Add optional Runpod untrusted-caller lab - #3
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
examples/runpod-untrusted-caller/, isolated from the core package and assurance claimVerification
swtpmtests deselected), 280 lab tests passed (1swtpmtest deselected); core combined coverage was 88.22% against the measured 85% floorswtpm: 161 core tests and 281 lab tests passed; combined core coverage was 90.35%35c60503f3b8daf95c2868ed6eddb95765191c62Live validation
The first bounded job exposed an unusable earlier image whose dependency lock was empty. It produced no worker response or signed record, and cleanup completed. The runner now rejects that class of image before any billable provider mutation.
A fresh bounded CPU Serverless run then completed using:
docker.io/ningwers2/attested-capability-broker-holder@sha256:ab2178d1a07f3ce99f884e6dbfe1e8d8e9003a7d2470fde9cf2ca778947c2306The local controller verified real-
swtpmappraisal evidence and the signed experiment record, including all 7 broker receipts and all 15 resource receipts. The transcript records 3 allowed and 12 denied attempts, 3 handler invocations, and 3 credential spends. In the eight-way race, exactly one attempt was allowed and seven were deniedCREDENTIAL_SPENT, with one invocation and one spend. The endpoint and private template were removed; three consecutive read-backs found both absent, and account spend returned to $0/hour. Checksummed evidence remains outside Git and is not part of this PR.Assurance boundary
Runpod, its control plane, queue, worker, network, metadata, and output remain untrusted. This lab tests application-level behavior against a remote untrusted caller. It does not attest Runpod or prove intended-image execution, key residency, TPM/agent co-location, TEE/runtime/network integrity, safe behavior, or exactly-once business execution. The self-contained JWS and bundled verifier establish internal signature consistency; attributing the record to a controller requires independently pinning its verification key. With that pin, the JWS authenticates only the configured local controller's observed transcript.