Dstack-TEE / Dstack-TEE/dstack

GPU attestation gate follow-ups: commit to RTMR, enforce CC mode, cache OCSP, SNP

Open
#778 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Rust
Stars
544
Forks
96
Avg merge
17h 57m
Merged PRs (30d)
117

Description

## Context

The GPU attestation gate landed in #765 and Dstack-TEE/meta-dstack#83. It runs local `nvattest` before key provisioning, and fails closed if an attached GPU can't attest. That's a good foundation, but a few follow-ups remain before it's a complete, remotely-verifiable trust story. Design context is in #751.

## Follow-ups

- [x] **Commit the attestation result into an RTMR, not report_data.** Today it only lands in a file under `/run`, and the planned binding would put it in report_data. But report_data can be set by any app to any value. So a VM with no GPU could copy a real VM's value and pass, and a verifier couldn't tell the two apart. If dstack-util instead emits a `gpu-attestation` event before `system-ready`, the value lands in RTMR3, which is measured and append-only, so KMS and remote verifiers can actually trust it. It also closes a gap we have today: a no-GPU VM with `verify_gpu=true` currently looks identical to a verified one.

- [x] **Require CC mode on, and reject DEVTOOLS.** We run `nvattest` with no policy file, so success comes down to the `x-nvidia-overall-result` claim. That claim proves the GPU is genuine and its measurements match, but it does not require CC mode to be on. That means a GPU in DEVTOOLS mode, where memory encryption is off, can still pass. A small Rego policy that requires CC on and debug off would close this.

- [x] **Don't let OCSP turn into a boot DoS.** Local verify makes a live call to NVIDIA's OCSP endpoint at boot (that's what the chrony step is for). Because the gate is fail-closed, anyone who blocks that endpoint stops every GPU VM from booting. That includes a malicious host, but also an egress-restricted or air-gapped deployment, or plain NVIDIA downtime. Caching or stapling the OCSP response would avoid it.

- [ ] **Add SNP support.** The RTMR approach doesn't port to SEV-SNP, because SNP has no runtime measurement register: its identity comes from launch-time HOST_DATA. So SNP will need a vTPM before the same binding works. Worth tracking now, otherwise SNP quietly ships a weaker binding.

Refs: #765, Dstack-TEE/meta-dstack#83, #751.

Contributor guide

Open the contributing guide

Research direction

Start with the design context in #751 and the existing attestation work referenced in #765 and Dstack-TEE/meta-dstack#83. Trace dstack-util’s event path around system-ready and determine the SNP/vTPM integration boundary; done means SNP has the same remotely verifiable binding without relying on an RTMR.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.