Skip to content

door_steps: a jwt-bearer member mints at its service account's token_uri, judged at the seal as 1.5.5 judged it - #622

Merged
MattJackson merged 18 commits into
predevfrom
auth-fix-a-jwt-token-uri
Oct 11, 2026
Merged

MattJackson merged 18 commits into
predevfrom
auth-fix-a-jwt-token-uri

Conversation

@MattJackson

Copy link
Copy Markdown
Collaborator

jwt-bearer parity. The busbar-auth-oauth plugin's jwt-bearer mint need targets settings.token_uri, but the seal wrote only token_url/scope/subject, so a jwt-bearer provider never minted. Audit pinned-auth-oauth HIGH #1.

Fix

Proof (Latchkey cli-f740f0b9, large, both commits in one job)

  • RED, a2d5da7 (the cells plus the parameter shape; the seal still fills only the stated keys): 1 passed (the oauth-cc control), 2 failed.
    • a_member_under_jwt_bearer_mints_at_its_service_accounts_token_uri (door_steps.rs:944): the mint need is never pinned to the token_uri.
    • a_service_account_token_uri_is_judged_at_the_seal_in_1_5_5s_words (door_steps.rs:997): an http public token_uri passes the seal.
  • GREEN, d1c27f1: cargo fmt --check 0; cargo clippy -p busbar-kernel -p busbar --all-targets -D warnings 0; cargo test --bin busbar root::door_steps:: root::serve::door_tests:: 86 passed, 0 failed.
  • predev was merged once after that (e6a60ed). The only conflict was a doc comment beside spelled_for. The merged head's proof is this PR's CI.

…l (token_uri unfilled, the service account's endpoint unjudged)

The seal's parameter shape gains token_uri and the provider's metadata posture; the
seal itself still fills only the stated keys, as on predev, so both cells fail:
- a_member_under_jwt_bearer_mints_at_its_service_accounts_token_uri: the plugin's
  settings.token_uri need is never pinned, so no bearer is minted;
- a_service_account_token_uri_is_judged_at_the_seal_in_1_5_5s_words: plaintext and
  metadata token_uri pass the seal unjudged.
…uri, judged at the seal as 1.5.5 judged it

The serving plugin's mint need targets settings.token_uri (busbar-auth-oauth NEEDS), but the
seal wrote only token_url/scope/subject, so a jwt-bearer provider never minted. At the seal,
once the credential resolves, its service account's token_uri (1.5.5's default
https://oauth2.googleapis.com/token when absent) is judged under the provider's metadata
posture with 1.5.5's check and words (v1.5.5 main.rs:2960-2966 over
egress_auth/jwt_bearer.rs::validate_token_uri) and written into the settings the plugin is
opened with. Spec: BUSBAR-1.6.0.md l.611 (mint endpoints token_url, token_uri; ARCHITECT
2026-10-04 parity ruling), l.799-801, l.860 (the kernel judges a token URL by the 1.5.5 rule).

config_validate gains MetadataPosture, service_account_token_uri and vet_token_uri, in the
shape #487 adds them, so the two land as one.
…n-uri

# Conflicts:
#	crates/busbar/src/root/door_steps.rs
@MattJackson
MattJackson enabled auto-merge October 7, 2026 23:18
@github-actions

github-actions Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

promote into predev: BOARD @110ec0b95: 0 failing test row(s), 11 DENY row(s)

DENY rows (11)

