Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion examples/weight-custody-manifest/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,7 +51,7 @@ Each script is one runnable feature with mock (software) attestation, so they ru

### Closed-weight vs open-weight

The same machinery, two trust settings. **Closed** weights (a frontier model deployed into someone else's infra) need secrecy. **Open** weights (Llama, Mistral, SmolLM) are already public, so the flow instead does integrity, license, and derivative custody.
The same machinery, two trust settings. **Closed** weights (a frontier model deployed into someone else's infra) need secrecy. **Open** weights (SmolLM and other public checkpoints) are already public, so the flow instead does integrity, license, and derivative custody.

- **`closed_model_e2e.py`** -- the closed/frontier flow where secrecy is the job (`base_confidentiality: confidential`): sign, attestation-gated release of the real decryption key, wipe-on-lapse custody, and the honest hostile-owner caveat.
- **`open_model_e2e.py`** -- the full six-step flow on an open model, honest about which steps are real work versus theater for a public base (the base's secrecy is theater; integrity, license, derivative custody, and the kill switch are the point).
Expand Down
10 changes: 5 additions & 5 deletions examples/weight-custody-manifest/manifest.example.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,7 +8,7 @@
"release_terms": {
"license": "customer-deployment-agreement-ref:CDA-2026-0091",
"permitted_derivatives": "fine-tune-only, no re-export of base weights",
"permitted_environments": ["opaque-cmcp-attested-enclave"],
"permitted_environments": ["cmcp-attested-enclave"],
"jurisdiction_restriction": "US, EU"
},
"release_policy": {
Expand Down Expand Up @@ -54,14 +54,14 @@
}
},
"custody": {
"custodian": "opaque-systems",
"custodian": "example-custodian",
"custodian_type": "opaque-hosted",
"kbs_image": {
"measurement": "sha256:abcd1234abcd1234abcd1234abcd1234abcd1234abcd1234abcd1234abcd1234",
"signer": "ed25519:opaque-key-placeholder",
"note": "the key release service runs in an attested enclave in every profile, Opaque-hosted included"
"signer": "ed25519:custodian-key-placeholder",
"note": "the key release service runs in an attested enclave in every profile, custodian-hosted included"
},
"enclave_id": "did:opaque:example-enclave-04",
"enclave_id": "did:example:enclave-04",
"attestation_cadence": "24h",
"kbs_attestation_cadence": "24h"
},
Expand Down
12 changes: 6 additions & 6 deletions examples/weight-custody-manifest/open_model_e2e.py
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@
The reframe that drives this demo
---------------------------------
For a closed frontier model the job is secrecy: don't let the weights leak. For
an OPEN-weight model (Llama, Mistral, SmolLM, ...) the base weights are already
an OPEN-weight model (SmolLM or any public checkpoint) the base weights are already

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

SmolLM is from huggingface which is a part of nvidia, are we allowed to mention it?

downloadable, so encrypting them and gating decryption behind attestation
protects nothing - anyone can just download the same checkpoint. Saying that
plainly matters. What the same six-step machinery still does, and why you'd run
Expand Down Expand Up @@ -130,21 +130,21 @@ def main() -> None:
gov_custodian = generate_ed25519()

rule("Open-weight model: base weights are PUBLIC")
# Pretend this blob is a downloaded checkpoint (in reality: your
# Llama-3.1 / Mistral / SmolLM safetensors). We hash the real bytes.
# Pretend this blob is a downloaded checkpoint (in reality, the
# any public safetensors checkpoint). We hash the real bytes.
checkpoint = b"<the bytes of a public open-weight checkpoint>"
base_hash = sha256(checkpoint)
serving = sha256(b"vllm-0.6.3 + policy-bundle-v2 (the certified serving stack)")
print("base weights_hash :", base_hash)
print("license : Llama-3.1-Community (usage + scale restrictions)")
print("license : example-community-license (usage + scale restrictions)")
print("NOTE: encrypting a *public* base protects nothing. The mechanism below")
print(" does INTEGRITY + LICENSE work here, not secrecy.")

