feat(verify): publish a TDX capture that binds a TRACE record's signing key - #69
Merged
Merged
Conversation
…ng key The July GCP captures bind a manifest hash whose input was never published, so /verify and the homepage could only say genuine silicon. A capture taken on 2026-09-14 in a new C3 trust domain puts SHA-256 of an Ed25519 key, generated inside the TD, in REPORTDATA and signs a TRACE v0.3 record with it. The quote, the record and the capture program are published under verify/fixtures. verify/key-binding.js checks the binding in the browser and the homepage panel; tools/check-key-binding.py checks the record signature, binding, quote, MRTD and program digest with the Python SDK in the verifier job. The differential now covers three captures, 5,526 inputs. verify/fixtures is marked -text, since every file there is pinned by hash. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013aK3gVWzNdcM3hZ2o2awK2
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
The two GCP TDX captures from 2026-07-21 put a manifest hash in REPORTDATA, and the input to that hash was never published. So /verify, the homepage panel and llms.txt could only say that genuine Intel TDX silicon signed the quote, and had to add that nothing tied a TRACE record to that machine.
This adds a third capture that closes that gap, taken on 2026-09-14 in a new GCP C3 trust domain (configfs-tsm, provider
tdx_guest). Inside the TD the capture program generated an Ed25519 key, set REPORTDATA to SHA-256 of its raw public key followed by 32 zero bytes, took the quote, and signed a TRACE v0.3 record carrying that quote with agentrust-trace 0.10.0. The VM was deleted after the serial console readout.Published under verify/fixtures
gcp-tdx-2026-09-14-keybind_quote.bin, 8,000 bytes, SHA-2562217b3d6...1d61, MRTDc1ee9c16...70a5.gcp-tdx-2026-09-14-keybind_record.json: the signed record, the public key and REPORTDATA.gcp-tdx-2026-09-14-capture.py: the program that ran, whose SHA-256 is the record'sbuild_provenance.digest.Checks
verify/key-binding.jschecks in the browser that SHA-256 of the record'scnf.jwk.xequals REPORTDATA[0:32], and that the record carries this quote and claims its MRTD. /verify loads capture 3 by default, and the homepage panel runs it with a REPORTDATA row that now passes or fails instead of pointing at a note.tools/check-key-binding.pyruns in the verifier job with agent-manifest 0.12.0 and agentrust-trace 0.10.0. It checks the quote to the pinned Intel root, the binding, the quote and MRTD in the record, the Ed25519 record signature over the SDK's canonical bytes, and the capture program digest. The browser does not check the record signature, because that would need a second canonical JSON implementation.check-tdx-verifier.mjsnow pins SHA-256 and MRTD per capture, and fails if the key binding passes for either July capture.Wording. /verify, the homepage note and llms.txt now say the quote commits to the key that signed the TRACE record. The stated limits are the ones that remain: no TCB or revocation appraisal, MRTD and RTMRs are shown but not compared with an expected image, and the record claims no model or policy.
Also:
.gitattributesmarksverify/fixtures/**as-text. Every file there is pinned by hash, and autocrlf would otherwise rewrite the capture program on a Windows checkout.Checked
appraise()(examples/runtime-evidence/generate.py, draft v0.3 schema plus signature) grades the recordattested.tdx-differential.pythencheck-tdx-verifier.mjs(port agrees on all 5,526 inputs, 1,872 accepted),check-key-binding.py, check-site.py (43 pages, 654 local links), build-controls.py --check, build-discovery.py --check, check-discovery.py, check-dashes.js and marketplace.test.js all pass.check-key-binding.pyfails when one byte of the record key changes (binding and signature both fail) and when a claim in the record is edited (signature fails).Generated with Claude Code
https://claude.ai/code/session_013aK3gVWzNdcM3hZ2o2awK2