Repository navigation
door_steps: a jwt-bearer member mints at its service account's token_uri, judged at the seal as 1.5.5 judged it - #622
Merged
Merged
Conversation
…l (token_uri unfilled, the service account's endpoint unjudged) The seal's parameter shape gains token_uri and the provider's metadata posture; the seal itself still fills only the stated keys, as on predev, so both cells fail: - a_member_under_jwt_bearer_mints_at_its_service_accounts_token_uri: the plugin's settings.token_uri need is never pinned, so no bearer is minted; - a_service_account_token_uri_is_judged_at_the_seal_in_1_5_5s_words: plaintext and metadata token_uri pass the seal unjudged.
…uri, judged at the seal as 1.5.5 judged it The serving plugin's mint need targets settings.token_uri (busbar-auth-oauth NEEDS), but the seal wrote only token_url/scope/subject, so a jwt-bearer provider never minted. At the seal, once the credential resolves, its service account's token_uri (1.5.5's default https://oauth2.googleapis.com/token when absent) is judged under the provider's metadata posture with 1.5.5's check and words (v1.5.5 main.rs:2960-2966 over egress_auth/jwt_bearer.rs::validate_token_uri) and written into the settings the plugin is opened with. Spec: BUSBAR-1.6.0.md l.611 (mint endpoints token_url, token_uri; ARCHITECT 2026-10-04 parity ruling), l.799-801, l.860 (the kernel judges a token URL by the 1.5.5 rule). config_validate gains MetadataPosture, service_account_token_uri and vet_token_uri, in the shape #487 adds them, so the two land as one.
…n-uri # Conflicts: # crates/busbar/src/root/door_steps.rs
MattJackson
enabled auto-merge
October 7, 2026 23:18
promote into
|
| gate | row | detail |
|---|---|---|
| construction | one-pick-site |
3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8 |
| kind-isolation | kind-isolation:deps |
3 finding(s), 93 shipped edge instance(s) over 30 class(es), 93 declaration(s); 56 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w |
| kind-isolation | kind-isolation:test-deps |
3 finding(s), 35 test edge instance(s) over 21 class(es), 35 declaration(s); 20 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge |
| kind-isolation | kind-isolation:law0 |
11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular |
| kind-isolation-ship | kind-isolation:deps |
10 finding(s) over 93 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hook-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the a |
| kind-isolation-ship | kind-isolation:test-deps |
10 finding(s) over 35 test edge(s): ship-edge cleanliness -> export busbar-core-admin -> busbar-export-prometheus is 'not-allowed': the architecture grants no cleanliness -> export edge, and the ship |
| kind-isolation-ship | kind-isolation:law0 |
11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular |
| kind-isolation-ship | kind-isolation:faces |
2 finding(s) over 40 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Transport' 1 time(s) in shipped source — the entry face of kind 'transport'. A trait implementation is |
| kind-isolation-ship | kind-isolation:legacy-drain |
3 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier) |
| ship-ready | ship-ready:ship-twin |
'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is |
| structure-lint | structure-lint:plane-dup:unledgered |
22 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs voice:crates/busbar-voice/src/config.rs (the ledger |
Judged against base 17b55f973: 0 new red, 0 worse, 5 standing (excused).
tests passed: 22322, failed: 0. Run: https://github.com/GetBusbar/busbar/actions/runs/38098523626 . Artifact verdict-110ec0b956d26003321f3f6dcb134f9109d58258 (failures.json, junit.xml, raw.log; 90 days).
github-merge-queue
Bot
removed this pull request from the merge queue due to a conflict with the base branch
Oct 8, 2026
…ataPosture-based service_account_token_uri/vet_token_uri, take predev's outbound_credential_refusals
MattJackson
enabled auto-merge
October 10, 2026 03:26
…s (name, canonical, door) triple The merge of origin/predev changed busbar_kernel::preflight::LinkedAuth to a three-field tuple; jwt_bearer_routes still built the old pair, so the busbar crate's tests failed to compile (E0308) and every gate that compiles them went red. Spell it as the oauth sibling does.
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 10, 2026
…), so the jwt-bearer test adds no busbar x auth Law 0 hits
github-merge-queue
Bot
removed this pull request from the merge queue due to failed status checks
Oct 10, 2026
MattJackson
enabled auto-merge
October 11, 2026 00:05
…ata fields The jwt-bearer door_steps fixture lacked error_map and serve_planes' route fixture lacked metadata after predev added the field, so the busbar test target failed to compile (E0063). Not proved on Latchkey: the run budget (RUN_CAP) is spent; the PR's CI judges.
MattJackson
added a commit
that referenced
this pull request
Oct 11, 2026
…redev's verify/admit/audit proofs Ruling: predev (#628, #622) landed the decisions root leg's verify, admit and audit cells with the corrected verify test (a_decisions_unit_from_a_key_naming_another_pool_is_refused_before_its_dial: Approve/ScopeDenied sealed before admit and dial, plus the granted-every-pool control). This branch's older duplicate (a_unit_granted_only_another_pool_is_refused_before_admit) is dropped and the three root cells cite predev's tests and notes; coverage is re-pointed, never retired (BUSBAR-1.6.0.md:3857), and the root-leg proof stays beside each cell as the teller-steps gate of Law 1 requires (BUSBAR-1.6.0.md:2176). serve_tests.rs is predev's verbatim, which also removes the duplicate `allowed_pools` field the auto-merge produced in serve_configured. The branch keeps its own intent: the seven jev rig cells and owed_gaps {}.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
jwt-bearer parity. The busbar-auth-oauth plugin's jwt-bearer mint need targets
settings.token_uri, but the seal wrote onlytoken_url/scope/subject, so a jwt-bearer provider never minted. Audit pinned-auth-oauth HIGH #1.Fix
token_uriis read. It defaults tohttps://oauth2.googleapis.com/token, as in v1.5.5egress_auth/jwt_bearer.rs:366.jwt_bearer.rs:117-149). A failure is rendered asprovider '<p>' (jwt-bearer auth): <why>(v1.5.5main.rs:2960-2966).token_url,token_uri; ARCHITECT 2026-10-04 parity ruling) and l.860 (the kernel judges a token URL by the 1.5.5 rule).config_validategainsMetadataPosture,service_account_token_uriandvet_token_uri, in the shape P2 D1: the auth split — auth-kind logic leaves the kernel for the auth plugins (stacked on #484) #487 adds them. Whichever of this PR and P2 D1: the auth split — auth-kind logic leaves the kernel for the auth plugins (stacked on #484) #487 lands second keeps one copy.Proof (Latchkey cli-f740f0b9, large, both commits in one job)
a_member_under_jwt_bearer_mints_at_its_service_accounts_token_uri(door_steps.rs:944): the mint need is never pinned to the token_uri.a_service_account_token_uri_is_judged_at_the_seal_in_1_5_5s_words(door_steps.rs:997): an http public token_uri passes the seal.cargo fmt --check0;cargo clippy -p busbar-kernel -p busbar --all-targets -D warnings0;cargo test --bin busbar root::door_steps:: root::serve::door_tests::86 passed, 0 failed.spelled_for. The merged head's proof is this PR's CI.