Repository navigation
refactor(tee): remove the opaque attestation provider and verifier - #737
Merged
Merged
Conversation
imran-siddique
requested review from
a team,
carloshvp,
qubeena07,
rajnisht7 and
zohebk8s
as code owners
October 8, 2026 18:29
|
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
The runtime provider was a placeholder that only raised, and the verifier credited hardware_attestation on an unsigned verified:true returned by a remote endpoint. Drop both modules, TEEProvider.OPAQUE, the ATTESTATION_PROVIDER_NOT_IMPLEMENTED error, the opaque and opaque-managed branches in verify_trace_claim, and the tests that only exercised them. A config naming provider opaque now fails like any unknown provider. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
imran-siddique
force-pushed
the
chore/vendor-neutral
branch
from
October 8, 2026 21:09
ad2f6ce to
f365510
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Removes the
opaqueattestation path. The runtime provider only raised, andcmcp_verify.opaquecreditedhardware_attestationon an unsignedverified: truefrom a remote endpoint (verify.py:1437-1447), which is not evidence. Also switches fixtures and docs to vendor-neutral example model names.src/cmcp_runtime/tee/opaque.py,src/cmcp_verify/opaque.py,tests/unit/test_opaque_fail_closed_594.pyTEEProvider.OPAQUE,AttestationProviderNotImplemented, theopaque/opaque-managedverifier branch,CMCP_OPAQUE_ATTESTATION_ENDPOINT,OPAQUE_API_KEY, and the spec'shighestassurance valueattestation.provider: opaquenow fails with the sameConfigErroras an unknown name (new test in test_config.py)test_tdx_opaque_verify.pyrenamed totest_tdx_verify.pyopaqueplatform aliasTouches security_paths
src/cmcp_runtime/tee/,src/cmcp_runtime/audit/,src/cmcp_verify/, so this needs two approvals.Tests: 2431 passed on main, 2388 here (44 opaque tests removed, 1 added), 31 skipped both. ruff, mypy, bandit and
mkdocs build --strictclean.🤖 Generated with Claude Code