation mutations expose their expected leaks. Exact bytes match at tool, peer and recipient. Source/import/dependency/image/policy metadata and sanitized observations are retained. Host/operator remains trusted; no protected model or independent-operator/hardware claim. Published integration packaging still awaits cMCP/cA2A releases; altrudev proposal can build on this core reference.

Execution order follows dependencies: response binding and confinement can be developed in software; measured identity is required before hardware lifecycle and protected-execution claims; disclosure authorization composes with confinement. The shared harness can start synthetically, but its live milestone depends on the component gates.

Existing work to reuse

Delivered foundation and active PRs

Keep existing open PRs current. A merged PR is delivered history, not a branch to keep extending. Do not close a hardware or composition issue merely because a component PR merges.

Completion discipline

Every work item needs an explicit threat model and trusted base, bounded acceptance criteria, implementation/revision links, reproducible evidence, negative controls and remaining limitations. Report requirements drafted, implemented, locally tested, hosted-tested and hardware-validated as distinct states. Closing an issue requires its stated acceptance criteria, not a generic green CI result.

The parent closes only when a documented deployment satisfies the selected end-to-end claim and the independent acceptance run is reproducible. Model correctness, unrestricted side-channel resistance and retroactive revocation of disclosed plaintext are not implied.

This issue is the canonical cross-repository backlog. Child issues own their acceptance details; local notes retain execution evidence rather than a second competing task list.

Paper evidence state — September 19

Local technical discussion draft updated to ten pages with separate software, hosted Linux, synthetic/emulated firmware, historical live hardware and replayed evidence. It includes the quote/application-digest, watchdog-liveness and installation-acknowledgment counterexamples; an execution contract; paired composition matrix; and revision ledger. No public publication, protected model execution or end-to-end confidentiality claim. WCM source/private hardware evidence remains access-controlled, so this is not a fully public reproduction package.

Activity

  1. imran-siddique commented on Sep 24, 2026

    @imran-siddique
    MemberAuthor

    cMCP #663 merged September 21, and WCM #148 merged September 20. WCM #150 closed without merging; the lifecycle contract and software controls are present on current main, and packaging PR #151 merged September 22.

    The composed harness is now under review in integrations #214. cMCP #660 still needs the durable disclosure-attempt fix.

    These updates do not complete the hardware, protected-execution or independent end-to-end acceptance gates. The parent tracker remains open.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions