Skip to content

refactor(tee): remove the opaque attestation provider and verifier - #737

Merged
imran-siddique merged 3 commits into
mainfrom
chore/vendor-neutral
Oct 8, 2026
Merged

imran-siddique merged 3 commits into
mainfrom
chore/vendor-neutral

Conversation

@imran-siddique

Copy link
Copy Markdown
Member

Removes the opaque attestation path. The runtime provider only raised, and cmcp_verify.opaque credited hardware_attestation on an unsigned verified: true from a remote endpoint (verify.py:1437-1447), which is not evidence. Also switches fixtures and docs to vendor-neutral example model names.

  • Deleted src/cmcp_runtime/tee/opaque.py, src/cmcp_verify/opaque.py, tests/unit/test_opaque_fail_closed_594.py
  • Removed TEEProvider.OPAQUE, AttestationProviderNotImplemented, the opaque/opaque-managed verifier branch, CMCP_OPAQUE_ATTESTATION_ENDPOINT, OPAQUE_API_KEY, and the spec's highest assurance value
  • attestation.provider: opaque now fails with the same ConfigError as an unknown name (new test in test_config.py)
  • test_tdx_opaque_verify.py renamed to test_tdx_verify.py
  • Kept: CHANGELOG history, sponsor and maintainer lines, and the schema-rejection test for the legacy opaque platform alias

Touches security_paths src/cmcp_runtime/tee/, src/cmcp_runtime/audit/, src/cmcp_verify/, so this needs two approvals.

Tests: 2431 passed on main, 2388 here (44 opaque tests removed, 1 added), 31 skipped both. ruff, mypy, bandit and mkdocs build --strict clean.

🤖 Generated with Claude Code

@codecov-commenter

Copy link
Copy Markdown

⚠️ Please install the 'codecov app svg image' to ensure uploads and comments are reliably processed by Codecov.

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

Qiang-Xu
Qiang-Xu previously approved these changes Oct 8, 2026

@Qiang-Xu Qiang-Xu left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks good.

imran-siddique and others added 3 commits October 8, 2026 14:07
The runtime provider was a placeholder that only raised, and the verifier
credited hardware_attestation on an unsigned verified:true returned by a
remote endpoint. Drop both modules, TEEProvider.OPAQUE, the
ATTESTATION_PROVIDER_NOT_IMPLEMENTED error, the opaque and opaque-managed
branches in verify_trace_claim, and the tests that only exercised them.
A config naming provider opaque now fails like any unknown provider.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@imran-siddique
imran-siddique merged commit e4d81e7 into main Oct 8, 2026
18 of 20 checks passed
@imran-siddique
imran-siddique deleted the chore/vendor-neutral branch October 8, 2026 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants