Repository navigation
docs: Adopt current NVIDIA SECURITY.md template - #473
Conversation
TRI-1935
|
TRI-1935
| * Models, configuration and other inputs come from trusted sources. | ||
| * Dependencies and the build environment are kept up to date and obtained from trusted sources. | ||
| * Operators protect secrets, certificates and credentials, and restrict access to logs and metrics. | ||
| * Host operating system, driver and hardware security are the operator's responsibility. |
There was a problem hiding this comment.
Local library warning removed The general host-security assumption no longer warns operators to keep library paths trusted. In Triton C API mode,
--triton-server-directory selects a library loaded with dlopen; MPI and CUDA libraries are also loaded by name. If an untrusted user can influence one of those locations, the tool can load unintended code. How this was verified: The configured server-library path reaches dlopen, while MPI and CUDA libraries are loaded by name.
|
|
||
| 1. **Untrusted input:** Requests, models, configuration or data supplied to this component may be malformed or malicious, and could cause crashes, memory errors or unintended behavior if not validated. | ||
| 2. **Supply chain:** Source and build dependencies fetched at build or install time may be compromised, outdated or unpinned. | ||
| 3. **Network exposure:** When deployed behind a network-facing server, endpoints may be reachable by untrusted clients. This component does not by itself provide authentication, authorization or encryption. |
There was a problem hiding this comment.
Network boundary points inward This describes an inbound-facing component behind a gateway, but Perf Analyzer is a client that connects to inference services. Saying it does not provide encryption also obscures its outbound TLS and certificate options. Operators may focus on an inbound endpoint instead of configuring protection for the connection carrying their requests. How this was verified: The client backend configures outbound HTTPS verification and certificate options, whereas the documented gateway guidance addresses inbound access.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
| 2. **Supply chain:** Source and build dependencies fetched at build or install time may be compromised, outdated or unpinned. | ||
| 3. **Network exposure:** When deployed behind a network-facing server, endpoints may be reachable by untrusted clients. This component does not by itself provide authentication, authorization or encryption. | ||
| 4. **Resource exhaustion:** Oversized or numerous requests may consume memory, compute or other resources and degrade availability. | ||
| 5. **Information disclosure:** Logs, metrics and error messages may reveal sensitive data such as paths, identifiers or request content. |
There was a problem hiding this comment.
Profile export exposure omitted This guidance names logs, metrics and errors but not profile exports. When
--profile-export-file is used, the export contains request inputs and response outputs and is written with default file permissions. Operators who restrict logs may still share or leave that file accessible without realizing it contains payload data. How this was verified: The profile exporter serializes request and response data into JSON and opens the output file with fopen(..., "w").
| * Models, configuration and other inputs come from trusted sources. | ||
| * Dependencies and the build environment are kept up to date and obtained from trusted sources. | ||
| * Operators protect secrets, certificates and credentials, and restrict access to logs and metrics. | ||
| * Host operating system, driver and hardware security are the operator's responsibility. |
There was a problem hiding this comment.
Shared memory precaution removed The general host-security assumption no longer tells operators to isolate shared-memory regions from other local processes or account for regions left after an abnormal exit. Shared-memory mode places test tensors in regions shared with the target server and relies on normal cleanup to unregister and unlink them, so omitting that precaution makes local exposure easier to overlook. How this was verified: Shared-memory initialization creates input and output regions, and unregistration and unlinking occur in the cleanup path.
Note: If this suggestion doesn't match your team's coding style, reply to this and let me know. I'll remember it for next time!
|
Closing: SECURITY.md already exists in this repository with NVIDIA's standard reporting text, so no change is needed here. Tracked in TRI-1935. |
|
|
||
| ## Critical Security Assumptions | ||
|
|
||
| * The component is deployed in a trusted environment or behind a gateway that provides authentication, authorization, TLS and rate limiting. |
There was a problem hiding this comment.
Elevated-Privilege Warning Removed The replacement assumptions drop the warning not to run Perf Analyzer with elevated privileges. If it runs as a privileged user, an
--input-data JSON file containing message_generator can execute a shell command with those privileges. The general advice to use trusted inputs does not make that risk clear to operators. How this was verified: The input-data command reaches popen and runs with the Perf Analyzer process’s privileges.
What does the PR do?
NVIDIA/NeMo,cuda-pythonandMegatron-LM.cuda-python, since Triton repos are mirrored to internal GitLab.Checklist
<commit_type>: <Title>Commit Type:
Check the conventional commit type
box here and add the label to the github PR.
Related PRs:
Where should the reviewer start?
SECURITY.md— compare againstNVIDIA/NeMo/SECURITY.mdfor the canonical wording.Test plan:
Documentation only; no code paths affected.
CI Pipeline ID:
Caveats:
NVIDIA/NeMosays "through GitHub",NVIDIA/cuda-pythonsays "through GitHub/GitLab". This PR uses the latter because Triton repositories exist on both GitHub and internal GitLab.Background
An AIVO asset review (securityportal.nvidia.com/aivo/assets) flagged Triton repositories with no SECURITY.md. Rather than authoring per-repository security documentation, every repository adopts NVIDIA's current standard template so the policy is identical everywhere and carries no repository-specific claims to maintain.
Related Issues: (use one of the action keywords Closes / Fixes / Resolves / Relates to)