gate row detail
construction one-pick-site 3 production call site(s) of 'pick_among(' (ceiling 2): crates/busbar-kernel-egress/src/walk.rs:298; crates/busbar-llm/src/engine/exhaustion/fallback.rs:120; crates/busbar-llm/src/engine/pipeline.rs:8
kind-isolation kind-isolation:deps 3 finding(s), 93 shipped edge instance(s) over 30 class(es), 93 declaration(s); 56 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge legacy -> plane busbar-llm -> busbar-plane-llm is a shipped edge w
kind-isolation kind-isolation:test-deps 3 finding(s), 35 test edge instance(s) over 21 class(es), 35 declaration(s); 20 '[[dep]]' row(s), 0 question(s): unlisted-dep-edge cleanliness -> legacy busbar-core-admin -> busbar-a2a is a test edge
kind-isolation kind-isolation:law0 11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular
kind-isolation-ship kind-isolation:deps 10 finding(s) over 93 shipped edge(s): ship-edge kernel -> hooks busbar-kernel -> busbar-hook-ranking is 'not-allowed': the architecture grants no kernel -> hooks edge, and the ship criterion is the a
kind-isolation-ship kind-isolation:test-deps 10 finding(s) over 35 test edge(s): ship-edge cleanliness -> export busbar-core-admin -> busbar-export-prometheus is 'not-allowed': the architecture grants no cleanliness -> export edge, and the ship
kind-isolation-ship kind-isolation:law0 11 hit(s) off the [[law0]] ceilings, 5 finding(s) over 14 neutral crate(s): law0-rise busbar × instance:secret 37 hit(s) against a ceiling of 35: this landing grew a neutral crate's instance vocabular
kind-isolation-ship kind-isolation:faces 2 finding(s) over 40 crate(s): foreign-entry crates/busbar busbar is kind 'root' and implements 'Transport' 1 time(s) in shipped source — the entry face of kind 'transport'. A trait implementation is
kind-isolation-ship kind-isolation:legacy-drain 3 finding(s): transitional-live qa/kind-isolation.toml 'busbar-a2a -> busbar-core-admin' (legacy drain: the retiring A2A engine's tests drive the admin surface that drained into the cleanliness tier)
ship-ready ship-ready:ship-twin 'kind-isolation-ship' is not green: kind-isolation:deps (a dependency the architecture does not grant is still in the graph); kind-isolation:test-deps (a dependency the architecture does not grant is
structure-lint structure-lint:plane-dup:unledgered 22 finding(s): PLANE-DUPLICATE (module): 'config.rs' — a2a:crates/busbar-a2a/src/a2a/config.rs decisions:crates/busbar-plane-decisions/src/config.rs voice:crates/busbar-voice/src/config.rs (the ledger

Judged against base 17b55f973: 0 new red, 0 worse, 5 standing (excused).

tests passed: 22322, failed: 0. Run: https://github.com/GetBusbar/busbar/actions/runs/38098523626 . Artifact verdict-110ec0b956d26003321f3f6dcb134f9109d58258 (failures.json, junit.xml, raw.log; 90 days).

@MattJackson
MattJackson added this pull request to the merge queue Oct 8, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to a conflict with the base branch Oct 8, 2026
…ataPosture-based service_account_token_uri/vet_token_uri, take predev's outbound_credential_refusals
…s (name, canonical, door) triple

The merge of origin/predev changed busbar_kernel::preflight::LinkedAuth to a three-field
tuple; jwt_bearer_routes still built the old pair, so the busbar crate's tests failed to
compile (E0308) and every gate that compiles them went red. Spell it as the oauth sibling does.
@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 10, 2026
@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 10, 2026
@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
@MattJackson
MattJackson removed this pull request from the merge queue due to a manual request Oct 10, 2026
@MattJackson
MattJackson added this pull request to the merge queue Oct 10, 2026
@github-merge-queue
github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Oct 10, 2026
@MattJackson MattJackson added fixing and removed fixing labels Oct 10, 2026
…ata fields

The jwt-bearer door_steps fixture lacked error_map and serve_planes' route
fixture lacked metadata after predev added the field, so the busbar test
target failed to compile (E0063). Not proved on Latchkey: the run budget
(RUN_CAP) is spent; the PR's CI judges.
@MattJackson
MattJackson added this pull request to the merge queue Oct 11, 2026
Merged via the queue into predev with commit 7d4dec9 Oct 11, 2026
9 checks passed
@MattJackson
MattJackson deleted the auth-fix-a-jwt-token-uri branch October 11, 2026 01:33
MattJackson added a commit that referenced this pull request Oct 11, 2026
…redev's verify/admit/audit proofs

Ruling: predev (#628, #622) landed the decisions root leg's verify, admit and audit cells with
the corrected verify test (a_decisions_unit_from_a_key_naming_another_pool_is_refused_before_its_dial:
Approve/ScopeDenied sealed before admit and dial, plus the granted-every-pool control). This branch's
older duplicate (a_unit_granted_only_another_pool_is_refused_before_admit) is dropped and the three
root cells cite predev's tests and notes; coverage is re-pointed, never retired
(BUSBAR-1.6.0.md:3857), and the root-leg proof stays beside each cell as the teller-steps gate of
Law 1 requires (BUSBAR-1.6.0.md:2176). serve_tests.rs is predev's verbatim, which also removes the
duplicate `allowed_pools` field the auto-merge produced in serve_configured. The branch keeps its
own intent: the seven jev rig cells and owed_gaps {}.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant