Implementation · Tinfoil model identity (Modelwrap)

Technical detail

On this page
  • Build. Modelwrap downloads a pinned Hugging Face revision, normalizes the directory structure so the result is reproducible, and writes an EROFS image. It then computes a dm-verity root hash, a 32-byte commitment, with veritysetup 1. Its outputs are the image and a metadata file holding the root hash, offset and verity UUID. An encryption mode supports private models 5.
  • Binding. The root hash goes on the kernel command line, which the enclave measurement includes. At runtime dm-verity checks each block read by the inference engine against the root and fails on any mismatch 1.
  • Boot chain. The CPU measures the OVMF firmware first, then the kernel and initrd. A tinfoil-config.yml is checked against a hash on the kernel command line. The enclave checks each NVIDIA GPU's attestation with NVIDIA's local-gpu-verifier to confirm confidential-computing mode, and aborts the boot if the check fails. Model volumes are mounted read-only and checked against their Modelwrap commitments 3.
  • Client check. The SDK verifies the attestation certificate chain to the CPU vendor's root and verifies a Sigstore bundle of expected measurements. It then confirms that the TLS public key matches the key in the attestation document 3.
  • Reported costs. The hash tree adds about 0.8% to image size, and builds take 5 s for a 549 MB model and 13 min 25 s for a 554 GB model. Cold-cache loading takes about 80% longer 1.

Search

Full search page