Skip to content

Pin busbar-auth-oidc 4d9e8f4: 1.5.5 egress class, key refresh, verdict cache - #700

Open
MattJackson wants to merge 12 commits into
predevfrom
lane-task-row-105b-oidc-pin-operator-infra
Open

MattJackson wants to merge 12 commits into
predevfrom
lane-task-row-105b-oidc-pin-operator-infra

Conversation

@MattJackson

@MattJackson MattJackson commented Oct 9, 2026 •

Copy link
Copy Markdown
Collaborator

Pin busbar-auth-oidc 4d9e8f4: 1.5.5 egress class, key refresh, verdict cache

At 4d9e8f4 every outbound need the OIDC plugin states is in the operator-infrastructure egress class. The host grants that class only to a first-party plugin (BUSBAR-1.6.0.md §5, l.604: "first-party means a grant in the root manifest").

Test-harness first-party key seam (ARCHITECT ruling, #700, 2026-10-10, option A(1)):

  • root::boot::trust_policy takes its first-party key from BUSBAR_TEST_HARNESS_FIRST_PARTY_KEY only under cfg(feature = "test-harness"). Without that feature, no code path reads the variable. Release builds compile -p busbar with default features, so production trust is unchanged (Locked ci: Docker packages the release binary instead of building its own #70).
  • RED arm: a_build_without_test_harness_ignores_the_harness_key_and_refuses_a_test_signed_first_party_plugin. A build without test-harness, with the variable set, still holds the embedded key and refuses both a test-signed and an unsigned first-party plugin.
  • Green arm: a_test_harness_build_takes_its_first_party_key_from_the_harness_variable.
  • the_release_feature_set_excludes_test_harness checks two things: the default feature set does not reach test-harness, and the release builds in scripts/release-build.sh and scripts/pgo-build.sh pass no --features or --all-features. A planted manifest gives it a RED arm.

Coverage move: tests/mcp_stdio_serve.rs now signs the real dropped-in OIDC module first-party under the harness key, and its cfg also requires test-harness. The battery therefore runs in the root test-harness row. It no longer runs in the single-plane-mcp row or the plain workspace (nextest) rows.

…c door's needs declare operator-infrastructure

The oidc egress needs move from open-web to operator-infrastructure (busbar-auth-oidc #26), so the token exchange admits http to a private or loopback IdP as 1.5.5 did; discovery and the JWKS stay https-only in the plugin. The pin also brings #27 (tick key refresh, verdict cache, waiter wakes) and #28 (an unobtainable key set answers Reject, 401). Cargo.lock source lines updated by hand; the new test fails at 0a7b7a5, where every need declares open-web.
@github-actions

github-actions Bot commented Oct 9, 2026 •

Copy link
Copy Markdown

promote into predev: BOARD @b0a313832: 0 failing test row(s), 11 DENY row(s)

DENY rows (11)

gate row detail
construction one-pick-site 3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8
kind-isolation kind-isolation:deps 3 finding(s), 93 shipped edge instance(s) over 30 class(es), 93 declaration(s); 56 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w
kind-isolation kind-isolation:test-deps 3 finding(s), 35 test edge instance(s) over 21 class(es), 35 declaration(s); 20 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge
kind-isolation kind-isolation:law0 11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular
kind-isolation-ship kind-isolation:deps 10 finding(s) over 93 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hook-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the a
kind-isolation-ship kind-isolation:test-deps 10 finding(s) over 35 test edge(s): ship-edge cleanliness -> export busbar-core-admin -> busbar-export-prometheus is 'not-allowed': the architecture grants no cleanliness -> export edge, and the ship
kind-isolation-ship kind-isolation:law0 11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular
kind-isolation-ship kind-isolation:faces 2 finding(s) over 40 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Transport' 1 time(s) in shipped source — the entry face of kind 'transport'. A trait implementation is
kind-isolation-ship kind-isolation:legacy-drain 3 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier)
ship-ready ship-ready:ship-twin 'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is
structure-lint structure-lint:plane-dup:unledgered 22 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs voice:crates/busbar-voice/src/config.rs (the ledger

Judged against base bd3947661: 0 new red, 0 worse, 5 standing (excused).

tests passed: 24284, failed: 0. Run: https://github.com/GetBusbar/busbar/actions/runs/38058450290 . Artifact verdict-b0a31383247aedcd835e75ec79df71cd584eb201 (failures.json, junit.xml, raw.log; 90 days).

@MattJackson MattJackson added fixing and removed fixing labels Oct 9, 2026
@MattJackson MattJackson added fixing and removed fixing labels Oct 10, 2026
… a test release key

busbar-auth-oidc 4d9e8f4 states every outbound need in the operator-infrastructure egress
class, which the scan grants to a first-party plugin only (EGRESS-GRANT 2026-10-03). The
kernel's plugin_chain_tests dropped it in unsigned as publisher `acme`, so the scan skipped it.

- busbar-kernel test_support: the test build's trust policy holds a test release key
  (test_release_key) as its first-party key, whose private half no test held before; the
  loader's conformance tests already sign under a release key of their own.
- plugin_chain_tests: the auth-oidc tarball is signed first-party (publisher `busbar`) with
  that key. The v1-refusal and untrusted fail-closed arms keep their unsigned copies.
- plugin-loader auth_conformance_tests::a_third_party_signature_is_a_different_row: the
  third-party copy now has no row at all; the red arm asserts it is never admitted and is
  skipped as RejectKind::EgressGrant in the grant's words.

Proved on Latchkey: busbar-kernel auth::plugin_chain_tests and the loader red arm pass.

Not fixed here: busbar mcp_stdio_serve (the governed-session battery). The child binary embeds
the real release key and does not link OIDC, so its dropped-in OIDC copy is refused and the
child exits. Making it green needs an owner decision: link the OIDC door into the root, add a
test-only first-party key seam in the binary, or revisit the plugin's egress class.
@MattJackson MattJackson added fixing and removed fixing labels Oct 10, 2026
…test-harness-only first-party key seam in the root's trust resolution; the battery runs in the root test-harness row
…ane-mcp, so the composition-root test names no plane instance (instance-noun-neutrality:mcp / :undocumented)
@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 10, 2026
@MattJackson MattJackson added fixing and removed fixing labels Oct 10, 2026
@MattJackson MattJackson added fixing and removed fixing labels Oct 10, 2026
…to neutral crates

The branch grew Law 0 cells off their ceilings (figure 11 -> 16):
busbar x auth (the new egress-class test's doc named busbar-auth-oidc),
busbar-kernel x auth (a third auth-oidc doc mention in plugin_chain_tests),
and busbar x plane / x transport (boot.rs's harness-seam doc named
tests/mcp_stdio_serve.rs). Reword that prose. The egress-class test must
name busbar_auth_oidc::door to read the pinned door, so the gratuitous
auth-oidc spelling in mcp_stdio_serve's expect message is drained in its
place; every cell is back at its base count and no ceiling moves.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant