Repository navigation
Pin busbar-auth-oidc 4d9e8f4: 1.5.5 egress class, key refresh, verdict cache - #700
Open
MattJackson wants to merge 12 commits into
Open
MattJackson wants to merge 12 commits into
MattJackson wants to merge 12 commits into
Conversation
…c door's needs declare operator-infrastructure The oidc egress needs move from open-web to operator-infrastructure (busbar-auth-oidc #26), so the token exchange admits http to a private or loopback IdP as 1.5.5 did; discovery and the JWKS stay https-only in the plugin. The pin also brings #27 (tick key refresh, verdict cache, waiter wakes) and #28 (an unobtainable key set answers Reject, 401). Cargo.lock source lines updated by hand; the new test fails at 0a7b7a5, where every need declares open-web.
MattJackson
enabled auto-merge
October 9, 2026 21:00
promote into
|
| gate | row | detail |
|---|---|---|
| construction | one-pick-site |
3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8 |
| kind-isolation | kind-isolation:deps |
3 finding(s), 93 shipped edge instance(s) over 30 class(es), 93 declaration(s); 56 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w |
| kind-isolation | kind-isolation:test-deps |
3 finding(s), 35 test edge instance(s) over 21 class(es), 35 declaration(s); 20 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge |
| kind-isolation | kind-isolation:law0 |
11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular |
| kind-isolation-ship | kind-isolation:deps |
10 finding(s) over 93 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hook-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the a |
| kind-isolation-ship | kind-isolation:test-deps |
10 finding(s) over 35 test edge(s): ship-edge cleanliness -> export busbar-core-admin -> busbar-export-prometheus is 'not-allowed': the architecture grants no cleanliness -> export edge, and the ship |
| kind-isolation-ship | kind-isolation:law0 |
11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular |
| kind-isolation-ship | kind-isolation:faces |
2 finding(s) over 40 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Transport' 1 time(s) in shipped source — the entry face of kind 'transport'. A trait implementation is |
| kind-isolation-ship | kind-isolation:legacy-drain |
3 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier) |
| ship-ready | ship-ready:ship-twin |
'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is |
| structure-lint | structure-lint:plane-dup:unledgered |
22 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs voice:crates/busbar-voice/src/config.rs (the ledger |
Judged against base bd3947661: 0 new red, 0 worse, 5 standing (excused).
tests passed: 24284, failed: 0. Run: https://github.com/GetBusbar/busbar/actions/runs/38058450290 . Artifact verdict-b0a31383247aedcd835e75ec79df71cd584eb201 (failures.json, junit.xml, raw.log; 90 days).
… a test release key busbar-auth-oidc 4d9e8f4 states every outbound need in the operator-infrastructure egress class, which the scan grants to a first-party plugin only (EGRESS-GRANT 2026-10-03). The kernel's plugin_chain_tests dropped it in unsigned as publisher `acme`, so the scan skipped it. - busbar-kernel test_support: the test build's trust policy holds a test release key (test_release_key) as its first-party key, whose private half no test held before; the loader's conformance tests already sign under a release key of their own. - plugin_chain_tests: the auth-oidc tarball is signed first-party (publisher `busbar`) with that key. The v1-refusal and untrusted fail-closed arms keep their unsigned copies. - plugin-loader auth_conformance_tests::a_third_party_signature_is_a_different_row: the third-party copy now has no row at all; the red arm asserts it is never admitted and is skipped as RejectKind::EgressGrant in the grant's words. Proved on Latchkey: busbar-kernel auth::plugin_chain_tests and the loader red arm pass. Not fixed here: busbar mcp_stdio_serve (the governed-session battery). The child binary embeds the real release key and does not link OIDC, so its dropped-in OIDC copy is refused and the child exits. Making it green needs an owner decision: link the OIDC door into the root, add a test-only first-party key seam in the binary, or revisit the plugin's egress class.
…oidc-pin-operator-infra
…test-harness-only first-party key seam in the root's trust resolution; the battery runs in the root test-harness row
…oidc-pin-operator-infra
…ane-mcp, so the composition-root test names no plane instance (instance-noun-neutrality:mcp / :undocumented)
…to neutral crates The branch grew Law 0 cells off their ceilings (figure 11 -> 16): busbar x auth (the new egress-class test's doc named busbar-auth-oidc), busbar-kernel x auth (a third auth-oidc doc mention in plugin_chain_tests), and busbar x plane / x transport (boot.rs's harness-seam doc named tests/mcp_stdio_serve.rs). Reword that prose. The egress-class test must name busbar_auth_oidc::door to read the pinned door, so the gratuitous auth-oidc spelling in mcp_stdio_serve's expect message is drained in its place; every cell is back at its base count and no ceiling moves.
…oidc-pin-operator-infra
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Pin busbar-auth-oidc 4d9e8f4: 1.5.5 egress class, key refresh, verdict cache
At 4d9e8f4 every outbound need the OIDC plugin states is in the
operator-infrastructureegress class. The host grants that class only to a first-party plugin (BUSBAR-1.6.0.md §5, l.604: "first-party means a grant in the root manifest").Test-harness first-party key seam (ARCHITECT ruling, #700, 2026-10-10, option A(1)):
root::boot::trust_policytakes its first-party key fromBUSBAR_TEST_HARNESS_FIRST_PARTY_KEYonly undercfg(feature = "test-harness"). Without that feature, no code path reads the variable. Release builds compile-p busbarwith default features, so production trust is unchanged (Locked ci: Docker packages the release binary instead of building its own #70).a_build_without_test_harness_ignores_the_harness_key_and_refuses_a_test_signed_first_party_plugin. A build withouttest-harness, with the variable set, still holds the embedded key and refuses both a test-signed and an unsigned first-party plugin.a_test_harness_build_takes_its_first_party_key_from_the_harness_variable.the_release_feature_set_excludes_test_harnesschecks two things: the default feature set does not reachtest-harness, and the release builds inscripts/release-build.shandscripts/pgo-build.shpass no--featuresor--all-features. A planted manifest gives it a RED arm.Coverage move:
tests/mcp_stdio_serve.rsnow signs the real dropped-in OIDC module first-party under the harness key, and its cfg also requirestest-harness. The battery therefore runs in the root test-harness row. It no longer runs in the single-plane-mcp row or the plain workspace (nextest) rows.