# ---- Step 0: certify the base checkpoint (integrity + license) ----------
rule("Step 0 - Certify the base: manifest (integrity + license), jointly signed")
base_doc = build_manifest(
weights_hash=base_hash,
license_text="Llama-3.1-Community",
license_text="example-community-license",
serving_measurement=serving,
builder_id="acme-model-governance",
custodian_id="acme-model-governance",
Expand Down Expand Up @@ -213,7 +213,7 @@ def main() -> None:
deriv_hash = sha256(derivative_weights)
deriv_doc = build_manifest(
weights_hash=deriv_hash,
license_text="Llama-3.1-Community + Acme-proprietary-derivative",
license_text="example-community-license + Acme-proprietary-derivative",
serving_measurement=serving,
builder_id="acme-model-governance",
custodian_id="acme-model-governance",
Expand Down
14 changes: 7 additions & 7 deletions examples/weight-custody-manifest/real_lora_custody.py
Original file line number Diff line number Diff line change
Expand Up @@ -240,29 +240,29 @@ def main() -> int:
serving = "sha256:" + hashlib.sha256(b"wcm-local-lora-serving-stack-v1").hexdigest()
manifest_doc = build_manifest(
weights_hash=envelope["artifact_digest"],
license_text="Apache-2.0 + OPAQUE-private-derivative",
license_text="Apache-2.0 + private-derivative",
serving=serving,
builder_id="opaque-wcm-builder",
custodian_id="opaque-wcm-custodian",
builder_id="example-wcm-builder",
custodian_id="example-wcm-custodian",
derivatives="none",
derived_from=base_digest,
rights_holder={"base": model_id, "derivative": "OPAQUE"},
rights_holder={"base": model_id, "derivative": "example-derivative-owner"},
)
manifest_doc["provenance"] = {
"model_signing": {
"method": "openssf-model-signing",
"signed_digest": provenance_digest,
"transparency": "local-key; publication pending",
"signer": "opaque-wcm-builder",
"signer": "example-wcm-builder",
}
}
manifest = WeightCustodyManifest.model_validate(waive_mock_verification(manifest_doc))
manifest = manifest.with_signatures([
Ed25519Signer(builder).sign(
manifest.unsigned_dict(), role="builder", signer="opaque-wcm-builder"
manifest.unsigned_dict(), role="builder", signer="example-wcm-builder"
),
Ed25519Signer(custodian).sign(
manifest.unsigned_dict(), role="custodian", signer="opaque-wcm-custodian"
manifest.unsigned_dict(), role="custodian", signer="example-wcm-custodian"
),
])
context = VerificationContext()
Expand Down
2 changes: 1 addition & 1 deletion integrations/comply54/README.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,7 @@ with open("result.json", "w") as f:
```bash
python src/comply54_to_trace.py result.json \
--agent-id payments-agent \
--model anthropic/claude-sonnet-4-6
--model example-provider/example-model
```

Output: `claim.jwt` (signed JWT, compact format) + printed to stdout.
Expand Down
2 changes: 1 addition & 1 deletion integrations/comply54/examples/emit_record.py
Original file line number Diff line number Diff line change
Expand Up @@ -46,7 +46,7 @@ def main() -> int:
parser.add_argument("--out", required=True, help="Path for the trace-tests-gradable record")
parser.add_argument("--result", default=str(DEFAULT_RESULT), help="comply54 ComplianceResult JSON path")
parser.add_argument("--agent-id", default="payments-agent", help="Agent SPIFFE identity suffix")
parser.add_argument("--model", default="anthropic/claude-sonnet-4-6", help="Model in provider/model-id format")
parser.add_argument("--model", default="example-provider/example-model", help="Model in provider/model-id format")
args = parser.parse_args()

result = json.loads(Path(args.result).read_text(encoding="utf-8"))
Expand Down
2 changes: 1 addition & 1 deletion integrations/comply54/src/comply54_to_trace.py
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@

