Enforce companion-only credential delivery and refresh activation handoff
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 7s

Assistant: codex
Assistant-Model: gpt-6-astra
Assistant-Session: 01a0e324-abce-7e51-bb2b-496f097afdb0
This commit is contained in:
tegwick 2026-09-27 15:58:53 +02:00
parent 303cbf652b
commit 5c6f2b319d
8 changed files with 150 additions and 24 deletions

View file

@ -109,7 +109,9 @@ The companion lane must consent in its own catalog entry with
the same stage, declare the field and `exec-env`, and bind no exec owner of its
own. Env names must be unique, must not match the fixed environment or the
primary field's name, and must not use loader or engine credential prefixes.
Pending owners cannot list companions.
Pending owners cannot list companions. A lane declaring `companion_of` cannot
be selected as the primary `exec` lane: it is delivered only through a listed
primary with a configured owner, even if standalone lane approval exists.
Companions are part of the owner binding, so changing a companion's lane, field
or env name changes the owner digest and invalidates earlier decisions.
@ -120,6 +122,9 @@ consume for action `exec`. No lane's decision covers another lane. After every
gate passes, each value is read through its own lane's AppRole session. A
failure on any lane starts no child. The binding is checked again after the
reads, and all values are injected together and redacted from the output.
The delivery helper independently checks that the supplied companions exactly
match the pinned lane/field/environment list and still satisfy consent and stage
constraints before reading the primary or any companion.
Proof: `tests/test_exec_owner_companions.py`, plus
`tests/test_integration_companions.py` on a throwaway OpenBao (two lanes, one