Usage:
python comply54_to_trace.py result.json
python comply54_to_trace.py result.json --agent-id payments-agent --model anthropic/claude-sonnet-4-6
python comply54_to_trace.py result.json --agent-id payments-agent --model example-provider/example-model

The JWT is written to claim.jwt and printed to stdout.
Set TRACE_PRIVATE_KEY_PEM to supply a persistent Ed25519 key; otherwise a
Expand Down
56 changes: 28 additions & 28 deletions integrations/comply54/tests/test_comply54_to_trace.py
Original file line number Diff line number Diff line change
Expand Up @@ -82,88 +82,88 @@

class TestAppraisalMapping:
def test_allow_maps_to_affirming(self):
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model")
assert payload["appraisal"]["status"] == "affirming"

def test_deny_maps_to_contraindicated(self):
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model")
assert payload["appraisal"]["status"] == "contraindicated"

def test_escalate_maps_to_warning(self):
payload = comply54_to_trace_payload(ESCALATE_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(ESCALATE_RESULT, "agent-1", "example-provider/example-model")
assert payload["appraisal"]["status"] == "warning"

def test_audit_maps_to_warning(self):
payload = comply54_to_trace_payload(AUDIT_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(AUDIT_RESULT, "agent-1", "example-provider/example-model")
assert payload["appraisal"]["status"] == "warning"


# ── Required TRACE EAT envelope fields ───────────────────────────────────────

class TestTraceEnvelope:
def test_eat_profile_present(self):
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model")
assert payload["eat_profile"] == "tag:agentrust-io.com,2026:trace-v0.2"

def test_iat_is_integer(self):
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model")
assert isinstance(payload["iat"], int)
assert payload["iat"] > 0

def test_subject_contains_agent_id(self):
payload = comply54_to_trace_payload(ALLOW_RESULT, "payments-agent", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(ALLOW_RESULT, "payments-agent", "example-provider/example-model")
assert "payments-agent" in payload["subject"]
assert payload["subject"].startswith("spiffe://")

def test_policy_bundle_hash_is_sha256(self):
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model")
assert payload["policy"]["bundle_hash"].startswith("sha256:")
assert len(payload["policy"]["bundle_hash"]) == 71 # "sha256:" + 64 hex chars

def test_policy_bundle_hash_is_deterministic(self):
p1 = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
p2 = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
p1 = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model")
p2 = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model")
assert p1["policy"]["bundle_hash"] == p2["policy"]["bundle_hash"]

def test_runtime_platform_is_software_only(self):
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model")
assert payload["runtime"]["platform"] == "software-only"

def test_model_provider_parsed_correctly(self):
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "openai/gpt-4o")
assert payload["model"]["provider"] == "openai"
assert payload["model"]["model_id"] == "gpt-4o"
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "other-provider/other-model")
assert payload["model"]["provider"] == "other-provider"
assert payload["model"]["model_id"] == "other-model"


# ── comply54 extension claims ─────────────────────────────────────────────────

class TestComply54Claims:
def test_audit_id_preserved(self):
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model")
assert payload["comply54"]["audit_id"] == "test-audit-002"

def test_overall_decision_preserved(self):
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model")
assert payload["comply54"]["overall"] == "deny"

def test_jurisdictions_extracted(self):
payload = comply54_to_trace_payload(PAN_AFRICAN_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(PAN_AFRICAN_RESULT, "agent-1", "example-provider/example-model")
assert "NG" in payload["comply54"]["jurisdictions"]
assert "KE" in payload["comply54"]["jurisdictions"]
assert "ZA" in payload["comply54"]["jurisdictions"]

def test_packs_evaluated_sorted(self):
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model")
packs = payload["comply54"]["packs_evaluated"]
assert packs == sorted(packs)

def test_violations_only_non_allow(self):
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model")
for v in payload["comply54"]["violations"]:
assert v["action"] != "allow"

def test_allow_result_has_no_violations(self):
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model")
assert len(payload["comply54"]["violations"]) == 0


Expand All @@ -183,21 +183,21 @@ def test_jwk_has_correct_fields(self):

def test_signed_jwt_is_decodable(self):
key = load_or_generate_key()
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6", key=key)
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model", key=key)
token = pyjwt.encode(payload, key, algorithm="EdDSA", headers={"alg": "EdDSA", "typ": "JWT"})
decoded = pyjwt.decode(token, options={"verify_signature": False})
assert decoded["eat_profile"] == "tag:agentrust-io.com,2026:trace-v0.2"
assert decoded["appraisal"]["status"] == "contraindicated"

def test_signed_jwt_has_three_parts(self):
key = load_or_generate_key()
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6", key=key)
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model", key=key)
token = pyjwt.encode(payload, key, algorithm="EdDSA", headers={"alg": "EdDSA", "typ": "JWT"})
assert len(token.split(".")) == 3

def test_signature_is_cryptographically_verified(self):
key = load_or_generate_key()
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6", key=key)
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model", key=key)
token = pyjwt.encode(payload, key, algorithm="EdDSA", headers={"alg": "EdDSA", "typ": "JWT"})
public_key = key.public_key()
decoded = pyjwt.decode(token, public_key, algorithms=["EdDSA"])
Expand Down Expand Up @@ -227,19 +227,19 @@ def _core(payload: dict) -> dict:

class TestSchemaConformance:
def test_allow_result_core_conforms_to_trace_schema(self):
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(ALLOW_RESULT, "agent-1", "example-provider/example-model")
jsonschema.validate(_core(payload), _load_schema())

def test_deny_result_core_conforms_to_trace_schema(self):
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(DENY_RESULT, "agent-1", "example-provider/example-model")
jsonschema.validate(_core(payload), _load_schema())

def test_escalate_result_core_conforms_to_trace_schema(self):
payload = comply54_to_trace_payload(ESCALATE_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(ESCALATE_RESULT, "agent-1", "example-provider/example-model")
jsonschema.validate(_core(payload), _load_schema())

def test_audit_result_core_conforms_to_trace_schema(self):
payload = comply54_to_trace_payload(AUDIT_RESULT, "agent-1", "anthropic/claude-sonnet-4-6")
payload = comply54_to_trace_payload(AUDIT_RESULT, "agent-1", "example-provider/example-model")
jsonschema.validate(_core(payload), _load_schema())

def test_appraisal_status_is_valid_enum(self):
Expand All @@ -254,7 +254,7 @@ def test_appraisal_status_is_valid_enum(self):
def _build_signed_payload(result_fixture: dict) -> dict:
"""Return a complete TRACE payload (cnf.jwk included via the mapping function)."""
key = load_or_generate_key()
return comply54_to_trace_payload(result_fixture, "test-agent", "anthropic/claude-sonnet-4-6", key=key)
return comply54_to_trace_payload(result_fixture, "test-agent", "example-provider/example-model", key=key)


def _run_level0(result_fixture: dict) -> dict:
Expand Down
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
#!/usr/bin/env node
// ComputeID — Standalone Offline Verifier (OPAQUE diligence deliverable)
// ComputeID — Standalone Offline Verifier
//
// Reads a saved evidence bundle (the exact JSON response from
// GET /v1/agents/:id/verify) and INDEPENDENTLY recomputes every
// cryptographic check from raw key/signature/payload bytes already
// present in the bundle. Runs with ZERO network calls once the
// evidence file exists.
//
// FIXED (per Imran Siddique / OPAQUE Systems review of PR #176):
// FIXED (per maintainer review of PR #176):
// classical_signature_valid and ml_dsa_signature_valid previously read
// the service's own claimed signature_valid/pq_signature_valid fields
// rather than independently recomputing the signatures. That meant the
Expand Down
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
#!/usr/bin/env node
// ComputeID — Audit Hash-Chain Integrity Verifier (OPAQUE diligence deliverable)
// ComputeID — Audit Hash-Chain Integrity Verifier
//
// Walks the ENTIRE mcp_audit_log table in order and independently recomputes
// each entry's hash, confirming the chain has not been tampered with or had
Expand Down
Loading
Loading